To all you folks out there who think being tortured and nailed to a cross to die and have your carcass being picked apart by scavengers constitutes a “good” day, Happy Good Friday to you. To everybody else (who doesn’t work weekend, anyway), hey, every Friday is good, right? This past week, I didn’t take Monday off. That turned out to be a dreadful mistake, so I have next Monday off. That makes today an even better than “good” Friday.
So, I mentioned a password manager the other day, and I’ve come across another one that may actually be better (and freer). It’s called LastPass and while I haven’t tried it, it looks like it has some good features (including, for instance, auditing you passwords for ones you’re re-using, and which sites may be affected by, for instance, Heartbleed). So it might be worth checking out. There’s a “premium” version you can upgrade to for $12 a month if you want to support them. As I said, I haven’t used it, but I may just give it a try.
Speaking of Heartbleed, I’ve had a chance to look into it and it doesn’t appear to be quite as horrible as it was originally made out to be. Bloomberg reported that two NSA “insiders” claimed that the agency knew about this bug in OpenSSL for two years and had been exploiting it.
This could be true (wouldn’t put it past them), but it seems like bullshit. For one thing, it’s kind of a crappy exploit. As I mentioned before, you can only get a random 64 Kb of server memory every time you “ping” a vulnerable server. This could, in theory, be a username and password if a user just happened to be logging in at that time, but it’s also just as likely to be a nugget of a web page or something.
This means that in order to get useful info, you’d either have to get lucky in a hurry or be constantly pinging the server and collecting the info. From what I’ve read, it is possible to use this exploit to obtain a server’s private key (that’s the thingie that can decrypt anything sent to it that’s been encrypted using the server’s public key – which is how this stuff works), but from what I’ve read it’s not a trivial thing to do.
Also, the guy who put this but of code into the project (a Kraut, ironically enough, given that the Germans are some of the most pissed off folks at the US spying) has been identified and come forward and he says that he just failed to verify that a particular variable had a “realistic length” and the error slipped through and that the NSA had nothing to do with it.
Having fucked up my share of code, I find that to be pretty believable. And given that this is all open source stuff done by volunteers, I really think the for-profit companies that make use of these freely available software libraries ought to spend some time and money on reviewing the code. Maybe they’ll do that now.
The other reassuring thing is that there’s been no evidence of anybody scanning the Internet over the past two years looking for vulnerable servers (one guy I was listening to the other day was saying that if you had a decent setup, you could scan the entire Internet in about 20 minutes). Of course, once this flaw was announced, the scanning commenced almost immediately.
So, anyhow, it seems as though most of us won’t get bit by this one, though it’s not a bad idea to go and change all your passwords (it’s not a bad idea to do that periodically anyway). And if you can enable two-factor authentication at a website (especially something like your bank or PayPal or whatever), you should do that even if it is kind of a pain in the ass.
Oh well, I guess it’s time to see about getting some work done. Have a good Friday.
:doh:
http://i.dailymail.co.uk/i/pix/2014/04/10/article-2601433-1CFCF64700000578-275_634x345.jpg
:doh:
http://i.dailymail.co.uk/i/pix/2014/04/10/article-2601433-1CFCF64700000578-275_634x345.jpg
I hate this fucking town. :fu:
I don’t know much about the Heartbleed bug or whether or not it’s related to the NSA paying ten million dollars to RSA for putting psuedo-random encryption into TSL and SSL, so the keys could be easily deciphered. My hunch is that it is. All of this stuff is way out of my depth, so I can’t really comment.
Most of my hatred for this town or city, whatever the fuck you want to call it, stems from my lack of employment opportunities, my shit-head neighbor that tainted a cookie he gave me with illicit drugs, and my ex-girlfriend with her borderline personality disorder bullshit.
I’m trying to get employment, but it’s all bullshit — jumping through hoops for nothing. I’ve completely stopped talking to my ex and my neighbor and I hope they can go fly a kite together.
This site has turned to shit, too. No offense, PJ, but seriously. I can’t even edit my posts anymore, the emoticons aren’t working, and I bet embedding pictures and videos is still fucked.
Very uncool and uncalled for.
Nah, I’ve been here just as long as any of you. Almost ten years, and I think I can voice my opinion freely and openly with any foul remarks I wish.
I’m not even able to enter the Site Admin.. Ridiculous.
It is not any matter of seniority. It is a matter of respect. As I have said before, this wee sandbox that pj has left here without compensation for what is left of the MS bloggers is out of the kindness of his heart. If it isn’t maintained to a level of ‘perfection’ because of WordPress program changes and other things, so be it. He has a wife, a life, a job, a home, a family, a tough winter… He really doesn’t owe us anything and I am surprised he didn’t shut it down a while ago. Hopefully, he won’t now. I don’t appreciate you getting in his face.
I’m not pulling any punches here. If I don’t like something and my comments seem rude, harsh or immature so be it. This is by no means a formal setting and if I want to vent about things I will. The sandbox has poo in it, Vernon.
Ditto!
Something else that pisses me off. One of my bookmark files mysteriously disappeared. I don’t know what the deal is with that. My assumption is that I was hacked. There’s not much I can do about it except complain. If I call the police they’ll put me on hold until I hang up, I’m sure.
http://youtu.be/s6NI4n8A2L8
[youtube http://www.youtube.com/watch?v=s6NI4n8A2L8&w=420&h=315%5D
Getting closer.
:bong:
For summer…
:cold: :hot:
Yeah, it sucks and I apologize. Been a real pain lately. Hell, I can’t use the reply link to reply to a comment.
It’s gone on a lot longer than I ever thought it would (frankly, I thought that once Maron’s LA show for AAR went on, that would be that), and has probably outlived its life. Places like Facebook, Twitter, and Google+ have taken the place of a lot of what people once came here for. I reckon I’ll have to give some thought to retiring it. But I confess I’d miss the handful of people that still pop in.
On the bright side, there are plenty of free places where you can do your own thing and make it way better than I personally have the time for.
Now don’t start talking like that just because of one disgruntled comment! I would greatly miss your ruminations and comments. If you close this shop down, you’d dang well better start a new one, pj. You make me smile, laugh and think as do the commenters here, those who post frequently and those who drive-by. Besides, after all these years, I think in Emos. :gate:
As I seem to remember, pj, you bailed on FB at one time and if you are back there you are well hidden or have me blocked. I do FB too much which spares you guys so I can only bring here something that matters to me that might be of interest here. I can see a few of our ‘locals’ and some of the alumni on FB but I am pretty sure a few are not. Also, I think we can be a little more personal here. Recently I have seen some troll behavior on FB and it gets tiring dealing with that crap.
Once again, I greatly appreciate it that you have kept the MS sandbox going. Whenever I have had problems, I let you know as information and not complaint. I am not sure I was here from the start 8 1/2 years ago but when I got in I don’t think we could embed and post photos. First time I did it was so large you would have needed a wide screen TV to view and I was mortified that I broke the blog. I have always been very careful ever since.
Let me suggest that you remove admin privileges from all but yourself. As I remember, you just allowed those so others could post a topper when you wanted to scale back and it was not long before it was all you again anyway. Thankfully you kept going and realized you didn’t have to do one every day at 7 AM so there could be a mad dash to be frist. Besides, you are a hard act to follow. Although I did not mention it before, I think when the new ‘problems’ started up a short while ago it was right after someone else posted a new thread. There is ample opportunity to make comment on the existing thread.
Whatever you decide, Coach.
:sammy: :fire: :kub: :pup: :banana: :alc: :bow:
PJ, you have every right to do whatever you want with this site but I would really, really miss it. Even though we have met only in cyber space I regard the folks here as friends.
Someone’s in the kitchen with Dinah…