Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book General > News

Notices

Reply
 
Thread Tools Search this Thread
Old 09-29-2014, 05:00 PM   #31
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Quote:
Originally Posted by cromag View Post
Actually, the government was a big user of UNIX (back in my day) and there are several versions of Linux that are approved for use in various departments. In particular, there is at least one version approved for the Dept of Defense -- with rumors that they have at least one even more secure version they use in-house.
Because they of all people would know just how secure Windows is, after the backdoors have been installed at their behest.
eschwartz is offline   Reply With Quote
Old 09-29-2014, 06:15 PM   #32
Andrew H.
Grand Master of Flowers
Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.Andrew H. ought to be getting tired of karma fortunes by now.
 
Posts: 2,201
Karma: 8389072
Join Date: Oct 2010
Location: Naptown
Device: Kindle PW, Kindle 3 (aka Keyboard), iPhone, iPad 3 (not for reading)
Quote:
Originally Posted by Sregener View Post
At a fundamental level, it is the philosophy behind the software that makes Linux safer. This is for a few reasons.

First, the code is not secret. That means that many security flaws are quickly discovered, because many eyes can see them.

[Snip]

Nothing short of heaven is perfect, but Linux's security through openness has been a winning formula for years and will continue to be so.
That's kind of the open source mantra, but I'm skeptical. The Shellshock vulnerability has existed since 1992. Heartbleed was published, reviewed, accepted as a standard...and a huge weakness was not discovered for two years.
Andrew H. is offline   Reply With Quote
Advert
Old 09-29-2014, 07:16 PM   #33
Waylander
Guru
Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.
 
Posts: 669
Karma: 2905052
Join Date: Oct 2013
Device: Kindle Paperwhite 5 16GB, Kindle Paperwhite 6, Kobo Clara,
Do I need to panic about my Macbook? I ran a virus scan and came up clean, but that may not mean anything.
Waylander is offline   Reply With Quote
Old 09-29-2014, 07:24 PM   #34
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Quote:
Originally Posted by Waylander View Post
Do I need to panic about my Macbook? I ran a virus scan and came up clean, but that may not mean anything.
Not unless you are running some sort of network service -- the vulnerability requires that people actually have some sort of way of inserting code on your computer.

SSH access would open the door too -- but that requires the attacker have a valid SSH authentication key.

http://www.pcworld.com/article/26886...shock-bug.html


Also, virus scans will only show that you haven't been attacked yet.

Last edited by eschwartz; 09-29-2014 at 07:42 PM.
eschwartz is offline   Reply With Quote
Old 09-29-2014, 07:34 PM   #35
rcentros
eReader Wrangler
rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.rcentros ought to be getting tired of karma fortunes by now.
 
rcentros's Avatar
 
Posts: 7,894
Karma: 52566355
Join Date: Mar 2013
Location: Boise, ID
Device: PB HD3, GL3, Voyage, Clara HD
Quote:
Originally Posted by Waylander View Post
Do I need to panic about my Macbook? I ran a virus scan and came up clean, but that may not mean anything.
The difference between Windows and Linux (and Mac) is that, with Windows, you're almost always talking about malware, drive-by infestations, ransomware, etc., after the fact. With Linux you're almost always talking about hypothetical problems -- "what could have happened."
rcentros is offline   Reply With Quote
Advert
Old 09-29-2014, 07:42 PM   #36
Waylander
Guru
Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.
 
Posts: 669
Karma: 2905052
Join Date: Oct 2013
Device: Kindle Paperwhite 5 16GB, Kindle Paperwhite 6, Kobo Clara,
I'm slightly worried because the college campus wifi has no protection. What should I do?
Waylander is offline   Reply With Quote
Old 09-29-2014, 08:04 PM   #37
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Quote:
Originally Posted by Waylander View Post
I'm slightly worried because the college campus wifi has no protection. What should I do?
Don't enable remote logins for a guest account (no password protection), don't enable remote logins period if you have decked out your login password in neon all over the lawn (or posted an SSH private key -- which you have authorized for logging into your computer -- on shady or even unshady sites), don't enable a webserver and put up CGI scripts, and you should be perfectly safe.

In other words, if you were vulnerable, you would've already known because you're in *that world*.

Last edited by eschwartz; 09-29-2014 at 08:09 PM.
eschwartz is offline   Reply With Quote
Old 09-29-2014, 11:35 PM   #38
pssquirrel
ebooknut
pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.pssquirrel ought to be getting tired of karma fortunes by now.
 
pssquirrel's Avatar
 
Posts: 297
Karma: 688154
Join Date: Oct 2011
Device: Kindle Voyage & Oasis
Quote:
Originally Posted by Waylander View Post
Do I need to panic about my Macbook? I ran a virus scan and came up clean, but that may not mean anything.
Apple just released a security patch:
http://support.apple.com/kb/DL1769

More info: http://mashable.com/2014/09/29/apple-shellshock-update/
pssquirrel is offline   Reply With Quote
Old 09-30-2014, 05:26 AM   #39
Waylander
Guru
Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.Waylander ought to be getting tired of karma fortunes by now.
 
Posts: 669
Karma: 2905052
Join Date: Oct 2013
Device: Kindle Paperwhite 5 16GB, Kindle Paperwhite 6, Kobo Clara,
Thanks pssquirrel, I've just downloaded the patch. Better to be safe than very sorry. to eschwartz, I haven't done any of the things you've mentioned, so should be ok. Thanks to both of you for the advice.
Waylander is offline   Reply With Quote
Old 10-05-2014, 07:50 AM   #40
Katsunami
Grand Sorcerer
Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.Katsunami ought to be getting tired of karma fortunes by now.
 
Katsunami's Avatar
 
Posts: 6,111
Karma: 34000001
Join Date: Mar 2008
Device: KPW1, KA1
Quote:
Originally Posted by taustin View Post
I'll say. NPR did a piece on it yesterday, and the expert they were interviewing did not seem to be aware this does not affect Windows. The host, of course, was unaware of what an operating system is.
It can affect Windows if you run Cygwin. I have it installed because, if I need or want a command line, i'm much more used to Unix/Linux than Windows. I've been running Services for Unix, and later Cygwin, since 1998.
Katsunami is offline   Reply With Quote
Old 10-05-2014, 08:56 AM   #41
gmw
cacoethes scribendi
gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.gmw ought to be getting tired of karma fortunes by now.
 
gmw's Avatar
 
Posts: 5,818
Karma: 137770742
Join Date: Nov 2010
Location: Australia
Device: Kobo Aura One & H2Ov2, Sony PRS-650
Quote:
Originally Posted by Andrew H. View Post
That's kind of the open source mantra, but I'm skeptical. The Shellshock vulnerability has existed since 1992. Heartbleed was published, reviewed, accepted as a standard...and a huge weakness was not discovered for two years.
Yes. The idea that the code must be safe because many eyes can see it assumes that many eyes (with the education and experience to spot a bug) are actually looking. It's not a reliable assumption.

A lot of this stuff, especially in the open source world, has been around for a long time. People re-use the code because that's the smart and efficient thing to do. But do they go over it looking for bugs? Of course not, because that would deny the efficiency you were looking for by re-using the code in the first place. They put trust in the fact that it's been around for a long time, so it must be reliable - right? Not always.

Which is not an argument against using open source software, it's just facing the reality that software is a complex beast. Bugs are found by explicit testing and by using the software - hence popular software often has what might look like a disproportionately long list of bug-fixes. The true advantage of open source is not that everyone can see if there are bugs in the source, but that anyone (with the relevant skills) can fix the bugs when they are found.
gmw is offline   Reply With Quote
Old 10-05-2014, 02:14 PM   #42
taustin
Wizard
taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.taustin ought to be getting tired of karma fortunes by now.
 
Posts: 1,358
Karma: 5766642
Join Date: Aug 2010
Device: Nook
Quote:
Originally Posted by Katsunami View Post
It can affect Windows if you run Cygwin.
I suspect that the expert has never heard of Cygwin. I'd bet real money the host never has. They both clearly had no clue what this is all about, what the risks are, or what computers are at risk. They were there to generate hysteria, because that's what news organizations do.
taustin is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Using Sony software (350) on two computers Dixiemsala Sony Reader 5 01-26-2011 01:50 PM
Can the sony reader software be installed on two computers? DarkHaloPrincess Sony Reader 4 06-14-2010 05:31 PM
Sony software bug?! schreibsatcu Sony Reader 17 10-01-2009 08:42 AM
Hacking like we had for the 500? TadW Sony Reader Dev Corner 2 04-03-2008 05:46 AM


All times are GMT -4. The time now is 12:05 PM.


MobileRead.com is a privately owned, operated and funded community.