HN user

fname

930 karma

Based in Northern VA, DC Area

Posts29
Comments224
View on HN
www.mimecast.com 5y ago

Important Update from Mimecast

fname
1pts0
www.wsj.com 11y ago

U.S. Suspects Hackers in China Breached About 4M People’s Records

fname
2pts0
blog.surface.com 11y ago

Announcing Surface 3

fname
7pts0
news.sciencemag.org 11y ago

Possible orphan black hole lies just 90M light-years from Earth

fname
2pts0
www.popularmechanics.com 11y ago

Here's How Scientists Can Save Philae from Its Rough Comet Landing

fname
3pts0
www.theverge.com 13y ago

In magnificent solar display, 'fiery rain' loops onto the sun's surface

fname
1pts0
science.time.com 13y ago

How to Escape From a Black Hole

fname
1pts0
news.cnet.com 15y ago

Sony sued for PlayStation Network data breach

fname
3pts1
www.math.columbia.edu 15y ago

Did the LHC find the Higgs boson?

fname
14pts4
tech.shantanugoel.com 15y ago

Making Kinect work on the PS3

fname
1pts0
www.businessweek.com 15y ago

Microsoft Gets High Court Review on I4i Patent Award

fname
0pts0
www.theregister.co.uk 15y ago

Yahoo boss blames revenue dip on better Bing

fname
1pts0
www.techcrunch.com 15y ago

HasWifi Shows You Which Flights Have Wifi

fname
18pts16
news.ycombinator.com 15y ago

Ask HN: Review my project for Inflight Wifi Tracking

fname
12pts4
binginstant.com 15y ago

More Instantization -- Bing Instant

fname
1pts1
msftnerd.tumblr.com 15y ago

Rumor: Windows Phone 7 will use Courier's "tuck-and-paste" in post launch update

fname
1pts0
www.youtube.com 15y ago

The Last Exorcism Marketing on ChatRoutlette

fname
48pts18
www.ted.com 15y ago

TED: Peter Molyneux demos Milo, the virtual boy (Project Natal/Kinect)

fname
1pts0
news.ycombinator.com 16y ago

Ask HN: Anyone have OCD?

fname
9pts4
www.mobileappmatch.com 16y ago

What Windows Phone App users want

fname
1pts1
seclists.org 16y ago

MSRC: Microsoft-Spurned Researcher Collective releases 0-day

fname
38pts4
gizmodo.com 16y ago

Rumor: 'Google Me' is a Facebook Killer

fname
9pts6
techcrunch.com 16y ago

Microsoft by the Numbers

fname
170pts101
social.venturebeat.com 16y ago

Could adding a LinkedIn connection land you in legal hot water?

fname
4pts0
techcrunch.com 16y ago

Memeo Connect Makes GDrive a Reality

fname
8pts0
www.isecom.org 16y ago

The Bad People Project - Security Awareness for Kids

fname
3pts0
www.wmexperts.com 16y ago

Skype for Windows Phone 7 "on the roadmap", not killed

fname
1pts0
tech.fortune.cnn.com 16y ago

IPad gobbles up netbook sales

fname
1pts0
techcrunch.com 16y ago

First Apple, Now PDA Inventor Slaps HTC With Another Lawsuit

fname
3pts0

+ the pencil @ $99 and the smart keyboard at $169. > $1k for the entry level model to be comparable with the Surface Pro 3 at ~$930 (which starts at 64GB, btw).

but DISA can't enforce STIGs across the entire government can they?

No, with a small caveat: If that civilian agency (say DHS) is connected to the GIG[1], then DISA has a say-so and can threaten to disconnect them for failing security audits.

Something to keep in mind is that the STIGs are merely implementation guides to secure a system. Therefore, different agencies have different interpretations. In some cases specific secure implementations break systems and applications (mostly legacy ones), so they avoid securing those particular settings all together.

1: https://en.wikipedia.org/wiki/Global_Information_Grid

I don't disagree. Unfortunately, this all falls on DoD-DISA. The NSA works with DISA to write the policy for how to secure systems (called STIGs) and also has 'Red Teams', but they aren't the arm that certifies these systems before coming online, nor are they the ones the ensure the systems stay secured as new vulnerabilities are found and patched -- that's DISA again.

Also on whether WinXP users are going to qualify for the free upgrade?

Nope. There is no upgrade path from XP -> Windows 10. You will have to go from Win7/8 to qualify for the free upgrade to 10.

From the comments in the article

Microsoft informed us that a fix was planned for the January patches but has to be pulled due to compatibility issues. Therefore the fix is now expected in the February patches.

So, they met the deadline and fixed the vulnerability, but due to compatibility issues had to pull it before being released through Windows Update.

Specifically, it related to Microsoft Secure Channel, known as Schannel, Microsoft's software for implementing secure transfer of data.

I'm confused... The article says this research relates to the SChannel vulnerability being patched this month and cites IBM Researchers[1] finding it, but the link to the blog post showing the work is towards OLE and not SChannel. Also, Microsoft has mentioned that they found[2] the SChannel vulnerability through an internal audit. To me, it seems the research is talking about CVE-2014-6332[3], which shows the patch as MS14-064. MS14-066 is the patch for the SChannel vulnerability.

Either BBC is confused on which patch they're trying to report on, or I am.

Anyone similarly confused as I am?

[1] http://securityintelligence.com/ibm-x-force-researcher-finds...

[2] http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-...

[3] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-633...

Apple Watch 12 years ago

Was there any mention of how it connects? LTE? WiFi? Did I miss that part?

I fail to see how the two are even remotely the same. Google continuously scans email content to sell ads; while Microsoft does it once and admits it so they can catch someone stealing trade secrets.

While I agree that the Scroogled campaign does tread slightly into the hyperbole, I can't agree that this the double-standard that most are making it out to be.

"...also alleged to have stolen Microsoft’s “Activation Server Software Development Kit,” a propriety system used to prevent the unauthorized copying of Microsoft programs."[1]

And another expansion on what the leak could allow:

"According to the reports, not only was Windows 8 leaked, but he also leaked Windows 7 files and the Microsoft Activation Server Software Development Kit which when reverse engineered, could allow hackers to crack the Activation process within Windows, meaning that pirated copies of Windows 7 could continue to function without the nagging presence of popup messages warning users about their copy of Windows."[2]

[1] http://www.seattlepi.com/local/article/Ex-Microsoft-employee...

[2] http://www.ubergizmo.com/2014/03/microsoft-employee-responsi...

EDIT: The Guardian has a pretty good live blog feed giving constant updates - http://www.theguardian.com/world/2014/mar/08/malaysian-airli...

Very sad. Only the third crash of a 777 since being introduced in the 90s.

[1]Confirmed 14 nationalities amongst the passengers, including:

    China - 153 (including 1 infant)
    Malaysia - 38
    Indonesia - 12
    Australia -7
    USA - 4 (including 1 infant)
    France - 3
    Canada - 2
    New Zealand - 2
    Ukraine - 2
    Russian - 1
    Italy - 1
    Taiwan -1
    Austria - 1
    Netherlands - 1
[1]: http://www.malaysiaairlines.com/my/en/site/dark-site.html

Because each driver is not responsible for 300 lives in their cars. That's why there is so much attention to plane crashes. It doesn't kill one person at a time.

Right.. and this crash only killed 2 people. Perhaps one if the reports of the girl being hit by a rescue vehicle are believed; so what's your point? The real story is just how better aircraft safety has come over the years. This same accident years ago could very well have killed everyone aboard.

Just like the AF447 crash between Rio and Paris: Pilots incompetence at its best.

...and a week after this accident everyone was blaming the weird weather that happens at the equator for the crash. The point is that everyone is speculating, even you, that this this accident is the pilot's fault, but more often than not it's found to be a combination of mechanical failure and the pilot not being able to respond to it quickly enough -- which just so happens to be the official cause of AF447 crashing in 2009.

They had to!

Not too long ago, there would be a 8-10 month wait just to get an interview with someone to just kick of the individual investigation. The investigations themselves can can many, many more months after that. By allowing contracting firms and outsourcing, they've significantly lessened the wait. Unfortunately, it's coming with the cost of rampant fraud, waste and abuse (at least form what the article is asserting).

Not true. The actual Reddit[1,2] posts the article pulls this from says they have been able to sync their game to the servers. It seems that when offline, it saves it locally and uploads upon reconnect. He was able to remove the 20 minute timeout disconnect, but it still saves things locally and uploads upon reconnect.

1. http://www.reddit.com/r/SimCity/comments/1a9n5j/you_can_edit...

2. http://www.reddit.com/r/Games/comments/1a9t0e/simcity_modder...