Security

Testing So-Called 'Unified Threat Managers' 98

snydeq writes "The InfoWorld Test Center has released vulnerability testing results for four so-called 'unified threat managers' — single units that combine firewall, VPN, intrusion detection and prevention, anti-malware, anti-spam, and Web content filtering in lieu of a relay rack stuffed top to bottom with appliances. The lab threw nearly 600 exploits of known vulnerabilities in a wide range of popular OSes, applications, and protocols, and despite being designed to thwart such threats, the UTMs as a class allowed hundreds to pass through. Why did the UTMs miss so many exploits? A lack of horsepower to perform the necessary deep packet inspection under load is suspected, as the lab pushed the limits of each unit's throughput with legitimate traffic. 'The upshot is, although the vendors have packed these devices with additional gateway security functions, clearly many UTMs are still strictly firewalls at heart.'"
Graphics

Budget Graphics Card Roundup 186

Anonymous Coward writes "Not all of us are prepared to drop $500 for a killer graphics card. Generally, the sweet spot in price and performance is in the budget category of GPUs. Joel Durham Jr. over at ExtremeTech reviews nine current graphics cards, all of which are below $250, some below $150, to determine which cards are worth the time and money for the gamer on a budget. In the sub $150 category, the ATI Radeon 4770 performed the best for its price. Spend a little more and Joel recommends the GeForce 260."
The Courts

Unmasking Blog Commenters Not a Huge Threat To Freedom 105

Frequent Slashdot contributor Bennett Haselton writes with his take on a recent court decision about the rights of online commenters. "Although a court has ruled that the police can subpoena the identities of users who posted comments in a newspaper's blog, I think this is not as big of a threat to journalistic integrity as it might seem. And in any case when the judge ruled against the privacy rights of 'bloggers,' he didn't actually mean 'bloggers." Read on for the rest of Bennett's thoughts.
Bug

Skype Billing Gone Haywire For Some Users 154

Cousin Scuzzy writes "This morning I awoke to 26 e-mail messages from Skype and PayPal notifying me of multiple payments for my Skype account that had been charged to my credit card and subsequently refunded. At first I suspected that this was a new wave of spam that had slipped through my defenses, but it quickly became apparent that they were legitimate messages. I then began to worry that my Skype account had been compromised. The first message from Skype thanked me for setting up their "Auto-Recharge" service which automatically purchases Skype credit when the balance falls below a certain amount. This was very suspicious, as I had never requested this service. Based on posts to Skype's forum, it now appears that there have been serious billing problems at Skype relating to Auto-Recharge for over a month. Although I believe that all unauthorized charges to my credit card have been refunded, it is worrisome that Skype, or anyone, would charge my account erroneously. Skype, for their part, has not yet e-mailed me an explanation or posted one online. This problem reinforces my aversion to automatic bill payment services that give companies the authority to draw money from my bank account at their discretion." For all the Skype users out there, have you experienced this? For what it's worth, the company's own response on the linked forum thread says that the problem is now solved.
Image

Front End Drupal Screenshot-sm 68

Michael J. Ross writes "Content management systems (CMSs) are created largely by Web developers using back-end programming languages (such as PHP, by far the most common choice). The free CMSs are built as open source projects, by volunteers who have many demands on their time. As a result of both of these competing factors, far less time is devoted to the front-end aspects of these CMSs. In turn, the "themes" that define the appearance of a CMS-based website are typically substandard, in the eyes of many Web designers and, most likely, countless users of those sites. This criticism has been leveled even against Drupal, although the situation is improving. A new book, Front End Drupal: Designing, Theming, Scripting, is intended to help Drupal designers everywhere speed up that process of improvement." Read on for the rest of Michael's review.

A System For Handling 'Impostor' Complaints 165

Frequent Slashdot contributor Bennett Haselton writes "A woman sued Yahoo because they wouldn't remove a page created by her ex-boyfriend pretending to be her and soliciting strangers for sex. What would be an effective system for large companies like Yahoo to handle 'impostor' complaints, without getting bogged down by phony complaints and unrelated disputes? This is a harder problem than it seems because of the several possible cases that have to be considered. One possible solution is given here." Read on for Bennett's analysis.
Spam

FTC Targets Massive Car Warranty Robocall Scheme 361

coondoggie writes "Robocalls are a scourge, and the Federal Trade Commission today took action against one outfit by asking a federal court to shut down companies that have been bombarding consumers with hundreds of millions of allegedly deceptive robocalls in an effort to sell vehicle service contracts. According to the FTC, the robocalls have prompted tens of thousands of complaints from consumers who are either on the Do Not Call Registry or asked not to be called. Five telephone numbers associated with the defendants have generated a total of 30,000 Do Not Call complaints. Consumers received the robocalls at home, work, and on their cell phones, sometimes several times in one day. Businesses, government offices and even 911 dispatchers also have been subjected to the calls, the FTC said." Reader powerlord points out that another such company, not named in the FTC filing, raised the ire of thousands of internet-goers, who struck back by rickrolling the company's voice mail and digging up personal information on the company's president.
The Military

US Military Looks For Massive Spam Solution 228

Several users have pointed out a recent request to technology companies from the Defense Information System Agency for ideas on how to build an e-mail defense system to catch spam. The solution would have to scan about 50 million inbound messages a day across some 700 unclassified network domains. "Defense currently scans e-mails for viruses and spam coming into systems serving the military services, commands or units. DISA wants to extend the protection to the interface between the Internet and its unclassified network, the Non-classified Internet Protocol Router Network. The agency also wants the ability to scan all outbound e-mails from the 5 million users. [...] DISA's request ties in with recommendations that the Defense Science Board issued in April that said Defense is more vulnerable to cyberattacks because of its decentralized networks and systems. The board envisioned a major role for DISA in developing the architecture for enterprise-wide systems."
Software

Computers With Opinions On Visual Aesthetics 125

photoenthusiast writes "Penn State researchers launched a new online photo-rating system, code named Acquine (Aesthetic Quality Inference Engine), for automatically determining the aesthetic value of a photo. Users can upload their own photographs for an instant Acquine rating, a score from zero to 100. The system learns to associate extracted visual characteristics with the way humans rate photos based on a lot of previously-rated photographs. It is designed for color natural photographic pictures. Technical publications reveal how Acquine works."
Books

What Can I Do About Book Pirates? 987

peterwayner writes "Six of the top ten links on a Google search for one of my books point to a pirate site when I type in 'wayner data compression textbook.' Others search strings actually locate pages that are selling legit copies including digital editions for the Kindle. I've started looking around for suggestions. Any thoughts from the Slashdot crowd? The free copies aren't boosting sales for my books. Do I (1) get another job, (2) sue people, or (3) invent some magic spell? Is society going to be able to support people who synthesize knowledge or will we need to rely on the Wikipedia for everything? I'm open to suggestions."
Government

Let Big Brother Hawk Anti-Virus Software 405

Frequent Slashdot contributor Bennett Haselton writes with his idea for mass adoption of anti-virus software: "If the US government did more to encourage people to keep their computers secure — by buying TV ads to publicize free private-sector anti-virus programs, or subsidizing the purchase of anti-virus software — we'd all be better off, on average. That's not just idealistic nanny-statism, but something you can argue mathematically, to the point where even some libertarians would agree." Read on for the rest of Bennett's thoughts.
Communications

Bandwidth Fines Bad, But Not Net Neutrality Issue 159

Frequent Slashdot contributor Bennett Haselton writes with his take on the recent Time Warner Cable fiasco: "Net Neutrality crusaders at FreePress.net recently called attention to Time Warner's plan (later rescinded) to impose fines on users for going over bandwidth limits. I agree generally, but I think this is easily confused with the reasoning in favor of Net Neutrality, and it's important to keep the arguments separate." Read on for the rest of Bennett's thoughts.
Image

How To Have an Online Social Life When You're Dead Screenshot-sm 187

A wave of new companies are springing up to offer such things as virtual cemeteries, alerts to remind loved ones about the anniversary of your death, and even email services that send an alert to your sinful relatives in danger of being left behind when the Rapture carries you away. "People have a desire to perpetuate not only for themselves, but for their loved ones, the story of their lives, and technology has all these new great ways of doing that," said John McQueen, owner of the Anderson McQueen funeral home.
Image

Universal Design for Web Applications Screenshot-sm 85

Michael J. Ross writes "Two decades ago, Web usage was limited to a single individual (Sir Tim Berners-Lee) using the only browser in existence (WorldWideWeb) running on a single platform (a NeXT Computer). Nowadays, billions of people access the Web daily, with the ability to choose from over a dozen browsers running on desktop computers, laptops, and a variety of mobile devices, such as cell phones. The number of possible combinations is growing rapidly, and makes it increasingly difficult for Web designers and developers to craft their sites so as to be universally accessible. This is particularly true when accounting for Web users with physical and cognitive disabilities — especially if they do not have access to assistive technologies. The challenges and solutions for anyone creating an accessible website are addressed in Universal Design for Web Applications, authored by Wendy Chisholm and Matt May." Keep reading for the rest of Michael and Laura's review.
Spam

Opting Out Increases Spam? 481

J. L. Tympanum writes "I used to ignore spam but recently I have been using the opt-out feature. Now I get more spam than ever, especially of the Nigerian scam (and related) types. The latter has gone from almost none to several a day. Was I a fool for opting out? Is my email address being harvested when I opt out? Has anybody had similar experience?"
The Media

Consortium To Share Ad Revenue From Stolen Stories 94

Hugh Pickens writes "Erick Schonfeld has an interesting story in TechCrunch about a consortium of publishers including Reuters, the Magazine Publishers of America, and Politico that plans to take a new approach towards the proliferation of splogs (spam blogs) and other sites which republish the entire feed of news sites and blogs, often without attribution or links. For any post or page which takes a full copy of a publisher's work, the Fair Syndication Consortium thinks the ad networks should pay a portion of the ad revenues being generated by those sites. Rather than go after these sites one at a time, the Fair Syndication Consortium wants to negotiate directly with the ad networks which serve ads on these sites: DoubleClick, Google's AdSense, and Yahoo. One precedent for this type of approach is YouTube's Content ID program, which splits revenues between YouTube and the media companies whose videos are being reused online. How would the ad networks know that the content in question belongs to the publisher? Attributor would keep track of it all and manage the requests for payment. The consortium is open to any publisher to join, including bloggers. It may not be the perfect solution but 'it is certainly better than sending out thousands of takedown notices' writes Schonfeld."
Spam

The Ecological Impact of Spam 176

krou writes "A new study entitled 'The Carbon Footprint of Spam' (PDF) published by ICF International and commissioned by McAfee claims that spam uses around 33 billion kilowatt hours of energy annually, which is approximately enough to power 2.4 million US homes (or roughly 3.1 million cars) for a year. They calculated that the average CO2 emission for a spam email is around 0.3 grams. Interestingly, the majority of energy usage (around 80%) comes from users viewing and deleting spam, and searching for legitimate emails within spam filters. They also claim that 'An individual company can find that one fifth of the energy budget of its email system is wasted on spam.' One of the report's authors, Richi Jennings, writes on his blog that 'spam filtering actually saves an incredible amount of energy.' He continues, 'Imagine if every inbox were protected by a state-of-the-art spam filter. We could save about 75% of the spam energy used today — 25 TWh per year; that's like taking 2.3 million cars off the road.""
The Courts

Jack Thompson Spams Utah Senate, May Face Legal Action 319

eldavojohn writes "Yesterday, GamePolitics ran an interesting story about the Utah Senate President threatening Jack Thompson with the CAN-SPAM Act. You might recall Utah being Jack's last hope and hold-out after being disbarred in Florida and more or less made a mockery everywhere else. Well, from Utah's Senate Site, we get the picture of what Jack is up to now: spamming his last friends on the planet. The Salt Lake Tribune is reporting on Senate President Michael Waddoups' statements: 'I asked you before to remove me from your mailing list. I supported your bill but because of the harassment will not again. If I am not removed, I will turn you over to the AG for legal action.' The Salt Lake Tribune reports that Waddoups confirmed on Tuesday that he would attempt to pursue legal action under the federal CAN-SPAM Act of 2003 against Jack Thompson."
Microsoft

Microsoft Won't Vouch For Linux 208

theodp writes "Gov. Christine Gregoire applauded Microsoft's job training partnership with WA state and county government agencies, which calls for the distribution of 30,625 training vouchers statewide during the next 90 days. 'This program [Elevate America] is all about equipping people with the new skills they'll need to get a job in the changing economy,' said Microsoft Counsel Brad Smith, who also made it very clear that getting 'workforce ready' won't involve acquiring any Linux skills. At least this offer appears to be no-cost, unlike the $35 Microsoft requested in an e-mail come-on for 'The Stimulus Package for Your Career' (so much for Smith's and Gregoire's war on spam)."
Worms

Twitter Gets Slammed By the StalkDaily XSS Worm 145

CurtMonash writes "Twitter was hit Saturday by a worm that caused victims' accounts to tweet favorably about the StalkDaily website. Infection occurred when one went to the profile page of a compromised account, and was largely spread by the kind of follower spam more commonly used by multi-level marketers. Apparently the worm was an XSS attack, exploiting a vulnerability created in a recent Twitter update that introduced support for OAuth, and it was created by the 17-year-old owner of the StalkDaily website. More information can be found in the comment thread to a Network World post I put up detailing the attack, or in the post itself. By evening, Twitter claimed to have closed the security hole."

Slashdot Top Deals