|
In my attempt to push puppet to its limits , (for no particular reason ), to develop more powerful puppet modules , to build in a distributed lock manager , and to be more dynamic , I’m now attempting to build a Finite State Machine (FSM) in puppet.
|
|
Two days ago the official hard-float Oracle Java 7 JDK has been announced on the official Raspberry Pi blog. Prior to this there was only the OpenJDK implementation which was lacking performance. Furterhmore the Raspberry Pi Foundation announced that future Raspbian images would ship with. Oracle Java by default. If you want to give it a spin you can install the JDK with: $ sudo apt-get update && sudo apt-get install oracle-java7-jdk
|
|
33 Of The Most Hilariously Terrible First Sentences In Literature History
-
thoughtcatalog.com
-
12 years ago
-
eng
Number ten, Tonya Lavel’s, and the eleventh, David Pepper’s, were reasonably good. With those two exceptions though, these were almost universally both terrible and utterly hilarious. Permalink.
|
I just turned 30. I wanted to share 30 things I’ve learned in the past 30 years. Or at least the things I
|
|
I just shelled out to wordpress.com to buy the No Ads upgrade. I think they’re good people. I hope you all appreciate it. Let me know if you do. Happy hacking, James You can hire James and his team at m9rx corporation . You can follow James on Mastodon for more frequent updates and other random thoughts. You can follow James on Twitter for more frequent updates and other random thoughts. You can support James on..
|
|
I just shelled out to wordpress.com to buy the No Ads upgrade. I think they’re good people. I hope you all appreciate it. Let me know if you do. Happy hacking, James You can hire James and his team at m9rx corporation . You can follow James on Mastodon for more frequent updates and other random thoughts. You can follow James on Twitter for more frequent updates and other random thoughts. You can support James on..
|
|
An excerpt from the Popular Science article in which they laid out their reasoning behind turning comments off. As John Gruber said , it’s hard to believe it took them this long. “A politically motivated, decades-long war on expertise has eroded the popular consensus on a wide variety of scientifically validated topics. Everything, from evolution to the origins of climate change, is mistakenly up for grabs again. Scientific certainty i....
|
|
I just realized that my Fedora 19 installation didn’t have any of the GNOME games installed by default any more. I guess there’s no love for nibbles . Here’s a quick one-liner to get them all back: $ sudo yum search game | grep gnome | awk '{print $1}' | xargs sudo yum install - y Loaded plugins: etckeeper, langpacks, refresh - packagekit Package gnome - nibbles - 3.8 . 0 - 2. fc19 . x86_64 already installed an....
|
|
I just realized that my Fedora 19 installation didn’t have any of the GNOME games installed by default any more. I guess there’s no love for nibbles . Here’s a quick one-liner to get them all back: $ sudo yum search game | grep gnome | awk '{print $1}' | xargs sudo yum install - y Loaded plugins: etckeeper, langpacks, refresh - packagekit Package gnome - nibbles - 3.8 . 0 - 2. fc19 . x86_64 already installed an....
|
|
I always find it interesting when I realize that something I have been practicing or dealing with for a long time has a name. This time it happens to be race conditions. This is something you can’t avoid thinking about as soon as you have more than one routine sharing any kind of resource. If you’re not thinking about race conditions in your code, now is the time. A race condition is when two or more routines have access to the same re....
|
|
This article was written for and published by Gopher Academy I was looking at a code sample that showed a recursive function in Go and the writer was very quick to state how Go does not optimize for recursion, even if tail calls are explicit. I had no idea what a tail call was and I really wanted to understand what he meant by Go was not optimized for recursion. I didn't know recursion could be optimized. For those who don't k....
|
|
A week or so ago I was browsing /r/Python and I saw a link to a website called rise4fun.com , which is a Microsoft Research project that contains a lot of cool demos and tools that you can run in your browser. The demo I was linked to was a restricted Python shell that could be used to experiment wi...
|
|
A week or so ago I was browsing /r/Python and I saw a link to a website called rise4fun.com , which is a Microsoft Research project that contains a lot of cool demos and tools that you can run in your browser. The demo I was linked to was a restricted Python shell that could be used to experiment wi...
|
|
How to make your code more concise and well-behaved at the same time Have you ever had an application that just behaved plain weird? You know, you click a button and nothing happens. Or the screen all the sudden turns blank. Or the application get into a “strange state” and you have to restart it for things to start working again. If you’ve experienced this, you have probably been the victim of a particular form of defensive programming whi..
|
|
In a similar vein , Marco tells the story of how he came up with the name “Overcast”. I love stories like this. Permalink.
|
|
I absolutely love podcasts. Much to my girlfriend’s confusion, I might add. After Marco Arment sold Instapaper in April, after Yahoo! bought Tumblr. 1 in May, and after he sold The Magazine shortly thereafter, only in my wildest dreams did I hope his elusive next venture would lead Marco to create a podcast client. Then, last Sunday at XOXO, my dream came true. Perhaps that’s putting it slightly melodramatically, but to say that I — an....
|
|
What Clayton Christensen Got Wrong in his Theory of Low-End Disruption
-
stratechery.com
-
12 years ago
-
eng
Another great article by Ben Thompson, this time on Clay Christensen’s interesting disruption theories and Apple’s approach in making products that both defy them and motivate people to purchase en masse. Come for the insights into Apple, and stay for his dissection of Christensen’s widely-regarded theory; this article is well worth the read. Permalink.
|
|
I realize in my last two articles, Instapaper 5 — in which I made a number of proposals for Instapaper 5 — and Betaworks Releases Instapaper 5 — in which I conveyed my mostly positive feelings on the new release — I likely appeared very critical of Betaworks and their continued work on Instapaper. This is not the case: while I do feel a better launch strategy entailing a service-wide design overhaul and one in which they added a lar....
|
|
Looking again at that chart, and with the realities of these three markets in mind, it’s not so much that the iPhone has saturated the American-style and European-style markets, and ought to focus on the Asian-style one; rather, the iPhone has saturated the high end in all three markets the high end just varies in accessibility ($200 for American-style, $650 for Asian-style). And, if you accept that the iPhone is in roughly the same compet....
|
|
By now I realize this issue has largely fallen to the wayside, as its various permutations invariably do seemingly momentarily after gaining any significant traction, despite the condemnation many so readily metered out. Regardless of its fall from the collective’s fickle favor though, the event and ensuing discussions nevertheless merit some examination. Permalink.
|
De-Anonymizing Alt.Anonymous.Messages TOM RITTER In recent years, new encryption programs like Tor, RedPhone, TextSecure, Cryptocat, and others have taken the spotlight - but the old guard of remailers and shared inboxes are still around. Alt.Anonymous.Messages is a stream of thousands of anonymous, encrypted messages, seemingly opaque to investigators. For the truly paranoid, there is no communication system that has better anonymity ....
|
|
Peiter Mudge Zatko - Unexpected Stories From a Hacker Who Made it Inside the Government
-
media.defcon.org
-
12 years ago
-
eng
Unexpected Stories From a Hacker Who Made it Inside the Government PEITER MUDGE ZATKO Having had the opportunity to see things from within the hacker community and from a senior position in the DoD, Mudge has some enlightening stories to share, and is picking some of his favorites. He'll discuss Julian's story to him about US government involvement in the origins of Wikileaks, how the DoD accidentally caused Anonymous to target governm..
|
|
Peiter Mudge Zatko - Unexpected Stories From a Hacker Who Made it Inside the Government
-
media.defcon.org
-
12 years ago
-
eng
Unexpected Stories From a Hacker Who Made it Inside the Government PEITER MUDGE ZATKO Having had the opportunity to see things from within the hacker community and from a senior position in the DoD, Mudge has some enlightening stories to share, and is picking some of his favorites. He'll discuss Julian's story to him about US government involvement in the origins of Wikileaks, how the DoD accidentally caused Anonymous to target governm..
|
|
Drea London and Kyle O'Meara - This presentation will self-destruct in 45 minutes: A forensic deep dive into self-destructing message apps
-
www.defcon.org
-
12 years ago
-
eng
This presentation will self-destruct in 45 minutes: A forensic deep dive into self-destructing message apps DREA LONDON DIGITAL FORENSIC EXAMINER, STROZ FRIEDBERG KYLE O'MEARA DIGITAL FORENSIC EXAMINER, STROZ FRIEDBERG Prior to 2013, the phrase 'Self Destructing Message' was most commonly associated with Inspector Gadget, Maxwell Smart, and the occasional Tom Cruise movie. With the advent of smartphone apps like Snapchat, Wickr, and F....
|
|
Drea London and Kyle O'Meara - This presentation will self-destruct in 45 minutes: A forensic deep dive into self-destructing message apps
-
media.defcon.org
-
12 years ago
-
eng
This presentation will self-destruct in 45 minutes: A forensic deep dive into self-destructing message apps DREA LONDON DIGITAL FORENSIC EXAMINER, STROZ FRIEDBERG KYLE O'MEARA DIGITAL FORENSIC EXAMINER, STROZ FRIEDBERG Prior to 2013, the phrase 'Self Destructing Message' was most commonly associated with Inspector Gadget, Maxwell Smart, and the occasional Tom Cruise movie. With the advent of smartphone apps like Snapchat, Wickr, and F....
|
Made Open: Hacking Capitalism TODD BONNEWELL MAN WITH A MESSAGE, MADEOPEN.COM The game is Capitalism. The rule makers are the banks, corporations and governments. This presentation is about playing a game that is rigged by the rule makers, and winning in such fashion that the game is never the same. If you like breaking things and building them back up, or are a person, please at least watch this at a later time. I forgive you for no..
|
|
Panel - Hardware Hacking with Microcontrollers: A Panel Discussion
-
media.defcon.org
-
12 years ago
-
eng
Hardware Hacking with Microcontrollers: A Panel Discussion JOE GRAND MARK 'SMITTY' SMITH LOST RENDERMAN FIRMWAREZ Microcontrollers and embedded systems come in many shapes, sizes and flavors. From tiny 6-pin devices with only a few bytes of RAM (ala the DEF CON 14 Badge) to 32- bit, eight core multiprocessor systems (ala DEF CON 20 Badge), each has their own strengths and weaknesses. Engineers and designers tend to have the....
|
|
Panel - Hardware Hacking with Microcontrollers: A Panel Discussion
-
media.defcon.org
-
12 years ago
-
eng
Hardware Hacking with Microcontrollers: A Panel Discussion JOE GRAND MARK 'SMITTY' SMITH LOST RENDERMAN FIRMWAREZ Microcontrollers and embedded systems come in many shapes, sizes and flavors. From tiny 6-pin devices with only a few bytes of RAM (ala the DEF CON 14 Badge) to 32- bit, eight core multiprocessor systems (ala DEF CON 20 Badge), each has their own strengths and weaknesses. Engineers and designers tend to have the....
|
Blucat: Netcat For Bluetooth JOSEPH PAUL COHEN TCP/IP has tools such as nmap and netcat to explore devices and create socket connections. Bluetooth has sockets but doesn't have the same tools. Blucat fills this need for the Bluetooth realm. Blucat can be thought of as a: debugging tool for bluetooth applications device exploration tool a component in building other applications Blucat is designed to run on many different platfo....
|
Blucat: Netcat For Bluetooth JOSEPH PAUL COHEN TCP/IP has tools such as nmap and netcat to explore devices and create socket connections. Bluetooth has sockets but doesn't have the same tools. Blucat fills this need for the Bluetooth realm. Blucat can be thought of as a: debugging tool for bluetooth applications device exploration tool a component in building other applications Blucat is designed to run on many different platfo....
|
|
Alex Stamos - An Open Letter - The White Hat's Dilemma: Professional Ethics in the Age of Swartz, PRISM and Stuxnet
-
media.defcon.org
-
12 years ago
-
eng
An Open Letter - The White Hat's Dilemma: Professional Ethics in the Age of Swartz, PRISM and Stuxnet ALEX STAMOS CO-FOUNDER AND CTO, ISEC PARTNERS The information security world is constantly buffeted by the struggle between whitehats, blackhats, antisec, greenhats, anarchists, statists and dozens of other self-identified interest groups. While much of this internecine conflict is easily dismissed as "InfoSec Drama", the noise of inter....
|
|
Alex Stamos - An Open Letter - The White Hat's Dilemma: Professional Ethics in the Age of Swartz, PRISM and Stuxnet
-
media.defcon.org
-
12 years ago
-
eng
An Open Letter - The White Hat's Dilemma: Professional Ethics in the Age of Swartz, PRISM and Stuxnet ALEX STAMOS CO-FOUNDER AND CTO, ISEC PARTNERS The information security world is constantly buffeted by the struggle between whitehats, blackhats, antisec, greenhats, anarchists, statists and dozens of other self-identified interest groups. While much of this internecine conflict is easily dismissed as "InfoSec Drama", the noise of inter....
|
How to use CSP to stop XSS KENNETH LEE PRODUCT SECURITY ENGINEER, ETSY INC. Crosssite scripting attacks have always been a mainstay of the OWASP Top 10 list. The problem with detecting XSS is that you can't go looking at web log traffic to determine if a request contains an actual cross site scripting attack attempt, much less one that will actually succeed against your defenses. Our work has helped reveal some nuances with implementing....
|
How to use CSP to stop XSS KENNETH LEE PRODUCT SECURITY ENGINEER, ETSY INC. Crosssite scripting attacks have always been a mainstay of the OWASP Top 10 list. The problem with detecting XSS is that you can't go looking at web log traffic to determine if a request contains an actual cross site scripting attack attempt, much less one that will actually succeed against your defenses. Our work has helped reveal some nuances with implementing....
|
|
James Denaro - How to Disclose or Sell an Exploit Without Getting in Trouble
-
www.defcon.org
-
12 years ago
-
eng
How to Disclose or Sell an Exploit Without Getting in Trouble JAMES DENARO PARTNER, CIPHERLAW You have identified a vulnerability and may have developed an exploit. What should you do with it? You might consider going to the vendor, blogging about it, or selling it. There are risks in each of these options. This 20-minute session will cover the legal risks to security researchers involved in publishing or selling information that detail....
|
|
James Denaro - How to Disclose or Sell an Exploit Without Getting in Trouble
-
media.defcon.org
-
12 years ago
-
eng
How to Disclose or Sell an Exploit Without Getting in Trouble JAMES DENARO PARTNER, CIPHERLAW You have identified a vulnerability and may have developed an exploit. What should you do with it? You might consider going to the vendor, blogging about it, or selling it. There are risks in each of these options. This 20-minute session will cover the legal risks to security researchers involved in publishing or selling information that detail....
|
|
Panel - Key Decoding and Duplication Attacks for the Schlage Primus High-Security Lock
-
www.defcon.org
-
12 years ago
-
eng
Key Decoding and Duplication Attacks for the Schlage Primus High-Security Lock DAVID LAWRENCE STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY ERIC VAN ALBERT STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY ROBERT JOHNSON STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY The Schlage Primus is one of the most common high-security locks in the United States. We reverse-engineered the operation of this lock, constructed a parameterized 3d mo....
|
|
Panel - Key Decoding and Duplication Attacks for the Schlage Primus High-Security Lock
-
media.defcon.org
-
12 years ago
-
eng
Key Decoding and Duplication Attacks for the Schlage Primus High-Security Lock DAVID LAWRENCE STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY ERIC VAN ALBERT STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY ROBERT JOHNSON STUDENT, MASSACHUSETTS INSTITUTE OF TECHNOLOGY The Schlage Primus is one of the most common high-security locks in the United States. We reverse-engineered the operation of this lock, constructed a parameterized 3d mo....
|
DEF CON Comedy Jam Part VI, Return of the Fail DAVID MORTMAN CHIEF SECURITY ARCHITECT, ENSTRATIUS RICH MOGULL ANALYST & CEO, SECUROSIS CHRIS HOFF RATIONAL SECURITY DAVE MAYNOR ERRATA LARRY PESCE PAULDOTCOM.COM ENERNEX JAMES ARLEN LIQUIDMATRIX / LEVIATHAN SECURITY ROB GRAHAM ERRATA ALEX ROTHMAN SHOSTACK, ESQ. You know you can't stay away! The most talked about panel at DEF CON! More FAIL than you can shake a stick at. Come ....
|
DEF CON Comedy Jam Part VI, Return of the Fail DAVID MORTMAN CHIEF SECURITY ARCHITECT, ENSTRATIUS RICH MOGULL ANALYST & CEO, SECUROSIS CHRIS HOFF RATIONAL SECURITY DAVE MAYNOR ERRATA LARRY PESCE PAULDOTCOM.COM ENERNEX JAMES ARLEN LIQUIDMATRIX / LEVIATHAN SECURITY ROB GRAHAM ERRATA ALEX ROTHMAN SHOSTACK, ESQ. You know you can't stay away! The most talked about panel at DEF CON! More FAIL than you can shake a stick at. Come ....
|
|
Brandon Wiley - Defeating Internet Censorship with Dust, the Polymorphic Protocol Engine
-
media.defcon.org
-
12 years ago
-
eng
Defeating Internet Censorship with Dust, the Polymorphic Protocol Engine BRANDON WILEY RESEARCHER, STEP THREE: PROFIT! The greatest danger to free speech on the Internet today is filtering of traffic using protocol fingerprinting. Protocols such as SSL, Tor, BitTorrent, and VPNs are being summarily blocked, regardless of their legal and ethical uses. Fortunately, it is possible to bypass this filtering by reencoding traffic into a form ....
|
Prowling Peer-to-Peer Botnets After Dark TILLMANN WERNER CROWDSTRIKE, INC. Peer-to-peer botnets have become the backbone of the cybercrime ecosystem. Due to their distributed nature, they are more difficult to understand and contain than traditional botnets. To combat this problem, we have developed the open-source framework *prowler* for peer-to-peer botnet tracking and node enumeration. It combines efficient crawling strategies with t....
|
|
Christopher Soghoian - Backdoors, Government Hacking and The Next Crypto Wars
-
media.defcon.org
-
12 years ago
-
eng
Backdoors, Government Hacking and The Next Crypto Wars CHRISTOPHER SOGHOIAN PRINCIPAL TECHNOLOGIST, PRIVACY & TECHNOLOGY PROJECT, ACLU The FBI claims it is going dark. Encryption technologies have finally been deployed by software companies, and critically, enabled by default, such that emails are flowing over HTTPS, and disk encryption is now frequently used. Friendly telcos, who were once a one-stop-shop for surveillance can no longer....
|