|
|
This topic comprises 3 pages: 1 2 3
|
|
Author
|
Topic: Windows 7 ??
|
Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001
|
posted 09-26-2014 10:48 AM
quote: Marcel Birgelen Even without having read the article, I do know that just recording someone without having their explicit consent can lead into trouble.
In the United States it depends on where the person is being recorded and how the video is used. People are entitled to privacy in their homes and work places. But they can't really do much about being recorded in public. If you're taking pictures/video of someone for commercial purposes you really need to get a signed release. If you're recording evidence of some jackass valet joyriding in your car the valet doesn't have any room to gripe.
quote: Marcel Birgelen Nowadays, it's not just your computer and mobile phone, but also your car, your "connected fridge", your TV and whatnot are becoming interesting targets for digital abuse.
There is a funny device that will let you hack a Google Chromecast device and Rickroll the HDTV set on which it is attached. :-P I don't know if Google has patched that security hole yet.
quote: Marcel Birgelen Yes, you can turn it off for any Windows version up until now, but you're a total douche if you never install updates.
I'll second that, but I'm actually pretty suspicious of Terry's comment, thinking it's probably bullshit. Windows 8 will pester you if you don't have automatic updates enabled and if there's any updates you haven't installed. I waited a few months after Win 8.1 was released before finally installing it. The computer would remind me at least once a day the free update was available. I waited for a slow work day before installing the update, which involved a download over 3 Gigabytes in size and an installation process almost as long as a factory reset. Win 8.1 has been an improvement over 8.0, but I have a feeling Win 9.0 will sell quite a bit better.
quote: Marcel Birgelen Yes, Firefox adapted roughly the same update scheme as Chrome. Personally, I find those version numbers somewhat ridiculous, but the old "waterfall" model of development is out those days, it's all about "frequent delivery" and "short release cycles". While this might fly with web-applications, it doesn't work for stuff that actually needs an install base on any device.
Another downside to the frequent updates to Chrome and Firefox: the updates can break compatibility with various browser add-ons. Some of those add-ons are coded by only one or two people and they're making little if any money with the effort. Sometimes a handy browser plug-in will just end up breaking and never getting updated. I've lost a couple Adobe Illustrator plug-ins over this same kind of situation.
quote: Marcel Birgelen Also, both Adobe and Oracle deserve to be punished for their evil tactics of trying to push some stupid toolbar or "free antivirus" down your throat with updates for Flash and Java...
It's all about making money with advertising.
| IP: Logged
|
|
Marcel Birgelen
Film God
Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012
|
posted 09-26-2014 12:48 PM
quote: Bobby Henderson In the United States it depends on where the person is being recorded and how the video is used. People are entitled to privacy in their homes and work places. But they can't really do much about being recorded in public. If you're taking pictures/video of someone for commercial purposes you really need to get a signed release. If you're recording evidence of some jackass valet joyriding in your car the valet doesn't have any room to gripe.
The situation isn't very different here, although stuff obviously differs a bit from country to country... I'm not sure what the situation on the valet is though, since this guy/girl is doing his job at that moment. There might be a whole bunch of other rules applying for those situations. While it's not entirely prohibited to film workers during their job, there are still some privacy regulations at work, like limited access to the recorded material, etc.
quote: Bobby Henderson There is a funny device that will let you hack a Google Chromecast device and Rickroll the HDTV set on which it is attached. :-P I don't know if Google has patched that security hole yet.
Yeah, I've heard about it. It was done with a RaspberryPi that tricked the Chromecast to connect to a temporary WiFi network. A great example of how easily exploitable a lot of those connected devices are. I guess it takes a few really serious incidents before people realize the potential implications of all those interconnected, badly protected devices.
quote: Bobby Henderson Win 8.1 has been an improvement over 8.0, but I have a feeling Win 9.0 will sell quite a bit better.
For me, Windows 8.0 was totally unworkable. My girlfriend almost catapulted her computer out of the window after I updated her notebook. I've seen hordes of people just staring at their screen, not knowing what to do. Yeah, it was really a great strategy, forcing a touch-screen interface with a zombie desktop mode onto desktops .
Windows 8.1, although being a bulky, awkward update (which often failed to appear in this dreaded Windows Store), restores some of the lost functionality, so it's almost not worthless.
Windows 9.0 looks promising... after one failed attempt at a fundamental UI change, we're more or less back where it came from.
quote: Bobby Henderson Another downside to the frequent updates to Chrome and Firefox: the updates can break compatibility with various browser add-ons. Some of those add-ons are coded by only one or two people and they're making little if any money with the effort. Sometimes a handy browser plug-in will just end up breaking and never getting updated. I've lost a couple Adobe Illustrator plug-ins over this same kind of situation.
Well, that's another consequence of this "If it breaks, we'll fix it in the next update... maybe" mentality: unstable APIs, leading to compatibility issues with stuff that needs to interface with other stuff. And indeed, if you're depending on some plugins or other software by some one-man developer team, you're often out of luck.
quote: Bobby Henderson It's all about making money with advertising.
Yeah, but do Oracle and Adobe really need those few bucks they're making on this? For me it's more a sign of acknowledgement that those technologies are dying... Because it's totally counterproductive to the purpose. Many people I know have entirely removed Java, just because those frequent updates, always trying to peddle some new spyware. The same goes for Flash those days. Although the web is still somewhat "defective" without a working Flash plugin, they're doing their utmost best to destroy the value that's left in the technology. It's like those companies have already written off those technologies and have decided to squeeze the last few dollars out of it via those nasty tactics.
| IP: Logged
|
|
Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001
|
posted 09-26-2014 02:21 PM
quote: Marcel Birgelen Yeah, I've heard about it. It was done with a RaspberryPi that tricked the Chromecast to connect to a temporary WiFi network. A great example of how easily exploitable a lot of those connected devices are. I guess it takes a few really serious incidents before people realize the potential implications of all those interconnected, badly protected devices.
I think it's going to take a really horrible incident of computer based crime to make all involved take security as seriously as they should. It may take a bunch of people getting killed or a successful company being financially imploded for the right steps to be taken.
One of the chief problems is unaudited code from many different sources. Every major computing company is mixing their own in-house developed code with stuff from the open source community. Yet they're providing hardly any funding at all to the open source community. Even Apple and Microsoft are inserting open source code into their stuff. Open source coders are driven by passion instead of dollars, but they often don't have the passion of going back to painstakingly audit code and fix any holes they find. Software engineers come and go, hopping from one job to the next. Some leave on bad terms, holding grudges and perhaps even plotting revenge. Companies are out-sourcing a lot of programming work, trying to make it cheaper and drive up the company's stock price.
It shouldn't be a surprise to anyone when a serious flaw is discovered. We're used to "Patch Tuesday" when it comes to Windows since it is by far the biggest target of black hats.
Heartbleed was a huge problem last year, targeting OpenSSL. Businesses are still recovering from that one. This week a new threat, dubbed "Shellshock" was discovered. And it could be a potentially bigger problem than Heartbleed. The actual security hole is over 30 years old. It's in a command line shell for UNIX called Bash or Bourne Again Shell. The hole is in Mac OS and various flavors of Linux. Patches are already available for Cent OS, Debian and Ubuntu. Apple hasn't said when a patch will be availble for OSX. The Apache server is vulnerable to the Bash bug, which is a huge problem since over 50% of active websites run on it. I wonder if my Android phone is vulnerable.
quote: For me, Windows 8.0 was totally unworkable. My girlfriend almost catapulted her computer out of the window after I updated her notebook. I've seen hordes of people just staring at their screen, not knowing what to do. Yeah, it was really a great strategy, forcing a touch-screen interface with a zombie desktop mode onto desktops [Wink] .
Windows 8.1, although being a bulky, awkward update (which often failed to appear in this dreaded Windows Store), restores some of the lost functionality, so it's almost not worthless.
My experience with Win 8 hasn't been as bad as yours. For me it's pretty similar to Windows 7 once you hop past that stupid tiled front end into the desktop. When I log into my work PC I just click the Windows key to toggle past "metro." I stay in the desktop side of Win 8 the rest of the day. Lots of people don't like memorizing keyboard short cuts, which Win 8 forced on users. I didn't mind that so much since it's already necessary (or at least far more productive) in graphics work. Win 8.1 has made that a little easier.
My biggest gripe with Win 8 is all the legacy software it broke, which made it necessary to buy a lot of new software with new computing hardware.
quote: Marcel Birgelen Yeah, but do Oracle and Adobe really need those few bucks they're making on this? For me it's more a sign of acknowledgement that those technologies are dying... Because it's totally counterproductive to the purpose.
It's extra bucks for them to pad their bottom line and make the quarterly report look better. The practice is widespread.
Most Windows-based PCs are pre-loaded with tons of crap-ware to subsidize the low price of that computer. This is one of the main reasons why a Mac or a Dell from their business side costs so much more money. Lots of smart phones are pre-loaded with crap-ware for the same reasons, either to lower the cost of the phone or improve the phone carrier's profit margin. It doesn't have anything to do with an application's popularity rising or falling.
| IP: Logged
|
|
|
|
Frank Cox
Film God

Posts: 2234
From: Melville Saskatchewan Canada
Registered: Apr 2011
|
posted 09-27-2014 04:06 PM
quote: Bobby Henderson The Apache server is vulnerable to the Bash bug, which is a huge problem since over 50% of active websites run on it.
Sort of. For this to be exploited, bash needs to be spawned by an internet facing service and pass environmental variables into a bash shell. Shell scripts under Apache's cgi-bin that call bash are vulnerable, but that's not all webservers or internet-enabled services by any means.
This doesn't just affect webservers, though. dhclient on my computer (Centos 7) runs shell scripts in /etc/dchp/dhclient.d, which could create an "interesting" interaction if it encountered a rogue dhcp server, for example.
quote: Bobby Henderson I wonder if my Android phone is vulnerable.
Non-rooted Android devices don't come with bash, as far as I know. Cyanogen and Cydia do come with an apparently vulnerable version of bash.
I have on my non-rooted Android phone an app called Terminal IDE that contains a great number of cool things including, unsurprisingly, a terminal. The terminal included is bash version 2.2.0(2) -- yes that is a vulnerable version of bash.
Perhaps some other Android apps come with bash, as well. It depends on what you have installed on your phone.
Here is an excellent write-up that explains how this bug works: Shellshock: How does it actually work?
| IP: Logged
|
|
Dave Macaulay
Film God

Posts: 2321
From: Toronto, Canada
Registered: Apr 2001
|
posted 09-27-2014 04:22 PM
The Microsoft update cycle of once a month "Patch Tuesday" isn't too bad. I haven't been hurt by these updates in maybe 3 years. They do, rarely, push some critical updates out-of-cycle when a bug is being exploited by malware. It's mad to disable updates. If you ever connect to the internet, you're at risk. "Honeypot" unpatched systems deliberately connected to the internet tend to be "pwned" within minutes. If you look at active malware exploits like "cryptolocker", they use known bugs that have were in updates months ago: they prey on systems that haven't been updated. For a computer working alone or on an isolated network with no ability for outsiders to connect to it, updates can be ignored. Such systems are rather rare these days. Business critical systems should be secured behind a proper firewall and have necessary updates fully tested before installation to avoid severe issues, there have been stories of major businesses having long service outages because of updates that break core utilities. You should run something like Qualsys Browser Check periodically to confirm all plugins are current. I agree that updates (hello, Adobe!) should NOT have opt-out crap like Chrome or "helper" toolbars included in the update process. This stuff is generally only with free software though, so I cut them some slack. So far, the only problem I've run across is with Java, current versions won't run unsigned applets. The old Jnior web interface was suddenly unavailable: a Jnior firmware upgrade can fix that (but... should you upgrade a working Jnior and maybe break it?) and the interface will still run from the support tool... but the problem was unexpected and frustrating. I don't know what other equipment with Java powered interfaces will be broken: I have found no way to make an unsigned applet run.
| IP: Logged
|
|
Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001
|
posted 09-27-2014 06:17 PM
quote: Monte L Fullmer Time for users to switch to Linux - Ubuntu 10.4, or Mint Cinnamon.
If only switching computing platforms was easy.
With the applications I run the only choices I have are Windows and Mac OSX. This is mostly due to Adobe's Creative Suite/Creative Cloud applications. I don't want to attempt emulating them in a non-native OS environment. The applications are making direct use of the graphics card GPU to accelerate renders and previews. At best, the applications would run slowly emulated in Linux. At worst, they wouldn't run at all. I doubt the Creative Cloud front end could work at all under emulation. I sure don't see "live" CC services like Typekit working. Simply put, you have to be using a Mac or PC to run Adobe Creative Cloud.
There is a vocal crowd of Linux supporters campaigning for Adobe to release a Linux-native version of Creative Cloud, but they're not getting anywhere with it. The user base just isn't large enough to support the development costs.
Even going from Windows to OSX would be a painful switch for me. Some of my applications are available only on Windows. CorelDRAW is an important one I've used for over 20 years. There's no version of it for OSX, despite many requests. I have quite a few Windows-based Postscript Type 1 fonts. I would need to make Mac-based conversions if I wanted to use any of them in OSX. That could be tedious.
And then there's all the archived files, many of which are best opened in their native applications rather than imported into another. This is a key reason why I use both CorelDRAW and Adobe Illustrator. They have their own specific strengths and shortcomings. Neither is perfect at importing artwork from the other, which can be a problem when dealing with customer provided files.
quote: Frank Cox Perhaps some other Android apps come with bash, as well. It depends on what you have installed on your phone.
My phone isn't rooted and it may not be affected by Shellshock. I think most Android phones are infected with malware via mistakes made by their users. They ignorantly load software from other places outside Google's Play store, sometimes with the aim of getting pirated content, be it applications, music or whatever. It's kind of similar to what happens on a lot of Windows PCs.
| IP: Logged
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
All times are Central (GMT -6:00)
|
This topic comprises 3 pages: 1 2 3
|
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2
The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion
and agrees to release the authors from any and all liability.
|