Thesis: reputation based antispam systems are dead
It recently struck me that one of the things that the universitywebmail phish attacks demonstrate is thatreputation based antispam systems are now dead. The university webmailattacks aren't just a few previously good sources going bad, which hashappened before; they're a systemic, broad attack on a whole class ofsystems that previously had a good to great 'spam reputation'.
(Well, this exaggerates the situation somewhat. There are two aspects ofreputation based antispam systems; you can attempt to blacklist placesthat are
The advantages of iSCSI's MC/S for multipathing
In theory, iSCSI has a feature called 'multiple connections persession', commonly abbreviated as MC/S. In iSCSI terminology, a'session' is a single logical connection between an iSCSI initiator andan iSCSI target, and a 'connection' is a TCP connection. MC/S lets asession be composed of multiple TCP connections, each of which can use adifferent set of IP addresses and thus a different network path.
(In practice, apparently very few iSCSI initiators and targets actuallysupport MC/
事先張揚超負面報道事件
上星期五到了西九龍做halloween活動嗎,我們俗稱的“大圍”記者均有到場采訪,通常活動完了,記者們會向每位嘉賓補訪問,訪完就大家收工。
不過那天大圍訪問過後就有FACE的記
More on Firefox 3's handling of self-signed SSL certificates
One of my blogging flaws is that when I write up an entry, I can be soclose to the issue that I leave important things out because they are'obvious' to me. I did that with my recent entry about Firefox 3's handling of self-signed SSL certificates: I skippeddescribing exactly what makes Firefox 3's approach so wrong.
Firefox 3 is not wrong-headed for being cautious about self-signed SSLcertificates, because there are real concerns with them in practice. Firefox 3
Bollywood的危機
近年印度勢力逐漸入侵美國. 先是Sony Pictures 負責替《Sawaariya》海外發行, Steven Spielberg旗下的夢工場(DreamWorks)的真人電影部, 也得到印度公司的金錢資助, 脫離開派拉蒙(Paramount)自立. 而印度電影界與外國電影製作單位的合作愈來愈活躍: Rambo和加州州
次次執二攤?
How self-signed certificates are a problem for browsers
I was a little harsh on Firefox 3's handling of self-signed SSLcertificates in the last entry , and in fairness Ineed to say that this is a genuinely hard problem for browsers, at leastfrom a security perspective. Let us talk about just how this is so.
First, let us start with my previous basic model of how https could work. Browsers always use SSL if possible, and theyprotect against straightforward man in the middle attacks by rememberingthe SSL certificate they saw last time, or