There are reasons for stupid anti-spam policies

Every so often, people do silly things in the name of anti-spamwork. While we can curse the creators of stupid polices like 'sendnotification email to the envelope origin address of mail scored asspam' as idiots, people aren't really, and I think it is more fruitfulto consider why such policies get created.

(There is a university subdomain in Texas that does this. Really.When we started getting these notices, I almost wrote them a verygrumpy letter asking what sort of idiots


Check then use is a dangerous security pattern

A commentator here recently noted the danger ofthe Unix pattern of stat()'ing a filename, checking to see if the statresults look good, and then open()'ing the file. The problem is thatin many cases an attacker can change what the filename is pointing tobetween the time you stat() it and when you open() it, so that youcheck a harmless thing but open a dangerous thing.

In thinking about this, I came to realize that this is an example


四個男人、兩個世代、兩個地方,策略的奉獻,真情的對話。

遊遊牧.圍圍評 ──藝術評論發展計劃 2007 座談會
四個男人、兩個世代、兩個地方,策略的奉獻,真情的對話。

也斯、呂大樂及來自台灣的 孫隆基、 李明璁等將於明天12月14及後天15日舉行的 「 遊遊牧.圍圍評──藝

努力偷懶(關島之行之二)

Sheraton Laguna Guam是偏遠了點,但如果像我用巴士代步,也很方便的


Continue reading...

Doing one-shot booting with GRUB

For a long time, one of the advantages of LILO over GRUB was that LILO had a one-shot mode, where it would make an entry thedefault for only one reboot. I've been pleased to recently discover thatGRUB can now do this too, although in the grand Linux tradition it's nottoo documented.

The magic incantation is the GRUB shell command:

savedefault --default= --once

(This has to be issued in a GRUB shell, such as what you


鬼哭

本文原刊於明報,世紀版,題目為編輯所擬,感謝。

中大異議者.無家的鬼魂

瞬息泛過交錯的日光
消逝在風裏
我兩手扶着欄杆外望
一串又一串的泡影從眼前閃過
那棵樹正悲壯地脫落高舉的葉子
——楊牧,〈學院之樹〉

想 起中大,

給從link過來的朋友

對不起,忍不住想說一句:

如果有人敢說 情如天 萬里廣闊/ 仇如海 百般洶湧/ 要共對亦難 分也不可 愛恨填胸」(黃霑〈倚天屠龍記〉)和「刀劍若夢 恩怨似風 有沒有輕重/ 只要情濃 不要武功 愛恨兩難容」(林夕〈刀劍若夢〉)

Implicit generalized open()'s are dangerous

A number of languages have open() functions that are generalized bydefault; they open more than plain files, sometimes far more. Suchfunctions are dangerous bear traps lying in wait for the unwary andinsufficiently paranoid, because what the programmer thinks is a simplefile open may be something very different and more dangerous. Inturn, this means that all an attacker needs to do is find some way to supply a 'file name' that your programwill try to open.

There's two core problems: the


A more abstract view of the generalized open() issue

Part of the generalized open() problem is thatsuch generalized open() s silently cross what I will call 'securitycontexts'. Here a security context is both what you can do and wherethe data is coming from; read versus write versus run a pipe, localfiles versus remote URLs, and so on.

When something is security sensitive (and open() is here), it shouldeither be explicit about what security context it is operating in,or it should at least be explicit about the


Come, sweet death

kaworu

渚薰又再一次死在碇真嗣手上。

在電視版裏,渚薰是個很特別的角色:他只出現一集,但卻是最受歡迎的角色之一。他的對白不多,但句句都似乎很高深莫測。他是朋友,但也是敵人。他的樣子斯文而瘦削,但卻能使用強大的ATF