Web DOS Attack

A hash collision vulnerability exists in a number of frameworks, including PHP, Ruby, and ASP.NET.  Microsoft has released a patch to fix ASP.NET.

Rafael Rivera criticizes the relatively short amount of time before full disclosure and links to a cutesy Microsoft video on the topic.  My problem with the video is that, although some companies are in fact responsive to security vulnerabilities (and Microsoft has become that way, after its years in the embarrassing security flaw wilderness), there are enough developers and organizations which will simply ignore a problem until the press gets bad enough or the flaw gets exposed in the wild through exploitation.  Full disclosure is a shotgun-blast approach, but that doesn’t necessarily make it wrong, especially when the company basically ignores you after you make your report.


EPD: Duels And Ordeals

There are two chapters remaining in Extraordinary Popular Delusions and the Madness of Crowds.  This one is a relatively long chapter, and pertains to duels and ordeals.  Mackay, naturally, is opposed to dueling as a way of solving problems, considering it something animals do but civilized people don’t.

A while back, I brought up Pete Leeson’s paper on why trial by battle isn’t quite as crazy as it seems.  In addition, we should look at his defense of ordeals.  I rather doubt Mackay would have agreed with Leeson on the fundamental sanity of these practices, given legal codes and the difficulty of bring enough evidence to prove a case legitimately.  However, Mackay does agree with Leeson regarding a biased priesthood (which probably led to more justice than the alternative):  regarding one form of ordeal, Mackay writes, “Many true judgments were doubtless given, and, in all probability, most conscientiously; for we cannot but believe that the priests endeavoured beforehand to convince themselves by strict inquiry and a strict examination of the circumstances, whether the appellant were innocent or guilty, and that they took up the crossed or uncrossed stick accordingly” (650-651).

To sum up a relatively long chapter:  duelling is cruel and stupid; ordeals were pretty silly, and an obvious way for the Catholic Church to become arbiter of the law.  Noblemen didn’t like this, so they stuck to duels.  Thankfully, we’re a bit past both.

Top 10 Games I’ve Played for the First Time in 2011

Honorable mentions: Heavy Rain, God of War III, Uncharted 2, Magic: the Gathering: Duels of the Planeswalkers (PS 3), Hearts of Iron: Semper Fi and For the Motherland (PC)

10. Mass Effect (PC)

If I’d played this more — I got it as a birthday gift along with Mass Effect 2 — it would probably be higher, but it’s unfair to really judge a game without having played it more.

9. Supreme Ruler: Cold War (PC)

I’ve played it more than Mass Effect, but I’m still not comfortable moving it higher without playing more.

8. Portal (PC)

One of the very best PC games of all time. The puzzles are excellent, the AI is pretty entertaining.

7. Madden NFL ’12 (PS 3)

One of the best football games I’ve ever played. It’s still got a lot of room to grow, but it’s definitely a worthy addition to this list.

6. Spore (PC)

It’s, in reality, five games that are C+, B- at best (with the space stage a solid B), but they’re integrated in clever ways. I’d enjoy this more if not for crippling crashes from time to time.

5. WWE ’12 (PS 3)

I’m addicted to this game. The Road to Wrestlemania Mode is sub-par (particularly the second of the three stories), but everything else is so crisp and entertaining that it’s just amazing. WWE Universe Mode is pretty sweet, as always.

4. Sword of the Stars: Complete Collection (PC) 

I’ve received three free games this year, from winning contests and GameFly. This is not only the best of those three (the others being Dead Rising 2 and Darkest Hour), but it’s one of the most fun games I’ve ever played. I’ll include a proper review at some point once I’m a bit more familiar with the game.

3. Batman: Arkham City (PS 3)

Any other year, this is an easy #1. If I made it “Games that were developed in 2011”, it would be #2. Still, it’s an amazing game. It’s much, much better than Arkham Asylum, which is scary, because that game was hardly chopped liver. The open world format works really well; the actual world is a good bit smaller than, say, a GTA or Red Dead Redemption, but that makes sense. Batman is on foot (or on cape) most of the time, so he can’t be going too far.

2. Deus Ex: Human Revolution (PC)

I’ve called Deus Ex the best PC game of all time on a number of occasions. Human Revolution is a much better game, as far as controls, difficulty, etc., although the story isn’t quite as intriguing as the first one. I really can’t find a real fault with the game, apart from the tutorial videos having really bad audio (which was allegedly fixed). I’ve heard the DLC is somewhat underwhelming; I can’t confirm or deny that properly, but this game is so good that I’ll probably get it anyway.

And the #1 game of 2011 (that I played for the first time):

Continue reading

The Volt: Low-Wattage

An analysis is out stating that the Chevy Volt costs taxpayers a quarter million dollars per vehicle sold thus far.  That number is a little misleading in that they’re amortizing one-time expenditures, so it would go down over time as more vehicles are sold.  But then again, considering that the total number sold is well under 10,000, practically nothing short of a government mandate to purchase one of these would suffice.

This is why I expect Obamacare 2:  Electric Boogaloo to have a provision slipped in stating that every American be forced to purchase a Volt.  This is one of the advantages to a corporatist state:  at least you don’t need to make any of your own decisions; you can simply let our benevolent overlords do that for you.

The secret plan of the GOP: stop students from voting?

From the NY Times (got it from a Facebook link).

This is one of the stupidest articles I’ve ever read. First of all, they make it sound like getting a state issued ID is impossible. It isn’t! Hell, I had a passport before I had a driver’s license.

Second, they’ve made one of the dumbest logical errors you can possibly make: correlation does not imply causation! Compared to the rest of the population, students do tend to vote liberal, because most professors are liberal. That’s no secret and never has been. Yes, stricter ID laws would also make it slightly harder for some students to vote. Why? Because students are fundamentally lazy and many wouldn’t vote without getting paid or at least free beer as part of deal.

You know who I bet the real target of the legislation is? People for whom it’s much harder (or it should be) to get a state-issued ID: illegal immigrants. Remember, you can’t vote if you’re not an American citizen.