back
user profile
Tomte
162,201karma·32,335submissions·August 23, 2012
about
Open Source Compliance, Functional Safety, Education Science.
[ my public key: https://keybase.io/2uo; my proof: https://keybase.io/2uo/sigs/3Nc5FGsaD-8qFEmS8FvyXv9aA3sAS6hx29MBPq8g6EA ]
recent activity (32,335 total)
comment
But that whole argument depends on the status quo in the US: many poor don't have ID cards already. If you shift your view to the situation in other countries, it's easily answered: (almost)…
comment
You usually register at the town's "citizen's office", where you can also pay for your garbage disposal, get parking passes, apply for your driver's license, have the lost+fou…
comment
I think it's important to regularly point these issues out, because even though many of "us" intellectually know about them, it's still hard to emotionally grasp for "us"…
comment
People have names. I find that digit in the mail address that clearly consists of a name deeply degrading. There are other ways to solve collisions: j.doe@, j_doe@, maybew one of those has a second gi…
comment
The worst I have seen was at a former employer. We had two people with the name "John Doe", and the mail scheme at the company resulted in john.doe@company.invalid. The second one got... joh…
comment
If you accept the premise of an efficient market (as most index investors probably do), then Fidelity's argument is bullshit. They say index funds have to follow the index, and -- in this concret…
comment
No, the court did not rule anything (although it probably will). The Advocate General at the court entered his plea, which the court usually follows.
comment
I think you're right. I probably channeled him inadvertently. I've collected lots of links to articles and man pages and so on about the issue, because I have been planning to write a cohere…
comment
Yeah, I see it the same way. but at least you can put forward a highly theoretic argument there that just doesn't work with all the crypto algorithms we actually use. Especially since: what are y…
comment
Good points. First, I'm not saying that cryptographic randomness can be created out of thin air, without entropy, I just argue that you don't need n bits of real entropy to get n bits of hig…
comment
I'm sorry, but this meme is flat-out wrong. /dev/urandom gives the exact same quality randomness as /dev/random (let's ignore the issue of boot-time and VM cloning for no…
comment
Meeting a sysadmin of your mail provider at some real-life net gathering, wearing the "I read your mail" shirt really was a bit unsettling...
comment
German Usenet was and still is (in)famous for demanding real names. In the late nineties and early 00s there ware huge wars between those who campaigned for pseudonyms (usually labelled "net terr…
comment
I always have to remember myself that it's Gauck now. Pity that Köhler resigned. He was a good guy, but no real politician. All in all we've been lucky with our presidents. Von Weizsäcker, R…
comment
Why should he? He actually recommends to write passwords down on paper. And for most attack scenarios for the private user, "a logbook on the desk next to the computer" isn't a big diff…
comment
That happens when you publicly shame and demonize your core contributors. Joyent has royally fucked up there, and if I was buying services from them, I'd have stopped now. They didn't have t…
comment
Many of those "problems" really don't seem to exist in Germany. I guess part of it stems from the common law system, but I'm not sure.
comment
It's not exactly a monopoly You can buy it from ANSI or BSI, as well. If you don't insist on the German language version (even then, the Austrians probably have another version). Remember th…
comment
The law references the standard(s), but only as optional. See the link to the English translation of the Product Safety Act that I posted in another comment. Article 4 is relevant.
comment
Doesn't change your argument (I think), but please note that the standards in question are neither "US" nor "EU". They are International Standards (ISO, IEC) that just get rep…
comment
Ask those who work in fields that don't have a harmonized standard at their disposal.
comment
Emphatically no. First, the Directive itself is not the issue here, the harmonized standards are. Please don't mix it up. Nobody would sue for copying the text of the Directive. And second, it…
comment
Look, I know, EU "law" is difficult. I happen to have a little bit of knowledge about that, because I work on safety-related systems in industrial automation, where the same legal mechanisms…
comment
I know, you're enraged, but truthfulness is still not optional. The defendant did not "make the law available for free", he (allegedly) distributed a copyrighted standards text. Which i…
comment
Actually my impression is that many many user space programs use /dev/random, even for short term keys and nonces and stuff, just because they have learned by "more experienced Linux us…
comment
If one of those ciphers is completely broken, so that can be decrypted as easily as ROT13, correct?
comment
But he is putting innocents at risk. That's why in my jurisdiction you can get fined up to 2000 Euros for that (a realistic amount is a low double-digit amount -- if nothing further happens, of c…
comment
Someone would probably notice, checking the DVD against a checksum. Repackaging it seems to be tricky, since the paper inlay is bound in the magazine, it's not just stuck on the cover or whatever…