What certification process? Driver signing does not need a WHQL certification and in fact, Microsoft isn't involved in the driver signing process at all. It's between you and whichever CA you choose to do your code signing.
The bigger question is how exactly does Rand Paul and his constituents benefit from this?
I'd like that question answered before I supported such a bill.
Make no mistake, the rights of the poor and disenfranchised (as noted regarding civil forfeiture in another comment on this post) has rarely been a reason for Congress to move, and most of the time when governments move for it they are working against those people. No matter where on the spectrum those people lie.
So can anyone come up with a scenario as to why Rand Paul would bother with this?
The following is true about the implementation of DNSSEC in Windows.
* You can require DNSSEC validation to happen at both the server and the client. (via GPO)
* Windows DNS does not automatically trust the root signing keys. Though these are there for convenience, if you have a specific-purpose for DNSSEC, you do not need to trust the roots. You can create anchor points for any individual domain or TLD you wish.
* While Windows clients do not perform validated resolution themselves (they rely on configured DNS Servers to perform validation), Microsoft recommends you utilize IPSEC within your LAN to validate client -> DNS Server resolution.
With all of the above, you protect all MITM attacks for specific target domains of your choosing. You can even do DNSSEC trust anchor updates by signing the KSKs with the previous KSKs (RFC 5011)
By trusting only the keys you wish and by trusting your LAN/Layer 2 access to your DNS Server, DNSSEC provides more than enough capability to prevent MITM attacks, domain redirections, etc.
Quite a few people I know would prefer to travel on an American passport because it offers less hassle than most other passports. We have fewer VISA requirements, etc.
We have somewhat shot ourselves in the foot here or there since we tightened travel restrictions on some countries. But it's still an incredibly good passport to have for traveling.
I've been strongly considering expatriating, either to Canada or even more exotic locations such as Dubai/UAE. I have no real intentions of breaking from the US as a citizen, but perhaps you could clarify for me.
1. I've heard that under a certain tax bracket this does not happen. Is that true?
2. I hear Canada will actually let you write off taxes you've paid to the US.
99% of the time the people are not "talking shit about you". Why this is a very common thought in the US is beyond me. Perhaps fear?
I learned enough Spanish to understand a few conversations here or there, or to get the gist of what they are saying. Newsflash: They're BSing about stuff like you or I would in English.
Forcing people to speak English when it is a 2nd language may actually hinder communication and team building. Perhaps something they may say could come out wrong because they don't understand the culture-specific constructs of what is or isn't appropriate.
In my former paragraph, I'm not stating that they are saying things that would otherwise be universally wrong to discuss in any language (racism, etc.) but more along the lines of word choice that may be inappropriate in a particular culture but perfectly fine in another.
The most obvious that comes to mind is the French (Quebec) word, "maudit". Literally translated, this is usually translated to "damn" (damn cat, damn dog, etc.) But they use it far more openly than we do here in the states. It's not appropriate in large work meetings and public forums to use the word. However, at the Musee de la Civilization in Quebec City; "maudit hiver" is on a sign and the literally translated statement, "damn winter" sits beneath it.
This sort of thing happens a lot amongst polyglots and people. The reality is that 'fluency' is never truly fluent, but usually close enough for every day interaction.
Firstly, how does he know the style sheet is conforming to the standard? He made no mention not comparison of this.
And "IE being listed in updates" has been the same for years. There is absolutely nothing new about that behavior and I'm pretty sure it goes back to at least Vista, if not XP.
What would you 'avoid' it with? Grow your own food? In poisoned soil? What if you lived on extremely fertile ground but didn't have the time nor resources to support yourself?
It's amazing at how so many people in the first world have absolutely no clue the kinds of things that go on in developing nations. Bribery, extortion, violence, genocide, and murder all exist in these regions over basic items (even that coffee that you drink every morning and cry about because the company you work for doesn't have the good stuff!).
Could you describe some of these things? You don't have to be detailed, obviously; but is there anything that sticks out? Development processes were off? Requirements too crazy?
The interesting problem with "cyber security" in this country is that the field generally sucks, same with IT. The large problem is that none of it has bite.
I work for a company that contracts for the US gov. I can tell you right now that the government has its shit together. They have some very strict requirements which SHOULD be inherent knowledge to all IT organizations but it is not. The field is largely thankless. As long as people on the "business side" continue to get in the way nobody's going to want to stick around long. And on top of that you want to underpay them?
If the government wanted to crack down on security they would audit all of their contractors and drop contracts if they were out of compliance. Te business types have yet to experience this so it's not well known in the circles yet.
- UDP datagrams with an invalid source address cannot be sent over raw sockets. The IP source address for any outgoing UDP datagram must exist on a network interface or the datagram is dropped. This change was made to limit the ability of malicious code to create distributed denial-of-service attacks and limits the ability to send spoofed packets (TCP/IP packets with a forged source IP address).
- A call to the bind function with a raw socket for the IPPROTO_TCP protocol is not allowed. Note: The bind function with a raw socket is allowed for other protocols (IPPROTO_IP, IPPROTO_UDP, or IPPROTO_SCTP, for example).
Also, the "half open connections" limit has been removed as of Vista.
Just as an FYI to the right wing nuts here, I actively voted for Obama knowing that internet rights would be an uphill battle. I followed Biden's tech trends over the years and knew going into it that this would be a significant challenge.
So no, I didn't go into it "blindly", and I didn't follow all this "hype" about "change". I knew what I was getting into by voting for those two.
That said, the combination of other stances and policies led me to vote for them--and so far they haven't disappointed me.
Also remember: SOPA is in a House Committee. Keep this in mind before bashing the President and VP.
Yeah, he lost me when he said "JUST CHANGE JOBS!" haha.
It's easy when you've been handed everything in life and the best you work for is a measily odd job here or there, but that's not doable when you're in a specialized field with a career path.
Guess it's okay for the free floater, but not so much when you've planned out your path years in advance.
Though I haven't read this specific bill, the philosophical point of having to collect sales tax in some form is a necessity. The money ultimately has to come from somewhere. Regardless of your views on income taxation, very few people would argue AGAINST a consumption tax (unless you're either brilliant or crazy).
Much like the fast movement of our economic system and the rise of "corporations", the rise of the internet has outpaced our government's ability to operate. This is painfully true when it comes to collecting taxes.
Honestly, at this point, a National Sales Tax would probably be one of the better things for our country, as much as people hate it--it works.
I think quite a few people are missing the point of this feature.
This feature is not to 100% fully secure "OMFG" protect your account. This isn't like some super secret government code sort of deal.
The idea is that your e-mail account does not get compromised when a company's database gets hacked.
The point of the unique, application-specific passwords isn't to "lower the security of your account", but it's to prevent someone from using a database leak to logging into your g-mail because YOU SHOULD NOT USE THESE CODES FOR ANYTHING OTHER THAN THE SPECIFIC APP.
Yes, someone can get that password and enter your g-mail account. But the point is that you're not using this to log in to your Paypal, your Xbox Live, your PSN, or your Hacker News account.