Skip to content
I T S S
  • Welcome
  • Hardware
  • Internet
  • Networking
  • Security
  • Data Recovery
  • Support
  • Contact
  • Webmail

A Nice Little Cryptography Primer

By itss | 28/06/2021
0 Comment

Pun Intended.

Category: Technology
Post navigation
← pfSense / Wireguard / Bad Code / Close Call Why Quake3 was so fast : Fast Inverse Square Root →

Recent Posts

  • Hardware Exploits?
  • Why Quake3 was so fast : Fast Inverse Square Root
  • A Nice Little Cryptography Primer
  • pfSense / Wireguard / Bad Code / Close Call
  • Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur)

Slashdot

News for nerds

  • AI's 'Creepy' Crawlers Criticized by Linux Foundation's IT Infrastructure Director
    by EditorDavid on 30/08/2026 at 10:38 pm

    The Linux Foundation's director of IT infrastructure says they now spend more CPU cycles "rendering commits for scrapers than we spend on all other kinds of legitimate access." At any one time, across 5 geo-distributed nodes, there are 14 CPU cores doing nothing but rendering git commits as html.... [W]hen a source is guaranteed to be LLM-free, like the entire history of kernel commits, it's worth its weight in gold as a source of training data... At the time of writing, linux.git is about 1.48 million commits. Oh, and we have about 922 forks of it on git.kernel.org — but don't worry, it's actually extremely efficient on the backend, since it's mostly the same objects in every fork. Unless, of course, you're a scraper, in which case you have, oh, several BILLION valid URLs you can scrape, only to get 922 duplicates of the same 1.48 million commits — which is exactly what the scrapers are doing. But wait, it's not just commits itself. You can also ask for patches, plain renders, diffs between arbitrary commits — cgit is happy to let you, which was perfect for the times when the Internet was for humans or crawlers who obeyed robots.txt, and is AWFUL right about now, because we can generate 1.2 METRIC BAJILLION valid URLs just for a single fork of linux.git. Initially, this was the solution — look through the logs, find out which IPs are obvious scraper bots, and fail2ban them. At first, this was easy, because the bots helpfully told you who they were via their user-agent. Then, they wised up and started pretending that they were random vanilla browsers. So, we started banning them by IP — after all, it's easy to figure out that an IP that is trying to grab every possible commit in a 8-year-old abandoned fork of linux is not really some lone Chrome on Windows user who is just furiously clicking every link that comes across their screen. The bots then started fanning out to entire subnets, but this was still meh, because obviously an IP coming from Google Compute is just pretending to be a Firefox user... And... that's when things turned really, really ugly. Suddenly, the crawlers were coming from millions of random residential or mobile IPs, all pretending to be random modern browsers. An IP like that would make 4-5 requests and then never show up in the logs again... They descended like swarms of locust, hit hard and fast until the system fell over and then moved on to the next target until you recovered. Then, they returned. Rinse. Repeat. They still do that — welcome to the wonderful world of "proxy SDK monetization." It's big business, and your TV is probably doing it... Today, git.kernel.org receives about 6M daily requests demanding to see random commits. Of these, 66% are still immediately batted away with the Anubis challenge, but 33% are now solving the math and getting through to the main site — because apparently what we have to offer is worth spending a ton of cycles to calculate the Anubis challenge... With a bunch of generous assumptions, legitimate requests are only about 2% of git.kernel.org traffic — everything else are scrapers... [W]e're turning off features to reduce the number of crawlable URLs and to gate off actions that are expensive for us to run. Expect to lose some functionality, at least when accessing our resources anonymously. Trust me, we hate it just as much as you, but at this point it's a necessity... [W]e promise to still offer all of our data for download to anyone who asks. You just may have to jump through more hoops to get it. Sorry. Read more of this story at Slashdot.

  • Chess.com Launches New Poker Site, Plans More Classic Game Sites with Player Ratings - Thanks to AI Protyping
    by EditorDavid on 30/08/2026 at 8:20 pm

    In May Chess.com "quietly launched" a free educational poker site named Gambit, reports The Verge, where players can learn the game and improve an Elo-like rating without risking real money. And next Chess.com will expand into more classic games, including go, backgammon, and mahjong: Like Gambit, Chess.com is developing Elo-style rating systems for these games, as well. [Chess.com's chief growth officer, Albert Cheng] didn't say when the new sites will launch but that "development is moving quite rapidly" on them, using the same playbook he used for Gambit... He and one other employee took Gambit from prototype to launch within a year, partly with help from AI, mainly for coding tasks. "I think the biggest advantage that it's provided is essentially being able to read our existing codebase and our design system and apply consistent patterns to how we develop Chess.com over to a different platform and do so quickly," Cheng said.... "Just because code is easier to write doesn't mean that you just let it run on its own, but it certainly is a superpower in getting things off the ground." Cheng also said the version of Gambit that's live at the time of writing has "zero or close to zero" AI-created assets, which were used in early prototypes. According to Cheng, without help from AI, getting another site up and running would have required a bigger team or "would have been a lot more disruptive to the status quo of building and growing Chess." Now that a "small, scrappy" team can get a new platform off the ground much faster, it's opened the door for Chess.com to dip into more games, starting with poker. The poker site already has 75,000 members, according to a blog post Friday — and they've already played nearly 20 million hands and completed 100,000 lessons. The site is now holding a daily poker tournament, and on Monday will broadcast the event with live commentary on their Twitch and YouTube channels. Read more of this story at Slashdot.

  • Google Maps Renamed Lake Ontario to 'Lake America' - But Only for U.S. Users
    by EditorDavid on 30/08/2026 at 6:53 pm

    It's already happened — at least on Google Maps. Google's online maps reflect name changes in official government sources, Google posted Saturday. So when the U.S. Geographic Names Information System formally changed the name for "Lake Ontario" to "Lake America," Google also renamed it "Lake America" — for visitors from the U.S. "Those in Canada will continue to see 'Lake Ontario'," Google said. And people from every other country in the world... "will see both names." Though here's how it will be written... Lake Ontario (Lake America) "These updates follow our long-standing policy for bodies of water with names that vary from country to country, and are starting to roll out now." Meanwhile, NPR reports that Ontario's Premier posted a billboard reading "Lake Ontario — Now and Always" on Canada's side of the lake (repeating the message in French). And The Daily Beast reports Google move has also drawn some criticism online: "Hey you gave one of the Great Lakes the wrong name; pretty embarrassing mistake so you might want to fix that," one user wrote on X... MapQuest has said it will not be changing the name, and instead launched a new tool that allows users to rename it themselves to whatever they want. Read more of this story at Slashdot.

  • Has Big Tech Captured America's Schools?
    by EditorDavid on 30/08/2026 at 5:39 pm

    America's public education system has become "an avenue for multitrillion-dollar companies to enact their agendas," argues a NewYork Times reporter who's covered that tech industry influence for over 10 years. Big tech companies "advocate for new laws to require schools to teach industry-aligned subjects. They sit on committees that help shape learning standards for public school students..." The reporter concludes that "Silicon Valley's efforts to capture the attention of education professionals and provide student training materials can also double as marketing or indoctrination." They enable some of the most powerful corporations on the planet to spin rosy technology stories for administrators, teachers and students, giving them a sanitized view of industry practices and product risks. Many parents would likely object if, say, Exxon Mobil wrote their children's environmental science curriculum. Or if Purdue Pharma trained their children's biology teachers. Yet, over the last decade, schools have often embraced the technology industry in similar ways with few questions asked. The article excerpts the soon-to-be-released book " Coding Kids: Big Tech's Battle to Remake Public Schools," with the reporter adding more thoughts on LinkedIn: Every few years, Silicon Valley has urged American public schools to quickly adopt the latest technology or teach the latest tech subject: Big Data analytics; laptops for every child; algorithm-driven math and reading apps; compter programming; virtual reality. And each time the urgent arguments sounded remarkably similar: if schools just adopted the latest tech tool, or taught the latest tech subject, it would democratize learning for every child and equip students with valuable career skills. Despite good intentions, "today we know some of those classroom tech drives did not exactly pan out as advertised." Now some of the same companies that urged schools to provide laptops and coding lessons are employing similar arguments to urge schools to quickly adopt A.I. tools. I've spent years covering Chromebooks and student chatbot use. And I'm troubled by our collective amnesia around school tech. Thanks to long-time Slashdot reader theodp for sharing the article. Read more of this story at Slashdot.

  • A Tiny 'Rainbow On a Chip' Could Help Supercharge 6G Networks
    by EditorDavid on 30/08/2026 at 4:34 pm

    ScienceDaily reports: A microchip about the size of a grain of rice can generate a highly organized "rainbow" of light, a capability that could eventually support faster, higher-capacity 6G communications and extremely precise timing for quantum technologies. Physicists at Loughborough University, working with an international research team, demonstrated a system that produces a series of precisely spaced light frequencies. Those optical frequencies can then be converted into multiple high-frequency electromagnetic signals known as millimeter waves. Millimeter waves are attracting growing interest for future communications because they can provide considerably more bandwidth, giving networks more room to transmit data. A major obstacle, however, has been producing these signals with the precision and stability required for advanced applications... "They could ultimately contribute to faster, higher capacity 6G networks," [said Dr. Luke Peters, of Loughborough University's Emergent Photonics Research Centre], "but the potential goes far beyond communications. These frequencies could also be used in radar systems as well as spectroscopy and astronomical instruments, helping scientists study materials and make extremely precise measurements of the universe. "These applications are still some way off, and there are challenges to overcome before the technology can be used in real-world systems — but our latest work has tackled a major one..." A microcomb generates an extremely precise set of light frequencies arranged somewhat like the colors in a rainbow, although the light itself is invisible to the human eye. A specialized antenna can then convert those optical frequencies into millimeter waves. Earlier research demonstrated that microcombs could produce a single precise millimeter wave frequency. Generating many frequencies simultaneously could be far more useful because each could potentially serve as a separate channel for transmitting information at the same time. Achieving that, however, requires a microcomb with exceptional stability and signal quality. In a new Nature Communications paper, the Loughborough led researchers report a system capable of doing exactly that. Their system connects its chip-based microresonator to a much larger loop of optical fiber where laser light continuously travels through both parts of the system, according to the article. "The team is now investigating how the microcomb system could eventually move from a laboratory experiment into practical technology." Read more of this story at Slashdot.

  • Citrix Adds a Linux-Powered Escape Hatch For Compromised Windows PCs
    by EditorDavid on 30/08/2026 at 3:34 pm

    Citrix's Desktop as a Service (DaaS) product includes a lightweight, hardened second operating system called UniconOS (once called "eLux") to offer Windows customers a write-protected file system Citrix says is secure against computer viruses and other malware. Nerds.xyz reports: According to the company, the environment remains isolated from the Windows filesystem and uses Secure Boot protections covering the shim, bootloader, kernel, and initial RAM filesystem. That separation matters when ransomware encrypts Windows or a faulty update leaves the operating system trapped in a boot loop. Instead of repairing Windows immediately, an employee can boot into UniconOS and use Citrix DaaS to access virtual applications and desktops. Citrix SecurAccess with Chrome Enterprise provides access to internal web applications under the organization's existing security policies. In other words, UniconOS does not actually fix the damaged Windows installation. It gives employees another route to their applications while the IT department investigates or repairs Windows... [T]he installer shrinks the Windows volume, creates a new partition, copies UniconOS onto it, and registers the necessary boot entries. Windows remains the default operating system during ordinary use, although administrators can configure boot delays and fallback behavior... The approach could prove useful following a widespread ransomware attack or another defective Windows update resembling the CrowdStrike incident of 2024. Recovery would happen independently on every compatible endpoint instead of requiring IT employees to physically handle thousands of computers. Thanks to Slashdot reader BrianFagioli for sharing the news. Read more of this story at Slashdot.

Archives

  • September 2022
  • November 2021
  • June 2021
  • March 2021
  • November 2020
  • October 2020
  • September 2020
  • February 2020
  • January 2020
  • October 2019
  • August 2018
  • July 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2016
  • July 2016
  • March 2016
  • February 2016
  • August 2015
  • May 2015

Categories

  • Innovation
  • Security
  • Software
  • Technology

Tags

backdoor cisco coding json laziness patterns public information announcement security vulnerability
© 2017 IT Sales & Services Ltd
Quality IT solutions in Tanzania since 2010
Iconic One Theme | Powered by Wordpress