ocean

匿名

4 月 012011
 

from chinaz.com

4月1日消息:今日,国内知名Java编程网站JavaEye.com被迫修改网站名称及域名,放弃一个运营了7年的JavaEye品牌。目前网站已经正式更名为ItEye技术网站,同时网站域名从javaeye.com重定向到iteye.com。

JavaEye网站发布公告称,由于Oracle公司通过授权的律师事务所,对JavaEye网站提出了无法接受的苛刻条件,在经过长期努力的交涉无效之后,Oracle授权的律师事务所以强硬的姿态要求我们服从,并且以停用javaeye.com的域名作为威胁,因此,我们只能被迫放弃已经运营了7年的JavaEye的域名和JavaEye品牌,更名为ItEye。

以下是官方对事件经过描述:

从2010年的11月26日说起:

11月26日我们收到了Oracle授权的联德律师事务所发来的律师函(律师函请看附件),声称:我方未经Oracle公司授权,擅自使用了javaeye.com的域名,涉嫌误导JAVA商标,要求我方如下:

Oracle 写道:

1. 不在javaeye.com网站首页使用“JavaEye”标识,并改用其他名称,例如“EyeonJava”;

2. 在javaeye.com网站醒目位置添加声明,表明该网站与甲骨文美国有限公司没有任何关系,如: “[Eye on Java]—有关 JAVA 的非官方社区网站 An Unofficial Community on JAVA”,或者 “[Eye on Java]—独立的 JAVA 社区网站 An Independent Community on JAVA”;

这两个条件很诡异的地方在于: Continue reading »

3 月 292011
 

中国站长站

对于京东,已经无需我再多做介绍,稍微有网购经验的网民都知道它是目前国内B2C领域的巨头企业。我们诧异于京东的低价格,诧异于它的品类齐全,诧异于它投资巨大的自建物流及客服体系。在3月27日的深圳电子商务大讲堂开启大会上,京东掌门人刘强东的一句“B2C不打价格战是不行的,但光打价格战是绝对不行的”引得台下阵阵掌声,这掌声折射出广大B2C商家在电子商务价格苦战中无法脱身的苦恼,却在茫然中没有摸索出明晰的利润方向。

B2C商家都卖商品不可能不用价格做营销工具,至于怎样才能不光打价格战,刘强东是不可能在大众面前直言的。但是笔者狼里格朗对京东的盈利模式倒有一番个人解读,供大家玩味推敲。 Continue reading »

3 月 242011
 

Report of incident on 15-MAR-2011

An RA suffered an attack that resulted in a breach of one user account of that specific RA.
This RA account was then used fraudulently to issue 9 certificates (across 7 different domains).

All of these certificates were revoked immediately on discovery.
Monitoring of OCSP responder traffic has not detected any attempted use of these certificates after their revocation.

Fraudulently issued certificates

9 certificates were issued as follows:

Domain:  mail.google.com    [NOT seen live on the internet]
Serial:  047ECBE9FCA55F7BD09EAE36E10CAE1E

Domain:  www.google.com  [NOT seen live on the internet]
Serial:  00F5C86AF36162F13A64F54F6DC9587C06

Domain:  login.yahoo.com  [Seen live on the internet]
Serial:  00D7558FDAF5F1105BB213282B707729A3

Domain:  login.yahoo.com    [NOT seen live on the internet]
Serial:  392A434F0E07DF1F8AA305DE34E0C229

Domain:  login.yahoo.com     [NOT seen live on the internet]
Serial:  3E75CED46B693021218830AE86A82A71

Domain:  login.skype.com     [NOT seen live on the internet]
Serial:  00E9028B9578E415DC1A710A2B88154447

Domain:  addons.mozilla.org     [NOT seen live on the internet]
Serial:  009239D5348F40D1695A745470E1F23F43

Domain:  login.live.com     [NOT seen live on the internet]
Serial:  00B0B7133ED096F9B56FAE91C874BD3AC0

Domain:  global trustee     [NOT seen live on the internet]
Serial:  00D8F35F4EB7872B2DAB0692E315382FB0

What didn’t Happen

Our CA infrastructure was not compromised.
Our keys in our HSMs were not compromised.
No other RA was compromised.  No other RA user accounts were compromised.

What Happened

One user account in one RA was compromised.
The attacker created himself a new userID (with a new username and password) on the compromised user account. Continue reading »

3 月 242011
 

内容很长,大家慢慢看.

Detecting Certificate Authority compromises and web browser collusion

Posted March 22nd, 2011 by ioerror

Thanks to Ian Gallagher, Seth Schoen, Jesse Burns, Chris Palmer, and other anonymous birds for their invaluable feedback on this writeup.

The Tor Project has long understood that the certification authority (CA) model of trust on the internet is susceptible to various methods of compromise. Without strong anonymity, the ability to perform targeted attacks with the blessing of a CA key is serious. In the past, I’ve worked on attacks relating to SSL/TLS trust models and for quite some time, I’ve hunted for evidence of non-academic CA compromise in the wild.

I’ve also looked for special kinds of cooperation between CAs and browsers. Proof of collusion will give us facts. It will also give us a real understanding of the faith placed in the strength of the underlying systems.

Does certificate revocation really work? No, it does not. How much faith does a vendor actually put into revocation, when verifiable evidence of malice is detected or known? Not much, and that’s the subject of this writing.

Last week, a smoking gun came into sight: A Certification Authority appeared to be compromised in some capacity, and the attacker issued themselves valid HTTPS certificates for high-value web sites. With these certificates, the attacker could impersonate the identities of the victim web sites or other related systems, probably undetectably for the majority of users on the internet.

I watch the Chromium and Mozilla Firefox projects carefully, because they are so important to the internet infrastructure. On the evening of 16 March, I noticed a very interesting code change to Chromium: revision 78478, Thu Mar 17 00:48:21 2011 UTC.

In this revision, the developers added X509Certificate::IsBlacklisted, which returns true if a HTTPS certificate has one of these particular serial numbers:

047ecbe9fca55f7bd09eae36e10cae1e
d8f35f4eb7872b2dab0692e315382fb0
b0b7133ed096f9b56fae91c874bd3ac0
9239d5348f40d1695a745470e1f23f43
d7558fdaf5f1105bb213282b707729a3
f5c86af36162f13a64f54f6dc9587c06

A comment marks the first as “Not a real certificate. For testing only.” but we don’t know if this means the other certificates are or are not also for testing. Continue reading »

3 月 242011
 

2011-03-24 互联网周刊  作者:启言 孙晓红

对大部分互联网用户来说,IDC(互联网数据中心)可能只是一个艰深晦涩的概念。但是放在整个互联网经济的框架之中,IDC就成为一个必不可少的存在。

IDC是互联网的基础资源,它能够提供高端的数据传输服务和高速接入服务,是应ICP(互联网内容提供商)的需求而产生的。互联网经济越是发达,互联网上的内容和应用资源就越多,相应的对IDC的需求就越大。可以说,IDC是互联网发展的晴雨表。

经过多年的发展,目前IDC的功能已经从基础业务如主机托管、带宽出租、服务器出租等拓展到网络安全服务、代维服务和数据存储等增值业务。随着中国信息化战略的不断推进,以及物联网、云计算等概念的出现,将来IDC的发展还有很大的空间。

但是IDC究竟能走多远,很大程度上不在于它本身有多大的潜力,而在于它是否有发挥这些潜力的机会。中国的IDC产业发展一直面临体制困境。

Continue reading »

3 月 232011
 

本文内容详细,建立家用nas服务器,值得一读,核对了一下原文件,补充了几个遗漏的内容。
仅做了翻译,没有做安装的验证,尽量做到没有技术错误,希望有感兴趣的fans能做个测试,分享一下经验。

HOWTO : Home made NAS server with Ubuntu 8.04.1
[HOWTO] 用Ubuntu 8.04.1搭建NAS服务器

There are many NAS for home users in the market, such as Synology, Qnap, LinkStation and etc. They are not in good performance and not cheap in price. However, they are good in less power consumption. It is because I owned not only one brand of such products at home now.
现在市场上有很多家用NAS产品,例如:Synology, Qnap, LinkStation等。它们性能并不好,而且价格不便宜。不过,在低能耗方面做得较好,因此,我家里有不止1个品牌的这类产品。

Recently, I bought a VIA PC-1 PC2500E motherboard, which has VIA C7-D 1.5GHz CPU on board. It is cheap in price and use less power too. The maximum amount of RAM is 2 GB.
最近,我买了1块VIA PC-1 PC2500E主板,板上带有VIA C7-D 1.5GHz CPU。价格便宜,也节能。最大可装2G内存。

Testing it with Ubuntu 8.04.1 Desktop version for a while, I am very satisfied with the performance of the CPU, although it is not quite fast indeed. I decided to build a home made NAS server with remote BitTorrent function.
用Ubuntu 8.04.1 Desktop测试一段时间,虽然不是足够快,我还是对CPU的性能相当满意。我决定在家组装NAS服务器,并带有远程BT功能。

Hardware
Motherboard – VIA PC-1 PC2500E with VIA C7-D 1.5GHz CPU
RAM – 2 X 1GB DDR2 667MHz (maximum)
Hard drive – 300GB Seagate SATA (The motherboard treats it as ATA drive)
Router – Planet WRT-401E (wired) (optional)

Software
Operating system – Ubuntu 8.04.1 Server Edition
File server – Samba
FTP server – vsFTPd
Remote access – OpenSSH
Web Server – Apache, PHP and MySQL
Remote BitTorrent – TorrentFlux (front-end) and BitTornado (back-end)
Security software – Fail2Ban Continue reading »

3 月 182011
 

【搜狐IT消息】北京时间3月18日消息,科技博客TechCrunch创始人Michael Arrington今天发表博文称,Digg创始人Kevin Rose自己都不再使用自家的服务了。

曾经风光一时的Digg如今情况不太令人乐观。自从去年8月份改版后重新推出已经过了几个月了。据互联网流量监测公司Comscore的数据显示,重新推出当月Digg有1800万来自全世界的独立访问用户,今年一月份这一数字下降到不足1200万,五个月的时间内剧减33%。

Digg官方放出的消息一直声称一切情况良好,公司会找到成功的方式。但所有人都觉得这已经不太可能了,尤其是创始人Kevin Rose似乎也这样认为。

据观察,Kevin已经几乎不再使用这项服务。去年12月份,他连续22天没有提交、评论或甚至挖掘(Digg)任何新闻。

过去30天内,他只在Digg上活动过7次,每4天不足一次。自2月13日以来的一个月里,他没有提交一则新闻。同样,Digg首席执行官Matt Williams也好不到哪里去,尽管他尽量努力平均每天评论或提交一则新闻。

与之形成鲜明对比的是,Rose在Twitter上非常活跃,上个月内发了181条微博,活跃程度比在他自己创建的网站上高了25倍。

如果连Kevin Rose这样的高管们都不再使用自家的服务,那Digg想要枯树逢春的希望实在渺茫了。对于这个曾经出尽风头的创业企业来说,真是一个彻底的悲剧。 Continue reading »

3 月 172011
 

作者: kurich

馬總統520就職演說中說到:「英九堅信,兩岸問題最終解決的關鍵不在主權爭議,而在生活方式與核心價值。我們真誠關心大陸十三億同胞的福祉,由衷盼望中國大陸能繼續走向自由、民主與均富的大道,為兩岸關係的長遠和平發展,創造雙贏的歷史條件。」

要如何著手實現這個願望呢?筆者認為民主政治就是政黨政治,中國大陸現在是共產黨專政,從長遠方向思考,世界歷史上沒有任何朝代是萬萬歲的,百年以上的企業也不多見,中國大陸如果要長治久安,走向自由、民主與均富的大道,應開放黨禁,開始規劃與培養第二個政黨!放眼中國自從辛亥革命、推翻帝制以來,國民黨與共產黨先後執政,都是有主義、有理想、有人才、功在史頁的政黨。

在九二共識的基礎上,甚麼問題都可以談!那麼就從「中國國民黨應否重返大陸設立黨部」開始談起吧。要求中共承認中華民國,短期內似乎不可能,但要中國共產黨承認中國國民黨是中國合法的政黨,應該不是不可以談的問題!

如果說先讓國民黨到大陸公開發展組織、吸收黨員仍有困難,那麼先到香港重新恢復興中會名號,等到2017年要舉辦響港特首直選時,也讓中國國民黨提名候選人,選不選得上姑且不論,至少這是一個起步。 Continue reading »