• 0 Posts
  • 319 Comments
Joined 3 months ago
cake
Cake day: June 23rd, 2024

help-circle

  • I worked in software certification under Common Criteria, and while I do know that it creates a lot of work, there were cases where security has been improved measurably - in the hardware department, it even happened that a developer / manufacturer had a breach that affected almost the whole company really badly (design files etc stolen by a probably state sponsored attacker), but not the CC certified part because the attackers used a vector of attack that was caught there and rectified.

    It seemingly was not fixed everywhere for whatever reason… but it’s not that CC certification is just some academic exercise that gives you nothing but a lot of work.

    Is it the right approach for every product? Probably not because of the huge overhead power certified version. But for important pillars of a security model, it makes sense in my opinion.

    Though it needs to be said that the scheme under which I certified is very thorough and strict, so YMMV.








  • Ich muss dabei leider am dieses Zitat denken, auch wenn es dort um die USA geht:

    I have a foreboding of an America in my children’s or grandchildren’s time – when the United States is a service and information economy; when nearly all the manufacturing industries have slipped away to other countries; when awesome technological powers are in the hands of a very few, and no one representing the public interest can even grasp the issues; when the people have lost the ability to set their own agendas or knowledgeably question those in authority; when, clutching our crystals and nervously consulting our horoscopes, our critical faculties in decline, unable to distinguish between what feels good and what’s true, we slide, almost without noticing, back into superstition and darkness…

    The dumbing down of American is most evident in the slow decay of substantive content in the enormously influential media, the 30 second sound bites (now down to 10 seconds or less), lowest common denominator programming, credulous presentations on pseudoscience and superstition, but especially a kind of celebration of ignorance.











  • Can’t make it right for everyone… Some people will complain about mining and the energy consumption (Bitcoin is supposed to currently use about 850 kWh per transaction), others complain about a supposedly unfair premine. They didn’t even hold an ICO.

    51%

    That’s not currently a required percentage, you need 67% of votes to confirm a transaction. Which in turn means 33% are enough to stall the network. But even then, what would their gain be, apart from owning more of their own currency?

    Which is irrelevant because holders can just choose different representatives.

    You can, but then you can no longer vote. And if you can’t vote, holding Nano does nothing.

    I don’t think there’s a cryptocurrency today that comes without downsides, be it high resource usage, lack of anonymity or others, if they’re not straight up money grabs and a copy paste of another random junk on ETH. Bitcoin is not an option for me because of the monster mining has become - I don’t blame Satoshi, this is something I didn’t expect either, but it’s insanity currently.