Slashdot videos: Now with more Slashdot!
We've improved Slashdot's video section; now you can view our video interviews, product close-ups and site visits with all the usual Slashdot options to comment, share, etc. No more walled garden! It's a work in progress -- we hope you'll check it out (Learn more about the recent updates).
"I used to think fatty food made you fat. Now it seems the opposite is true. Eating lots of peanuts, avocados, and cheese, for example, probably decreases your appetite and keeps you thin. I used to think vitamins had been thoroughly studied for their health trade-offs. They haven't. The reason you take one multivitamin pill a day is marketing, not science. I used to think the U.S. food pyramid was good science. In the past it was not, and I assume it is not now. I used to think drinking one glass of alcohol a day is good for health, but now I think that idea is probably just a correlation found in studies."
According to Adams, the direct problem of science is that it has been collectively steering an entire generation toward obesity, diabetes, and coronary problems. But the indirect problem might be worse: It is hard to trust science because people have become accustomed to learning that they've been steered wrong. "I think science has earned its lack of credibility with the public. If you kick me in the balls for 20-years, how do you expect me to close my eyes and trust you?"
The report echoes a well-known joke/prank wherein people discuss the dangers of the chemical "dihydrogen monoxide" also known as hydrogen oxide and hydrogen hydroxide. Search online for information about dihydrogen monoxide, and you'll find a long list of scary-sounding and absolutely true warnings about it: the nuclear power industry uses enormous quantities of it every year. Dihydrogen monoxide is used in the production of many highly toxic pesticides, and chemical weapons banned by the Geneva Conventions. Dihydrogen monoxide is found in all tumors removed from cancer patients, and is guaranteed fatal to humans in large quantities and even small quantities can kill you, if it enters your respiratory system. In 2006, in Louisville, Kentucky, David Karem, executive director of the Waterfront Development Corporation, a public body that operates Waterfront Park, wished to deter bathers from using a large public fountain. "Counting on a lack of understanding about water's chemical makeup," he arranged for signs reading: "DANGER! – WATER CONTAINS HIGH LEVELS OF HYDROGEN – KEEP OUT" to be posted on the fountain at public expense.
I assumed this referenced Docker's heavily promoted image signing system and didn't investigate further at the time. Later, while researching the cryptographic digest system that Docker tries to secure images with, I had the opportunity to explore further. What I found was a total systemic failure of all logic related to image security.
Docker's report that a downloaded image is 'verified' is based solely on the presence of a signed manifest, and Docker never verifies the image checksum from the manifest. An attacker could provide any image alongside a signed manifest. This opens the door to a number of serious vulnerabilities." Docker's lead security engineer has responded here.