The Register Home Page

* Posts by SVD_NL

439 publicly visible posts • joined 15 May 2022

Page:

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

SVD_NL Silver badge

Re: Mass queries are dead giveaways

Yes there were a lot of signs there... Password spray followed by legitimate sign in, AD enumeration, suspicious binary downloads, (unauthorised?) remote access tool, data exfiltration, and attempt to boot into safe mode. Any one of these could've been caught by an [E|N|X]DR solution. Note: This whole attack took over 3 hours!

Also, Defender EDR now allows you to block rebooting into safe mode (which blocks any attempts, except for UI-initiated and WinRE safe boots). Probably wouldn't have helped as they had UI control through AnyDesk, but it's a good option to enable to help prevent this type of EDR bypass. Not sure if other EDR solutions do the same.

Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway

SVD_NL Silver badge

Re: Switch it off, then on again

Ah yes, a hidden, always-on, undocumented remote maintenance function. Seems legit.

NASA puts astronauts’ lives in the hands of Tesla’s flaky Cybertruck

SVD_NL Silver badge

Re: Using a Cybertruck

Pick your poison: hydrogen fire, or lithium battery fire!

Word worm crawls into Copilot, spreads chaos

SVD_NL Silver badge

Microsoft already has accessibility checkers that trigger warnings on difficult-to-read (low contrast) text. Tune it to be a little less sensitive and you've got a fairly effective mitigation method.

That would require using deterministic code though, and MS seems to be against that as of late.

SVD_NL Silver badge

Re: Keeping code and data separate

It's not like many of the most common types of vulnerabilities result from failing to seperate the two... (SQLi, XSS, Command Injection, etc.)

High hardware costs see Red Hat offer a two-server edge rig, no mini-PC required

SVD_NL Silver badge

This sounds like a horrible idea

If you're running a 2-server cluster with HA requirements, just spend the tiny bit extra to also run an arbiter... Literally any Linux device or VM will do.

This completely solves the cold boot and reboot inconsistency issue, as it will store the most recent cluster config, so any node that comes online can be quorate and will have the most recent config.

I feel like this solution solves a very minor problem, and replaces it with a massive potential risk.

Tech support chap told angry customer to think inside the box – and solved the problem

SVD_NL Silver badge

Re: "when many phones still had removable batteries"

I remember a case where a company had somewhat shoddy cell reception in their office. This was playing out in the early-ish days of mobile telephony. They weren't the only one suffering, and the telco's took notice. Rejoice! They will build a cell tower for this part of the city! Directly on top of their office even! That should give great reception, right? ....Right???

Nope. Still shite after it went live. Turns out they don't point their antennea directly downwards. Took years for an overlapping cell tower to be built, which did solve the coverage issue.

SVD_NL Silver badge

Re: "when many phones still had removable batteries"

To be fair, i think it's a good tradeoff to not have removable batteries, but have better water-proofing. Water damage was also a large reason why phones went to the e-waste pile.

That does assume that phone manufacturers actually make it easy to replace batteries... Glued batteries are especially offensive

Telling internet platforms where to stick public service media will serve nobody. Turn it on its head

SVD_NL Silver badge

Dutch Public Broadcast

outsourcing more and more programming to independent production companies

In the Netherlands, the NPO (Dutch Public Broadcast) has been working like this for a long time, and takes this even further: It also has a bunch of sub-broadcasters who are members of the NPO, but all of them produce their own content, and promote their own interests. This stems from historic "pillarisation" in the community, where every vertical segment of the population (Protestant, Catholic, Socialist, Liberal/Neutral) had it's own shops, schools, political parties, etc. When TV came around, most of them also got their own broadcasting company.

Over time, as pillarisation broke down and lines were blurred, the distinction became less prominent. These days, most of them still exist (some of them renamed or merged, if they were similar). The sub-broadcasters are all their own entity, and are partly funded by their members. The NPO holds the broadcasting rights, and does programming and government fund distribution primarily based on the member count of sub-broadcasters. The rules and regulations for sub-broadcasters are determined by law. The sub-broadcasters produce content, and are responsible for the actual content.

This has a great effect on public broadcasting, as it is a reflection of the population. For example, the EO (Evangelical broadcaster) still does the sunday morning church service broadcasts. That doesn't interest me, but it is extremely important to a significant part of the population, and would have trouble existing without this system. The EO also makes a lot of great human interest programmes (in my opinion), which stems from their mission, likely wouldn't exist otherwise, but benefits way more people than their core audience.

Another part of this system, is that less represented parts of the population have a chance of making it to public broadcasting. All they need is a certain member threshold, and they are entitled to their slot in the programming. Fairly recently a right-wing broadcaster called "Ongehoord Nederland" (Unheard Netherlands) made this threshold. Do i agree with their views? No. Have they been in trouble for spreading misinformation and conspiracy theories? Yes. Do i think it's a good thing they exist? Yes, actually. I will always celebrate freedom of speech, especially if it's government-funded. This has also sparked *a lot* of public debate, which means both sides of the coin are represented in public discourse.

As you can probably tell, i really like this system. They are a little strapped for cash at the moment, but it will always be an uphill battle to secure funding for public broadcasting, i'm pretty sure that's universally true across the world.

NTP server that traveled back in time caused massive Aussie mobile outage

SVD_NL Silver badge

Re: SNTP clients

Exactly. On a system this large and critical, i'd expect at least 5 NTP servers, that way you can survive 1 or 2 going insane (or going down).

On the other hand, a lot of telco equipment in use today has a marketing bulletpoint that says it's Y2K proof....

Waymo hits the brakes after robotaxis keep missing the signs for freeway construction zones

SVD_NL Silver badge

Cars cope with this surprisingly well!

They use a combination of map data and posted signs, and the time limit signs are standardized enough (or the published map data is good enough) to recognize this. Posted signs take precedent over map data.

The main issue I've noticed is when there's parallel sections of road with differing speed limits, it'll sometimes read the signs of the wrong section. (I've got personal experience with VW, Audi and Tesla)

AI and brain-computer interface allow speechless ALS patient to work a full-time job

SVD_NL Silver badge

"An actual practical use of AI"

There have been practical uses for "AI" for ages. It's just the LLMs that everyone associates with "AI" are useless.

Google found liable for bad AI Overview results. Let's play Truth Or Consequences

SVD_NL Silver badge

I'm pretty sure they use Retrieval-Augmented Generation (RAG), which does reduce hallucinations and helps with models getting outdated, but it's not a silver bullet by a long shot. ARS Technica has a pretty good writeup on the subject, if you're interested in what it does and what the limitations are. TL;DR it still hallucinates, doesn't know it's own limitations (so doesn't know when to initiate RAG), and can't accurately determine the credibility of the source used with RAG (i.e. "Shit in = shit out").

SVD_NL Silver badge

...until hallucinations and false equivalencies are fixed

Soo.... never?

I'm also wondering about their statement about "everyone" knowing not to trust AI. All i see around me, is people not moving past the AI overviews, because they are very convenient. Why do i see this? Because i constantly get people telling me falsehoods, and being unable to solve issues with non-existent or non-applicable fixes. I'd like to have someone subpoena the statistics on click-through rates on the AI summaries links, and comparison data between search result website visits before and after introducing AI overviews. You have to back up your claims in court, don't you? I've seen some small-scale research papers painting a very different picture from what Google describes here, showing that zero-click search results are down overall, and showing a very strong correlation between zero-click searches and AI overviews being present.

Two examples: SparkToro, PewResearch.

NHS patients can't opt out of Palantir's data platform – but their hospital can

SVD_NL Silver badge

Re: No surprise here

So the so-called "opt out" is treated with the same level of respect (contempt) as a HTTP "Do Not Track" flag..

Ah, the browser flag that does not stop tracking, but does make you easier to fingerprint ever so slightly. Truly a marvel of modern technology.

Chinese e-tailer claimed 14-inch box stretched the size of a 9-inch tablet

SVD_NL Silver badge

Ugh, surface laptop chargers. It has the worst attributes of any type of charger. The worst design aspect of it, is that it magnetically attaches without the actual charger being connected. So if it's slightly misaligned when trying to attach it, it feels like it snaps in place, but in reality it's just sticking out the back.

It's essentially a crappy version of MagSafe. I don't like the proprietary nature of MagSafe, but at least works really well mechanically (and you can still use USB-C as a bypass on modern versions).

Brussels' datacenter efficiency scorecard may come with a credit warning

SVD_NL Silver badge

What, corporations playing by the same rules as civilians?

Good. When i buy or sell a house, it's mandatory for me to get an energy label. This energy label determines (among other things) the amount of financing that a buyer gets from a bank.

They also temporarily stopped offering 3-phase upgrades to houses, in the middle of a push to get off gas and start driving electric, so it's just insulting to me that they keep building bit barns.

It blocked us at 'hello!' Anthropic Fable 5 refusing innocuous prompts

SVD_NL Silver badge
Trollface

Re: Having models trying to figure out when you're doing something evil

Just make sure to buy an IRA outfit (or similar camo fatigues), a balaclava, and a rifle. Maybe even multiple. That way you have plausible deniability for the screenplay scenario when the authorities visit.

Angry bug hunter with Microsoft beef drops new Windows 0-day

SVD_NL Silver badge

Re: trumPet

RESPECT MY NT AUTHORITY

Claude celebrates Anthropic's stock market float with blockbuster ... outage

SVD_NL Silver badge

Re: REPORTEDLY, Anthropic earns more in revenue

None of the numbers surrounding AI are accurate. It's all a smoke and mirrors game designed to confuse everyone who tries to look into it. I can highly recommend Ed Zitron's Where's Your Ed At (note: he is very sceptical of AI). He does some deep dives into the financial flows between companies. It gets very muddy, for example: a datacenter builder takes an offer to build a database for nvidia, but it has not secured any of the prerequisites. it "buys" nvidia gpus with a net360 payment term *after finishing the datacenter*, and nvidia acts as collateral for the loan from a bank. Who has earned money here? or will this datacenter never get built and will all of the imaginary money just evaporate? And that's just two companies, this kind of fake money-shifting happens across the entire industry.

I'm personally very sceptical about LLMs being presented as the solution to everything. I think there is a place for AI, but this is mainly custom, purpose-built models. The financial sector definitely comes to mind. However, this market is not nearly big enough to sustain the ever-growing glutton of the AI boom. They are trying to get everyone hooked on general-purpose LLMs, but it's just not working, and without half the population spending 30 bucks a month on their AI plan, they're not going to get a return on their massive investments.

SUSE's sovereignty pitch meets an inconvenient $6 billion question

SVD_NL Silver badge

Re: Trump

Exactly! Because of Trump my countries' politicians have finally woken up to the fact that it's a pretty good idea to have a proper military, and not put our government IT at the mercy of a foreign power.

Those two things (among others) have been major annoyances of mine for a while now, so I'd like to thank the Dorito in Chief for addressing those issues.

GitHub opts all CLI users into telemetry collection whether they want it or not

SVD_NL Silver badge

Re: "no solid list of data points that might be included"

(IANAL, but i need to assess GDPR stuff on a regular basis)

It's allowed under certain provisions, Legitimate Interest being a horribly abused example of that. They theoretically need to provide you their legal basis if requested, but good luck with that. And if they do, i wish you even more luck with disputing them!

That being said, i think they're really threading the needle here, you'd at least expect that information in the privacy policy, and if someone does decide to make a ruckus, they could very well be in trouble. Also, data subject requests exist, and are a very easy way to see what's being collected, and also an easy way to report companies to a watchdog.

To fix this Wi-Fi network, we'll need a crane

SVD_NL Silver badge

"We looked at the spectrum analyzer and the entire 2.4GHz spectrum across all channels was blanketed by a very strong signal,"

Good catch on spotting the crane operator! If this occured during lunchtime i'd be sprinting towards the cafetaria with a mallet to expedite the microwave replacement.

Physicist reckons two-button calculator can do all elementary math

SVD_NL Silver badge

This gives me flashbacks to programming old PBXs using dial tones. One mistake, and back to the start you go... Especially the systems without any sort of feedback are terrible, blind programming through number sequences.

Hotel's rotary switchboard so retro it predates the concept of crashing

SVD_NL Silver badge

Hotels are retro telephony treasure troves

Hotels tend to have very dated telephony requirements for a bunch of reasons. This is a combination of analog phone cables that are very difficult (and expensive) to replace, large analog PBX's being expensive, and local legislation often mandating that guests should always have a phone available to dial the emergency number.

While modern telephony platforms won't have as much trouble with 100's of phones, the expense of replacing all of those cables in an old building and all of those new phones is often too much to bear. So much so that we once came across an old comms room with hundreds of ATAs to convert SIP to analog phone signals.

Work experience kids messed with manager's PC to send him to Ctrl-Alt-Del hell

SVD_NL Silver badge

Another classic background prank

The classic i remembered (i grew up with Windows XP+):

Screenshot, rotate image 180 degrees, set as background. Remove all icons, hide taskbar. ctrl+alt+down (this rotates the screen 180 degrees). Bonus points if you flip the screensaver too!

Classmates appreciated the pranks for the most part. Teachers didn't like me, i wonder why!

Desktop tech sent to prison for an education on strange places to put tattoos

SVD_NL Silver badge

"A little effort showed the issue was actually with a mainframe"

I imagine someone getting that job without knowing what they're doing, spending hours on troubleshooting a basic issue, all while the rest of the team waits for him to show up to the cooter corridor.

Ghost gun legislation casts shadow over 3D printing

SVD_NL Silver badge

Re: RE: 3D printers are actually dumb tools

Yes! Same for the Błyskawica submachine gun (Wikipedia), a Sten clone produced in occupied Poland, where each part was disguised as a part for something else. (I believe the buttstock was supposed to be a microwave door handle for example).

I highly recommend the Forgotten Weapons episode (YouTube) on that one.

SVD_NL Silver badge

RE: 3D printers are actually dumb tools

I got an old Ender 3 from a friend, i can attest to how dumb they are (especially older models). The most intelligence that it can show is that it stops moving when it reaches a stop (and even that doesn't work in some cases).

Working on the assumption that this would be an effective and sensible law (which it isn't), and privacy doesn't matter (it actually doesn't matter to the US government), it would make way more sense to move this restriction to the software side, right? More processing power available, network connectivity to check for a db of known firearm models, etc.

And i fully agree with you, the moment you start banning or restricting general-purpose tools, you might as well ban every tool known to man.

Microsoft actually does something useful, adds Sysmon to Windows

SVD_NL Silver badge

Re: Another thing MS should have done earlier...

Right!!

The last laptop with a SATA SSD I've bought was probably 15 years ago, everything after that has been NVMe. Desktops took a tiny bit longer to move, but it has been the default for at least a decade by now. How has it not been a priority to implement this? Especially with how many things Windows servers do generally being bottlenecked by IO (SQL, SMB, etc.).

Watchdog says US weather alerts are getting lost in translation

SVD_NL Silver badge

Excellent waste of money!

I'm so glad they spend so much time and effort into developing a custom AI translator for weather alerts. Similar products surely aren't available off-the-shelf, because they have such novel requirements. The use of AI is also absolutely required, weather alerts are going to be extremely dynamic and complicated to translate!

I'm genuinely wondering why they can't just create template warnings with <severity> <weather event> <timing info> <call to action> and have those available in a bunch of languages (basically string templates that are used for localization everywhere).

Keep it simple, stupid: Agentic AI tools choke on complexity

SVD_NL Silver badge

Re: Lovely.

Especially industrial equipment triggered me there. Imagine living close to a chemical plant, and finding out they use AI to control the equipment?? It's dangerous enough already when it's operated by humans with procedures written by experts. (Or maybe i just watch too many CSB videos)

Marketing 'genius' destroyed a printer by trying to fix a paper jam

SVD_NL Silver badge

Re: Users and printing devices...

Those partially used label sheets haunt me in my dreams... It works just fine until it doesn't, and when it goes bad, it goes very, very bad.

SVD_NL Silver badge

Ah, end users and basic printer maintenance...

I've got many, many stories of users messing up printers beyond repair while trying to solve basic tasks, here's some highlights:

1. A brave attempt at swapping out a toner cartridge. Unfortunately the user didn't realise a locking tab was in place, which also closed the opening in the cartridge. Their solution was to simply apply more force. Aftermath? The room was coated top to bottom in black carcinogenic dust! It genuinely looked like an explosion had taken place, the entire printer was coated, and a streak ran up the wall across the ceiling over to the other side! Bonus points for the brave soul who wanted to clean this up using a wet mop, at least they tried. I ended up printing a biohazard sticker (on a different printer) and sticking it on the door, and calling in a professional cleaner. I really wish i could've seen the perpetrator, this stuff is probably worse than the ink bombs they use for money.

2. Paper jam in a small simplex mono printer (i mention this because it's not some large MFP with a bunch of rolls and pulleys). They managed to solve the paper jam using their tool of choice: a knife! Unfortunately they also stabbed the drum to death. Of course none of this was mentioned in the service request, the printer just stopped working. We were shocked the first time, ended up replacing the printer (drum replacements weren't economically viable for those small printers). End of story? Nope! less than a week later the exact same story! The client followed our recommendation, and they implemented a new policy for that location, where only a few select users were "trained" at refilling paper, and any other task had to be performed by service techs...

3. Printer in a primary school, for some reason there weren't any rooms available that children couldn't reach. They called because of a really bad paper jam and a bunch of error codes. I have no clue how, but a child had managed to jam a colored pencil waaay into the innards of the printer. I was genuinely impressed! (I'm saying it was a child, but i have no way to be sure of that. It's a bit of a coping mechanism to assume it's a child, but realistically it could've been another improvised tool to "solve" a paper jam.)

Anthropic writes 23,000-word 'constitution' for Claude, suggests it may have feelings

SVD_NL Silver badge

Re: I don't understand what they're trying to do

I fully agree, just a small update: Should --> must.

My view of a constitution is a small set of (practically) immutable laws that establish clear boundaries and restrictions. I can't be arsed to read the whole thing, but the snippets highlighted here read more like vague guiding principles and broad instructions how to weigh certain values. I personally think that this is more of a policy or guiding principles document (mission/vision etc.).

Maybe this is just how you talk to LLMs, i can't get the bloody things to work with direct language and technical specifications, after all.

Rackspace tests customer loyalty with brutal email price hike

SVD_NL Silver badge

"Get world-class business email at a fraction of the cost of other platforms."

"25 GB mailboxes, 30 GB file storage"

Maybe true for the previous pricing, but at 10$ that's a plain old lie! Even MS365 Business Basic only costs $6, which has 50GB (soon 100GB) mailboxes, and 1TB of OneDrive storage, and web versions of Office apps. You have to do some serious mental gymnastics to make your own offer sound like a better deal.

Don't even get me started on a price increase of that magnitude at such short notice...

AI framework flaws put enterprise clouds at risk of takeover

SVD_NL Silver badge

I feel like a broken record...

...I've said this very recently on an article discussing the n8n RCE vulns, but i'll repeat the gist of it here:

Why would you ever deploy an AI service that accept user input with highly privileged access to a bunch of important internal systems? And even worse, expose it to the internet?

Akamai CEO wants help to defeat piracy, reckons he can handle edge AI alone

SVD_NL Silver badge
Joke

Re: Italy ? 30 minutes ?

Yes, the actual, undisclosed deadline is 3 months. It's just that by the time it has worked it's way through the Italian burocracy, there's only 30 minutes left!

Chinese spies used Maduro's capture as a lure to phish US govt agencies

SVD_NL Silver badge

Clickbaited!

Did the Chinese really just try to clickbait US Govt. officials? What's next? "Hot singles in the Washington D.C. area"?

Engineer used welding shop air hose to 'clean' PCs – hilarity did not ensue

SVD_NL Silver badge

Good lord

It takes an idiot to use a random welding shop air hose to clean out computers (maybe i'd even pass it off as an honest mistake), but it takes a special kind of idiot to keep going after visibly destroying the first PC!

Not even a quick check to see if it still worked...

Court tosses appeal by hacker who opened port to coke smugglers with malware

SVD_NL Silver badge
Coat

I think it was RS232, because he gained access to the terminal!

Maximum-severity n8n flaw lets randos run your automation server

SVD_NL Silver badge

Re: Nandos

RCE - Remote Chicken Enhancement

SVD_NL Silver badge

Good lord...

"Let's authenticate this one product running LLMs and accepting user input/commands to every single software product in our environment with highly privileged permissions!"

Am i the only one seeing the issue here?

OpenAI putting bandaids on bandaids as prompt injection problems keep festering

SVD_NL Silver badge

Idiots

The implementation of LLMs has always bothered me, especially the software architecture.

If you don't know by now that you shouldn't trust external input in any way, you shouldn't be near software development in any capacity. Why is it not possible to escape or sandbox external inputs? "Technical limitations"? I think that just means "I made a shitty insecure product".

What also bothers me is the lack of any kind of optimisation. I recall seeing a quote from Sam Cuntman that people were wasting X amount of money by saying goodbye/please/thank you to chatgpt, and asked people to stop doing it. WELL MAKE A GODDAMN FUNCTION THAT HANDLES GOODBYE MESSAGES WITHOUT SENDING IT TO THE LLM THEN YOU PLANET-DESTROYING CLANKERFUCKER!!

Same goes for prompts that don't need LLMs in any way. Why not parse calculations and send them to a calculator for example? Man, LLMs suck.

HSBC app takes a dim view of sideloaded Bitwarden installations

SVD_NL Silver badge

Re: Been happening for years

It's a safety control, apps can block other apps from "seeing" that app window, this includes accessibility apps. (You can easily tell this by trying to screenshot an app, it won't work for protected apps).

I do understand this to some degree, but at some point it's the users' responsibility IMO. Android warns you 10 times that you're giving access to everything that's on your screen when you enable accessibility perms, and regularly warns about apps that have accessibility perms enabled. There is a legitimate use cases for those, and users should be able to enable it if they want to.

I can definitely understand your frustration, modern tech seems to become less and less accessible despite technological advancements in that field. I don't have any disabilities, and even i am impacted by this. Example: "smart" appliances and their horrible touch screen interfaces. They're bloated, not logical, have a bunch of fancy animations and decorations i don't need, and the touch screen is hard to use, especially when i've got wet or dirty hands (while cooking for example). I can't imagine trying to use my oven if i had some sort of physical or visual impairment, and even without disabilities it's just better to have buttons and knobs.

What if Linux ran Windows… and meant it? Meet Loss32

SVD_NL Silver badge

Re: kernel has a stable ABI?

For anyone interested, here's a snippet of his opinion on the matter. (that whole repo is gold)

Lenovo shows off new laptops that twist and roll

SVD_NL Silver badge

Widescreen laptop?

It's a shame they went for the gamer branding on that one. I rarely feel like i need some additional vertical real estate on my 13"laptop (it's a 3:2, but a lot of new models are 16:10 already), but i can definitely imagine situations where having some additional room for side-by-side windows comes in handy.

Also, execs would absolutely eat that concept up. Imagine their boner when they show off this thing expanding to show that big spreadsheet they don't understand in it's entirety!

Researchers poison stolen data to make AI systems return wrong results

SVD_NL Silver badge

"Oh no, my LLM can't use this treasure trove of stolen data!"

So, this method basically adds a bunch of junk data to real data and makes the LLM more likely to choose junk data when it queries without an encryption key?

I don't see how this actually protects against IP theft, unless the only IP you're trying to protect is the knowledge graph itself, not the underlying data as you should be able to extract that using other means. I'm sure there's cases where this has some real-world applicability, but i feel like most companies wouldn't be happy about the plaintext data being stolen, even if it is slightly obfusciated.

Baby's got clack: HP pushes PC-in-a-keyboard for businesses with hot desks

SVD_NL Silver badge
SVD_NL Silver badge

I'm genuinely wondering what makes this better than carrying around a tiny PC (Dell Micro, Intel NUC, etc.). You need peripherals to use this either way, why does it matter the keyboard is integrated?

I can also already see how confused the average user is going to be about this product. From experience, a lot of them can barely grasp the concept of a USB-C dock with wireless peripherals...

Page: