* Posts by Mister Jones

18 publicly visible posts • joined 3 Jan 2024

Signal chat app clone used by Signalgate's Waltz was apparently an insecure mess

Mister Jones

And Then There Is The NSO Product Pegasus......

If an endpoint has been compromised with Pegasus, Signal or Telegram or TeleMessage are all compromised......

...because the miscreant controlling Pegasus can see everything in plain text on the end point!

(1) Just ask Angela Merkel!!!

(2) Have agents elsewhere in the administration used Pegasus on THEIR OWN COLLEAGUES??

Paranoid? No.....not me!!

CDNs: Great for speeding up the internet, bad for location privacy

Mister Jones

Ha.....Where Is The Commentard Troll Actually Located?

@druck

Quote: "....commentard trolls...."

.....I'm confused.....don't commentard trolls use VPN?

So.....UserX (who is actually in Bulgaria) has traffic emerging from a server 100 miles from a USA server.

So what?

Five Eyes nations tell tech startups to take infosec seriously. Again

Mister Jones

...So Seriously That GCHQ Can't Pay A Decent Wage......

See: https://www.theregister.com/2024/10/29/gchq_needs_advanced_cybersecurity_professionals/

Yup.....HMG can face both ways at once!!! Even with different folk in charge in SW1!!

Why am I not surprised????

Oracle's Java pricing brews bitter taste, subscribers spill over to OpenJDK

Mister Jones

Re: You can increase fees only when you increase value

No.....you forgot about "increasing fear"...........fear that moving from today's platform might be more risky than paying Larry Ellison!!!!!!

Disenchanted Windows user? Pop open a fresh can of Linux Lite

Mister Jones

RE: Microsoft Money

Here at Linux Mansions Quicken has been running on Linux for about ten years.

......snags: it's a CD-based Windows release from 2006

......and: you need WINE on Linux.....but it installs and works fine with no probs.....

......which makes me wonder......maybe M$ Money would work fine with Linux/WINE?

Cisco fixes WebEx flaw that allowed government, military meetings to be spied on

Mister Jones

Actually: ANOTHER NSA backdoor exposed.....

There.....

How Apple Wi-Fi Positioning System can be abused to track people around the globe

Mister Jones

Burner Anyone?

In summary:

(1) Apple iPhones report back to Cupertino when they find (by Bluetooth) a "Find My" device in the neighbourhood

(2) Apple iPhones report back to Cupertino when they find a handy geolocation service on a nearby WiFi router

(3) Any other mobile phones using WiFi for GPS may be (are?) reported back to Cupertino

One wonders what other "facilities" are buried in:

- The WiFi infrastructure

- The iPhone software

- The Android software

I think we should be told!!!

P.S. Doesn't owning a burner seem increasingly attractive? Just saying!!!

A tale of two Chinas: Our tech governance isn't perfect, but we still get to say no

Mister Jones

Where Is George Santayana When You Need Good Advice?

Quote: "China ... untrammeled by legal safeguards..."

Remember the Snowden revelations? Yup...Fort Meade....untrammeled by legal safeguards...............

End-to-end encryption may be the bane of cops, but they can't close that Pandora's Box

Mister Jones

Re: Sigh......Assumptions Again.......

So.....private encryption may solve the privacy problem (for some).

The anonymity problem will be a bit harder!!

UK's Investigatory Powers Bill to become law despite tech world opposition

Mister Jones

Re: Harvest Away......Avoidance Is Possible.........

@AC

Quote: ' Use of a burner phone, private encryption, or even a VPN, will immediately flag you as a "person of interest" '

Think about it -- if the personal identity and the end point are both obfuscated..........

...........exactly who is THE PERSON in "the person of interest"??????

UK county council misses deadline for £7.3M RISE with SAP system launch

Mister Jones

Re: All ERP migrations are complex

@codejunky

Quote: "This sort of thing should be centralised"

What "sort of thing" exactly?????

It's clear that you are thinking about a "centralised" application provider.

But there are other ways of doing this:

(1) Define a STANDARD set of processes for county councils

(2) Develop a STANDARD software package aimed at county coucils

(3) Sell umpty-up licences for individual councils to buy and implement on their own

So.....standard process.....umpty-up individual implementations.

How hard could this be?

.....and it might mean that huge corporations (ORACLE, SAP,.....) don't have a lock in with their huge cloud-based products!!

But......what do I know??

Britain enters period of mourning as Greggs unable to process payments

Mister Jones

A Suggestion Or Two......................

(1) get rid of all that encryption kerfuffle used for payments

(2) replace with good old EBCDIC (mmmmmm....maybe UTF-8.....maybe ASCII) 80-column stuff

Less code, smaller network traffic, simpler hardware (you know 8086 and 16 bit assembler).........

No huge costs for "the cloud".......less money for Jeff Bezos.......

Simples!!!!

Oh....and the SW1 contingent behind the Online Safety Act 2024 would just LOVE THIS SUGGESTION TO DEATH!!!!!

German defense chat overheard by Russian eavesdroppers on Cisco's WebEx

Mister Jones

Paranoia Is Mandatory In 2024!!

The Americans were listening in to Angela Merkel's phone.

The British were listening in to Belgian telecoms (targets unknown).

The NSA is istening in to almost any voice communication in the USA (and maybe elsewhere too).

Oh......and then there's a long tradition of Fort Meade "influencing" the design of Cisco equipment.

So why is anyone surprised when we learn that the Russians have figured out some of the Fort Meade "enhancements" to Cisco products?

....and not just WebEx!!!!

Quote (William Burroughs): "The paranoid is a person who knows a little of what is going on."

Meta's pay-or-consent model hides 'massive illegal data processing ops': lawsuit

Mister Jones

Re: Don't Understand....................

@Helcat

....but who says that when the customer pays up, Meta does actually stop data collection?.....and actually stops selling stolen data?

Who....exactly....will validate that the processes at Meta ACTUALLY DO STOP?

I can only see a promise to stop pushing advertising!

iFixit tears Apple's Vision Pro to pieces

Mister Jones

No mention of......

....the software needed to make this device work.......

Ah.....if you thought the hardware was expensive, just wait till you see the software SUBSCRIPTION biils!

Teardown finds Huawei's 5nm notebook processor was made in Taiwan, not China

Mister Jones

Re: Love This Conversation About Taiwan VS China VS USA.....

@Mage

........and your point is.......exactly what?

Yes....INMOS was an interesting UK company.......which led exactly where?

Growth......growth is the subject. Growth might mean.....more jobs....more personal income....more profits.....more dividends.....greater ability for ordinary folk to buy houses.....

Where does INMOS figure in that picture?

NHS England published heavily redacted Palantir contract as festivities began

Mister Jones

A Bit Wider Than Worries About Palantir......

One central argument for centralised data is that there are huge benefits for improvements in diagnosis, and then perhaps improvements in treatment.

We are also told that personal privacy is protected because the records are "pseudonymised".

Unfortunately, the Government completely fails to mention some central arguments about risks:

(1) https://www.theguardian.com/technology/2019/jul/23/anonymised-data-never-be-anonymous-enough-study-finds

(2) No mention of "data in transit"..... focus only on a final "central database"

(3) Never mind Palatir SELLING the data, or otherwise abusing trust, what about unknown third parties HACKING the database

Then there's the relaibility of each NHS Trust in the first place:

(4) https://www.ft.com/content/6954971e-5d3a-11e9-939a-341f5ada9d40

(5) https://www.theguardian.com/technology/2017/jul/03/google-deepmind-16m-patient-royal-free-deal-data-protection-act

And even Government agencies routinely ignore the law......never mind Palantir:

(6) https://www.theregister.com/2022/01/10/ipco_report_2020/

Yup........It's not just that Palantir is a "contract too far".....Government agencies, NHS Trusts, and the basic technology are all BIG RISKS too!