The Register Home Page

* Posts by Frank Bitterlich

569 publicly visible posts • joined 9 Nov 2007

Page:

Utah tells porn sites to take the P out of VPNs, and it's their fault that they can't

Frank Bitterlich

If only the East Germans had VPN back then...

In East Germany it was forbidden to watch or listen to West German TV and radio stations. Many people did it anyway. Except for the people in a certain area in Saxony, who were living in a valley that made reception of West Germany broadcast all but impossible. Back then, that area was called the "Valley of the clueless" ("Tal der Ahnungslosen") because they had to make do with the propaganda brodcast from the East German stations.

People from some small towns and villages, sometimes with the support of local officials, conspired and set up disguised TV antennas on nearby mountaintops and other suitable locations. Not even geography could prevent them from accessing information and news.

Utah is apparently trying to do what the East German government failed to achieve: controlling access to information, and thereby transforming the whole state into a new "valley of the clueless". In addition to the impossibility of this, one has to be amazingly shortsighted to ignore what the outcome of that would be. Large parts of the country are already demonstrating what a lack of education can lead to, and I'm not so sure that the economic success of Ohio will be stimulated by choking and controlling the internet. "Who needs an open internet? You should read the bible instead." Good luck, Ohio.

If malware via monitor cables is a matter of national security, this might be the gadget for you

Frank Bitterlich

Re: I have doubts...

I guess that may be true for the Display Data channel, but I'd expect any meaningful hacking happening over the Ethernet channel.

But even validating the DDC traffic would be a tall order for such a tiny device, considering the hodgepodge of different protocols potentially running over that channel... not impossible, but a pretty ambitious goal. I'd rather expect it to break some more exotic (but legitimate) uses.

Frank Bitterlich

I have doubts...

So there is a new device that claims to protect us from hypothetical threats, all of them, regardless of the type of threat or which method they use, everything "malicious" is being filtered out, without hampering the the actual use of the data channel for legitimate purposes, and they can't tell us how it works, we should just trust them.

Is it me, or does that sound totally crazy?

Hope your holiday was horrid: You botched the last thing you did before leaving

Frank Bitterlich

Re: "That Box Full Of Old Tech You Should Probably Have Thrown Out But Kept Just In Case"

So, you think I shouldn't throw out my 1st gen iPod yet?

Betting shop bug ends in kidnap plot as staff turn ransom artists

Frank Bitterlich

Re: whut?

Manager rescued 90 minutes after the kidnapping.

You can now run WSL on Windows 95, in case you're crazy, too

Frank Bitterlich

Re: Can it run Linux?

I was about to ask "Can it run Wine?", but then I remembered the "no GUI" part... what a pity.

Elon Musk wants to build 50 times more chips than the world currently produces, using 'new physics'

Frank Bitterlich

Ten billion humanoid robots?

I guess that about half of them will eventually sport a sticker claiming "I bought this before Elon went crazy".

CERN sends AI-trained robot mice scurrying through LHC beam pipes

Frank Bitterlich

Hope they're counting them

I just hope that they keep good track of how many on these "mice" they sent in there, and how many came back out.

Otherwise I see an interesting submission to "Who, Me?" in the future.

Here’s your worst nightmare: E-tailer can only resume partial sales 45 days after ransomware attack

Frank Bitterlich

Re: This shows a clear gap in the market

Most can be pwned by two black sheets of paper taped into a loop. Ah, the good old days... never got around to testing my idea of faxing someone a roll of tissue paper, though.

UK asks cyberspies to probe whether Chinese buses can be switched off remotely

Frank Bitterlich

Re: Well... yeah, but nah?

So true... and the idea that they can just "remove the SIM card" and everything is fine is just ridiculous. That certainly won't fix a bricked bus that has downloaded and installed a malicious firmware update. Unless the bus has a "bad firmware incoming" indicator light, of course.

North Korean spies turn Google's Find Hub into remote-wipe weapon

Frank Bitterlich

"... an easy way to destroy evidence"...

I think the problem here is the word "easy". If all that is between you and a remote wiping of your phone is a password, then... Good night and good luck.

Excel is three sheets to the window on iOS as update borks everything

Frank Bitterlich

Share and enjoy!

Share and enjoy!1, 2

1"Share and enjoy" is the company motto of the hugely successful Sirius Cybernetics Corporation Complaints Division, which now covers the major land masses of three medium-sized planets and is the only part of the Corporation to have shown a consistent profit in recent years.

2"Sirius Cybernetics Corporation" used to be called "Microsoft" until their renaming in the year 2035, in an effort to save the reputation of the company.

Viking 1 at 50: NASA's first raid on the red planet

Frank Bitterlich

A tape drive...?

A tape drive? Considering how hard it is to get them working reliably even down here, that's a pretty remarkable thing...

PRESS RECORD AND PLAY ON TAPE

Trump officials float plan for Americans to share their medical data more freely

Frank Bitterlich
FAIL

Upload your CMS QR code here...

... and get a FREE BIG MAC!

Trae AI IDE quietly beams data to ByteDance, even with tracking turned off, report says

Frank Bitterlich

It's the response that counts...

If someone reports suspicious behaviour, looking at the response of the company (beyond boilerplate press releases – "We take the security of our customers' data very seriously...") is way more interesting than the report itself. If the author of the report is block from their support forums, that's more than a red flag. Stay away from Gretchen.

A software-defined radio can derail a US train by slamming the brakes on remotely

Frank Bitterlich

So this is what CISA thinks?

"To exploit this issue, a threat actor would require physical access to rail lines, deep protocol knowledge, and specialized equipment, which limits the feasibility of widespread exploitation."

OK, to recap: CISA thinks that (a) knowledge of the protocol and (b) owning "specialized" equipment (a $200 SDR transmitter) "limits the feasibility" of "widespread exploitation", and so everything is fine? What an absurd take on this risk.

But then, the US has always had weird ideas about "security" – otherwise the concept of a credit card number wouldn't exist.

Odd homage to '2001: A Space Odyssey' sees 'Blue Danube' waltz beamed at Voyager 1

Frank Bitterlich

Music is universal... not

Given the differences even between what my neighbour and I consider to be "music", it is more likely that this is seen as a threat, a declaration of war, a capitulation or a guacamole recipe, than a culturally significant musical movie reference. Or maybe to them, it's just muzak. If we're lucky, we'll never find out.

Signalgate lessons learned: If creating a culture of security is the goal, America is screwed

Frank Bitterlich

It doesn't need "super-spyware"...

Sure, Signal may be pretty secure in its transport, and it is usually easier to compromise one of the endpoints than to attack Signal itself. That is why security-conscious people would at least use a locked-down, dedicated device for such adventures.

However, seeing this whole dumpster fire of security blunders, do you really believe that the "personal device" Hegseth is using on that unsecured line is really protected? To me he seems like the guy who would double-click any attachment named "cute_kitten_videos" and disables the AV because it interferes with his ability to install cracked games.

He probably airdropped a .txt file containing the sensitive info onto his laptop so that he could copy and paste whatever he wanted to brag about to his wife and his hairdresser. And since Hegseth didn't make the one mistake yet that could endanger his job – making Trump look bad in such a way that even Trump notices – this will likely not be the last of these blunders. Only now just about every bad guy on the planet is trying to find out the IP address of his private insecure line or his iCloud username.

Cook'd: Judge says Apple lied to court in Epic case, asks Feds to mull criminal charges

Frank Bitterlich

App Review Guidelines have been updated

Looks like Apple is taking this seriously. They have already updated the App Review Guidelines, 3.1.1 thru 3.1.3, removing pretty much all prohibition of links to external payment systems etc. for "apps on the United States storefront".

Whatever that means for apps which are available worldwide...

Meta to feed Europe's public posts into AI brains again

Frank Bitterlich

Re: Legitimate interest

But... but... the heading on their cookie banner said "We Respect Your Privacy", ...?

And these 876 partners they're sharing your visit and every interaction with, are really close partners, right?

And they only need to track you across every thing you do on the internet for your own good, see? Like Meta's response said... what good would an AI be that doesn't understand European culture? For example, why we're so picky with who can process our most private information and so on...

European Gaia mapping satellite is retired but proves very tough to kill

Frank Bitterlich

Re: -.. --- -. .----. - / .--. .- -. .. -.-.

Whatever they're overwriting the disk with – the engineers' names, the Hitchhiker, a GIF version of the dancing baby, or a Fortran version of the source code of Microsoft's Clippy, – will probably turn out to accidentally be valid machine code that the sat will execute when it eventually reboots.

For the rest of that story, please refer to the already mentioned "V'ger" storyline in the Start Trek movie...

Top Trump officials text secret Yemen airstrike plans to journo in Signal SNAFU

Frank Bitterlich

Re: The Means were not Insecure

The thing is, it doesn't matter whether the "channel" was secure. Every channel has at least two ends, and in this case multiple, and they were all on devices which had not been secured for classified communications. (Signal would't be allowed on such devices.) So we have no way of knowing whether any of these devices were or are compromised. And if they are, the chat contents are compromised, too.

I'm pretty sure that there are already bounties being offered for hacking Goldberg's devices, though I'm also sure that he is taking precautions. But he's now a high-value target, and from what I've heard, some of the information in that chat would still be useful to adversaries after the actual mission is over.

Sure, the tool (I mean Signal, not Waltz) was secure. And of course some idiots will claim otherwise (just waiting for the US govt themselves to blame the whole affair on Signal.) But focussing on that takes the focus away from the criminal negligence, incompetence and disrespect for law and rules of that whole government.

Stuff a Pi-hole in your router because your browser is about to betray you

Frank Bitterlich

Re: Better solutions ? - try pfblockerNG (a PiHole on steroids)

Wait... what? You believe that using HTTPS doesn't protect you, and that you "identify" yourself to "Google etc." when you use HTTPS?

What have you been smoking?

I thought that the "I have nothing to hide" and "I don't need a secure connection for everyday stuff" faction had long since dies out, but here we go... I think you might be wearing your tinfoil hat the wrong way.

HP deliberately adds 15 minutes waiting time for telephone support calls

Frank Bitterlich
Mushroom

Thank you very much...

... but I don't need any further reasons to avoid HP like the plague. I think things like a printer telling me that it doesn't approve of where I purchase my ink from and therefor self-destructs are a clear enough message about what they think about their customers.

XCSSET macOS malware returns with first new version since 2022

Frank Bitterlich

OK, I don't get it.

All the reports about this malware are a bit unclear or ambiguous on the infection vector.

The TrendMicro report says, "Affected developers will unwittingly distribute the malicious trojan to their users in the form of the compromised Xcode projects,..."

Does that mean that the malware is passed on only in Xcode projects, and not in the built apps? Since when are developers distributing Xcode projects to their users? At first I thought this was a typo or something, but it also says: "These Xcode projects have been modified such that upon building, these projects would run a malicious code. This eventually leads to the main XCSSET malware being dropped and run on the affected system."

So the malware is executed when an Xcode user builds an application (as opposed to injected into the product)? Or are they just completely confusing projects and products?

Can someone with more understanding about this malware please clear things up a bit?

Coordinates of millions of smartphones feared stolen, sparking yet another lawsuit against data broker

Frank Bitterlich

Privacy control

You can typically decide which data an app can access. However, it is technically almost impossible* to enforce what an app or service does with that data, especially when the function of that app depends on that data being transferred to a server (eg. Tinder etc.) You can require app vendors to have comprehensive privacy statements, but these are mostly just "swindle sheets".

"We value your privacy. In order to provide you with this service, we share your data with 975 partners. This is necessary because, well, um, we want the money."

* For any references to how useless the GDPR is thanks to the concept of "reasonable interest", please refer to any one of my other rants here on this forum.

Frank Bitterlich

"unjust enrichment"?

Since when is unjust enrichment illegal in the United States?

Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims

Frank Bitterlich

"Shiny Flashlight requires access to your photo library, your contacts, text messages and phone log to function properly. Allow?"

Eggheads crack the code for the perfect soft boil

Frank Bitterlich

Time is of the essence

If I have the choice of (a) having an egg the consistency of either a tennis ball or a fresh oyster, or (b) having to wait more than 30 minutes for a breakfast egg – I'd rather take the egg. Now. Not in 30 minutes.

And let's not even start about having to juggle an egg between two different pots for half an hour.

UN's aviation agency confirms attack on recruitment database

Frank Bitterlich

Possible Security Deviation

"I've got a phone number for you to call after landing. Advise when ready to copy."

FTC drops hammer on unwanted subscriptions with 'click to cancel' rule

Frank Bitterlich

Goodbye Adobe, then...

... it was nice to know you. (NOT.) I like the "... immediately halt charges" part best. That will destroy quite a few deceptive business models.

"Subscribe here for $5/month. Cancel anytime*."

* Your cancellation will become effective after completing the mandatory first five years. Cancellation fee $250. To cancel, send a letter by diplomatic courier to our customer service department in Kabul.

And about that "[T]his rule will have major harmful repercussions for the marketplace", yes, that's the point. Especially for that dystopian Mad Max arena you call "autorenewal marketing".

Scientists demonstrate X-rays as a way to zap asteroids out of Earth's path

Frank Bitterlich

Wrong approach...

According to some documentary I've watched recently ("Don't look up"), wouldn't it be, say, for example, Elon Musk's job to take care of such threats?

Did you hear the one about the help desk chap who abused privileges to prank his mate?

Frank Bitterlich

More fun with Linux...

These days leaving your unattended machine unlocked can lead to situations quickly getting out of hand...

alias cd="rm -rf"

Woman uses AirTags to nab alleged parcel-pinching scum

Frank Bitterlich

Re: "police declined to pursue the matter"

Things were so much simpler in The Good Old TimesTM...

My parents gave me a very cheap, three-digit combination lock with my very first (also very cheap) bike. One day when I came back from a friend's house, it was stolen. Not the bike. The lock. The bike was still there.

I'm still not sure whether that says more about the quality fo the lock, or the bike...

Cisco calls for United Nations to revisit cyber-crime convention

Frank Bitterlich

Re: AHCTEACICOCTUOIACTFCP

I'm pretty sure in Cyrillic it means something. Something like "Gotcha, you fools!" or so.

Twitter must pay over half a million to unfairly dismissed Irish exec

Frank Bitterlich

Delighted...

... to see the Reg calling the platform by its old name. Even if it's just to troll Musk.

Punkt MC02: As private, and pricey, as a Swiss bank account

Frank Bitterlich

Their website is very secure, too...

.... so secure, in fact, that it is completely down at the moment.

Hello? Emergency services? I'd like to report a wrong number

Frank Bitterlich

"... this isn't true..."

... or would depend on the country, the configuration of the PBX system, and - as someone noted - the century.

In my place, whatever you dial, if you're not dialling the trunk prefix (typically 0), you'll reach either an internal number, or nobody at all. And everybody in the (/ any) company is familiar with that.

CrowdStrike unhappy about Delta's 'litigation threat,' claims airline refused 'free on-site help'

Frank Bitterlich

Going after Microsoft is a bit of a stretch

I'm the first one to bash MS any day. But going after Microsoft with the reason that the faulty software affected only Windows machines seems like a bit of a stretch to me.

That's like suing Apple if I buy a shoddy iPhone charger on Amazon from the well-known HZRYGWUL brand store and the charger catches on fire. "After all, my Android phone wasn't affected."

Microsoft's Azure networking takes a worldwide tumble

Frank Bitterlich

"Share and enjoy!" – Sirius Cybernetics Corporation

"We apologise for any inconvenience caused." – That should be Microsoft's corporate motto.

Failure to follow proper procedures caused US-wide AT&T outage, FCC says

Frank Bitterlich

I'd like to understand...

...more about the "protection mode" that was triggered. So a network device was installed that triggered some kind of watchdog system and, instead of just isolating the faulty new component, it somehow brought the whole network down.

I have no clue about how mobile networks are being run. I do understand that many layers of safeguards are necessary to protect the network from faulty/compromised/wrongly configured components. But surely the protective response can't be "let's shut the whole network down". So why did it happen? Was that protection system behaving as designed? Was it built to protect against a different scenario, and made the whole problem worse? Or was it designed to do exactly that to protect against some even more undesirable consequence by disconnecting all devices?

North Korea likely behind takedown of Indian crypto exchange WazirX

Frank Bitterlich

Press Release – Draft

"You gave us your money, and we promised to keep it safe. Except we didn't. But we really thought that rolling our own wallet security would actually work, an so we couldn't really expect that it didn't. So, Force Majeure. But fret not – we are looking into who stole your funds. And in the unlikely case we can pin it somebody more concrete that 'it was the norks', we will share their phone number with you, so you can try to recover your funds. Thanks for your business, and come again (in case you still have some money left)!"

Dangerous sandwiches delayed hardware installation

Frank Bitterlich

Re: "a very sheepish football fan"

Correction: "[...] only to find a large group of hungry men in full bomb squad gear with guns munching on his sandwiches."

Car dealer software slinger CDK Global said to have paid $25M ransom after cyberattack

Frank Bitterlich

"Still, $25 million is apparently nothing to the industry-wide damages that this incident caused."

Keeping in mind that these $25M are being used to finance the crooks and their operations, allowing the to hire even more talented hackers, and also being a huge advertising for cybercrime, with its "crime pays" message, I think the total bang-for-the-buck ratio of these $25M is several magnitudes higher.

And that's the problem: by paying $25M, the company saved a few million in costs to other scenarios, but caused a damage that is ten to hundred times higher to future victims. And I think they should be liable for this. I'd like to see a class-action lawsuit from future cyber-attack victims against companies that are willing to finance criminals just to keep the cost and consequences of failing to secure their own systems lower. And I'd like to see a smart AG to open a case showing how paying ransoms like this constitutes "material support" of criminal organisations.

All in all it should be more expensive for corporations to pay the ransom than not to. That's the only way to stop this.

I'll keep dreaming.

EU grants €15M funding for ICARUS inflatable heat shield

Frank Bitterlich

Re: “Inflatable heat shield”

I know, right? After all, we all know they can't go to space (wouldn't get past the dome), and also, why a heat shield? Everybody knows the higher you go, the colder it gets. And now the reptilian leaders want to sell us using an inflatable rubber dingy to use as a heat shield. It's obviously a scam to hide the secret colonies on the backside of the moon. They should rather spend that money in making free energy available to everybody.

(Just to be sure: /s.)

US watchdog chases Waymo robocars to catch violations

Frank Bitterlich

You sure they are automated?

"The incidents include collisions with objects like gates, chains, parked vehicles, as well as showing an apparent disregard for general traffic safety. [...] including its vehicles entering construction zones or heading toward oncoming traffic, [...]"

To me that sound like typical taxi driver behaviour. Are you sure they were talking about automated cars?

/s

Google thinks AI can Google better than you can

Frank Bitterlich

That will probably be very helpful...

... as long as you don't ask Google "How many fingers|legs|arms does the average human have?"

I wonder how well the AI will deal with Google already messing up your native search results. Ask for the nearest restaurant, and Google will ask back whether you have considered buying a new kitchen instead. If that is the input to the AI search assistant, then the result will be worse than Midjourney attaching a few extra arms to everybody on your faked Christmas family photo.

Brain-sensing threads slip from gray matter in first human Neuralink trial

Frank Bitterlich

I know what it is...

They probably used the same type of cable as the iPhone charging cable. Frayed after a few weeks even when sitting unused in a drawer.

GhostStripe attack haunts self-driving cars by making them ignore road signs

Frank Bitterlich

There are other ways...

Other ways to do this involve a trash bag and some duct tape. Makes the stop sign practically invisible.

UnitedHealth CEO: 'Decision to pay ransom was mine'

Frank Bitterlich

Re: And off to jail you go

It might not be illegal in a criminal sense, but I hope that from now on every victim of that ransomware group will sue Witty (personally) for damages, for being an accessory to ALPHV in their "business". He certainly contributed to their finances quite a bit.

Page: