* Posts by Vic

5860 publicly visible posts • joined 7 Dec 2007

Dodgy software will bork America's F-35 fighters until at least 2019

Vic

Re: Next week's "Line Break" article....

so then the whole plane has to be restarted, at 30,000 feet, lol

That's really no big deal.

Restarting at 300ft - yeah, that's you in the hole[1] in that field.

Vic.

[1] Yeah, the *new* hole...

Vic

Re: How's that for planning ahead ?

Brand new carrier won't have any planes for half its life span.

That wouldn't have been nearly so much of a problem had we not sold off the planes we had that would have worked[1] long before the replacement is ready...

Vic.

[1] Yes, I know Harriers wouldn't have been that great a solution. But they'd have been better than no aircraft at all...

Vic

Re: Can someone please...

most of the flaws related to the F-35 are related to the human being actually in the plane

No, absolutely not.

Whilst I daresay there are some such flaws, substantially all of the problems it is currently facing are down to the design being a sack of wank. Pilot presence is the least of the problems...

I guess it's the bravado factor.

Not entirely. I read some research a few years back that reckoned that pilots who were actually on-station were more empathetic towards their targets, making them somewhat less likely to bomb weddings, etc. I cannot prove the veracity of that claim, however.

Vic.

Vic

Re: @Ledswinger

If your design schedule is such that technology that isn't available at the start of the process will be obsolete by the time you deliver you're doing it wrong.

Whilst I would not attempt to refute your point, I would point out that the situation you describe is entirely normal in aerospace projects...

Vic.

Vic

Re: @bri

The F35 programme should cancel the B variant

If you're going to return the F-35 programme to any semblance of cost-effectiveness, the A and C variants need to be canned as well.

The F-53 was originally touted as a cost-down F-22. It appears that it will end up being much more expensive, much less capable, and probably much more dangerous to the pilot...

let the UK government sort out their own S/VTOL needs

If the UK government hadn't bought such wank carriers from BAe, we wouldn't need STOVL. Alternatively, if we fitted EMALS, we wouldn't need STOVL. But BAe insists that the EMALS retrofit - on carriers for which we paid significantly more for them to be modular and modifiable - is going to cost as much as a new build. Despite the fact that General Atomics - the manufacturer of EMALS - quoted an order of magnitude less...

Vic.

Vic

Re: A boondoggle through and through and now ejection seats are also a problem?

the Harrier is a better all round aircraft

No, the Tornado is a better *all-round* aircraft. Harrier suffers from a few nasty issues like being mostly unable to return with unused ordnance.

But for the things that Harrier was designed for - STOVL, VIFF, etc. - it is unparallelled.

The F-35 attempts to combine the roles of both aircraft, along with a few extra WTFs. And it fails at all of them, so far :-(

Vic.

[Who flew an RV-7 this afternoon and is still grinning like an idiot]

Microsoft files patent for 'PhonePad', hints at future Windows plans

Vic

Re: Linky

Not sure it seems hugely inventive

It seems to be re-inventing quite a lot of what we were doing 20 years ago in HAVi

Vic.

Error checks? Eh? What could go wrong, really? (DoSing a US govt site)

Vic
Joke

Re: But the program is error free!

"Halleluja, It Compiled! It Compiled!"...

For some of the developers I have met, this alone is a fucking miracle.

Why do you think there is so much interpreted code around these days?

Vic.

It's nuts but 'shared' is still shorthand for 'worthless'

Vic

Re: All well and good

How do you mesh this with the cutthroat world of today where "you only live once" and "you fail = you're dead"?

You need to introduce risk gently, so that proper assessment and mitigation becomes part of the experience of growing.

If the first time you experience risk is a life-threatening situation - you run the risk of not surviving that learning process.

TL;DR: we shouldn't wrap kids in cotton wool all the time.

Vic.

Google publishes list of Certificate Authorities it doesn't trust

Vic

Re: Since users too often click through those warnings.

As an admin is there actually ever a good reason to even allow such a behaviour on client PC's?

I have an invalid certificate on my webmail server. It is deliberate.

From time to time, I will find myself on customer site where all the machines trust a local CA, and there is a MitM machine to intercept HTTPS traffic. I don't want my data to be intercepted. Thus, if I *don't* get a certificate warning when I try to connect, I know I cannot use my webmail from that location...

Vic.

Azure's wobbly day as three services glitch around the world

Vic

Re: Interesting...

not a peep about El Reg's "wobbly day". Error 524 or 5 march 2016. Down for hours

El Reg has had a couple of those now. I'm still waiting for the article guffawing at such occurrences...

Vic.

How one developer just broke Node, Babel and thousands of projects in 11 lines of JavaScript

Vic

Re: Thames

Or would you code a site in C++?

I've coded sites in C, using apxs.

I'm not going to claim it's suitable for everyone, but in the right set of circumstances, it gives you a very performant site for minimal coding difficulty. Sometimes, that's the right choice.

Vic.

Your money or your life! Another hospital goes down to ransomware

Vic

Re: And the moral is.......?

Another is that every operating system allows any program to write to any file based on user privileges only. If, for instance, only your office suite was allowed to write to word processor files and spreadsheets a random encryption program couldn't touch them

SELinux provides exactly that protection...

Vic.

French publishers join Swedish 'Block Party' to pester ad refuseniks

Vic
Thumb Up

Re: I'll make you a deal...

Your ads won't use flash

I like Flash ads.

As I do not have Flash installed on my machine, they end up being self-blocking. Which is nice.

Vic.

Comms 'redlining' in Brussels as explosions kill up to 30 people

Vic

Re: getting close to home

Hopefully makes you think that the beer's lovely, and so are the restaurants

Yep. I went to Belgium about a month ago. I was surprised to find how much I enjoyed the bits of it other than the beer[1].

Vic.

[1] Which was, of course, magnificent :-)

Ofcom wants to crack down on pisspoor BT Openreach biz lines

Vic

Re: The whole thing is a crock of s**t for everyone

I'm with Eclipse, and in my area OpenReach rolled out FTTC at the end of last year. Since then, the ADSL drops out infrequently due to interfearence on the line.

I used to be with Eclipse. I had fairly frequent drop-outs.

I sent them my router logs - clearly showing double-CHAP requests. The first would succeed, the second would fail. But they claimed this was clearly a fault in my equipment, as if there was anything wrong at their end, everyone would be complaining.

I left Eclipse. I went to A&A. I still use all the same kit[1], but the drop-outs no longer occur...

Vic.

[1] They did send me a new router - which would improve my speed. But I haven't quite got round to installing it yet :-)

True believers mind-meld FreeBSD with Ubuntu to burn systemd

Vic

Re: Haters gonna hate

I like that when I insert a USB thumb drive it can automatically FSCK it if needed.

I don't. I want my devices to stay intact until I decide to do something with them.

This sort of thing means that forensic examination is no longer possible - if the device is altered as soon as you plug it in, your evidence is destroyed.

Vic.

Microsoft to add a touch of Chrome to Edge

Vic

run any ware

I really hope that was a deliberate joke that I didn't get...

Vic.

What to call a £200m 15,000-tonne polar vessel – how about Boaty McBoatface?

Vic

Re: Noooo...!

you can't put a ship on a boat

Sure you can.

Probably just the once, though...

Vic.

'Just give me any old date and I'll make it work' ... said the VB script to the coder

Vic

Re: Prisoner release dates

there is also loss of remission for bad behaviour to be taken into account (which was calculated as days added to the determined release date, not to the sentence, but still before taking into account weekends and Bank Holidays).

A mate of mine did some time in an Army prison some while back. The approach is, apparently, rather simpler: you are sentenced to n days in prison, but that is "serving under sentence", and you are expected to obey your commanding officer during that time. So if you do something wrong - you are not serving, so that day does not count as one of the days of your sentence. You are, quite literally, wasting your own time...

Multiple sentences, for example 6 months for a primary offence and two consecutive 3 month sentences to run concurrently, make things interesting as it is not always obvious which is going to be the longer.

OO programming is your friend...

Vic.

Vic

Re: Visual Basic

Your mission is to find cases where a function or procedure that expects a Date (probably along with lots of other arguments) is passed a String or Variant

Ah, so you're an awk man[1].

Vic.

[1] I wrote some code a few years back to expose the symbolic constants from C header files as Forth words. The heavy lifting in that was all done in awk. It's worth the effort...

Michigan shooter says 'mind controlling' Uber app told him to kill

Vic

Re: Dalton

He claimed a machine had been implanted in his stomach (I forget by who or what) that was telling him to kill.

That's Videodrome, isn't it?

Vic.

Vic

Re: Typical narrative in the US

can I please be the field technician during the making of the documentary?

Derren Brown did a programme called "The Assassin"[1], in which he get a member of the public to assassinate[2] Stephen Fry on command. After the shooting, the assassin sat back down with no recollection of what he had done...

Vic.

[1] There are YouTube links for it, but Channel 4 seems to have been around and had them all deleted.

[2] Of course it wasn't a genuine assassination. But the gun was real, as was the action to use it. If there had been a real bullet in the gun, Stephen Fry would have been dead.

Millions menaced as ransomware-smuggling ads pollute top websites

Vic

Re: WCPGW

I think all managers need to have a bronze plaque installed on their office wall for every time they ignore warnings

I think they need a lead plaque installed on their ankles every time they ignore warnings.

Then, at month-end, we throw them in the canal.

Vic.

Want to kick butts? Go cold turkey

Vic

Re: Everyone in the study used NRT

Short term, no-one has produced methodologically sound evidence of any serious harm

Given the provenance of Nicotine and the known toxic effects, it would be a brave man that says there is no risk. But compared to everything else in a cigarette? It's clearly dramatically safer...

Vic.

Vic

Re: Everyone in the study used NRT

Current best way to stop appears to be e-cigs and support of a stop smoking service

That depends on how you define "best".

I know a few people that have used Champix. As an aid to stopping smoking, it is very effective - but beware the side-effects. This is not a drug to be taken if you live on your own...

Vic.

Watch six tiny robo-ants weighing 100g in total pull a 1,769-kg family car

Vic

Re: Skynet's chariot

"Don't tread on an ant, he's done nothing to you

There might come a day when he's treading on you"

Have you unplugged the jukebox yet?

Vic.

Linus Torvalds wavers, pauses … then gives the world Linux 4.5

Vic

Re: PS/2 Mice

do you still need to reboot after inserting a PS/2 mouse or keyboard for it to be recognised?

That seems to depend on the motherboard; some cope just fine with hot-insertion. And some don't.

Vic.

Shock: Russian court says Russian court is right in slapping down Google monopoly

Vic

Re: Much as I hate to say...

Can you tell some more about that? Personally, I regularly download 'free' apps and I've never been asked for a card on the play store.

I also keep getting a popup that I need to add a card.

There is a "skip" button; it works, but you will get asked again...

Vic.

Linux fans may be in for disappointment with SQL Server 2016 port

Vic

Re: Perfectly understandable

But not from Linux, which has a big capability gap here.

Bullshit. Linux has the same capabilities, as well as a few more. You do not know what you are talking about.

Even the slightest technical knowledge about SUDO would tell you that's EXACTLY how it works so you clearly don't understand the subject matter - /usr/bin/sudo must be owned by uid 0 - the next time you run SUDO, type echo $UID

[vic@perridge ~]$ sudo echo $UID

[sudo] password for vic:

1000

Oh look - it's not 0.

[vic@perridge ~]$ sudo -u jetty -s

bash-4.2$ echo $UID

991

Still not 0.

The sudo binary must be owned by root to have its capabilities - but that does *NOT* mean that anyone that uses sudo gets root capabilities, nor that they become root explicitly[1]. You do not know what you are talking about.

I don't know whether you're paid for this crap, or whether you get some sort of kick out of it, but your knowledge is so substantially wrong, you're really not doing anyone any favours here. Read the man page - you might learn something[1].

Vic.

[1] Becoming root *may* be permitted, according to how the sudoers file is set up. But it is one of many ways to run sudo. You might want to find out some of the others, as they competely destroy your assertion.

[2] This does, of course, presuppose an open mind. So maybe you won't.

Vic

Re: Perfectly understandable

How about constrained delegation:The ability to give an account only the minimum rights required for a specific task.

You do know that idea came from Unix in the first place, right?

Not a bodge like SUDO that MUST have root access (UID0) to work.

Even the most cursory reading of the man page would show you that's total cobblers.

I could go on

I wish you wouldn't; your lists of supposed advantages are invariably full of schoolboy errors and incredible misunderstandings.

Vic.

Vic

Re: Perfectly understandable

How do you ensure that the guests are backed up at a consistent point-in-time?

I'd do it with LVM snapshots. But others will have their own pet methods.

Vic.

Polite, helpful? Stop it at once in the name of security

Vic

Re: Easily turned around...

plenty of organizations, where Sony is the most obvious example, had very specific polities for user passwords to make sure things were safe

I used to have a very simple rule for password complexity.

I would run john against the shadow file overnight. Any accounts that got cracked in less than an hour would be locked...

It was surprisingly effective - especially as you found out which accounts weren't being used at all[1].

Vic.

[1] I had inherited the userset, amongst which were many remote workers. It was quite clear that some of the accounts were dormant, as no-one ever asked me to unlock them.

Computer says: Stop using MacWrite II, human!

Vic

Re: TROPPUS TI

myths that there are signs in the village, pointing the way to the sea and emblazoned with "Muff Diving" are sadly just that.

There is a Muff Diving Club, though...

Vic.

Go ahead, build better security: it just makes crims try harder

Vic

Re: The syntax police

"He says risk is critical for security executives despite that he admits it is his weakest area." Maybe "despite admitting," or even "even though he admits."

I suspect a semicolon after the word "executives" would be more appropriate.

That said, I suspect the word "understanding" is missing just before "risk"; the alternative really isn't very palatable[1].

Vic.

[1] Although it might be correct as is ::shudder::

Obama puts down his encrypted phone long enough to tell us: Knock it off with the encryption

Vic

Re: hypotheticals?

Perhaps send the "world's most powerful army" to convince them stop encrypting?

You want to invade every country in the world simultaneously to prevent them doing (currently) legal things?

That'll work well...

Vic.

Vic

After that he says that predictions of an Orwellian society are overblown.

Are there any queers in the audience tonight? Get 'em up against the wall.

Vic.

[Don't downvote just because I wrote "queer". Watch the video. It's only four minutes. It has a point to make. In fact, watch the whole film - it is magnificent.]

Vic

Re: "You can't take an absolutist view on this",

No, no. He's right.

All we need do is invent a non-absolutist mathematics and the problem is solved. Calculations that only work for the Good GuysTM.

Vic.

Vic

there is encryption and there is broken encryption. ... Please correct me if I am in error...

You are in error.

There is encryption and there is everything else. Associating this latter with the word "encryption" in any way is incorrect.

HTH, HAND, etc.

Vic.

Vic

Oh, FFS...

Clearly if you have physical possession of the device, you can just read out the flash chips and RAM. You can probably do that via JTAG in minutes... so that's not really an issue.

The data in flash is encrypted.

So yes - you can read it out via JTAG. And you'll be left with an encrypted dump that will take you a few trillion years to decrypt. That will help.

Vic.

UK fella is a multimillion-dollar cyber-hustle mastermind – US DoJ

Vic

to whence

Please. "Whither", if you must...

Vic.

Vic

He owned a fire truck because he always wanted one as a kid

He bought five aircraft and some land. It sounds rather like he was trying to set up an airfield (for which you will need a fire truck).

Vic.

Airbus' Mars plane precursor survives pressure test

Vic

Re: Not all that bad

Not too bad if it's a 4 point harness.

It wasn't the harness that caused the problem. I was laying quite far forward in the cockpit. Then raised the nose sharply...

Vic.

DARPA to geeks: Weaponize your toasters … for America!

Vic

Re: No. Shan't.

Damnit, my hands are weapons.

As are your feet.

One of the best weapons in confined surroundings is a broken bottle.

Yep.

Do you carry a laptop power cable? It takes less than three seconds to tie a clove hitch in one - that's a very effective weapon.

Do you have a sock? Put anything with a bit of mass in it and you have something lethal.

The list is endless. Just don't tell airport security or none of us will ever fly again...

Vic.

Vic

No. Shan't.

I'm not playing this game.

Most things can be turned into weapons with a little ingenuity[1].

So the *best* thing that can come out of such a contest is that I won't be able to buy the things I want to buy. And that's the best outcome...

Vic.

[1] I'm always a little evasive when asked at an ariline check-in if I'm carrying any weapons. The real answer is "yes - and so is absolutely everyone else". But that gets you busted...

Vic

Re: "DARPA's mission is to create strategic surprise"

Would people like Liam Fox be begging on the streets?

ohpleaseohpleaseohpleaseohpleaseohplease

Vic.

Microsoft adds 'non-security updates' to security patches

Vic

Re: What do you have installed?

aww, I lost my badge

I suspect you might have a browser problem; I can see it...

I guess that means I have a life now??

*snort*.

Vic.

A typo stopped hackers siphoning nearly $1bn out of Bangladesh

Vic

Re: I just checked my account

I've (accidentally) paid over £6 for a pint.

Erratum - it was over £8 for a pint.

Still worth it...

Vic.

Vic

Re: I just checked my account

Seven quid for a pint????

I've (accidentally) paid over £6 for a pint.

It's not something I'll do regularly, but it was worth every penny...

Vic.

7,800 people's biometric data held on police anti-terrorism database

Vic

proving someone did NOT do something would require 100% surveillance of that person.

But that's not what happens here; "exculpatory evidence" could be a small amount of surveillance that, for example, provides a watertight alibi. It would require 100% surveillance to guarantee to find all such exculpatory evidence, but that does not preclude some being found in a lesser degree of surveillance.

So I think that is a cover for Parallel Construction

It's possible - but note that in the UK, we don't have the "fruit of the poisoned tree" doctrine, so unless the security services were simply trying to disguise their capabilities, parallel construction is unlikely to be necessary.

That includes passport info which includes all the biometrics for most Brits.

No, not any more. All that big biometric gulp has been abandoned. Current passports contain very little (I think mine just has a digital photograph).

Vic.