The Register Home Page

* Posts by Pascal Monett

19252 publicly visible posts • joined 10 Apr 2007

Smash GandCrab: Free tools released to decrypt files scrambled by notorious ransomware

Pascal Monett Silver badge

Well then, one down, a hundred thousand to go

They say (in the linked article) they have proven that crime can be without retribution. So it's a lot easier to do crime with the Internet, well duh. Did they actually think that needed to be demonstrated ?

With the Internet, you are all over the world, but there is no world police. You can create and launch processes from your computer but they can execute anywhere in the world. If that process is malicious, it will hurt someone who does not have any other possibility to track you down except call the police - who cannot do anything because the perpetrator can likely not be found.

It would take quite a few experts to track the origin of a malware, and it would require local law enforcement cooperation to get the details that would allow an actual arrest. That is not something that is going to happen for issues that are less than a few thousand dollars, because it would probably cost more than that to bring the criminals to justice.

Finally, an AI that can reliably catch and undo Photoshop airbrushing. Who made it? Er, Photoshop maker Adobe

Pascal Monett Silver badge

It's a household name now

The term photoshopped is as common as the notion of googling something. Is there any irony in the fact that the very company who made that happen is now wanting to "keep it real" ?

I think so.

London opens stock market for a tickling from Chinese tentacles

Pascal Monett Silver badge

"deepen our global connectivity as we look outwards to new opportunities in Asia"

Shanghai, a city directly governed by the central government.

But, I thought there were "security issues" when dealing with Chinese companies ?

Does this mean that the Shanghai Stock Exchange is immune to requests from Beijing ?

Or does this just mean that, as usual, money talks and politicians can just stay out of the way ?

Greatest threat facing IT? Not the latest tech giant cockwomblery – it's just tired engineers

Pascal Monett Silver badge
Trollface

"the sympathetic vultures of the Register"

Now, what does that remind me of ?

Oh, right : this.

UK industry calls for delay of IR35 off-payroll tax rules to private sector

Pascal Monett Silver badge

Interesting article, but for one thing :

"The analysis found the UK’s deficit would largely have been eliminated in the 2018-19 financial year if Britain had voted to Remain"

I'm sorry, but I don't believe that for one second. That sentence raises my credibility warning to red alert. There is no way any country will get rid of its debt, and pretending that an alternate reality would have seen debt disappear in just one year is the product of one of two things : either they are smoking some real good stuff, or this is a puff piece designed to damage the government and attempt to reverse the UK population's opinion on Brexit, for some goal I cannot imagine.

In any case, that article contains some amount of smoke and mirrors.

Pascal Monett Silver badge
Trollface

I guess I misunderstood the situation

I thought the UK government just wanted out of the EU, but it would seem that it actually wants out of the economy entirely.

Well, carry on then.

Blighty's online pr0n gatekeepers are begging for a regulatory beating, says digital rights org

Pascal Monett Silver badge

"We want the UK to be the safest place in the world to be online"

Simple : do not let children go online without supervision. Do your bloody job as a parent, instead of using a screen to do your child's education.

And can someone tell me why, for the love of all that is holy, an age verification scheme is voluntary ? Let's be logical : if there is a law that says that age verification is mandatory, then there should be a mandatory scheme to verify age that is compliant with the law.

Get your ducks in order.

HP CFO Cathie Lesjak didn't even read KPMG's Autonomy due diligence before $11bn biz gobble

Pascal Monett Silver badge

Re: OK, that does it!

Totally agreed. It is now official : HP's top management takes the money, but doesn't do the work.

Atari finally launches its VCS console. Again.

Pascal Monett Silver badge

Re: Why the pessimism?

Because the leadership has its mouth full of buzzwords and makes declarations that are the polar opposite of what they are actually doing. On top of that, we are less than a year from launch after two missed launch deadlines and they can't even show a demo unit.

That is not a good sign, and good faith is not enough to produce a working product.

Pascal Monett Silver badge

Re: This is about retro and nouveu combined

Well don't forget to tell us about your experience - if you ever actually get one, that is.

Flight Simulator 2020: Exciting new ride or a doomed tailspin in a crowded market?

Pascal Monett Silver badge

Re: So...

Well, given that Win 7 is EOL, I doubt that Microsoft would allow it's next-generation flight sim to run on that creaking platform.

Even though it could probably use the Win 7 population to get more subscriptions, while teasing them about how much better the game would be in Win 1 0.

Pascal Monett Silver badge
Happy

Welcome to English-speaking journalism. Not having the info is not an impediment to writing an article.

You'll always need VMs says, surprise, VMware: Run on any cloud you like and get portability

Pascal Monett Silver badge

"the industry is sufficiently wedded to VMware technology"

Yes it is, so much so that declaring that VMware is here to stay is not only superfluous, it borders on pandering to the ego of the CEO.

There isn't a single IT department that doesn't use VMs. Heck, even small companies can use it - I know the company I worked for before does, and we were a 3-person shop at the time. Okay, it helped that my associate was a network administrator, but still.

So yeah, VMware has a long and bright future ahead of it. I think we all know that but hey, a successful CEO has the right to stroke himself the right way every now and then, doesn't he ?

Facebook won't nuke deepfakes? OK, let's tear up those precious legal protections from user-posted content, then

Pascal Monett Silver badge

"in order to tackle the rise of deepfakes"

Right, because now that politicians have been the subject of such alterations, We Must React.

That private citizens may have had their lives or reputations destroyed by such activity, or may risk that, is just collateral damage to the great march of Capitalism. We can't regulate that.

But touch the politicians and ohh buddy, then you get their attention real quick.

'AI is not the cause, it’s an accelerant. The pace of change is challenging' Experts give Congress deepfakes straight dope

Pascal Monett Silver badge

"People watching falsified videos of political leaders could be duped into believing lies"

Yeah, well people watching Fox News are regularly duped into that and I don't see anyone doing anything to stop it.

settlement.js not found: JavaScript package biz NPM scraps talks, fights union-busting claims

Pascal Monett Silver badge

"conflicts represent the natural order of the open source world"

And apparently you handle them very badly in your own company.

But hey, it's nice to know that you have such an open mind about the other companies that are sprouting up due to your incompetent handling of your staff.

Not that you have much of a choice anyway.

When customers see red, sometimes the obvious solution will only fan the flames

Pascal Monett Silver badge

Re: Dolt

Agreed. When I am faced with a presumed error that I cannot replicate, it's the first thing I ask for : show me how it goes wrong.

Mirai botnet malware offspring graduates from uni, puts on a suit, slips into your enterprise

Pascal Monett Silver badge

So now IoT can pwn your company

It really seems time to declare a moratorium on this market and freeze sales of all IoT things until the makers can prove that they've understood that they need to think security before thinking product.

It's also time for fusion to become useful, but I'm guessing the latter will happen way before the former.

Gonna be so cool when we finally get into space, float among the stars, work out every day, inject testosterone...

Pascal Monett Silver badge

You can't get pregnant in space, because the guy has no way to get an erection.

In order to become erect, blood needs to pool in the loins, action which can only happen in a gravity well. So, no hanky-panky in space, sorry.

Hacking these medical pumps is as easy as copying a booby-trapped file over the network

Pascal Monett Silver badge

One silver lining

At least the latest firmware is not subject to this particular threat, apparently.

How to upgrade something that is embedded in a person's body is something else though, and given that I already fear upgrading my motherboard firmware*, I shudder to think of me having one of those things inside me that needs upgrading.

* : somehow I never can bring myself to trust those things - I always fear that, after the update, the board just dies and never starts up again

ALIS through the looking glass: F-35 fighter jet's slurpware nearly made buyers pull out – report

Pascal Monett Silver badge

America : the #1 hypocrite

Its mouth is full of God and Freedom but while you're not looking, it rifles through your wallet, stalks you through your phone and captures everything you say, all while screeching hysterically when anyone else tries to copy it.

Okay, let's admit for half a second that this data slurp was thought of "with the best of intentions". The fact remains that any country buying this airframe is basically giving Uncle Sam the complete overview of its strike capability. Ally or not, there is zero reason to accept this.

Talk of pulling out is pure bunkum though - posturing by someone who wants to look tough to his political base but doesn't have the balls to go through with it. No pity here.

More and more America is looking like your unwanted neighbor. He's a bully, a pervert and he's armed to the teeth. And you can't move out.

Meet the new Dropbox: It's like the old Dropbox, but more expensive, and not everyone's thrilled

Pascal Monett Silver badge

"deep integrations"

When I hear those words, my mind immediately translates to "deep fucking of your data".

I am a free user. I only need Dropbox to share a few small files between friends. Those files have absolutely no importance to anyone but us, and anyone who wishes to take a look can have a copy, I don't care.

But if Dropbox starts fucking with me, I'll find another platform in a heartbeat.

Pascal Monett Silver badge

And it is encrypted, you failed to mention.

I started using Sync when I realized that I needed a secure way to have a few highly confidential files available to me whatever the computer I was on.

Before that, I had signed up to Dropbox, but I never put anything confidential there.

Hongmeng, there's no need to feel down: It's patently obvious this is Huawei's homegrown OS

Pascal Monett Silver badge
Coat

Re: Here at last!

Um, if I'm not mistaken, without Linux there would be no smartphone industry at all.

So you're a bit late, but hey, nice of you to have arrived anyway.

Pascal Monett Silver badge

It's just Google kowtowing to the White House.

Just as Google has kowtowed to Moscow, Beijing and basically everybody that is a threat to its revenue.

No Telegram today, protestors: Chinese boxes DDoS chat app amid Hong Kong protest

Pascal Monett Silver badge

Democracy is an eternal uphill battle

We would do well to remember that we are not safe either : complacency is the preferred attitude as far as TLAs are concerned. And if they get caught, they just trot out something about defending the people and mention terrorism, and we go back to sleep.

I wish all the best for the people waking up to the true nature of their government, but we should not forget to remain vigilant ourselves.

Large Redmond Collider: CERN reveals plan to shift from Microsoft to open-source code after tenfold license fee hike

Pascal Monett Silver badge
Flame

Well done, Microsoft

You've managed to find yet another way to shoot yourself in the foot. Congratulations, really.

Oh, and kudos on denying CERN the statute of academic. Honestly, for the life of me I would be really hard pressed to find any other institution, apart from NASA, probably, that is not more worthy of being called an academic institution, but hey, I obviously haven't been through the elite training of your marketing staff.

In any case, bravo. Once again, Microsoft, you have proven that you are the best reason for Open Source software to exist. Way to go. Thanks to you, the world just might finally get a viable alternative to Exchange.

Really, Microsoft, you spoil us.

Now, if you'll excuse me, I have to get a towel to mop up all the sarcasm that is dripping from my screen.

Wondering where that upcoming meeting with 'Cheap Viagra' came from? Spammers beat Gmail filters by abusing Google Calendar, Forms, Photos, Analytics...

Pascal Monett Silver badge

"Spammers are abusing the preferential treatment Google affords its own apps"

Ah, the eternal battle between the sword and the shield. Except, in this case, it looks more the damn holding back the lake has sprung a leak. Or it would be, if the damn hadn't been built with a hole in it in the first place.

In any case, the good thing that is going to come out of this is that Google is now going to have to find a way to vet legitimate messages from its own applications instead of just letting them through.

The fight against spam continues.

Hate your IT job? Sick of computers? Good news: An electronics-frying Sun superflare may hit 'in next 100 years'

Pascal Monett Silver badge

Re: Carrington Event

Or maybe the next superflare will not be aimed at Earth ?

There is, after all, a zone of, like, 359° around the Sun where we are not.

These boffins' deepfake AI vids are next-gen. But don't take our word for it. Why not ask Zuck or Kim Kardashian...

Pascal Monett Silver badge

"We are concerned about such deception and misuse"

Well then don't make it available via a web portal. As long as you're the only ones tinkering with the thing, we should all be rather safe.

Have I Been S0ld? Troy Hunt's security website is up for acquisition

Pascal Monett Silver badge
Thumb Up

I tip my hat

Mr Hunt has done the world a great service in a responsible way. I wish him the best and hope that his efforts will be bolstered by a company or partners that will bring the same respect to his creation that he brought to the public.

US border cops confirm: Maker of America's license-plate, driver recognition tech hacked, camera images swiped

Pascal Monett Silver badge

"the subcontractor violated mandatory security and privacy protocols outlined in their contract"

And all the subcontractor gets is close monitoring ?

That's the problem with all the stern wording and posturing - if you don't follow through, then you're the one who is ridiculous. And, in this case, Perceptics should be thrown out and there should be a complaint filed for gross negligence against the company, with damages.

But Perceptics cannot be thrown out, because the company has its arm entirely in the US Border and ripping that out would be very, very painful. So I'm guessing the CEO went in to make his apology, probably even groveling as nicely as possible, promising that it would never happen again, and left secure in the knowledge that he will be able to keep milking that particular cow for a long while yet.

Because actually holding oneself to the terms of the contract would mean getting another contractor, spending time training the peons on the platform and enduring the inevitable mistakes before they get up to speed, and all that's just too much of a nuisance, right ?

JavaScript tells all, which turns out not to be so great for privacy: Side-channel leaks can be exploited to follow you around the interweb

Pascal Monett Silver badge
Stop

JavaScript is only a threat when it runs

And NoScript stops it from running.

Use NoScript, or any other extension that controls what JavaScript runs and when.

That is what protects us.

No backdoor, no backdoor... you're a backdoor! Huawei won't spy for China or anyone else, exec tells MPs

Pascal Monett Silver badge

Well, that was obviously a well-balanced and thoughtful grilling

"Norman Lamb MP, chairman of the Commons select committee, kicked off the proceedings by asking the executive about Huawei's involvement with governments that have records of corruption and human rights abuses"

I look forward to Mr Lamb's grilling of a Google high-level suit with the same approach.

Oh wait, I forgot : Google is a US company, so it's all good.

Pascal Monett Silver badge

It's all good and nice to be wary of The Man, but telcos are the de facto custodians of our telecommunications, so it falls on their shoulders to make sure our comms are secure.

Unless you prefer your phone provider to just be the NSA ?

Pimp My PowerApp: Microsoft touts AI Builder and augmented reality tools for low-code apps maker

Pascal Monett Silver badge
Windows

Are they that desperate to make pseudo-AI look useful ?

It would seem that everyone and their dog has their mouths full of all this new-fangled AI that isn't AI, and the new use for this tool is counting bottles ?

You don't need any kind of AI to count bottles. Industry has been using mechanical means since the dawn of its inception and that works fine.

We are obviously now in Hollywood mode in this market, they're going to be redoing every simple thing that has already been done, slap the AI sticker on it and wham ! A new AI thingamabob.

Look forward to seeing your AI coffee maker, toaster, microwave, door opener, etc.

Humbug.

TSB appoints new tech transformation chief cuz last tech transformation went really, really well

Pascal Monett Silver badge

Re: Good Luck

Seconded. At least, this one apparently has experience. It would truly be a cap in his feather if he were able to say that he transitioned TSB to a stable state.

DXC Technology exec: What should our brand be known for?

Pascal Monett Silver badge

Re: Who?

Don't worry about it, there's barely been a whisper about them.

Pascal Monett Silver badge
Thumb Down

Whaa, whaa, whaa

"DXC is losing ground to rivals integrators in 'digital programmes' by 'not getting its share of the wallet spend'"

As far as I'm concerned, if you're getting something it's already more than the share you deserve.

When it comes to DNS over HTTPS, it's privacy in excess, frets UK child exploitation watchdog

Pascal Monett Silver badge

An interesting read, but I'm not sure Charles 9's statement is wrong on that point.

Given the obvious governmental push for state surveillance (this DNS stuff, backdooring encryption, shoddy age verification, etc), it would certainly seem that, from a governmental point of view, it's either the police state will keep you safe, or it will be anarchy through and through.

The real problem is that the term anarchy is not used correctly. In Joe Public's mind, anarchy and chaos are the same thing, but that could not be more wrong.

Anarchy is, philosophically speaking, the ideal society ; anarchy is where there are no leaders because everyone pitches in and gets the job done, so no leading is needed. It's a world where you see that the garbage needs picking up, so you go get the truck and pick up the garbage. On your way, you see a neighbor filling in a pothole, because that's what he saw that needed doing. Further away, someone else is directing traffic while another person is fixing the street light that broke down.

That is a world in anarchy. Everyone is doing their bit, no one needs orders.

Of course, that vision is literally impossible. Aside from the insurance issues of just anybody walking into a garage and taking off in a garbage truck, there are not all that many people who have the knowledge to fix street lights or potholes via the proper procedure. You may easily find other examples.

So, what Charles 9 should have actually said was : what's it gonna be : chaos or the police state ?

Pascal Monett Silver badge

Re: How is this any different

Or typing an IP directly ?

I'm guessing that, if you type in the IP address, there will be no DNS lookup, right ? So how can that be traced ?

Of course, I'm guessing that, just like the vast majority of Internet users, pedophiles don't generally know what an IP address is, much less how to get it, but that information is not difficult to find, and it only takes one to explain things on a forum for the others to realize they need to do that to stay under the radar.

Idle Computer Science skills are the Devil's playthings

Pascal Monett Silver badge

Re: Oops.bat.

Test in Windows command prompt :

Type a>a.txt <ctrl>

The system cannot find the file specified.

So, unless you've already created file a.txt and b.txt, your script is going to fail to do much more than use CPU cycles and fill the command prompt buffer.

And, as soon as you kill the window, the problem is gone.

There's a reason why my cat doesn't need two-factor authentication

Pascal Monett Silver badge

The problem there is not the guy with the button, it is the procedure itself.

You cannot expect to have any semblance of security if the guy who should enforce it has no way of knowing who he is supposed to let in. You say "the security guards could not really be expected to know everyone". Well, if you want security, then yes, they should. At the very least, they should have had a list of license plate numbers and checked that every car was in the list.

The fact that the problem was "corrected" with a swipe system simply means that that was the point when authorized people were known. A guard with the proper information would have been just as efficient.

Who left a database of emails, credit cards, plain-text passwords, and more open to the web this week? Tech Data, come on down!

Pascal Monett Silver badge
Trollface

"The [..] company did not mention the incident in its most recent SEC filings"

Ooh, that's a big no-no. You can apparently lie to Congress with impunity, but not mentioning a serious incident to SEC ? That's gonna hurt.

You. Quest and LabCorp. Explain these medical database super-hacks, say US senators as 425,000 more people hit

Pascal Monett Silver badge

"two years of credit and identity theft monitoring"

Could somebody please tell me if that is actually of any use ? I have the feeling that it is just a polite band-aid to make you go away and keep quiet.

New twist in underworld of alleged code, data theft: Two, er, boffins accused of trying to steal, uh, a river model

Pascal Monett Silver badge

Re: Home office?

Um, did you miss the part where one was offering a job to the other if he got the model data ?

I'm under the impression that that was in their personal communications - which they set up in the sole intent to "avoid detection".

That is not behavior I associate with loyalty or dedication.

Besides, don't tell me that Hu did not know that downloading confidential data to personal storage was a no-no. He was a professor and had been working there for a while. He knew the procedures and what they implied.

In any case, I also hope The Truth will prevail. Looking forward to hearing more on this.

If your broadband bill is too high consider moving to Idaho, they get the internet for free

Pascal Monett Silver badge

Good to see that the Free Market is still holding on

This is a case in which I completely applaud capitalism. US citizens have been pawns in the hands of greedy oligarchs for way too long. It is nice to see that The People are waking up and getting back their freedom.

Good on Idaho, but what is better is that the dominoes are now starting to fall and Idaho's example will be repeated elsewhere. I agree that utilities should be under local control in any case, be it city or state. That prevents a good lot of situations where you have to wait for some enormous conglomerate to bother dealing with your problem. It mostly means that you don't have to go that far if you need to go and chew someone's desk out to get things moving.

What's big, blue, and hands out pink slips? IBM on Thursday: Word spreads of job cuts

Pascal Monett Silver badge
Trollface

"trying to get money out of its dying businesses and into emerging areas"

Wait, IBM has emerging areas ?

Someone slipped a vuln into crypto-wallets via an NPM package. Then someone else siphoned off $13m in coins to protect it from thieves

Pascal Monett Silver badge

Just goes to show

You do not have production servers depend on unknown code.

Known code is code you have evaluated, reviewed and tested, and should be stored on a server you control.

When you are notified of an update, you evaluate the necessity of the update, review the new code if the update is necessary for you, and apply it to your test server only if you do intend to use it. There, you test it thoroughly and validate its merging with production code on servers you control.

This form of attack only works because everyone is abandoning their duty of care and just blindly trusting dozens of people they don't know to do things right. That's like hiring a cleaning lady and getting ten people shuffling around your house, doing things that are not necessarily related to cleaning. You'd have to be mad to accept that, but when it's code, you just can't be bothered (I know, might not have the time either - doesn't mean it's a good situation).

It's official! The Register is fake news… according to .uk overlord Nominet. Just a few problems with that claim, though

Pascal Monett Silver badge

Re: Insider Trading

You can find that situation every day in the business world. As soon as you have a marketing guy overhearing a conversation at lunch or dinner and thinking of a way to benefit from it, there you go.

If that were illegal, there would be no business.

Besides, insider trading exclusively concerns the buying or selling of shares before some important news which will make the share price change in an important way. So it's only a Stock Market thing.