* Posts by Ole Juul

2726 publicly visible posts • joined 27 Apr 2007

AdBlock replaced blocked ads with ads for Amnesty International

Ole Juul

Or just wait and bitch.

Auto vulnerability scanners turn up mostly false positives

Ole Juul

Re: One Concern

My problem is that I'm fixated on nostly.

Obama puts down his encrypted phone long enough to tell us: Knock it off with the encryption

Ole Juul

hypotheticals?

What Obama is trying to tell us is that encryption actually causes paedophilia and terrorism.

Web servers should give browsers a leg-up, say MIT boffins

Ole Juul

Found two problems

"With ad sites, trackers, and third-party services delivering images and fonts, those dependencies have multiplied in the last decade, . . ."

“As pages increase in complexity, they often require multiple trips that create delays that really add up."

Once those are dealt with, we'll be good to go. You're welcome.

Approved: Master plan to end US gov control of internet's highest level

Ole Juul

Re: If things get bad enough...

"The result of the decision not to ensure the internet community had a legal right to force change will likely haunt it for many years to come."

And as AC said above, nameserver operators can do their own thing. But to me it is not only them who can walk, it is the rest of us. As it stands people already operate other alternative systems within the net. OpenNIC has its own nameservers and TLDs, for example. Also, Tor is quite independent. I'm not necessarily advocating for those, but just saying that there are alternatives and many more can be implemented if ICANN becomes too much of a drag. In fact I think the new master plan is going to push development in that direction and ICANN's thirst for power is just going to lead to increased fragmentation. Perhaps that's good. Perhaps it's bad. But that is another discussion.

What are you doing to spot a breach?

Ole Juul

conflict

There's a lot of unsafe practices like a hospital sending data to a third party to produce invoices. While I do think it is a good idea to work on those, there seems to be a reluctance to eliminate less safe practises when possible. It's as if there is a pull from management to use fashionable outsourcing techniques and otherwise increase the risks. Perhaps it would be more effective to do some things in-house than solve the more difficult security problem of sharing security issues with a third party.

Don't snoop on staff via wearables, says Dutch privacy agency

Ole Juul

good decision

Its argument is that there's an asymmetry between employer and employee that's likely to make staff feel they need to say “yes”

I wonder how many other situations there are where that asymmetry could be an issue for privacy.

Is there anything left to ask Bill Gates? (Other than gissus a million?)

Ole Juul

Re: I've Got A Question For Him

One does not make tea with teabags. Period. And no milk. However, if one insists on being British, then I agree that the milk definitely goes in first.

Yes, I'll certainly have a lot of minutiae to contribute about myself when I get to be interviewed like that about my life. Unfortunately I think I missed the boat - just realized Bill Gates is younger than I am. (And the first million is still nowhere in sight.)

Open trucker comms lets Shodan snoops alter routes, tap CANs buses.

Ole Juul

"New delivery address: my place"

Too risky. Better to act as a middleman and sell the goods on-line, delivered of course.

NatWest tightens online banking security after hacks' 'hack' exposé

Ole Juul

one in 10,000

Our records show that of all the people who enroll in online banking and forget their details, only 0.01 per cent are fraudulent.

How many bank robbers is an acceptable number?

Romanian ATM hacker exploits vulnerability in FENCE, escapes jail

Ole Juul

Hacking fence

Bit of a low level exploit if you ask me, but I suppose one needs to be pragmatic in these sorts of situations.

US slaps trade ban on ZTE over Iran links

Ole Juul

Control issue

The US doesn't want others to gain any advantage. Also, at every opportunity they want to push their laws on other countries.

McAfee gaffe a quick AV kill for enterprising staff

Ole Juul

responsibility

Avecto reckoned 97 percent of critical Microsoft vulnerabilities released in 2014 would be mitigated by removing admin rights.

So for this little user convenience we all have to pay.

Google gives ringing endorsement to US VPN providers with 'right to be forgotten' expansion

Ole Juul

Re: Better solution?

Well, your solution may not be the better one, but the idea that there may be a better one is good. The current one certainly leaves a lot to be desired.

Ole Juul

Geolocation

Filtering on supposed location is just plain censorship. Another problem is results are commonly quite wrong and generally only good to country level. Of course country level is what we're talking about here, but it is still censorship. I advocate the use of a VPN at all times in order to help obfuscate information for would-be censors and surveillance creeps, as well as to help discourage such practice.

Norman Conquest, King Edward, cyber pathogen and illegal gambling all emerge in Apple v FBI

Ole Juul

Re: Society be dammed

"That would be the Hoover dam then."

(I'm embarrassed about the spelling error) Actually that should probably be the J. Edgar Hoover kind of damned.

Ole Juul

Society be dammed

"An underlying principle of English law is that it is better for nine offenders to go free - than one innocent person be unjustly convicted."

Unfortunately this is not how the FBI and other American law enforcement agencies view the situation. It appears that to them there is no cost too high. They must "win". That society looses is of no consequence to them.

Ole Juul

Correction

society accepts that the people that break its rules and laws should not be able to rely on those same laws to prevent them from being punished.

No. Society accepts that we should all be subject to the same laws.

Electrified bird bum bomb shuts down US nuclear power plant

Ole Juul

bird in hand

This is one of those situations where it may actually have been better to have the bird in the bush.

Snowden is a hero to the security biz – but not for the reason you'd expect

Ole Juul

Not for the reason you'd expect

Well actually, the "security biz", being a business, is primarily interested in increasing their business. Article OK otherwise.

E-borders will be eight years late and cost more than £1bn

Ole Juul

Where's the bouzouki player?

Is it possible that actually nothing has been achieved to date and that this is an alternate version of The Cheese Shop? How will this end?

Facebook can block folks using pseudonyms in Germany – court

Ole Juul

Doxing

without her permission, switched the name on her page to her real name

Classy company.

Actual pirates hack shipping biz servers to pinpoint vessels carrying precious booty

Ole Juul

Golden age of piracy

As I understand it, modern day pirates usually make the big money through ransoms, so actually getting away with high value loot is a bit of a throwback.

India to educate 60 million more village homes about tech

Ole Juul

OS agnostic?

This sounds very good, I just hope some vendor doesn't use this as a way to gain an advantage like Facebook tried.

UK biz fails to report two thirds of cyber attacks, says survey

Ole Juul

So maybe the headline would be more accurate if it said "UK Biz tries and fails to report two thirds of cyber attacks"

Sounds more like it should be "Police reject two thirds of cyber attack reports".

Greybeard monobrow baldies rejoice! Boffins comb out hairy genes

Ole Juul
Joke

"we're a long way from treatments"

Too bad, I was hoping they'd have something you could slip in someone's drink.

Facebook's Latin America veep set free by appeals court

Ole Juul

Hostage taking

Is there something missing in this story or is it really true that the Brazilian authorities actually expected Facebook to break encryption in return for a hostage? That really takes this to a whole new level.

Bruce Schneier: We're sleepwalking towards digital disaster and are too dumb to stop

Ole Juul

Re: "The problem is in the design..."

Yes indeed, history is littered with innumerable examples. So when Schneier says:

For example, everyone understood that the invention of the car allowed humans to travel farther and faster than before, but no one predicted the rise of suburban living and the consequent issues that caused.

he is not quite accurate. I've seen examples of high density (for the time) neighbourhoods constructed by developers just "outside" town because the bicycle made it attractive to live further out and work "downtown". It's not really a matter of examples, but rather the will to look at them.

SCO vs. IBM looks like it's over for good

Ole Juul

Re: Put on your red dress baby

Pamela Jones deserves to party now. I started reading Groklaw near the beginning and I learnt a lot there. PJ worked very hard for all of us.

PS: I wonder if my lone downvote is from someone who doesn't know about PJ's famous red dress, or if it was from the last (surely there couldn't be two) SCO supporter. Actually, I can imagine it was Darl McBride.

PPS: For those that weren't there, here is that great cartoon with the dress and the Titanic which nailed it like nothing else could.

Ole Juul

Put on your red dress baby

'cause we're going out tonight,

Schneider Electric building manager bug allows security bypass

Ole Juul

with or without?

The ICS-CERT advisory notes that it's exploitable without a “low skill set”.

Surely they don't mean to include no skill set at all.

Hitchhacker's Guide to RSA clones conference badge with a towel

Ole Juul

another chapter

in the Hijacker's Guide to the Universe.

Net neutrality: Email trail reveals how Prez Obama bent the FCC to his will

Ole Juul

rolleyes

"It should be highly concerning that an independent agency like the FCC could be so unduly influenced by the White House, "

How can somebody say that while turning a blind eye to how the White House pressures even more supposedly independent agencies? Dream on.

NSA boss reveals top 3 security nightmares that keep him awake at night

Ole Juul

The devil within

In fact the NSA is its own worst enemy.

"Citing the recent Ukrainian power grid hack as an example, "

And isn't it interesting that his best example is factually questionable? Seriously, why don't these guys just go back to discussing how many angels can dance on the point of a pin.

Gartner to FBI: Stop bullying Apple and the tech industry

Ole Juul

Charlie Don't Surf

“I wish they would stop bullying Apple and the technology industry around and spend their time and energy instead on figuring out how to rise to the challenge.”

Except the FBI doesn't do that.

Mathletics promises security upgrades after parents' security gripes

Ole Juul

coding error

Seriously, login details in the clear is probably not really a "coding error". So, will kids now start to say "I lost my homework because of a coding error"?

Confirmed: IBM slurps up Bruce Schneier with Resilient purchase

Ole Juul

Does this signal a change?

Perhaps this is the beginning of a new era where corporations will stop playing victim and be proactive with their security.

Gopher server revived after 15 years of downtime

Ole Juul

Re: needs some work

Thanks. Now that you mention it, I see that I can browse it in Lynx as well but that's using 32 bits which is cheating. The site does not work with one of the original Gopher clients which I'm running in DOS 6.22 on bare metal. I have no problem with "real" gopher sites, so this is not as retro as they're suggesting. I guess it's OK, but I'm disappointed that us vintage guys won't get any use of it.

PS: try gopher.floodgap.com

Ole Juul

needs some work

I saw the story a couple of days ago on Hacker News, and went to have a look. It's not working properly. Now I see the story here (kudos to El Reg) and try the gopher again. It's still not working properly. Is this a case of bragging without checking?

I'm using a classic WATTCP DOS application and still the site is extremely slow and most items just return a "(null)". It's an unfinished mess. I don't know what they're running this on, but a period appropriate floppy system is much faster. There are still a bunch of gopher sites out there that actually work. I think this is embarrassing for MetaFilter.

Tor takes aim against malicious nodes on the network

Ole Juul

misconceptions

"The nature of this article and other others lately suggests that TOR is less anonymous than anyone really thinks it is."

You nailed something there. Except for the "anyone". Lots of people know the truth about Tor, but unfortunately many people also think only in absolutes and so are unable to grasp the basic ideas of security and anonymity - neither of which are absolutes.

It is true that Tor provides anonymity, it is a tool for that, but it is not true that that anonymity is absolute. Until someone understands the seemingly simple ideas that nothing is 100% and "never say never", they will not understand this software. Tor is simply a tool, and for some things the best available at the moment. Hopefully it will improve with time, and hopefully a lot of people will eventually learn to not trust any software absolutely.

Official: Toshiba pulls out of European consumer PC market

Ole Juul

Warranty probably expired

I've got a Toshiba 3100. Haven't used it in a while though.

Tor users are actively discriminated against by website operators

Ole Juul

Re: Understandable..

Staying annon, so I'm going to be vague, but one of them is home furnishings. I can't think of a reason most people would find it necessary to use TOR to buy a nice cushion. Plus their user demographics don't really overlap with hardcore privacy campaigners, in fact I'm surprised most of them can operate a computer in the first place.

I get what you're saying about overlap, though I would think that other "privacy campaigners" like myself would also go shopping for cushions and the like. I can't be the only one.

I'm sure your sites are fine, but many in that category are full of trackers and other privacy antagonizers. It is a good idea to use Tor Browser when going to all kinds of places. Besides, why shift from one browser to another all the time when it's easier to just use Tor Brower for everything. It's not a matter of even needing a reason to use Tor to go to your sites, but just as much that there is no reason to change browser to go there.

Ole Juul

Re: Understandable..

Yep, that's the reasoning where I work. No legitimate traffic comes via TOR, it's all malicious, (to be fair, our customer's websites are not the sort of thing one would usually use TOR to access).

What kind of websites do you operate that would cause somebody who prefers to browse anonymously to change browser for your sake? I'm guessing what you're missing is that many people use Tor to protect themselves from the sites they visit.

Ole Juul

Re: Understandable..

I don't find it so easy to understand, especially since these web site owners seem to be keeping mum about exactly what kinds of attacks they're dealing with. As the administrator of numerous web sites I am well aware of the volume of malicious traffic that servers face, but I have a feeling that this is about something else.

Bleeping Computer sued by Enigma Software over moderator's forum post

Ole Juul

Popehat

Perhaps this is one for Popehat who is good at finding pro bono representation, or just on-line support, for these kinds of cases.

Ole Juul

I'll decide for myself, regardless

Obviously if information about Enigma Software is likely to be coerced, then anything I read about them is untrustworthy. Probably best to just avoid them.

Wikidata makes Wikipedia a database. Let the fun begin

Ole Juul

The mind boggles

Sorting countries by average temperature.

Novels by number of words.

Great composers by shoe size.

Lose the onion tears, Tor fanboys: CloudFlare may consider binning CAPTCHAs, says CEO

Ole Juul

I am interested in exactly what kind of abuse comes through Tor connections. For some reason they never say.

Apple fans take iPhone unlock protest to FBI HQ

Ole Juul

There's a dozen other iPhone cases

And it is not just about one case either. Apparently there are a dozen other current cases where the government is trying to get Apple to break iPhone encryption. See Wall Street Journal.

Intel shows budget Android phone powering big-screen Linux

Ole Juul

attack surface

This looks like it's going to be a security nightmare.