How appropriate. 13th May 2050 is a Friday. Just the day for bad luck.
Posts by Number6
2387 publicly visible posts • joined 10 Jun 2009
Page:
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
History of CentOS: How a biochemist's Linux hobby project became the enterprise world's default operating system
When I first got interested in Linux, it was a Red Hat CD that made sense. I tried Debian, but back then it seemed too alien to what I was used to (OS/2 - never been a Windows fan) and so it got filed. Then RHEL turned up and I switched to Fedora, then got fed up with the need to re-install every 18 months and so looked around, eventually switching to the Debian-based Mint and learned about how they did everything and where the default config files lived. That's what I use for user machines now, although Ubuntu and Debian are in use on servers where I just interact over SSH and don't need the overhead of the GUI. I did look at Centos at one point, but decided I liked Mint better.
California passes bill declaring death-by-algorithm to 3D-printed ghost guns
A pointless bill, way too easy to circumvent, so it becomes bad legislation. Unless the rest of the US adopts similar legislation, even if it 100% worked in California, a quick trip to Reno or somewhere else across the state line would provide access to unencumbered printers. I'm also interested in how long it takes the state to come up with an algorithm that can be implemented within the limits of your average 3D printer. If they do it in the slicer software then the open-source community will definitely have access to versions without restrictions. If all else fails, an "upgrade" of the printer electronics because you accidentally blew up the original board would take out any authentication exchange that attempted to tie the hardware to approved slicers, assuming a low-level flash of the original board couldn't be done.
The 'Additionally, anyone caught trying to “knowingly disable, deactivate, uninstall, or otherwise circumvent any firearm blocking technology” could face misdemeanor charges' is not going to stop someone printing a ghost gun, given that they've already gone beyond a misdemeanor so it's just penalising the law-abiding with no deterrent effect on those breaking the law.
Phone users know when to hold ’em, delay upgrades amid inflation
Using the password 'admin123' wasn't as bad as sharing it on Slack
Re: Security Measures
Rotation is annoying but there is some justification. Correct security paranoia is to assume that every password is compromised even if it hasn't been (ab)used yet. By changing them out you lessen the window of opportunity for any given password to cause problems. Of course, the quick "fix" for users is to keep the same password and add 1 to the number on the end.
Lateral random thought on the brute-force approach. Given that the usual password authentication method is that you type in the password and at some point it gets converted into a cryptographic hash which is then compared to the stored value, what happens if you happen to have managed to generate a 20-character random string that just happens to have a hash collision with "123456"? Apart from recommending purchase of a lottery ticket. Probably not likely with modern hash functions, but there is always the chance.
Raspberry Pi leans into semiconductors as sales climb – especially in US and China
Re: :RP2040/50 microcontrollers
To me, a microcontroller is a device with internal memory and designed to be low power consumption and small footprint. So I wouldn't expect DDRx support, because that adds volume and power to the mix. If you really want DDR then you're moving up in the world to larger chips with more pins and a bigger power budget, not something that powers the low-level tech that doesn't need lots of RAM and may be battery powered and expect to last a long time. Who needs DDR support for a fridge controller, or a central heating controller,or a microwave? There is a huge market for "last decade tech".
Re: RPi netbook when?
I already have an Aspire One netbook. For limited tasks it's still really useful because it's self-contained and I can hold it in one hand while typing with the other.
I did recently configure an old RPi as a GPS NTP time source, now used as my network's primary time sync. Great use for the older RPis, along with being media players (they run Squeezeplay/Squeezelite nicely). Even one of the second-ever production batch (I was slightly too late for the first) is still doing duty in that form.
As for professional use, I've noticed quite a few in various labs at work, and I remember putting together a wobbulator with one at a previous place.
Perplexity Comet hurtling toward Amazon ban
If the access is from a browser on the user's machine then the only things identifying it as a bot are the behaviour and the user agent string. I trust my access credentials to my browser of choice, so if a user wants to risk theirs with an AI bot then it's at their own risk. I can see Amazon's point if the bot/browser is hammering the site with a lot of accesses that far exceed what a human would do when browsing, but otherwise if it's a Chromium-based browser, what's the effective difference from their end compared to using Chrome, Vivaldi or Brave? I'd say that using Chrome probably leaks way more information than some of the others.
RSS dulls the pain of the modern web
Already Here
As it happens, I came across this article courtesy of Akregator subscribed to El Reg's RSS feed which has been a staple here for many years. Admittedly my feed list is looking a bit thin at the moment, quite a few stopped working and I just assumed (perhaps wrongly in a few cases) that the source had ceased to provide one.
Amazon tells FCC to bin SpaceX's million-satellite datacenter dream
TerraPower gets permission to build, not operate, sodium-cooled nuclear reactor
AI can predict your future salary based on your photo, boffins claim
So if companies are using this in early screening, make sure your LinkedIn picture is low-enough quality that they can't tell fine detail, lock down any photos of you that are searchable on the web and generally make it hard for people to find your image. I've checked mine and I don't appear in a Google Image search for my name, so that's a good start. I seem to share a name with authors and academics so they occupy the search results.
Microsoft engineer speedruns Raspberry Pi magic smoke in five minutes
Re: He posted this?
That's the usual thing. Quickly disconnect all the power, surreptitiously try to dissipate any visible smoke with gentle and quiet blowing and appear innocent when someone else in the room smells burning and looks around for the source. Or celebrate the achievement if it's clearly obvious. Own it and say "Impressive!" loudly. I do remember as a junior engineer producing a light-emitting op-amp when a test probe I was holding slipped and shorted something. Lasted a good ten seconds, with with everyone else panicking and me just sitting there admiring the sight because I knew it was already too late.
I'm sure people who do electronics are capable of detecting the magic smoke at concentrations well below that of the general population.
Euro firms must ditch Uncle Sam's clouds and go EU-native
Re: Not a Trump thing.
Someone researched it[*] and it was effective in some cases. The body's immune system has some control over the proliferation of intestinal parasites, but the effective Covid treatments at that point suppressed the immune system and allowed the parasites to multiply to the point where they contributed to the death of the host. So if you were in an area where parasites are endemic, taking medication to kill them at the same time as Covid treatment was effective. Outside of those areas, there was no noticeable effect.
[*] it was a published paper that tried to make sense of all the small-scale studies that either claimed it was effective or not, and noted the correlation. I didn't keep a link to it.
Bankrupt scooter startup left one private key to rule them all
Re: Law...
I was once in earshot of management of a company that was spiralling down and they were discussing what they could set in place before the plug was pulled in order that there would be enough infrastructure and information out there to allow existing users to continue using their product. So they're not all bad.
Power scarcity drives datacenters to Texas, where the juice is
Given how well the Texas grid performed in 2021, I would steer clear of the place. An isolated grid, so they can't even pull in power from elsewhere. The pricing model imposed on residential customers (and possibly some/all business ones too) that hiked prices to gouging levels when demand far outstripped supply, means that the locals should be resisting the arrival of such power hogs.
AI may be everywhere, but it's nowhere in recent productivity statistics
For Reference Only
I find the best way to use AI is to get it to provide me with a list of useful reference articles, which I can then read and (hopefully) understand and then go use the information constructively. If I ask it to generate code then I need to spend time checking that code, if I want it to write prose then I have to spend time proofreading it and checking for accuracy. I've seen it be flat wrong before now. One day it may work well enough to just get on and do stuff, but I remain to be convinced that it is reliable outside of fairly narrow areas where it's been trained on carefully-curated content.
Techie banned from client site for outage he didn’t cause
Re: 13A plugs
One of the common causes of overheating is dirty contacts. That bumps up the contact resistance, which generates a bit of heat and a bit more oxidation, which bumps up the contact resistance, which...
I suspect part of the problem there is that most of us plug the kettle into the wall socket and never unplug it, so the wiping action of inserting the plug never has a chance to clean off the crud.
US freezes $42B trade pact with UK over digital tax row
Cabling survived dungeons and fish factories, until a lazy user took the network down
AWS builds a DNS backstop to allow changes when its notoriously flaky US East region wobbles
I assume this means they've set the default TTL on DNS queries to 60 minutes. I've done that sort of thing (except down to 10 minutes) for scheduled changes to allow IP address changes to propagate faster when a change is made. 60 minutes is probably a reasonable compromise for unscheduled outages.
Canonical pushes Ubuntu LTS support even further - if you pay
I find one of the incentives to upgrade to a new release is the rest of the world. If you're stuck on a distribution that uses Python 3.4 (assuming it's new enough to have made it to V3) then a lot of stuff needs a newer rev. Similarly with other things, you're still getting upgrades that don't include features from newer releases, and occasionally you learn that the functionality you crave does exist in the latest revision.
BOFH: You know something's up when the suits want to spend money
Win10 still clings to over 40% of devices weeks after Microsoft pulls support
I have a laptop that works perfectly well with Win10 and Linux (dual-boot). It won't run Win11 and I don't see why I should ditch a perfectly good laptop because of some arbitrary MS requirement, so no Windows 11 there.
I did discover that my main desktop machine, which runs Linux but is also not good enough for Win11, will actually run it in a VirtualBox VM. No doubt MS will break that at some point, but I did take a snapshot of the Win10 image before upgrading it, and I did take a snapshot of the working Win11 image once it was done, so hopefully I'll be able to keep something running. It only exists because I have one Windows-only piece of software I have to run once or twice a year and it's insisting on Win11 now.
Amazon spills plan to nuke Washington...with X-Energy mini-reactors
Re: More Micro than Small
If there's a decent market for the fuel then someone will invest in making it.
To me, as well as the tech and reg hurdles, what about physical security? You don't want some nut job (or group thereof) breaking in and doing bad things with the fuel, given that the rest of us would much prefer it to be kept in a safe, controlled environment. And what happens when they need to refuel the things? Something has to happen to the spent fuel, and that costs money that should really be properly planned for up-front rather than a vague "by the time we need it we'll have it figured out", which hasn't really worked too well so far.
End of Windows 10 support is the perfect time for the Windows 11 installer to fail
Some US tax software is requiring W11 starting with the 2025 edition (which we can't really use until 2026) on the basis that W10 will no longer be considered secure at that point. Whether it will actually still work on W10 remains to be seen. If they were smart they'd let it work with a big warning about security.
Isn't the presence of MBEC part of the definition of compliant hardware? My main PC was built in 2013 so it's definitely not going to support the newer features, but so far Linux runs just fine.
For me, the Win10 predecessor of my VM would be fired up twice a year, first to do updates, then again a bit later to do my US taxes. So I can put up with a lower performance because it's still the easiest/cheapest way to do that for me.
I learned this week that VirtualBox will allow Win11 to run on an old system in a VM. It will emulate TPM2.0. If you do a fresh install it seems to go quite happily, if you try to upgrade a Win10 installation it will object to the CPU variant, but a Google search will provide a registry hack to get past that stage.
I assume at some point Microsoft will break this, but for those who run Linux but keep a Windows VM around for that one program that isn't available on Linux, it's a way to keep going. Just take a snapshot before installing updates so you can revert to the last one before the breakage.
Trump admin says tech companies are abusing H-1B visas, slaps $100k a year to allow entry
I saw something go by late last night that needs more verification, that claims this fee is going to be retroactive and that anyone turning up at immigration with an H1B isn't going to be allowed in unless the fee payment is on their record, even if they've been living here for a while. The advice is that anyone on an H1B who's in the US stays in the US, and anyone with an H1B who's currently out of the country should get back before the rule kicks in. The advice also says that those on a derivative visa (H4?) should also do the same. It can certainly be read that way, and with the behaviour of the current US administration, assume the worst case.
Section 2(c):
(c) The Department of Homeland Security and the Department of State shall coordinate to take all necessary and appropriate action to implement this proclamation and to deny entry to the United States to any H-1B nonimmigrant for whom the prospective employer has not made the payment described in section 1 of this proclamation.
Microsoft insists Copilot+ PCs are 'empowering the future' – reality disagrees
Absolutely fabless: Trump derails TSMC's China chip-building effort
The dead need right to delete their data so they can't be AI-ified, lawyer says
Why blow up satellites when you can just hack them?
US signals intention to rethink job H-1B lottery
Re: There's a simple fix
If they're steadily raising the minimum then I would guess they're trying to implement something sensible over several years so as not to disrupt too much in the short term. Can't quite see government being that joined-up and forward-thinking though. They just went for a cheap headline and then it'll get filed.
The actual skill level of H1B workers varies enormously, from "yes, we must encourage this person to come because it will benefit the US greatly" to "barely qualified and probably only here as a warm body to fill a seat and enrich some staffing agency by being paid a pittance while being contracted out at a much higher rate. To be fair, some of the latter category who manage to hang in there long enough do eventually learn if they've got people willing to coach them, but that's not really what the H1B is for.
In theory it's a valuable and useful programme, in practice it's been corrupted for the financial benefit of a few, often to the detriment of the people that really should get a visa but can't because the quota has been used up.
DHS warns of sharp rise in Chinese-made signal jammers it calls 'tools of terrorism'
Re: Don't panic people
The cell protocol has provision for priority, so what would happen is that the emergency comms would still get through, and no one else would be able to make calls. Still vulnerable to a jammer that blocks the entire cell tower though.
Having said that, there are directional antennas on most towers that try to radiate out towards the horizon in most cases, not straight down, so a jammer near a tower might not take out all of it, and would have to radiate sufficient power to overcome the antenna beam pattern that gives signals on the main lobe a significant advantage, which would probably make it fairly easy to track down. The main application for the sort of jammers in the article is to take out the handsets at the scene of the crime, not the tower. They can afford to be a lot lower power and cover a limited range.
"as lawmakers introduced new rules against vehicle key and key fob jammers as part of the Crime and Policing Bill."
The irony here is that many years ago they introduced a new frequency band for key fobs at 433MHz, which just happens to be in the middle of a popular amateur radio band, shared with the MOD. Documented cases of people parking near a radio tower and locking their car when the repeater on the tower was quiet, then coming back and being unable to unlock their car because the repeater was transmitting and effectively swamping the remote receiver. Didn't even need to be on the same frequency because of the cheap design of the fob receivers.
Techie traveled 4 hours to fix software that worked perfectly until a new hire used it
Re: I touch it and it breaks!
I was always good at breaking things too. It started at school with fellow students writing BASIC programs. "Enter a number from 1 to 5" was just inviting me to enter anything but, and they learned an awful lot about the importance of input validation from my actions.
The outstanding one was crashing the stuff written in Ada in my first proper job. It was trumpeted as being wonderful and rigorously tested etc. I was doing some testing on some aspect of the system and as part of it I had to navigate a page full of input parameters, which I filled in by alternating "0" and the enter key. I should note that this was on a VT220 terminal, to give some idea of the state of the UI. Having done this successfully numerous times, suddenly I got the thing to crash. The fully-validated input module took whatever input I'd given it and barfed. I mentally went through the muscle memory of what I'd just done and realised that I'd missed the 0 and hit the minus key next to it. This was an input it would accept because the number fields were for signed decimal numbers, but it turns out that having gotten past the initial input filter that took out all the characters that were not part of a number, what followed couldn't cope with a single minus sign as the entry because there was no numeric digit in the string. On a roll, I tried it with a + sign too, and got the same crash result. What a deeply satisfying day that was, breaking something that had passed all the required verification testing. And no, it's not one that had occurred to me before that day either, but you can be sure I've tried it on stuff ever since.
I got dragged from the West Country into London for a "feature" once. I was part of the dev team and it was escalated from the front-line support because they couldn't figure out the problem. So I turned up with one of the support guys who did the interface with the actual people and we went through a bunch of stuff and couldn't find anything wrong. We were literally on the way out the door having given up, when someone made a comment that provided the one piece of information that was missing. I remember we both knew exactly what was happening at that point and pivoted in unison to head for the control PC. It was doing exactly what it was supposed to, according to how it had been designed and configured, but they clearly needed a slightly different configuration.