* Posts by Allan George Dyer

2547 publicly visible posts • joined 12 Jun 2009

Kids in Hong Kong and other highly surveilled states worry infosec careers are just asking for trouble

Allan George Dyer
Black Helicopters

National Security Law

From my point of view, the National Security Law is quite clear, even though the administration doesn't seem to realise just how broad it is. Two provisions, taken together, make it risky to do any sort of information security: it allows covert surveillance by the national security department of the police (Article 43(6)), and interfering with the performance of duties of state power is an offence of Subversion (Article 22(3)). Suppose a user in your company is under surveillance, you run your anti-virus scanner and remove spyware from their machine... guess who goes to jail for Subversion? If you sourced the scanner from a foreign company, that might also be Collusion with a foreign power under Article 29.

As this law has worldwide jurisdiction, then researchers in the foreign company developing the scanner might also have committed an offence.

Oh, and as this would involve state secrets (there's no point in using a covert surveillance tool that isn't secret), the trial could be conducted in secret.

Don't worry, I'm sure the trial will be conducted to the highest standard of Chinese justice.

British IT teacher gets three-year ban after boozing with students at strip club during school trip to Costa Rica

Allan George Dyer

Re: I am disappoint...

Our teachers didn't drink with us... until after our last exam, when we were no longer students, then we had a bit of a celebration.

OTOH, I was drinking with the Venture Scout leaders at 16, after the meetings.

Brit authorities could legally do an FBI and scrub malware from compromised boxen without your knowledge

Allan George Dyer
Black Helicopters

National Security

@Doctor Syntax - "The issue is malware. I think you're stretching the definition of malware a little more than warranted to include publishing information embarrassing to the government."

It's not limited to malware, it only requires a minister to agree that exposing his fellow minister's wrongdoing would damage the economy.

A minister would NEVER betray his position of trust, so we're all good, right?

A keyboard? How quaint: Logitech and Baidu link arms to make an AI-enabled, voice-transcribing mouse

Allan George Dyer
Holmes

Re: Mouse?

Mice and keyboards both have this problem of people's hands clicking on the buttons, which is likely to cause a certain amount of noise on the mic. A lapel mic gets yanked out when the user walks away, forgeting to take it off. Built into the monitor, a mic can be right in front of the user's face, and, if the speakers are there, filtering can eliminate the problem of picking up screen reader output inadvertently.

Allan George Dyer

Re: Really?

There are a lot more options for Chinese input - both shape-based, phonetically-based, and hybrid systems. One reduces the number of keystrokes per character to 2, for stenographical use, so speed is possible with practice. Conversely, Chinese (of all variants) is a tonal language so speech recognition is a different challenge to many other languages. Not infrequently I've seen people write a character in the air or on their hand to clarify which of several similar-sounding characters they mean, usually for names where context is less informative. Try doing that with your speech input.

Overall, it's worth remembering that this is a marketing claim.

Average convicted British computer criminal is young, male, not highly skilled, researcher finds

Allan George Dyer
Holmes

"Average caught British computer criminal is young, male and not highly skilled" - FTFY

Maybe there is a correlation with the average skill level of the British Police in these matters?

Yep, you're totally unique: That one very special user and their very special problem

Allan George Dyer
Facepalm

Re: When turn off/turn on fails

How about a floppy driver with a hidden on/off switch?

I got called to a user who couldn't get their new PS/2 external drive working. It took me 5 minutes to find the switch cleverly hidden by the recessed base, half the problem being that I didn't expect the drive to have its own switch.

Mullet over: Aussie boys' school tells kids 'business in the front, party in the back' hairstyle is 'not acceptable'

Allan George Dyer
Pint

Re: Well done!

@Version 1.0 - " they banned smoking weed, LSD and beer too"

How the hell do you smoke beer?

'Agile' F-35 fighter software dev techniques failed to speed up supersonic jet deliveries

Allan George Dyer
Trollface

@AC - "came back to the business three years later with something they no longer wanted" / "failures were usually due to issues in the business... moving goal posts, "

Maybe there's a connection here?

The Roaring Twenties: Future foreign policy will rely on rejuvenated 'cyber' sector, UK government claims

Allan George Dyer

Re: Let's start a nuclear ware in a spiteful tantrum

@EvilDrSmith - 'You follow "wear a mask" with "Seriously".

Hmm.'

Well, I was being a bit flippant - masks aren't the complete answer, and I was following up with more detail. As I tried to mention later, simple public health measures, including masks, have been shown to be very effective at reducing the spread of a new disease. Sorry if this didn't come across well.

"The idea that a biological attack on UK triggers a nuclear response isn't actually new." - It might not be new, but it still doesn't sound reasonable. There is a certain proportionality in firing off your nuke in response to a nuke - and you've got the radar data for valid attribution. But for a supposed biological attack... that develops over days or weeks, and the search for the source takes longer, with uncertainty in the attribution. You wouldn't want to be the Minister saying, "Really sorry about that nuke, we thought X had hit us with a biological WMD, but it was just a new 'flu variant."

"Deterrence works." But, in all your examples, not nuclear deterrence. It's back to your "no valid target / they would be disproportionate" limits on the deterrence value of a nuke.

"You may have house insurance, but you still want to lock the back door." - Nukes aren't like house insurance, they're more like stockpiling Molotov cocktails to retaliate against your arsonist next door. If you spend too much on Molotov cocktails, you can't afford* the window locks and hinge bolts.

(* - for illustrative purposes only, I haven't checked the relative prices of petrol, hinge bolts or anything else)

Allan George Dyer

Re: Let's start a nuclear ware in a spiteful tantrum

@EvilDrSmith - "So what would your solution be to the situation whereby the UK was threatened with being attacked by biological attack?"

Wear a mask?

Seriously, thank you for eloquently laying out the argument for nuclear as a deterrent against strategic threats, it really makes me think about its inadequacies. It's difficult to see a biological attack as a strategic threat: diseases are difficult to control, how does the attacker make sure they don't harm themselves? Supposing an attacker did manage to cause 100,000 deaths spread across your country, it would be really easy to look like the bad guys if your Health Minister stands up and say, "In response, we are nuking a small city in country X, where we totally know it was developed." The same for a cyber attack knocking the national grid offline for a week in winter. As you say for the Argentinian invasion of the Falklands, "no valid target / they would be disproportionate", so therefore no deterrence.

The answer I would propose is to strengthen *defences* against biological and cyber attacks: funding the health service, emergency planning and educating the public about preventative measures (e.g. masks) works just as well against natural pandemics as artificial diseases; proper infosec planning and user education work against criminals and nation-state APTs. But that would be hard work, and not as sexy as a nuke.

Beijing pressures Alibaba to offload media assets, including Hong Kong's top newspaper

Allan George Dyer

Re: Ma

He made a short appearance in a video in January, saying, “Working hard for rural revitalisation and common prosperity is the responsibility for our generation of businessmen.”

US newspaper's 'Biden will hack Russia' claim: A good way to reassure Putin you'll leave him alone

Allan George Dyer
Paris Hilton

It's a Cunning Plan

1. Leak timing of "clandestine operations"

2. Do nothing

3. Watch adversary franticly searching for the clandestine operations

4. Deny ongoing operations

5. goto 2

Microsoft rolls out mask detection to Azure Cognitive Services. And yes, there is a noseAndMouthCovered attribute

Allan George Dyer
Big Brother

More attributes needed...

Some places (e.g. Switzerland, Hong Kong) require masks in some circumstances, and ban them in others. Does it have useful attributes:

participatingInAnIllegalGathering

religiousDress

and configuration options:

globalPandemic = TRUE

we_reNotReligiouslyIntolerantBut = TRUE

The sooner AI stops trying to mimic human intelligence, the better – as there isn't any

Allan George Dyer

Re: the "AI" was matching the chest drain in the X-Ray and not the symptoms.

@Loyal Commentator - 'If they give a reply along the lines of "it just felt right the right answer", they've just failed their Voight Kampff test.'

Not really, often people find it difficult to explain why something is "not quite right", the Uncanny Valley can provide examples. In the opposite sense, conmen try to manipulate people into trusting them with the right triggers, "but he seemed so nice".

Allan George Dyer
Terminator

Re: Learns?

@Mage - "A child that has eaten bread and sausages will assume a sausage-in-a-bun or a hot dog is edible. A two year old can do things easily that are impossible for AI."

A good thing too. It'll be bad enough when the machines take over, without them eating all the damn hotdogs!

Hong Kong teases tech to track residents as they move past QR codes

Allan George Dyer
Big Brother

As clear as mud

How the “LeaveHomeSafe” app actually achieves its aim is unclear. You can scan the QR codes at venues, and enter taxi license numbers, and confirm when you leave a venue. The Government has, multiple times, assured people that their visits are ONLY stored on their phone and automatically deleted after 3(?) weeks, so there are no privacy concerns. But, if you are tested as COVID +, you have the option (otherwise, what's the point?) for uploading your records to the Centre for Health Protection. Presumably, the consolidated records are then transmitted to all app users. This might cause two issues:

i) If there are lots of cases, does this scale well? Three weeks of visit date for every case must be transmitted to every app user for matching.

ii) If there are very few cases (yesterday there were 14 new cases in HK), privacy is compromised. In the extreme case, the movements of one person are transmitted to every app user. Anyone who can work out who the case was ("Bob went into quarantine yesterday") can check where they have been (depending on the in-app security... probably reasonably breakable).

In practical terms, the actual scanning of the QR is fast enough, it's the other stuff that is inconvenient. I've experienced all of these:

a) I didn't see the code on entering

b) I did see the code, get the phone out, start the app...

c) Someone (a security guard) is standing in front of the code

d) The lift arrived, catch the lift or scan the code?

e) I'm leaving... Oh, look, there's the code, scan it now?

f) I left, and forgot to tell the app (it defaults to 4 hours before expiry)

The resulting records are likely to be incomplete and inaccurate.

The size of the venues is highly varied... restaurants are now required to display the code, and eat-in customers must either scan it or record their details manually, so every corner cafe has a code. So do 20+ floor Government buildings with thousands of people. There's a large public hospital with multiple buildings with QR codes at each entrance, and some of the buildings are linked by bridges, without QR codes. Is it counted as one venue or many? Either you end up testing far more people than have possibly been within shouting distance of a case, or you miss close contacts, or, most likely, both.

Interestingly, during public briefings on the latest figures, Government officials have not reported the number of cases that were detected because of this “LeaveHomeSafe” app. I won't speculate why.

SpaceX small print on Starlink insists no Earth government has authority or sovereignty over Martian activities

Allan George Dyer
Paris Hilton

Re: What a surprise

@Jellied Eel - "complete with modified claymores and Davy Crockett nuclear bazookas"

Are the claymores anti-personnel mines, Scottish swords, or both? I'm imagining Highlander in Spaaace.

OTOH, Davy Crockett's Nuclear Bazookas sound like a classic porn film title.

Co-founder of coronavirus vaccine biz holds in-person tech event... 20+ attendees later test positive for COVID-19

Allan George Dyer
Boffin

More data required...

So, what sort of masks were the production crew wearing? Assuming the level of interaction was roughly the same as the participants during the event (possibly a bad assumption, if some stayed in the control room the whole time), the masks appear to have been completely effective at protecting their wearers. We know even improvised masks are highly effective at protecting other people if the wearer is infected and asymptomatic. Were the crew wearing N95 masks, or something less effective?

My bad! So you're saying that redacting an on-screen PDF with Tipp-Ex won't work?

Allan George Dyer
Joke

Re: Lego™®

@Mage - "Or warhammer models"

You mean the ones where the 25mm tall figure is wielding a 6-foot sword? Not a scale 6-foot sword, literally 6-foot.

Accused murderer wins right to check source code of DNA testing kit used by police

Allan George Dyer
Headmaster

Wolly thinking

"overestimate the likelihood of guilt" - While I agree with the Appeal Court's decision, they could do better in describing their reasoning. The test doesn't determine guilt, it matches, or fails to match sample A to person B, the meaning of the match depends on the context.

Or have we reached beyond thoughtcrime to the point where genetics can be used to identify evil races? Icon: Godwin's Law.

You would expect a qualified electrician to wire a building to spec, right? Trust... but verify

Allan George Dyer

Flexible plugs

@WhereAmI - "With a bit of care you can get European two-pin plugs to fit the Indian old-style British round pin sockets"

Hoover used to do a rubber 2-pin plug that would deform to fit the spacing on 2 or 3 pin (unshuttered) UK sockets. I'm not sure if it would fit a European socket, the pins might have been too thick.

Smartphones are becoming like white goods, says analyst, with users only upgrading when their handsets break

Allan George Dyer
Coat

Re: I'm not sure I saw it in the article...

Obvious, their device breaks when they drop it.

OK, I'll get my coat.

Allan George Dyer
Coat

Am I an outlier?

I only replaced my first smartphone last year, and that was when it died.

Apple reportedly planning to revive the MagSafe charging standard with the next lot of MacBook Pros

Allan George Dyer
Boffin

"MagSafe charging standard"?

What standard? I like MagSafe, but I was annoyed that I couldn't use the old PSU from a broken MacBook Air with a new MacBook Air, because the MagSafe connector was a different size.

Airbnb, or not to be, if you're headed to Washington DC: Biz cancels bookings over fears of inauguration insurrection

Allan George Dyer
Windows

Golf, not Insurrection

So these armed hate-groups are going to turn up to the inauguration cold and grumpy because they slept in the back of their pickup trucks?

How about offering them alternative accommodation somewhere warm, like Florida? Hey, there's an idea, spread a rumour that Donald likes them so much he wants them to hang out by his pool and play a round of golf. The course is empty, now the PGA has dumped him.

United States Congress stormed by violent followers of defeated president, Biden win confirmation halted

Allan George Dyer

Re: ...and where exactly do you live in the US?

"over the span of the pandemic"? Jake, the pandemic is not over. I checked today's figures at https://covid19.who.int/table :

Cum cases/mill Cum death/mill %

USA 65053 1070 1.64%

Canada 16391 430 2.62%

So that agrees with your figures, but this isn't a good way of calculating the mortality rate. Deaths trail infections, so if the number of cases is rising steeply, the rise in deaths will be in a few weeks or months, and the rate calculated today will be lower that the final figure. Is that the case here? I don't know.

Supposing there is a real difference in mortality... you (well, USA health professionals) should be telling the world what they are doing differently. Canada and the USA both use Western medicine, and there is mobility of professionals between the systems, so the treatment (as opposed to how the treatment is funded) should be pretty similar. Can you identify a difference that could account for the claimed difference in mortality, or is it just an anomaly caused by the dynamic nature of the statistics?

Allan George Dyer

Re: ...and where exactly do you live in the US?

https://covid19.who.int/table

Cumulative deaths per million population:

Canada 426

USA 1059

Tell me again, Jake, who's doing better against Covid-19?

US aviation regulator issues safety bulletins over flaws in software updates for Boeing 747, 777, 787 airliners

Allan George Dyer
Coat

Re: A Boeing Spokesperson said:

He's not lying, "Safety" is, in fact, the name of the CEO's white Persian cat.

Pure frustration: What happens when someone uses your email address to sign up for PayPal, car hire, doctors, security systems and more

Allan George Dyer
Facepalm

Re: Netflix

@AC - "Thanks to the person in Mexico that signed up and paid for Netflix with my email address :-)"

You lucky s*d! All I get from Netflix is that they're going to cancel my (non-existent) account unless I pay immediately, sent from their well-known personal.name@cluelesscompany.com address.

You're going to need to unwrap and rewrap those Pi-400 holiday gifts. There's a new Raspberry Pi OS Update

Allan George Dyer
Childcatcher

Re: Never too young....

BatteriesUpdates Not Included.

Who knew that hosing a table with copious amounts of cubic metres would trip adult filters?

Allan George Dyer
Paris Hilton

Archaic Usage

Until recently, the HK government was fond of using "cum" in it's meaning of "combined with". Who wouldn't want to use a litter cum recyclables collection bin?

However, I declined the invitation to a "Networking cum drinking party".

China offers world its COVID QR Code movement passport at G20 Leaders' Meeting

Allan George Dyer
Paris Hilton

Multi Apps are available

"It has since become ubiquitous, racked up billions of uses and is now to be adopted in Hong Kong."

The HK Government is currently promoting a different app, which relies on users scanning a QR code at participating venues, not the other way around like Xi Jinping's app.

I'm confused.

Not sunshine, moonlight or good times – blame it on the buggy

Allan George Dyer
Trollface

Unexpected Error

So, the other errors were all expected? Why didn't you do something about them.

Reports of one's death have been greatly exaggerated: French radio station splurges obituary bank over interwebs

Allan George Dyer
Alien

French Technology

What RFI is not saying is that their chief engineer is from Gallifrey, and un problème technique involved the temps et dimension relative dans l'espace.

Let's... drawer a veil over why this laser printer would decide to stop working randomly

Allan George Dyer
Facepalm

Re: Never under estimate the ability of a user to out stupid you

Randolf McKinley - "there's no great and compelling reason for a non-technical person to know it needs skin contact or optical visibility of the finger to work"

Where do you find employees who have never watched a crime drama? If it's not a major plot-point, it generally gets mentioned as an aside.

Why do users remember the dodgy "zoom and enhance" and magical hacker cliches, but not a simple 'wearing gloves = fingerprints hidden' ?

Tech support scammer dialed random number and Australian Police’s cybercrime squad answered

Allan George Dyer
Devil

“Police recommend that you do not engage with scammers,”

So what do we do for entertainment now? Particularly as some places enter a new lockdown.

Suggested conversation extenders:

"So, where is this 'Any' key?"

"How do you spell dub-dub-dub?"

"Is this about the delivery of my duct-tape, pincers and spade?"

Did I or did I not ask you to double-check that the socket was on? Now I've driven 15 miles, what have we found?

Allan George Dyer
Paris Hilton

Re: Can't be arsed

How about a new script:

1. Is it turned on?

2. Is it plugged in?

3. Is the alligator in position?

4. Is the socket turned on?

If the user answers "Yes" to question 3, refuse the callout until the dangerous animal has been removed.

After Dutch bloke claims he hacked Trump's Twitter by guessing password, web biz says there's 'no evidence'

Allan George Dyer
Joke

'Twitter says it has "no evidence" this claim is true.'...

So the hacker posted the most outrageous lies he could think of as The Pres, and no-one could tell the difference?

ISS air leakage fixed in time for crew handover, thanks to floating teabag

Allan George Dyer
Joke

The first commercially funded airlock?

Let me guess, it lets you out for free, but charges on the way in...

"I'm sorry Dave, your credit card limit has been exceeded."

Lift us up where we belong: UK's Network Rail puts elevators online

Allan George Dyer
Joke

Think of the possibilities...

If this is successful at getting status information to the public, they could extend it to inform maintenance teams at some point.

Five Eyes nations plus Japan, India call for Big Tech to bake backdoors into everything

Allan George Dyer
Coat

Re: "How would they stop terrorists from sharing keys"

@LDS - Only if they know about it. Never heard of steganography?

Mine's the one with 200 hours of cat videos in the pocket.

From the Department of WCGW: An app-controlled polycarbonate lock with no manual override/physical key

Allan George Dyer
Alien

Re: Cabeaux tape can get a cab.

I think you mean this one: http://www.doctorwhoreviews.altervista.org/2005-09_files/The%20Empty%20Child%20(8).jpg

A decades-old lesson on not inserting Excel where it doesn't belong

Allan George Dyer
Joke

Re: Is my memory failing..

A CSV library for C, Java or Python? Why not use Perl instead, then you can choose from Text::CSV_XS, Text::CSV_PP or Parse::CSV. Choice is good, right?

Obligatory xkcd

What a Hancock-up: Excel spreadsheet blunder blamed after England under-reports 16,000 COVID-19 cases

Allan George Dyer
Facepalm

How to double the problem...

"For now, we're told, the solution, for want of a better word, is to break the data into two or more spreadsheets."

Incidently, has anyone mentioned handling of US date formats yet?

In other news, due to a Y2K problem, all the statistics so far are from the Spanish flu pandemic.

Hydrogen-powered train tested on Britain's railway tracks as diesel alternative

Allan George Dyer
Coat

Re: Unloved?

Ah yes, the Snow Hill line. I moved into a house on Farringdon Street which had a 12-foot chimney from the line passing through it, occasionally inspected by a BR steeplejack. The real surprise was that, in the deepest winter, the house somehow conspired to be colder than outside. Well, that and the unexpected mercury leak from a disused basin U-bend.

The perils of building a career on YouTube: Guitar teacher's channel nearly deleted after music publisher complains

Allan George Dyer
Flame

No Appeal

I don't know why Penman thinks that only success channels incur the wrath of the industry. I used Scott Joplin's The Entertainer, taken from an original (1900ish?) piano roll as background music on a video and the copyright owners of the film The Sting put a strike against me. That, to my mind, is a false claim, they didn't compose the music and had nothing to do with the production of the piano roll. So, I appealed with an explanation, and got a blank response that they were pressing the claim. I wasn't willing to start an expensive legal battle over a video that will probably be viewed by almost no-one so that part of the video is now silent.

Don't pay the ransom, mate. Don't even fix a price, say Australia's cyber security bods

Allan George Dyer
Pirate

There's room for different strategies among the criminals... the ones looking for a stable, long-term criminal income diligently provide the restore keys for victims that pay, and build a reputation. This provides an opportunity for "cowboys" that just trash the data and take the ransom, effectively feeding off the "reputation" of the "honourable" criminals.

A plague on both their houses.

When Irish screens are borking: Ticketing trip-up for Dublin-based Windows 10 IoT terminal, but at least it's not XP

Allan George Dyer
IT Angle

Re: Irish Gauge

Obligatory XKCD

UK national debt hits 1.46 Apples – and weighs as much as 2 billion adult badgers

Allan George Dyer

red.grey ?