* Posts by Glen 1

960 publicly visible posts • joined 17 Jun 2009

Someone not only created a comment-spewing Reddit bot powered by OpenAI's GPT-3, it offered bizarre life advice

Glen 1

Do AIs dream of Reddit posts?

"I wonder if only OpenAI or someone with GPT-3 can detect it,"

Voight-Kampff?

Global Privacy Control emerges as latest attempt to let netizens choose whether they want to be tracked online

Glen 1

Re: Browsers

"third party service of some kind"

Which would make it trivially easy for browser clients to isolate.

The point of the container is not to block everything (ala noscript of ghostery), as many sites deliberately break themselves if they detect ad blocker type behaviour. The point is to have every domain see its own browser, forcing third party services to infer/guess connections between sites rather than the tentacles we currently have.

Third party cookie isolation is just the start. No eTags outside of first origin. Each container getting its own cache etc

The main countermeasures to such moves include things like OAuth, where its the first parties sharing information directly with each other, cutting out the third party middleman.

Also, isolating separate accounts with the same service is still a pain. Log in to a family-facing Facebook account, then switch to an account showing a less culturally accepted side of you? That account is probably going to show up on your family's "people you may know" feed. Or worse - it will be given as a "helpful" option to login as on a shared machine - a potentially life threatening situation in certain parts of the world.

That said, if you are spending enough time on any single service, they probably have enough information (search habits, browsing preferences) on their own to build a useful ad profile on you, without having to link to any other site/service.

Glen 1

Browsers

Surely its down to BROWSERS to enforce this type of thing? or at least mitigate against the snoopers?

Don't allow 3rd party cookies (and possibly code), or at the very least, don't allow them to persist across different first party domains.

Firefox has already started doing this for its "Facebook Container". This should be the default. A container for each 1st party domain visited, not "let everyone have everything" unless specified.

It boils down to the point others have already made. Asking someone not to collect/sell your data, when that is their entire business model, is like asking the wolves not to raid the chicken coop. Its in their little wolfy natures.

As exemplified by the hoops you have to go through to do anything other than "allow all cookies" on many sites.

ICANN begs Europe: Please fill in the blanks on this half-assed GDPR-compliant Whois we came up with

Glen 1

Re: The Gordian Knot

They "effectively shut down" whois in the EU, so are technically compliant.

The paymasters are whining about it, but it looks like the EU is carrying the bigger stick.

Big IQ play from IT outsourcer: Can't create batch files if you can't save files. Of any kind

Glen 1

A bit like replacing Utilman.exe with cmd on Windows 10.

Pack your bags! Astroboffins spot 24 'superhabitable' exoplanets better than Earth at supporting complex life

Glen 1

Re: Warmer.

Say there is a planet out there without moons, that also has intelligent life.

The locals might posit that a planet *with* large tides might make it impossible for life, what with all that sloshing about and all that.

Excel Hell: It's not just blame for pandemic pandemonium being spread between the sheets

Glen 1

Re: VBA Security Security Security Security... I can't hear you!!!

Given the propensity for JavaScript libraries dedicated to graphing and similar, do you (the el Reg readers) think the move to web-based stuff is an improvement on Excel?

I suppose having a JS front end implies there is a proper database somewhere at the back...

Glen 1
Trollface

Re: Alternative?

"point-and-drool interface"

Isn't that what VB was for?

Glen 1
Coat

Re: Alternative?

"Whatever happened to Access?"

It was taken over by Mastercard.

US comms watchdog calls for more scrutiny of submarine cables that land in 'adversary countries'

Glen 1
Paris Hilton

Re: Encryption

"You don't have much work "managing keys" if you encrypt on one end and decrypt on the other."

Encryption isn't just a magic wand you can wave over something. It has 2 parts. The algorithm and the key. The key itself can be a key pair in the case of asymmetric cryptography. Unless you have invented some other type of magical keyless cryptography...?

Will they keys/algorithms ever change as technology improves? How do you switch from one to the other without disruption?

"they aren't going to ask you to decrypt in the middle of the Pacific"

They don't need to. Read the article. Its about cable landing in China. They just have to tap the network company on the shoulder and say a condition of operation is giving them the ability to do a "lawful intercept" - which is whatever they say it is. That includes putting the data in the form they receive it (ie undoing any decryption the network folk have done)

Submarine cable interception is useful when you don't have access to one or more of the endpoints. eg For 5 eyes countries , intercepting links between any 2 non 5-eyes countries.

"The customers WILL be managing their own risk, because they can encrypt whatever the hell they feel like before they pass the data to the submarine cable provider. "

That's what I said. Why is that hard for you to understand?

"You're kind of thick, aren't you?"

It isn't *me* who thinks encryption is just a question of shouting "ITS ENCRYPTED", magical encryption person.

Don't get me wrong, I think the traffic *should* be encrypted (see my other comment about STARTTLS). That way even the "lawful interceptors" only see an encrypted stream. However, I don't see it as the cable operator's responsibility. That's why spy agencies don't like end-to-end encryption,.

Saying "just encrypt it" then showing a basic lack of understanding of what that entails while calling other people thick... Are you a manager?

Glen 1

Re: Encryption

"No "

What part are you saying no to?

"No need to manage keys or be responsible for someone else's security"

That is literally what you are doing by encrypting the line.

Encrypting the entire wire is fine until you get a nice lawful letter saying "Decrypt it for us, or else. Oh by the way, you can't tell anyone you're doing it."

Like the person you are replying to says -

"A carrier or in this case the undersea cable operator would not want to maintain encryption keys for other people's traffic "

Its a cost to do it, a liability if its not effective, you can be legally coerced to undo it for powers that be, and you won't be allowed to tell your clients that you've been forced to undo it. Even if you were allowed, your business has just admitted the encryption is pointless.

Better to state its in the clear to begin with, and let your customers manage the their own risk.

Glen 1

Why would you be sending data unencrypted anyway? If your traffic is in the clear, that's not a problem checking transit routes will solve. Whadya mean your email provider cant even use STARTTLS? (firewall of china MITM notwithstanding)

Traffic analysis metadata (who talks to who and how often), can be obtained *lawfully* by any western government.

Why complain about other govs going it also?

There ain't no problem that can't be solved with the help of American horsepower – even yanking on a coax cable

Glen 1
Joke

Wouldn't that make it Sword-ering?

Open-source devs drown in DigitalOcean's latest tsunami of pull-request spam that is Hacktoberfest

Glen 1

Don't be afraid to commit

I think that perhaps contributors should be in a more structured workshop such as "Don't be afraid to commit"

Bill Gates lays out a three-point plan to rid the world of COVID-19 – and anti-vaxxer cranks aren't gonna like it

Glen 1
Coat

Re: If Bill Gates has the technology to implant chips to control people's behavior

It looks like you are trying to write a letter create the back story of the Universe.

Would you like help?

I love my electricity company's app – but the FBI says the nuclear industry bribed politicians $60m to kill it

Glen 1
Trollface

Re: Scandal, but not this

Careful, that sounds like socialism.

NATO's at risk if you go your own Huawei on 5G, US government warns Germany

Glen 1
Facepalm

Re: @Potemkine!

*their dependency on the American military industrial complex.

My Bad

Glen 1

Re: While etc.

"It is wrong and detestable, but it has nothing to do with NATO or military funding."

Perhaps "I think Ukraine and Syria might disagree" would have been a more on-topic response?

Glen 1

Re: @Potemkine!

"The final straw seemed to be the EU pissing money on their own GPS and wanting to make their own army."

Yes, I mean HOW DARE THEY want reduce thier dependancy on the Amercian military industrial complex. How UNPATRIOTIC er... I mean UNAMERICAN

Glen 1

"Angela Merkel appears unpersuaded by US aggression"

That's what happens when you have a spine.

Its interesting to note that the UK is no longer a lever the US can pull to influence EU decision making.

Inflated figures and customers who were never there. Just another data migration then

Glen 1

motor or pedal?

The choice will make a big difference

Glen 1

"grep party"

Reminds me of the time as a PFY I tried to write a web scraper/parser in bash/grep/sed. I didn't know there were already tools for that. I didn't google it, because I already had curl and grep. What more could I need?

Ah, the innocence of youth.

Xen Project officially ports its hypervisor to Raspberry Pi 4

Glen 1

Will be interesting to see how the GPIO is handled.

Happy Hacking Professional Hybrid mechanical keyboard: Weird, powerful, comfortable ... and did we mention weird?

Glen 1
Coat

Re: You should be ashamed of yourselves!

I shall write a letter!

Help! My printer won't print no matter how much I shout at it!

Glen 1

Re: Lots of great stories, as usual...

Because you can do 1-3 without leaving the comfy chair.

IT guy whose job was to stop ex-staff running amok on the network is jailed for running amok on the network

Glen 1

In many of the stories like this that get reported, the wannabe BOFH got caught because of... incompetence.

It makes me wonder how many *competent* folk have pulled such shenanigans and never been caught.

Not Particularly Mortifying: IEEE eggheads probe npm registry, say JavaScript libs not as insecure as feared

Glen 1

Re: Phew! We're safe then!

See also: Flatpak and Snap

India shows off new home-grown CPU – but at 100MHz, 32-bit and 180nm, it’s a bit of a clunker

Glen 1

Re: RISC-V Pi

I think its more that the Raspberry Pi foundation takes a pragmatic approach to openness.

As in (paraphrased) "as open as we can be, but not minding some closed stuff where it makes sense".

It was thanks to pressure from Eben et al, that the first set of open source graphics drivers for the Pi were released. (although it turns out they were just a shim for the onboard functions). These days we have full OpenGL ES 3.1 conformance through Mesa, with Vulcan incoming.

Remember, the early prototypes for the Pi bore more of a resemblance to the Arduino Uno than the eventual Pi 1.

Quote from Eben referring to toolchain assistance:

"We believe that instruction-set diversity is important, and that open, free instruction set architectures are an important enabler for innovation. Our impression is that the hardware side of things is going pretty well. We think we can contribute on the software side, which is important if RISC-V is going to become a viable alternative for desktop general-purpose computing."

Microsoft will release a web browser for Linux next month. Repeat, Microsoft will release a browser for Linux – and it uses Google's technology

Glen 1
Trollface

Re: "This means Linus Torvalds has definitely won, doesn't it?"

Wot, BSD?

We're not getting back with Galileo, UK govt tells The Reg, as question marks sprout above its BS*

Glen 1

Re: Hoots Mon

"telling people one thing (socialist utopia) and the required fact (cut public spending harshly)"

Those things aren't necessarily mutually exclusive. It would help if we stopped pissing money away on rich people. The Lords 'attendance allowance' is, per day about the same a job seeker gets in a month.

That's not to say I think the Lords shouldn't get anything, but we are currently nickel-and-dime-ing the poorest in society while spaffing - *picks at random* - £43m of public cash for a garden bridge that was never built - and even *that's* small potatoes compared to the current/impending clusterfucks.

I wonder what percentage of the recent "emergency contract" funding is now in the usual tax havens?

Glen 1

Re: "Europe (UK included) exist under the protection of the US military"

Given the recent assassination successes/attempts with Polonium and Novichok - our overt response has been... to eject diplomats. Oh no! I'm sure they are shaking in their boots!

We also sanctioned people close to Putin, but thanks to the weak link that is the UK financial system, that has not been as effective as we might have hoped (see recent FinCen leaks)

Russia can kill people in our countries with apparent impunity. They will keep doing it until there are consequences. That's without even mentioning Crimea... There is a reason a lot of the Baltic states were clamouring to join NATO.

Given the Brexit Politicians -> Aaron Banks -> Russia money trail, that the UKs *own investigators* were told *not* to investigate. It doesn't take a rocket scientist to see Russia as serious threat.

Like the man said:

“We have crushed the British to the ground, they are on their knees and they will not rise for a very long time.” - Aleksandr Yakovenko, summing up Russian achievements during his tenure as UK Ambassador, 2011-19.

Space. The final frontier. These are the voyages of 'Advanced Night Repair' skin cream helping NASA to commercialise space

Glen 1
Coat

Re: Once the glamour shots are done...

Oh No! The wrinkly panels are there so they can freely expand and contract under thermal changes.

From SR-71 Wiki page:

"The heat would have caused a smooth skin to split or curl, whereas the corrugated skin could expand vertically and horizontally and had increased longitudinal strength."

IGMC

Glen 1
Alien

Oblig

No, have you?

Context: YouTube Link

Glen 1

Re: Time to hit the retros

That would come under the heading of "interfering with the space work".

Think of it as a sports sponsorship. You know the team, you know the game. Having a sponsor try to interfere with the game will piss off a lot of potential customers.

"you can't do X because it will piss Y off ... Government has already cut our budget "

Governments/space agencies have their own objectives separate from the commercial sector. If they actually want to get stuff done, they have to pay for it. Contributions from sponsors are greatly appreciated, thanks, but if an advertiser pulling funding jeopardises an actual mission, was the mission viable in the first place?

Glen 1

Re: Time to hit the retros

Its the disposable income of the gullible that is ultimately paying for the trip.

While I'd prefer the commercialisation to be a high-tech thing, if NASA can reduce their costs through sponsorship, I can only see a problem if it starts interrupting/interfering with the space work.

0ops. 1,OOO-plus parking fine refunds ordered after drivers typed 'O' instead of '0'

Glen 1

Re: And this ladies and gentlemen...

I suspect the problem expense for change-giving machines isn't the capital outlay, its the costs of keeping it stocked with change.

Its harder to rob a card terminal - assuming EMV these days - or at the very least, it requires a different skill set.

Elecrow CrowPi2: Neat way to get your boffins-to-be hooked on Linux from an early age and tinkering in no time

Glen 1

Re: Repetition = practice

"Learning those by rote is (unfortunately) the only practical way."

<sarcasm>I know! Its not like were going to be carrying devices capable of doing calculations with us 24/7</sarcasm>

Das Keyboard 4C TKL: Plucky mechanical contender strikes happy medium between typing feel and clackety-clack joy

Glen 1

Re: No typist needs lights

One of the the things missing from (some) typing trainers is a ghost keyboard on the screen highlighting the typed character.

When I mess up, I have to look down. It breaks the flow of things. Having it on screen means I no longer have to look down.

Anyone remember Typing of the dead? (Its sequel is available on Steam, and is Very NSFW)

Glen 1

Re: @ Mr Cumberdale

Numpad, I can live without. However, I'd be much obliged if I could get a keyboard with Home and End keys without having to do an 'Fn' related monstrosity.

I don't always get a choice though.

Chinese database details 2.4 million influential people, their kids, addresses, and how to press their buttons

Glen 1

Re: How many does that database say read El-reg ?

"Reading between the BS statement lines"

Clever people are better at rationalising. Healthy cynicism doesn't mean they can't be fooled. Dunning–Kruger effect applies.

UK and Japan agree to free trade deal that excludes data localisation requirements

Glen 1

Re: Cheese

How much is Liz Truss' salary again?

£80k for being an MP + £80k for being secretary of trade?

So her personal "win" is worth less to the UK than her salary.

Not to say there isn't other stuff involved, I'm sure she works very hard etc, but hailing this rounding error in trade as a win seems... desperate? Clutching at straws to overstate how good it is?

TBF, I haven't seen officials *themselves* mentioning the cheese specifically as a win, only the forever over-keen sensationalist press.

Glen 1

Re: 2nd?

The EU, when it acts as one, is a superpower.

If it ever manages to grow a spine, that is. (see GDPR and safe harbour)

Glen 1
Flame

Re: But this is the point

I dunno, given some of the high profile resignations in the Civil Service, there are at least *some* people for whom integrity isn't just marketing BS.

Of course those people are no longer in the Civil Service, so....

Glen 1

... and hope the other side still takes us seriously without the backing of the world's 2nd largest economy.

Vinyl sales top CDs for the first time in decades in America, streaming rules

Glen 1

For me, there are *whole genres* of music I would have never heard of if not for the "Continue playing songs like this after last song" thing on Spotify.

Kinda reminds me of the early days of internet file sharing where people would pad the file names with similar bands to aid discovery.

Hell, I'd never heard any Iron Maiden till the Carmageddon II soundtrack... These were the days where game music was extra tracks on the game CD, so you could play it on a regular player.

Radio used to be the primary means of new music discovery, "The rock and Metal show" on 12am on a weds isn't going to feature on peoples radars unless they seek it out... or come across it while channel hopping for music to fall asleep to.

Even when Kerrang Radio launched, it seemed to deteriorate into one sub-genre (emo pop punk), which in itself is fine, but when its gets difficult to differentiate between bands, let alone songs, that gets old fast. Add to that the fact you get at most 2 songs in a row without interruptions and you start wondering what the hell are you dong with your life.

Auto generated playlist with "continue playing" at the end, and suddenly a lot of the frustration goes away. A mix of the familiar and the new (to the listener).

Typical '80s IT: Good idea leads to additional duties, without extra training or pay, and a nuked payroll system

Glen 1

Re: whoops - wrong disk

"whoops - wrong disk"

I read that title and flinched.

NASA puts an Astrobee to work sweeping the ISS. Yep, floating cube good at taking pics and hanging around....

Glen 1
Holmes

Re: Bacronym Creator

Surely that would be Яetrofuturism?

or possibly even Яetroꟻuturism?

Adtech's bogeymen are tracking everything - even your web visits to mental health charities, claim campaigners

Glen 1

Re: Too much javascript

That only has an impact where you have a monetary relationship with the site directly.

With somewhere like el Reg, how do the writers get paid? Remember, it's the *advertisers* that pay their wages, and its the advertisers that have their 3rd party domains serving up ads. You could do some proxy stuff, where el Reg acts as a MITM between the ad server and the reader, but that would cost a bunch of resources that are currently unnecessary - not to mention potentially falling foul of some privacy laws and defeat many ad blockers.

You say you don't want to give your data? That makes you *substantially* less valuable as a reader to advertisers, and the writers company paying the writers gets paid accordingly.

All in all, not allowing 3rd party assets currently breaks a lot of stuff (CDNs, embedded YouTube vids etc)

That said, I largely agree with you. I feel there should be mechanisms for specifying which domains are in use for *code* and which are for content - Think NX-bit but for browsers. Email clients (should have) learned years ago that arbitrarily loading/running remote content is dumb as hell.

Web browsers need to be a lot smarter. Same-origin policy was a good start. Maybe specifying a whitelist? We are already bombarded by "please enable notifications" pop overs on lower quality sites, having 3rd party JS disabled *by default* would force web folks to be a lot less obnoxious about what they throw at us.

Q: How does hydrogen turn into a metal? A: Hang on a second, I need to train my AI supercomputer first

Glen 1

Re: Beware The Gosling effect

"borders on the ridiculous."

No more ridiculous than requiring space to have curvature in "another dimension" to explain gravity. Yet relativity (and spacetime) is one of the most rigorously tested theories we have. Hell, GPS has to account for it to work.

Quantum teleportation describes the *observed* phenomenon, much like dark energy and dark matter describe others. The theories as to *why* are... less clear

Remember, the Schrodinger's Cat thought experiment was a *critique* of the superposition theory (Copenhagen Interpretation). After all, saying the cat is somehow dead *and* alive "borders on the ridiculous". Yet it matches the observed results. (the superposition, not the cat thing -YKWIM)

*shrug* There are bigger brains than yours (or mine) working on it.