* Posts by TrevorH

197 publicly visible posts • joined 22 Sep 2009

Page:

How do you solve a problem like Discovery?

TrevorH

I seem to recall that the Chinese had a line of really large balloons that may or may not have accidentally flown over the continental USA by mistake and been shot down. Maybe they can borrow half a dozen of those and strap the shuttle to them and airlift it to where it needs to go.

Radiant Group won't touch kids' data now, but apparently hospitals are fair game

TrevorH

https://www.bbc.co.uk/news/articles/cpvlgzk0xvpo

Scattered Lapsus$ Hunters offering $10 in Bitcoin to 'endlessly harass' execs

TrevorH

So, how long a period in jail for harassment does $10 buy you?

Firewall upgrade linked to three deaths after Australian telco cut off emergency calls

TrevorH

What possible relationship is there between a firewall and calls failing to one specific number when all other calls connect correctly. A firewall might block ALL calls but calls to a specific destination, no, I don't think so.

As Xi and Putin chase immortality, let's talk about digital presidents-for-life

TrevorH

Thatcher was gone within months of saying that she intended to "go on and on". Is it too much to hope for that a similar fate awaits these 2 morons?

GNOME Foundation boss exits after just four months

TrevorH

I'd apply for the job but I'd want to throw out everything done since gnome 2 and start over with something that actually works for human beings.

Gadget geeks aghast at guru's geriatric GPU

TrevorH

Re: A graphics card?

Last time I saw an article about what he uses for development it was some form of threadripper or EPYC desktop board so, yes, no iGPU if it's the same machine.

Oracle VirtualBox licensing tweak lies in wait for the unwary

TrevorH

Re: VirtualBox 7.1 released Sep 9, 2024

There are several "rings" in x86 architecture and OS/2 is unusual in using more than just 2. Most things use 0 for kernel and 1 for user space. OS/2 uses ring 2 as well and not all hypervisors emulate it correctly (or maybe at all). VBox came from Innotek software, a German company that used to write OS/2 software so they made it work.

Innotek got bought by Sun(?) and then acquired by Oracle which is how Oracle ended up with it. I don't think Oracle bought Innotek directly, I think they acquired it via another purchase but I may be wrong about it being Sun.

Firefox is fine. The people running it are not

TrevorH

It's pretty easy, what Mozilla needs is a management team that use a web browser on a daily basis. All day, every day. And they need to be focused on making it easy to use, fast, accurate, cross platform, secure and stable. Not necessarily in that order. Oh, and I guess they need to know how to make money too.

Ubuntu 25.10 and Fedora 43 to drop X11 in GNOME editions

TrevorH

I have seen conversations with people that are very familiar with the X codebase and they were of the opinion then, about 10 years ago, that it was a complete security nightmare that could probably never be fixed completely. They also said that most of those security problems had been known for 20 years, now 30 years, and were as a result of the way it was designed. From that point of view I can absolutely see why they would want to do this. It's also possible that they're sitting on a bombshell CVE that they can't disclose (no knowledge of that here, just speculation).

TrevorH

If they remove X support from Fedora 43, how will that affect all those other Window managers that are listed as alternatives to gnome? For example, can you still run MATE or xfce on a Fedora 43 that has no X support? I don't think wayland support on either is particularly great if present at all.

RHEL 10 quietly leaks ahead of Red Hat Summit

TrevorH

RHEL 8.10 was already the last point release to receive "new hardware" updates and that was released about 6 months ago. From now on it's security updates to 8.10 only for the next 4 and a bit years of its 10 year support period. You have plenty of time yet. But no new enhancements.

TrevorH

You don't seem to need to do anything special to see if from my login. I get in to redhat.com and go to the download link then to "All downloads" and it shows me all the links to download 10.0 isos, 4 of them, boot, binary, realtime and virtio-win isos plus 2 image files for KVM and WSL2. This is from a free developer subscription renewed about a week ago.

Direct download https://access.redhat.com/downloads/content/479/ver=/rhel---10/10.0/x86_64/product-software will require a RH account.

AMD is Ryzen to the SMB occasion with a bundle of baby Epycs

TrevorH

I wonder why it maxes out at 192GB RAM when the desktop variety can use up to 256GB (if youcan find 64GB DIMMs). Perhaps there are no ECC 64GB DIMMs...

Microsoft tries to knife passwords once and for all – at least for consumers

TrevorH

Dear Microsoft

Please FOAD.

See I was polite, I said please.

Nationwide power outages knock Spain, Portugal offline

TrevorH

Re: To channel a certain class of reader ...

> Not relevant to ME?

And how close do you think .uk might be to exploring this new avenue of electricity delivery? If it is a cyber attack, would you rather read about it now in another country or wait until it arrives on your front doorstep?

Don't delete that mystery empty folder. Windows put it there as a security fix

TrevorH

IIS is still listed as having a 4% share of the web server market. There's an awful lot of web servers out there so 4% would still be a large number if you were needing to patch them all...

Trump's tariff turmoil leaves IT projects in deep freeze

TrevorH

I thought that HIGNFY quote was good too but I went to Google it to find out who had said it and it turns out it has been around in one form or another since 2019ish so it predates the current reported use by several years.

UK's answer to DARPA sprouts new ideas, like programmable plants

TrevorH

Are you sure this whole thing wasn't from a press release dated April 1st?

Hm, why are so many DrayTek routers stuck in a bootloop?

TrevorH

> What exactly, can your proprietary router do that this cannot?

Speak directly to a DSL connection without a separate modem?

TrevorH

Re: Over reaction

That rather depends on what security error your browser was showing. If it's "hey the self signed SSL certificate is... self signed" or, judging by the date on my Draytek's SSL cert, it is baked into the firmware and expires in about a year so not upgrading looks likely to give you a cert expired error. Which might encourage you to go in search of an update...

TrevorH

Bullet point #1 in the release notes for the 2762 3.9.9.2 firmware:

- Improved: Improve the web GUI security.

No sh*t!

TrevorH

Front page of the web UI shows you the current modem code that's in use like

DSL Version 8D1B17_A/B/C HW: A

You can use that to work out which firmware file to download.

BT unplugs plans to turn old cabinets into EV chargepoints

TrevorH

I imagine an EV charger also requires significant quantities of power that a green comms cabinet probably didn't need so the "they're already connected to power" point is probably moot.

Infoseccer: Private security biz let guard down, exposed 120K+ files

TrevorH

Their response appears to be the usual "kill the reporter, ignore the cause". Inspires confidence.

Win a slice of XP cheese if you tell us where Microsoft should put Copilot next

TrevorH

We're competing for a prize that no-one wants or has a use for?

Open source router firmware project OpenWrt ships its own entirely repairable hardware

TrevorH

Call me when they ship a model with 3 x 2.5GbE ports.

RHEL 9.5 debuts alongside AlmaLinux, Rocky, and Oracle updates

TrevorH

> We confess to a moment's amusement at reading this section of the docs:

Even more amusing when you know that Lennart works for Microsoft these days.

AI PCs: 'Something will have to give in 2025, and I think it's pricing'

TrevorH

AI is to PC what 3D is to TV

The troublesome economics of CPU-only AI

TrevorH

> As we understand it, hyperthreading was disabled for these tests, so only 88 of the VM's threads were actually active.

What? Are you sure that's a valid assumption to make? 176 vcpus on a VM would be 176 vcpus whether you have HT enabled or not.

FortiManager critical vulnerability under active attack

TrevorH

Surely the issue is that they *silently* patched the vulnerability and released a new version without telling anyone that the bug existed or that it was fixed.

CIQ takes Rocky Linux corporate with $25K price tag

TrevorH

Re: RH support levels

You did see the bit in the main article that says "Support is available separately." ?

TrevorH

Re: $25,000 for an annual subscription?!

> Imagine you were the system engineer of a multi-million corporation. If the system went horribly wrong

If I were, I'd be paying Red Hat not the monkey.

OS/2 expert channeled a higher power to dispel digital doom vortex

TrevorH

Or you could just press and hold the key combination when the WPS starts up which stops it from restarting the running things.

"You can prevent the WPS from starting applications during startup by pressing Ctrl-LeftShift-F1 when the desktop first appears."

That doomsday critical Linux bug: It's CUPS. May lead to remote hijacking of devices

TrevorH

The issue linked is to one that is public because it appears to be less severe. It mentions other fixes to libcupsfilters and libppd which are not public so are presumably more severe. I am dubious whether these will end up being as severe as the hype makes out.

AMD reverses course: Ryzen 3000 CPUs will get SinkClose patch after all

TrevorH

> Does Windows fair any better in getting microcode updates for the non Epyc chips?

No. It's a desktop processor thing not an operating system thing.

AMD won’t patch Sinkclose security bug on older Zen CPUs

TrevorH

Desktop Ryzen 3000 series now showing a fix version of:

ComboAM4PI

1.0.0ba

(2024-08-16)

TrevorH

The link to the AMD CVE details page has changed since I looked at it when this article was first published. It now says under "Ryzen 3000 Series Desktop" "(Target 2024-08-20)" so that looks to me like it is being fixed for the 3x00X series after all.

MDM vendor Mobile Guardian attacked, leading to remote wiping of 13,000 devices

TrevorH

MDM is that Man in Da Middle?

How deliciously binary: AI has yet to pay off – or is transforming business

TrevorH

Dotcom boom n bust all over again

Dotcom boom n bust all over again. Does anyone actually believe in this miracle cure?

Users rage as Microsoft announces retirement of Office 365 connectors within Teams

TrevorH

Update 07/23/2024: We understand and appreciate the feedback that customers have shared with us regarding the timeline provided for the migration from Office 365 connectors. We have extended the retirement timeline through December 2025 to provide ample time to migrate to another solution such as blah blah blah

Is Teams connector retirement a tweak to fit EU laws, or a sign of price rises to come?

TrevorH

They blinked:

Update 07/23/2024: We understand and appreciate the feedback that customers have shared with us regarding the timeline provided for the migration from Office 365 connectors. We have extended the retirement timeline through December 2025 to provide ample time to migrate to another solution such as...

TrevorH

Interesting, the SPAM that was being appended to each webhook post saying "Action required, we're screwing you over" has now gone away. As of about 05:00 BST this morning, that SPAM stopped.

TrevorH

The current connectors use a domain per customer like $company.webhook.office.com and then go on to add another 3 UUID's to the hook url plus another random string that looks suspiciously like another uuid with the '-' characters removed. Total length minus the identifiable company + webhook.office.com is around 170 bytes so it's not what I'd call easily guessable. So first step for anyone wanting to exploit a security vulnerability in a webhook is to guess the 170 character random string so they can post to it. Sure, that's security by obscurity but you need to know the correct url to be able to get to it.

Microsoft to intro checkpoint cumulative updates for Win 11

TrevorH

It's not the bloody size, it's the TIME it takes. I can update 100 linux systems while the progress bar on Windows Update is still spinning. How can it possibly take longer to patch an installed windows system than it does to install it in the first place?

CentOS 7 holdouts thrown a support lifeline by SUSE

TrevorH

Better than the quote I got from CIQ which worked out at $500 per server per year.

Brit tech tycoon Mike Lynch cleared of all charges in US Autonomy fraud trial

TrevorH

Does indeed seem to be true, other news sites are reporting it in more detail like https://www.bbc.co.uk/news/articles/cneel8ed2vvo

What can be done to protect open source devs from next xz backdoor drama?

TrevorH

Nice selective quoting there... the original says "ordinarily used by ..." meaning xz the package, not restricting it just to the compromised version.

Iowa sysadmin pleads guilty to 33-year identity theft of former coworker

TrevorH

This guy was on freenode and then libera.chat IRC in the #centos channels for years and came across as a thoroughly nasty person.

The Hobbes OS/2 Archive logs off permanently in April

TrevorH

This is not the first time that hobbes has announced it's going away. Last time it was rescued after a lot of complaints and a number of students or faculty came forward to continue to maintain it.

Page: