* Posts by tfewster

1285 publicly visible posts • joined 18 May 2007

Page:

Law firm 'didn't think' data theft was a breach, says ICO. Now it's nursing a £60K fine

tfewster
Pint

Re: "Commitment" is not enough

3 excellent points there, I can't upvote this enough.

SOX is a mandate for consultancy overreach by auditors who focus on the wrong issues.

CIS have a cheap checking & remediation tool, so there's no consultancy money in that. https://www.cisecurity.org/insights/blog/assess-remediate-and-implement-with-cis-securesuite

PCI-DSS is good on the prescriptive side, but bloated by external auditors

Microsoft total recalls Recall totally to Copilot+ PCs

tfewster
Facepalm

Sorry, maybe I didn't make myself clear

What part of "fuck off and die in a fire, you arseholes" did you not understand?

DO NOT WANT

Users hated a new app – maybe so much they filed a fake support call

tfewster
Flame

Re: Fake interest in product

My standard response to "local" or "in your postcode" is "Oh yes,what area/postcode is that?" <NO CARRIER>

If they try to continue their bluff with sales bullshit, shoot them down without mercy. <NO CARRIER>

Best one ever: Getting a second call from the same person: "Hi $NAME, didn't I call a bullshitting arsehole last time?" <NO CARRIER>

Signalgate: Pentagon watchdog probes Defense Sec Hegseth

tfewster
FAIL

Re: Who knew what and when?

They knew exactly what they were doing. Signal is fairly secure, though it doesn't meet governance standards.

What's curious to me is that none of these security oriented people thought to check "Who's in the room" before discussing sensitive topics. Does Signal hide the list of attendees?

Palantir suggests 'common operating system' for UK govt data

tfewster
Joke

Re: Computer Monocultures

I wondered whether he meant "common" as in "the same", which won't work as different OS's and platforms are optimised for different purposes.

Or "common" as in "low bred". Java would be an example of both - runs (badly & insecurely) everywhere!

Infosec pro Troy Hunt HasBeenPwned in Mailchimp phish

tfewster

I'm sympathetic to Troy, and not overly concerned that some of my email addresses have been pwned again - They're on his list because they're compromised anyway.

It seems to me that Troy's list is generally low value to baddies - Addresses only, for people who are security conscious and less likely to fall for a weak phish? (I know, famous last words!). It may be more valuable to spear-phishers.

16,000 subscribers sounds depressingly low for such a useful service - Am I missing something and "subscribers" is not the same as "registered email addresses"?

After three weeks of night shifts, very tired techie broke the UK’s phone network

tfewster
FAIL

Mistakes happen

Mistakes happen. The priority is to fix it, then prevent it happening again. But colleagues who will throw you under the bus are a sign of a bigger corporate problem.

No alarms? Network Management Centre didn't notice for a while? Weren't they supervising/supporting a critical system upgrade? If they reported the mistake they would have some tough questions to answer too. I'm not suggesting they should lie, but don't stir up trouble.

As a side note, I see a lot of Incident tickets with vague descriptions that are then closed as "resolved" with no diagnosis, troubleshooting or resolution info. It usually annoys me, but maybe they're covering up for mistakes like Wayne's without blowing up the issue?

US tech jobs outlook clouded by DOGE cuts, Trump tariffs

tfewster

Re: Absolute Fairy Story

More to the point, why waste peoples time applying for rigged positions?

Printers start speaking in tongues after Windows 11 update

tfewster
Windows

Re: Throw in HP

I suspect USB-attached printers are most likely on home installs, so the "Known Issue Rollback" process is probably useless to them.

Fortunately only adrenaline junkies would install a Microsoft preview, and they'll be thrilled by this bug.

FAA confirms it's testing Starlink, maybe for tasks Elon says Verizon is doing badly

tfewster
Thumb Up

Grease vs grise

https://en.wikipedia.org/wiki/%C3%89minence_grise

I'm not going to send it to corrections as it's a good pun, appropriate and probably intended!

US Dept of Housing screens sabotaged to show deepfake of Trump sucking Elon's toes

tfewster
Trollface

Re: Appropriate action will be taken

The Muskovite hasn't taken action to remove the video reposts from X yet. Maybe the first signs the two thin-skinned nutters are falling out?

HP ditches 15-minute wait time policy due to 'feedback'

tfewster
Flame

Re: Re-parse that response

What do you think is more likely?

- HP reverse the change, tell you actual wait times and staff their call centers to minimise those wait times. Oh, and improve the "digital" options.

- HP double-down on their lies, by telling you it's a "real" wait rather than an artificially induced one?

Looks like paywalls are coming soon to a subreddit near you

tfewster
Joke

Re: Advertising?

Wong said. "In a lot of conversation pages people are looking for recommendations". If Wong is right, maybe you're missing out by not viewing ads?

You're going to do what to the feature? Microsoft defines what it means by 'deprecation'

tfewster

Re: What “deprecated” means in software development

Agreed. Though I don't consider Windows 11 "better" in any way.

Trump eyes up to 100% tariffs on foreign semiconductors, TSMC in crosshairs

tfewster
Facepalm

I predict that all the big US chip consumers will move their consumption abroad, by building datacentres in a business-friendly country like Ireland. Services can be provided from anywhere, as we know.

- No tariffs on chips, check.

- Secure access to the European market, check.

- Low taxes, check.

- No living on tenterhooks waiting for the next wobbly from El Trumpo, check, mate.

Why does the UK keep getting beaten up by IT suppliers?

tfewster
Facepalm

Re: "unforeseen technical complexities"

It's curious that Accenture can take on outsourcing deals, come in and absorb local knowledge and take over running legacy systems and processes[1]. But apparently can't document a system they manage so support could be tendered?

[1] Yeah, they're crap at that too.

Tool touted as 'first AI software engineer' is bad at its job, testers claim

tfewster

Re: "rather than recognizing fundamental blockers"

"The marvel is not that the bear dances well (15% of the time), but that the bear dances at all." -- Russian proverb (Updated)

User said he did nothing that explained his dead PC – does a new motherboard count?

tfewster

Re: Please, please, please....

It's not much of a spoiler, we all know that "did nothing" is a lie anyway

AI pothole patrol to snap flaws in Britain's crumbling roads

tfewster
Thumb Up

Re: The fix is conceptual

Some great points there.

I posted "bin lorries" before I read your comment. The problem with manual reporting is it's distracting the workers from what they should be doing and duplication. Automated detection and reporting makes sense there.

tfewster

I've used Fill That Hole (developed by a Cyclists organisation?) in the past; I reported about 20 potholes in a stretch of worn out road, they were patched within weeks and the road was later resurfaced.

But for this "AI" to have comprehensive coverage, it needs to be fitted on bin lorries to cover all the roads in the area, not just the highways.

The channel stands corrected: Hardware is a refresh cycle business now

tfewster

Re: Add value

Resellers can add value by supplying software as well as the hardware, plus installation & configuration services. A one-stop shop. Not much use to a large enterprise with their own standard builds and volume agreements, but vital for smaller customers.

tfewster

Re: Pardon my ignorance. . .

. . . but what, pray tell, is The Channel?

At the risk of being boring: Sales channels are the places you offer your products or services to reach your customers.

Typical sales channels are manufacturers selling direct to large customers, or resellers/Value Added Resellers etc. expanding the manufacturers sales force to take on smaller customers. Personal buyers would go to a retail outlet or buy online, with few options for customisation or discounts.

"The Channel" in this case is the resellers.

Trump's tariff threats could bump PC prices by almost half

tfewster
Facepalm

Re: Avoid Imports?

https://madeintheusamatters.com/laptop-desktop-computers-made-in-the-usa/ Better sources of information may be available.

Ironically, Lenovo are on that list ;-)

One third of adults can't delete device data

tfewster
Facepalm

Re: Fallback

The standby. That you then find won't turn on, so you can't delete the data. But you worry that a dodgy recycling company might find an easy fix, so The Dead Device Drawer is easier.

OpenAI to charge $200 per month for ChatGPT Pro

tfewster
Facepalm

Re: It's $200 to talk to the smart one, or you get the dummy.

"more accurate" != "accurate"

Win a slice of XP cheese if you tell us where Microsoft should put Copilot next

tfewster
Thumb Up

Re: The empire has no clothes

Accrington Stanley? Who are they?

Techie left 'For support, contact me' sign on a server. Twenty years later, someone did

tfewster
Facepalm

Unlike me - One time I was trying to debug some obscure code and thought "What idiot wrote this?".

Then I found my name in the header...

Thousands of AI agents later, who even remembers what they do?

tfewster
Facepalm

Hotness or Notness?

Letting chatbots run robots ends as badly as you'd expect

tfewster
Facepalm

Re: One word:

Is it even that difficult? Would a robot even question orders to deliver and activate a "package" or "device" if you didn't use the words "bomb" or "gun"?

O2's AI granny knits tall tales to waste scam callers' time

tfewster
Thumb Up

It would be nice if every unused number could be diverted to this service.

Of course, you would need to scale the bot to have multiple voices & personas and respond to different scam types.

Want advice from UK government website about tax 'n' stuff? Talk to the chatbot

tfewster

Re: Can't be any worse...

In my experience, once you get through to someone then they're very good - helpful and thorough.

But the long phone queues and slow responses to emails or letters are still painful

Sysadmin shock as Windows Server 2025 installs itself after update labeling error

tfewster
Facepalm

Re: Wait...

Wait, what? A patch supposedly for Windows 11 installed on Windows Server 2022? And was pushed out by patch management? Regardless of the patch content, doesn't that jump all guardrails?

Relocation is a complete success – right up until the last minute

tfewster
Facepalm

Re: EPO next to the door button: That's where it needs to be and shouldn't really be covered - Imagine if the operators hands are burnt and they need to hit the button with an elbow while evacuating but can't open the cover...

However, I recall hearing a tale that, after an incident where a tape-ape had hit the EPO instead of the door opener, senior management convened to find out exactly what had happened. The poor soul was ordered to retrace his steps exactly.

"Well, I was leaving the room carrying a stack of tapes that obstructed my view, like this. I reached out like this..."

And the computer room went dark again.

Combustion engines grind Linus Torvalds' gears

tfewster
IT Angle

Dumb interviewers

Torvalds is a clever guy, but I'm not interested in his opinions on subjects he's not expert on. And I wish he and other "pundits" wouldn't go along with interviewers trivial questions.

Linux, yes. Dealing with idiots, yes. Open source, probably. Gen AI, possibly. Cars, no.

Cast a hex on ChatGPT to trick the AI into writing exploit code

tfewster
Facepalm

If you hop over the guardrails surrounding a cesspool, you're literally in deep shit.

The problem is not the guardrails being easily circumvented They're there to stop workers falling in accidentally, not to stop crazy people. It's the cesspool being accessible by crazies/idiots.

I thought we learned these lessons in the early days of the Internet?

tfewster
Facepalm

Re: Squirrel?

If an LLM has to translate the input from hex, Klingon, Russian or even English in to commands, post translation should be the point of applying guardrails.

However, I'm not convinced the "AI" developed the exploit itself - It was told to research it, so probably found the existing POC code and converted it to Python.

I made this network so resilient nothing could possibly go wro...

tfewster

Re: Making things worse

Spoiler alert: Read "YY" as "two Y's"

WordPress forces user conf organizers to share social media credentials, arousing suspicions

tfewster
Facepalm

"When posting from an official WordCamp account..."

Not your personal ones

California cops cuff suspect in deadly drone-assisted drug deal

tfewster
Pint

Those are some odd laws...

Distribution of drugs resulting in death and possession with intent to distribute would seem sufficient even if you don't have more specific evidence of dealing drugs, I guess you don't have to prove ownership or payment until the sentencing/confiscation of proceeds of crime stage.

But possession of a gun and drone seem like strangely specific laws, even if they were used to facilitate the crime. Is it because those items need to be registered, whereas the shoes the perp wore to facilitate the crime are not regulated items? How about if they were registered? How about phones/cars/houses, all of which should be "registered" in some way?

A virtual pint for anyone who can enlighten me ---->

Post Office CTO had 'nagging doubts' about Horizon system despite reliability assurances

tfewster
Facepalm

Re: ...and it was open to abuse.

> Terminal retransmitted the transaction. Head office logged it as a second sale.

Which is why a transaction should have unique reference, so if it's retransmitted then Head Office detect the duplicate.

Duplicate transactions are a possibility that has been considered and solved in many paper, computer and network processes. Surely Horizon couldn't have that basic a flaw?

Also, that doesn't explain the "remote access" issue, unless Fujitsu were changing the unique reference at both ends to allow the transaction to be processed.

'Newport would look like Dubai' if guy could dumpster dive for lost Bitcoin drive

tfewster

Re: Crypto Bro Loses All His Crypto Cash

I'm surprised the council doesn't just contract Howell's company to do the excavation work, with appropriate charges and penalty clauses.

On the other hand, why should they bother getting involved in a speculative treasure hunt?

Windows 11 24H2 hoards 8.63 GB of junk you can't delete

tfewster
Windows

Re: Locked within the Crystal Ball

https://www.theregister.com/Author/Email/corrections?message=re:%20https%3A%2F%2Fwww.theregister.com/2024/10/11/windows_update_cleanup/

Apparently "24H2" began rolling out to all users on October 1, 2024.

Allowing it to install within 10 days is ...brave.

BOFH: Boss's quest for AI-generated program ends where it should've begun

tfewster

Re: Color me disappointed. . .

Why push them out of a window when an AI will make them crazy enough to jump?

UK Regulatory Innovation Office vows to slash red tape – but we've heard it all before

tfewster
Facepalm

Re: Tax land, not labor

Interesting, but as flawed as any other measure such as the "window tax". Approximately 70% of the UK's land is farms and parks. Look forward to prices for food and recreational amenities rising.

My land is half house, half garden. Could I sell the garden to build another house? Or better, high-rise flats so all the flat owners share the land tax between them? Of course I can, without those pesky planning permission and safety regulations getting in the way!

Geico tells El Reg, no, it's not canceling all Cybertruck insurance

tfewster

Re: It's "contact"

To me, "contact" means they got a response, i.e. a successful communication attempt.

"Reach out" implies minimal effort, from "wrote to last known address" to "It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard."

After we fix that, how about we also accidentally break something important?

tfewster
Facepalm

> finding you have to sort out some other mess before you can even start the job

I find that a reboot before I start MY work exposes most booby-traps. I might have to fix a non-bootable server, but provably it wasn't me that broke it ;-)

Meta gives Llama 3 vision, now if only it had a brain

tfewster
Terminator

I wonder how good it is at Captchas?

The post is required, and must contain letters.

Cloudflare beats patent troll so badly it basically gives up

tfewster

It depends on your definition

Patent Troll:

El Reg: a term for an individual or organization that exists solely to makes patent infringement claims in the hope of winning a settlement from defendants concerned about costly patent litigation.

Cloudflare: [Sable IP] doesn’t make, develop, innovate, or sell anything. Sable IP is merely a shell entity formed to monetize (make money from) an ancient patent portfolio acquired by Sable Networks from Caspian Networks in 2006."

Many companies want to monetize their IP. If it's not of use in their technical strategy, they also have the right to sell it, and the new owner can monetize it as they wish.

The red line is where the IP owner is suppressing progress with unreasonable claims or licensing fees. And only a court can rule on that, as the USPTO don't exactly help.

Kamala Harris campaign motorcade halted by confused robotaxis

tfewster

I've never encountered a Presidential motorcade, but isn't it just a sub-case of flashing emergency vehicle lights? I.e. get out of the way until you know what's going on.

US Army orders next-gen robot mule to haul a literal ton of gear

tfewster
Thumb Up

Re: How is this better than a truck ?

E.g. a Toyota pickup truck - Cheap, and stealthy (They're ubiquitous, so the enemy can't tell at a glance if they're ours, theirs or just a civilian).

Page: