I have been waiting for a while ...
so it looks as if I shall be upgrading CentOS 6 machines some time next Summer.
2646 publicly visible posts • joined 29 May 2007
at the moment if my washing machine breaks & the manufacturer won't repair then I can call in an independent outfit to replace the broken bits, made by some third party supplier.
If IoT software breaks (or a vulnerability becomes known) then I can only go to the manufacturer. Unfortunately they loose interest very quickly and announce 'end of product lifetime'. Once they do that then the software must become open source. There is a potential business in patching such software.
Unfortunately the general public will be reluctant to pay even £2/year as software support contract for the washing machine - they will want to know why & then bitch if they get hit.
It'll be interesting t see how this goes.
NoScript only works if the naughty script is served from a domain you don't care about. It might be trickier if the naughty script is hosted on a domain you actually need to whitelist because else the site you're visiting doesn't work (online stores come to mind).
If it is from the online store, or similar, then the domain owner is a big target that could be prosecuted under the computer misuse act. A few costly & high profile actions could stop a lot, but not all, of this.
in many respects when it comes to software because, over time, the bugs will have been found and squashed. Systemd brings in a lot of new code which will, naturally, have lots of bugs that will take time to find & remove. This is why we get problems like this DHCP one.
Much as I like the venerable init: it did need replacing. Systemd is one way to go, more flexible, etc, etc. Something event driven is a good approach.
One of the main problems with systemd is that it has become too big, slurped up lots of functionality which has removed choice, increased fragility. They should have concentrated on adding ways of talking to existing daemons, eg dhcpd, through an API/something. This would have reused old code (good) and allowed other implementations to use the API - this letting people choose what they wanted to run.
But no: Poettering seems to want to build a Cathedral rather than a Bazzar.
He appears to want to make it his way or no way. This is bad, one reason that *nix is good is because different solutions to a problem have been able to be chosen, one removed and another slotted in. This encourages competition and the 'best of breed' comes out on top. Poettering is endangering that process.
Also: he refusal to accept patches to let it work on non-Linux Unix is just plain nasty.
has long been a Microsoft philosophy. It served it well in the early days as it meant that it got a product to market before the competition. The bugs could be fixed in a later release. Competitors who, later, shipped something with fewer bugs didn't get the sales as the Microsoft offering was seen as 'the standard'.
Others have also done this sort of thing. In some ways: better something with holes than nothing at all.
But today Microsoft should not need to do this, it is not scrabbling for market share in the same way. They have the time and resources to do proper QA regression testing - but don't seem to want to.
I tried looking in about:config and searched for TLS, but nothing seems relevant.
A 10 minute timeout seems more than generous, the real value is in saving lots of TLS packet round trips when many connections are made in rendering one page (lots of images, etc). One extra round trip every few minutes will likely not be noticed.
The need for this will be reduced with HTTP2 since one HTTP2 TCP connection can be used to download several files at the same time by in different streams (AKA multiplex).
Most of the comments here look at the problems of getting existing programs to work on a new architecture, be that via recompile or emulation or something.
An Apple designed CPU could bring a whole range of new instructions, maybe doing some of the things that are today offloaded to GPUs. This might help with more AI (whatever that means) and other needs where new silicon could give great advantage. Apple will not share its designs and will probably patent what its new silicon does to stop others following suite.
I believe in 10 years, architecture (ie. x86, PowerPC, ARM) will be more of a preffered brand
Having spent the last 35 years working with Unix/Linux - that has always been my view. A new architecture is just a 'make' away for decently written programs.
20+ years ago the common use of different architectures was much greater than today.
then someone would probably implement an open source client. But Microsoft will not do this because they do not want the competition. Someone might also implement an open source server - which would be even worse as far as they are concerned. Look at their other stuff - how they make compatibility hard.
at $156/month. This is like the current trend with cars - where you lease (with a very small mileage allowance) and end up with nothing after 3 years - having almost paid the cost of buying it.
Every business these days seems to be trying to tie customers in to a monthly payment. I assume that it is for the benefit of the business not the benefit of the customer - although marketing will try to convince you of that.
I suppose that they don't sell to engineers or devs because they are sufficiently mathematically able to work out that it will be a bum deal.
This is one area where I wish the government will give GCHQ some strong powers to compel vendors to do as it says: make these things secure (but without any nice five eyes back-doors). The article contains phrases like ''GCHQ hopes'', which we all know means that vendors will do as little as possible, preferably nothing.
The onus needs to be on UK manufacturers AND those who import foreign (== mainly Chinese) kit into this country.
There also needs to be an onus to support these things for their *use* lifetime, not a lifetime defined as until-the-next-model-is-released. The entire code-base needs to be held in escrow and released Open Source once manufacturer updates cease to come. For some thing I can see a 'use lifetime' of 30 years or more (eg IoT light switches).
This needs the backing of strong laws (that are actively enforced == big fines) otherwise it just will not happen. The cost of not doing this will be millions of tiny breaches.
in that their Windows is installed on many different sorts of hardware. This makes it hard to test all the combinations - which means a lot of work. But if they have sold, we are told, some 700 million of them then they must have the resources to properly test.
Contrast this to Linux: which runs on a wider selection of hardware than does MS Windows - you rarely hear of such breakage after an update. Even with manufacturers that only support MS Windows, once a device work it tends to stay working.
So: which is the 'hobbyist' operating system I wonder ?
For companies in more than one market sector. Such that when it exceeds that size the new sectors must be sold off.
I agree that a mega Amazon might be able to negotiate/sell-at a lower price than anyone else, but where is the benefit to society if you can only buy xxx from one source ? OK: this is more complicated than I suggest, but stopping companies from getting too big must be good.
I would much rather live in a pond with many minnows than one inhabited by a few sharks.
I have. I bought it in 2012 as it was, at that time, the only sensibly priced router that would give me IPv6. I have not had any problems with it, a few small bugs but nothing really bad. It is highly configurable but not for a novice user -- eg you need to have an idea of how Linux IpTables works.
However: usual story, I can't get any updates, they were available for a couple of years and then ... zilch, nada. As with most hardware vendors they rapidly lose interest, expect you to buy a new box.
A new one would cost me some £40-£70ish, but then you add in:
* time to work out what new model I need
* time to configure the thing (IPv4 & IPv6 filtering, forwarding, etc)
I have another firewall on my main (Linux) desktop - so potential damage would largely be stealing bandwidth.
The only way to fix this is to make the UK reseller liable for any problems that might be caused by bad OEM security. The result would be that UK resellers would only deal with OEMs that provided products with good security. So the likes of Xiongmai would either go out of business or smarten up their act.
Currently UK resellers can just shrug their shoulders to these problems.
Yes: this would result in a small price hike, but we all understand that quality costs.
I guess you could argue that nobody has any business running a ToR client on a PC in a supermarket, so blocking 9001/tcp outbound would have stopped that for the 2 minutes
We are told that the data was uploaded via ToR but do not know if that is how the data was taken off the Morrison's servers. It could have been walked out of the building on a memory stick and uploaded via ToR at home or in a cyber-cafe.
Since he was an auditor he could have asked for access to the backup system/media/... to check that it was being done properly or that it could be restored or ... or ... One of many reasons to get his hands on a copy - then swipe a copy in one of many innocuous ways.
"Who audits the Auditors ?"
Andrew Skelton was not a director, neither was he part of a team doing something 'furthering corporate aims' that resulted in the data loss or, as is often the case, not doing things that they clearly should have done to prevent the data loss. In order to operate a company does need to trust some individuals, it is not possible to lock everything down so that someone internal trying to nick data can be prevented 100% of the time.
Andrew Skelton should have the book thrown at him, he pay the fine, if it means that he looses his house then so be it - it might act as a deterrent for others.
This should, however, not be used as an excuse to allow all corporations off the hook by blaming everything on rogue employees.
Let's hope that they fix it.
Gyros seem to be a perennial problem, I suppose that since they have to move (spin) all the time they suffer wear & bearings break.
One thing that I just learned is that the gyros are used to detect Hubble's orientation, and that reaction wheels are used to move/rotate it.
If we assume that Bloomberg has got it wrong and also assume that Bloomberg would not want to dent its reputation by asserting bollocks then a lot of effort must have gone into pulling the wool over Bloomberg's eyes. Knitting that wool is probably beyond the abilities of pranksters and would need to be state actors.
What would a country gain by hurting Bloomberg ? Maybe one that wants to make it harder for us to distinguish between fact and fiction, one that generates fake news that it does not like reputable journalism from showing that the news is fake. If we do not know what is true or false then we become confused and less able to make good decisions.
Another possibility is that the five eyes were in on this and do not want it exposed. This I doubt.
those who have downloaded it voluntarily. These are, presumably, those who know a few things about computers and who will have maintained some form of backup.
Will this still happen to the hapless home users who will have the update happen without them asking for it ? These are the ones who have probably forgotten to do a recent backup, or who never realised that it was a good idea to do so.
One wonders if this is part of the MS push for users to keep a copy of their files in the MS cloud - with all that that implies?
Will be the typical reaction of most Internet users. If it takes more than 10 seconds to implement a change then they won't bother.
Yes: some of them might have heard stories about abuse of data by the facebook & friends, but they have not seen the sky fall & don't understand why these apps that let them chat to friends, the purveyors of pictures of kittens are in anyway malign. Then they forgot about the stories.
Much as I applaud Solid they are unlikely to get more than 1% of users (most of whom will be the sort of techno nerd that visits el-Reg) - so the data abuse will continue. Solid is going to need to come up with exciting must-have features to attract users ... features that the big boys will copy in a trice. Most people do not consider security & privacy. They are not must-have features that Sharon from Essex thinks about.
One thing that 'cashless' does is to shift administrative burden from the shop to me. I have a whole extra lot of card transactions who's slips I need to keep and reconcile when the statement comes in.
I dare say that many millenials will want to know why reconcile ... I regard it foolish to NOT do so.
So ~68 cents each, even assuming that the lawyers don’t take the lion’s share (unlikely)?
How much did many have to pay their local ''IT man'' to come and look at the printer, only to realise that it could not be fixed ? The minimum should be that cost, then look at adding in other time spent farting around because of HP's shenanigans -- I think that £200 each is a good starting point.
Unless HP are made to pay something like this they will just do it again.
the manufacturer should not be able to remove that feature afterwards
You don't need a wider rule ... most devices have a (special purpose) computer inside. The manufacturer changing what it does, without the explicit agreement of the owner, surely falls under the computer misuse act.
Almost a year ago Red Hat announced Arm server support for their Linux. So, all the hard work is long done. I notice that CentOS (aka Red Hat) was working on this in February, so they have probably knocked the bugs out by now and this is ready for real customers.
because it is obviously better to give the money to banks - can't have their funds drying up and not being able to pay the usual mega-bonus.
This is because bankers are obviously much more valuable to the country than physicists because ..., err, umm, gosh - I am certain that there are lots of reasons ... I seem to have temporarily forgotten any of them!
Rather than suing BA for about 1/3 of last year's profit, something that will be regarded as a business cost and forgotten in a few years -- the individuals responsible for failing to ensure secure systems (eg BA board & top level Web managers) should be fined; something like 80% of their assets (ie house) and their pension pot. This will be noticed by directors, etc, in other companies who will then ensure that the same thing cannot happen to them.
I assume that customers who suffered losses will have those repaid by BA; something for the inconvenience would also be good.
that Barbra could force Wikipedia to remove this page: https://en.wikipedia.org/wiki/Streisand_effect ?
Yes: some of it is 'meat market, wham bang thank you marm' stuff that disrespects both sexes**; it does little to help kids build good relationships as adults. However I would rather that they looked at porn than some of the blood & guts stuff where people are killed with little thought. What does that do to build a respect for others' lives ? Then don't get me started on the religious stuff that encourages people to believe in whatever nonsense that they see just because it sounds good - without any checking for reality.
Is this really the right target ?
** BTW: I gather that female porn stars are paid more than the men that the f**k, should there not be a move to pay them both the same ?
Hopefully, like in Windows, you can tweak Chrome's settings to disable this behavior.
Very few people will know how to (or care/bother) to do so; these will be the technically literate. The others will believe what they see and their general level of understanding of how the Internet works drop even more.
Simplification is one thing, but not this.
by HMRC to companies who have not been able to make their accounting systems compliant by March 2019 to the rules that will have been modified (again) in February 2019.
There are many who run accounting systems that have been developed in-house to deliver what the organisation needs.
This is on top of MTD (Making Tax Difficult) that everyone, including your house-to-house window cleaner) is supposed to do from next year.
Muppets.
Hopefully MS won't fluff it this time so it will be. In the end it's about the software.
They already have fluffed it ... it runs Windows 10 S -- the version that restricts you to only running stuff from the MS App store.
I like the reported battery life, but not at that price. Anyway: I would wait until someone reports that Linux Mint runs on it.
If you wanted to see globally who was visiting where it would be easier to compromise the 8 DOH end points than to get into the thousands of ISPs all around the world. NSA, GCHQ, ... must be rubbing their hands in anticipation.
However if you live under a repressive regime having the NSA/... spying on you might be preferable to your own government. But expect $REPRESSIVE_REGIME to force their Mozilla users to use their own DOH end points.
Who do you trust least ?
What is the point of them ?
OK: I know that they are supposed to give the visitor extra confidence that they are going to somewhere trustworthy & all that, but how many even have a clue what the green padlock means ?
That is the problem: most neither know nor care. So why pay for something that few notice ?