* Posts by alain williams

2820 publicly visible posts • joined 29 May 2007

NetBSD, OpenBSD improve kernel security, randomly

alain williams Silver badge

it is a good start ...

yes: more to do, but follows in the Open Source philosophy: release early. They can get a next step done in the next months, then release that. Eventually they will have something that will please even you!

MEPs vote to update 'cookie law' despite ad industry pressure

alain williams Silver badge

Session cookies

The big problem with the current legislation is that it does not distinguish between session and other cookies.

Session cookies are used to tie together the pages viewed on one visit and are auto-destroyed by the browser some 20-30 minutes after the visitor has left the site - these are reasonably benign.

Other cookies have a long life, potentially years.

Yes, British F-35 engines must be sent to Turkey for overhaul

alain williams Silver badge

Total cost ...

Multiply $123m unit cost by 138 quantity and I get $17 billion (£13 billion). How many hospitals is that ?

Samsung to let proper Linux distros run on Galaxy smartmobes

alain williams Silver badge

Does that mean that I can get a root shell

on the 'phone and remove all the rubbish & spy-ware that I do not want? Or will I still need to replace the Samsung supplied OS to do that ?

Man prosecuted for posting a picture of his hobby on Facebook

alain williams Silver badge

Ian Rankin is dangerous!

Beware discussing an Inspector Rebus novel on a public forum. If you do so then you risk McCopper deciding that you are researching how to carry out some heinous crime.

Supreme Court to rule on whether US has right to data stored overseas

alain williams Silver badge

Interesting tussle coming up ...

between the supreme court of the USA and the Irish courts.

IMHO it is all in Ireland, so it is up to their courts.

Ernst & Young slapped with £1.8 MEEEELLION fine for crap accounting

alain williams Silver badge

Rather than a fine ..

should not the FRC have insisted that all of E&Y's work was checked by another auditor for a couple of years ?

Customers cheesed off after card details nicked in Pizza Hut data breach

alain williams Silver badge

Re: Surely they don't store payment card details. So wtf?

I presume they don't store payment card details.

See their T&Cs section 3.2: "We will not charge your credit or debit card until we despatch your order." which means that they do keep your card details ... I would not be surprised if, once they have them, they keep them for a lot longer.

Microsoft faces Dutch crunch over Windows 10 private data slurp

alain williams Silver badge

Re: Irony

Why can't Micro-shaft JUST COME CLEAN on what they're collecting on everyone?

That could be fixed by the Dutch legislators insisting that Microsoft provide a tool that will show everything that has been slurped in the last couple of months -- complete with an explanation of what the tool shows.

After all: it is (supposedly) your Personal Computer and thus you should be able to find out anything that relates to you or the operation of the PC.

Fear the SAP-slap? Users can anonymously submit questions about licensing naughtiness

alain williams Silver badge

Who owns the data ?

SAP or the company/customer ?

So if a company exports all the data, say every night at 4am, into a MySQL database then SAP can surely not demand $$ for queries against the MySQL database ?

Russian telco backs up North Korea's sole Internet link

alain williams Silver badge

Re: Comments?

Will JC or BOJO be the next PM ?

Forget the 'simulated universe', say boffins, no simulator could hit the required scale

alain williams Silver badge

Re: Simluator

Coat has Occam's razor in pocket.

Don't cut your fingers on it when you reach for your bus pass.

UK lotto players quids in: Website knocked offline by DDoS attack

alain williams Silver badge

'Gamble' not 'play'

Please do not use the Camelot marketing department's word 'play' - which implies that the lottery is a bit of fun, not serious. For many, reasonably well off, el-reg readers that might be true, but I have seen people at my local newsagent gambling money that it was plain that they could not afford -- it is harmful.

People are taken in by the con that they will get rich - the adverts try to convince people that they will be more lucky than their neighbour - clearly that cannot be true.

Would you make an investment that returned 25% of your original stake ? That is what you are likely to get when gambling on the lottery.

This DDOS has saved many people money that they could not afford to loose.

Ex-sperm-inate! Sam the sex-droid 'heavily soiled' in randy nerd rampage

alain williams Silver badge

Re: Gimmi!

compared to what some long term XX wetware require.

Married for 7 years, been paying alimony for 22 years; spent a fortune in the courts just to see the kids - one of who now lives with me, another I'm paying Uni fees (mature student).

At $3,000 it would have been cheaper to buy several a year - and less emotionally stressful.

SQL Server 2017: What's new, what's missing on Linux, and what's next?

alain williams Silver badge

''Various flavours of Linux''

and then mention a few distros; no mention of hardware platform. Red Hat, for instance, runs on x86, power PC, IBM mainframe, ARM -- is it available on all of these or just Intel compatible ?

HP denies rumours Elite x3 is for the axe, admits coveting neighbour's OS

alain williams Silver badge

Multi-OS

LineageOS would be nice.

Brit broke anti-terror law by refusing to cough up passwords to cops

alain williams Silver badge

Re: Possible Solution?

Your destination has been changed to this holding cell: you may 'phone your colleague now.

alain williams Silver badge

What a good thing that he was not coming into Catalonia

where they might have wanted to search his laptop to look for illegal opinions such as wanting to separate from Spain. At least the UK law is only used to stop people who might kill people; they will never use it to search people who have political opinions that the government of the day does not like.

</sarcasm>

alain williams Silver badge

Re: Defeating Draconian laws

I have a second Apple account

Are you saying that Apple are not subject to the Patriot act ?

Insteon and Wink home hubs appear to have a problem with encryption

alain williams Silver badge

What do we care ?

Putting in proper security will just cost us to no benefit - ie we will not make more money.

It will cost us developer time & make our products more complicated so that we will have to deal with extra support calls from the Muppets who buy our stuff - someone has to pay for those support calls y'know!

If some of these do get cracked, they probably won't blame us, if they do we will just send out our press release blaming ''the bad guys'' - we have is already written, it just needs the date putting on it. After a fortnight the broohaha will have died down and our sales will just continue.

If the law were change to make us liable for customer losses we might take notice, we have our lobbyists ready just in case legislators think about this.

Love & kisses: Insteon PR department.

iPhone 8: Apple has CPU cycles to burn

alain williams Silver badge

Please explain to me ...

why I need all of this to talk on the phone and send/receive text messages ?

Sysadmin tells user CSI-style password guessing never w– wait WTF?! It's 'PASSWORD1'!

alain williams Silver badge

Re: "They looked for the password on the CD . . ."

Some 8 years ago I opened a bank account with Santander, they did not understand security:

* they sent the username for on-line banking in a clear text email; the password was in another email sent 1/2 second later.

* we went in, took all the documents needed to open a bank account (passport, etc); they took a copy; a month later ''we have lost them, please scan and send the images by email". (I refused to do so)

* I complained that important, security related documents were lost. They assured me that they were quite safe: but were unable to explain how they knew so since they did not know where they were.

And so it went on. The account has been closed for many years, final statement showing a NIL balance - but every 6 months I get a letter telling me that there are a couple of quid there (I have checked - there is not).

Muppets

IT plonker stuffed 'destructive' logic bomb into US Army servers in contract revenge attack

alain williams Silver badge

Where to hide a logic bomb?

Unless you are of the mindset of a suicide bomber the most important thing is plausible deniability. Make it look like a logic error -- a bug.

Ah, good ol' Windows update cycles... Wait, before anything else, check your hardware

alain williams Silver badge

Re: I'm confused

I don't understand how the security of a device is dependent upon its bus width.

More room for ASLR (Address Space Layout Randomisation), which makes buffer overflow attacks harder to exploit. Windows 10 uses so much RAM that there is not much left over for ASLR if all that you have are 32 bits of virtual address space.

My guess anyway.

Researchers claim ISPs are 'complicit' in latest FinSpy snooping rounds

alain williams Silver badge

Re: Certificates

But were the packages not signed with the public key of the software vendor/distributor ? Or are we dealing with a bunch like slack ?

OK: I don't know how this is done in the windows world, and if you have never installed anything from the vendor you will not have the key (so getting it could be spoofed) ... but Skype is from Microsoft and so the Windows machine will have their signing key ... so if the installer does not complain we need to ask how the spooks got their malware signed to make it look legitimate.

You lost your ballpoint pen, Slack? Why's your Linux version unsigned?

alain williams Silver badge

It isn't that hard to do

Even I do it for the tiny repo that I have created - mainly for my own convenience.

Words are always cheaper than actions; so do they have a blame-someone-else script already written if/when it is hacked again? I notice that it was hacked in February 2015.

UK Prime Minister calls on internet big beasts to 'auto-takedown' terror pages within 2 HOURS

alain williams Silver badge

Please start with all T May utterances

because, by gum, she sure terrifies me. If she wasn't a woman she would be wearing a Joe Stalin moustache by now. She is not called the Pry Minister for nothing.

More data lost or stolen in first half of 2017 than the whole of last year

alain williams Silver badge

What do you mean by ''lost'' ?

I suspect that you mean ''laptop left on train'', or similar, ie misplaced - and possibly in the wrong hands.

This is very different from ''data accidentally deleted''. There is sometimes a requirement for data to be kept for certain periods. I observe that embarrassing data, especially when asked for by a subject access request, has a propensity to become ''lost - accidentally deleted''.

These two should be counted separately.

Could we please start calling the ''left on train'' incidents ''misplaced'', not ''lost''.

Black screen of death after Win10 update? Microsoft blames HP

alain williams Silver badge

Rather than blaming each other ...

Microsoft and HP should get together and produce a fix. Customers don't care who broke it.

What's that, Equifax? Most people expect to be notified of a breach within hours?

alain williams Silver badge

Words are cheaper than sysadmin time

'nuff said.

123-Reg customers outraged at automatic .UK domain registration

alain williams Silver badge

Unsolicited Goods Act 1971

This makes unsolicited goods something that the supplier cannot demand payment for. This is 123reg trying to indulge in inertia selling ... so if they renew the domain without the customer saying they want it: then they are acting illegally.

Not that acting illegally seems to bother many businesses these days.

If they grab the money from your bank account: just get the bank to reverse the charge and let 123reg whistle for their money.

How alien civilizations deal with climate is a measure of how smart they are. Just sayin'...

alain williams Silver badge

What is meant by 'advanced civilisation'

Most people think that this means that the boffins has worked out how to do all manner of technical wonders.

Just as important is: have the politicians grown up enough to not destroy the planet. I used to think that this meant not throwing nukes around, but increasingly realise that it means controlling expansion and population growth to what the ecosystem can sustain.

Of the two: the harder is the politics. Politicians are just big children who have the gift of the gab and persuade the rest of us to vote for them (or self interested psychopaths who become dictators). They have little interest in the long term of anything (including the ecosystem) as long as they get what they want now.

Close Encounters of the Kuiper Belt kind: New Horizons to come within just 3,500km of MU69

alain williams Silver badge

It is a long way away from the sun

how much light is there there for taking pictures ?

80% of IT projects in public sector delayed due to IR35 – report

alain williams Silver badge

The duty to pay taxes ...

is something that middle class people must do. It is not a burden that is to be felt by the very rich or by large corporations.

If large corporations were made to pay taxes just like the rest of us: where would all those nice consultant type jobs come from once MPs and top civil servants retire ?

Chinese smartphone cable-maker chucks sueball at Apple

alain williams Silver badge

I can see the value in certification

to assure users that the the cable/... will not damage their expensive iBling.

I cannot see why Apple would want a chip in the cable ... to me this smells like printer vendors putting chips in printer ink cartridges - as a means of trying to stop perfectly good independent suppliers from undercutting their overpriced stuff.

US government: We can jail you indefinitely for not decrypting your data

alain williams Silver badge

There is an easy way out ...

He needs to get a diagnosis for Alzheimer's disease -- hard for the prosecutors to then show that he can remember any passwords. Once he is released he just needs a quick visit to Ernest Saunders' physician and can resume his life.

Mazda and Toyota join forces on Linux-based connected car platform

alain williams Silver badge

If I don't want any of it ...

will it still play the radio and CDs without needing to pollute my 'phone with some privacy destroying app ?

Boffin rediscovers 1960s attempt to write fiction with computers

alain williams Silver badge

Computers that write fiction ?

Happens all the time -- look at anything that generates management reports.

Intel ME controller chip has secret kill switch

alain williams Silver badge

Re: I guess I know what architectures to avoid...

What would be far more useful is a list of architectures that I can trust.

VW engineer sent to the clink for three years for emissions-busting code

alain williams Silver badge

Good start ... what about

the managers who knew about it and probably asked him to write the code. This needs to go up as high as possible in the management structure. Most of them are probably happy that someone else has taken the blame.

The only way of making change is my making it so painful for the read decision makers that they, and their successors, will never do this again.

Forget trigonometry, 'cos Babylonians did it better 3,700 years ago – by counting in base 60!

alain williams Silver badge

Re: So much for digital

I always thought that they used 60 because 6*60 gives you about the number of days in a year and that a circle has 360 degrees because every day you move about one degree around the zodiac.

Identity fraud in the UK at 'epidemic' levels as cases rise 5% – report

alain williams Silver badge

"It won't hurt me"

is the comment that most of my friends make when I tell them to be careful, use different passwords, ...

They just think me strange because I am careful about security and privacy.

Ubuntu sends trash to its desktop's desktop

alain williams Silver badge

Trash can icon ?

Don't use it ... the rm command works nicely for me.

Nosey ex-NHS staffer slapped with fine for illegally peeking at medical records

alain williams Silver badge

How many more ...

do this but are not caught ?

Revealed: The naughty tricks used by web ads to bypass blockers

alain williams Silver badge

Computer misuse act ?

They are deliberately acting against what they know that the PC owner wants and getting his PC to do things that they know that s/he does not want to do. A prosecution would be nice. Company is in the USA so go after some of their UK based clients.

PayPal splashes cash on biz that persuades folks to splash cash online

alain williams Silver badge

Is PayPal giving purchase history ?

PayPal is in a good position to know what people have bought. So does 'partnering' mean 'we tell you about what they have bought so that you can send them more spam' ?

If so then this is one less reason to go anywhere near PayPal.

Autonomous driving in a city? We're '95% of the way there'

alain williams Silver badge

Caesium Microsoft-Azure-based shuttle management system

Ohh, err .... building anything that people's lives depend on top of a Microsoft system is ... foolish to say the least. Look at the recent Wannacrypt debacle, or lots of unexpected shutdowns, ...

No way!

Kid found a way to travel for free in Budapest. He filed a bug report. And was promptly arrested

alain williams Silver badge

Gary McKinnon

This is much the same thing. Guy discovers gaping hole in computers, is held to blame and arrested - this is an attempt by the site owners (in this case USA military) from having to admit that their own staff are incompetent. It is called saving face that just ends up showing the site owner to be arrogant & stupid.

Moneysupermarket fined £80,000 for spamming seven million customers

alain williams Silver badge

Re: £80,000 for sending 7.1 million

Fine £80,000 - new business as a result £xxx ??? The fine should be in excess of what they gained otherwise fines will just be seen as an extra cost.

Also: 1/2 the fine should be paid by board members, personally - out of income after tax. Unless it hurts someone in authority: behaviour will not change.

School of card knocks: Russophone criminals offered online courses in credit card fraud

alain williams Silver badge

I hope that PC Plod ...

will pay up and send a delegate on this course. Probably nothing new for him, but there might be a novel trick. Next Plod should have a publicity campaign on how to avoid being duped by the new crims who learn their trade on this course.