* Posts by alain williams

2644 publicly visible posts • joined 29 May 2007

PHYSICS APPLECART UPSET as dark energy disappears, Universe slams on brakes

alain williams Silver badge

100 watt bulbs

The findings are analogous to sampling a selection of 100-watt light bulbs at the hardware store and discovering that they vary in brightness

I always knew that these low energy bulbs were not what they were cracked up to be. Don't last as long as claimed either.

David Cameron's Passport number emailed to footy-head

alain williams Silver badge

Re: Is it such a big deal?

So if they want a copy of your passport so that you can see what information they hold about you, does that not suggest that they did not do enough to assert who you were when you signed up on their web site in the first place ?

Surely: give the exact same information (be that true or false) should be enough.

alain williams Silver badge

The wrong address is not the real issue

Sending the list by (presumably unencrypted) email is a bigger problem. Sending email is like putting a post card into a letter box, it can be read by anyone who handles it. So: this email has potentially been read by all sorts of people.

This is the REAL cluelessness - it seems that el-reg's journalists have also forgotten this problem with email.

OK: in this case the NSA has already got this information, but who knows who else has tapped into the Internet routers that the email went through ?

VMware channel confirms price hikes from next month

alain williams Silver badge

They need to pay their lawyers

who are defending them in court over their GPL infringement: https://sfconservancy.org/linux-compliance/vmware-lawsuit-faq.html

They will need even more money after they have lost to rewrite their code so that it does not rely on them just grabbing someone else's code and ignoring the license.

They would be very upset if others did that and used their product without paying them ... thinking about it - since it is based on GPL code, it must be licensed under the GPL, so you can do that - just take a copy and use it where you want to.

Hello? Police? Yes, I'm a car and my idiot driver's crashed me

alain williams Silver badge

Will it be easy to disable ?

Will it be legal to rip it out of your car ?

Respect mah privacy! EU delegation begs US to play nice with data

alain williams Silver badge

Re: Lip service..

That is all the MEP delegates will get from the US...

Not true - Monica Lewinsky no longer works for the gov't of the USA.

alain williams Silver badge

Even if the USA gives assurances

the lying toads will not lose any sleep by living up to the promise. The NSA will just continue to slurp up whatever it wants citing Four Horsemen of the Infocalypse: terrorists, drug dealers, pedophiles, and organized crime.

OpenSSL preps fix for mystery high severity hole

alain williams Silver badge

Re: Software written in C contains bugs, that will include Java then...

The definition of debugged software is: software in which the bugs have yet to be found.

Ie all non trivial code contains defects.

VMware wants amicable end to 'meritless' Linux-lifting lawsuit

alain williams Silver badge

Re: A nice donation?

There is a relief for breach of GPL that is written into the GPL: release the offending code. VMware could become GPL compliant by releasing its code under the GPL.

Quite simple really.

Crap employers banned from enforcing backdoor crim records checks

alain williams Silver badge

Could I do a crim check on a prospective employer ?

That would be very interesting - especially in banking circles!

‪Obama criticises China's mandatory backdoor tech import rules

alain williams Silver badge

Re: ha

Do the backdoors in iPhones have rounded corners ?

East Timor was officially removed from the internet yesterday

alain williams Silver badge

Getting rid of country codes ...

Well, you could even get rid of the country codes themselves. ....

It all depends on how people see their identity or that of their organisation. Many of us still see us as entities within a country, thus I am phcomp.co.uk. Larger or multinational/global entities might choose something different, eg ibm.com or one of the new TLDs that were recently created.

Would you trust 'spyproof' mobes made in Putin's Russia?

alain williams Silver badge

Who do you fear most ?

NSA/GCHQ or KGB ?

If I were any of the above I would be setting up companies that sell security products and put a few backdoors in all products. To deal with security companies that I did not 'own' - I would also get a few employees on side by helping them out of problems (financial/drug/marital/...) - problems which I would prob have put them into in the first place.

Maybe they are not doing this; but would anyone believe them if they said not ?

And the buggiest OS provider award goes to ... APPLE?

alain williams Silver badge

Comparing like with like ?

It is very hard to see what they are comparing with what. If it is a default install then all operating systems will install a very different collection of applications ... this makes a naive comparison meaningless.

LinkedIn values your privacy at ONE WHOLE LOUSY DOLLAR

alain williams Silver badge

Why bother to be secure ?

It is not worth the effort.

The main purpose should have been to make Linkedin take security more seriously so that this did not happen again. But the ''fine'' was a rounding error when compared to its turnover, so small that it will only figure as a footnote to a footnote in their annual report.

Only once we start to see the penalties for crap security actually hurt will we see real improvement.

May the fourth be with you: Torvalds names next Linux v 4.0

alain williams Silver badge

Re: don't break compatibility since forever

That is because the ABI compatibility that Linux it talking about is *userland* ie programs. Compatibility within the kernel has never been a design goal - they want to be able to change the way that things work so that they can do things in new/better ways.

That is not at all a problem because all device drivers should be within the kernel tree and thus be recompiled (after perhaps some code changes) with a new kernel.

Binary device drivers are an anathema in the Linux kernel world -- so if you do it, what do you expect ? -- it was never intended to work in the first place! Everything in the kernel is supposed to be Open Source.

So: don't complain about something that was never a design goal.

IEEE rubber-stamps new patent policy

alain williams Silver badge

What about open products ?

Eg GPL software that is free (as in no money) for all to use. If I compile and give a binary to someone will I be liable for license fees ? If so then giving something away will cost me money.

$10,000 Ethernet cable promises BONKERS MP3 audio experience

alain williams Silver badge

Re: Nope...

A provider who has, presumably, moved to HiFi from the health food industry.

Zimmermann slams Cameron’s ‘absurd’ plans for crypto ban

alain williams Silver badge

Who are you A/C ?

A member of the British army 77th Brigade brigade ?

http://www.bbc.co.uk/news/uk-31070114

alain williams Silver badge

Nothing to hide if you have done nothing wrong ?

Having a crap is not illegal, so why do toilets have doors ?

Microsoft eyes slice of Raspberry Pi with free Windows 10 sprinkled on top

alain williams Silver badge

With Microsoft nothing is free

you will end up paying sooner or later. The free bit is to get you hooked.

Google forced to – wah! – OBEY the LAW with privacy policy tweaks

alain williams Silver badge

Subject access request

So does this mean that I can now give Google a subject access request and have it, within 40 days, give me a copy of all the data that it has one me ?

I ain't afraid of no GHOST – securo-bods

alain williams Silver badge

I have just updated some 8 machines, none of them rebooted. I restarted some services (exim, httpd, sshd, ...) - but a reboot was not needed -- these are Linux systems, not MS Windows.

I agree that a reboot is an easy way of restarting everything - but if you know what you are doing it is not necessary.

LEAKED Qualcomm processors reveal sexy new specs

alain williams Silver badge

Re: IS IT?

Yes: 64 bit.

For something that seems designed for handheld use not using big.LITTLE seems strange. Any device will have times when it has little to do, so why not save the battery by powering down the fast but battery eating big core ?

Ailing AMD battered by goodwill, inventory charges

alain williams Silver badge

Re: They missed a trick

IIRC a couple of years ago AMD sacked a lot of R&D types. It improves the bottom line for a couple of years and then the chickens come home to roost.

Checkmate, GoDaddy – Google starts flogging dot-word domain names

alain williams Silver badge

I wonder what google can scrape from this ?

If I visit a web site by some means other than: doing a google search, using google as my ISP, ... it learns nothing about what I am doing (the NSA does not give them a feed!).

If google tells my machine where a domain's name servers are it will know that I am trying to reach the domain. It will not know why, or how long for - but it will know. This is why they provide a free to use name server at 8.8.8.8.

Yes: I do realise that if you use your ISP's name servers, your address is fuzzed and the ISP will cache results ... but google will still learn something.

Should there be legal limits one how data can be shared between the various different business units of large corporations ?

MI5 boss: We NEED to break securo-tech, get 'assistance' from data-slurp firms

alain williams Silver badge

checks and audits

I do not have a problem with targetted surveillance where MI5 need to justify their concerns to a judge before they snoop. ISPs/website_operators must be given these decisions (judgements but not the evidence) as part of a request for help in an intercept. These applications to court must all be published after, say, 10 years. I do not like warentless hoovering of all communications data.

The other thing that I do not see is full auditing and a truely indepdendent auditor - ie not an establishment figure. This guy would be given free access to what is happening and will publish an annual report (yes: summary only) and when there is a 'bust' say how important surveillance was in achieving it - currently I get the feeling that how imporant e-evidence was in a bust is somewhat over played.

Marriott: The TRUTH about personal Wi-Fi hotel jam bid

alain williams Silver badge

I doubt many people would be especially bothered about having to drink a specific soft drink brand at a concert

I would. If I have paid for a ticket for an event I do not expect to be further ripped off by having to buy some overly sweet fetid drink like coca cola or pepsi. I know that some people like them, to me they are disgusting.

NSA's Christmas Eve confession: We unlawfully spied on you for 12 years, soz

alain williams Silver badge

These are the ones that they have chosen to tell us about

There are all those snoops that were not noticed by anyone. It would be naive to assume that NSA auditors/... were able to catch them all.

We have been shown reports of a number of violations. I would not be surprised to learn that there were many more but that the NSA 'fessed up enough to make us all tu-tut and be satisfied that they have told us all that they know ... but the real number known internally is what ?

The NSA has been shown to lie in the past, we would be naive to assume that this is the full truth.

Denmark BANNED from viewing UK furniture website in copyright spat

alain williams Silver badge

Re: The Danish legal system must be retarded to have 75 year copyright

In England we have 70 years from the release date for music and 70 years from author's death for books - both a far too long, IMHO.

Linux software nasty slithers out of online watering holes

alain williams Silver badge

So how does it work then ?

This Turla cd00r-based malware maintains stealth without requiring elevated privileges while running arbitrary remote commands. It can't be discovered via netstat, a commonly used administrative tool. It uses techniques that don't require root access, which allows it to be more freely run on more victim hosts. Even if a regular user with limited privileges launches it, it can continue to intercept incoming packets and run incoming commands on the system.

If it does not use elevated privileges then, I assume, that it has not tampered with the kernel. So how does it hide from netstat ?

Ah, later he says: The module statically links PCAP libraries, and uses this code to get a raw socket, ..., but use of PCAP requires superuser privileges???

I am not saying that this is not a threat ... but I would like to see something more plausible - if only so that we can protect ourselves -- without having to buy something from Kaspersky ... which is what I get the feeling this is all about - a marketing exercise.

Government locked into £330m Oracle contract until 2016

alain williams Silver badge

The public sector spent £290m in 2013 with Oracle

If they put 10% of that into sponsoring open source projects I wonder how long before they have a royalty free suite that does what they need ? Run it on top of Linux using PostgreSQL, etc, and the bills would drop.

OK: open source projects will not do exactly what is needed, so pay FLOSS hackers to write the code and release it under the GPL. This code could be used/shared by different government departments, by industry and even other governments[**].

Do they not think that this is what Oracle is doing ? Write the code once and then implement it many times at different customers ?

I do realise that requirements will change, so any solution will need maintainance. I also realise that different use cases will have different detailed requirements, but well designed core components will be able to be reused.

[**] Hmmm, the thought of helping the French might put the kibosh on this :-)

Microsoft hikes support charges by NINETY TWO PER CENT

alain williams Silver badge

If it turns out to be a bug

in the Microsoft s/ware, will they pay the $499 back ?

Oh - look at the pigs fly by ...

It's BLOCK FRIDAY: Britain in GREED-crazed bargain bonanza mob frenzy riot MELTDOWN

alain williams Silver badge

Re: Buying For The Sake Of It.

Dear Marjorie,

I have not felt the slightest urge to go out and buy anything today. Is there something wrong with me that even my best friend won't tell me ?

Assange™ slumps back on Ecuador's sofa after detention appeal binned

alain williams Silver badge

The wrong story

Assange was about Wikileaks and, at the time, Snowden. It looks that the USA have succeeded in neutralising him as I seem to remember that there was a lot of talk about the rape charges being 'encouraged' by USA operatives. Assange has now been removed from this.

What would Assange have gone on to do if he were not holed up at the embassy ?

BTW: I wonder what he does with his time and how he pays for his keep ? Does he wash the dishes or perform office tasks ?

Ofcom tackles complaint over Premier League footie TV rights

alain williams Silver badge

How to bring competition

Is to ban exclusive deals, ie insist that every football match can be broadcast by at least 2 TV channels (or Internet stream). That gives the media the incentive to be cheaper than their rivals to get the eyeballs - thus introducing real competition. If the price paid to clubs drops, then so be it. There should be no minimum fee that has to be paid to a club; so if no (second) bidder bids more than your £100 to be there streaming from a web cam - then so be it.

The fans will gain from this.

The only losers will be the clubs & media.

Expect collusion between the clubs and the media and a few people going to prison as a result.

Rosetta probot drilling denied: Philae has its 'leg in the air'

alain williams Silver badge

Re: One leg in the air?

It is looking for a lamp post to pee on -- wouldn't you be after 10 years ?

RBS's Ulster Bank whacked with enormous IT cock-up fine

alain williams Silver badge

About £4.60 per customer affected

A few days bank charges will pay that.

Cry Havoc and let slip the dogs of Patent WAR! Samsung strikes back at Nvidia

alain williams Silver badge

Lawyers win

No one else.

Don't assume public trusts you, MI5. 'Make a case' for surveillance – Former security chief

alain williams Silver badge

Give us the evidence - then I might trust you

I remember all too well Tony Blair saying how Saddam could blast us in 40 minutes and lots of other stuff from the dodgy dossier. I remember him asking us to trust him. What Therea May and the chief spooks are saying today smells as it came from a similar source.

If they want to convince me then show me the real evidence, come out with real numbers - not ones massages to support their case. I accept that I cannot see everything as it may destroy current investigations, but they could show it later. Show how they got to feel the bad guy's collars, how much by wire tapping, how much by old fashioned investigation. Do not sex it up.

And please don't blather mindlessly about terrorists, drug lords & paedophiles while vaguely waving your hands - it just does not wash. Whenever anyone tries to use emotions to make me forget logic: I switch off and put them in the 'not to be trusted' box.

HOT YOUNG STAR about to GIVE BIRTH, long range images show

alain williams Silver badge

Teenage pregnancy ?

Where is the daddy ?

IPv6 web starts to look like the internet we know

alain williams Silver badge

Name and shame

We need to start to name & shame ISPs who do not offer IPv6 support.

I will start with Direct Save Telecom. I used them when I set up IP connectivity for the local community group office. I was told that they would provide IPv6 soon. Querying this 6 months later I was told "Oh, that was just the salesman - we have no plans for IPv6".

More Home Office and MoJ jobs could move abroad, union warns

alain williams Silver badge

All that lovely data going overseas ...

where it will be perfectly safe! Ahem :-(

What could possibly go wrong ?

+1 to MOJ ignoring the cost to the tax payer through job losses & tax lost if it were done in the UK.

#100m over 10 years = #10m a year. Job loss: 65000 = #154/year saved for every job lost!

MoJ might gain; UK as a whole loses. Morons.

WHITE HOUSE network DOWN: Nation-sponsored attack likely

alain williams Silver badge

Presumably this crack is legal

They say that it bears the hallmarks of a state-sponsored attack, so presumably the White House will say ''fair enough, this is a legal crack into our network'', after all Prosecutors in Silk Road raid trial: If you're outside the US, you're fair game for hacking.

What is sauce for the goose, is sauce for the gander.

Adobe spies on readers: EVERY DRM page turn leaked to base over SSL

alain williams Silver badge

Re: EULAs

Currently EULAs are one of several wild wests of the Internet. However: because they do not disadvantage corporations there is little action to control them and certainly no campaign contributions for doing so.

alain williams Silver badge

Computer Misuse or Data Protection ...

Surely there must be some infringement under the Computer Misuse Act for it doing something that the owner does not want .... Oh, he agreed to it on installing it did he ? Does this thing record the number of people who did not read the agreement ?

Looking at what is collected - it is personal information. This information is being taken out of the UK.

However I agree with those above who say ''just say 'no' - don't use it''.

GP records soon wide open again: Just walk into a ‘safe haven’

alain williams Silver badge

Subject data access request

I wonder what would happen, if in a few years time, I were to demand that the insurance company were to give me a copy of all the information that it has on me. This would have to include anything obtained from the GP records.

French 'terror law' declares WAR on the INTERNET itself, say digi-rights folks

alain williams Silver badge

Who defines terrorist ?

What if someone goes to join the conflict in Gaza, should he be allowed to go ?

Yes/no if he goes to join Hamas to throw bombs ?

Yes/no if he goes to join the Israeli army to throw bombs ?

Both almost as bad as each other - but I bet only one gets stopped!

FBI boss: We don't want a backdoor, we want the front door to phones

alain williams Silver badge

Re: "I've never been someone who is a scaremonger..."

He might not be - but too many people like him have called 'wolf' too many times - we no longer believe them.

Return of the Jedi – Apache reclaims web server crown

alain williams Silver badge

Re: Closed is out of flavour these days.

The difference between closed and open source is rather like the difference between religion and science.

Religion (closed source): you do not have evidence (source code) and have to just accept what someone says is true. Theory correction (bug fixes) is hidden - if it happens at all.

Science (open source): you know that you can look at the evidence (source code) and verify what you are being told. Theory correction (bug fixes) happens in public view.

You might not have the ability/desire to look at the source code, but know that other can.

Open source problems are visible for all the world to see, do you know what horrors lurk in closed source ?