* Posts by Justicesays

629 publicly visible posts • joined 15 Jun 2010

Page:

WTF is up with the W3C, DRM and security bods threatened – we explain

Justicesays
Facepalm

Hey guys, I've found a flaw in your DRM

Turns out it's still actually possible to see and/or hear the content.

Therefor it cant actually prevent people copying it.

Parents have no idea when kidz txt m8s 'KMS' or '99'

Justicesays
Happy

"Perhaps we should focus on making kids resilient to failure and capable of dealing with conflict"

Some kind of cluster with a quorum would seem to be required then.

US government agency pops 16 years of solar weather data online

Justicesays
Coat

Re: solar weather

Wuss.

I'm orbiting the sun right now!

UK defence secretary: Russian hacks are destabilising Western democracy

Justicesays
Unhappy

Re: Don't be a cvnt and there won't be a problem

Due to the way political funding works, and the required attributes of a politician in a party based system, it turns out that non-(dodgy crooked bastards) are pretty much incapable of getting elected anyway.

Coming to the big screen: Sci-fi epic Dune – no wait, wait, wait, this one might be good

Justicesays

"There was no basic trade going on"

I'm not sure what logic you are using to think this is wrong.

How much stuff do you think we would import from Mars were we to establish a colony on it?

Even one that was hugely successful and producing a surplus?

The only thing that would justify space shipping would be super high value, low weight items like "spice".

Elon Musk could afford to have stuff shipped back from Mars.

Normal people couldn't.

The fact the whole economic basis of space travel in dune is super rich people prolonging their lives seems reasonable to me.

Current trends on earth mean space travel is now in the hands of wealthy individuals, not just governments.

Sci-fi settings with "space truckers" moving around holds full of space wheat are typically the unrealistic ones.

Justicesays

Re: Make something new

"A better candidate might be Anne McCafferys Pern dragonrider series. Sci-fi with some fantasy tropes but well written and not suffering from the same flaws as the teen-aimed dragon stuff now."

Did you try re-reading those recently?

Motivational speaker in the slammer after HPE applies for court order

Justicesays

Re: Any explanation on how it cost HPE £17m

Maybe something similar to this case?

https://arstechnica.co.uk/tech-policy/2016/07/hpe-wins-high-court-fraud-fight-international-computer-purchasing-ltd/

Basically grey marketing HP kit against their wishes.

Might perhaps upset the narrative to show HPE as some kind of grasping, evil corporate monster though.

President Donald Trump taken on by unlikely foe: Badass park rangers

Justicesays
Trollface

Re: About time

"Well, I must admit that Democratic People's Republic of North America has a certain ring to it."

That would never happen.

It would be the "Republican People's Republic of North America".

Lords slam 'untrammelled' data sharing powers in Digital Economy Bill

Justicesays
Devil

Looks like a great commercial opportunity

First they get every ISP in the country to collect every activity everyone does on-line.

Then they sell that data to commercial companies for advertising.

Sounds exactly like what Digital Economy would be about.

CIA boss: Make America (a) great (big database of surveillance on citizens, foreigners) again!

Justicesays
Mushroom

Additional requirement that didnt make the story was

Integrates with Twitter, providing the President a direct right click menu from which he can select options such as

IRS audit

Smear campaign

Dispatch Police/Secret Service/Killer Drone

Declare War

Nuke

Europe mulls treating robots legally as people ... but with kill switches

Justicesays

Re: AI hype?

"The fact that the gap between remote controlled car and intelligent murderous robo-killer is simewhat ggantic would never occur to them."

Well, in fact, the gap between a remote controlled car and a Google Car is mostly just size, and you know the most common winning Robot type in Robot Wars and similar competitions?

Its the boxes with wheels that just ram the opponents until they break or push them into the hazards.

This is why they have added rules to make the robots have weapons etc. in order to not make the show about two blank metal boxes ramming each other.

Co-incidentally, an autonomous car is basically a large metal box robot capable of high speed ramming.

Except not remote controlled (well, until the hackers get at them).

Why the UK is unlikely to get an adequacy determination post Brexit

Justicesays

I'm not sure where the "We" is in the appointment process.

"We would, in future, be well advised to avoid promoting Home Secs to PM; the experience seems to warp their judgement."

As the appointment process consisted of several rounds of political backstabbing and back room deals, and not even the tiny proportion of the country that are official members of the conservative party got to pick between prospective candidates, I'm not sure where the "We" come into it.

Man jailed for 3 days after Texas cops confuse cat litter for meth

Justicesays
Devil

I'm assuming

that these test kits are the wooden sticks in which you insert an "attuned" template, and then dowse for the drugs/bombs/terrists?

Robo-supercar hype biz Faraday Future has invented something – a new word for 'disrupt'

Justicesays

Re: Are we nearly there yet...?

Battery swaps are not going to solve the key issues.

They would only act to even out the recharge delay, as the replaced battery is going to have to be charged for the requisite period before someone else can use it...

You have the problems of having enough storage capacity at your "recharge stations" to hold all these charged/charging batteries, and the power transmission/conversion equipment required to charge all the batteries simultaneously.

Say a petrol station has 12 pumps, takes 5 mins for a driver to fill up, and say a battery takes 80 mins to charge.

16 batteries per "pump" on charge to keep up with demand, assuming petrol stations are sized appropriately, at peak hours.

=192 batteries.

Telsa S has 85 kWh battery.

That's 85*192KWh to be supplied in 80 mins

~12MW draw if my math is correct.

That's 24000 homes worth of electricity being funneled in there.

Obviously if you has more batteries you could stretch out the demand over a longer period, but to get it so you could charge overnight and then use those to meet high daytime demand you would be looking at several multiples of 192 batteries.

Assuming peak usage of all "pumps" as it were.

What gifts did ol' kitten heels May get this year?

Justicesays

Re: Checklist

"We haven't reaced the stage of neighbours informing on neighbours."

We are way past that stage I'm afraid.

https://web.archive.org/web/20060925221903/http://www.met.police.uk/counter_terrorism/docs/61688_Bell_Push_LR.pdf

This is your captain speaking ... or is it?

Justicesays

Re: Whoa, hang on

Obviously its was to dismiss already known issues as "of course we already know about that and therefor..."

I call bullshit on the magical system fairies that know all unknowables, encompass all conceptual spaces, can fully prove a complex system with state combinations well beyond the number of atoms in the universe, and never make mistakes. Oh, and do everything from scratch so they don't rely on possibly flawed work from outside.

Unless you never release of course, then all things are possible.

Justicesays

Re: Whoa, hang on

"Rowhammer doesn't work over RS-232..."

Sure, rowhammer (my mistake) doesn't work over RS-232 (as it requires fast memory access) ,and RS-232 is a simpler interface than a full 7 layer network stack, and therefore less likely to have exploitable vulnerabilities.

However, rowhammer is merely an example of a class of exploits that lie outside "state space analysis" (such as checking all inputs and outputs...) of a system. Even formally proven systems could be vulnerable to such attacks.

Like having unbreakable encryption, that is none the less broken because your CPU activity while decrypting gives clues to the keys and can be picked up by a hack into your sound card...

In most cases of course, it's often more cost effective to use an alternative method than trying to find some exploit.

for example, developing deep water submersible drones with electronic probes on them.

The big issue comes when COTS equipment and software is used (like TCP/IP networking kit, Intel Processors, Linux, Net-SNMP) etc. As these are extensively used, constantly attacked and are "generic" (in the sense they need to be flexible enough to cover a multitude of situations) it's almost inevitable that exploits are discovered against them. And should one or more of those exploits "line up" in just the wrong way, suddenly your "secure" system is exploitable by anyone who can run a script or two. And you only find out about it if the exploits are public, if they are one of the "hoarded" exploits then you may never find out. This of course ignores the fact that COTS and open source systems are also vulnerable to bad actors deliberately introducing flaws specifically to allow attacks to be carried out , if the attackers are dedicated or funded (or connected) enough. Even bespoke code can use generic compilers or libraries, or run on generic CPU's, BIOS/UEFI stacks etc.

Justicesays
Trollface

Re: Whoa, hang on

Well, smug "my security is perfect guy"

Riddle me this.

Do you ever apply patches to your oh so secure system?

Justicesays

Re: Whoa, hang on

"you can't even overflow the buffer unless the cpu isn't doing what it's supposed to".

Even if (and I highly doubt this being the case on any modern system) you had a full state machine layout of your entire system and thus could make some assertions that no unexpected states existed, this would still overlook issues outside the logical system state that stray into physics territory (such as the ramhammer technique).

As a result, I would take askance at any assertions of 100% security, for any kind of interface where information is passed between two systems. The more complex the interface, the more likely some exploit is going to exist.

Justicesays
Facepalm

Re: Whoa, hang on

"Hell, at [redacted] we implemented an exchange between secure and nonsecure parts of the ground network where the nonsecure part would ask for new data using an SNMP packet, and the secure part would eject the data as needed. It's not rocket science!"

And that's all fine until it turns out an unhandled buffer overflow in SNMP allows your "non-secure" request to hack the software on the "secure" system, right?

Which is exactly the kind of issue that should be avoided by using actual physical separation , not just some firewalls or restricted port services.

No Soylent for Santa after key ingredient supply is choked off

Justicesays

Re: Remind me...

'So how do they sell it at about 2-3 times the price of a pint of milk?'

In the UK the ingredient labeling is a lot stricter than (say) the US.

https://www.alpro.com/uk/products/drinks/almond/unsweetened

Almonds (2%).

You may as well drink water and eat a couple of almonds.

Put down the org chart, snowflake: Why largile's for management crybabies

Justicesays
Devil

Just ignore the non-userland requirements...

"Once this team started deploying software weekly and studying how the user interacted with the software, they learned what was actually needed and changed the requirements appropriately. The team removed the need to "align" with others in their organisation. Sure, there were external systems to cope with, but removing the need to coordinate and take ongoing input from parts of the organisation that weren't close to the actual users speed up the schedule tremendously, delivering months ahead of time."

So, as the users know nothing about security and in the main it just gets in their way, that bit doesn't get implemented I guess? Along with any other "hard but not user visible" requirements.

Had a friend tell me about an application someone in his organization implemented to replace an older piece of infrastructure. It didn't work , and when asked why the development team said they had developed their side of the interface and taken it live, but the other side their team wasnt responsible for hadnt been implemented , so the data just went into a black hole... I guess they liked delivering fast as well...

Capita STILL hasn't delivered usable Army recruitment IT system

Justicesays
Devil

Re: System delivery

"Offshore developers are rarely the issue as long as they are treated as a pure subcontractor (in-house or not) however it is necessary to apply as rigorous quality management processes as your your customer will (or should). This overhead usually means that offshore is not a cost reduction but for resource only and may indeed cost more due to quality assurance overheads. "

Translation:

Pay peanuts, get monkeys. Then employ extra people to look through their random output until you eventually find an approximation of Hamlet. Then it turns out the customer wanted Macbeth.

Sound-mufflers chuck acoustic sleep blanket at the noise-plagued

Justicesays
Trollface

Tired of being woken up ?

By smoke alarms, your crying children, or gunshots in your house?

Why not try our new "sleep well" sound blanket.

Also available:

Peril Sensitive Sunglasses, for where you are better off not seeing what's coming!

PayPal patches bone-headed two factor authentication bypass

Justicesays
Trollface

Did he try

putting correctpassword1 in the POST while he was at it?

I've arrived on Mars. Argggh, my back!

Justicesays
Happy

Re: Spin is the answer

Two part solution,

A spin that provides somewhat less than 1g, say 1/3 g

+ lead-lined helmets and shoulder pads!

Just try not to look down too much..or topple over... or move too fast and forget it takes longer to stop with a few 10's of kgs of lead about your person.

Still, might be something in it!

Alternatively, several sizes too small (in the vertical direction) rubber onesies might serve to put some gravity like pressure on the spine.

This is not a drill: Hackers pop stock Nexus 6P in five minutes

Justicesays
Devil

Re: Say whaat?

The first thing they hacked was the clock and/or calculator...

Swedes ban camera spy-drones for anything but crime fighting

Justicesays
Devil

Re: _

"When drones are outlawed, only outlaws will have drones."

Which is great, because if you then see someone with a drone, they are a criminal and thus calling the police is definitely the correct thing to do!

Puppet shows its hand: All your software is belong to us

Justicesays
Devil

Re: In the future code is going to be managed and deployed by other code

It''s simple,

They provide code that allows you to write code to manage code.

You still have to write that code yourself, but if everyone used puppet you might be able to steal most of your code from "puppetmonks" (without really understanding it), then brick your entire data-centre during some edge case deployment.

Even Google have managed to do that, so it wont be hard for other people.

The IRS spaffed $12m on Office 365 subscription IT NEVER USED

Justicesays
Devil

I can see it now...

PHB: So, I need a plan for the next email and server upgrade.

Guy1 : Lets buy office "in the cloud" instead of hosting our own email and file servers.

Guy2: Great idea, and we can save money on local support, servers, all that stuff

PHB: I'll raise the PO, good job guys.

... Sometime later...

Security guy: I just heard that we purchased office 365 for the whole organization.

PHB: Yeah, isn't it great!

Security guy: You realize that this means we'll be storing all our email and documents on Microsoft servers? And that we have at least 3 ongoing cases where we are investigating them for billions in taxes right now? Do you think it's a good idea to potentially let them read all our email , investigation outcomes and case preparation?

PHB: Err...

Security guy: Yeah that's what I thought. Migration cancelled. How much was that again?

PHB: $12 million...

Virtual reality is actually made of smartphones

Justicesays
Facepalm

Yep, undoubtably

I guess those first few iPhone users who had to pay $100,000+ of dollars for their iPhones can feel a great sense of achievement now. Hang on, I seem to have found a flaw in this argument...

Snowden investigator slams leaker-detector background checks

Justicesays

He seems to have a highly specialized sense of outrage

"As a taxpayer, it made me angry … whenever someone stabs you in the back, from a professional standpoint it is a hard thing to endure."

But he still manages to work for the American government... I guess they call it "Front-stabbing" so he's fine with it?

Confirmed: UK police forces own IMSI grabbers, but keeping schtum on use

Justicesays
Unhappy

The question people are really asking is

Are you using Covert Mobile Intercept Technology to illegally spy on the public with no oversight?

To which the answer is almost certainly "yes", which is why they wont talk about it.

It will all be ignored until it turns out some copper was using it to listen in on his ex-wife's calls/texts, then goes out and murders her/her new boyfriend or whatever and they can't cover it up.

Devs! Here's how to secure your IoT network, in, uh, 75 easy pages

Justicesays
Unhappy

You can expect your developers to have done a 3 year degree...

But if you expect them to read a 75 page document... turns out it's TL;DR.

Psst. Need some spy-on-employees tech? Ask Oriium

Justicesays

Re: The usual "credit card" string

"Every vendor in the spaces used Credit Card strings and they are really simple and unique format, and thus easily defined"

Sure,

That's any number between 13 and 19 digits long then, with maybe some other characters in there dividing them into groups.

Hey, my phone number is 14 digits long in international format...

As the saying goes "now you have two problems"

BOFH: There are no wrong answers, just wrong questions. Mmm, really wrong ones

Justicesays
Trollface

Re: 2B) or not.

"good news; you're not an axe murderer".

Followed by.

"Unfortunately this mean you do not qualify for the CEO position. If we have any non-executive positions come up later be sure that we have your CV on file.

Report: NSA hushed up zero-day spyware tool losses for three years

Justicesays

Re: Relevant

The correct analogy in this case is:

you manage a school network.

Unbeknownst to the principle and staff, you (however unwisely) have a copy of all their passwords that you use to access their systems at will, which you use to "check for viruses/fix issues" etc. Obviously you could use that power to steal cash/read private emails/sell exam paper access, but you don't because you are nice, even though there is no oversight (so maybe you do). The passwords don't expire, so you don't have to worry about getting the new ones unless someone changes theirs for some reason.

One day you find that a hard copy of your list of all the staffs passwords has been stolen by someone (probably a student).

Rather than admit what you have been doing, and getting all the staff to change their passwords, you instead just do extra monitoring to see if you can spot when someone logs in with those accounts who isn't the teacher involved.

After a few weeks you think, "Ok, probably fine, I cant see any dodgy logins".

Three years later someone posts the password list to the schools internal mailing list using the Principles account.

It's a bit different from rounding up criminal conspiracies or thwarting student pranks.

How do you think an auditor should react should they find a situation like the one described?

How trustworthy are your schools exam results for the last 3 years...

Justicesays

Right... and if they spotted them then?

So, what was their plan if they spotted these tools in use?

If they suspect a "state actor" then what would they be able to do about it anyway?

There is no way they can somehow magically delete them once someone else has copies.

Next port of call should have been CERT. At this point they can't even claim that "only they know the hacks they use", so that argument is demonstrably bullshit.

And these are supposed to be the group that also help stop cyber attacks on US infrastructure...

What a crock.

Despite IANA storm, ICANN shows just why it shouldn't be allowed to take over internet's critical functions

Justicesays

All they really own

Comes down to 26 lines in a large number of text files world wide...

British unis mull offshore EU campuses in post-Brexit vote panic

Justicesays

What underwrite means when politicians say it

See also:

underpay

undertaker

understanding(lack of)

Microsoft deletes Windows 10 nagware from Windows 7 and 8

Justicesays

Re: how badly they fuck up something so simple

Ironically the standard fix for this issue is to install an update...

You can manually download the individual update from MS however.

Tip: temporarily stop the windows update service before installing it or you have to compete with the locked up background update scanner.

http://superuser.com/questions/951960/windows-7-sp1-windows-update-stuck-checking-for-updates

Great British Great Bake Off gets new judge

Justicesays

Re: I'm not really sure how this fits with the Channel 4's charter

I guess "publicly owned" sounds better than "state owned" when it comes to broadcasters....

Elsewhere on the site it does say "State owned"

http://www.channel4.com/info/corporate/about/channel-4s-remit

And Wikipedia says "Although largely commercially self-funded, it is ultimately publicly owned; originally a subsidiary of the Independent Broadcasting Authority (IBA), the station is now owned and operated by Channel Four Television Corporation, a public corporation of the Department for Culture, Media & Sport"

Justicesays
Stop

I'm not really sure how this fits with the Channel 4's charter

Channel 4 is a government owned commercial channel with a public service remit

"We are a publicly-owned, commercially-funded public service broadcaster. We do not receive any public funding and have a remit to be innovative, experimental and distinctive. "

I'm not sure how buying an existing show by outbidding the publicly funded broadcaster is forwarding any of those values.

You should install smart meters even if they're dumb, says flack

Justicesays
FAIL

There would be a saving

"The UK’s controversial smart meter programme will only succeed in saving consumers cash if people are made aware of the benefits, says Rob Smith, head of policy and public affairs at Smart Energy GB."

So, if we were made aware the benefits would be non-existent, we could save consumers the price of these new meters by stopping the roll out now? Sounds fair.

This nob-end is in the same league as Nicola Shaw (head of the National Grid), who is convinced that Smart Meters (and presumably fairy dust) , not a sensible policy of replacing aging power stations, will prevent brown outs.

Then she suggests moving dishwashers, tumble dryers and washing machines to run at night, in the "cheap tariffs"

Presumably not aware that these devices are not supposed to be run unattended due to fire risks (as we all discovered during the dryer recall last year).

I guess we can keep warm at night using the energy of nearby burning houses.

Star Trek's Enterprise turns 50 and still no sign of a warp drive. Sigh

Justicesays

Re: "The Hitchhiker’s Guide to the Galaxy had hyperspace..."

Given the earth was demolished to make way for a hyperspace bypass, they also had hyperspace. Apparently travelling in hyperspace is unpleasantly like being drunk.

The infinite improbability drive was invented to allow interstellar travel without all that tedious mucking about in hyperspace.

'Smart belt' loosens purses

Justicesays

Hopefully comes with

Grappling hook, bat shark repellent etc.

Delta computer outage costs $100m

Justicesays
Trollface

Re: $100M

Yeah well, they cant afford that now, they just lost $100M!

And really, what are the odds of it happening again?

</beancounter>

Sex is bad for older men, and even worse when it's good

Justicesays

Did they check

for the consumption of "supplements" by the men involved?

Robot cars probably won't happen, sniffs US transport chief

Justicesays

Re: I'm not sure I understand

"I think I'd want a car programmed with self-preservation."

Sounds good - until you try to scrap it...

IBM swings axe through staff, humming contently about cloud and AI

Justicesays
Devil

Re: The American Dream

"Better to layoff a few thousand and revitalize your business than to keep going in a failing direction"

Amazingly IBM seemed to have cracked the secret of managing to do both (minus the "revlitalize", I wonder how many remaining employees at IBM are feeling "revitalized" right now).

Page: