The Register Home Page

* Posts by HereIAmJH

758 publicly visible posts • joined 24 Aug 2010

Page:

Tennessee congressional hopeful accused of shooting license plate cameras

HereIAmJH Silver badge

ALPRs

As for the cameras, they're all over the place.

There is another method of deploying them. You know those trailers they use for temporary road signs and construction work lights? Well they use those for ALPRs too. I noticed several pop up while the FIFA world cup was in town. They are the orange trailers with the small box like a road sign, but instead of a sign there is a mast with an object at the top. These can be towed anywhere and assembled in about an hour. The ones I saw were off the side of the interstate highways, scattered around town.

For plate recognition they snap a picture of every vehicle that drives past them. They send those pictures to their database and AI generates metadata for them. Including plate number, make, model, and color of the vehicle. And any distinguishing characteristics like stickers, dents, or scratches. So they absolutely know about your Fuck Flock sticker.

As far as abuse, Flock is taking a hands off approach on access. They sell access to agencies and log the queries that get run, likely because they bill on a per query basis. But they state out right that it is up to the client to control who can run queries and what policies should be followed. And they don't just sell to government agencies. I've see stories about HOAs (Home Owner Associations) installing Flock cameras.

HereIAmJH Silver badge

Re: Size

He's running as an Independent, this means that neither Democrats nor Republicans (who are voting a straight ticket) would vote for him.

In Tennessee, which means he had no chance of getting elected anyway.

Windows Server Update Services buckle under Microsoft's metadata mountain

HereIAmJH Silver badge

Re: WSUS was such a wasted opportunity

From a business critical application perspective, you never want an update to install automatically. It doesn't matter what it is. Updates always get applied to non-production environments and then tested before a scheduled update to production. I wouldn't even update all the nodes in a cluster on the same day, just in case. WSUS gives administrators an interface to group those environment for business stability. So of course Microsoft doesn't see the value in that.

What I found most annoying about WSUS was caused by Microsoft. They tied Windows Updates with their app store. So once you configured your system to only get updates from your trusted WSUS, it would no longer allow installing apps from the store.

Photovoltaics are still running after a year under Swiss trains

HereIAmJH Silver badge

It's also labor costs are cheaper in emerging markets. That lowers the price of everything. But they also don't need to earn as much because their living expenses are lower. A quick google search says the cost to live in Shenzhen is $1000 USD/mo. Where I live it says it would be $2500. $550 one-person rent vs $1650. Food here is 2.5 times as much. If you move your factory to a more rural area you can reduce labor costs further, but you might lose the savings to transportation. And then there are the questionable labor practices....

HereIAmJH Silver badge

Re: No, the real challenges are technological and economical

Ignore the grid. Require solar panel installation where possible, to the degree that it's output is consumed at the source. Those air conditioned Warehouse-turned-Supermarkets use a lot of energy. Both for climate control and food preservation. Even if not required, change regulations to allow installation of solar carports to charge electric cars. My city simply will not allow it currently. They only understand (permit) standard grid tie configurations.

HereIAmJH Silver badge

Another advantage; ability to provide power where there is no grid connection. The railroads use signals and communication every where along their routes. This is how SPRINT was born. If they provide some backhaul, they could also support cell towers in remote areas.

HereIAmJH Silver badge

Re: Oh but just you wait

the spaces between the rails were pretty grody with tar, oil drippings, and who knows what else

Some of that might be decades of waste oil sprayed around the tracks to stop plants from growing. The thing I wondered about, do US passenger trains still dump their toilets on the track? That would make cleaning the panels a nasty job.

Frame: A new X11 server – implemented directly in assembly

HereIAmJH Silver badge

Re: So...

hand-crafted assembly has underperformed what a modern compiler can do for years

And if a compiler can do it, it won't be long before AI is out performing humans in this area too. Right now we are asking AI to give us code, not binaries.

MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage

HereIAmJH Silver badge

Re: Passkey issue

being able to have one device attest for another (i.e. have your PC talk to the phone on behalf of your PC's browser to get the passkey needed)

This may be what you are thinking about; I never access my banks via my phone. When I log into one of them with my laptop, I select a 'other device' option on the login. Name/password, enter and get a QRCode. I then have to pull out my phone, scan the QRCode and then my laptop browser session proceeds to be authenticated.

Personally, the whole process pisses me off. There are two passkeys on my phone, one works and one doesn't, but they have the same name so just guess and try again. I don't like the QRCode because I have no clue what it is doing, and I just have to trust them. And now both my phone and my laptop are linked (I can't use the same process to log in from my desktop). If either of them fail I need a new passcode which basically appears to be a lost password process.

HereIAmJH Silver badge

ATM cards and PINs

The bank doesn’t let you transact without a password, and it doesn’t issue you an ATM card without a PIN, because it knows that there has to be a required minimum level of security.

PINs are only needed in special circumstances. In person transactions. In the US, ATM cards are almost exclusively Visa debit cards. If you are accessing your account via an ATM, you need the PIN. If you are buying something at a local merchant, you need the PIN IF you are doing a debit transaction. Visa debit cards can be processed as credit cards, no PIN required. And if you are purchasing online, no PIN is required.

And as far as MFA, banks use it as a revenue generator, not essential security. Rather than doing something simple, like using Google Authenticator, they roll out an app so they can push additional services to you. I had one bank tell me last fall that they were rolling out an app and that it would be the only way to access my account going forward. I, and many others apparently, told them that when the app was required I'd close my account. I won't make my phone less secure by loading everyone's special app just so they can send me notifications of their latest marketing scheme. They backed off the app requirement and still allow web access, with no MFA.

And on the whole app craze; I don't want to load apps for businesses that I use rarely. That includes some of my banks. And it also includes a new one, pre-check-in to confirm a doctor's appointment. I have worked in large corporations, I know their security is sloppy. I do not trust them to install secure apps on my phone or QR codes that can take you to any website on the internet.

Microsoft previews Linux containers that run in Windows

HereIAmJH Silver badge

Re: WSL is great

Would be nice if Windows supported docker directly. Click on a container, it launches in a window with clipboard support.

Former Microsoft engineer shrinks Notepad down to size

HereIAmJH Silver badge

And being corporate IT, they wouldn't even allow you to run an non-registered EXE.

I used to get flagged by the scanners building versions of the app I was supposed to be developing. And don't dare add a new EXE to the application.

I used to be afraid to lock my laptop because it might think it was idle. So I'd come back from a short trip to the restroom and find it too busy to let me log back in. I'd hit a key to get the login box, the screen would blur, but the login prompt wouldn't show up for 30 minutes. That really sucks if you just had a couple free minutes between meetings.

It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns

HereIAmJH Silver badge

Re: With Enough Eyeballs...

The good thing about F/LOSS is that the White Hat eyeballs scanning the code rival or exceed the Black ones.

Keep telling yourself that. There never seems to be a shortage of criminals or state sponsored actors. Many open source products have a shortage of skilled volunteers. In fact, that is why many of those projects die.

Midjourney pivots from AI image generation to body scanning medical spa where patients bathe in 'golden light'

HereIAmJH Silver badge

My first thought is using AI to make naked videos of people is requiring too much compute. So they'll just con you into coming in and they can get the images directly. Because obviously you need to be naked for the 'golden light' to work. Special invitations going out to celebrities and influencers.

KDE Plasma 6.7 brings the X11 era to a close

HereIAmJH Silver badge

Re: Endless discusssion cars : start your engines !

You won't have time after you retire. Trust me, the todo list just gets longer and longer because you have all those things you were going to do 'after I retire'. Better get started on them now.

Developers build the best tools for developers – and are now defanging the AI menace

HereIAmJH Silver badge

Re: Two reasons

The second is that more often than not (and despite the best efforts of managers) software writing is fun.

For me, software development was fun before Agile. Then it became micromanagement by people who didn't understand technology, tickets, and meetings. Management has worked for years to turn creating software into an assembly line job. After all, no talent is needed to manage people if you rely solely on automated KPIs.

I don't fear AI, I view it as a tool. But I've already given up on creating software as a career. If lone developers and small teams can leverage AI, they will produce quality software faster. If you use it to turn out that crap that many large projects produce, then we'll just get the same shit software we get now, only faster. Right now AI is an alpha stage tool, it has a long way to go before it's fit for daily use. That isn't going to stop people from using it if they think they see a competitive advantage.

I remember the days when development environments were little more than text editors. Remember when syntax coloring was new? Then the brutal early days of creating apps for GUIs. One day drag and drop tools emerged for fast prototyping. Visual Basic and Delphi. When was the last time you thought about a message queue, much less managed one? Things have grown so much since then, source code repository integration, searchable component libraries. For most, AI will just be one more tool.

Unfortunately, with improved productivity will come smaller workforces. Cheaper development costs will eventually increase demand, but in the meantime many are going to be looking for new careers. Productivity improvements always go to the corporation, not the individual.

BOFH: For one ambitious security type, chaos is a ladder

HereIAmJH Silver badge

BOFH has a back door into everything. With all the AI video tools, I could see him replacing surveillance video with some AI generated video showing security head loading laptops in his car.

Angry bug hunter with Microsoft beef drops new Windows 0-day

HereIAmJH Silver badge

Re: MS vs what?

Basically true, but some design decisions do make some systems easier to crack open than others ....

You mean like choosing a monolithic system that handles boot, init, logging, logins, can spawn processes, network configuration, host name resolution, and time synchronization?

HereIAmJH Silver badge

Re: MS vs what?

Linux.

Once upon a time I would have wholeheartedly agreed with you. This is the year of the Linux desktop. But then systemd happened. Most of my Win systems have been retired, but I still have 4 and they won't upgrade past Win10. (2 laptops, 1 desktop, and my AD server) And one of them, a relatively new MSI laptop with an NVidia GPU that is apparently dying, will be going away soon. Still looking for a Linux ODBII tool on the level of Forscan, so one system has to stay Windows.

here is a bright future, but it does not contain those pretty Excel charts that manglement is enamoured with.

LibreOffice does just fine for me. But I don't have to deal with manglement any longer. Now it's just the smurfs on the highway (turning blue because their head is up their ass) or the rude people that always block the aisle at the grocery store. They don't care what OS I use.

And I'd like to point out, in 30 years of my home network being online all the time (post dialup), I have had one system compromised. An OpenBSD box got rooted in the 90s.

HereIAmJH Silver badge

MS vs what?

I've come to believe that there is no safe option. Just systems where the exploits haven't been found yet. Even with open source there have been vulnerabilities found that were there for over a decade. Maybe in the future, after dedicated researchers and miscreants have used ever advancing AI scanners on everything, we might see something without critical flaws. But I doubt it.

So mitigate the risks and use what suits you.

Uncle Sam considers buying a seat on the Titanic

HereIAmJH Silver badge

Re: Please give Trump a ticket on the Titanic

And Vance has no control over the Republican party like Trump does.

The Republican party doesn't fear Vance.

Even with his low approval rating (36%?), and the economic train heading for a cliff at full speed, Trump still manages to primary Republican Congressman that speak out against him. Can Vance wield that power? I'm willing to roll the dice and bet he can't.

HereIAmJH Silver badge

Re: Sounds familiar

The US used to complain about China doing this. Now it is emulating China.

Correction. The US still complains about China doing this, and bans some companies because there is government ownership. TikTok, Huawei, etc. Then turns around and does the same thing. (Intel)

Ohio hits pause on datacenter tax breaks draining its coffers

HereIAmJH Silver badge

Re: That Max Shreck Moment

I'm looking at an 'island' system. And yes, you point out all the ways they screw you. You sell to them at wholesale, and they sell to you at time of use retail. Also, if the grid shuts down so does your solar. I intend to have grid service, but not have my solar connected to the grid. I don't want or need the power company meddling with my solar. And with the drop in battery costs, I'm looking at 24kw battery storage ($4200 and you can catch sales for 20% off or inverter included) to start with a goal of around 60-72kw. If you didn't build your system in the last year or so, you should go back and look at prices. Also note, I won't be using some solar company that charges more for labor than equipment.

The big issue is definitely the city codes department. Since what I want is not the standard grid tie that gives all the benefits to the energy corporations, it's not a familiar configuration. And they don't like that. But it's not a complete unknown, it just has to be framed correctly. Consider critical businesses. A local company that does funds transactions has a huge battery bank and backup generators. Same type of configuration it's just I'll replace the generators with solar panels. So I have a grid connection to satisfy city codes and the power company.

TBH, having seen some of the stuff that codes enforcement and city inspectors have approved, I don't have much respect for them. If they won't approve a non-grid connected solar system, then I'll quit making improvements on my property and start making arrangements to sell. I get daily texts offering to buy my house. It'll get bought by a flipper or a slum lord and turned into another rental.

HereIAmJH Silver badge

Re: There was very litte lost revenue.

I wouldn't downvote, but I do disagree. Are police and fire protection free? How about maintaining the roads to the facility? Then there is opportunity cost. If the 100 acres of woodland isn't being used for the DC, it could be used for something else. As an example, the Google DC just approved near me will use 500 acres and be located near the intersection of 2 major highways. It's in an area between a major metro and a growing smaller city. One of which will expand, without a doubt, in the next few years and want that land for residential or light industrial. So it's not as simple as "you already weren't getting taxes on that land".

HereIAmJH Silver badge

Re: That Max Shreck Moment

As the cost-per-unit of electricity eats and even bigger hole in the household budgets of people who are already taking a hammering.

Increased residential roof top solar will take at least some homeowners out of the circus. If I can get city approval, I'm looking to put my entire house on a critical loads panel powered by batteries. I'll use solar panels to provide the majority of my power requirements and my grid connection will only be for battery charging (load shifting), electric clothes dryer and stove. It requires a significant up-front cost. But for the average home it can be done for under $10k. Higher energy costs improves the ROI calculation.

Why is the US moving hell-for-leather to ship people out of the country, even American citizens?

Let's go back to 'Build the Wall' and birthright citizenship. What is becoming obvious is that they are attempting to turn the US into a gated community. Remove all the 'undesirables', then allow in people who can do necessary labor. If you look at it that way, how many of us currently live in a gated community? If you don't, you better be thinking about what benefit you provide that the super wealthy require.

HereIAmJH Silver badge

Re: A Datacenter is not a Warehouse

Surprise, it only takes a few jockeys looking for the red light that shows what burnt-out boards to swap.

They don't swap components anymore. If a server has a problem, they pull it out of the pool and it sits idle in the rack. Then at some point they come through and swap the server with a new one. Shipping and receiving requires more effort. But not much.

HereIAmJH Silver badge

Re: Bit Barn Palooza

They like to inflate the numbers with the construction workers, who are only there for a couple months. A fair amount of the construction is done off site too. They use precast exterior walls that they drop in with a crane and weld in place. Most of the jobs created are security. A couple techs to swap servers, and most likely all the building maintenance is contracted. We have a Meta 'billion dollar' datacenter, a $1b Google DC 20 miles away, and a proposed (approved) $10b Google DC near me. I notice the news articles don't even talk about job creation anymore. With Amazon we at least get their distribution centers with all the delivery drivers.

And to be fair, McDonalds probably provides more benefit to the community. They provide more jobs, services, and taxes. DCs are just holes in the property tax maps. At best they get locked in at the undeveloped tax assessment for 25 years.

Troops’ phones gave away location data to foreign adversaries

HereIAmJH Silver badge

How telcos know where you are

A useful link, take at look at PCMD. Now, if your sector is a 120*, your arc is 120* in the specified direction and 10 meters wide. From a single tower. Add data from a second tower and your location is the intersection of two arcs. Add a 3rd tower and you have about a 10 meter circle for your location. This data is always collected for device connections and is retained for a number of years. Unlike a GPS location request, which is an on-demand request.

HereIAmJH Silver badge

Re: re: no actual policy that requires servicemembers to turn off geolocation capabilities

No, it's not a power-saving feature of the transmitter. It's splitting the band so that the transmitter can carry more traffic. On a low traffic rural tower it might have an omni (360*). As traffic increases they upgrade to 180*, then 120*, or even 60*. With a sector antenna the only one that will see you is the one that is facing you. It doesn't care about your physical location (IE GPS coordinates). Note that the handset initiates the transmission, not the tower. All the tower does is reply on the same sector.

While your cell might be visible from more than one tower, it's unlikely to be visible from more than one sector from any given tower. (there are fringe areas where your signal might bleed over)

HereIAmJH Silver badge

Re: re: no actual policy that requires servicemembers to turn off geolocation capabilities

The location data that is being freely traded by the network operators is low definition, not GPS quality.

Bullshit. The carriers always know exactly where you are as long as your phone is turned on in their coverage area. First, turning off GPS turns it off for the apps, not necessarily the device. They need to know where you are if you dial 911. (in the US) And second, your phone connects to multiple towers and they can determine an exact location from triangulation. The data they sell is at best anonymized. They don't have the sophistication to fuzz the data first. If you doubt that, see how often their networks are penetrated.

I'm not aware of a standard mechanism that routes GPS info to a cell tower, that's device info that the cell tower doesn't need to function.

The tower doesn't care where you are, although it knows some info based on the sector antenna carrying your traffic. The carrier, OTOH, always wants to know your location and signal strength. They use it to determine network performance.

California passes bill declaring death-by-algorithm to 3D-printed ghost guns

HereIAmJH Silver badge

Simple solution. Require all printers sold in the state to be cloud enabled. To print anything you design it, slice it, send the g-code to the printer. The printer then sends it to a cloud service to be verified as legitimate. The cloud service sends back a yes or a no, and the printer then prints or aborts.

With that work, absolutely not. It will annoy legitimate users with false positives. It will be abused by people who want to stop competition or enforce copyrights, or hacked to steal IP for unreleased products. And the people printing ghost guns will do it offline with files traded on the dark web, paid for with crypto currency.

HereIAmJH Silver badge

Unless the rest of the US adopts similar legislation, ...

I give you:

3d Printer bills

California, Washington, New York, Colorado, Texas

And don't forget the US Congress wants to do 'something'. S.2165 would have restricted distribution of 3d printer files considered to be gun parts.

HereIAmJH Silver badge

Re: ridiculous

Just restrict ammo.

And brass. And gunpowder. And don't forget lead. So you can catch all those deviant reloaders out there. Maybe require an FFL to purchase primers.

Another option that I know won't be considered. How about mental health care. Or maybe limitations on divisive politics whose purpose is to keep the population fighting with various groups of minorities while they plunder the treasury and warmonger.

And I have to point out, I have NEVER used a 'splicer' that was included with ANY of the 3d printers that I have purchased. I have my preferred slicer software that supports all my printers. Maybe I should stock up on BigTreeTech controller boards for the next generation of 3d printers in case this follows the path of age verification legislation.

AI eyes scanning for bugs create a worrisome Linux security trend

HereIAmJH Silver badge

Re: LPE - it can be as bad as it gets

Do you run any user space programs with network access...

So now you're worried about running a trojan that could take advantage of an LPE? If you're running trojans, you have much bigger problems. Is it capturing your information when you log into your password manager? Encrypting your user files? How about when you execute sudo? Windows Firewall used to be annoying about allowing apps access to the network. I don't recall ever having Linux refuse network access to a user app in a general distribution.

HereIAmJH Silver badge

LPE

I know it's part of a quote, but "LPE (Linux privilege escalations)" is wrong. It's Local privilege escalations, and the difference is significant. A. it requires a local login account, and B. the classification isn't limited to Linux.

It's not handwaving time, "everyone on the Interwebs is going to pwn our servers!"

It's almost like we need to trust the people we allow to log into our systems.

Vivaldi 8 polishes the chrome without coating it in AI

HereIAmJH Silver badge

Re: The 'Zen theme'? I thought it was the AI bubble, rendered in pixels.

Vivaldi offers a free Proton VPN for your browsing. You'll need either a Vivaldi or Proton account to use it. It's just the Proton VPN Chrome extension that is installed automatically.

HereIAmJH Silver badge

Address bar completion?

Does it fix address bar completion? Like getting rid of urls that I clicked on within a page. If I'm typing in TheRegister.com, I don't want auto complete suggesting https://forums.theregister.com/forum/all/2026/05/21/202610/ at all, much less in place of an URL I have typed daily for months.

Address bar completion has been complained about for years. It seems no one has any idea which options to set to get it to work reliably. It changes from version to version but never actually gets fixed. It is the dumbest out of all the browsers I have worked with in the last 3 decades.

If you can't be bothered to fix it, at least write up a detailed tutorial explaining what each of the 'Address Field Suggestions' does, and verify they work as documented. I can't think of any feature or beautification project I want more than an address bar that works as expected.

Google accused of pushing 'free for life' G Suite users onto paid plans

HereIAmJH Silver badge

Re: gulp, gulp

You might check an email provider that will allow you to use your domain. It won't be free, but you won't be subject to Google's whims either. I have a free ProtonMail account. I'm considering upgrading to the $4 a month plan and letting them handle mail to my domain.

HereIAmJH Silver badge

Re: Lifetime

It goes hand in hand with 'unlimited'.

Windows boot partition runs out of space for Microsoft's May security update

HereIAmJH Silver badge

Another horror story. A Lenovo laptop with Win10 installed on SSD from the factory. Looking to upgrade it to Enterprise because it ignored WSUS and installed CoPilot. Add a second SSD and dual boot both Win10 Home and Win10 Enterprise, simple.... Except Lenovo used a SSD that requires drivers that aren't included in the Win10 installers. I now have EFI partitions on both SSDs, and OSes on both. But the new install can't see the old drive. If secure boot is on it will boot to the old OS. Turn it off and it goes to the new one. It seems that I have to install the driver DURING the Windows install process (or slip stream a custom ISO), and it fails to work to varying degrees.

I wish my ODBII diagnostic software that I use with GM had a Linux equivalent. I'd just install Linux. Instead I had to move the software temporarily to a different laptop that I was going to use to test Bazzite because it has an almost decent GPU.

Google'll grab your gigs if you don’t cough up your number

HereIAmJH Silver badge

Re: Fuck go ogle. And the horse they rode in on.

I also don't use it from home. If I need to update the app, I'll park in the library car park and borrow a cup of wi-fi since it's next to the post office if I'm not going into the library.

You are seriously paranoid. :-)

The point is that even Google requiring a gmail account is circumventable.

Gmail throwaway accounts are easy to get, and you don't have to use them for anything not related to the phone(s) in question.

HereIAmJH Silver badge

Re: Fuck go ogle. And the horse they rode in on.

The original reason was because Google went on a rampage deleting accounts of "people not using their real names" and my name is weird enough that I was worried it would happen to me.

Odd, I have a gmail account that is definitely not a 'real name'. It's a catch-all email address for one of my domains. I've had it for probably 15 years, but didn't use it much until they started playing games with the free Google Workspace.

And I thought everyone that had an Android phone used a Gmail account for it....

HereIAmJH Silver badge

Re: Could be worse I guess

Costco did this to me. I signed up as a new member, within a week I was getting several SPAMs from them per day. Their unsubscribe doesn't work, and I used every customer support route available to try to get them to stop. I quit using my membership before the second month was up and they'll never get another penny from me. Any mail from their domain is now automatically flagged as SPAM and I'm blocking costco.com in my DNS.

Now, Google has transferred my domain to GoDaddy and I'm starting to get the same shit from them. And the renewal went up 140%. They didn't do this years ago when I had hosting there, and this isn't going to get me to spend any money with them. I may be looking to move my domain in the fall if the SPAM doesn't stop.

Veteran network architect proposes IPv8 – to improve IPv4, not leapfrog v6

HereIAmJH Silver badge

Re: "No existing device, application, or network requires modification."

Seems like if you have an IPv4 device it will only be able to do an outbound connection with another IPv4 system. Unless you update it's protocol stack to support IPv8 DNS name resolution. Inbound though the gateway would handle all the translation (ala NAT). That seems problematic since most devices are end user (primarily outbound connections) and not servers.

HereIAmJH Silver badge

Zone Services

The other services are really meant for corporate gateways not so much for ISPs.

I was wondering about that, since so far I've only read the article and some comments. I'll still keep my systems separate from the Internet. Only systems I have put in a DMZ should be accessible to the world.

I don't really care who provides NTP, as long as it's a trusted source. I'll handle my own address assignment internally, static and DHCP. But some of us DO NOT want our ISP providing DNS services. They betrayed our trust by pushing ads instead host not found errors. And then collecting all the DNS request 'telemetry' to build info on their customers.

HereIAmJH Silver badge

I do like the idea of an IPvX that is backwards compatible with v4. I don't think its nearly as simple as this article makes out though.

Extending the IPv4 address space was discussed here a few months ago. Didn't seem too popular. It could be simple, or it could be complex if you tie a lot of new stuff to it. I haven't dug into this new spec yet. But something that seems concerning is using the ASN for the high order bit space. It seems like this could lock you into a network provider. While you could migrate to a new one, and wait for DNS propagation, it could get quite messy if the new provider has already allocated your number blocks. Unless your network provider could request a unique (and portable) ASN for you.

Linux kernel maintainers pitch emergency killswitch after CopyFail and Dirty Frag chaos

HereIAmJH Silver badge

Re: Sabotage?

Seems the problem isn't the vulnerabilities that got detected, but the appalling way they were advertised to the entire world, before patches could be rolled out.

The process is what it is because so many reported vulnerabilities were simply ignored. Companies didn't want to waste $$ chasing bugs in legacy code. OSes didn't want to admit that they had vulnerabilities. OSS devs that had other priorities. It had been the practice to report the bug to the owner, then wait a period of time before announcing to the world. But if your only option for reporting a vulnerability is to open a ticket on some public bug tracker that is possibly monitored by people who want to find new exploits, do you not report and hope no one else finds it, or use the tools available that make it public immediately?

BTW, note that the details of neither of the CopyFail or Dirty Frag were 'simply released'. They were reported, there was an embargo on releasing the details, and someone else released exploits. One was by looking at developer commits to fix the problem.

Also, both of these were LPE (Local Privilege Escalation). So rather than needing a kill switch, lock out non-admin local logins until it's patched.

GameStop CEO's eBay account reinstated following takeover PR stunt

HereIAmJH Silver badge

One possible synergy

One of the hassles of small seller selling on eBay is shipping. They want to compete better with Amazon. When I send something back to Amazon I just walk into one of their supporting retailers, hand them the product and a barcode and I'm done. No packaging, no shipping. GameStop needs something for their retail stores to do, or they are going to close a lot more of them. If I could walk into GameStop with an unpackaged item that I have sold, pay them a fee for shipping and tracking, and be done it would make me more likely to sell items there.

Although I do believe GameStop needs a way out of retail sales more than eBay needs a storefront. And despite eBay's roots being the second hand small seller, they're quite happy with the importer middle-man storefront business. So Gamestop really doesn't bring much to the table.

We've only gone and done it: Changed what you're used to

HereIAmJH Silver badge
Joke

On a bright note

This article has had more user engagement than anything except American politics. Traffic is traffic. YouTube would be proud.

Chrome silently installs a 4 GB local LLM on your computer

HereIAmJH Silver badge

If the choice is between local AI and non-local AI, then I think I prefer the local AI, thanks.

If you don't have control of the AI, it's not local. They are just letting you pay for the GPU, RAM, and electricity to run it.

By definition, an LLM installed without your permission or knowledge is not under your control.

Page: