* Posts by Peter 26

233 posts • joined 10 Nov 2010


SCO v. IBM settlement deal is done, but zombie case shuffles on elsewhere

Peter 26

Re: Am confused

But isn't this encouraging others to have a go as you can get a $14M payout for nothing?

Boffins propose Pretty Good Phone Privacy to end pretty invasive location data harvesting by telcos

Peter 26

Re: Won't happen

The purpose of this paper is to prove it's possible and show how to do it without changing hardware.

Making it happen is a job for someone else.

This paper moves the discussion one step forward beyond whether it's possible.

IBM's 18-month company-wide email system migration has been a disaster, sources say

Peter 26

Re: An impossible task

I agree with you, I loved Notes. Outlook annoys me to this day that it can't do the basics.

But the problem was familiarity, everyone knows Outlook, Notes was different, very different. If you had a technical inquisitive mind you'd learn to love it, but that was the very small minority of staff. Notes was a nuisance that got in the way from doing their job, another thing to learn...

Peter 26

An impossible task

I worked for IBM supporting Notes about 15 years ago.

Everyone hated it, 99.9% of the staff wanted to use Outlook because that's what they knew from their previous jobs, but technically Notes was better and had better features. There was so many features in Notes not in Outlook that I remember thinking, god help whoever has to migrate this in the future.

I would have just thrown my hands up in the air and said, we are not migrating this. Here's your new system, we will keep the old system as an archive read only for the next few years.

UK Court of Appeal rules Tiny Computers' legal remains can sue Micron and Infineon over 2002 DRAM price-fixing cartel

Peter 26

I'd forgot about the mass memory stealing around that time! It always made the Computer Weekly headlines.

It seems bizarre looking back that memory was the most expensive part of a PC with the mass production we have now.

Google's ex-boss tells the US it's time to take the gloves off on autonomous weapons

Peter 26

Re: Autonomous weapons need to be internationally banned.

Banning it should stop everyone doing it. While we are at it we should really look into an international agreement to ban recreational drugs too, we have enough ways to kill ourselves with bad health without taking chemicals for fun!

EncroChat hack case: RAM, bam... what? Data in transit is data at rest, rules UK Court of Appeal

Peter 26

Re: Wrong reasoning, right result.

I agree this is akin to planting a bug or a wire tap.

In other articles I've read about this they said they couldn't decode the signal if they had sniffed it in transmission, therefore this proves they didn't get the data in transit. I believe this is sound logic.

Police need to be able to investigate crimes, plant bugs etc. I have an issue with mass surveillance, but at an individual level getting a warrant to bug a specific person because you think they have committed a crime is what I think most people would agree should happen.

The bigger implications of this though is that they planted an updated firmware to EVERYONE who had one of these phones. This was mass surveillance by the backdoor. Maybe in this case it's true that the vast majority of people were using these phones for crime, but I'd like that to go to a judge beforehand to approve the mass surveillance, and I'd expect the bar of evidence to be extremely high before approving this. Plus instructions from the judge on destroying data of any non criminal behaviour captured for innocents caught up the in the mass trawl.

Then you have the issue of which country approves this... Should French courts be authorising hacking of other English citizens phones?

Cisco reveals critical bug in small biz VPN routers when half the world is stuck working at home

Peter 26

Re: "These vulnerabilities exist because HTTP requests are not properly validated."

I don't think I have seen any tutorials around this area in the last decade which don't cover this. It must be people reusing old code, or a proof of concept which ends up making it to the final product.

Windows Product Activation – or just how many numbers we could get a user to tell us down the telephone

Peter 26

I think almost everyone prefers to use an alternative to Office these days.

But there's always that one document you really need that isn't compatible with anything else.

Unauthorised RAC staffer harvested customer details then sold them to accident claims management company

Peter 26

Only 8 months suspended?

These cases are so hard to investigate and uncover it's disappointing an example is not made of the few actually caught and prosecuted.

US nuke agency hacked by suspected Russian SolarWinds spies, Microsoft also installed backdoor

Peter 26

Re: "full rebuild"

You've hit the nail on the head. The scale of this hack cannot be understated and it's going to be practically impossible to confirm you've eliminated all the backdoors into your network they have planted.

From now on you will just have to assume they have access and be constantly trying to find it. Probably not a bad approach to security anyway and a lot like our COVID safety protocols, just assume you have the virus and take precautions.

Cybersecurity giant FireEye says it was hacked by govt-backed spies who stole its crown-jewels hacking tools

Peter 26

Yes, you'd expect a more detailed response from a company like this. Clearly they have decided to hide that information, why? Is it embarrassing?

I am highly suspicious of claims of state sponsored actors being the culprits. It's the ideal excuse. Only the best of the best could beat us we are so great...

Where's your evidence that it was a state sponsored actor? Hmm you've decided not to provide that information, why?

My spidey sense is tingling.

Twitter hackers busted 2FA to access accounts and then reset user passwords

Peter 26

Re: insider trading

I doubt these were system admins, just 1st line support. They probably pretended to be their IT and got them to let them remotely login to their computers to fix something, including inputting any 2FA required.

There's no easy solution, more training on phishing calls, including internal phishing attempts to catch those who fall for them. Maybe a change in process so it requires more than one person to fall victim to make changes.

Health Sec Hancock says UK will use Apple-Google API for virus contact-tracing app after all (even though Apple were right rotters)

Peter 26

Re: I've said it before here on el Reg

FYI, I've been tested twice and got results 26 hours after first test and 18 hours the second time. I drove to the testing station rather than using the postal version. I was impressed with the speed of results.

The show Musk go on: Tesla defies Silicon Valley coronavirus lockdown order, keeps Fremont factory open

Peter 26

Re: Simple question

Every old person I have spoke to said it is an overreaction and they don't see themselves as high risk.

I think you summed it up though. Old people, ask yourself, would I call an ambulance and take up a bed if I was dieing from it? If yes, then self isolate and take it seriously.

Post Office burned £100m in UK taxpayer cash on Horizon IT scandal legal fees, MPs told

Peter 26

Re: "That doesn't make sense" ...

Maybe it was. Suspiciously we never heard back from them regarding that issue after my suggestion...

Peter 26

Re: "That doesn't make sense" ...

Back to the IT angle. I had a customer who had random files go missing on Windows Shares intermittently (breaking our software). I suggested they turn on windows auditing so we could see what/which account was deleting them. The MD replied, I will get my IT to do this and sack the person responsible once we find out who it is! I couldn't believe he was so quick to jump to thinking it was some employee doing it out of malice. In my mind I thought the most likely reason was some overzealous antivirus.

Amazon launches itself into retail IT with 'all the necessary technologies'. Not saying which, but you know...

Peter 26

Which businesses is this aimed at?

I really struggle to understand which businesses they are aiming at with this as it's only going to work for everyday convenience items. All the larger retail stores wouldn't touch it with a barge pole for obvious reasons, leaving only the little guy running a corner store. But everyone knows the corner shops main way of making profit is by not declaring all the cash they receive so they won't want all these digital records.

Maybe they are aiming it at the landlords of all the empty retail stores?

Now that's what I call a sticky situation: Repairability fiends open up Galaxy S20 Ultra 5G, find the remains of Shergar

Peter 26

Samsung Repair not that bad

The fact Samsung has its own repair centre's is actually a selling point for me. It's the only flagship phone manufacturer that provides genuine replacement batteries at a reasonable price. If you buy a 2nd hand battery anywhere else it will be fake and have nowhere near the storage capacity of a genuine one (you might as well have stuck with the dud one). I used to repair phones myself and gave up on genuine replacement batteries bought from third parties.

I recently had my Samsung S8+ battery replaced in the Kingston store for £50 all inclusive. It's made my phone like the day I bought it. Looks like I'll get another couple of years out of it now, which is quite clearly why other manufacturers don't want to sell replacement batteries.

If there's a bustle in your hedgerow, don't be alarmed now: Brexit tea towel says it'll just be the gigabit broadband

Peter 26

Re: Who needs Tea Towels when you can have Jack Boots?

Thanks for that link. I'm now a subscriber. It's good to read something honest and unbiased for a change.

Firefox now defaults to DNS-over-HTTPS for US netizens and some are dischuffed about this

Peter 26

Re: So what....

This is a really valid point. We don't think it's the case, but who's to say for sure?

Also, what if they have been issued a secret subpoena requiring them access to all the DNS logs?

Alternatively just targeting their network data which I've read can be fingerprinted to identify lookups. A massive project, but certain people have big pockets and by putting all your eggs in one basket it means they have less networks to target. Cloudflare/Google DNS being the main ones.

Anyway, 99.9999% of people don't know what DNS Sec is, so I think Fierfox have done the right thing for today. In a years time there might be a better option. If you're a techie you can change it in the options, if you aren't you would have no idea and noprotection anyway, so something is better than nothing.

Peter 26

Re: You can disable

How would that work? Surely it's hard coded to use In general you don't use DNS to look up a DNS server, although it theoretically would be possible in this case.

One man is standing up to Donald Trump's ban on US chip tech going to Huawei. That man... is Donald Trump

Peter 26

Re: I blame Rupert for this...

It's the reason the Republican party is what it is, and people are willing to vote for this criminal idiot.

It's clear Brexit happened because of tabloids blaming Europe for everything. We have started down this path, if we let them destroy the BBC we will be much further down the the same route as the US.

Microsoft boffin inadvertently highlights .NET image woes by running C# on Windows 3.11

Peter 26

Re: "Visual Studio is a paid-for product"

"If Microsoft want more developers using C#, they need to drop their enterprise-style pricing and make Visual Studio much more attractive. I know that there's a Community Edition, but the cost of the jump from free to non-free is incredibly high, it's no wonder everyone just goes off and uses something else..."

It's the same as travelling in business class. Way too expensive, but you don't care as you're not the one paying it.

Peter 26

I love .NET

I love .NET, it's so easy to use, the IDE is great, all the libraries are fantastic. It links to everything. If you have an issue a quick google finds an answer.

But then I am over 40 years old... The stereotype seems spot on.

Crown Prince of Saudi Arabia accused of hacking Jeff Bezos' phone with malware-laden WhatsApp message

Peter 26

Time for the super rich to fund security research?

I'd like to see the super rich like Bezos fund security research into anything they use day to day. We'd all benefit from it if he had a team looking into WhatsApp security finding bugs and alerting WhatsApp. Apparently this breach cost him his marriage and a $38 billion settlement with his wife, whatever it costs it's going to be a drop in the ocean compared to that.

FYI: FBI raiding NSA's global wiretap database to probe US peeps is probably illegal, unconstitutional, court says

Peter 26

Re: Checks and balances essential

I definitely think Trump Tower is fishy, but just to play devils advocate this does happen with bigger constructions.

Here's an example. WWF UK Headquarters (The panda one, not wrestling!) WWF knew they needed a new site for their head quarters in the UK, they asked around the different councils to see who would subsidise their new building the most. Woking won by offering to pay for the building for them, in return they got the prestige of having WWF UK Headquarters in Woking putting them on the map, and presumably more jobs... You can argue whether that was a good deal, but it shows that it makes sense to get the subsidies in place first before deciding on location. Even on a smaller scale when doing a house extension, you first sort out with the bank how much money you've got before you start the plans and construction.

This vBulletin vBug is vBad: Zero-day exploit lets miscreants hijack vulnerable web forums

Peter 26

I don't think this classifies as a vulnerability, this is a feature which allows you to run a command on the server from the client. I don't see any way this could be accidental, it's bizarre. It's either a deliberate backdoor or some development code that got into release by accident? The development code part doesn't make any sense either though, why would anyone add remote code execution into a development build?

Capital One 'hacker' hit with fresh charges: She burgled 30 other AWS-hosted orgs, Feds claim

Peter 26

I find it interesting how people can be clearly smart, but also equally stupid at the same time.

Talk about unintended consequences: GDPR is an identity thief's dream ticket to Europeans' data

Peter 26

A solution?

Perhaps snail mail with a code, then a visit to an approved ID checker, such as a bank or post office with that code.

There's an opportunity here for someone to set this service up and sign up the ID checkers and the companies who want to prove identity.

Although this just proves a person is who they say they are, not that they own that particular login name, so it's only part of the puzzle.

Peter 26

It is GDPR's fault. The reason GDPR exists is because we know most companies have piss poor data protection controls. Therefore in the design of it they need to force companies to ensure they protect our personal data. Let's hope they add protocols that have to be followed into GDPR v2.

In the mean time this is great news for companies, they now have an excuse not to deal with GDPR requests, let them get stuck in the red tape of proving who they are.

Get ready for a literal waiting list for European IPv4 addresses. And no jumping the line

Peter 26

Re: We need a new approach

Absolutely agree. I think a big issue with IPv6 is that it may be better on paper, but the human element hasn't been given enough weight. We have all grown up with IPv4 and on the surface it's pretty simple, people are lazy and don't like something that different and looks complicated.

Was this quake AI a little too artificial? Nature-published research accused of boosting accuracy by mixing training, testing data

Peter 26

Raj's response to authors response

I'd like to see a response from Raj about the authors comments. Can he explain why they are wrong?

“The network is mapping modeled stress changes to aftershocks, and this mapping will be entirely different for the example in the training data set and the example in the testing data sets, although they overlap geographically," the pair said.

"There’s no information in the training data set that would help the network before well on the testing data set - instead, the network is being asked in the testing data set to explain the same aftershocks that it has seen in the training data set, but with a different mainshocks. If anything, this would hurt [the] performance on the testing data set,” DeVries and Meade, wrote back to Shah.

When 2FA means sweet FA privacy: Facebook admits it slurps mobe numbers for more than just profile security

Peter 26

Re: Google too

Can anyone recommend a cheap burner SIM? They all seem to start at £10 minimum topup. A bit much to create anonymous accounts.

Ah, this military GPS system looks shoddy but expensive. Shall we try to break it?

Peter 26

yeah totally, I thought they were going to reveal what crap was inside.

You got a smart speaker but you're worried about privacy. First off, why'd you buy one? Secondly, check out Project Alias

Peter 26

Re: you could simply not put the creepy things in your home

The remote server is required for the quality voice recognition.

I helped catch Silk Road boss Ross Ulbricht: Undercover agent tells all

Peter 26

More Questions

That was a really good read. I have more questions.

How did they find the server in Iceland using the admins account? What was the security failure here, surely there was an encrypted reverse proxy?

How did they find connections from San Francisco to the server? Wasn't he using a VPN?

Customers baffled as Citrix forces password changes for document-slinging Sharefile outfit

Peter 26

2FA Fail

I'm all for increased security, so I went to their website, changed my password to a random generated one (I have no idea what it is) and saved it in my password manager Blur. Then I went to see if they had a 2FA option. There is yay! But only via sms/phone call, boo! But wait, after enabling SMS 2FA, I can then enable a backup 2FA via an Authenticator App, but you cannot remove the SMS 2FA.

I signed in on my mobile and it sent me an SMS rather than using the authenticator app.

They are nearly there, but they need to push to use the authenticator app as the first choice and give the option to remove SMS as 2FA (in fact encourage it), sim swapping is incredibly easy to do, use of it to take over accounts has exploded recently. SMS 2FA cannot be trusted anymore.

I've removed SMS 2FA from my google account, name cheap and anywhere else that gives me the option.

Sharefile is probably the most important account I have, I use it to transfer customer data. That thing needs to be secure. They should up their game with regards to 2FA.

LastPass? More like lost pass. Or where the fsck has it gone pass. Five-hour outage drives netizens bonkers

Peter 26

Re: Keepass

I can't get over the fact you have to manually copy the password file to your device. I get that it's more secure, but it sounds really annoying. What if you sign up on your PC to a service then want to login with the accompanying app on your phone? You have to copy the file first.

Just seems like a lot of hassle, last pass sounds like a good compromise on security/ease of use unless I am missing something.

Azure, Office 365 go super-secure: Multi-factor auth borked in Europe, Asia, USA

Peter 26


I was thinking this morning how awful it was that people couldn't get to work because the Waterloo line was shut, and how lucky I am to work from home and not be affected...

Peter 26

Re: I'm locked out of my account for work

Haha, I cleaned the Kitchen Skylight, been meaning to do that for months..

Still locked out, what next...

Just because you're paranoid doesn't mean hackers won't nuke your employer into the ground tomorrow

Peter 26

Re: Paranoid

You're just paranoid until it happens. Do you cover your house in CCTV and alarms, or do you wait to be burgled before installing them?

Getting secure in IT is just such a ball ache. It requires an incredible amount of work, for something that might never happen. Personally I try to do half of it, but I'd be screwed if targeted.

Cancelled in Crawley? At least your train has free Wi-Fi now, right?

Peter 26

Time to dream up solutions

I turn off WiFi on the train as it is next to useless. With my free time I dream up personal windows suction mounted antennas, tethered to your phone somehow that you can use to boost your signal. I have yet to figure out the details on how that would actually work. Maybe I need another train journey to continue the dream.

Namecheap users rage at domain transfer pain, but their supplier Enom blames... er, GDPR?

Peter 26

Re: The clue is in the name

When I looked into registrars a couple of years ago, everyone seemed to say they were the best. They were one of the first to implement 2FA which was one of the reasons I moved to them from GoDaddy.

I haven't any issues, but would be interesting to see what Google's Service is like.

CEO insisted his email was on server that had been offline for years

Peter 26

Re: Deleting emails

I am that hoarder, but it's not because I want every email, it's just that I can't be bothered to sort them out. I have two types of email, read one and unread ones.

I am thinking I should really delete all my work ones (>10 years) as I was once told at an Oil & Gas firm that we should delete everything after 3 years of the project ending so that our own email records couldn't be used to sue us in the future.

uTorrent file-swappers urged to upgrade after PC hijack flaws fixed

Peter 26

Better alternatives

I switched to qBitorrent (qBit) yesterday after reading recommendations on reddit. I was a bit reluctant as there has been so many features added to utorrent that other torrent programs didn't have such as the remote downloading, automatic seed ending, move completed downloads to another folder. But it turns out qBit has all the same features as far as I can see except the annoying adverts. It looks a lot like utorrent did before it went ad crazy. I should have switched ages ago.

Combined with Transdroid on your android phone for remote downloading and torrent searching, it's a perfect combination.

Use ad blockers? Mine some Monero to get access to news, says US site

Peter 26

Re: Just Visiting

I'm just running ublock origin and am not getting any notifications about this. 31 Ads blocked though.

The e-waste warrior, 28,000 copied Windows restore discs, and a fight to stay out of jail

Peter 26

He even admitted he was stupid to put the logos on the CD. He should be convicted as he technically committed the crime, but it should be taken into account that there is zero cost to Microsoft from doing this, he copied something which can be obtained for free and he gains very little from this copyright infringement himself (there is some as people are more likely to buy the old PC if it comes with a legitimate looking restore disc)

There shouldn't be any prison sentence, make him destroy the discs, give him a small fine at worst.

GitHub shrugs off drone maker DJI's crypto key DMCA takedown effort

Peter 26

Re: one experience ...

MSDN license? You get enough free credits each month to do quite a bit. I've got a couple of servers running at the moment free of charge for testing.

Brit transport pundit Christian Wolmar on why the driverless car is on a 'road to nowhere'

Peter 26

He's right about all the issues, but sometimes you need to disengage your brain to succeed

Although he gives a good reality check, I think there is a lot of innovation that come come out of this, so it is a worthwhile exercise. The tech companies have money to burn like he says, so they might as well put it into something like this.

Some of my greatest successes have been when I started something that I had no idea how complicated it would actually be thankfully, otherwise I never would have started.



Biting the hand that feeds IT © 1998–2021