The Register Home Page

* Posts by Richard Cranium

238 publicly visible posts • joined 8 Sep 2011

Page:

Spy agency GCHQ told me Gmail's more secure than Microsoft 365, insists British MP as facepalming security bods tell him to zip it

Richard Cranium

email is fundamentally flawed

The problem is that when Ray Tomlinson sat down half a century ago to create the basis of the email system we see today, it was an unofficial side-project to facilitate communication between a somewhat limited group of largely techies.

Anyone intending to design a global email system today supporting 4 billion accounts would make some very different decisions.

The problem we have now is that there are so many mail servers that it's far too late to change. The NCSC estimated 7,000 microsoft servers in the UK alone had been affected by the Hafnium email hack, despite the widespread publicity, several days later only half had implemented the patches). The slow adoption of approaches like SPF & DKIM are examples of the difficulty of implementing change however worthwhile that change may be.

A floppy filled with software worth thousands of francs: Techie can't take it, customs won't keep it. What to do?

Richard Cranium

Re: A Cunning Plan

Maybe you were thinking of Viewdata?

Or Prestel or was that the same thing?

Yep, you're totally unique: That one very special user and their very special problem

Richard Cranium

Re: Where’s the effing handbrake!?

"My first (and so far only) hire car in the USA was not only the first automatic transmission car I had driven..."

Me too and do you know what else? The silly buggers had stuck all the controls in front of the passenger seat, I ended up having to sit on the left to control the damn thing. I understand the same happens in France but I'd expect that kind of contrariness from them.

UK draft legislation enshrines the right to repair in law – but don't expect your mobile to suddenly be any easier to fix

Richard Cranium

What about batteries?

OK not white-goods but many smaller electricals use rechargeable batteries with a limited life. I've just binned a decent battery drill because the battery pack has died and replacements are no longer available. I took the battery pack to bits to see if it was just a cluster of something like 18650s but no, proprietary. I also have a collection of other stuff, mobile phones, digital cameras, satnav, dashcam, multimeter, kitchen scales etc with dead, non-standard batteries and no manufacturer replacements available.

A lot of this stuff has a 3-5 year life expectancy as a consequence.

On the other hand my RadioShack EC4075 programmers calculator (using 2xAA cells that last several years) is still perfectly fine after over 40 years regular use.

Lets see some standards for battery electricals:

Standard cells or if they must be proprietary then consumer replaceable (or at least by third party repairers) not glued in and spares available for 10 years. BTW another issue is that I was able to get replacement party batteries for a digital camera but I guess they were old stock (or counterfeit) with much lower effective capacity than new.

Splunk junks 'hanging' processes, suggests you don't 'hit' a key: More peaceful words now preferred in docs

Richard Cranium

Are Splunk trying to adopt the status of the Académie française in respect of English?

Well they can f***-off and stick to their line of business.

Wouldn't it be useful if the resource they've wasted in this attempt to redefine how the English language should be used went instead into doing something productive.

As for the hundreds who have contributed their valuable time and intellectual efforts to this forum thread - lets forget the losers at Splunk trying to tell us how to use OUR language and go do something useful instead.

Do we want to end up with an English equivalent of the Académie française? If we do, should that role be in the hands of a commercial organisation? In any case it will be an ineffective laughing-stock just as the Académie française has become.

English is fluid, continually evolving. That is its strength. Where there's a need it will adapt whether that be by adopting a word from another language, coining a new one or expanding the scope of an existing word. That's why English is effectively the global language, perhaps not the largest first language but adding speakers for whom English is a second language, it is by far the most widely used. And that's to disregard those who may not have the confidence to speak English but can read English, understand spoken English and possibly write in English. It is the common language the educated classes everywhere and the de-facto language of science, business and navigation.

Where any two persons get together whose first languages differ, how do they communicate? As often as not, in English.

Seagate UK customer stung by VAT on replacement drive shipped via the Netherlands

Richard Cranium

Profiteering

I've experienced problems with imports (from other places) before. In both cases the fee payable was substantially less that those in recent press reports some of which have been substantially more than this seagate example. Someone is making a killing from this, I wonder how the charges differ between parcel delivery companies.

My 2 examples:

As a prize for "Comment of the week" on a forum. I found I'd won a Tee shirt. It came from the USA and was declared at $15 but HM customs looked the product up online and found it retailed for more than that. I had to go to the post-office to collect and pay £18.

A friend in Japan sent us a gift (silk kimonos she'd made herself) and declared a value of $200. Post office got in touch to say they needed £70, as we weren't expecting anything and didn't know who it was from we debated whether we wanted to spend £70 for a "mystery parcel" or let them return it. Luckily we chose to pay, and, as it turned out to be "legitimate", the sender would have been offended had it been returned, it might seem to her that WE had rejected it.

For the time being I think the best advice is: avoid sending parcels between UK and EU if at all possible.

You want me to do WHAT in that prepaid envelope?

Richard Cranium

I read the story without looking at the author's name but was soon able to guess (didn't AD write for some of the early computer mags - remember those printed paper things we used to rely on before the internet).

Anyway as an oldster I can confirm the the process has improved, the earlier little wooden strips to place samples under little cardboard windows on 3 consecutive days (like a kind of reverse advent calendar - each day fill a window with shit, close it and post it to someone), were a real pain in the ... (how appropriate) calling for a major clean up of one's person and of the "bathroom environment".

I advise against sending shit through the post in any other circumstance, it can cause offence.

The NHS has a series of gifts in store for you as you age, the pleasant one comes next when the pharmacist told me to put my money away, I'd become so old I didn't need to pay for prescriptions. And then (men only) there's the Abdominal aortic aneurysm screening.

Any bloke over 45 should be thinking about asking the GP for an occasional Digital rectal examination if there are any of the early signs of prostate problems. Some GPs aren't very keen as the "digital" bit is not in the high-tech sense you might first consider, this being an IT forum (it involves a rubber glove) but my view is that they get paid a lot more than me and I used to metaphorically "shovel shit" in an IT sense (for HSBC) so make them earn it.

On to the other topic of the article: ergonomic everything. Over 20 years ago my wife bought a Microsoft ergonomic keyboard. After a few months the letters were wearing off the keys so she complained. The complaint was not acknowledged in any way except one, a carton of about 10 more keyboards arrived unannounced. They weren't UK standard but a version with some accented letters, still QUERTY and quite useable, just minor quirks like the @ sign not in the usual place. As a "proper" typist she considered the keyboard more comfortable but as a two finger typist I found it less so. They kept us, friends and family, in keyboards for many years.

LastPass to limit fans of free password manager to one device type only – computer or mobile – from next month

Richard Cranium

Re: moving on

Same story. I don't have a problem with paying a reasonable amount for decent software (I even pay for good apps where payment is a voluntary donation like IrfanView).

IIRC LastPass used to have a one-device limit and I used to pay to use on mobile as well as laptop. Then they removed that limitation on the free version but increased the price on the paid version which I no longer needed now the free version did what I need. As a home user the price is now too high for multi-device so I'll have to move. How odd. If they'd kept things as they were a few years ago I'd continue with Lastpass and pay a reasonable amount.

Isn't it the same people that pigged off LogMeIn users a few years ago?

Faced with the sack, Nominet CEO half-apologizes for taking the 'wrong tone,' asks angry members to hear him out

Richard Cranium

Re: Dont Count your chickens

"some of their customers may decide enough is enough and switch to another"

IMHO very doubtful.

I assume many registrants only hold a handful of names, most probably just one or two. They are probably not aware of this issue and may not have the technical nous or financial incentive to shift if they do.

Imagine a micro-business has not just paid over the odds for registration and "Domain Ownership Protection" (£24 combined) through 123reg but have also signed up to their email and hosting deals. Moving will be a major PITA just to register dissatisfaction with some guy at an organisation they are barely aware of.

I'm happy to place a substantial bet that Haworth will find a way to incentivise a small number of those with large voting influence to vote down the proposal to replace him.

Terraria dev cancels Stadia port after Google disabled his email account for three weeks

Richard Cranium

Paid Gmail accounts

Any better or can they cut you off with no warning and no reason given too?

Nominet boardroom battle may already be over as campaign to oust management hits critical milestone

Richard Cranium

publicbenefit.uk has a list of those in support of change, 8 of them have fewer than 20 names which seems an odd choice from a simple cost-benefit viewpoint. Are there additional factors involved?

One is voting rights. Even the guy with no domains gets an entitlement to 1331 votes but is it worth paying £100 a year for some voting rights? (Or paying a £400 joining fee and to join now to get some votes).

Given past evidence of having been to the Trump school of management (e.g. the past statement that "The Register is Fake news") what else can they get from the Trump playbook? Fiddle the figures by spending £40k to create 80 new members and so score 100,000 extra votes? Or keep it simple by fiddling the way votes are counted, claim some votes are not valid, or just disregard the result ("Stop the steal!"). If I was getting £500k a year I'd go to some lengths to keep it coming...

Richard Cranium

"What can be done to encourage members to vote for change"

Registrants could "vote with their wallets" and move domains away from member organisations who are not in support of change to those who are (partial lists of both can be found here https://publicbenefit.uk/). That's a load of hassle, not much can be done in the short time available before the vote and many registrants won't know there is a dispute or if they do won't care/understand.

Better is to try to understand the reasons why some are not supporting change and see if anything can be done to identify flaws in their reasoning. Presumably it's fear that changes under new leadership will be detrimental to their interests. In what way? Can those fears be allayed?

Richard Cranium

...more than 20...

I've got over 100 under my management so this attracted my attention - however firstly break even on 20 names would take a while, especially as it seems to be predicated on an assumed retail price of £10 (I'm paying rather less) but also I assume a need for software to manage the names.

Dems to ISPs: You're not gonna hike broadband prices, slap restrictions on folks in a pandemic, are you?

Richard Cranium

Yes I'm not happy with Virgin Media continual price hikes.

My Virgin Media price hike is only £3.50 (on a base package cost of £74.56 for phone, cable broadband 200Mbit, and a TV bundle) so I'm seeing an increase of 4.6%, more than ten times the UK inflation rate (December CPI 0.3%)

And it's difficult to get them to cut the cost. They'd charge about £20 a month for landline, I'm in the process of seeing if I can switch the landline number to Sipgate (and then forward calls to mobile) so will Virgin knock £20 off my bill - no because its a package, I can have a different package at a zero cost saving... Same applies if I drop some of the TV channels, the stuff that comes down the TV aerial is more than enough.

Our road has recently got BT Fibre (FTTP), I'd consider a swap but they're a bunch of [expletives deleted] too, they'd charge about £60 a month for a comparable bundle (inc phone as VOIP, TV entertainment bundle and 300Mbit ) so it looks like a £200p.a. saving

Brexit freezes 81,000 UK-registered .eu domains – and you've all got three months to get them back

Richard Cranium

Mismanaged from day one

One might even suggest, fraudulently.

I tried to buy the EU equivalent of my long established uk Ltd company name when the tld was first set up in the "sunrise" period (when names were only available to those with a reasonable claim on them) . That involved some red tape, proof of company ownership/registration and a non-refundable £100. No response until a few days after the landrush period (lower price and no need to prove Ltd company entitlement). That was to say my application was rejected, no reason given.

A third party had bought the name at the start of the landrush. It was not an obvious name and of very limited use to anyone else. Eventually a website appeared, host to a load of dubious advertising links and "for sale". I found another business who had the same experience. The inference one might draw was that perhaps by applying we had indicated that the names had a value so someone involved in the administration delayed the process in order to grab the names at the start of the landrush phase with a view to resell for a much greater price. But I must be mistaken as I'm sure EUrid is a model of the highest standards of integrity.

A lucky escape, and in any case it turns out the EU tld is little used beyond the EU organisation, more like an equivalent of Gov.uk domains.

As Uncle Sam continues to clamp down on Big Tech, Apple pelted with more and more complaints from third-party App Store devs

Richard Cranium

"If you don't like that, don't buy an Apple phone"

Most of the world agrees with that advice:

iPhone _global_ market share is under 15% even its biggest market, USA, it only reaches about 50%

As a coder, reading the T&C as well as tech news like The Register it's clear that your choice is invest many months effort, hope Apple accept the app for their store and then reap the reward of paying a third of your income to them - if the app is a success.

As an iUser, understand that you are paying a significant premium on all your apps to compensate the developer for the 30% cut, development costs and risk of rejection by Appstore.

You've got to be shipping me: KatherineRyan.co.uk suggests the comedian has diversified into freight forwarding

Richard Cranium

Why redirect there?

It could be a strategy to make it harder to dispute ownership because it's not being used to Katherine's detriment, like hosting derogatory content about her or masquerading as her official site.

If the name was pointed at a page saying "name for sale" it might be possible to argue that the registration was vexatious. GDPR has meant that the registrant's contact details are no longer "public", it's not supposed to be possible to find out who the owner is. That does make me wonder how The Register has a trail of recent owners.

This is what Nominet say about domain expiry:

"Once you’ve gone over your expiry date, you’ll still have time to renew your domain before it gets cancelled, so there’s no need to panic. But if we don’t receive a renewal request within 30 days of the expiry date, we’ll suspend the domain name. This means all services that use that domain name, such as your website and email, will stop working. We’ll send you a suspension warning seven days before this happens, and will also send you a suspension notice when it takes place, unless your registrar has opted you out of receiving these. It’s still possible to renew your domain during this time.

When your domain has been suspended for 60 days without being renewed, we’ll schedule it for cancellation. We’ll send you one final reminder to renew your domain 83 days after the expiry date. As this is just seven days before your domain is scheduled for cancellation, you’ll have to act quickly if you wish to renew it at this last stage."

The way I read that, there's a 30 day period of grace then 60 days of suspension i.e. the address will not link to the web-site or email so it must have been unavailable but nobody (including katherine) noticed between 17 Sept and 17 Nov. (or did notice but didn't take appropriate action) so losing the name is no big deal, there are plenty of suitable variants.

If the friend's ex- was proving uncooperative during that 60 day period Nominet could probably transfer control even if the registrant name was "friends ex" (I needed to do something similar a couple of times and it worked).

In terms of traffic redirection, I guess search engines will have been getting an error for 60 days and either removed the name or allocated it much lower position in results so little value to the new owner - at least until there's news coverage like this so everyone goes to take a look...

Who knew that hosing a table with copious amounts of cubic metres would trip adult filters?

Richard Cranium

Re: Funny placenames

There's a nice map of the UK with a focus on "unusual" place names:

https://shop.ordnancesurvey.co.uk/st-gs-marvellous-map-of-great-british-place-names-folded-poster-or-framed/

A freshly formed English council waves £18m at UK tech industry, asks: Can somebody design and run pretty much everything for us?

Richard Cranium

Re: Simples

After deducting her pay there'd not be much left from the £18m - but that's OK, it can all be done on an obsolete version of Excel.

Apple's at it again: Things go pear-shaped for meal planner app after iGiant opposes logo

Richard Cranium

"People who don't like that should push credible trademark reforms to their elected representative, instead of the pointless "signing" of online petitions."

Yes in a few more decades the elected representatives might act. Which side do you think Trump would take? Big businesses (i.e. political donors with deep pockets) or small?

Trade marks and patents were introduced to protect the small guy, they've been turned around to become the tools the strong use against the weak. An individual innovator or small business can't afford the cost of trade marks or patents but has to assume designs will be ripped off. The only choice is to try to stay ahead by innovation - or just don't bother in the first place, you're on a hiding to nowhere. That's where the real economic damage arises, a chilling effect on innovation. The problem patents were intended to fix has become an obstacle to innovation.

The global acceptance of the concepts of trade mark/patent/copyright makes it very difficult for any one nation to fix that - so which legislators anyway?

I agree that signing petitions *alone* is of very little value so if you mean it do something positive too. Vote with your wallet; donate to the legal fund; buy better cheaper IT hardware/software from more ethical businesses; ensure all your purchases and investments are in ethical businesses (and check the criteria used to define "ethical" are in line with your interpretation).

Geneticists throw hands in the air, change gene naming rules to finally stop Microsoft Excel eating their data

Richard Cranium

Excel is a problem but so is the CSV format

There is an RFC but it's not really a standard.

I have a regular task to import a very odd "csv" file to a MySQL database. My solution is some task-specific code. The generalised problem, for which I've only found one possible "one size fits all" conversion program (in Python & not tried it) is: identify the peculiarities of the incoming file, identify the requirements of the destination app, do the conversion.

It may be possible to write a file parser to identify the characteristics of the input file but the user would need to enter the requirements of the destination app.

My specific task, the incoming file uses tilde as field separator ("comma" equivalent) tilde being unlikely to appear in the data, then a mix of quoted and unquoted fields which may include quotes, commas, apostrophes, tabs, escape characters and a load of other "surprise" characters.

I read that 20% of a large body of scientific papers on genomics included CSV data that would be misinterpreted by excel

Nominet shakes up system for expiring .uk domains, just happens to choose one that will make it £millions. Again

Richard Cranium

Re: From the 'consultation'

The flaw with the system of notifying registrants is that it relies solely on email although nominet hold postal and phone contacts. A client of mine lost a valuable domain name because she'd changed her email address and hadn't updated Nominet. It was a secondary name held to protect a trademarked product name not the primary one used for her web site so the period for which it was not functioning went unnoticed.

One map to rule them all: UK's Ordnance Survey rolls out its Data Hub and the juicy API goodness that lies therein

Richard Cranium

Navigation

Eratosthenes proposed a global coordinate system 2300 years ago, that was flawed but in the next few centuries it evolved into the Latitude & Longitude system much as it exists today after ongoing important refinements like moving the prime meridian to its rightful place ;-)

All the other systems are inferior and only cause to confuse. They do have niche applications but are there really any "better" than Latitude & Longitude?. My mapping app gives locations to a very high level of numeric detail, W 0.12456246 N 51.500661 but it's fine to do some rounding so W 0.1246 N 51.501 gets me on the other side of the road to my intended destination, I think I should be able to spot the Houses of Parliament clock tower from there.

The issue I have is not postal addresses but getting people to meet up at a specified location to go for a walk in the countryside.

In one instance I provided a screen-grab of OS map and Google map, turn by turn directions, UK NGR and Latitude/Longitude coordinates, all carefully double checked and taking them to a parking spot on a minor road. Two of a group of ten didn't turn up, they were a mile away on a main road.

W3W is one of those things that sounds like a good idea until you think it through as discussed above. Useless for me because too few people have heard of it and far fewer have the app. I deleted it.

Distressingly few people understand UK national grid references, some seem to be unaware the the two letters are relevant and will omit them. (And of course they are UK only).

Most sat-navs sold in UK understand UK postcodes as do users but they are hopeless in areas of low population.

I understand some UK sat-navs can take UK NGR (mine can't)

I think most satnavs can take Latitude/Longitude coordinates but that option may be deeply buried and many users seem not to understand or are afraid to use Latitude/Longitude. A friend with a BMW proprietary built in satnav is adamant he can't use Latitude/Longitude (but then he's got a hand-held Garmin GPS device he cant work out how to use either).

Mobile phone navigation apps vary in their location specification requirements.

With dedicated GPS devices Latitude/Longitude coordinates are usually fine except for the variations in how those coordinates are specified. Is it 10 degrees West or 350 degrees or -10 degrees? It is degrees, minutes, seconds or decimal, Is it UGM WTS 84 International or UTM WGS 84 NMEA. And although those devices may have good quality maps, they don't work like satnavs providing turn by turn navigation (sending a GPX route file would be an option if the recipients knew what to do with it.

Apple: We're defending your privacy by nixing 16 browser APIs. Rivals: You mean defending your bottom line

Richard Cranium

Re: Safari

True and there are other ways to check a web site is OK in safari without paying the apple tax (like ask a friend who has an apple).

I now take the view that it's not my job but that of the browser authors to ensure that any well coded W3C standards compliant web site functions on their platform. If it works on all the main browsers but not yours, that's a bug in your software not in my web coding.

Richard Cranium

Re: Safari

If it's so great, why did they kill-off the version that runs on other platforms? I used to test my websites on multiple browsers including Safari (on Windows) but I'm buggered if I'm going to buy an apple device just to be able to check whether a web site is OK on Safari.

Whose side you on, Nominet? Registry floods .co.uk owners with begging emails to renew unwanted .uk domains

Richard Cranium

Re: I used to pay...

FWIW I'm paying £6 inc VAT for uk names at purely.domains, while I grumble at that (mostly at the slice Nominet take for doing bugger all other than run a database rather badly and pay themselves very generously), at least it's less than .com (I get those for under £10 somewhere else).

My advice to clients in respect of .uk is:

If it's the equivalent of the .co.uk name you use, keep it

If the .co.uk name is just held defensively (i.e. not used for anything, web, email or other) then consider how valuable that name is and consider dropping that and the .uk

When I say "consider how valuable" best names are short, no hyphens, single word, dictionary word, noun.

So I'm finding names like mikes-dodgy-second-hand-motors.co.uk and the .uk equivalent both being dropped, especially where the client bought loads of variants defensively years ago. The risk of abusive registrations seems to be far less than people thought 20 years ago.

On the other hand some just take the attitude that it's only a few quid...

I also advise not to use the .uk variant at all, just leave it parked with the registrar, keeping it solely to prevent anyone else buying it. If it gets "known" then if you decide to cancel in years to come then you risk your customers seeing a dead link or rejected email and may decide you've gone bust. But also I think most people recognise .co.uk as "legitimate" and may be unsure of .uk

Best thing Nominet could (should) do is charge a nominal amount for the variant if the client owns both.

The other thing Nominet could do to increase the value of .uk is very actively police registrations with strict T&C as to usage and limit ownership to genuine UK organisations (or persons). IIRC The Register recently reported bulk buying of lapsed .uk names by overseas speculators.

Nominet have the registry as a gift of the UK government, it's time government demanded better or put uk name management out to tender.

Namesco email 'scripting error' has last bastion of Demon Internet holdouts scratching their heads

Richard Cranium

Having helped a friend go through the palaver to set up the switch to the temporary email service I'd not be surprised if a lot of former demon customers gave up.

As for the name, in the early days of internet my business used Demon email. One potential client (with strong connections to a church) declined our proposal on the grounds that he didn't want any association with the word. (We revised the proposal using a different email service to comply and he's still a customer 25 years later).

Remember April 2020? It brought pandemic, chaos and an unseasonable spike in new domain registrations

Richard Cranium

Move on, nothing to see here...

Yes, a bit of a non-story. Looks to me like there was a significant drop in new UK registrations in March, ~ 17,000 perhaps people had something else on their minds? March was the anomalous number then April was catch-up time with ~32,000, just 3000 more than Jan ~29,000

As for AC mention of the Namesco demon changeover. I helped a client through the nightmare to configure the "interim" solution in 2016 but at the same time set him up with a Gmail account and added a forwarder so mail to my.client@his-domain-name.co.uk went to both the old demon address and to gmail so when "interim" comes to an end it will no longer matter. In addition, there have been a couple of articles on The Register recently (15/5 and 30/5) referencing the demise of the Demon mail facility so I was able to advise my client of the impending change even if Namesco have seemingly failed to do so.

Something a bit phishy in your inbox? You can now email suspected frauds straight to Blighty's web takedown cops

Richard Cranium

Re: On a point of detail...

No. Anyone can register (almost) any domain name, the uk police registered police.uk under which they have several subdomains like actionfraud.police.uk only the owner of a second level name can register subdomains of that name.

Photobucket says photo-f**k-it, starts off-site image shakedown

Richard Cranium

Re: That reminds me..

A very long time ago, when bandwidth was expensive, one of my customers had been trawling through their access logs to see why they were using so much bandwidth. The main culprit was a nice little animated GIF someone had chosen to hotlink as his avatar on a busy forum where he posted extensively. I used htaccess to substitute a naked barbie doll image when accessed from the forum. Unfortunately it was easy for him to fix but he enjoyed a few days of ridicule.

The same client had also spotted another anomaly in the logs, the most successful search result driving traffic to their website, a country inn was for "beautiful black man". This was, to say the least, "something of a surprise". While hits on the web site were sought after they felt these would lead to disappointed visitors and bandwidth was expensive back then, could I explain? Yes! the search engine (I expect this pre-dated Google so probably AltaVista) had found those 3 words on one page. The name of the inn included the word MAN, the page wrote about the BEAUTIFUL rural setting and detailed the "full English breakfast" which included BLACK pudding.

Tesla has a smashing weekend: Model 3 on Autopilot whacks cop cars, Elon's Cybertruck demolishes part of LA

Richard Cranium

Re: I Can't Stop Myself

Agreed, a downvote here without an explanatory comment often gets me scratching my head to understand why.

I long ago concluded that any mention of Apple (other than a glowing testimonial) will get a downvote. Looks like we can now add any negativity toward Tesla/Musk as another route to a guaranteed downvote.

123-Reg is at it again: Registrar charges chap for domains he didn’t order – and didn't want

Richard Cranium

Re: Not just 123reg but also LCN (though not on auto-renew)

I'd not call out any single registrar on the free .uk registrations. As far as I can see many (most?) did it and probably better than letting the names go onto the open market by accident.

Frankly, many small business owners are too busy doing whatever their business does and disinclined to try to get their heads round what seems to them to be an obscure technical issue, they need advice from someone a bit more clued up but that too could imply time and money.

The free first year was a gentle shove to say: we take the issue seriously, we think you should too. If that didn't work then maybe scare tactics are a valid way to prod the client into making a decision. Of course auto-renewal by inertia, seemingly what some registrars have tried, is not acceptable.

In some cases the downside risk is possibly needing to pay Nominet DRS £750 (or worse) making even the rather steep £12 p.a. at 123reg worthwhile. For many that annual fee is money down the drain, for Nominet it's the gift that keeps on giving.

In my opinion Nominet are the real bad-actor in the whole scenario. The cost to them of allocating the .uk name to the corresponding existing .co.uk name registrant could easily be absorbed. In future registrants of _new_ names could choose to buy uk, co.uk or both. Existing owners of both could be free to sell one variant at which point the new registrant would start paying annual renewals.

The easy option is "pay up", a little smarter is a quick risk benefit analysis. The risky choice is to do nothing, the risk may be trivial but I've seen some valuable lapsed .uk names being auctioned by drop-catchers for substantial prices.

Chancers keep buying up dot-UK company name domains: Got a problem? That'll be £750 for Nominet to rule on it

Richard Cranium

Who Is

Contact details should be available in WhoIs but the registrant should be allowed to opt-out . I have some names I no longer need, I'd be quite happy if people could look up in whois, find my email and offer me vast sums of money for the names... The act of opting out could be taken as an indication that the name may be registered in bad faith but Nominet don't seem to do much checking so registrants have the option of providing incorrect details anyway.

My Nominet control panel contains details of domains that were transferred to other owners many years ago but the registrant never bothered to update them so owner, phone, email and street address are all wrong, the email address is mine, the phone was disconnected 5 years ago, not sure if the building still exists.

In any case Nominet don't use any of that data apart from the email. I discovered that when someone got in touch to see if I could find out why their web site had stopped working. The client had paid the annual renewal a couple of months earlier.

It turned out the client changed email address a few months earlier. They still had the old address but didn't check the mailbox any more, hundreds of junk emails a day had rendered it useless. I logged in and did a search. I found an email from Nominet advising that the domain name would be cancelled due to incorrect information, they didn't specify what the problem was, I had to find out by trial and error.

The client hadn't changed postal address or phone number but Nominet hadn't tried to use either. The client hadn't updated their email address at Nominet . Even if the email had still been current it's stupid to rely solely on that, emails don't always reach their intended recipient, spam filters for example.

I think the problem was that the company name field held something like "Richard Cranium (trading as dickhead)" . When registering the name at e.g. 123reg (don't) there is no field for "trading as" so the client had used their initiative for greater clarity. The t/a name matched their domain name. If you log in to your Nominet account there is a separate field, for trading as, the client didn't know that. Had they provided less information omitting "trading as..." they'd have been OK.

Had Nominet followed their supposed normal process of merely suspending the name, fixing the "trading as" issue would have resolved the problem but Nominet had released the name back to the market although the client had paid their annual renewal not long before.

Rather than waste any more time trying to get any sense out of Nominet the quickest fix was to just buy the name again as leaving it on the open market any longer risked a drop-catcher grabbing it.

So Nominet do seem to wake up from time time and make a few checks but as we have come to expect of Nominet, they do it badly.

A very similar arose with a name registered some 25 years ago, it had been fine for most of that time but then a Nominet jobsworth spotted that the address fields specified the country as GB rather than UK. They threatened to repossess the name, again they didn't identify what the problem was merely that there was a problem: "the registrant details are not correct".

OK both stories date back several years and doubtless Nominet would deny everything and then claim that they've tightened up procedures anyway...

Not just adhesive, but alcohol-resistant adhesive: Well done, Apple. Airpods Pro repairability is a zero

Richard Cranium

I spot a business opportunity...

I too have ears that don't conform to the standard, earbuds wired or not, they just don't stay put, including those with interchangeable rubber adapters to fit different ear canal dimensions. While I'd not consider spending $250 on such things, especially at Apple, for those that might how about manufacturing inert clones? Just a lump of plastic, same size, colour and shape. A potential buyer could buy one just to do a "does it stay in place" test.

And some might buy two so they can walk around in public looking the twats that have wasted $250 on a veblen good - bit like having a fake Rolex.

Haunted by Europe's GDPR, ICANN sharpens wooden stake to finally slay the Whois vampire

Richard Cranium

WHOIS was useful...

Well it would have been if it had been done properly.

It was useful to be able to check that an owner was legitimate - but even more useful if the WHOIS data was properly validated so scammers couldn't buy a domain and give fake details.

It was useful if there was a domain you might be willing to sell or one you might want to buy, easier for the two parties to get in contact.

If there was an opt-in/out option the domain owner could decide whether they wanted to be listed and possibly what level of detail. Domain name owners could make their own choices and anyone making a whois search could make useful inferences from those choices.

I used to run an internet business, we would register domain names using the customer's name as "owner" but with our contact details. That meant we got all the spam and, as it usually had fairly predictable content and structure, it was easy to filter the garbage and respond or forward any legitimate messages. Our concern was that end-users were not good at spotting the scams and might respond. Before we started using our contact details the most common queries we got from our customers related to fake domain name renewal emails and the "someone wants to buy [your domain name].cn or .asia, if that's not OK we will secure it for you" scam. We were concerned that some might not check with us first and pay-up.

US customers kick up class-action stink over Epson's kyboshing of third-party ink

Richard Cranium

Surely better to try _compatible_ cartridges or try refilling the OEM cartridges rather than just go straight for a new printer.

Help! I bought a domain and ended up with a stranger's PayPal! And I can't give it back

Richard Cranium

The larger the organisation the greater their focus on cost-cutting hence "help" desks staffed with staff paid statutory minimum (or off-shore for a dollar a day) and pressured to close calls fast. A large business can afford to lose a few of their millions of customers (probably want to lose those who need a lot of support).

I've experienced excellent customer service using small local ISPs but then along comes someone like GoDaddy, buys them up and - well, time to move on.

Fancy yourself as a bit of a Ramblin' Man or Woman? Maybe brush up on your cartography

Richard Cranium

"... wind frequently makes paper maps hard to use!..."

The big OS sheets are unmanageable in "weather", worse still if your route involves two sheets. And the plastic laminated versions although waterproof, are rather bulky.

I use desktop OS mapping (not the OS app but the vastly more versatile Mapyx Quo) to plan my route then print the relevant area (usually 1 or 2 A4 sheets) and take in a plastic A4 envelope. That's easier to use than mobile as a primary navigation aid, the mobile can be helpful where the path isn't obvious or you need reassurance about exact current location. Printing also means you can enlarge from original paper map-scale making it easier to read.

Nominet continues milking .uk registry cash cow with 4 per cent price rise for... what exactly?

Richard Cranium

No other security software?

Surely the UK TLD is in the gift of the Government, is it time Government regained control?  Have Nominet not violated the terms under which Government allowed Nominet to manage this national monopoly resource by dropping the charitable aspect?  Shouldn't the task of managing the UK address space be put out to tender periodically (like the lottery, the railways)?

Should Nominet be referred to the monopolies commission for exploiting the monopoly to the disadvantage of the public?

Wake me up before you Gogo ... so I can jump out: Kenyan MP takes on aeroplane flatulence

Richard Cranium

Airbus 380

Very rough estimate: on a 12 hour flight the 500+ passengers will boot the cabin atmosphere by somewhere around 350 litres

Chrome add-on warns netizens when they use a leaked password. Sometimes, they even bother to change it

Richard Cranium

Pointless

If I understand correctly if anyone anywhere has used a password that's been leaked it gets onto the list and you get advised to change *your* PW which relates to a *different* service with a *different* user ID. A leaked PW alone is of little use to anybody.

I said "Little use" rather than "none" because I guess someone trying a dictionary attack might use the list of compromised passwords as their dictionary but surely any credible login system blocks dictionary attacks these days...

If the alert were for poor passwords: too short, no use of mixed upper & lower case, numbers and some non-alphanumerics, that would be valid (but annoying when visiting web sites that don't permit non-alphanumerics in passwords).

Alternatively if the blacklist were just of, say, the top 10,000 passwords then it might be worth advising those using things like "123456", "password", "letmein" and "topsecret" that their choice may be poor (although like others I have a garbage email and UID/password pair I re-use on inconsequential sites like those wanting a login for reasons things like to "get our free whitepaper on..." )

It's official! The Register is fake news… according to .uk overlord Nominet. Just a few problems with that claim, though

Richard Cranium

Re: Nice write up! Excellent fact checking!

re: " and FedEx attempting to bring a trademark dispute or 'passing off' action would have a hell off a job doing so".

True up to a point but a small business can't afford the court costs of fighting. An example is KFC attempting to strong-arm the Tan Hill Inn for trademark infringement because they called their Christmas Dinner a "Family Feast", a term KFC use to describe a meal conveniently delivered in a bucket (that one might later find useful as a receptacle for vomit). Tan Hill fixed the problem by getting national news coverage and shaming KFC into backing down, in the face of legal threats, however spurious, many others would just comply.

https://www.telegraph.co.uk/news/uknews/1551113/KFCs-legal-threat-to-Englands-highest-pub.html

UK's internet registry prepares a £100m windfall for its board members – and everyone else will pay for it

Richard Cranium

@J G Harston

Yes the .co.uk names for most "household names" do already exist. The point of the article is that if they don't register the corresponding .uk (without .co) very soon there's a risk someone else will and may use it to the disadvantage of the registrant of the .co.uk name.

Nominet's attitude to that risk is that if a third party were to use a the .uk equivalent of a .co.uk name to the disadvantage of the .co.uk name owner, it would be a breach of Nominet's T&C. What they gloss over is that their Dispute Resolution Service costs £200 for mediation, if that fails you can get an expert decision for £750 and if you don't like the result an appeal costs a further £3,000 taking the potential total to £3950 +VAT.

If a third party had registered mars.uk and was selling sweets Mars Inc lawyers would be on the case in the twinkling of an eye (and probably resort to the courts at much higher potential legal costs than Nominet's DRS if mars.uk was being used by a third party for any purpose whatsoever).

The real risk in this situation is to small businesses. They are less likely to be aware of the issue so may not have registered the .uk name variants. They are less able to fund a legal battle should the need arise.

Some of the examples listed in the ElReg article, including mars.uk, have been registered (presumably by the eponymous confectionery manufacturer). The fact that many of the .uk registrations (including at time of writing mars.uk) don't take you to a functioning web site seems to me to be a recognition by the holders of those names that they are worthless but need to be held to prevent anyone else getting them.

You might think: why not route mars.uk to the functioning web site at mars.co.uk The reason is that once you've done that the name will get "known" possibly by some search engines, possibly by some users of that web site. That means that you're committed to paying the annual renewal for ever. Not a problem for Mars Inc but for a small business, perhaps protecting a few brand names and domain name variants (like multi-word names with and without hyphens between words) the opportunity to save even a few tens of pounds is sometimes welcome.

Chap joins elite support team, solves what no one else can. Is he invited back? Is he f**k

Richard Cranium

Re: I'm lazy. Really fucking lazy!

Friend of mine had to spend a week adjusting the program code for every customer sale. He'd suggested to management that he could convert the code to take a simple parameters file so future orders would just take a few minutes to customise the config file.

Manager said no.

Manager went on holiday so friend rewrote the program anyway. I told him that disobeying orders was risky, better to keep quiet but he proudly told his boss - who responded by pointing out that his job was configuring the code and since that was no longer necessary he was now redundant.

Happy Thursday! 770 MEEELLLION email addresses and passwords found in yuge data breach

Richard Cranium

data quality issue

I'm concerned that in the pursuit of headline grabbing numbers the quality of the list is at hazard. I've got numerous gmail accounts designated for different purposes so the first problem is that I can't submit a list but have to do the names one by one.

One example of a second issue is that one of my addresses is shown as leaked on Disqus, but was it? The report says "In October 2017, the blog commenting service Disqus announced they'd suffered a data breach. The breach dated back to July 2012 but wasn't identified until years later when the data finally surfaced."

I joined Disqus in 2016. So was the leak of 2012 data or did the leak continue right up to the date of the announcement in 2017? The password that might have been "disclosed" (disqus stored as salted SHA1) was unique to access that site, it wasn't my EMAIL password, even if it had been it's protected with 2FA giving extra security. I don't recall if Disqus sent a breach report to all their users but if they did I would have changed password. Good practise on their part after a leak would be to require a password change on next login, if that were the case much of the database would be entirely misleading - your email address is "known to third parties" but what use is an email address that's not known to others?

It seems to me that haveibeenpwned lists any email address that has ever been on any site that's suffered a leak irrespective of other considerations and they are being treated as compromised.

So the email address check is not very useful, is the aim of haveibeenpwned.com merely self aggrandisement? More use might be the "pwned password" test but don't forget that's not YOUR usage of that password and not necessarily linked to one of your sets of login credentials. It just tells you that someone, at some time in the past, has used that password on one or more of thousands of compromised sites. Interestingly it seems plenty of low-grade passwords haven't been compromised. Obviously "123456" and "password" have millions of instances, we are advised against short passwords but even "l2e4S6" and "p4s5w0Rd" (letter/number substitutions) aren't in the database.

A combined test for email and password would be more value to you but who'd be stupid enough to enter both to a third party web site? I'm reasonably confident that haveibeenpwned.com is trustworthy but I'd not disclose full credentials on the basis of "I think it's probably a trustworthy web site". Even if you checked email and then password on the same site, visitor tracking capabilities are such that the two separate enquiries could be shown as coming from the same source so you've potentially provided the site owner with the full set of login credentials.

A few reasons why cops didn't immediately shoot down London Gatwick airport drone menace

Richard Cranium

RAF?

Reports are that the Army has been called in - why Army but not RAF?

LG's beer-making bot singlehandedly sucks all fun, boffinry from home brewing

Richard Cranium

Re: Why?

"Bread makers are an excellent invention."

Or another unnecessary piece of junk to further clutter your kitchen? As we're on The Register we'll all be familiar with Nathan Myhrvold, but what about his post Microsoft career? Cookery! A deeply researched and rather expensive book about bread (around 400 USD). One of his findings it that you can make very good bread without tens of minutes of kneading. Ingredients are simple, not much more than flour, water & yeast. Processing is simple give it a stir, leave it somewhere warm for a while, bash it into a baking tin and leave it in the warm a bit longer, shove it in the oven for half an hour. You end up with a bread shaped loaf, without a metal paddle embedded in the base, OK a couple of hours elapsed time but only a few minutes actual effort. And to save your $400, of his many hundreds of recipes he considers the best to be chocolate & cherry sourdough.

Merry Christmas, you filthy directors: ICO granted powers to fine bosses for spam calls

Richard Cranium

TPS created 1999 (home users only, I immediately registered)

Given statutory force 2003 (& Business registrations now allowed, I signed up ASAP)

2013 described as "not fit for purpose"

Until ?2013 ICO's response to complaints was (I paraphrase) "If a large number of complaints is received relating to one organisation we send a 'please stop doing this' letter, if complaints continue we send stronger warnings" but had never used to power to impose fines.

And am I right in thinking political parties are exempt?

2018 Still almost useless (I get at least one scam call a day) finally, fines on directors BUT what about silent calls? What about robocalls? What about calls from overseas? What about getting Telcos to cooperate by operating blacklists & blocking fake caller IDs.

When will the UK government realise that whenever they launch a scheme like "Grants for loft insulation" the first result will be every "home improvement" business will be on the phone to us (Govt. considers that as a positive: free publicity for the scheme). And so will the "home improvement" scam callers.

19 years on Govt. is intentionally dragging its feet in response to marketing industry lobbying.

My business line is always on straight to voicemail

My home line is on 2 rings then answerphone (so I do get a brief opportunity to see CLI and most legit callers start speaking so I can then pick-up when I recognise the caller)

A problem: the NHS makes calls to confirm I'll be attending an appointment, number withheld, line drops if its answerphone. Is this Govt. policy to stop us using answerphone?

Congrats from 123-Reg! You can now pay us an extra £6 or £12 a year for basically nothing

Richard Cranium

Re: I want to move away

Isn't TSO host now part of the same group, HEG?

Page: