* Posts by diodesign

3533 publicly visible posts • joined 21 Sep 2011

Microsoft's end-of-summer software security cleanse crushes more than 80 bugs

diodesign (Written by Reg staff) Silver badge

Re: OMIGOD

Yeah, it's in that big box in the story, BTW.

C.

Microsoft releases new Windows 11 builds, confirms running on an Apple M1 'is not a supported scenario'

diodesign (Written by Reg staff) Silver badge

Windows 11 Arm is Windows 11 on Qualcomm

Windows 11 runs, officially, on the specified Intel and AMD x86 processors and Qualcomm's Arm-compatible system-on-chips.

If you try to run Windows 11 on anything other than the specified Intel, AMD, or Qualcomm chips, it's unsupported.

The Apple M1 is thus unsupported, with or without a hypervisor like Parallels.

C.

diodesign (Written by Reg staff) Silver badge

Windows 11 on...

It appears Microsoft considers anything outside the specified x86 + Qualcomm chipsets is unsupported, so yes, even W11 within a Parallels or VMware hypervisor on an M1 Mac would be unsupported.

Edit: We specifically asked about Windows 11 on Parallels on an M1 and were told this is an "unsupported scenario."

What happened was this: Parallels 17 on M1 ran W11 Insider build. Then W11 stopped working as it declared the hypervisor unsupported hardware. Then Parallels 17.0.1 came out and W11 started running on it again. We asked Microsoft if this setup is supported or not, and MS said W11 on Parallels on an M1 is an "unsupported scenario". Parallels didn't say what it changed to make the OS work.

So in fact, we asked the question you wanted. Job done.

C.

Tennessee agrees to pay Oracle $65m for Nashville location plan

diodesign (Written by Reg staff) Silver badge

Re: $1.2B? Really?

That's according to the mayor's office, FWIW. We'd be happy to break down the figure.

C.

Australia rules Facebook page operators are legally liable for user comments under posts

diodesign (Written by Reg staff) Silver badge

NETIZEN IN READER 'RIOT' STORM

An internet user was under fire today after likening Register readers to an "online riot."

In a wide-ranging attack on those who seek out information online and post comments, Imhotep suggested they were easily manipulated by the media. The answer? Censorship.

"Let them moderate the comments," said Imhotep.

DO YOU AGREE? ARE YOU A RIOTER? Like, subscribe, follow, share, click, unclick, retweet and comment below!!!11~

Software piracy pushes companies to be more competitive, study claims

diodesign (Written by Reg staff) Silver badge

Is this a five minute argument, or a full half hour?

FWIW the study is basically about $100m+ software companies (like Microsoft, IBM, etc) and there was no focus on games developers.

The study looked at the correlation of piracy explicitly mentioned by companies in their paperwork filed to the SEC, and subsequent R+D expenditures and IP creation by those companies. Sure, other factors come into play and it's not 1-1 causal, but that’s a given for this kind of investigation.

It’s not a medical study looking to see if aspartame causes cancer or something like that where the causation is the key thing.

And FWIW, the study was about piracy affecting IP investment and indirectly revenue; it’s not a reversible operation where IP necessarily prevents piracy.

C.

JavaScript library downloaded 3m times a week exposes apps to hijacking via evil proxy configs

diodesign (Written by Reg staff) Silver badge

"do a MITM attack from there"

Yeah sure, though that MITM may not lead to RCE like the poisoned PAC can.

It's not likely to be widely exploited, sure. But I dunno, it personally gives me the heebie-jeebies knowing that an application could be blindly running JavaScript given to it outside of a sandbox by some remote source.

C.

diodesign (Written by Reg staff) Silver badge

RCE

"An attacker cant chose the code to execute."

They can -- see the advisory and the example in the article. It's not a slam-dunk RCE (it's clear you have to somehow feed a poisoned proxy config to the app) but it's pretty gnarly if you manage to pull it off.

I normally don't like hyping up super obscure bugs (unless there's a fun educational element to it) that aren't going to be exploited in the real world. But this one felt like either a near-miss or something to flag up to developers.

C.

Banned: The 1,170 words you can't use with GitHub Copilot

diodesign (Written by Reg staff) Silver badge

Usage

If the filter works, you'll find Copilot won't autocomplete your code if it involves the forbidden words, or if the source uses them.

Your IDE will still work, but you'll probably find that Copilot doesn't want to play ball. You might get away with it if the words are in data files the IDE/Copilot can't inspect.

As I understand it!

C.

Arm says it has 'successful working relationship' with Chinese joint venture run by CEO who refuses to leave

diodesign (Written by Reg staff) Silver badge

Spin

True, but we asked Arm what it thought of Dylan's characterization of the situation and this is what it came up with. A positive spin.

Given that it tried to oust Wu, failed, and we all know that happened, a more terse response could have worked.

C.

The unit of measure for fatbergs is not hippopotami, even if the operator of an Australian sewer says so

diodesign (Written by Reg staff) Silver badge

'Pural'

Yeah but it sounds funny. I dunno if you've noticed but we tend to torture the language around here sometimes.

C.

How to stop a content filter becoming a career-shortening network component

diodesign (Written by Reg staff) Silver badge

Tuesday

It was a public holiday in the UK on Monday so we moved Who, me? to Tuesday so that it wouldn't be missed by people.

We do notice that readers disappear a little over holidays, from the traffic logs.

C.

Cloudflare says Intel is not inside its next-gen servers – Ice Lake melted its energy budget

diodesign (Written by Reg staff) Silver badge

Nope.

Obviously it's a typo -- single socket, not single core. It's already fixed.

C.

Brit says sorry after waving around nonce patent and leaning on sites to cough up

diodesign (Written by Reg staff) Silver badge

Re: Not over

Yeah, we've noticed and investigating.

C.

Microsoft sinks standalone Hyper-V Server, wants you using Azure Stack HCI for VM-wrangling

diodesign (Written by Reg staff) Silver badge

Hyper-V role

Yeah, sure. If you can create and use the role, great: you can run some VMs on a Windows Server. That functionality's still there.

But as we understand it, Hyper-V Server might be useful to you if you want to manage and build a hybrid cloud. And Microsoft wants to steer people onto Azure Stack HCI instead for that.

As the Microsoft manager said in the linked thread, "Microsoft Hyper-V Server 2019 is that product's last version and will continue to be supported under its lifecycle policy until January 2029. This will give customers many years to plan and transition to Azure Stack HCI."

C.

Solar System's fastest-orbiting asteroid spotted, flies closer to the Sun than Mercury

diodesign (Written by Reg staff) Silver badge

"unsubstantiated"

We're talking about orbital period. It's said to be the fastest-orbiting asteroid. It gets around the Sun in 113 days, fewer than any other asteroid in our neck of the woods, apparently.

PH27 is described as "an asteroid with the shortest orbital period of any known asteroid in the Solar System."

C.

diodesign (Written by Reg staff) Silver badge

Re: How fast is fast?

By fastest, we mean: its orbital period, at 113 days.

No other asteroid gets around the Sun in fewer days, according to the academics involved: PH27 is "an asteroid with the shortest orbital period of any known asteroid in the Solar System."

C.

Razer ponders how to fix installer that grants admin powers if you plug in a mouse

diodesign (Written by Reg staff) Silver badge

Windows at fault?

We alluded to the possibility that's more than just Razer affected, and there may be a greater underlying issue. Now that we know more about the vulnerability, I've expanded that part to make it clearer.

The issue appears to be that Windows runs some installers automatically at SYSTEM level, bypassing UAC and the like. Those installers don't care if someone can spawn a PS shell from Explorer during the install process because if the user can run the installer as admin, they can open an admin shell whenever they want anyway.

Razer is at the forefront of this story because it neatly demonstrates the problem with this approach, and how it can be easily exploited. Depending on how Razer responds, and Microsoft, we'll follow up with more coverage.

C.

Tesla promises to build robot you could beat up – or beat in a race

diodesign (Written by Reg staff) Silver badge

Typo

It's a conversion error by us, and now fixed. Please report errors via corrections@theregister.com in future, thanks.

C.

After reportedly dragging its feet, BlackBerry admits, yes, QNX in cars, equipment suffers from BadAlloc bug

diodesign (Written by Reg staff) Silver badge

Rust

I just knew if I left the reference to Rust in, we'd get dinged on it. I've just decided to take that sentence out rather than argue at length over it. We wrote at the end, regarding the BadAlloc hole in QNX:

"Such bugs explain why the Rust programming language, capable of memory-safety and type-safety, has become popular in recent years at companies like AWS, Google, and Microsoft."

Would Rust have prevented this specific bug? Maybe, depending on how it was used. You could use Rust's checked math operations that catch overflows, if you remember to use them; debug mode has them on by default. If the overflow is in a separate C lib, you're out of luck.

Is it a good idea to use Rust to avoid similar memory bugs - like what Google, AWS, and others are doing - yes. We mentioned Rust in a general sense because at least some devs look at bugs like BadAlloc, think, 'there but for the grace of God, go I' and opt to use Rust to minimize similar, related flaws to improve the quality of their shipped code.

C.

US boffins: We're close to fusion ignition in the lab – as seen in stars and thermonuclear weapons

diodesign (Written by Reg staff) Silver badge

Re: Re: Self sustaining

Heh, eh no. I mean, it's all over the NIF site that they do nuke research, with some bits about the cosmos, future energy, and national security sprinkled in.

Thing is, we saw other publications writing about this as if this was useful for fusion. But if you look at the info and the quotes - and Katyanna did speak to them - there's little tying it to sustained power generation.

I am quietly fascinated by weapons testing, and the lengths the US etc go to test their designs without breaking treaties. Eg, primary stage implosion tests, just without the fissile material in it, using x-rays.

C.

diodesign (Written by Reg staff) Silver badge

Re: Self sustaining

Who's "you" in this context?

FWIW I would imagine a self-sustaining reaction in this lab would last a fraction of a second -- no one's given any lengths of time beyond the 89ps this one shot lasted.

It's pretty clear this is science experimentation for things like nuclear weapon stuff rather than experimentation for making power reactors, as I thought the article was at pains to point out.

C.

Remote code execution flaws lurk in countless routers, IoT gear, cameras using Realtek Wi-Fi module SDKs

diodesign (Written by Reg staff) Silver badge

Affected products

It's at the end of the linked-to advisory.

C.

84-year-old fined €250,000 for keeping Nazi war machines – including tank – in basement

diodesign (Written by Reg staff) Silver badge

Ah, shucks

No, thank you for reading and commenting!

C.

diodesign (Written by Reg staff) Silver badge

150,000th moderated comment

FYI: Congrats – you are the 150,000th comment I've manually moderated in the ~10 years I've been at The Register. The comment has the ID 4309021, so about the 4.3m'th comment we've shared.

When I started, we had to manually mod everything. Then automatic moderation was built, and still some had to be manually checked (mainly new and naughty users).

Phew.

C.

International Space Station actually spun one-and-a-half times by errant Russian module's thrusters

diodesign (Written by Reg staff) Silver badge

Like a broken record, baby, round round

Yeah, it did occur to us to do some kind of 'you spin me right round' reference but we may have worn out that gag. Shocking, I know, for a Reg editor to admit that. Exhibits A through E:

You spin me right round, baby, right round like an exploding asteroid, baby, right round round round

You spin me right round, storage, right round – like a ferrous-based platter baby, round round

(Picture caption in a Lara Croft game) You spin me right round, baby, right round...

(Picture caption of a galaxy) You spin me right round ... an artist's impression of the Milky Way

(Crosshead in an Audacity review) You spin me right round....

Plus, I've had many variations of Dead or Alive's smash hit on loop in my gym playlist so I don't think I can take any more spinning right round, like a record, baby, round round, you spin me right round, like a....

C.

Google says Pixel 6, 6 Pro coming this year with custom AI acceleration

diodesign (Written by Reg staff) Silver badge

Re: Handler

> crucial information is missing

It wasn't given, FWIW. We're not impressed by the info-lite approach to this launch.

> This Tensor chip, will I be able to buy it on Mouser or Digi-key? Is documentation going to be available?

Seriously doubt this all round. It's an SoC for this one product line.

> What kind of telemetry it is going to be sending to Google and what this chip is going to be doing with it?

The usual Android telemetry.

> How independent that third party is?

No idea.

C.

Microsoft made $167m a day in profit, every day, over the past 12 months

diodesign (Written by Reg staff) Silver badge

Re: Two tier Britain

This is income after taxes. Microsoft set aside $9.8bn for tax on an annual pre-tax profit of $71.1bn.

Microsoft had a global tax rate of 15% in Q4 FY2021, down from 17% a year ago.

C.

SSD belonging to Euro-cloud Scaleway was stolen from back of a truck, then turned up on YouTube

diodesign (Written by Reg staff) Silver badge

Re: I'm a bit sceptical

There's such a thing as "all publicity is good publicity" but I think this is an exception in this case.

The final YouTube video on this saga is here. It's all in French. If an English-speaking YTer picked this up, I would expect this to be all over the news more.

C.

Open-source dev and critic of Beijing claims Audacity owner Muse threatened him with deportation to China in row over copyright

diodesign (Written by Reg staff) Silver badge

Re: Is this really news?

Bringing up someone's immigration status and home government in an argument over APIs and copyright seemed newsworthy enough to the Reg team, nothing more, nothing less.

C.

Imagine a world where Apple shacked up with Xerox in the '80s: How might it look today?

diodesign (Written by Reg staff) Silver badge

'What is this rambling train-wreck of an article even about?'

It's a fictional history, a what-if piece. As in, what if history went another way in the 1980s.

C.

Treaty of Roam finally in ashes: O2 cracks, joins rivals, adds data roaming charges for heavy users in EU

diodesign (Written by Reg staff) Silver badge

Re: Something doesn't add up...

Yeah, there was a math failure. It's been fixed. Thanks to those who wrote in via corrections@ to let us know.

C.

Hubble Space Telescope may now depend on a computer that hasn't booted since 2009

diodesign (Written by Reg staff) Silver badge

"the main computer is borked"

The main computer is fine, it seems, it's the instrument/payload computer that's halting. So they hope to turn off the payload computer and turn on the backup payload computer.

C.

diodesign (Written by Reg staff) Silver badge

Er, yes, mate?

"The computer was replaced in 2009," and hasn't been turned on since it left the lab.

C.

Containers have security problems and flexibility issues. VMs will make them viable

diodesign (Written by Reg staff) Silver badge

"This is one pointless debate"

So pointless you contributed to it -- thanks!

C.

Seven-year-old make-me-root bug in Linux service polkit patched

diodesign (Written by Reg staff) Silver badge

Kernel

Yeah, sorry, mea culpa. I hastily wrote the headline at the end of the day and used kernel and not service. It's fixed. Don't forget to email corrections@theregister.com if you spot anything wrong, though.

C.

RISC-V boffins lay out a plan for bringing the architecture to high-performance computing

diodesign (Written by Reg staff) Silver badge

Re: OpenRISC

The advantage of RISC-V over OpenRISC is that it has more momentum, more financial backing, more corporate and enthusiast interest, and (I'm pretty sure) more hardware available now or on the horizon. It's an Arm rival that seems to have gained traction.

OpenPOWER and OpenSPARC just seem out of reach. We do keep an eye out for them. I can imagine folks feel OP and OS are a little encumbered by their parents, IBM and Oracle, respectively.

Also, Intel just reportedly tried to buy a RISC-V startup for $2bn+. I don't see that happening with OR, OP, and OS outfits.

If there's a screw-up in the RISC-V world, then let us know if we don't spot it, and we'll write about it. We're pro-competition and we like tracking things that may challenge the status quo (eg, Arm). RISC-V is still so young that it's not in widespread use and the opportunity for that community to blow it hasn't come up yet.

There may be some technical limitations to OpenRISC v RISC-V. The people who created RV complained that OR still had branch delay slots (ew), the architecture and its software stacks weren't fully 64-bit ready, and the ISA encoding space gave too much room to immediate values, which is awkward.

Sure, I hope one day we get a chance to do a technical look at RISC-V v OpenRISC v OpenPOWER v OpenSPARC, but for now, the reason why we write about RISC-V is because we like an underdog. As Arm's CEO said, RISC-V keeps Arm on its toes, which is good for everyone. OpenRISC and OpenPOWER ain't doing that.

C.

Google says its artificial intelligence is faster and better than humans at laying out chips for artificial intelligence

diodesign (Written by Reg staff) Silver badge

Traditional algorithms

The neural network, Google says, outperforms human and industry automated tool placement.

So when you see in the article "beats humans" read it as "beats humans using their brains and their automated tools". I'll try to make that clearer.

Google's argument is that the neural net places macro blocks better than humans and their tools, and does it in hours, and not in a process that can take months to juggle around blocks and cells. Also, the AI can place the blocks in an unconventional manner: it seems to scatters them as needed, which some humans might not be so brave to do. The design looks like a mess but it's optimal.

FWIW it's been 15+ years since I've done any kind of chip design. In researching this piece, I read a pre-publication analysis of the paper by Andrew B. Kahng, a VLSI professor at UCSD, and for instance he mentions:

"The authors report that the agent places macro blocks sequentially, in decreasing order of size — which means that a block can be placed next even if it has no connections (physical or functional) to previously placed blocks.

"When blocks have the same size, the agent’s choice of the next block echoes the choices made by ‘cluster-growth’ methods, which were previously developed in efforts to automate floorplan design, but were abandoned several decades ago.

"It will be fascinating to see whether the authors’ use of massive computation and deep learning reveal that chip designers took a wrong turn in giving up on sequential and cluster-growth methods."

In other words, the AI works differently to humans and their automated tools, and that difference can be seen.

C.

Indian government to Twitter: Stop offshoring and outsourcing – or risk losing legal protections

diodesign (Written by Reg staff) Silver badge

Re: The world’s most-populous nation

Thanks -- it was fixed. But don't forget to email corrections@theregister.com if you spot anything wrong so we can fix it straight away.

C.

Global Fastly outage takes down many on the wibbly web – but El Reg remains standing

diodesign (Written by Reg staff) Silver badge

Re: UTC

Thanks, it was fixed. Please consider dropping corrections@theregister.com an email if you spot anything odd so we can take a look straight away.

C.

Chinese app binned by Beijing after asking what day it is on anniversary of Tiananmen Square massacre

diodesign (Written by Reg staff) Silver badge

Incident

Yeah, apologies: it's fixed. Was a bit more than an incident.

C.

Australian cops, FBI created backdoored chat app, told crims it was secure – then snooped on 9,000 users' plots

diodesign (Written by Reg staff) Silver badge

'What kinds of mobile phones would these be then?'

Mobile phones that can't make calls. There's a demand among drug traffickers for handhelds that have had their voice call capabilities, and other functions, removed for security and privacy reasons -- preferably physically removed, if possible. See Sky ECC, which was bundled on devices that had their microphones, cameras, and GPS receivers removed.

From the AFP announcement:

"The app AN0M was installed on mobile phones that were stripped of other capability. The mobile phones, which were bought on the black market, could not make calls or send emails. It could only send messages to another device that had the organised crime app. Criminals needed to know a criminal to get a device."

C.

Everything Apple announced: Tor-ish Safari anonymization. Cloaked iCloud addresses. Cloud CI/CD. And more

diodesign (Written by Reg staff) Silver badge

Not quite like Tor

Yeah, you kinda have to take Apple's word for it for now when its people say "no one, including Apple, can see both who you are and what sites you're visiting."

Presumably the Apple security guide [PDF] will be updated with details of Private Relay for cryptographers to study and assess. That guide is usually detailed enough to determine the viability of a design.

C.

UK's Labour Party calls for delay to NHS Digital's GP data slurp until patients can be properly informed

diodesign (Written by Reg staff) Silver badge

Re: Note to El Reg

Sure, OK, I'll see what I can do.

C.

Google's diversity strat lead who said Jews have 'insatiable appetite for war' is no longer diversity strat lead

diodesign (Written by Reg staff) Silver badge

'I wonder if anyone has checked to see if these are still his views.'

We've asked him. We'll let you know if he responds. Google PR and HR are going to be all over him, though.

C.

Are the forums broken?

diodesign (Written by Reg staff) Silver badge

Re: Are the forums broken?

We did some upgrades to the backend of our systems over the long weekend and that held up the processing and publishing of comments.

C.

Big Tech has a big problem with Florida passing a law that protects politicians from web moderation

diodesign (Written by Reg staff) Silver badge

California

You mean Florida, right?

C.

Arm has another 'most powerful CPU to date' – this time, the 64-bit-only Cortex-X2 for laptops and smartphones

diodesign (Written by Reg staff) Silver badge

Re: ARM A710 or ARM710

Yeah I know. The A510 kept making me think of the Acorn A540, too.

C.

diodesign (Written by Reg staff) Silver badge

Re: "It also supports 128-bit-length vectors"

Ah, see this article about the introduction of Arm's SVE, which can support SIMD vectors that are 128 to 2048 bits in length, though this implementation for smartphones goes to 128. x86 can go up to 512 bits (see AVX)

SVE started life as vector extensions for Arm supercomputers, and is now coming to client chips in the form of SVE2 (which includes SVE).

C.

10+ users can lead to washout: Data lakes struggle with SQL concurrency, says Gartner

diodesign (Written by Reg staff) Silver badge

No.

"This is an advertorial for Databricks"

No, it's not. Please don't accuse us of passing off sponsored copy as editorial -- paid-for articles are clearly marked as such.

C.