* Posts by Jamie Jones

4302 publicly visible posts • joined 14 Jun 2007

Seagate says it's designed two of its own RISC-V CPU cores – and they'll do more than just control storage drives

Jamie Jones Silver badge

But can they read mail?

Let's check in now with the new California monolith... And it's gone, torn down by a bunch of MAGA muppets

Jamie Jones Silver badge

Re: I don't think the "monuments" are related, nor are the removals.

Nice idea, but "Muppets" is too kind.

"Morons"?

Android devs: If you're using the Google Play Core Library, update it against this remote file inclusion CVE. Pronto

Jamie Jones Silver badge

Well yeah, and of course, users can ignore play protect if they wanted to, too. They could also sideload any old shite.

That doesn't answer the question though. By your logic, play protect is no use at all, because it's possible to ignore its findings!

Jamie Jones Silver badge

Android can block/revoke apps with discovered viruses etc. What's stopping them doing so for these cases?

Jamie Jones Silver badge

Re: users may be more inclined to update apps

I agree. I now back up automatically all my apk's so I can rollback if necessary.

Unfortunately, there are at least 3 apps I no longer update because the newer versions are rubbish.

How the US attacked Huawei: Former CEO of DocuSign and Ariba turned diplomat Keith Krach tells his tale

Jamie Jones Silver badge
Happy

Re: 2 months to go

Both, or neither.. I forget now!!

Still, talking about Heinz, remember "The Great Egg Race"?

Jamie Jones Silver badge
Coat

Re: 2 months to go

But the tomato soup has gotten so much more expensive lately.

Master boot vinyl record: It just gives DOS on my IBM PC a warmer, more authentic tone

Jamie Jones Silver badge
Facepalm

Re: Nokia Communicator

Ahh ok. Yep, it was the 9110(I?) I had. Neither of them survived a washing, unfortunately!

Jamie Jones Silver badge

Re: Alpha Micro...

That sounds like the Nokia Communicator.. I had one of those.

Vodafone gave me a free separate number for faxes..

A phone with telnet, fax, a web browser, and 2 phone numbers; back in 1999!

I suppose it was also a PC, as it's GUI OS ran on top of DOS, which you could boot directly with a hack...

Jamie Jones Silver badge
Thumb Up

Re: Older ?

BBC rewind! I'd never heard of that site before..

There goes my weekend!

Cheers!

Jamie Jones Silver badge

EDIT: Actually, it was a later programme, "Micro Live"

Jamie Jones Silver badge
Jamie Jones Silver badge

Re: Ah, happy memories...

Yes, I remember using one of those on my ZX device at the time... (zx81/spectrum/128+)

Jamie Jones Silver badge

Yeah, "The Computer Programme" or one of its followups.

Available on iplayer! https://www.bbc.co.uk/iplayer/episodes/p03062mq/the-computer-programme

and internet archive https://archive.org/details/computer-programme

Edit

Billionaire's Pagani Pa-gone-i after teen son takes hypercar out for a drive, trashes it

Jamie Jones Silver badge
Happy

Re: Why this

"I fail to see how having anything relevant to contribute is related to the number of posts one makes"

Guilty as charged!

Jamie Jones Silver badge
Happy

Re: Ask any actuary

I didn't know they did that. That's harsh.

Still, this happened 30 years ago, so he's probably over it by now!

Jamie Jones Silver badge
Mushroom

Re: Ask any actuary

Aged 17. my brother - "best driver in the world", according to him - severely damaged our parents car, and an innocent car when he lost control of it 3 days after passing his test.

As he (literally) ground to a halt, radio blasting, windows open, the other driver calmly said "I hope you're bloody insured." - The poor guy was just out for a spin - he'd literally picked his car up that day from the garage - where it had been to be fixed after another crash that wasn't his fault!

HTTPS-only mode arrives in Firefox 83 as Mozilla finds new home for Rust-y Servo engine

Jamie Jones Silver badge

Re: Eggs and baskets

Ok, fair enough . I have verisign in the chain, and should have mentioned that.

Verisign is also one of the recognised CA's, so you gain nothing there.

Also:

As of 24 August 2020, 147 root certificates, representing 52 organizations, are trusted in the Mozilla Firefox web browser,[8] 168 root certificates, representing 60 organizations, are trusted by macOS,[9] and 255 root certificates, representing 101 organizations, are trusted by Microsoft Windows.[10] As of Android 4.2 (Jelly Bean), Android currently contains over 100 CAs that are updated with each release.[11]

Again, how can that be just as safe as the DNSSEC signing mechanism?

Jamie Jones Silver badge
Thumb Up

Re: Eggs and baskets

Cheers for that. I haven't considered them up to now because I'm happy running my own infrastructure, and besides, I simply don't have to deal with traffic levels even close to requiring CDN help.

I'll stick with myself, for now at least!

Jamie Jones Silver badge

Re: Eggs and baskets

There have been many cockups with CAs:

https://www.theregister.com/2015/10/29/google_symantec_dodgy_certs/

https://www.fastcompany.com/3042030/the-huge-web-security-loophole-that-most-people-dont-know-about-and-how-its-be

Additionally, do you trust that there is no rogue employee in one of the CA's based in (say) Panama City?

Compare that with how dnnsec is signed: https://www.cloudflare.com/en-gb/dns/dnssec/root-signing-ceremony/

No contest!

P.S. I haven't been downvoting you.

Jamie Jones Silver badge

Re: Eggs and baskets

There's a huge quality difference between those that sign the dnssec root zones, and the huge array of disparate companies allowed to issue browser-recognised certs.

CAA doesn't help much because it's up to the CA to honour, and meant don't bother.

Jamie Jones Silver badge
Thumb Up

Re: Eggs and baskets

Thanks for the reply. Certainly worth considering if I ever go to cloudflare

Jamie Jones Silver badge
Facepalm

Re: Eggs and baskets

My question was somewhat rhetorical - my point regarding DANE still stands. CA's are a crappy way to validate.

Thanks for the tip re: searching, though. I'd never heard of that before. Maybe you could explain what it means?

Jamie Jones Silver badge

Eggs and baskets

Is Lets Encrypt the only provider of free certificates?

We should be seeing a push to DANE acceptance before further forcing https.

https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities

YouTube is going to splash adverts all over your videos, and won't pay creators unless there's a big enough audience

Jamie Jones Silver badge

Re: This will drive good content away from YouTube

When have Google needed an excuse to bin a project?!!

Jamie Jones Silver badge
Unhappy

I think a more important question to ask the legitimate advertisers is if they like being associated with scams.

Most of the ads on youtube are out-and-out scams, that would never be allowed on UK TV. Even as not some sort of protest against online ads, I advise friends and family to ignore all ads on YouTube, and assume they are scams - it's the safest option.

YouTube obviously doesn't care, but I don't know how they get away with it.

Dell online store charges 16 million dollars for new laptop with paint job

Jamie Jones Silver badge

Re: Some would say

It's only one Ronnie! (and Harry Enfield)

Samsung asks New Jersey court to sink class action suit about Galaxy S7 waterproofing woes

Jamie Jones Silver badge

Re: WTF with the disclaimer?

But IP68 certifies underwater to 1.5m for 30 mins!

Jamie Jones Silver badge
Facepalm

WTF with the disclaimer?

From https://www.samsung.com/global/galaxy/what-is/ip68/

IP, or Ingress Protection, is a universally accepted measurement of varying degrees for dust and liquid resistance. Galaxy S20, S20+, S20 Ultra, Note10, Note10+, S10e, S10, S10+, Note9, S9, S9+, Note8, S8, S8+, S7, and S7 edge feature an IP rating of 68, which means you can bring it with you on adventures and take comfort in knowing that you can carry on using these devices.

Devices backed by an international standard rating of IP68 are deemed fit enough to withstand dust, dirt and sand, and are resistant to submersion up to a maximum depth of 1.5m underwater for up to thirty minutes.

*Based on test conditions for submersion in up to 1.5 meters of freshwater for up to 30 minutes. Not advised for beach or pool use. Water or dust damage not covered by warranty.

Ericsson warns investors: This Biden fellow coming into the White House may look to resolve China trade dispute...

Jamie Jones Silver badge

Re: It is more than a trade war

"*ALL* lives matter. If you feel the need to put a colour in place of the 'all', then *YOU* are the racist."

Seriously? The word "Only" is NOT implied in the phrase "black lives matter". I hope you are just ignorant, and nothing more sinister.

If you see people collecting for cancer charities, do you complain that "ALL FATAL ILLNESSES MATTER"?

Why you should stop saying “all lives matter,” explained in 9 different ways

Cambridge expert explains why 'All Lives Matter' completely misses the point

The philosophical flaw in saying “All Lives Matter”

Google for further information.

Jamie Jones Silver badge
Happy

Please be careful, Sweden.

Sweden, please don't piss off Biden, or UK telecommunications companies will be forced to rip out all the Ericsson kit, and replace it with Huawei kit!

Former Microsoft tester sent down for 9 years after $10m gift card fraud

Jamie Jones Silver badge
Coat

Re: But what's it for?

Oh, "Crimea" river!

Zoom strong-armed by US watchdog to beef up security after boasting of end-to-end encryption that didn't exist

Jamie Jones Silver badge

Re: End-to-end?

I'd guess your solution would work.. Of course, you'd lose the E2EE then though (how much do you trust your VM hoster etc.?)

An E2EE shared key service would benefit from an external server with bandwidth, because your outgoing data stream will be identical for all recipients and so an external server it can be used to distribute your stream rather than have your home connection feed each client individually itself.

Biden projected to be the next US President, Microsoft joins rest of world in telling Trump: It looks like... you're fired

Jamie Jones Silver badge
Facepalm

Re: Yay! Party time!

Cederic, why don't you actually read the article you bloody linked to?

You're arguing with yourself here.

Jamie Jones Silver badge

Re: Best to stay away from US politics.. you havent a clue what you are talking about

LOL, shouldn't you be packing, Donald?

Jamie Jones Silver badge

Re: FCC

I thought that's who "friuit and nutcase" was referring to with "Tweety"...

"Tweety pie/pai"?

Jamie Jones Silver badge

Re: Yay! Party time!

That was for ousting Trump, using amendment 25. (Him being nuts).

Nothing to do with Biden.

Snap-crappy: 183 Brit local authorities operate 80,000 CCTV cams between them, says surveillance watchdog

Jamie Jones Silver badge
Coat

Indeed. People are so fed up with these cameras, nearly everyone now wears a mask when they go out.

Tech support scammer dialed random number and Australian Police’s cybercrime squad answered

Jamie Jones Silver badge

Answeting the phone with "Hello, fraud department" usually sees them end the call pretty quickly!

Criticalstudies.org sounds pretty important, right? Wrong: USA says it’s an Iranian fake news front

Jamie Jones Silver badge

Re: Disinformation?

"Media Bias / Fact Check" is a good site for checking the bias of other sites:

https://mediabiasfactcheck.com/fivethirtyeight/

https://mediabiasfactcheck.com/fox-news/

Remember when the keyboard was the computer? You can now relive those heady days with the Raspberry Pi 400

Jamie Jones Silver badge
Thumb Up

Re: The keyboard is everything

A weird idea on paper, but works wonderfully well. I couldn't be without them!

Jamie Jones Silver badge

Re: The keyboard is everything

Replied from my sofa, with my "airmouse".

Jamie Jones Silver badge
Coat

Apparently, they initially went with your first naming scheme suggestion, but with the 4GB version, each time someone went to fetch it, it would turn out to be not found.

(ok, that sounded better in my head)

Brave browser first to nix CNAME deception, the sneaky DNS trick used by marketers to duck privacy controls

Jamie Jones Silver badge

How does this help?

All they need to do is change the CNAME to an A.

Ultimately, it's the site owner that determines whether a site is part of his domain or not.

Possibly breaking legitimate CNAME usage with a dodgy bandaid fix is counterproductive.

If you want to block 3rd party cookies, you need to block all cookies from a different *site* not just a different domain (that would also get rid of the need for that database of which top level domains give public domains at the second level, and which at the third etc. - a noble project, but the fact it's needed is a big hack)

Another body for the Google graveyard: Chrome Web Store payments. Bad news if you wanted to bank some income from these apps

Jamie Jones Silver badge
Jamie Jones Silver badge

"Today, there is a thriving ecosystem of payment providers offering a far more diverse set of features than a single provider could hope to. "

Bollocks. You could say the same about the android app store, but you still force users to use your own payment system.

Chrome apps were a horrible back anyway. They were a way to get around the shortcomings of the ChromeOS "everything runs in a browser" premise.

The security baked into ChromeOS is good. If they actually allow sandboxes apps to run, and ditch the browser-centric UI, then coupled with the already existing Android integration (windowized android apps) , they'd be onto a winner.

As it stands, OS configuration, even the SSH terminal are shoehorned into browser tabs. The obvious problems with that exist, not to mention the completely different UI for browser Vs android (and it's not due to touchscreen emulation.. The Android mouse interface does that well)

Your latest security headache? Ed from accounting using his kid as an unpaid helpdesk

Jamie Jones Silver badge

Re: Best Kept Secret

Try:

"Clean hdmi" "<camera model>"

I.e. include the 4 double-quotes

The one before Harmony? Huawei pushes out EMUI 11, running on Android 10

Jamie Jones Silver badge
Thumb Up

Thank-you both for your replies. I checked the update thing, and it said in on the latest version.

I then checked on their website, and that is indeed the case, for some reason.

Jamie Jones Silver badge

My Huawei medialad m5 got an Android security patch in May, but it's still running emui 9.1.0 / Android 9 !