I used to work with someone who requested we print the website (all of it), and they'd mark up changes when being driven around, and hand them back for us to update....
Posts by Blacklight
187 publicly visible posts • joined 6 May 2008
Brilliant backups that kept data alive for ages landed web developer in big trouble
Meta pauses mobile port tracking tech on Android after researchers cry foul
Re: One rule for them
There are ways around this, although they are "not for the average user" (sadly).
I've got piHole, linked to OpenDNS - and WireGuard on my LAN which my phone accesses remotely - and you can route "0.0.0.0/0" (everything) back over it - and then just block 853 (DoT) and any unknown port 53 sites. DoH is harder but you can at least "block known hosts".
I've only seen a couple of apps try to force their own DNS - normally easy to spot as various icons break due to not loading :)
Billions of cookies up for grabs as experts warn over session security
Although it would be frowned on buy some, companies utilising session cookies should be doing some IP based due diligence here. MS MFA does exactly that (although it alerts first, rather than block).
If a new session pops up suddenly, from a new IP and/or device (and typically a new geography) - ask it to re-auth and drop the session trust. Granted, mobile users will be handed out IPs all the time, but typically those are within a carriers range and can be 'foreseen' - and combined with device and/or passkey verification - job done.
Simply going "Ahah, that's Bob's session, suddenly in Nigeria, that's ok" is "not ok".
OpenAI model modifies shutdown script in apparent sabotage effort
Cast a hex on ChatGPT to trick the AI into writing exploit code
Harvard duo hacks Meta Ray-Bans to dox strangers on sight in seconds
Ten years ago Microsoft bought Nokia's phone unit – then killed it as a tax write-off
Support contract required techie to lounge around in a $5,000/night hotel room
Jaunts and escapades
I was lucky enough to be invited to speak at a supplier's gig, overseas, at their expense. Said gig was in Vegas however, which didn't appeal.
Got to Vegas, got to room in 'well known hotel' - and found a food cart in the room. "Oooh" I thought, suspecting they'd put out some buffet thing for my arrival (they hadn't asked if I was vegetarian etc)....except when I lifted the lid on one container - it was half eaten food. Room was also a mess.
One call to reception and I was upgraded to a suite. Result. Only for two nights mind.
Simarly a later company wanted me to back to the US for other activities - and they had a corporate policy about class of flight being dependent on length. Anything over 6 hours was business class. My flight? 6 hrs, 15 mins. Oh noes....
Google Drive misplaces months' worth of customer files
Scripted shortcut caused double-click disaster of sysadmin's own making
No more feature updates for Windows 10 – current version is final
Hey Siri, use this ultrasound attack to disarm a smart-home system
For password protection, dump LastPass for open source Bitwarden
In addition to haveibeenpwned - have a look at https://leakpeek.com/ - that lets you stick in a username, email address etc, and it will show you partially redacted passwords it has for you....
It doesn't show (that I've seen) the source, but it certainly helped me confirm which passwords were nobbled and then by proxy, what the source was.
When we asked how you crashed the system we wanted an explanation not a demonstration
Well it's clearly working as designed....
I upset a German bank a long time ago, by replicating 'an error'.
For a while I lived in deepest darkest south Germany (so south it is technically Switzerland, but the German's nicked it), and returned some years later for a holiday - and attempted to use my NatWest Switch card (that dates it doesn't it?) in a Sparkasse ATM.
Removed card from wallet, inserted card into machine, machine immediately reboots itself.
Once rebooted, of course, there is no sign of my card...and the bank was closed - and the phone numbers went to answer services services.
Next morning, waited outside the bank until they opened, and explained (in halting German) that their pesky machine had b0rked and could I have my card back please?
The attendant's response was (gesturing at the machines) "all the machines are working, if your card has been taken, it's because your bank has reported it stolen". I protested.
Eventually, someone checked the machine, and found the card. I could see them looking at it, but still refusing to give it back. I protested a bit more, saying I'd been using it happily in other places and it was fine, and offered to ring my bank to have them explain.
After a few minutes I was handed my card back, and asked to show them what I did.
So I put the card back in the same machine. And it rebooted again.
They apologised, retrieved my card again, and I toddled over the Deutsche Bank and I withdrew some cash from their machines quite happily.
No idea what combination of info was on the magstripe that clearly b0rked Sparkasse machines, but it did tend to mean I used "larger" banks after that :)
'Last man standing in the floppy disk business' reckons his company has 4 years left
Many flops....
At one point I was happy to have a PC that could read 5.25" 1.2MB, and a 3.5" that could read up to LS120. And an IoMega drive that could take ZIP100 and ZiP250. And a multitude of storage cards (yay, MagicGate).
But the LS120 drive and Zip drives both died clickety deaths.
And the cards are now nearly all microSD (with an SD or USB adaptor).
It's like the BBC Domesday. Great until you can't read it.
And a shame, as kit typically still works. My car has a PCMCIA slot. My PC has a ln LTO3, except I killed it and now can't read some tapes. Yay for cloud etc.
'I wonder what this cable does': How to tell thicknet from a thickhead
Re: Non-VOIP, POTS payphones
I love the fact that POTS had it's own redundant power supply. I've maintained (probably at great cost to myself, although VM tell me I'll pay more if I remove it) a POTS landline for the entire time I've had this house - although I know it's soon to be going away.
It's like analogue radio and the push to digitise - yes you can cram more in to the same space, but the KISS principle should remain for anything that might be needed as an emergency comms medium.....
Zero Trust: What does it actually mean – and why would you want it?
Layers
It's all about the layers. APIs & inter-app comms are probably an afterthought for most.
The 'tightest' place I've encountered had:
a) Windows desktop & server firewall controlled by AD policy
b) Cisco ISE operating on all switch ports (assigning VLANs etc) with MAC and 802.1x back to AD
c) Switch port policies applied to ports based on the VLAN or ISE assignment
d) Site level firewalls (Palo Alto) governing intersite and internet access
e) SD-WAN (Silverpeak)
f) Regional firewalls for internet (and any failover between intersite if SDWAN routing went awry)
g) VPN with device and user authentication, and policies applied dynamically based on both
h) WAFs and NSGs running on the Azure side of things (if you made it that far)
i) AD ACL and SEC groups, applied thoroughly on actual servers, shares & resource groups
But, as outlined in the article, if (or once) you were 'in', you were generally able to 'get around' - but that was also partly due to a hangover from a prior set of circumstances where they were no proper firewall policies previously, and there was still reasonable paranoia as to restricting things further.
Declassified and released: More secret files on US govt's emergency doomsday powers
Seriously, you do not want to make that cable your earth
Electrickery...
My secondary school had a lovely BBC Econet setup, with a variety of BBC-B and Master machines (ah, CUB monitors), across the whole school site (some fun cabling runs, mostly external). One night, there was a storm, and some well aimed lightning hit the Econet cable.
I remember the IT teacher spending the next few days soldering many, many poorly BBC computers.....
Creator of SSLPing, a free service to check SSL certs, downs tools
Re: I feel for the guy, but..
It also depends on how Docker was being used.
Building containers (each time) from Dockerfiles may result in the underlying modules and things in the Dockerfile getting updated. Having anything which runs apt-get/apt-update in the scripts can also b0rk things. Doing a simple thing as "just pulling an image" can wreck you if you are pointing at #latest and weren't paying attention (and/or a maintainer removes prior versions).
The 'safe' (ish) way is to build an image, and export that image and keep it somewhere very safe, or (if you can) ensure the Dockerfile points to static versions of things - but that's not a guarantee....
Case in point, I *really* should update one of my container Dockerfiles to use a specific (i.e. buster) version of Debian, else I will probably find my stuff breaks eventually!
Help, my IT team has no admin access to their own systems
Does your CMDB extend to password stores & credit cards?
Similar thing at "an/other" financial organisation, where Azure was setup with a credit card. A personal one. Something got productionised, and then the card holder left the company. Some payment reminders presumably went to an inbox which was no longer serviced (or more likely in existence).
Not long after, an Azure subscription magically vanished. Which was nice.
Password storage (actually secure) *was* a thing. Checking how it was funded, less so....
Freezing in Newcastle? You're not alone: For one lonesome creature, the world stopped on 31 Dec 2020
The reset card
In the early 2000s I put a NatWest card into a German Sparkasse ATM.
It reset, and ate my card.
The next morning I had about an hour of joy convincing the bank to return my card from the bowels of the machine (and they were adamant the machine was fine) - until we got them to let me put it in again, and lo, it reset (again). They gave me the card back, and I used it in another bank across the street....
So yeah, something in a (foreign) magstripe took out an ATM - which was nice.
Pure frustration: What happens when someone uses your email address to sign up for PayPal, car hire, doctors, security systems and more
Argh!
This.
So much this. And lazy arse people.
I have a firstname.surname AT gmail.com account, and I use the dot. You don't need to use the dot.
I also have a few people with "my name" who have "similar" accounts, i.e. firstname.initial.surname@gmail.com - and do they use the initial?
No.
Do I get the emails?
Yes.
I've had someone's flight tickets to Australia (STA did sod all - I considered actually pitching up for a free holiday) - emails from the police on a crime, from Westminster on a political topic, pictures of someone's family, home extension details, washing machine repair info, invites to a stag do, photo print order etc - and various other crap.
I've also (maybe helpfully) clicked the "Not me" links (when provided) and/or logged in and "closed" the account. So far, none of the accounts have contained any information beyond the name & email address. I then setup a FB group and invited people with "my name" to it, to try and nail a few down - but most have buggered off since. Ah well.
The other joy is that I share a name with a couple of IT professionals, and I've had agencies call me thinking I'm one of the others, and they spill plenty of info before I shut them up....(I'm assuming they search for a name in whatever CRM they use (Excel?!) and ignore multiple results...)
Google rolls out pro-privacy DNS-over-HTTPS support in Chrome 83... with a handy kill switch for corporate IT
Three things in life are certain: Death, taxes, and cloud-based IoT gear bricked by vendors. Looking at you, Belkin
Hey bud – how the heck does that stay in your ear? Google emits latest Pixel Buds, plus extra bloatware if you have the matching phone
So you locked your backups away for years, huh? Allow me to introduce my colleagues, Brute, Force and Ignorance
Pencils
Our old 8088 and then 8086 used to have a batch file we ran to "park" the heads on the disks prior to shutdown. But we started with a 20MB "hardcard" (and a Hercules b&w graphics card, along with DOS 2.11...)
But later we had a dead hard drive, that we could restart with a pencil in the drive spindle, releasing it. We did back it up then
Voyager suffers a power wobble as boffins start the final countdown for Spitzer
Uncle Sam challenged in court for slurping social media info on 'millions' of visa applicants
It's back: The mercifully normal-looking Moto 360 smartwatch
V3...
I have a 2nd gen 360, bought from new when Moto did a father's Day offer. Totally black with black metal strap. That pic in the article looks like the straps may be transferred from old units.
Moto were awesome and swapped my battery well outside warranty, as the various updates oiled the battery (Google that, it wasn't fun) and whilst I don't wear it much it still provides time functions by the bed. The main drawback is its a bit slow now.
If the new one has NFC, a speaker and wireless charging, I may be in.
HMRC's HTTPS howler: Childcare payments site cert expired at 1am on Sunday, down for hours
Backup your files with CrashPlan! Except this file type. No, not that one either. Try again...
Received this morning:
"Dear Valued Customer,
On May 6, 2019, our technical services team rolled out a number of changes to the CrashPlan for Small Business data protection service. These changes were intended to make restoring files and machines more efficient by eliminating unnecessary files from your backup sets. Unfortunately, we made two mistakes during this change process.
The first mistake relates to our email notifications sent to you regarding the changes to CrashPlan. Our initial email sent in early April was classified incorrectly as a marketing communication and did not reach customers who opted out of marketing communications. We resent the notification to all customers on May 17, but this did not give enough advance notice to some of our customers. We apologize for this mistake and we can assure you that we have since changed our processes to ensure better communications in the future.
The second mistake involves the actual file changes that we made. As part of this update, we stopped archiving 32 file types and directories. The email notification included a link to an updated list of files that are excluded from CrashPlan backups. One of the file types we began excluding from backups is the .sparseimage file format. We believed that this file format was obsolete because in 2007 Apple introduced a new format called .sparsebundle, which we thought replaced .sparseimage for the use case we track. After we implemented the changes in May, some of our customers made it clear they still have valid use cases for .sparseimage. We now believe we made an error in excluding .sparseimage, and we have since added it back to the list of files we support via backup.
If you use .sparseimage files, there is no action you need to take. The change will automatically be pushed to your client and .sparseimage files will once again be backed up in CrashPlan. This process will take several days as these devices connect to our service. You can see a full list of excluded files here.
We regret the inconveniences that these two mistakes may have caused you. Our priority is to provide a great product that protects your important small business data. We appreciate your feedback and ongoing partnership. Should you have any questions or need assistance, please contact our Support Team.
Thank you for your support and trusting us with your most important information.
Sincerely,
Joe Payne
President and CEO
Code42"
Re: Whatever happened to three copies ?
My data is held locally, protected by RAID and was backed up to Crashplan, which until now had been flawless. I also periodically ran an LTO (yes, that old tape) backup.
Most of my data was also only on the server when it was shunted off the original device, so I had 3 copies for a point, then typically two.
The point being that whilst I know a Cloud provider may be ephemeral and your data may go poof, the management of this implementation leaves a "lot" to be desired. Like "management", decent comms etc - I can't believe they just looked at the potential disk size reduction and went "What could go wrong?"....
You got a smart speaker but you're worried about privacy. First off, why'd you buy one? Secondly, check out Project Alias
Um, I'm not that Gary, American man tells Ryanair after being sent other Gary's flight itinerary
I've had this, for a similar named person to me, and their flights.
And someone else crime report, with number (direct from the police)
And something from HM Government.
And home building plans, and insurance.
Normally I do get a "sorry" in most cases, but STA (re: the flights) took a LONG time to sort it, and I did consider cancelling the flight....
A year after Logitech screwed over Harmony users, it, um, screws over Harmony users: Device API killed off
Alternatives...
Anyone who has enough nouse to play with APIs, can do the following...
Get a Raspberry Pi, an enclosure, and install OpenRemote on it.
Yes, there is a cloud UI to set things up, but once you've got the config on the Pi, you can cut it off from t'interweb and it will still control anything in your house/network that you can make it talk to (from HTTP/JSON to raw TCP/UDP).
Mine runs on a NAS rather than a Pi, but talks to Philips Hue (which runs when no cloud is available), Lightwave (same), and direct to other devices on the LAN. It is a bit of effort to get going, but it's so worth it when you hear of crap like this!
Rookie almost wipes customer's entire inventory – unbeknownst to sysadmin
Amazon warns you have 30 days before Music Storage files bloodbath
Android P will hear no evil, see no evil, support evil notches
Intel gives Broadwells and Haswells their Meltdown medicine
I recently played with amending AMI type BIOS, as I wanted a new Intel BIOS for RST, and it worked. Hopefully if they drop the microcode in useful formats, people can try rolling their own (if they are suitably equipped).
At least my Gigabyte motherboard has Dual-BIOS, so I can't *totally* kill it...
Intel’s Meltdown fix freaked out some Broadwells, Haswells
Hmm.
Since putting the latest MS patches on my (Sandy Bridge based) PC, I've had two unexplained crashes - which is annoying when working remotely as while the Intel RST on my machine recovers correctly, it doesn't then reboot, so just sits waiting for someone to reset it. Maybe time invest a remote power switch....
Also quite annoying as my Sandy Bridge (i7 2700K) DOES support PCID, but not, apparently INVPCID...
So, on a Sandy Bridge i7 2700K (released Oct 2011 I believe) running Win 10 Pro, the results of "Get-SpeculationControlSettings" are:
Speculation control settings for CVE-2017-5715 [branch target injection]
Hardware support for branch target injection mitigation is present: False
Windows OS support for branch target injection mitigation is present: True
Windows OS support for branch target injection mitigation is enabled: False
Windows OS support for branch target injection mitigation is disabled by system policy: False
Windows OS support for branch target injection mitigation is disabled by absence of hardware support: True
Speculation control settings for CVE-2017-5754 [rogue data cache load]
Hardware requires kernel VA shadowing: True
Windows OS support for kernel VA shadow is present: True
Windows OS support for kernel VA shadow is enabled: True
Windows OS support for PCID performance optimization is enabled: False [not required for security]
Suggested actions
* Install BIOS/firmware update provided by your device OEM that enables hardware support for the branch target injection mitigation.
BTIHardwarePresent : False
BTIWindowsSupportPresent : True
BTIWindowsSupportEnabled : False
BTIDisabledBySystemPolicy : False
BTIDisabledByNoHardwareSupport : True
KVAShadowRequired : True
KVAShadowWindowsSupportPresent : True
KVAShadowWindowsSupportEnabled : True
KVAShadowPcidEnabled : False