The Register Home Page

* Posts by Lee D

4942 publicly visible posts • joined 14 Feb 2013

UK signals legal changes to self-driving vehicle liabilities

Lee D Silver badge

It's the old hybrid-dilemma.

If you hedge your bets and try to make a device do two different things, chances are it will do both badly and cause you more problems than either.

As far as I see it, you would need to be buying a "self-driving car" (with a subscription because the software/insurance would be on the manufacturer of the car) or a "human-driving car".

At that point you can abandon all controls, steering, instruments, much of the dashboard, etc. and make the car's job so much easier.

But trying to do both in one is just a temporary solution that's never going to work well in terms of liability, insurance, etc. We're already seeing that with Tesla "Autopilot". All parties point fingers at the other and it becomes an expensive mess to sort out.

Whereas a dedicated self or human driving car - you know exactly who's liable immediately and can just deal with the collision (never "accident") straight away.

Self-driving cars will be a thing eventually, but they'll be a totally different thing. They'll be a personal transport unit that you hire or rent. The seats don't even need to face forward or even be seats - they could be beds! But the obsession with trying to make the car do the human's job but tolerating interference from the human, not to mention all the other humans around it, on a road built for humans and signs and signals readable by humans, plus handing back to a dead/inattentive human if it panics, and putting the onus on the human at all times... that's just a ridiculous mess of liability.

I would be happy to see a little automated pod zooming down an isolated lane of a motorway overtaking me, with kids lying on a bed reading a book on the back seat, and mum and dad making sandwiches in the front seat (which is turned to face the kids). I'd be in sci-fi heaven.

But what we have at the moment is idiot-hell where some twat thinks that their self-driving car is infallible, falls asleep at 70mph and kills a family, then tries to blame the manufacturer when it's not even clear if he ever turned on the self-driving at all.

Lee D Silver badge

This has always been necessary.

At which point you're putting the liability on the software - which if they are the "driver" by their definition - also means: INSURANCE.

So now although you might choose to insure your car as an asset, the "3rd-party" (main) component of the insurance should be on the system driving it.

Then you will discover that a) nobody wants to take that on as a car manufacturer and/or b) the cost of self-driving cars / subscriptions (yep, ongoing costs of insurance will require ongoing subscriptions) skyrockets to compensate.

And it's only at that point that, drunk as a skunk, you can get into a self-driving car and let it take you home. Until then, you are always the driver/responsible.

So, look forward to expensive subscriptions for self-driving, paying insurance for the vehicle AND 3rd-party insurance via the subscription, and companies being sued to oblivion and your car "decertified" if, for instance, something like the Dieselgate scandal comes out, or some AI is found to be terribly faulty as a knock-on effect of even one lawsuit involving the cars around the world. A recall will mean "no driver" until you update your software to a recertified version. Not to mention obsoletion when your car software is not up-to-date, or is too old to support, and now it's no longer legal to use on the road except if you're driving it yourself.

This stuff is all "just another 20 years away" again, because the above isn't going to happen overnight no matter how much business you throw at it. And when it does, Ford etc. are then basically a software / insurance company that happens to make cars.

Datacenter would spoil beautiful view ... of former industrial waste dump

Lee D Silver badge

Exactly what I suspected in my post below!

Lee D Silver badge

If it was last used as a landfill in 1987, chances are its nothing like a landfill now. There are lots of former landfills that are now parks, green hills, and actually quite pretty.

I mean, it could look like Beckton Ski Slope (anyone?) but it could also just look like a hill now.

That aside, I live in rural Oxfordshire now, and it's actually very picturesque but you could easily ruin it with just one new huge building like that. Whether it was near me or not, I wouldn't want it spoiling that view when there are plenty of more suitable locations - a datacentre doesn't need to be out in the sticks, it could be on any brownfield site. Hey, what does Ford Dagenham look like nowadays? And I think they had 2 wind turbines there at one point, plus a large river for cooling...

And I'm no NIMBY. The only planning permission near me lately was for 10 very nice houses that would have kept my cul-de-sac a cul-de-sac permanently. At the moment, it just ends facing a field, and I can quite see someone trying to turn that into a road to new houses on the field at some point. But the plans were to shut it off and I would live in an isolated rural cul-de-sac forever more. I was quite sad to see the planning denied (mainly because it would almost double the "traffic" and the population of the town overnight, and Oxfordshire's argument against it basically said that there were TONS of other, more suitable sites, and that you could make far more houses elsewhere (than building just ten £1m mansions for rich people), and that expansion on that land would require humungous upgrades to everything in the local area because there are no shops, schools, doctors, etc. I was actually in agreement but also secretly wanting them to build it so I only have millionaires a long way away as neighbours, and nobody can ever use my road as a cut-through, and pretty much all further planning would be denied because of the way it was laid out making anything else impractical.

But for sure I could find you a better site for a datacentre, in a much better place for people to actually get to in order to work there.

Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

Lee D Silver badge

I was thinking more that a CAA record can be definitive, so if the presented root CA is as pre CAA, it gets accepted for THAT SITE ONLY.

And therefore sites are automatically filling in their CA and root CA and browsers ship with nothing trusted by default.

Why should I be accepting a root CA to browse My Bank and then automatically accept everything that it claims to secure including Random 3rd Party Website forever more?

And if the governments want to get into CAA and DNSSEC tampering, there are alternates and measures in those already.

Lee D Silver badge

There was me wondering why my browser comes with any CAs by default anyway.

Just give me the option to wipe them clean when I start and then I approve/deny root CAs as and when I need to (in a similar style to approving SSH keys).

Major telco outage leaves millions of Australians disconnected

Lee D Silver badge

Re: Not quite to same scale

As an IT manager for schools - that's a nonsense.

There's no way that an Internet failure should take out fire alarms - they can't be compliant.

Also - no MIS access is feasible, but emergency contact details should be printed out and/or otherwise held offline and on-site. You could phone the MIS provider and ask them to send the output of a single emergency report (which all MIS have) to an email address, and then access it on a phone, in extremis.

Stopping a school running for either of the above is a failure of their basic processes, whether they use third-parties or not.

What are they going to do in a real fire that occurs in the middle of the school day and burns through the networking cabinets? Are they going to shrug and say "Oh, well, we can't possibly know how to contact parents or see if we're missing any children now". They'd be shut down by the DoE and the fire service if nobody else.

And no - repeat NO - fire alarm should have any network dependency, let alone Internet dependency. You keep that stuff entirely separate for a reason.

Something tells me a fire inspector is going to be paying them a visit "real soon now".

Lee D Silver badge

Re: I Feel for the small shops...

Almost like if you're running a business-critical system like payment processing that you need an independent backup that's not reliant on a single telco.

No matter the practicalities of that, small business is no different - if it's going to cost you, say, thousands of dollars to go a day without payment processing, then you should at least be spending a thousand dollars to try to mitigate that in most circumstances.

They could buy Starlink (or other satellite broadband), they could use another cellular provider, they could link with other local shops and get another / better line, etc.

I cannot imagine - as a self-employed person - running any kind of physical retail shop without at least a Square or iZettle reader under the counter for backup, and some other way of getting online.

I kind of get it in the middle of nowhere out in the sticks, but that's not where the vast, vast majority of Australians live or Australian shops are.

Honestly, if I had my entire income stream reliant on a little box that swipes cards, I'd have several backups of all the parts necessary if that were to fail.

Monero Project admits thieves stole 6-figure sum from a wallet in mystery breach

Lee D Silver badge

Sorry, but why aren't you moving that into an offline wallet on a regular basis?

I mean, at least every $100,000, even if there's a transaction charge. I'd be doing it every $10,000 or similar. Activate machine with offline wallet, send money to offline wallet, confirm transaction, turn off machine with offline wallet.

Same way that supermarket cashiers would put notes into a tub and send off to a safe rather than having it all on the shop floor for anyone to rob.

For rich people, and large companies dealing in money, they appear to be completely naive in how they handle other people's.

Microsoft likens MFA to 1960s seatbelts, buckles admins in yet keeps eject button

Lee D Silver badge

Re: Please think of the techies

This doesn't affect any corporate user, because you're not actually storing data on those systems anyway (so the user can be given any other machine in the meantime) and you have full access to the machine.

Remoting into a broken computer where you can't log into it as yourself is definitely a "return to base" issue nowadays.

The whole point of MFA is that you can't pretend to be the user without their cooperation. The whole point of a corporate managed system is that IT don't need to.

'Corrupt' cop jailed for tipping off pal to EncroChat dragnet

Lee D Silver badge

Re: Sneaky badges got caught

As Terry Pratchett went to great lengths to point out in his character Samuel Vimes:

Sometimes you need secret policemen because there are sometimes secret crimes.

Home of the world's longest pleasure pier joins public sector leak club

Lee D Silver badge

Re: So :

Not really.

Your NI number isn't privileged and nothing should hang off it (unless people are being absolutely incompetent).

Your name and address are a matter of public record, easily discovered for any given individual - you give that to Amazon or everyone that you ever receive a letter from, for example.

Pension scheme - yeah, maybe some slight phishing possibility there but nothing really major.

Salary? Nope. Horrible personal data to have leaked but not a security issue of accessing anything (nobody genuine is going to ask you to enter your salary to gain access to a website, for example).

Same for equal opportunities data.

Any place that lets the above information take over an account without checking is utterly incompetent, and probably failing their own GDPR to be honest.

What I don't see in that list are passwords, account numbers, security questions, etc. that would actually be required to directly do any harm.

It's actually quite a low-level compromise, with the exception of the salaries.

P.S. your employer knows all the above, anyone who works in the accounts or payroll department, anyone who works in the HR department, as do all of your previous employers up to a given point in time.

Lee D Silver badge

Re: Excel and FoI basics

It's the one sole reason for which I tolerate CSV.

No fancy hidden data, just a text-readable file that you can inspect and search for any private data if necessary.

We need a kind of "PDF" standard for data export (but, again, without the possibility of revealing data hidden behind poor censorship attempts, etc.).

Something like a single SQLite database table with no fancy features, or similar. Or Firebird. Same kind of program.

UK throws millions at scheme to heat homes with waste energy from datacenters

Lee D Silver badge

Re: The University of Birmingham do this

It's very different when you own all the infrastructure and buildings involved.

Lee D Silver badge

While this all sounds fabulous, it really doesn't work and is not even worth the infrastructure to do so.

If we had some kind of universal municipal grid where any spare heat from any industry can be dumped into it, and used to service homes on a long-term obligation, then it might work.

But not small-scale, or dependent on one place / company.

What you want is something like the old steam utility lines that used to be in London and are still used in places like New York I think (but declining for similar reasons).

But then you want any industry with spare heat to be able to use it for their recovery too.. until you reach the point that people are taking the heat on the ground floor to heat the home, and then feeding back the heat from their roofs to feed back.

The biggest problem, though, is that heat dissipates, it cools in open air, and you need the incoming to be cooler than the outgoing when it comes to the recovery portion... at that point you're basically operating a heating and refrigeration network for an entire city, with enormous heating/cooling losses.

Though even I have felt the top of my tumble dryer and thought "there must be something useful I can do with that heat", apart from just letting it vent into the room, there's not much you can do with such small, fleeting amounts.

In a similar vein, I was testing a stove fan the other day. You put it on top of your heating stove, and it has a thermoelectric plate in it that generates electricity enough to spin a tiny cheap fan to try to waft the hot air around the room. After putting it on a 300C heating surface, I can tell you... it's pathetic. It does spin and "for free", but the motor that spins is one of those toy-fan motors, and it doesn't spin fast enough to even make an air movement that you can feel with your hand. Large blades, proper angle and correct rotation and I literally couldn't feel anything without getting close enough to chop my finger.

That's pretty much the current state of any heat-recovery technology for the home. I honestly think you'd do better just keeping a pot of water on the boil and using the steam.

Musk's broadband satellite kingdom Starlink now cash flow positive – or so he claims

Lee D Silver badge

Have you seen the price?

Also you need full sky view (which rules out a lot of places), the kit is wireless-only in its home form (you have to pay a lot more to get an Ethernet port), and the one that lets you actually move around (i.e. use on vehicles, etc.) isn't available everywhere and costs even more again. Don't know about you but paying nearly 5 times what a basic DSL line costs each month, on top of a huge layout to get something that you have to mount on your roof (and hope there's nobody nearby) and then hope the wireless penetrates into your home without affecting the speed too much isn't as great a deal as it sounded at first. (I know, I live rurally and was considering it).

Also, the speeds of the service are dropping as reality sets in that if you give everyone what they want, you need to have the back-end connectivity to supply it - Starlink has been trying to do deals all over the world to increase its ground station bandwidths, and trying to get its satellites to share the traffic among each other, which again costs a lot of money. There have been articles on The Reg about that only this year, I believe. In the meantime it appears to be applying traffic shaping and limits (hitting home users first, obviously) which are bringing it back down to what DSL supplies rather than the glorious advertising numbers.

Believe it or not, a few rural joes with little to no current Internet aren't a great money-making market in the long-term and for the more useful features, it's actually not ready and/or very expensive (not Iridium-expensive, I grant you, but not great).

Over-promised, under-delivered. As always with Musk.

CompSci academic thought tech support was useless – until he needed it

Lee D Silver badge

Re: CS students are interesting

When I did a CS degree, I had to:

- Fit a (stupendously expensive) IDE DVD-ROM drive in a home PC for a guy studying for his Masters in CS. He literally paid me to do it because he didn't understand how to. Two days later, he complained that he "couldn't switch region" any more - and we'd already had a VERY extensive chat about how those drives would stop you changing region after 5 goes, and he shouldn't mess with it.

- Explain "minimax" algorithms to Masters programming students.

- Literally debugged a guy's program from across the room. Saw he was struggling, knew exactly what the problem was, walked up and offered the solution. It was that simple and obvious.

- Explain how an emulator worked to many, many people after they saw me using one to run old programs.

- Show several people how to login to their university FTP accounts (which was a requirement of submitting any programming project!). I'm pretty sure I was the only one in that year's intake of the department to submit coursework from home (by modem) because nobody else understood FTP (and www was still in its Netscape days back then).

- Explain to people how I managed to download hundreds of megs (huge for the time) and spread it across several disks using PKZIP on the command-line to take it home. Hell, I was doing parts of that onto floppies still (and all the machines had ZIP drives).

And I was literally the only person I ever saw, in a CS department with a huge suite of dual-boot Linux/NT machines only for use by CS students, to ever boot into Linux. It was specifically set up to allow both OS, all the same software, all the same access and logins. It must have been a work of art for its day, because it was seamless. And I think I'm the only one who ever used it, at least in the Bachelor's programmes. I watched many people submit code that worked on Windows but failed on Linux because they'd written it exclusively with Windows components / assumptions etc. and it would be rejected and they couldn't understand why.

I came to the conclusion - as a Maths "major" with CS being only the "minor" in my degree - that almost all of the CS people I'd met there would never work in IT, never write a program once their course was finished, and would struggle to run a home laptop, let alone anything more complex.

From my alumni updates, I was pretty much right.

Lee D Silver badge

By various well-paid supposed IT experts (usually instructed to "show me how to do my job properly", and often under "I must co-operate with them" clauses) I have been told, in earnest:

- Having an odd number of cores in a virtual machine will slow it down compared to having an even number, but less, cores.

- That a version of Linux back in about 2004 "could run everything Windows can" (and not via virtualisation). It was a cheap, shite remote-desktop service targeting schools. They wanted to replace the entire school with thin-clients and have all of them log into a remote Linux server. I would normally be RIGHT BEHIND that idea, except: They claimed that Wine could run *everything*, including Ranger ... which was an RM-made network management product aimed at Windows that operated by interfacing into the Windows GINA logins etc. and enforced settings in Windows, deployed security policies for the underlying OS, and basically "secured" the machine from people tampering with Windows settings etc. Apparently that would "just work" running under Wine to control those SAME settings in their Linux remote desktop. (P.S. the remote OS had a full suite of Microsoft Office icons that opened OpenOffice applications, which I reported as attempted fraud and breach of copyright/trademark).

- That it was "impossible" to have a Chromebook working with a major-brand web filter designed for schools. So when that was declared, I pressed "Enable" on a configuration that I had set up in ten minutes.

- Enabling spanning-tree will bring down the entire network, and "it never works".

- An at-length lecture about how NTP operates... when they were constantly referring to NTP Pool Project... which I run servers for. All kinds of nonsense was claimed there, complete disregard for strata, no idea how Windows actually syncs time, etc. etc.

- That a legitimate way to mass-deploy iPads with apps was to use a tool to suck out whatever the Apple equivalent of an APK file is from an existing iPad with licenced apps, then put them into an Apple Configurator profile and deploy every app to hundreds of iPads. Even legal use aside, when one day the apps all turned off (except on the original iPad) and everyone in the building started getting thousands of login prompts for accounts they did not own (the accounts those apps had originally been purchased for, once) making the iPads unusable. They doubled-down by charging by the hour to "fix them all" which consisted of them manually logging into a dozen different accounts on every iPad whenever prompted until the warnings went away... for about a week before they all re-appeared. That one, I actually laid down a "I will rebuild them all again, but this guy absolutely cannot be allowed anywhere near them" because of previous tampering when we re-imaged them without any such apps, and he put them back on. Strangely, without the illegal apps on them, they all worked and never provided spurious login prompts for things like "administrator@" our domain.

- Same guy thought that a legitimate way to image PCs was to take whatever the nearest computer was, make an image with Clonezilla onto a USB hard disk, then image it across to another machine, take it off the domain, rejoin the domain. We ended up with thousands of illegal copies of software, stupendous domain problems (because of the SID, naming etc. issues), and the image - after a year of him having been doing this before anyone else was hired to run the IT - was a humungous mess of confidential files, user profiles, software, taskbar icons and junk everywhere, gathered from every machine imaged and built up every time another machine was "imaged" and imaged and imaged in the same way after use by users. No sysprep, nothing.

- A server support engineer at a large MSP that was recommending, purchasing and servicing all the IT for a small one-server shop. They were asked to upgrade their storage as they were running low on space. Storage was all on one server, on a RAID5 set (at their previous recommendation!). The method by which they upgraded the storage was thus: Turn up. Pull hard drive #1 out while the machine is running live on production during the working day. Throw in a blank drive. Wait 8 hours for it to resync. Charge for 8 hours of sitting there watching a percentage bar with a cup of tea. Go home. Come in the next day. Pull hard drive #2 out. Throw in a blank drive. Wait 8 hours on a chargeable rate. etc. etc. etc. On drive #3, the resync failed, the RAID collapsed and it was unrecoverable. He was asked to restore the data to how it had been. "Oh, backups are your responsibility, not mine. Bye!" and literally walked away. He hadn't even checked before starting. (At which point I was dragged into the situation to try to salvage things back to some sanity and the MSP was dismissed from their contracts).

- A "network specialist" at an MSP (one we had to wait weeks to get their engagement because everyone else in the MSP had to defer to them because they knew nothing about networking themselves, and he was "the guy" for networking for the entire MSP) who couldn't - after months - work out why a VPN device that they insisted on (which was installed between two routers that had had an IPSEC VPN between them for years, no external device required) couldn't pass UDP broadcast traffic. They were even pre-warned, many times. They had the existing IPSEC, routing and firewall configuration to refer to. They put a VPN device behind the original devices that had been doing IPSEC happily for years and passing that traffic, sold it to the company for ridiculous money, and then couldn't get the single most vital - and warned about - application running across the link that had always worked before. It took literal months of tinkering, rebooting, rewiring, and then they declared it "impossible". At which point, I finally convinced my boss of the MSP's uselessness, removed the VPN boxes, and clicked the "enable" button on my existing configs at both ends again and... viola... perfect traffic passing.

- An "IBM" (I use the word dubiously as he worked on IBM systems but I think was actually unaffiliated with IBM) cyber-forensics engineer who was supposed to assist in recovering data (and verifying the extent of a compromise) from a corrupted / infected blade storage system. It took several days and basically consisted of him plugging his personal laptop into the blade server and copy-pasting what he could from an virus-ridden Windows server to his laptop, retrying whenever that failed, leaving it running overnight, etc. to then later try to present those files to us unsanitised on a USB created from that same machine. It took him most of the first day to work out how to actually get it working because we had isolated the machine entirely and refused to let him plug anything into the rest of the network - so even connecting a network cable direct to a laptop and configuring a static IP in a known range was completely beyond him.

- A former BT engineer trying to override my putting fibre into an existing building on the basis that "fibre is conductive" (and, no, the fibre in question didn't even have foil shielding, etc.)

And I have been asked, by those same kinds of people:

- "What's spanning-tree?" - in the mid 2010's.

- "What's virtualisation?" - in the mid 2010's.

- "What's a VLAN?" - in the mid 2010's.

Pentagon seeks government gossips to dish dirt on UFOs

Lee D Silver badge

"Not that I'm a believer, but there have been sightings around the globe."

And yet not one single credible photograph, video, recording or corroboration in a planet of 7.8 billion people with over 6.5 billion smartphones.

There are *definitely* 100% UFOs. Things we can't identify. Because the evidence is so terribly poor. It's like holding up a blurry, badly processed photo of a blob and going "See, evidence!" and expecting the world to believe you have caught an alien/ghost//bigfoot/honest politician on camera.

Most of those UFOs will be nothing at all. Specks on the camera, sunlight, out-of-focus ordinary object confusing scale.

Some of those UFOs might even be aircraft... foreign, spies, drones, *cough* Chinese weather balloons *cough* etc. etc. etc. That's what the Pentagon are actually interested in.

None of them are aliens.

And yet: There are absolutely *definitely* 100% aliens out there. Just nowhere (and no-when) we will even encounter each other even blasting signals out into space 24/7 at the maximum power we can muster from the second we discovered radio/lasers/whatever to the second our civilisations collapse.

And if you haven't noticed, humans - all humans, from all walks of life - are absolutely unreliable witnesses. RAF or not. Politician or not. Scientist or not. There are cranks, crackpots, people with mental health issues, people who age, get dementia, make up stories, lie, turn to conspiracy theories, join cults, or even outright believe in things that simply don't exist (like, hey, gods and ghosts and things). Even among top-tier PhDs and Nobel Prize winners to the highest general in the land.

Saying there have been sightings around the globe doesn't mean a damn thing, until one vaguely credible person (hell, even a journalist!) stands up with one good photograph or video that clearly shows something we absolutely can attribute to non-human creation, ever, in the history of the world.

Strangely, the more CCTV, cameras, smartphones, selfies and cloud-connected automatic uploads we have in the world, the fewer UFO sightings we actually get per person. It's almost like having lots of good quality, easy-to-operate cameras in the hands of every ordinary person isn't actually making any difference to our detection of these mystical beings that are crashing into Earth, flying around populated locations, and posing a massive threat to the world's militaries if they were to exist. But find a blue/gold dress photo and we're all poring over it trying to analyse it.

It's a nonsense, and while aliens will exist (just by sheer weight of numbers of galaxies), I'm a far, far, far greater believer in the Drake equation than I am in some guy who say something briefly once while pulling 8Gs shortly because being discharged on mental health grounds after suffering immense shellshock.

Don't fear the Thread Reaper, a Windows ghost of bugs past

Lee D Silver badge

There I was thinking it was a new AMD chip aimed at the Northern market...

On-by-default video calls come to X, disable to retain your sanity

Lee D Silver badge

Android - app doesn't have permissions to open my camera or microphone.

Brain - First "call" I get, the app gets uninstalled.

Also Brain - Why the f**k would I ever want to call someone on Twitter... like... who would you ever add on Twitter that you'd want to call? And even if you did, who would you call that you couldn't do in a million other better ways?

I know you're trying to bury Twitter, Musk, and I can't really understand why except out of some kind of spite, but it's about time everyone still working there just walked out.

Apple jacks prices to juice profits because $19.3B a quarter isn't enough

Lee D Silver badge

I don't understand the mentality of anyone using or endorsing Apple products.

It's just inferior shite, years behind in technology, wrapped up in fancy-looking wrapping and sold at extreme markup, and people just lap it up for no sensible reason.

That script I wrote three years ago is now doing what? How many times?

Lee D Silver badge

As someone who's taken over any amount of legacy junk, I now operate on this basis:

- If it's junk, I'll tell you so, and expect you to replace it.

- If you don't replace it, I have little interest.

I've always left behind documentation, experienced staff, etc. whenever I've had to put in a bodge, but nobody seems to care very much.

Every time I take over a place, nothing useful is documented (and documented the weird and wonderful, including the rationale for that, is far more important than telling me the exact spec of your server, or how you organise your IP subnets). In the last place I took over there was an entire community FM radio station hiding in a cupboard that nobody really knew anything about.

So when I take over, as I touch things, I document them. I force staff to document stuff they know, especially if it's a "Oh, look, I'm the only one who remembers how this works, let me just fix it quickly for you" kind of arrangement.

If it's not documented, it's not something I deal with. Not until it's been documented. Force me to take it over and job #1 is documenting it... for me and future replacements. And in that process, if you're documenting and thinking "WHWHWHWHHYYYY?!?!?" then you should be telling them they need to change it, and moving down that path, and accepting no responsibility for it failing in between that moment and the moment of replacement.

And, yes, it's the weird stuff like this that absolutely NEEDS documenting. And why it exists. That backstory is important. Why didn't you just go the simple way? I need to know. There might be a very good reason for that.

If you're not leaving behind a Wiki / Sharepoint / Whatever full of consistent documentation, with rationale, then you've failed in your job managing that system. If the next guy has to pick up the pieces and either doesn't know it's there, only discovers it later (or when it goes wrong) and has no idea why it's doing that, you've failed in your documentation AND handover.

It really doesn't take that long to spin up a Wiki and start bashing out a page for each piece of software, a page for each server/VM, a page for each system and its dependencies, a page for renewals and expiries, a page for suppliers, licensing, etc. and you can literally do it as you go. Every time you have to do something, think "Is that documented?" and if it's not make a blank page with a TODO message on it (I use MedaWiki and a category for "Incomplete Pages"). Then when it's quiet or you have even a couple of minutes, grab a random unfinished page and add to it. You don't need to complete it, just add to it. Every time you do that weird thing you have to do every year but always forget how to do... write a page on it.

And at a pace of 1 small page a day, you have over 300 pages of documentation done in a year just as one guy. 300 systems, servers, quirks, softwares, etc. It's really not hard. With a team, you can blat out thousands of pages.

And then it all pays back that one day you have to handover, train a new member of staff, or disaster strikes. "Now... how did we build that cluster, I remember we had to do something with the registry to make the RAID controller work, what was it again..." "Oh look, there it is. All written down by someone like me who accounted for all the pitfalls in the process, and knows exactly what I need to know and what order to do things in, and why we DON'T do that step first even though it appears logical to me."

Past me is a really nice guy who helps me out a lot, and is psychic - he always knows what I'll be asking when something goes wrong, and telling me to ignore THAT menu even though it looks tempting because the option I actually want is OVER THERE instead with a similarly-named option. He's a smart guy.

Past-predecessors are almost universally a bunch of inconsiderate twats.

Millions of smart meters will brick it when 2G and 3G turns off

Lee D Silver badge

I'll worry about it when they bother to give me a smart meter.

Every month or so I press the button again and am told that they're "not available in my area" yet.

I have an old teleswitch meter, which is dependent upon a BBC radio signal, which is dependent on the Droitwich radio station, which is dependent on a huge *valve* based transmitter, which is dependent on a stock of the now-unavailable valves (which the BBC bought up in their entirety worldwide, and burn through one every year or so).

They've announced that it's going to be decommissioned - with no planned replacement - as soon as the last valve dies. That date keeps getting pushed back but nobody seems to be in any rush to actually DO anything about it until one day it just stops working. Then presumably there'll be a mad scramble to move me to a smart meter, and I'll tell them to get lost and only do it at my convenience because they've had YEARS to do this and haven't bothered.

Want a clean energy transition? Better start putting cash into electrical grid

Lee D Silver badge

Re: One more strategy,,,,

"Solar is also a terrible idea at UK latitudes. Production in the winter when you actually need to heat your home is near zero."

I rode through a 4-hour power outage last night in the depths of Oxford countryside, with a pretty poor charge all day long because of the gloomy, wet, stormy weather.

Sorry, but solar at UK latitudes is perfectly viable. So long as you're not playing with toys.

https://www.fabhabs.com/solar-insolation-calculator

At worst-case, you get 1KWh / m^2 / day. My daily usage is 7KWh. 7 m^2 is nothing in terms of solar panels on a standard UK roof.

Lee D Silver badge

Re: Strategy 2

Is there anyone in the UK with a smart meter that's capable of turning their energy off?

I don't think they've rolled any such devices out.

The only smart meters I see are normal meters with "monitoring" boxes so you can see what you're pulling (basically a clamp meter and a remote screen).

First Brexit, now X-it: Musk 'considering' pulling platform from EU over probe

Lee D Silver badge

Re: Wild west?

I reported 6 different ads yesterday for cryptocurrency scams, all featuring Musk's face, and most of them with the "warning" label of everyone telling you that it's just a scam using his image.

He can't even control his own image being used by his own advertisers to scam his own customers on his own platform.

It never used to be like that.

Lee D Silver badge

Bye, Elon.

That said, I've yet to hear of any major international company that ever says this ACTUALLY pulling out of something that represents 40-60% of their income.

'Recession-resilient' Tesla misses Q3 expectations, slows Mexico expansion

Lee D Silver badge

Is this the guy who praised their European sales and then simultaneously announced a release date for a vehicle that cannot ever be road-legal in the EU?

Amazon's Project Kuiper satellites prepare for testing after one late Prime delivery

Lee D Silver badge

Better as a human? No, he's a voluntary billionaire. Of course he's not nice.

What he isn't, though, is a loud-mouth lying twat.

Lee D Silver badge

Re: Are you sure it wasn't delivered before ?

Once had an Amazon driver put my parcel in my recycling bin. The full one. That I'd put out on the road that morning for the collection.

Sheer fluke of coming home, and wondering where my "delivered" parcel was made me look in there.

I mean, who'd suspect that a recycling bin full of crushed Amazon boxes awaiting collection/disposal wasn't a good place to put a small Amazon parcel with things actually inside it?

I have to say, though, that that incident represents probably less than than 0.01% of all the Amazon deliveries I've had in the 20+ years I've been using them.

Lee D Silver badge

Yes, they may be behind. But they're not Musk.

I'd buy them just for that, when they get the constellation running.

Thousands of Teslas recalled over brake fluid bug

Lee D Silver badge

Re: We really do need a new name

Fine.

"Mass mandatory critical software fix for potentially lethal issue".

What's that? Oh, you're happy calling it a recall instead?

Down and out: Barclays Bank takes unplanned digital detox, customers not invited

Lee D Silver badge

I wouldn't bother.

In this instance, stamp it "Not at this address" and put it back in a postbox.

The longer they are receiving mail (without this happening) at your address, the greater the chance they're affecting your credit record because the banks will think they still live there along with you.

Any kind of contact is going to reinforce that.

Just mark it not at this address, post it back and keep doing it until they stop.

Whenever I move (and I bought a house last year), I do this with all mail addressed to previous occupants. Otherwise you're just making trouble for yourself. As it is, the guy somehow appeared on my electoral-roll registration form this year and I corrected it (and then received a letter from the council addressed to him, which I returned... that's their "test" to see if he still lives there).

You are opening yourself up to card fraud (like the other post below yours here), credit record merging, etc. if you're not careful - I know, because I've had that at previous addresses, even to the point of debt collection people turning up at the door looking for the previous residents.

If it's not addressed to you, you're not supposed to open it, either.

When companies - including councils, banks, lawyers, etc. - get mail marked "not at this address", they start cancelling the accounts automatically because they are being told it's not an address you live at, and if they have no other address they will shut down the accounts and wait for the owner to contact them. I know because I've seen that happen too! Just a few letters marked "not at this address" is enough to cancel someone's credit card, for instance, and debt collectors actually tend to respect the same (but usually after a more persistent contact campaign at first).

Lee D Silver badge

Re: Customers of the bank, whose values include "Excellence" and "Service"...

Many years ago I spotted the trend, and just went with an online-only bank.

My thinking: If they are ONLY online, then being "down" is ultra-ultra-ultra-critical to them. And they would have to provide a way for me to do everything I need entirely online.

That's worked out perfectly for me so far, after having blacklisted every UK high-street bank for not-unreasonable reasons (being laughed at when asking for a mortgage, so I went next door and got one, complete inability to have a secure website for years and expecting some Java plugin nonsense to suffice, and even holding onto a cheque until the VERY, VERY last moment having never done so before, in order to fine me for briefly going overdrawn, etc.)

I couldn't find any UK bank that would give me notifications of every transaction. My Italian friends had it with their bank fo years, in the UK only "above a certain limit", by a text message that could take forever to arrive, etc. Went to an online-only bank, my phone literally pings as I'm tapping my card in shops. Any shop. All shops. Immediately. For all transactions. The best anti-fraud measure you could ever hope to have.

Since moving to an online-only bank, I've literally not had any complaints about them. They bump my savings rates up and tell me instantly, I can set money aside, I can view my card details in the app, I can freeze it if I lost my card, etc. etc. etc. It all just feels 21st century, while the high street banks were still in the 80's.

Hell, I can't even check my mortgage online with the provider, but the banking app checks my credit record and shows it in my account for me. If they offered mortgages at the online-only bank, you can be damn sure I'd be switching.

And they even let me claim my wages a day earlier than everyone else because, as they say, "All banks could do this, they just choose not to". It's been great.

When someone is giving you bad service, move. I did the Current Account Switch Guarantee and I didn't have to do a thing for all my old high-street bank account to come across to the online-only bank, with scheduled payments, etc. as well.

Plus, I'm not paying for surly staff, useless machines, security and the like in a bunch of increasingly-expensive retail locations. It's totally unnecessary.

If you're expecting a return to the good old days of high street banks... it went. Decades ago. Even the better ones have all followed suit. There is no good high-street bank.

Pack up your things, move to an online-only one, and enjoy life again. It took me installing the app and a couple of photos of my documents. That was it.

I would recommend Monzo, personally.

Workload written by student made millions, ran on unsupported hardware, with zero maintenance

Lee D Silver badge

Indeed, I have a bluetooth, battery, portable one in the car for my own purposes.

But these ones were hardwired USB, cheap, simple, fast, plain-text, standard, and can print out hundreds of receipts before they need paper changing.

And not long after I built the system, I bought a box of receipt rolls off eBay so they have enough receipts to last them 10 years (since I made the system), and another 10 years on top.

Lee D Silver badge

Re: The staying power of powerpoint

I'm writing a documentation wiki and I abandoned all the previous documentation except for reference.

The fibre maps are literal scans of scrappy pencil scribblings over the top of an ancient map (which was made for another purpose).

I took the best vector map I could find, tore it apart with Inkscape, rebuilt it (with the doors where they REALLY are, and things like that), named everything properly, grouped it into individual buildings and produced a bunch of SVG maps - one for each floor, one for each building, whole-site overviews, etc.)

Then I took the whole-site overviews, made it a fixed layer at the back of an SVG with its opacity turned down, and started to overlay CCTV, access control, networking, etc. over the top, one file per system. Every time I find another cupboard that the map says doesn't exist, or another doorway that's just entirely wrong and was bricked up decades ago, I redo the building map, copy it into the overview map, then update the overview map layers in Inkscape on all the others as and when I need to.

Already I've had marketing and the site departments ask for copies of it, because it's the only vaguely-accurate map they have seen. Hell, it's being used to show parking on the visitor sign-in system.

I am now an expert at manipulating SVG with Inkscape, putting them into the documentation, and solving problems with the original mapping and SVG file (P.S. if you want to publish an SVG on a website... remove all clippaths from the XML... you can just delete the tags. Then cleanup the file by adjusting the nodes of lines rather than using clippaths... you can use Inkscape CLIPPING just fine, but purge all clippaths from the SVG... you'll thank me later when it actually renders properly in anything using rSVG, including things like Chrome and most WIki and image-library software).

So much so that I diagrammed out my home solar install in the same fashion, and made something so good that I'm currently looking for a frame to put it in.

Lee D Silver badge

If the printer is near the fire, it's game over anyway.

But I literally couldn't think of any quicker method to get something onto paper... anyone?

Lee D Silver badge

Access control system - unusual manufacturer (South Africa based company), heavy investment on it on site.

Had the need for a firelist. By this time, every member of staff is using the system to tag-in, tag-out, and it's being (somewhat) misused on occasion to prove time and attendance.

We look at the official fire module. It costs a fortune, takes forever to run, has to be manually triggered, and produces print output. Useless to us, especially in a fire.

So I realise that underlying it is an antique Firebird database (which for those who don't know is a bit like SQLite in that it just logs to ordinary filesystem files that you can query with just ordinary file locking).

So I write some SQL and I write some monitor scripts and it basically watches out for the fire alerts (which do trigger a table on the system), builds the list of everyone on-site, and then I sent it to a thermal receipt printer that churns out the whole list in seconds.

It passes initial testing, solves our problem (which wasn't a CRITICAL problem, but it's certainly very useful to know that Jim actually tagged out of the site and so is unlikely to be burning to death in the building).

As with everything - feature creep sets in.

Within a year, the script is running 24/7, the printout separates people by area and creates perforations on the receipt so that each area can be torn off and given to the person with responsibility for that area to check they have everyone, the output includes a "last seen" time for when people tagged in once in the morning but haven't been seen since and cause confusion over whether they actually are in today or not, it stores the logs plus emails the output to a distribution list, lockdown functionality is added, and there's a second identical redundant system set up at the other end of the site to facilitate quick access to it from there, as well as a backup if one fails. The schedule for replacing the paper is incorporated into consumable replacements, etc. etc. And with some tightening, the first people know of a fire alert is actually the printer being half-way through a receipt printout because it actually outperforms the alerts from the system itself (so audio alarms happen AFTER printing starts!).

The system is now so integrated in processes that it basically is the fire rollcall system, and the suppliers who fit our access control try to buy it off me - because their customers are all asking for "this thing I heard about that this other customer of yours has in place".

Then I leave. All dues to the guy who took over from me, he can keep it running. But he's told them a thousand times that when it stops working, it's dead, simple as that. He has no interest in maintaining or supporting it (and I can quite understand why!). They go back to the company who tell them the price of the official firelist module - still got all the same problems (do you want to wait for a laser printer to warm up to print 20+ pages of A4 while the building is burning? Or would you rather grab a till-receipt from a machine that actually BEATS THE FIRE ALARM in churning it out), and it has tripled in price.

Also, they now need to "convert to the web-based version" which means replacing half the controllers and losing all such access to make your own reports (and quite a few other tweaks we used to do as well). So a firelist from the system is now basically impossible, unless you pay for a module that emails it in a single standard format (a big list of names in an A4 PDF) on its own schedule (cloud, remember) and no customisation whatsoever.

To my knowledge, it's still churning along and a vital part of the system. It was about 2-3 days of collective coding, plus two cheap receipt printers off Amazon. Oh, and there are plans to move it to a Raspberry Pi to keep the old desktops it ran on going. Hope that there are no architecture incompatibilities in my code!

Brit competition regulator will make or break Vodafone and Three union

Lee D Silver badge

Infrastructure should be nationalised.

It should be paid for by selling its services to consumers via privatised companies.

This way, we get the blanket, funded expansion of standardised services without companies rolling their own proprietary nonsense, interfering with each other, or one "gaining" frequency rights that the others cannot.

And you and I deal with any company we want to, with all of them having the same national coverage, but competing on price, service, support and deals.

Same for all industries - water network should be nationalised, water supply privatised (it would be nice to be able to CHOOSE WHAT WATER COMPANY I WANT TO USE, which currently isn't possible!). National Rail, private rail trains and services. National Grid, private electrical firms. "British Gas", and private energy firms. "British Telecom" and private firms overlaying their individual offerings over the national network.

All-nationalised is terrible.

All-privatised is terrible.

And switching the roles (privatising the network / infrastructure) is terrible.

Nationalise the infrastructure, privatise the resellers and services laid over it to offer to the public.

Gas supplier blames 'rogue' code for Channel Island outage

Lee D Silver badge

Re: Million to one chances ....

But what if it's not EXACTLY a million to one?

Squid games: 35 security holes still unpatched in proxy after 2 years, now public

Lee D Silver badge

*cough* SMOOTHWALL *cough*.

Excel recruitment time bomb makes top trainee doctors 'unappointable'

Lee D Silver badge

I'm gonna say it:

- Business processes should not be carried out in spreadsheets.

Spreadsheets are for financial tabulation (with double-entry, multiple-eyes, verifying totals, sanity checking large numbers, etc. etc.)

They are not databases and they shouldn't be used as such.

This extends from everything "just upload a CSV" to huge things with macros. None of that should be happening via a spreadsheet program.

We have a standardised database language format. Use it.

If you're conjoining seven different areas, you need a standard template, or an interface (e.g. gosh, maybe like a FORM that you fill in online!) at minimum. You also need one person who does nothing but collate, press and verify that data before handing it over.

I have seen multi-million pound businesses with a bunch of "critical" spreadsheets that have a 20-year legacy in them, not to mention storing the latest version as "FINAL.xls" (not even xlsx!) each year in a bunch of folders spread at random across a network and client devices such that version management and collaboration is almost impossible. And not long ago, either.

They had finance packages designed for their industry, they had every tool under the sun available to them, but no, it was all clunking along with Copy of Copy of spreadsheets with an archaic origin, manual formatting, horrendous formulae and plucking numbers out of the expensive finance system to go into Excel to then jigger about and put them back in.

And not just numbers - criminal record checks, staff lists, training courses, you name it.

EXCEL IS A SPREADSHEET. Use it like one. It is not a database, not a form interface (so people shouldn't all be "entering their data into a spreadsheet" directly for you!), not a financial ledger, and it's not an automation tool.

curl vulnerabilities ironed out with patches after week-long tease

Lee D Silver badge

Re: re: Stenberg admitted that the flaws found in curl...

As it says later on - if you want to volunteer, get on it.

The use-cases and options in something like curl mean you could easily spend several years trying to get there, and not be able to keep up with curl changes in the meantime.

Also, Rust, etc. are not panaceas and CANNOT act on untrusted data safely either. That's why you have unsafe(), etc. which is literally as bad as C but also can affect guarantees of "safe" Rust code near it in memory if they should fail or miscalculate.

When something is literally designed to act on untrusted data from the Internet, the number of sanity checks you would need are ... well... insane. And Rust etc. can't always fix those kinds of problems, or even deal with them at all.

It's why Rust is no good for device drivers, low-level kernel, memory management code, etc. - at some point in those tasks they have to act on untrusted data without a "type" and then form a well-specified type out of it in an error-free manner in order to be able to use it (e.g. DMA just gives you a memory address where the hardware is putting stuff). Those kinds of things require unsafe() code blocks in order to do, and unsafe is just as dangerous as C but with a false sense of security about surrounding Rust code built-in to it.

Sure, there's a lot that you can make safe in myriad ways, but you can also make it safe by using a safer version of C/C++ with a compiler that throws a fit at everything. And that's a far more viable outcome for a volunteer project than throwing out 30 years of development and starting again in a bug-free manner.

Your phone's cracked screen may one day heal itself, but try not to drop it for now

Lee D Silver badge

Well, at least he found a use-case for an iPhone.

Lee D Silver badge

20-something years of owning a mobile, keeping it in my pocket every single day with metal keys, never using a screen protector, dropping it down things like concrete staircases, and not once ever scratching or cracking a screen.

I honestly don't know what junk you're buying and/or what kind of childish "care" you're taking of your expensive phones to ever have cracked them short of running the damn things over.

Microsoft takes another run at closing Exchange brute-force security hole

Lee D Silver badge

Re: Hope springs eternal

You need to come up with a catchy name first, some sort of "local cloud" pun.

"Run your own Drizzle server" or something like that.

Scripted shortcut caused double-click disaster of sysadmin's own making

Lee D Silver badge

Ricardo needs to learn "not to run as root".

Because if it wiped out his boot sectors, that means he was working as an administrator - I'm not sure you could do that otherwise even in the 90's when you were inside the OS itself.

Also... always have a confirm script and/or an "if this is my test computer, then don't actually run these commands" in the script.

I caught one from my team a few weeks back where they were trying to use a script they'd copy-pasted to deploy disk encryption (rather than just group policy it!) to a bunch of machines... and the script meticulously:

- Generated a highly secure random key.

- Encrypted the disk with the key.

- Backed the key up to a file on the server.

I think you can see the problem with the order there.

To top it off, the script was supposed to be used to encrypt multiple machines and the "backup" involved echoing the computer name and key to a text file on a shared network location.

Bad enough in and of itself, but it used > instead of >>.

So now every machine that had the script run, would permanently overwrite the only record of all the previous computer's keys anyway.

The script never hit a real machine, tripping up on my very first eyes-on review and was immediately condemned.

In the space of a few minutes, we deployed an alternative that was vaguely sane and also checked to make sure the key was stored in a secured area before it then proceeded to encrypt.

FTC: Please stop falling for social media scams, you've given crooks at least $650M so far this year

Lee D Silver badge

Re: Meanwhile, here in the UK

As someone who reported several sophisticated attempts to take £100,000's from previous employers, including some of the best build-up to accustom people to their interaction, several live phone calls, very detailed supplier impersonation, etc. and each time stopping and recording it officially as a cyber-crime with reams of evidence...

Not once did we ever have any follow-up whatsoever. Not even "no conviction" or "radio silence so they could investigate", but literally not even someone bother to contact us regarding more information, gathering evidence, etc. etc.

I think the national cybercrime reporting sites just end up in a black hole and the data only ever used for statistical reporting.

Lee D Silver badge

There's a difference between claiming others are poor at spotting scams and the claiming that they are infallible.

For reference - I've never had a credit card skimmed, a single unauthorised charge, an online scam or compromise, etc.

In fact, step 1 of the plan for verifying scams in very organisation I have ever worked for is "Run it past IT if in doubt".

We are then the arbiters of whether it's a scam or not. We haven't got it wrong yet, and that's several different workplaces over decades.

Doesn't mean that we COULDN'T EVER get it wrong, it just means that we're much harder to fool.

And I've had things where I literally spoke to the scammers on the phone because the phone was handed over suspecting a scam, and as soon as they realise they're talking to the IT department, suddenly their enthusiasm evaporates. Whether that's trying to authorise a transaction, install some "remote support" software, or merely click a link.

Because we've been trained rigorously by cyber-security specialists, MI5 have shown us how to detect lies, or that we spent our lifetimes handling nothing by front-end, high-risk financial interfaces? No. Because we have a modicum of common sense and can spot a scam a mile away, and have the authority to say "Nope. That will not happen on my system." I've said that to the top level of the organisation, against their wishes. I have literally overruled "the big boss" that nobody says no to. By saying no. In some of those cases, it was "genuine", just extremely poorly handled by the other end, and in some cases it was an outright fraud trying to extricate £100,000's from our coffers. Still, I overruled until we were cast-iron certain things were legitimate. I never received any flak for doing so.

Spotting scams doesn't make you infallible, but it's not difficult to spot the vast, vast, vast majority of them.

And it's not wrong to call people stupid if they fall for obvious scams, and do so repeatedly.

(P.S. We run simulated phishing attempts in my organisation, from a sophisticated paid-for service... it literally reads your inbox, tries to make a "genuine" email from your contacts, and hides lots of the origin information to make it more viable. They are easily spotted for the most part, but you can tweak the levels, e.g. for the IT department. I will tell you now that the people with some of the most serious responsibility and power on the system are some of the easiest prey and users fall for some ridiculously obvious things - especially the newbies who aren't accustomed to their employer running phishing tests on them).

You don't need to be infallible to be not-stupid.