The Register Home Page

* Posts by Lee D

4951 publicly visible posts • joined 14 Feb 2013

Windows 11 update leaves Blu-ray and TV apps stuttering

Lee D Silver badge

DRM

Gosh.

DRM resulting in a sub-standard consumer viewing experience.

That's never happened before.

AI in your toaster: Analyst predicts $1.5T global spend in 2025

Lee D Silver badge

Automation

I recently bought heatpumps, electric heaters and a towel rail and went for a smart model of each.

However, in each case I made a very big point of also making sure that I can:

- Operate the device without any subscription.

- Control all the useful functions from the bog-standard infrared remote control.

- Control all functions from the device itself.

Now, if I *want* my heating to come on at 2 in the afternoon... I can do that from work. Very useful. Especially when Octopus announce a free energy session.

But if it doesn't work, or the service disappears in ten years time, or I'm in the bathroom myself anyway... I can just press the button to do that same thing.

AI and "smart" stuff is just automation. That's all it is. I don't need automation of every possible conceivable scenario. As you point out... I tend to use one. My washing machine is "dumb" and has arrow stickers pointing to the only program I ever bother to use. My dishwasher is the same. My oven literally has a child-proof cover over the temperature gauge because I don't need to change it 99% of the time and I was tired of it moving just because I brushed past it. My heatpump operates - now that it's configured - in two modes. Heat and cool (aircon). That's it. That's all I need. It's useful to turn them on remotely occasionally (e.g. coming home to a toasty house on a winter's day), and things like schedules, but that's it.

My brother has just bought a smart washing machine. I really don't see the point in that. Because you have to load the washing machine anyway... so you have to physically be there and do something. Sure, you can schedule it for late and night and it can tell you when it's done but... you can do that with much simpler things than smart functionality (e.g. timer and beeping). It's not like it can unload itself when you're not there. A bit like "remote start" car engines. Literally the next thing I do is sit in the driver's seat, surely, so... what's the point (P.S. it's illegal in the UK to leave a running car engine unsupervised, so no, "pre-warming" the car isn't legal). Or remote unlocking. I've unlocked the car... the next thing I do is... approach the car anyway. What did I achieve? Nothing.

If you want to automate things, that's great. But smart/AI has so little role in anything I ever do that I can't fathom why I'd ever specify it or pay for it.

Return on investment for Copilot? Microsoft has work to do

Lee D Silver badge

"AI"

I'll show you how convinced I am about Microsoft's repeated and persistent attempts to crowbar Copilot into literally everything without my consent or often knowledge...

I've just priced up a laptop for myself with explicit Linux compatibility.

I don't need AI, I have no use for AI and I don't want AI. And that should be respected, whether you *agree* with that or not. But Microsoft don't even want to respect that much.

Along with the Windows 11 horrid revamps, and the same old decades-old pathetic problems... I've had enough. Again.

Previously spent 10 years on Slackware (which ironically made a far-better desktop GUI at the time that almost everything else because... it just did what I told it to), no problems. The irony at the time was I was managing Windows networks while running only a Slackware home/work shared laptop for myself.

Now I'm doing the same again.

And I've been auditing the software I use casually as I've been considering this and... there are no blockers. Everything already works. Bye Microsoft.

Honestly, it's the constant UI "innovation" (i.e. "remove 99% of the options and you WILL have your taskbar centered") and the AI push that have pushed me away this time. Last time it was things like instability (e.g. Windows 95) and blue-screens and driver and performance problems, but this time it's purely trying to shove things down my throat that I don't want. It started with Edge (still prompts me and tries to intercept Chrome downloads and tell me Edge is better), and OneDrive (I have no interest in paying to store my files, thanks, that's why I have network storage), and now it's pointless UI changes and AI and things like forced updates and constant prompts to upgrade, etc.

And in a world where things are almost all web-based... it's a really dumb thing to be pushing people off your OS.

You're an OS. In fact, you're not even that, you're just a shell (for most of those things that interfere with my operations). You're there to do what I tell you to do. That's it. I don't want AI backchat, things telling me "you can't" or things popping up to tell me what they WANT me to be doing instead.

Why Microsoft has the name of an old mouse hidden in its Bluetooth drivers

Lee D Silver badge

You only have to browse the Linux device driver's code to realise:

So much shite only works in extremely specific circumstances, and so many things require quirks, workarounds, to pretend that you're Windows, to do things in a very particular order, identifies as another device entirely, has the same model/serial as something else that clashes, etc. etc. etc.

So little hardware actually complies to the specification that for some class devices (especially anything widely available and cheap like HID mice), there are often more workarounds than there are compliant devices.

And it applies to everything from plug in USB mice, to Bluetooth devices, to PCIe cards and even mainboard chipsets.

Campaigners urge EU to mandate 15 years of OS updates

Lee D Silver badge

Or just hold Microsoft to their "Windows 10 will be the last version of Windows" promise.

Starlink outage knocks tens of thousands offline worldwide

Lee D Silver badge

Re: The pickle-jam constellation

Only one man would dare raspberry me...

It's time mobile devs started to think seriously about foldable smartphones

Lee D Silver badge

Re: How much?!

Quite.

I had to seriously sit and consider a £400 phone as a treat some years ago, but it was one of the best purchases I've ever made (Samsung XCover Pro... still have removable batteries, headphone sockets, dual-SIM, microSD slot, etc.).

I see kids with phones that cost twice as much and they don't do anything on them. And when they inevitably break them, they just buy another stupidly expensive on, on contract.

(P.S. I've never broken a phone. The only phone I ever "broke" was my XCover... I was sure that water had got into it - it's supposed to be waterproof - and the screen had a permanent water puddle inside it that didn't move. I tried drying it out, but it wouldn't go away and it was a mild annoyance at best because the screen still worked fine. I just assumed the water had got into the screen and damaged it. Turned out it wasn't broken at all. When the phone was taken to a warm climate for a day, the puddle disappeared. I've always used it in a steamy bathroom or while walking in intense rain with no problems at all, don't know what was different about that one time.)

Lee D Silver badge

I cannot express quite how much I do not want, nor need, a folding mobile phone.

The same way that I don't even want a second monitor (or third... or fourth...) on my computers.

What I want is for you to make apps that work, on an OS that works, without worrying about nonsense like "camera notches" and folding screens and curved edges and .... all the other nonsense invented for no other reason than the "feel novel".

I would, however, PAY MONEY to be able to just turn off any AI junk, and account-based stuff, and uninstall ALL applications, even the so-called mandatory ones that I instead lob into a folder called "Junk" and never touch ever again.

ChatGPT: Why do most of your users ask for help writing – prose, not code?

Lee D Silver badge

Because people can't be bothered to read or write anything more than a couple of paragraphs nowadays.

The last time I was asked for a report (cybersecurity) by my employers, I was accused of using AI - which I'm vehemently opposed to doing - purely because it was: long, comprehensive, detailed, correct and covered everything they could think of to cover. Apparently "nobody does that".

And it's a trend I've seen grow even before AI... people just can't be arsed to read comments or documents that are longer than a couple of paragraphs unless they're forced to, or they do it as part of a larger group, etc. Hell, I meet increasing numbers of people who have never read a book, not even a short Terry Pratchett or similar.

But do you know what? Sometimes you NEED more than the basics in a document. I literally write up contracts and binding agreements as part of my job and everyone just assumes I'm copy-pasting or using AI to do so. No, I'm not. Because I actually *read* those things and I know what they need to say, rather than just relying on "Oh, you know what I mean, though".

There are also related reasons why people don't understand politics, the economy, what they're voting for, how credit cards work, how debt-collection works, etc... it's because they've never read stuff.

TL;DR: People are dumb.

Hack to school: Parents told to keep their little script kiddies in line

Lee D Silver badge

There are a number of problems with it.

Phones in classrooms for one. Most schools have to make the exception that staff can have them out to use them for 2FA which can then lead to problems with "I just took a photo of the kids showing me their displays", etc. on a personal phone.

And you can't give a kid a 2FA device, they lose them and break them. They can't use their phones (same reason).

Biometrics suck for that age-group (every biometric supplier I consult ultimately confesses that below the ages of about 13, it just doesn't work reliably because of body changes - facial, fingerprint, etc.).

Even passwords are too difficult for the younger ones.

About the only thing you can do practically is something like a Yubikey or similar... but that's expensive to deploy site-wide.

Lee D Silver badge

I remember in the 90's in my secondary school.

In Windows 3.1, they disabled Winpopup messaging because I wrote a program that could be used to chat across the network using it.

When they were still on Windows 3.1 they wanted to stop programs running from a network share because anyone could download (or copy off a floppy disk!) any executable onto a Z: shared drive, and run them - so kids were playing solitaire and running chat programs (and I wrote a chat program that worked by saving the chat on the Z: drive after they disabled winpopup).

I created a replacement shell executable that you could change the Windows 3.1 win.ini (or was it system.ini) to point at and it would just passthrough everything to the default windows shell UNLESS it came from the Z: drive, when it would block it with a message. It basically locked Windows 3.1 down much like software restrictions does now. It was AMAZINGLY advanced for the time, even if I say so myself. And it worked absolutely... the network manager tried it out and it literally locked him out of everything except the things he'd allowed... which included the tools to undo that change... fortunately he had a backup admin account!

I also discovered - because by then, I was made to run anything I did past the network manager - that he looked for rogue admin accounts with a timed script that listed all the admin users on their (I want to say Netware?) network. Knowing what that was doing by a single-look at the screen, I saw how it worked. When the computer studies teacher inadvertantly revealed his (awful and insecure) password, one kid (not me!) logged in as him and gave all the kids in the class admin rights. They all got in trouble. Except me. Because I knew it would flag. I did have an admin user, but I knew how to make it not flag (memory is hazy but I removed it from a certain group, and created an equivalent group instead?)

Later, they had a Windows 95 network, with some kind of proprietary (probably RM?) login front-end.

First thing I did was code up a pixel-for-pixel identical copy of the login screen, in Visual Basic... probably 3.0, which mostly functioned (even the help button was linked to a Windows help file etc.). But what it did was run, record the passwords typed, and refuse the login with convincingly identical dialogs.

Log in, run that program, leave it full screen, staff would log in, it would tell them they had the wrong password, they'd have a couple of goes, then use another machine, and I retrieved a txt file with their password.

This was used to make the case to force Ctrl-Alt-Delete to login, like Windows NT did.

I ended up, as a child, literally teaching my OWN CLASS - so when I was supposed to be being taught computer science, it was actually ME taking the lesson teaching everyone else in the class because the teacher didn't know enough - and they had me help them out and show their weaknesses. I honestly took my own A-Level computing classes and the other students treated me like a teacher for them, and my reports that year said they were afraid I was "neglecting the course content to pursue more advanced skills"... turned out not to be true, I was just fine, but bored with the course content because it was so dull.

I also had a roaring trade in the computer programmes I was writing for a TI-85, to the point that other students bought that calculator (despite it being stupidly expensive and unnecessary) just to play them in class. My link cable got a lot of usage.

Basically, I was an absolute nightmare for them at every turn.

I'm now a school IT manager for the last 25+ years. I would hate dealing with my younger self. Fortunately, the kids have very little interest in the actual, technical aspects of anything nowadays, and think that changing the local cached HTML of the BBC News page (via Chrome developer console) is "hacking" the BBC. But then, so do the teachers.

Lee D Silver badge

Re: Hang on a sec

Honestly, I work with a bunch of educated teachers, and they repeatedly believe that pressing F12 in Chrome, or loading anything that looks like a terminal/command prompt is "hacking".

‘IT manager’ needed tech support because they had never heard of a command line

Lee D Silver badge

Re: WTF?!

PRINT isn't the command for that... PRINT prints a txt file.

You mean

ECHO ##WTF?!?!##

Lee D Silver badge

They don't need to.

They just need to do whatever is critical that you do day-to-day to manage in your absence, or find a way to make that happen (e.g. hire a replacement that they are able to evaluate as being suitable).

Also, for those above you, you only need to be able to do PARTS of their job.

Lee D Silver badge

The word "immediately" is right there.

Lee D Silver badge

Re: Thus it is

That's just an attribute of being a manager.

I shield those above me from you.

I shield you from those above me.

That's how it works.

It is a necessary element to being a manager, but not on its own sufficient.

Lee D Silver badge

Sorry, but after 25+ years I've learned:

A manager should be able to do the jobs of those immediately below them.

A manager should be able to do parts of the jobs of those immediately above them.

They shouldn't BE doing those jobs, except in extremis, and they don't necessarily have to do everything perfectly or the same, but they should be ABLE to cope with that and understand that role.

Anything else is a nonsense that ends in disaster.

UK schools give system supplier Bromcom an F for Azure uptime

Lee D Silver badge

"And who the hell makes significant changes to a school MIS just before the start of term?"

ALL OF THEM.

ALL THE TIME.

EVERY YEAR.

Yours,

A school IT manager of 25+ years.

Lee D Silver badge

Don't know about Bromcom in particular but I find that almost all school MIS "online" versions are basically cobbled-together things run on Windows servers because they still just work like a layer over the original program, which is usually a nightmare of .NET Framework etc. that's actively maintained.

When they take them into the cloud, rather than actually making a full redesign in a web-based language, they just run the same program on the same servers and slap a web interface over it, often served not by any sensible web language but by the original program itself, just hidden away from you, or a mess of DLLs in IIS.

Almost all of them are just proprietary software running on a SQL database (almost exclusively Microsoft, because their developers never know anything else).

All that happens when they "cloud" them is they run a bunch of Windows servers set up in the same say as their prior on-prem servers used to have to be deployed, and often lump a few dozen client's data onto each machine.

If it was a true "web" MIS, you would be able to just deploy a clean server, fold it into a web cluster, it would connect to the clustered database with all their clients data, and it would just work again. The reason they have problems is that that's not how any school MIS I've ever encountered is actually developed on the back end.

The one I used previously to my current school actually had everything reliant on a "report server" (not school reports, but SQL reports) and what happened when you requested certain pages on the web interface was it ran off to the report server (which could be hosted in-house!) and had that run SQL queries, convert the information, and pass it back to the interface (local executable or web). The report server was NOTORIOUSLY unreliable and would jam up all the time because what it was doing was creating an Office document, filling it out with the information from SQL, and then returning a PDF etc. automatically. If there were Office updates, or any new things in Office that caused dialogs to pop up, or an error in the document... it would just hang the service with half-a-dozen instances of Word, etc. running in the background waiting for a response (as a user that you could not log-in interactively as). Changing the default printer to anything other than a Print-to-PDF printer would cause the report server to stop working. Because that's how it made PDFs... automating print to a virtual printer on the same server from Word.

The solution was kill the report server, kill all the Office apps on the server, restart the report server.

It was that common that I made a script to do it for myself, called it "Fix <company name's> mess of a report server AGAIN" and put it on the server desktop. At a technical user group meeting, a dozen people asked me for that script. They all had the same problem. Users would just go to, say, print a register and the whole MIS would grind to a halt for most operations because the Report Server had popped up a Word dialog that nobody could access.

They "went cloud" and forced everyone off on-prem instances eventually. And I discovered, through experimentation and talking to their tech support, that they basically just had the same report servers running in their datacentre and watchdog scripts to kill and restart them if they fell over or failed. Everything was just written in C# still. And that was after YEARS of redesign and upheaval in the migration to cloud.

Reg hack attends job interview hosted by AI avatar, struggles to exit uncanny valley

Lee D Silver badge

Re: If a prospective candidate expresses concerns about AI-based interviews ...

If you don't have the time to interview me as a human being, it's absolutely not a job I want, a workplace or person I want to work for, or anything I want to encourage.

Of ALL the things you could do.... sitting down for 5 minutes to interview a real person who you hope to impress enough to work for you is the absolute bare minimum that should be expected.

I would refuse any such AI-interview, as would an awful lot of people I know.

And, as a manager, I would refuse to ever implement such a thing as anything other than "additional" (to check some boxes) to my personal interview with anyone who was going to work under me.

I am by far not one of those "handshake and eye contact and let's meet in person" kind of managers day-to-day, but you know what? For an interview... I want to see you, the person, on your own, talking to me. For so many reasons that it's laughable to think that an AI interview would ever suffice, or even add anything into the process.

Lee D Silver badge

Yet again... "why should I bother to read something that you couldn't be bothered to write" comes into play.

And good luck with the HR process when you can't even desribe the criteria and processing used to ensure it was done fairly.

GNOME Foundation boss exits after just four months

Lee D Silver badge

"Mutual"

"Mutual" = we wanted rid of them and they wanted out.

Otherwise you'd get the "we're sorry to see them go" speech.

Supermarket giant Tesco sues VMware, warns lack of support could disrupt food supply

Lee D Silver badge

Hey, Tesco, do Oracle and SAP next.

I'm not a customer of any of them, I just think they need to be taken down a peg or two and Tesco has the oomph to be able to do that.

UK datacenter developers turn to gas rather than wait for grid power for builds

Lee D Silver badge

Re: Hmm

You can have all the energy you want.

The only pertinent questions are:

- What are you willing to pay for it?

- Who is detrimentally affected by providing it?

Which tell you why government aren't doing it.

Honestly, I think we should just charge a huge premium on any large and unusual power usage, regardless of the unit rate being charged. Literally a "high-user tax" on it.

Then watch as all the datacentres scramble to buy more efficient systems and/or supply their own power rather than just keeping buildings full of floors full of racks full of servers full of cards running at maximum 24/7/365.

Defiant Broadcom calls for tech to go back where it belongs: On-premises

Lee D Silver badge

Broadcom - like Oracle - has no say in my systems or how they're deployed.

Precisely because of their previous behaviour.

And everything goes in cycles.

Consolidated, distributed, thin client, fat client, external service, on-prem, it's all going to go on the same 10-20 year cycle as everything else, as people hop from one to the other because the thing that's "bad" at doing X will make them move onto the thing that's "bad" at doing Y, and then vice versa, rather than accept X or Y or find a middle ground.

Honestly, I lose track of how many times some things have been through that cycle now.

One long sentence is all it takes to make LLMs misbehave

Lee D Silver badge

Did you read the article?

Where the AI's guardrails are eroded more the longer the query is? Because the AI is the thing implementing its own guardrails via analysing the tokens it's being given, rather than an external factor strictly limiting them before they can reach the LLM, or where an external factor filters the LLMs output to make sure it's not breaking out of its own guardrails?

Lee D Silver badge

Having the AI implement its own safeguards on tokens is like having a self-regulating, self-assessing water industry.

Doomed to failure.

Microsoft puts the squeeze on onmicrosoft.com freeloaders

Lee D Silver badge

Re: spam coming from inside

I use unique email addresses at my domain for everything I sign up for.

This tells me immediately who gave out my addresses, just by looking at what address the spammers sent their email to.

In my time, I have had DOZENS of companies spam addresses that were only ever given to one company.

This includes places like Scan.co.uk, RM (hilariously that one was actually stolen by a former employee who then took it to an educational furniture reseller and used it as their customer list - I know because they confessed all when I asked this random company how they've got an address that I'd only ever given RM), SecurityFocus (remember them?), Tagadab, PizzaGoGo, Macromedia, CheapFlights, WordsWithFriends, etc.

And those are just the ones which got so widely spammed that I blocked any reception to that email address ever again. For reference, I have never once allowed someone to use my address for "3rd parties", etc.

Emails get spammed because companies don't protect those emails from their employees, and the employees sell them on or literally take their customer list to their next employer.

The bigger irony? All those emails eventually end up at GMail - that's what I use for actually managing my email. And I can tell you that I get a thousand times more spam addressed to my GMail account directly (which has NEVER been used/advertised) than anything else. To the point that I'm now considering just running my own webmail now.

As I've said before, companies are obligated under GDPR to not provide data which their employees do not require access to, and that really means that they shouldn't just have customer databases that allow arbitrary queries, and show all the customer information, and most certainly that that information shouldn't be capable of being stolen en-masse. But I promise you that nobody actually does things properly in this regard (e.g. me calling up a company shouldn't need them to see my address, phone number, or email whatsoever - not even to send a delivery, message or call me. That can be done without the end employee actually seeing that data unless - explicitly - I ask to change those details or they need to verify them, at which point JUST THAT ONE FIELD should be visible to them). It would instantly stop a lot of customer data theft like this if it becomes actually difficult to suck out thousands of customer addresses and provides a great big red warning of an audit trail to do so.

Your email is being stolen from Microsoft, but most probably by one guy in a call center somewhere on minimum wage with full access to customer details that he shouldn't have. As more of our data goes cloud, gets outsourced, etc. the problem will only get worse without effective data privacy controls.

I once signed up for Microsoft volume licensing and the entire sign-up was electronic. I later enquired what was taking so long and it turned out that someone had mis-spelled the email which we'd asked for it to be sent to. An email we'd only EVER sent electronically and with the correct spelling. It was literally the case that, somewhere in the world, someone at Microsoft themselves was PRINTING OUT AND TYPING IN volume licensing administrator email addresses by hand. This was also not that long ago.

The Unix Epochalypse might be sooner than you think

Lee D Silver badge

Re: It's different this time

True story:

Once walked into a customer's network that, overnight, had literally just stopped.

It was one server running a school (normal in those days) and it just wouldn't do anything. Frozen.

Hard-rebooted it. Booted into Windows. As soon as it got there, same thing. Safe mode: same thing.

Services would work and the thing would ping for a few seconds but once it got into Windows it would just all stop.

No problem, restore from backup. Yesterday's backup: same thing. Last week's backup: Same thing. Last YEAR'S backup: Same thing.

No way, because those backups were FINE and were tested and restored perfectly just recently.

Tries a Live CD... server was fine.

After much hair-pulling, I found a hint in an online forum.

Turns out that the APC UPS software was written in Java. One of its JAR files held a certificate. That certificate silently expired (and no way for a customer to renew it anyway). When it expires, rather than just error, the APC software absolutely jams the server up so hard that you literally can't do anything, not even get a ping out of it.

The fix was to modify the filesystem in another OS and remove that JAR, then the software would just stop working rather than mess everything up.

Then you could uninstall the UPS software and install a later version and it would be okay... until the certificate expired again, I suppose. I had a very annoyed customer over that one, because they were entirely down and there was nothing obvious at all, and backup restores are NOT things you can do quickly, and a few of them and STILL no success? Nightmare.

In other news, a very important MS certificate just expired and people have been scrambling to fix it, but fortunately that doesn't bring your machine to a grinding halt and Windows Update mostly takes care of it so long as you update regularly enough.

Microsoft continues Control Panel farewell tour

Lee D Silver badge

Re: It might be just me...

I don't mind what they do in terms of UI but don't make it so that there's some setting that WAS in control panel and no longer IS in Settings anywhere.

Drives me mad to have to jump through hoops to get back to the old interface because that's the ONLY place to set certain things... and they KNOW it because they literally take you there from Settings if you dig deep enough looking for the damn thing.

I guarantee it happens every time they migrate any settings. Like network adaptor settings... you end up on the old "control panel" network interface because it's the only place to configure protocols, gateways, the network driver etc. but rather than migrate those settings, they just lead you a merry dance trying to get to them.

Microsoft crams Copilot AI directly into Excel cells

Lee D Silver badge

Re: How about...

I can kind of see why they might work that way.

But there's no excuse not to just have two checkboxes on export that let you change those options.

As ever with Microsoft, it's their way or no way. Where a simple option selection would actually PLEASE millions of people.

P.S. I'd like my start menu back please, and the taskbar to be draggable again.

Lee D Silver badge

Re: Is nothing sacred?

The best bit is when people have their businesses running on spreadsheets with this nonsense without even realising they are reliant on it, and either the response changes, becomes pay-for, or Microsoft discontinue this functionality entirely.

IETF Draft suggests making IPv6 standard on DNS resolvers - partly to destroy IPv4

Lee D Silver badge

Re: No mention of NAT, then?

The whole anti-NAT thing really hindered IPv6 adoption for a completely UNRELATED technology.

Give me a billion addresses and I'll deliberately NAT through one of them. I know I will because I'm sitting in a workplace with a leased line with an allocated subnet and that's exactly what we do on IPv4 anyway.

Anti-NAT sentiment literally held everyone back. Why?

Because I could have transitioned a single NAT router to IPv6, at home, in my workplaces, etc. and that would INSTANTLY allow all external connections to move to IPv6 only. What do you CARE what I'm running internally? Any problems that causes are MY OWN.

But the easiest way to transition to IPv6 is to change the router first, and retain IPv4 on everything internally, then moving everything internal at your own pace.

But no... that wasn't "good enough"... we had to utterly abandon our network numbers force huge routing tables into our devices, replace all the simple numbering with more complex numbering, modify EVERY device internally and allow direct routing to every internal IP.

Just no. The very suggestion was ridiculous and (rightly) ignored by ABSOLUTELY EVERYONE, to the detriment of IPv6 adoption.

And now what is our solution? CGNAT. Who cares about that? Almost nobody. Your phone is being NATed right now, I guarantee it. My 5G phone gets internal ranges like 10.x.x.x on it's 5G connection and they are NATed to the Internet. Nobody gives a damn.

The reason there's no mention of NAT? They finally realised that they utterly cocked up by tying anti-NAT sentiment to IPv6 and that it badly hurt adoption.

There's no reason on earth we couldn't give everyone an IPv6 NAT router for their home network which does 6-to-4 and 4-to-6 translation as necessary. No changes required to anything at home whatsoever. But suddenly you can then convert all the ISP backbones to IPv6 only and nobody would even notice.

Lee D Silver badge

Re: ISP Hubs

All of them use IPv6 on the backend somewhere because it's required to support 4G (LTE) and/or DOCSIS (cable networks) and other protocols.

Virgin really pee me off because even their leased lines have NO support for IPv6.

(Any suggestion to use proxy services, 4-to-6, 6-to-4 etc. is a nonsense, by the way)

Something like 50% of all queries to Google come in over IPv6.

https://www.google.com/intl/en/ipv6/statistics.html

Because people don't even know they're using it.

What we need is a government mandate - like they issue for schools and other industries regarding IT technologies - that all UK ISPs must support IPv6. That's all it needs to say. Not deprecating IPv4, not supporting ONLY IPv6. Just that they need to support IPv6.

The problem would solve itself overnight.

It's not the DNS servers dragging their feet, or the OS support, or the devices, or the protocols, or any incompatibility, it's literally the content providers (*COUGH* THE REGISTER *COUGH*) and the ISPs.

Content providers cannot go IPv6 only while ISPs do not support it (but they could damn well start supporting it, after nearly 15 years of people complaining about it, eh, Reg?!)

ISPs could easily support IPv6 in a second, and even provide some 4-6 and 6-4 services for their customers to make it absolutely seamless (much like they cut off phone lines for VoIP services, just do the same and give all your customers IPv6 and the appropriate conversions to allow them to get to IPv4 services seamlessly).

But it's the ISPs that have to move. The DNS is already there.

Yet again, the block on this is really BT's pseudo-monopoly remants on home landlines. Mobile services are already there and you're probably using it without even realising (that's where most of the 50% of Google searches using it come from). And places like Virgin and alternative providers will need it mandated too because they probably won't see it as a competitive service to offer even if BT networks provided it.

I've yet to see a single UK ISP connection, business or personal, that actually just supports IPv6 natively and gives you an IPv6 IP when you ask for one. I believe A&A are the only ones that say they'll support it, but nobody I know can afford them for home use and because they're not a primary provider, no workplace I've ever worked for uses them.

If you want IPv6... get the government to give BT a kick up the backside. The same's been true for just about everything for the last 25+ years.

You've got drought: UK gov suggests you save water by deleting old emails

Lee D Silver badge

Or you could charge the heaviest commercial users more given that they are having the largest impact on those people who need water (i.e. small-usage residentials) and have the most money with which to fund this stuff.

It's a nonsense that I can't water a 3m x 3m garden with a hose, but datacentres can slurp whatever the hell they like.

UK unveils plans to 'transform' the consumer smart meter experience

Lee D Silver badge

Re: Not so smart

By the time everyone is on smart meters, most people will be on solar anyway.

Honestly, just over the last two years, the EXACT SAME kit I was buying is nearly half the price it was, and it was already some of the cheapest things there were (batteries and panels).

The ones who can't do that - and even councils are moving people to solar and heatpumps - are likely on a pre-pay meter or a private landlord anyway, so they'd struggle with doing either.

But honestly, I'm now planning my retirement (~20 years out) around the fact that I won't be using grid electricity by then.

And though there's nothing new in being able to cut you off, really, even without access to the property - the barriers were mainly legal, not physical - via my smart meter I've had 4 hours of free electricity (as much as you like in those hours) already... because we're basically throwing electricity away when it's sunny and dry. The last few weeks, all my chores were done during those hours, and I charged my solar batteries to make as much use of it as possible. I literally tripped my RCD because I turned everything on and even did things like charge my drill batteries and suchlike. I even thermal-camera'd my fusebox - which is rather old - to make sure there wouldn't be a problem if I did pull a lot of power in the winter.

And Octopus keep linking to this:

https://wastedwind.energy/

We're basically throwing energy away now. Cut you off for it? They're more likley to be begging you to use it or forcing you to stay connected to the grid. They have a MASSIVE investment in the grid, and we're all going to start fulfilling our household's entire energy needs in a few years, and I wouldn't be surprised if they started introducing taxes on electricity because of - say - electric cars. To make up for the fuel tax disappearing, and to then charge people by their usage at home even more. Whether or not they have an electric car.

I need 8KWh a day. I basically have that in batteries already. My roof can take at least 24KW of solar. Multiply by a minimum of 8 hours of sunlight per day, and cut it DRASTICALLY for the winter months... and I don't think I'll care about the grid in another 5 years, let alone 20. My heatpumps take ~200W to cool/heat my rooms to 20C, even in the depths of winter.

The only thing I'll need a lot of power for? An electric car. It's likely to be the only reason I bother to keep grid connectivity. But even that wouldn't be "essential". I'd have enough power in the house to get it going, and could just pay at an EV charger somewhere for the rest if needed.

Lee D Silver badge

Re: who is it smart for?

The credit thing?

I moved to a smart meter and OVO still kept over-estimating my bill by ridiculous amounts. The question "why are you estimating at all, when I can literally see my half-hourly smart meter data in your portal and it's accurate?" went unanswered.

After the second such bill, I complained formally.

After the third, I told them that if it happened again, I'd be escalating and moving supplier.

I changed supplier shortly after. They were collecting 30-minute readings of my meter, yet were charging based on made-up numbers with no basis in reality.

The reason, as has been hinted at, is that they can then use that money to earn interest and then "pay you back" any extra you paid about once a year. But not the interest.

The long-term fix is really simple: make it so companies cannot earn interest off funds held on behalf of the customer (or if they do, that that interest is paid to the customer)

But my short-term fix was even simpler: I moved companies, filed a complaint and OVO paid me my money back, plus had to pay me for not billing accurately.

See, we can complain about smart meters forever but actually they don't really hurt consumers at all (which is one of your points, really). They don't necessarily help much, but they don't hurt.

But being able to prove that OVO had their own, accurate readings that they were literally ignoring? That's invaluable.

I did something similar with my water company, forcing them to put in a water meter. Turns out that I use ONE-TENTH of what they were charging before I had a meter. Literally a 90% discount. I'm technically still using the "accrued credit" from their old billing 2 years later, because my bill is so pathetic now that no further payment has been necessary yet.

Let them put in their expensive calibrated meters. It really makes no difference to me (and on Octopus, I've had four hours of free electricity usage so far this year - which is only possible when you have a smart meter. I used them to charge my solar batteries to the absolute max, so all my chores, charge all my tools, cook dinner, etc.). And even going by my own analysis of that data (I pull it all into a spreadsheet) over two years, there's no "energy saving" and there's no privacy problem. I have graphs of everything and you know what? I couldn't even tell if I was at home or not from it, and I know the answer! Beside the fact that the base load varies by local temperature (e.g. heating, fridge, freezer, etc.) more than anything, I have a load of stuff that turns on rather randomly (e.g. NAS) and stuff that pulls power if I touch something from my phone (e.g. aircon controlled / scheduled remotely) AND I have a solar & battery install that's not grid connected but - via an ATS - takes load off the house if it's got power. There's no "smart" there, but it totally screws up any stat analysis you might do because it'll suddenly dump a huge load back onto the house, or it'll keep it running all day and night without a problem. And that depends more on the weather too.

So I have no problem with smart meters. I'm more interested in it saving me having to be home for a meter inspection (strangely, OVO keep insisting that my meter needs checking when I've not been with them since 2024 and all the previous hassle is long settled) or some such.... hell, I take photos of the meter readings and check it tallies with my spreadsheet most weekends (hint: It does. It always does) so I don't save anything in that regard.

But they do act like a perfect undeniable record of what I should have been charged, that not only my supplier and myself, but anyone I authorise has access to (it turns out you can give USwitch access to confirm your usage for comparison shopping between the suppliers, who knew?). Tell me why you're billing me £1000 this year when I've clearly only used £600 in electricity (real-life example). As a mathematician, OVO's "annual estimates" are based on some ridiculous formula that bears no resemblance to reality whatsoever... I know, because I'm sitting there with two years of data and their bill and there's no correlation whatsoever.

I'll have them just for that.

Top spy says LinkedIn profiles that list defense work 'recklessly invite attention of foreign intelligence services'

Lee D Silver badge

Re: Job offers

Nope, that would flag on police checks and they were pristine.

Lee D Silver badge

Re: Job offers

True story:

Once wanted to hire a guy but he had a weird gap on his CV. They had to explain, without explaining, that they'd been doing something protected under the Official Secrets Act. It wasn't anything high-level, as far as I could ascertain, but it was covered.

Okay. Fine. That's no barrier in itself. Sure we can get round that.

But it proved absolutely, categorically impossible to get ANYONE to confirm that he'd worked anywhere at all in that time. Obviously he knew where he had worked. He spoke to (or tried to) his bosses there. He couldn't get a damn thing out of them, and neither could we.

Not even "this person was in the employ of X during this time". Nothing.

Sadly, our industry restrictions mean we have to have a complete history of employment, especially recent employment, so I was forced by HR to remove him from consideration.

He was clearly tired of getting that response because he'd had it everywhere he'd gone, and he had been by far the best candidate.

You'd think there'd be some way, even if it's very brief, to confirm that someone had been in the employ of SOMEONE official and this could be confirmed at a government level, the same as the police checks etc. we're required to run on everyone. Even if it had zero details. But no. Nothing. Just a blank space. No responses. Nothing.

He COULD have been lying... that's how little evidence we could obtain from anyone whatsoever (but I think that if he had been lying, someone, somewhere would be having words with us and him about that). But that means we also couldn't - as per government requirements for our industry - confirm that he'd been employed or that he hadn't, say, been sacked for inappropriate behaviour that would exclude him from consideration for working in our industry.

I mean, I know that's how that kind of thing is supposed to operate, but it's ridiculous that one government rule basically prohibits us ever hiring him because of official government secrecy that was nothing to do with the role he was applying for.

I told him that he was better off not applying to our industry (because everyone would tell him the same) and that if he ever got another job and built up enough work history there that could be disclosed, he should get back in contact with me. I'd hire him in a second.

Amazon’s Kuiper satellite broadband to offer commercial services in mid-2026, at least in Australia

Lee D Silver badge

Re: Kuiper

Nope... I've tried and pre-registered with all the ones working the local area should they ever offer service.

As I say, at this rate, FTTP looks more likely as in that case they (Gigaclear) are actually doing some works as I speak and rolling it out to nearby villages.

Lee D Silver badge

Kuiper

They just need to get on with it.

I have perfectly clear skies, with a huge horizon view, for my rural little house, and a router capable of balancing half a dozen different connections.

But I'm not ever giving my money to Starlink while they are still in the employ of the nazi-twit, and everything else is ridiculously expensive.

As it is, I've been waiting three years for it with the direct intention of getting it as soon as it's working for my area, but nothing of substance has happened, or even been released. Like it would be good to know an indicative price, and maybe what the terminal costs, how big it is and how it connects (please no "wifi-only" junk for consumers). I knew about it before that and actually factored it in in case my broadband was awful. Hell, even a trial, a review from an early-adopter, anything.

At this rate, I will actually have FTTP before I see Kuiper and given that I live in the middle of an Area of Outstanding Natural Beauty and Special Scientific Interest... that's quite poor.

Honestly, I couldn't get more open skies and fewer buildings near me. It's simply not possible. LEO satellite broadband is ideal. But at the moment there's one viable option and it's run by someone who I refuse to do business with. Literally a open-goal for any sensible competitor.

But it's been pretty much radio silence for the 4 years I've been looking it at as an option with the specific intention to purchase.

Virgin Media scraps wholesale network rival to Openreach

Lee D Silver badge

I am increasingly of the opinion that the only way to ensure I can get a decent, reliable connection is to buy several technologies and use them together in a redundant manner.

As far as I'm concerned "BT" and anything involved with it is one single point of failure.

I have an expensive Draytek router that can do Ethernet, VDSL2, and 5G directly. That gives me all kinds of options because, clearly, there isn't going to be any regulation in any one area of Internet connectivity for a long time to come (and it's already been too long).

I thought that scrapping traditional voice service would be it, but apparently not. I'm now with an ISP who couldn't give me a voice service (I don't care, never use it) except VoIP and the line only does DSL. But it appears that any kind of competition / regulation just isn't going to happen in this area. So I have 5G and if Starlink wasn't Musk-borne I might have that too (I'm in the perfect area for it with stupendous clear-sky access). I'll just have to wait for Kuiper, I suspect.

But this week there was hope. Gigaclear are running FTTP lines into my road and down my road (but I don't know if they will come as far as my house, even though it's a tiny road). That'll be a good "third option" if I can get FTTP.

Ironically, I now have better connection in the middle of nowhere surrounded by fields, in an AONB and SSO, miles from anything than I did when I lived inside a major town that you will have heard of, inside the M25, a stone's throw from the town centre. If Gigaclear comes in too... that could be a 1Gb line direct to my door. And given the constant power cuts in the area because it's so rural, that might well be the last to fall over in my area.

It's just pathetic how any kind of regulation, market management, etc. that's been posited for decades is just overtaken by actually just waiting for something new to come along entirely. We could have all had FTTP decades ago, but we're apparently too scared to just nationalise OpenReach and make it do its job.

Zed code editor hears your prayers, rolls out AI-free mode

Lee D Silver badge

I used to work on a single-floppy Linux distro that turned an old PC with network cards / modems etc. into, basically a router.

1.44Mb to boot the OS, have drivers for all the possible networking, and then do all the NATting, routing and everything else necessary as well as be a DNS caching server and all sorts of other things.

I remember being quite put off when people started publishing 2.88Mb boot images, and then later ISO images of it.

Now 1.44Mb is probably not enough for the HTML/CSS/Javascript on this comment posting page, without even the images included on it.

Ransomware gang sets deadline to leak 3.5 TB of Ingram Micro data

Lee D Silver badge

Re: Basics?

I worked at a place that had ransomware, but we were being asked to prove that data exfiltration never occurred.

It's extraordinarily difficult to prove such a thing.

In the end, the insurers and cybersecurity forensics, etc. people as well as the ICO were satisfied because we just happened to be in the middle of an ultra-quiet period, almost nobody was on site (COVID), and this showed on the networking stats, and our backups were clean (they managed to delete some backups, but the ones they couldn't get to were clean of the ransomware).

It was only sheer luck that the thing they hit was on a server cluster, that server cluster was running a software router (Smoothwall) as a VM, and hence as soon as they affected its storage, the router (including the primary DNS, default gateway, all the inter-VLAN routing, etc.) shut down hard. That immediately stopped any exfiltration being possible without knowing the REAL gateway address on an entirely separate VLAN that only the Smoothwall used and to which all the actual physical upstream connections were forced onto at the networking ports. No other ports were configured to allow that VLAN to be accessed or routed to, even if they tried.

It was pretty simple to determine that, before, during and after the attack took hold, there simply wasn't enough data going over any of the connections to do anything in terms of significant exfiltration.

A weird combination of cloud-managed switches with full stats, and a software router as the primary gateway for EVERYTHING, saved our backsides from having to notify thousands of people that their data may have been exfiltrated.

As it was, to this day, nothing has ever come of that, and we believe that even the ransomware responsible wouldn't have had time to call home or get remotely-controlled. It was introduced by someone plugging in an unauthorised USB stick - which we know from logs - with a zero-day detected malware, that 2 years later STILL did not appear on any antivirus check as malware... our cyberforensics specialists kept checking and submitting and it always just passed straight through the AV, which is how it was able to infect us. The timing between the USB stick warning, and systems dropping off the central AV dashboard - starting with that PC - was seconds. It was able to then get into the servers, and from there escalate into the cluster hosts itself within a minute. And then everything went off because the primary gateway for ALL VLANs had been knocked offline by it doing so.

But it wasn't able to talk home and its automatic actions were to shut down the only way for it to talk home by encrypting the cluster storage and then demanding Bitcoin to an address to get the key to unlock.

We basically had an unintentional automatic lockdown because of the design of the system (which was necessitated by simply not investing in IT for a decade).

(We clearly just wiped the entire network, changed all credentials and started again extremely carefully, no ransom was paid, no data was exfiltrated).

Lee D Silver badge

Re: Basics?

50 minutes on a 10Gbit leased line.

A terabyte is literally pathetic amounts of data for a large place like that and I guarantee they have way more than 10Gbit.

Plus... nobody is looking for, or will notice, slower data extraction. That blip wouldn't even SHOW on the networking of your average primary school (which are now being required to have 10Gbit leased lines), let alone a huge IT company.

And even looking for it... they're already inside, they've only got to talk an SSL session out to, say, Azure or Google Drive and how would you tell that from Marketing uploading a video to their OneDrive? You wouldn't.

Honestly, it's just not the kind of thing people can spend resources looking at, because the false positives would be humungous. Do it out of hours, in slow trickles, etc. and you would never tell.

Microsoft used staff in China to help babysit US govt cloud services, report says

Lee D Silver badge

Put things in cloud.

Realise that all the things you put in the cloud are now ephemeral to you and Microsoft can run off and do silly stuff that you never wanted them to do and you'll never know about it until they confess.

Dumbest idea ever. Completely predictable too.

Any government cloud should be operated on an entirely government-controlled isolated system with appropriate access controls and vetted staff throughout.

The cloud really is going to take a massive hit at some point and everyone is going to run for cover back to on-prem and isolated systems again.

Until 20 years later when they've all forgotten about that and "hey, it's fine, this is holographic cloud, it's not the same" and the cycle will repeat again.

Under-qualified sysadmin crashed Amazon.com for 3 hours with a typo

Lee D Silver badge

Re: Logs

Same for RADIUS logs on Windows.

Put them on a separate drive, they manage themselves and delete themselves when full.

Put them anywhere on C: and you will regularly find yourself with no space on the boot drive and failing services etc. because of it until NPS decides to clean them up.

Please, FOSS world, we need something like ChromeOS

Lee D Silver badge

So what you're saying is that your American car wouldn't fit in a British garage, bu you'd be able to fit even more British cars in your American garage? Because they're inherently different standards?

I don't think that's the argument you wanted to make on this particular comment.

Lee D Silver badge

" Like them or hate the Microsoft, Apple and Google all have an OS that comes pre installed with a (mostly) usable and consitent interface. Applications can be downloaded and installed from the corresponding App Store. Updates happen with no interaction and within reason for the majority of users there are no issues."

Ubuntu Desktop which has all the above you just listed.

Sure, there may be a plethora of choice, but if you can't search and find a "beginner" linux distro with one search, then literally everything else is going to be beyond you anyway.

Hint: You can install Ubuntu Desktop from Hyper-V Quick Create if your Windows edition is high enough.

Microsoft patches under-attack SharePoint 2019 and SE

Lee D Silver badge

There are models of car that have been very publicly vulnerable to USB/Bluetooth attacks to the point that the criminal fraternity targetted them explicitly and insurers started to refuse insurance for them.

Doesn't make either situation any better, but modern life apparently now means "we don't give a damn, you've already paid us".