The Register Home Page

* Posts by Lee D

4951 publicly visible posts • joined 14 Feb 2013

Dodgy parking firms to be denied access to Brit driver database

Lee D Silver badge

Re: dodgy parking companies

For all the fuss people make about parking, I have literally never had a problem.

Mainly because, if they have stupid rules or payment systems, I just don't park there. I'll literally park miles away and walk instead, or just not bother.

I'm sure that this attitude achieves only one of two things a) the landowner gets what they intended and I don't park there, b) the landowner loses out on potential revenue because they're overbearing and I don't park there.

Neither of which I really want to change.

For instance, in any of the towns I go to, I have a nominated car park that I always park in because they are the one that don't have stupid junk. Ticket-in, ticket-out ones are normally the best, because then I have a timed, dated, stamped, paid receipt (and now that the TITO ones also auto-recognise your number plate you get to keep the receipt more often than not). Pay-and-display are open to interpretation, abuse, etc. but with a TITO one you can't argue about when I arrived, when I left, and you can't go around sniffing every car to see if you can pull it for being a second over because the ticket isn't even on the car anyway. There's almost no point patrolling a TITO car park, except to find abandoned cars (which will flag immediately on your database anyway after 24 hours, so you know exactly what you're looking for).

Plus, I have a dashcam for this purpose too. I even like to park near the signs if I'm forced to use a pay-and-display so that I can get those on camera too.

To be honest, though I don't doubt there are unscrupulous people, those are easily combated by the vaguest use of a personal record of any kind. Everything else, like speeding fines, is an idiot tax on people who park where they know they aren't supposed to. I still chuckle every time I see someone arguing with a traffic warden despite clearly being in the bus lane / on the double-yellows / etc.

Sysadmin crashed computer recording data from active space probe

Lee D Silver badge

Deployed an MSI package with a space in the filename to an RM Curriculum Connect 3 school network.

All CC3 software packages are installed as an ordinary MSI, just with paths to things like shared icons, configuration files, etc. put on certain drive letters. Educational suppliers would often supply them if bothered, but they were easy enough to make yourself and you could also use their "Discover" software (which was basically just Wininstall with knobs on) to create one for any bit of software. All the complicated bit went without a hitch, and I got a working MSI. Decided to rename it something sensible before deploying it.

Put it into the management console thing, pushed it out to a handful of test machines (I'm not stupid!), left for the day.

Came back in to someone screaming that everything was down and they'd had to call out RM support. Turns out, if you had a space in the filename (and we're talking Windows XP/Vista here), their crappy software that decided WHAT packages to install couldn't parse the list and so the next time ANY computer (including the server) rebooted it, it would crash on boot while that software ran to see if it needed to install anything. Literally took down every client on the network, plus the server when some bright spark thought they'd restart it.

They tried to blame me but literally NOT ONE WARNING to the effect of "don't use spaces" existed in the documentation, not one check in the deployment software, nothing, at the time. But, hey, they released a patch pretty damn quickly after effectively having to rebuild every client and patch up the server to remove that package from the list. P.S. after the patch... the package I made worked flawlessly for years.

Apple whispers farewell to macOS Server

Lee D Silver badge

Macs were never servers.

I have two Mac Mini "servers" (as sold to my employer) sitting next to me. I mean... come on... one hard drive, not even proper RAM, nothing. You couldn't rely on them to do anything at all. And if the only difference was a £25 software upgrade, you know they aren't going to be anything special. That's pretty much why they had to buy two... just in case one went pop.

Literally, I turned one off several years ago because at that point MacOS clients could directly join to LDAP without all the OpenDirectory / golden-triangle junk. The other is kept running because it supervises our iPads but even that I'm regretting (and, in fact, we're scrapping iPads too). If I could, I would gather them all in, wipe them all out and supervise them on an online service (Google Apps lets you do it).

Neither devices were my choice of hardware, but certainly classing anything Apple as "a server" is a complete lie. And, yes, I have had RAM and disk failures in them.

Good riddance to a complete misuse of the word server.

Ever wondered why tech products fail so frequently? No, me neither

Lee D Silver badge

Re: C64 Joysticks

Daley Thompson's Decathlon cost me two Sinclair Interface Two's, two edge connector repairs and no-end of joysticks.

Damn game.

And only because it was the closest I ever got to playing Hyper Sports, which I used to coo over because it looked so fun (hint: still is, but the weightlifting event is just RIDICULOUSLY difficult).

Ex-staffer sues UK's DWP, claims superior blabbed confidential medical info

Lee D Silver badge

I've worked in plenty of places were people were let go for being off-sick long-term.

If you're off-sick it means you're not fit for work.

If you're not fit-for-work long-term, then it means you shouldn't be doing that kind of work and they shouldn't be insisting you do.

Just because people run scared of actually acting doesn't mean you don't have an easy and obvious legal recourse to say bye to them. You just have to make sure you're not doing it out of spite and that you give them reasonable recourse in case everything they have ever told you about why they were off happens to be true, and maybe even that there's more that they don't want to share with you for personal reasons.

Of course, this leaves some scope for abuse, but you can do precisely nothing about that. In the same way that you don't know if someone returning a product actually genuinely couldn't get it working or whether they just want their money back because they overspent at Christmas. It's all part of the cost of doing business.

More worrying is that, if one person is off-sick, it means your office/department comes to a grinding halt. That's not a well-planned business.

Hint: I basically never have a day off work. I think my last sick-leave was about 8-10 years ago. Before that, it would be another 8-10 years. So if anyone was going to be upset about people malingering with illness, it should be me.

But as the guy says - not my business, so I don't care. If someone gets more money than me, more holiday than me, more responsibility than me, a better job title than me, more days off than me, or whatever... good luck to them. If I think I'd getting a duff deal overall, I'll be sure to speak up, don't worry. But if they've negotiated a better deal, kudos to them. It doesn't mean I MUST be given exactly the same, as I have no knowledge of the differences in situations.

This is my biggest problem with unionisation, by the way, the concept that everyone is equal which means they all get top wages for doing the lowest-common-denominator of work. I've never been a member of a union, as I negotiate my own salary and conditions. Strangely, that means I'm often under onerous NDA's with my employers for getting a better deal than anyone else (and as part of my job I see, manage and have to manipulate salary etc. data so I know I'm not being fibbed to but equally know that even if I found out something that way, it's none of my business as I was only processing that data and couldn't act upon it).

I think the childish jealousy of "he gets paid more", "she works less hours", "why doesn't HE have to do X", etc. is what tears apart a team much more than any disparity. You know what? The people I see who get the biggest raises etc. more often than not work harder for it, suck up more for it, try harder to get it, and even ASK for it where the other people don't. If you don't ask, you don't get. Feeling hard done by? Ask for a raise. The people I see who get stuck on a wage structure for decades are the ones who "never want to make a fuss".

Lee D Silver badge

And the perfect way to ensure the guy gets even more money out of the company, plus the opportunity to say "No, I still want to keep the job", plus cause everyone involved more hassle is to splat his private data around the team unnecessarily.

Nobody else need know WHY he was off, just that he was off. Almost every workplace I've ever worked in understood this... "off-sick" / "medical leave" / etc. is all you need to know.

The perfect way to encourage a malingerer is to hand them a £50k payout by being an idiot. The perfect way to lose the support of your team is to lose your own job because you spaffed the info everywhere, and still your team has to do the work but without the guy AT ALL, without you, with all kinds of HR hassle to boot, finding replacement staff, and having £50k+ taken out of the salary budget to compensate him.

If you've got the job title that includes "manager" this should be quite obvious.

Pro Evo-lution shocker: Samsung SSDs focus on endurance over capacity

Lee D Silver badge

Re: Endurance != Reliability?

That's my point...

Increasing speed is pointless.

Increasing durability is pointless.

We need them to do no more than produce a standard, small module, in massive quantities, and bring the price down. They can sell that module singly in a small drive, or thousands together in a humungous one. But until the cost per module comes down, they aren't practical and wasting money on FASTER controllers/chips isn't helping.

I'd be more than happy with whatever chip is in that several-year-old SSD, multiplied up to fill the box, and sold at a decent price. A 1TB Samsung cost me £300 several years ago. By the same token, a 15Tb one should cost £4500 max. In actual fact, it costs £7000 ($10k).

If they can't get the modularity, mass production, and scale correct, we are never going to get affordable SSDs. And I'd be happy for them to abandon HDD production to do so.

Lee D Silver badge

Re: Endurance != Reliability?

Endurance and reliability are both within or exceeding the ranges that non-SSD drives do.

Speed too.

Capacity? Nope.

Price? Nope.

So why they would not bring down prices, or raise capacities, but give more endurance and speed? I can't fathom. Just STOP making traditional HDDs except for high-end server stuff if you really need to.

And, as an anecdote, I bought the cheapest, most useless SSD I could find for work machines. It's a Crucial thing that cost a pittance and just large enough to cover our base image. It makes all our machines FLY if they have them in there. Literally a bigger speed impact than double-RAM or five-years-newer processors. We bought them for machines that can't go above 4Gb because of motherboard restrictions (even though 64-bit Windows). They make a bigger difference that the ones we upgraded to 8Gb and beyond.

According to the Crucial Storage Executive software, the SSD in my IT-Office, always-on, only machine I use every day, remote-desktop-into-from home, everything-installed machine, lowest-of-the-low (so people can't say I'm using better kit than they are) reads thus:

Power On Hours Count: 2172 Hours (the disk has been in there a year, the machine is on 24/7, it's only been "powered on" for 3 months, by that number so obviously it powers down out of hours and in idle times).

Reallocated NAND Blocks 0 NAND Blocks

Percentage Lifetime Remaining: 97 Percent

Available Reserved Space: 100 % Spare Blocks Remaining

Total Bytes Written: 9.87 TB

It's 500MB/s read and write. Warrantied for three years (which they class as 80TB Total Bytes

Written for that drive). At current usage, it should give me.... another 8 years. I don't expect it to, it was cheap-as-chips, but it should, on average, overall, across my users. I don't think there's an hard drive that I'd trust for that length of time in active service.

P.S. I did nothing more than image the drive from the previous HDD - didn't change swap settings (and it's only 4Gb RAM), didn't put on over-provisioning, ignored all the software recommendations for caching, etc. so technically I'm really abusing it as an SSD and could get much more life out of it.

Sure, I wouldn't want to use it as a 24/7 CCTV-recording NAS or something, but that's more than adequate. We haven't had one fail. When we do, they're really cheap to replace.

But what I'd really like is something much, much, much larger even if that meant it came in 3.5" format. Cracking one open (they aren't hermetically sealed like HDD's) reveals that it's a little aluminium tin can with a tiny half-populated circuit board taking up about 1/3rd of a 2.5" drive on it. With no further effort, they could easily multiply capacity by six without having to even use different storage chips (maybe a different controller chip). My Samsung 850 EVO at home is the same. That's 1Tb but you could easily make it 4-6Tb in the same container. In a 3.5" drive? You could easily have a RAM-stick-like arrangement and put many dozens of Terabyte chips vertically on an horizontal controller board.

But it's the one area we don't seem to see SSDs growing in - actual capacity, or cost-per-capacity. Which, given that even commodity Windows PCs now come with SSD options, sometimes even by default, I can't fathom.

Stop faffing around and start making larger versions of what you have. I couldn't care less if it was even slightly slower than the current SSDs so long as it was lots faster than an HDD. And was affordable in the multi-Tbyte range.

Death notice: Moore's Law. 19 April 1965 – 2 January 2018

Lee D Silver badge

Personally, I look at clock speeds now (as in real-world clock speeds, not theoretical maximum if you plunged it in liquid nitrogen) and most desktop Intel chips look pretty sad. There are mainstream computers out there that dial back down to 1Ghz or so.

At one point 3GHz was the norm, 4GHz was possible, but we don't see improvements on those kinds of speeds any more. The top-of-the-line Intel chips are 4GHz. Hey, sure, lots of cores, but still 4GHz. We hit peak "speed" years ago. Then we took advantage of more "bandwidth" if you like (same speed but could do more at the same time). Now we're stuck because nothing really takes advantage of a 32-core processor, you can't make one work at 3-4GHz constantly without stupendous cooling, and we have nowhere to go. Compiler optimisations and branch prediction don't even figure, most of the Intel fixes have 5-10% impact only, it's only the worst-case loads that suffer more.

The money for anything extra goes on GPU now if you want to actually do anything useful - whether that's gaming, mining or actual serious calculations. 1000s of tiny cores running at GHz.

But we plateaued years ago, and nobody is really able to do much about it. Maybe it's time we started writing software that doesn't require some hundreds of megabytes of code to draw a couple of windows on the screen, especially now that we can just throw OpenGL data at the screen directly.

Aut-doh!-pilot: Driver jams 65mph Tesla Model S under fire truck, walks away from crash

Lee D Silver badge

Re: The Nasty Little Truth About Deep Learning

Machine learning of a trained network tends to have a logarithmic pattern - it learns quickly at first, then quickly plateaus and it takes a lot to "untrain" it onto something else.

This is why most of these "AI" things peak with basic functionality, because after 100 trainings it might get the idea, but between 100,000 and 1,000,000 trainings it improves very little indeed. And it also becomes MUCH harder at that point to change what it was trained on... because it may have reinforced the wrong parameters a million times and you can only feed it a handful of corrections.

This is why Google doesn't have just one massive AI that they use to do all their AI jobs (e.g. "Viki"). They start fresh each time and retrain only on what they want it to know. Because when the plateau strikes, it's no longer any fun to beat your head against a brick wall. Their Go robot loses at poker, their poker robot loses at Go.

It's also the reason that PhD students in the area can operate - train a model, get it to do something interesting, realise that you can't make it do any more, write up paper, flee for some high-paid job.

Anything sold to you as "AI" today is lying. It's not even close. It's just a huge statistical model with heuristics to tune it to what you want it to do. It's not intelligent in any way, it's just seeking statistical similarities with its training material. The more training material, the slower, harder and less reliable a particular result will be (e.g. train it to see bananas and apples and it will start to classify things in the wrong group, as opposed to just training it to see bananas and saying yes/no). And the best bit - being "AI" you have absolutely no idea what criteria it's judging on. You train it, sure, but is it just looking for "image is mostly yellow" or "image has mostly yellow in the middle" or "image has a curve" or what? You have no idea the hidden criteria it's associating with the image of the bananas you're training it on. Which means you have no idea how it will react to any one image, that you have to counter-train it (i.e. give it lots of things that are not bananas), and you will also find it very difficult to modify its behaviour later on if it turns out to not be looking for what you think.

Pretty much, there's not much difference between what people are pushing as "AI" and a Bayesian spam filter. Sure, they're useful. But they are far from reliable or predictable. And at the end of the day it takes a human to feed it enough data (not just emails but "This was spam", "This wasn't spam") to actually get close to useful, and then it can be easily undone by anything it's not encountered before.

That's a worrying facet for a machine that's driving your car in the real world. Pretty much if a UFO were to park itself on the M25, people would still recognise it as a hazard and know how to stop their cars safely. "AI" like this won't necessarily, and you have absolutely no way to tell what it'll do until the day it happens.

Lee D Silver badge

Re: Darwin Robbed Again

Well... pretty much if you want to pass EuroNCAP that's a necessity.

This is why everyone moans about modern cars "being made of paper" in terms of deformability. That old Volvo might survive a tumble off a tower-block but if you're inside it you won't.... you'll be killed by that immovable object surrounding you.

Modern cars disintegrate so that by the time your body hits something, you're only really going from about 30mph to nothing instead of 60mph to nothing. Short of head-on 70+ vs 70+mph, or anything out of the ordinary (i.e. a car front coming up into the windscreen itself), you stand a damn good chance of walking away or at the very least being alive enough to worry about the insurance.

One of the things I did when I bought my last car was watch the EuroNCAP crash videos of it. They can be very telling as to the build quality of the car and quite why your windscreen supports are thicker than you have ever seen on an old car.

P.S. I drive a Ford Mondeo... rated 5-stars. Watch the videos on their page. You and your passengers / kids end up in a cushion of airbags. Who cares about the car, we can walk away when some idiot like this ploughs into us.

Lee D Silver badge

Re: The Nasty Little Truth About Deep Learning

No, but they do claim semi-autonomous driving.

And also:

"As of 2017, Autopilot included adaptive cruise control, lane departure warning, emergency braking, Autosteer (semi-automated steering), AutoPark (parallel and perpendicular parking) and Summon (recalling the vehicle from a parking place)."

Seems that the emergency braking isn't really up to scratch, nor Autosteer. Whether or not "Autopilot" is enabled, why does a car that CAN detect it's about to hit a large stationary fire truck at 60mph allow such an action when it clearly should have been able to brake in time?

And, sorry, but the OP is right... such things are not intelligent in any way, shape or form which is why even with Autopilot on they don't see large trucks crossing the road ahead and plough straight into them. It's not been trained on the exact circumstance, so it's reaction to it is largely arbitrary. And yet they're claiming you can let it safely "autosteer", "autopark", "drive itself from a parking place", "brake in an emergency", "tell if you're straying out of a lane", and "change speed to match surrounding cars" as per the list above.

No matter what you might think, the technology isn't there and companies like Tesla are complicit in letting people believe it is. We do not have AI, or anything vaguely intelligent enough to do these things. They're all just "trained" heuristical systems that are pretty much unpredictable in any given situation.

Firms pushing devices at teachers that let kids draw... on a screen? You BETT

Lee D Silver badge

They know that already.

They all have iPads or smartphones. By comparison a Raspberry Pi is a toy. P.S. you think they care that they can use a machine, if it can't play GTA V and Overwatch?

I work in IT in schools, always have. RPi are a waste of time. MicroBits are even worse. Pretty much everything they want to do, they know they can do on an iPad, Android phone, or portable PC. They already don't care about OS or architecture.

What they do know, though, is that you need a decent PC if you want to do anything serious, especially 3D or video editing, and everything else is so damn powerful that a RPi 3 is just a joke. They might like plugging it in, that's about it. It's not a wonder-toy to a kid that has even the most basic Samsung Galaxy (which will be smaller, faster, have integrated 3D, run on Android, and probably is in their pocket). And yet, you still need monitors to plug into, power supplies, kits of parts, keyboards, etc. And a space to do it in. Gosh, if only every school had, like, a suite in which they had all that kit and workspace already? You have to shove the PC out of the way to play with the RPi or add in so many other parts you could buy them all an iPad / Chromebook each anyway.

Guess what app they all try to install on their iPads? Word. We don't even give them Office 365 but they all expect to open things in Word by default even on non-MS platforms. They are completely platform-agnostic, but they "know" they need Word.

So, sorry, but the RPi's aren't all that interesting. And staff don't know how to utilise them. And apart from a little computing lesson where you learn to plug it all in, everything they do is better off done on a real computer.

If you go to BETT, they were pushing MicroBits one year. Literally no products - just pushing what they could do but you couldn't buy them. And a few years before it was RPi. No lesson plans, no teacher assistance, just boxes of gadgets. Both are now almost invisible, like the 3D printers before them, visualisers before that, etc.

This stuff isn't for education, which has entirely different priorities to you and I (and I work in private education with kids who go to Eton... they literally lose all interest in RPi etc. within minutes but will happily build their own drone aircraft). Coding? Yeah, they "did that". Whether it was Scratch or Python it consisted precisely zip of their lessons over even their primary education and then that was done. Why? Teachers who can't code and who have huge curricula which includes a lot more than coding. Or playing about with little gadgets.

To be honest, you could run a school without visible Windows. I have seen one or two attempt it, reverted one (reluctantly being a massive Linux fan, open-source programmer, etc. myself but they really messed it up), and I tell you that you could run the kid-side easily on anything you liked. Google GSuite for Education, a handful of third-party website subscriptions, any decent browser and that's 99% of what you need for the kids to get through all they ever need to - including testing and assessment. Guess how many go that route? Very, very, very few. Why? Teachers ask for Windows and Office. Why? 10 years ago, those teachers were the same kids with the teacher who was baffled by Windows 7 and who would have stayed on XP forever. Trace it back enough and you still see things like "Word is the word-processor, Excel is the spreadsheet" as if nothing else exists.

Sorry, but education is a market based on teaching things that you're told to teach, when you were never taught them yourself, so they stick exactly to what they know and can pick up quickly themselves. Just try explaining app vs website to most teachers and you could be there for hours. Especially when you then demonstrate that "the iPad app we must have" won't run on Android / Chromebook / Windows.

Education doesn't care about your RPi's precisely because - as I warned at the time - RPi doesn't care about the teachers. Look around and only OTHER TEACHERS provide resources to use for them linked with the UK national curriculum in any way. And that curriculum changed smack-bang as RPi came out. Teacher won't touch that without paying £1000 for the "pack" of RPi's with massive book of lesson plans and a 3 hour course for their entire staff with a support line the other end. That, pretty much, doesn't exist.

Until then, every school you see will be paying for Microsoft licensing annually (but we pay for one copy of Windows/Office per full time teaching employee only anyway), still buying iPads AND Chromebooks AND PCs AND other stuff, and then still complaining Word can't run on a RPi. And your kid will come out thinking half-a-dozen copy-pasted lines of Python is "programming".

P.S. I was also an early tester for RPi 1.0... including diagnosing the Ethernet/SD card USB bus saturation issues with Broadcom directly. My RPi is gathering dust in the attic, as are the school ones at every school I've worked at since they came out.

Take a former NSA head hacker, a Raspberry Pi, weird Kiwi radios and what do you get?

Lee D Silver badge

Possibly the most already-done-a-million-times and boring thing you could do as a geek/hacker.

I mean, yeah, sure, it's fun for him. But even with the FM bit this isn't new to anyone. There are guys all over the Internet doing this, and a million times better, and with the same kind of local broadcasting of accompanying music.

My first question is not about the radio, as such, but: Did he pay for the broadcast rights and the right to use the Peanuts imagery? Probably not a good idea to tell everyone at a conference / on the Internet that you did that stuff as there's almost certainly a rightsholder waiting to complain somewhere once they see that.

I was much more intrigued by the DVDs you can get and project on-loop onto a thin bit of fabric in the window to do everything from showing a mystery Santa leaving presents to scary ghosts walking past the window every now and then - all synced together for each window in the house.

Why did I buy a gadget I know I'll never use?

Lee D Silver badge

I have:

- Two Video Backer cards (ISA card that outputs a recordable video stream that you can then play-back to get about 2Gb of data backups on a 3 hour VHS tape).

- A SyQuest Sparq drive (think ZIP drive, but with 1Gb disks and a parallel port interface / DOS driver).

- A serial cable that is about 20m long and is made up of every possible combination of M/F/25/9-pin serial cables in series, plus gender changers and adaptors (this once was the basis of a two-computer "Ethernet" network using an old DOS packet driver that nobody can find any more - used to play IPX and TCP/IP games over it under DOS / Windows 3.1).

- A similar chain of USB, mini, micro, full-size, male, female, etc. adaptors/gender changers.

- A floppy drive for an IBM Thinkpad from out of the Ark (a 360? Which I still have)

- A modem-based VPN device that you could dial into to talk to local Ethernet / serial lines, I think it's datestamped 1980-something.

- PS/2 and even serial ball-mice (I kept the serial as you could play The Settlers in DOS split-screen if you had a PS/2 and a serial mouse)

- A Trust-branded VGA -> TV convertor that can just about make a mess of putting 800x600 VGA into a standard coax signal if you don't mind missing half the screen and it being all wibbly.

- A box full of proper non-Winmodems, which I still use to form the basis of fax->email systems in places that still have analogue lines. Sadly these are on the verge of retirement, however.

- A PCMCIA GSM data card. Pretty much far too expensive to use even when it was possible, but did at one point form part of a PCMCIA-only laptop that was a router / gateway / firewall for my home network - PCMCIA 56K modem, PCMCIA 10BaseT Ethernet, PCMCIA GSM data card, all in the same machine and it managed my home network for years, after booting from a single floppy (Freesco/Linux).

- Bags of other stuff.

Scumbag who tweeted vulnerable adults' details is hauled into court

Lee D Silver badge

Re: Threatened the ICO ?

"or could reasonably be expected to be aware of it "

Such as, for instance, ensuring that you run industry-standard software to stop unauthorised devices on the authorised machines.

"Reasonable" in terms of data protection has included - in case law - things such as reasonable preventative measures to ensure compliance with your verbal "don't do that"'s. Saying "I told them they should have a password" just doesn't pass muster any more. You have to show that you've enforced that and are aware of those exceptions. To not do so is negligent in your data handling duties.

It's also been a factor that you can say "we don't allow that" until the cows come home - but the courts only consider it reasonable if you're also CHECKING that it's not possible, and that people aren't doing it. You can only do that by putting in, for example, device and data control systems. Courts deem that to be the "reasonable" measure, not "Oh, well, it's Sheila, we did tell her".

The fact is - this is all a consequence of DPA case law, where the definition of reasonable has been decided by a judge but not written back into law. GDPR is an attempt to codify that case-law back into actual words.

Hint: An NHS trust was fined for NOT BEING ABLE to prove that a lost disk had been encrypted before it left the building. Not that it WASN'T encrypted. Not that it wouldn't have been expected to be encrypted. But that they couldn't definitively prove that it WAS encrypted BEFORE it was posted and then lost. Case law is not on the side of liberal interpretations of "reasonable" here. Even *potential* for someone *unauthorised* (i.e. not necessary for their job) to see any amount of personal data that they don't need to see as part of their job, can be interpreted as a breach. i.e. that there was even a brief window of opportunity for Fred Bloggs who works for the company to have BEEN ABLE to log into something that might have given him more info than was strictly required for his job? Fineable offence, including personal liability of whoever facilitated that.

You can scream "but nobody ever would prosecute for something so minor" until you're blue in the face, because that's not how the courts are interpreting it.

Take an example: Some minimum wage phone operator sells on your customer list to a rival before they leave. It's STILL a breach of the DPA, even if you told them not to do that, even if their doing that was a breach of everything in question, and even if they were authorised access to those records as part of their job. You will still be fined, as a company, for a) it happening, b) allowing it to happen without a reasonable safeguard against it. It really doesn't matter what THEY do, which is the essence of the whole problem. They just shouldn't have access to anything they could do that with, or be able to splat that information about willy-nilly and you need to show reasonable attempts to control that data (which doesn't wash if you just say "Oh, well, they had an Excel of every email address"... the next question the court asks is "Why?" and "How did they get that?")

Lee D Silver badge

Re: Threatened the ICO ?

You need to read up on the DPA and, especially, GDPR (which is really just a formalisation of what the DPA case law already establishes).

If you have personally-identifiable information on a machine (or now even on paper), it's subject to the DPA and is most definitely an IT and HR issue. As in... she shouldn't be allowed to use a USB stick, shouldn't need to write up notes at home, certainly shouldn't be doing so except on encrypted and controlled devices via encrypted and secured channels (e.g. remote desktops over VPN).

It is most definitely an IT issue for there to be an unencrypted USB stick wandering around with any kind of information gathered as part of someone's job. Whether you like it or not.

P.S. DPA has always had, and is now formally codified as having, personal liability. Not only her, but YOU as the IT guy can get fined, as well as the company, for not knowing this.

Linux's Grsecurity dev team takes blog 'libel' fight to higher court

Lee D Silver badge

It seems incredibly like imposing further conditions on the distribution, which is prohibited under the GPLv2: "You may not impose any further restrictions on the recipients' exercise of the rights granted herein."

It seems quite clear to me that making people pay for the software, and then denying them future updates in perpetuity should they EVER exercise any of their distribution rights under the GPLv2, is quite a bit more than "imposing further restrictions".

That's pretty moot, however, because you'd have to be an idiot to want to do business with this guy at all anyway.

Lee D Silver badge

GRSecurity / Brad Spengler

This couldn't happen to a nicer fella.

Finally his big-headedness has caught up to him.

And, never forget, he has to publicly declare certain things to work on tiny little government contracts:

https://www.collierreporting.com/company/open-source-security-inc-lancaster-pa

Quote: "Estimated Number of Employees: 1

Estimated Annual Receipts: $140,000

Business Start Date: 2015"

No matter what he says, he's been a tiny one-man operation for years. How he can afford a lawsuit, I can't fathom.

Lee D Silver badge

Re: Lawyers and Catfish

The judge said that the current case can't proceed as is without being amended.

They don't want to amend.

So what they are saying is "the judge made the wrong decision" and appealing the case. Which first requires the case to be dismissed.

It's pretty much certain they're on to a loser at this point, as they're literally saying "NO! YOU'RE WRONG!" to the judge, who was quite clear and didn't have to do much interpretation to come to the conclusion they did (i.e. it is an opinion, and you can't be libellous unless what you're saying is provably false). They can't prove the statements false, hence they can't continue with the libel claim, but they want some "different" answer.

The best bit is at the bottom, though... no matter whether the case is dismissed or the complaint amended, there is a court-sanctioned avenue of suing them back under an anti-harassment law, with positive encouragement from the judge as to the likely success of such an action.

Not only are they onto a loser with their original suit, they're onto a loser with the appeal, and in the process they can be counter-sued almost automatically no matter what. This is not just losing... this is M&S losing...

NHS: Thanks for the free work, Linux nerds, now face our trademark cops

Lee D Silver badge

Re: I always thought Microsoft would be the one to get them...

I used to work for a school that was taken over to become an academy.

In the process, they wanted to merge sites, ditch half the IT staff, etc. But not before they'd forced us into IT service agreements that would benefit the "superhead" and his golf-chums into perpetuity, by selling us everything from cabling and networking to software and hardware.

One of the products they wanted to push was LightApp (I believe it's dead now). They exhibited us at BETT using it, but actually we already vetoed it and refused to touch it. It was a thin-client solution based on pushing X-Windows sessions into thin-clients, and then replacing everything on the backend (i.e. the IT team) with a remote server managed by the company in some god-forsaken third-world country. We vetoed it on many grounds, everything from "no local support" to "we don't have an internet connection reliable enough" to "data protection issues" to "security issues". Bear in mind they wanted hundreds of students to use those thin-client / remote-sessions for EVERYTHING they did, plus all the school admin, etc. It was just laughable.

They allowed me to trial it as a pupil so that I could voice concerns and they could answer them. So I logged in via their thin-client, got full root access in a matter of seconds (no security at all, they just assumed you'd never look in their chmod 777'd folders for all the admin users), and left a document on their desktop detailing my objections.

One* of those was: They sucked out the icons from MS Office and used them as icons for OpenOffice/Libreoffice (I think it was OO at the time, I can't remember), with Word, Excel etc. as the names. Prima facie trademark infringement.

Needless to say, at the time it was the least of my worries, and the least of theirs trying to sell us such a junk piece of system, and they never saw a penny of it. I left soon after and I've never heard of them since.

(*) Best one, though, was that they promised us it would "run any Windows program". I don't think they knew that I was a Linux programmer and so could understand what garbage that was - at the time, WINE was barely viable for an old version of Office, let alone anything else, and virtual machines weren't heard of in Windows circles.

As part of this, we had "Ranger Suite" (since bought up by RM, so that's dead too), which is a Windows GPO deployment / user control program that shuts down rogue processes, forces the desktop settings, reports violations, allows screen-based remote control, etc. etc. and creates and manages users in AD. It was basically THE front-end security on a Windows machine. They said it would run under WINE and do everything it always did. I nearly died with laughter at the suggestion, and the salesman ran from the room and ran crying to the head saying I was being unprofessional. My boss then countered saying that the salesman is the one talking rubbish and didn't have an answer when proven that it would NEVER work (I doubt you could run that software now under WINE, it's so heavily AD/GPO/Registry/task-hook based), so nothing happened and we never saw him again.

Two weeks later, the guys in charge of trying to move us to this setup offered me £600 a day to go around their other schools and help them sell it, on the basis of "he's smart, but lots of money should be enough to let us use that smartness against our other clients", I think. As my boss correctly predicted I would tell them at the time, and how I re-iterated when asked, "there wasn't enough money in the world that would make me lie and con schools out of money for a living".

But it's funny that 15+ years later, people are still pulling the same tricks with no knowledge of how to do business.

Lee D Silver badge

I bought a Windows tablet on Amazon for £100 that included Windows 10 and a year's worth of Office 365 (which has since only cost, what? About £5 a month to renew?).

Though I have done any number of conversions in the past, and used Linux exclusively while managing Windows networks for at least 5 years, and even used open-source as part of business deployments, I don't think that the cost should really factor in at all. The price to most people to bother their friends enough to sort this lot out for them, plus the ongoing hassle, plus that they feel they "need" a new machine anyway, it just isn't worth the effort.

Now consider how much he's going to run into stuff that he can't fix himself but would need to bother you for, plus things like compatibility (Outlook is just the start of it... I used Outlook for the first time in my life three years ago, and I've been doing IT support for nearly 20 years).

LibreOffice is a viable alternative to Office. The browser wars came in and - pretty much - open source won them, even if Chrome is just a commercialised Chromium, there's still the option there. There are open OS and VM hypervisors if you want to maintain compatibility. Nobody dual-boots any more. If someone doesn't have money or needs something quick, I recommend open-source and even just freeware. Classic Shell is one of the best things I've used in years. But if they don't have the nous to cope with any idiosyncrasies that arise from its use, though? Chances are they're better off with an Office licence or whatever.

Paying for software that does stuff that you could do for free is no different to paying someone to do DIY tasks that you could do yourself. Some people love the challenge and the learning and saving money. Other people just want the damn shelf to not fall down on their heads, it's not really their cup of tea, their time is more valuable, or they need it yesterday.

I've come to accept that, in the end, the people who want to use free / open stuff naturally will when introduced to it anyway. Everyone else can pay. There's no need for hand-holding.

(I'm an open-source programmer in my spare time, I patch my own kernels, I code my own utilities, I run 50% Linux servers in my day job, I run Linux servers and desktops in my personal life... I'm hardly biased here. Hell, I have a Crossover Office licence still).

In my mind, we won on web browsers. We compete in home-office. We have a viable alternative in terms of operating systems (which, when you consider areas other than home PC, actually wins hands-down in terms of unit-sales). And everything has moved from "Win32 application" to "WebGL / HTML5 that runs anywhere" anyway. Even Office (+ Google Docs, etc.). We don't have any points left to prove. But we still won't convert everyone.

The reasons for that are easy to see: Businesses can't sell you open-source, and so they never recommend it. People are happier to pay to have a company they can yell at, and pretty much I only know of Red Hat in terms of "open-source you can yell at" (who are both incredibly expensive, and won't do anything about your LibreOffice problems). People's time is often more expensive than a licence price.

Make Apple, er, America Great Again: iGiant to bring home profits, pay $38bn in repatriation tax

Lee D Silver badge

Re: Shame they pay no tax elsewhere

America has always double-taxed things. They basically don't care what the outside world taxed you, they will tax you too.

Many dual-citizenship people find this out - pay US taxes while living abroad, or give up the US status. It's a very common dilemma. Even if you use certain credits to not have to pay the US tax, you still have to fill out all the US tax forms to claim that even if you haven't lived there for decades. I don't know of another country that does that.

Today in bullsh*t AI PR: Computers learn to read as well as humans (no)

Lee D Silver badge

If is was "just a matter of feeding in more data", Google would have the world's best AI running across their datacenter already.

Sadly, it's not that simple. "AI" as you know it at the moment is just the same as it ever was... progress in the field is limited and has been allowed mainly because of commodity hardware but what they've found is that - though they can throw much more parallel, much faster, much more powerful, much more prevelant, much cheaper hardware at it - it doesn't change the fundamental nature of what it is: A statistical model.

Statistical models are not "intelligent", they don't "learn" as you expect. Quite often 99% of the gain is in the first 10% of the training and then very little else changes and it takes much longer to "untrain" it in order to show it exceptions that it had never seen before. And, at the end of the day, nobody is quite sure what it's trained itself to at all. It might be statistically correct most of the time, but it's not trained.

If it were just a case of throwing more hardware and time at it (time being much more important, I would posit, literally just training it 24/7 for decades), then we would have a Bitcoin-like economy where companies were fighting to throw as much time and power at a basic AI as they could to be the one with the most well-trained AI. Amazon and Google would lead the entire scientific field. Places like CERN would exist just to train AI en-masse.

But that's not how it works. Or how the technology works. Or how we even believe it could work. All the "AI" you know isn't... it's closer to a heuristically-determined expert system. We've had those since the 1960's, and though computing power has increased by factors of BILLIONS in some circumstances since then, not to mention that's just a single computer and the ability to scale the AI to billions of computers exists, it hasn't really got much better at all.

IT's like saying that the way to train a child is to throw as many books as possible in its direction. Literally bury the poor sod under literature and expect him to be an expert in everything from Shakespeare to quantum mechanics. Kid not smart enough? MORE BOOKS! Kid can't read yet? MORE BOOKS! Kid gets something wrong? MORE BOOKS! Kid biases towards a certain answer? MORE BOOKS!

That's not how it works with real intelligence, and it's certainly not how it works with what passes for AI.

Everything "AI" you ever seen, from Alexa and Siri to artwork-creating robots, Google image detection, whatever you've seen at CES or any other show: It's the same thing. A statistical model, trained on a data stream that, after a very short period of time, has increasingly poor gains for the time/effort/resource/training it requires to add on criteria or more data. Literally they plateau very quickly after becoming vaguely useful, and then progress drops to nothing.

And without the human-led training, they are even worse. I can knock up some Java code - like many of my peers from CS courses did in the 90's - to show you neural nets, genetic algorithms, all kinds of stuff that will demonstrate "learning" behaviour. Right up to the point where you need it to do something slightly complicated. At which point the returns diminish to nothing.

There's a reason that most of the AI in the field lasts precisely the length of a PhD research project and then dies a death - do it, get results, realise that's the best you're ever going to get, write a paper, run away from the entire field.

OK, Google: Why does Chromecast clobber Wi-Fi connections?

Lee D Silver badge

Re: when in tandem...

Draytek Vigor routers are fabulous. I have the 2860 - firmware updates all the time (with new features as well as bug fixes), certified compatible with BT fibre offerings (and ADSL2, and Ethernet, and 4G). Failover, IPv6, all kinds of internal options including web filters and DNS filters and LDAP authentication and AP isolation and dual-frequency radios (including handover between frequencies for compatible hardware), proper QoS, SIP handling (including analog ports that run over SIP on board), VLANs, and every option under the Sun.

I run my house and a work site off them, they are just solid, fast and so featureful you'll spend your life reading the manual and going "I didn't realise I could do that!"

Lee D Silver badge

Mine is powered off the projector that it displays on (literally the USB plugs into the projector).

I have a remote for the projector on my smartphone, so even if I desperately need it in a hurry, press button to turn on projector, by the time I get into a Cast-capable app, it's up and showing on the screen.

Lee D Silver badge

Chromecast announces its presence on the LAN at regular intervals so that devices that want to Cast know there's a Cast-compatible device.

No different to Airplay, DLNA, or any similar technology.

The stupidity is in sending a packet for every announcement "missed" because it was asleep, all lumped together the second it wakes up. That's just dumb.

Hawaiian fake nukes alert caused by fat-fingered fumble of garbage GUI

Lee D Silver badge

Re: Confirmation checkbox needed

But... like the infamous "four minute warning", it's 100% completely useless anyway.

By the time that alert was cancelled, any missile would have hit and done whatever damage it couldand basically no-one would have had a chance to do anything about it. Hell, that's assuming they could even get the alert out in time, let alone people actually receiving it, reading it and running immediately for shelter (where?).

A second person isn't exactly difficult to come by if you're working on a missile alert system. I presume that second person's function of late has been to slap the first person who fat-fingered it..

Ecuador tried to make Julian Assange a diplomat

Lee D Silver badge

Re: Obvious ploy but...

Strange, then, that they haven't done that for 5 years when it would solve the problem overnight, isn't it?

Article 9 of exactly the convention you state, look at my highlights:

1.The receiving State may at any time and without having to explain its decision, notify the sending State that the head of the mission or any member of the diplomatic staff of the mission is persona non grata or that any other member of the staff of the mission is not acceptable. In any such case, the sending State shall, as appropriate, either recall the person concerned or terminate his functions with the mission. ****A person may be declared non grata or not acceptable before arriving in the territory of the receiving State****.

2.****If the sending State refuses or fails within a reasonable period to carry out its obligations under paragraph 1 of this article, the receiving State may refuse to recognize the person concerned as a member of the mission.****

So long as we declared him persona non grata at some point between then and now he is not, cannot and never will be able to be classed as a diplomatic member who enjoys those rights. No matter what Ecuador says.

Lee D Silver badge

Re: Smuggle him out in the Diplomatic Bag

It has to contain articles for official use, specifically documentation written for the purpose of the diplomatic mission. I don't think he comes under that.

Though it's a "nice idea", in that you could in theory use a shipping container as a diplomatic bag and hope they recognise it as such, it doesn't give you rights to just put anything you like in there - and it's been tried (and failed) in the past. Everything from space shuttle components to heroine to bombs.

And the knock-on diplomatic effects even if successful could cost them billions in trade, just for a prat they don't want any more.

Lee D Silver badge

Why... we're not paying for him, Ecuador are.

Let them get bored of it, maybe they'll learn not to jump on political bandwagons next time (I bet it's hurt their political negotiating power with the UK since day one).

When they're bored of it, we have to start paying the same amount anyway to imprison him. Let them fund their own stupidity, and take out the difference (e.g. policing) from their next trade agreement with us.

They were hoping to use him as leverage but that obviously doesn't work out unless we actually want to deal with him.

Lee D Silver badge

https://en.wikipedia.org/wiki/Diplomatic_bag

Read the Noteworthy Shipments.

Basically, if you're taking the mick, no it's not covered. And sending a human inside it has been done before (as has drugs, bombs and just about everything else), but is still taking the mick.

Thus still liable to seizure, arrest, etc.

"The packages constituting the diplomatic bag must bear visible external marks of their character

and may contain only diplomatic documents or articles intended for official use"

Given that the purpose of the bag is to move "The official correspondence of the mission", unless they'd tattooed their visa lists on him, I don't think you could class him as correspondence, hence you wouldn't be able to get away with just stuffing him in the bag.

Lee D Silver badge

Re: It's a weird world...

Don't actually see that the UK is anything but a middle man.

"Please arrest him, here's all the paperwork"

"That paperwork isn't right."

"Oh, sorry, here."

"Nope, still not right."

"Oh, for feck's sake... HERE"

"Okay, we'll do that now that you've done it properly. Mr Assange... Hold on, he's skipped bail."

"Oh, well, forget it."

"Er... no... we're having him for skipping bail because we can't just have everyone do that. What comes after may be a matter of protocol, but we can't have people just think they can skip UK bail by running to an embassy and that's that."

I honestly think it will at this point be a million times more likely and a thousand times more embarrassing for him to come out, be arrested, sent to jail for skipping bail, six months without press, gets out of that and... literally nothing happens. Nobody cares enough to bother to chase him any more. A couple of press conferences and then fades into obscurity.

Pretty much the only reason we're still talking about him is that he's an outlaw. As it is, he's spent years in a self-imposed prison, will spend more in a proper prison, and then... well... pretty much whatever was going to happen will happen anyway - prosecution, extradition or nothing at all.

Transport pundit Christian Wolmar on why the driverless car is on a 'road to nowhere'

Lee D Silver badge

Problems with automated cars:

1) Denial of service attacks. Though possible with traditional cars, they can call for help. Imagine being asleep for the journey to Scotland only to find the car stuck 100 yards down the road because it couldn't progress? Everything from painting extra white lines on the road (there's a guy who puts salt-lines on roads as an art-project to mess with the car's heads), to playing games with the sensors (stick some clear tape on the LIDAR, watch as your neighbour's self-driving car won't move because it thinks it's touching an object).

2) Technology immaturity. We just don't have cars that don't plough into the side of trucks - the stated Tesla case is proof in point... the car still hit the truck. An ENORMOUS truck. HUGE. At speed. Killing the driver. Whether or not the driver was dead in the passenger seat, it shouldn't have mattered. It shouldn't have been possible.

3) Liability. Because of the above, nobody has yet agreed whose fault they are if they go wrong. It's a bit I-Robot-esque to me. Either we have control AND responsibility, or neither. And that means ceding control to the car company. This could impact on everything from finance agreements (sorry, your payment is late, we won't take your wife to hospital) to social enforcement (sorry, you're all under 21, I detect three people in the car and it's past 10pm... you're not going anywhere pal). Also... who has liability for the loading of the car? If someone doesn't put their kid in the child-seat properly, how is the car going to know? But you'll still sue them to oblivion if it crashes. Presumably child-seats would still be legally required, or are we claiming they're so safe we never need to use them?

4) Mixing of autonomous and manual traffic - it's stupid, liable to danger, the biggest programming hazard, the cause of the Tesla accident, and easily solved by just... well, having a special lane, almost like a straight line between destinations, that only authorised cars can drive on, where the hazards are lessened and decisions and marking are clear-cut rather than negotiating the rush hour traffic at the Hangar Lane Gyratory. (P.S. we have that, it's called a railway).

I'd be quite happy with a special segregated lane, just for autonomous traffic, that is the only part they're allowed to drive on, and has all the special gear in the road to signal junctions, other traffic, etc. Put the safety in the infrastructure, not the vehicle. Literally, a personal train. And then roll that out bit by bit until all roads are like that and we can get rid of humans (50 years +). The suggestion to just have these things co-exist is a nonsense.

5) Over-trust in humans. If you don't need a driving licence to drive, then you will see them abused by people who aren't subject to bans etc. People will overload their autonomous car, let it pile through tiny backstreets late at night, leave them in the middle of nowhere like an abandoned shopping trolley, etc. And if the people who drove them can't be traced / stopped / banned, what can you do about it? It needs a kind of registration system at minimum. You'll see them used as drug-runners, porn-peddlers, even automated motorway adverts, getaway vehicles, whatever they can be misused to do. People will be loading drunk friends into them and programming it for Glasgow, etc. Wanna have a laugh? Summon 1000 automated Uber's to your mate's house and block the road. Who's responsible, the companies involved who made cars that block up the roads for hours for everyone else, or the guy who paid them them to do it?

But the biggest deal... we just don't have automated cars. They don't exist. We have software junk in a normal car with a couple of sensors. They aren't fit for purpose. Test them as people-less cargo deliverers for 5 years before you licence them to carry humans (thereby halving potential casualties). But we seem to be skipping that bit.

Stop us if you've heard this one: Apple's password protection in macOS can be thwarted

Lee D Silver badge

It is a bug.

It just might not be a security-critical one.

There's no point having a dialog asking for a password that literally doesn't care what password you put in, whoever you are. Either the dialog shouldn't be appearing, or it should be refusing bad passwords.

This is not "a problem" in this particular context. But it's incredibly telling of the laxity of testing and the code-paths in the secure sections of code that Apple uses - not unlike the bug a few months ago that allowed anyone to get admin by.... doing exactly this... typing in any nonsense twice into a password dialog would let them log in.

What's wrong here is the process... quite what is popping up that password prompt and why does it accept the wrong password WITHOUT showing an error at all? And how many other places / weird combinations allow the same. If this was the only bug, sure, you could chalk it up to some form of coding accident. But this is only another in a worrying trend of "You must authenticate" "Gah, just have admin rights anyway" issues that MacOS has had.

Think not about what the bug is, but what it represents. Somewhere there's a piece of code that literally says "Even if that password fails, carry on regardless, using the admin rights, and don't tell the user". That's not a situation that you want to propogate throughout your OS code.

Apple agrees to pay £136m in back idiot taxes to UK taxman

Lee D Silver badge

What we should do:

Make any company that pays less than 10% (or whatever) of its revenue as tax affix a mandatory sticker to every product they sell saying just that.

"Designed by Apple.

THIS PRODUCT WAS PRODUCED BY A COMPANY WHICH PAID LESS THAN 10% TAX LAST YEAR".

Russia claims it repelled home-grown drone swarm in Syria

Lee D Silver badge

Nailed it.

Been waiting for this to happen for ages.

Now, when they say that they took some out with an AA missile, how many missiles for how many drones? I'm guessing that it's a lot cheaper and more practical to launch 1000 drones than 1000 missiles, especially if you only need one to get through and your target doesn't HAVE 1000 missiles.

This is basically what first popped into my head when GPS + load-bearing drones became a possibility. Not even a professional attack, either. Amateur terrorism. Coming soon to a city centre near you. It's scary stuff.

Maybe then these things will get some regulation (but that won't stop them either).

Literally nothing stopping someone making an "art project" of 1000 drones in a warehouse, and then making them fly out... over thousands of kms if necessary, by all kinds of random routes. Landing on a building should they be low on battery, solar panel on the back and off you go again (maybe even with a little fuel for an "emergency" launch if it detects someone approaching / touching it while it's charging back up).

Program in the same target location to them all, their origin will basically be impossible to ascertain (quite why these one's origin was isn't explained), they would come at you from all angles, over the course of many hours (or could be synchronised to the second but likely to generate attention while they wait around) and you'll never be quite sure if the attack is over.

It only needs one to get through to cause havoc, it'll generate scary headlines IMMEDIATELY and have a massive knock-on effect, it won't need a ton of funding, or for them even to be carrying anything necessarily, and it'll be hard as hell to knock out 1000 drones all in a little flock that you can't just get with one missile.

I would also think that rather than bombs, gas would be more effective - much more scary, basically only needs some scary-looking green fogging gas to be heated up to prove proof of concept and scare the life out of everyone, lighter, controllable, doesn't make you explode while you're setting it up, etc. and yet still a viable attack method if you did have some dangerous gas.

Parliamentary 'puters made 30k tries to procure pr0nz last year

Lee D Silver badge

Re: Is that not a challenge?

You can't work for schools without being vetted. Even our access control guys / telephone guys / hole-diggers are required to be. The only exception is completely contracted-out staff under the strict supervision of already-vetted staff (e.g. Virgin Media cable pullers, etc.), which is why such work is often done when no children are present or someone literally has to stand with them at all times.

That doesn't mean they don't have a phone full of porn, though.

Lee D Silver badge

Re: Is that not a challenge?

To be honest, there's not much you can do about it anyway. No filter will ever be perfect.

But the alternative is "no internet access at all" which is then a problem for everything from visitors to contractors to just general contingency if the computers go down.

As someone who does operate a workplace wifi network, including guest access, I can also tell you - it means nothing. The system is for a school and it blocks ALL access to dodgy stuff, everything from Facebook to porn (kids definitely shouldn't be trying to get the latter, but also they shouldn't be able to just join the guest network and bypass our Facebook blocks!).

You know what flags the most? Contractor's mobile phones during the holidays (contractors are rarely allowed on-site in term-time, and certainly not allowed to use their mobiles when they do because of the basic child protection rules). They come on-site, can't get 4G, they need to send an invoice, check a spec, download a manual, access their corporate intranet, etc. So they ask to join the guest wifi, and bam... all their background stuff hits the filter and sets off alerts. It's not at all unusual for someone to instantly be blocked because of the number of alerts, the maintenance team bring them to the IT office, they show us their phone and the second we unlock it there's a browser with a dozen porn tabs in the background and significant history.

Sure, it shouldn't be there. Sure, you can't block everything. But it's also not necessarily the best thing in the world to just block all wifi access (they'll just do it via 4G anyway... at least going via the Wifi you can make them accountable for it if it's something really dodgy).

To be honest, with something like Parliament, I imagine there are a thousand reporters who "just want to submit their story" but aren't able to just connect to 4G from inside the massive stone walls, so they give them a guest wifi. And I don't imagine the average tabloid journalist is averse to having a phone full of porn.

Fact is - there's a block in place. This lets you record traffic, see trends, get alerts. This lets you detect and investigate the illegal stuff immediately (I should hope!). While providing a useful function to guests, and not being a way to "bypass" restrictions on the normal network (because then you'll just have everyone join the guest wifi to do their "classified" work).

UK exam chiefs: About the compsci coursework you've been working on. It means diddly-squat

Lee D Silver badge

Re: Numpties

You can spot a learner a mile off.

You won't care about their qualifications, as such, you'll notice the other stuff they've done. Seriously, do you employ someone in IT because they have GCSE Computer Science? No. You employ them because they have X number of GCSEs plus they've done this and this and this, and have this hobby, and built this, and this is their YouTube maker channel, and "Cool, how does that work?" when you show them around.

The only people who give any kinds of credence to GCSEs / A-Levels are: Teachers (because of school league tables), HR people hiring positions they have NO idea what they involve.

Industry certs are the same. I'm much more interested that someone actually managed a live network for X years than that they have the last X years of Microsoft certs.

Degrees are different - that's an optional 3/4 years of studying that they CHOOSE to do, at an advanced level, with almost no help from others. It doesn't even matter what they do it in - it means they're a learner by choice. But, like I say, you can spot the learners.

GCSEs are to get you into college for A-Levels,

A-Levels are to get you into university for degrees.

Nobody pays any real heed to GCSE/A-Level outside of that. Sure, it's often a "Must have basic GCSE in English or Maths" line in there somewhere, but HR write that, not the people who will be working with the guy. And there's some justification in there that you'd expect someone able to count/write properly to have passed through the joke-which-is-GCSE nowadays without any trouble at all.

Other than that, if you want to hire a kid you look for a learner. They can be a complete school dropout, you can still spot a learner ("I dropped out to start my own business doing... and I was successful for X years... and as part of that I did Y and Z...").

I have hired from the Apprentice programs. The guy had previously qualified / worked as a chef and a jeweller's sales assistant. He's now, two years down the line, an IT Tech for a large company with a career path and a work history in IT, beating all his "mates" who only have GCSEs or A-Levels (and, in a few years, degrees) in Computer Science.

Especially nowadays, all the kids have a big list of weird qualifications because that's what the schools push them towards if they don't get GCSEs. Hairdressing. Catering qualifications. Customer service. Etc. You can't really pay heed to them as EVERYONE has them, or could get them.

I have a degree. In maths. It proves I can learn.

I started an IT business out of university. It proved I am skilled enough to make a living and juggle my own staff / business / accounts.

My first "real" job, and everyone since, they couldn't care less about my GCSEs, ALevels or what my degree is in (three times I've had it stated that HAVING a degree is what they look for... lots of the people in high-power jobs have degrees like Art History or Geography etc.). They look for "what else has he done", "what has he done that proves he can do the job" and "what has he done that proves he can tackle something he's never seen before".

Sure, if you want a career in McDonald's, I'm sure GCSE's or "food safety" courses will help.

But if you're hiring personnel for ANY job, ignore the Qualifications page unless it's literally blank. Even being full of junk every year is suspicious (how do you find the time/money to do all those courses? Oh, your employer MADE you do them...).

But scoot down to the "what other transferable skills" bit and/or have a chat with them. They don't need a massive industry experience to stand out from the others.

With WPA3, Wi-Fi will be secure this time, really, wireless bods promise

Lee D Silver badge

"WPA2 has some problems. It allows anyone with a bit of software to boot people off a Wi-Fi network with a DEAUTH attack. And it's not particularly secure."

I was a little surprised to find that the Cisco Meraki wireless kit in work takes advantage of this. Pretty much, you get a list of every wireless network "nearby" yours, with the option to "quarantine" it. If you do that, your own kit performs de-auth against any nearby clients trying to join those networks, which results in only "your" networks working and everything else literally disconnecting for everyone within seconds.

Obviously, being an unlicensed channel, this is possible but I was more than a little concerned about the legal consequences of such things. Being a large school, our site is in the middle of acres of fields, so we only ever see our own network and "rogue" networks trying to pretend to be ours (usually the kids trying to fool their friends) or things like public wifi from nearby coaches. But I was quite shocked that not only is it possible to easily block foreign SSIDs from even operating, but that this is sold as a feature (Air Marshal) that you can apply to ANY SSID you don't like, rather than just those trying to masquerade as your own.

It is, however, quite effective... if you set up an Android phone as a hotspot on the site, you'll find that no device is able to connect to it for more than a second without getting kicked off by the site-wide wireless. And, yes, the logs literally tell you that it basically performs a de-auth attack to do that.

If WPA3 does indeed find a way to stop this, I imagine that they'll find some other way to do the same, but still... it's a scary thing to have as just an advertised feature on a common managed wireless product. If someone did want to be malicious you could easily kill the wifi to an entire swathe of offices, houses, etc. in minutes.

WD My Cloud NAS devices have hard-wired backdoor

Lee D Silver badge

Re: I assume that....

1) They probably have UPnP (read: Automated, unauthenticated system to instruct your router to port-forward any given port externally to any given IP/port internally. In case you didn't know that).

2) Talking out is enough to cause issues like this to be worrying as you can then use apps to connect back to the drive. Presumably they are now blocking that username combination but who knows?

3) It doesn't matter... it's much more of a risk INTERNALLY. People are suggesting using these as iSCSI devices, which means they are acting as backing stores and live storage for VM's for servers, etc. That's just dumb to have a pre-fab password. This time next year, every virus will have those passwords included and will probe the local network so that that tiny local infection can - if you don't have full isolation - turn into direct access to all your iSCSI storage, etc.

Skynet it ain't: Deep learning will not evolve into true AI, says boffin

Lee D Silver badge

Re: Seems clear, refuse to use it if that's what you believe

Would I take the advice of an AI over a doctor's interpretation of the same result?

No.

P.S. For many years I was living with a geneticist who worked in a famous London children's hospital but has also handled vast portions of London's cancer and genetic disease lab-work. Pretty much, if you've had a cancer diagnosis (positive or negative) or a genetic test, there's a good chance the sample passed through her lab and/or she's the one who signed the result and gave it back to the doctor / surgeon to act upon. Doctors DEFER to her for the correct result.

Genetics is one of those things that's increasingly automated, machinified, AI pattern-recognition, etc. nowadays. Many of her friends worked in that field for PhDs in medical imaging, etc. It takes an expert to spot an out-of-place chromosome, or even identify them properly. Those pretty sheets you see of little lines lined up aren't the full story you think they are. She has papers published in her name about a particular technique for doing exactly that kind of thing.

The machines that are starting to appear in less-fortunate areas to do that same job (i.e. where they can't source the expertise, let alone afford it)? All have their results verified by the human capable of doing the same job. The machines are often wrong. They are used to save time preparing the samples etc. rather than actually determining the diagnosis (i.e. cancerous cell or not, inherent genetic defect or not, etc.) and you can't just pluck the result out of the machine and believe it to be true, you would literally kill people by doing that. Pretty much the machine that could in theory "replace" her costs several million pounds plus ongoing maintenance, isn't as reliable and needs to be human-verified anyway.

So...er... no. A diagnostic tool is great. But there's not a chance in hell that I'd let an AI make any kind of medical diagnosis or decision that wasn't verified by an expert familiar with the field, techniques, shortcomings and able to manually perform the same procedure if in doubt (hint: Yes, often she just runs the tests herself again manually to confirm, especially if they are borderline, rare or unusual).

If one of London's biggest hospitals, serving lab-work for millions of patients, with one of the country's best-funded charities behind it still employs a person to double-check the machine, you can be sure it's not as simple as you make out.

Last time they looked at "upgrading", it was literally in the millions of pounds for a unit that couldn't run as many tests, as quickly, as accurately, wasn't able to actually sign off on anything with any certainty, was inherently fragile and expensive to repair, and included so many powerful computers inside it I could run a large business from it. You can put all the AI into it that you want. It's still just a diagnostic tool. The day my doctor just says "Ah, well, the lab computer says you'll be fine" is the day I start paying for private healthcare.

Computers are tools. AI is an unreliable tool.

Lee D Silver badge

What I've been saying for ages.

What we have is complex expert models built by simple heuristics on large data sets providing statistical tricks which... sure, they have a use and a purpose, but it's not AI in any way, shape or form.

Specifically, they lack insight into what the data means, any rationale for their decision, or any way to determine what the decision was even based on. If identifying images of bananas, it could just as easily be looking for >50% yellow pixels as it is for a curved line somewhere in the image. Until you know what it saw, why it thought it was a banana, and what assumptions it was making about the image and bananas in general (i.e. they're always yellow and unpeeled), you have no idea what it's going to continue doing with random input and no reasonable way to adjust it's input (e.g. teach a chess AI to play Go, etc.).

This isn't intelligence, artificial or otherwise. It's just statistics. Any sufficiently advanced technology is indistinguishable from both magic and bull. In this case it's bull.

The scary thing: People are building a certifying cars to run on the roads around small children using these things and yet we don't have a data set that we can give them (unless someone has a pile of "child run under car" sensor data from millions of such real incidents), nor do we have any idea what they are actually reacting to in any data set that we do give them. For all we know, it could just be blindly following the white line and would be happy to veer off Road-Runner style if Wile E Coyote was to draw a white line into a sheer cliff in a certain way.

We don't have AI. We're decades away from AI. And this intermediate stuff is dangerous because we're assuming it is actually intelligent rather than just "what we already had, with some faster, more parallel computers under it".

Proposed Brit law to ban b**tards brandishing bots to bulk-buy tickets

Lee D Silver badge

1) So kids will have to have a member card to let them pick up the tickets. Not hard. You could even link them so your kids can use any ticket in your name, if you really want to.

2) Buying tickets that haven't been confirmed? Sorry, no sympathy at all. That's probably why there ARE so many resold tickets in the first place, and not enough for the people who want to actually go see. Speculative booking is at least partly the cause of shortages, and shortages the cause of speculative booking ("Quick, just order 2 while they have them, we'll see if Jeff can come later").

Compared to the sheer volume of tickets that are touted for every possible concert, such concerns are a drop in the ocean. And those other reasons are why the tickets are so hard to come by / so expensive in the first place anyway.

Lee D Silver badge

I just think you'd find an awful lot of John Smith's by that method.

Better... "Your ticket is confirmed, Sir. You just need to swipe the credit card that you booked with to release your tickets at the box office."

In fact, I'm pretty sure that an awful lot of London theatres that I've been to operate on that exact principle, just not for every single ticket. There's no reason you couldn't demand card-only booking in this day and age, though (hell, it's already almost "book online in the first ten minutes" if you want tickets to anything popular anyway). The Olympics basically did that and few complained even if it was only one particular type of card, too! Or even a "member's card" (with photo) that you have to sign up for and which is disabled if it's used for touting.

There're all kinds of ways to stop touting or make it so difficult that you could crush the industry overnight. The fact that they're not used tell me that someone gets a backhander or that it works to the artist's (or their management's) advantage to allow touting even if they can't admit that because it's screwing over their own customers to get more money.

If you compare touting to eBay bidding, that's what I think happens. 10% of the tickets aren't sold until the last minute when those people so desperate to go are willing to pay so much more just for the chance, so the total income rises dramatically just by holding onto 10% of the tickets until later on and selling them via "other" sites (often related, as mentioned above). You still only sell 10,000 tickets, but the last 1000 get you 10 times more money ("because they were sold out, but look what I got!").

I can't believe it's not an industry set-up, rather then thousands of independent people all looking to make a quick buck and hang around outside venues carrying lots of cash.

They don't want a "fair" system - of 10,000 tickets being available for the published ticket-price. They'd make less money, and it would also cost administratively to run. They'd then have to put up the face-price of the ticket to compensate, and fans would revolt.

While it still says £30 (or whatever) on the ticket, the artists etc. aren't the bad guys. And while someone is still willing to pay £3000 for a "rare last minute" £30 ticket, even the touts are the good guys. Win-win and the only person screwed over is the guy who can only afford the £30 ticket but never gets one because he can't book in the first nanosecond. You can make more profit out of a touted ticket than 100 of those people, so who cares?

That said, I haven't been to a live gig in my entire life. Nearest I get is classical music, West End shows, or a stand-up comedian. Biggest piss-take I've had? Russell Howard at Wembley Arena. Someone bought the tickets for me at great expense, we were so far away the guy was a tiny dot even on the big screens, and it was basically his normal TV stand-up, with almost no ad-libbing or interaction with the audience. Paying a fortune to stand in a sweaty pushing crowd for hours to listen to a bad ad-libbed and interrupted rendition of a handful of songs you've heard a thousand times, and a thousand songs nobody would ever choose to listen to? More fool you.

ICO slammed for 'unfair' approach to FoI appeal by UK judges

Lee D Silver badge

"Can't. Security, mate."

Now replacing "Can't. Data protection, mate" (which I've heard in the most LAUGHABLE of circumstances by people who haven't even read the DPA, nor have any idea what it's talking about).

[[I was once cited "data protection" by a bed company for sending out a free pack of missing parts to the shipping address that they'd shipped the bed to earlier that same day. Apparently, they could only send to the billing address (several miles away and not conducive to delivery of a bed in our new house) because of "data protection". P.S. Yes, they ended up shipping the parts to the right place after lots of yelling... sending a lorry out after-hours just to hand me a small bag of missing dowels and screws, so it never worked to their advantage to be obstructive and cost them a lot more than just the cost of the screws, including all future custom.]]

Sorry, but unless you can prove that releasing the entirety of the information requested somehow actually impacts national security in front of a court of law, I see no reason that you can't just be sanctioned into oblivion. Fine if you say "We can tell you this, but we've had to redact these parts", but to refuse the entire request? Nah.

You can't hide behind "national security" for everything vaguely military, because that's how you end up spending billions with golf-buddies because nobody was ever allowed to find out about it.

Kernel-memory-leaking Intel processor design flaw forces Linux, Windows redesign

Lee D Silver badge

Re: Unusual stock trades

Correlation is not causation.

Shopped in Forever 21? There was bank-card-slurping malware in it for, like, forever

Lee D Silver badge

Re: Question

Why were they downvoted?

"physical access to a terminal" - okay, fair enough.

"back office server" - storing plain-text credit card records? Strike one.

"head office PC" - storing plain-text credit card records? Strike two.

"plugging their own lappy into a live LAN socket in store"? No VLAN? No traffic encryption? No port-isolation? Strike three.

" (or weakly password-protected in-store Wi-Fi)" Strike four.

"infected website payload downloaded on the back office PC by staff at lunchtime etc" (See above)

None of those but literally access to a terminal should mean compromise. And even that means compromise of the terminal, no compromise of the entire system. Anything else is not only poorly-designed but not PCI-DSS compliant at all.

NOBODY - at any kind of office or otherwise - should be able to see the plain-text credit card data on their PC. From merchants to a central secured network with full encryption, which then submits to the bank over a similar encrypted channel, sure. But nobody should be using the credit card data itself (sales records and APPROVED/REFUSED are another matter entirely and should be on an entirely different system) at all except the bank. Hell, most of the retail-store systems you see just talk straight out to the bank over secured channels that the company has no control over.

That you can put ANYTHING on a POS network and have it sniff traffic, or compromise other ports, or do anything but talk over an encrypted channel to a bank is ridiculous. And certainly there should be no bog-standard office PC which has access to that data, even in theory for a large retail chain. Maybe a mom-and-pop shop, but they talk to the bank direct and the attack vectors are elsewhere in that case.

Honestly... just shouldn't be happening. And certainly shouldn't be CLOSE to a network that allows any kind of software update / attack / compromise of the system by a third-party. Their bank will have their ass on their PCI-DSS disclosures if that's even possible.

SuperFish cram scandal: Lenovo must now ask nicely before stuffing new PCs with crapware

Lee D Silver badge

Buy it.

Wipe it.

Reinstall it.

Best way to find out:

1) That you have the necessary disks, drivers and software to do so in the future.

2) That it's standard stuff and not proprietary "Lenovo-only" hardware with tweaked drivers that's impossible to source, replace or upgrade with anything else.

3) That there's nothing on there that shouldn't be.

4) That you "activate" on a version of software that you're able to reinstall yourself, rather than some pre-fab activation that might fail in the future.

If you're doing this on a corporate-level, there's no excuse. You should have pre-fab images, software installs and policies to go from bare metal to fully-working and secured client, no matter what model you choose. In my place, we literally have ONE image that everyone uses on every machine. It doesn't matter what hardware we throw it on, worst we have to do is slipstream a network driver into the boot, add an MSI package, or tweak a setting somewhere for them all the work the same. Literally 20 minutes and whether it was fresh out of the box, or an existing client, and you are back on the domain with everything you ever had.

Malware re-introducing itself via updates? Well, you were managing updates, weren't you?

At home, sure, bit different because of what's available but the principle is the same. And it's a lot easier to take a laptop back the day after Christmas and say "Look, it doesn't even turn on" and get your money back / choose a different model should your reinstall not go to plan, than it would be a year down the line when you need to use the restore disk.

To be honest, post-Christmas I refuse technical support requests because it ALWAYS turns out to be thousands of preloaded bits of junk on new machines that people aren't familiar with and so it panics them. Sure, most of the time you just uninstall and put the Windows image viewer back on or whatever, but it can take hours per machine. And smartphones are doing the same nowadays. I always recommend people get their shiny new smartphone, reset it before they start (especially if it's second-hand, you have no idea what's actually lurking back there), and set it up from scratch. But even then you end up with a load of bundled junk that you don't want and/or services you don't need (No, Samsung, I don't want to enable all your proprietary link-sharing junk, thanks).

I would actually pay £5 on the price to get a phone which doesn't have that junk. An official option from the manufacturer (not some random guy). "We can install our value pack of common apps, and save you £5, or you can have a plain Android install". I'd pay that. And for sure that's got to be more than you'll ever get from those ad-ware pushers to forcibly install an app on my phone, no?