The Register Home Page

* Posts by Lee D

4951 publicly visible posts • joined 14 Feb 2013

Credit insurance tightens for geek shack Maplin Electronics

Lee D Silver badge

Re: You cant have it both ways

Personally... let them fold. The jobs will go elsewhere (warehouse packings, shippers, delivery staff, telesales etc.) rather than disappear entirely.

Then maybe the high-streets will die back. And we can have restaurants etc. again, or 24 hour shopping centres. And all the rest can be turned back into the housing it once was.

Many things annoy me about modern life but being able to walk into a shop after work, or phone up a company when I get home, or pick up my parcels sometime outside 9.01am-4:59pm Mon-Fri.... that's quite nice. But how many shops do I need? Not many. Just the basics. Everything else I can schedule and have brought to me when I choose... that's called progress. For the last 10-15 years I've done all my Christmas shopping online. God, I'd HATE doing Christmas shopping in an actual line of shops... do people still do that?

And if we're not using them, then they can't survive, so why bother to try? What are you going to do, subsidise the high-street? Sell it off, use it as housing, then you might have people who actually live in these fake city-centres rather than just shop there during the day and get drunk of an evening.

24-hour services.

A place to park (hey, if only there were a big Maplin store we could convert into a car park or resident parking?).

Home delivery.

Cheaper and more convenient purchases.

Seems like a no-brainer to me. And judging by most town centres, nobody is going to lament the loss of those huge pedestrianised areas dedicated to Marks & Spencer and/or regurgitating kebabs.

Hell, build a ginormous post-office, a 24 hour supermarket, an Amazon dropbox thing, a petrol station, a pharmacy (could all be same place for all I care) and convert the rest into housing. Done. Don't even need a bank nowadays - totally pointless in the modern era anyway. 14 estate agents in the same street, though. And lots of gambling dens, just lately - I imagine the licensing laws have been relaxed because it's that or empty shops. Usually there are more estate agents than places for rent in or near that street, in fact, which I find ironic.

Hell, my road has no less than 4 pharmacies and it's only a tiny back road. I honestly can't work that one out.

I just hope that the incomparable convenience and customer service of online ordering will kill off all such places, and maybe then we'll get towns again. Rather than the same ten shops in a row, and a bank with no staff.

Our kids are going to think that actually going into a shop is "quaint" and a novelty by the time they're my age. I can't say that I would fight for them to have access to such things. A library, yes, but we closed those all down because they aren't profitable "and the internet".

Town pubs are dying off.

Post offices are dead.

Most conventional shops are dead.

Banks are gutted shells now.

But my shopping arrives tonight, and I can't say I begrudge the poor guy the £3 delivery charge for saving me half-an-hour's drive, an hour pissing about with a trolley, then several re-packs of my groceries to the till, to the car, to my house, to the cupboards, and not having to contend with a single queue or idiot who can't remember their PIN or wants to hold up the queue while they go back for a different bottle of bleach.

If we could just kill off ticket offices at rail stations and turn them into parcel-collection points, I'll be a happy man, and I don't even take the train any more.

Sick burn, yo: Google's latest Pixel 2 XL suffers old-skool screen singe

Lee D Silver badge

Irony - today I saw my first ever burnt-in monitor, and I've been using and building PC's for 25+ years.

I had a week off work, got back, and our workplace logo was burnt into the LCD screen of the computer that only I use. Not bad, you only really notice on flat-backgrounds, but when I lock my screen it's perfect placement on the dark-colour-on-bright-white logo that sits on the lock "screensaver" (whatever you want to call that screen that comes up eventually if you wait too long to login).

Never seen it before. Had heard about it for years, but even my oldest CRT never did it, I've never used a plasma screen (mainly because of such issues) and I'd never seen an LCD do it. The only other place I've ever seen it is some really cheap projectors.

Until today... and now The Reg tells me that phones get this too? I'll worry about it in 25 years.

Fortunately, I'm the IT Manager. A new monitor is no biggy, but I'm gonna see if just some normal-screen-use will fade it out over time.

Phone crypto shut FBI out of 7,000 devices, complains chief g-man

Lee D Silver badge

If the lockscreen is on, and you don't have the passcode/word, how do you think you can go about cloning it?

The passcode unlocks the real decryption key, which unlocks the data. The shim that takes your passcode and does that will wipe the data if you try too many passwords. So you need to dismantle the phone, clone all the storage (difficult enough with today's miniature chips), and then password brute-force against the storage while then checking to see if what you decrypted ends up as nonsense or (in a single, solitary instance) your stored data.

Manufacturers - including Apple, surprisingly - refuse to co-operate or supply fake shims, backdoors, etc. so there's no help there. You're basically into full brute-force, which could take... well, centuries if they'd chosen a decent password.

And that's if they didn't further-encrypt the data on the device using some other program.

And the penalty for them is a few years in prison for failing to reveal, or to have an entire terrorist cell know who it was who gave up the information that landed them in the spotlight. I think most terrorists with a brain would keep schtum at that point.

Plus, after a few years in jail, claiming that you don't remember the password would probably get a lot of medical experts on your side saying that most people wouldn't remember it by then, even if they originally had and wanted to co-operate.

Lee D Silver badge

Re: Weak Logic

Pretty sure the European Court of Human Rights would hear about that quite quickly.

Lucky we're not pulling out of that organisation or anything....

Lee D Silver badge

And thus the primary purpose of device encryption has been fulfilled.

Though I'm not at all happy that a potential terrorist may have got away with something because of this, I could not bring myself to say that this is in any way unexpected or reason to take specific action against it. It's like trying to outlaw fires in case criminals burn the evidence against them.

That said, kinda puts paid to all that "acres of datacentres" nonsense, if they can't even decrypt a phone. either all that stuff was no help at all, or it doesn't actually exist.

Plants in SPAAAAAAACE are good for you

Lee D Silver badge

Re: There's got to be a lot more of this if humans want to live on other planets.

The problem is - as always - weight.

The weight of food needed to sustain a handful of humans for a year is... well, quite enormous. Yes, you can argue that you can recycle your own waste, etc. but it doesn't get away from the fact that that requires more heavy equipment to do so.

The break-even point on weight has to be low, or it's just not worth bothering. Weight has been the expense on everything from satellite launches to the Apollo missions to modern probes. Whatever you send, you have to get up to 10's of 1000's of mph to escape Earth. And that's the CHEAPEST POSSIBLE WAY to do so (moving slower than that costs you more because you have to "stay up" for longer while still trying to make progress).

And when you look at how much it cost to launch a human, all the food they would need to survive the minimal amount of time, all the equipment / seeds / whatever they would need to grow - with the best fortune possible - more food as quickly as possible using as much of the local resources as possible, plus all the life-support and other stuff... it's a ludicrous amount of equipment. No human has ever been more than a month away from an entire planet-worth of food. No human has ever grown anything near enough to sustain themselves in space. No human would be able to carry the amount of stuff you'd need to do so. The Martian - which I absolutely hate because the writing is childish and atrocious - kinda got this one right. To get to that point, you need an entire damn base which you have to give over to food production, and then you might just have enough to stay alive a bit longer.

Weight kills space travel. And the problem we have is that you can barely pack a year's worth of food onto a long spaceflight if you just threw money at the problem. Let alone enough stuff to actually grow another year's worth - guaranteed - within a year.

Combinations? Permutations? Those words don't mean what you think they mean

Lee D Silver badge

Have a UK maths degree.

Have never referred to it as a shriek. Or a bang. Both are quite American, I think. Yes, even in the Unix shell-script !/bin/sh sense, I don't call them shrieks or bangs.

Never heard of the other words used in this thread either.

It's an exclamation mark (if in speech / symbol) or it's a mathematical mark: "x factorial". Or it's possibly "NOT" if used as a logical operator.

The one in UNIX paths, I don't call anything in particular because how often do you have to explain to someone to type in a ! into a shell script who doesn't already know exactly how to do so?

I guarantee that if you try to read out a password with an "!" in it to a random person, they won't understand shriek or bang or pling. But they know what an exclamation mark is. Hell, even "hash" for # confuses people ("Yes, it's the little noughts-and-crosses board" "What's noughts and crosses? You mean Tic-Tac-Toe?" etc... it might be called 'hash' or 'pound' (US) or 'octothorpe' or, to music people 'sharp' but if you choose any one of those when talking to a random person you have about a 50% chance of success - if anything "hashtag" actually works better but I refuse to call the symbol that, and people often don't know what "hash" on its own means).

Lee D Silver badge

A pseudo-maths article, that's unusual.

Though the bit I like about perms and combs is that it's a perfect demonstration of factorials. Factorials get out of hand REALLY quickly - 21! won't fit in a 64-bit number, for instance, and just 69! is enough to exceed most calculator's display capacity (even with exponents up to 10^99 and complete loss of accuracy). And something like 449! is an incredibly difficult-to-handle number (> 10^999).

However, nPr and nCr are basically multiples of large factorials (e.g. 49 choose 6 for the lottery: 49! / (6! x 43!) ). But, because of what a factorial is - every number up to itself multiple together - they cancel out really fabulously so you never have to have 1024-bit numbers to work them out.

It's little things like that that make maths beautiful - eliminating the need to do ridiculously large calculations by just using the right notation and a little algebra.

Future of Misco UK hangs in the balance – sources

Lee D Silver badge

"No, nothing of value being lost at all. Just potentially hard working people's jobs and careers. Nice comment."

Would you rather we set them up in a fake office, with fake customers calling, buying fake products, just to give them some money?

Companies come and go. Therefore jobs come and go. There's no such thing as a job for life any more. Even politicians can't stay in one job more than a couple of years. Anyone with half a brain / skill / experience would have been out the door long ago.

Never got the "it's people's jobs" thing. If they were doing their jobs, the company wouldn't be bust. And by doing their job, I include things like "walking out the door, registering vocal complaints, when the CEO spends £10k on a golfing holiday while the sales team struggle to sell the rubbish kit his golfing buddy has lumbered you with". We live in an enlightened, rich, pseudo-democracy. There's a dole queue. And there's jobs out there. It's not like they'll be a starving Welsh miner with nothing to feed his family with and hundreds of miles from the nearest work. These people work in Watford and places like that! (P.S. I live in a neighbouring town!).

The company is bust. The jobs are gone. Anyone with half a mind at the company knows what was coming (as it's been coming for MANY years as I describe). They needed to get out long ago. No fool ever stays somewhere that's going into administration - not even for their pension / redundancy as you can be sure that's the first thing that's found to be inadequately funded. I'm not unsympathetic - but precisely because this thing happens all the time and is the norm now, not the exception, I can't say I'm crying into my cornflakes for them either.

Don't work for bad companies. And don't EVER give me the "there are no jobs" rubbish. Certainly not if they live anywhere near Watford.

Lee D Silver badge

Re: Blast it

You must deal with some really crappy suppliers then.

WStore are the people who CC:d my boss calling him a idiot on an internal email. They lost tens of thousands of pounds of annual business just by not having a proper CRM program.

But basically from there, the world is divided into "we only stock X" and "we stock nothing in particular and everything you can imagine - what do you want?" companies. The problem I have with that is that there's no knowledge or investment with selling other people's stuff whether you're gold-partner or whatever other nonsense they took an online test to get.

I bought IBM (was still IBM at the time, now Lenovo) server kit from a reseller. I then found another reseller when that one couldn't work out simple things like "I have it in writing, on the quote, the purchase order and the invoice, and in several emails, the fact that I don't have the thing I ordered is your mess-up for mis-quoting, not my mess-up for insisting I get what I ordered" (to the point of legal threats and having their financial directors visit my workplace to argue it, where I pulled out all the emails and paperwork that they could have found in 10 seconds if they'd bothered). Since then, I've moved from them to another because they changed staff and became junk overnight. But it's years between each, and there are always 5-10 just waiting in the wings willing to sell me absolutely anything from anyone. I've dealt with four different companies to supply Cisco Meraki kit (and that's one of those "Merkai phone you up because you've dared to order your kit from someone else this time around and do you want to change who your supplier is?" places that drives me mad). I have a company that sells mainly Axis IP cameras who are looking into buying their rival's equipment because I asked them to.

When a company doesn't want to give you want you want, you move on rather rapidly, and I'm happier to move very quickly and on a whim / minor issue because there are just so many others competing that I can play them off against each other. But it's never been hard to get someone who'll resell anything you ask of them. I have at least 100 emails in my inbox (after I refuse their calls or just fob them off with "If you want to get on the list, you have to be searchable in my inbox") from similar companies, some of them vying to regain 10-year-old business with me. Most of them I'd use quite happily. But I have to take it with the knowledge that a) they are paying other companies their profit, b) they have little to no influence, c) after special "introductory" deals, they're usually more expensive than just buying the kit straight (but that can work to your advantage), d) they often disappear overnight - even big names like Misco once were...

Lee D Silver badge

I had a friend who used to work for Simply Computers, back in the day (in the Watford office, I believe, but I may be wrong).

Then they were bought up / renamed by Misco.

Then Systemax bought up Misco.

Now Misco/Systemax look like they're dead. They also own WStore, and that uses the InMac name. These were all big names at some point in their existence.

I can't say I'm surprised. At one point, the days of flicking through PC Pro tomes as thick as your thumb looking at the shiny-new, they were some of the biggest... but even then I only used them for little commodity items. Neither I nor the guy who worked for them had a computer from them, even with the staff discount, and rarely used them for anything else.

Then mail-order became old-hat and, honestly, it took them a long time to work out what to sell. For the last 5-10 years they've been just a parts-pusher - in one door, out the other as quickly as feasibly possible. Standard stock. No unique selling point. The Maplin of the mail-order world - nothing they have that you couldn't get elsewhere cheaper, faster and more pleasantly but people used them because they'd always used them.

In all that time, I literally don't think I've ever ordered anything from any of those companies. They just couldn't come close to competing for business-level transactions, and they were too obscure for retail - people didn't know what they were buying, and those who knew went elsewhere. I can't think of a market they catered to. They used to phone me up occasionally or I'd use them as that handy "third-quote" because I know they'd be more expensive.

I'm sure they'll blame "Amazon" (or that CEO SEC filing controversy listed on their Wiki page) but those companies were in absolute freefall for many years and did nothing about it, besides making themselves even less relevant.

To be honest, nothing of value is being lost. They're box-pushers, and thinking that competes with others by standing out is a mistake. It's sad to see all the old names slowly being bought up, but that's because they just don't adapt.

Linux kernel community tries to castrate GPL copyright troll

Lee D Silver badge

He owns the code.

He therefore has the right to sue if you're not compliant with the license.

I can't say I disagree with his stance - maybe his intentions, but he's not doing anything wrong as such. He's probably annoyed the people AREN'T honouring the GPL on his code. And 0.25% is a DAMN SIGHT more code than I'll ever wrote, own, or get to be used in a major modern operating system. He's done the legwork, he's not exactly trolling, and courts are presumably not throwing out his cases. If he gets a few million from companies because they're not complying, well done to him. I'd like to think if 'twere me that I'd give some of that back to Linux somehow as it's not just his code that was infringed, but that's a personal, moral choice, not a legal one.

And these companies presumably infringed his code that GAVE NO SUCH RIGHTS to allow them to resolve their GPL infractions in a nice way. Even with such a statement, there's nothing to say that every kernel developer / copyright holder agrees and will abide by that - they can't. Some of them aren't even around any more to give that kind of permission.

Sure, it's not what I'd do. But several million Euros for plainly illegal infringement of your personal copyrights? Yeah, I'd be having words for sure and that would give me one heck of an incentive.

I can't say that I could really make the guy out to be inherently evil, as the article seems to imply I should.

Never mind the WPA2 drama... Details emerge of TPM key cockup that hits tonnes of devices

Lee D Silver badge

Re: Ignorance is bliss, so why do I drink so much?

Good luck buying a machine nowadays without a TPM.

Most places will let you turn it off, but sometimes "Secure Boot" is a necessity, especially for odd devices (e.g. Windows tablets, Chromebooks, etc.) and TPM is a part of that.

It's a chip that holds a keystore. The keys can be plugged into it. They can be used to encrypt and decrypt. But the key doesn't come back out (I'm pretty sure nobody's managed that yet, certainly not a cheap/easy/guaranteed way). It's basically what smartcards are - you know they have a key, you know they have the private part of it (because they can encrypt and decrypt) but you can't extract the private part of the key itself once it's on there.

The OpenSSL stuff is just using the TPM as a keystore. It has nothing to do with usage of the TPM by, for example, a Microsoft key signing a Microsoft bootloader. P.S. even modern Linux distros have to have a Microsoft-signed bootloader to boot on UEFI / Secure Boot systems. In theory you can add third-party keys, but the UEFI BIOS rarely actually expose the option to the end-user.

Modern Windows can even put things like the equivalent of Windows product keys into the TPM (not quite, but almost) - so that the machine is licensed without needing the user to type anything. BIOS-locking done at the factory, basically. It also means that if you move your Windows install to a different board / chip / BIOS / machine it likely will de-activate itself.

The generation of those keys, however, is a concern and it very much depends on whether they were made by the machine itself, by the TPM chip in the machine, or by the manufacturer. Also, as per your OpenSSL example, there is room on the chip to use it for DRM for software manufacturers or yourself. Thus, some people will now have TPM keys that aren't as secure as they believed.

It's not infeasible that such an attack will hurt BIOS-locking manufacturers (including people like Google who use the TPM on their Chromebooks), software DRM schemes for the most expensive software, Bitlocker (eek!) and activation keys on Windows, etc.

The TPM chips now do everything from random number generation to the full encryption/decryption of the data stream, potentially from boot-up to shutdown.

And just about every machine now has one to the point that they are incredibly difficult to avoid. Your smartphone probably has one. As does your tablet. And so will your PC if it's been made in the UEFI era (even legacy BIOSs are becoming rarer now, but they often appear as a set of "UEFI Only / UEFI and Legacy" options so the UEFI/TPM/etc. stuff is often still present but unused for boot-integrity (Secure Boot) unless you make the machine do something like Bitlocker).

This is a big ouch, which is why some manufacturers are running around re-building their TPM keys at the moment.

WPA2 security in trouble as KRACK Belgian boffins tease key reinstallation bug

Lee D Silver badge

Re: Uncorrectable Horse Staple Battery

The handshake is part of the protocol. Not the encryption.

As I predicted / guessed / inferred / lucked-out-on: The protocol is broken and re-uses data that it shouldn't (presumably in order to account for wifi noise). Nobody's broken Diffie-Helman. Nobody's broken AES. If you treat your wifi as an UNTRUSTED NETWORK (yes, my clients are firewalled even ON the wifi such that it's "the internet" to them), then you're not affected. Maybe someone can browse Google on your wifi, at best.

So you do what I suggest - treat the wifi as UNTRUSTED. Make it so that clients have to VPN into a router/server even on the WLAN, so that even if someone is sitting reading EVERY PACKET of your wifi connection, they still can't get online / talk to your network / interfere with your devices without first connecting to and authenticating against the VPN server too.

Wifi is - and always has been - insecure. Because you rely on the fact that every client is "safe" and whitelisted, including your laptop, if you have the right password. It's stupid. Stop it. Treat Wifi like an Ethernet cable that goes through a wall into... what? Who knows? Could be anything happening back there.

Public-key encryption, proper security, public-keys, and to an authenticated destination that's the only machine you have to trust (instead of EVERY SINGLE client and device on your network).

Lee D Silver badge

Re: Uncorrectable Horse Staple Battery

What a silly statement.

Encryption is DESIGNED so that anyone can capture the packets and still not be able to decrypt the message. The medium matters not. if you operate your systems on the basis that it's difficult to send / recieve rogue packets, you're just leaving yourself open for compromise. Encrypt, VPN (even over home wifi - why not?). All media are equally risky if anyone else is on them at all.

In this case it looks like they've forced poor implementations to behave improperly (nonce reuse), which has little to do with the actual encryption. Maybe the protocol is poor, like WEP. But notice how no-one is saying AES is broken?

If you just work on the assumption that all media are vulnerable, then encrypt with known-good encryption (not RC5 or TKIP, and yes you MUST keep up to date with what's safe!), it really doesn't matter what happens or who can send you packets.

VPN over WPA2 on every home network I've had. Zero latency (I game a lot). And survived the whole WEP/WPA/TKIP vulnerabilities with time enough to safely upgrade.

Always assume every network interface is sniffable. Encrypt everything.

Sniffing substations will solve 'leccy car charging woes, reckons upstart

Lee D Silver badge

I have a huge 32A commando connector thing on the outside of my house.

It runs an electric kiln but, while you're there, why not make it a permanent and swappable fixture so you can use it for other things in the future, building works, etc.

But, unfortunately, it would be bog useless for even standard charging of an electric car the way I use mine. I'd just about be able to use it for the little electric moped that the other person who lives in the house would use incessantly (they're Italian, though, so...)

Given that that one device can pull more current than ANYTHING ELSE in the house (even a boiler or cooker), and that even that device is not sufficient, I can see no reasonable alternative that people can use. The wiring here is actually quite good, I pity those people who don't have modern wiring though.

You're basically talking about a significant portion of people who currently own a car having to upgrade not only their fuseboxes / fit electrical points etc. but also upgrade their incoming feed entirely (and so the electric company will demand new meters, checks, etc. along the way). That's an incredible expense.

The alternative is that petrol stations become charging stations, but then you are stuffed if your battery does die while you're on holiday - you need a tow to get it going. And the queues are going to be horrendous if you have to wait 20+ minutes per customer, unless you literally have five times as many charging points as you did petrol pumps. Which just adds to the problem.

I can't see it happening any time soon. I doubt they'll ever reach their petrol-car cutoff dates. I foresee an endless pushing-back of that date. Especially as they get no tax from it, but have to pay a fortune to provision for it.

Fear the SAP-slap? Users can anonymously submit questions about licensing naughtiness

Lee D Silver badge

Re: Complex licensing

Exactly.

But then, that's SAP's business model, isn't it? Along with Oracle? Make the licensing sound so attractive while you're small and then sting you on absolutely everything once you're larger.

To be honest, SAP's stuff isn't even the worst. But I fail to see how what someone does with the output of a program can somehow still be "licensed". A basic licence for the software, sure. A licence per seat, sure (but I would add that support costs should be included in such a licence). A licence to unlock features, sure. But the "licence because your computer has another core/processor"? That's just getting silly. Hell, charge a fortune for an integration licence, that gives your data out in a specified API that others can use - I get that. Hell, charge per API call or something if you like. But if you CAN miscalculate to the tune of £50m just by taking the output from the software and using it somewhere else in your own business, that's really getting a bit stupid.

I have to say, for this reason, when people who don't work in IT talk to me about IT and are so keen to tell me that they've just moved over to SAP, or Oracle, or whatever, I shake my head and walk away. Some day it will come back to hurt them. Many of them don't even know what it is and certainly don't work in a company large enough to justify it, they've just heard that other bigger people do, so they end up on the same things.

Video games used to be an escape. Now not even they are safe from ads

Lee D Silver badge

Echoing all the comments above:

I've never purchased HD content deliberately in my life (sometimes you don't get a choice now).

I've never cared about anything but a reasonable screen size given the purpose. This means, yes, a smartphone is MORE THAN GOOD ENOUGH to watch HD movies on. Which is it? Is SD too blocky that I would notice on a phone, or is the phone good enough to watch HD on from the short distance you would. Also, my 32" TV is perfect. Doesn't consume a wall, while being great for gaming, movies and TV.

Strangely, the money I've saved on not having stupendous display devices is spent on ACTUAL CONTENT to watch instead. Weird that. It's almost like I prefer actually watching things to measuring contests.

Additionally, hello, this is the 21st Century... Chromecast / Firestick? You just flick the app and send it to the TV. Done. Like hell am I booting up a full machine just to do that when the phone is next to me.

And then, when you really get to it, all the modern HD-only junk is really not my thing anyway. I much prefer to put on an old sitcom, anyway. Who cares whether it's SD, HD, or not in that instance? You literally NEVER NOTICED until someone brought out DVD's, then you NEVER NOTICED until someone brought out flat-screens, then you NEVER NOTICED until someone brought out HD, then you NEVER NOTICED until someone brought out 4K or whatever. Yes, VHS sucked and was blurry and we all knew it, even back then. But ever since, I can't remember complaining once.

Revisionist history of resolution/quality is what you suffer from. When you got your HD TV were you just thinking "God, if only this was 4 times more high res, I can't stand watching it?" No. And the reason is because you couldn't see it then and can't now. Same for SD/HD.

The best TV picture I've ever seen in my life, that literally made me go "wow" and use it for everything, was with a Hauppauge WinTV card on a SVGA monitor. It was so fabulous a leap in quality from an old interlaced TV that it was amazing, despite still only showing an SD signal (but it was pixel-perfect because of a huge loft aerial and a monitor that could show the full TV res in a tiny little window while you worked). Since then, it all looks the same at any reasonable distance (which could be inches for a smartphone resting on your chest lying in bed, for instance).

To me, I believe in the XKCD cartoon - HD is only slightly better than the monitor I had in the 90's, which I used every day a lot more than I ever did the TV. Only in recent years have TVs and monitors been the same tech in different shaped boxes. But I'm used to that kind of resolution. It's essential when doing pixel-perfect placement. But watching a movie? I really couldn't care.

Yes, a smartphone on my chest shows me a movie in all the quality I need. And I saved £2 by not buying the HD version. And I enjoyed the core point of the whole exercise - the movie.

Lee D Silver badge

Don't mind ads.

Just don't interfere with the game.

E.g. in GTA V - feel free to sell the billboard space, and even radio ad space. Same in movies - Bladerunner can advertise whatever it likes, as an advertisement itself within the movie world.

But don't make it so that I have to listen to / watch it. That's game over.

And don't make it like "I, Robot" with the Nike/whatever shoes - where I just cringe at the blatant and unapologetic product placement for no reason whatsoever.

Racing and football games have often had ads on the billboards around the arenas. Fine.

As people say, things like Robocod had sponsorship from Penguin. Fine. There were levels of penguins (not unlike any other level in the game) where the penguin bars were part of the scenery. No problem. If you don't know what a penguin bar is, you wouldn't even notice.

But make me sit through an interstitial, break through the fourth wall with it, or make it so horrendously blatant - IN A PRODUCT I'VE ALREADY PAID FOR - and I'll not touch it.

Hey, Amazon. How about NOT giving me a trailer for something I couldn't care less about every time I open the Amazon Prime Instant Video app on my phone - a service that I already pay you for? A Skip button is not the same as just NOT showing me that junk by default. In fact, a Skip button is like an "opt-out" button on a piece of spam, as far as I'm concerned. I shouldn't have to opt-out, as I never opted in to the damn email in the first place.

Microsoft silently fixes security holes in Windows 10 – dumps Win 7, 8 out in the cold

Lee D Silver badge

"Windows 8.1 is supposed to receive monthly security fixes until January 10, 2023, and for Windows 7, January 14, 2020."

Great. I shall set my deployment plan for Windows 10 into motion in January 2022.

Four-and-a-bit more years of bliss before I have to deal with that heap of junk. That's an entire hardware/software cycle to me anyway.

I mean, making 8.1 work like 7 was bad enough, but pretty much you could get there and not have people notice.

SCARY SPICE: Pumpkin air freshener sparks school evacuation

Lee D Silver badge

"After the break, we'll be bringing you the story of the Lush store that was shut down as a chemical health hazard. Keep watching."

Dumb bug of the week: Apple's macOS reveals your encrypted drive's password in the hint box

Lee D Silver badge

Re: To be fair

AND THE HINT IS COPY/PASTE OF A PASSWORD FIELD THAT SHOULDN'T BE ANYWHERE IN PLAIN TEXT.

Literally, they have two variables;

Password

Password Hint.

They have taken plain text from the user, put it into password and that's ended up in password hint by mistake.

But EVEN PASSWORD shouldn't be like that. It should be opening keychain, or it should be hashed and stored and the original immediately disposed of, and it certainly shouldn't be accessible to the disk encryption program. That the password and the hint are handled anywhere near the same way tells you that they're doing it wrong.

The entire PROCESS is wrong, such that a simple error reveals the password. That password shouldn't be sitting in a plain-text field to begin with, such that it can be confused and accidentally written somewhere else.

(Hell, I'd argue the password shouldn't be in memory as a string anywhere... I would code it so that the password box was really just a keyboard-event receiver and for each key hit I would throw the received key straight into the hash function and store only that in RAM. Store the last 50 hash functions to let people backspace (and, yes, stop, them clicking into the middle of the password and typing extra chars, etc.) - show it as a password box with X amount of *'s in it, but only store it as a hash)

Lee D Silver badge

Re: To be fair

It's more worrying than that.

Plain-text copies of your password are being used and stored. That's just not how you do it. You take the password, hash it like mad - including salting it - and then encrypt using the hash.

If you have half-a-brain, you then use that only to encrypt the REAL key that unlocks the drive, rather than the data itself.

In this way, the password is not stored anywhere. You have to match the salt and hash (which can only come from the password the user types in), to unlock the real encryption key (which can be many times stronger). Nowhere on the disk is stored "My Key Is: ...", only users who know the password can log in, anyone can steal the drive and NOT be able to unlock the key, because the drive isn't unlocked until you've typed in the password, there's no chance of there being remnants of the key stored on that same drive, and you can back up the critical headers which store the real key (and the initial password they were created with) and so recover the drive later if something goes drastically wrong or the user forgets the password they changed it to.

There's a reason that TrueCrypt and all its descendents work like that, as well as any sensible commercial encryption software. Because anything else is snakeoil.

The Disk Manager app should have PRECISELY zero access to the actual password, it should be hashed and salted immediately on entry and only THAT passed to the processes that need it. That fact that there's even a bit of code that resembles "put plain-text password into this structure" means that they did not design the encryption properly, whether or not they slipped up between "password box" and "password hint" box.

Support team discovers 'official' vendor paper doesn't rob you blind

Lee D Silver badge

What a stupid failure mode and assumption that is, then.

Hell, put a barcode at the BACK of the empty slot and if you read that barcode - yeah, it's fair to assume it's empty. Or a 20p micro-switch testing for physical presence per slot to distinguish "no tape / physical obstruction" from "tape has a slightly smudged barcode".

But tapes get handled and modified, and it must have read it once to put it in that location. It's bad design to not distinguish between a bad barcode, and one that doesn't even exist.

Lee D Silver badge

Coupled with the usual "Oh, no, we haven't changed anything" syndrome from the customer, most likely.

Yeah, it's odd that in a device costing quite a lot of money, nobody bothered to put in a routine that said "Hold on, I can't read that barcode, better alert the user in an obvious and sensible fashion".

HPE server firmware update permanently bricks network adapters

Lee D Silver badge

This.

But more precisely - why does a driver let you update it except against known-good firmware?

Quite literally "Sorry, you have to update driver firmware to continue, to at least X.X.X which has been tested with this driver".

If the ***only*** official way to do it is to update the firmware and then the driver, the driver should be checking that the firmware is up-to-date and refusing to continue.

And I'll tell you the answer - because they will break as many systems that way as any other. People will be stuck on old firmware/drivers because of a bug in or one or the other that they know hits them elsewhere, so they don't upgrade at all, rather than risk having to do both.

But, honestly, with this kind of kit - you literally say "Not a supported configuration" in your update tool, and then offer the path to get a support configuration (i.e. update the firmware first, then the driver). At this level, if it's not been tested, it shouldn't be possible.

Microsoft Edge shock: Browser opts for Apple WebKit, Google Blink

Lee D Silver badge

"On iOS, we are using the WebKit engine, as provided by iOS in the WKWebView control. "

Because Apple will literally not allow anything else.

Chrome is the same on iPad, just a wrapper around the same controls.

ALL IOS BROWSERS ARE THE SAME ENGINE. Hence, there is literally no point, as you can't change or improve anything to do with the rendering whatsoever.

Been telling people this for years, but nobody listens and they still install "another browser" on iOS.

P.S. Also bad from security perspective - one flaw, hits all iOS users no matter what they use.

Toshiba, you can't have 14TB served on a platter. It'll take eight, at least

Lee D Silver badge

I'd still much rather have an affordable 2Tb SSD.

As in MUCH rather.

That's the second article today on hard drives (Seagate, Toshiba) and I actually question why anyone is still pumping money into them, except to get the "last run" of hard disks out the door.

I do hope that these companies aren't spending all their time and money faffing about with helium.

Is it the right time to virtualize?

Lee D Silver badge

Re: Not always

VM's migrate. Physical servers don't. You can send them to another datacentre, onto a server you've never touched before and it'll work and keep running like you'd never switched it off. That's a real bonus that you hope you'll never have to utilise.

VM's make better use of server resources. All those "spare" VM's that aren't actually doing anything can sit idle on servers that ARE doing lots of other things. That stupid VM sucking up Gbs of RAM for no real purpose or usage can be pushed back to swap while the ones that need it can use the hypervisor's real RAM. Few things use a lot of CPU - Exchange uses almost nothing, so it can co-exist with VM's that are CPU-heavy, but IO-light.

Additionally, yes, VM backups are SO MUCH NICER. No more faffing by cherry-picking system state items and hoping that you can replicate the config should that fancy network card blow up and you need to put it on something else. Just backup "the machine", with every configuration on it and every setting and snapshots of the historical settings. Done.

VM's also snapshot and replicate: snapshot the live server, spin up the replica in a test environment, play with ALL the settings and break things, and know you can roll-back to known-good instantly even if you made a mistake. Sometimes in seconds. And being able to "splice and test" like that is invaluable. "What WOULD happen if we upgraded that primary server to the next version of Windows?" - don't guess... do it... see what happens, just by branching from a snapshot of that EXACT server. Delete it when you're done, or push it back into production.

And redundancy costs twice the resources (or more) because it's redundant. That's the ENTIRE POINT.

VM's are the only thing I'll use now. The only blockers are those stupid things that DEMAND a certain piece of hardware (e.g. dongles, etc.). Everything else, you get a VM. I run CCTV NVRs from inside VMs and they work perfectly. And it's cheap to spin up a VM every time someone says "the guy is here to install the software for X". Don't faff - just give them an entire VM to do whatever they want in, and then put that VM on your network. They can have no argument then about "Oh, well, it's not compatible" or "it's because you have X installed", etc. Most of my vendors are offering their appliances (e.g. webfilters, firewalls, etc.) as VM images now.

VMs and VLANs are the best thing to happen to in-house IT in decades. It's literally makes your network portable, to the extent that there's one backup device in my pool which is just a cheap NAS, large enough to hold and offer every VM out over iSCSI.

I could take that box. Find ANY decent server hardware. Load those VM's. Boot them up. Have EVERYTHING running as it was in under a day. Literally my entire network in a box. And - in theory -the only thing I'd need to get running on new physical hardware is a way to load up the one VM that's the hypervisor to all the other VM's. Nested hypervisors are cool.

Lee D Silver badge

Re: Has a Blog Bot kicked in?.....

Glad it's not just me.

"Is it the right time to virtualize?" - er... no... that time was about 10 years ago, mate.

To me that's at least three hardware cycles, servers and clients.

Sure, network virtualisation is still a bit "what's that?" to most places, so I can understand not touching it. But servers - yes. Storage? Depends. Most people don't do a lot of storage, but the article is aimed at datacentre (or so it says).

But "should you be virtualising your old crusty servers?" Hell yes. Unless you are in HPC or similar, of course you should. You should have been doing it for YEARS already.

Web uni says it will get you a tech job or your money back. So our man Kieren signed up...

Lee D Silver badge

Re: "...a good percentage of the population is not suited to programming..."

Damn right.

I could write any program someone wanted (if it was a program that could be written). Pretty much, I could write it in any language (those esoteric non-traditional ones would be a real struggle but I'd pick them up). I can't guarantee a timescale at all, but I'd be able to do it. I've programmed in everything from BASIC to x86 assembler, Pascal, FORTRAN. C. Java, hand-crafted Z80 opcodes electronically zapped direct into a memory chip. I've ported software between platforms, ripped-out-and-re-done entire codebases, patched my own code onto the Linux kernel and other people's projects, and been doing it all for years. I sat through years of courses on coding theory, compiler design, etc.

But for sure, I'm not a coder. Doing it professionally? Pfft. No thanks.

I'm sure I could write any program I needed, and I'm often really frustrated by the tools I'm forced to use and know they could be made better. In some cases I've actually done just that, where it was an option. But coding is a skill that is rare indeed.

Instead I work IT management in schools. Let me tell you, thousands and thousands of children from a range of abilities and ages have passed through my systems. I help out in coding clubs and we build and fly drones and all sorts of things. Independent (private) or state, primary or secondary, etc. Would you like to know how many of them there are that I believe could, one day, go on to be a full-time software developer? Maybe one or two. How many could knock up a quick script or program or even a complex macro in their adult years, or become a hobbyist programmer, without having to literally be taught how to do so from scratch? Probably a few dozen. Maybe slightly more.

As a percentage, we're really talking less than 1% for most of these things. Which is right. Less than 1% of them will become aeronautical engineers, or explosives experts, or forensic scientists. But for some reason people assume that "everyone can code if you just teach them". That's true right up to a point. And that point is where "computing" (using a computer) becomes "computer science" (understanding how they work). That's where almost everyone who uses a computer gets stuck. In the same way that we can't all be car mechanics, we can't all be programmers. We all need to use the tool, we don't all need to understand every intricate detail of it.

We've lost sight of that, though. Especially in education. Programming is really something that you either have a knack for (I would say I do) or not. You can nurture an existing natural predilection to being able to think like a programmer, but you can't instill it if it's not there.

The other day, I glanced out of the corner of my eye at some code a 9-year-old had written in Python (which is pretty cool, don't get me wrong, but if it's just taught by rote it tends to be forgotten REALLY quickly). My brain picked up on four syntax errors, a couple of potential integer range situations, several comparison errors, mis-typed and mis-scoped variables, and all kinds of other things. I didn't even need to analyse line-by-line. I don't even program in Python. My brain did it without my intervention.

I'm not sure that's something you can teach that easily, and certainly it's not something possessed by many of the teaching staff, including those in ICT. In 20 years of working in schools, I've met three teachers that I think could write a program. One a Maths teacher, one a former COBOL programmer of old, and one who worked in industrial control before going into teaching. The ICT teachers get most aggrieved if I mention that. But they absolutely cannot program (they might be able to TEACH it, but they can't do it - that's quite common in all subjects of teaching). I mean... it's not unfair - I couldn't teach kids, even the simplest of things. That's why we have the jobs that we have. But people who can code, even in the IT industry as a whole, are few and far between.

Mozilla extends, and ends, Firefox support for Windows XP and Vista

Lee D Silver badge

Re: Here lies Firefox ESR 52.x.x: Sep 2002-Jun 2018

I want to see what a number of the major banks and card services companies are going to do when ESR doesn't work on a machine any more.

Because they all like to use NSAPI, etc. and can't hide behind "just run Internet Explorer" any more.

I'm not sure there are even drivers for most things I use that work with any APIs in place to use things like smartcard readers on modern browsers, which points to major hardware replacements to compatible models or an awful lot of new software to cope.

European Commission refers Ireland to court over failure to collect €13bn in tax from Apple

Lee D Silver badge

Re: Debt Collectors

A court order is a court order. You comply or go to jail. It's quite simple.

E.g. your child is removed from your care. You can appeal against it. Does the child stay with you while the appeal goes on?

E.g. A million pound judgement is made against you for a public liability (i.e. you let someone kill themselves by not having adequate safeguards). The court orders safeguards and to pay the victim's family. Do you think you can string that out for a year and not do either?

E.g. You don't pay your tax bill. A court orders you to pay your tax bill. You dispute that X should be marked as an expense. You STILL have to pay the court, while your appeal is occurring.

Notice the word escrow in the article. i.e. we have the money from Apple, it's there, nobody can take it from us, but we won't budget it / use it / spend it until the appeal is actually finalised. And if we do need to give it back, we can do so quickly.

With a court, you comply. If you win the appeal, you'll get it all back. All you lose is the potential interest on it, but if you're dealing in figures of billions, the interest on that is really chicken feed still even if it sounds a big number when stated alone.

Feet-dragging in a case like that is really just politics, not law. Apple are REQUIRED to pay Ireland, who are REQUIRED to collect it. That it takes more than a day to organise is ridiculous, even if you have to shift it between accounts to make things tally. Ireland are dragging their feet not because lawyers are filing appeals - the escrow covers that and the court has ALREADY ordered Apple to pay - but because they don't want to lose Apple's business.

Personally, I'd be adding on interest for everyday it was overdue.

Hollywood has savaged enough sci-fi classics – let's hope Dick would dig Blade Runner 2049

Lee D Silver badge

Bladerunner isn't that great .. well, it's alright. But it set the aesthetic. In the same way that the book Lord of The Rings collated and set the aesthetic for lots of similar tales and settings. And how things like The Matrix set the aesthetic for many similar movies.

The problem - The Matrix was good because it wasn't trying to be too clever, it just introduced you to a well-thought-out universe with a unique aesthetic, You can drop in the deja-vu, and the "bound by rules" and all the other bits and it's all new, fresh, interesting and makes sense. The rest of The Matrix movies are trash. Literally just action films where he gets more and more ridiculously powerful. Boring. (God, just remember that final fight between Neo and Smith that just goes on forever while they destroy the world around them... you just think "You might as well just give up, because beating each other with lampposts etc. isn't working no matter how many times you do it"). I would hold that the thing that kills the Matrix sequels is, quite sadly, the whole human city thing. Too much time in caves and pipes and not enough inside the Matrix, and the time inside the Matrix is just never-ending fighting with someone who basically doesn't really get hurt.

The same happened with Alien / Aliens (both set their own kinds of aesthetic, I happen to think Aliens is much better in doing this). Everything past that was just "let's throw in something different at random" while pretending it was more of the same. It wasn't necessary, it didn't really work, and now the whole franchise is just trash. Alien 3 figuratively changes the colour of everything (and literally, too - think of Aliens, you think blacks and blues, think of Alien 3 and everything is brown, even the alien), even though the story has gone "unskilled crew vs alien in confined space ending with lone woman, over-equipped military against alien on huge planet, unskilled crew vs alien in confined space).

There are lots of movies that set their own aesthetic, most are not all that good. The early Star Wars movies, moves like The Thing (for zombie/alien like movies), etc. If you are setting the aesthetic for a genre that's not been seen before, it will become yours, and that movie will be used as the standard (I've heard many people see/read cyberpunk stuff and call it "Bladerunner-esque".

But the problem is that new storylines and new aesthetics are few and far between, and aesthetics are easily ruined. Those kinds of opportunities can be squandered. And sequels don't work too well once you've set the aesthetic as you're then competing against a movie with the same name and idea and aesthetic. Alien/Aliens is probably the only one I can think of that's really successful in that regard, almost because it's two different movies: "alien vs lone survivor" and "alien vs elite military unit packing state-of-the-art hardware".

It's not even about original actors, or same scriptwriters, or same directors, etc. Remember Highlander? First was great. Second was trash. The aesthetic change kills it.

Bladerunner set the aesthetic, but then was also overrun with re-interpretations. Sure, everyone probably likes a different one but it hit saturation really quickly. That's cost it dear in the sequel-viability stakes, as has the amount of time that has passed. Again, going back to Aliens, it had the Special Edition - people will prefer one or the other. [Special Edition is better than the original (if you exclude all the namby-pamby Ripley-famliy nonsense)]. It was a way to get "more" out of the original Aliens aesthetic.

But sequels don't cut it. They change too much, alter the aesthetic. The movie that makes a second aesthetic that's as good as the first, without just piggybacking or reinventing everything, is really rare. I foreesee any Bladerunner sequel trapped there - they can't abandon the aesthetic of Bladerunner, but they also can't add much to the story that will introduce new things to it without breaking into something else.

And because it's an undefineable quantity, it's almost impossible to promise or to prove, so any such attempt to follow it with even the smallest claim to being able to replicate (ha!) it is really quite dishonest. When film people say "We're going to move in a different direction", it's because they know they can't compete on an aesthetic level.

I think what Hollywood misses is that often we want more of the same, without having to put in "new" stuff too. We'd give our hind teeth to make the Aliens movie just 10 minutes longer, but we wouldn't want fleets of marines arriving to take out the mega-queen or whatever. I'd love to have had The Matrix play out to a movie twice as long with some of the elements of the later movies, but as soon as you shut the clapperboard for the last time and then try to resurrect it a year later, you lose it.

Aliens was so cool to me, that when the Colonial Marines video game came out, and it had original voice, sound effects, licence, etc. I was over the LV426. Now I could play IN THE MOVIE, as it happened, with the same aesthetic. But, no, it was just dire because it was all reinterpreted, and rushed. But I was more hyped about being able to BE Hicks, exactly as it was, exactly like an 80's movie, with motion trackers that now look out of the Ark, and original gun sounds, etc. than I was about any of the movies that followed.

You have to keep the aesthetic. Nowadays. I imagine any sequel would be destroyed by over-use of fancy special effects, rather than just keeping on par and inventing new twists rather than just "telling us more" about the story.

White House plan to nuke social security numbers is backed by Equifax's ex-top boss

Lee D Silver badge

Re: Confused identification with authentication.

At one point I was issued a Government Gateway ID.

It allows me to file tax returns, get a new passport, change the photo on my driver's license etc.

At the start it was a long random code and a key-pair.

Then it was just an identifier and a strong password.

Even businesses have such an ID to themselves, to file tax and various other information.

If the UK government has this kind of thing worked out for the last 10+ years, then I'm sure the US government can work it out, given our history of government IT projects.

The only thing is that we haven't rolled it out to ABSOLUTELY everyone (it's probably a bit early for that, while we still have pensioners that have never used a computer in their life), but it's there.

MH370 final report: Aussies still don’t know where it crashed or why

Lee D Silver badge

Re: planet is surrounded by spy satellites

Do you know how big the planet is?

And do you know how small the resolution required to see a plane is?

Hint: No, you can't see the Great Wall of China from space.

Sure, if you want to peak at a building in the Middle East, you can move the sat to look at it and take hi-res pictures, etc. But over 25,000km of empty ocean, not a chance that you'll see more than a dot, and that'll be hours stale, so you'll still have no idea where it went or what happened or even what direction is was actually flying in by the time you get the image back.

People forget that, tiny though the planet is, the world is HUGE and there are all kinds of humongous things that just aren't visible unless you're specifically looking for them, and that even when you're looking for them aren't easy to track - because we HAVEN'T turned thousands of miles of empty ocean into 1984-style surveilled territory for one-in-a-million plane flight that we had no idea was going awry until it was far too late anyway.

Seriously, go find a whale on Google Earth. I guarantee you that in the vast trackless ocean mapping there, there's a whale surfacing somewhere, because there are hundreds of thousands of the damn things and they're huge. Don't cheat. Start in the middle of the ocean, max-zoom, and go find one, just by looking and scrolling around.

Now guess what? Google Earth is updated once-in-a-blue-moon for most locations like that, and even if you saw the whale, could you tell where that whale was now? Absolutely not. That's pretty much the best spy-satellite you'll ever get to play with, and it's damn useless for that kind of task.

An MH370 plane has precisely 60.9m wingspan. Let's call that 60m. Let's pretend it's square and obvious, to make the maths easy, so call it a 60m x 60m sheet of metal. That's 3,600 square metres. The search area is 25,000 square kilometres. Which is 2.5 x 10^10 square metres. That means you could fit, in the search area alone, 6,944,444 planes. 7 million planes. You'd have to search 7 million plane-sized images to find it. If each image took 1 second to photograph and transmit, it would take 84 DAYS before the amazing-mega-spy-sat-2000 went back and took the next image at the first spot. If the plane WAS in the search area, and you stabbed at a point at random, you stand more chance of being struck by lightning than hitting the plane. And that's if it's fully visible and not submerged, broken up, confused with anything else (e.g. whales!), etc. AND that it's in the area you're looking at.

Add in the 3D of water and ocean and junk settling on something on the ocean floor and you stand slim chance of finding it even if you have a rough idea where it went down.

Despite what the movies might show you, satellites aren't that good (limited by the same stuff as telescopes on Earth spotting those satellites), nobody sits watching thousands of miles of empty ocean, and a plane going down is a tiny speck in the world.

BBC Telly Tax petition given new Parliament debate date

Lee D Silver badge

Why should you pay for the NHS if you haven't been to the doctor this year?

Why should you pay for subsidies for telecoms connections to poor rural households when you have plenty of money / don't use a phone / live in a city?

Why should you pay for pavement repairs when you drive everywhere?

Why should you pay for street lighting when you carry a torch if you go out at night.

Why should you pay for a police force if you don't commit crimes or get burgled?

Why should you pay for people to monitor riverwater when you don't even fish?

Why should you pay for schools if all your kids are grown up?

...

Taxes are paid, a small amount by all, to pay the large amounts for the few. That's how they work.

To be honest, I'd be quite happy to scrap TV licensing and actually just tax TV purchases. Literally put a 10% import / sales tax on new TV's. Problem solved. No complicated paperwork, no real evasion of it, easy to enforce (just tax the importers/manufacturers like you do for all kinds of things anyway), and then put the funds. Bigger, luxury TV's with all the knobs on would be charged more than tiny little screens, etc. Or even a tax on streaming services, there's no reason you couldn't tax Netflix/Amazon Prime/Google Play/etc. or subscription providers (Virgin, Sky, etc.) and make them increase their prices to reflect that.

The administration, legislation and enforcement of such licensing must cost me more than the BBC ever sees from my paying it. And I've lived without a TV for many years in the past, I didn't miss any of it. It's now literally the "something to watch while eating tea" phase of my life, and anything I do watch is purchased streams/DVDs of old shows and very, very rarely anything new.

When the tax rule is anything more complicated than "some percentage of an amount we collect anyway", without lots of disclaimers, exceptiosn and differences, the administrative costs just don't make it worthwhile. "10% on every new TV sold" is easy to implement, collect, enforce and prove evasion of. But they should have done it a year pre-digital, and THEN they could have raked in enough to keep the BBC going for 10 years on that.

Home Sec Amber Rudd: Yeah, I don't understand encryption. So what?

Lee D Silver badge

Gosh, maybe we shouldn't expect someone trying to draft laws about something to actually understand what they're drafting laws about and not make ridiculous claims?

Whether you're a techy or not, if you're drafting laws, you CALL IN EXPERTS. That's what you do. You don't just make up things that sound good. And if those experts are telling you that your plans are rubbish, untenable, have knock-on effects, etc. then maybe you should listen to them rather than put fingers in ears and go "La, la, la, can't hear you".

This is what annoys me most about modern so-called democracy. People without a single clue are just as likely to end up in a job as someone who actually knows what they're doing. I never get why ministers of various things have ZERO BACKGROUND in those industries/areas.

"We have consulted with experts, and they advise us that this isn't the best way to go about things, so we will look for other solutions". What the hell is negative about that sentence?

There's a way to dodge Fasthosts' up-to-160% domain renewal hike but you're not gonna like it

Lee D Silver badge

Re: Price gouging.

Defending your trademark does not mean you buy up everything with your trademark on it.

You literally just sue whoever put up that domain with the unauthorised usage of your trademark, and force ICANN/whoever to suspend the domain / remove it when that court case starts / finishes.

It's like saying "to defend the trademark Nike, we need to buy up anything that has the word Nike on it". It's just a nice way to go bankrupt fast.

That said, where there is fair usage (e.g. "nikesucks.com") then they'd rather pay the $50 to own it themselves than let someone else humiliate them in court by winning rights to such a name (which they often do). But then, surely, that person would just buy "nikeREALLYsucks.com" if they couldn't get the first one anyway?

It's all pointless and achieves nothing but some people have domain-name fever and throw their money at naming authorities, while everyone else just thinks up a name that nobody else is using or makes do.

I remember when novatech.com used to be a military equipment supplier. The number of times I landed on there by mistake when trying to get to novatech.co.uk was unbelievable. And then Google came along and it's quicker to Google "novatech". It seems that, in the intervening years, they obviously paid someone money for the .com too, though.

Lee D Silver badge

Personally, I use Tagadab:

.uk domains at £10.00 + VAT for 2 years

.com for £7.99 + VAT for 1 year

There was a time I used to use a much better niche company (justhename) but they got bought out and ended up being under the PlusNet brand when BT took over. Needless to say, they're just completely gone now. But they had cheap, simple, easy domain management and didn't try to faff with anything else, and they had one really cool feature they called "URL Masking" (which was actually an Apache reverse proxy set up at their end, so that you could forward the domain to, say, cheappwebhosting.com/~username/folderpath/, and it would retrieve all requested files from there and present them as youdomain.com/filename - it was a fabulous way to make your domain very portable (store the same files anyway, change the path), without anyone knowing where it was actually hosted).

If anyone knows a company with a feature like that, give me a shout, or I'm going to have to read up on the Apache docs and do it myself.

Lee D Silver badge

Re: Price gouging.

Simple. Non-standard domain names TLDs are the vanity plates of the Internet world.

You are paying for "ownership" of an arbitrary string. Certain strings are "worth more" because the people in charge of writing the strings down say so.

It's literally that simple.

Lee D Silver badge

Or... just take your domains elsewhere.

Man with 74 convictions refused permission to fling sueball at Google

Lee D Silver badge

Streisand Effect.

UK lotto players quids in: Website knocked offline by DDoS attack

Lee D Silver badge

Re: It would be interesting to know

The problem with DDoS is that you can only combat it from one step higher.

If you're DDoS'd, you need to implement a filter on the data coming in BEFORE it comes down the line. And with Distributed, those filters are more complex than you might think (i.e. millions of random web requests from random IPs would do it, but how do you distinguish real users?).

Pretty much, that's your first port-of-call, and the end of your worrying. The upstream then has to work out where it's coming from and try to filter from source, if that's possible, or just swallow the traffic for you. It matters not what YOU have in-house, that's always capable of being overwhelmed. It's what your upstream partners have, as they are the ones collating packets from millions of smaller connections into one big bundle for you, and they have to fix it there, not just blindly send it to you.

No amount of technology can really solve that issue, while it's still possible to generate a genuine web request from a genuine user's compromised PC, as that genuine user, it's impossible to distinguish no matter you put in the way of cookies, authentication, behaviour-tracking, etc.

It's cheap to tell 1,000,000 computers that you don't own, to all access a website at the same time. The people who own the computers are paying for the resources. It's not cheap to run a website capable of dealing with 1,000,000 extra visitors without noticing.

As time goes on, the problem isn't going to change much except in scope. We can only hope that backhaul transit increases in sizes proportional to the average home broadband user. While it takes, what? 10-30 compromised home fibre connections to flood a 1Gbit leased line now, if that scale doesn't increase at the same rate at both ends then it becomes even easier to swamp a connection.

(it's wishful thinking that larger connections would grow at a faster rate than home ones, however).

What happens when every user has uncontended gigabit? You better hope that every ISP becomes good at filtering, or that every backhaul and datacenter start offering 100Gbit as the basic business leased line / the interface to the cheapest server they rent out.

To be honest, servers in datacentres would be my worry. It's pretty standard to get only 100Mbit or 1Gbit networking. Most servers running in datacentres, therefore, could be taken down by a single fibre home-user with a grudge quite quickly if there was no mitigation. And paying to have every single blade / VM / whatever to have 100Gbit connectivity and necessary switching/upstream for that sounds expensive

Lee D Silver badge

I'm fairly sure that if there's one organisation with the money to buy enough bandwidth and filtering to handle a DDoS, then it's going to be Camelot Group. Especially as it would just be filed under "operational expenses".

Apple Mac fans told: Something smells EFI in your firmware

Lee D Silver badge

A cloud-managed network (e.g. Cisco Meraki) would be able to provide anonymised version information on all kinds of things without having to actually interfere with a customer's network.

It's a real FAQ to ex-EDS staffers: You'll do what with our pensions, DXC?

Lee D Silver badge

Final salary pensions are an unsustainable joke.

You spend your life from age 20 getting to a figure, slowly raising and raising from minimum-wage (or better) to the highest you're ever likely to earn. Then you retire at 65. That's 45 years of salary earned. And at that point you expect that probably-maximum salary to continue for free until you're... what... 90?

That's 25 years of full-salary paid back to you.

Then you need to pug away AT LEAST 56% of your earnings from 20-65 to sustain you in that amount from 65-90. And probably a whole lot more, if you ever earned less than the final salary at any point.

Even if you assume you'll only get to 75, that's 22%.

22% of EVERYTHING YOU EVER EARNED EVER (not even counting tax, interest rate rises, depreciation, etc.). Likely 30-40% by the time you take that into account, even for someone who is expected to die at 75. By the time you work out the odds, profit for the insurance company, sustaining those who live into their 100's on salaries much higher than yours but paid for out of the same pot... 40% seems positively generous.

40% of every you ever earned, from the time you started work / left uni. If you reach even the bare bottom of life expectancy. Hint: Those likely to be offering final salary pensions probably have good jobs, and therefore will have lived better and therefore for longer.

It's not sustainable. And it's being funded by screwing over the generation below (by the companies going bust, the pension offers being made worse, etc.).

There's a reason that state pensions are a pittance, aren't final-salary, and yet represent huge percentages of the total money paid out by government - more than healthcare or education and FOUR TIMES that of defence:

https://www.ukpublicspending.co.uk/chart_central.php?title=UK_government_expenditure&meta=government_expenditure

Final salary pensions are entirely unsustainable. And yet we offer them to VAST TRACTS of industry and civil servants.

iOS apps can read metadata revealing users' location histories

Lee D Silver badge

Feature-creep caused by overly-open permissions on basic apps.

No, the camera app doesn't need GPS or location permissions. If a user chooses to add it, they will add it to every photo, by default, forever. And there's no easy way to remove it from all those photos, or strip it when it gets uploaded to other apps / website that don't also have location permissions.

Sure, it's as much "the camera app put the location into the image file" as it is "apps given photo access can read the location", but the problem is still creeping into ever-more permissions for the most basic of apps.

There is no substitute for fine-grained access control permissions.

NatWest customer services: We're aware of security glitch

Lee D Silver badge

I abandoned NatWest in the 1990's when they were still insisting you needed to use IE with ActiveX controls to access online banking as other browsers "weren't secure".

To be honest, working in IT back then, I was hardly the front-runner of new technology in everyday life anyway, but I just moved to a bank that had a vague understanding of what SSL actually did.

Power meltdown 'fries' SourceForge, knocks site's servers titsup

Lee D Silver badge

"their redundancy failed us..."

Er... no... your COMPLETE LACK OF REDUNDANCY failed you.