The Register Home Page

* Posts by Lee D

4945 publicly visible posts • joined 14 Feb 2013

Ker-ching! NotPetya hackers cash out, demand 100 BTC for master decrypt key

Lee D Silver badge

Re: Can't anything be done??

Bitcoins are just a numbered account.

And most bitcoin accepters won't know to block that particular account.

And the holder of that account can generate effectively infinitely many new accounts, break the funds up, redistribute them, and pay from those other accounts in seconds. Although technically traceable to an extent, they would have already received their goods/services by the time anyone can correlate them properly, and the more they break them up, the harder it becomes.

Bitcoins can literally be broken into billions of pieces. And who knows whether someone who receives or acts as an intermediary for any of those pieces are an innocent party (e.g. been paid in Bitcoin and know nothing about the origin of the funds), related to the scam, or the scammer themselves? It could be the scammers setting up a billion laundering accounts, but each one is indistinguishable from an account that someone else has had for years but never used and who happened to get a donation on their website (e.g. I have a button on my website to donate Bitcoin to me in such a fashion, people use it to donate to me for running a gameserver).

And though Bitcoin is "traceable", it's far from easy, and only gives you and enpdoint (i.e. someone paid the ransom into the ransom account, which was ultimately spent in these several billions different pieces at any number of end-points which are places like shops, service accounts, Internet hosts, pastebin, etc.

Even ordinary stores are starting to take Bitcoin now, and vending machines, and places like the Humble Bundles. Though you can say the ultimate destination, and know the path it took, why it took that path and whether that was money laundering or innocent transactions in the interim is impossible to determine.

These guys spent it all without breaking it up much. But that still doesn't help. Sure, pastebin would probably know the associated account and may terminate now that it's in the news, but they aren't obliged to check EVERY origin of EVERY payment they ever receive for EVERY type of currency.

Brit prosecutors ask IT suppliers to fight over £3 USB cable tender

Lee D Silver badge

I work in schools.

I am SO MUCH HAPPIER in independent (private) schools, because they don't have this kind of mass procurement nonsense. State schools used to insist on three identical quotes, which obviously has any number of ways to fudge at extreme lengths of effort to attempt to do, resulting in a lot of wasted time to end up with the answer I would have given anyway.

And not everything is about cost... in fact most things AREN'T about cost. I reject companies or change to their rivals more often because of poor service or unreliability, not cost. Service, reliability, and assuredness of future business is reliance on a certain cost.

Nowadays, I find a link on Amazon, send it to a bursar, if it's not stupendously expensive, it gets clicked and ordered and arrives the next day. Hundreds of thousands of pounds of business every year happens like that on Amazon only, let alone the myriad other websites where you find a product that no-one else sells, etc.

But in terms of procurement - long-term suppliers, that the business relies on, cost is secondary to "are you going to be around next year and give us the same service".

Sorry, but if it's under £100, it's basically automatic approval so long as there's two names on the sheet (so you don't just walk off with it). If it's under £1000, sure, look around and try to make sure it's comparable pricing, but order from the place that handles your business the best. If it's larger than that, you're into requests for quotes and sign-offs but it doesn't need to be some huge big deal involving a dozen people.

This is the problem with the NHS too - they are locked into procurement processes that are ridiculous, AA batteries costing £10 each because of procurement rules, that turn up as single Duracell batteries you could buy for 50p each on your lunch hour. But, of course, you're not allowed to do that as that would not be recompensed on expenses because it cuts out their minister-approved middle-man.

I ordered something like 200 iPads on Amazon once. It was barely questioned, on unit price, because it was just the no-brainer for a product that's never discounted and identical from everywhere you buy it. It arrived with 24 hours, returns were piss-easy, and we never had a comeback.

They say Amazon is killing the high street? It's because the service is second-to-none and they sell everything you might want. Suppliers can't compete on either factor, and I've gone through 3-4 major equipment suppliers in terms of network procurement and ongoing support because they all turn useless in a year. But for just *buying* stuff? Go to the most sensible place.

My bursar actually tells me off for wasting his time if it's under £50 and obviously required.

Bonkers call to boycott Raspberry Pi Foundation over 'gay agenda'

Lee D Silver badge

"They want to tell your children it is 'ok to be gay' even if you as a parent work diligently and carefully to put your child on a hetrosexual path."

So... you're saying you want to tell my children that it's NOT okay to be gay?

Way to win over the audience. You can discount my support for such stupid nonsense.

If they were INSTRUCTING your kids to be gay (they're not, the operative word here is 'support' - I 'support' all manner of groups and causes, none of which demand I live their certain lifestyle), then maybe you'd have a case. But they're not.

P.S. I suggest you look into what your school teaches your child. Because I guarantee they WOULD NOT tolerate any speaker, guest, staff or other child telling someone that it wasn't okay to be gay.

GnuPG crypto library cracked, look for patches

Lee D Silver badge

Re: It's important that it's been fixed..

In which case we're all dead, because HTML is just the same - any website is potentially complete compromise by that reasoning.

However, in practical terms, WebAssembly is low down on the list of possible avenues, as is modern Javascript (however it's scripting of ActiveX etc. was always it's main problem, not the Javascript itself). Just above HTML, and probably just below Javascript.

And it's REALLY difficult to execute any kind of local attack utilitising local C-written shared libraries that are nothing to do with the browser by any of those. Honestly, those are not the issues to worry about.

You'd be measurably safer if all your application writers recompiled their apps to WebAssembly and you only accessed them via a browser. However, you'd also lose a lot of functionality in the process - e.g. opening local files, network communication etc. - because of the browser security model that would be imposed on them by doing so.

Lee D Silver badge

Re: It's important that it's been fixed..

Why would WebAssembly be any different to anything else? Do you even understand what it is and does?

WebAssembly is nothing more than a cut-down interpreted VM, like Java used for decades, in a very limited scope, executing only with the privileges given to a normal HTML page. Just because it has the word "Assembly" in there, don't fool yourself into thinking that it's actually executing anything. It's still just a compressed version of a very limited instruction set subject to the browser security controls (which are a lot stricter now than they were in the days of plugins - Java plugins were basically given full run of the machine, WebAssembly can't even open a network socket as you would expect - it gets encapsulated as a WebSocket that will only communicate on web ports).

You need to run software. In the absence of direct execution, that means running an interpreted restricted-instruction-set language. Whether or not you want to run software from a particular website? Well, that's a browser control. But WebAssembly has NOTHING to do with executing code on your processor, certainly not one that interacts in any way with local shared libraries, and certainly not one that can just execute routines and pass stuff off to your OS.

Students smash competitive clustering LINPACK world record

Lee D Silver badge

Are you really just students who "guess" that the bus is overloaded?

And am I reading this right, in that it's just a competition to slap a machine together without such knowledge and put as much stuff in as you can until you find the sweet spot?

I find nothing technically interesting in either.

Dead serious: How to haunt people after you've gone... using your smartphone

Lee D Silver badge

Re: You surely must have forgotten

"The wonks who call you to sell you a better tech solution than you already have, but don't know either what you have or what they are selling."

Almost as bad as those SIP trunk providers who call you from a line that sounds like it's being fed over the deep space network in real-time, and someone is multiplexing it over "morse code in silence".

They always try and claim that it's "at my end", but it's only EVER SIP trunk providers that I have the issue with, whether they come in over my otherwise perfectly-working analogue, ISDN or SIP lines.

Not that scary or that hard: Two decades of VLANS

Lee D Silver badge

Re: First two things...?

I find, if taking over a particularly bad place, that the backups are rarely backing up the CONFIGURATION, i.e. the server, server state, application configuration, etc, properly. Or if they are, it's been cherry-picked to the bare minimum and then never updated as new things are added.

One of my prime reasons for converting to VM is that you can then backup the entire VM image + snapshots beforehand, and as you make changes, and ensure that you have a way to get back to where you started and a FULL backup (and hence even keep the original server and/or the original server disk image to do a full revert if there's a problem, even back to the original hardware).

Part of that, yes, I agree, would be the backup of storage too.

Lee D Silver badge

I find it unbelievable that people setting up switches don't know what a VLAN is, or don't use them. I've dealt with a number of IT managers and IT contractors who literally have no idea what a VLAN even is.

I've heard all sorts of rubbish reasoning, but never a reason to NOT deploy VLAN's on almost every network by default, the second you take it over.

And if you're worried about adding them to a "legacy" network, just do it. Put anything new on the "new" VLAN's, and access to them, and leave everything on the "default / untagged" VLAN until you can start moving it over.

With server VM's (also a no-brainer that should be your FIRST job if you're taking over a non-virtualised network), it's literally just adding another interface on the necessary VLANs and off you go.

You should be isolated as much as possible.

- Make the default VLAN as boring and empty as possible.

- Separate off wireless, guest wireless, access control, CCTV, telephony (probably job #1!), printers, inter-server traffic, etc. into their own VLAN. Put the necessary VLAN interfaces on the VM's that need it (e.g. telephony integration servers).

Then you can separate and monitor traffic (e.g. CCTV VLAN using much more traffic than telephony VLAN, etc. rather than have to do protocol analysis to find that out), remove any opportunity for browsing and bypassing stuff, and apply completely separate settings to entire VLANs (e.g. QoS on the entire telephony VLAN, rather than on individual endpoints, or DSCP tagging, or port-detection or whatever).

Personally, I think even printers should be on their own VLAN (hint; They don't even need VLAN support for you to do this! Just keep your wiring sensible so that they don't piggyback/share with other devices). That way nobody can "browse" for printers to exploit / prank, and have to go through - say - a Papercut server that's the only "computer" on the printer VLAN, and has a public web interface on the client VLAN. You're also separating out thee broadcast traffic to only those devices that actually need to be listening in on it (not everything does multicast properly) - no more dozens of printers constantly advertising their wares to every port on your network.

And though it might allow you to run two identical IP ranges over two different VLANs on the same cable, I think that's stupid. Just renumber. Internal ranges are plentiful. In fact, I tend to number ranges to mirror the VLAN number - e.g. 192.168.10.x - 192.168.19.x to be on VLAN 1, 192.168.20.x - 192.168.29.x to be on VLAN 2, etc.). Because then you can spot your mistakes so much more easily and someone "just browsing" has much more work to do.

VLANs are a no-brainer. I work for schools and for years, stupid educational companies ingrained the concept of separating wiring for "admin" and "curriculum" networks. When all the kit could have just supported VLANs (and proper damn permissioning / authentication would solve the problem anyway). I still walk into schools wired that way, where a bursar cannot log in in a meeting room, etc. because he's "on a different network" that's physically separated so even domain trusts aren't possible.

VLAN. VM. First two jobs to solve in every workplace that doesn't already have them. Anything else is just madness.

Virgin Media cuts 250 jobs amid £3bn Project Lightning cockup fallout

Lee D Silver badge

Re: Oh Good grief!

Buy yourself a decent router, which Ethernet, VDSL, ADSL, 4G, etc..

Put the VM Ethernet cable from the hub (in modem mode) in one port.

Put an RJ11 ADSL/VDSL connection in the other.

Put a 4G stick / SIM in for emergencies.

Configure the routing/failover options on it.

Pay for two "less speedy" connections without all the associated gumph, so that when one falls over you don't even notice except for the email from the router saying that it's fallen back to something else. If you buy a decent enough router, it'll even load-balance over them without you knowing the difference (I set this up on an ancient PC once with Linux, over two really-flaky ADSL lines, and every webpage you accessed or port you opened could have gone over either connection and you'd never know any difference).

Literally, a couple-of-hundred-quid investment that will last for years and solve all the problems for you by doing what people in IT do (always have a backup, redundant systems, etc.). And there are many advantages ("Oh well, it's your connection!", really? Because I have three!), you can always move it anywhere, to any ISP, at any moment. Hell, I can even run the whole home network run off my phone's 4G offered over wireless as a "WAN" connection if I like.

If you have a number of fluctuating qualities of service, take steps to reduce your dependency on any one of them and cover your bases. 200Mbps costs what?

I'd rather have two independent 50Mbps services than even a 200Mbps SPOF.

Rackspace goes TITSUP in global outage outrage

Lee D Silver badge

Ah, cloud provision.

And DRM / licensing.

Who'd have thunk they could be problematic in a large enterprise?

What gets me - why the hell is the ticket system behind the same thing, making it inaccessible if it screws up?

The bloke behind Star Fox is building a blockchain based casino. No, really

Lee D Silver badge

Re: But...

Poker is very different to other games, being a game requiring perfect play in order to achieve the stated odds.

Roulette, craps, fruit machines, etc. do not.

If you're playing poker online, you need to know that you're playing perfectly in order to avoid bots, etc., in which case there are much easier ways of winning a poker game (e.g. play against random people in real life).

In almost all other games, there's no point in playing as you have no contorl over the situation and you may as well just be putting "£5 at 0.3 probability" - it's essentially the same and the "game" has no effect on the outcome. With poker, it's actually worse. You play perfectly and you might get those odds in the long-run. You don't, and your odds are indeterminably lower.

Lee D Silver badge

Re: http://provablyfair.org/

Was going to say exactly the same.

Hot news! Combustible Galaxy Note 7 to return as 'Galaxy Note FE'

Lee D Silver badge

Fire Extinguisher.

Fire Extinguisher

Linus Torvalds slams 'pure garbage' from 'clowns' at Grsecurity

Lee D Silver badge

Re: Ego Overload

The Brad guy manages a set of security patches.

Patches that he has questionably licensed (it's GOT to be GPLv2 because they are kernel patches, but now you only get them if you are part of his little clan, and if you distribute them, he threatens to never supply you another patch again).

Patches that he has zero interest in submitting through the proper channels. He regularly claims to have done so but it's mainly just dumps of the entire thing with no breaking down to individual patches. Not even an idiot is going to apply megabytes of patches to the Linux kernel overnight.

Patches that are based on the Linux kernel which is a damn sight harder to manage than just his security patches, but he won't co-operate with anyone, and - as with the licensing - he somehow thinks he should be treated better than anyone else.

I've had a couple of run-ins with him on other forums, nothing to do with the code (I'm happy to assume his stuff works and is worthwhile, technically he's quite clever) but about the attitude. He just expects everyone else to do the work to integrate, because his code is so fabulous, while at the same time refusing to make any effort that way himself and questionably mis-licensing and threatening people. Then he complains about how Linux doesn't have all this stuff.

Instead, BECAUSE of his attitude, the kernel maintainers are reinventing the wheel without bothering to look at his code in case it somehow taints them and causes trouble. You can just imagine the attitude of the above guy if they start just pulling in his code anyway, or copying it wholesale. This completely hinders any integration of his patches. NO ONE will volunteer to pull his stuff across piecemeal (as EVERY OTHER major patch to Linux was handled) because of this attitude. If you speak to the guy, you'll see why.

It seems to me that we have another "BitKeeper" debacle, that's going to end with his patches becoming obsolete, while someone else does the hard work again in another way to do what he could just do overnight.

To be honest, I can even understand his point of view. He knows his stuff. But equally, I can quite understand why no-one will deal with him. And should anyone go to the effort of doing this integration, his patch-set is dead overnight. Nobody will ever remember him. Perhaps that's why he actively hinders efforts.

I've never seen another major kernel patch set where NOBODY will step up to help them integrate any more (it's been tried several times), and where people would rather re-invent the wheel rather than deal with the personality.

TBH: I'm with Linus here.

It's 2017, and UPnP is helping black-hats run banking malware

Lee D Silver badge

1) Rubbish.

2) One XBox will get Open NAT, the other will get Strict NAT, and that only if you have them both working simultaneously.

3) Because it *wants* to forward the following to your console:

Port 88 (UDP)

Port 3074 (UDP & TCP)

Port 53 (UDP & TCP)

Port 80 (TCP)

Port 500 (UDP)

Port 3544 (UDP)

Port 4500 (UDP)

You are opening up your DNS, HTTP ports and numerous others (including targets ripe for brute-forcing and automated HTTP scraping / metasploiting) to a fecking console.

4) Damn niche problem.

Lee D Silver badge

SWITCH IT OFF.

UPnP = automatic, unauthenticated port-forwarding of any external port to any internal machine port.

If you don't know this already, and you work in IT, you've not looked into it at all.

If you do know it, and left it enabled, more fool you.

Literally, any user - even in internal VLANs in some cases - can send a UPnP request to port-forward your external port number 7483 (or whatever) to internal client SERVER1 port 139. Game over. Even if you disable SMB or have internal firewalls, there'll be SOMETHING you don't want exposed that they can expose (and even a port 139 that refused traffic could be used for damage as WannaCry showed!).

Authentication modules were never really used for UPnP and finding compliant software/router combinations for such is rare. Add to that that ANY PROGRAM running as ANY USER on ANY LOCAL MACHINE can request the router to forward any arbitrary external port to any arbitrary internal port.

If that doesn't scream "stupid design", I don't know what does.

Additionally, to counter the usual argument, there are ZERO modern services that do not operate when you disable UPnP. Same as anything - if you're running a server you should be the one opening the port, not having it happen automagically without your knowledge. If you're not, then everything works just fine without port-forwarding, UPnP or anything else.

1000 Steam games, Skype, Torrents, Bitcoin, everything I have ever installed works fine. At absolute worst if you're HOSTING a server (not just connecting to matchmaking servers which have open ports for just this reason) you put in a port-forward entry.

Anyone who has not had UPnP disabled from day one on their network gateways deserves a slap. Even a cheapy Draytek will let you provide "Internet Connection Status" over UPnP while denying the "magic port-forward" stuff, but there's no reason for UPnP at all in that case anyway.

Microsoft's new Surface laptop defeats teardown – with glue

Lee D Silver badge

Quite.

I'd rather have two £500 laptops and stick one on a shelf. At least then you stand a chance at longevity, spare parts usage, etc.

The non-replaceable items get no love from me whatsoever. And, to be honest, I hate having to take things apart. I lose at least one screw every time I do so. But at least I have a choice between "£10 keyboard replacement done by myself even if I have to take the whole thing apart" and £1000 replacement.

Lee D Silver badge

Re: What happened to screwing?

Do you not know how to tease things open gently? Carefully probing and fondling with little tiny skillful movements to elicit the opening piecemeal, savouring the anticipation?

All so eager to get at what's inside, you don't appreciate the packaging.

Brit uni blabs students' confidential information to 298 undergrads

Lee D Silver badge

- Poor data storage (spreadsheet for potentially medical information? No password? No encryption? Just one big spreadsheet for everyone? Hope it doesn't have macros neither!)

- Poor data management (people just picking the document up and attaching to emails, no control or confirmation of outgoing attachment, no data control intercepts to spot multiple personal information leaving the site, no limit control on emails going out to 290+ students with an attachment?)

- Poor permissions management (can just email out to groups of students with attachments? No having to post to internal services and link instead: "the document is available under your online account", etc.? )

And all for what? A spreadsheet of their reasons for failling exams. Why is that even a spreadsheet? Why is it not contained in the MIS? Why is it not in the privileged area of the MIS? What service requires you to generate a list of every students extenuating circumstances in one place in plain-text, and why would you keep that around past submission over a secure channel?

I'm guessing - based on working in schools for decades - that it's someone's pet project which they use and store separately because they can't work the MIS system, which they then email out to other people rather than them have to work out how to use the MIS. And they mis-hit and sent it to the group of affected students rather than the person they meant to inform of those students.

There's really no excuse, and it's sloppy data management in human terms, which is indicative of much larger problems in terms of handling data. The fact that someone could generate such a list from, presumably, confidential form returns is just damning. Either those returns should be electronic and straight into the database and thus this was a specific "pull out everyone with this field because I want to read them all in one go" action, or they were collating them from some other service or typing-in which shouldn't be done with confidential records.

I would expect fines on the order of 100's of thousands of pounds in such an instance. They are issued on that scale to schools and hospitals all the time, even if there's no proof that anyone else actually read them (e.g. missing encrypted CD's that you can't prove were encrypted in some cases).

And that's a whole lot more expensive than teaching Joan in the office not to do that, or replacing her entirely (now an option) and getting an MIS that handles this stuff in a way that mass-queries are held securely rather than can be Excelled out of the organisation.

Samsung releases 49-inch desktop monitor with 32:9 aspect ratio

Lee D Silver badge

Re: code word

Do what you like as a hobby.

But wasting money on snake-oil products vaguely related to said hobby? That's the silly part.

I'm a gamer. I operate gaming servers too. I don't have any of that "gaming" junk (Amazon today has a "gaming" sale, consisting of little routers with about 12 antennae on them and light-up keyboards - and yet my ping is lower than anyone else's because I just have proper QoS on the connection, local network, etc.). My mouse is a TeckNet cheapy. But I'll still kick your backside at Counterstrike with it, though.

I'm an astronomer. I have telescopes, mounts, camera bodies, image-stacking software, None of it cost very much at all, and all of it produces results that even a guy in the street would go "Oh, wow, yeah, that makes a big difference". You could spend £1000 on a filter. Or £10k on a massive Schmidt-Cassegrain. I don't. Because other factors - not least the expertise to use it, clear skies to make it worthwhile, or limited value of the difference I'd get from using it - mean it's not worth it.

There's a case of choosing the right tool, and it improving the output of someone skilled in the use of it. But being skilled in the use of it is more important no matter what tool.

Buying snake-oil products like Killer Ethernet cards, or super-duper-carbon-fibre fishing rods, or some professional set of £2k golf clubs when your handicap is still in the double-digits, or some special spark plug doesn't magically make things better than you could have got anyway, and rarely provides any kind of return-on-investment, especially for a hobbyist.

In fact, the more you avoid that snake-oil junk, the more you can get out of your hobby, the more hobbies you can have, and the more drinks you can have down the pub with your mates afterwards. It's the people who bore you to tears about some thousand-pound snooker cue and its manufacturing process when they can barely hit the ball, that then try to justify it, and never have any money left for anything else that I would feel sorry for.

Lee D Silver badge

Re: code word

No different to audiophiles, motor enthusiasts, or any other sector where people consider themselves to have an expertise that few others have.

They all buy expensive toys that they think professionals use to make themselves seem "more" professional, whether or not they can even use them effectively.

I look at my Facebook and I see people with fishing gear costing thousands, which they then use in reservoirs where there are no fish. I see car nuts buying bits for their cars that are totally worthless and unnecessary and the cost of which would cover buying a better car. It's the same for all sorts.

My technician was telling me only yesterday that he was in a store and a guy was buying a "gold-plated optical audio cable". I can't even fathom how that works. But the guy paid a fortune for it because "it'll make it sound better".

Everything from the guy with the large 4K TV, to the bloke with go-faster stripes and under-car lighting, to the gamer with the 48-button, 10Mdpi mouse, they're all the same.

And they all whine like hell with excuses when your run-of-the-mill, bog-standard, but you spent a tiny bit more than the minimum and actually researched, purchase beats their super-duper kit into a cocked hat. They all then pull out the "Yeah, but that's just electronic timing / digital audio / carbon fibre / whatever, it's not as good as my ancient mechanics / dust-strewn LP's / stick of wood even if you think it is".

Ofcom fines Three £1.9m over vulnerability in emergency call handling

Lee D Silver badge

"However, this vulnerability has not had any impact on our customers and only relates to a potential point of failure in Three's network."

Translation: We only NEARLY killed people.

Fighter pilot shot down laptops with a flick of his copper-plated wrist

Lee D Silver badge

^ someone with experience.

Lee D Silver badge

School office.

Noticed the office staff layering plain paper and cheque paper alternately. For hundreds of cheques.

Queried why: "It's always been like that".

The printer always churned out two copies of the cheques, so you had to sacrifice a bit of plain paper to avoid printing out double-cheques.

Borough support had "looked at it dozens of times" over the years. This person had been in the same school for 20+ years, so she could tell you names, dates and what they did.

They'd reinstalled the software, reinstalled the machine, changed all the server settings, deployed print group policies, tweaked every option, and after years of callbacks given up and told the staff to put blank paper every second sheet.

It was a HP Laserjet, the ones with the old "cold blue" LCD displays. They only ever used it for cheques because it was the only printer on site that didn't jam when it printed them (cheque + sticky seal + plastic address window in one A4 sheet).

I tapped a few buttons.

Found the option that said "Copies; 2". Changed it to "Copies: 1"

Worked perfectly for years after that. I think she would have kissed me if she could. Years of "paper, cheque, paper, cheque, paper, cheque" for thousands of cheques before she printed every time...

(Yes, Borough support was in bed with RM so the system/support was basically entirely RM and HP. The same school sent back three machines five times because they "never worked". The problem? CMOS Checksum Error. I got the job there by sending a member of staff down to the watch store for 3 x CR2032 batteries. They worked fine for years after that)

When we said don't link to the article, Google, we meant DON'T LINK TO THE ARTICLE!

Lee D Silver badge

"For the sake of ensuring compliance, we've removed every mention of your company from the entire search database, including your website, articles, links, adverts, reviews, map location, stock ticker, etc."

Sorry to burst your bubble, but Microsoft's 'Ms Pac-Man beating AI' is more Automatic Idiot

Lee D Silver badge

Re: Problem?

"work out the rules of chess and the relative values of the pieces by itself"

Rules, maybe. But they can learn that by making random moves and some control somewhere says "Invalid move, you lose". That's INFINITELY better than "you can only make moves from the restricted subset we offer you that you never have to consider" in terms of learning.

And, similarly, value is a heuristic. The value of a piece is nonsense compared to whether you win. You can sacrifice every piece on the board so long as you end up checkmating. That "value" could be learned or hard-coded. Learned value - when it decides itself "Actually, my queen is probably worth more than that" rather than adds up some metric - is what you're after if you're claiming "AI" and "machine learning".

It's about what you test on. Are you testing "can this machine learn to play the game by itself" or are you testing "Can this machine find what we would call an optimal play in this heavily-prescribed world". They are claiming the former, but actually it's the latter.

You have to consider this: If your machine is "learning" then you could throw it at Ms Pac Man and train it. You would then be able to move THE EXACT SAME PROGRAM to, say Pac Man 2000, not tell it what the difference is, and train itself towards optimal play for that WITHOUT TWEAKING.

This program couldn't. It's been told what the value is and what to do, in limited means but it's been instructed. That's not "learning", that's some kind of "organic growth programming from seed". And the whole point of "learning" is not to make a Ms Pac Man player. Any idiot can do that. It's to make a machine that learns. If it only "learns" Ms Pac Man when it is hand-led, then it will forever need to be hand-led on every task it does.

To be machine learning, it would have to arrive at that itself, naturally. Even if you start from zero knowledge, or from knowledge of ENTIRELY THE WRONG GAME. It should learn enough that it realises that.

Otherwise, all you've made is a very expensive computer player, and nobody is going to care about your research, licensing your patents, etc.. Although we might call them "AI" players, they aren't. What people are after, the value we seek, the thing that makes money, the thing we don't have, the useful feature... is learning.

And learning shouldn't need to be hand-held. Stick a new-born animal in a room and it will learn when/how it gets fed without any extra tuition. If you make a change to that, it will adapt to it. The "seed" is sown before it ever knew what task it was up against. And it learns and adapts to the tasks given from then on.

Lee D Silver badge

Re: It's not very good AI

Humans read rules, interpret them and voluntarily stick to them.

Machines operate in an environment where the rules prevent them ever doing anything else, so it literally bounds their possible actions.

Morpheus knew this: You will always be faster... because they live in a world built on rules.

Lee D Silver badge

Virtually nothing that says AI or "learning" actually is.

It's all heuristics, instructions from programmers on "how to learn", in effect. And not at some basic coding level, but quite literally specified explicitly for the task at hand.

AI, to me, is still interpreted in the same way as the old gaming adverts: "destructible environments" (so long as you don't go out of bounds, go too deep, shoot the critical plot structures, or actually expect it to turn to rubble), "realistic physics" (which is why you can make the enemy bounce a thousand metres in the air by getting him stuck on a door), "open-world" (so long as you don't try to go the opposite direction to your objective or mind being herded back in if you stray too far, and by the way, for mission 2 you have to go see John or you'll never get a mission 3 until you do).

It's all rule-based and targetted. Google's AlphaGo strayed into something different, which is why it's newsworthy and pretty astounding. But you have to understand the game and the rules of the game to make those sub-agents do what you want in order to come to a decent play. And I guarantee you that the "master agent" isn't culling off useless sub-agents and creating unique ones of its own to try to fathom out the game.

It's all hard-coded rules, left to run for a long time with an aim in mind. That's not AI or "learning", no matter how long you leave it running. Unfortunately, any sufficiently-advanced technology is indistinguishable from magic, so people do think that Siri is actually understanding them rather than some speech recognition that hasn't improved in decades (per cpu cycle), shoved into a search engine which returns colloquially-worded results.

Labour says it will vote against DUP's proposed TV Licence reforms

Lee D Silver badge

Re: Give it to us

No.

Taxes are just as often a penalty on an action to discourage use of it.

- Buying luxuries.

- Running a car that slowly damages roads and air quality, charged on a sliding scale of damage caused.

- Offshoring assets / jobs (tax on them so you can penalise that action and encourage local job use, etc.)

- Tax on unnecessary personal habits that damage your health incur costs for everyone (e.g. smoking, alcohol).

- Tax on selling houses

- Tax on international profit-moving and intellectual property usage (e.g. Starbuck's taxes being mulled).

- Tax on betting and gambling

In this case, the tax was on people who want to watch TV live as broadcast, contributing to peak power usage and trash-entertainment.

That's shifted slightly since (the way things do when there's profit to be made) but generally speaking tax is not a insurance that everyone pays into and everyone gets back from, in any way.

It's just as often a penalty on actions that are in the nations interest to discourage, and/or to profit from.

Lee D Silver badge

Re: The BBC: Crown Jewels of UK Broadcasting

My BBC iPlayer list has:

Mock the Week

Have I Got News For You

QI

Room 101

Sorry, but though I'd happily pay for the just-released box set of all the seasons of QI, I can't even do that as it's not available online, only on DVD. The rest... though great fun, I wouldn't pay a lot for it.

The BBC is no better than any other producer, and quite a lot of their formats are bought in from companies that make such things (e.g. Graham Norton moved from Channel 4, for a while they had a comedy show that was EXACTLY Whose Line Is It Anyway, made by the producers of... Whose Line Is It Anyway, Bake-off has gone, etc.).

They have just shut their online streaming shop too. So, despite a commenter on here assuring me not so long ago that I can buy old TV series from them - everyone who did just got chucked off and a refund cheque and no more access:

"BBC Store no longer offers programmes to buy. Purchases will not play in iPlayer."

They have a massive archive of content that's already digitised that they can't sell.

They have major influence over technology products for video streaming, etc. (everything has an iPlayer app).

They have the TV license fee income.

And still I can't actually give them money.

And still I'm not sure I'd bother if they can't sort themselves out after all this time.

Lee D Silver badge

I know I'd be happy just paying, say, £10 for permanent online access to a season of my favourite programs. Or even a Netflix-y deal of say £30 a year for everything.

And then, literally, forget the rest of the TV licence.

I could buy FOURTEEN seasons a year for that. And I probably would, if not more. And not be subject to scheduling, watersheds, or waiting for days for the next episode, or the other dross that I honestly couldn't care about but have to sort through to find the one program I want.

That said, there's no way I'd vote for a party just because they have proposed one vaguely-decent, non-binding idea.

Lee D Silver badge

Give me a call when any of it is legally binding with a forfeit of removal from their seat if they fail to deliver adequate progress towards it, measured at least annually by an independent party, and able to be triggered by public pressure if they look like they're not delivering.

Until then, they can promise to give me the world on a stick and it makes absolutely no difference.

No other job in the world can you get away with saying you'll do something, not do it for four years, and then get re-hired on the basis of promising to do it "this time around".

PC, Ethernet and tablet computer pioneer 'Chuck' Thacker passes

Lee D Silver badge

"Why don't we corrupt a memorial article with a mention of Steve Jobs for no particular reason?"

(No, Apple did not have first tablet, not even first touchscreen mobile device, nor first GUI).

Telegram chat app founder claims Feds offered backdoor bribe

Lee D Silver badge

Re: Secure Chats

Or just don't send messages that you haven't encrypted yourselves too.

If YOU encrypt the message properly, you could CC: in the head of GCHQ, let WhatsApp double-encrypt it, or give it away in packets of cornflakes, and it would make no difference.

What you can't hide - and what spooky agencies should be using - is the metadata. What account you spoke to. When. For how long. How large a message. Who else did that speak to? Can you tie that to another person? That's what'll convict you if you can't provide a reasonable defence, and that's what they'll use to trace the networks (whether or not they bother or can get anything useful, that's subjective).

But the actual ENCRYPTION of a message is something that is quite easy to do. Do it offline and you know your key isn't compromised and don't have to rely on WhatsApp to secure it for you.

One of the stated purposes of encryption is that you can broadcast the message over a non-secure channel. Beyond that, it really doesn't matter. There are no such things as known-plain-text attacks, etc. any more with modern encryption, even.

If you're worried about the guy at the other end being your intended target of the message, that's what keys are for (you would have to verify them by some other means - again, an entry point for a spy agency, but pretty much they can just print their public key on posters and put them up around London if they like, that's why it's CALLED a public key - it doesn't help at all in decrypting the message and only the PRIVATE KEY that generated it could do ever that).

But the medium of transport? You could put it on Twitter with all the permissions open. You'd be giving nothing away about the content of the message by doing so that you aren't giving away by every other possible means. But they still won't know WHAT was said.

Ever wonder why those Apple iPhone updates take so damn long?

Lee D Silver badge

Re: When have a billion filesystems ever been upgraded without permission before?

Hey, no problem. I want to "test" Ext5. Can I just use your phone as a test device before I roll it out and not tell you?

Tinkering with filesystem code is the easiest way to cause data corruption. It's not like upgrading to a new style of GUI widget, it's literally implanting offsets and pointers into a permanent data store, that contain the locations of your files in storage. Get that wrong - even one bit wrong in an extreme circumstance, and you can trash the root or even end up with a slowly-corrupting filesystem.

Even with all the checksum checks and error correction in the world (hint: What are you going to do if the checksum comes back as "wrong"? Invalidate data. What if that checksum wasn't ACTUALLY wrong, but you forgot to include new-fancy-attribute-X in the data you were checksumming. You just lost a sector. Error "correction" does what it says - fixes things that it believes are errors.).

Using people as filesystem guinea pigs is the worst thing you can do in terms of data integrity. Even if just for testing. One wrong pointer and you can wipe out even the "backup" or other partitions - because they are literally just numbers in a box and if you have two "partitions" you've just assigned a convention of using numbers between A and B as one partition and between B and C as another, and then recorded A, B and C somehow. Get that wrong - even one bit out, or fail to check the write properly or any number of events and you trash the "new" trial partition and the "safe" backup of the user's data in one hit.

Voyager 1 passes another milestone: It's now 138AU from home

Lee D Silver badge

"27 billion light years across, but we're just 19 light hours into it"

Imagine that.

"Are we there yet" for 27 BILLION YEARS ahead of you, and you're barely 19 HOURS into the journey. No saying that Voyager would ever make it even a fraction of that far, but it provides context.

Lockheed, USAF hold breath as F-35 pilots report hypoxia

Lee D Silver badge

Gunsmoke.

Virgin Media resolves flaw in config backup for Super Hub routers

Lee D Silver badge

Re: "Virgin rolled out a patch last month."

Have you never had your hub reboot on you, or do you just not monitor it?

My SamKnows broadband monitoring box often picks up the reboot and so knocks the statistics.

But my Draytek router also just fails-over to whatever else it likes when it happens (e.g. 4G / VDSL).

This is an IT site, yes? And you're just running a plain Superhub and haven't noticed this stuff?

Who will save us from voice recog foolery from scumbags? Magnetometer!

Lee D Silver badge

I place a thin sheet of metal between the speaker and the phone.

Your system is - quite literally - foiled.

If someone really wants to go the way of faking such things, they'll do so.

Just STOP relying on replayable, unchangeable, interpreted biometrics to secure stuff. You're not in Star Trek, you just don't have the technology enough to make it reliable.

First-day-on-the-job dev: I accidentally nuked production database, was instantly fired

Lee D Silver badge

AND WHY?!

Why would you do that? Is he going to be committing to the live database on his first day? No. Read-access, yes. Write? No.

Least privilege principle. If you don't have write access to it, you can't damage it.

And what prat just puts passwords for write-access on the production database in a document that's going to end up just-about-anywhere in six month's time?

This is my question, not "how", which you answer. WHY!?

Lee D Silver badge

Question:

Why did first-day-worker have write access to the production database anyway?

It's not even a question of backups (that goes without saying) - but how did someone walk in and get given production database write access by default without even a hint of training?

And why are THEY setting up their dev environment? Why is that not done for them, especially if it involves copying the production database?

The problem is the culture of a place like that, not what the guy did - even if you assume he's being quite modest about how careless he was.

Virtual reality headsets even less popular than wearable devices

Lee D Silver badge

Price.

I was kind of hoping that the Nintendo Switch would have been another Virtual Boy - just a console but that used VR as the gimmick, even if it was done with clever tricks but cheap components (which is kinda how the Wii took off - a "cheap" accelerometer coupled with some silly games that used it to pretend you were bowling, etc.).

But the choice now is:

- Cheap cardboard/plastic thing that needs a smartphone to work, falls apart, only works for smartphone games, and isn't that good.

- Expensive plastic things that need an expensive smartphone to work, only works for smartphone games, but it actually quite good.

- LUDICROUSLY expensive plastic thing that needs a powerful and expensive PC to work and does what we expect of "VR".

Until that situation changes, there's not going to be much traction in the market.

The only thing that isn't a toy are the Vive and Rift, and both are as expensive as a new laptop, as well as requiring a beefy PC with a serious graphics card to run them. Out of all my Steam friends I think one has one, and he has something like 5000 games on Steam so obviously has money to burn.

Also, while there are two separate tech leaders, nobody is going to hedge. It's quite probably that there is only one winner at the moment (HTC Vive), but that's not clear and they aren't completely cross-compatible, so you have to have the "right" game or someone needs to develop the tools that let you play one on the other properly (there are such drivers, I believe).

I'm waiting for the VR thing to take off. I honestly thought Nintendo were going to be first-to-market in the console stakes for the same, but they completely missed the boat. Grannies would have loved sticking on a headset and playing bowling through it and smashing up the living room in the process.

That's where the market was. But the next round of consoles is years away. The PC tech isn't coming down in price at all and is still high-end gamer-only kit, and it's a lot to pay to "hedge" on yourself enjoying those kinds of games. And everything else is not even a toy, really. It's tech-demos.

The Google Cardboard app, where a really, really low-poly whale jumps out of the water and goes over your head, shows that it's possible to do things with them that do make you wow a bit, even on low hardware. The new Star Trek game where you are on the bridge of the Enterprise, that's the kind of thing that will sell it. But there's no standard, no middle-ground, and no affordable hardware that isn't just you looking at your phone very close up.

If a VR headset (I don't need all the controller junk, a normal controller would do for introducing the tech) was in the £200 range and worked on an ordinary gaming laptop, I'd already have one. At the moment, though, they are still 5 years away from being viable. By that time, hopefully one will emerge as a clear winner to the average consumer, and work on consoles the same as on PC (it's obvious what the winner is in terms of tech, but that doesn't mean it's the market-winner - who wants to spend a fortunate to fall foul of another VHS/Betamax scenario?).

Edinburgh Uni email snafu tells students they won't be graduating

Lee D Silver badge

Re: Email is a bit like KFC

Tell me about it. I work in schools. Once a year or more, you will get a whole-school email blast (to parents, staff doesn't really matter) that has the wrong info, doesn't have the attachment, isn't configured right for mail-merge or just plain shouldn't have gone out yet.

Email really needs Print Preview too. I've often considered implementing an email "hold-and-release" for everything external. Where your email client says it's sent but actually it doesn't get sent until you go into another interface, check the content (as they would see it, and clearly highlighting whether there was an attachment or not) and authorise it to actually go out for real.

You just know that people would still be in the habit of releasing every tiny email and so would just release the 500 wrong emails too. And if you put in a size/recipient limit on such a hold-and-release, you just know people would forget to release it, even with all the system reminder emails in the world.

Papercut gets it right for printing, and I think the functionality it employs should be in the core OS itself, we really need a way to get it right for email too. If nothing else, just to make people think twice about pressing Send, or realising that the email is blank before they fire it out. I'm sure it's not hard to code and I'm sure there's a plugin for Exchange or similar that would do just this.

It would also give you an opportunity to "recall" a stupid email before it went to anyone. Though you can recall from a local Exchange server, there's absolutely no guarantee that the other side will honour it, and I only ever get recall requests for emails that have JUST gone out (but unfortunately, already made it to GMail, Hotmail, Yahoo, etc. accounts).

Giffgaff 'roam like at home' package means £1/min calls in Jersey

Lee D Silver badge

Personally, I'd be asking Jersey and those other territories to step in if I lived there.

They are the ones who are choosing to be separate, if they cared they'd be integrating or creating local rules that prevent such pricing.

WebAssembly fandom kills Google's Portable Native Client

Lee D Silver badge

Re: Call me back in 5 years

Program in established and platform-independent languages.

If I can still compile C99 to Win32, Win64, Linux, ARM EABI, LLVM intermediate code, HTML5/Webassembly, etc. then it doesn't matter that the end product might change. That's 18 years - or more - of portability.

If, however, you're required to program in "the latest fad that everyone is using", then it's a no-win game.

The problem comes from people who re-architect everything to take account of, say, HTML5 before the generic portable stuff is brought over, because they "must have" it. Any platform not old enough to have a compiler to it from just about any language isn't one you want to code on. You might HAVE to code on it, but you'll always have the problem of constantly being required to learn things that quickly turn obsolete.

Perl or PHP. Java or C. GDI or Metro. Mac or Windows. Whatever you use, abstract it out and make it portable so that it doesn't matter if someone completely changes the target device. The languages to do that are quite obvious. Basically anything not written last year, and not appearing as a buzzword on social-media-backend-developer job ads for startups.

Lee D Silver badge

Re: Has Anyone...

It's not arbitrary code, though.

If you've played about with things like Emscripten, which will soon compile to WebAssembly too, you'll realise that all the usual web-page restrictions apply.

You can't just open random files (you have to virtualise a filesystem), you can't just talk on the open network (you have to be in a trusted zone, or go via WebSockets which greatly limits what you can interact with to - basically - websites which act as intermediaries to pass anything more complicated), you can do sound but it's under the control of the browser tab, you can request webcam and mic access but it can be denied, you can do 3D but it's WebGL subsets, and so on.

Java's problem was that it claimed to be a self-contained and isolated system but from day one you could browse the user's filesystem and select files and it had to replicate the zoning/permissions in it's own plugin rather than let the browsers etc. apply theirs.

The language is still interpreted, permissioned, controlled and even CPU-restricted (so you can't just bring a computer to a halt with a webpage that loops forever, etc.).

With Emscripten (which I'm familiar with, so I'll use as the example here), I can throw a C99 SDL program at it and get something out the other end that'll run in an modern browser. There's very little to change to make it run. But to make it *work* for some actions takes a lot more (intermediate servers to translate WebSocket actions, culling of OpenGL operations back to a subset, specifying a "fake" root filesystem that is populated only in memory from the contents of a web-based seed file and allows no access to the client computer filesystem even so, etc.).

It lets you do some amazing things, and all the compilers are now starting to support WebAssembly as a target architecture, and some wonderful complex actions (e.g. take an SDL OpenGL game and compile it almost directly to a file you can put on a webserver and load in a normal browser) are now quite easy to do. But you're still restricted to the same as any other webpage.

So long as we keep that model and don't make WebAssembly a special-case (like we did Flash, Java, etc.), so long as it's just an interpretable HTML/JS page in a slightly different format, so long as it's treated the same whether Google decide to use it on their front page or you load it up from an email attachment, there shouldn't be a problem.

Meanwhile, I'm actually playing about with getting things to work - because I hate web languages but still love tinkering in C - and enjoying a lot of success. To be honest, to me, the biggest block in using such things is still the restrictions imposed by the browser, which is how it should be. Running 100,000 lines of C99 through a gcc/llvm-based compiler targetting WebAssembly is actually the easy bit.

BT considers scrapping 'gold-plated' pensions in bid to plug £14bn deficit

Lee D Silver badge

Re: Much like my pension, which I'll likely never get.

A pension is a life insurance.

You're basically gambling that you'll live past 60/65/68/whatever it is now.

If you do, you might get some of your money back.

If you live a LONG time past it, you might get all of your money back, and maybe even make a profit.

But the reason you can do that is because the other half of people will never get that far, despite paying in religiously every month.

Add in administrative costs, regulatory costs, inflation, increase in necessary provision under law, shifting retirement dates, etc. and obviously profit for the pension company, and most people WILL NOT ever get out of a pension what they put into it. It's as simple as that.

The line has always been that those people in charge of a large pension fund were smart enough and regulated enough that they would be able to guarantee its availability, and also safely increase the fund enough to cover inflation such that it would become more viable than you just stuffing it all under a mattress or sticking it in a bank. That's no longer true, I feel.

Even banks barely offer saver's interest rates now, so for every minute your money is in a bank it's actually becoming less valuable.

There's a reason that we were all made to invest in pensions via a compulsory law on workplaces. Because the governments and pension schemes know that there likely would be nothing left for them (taxation, etc.) if people sit down and work this out, and invest or save the money themselves.

Pensions are a wager on whether you'll live significantly past retirement. Any mathematician could sit down and tell you what the age was. And up until that age - when you would break even - you're effectively losing money every month. That's likely to be around 80 for most people nowadays, I imagine. 15 years of pension paid for by about 40-something years of pension contributions, averaged out across everyone. If you die before 80, you've basically paid for someone else's retirement - even if your widow gets some lump sum or similar.

Now go look at average life-expectancy. it's 81 in the UK at the moment. Work out what the retirement age will be by the time you're there, and it's likely that 50% or more of people won't ever see a penny from their pensions, and most of it will go to others (what's the state pension nowadays? £490 a month?) Give it another 40-50 years and see what a pittance that becomes for you.

Of course, this is how they're designed and have always worked. But I can't say that I have any confidence in ever drawing any pension of any significance, and I'm still in my thirties and perfectly healthy..

Nest leaves competition in the dust with new smart camera

Lee D Silver badge

Re: There is

Remember the doctor Lanning in I, Robot (terrible movie adaption, not the books?)

Working at home, while VIKI watched him through a sensor bar?

It's what pops into my head whenever someone mentions the Echo or Siri even.

Sainsbury's IT glitch spoils bank holiday food orders

Lee D Silver badge

Re: First world problems

Doing the virtual shopping gives me the time to write the lengthy post!