The Register Home Page

* Posts by Lee D

4941 publicly visible posts • joined 14 Feb 2013

Nest cameras can be easily blacked out by Bluetooth burglars

Lee D Silver badge

Re: bypassing CCTV is easy

Bypassing it is easy.

Doing it without arousing suspicion is hard.

Most CCTV systems have an "image obscured / power fail" alert that detects when a camera is obscured, damaged or disconnected and alerts people.

And such alerts - because they NEVER happen - generate much more suspicion than anything else. Hell, you can even have it set off the house alarm when that happens if you like, it's that rare.

Lee D Silver badge

Re: In other news

Which is why you use 3G/4G backup on your router, and why you use UPS on any device that you care about surviving a power outage. CCTV DVRs and cameras should be top of that list.

(And is the Nest PoE-powered or mains? Even if it's mains (stupid), it's not difficult to ensure it runs on a protected circuit, but if it's PoE, you just need to UPS the switch).

Anyone who cares about home/business security can spend £50 on the cheapest of UPS and buy a GSM alerting alarm/camera system (which is the only kind of thing I'd buy anyway... why would you want the alerts from your cameras - literally "someone has cut me off!" - not get sent over an independent connection to warn you personally?

Don't rely on ADT/Yale to come running. Don't rely on your phone line being up. Don't rely on your neighbours to see the burglars or respond to your alarm. Even the police barely respond unless there's proof of a robbery in active progress, just an alarm going off is useless and CCTV? "Yeah, if you can just search that for us and send us anything that's relevant" (I worked with the CCTV in schools for 15 years and have also provided evidence for 3 crimes for neighbour's burglaries etc. - they just don't have time to sit through even YOUR footage, they will ask you to provide it or not bother).

My system is actually a proper system:

- 30-day recording CCTV on all cameras, full res, none of this motion detection junk.

- Wired cameras with blackout / cable-cut detection alerts (even putting a bit of chewing gum over the lens).

- UPS-backed NVR.

- Connection for alerts via email, GSM, etc.

- Smartphone app on my phone, my girlfriend's phone.

- Tablet app on an iPad in work, constantly showing all the cameras all day (just underneath my monitor. After a while, you ignore it all unless something happens, but because it's ALWAYS in line-of-sight you see everything you need to).

- Home burglar alarm is wired internally and alerts via GSM messages with internal battery backup.

Already proved useful in 3 police-reported crimes for my neighbours, numerous "neighbourly" disagreements ("If I catch your kids standing on top of my garden fence again, you're buying me a new one", "But they don't!", "1.28pm today, 12:12pm yesterday, would you like me to send you an MP4? Just because I'm not there doesn't mean I can't see it"), and no end of other minor disputes (my council weren't collecting my rubbish, then they claimed it was "contaminated", then they claimed that my bins were in the wrong place - ALL WRONG!, DHL parcel guy lobs fragile parcel over back-fence and then signs our signature... etc.), as well as my girlfriend "checking the cats were okay" every two seconds. It survives power-cuts (an hour at least, I think, but I've never had it out longer than that in 3 years), it survives cable-cutting, it survives people blocking or obscuring the cameras, and instantly raises enough alerts / suspicion that I'd be on my way home with a friendly call to the police on the way there (which, generally, should gee them up more than just "Oh, someone is burgling an empty house")..

And, strangely, the closest we've come to a problem is the guy who burgled one neighbour, then came back the next week in the same car, drove past my house at 2mph looking intently at my house for a long time, then decided to burgle the other neighbour instead. I'm sure the cameras, infrared floods, hard-wired connections, bell-box, RFID alley gates, etc. had nothing to do with that....

Ironically, all-in the system cost about £300 and a couple of days of cable-running. And you'd be hard pressed to find enough inside to walk out with worth more than that before I could do something, and it'd be much more tricky to do it untraceably.

Hell, even the iPad at work isn't actually mine.

Cisco reports bug disclosed in WikiLeaks' Vault 7 CIA dump

Lee D Silver badge

I judge Cisco way more than anyone else in that regard.

That's not some super-secret hackery.

They have damn unencrypted open-packet interface enabled by default whether or not an option is explicitly set, that accepts commands from ANY packet.

Why the hell is that not just sheer negligence in creating a product?

That someone found it "before they did"? No... someone found the UTTER TRIPE that they were pushing as an interface to a modern device and just left in there.

The priest, the coder, the Bitcoin drug deals – and today's guilty verdicts

Lee D Silver badge

Re: That's funny, isn't this the same as how the stock market works?

Not exactly sure that I agree either is really a crime.

"Hey, John, this product is so fabulous you should buy shares!"

John does so.

Shares turn out to be worthless.

As far as I can see, John kinda deserved that by not doing his homework.

Now if they were fiddling the accounts, or putting out false sales figures to make the stock prices rise, that is indeed fraud.

But bigging up worthless shares? Not sure I see the problem with that. The only people hurt are those stupid enough to believe advertising.

Shine on, you crazy Eind minds: Boffins fire out 43Gbps infrared 'Wi-Fi'

Lee D Silver badge

Re: Radical new idea

IrDA and the like has indeed been around forever.

And site-to-site infrared / microwave systems too.

They have serious problems that stop them being used for anything other than consumer toys (IrDA way surpassed by Bluetooth, line-of-sight kills anything but use over your own land or free space).

Been trying to convince my employers to put in site-to-site-links but the only places that can "see" are in positions that would show the ugly, and they disapprove.

Instead, we spend £10k a year on a Virgin leased line and another £10k on a BT leased line at the other end (because no one supplier covers both areas... sigh). When I can see each building from the other. Just a shame we don't own all the land in-between because I'd just get them to chop down a couple of trees and problem solved.

Why is the Sinclair ZX Spectrum Vega+ project so delayed?

Lee D Silver badge

Stick a RPi 3 in a box, run Fuse, use a real keyboard or wire up a Speccy keyboard matrix into one of the stupendously cheap arcade-controller extension boards. Done.

I love the Spectrum.

I love emulation.

A £25 copy of Spectaculator is my pride-and-joy, after my £30 registered copy of Z80/WinZ80 by Gerton Lunter.

They do everything the Speccy could do - and more - and even have options for nostalgic real-tape loading/saving (via the proper screechy audio, headphone cables or via WAV, TZX, etc.), TV scanline emulation, etc.

And then I bought a GP2X many years ago, and things like FUSE worked perfectly. A bit of controller config (and then realising you need a full keyboard for most Speccy games anyway) and you had this product - handheld, full-colour, console-like Speccy but that could also play ANYTHING else and even had GTA-clones written for it.

Honestly do not get the fuss. Buy anything that portable can run homebrew and they'll be a Speccy emulator for it.

But nothing quite beats a laptop with 1000 Steam games, all my work, VM's for programming, a full browser, and a Speccy emulator second-to-none with HDMI out if I need it. Hell, plug in my XBox360 wireless controllers and we all played Gauntlet on TV at a party a few months back. And I demonstrated loading from tape into the emulator, and playing a TZX out of the emulator into a real Speccy. It just worked.

If you spent any money on this, I really pity you.

A Nintendo DS could do what you want, and they're basically second-hand scrap nowadays:

http://zxds.raxoft.cz/

Hardware 'dislodged' from HPE SAN during cable replacement

Lee D Silver badge

Re: Never knew...

Offtopic but - the single most stupid rule for a rotational movement.

More Brits' IDs stolen than ever before

Lee D Silver badge

Technically, for your identity to be stolen you would have to have been permanently deprived of it.

Therefore, if what you say is true, you are literally nobody.

Identity "theft" is really identity "fraud". There is no permanent deprivation of your identity.

If they used fraud to steal your money, they have deprived you of the money. They have stolen your money VIA committing identity fraud. Obtaining goods/services by deception.

Like software "piracy", identity "theft" doesn't exist. Unless they kill you in the process. But even then the charge would be murder and fraud, not theft.

Lee D Silver badge

Re: let's not even mention companies house

What on earth makes you think that a signature should ever be accepted as authentication?

Like fingerprints, that's SECURITY DONE WRONG.

And it's easy to get hold of most people's signature. Ask them, make them sign for a parcel, or just get them to write you a letter.

There's no way that the system should let name + address + signature = confirmed identity.

Anyone who thinks so is DOING SECURITY WRONG.

National Insurance tax U-turn: Philip Hammond nixes NIC uptick

Lee D Silver badge

How can you plan a budget for a year, only to undo it because of a couple of days of mild disapproval?

1) Did you not plan things properly and check you could do it earlier?

2) Is a year of planning really inferior to a few affected people grumbling?

3) What kind of forethought is going to be put into the change, which is a few days old?

At what point does anyone sit down and do research in government before opening their mouths?

Oh, Brexit is fine and we won't need to follow the law that we wrote... oops. After much expense and court-cases and backtracking, back to where you SHOULD HAVE BEEN before you even suggested the idea seriously.

Drives me mad.

UK's BT Openreach settlement highlights wider issues of 5G convergence

Lee D Silver badge

Re: Forget 5G

People get confused here.

A cable, fibre or copper, gives you what's promised, and only tends to get more as time goes on (ADSL->ADSL2->VDSL, DOCSIS->DOCSIS2->DOCSIS3, etc.). You are sharing it with your street, but can be guaranteed a portion of it.

A speed on wireless / cellular is HIGHLY variable and totally out of your hands and will ONLY get less with time as more people jump on. And the old devices will make your new devices slower. You are sharing the connection with anything in a sphere of a certain radius and there are no guarantees.

It's a bit like Ethernet - Gigabit to every single machine is easily doable. Gigabit wireless to even half-a-dozen devices is almost impossible to guarantee in any significant way as you're sharing, say, 802.11ac between six before you even start. Adding more points makes more noise too. Whereas adding more cables makes things faster (LACP, etc.).

I use the rule-of-twenties. It takes one minute to download your network profile on a wired connection? It would take 20 minutes to do the same over wireless. This is why you don't use wireless, especially in crowded environments or for more than web browsing.

5G would be no different. Technically, it can give amazing speeds. In real life you'll get a pittance just larger than the previous pittance, which will get less as more and more people use it.

Borked browser baked into Nintendo Switch

Lee D Silver badge

Re: I see what you did there

Since when has The Reg been Apple-loving? They can't even get a quote from them any more.

Lenovo EMEA wakes up after five quarters of sliding sales, adds CEO

Lee D Silver badge

Re: Maybe ....

Lenovo kit is okay.

It's their home-based junk that got loaded with all sorts but what kind of place doing any serious deployment doesn't just image over the computers, even if they are brand-new.

My place is entirely Lenovo (IBM Bladecenter servers, Lenovo clients) on the PC side, their hardware is pretty bullet-proof. The laptops aren't bad (IBM Thinkpad legacy), the desktops are solid yet cheap. Their Chromebooks leave something to be desired but are in the same ballpark as Acer, Asus, etc.

Pretty much, they have the business side down. Their problems in the home-market are self-inflicted but I'm not sure most people would even recognise the Lenovo brand, and certainly won't understand its history.

200+ desktops deployed, into the fourth year soon, not one failure - not even a hard drive.

Oxford Uni boffins say internet filters probably won't protect teens

Lee D Silver badge

Re: hmm

Private schools are far from doing what they like.

We have exactly the same child protection and e-safety problems as any other school, plus a bunch of pushy parents threatening to remove funds all year round if their darlings don't pass standardised exams with top grades every time.

With the ISI etc. breathing down your neck as vehemently as Ofsted.

Naming computers endangers privacy, say 'Net standards boffins

Lee D Silver badge

Re: Ping

No, they said that having ping enabled made it a visible attack vector - which is hilarious as the connection in question offered SMTP, HTTP and HTTPS among others.

PoD is old-hat caused by people expecting packets to be compliant with RFCs, which is a stupid assumption in any network-connected system.

Lee D Silver badge

Sorry, but if my internal network is leaking my hostnames, or I'm joining untrusted networks that can probe device names, I have bigger problems than the names of the devices.

That said, I do just name things when working using alphabets (phonetic, greek, etc.) or long lists of names. And lots of clients are generally just numbered. Thus there is no leak but - again - nobody but my users should have any clue that there even exists a machine called sierra.domain.com or whatever.

Devices joining my wifi generally only get web anyway, so there are no mysterious discovery protocols running around unless they are trusted devices and, again, how the hell is that stuff leaking outside the network?

The problem is much simpler - you have to advertise what your mail server is called, your local network advertises (internally) what your domain controller and DHCP servers are called. That some iPhone belongs to John? Really, who cares? And, again, what are they doing being able to talk out as if they are Johns_iPhone.domain.com? They're surely not.

This is almost as silly as when my security auditors told me that having ping enabled was a security risk. Not for any definition of security that I can fathom when it's already serving mail and web to the world.

If fast radio bursts really are revving up interstellar sailcraft, here's the maths

Lee D Silver badge

Re: Astrophysicists think

If you have enough on-board energy to slow down, you could just use the same amount of onboard fuel, travel at half the speed, be able to stop and start yourself, and not need some complicated interplanetary laser system to help.

It just doesn't really add up.

Lee D Silver badge

Re: Astrophysicists think

How do you stop?

I mean, momentum can hurt quite a lot in space, and do you have to have another beam slow you down from the destination?

Or do you have to get a tiny craft with no propulsion down from millions of miles per hour to nothing with no on-board energy?

Cold callers illegally sold Aussie farmers 1,700 years worth of printer ink

Lee D Silver badge

$44 a cartridge?

My last printer lasted 12 years and didn't use $44 of toner or other parts in all that time. And it had a replacement drum and roller for that cost too.

Damn, I miss that Samsung laser printer, but there's only so long you can keep an Intel NetPort Express (with its 386SL chip inside) running to convert the Centronics port on the printer to be a network-addressable printer.

It's replacement, which is a mono wifi laser with NFC, smartapps and all sorts, cost less than $100 in equivalent money too.

They could have bought several hundreds of modern printers for the cost of that ink.

Anti-TV Licensing petition gets May date for Parliament debate

Lee D Silver badge

Please list any action taken (beyond "discussing it") about any of the Parliamentary petitions whatsoever.

And how much happened compared to how many petitions are made every day. If there's even 0.1% that actually result in anything beyond talk whatsoever, I'll be incredibly surprised.

Like when I was back in school and the pupils petitioned for all kinds of ridiculous things, it doesn't matter how many people sign, nothing happens at all.

In the most extreme cases, lip service is paid to having a discussion about the issue, and literally nothing happens after that anyway.

It's a total waste of everyone's time.

Apple empties gas can, strikes match, burns bridge to hot-patch apps

Lee D Silver badge

Re: Code injection.

Do you think the vetting process tests every possible code path? Do you think it even can?

Do you think you hand over your source code to Apple for testing, or a pre-compiled binary?

Do you think you can't just put "Test this website DNS entry, is it X.X.X.X? If so, be a virus" into the code and have it slip past ANY app review process?

Even if you have to obscure it, have you seen how easy such obfuscation is?

Even pretending that you're auditing such code is just smoke and mirrors, I'm afraid. There are no guarantees whatsoever even with the most skilled reverse engineer on the other end. Modern apps are tens of megabytes of compiled binary.

Stop relying on some guy at Apple who has seven millions apps to approve before Monday to spot things.

Just make sure that your permission model means they CAN'T ACCESS those hidden internal APIs, that they can't gain permissions they weren't given, that they can't interfere with other apps or data not explicitly given to them (e.g. via "Share" or other IPC) and that they can do no worse than run up your CPU time.

But, of course, that requires a proper security model rather than smoke-and-mirrors.

P.S. There is still an app - for the last three years - on the Apple iTunes store which is a full VPN, advertised as "break through your school filters", which is rated suitable for ages 3+, and Apple refuse to change it because "it's up to the app developer" (I have the emails if you'd like to see!). But Google Chrome, official app, is rated 18+ because it "lets users access the Internet).

Apple couldn't care less about you. All they want to do is stop you bypassing the app-store to do things.

Messaging app used by Trump aides 'riddled with security bugs'

Lee D Silver badge

Sigh, as always totally missing the point.

It's like a checklist of things only present if you have no care for security except as an afterthought, which is pretty serious for a "secure" messaging service.

"Not only have these issues been addressed, but we also have no detection of them being exploited by any other party."

That would require you LOOKING and BEING ABLE to tell they were happening. You didn't see the guys doing it when they were initially building their tests and reports, so why would you suddenly detect them now.

You are failing best practices, before you even made a single line of code.

Scammers hired hundreds of 'staff' to defraud TalkTalk customers

Lee D Silver badge

With multiple SIP trunks at my disposal? Not a lot. Especially once you call the BT abuse line and just tell them to intercept your line for an hour because of the harassing calls. BT don't much care for such things and have ways to block it upstream and take you out of business past a certain point. Did it to a bank, who got threatened with all their phonelines being disabled (they had an automated dialler that went potty and just kept dialling the same number, no CLI, but soon after BT intercepted it I got a phone call from the managing director of the bank to apologise).

I don't answer non-CLI calls and it takes only a few seconds to add certain groups of international numbers for, say, a few days to a very, very, very long and boring phone menu that costs me nothing to send them through, doesn't disturb or interfere with my system at all, but costs them a lot to dial and listen to.

(Last time someone tried to pull similar stuff it was actually a UK letting agent I was dealing with, who didn't have anything at all techy in the way of a switchboard, and I pissed one of the call-centre guys off so they thought it would be funny to keep ringing from all their different numbers and from withheld numbers. So I called their call centre direct - always argue prepared - and when they realised who I was, i.e. the guy they were trying to spam for sport, they kept hanging up. So I jammed their phone lines solid for 30 minutes with automated calls and scripted it to ring me only when they decided to stay on the line for more than a few seconds. Basically, I carried on with my day and just waited for the phone to ring which meant they actually wanted to talk rather than hang up or play pranks. They confessed that they couldn't do any business for all that time and eventually relented and dealt with my complaint - after threatening all kinds of things that never happened. Probably cost me about £10. I think it cost them a LOT more. Worth every penny for the phrase "No, look, we're sorry, please stop")

Lee D Silver badge

With modern SIP trunking, it's almost impossible to bother to police like that.

I can get a Weybridge number in seconds, dialled into from the other side of the world, paid with a credit card (probably stolen if they are a scammer) in minutes, and it would take days to work out what was happening and shut it down.

Additionally, when you did shut it down, it would take only minutes to set up another or use one I've set up previously but not yet used to spam.

CLI is as useless as a From: header in an email nowadays.

Hell, if you do it right, you can have one telecoms system set up in your callcenter with staffed phones, and SIP trunks from all over the world that weren't traceable to that IP (just wrap them in various VPNs, who cares?), and every time a SIP trunk falls over, you have another ten programmed to go. Your staff would never know, your system would just carry on working flawlessly, the SIP people wouldn't be able to play catch-up fast enough, and it would be rather difficult to trace to you.

And when you commit fraud for a living, that kind of setup is probably the bare basics. To be honest, when they catch phone scammers in the UK where every phone is just registered to a certain business that they then raid, I feel a hint of disappointment that they were that stupid to get caught.

Hell, Skype will give you phone numbers galore for a couple of quid a month.

Lee D Silver badge

I find that the phrase:

"You are aware that you're committing fraud for a living, don't you?"

usually gets an immediate hangup. I've actually had revealing talks with some of them, where they are quite unhappy with what they are doing.

UK's Virgin Media subscribers suffer fresh email blocking misery

Lee D Silver badge

Problem with relying on server bounces? Server bounces end up creating more spam than the original messages, because you can't verify that the address to bounceback to is correct. The only thing that guarantees the server that is sending to you got the message is an error response in the SMTP session itself. Which is easily ignored and not propagated back to the original sender because... you can't verify the original sender's email address if you're the endpoint or a transport server somewhere in the middle of the conversation (e.g. a mail forwarder). And if you don't have the correct settings and suspect that bounceback email isn't genuine, you CANNOT send a bounceback and if you do, likely you're distributing spam on their behalf, etc. anyway.

Email is fundamentally broken in this regard, as are the associated standards which say you MUST send bouncebacks no matter what, etc.

Until someone re-invents email, there is no guarantee of delivery or timeliness.

Lee D Silver badge

People relying on email to be delivered EVER and certainly within a specific time-frame are failing to understand how email works anyway.

An email server could hold onto email for 24h or not deliver it at all and nobody would ever know, once the message has been acknowledged by the server itself.

Email is NOT guaranteed. Stop using it as if it is.

It is CERTAINLY not time-guaranteed in any way, shape or form.

But, yes, greylisting often works on a hash of the sender domain, recipient user/domain and IP address such that genuine email from genuine mailservers is delayed by a few minutes for the first ever combination and then never again after a successful retry (subject to certain time windows, e.g. after 30 days of no email it might reset and delay an email again).

Lee D Silver badge

Would you like to see my mail logs for a large school?

Greylisting blocks something like 90% of the spam that manages to make it through Spamhaus etc. RBL checks, reverse-DNS checks, SPF checks, etc..

You're required to retry, but on the timescale that the SERVER asks. If you retry too quickly (e.g. automated blasts from botnets), you end up making it even longer before your email will be accepted.

Additionally, retrying adds a lot of logic, storage and bandwidth to the system that only interfere if you're emailing en-masse, without hindering genuine email servers that play ball. You have to retry, from the same address, with the same email, only after the specified delay.

Yes, it's just "another measure". But it's effective. And, like tarpitting (which is basically what it is), it shows you who's just trying to get as many emails out as they can before they get shutdown, and those mail servers who are happy to just deliver your email on your schedule.

Honestly, greylisting does more than some blocklists manage on their own.

Until someone fixes email with a replacement that's secure, authorised (i.e. NO you can't send me email because I don't know who you are), low-bandwidth, compatible, popular etc. then greylisting is a pretty damn good measure.

Prisoners' 'innovative' anti-IMSI catcher defence was ... er, tinfoil

Lee D Silver badge

"I'm going out on a limb here, but I guess they get the foil from the kitchen."

So prisoners are walking out of a kitchen with a concealed metal object, back to their cell, where it's stashed, traded and used and nobody notices?

This is exactly my point. There's a problem right there.

Lee D Silver badge

Two questions:

Where did they get tin foil from such that they could all use it to block their signals from their own cells?

How do the mobile phones they have smuggled in get charged?

Tuesday's AWS S3-izure exposes Amazon-sized internet bottleneck

Lee D Silver badge

Re: Optional DR/Resiliency

The number of times that I've had to explain this:

If you want a backup system, it will cost you what the real system cost, again, and a bit more for whatever tech to make it fall over.

And, yes, that functionality, hardware, processing power, storage, etc. will NOT be available to you to use. It will literally be idle (from a user point of view, but hopefully replicating etc.!) most of the time.

If you want something that tolerates a failure, you have to buy two of them and one of them does nothing all day long but wears, depreciates and costs just as much as the first. If not, it's not a suitable replacement.

And then you get into the depth you take this to - a redundant disk is just another disk. A redundant array is just another array. A redundant server is just another server. But a redundant site is another site. A redundant datacentre is another, fully-funded, fully-functional, datacentre. That sits and does nothing but can break in exactly the same kinds of ways over time.

And then you have to have a controller card, or another storage array, or a licensing for the server and software to make it failover, and site-failover logic and hardware, etc. on top of that cost.

I'm currently working at a place that can put a value on their data. They very nearly lost everything, and it would have cost an awful lot to get back running, let alone try and get their data back. Thus their DR is "proper" as they realised how much it would have cost in time and money, realised how much it would cost to avoid that (including my salary, for instance) and choose the "good" side of the coin.

As such, despite being a tiny employer by global standards, we have remote sites, remote servers, remote backups, full remote operation in an emergency, redundant leased-lines, redundant cabling around the site, redundant servers and all the logic to tie this together nicely.

But to secure System A against failure requires System A and System B of the same spec - MINIMUM - sensibly System C and maybe System D as well, plus the additional licensing and logic to fail them over and complete copies of EVERYTHING on them all. So you would have to pay 2-5x the total price your system cost originally, just to do a basic job of it.

When you do the maths, that STILL works out better than data loss, however. But nobody ever costs data loss properly until it happens and they realise how much it REALLY costs in terms of lost custom, legal requirements, hassle, time and money, the complete INABILITY to recover some data (no, you can't just post it off to 'a specialist' and expect anything to come back except a bill), etc.

One IP address, multiple SSL sites? Beating the great IPv4 squeeze

Lee D Silver badge

If anything, I've only ever required one IP per workplace but been given 5 per connection, plus 5 for any external server we rent.

Were we able to get, e.g. BT and Virgin, to properly co-operate on their lower-end of leased lines so we could have proper AS announcements, we would only need the one IP address per site.

From that, SNI is a given and you can safely NAT thousands of users without a problem. I have Smoothwall reverse proxy for a number of things (not least, it can inspect the traffic en-route to internal services acting as IPS at the same time as SSL-wrapping services which aren't SSL-capable internally) but I wouldn't use it to save on IP addresses.

There's no reason that I need lots of external IP's any more. One is sufficient and every connection that gives me a second IP, I'd be more than happy to set up in a load-balance/failover configuration on the same IP anyway, but it's generally not possible with normal business offerings. If anything, having one IP makes things so much simpler.

Currently I run two sites with an external server range in a datacenter, including two leased lines and two VDSL lines. I currently have three ranges of five IPs (six including the gateway IPs, and the VDSLs include a Cisco router which is doing bonding to one internal range), each of which only one is used to refer to that range and add it to the firewall. And only one is publicly advertised as the destination of every DNS setting we use. On top of that I have a small range for the external servers, again, we only use one.

I make that a wastage approaching 85% just for a small business. If everyone is doing the same, it's no wonder there are no IPv4 left.

And again, Reg, when you are going to deploy AAAA records. Look - you could use this article to put a machine on IPv6, add it as the AAAA record, and just have it proxy to your IPv4 site. But I'm guessing the answer will be "we're working on it" for about the seventh year in a row.

Boeing seeks patent for mobile device case with built-in fire extinguisher

Lee D Silver badge

Re: Daft!

Better than that.

Patent the solution to the symptom, thus profiting from every fire instead of stopping them.

Lee D Silver badge

Re: Water

I'm honestly hoping you're being subtly sarcastic.

Water wouldn't be very effective at extinguishing a Li-ion fire either. Given that lithium explodes or catches fire on contact with water.

ESET antivirus cracks opens Apple Macs to remote root execution via man-in-middle diddle

Lee D Silver badge

Re: Less secure?

Antivirus is a program running with system privileges that intercepts each and every filesystem call and has complete and arbitrary control over what it does with the data from that. It sees every byte that flows to and from storage, and is capable of trawling storage any time it likes with privileges beyond that available to any user (i.e. it can read locked and system files, etc.).

It auto-updates from a third-party on the Internet to gain new functionality, including downloading new executables and rulesets. It prevents you uninstalling it easily. It monitors every user, can access all of RAM, and has carte blanche over your system processes. If you have an AV suite with firewall built in, it's also capable of doing the same for network traffic while having the capability to exclude or hide any traffic it likes and even potentially acting as a man-in-the-middle for SSL with access to your trusted root certificate store so you can't even tell. It's also particularly hit-and-miss on real-world infections, and is more easily disabled by malicious software than by its own intended users. It's primary function in professional environments is mainly as a canary, where it talks home from every client to an installation on the local network with the same privileges and itself decides whether to alert the user if one of the client AV's drops off.

AV is, pretty much, the very definition of a bad idea. And yet it's still suggested that AV is REQUIRED for things like PCI DSS.

If you value your system security, an AV package is about the worst possible thing you can install.

The Psion returns! Meet Gemini, the 21st century pocket computer

Lee D Silver badge

Re: What a negative bunch of comments

Or, I could wait. See if it flops. Save my money. Buy one later when they're actually available and tested.

I've done LOTS of kickstarters etc. But from established companies that have a proven track record of delivering.

All the kickstarters I WANTED but which suffered from the same criteria? They never made it to market or were a very niche flop.

Sorry, but I was a big fan of the GP2X and looked at many of its successors - a niche handheld Linux gaming machine. I would have gladly have invested if there was even a HINT of actual work before the money was begged for. As it turns out, most of the projects that succeeded it were flops, scams or just outright wastes of money even if they delivered. One guy literally took money for preorders for years, then wanted nothing to do with the project, and kept milking more and more money out of preorders and still never delivered. It was only because someone else stepped in and bailed them all out (incurring financial loss) that anything was ever delivered. What do you think is the size of the market for such a device, its software or peripherals reliant on it? Zero.

Skepticism isn't negativity. Literally, yesterday this device was "ready". Today, there's a single prototype in existence, which doesn't have the most critical element. There's a reason that the big investors are ignoring it and crowdfunding is the only option.

Come back in a year with your shiny device and lord it all over us, by all means.

If not, I'll certainly be coming back when it all turns out to be an outright scam, never deliver, or only deliver something that's completely inferior.

Just the playing on Psion's name is enough to put me off. Sure, we have the guy who designed the keyboard on board. The only bit that NOBODY has actually seen yet.

Lee D Silver badge

Re: predantry

Not really.

Both use the Linux kernel, but they are vastly different userspaces exposed to users, even if underneath that they have a common layer.

Up close with the 'New Psion' Gemini: Specs, pics, and genesis of this QWERTY pocketbook

Lee D Silver badge

At one point I owned about 10 Psion Series 5MX's.

I know what they are.

I also know that the history of crowdfunding something that doesn't exist in even prototype form is why they have to crowdfund rather than seek investors - because NOBODY else but fanatics under the illusion of hype will touch them.

Lee D Silver badge

Re: 18:9?

In this instance, I think I could justify an improper fraction.

We all know what a 16:9 screen is. An 18:9 screen is obviously wider.

It's not IMMEDIATELY obvious that a 2:1 screen is wider than a 16:9 screen for the layman, however.

People don't handle ratios well. I've had any number of arguments over this, and also that it's measured by screen diagonal.

No, a 65" 4:3 smartboard is NOT the same as a 65" 16:9 touchscreen. In fact, you lose quite a bit of height and it looks tiny and stupid in comparison.

Lee D Silver badge

So the entire point of the new device - the keyboard - wasn't there, doesn't exist in even the only demo unit? But you saw a HINGE? Wow!

It's sounding much like the Vega scam that some of the same guys are involved with.

And this is the THIRD story (if you count the "pre-announcement" vote thing). I'm disappointed, Reg, that you've got suckered into pushing this so hard so early.

At the moment, it's a mini Android smartphone, the like of which there are thousands.

Licence-fee outsourcer Capita caught wringing BBC tax from vulnerable

Lee D Silver badge

Why is it not just folded into normal taxes?

So sad how much wasted time and money is spent on administering a bunch of unnecessarily complicated taxes.

Put £5 per screen inch on the price of a TV, on import or manufacture. Done.

Everything else is really just messing about. 30m households each buying a TV a year = £1.5bn for zero admin whatsoever.

New prison law will let UK mobile networks deploy IMSI catchers

Lee D Silver badge

Is it still me that's of the opinion that if you need to track mobile phones in a prison, that the prisoners shouldn't be able to get hold of them anyway?

Fixing entirely the wrong problem.

Sure, this might catch a few (stupid) over-the-wall-throwers, jailbreaker assisters, etc. but they will smarten up quite quick and just leave their phones at home that day.

If prisoners having phones is a problem, stop them getting phones.

And if a dragnet like this is anything other than "there's a new phone on the site!" "Well, where did they get that from, trace the history and see if we can work it out", then you're really on the wrong side of the problem.

If you can smuggle a phone, you can smuggle a knife or even a small bomb.

Git fscked by SHA-1 collision? Not so fast, says Linus Torvalds

Lee D Silver badge

Not really - SHA-1 was, as you say, fine for what he was using it for.

And if you look at why he's not panicked, it's because he didn't rely on any particular assumptions about SHA-1 lasting forever, for instance.

Hashes and cryptoalgorithms last 10 years now if you're lucky. Protocols and code last much longer than that (isn't the Linux kernel over 20 years old now? And even IPv6 is that old and not seeing full deployment still.

In git, SHA-1 is not used for security, it's used as a quick check, and a easily referenced nugget of information that can identify a particular change. As such, it can be replaced by any number of things quite easily. Sure, probably an on-disk format change would be required too but in such an open program, that's hardly a concern.

But if you were using SHA-1 in your SSL setup, you have had an issue for a while now. That's why it's being phased out. And we all knew that was what was going to happen.

Sooner or later, WPA2 will be dead, just like WPA and WEP before it.

Sooner or later, SHA-3 will be dead, just like SHA-2, SHA-1, MD5 and myriad others before it.

Rather than design your protocol to be RELIANT on it, especially if that reliance directly affects the secrecy of data rather than, say, use as a quick reference checksum in an open repository, design your protocol such that every such advance is handled like this: "Yeah, it's not really a problem. Next version fixes it for another 10 years."

Ah, the Raspberry Pi 3. So much love. So much power ... So turn it into a Windows thin client

Lee D Silver badge

Re: refurb hp elite 8000 with win 7 license

These things are the size of a large matchbox. Silent. No moving parts. No heat. No ventilation. Minimal power.

By comparison, deploying a laptop or even a mini desktop is much more expensive and hassle.

These things sit behind the monitor that you're viewing them on (VESA mounting).

Anyone can find a "free" way to do the same. But not in so small a box.

That said, their annual licensing is expensive. But they do have a niche usage case.

Lee D Silver badge

Re: And the rest of the bill...

They're aimed at schools.

Schools pay (at least depending on what they signed up for) one licence for each full-time-equivalent teaching employee.

So a small primary might pay for 20-30 licences. A large secondary for 100 licences.

At educational pricing, I have 500 pupils and 50 staff. We have DataCenter (all versions), Windows (all versions), Office (all versions), RDP licences (all versions), Exchange (all versions), SQL (all versions), etc.

And what I pay is 40 x Windows. 40 x Office. 40 x RDP. 40 x Exchange CAL. 40 x SQL CAL. And then one each of the others. It costs a few thousand a year.

Per user, that works out to a couple of quid each per year to have it all.

And because of the licenses, it matter not how many actual machines I deploy. Only servers are charged individually. We have 150 client machines, for instance.

My network switch licences cost more than that each year.

New UK laws address driverless cars insurance and liability

Lee D Silver badge

Re: failed to "install software updates to the vehicle’s operating system - hmm

I wanna see an automated car negotiate the Hanger Lane gyratory.

If they can pass through that unscatched, then I think they're ready to go on the roads.

I imagine, however, that they would spend their lives stuck on the roundabout entrance never quite managing to get anywhere.

Lee D Silver badge

Re: Meanwhile back in May 2000...

To be honest, it's a stupid analogy.

90% of drivers have probably never opened their bonnet (hood).

Those that do, surely 90% of those are doing so to top up oil, water or other fluid. All of which could be from from a cap on the outside of the car.

Hell, have you TRIED changing a lightbulb on a modern car yourself? It's nigh-on impossible without taking all kinds of stuff out.

But the number of drivers who NEED to look under the hood is vanishingly small, and those that do could do all the ordinary stuff without needing to open it anyway. Why is it not just petrol, oil, water, washer fluid, brake fluid, clearly labelled, different size / colour / shape holes, locks on everything but the water, and a welded-shut bonnet? Everything further (servicing, etc.) you could quite easily dictate be done from under the car, which any garage can organise as part of their normal routines anyway.

Most people do, effectively, buy cars with the hood welded shut and pretty much have since electronic ignition came in. It's also the same for software, which makes the analogy even worse. The reason is - if they have no understanding or need to tinker under there, it's safer not to give them access. What he was advocating was the antithesis of the least-privilege-principle, in effect.

Bring it BACK... with MODs! Psion 5 storms great tech revival poll

Lee D Silver badge

I found five of these in an old cupboard I was asked to clear out in a school I did the IT for.

I checked what they were (they were rebranded, but they were precisely just a Psion Series 5mx with a certain software card in them for educational use), nobody had ever used them for anything, and I asked if I could have them. They were only destined for the bin, so they said yes and I took them home.

They're a great piece of kit. I would have killed for one when they were actually the state-of-the-art. I ended up selling them off on eBay for about £30 each when I was short of money a few years later, so they were still popular and useful to someone (aren't they used for stock control and things quite often still?).

They knew how to cross the barrier between "entirely new technology", "sensible way of working" and "converting people from paper records" perfectly. I fear that any revival would lack that kind of knowledge and design skill entirely.

BT, Ericsson square up to Arqiva, Samsung over 5G arms race

Lee D Silver badge

"Along with university research partner King's College London, Ericsson and BT announced a multi-year collaboration agreement on 5G testing and development this morning."

Well - that's that project dead in the water if KCL are the ones doing the backups of the research data...

The final 5G technical performance specs have been set

Lee D Silver badge

Re: Before anyone says...

London? Any major city.

A single tall office block could have several tens of thousands of devices in it, and occupy, what? 200m x 200m footprint?

And mobile wireless is NOWHERE NEAR capable of replacing hard-cabled connections, and likely won't be.

A fibre can do 100Gb today, now. Wireless radio technology of any kind can't even get close to that. Entirely different use cases, point-to-point versus multi-point time-sliced broadcast.

Even if it worked for now, it will be obsolete before you can mention it.

Even the USO is now 30Mbps instead of 10Mbps, and we never even got to the point where everyone had 10Mbps. The goalposts will keep moving, and radio technologies will always lag. Especially as, past a certain point, using radio waves of any frequency just aren't practical - we're already struggling with the frequency/wavelength -> signal penetration trade-off.