The Register Home Page

* Posts by Lee D

4945 publicly visible posts • joined 14 Feb 2013

Windows Atom Tables popped by security researchers

Lee D Silver badge

Re: Super cool name!

They are just a data store, yes.

But if nobody has considered that an Atom Table can be modified by other malicious programs, likely they aren't sanitising the input. And given their length of history, there are bound to be thousands of apps that can be crashed in particular ways with a dodgy Atom Table entry that they try to use.

I would hazard that there's at least one in an office suite somewhere.

This is why I don't like inter-process things, stores, registries, services, internal kernel buses and all the other stuff. There' are too many entry points to send data to programs that are not visible to users or even the programmer, and that means they are too hard to sanitise and isolate properly.

But you don't need to execute the code directly. If you do it right, that Atom Table entry might be copied into RAM, contain a buffer size, which the program acts upon, and then if you corrupt it it might be able to fall off the end into a copy of whatever string you've stored in the Atom Table, which might well mean that executable code sitting at the end of it ends up getting executed. It's not that people "run" the Atom Table. It's that it can be used as a source of potential buffer overflows and the code that they will overflow into.

Dan Kaminsky calls for a few good hackers to secure the web

Lee D Silver badge

And if we can make it so that you have to prove ownership of the private key (by signing some kind of nonce value) for the domain you CLAIM to be sending FROM, we can cut fake email out the second it arrives without having to guess based on IP address (which is just silly in an IPv6 world).

Lee D Silver badge

Not so bothered about DNS. That's a back-end infrastructure issue and redesigning a set of name-to-IP lookups isn't exactly tasking, it's just awkward, and there are plenty of things we already have that we're not using (DNSSEC etc.).

But can someone, please, for the love of <deity>, fix email?

Spam email, fake email, unencrypted email, etc. That has a real-world effect and has absolutely no solution at the moment, besides rubbishy, non-guaranteed bolt-ons to existing SMTP protocols (SFP, DKIM, etc. but still no proper end-to-end encryption).

Why does DNS not hold a set of public keys for each domain that are used to encrypt email to that domain by all email servers (and unsigned email is just discarded)? DKIM isn't the same, that's more like a signature and the content still isn't encrypted (and certainly not guaranteed to be past the first hop).

High-end DNS-based attacks using VALID DNS DATA like the Dyn hack don't interest me at all. But email still be open to a network sniffer at any point along the way to your destination is so 1980's that it's just laughable. And people STILL think that email is secure. It's time we actually made that assumption true.

PayPal patches bone-headed two factor authentication bypass

Lee D Silver badge

Re: Always been like this

Question: What would you do if you lost the TOTP?

However, I can't see TOTP without thinking of a largely-discredited BBC One music show.

20 years to get Amiga Workbench 3.1 update, and only a fortnight to get first patch

Lee D Silver badge

Re: Workbench update..my ass

Yeah, cor, they must be RAKING it in with their update racket.

From both customers.

Squeaky bum time for Apple: It hasn’t made enough iPhone 7 Pluses

Lee D Silver badge

"What went wrong?"

Usual story.

Nothing. We can now officially claim that we sold-out.

'Non-state actors*' likely to blame for Dyn mega-attack – US intel chief

Lee D Silver badge

Obviously not.

A state actor would have made a complete hash of it and nobody would have even noticed they were under attack.

Quite how many "Syrian website offline after US cyberattack" stories are there? None.

That means they're either so good that mention of it cannot even make it back, or they are untraceable, or they aren't doing it / aren't capable of doing it.

Occam's Razor gives you the answer.

And so we enter day seven of King's College London major IT outage

Lee D Silver badge

"Not having to buy many bunches of hardware, each specced out to peak usage and hence idle 99% of the time."

Nope. Then you'd just consolidate your server's functions onto one server.

You virtualise to remove the dependency on the underlying hardware to provide portability, and isolate it from the other machines also running on the same hardware.

Otherwise you'd container, or consolidate, or something else.

Lee D Silver badge

"detemine the root causes of the problem"

Insufficient VM replicas.

Oh! You mean why that particular storage failed?! I didn't.

The whole point of virtualising your infrastructure like this is that you DO NOT have to rely on one storage, machine, datacentre or whatever else to stay up.

Where are your independent replicas? Your warm-spare hypervisors? Your secondary cluster machines to move those VMs to?

Hardware upgrade failing a RAID - yes, agreed, nasty.

But you seem to have NO OTHER RAID or indeed any practical hypervisor or storage replica, certainly not one with a vaguely recent copy of data it appears, around.

What is the point of putting your stuff on VMs and then running them from one bunch of hardware? By now you should have been able to - at worst case - restore your backup to anything capable of acting as hypervisor (e.g. a machine from PC World if it really comes to it, but more reassuringly your backup server cluster?) and carried on as if nothing had happened. Alright, maybe an IP change here or a tweak there, or running off a local drive somewhere temporarily while your storage is being rebuilt.

But, hell, being down for SEVEN WHOLE DAYS on virtualised infrastructure that includes your telephony and all kinds of other stuff? That's just ridiculous.

Gravitational lensing event could provide ideal conditions for planet hunting

Lee D Silver badge

Re: Cinderella orbit distance is a JOKE....

And the problem with astronomical numbers? They appear quite ordinary when you compare them to other astronomical numbers.

Even at millions to one, being the only one in the galaxy would be unlikely.

Milky Way: 200-400bn stars, 100bn planets minimum.

That's a hundred thousand planets with life at even a million to one. Even at a billion to one, that's 100 of them.

Visible Universe: 2 TRILLION galaxies. Each with roughly the same as above.

And that's just what we can see.

Chances are that there's life in our galaxy and it's basically certain there's life in the universe. The problem is really when you run the number for "Would we ever meet them?" to which the answer is - probabilistically - a resounding no.

Lee D Silver badge

Re: Cinderella orbit distance is a JOKE....

Did Terry Pratchett teach you guys nothing?

Million-to-one chances crop up nine times out of ten.

Microsoft: We're hiking UK cloud prices 22%. Stop whining – it's the Brexit

Lee D Silver badge

Re: Cloud costs

No different to anything else.

Your Office and Windows licences will likely go up, whether or not you're cloudy.

It's not cloud that costs, it's reliance on a third-party. If you're reliant on MS software, then MS can dictate any price they like from free to prohibitively-expensive-but-just-enough-to-keep-them-in-business.

And there's nothing you can do about that except pay up or move elsewhere.

The only other alternative is to reduce your reliance on third-parties entirely: Use in-house software. Even OpenSource software is still a reliance on a third party to continue supplying it and maintaining it, but at least it's not quite so drastic if they go bust tomorrow.

I do wonder quite how many companies actually need general purpose PC's running general purpose OS, with general purpose office apps. I think you could increase productivity enormously by making any forms, paperwork, documents, letters, mail merges, etc. be conducted through a limited menu running on a server, that you log into from a thin-client (which could, in fact, be a general purpose PC).

Back when I did work experience, they were ditching a custom-built software running on a WYSE terminal setup and the transition was horrendous. They went from "You can't put a foot wrong, do something outside your power, misspell your customer's name, or not do things without the necessary prerequisites all in place" to "Just knock up a letter in Word and post it out". Literally from "Press 1 for this, press 2 for this" menus that strictly limited what you could do to what you needed to do, to everyone and his brother having Internet Explorer, Word and potential for major chaos.

There's a reason that many shops, banks and other large establishments use shop terminals as nothing more than an interface to an "antiquated" terminal- or web-based stock/inventory/invoicing/whatever system.

If functions DO NOT EXIST then you cannot mis-use them. The things you can do in even basic office macros is just plain scary.

Hacktivist crew claims it launched last week's DDoS mega-attack

Lee D Silver badge

Or just charge users by the byte coming into and out of their connection.

Solves all their problems, while screwing over everyone else, and looking like they are "doing something" about rogue devices attacking others.

Chap turns busted laptop into phone keyboard, in Himalayan book-rescue mission

Lee D Silver badge

Re: Not quite as hardcore but...

I once tried to fix a Spanish au pair's laptop. Most stuff in Windows you can guess the equivalent of, but we were uninstalling and reinstalling an AV and trying to clean up the computer generally.

At one point, we resorted to Google Translate which did enough of a job to get things done.

Until we hit one dialog on the AV installation.

It translated as "Send a second piano". I wasn't sure that was going to help at all, to be honest, so I didn't dare press it.

(It was obviously a button to "try again", but it was quite hilarious at the time)

Other joys include trying to use monitors that have had their display settings flipped sideways, Chinese keyboards (a work of art even if you speak Chinese, apparently), and one machine that would only give the top-right 640x480 pixels of the screen even though it was drawing to a full HD framebuffer.

Fortunately, I work in schools, so the keyboard shortcuts to activate the old "control-button menu" on the top-left of every window, and then slide the windows back into view and resize them using the keyboard are in my long-term memory.

Ageing GSM crypto cracked on commodity graphics rig

Lee D Silver badge

I'm guessing the graphics cards weren't the main expense.

With things like rainbow tables, probably the machines was fully kitted out with RAM, and extra graphics RAM and some more RAM, and a few SSDs to catch what the RAM can't hold.

Como–D'oh! Infosec duo exploits OCR flaw to nab a website's HTTPS cert

Lee D Silver badge

Re: just the font?

Well, I once signed up a school for Microsoft's volume licensing program.

The sign-up is all electronic, they verify everything via Microsoft Live accounts, you log into the VLSC with those same accounts, you add others (e.g. billing) via the same accounts, and so on.

At no point do you fill out a piece of paper or write anything down.

Yet, one year when I was signing a school up they were taking forever. We eventually got to the bottom of it - someone had "misspelled" administrator in our email address. My first question was, how the hell have you misspelled a word that we've only submitted ever to you electronically?

Someone at Microsoft sits and types in volume licence administrator email addresses by hand, from entirely electronic forms and emails.

Smoking hole found on Mars where Schiaparelli lander, er, 'landed'

Lee D Silver badge

So we can make drones that can beat Earth's gravity, fly around like lunatics and be computer controlled for less than a tenner...

But nobody has applied the science of actual aeronautics to something intended to land elsewhere? Why are we not sending GLIDERS instead of trying to aim at the damn planet in a straight line and hope we can slow ourselves down.

Literally, send something that needs NO POWER to land, that's been well-tested, that you can simulate easily (air turbine pointing up in a sealed chamber full of whatever gas!), that can descend in a spiral and even ASCEND if it's required and it can find the right breeze to do it, simple, low-tech, can be controlled by a box big enough to fit inside a micro-drone and carry a lot of weight (e.g. hang-gliders).

No complicated pressure-sensing altitude setup required, no decision on when to fire the boosters or drop the cargo, just a huge wing shape and a little flap here and there to make it spin round.

Why are space shuttles plane-shaped with wings and aerodynamics and thrusters "behind" that are not used in descent, and circular and looping gliding paths for landing, but everything we send to other planets is always a huge box with thrusters on the bottom trying to slow itself down from stupendous speeds in a straight line aimed right at the damn planet?

Sysadmin flees asbestos scare with disk drive, blank pay cheques, angry builders in pursuit

Lee D Silver badge

*cough*

Undecided.

http://itre.cis.upenn.edu/~myl/languagelog/archives/000378.html

Lee D Silver badge

Re: Bursar

Three swimming galas (in boiling hot heated indoor pool with chlorine up your nose for hours)

Two sports days

and a cross-country run.

Just don't forget to take the 3G dongle or you'll be bored stiff before the first event even starts.

Lee D Silver badge

Nothing.

Nothing.

Nothing compared to the wrath of hundreds of parents at a school sports day honing in on you when their little darling miscounted their own points, or argued over a fraction of a second.

And you're the school IT guy who was given the job - by a friendly bursar who was rewarding you for a good week's work - of sitting out on a field, in the sun, under a veranda, with a free drink and a laptop and a box of USB stopwatches, the world's most complex event scoring system, dozens of simultaneous events with hundreds of children, and a years-old Excel spreadsheet with broken formulae written by a PE teacher.

Oh, and the overall results need to be announced in 5 minutes, and the other schools competing will ALL be emailed the results for their newsletters this afternoon, and you can be damn sure that your scoring will be scrutinised heavier than a ticking suitcase at an airport by those nice sportsman your teams just thrashed, and their mummies and daddies, and the result you give now under pressure is going to be used to award trophies, so it better match their week-long analysis of the same data perfectly.

No pressure.

What will happen when I'm too old to push? (buttons, that is)

Lee D Silver badge

Christmas is easy.

Amazon wishlist.

Steam wishlist.

Other site wishlists.

Stick the links to the above in a Google Doc which contains the line "And a jumper with a reindeer" and share it out to everyone who wants to buy you something.

Make sure there's big expensive gadgets on there. And tiny silly things. And a DVD for Auntie Joan who doesn't know what to get so your brother buys you the DVD and tells her that he got you something from her.

And then anything off-list is basically potential eBay material. Sorry, guys. That's the truth of it. So much so that when I buy others gifts, I make sure to make it clear that - so long as they enjoyed the OPENING of the gift, the surprise, the joke, or the initial tinker - then that gift is theirs to do with as they will, even re-gift, and no shame.

One year I bought a particularly troublesome teenager an Amazon giftcard and stuck it in a plastic maze which you have to solve before you can open it up to get to the giftcard. It became a running joke (especially after she opened it up and then THREW THE GIFTCARD AWAY not realising what it was) and that box went round FOUR other people (family, friends, friend's family, etc.) with differing contents before Boxing Day actually finished.

But, yes, I get the "I'm feeling old" bit. I've been middle-aged since birth but - Steam games? Meh. All remakes and junk indie games and overpriced AAA titles. TV seasons? Nothing I can think of that I would want, even with free reign over all of Amazon and Google Play. Gadgets? Nothing enthuses me there any more and I'm quite happy with my current phone and laptop.

Nowadays, it's the junky toys, the childhood things I never had when I was a kid, and the stuff that makes me laugh that I ask for.

Christmas is about having fun, enjoying yourself whatever religion (or no religion, like me).. Socks don't do that. Serious things that you "need" are no fun at all. And if I need them, I've probably already bought them.

No, I want toys and junk and noisy things and science experiments and board games only hilarious when everyone is drunk, and all the tut in the world - of which I'll only be playing with the boxes from the day after. That's what Christmas has always been about, ever since I was a child, and I see no reason to break with tradition.

If I'm going to have to drag a dead tree into my lounge without needing to provide an explanation, I can damn well have some silly toys too without having to pretend to be an adult.

Fruity hacking group juiced by Microsoft's October patch parade

Lee D Silver badge

Re: The

TTF Font rendering is actually partly using a virtual machine. Truetype is a horrible and complex beast.

That said, why it wasn't doing it in an isolated user in the first place is a bit of a mystery, but then WMF files were just function pointers to GDI functions and we used them for 20+ years even while they were being exploited.

But Truetype rendering - and pretty much all font-rendering - is a horrible job. Everything from font hinting bytecode machines to sub-pixel rendering integrating with graphics drivers.

Let's all go down the Strand (our data centre). King's College London goes TITSUP*

Lee D Silver badge

"while HPE continues to work with the institution on getting its kit working again..."

Say no more.

Swisscom claims world's first G.fast broadband service

Lee D Silver badge

If other countries that are more rural, less dense, and yet can get higher speeds on ordinary lines for the same prices? Sorry, but we're doing something wrong somewhere.

And I'd point the finger at deployments like this, and the complete lack of take up of the broadband subsidies, and the lax legislation forcing companies like BT to service those kinds of customers.

Nowhere do I imply that there's some magic that we haven't yet discovered as a civilisation that we should just "go out and research". It's been done. Many times. But we're not doing it.

And yet we're still talking about broadband connectivity over only 90% of the country, a tiny little country, where much larger nations have done much more in much less time.

Hell, it's STILL going to be another couple of years because I can use my foreign-owned carrier mobile phone, in their home country, without them charging me for data roaming when all they do is shove the local Internet connection on each tower down an already-existing leased line with the traffic tagged with the lowest QoS available to them.

The problem is not technical. The problem is complete lack of interest in breaking up BT / Openreach and forcing it to do what it should be doing - providing back-end services to everyone and averaging out the cost across the country so that some bloke in Scotland pays no more for his first connection than some bloke in London (who's secretly subsidising the bloke in Scotland).

Lee D Silver badge

I don't see 500Mbps at 200m as much of an achievement nowadays. You can do 10Gb at 100m with off-the-shelf networking hardware, and 1Gb at that same distance is ludicrously cheap (you can get a 5-port switch off Amazon that can do that for about £20).

Sure, the copper is different quality. It's a slightly longer length. But you're telling me it's THAT MUCH HARDER that it's taken 20-25 years to catch up?

I'd be infinitely more impressed at, say, 10Mbps at some enormous length. Kilometres. But that's actually DIFFICULT, rather than arguing over which protocols to use and then buying whatever vendor's kit that took you out for lunch.

The problem with modern Internet is not the top-speed. We have that sorted. If it comes to it, we can easily do gigabits to local cabinets over these sorts of distances, it's just not an issue. The problem we have is that outside that distance we have almost nothing. Other countries fibre in their properties, so distance isn't even an issue (sure, it costs, but once it's in you're done for the next 50 years).

Sorry, this just isn't impressive at all. And it doesn't really help anyone but the ISPs who might be able to get more money out of you by whacking up your speed against your will and charging you extra for it.

And I live inside the M25, and have decent FTTC Internet. I just don't see speeds 200m from boxes as a problem worth solving at the moment when you still have people only a matter of km from a major town who get bugger all.

You work so hard on coding improvements... and it's all undone by a buggy component

Lee D Silver badge

Re: Levels of blame...

What about:

The system that was designed so that updating one module of a piece of software, reliably, on multiple versions of - say, picking an OS entirely at random, Windows - is non-existent or almost impossible.

If people could just say "Is this module, a Java module called X, installed, or could you install that for me, please OS, along with its dependencies?" programmatically and have it reliably work cross-platform, that would be some way to a solution.

Then you can end the static binaries, hard-coding and compiled-in-libraries and literally just say "This software needs OpenSSL, please install it" and then updates to OpenSSL take place for EVERY piece of software that needs to use it.

But we don't have anything like that, from a programmatic point of view. Even Linux distros, that's an action outside the scope of programming and into the scope of package creation and OS integration. There is no programming language that I'm aware of that automatically sorts out such things for you so that when you #include popular_library it makes sure that popular_library exists, or asks the user if they want to install it, and keeps it up to date. The onus is all on the packager, not the developer (and they are rarely the same person), and on the individual package management for that particular OS (there's no cross-platform way to do this).

Perl CPAN.

PHP libraries.

Java dependencies.

DLL's.

You name it, the problem rears its head in every language in common use, and the languages always consider it "outside the scope" of their remit to provide for it.

If you want to stop building statically building in old versions, and thus propagating vulnerabilities in un-updateable code, you have to design an OS and a language that takes account of things like this. There's no way we should be manually creating dependency files, packing up RPMs with funny little tags, or running setup programs that have to be told to run off and download MSVCRT from the MS website and then installing it and then switching back to the "setup" program if it worked.

Java is no different here. But Java was always a highly-specced langauge with the capability for this kind of thing. Aren't java packages almost exclusively referred to by a corruption of their origin domain name? (com.java.sun, etc.). There was scope there to make it automatic, tie it in with DNS, XML requests, etc. and it wasn't done.

The closest we get is things like Javascript libraries and XML DOM's where you can instruct a browser to run off and download the latest JQuery or use a particular version of the Google web fonts or whatever, and it tries its best to do so. And that works quite well, to be honest. Millions of website rely on it.

But still you see websites that copy/paste their code to local URLs and things like that. And yet no "offline" programming language or mainstream operating system has facilities for this kind of thing.

Nobody who wrote a piece of code 10 years ago is going to bother to keep the libraries up to date. They probably no longer work on it, no longer have the power to do anything about it, no longer paid to do that, no longer remember or care. But we still just assume that software will live forever in the same state once its written.

Imagine if, when OpenSSL was flawed, or MD5 was cracked, we could just mark it as obsolete, mark an upgrade path, and EVERY piece of software that dealt with them worlwide was updated to use a replacement library or object class as soon as it was next executed?

SHA3-256 is quantum-proof, should last billions of years

Lee D Silver badge

The thing is that if quantum decryption becomes real and viable (at the moment, it's just not), then quantum encryption is waiting in the wings anyway. Why worry about how the current algorithms might be obsoleted (like DES, etc.), just ensure you have a replacement you can move to when the inevitable happens instead. Then re-key, re-encrypt and you're good to go for another 10 years until the next flaw (and next algorithm that solves that flaw) appears.

Expecting ONE algorithm to stay around forever and be uncrackable is ridiculously naive. Public key encryption such as we use didn't even exist 100 years ago and in the meantime - apart from literally two or three of the very latest algorithms - everything along the way has been cracked, weakened beyond repair, or was just plain useless to start.

There is absolutely no reason to suggest that in the quantum world it will be any different, although a guarantee of message authenticity is slightly easier, yet still subject to human error - just as even Enigma was.

Every time you find a hole, or a new feature of maths/physics you can make use of, redesign, re-key, re-encrypt. In a thousand years, we'll still be doing exactly that.

Apple's car is driving nowhere

Lee D Silver badge

Not wasted as such, they may come about one day and the same info and laws will be in place and apply equally.

But anyone with half-a-brain knows that self-driving cars are dangerous and unlikely to happen until the AI epoch arrives, which is currently a LONG way off. There's literally no such thing as AI outside of uni labs, and they are INCREDIBLY limited in scope (e.g. playing Go) rather than anything to do with interpreting the outside world or making decisions about incredibly complex real-world situations (like sitting at a traffic light).

If you want a self-driving car, you need to move the humans out of the way. We did it already. It's called a train. The ones on the London Docklands Light Railway are, basically, autonomous. It's easy and we did it decades ago. They don't need to be "intelligent", which is extremely difficult and outside the scope of the ENTIRE WORLD'S current technology.

And then you realise that it would be quicker, cheaper and safer to take cars off the road, make the roads electronic, and give everyone a personal electric train. Problem solved, and things won't run off the rails quite so often as a self-driving car trying to navigate a maze of BMW-morons and Audi-idiots.

HPE UK overlord lines up sales generals, gives ra ra speech

Lee D Silver badge

Allow me to relay a telephone conversation I've just had with someone from HPE only a matter of minutes ago:

Them: Hi, this is X from HPE, I just wanted to...

Me: If HPE phone me again, I will add you to the switchboard blacklist, thanks very much, goodbye.

Seriously, they - and their resellers - are bugging the life out of me. I admin a small school but we have some really good kit and NOT ONE BIT of it is HP. There's a reason for that - everything from these kinds of phone calls all the time to just not selling a single thing I'm interested in.

And when I *tell* them that we don't have - nor want - a single HPE machine, service or anything else, they don't stop. Any other company with half a brain just says "Okay, no problem. Do you mind if I give you a call in six months or so?". And you know what, THAT I don't mind. Even if the answer is going to be the same in six months and I KNOW that for a fact.

But HPE have just one nerve of mine left before I just start blocking their calls at the switchboard entirely. And they have no interest in fixing that situation.

Spent £250k with IBM/Lenovo on server kit, though. And have literally NEVER had an un-asked-for phone call from them.

HPE have definitely had a massive push in this area over the last year or so, it's highly noticeable but from my point of view it's been nothing but counterproductive in increasing their actual sales.

I've just made a bet with my technician over how long before we find out that HPE are actually bankrupt and desperate for any custom to salvage that.

How a chunk of the web disappeared this week: GlobalSign's global HTTPS snafu explained

Lee D Silver badge

Re: Let's Encrypt is Free?

Maybe the ACME client is incompatible with their IPv6 setup.....

(/sarcasm)

Lee D Silver badge

Because signing up for thousands of subdomains is a pain in the arse, especially if they all renew at different times.

Fine while the software works. Major headache when it can't renew one for some reason or you need to move machines.

Lee D Silver badge

Re: Still struggling with the concept of

Was about to comment the same thing.

Should cross-certs have the same public-key as any of the certs they are signing? That seems daft, to me.

It seems a not-unreasonable assumption to me that if you request revocation of a cert with a certain key, and a certain subject name, differing only in date, to then render that cert - and any that it signed - as invalid from the point of issuance of that cert.

Otherwise, what's the point of the revocation and cross-signing mechanism? If, say, the R1 cert WAS compromised and new intermediates signed against your will, isn't that EXACTLY what you would want to happen? Using the cross-signed R2 to revoke it AND its intermediates?

Seems to me to be blaming the software in use for a particular operation when that operation is quite within the scope of reasonable measures, even if it was unintentional or other software DOESN'T do that.

How about you be more careful when revoking certs, and issue cross-certs that aren't using the same public key? If R1 signs a cross-cert that signs R2, there's no need for any of those to use the same public key. If anything it defeats the point of the cross-cert if they share a public key, because they then also share a private key, which means that if that shared key is compromised SOMEONE ELSE can sign any cert they like.

Maybe I'm misinterpreting their PR, but it sounds like they skimped on the implementation, didn't test, and then tried to blame software that had a not-unreasonable, maybe even highly-desirable assumption in it.

GlobalSign screw-up cancels top websites' HTTPS certificates

Lee D Silver badge

Re: Ouch

I'm not at all sure that ANYONE actually verifies the certs in SMTP servers. The chain of trust is rarely investigated for such things, as they generally only want it for encryption and aren't checking endpoint authenticity. With things like DKIM, the certificate chain doesn't matter, only the certificate thumbprint, and DNS/DKIM is doing the endpoint verification for you.

A lot of Linux distros set up self-signed certs for SSH and SMTP when you install the relevant server packages.

In fact, I would suggest that using the SAME signed cert for SSL, SSH and SMTP might well be a risk, but I'd be hard-pushed to remember where I read that or what the reasoning was (it might be as simple as "things like SMTP servers sometimes use internal / older SSL libraries").

Aussie Aussie Aussie, oi oi oi you, you're fired: Apple sacks staff secretly snapping shoppers

Lee D Silver badge

Then Apple users are even sillier than I thought. They should be asked to REMOVE the passcode before any work takes place, or as soon as the device appears functional again (e.g. screen repair). Even if that means by some Apple debugging technique that requires a special cert only issued to Apple repair shops AND the user passcode entered over a USB cable.

However, if you're expecting your data to ever be recovered, from any company, you are going to need to give that company some kind of access to it. At that point, you need to be able to trust them. And I would trust Apple store staff about as much as the local PC World.

Unless someone invents a way to encrypt user files and applications completely separately so that you can just transfer "user_files.encrypted" off the broken machine and onto a new machine and then get the user to put in their code on the new device at their convenience, then there's no other solution.

I must say a thousand times a day that I don't KNOW people's passwords. I just have access to their files or devices. I can't log in as any user, except by resetting their password which is auditable, noticeable, affects THEIR use of the machines AND I can't put it back how it was before I changed the password. I can impersonate their user account from mine (auditable), and I can access the storage medium they have stored their files on. But I can't "be" their user or see their password. Even on iPads. I can't remove the passcode or find out what it is, but I can bypass it by supervising their machine beforehand.

But if you want to repair a random device that involves either resetting passwords (potentially wiping out encrypted files, e.g. Bitlocker), or the user's passwords. NTPASSWD, for instance, wipes out Bitlocker encrypted files for that user when you use it. Any other way in requires a password or hacking equivalent to giving out your password and data.

The solution is to stop building machines that throw user files over several folders, all over internal and external storage, mix them all together for every user (e.g. Program Files, ProgramData, etc.), with no easy way to transfer that configuration to another machine without interfering with passwords, being able to read or wipe out encrypted data and its keys, and that works from any version/machine to any similar version/machine.

But we're still building systems where user files on a single user laptops are stored in C:\Users, C:\ProgramData, C:\Program Files, C:\Program Files (x86), etc. but you can't transfer most of that to another random machine without causing immense amounts of reinstalling, reconfiguring, flat-out crashes and non-working parts, etc.

It's not even true on Linux any more. /etc/ is almost completely non-transferable and picking apart the bits that aren't is a nightmare. /home is a good start for individual user's however. But then you get into /usr/ /usr/local/ etc. and it all falls apart again.

We seriously need to move to a system where every program is entirely self-contained and portable, and every user home self-contained and portable, and the combination of both on any machine makes them "just work". Our "bodge" of the moment is VM's which just carry all the above in one file and then have multiple of them running on some system with the exact same problem.

Blighty's National Pupil Database has been used to control immigration

Lee D Silver badge

Read the full quote.

Unless they are legally required to.

If the police or Home Office asks, they are ALREADY legally required to.

It was game over before they even begun.

Burger barn put cloud on IT menu, burned out its developers

Lee D Silver badge

"Let's pay an expensive middle-man to do almost exactly what our IT guys were doing, with less responsibility and care, for more money, representing a tinier portion of importance to their careers, and being more out-of-reach than ever."

I honestly do not understand this strategy.

I mean, I sort-of get outsourcing if you're going to save money but... ORACLE?! I mean, you might as well just stamp "Will sign any contract for a free lunch!" on your head. It's the stupidest move I've ever heard of and it WILL come back to bite you like... well, just about every other Oracle customer there is.

But ignoring that, you only had a team of 20 in the first place. That's good for running what must be hundreds(?) of outlets if they're all using your systems.

I honestly can't wait for the fireworks when you next want to make a change to that system. It's going to get expensive fast and you'll either need to bury that cost under your denial, or pay up and backtrack on every reason you did it.

I had a guy on the phone the other day who was trying to convince me to put him through to my boss so he could discuss outsourcing the IT department. Needless to say the phone call never went through, I considered that the height of rudeness, personally, but that there's also a reason that I'm on-site. Because EVERY time they've outsourced the IT, in any place I've worked, it's been a disaster.

I spent the first half of my career exclusively running around those places who had outsourced - or been forced to by local councils - but "needed extra help" to maintain their usual levels of service, and I've spent the second half exclusively fixing up the messes caused by outsourcing IT carelessly (I'm sure you CAN do it, if you're careful, but you shouldn't do it for cost factor alone).

Cyanogen mods self away from full Android alternative

Lee D Silver badge

Re: There's a definite market ...

I have to say, it's hard to sell something that's free unless you add value.

They obviously are NOT adding value. You can just buy a normal phone, slap CyanogenMod on it, and pretty much you have a Cyanogen phone. Any unwanted "extras" on it could well be in Cyanogen as well, so you gain nothing by paying. And, as you point out, most of the features and development are coming from people giving their stuff away to the open-source project anyway.

I can't say that I feel sorry for anyone here - I'm an open-source coder myself. You write the code for the love of the code, not so that some company can / cannot steal it. If you wanted the company to exclusively benefit from it, you'd sell it to them. If you wanted to keep it out of that companies hands, you'd licence it so they couldn't use it. That you licenced it liberally so EVERYONE could have it, including the company that might benefit from it and then sell it on - almost "as their own" even if they don't explicitly do that - means you volunteered that scenario be possible.

I don't think Cyanogen are particularly scummy here. They could have been an awful lot worse. But I also think that because they've not added ANY value to their commercial offering, that's why it's flopped bad enough they can't make money.

The Microsoft parts? Not really interested. Every phone manufacturer does it. That an "open" one selling a closed product does it? Well surprise me sideways. Who'd have thunk?

Guess what the only survivor will be out of the mess? The open-source code. Maybe not even the name, certainly not their own phones, or their company. There's a reason that open-source code is so highly valued. And I've never heard of anyone use their products except the results of the open-source project.

Leap second scheduled for New Year's Eve 2016

Lee D Silver badge

Re: How to handle leap seconds

Then they cause problems for themselves - as you are fully one second out of whack if you ever compare "seconds since a certain time" against the result of "current time in seconds".

And your server clock can be accurate to thousandths of a second without even trying. NTP alone provides millisecond accuracy.

And it doesn't matter for most applications, but it DOES matter for the ones that fall over when it changes if you haven't taken account. Word isn't going to throw a fit, but anything billing, accounting, collating statistics, or reading data each second is going to mess up unless you take account. And that's EXACTLY why you program those as if they DO matter and not just slew clocks. E.g. the 59th second of Dec 31st will collect TWICE as much - transactions, temperature collections, billing periods, etc. as any other in the year, which might well trigger alerts and compensations that you DO NOT want.

No need for atomic clocks.

But an extreme need for people to learn that - when programming anything reliant on the clock - the OS clock can be extremely unreliable.

And it's more to do with people doing things like: programming seconds that only go from 0 to 59. 60 causes them to crash, loop, or other things.

There's no excuse - like there's no excuse for programming leap years wrong (every four year? WRONG!). The specification is out there and if you don't program to the specification, you're going to have trouble.

Lee D Silver badge

Re: WTF

Mid-morning, what time-zone?

Doing it at midnight UTC makes much more sense, because it won't screw up people who are working in most timezones, and you'll have 9 hours to fix anything that does go wrong.

However, I agree on the date. There are better days to choose.

I'm infinitely more concerned, however, that a leap second mechanism that's existed for years, if not decades, still doesn't have a general solution in any software package dependent on time. It shouldn't be something we're wasting so much time on any more, like you shouldn't be using any software that doesn't understand February 29th.

Invasion of the virus-addled lightbulbs (and other banana stories)

Lee D Silver badge

Please stop talking about AI as if it's anything other than a rule-following robot that needs it's hand held for years before it finally "gets" what you're trying to teach it and is confused by the simplest of things outside that scope.

We don't have AI. We've never seen AI. And we aren't likely to have AI for a long time (when we do, you'll will immediately and categorically know about it as it will likely form a whole new era of human evolution).

That stuff that says it's AI today? It's lying. Self-driving car or face-detecting camera, it's lying. It's not capable of anything even approaching intelligence, artificial or otherwise.

Stop it.

Zilog reveals very, very distant heir to the Z80 empire

Lee D Silver badge

Yep.

And Gameboys.

And all kinds of devices.

TI graphing calculators still do, for many of their models (but that's because they never actually have anything vaguely modern in their calculators).

Lee D Silver badge

Re: http://www.pofo.de/S8000/S8000_scaled.jpg.

Take the dot off the end, you plonker.

Never explain, never apologize: Microsoft silent on Outlook.com email server grief

Lee D Silver badge

Re: "hosted on third-party servers"

Think, though.

Those customers DO STILL HAVE ACCESS TO THEIR DATA. Their thinking was correct.

What they don't have is access via Outlook.com, but they still hold their own data.

This is why I have no objection to "cloud services" so long as they aren't holding my data or capable of holding it to ransom.

Whether they have SERVICE or not is another question entirely. But I'd be an idiot if I rolled out something like this without another way to access mailboxes, send and receive email etc.

Backup MX records? In-house webmail? These things should be available.

And then you question why, for instance, you're paying for an online service that - if it turns off - you run your services. And when it turns on, it's reliant on your services running. It's like hiring a chauffeur for yourself that drives your car. If he's absent, you still carry on as normal. But he can't work without your car. If the car's not working, neither of you can drive.

Why you'd want that - except as a way to throw away money for the sake of looks - I can't fathom.

I work in schools. They want us to move to cloud-based MIS services. But all the MIS providers allow you to run the "cloud service" from your in-house servers. Mainly because IT throw a fit if you suggest that ONLY the MIS provider holds your critical data and you have to pay to get it back out from them, and you're reliant on them working perfectly to do simple things like take attendance registers (legally required).

So we actually have an "MIS Online" which is an online interface to the traditional SQL database for the MIS. And you can have that hosted by the provider, or hosted by yourself. So you end up in the silly situation of having "MIS Online" being a local service that you're hosting yourself, with your data also hosted in-house.

Why would you pay the MIS provider to host AN INTERFACE to your data that requires to connect back through your firewall to get to your actual data that you're hosting in-house anyway? It's just daft.

'Please label things so I can tell the difference between a mouse and a microphone'

Lee D Silver badge

Yeah, where's the confirmation dialog? I mean, how often do you MEAN to move a whole folder of thousands of emails somewhere else?

Lee D Silver badge

Yesterday I had an email from one of the senior management team here.

They "had lost all their email folders".

Somehow, they managed to provide a screenshot (without asking, in the same email, with the entire screen! That almost redeemed them instantly!).

I replied with a cropped section of that screenshot, with a big red arrow pointing to the tree-expanding arrow that collapsed folders such as "Inbox" have on Outlook.

I usually do my own Friday Funny emails around my workplace, when there's something worthy. I already today's...

Google's hardware extravaganza: Ad giant takes on Sonos, Roku, Linksys, Amazon, Oculus... you name it

Lee D Silver badge

Sure. If you DON'T LET YOUR EYES REST.

That's the point.

Nothing to do with the actual distance. Just to do with staring at a FIXED distance for so long and never changing focus.

No different to headaches when trekking through jungle - which you can get because you're either in fixed focus at the floor, or constantly shifting focus if you look at all the trees for hours on end.

Lee D Silver badge

"Just as a side point: are we all choosing to ignore the fact that ramming a screen inches from your eyes for hours at a time is unlikely to do your eyes or brain any good?"

Your mother was wrong.

Distance does not matter.

Fatigue through over-extended use - yeah, sure that's a problem. Same problem as watching too much TV or playing too many video games. When you're tired and your eyes hurt, stop.

But your eyes were built to focus on all kinds of things at all kinds of distances.

Level3 switch config blunder blamed for US-wide VoIP blackout

Lee D Silver badge

Re: Update RFO - TL;DR:config change error

Some lower being in their IT rolled out a duff config to mission-critical routers affecting some - what, millions? - of customers, because they didn't bother to pre-test, check, verify or anything else on their config change and manage to take down - what? a million? - phone lines.

Of course, none of this was caught by testing or configuration or change management, and it was only when it got to the top bod who actually knew what he was doing, who started shouting, that someone owned up to putting a stupid config on their main devices without testing.

This obviously all took hours to happen and fix rather than someone pushing a change to a set of switches they manage, testing them immediately afterwards, and then immediately rolling back when they realised they weren't working as before. Because, nah, forget all that, our customers will tell us if something doesn't work.

It doesn't matter WHAT scale of business, the same stupid junk happens all over.

Stingy sapphire lens in Apple's iPhone 7 is as scratchy as glass

Lee D Silver badge

Re: El Reg

When the choice is "be honest" or "get co-operation from Apple", I know which one I'd prefer and which one I'd expect a website I frequent to do.

Literally, who cares what Apple thinks? If you have to suck up to them, and tell something other than your honest opinion to get any kind of dialogue with them, then stuff them. One of the biggest reasons I read The Reg, and I've even complained when an article-writer on here mentions Apple, or Apple-bashes, just for the sake of it. If it has little or not relevance (beyond humour) to the article, I don't care about it.

Apple's opinion on and reaction to The Reg's review technique of their products from many years ago has ZERO relevance here.

Lee D Silver badge

Gosh, all sales patter and bog-standard (or even below-standard when you take into account the cost) product.

Who'd have thunk?