The Register Home Page

* Posts by Lee D

4941 publicly visible posts • joined 14 Feb 2013

Expired router cache sends Google Cloud Engine TITSUP

Lee D Silver badge

Re: Remind me again

http://uptime.is/99.95

They can be down for 4h a year, on average, and still claim that uptime.

If they play silly beggars about uptime not being 24/7 but usual business hours, or whatever, then it's even worse.

And, remember, that's only a target. They can't "guarantee" that worse won't happen, only that they (might) compensate you some pittance in proportion if it does.

Lee D Silver badge

Re: Remind me again

Because local services NEVER go down...

Cloud isn't evil, as such, you just have to know what its limitations are, like everything else. The dependency on your whole work network of simple things like: The clocks being in sync, connectivity being absolute and not overloaded, power being up etc. are all present still. There are few businesses or even home users that can approach the uptime of something like Google Cloud given the number of services it runs for them.

Hell, I have to reset my home router about once a month and if it's out for five minutes at a time, that means in a year, I have an hour's downtime just doing that.

Cloud isn't evil, but neither is it the answer to everything.

Personally, I don't enjoy faffing trying to keep our Exchange server up and exposed to the world compared to my last workplace where we just had Google Mail for Domains. Sure, it can go down, but more likely WE went down as a workplace and that means we can at least check email on phones even with the connectivity and servers off.

It all depends what you want, how you want it, and what you're willing to pay for it. Personally, there's a lot of in-house stuff here and I'd like to keep most of it that way. But a few things, I'd gladly push to the cloud and let someone else worry about it en-masse.

And anyone who believes that ANYTHING is the complete answer on its own is an idiot. Sorry.

Horrors of murky TrueCrypt to be probed once more

Lee D Silver badge

TrueCrypt never supported UEFI either. That's the point - rather than reinvent the wheel, if we can add GPT and UEFI to TrueCrypt (which is no small feat), we're more likely to get a working, compatible, secure system than if we rip everything out and restart it from the ground up.

Truecrypt was great - it just needs to be brought into the 21st Century a bit, that's all, and then it will be fabulous.

By comparison, doesn't Bitlocker still encourage you to upload your keys to OneDrive?

Did NSA, GCHQ steal the secret key in YOUR phone SIM? It's LIKELY

Lee D Silver badge

Re: If Apple wants to really piss off the feds

Pretty sure I would trust Apple much less than I would trust GCHQ.

And I don't trust GCHQ at all. I mean... they're spies. It's kind of their job. It'd be like trusting James Bond with your secret plan. He's BOUND to act upon it even if he sleeps with you and promises not to tell anyone. (sob).

Lenovo shipped lappies with man-in-the-middle ad/mal/bloatware

Lee D Silver badge

Re: Secure boot?

Secure Boot makes sure that you boot securely into the OS you intended.

It has no effect, design or control over what the OS chooses to do. In the same way that you can login as an admin and delete critical registry entries, you can login as the system OEM installation user and install bloatware and junk.

There is no, and never has been, way to stop that in Windows. Windows does not verify that you, the physical user, want to install that Lenovo junk in the same way that it doesn't verify that you, the physical user, want to choose Chrome as your default browser or change the desktop background.

It's ridiculous to suggest so.

To install ANYTHING on Windows or Linux which runs in the way of necessary drivers, you need to be able to slipstream things into the initial install which can be run as an administrator. It's game over. What broke these system was not Windows, or Secure Boot, failures, but having Lenovo install - as an administrator user - malware before it got to you. Whether that was in an automated (slipstream install) or manual (log in as the initial admin user) fashion, there's NOTHING that can stop that but Lenovo not doing it.

The alternative is that MS has to certify and pre-install not only every driver that could possibly work on their system, but every application as well. That's not what you want, I assure you. Want to install that freeware that you downloaded off the net to fix a problem? Sorry, not signed by Microsoft and therefore not in the MS trust chain. You want to put it into the trust chain manually yourself? Lenovo could have done that exact same thing and you'd never have known more than this showed itself.

Secure Boot just ensures that you boot into a valid, authorised bootloader of your choice. At all points past that, you're on your own. Even the OS isn't necessarily dictated - hence why Linux can still boot on Secure Boot systems with (I believe) a Fedora/Microsoft-signed bootloader. Past that point is not the domain of Secure Boot in any way, shape or form, but the OS. And the OS will allow a user with administrative rights (whether inserted as a slipstreamed instruction via unattend.xml or similar or just by virtue of being the first user created during setup) to do whatever they want. This is no different on Windows, Linux, or anything else.

The second you break that, you break every SCCM system in existence. And I'll be damned if I'm going to get MS to "sign-off" on my custom install of Windows that I deploy to several hundred machines every time I change it.

Lee D Silver badge

Just one* of the reasons that I image over or reinstall a PC on purchase, business or personal.

But, seriously, how much can Lenovo have earned back from that to justify screwing their customers over? If someone is paying hundreds for your laptops, and then you're screwing over their privacy and security for a handful of pence (after commission), it really shows where your priorities lie.

Don't "get an update" or "review the situation", stop doing business with them and stop bundling that junk at all.

(*) Other reasons include: I don't know who touched it before it got to me, I don't know what other junk is bundled to pop up when I plug a camera or printer in, I want to prove to myself that it CAN be reinstalled from scratch with all the drivers using only the discs given before data goes on it and before it goes out of warranty, etc. and the amount of junk I see bundled on "new" PC's that slow them to a crawl is unbelievable. Just cleaned a PC from the Vista era as a favour and it was STILL popping up things from Fujitsu etc. about restore processes, driver disks, special offers, spyware junk, printer drivers, you name it that HAD COME WITH THE MACHINE ON PURCHASE.

Also, I once found out that brand-new purchased laptops would not work with full disk encryption because of a dodgy BIOS by testing this. Encryption would work, everything would be hunky-dory, but reboot and the BIOS refuses to boot from anything that did not have a zero in a certain hex offset of the hard disk (which corresponded to a zeroed field in an NTFS header). As such, anything non-Windows you ever tried, or any sort of disk encryption, and it rendered the machine unbootable. Actually forced the manufacturer to obtain and issue an updated BIOS for that model, because we'd purchased many of the same model, I'd noticed immediately, had a reproducible test case (involving writing a non-zero to a point on the hard disk), they'd said it was compatible, I work somewhere with a legal requirement to encrypt mobile devices, and they were about to lose the sale because of it.

It's quite possible I'd only have found out about that months or years down the road if I wasn't needing to use and encrypt those computers immediately.

Samsung's spying smart TVs don't encrypt voice recordings sent over the internet – new claim

Lee D Silver badge

Re: Dumb, dumb, dumb

I don't get why a TV needs to be smart. My Samsung TV is deliberately dumb - purchased in the height of the flat-screen/smart TV fad to go on the wall of my new house at the time, I fought to get a dumb TV without all the junk.

In fact, half of the dumb features, I don't even use. Give me a TV with power, ten HDMI sockets and a remote to switch between them and change the volume and that's me done on the display front. I just don't need anything else in a TV.

What I connect it TO is another matter, and at least that gives me a choice of devices, and I can pick a suitably dumb device at will. As such, I have connected to my TV:

- a DVB-S box that has no network connection

- a Blu-Ray/DVD player that has no network connection (I'm told some of my Blu-Ray can go online, update, show content from the web etc... why the hell would I want that?)

- a cable box that has a network connection but only because you can't do cable without it (red-button, etc.) and it's part of the cable installation (it gets iPlayer, VoD, etc. over the coaxial cable with an in-built cable modem so I can't really stop that).

- I have a Freeview box but the TV has Freeview built-in and I've never watched either, so I don't bother with the box.

- A Wii that has no network connection.

- A spare HDMI lead to connect a laptop or whatever device a guest might bring.

- A dumb, £5 HDMI switch to connect all of the above as I power a new device up.

None of them can do anything other than what's required for their job, and all of them are replaceable in a heart-beat if I suspect foul play. And many of their functionalities are duplicated among the devices - I can supposedly do iPlayer, YouTube, Skype etc. on the DVD player, the cable box, the Wii and the laptop. So I'm sure I can use the one that's most convenient and least privacy-destroying if I ever wanted to do that (iPlayer, possibly, but YouTube or Skype? Skype on a TV must be like having a conference call while your family are trying to have dinner).

The TV should be dumb. Put the smarts into your content devices, if that's what's required, and keep the TV dumb. There's no need for it, and it can - as demonstrated here - cause problems.

The TV is JUST a display device. The Blu-Ray player JUST takes a disc and outputs the video and audio. I call it the UNIX philosophy, as applied to my home appliances. One thing does one job, and does that job well.

Lee D Silver badge

Re: Only Samsung?

I'd be quite impressed if my Samsung TV was doing that. It's not plugged into the network. Not that that would stop COLLECTION, but certainly DISTRIBUTION of my private information.

There is a reason my systems have mics on mute, not connected unless they need to be, voice recognition is switched off wherever I go, etc.

The question really is: How long before some police force subpoena's Samsung for what suspected criminal X might have said in front of their TV?

You know when you all loved Siri, and "OK Google", etc.? Yeah, I was cringing even then. I'm by no means a conspiracy theorist, but just a computer scientist grounded in reality - if you give an app permission to record voice and transmit to the cloud, then you're giving it permission to record your voice and transmit to the cloud. Sure, it's "only so it can translate while I'm abroad" or whatever. But I bet you don't turn it off, revoke permissions or uninstall once you're done with that single legitimate use.

Least privilege principle, people. And your TV really doesn't need the capability to record the sounds of your living room 24/7 and upload them live to a cloud provider.

Canuck Bitcoin exchange gives up after security SNAFU

Lee D Silver badge

The insecurity isn't in the design of Bitcoin. It's people passing their Bitcoin to a third-party wallet which holds it in trust and provides equivalent currency in, say, dollars or Euros. It's like giving your cash to a bank without a vault or security on the doors. The cash works just fine (or else the criminals wouldn't want it)... but if you're giving it to third-parties to hold who are unable to secure it and unable to have sufficient funds or insurance available to cover any potential loss, that's a risk.

Your own Bitcoin wallet, that's forever and secure for as long as you keep it secure. Putting those coins into a foreign wallet is an act of trust in that third party and numerous incidents have proven this to be quite a bad idea.

The places hosting these exchanges aren't secure, aren't audited properly, don't have intrusion detection, prevention, insurance against those kinds of intrusions (which would almost certainly demand security procedures and audits as a condition of insurance), etc. Banks are legally required to do that, and hold a certain amount of funds in trust in case of problems, and all sorts of other regulations. BitCoin exchanges don't, maybe the cash-side of their businesses but their BitCoin sides don't.

And that's the problem. Bitcoin are valuable, but the risk is in the exchange for other things of value. As soon as you try to cash them out, you are in the hands of a third-party who has to take your Bitcoin and give you something tangible or cash in return.

Vodafone didn't have a £6bn tax bill. Sort yourselves out, Lefties

Lee D Silver badge

Have said all along: If they are doing nothing "wrong" in the eyes of the law, HMRC, etc. then it means that the taxation system is broken, not the companies.

You can't rely on companies to do the "moral thing". That's not in their remit. They have a legally prescribed duty to their shareholders only. If their shareholders would rather have more more from shares than more customers from doing the "moral right", that's what happens. Hate it as much as you like, that's what things say. Go set up a company and you'll see that.

As such, if we can't rely on companies to pay tax out of morality, you have to have laws that make them pay tax out of legal compliance. If the laws don't say that, or aren't enforced, then that's the bigger problem. We can't even MAKE them pay this tax, in a court of law.

So the companies involved are doing what's in their shareholder's best interests (there's a kind-of argument about the moral high ground being better for business, but that doesn't necessarily hold and isn't so obvious or clear-cut as to bind their hands), they aren't breaking the law, and they're still paying no taxes on a multi-million pound income.

That's the problem - that it's possible, without breaking the law, to do so. That stinks of a taxation system so full of holes that you're losing tax hand over fist and there's nothing you can do about it except change the taxation system. And that takes years precisely because a lot of these kinds of companies will flee or become unprofitable in those circumstances and that greatly affects political support (which, let's be honest, is purchased these days - one way or another - either through loss of business, loss of jobs, or just sheer back-handers).

Starbacks et al found a loophole which they are able to exploit without comeback from the legal authorities. That's what needs to be fixed. Punishing Starbacks etc. specifically doesn't solve the problem, doesn't stop the untold number of other companies that aren't as famous doing the exact same thing, doesn't get your tax back. Changing the taxation law... does.

It's like never watching TV live and then people saying that you're not paying your fair share of the TV Licence. You aren't obliged to. You never have been able to. You COULD be made to, but that would involve a change in the law. You are doing nothing "wrong" in the eyes of the law, even if you are freeloading at other's expense. But you don't get dragged through the world's press for doing that.

I think Starbucks et al probably shouldn't have this kind of arrangement. I don't think they should be able to have millions of pounds of INCOME (profit or not) from UK customers and not pay at least a single-digit percentage of tax on it every year to the UK taxation system. But that's not what the law says in this case. So although they can be dragged over the coals of the media and get a bad image, nobody can force them to pay that "missing" tax because it's simply not due.

And that, my friends, is because of over-paid politicians of every party crafting tax laws that can be taken advantage of (deliberately or accidentally). Who should be paying the missing billions? Those guys.

Are you ready to ditch the switchboard and move to IP telephony?

Lee D Silver badge

Re: My personal opinion...

Power loss - stick a UPS on, but otherwise - yes, a problem.

But Internet loss? Anyone with a large enough phone deployment will have a leased line. Chances are that your leased line has greater guarantees than any analogue or ISDN that you can get hold on.

I work in schools - they are, almost without exception, going VoIP internally and moving to SIP for the external calls. You can also include it in disaster recovery plans - school burned to the ground? We can set up a new school inside another site and just get an IP connection and we're back in business on the same phone numbers - taking parents calls and organising whatever is required.

IP phones are so much simpler to manage, deploy, update, expand, etc. that analogue and digital tend not to get a look-in once they're deployed. You can pay some guy to extend some manky old copper out to the new outbuildings, or you can just use the data cable you had to put there anyway. Worst that happens is that you have to VLAN it off and that's a one-off (though I have worked in many schools where voice and data share the switches quite happily, too).

Need more phones? Buy them, slap in the licence (hate it, but that's the cost of those kinds of systems), assign the number, done. Need to change your call carrier? Users don't even notice. Need to move everything off-site? Done. Need to integrate with old lines? No problem. Need users to be able to dial in via softphone? Already in place.

There's not much that old phones have over VoIP, and you can do it completely piecemeal so it's even better. However, I spent a long-time trying to find affordable cordless IP phones that use normal wireless with our manufacturer (Mitel) - they claim to sell them but can't get hold of them for love nor money. At other places I've worked, Cisco wireless phones like that are throughout the site. People forget they rely on the IP network.

If you're going to kit out a fresh building, do one deployment - Cat6. Put your phones on it, even if you have to PoE-inject them individually. Then move to PoE switches. Then put your wireless on PoE. Then put your phones on PoE and even on the wireless too. Then make sure the single system is battery-backed enough for an emergency (which isn't that hard or expensive for the PoE power range for an hour or more). Going to out-last that and need to stay up? Move it off-site without a single customer / member of staff ever knowing.

Sorry, but old-fashioned phones are dead. The only place I see them is the one in the IT Offices "just in case".

Your hard drives were riddled with NSA spyware for years

Lee D Silver badge

Re: Wait

Sure, so we should all give up and just email our passwords to the NSA / GCHQ, then?

No. Sorry. If the hard drive could be malware, then basic system security and encryption would have prevented it BEFORE we even knew about this attack. So enforce security or stop using hard drives. Same all the way to the metal in every case. Hell, you can use another motherboard/processor, but access to that kind of size of data storage isn't something that's available in every electronics hobbyist shed so you may be forced into using them.

However, biggest thing would probably be - WATCH YOUR CONNECTIONS, because the only sensible way to control these things and have them talk back is to be on the net. And if someone is implanting Win32 malware into drive firmware, then you need to start watching what's going on in your supply chain - particularly because it means you're putting bog-standard Windows machines in areas that you shouldn't be.

This is not "you can stop everyone getting in, ever", it's basic security. I'm sorry but it's embarrassing for you if your nuclear power plant is running on general purpose x86 hardware that loads from SATA and doesn't bother to check integrity of bootloaders, it really is. And it's laughable that NSA etc. are bothering to attack such open machines in so blatant - and recordable - a fashion.

Secure your important stuff as if... well as if were important that others didn't get into it.

Lee D Silver badge

Re: Wait

Likely it doesn't "force" anything. It probably intercepts calls to well-known Windows boot files and replaces them with it's own version. Might be behind a blue-screen or two but then you'd realise when you bin the drive it fixes itself (however, by then, the malware is likely inside your core Windows images and backups).

But, yes, you have to start somewhere - you can't make a any-platform malware that'll work for everything, so you likely just write for your most likely target.

More importantly, this will stop source-code access to such things and/or stop foreign entities trusting anything made in the US. And likely they aren't the first. There's never been anything stopping a hard disk firmware literally KNOWING when you are accessing, say, the Windows boot process files and slipping in its own data. It could even interpret the NTFS, check filenames, boot sectors, etc. on-the-fly.

Except... surely... if you're encrypting everything that goes to disk, even the OS (which is the only secure way to encrypt)... this is useless? The hard disk won't be party to the key (because the read sectors will be encrypted data or an encrypted key which is only unlocked in RAM by the user's entered key?), and will never spot that the data going through it is ripe for insertion, nor have the ability to do so undetected.

The only chance to infect is initial boot and, well, wouldn't TPM and/or privately signed bootloaders stop that in its tracks? Again, anyone SERIOUS about not wanting the NSA et al inside their machine (e.g. Iranian nuclear plants, Chinese military, etc.) could probably just encrypt and enforce basic security and they're done?

Sorry, but these are attacks against bog-standard mainstream PC's with no security. Anyone with a brain shouldn't be storing anything of interest in there.

Windows 10 to give passwords the finger and dangle dongles

Lee D Silver badge

The fingerprint is your username, not the password.

You can tell everyone on the Internet your username if you like (most forums do), but that does not provide them access. The fingerprint is "this is who I am", and the password is "this is the secret to prove it". Anyone selling anything else DOES NOT UNDERSTAND biometrics. You cannot have a secret fingerprint any more than you can have a public password.

And fingerprints aren't unique*, because they aren't static, because they can be modified by simple actions, because they can actually be virtually identical from the start, and because of the reader sampling problem you describe, and thus can produce "flux" enough between two individuals that they are impossible to tell apart by fingerprint alone. Court cases rest not on "you are unique" but "you fit the pattern that only 1 in so-many people would have and you were also confirmed to be nearby".

[[ (*) Fingerprint uniqueness rests in the "every snowflake is different" area. Because there are a number of random variations, almost every fingerprint will differ from another. But because there are such a huge number of variations, uniqueness isn't guaranteed, merely suggested. And your own fingerprints are different on different fingers. It's this "pattern" that gives the random chance of someone leaving the same fingerprints - in the same order - at the crime scene billions-to-one odds. But there's no guarantee of uniqueness, and in terms of authentication they suck because you don't know if you're sampling the unique bits or not. ]]

The other problem is how easy it is to fake - there's no point them being "unique" if I can make a copy in ten seconds. The last fingerprint reader I used was a tiny 100dpi scanner with a rubberised surface. The surface was supposed to "splay out" your fingerprint, and the scanner merely scanned as any ordinary scanner does (they are mostly webcams etc. now). I got some Linux software and proved it by scanning in a document with it in 1 inch strips. Literally, printing the output of scanning my thumb and then putting it in front of the reader was enough to validate me forever after with a piece of paper. Similar tricks have been used on almost any amount of security measures since put in place in your average fingerprint reader. This is why banks, for example, DO NOT USE fingerprints on your credit cards, etc. They may be daft, but they're not stupid.

Something you have (fingers!), something you know. Otherwise it's not security, it's just convenience of not having to type in your username.

FOCUS! 7680 x 4320 notebook and fondleslab screens are coming

Lee D Silver badge

Re: An 8K fondleslab?

Very, very, very tiny writing that you have to then zoom back to bigger sizes in order to be able to read.

Linux kernel set to get live patching in release 3.20

Lee D Silver badge

@Anon Re: Useless...

"Windows stops IIS for every .Net update for each version"

And Apache stops every time you update in-built PHP modules. This isn't really much of a problem, the problem is that a simple .NET patch is often 200Mb of MSI's that trawl through all your .NET assemblies before they'll do anything, then change a handful of files, while writing at 30MB/s for 10-15 minutes sometimes (note: Actual figures in front of me as I update a server!)

And Linux updates to Apache DO stop Apache. They have to, or you'll still be running the old version - even if the underlying files are (sometimes) updateable without having to stop Apache to update them. Until you restart the service, you'll still be on the old version. Same for SSH, email servers, etc. on Linux. This isn't an argument.

As far as I can tell, Linux updates are done in series too. Otherwise dependencies are a nightmare to resolve properly. However, application updates do not require a reboot, that's the advantage. And a fresh Linux install from the stable ISO can easily take an hour or more to update to the latest version and slipstreaming isn't something that the average Linux sysadmin would do (though it may be easier to do so, I don't know).

Lee D Silver badge

Re: Useless...

If you genuinely believe that anyone with brains ever claimed that Linux never needed a reboot, you're really as bad as the people who claimed it. Every kernel update, unless you wanted to use the early kernel trampoline patches or these patch's predecessor, required a reboot.

However, that said, how many reboots are needed to do simple things like patch office suites, do the initial install, etc? I'd say "less", not none. Windows reboots, is it three times? on every deployment of it that I push out to my network. It seems to be unavoidable after sysprepping. But I can roll out a Linux deployment with a single reboot (i.e. the one to get into Linux from whatever deployment tool I've used).

And now how many reboots do Linux installs need if we have official live patching - something that MS just doesn't offer in their software? That's the point.

Nobody sensible has ever claimed that you don't need to reboot Linux. But it's been disgustingly easy to get 400+ day uptime for years, long before the MS offerings stabilised, if you're that way inclined (Why would you do that? It means 400 days of no kernel update!). However, now, even a kernel update doesn't necessitate a reboot.

However you argue it, I have a few dozen more updates today as part of Microsoft patch Tuesday, which is going to necessitate rebooting every computer, including servers, on-site at least once. However, the VM's I have of Linux-based stuff only reboot when I decide they need a kernel update at the moment, which because they are internal, non-critical and non-privileged, is rare.

UK boffins DOUBLE distance of fiber data: London to New York WITHOUT a repeater

Lee D Silver badge

Re: Testing

When you buy fibre, does it come as an 80km long parcel?

No, it comes wrapped up in a coil.

Put coil on floor. Grab both ends. Plug into your equipment half-inch away from each other. Voila! Test circuit.

Hence why a lot of these kinds of things don't work (or are severely reduced) once they are deployed in the real world.

That said, it's an interesting technique and if you think of the amount of SFP in the average business, getting the same speed over twice the distance may eventually equate to twice the speed over the same distance. This is the sort of stuff that ends up being in 100Gb protocols and you never know about it.

Turing notes found warming Bletchley Park's leaky ceilings

Lee D Silver badge

Re: Don't go to see The Imitation Game...

Queen Victoria would say the same thing of Mrs Brown.

George VI would say the same thing of The King's Speech.

Tolkien would say the same thing of Lord of The Rings.

Hell, the Mary Poppins author HATES the movie.

It's a movie. It will not be accurate. Ever.

However, it's a great blast for this Turing fan to be in a "Turing-like" historical environment for a couple of hours. And, hell, it's not bad enough to condemn it by any means. I mean, sure, I'd kick Keira Knightley into shape a bit for her performance but other than that, the bits I'd want to add/remove/change would just turn the film into a documentary (and a boring one at that).

(P.S. Studied Computer Science and Mathematics at university, with particular emphasis on Coding Theory, etc. and work in the industry created by those people... I'd be the first to lump onto it if it was actually U-571 bad, as opposed to just a Hollywoodisation).

Lee D Silver badge

16 Comments

And nobody has spotted that the wiki link is broken (extra "z" on the end)?

RM has been schooled: Sales fell by over £69m in fiscal 2014

Lee D Silver badge

Re: Sassoon Font

Font licences are no different to anything else.

Just because you can download it for free doesn't mean it's licensed.

Lee D Silver badge

Re: Hardly surprising

I've spent a good portion of my career as an independent IT guy (I hate the word consultant) going into schools, removing the RM-specific stuff and giving them a group-policy equivalent that's easier to manage and MUCH cheaper. The dirty sods even do things like license a particular font that they put into butchered-versions of MS Word (that talk to you and all sorts of stuff) so when you move on, you either have to pay a fortune for a licence for the font or change all your old documents (and, sorry, but the font is horrid - but teachers love it for reasons I cannot fathom).

CC4 was the death-knell for me. I spent more time pulling schools from it than I ever spent managing it and the timing coincided with me going to full-time stable work in the same sector. I once took down an ENTIRE school network, clients and servers, by deploying an "CC4 package" (a msi with particular paths for particular things) with a space in the filename. I kid you not. No warnings, nothing. They updated the software to stop that happening eventually but that just shouldn't even be possible.

I went full-time for a school that I'd helped abandon RM (first formatting the RM kit and servers to re-use them as proper plain Windows - the speed up was so immense it was embarassing, and zero lost functionality - and then to new / extra servers clients with the money saved over the course of the year, even with my wages). From there, I moved further through primary, secondary, state and independent and ended up where I am now - in a school that stated in interview that they hated RM and would never touch their stuff again. Not the first school I'd heard that, by a long shot.

That RM was losing money on that hardware - well, that was just schools waking up to the fact that they were selling cheap junk for overbloated prices. The official RM support stories I have could turn your mind to jelly. They knew the capacitors suffered rot on a particular model of motherboard. Their solution? Issue you with a network card (the first thing to blow was the on-board networking). When the problem crept to the USB, they gave you a USB PCI card. Then a PCI graphics card. And only THEN did they tell you to scrap the machine because the caps were going to blow the machine up. Their engineers knew the sequence off by heart, they'd dealt with it so much on that model and would have the next card ready for you. Rather than REPLACE the damn motherboard.

Their software and online services are their only saving grace (didn't they buy Ranger years ago?), but even there they're being pushed out of the market. The one piece of software of theirs that I love (as a mathematician) is RM Maths. As an IT guy, I hate it.

I also have had PC's shipped direct from RM with no motherboard jumpers (just beep-beep-beep on turn-on, and not even rattling around inside the case, literally not present at all). One school had sent back three PC's repeatedly over the course of a year and still weren't working. On a pseudo-interview to work for them, I spotted them and asked about them. They have been verifiably back to RM several times for "repair" and each time came back broken. I asked if I could take a look. Turned it on. "CMOS Checksum Error". I kid you not. Sent one of the teachers to the local shop for a pack of CR2025's, those three PC's worked flawlessly (as possible for RM stuff) for four years. I literally got offered the job on the spot.

Let's not even mention the Borough-lock-in that they negotiate so that entire swathes of schools are told they can ONLY be supported on RM equipment and nothing else. Didn't stop me making a career from taking on those schools not willing to play ball with such monopolisation, in fact it just made me more popular.

But RM? Total shower.

(Offtopic: I was talking to a guy the other day who designed the RM Nimbus and, as part of that, the M in the RM logo. Interesting guy, but even he was so disillusioned with RM that he mocked them even though they had paid his pension long ago and he is now making a nice career selling 3D printers to schools and lecturing at a university while the RM pension keeps him in funny hats).

Wheeee! BT preps for FIVE HUNDRED MEGABIT broadband trial

Lee D Silver badge

I work for a school.

BT took nearly TWO YEARS to get a leased line to us. They were blocked from completion after we cancelled the contract because they said there was a 20th delay because "there's not enough room in the duct" followed by "there's not enough room at the exchange". You'd have thought someone might notice in two years that you had no room, eh?

We cancelled because, despite wonderful promises, prices and speeds, we never actually managed to get the line into the building.

Now I have the opposite problem. We went with Virgin for their leased line, and they are chewing at the bit trying to get the install finished while the local county council "umms and arrs" about the plan that they've already said they approve of and won't block.

In the meantime, I'm running a school for 400 kids on a VDSL line with ADSL backup which BT promise me can get "45Mbps" and "20Mbps" at best, respectively. Funny. Because my Smoothwall says we've never pushed more than 10Mbps for a fraction of a second and the average over the working day - with 500 users and 600 devices - is somewhere around 4MBps down and 1MBps up..

BT can make all the "maximum" speed promises they want. If you can't get it installed, or the actual download is so much less than the maximum, it's pointless. Absolutely pointless.

Ironically, I get 32Mbps download on 4G when sitting in the IT Office. If only 4G didn't have such pathetic data allowances.

Microsoft Outlook comes to Android, iOS: MS email now a bit less painful on mobile

Lee D Silver badge

No thanks.

In all those years it took you to get here, there's been a whole raft of products that do the same, and they wanted my money, gave me the features, "just work" and have done for years (decades) in some cases.

Exchange accounts are pretty standard on all Android phones and if you want deep integration then things like Touchdown, etc. only cost a few quid. Everything else, well, if you can't do IMAP and SMTP with your email, it's not really an email account.

I can't imagine many people CHOOSE Outlook because its workflow is so much better than all the competition. They choose it because their workplace is Exchange and they want to integrate with it. I've survived all my IT career without Outlook on my desktop, yet I still have every email I've ever sent or received, and I can schedule things on calendars, answer votes, attend meetings, etc. alongside everything else on any platform, at any time.

The time to open this sort of thing up and start providing Office, Outlook, IE (yuck!), etc. on other platforms was about the time you got sued for anti-competitive behaviour in the EU. But at the time, you were too busy turning off my Hotmail so I couldn't collect it with POP3 any more and stuff like that.

How's this for customer service: Comcast calls bloke an A**HOLE – and even puts it in print

Lee D Silver badge

Retention agents? I don't even talk to them.

My favourite phrase "I just have to ask you these questions, sir, before I can do X".

No. You don't. You just don't want me to say no without getting bored of your rhetoric first. At that point of the phone call, I generally just say "Sorry, no, no, no, no, no, not interested. You know who I am, you know what I'm requesting, I consider this conversation over, this is your notification of termination."

And there's a reason that I record my calls of complaint, and keep all letters of any import for a long time. Last year I had a car insurance company cancel my car insurance (retroactively, according to the postmark!) for non-payment when they never had any record of attempting to take payment whatsoever. They claimed there was a warning letter, but couldn't produce copies. They claimed they sent it out on X date. But a letter dated 2 days later was the only letter I ever received and it quite clearly stated that "No further payment is necessary" at that point and had no mention of any sort of cancellation. They then claimed the bank had refused the charge, which was news to my bank.

They eventually threatened court. I offered to initiate the action for them. After much back and forth where every claim in their letters was refuted with cast-iron physical proof in the letters I'd been given (many of which they had no copies of!) and an offer of a copy of the recordings I had where the woman on the phone TOLD me all these things and said it was a mistake, they offered me £50 "compensation". Given that they'd cost me much more than that already, I told them I'd be using it to initiate a small claims court case. Eventually got them moving when they realised that the court would quite literally tear them to pieces for not having any of the documentation that *I* had, and having their customer service reps admit that.

Luckily, by the time their investigation was completed (where they realised they had no copies of the letters I had been sent), it was many months later but I still had all the letters since the previous year. So I was able to refute every claim with their own paperwork. I kept hold of the postmarked envelope, even, in one case.

Sorry, but some companies you just can't trust and you won't know that until you try to complain or cancel. Invest in a device that can record phone calls with one press. And keep your old bills etc. for a year or so. It doesn't hurt at all, and it can make this sort of stuff go away.

"I've been put through to you, a company representative, after proving who I am, and now I'm telling you that I'm cancelling." That's it. That's the notification you need. If you want, I'll put it in writing instead and give you even less chance of backing out. That's the end of the matter. This WAS your notification. Goodbye.

Opera Jon weaves a brand new browser

Lee D Silver badge

Re: Tab handling makes it almost unusable

The old Opera "what's the next tab" choice is in there.

The Ctrl-Click trick works (but middle-click used to do the same thing in Opera and I find that easier - will have to check their hotkey preferences and see if I can make it do that).

Lee D Silver badge

Re: no 32-bit download? :(

How old is your computer to not support 64-bit? The CPU's have been around since 2003 in the x86 world, the last two three Microsoft OS have had 64-bit versions (and so did XP but it was poorly supported), the last server OS is 64-bit ONLY, etc.

I get that you might have a 32-bit OS legacy that you're carrying forward, but the underlying hardware should support 64-bit on anything that's still viable to use on the modern web.

And I don't think it'll be long before a 32-bit version appears but, really, you might consider it a first shot at moving to 64-bit systems. Hell, 4Gb RAM is my minimum spec nowadays, and I work in schools who don't need anything past Word and a browser for the majority of the time.

Lee D Silver badge

There's not a wealth of options in it at the moment, but Ctrl-T tabs open on top of older tabs.

You can also change tab-cycle order for when you're keyboard navigating to be tab-order or recently-used order (which is INVALUABLE and one of the best bits of old Opera).

He's obviously aiming for a proper Opera clone on a Chromium rendering engine, and the tech preview shows that. There's Windows, Linux, Mac versions available and it allows import of a lot of data from Opera and other browsers (including Opera Notes, passwords, etc.). And it's fast at rendering.

I will continue to try it out, because just the tech demo is impressive enough to a Opera 12.x user that's been hanging on for dear life. Haven't yet found a site it can't render (Acid 3 test is 100/100) but I expect that if they are using other's rendering engines. Opera's rendered used to be the selling point for many years, but now it's actually replaceable and it's the options / setup / configuration that matters and they appear to be working heavily in the Opera direction (e.g. side-panels, etc. are almost the same).

Only thing that's annoying - the window colour changes with the CSS in the tab you have open. I don't WANT a yellow tab bar when I'm viewing some garish site. But I'm sure they'll sort that out or "option it" soon.

Lee D Silver badge

Sold.

Jon, I'll pay what you were charging for the old Opera browsers of yore for it.

So long as it is as promised - customisable, practical to browse the modern web with AND has the email client built-in.

I've been waiting for the open-source Opera clone to take off, and it's not there yet.

People who don't use Opera don't understand Opera and it's power. You could do ALL the things that they've been plugging in add-ins to do for the last few years MANY years ago, as part of the standard browser. Just because normal users didn't know of, or use them, doesn't mean they aren't valuable to the people who do.

Honestly, will gladly pay if it's as advertised, which is pretty much where Opera began many years ago.

'Linus Torvalds is UNFIT for the WORKPLACE!' And you've given the world what, exactly?

Lee D Silver badge

Re: How bad is Torvalds?

Please hand back all your TomToms and other satnav devices.

All your CCTV DVR's.

Most of your wireless ADSL routers, etc.

Anything with Android written on it anywhere, smartphone or tablet - currently outselling Windows phones by ENORMOUS ratios and even iPhones but people don't like you knowing that.

Most of the in-house networking gear in your workplace that's not purely switching stuff (e.g. Smoothwall boxes, content filters, WatchGuard firewalls, etc.)

All your Raspberry Pi's.

Most of the world's webservers, cloud servers, etc.

Almost all your "smart" devices like GPS trackers, fitness watches, ANPR, etc.

You don't want Linux on your desktop? Fine, but vast amounts of the world collapse without it, and it's actually running your ISP, almost certainly running your webhost, etc. Sure, there are alternatives that you could use instead but that's hardly the point.

This is like saying that Rayleigh have cornered the push-bike market, but Rolls Royce are a disaster because despite being in (and world leaders of) the automobile market, the aircraft market, the shipping market, generator markets, etc. they don't have a Rolls Royce bike that's as popular as Rayleigh.

Eurovision tellybods: Yes, you heard right – net neutrality

Lee D Silver badge

"Quick, there's something in it for us now, let's stop being against it for a microsecond until we get our way, then we can forget all about it forever after."

You weren't interested five years ago, then it means that - on balance - you probably won't be interested in five more years.

Project Kangaroo died, you can't force people to pay for your channels individually online, the ISP's won't let you provide your own bias to their content provisions, large content providers like Netflix mean you're either "in" or "out", so you come out for net neutrality now to make sure none of your rivals can do the above successfully after your failed attempts. And then when one of them does anyway, you'll all be vying for your own version of lock-in and bias because THEN you'll be able to get away with it.

It's pretty simple. I don't care who you are. I don't care how you want to sell your stuff. If you have content that's interesting, I want to pick it up wherever I am, whatever I'm doing, whatever device I'm using, whatever ISP I happen to be on, whatever mate's house I'm around. Understand that and you find the value is in your content, not what platform you appear "exclusively" on, or what ISP will agree to bump up your speeds just because you pay them more. What matters is your content, not what bandwagon happens to be heading your way at the moment.

The last ten years should have shown you this. 4od basically give all their content, even historical, away online for nothing. BBC iPlayer only has a time/region restriction because of the way the corporation is forced to operate and that gets recorded/proxied to death even so. Netflix et al are making a viable business just providing your content in a sensible online format. And now places like Amazon are muscling into PRODUCTION, not just distribution.

But some of you fought it all the way to make it as difficult as possible to get your content in reasonable formats and reasonable ways. And now suddenly you want pan-Europe rules to make sure none of your competitors can best you? Maybe if you'd been listening and properly competing on what matters in the first place, they'd be USING THOSE RULES against you instead now.

I don't care who you are. Provide the content I want, for a fair price, without any restrictions (or pseudo-restrictions by giving "advantage" to others). And provide it everywhere - satellite, terrestrial, cable, online, etc. all at the same time.

Sell me content. Just content. Because I'm not interested in "your" preferred ISP, etc. I use Internet companies for my ISP and I use content companies to watch on TV. I use TV companies to sell me a TV in the first place, too. Stick to what your business is supposed to be, and there won't *be* any issues. Try to make your content exclusive or your competitors be at a disadvantage and your lose my content revenue AND I'll change ISP to one that doesn't bias itself. It's not hard.

Alan Turing's lost notebook goes under the hammer

Lee D Silver badge

Re: Glad to see Turing had problems with notation!

Notation is everything but one notation for everything isn't the best idea. The idea of notation is that in some cases it's better and in others it's worse but merely CHANGING the notation you use between the two instantly makes a certain class of problems easier.

Think about chess games. You notate in classic co-ordinate systems, but that's no good if you want to record the board position itself (as you have to replay all the moves). So we have Forsyth notation to note the board position. But even in game-record notations, sometimes it's easier and more sensible to talk about particular ranks and to do so from the viewpoint of each player, hence we get into descriptive notation, but for beginners they probably are more comfortable with algebraic, both of which are really just a simplification of much more long-winded notation which notates every square moved from even when it's unnecessary.

But computers have their own notation for games, and there's even odd things like chess notations that side-stepped censorship on coded messages sent through the post office during certain wars, etc.

A different notation of EXACTLY the same problem can make it trivial to solve. But no one notation can do that for ALL problems. This is true of all mathematics, where merely using the notation of a different branch of mathematics to describe the same problem can provide links that nobody ever thought of between the two and make solving complex problems trivial. This is pretty much where a lot of the "universal theory" mathematics is heading towards at the moment, for instance.

Lee D Silver badge

Re: "The Imitation Game"

"True story" movies are boring. It's as simple as that.

Hence why every "True story" is "based on", not "this is what actually happened".

You have to go into movies KNOWING this. U-571, however, is a different class of tosh. Imitation Game is merely embellishment and "artistic licence" with the story so that grannies aren't saying "That was boring, what the hell was going on" for everything.

NEVER watch a movie expecting historical re-enactments. You won't get them. Ever. You think Mrs Brown was accurate? Or The Iron Lady? Or Made in Dagenham? Or The Queen? Or The King's Speech? No. Never. Not even close, any of them.

What you can get, having seen the movie, is a fun run-around in a Turing-like world. A homage to the man. Something embellished and polished but fun and interesting and insightful and true to the SPIRIT if not the word of the law. I'm a massive Turing fan. Sorry, I'm a mathematician and, from there, a computer scientist. I'm a programmer. I'm a computer theorist. I'm into coding theory and cryptography. I couldn't help but be anything else. I do not go to watch movies in cinema. I did for this. It was great fun, close enough and good enough that I can point out the problems (and that's half the fun of knowing the subject truly, like half the fun of knowing The Silmarillion and LOTR inside out is pointing out the bad bits of those movies) but my girlfriend can enjoy the movie as much as I do, and we can get some kids in the cinema going "Oh, cool, I never knew about this guy but this looks interesting".

You want factual representations? There is NO VENUE for them whatsoever. Even the "science" channels on TV are a load of tosh, the Royal Institution Christmas Lectures nothing more than QI without the questions, etc. YOU WILL NOT GET IT.

But you can enjoy a good movie that you can poke holes in as an expert in the subject, if you like.

Video nasty: Two big bugs in VLC media player's core library

Lee D Silver badge

Re: FFS

I find that a bit quick, for disclosure.

To think that MS were whining about 90 days +!

And the fix is in the developer version, according to the article.

Sorry, but if you did that to a commercial project, they'd tear your arms off and beat you to death with the soggy end.

But two weeks is barely adequate to test a fix.

Buggy? Angry? LET IT ALL OUT says Linus Torvalds

Lee D Silver badge

If someone, anyone, a security researcher or some kid downloading something from the Internet, is able to tweak a setting and compromise a system... it DOES NOT MATTER the origin of that information. There are entire markets with 0-day flaws, there are flaws floating about IRC channels and Usenet, there are pre-built hacking tools just ready to download and craft your own version of any particular exploit.

The fix is not to pretend the flaw doesn't exist, couldn't be found by someone else, etc. It's to patch it. As soon as you can. As well as you can. Rather than bury your head in the sand.

And "testing" some of those patches is almost not necessary - the fixes are so simple as to be auditable quite quickly and only in very isolated components that serve one particular task.

Take the OpenSSL flaws. Some of those were hinted at and reported. When I looked through the OpenSSL code, it was a mess, but anyone with time on their hands and reason to do so could have found those flaws YEARS ago and kept a lid on it all that time. The fix is not to then go into a 90-day hiatus and eke out every second of non-disclosure. It's to fix the problem ASAP. For 90 days, someone in Google, probably several people, has KNOWN of that flaw. It's been in a database that probably dozens of people had access to. Any compromise at Google would have given someone a 90-day window of flaw execution. Why is it that people "don't trust Google" for years but all of a sudden they expect them to hold onto such a flaw perfectly and never reveal it.

It's a flaw. Someone knows about it. Fix it. Whether that someone is your own security team, a security researcher (of course, they are ALL trustworthy and would never sell their skills on the black market on the side....), or some kid on the Internet. Fix the damn problem.

You'll get sick of that iPad. And guess who'll be waiting? Big daddy Linux...

Lee D Silver badge

Re: Lee D Laptop/convertible+smart phone

In my experience, places that care about support aren't using Microsoft for it. They are using a myriad of technicians, consultants and specialists.

Sure, it may be more difficult to find Linux tech support, but you wouldn't necessarily be looking to the companies themselves.

When was the last time you called Microsoft? In 15 years of MS support, I've ever only done it to resolve licensing issues. When I have an error, the chances are the first 20 hits are random websites, not the MS KB. And the MS KB will likely be outdated, incomplete, have no real solution, or be referring to something else entirely.

Support, in general, doesn't come from the manufacturers. If your business is big enough to hire an IT guy, the IT guy is your support. The number of times he has to fall back to talking to Microsoft, or Red Hat, or whoever is going to be few. And there, I'll find he'll gain much better support from the Linux side than the Microsoft side.

Hiring in-house support for Linux may be more tricky. But past that, places not big enough to hire an IT guy don't really have enough IT to worry about (and will never hear of Linux anyway).

Lee D Silver badge

There are issues in these areas, certainly.

But similar issues also plague "new" Windows. I admin Windows networks and the amount of things you have to drop into the shell for are amazing. Activating Windows / Office on a network? VBS scripts run on the command line. Deleting an email from networked Exchange inboxes? Powershell commands. Have you seen what you have to do to get the Windows 8 "user logo" to be their photo from Active Directory? Logon script, basically, that downloads from AD, resizes to various sizes, sticks it in a certain folder on the local machines, and has to be rerun on every logon in case they changed their photo.

99% of users don't use that stuff and 99% of users of Linux wouldn't need to either. You can install software from the GUI, you can create users, modify your network, all the stuff that's GUI on Windows is GUI on Linux too. The difference is that it's ALSO available in the CLI as well, which is no longer true of Windows.

And the issue is moot. With VM's, you have no idea what you're really running anyway. Linux or Windows is then nothing but a pretty interface to the real machine underneath. And with VMWare etc. it could be Windows, Linux or NO OS AT ALL underneath the VM.

P.S. Defaults on installing Server 2012? It wants to give you a CLI only. You have to SELECT the GUI option. The only way to run bare Hyper-V hypervisors that aren't Server 2012 themselves? CLI only - inside a normal Windows GUI that you can't use.

Lee D Silver badge

Re: Laptop/convertible+smart phone

I could work that way today, it's not really "future".

The holdback for years was Office (been a LibreOffice user since day one, it's more than good enough) and games. 1/3rd of my Steam library is on Linux now. If Windows were to go away tomorrow, I would barely notice, personally. It would mess up my workplace for a few months until we got the alternatives in, but at home, who cares?

I've invested more money into VMWare at home than I have Windows operating systems. And most of that was for development purposes. Though Linux can build and compile a Windows 32/64-bit app, you really have to test it ON Windows to get a feel for it working properly.

There will be no "year of the Linux desktop". Desktops are dead already. Year of the Linux hypervisor running a bunch of whatever you want is more likely. It won't be long before I'm recommending that people just run VM's in their daily lives. Imagine the hassles that grandma could avoid if you could just roll her back to yesterday's snapshot with one click?

For five years, I managed without Windows at home, while running Windows networks. It was Slackware (Ubuntu was around, but I like Slackware). Then I had an employer-laptop provided with Windows. It made little difference, I still ran the same software. (and, yes, often had to open stuff in LibreOffice that MS Office didn't stand a chance of opening - even MS Works!). Now, work-wise, everything is going cloud and web-based so it's even easier.

If I didn't already have a 7 Home Premium and 8 Pro install loaded on the machine at home, I'd probably not bother with it. Gimme remote desktop for work, a web browser that works on modern sites, a decent chunk of my Steam library, LibreOffice and Eclipse and I'm done. None of that is dependent on Windows any more.

When all my employer requirements include iPad and Android compatibility anyway (so everything is web-based even if the server that makes it so is on Windows), and everything on the server end is a VM, there's not much room for Windows itself except for convenience, familiarity and licensing.

Lee D Silver badge

Re: I'd try Linux mobile

Have not used the Samsung tablet much but have Samsung Android smartphones. Killing app is a rarity. Rebooting is unheard of (admittedly, a couple of times a year I forget to charge it, but that's probably WORSE as it's a hard-crash when it does that).

Not sure what you're doing differently, but I've not had that experience. With my old Galaxy Ace, yes, I ran out of space all the time. But that was because the space was so pitiful and things insisted on going on the internal RAM first even if you used apps to move them to SD later. And, yes, Facebook is one of the worst culprits - it seems to grow madly over time, requiring you to Clear Data and log back in. God knows what's it doing.

But I've deployed other Android tablets in schools and we don't have these problems either.

This Christmas, I went to my Italian girlfriend's family. At one point in the room there were three new Samsung tablets, four new Samsung phones, and whatever we had in our pockets (almost entirely Samsung). We were teaching people how to use some of them, but others had been using for years. I don't think we killed a single app or rebooted once, even with the kids taking over and installing every free app they could get their hands on.

As resident techy guy - even with a language barrier - I got called on for all sorts. But the tablets and phones never figured except to show people how to use them. I did have to fix two iPhones that had gone muppet, however. And nobody even had a Windows phone. Bear in mind that dozens and dozens of relatives and friends came and went over the period and they all know me as the techy guy who fixes things for them.

And, no, I've never rooted anything either. The biggest problems I've ever had with Android tablets were the cheap ones not coming with Play Store so I had to fudge an old APK onto them and then update.

Lloyds supplier payments TITSUP: What, you want money from a bank?

Lee D Silver badge

You can be sure, if that was the other way around, you'd have bailiffs and court representatives hounding you left, right and centre by now.

You're a bank. You know what needs paying. You press a button and it gets paid. Pay it from your contingencies while you fix the system. And if you're still paying TWO MONTH OLD invoices, then you're probably in breach of contract, technically, depending on what the invoice allowed for payment. Those people can easily come back in, take back their goods/services at any point, and still bill you for their hassle. Like YOU would if it were the other way around.

I understand a day, a week, of hassle. But it costs nothing above normal costs to get people to drop other tasks until you've paid your debts off, even if you have to do it manually and from some other fund for the moment.

At some point, we're going to have to treat banks like banks treat us. By now, in that situation, I'd be on nearly 1.5x the original debt with fees, hassles, etc, with a permanent credit history mark against my name, and I'd never get credit from those people again and they'd be demanding money up-front on all future projects.

There's a reason I avoid giving any bank a single penny more than I have to, or leaving a penny more in my current account (don't have a savings account, for them to play games with and then give me below-inflation increases back after several years of my not touching it) for a second longer than necessary.

Remember when I went a tenner over and you charged me £50 for the privilege? Let's multiply that up. The only way I could get my own back was to waste an hour of a bank manager's time (which probably costs about the same, I estimated) and then tell him why I'd done that. He said that it wasn't "very productive". I agreed entirely. Charging your customers five times their debt for a day "borrowing" £10 that they never asked to borrow (I'd have been happier for the payment to be refused!) is no more productive than me having to waste your time either.

Get coding or you'll bounce email from new dot-thing domains

Lee D Silver badge

I'm not going to go out of my way to accept these domains.

If Exchange / postfix / etc. don't support them in their latest stable version, and a couple of stable versions before that, I'll likely never see them in use anyway.

The way to deploy something like this is to be low-impact (punycode stuff isn't), backwards-compatible, and get the software working first before you start selling such domain names en-masse.

Chances are, most people who buy those domains will quickly discover that nothing works for them and nobody ever answers them, then stop using them. By the time the software does catch up, nobody will trust them (or their "fixed" replacements) anyway.

Honestly, I see no reason that punycoding something should affect existing email rules anyway. If it's just as simple as allowing hyphens in the domain name, that's a one-liner of a patch to the majority of email software out there and nothing else should really be affected. But unfortunately, it's just not that simple.

And, I've told you before, Reg. You can mention IPv6 when you put out an AAAA record for your own domain. Or did you not bother to write that into the spec for whoever did the new design / CMS for you?

Insert 'Skeleton Key', unlock Microsoft Active Directory. Simples – hackers

Lee D Silver badge

Re: domain controller is restarted

I agree completely.

The biggest problem is small IT shops where, actually, the DC is misused as not only the DC but also the primary file store, profile store, etc. Even if they have a secondary / tertiary DC, they can't just reboot them because they don't have adequate DFS setups etc. to cope with one server going down.

Hell, I've seen schools who have Exchange on the DC (which is a totally unsupported configuration) because they don't want to have lots of expensive servers running (Most of them haven't caught up with modern VM technology, either).

A lot of it comes from the legacy of 2000/2003 where a lot of functions couldn't be failed-over to other servers properly or easily (e.g. DHCP, DFS, etc.).

Also, because it's a "DC" it's seen as some mystical magical configuration that must never be rebooted even if you have a secondary.

Hopefully as we move forward into VM'd configurations, such a mindset will be phased out.

Lee D Silver badge

If your domain admin account gets malware on it, you have bigger issues than something hiding temporarily on the DC's.

Grand Theft Auto 1997: 'Sick, deluded and beneath contempt'

Lee D Silver badge

Re: I loved the top down GTA Games

I can remember playing multiplayer and my brother and I would see how many cars we could line up in a single screen and one of us would then rocket them while the other tried to "surf" over the cars as they exploded.

Sadly, the off-screen cars often disappeared quite quickly so it was tricky to get right.

However, I always loved that style of game, much more so than the first / third person 3D versions.

Also one of the first games to support 3DFX properly so you could run in some ludicrously high resolutions for the time.

Lee D Silver badge

Re: Memories

And a map, with that game.

Though, sadly, in-game tech has increased with outside-world tech and such games have sat-nav nowadays.

Windows 7 MARKED for DEATH by Microsoft as of NOW

Lee D Silver badge

Not really.

I deploy Classic Shell. It has the "Don't start in Metro" option turned on (again - GP-configurable with Classic Shell's GP settings). You boot, login, go to desktop without seeing Metro at all. Everything else is pretty much the same.

Press Windows key and it brings up the Start Menu. (However, sssshhhh, don't tell my users, press Shift+Windows and it brings up Metro!). Disable the sidebar etc. as much as you can and you'll never see anything Windows-8-y again. It just looks like Windows 7 that's been prettied up and locked down (e.g. the network interface taskbar icon looks a little different, Autoplay - if you have it enabled - looks a little Metro-y, etc.)

Rolled it out to 500 users who had had a VERY bad experience with a previous (botched) 8 deployment, and they were about ready to scream at the mention of 8. It was only afterwards when they then started coming to me saying "Does this work in our Windows 7?" that I told them what we had. They're not the most-observant of users (the techy ones spotted it obviously but also didn't care as they could see I'd toned it down), but I had more trouble from 32- / 64-bit software issues than I ever got out of having Windows 8 on the desktop.

Lee D Silver badge

Been deploying Windows 8 for a few years now.

With Classic Shell deployed as an MSI, pretty much it works the same in a domain environment. I agree that, at home, I use Windows 7 but - you know - Windows 8 really isn't that bad. And I say that as someone who held off on the "new" Offices for years, was stuck for XP until 7 was viable (and some time past that on some machines). I am a stick-in-the-mud.

But 8, with the usual "Let's fix this for my domain users" is pretty much there. The extra faffing isn't really that noticeable when you have several hundred new GP options to go through anyway. The users barely notice or care and half of them don't even realise it is 8 (when they've been told to stay off 8 by their children/techy friends).

Sorry people, it may not be ideal and it may be ugly in places, but all OS are. In a domain environment, the tweaking necessary to get it back to "sensible" is just normal. The only thing that really annoys me (and it's not 8-specific)? Simple things still can't be done in GP.... how do I specify the user logon image? Can't put it in AD, no, you have to pee about with scripts and copying over local files. How do I turn off accessibility options? Can't do it in GP, have to deploy registry-editing GP's or block access to a certain program in the System32 folder.

Not specific to 8... I still don't get why MS release an OS or an Office suite where every option the user can customise isn't available in the GPO's...

So, these guys turn up with AK47s and offer me protection ...

Lee D Silver badge

Is it just me

Or is there no amount of money you could pay me to put me in a town with random people wielding AK-47s and all the other trouble?

Not suggesting where I live is "safe" but... sod that...

Eight pocket-pleasing USB 3.0 hard drives

Lee D Silver badge

The problem I have with these is that they're still a bit small in terms of capacity.

1Tb is fine for the "let's lob some photos on" crowd, but my laptop alone has 4Tb of storage. In terms of putting things on for backup, I need something huge. And when you get into those sizes, then backup speed is a real issue.

These things are neither one thing nor the other. 64Gb USB sticks are dirt cheap, can be dropped and are very fast. These things are large but (comparatively) slow and fragile. Not the best for home backup.

And then you consider that pretty much any old enclosure could do if you slap the largest drive you can afford onto it. I can get a 2.5" 1Tb SSD for a couple of hundred now, but I can't get four times the storage in spinning disk enclosures for the same price.

I prefer the Zalman VE- range anyway as they allow you to mount ISO's stored on the disk and it pretends to be a bootable USB CD drive at the same time (no more carrying around boot/rescue/driver/OS install disks). One of those unique selling points that nobody else ever bothers to copy despite it being nothing but a firmware upgrade. But they can bundle some freeware backup junk that I wouldn't trust my temporary files to...

UK data cops warn Optical Express to stop spamming 1000s of customers

Lee D Silver badge

Re: Odd marketing strategy

Clearly you don't keep up with the news.

Laser eye surgery isn't permanent, far from it. Sometimes the only fix for botched laser surgery is... more laser surgery. No guarantees are provided.

And the DVLA are looking into cases where someone has laser eye surgery, passes the test / paperwork to confirm they have no need for glasses when driving any more, and then a few years later are arrested because their eyesight has dipped below the legal standard again.

More important, it's a functional surgery, not a cosmetic one. Cosmetic ones, I can understand (but not condone) the spamming to a certain extent, as an "impulse buy". But either your eyes are bad and you need surgery or you don't. Spamming customers isn't going to help you.