* Posts by a_yank_lurker

4138 publicly visible posts • joined 16 Nov 2013

Banks team to paint shared target on Target

a_yank_lurker

Not surprised

At some point the only way security is take seriously is when a major corporation has to pay a rather large sum that is many times what would have cost to do it right the first time.

Target may be able to fend off the card holders and other assorted small fry but major banks is whole new league.

'To read this page, please turn off your ad blocker...'

a_yank_lurker

A Note about ads in other media

Let's look at other media. Print ads are easy to ignore and most readers basically ignore them. They are rather ineffective if the reader can not remember the ad. TV/Radio ads are basically a good time to take care of the #2 business,raid the fridge, or channel surf. Many ads are never seen rendering them totally ineffective. So what is the issue with an ad blocker, again?. Ads one never notices, sees, or hears are totally ineffective no matter what the media.

Fed-up sysadmins beg Microsoft to improve pisspoor Windows 10 update notes

a_yank_lurker

Re: Never thought it would come to ths

Interesting you mentioned Apple, after learning about the secret W10 upgrade download I called the local Apple store and asked how Apple's upgrade policies.

a_yank_lurker

Re: The problem isn't coherence...

Trust MS absolutely never, generic USA corporation it depends but mostly, sadly no

a_yank_lurker

Re: Your confidentiality or your applicaitons … time to decide.

Bravo, MS or any OS is a guest on my hardware. On my hardware my rules will prevail and if that means Windows never runs on any of it the future that is my call.

Security bods jab pins at encrypted database system balloons

a_yank_lurker

Seems circular

Encrypting the database sounds good but what about someone who has somehow gotten valid credentials to log in? Once the data is decrypted it is in plain text.

Also, most of the major breaches will caused by operational stupidity and PHBs not wanting to be inconvenienced.

World finally ready for USB-bootable OS/2

a_yank_lurker

Punch cards next?

Let's remember Herman Hollerith - go full retro and use punch cards :)

Don't want to upgrade to Windows 10? You'll download it WHETHER YOU LIKE IT OR NOT

a_yank_lurker

Story is confirmed

I have a laptop with W8.1 on it that is not registered to receive the "free" "upgrade" to W10. I just checked, it has the $Windows.~BT with a date stamp of 20-August-2015. This has been occurring for awhile now.

a_yank_lurker

Re: So long...

Install Synaptic for nice GUI front-end to APT.

a_yank_lurker

Re: Sea change

The whole fiasco is totally unacceptable on MS' part. This will force some to take a strong stand and ditch Windows altogether. The tech savvy will mostly move to Linux while the masses will eventually migrate to something. Apple and Google are improvements here.

The only kit I have is a couple of laptops which might become Linux Mint only boxes in a few weeks. They are currently dual booting various non W10 and Mint.

a_yank_lurker

Re: "Personal" computer no more

A couple of good Linux alternatives Ubuntu (turn off Amazon searching), Linux Mint, Zorin, openSUSE, Mageia are viable alternatives. You can get a live disk of each to try it out and install from. No nagware, updates regularly come but are installed with YOUR permission. No 50 page shyster manual to agree to.

Intel's 6th gen processors rock – but won't revive PC markets

a_yank_lurker

Re: Nothing is going to revive the desktop market

My opinion has been the desktop/laptop market is a mature market and most sales will be replacement kit. Jack & Jill User do not stress their current kit and are not likely to stress any new kit.

Doctor Who returns to our screens next week – so, WHO is the worst Time Lord of them all?

a_yank_lurker

A Yank's Opinion

I never liked McCoy's era but I will second the many comments that was not really his fault. I never saw any of the Hartnell episodes.

As McAfee runs for US President – we ask a crucial question: Will Reg readers back him?

a_yank_lurker

Re: American Politics

They having trouble with Hildabeast and her email saga - might need to add treasonous to the list.

FTC gives FBI the finger over govt backdoor encryption demands

a_yank_lurker

Re: IF the US adds backdoors

Unfortunately, I am almost certain some very common proprietary products contain backdoors.

America's crackdown on open-source Wi-Fi router firmware – THE TRUTH

a_yank_lurker

Re: Just checking

Since the output power is limited by hardware, which is true of all transmitters, you are correct in that there is a upper limit. Most wifi devices are low power devices by hardware design and trying to push more power out will at best do nothing or at worst fry the innards.

a_yank_lurker

Re: Idiots on the loose

The real issue is the an iron of bureaucracies (I think Pournelle) which is bureaucracies look for "problems" to expand their power. It is not that the problem could occur, if one is willing to risk borking a router or two, but that most are not going to sideload an update of this nature. The FCC has found what is likely a very minor problem mostly affecting probably a few dozen idiots and has made it a "major" issue to justify their power grab.

The normal update pattern is for the user or the device to contact the official source for an update and to install it. Official updates have been shaky at times (MS looking at you) and unofficial updates are definitely shady.

a_yank_lurker

Idiots on the loose

The proposed solution is in search of a problem that does not exist. Very few people have the technical knowledge to rewrite the firmware for a phone or router. Also, firmware updates to phones, routers, etc. can bork the device. Thus, almost all users should be updating the firmware with an official update from the vendor only. In fact most users probably will not update the

Yes, there is a potential problem.But the problem exists now and appears more theoretical than practical. As the "exploit" requires sideloading of a firmware patch onto a device that has a fairly narrow, specific purpose.

So Quantitative Easing in the eurozone is working, then?

a_yank_lurker

Economics, "The Dismal Science", has had a long recognized problems in idealizing information flow and human behavior. The first fails to recognize that information is not known instantly in any real system. Individuals know bits, often important to them, but not all relevant bits. One knows what is in the pantry and knows what they want but they do not the inventory at the store. Also, as evens occur people react with their best navel gaze of the future, which by definition is unknown.

Hacker chancer looking for $500,000 after offering Clinton emails for auction

a_yank_lurker

Re: leaks..

I suspect several countries (Russia, China, India,...) could provide all of Hildabeast's emails including the ones she deleted. If these are real, how did he get them would be an interesting story.

Larry Ellison's yacht isn't threatened by NoSQL – yet

a_yank_lurker

Re: MongoDB? *laugh*

NoSQL databases are relatively new products while RDMS are relatively mature, well understood products. However, both are good at certain applications. The trick is to use the correct technology for the task

Want your kids to learn coding? Train the darn teachers first

a_yank_lurker

If most educators in Blighty are anything like their US cousins I am not surprised at the failure. Most teachers do not understand computers and as a former instructor you can teach what you do not understand. Money for training for programming will not solve the more fundamental problem. scientific and technical illiteracy.

Windows 10 grabbed about five per cent market share in August

a_yank_lurker

Probably Misleading

While the nominal market share is probably about right. there are probably three issues that make it misleading. First W10 was a "free" upgrade for many so the initial surge is likely to be higher with quicker tailing off. The initial surge is almost entirely MS users so MS is cannibalizing there own user base with only potential profits. Many have reported problems with the installs and have reported reverting back to W7/8/8.1. Thus there is some churning of the numbers. The industrial scale spying may force companies to carefully review their options in about 3 years. Many industries have rather strict data protection requirements that make W10 problematic. The initial surge is interesting but how long will it play out and will enterprise move to W10 are real questions.

Associated Press sues FBI for impersonating its site to install spyware

a_yank_lurker

Re: Clever

The spyware as apparently needed to properly identify the computer in question was the one used.

a_yank_lurker

Re: Do as I say, not as I do

The real issue is whether AP's brand was damaged by this action. Given the AP ability to screw up I doubt this will hold much water. Plus the attack was targeted to very specific person who was a suspect at the time not just to everyone. In fact the first I heard of this was this particular story though I am not surprised that it has been used.

So, was it really the Commies that caused the early 20th Century inequality collapse?

a_yank_lurker

Re: Scarcity of resource

As someone who has worked importing German goods into the US manufactured goods cost money and time to move from factory to store. It is roughly a month by ship from German port to US port. Secondly duties and freight are not necessarily trivial costs either. At some point the manufacturing costs will rise to a point when it is cheaper to move manufacturing back to the consuming country.

Also, do not underestimate the problems of managing a global workforce and contractors. Outsourcing is not a panacea nor is offshoring. Both have hidden risks from issues like difficulties in coordinating meetings, travel costs, cultural issues, and political stability in some countries.

a_yank_lurker

Re: The growth

I think point 2 may be overlooked. In combat, everyone depends on each other to survive. It is very difficult to understand the bond of combat veterans and understand that many owned their lives literally to actions of a private bravely doing his job.

In redneck heaven, internet outages are the American Way

a_yank_lurker

Re: Spade fade

some shotguns shoot rather large pellets plus being an (un)lucky shot

Win10 Insider build 10532: Avoid if you run Chrome 64-bit

a_yank_lurker

Re: Data

It should also be noted that services like Facebook are completely voluntary. No account then there is no ability for data slurps. Data slurps with any OS is a concern. With mobile OSes I will tolerate some location tracking for apps to be useful. Also, phone locations need to be tracked by the carrier so calls can be properly routed. Not thrilled but tolerable. Desktop OSes, however, are generally used in fix, predictable locations (for laptops) and none of the key features depend on knowing the location of the device. The only information the OS provider really needs is crash reports/logs. W10 has an overly broad EULA that appears to be a blanket EULA for all MS services without explicitly identifying which parts apply to what services. For this MS aka HooverSoft/MicroSlurp deserve all the negative publicity and hammering they have gotten and more.

Spaniard claims WWII WAR HERO pigeon code crack. Explain please

a_yank_lurker

Was this encoded with a one-time pad

Properly used one-time pads are notoriously difficult (virtually impossible) to crack when certain basic precautions are used. It is possible that this message used a one-time pad which would make breaking it an incredible feat.

Company in shambles, marriages ruined. My work here is done, says Ashley Madison CEO

a_yank_lurker

Criminal charges?

Given some of the antics of AM, i wonder if criminal charges are not in the works for the mismanagement team.

Windows 10 blamed (partly) for stalled PC sales recovery

a_yank_lurker

I tend to recommend to my non techie friends and family that they only upgrade their OS when the current one is at EOL not when released. If they can not run the latest Windows I often recommend a trial of Linux Mint after considering their needs.

a_yank_lurker

Re: Setting Windows aside for a second...

Agreed, I would also add almost all consumer oriented applications are mature products. There are very few if any features that a consumer would spend money to get the latest and greatest. This extends to OSes, the features I want are mostly kernel improvements such as the Linux 4.0 kernel hot updates. Even so, they are not something to make me go out a buy a new version to have. All the stuff MS is pushing on W10 is not really something that people are slobbering for.

Relatively old kit which runs the applications the consumer wants does not need to be replaced just because W10 has been released. Nor does anyone really need to upgrade to W10 for a fantastic new feature.

Krebs: I know who hacked Ashley Madison

a_yank_lurker

Re: ...Finally, if you're sick and tired of endless coverage of the Ashley Madison scandal....

The Hostess Brands (parent) was sold during the bankruptcy proceedings and is still limping around.

What Ashley Madison did and did NOT delete if you paid $19 – and why it may cost it $5m+

a_yank_lurker

Re: Chapter 11

It is hard to do, but the corporate shell can be pierced in some situations to get at personal assets. Whether this would the case here, I do not know.

a_yank_lurker

Re: Greasy

Your system is reasonable, levels of deletion to suit the customer. And you follow through. Full delete means there are no records kept. AM needs a good schooling on the meaning of "full".

Swiss watch: Cuckoo-clock cops threaten Win 10 whup-ass can pop

a_yank_lurker

Russians now the Swiss who next

Moscow Times reported there is a complaint to the Russian government to declare W10 spyware. Now the Swiss are making noises to declare W10 spyware. I do not remember that within 1 month of release two governments beginning possible legal proceedings to ban any OS.

If this takes hold, many companies will not be able to install W10 legally. Multinationals could be asked to certify that they are using a currently supported OS and they are not using W10 by governments in order to do business with them. Now the only generally available OSes are there that are known not to spy on users are Linux and BSD distros.

Apple could easily change their license and code for OS X to be complaint if it is not already so (I have not checked their EULA); they are a hardware manufacturer. Advertising revenue from OS X is not as important, more like chocolate drizzled on desert.

a_yank_lurker

Re: Ban the sale of Windows 10 in Switzerland?

Also, toss in one has to actively chose to use Google or Facebook while the OS is requirement.

Using SQL techniques in NoSQL is OK, right? WRONG

a_yank_lurker

Know when use 'em

The problem is not the database technology but knowing when one type is appropriate and it is not. Document NoSQL databases are best when the data is somewhat similar between each document. Relational are best when the data can be specified very well beforehand and are particularly valuable when ACID compliance is not optional.

Windows 10 market share growth slows to just ten per cent

a_yank_lurker

I would expect an early peak of installs with a tapering off to some level - my navel is saying about 3 - 4% per month max. So far that is the pattern. The only question is final rate of installs per week or month going forward.

a_yank_lurker

Re: At what cost

The Windows Store, actually a very idea potentially, should be the only place the average user needs to go to get any applications for their PC or mobile device. The repository system in Linux works very well with the entire system being updated including applications in one go. It would help solve many of the security issues plaguing Windows.

a_yank_lurker

Re: What did they think they were doing?

I have some very old kit still works in Linux when there are no current (W7 or later) drivers for it.

a_yank_lurker

Re: Dear Microsoft, good luck with that.

No new MS products on any of my kit and W7 & W8.1 will not be upgraded period. No new MSO, etc. I own the kit, I have final say what happens. Eventually W7 & W8.1 will be wiped from both boxes that have them (came preinstalled).

Amazon to trash Flash, as browsers walk away

a_yank_lurker

Google, Amazon, Apple, next ... Good riddance to a scummy "technology"

Microsoft will explain only 'significant' Windows 10 updates

a_yank_lurker

I usually have a DVD with the current version of Mint floating around. Mostly to use to install it on other boxes. Same original ISO, no personal questions asked during the install only what time zone, language, key board, and how do I want to partition the hard drive.

a_yank_lurker

Re: The future of MS-OS.

I believe consumers are essentially lost to MS with tablets and smartphones being the devices of choice. MS is an enterprise oriented company and has been for years. There are enough people in most companies who are aware of the Linux and that many distros are easy to transition to. The only hold up will be specialized packages only available on Windows that keep some "loyal". Many are not actively researching their options yet - they just finished migrating from XP. Others are probably being quiet about it.

Plus many IT pros are strong FOSS advocates and Linux & BSD are FOSS OSes. We use MS because that is what we are given not by choice

Want security? Next-gen startups show how old practices don't cut it

a_yank_lurker

Re: People "trained in IT security" are a lot of the problem

I had about an hour of training which consisted of reading a couple SOPs. No hands on, interactive training was done which used role playing. Also, very few reminders what to look for and how attacks are actually done.

a_yank_lurker

Re: Additional thoughts

"a backup system designed by a completely separate provider so that the same vulnerabilities cannot be exploited" - How many offices are MS (or more rarely Mac) mono-cultures? In ecology species diversity is one sign of a healthy ecosystem. If a company used a variety of OSes in all areas including Windows, various Linux distros from different families (Debian, Slackware, Ubuntu, Arch, Redhat, SUSE, etc.), Macs, etc. Attackers would be slowed down if not sometimes stopped because the each OS has different vulnerabilities and quirks. The only common vulnerabilities would be applications installed on all devices such as web browser.

a_yank_lurker

Re: Not fully convinced

I agree the process should be automated as much as possible. However, the article highlights security is often an eggshell with nothing behind the shell. Breach the shell or all already behind the shell (insider) you can do a tremendous amount of damage.

Security best practices include a layered defense with strict limits on user permissions including admins, user training, and white-hat attacks. Layered defense assumes the outer defenses will be breached and there are more defenses set up behind the crust. Standard military defense doctrine is "defense in depth". Users need training to identify phishing attacks - in person, phone, fax, and email - and how to respond. Also, they need training about basic physical and electronic security - do not assume they know. Irregular, unannounced white-hat attacks will help identify weaknesses to be fixed.

Microsoft sues InterDigital for 'monopoly power' over mobile patents

a_yank_lurker

Re: Huh?

I understand that "fair pricing" would preclude differential pricing to different vendors under SEP scheme. Thus, along as everyone gets the same deal there is no advantage in the marketplace. MS seems to be complaining unfair practices for having to pay the according to the schedule. Rather ironic given MS' history of unethical business practices if not outright criminal behavior.