* Posts by Doctor Syntax

40432 publicly visible posts • joined 16 Jun 2014

Page:

Malicious xz backdoor reveals fragility of open source

Doctor Syntax Silver badge

Re: Complexity

"Do one job, do it well"

And when you've done that, leave well alone - and applaud others for doing the same instead of denigrating the project for not having updates.

Doctor Syntax Silver badge

Re: Would This Have Been Caught Sooner In Proprietary Software?

"which requires, well, actual work, for a prolonged period"

No problem in this case. It was a well organised long term con.

"Then of course there are your peers and your management, who are paid to spend their days looking at and producing code, which likely include yours too."

Are you impyling some sort of QA? That's what Microsoft's customers are for.

Doctor Syntax Silver badge
Joke

Re: Would This Have Been Caught Sooner In Proprietary Software?

Maybe it's already happening and that's how the existing ones came to be there.

I hope the icon's relevant.

Doctor Syntax Silver badge

Money would undoubtedly be a start. Another would be the availability of someone paid by a foundation (I think this would be the vehicle) to take on overload, discuss problems or whatever.

Perhaps also the entire S/W world also needs to adopt the attitude that something is feature complete and, other than bug-fixes as needed, it should be left alone. A bit of encouragement towards that approach wouldn't come amiss. At present a project that hasn't had recent updates is often regarded as dead and gets denigrated whereas they should be celebrated as not needing updates. Handing out some sort of recognition to such projects could be another line of approach. Dis liblzma need to reach a version 5.x?

Doctor Syntax Silver badge

There are features of the social engineering - a couple of newly created sock puppets playing good-guy/bad-guy roles as well as "Jai Tan" and it was these pushing for incorporation into distros. Perhaps some automated trawl could be used to look for a similar pattern - it might even be an area where AI could actually do something useful.

In the meantime something needs to be done to support lone developers and maybe scrutinise maintainer handovers like this as they happen.

Ex-White House CIO tells The Reg: TikTok ban may be diplomatic disaster

Doctor Syntax Silver badge

"you need to be play-booking the worst scenario of what a shutdown means,"

I'm not sure they'd be calling it "the worst scenario", more like a game of chess. It probably means preparing to roll out something called "Tock-Tick" or the like that they've prepared for just such an even and trying to work out how close to 180 days they can get and still be first mover.

You break it, you ... run away and hope somebody else fixes it

Doctor Syntax Silver badge

If the line printer was only buzzing there must have been something wrong.

Rust developers at Google are twice as productive as C++ teams

Doctor Syntax Silver badge

Mybe I should look at it. My C is very rusty now.

Do not touch that computer. Not even while wearing gloves. It is a biohazard

Doctor Syntax Silver badge

I always looked on them as more or less equivalent to spats for cars.

Doctor Syntax Silver badge

Re: Dentists

Quite possibly it's dental stone - plaster of Paris used to make casts.

I used to get 25kg bags of that from a dental supplier in Belfast to be made up into 1lb bags for SOCO to make casts of footprints & tyre marks. The supplier decided to add a 2nd line of business - video store, back in the days of VHS. It made a strange contrast, his shop full of videos and his dental display item - an old dentist's chair complete with a pedal-driven drill.

I reckoned that rather than have the SOCO's add a bucked and stirring stick to their kit it was easier to make the bags big enough and tell them to add a pint of water and mix them in the bag by squeezing it a few times. I wish I'd patented the idea - a few years ago I came across bags of mortar or concrete mix in M&Q with hose attachments to add water for in-bag mixing.

Doctor Syntax Silver badge

Re: Following BSE in cattle...

Good news is no news.

Doctor Syntax Silver badge

Re: I had a maintenance contract ...

"Volcanic ash and cinder dust is the absolute worst thing you can do to moving parts"

HCl fumes. We wondered why the drying cabinet was losing efficiency. The fan blades had gon AWOL.

Doctor Syntax Silver badge

Re: Burned Cow Bones

In Aldergrove it had a slight tang of aviation fuel AFAICR.

After one training course in London I was asked to take some samples back for some sort of QA trial for some of my colleagues. Solutions of explosives .

Doctor Syntax Silver badge

Re: What happened to the truck or its driver?

Just hop it.

Doctor Syntax Silver badge

"Obviously, white tires won't stay white very long"

Whitewall tyre used to be a (very upmarket) thing. And DDG tells be you can still buy them.

Doctor Syntax Silver badge

Re: CompuPro S-100 boxes in cat litter plant

Tell it to the youngsters these days, they'd never believe you.

Mind you, a few years before that, tell it to the old hands and they'd never believe you either. Things are of their time.

How a single buck bought bragging rights in the battle to port Windows 95 to NT

Doctor Syntax Silver badge

Re: I liked NT4

And annoying.

Doctor Syntax Silver badge

Re: Nah.

But just hink of all the support business it would have brought in.

Doctor Syntax Silver badge

Re: Vista is a very unfairly maligned OS.

"If you really wanted to be serious about this sort of thing, you'd take angular velocity into account and put the most frequently accessed files on the outermost tracks of the drive, and the least frequently used ones on the inner most tracks."

If you want to get into track optimisation you put the most accessed material as close together as possible to minimise head movement between it. To minimise head movement to the less often used material you put that most used material in the mid-range tracks so you seldom have to do a seek right across the width of the disk.

Doctor Syntax Silver badge

Re: Nah.

"Sort of like how it took them a few tries with Windows 10 to deal with the new policy of forcing updates that may require reboots. Yes, it's annoying since it seems like it always happens right when you're in the middle of something,"

I remember that one. At a local archaeology do, somebody was about to demonstrate his surveying S/W - luckily it was just to a few of us after his talk. His laptop must have picked up an open WiFi or something and phoned home to be told to update there and then.

"but if you stop and consider, a lot of the shit that we used to deal with (email worms, the messenger service reboots/spam) have almost completely stopped. Grand scheme, it seems like a small price to pay."

It only seems a small price if you don't know there can be a smaller price to pay by doing unobtrusive background updates that only occasionally go low enough to require a reboot after the upgrade's complete, and just plain reboots at that, When you know that it seems an inexcusably inordinate price.

Doctor Syntax Silver badge

Re: Nah.

"But, even on sites like this, which cater to more technically inclined users, rarely do you see anyone who has taken even basic steps towards debugging the issue to show that it really is the OS."

If the upgrades to the OS, made by the OS vendor who has charge Real Money for the OS (albeit via the H/W vendor) crash because, as you say, they've cut QA costs there there's no reason to look beyond the OS and its vendor.

We've seen a fairly recent example where the upgrade required a recovery partition larger than the default installation recovery partition and would either hang at about 20% complete or throw an error. And the vendor's advice to fix the "everything can be done with clicks" OS was to drop down to the command line, resize a partition. drop and recreate a partition (and hope the command-line newbie would drop the correct one) and then do some configuration based on information they'd recorded before the partition drop. W2K was a reasonably effective OS. The above is the reason a lot of us think it's all been downhill from there.

Doctor Syntax Silver badge

Re: Nah.

"Grow up nd maybe spend a little time learning what it is you don't know, because it is legion."

Good advice. Act on it.

Doctor Syntax Silver badge

Re: Nah.

"I think we look fondly on 2000 because it was the first business class OS from MS that had things like plug and pray."

And the last not to want to phone home.

Doctor Syntax Silver badge

Re: Windoze NEVER worked well.

"In those days, for a server you used Novell Netware."

Oh no I wouldn't. I'd use a real Unix server. I had a very brief encounter with a Netware server. Trying to stop a database server brought down the whole thing because, as far as I could see they were doing the equivalent of running the kernel and all services as a single process.

Doctor Syntax Silver badge

Re: Windoze NEVER worked well.

You need to realise that there's and argument consider W2K was probably peak Windows and everything has been going downhill since then but you might have trouble running more recent versions on your old H/W anyway. It's always good to hear of H/W that was built to last, so much is built to be disposable these days. If you wanted that reliability of S/W there day's you'd be well advised to go for Linux or BSD,

Doctor Syntax Silver badge

Re: Windoze NEVER worked well.

You can always spot those whose knowledge comes from reading a post by someone whose knowledge comes from reading a post whose knowledge comes from Microsoft marketing* - or maybe a bit less direct than that. One thing they don't realise is that those of us who run Linux as a daily driver are often asked to sort out problems for those running Windows.

* The alternative is those who, despite never actually having installed Windows, have used it, now consider themselves a computer expert and made a ham-fisted attempt to install Linux by clicking all the non-default, wrong options.

Doctor Syntax Silver badge

Re: Windoze NEVER worked well.

"And now, there's nothing a mac or linux box does for an average user than a PC doesn't do better for still way way less money."

Yup, when it comes to crashing, slow boots, extremely slow and buggy upgrades a PC with Windows is way ahead of the the pack, or at least, way ahead of Linux. I don't have a Mac so I don't know for sure but I'd guess on those metrics Windows is ahead those as well.

"And no, you aren't going to install Linux on your non-technical household type users."

Odd you should say that. I installed Linux on my cousin-in-law's PC some years ago after she'd got hit with ranomware. She's still using it for web, email, maybe a bit of LireOffice, maybe not much these days, very fond of Google Earth. She's at least 90 and a in terms of long-ago work experience, used to be a hairdresser. Does that fall into your non-technical household type?

Doctor Syntax Silver badge

Re: Windoze NEVER worked well.

"when you have a day or so of un-saved contract open in your editor!"

Save early and save often.

Doctor Syntax Silver badge

Re: Windoze NEVER worked well.

"Linux was barely out of the starting blocks in 1995."

Available but my preference was SCO Openserver 5 on a laptop.

Why Microsoft's Copilot will only kinda run locally on AI PCs for now

Doctor Syntax Silver badge

I think I have one possible useful application for such a device. Screening emails to detect those touting for reviews, ticking all the boxes for the most negative response and entering complaints about touting for reviews in all the text boxes, perhaps varying it occasionally to say "This reviews has been completed at random by computer".

The Register meets the voice of Siri Down Under

Doctor Syntax Silver badge

BT's idea of rendering text to landlines leaves something to be desired. After no information since ordering one Amazon vendor started giving me a text commentary, quite useless as it was about delivery of a present a couple of hundred miles away.

The first word was, I think, "shipped" spoken very abriptly - but that's not what it sounded like.

And a hint for anyone whose business process involves sending SMS without checking that the destination really is a mobile: test it to see just what you're sending. Include a URL and a few numbers with more digits than a street number or a date. Then review your business development process.

Malicious SSH backdoor sneaks into xz, Linux world's data compression library

Doctor Syntax Silver badge

Re: What about the culprit

Good question, but no. It just means you can't download it from the original Github repository. You could, for instance, use the Debian source packages for it. Other source packages are available, just choose carefully.

Doctor Syntax Silver badge

Re: SytemD?

If the attacker was only a little more careful/competent

Don't knock the developer. You know how it is:

"Ship it"

"But comrade, I need another week or so to fix performance problems."

"Never mind that. It runs so ship it."

Doctor Syntax Silver badge

Re: More Details

"minimalistic libraries for widely-used functions (such as communicating with systemd activation)"

Mimimalistic ... systemd? Does not compute.

Doctor Syntax Silver badge

Re: It Was In Debian Unstable --- *buntu LTS

Ken and Dennis have/had (AFAIK Ken is still with us) many good things to say. What a pity so many didn't listen.

Doctor Syntax Silver badge

Re: systemd was responsible for injecting the vulnerability into the SSH daemon

As far as I can follow the discussion elsewhere the malware is introduced in a build-time script in the source tarball and, subject to various constraints might or might not be incorporated in the actual built library binary. It's crafted to attack SSH only but even that, again, if I've followed the discussion correctly, still depends on systemd's use of the SSH server. So MacOS might or might not have the relevant code into the built version it's unlikely to become a problem without systemd - unless launchd works in the same way in this respect.

At least some of the discussion hinges on this appearing to have been what used to be called a long firm fraud with a state actor as the likeliest perpetrator so the question arises as to how long and what else might they have got into, possibly using other handles.

Doctor Syntax Silver badge

Re: SytemD?

"What on earth is the connection between that and xz?"

You could ask the same about almost anything, not just xz.

Current Devuan and hence current Debian, give or take any infection Debian bight have acquired from systemd, is 5.4 so they're clear.

These 17,000 unpatched Microsoft Exchange servers are a ticking time bomb

Doctor Syntax Silver badge

"they should have thought about that before switching to a managed service provider"

Or chosen their MSP more carefully. One that doesn't try to spread itself across everything from OS to AI bandwagon jumping.

Doctor Syntax Silver badge

Re: Those damned reboots

Try reading the sentence after the one to which you referred. Pay particular attention to the words "the exim mail server".

Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching

Doctor Syntax Silver badge

"The latest method has been called Dirty Pagedirectory"

Looking at the CVEnumber, perhaps it should be called Domesday.

Amazon fined in Europe for screwing shoppers with underhand dark patterns

Doctor Syntax Silver badge

The Amazon logistics set-up is a strange beast. Over the last year or so the predicted times when a parcel is out for delivery may very a little but usually settle down to a range of a couple of hours or thereabouts and the the delivery is usually within about 10 minutes of the centre of the range.

If that fails the system more or less falls in a heap. It looks as if there is no provision in the software to deal with a missed delivery. Apart from anything else, if the failures are not being caught not only can the customer not be properly informed what's happening, the data needed for quality improvement isn't being collected.

In the past errors have included the failed delivery being treated as a return with emails to print off an RMA and a courier arriving at the door to collect the package they never delivered. That's not happened recently - now there's just silence followed, eventually, if you're lucky, by the delivery information being updated to say it will be delivered at some unspecified time in the future. I'd guess their weaselling is to deal with the consequences of that lack of handling anything that doesn't go as intended.

Doctor Syntax Silver badge

I wonder if Polish law allows for the penalty to be reviewed upwards in the appeal process.

University of Washington's Workday woes leave research grants in limbo

Doctor Syntax Silver badge

The prices will go up. The punter will still end up paying in the end. And what will they be paying for? Their own inability to do a bit of thinking upfront.

Cloud server host Vultr rips user data licensing clause from ToS amid web 'confusion'

Doctor Syntax Silver badge

"We know the average customer doesn't have a law degree"

Not all customers are average.

FTX crypto-crook Sam Bankman-Fried gets 25 years in prison

Doctor Syntax Silver badge

You put the conspiracy on the charge sheet in case the actual offence gets dismissed for some technical reason but hte conspiracy charge succeeds.

Doctor Syntax Silver badge

Re: Theres a shock

"there's more money to be made by holding the excess cash through the summer and wisely investing it"

That's probably SBF's thinking but he was a bit unlucky. He probably genuinely, really expected to be able to get it back, plus what he spent on himself, friends and family, before anyone noticed; the self-delusion of everyone who gambles with other people's money and loses.

Microsoft rolls out safety tools for Azure AI. Hint: More models

Doctor Syntax Silver badge

Re: AI can turn any rushed oversight into a lethal footgun

In other words, having the experts train their replacements. I don't think that would turn out well once the trainers cottoned on to what they were being asked to do.

Doctor Syntax Silver badge

"a custom language model that evaluates unsubstantiated claims based on source documents"

Which source documents are these? The source documents that we really positively never touched because they're customers' property? The source documents that really are not in the model because the model is simply a statistical summary of lots of documents so it can't be a copyright infringement? Or the source documents which form a carefully curated, reliable training set as opposed to blindly sucking everything in sight into the general training set?

Pressuring allies not to fulfill chip kit service contracts with China now official US policy

Doctor Syntax Silver badge

At what point does this become state aid on behalf of the US industry? The sort of alleged state aid that the US usually takes as an excuse to erect tariff barriers.

Majority of Americans now use ad blockers

Doctor Syntax Silver badge

Re: If they had behaved themselves I wouldn't need to block them

" If someone wants to insist that I have to watch their video adverts, well I don't need to view anything on their site."

And I certainly wouldn't want to buy anything they're trying to flog me. Paying to show me ads for their competitors might be marginally effective.

Page: