Re: The most expensive dick swinging contest in history
"America couldn't bare the thought "
Are you claiming to have the naked truth?
42400 publicly visible posts • joined 16 Jun 2014
"Let the DWP verify people's ID"
DWP? ROFL
Seriously, how do you bootstrap these "IDs"? What does identity mean?
AFAICS it's all relative - this passport holder might be the same as this driving licence holder. But what TPTB might want to know is whether they're the same as the owner of this business which they suspect of being a front for organised crime or the same as this person on a facial recognition system. If, somewhere along the line, those IDs get lined up wrongly (and good luck to that not happening with the reported "success" of the latter) then it might take years for some poor schmuck to get out from under.
"The use of bulletproof hosting is particularly bad in the case of Magecart, as it eliminates one of the more effective means of stopping the infection - disabling command and control servers."
It doesn't stop the re-assignment of the IP addresses of the DCs concerned. OK, it takes out anything co-hosted there but of the DC operators want to get back into business then they have to clean up, assuming they can given that they're in bandit territory.
"The only employees who are likely to need outside email access in most companies are the sales team"
Sales and marketing are the worst offenders in what they send from their businesses. They are the most addicted to sending HTML mail, the worst for embedding links and apt to use outside agencies so that the actual domain from which mail is sent isn't their own and the embedded links are also likely to belong to a different domain. In short their emails look exactly like phishing emails.
They expect other people to open their emails so why wouldn't they open those with exactly the same characteristics?
What penguin? The OP mentioned no OS by name and the point is a good one. We need to seriously rethink desktop OS design amongst other things.
From what I've read Qubes OS seems to be a good start but I'd go a lot further. Do we need, for instance, an all-powerful user ID? Perhaps one user ID can handle disk partitioning but not have permissions to read disk contents. Another is responsible for installing applications and another manages user IDs. Another has permissions to structure a disk partition as a database and provide storage and retrieval systems as a service. Ordinary users don't get to access that database, their applications ask the server to store and retrieve files. Preferably some sort of authorisation could be devised so that the server recognises not only the user on whose behalf the request is made but also the application. Less convenient but then security is often a trade-off with convenience.
When I read a comment like this it always leads me to reflect on why the commentard doesn't go into politics. After all if they are so principled and nobody else is wouldn't they make such a better job?
Could it be that they wouldn't want to be slagged off by generalising commentards such as - well, such as themselves?
how about you accept drugs approved by the US FDA for use in the NHS without requiring us to get them certified by the EU's EMA?" Which isin't actually utterly unreasonable, and probably not actually *that* problematic given that the standards are pretty similar.
How's Hancock getting along with setting up a UK approval body given that we're going to need one of our own?
AavGo
Is that pronounced "'ave a go?"
told The Register the exposed database did not contain any personal info beyond names, phone numbers, and email addresses.
What else would be needed for phising? "Could you please confirm your payment details"
The biz also insisted no payment card details were stored,
See above.
and nobody other than Brown is believed to have spotted the server
On what is this "belief" based, other than blind faith?
"If you read the news... in the US... it appears that the UK Ambassador to the US was leaking classified information."
Either the US news media read it wrong or you did. The ambassador's reports were confidential. What was leaked - by someone else - was his actual words. I doubt many would consider what he was reporting was a secret - we can work that out for ourselves from POTUS' own pronouncements.
I'm sure all the other ambassadors have made similar reports - I'd love to know what the French said, for instance.
"No mention about it being designed in Britain."
No mention of anything at all unless javascript is enabled. We really need some technologically competent business to devise a language to convey marked-up data from websites to browser without all that extra overhead.
"hence why the data is being uploaded"
And yet it's possible for the mobile phone in my car to have its voice commands processed locally. How old is this advanced tech? Well, I remember a mobile phone with voice control being launched in 1986 (Topaz in the old BT Mobile catalogue).
"Actually, there is one solution"
There's another which was John Brown's solution above. Give an audible warning when it starts live. And let's not stint, a nice flashing red light as well. It should be possible to do this locally but even if it isn't, all input when it's not live is sampled for wake-up detection and then goes straight to /dev/null.