The Register Home Page

* Posts by Doctor Syntax

42273 publicly visible posts • joined 16 Jun 2014

Page:

Your software hates you and your devices think you're stupid

Doctor Syntax Silver badge

Re: Non determinism

"When I cut a cheque with it and pressed Go, the cheque image scrolled slowly upward to reveal a new cheque underneath, instead of the entry just blanking as in the previous version."

I once worked with a guy who spent an afternoon animating the replacement of one message by another. The new one appeared to slide out from behind and then in front of the old one. I suppose it was an afternoon well spent. It kept him from harming some other piece of code.

Doctor Syntax Silver badge

Re: Please don't kill me with downvotes...

"I won't even get started on the marketing department"

I think you should. With extreme prejudice.

Doctor Syntax Silver badge

Re: There's an island somewhere...

Taiwan?

Doctor Syntax Silver badge

Re: Hang the UX designer

If you're from MS, make it look like Windows 7 2000

FTFY. Anything later than that started to get a bit bloated. The same look can be achieved on KDE pre-5.

FCC sets a record breaking $120m fine for rude robocalls

Doctor Syntax Silver badge

"So you really think that number you see when your Insurance company phone up is ACTUALLY coming from someone working for that company?"

If it isn't it's a problem. In fact, it's one of two problems. One is that it's a fraudster. The other is that the company is outsourcing its relationship with its customers which, in the long run, is an incredibly stupid thing to do.

This, of course, introduces a third problem: telling which is which. Or, to express it a different way, it makes the telephone, like email, into an untrustable means of communication. If a communication, possibly urgent, from a business such as a bank, is untrustable that is a very serious matter. Any time my bank tried to call me they were unable to authenticate themselves so I simply told them I didn't believe they were the bank. (As these were marketing calls no harm was done.)

Doctor Syntax Silver badge

Re: "As for fixing the robot all problem"

"You're running up against the First Amendment which is why campaign calls (political speech) is exempt."

Presumably this allows politicians to lose votes by pissing off potential voters. Does it also allow calls to be spoofed as being on behalf of your opponent? That would appear to be the most effective form of robocalling.

Doctor Syntax Silver badge

"It's all legit and perfectly legal."

That's the problem. It provides cover for those who abuse it. Perhaps it's time to make it illegit and illegal.

Doctor Syntax Silver badge

Re: First step the fixing robocalls

"With a big enough fine, the government can seize and garnish."

Only if there's sufficient there to seize.

Doctor Syntax Silver badge

Re: $120 million fine

"fine has been set, but not paid as yet"

How long in jail in the event of a default?

US border cops told not to search seized devices just for the hell of it

Doctor Syntax Silver badge

Re: Works for me

"Fewer crims will get by claiming bogus privacy violations now. Society wins, the crims not so much."

AFAIK the presumption of innocence is as much part of what I assume to be your country's constitution as it is for mine, the UK's.

Thus you cannot point at a person and say "he's a crim" (to use your own terminology*). We are all presumed innocent until found guilty and so if any protections exist under the law they exist for all of us. Therefore the protections which protect those you call "crims" are actually there to protect you. Didn't you realise that? So if you ever find yourself having to claim a privacy violation to get the law's protection would it be, to use your own terminology again, a bogus one or is it the case that special rules apply to you so that your privacy is genuine and everyone else's is bogus?

I should point out that I spent over a decade working in crime investigation in circumstances which had an ongoing terrorist problem (substantially funded from the US as it happens) and I'm a firm believer in the presumption of innocence an essential part of the rule of law. This was something I had to think of everyday as it quite rightly set the standard for my work. The view from your sofa might vary.

*In case you never learned to spell the full word is "criminal".

Collateral carnage as ZTE sanctions see Australia’s top telco dump mobe-maker

Doctor Syntax Silver badge

"their government’s actions have blown back"

Pushy govt actions blow back? Surely not?

Consent, datasets and avoiding a visit from the information commissioner

Doctor Syntax Silver badge

IANAL but...

...as far as I can the following should be a good starting point, "data" being personal data

If you are required to collect and process data for statutory reasons then you're allowed to do so to the extent that the statute says.

If you need to collect and process data in order to complete a transaction for goods or services then you can do so and retain it as long as needed bearing in mind that different data items may be required for different lengths of time. You should delete data when its no longer needed.

You should only process the data according to the needs of the transaction for which it was required.

Need is not want, neither for collection, storage or processing. What some department wants is irrelevant, it's what the transaction needs that matters. You need to analyse this carefully; so carefully you can stand over your analysis in court if need be.

If you want extra data or want to process it in some additional way you must get explicit consent for that extra data or usage from the data subject. The consent may be withdrawn at any time. If it is you must delete that extra data. The regulations allow for technological limits so you don't have to edit backups. OTOH you're unlikely to get away with not re-deleting it if you have to restore from backup.

Getting extra permission can't be tied to providing the goods or services. Trying to weasel out of that or anything else is what brings the top tier of fines. The authors of GDPR saw you doing that previously. They've taken precautions this time.

You need to show data subjects what you hold about them if they ask and fix it if it's wrong.

You need a data protection officer. That's a role not a post. You don't need somebody full-time unless you think the workload is going to justify it. The DPO needs sufficient clout to say what can and can't be done and to find out the truth of what's being done.

Data is stuff held in written records as well as this trendy electronicry

If thy business is monetising data subjects' data rather than just selling goods and services to them then the curse of GDPR be upon thee and upon thy weasels lawyers

Doctor Syntax Silver badge

Re: Commercial relationship?

"Erm, in exactly the same way as bricks-and-mortar shops do."

Not quite. Bricks and mortar shops aren't subject to the distance selling regulations. If you're subject to those you may have a good basis for retaining the minimum info needed to make a refund to the card used for the purchase. Also, if the bricks and mortar shop is selling on a pick it up and take it away basis they don't need a delivery address.

Doctor Syntax Silver badge

Re: GDPR Nirvana versus reality

"The reality of the GDPR is that there will just be a whole load more terms and conditions attached to every website and every agreement that no one will ever read, at least past page 97."

How many times do we have to explain it? You can't add data-slurping to provision of whatever it is that you're selling on a take it or leave it basis and attempting to do so is one of the behaviours that brings the top tier of fines.

Doctor Syntax Silver badge

Re: Have you seen the credit reference parasites' answer to this?

"n other news, it's going to be fun watching the card issuing biggies deal with GDPR."

Another one I'd like to find out about is PayPal. I discovered that they send the buyer's email address to the vendor. I discovered it because one vendor discovered in no uncertain terms that I don't like being spammed. I had to go through the trouble of changing my PayPal email address.

This is stupid beyond the spam issue. The email address is also half of the login credentials. That alone is more than sufficient reason not to pass it on.

If the vendor needs, or thinks they need, an email address I'll give them one. Unless I anticipate giving them repeat business it'll be a short-lived address and even shorter lived if they spam me. And if I do anticipate repeat business the most effective way for them to forgo that is to spam in which case that email address will also be short-lived.

So far I haven't seen any request from PayPal for permission to continue doing this although, of course, it's possible that they've stopped doing it.

Doctor Syntax Silver badge

Re: Commercial relationship?

> For a one-off purchase, there is no legal reason to keep details of the customer, and the old practice of requiring that someone set up an account before being able to buy something will no longer be tenable.

That's also not strictly true.

You may need to retain the customer's details (in the form of your invoice) for tax purposes. GDPR provides for this with Section 6(1)(c) Compliance with a Legal Obligation.

That's rather a different situation than insisting on the customer set up an account with a login ID and password and hold all sorts of information against it "so as to make your purchases easier next time". It's liable to mean that they want to hold payment methods such as card number/expiry date/security number. The card number might reasonably be held as long as the distance selling cooling off period. If I only want a one-off purchase I don't want any of it held longer than the length of time it takes to go through. As to the user name and password making hypothetical repeat purchases easier it's quite easy, and preferable, to enter my name and address again as opposed to either setting up a unique set of credentials and then looking them up again or of giving some generic credentials which will be usable elsewhere should their site leak.

Doctor Syntax Silver badge

Re: Commercial relationship?

If having an account is part of the contract for the sale (ie. "we only sell to customers who have an account") then that account is converted as part of the contractual consent.

GDPR requires granularity of permissions. You can't rope an extraneous set of conditions in as a requirement of doing business. A one-off sale does not need an account. Everyday purchases in a bricks and mortar shop prove that so insisting on an account wouldn't be essential to the sale and putting it into a contract for the sale would be contrary to GDPR.

Doctor Syntax Silver badge

Re: Commercial relationship?

"For a one-off purchase, there is no legal reason to keep details of the customer, and the old practice of requiring that someone set up an account before being able to buy something will no longer be tenable."

Several different issues here. You may need an audit trail for the VAT man even for the one-off purchase or to verify possible warranty claims. In the context of the original query then there's also the implication of an on-going business relationship if, for instance, the website development includes hosting arrangements or software which requires periodic licence payments.

OTOH the set up an account sites are going to be in trouble.

Doctor Syntax Silver badge

Re: Commercial relationship?

"every junior job in Python programming requires you to do web scraping, surely that is basically illegal under GDPR?"

It depends what's being scraped. If it's personal data then yes but it does raise the question of why it's on the screen being scraped.

Doctor Syntax Silver badge

Re: Commercial relationship?

"I presume (wrongly?) that keeping details of a sale/customer remains legal, provided the data is kept safe. Does entering into a contract to develop a website for someone mean they have given you explicit agreement to remember who they are? "

Keeping what's necessary and using it for what's necessary is legal.

You may need their business address, you don't need their home address, their age, their spouse's name or their children's names - unless they want that as content on the site.

Although you need their business address that doesn't mean you can also sell it a double-glazing salesman.

Doctor Syntax Silver badge

Re: but you can't then presume to use it for mailshots trying to sell other stuff

"Does this break Amazon's recommendation system, unless they explicitly ask for your consent?"

You mean the "Other people who but what you bought also bought..."

I'm not sure how that could possibly be any more broken than it is. Isn't it based on a random selection?

Doctor Syntax Silver badge

Re: Glad to see the appropriate GDPR noises are being made

"Nobody is going to go after a customer/contacts database"

Some of us are going to do what we can to make life uncomfortable for those who don't behave.

One that I have saved up relates to an enquiry I made a few weeks ago. The enquiry was answered but soon after there was a "rate our service" request which, in fact came from a third party. The reply address was in the form first-party@third-party so I replied pointing out that my permission had not been given for my data (email address) to be passed to the third party, I wasn't going to click any links in a spam and I wanted my data deleted and confirmation that that had been done. The only response was a follow-up because I hadn't filled in their survey. Come GDPR day a letter will go out to the data controllers of both organisations asking them to explain themselves and pointing out the consequences if this were to happen now.

I suspect that in many cases the data controllers don't know what others, particularly sales and marketing are getting up to. If nothing else complaints like this are going to mean that many of the guilty get a well-deserved kicking from their data controllers.

Doctor Syntax Silver badge

"data processors are often engaged to form a contract between the subject and the controller e.g. a ticket sale for an event. If consent was not basis for processing, removal of consent is not applicable."

Once the processing for performance of the contract is over there is no ongoing basis for retaining the data. In your example there might be a basis for retaining the data until the event is over in case refunds have to be made but when that possibility has passed the entire basis for holding the data has gone. The data should then be deleted. However the entire basis for processing was performance of the contract and there is no basis in the form of consent for the ticket processing business to use the data whilst it exists for anything else such as trying to sell tickets for something else.

Doctor Syntax Silver badge

"First, you have to make clear to the subjects where you got the data and what you're doing with it, and – most importantly – why you have the right to do what you're doing."

Arse about face| You don't have to make it clear to the subjects where you got it. You have to make it clear to them what you want to do with it before you get it and ask them if you can have it. If they say no you can't have it. And if they change their minds subsequently you have to delete it.

(Note the exceptions of data used for the provision of a service, etc. or statutory requirements. Of course you need a name and address for delivery of goods but you can't then presume to use it for mailshots trying to sell other stuff.)

Brit govt told to do its homework ahead of talks over post-Brexit spy laws and data flows

Doctor Syntax Silver badge

"A competent government would've had teams of experts working on this sort of thing from 2016-06-24."

Not just that. A competent government would have waited for those teams to report, understood the issues, have worked out how to deal with them and had the work sufficiently advanced so as to meet the target date before pulling the trigger, and, indeed, whether it would be a good idea to pull it. It's called planning.

Doctor Syntax Silver badge

"the Privacy Shield deal, which allows transatlantic data flows and was set up after its predecessor Safe Harbor was struck down, was pushed through faster."

And it's been on borrowed time from day one. Its life-span was always limited to how long it would take SuperMax to get from complaint to ECJ ruling.

IBM bans all removable storage, for all staff, everywhere

Doctor Syntax Silver badge

Re: Does the ban cover smartphones also?

"a USB port block at BIOS level"

Do it right. A port block at epoxy level.

Doctor Syntax Silver badge

Re: It's not for everyone but for most it could be good

"company certified sharing systems that can be controlled, scanned and safeguarded"

By whom? And note that the "whom" might be different for each verb.

You love Systemd – you just don't know it yet, wink Red Hat bods

Doctor Syntax Silver badge

Re: As an outsider I find this fascinating

"Technology moves on, often in directions that we don't all approve of. Nevertheless you have to keep up"

Let's extend the direction metaphor. You're driving along when you realise the road you're on leads in the wrong direction, possibly in the direction of a dangerous flood. Do you keep up or do you take a turn in a better direction?

In your situation there may be no alternative. In the Unixy world there are: several BSD Unices and systemd-free Linux distros.

Doctor Syntax Silver badge

the people with the problem with it are more of the Torvalds type, old school who want to use Unix-like systems

FTFY

I have no problem with Red Hat wanting their semi-proprietary system. Unfortunately, in order to preserve their data centre presence they had to eliminate competition from non-systemd distros by ensuring it got into the likes of Debian.

Doctor Syntax Silver badge

"The more people learn about it, the more they like it."

Translation: We define those who don't like it as not have learned enough about it.

So when can you get in the first self-driving car? GM says 2019. Mobileye says 2021. Waymo says 2018 – yes, this year

Doctor Syntax Silver badge

@A/C

You're not alone. Here in the Pennines we have much the same issues as Cornwall, less the peacocks but add in snow drifts and cyclists who wish to take no responsibility whatsoever for their own safety.

Doctor Syntax Silver badge

Re: Asking the wrong question

"I want to know when they will be affordable for an average guy, like me?"

I doubt they'll ever be affordable to buy.

The legislative basis for their use, at least in the UK, seems, quite rightly, to put the legal responsibility for safe driving on the manufacturer. That means that the manufacturer rather than the owner will have to insure themselves. The manufacturer will, of course, pass this on to the customer. In the event of a straight sale, however, the manufacturer will only be able to have one opportunity to do that so would need to charge the customer for the vehicle's life-time insurance as part of the purchase price. That would substantially increase the price of a new car. The likelihood is that these vehicles will only ever be available for lease.

"What is the point of buying such an expensive object, that depreciates faster than you can burn £50"

To have one available when you need it. If your prime use is in the rush hour when everyone else wants a ride you'll be in competition with everyone else. If the numbers of available vehicles are such that peak demand is adequately covered they'll be mostly idle during the day and the costs per mile will go up to allow for that. If you have your own car now you'll still need your own AV. If you can manage by taxi now you'll use and AV taxi.

Doctor Syntax Silver badge

"lifts (elevators) had human operators and people were worried about riding in one without an operator. Things change."

Lifts just go up and down a fixed route which they don't share with any other lifts, cyclists, pedestrians or stray animals.

Doctor Syntax Silver badge

This is basically the automotive industry version of what "the cloud" has done for IT infrastructure and everyone wants to be the new AWS.

Lets not forget that one of the features of "the cloud" seems to be massive breaches of personal data left swinging in the breeze in ill-secured cloud backups and the like.

With vehicles it will be unacceptable to leave safe operation* to the customers as the risks to life and limb dwarf the severity of the risks from cloud. There won't be a "new AWS". AWS can shuffle all the responsibility for third party damage onto its customers; vehicle manufacturers won't. It's not just a huge potential market for manufacturers, it's also a hugel risk.

* The opportunities for gathering, mining and subsequently leaking personal data are the same or worse than the cloud but now only a side-issue.

Doctor Syntax Silver badge

"when will people other than beta testers get in them?"

When they do the correct term will be "guinea pigs". The unfortunate aspect of this is that while the guinea pigs who get into the cars will be volunteers those in the surrounding traffic or on foot will be innocent bystanders.

I've made the point before but it still needs reiterating: compensation for death, injury or damage to innocent bystanders and their property should not rely on them having to take on manufacturer or insurance funded lawyers in court.

Windows Notepad fixed after 33 years: Now it finally handles Unix, Mac OS line endings

Doctor Syntax Silver badge

Re: Notepad++

"a new machine and vim hasn't been pre-installed"

Is there a Linux distro that doesn't come with vim installed with all the vi synonyms already linked?

Doctor Syntax Silver badge

Re: Priorities

"I can't see anyone really using Notepad what with the superior better alternatives of Notepad++ and Atom"

I can. The millions upon millions of Windows users who just use the PC as it came without realising that a text editor is something for which there are alternatives other than a full-blown word processor.

Doctor Syntax Silver badge

Even so I assume that it will continue to be the case that if one wishes to distribute, say, a set of notes for which .txt would be perfectly adequate the only way to be sure the recipient will be able to read them easily is to use the overhead of a PDF as older machines will probably never get the revised Notepad.

Every major OS maker misread Intel's docs. Now their kernels can be hijacked or crashed

Doctor Syntax Silver badge

Re: I'm impressed

"I used to know a DEC technical writer who knew so much about the VMS file system that the developers used to consult her when they were in doubt as to just how something worked."

But if the documentation was as good as you say why would they need to ask?

Windows app makers told to think different – you're Microsoft 365 developers, now

Doctor Syntax Silver badge

Re: "We want to do things because they're the right thing to do, not just because we can"

I think someone kidnapped a Microsoft manager and sent along a look-alike.

Yes, people see straight through male displays of bling (they're only after a fling)

Doctor Syntax Silver badge

Re: Gender bias...

"My bag contains a lot more than the typical male pocket contents of keys, wallet, travel card + phone."

So does my wife's. She also complains of it being too heavy. I think it might contain a mini-black hole or at least a moderately sized anvil.

Doctor Syntax Silver badge

Re: I've been both

"I have bought two new cars in my life too.. The Dan phase(s)."

Same here. I'm not sure how the 2nd hand MGB which was one of the cars in between fitted into the Dave and Dan scenarios. It was more a case of "this is the time to have one while we can still fit the children into the back seats".

Doctor Syntax Silver badge

Re: bike attire

"I usually wear the rain suit and bicycle clips - also guaranteed to repel the opposite sex."

And what do you wear when you're cycling?

Risky business: You'd better have a plan for tech to go wrong

Doctor Syntax Silver badge

Re: @Doctor Syntax

@yank_lurker

Yes, I take the point that things were less critical then. That was, indeed, the point made in the article. My point was that if one were looking for reliability to match that one might first consider an integrated system from a vendor able to supply everything from hardware to application. We have, in fact, the converse. We are building architectures with multiple points of failure.

When I retired a decade or so ago we were moving in that direction. I worked on distributed systems where multiple service providers cooperated on contract: one specialist supplier might face the customer, collect data and passed it on to another to provide the actual service. There might even be more providers than that, possibly with a prime contractor in the middle. But the lead time to deliver might be hours and each provider's system would be relatively self-contained.

Moving into today's architecture with,essentially, the lead time gone, every link is a potential point of failure and yet there seem to be more of them. Back in the day there was at least the ability to rely on the fact that any libraries used were on the local system and only subject to change under change control. Now we're liable see reliance placed on Javascript downloaded on demand from repositories completely outside the service provider's control.

So why, having gone to a trading environment with no slack in it, are we seeing businesses accepting more and more possible points of failure? Is it simply over-confidence? The price paid seems to be in data breaches and TITSUP episodes.

Doctor Syntax Silver badge

Of the two scenarios the mainframe with everything from H/W to applications provided by a single vendor seems less risky then a tangle of boxes, network OS and apps sourced from everywhere. And yet the suggestion is that the former belongs to a time when, allegedly, the cost of failure was greater. Does this contradiction stem from familiarity breeding over-confidence?

Adobe, 'hyper personalisation' and your privacy

Doctor Syntax Silver badge

Re: Choices

"You'll be left with a stark choice: agree to their use of your data, or don't use the service."

Only if they withdraw from the market altogether because what you outline is what incurs the big fines.

Doctor Syntax Silver badge

Re: Why do they all have such lame examples of personalisation

"passing the GPDR in appearance."

I don't see how doing what you say gives the appearance of passing GDPR, nor do I see a sham front end doing anything other than attract bigger fines.

Doctor Syntax Silver badge

Hypo-personalisation?

The saga of Tim's attempts to get information out of Adobe suggests they weren't very good at personalising their approach to him.

And:"I haven't thought through all of the access and deletion requirements for that but that's something that we’re working on."

Isn't it a bit late in the day for that?

Page: