"Yet if the machines are as advanced and secure and generally wonderful as IBM insists, surely more buyers would already find them compelling?"
Price? Worry that as the vendor keeps shrinking there may be nobody left to support the kit?
42272 publicly visible posts • joined 16 Jun 2014
It's perfectly simple. All they have to do is put it out to tender with the proviso that any proposed solution be critically examined for cryptographic flaws and flaws which would allow the system to be hacked. The project tender should be in two stages. The first would be given to a number of contractors, each to perform a feasibility study and proposal, the second would be awarded to the best proposal.
They can be seen to be doing something which will keep them happy. As the rest of us know the tender will be on a hiding to nothing the rest of us can be happy. The latter includes the contractors because they know they can be paid for doing a lot of work on the feasibility study and still get paid for saying it can't be done. One bright spark, of course, will probably come up with an idea which will eventually fail on critical assessment but they'll still be paid.
This is not, unlike many government IT projects, a waste of public money. It will be an excellent investment on keeping the idiots off everyone's backs, possibly for years with the additional advantage that as it will fail in their own terms they can still eventually be vilified for wasting public money.
"I have no idea if vi can be set up to do that. "
Neither have I but seeing as I've been using it since the days before keyboards had such fripperies there's no need for me to even check. The dreadful vim might well have that. My first encounter with that load was with a setup that had been configured to hide the ^Ms from then end of lines and as I wanted to use it to delete those I wasn't impressed. I was left wondering what else it might be set up to hide. So as far as possible vi and its relatives are links to /usr/bin/nvi.
"No one ever sat down at the computer with the express intent of playing with Word or Excel itself."
Well, that pair, never. The LibreOffice equivalents are a different matter. If the program icons are sitting on the panel waiting to be clicked it can be the quicker way to bring up a recent document. On the whole I agree with your sentiment, however; the idiocy of UX designers who seem to think forbidding data icons on the desktop is beyond belief.
"Didn't Tomcat, IIS or SharePoint suffice?"
You need to explain it in terms your potential market will understand. Good luck trying to sell any of those and many others -PHP, Drupal etc - outside of the IT department. Someone going to political parties and explaining their services in terms that politicians understand ("winning votes" will be a good one but "communicating with voters" will probably be enough) stands a chance of making a sale.
a crisis in the charity sector due a severe drop in income as a result of their inability to write to supporters who didn't return the "yes you can contact me" forms.
That'll be the National Trust in my case. Their effort has a very nastily misleading header on the top of the letter. It's a picture of a very large ticked box beside a headline "Stay in" clearly intended to give the impression that you'd lose your membership if you failed to tick the boxes on the form. Of course it only refers to their mailing attempting to flog me cruises, holiday cottages and all sorts of other stuff I've no interest in so they'll actually save money by my not opting in. I'm considering a complaint to the ICO as it clearly gives the impression that membership is tied to accepting their marketing guff which is contrary to the GDPR. Whilst I'd not like the NT to be fined a public caution might be a warning shot to others.
"The performance targets are badly flawed."
This is almost always the case with performance targets.
Firstly, they have a great tendency to be inappropriate. Measuring things properly is hard. That means looking for something easy to measure even if it's not a big issue and ignoring the hard to measure relevant target.
Secondly, it sets up a system just asking to be gamed.
"Obviously there's the easy go to of the Robin Hood Airport Case. What everyone wrote off as a joke, South Yorkshire Police thought was worth pursuing"
And yes, every bomb threat can be written off as a joke. Right up to the time when one isn't and then everyone from the Grauniad to the Fail will come down on the police like a ton of bricks for not taking it seriously.
"Where, if you lose then you may well find that YOU are having to pay the other sides legal fees as well as your own."
Not if the damages fall within the small claims limits. BigCo then has to decide whether to throw lawyers at the case or pay the claim which is probably going to be the cheaper option. They may, of course, choose the former to avoid opening the floodgates.
"One could ask the same of the vast majority of software packages and features, and never receive a satisfactory answer,"
It depends who you ask. Ask most people who thought, say QGIS (what's that, you've never heard of it?) was for and you'd receive blank looks. But there are enough people who need a GIS (never heard of that either?) to develop it originally and to continue with that.
Another good book pass on to the youngster is O'Reilly's "UNIX Power Tools".
Got that one somewhere as well. Coherent brings back memories albeit only of reading about it in Byte. However, there's a limit to what one can present a 10 year old with.
However, mention of Byte reminds me it might be a good idea to find my copy of the issue on RDBMS from which I learned pretty well everything I know about database design* apart, of course, from what I picked up by actually doing it for a few decades.
*I've encountered at least one CS graduate who knew less than that Byte covered.
"So, there wouldn't be much signal below them anyway."
Now try explaining that to those objecting to near-by mobile phone masts. And also explain that when they connect the mobile transmitter next to their head to a more distant mast it has to transmit at higher power and there's this thing called the inverse square law.
"My phone quite happily connects with my car every day, makes and receives calls using the car audio system"
Connecting isn't the problem. It's not realising it's disconnected when I take it out of the car that's the problem. It ends up in an offline mode but only infrequently so that I never get to learn the incantation needed to get it working again without a lot of trial and error. Or maybe the trial and error is the incantation.
"The popular salt/hash method demands that the password is transmitted plain"
It demands that the password be made available to be hashed for comparison with the stored has. How it gets from keyboard to hashing algorithm is not addressed. It can be encrypted in transit and decrypted to be hashed.
Very much like banks that are so "secure" that they insist on certain characters out of the extent of your password. In other words, they have the thing in plain text in order to compare individual characters.
They ask for a combination of several characters. Let's try this one for size:
- You enter a new password.
- The bank extracts combinations of N characters. Perhaps all possible combinations, perhaps a subset of a long password.
- Each combination is hashed and the hashes stored together with a note of the positions of the characters of that combination.
- When you log on the system chooses one particular combination, asks you for the relevant characters, hashes what you enter and compares the result to the stored hash.
Not only can this be achieved without storing plain text, the system doesn't even store your password as a single entity, not even when hashed.
"gotta wonder what their customers would have thought if they found out all the business and personal information they were sending these people was going to a hosed , not secure in any way, computer."
As a customer I'd first want to know what exposure the computer had to the internet. XP off net vs W10 on net: which would you prefer?
"A 'business' with a few thousand pounds of turn over is clearly not in line to spend huge amounts on a consultant to verify their system, paying their increasing business rates is probably further up their action list."
A business with a few thousand pounds of turnover probably isn't paying huge amounts for data storage in the first place - possibly an old exercise book. It still doesn't excuse them if they write more in it than they're entitled to.
"I'd maintain my position that the new rights and fines will not substantially improve the situation in the real world."
I think the knowledge of this extends well down the scale of business size. The problem is more likely getting a firm grip on sales and marketing pestering departments who have the mentality of 4 year old children including the same response to being told "No".
"If you're, say, a software developer doing the same work/same hours as your colleague in the next cubicle (who happens to have ovaries or any of the other recognised grounds for discrimination) you should both earn the same pay."
You seem to have missed several posts pointing out that as that's the law it is actually the case. Maybe you missed it because it wasn't stated in sufficiently colourful language for you to complain about.
the subsidy the net gets from the advertising industry will have to come from somewhere else
The net existed without it and many feel that those were better times.
Too many people expect everything on the net to be "free" for alternative payment to work
I'm quite happy for them to be disappointed.
Even if faced with a stark "Agree to let us slurp your data or you don't get access" warning, most Facebook users will happily tick the box and go on their merry way.
I think Facebook is too smart (i.e. employ enough lawyers) to realise that that just lines them up for maximum fines rather than being told not to be naughty. The authors of GDPR saw the possibilities of that one and dealt with it
"But you have just told world + dog that you do eat breakfast, and that you go out to eat it."
You believed all that did you? That's the trouble with the data fetishists who pay for that stuff., they can't distinguish between data and fact, let alone information. Intelligence and wisdom are entirely beyond their reach.
"all of which ... is monetisable."
The most valuable thing for advertisers to know about me is that advertising at me is counter-productive. It's not a thing they want to hear, of course, wants and needs being two different things. Would they pay good money to discover that?
"So they probabbly HAVE data about me, but that data is likely to be of very poor quality."
Never mind the quality, feel the width. As nobody has any alternative data about you to judge the quality of what's collected the customers will believe what they've got and pay for it so the phone companies or whoever collects the data in the first place get paid. At some point, however, the customers might finally realise that what they're getting is worth less than they're paying for it. It's a bubble that's due to burst some time.
"A vanity domain you pay for, then you can redirect as you want and noone will be any the wiser."
Nothing vain about it. It's just a more practical solution. If you have your own domain you can move ISP without disrupting your email contacts.
Some years ago my formerly very good ISP fell into the clutches of TalkTalk. At that time I'd used the ISP email. I moved to a new ISP but to prevent a recurrence of the inconvenience of that happening again I registered a domain with a registrar who provided an email service. After my new ISP fell into the clutches of Sky I switched to another ISP.
I also found that eventually my original choice of registrar started getting outages which they never troubled to explain - and seldom troubled to acknowledge to I transferred the domain and email service to another registrar/email provider, again without disrupting my email address.
The other side of having your own domain is that you can set up and tear down addresses as necessary. Anyone I expect to deal with on a regular basis is given an alias I've set up specifically for them. If they start spamming I simply drop that alias; in fact I've the option of setting it to bounce email with a message telling the sender why they're being bounced. I also set up aliases which will only last a few weeks and anyone who doesn't, in my view, need a long term alias gets given the current one of those which will be pulled immediately if it gets spammed.
For a few quid a year you can have a flexible email service that's not, on the one hand, tied to a service provider you can't dump, nor, on the other to a big corporation who treats you as their product.
I have a Hotmail address for situations which demand an email address but where I don't expect any interaction whatsoever and that's treated as /dev/null and a gmail address if I need a Google login which carries no traffic at all.