Re: Just an ICO probe?!
"And that's just with my commercial-grade network security in place; I can only imagine what MI6 have set up for parliament."
There is one thing. It's police property.
42414 publicly visible posts • joined 16 Jun 2014
"And that's just with my commercial-grade network security in place; I can only imagine what MI6 have set up for parliament."
Very much less, I'd think. For a start MI6's role is foreign intelligence so it wouldn't be their job at all. Also, if Parliament is sovereign who are MI5 or GCHQ to tell them what they can and can't do?
"Cost of benefits, because he can't get a job afterwards."
He still has a criminal conviction against his name.
One shortcoming of the the rehabilitation system is that a number of supposed rehabilitees seem to get away with failing to meet their obligations with no substantive escalation of punishment to deter this. There are a surprising number of instances reported in the local press where so-and-so has missed appointments with probation officers/failed to turn up for their unpaid work/whatever and simply get a further term of whatever it is they're ignoring added or maybe a week or two's curfew.
The courts presumably think they're sending the message that the offender can't get away without extra punishment. The offender receives the message that he can continue without being punished. The first law of communication: the message communicated is what's received, not what's transmitted.
"Beyond that you implore your boss to tell their boss his users are not competent and need training / redeploying and its not his or your problem."
It depends. If it was your department's decision to replace the familiar with the unfamiliar then perhaps it is your problem.
But in general, use of the software is just part of the user's job so training the user to do their job including the software should be part of the user department and, although you might help with it, any written document should be the user department's work and cover the whole job instead of the IT aspect being taken out and documented separately.
"That is what they inherited or were gifted."
I think you're trying to say it's what the shareholders bought at privatisation from a government that didn't want to invest more in building up the infrastructure. And, of course, you're ignoring all the investment BT put into it in the intervening decades. Or do you think all that fibre was in the ground back in the '80s?
Remember the howls of anger when it took a few weeks to go to court to establish the correct legal process to pull the trigger and how this was delaying "the will of the people"? It's becoming increasingly clear that the lead time to accomplish this is stupidity should have been years just to work out what's needed.
"It will be like the millennium bug all over again, nice pay, good bonuses, resulting in tax revenue."
Except that the Millennium bug was fixed. Apart, that is, from the odd numpty business who insisted on running their old system into January because "year end"; that was - interesting. I reckon this is going to be a lot more interesting.
"I simple don't understand why the rules should allow tacking one (or more) distinct, unrelated items onto a bill."
It's got a long and not entirely shining reputation. In Westminster, back in the days when divorce required an Act of Parliament one way to do that was to tack on a clause to some other Act.
Being generous - it's Christmas - let's suppose for a moment that the TT management realise that they need to provide customers with a safe, reliable service, allowing for the fact that the bulk of their customers aren't going to be anywhere near the upper quartile of IT-savvy.
Given their starting point of having had their customer data breached multiple times, how do they do that?
Won't this mean that even more businesses will put customer data directly onto the Internet so that requests for what is held can be automated and sent to the applicant?
Only if they're stupid. For the reason's you mentioned, of course. There's a primary requirement to take care of the data. Putting it "directly onto the internet" would be the opposite of that. That doesn't, of course, mean that stupidity in business management doesn't exist. Some people only learn the hard way. The increased fines just raise the cost of being stupid.
Isn't it just a tax without any benefits to the end user?
Tax? Complying - which is what they should always have been doing, is just a cost of doing business. And "end user" of what? What you should be thinking about is "data subject". And the data subject could be a customer, a supplier, a patient, an employee ... Everyone about whom you want to hold data. If doing things right is too expensive don't do it at all. Don't hold data that you don't need. That is and always has been one of the principles of data protection.
Data Protection was the same, seemed like a good idea
What do you mean "was"? It still is Data Protection. That's what the DP in GDPR stand for.
world plus dog used it as an excuse for "I can't tell you that because of data protection laws" and it became a barrier for getting hold of useful information.
I'm not sure if it's specifically dealt with but wrongful invocation ought to be an occasion for judicial remedies. A good reply to anyone trying would be "I've got the entire text of the Regulation on the computer in front of me. Could you please refer me to the passage to which you refer? If it helps I'll read the entire thing out and you can tell me when I get to the relevant passage".
"If it's possible to access private date of multiples in clear text from an employees email system, you're already doing it wrong and nothing will save you. That's not designed for safety, that's designed for disaster."
For high value targets the object of spear phishing isn't to grab the employee's email. It's to subvert that employee's machine as a beach-head to work their way into the system. If you don't allow for that you're doing it wrong.
What nobody's managed to say: you can have all the policies in the world but if one eejit clicks on the wrong thing in a booby-trapped email which leads to a breach it's all for nothing.
So what do I make of a bank that causes an email to be sent out that looks exactly like a phishing email* with 12 clickable links in it and claims to be advice to say safe online? Clearly this was devised by a team** of numpties none of whom would see anything wrong with clicking links in spam let alone recognise a phishing email when it arrives in their in-box. Apart from training their customers to be phished they are imminent dangers to their employers because unless they have been safely firewalled off from the rest of the business they are liable to let any passing scam artist into the building.
* It pretends to come from a bank but actually is from a 3rd party digital communications business spammer and the links also resolve to the same 3rd party.
** Nobody gets to spend the budget on their own, do they?
Google is a mere beginner at confusing people. Genealogists have been at it for centuries resulting in people allegedly becoming parents after they'd died - and probably before they were born as well. It's not easy matching names to construct profiles of people. Perhaps they should have tried it out on historical data first and then rolled it out slowly - and stopped when they discovered what a pig's ear they were making.
"AND THEN I MAY FINALLY BE ABLE TO MOVE OFF ADSL!"
Let's say OpenReach drops roll-out of FTTC and concentrates instead of extending FTTP to those areas where it already has fibre in place, namely those which already have FTTC. Does this shorten or extend the time needed for you to get off ADSL?
Meanwhile, over on the Beeb I see the US is blaming the Norks for Wannacry. http://www.bbc.co.uk/news/world-us-canada-42407488
Here's a quote from them: "The tool kits of totalitarian regimes are too threatening to ignore." Just how much brass neck does the US have?
Ace reporting from the Beeb: as far as I can see there's no mention of the basic toolkit having come from the NSA.
"So Kaspersky's theory is that the US Government is somehow required to have Kaspersky AV software installed on their computers?"
Where does it say that? The complaint is about not even being allowed to sell in competition with other suppliers.
Competition. The great American principle of free trade. Remember that this is the country that goes after its corporations' foreign competitors on any suspicion of state aid. This one stinks of state aid (OK, anti-aid but it amounts to the same thing).
"Not sure in this sort of situation they need to conclusively prove you operate at the behest of a foreign spy agency, or potentially provide any proof at all."
What they should have done was depersonalise it - just say US suppliers only. It's calling out a specific supplier that can cause them problems.
Followed rapidly by "Wouldn't it be better to have them both read/write?" heads. And that followed by "That's what they've done". Followed in turn by "But they've only addressed half a cylinder at a time. Why didn't they make two separate arm sets and make them full height?".
"Hydrogen baloons with lit fuses floating at the ceiling - you name it."
Beginners! We had a means of inflating balloons with town gas (coal gas). Blotting paper impregnated with sodium chlorate as fuses and several match heads as dets. There were launched outdoors from the bottom of a deep, narrow valley after dark. The bang echoed nicely and the burning match heads arced across the sky.