* Posts by Doctor Syntax

40432 publicly visible posts • joined 16 Jun 2014

Page:

WannaCrypt: Roots, reasons and why scramble patching won't save you now

Doctor Syntax Silver badge

Was XP the problem?

Over on /. there's a report from Kasperksy that actually it was mostly W7 machines that were hit. https://tech.slashdot.org/story/17/05/19/1916257/almost-all-wannacry-victims-were-running-windows-7

Doctor Syntax Silver badge

Re: Remember the Millenium Bug?

"those risks were in fact minimal if not non-existent."

I've trotted this one out a few times but it looks as if it has to be repeated. I had a client for whom I'd got new live and backup ready because the old ones (actually, the old backup server to be precise wouldn't run the Y2K-ready version of their application. We were all tested and ready to cut over between Xmas & New Year. Their beancounters refused to let us go ahead because they didn't want to take the risk!!! of migrating before they'd gone through their year-end closedown of the books.

So for a fortnight we had the application vendor logging in on about a daily basis, maybe more, maybe less, to fix the data corruption we kept getting. It wasn't, therefore, an absolute disaster - a pity as I'd have liked to have had to take them back to the end of December and make them re-input several days work - but I don't think you can count daily remote access to fix corrupt data as a long-term working solution.

Yes it was a real problem. Most people weren't that stupid so didn't get to see what could have happened.

And BTW however much money was to be made out of Y2K not much came may way - 99 was the slackest year I ever had.

Faking incontinence and other ways to scare off tech support scammers

Doctor Syntax Silver badge

Insist you're running Windows 94.

Man sues date for cinema texting fiasco, demands $17.31

Doctor Syntax Silver badge

Re: This guy is about to become a legend

"I think the judge should sentence these two to marry each other to protect the rest of society."

No. Think of the children.

Doctor Syntax Silver badge

They seem like a well matched pair.

Mi casa es su casa: Ubuntu bug makes 'guests' anything but

Doctor Syntax Silver badge

Re: Flaky guest account

Poettering's Law: the idea that as an online discussion grows longer about a flaw in Linux, eventually _someone_ will irrefutably pin the blame on systemd

FTFT

IBM CEO Ginni flouts £75 travel crackdown, rides Big Blue chopper

Doctor Syntax Silver badge

Quite consistent

"Do as I say, not as I do"

Just the same as recommending teleworking to customers.

‪There's a ransom-free fix for WannaCry‬pt. Oh snap, you've rebooted your XP box

Doctor Syntax Silver badge

If it relies on getting the data out of memory would this also be in the swap file if the PC hasn't been restarted? If so then there should be scope for recovering of the disk is taken out and mounted on another running system.

Proposed PATCH Act forces US snoops to quit hoarding code exploits

Doctor Syntax Silver badge

Re: Simple process

Add:

The authority to hoard a vulnerability must be signed off by whatever politician is in charge of the department (e.g. Home Sec or Foreign Sec in the UK) and that sign-off should be made public when the time limit has expired or the vulnerability is exploited in malware.

Doctor Syntax Silver badge

Re: "I'm still amazed that no-one else had found this vulnerability* "

their biggest patch was "Shift toBuy Windows Whatever-is-current"

FTFY and I'm not sure their intended benefits extended anywhere beyond themselves.

Doctor Syntax Silver badge

Re: Is what we might learn about the terrorists worth risking people's lives for?

@WatAWorld "If you patch the NHS computers, civilian computer types are going to know..."

Which is why I said the "suggestion" would be to block SMB at the firewall, which can be justified for other reasons.

Blocking SMB at an external firewall would be effective against external scans. If you're running SMB internally because that's how your network works and the malware is distributed by phishing scams than it really doesn't help very much.

Windows 10: Triumphs and tragedies from Microsoft Build

Doctor Syntax Silver badge

Re: "I'd like to employ Microsoft F'CU (NT) S to help clean up this Ransomware mess"

A "Windows skin" for an underlying Linux codebase is where the solution is, Microsoft.

No. Let MS keep their own mess. Don't import it to Linux.

Doctor Syntax Silver badge

Re: "Focusing"

Bob,

If you're against things that cause eye strain, pleas give the caps & exclamation marks a rest. Just make the effort to type normally like everyone else.

Doctor Syntax Silver badge

Re: Business users

"It is an in joke. You have to be in the group to know what it means."

In jokes limited to a group are not the best approach to wider communication although I'm not sure wider communication is Bob's intent.

Bloke charged under UK terror law for refusing to cough up passwords

Doctor Syntax Silver badge

Re: There's 2 sides to stories

"So, technically, on the face of it he's not innocent; he didn't hand over his passwords when asked and there is a statute in place to prosecute him as a result. Whether that's right or not is another matter."

In this country there is, theoretically, a presumption of innocence. Making it an offence not to hand over passwords without good reason sets aside that. If there is reason to believe that there might be something incriminating locked by the passwords then the appropriate course of action is to present that evidence to a court and get a warrant. It's called due process of law. It seems that having given the idea a trial for 8 centuries (hint: look up what happened in 1215) we seem to have decided it wasn't a good idea and ditched it.

Dell BIOS update borks PCs

Doctor Syntax Silver badge

"Dell's initial reaction was to tell customers they needed to buy new motherboards."

Sorry but if Dell Command Update offers you a BIOS update that then bricks the chip it is your responsibility to fix it Dell.

Presumably it was someone on work experience who gave out that advice. One hopes the grown-ups took over after that.

EC fines Facebook €110m for 'misleading' data on WhatsApp deal

Doctor Syntax Silver badge

"they're not that concerned about privacy in the first place."

Or even worse - that they're not aware.

UK.gov plans to overhaul £6bn in big IT deals 'watered down'

Doctor Syntax Silver badge

Re: Public sector IT

"I think I've found the problem"

I think you've found two.

Doctor Syntax Silver badge

"a lack of will by the Government Digital Service under Kevin Cunnington's leadership"

Was that all that was lacking?

Latest example of GDS's efforts: go to site to make an appointment suggesting several different slots which,according to the online diary, were available. A few minutes later there's a call back to say none of them were available; the office diary isn't linked to the GDS online version which is consequently out of sync with reality.

Self-driving car devs face 6-month backlog on vital $85,000 LIDAR kit

Doctor Syntax Silver badge

Re: Once upon a time

"When stuff like tellies in the home were too expensive to buy, people got them on the never never instead."

Your ability to pay off the TV loan didn't rely on your watching the TV so it can be assessed on your earning history.

The ability to pay off an R & D cost relies on the outcome being successful to create future earnings. That means there's no history on which to rely. You won't be able to go to a hire purchase company for that. The people who'll be lending money on that scale in that sort of way are going to want your first-born a slice of the company. It's called venture capitalism and the pre-IPO spin and PR are also factors in the VCs being able to get their money back. They won't see R&D and PR as alternatives, they'll see them as complementary.

Doctor Syntax Silver badge

Re: I don't know...

In order to perceive distance you first have to perceive the objects in the visual field. That in turn involves edge detection. Then you have to correlate the relative positions of the objects as seen from the two eye points and the feedback from the muscles controlling the eyes. It's all massively parallel - some of the processing seems to be done in the retina itself. And none of it is conscious so I'm not sure that the I bit of AI applies.

Doctor Syntax Silver badge

Re: I wonder...

The precedent that it "should" work is that it is how us humans do it.

The way we humans (and bats) do it is by having massively parallel processing available. You're right to point out that it's not only distance but also speed that matters. Both of those give timing and that matters even more. You don't mind occupying the same piece of road that another car will occupy but you really don't want to occupy it at the same time.

You think your day was bad? OS X malware hackers just swiped a Mac dev's app source

Doctor Syntax Silver badge

Re: Lost ?

Lost absolute control until he could change the credentials. And lost control of a copy of how it was at the time the repository was cloned.

And the moral of this story is that you should use a password manager although that still won't protect against a key logger.

Hyperscale data centres win between their ears, not on the racks

Doctor Syntax Silver badge

It's all easily explained

Just go back and look who these guys are working for. Gartner.

Backup crack-up: Fasthosts locks people out of data storage for days amid WCry panic

Doctor Syntax Silver badge

You're not going to be able to blame Jeremy Hunt for this one.

Britain shouldn't turn its back on EU drone regs, warns aerospace boffin

Doctor Syntax Silver badge

Re: ECJ/ECHR

"it is freedom from the ECJ that tends to get emphasised at the moment."

That's the easier one for her to deal with. ECHR raises issues with the Good Friday Agreement. But with the two sectarian parties supposedly sharing government in N Ireland falling out and all sorts of questions over the border she might be able to weasel out of that one as well.

Doctor Syntax Silver badge

Re: Confused....

"So... because we might want to fly in the EU, we should adopt their regulations? That makes no sense whatsoever. What rules we follow domestically does not dictate the rules we follow in other countries."

IFAICS what you're saying is that instead of having one set of regulations we could have two? That'll simplify things, take back control, cut red tape and [insert pro-Brexit slogan of your own choosing].

Doctor Syntax Silver badge

Re: Here be snowflakes...

"I dont understand where the problem is. Before the EU we wrote our own regs. Our own regs are so good the EU adopted a number of them. How is this a legitimate problem? Or do you have some kind of xenophobic problem that people in the UK are too thick to function?"

From TFA: "The [UK's Civil Aviation Authority, the CAA] hasn't got the capacity or the expertise to provide an effective standalone aviation regulatory organisation. It did have, 20 years ago, but we've sacked three quarters of the people. And the expertise... has gone to join EASA,"

Of course we could try offering suitable salaries to tempt them back. Repeat that over and over for each situation where that happened and see how much change is left over from all that money we save by not paying into the EU budget.

Azure becomes double DaaS-aster zone as VMware loads up

Doctor Syntax Silver badge
Mushroom

Azure becomes double DaaS-aster zone

You've done it now. I'll never again be able to read DaaS as anything but Disaster as a Service.

Clouds' crazy kinks can spin your wheels and lead you to mistakes

Doctor Syntax Silver badge

"He instead counselled connecting all offices to a cloud exchange, over one link, and letting the cloud exchange handle links to clouds."

I think the technical term for this is "single point of failure".

Management's agile, digital (insert buzzword here) strategy ossifying? Blame the Red Queen

Doctor Syntax Silver badge

Did he say anything? I vaguely remember some sort of contrived simile and then I nodded off.

Police anti-ransomware warning is hotlinked to 'ransomware.pdf'

Doctor Syntax Silver badge

"Maybe OS could become a little more clever"

As in https://linux.die.net/man/1/file and https://linux.die.net/man/5/magic both of which are long time inhabitants of the Unix world.

US judges say you can Google Google, but you can't google Google

Doctor Syntax Silver badge

Re: National modding

"That's a non-word, unknown in dictionaries, so I don't need to use uppercase."

Sorry but: https://www.collinsdictionary.com/dictionary/english/guggle

WannaCrypt 'may be the work of North Korea' theory floated

Doctor Syntax Silver badge

Re: Naive Question

"All said, simple win32 program from NT era will generally still work perfectly!"

And simple web sites run on any browser.

It's always the same; folk who try to be clever end up being too clever by half.

Doctor Syntax Silver badge

If it's right the Little Leader might find himself "invited" on a state visit to China where he will be taken suddenly, mysteriously and fatally ill.

Do we need Windows patch legislation?

Doctor Syntax Silver badge

Re: "The NHS had 70,000 Windows XP PCs"

the often quoted "90% of NHS Trusts still running XP".

And that in its turn seems to have come from a survey - I think a year or two ago - of trusts running at least one copy of XP. The fact that this might actually be just one is beyond the grasp of our mighty national newspapers.

Doctor Syntax Silver badge

Re: Eternity

"The obligation to correct defects in a product that should never have been there in the first place should never expire."

It's also an obligation that might substantially reduce the number of such defects in the first place.

Doctor Syntax Silver badge

Re: Somebody should be fired at your NHS

" In addition to being resilient to attack a VM can run on modern hardware, it's not limited to antique machine like native XP."

You do realise, don't you, that in some cases you're dealing with real time S/W that twiddles bits directly on specialised H/W?

Doctor Syntax Silver badge

"But the problem is not so much that support was stopped for XP, it's that hardware like this should never have been based on XP in the first place. It isn't Microsoft's fault; it's the fault of the developers of the hardware."

The developers were probably in a bit of a bind themselves. The introduction of commodity H/W and S/W killed off the minis and Unix workstations that were used previously. Even if it hadn't it would have enabled competitors to have undercut any who still used such kit.

What would have helped would have been the certification authorities requiring long term support. That would have either required MS to offer it or, if they didn't, would have levelled the playing field and allowed specialist workstation manufacturers to survive. That in turn would have needed the certification authorities to have anticipated the situation we now have.

Doctor Syntax Silver badge

Re: "ultimately this means that the end user can take control"

"But I know many coders who can do that kind of thing easily. And do."

And write a distributed version control application in passing.

Doctor Syntax Silver badge

Re: Who is going to do the maintenance?

"To provide full support for all its old systems MS would have to have large numbers of programmers trained up in those systems (no one person can know more than a small part of code that big)."

They could save money. They could ship better code in the first place.

And your general thesis founders on a single fact. They have already issued a fix.

Doctor Syntax Silver badge

Re: Beancounters

What the beancounters probably choked on wasn't upgrade or replacement of client platformss. It was the rewrite of the whole client/server system so that the clients didn't depend on running on XP.

Doctor Syntax Silver badge

Re: Support it - or Open Source it

"So how do they open source the code without revealing 80% (guess) of their code still used?"

They can't open source it in the FOSS sense which I think is what the OP meant.

What they can do is put the source code, including patches, into escrow. If the vendor turns their toes up or if they cease support then the source can be released to specified interested parties wrapped up with whatever conditions were mutually acceptable when the original transaction was entered into. I've seen that made a condition of an RDBMS installation.

Another option would be to make the source available to interested parties all along under NDA conditions. I've had one gig where part of the source was exposed like that, the user interface being the main part that was concealed. It served the vendor well as they got free debugging.

Doctor Syntax Silver badge

Re: Reluctantly

"However you cannot expect a vendor to continue to support the product indefinitely since it is in no way a cost-free activity."

We're looking at a fault which should never have been present in a shipped product. Are you saying that if they manage to get away with it for x years they get a free pass if it brings the house down in the future?

Doctor Syntax Silver badge

"Yes it is slightly more complicated, but once you've worked out the details you can semi-isolate lots of similarly challenged pieces of kit. (Perhaps the chaps at http://www.nhsbuntu.org could help you set it up.) Yes, it isn't perfect isolation, but it is a perfectly valid component in a layered defence. Yes, it is a pain in the butt,"

And yes, it it impinges on any certification the original machine requires than either you've got to hold off for a few months while that's sorted out or simply shut down for that period.

Doctor Syntax Silver badge

Re: @alain williams

"Those PCs were sold with Windows 7 Professional + downgrade rights to Windows XP, so there weren't even any licensing issues about upgrading and getting continued support."

The PC and its OS in such a situation is likely to have been only a component in a larger system, a system which required XP because some client/server application were the client end won't run on a later version.

You inevitably end up having to consider a more complex situation where simple solutions don't work. Yes, tou could argue that the original system shouldn't have been put together that way. Maybe it wouldn't have been if the original developers only knew what a later OS version was going to break.

Doctor Syntax Silver badge

The real world is much more complex than all these "simple" solutions everyone keeps coming out with can handle.

Another characteristic of the real world is that evaluating each "simple" solution for each individual case takes time. Half a dozen individual installations with unique, complex requirements could take a lot longer to update than a large office of routine desktops with a common build.

Doctor Syntax Silver badge

Re: Forced to support forever

"Of course 16 years is too long to expect a company to support a product"

There's a difference between supporting a product in terms of adding new functions or drivers and fixing a defect which was present when the product shipped.

But let's not lose sight of the fact that when the shit finally hit the fan MS made a fix publicly available within hours.

If they were under no obligation, it was too long to expect them to do it etc then why did they do it?

I can think of three explanations:

1. It was to mitigate a PR disaster.

2. Events brought it home to them that they had a moral rather than a commercial responsibility.

3. They anticipate legal action and are attempting to mitigate any penalties.

I don't think the last one flies - it simply points out the fact that they'd held back something that could have been made generally available.

But let's not lose sight of the fact that for whatever reason they have done what lots of commentards have said they didn't have to do.

Doctor Syntax Silver badge

Re: All products have a support life

"OTOH should we also be looking at the suppliers of MRI scanners etc which are often blamed for being the cause of 'staying on a known OS'. They ought to be obliged to release software for newer versions of their chosen OS (whether that's MS/OSx/*nix/*BSD/....) for the expected lifetime of the machine (probably more than the expected life actually)"

A recent post by an engineer who's worked on such kit suggests that this is by no means straightforward and you could actually brick the instrument by getting it wrong. At the very least you'd have to re-certify the new combination.

Doctor Syntax Silver badge

Re: Lawyers

"As far as I can see it also went to those who used a well known registry hack to continue support for XP!"

That wouldn't be a viable option for anyone who needed to maintain some sort of certification.

Page: