Re: If they cared about security at all
"And if they cared about security AND gaming at the same time?"
Life's a bitch.
42414 publicly visible posts • joined 16 Jun 2014
"Upgrades are not always improvements."
Quite so. That's a good reason to stick with LTS systems as far as possible. It reduces the number of occasions you have to spend time chasing after someone's failure to maintain backwards compatibility. Bleeding edge distros are fine if you want to play with them. If you want to get stuff done use an LTS for as long as possible.
"This gets really, really bad when you consider that a lot of distros keep the kernel version stable and just backport security fixes."
If I use version N of the kernel because it supports my hardware and has the features I need why would I want more than security update providing those come at regular intervals? I'm old enough to remember that upgrades all to often means breakage and have no intention of having to keep fixing things because someone somewhere couldn't be arsed to pay attention to backward compatibility. That's why I like Long Term Support versions.
So here's Debian 7, not at LTS (staying pre-systemd) and the current version is Debian 9 (equivalent to 10 in Microsoft numbering ;). What's the kernel number and what's the date the last version arrived? 3.2 and just over 2 weeks ago on 20th of September.
"They have over 2 decades worth of experiences of dodging that one. That's why they have these exabyte-sized conditions you have to agree to."
Whether these EULAs are worth the paper they're not written on depends on your jurisdiction and status (consumer vs professional).
Try to remember, this Khosla dude will be just as upset at a lone jogger on "his" beach at sunset as he would a major twelve-dozen keg barn burner with The Who's sound system cranking multi-genre, multi-decade rock&roll for three days
Not saying you're wrong but it sounds like a statement that could be tested.
surely it would of become very obvious once the robot went to retrieve the tape from the drive, and failed because 'I can't find the tape!'
The article describes exactly this except that the tapes were missed on the shelves and didn't get as far as the drives.
Even tapes that the team put on shelves by hand weren't being detected.
“The robot sometimes even tried to place other tapes in those 'empty' slots,”
I complained to "bitdefender" because with their new enforced fucking "cloud" system, not only can they "snag" files. (never used to happen with the standalone version, which they discontinued)
I believe Bitdefender are a UK company. Assuming you're also in the UK invoke your rights under the DPA or, better still, wait till next June & hit them with the new, GPDR-enabled Act. And in the meantime, don't use them. "Cloud" should have been a warning to stop right there.
"For the thousandth time, counting CVEs does not indicate relative security levels."
Doug, there's no point in trying to explain things to A/Cs spouting the MS party line. They're only doing what they're told. You don't expect them to actually understand any of it do you?
"the very probable fact that, spook or no, management will be using Windows and management wants their time sheets, planning, expense reports etc done on time. I haven't heard of a lot of Linux versions of the products that handle that, so you'll be most likely using Windows for all that stuff."
Management should be using what the organisation's security bods specify which, you'd hope, would be something more like Open BSD. LibreOffice will run quite nicely on BSDs so I can't see any problems with the sorts of management stuff you mention.
"t'll probably cost less to deal with the fallout than to actually do things right."
Pay and cost, at least monetary cost, are two different things. It may cost the vendor money to do things right but if they don't you may pay - with your life.
Of course, there's always the other aspect of it: if the market is properly regulated you, as a vendor, don't get to sell your product if you're not doing things right so you don't get any money at all. And as it's the same for your competitors you're not at a disadvantage by doing things right. The only way to disadvantage yourself would be not to spend the money in the first place.
"It would be possible for someone to have their personal credit card details accessible on a company PC for booking hotels etc on company business."
That's one category of information I don't have to keep on a PC. It lives in my wallet.
If, however, there's stuff that I think should be kept private it can go into something like Keepass. Even if the disk is encrypted on a company laptop having a separate encrypted file to which the company has no access would have solved the problem. It would also solve the problem of the company backing up the laptop onto their own servers.
"But the fear of multi-million or even billion dollar jury verdicts will help keep them in line. Even with government regulation, such threats are the only reason they even obey the law any ways."
Proper says that the vehicle model has to meet safety standards to be offered for sale. Failure to take the money in the first place is an even more effective reason to obey they law than fearing it being taken away again.
"This is why:"
Hmmm. And you think an autonomous car will do better? I think the real reason why is lobbying by companies that want to sell autonomous cars. There'll be an awful lot of profit sales to be made before there's a real handle on whether they really are safer and if the final decision is that they aren't then the companies still get to keep the money.
"One is the reduction in accidents as most accidents are really due to some form of operator error/stupidity."
As human drivers generally drive very safely (I don't know about US figures but as far as I can make out the fatalities in the UK must be of the order of one per 100 million* miles). This is a pretty tough target to set for an autonomous vehicle. In fact, the figure suggests that accidents are corner cases, the driver failing to cope with an out of the ordinary situation. Experience suggests that dealing with corner cases is something S/W isn't particularly good at. In addition inexperienced drivers are more likely to have accidents than experienced drivers. One should reasonably expect experienced and sober drivers to be somewhat better than the average. If I were to trust my life to an autonomous vehicle I'd want it to be at least as good as an experienced and sober driver; I have no confidence that this will be achieved for a long time if ever. Meanwhile I'm quite happy for an experiment like this to take place somewhere where I have no intention of ever being so the US fits that quite nicely.
*I base this on there being c 30 million vehicles in the UK and c 3,000 accidents and assuming 10,000 as the average mileage to get an order of magnitude figure.
I'm not clear as to exactly what Dave was recommending here. If he's suggesting - or it gets interpreted as suggesting - that the business just sign up for a bunch of gmail or outlook or (let's really go for it) TalkTalk or Yahoo addresses then it's not particularly a good idea. Because that looks so professional. At the very least go with a mail provider who can provide you with email addresses on your own domain.
Isn't it amazing that all these allegedly net-savvy SEO specialists don't have their own company domain but spam from gamail.
"I don't need to understand how encryption works to understand how it's helping – end-to-end encryption – the criminals."
What needs to be fed back against this is that it's simply a tool and like any other tool, has its good and bad uses. In this case its good use is the securing of everyday commercial transactions. In trying to destroy it you are helping criminals Home Secretary.