Re: Cheers Tory voters - United kingdom = worst kingdom
"You already need one to work legally."
In my entire working life I only needed a passport for a job once. That was a contract which involved going on site in Italy to install S/W.
42530 publicly visible posts • joined 16 Jun 2014
"non-British ISP's and network providers ... will almost certainly exit LINK "
Easier said than done if they require the facilities it provides. They'd have to replace the facilities it offers outside of the UK which will presumably take time. Most likely they'll insist on LINX pursuing any such order through the courts, if only to give themselves time to be able to route round the damage.
"LINX have proposed no such thing at all"
Follow the link to the gGovernance review PDF in the article. Check that the URL is indeed on Linx's site. Download the article. Go to page 7. Read. You will find out that this is exactly what's being proposed and for the reasons in the article.
"This has nothing to do with patriotism and everything to do with power."
True but then you go off-course.
May loved the referendum result. It's brought her to power and given her the opportunity to do as much as she can to evade European jurisdiction which would limit her ability to implement the Home Office's policy on surveillance. Did you, pre-referendum, see her giving any more than the minimum support to Remain that would be required to keep her job on the assumption that Remain would win? Hard times for everyone else post-Brext? Why should she care, she's got the foreman's job at last.
"If you voted Tory you voted for this regardless if you knew it or not."
I think it's been HO policy for a long time and they usually manage to have Home Secs go native. In general common sense in the rest of the govt held them back. We now have the misfortune to have an ex-Home Sec as PM, first time in a long time. It could be worse - think what happened to the economy last time we had an ex-Chancellor as PM.
Were you referring to this statement:
"the most popular graph DBMS by some magnitudes is Neo4j, followed by OrientDB and Aurelius's TitanDB graph databases"?
If so let me repeat it again with one word emphasised:
"the most popular graph DBMS by some magnitudes is Neo4j, followed by OrientDB and Aurelius's TitanDB graph databases"
"I think the defense attorney could have spun this as a non-authorized penetration test"
Indeed, a defence lawyer's job is to spin any defence that offers itself. There's not guarantee it will be accepted and if that one succeeded the court would need to provide a runway for the pigs.
@eldakka
Thanks for that. It means that if this system issues debt letters solely on this basis it's not fit for purpose. As I explained in a comment above the acceptable rate for false positives is zero and what you describe cannot avoid false positives.
In a human-operated system a case would be built by one team, e.g. police, and passed to a second, DPP, CPS or whatever for review before it gets to court. The second team and the court itself should act primarily as checks on the first team's work, not as an excuse for the first team to get away with sloppy work.
In the system you describe the output should be no more than a list of cases to be checked against the original fortnightly data. It should not be possible to issue debt letters which do not give the dates and figures for the incorrect payments.
"Whether 99% accuracy is a good result or not depends very much on the split between false positives, false negatives AND the underlying base rate "
Where the decision leads to legal action the acceptable error rate for false positives is zero. If you were accused of some offence of which you were innocent would you consider it OK to be found guilty and incarcerated providing the false positive rate was considered acceptable?
False negatives are trickier. A false negative can also lead to injustice* beyond the occasional guilty party escaping on grounds of reasonable doubt.
Such high standards makes criminal investigation a stressful occupation for anyone taking it sufficiently seriously.
*A complainant of assault being wrongly disbelieved could come into this category.
"common-or-garden SQL database?"
They were solving that even before relational databases were a glint in Ted Codd's eye. They were solving it in the days of tape-to-tape. They were solving it in the days of mechanical accounting machines. They were solving it the days of quill pens & paper. It all goes to show that if you want to fail really badly, use a computer.
Pleas hack his "smart" phone, install keyloggers and crack his twitter account... install some voice capturing software that is permanently on
What makes you think that hasn't already happened?
send some nice postings like "I am so soryy, Hillary" or better "Hi Mexicans, I luv u all!"
That's just skiddie stuff.
"Here the government is the best customer you can have if you want your invoices paid on time."
One client of mine doing work for HMG billed one of their clients by EDI. The client's EDI server had been down for a few weeks before they got round to telling them. I also spent a long time analysing the far from clear self-billing of another of their clients, trying to reconcile it with work done for them.
I have a Hotmail A/C which is mostly used for people I expect to be spammers (hello Tickemaster) or in situations where it's likely to be harvested. It frequently gets a few emails sending me "invoices". My son may have to go the the US later this year. I may let him have the password for it and hope they try to download and open a few of those nasties. I'd just have to move them from Junk to Inbox...
you're meant to be "tech" people (whatever the hell that means this day of the week) or sysadmins etc
It might have escaped your notice but there are now several people who aren't network admins, sysadmins, DBAs or whatever who actually have internet connections to their homes.
In fact there are a lot of them.If IPv6 is ever going to be rolled out it's got to work, work well and work securely for all these people as soon as they lift their router/firewall/whatever-naming-hair-you-want-to-split out of its cardboard box. When I read comments about how any competent sysadmin should be able to set up IPv6 routing I know this issue isn't being addressed and a successful roll-out is just receding into the distance.
"This is a really naive attitude and it is exactly this attitude (and ignorance) that makes the IPv6 transition so difficult."
What makes the transition so difficult is an almost will-full refusal to look at the the problems it causes on the ground.
"This is not a problem with IPv6, but instead with your network topology. Put them on a VLAN that doesn't route to the Internet, or use a firewall to prevent traffic to/from them."
Right. Tell me how Joe Soap, who can't put his webcam on the net without getting it bounced into a botnet within minutes is going to accomplish all that. Because that's the core problem.
"No, I'm pretty sure that most people do want their stuff on the internet."
More likely people want the internet on their stuff but not necessarily the other way around. They want to connect their laptop, desktop, tablet, phone etc to the net. What they don't want is Joe Random on the net connecting to the above. It's a one way thing.
A smaller set of stuff doesn't get connected either way - my printer and NAS don't need to see the net, nor do they need to be visible from outside.
Then there's another class of stuff that some folk do want on the net: their Nest, their webcam etc. And just look at the problems that's causing for everyone else; most of us would be happier if none of that had got on the net. It's been a big illustration of the problems that happen when Joe Random can connect to their stuff.
The first case has been handled well by IPv4 & domestic routers for a long time and a part of that is that NAT ensures that the individual device can't be directly addressed from the wider net. At the same time the services behind the router/firewall/whatever can talk to each other; I can print from my laptop or exchange files with my NAS. Somebody in another comment mentioned NAT breaking end-to-end routing. That's just what these use cases need.
It's these first use cases that need to be addressed simply by IPv6. Being told that address randomisation answers users' concerns by preventing being tracked is a failure to understand the issue. My printer isn't going to be tracked anyway but what I don't want is someone coming across my printer on its current randomised address and either dropping a load of stuff to be printed just because they can or taking advantage of a zero-day to enrol it into a botnet.
"Is it just me or does Linus tend to have a lot of process problems"
It's not just you as others seem to come to the same conclusion. It's a consequence of your looking at the exceptions, not the rule. Consider the situation:
- He has a huge number of contributors
- He's probably never met most of them
- He never recruited any of them
- He doesn't employ any of them nor work for a company that employs them
- He doesn't provide any annual assessments of them
- He doesn't recommend pay levels
- He can't fire them
If you were in that position and responsible for a project of such magnitude what management tools would you have to hand and what process problems might you experience?
@anthonyhegedus
I think there's something in common in all these. People need an OS to just work and just keep working. They want it to be secure - and that includes not being snooped on by the vendor
The claimed rationale behind W10 actually fits the first of these: rolling updates to accommodate new H/W, fix bugs and occasionally meet new requirements and standards in IT.
What's not good is the implementation The initial release should have been fit for purpose and updates should have maintained this status. There is plenty of evidence that that isn't so.
The idea of giving feedback from users about performance as an aid to this is reasonable. Again the implementation isn't; if I have a KDE application crash, for instance, I can choose to have it send a crash report, if I'm using Debian I can choose to let my installation participate in popcon. And then there's the appalling privacy policy of W10.
Here's the real rub: running R Services in SQL Server 2016 is running analysis on your transactional databases. That's your live database, your R code is running inside your production database, eating the CPU cycles and disk access, slowing down your expensive SQL server.
You could use a second server to run R, but then you've got the potential network bottleneck of moving the data back and forth between the machines.
That's only one of the problems. The data inside a transactional database is not designed for analysis; it's likely to be dirty, inconsistent and full of errors.
Let me second Joe's comment about dirty data.
Apart from that, you can always restore your transactional DB backup to your analytical server. That way you get real data and test the restore procedures at the same time. There may, of course, be other issues with this - such as data protection - but the objection as quoted really doesn't stand up.
However:
1. Is this PDF a draft or a final document? Even at a glance the number of bad page breaks suggests that nobody has proof-read it. On a more detailed reading there are places where the wording could be significantly improved. A particularly egregious example is A CISP may choose to declare only specific of its cloud infrastructure services as adhering to the Code Requirements.
2. The code provides regulation of the location of data processing to be within the EEA. It doesn't address data sovereignty fully. If the CISP is owned by a non-EEA entity it might find itself subject to the sorts of demands as we see in the Microsoft and Google email access cases in the US. There needs to be a requirement for something like the Microsoft/DT trustee arrangement or the DC being operated by a wholly EEA company under franchise from the foreign business.
3. There's provision for self-certification. This needs to be restricted. For instance I use a small data registrar & hosting business for my personal email; it might be unreasonable to expect such a business to be economically audited by a 3rd party. The Microsofts & AWSs should be, especially when data mining is also part of their business.
4. The code states that security of the guest OS is solely the customer's responsibility. The customer should be responsible for not letting in malware or whatever but if the OS is initially installed by the CISP from their own build or profile they should have a responsibility for ensuring that that install is clean.
Would it also be too much to ask that data controllers, the CISPs' customers, have a similar code of conduct including an undertaking to only use CISPs who abide by this code of conduct?