Re: 100% success record
"It's worth a shot - honestly, try it."
OTOH £10 on a PAYG SIM lasts a long time if you have a fixed line.
42273 publicly visible posts • joined 16 Jun 2014
"Most of them give up after five minutes, lightweights!"
I just leave the phone for a good while & then hang up; usually they've done that themselves. But I did have a very persistent/dumb company (double glazing, of course) where the sales manager rung back to say the line went dead.
"That's why banks still hand out those calculator style gadgets."
Mine handed out one and I still have no second factor.
The only time I had to use the useless piece of crap their site refused to accept the result so I had to go into a branch.
"There are some who will let you buy things without creating an account, and since retailer accounts seem to be used mainly so that a: they can remember your credit card number and b: they can send you marketing emails, frankly if such an option is offered, I'll take it."
I use frequently changed email addresses to kill the marketing emails if I have to create an account.
Like you I prefer accountless transactions and using PayPal is one way of ensuring they don't keep the credit card number but the downside is that PayPal provide your PayPal email - which is also the PayPal login ID - to the vendor. I've had to change my PayPal address twice because of this. I took this up with PayPal; from what I was told they have T&Cs to forbid this but can't be arsed to enforce them. Bastards - twice over!
"Devil's advocate here, but don't these systems actually store all your data online so that you can share passwords between devices?"
Certainly not the password manager I use. If you have multiple devices then share the safe directly, device to device. That may be less convenient than you wish but increasing convenience will almost certainly involve a trade-off with the security you're looking for.
if they emailed users with "we don't want you to lose your hard-earned money/house/job, and we noticed an insecure password and would you please change that to a better password (and here's how)."
And being the bankers they are, they'd embed a "helpful" link in the email, further training their users to click on any link in any random email purporting to be from them.
Why do banks etc persist in training their customers to be phished?
The "data dumps" that were perused for these popular passwords; how did they extract plaintext passwords from properly encrypted
In a lot of cases the passwords may have been encrypted but not salted. In that case rainbow tables, lists of common passwords encrypted by popular algorithms, can break them. A strong password is one that's not going to make its way into such tables.
Not only do sites apply odd rules without disclosing them, they also don't disclose whether they encrypt information, whether they salt it etc. The safest bet is to assume that they store it in plain text and that they're easily hacked. Use a password safe and allocate strong passwords everywhere.
"Which means that either they're ignoring you, or they're writing their passwords down on paper."
Teach them to use a password safe. That will allocate high entropy passwords and store them. You need never even have to read and type the password.
It means you always have to use your own PC? Even better.
"The play today is to automate all of that infrastructure at hyper scale through a Google or Amazon cloud service vs just firing relatively expensive people, hiring relatively inexpensive people"
Same thing, different tech.
Eventually the survivors will be those few business with the wit to realise that to do things well, from both the financial and customer service points of view, requires recruiting and retaining good people and that that requires good pay. A lot of businesses will go to the wall in the meantime.
"Unfortunately it'll be too late to even contemplate insourcing when Lloyds looks like its circling the drain due to inability to keep up with the market and various scandals caused by poorly cobbled together IT provided by a giant who cares not about the its customers customers & general lack of IT integration with the core business."
The sad thing is that it won't matter because you've also described the competition.
I suppose it depends on how the product is marketed. If I sold sodium hypochlorite solution as household bleach I wouldn't expect trouble. If I sold it as something suitable for finishing off someone you didn't like in an unpleasant manner I might reasonably expect a knock on the door PDQ. Same product, different purposes.
In this case we're not told how he marketed it. However, there's no mention of this little sideline on his CV page and he registered a different domain for the job so that might be indicative, as is the fact that he took steps to conceal it from anti-virus S/W. He just didn't do a good job at covering his tracks.
"another person who clearly knows nothing about his remit."
Given those reports about his own website I think he's about to learn something PDQ, even if only how little he knows. The skiddies won't be able to resist. The downside is that once he's paid someone to sort it out he'll think he's an expert.
" If I had to send a laptop for repair now I would remove the hdd, I have nothing to hide but it's my data and ONLY I control it."
The problem in this case was that the laptop wouldn't start. The problem may well have been on the drive so removing it wouldn't help. And whilst you and I might be happy to remove a drive before sending it in for repair the average punter wouldn't. So the point is that although the tech can see what's on the disk they've no business looking at anything that isn't strictly appropriate to the task so in practice they shouldn't see other stuff.
"The term you're looking for is a strict liability offence. They were adored by the pre-2010 Labour government, because they are so cheap to enforce and look so good on the crime clearance statistics - no need to worry about mitigating circumstances, if it's there, you've got a conviction."
Let's hope someone takes one of these to the ECHR whilst there's still a chance.
"You do bring up a question... what was the reason for the tech to look at the hard drive? That would go back to the reason why he was called."
We're told that: the computer wouldn't start. Looking at unallocated blocks seems an odd way to sort that out.
"If the image was planted... you would know "
Who's "you" in this sentence?
The owner of the computer would know but it's then one person's word against another.
I spent years examining evidence in criminal cases. Quite often there were conflicting statements about a case. I could look at evidence and form opinions about how what I saw fitted one statement or another (or both or neither!) and about how it might have happened. But I was very often aware that whatever I thought could have happened, was likely to have happened etc only the people involved actually knew and at least one of them, possibly the complainant, might have cause to lie.
So the weakness of your argument is clear to me. Maybe you lack that experience.
There are also a number of details missing here to decide whether you could actually establish a chain of custody the way you suggest. Was the computer handed direct to the tech? If not, to whom was it handed? Did they hand it direct to the tech? Was it placed in storage between being handed in and being examined? Was the storage secure? Who had access? Was it in sealed packaging whilst being stored?
Actual child pornography was allegedly found in his home
After an alert by someone who appears to have been paid a fee for finding a not actually pornographic image in unallocated space. Don't you get even a little suspicious about the whole business?
Paying techs to perform unsupervised searches which they can't legally perform themselves is getting onto a slippery slope. Once on there how far have they continued to slip? This is the whole trouble with this casual approach to the legal niceties surrounding collecting evidence, whether it be this approach or mass-surveillance; you get to a point where you can't be trusted to uphold the law. The saying about justice not only needs to be done, it needs to be seen to be done cuts both ways.
"I'd have a guess from the details given that in this case the doctor had a problem with his computer and realising that it would have to go in for repairs deleted his kiddy porn stash, probably by dragging it to the trash and emptying the trash bin."
Given that the problem seems to have been that it wouldn't start that seems an unlikely scenario.