"Because we failed to learn from them, we made the same mistakes as everyone else."
It would help if people learned from successes.
42402 publicly visible posts • joined 16 Jun 2014
Has gone about it in the right way to do what?
AFAICS, they've gone about it in the right way to give them the best chance to obtain a precedent that they'll then take every opportunity to extend until no meaningful safeguards are left. I doubt they give a monkey's about the content of the phone, even assuming it has anything they haven't got from the backup.
"The end result is that non democratic states and and crooks will gain an advantage - while those following democratic rules will be cut off from essential evidences in many crimes."
If legit software had backdoors then legitimate users would have be at risk. Criminals? There's be plenty of people, some of them competent, prepared to produce illegal software and remember this simple fact: you do not discourage people intent on breaking the law by furnishing them with more laws to break.
"it is interesting that they've approached this issue in this way"
I think they've taken the best case they can to get a precedent from the courts. This particular case takes advantage of the fact that the phone was owned by a public body, not the user and that the user's rights don't come into it because he's dead. OTOH if that last were a significant part of the precedent then the SOP for getting a phone unlocked might include "shoot user".
"AFAIK no one has ever successfully tinkered with microcode. It's a security through obscurity thing on a very large scale."
My first reaction reading this was that someone who was able to get the old firmware loaded could then trigger the exploit. But I suppose anyone with that level of access wouldn't need to worry about finding exploits to use.
It's rather trite to say that everyone should assist in the pursuit of lawbreakers etc. But we also have to remember there's supposed to be - and I'd like to think still is - a concept of presumption of innocence.
The FBI appear to have chosen the case on which to raise their demand with considerable care. There is nobody charged and very likely nobody ever to be charged as a result of this. The user of the phone, whilst neither charged nor convicted, has any outstanding human rights to be contradicted, moreover it's likely that when a coroners court sits on the murders it's likely to pronounce that he committed them. Also the phone wasn't his property, it belonged to the local government body who are agreed to the phone being hacked. So, apart from the fact that the FBI and the owners between them made a cock-up by changing the password and the dubious arguments for the phone's likely evidential value over and above any information the FBI might already have, the case for doing this is about as persuasive as it gets.
However, the precedent it would set, practically if not legally, would extend well beyond these circumstances. Even if a decision in favour of the FBI were limited to the particular circumstances I outlined above it would still be a dangerous precedent. On the one hand it would undoubtedly be just the first slice in a campaign of salami tactics to make the decision universal. On the other, if the circumstances were limited to those in which the user were dead that might be an irresistible temptation that shouldn't be on offer.
The argument's been made that those who break the law shouldn't be entitled to call on the law to protect them. That argument fails to take account of the presumption of innocence. Until proven guilty the alleged lawbreaker is as entitled to the protection of the law as anyone - it's one of the final lines of defence we all share against a false allegation. So the risk of such a precedent being widened to overrule that presumption is not a trivial one.
If we are to be called on to assist against lawbreakers we need to be able to trust those who make such calls. As things stand various agencies in both the US and the UK have forfeited a great deal of public trust. ISTM that one of the most important things now, for the FBI and for the others, is to rebuild that trust. In the circumstances, whatever new evidence might be gleaned from the phone the wisest step the FBI could take right now would be away from their request. It could be the first step towards that rebuilding.
As the FBI and their supporters have chosen to invoke the rulings of Edward I we should remember that the presumption of innocence was reintroduced into European law in his time and also that he not only reaffirmed Magna Carta, he made it part of English statute law. From Magna Carta we have the concept of due process of law. These days I fear the concept of due process is being stretched to breaking point if not beyond.
Finally I should reiterate that I spend a good many years as a forensic scientist in the midst of a terrorist campaign. I carry no brief for terrorism or any other form of criminality. I understand from my own experience the desire to investigate cases as fully as possible. But the thing I dreaded for all those years was the possibility that, however inadvertently, I might end up making a mistake that could help convict someone who was, and would know themselves to be, innocent. I wish I could see evidence of that dread in the decision makers of law enforcement agencies today.
"That might fix it."
I'm glad you put on the joke alert. The entire chain other then the user's computer and the IP network leading to it could be outside HMG's jurisdiction. The only point at which the user's computer can realistically be defended is at the computer itself. I doubt the ISPs would be able to perform DPI on all the traffic and even if they could it would require MiM of HTTPS sites - not, of course, a problem with our beloved elReg.
"Unfortunately, for the past few weeks my phone has decided that it likes the BT Fon connection better than my private home WiFi, so it always connects to it."
Back in the day when unsecured home access points weren't that unusual my laptop would manage to ignore my network and latch onto some unsecured one-bar job down the street at what felt like 10 bits per minute.
"The reason why advertising is everywhere is because, on a human psychological level, advertising works. It influences people, against their own will, to make various choices"
Sort of. It works because, on a human psychological level, the advertisers can't comprehend that their monotonous advertising will piss off so many people that they lose potential customers. When you're so utterly convinced that the sun shines out of your arse rational thinking becomes impossible.
"Nope, not in his view."
In fact he seems to be rather ambivalent about it.
ISTM that he's been lobbied into making a speech in favour of the advertising industry but realises that users have made up their minds and it would be politically stupid not to go with the flow. So he's started off by saying what the industry wants to hear but then put the users' viewpoint and some meaningless dribble about being ready to help. When push comes to shove he's got his marker in which will enable him to take the popular line without being accused of a U-turn.
"I know the digital sector prides itself on [self-regulation and co-operation]"
Belief in that, at least as it applies to the advertising sector, can't be described as sensible.
At present we have the ASA as an advertising regulator, proof needed, if anything, that the advertising industry in the UK can't self-regulate. The ASA can only act after the event; good luck with using that as a means of cleaning up malware served up via an advertising network. And the ASA only has authority in the UK at best.
Ad-blockers are no longer an option for people who don't want ads, they're another part of the PC user's security toolkit.
“We need the whole advertising sector to be smarter."
The heat death of the Universe will arrive before the advertising sector gets smarter. And there's absolutely no point in him trying to either encourage self-regulation or legislate in the only region where he has any influence. Someone needs to explain to him that the first two Ws stand for world-wide.
The only people who can regulate advertisers on this scale are the users and ad-blockers are the means they use.
Yes, I know, commenting on my own post & all that.
I use a Mint netbook for visiting libraries and archives for research. As it happens I run Informix & a selection of its tools which enables me to knock up new data-taking forms as needed. It wouldn't, however, be difficult to implement something similar with a different RDBMS tool-set.
I also carry a USB stick to which I can download images from the library's computer.
So there I am, on the one hand collecting images on the stick & on the other taking notes and at some point the two have to be brought together.
What would be ideal would be to have an arrangement where a USB lead would allow the netbook to present itself as mass storage in just the same way as the USB stick. An Android tablet would allow this but wouldn't, AFAIK, allow for a full-blown RDBMS tool-set to be installed. But if a Ubuntu tablet provided the mass-storage simulation via USB and an RDBMS then combining this with a Bluetooth keyboard would be a winner for me. OTOH maybe the same thing could run on my existing netbook.
"So all these 'seamless' systems have to come up with some kind of clever software layer which knows or remembers what kind of layout we want for all sorts of things, and when."
If you're thinking in terms of a system that normally has a deep integration between the desktop and the rest of the OS then you'll undoubtedly need to think of some layer on top of that. However for any Unix-like system that's already a solved problem. The core OS is independent of the interface - it can even be run headless. The windowing system sits on top of that and the desktop, of which there is a choice, sits on top of the windowing system. There are even standards for storing info about desktop contents. It's possible to install several desktop packages on one device* & choose one at login. Swapping one for the other when connecting or disconnecting a docking unit wouldn't be a great step beyond this.
*Providing you're not using a device whose vendor's walled garden prevents this.
@Dave 126
As per my previous post, what you envisage wouldn't be my use case. Nevertheless it's not difficult to see that there are several different ways of using expansion of a phone.
If you're targeting use at home or in an office you might have a docking unit permanently plugged in so if you need to revert to hand-held operation for some reason its simply a matter of picking it up from the dock.
If you want to use it with an hotel TV you might need to carry an HDMI lead along with a bluetooth or USB keyboard.
A business traveller, therefore, might pack a keyboard and lead for use in hotels but leave them in his luggage when returning to the office where a docking unit would be available.
As to the trade-off between a computing stick and a phone, the former is dependant on having a TV or monitor available whilst the phone is usable within the limits of its interface at any time. As to one standing in for a missing other, well all you're saying is if you start with two devices, of whatever nature, and lose one you've got one left. That's just simple arithmetic. However, if one has your data on it and the other doesn't and you lose the one that has you effectively have nothing left. You might also end up with half your data on each device and become dependant on using both; you're going to need to keep them in sync.
A phone running Ubuntu could have an appeal. Being able to use it as a general purpose computing device wouldn't be the major part of the appeal. The appeal would be that I buy the phone and that's the end of matters. What runs on it, apart from the phone S/W itself, is my choice, not the vendors. What it reports back to the vendors is my choice (nothing as it happens). Whether Ubuntu and their vendors would be prepared to restrict themselves to that sort of deal remains to be seen.
"Which in real terms would mean cars travelling 300-500 miles on one charge for less than $10 – a fifth of the price of gasoline."
It's not just a matter of range and cost. It's also a matter of how quickly you could get the energy into the car. Can they achieve a charge rate equivalent to a petrol pump's delivery rate and as simple to operate?
"James Webb telescope ... would be able to see much farther than Hubble. Now, not even a week later, it turns out maybe not THAT much farther since Hubble can apparently see farther than ever imagined."
Of course if the James Webb telescope turned out to be able to see much further, say in excess of 14 billion, things could get really interesting...
"Businesses who do report these types of issues are beaten viciously and at length with a stick by our fine selves"
And rightly so if they have their customer database popped by teenager skiddies via an exploit older then themselves. If they get DDOSed that's a different matter.
"The bigger issue is with companies that are selling personal data besides credit information. There are no legal requirements for those companies to give somebody a copy of the data they hold about them and have no legal obligation to remove incorrect information."
That's one reason why we don't like personal data being sent to the US.
"It's high time Facebook gets an anti-monopoly boot up its arse. (And a completely unrelated privacy boot up its other arse)."
I see them more as two halves of a single operation - like hammer & anvil. The privacy charge could be evaded on the basis of "they agreed" and the agreement argument gets nixed by "no they didn't because of the monopoly".
@ Richard 12 (and assorted others).
Read this very carefully. Read it several times if you don't understand it first go.
The FBI want to try brute force.
What they're trying to brute force isn't the encryption key.
What they're trying to brute force is a pass code of a few digits.
'Yes you'd think so, but by the time the process has been bloated with "eye candy", large images, buttons that are images so must be downloaded before you can see what they are'
Testing.
Not just testing on the dev's box sitting on the desk but build a prototype and go out into the field and test it from there on the sort of links that will be used in practice.
"Ahh, the joys of having to use internal IT resources rather than going out to the market for the best supplier."
I'm not sure about this. There would be a good argument for having real internal IT, namely internal to the individual departments who could work with the rest of the department on a regular basis and call in outside resources as and when needed. Part of the problem seems to be the lack of skills required to even communicate with outside suppliers or even to work out requirements in an orderly fashion.
"And yes, I did once work for an Ad agency"
Do you know if the industry has ever attempted to measure the net effect of advertising? They can easily say x% of people who saw an ad bought from it. But if y% were so pissed off that they made a mental note never to buy that product the net effect is actually x-y% and that could very easily be a negative number.
I doubt its something that could be easily researched. I also doubt that anyone with any sense in the ad industry would avoid doing that for fear of what they might find but there seems to be sufficient arrogance that the possibility of finding something to burst their bubble might never occur to them.
"I am obviously in the minority, because I would rather pay than see adverts online."
I'm not sure that that's properly tested. The number of sites one would pay for is always going to be less than those one might arrive at by a link from a paid for site. But that doesn't mean that there wouldn't be scope for worthwhile sites to earn paid subscriptions and - who knows? - maybe make more than they could through adverts.
I can't help feeling that the people who are really being ripped off in all this are the actual advertisers, the people with the products being pushed. The advertising industry is taking money from them and presumably they see some orders coming in but the industry's antics might well be losing them more potential customers than they bring simply by being so annoying. But then, as I've said before, the one thing you can be sure the advertising industry sells successfully is itself.