The Register Home Page

* Posts by Doctor Syntax

42407 publicly visible posts • joined 16 Jun 2014

Page:

IOCCO: Police 'reckless' for using terrorism powers on journo sources

Doctor Syntax Silver badge
WTF?

Re: IPBill

"Even if a criminal prosecution wasn't followed, the individuals who broke the rules could have been fined 50k (s6 of the bill)."

How do you fine someone without a criminal prosecution first?

I suppose my problem is that I'm used to proper legal procedure in courts of law.

Fingers crossed tomorrow morning for Telecity's third repair shot

Doctor Syntax Silver badge

Re: Design

"perhaps written by an IT guru rather than a power systems specialist"

Or maybe rewritten from a press release written by a PR man who understood neither?

Grow up, judge tells EFF: You’re worse than a complaining child

Doctor Syntax Silver badge

Re: 'not known to Plaintiffs'

"Only if bias means interpreting the law correctly.

Do read the EFF brief it is totally hysterical."

Be that as it may, the judge's mode of expression is not what I was used to hearing in courts on this side of the pond*, let alone introducing an additional party, his teenage son. Is the son to be called as a witness?

*Well, maybe in a magistrate's court but would a court deciding on the admissibility of an amicus brief be the US equivalent of a magistrate?

Doctor Syntax Silver badge

Re: 'not known to Plaintiffs'

"This judge has a strong whiff of bias about him."

Which should come in handy for the appeal.

Spending Review: GDS gets £450m, Cabinet Office budget slashed

Doctor Syntax Silver badge

So, an extra £450m to save money. Sir Humphrey is undefeated - it costs money to save money.

Kim Dotcom slams 'dirty ugly bully' Uncle Sam as extradition hearing ends

Doctor Syntax Silver badge

I don't think he's helped himself by all these antics during the hearing. Judges don't like the idea that you might be taking the piss out of the court.

Cyber-terror: How real is the threat? Squirrels are more of a danger

Doctor Syntax Silver badge

Judging by the reports of SCADA kit being exposed to the net skiddies would be as much of a threat as anything.

Paris, jihadis, tech giants ... What is David Cameron's speechwriter banging on about now?

Doctor Syntax Silver badge

Re: So-

"Cameron's speeches have traditionally been dreadful: one-sentence paragraphs full of assertions rather than rational argument. They look good on an autocue but not in print."

Sadly they were good enough to get him elected party leader rather than David Davies. Or maybe it was because they were so mesmerised by Blair that the looked for the closest match they'd got.

Doctor Syntax Silver badge

""So only people with advanced tech knowledge are allowed to write about technology? Even though it's pretty important these days?"

Of course not, but in the absence of such knowledge they have to realise that what they write might be complete bollocks. Might be? Almost certainly will be!

And as for "adversarial", start looking closer to home.

Dum dum dum - another cloud bites the dust (Adobe's photo cloud)

Doctor Syntax Silver badge

Re: Bit of basic maths seems to be the issue here.

'Honestly all of this seems less about cloud and more about tech companies failure to understand the implications of the term "unlimited" (again)'

I suspect the thinking was that "as H/W gets cheaper all the time we'll be able to add capacity faster than the customers can use it".

Spot the flaw in that.

Doctor Syntax Silver badge

Remember, it's someone else's computer...

...to do with as they like, including switching it off.

Doctor Syntax Silver badge

Re: Never was fully sold on the cloud concept

'Now if there was an easy way to replace the "cloud" with my own server, I'd be happy.'

1. Make your choice of several models of NAS boxes

2. Buy one

3. Plug it in

'Hypocritical' Europe is just as bad as the USA for data protection

Doctor Syntax Silver badge

The reason the ICO hasn't reached for its pad of enforcement notices is probably because nobody has challenged a UK company's use of Safe Harbour. If that happens then they'll be obliged to investigate.

GCHQ is another matter and someone might need to take that to the ECJ.

North Korea is capable of pwning Sony. Whether it did is another matter

Doctor Syntax Silver badge

"Anyone who has the resources to hire a full-time research team and a pair of decent developers can build credible offensive hacking capabilities. This means that most 50-individual companies on the planet theoretically have the resources to build both malware and network-based deployment capabilities.

....

Someone who has actually spent time penetrating other systems and had to think about these things just might. These people are not cheap, and there aren't many of them."

Well, which is it?

Who's right on crypto: An American prosecutor or a Lebanese coder?

Doctor Syntax Silver badge

Re: Misses the point

"Under USA law there's a right to not self-incriminate"

Rules of evidence in England, Wales & N Ireland (I don't know about Scotland) amount to much the same thing. The police caution starts "You have the right ot remain silent".

There could be an interesting situation here. If a suspect gives up his key under a judicial instruction could the phone's contents then be used in evidence against him? ISTM that this is an issue that could go right up the court hierarchy.

Dell: How to kill that web security hole we put in your laptops, PCs

Doctor Syntax Silver badge

Re: SOP when buying new laptop (with Windows, obviously)

The trouble these days seems to be that you can do all that and the crap still comes back to haunt you.

Windows 10 pilot rollouts will surge in early 2016, says Gartner

Doctor Syntax Silver badge

Re: Works for me

"But MS have just released a massive update (actually two of them) and this time, I think they've got it right."

Did that include an update to their T&Cs?

Doctor Syntax Silver badge

Re: Don't waste your time

Maybe you should check up what sites she's browsing. Where she got all that stuff might be more worrying than the stuff itself.

Doctor Syntax Silver badge

Re: Optimistic

"the PC is dead, tablets are the future!"

Dell are currently working on the first part of that.

Doctor Syntax Silver badge

Re: Optimistic

"Agree. It's not a report, it's marketing."

It's not marketing, it's a Gartner prediction.

Windows 8.1 exams kept alive six more months, Win 7 tests immortal

Doctor Syntax Silver badge

Re: Probably a necessity

"SystemV has been always regarded as a blunder by people in the know"

I take it that you think the folks in Bell Labs weren't in the know. Hmmm.

"Systemd while not perfect allows one to write a service init script or custom action in minutes rather than hours."

One of my worries about systemd is not that it doesn't allow the use of init scripts but that that use could disappear at whim.

Doctor Syntax Silver badge

Re: Probably a necessity

" BSD is just different enough that it's actually quite frustrating to use. It looks like Linux. It feels like Linux."

We're approaching things from a different point of view. Mine was that Linux looked like Unix, felt like Unix. Now it doesn't. It's maybe time to start referring to it as GNU/Linux as the purists insist and remember that Gnu's Not Unix.

Nevertheless I agree that BSD can be frustrating but that's because it lacks the polishing that Linux has received over the last few years, the polish that turned it into a product in the sense that Brookes uses in TMMM.

Doctor Syntax Silver badge

Re: Fuck systemd

"RedHat Is Not Linux (Not any more...)"

I think 6.x still is.

Could there be a cunning plan at work?

Doctor Syntax Silver badge

Re: Fuck systemd

'I will keep your post in my reference list for all those who incessantly spout off about how "easy" Linux is.'

I'm afraid that while "is" still applies to a few surviving long term support distros, Linux is becoming Windowsified. Free BSD looks encouraging but in some aspects is where Linux was about 10-12 years ago. I haven't tried OpenBSD yet.

Doctor Syntax Silver badge

Re: Probably a necessity

"I'm sure you're aware of Devuan. I hope they succeed."

I doubt it. Everything upstream will simply be assuming systemd will be there & coding for it. Working round is going to be an ever increasing task. I just hope that doesn't affect BSD as well.

Doctor Syntax Silver badge

Re: Probably a necessity

"Move over to Ubuntu and...wait...vi doesn't behave the same."

I think I can see your problem. You're not really using vi, you're using vim which stands for "vi improved". And all those improvements allow distros to play silly buggers with config. Old vi has been available since V7, which included the code for ed became open source. Old vi is confusingly called new vi, nvi. Use that instead.

How cyber insurance actually works

Doctor Syntax Silver badge

A hard sell

Cyber insurance must be a particularly hard sell to companies whose response to an incident is simply to brazen it out. Not thinking of anyone in particular, of course.

Malware caught checking out credit cards in 54 luxury hotels

Doctor Syntax Silver badge

Re: Replacement card policy

"They notice that all the people complaining have used their card at one particular place - Heathrow Express was one example from a few years back."

What they need to do is go a step further & require compensation from the merchant. It would give them an incentive to tighten up. As things are, if it doesn't cost them anything to do nothing then nothing is what they'll do.

Doctor Syntax Silver badge

Re: Cash

Their problem. Cash is on the counter, demand a receipt or failing that a written statement that they won't take your cash. If in doubt record the incident.

Doctor Syntax Silver badge

Cash

Just pay by cash. But don't get cash from the in-house ATM.

What, they don't want to take cash? Their problem. There's the bill and there's cash being tendered to pay it. You've done your part.

Malvertising: How the ad model makes crime pay

Doctor Syntax Silver badge

Re: Ad Ecosystem

"Of course, you could just nuke it all from orbit and start over fresh..."

Good idea. Except maybe the last bit.

But to take your analogy further: I suppose what you're really saying is that sites that depend on advertising would be damaged along with the advertisers.

The advertisers themselves, as they currently operate, are no great loss. In fact, they're really no loss at all; their MO is to poke their fingers into user's eyeballs and maybe also ears. The rest of us would be better off without them. They may be doing themselves more harm than good in any case so they might actually be better off if their advertising channels were nuked.

So let's look at the sites. Under your Darwinian notion they have choices, adapt or die. They could adapt by allowing adverts in page and exercising direct control over what goes there. If they succeed in that they survive, if they allow the usual slow-loading, animated, screaming crud they die & if they allow malware they get sued to oblivion. But yes, they can survive.

Doctor Syntax Silver badge

'Often, the advertisers involved in a malvertising incident may not be the malicious actor themselves. Segura stated: "They may simply have resold to a third-party that abused their trust. For this reason, it would be unfair to terminate the top level advertiser because they did not 'knowingly' participate in the malvertising"'

Point taken. So suspend them for negligence. The entire chain, website & all. Even better, make them all jointly and severally liable for damages by reason of negligence. Then we'll find out just how quickly they can either track down the bad actors or put a trustable chain in place. PDQ I suspect.

Want to defend your network? Profile the person attacking it

Doctor Syntax Silver badge

"This is why bulk data theft is so much rarer than simple compromises to ... pump out spam ... Getting in is easy. Getting out is hard."

It could be that the "spam" isn't. Set up a batch of email accounts on gmail, outlook etc & fire up the spam bot. Rinse & repeat.

Plus the regular spammers seem to be quite good at burying URLs deep in other people's web sites. If the target is sufficiently pwned that could be an exfiltration portal. Just stuff going out of the normal webserver provided it could be made to look innocuous in the logs.

Blocking out the Sun won't fix climate change – but it could buy us time

Doctor Syntax Silver badge

Re: DOOMED, WE"RE ALL DOOMED...

"My money is on raccoons"

Cockroaches & woodlice (pillbugs for leftpondians). They're indestructible.

Doctor Syntax Silver badge

Re: Satellite measurements don't .....

The entire satellite age represents so little of the current interglacial that they show nothing but noise.

Doctor Syntax Silver badge

Re: Sea rise

"this erosion" is likely to be determined by your local geology.

Doctor Syntax Silver badge

Re: Refreeze the poles?

"the sixth lowest October in the satellite record."

Remind me - what proportion of the current interglacial does the satellite record cover?

Mostly harmless: Berlin boffins bleat post epic TrueCrypt audit feat

Doctor Syntax Silver badge

Re: Well, hurray..

"Given this last year has seen Heartbleed AND shellshock in far more frequently used codebases - my personal preference is to go with the actively maintained stuff, but YMMV."

"Frequently used" doesn't necessarily mean heavily scrutinised, at least, not until those bugs emerged. It was active maintenance that introduced the Debian ssl bug.

Yahoo! Mail! is! still! a! thing!, tries! blocking! Adblock! users!

Doctor Syntax Silver badge

Re: Are Yahoo! Experienced? Have Yahoo! Ever Been Experienced?

"Please note, sysadmins everywhere."

I'm sure sysadmins everywhere are with you on that. It's the hipsters who want to provide you with experience.

Doctor Syntax Silver badge

Re: Yahoo is Over

"or if you are a customer so don't report it as spam"

ROFLMAO

Do you really think reporting spam has any effect?

Doctor Syntax Silver badge

Re: Yahoo is Over

"It take some work to switch to another less intrusive and spammy email, considering all the sites I have registered at using the Yahoo address."

It does but it's worth it. I used to have two addresses, a hotmail one for places likely to result in spam & an ISP one. The ISP one survived several buyouts until TalkTalk bought it out. As part of the ISP migration I registered a domain still with a single address on it until that must have leaked and started to get spam.

The current arrangement is that every company I deal with regularly has their own address so if any leak I can (a) identify where the leak came from and (b) replace the address. The hard work is in going through all the different address change mechanisms, some of whom can be a pain. It's also an opportunity to re-evaluate all the businesses to whom you've given an address & cull a few. Finally, every month or so I set up a new temporary address for circumstances where I might need to give out an address for a single transaction and then I kill that after a few weeks. All the live addresses go into a single account and so into a single inbox on Seamonkey. That's been the arrangement for a few months & seems to be working OK. In the long term the work will have paid off.

The Hotmail account receives almost nothing but spam now (the exception are usenet users who simply can't read the instructions in a sig.) and as I never kept an address book online no contacts who used it can get spammed from the Hotmail me apart, possibly, via the occasional numpty who included it in a cc: list. I really should get round to closing it and changing the one registration left using it - el Reg.

Doctor Syntax Silver badge

"Its only the best all round solution if you don't have any significant delays in loading ads, and they are not poisoned flash files or similar that then infect your PC."

You'd need to have an overall limit, volume and time, on what could be downloaded. And as it would all be sent to /dev/null or whatever equivalent you OS provides poisoned flash files would be no more of a problem than the noisy ones or the animated gifs.

Doctor Syntax Silver badge

Re: It's not about spam, it's about /security/

You're quite right. It's rapidly getting the the stage where the general public realises that basic internet access security requires 3 things: anti-virus, noscript and an adblocker. As soon as the adblocker becomes universal it's game over for the entire advertising chain. They need to tackle malvertising urgently if they hope to survive. I'm surprised Google haven't done something about this already although as soon as they do, hoping that adblockers will whitelist them, the rest of the industry will make the usual monopoly complaints while ignoring the fact that it was their own arrogant sloppiness that brought the situation about.

Doctor Syntax Silver badge

"Give us ad-masking instead"

I don't understand the downvotes. This is the best all-round solution. The website gets paid. The user doesn't get pissed off. The ad networks also get paid. The advertiser? Well, as they haven't succeeded in pissing off the user they haven't lost potential or real customers and their direct costs are no more than they would have been had they paid to lose those customers.

Hillary Clinton: Stop helping terrorists, Silicon Valley – weaken your encryption

Doctor Syntax Silver badge

A counter-suggestion

Government should stop treating Silicon Valley (and the rest of the tech world) as an adversary. Get them to explain the issues to you. Listen to them. If you can't understand what they say (which is quite likely) just accept that what they say is true. The hardest thing for you, as a politician, will be to break your normal habits and disregard the Yes Men because inevitably there will be a few trying to sell you snake oil. It might not be what you want to hear but it will be real and real is what you have to live with.

Doctor Syntax Silver badge

Re: "...we were told bluntly: No compromise exists..."

"- give us the square root of -1,"

i

Many UK ecommerce sites allow ‘password’ for logins – report

Doctor Syntax Silver badge

Re: Account Fetish hurts online retailers

@cbars

Suitable alternatives are

You

Dont

Need

This

and for an email address chairman@domain of company

Even better if you can get a direct email address of someone in the marketing dept.

For situations where a real email address may be needed for the transaction I generate a temporary email address every month or so & close it down when the transactions are complete so their spam will bounce.

I offer the following free of charge to anyone looking for a business idea. A service which will provide an email address forwarded to a real address for a preset time but will thereafter bounce further mails with a very pointed message explaining why it's been bounced. Or alternatively forward them cc: (not bcc:) to the reply to addresses of several other such mails. Let the spammers spam each other.

Doctor Syntax Silver badge

Re: On the other hand.

"Been in this situation before, and someone above me decided that they would attend the KPMG IT audit, without letting me know, until after the auditors had been in. Said person simply lied throughout it."

What sort of auditor would simply see one person instead of insisting on checking with a number of other members of staff? (Answers on a postcard)

Who's running dozens of top-secret unpatched databases? The Dept of Homeland Security

Doctor Syntax Silver badge

"The report details ... a seemingly bureaucratic effort to delay a report announcing the flaws in its systems."

Next time, don't piss off the auditors. They get the last word.

One-armed bandit steals four hours of engineer's busy day

Doctor Syntax Silver badge
Coffee/keyboard

"while trying to take a sick day with stomach flu"

What? You didn't throw up over her keyboard?

Page: