I think we should be told.
These canned statements of which you write - are they ring pulls, wind-up keys like corned beef or do you need a tin-opener?
42400 publicly visible posts • joined 16 Jun 2014
"They gave me a CMS (I'm the web person) that didn't work in the company browser, but I was forbidden to download a browser where it would work."
Who was "they"? If it was IT then they did a crap procurement job if they didn't ensure it would work with their approved browser (or approve an acceptable browser). If it wasn't IT then it sounds like you're a minor offender compared to whoever put in the CMS. Unless, of course, that was also you.
"And all because someone did an MBA."
At some point MBA courses will start using the Sony cockup as a case study, especially if it proves terminal. When that happens MBAs will finally be given a clue that this security stuff matters.
In the meantime it might be a good idea to start a rumour that the initial Sony break-in was via a BYOD - at best it'd be useful FUD & possibly even true (you heard it here first).
What part of "if it ain't broke, don't fix it" did El Reg not understand?
Time to charge up the cattle prod.
Specific problems?
Humungous pictures, even if they're relevant, blocking the top of every article.
Top of article link to comments now reduced to a wizened little appendage.
Adblock & Noscript probably shield me from come of the other problems.
"Driverless car arrives at your home and is foul - press the 'it's foul' button, it'll go to get cleaned whilst a replacement makes its way over to you. "
It's Saturday morning. The next one is in the same condition as is the one after that. At some point it dawns on you that either you get in anyway or you miss your plane.
If I go into a traditional shop I pay, take what I've bought & the shop has no idea who I am. If I buy online the trader needs more information - the payment will be by some electronic means & there'll need to be an address for delivery - unless it's a download. But once that's done there's no need to retain that information, indeed doing so contravenes the DPA.
So no, traders, you are not entitled to know who I am. If you want me to register my email address I'll look elsewhere unless I envisage trading with you again & think that it would be to my advantage to give you the address. If I look elsewhere and there's no alternative you'll get my spam bin address but if I notice you sending me any spam there you'll get a brusque mail back, aimed as high up your org. chart as possible, telling you that not only was that spam unwelcome but it has blocked you off from receiving any more business from me.
My identity is not yours to manage. It's mine.
'There's no technical reason why iPlayer can't work for me, and I'm perfectly willing to pay a subscription if that's what it takes... but I don't have the option. There's no technical, legal or financial reason for this - it's purely a matter of "f*** off, you filthy foreigners".'
The reason is that it's the Beeb. You're confusing it with a competent organisation.
I just saw a mention of this in Another Place (as they say in the HoC):
http://dhowe.github.io/AdNauseam/
It seems to fit the bill nicely. The user doesn't get bombarded with ads, web-sites get paid and, contrary to what one might think, the advertisers who pay to not get their ads seen also gain. Because the user doesn't actually suffer the ads they don't build up a negative response to the advertiser.
It might need a bit of tuning, however. "Clicking" every website might be excessive, it would need a maximum bandwidth setting.
We designed this system so that everything to do with setting up a new product (no, not just setting up a product code) could be done through a proper GUI interface by business users. All the surrogate keys & what not would be properly fitted together. What management decided they wanted was a full-blown procedure written out for IT support with hand entered SQL. Horses & water....
Not really. Just a run of the mill report. And a manglement who decided that what they really needed was an empty desk. He certainly wasn't running anywhere as he turned up in the entrance to the local supermarket flogging double glazing a short while after.
"Clear out your desk, you don't work here anymore"
One of the client's sales execs (desk at the other end of an open plan office) asked for some sales data to be extracted from the database. About an hour later I had a nicely formatted report printed off for him and took it down to his desk. I asked someone nearby "where's xxxx". "He doesn't work here anymore."
I use PlusNet but I just gave them a Hotmail address which I tend to give to anyone I've no experience of dealing with in case they turn out to be a spammer. So if any of it comes in my direction the Hotmail spam filters will have dealt with it. Mostly the spam that the filters let through is that pretending to come from Hotmail/Live/Outlook/Have-they-rebranded-again-this-week? You'd think that not only would that be pretty easy to trap but that they'd be particularly keen to do so.
But one very odd thing does sometimes turn up in that mailbox. It's mail addressed elsewhere being sent by other Hotmail users. There's no mention of my address anywhere in the headers so no indication of how it got there. The contents are quite innocuous - it genuinely looks like other people's mail gone astray. So far there have been 3 instances of that.
"Stalinist central planning like the NHS"
NHS central planning?
At one level there are English, Welsh, Scottish & N Ireland health services. Below that, at least in England and Wales there are then various local trusts plus trusts running hospitals. And then there are also local organisations such as http://locala-homecare.org.uk/ whose exact status is a mystery to me. There are also local organisations in Scotland but I can't remember whether they were also trusts or called something else.
N Ireland I'm not so sure about as it's nearly 30 years since I lived there & I haven't had to deal with them from a business point of view. In fact it's now a few years since I had to deal with the trusts in the rest of the UK level so it might have been all change there but unlikely to have been simplified.
"But sure, not going to find me defending the insane US medical system."
In your analysis you're treating the benefits of various US health insurance schemes as a social benefit. But looking at taxes you're comparing US taxes which don't include the health care costs with those countries where the health care budget comes from taxes. To make a fairer comparison you should be adding insurance payments to the taxes*. How does this affect the comparison as regards progressiveness and overall levels?
*There is a precedent for this in that in the UK there is what is nominally an insurance payment, National Insurance, but which is really part of the taxation system.
" I think the idea is more to get companies to declare them in the UK at 21%, rather than have an expensive court battle followed by a rate of 25% on those profits."
I'm sure you're right. Plus a bit of negotiation with HMRC on what to declare as profits. No doubt Google, Starbucks & the rest will still end up transferring a good deal of their profits but not as much as before.
The objective is £5b. If HMRC have a BigCorp down for 10% of that go in asking for 15% & let them wrangle it down. HMRC gets their £5b overall, the lawyers get their new cars, the BigCorps get the rest & everyone's happy. Next year the target gets set a bit higher...
'George Bull, senior tax partner at accountancy firm Baker Tilly, said: "The government now has to produce a new tax law in the next four months and get it up and running - that is something I have serious doubts about."'
Does he really think they'd not have started work on this before announcing it, maybe several months before?
"it's much more likely you are just chaff, more noise to be discarded to get at the really interesting signal."
At one time our phone number was a fat finger away from a local travel agents' with the resulting crop of wrong number calls.
Now suppose one of them was from someone, rightly or wrongly suspected by TPTB of being a terrorist phoning to book a trip to see his granny in Pakistan/join a terrorist training camp/take his kids to Disney. All this meta-data harvesting then means that I'd then be a terrorist suspect. Given that at the time I was working on a gig that required security clearance that could then have led to a sudden cut in the household income.
OK, that's one negative outcome with a low probability. But once you ramp up the volume by mass surveillance the probability of someone being wrongly suspected becomes non-negligible. And the outcomes could be considerably worse than losing security clearance. We've had at least one example of what the Met can do when they wrongly suspected someone. They killed them.
"The fact that most FISC proceedings have been kept secret may or may not mean they are not doing the job the Congess intended."
One thing it does mean is that there is something very wrong with US concepts of democracy. Very occasionally there may be a case for holding court proceedings in camera (and no, that doesn't mean putting them on TV) but a secret court to quasi-legalise actions which appear to be non-constitutional cannot be justified in an open society.
ISTM that theyre dealing with a very slippery concept.
Someone presents himself at a web site or office claiming to be John Smith.
Under UK law anyone can change their name to anything they want providing they're not doing so for nefarious purposes. One individual has variously adopted the names Jake Mangelwurzle & The Occupier. So providing that the person calling himself John Smith isn't up to some trickery he is a John Smith.
But is he the John Smith on the birth certificate he's carrying (small print on the bottom of a BC says that it isn't proof of identity)? Is he the John Smith whose NIN is XY123456Z? Is he the John Smith who passed his driving test at Much Binding in the Marsh in 1972? Is he the John Smith convicted of GBH at the Old Bailey in 2001? Is he the John Smith who owns the credit cards he's holding with that name on them? His employers and neighbours may confirm he is John Smith but they only know that because he told them.
From as data analysis perspective "John Smith" is simply a non-unique character string linked to a number of different attributes. The scope for mis-linking some of the attributes is considerable.
What does the particular department's requirements in identifying him, not just as John Smith but as some particular John Smith out of many - which are the attributes which matter to them? Do other departments have the same requirements?
"A warrant requires that law enforcement say what violations the person be investigated is guilty of"
is suspected of being guilty of
But I'm sure that's what you meant.
I'd also like to think that they have to give some reason as to why they suspect the person. "Because he looks shifty" isn't good enough.
"> Firstly, fixing the existing broken one, if the existing maintainers are unwilling to do it themselves, is accomplished by forking. It's the traditional Linus/FOSS way.
Uhm. no, it's not. The Linux/FOSS way is
1- you fix it yourself
2- you post binaries and source of the fixed stuff so that others can try and see for themselves if the new version is indeed better than the old one."
Quite so. It's called a fork.
Systemd looks set to bring me problems I don't need to solve problems I don't have.
It intends to replace all manner of things that have been working well for a long time for no more apparent reason that its authors want to. What's more, when I read things such as the claim that the new udevd can be installed without systemd, it just can't be built on its own I realise that, whether by conspiracy or cock-up, the source code is clearly a hairball. That's one black mark. The fact that at least one of their developers have been on the receiving and of a bawling out by Linus on code quality underlines that. (And really Linus's bawlings out don't seem to be all that frequent, just highly publicised.)
The notion that the standard logging is binary is another black mark. It's akin to shipping binaries without source; I'm amazed the whole FOSS community hasn't descended on them for that. Maybe they've escaped on the basis that they allow additional text logging. I'd have to trust them that if, one day, that should happen to break, they'll fix it but I'd have to check their history of responding to bugs.
Then there's the position on start-up scripts. I know there seems to be a fashionable aversion for scripting languages invented longer ago than the day before yesterday. Nevertheless anyone who is administering serious Unix-type systems should have some familiarity with shell scripting. It allows arbitrarily complex operations to be performed, .ini style languages not so much. Again, we are allowed, at present, to use scripts in addition to the default .ini approach. For how long? Until there's no going back?
With Debian falling in line I fear there will be little to inhibit devs for all manner of stuff simply assuming that systemd will be there and including it or one of its relatives as a dependency. It will gradually become more and more work to maintain a non-systemd fork. In short, I think the Devuan fork is built on optimism and will become unsustainable on a voluntary basis within a Linux ecosystem within a few years.
Red Hat may be able to sustain their pre-systemd distro for a good while on a commercial basis. Alternatively, having seen off the last major non-systemd competitor in the server world, they'll be able to discontinue it any time they like once their contractual obligations expire.
In the meantime, it looks like many of us will be switching to BSD.
"Why not solve this in the traditional Linux/FOSS way? Meaning: you want a better alternative for component XYZ, because you believe XYZ is broken? Then you write one. Or you fix the existing broken one. Forking because you don't like the init subsystem or its replacement systemd is quite the unnecessary leap. I don't know if it will really lead anywhere."
Firstly, fixing the existing broken one, if the existing maintainers are unwilling to do it themselves, is accomplished by forking. It's the traditional Linus/FOSS way.
Well, it's not just one component, it's a whole inter-related heap of them. In fact, apart from the kernal & libc, it's the core of the OS. So just replacing a single component won't cut it. The term fork is reasonably well merited although you could also call it a respin or a derivative.
Of course the twist in the tail here is that in fact the underlying rationale is that the original wasn't broken but it's being fixed anyway. Conventional wisdom has something to say about that,
Yes it has.
One of the things sysv is accused of is handling race conditions. The only race condition I've encountered is on my MythTV box. A second disk which goes into the volume group providing /srv sometimes isn't ready when the system tries to mount it. It requires plugging in a keyboard to recover which isn't very useful if the box is starting up for an unattended recording. The init system being used? Upstart.
"Debian Jessie provides a choice of init systems, and provides systemd-shim for those who wish to use a rich desktop without systemd running as PID 1"
At present Jessie can be installed without systemd but if tasksel is used will put it back in there. Maybe between now & release tasksel will be modified to avoid this, but maybe not.
"Who says "Gnome" is ignorant. Systemd is set to take over many parts of Linux, no exaggeration: udev, mount, PAM, syslog, cron, tcpwrappers, xinetd ..."
Ah yes, udev. A couple of times I've read the statement that although systemd has taken over udev you can still run udevd without systemd, it's just that you can't build it without systemd because of all the shared code.
WHAT????
Has it not occurred to these folks that all that needs to be done is separate the shared code out into one or more libraries that udevd and systemd can be individually built against? The fact that they haven't tells me that either the entanglement is deliberate, that the code it too much of a hairball to refactor or that it requires a degree of planning of proper interfaces that they can't be arsed to do.
" One of the problems with sysvinit is that it is very poor at handling things that happen while the system is running, plugging in drives and so on."
Really? Isn't udev supposed to handle that, not init? Certainly, running current and past Debians on a laptop I haven't noticed a problem in that respect.
"things will start getting interesting depending on the policy on init system,"
AIUI after the various votes the policy is now that its up to Debian package maintainers whether they support multiple inits. The likely consequence is that if more upstream package maintainers assume the presence of systemd and friends the Debian packagers are just not going to be able to keep up working round the dependencies. As has been said, there's no DebianCorp to finance such working around. And I fear Devuan and the alternative tack, making the current Debian an LTS release, will have the same problem.
Red Hat (with one exception, see below) have already captured the .rpm side of Linux. With Debian, Ubuntu & derivatives also captured they had the whole server business condemned to run systemd.
AFAIK Slackware is the major remaining holdout - Gentoo seems to wish to be agnostic. There is now little incentive for upstream devs to assume systemd etc will not be there. So running a traditional init as an alternative becomes less possible as applications a user might need depend on systemd.
There is an exception, of course: RHEL releases < 7. If Debian sysadmins want to keep running unbloated systems they may have to buy RHEL 6. What I'm wondering is whether that's just irony or a case of cui bono?