* Posts by Cederic

1953 publicly visible posts • joined 22 Dec 2014

Epoch-alypse now: BBC iPlayer flaunts 2038 cutoff date, gives infrastructure game away

Cederic Silver badge

Re: A fix for this

I do like the Great British Sewing Bee.

If only the rest of their output was as balanced and politically neutral. The culture wreckers _are_ the BBC.

Tesla Full Self-Driving videos prompt California's DMV to rethink policy on accidents

Cederic Silver badge

Re: Two Teslas

Perhaps I misread but I thought they do - explicitly stating that where there's an advance box available, cyclists may go through the first white line (which cars must stop at) but must stop at the second until the light turns green.

Of course, no road markings require a cyclist to pass a vehicle waiting to turn. The cyclist could pause and wait behind it, just as other road users do.

Cederic Silver badge

Re: Two Teslas

So a Tesla will ignore temporary speed limits, e.g. where there are roadworks?

That sounds dangerous.

Cederic Silver badge

Re: Two Teslas

I'm feeling rather good that as a driver the only thing in there that will require a change to how I drive is giving pedestrians priority at junctions. Which I already do if they're in the road, just not necessarily while they're waiting.

But that's been normal in Germany for decades so I'm used to it from there; it'll be trivial to adapt here.

The thing that annoys me is the acceptance that cyclists can just bundle down the left of whatever vehicle they choose. Quite why the Highway Code (and associated laws) don't tell them to never go down the left of a vehicle indicating left I don't know. Maybe the authors want dead cyclists.

Open source, closed wallets, big profits – nobody wins the OSS rock, paper, scissors game

Cederic Silver badge

Re: Sounds very much like the music industry

It'd be even more broken than mandatory music royalties. After Linux sucks up 90% of the revenues (on the grounds everyone and everything uses it), the Apache foundation, Red Hat and 2-3 others take 90% of what's left. After that the people distributing will say "It's not cost effective to try and recompense everybody else" (and be entirely correct, because transaction costs will be higher than the payments) and nobody will get anything anyway.

Then Governments will step in, make it compulsory, and you'll end up having to pay some profit making royalty distribution service money to use your own software and get nothing back.

Support specialist Rimini Street found in contempt of court for continued Oracle copyright infringements

Cederic Silver badge

Re: Alternatively, it may be safest for people to just not use Oracle at all...

From threatening to sue users.

They prefer to use the threat, as that way the sales people making it get a chance of commission.

Google splurging cash on UK offices to lure staffers back from the kitchen table

Cederic Silver badge

Re: Draconian?

Because it achieves nothing. It doesn't stop infected people going into the office or catching nastiness from colleagues.

Perhaps if you could explain the benefits I might understand why you think it's a positive policy.

Wipro, Infosys and TCS feel pain of staff attrition as the Great Resignation continues

Cederic Silver badge

Re: Wonder how long we have left?

If you're in Blighty why on earth would you leave to go and work in London?

Especially now all the London jobs are becoming available to people working from home in affordable locations?

Insurance giant Lloyd's hires DXC to migrate org off legacy mainframes to AWS cloud

Cederic Silver badge

Re: DXC and Digital Transformation

Sadly while job hunting half the jobs I was applying for had former consultants involved demanding a track record in "digital transformation".

As though mainframes aren't fucking digital. As though decades of experience building and designing full stack Internet based systems isn't fucking digital. As though automating literally hundreds of business processes saving personally many millions of pounds wasn't fucking digital.

No, apparently the jobs are only open to people with experience in 'digital transformation'.

My current job asked about that. I just told them straight that I don't understand what people are talking about when they go on about digital transformation, and I don't think they do either. Tell me the outcomes you'd like and we can discuss how to achieve those - through a mix of digital technologies and other approaches, as is most appropriate given cost, time, capability, start point and other constraints.

Digital fucking transformation. Lloyds are fucked.

HMRC tool for measuring IR35 status is so great, employers are ditching it in their droves

Cederic Silver badge

Re: The pachyderm is dead and getting whiffy

While the wife of the Minister to whom HMRC report to owns several hundred million pounds worth of Infosys I'm not sure the elephant is going to be noticed. Even if blindfolds are needed.

Software engineer jailed for 2 years after using RATs and crypters to steal underage victims' intimate pics

Cederic Silver badge

They get left locked in an attic for 7 months and end up with double incontinence and other physical health issues.

https://www.bbc.co.uk/news/uk-england-south-yorkshire-59999250

Or kept in a cupboard for four years.

https://www.walesonline.co.uk/news/uk-news/autistic-young-man-been-detained-22626013

Or detained for 20 years despite never committing a crime.

https://www.dailymail.co.uk/news/article-10332367/Whistleblower-reveals-autistic-man-44-basic-needs-met-like-animal.html

Autism. Not fun.

Cederic Silver badge

Re: Not again..

Indeed, and many people that didn't want McKinnon extradited (including me) were suggesting that he be tried in the UK for any crimes committed here.

Being autistic meant he was deemed likely to kill himself if imprisoned in the US. I can relate to that, I've come close to killing myself for being left free in the UK, being wrongly extradited to another country would make me downright lethal.

EU data watchdog to Europol: You've helped yourself to too much data

Cederic Silver badge

Re: Something is better than Nothing

In the UK an official body didn't need to tell them, as it was already against the law.

Not that the Home Office cared.

https://news.sky.com/story/only-dozens-of-images-deleted-from-police-database-11247282

LAPD cops who preferred playing Pokémon Go to tackling robbery can be fired, appeals court rules

Cederic Silver badge

If you need a police presence in a location, to enable swift response to any calls (traffic accidents or criminal activity), the police need to be somewhere there. Parking out of the normal traffic in full view provides a visible presence encouraging people to drive safely through simply reminding them by being there.

So those police "doing nothing 99% of the time"? That's because you only see them when they're not doing anything else, and even there they're helping you reach your destination swiftly and safely.

Logitech Signature M650: A mouse that will barely emit a squeak or a clickety-click

Cederic Silver badge

Re: Stop with the handedness!

Depends if you're a finger or palm mouse user. Finger mouse users are fine with ambi mice, and indeed I find them more comfortable - with either hand.

Although I use a G903 (three of them), as a good mouse is worth investment, so I'm not best placed to comment on more affordable options

Meta Platforms demands staffers provide proof of COVID-19 booster vaccine before returning to office

Cederic Silver badge

Re: Hmm

Indeed, demonisation of people to 'other' them is endemic. I've had vaccines against measles, mumps, rubella, tetanus, polio, hepatitis B and yellow fever. I've also had what I was told was a vaccine against Coronavirus.

This article accuses me of being an anti-vaxer. Thanks.

Cederic Silver badge

Re: Good.

They're not isolating 'plague carriers'. They're isolating people who haven't been vaccinated.

Had your vaccinations? Spewing clouds of toxins, coronavirus and STDs? Come right in!

Sorry but policies like this are purely theatre unless they demand a test from everybody.

JavaScript dev deliberately screws up own popular npm packages to make a point of some sort

Cederic Silver badge

Re: Proof that the industry is mad

They were also the first to pull in this intentionally broken package. Getting lucky doesn't validate a bad process.

The bad process replicates the Log4J vulnerability, whether its implementer use Log4J or not.

Cederic Silver badge

Re: Proof that the industry is mad

No, every build should absolutely not pull in the package afresh.

Pull in the package. Test it. Keep the version you've tested. Use that in your builds.

Want a new version? Repeat that process.

Look at the time, cost and effort needed to address the Log4J vulnerability. Don't replicate that vulnerability intentionally in your build process!

California files appeal in latest bid to intervene in Activision Blizzard's $18m discrimination lawsuit settlement

Cederic Silver badge

Re: Bobby Kotick, the Activision Blizzard CEO, is getting off scot free

Blizzard's games were among the most popular for women, and outside the US, so no, many of their clientele does not buy into or participate in 'frat boy' culture.

Games players cover all demographics these days, and generally represent well societal views and norms. Sexual harassment is not a norm here, or any business I've worked in.

Mobile networks really hate Apple's Private Relay: Some folks find iOS privacy feature blocked on their iPhones

Cederic Silver badge

Re: Cry me a river (of fake tears)

If they charge more for a service that doesn't block VPNs then at least they're giving people the choice. If they're making money from customers' data the fairest way of recompensing the customers is to give them a lower priced service.

I suspect their competitors will offer the lower prices and still support VPNs though, so that'd be my choice.

Avira also mines imaginary internet money on customers' PCs

Cederic Silver badge

Re: But when will there be any free cycles?

With over a billion PCs worldwide, around 3/4 of those having AV installed, Norton holding (at a guess, as Avast alone covers this) 1/8 of the market, let's use simple round numbers and say there are 100 million PCs with Norton AV products installed.

If a bog standard PC takes two years to mine 'an' ethereum, and each PC is switched on for just an hour a day you're looking at over 5000 ethereum a day, or $11m/day pretty much pure profit.

I can see the attraction to Norton.

Google: We disagree with Sonos patent ruling so much, we've changed our code to avoid infringement

Cederic Silver badge

Re: Sonos.....

Yeah, Sonos were already on my 'do not buy' list - along with Sony for their rootkit fiasco, Ring for their privacy invasion and anything Google buys as it's doomed to expire.

Spruce up your CV or just bin it? Survey finds recruiters are considering alternatives

Cederic Silver badge

Indeed, the measure of a software engineer is not the source of their knowledge, it's their ability to work with a team to deliver working software.

Computer science graduates I've worked with have never distinguished themselves in development roles from people with any other background. The curve of awful to brilliant doesn't care one way or the other.

A fifth of England's NHS trusts are mostly paper-based as they grapple with COVID backlog, warn MPs

Cederic Silver badge

Re: Wild guess here...

Well, yes, those would be the under represented communities that a diversity officer should be seeking to understand and address.

Men are 53% of the workforce yet only 27% of NHS employees are male.

White people are 83% of the workforce yet only 77% of NHS employees are identified as white.

Still, we can I'm sure look forward to the extra funding, training and target advertising seek to boost those numbers.

Cederic Silver badge

Re: "improve productivity in an organisation severely short of staff"

The world's eighth largest employer is not short of staff, severely or otherwise.

https://en.wikipedia.org/wiki/List_of_largest_employers

Whether those staff are competent, productive and needed is a far more relevant question, the answer to which is only ever occasionally 'yes'.

Perhaps addressing the 47.2% of the NHS workforce that aren't in a clinical role might free some of the ever increasing NHS funding to better support healthcare outcomes. Seriously, we really don't need (yet another) £90k/year Head of Diversity and Inclusion (to cite just one vacancy currently being advertised).

Nothing's working, and I've checked everything, so it must be YOUR fault

Cederic Silver badge

Re: Blue flash

Ah, I worked with one of those. His job was providing tech support to our customers but between calls kept regaling us with stories about how his motorbikes needed constantly repairing and rebuilding, and how he'd had to strip his home PC, replace parts in it, reinstall the operating system..

It was always a mystery to us that he could never 'fix' something and then just leave it working for months or years, like the rest of us.

It takes more clicks to reject their cookies than accept them, so France fines Facebook and Google over €200m

Cederic Silver badge

Well, at risk of yet further downvoting from people that choose not to understand the law, consider marketing purposes.

It's reasonable and appropriate for websites to market goods and services to you, and to seek to tailor that marketing to meet their understanding of your needs. They have a legitimate interest in processing your personal data to do this, and using a cookie to support that activity should be legal.

Don't ask me, ask the ICO: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/legitimate-interests/when-can-we-rely-on-legitimate-interests/#marketing_activities

But look, I didn't write the law, I don't enforce it, I don't grant permission for any marketing or tracking cookies and I block them using browser plug-ins. If you really don't like a site's claim of Legitimate Interest go write to the ICO about it.

Cederic Silver badge

I was discussing the legal need for 'legitimate interest', which exists independently of but can also apply to cookies. I used an example that should get through even to people that seem to need communication via idiophonic percussion.

Cederic Silver badge

Why?

I have a 'do not track' toggle set in my browser. Its status is provided in my HTTP headers. If sites read and acted on that, my cookie preferences would be known to them with zero clicks.

Give 'do not track' legal force, backed by the right to make financial claims for breaching it. Let's see Facebook survive 800 million individual lawsuits.

Cederic Silver badge

No, it's because there are multiple valid reasons a company may process your data whether you like it or not.

For example, they may have a legal obligation to issue you a refund long after you've closed your account. To do that they need to track you down and assure that they've found the right person, something that requires private data about you.

You better have patched those Log4j holes or we'll see what a judge has to say – FTC

Cederic Silver badge

Re: eBay vs Newman

Al Franken's opinion is not law.

The judgement in eBay v. Newman disagreed with Franken.

Shareholder value does not mean profit. The two are merely often aligned.

IntelliJ IDEA plugin catches lazy copy-pasted Java source

Cederic Silver badge

Re: False positives?

The description seems to suggest it's not looking at external code at all.

It's looking at code you paste in, and comparing it to other code within your code base. Where it finds a match, it suggests that instead of copy/pasting the code multiple times you apply software engineering basics and create a callable method.

There are occasions on which that won't be appropriate but anybody capable of understanding those will also welcome the IDE refactoring support to prevent the same code being replicated multiple times.

John Edwards takes the reins at the UK's data protection watchdog

Cederic Silver badge

Oh, no. Not put into 'Private Hands' at all.

Sold. Your data will be sold. You will be sold.

Tesla disables in-car gaming feature that allowed play while MuskMobiles were in motion

Cederic Silver badge

Re: Removing distraction = good

Bypass the barrier on a bicycle? No. Try and beat it, cutting it so fine it drags down your back as it comes down? It would be sacrilege not to.

They've since blocked that level crossing, and didn't even replace it with a bridge. Two mile detour because the council were too tight fisted to pay for it doing properly.

Cederic Silver badge

Re: Removing distraction = good

My friend from Guildford was on his driving test in the US, in a state that had just had its first roundabout installed.

Having learned to drive in the UK and being a successful race driver in his spare time the US driving test was always going to be a formality. Until he reached the roundabout.

In typical British fashion he came off the accelerator as he approached it, saw it was clear, hit the apex of his lane and was accelerating off the roundabout while the car behind him was still coming to a stop before going onto it.

The driving examiner turned to him in shock. "So that's how they work!"

Cederic Silver badge

Re: Removing distraction = good

I don't see the distinction. Plus any good roundabout can be taken at 60.

Except in Marrakech. Roundabouts there are magnificent for very different reasons.

A proposal to beat below-the-belt selfies: Crowdsourced machine learning using victims' image stashes

Cederic Silver badge

Thus breaching revenge porn laws.

Just don't email pictures of penis.

UK's Defra and Ministry of Justice facing £120m IR35 tax bills thanks to inaccuracies in assessing contractors' status

Cederic Silver badge

Re: Precedent

I didn't see mention in the article that this had been to court, let alone a precedent setting court.

So it has no legal relevance at all. HMRC can bleat all they like, they'd still need to prove that a company using CEST and following HMRC guidance were responsible for getting the wrong answer anyway.

CISA issues emergency directive to fix Log4j vulnerability

Cederic Silver badge

Re: Ah, Java

Quite why Log4J chose to allow access to JNDI is more interesting, plus the failure to escape logging strings.

This is not a language issue.

East Londoners nicked under Computer Misuse Act after NHS vaccine passport app sprouted clump of fake entries

Cederic Silver badge

That'd be Scotland, that with a 'papers please' mandate ended up with higher infection rates than 'whatever' England?

I'm far from convinced that this demonstrates the effectiveness of vaccine passports.

£42k for a top-class software engineer? It's no wonder uni research teams can't recruit

Cederic Silver badge

Re: It is almost as if the company does not test things properly before unleashing them on the world

However, my current job was advertised on LinkedIn and nowhere else.

It wasn't even on the company's website. I had to do some due diligence to make sure it wasn't a scam.

Apache takes off, nukes insecure feature at the heart of Log4j from orbit with v2.16

Cederic Silver badge

Re: So why did this feature exist in the first place?

The thing is that they could've provided the ability to include additional code through correct implementation of Inversion of Control. It's been a standard pattern for a couple of decades and is trivial for both the framework to incorporate and for users of the framework to use.

No need for JNDI (as that can be included if needed by the user of the framework) or LDAP lookups (as those can be included if needed by the user of the framework).

Log4j doesn't just blow a hole in your servers, it's reopening that can of worms: Is Big Biz exploiting open source?

Cederic Silver badge

As someone that's used and contributed to open source software for decades I disagree entirely.

People picking up litter reduces the demand for street cleaners but everybody in the village benefits.

Cederic Silver badge

Depends on the project. LibreOffice is shipped to production.

Cederic Silver badge

Re: what's hard

Hmm. Funding the Apache Foundation is a moral and just thing to do, and would help with the hosting costs for Log4J, but is distinct from funding the developers/maintainers of Log4J itself.

Cederic Silver badge

Re: Businesses are simply not in the business of fair dealing.

Re: "Part of it is American law saying "anything not directly for shareholder benefit is basically illegal""

Compliance the law overrides that specific mandate - including copyright laws. Breaching open source licences is not permitted just because it's better for the shareholders than paying a licence fee.

Cederic Silver badge

Excellent suggestion. Certain managementy types I work with are now giggling without even realising they've been educated.

Assange extradition case goes to UK Home Secretary as High Court rules he can be sent to US for trial

Cederic Silver badge

Re: Two sides

I don't care what the nature of the offence was.

Either he broke the law of the country he was in or he didn't.

I can make statements that would get me stoned to death in Pakistan, or that would get me caned in Singapore, or that would get me imprisoned in Thailand, and I can make those statements online and/or to people in those countries.

None of which breaks UK law, and so no, none of those countries can extradite me. A world in which everybody must obey every country's laws would be inherently broken, so how about we tell the US to back off and behave.

Ooh, an update. Let's install it. What could possibly go wro-

Cederic Silver badge

virus scans

I remember a decade ago. "Ah, my work laptop has started its daily virus scan. Guess it's time for a coffee."

Longer ago than that? "How do I disable the on-access scanning?" "You can't." "Ok, tell my boss she needs to hire another developer because you've just halved my productivity waiting for your virus scanning every time I hit compile."

I run sans AV at home. It's genuinely quicker and easier to rebuild from scratch if I do ever get an infection.