The Register Home Page

* Posts by Claptrap314

3711 publicly visible posts • joined 23 Jan 2015

IT boss left root session open for bring-your-kid-to-work day

Claptrap314 Silver badge

Sure

"back then"

Claptrap314 Silver badge
Happy

Re: BASIC to C conversion

I'm sorry, but that triggers my much younger self: "That would be AWESOME!" I would LOVE to play with that...

Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict

Claptrap314 Silver badge

Re: Surprise?

Decades, son. Decades.

US Air Force AI drone 'killed operator, attacked comms towers in simulation'

Claptrap314 Silver badge

Re: Call me a nasty minded old cynic, but...

https://en.wikipedia.org/wiki/Claud_Cockburn

Support newbie figured out how to avoid all-nighters, and his colleagues hated him for it

Claptrap314 Silver badge

The Panda bandit

Eats, shoots, and leaves.

The plain panda

Eats shoots and leaves.

Yes, this left-pondian uses the Oxford comma.

A developer always pays their technical debts – oh, every penny... but never a groat more

Claptrap314 Silver badge

Re: If it was hard to write, it should be hard to understand!

Re-reading this after...eight years. Still has me laughing with slight discomfort...

Oracle drops 1,449 security patches like it's the new normal

Claptrap314 Silver badge

If only

The problem is that really none of the incentives that got us hear have really changed. If anything, they are intensifying. Certainly, there is some low-hanging fruit out there which likely will be caught in the next quarter or two.

The problem is, that relying on LLMs means that the supply of fruit is going to be increasing.

One ChatGPT link could smuggle a rogue AI agent into your company

Claptrap314 Silver badge

I'm pretty certain that's a feature...

not a bug.

Get the popcorn, this one looks to be fun.

Linux kernel team publishes 432 CVEs in two days

Claptrap314 Silver badge
Facepalm

Repeated falacy here

Is that this set of bugs is the same set that would be found by running the same LLM a second time with the same prompts.

IT IS NOT.

We therefore have no hope that this actually represents a substantial improvement. This is an ongoing experiment, with no controls.

Greedy ransomware crews return for seconds after victims cough up first extortion payments

Claptrap314 Silver badge

Re: Something something Dane-geld

See, I was going to go the other way to get there.

" But we've proved it again and again / That if once you have paid him..."

NASA boss: make Pluto a planet again

Claptrap314 Silver badge

Re: At the time..

Remember XKCD on the nerd-geek relationship? My daughter hates it when I bring that one up whenever she starts waxing lyrical about the differences between the two.

Clear communication is not just something that hr puts in every job description. It forms the very basis of scientific and mathematical advancement.

You're expecting scientists to abandon a core part of their personality, and one of the parts that makes them good scientists.

Now I agree that if research were not done by squishy things with emotions, that this subject could and should be put off, if it weren't for my own experience.

I was researching an almost-century-old topic one day, and came across a strange term, one that had fallen into disuse after a couple of decades of debate. This change in term usage was rather distressing because it meant that any research I was doing from that period, I would have to use context to determine what was actually meant for a particular, related term.

Same thing here. TODAY, I doubt that there is any scientific reason to bother with the distinction between planet & dwarf planet. But maybe there will be in thirty years. And there is scientific value in clearly communicating across the decades.

Claptrap314 Silver badge

Re: It had to clear the neighborhood around its orbit – nope …

Turns out there is a scientific definition for "clear the neighborhood around it's orbit". The eight meet that definition. Other objects in the Solar System do not.

OpenAI admits it was the source of the agent swarm that attacked Hugging Face

Claptrap314 Silver badge

Re: Air Gapss

My recollection is that it was designed to jump air gaps. Wikipedia agrees. Hardly an authority, but I would be interested in authoritative links to back up your understanding.

Claptrap314 Silver badge

Only if they are communicating.

Claptrap314 Silver badge

Ham Sandwich on line 1

As I understand it (from someone who served on a federal grand jury), each member of the jury can bring a complaint to the attention of the prosecutor.

Note also that it is not rare for prosecutors to prosecute cases of domestic violence against the wishes of the victim.

So it can be done. No bets on if, however.

Comment in code read 'Dear future me, sorry I wrote this'

Claptrap314 Silver badge

Let it lie. But not for too long...

Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn

Ransomware curdles production at Coca-Cola's Fairlife dairy biz

Claptrap314 Silver badge

Re: Jack Daniels Coke

Jack & coke? Sounds like a real party!

NTP server that traveled back in time caused massive Aussie mobile outage

Claptrap314 Silver badge

Re: A retail tech problem too.

I've had fun with some internet games by changing the local clock to sometime in the past. When NTP says, "No, that's not the time", I get the benefit of a lot of time...

Scientist models way to make sure no one's violating the ban on nuclear weapons in space

Claptrap314 Silver badge

Re: So you could detect nuclear weapons previously placed in orbit

This. When the back-of-the-envelope countermeasures are so apparent, there is little reason to doubt that the serious will be forthcoming.

AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data

Claptrap314 Silver badge

This is an excellent observation, except for the following point: crackers tend to start with an initial access point, and then worm their way through a network. In particular, while getting root on the database server would allow a database dump, which would not do much if the data were encrypted in the database, that's not how I expect a cracker to get to the data. More likely, they manage to gain control over the database application. This application has legitimate access to the database, and the need to be able to decrypt whatever comes back.

Best practice might be to have the decryption key for the data generated as part of the session. In this fashion, the application would only be able to decrypt data for the current client. Sadly, I've yet to see it done that way. Possibly because doing so might break password recovery.

I am NOT saying that there is no value to encrypting at rest. Indeed, this has been best practice for a decade. But, sadly, it's a pretty limited block.

Zombie ‘who owns Unix?’ lawsuit comes alive again

Claptrap314 Silver badge

Re: In other news

Except for marriage and divorce...

Failed blockchain project ends with big fine for fibs about it being on track

Claptrap314 Silver badge

Re: I might be a bit thick...

The problem with financial transactions is that they have to be ACID when they settle. That means that the CAP theorem is going to kick in, so blockchain won't ever be fast.

Claptrap314 Silver badge

Re: I might be a bit thick...

The CAP theorem applies to blockchain (assuming a distributed implementation), and therefore to BitCoin.

Claptrap314 Silver badge

Technical limits

As was pointed out here some years ago, the CAP theorem applies to blockchain. Implementations which attempt to ignore this are going to have...disappointing results.

Claptrap314 Silver badge

Re: I might be a bit thick...

NO IT WAS NOT. I was there. On the cypherpunks list. In the 1990s.

There are two reasons to increase mining difficulty. The first is, you want there to be easy adoption and a finite total supply. Deflation is therefore built in. Some might consider this to be a Ponzi scheme. While there are similarities, there is nothing hidden or dishonest for anyone willing to read the technical specification, which not particularly opaque.

The second reason is, especially 20-30 years ago, the cost of work goes down with time. You need to make the hashing more difficult to avoid the bad effects of this.

Hackers shoveled snow for company, were rewarded with network admin access

Claptrap314 Silver badge

Re: Interesting

You obviously have not had training in reaction times. And the article is about social engineering. Someone intending to trigger some sort of *interesting* response from whatever the bag is holding might do EXACTLY what you did. That TSA agent did the right thing.

You do NOT make a move like that unless you enjoy Russian Roulette.

Claptrap314 Silver badge

Re: Interesting

My last job was at a health care middleman company. Filling out security surveys became my primary duty. Can confirm.

Five Eyes spooks warn AI means infosec incidents can become ‘major operational and financial crises’

Claptrap314 Silver badge

Re: As I Recall.......................

It's a BIT difficult to put information in a box unless it starts there. It's only slightly less difficult to keep it in a box if starts there.

Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era

Claptrap314 Silver badge

NO. The fault here is the #$*&$# 0-terminated string type. It was mildly criticized when it came out because academics did not understand that the next batch of programmers to be decanted would NOT hold advanced degrees in mathematics and therefore would make errors of this sort. If they did, Ritchie would have been denounced in every CS 201 course. What is really strange to me is that, even with the superabundance of buffer overflow errors that happened in the 80's, that there was no push to eliminate this datatype in the 90's.

Space Force goes to (pretend) orbital war following record-fast Rocket Lab launch

Claptrap314 Silver badge

Color me skeptical (or is that colour?)

"again suggesting that star wars - or at least orbital ones - are rapidly looking inevitable" Really? How many comparable exercises have we had with our nuclear assets, and how many DECADES have we gone without a nuclear war?

What is inevitable is that if you appear to be weak and/or unprepared that hostile powers will treat this as an invitation to aggressive behavior.

Demonstrating our ability to carry out operations in this theater discourages adventurism on the behalf of China and Russia.

Security boss thought MFA would be too much security

Claptrap314 Silver badge

Re: Not quite the same but...

By cutting power to the electromagnets? (Which is what I hope.) Fail safe is REALLY important...

Even the Secret Service won't use company-issued phones

Claptrap314 Silver badge

My first thought was, "at that range, how did he miss"? Turns out he was kicked off the gun team for poor accuracy.

It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns

Claptrap314 Silver badge

Re: infinite bugs

If we define a "bug" as a "failure of some subset of the code to perform as expected", then a finite-sized code has a finite number of subsets. If we require that the expectations be specified in advance, these will be finite, then there are only a finite number of fails available for any fixed codeset.

"99 bugs in the codebase, 99 bugs in the code!. Write one down, send fix around, 100 bugs in the codebase!"

Experientially, we'll run out of money long before the bugs are all fixed in many, many codebases.

And BB(432) is unprovable in ZF & ZFC.

Claptrap314 Silver badge

Re: Its called technical debt...

I LOVE hunting bugs. Finding a company willing to pay be an appropriate wage to do it? 20 months & counting, this time.

Anonymous researcher drops 0-day 'exploitarium' repo

Claptrap314 Silver badge

Re: Welcome To Unix, Windows etc

Hundreds of thousands, I would expect...

Claptrap314 Silver badge

Re: Excessive packet lengths?

You should probably check a mirror, because a lot of news articles describing overflow attacks go into some detail as to what actually happened.

Without checking, I'll bet you 100-to-1 that there WAS checking going on. It simply was inadequate because C doesn't make such checks easy, and to this day no one seems to understand that no, really, you need an advanced degree in mathematics if you want to prove that code is correct. (Nevermind the compiler, linker, and OS.) For a fun example, checkout StageFright I & II. Even when you KNOW there is an issue, someone without the proper training will get it wrong.

As for C, I DO blame the language here. Such errors are unheard of in asm because the flag register is immediately available, and EVERYONE knows to do the proper check. I mean, some fool might check O for unsigned operands, but what can you do?

Security researchers tricked LLMs into giving them cocaine recipes by abusing role models for prompt injection

Claptrap314 Silver badge

She's alright

She's alright. She's alright.

'Please do not vibe f--- up this software': Broken backups spark AI coding row in rsync project

Claptrap314 Silver badge

Quite a bit, it would seem...

'Dumbass' criminal breaks the 'first rule of ransomware club'

Claptrap314 Silver badge

Remember the airline hijacking spree in the 70's. While Western governments struggled for a response, the USSR engaged in direct action. They had very little trouble after that for some decades.

AWS to Quick admins: The access control didn't work, but you weren't using it anyway, so what's the problem?

Claptrap314 Silver badge

Enshitification

Do we go through this again? Suppose you become fed up. AWS has failed at it's supposed only reason to keep your business. What do you do?

Azure with Office 360? (We only schedule outages on days ending in "Y")

GCP with Gmail? (G as in "you account is GONE because resilience is someone we built for ourselves only")

Oracle? (We don't hire devs who want to talk about testing)

IBM (India)?

Well, just bring it in house, then. Is there even ONE member of your organization that has worked on a service delivering five nines? Are you ready to hire ops teams in three geographically dispersed areas to make sure that the lights are always on somewhere?

Getting the boring stuff right is HARD. It's also rather pricey. And very few organizations have the ability, let alone willingness, to identify the right talent to make it happen.

AWS is loosing to Azure because Microsoft it targeting the decision makers, not the coal faces. Technical merits haven't been the issue, or Azure never would have gotten off the ground.

EU's digital sovereignty boo-boo may be the best thing to ever happen to the project

Claptrap314 Silver badge

Small correction

"...code written by people someone else will regulate..."

Claptrap314 Silver badge

Re: Clarification

"England has no friends. She has only interests." This is the way of the world, and it always has been. Every play Civilization?

How to guarantee a speaker gig: Hack the system. Literally

Claptrap314 Silver badge
Facepalm

What decade is it?

XSS vulnerability? Seriously?

Threat hunters find Google API keys still usable 23 minutes after deletion

Claptrap314 Silver badge

Coincidence?

I worked at Google a decade ago, and that 23 minutes sounds suspiciously close to another number I know. Updates to the config service (Spanner?) had to be made 20 minutes before they were to go into effect.

HOWEVER, we also knew that that was only for global data. The golden data center cleared a LOT faster.

We made a point of partitioning our config data by region. In a pinch, we would effect a global change fast by pushing in every affected DC. I don't think I ever had to do that personally.

----

But for auth? I don't believe this "infeasible" nonsense for a single second, let alone 1380 of them. The trick is to view auth as an limiting case of quota--and G MUST enforce quota to state functional. A revoked access token has it's quota dropped to 0. That system will almost certainly clear in seconds.

TL;DR: AWS has it done in seconds. G absolutely can as well.

Google has seriously leaned into AI enshittification lately

Claptrap314 Silver badge

No mention of maps?

My city has a very nice freeway system looping around it. Six months ago, maps would make regular use of it. Now? Not so much. Too much compute to look too far "out of the way", and not enough computer science to identify & at least quickly try use of the freeways.

Ten years ago, it was the other way--freeways were way over preferred.

Google Cloud suspended major customer Railway.com without cause, causing outage

Claptrap314 Silver badge

Re: Probably shouldn't be using it anyway

This seems to me to be the most thoughtful post along these lines. Let me put it this way:

Resilience is hard. You just won't believe how vastly, hugely, mind-bogglingly hard resilience is.

Of course, I've not seen the particulars, but $10MM/yr doesn't get you very far down the road for a business like that. Maybe 99.97% uptime. Probably not.

Claptrap314 Silver badge

Re: In-house

That "stitching together themselves" is doing a LOT of work. I mean tens of thousands of man-hours. By VERY senior software engineers.

It's cost prohibitive, and that's why the gross margins are so high, and the service quality is dropping.

Zombie user account let hackers control the city’s water

Claptrap314 Silver badge

Re: This is why I still like "password change policy".

Not a horrible plan, but check how X compares to the length of vacations.

Google reimburses Register sources who were victims of API fraud

Claptrap314 Silver badge

Re: Remember, kids...

The business equivalent is a no-asset LLC. Monies are moved into the LLC account when bill payment has been approved.

That doesn't secure your data, but it DOES secure your bank account.

Iran claims US used backdoors to knock out networking equipment during war

Claptrap314 Silver badge

I am particularly fond of when they sent NSLs to the major shipping companies redirecting all packages sent to particular addresses to a classified location wherein certain modifications were made to the items being shipped.