* Posts by Claptrap314

2995 publicly visible posts • joined 23 Jan 2015

Bank of England ponders minting 'Britcoin' to sit alongside the Pound

Claptrap314 Silver badge

Re: Global Warming?

The Greater Fool. (The Greater Fool.)

Claptrap314 Silver badge

They know how to destroy bitcoin. It was obvious when the first proposals came up on Cypherpunks in the 90's, and it is obvious today.

But there is always a cost to such things, and so far, they have not cared to pay the cost.

Really, this is why I've never been into coin. If the time comes that they do care, and it is FAR from clear that matters will actually get to this point, it will be decisive.

Harassers and bullies succeed in tech because silence is encouraged

Claptrap314 Silver badge

I've been around long enough

To see two entirely independent waves of this. There was a spasm of complaints in 1990. They started with the complaint against Senator Packwood. They miraculously ended when Senator Kennedy's name came up. Originally, the claim was, "a woman would never lie about such things". Then, "we must assume innocence."

The entire exercise was blatantly about who's ox was being gored.

Of course, this wave started with one aging starlet taking on perhaps the most notorious Hollywood abuser (see the original "A Star is Born" to get an idea of how long this has been going on), which immediately turned into an anti-Trump crusade. We also got another spectacular attempt to destroy a Supreme Court justice by false claims.

Wise pastors have known for decades never to have a closed door when counseling a woman. The Reverend Billy Graham was not the only one to have what amounted to a reputation body guard that _always_ went first into hotel rooms for him. I know two state legislators in the 90's who were not so careful and who lost their jobs this way.

And people complain that a certain US senator today won't meet with a woman over a meal by himself.

I feel ridiculous for having to say this, but I am NOT suggesting that even a majority of complaints are unfounded. I am saying that tribalism regularly eclipses everything else in these situations. Also, that anyone suggesting that we do away with due process in the workplace is bringing in lions to drive out dogs.

This is already long, but let's talk about solutions.

Singling out particular types of unacceptable behavior as if they are somehow more problematic is beneath us as IT professionals. It's not sexual harassment, or racism or some other narrow thing--it's abuse. The solution is a culture that does not tolerate it. But at the individual level, it is not so simple. I've been out of work for almost eighteen months. Do I refuse to even talk to Uber? High-minded behavior is a luxury of the fed. My longest period of employment was at a company which had a horrible culture--because for years my wife's health needs prevented me from pursing a move.

As for sexual harassment, it's bizarre to watch the blatant sexism in people's approach. It is not even a little bit credible to claim, for instance, that men and women should be paid the same while a woman's complaint of sexual harassment against a man is to be accepted without challenge. The problem is that we are attempting to deny a billion-year-old fact: men and women are deeply different creatures. Until our approach to the matter uniformly acknowledges that fact, we are like the cartoon of someone fighting a fire while a stick in their back pocket is dropping sparks.

Microsoft received almost 25,000 requests for consumer data from law enforcement over the past six months

Claptrap314 Silver badge

Honestly, that's not a whole lot.

Do some checking on how many search warrants are served each year in the US. If the cops have reasonable suspicion that you've been a bad boy, I would expect them to search for evidence in all the places that evidence is likely to be.

Claptrap314 Silver badge

Re: Poor Canary

It's resting!

It was Russia wot did it: SolarWinds hack was done by Kremlin's APT29 crew, say UK and US

Claptrap314 Silver badge

Re: I love

An Israeli raid six months later on a Syrian site which did _not_ result in a protest by the Syrians.

You had to be paying attention to catch that one, I'll admit.

Cracked copies of Microsoft Office and Adobe Photoshop steal your session cookies, browser history, crypto-coins

Claptrap314 Silver badge

Re: I would still take my chances with the lesser crooks

Yes, but which solution provides which outcome?

It's very, very far from clear...

FBI deletes web shells from hundreds of compromised Microsoft Exchange servers before alerting admins

Claptrap314 Silver badge
Black Helicopters

They doing this with a cron job?

Because if not, it's not going to last for long...

I can understand the impulse to do something like this, but unless the servers are taken offline, one way or another, this smacks of feel-good-ism at best. At worst? -->

Claptrap314 Silver badge
Facepalm

Yep, because you just KNOW that the JEWS are the most likely culprit in any given scenario.

Take that picture of Mr. Mustache off your wall. It went out of style in the 40's.

Wormhole encrypted file transfer app reboots Firefox Send after Mozilla fled

Claptrap314 Silver badge
Flame

Re: CPU usage

To be clear--this demonstrates that these people are NOT concerned in the least about the end user. Stay away.

Satellite collision anticipated by EU space agency fails to materialize... for now at least

Claptrap314 Silver badge

The LEO commons

is a lot bigger than the doom-sayers say. Having said that, when it DOES fill, the mess will also be bigger.

At the same time, various cleaning technologies are going to get easier almost every year, and the leadership of the big boys are rational enough that someone who declares, "We're going to zap object X in 48 hours unless someone objects" won't be known as the bad guys. The biggest thing is likely to be the national loss of face for some one else cleaning up your trash, but that's avoidable.

Oracle vs Google: No, the Supreme Court did not say APIs aren't copyright – and that's a good thing

Claptrap314 Silver badge

It's a bit ironic that "I invented the Internet" Al Gore was the one to change the mandate of the USPO from "Issue valid patents" to "Help our customers get patents".

SOME of us knew where this was headed immediately...

17 years since release, iMac G5 finally gets an upgrade after tinkerer shoves M1 Mac Mini inside

Claptrap314 Silver badge

Re: you've slipped, luv

Nope. It was the GPUL. We (IBM) took the GP, cut 2/3rds of its L3, added graphics instructions, and sold it into Apple's entire line.

Sucker.

SAP: It takes exploit devs about 72 hours to turn one of our security patches into a weapon against customers

Claptrap314 Silver badge

This gives me confidence

in technologies like self-driving cars.

IN THEORY, a company like SAP could back off the "new features", and focus on bug & vulnerability fixes for a couple of years, thus drying up the profitability of decompiling fixes. This, in turn, would cause the bad guys to move one & even lose expertise.

But no, we must have FEATURES! YESTERDAY!

<sigh>

Japan tests digital currency, because all the cool kids are doing it already

Claptrap314 Silver badge

Re: Crypto vs Banking

So there is no paper in your recycle bin?

Look, I'm a coin skeptic, but let's stick to actual problems.

Ex-Geeks staff lose legal bid to claw back withheld training costs from final paycheques

Claptrap314 Silver badge

Re: A scam?

My wife was offered a job by Ross Perot's company in 1989 with a very similar (but MUCH more onerous) arraignment. (We weren't married at the time.)

The detailed breakdown is the part that I don't buy. There are WAY to many ways to play fast & loose.

But an arraignment of "after x weeks training, you owe us y, prorated over z years" is a clear contractual arraignment. Take it or leave it, your call.

I've actually mentioned the possibility of a similar arraignment to potential employers regarding relocation support.

Facebook job ads algorithm still discriminates on gender, LinkedIn not so much

Claptrap314 Silver badge

Occam on line 1...

The far, FAR more likely cause is that these "biases" are in fact the natural result of following the ROI.

I missed seeing one myself, but apparently the presentations by the ad teams to the rest of the Googlers regularly resulted in mass triggerings.

Buckle up, Buttercup.

Feature bloat: Psychology boffins find people tend to add elements to solve a problem rather than take things away

Claptrap314 Silver badge

Re: Lego example

That's actually a dangerous heuristic you're implying. You certainly never spent much time on a farm, for instance.

Just because YOU don't know why something was done does not mean that there was no reason. There almost certainly was. The correct question is "is the reason currently valid?"

Airline software super-bug: Flight loads miscalculated because women using 'Miss' were treated as children

Claptrap314 Silver badge

Re: Not necessarily.

I'm sorry, but re-read what happened. That's the sort of error that should have either grounded the fleet, required some sort of fallback to a manual process, or overridden the computations to assume all passengers are adults.

This was a callous, even cynical decision by someone in the airline to go for profits over a blatant safety issue. Full stop. At Boeing, it can at least be argued that no one person had all the data to know that they would be endangering lives.

Patch alert for Apple fans: Cybercrooks have already been exploiting this flaw in iPhones, iPads, and watches

Claptrap314 Silver badge

Re: "...after being alerted to multiple possible intrusions by Google."

Got me reading it twice...

Sitting comfortably? Then it's probably time to patch, as critical flaw uncovered in npm's netmask package

Claptrap314 Silver badge

It took WAY too much effort to parse the article simply because I had no expectation that octets would treat a leading 0 as meaning that what follows is in octal.

Quick question: How would you parse 011.011.011.011? I would expect it to be decimal because I've got it in my head that some systems (old Windows? I don't know!) require three digits.

I could be completely wrong of course, and THAT is why I rely on a library to handle such things. In fact I did not even know that 1.2.3 was a valid IPv4 address until I grabbed the python library for a test project.

So, yes. If I'm faced with identifying, finding, reading, interpreting, and implementing some RFC, I'm going to instead look for a library with a decent reputation and use it.

IF, (and I do mean IF) I happen to observe something weird (like accepting 1.2.3 as a valid IPv4 address), I'll check around and see if that's correct.

But I'm probably NOT going to trust an npm. There is WAY too much bad mojo in that space.

After oil giant Shell hit by Clop ransomware gang, workers' visas dumped online as part of extortion attempt

Claptrap314 Silver badge

Okay, Shell is not an IT company....

But SURELY they've got enough semi-competent IT people to, I don't know, use scp?

Why even consider some ridiculous proprietary solution to a problem which has been well and truly solved by the OS community for decades?

Blockchain may be the machinery of mischief, but it can't help telling the truth

Claptrap314 Silver badge

Re: One thing I've learned in life

Actually, I'm pretty sure that the shouting itself is a significant flag of a scam.

Claptrap314 Silver badge

Re: 51% attacks, de-fi, tracing/fungibilty

Ironically, one of the most obvious wins for blockchain is lubricating internal currency exchanges. In fact, my understanding is that the SWIFT system is actively piloting.

Blockchain --> MORE profits to the big banks. At least, for now...

Claptrap314 Silver badge

It's tarring by association. Yes, cypherpunks@toad.com was a hotbed of technolibertarianism, and the common ideology supporting coin remains heavily libertarian. HOWEVER, tying with with "racists" and some other sleeze-du-jour links libertarians to these other groups in a way which is...propagandistic, and to a degree that far exceeds the Right-Pondians.

FCC moves forward with plan to ban three Chinese telcos from American market

Claptrap314 Silver badge

Re: Worthless effort

1) Building half of a wall is only a "worthless effort" if you have no willingness or intent to complete the job.

2) Stopping shipping containers is a MUCH simpler thing than ripping out networks.

Being asked to rate fake news may help stop social media users sharing it, study finds

Claptrap314 Silver badge

Nah, there has never been a major journalist or major news show spreading fake news.

Seriously, must I bring out Thomas Jefferson's famous quote on advantages of not reading the papers?

Fake news has been around since long before the Republic. It was VERY well known to the authors of the US constitution, as well as the members of the first US congress, which proposed the First Amendment, and to the members of the state legislatures, which passed it.

The purpose of the First Amendment freedom of speech and freedom of the press can only be honestly read as the right of the minority to loudly make statements which the majority would consider either to be lies or to be offensive. Statements accepted as true and unoffensive by the (current) majority need no such protection.

Lying is basic to human nature. Get your big boy skeptic pants on.

What could possibly go wrong? Sublet your home broadband to strangers who totally won't commit crimes

Claptrap314 Silver badge

Re: Sounds great...

I contacted my ISP about this more than a decade ago. Turns out that 822 specified more than one port, and it's only the default one that's blacklisted. I continue to email the world from my home system inside various ISPs ever since...

Google fails to neutralize lawsuit that complains Chrome's incognito mode isn't very private at all

Claptrap314 Silver badge

If accurate

then it sounds like the judge does not understand what's going on. At all.

Google analytics is a domain serving javascript like any other. It has nothing to do with any particular browser. Any expectation that a browser's incognito mode would magically know about each and every of the hundreds of tracking domains and turn them all off...is magical thinking.

Unless Chrome is sending this data out itself, there is nothing here.

PSA: If you're still giving users admin rights, maybe try not doing that. Would've helped dampen 100+ Microsoft vulns last year – report

Claptrap314 Silver badge

Re: Surely there must be a better way to do this

At my last workplace, that was Visual Studio...

Google engineer urges web devs to step up and secure their code in this data-spilling Spectre-haunted world

Claptrap314 Silver badge

Re: How do they get away with it?

I am saying that

#1 The manufactures did due diligence at the time when implementing these features for consumer products.

#2 The manufacturers warned in the product literature that the parts were not certified for CONFIDENTIAL use.

There is nothing to apologize for. If you buy your three year old a plastic bat, and on the label it says, "Not for use with MLB", are you going to expect it to take a pitch from the Minors? I expect you will be wanting your money back...

A Code War has replaced The Cold War. And right now we’re losing it

Claptrap314 Silver badge

Re: Rust to the rescue?

#1: system uptime has almost 0 to do with service uptime. And we are talking about services.

#2: system uptime reliability has a hard limit of power supply uptime reliability. (I'll give you the network for free.)

You can only choose one of those.

Claptrap314 Silver badge

Are you aware that in recent decades, a TLA would occasionally contact a company and say, "Hey, sign this NDA. We need to talk." followed by "We've observed foreign actors compromising your systems in the following fashion. You need to fix that. Quietly." To which the response is, "Huh. I can see that the attack would work, but we don't see any evidence of it being used."

The general conclusion was that the intelligence services were doing exactly what a rational actor would want them to do in a hostile world.

But yeah, not always.

Claptrap314 Silver badge

Rule #1: The consumer is king

We've gone through this many times in different permutations. The FDA was created to try to drive out the snake oil salesmen. The professional boards (mostly medicine & law) exist to try to keep the worst practitioners from causing the death of their clients. But in the end, the consumer remains king. We had a perfectly good consumer cell phone with a much better security model than Apple, let alone Android. Remind me, how is RIM's retail branch doing these days?

Okay, so consumers don't really understand the dangers of bad security. Even if they did, security is a distributed threat--99.9999% secure means 100% insecure. To argue that consumers are willingly going to bear the costs of security is to argue that Communism works. (Hint to the Millennials: even the Pilgrims could not pull it off.)

How about we start at the other end of the problem: what exactly is meant by "this server is secure"? istoomuch.jpg How about, "this code is secure". Care to back up that claim? May I see your MA in mathematics? Because proving that a piece of code actually does what you want it to do, and nothing else, is at least equal to a thesis. (And, yes, I do have one of those.) That's assuming that the compiler has also been proven. And whatever was used to create the compiler. And the OS. For both. And the cpu. For all. Moreover, your CPU must not only do what the architecture says, but must be side-channel free. That means (and I have the background to say this) either taking a 10x hit to speed, securing not just your code, but all code running on the server--including cross-domain interactions between applications (think: SQL injection), or getting completely new cache architecture.

Okay, so somehow we have a magically secure programming environment. Luckycharms.img And, you want some new code. You going to hunt down a mathematician to write it? Oh, but maybe we can use the model that engineers use. The mathematicians doesn't have to write the code himself--he can check the work and certify it. No. grumpycat.img Code is not a piece of metal that can be machined into tolerance. It does not have microfractures that only spread at a given rate. There is no procedure to guarantee changes are correct. kurtgodel.img When we are talking about demonstrating security, we are talking about creating valid proofs, and while two might be three times as fast, that's two fully trained mathematicians, not a mathematician and someone else.

But security really is that important. Why don't we pass some laws & regulations? yeahsure.jpg Just how long will a politician stay elected if he passes a bill that outlaws 99.99999% of existing code?

We are losing the war. We do need to fight it. But we must focus our efforts where it can be productive. We need public awareness of the pervasiveness of the security threat. Maybe we can get Bill Gates to fund a publicity campaign. I do believe that liability legislation has its place, but the only way that is going to survive is if it is extremely incremental. That is, too little to be effective until some sort of phase change happens. Something in the same spirit as the GDPR, but significantly more limited in relative scope.

Yeah, I really try not to think too hard about this. Kinda like the Cold War.

Claptrap314 Silver badge

Much sound and fury...

signifying nothing.

At the top of the article, you cite the utterly debunked Bloomberg magic chip as credible. And the quality of the analysis doesn't improve much from there.

I agree with the final paragraph, 100%. But ill-informed busybodies pontificating is not going to help anything.

Claptrap314 Silver badge

Re: I remember

Tell me. Does Rust prevent SQL injections? XSS? Unsafe object deserialization?

You've pulled the 70% out of thin air. Rust deals with certain common, but ultimately narrow class of low-level bugs. Certainly, an improvement in many cases, with cost. But you're not going to save Tinkerbell with it.

Claptrap314 Silver badge

Re: Rust to the rescue?

Do you even know what 9 9's reliability means? I learned SRE at Google. I consider 6 9's to be theoretical.

Claptrap314 Silver badge

As the much-misunderstood general testified, "There are no civilians." If you want the government to protect you (ie: be a civilian), then you will need to have government provided built CPU, smart phone, OS, and all apps. No sites available unless they have been approved by the government, (and no changes on them without going through change management.)

I don't think you will be happy.

Claptrap314 Silver badge

" If you were doing this then you were effectively impervious to that entire class of attack unless the attackers start on the inside of your network. (which should be guarded against by other access control measures)."

Seriously? Were you found in a cabbage patch this morning?

Even if, by some act of magic, your VPN was perfectly secure, that does close to 0 about one of your users who mistakenly clicked on an ad or clickbait article and now has been rooted.

Your user's machines have been compromised. All of them. For quite some time. Now--explain your security posture with twenty-year old procedures is adequate.

We still are not settled on exactly what should be considered proper MFA. Keeping up is going to matter for a while.

US newspaper's 'Biden will hack Russia' claim: A good way to reassure Putin you'll leave him alone

Claptrap314 Silver badge

Let's see if it works.

Claptrap314 Silver badge

Re: Its all a cunning plan

Now, now. Everyone knows that we shut down the internet on April first. We need to let the bits air out, you know.

Twitter sues Texas AG to halt 'retaliatory' demand for internal content-moderation rulebook in wake of Trump ban

Claptrap314 Silver badge

Re: First Amendment - False Claims

When someone speaks of their First Amendment rights, they are speaking about rights enshrined in the First Amendment. As part of the constitution, the Amendment can only address government.

Now, when I go to a public square, grab my soap box, and start speachifying, I am exercising my right to free speech. Humans being lazy creatures, I might even claim to be exercising my First Amendment right. If someone objects to my words, and they come by with a loud speaker, and use it speak over me, are you going to claim with an honest face that my right to free speech is at that point effective? There is a term, "heckler's veto". If we allow (or encourage) that, then we no longer allow effective use of the right.

What if, in some region of the country, a political party has come to dominate politics to the point that nomination by the party is tantamount to election. Suppose further that this party refuses my entry. No government violating any right as far as the eye can see. I claim that in fact said party is denying my right to be effective in my voting. (And for those who don't understand what I am talking about, in Grovey v. Townsend, the United States Supreme Court unanimously ruled that the rule by the Texas Democratic Party forbidding blacks from participating in their primary was constitutionally sound. Not our finest moment at all.

Big tech is hanging out at the town square. They are handing out megaphones to some people and not to others. (Also, playing Madame Defarge and plastering flashing signs all over the place) For many, many people, these platforms are loudspeakers allowing them to reach tens if not hundreds of times as many people (who actively want to hear what is being said) as any other method.

To deny the reality of the network effect and say, "build your own" or some such is at best disingenuous.

Certainly, we expect (and demand) that content promoting, planning or celebrating acts which are malum in se be taken down. But my idea of what counts differs rather drastically from, say, Pooh Bear's. And there is a strong concern that there is institutional bias in these companies against conservatives. It's easy to dismiss the anecdotes. I myself would be skeptical except that:

I personally witnessed, in 2015, a director at Google brag at a TGIF (weekly company-wide town hall meeting) that they had thrown an election in Central America.

Of course, El Reg reported research in August 2016 catching Google suppressing negative search suggested for Hillary Clinton.

El Reg also reported in 2012 that Facebook "partnered" with the Barack Obama reelection campaign to use their network. I've not heard of them doing so with any conservative candidate.

"Free speech", like "poverty", is intrinsically a comparative term. For thousands of years, even the ability to write a letter was the province of a few Mandarins. Then came universal education, and paper, so that the term "papers" was expressly included in the Fourth Amendment. Now, I can send an email to any of three billion people. IF, and ONLY IF, we can both find ISPs that allow us to do so.

Claptrap314 Silver badge

I am reasonably certain that there was a clause in the original treaty of Union that allowed Texas to divide itself into five at will, as well as to secede. As is often the case, however, subsequent events, particularly those of 1861, nullified the treaty. Texas's annexation to the Union in 1865 did not undo that nullification.

OVH data centre destroyed by fire in Strasbourg – all services unavailable

Claptrap314 Silver badge

Lambs to slaughter

Anyone naughty who cares about physical location has as their day job scouting buildings for potential interesting locations. Otherwise nondescript buildings with any sort of heightened security measures scream "Find out what's going on here!"

Obligatory Schlock

Surprise: Automated driving biz finds automated driving safer than letting you get behind the wheel

Claptrap314 Silver badge

It's a computer. It will be hacked.

If we are lucky, it will mostly be ones & twos. Just don't anger anyone with the resources to digitally disconnect your break line. And pray that we never go to war with China. Or that Iran starts redirecting their resources from nukes to roots.

We JUST TODAY have an opinion piece about the sorry state of affairs in the software industry. Connect the dots, people. The failure mode that I'm worried about is system compromise. Convince me on that before surrounding me with thousands of murder machines.

Claptrap314 Silver badge

Re: That's a useless statistic

I upvoted you, but the failed Smokey & the bandit maneuver might well have happened even with an attentive driver. Radar would have picked up on it fine, but lidar, like the Mark I eyeball, had a tough time of it.

Claptrap314 Silver badge

Re: But... but... we are driving because we like it, right?

With a Bond-sytled rotater to the one saying "GREEN LIGHT"?

Microsoft settles £200,000+ claims against tech support scammers who ran global ripoff from cottage in Surrey

Claptrap314 Silver badge

Re: And prosecution?

Because even Microsoft is more effective than your typical national government in getting **** done?

Google's ex-boss tells the US it's time to take the gloves off on autonomous weapons

Claptrap314 Silver badge

Re: This person...

"If the time has come for the lion to lie down with the lamb, I prefer to be the lion."-slight paraphrase

Morals are for the living. If we do not give our opponents good reason to worry either that their weapons will be ineffective, or that the response will be more than they want, they do as they please.

And what they please displeases me.

Claptrap314 Silver badge

Re: Can be banned

Great idea. Now, how do we apply it?

What inspections can be performed? What is code and what is training data? (And what kind of poisons have been slipped into the training data?)