The Register Home Page

* Posts by bombastic bob

10944 publicly visible posts • joined 1 May 2015

It took 'over 80 different developers' to review and fix 'mess' made by students who sneaked bad code into Linux

bombastic bob Silver badge
WTF?

Re: "use the money to bribe Microsoft to hire him away from Redhat"

see icon...

'services' in windows NT (and later) were supposed to be like daemons in POSIX OS's...

* run in userland as background processes

* 'system' type of user context (root, other user)

* auto-start on boot or on demand

* managed by system utilities

without arguing against systemd [which I would] I question the validity of your comparison between windows and Linux and 'windows services' [which I've written] and the assertion that in any way the windows way is superior...

bombastic bob Silver badge
Stop

Re: not just umn.edu

no... peer review is still possible.

bombastic bob Silver badge
Unhappy

Re: not just umn.edu

right - significant peer review is in order.

Sad.

This week, Apple CEO Tim Cook faced surprisingly tough questioning from judge

bombastic bob Silver badge
Coffee/keyboard

Re: Apple's to lose

only a "feeling" that it was profitable.

I couldn't find the 'vomit' icon, so I'll use this one instead...

US Treasury wants to treat cryptocurrencies like cash – as in you need to report $10k+ transactions

bombastic bob Silver badge
Devil

Re: So every time you fall to ransomware

As I understand it, if you pay $10k or more there might be a 1099 form for that, which you'd send to the IRS and a copy to the person/entity you filed it for. But when you deposit the check in the bank (for over $10k) the bank reports it. That's my understanding, at any rate. I would expect it would accompany every OTHER disclosure, like payroll and tax forms.

But if "they" suspect something, they'll just audit you. Or, if you make enough money. Etc.

A ransomware payment would be a HUGE line item in the books. Reporting it would be the LEAST of your problems.

Cloudflare stops offering to block LGBTQ webpages

bombastic bob Silver badge
Devil

you DO have a point, when you are specifically looking for LGBTQ(etc.) related things. However if this is a work-based internet filter, maybe you can use your phone instead?

Some work-based filtering systems make it VERY hard to update Linux systems, essentially blocking all of the repo mirrors. I'd prefer NO blocking at ALL, but you know how some IT admins can be... and yet a "porn blocker" [if it even works] might be all they need.

I also just did a search on "lgbtq friendly business San Diego" and the top 5 results were business listing sites, NOT porn. And that's worth pointing out also.

bombastic bob Silver badge
Meh

I doubt Cloudflare set up the filter to outrage gay people.

No, they probably set it up that way by request.,, because a LOT of people really do not want to see that kind of thing. There is a HUGE difference between "I do not want to see it" and "make being gay illegal and punishable by death". (Fortunately most of society has moved WAY past that last bit)

Now, if the really offensive stuff is labeled as "porn", a simple porn filter might do it, to eliminate the NSFW stuff at any rate, without the "triggering".

Apple's macOS is sub-par for security, Apple exec Craig Federighi tells Epic trial

bombastic bob Silver badge
Meh

Re: Keeping things secure

Is Windows really that problematic...or is does it simply present the largest target footprint

Both, when compared to a computer running Linux, BSD, or even Mac OS.

The problem with Windows is NOT the user's ability to run whatever he wants. The problem is the inherent lack of peer review on the OS itself, certain vulnerabilities that are basically designed into the system itself (through the API), and a security model that encourages you to run with "admin" privileges all of the time using an "in the cloud" identity.

[and I used to be such a windows fan, too, decades ago, as it was SO much better than DOS]

bombastic bob Silver badge
Childcatcher

Re: He does have a point, even if it's draconian

when you read the article looking for it, you find their justification.

a dramatically higher bar for customer protection

and

iOS is something you'd let a child use.

But rather than having a "child lock" available for PARENTS to decide to use, WE are ALL "children" to them.

And, that makes it "for the children".

Microsoft hits Alt-F4 on Windows 10X: OS designed for dual-screen PCs axed

bombastic bob Silver badge
Thumb Up

Re: Locked down Windows

well said

bombastic bob Silver badge
Devil

Re: why does this remind me of

When I first started using CodeView for Windows I had to have a 2nd (monochrome) monitor. I always thought it would be cool if I could somehow use that with regular windows applications.

So it made the case for dual monitors with separate function, for debugging at least. Until it didn't (MSVC).

bombastic bob Silver badge
Unhappy

Re: Dual screen

decades ago, when Windows 2k was the newest, I experimented with multiple desktops. I wanted to see if I could have applications running on one that were separate from the other. I discovered that SEAT COUNTING was behind this - you could not get the start menu to run properly on the second desktop without having multi-seat [like terminal server, basically].

Otherwise, you could run applications there if they were "aware" enough to open up on the other desktop. But it wasn't very useful because of what I just described...

I don't know how Windows 10 manages multiple desktops now [probably some 'soft' way that hides some windows and makes others visible]. In theory, though, you should be able to have one set of desktops for one monitor, and another set for another monitor. That capability has been in the NT kernel for a LONG time. NT 4 had it.

BUT... with the way they handle seat licensing, it's effectively "brittle".

bombastic bob Silver badge
Thumb Up

Re: So you might say ...

heh, you motivated me me to look those up.

("that's a big 10-4, good buddy" - that song by C.W. McCall)

Pics or it didn't happen: First images from China's Mars rover suggest nothing has gone Zhurong just yet

bombastic bob Silver badge
Boffin

Re: Nothing there...

actually I was hoping they'd do "confirmation" and additional science that the others have not yet done (for whatever reason), then the data is shared around the world so scientists can mull over it for years to come.

bombastic bob Silver badge
Pirate

Re: Cold War II in SPAAAAAAAAAAAACE....

Heh - ours has a laser AND a helicopter

bombastic bob Silver badge
Pint

Re: Good to see.

yes - beer for the boffins!

1Password unsheathes Rusty key, hopes to unlock Linux Desktop world

bombastic bob Silver badge
Joke

Re: Not a fan

Who needs a password locker? There are *OTHER* ways for storing passwords:

* Fa[e]ceBook, Tw*tter, G[a,oo]gle, Micros~1 Login

* Sheet[s] of paper

* Same PW, EVERYWHERE! "Correct-Horse+Battery*Stapl3"

* Keep it short and easily remembered

bombastic bob Silver badge
Devil

Re: Not a fan

So far the best password manager I've found is KeePassXC (the C language version of KeePass that can be compiled from source on Linux and FreeBSD).

There's even a button to make passwords visible. I use it a LOT so i can have longer more random ones. And though it may be possible to auto-paste into a browser, I typically just copy/pasta the passphrase from the KeePassXC 'edit' dialog box directly into the browser or ssh session. Or you could use the 'make visible' button to see the password and just type it.

(and I must have about 50 of them stored in there, now, because I *REFUSE* to use FB, T, G, or Micros~1 logins)

Yahoo! Japan! offers! free! comment!-moderation!-as!-a!-service! API!

bombastic bob Silver badge
Pirate

Re: Neat in theory, not so much in practice

A carefully worded comment might illustrate how you might easily get past an AI algorithm.

(but I'll leave that one as an exercise)

This also reminds me of that old phrase, "the tail wagging the dog" when "the few" (easily triggered) must control "the many" (who lose freedom).

So humans with soft-touch moderation are needed to fight off the trolls and bots. However, an AI is more likely to behave like an aggressive spam filter, where e-mail from your mom is marked 'spam', but e-mail from scammers and 'male enhancement' vendors get through. EVERY! SINGLE! TIME!!

The internet does not HAVE to be a sewer. But it is. Maybe a click-through disclaimer is needed?

bombastic bob Silver badge
Big Brother

Re: By any other name

The silence will be deafening.

THAT would be the ONLY positive outcome possible. Yet HACKERS will always be able to cheat any algorithm. I suppose a proper set of snarky adjectives and twisted metaphors would be a good start...

When the chips are down, Intel's biggest gamble isn't what to do – it's whom to do it with

bombastic bob Silver badge
Devil

Re: Subsidies?

Require that US federal funded agencies buy these "Made in America" chips

That (inevitably) may be necessary at some point... And hopefully it makes pure economic sense, especially if the process is heavily automated.

Space is hard: Rocket Lab's 20th Electron launch fails

bombastic bob Silver badge
Joke

Re: what are they going to name the next one

"Albatross around your neck"

(best I could cough up on short notice)

Cloudflare launches campaign to ‘end the madness’ of CAPTCHAs

bombastic bob Silver badge
Unhappy

Re: Hardware dongle

do it automatically while revealing your current cell phone number and IP address along with other personally identifying information that was gleaned the last 92 times you used this method.

Would the 'app' that you would need to make this happen ALSO upload GPS tracking data from your location over the last several days so that "they" will know where you've been?

yeah no tracking going on here. Nothing to see, move along...

[it's bad enough when you use a credit card in a store AND online and when you visit the online page you see your in-store shopping history along with online history...]

bombastic bob Silver badge
FAIL

Re: Hardware dongles?

Hardware Dongle = TRACKING - you identity is NOW KNOWN to the web site, uniquely so.

As IRRITATING as a CAPTCHA is, I'd rather use CAPTCHA than GET TRACKED on that level...

Only an ad-slinging over-present cloud network would come up with THAT as a "solution".

(at least cache clearing and VPN can anonymize you a little bit, even with CAPTCHA)

Ransomware victim Colonial Pipeline paid $5m to get oil pumping again, restored from backups anyway – report

bombastic bob Silver badge
Happy

Re: cyber job at colonial

This deserves an equivalent BOFH article

bombastic bob Silver badge
Stop

Re: FAIL $5 million for criminals

Unless you are running high frequency snapshotting (and who does that on everything - especially file systems?) restoring from backup is a guaranteed loss of data

Some time ago I had a hard drive that was developing bad sectors in a short period of time. It was my server box. Here is how i handled it:

* do separate backup of as much critical data as I can, data that is not corrupted.

* install OS onto new hard drive, plus the basic software needed, as quickly as possible

* swap hard drive

* restore important data from most recent backup

Now it is up and running. OK I spent a day doing that. Better than a WEEK.

Then I went about analyzing the old drive to see what stuff was recoverable, and what wasn't. In the mean time, the server was RUNNING.

FIRST, get it BACK RUNNING AGAIN. *THEN* you worry about data recovery. Human safety gets shoehorned into the front of the line, as needed.

But I don't know how easily their systems could be restored, which might suggest their backup and restore process was a part of the problem. So maybe my perspective is off a bit. Still, I think they OWE us an explanation, regardless.

In any case, you can get SOMETHING running fairly fast if you set things up properly with your backups. If you're missing a week's worth of billing, at least you did not STOP THE OIL FLOW.

I'm also thinking that if I had set things up better, i.e. having a backup hard drive waiting in the wings with identical software [minus data] on it, that I could just swap in the drive and restore the most recent data from backup, and be up and running in a couple of hours, and not most of a day. BETTER planning, yeah.

bombastic bob Silver badge
Devil

Re: $5 million for criminals

And there should be a fine of 10 times your blackmail money to prevent this kind of thing from happening.

that would be a good start, yeah. step 1.

Hey Vlad Putin, you can earn some worldwide kudos by ACTUALLY SENDING those perpetrators to the modern day equivalent of a gulag... and THAT would be an EXCELLENT "Step 2"!!!

China says its first Mars rover Zhurong has landed on the Red Planet

bombastic bob Silver badge
Devil

and it's got a helicopter.

(air traffic control, permission to land...)

Tor users, beware: 'Scheme flooding' technique may be used to deanonymize you

bombastic bob Silver badge
Devil

Re: The benefits of Tor (assuming no additional hanky panky), no more no less than this:

chrome (at least the versions I have seen) does not automatically delete privacy tracking info on exit but Firefox can. But for chrome (on Linux or BSD - windows, mac YMMV) you can either delete all of chrome's files in ~/.config and ~/.cache [which gives you back the defaults] or cherry pick and just delete MOST of them until you get all of the ones that track you, but don't actually delete settings you want to keep.

bombastic bob Silver badge
Meh

Re: Problem already solved

I saw that in my main browser, which prompted me to re-try it in the "safe-surfing sandboxed" browser that has script enabled.

I tested it with chrome on FreeBSD [a version built from ports a while back]. I initially used my "kill history" script that deletes LOTS of those files that chrome tries to use to save data across sessions. I recently increased the size of that list of files to be deleted, when I discovered that I wasn't deleting enough of them any more (certain things were starting to persist across browser sessions).

*ahem*

In any case, I did the "deanonymizing" test twice and got two completely different IDs. It does seem to take a while, though. You'd have to do this completely in the background for it to be effective, and over a fairly long period of time.

But a social media giant that "keeps you on the page" for a while (or runs a web bug script even after a trackable page closes) might still find it practical...

An actress, an internet billionaire, and Tom Cruise walk into a space station ... not necessarily at the same time

bombastic bob Silver badge
Devil

Re: Nothing there...

maybe we could send up a few "hotel" modules with piano lounges, restaurants, fully stocked bars, and other typical guest accommodations.

Space tea, space coffee, and space croissants at 7 AM, every day for the interplanetary breakfast bar.

And every lounge with a "stellar" view of the, er, stars.

Water's wet, the Pope's Catholic, and iOS is designed to stop folk switching to Android, Epic trial judge told

bombastic bob Silver badge
Meh

Apple App Store "a necessary evil"

If they simply made it POSSIBLE to load a non-app-store application [similar to Android downloading and installing a non-store APK] this whole issue would PROBABLY go away...

After following the first link in the article, I'm reminded that Apple banned Epic's game because it allowed in-game purchases outside the Apple store. But I recall _other_ applications being banned by Apple for different reasons. If there are no exploits or gross vulnerabilities, WHY ban them?

Instead, Apple has made _THEMSELVES_ the gatekeeper of iOS, with the obvious motive of PREVENTING people from switching to an Android platform (as indicated in the article), as well as preventing "apps they do not like for some reason" from being deployed on iOS.

So it looks like they got the 'evil' part of the definition right. The 'necessary' part, not so sure.

regardless iOS is great if it's what you want - I just don't see why they need a STRANGLEHOLD on "The Store" like that. I have to wonder how many customers they LOSE because of it.

Compsci boffin publishes proof-of-concept code for 54-year-old zero-day in Universal Turing Machine

bombastic bob Silver badge
Devil

Re: Shows we have lost the plot!

eh, that's not _ENTIRELY_ true...

You're describing "Harvard Architecture" where code/data spaces are separate things. Your typical minicomputer never did this. In fact, PDP-11 code could even be categorized as "self modifying" when you put variable parameters after the function call, directly in INSTRUCTION SPACE, by using the previous program counter as a base register, and then cleaning the stack up with the 'RTS' instruction. Soft interrupts are similar, parameters are expected after the EMT instruction and the stack gets cleaned up when you return from interrupt. And to pass those parameters, you literally poke the values into the code space before making the call.

So it's worth pointing out that many non-IBM computer systems have had code/data in the same address space, particularly microprocessors and minicomputers. The big iron machines may have had separate code/data, but not necessarily all of them.

Anyway, some computer history from 50 years ago form someone who was there...

[worth pointing out - AVR microcontrollers use 'Harvard Architecture' so that you can run the program directly from NVRAM]

bombastic bob Silver badge
Devil

Re: Calling it a "vulnerability" is a bit of a stretch.

it lacks proper input sanitization, and is therefore vulnerable to code injection.

How about that - the world's oldest 0-day exploit is a code injection vulnerability!

[I was actually expecting 'buffer overrun' when I started reading the article]

so yeah - in MY book of definitions, that'd be "a vulnerability".

Microsoft embraces Linux kernel's eBPF super-tool, extends it for Windows

bombastic bob Silver badge
Devil

ditching Windows [kernel] and licensing Wine.

I've been wanting THIS for a long time.

It might cause some initial problems, due to case-sensitivity of file names and the use of '/' vs '\', as well as drive letters and different device names/handling, but I believe if they were to "embrace" Wine, and migrate to a Linux kernel with Wine on top, we'd all be better for it.

I'd pay money for that, particularly if I can keep my Mate desktop and just use the subsystem to run windows applications.

China sprayed space with 3,000 pieces of junk. US military officials want rules to stop that sort of thing

bombastic bob Silver badge
Devil

Re: F-15 Eagle shoots down satellite in 1985

you could make use of memory metal to cause an expected change in temperature (heating or cooling, whatever works best) to open up the "space blanket", and it wouldn't require a whole lot of expense nor electricity.

A solar sail could work the same way, actually...

Uncle Sam wants 'ethical hackers' to crack its planetary defenses, but don't expect a pay-day from this bug bounty

bombastic bob Silver badge
Unhappy

Re: US Inland Revenue Service?

The I.R.S. doesn't like tax evasion much. So if anyone bought and sold a lot of bitcoin and made real money on it, and did NOT declare all that on the tax forms [it's considered "foreign currency" and apparently has a special place to declare it, though i always use tax software that just asks me about it], then the IRS will be wanting to find out how much money you made and bill you for the unpaid tax, with interest and a LOT of penalties. Yeah, they do that.

US declares emergency after ransomware shuts oil pipeline that pumps 100 million gallons a day

bombastic bob Silver badge
Devil

Re: One word:

thanks for the reminder, I need to do backups today. not the automatic daily "do the dumps and copy the incremental changes to 3 different machines on the network" kind, but the "burn it to DVD and put it in the safe" kind. just my own stuff, but still...

(I admit, I've been a bit lax on the DVD burning)

Perl changes dev's permaban for 'unacceptable' behaviour to a year-long lockout after community response

bombastic bob Silver badge
Devil

Re: Very.Big.Sigh

didn't I see some articles on El Reg over the last year when they basically asked people to post available jobs? OK I could go searching, but this discussion triggered my memory...

bombastic bob Silver badge
Unhappy

Re: Very.Big.Sigh

infighting and factionalism

*THEREIN* lies the problem. That, and what appears to be a too-willing desire to wield "power"

'A massive middle finger': Open-source audio fans up in arms after Audacity opts to add telemetry capture

bombastic bob Silver badge
Meh

Re: What the GDPR requires

I found an issue where Audacity will already have a "disabled by default" build option for the tracking, as a CMake option, so the FreeBSD port could simply leverage that as-is. Good thing I guess...

bombastic bob Silver badge
Meh

Re: F**k It

Well it looks like there's an issue for this over on github

https://github.com/audacity/audacity/pull/835

It's marked as 'closed' though. I was going to put my own $.10 in but looks like the pressure is on.

One specific thing they said: "If you are compiling Audacity from source, we will provide a CMake option to enable the telemetry code. This option will be turned off by default."

I expect that FreeBSD Ports and various Linux distros will be taking advantage of this, by NOT putting the tracking in.

(probably best to read their words from the issue)

bombastic bob Silver badge
Mushroom

Re: Audacity opts to add telemetry capture

I, too, had similar kinds of comments...

TRACKING is THE WORST thing they could have done, short of a PAYWALL. And it's only been a few days...

bombastic bob Silver badge
Unhappy

Re: What the GDPR requires

Local applications should NEVER have ANY tracking in them, REGARDLESS of opt-in.

I think the FreeBSD port might even need to include a patch to disable tracking COMPLETELY, or perhaps make a "no tracking" build option... that is NO TRACKING by default!

(to THINK they had the AUDACITY to add tracking...)

Big right-to-repair win: FTC blasts tech giants for making it so difficult to mend devices

bombastic bob Silver badge
Devil

Re: Being able

reasons for soldered-in battery:

* thin profile [people want this]

* WAY less likely to have the 'flickering' problem that flashlights get when galvanic corrosion appears on the battery terminals [even with gold and silver, dissimilar metals and moisture and electrical charges still present]

* unlikely for the battery to be easily reversed, which would probably explode it and/or seriously damage board components.

etc. - there are many good reasons for soldering the battery in place. Then you void the warranty if anyone changes their own battery. But I agree it SHOULD be both possible AND reasonably easy to do so. And cracking the case open should take less than a minute and be repeatable.

bombastic bob Silver badge
Meh

Re: End of life

that might be reasonable if you bump it up a bit, to account for the time it takes to change out a battery.

Keep in mind that just looking at a broken device and determining what is wrong with it might cost more than $50 in the USA (when you factor in costs of labor, time, equipment, number of techs needed to handle the expected demand, and so on).

Back in the day, TV repair shops had a minimum fee for this reason.

However, a price cap on battery repair *MIGHT* motivate engineers to make it easier to change the batteries out, in order to save time for the tech doing the replacement and make it cost-effective, and at least 'break even' on the repairs. Profit would be better, of course.

A plus for the industry: if this only applied to FUTURE devices, they could re-design THEM to be more easily repaired, and THEN use this mandated service as a "new feature" for the new phone/slab/whatever.

(I'm currently thinking of a case modification in which you simultaneously press pins into 2 or more waterproof holes on the sides of case, where locking hooks are, and then slide it open - this could allow it to remain "thin" while also making it possible to open in a shop [or DYI repair], AND to assemble quickly, and ALSO rework a device that fails in manufacturing or is returned for warranty repair)

bombastic bob Silver badge
Unhappy

Re: F- it!

strangely, i-Things may be one of the biggest violators in this regard.

LiPo batteries wear out after a few years, usually not that few (3 or so). A relative of mine has an i-Pad, a hand-me-down actually, and it needs a battery. I checked the procedure for repairing it and it involves heating the glue around the screen to separate the halves so you can access it. The batteries ARE available, but the procedure is just as likely to do damage to the unit as allow you to repair it...

(a battery compartment where you can access it directly would be nice)

[Unfortunately, sending it in to get it repaired would cost half as much as a new one]

on a related note, I've repaired laptops a few times, and they are difficult enough to deal with. This is just impossible in my view. I can only see a cracked screen as a result of getting it slightly wrong.

Microsoft has gone to great lengths to push its tech, but survey suggests many devs slipped through the .NET

bombastic bob Silver badge
FAIL

overrated

the whole '.Not' thing (In My Bombastic Opinion).

The attempt to be all and do all for both back-end AND desktop on EVERY possible OS is just too, too much. And when Micros~1 began to use it on the desktop, in Windows Server 2003, performance was the FIRST thing that suffered. I know because I had Win Server 2k running on the same box, but 2k3 ran like a FAT BLOATED PIG, required over twice the RAM, and 3 or 4 times the CPU clock speed to even APPROACH equivalent performance.

That kinda said it all, to me [other than the humongous bloated shared lib collection that takes an hour or so to "update the indexes" after updating the libraries, even on MODERN computers!].

Visual Basic 6 returns: You've been a good developer all year. You have social distanced, you have helped your mom. Here's your reward

bombastic bob Silver badge
Devil

Re: Why not bring back REXX too!

VB6 had multithreading

not multi-threading per se, as i recall. VB had a 'DoEvents()' [or similarly named] function that would call the message loop handler. It could make it LOOK like you were multi-threading. It's like cooperatively pre-emptive tasking.

In fact, this was present in VB 1

What I used to do for time consuming operations is disable the window that was doing the task by setting the 'Enabled' (I think that's right) properties to zero, then do the function that is time consuming while the hourglass cursor is visible, where the polling loop calls 'DoEvents()", and then fix it back once the operation is complete. typical example: waiting for DDE transactions or file transfers.

bombastic bob Silver badge
Devil

Re: Why not bring back REXX too!

REXX has its usage as well. But I prefer bash scripts and Perl. More powerful.