* Posts by EnviableOne

2102 publicly visible posts • joined 28 Jan 2016

Canadian data order risks blowing a hole in EU sovereignty

EnviableOne

according to co-pilot

Canadian Law: Under the Criminal Code and PIPEDA, our obligation is limited to providing records in our possession or control. We cannot compel a foreign entity to disclose data outside Canadian jurisdiction.

French & EU Law: The parent company is subject to the GDPR and French law, which require strict safeguards for international data transfers and prohibit disclosure without a lawful basis or treaty mechanism.

International Cooperation: Requests for data held abroad must proceed through the Mutual Legal Assistance Treaty (MLAT) between Canada and France or other recognised diplomatic channels.

EnviableOne

Re: Treaties

The French might, but they wouldn't admit to it in front of anyone.

They will do their usual and say "Je ne comprends pas le français que vous parlez."

followed by "Je ne parle pas anglais"

Scottish council still rebuilding systems two years after ransomware attack

EnviableOne

If you haven't tested, does it count as a backup?

There are government emergency plans for specifically 2 things: Pandemic and Widespread Cyber Attack.

Neither plan survived enemy action. gov.scot has a lot of cyber resources, and they've been there for years:

https://www.gov.scot/publications/cyber-resilience-incident-management/

Crocs get the Xbox treatment with sole-crushing price of $80

EnviableOne

A previous employer did a collaboration with Crocs, and I think they still have about 80% of them in the warehouse, not even the staff want them at a big discount

London councils probe cyber incident as shared IT systems knocked offline

EnviableOne

Re: UK Knowledge Sharing

Considering the Mayor doesn't know what resilience is, as his comments in the BBC coverage suggest, I seriously doubt it.

EnviableOne

Re: Shared IT Services should not mean merging the data of multiple Councils

With the councils, it's less likely to be a shared IT service, and more likely to be one group providing a service across both council areas, which means federated auth and cross-council access.

It happens in the NHS too.

Ministry of Defence's F-35 blunder: £57B and counting

EnviableOne

Re: Again why beancouters

The QE Class are a joke. There is no way we needed fleet carriers. After the mid-life upgrade, which expanded the flight deck, they were more than capable of operating enough sorties for the types of missions they were deployed on.

The proof can be seen in the numerous navies, Spanish, Italian, Japanese, etc., that are building/have built carriers similar in size and aircraft complement to the Invincible class.

using the same techniques used to keep the crew count down on the new carriers and using the lessons learned from deploying the Invincible class, for all likely operations, the carrier strike capability is not something the UK is going to need to employ alone, and by combining with partners, we can mount that volume of sorties as happened in Libya.

The FAA(Fleet Air Arm) was never likely to have the funding to provide 96 aircraft for both carriers, and keeping them operational was always going to be an issue.

The optional EMALS upgrade, at a highly restrictive cost and with the technology unproven.

The only option is VSTOL; no time should have been spent considering the F-35C, as the A and C are thoroughly compromised to have commonality with the B.

The loss of resilience on the third vessel, the loss of speed, the cut corners going CODLOG rather than CODLAG, invincible steaming from the Caribbean to the Gulf of Aiden in less than a week was a feat that the QE or PoW could never achieve

Basically, the QE class were an overambitious plan to provide a capability that we did not need, at a cost we couldn't afford. something similar to what we had, with a new Mach 2 capable V/Stol from BAe detailed designs were created, never made it to prototype, would have carried considerably less risk, and provided capability considerably quicker, at a reduced cost, and be able to use the current facilities and maybe delivered before the previous lot were retired.

EnviableOne

Re: more Typhoons

The whole point of the F-35 was cominality, have you seen the Sea Typhoon, it's so heavy its max take-off loadout is pitiful.

The Typhoon is half the aircraft it replaced.

The MOD can't purchase anything without changing the scope every few weeks, it's what bankrupted Marconi

EnviableOne

Re: Again why beancouters

The whole Elizabeth class CVF project was an exercise in vanity; the previous Invincible class size carriers are cheaper and easier to operate and crew, they are more effective in littoral combat, and an effective platform individually or support larger deployments in a group. They were considerably faster and had better propulsion.

As for the flying rust, BAE offered a Mach 2 capable VSTOL aircraft to replace the Harrier, but the US of A had to find someone to share the cost of the pork barrel known as F35, and the little lapdogs in Whitehall were taken in tow, so we had to build a pair of white elephants, that we cant afford to crew and fuel, to put the pork barrel upon.

There were bad decisions all around in the 4G/5G aircraft capability

Microsoft Configuration Manager to switch to an annual release cadence

EnviableOne

controlled obsolence and Perpetual to subscription transition

See Title

This seems to be the M$ MO at the minute: migrate to the cloud, pay us monthly, or face obsolescence.

And they seem to be confused as to why servers are moving to Linux

Win10 still clings to over 40% of devices weeks after Microsoft pulls support

EnviableOne

Re: A Letter

Dear Microsoft,

Good luck in education, we have been providing them free kit for years, "All your Kids are belong to us"

Yours Apple

EnviableOne

Re: I keep a win 10 laptop

Edge still has the Trident engine in it; you just need to tell it its ok to use it for the specific sites.

EnviableOne

CE only requires that the software is licensed and supported, and recommended (mandatory for highs and criticals) that all released updates are applied within 14 days of release.

Easily managed with most Linux Distros.

CE audit costs £320 + VAT for less than 10 employees, and comes with £25k cyber insurance, if your turnover is less than £20 mil.

CE+ is a bit more onerous, but usually about a day and a half of consultancy to get that cert

EnviableOne

Re: Benefits for Microsoft (spyware), not users

Hannlon's razor applies; there is no reason to tar MS with the malice of inflicting bugs. I'd say it's more down to the lack of QA and testing before it's released to the masses.

EnviableOne

Re: Bloat like never seen before

controlled by local GPO and Decrapified, you can get a pretty decent ad-light, snooping-light, AI-light version of Windows 11 that kinda just works

EnviableOne

Re: No need or rush to upgrade

Pi 5 with 8GB should be man enough for most tasks, if you are into heavy gaming, then 16GB and some DIY graphics additions:

https://www.jeffgeerling.com/blog/2024/use-external-gpu-on-raspberry-pi-5-4k-gaming

The race to shore up Europe’s power grids against cyberattacks and sabotage

EnviableOne

Re: There is a simple fix - which will not be implemented

The simple plan is to use the distribution network to send data, no need for a separate infrastructure, and modulate the data on the electric carrier signal.

It's been done before and could carry all the data requirements for grid management, self-contained within the grid infrastructure.

There is no need to connect it to the internet, but you can still use TCP/IP and the resilience built into the grid to make the data transfer reliable.

AI bubble to deflate as enterprises defer spending to 2027

EnviableOne

Anthropic vs OpenAI

Who's gonna win?

While OpenAI have first actor advantage and mindshare, Anthropic's models are better and work, the rest are going to fall by the wayside

Anthropic's Claude is learning Excel so you don't have to

EnviableOne

the problem with Excel

The problem is Excel is just good enough at so many things, and considerably cheaper than the proper tools, that convincing purchasing that you need the tool needs multiple spreadsheets, graphs and PowerPoint, so it never happens.

Everything you know about last week's AWS outage is wrong

EnviableOne

Re: "A single AWS region is a single point of failure."

one of my go-tos:

https://xkcd.com/908/

Windows 11 update knocks out USB mice, keyboards in recovery mode

EnviableOne

Re: The question is...

Its ok they expect their code to be bad now, so all patches have A/B options so if it fails they can release a KIR to flip the logic

UK calls up Armed Forces veterans for digital ID soft launch

EnviableOne

There is no Voter fraud

Yet another project that Digital ID is not a solution for.

There never was a voter fraud issue (there have been 3 cases in the last 20 years, all for people being voted for, not doing the voting) so no need for ID.

Digital ID does not solve Illegal migration. If you don't have papers, and the people you want to work for don't check, it doesn't matter if they are digital or not.

There are very few benefits to being a veteran in the UK and never have been, records are easily checked if you can be arsed, so no need for Digital ID

'Fax virus' panicked a manager and sparked job-killing Reply-All incident

EnviableOne

Re: Reply-all

its worse than that, there was a reply to All storm in NHS Mail, including all 840k nhs staff, took weeks to sort it out.

https://www.bbc.co.uk/news/technology-37979456

What do we want? Windows 10 support! When do we want it? Until 2030!

EnviableOne

Re: Installing Linux Alongside Windows

The problem is that the Windows boot loader needs tweaking to allow you to boot into something other than Windows.

And all the UEFI/Secure Boot settings are beyond the standard Windows LUser

Oracle rushes out another emergency E-Business Suite patch as Clop fallout widens

EnviableOne

ERM Software

Something about eggs and baskets

Shadow AI: Staffers are bringing AI tools they use at home to work, warns Microsoft

EnviableOne

TBF, when I was trained for Consumer Windows support, we were told a format re-install would fix any problem.

OK it was caveated that that should be the last resort

EnviableOne

Golden Eyeeeeeeeeeeeeeeeeeeeeeeeeee

EnviableOne
Coffee/keyboard

Microsoft struggles with Windows.

You owe me a keyboard, my friend.

there is tea everywhere.

I am still of the opinion that MS should rename itself Beta and refer to its customers as testers

Scattered Lapsus$ Hunters rage-quit the internet (again), promise to return next year

EnviableOne

the problem with SLSH

They are a subgroup of the com collective, so are replaceable, each provides a specific service, and if they are caught, someone else steps up to take their place.

Hacking is and always will be something you age out of, and also something you can get into at a young age, so there are always more people to step up to replace those who leave / get caught

CISA sounds alarm over TP-Link wireless routers under attack

EnviableOne

Google categorically denies Gmail has been hacked

never believe it until its denied

No more Blocktoberfest? German court throws book at ad blockers

EnviableOne

this is a non-story

THe EUCJ will overrulle the BGH and everything will continue as normal, except the lawyers will have fatter wallets.

Marc Andreessen wades into the UK's Online Safety Act furor

EnviableOne

So very few are disagreeing with the stated intent (preventing those below legal age from seeing inappropriate content)

Many people are complaining about how it has been implemented and its potential impact on freedom of expression and privacy.

If the implementation had been postponed until a secure and privacy-preserving proof of age system could be put in place, then the whole issue could have been avoided.

But as always, the government wants to be value signalling and doesn't actually care if it works or causes a massive-scale Ashley Madison-style data breach.

Unfortunately, the average teenage boy is infinitely more tech-literate than the average MP and will find a way around the controls, whereas the average grown-up, for who this content is created, will end up suffering as their private habits are exposed in the inevitable breach of the age verification service.

While technology catches up and puts in place the verification, it has made a considerable dent in the finances of the increasing number of "Content Creators," who rely on its consumption for their livelihood.

Watch out, another max-severity, make-me-root Cisco bug on the loose

EnviableOne

TBF input validation by many names has been part of OWASP top 10 since the beginning, its not gonna be solved anytime soon

Yes, I wrote a very expensive bug. In my defense I was only seven years old at the time

EnviableOne

fastest backups in the west

If Concorde still flew London to New York, it could pay for itself as a high-density backup solution.

3 hrs cross Atlantic with several PB in the back

/me investigates buying some of the ones that still fly

Australia finds age detection tech has many flaws but will work

EnviableOne

55378008

Never underestimate the lengths a 13 year old boy will go to to see boobs.

Bearing in mind some of the convictions for hacking recently, this is more likely to prevent less tech savvy adults from accessing the sites than the kids its trying to "protect"

Microsoft 365 brings the shutters down on legacy protocols

EnviableOne

yes they do security welll

NTLM is still based on MD4 hashing

Glazed and confused: Hole lotta highly sensitive data nicked from Krispy Kreme

EnviableOne

Data Minimization

Man, am I glad for the data minimisation principle in GDPR.

They would never have been able to justify storing all this in the Federated States of Europe.

'Major compromise' at NHS temping arm exposed gaping security holes

EnviableOne

underestemating the impact

Those NTLM hashes from the ntds.dit will all be cracked but now. I used to use this technique in the NHS to do password audits, could usually get about 60% in the first 3 days.

Single passenger reportedly survives Air India Boeing 787 crash

EnviableOne

Re: Pure speculation

This seems to be the most probably cause, an unlikely double engine failure.

especially as it appears to be taking off fine, then stops and drops.

If it were a bird strike, it would come back on the administration, as they should have done more about bird strikes and moved the airport/runway away from the residential neighbourhoods.

If it turns out to be a fuel starvation issue, Boeing will try to blame it on lack of maintenance, maybe rightly, but with the MAX issues, they are going to have a struggle.

At least they shouldn't have too many issues locating the black boxes.

Schneier tries to rip the rose-colored AI glasses from the eyes of Congress

EnviableOne

Re: That creeping centipede Elon Musk

Murphy's golden Rule: The one with the Gold makes the rules

Ukrainians smuggle drones hidden in cabins on trucks to strike Russian airfields

EnviableOne

Re: Ukraine did

Russia has already had to start conscription in limited ways; they have close to 1 million casualties, and you don't replace that many with volunteers, unless people are being voluntold.

Many initial volunteers were from the Wagner Group, and Putin imploded that.

So with nigh on .7% of the population being killed, there is starting to be a significant part of the population that knows of someone who has been killed.

tie this with the treasury emptying fast, and the PR hit from this attack, and no amount of accidental falls from the 7th floor will be able to silence the opposition.

European customers report Oracle Cloud identity outage, Big Red is silent

EnviableOne

OCI

Offline Cracked Infrastructure?

They need to sort this out, or their already tiny share of the cloud market is going to shrivel to nothing

IT chiefs of UK's massive health service urge vendors to make public security pledge

EnviableOne

Re: Easy to solve:

Your post shows you have never managed macOS in a corporate environment.

It's not impossible, but it's a lot of work; the devices aren't designed to work that way.

There is no bulk installation or update mechanism, there is no centrally controlled permissions.

There is no easy way to catalogue and protect a network as a whole, just point solutions.

Windows is EVIL, in a corporate environment, however, it's a necessary one.

In the NHS even more so.

Medical devices are a pain, but it took years to tweak Linux so it could effectively authenticate with the NHS smartcard System, and then they killed the project.

EnviableOne

S2D2

The more things change ....

All politicians are in it for themselves, no matter their allegiance.

How can someone earning more than 99% of the population seek to accurately represent the interests of those they are supposed to represent?

The problems in the NHS are more fundamental, and they are acting as designed. The HSCA 2012 was designed to break up the NHS, and it has done so. There is no longer an NHS, just 2600+ franchises with the badge and 2600+ boards with their own agendas and pockets to line, just like their paymasters in parliament.

Boffins devise technique that lets users prove location without giving it away

EnviableOne

The Devil is in the Meta-Details

Meta know you were at the gas station for 10 minutes every x days, they know you go to a specific supermarket for a few hours every week/month, and even that you go to mom and pops local (if it still exists) in between

They don't know, but can infer a hell of a lot from that.

Meta also know who you talk to who you message, where they send your push notifications to, the meta data may not tell you as much as the data, but it gives away a lot of things you might want to keep private

DOGE may help Elon Musk's biz empire dodge $2.4B in liabilities – Senate probe

EnviableOne

Re: "No one individual, no matter how prominent or wealthy, is above the law,"

of course they are he added the tie breakers to tip it in his direction

LLMs can't stop making up software dependencies and sabotaging everything

EnviableOne

Re: Is this news ?

35 will never be executed, you fail at programming, but might just get a job as a vibe coder

Artist formerly known as Indian Business Machines pledges $150B for US ops, R&D

EnviableOne

because someone has to have a use for it... they have been trying to find it for circa 30 yrs

CIO and digi VP to depart UK retail giant Asda as Walmart divorce woes settle

EnviableOne

What Happened to M&S IT

Makes sense now, the two adults in M&S IT left in 2021 to get phat paychecks from this lot, and now they are going back to fix the mess it got into since they left.

Official abuse of state security has always been bad, now it's horrifying

EnviableOne

This was definitely the case, the frustration of the ruling party that their laws were ruled unenforceable by the ECJ, who, unlike all the politicians in the discussion, are the adults in the room, was a major reason for them wanting to get out of their jurisdiction.

The ECJ upholds the international agreements signed by the member states and uses its independent jurisprudence to decide legal matters or refer them back to a lower court.

The UK legal system used to have these checks and balances, but their power was easily eroded by the kids in parliament to a point that the power they have over parliament is about as much as that that Charlie can wield (they might hold stuff up a bit, but ultimately it will happen)