* Posts by AnAnonymousCanuck

71 publicly visible posts • joined 29 Mar 2016

Page:

Crypto wallet shop Ledger confirms customer data lifted in Global-e snafu

AnAnonymousCanuck

Shouldn't That Be?

Blockchain (non-)security biz Ledger says customer information was accessed in a breach at it's (insecure) ecommerce payment partner Glob

FTFY

AAC

Brit lands invite-only Aussie visa after uncovering vuln in government systems

AnAnonymousCanuck

Re: His name appearing

Really?

> He said that it took him a couple of hours to find a critical-severity vulnerability in DFAT's systems

Sounds like an extremely insecure system to me.

YMMV

AAC

HPE tells customers to patch fast as OneView RCE bug scores a perfect 10

AnAnonymousCanuck
FAIL

Agents on Every Machine are a Security Hole

Ahhh. Yes, one of the first monitoring systems, OpenView, an agent on every machine. It gave everyone,, including outsiders, an open view of your IT domain.

I see it is now called OneView, So does it now give everyone a single, complete view of your IT domain?

YMMV

AAC

Airbus exec: Most CIOs in Europe will not finish SAP ECC6 migration by 2030

AnAnonymousCanuck

Standard Business Processes?

>We're coming back to SAP standard, which will bring a lot of value because next time we upgrade, it will be much easier,

And of course SAP Standard offers a huge competitive advantage as well as the being the right business process for every business and those processes were designed by, who? Right.........

As an (almost ex-)operations guy, I love the technical side, keeps my life easy, but such vision on the management side would terrify me enough to look for a new job, sell my stock....

YMMV

AAC

MAGA cognoscenti warn feds away from shielding AI infringers

AnAnonymousCanuck
Devil

Copyright is Dead, Get Over it

Subject says it all. And it died in the Napster era. I have been part of 3 companies sued into oblivion. Of course, none of them had assets. And the code is still public. I view it as our contribution to society.

YMMV

AAC

Lifetime access to AI-for-evil WormGPT 4 costs just $220

AnAnonymousCanuck

How Long Was The Prompt

>The script also established an SSH session and allowed a remote attacker to escalate privileges, perform reconnaissance, install backdoors, and collect sensitive files.

Because the specs and reqs I would require to build that script would be at minimum 1 full page in point form, multiple pages in paragraph form

Of course, if I provide my script as a prompt ........

YMMV

AAC

Airbus: We were hours from pausing production in Spain

AnAnonymousCanuck
Facepalm

An Aviation Company Runs Out of Gas?

Maybe they should have had one of their pilots dip the tank once/twice a year.

YMMV, maybe not if the tank is empty.

AAC

ShinyHunters 'does not like Salesforce at all,' claims the crew accessed Gainsight 3 months ago

AnAnonymousCanuck

OAuth Security

It's not that the tokens are insecure in themselves. However, storing security tokens in a SCCS is negligence and has been considered so since at least the mid-80's (SCCS: Source Code Control System for the non-devs).

YMMV

AAC

LLM-generated malware is improving, but don't expect autonomous attacks tomorrow

AnAnonymousCanuck

Pot Calling the Kettle Black?

Plus, Claude "frequently overstated findings and occasionally fabricated data during autonomous operations," the Anthropic researchers said.

https://djnn.sh/posts/anthropic-s-paper-smells-like-bullshit/

AAC

Cloudflare coughs, half the internet catches a cold

AnAnonymousCanuck
Mushroom

Funny The Register Could Not Stay Up

This morning was the morning we identified which network properties have competent network and system administrators.

I was extremely surprised to find The Register was not in that group.

There was no need for a SPOF 25 years ago. The fact that people choose to have them now, blows my mind

YMMV

AAC

MCP attack abuses predictable session IDs to hijack AI agents

AnAnonymousCanuck
Angel

C++ Web Apps in 2025?

That's we we were doing in 1996. And it was not a wise technical choice then.

I sure did learn a lot tho

YMMV

AAC

Google DeepMind minds the patch with AI flaw-fixing scheme

AnAnonymousCanuck
Facepalm

How Long to Review?

Monday Morning conversation:

Hey Bob, did you see your latest task? lucky you, you get to review a 4.5 million line patch from, wait for it..... CodeMinder.

Oh, by the way, Project Managment wants it done by Thursday night for their Friday update.

Have Fun

AAC

Techie found an error message so rude the CEO of IBM apologized for it

AnAnonymousCanuck
Devil

Re: What's the joke?

I would return a sleep 5 minutes to your code/connection instead of the real database error.

Yes, I was/am and always will be an Oracle DBA.

I don't ever remember using the name Kevin, but I ......

YMMV

AAC

Google's dev registration plan 'will end the F-Droid project'

AnAnonymousCanuck
Devil

Re: Now Google starts _exactly_ the behavior that made me avoid Apple ...

And I assume you wait quietly in that line? Why not start a LOUD conversation about how the credit union is too cheap to hire decent programmers and is now too cheap to hire cashiers and decent branch managers.

Repeat.

YMMV

AAC

How and why Linux has thrived after three decades in Kernelland

AnAnonymousCanuck

Re: It's quite well known that Linus Torvalds himself doesn't enjoy public speaking.

> You have 10,000 desktop PCs in a company and you want to make sure that logins work and policies are enforced across all of them - still tricky to do simply on Linux

Really? Maybe you should try hiring someone or two who have a clue.

YMMV

AAC

Careless engineer stored recovery codes in plaintext, got whole org pwned

AnAnonymousCanuck

goatse.txt

Wonder what I should put in that file now that the AIs will come looking for it?

What does the text version of goatse look like?

Inquiring minds do NOT want to know!

YMMV

AAC

Python survey shows growth even as Foundation funding falters

AnAnonymousCanuck
Thumb Up

Re: Upgrade Relatively Easy?

I wish the libraries I need are available in perl. When I finally understood perl I loved it.

Of course it took a little while to understand it :)

AAC

AnAnonymousCanuck
Facepalm

Upgrade Relatively Easy?

Hahahahahahahaha

Run a real production application. Which version of which libraries?

What about all the one line edits in 70% of your libraries because no-one can be bothered to maintain them. What about the new one line edits that will be required for the upgrade

Just run in venv! Which venv? 3.10, 3.11, 3.12 or how about 3.8? Because the app uses libraries that are only available for these versions.

Python is an operational nightmare.

The app was written in 3.8, upgraded through 3.9/10/11 and now runs under 3.12.

I reckon 50-100 hours to move to 3.13. Not going to happen

YMMV

AAC

'Suddenly deprecating old models' users depended on a 'mistake,' admits OpenAI's Altman

AnAnonymousCanuck
Angel

Re: Knockers-up

Taken, Please send my fiver to Alberta, Canada. I might suggest you fallback and punt, but I'm not sure if that one will make it across the other way

Wit luv

AAC

Microsoft reminds developers that Visual Studio 2015 is set for retirement

AnAnonymousCanuck
Joke

vi is Being Retired!!!!!

Oh no, what am I going to do, PANIC, I do not want to return to ed. Nooooooooooooooo

YMMV

AAC

Trump teases ‘approximately’ 100 percent tariff for imported semiconductors

AnAnonymousCanuck
Mushroom

Re: successors

> Ooooh yes. That might not be for long.

For any of us given the zealots in the world

50 years ago, Gates and Allen made the deal that launched Microsoft

AnAnonymousCanuck

Yes it did. They are called panel switches :) Up is (usually) 1 and down is (usually) 0. Unless you mounted them horizontally orientated :)

YMMV

AAC

CloudBees CEO says customers are slowing down on 'black box' code from AIs

AnAnonymousCanuck

How Do You Teach People to Review Code?

If all the code is written by LLM's?

YMMV

AAC

37signals is completing its on-prem move, deleting its AWS account to save millions

AnAnonymousCanuck

Re: Press X to Doubt

Ahhh, five 9's, a concept from the nineties :)

As a young (40 year old) DBA, in a shop that had 1 scheduled outage per year (Christmas), I use to tell my juniors:

"If we go down unscheduled it will take a lot longer than 15 minutes to get back up."

YMMV

AAC

Google admits depreciation costs are soaring amid furious bit barn build

AnAnonymousCanuck

Re: There is no business case for AI.

I don't know, the open AI Speech to text model, Whisper, allowed me to keep my voice assistant (kalliope) 100% local instead of using Google or Amazon cloud services for interpretation.

Extremely valuable to me!

YMMV

AAC

Writing for humans? Perhaps in future we'll write specifically for AI – and be paid for it

AnAnonymousCanuck

Re: Pie in the sky

Exactly, copyright is dead, get over it. It's time for new economic models anyways.

AAC

Malware in Lisp? Now you're just being cruel

AnAnonymousCanuck

All my perl code was malware, not fit for the purpose :)

AAC

Vivaldi 7.2 browser wants to topple tech's feudal lords

AnAnonymousCanuck

DONT WANT CHROME Or CHROMIUM

Subject says it all.

AAC

As Trump slugs Canada, Mexico and China with tariffs, industry groups hope trade war weapon isn’t pointed at their feet

AnAnonymousCanuck

Re: It's all in how you look at it

Start shipping your products to us. We will buy them. It is quite impressive how us canucks all feel quite "hurt" and want to do what we can to express our disillusionment.

With friends like America, who needs enemies?

YMMV

GLTA, we're gonna need it

AAC

OpenAI's Operator agent wants to tackle your online chores – just don’t expect it to nail every task

AnAnonymousCanuck

I Do Want! But Must Be Mine On My Machine With My Ethics

Subject says most of it, but filtering phone calls, answering /deleting junk emails, searching Amazon if I'm forced to use it :). is what I need.

YMMV

AAC

Where does Microsoft's NPU obsession leave Nvidia's AI PC ambitions?

AnAnonymousCanuck

Re: What is the point?

As to need

My main house computer is a 10 year old fanless Intel i3 running kalliope, a Voice Assistant. This attaches to all my media/email/web as well as a Home Assistant server for all the IOT hardware. All 100% open source.

Both my TTS (text-to-speech) and STT (guess:) are now offering ONNX or tflite enhanced models. The accuracy is double that of the old matching engine. However, it takes 2 seconds for a response vs 0.4 for the old engine. This makes it currently unusable. I am CPU bound. :( Furthermore, I am dependent on one of the big corporates for my speech recognition. There have not really been functional local solutions. The ability to run LLMs and pattern recognition processes locally is vital. They are my only processes dependent on the Cloud. Not only that I currently have a very restricted list of words/phrases for orders. The ability to have an LLM handle verbal input will make pattern matching much easier. Speech output.also improves immensely.

I am looking at renovating one of my towers and have been researching what the motherboard looks like. First iteration looks like a mass produced NPU solution, then when NVidia prices collapse, get a top notch card. I have been following the "Build Your Own AI" series here on The Reg, this article fills in some of the mid-level hardware options

YMMV

AAC

Eutelsat OneWeb blames 366th day for 48-hour date disaster

AnAnonymousCanuck

Re: Equivalent problem 45 years ago

Ahhh, the joys of JCL. The most powerful and most unreadable language EVER. And, I include assembler, as some of us can (or used to be able to) read hexadecimal.

Thank you for the story and the memories. Ex-data entry clerk who "learned" JCL from "examples" and production code in the system.

Another Anonymous Canuck

VMware revenue bounces for Broadcom, chips were a little undercooked

AnAnonymousCanuck

Accounting

I'm not even an accountant and I can make the books look good for 1 quarter for ANY company.

I was able to make the books for my company look bad for over 20 years, lol. It took government Covid support for us to turn a profit.

Please Simon, skepticism is a useful skill for a journalist. Time will tell, This time next year?

AAC

Punkt MC02: As private, and pricey, as a Swiss bank account

AnAnonymousCanuck
Devil

No Need For Privacy?

> Being a price-sensitive buyer with little use for secrecy, encryption and so on,

If you have no need for privacy then those sensitive prices are going to be very sensitive to the condition of your wallet, and will adjust appropriately, for the seller at least

Apple users have had to deal with this issue for a long time.

YMMV

AAC

AnAnonymousCanuck
Devil

> Being a price-sensitive buyer with little use for secrecy, encryption and so on,

If you have no need for privacy then those sensitive prices are going to be very sensitive to the condition of your wallet, and will adjust appropriately, for the seller at least

Apple users have had to deal with it for a long time.

YMMV

AAC

US claims TikTok shipped personal data to China – very personal data

AnAnonymousCanuck
Pint

Re: Or

A sociable, I'm in. Is it BYOB or do we have a generous host??

( Sociable: regional Canadian slang for a house party)

AAC

Satellite phone service could soon become the norm

AnAnonymousCanuck

Re: Just in time...

And I trust a capricious man-child more than i do the ripoff artists that are Canadian telecom companies. Dealing with Elmo is far more pleasant than dealing with Bell, Telus or Rogers.

YMMV

Another Anonymous Canadian

Firefox 119 unleashes PDF prowess and Sync sorcery

AnAnonymousCanuck

Nothing Wrong?

> There is nothing intrinsically wrong with snap,

Yes there is, the same problem as python has: duplicate, inconsistent system libraries.

YMMV, but I'm not interested in debugging through multiple loaded dynamic libraries.

AAC

Linux interop is maturing fast… thanks to a games console

AnAnonymousCanuck

interesting Until....

Only installation method is Flatpack.

Next ....

AAC

SK hynix says no Huawei its memory should be in Chinese wonder-phone

AnAnonymousCanuck

Re: Can anyone tell if the Mate 60 Pro will work in Canada ?

It will work, but there is nowhere that can service the phone if there is a problem. It is a pity, Huawei phones are wonderful, you actually control them, unlike the Android or Apple products. Unfortunately I broke the screen on mine and I don't know enough to repair it myself :(

YMMV

AAC

Ex-Twitter sextet sues Elon Musk for 'stiffing' them on severance

AnAnonymousCanuck

And Yet Starlink is Far Better than Any Canadian Cell Company

So, as long as Starlink keeps working I could not care about all the rest of the babble. E. Musk is the perfect example of a sociopath, someone who cannot relate to others, but he has done more to change the world than any other person in the last 50 years.

Just saying.

Another Anonymous Canuck

Parental control apps prove easy to beat by kids and crims

AnAnonymousCanuck

Frida

First time I have heard of Frida. It looked interesting And then I learn it's written in python.

Poor performance and an insecure environment. "pip install" Does not meet standards. Too bad.

AAC

US border cops harvest info from citizens' phones, build massive database

AnAnonymousCanuck

Re: Travel to or through the US?

> They'd only just changed the rules to say that international transfer passengers must go through US immigration,

No rule change, it has always been that way, since the mid 1950's I believe.

YMWNV (Your mileage will not vary, not with US Customs.)

AAC

Airbnb turns its anti-partying tech on American lodgers

AnAnonymousCanuck

AirBnB: Where a Confirmed Reservation is Not

See the title. 3 times I have been left without a place to stay despite having a confirmed and paid for reservation. Airbnb's response: "Here is a 10% credit for a place of EQUAL or MORE VALUE."

I no longer use AirBnB, I will no longer use AirBnB and if I was younger I would take them to small claims court for breach of contract.

YMMV

Another Anonymous Canuck

Coinbase CEO cuts 1,100 jobs, warns of 'crypto winter'

AnAnonymousCanuck

Good Way to Let People Go

14 weeks severance for 1 year is exceptionally good.

A good way to pay for your mistakes in over-hiring.

Another Anonymous Canuck

Google blocks FOSS Android tool – for asking for donations

AnAnonymousCanuck

Don't Trust Google?

+1 for F-Droid. APKPure is another trustworthy app collection.

We have never given census data to anyone – not even the spy agencies, says the UK's Office for National Statistics

AnAnonymousCanuck
Unhappy

Sounds like The DBA Knows What She is Doing

Access to the summarized data will be a standard SOX/ISO process. Everyone: government, businesses, individuals will have access to this

Access to the dataset with the individual records will be ISO/SOX and then re-requested, re-authorized, AUTHORIZED BY A SENIOR someone, re-documented, re-executed, re-logged, multiple times. These people are bureaucrats, secure behinds are the primary requirement.

Other than the security services and criminals, I don't see any other group that would even try for the detailed dataset. And, like many others, I am sure the security services already have a copy of it.

IMHO

Just An Anonymous Canuck

What could possibly go wrong? Sublet your home broadband to strangers who totally won't commit crimes

AnAnonymousCanuck

Re: Sounds “interesting”

This is not true, at least not within the past 2 years. Shaw cable modems are controlled by Shaw, however, you control the wifi router and you can connect any wifi router to the modem. Shaw does offer a wide area wifi network for all it's subscribers that it supplies through it's business customers. That service is opt-in for the business. The wide area wifi was extremely useful 5-10 years ago when there was very little publicaly available wifi, it is still useful occasionally.

As to reselling internet access, the users are just running a server on their machine. Unless their contract with the ISP prohibits servers I cannot see why it should not be allowed.

IMHO

AAC

Ever wondered why the big beasts in software all suddenly slapped an 'I heart open-source' badge on?

AnAnonymousCanuck

The Platform I Not the Problem

We have had reliable platforms to run software since the mainframe days of the 1960's. What is still missing is the reliable software to run on any platform. While there are a few programming shops that turn out top quality code, 90% of the software I have to operate for the business that pays me is absolute crap and often does not perform the function it is supposed to. It does not matter if it is custom in-house work or million dollar commercial sftware, 90% of it is crap. Containers = a way for developers to deliver worse crap quicker.

YMMV

AAC

Alexa, swap out this code that Amazon approved for malware... Installed Skills can double-cross their users

AnAnonymousCanuck

How to Get Privacy

Run YOUR voice assistant on YOUR machine, not someone-elses.

https://kalliope-project.github.io/

AAC

Page: