The Register Home Page

* Posts by doublelayer

11386 publicly visible posts • joined 22 Feb 2018

Attention, gamers: The FAA wants YOU to be an air traffic controller

doublelayer Silver badge

Does Germany have an exemption so you don't have to pay for housing or other obligations if your employer isn't paying your salary? No? Then your pretense does nothing to defend your incorrect assumption that not getting paid while being expected to work is somehow normal or acceptable.

doublelayer Silver badge

You know there are people capable of taking things seriously when they're important and still being lighthearted when it's not? That's one of the things that the training is designed to do, and someone not paying sufficient attention will be rejected. Whether or not gamers have transferable skills, it is another way to attract applicants, some of which will be suitable.

Experts and laypeople agree: AI will hurt elections and relationships

doublelayer Silver badge

Re: WTF?

But that's work. So they tell their assistants to do it, but they also tell their assistants to do it for a lot more documents than you could or the assistants have something they'd rather do, so either way they don't bother, or the more insidious version, they check that the reference exists but not whether it says what the original document says it does. Laziness and overwork make a small problem a big problem.

Windows Update is a torture chamber for seldom-used PCs

doublelayer Silver badge

Really? Nothing is as bad? Why don't I describe an experience I had updating an Android device that hadn't been used for a while. Good news, the manufacturer is, for now, releasing security updates monthly. Bad news, the process for bringing them up to date is:

For each month between the last time this installed updates and today (thirteen in this case), download an update file, wait for about twenty minutes as it verifies, then the phone reboots for ten minutes but only after you've pushed a button because there's no just install them all option, then it has to copy to the secondary partition (several more minutes), then it decides that, since you've just installed an update, it doesn't need to check for and install updates for a while so you have to manually go to the update screen and push to check so it will start again, which you cannot do while it's copying so you have to remember to come back and try it until it lets you. If we're blaming Windows for something kind of similar, why is Android getting credit for avoiding that? Especially as Windows will install many of the updates in parallel so you don't have to reboot for January's patch Tuesday, February's patch Tuesday, March's patch Tuesday. I come here not to praise Windows but to insist we stop pretending it's the only one to do something unpleasant.

doublelayer Silver badge

That's a very different point, and I can mostly agree with you, although you do have Windows build numbers if you want a very specific way to confirm whether we're on the same Windows part of this. For driver updates that come from others even though Microsoft is distributing those, they aren't as easy to compare but that's to be expected when the different machines you're comparing will need different sets unless they're the same model.

But nothing in the original comment said otherwise. That was a discussion of the time it needs to install updates and the difficulty involved if you haven't used a machine for a while. In both cases, they end up needing to download a lot of data to update, and my anecdotal experience is similar in that Mac OS updates tend to be larger files. That's not a problem for me with my relatively fast connection, but the last time I turned on my old Mac and downloaded a minor Mac OS update, it was 20 GB so not so enjoyable with a slow connection. They both need to reboot, with Windows generally needing to do this more times and Mac OS generally needing only one, but not a short one. Neither is pleasant, but it makes it hard to sell one of those as the uniquely bad option.

Microsoft raises UK Surface prices as RAM crisis reaches the checkout

doublelayer Silver badge

Re: I wonder how many surface things they sell

You can remove Windows and install Linux or BSD on Surface machines too. Last time I did that, the Linux driver support was comprehensive, but of course, I can't promise that every Surface model will be like that as I haven't tested newer ones. That doesn't mean that hardware is the kind of thing you want, but your suggestion that they try to stop you is not correct.

France’s digital directorate dumping Windows desktops, adopting Linux instead

doublelayer Silver badge

I think that depends how they do it. There are those who propose the top-down everything changes overnight approach. I think that's mostly infeasible unless you're really motivated and I don't believe they currently are in most cases or, for those very few who are, that they will stay that way.

The bottom-up approach can work much better. Instead of changing everything, plans for individual components are made and implemented. At the end, there will still be Windows machines somewhere which resisted or for which non-Windows wouldn't work well and they are still figuring out how, but many areas could be migrated quite painlessly if the IT teams are given enough time and resources to determine what would work. Using open source software would also help significantly over trying to find something based in only that country or trying to agree on which other parts of the EU or EEA qualify and which don't. I think those changes would be easier and would also have the benefit of not being as obvious to anyone except El Reg readers, so probably no big complaints from Trump because no big pronouncements from the governments.

doublelayer Silver badge

Re: "Consider [the] Foundation’s scorecard of organizations that contribute to the Linux kernel"

The readme certainly suggests that and I had not seen that information before. Thanks for the reference, and if this is what they've done, it's better than I thought it was.

I still want to know things like whether Visio is a modification of this software or just the name of an instance of it like that readme suggests and whether they forked this or are contributing back. I hope it is the latter as this is a great opportunity to turn interest in software that can be self-hosted into better software for everybody.

doublelayer Silver badge

That's not the rule yet, hence why there are many other departments in the French government who still have Windows devices. The existing transitions in this and other countries are partial and voluntary, not complete and mandatory. If you want the latter to become the plan, it would be better to figure out how to accomplish that successfully with the minimum of disruption rather than to pretend you can just fire anyone who doesn't agree, which you can't yet because that's not the rule and you can't if it becomes the rule either because, if the transition you mandated fails for lack of planning, the people who said it was a bad idea will seem the more sympathetic. If you keep pretending long enough, someone might decide that, as much as they want this change, it seems the people they want to implement it seem incapable of accomplishing it without ripping out every computer and IT employee.

That's what I mean by solving problems rather than pretending they don't exist. Existing systems that don't simply switch over are problems. They won't go away if you make up rules, and they won't go away if you could enact those rules you imagine. Some problems can indeed be solved by threatening people enough, but if you've worked in IT long enough, you should be aware that there are many where you need more.

doublelayer Silver badge

Aren't problems much easier to solve when you can just assume you have anything you could possibly want and permission to incur as much pain and cost as you need or want to? Why do the rest of us bother with trying to solve problems when we could be taking this approach?

I have this new piece of software I want to write at work. Here I've been wasting my time trying to convince management why it would be better than what we have and how we could build it cost-effectively. I really should take a page out of your book and get the CEO to threaten to fire anyone who doesn't do everything in their power to let me build it, the rest of the plan and resource limitations be damned. That's easy to do when they have no idea what this is or whether my technical boss is doing what they need to to facilitate the plan.

doublelayer Silver badge

Re: "Consider [the] Foundation’s scorecard of organizations that contribute to the Linux kernel"

Not all of those proposing or supporting sovereign infrastructure plans know about or agree with your "open source means you're fine" suggestion. To take an example from this article, France wants to build their own videoconferencing system. Why not use or improve on something that's already been started? In this specific case, maybe they considered it and decided that the likes of Jitsi or Nextcloud Talk are so bad they're not even worth forking. Or maybe they decided that the things must be French. Many suggestions have taken that approach, with projects being rejected because maintainers are based outside the EU or sometimes even in the wrong parts of the EU. That leads to fragmentation and higher costs because perfectly suitable projects are ignored. Higher costs makes it harder to succeed at even if everyone remains interested and increases the chances that someone comes along and decides it would be easy to cancel this whole thing and declare the savings as their victory.

I vibe coded a feed reading web app. It was enlightening and uncomfortable

doublelayer Silver badge

I would probably find various types of architecture to be very boring. Yet another building with normal rooms and structures, why can't I do something fun and build some secret passages in this? That means I shouldn't be an architect. If I decided to be one anyway but use something I didn't understand and didn't bother to check on to skip the work part, then I'd still be to blame when my poorly architected building collapsed. Just because you don't like writing software won't absolve you when poorly architected software breaks your users' security. Perhaps we'll eventually invent something which can produce software of acceptable quality, including those parts you don't see up front. We're not there yet, no matter that people sell products as if we have while admitting in their terms and conditions that they haven't so you can't sue them. If your laziness and displeasure with a task makes you ignore this fact, you are to blame for any and all consequences.

Apple update looks like Czech mate for locked-out iPhone user

doublelayer Silver badge

Re: No

Their point is more complex than your reductive statements meaning either:

1. You don't understand why what you said and what they said are different, so you should learn why, something that people sufficiently interested about their privacy already considered, which is why Signal has UI settings explicitly to cover this situation.

2. You do understand but want to overstate what significance that has to make a point that you know is weak which is why, instead of stating it, you're using assumptions about what breaking encryption is and isn't and constantly inviting us to draw the extra lines for you.

doublelayer Silver badge

Re: ...But Wait....There's More....

There are exploits. Apple keeps patching them in updates, but even assuming that the providers of spyware tools to governments have ones Apple hasn't fixed or is deliberately not fixing yet, all this proves is that neither the FBI nor Apple has offered to use their tools to help this user. This is, of course, surprising, as both organizations are well-known for jumping at the chance to help fix a tricky technical issue without making people buy new hardware or having a person whose data they want to copy.

doublelayer Silver badge

So the ASCII characters can be typed on every keyboard on the planet? How certain are you about that? Non-Latin languages where some of those punctuation marks are unused and nobody uses the ^ or ~ for anything. Still certain? For that matter, find the ` character on the US English IOS keyboard; it might be a long press on something, but otherwise, that's not there despite it's nice 96 value. What you mean is that they're easy to type on your keyboard.

Microsoft locks out VeraCrypt and WireGuard devs, blames verification process

doublelayer Silver badge

Re: Why do people keep working with Microsoft ?

I was especially considering the question in the title: "Why do people keep working with Microsoft ?" with context from the comment. Of course, the answer is generally because a lot of people use Windows and, if you're writing a kernel driver and want people on Windows to have access to it, you have to work with them. But more generally, the reason is that, no matter how you choose to write software, you end up having to deal with either Microsoft or someone else who operates in the same way, unpleasant as I find that. I agree that it's not a good thing for Microsoft to do either for themselves or for the rest of us, but I don't expect them or anyone else who does the same thing to improve rapidly or necessarily at all.

doublelayer Silver badge

Re: The usual misleading headline and buried useful informatiom

That would depend how many messages they did send and where they sent them. If it was banners in the sign something workflow, that's not enough for people who sign infrequently, so yes, more emails would be a good thing. Banners in general aren't great choices if they're in a system that ever uses them for advertising or unimportant announcement messages where they're more frequently ignored. There's a difference between one email months in advance and multiple, more frequent ones leading up to expiration, because even responsible people will often see a single email warning for something they need to do months from now and put it off since they're busy and figure there will be time then.

Neither Microsoft nor the devs were specific about what communications they sent and got. I don't entirely trust the devs claiming they never saw anything since, in my experience, it's quite easy to ignore and then forget about some of those, but it does suggest that they weren't getting them in channels they were looking at more frequently. Neither do I trust Microsoft that they were active in sending messages to the right channels when they didn't say where specifically and how often. Hopefully, this is a message to all involved indicating how important it is not to break this and that there are benefits in improving the process.

doublelayer Silver badge

I don't because it's much more likely that we hear about it for something well-known like WireGuard than a game nobody's heard of and we don't really care about. There could be lots of those examples without getting quite so many articles. Though I do remember them happening like this Google one, the article for which mentions many more examples. I don't think this is targeted. I think this was an example so extreme that we heard about it. I also expect that most of these do get resolved, eventually, after weeks or longer of repetitive and mostly fruitless calls to customer support which ignores them, though that is just a guess. That doesn't make it acceptable, but it does contribute to my belief that this is more likely incompetence and disorganization than someone at Microsoft having an evil plan that relies on WireGuard not being updated for a week.

doublelayer Silver badge

For the many users who don't know what the box saying "Do you accept key [hundreds of random letters]" means. Nothing stops you from getting the driver that's not currently signed because Microsoft messed this up and using it anyway, but you have to trust that you're doing that correctly and the consequences for making a mistake are malware with lots of privileges. The CA process exists to make it easier for people who aren't sure how to do that to have some way of judging when something has been signed by the right source.

doublelayer Silver badge

Do you have a theory on how Microsoft is supposed to buy out, for example, WireGuard which is an open source program with a single primary maintainer? Who do they buy Jason Donenfeld from? How, since WireGuard users don't pay him, would he be worth less if there are fewer users, and how would the inability to push updates to Windows users make that user decrease happen quickly enough for that effect to activate? This theory makes no sense.

doublelayer Silver badge

Re: Why do people keep working with Microsoft ?

Because pretty much everything is like that nowadays. Google and Apple are very similar. So are many other services. Either you're a largish commercial customer, pay a lot, and have people you can contact who will directly help you, or you're not and have to hope the automated systems don't break. You can be an open source only group as well, in which case you have neither of those options because there's no responsibility that projects work together. Your question implies there's some kind of way to write software where everyone you interact with treats you as an important person and resolves problems, but I haven't found it.

doublelayer Silver badge

Re: Incompetence, malice

"So it took 2 years for their accounts to be deactivated? Or 2 years for Micro$lop to get around to sending out notifications to these guys?"

That's not what that means. People who had verification less than two years old were fine, whereas ones with older verification were supposed to repeat that, but Microsoft apparently weren't very clear with the notifications so the deactivations happened now. I don't know how clear Microsoft was with the messages, but they probably put them in places that they thought people would use but skipped entirely or didn't send enough emails, annoying modals, or things more likely to make sure people were aware of the pending automation. History has demonstrated that, even for the most attentive users, one ping in a banner notice six months before something goes into effect isn't enough to get their attention.

Microsoft cuts cloudy desktop prices by 20 percent, warns they’ll wake up slowly

doublelayer Silver badge

Re: Overpriced

And the viability of that approach depends a lot on what they're selling and who they expect to buy it, because there are a lot of things that can successfully rely on people having internet access most or all of the time. I have been allowed to work remotely all of the time before, but mostly because my employer could expect that I'd have internet access pretty much all the time and be correct about that. It happened that some of my work could be done if my connection dropped because I was using a local machine, but if that happened very often, it would have been a problem and they'd have told me to fix that so I could work unaffected. Not all jobs will need or want that, but many do and many people do have that reliable a connection.

Cloud PCs would work for a lot of people because of this. Those who are frequently without a network connection know that and wouldn't try this. For those who do, network reliability is not something they worry too much about, so they need a different reason not to use this. There are a lot of different reasons, though I still find the most convincing one to be to look at the price plus that of a client, look at a machine with the same specs, and see how few months it takes to break even. If it was much cheaper, I'd still have more reasons not to do it, but at the current prices, even today's new ones, that's not necessary.

doublelayer Silver badge

Re: Overpriced

When doing that, remember to price in the hardware used as a terminal to connect to the cloud desktop. The hardware I've seen is neither as low-power nor as cheap as I'd expect. Some of it is as powerful as the low-end cloud desktop is likely to be. The available specs for these instances match a very low-end computer*, a basic one, and a respectable but still quite normal machine. New machines with matching specs are relatively cheap in comparison, even with today's RAM prices.

* You can run plenty of things successfully in 4 GB of RAM, but it's not that common to find a modern laptop with that outside the far budget end.

doublelayer Silver badge

Re: Overpriced

I think the both cases were a desktop and a laptop. With a cloud computer, that's not going to work at all without a sufficient connection.

Admittedly, anyone even slightly considering a cloud PC isn't dealing with people who are expecting to frequently not have an internet connection. They're either considering it for people whose jobs won't work as it is without a connection or to people who can reasonably expect that they'll almost always be connected. I don't think it's a useful or cost-effective answer in those cases either, but pointing out the people working off-grid in a signal dead zone isn't very useful in convincing someone whose home internet hasn't gone down at all in the last year that it's not a good option for them either.

Tech support chap's boss got him out of jail so he could finish a job

doublelayer Silver badge

Re: could you work ...

What?

You saw that the "meet" was in quotation marks and the "without" wasn't, so you know it was a preposition in the phrase "without the with" in which it meant "lacking", right? Are you complaining about someone else's use of without now? I'm surely missing some kind of joke here, aren't I?

doublelayer Silver badge

Re: Define work.

"Does the "with" add anything except prolixity?"

Yes, it does. Because when I say "meet" without the with, it usually means that I am being introduced to someone for the first time. Sometimes, it also means an unexpected encounter. Therefore, adding the word allows me to communicate with a single extra syllable that there was an arranged encounter with a person I already know rather than either of those, whereas if I had to use "meet" alone for all of them, I might have to clarify which of those it was which would probably take more words than one.

I also don't tend to bother following grammarians who object to things on the basis that they're not old enough for their tastes. That always leads to arguments about how old a word has to be or about why, even though a rule was invented relatively recently, that one is one I still have to follow to earn their approval. I can appreciate grammarians who advise on how to be better understood. I can't appreciate ones who like making rule books based on nothing but their own preferences and then complaining about people who didn't follow them.

Criminal wannabes even more dangerous than the pros, says ex-FBI cyber chief

doublelayer Silver badge

Re: Want to stop ransomware? Ban paying ransom.

"such scams didn't exist before it"

Complete rubbish. Money managed to cross borders, even illegally, before cryptocurrency. As long as paying it is still legal, criminals can come up with a different way to pay and companies can go along with that. Banning payments will be more successful and more obtainable than banning cryptocurrency.

doublelayer Silver badge

Re: Sicarii encryptor generates a new cryptographic key pair

"Discarding the private key is legitimate as long as you retain the public key for decryption."

That's not how public/private key encryption works. You can encrypt with the public something which you need the private to decrypt, but not the other way. What they were likely doing is encrypting each file symmetrically, encrypting that symmetric key with the public key, and then you could use the private key to recover the keys to decrypt. Except they deleted the private key so they can't do that. Generating a fresh keypair on the victim's computer is also stupid when you could just include the public key they're supposed to use.

Fewer than 3 in 10 register for HMRC's Making Tax Digital shake-up

doublelayer Silver badge

Are we seeing different headlines? Mine says "Fewer than 3 in 10 register for HMRC's Making Tax Digital shake-up". Is it unbalanced by not criticizing the program in the headline? Since I don't see praise of the program there either, that doesn't seem like imbalance to me. Since it's a legal requirement whether good or bad, rather than something optional, the numbers don't seem unbalanced either. What would you want the headline to say?

World's smallest violin spotted at Amazon HQ as exec pay packets deflate

doublelayer Silver badge

Re: Don't cry for them

Martinusher's description is indeed incorrect but there is a way that works close to the thing described. The way it works is that the person borrows money from bank A against their collateral, spends some of it, pays a few installments but not many, then refinances their loan with bank B with the same collateral, pays off bank A with some of that loan, and return to the top of the loop. If their shares have increased in value more than they spent, this process is easy. Otherwise, they'll need to use more of their wealth as collateral each time they do it in order to make up the amount they spent. If you can do that all the way until you die, it works out very well. If you can't, then it gets much less pleasant, but that's why it's mostly very wealthy people who can afford to take that risk.

Virtual SG-41 project brings Nazi cipher machine to life in the browser

doublelayer Silver badge

Re: Curious

A good encryption algorithm can still be weakened by using it in the wrong way. That's not what the Russians did there, since the one-time aspect of a one-time pad is very much not optional.

doublelayer Silver badge

Re: Curious

In theory, yes, because just as any machine can be modeled in software, any software could be built into a mechanical thing. The EC25519 machine is likely to be rather massive, though, so it's probably best not to.

If you're asking about actual, historical machines, most of them implemented an algorithm which is not sufficient for security today. It depends where your threshold for sufficient encryption is, because some more complex machines would withstand a basic attack, but if you're faced with people who are motivated to break in, the constraints of historical equipment won't stand up as well as modern software can. Some of that is just the high cost of making keys longer, which in the modern day just slows down the encryption (and for asymmetric keys the generation) stages, but in a mechanical thing means more parts and circuits to handle them. As others have posted, one-time pads are very secure and I'm sure plenty of hardware was built to make the process of using them easier as doing them on paper is annoying and slow, but I doubt that's what you meant.

Amazon rewards loyal Kindle devotees by closing the book on old e-readers

doublelayer Silver badge

Re: It's not about "support"

This analogy does not work well because there is no direct comparison, no matter how much anyone tries to squash something into that hole. Amazon's cutting off all remote functions, including the ability to download already purchased material to the device. That's more severe than cutting off updates. Amazon is not making the devices stop working entirely; users can still copy book files to the devices and read them in the same way. That's less severe than preventing any new files from being opened on a computer. If we did try to match definitions, it might be something like the ability to download optional components from Microsoft's servers, in which case Microsoft does provide that much longer than Amazon is doing, but even that isn't a logical comparison because the books that Amazon's cutting off access to were a bigger part of the workflow of most but not all Kindle users than optional components are to Windows users.

doublelayer Silver badge

Re: Obviously bollocks

Their statement does sound like that, but no, you don't brick it by resetting. If you reset it, you can't log in and download the books you bought from them on that device, even those that would be on the device now, but the reading function on files you copy to it does continue working because that doesn't require registration.

doublelayer Silver badge

To clarify, it's the remote Kindle store books you won't be able to download new ones, and if you reset the devices, you won't be able to download the old ones. The devices will still read things you copy onto them directly, so they can still be used in some ways. They don't require registration for that part, so you can reset them safely and still read files. Not that it makes Amazon's decision better, but the devices may be of more use than you expected.

Hundreds of orgs compromised daily in Microsoft device code phishing attacks

doublelayer Silver badge

Re: The problem with html email

There are two problems with the complaints about HTML email. One is that they do claim HTML to be to blame for a malicious URI, as in this case. There is no script in that mail. There's a link to a place people shouldn't go.

The second is what you've implied. Try sending some JavaScript in email and see how many people who receive it have it executed. I don't doubt that some mail client exists that does execute that, but nothing normal, client or webmail, does. That's not new. HTML email has been static but formatted for most of the time HTML in email has been supported. People who pretend it has powers it does not aren't making a convincing argument; the argument should be "no JS in email" instead of "no HTML in email", and the valid argument would end up a rather short one as it's already been won.

doublelayer Silver badge

But it doesn't make it any harder to paste a URL in it so people can go somewhere, which users are already used to and will become more used to because emails often direct people to other locations. HTML does not cause this. Plain text will not fix it.

Apple's chips are the core of a new landscape, but its biggest win is Windows

doublelayer Silver badge

Re: Microsoft could produce a Windows Neo variant …

An Apple ID is not needed for everything, but it depends what you consider a normal task. You can set up a Mac without one, install plenty of software without using the store, etc. If you want to install something that's in the store, then you'll need to log in, even if it's a basic piece of free software from Apple. So whether this is a problem depends on what you want to install and whether you consider it acceptable that a login is required for that part. Windows is different, because depending on the version, you are forced to log in unless you take opaque steps to bypass it in order to do anything at all. It should be noted that this is not all variants of Windows 11 with Professional and up allowing local accounts (Professional with a little circumvention but no CLI or installation patching, Enterprise/Education just by pressing a button).

doublelayer Silver badge

Re: If only Linux was as simple...

Because you've got, respectively, a bunch of admins familiar with Linux running hardware designed by its manufacturer to run Linux, people who custom-built the entire machine and have plenty of knowledge on how to make Linux work with it, and a custom kernel built specifically for the hardware by the manufacturer. The last one is a perfect way to demonstrate this; try replacing your phone's kernel and OS with something else. It's hard for many people and those who can do it generally can do it on a small number of phones and otherwise have problems, which is why most phones run only the firmware their manufacturer shipped with them.

There is also user error, but far less often than you're claiming. But since you've admitted that you don't care, then at least you're consistent.

doublelayer Silver badge

Re: Why?

My anecdotal experience is different. I've heard plenty of people complain about the change in design of IOS 26 who dislike the appearance or have become lost with moving controls. Of course, they usually figure out where the buttons have moved and deal with it easily enough, but that's also true of the UI changes in Windows 11; I may not like that there's a two-level context menu now in Explorer, but it didn't take me very long to figure out how to use it.

Either way, UI changes, usually for no reason other than it's been a few years since it was last changed, users don't like it, many figure out how to put up with it, and a few have to be talked through it. I'd be fine if people figured out something that worked and just stopped there, but history suggests that's not going to happen.

doublelayer Silver badge

Re: If only Linux was as simple...

What use is that comment? If you're going to respond to anyone reporting problems switching to Linux with comments that either say "your problem isn't real" or "I don't have your problem so I can't be bothered", you can't act surprised when Linux doesn't get adopted because anyone who has any problem will decide that it evidently doesn't work for them and abandons it. These kind of problems are very annoying to solve because, even if I want to spend the time on each one, I have to track down the exact combination of hardware and software involved to identify what went wrong or whether it was user error, find the fix, try to do something so I don't just tell each user to run these opaque scripts and maybe it gets fixed long-term, then start again on the next report. I don't really want to do that, so I only rarely try.

Maybe we should just not care whether the general public adopts open source software. That's definitely easier. But if we are going to do that, we should stop pretending we still care and recognize the loss of the network effects that their presence could provide.

AI slop got better, so now maintainers have more work

doublelayer Silver badge

Re: Its a shorter term problem

AI can also submit new code. That new code can work. Then another AI can find security problems in the submitted code. This can spiral forever with the creation and resolution of bugs that are security-relevant. One problem, even if the security detection and resolution AIs were both perfect, is that bugs in the user experience are much harder to detect by inspection when there's no simple model of what users intend the code to do, so it's difficult to identify automatically when it's doing the wrong thing, and LLMs aren't driving the software anyway. The attempts to clean this up are on a few maintainers who were already burned out, and now they've got a lot more stuff to review and a mental model of what everything does and how it does it to try to keep stable. The pain will increase.

Shots fired – literally – over proposal to build datacenter in Indianapolis

doublelayer Silver badge

Re: Pre-emptive self defence?

"If he'd said the bullets hit near where his child/him/his partner was sleeping, then the statement would have been more accurate, and no less shocking."

Unless he and his partner and his child happened to be sleeping on the opposite side of the building, in which case it would be less accurate but a meaningless difference to the general danger of shots being fired at the house. The relevant part, that the bullets were going through a part of the house frequently in use, remains the same, even though the early morning meant the chance of that part being in use during the shooting was lower. Someone having an early appointment or difficulty sleeping could easily have changed the circumstances in a more tragic direction. I don't understand why you consider this difference to be as important as you do, but your minimization of it, suggesting that you would have to be outside to be at risk for instance, is tripping my own "why is that the point you're making" alarm.

doublelayer Silver badge

That could be part of it and does seem to have happened at times, but there's also two more options, both much more sympathetic:

1. The politicians misunderstand this and think there are more jobs available. The companies wanting to build them are easily able to claim so, and politicians aren't experts on what a DC needs.

2. The politicians correctly understand this and think the jobs are worth the cost, possibly because they misunderstand the costs for even more sympathetic reasons. A couple hundred jobs is still worth something, and the DC providers are often good at pretending they'll cover all the costs of powering their new site. If they're covering the cost and the only downside for the residents is an ugly building, that is a much lower cost to pay. The fact that the promised payment is contingent on contracts between the DC and the local power provider which actually will pay for all the power costs assuming everything goes well and no plans change any time in the next ten years is more difficult to prove and may rely on information politicians don't have since they're negotiated between those two directly.

And for that matter, the citizens who oppose it generally don't have any more information about whether there will be problems from the proposal. They are likely using similarly limited information and coming to the opposite guess. It happens that, with modern GPU-heavy proposals and move-fast-hide-everything logistics, that guess is more often correct, but the same people object to lots of things that don't have negative effects on similarly knee-jerk reasoning.

doublelayer Silver badge

Re: Pre-emptive self defence?

Bullets can go through doors and retain plenty of momentum. Your suggestion that the child would need to be outside for the comments to be correct is flawed. The early in the morning aspect reduces the risk somewhat, but by the time we're getting to that level, I think we both know we're not talking about useful differences. If a child as a potential victim makes this any worse, then regardless of the time of day, that is relevant.

OpenInfra General Manager talks sovereignty, governments deploying tech 'kill switches'

doublelayer Silver badge

Re: Another Puzzled Old Person Here.........................

Those ways are not quite as different as you describe. I don't think there are internet kill switches in Washington, but if there are, why wouldn't they have had them on private lines? Did they suddenly become interested in the ability to take things down in 1995? That's especially true because a kill switch on the internet or big chunks of it would cause a lot more damage than individual ones on private lines, so if they wanted the ability to target individual things rather than black out communications altogether, the private lines were the easier things to mess with.

The old ways are the best ways if you need to and are in a position to operate your systems as if you're going to face deliberate attack trying to take you down and you need to survive that. If that's your situation, then you do want private buildings with your servers and a private line connecting them on private land you own and patrol with private security guards and anti-aircraft weapons. Since almost nobody non-military has all those things, you would make do with the subset you can have. For many others, they don't expect that a government's going to aim to take them out and, if they are, they won't withstand it. If my country's government wants my employer's network to go down, they don't need to try to break the internet or strong-arm the cloud providers when they could march some police into the office and order us to turn things off, so hardening our infrastructure to withstand something we don't expect and can't survive is not a logical argument for doing so.

Researchers didn’t want to glamorize cybercrims. So they roasted them

doublelayer Silver badge

Re: took long enough.....

I hope it works, but it's much easier for something to be successful when the same guy gets to write the proposal and the results. I'm not sure many of the criminals they're talking about are motivated by notoriety. I think they're mostly motivated by money. Those wanting their own brand will make one themselves rather than waiting for a security researcher to name them. So far, when organizations have given themselves a name, most researchers have used it in order to clearly communicate, but even if they insisted on referring to Dark Side as Pathetic Slugs #39, I don't think that would worry members as long as they were making money and still using the term Dark Side in their messages and advertisements.

If an AI agent screws up while running your business, there's nobody to sue

doublelayer Silver badge

Re: Strategically placed scapegoats

So did the individual software engineers pay fines? No? Fine then, did blaming them mean VW didn't have to pay any fines? Again, no. Whether you think the external consequences VW got were sufficient or not, they didn't manage to get out of them by blaming the engineers. Of course they gave it a try, but like most things when it gets that far, it did no good. The problem is getting things to go that far in the first place and, when they do, making the penalties strong enough that the perpetrators don't repeat them.

doublelayer Silver badge

Re: Bias will come from the training

Even if everything was perfect, that wouldn't be enough since most of the information about whether to hire someone is from the interviews, not the original application or CV. An application can get past the initial CV screen because the candidate lied, stated what they did in a self-promoting way that misled the screeners into thinking they'd be more experienced than they were, or accurately stated all their qualifications but demonstrated themselves to be a nightmare to work with in the interview. There's no way to put all the information into a model, which makes it virtually impossible to confirm whether it's done the right thing.

If AI CV sorting is going to happen, the only stage I'd suggest is testing whether a human would have approved it for an interview, not whether the candidate would have been hired at the end of the process. That removes many of the parts that can't be tested. It still has all the problems you listed and several more, for example that human reviewers have plenty of opinions on how to sort applications which aren't always correct or that lots of experience in Java applets and Silverlight is not the asset it would have been decades back.