The Register Home Page

* Posts by doublelayer

11420 publicly visible posts • joined 22 Feb 2018

APNIC: Big Tech's use of carrier-grade NAT is holding back internet innovation

doublelayer Silver badge

Re: I've said it before and I'll say it again

I suppose it depends how your cartons are set up. I could see a possibility if yours has a lid that is flat all the way over, and thus you could balance an egg between some others and have the lid go over that. I think the analogy requires that you not break an egg or the carton and it still has to close though, and although I can't prove it, I think the cartons I know can't do that.

doublelayer Silver badge

Re: Thanks, but no thanks

"Under v6, my phone has a long lived identification that persists across all WiFi, mobile connections etc."

No, it doesn't. It will have separate addresses for each network. The system doesn't have your devices keep their IP wherever they go because that would make routing a lot more complicated. You're right if you stay on one network, but if you move between them, the address will change when you do.

The trackability of addresses is one reason I prefer to use NAT for nonpublic devices, even under IPV6. However, don't interpret it to be more powerful than it is. For example, you may think that using a dynamically-assigned IPV4 address makes it hard to track you, and it would if it changed a lot, but it probably doesn't. If you leave your router turned on all the time, then your ISP probably just extends your DHCP lease. The IPV4 address is assigned dynamically, but you've probably been assigned the same one for the last few months continuously. CGNAT does provide more; you probably also kept the same address but there's a lot of people sharing it with you. However, tracking companies know about both of these things and find better ways to identify you. It's certainly a problem, but it's not the biggest problem.

doublelayer Silver badge

Re: I've said it before and I'll say it again

You're right that it's simple, but this still worries me because it's very unlikely to be the default. The benefits of nontechnical people on a NAT system include the assumption that, purely for the ISP's self-interest, the default config is likely going to prevent publicly-accessible ports for the user. That helps when they bring in untested devices or software. It's not hard for me to have a firewall which prevents incoming traffic by default, but many cheap, ISP-supplied routers I see leave that to the device's own firewall which, if it's a security nightmare already, probably won't do it.

I've dealt with this by having devices on my IPV6 home network connect to a NATed subnet unless configured to have statics or to be trusted, but I can't set that up for my friends or family, let alone trust that the rest of the public is going to get it. This doesn't mean that IPV6 is to blame, but I would like to see a general improvement in default router configs and I don't think it's going to happen.

doublelayer Silver badge

Re: It's the mobile networks that seem to be stuck in CGNAT

I'm far from a zealot, but it does have a few benefits for some users, me included. One of the aspects that is nice is that I don't have to do weird things to have some dedicated addresses. With an ISP that gives me an IPV4 address through DHCP, I have to forward ports to individual devices, remember what the ports are should I have two or more of them operating there, have a method if they switch my address, etc. If they used CGNAT, I might not be able to do it at all. With IPV6, I just configure the static IPs and firewalls on my end and put the devices online, and since there's so much address space for now, they're not going to change my block. Getting dedicated IPV4 addresses from an ISP is usually not easy. I could get a business package, which will definitely cost more, may require extra equipment from the ISP, and might not be available in a clearly residential area.

IPV6 is extra work, no doubt. It has some problems that impair its usefulness and require a configuration change to remediate (multiple IPs for end-user devices on the same network, I don't think so). If IPV4 was good enough, these could be enough to simply ignore IPV6. Unfortunately, IPV4 is not good enough. It's a little pathetic that I have a weird network setup just because we have run out of numbers, and it's a terrible reason for everywhere on the planet to keep getting more snarled in the organization of a limited resource. At least with other resources, the scarcity is due to physical limits. With addresses, it's a shortage we can fix ourselves.

You might want to consider the cost of not upgrading legacy tech, UK's Department for Work and Pensions told

doublelayer Silver badge

Re: Manual

I've never done that, but I have this feeling that it doesn't work that way. It seems to me that you're just as likely to get fired, but if you are, things go really badly for the company that fired you in that case. For you not to be fired would rely on the people making the decision knowing that what you do is hard for others to take on and hard to improve quickly, but that information rarely seems well-understood by those who don't do the processes themselves.

Privacy is for paedophiles, UK government seems to be saying while spending £500k demonising online chat encryption

doublelayer Silver badge

Re: Sure. Why not cull E2EE...?

There's a book which describes that situation: The Circle. In it, a company manages to get the required infrastructure to do that and enough public support to make everybody, including politicians, publish everything they do. This to the extent that people have to wear cameras at all times. It has some short-term benefits, but it predictably doesn't do much other than hand power over to the company which has many inventive ways to use that power. It can be a bit depressing to read it as what it suggests is possible, but still worth a read.

Open source, closed wallets, big profits – nobody wins the OSS rock, paper, scissors game

doublelayer Silver badge

That's overly literal. It's a phrase example from a well-known speech, clarifying that the word "free" means freedoms to use and modify. I put quotation marks around the phrase to clarify that I was referring to that meaning.

If payment to the original author is required for certain kinds of uses, then the freedoms to use and modify are not absolute. Those restrictions are already often seen in proprietary licenses of all kinds, from the simplest noncommercial license to the most defended product of Oracle's lawyers and the most arcane formation of weird legal terms. They are perfectly possible and acceptable, but they mean something clearly different and users will treat them very differently. That is the point I was making.

doublelayer Silver badge

Re: Sounds very much like the music industry

That's not a good idea in my opinion. In order to do that, you run into lots of definitional issues. For example, which of the following people gets funding, and how much in each case:

1. A developer who writes a project important to many people in their free time, but has a job at a tech company writing other code as well.

2. A developer who maintains code, fixing bugs and the like, but didn't create the project and doesn't add new features.

3. Someone who writes documentation only.

4. A translator who localizes open source software.

5. A person who spends a lot of time on a project they came up with, with few other users.

6. A person who commits occasionally, but not very much.

7. A person who frequently switches what projects they're working on.

I don't know how France's music system works, but that already sounds like a bad idea (I write music as a hobby, but I don't think you should pay me to do that). Open source contributions are perhaps even harder to assign a monetary value to.

doublelayer Silver badge

You can do that if you want, but there's a reason that doesn't fall under either the FSF's or OSI's definitions. I agree with them. If you do that, I won't contribute to the code or donate, because it gives the author or owner too much power to restrict the rights of the user. The whole "free speech not free beer" bit has gotten old, but it's still accurate in this case; letting the author decide that someone can't use it because of who they are or how they intend to use it is a very different philosophy and one I will treat differently.

doublelayer Silver badge

Depending on how you want to make a living, you have to decide the way you want to do this and structure your work accordingly. If you use a license that says the user can use, modify, distribute, and sell your code without receiving permission from you, then they're not required to pay you. If you use a license that says that they must pay you to do those things, then you probably won't get assistance from others. If you started with others' code, you may be required to adhere to their license. If voluntary donations aren't sufficiently secure for your comfort, you may want to do something that gets you a more stable income stream, but the consequences of your choice are your responsibility.

I have a library I wrote to solve a problem for me. I considered releasing it as open source, but I didn't. One reason is that there's already a better version out there (mine is only better if you have to run on an embedded device with very little memory). But another reason is that I thought maybe I could turn this into a commercial project. In order to leave that option open, I didn't give my work away. If I did, I shouldn't expect companies to come to me and pay me for the thing I just gave them for free.

Big shock: Guy who fled political violence and became rich in tech now struggles to care about political violence

doublelayer Silver badge

Re: Maybe Not Mistaken

It might not be much, but caring is still important. If I found a way to benefit them, I would do it, making some sacrifices to do so. At the moment, there is some action sanctioning individual companies who use forced labor in the camps. This may be cold comfort to someone suffering now, but at least I, and likely you, would do something. The person covered here could do various things, and certainly has more power than I do because he has billions of dollars to spend on problems, but wouldn't choose to do anything because he doesn't care.

doublelayer Silver badge

Re: The land of the "free"

I don't applaud people just for telling the truth. I applaud people for sticking up for ideals in the face of adversity, and more so if I share those ideals. Someone who denounces a human rights abuse even though their employer won't like it has taken a major risk. Someone who defends a political view I don't agree with may still face a risk. This guy's view, which he is defending as if someone is going to do something to him for it, is "I don't care". That's not an ideal, and he isn't going to face any consequences for it as he already has billions of dollars to insulate him from any negative response (which probably won't even exist).

doublelayer Silver badge

Re: Too true

"The only thing the Chinese are intolerant of is trying to bite off pieces of their country."

Wrong. The crimes for which people are imprisoned are a lot more than advocating independence. And that's assuming we believe them every time they claim that a more serious crime is related to their imprisonment of another group. Advocating any level of democracy is heavily punished there, and there are restrictions on cultural activities as well. China has several minorities, and throughout their modern history, they have tried to wipe many of them away. From attempts to reduce the use of minority languages in schools to ethnicity-based concentration camps, this is not just for the integrity of their borders.

As with the case of Spain, I also don't think countries should repress serious interest in regional independence. However, I will point out that nobody is being locked up in Spain for speaking Catalan or requesting independence. Only the government leaders who declared independence were charged, and I do not think that was justified. China's actions are in all respects more severe.

Apple grabs smartphone crown as iPhone 13 wakes up the fanbois, leaves Chinese rivals eating dust

doublelayer Silver badge

Re: Made in China

It's not about manufacturing location, as Samsung's phones are made in a bunch of places and everybody's phones contain parts from at least a few countries. It's about the location of the creating company. The companies based in China had slight decreases in market share.

Plumspace's Smart SFP TAP can monitor, capture or relay gigabit-speed comms – for legitimate business reasons

doublelayer Silver badge

Re: ......but it's not clear whether the monitored traffic....

Depending on the use case, there's another option:

3. It's not sending the data, but it is manipulating it to modify the traffic sent through it.

Even if it is one of the others, it could be either depending on what the attacker (or normal business user) wants. If they can get away with using the network it's already on, they can upload captured data that way. If they're afraid that will be spotted, they could add a different channel for getting the data out.

North Korea pulled in $400m in cryptocurrency heists last year – report

doublelayer Silver badge

Re: Let me get this right..

And from central banks. They like stealing the monetary reserves of countries and convert it into something more easily kept away from others. A lot of it is in cash, but some is converted into cryptocurrency. They've also launched smaller robberies from personal accounts as well, though they're not as big, so less often done and much less often reported. But why let reality interfere with your attempt to insult all victims of a crime and cryptocurrency in one easy sentence?

doublelayer Silver badge

Re: cryptocurrency

"And I thought the North Koreans were starving and so had other things on their minds. How do the find the time to train these people?"

Take a look at why they're starving. It's because all the money goes into government and military investments instead of public services. The things that get investment are the leaders' personal comfort, a lot of troops to stand around the southern border in case it's time to invade, a lot of troops to stand around elsewhere in case someone needs quick imprisonment, nuclear weapons, and stuff that makes more money for those things listed above. Ways to make more money include manufacture of illegal things (counterfeit money is one of their specialties), weapons systems for sale and internal use, and cybercrime. In other words, they are starving because the resources that could help are being spent on training these people. Entirely consistent.

Email blocklisting: A Christmas gift from Microsoft that Linode can't seem to return

doublelayer Silver badge

Re: I am not surprised

"So I'm supposed to leave my systems open to SMTP auth and spamming attempts from Linode hosts to allow for a maybe one day in the future I might get a legitimate email from there?"

That's what I would recommend. Use something more targeted to deal with the spammers themselves. Fail2ban is a good starting point, and you can build on that or custom-build your system if it's not good enough. That locks individuals out without having to ban everything. Your system should be secure enough that you don't need to eliminate bot probes to keep them out, and assuming it already is, then you don't need to go nuclear on background noise.

doublelayer Silver badge

I have a server that can send emails or act as a VPN endpoint. It has a dedicated IP. I'm the only one who can use it. It shouldn't matter what the person who controls my IP + 1 is doing. If they're spamming, block that address, not the address block or the hosting provider altogether.

Also, you may be overestimating how much other providers are monitoring to prevent spam. I don't get a lot of spam, but it often comes in from addresses controlled by email systems rather than home-run mailservers. Sometimes it's basic GMail addresses. Sometimes it's from an Office 365 account they've gotten access to. Often, it's from a domain provider they've just used to set up the endpoint for the phishing link. In each case, it's a place that can't be blocked because too many other users use it. Because of this overeager approach to spam prevention, the spammers can still do their thing, but individual mailservers are restricted. This is harmful and unproductive.

doublelayer Silver badge

Until someone on a different IP but in the same block sends out a lot of spam, and someone decides to ban the whole ASN or subnet. It's not a logical thing to do, but it happens all the time. The same way some people will firewall off an entire country just because they get bots running from those addresses; it's opening a nut by driving over it but sometimes people are too lazy to do it properly.

doublelayer Silver badge

Re: Mark my words...

"How many thousands of spam complaints did Linode ignore before getting blocked? A quick search shows that they have active problems."

You can't run a service where users can send out packets of any kind without getting people sending spam. I'm sure they do have spammers using their systems. However, this doesn't mean they're unusually helpful to spammers. Microsoft also has spammers using their systems, but I doubt they would be very happy to have Azure's IP blocks shadow-banned.

Google says open source software should be more secure

doublelayer Silver badge

"What obligation does one have as an author of an open source program?"

None. None at all. The users need to understand that and plan accordingly. If they want you to have a responsibility, they're going to have to get you to agree to it specifically.

"What obligation does one have as a user of open source software?"

Again, it's basically none. They could be responsible for incidents that occur from their use, but that's pretty much the extent of it. They have to decide what to do whenever something happens that they don't like.

"Does it depend on means?"

No.

"Does it depend on use?"

It might for users depending on what they're doing with it. For example, if it's used to store personal information in a GDPR country, they could be obliged to fix or change it in a certain time to prevent breeches.

doublelayer Silver badge

Re: Sorry

I have argued that as well, but the reverse is also true. If someone else makes money off the thing you did for free, it is still their, not your, responsibility to ensure it's good enough for their uses. That means that, if there are bugs they want fixed, they don't get to argue that you are failing in your duty to fix it quickly enough (or failed when the bug first came into being). You have no responsibilities to them just as they have no responsibility to pay you.

doublelayer Silver badge

Re: money is not the way

Very nice. Make the people who are already developing stuff for free also code review for free. I'm guessing that will also include some restriction to ensure they review well and with the security and quality goals you have in mind? If the security of components is so important to companies that make money, they can afford to pay for that developer effort, hiring the developers themselves or paying into an organization that will do it for them. They shouldn't be forced to do that, but they certainly shouldn't be able to argue that they need it, therefore I have to do it and likely also pay for others to do it.

'IwlIj jachjaj! Incoming LibreOffice 7.3 to support Klingon and Interslavic

doublelayer Silver badge

Re: Fourth gender

That's gendered pronouns, not grammatical gender. You, for example, do not have different adjective forms if the described noun is one of those genders, nor do you assign those genders to inanimate nouns. For that matter, you also don't have different adjective forms (though there are different verb conjugations in some cases) for singular or plural nouns.

doublelayer Silver badge

Re: Fourth gender

"English is (almost?) unique, globally, in not having masculine/feminine verbs as well as netuer"

You may be unfamiliar with non-European languages, but it's really not that unique. For example, one other language that doesn't have grammatical genders is Chinese (Mandarin, Cantonese, and other variants included). Most of languages spoken in eastern Asia do this, including Korean, Japanese, Thai, and Vietnamese. That's quite a large one. Here's a short, non-exhaustive list of largely-spoken languages that don't have grammatical gender: Bengali, Yoruba, Javanese, Basque, Persian/Farsi, Turkish, Finnish, Tamil, and Quechua. There are loads more. It's just that a lot of the languages spoken in and around Europe do have genders, so they have become expected in many cases.

EthereumMax, a Kardashian and Floyd Mayweather Jr sued over alleged 'pump and dump' cryptocurrency scam

doublelayer Silver badge

"Maybe it's because I'm getting old, but I cannot 'appreciate' or 'understand' the value of crypto.

It doesn't exist, and to understand the irony - it's in the ether(eum)"

In most cases, you are absolutely correct. A lot of cryptocurrencies have no value. However, your reasons aren't sufficient. Many things don't have intrinsic value and yet have real value. Most money, for example. The pound is worthless. It's a piece of paper with some writing on it and some circular bits of cheap metals. It also might not even have those and be a number representing the number of pieces of paper someone should give you if you ask. Yet we don't tend to throw it away. Some cryptocurrencies have value in that sense, because others are willing to give you stuff, most often a different currency, in exchange. That's the only value they have, and it could disintegrate. It is certainly more likely to disintegrate than it is for the pound to do so (though note it is also possible for the pound's value to be destroyed).

That cryptocurrency doesn't have tangible existence, that it owes what "value" it has to fickle and uninformed investors, that it takes resources to operate, these things are entirely true and don't make it evil. The same is true of a number of other instruments of value, including but not limited to national currencies.

doublelayer Silver badge

That is how pump and dump works. Theoretically, if you bought then immediately sold, it would work as you would benefit from the same scheme the fraudsters were doing to others. If you didn't, because you expected a normal, unfraudulent investment, you lose due to their fraudulent actions. The effect would be the same if it were a stock they were selling. In every case, it's a loss due to a fraudulent action which is a crime, so if you can prove it, they are in trouble.

doublelayer Silver badge

Re: Is there a way they can both lose their money???

Both sets of lawyers lose money? Not a chance. That's not how lawyers work. Sometimes you can get it where one set of lawyers loses money. That's as close as it will go.

Open source maintainer threatens to throw in the towel if companies won't ante up

doublelayer Silver badge

Re: Tech crash?

Yes and no. We sort of already live through this right now, in that vulnerabilities in open source code cause security problems with some frequency. Reliance on open source distribution systems leaves opportunities for hijacked packages to cause problems elsewhere in the chain. However, this isn't specific to open source because the same problems exist in proprietary software as well, with similar effects.

I think the better answer is no (yes, I'm hedging). We're always going to need code to run something, so unless we voluntarily return to the 1980s, people are going to build systems out of something. As stated, proprietary software and open source software have the same risks; either can turn out to be fatally flawed to your detriment. If people are still using the same components in similar ways, it isn't really a crash. That would imply that a radical change has occurred, and this seems unlikely. Laws intended to require security run up against the problem that it's impossible to write bug-free software, and that existing laws that regulate against more obvious deliberate abuses already get enforced laxly. Consumer choices are unlikely to provoke change because most consumers don't have a clue what the terms mean and those who do often have no clue what code got used in the products they buy, use, or interact with. Companies are unlikely to change on their own without some external reason, most often a change to their profit or costs.

doublelayer Silver badge

Re: A bit self-righteous?

I don't think anyone thinks that. The people who write the software are under no obligation to maintain it or do anything to help the users, commercial or otherwise. At the same time, the company or other user is under no obligation to pay them for it. How or if they choose to do those things can depend on how they want the project to proceed.

The attitude of the maintainer in the article makes perfect sense to me; basically, it boils down to "I won't keep working on this unless there is enough money donated for the purpose, and I know the people who would benefit from my work can do that". I support that decision and have no problems whatsoever with those who do that. The argument that makes less sense to me is "I gave this away for free, but you must pay me for it". At that point, I have to ask why they gave it away for free if they're looking for people to purchase licenses. If I write something and give it away, I don't expect the users to pay me. If they want me to do something to improve it that I wasn't already planning to do, then I could give them an estimate, but if they just take the code and use it, which is what most people including companies are doing, that's what I expected when I used a license that said so. Donations are appreciated, but they are voluntary, just as my maintenance effort will be voluntary.

Open source isn't the security problem – misusing it is

doublelayer Silver badge

Re: If every cloud server is dark with all inbound ports close, do we care about Log4shell?

I think this is a bingo for anyone who chose a card for "meaningless technobabble buzzwords for security project".

We have that. It's called IP. It has ports, and you put a firewall over them. That lets you connect some things to the internet and block others. It works great. It would have worked great for this vulnerability too, as long as people remembered to turn on the firewall part. All the components used to do this can be open source and often are. They're designed for a zero-trust environment, the internet, and the problem is when the software being contacted doesn't properly check what the user wants to do and whether they should be allowed to do it (or the software being contacted shouldn't be contactable).

To the extent that your suggestion means anything, it appears to mean that we shut down the IP system and make another one, so that any bot scanning ports won't find anything. If that ever works, then bots will be rewritten to scan the new one again.

doublelayer Silver badge

Did you read the article? How about this bit:

If, and it's a big if, those eyeballs are there and looking. If the code just sits there getting copied over and over again without a moment's thought, no bugs will be found. Simple, isn't it?

or this bit:

But would Goers get paid to go over old Java code with a fine-tooth comb looking for security vulnerabilities even if Oracle were to hire him just to work on Java? I doubt it. Coders are paid to make new code, not fix old code.

The argument really does hold some water, but since you're incorrectly attributing that argument to the article author, you're already going the wrong way.

Anonymous employee review site Glassdoor research: Tech companies dominate the best places to work

doublelayer Silver badge

Specific criteria

"Research from anonymous employee review site Glassdoor shows that dominant software giants Salesforce, Microsoft, Google and SAP are the only companies — from any sector — to appear in all the top 50 best places to works lists in the UK, France, Germany, the US, and Canada."

But a company that operates in only four of those countries wouldn't even be able to appear on all the lists. That means the only candidates that could appear there need to employ a lot of people and have operations in several countries. Given the number of largish employers that don't operate everywhere, it's possible the sample size was smaller than it sounds.

That tech rates highly doesn't surprise me much. It's a field with a distinctive culture because it's relatively new and because individual employees usually have more ability to change things. That certainly doesn't mean it's the best way to operate, but there are many things about the tech culture that don't seem common in other types of company.

Mobile networks really hate Apple's Private Relay: Some folks find iOS privacy feature blocked on their iPhones

doublelayer Silver badge

Re: Simples to get around

That's an issue with carrier-purchased Android devices, but Apple is very controlling about their hardware. It's annoying for the user who wants lots of access, but one perk of their stance is that carriers don't get to load unwanted software onto the phones they sell. It's still locked to them, so better to buy an unlocked version.

If you have to buy a carrier IOS device, it's generally safe. I wouldn't suggest anyone get a carrier Android device ever.

doublelayer Silver badge

Re: "Apple doesn't know which ads I see"

Hold on. The person you replied to is indeed incorrect, but I suggest caution before attributing those protections to Apple's system. The description you have supplied represents what they've said, but there is reason to doubt it. They operate both the ingress and egress proxies, meaning it is technically possible for them to connect the network activities all the way through. This is in contrast to Tor, where each proxy is ideally run by independent people* who don't coordinate. Since it is possible for Apple's system to identify your path, you need to identify yourself to them, and if they did collect that information you wouldn't know about it, I think it can be dangerous to assume it functions in a way similar to Tor. It is an Apple-run VPN only, and you should only use it if you trust Apple to handle your traffic.

* When you get a random path through the Tor network, you don't necessarily know that your path isn't controlled by a single person pretending to be from multiple operators. However, because you generate new paths frequently and have some control over how you route traffic, it is unlikely.

doublelayer Silver badge

Re: Cry me a river (of fake tears)

They will try, and they might succeed, but we have seen that it can be done despite their efforts if there are enough people willing to go to the effort required. GDPR may be poorly enforced, and CCPA may be significantly weakened from the original ideal, but the big data collectors didn't want either of them to pass and they were. They have also resulted in some action (definitely not enough, but they really do have the force of law). If they're going to fight, we have the option to fight back or crumble under the assumption that they cannot fail. They've failed twice and they can again.

doublelayer Silver badge

Re: Cry me a river (of fake tears)

"If they're making money from customers' data the fairest way of recompensing the customers is to give them a lower priced service."

I suggest an alternative:

If they're making money from customers' data the fairest way of recompensing the customers is to fine the company under privacy legislation (if there isn't any, pass some first). Then, if the company hasn't entirely stopped doing it by the next day, fine them again. Continue until the data is private or the company has ceased existing.

Back to school for Microsoft as it prises apart the repairable Surface Laptop SE

doublelayer Silver badge

Re: Good as far as it goes

To me, the only other part I would care about is the storage being replaceable. That does wear out eventually. I think the chance that schools are going to increase the RAM on a cheap device for students to use is remote. Screen and battery are the most important, because they'll be broken or wear out more quickly. Now, since they have proven they can do this, let's see if they'll start doing that with the ones I might end up repairing.

Spruce up your CV or just bin it? Survey finds recruiters are considering alternatives

doublelayer Silver badge

I have a feeling we're not going to agree, but I still have some objections to the methods it sounds like you're using.

"But you can provide a link to your [Stackoverflow] profile when you apply for a job so others can see what comments you've made. This gives potential employers an insight into not only whether you're knowledgeable, but also whether are you able to help others in a meaningful manner."

I don't think that's a useful yardstick. In order to earn a job at your place, I not only have to be good at writing code in the systems you are using and solving the problems you have, but I also need to have volunteered a lot of time answering others' questions and proving myself to be a good teacher. Are you trying to hire a teacher? Because that's the skill you're measuring with this. If you want to see that the candidate can explain a technical thing, ask them to explain a technical thing of your choice during the interview. This demonstrates that A) they can explain technical things, B) they know about the thing you chose, so you can tailor it to something you want them to know about, C) their skill can work with people of the knowledge level you have, rather than someone who may not have a clue, and D) if you aren't sure yet, you can ask them about something else.

"Regardless of whether they're directly relevant to the job you're applying for, [GitHub repos] will give an insight into your abilities to structure and design code."

In my original example, I pointed out why that could easily be misread. I gave an example where the code you would see is the stuff where code is likely to look of poorer quality and where the person has little experience, thus giving an unrealistic idea of their quality.

"If they're personal projects, they will show you have a genuine interest and passion for software development outside of it merely being a way to pay the bills."

This is a problem I didn't deal with last time, but let's do it now. Why does someone need to spend a lot of time on writing code outside their job in order to qualify in your mind? If you're hiring an architect, you generally don't require them to show you the several hobby building designs they have. There are several reasons a candidate might not have a lot of contributions for you to comb through. They could be limited by a legal contract that prevents them from developing or releasing things outside work. They could have a job with long hours and obligations outside it such that they don't have the time to maintain a complex project outside work. Or they could have interests other than computers and still be entirely capable of doing the job you want.

"Whether you agree with them or not, a potential employer should use all tools available to evaluate a potential candidate,"

I disagree. A potential employer should endeavor to establish whether the candidate has the needed skills without being creepy and without requiring unreasonable steps on the candidate's part. The definitions of creepy and unreasonable are subjective, but it's easy for "all available" to start spilling over into them. I've seen employers who do the creepy investigation into anything they can find with the employee's name on it, which has caused problems for people who share names with other people. I've also been asked for everything under the sun by companies because they couldn't possibly know whether I can develop a system unless they can talk to everyone I've ever worked with back to jobs as a student. In each case, they had the ability to ask me to prove something but chose an unreasonable method instead. I don't work there.

doublelayer Silver badge

That's a distinct possibility, but you could ask the same question about interviews, tests, puzzles, or basically anything else that could be used. The CV can at least be reviewed or improved by others, is mostly factual (if the right person is reading them), and can be used to establish the skills of the applicant during other parts of the process. Unless you can find something that accurately represents the candidate no matter their communication skills, the CV may still be among the better of the options.

doublelayer Silver badge

I would guess a lot of them. I send my own copies to the manager as soon as I connect with them to ensure they're getting what I've written. I don't know what it is with agencies not paying attention to the job requirements or the candidates' qualifications; I would have figured that a company wouldn't pay an agency for someone who lacks critical qualifications.

My problem with agencies is that they don't seem to understand what the jobs they have are about. I recently had one where they asked about my skills, and I told them that I don't have experience with frontend. I also don't really want to do frontend, but even if I were to relax that and take a job, they're going to have to accept a person who will be learning (and they're going to have to be unusually interesting to me because I don't like frontend). The recruiter then suggested a job which I rejected as too much frontend. At the end of the conversation, the recruiter had found a better job who wanted the skills I actually have, and they sent the description to me. It's well they did, because the hiring company wanted five years experience with client-side JS, React, Angular, and a number of other frontend frameworks. The recruiter was grumpy when I informed him that it still wouldn't work. They could have saved themselves the effort had they had a clue what "frontend" means.

doublelayer Silver badge

"There are other ways to evaluate potential candidates.", but I have some reservations about many of your suggestions.

"Most people have a LinkedIn profile these days which usually duplicates the majority of things on a CV."

There are three problems with this. One is that not everybody should need a Linkedin profile to apply to a job. Most of them will have it, but not everyone. The second is that a CV can be tailored to the job, listing qualifications of interest to them without listing the things they won't care about. True, it can also have lies on it, but so can a profile. Third, even if we assume the two contain the same content, you could either write a bot to scrape the data from their profile and analyze it for you or have the candidates send you the information in a more readable format that requires no coding or searching to quickly scan. The resume is the easier method for both sides.

"GitHub repositories of personal projects and StackOverflow comments/answers/etc can give an indication of practical knowledge."

Yeah, I generally don't like this. I don't post answers on Stackoverflow often, and when I do, I don't post under my name. I don't think answering people who potentially don't have a clue what they're doing shows much about my practical knowledge. It would speak better of my ability as a teacher, but even there it's not great.

Github is a little better, but it also can be risky. My Github projects are those things that I do as a hobby, at least mostly. That means they're not necessarily the stuff I have the most experience with. If my job is mostly writing a process that runs on servers, but in my spare time, I'm writing something that runs on an embedded system with limited resources, someone reading my Github will get a skewed image of what I know for two reasons. They could misinterpret what the project is and assume that the hacks I'm using to fit my program into the limited resources are what I would do all the time. Even if they don't, they could assume that I only know embedded stuff, and take my less experienced code as what I can do there. This would not take into account that what I write at work can be different and better. Yes, I have multiple repos out there, but not all of them are updated and some of them are simple tools that are useful to me and others but not particularly complex.

The coding challenges before an interview can be a better filtering system as long as they're realistic.

BeOS rebuild / Haiku has a new feature / that runs Windows apps

doublelayer Silver badge

That's still adding the device to a domain with multiple users, where it can be accessed by other users. MDM doesn't negate the multiple users status I mentioned, especially as I already mentioned it when I said that the admins may never actually use their account on the device but nonetheless it has significance by existing.

As for phones, you're correct that they are mostly single-user, although this is one of the restrictions that makes mobile OSes unsuitable for many organizational uses. However, they're not necessarily that way. Android supports multiple users. Sure it's a pain and doesn't do very much, but even they knew the option was necessary. People share phones and tablets, even things as simple as a parent giving their child one temporarily (that happens all the time). Just because the OS doesn't allow you to have separate logins doesn't mean that only one person uses one.

doublelayer Silver badge

"However, in their eyes, and in mine at the time, this was a feature, not a drawback. No end-user computers are normally multiuser any more: people sharing computers was how things worked in the 1960 and 1970s, not in the 21st century."

That's mostly incorrect; any computer that's run by an organization does have multiple users. While each desktop is probably used only by one person, they have a restricted set of privileges because the administrators run some components. The administrators, while they don't use the machine routinely and may never access it physically, are effective users. Many organizational machines are also available for others to log in, even if they mostly don't do so. Home machines may still have multiple users if it is shared among family members or friends, which was a lot more common in the 1990s but is still common today.

A multi-user OS can have any number of users, including one. A single-user machine always has the limitations of that design. I think the decision by basically every OS to remove single-user limitations was necessary at the time and still remains useful.

And yes, servers are multi-user. Not in the sense that every client logs in and runs programs, but in the sense that there are multiple people who do things where they log in and run programs. The server's admin needs root privileges, whereas the clients who run a website from it probably don't. If there are multiple admins, they probably each have their own user account which enables per-user privilege management (even if it's only locking out a user when they leave). Not every server has one admin or a set who can all act as root.

Signal CEO Moxie Marlinspike resigns, leaves WhatsApp co-founder to run things until a successor is named

doublelayer Silver badge

Yes, as in all the successful privacy technology, whatever the platform or effectiveness, in common use by the public today. Even things as simple as TLS/SSL are open source. PGP is open source. The encryption algorithms themselves are open source. The clients on the endpoints are usually open source. What exactly was your objection?

Time to party like it's 2002: Acura and Honda car clocks knocked back 20 years by bug

doublelayer Silver badge

Re: GPS week rollover

I think the chance we're still using the GPS satellites in 3238 is quite low, especially as we already have three other options that work everywhere and don't have such a restricted version. By then, those satellites won't work if they're still in orbit at all. Even if we didn't ever redesign them, one problem that affects people in 3238 beats problems for people in 1999, 2019, apparently also offsets of those years, and almost certainly in 2038. The 1265-year option is only if they wanted to keep their design--they also had the option to report dates in a more configurable way.

doublelayer Silver badge

Re: GPS week rollover

"When GPS was being specified a 1K field was more than enough given the memory limitations of the time"

That's 1kweeks, not 1kbytes or 1kbits. In other words, it is ten bits. Memory was expensive in those days, but so were rocket launches and they paid for a lot of them. Had they sprung for 16 bits for the week counter, they could have kept all the rest of their design and only had a rollover every 1265 years. I think that, even in 1973 when the project was started, they could have afforded less than a byte extra in memory per satellite. A single game console of the period had more memory than they'd have to add throughout the whole constellation.

Avira also mines imaginary internet money on customers' PCs

doublelayer Silver badge

Re: Tried Avira...

"* does that statement make me an AV hibster?"

No, it makes you one of literally everyone here, at least I think so. Has anyone who used Windows before Windows 10 not had the experience of finding an antimalware program that runs well enough, doesn't take up tons of resources, doesn't have some sketchy method of pushing the paid version, and is pretty good at keeping up to date with new malware only to have that program lose one or more of those factors in an update? This also counts if you don't use Windows or don't get malware yourself but have to recommend or even operate antimalware for friends.

Bitcoin 'inventor' will face forgery claims over his Satoshi Nakamoto proof, rules High Court

doublelayer Silver badge

Re: Old Nicknames

No, I don't think they would do that. The tax issue is easy enough, as shown by existing governmental tax policy toward cryptocurrency. Whoever controlled that key hasn't sold any from that chunk, thus no gains to be taxed.

There's no copyright available to be claimed. The code wrote for Bitcoin was released a long time ago and is completely public. We know what it says. Anyone who was going to claim copyright would have made their allegations a while ago. They would almost certainly lose now even if they had written it, and they didn't.

As for a government kidnapping him to take the money, no, they won't do that. A criminal organization maybe, but even they would probably know how unlikely it is to work. If any Bitcoin is sold from this account, it will be immediately noticed and could trigger a collapse in the price because that's 5% of the supply right there. The United States can spend trillions of dollars whenever they want to, so they're not going to kidnap someone for fifty billion. North Korea might want to, but their thefts in real currencies already dwarf this one, so they have better targets.