The Register Home Page

* Posts by doublelayer

11434 publicly visible posts • joined 22 Feb 2018

Intel claims first Alder Lake chip is the fastest desktop gaming silicon in the world

doublelayer Silver badge

Re: Point

The point is to add performance for concurrent tasks. Consider AMD's chips. They're showing much higher benchmark scores than comparable Intel ones. Why is that? Individual cores don't run a lot faster than Intel's cores, although in some cases there is a difference, but one major difference is that AMD's chips have a lot more cores available than the comparable models. AMD laptop processors can have 8 cores/16 threads, whereas even the highest-end laptops using Intel usually have 6/12 or 4/8. The same is true with desktop chips.

Having eight fast cores is expensive, and if the user doesn't run compute-intensive things all the time, they may go unused. Intel's thinking in this case that many users will benefit from extra cores, but mostly so the compute-intensive stuff they do run has less competition. Instead of having to provide a lot of fast cores, they could instead provide some fast cores as they have done and add some slower ones to take background tasks. That would give people a similar level of hardware parallelism while keeping the manufacturing price lower. Whether that convinces manufacturers is yet to be seen, but it has been demonstrated as useful in mobile devices and by Apple, so it's not so unusual an idea. If it works, likely AMD will do similar.

Singaporean minister touts internet 'kill switch' that finds kids reading net nasties and cuts 'em off ASAP

doublelayer Silver badge

Re: "It could be crowdsourced like Wikipedia, for its accuracy."

He's quite correct: it could be crowdsourced. It wouldn't work and would be even worse than the alternative, probably, but it is at least a possibility.

Wikipedia's great, but not every article has correct and up-to-date information all the time. He should know that, but based on the various other things he's talking about, I'm guessing he has more expertise in authoritarianism than in how the internet works even from a user perspective.

Teen bought Google ad for his scam website and made 48 Bitcoins duping UK online shoppers

doublelayer Silver badge

Re: Hmm...

You are correct. Bitcoin and many cryptocurrencies like it are not at all anonymous. They are only pseudonymous. Law enforcement and private companies have systems for tracking transactions in it. There are some cryptocurrencies which use more complex mathematics to be anonymous, but they are often less popular.

doublelayer Silver badge

"What I never understand, is that if this is true, how can entire bitcoin depositories be raided (digitally) and they lose millions of $ in Bitcoin. Surely if this is all traceable then stolen bitcoin can be identified, and then treated/recovered as stolen goods."

Here's the workflow. An exchange stores its coins in a wallet. A good exchange uses a bunch of wallets, just as a bank uses multiple vaults in different places. A bad one may only use a few ones containing all the value. In order to transfer coins for the customers, the private keys for the wallets need to be on a trading system; if you use humans for security on each transaction, the exchange doesn't get customers because it would take hours to start a transaction.

If an attacker steals a private key to one of those wallets, they can authorize any transaction from it. They do that and transfer all the coins to their wallet. The problem now is that, although the blockchain tells you where the money has gone, it doesn't tell you who controls that place. A wallet address is just a cryptographic value. Setting one up is anonymous and takes a few seconds. Anyone can watch that address to see what it does, but they can't just take the coins out. If the thief uses the coins in some way that identifies themselves, law enforcement may locate them and force them to turn over the private key. If they take efforts to hide where the coins are going, they may not be located.

Stolen cryptocurrency may be converted into other types which are harder to track. It can be tumbled, which means that a system will chop up the value from multiple people and distribute it into a bunch of new wallets so you don't know who has it. It can be used to purchase things which won't report to law enforcement (E.G. buying stolen credit cards in order to use those to fund purchases). In those cases, the problem is identifying who has the currency.

doublelayer Silver badge

Re: Will he get a job offer?

I doubt that very much. Some social engineering helps in penetration, but you still need to know how to do the various other things involved in testing. For the media understanding of pen-testing (hey look at this story of a security procedure failing) he could probably do it. For the actual job of pen-testing (identifying the security failings which are most dangerous for the institution and finding ways to start to solve them) he would probably not have the required skills yet.

DDoSers take weekend off only to resume campaign against UK's Voipfone on Monday

doublelayer Silver badge

Re: Annoying...

That will stop them (if they haven't already done what I'll say next) for about two days. Since they already have a bunch of victims, if you find their C&C, and it could easily be outside Russia and if they're Russian it probably is, they could make their bots do it. By distributing C&C across several bots and giving each one a few options, they prevent their whole system, worth quite a lot to them, from being disabled simply by disconnecting one key point.

Placing C&C servers outside the country in which they operate is quite common. If the attackers are Russian, they have a lot of choices of cloud or colocation providers elsewhere who won't notice if they host a simple server which occasionally gets uploads from a Russian IP.

doublelayer Silver badge

Re: against a DDoS

People could block certain recipients quite easily. Especially when the gaps in the analog system became better known. There were tricks to get resources that you didn't pay for, often by finding someone else's resource unprotected. You could then use that to tie up one of the victim's lines. If you could get enough independent connections to close all of theirs, you could lock them out. Eventually, they would terminate your connections and you could race to reconnect before someone else did.

As for taking down the whole network, that wasn't as common. You couldn't call through all the lines available because they had different capacity in every area. Something to cut through wires would be more effective for a single area.

Ransomware criminals have feelings too: BlackMatter abuse caused crims to shut down negotiation portal

doublelayer Silver badge

Their opinion's obvious, I don't know what I think

"Something else that has troubled Emsisoft, when it comes to ransomware publicity, is decryptors."

As a company which makes money from providing services to people who have been infected, it's unsurprising that they don't welcome free decryptors. They have a point that, if one gets released, it's likely to stop working when one of the criminals locates it. However, if the flaw exists in the code but the person who found it doesn't release a decryptor, then a user has to hope that the company they go to happens to have it. If they go to someone who doesn't, they will think their files can't be decrypted locally and are more likely to pay the ransom. That funds criminals when the reasons are even weaker than usual, and it incentivizes companies to find decryption options and hide them from others so they can get more clients.

This would make for an interesting debate topic. What do you think?

Asia's 'superapps' bundle ride-share, food delivery, even financial services – and they're beating big tech

doublelayer Silver badge

Re: Beating who?

"WeChat's biggest risk is probably China's recent crackdown on "too powerful" tech companies."

We interpret that in different ways. I see that as an asset for them, in that if China knows it can subsume their operations, either explicitly or through threatening its management, they can use its monopoly to augment state power. A competitive market would mean that they would have to integrate several different companies, increasing the chances that something doesn't work or someone actually tries to make it hard. The operators are in their position because China effectively marked out a monopoly for them to enter, and they know they have no ability to resist, so they will likely remain valuable enforcement arms.

doublelayer Silver badge

Re: Very different mindsets...

Apple, Google, and Microsoft do not run my financial system. Apple and Google offer payment systems, but they just provide the payment method, not all the other financial aspects. Also, I can easily avoid them, and I do. Similarly, none of those companies runs a transportation system; I use someone else's app on their platform for that. Each company does have a monopoly or oligopoly in a few places and each abuses it to some extent, but not to the level that the apps covered in the article do.

Apple's Safari browser runs the risk of becoming the new Internet Explorer – holding the web back for everyone

doublelayer Silver badge

Re: How do you think web standards work?

"The web goes through standards bodies of very hard working people from many companies,"

Many of whom come from Google and do whatever Google says. That's why we have, in addition to the open standards of HTML which don't change very often, Google's proprietary DRM system as a W3C standard (well, technically, a standard that Google implements, but it goes the other way). This despite several things:

1. It's not a standard. Google wrote it and doesn't give out the mechanism.

2. Google decides who gets to use it, and if you don't have their permission, it's illegal.

3. It's not even very good, but nobody can improve it, because Google doesn't allow modification.

They do the same thing with a lot of other ideas they come up with. They shove API suggestions through the W3C all the time, and then they usher those through after they've already created them in Chrome. This means they can say that other browsers aren't adhering to standards rather than that other browsers don't immediately adopt all of Google's code.

The standards bodies try to work on solutions, but they don't have many resources and nearly everybody there is there because their employer wants them to change the standard in some way for that company's benefit. Google doesn't control it, but they influence its direction and the others there are not there because they want to protect the standard, so Google doesn't have to go to pains to get them to agree.

Not just deprecated, but deleted: Google finally strips File Transfer Protocol code from Chrome browser

doublelayer Silver badge

Re: Overkill for many sites

Yes, that use case works well. My comment was about the uses from a browser as that's what changed and what some here dislike, and you can't do any of those checks from a browser. You could of course download the file with a browser and see whether encfs likes it, but I'm guessing you're using an automatic system which does it more efficiently and therefore don't rely on the browser for any FTP tasks.

doublelayer Silver badge

Re: Overkill for many sites

Entirely true. Few attackers would go to that effort when they have other mechanisms. The only reason I brought it up is that it is a case where the data itself isn't sensitive but can still produce a dangerous result, and you'll note that it only is needed if two conditions which don't always hold are met, and if either is not met, it's a lot easier to inject malicious data.

doublelayer Silver badge

Re: Overkill for many sites

You are sort of correct that almost all FTP traffic in use doesn't come under the use case I suggest. However, that's most of the traffic using FTP for transfers between known machines for known purposes. Most traffic from browsers is users downloading stuff, where the risk of an attacker is larger. Since this article was about the inclusion of FTP in a browser, not an FTP client, I was talking about that use case most of all.

"If someone has the skill, and most importantly motivation to hijack one of the routers between an Internet server and an end user then it's pretty trivial to also insert their own TLS without that user noticing, making the extra layer pointless."

People do have the skill and motivation, observed in ISPs and dodgy public networks alike. And no, it's not always easy to inject TLS. TLS certs are verified against CAs and associated with specific names. Unless the attacker succeeds in redirecting the user to a different endpoint without their noticing, they will find impersonation a bit harder.

doublelayer Silver badge

Re: You can't sell Advertising

Yes, you are right. I used authentication to mean that there was nothing ensuring the identity of the server to the user, as there is with a certificate. That's not the obvious meaning, and a better word would have been clearer.

doublelayer Silver badge

Re: Overkill for many sites

"Literally any anonymous download from the Internet. There is zero reason to encrypt publically available information,"

There are several. Here are a few of them:

1. "encryption does not help with file verification.": It does prevent a listener from modifying the content and it still being valid. Most edits will break the encryption and alert the user rather than corrupting the file, and even if they can corrupt the file, they are unlikely to be able to inject new data into it.

2. Privacy: If I'm downloading a file which anyone can download, but it's encrypted, then an attacker doesn't know exactly which file I'm viewing. This may be of interest to me. The degree of privacy still depends on other factors, as they can usually get the domain I'm downloading from, but there are some plans to encrypt that as well.

3. It prevents meaningful injection of other data, which means that, for files which can't be verified (never an SHA1 hash for a standard page), you're not getting an attacker's replacement instead.

4. If you do have a verifiable file, but the hashes are also retrieved unencrypted, the attacker could replace the file you're downloading and the hashes when you retrieve them so they do match.

If you need something which can talk to something old or something that really can't do encryption because it's so weak, FTP is tested as a protocol. Otherwise, there are reasons to want something that protects the user.

doublelayer Silver badge

Re: Overkill for many sites

And thus it failed. The line was intended to be impassable, or at least very difficult to pass, and it probably would have been pretty good had someone tried to assault it directly. However, because it was possible to bypass it, it ended up not doing what it was designed for, and being effort wasted. Its only benefit was delaying troops by a few days, and it used resources which could have been used in making a more vigorous defense against them.

doublelayer Silver badge

Re: You can't sell Advertising

The connection is not authenticated. You can inject anything you like into the readme when the user downloads it. Anyone willing to go that far can advertise or attack as they like.

doublelayer Silver badge

Re: "frankly, Google and pals would rather users opted for a dedicated transfer app"

"So rather than implement the secure protocol they abandon the facility entirely in favour of a certainly proprietary and almost certainly opaque tool."

You're telling me that you can't find a single open source SFTP client? I can. Lots of them. CLI or GUI. Linux, Windows, Mac OS, all included. They're not new either. Most seem to support unencrypted FTP if you need that still. They're not proprietary. They're not opaque as the standards are well defined. And, unlike browsers, they support uploads as well. Use them.

Allegations of favoring visa holders over US workers for jobs cost Facebook just 4 hours of annual profit

doublelayer Silver badge

"None of them seemed to mind that the stability they enjoy is being paid for with mounting national debt. Nor that the stimulus keeping venerable companies afloat also subsidizes bad management and keeps younger companies out of the market."

I fear you may find many who don't care or even don't know about those things. It's not at all limited to migrants. In order for a country to end up in that situation, a lot of its citizens must ignore or support the actions that cause it.

"The Indian EE just laughed when I told him that some Americans would rather work harder on something excellent than be paid well for a career that will be forgotten before they've even retired."

And once again, I'm sure you could find many Americans with the same attitude. In most cases, it's quite reasonable. In computing, we have the chance to make a codebase that will be respected and built on for years. In most other jobs, that's never going to happen. For the millions who work in a position where they won't get to change the company or the product very much, they may prefer to do their job well enough and reserve their profound enjoyment for the rewards of that labor. The number of people who use their pay to work very hard on a hobby, for example, is surprisingly large.

doublelayer Silver badge

Re: Its a quirk of the (immiegration) system

"Any new roles should be filled by US citizens where possible, so again failing to advertise is misbehaviour. [...] there's also a moral obligation to recruit and train people so that they can do those roles."

The problem is that one could argue that there's a moral obligation not to fire people out of the country they live in, albeit into a country they lived in before, just because you've done a reorganization. They aren't doing that to the Americans they've hired and want to keep, after all. You might not think that obligation exists, but a lot of companies don't think they have any moral obligations [whatsoever] I mean to only hire people from one country. In that case, it falls down to what the law requires, which includes neither obligation.

Facebook may soon reveal new name – we're sure Reg readers will be more creative than Zuck's marketroids

doublelayer Silver badge

Re: It doesn’t need a new name

"What about the employees? About 150,000 of them."

Well, it's too bad for them. They'll have to find new jobs or pay their bills with the savings from the pay they already received. Facebook doesn't stop being evil just because they pay some people to implement the evil and some other people to coordinate the evil plan. I'm sure some of them could rebuild some of the useful stuff that gets shut down because the original version was breaking privacy law.

But there's no chance of those consequences happening, so those people will be fine.

Microsoft unveils Android apps for Windows 11 (for US users only)

doublelayer Silver badge

Re: is this new?

I think it would have several features not in the emulator. For one thing, you should be able to run several things together, rather than just your one project. You can also run things that you don't have the source for, which also helps. And it should integrate better with the local system, for example by letting you share disk space between Android apps and Windows programs.

All that said, I can't think of why this is useful. I'm sure I'll download it when it's available in production because I have some time I don't mind wasting, but I can't think of any Android app that I want running on my computer. Most apps either have better versions for desktop which work natively or benefit from the features of a phone (my computer can't provide a GPS receiver or mobile connection, and it isn't pocketable). I'm more interested in trying to run desktop apps on the mobile device, to be honest.

Software Freedom Conservancy sues TV maker Vizio for 'GPL infringement'

doublelayer Silver badge

Re: I smell a fight coming on

"Actually, that raises a point about John Deere itself, where their software comes from. Truly proprietary, or Linux-based? And, if Linux-based, their entire stance against right to access their software for right-to-repair completely falls apart."

Unfortunately, depending on what software they're talking about, it might not. If the software is only given to the repair people they authorize, then the owner of the equipment doesn't have license rights because they didn't receive copies. The GPL only gives the right to source to those who already have the software, not to those who come into contact with someone who uses it. That allows you to use GPL components if you only use the program internally. For the same reason, they could use a proprietary stack on Linux and similarly avoid having to give up things they don't want to. A copy of the kernel source without the bits that run in userspace won't be as useful.

doublelayer Silver badge

Re: Signed binaries

If they use something under GPL3, you can request installation information. You probably won't get it, but the license gives you a right to it. That wasn't in the GPL 2, though, so just having the Linux kernel won't give you that. That may be a source of more legal action to come, but a lot of the projects concerned don't use GPL3, so it will be harder.

Reg scribe spends week being watched by government Bluetooth wristband, emerges to more surveillance

doublelayer Silver badge

Re: I'll be tracked almost everywhere I go...

"I see "adverts" in the UK for heart disease foundations, cancer charities and other diseases and I feel that if I add up the risk of dying from all of these "advertised diseases" I'd be dead three times over :-)"

The reason for this is that at some point you will be dead (spoiler alert), and the chances that one of those things will be the largest cause is quite high. Various numbers are used, and they can sound high, but things that cause hundreds of thousands of deaths each year are kind of dangerous. How much your particular risk is depends on a lot of other factors. They certainly do advertise using statistics that look extreme, but the brevity of information may lead you to think the statistic is stating something it's not (E.G. your risk of dying by cancer in one year given your age is a lot lower than your risk of dying from cancer some time in the rest of your life, which in turn is lower than your risk of dying from something which you could have dealt with had your system not been weakened by cancer and cancer treatment). Other diseases work in similar ways.

Microsoft called out as big malware hoster – thanks to OneDrive and Office 365 abuse

doublelayer Silver badge

Re: Responsibility

The scanning tools are of use in detecting known malware, but not so useful for finding the new stuff. If it's a method for providing a basic CDN for delivery, most of the content is likely unknown to scanning, and it can also be obfuscated if the initial vector can decode it on the victim's machine. Those two factors make scanning less useful.

doublelayer Silver badge

Re: Users need to know that

It's a feature, sort of, in that it allows someone to link to a translated page rather than its original. Instead of requiring each user to know that you can go to translate.google.com and put in a URL, you can directly link. For example, this article translated to Spanish gives the following URL, which doesn't have google.com in it because they have their vanity TLD and they're going to use it:

https://www-theregister-com.translate.goog/2021/10/18/microsoft_malware_brand/?_x_tr_sl=en&_x_tr_tl=es&_x_tr_hl=en-US&_x_tr_pto=nui

This format is more obvious about where it's going, but the old format did all of it with query parameters and probably still works. The user needs to know that something starting with translate.google.com doesn't mean Google approved the content.

doublelayer Silver badge

Re: Users need to know that

You will note a few things in my post and the article. One thing you will notice is that I mentioned Microsoft first, and started by talking about their and Google's drive services. I referred to both of them for a specific reason: the article compared those and found problems in both. Google was faster at removal but stored more malware in aggregate, or didn't you read it? As for the translate links, I believe an attacker could use Microsoft's translation service to the same effect, but I have not seen it used yet. I have seen Google's used in that way, and it is a similar method to cloak the real source of content online.

Whataboutism is a method of distracting from a point. I did not distract from the problem of malware in Microsoft's cloud, and in fact the only other place I mentioned was the one the article used as a comparison.

doublelayer Silver badge

Users need to know that

Even if Microsoft and Google speed up their resolution of these things, someone is still going to put malware on anything which can distribute data. When I train users, which fortunately I just do informally, this is one of the things I try to get across. Links to a storage service are links to unknown content and no more trustworthy than a link to an unknown website. It's also worth knowing that people will use other tricks to make their content appear to come from a site users trust. I have seen a few attempts using Google Translate so the domain appears to be google.com but contains another domain in the query parameters which the web app will kindly render for the victim. Not all spam is obvious.

Apple arms high-end MacBook Pro notebooks with M1 Pro, M1 Max processors

doublelayer Silver badge

Re: eWaste

"why the hell would you buy a Mac laptop to run Linux?"

Here are a few reasons I prefer my computers to run Linux, whether I intend that to be the only OS or not. This includes the Macs I have bought.

1. I use Linux, so if I can run it on my hardware, then I have that option. If I'm using Mac OS, then I'm fine. If I suddenly find that I want something Mac OS doesn't have, boot to Linux. I find that convenient.

2. In case of damage to the operating system, I can boot to Linux as a convenient method of investigation and recovery. I can mount the Mac OS filesystem read-only in order to copy off files I don't want to risk losing during a repair, and I can also poke around to see what went wrong. Using the built-in recovery system can work for this, but it's running from the same storage device and it has some tools which write to the local system, so I like starting with something I know will not before using the recovery to repair the system.

3. If Mac OS drops support but the hardware keeps working, Linux can be a replacement OS. I like having that option.

"But, FWIW, there are projects to put Linux on M1."

I wouldn't trust those. For one thing, we haven't yet seen whether they work at all on the new chips in these machines. Undoubtedly some hardware and firmware have changed. The only question is how much those changes will impact the existing efforts. Apple isn't, to my knowledge, trying to actively stop those efforts, but they certainly aren't making any effort to keep to a standard that Linux can follow, as they did with their Intel laptops.

I would not buy an ARM Mac if running Linux on it outside a VM was important to me. If you're fine with Mac OS being the only native OS you can run, then it's still an interesting option.

doublelayer Silver badge

You can if you can convince Apple that you're not the only one who likes that strip. I haven't bought a Mac with that on it, but having played around a bit, it seems inconvenient and distracting, and I have not heard anyone who finds it better (observed opinions range from don't use it to sort of dislike it, but that's basically all). That will probably also compress the trackpad a little because they'd have to move the keyboard down to accommodate the extra row.

US lawmakers give Amazon until November to prove it didn't lie to Congress

doublelayer Silver badge

"Amazon slurps all the data and does with it what every web giant does, it makes MONEY"

It's astonishing to me how bad their advertising is. When Google tries it based on some browsing data, especially since I stopped using them for search, they don't have that many data points. Amazon knows everything I ever purchased from them, which I also try to minimize, but it's a lot more useful data. And yet, they don't seem to know how to extrapolate from that. Maybe they would be better if I bought everything from them alone, but that's never going to happen and I somehow doubt they would improve.

Think your phone is snooping on you? Hold my beer, says basic physics

doublelayer Silver badge

Re: Laptop electrical noise

Yes, because that's one of your buses operating at its typical speed. Other parts change their frequency a lot so their signal moves around and is less noticeable to humans or is at too low a frequency to be detected by the common equipment. An active transfer usually means that at least one and more often two buses are communicating as fast as data becomes available, and if your disk is fast enough, that would be almost all the time. That's a simpler wave. Your connection to the TV may also be leaky. I remember this being a problem with 2.4 GHz WiFi on unshielded devices using HDMI because one of the HDMI standards was using a frequency that interfered with it unless either the cable or device was protected from it.

Apple beat Epic Games 9-1 in court. Now it's appealed the one point it lost

doublelayer Silver badge

Re: Freemium game model

Really? Ask yourself these questions, because they have answers.

"Who created the marketing and distribution infrastructure,"

Epic. They have marketing for their game, which Apple doesn't provide, and they do all the heavy lifting for distributing accounts except for downloading binaries. Their part is significantly bigger, and they would be happy to take over that binary bit as well except Apple won't allow them.

"including the store itself?"

Which doesn't market for developers, so you're mischaracterizing what it's for.

"Who maintains and curates it?"

Apple, but the developers don't particularly care that Apple pays someone to redesign the front page all the time. If Apple didn't do that, the developers could still write their software and the user could still run it.

"Who pays for and maintains the cloud storage backend?."

Apple, although just for the app download. Epic would probably be quite happy to do that and stop paying Apple a price significantly higher than servers and CDNs cost.

There are 875 million good reasons why the paperless office won't happen soon

doublelayer Silver badge

Re: A fundamental problem

Try using ffmpeg on them. Usually, if there's something unusual about the file or the player, ffmpeg can turn the file into something the player can understand. Unless it just got corrupted. It doesn't work on everything, so if it used a very proprietary codec somewhere it might fail, but most ones were identified and implemented there at some point.

German Pirate Party member claims EU plans for a GDPR-compliant Whois v2 will lead to 'doxxing and death lists'

doublelayer Silver badge

Re: "doesn't make piracy much easier."

"It's far more difficult to shutdown domain names when they can be created automatically using fake credentials and being unable to identify who's behind"

If you're in law enforcement, it's not that difficult to shut down the accounts and go after their payment method, which is a lot harder to fake. Most of the time when they're not shut down, it's because nobody investigated them, not because they were just too good.

"Did you give a look to the spam your receive? Phishing websites? Botnet and ransomware delivery and C&C?"

Let's consider those then. Phishing is mostly coming from spoofed addresses, meaning they don't need to buy a domain name. Botnets almost never have domain names. Nodes in them may not even have dedicated IP addresses. C&C: domain names are more common here, but they're not either. If the malware writers put in an IP address, they can still route their C&C traffic there.

"It's not possible to allow online what is not allowed in the physical world."

It's very possible and often desirable.

"Can you open a shop wtihout being registered in many different "books"?"

Legally? Not exactly, but sort of. You could have an unofficial shop which doesn't operate as a business, doesn't have financial accounts, and doesn't own or rent property. So long as you tell the tax authorities about the money you make, that's fine. It gets more complex if you want to be bigger, but that small approach is entirely possible.

"Can you publish something physically without registering your publication and identifying who's responsible for it?"

Yes, without difficulty. 1) Buy a printer, 2) print a document several times, 3) distribute the paper however you like. Entirely legal. You are not required to register any publication, and you can still copyright it without having done so. The only places which require registration are authoritarian nightmares, and the method still works there too.

"copyright violation is the smallest issue. There are far worse ones. Just, most people are OK with the worse ones as long as they can get their pirated contents for free... a very myopic and selfish attitude."

Which I have stated that I don't support, and yet you seem to have such a low opinion of me. Your examples of worse ones were above, and they didn't use domain names, so you're not convincing me yet.

"Sure, it won't solve completely the issue, but why let crooks be able to hide very easily when there's little reason to allow that?"

Because anonymity is useful, and because despite what you've claimed, there is little reason to expect that removing it will prevent any crime. Meanwhile, I think domain names are so core to the functioning of the internet that people shouldn't have to be publicly identifiable to host one.

"A whistleblower or activists in danger registers their own domain to publish what they need? C'mon...."

They do, you know. If you're afraid that something will be removed if you publish it on a service, whether because it's illegal or just unpopular, then hosting it yourself works pretty well. If it is really illegal, law enforcement can have the domain name and hosting cut.

doublelayer Silver badge

Re: "He appears not to have read draft article 23"

"But I guess many will agree on the call centre issue, but won't on domains because they are driven by greed,"

Not my reasoning. For one thing, call centers will spoof IDs until the laws against that are enforced or the protocol is updated to prevent it. Requiring an ID to operate a phone number won't get either done.

Having a domain name without an identity connected to it doesn't make piracy much easier. The governments still have the ability to shut down the domain name and collect information such as the payment method used to register it. If you view IDs on items used to pirate media as a justified response, you would have to collect them for lots of other things. Internet connections, including temporary ones on a public network, for example. Also the equipment you use at the end of those lines, meaning all computers. You'd also want to identify any user of an online service which could share information, because they could put copyrighted information up there or identify the system on which it's found. You could make a case for registering each IP address and each general-purpose computer as a measure against copyright violation. I think that, if you did, it's a terrible idea and has several worrying risks, and I think they apply similarly with domain names.

In my opinion, there are few items dangerous enough that their purchase should be recorded for the use of law enforcement. Any item added to that list needs a lot of justification, and so far I haven't been convinced by any argument about domain names being that dangerous.

doublelayer Silver badge

Re: WHOIS not alone

I don't support anonymous companies, though I can see a case for companies that a member of the general public can't identify, leaving that to law enforcement. But I'm not going to argue that point right now; we can proceed with the idea that the public should have instant access to the identities creating any company. In which case, a unique number is much better than birth month and year. If two John Smiths born in May 1981 open companies, you could confuse them. If John Smith 1285939 and John Smith 1287561 open companies, you can't mistake them for one another. And in order to find all the companies with the former, you just search for that director number.

doublelayer Silver badge

Re: Checking at least some details?

It's not hard to set up a front organization in a country you think you trust. The organizations who sell anonymization services or did so before GDPR made that generally applicable were located all over the place. I remember several based in Canada, the U.S., France, and Denmark. Would you trust any of those countries? If not, I wonder what your list is and whether you really checked sites for presence on it.

doublelayer Silver badge

Re: WHOIS not alone

And why might you need to narrow down the company director without the extra access, and if you do, why is it birth month and year that you should use as a key? That is not a very good key, as people could share that data as well and it is of use to scammers. Eliminate those issues by instead having a company director number, which is randomly assigned to a unique person so you can immediately see any other companies they have registered but you can't use it to pose as them. Risk of collision: zero, so it's a better tool for your use case. Risk of abuse: significantly lower.

doublelayer Silver badge

Re: WHOIS not alone

Birth month and year is bad enough, especially as I see no reason the public needs to know that when investigating a company. As for the address, that's great for a company that has its own premises somewhere, but if it's a small one where all the workers work from home or it exists for a freelance person to organize contracting work, then they won't have one. Should they be obliged to rent some external address to receive post just so their real address where they can already receive post won't be publicized?

Bank manager tricked into handing $35m to scammers using fake 'deep voice' tech

doublelayer Silver badge

Usually when I've seen these, they make you say something that they've just come up with so you can't use a recording. That would require them to have a pretty good model for sounding like you because they could have left out an accent trick which the bank's model has remembered. However, it's hard to test and easy for an attacker to play with, so I would recommend that nobody enable that if they have a choice to use a less convenient but more secure method.

doublelayer Silver badge

Re: Of all the scams in all the world -

From the sound of it, they also had fake documents and emails to start the scam, with the voice call only as a second factor. The bank certainly should alter their policies so one person, even completely convinced, cannot lose them that much money without oversight.

Everyone who wants a smartphone for Chrimbo will get one, but in the real world things are somewhat different

doublelayer Silver badge

Re: "The chipset famine has truly arrived"

They're unlikely to admit that, but it's not compatible with the current situation anyway. The problem now is that people are trying to buy more tech than the manufacturers can produce and ship, so demand isn't that low. It would help if people didn't want to buy more phones, because then the related items would be manufactured and shipped more quickly. Well it would help me at any rate. The phone manufacturers have a different view.

Client-side content scanning is an unworkable, insecure disaster for democracy

doublelayer Silver badge

Re: Apple has its own agenda

I agree, and yet think you're wrong about the others. I would rather have Google and Facebook comb through my data on their servers than Apple comb through my data on their devices, because I go to lengths not to put any data on Facebook or Google's servers. For that matter, I also put very little data on Apple's servers. That's where I can exert my control, by not allowing things on other people's servers. If they run it on things I own and use, they have much more access to the place where my data really is, and I have less ability to know what is available to be analyzed and what will happen to it. It's not like they were going to offer a "Do you want all your stuff scanned" switch.

doublelayer Silver badge

Ah, you're back. I thought you left.

Standard problems with your repeated comments apply: not text under consideration, these are images. Also of no relevance as we're not talking about advertising and the problem is privacy.

Judge rejects claims Cloudflare should be held responsible for customers' copyright infringement

doublelayer Silver badge

Re: knowledge and the law

Many crimes do in fact require that the person doing them must know that they are committing a crime. It doesn't always apply, for instance the author who committed the plagiarism doesn't have to know that it's illegal, but someone who binds the book does not know of its contents and would not be charged because they didn't commit a crime. Usually, it's the accessory or aiding charges that require knowledge, and that's the charge that would be leveled against most of the people on the "might" list.

Missouri governor demands prosecution of reporter for 'decoding HTML source code' and reporting a data breach

doublelayer Silver badge

Re: Dare I admit to the govenor ...

Sadly, there are some people who would see those as worrying criminal tools. I know if I'm ever investigated for some crime, I'm going to get a lot of blame for having a tool called Wireshark installed on my computer. It's even got that scary name and talks about packet capture, so I must be evil. Wget doesn't have the same cool name credential, but by not being a full word, they'll give it extra points for ubertechnical hacking tool so we're probably even. Unless they have a forensic investigator review my hard drive and find that I've got wget too. Then we will be assumed to be acting in concert, which will be very fun if we're in different countries so we can be called "an international cybercrime organization".

LAN traffic can be wirelessly sniffed from cables with $30 setup, says researcher

doublelayer Silver badge

Re: I thought LAN cables were shielded

If by "one of those plastic tags" you mean a label on the cable, then they've managed some very compact designs. A listener needs not only an antenna of sufficient length to receive the signal, but also a processor to decode the signals, a mechanism to send that data to the attacker, likely wireless if this mechanism is useful, and a power source to run all of those. That's going to make for a very thick tag.