The Register Home Page

* Posts by doublelayer

11394 publicly visible posts • joined 22 Feb 2018

Wi-Fi devices set to become object sensors by 2024 under planned 802.11bf standard

doublelayer Silver badge

Re: Stalker's dream

"you have to make 6 million calculations a minute on 18 million datapoints. Just to get the 'raw' location data."

Sorry, but this doesn't sound as difficult as I think you meant it to. My desktop can process millions of operations per second. A server can do it even faster by throwing more cores at the problem, because it's completely parallelizable. The only tricky part is getting the large databases into the processing system, but since they have high-speed connections to send user data, it's not that difficult to do that either. Existing software is available to take that raw location data and display it on a map, and I'm sure there are companies willing to build a system to analyze that kind of raw intelligence.

And that's yet another UK education body under attack from ransomware: Servers, email, phones yanked offline

doublelayer Silver badge

I don't know about this situation. That is true. However, I do know about a lot of other situations where ransomware has struck in the past. A lot of those which had problems were due to configuration problems. People got hit with ransomware and you don't know about it because they limited the spread and recovered quickly. The ones who get articles here usually had more trouble, either a more pervasive spread, difficulty recovering from insufficient backups, or both. Therefore, if an organization is having a lot of trouble because of a ransomware situation, I view it as more likely they didn't take a backup step than they were hit with a very sophisticated ransomware variant.

doublelayer Silver badge

Any network will get malware on it eventually. Some networks get malware on them a lot more often than others. These things are not contradictory.

Any system will lose data permanently eventually. Some systems have no backups and therefore will lose data permanently more often and in a more damaging manner. These things are not contradictory.

The most sophisticated attack will eventually get access through a very good security system. A good enough security system will block less sophisticated attacks. These things are not contradictory.

Some of this is about doing the job well. Ransomware can be prevented more often by employing security measures that make it harder to install. While it can't be prevented in all cases, the risk can be reduced. If ransomware does strike, it will be debilitating, but if there are good backups, it will lessen the cost of fixing things. A sophisticated attacker may manage to infect the backups too, but it's possible to avoid that. Therefore, it is justifiable to say that a place with local admin rights for everybody and no backup system has failed to do its job related to security. We're not being sanctimonious any more than you would be if you told me not to leave the keys to my car in the car and then walk away. It's a precaution they have to take and they didn't. This doesn't apply to everybody, but you'll find it applies to a lot of them.

Intel accused of wiretapping because it uses analytics to track keystrokes, mouse movements on its website

doublelayer Silver badge

Re: Well...

The law is clear. Parties which can record when one-party consent is permitted are those parties known to be on the call. I initiate the call and am one of them. The recipient of the call receives the call and is known to me, therefore they are also one of them. Another person is listening in and I didn't know they were there and I didn't consent to their collection. That's illegal. If they sold their software to Intel, only Intel runs it, and the data is only stored on Intel equipment, then that's not a violation. If any of my data goes to the operators of the library, they are violating it with Intel's collaboration.

Even if Intel runs it all locally, they are violating legislation in states requiring two-party consent (this does mean all-party consent) and privacy legislation in the mold of GDPR, including the CCPA.

doublelayer Silver badge

Re: Well...

"In some jurisdictions, recording ("wiretapping") can be legally done with only one party's consent"

Yes, but not with a third party. In such jurisdictions, if I call you, I can record our conversation. However, if I call you and a third person not on the call records it, even if you know that, it is not legal. Also, California doesn't allow this. Florida does, but that proviso applies there.

Satellites, space debris may have already brightened night skies 10% globally – and it's going to get worse

doublelayer Silver badge

Re: Blankety Blank

Why? You can choose to open in a new tab if you want to. You can even make that default. Why should a link to a different page on the same site open a new tab by default? That just leads to ten tabs including eight zombies which I'll have to close later. The browsers give you an easy way to ask for that if you want it.

Apple expands third-party repairer program, mostly in Asia

doublelayer Silver badge

Re: A growing “right to repair” movement

"I'd also argue that it's not a cartel if anyone can apply to join. Sure, they have to meet a minimum standard - but surely that's a good thing?"

Cartels aren't limited in entry criteria. This is a cartel:

"1. (economics) A group of businesses or nations that collude to limit competition within an industry or market."

OPEC, for example, is a cartel. Yet they're happy to let people in. If you run a country which produces petroleum and you're willing to restrict production to manipulate the price along with the other members, OPEC will welcome you with open arms. It's not about how you get into the group. It's about what the group does.

In this case, Apple is making it such that any company needs to meet their standards to work on any Apple product and therefore deny the right for people who haven't had that certification to do so at all. They will have all the repairers in their corner, and since the repairers must purchase all their plans and parts from Apple, Apple will control the market. Apple sets the price. Apple sets the supply. Apple says what is going to be allowed and what isn't. Apple also controls the supply of repairers if they want to. That's a cartel, albeit one where Apple has nearly all the power.

As for whether that's a good thing, I'd argue not. For the moment, people who advocate the right to repair have a reasonably good argument. "Apple won't repair our stuff and they also won't let us do it. We should fix that by making them allow us access to the necessary parts." Apple, by letting people open restricted repair shops, is cutting off this argument without fixing the problem. If their repair shops exist and theoretically could fix a product, then there must be options and thus no need for access. However, Apple's control over the repair shops can make it so repairs aren't available or economical. Break a screen? Pay 90% of the original price for a replacement. Break a button? Sorry, that's not available so you'll have to buy a replacement. Meanwhile, they're attacking anyone who attempts to go around them. People who make replacement parts or people who recycle broken phones for those parts which work are being attacked by Apple, both with lawsuits and increased software locks to make sure the parts don't work.

5-year-old Fairphone 2 is about to receive a major update to Android 9

doublelayer Silver badge

Who's heard this before?

"In December, Qualcomm and Google teamed up to re-architect how Android versions are made, aiming to increase the number of OS versions a device will receive. These changes, which apply to devices released with Android 11 and the Snapdragon 888 or newer, will conceivably allow vendors to provide three major software upgrades."

How many times has Google re-architected Android in order to make it easier to update? Or easier to install the newest version on something? I've heard this over and over and over. Android 2.2 was supposed to help with this. It was one of the selling points of Android 4.1. It was announced with fanfair sometime around the release of Android 7. And it was announced with triumph that Android 8.1 would finally achieve it. They're just lying, aren't they? Either the manufacturer tries or they don't, and the architecture means it's trivially easy for chipset designers not to hand the solution over to a manufacturer which in turn decides not to do the work themselves. Google clearly doesn't care.

doublelayer Silver badge

Re: Who still uses a 5 year old "smartphone"

Well, me for one. My main phone is from 2016. Why? Because the newer phones provide only a few benefits. They're larger. That's a downside for me. They have more cameras. Given that I use the camera maybe four times a year to demonstrate something, that's not very important. They have 5G. If I was using my data connection outside WiFi range a lot, this would... probably not make a difference because 5G coverage is still limited. As it is, I don't use the data connection very often and 4G has been just fine for it. They have faster CPUs, which I wouldn't mind, but I don't do heavy lifting with my phone's CPU so its speed is relatively unimportant to me. I have nothing that I want from a new phone, and by not spending money on a new phone, I can have the ability to buy something else which will be more useful.

Now that half of Nominet's board has been ejected, what happens next? Let us walk you through the possibilities

doublelayer Silver badge

Re: GoDaddy, but that will be changed at the next opportunity.

"I'm still waiting for an answer to that question from Fasthosts"

Based on the publicbenefit.uk site, they're a subsidiary of 1&1 which voted against. I'd say that's enough to go on.

Free Software Foundation urged to free itself of Richard Stallman by hundreds of developers and techies

doublelayer Silver badge

Re: "Punishments" vs "consequences"

Yes, it is. Your threat of punching is a crime though. Your actual punching is another crime too. You have the freedom to tell your boss or client that you hate them and think it would be best if they were locked up just for annoying you, but if you do, they will not be your boss or client much longer. This is a deliberate decision on their part. On that basis, you may call it a "punishment". Too bad. It's a punishment that they have the right to give to you.

doublelayer Silver badge

Re: Oh how the woke wimper

Freedom of speech means the government can't be the one giving you consequences. This seems to be required teaching about once a month, so let's do it a few more times. North Korea does not have it because, if you say the wrong thing, the government comes to arrest you. If I don't like what you said and tell you never to come to my house again, that's not a violation of your freedom of speech. If I don't like what you said and make it so you can't post on my site again, that's not a violation of your freedom of speech. If I don't like what you said and say something to you that you don't like, that's not a violation of your freedom of speech. If I don't like something you said and refuse to associate with you ever again, that's not a violation of your freedom of speech. If I don't like something you said and I tell other people that you said it, and they also don't like what you said, that is not a violation of your freedom of speech. As long as the government doesn't come to arrest you or otherwise affect your rights, your freedom of speech has not been violated.

Guilty: Sister and brother who over-ordered hundreds of MacBooks for university and sold the kit for millions

doublelayer Silver badge

Re: "Gentlemen do not read each other's mail."

Police surveillance is bad ... when the police don't have a warrant. This was a situation where they almost certainly had one. They accessed a specific person's records because they had probable cause to suspect that person of committing a crime. That's clear and justified use. Also, this line:

"I feel a bit sorry for them. Victimless crime an' all that..."

That's stupid. It's not a victimless crime. The employer who spent extra money is out millions of dollars from their crime. That's a victim. It's a university, meaning most of their money comes from student tuition payments and grants. Those payments probably went up to handle their increased budget. That's more victims. These aren't even secondary victims who lost a potential benefit. They lost money directly. You need to learn that.

doublelayer Silver badge

Re: Why is the second part of:

It's not PayPal's job to validate each transaction to determine whether the sale is valid or not. They just move the money. As long as they do the checking to determine that it's not money laundering, they're in the clear. How should they know if the laptops are stolen or not? In fact, they won't even know the exchanged items are laptops.

Outsourced techie gets 2-year sentence after trashing system of former client: 1,200 Office 365 accounts zapped

doublelayer Silver badge

Re: Thank god I work for a company that makes something

Er... there's a lot of useful work that's done that way. Your company makes something, right? I'm guessing you build that thing? There are people who receive emails from people buying the thing. Those wouldn't be available. There are more people who receive emails for contracts for the components. They're cut off too. Lawyers review your thing for compliance with regulations. This is useful work which requires communication, and your company needs them too.

doublelayer Silver badge

That's possible, but it's not guaranteed. There are a few options. For example, the employee might not have entered on such a visa. He might have other rights of residency, or have been hired as an outsourced worker who visited only a short time. For that matter, he could have been a dual citizen which is unlikely but possible. Also note that the victim company also didn't get their name printed. Maybe they just don't want to be known as the people who broke the system that badly.

The kids aren't all right: Fall in GCSE compsci students is bad news for employers and Britain's future growth plans

doublelayer Silver badge

Re: Full time IT education courses

"What I do find unfortunately is a tendency for new starters to want to go straight in to an IT specialism (such as Cyber Security), without having done the hard miles first on the likes of an IT support desk, or infrastructure teams."

Because they don't want to work on the helpdesk. It won't help them all that much, will it? If they waste a couple years helping people turn the computer off and on again, run antivirus scans, or the like, they haven't learned anything other than how users mess things up. If they're using that as a way to earn some money while they learn stuff elsewhere, that's fine. If they actively enjoy the role, that's fine. But if you think that's actually going to teach them something useful before you'll let them do what they want to do, they'll just leave. A helpdesk position only gives someone experience dealing with users and user-facing equipment. You don't learn how the server's run by doing that. You don't learn how to use databases by doing that. You don't learn how to manage networks by doing that. Theoretically, they could get some useful experience by impressing someone who tells them "Hey, stop doing that and come learn something better with me for a while", but that's not guaranteed and they could also just learn that themselves. So as an educational tool, it's not very good.

doublelayer Silver badge

Fine. I'll concede that you are an office admin. The IT people who do more than that, though, are not. A person who does easy stuff with desktops like you describe is doing something users should know how to do. The person who made that default image probably knows more. The person who configured the network and got everybody online while monitoring their machines for security incidents knows more. The person who ensures the necessary servers are available so work can continue know more. These things are clearly IT. We can draw a line between IT and software development if you like and still acknowledge that there are roles on the IT side requiring more advanced skills.

America's Supremes give Facebook nothing but heartaches: Top court won't stop '$15bn wiretap' lawsuit

doublelayer Silver badge

Re: Be careful what you wish for.

Right. Facebook is a hero which lets me do all sorts of things I couldn't do with a webserver or any of the thousands of forums that existed before they started, quite a few of which still exist today. It's all down to them that we have an open internet, even though they keep buying up parts of the internet and making it more centralized. This is a forum of technical people. We know what's possible without Facebook there. Talking is still possible. We also know what's related to Facebook and what isn't. National spying, for example, is perfectly possible with Facebook there and in fact easier with all their data in one convenient place. You are wrong.

doublelayer Silver badge

Re: The Impossible Wall

That's correct. You can't FOIA Facebook. If you live in a country with GDPR or California with CCPA, you have the right to get a copy of their data on you. Be prepared to give them a bunch of identifying information so they can find the data on you. Be prepared for them to keep that information and not tell you about doing that. Also be prepared to see some lies about what they don't have.

doublelayer Silver badge

Re: The Impossible Wall

"How do I go about ascertaining whether or no that Facebook has or doesn't have any of my information?"

Flip a coin. If it lands, they have some information about you. It might be wrong, but they have it. If it doesn't land, you are not on Earth. Since you have access to the internet, we presume you're on the ISS, in which case they have information about you. All paths return the same value.

Chairman, CEO of Nominet ousted as member rebellion drives .uk registry back to non-commercial roots

doublelayer Silver badge

Re: One question

"To encourage registrars to sell .uk names instead of .whatever."

Seriously, they don't do that and don't need to. That's an issue for the new GTLDs because A) nobody has seen them so they don't have any existing credibility and B) there are hundreds of them available. Neither is the case for .uk. .uk is what you buy if you want to look like you're connected to the UK. Everybody knows that. It doesn't have a massive selling point otherwise. It's also very popular as TLDs go just because the UK has had sites for a long time. Anything they're spending advertising .uk is money wasted.

doublelayer Silver badge

Re: Looking for a new registrar

If you want a registrar that supported it for a while, the publicbenefit.uk homepage lists the supporters. The largest ones who supported for a while are Gandi, 20I, Coherent, Crystal, and ANY-Web. Two even larger ones, TUCOWS and Namecheap, also voted in support but made up their minds later. There are about 480 other supporting members available. I have only listed those managing over 30K .uk domains. There is plenty of competition available while allowing you to stick with companies supporting the motion.

Richard Stallman says he has returned to the Free Software Foundation board of directors and won't be resigning again

doublelayer Silver badge

The thing I'm taking issue with is the "moral" part. To argue that something is "moral" usually means something specific. More than "It's good of you to do it", it's usually "It's bad of you not to do it". In the same sense that it's moral to be kind to people. That is what the original comment seemed to say, and I've seen lots of people say just that. Therefore, that is what I'm arguing against.

doublelayer Silver badge

It does take a lot of resources to actually create the software. Writing code which functions takes time. Making that code not crash takes time. Creating the resources which most nontrivial code uses takes time. And not only time, but also a lot of specialized resources like programmer knowledge, equipment, attention to detail, etc. Copying may be cheap, but that does not make the rest of it free. It is not. I'll grant that the car analogy is not perfect, but then little is. I'd try a book analogy, but some people also think those should be entirely free whether the author wants to do that or not, so it isn't as illustrative.

There are people out there who hate GPL with a passion. They have often taken the argument that licensing code under the GPL is violating their rights because it doesn't let them use it in proprietary software. I am very annoyed with those people. However, there are people who make similar arguments about anything not licensed under the GPL, including proprietary and permissive. They are wrong too. It is an issue of choice. What they have to realize is that copyleft is based on copyright, just like proprietary is. The reason GPL has the freedoms of GPL is that copyright law makes it happen.

doublelayer Silver badge

Re: It's FLOSS btw

This argument is nice, but it doesn't always work. If you write code and make it copyleft, I'm happy because yay, free code. If you build a car and give that away too, yay, free car. This is not a moral imperative though. It's just a nice thing to do. I write code and release it for free (variety of licenses, but I have written GPL3 stuff because I want the license terms to apply). When I do, I understand that I'm not going to get money for the work unless I'm very lucky. It is also my right to create software which I don't release so freely as long as I don't use others' GPLed code to do it.

If someone writes some code, not using any copyleft components, and doesn't give that code to everyone but instead sells it, that's not an immoral act. Acting like it is is weird and is exactly the kind of thing that makes the original poster not want to take you into a meeting. Not having access to the code may be a sufficient reason not to use it. That's your choice, not an ethical certainty. Sadly, we don't always live in a world where code written from pure altruism is available or superior to proprietary code written for profit, which means that people who either don't care about or don't understand the license wars may choose the proprietary option.

doublelayer Silver badge

I read the comment as giving Stallman credit for the Linux kernel. Now that I'm reading it again, it could be that or they could be correctly setting it apart and giving Stallman credit for the rest. I'm not sure which it is. If it's the latter, then my original critique is incorrect.

If it is the latter, it's unfair to lots of people who are not the FSF. This is the problem I have with those who are intent on calling Linux GNU/Linux. Yes, GNU deserves credit for lots of nice code they've written, but by including them in the name as some demand, it does two things that I see as harmful. The first is that it implies that GNU code is required for a Linux system that respects user freedoms. This is not true. Almost all the most popular and required GNU programs have non-GNU alternatives. There are alternatives for libc, GCC, the core utils, and quite a few other things.

The second problem is that plenty of other projects deserve some credit and don't get it when GNU and Linux are listed as if they're the most important. Most running Linux installations, desktop or server, have lots of software written by people who are neither the Linux foundation nor GNU. If the name of the system has to list all the important players, then it will be a very long name. KDE/Mozilla/Python/TDF/ApacheFoundation/Apple*/GNU/RedHat/Linux describes a basic desktop distro before the user installs anything, and there are undoubtedly plenty of others who deserve membership in the list but I stopped listing them. Not that it diminishes the real contributions made by the GNU project and the FSF, but such statements are often a lot more limited than they should be for honesty.

*Apple, in the Linux company list? Yes. Several important components rely on Apple-maintained components. They include CUPS for printing, OpenCL, LLVM and Clang, etc. One could list each project by its independent name, but so the name fits in this comment box, I'm recommending we don't just glob together all the installed package names.

doublelayer Silver badge

"I think Stallman ought to be recognised for his tremendous contribution to FOSS (as Linux is much more than just a kernel),"

Sorry in advance for the pedantry, but this is the wrong way round. Stallman didn't write Linux at all, and the people who did are not associated with the FSF or GNU. What those projects created are a lot of the utilities that go around the kernel. This has led to arguments between the two projects, for example Linux sticking with GPL version 2 only while the FSF is intent that version 3 is much better. Also, insert the Linux versus GNU/Linux argument here.

John Cleese ‘has a bridge to sell you’, suggests $69,346,250.50 price to top Beeple's virtual art record

doublelayer Silver badge

Re: We have lots of non-fungible tokens

No, they can't. If you buy an NFT, you get a copy with a digital signature which is signed by a couple of keys including one you have. So you can authorize a transfer if you want to and you can prove that you have the key and others don't have it. But you can also just chop off the digital signature and send the part of the file you can look at out to anyone you like and they can't tell who sent it or who received it.

What could be worse than killing a golden goose? Killing someone else's golden goose

doublelayer Silver badge

Re: "Things were purposefully not documented"

It's pretty clear those things don't apply. Nothing went "contrary to internal procedures". The other person wasn't annoyed because it should have gone through a meeting. They were annoyed because they deliberately created the mistake. In literally every scenario, your objections do not apply. Here are some likely options:

The change didn't go through procedures and the creator didn't do anything deliberately: Have it reversed then go through procedures. That didn't happen. This scenario isn't right.

The change didn't go through procedures and the creator was trying to hide their mistake: Don't complain about the change and nobody finds out who made the mistake. That didn't happen.

The change didn't go through procedures and the creator was annoyed enough about someone not following procedure that they wanted to fire that person: Discipline them for not following procedures. That didn't happen.

No, this was clearly malpractice and there's no reason for it. The senior developer should have been fired for it following the procedure to figure out who knew about the code and why they didn't do something about it.

Encrypted phones biz Sky Global shuts up shop after CEO indictment, police raids on users in Europe

doublelayer Silver badge

Re: "paint encrypted mobile phone services as something used exclusively by criminals"

You have now proven my point. The indictment linked is entirely about complicity with criminal clients. What did I say about that option? I called it "plausibly true".

My complaints are about application of export law which doesn't apply outside the U.S. Is that in the indictment? No, it's not. Is it in the Dutch or Belgian reports? No, it's not. Why not? Because it does not apply. The lawyers and I agree on what charges are valid. We also agree on what's plausible. To prove it true instead of just plausible, they'll need more proof than I've seen. They probably have it. That's their job.

They are likely correct. You ... are not. They are focusing on a crime which they will have to prove. You're attacking cryptography on fallacious arguments and incorrect application of limited legislation.

doublelayer Silver badge

Re: "paint encrypted mobile phone services as something used exclusively by criminals"

You are wrong several times. Let's start with the obvious one:

"The culpability in this case is two-fold: (a) he sold strong encryption to drug dealers for the purpose of evading detection while committing a crime and (b) in the process of committing (a) he violated ITAR and US Export Control regulations."

A is covered in my original comment, short version is "more proof than that needed". For B, no, he did not violate U.S. export controls. He and his company are Canadian. The exports happened from Canada. U.S. export controls only apply to people exporting stuff from the U.S. Same with ITAR. It's a U.S. law and applies only to the U.S. Other countries have similar legislation, at times structured to be compatible, but it's not ITAR. Canada has export control legislation. Calling it ITAR and alleging that U.S. export regulations apply to Canadians makes it clear you do not understand how those laws work.

Now let's consider Canada's legislation. Actually, it's best we don't, because Canada hasn't charged anybody with breaking its export legislation, and they are the ones who would have to. But let's consider it anyway. In the list of controlled items, it originally seems somewhat damning since symmetric cryptography which works is prohibited (limit of 56 bit keys). However, there are long lists of exceptions. One of them looks like this:

"e. Portable or mobile radiotelephones and similar client wireless devices for civil use, that implement only published or commercial cryptographic standards (except for anti piracy functions, which may be non-published) and also meet the provisions of paragraphs a.2. to a.4. of the Cryptography Note (Note 3 in Category 5 - Part 2), that have been customised for a specific civil industry application with features that do not affect the cryptographic functionality of these original non-customised devices;"

Well, the phones themselves are mass-market with hardware modifications unrelated to the cryptography. So as long as they use public algorithms, they count under this exception. Public algorithms include AES and RSA. So now, if Canada wants to charge him, they will have to identify the encryption in use. I'm guessing it's likely to be a public one, in which case they have already allowed it.

Also see this FAQ about cryptography exports. It's useful in determining what is allowed and what is not.

By the way, you'll find that no charges for breaking export controls, whether Canadian or U.S., have been filed. That's because the lawyers understand what is illegal and what isn't. They are hinging their entire case on point A, and point A is quite plausibly true. Still, it needs more proof than you have.

doublelayer Silver badge

Re: "paint encrypted mobile phone services as something used exclusively by criminals"

Well, they can both be used to commit a crime. A car lets a criminal get to or away from a crime scene a lot faster or you can kill someone with it. For the same reason, encryption can be used to hide information about your crime. Both can be put to nefarious use. They are also similar because both are heavily used by others for entirely legitimate purposes.

The important detail is whether the operators of the encrypted communication company knew their products were being sold to criminals. The wording there is important. It's not enough that the equipment was being used by criminals; car companies know that criminals will use cars and ISPs know that people will send malicious packets. The business has to know that they're interacting with a criminal for them to share culpability. Again, the wording is important. If they went to strange steps not to know their customers because they knew they would be criminals, then they knew and the circling around doesn't help them. If they actually thought the products were being used by normal businesses which would have a reason to want secure communications, they aren't culpable. This is the reason the trials of these companies have to be based on specific evidence from each company. There have been many companies deliberately aiding criminals and this might be one of them, but that has to be proven and just saying "they provide useful stuff that criminals used" isn't enough.

Staff and students at Victoria University of Wellington learn the most important lesson of all: Keep your files backed up

doublelayer Silver badge

Re: No....not 3.....but 4......

You have to test and check. Verify that, when it says everything, it's actually everything. That catches you if you misconfigured it once or it didn't back up a file because it wasn't unavailable. Verify that, when you restore, it actually restores. That catches you against a corrupted file that broke something. Verify that, when you want to restore and you don't have stuff, you can. That catches you in the case that the software needed for restoring is unavailable or doesn't work, for example it requires a network connection, license key, or dependency which you didn't have before but now will. This is part of using proper software in a proper way.

What could possibly go wrong? Sublet your home broadband to strangers who totally won't commit crimes

doublelayer Silver badge

Re: Sounds “interesting”

I didn't have that because I was using my own equipment and not about to change it. Also, that's limited to customers of that ISP, which I didn't want to do. Basically, I anticipated that my neighbors could use it if their connection broke but mine didn't. Or someone else who was in the area and needed to connect. I also doubt there'd be that much risk of abuse since it would only be available relatively close to the access point, but I decided that if things did go wrong, they would go horribly wrong and I didn't like that idea. I mentioned to a neighbor that they could have the password if ever it became useful and gave up on the rest of the idea.

doublelayer Silver badge

Re: Sounds “interesting”

"I once knew someone who left their wifi completely open (was a few years ago) so anyone could access it. Know I don’t know why unless he planned on hacking everyone who connected...."

I once considered doing that basically as a service. I already had a guest network set up which couldn't see my normal network, had bandwidth limits, and could support automatic cutoffs if I wanted them. I was thinking that I had a reasonable connection rate, never got near a bandwidth where they'd reduce my speeds, and therefore wouldn't mind letting others in WiFi range use it if they needed to move some data. Then I considered what would happen if the police showed up for information on a user, which I wouldn't have, and decided that my technical knowledge meant the lack of logs proved I was erasing them. So I didn't. Still, my idea to do it was basically altruistic.

Trail of Bits security peeps emit tool to weaponize Python's insecure pickle files to hopefully now get everyone's attention

doublelayer Silver badge

Re: A fly in an ice cube in a microwave.

It usually comes down to laziness. There's probably harmless laziness, like using pickle to automatically serialize something because you don't want to write the thing which converts it to XML or JSON or something. Then there's harmful laziness, where people pickle code just because that makes it easier to import without giving people the actual code.

What people receiving such models should keep in mind is that they're getting binaries, and those binaries should be treated with the same mistrust as a more typical one. If you wouldn't run an executable from these people, maybe don't run their different-format executable just because it takes a few more steps to execute.

doublelayer Silver badge

Re: pwned by default

Not exactly. Just unpickling one can't run code. It can produce an object that is runnable. It should be treated like anything that can be executed, but not like something which automatically executes. It's one level below a document which can run data just by opening it.

doublelayer Silver badge

I'm not seeing it in the article. It runs in a sandbox, perhaps though I'm guessing, but the problem with malicious code is that it's run in the first place. It's not hard to put untrusted pickles in a sandbox, but if you don't or they can do whatever they want to do from in there, it hasn't fixed anything. The best way to handle this is to create a restricted language which can be serialized and runs only in an interpreter which has no OS access. It only does math and has no hooks elsewhere. That would work, but nobody would end up using it because people who so far don't have any problem unpickling random things and running them aren't going to go to extra effort for provable security, especially if it means not using one of the libraries they're used to.

doublelayer Silver badge

Re: pwned by default

This is correct. Pickles are just serialized objects. And that means basically any object. If you pickle a function, then it unpickles into runnable code. If you're not careful what you do with it, you could run it. For ML models, this can end up being the intent; you just load your preprocessor, run it, then run the model. If the attacker submits a preprocessor function which does other things, you don't know what it's going to do and should protect yourself or not run it at all. The same issue occurs everywhere where you can serialize something which can execute. Unless you're careful about using it later, you could end up executing something malicious.

What happens when your massive text-generating neural net starts spitting out people's phone numbers? If you're OpenAI, you create a filter

doublelayer Silver badge

Re: So much for "AI"

The problem is that a random number generator can produce valid or invalid numbers and, even if it produced a valid number, it has no idea what it is for. This has collected a bunch of real numbers and starts handing them out. Admittedly, it's not malicious about doing it, because it just hands out real numbers whenever they're tangentially connected, but it's not just random strings of digits which happen to be callable. If I run a random number generator to produce a number that looks like a credit card number, the chances are incredibly high that it will not work. If I collect real credit card numbers, the chances that at least one of them will work is significant. That is the important difference.

doublelayer Silver badge

Re: A little idea

I did read that. I didn't care. It needs to read real phone numbers to learn what a phone number's like? Two solutions. First, replace all phone numbers with a tag indicating it's a phone number, but without the content. If you're afraid that your code is so bad that it will read a single [phone_number] over and over and weight it too heavily, append a random number so it will see them as different. Second option: don't bother. Why does the AI need to know about phone numbers? It shouldn't be printing them. Phone numbers should only be printed if they go to people who are supposed to be contacted, which means they should be provided manually. Otherwise, it's actually doing a worse job at its task because it is including not just information which is irrelevant, but information which is actively wrong. I think those are reasonable options for handling the phone number problem.

doublelayer Silver badge

A little idea

In case OpenAI is listening, I have had a brainwave that might be a little handy. Your engineers are busy writing some software to scan output for phone numbers? Then the software will remove that output so people don't see it? I think it might work pretty well if you reversed this process and applied that filter to, you know, the input. So the big blob doesn't have phone numbers in it. That way, it would only generate numbers by randomly adding digits, which is much less likely to be a valid number and wouldn't be able to associate it with other information. In fact, while we're having brainwaves, maybe it's not so useful to give it the option to randomly spit out digits; we already have random number generators thank you, and they only give us numbers when asked.

Any chance OpenAI is looking for a chief sanity officer? I'd apply as long as they don't prevent me from working another job simultaneously. I think I might need a backup job when the data protection authorities come along.

Apple accused of unfairly banishing Watch keyboard app for the visually impaired from its software souk

doublelayer Silver badge

Re: Apple aren't one for banishing people only to pick them up later at a discount

Some of your points are characteristic of Apple, but others, while logical, aren't necessarily used.

"I'd guess that most countries have at least some legal impediments around driving the value of a potential acquisition into the ground; if nothing else, there's a definite overlap with the kind of predatory behaviour which anti-monopoly laws are meant to address."

It is not clear. Using a monopoly decision to do that is illegal. But there are many other methods which are not illegal. There is a certain amount of activity which gets dismissed as "bargaining well for a better price" and therefore accepted. In this particular case, the app team have a reasonably good case because Apple abused its monopoly position, but that would work as well if Apple didn't want to acquire them. I.E. it's only Apple's App Store monopoly which makes that happen rather than another law.

"The first is that if the acquisition has value to you, then it presumably has value to other people/companies. So if you do drive the price down, the odds are good that someone else will step in and buy it at a higher price."

Good point, although it doesn't apply much for this example. The app in question works on phones and watches, but there are lots of keyboards for phones. The IP in question is for their watch app, as their phone app is still permitted on the App Store. There are only three smartwatch platforms with enough functionality to make use of a keyboard with the multitouch and processing requirement of this keyboard. Apple is by far the largest. Samsung's platform is believed to be dying. So the only other purchaser is Google, whose platform is also not in great health. Given that Apple has the most users and that the app doesn't run on Android at this stage, they're by far the most likely to buy it.

"Another point is that by driving the value down, there's a risk that you'll lose the things which made the acquisition valuable. E.g. the target may sell off some of their assets to stay solvent, or lay off people with the domain knowledge needed to make the acquisition valuable."

Again, not a bad point but it doesn't apply in this case. The tech is a single application, although some of its functionality is open source released by another developer. The staff is two people. Not all that much they can do except try or give up.

"And if it becomes known that you're responsible for driving down the value, then people may choose to leave the target of their own accord rather than working for you."

I doubt that's a factor for most acquisitions. Apple can hire new developers to understand and develop a codebase. What they need most is the code that already works and the rights to any patents involved. It's a bigger problem when there are lots of people and the acquirer wants to keep that running, but for something IP-based like this, not as much.

Your final point about PR problems is good and applies.

'Business folk often don't understand what developers do...' Twilio boss on the chasm that holds companies back

doublelayer Silver badge

Re: Bottom line.

It's not humanities which are at the root of the problem, and I see no comments which suggest it is. Check most people who manage without understanding. They're often not humanities people. Nor is management necessarily a problem. They have a role to play which is important, and without them, there is more chaos. What is the problem is that management is more often able to exceed their role and cause issues because they have more power.

I posted on this topic a while ago. I noted there that it's not just engineering that needs this consultation. The discussion here has mostly been about engineering since A) most of us are engineering people (software included, please let's skip the linguistic discussion this time) and B) the article was about engineering. The general sentiment applies to any work where there is someone making the product and someone managing them. That product may be a technical one requiring hard science, or a legal one requiring lawyers (a lot of whom are humanities people), or an artistic one, or literally anything. The problems and suggestions apply equally well to them all.

doublelayer Silver badge

Re: Bottom line.

In general, developers know what is possible better than do the marketing and management sides. Not always, but when the product is technical, yes. For the same reason, if your product was carpentry, you might want to include the people who know whether something's feasible or easy to build when deciding what products to advertise or which contracts to use. If your product had legal consequences, you might want to have the lawyers review what you were planning before you publicize it. The expertise in actually building the thing needs to be consulted before making management decisions, with the management responsible for coordinating actions afterward.

Take a program someone suggested I write a while ago. They had seen that passwords were a problem, both simple-to-guess ones and reused ones. They thought it would be a great idea to write a program which could go through a network, check the passwords in use for strength, verify that they weren't reused on other services, etc. They thought this was a relatively easy thing to do and they could sell it to lots of places if we could just write it up quickly. Since I was interested in security and could write code, how would I like to be the lead [only] developer on the project? Fortunately, they hadn't already marketed this, because they found it a little disheartening when I described how salting and hashing meant it was basically impossible to do the first thing on any proper system, that salting and hashing were more important fixes than verification on any improper system, and that checking against other services would be at best a profound breach of privacy. If they had tried to promise things before, they would have been stuck with a promise to produce an impossible project.

UBports community delivers 'second-largest release of Ubuntu Touch ever'

doublelayer Silver badge

Re: Why not fork Android + make it a shell

Primarily, because they want a more controllable thing. If they fork Android, they can do a port without changing much, like the various semipopular custom distributions, which wouldn't make you happy since the Android UI hasn't been changed. That is the option which keeps most app compatibility, but you have to live with Android's UI.

Or they could do what you ask, keep some of Android, but do a bunch of work to make the UI different. Result: some Android apps wouldn't work because the UI's too different, so now they have to do extra work to emulate the old structure so things aren't broken. In the meantime, they have to work with other problems in Android which they might want to fix. For example, Android's handling of external storage devices which isn't the clearest or easiest to manage. People who are used to the old Android interface may not recognize this one either, meaning more complaints about how they don't like the UI choices made. Meanwhile, Google keeps developing new Android things and, if this fork is to stay up to date, the devs have to keep backporting the Google updates which are important. That's a full-time job for several developers even when few changes have been made; doing it with a very different fork is intensive.

For people willing to do some of this work, they're probably not that happy with half-measures. If you're going to change a lot of things in Android, why not give a full Linux-style interface a go? If you want to solve Android's storage thing, you could do a bunch of work on Android itself or just run more typical Linux userland software which already knows how to manage that. This also lets you develop things without having to worry about Google changing Android in such a way that it's hard to integrate again.

Alibaba Cloud quietly tests desktops-as-a-service

doublelayer Silver badge

Re: Two whole gigabytes?

The point is that, to use these, you already have to pay the electricity for most of the parts. All the peripherals including the displays, but also something capable of doing the computing work of establishing the connection and driving the peripherals. That's likely to be a full computer capable of working locally. If it is, it probably has specs superior to the lower tier of possible VMs just on its own. So you could pay for the electricity to run it yourself or you could pay for the electricity to run it and also for a remote VM which is no more powerful than it.

Google fails to neutralize lawsuit that complains Chrome's incognito mode isn't very private at all

doublelayer Silver badge

Re: when the win finally comes.....

Probably not. They'll likely try to buy off the people bringing the suit. If they succeed, that moves anything down a year at least. Let's assume either this one or another one wins against them. What will happen then is they will update the terms of service to include a bit of new legalese and continue as normal. Like what happened with GDPR. They're clearly collecting stuff and they're not in compliance, but the various data protection authorities aren't doing anything. Unless somebody actually brings out a big fine, they won't do anything. The fines from small or class-action lawsuits are not sufficient for the purpose because the lawsuits are always run by lawyers who want a payoff rather than to see change.

US govt indicted me because I make privacy tools, says crypto-chat app CEO accused of helping drug smugglers

doublelayer Silver badge

Re: So tomorrow Signal, Telegram?

"Does WhatsApp use strong encryption? By strong encryption I mean the US Government's definition of strong encryption. Not yours."

Yes.

"Is WhatsApp purposely designed with intent of evading detection of criminal activity by a US Law Enforcement Agency?"

No. Is Signal? No. Was this? Hard to tell, but they'd need to prove it, you know. You can't just say "Criminals use it, therefore it was designed for them." You actually have to prove a statement like that.