The Register Home Page

* Posts by doublelayer

11445 publicly visible posts • joined 22 Feb 2018

Myanmar’s new military government bans Facebook

doublelayer Silver badge

Somebody finally did it

And to think I was thinking military coups are always such a bad thing. At least someone has the courage to turn off the privacy invader for once.

In all seriousness, what we really should create is a reliable, single-standard, easy-to-use encrypted mesh communication app that also does centralized communication. Existing mesh apps are usually tricky to get working or have such a small footprint that nobody bothers to use them. Also, who has the foresight to install one before something happens making it useful? Imagine what it would be like if Signal had a mesh option. People would use it normally because it had a guaranteed message delivery system, and if access was cut, either to Signal's servers or generally, there would still be the ability to communicate locally. Especially if there was a method to send messages through a node with connectivity should that be available. Not that Signal is the only available app for this purpose. The technical challenges are substantial, but the benefits for a situation like this one could be similarly large.

Ever wanted to own a piece of the internet? Now you can: $1 for a whole gTLD... or $2.8m if you want a decent one

doublelayer Silver badge

+$24K per year

Before anyone considers bidding $1 on each of the ones available because why not, I looked at the ICANN pricing information. Annual maintenance fees for each GTLD are $24K US, not including prices for the infrastructure to run the thing. I can imagine why they're up for auction now.

Here's hoping that most of these are not purchased and returned. And that we can kill most of the TLDs set up in the past decade. Less junk that only gets used for malicious sites.

In Rust we trust: Shoring up Apache, ISRG ditches C, turns to wunderkind lang for new TLS crypto module

doublelayer Silver badge

Re: Is it just me ...

"Here's the thing, I'm still waiting to see some C or C++ code that is well written, and yet exhibits these flaws that are much lamented but not evidenced. Making life easier for people too lazy to do the work is not a winning move."

I'll grant you all of that. The problem, then, is that most of the core stuff, on which we rely, which is developed by many people who have experience, but evidently not enough, is not "well written". These are large projects, which have been tested to some extent, and they still do this wrong. Perhaps there are some people who can be absolutely trusted to never do that, but they don't seem to be writing this core code. We can't fix this problem by telling all the developers of libcrypt that they're rubbish and need retraining. They will ignore us.

The electricity analogy is continuing to make my point for me. I made a point about safe or unsafe plug sockets. You countered that a different part of the system can also be risky, changing the subject. Similarly, you have successfully pointed out that you can get vulnerabilities in languages other than C, which nobody argued against. Security requires good practice in coding, and it especially requires it in C because bad practice in C leads more often to security vulnerabilities whereas bad practice in other languages leads more often to crashes. You can still get security vulnerabilities in those languages. If we removed C tomorrow, we wouldn't solve security. However, that point is not in itself a cogent argument for keeping C. Such arguments exist, and they're convincing, but you're not making one. You are not defending C. You are not really even attacking anything else. You're just trying to change the subject to point out that I can't get perfection and hard work is required to approach it. Which is correct and beside the point.

doublelayer Silver badge

Re: Is it just me ...

I'm not an anti-C person. I use it with some frequency. Still, I don't see a problem with the core argument that C makes it easier to include certain types of vulnerabilities than other languages do, primarily buffer overflows and memory mismanagement. We see such vulnerabilities in code that's been tested and written by experienced people; this isn't just a problem of novices.

People who wish to continue using C for its various advantages should either agree with this and state a reason why it's not a problem this time, disagree with this and explain why manual memory management isn't the cause of buffer overflow vulnerabilities as we have seen, or agree with this but explain a reason why alternatives aren't going to fix the problem or aren't suitable for the situation. For example, I frequently use C because of its memory efficiency, which makes it suitable for systems with limited specifications, and most alternatives lack that efficiency, making them unsuitable. I have to consider a few newer alternatives to determine if they have fixed this problem. Unfortunately, I don't see much of this here. I see people blaming all problems on bad coders, which is far too simplistic. I see people asking for perfection, using the fact that there is no foolproof language to excuse any and all arguments. And I see perfect analogies to prove this point. Let's look at yours:

"My electricity supply is sufficient to kill me, it's not the fault of the installation if I defeat the safety interlocks."

No, it's not. Unless the safety system is built wrong and there's a live phase where you're about to touch. That would be the system's fault. But even if it's not the system's fault, we might decide to replace the system if we find that the system is unsafe, because it's far too easy to accidentally defeat the safety components. The plug sockets which attempt to ensure that a ground connection is available before the other pins make contact were put in place because they were safer than the previous sockets. The decision was made that the previous equipment was sufficiently likely to cause a preventable problem that it should be replaced with a safer alternative. The system wasn't at fault for acting as designed, but it wasn't safe enough to defeat its alternative.

Ring, Ring, why don't you give me a call? Amazon-owned doorbells aren’t answering after large-scale outage

doublelayer Silver badge

Connect to the internet, don't rely on it

This is the reason, as if we didn't know already, why electronics given a network connection should have offline local management. From the sound of it, users can't do anything with these doorbells, even if they're right next to them. An acceptable system would have a backup or primary communication option which didn't require the remote servers to work. Connecting something like this to the internet isn't always a bad thing (although this is Ring, so everything related to it is a bad thing), but relying on equipment which breaks when a system not under your control goes down is always a problem.

Going underground with Scaleway's Apple M1-as-a-Service: Mac Minis descend into Paris nuclear bunker

doublelayer Silver badge

Re: But... why?!?

Some of the users are probably cross-platform developers who don't need to buy a Mac when they can rent one. Possibly some others need to run Mac-specific software for some reason though I don't know what that is. Probably the largest group are developers who use Macs already, own Intel-powered ones, but want to ensure their stuff runs on ARM Macs even though they don't want to purchase one themselves yet. Those groups probably account for the majority of customers for that service.

Synology to enforce use of validated disks in enterprise NAS boxes. And guess what? Only its own disks exceed 4TB

doublelayer Silver badge

It doesn't matter what the price is now. It mostly matters

what the price will be a few years later. If one of the disks that you got for a market price dies three years from now, and you can still get disks for the market price, but the only functional ones have now become a lot more expensive, then you'll have to pay for that because you've locked yourself in. They could decide to increase the price if many people accept your argument and buy the NAS boxes because the disks are cheap today.

Now let's ask whether there's any technical reason that the disks have to be from the manufacturer. Is it because they need the disks at a certain speed? No, the speed of the disks matters to the user, not the system. Is it because they need a different connector? No, it's SATA. Is it that they'd have to replace subpar drives? No, those are user-supplied and don't come under warranty. Because certain features only work on some disks? No, the entire point of their equipment is that it does the management on dumb disks. Because they don't have enough space to store custom drivers? No, there are standards, they've had that code in previous devices, and they have plenty of processing and memory.

If their disks are wonderful disks, they can advertise and sell them. If the price comparison is as you state, they'd likely be successful. They could probably get a bunch of business from customers buying NAS boxes and disks together, since that means a single place for warranty claims and support requests. They don't need to lock down the system to get that business advantage. Nor do their customers need to be forced into the option since many will do it anyway and, if it is better quality, many others will follow.

Chrome 89 beta: Google presses on with 'advanced hardware interactions' that Mozilla, Apple see as harmful

doublelayer Silver badge

Re: Mozilla good, Apple bad

"The truth on the Cupertino end is that Apple doesn’t want to allow hardware interaction because it makes PWAs useful enough to act as a viable alternative to native apps from their App Store. Anyone who grew up with addictinggames and newgrounds knows what WASM+WebGL+WebUSB can do for those who want to build 2021’s equivalent of “free flash games” without the walled garden getting in the way."

The important part there is WebGL. Which Apple supports already as they were part of the initial development group. The second-most important part is WASM, because some of the games won't get enough performance from JS. Apple supports that already too. The only thing they don't support is the USB API. And you can only attach USB devices to the computers which have USB ports, which are also the ones which don't require apps to go through the App Store. IOS devices do have the store requirement, but they don't really have much in the way of USB support anyway. So perhaps your accusation is a bit premature.

Meanwhile, there are APIs to get keyboard, mouse, and other peripheral input. They don't need access to USB devices to do that. The quote in the article about implementing custom logic for old game controllers is pathetic, because nobody is going to include a hundred drivers for game controllers, all written in JavaScript, in a web game. That API's in here so Google can do everything from a web app, and while I don't think they have a nefarious purpose here--Chrome already has access to system-level USB if it wants--they haven't put a single thought into security vulnerabilities. Which there are, a lot of them. USB is used not only for peripherals but for some system components as well, more so on laptops. The attack surface is incredible.

Momentum builds behind campaign to fire Nominet CEO, board – though success still far from certain

doublelayer Silver badge

Re: Fork it!

You can do that if you think the UK government will do a better job than a group of people replacing current leadership. I'm guessing the people trying to change the people but keep the structure either believe the government won't help resolve these problems in a timely fashion or would make things worse.

Google QUIC-ly left privacy behind in its quest for a speedier internet, boffins find

doublelayer Silver badge

Re: Numbers

"I would argue that you should never use percentages to indicate an augmentation or reduction of a number which is itself a percentage. If you say "50% higher", it can mean from 2% to 3% or from 66% to 99%."

That's a problem with percentages in any use case. 50% could also be the difference between two units and three units or 30000 and 45000. It's a tool for multiplicative comparison, whether it's a rate or an amount, you can use it badly. And yes, there's an XKCD for that too. If you don't like that lack of clarity, don't use percentages for comparison.

doublelayer Silver badge

Re: Questionable Research?

Google is banned in China. QUIC is not banned in China. QUIC is an open standard, which can be run by anyone and impacts others. People will research new technologies like that. The research doesn't claim that Google did this deliberately, and they probably didn't, but still points out a vulnerability. It doesn't seem in any way an attack on Google.

doublelayer Silver badge

Re: Numbers

"Some people would say that 57% is only 24% higher than 33%, because they would want to use [...] addition and subtraction instead of multiplication."

They are allowed to do that if they want, but only if they use the right words. Those would be "57% is only 24 percentage points higher than 33%". If you say X is Y% higher/lower/of Z, it means multiplication and it always will. If you don't do that, you get this XKCD.

Xiaomi proof that we're a military company, says Chinese tech slinger as it sues US over ban

doublelayer Silver badge

Re: Investors

It's a pretty normal investor tactic. They take risks in the hopes that the possible but mostly unprecedented thing doesn't happen and they reap their rewards. For example, they invest in the newly public Saudi-Aramco even though it's majority owned by the Saudi government and keeps not appearing on international stock exchanges; they hope that Saudi Arabia won't decide to ignore them later. Or they let Facebook and similar companies change the way voting works so that their founders have total control over the board even when they don't own a majority of the shares. They take the risks that the companies might do something dangerous, like incurring a really big fine by breaking the law while not allowing investors to do anything to stop them. Investors take risks. It's how they work. Some are willing to take very large risks.

'It's dead, Jim': Torvalds marks Intel Itanium processors as orphaned in Linux kernel

doublelayer Silver badge

"The core processing on x86 is still 32-bit which is why everyone in the world didn't have to recode their app in order to work at all on x86-64."

That's not really how I'd phrase it. AMD64 can run 32-bit X86 code natively, but that doesn't make it 32-bit. If you compile for AMD64, you use 64-bit capable instructions, which this has. It's not just a 32-bit processor with larger addressing. So I'm not sure what you're trying to say with the part I quoted. I have two ideas:

1. "AMD64 is 32-bit even when you compile to its ISA natively": That's incorrect, but I don't think that's what you're saying.

2. "It would be better if the transition to 64-bit required everyone to recompile for it so we got the benefits faster": I get the idea, but I don't know that it's been a major problem. We've had 64-bit desktops and laptops for over a decade now, and you can pretty much guarantee that most users today have a 64-bit OS and most of the performance-sensitive programs they run on it are also 64-bit. The occasional old or small program still runs under X86, but that's only a problem if it will actually benefit the user by using the faster instructions or more memory. Quite frequently, such programs don't need to be that fast.

For that matter, we also have ARM64, which is like AMD64 in that it can coexist with previous versions of the ISA. Still, most mobile devices that are powerful enough (phones, tablets, not the SOC running the embedded devices), are using a 64-bit OS and apps compiled natively to it. ARM is even planning to drop 32-bit support in their next range of high-end cores because so many people never use the 32-bit capabilities.

Meanwhile, the ability to run stuff without having to recompile it means people will adopt 64-bit hardware faster. When the software supporting it comes out later, they already have the ability to run it, and having the hardware themselves, they can also compile and test their stuff to run under it as well. The overlay method makes some sense given those benefits.

Very little helps: Tesco serves up 3-for-1 borkage special to self-scanning Tesco shoppers

doublelayer Silver badge

On the CE devices I have used, they had a button, either hardware or on-screen, which would close the active window, or sometimes it would close the entire application. Never could be sure until you pushed it. If that button didn't eventually close the application which was rare, there was always an exit option in the menu.

I once had the opportunity to use a Windows CE device with a full keyboard and reasonably-sized screen. It was surprisingly usable and like desktop Windows, even though it had only about 128 MB of memory for the OS and all user files. Then again, I didn't try anything all that complex. Still, I distinctly remember having a command prompt, C compiler, and Python interpreter, all of which ran pretty well such that I could write code on the mobile device if I needed to. I'd like to see a modern mobile OS let me do that. Then again, I doubt many people bothered connecting peripherals to turn a Windows CE device into a desk-bound machine.

Google allows 15 more nations to offer gambling in the Play store

doublelayer Silver badge

Re: "such apps must be free"

I don't think it is a law. I think it's a rule they have set so that it's clear they didn't get paid to make the rule change. That way, if some app is found to be violating gambling laws, there won't be people claiming that Google must have turned a blind eye to keep up a commission. Unless recent cases succeed in reducing Google and Apple's level of control over their stores, they are allowed to set some rules for any reason or no reason at all.

Samsung Galaxy S21: Lots of little downgrades, but this phone is more than the sum of its parts

doublelayer Silver badge

Re: Well worth it?

I don't mean to accuse you of doing it deliberately, but there are those who do it a lot to distract from the actual point, and it still doesn't matter. The difference per week is £3.65 (£4.93 vs £1.76) or, in other words, a factor of 3.86. That difference, over the life of the product, is £570. Either you are willing to pay £570 more for the improvements or you are not. Whether you describe that as a single £570 payment, £3.65 per week, £0.02 per hour, or any other version doesn't change what the number is.

With that in mind, the most honest way to describe the difference in my opinion is how the cost will be paid. If the person actually pays a bill each week, that might make sense since the person could consider the weekly payments in their budget. I've never seen that. I've only seen per-month contracts, usually with subsidized prices or sometimes with overinflated prices when the open market has discounted the device. I think most purchasers considering this debate are going to purchase outright. In that case, the difference is £570, clear and simple. Dividing the price per week only helps if the consumer has the choice to pay it for a few weeks, decide against it, and pay a lower amount for a different product. They can't, so in my view, the division holds no value.

doublelayer Silver badge

Re: Well worth it?

"If we're talking about phones that people will keep for 3 years, then the difference in price is a few quid a week..."

Doesn't matter. Unless one phone is expected to die a lot faster than the other one, the price difference is still ~4x, whether you choose to view it as per week, per year, or up front cost. So the question is whether one phone is really four times better. Which it might be, although I don't know why. Dividing prices by large denominators so they look small is a frequent tactic, but it doesn't change anything about the total cost of the device.

Facebook finally finds something it thinks is truly objectionable and needs to be taken offline: Apple

doublelayer Silver badge

Re: There is no free lunch

Yes, there is a difference. Facebook doesn't limit its tracking to things I do on their platform. They will track me and everyone else who doesn't have an account as we use other sites. They will buy up companies we may have used (who here used WhatsApp pre-facebook and doesn't anymore?) to get more data. They'll excavate others' data and collate it about me. They will use that data to mess with my friends who have accounts. And they will try to weaken a technical privacy measure that could help me from them and others for their own bottom line. I don't have to have an account for all of that to be done to me, and Facebook is the culprit. That's what gives me the right to complain about Facebook. I never agreed to any of their activities and they came after me anyway.

Decade-old bug in Linux world's sudo can be abused by any logged-in user to gain root privileges

doublelayer Silver badge

Re: Bounds checking is necessary but has a performance hit

Exactly. That's a benefit. If you get a clear error case, you A) don't have a security hole and B) it tells you exactly what the problem is and you can now fix it. It won't automatically fix it for you so it works, but it prevents it from doing unintended or intended damage and makes it more obvious. It also makes it a lot easier to find the issue by fuzzing, because there are some cases that won't make it segfault but every out of bounds would trigger an exception.

doublelayer Silver badge

Re: Only sissies use sudo

Sudo has two uses. It provides granular privilege control on a shared system, and it enforces a password check for users running privileged commands no matter what on. Those are useful, but if you don't care about either, go ahead and remove it.

"If you're only logging in to do maintenence tasks every so often, sudo is useless. And as we see now, one extra step/attack vector."

If you're only logging in for maintenance, and nobody else logs in, then the attack can't work. It only works if you have a shell already. And how do you want to log in to run root commands? Log in directly as root? Exposing the root account to external login attacks, which is usually disabled? With a single password for the whole team, which can be leaked or changed? There has to be some way to get root. Why is your one so much better?

"For users, "sudo this sudo that", people are so used to typing sudo the mistakes its supposed to protect from are void."

Sudo cannot and does not protect you from knowing what you're doing. If someone tells you to run a command and you do it without knowing what it's for, the problem is you. Whether you used sudo or su to get to root, or made a script that automatically has root, or any other mechanism, the problem is running the command.

"Commands to use online are often written with sudo in front of them, copy paste."

Because they need root access and that's how they run. Again, it's the fault of the user who doesn't check what they're about to do. Sudo is not a sanity checker for commands. It's a privilege management tool.

"Not many people actually tie sudo to an authenticated/centralised back end, and almost all uses of sudo allows any root commands to be run, not tied to specific tasks you want to give a non admin user."

So? It lets you give people root privilege in a restricted or unrestricted manner. You want to have restrictions, you can. Take one of my personal servers. I have full sudo access from a management account. I don't have any users with restricted access. I don't now, at least. I have allowed friends to have accounts for various purposes, and sometimes I have given them access to a few commands. They're not getting full root access though. The easy way to do that is Sudo.

The killing of CentOS Linux: 'The CentOS board doesn't get to decide what Red Hat engineering teams do'

doublelayer Silver badge

Re: They’re now inserting ads in the middle of the comment stream

BTW did I miss the coverage of the Sonicwall hack on here?

The one in this week's security roundup article or This one from October? They could have made a full article about this week's, but they do have a section.

We regret to inform you the professor teaching your online course is already dead

doublelayer Silver badge

Re: Kinda similar happened to me

When the same happened to me, the professor dying during the summer apparently without warning, they just cancelled the class. We all had to quickly find a replacement, and given that registrations were typically done four months earlier, choice was somewhat reduced. I don't think they ever offered that class again either.

doublelayer Silver badge

Re: Maybe I was too literal...

A good idea in principle, but often a professor giving lectures answers questions from the students, assigns homework, refers to specific textbooks suggested for the class, and writes other course materials. Taking the lectures out of context from that may be less useful than it sounds, because the successful outcomes may have a lot to do with those other aspects. It might make sense to take certain classes and teach them identically in many schools, but that can make quality better or worse depending on who is chosen to do that and it doesn't help with the individual responses to questions. That aspect can at times be very important. All the professors I respect the most were good at lecturing but also good at relating to their students in discussions.

North Korea infected infosec bods with backdoors via dodgy blog pages, Visual Studio files – Google

doublelayer Silver badge

Re: So much for the experts

There are computers at the universities, and there is a lot of competition to get the few places in the elite. If a student wishes to do well and not end up as a construction worker in the military, they have to be exceptional at something the state cares about. Those things include a variety of natural sciences for manufacturing innovation or weapons development, computer science (now, it took a while), and things that you can compete about or exhibit for external propaganda. People don't generally get to apply for roles in the government that require social sciences (E.G. diplomacy or administration) unless their family is already there, so few need to study things relevant to that.

I'm guessing you have a certain amount of computer skills because you posted here. If, during your youth, you were faced with the choices become really good at that by spending no time on anything else, become very good at nuclear physics, become a really good musician, work in manual labor at 600-700 grams of rice (if you live in the nice places, otherwise it's the same amount of a grain with less caloric content), or die, which would you have done?

Apple slapped with €60m lawsuit from Italian consumer rights org for slowing down CPUs in old iPhones

doublelayer Silver badge

Re: Enough all ready...

"Whilst what they did was very badly explained when it was introduced, the "throttling" actually allowed people to continue to use their phones for longer than they could have otherwise (i.e., when they battery was so badly worn that heavy use of the phone would cause it it reboot)."

For context, I have one of the affected models. The following are true:

1. The first unexpected reboot I know about occurred a year or so after purchase. It's not possible for me to check if any occurred beforehand.

2. It applied the performance decrease then, which I normally don't notice but sometimes it's clear.

3. I never turned off the slowing feature. I figured I could live with the performance decrease.

4. It still shuts down unexpectedly, and actually somewhat frequently. Battery level measurement is unreliable and sometimes it will shut down when the battery supposedly has more than half of its life remaining. It will then not turn on again until connected to mains power, and it will report a very low battery level then.

5. Apple-authorized service providers tell me that they can't replace my battery yet because the battery health percentage needs to be at 79% or lower. It has been stuck at 81% for months.

6. I have no method to measure what the faulty battery has done to the performance or the reliability because the only metric is a never-changing number.

Now you are probably right that, had I disabled the throttling, I'd have to deal with even more crashes and worse battery life. That, in my mind, is no excuse for the problems caused by their failure to consider how much power they need a battery to give. I am out of warranty, so I can't require them to fix the problem, but I do view it as the fault of their design, and it does cause problems. Fortunately, I don't rely on my phone very much, so it crashing and requiring a wall connection is simply an annoyance. For others, it may be much worse.

doublelayer Silver badge

Re: Enough all ready...

The batteries start to fail to deliver the power needed by the hardware after a year or so of usage. Other electronics ... don't do that. They don't do that because the engineers looked at their power usage when choosing the battery they would use, planning to have a battery that would last for an actual expected usage amount rather than the length of the warranty. I choose to believe that it was a mistake on Apple's part. They just didn't think too hard about the battery and oops it's too late. Still, it's possible that some or all of the steps taken were intentional, because a phone slowing down or suddenly dying (which it still does after slowing down) makes people think their device has a problem requiring replacement.

A new take on programming trends: You know what's not a bunch of JS? Devs learning Python and Java ahead of JavaScript

doublelayer Silver badge

Re: I'm confused

They think people should be able to do that with HTML. Because there's not that much risk with HTML. Sure, you could copy a link to something malicious, but it wouldn't serve any purpose and you would change it. You can't do that with the sites which construct themselves from JS, because A) you don't understand what most of that is doing and B) almost certainly the new page wouldn't work, especially if the JS contacts some other system. Their comments are limited to HtML.

Google, Microsoft pitch in some spare change to keep Mozilla's Web Docs online bible alive

doublelayer Silver badge

Re: Interesting

I think it's probably good. Mozilla can't take this money and spend it on something else. That means we don't have to worry about Mozilla failing to support the documentation and any company which doesn't trust Mozilla can still donate specifically to support the docs.

Given what we know about their finances, the claims of problems are not always proven true. Last time they claimed a budget problem, they killed the security team then got the same Google funding they already had, leading some to wonder if they just wanted to kill the security team and perhaps have more money for something less important. At some point, it's useful to decide how you want your donation spent if you're unsure you can trust them to allocate it. Meanwhile, Mozilla still maintains ownership and control; the extra organization merely maintains it with a chunk of cash, but can't override Mozilla's instructions on the docs let alone anything else.

Showering malware-laced laptops on UK schools is the wrong way to teach them about cybersecurity

doublelayer Silver badge

Re: Nothing happens by chance in a plandemic

"I expect that at the event 201 planning sessions they realised a need for deniable covert monitoring of targeted households. Pre-installed “Russian” spyware (yet again) kind of gives the game away, they probably paid extra for it."

I was at the planning meeting and I can assure you that's not what happened. Why on Earth would we at the Secret Control of Everything Ha Ha Ha Agency (SCEHHHA) use known malware to spy on people? We're smart enough to know that's going to get spotted. We used spyware we had written ourselves, which got installed onto a secret chip inside each laptop. Then, we passed the infected machines off to the standard technical division and they flubbed it by not checking their system image. Now people will be going through those machines with a fine-toothed comb looking for other malware and someone will eventually find our stuff. We're foiled again. Of course, given that we do have enough control to do that, I have to wonder why we bothered so hard to infect some laptops going to the houses of poor children. After all, we also have SCEHHHA spying software on all ISP-required hardware released since 2012 and all modern electricity suppliers' equipment, so you'd think that would be enough. But you know what happens when someone at the top comes in and tells us we have a real reason to secretly track a subset of the population and we should design a new custom tracker, so we did this one too.

doublelayer Silver badge

Re: RPi 400

I'm guessing they wanted to ensure hardware availability which a Pi 400 can't do. That includes a camera so they can be in video classes and be seen, for that matter a microphone which is actually important and the Pi 400 also doesn't have, a battery so the students don't have to be tethered somewhere in their house, and a screen so, if there are two students and one television, they can still work. That all seems reasonable to me. The 400 is a nice device in some respects, but laptops generally offer more.

doublelayer Silver badge

Re: Money making middle men

I partly disagree there. Windows is bloated, but nearly every OS I could expect schoolchildren to use isn't going to like 32GB storage. A Linux with a GUI can run in that, but the internal disk will end up storing school files, programs for videoconference classrooms, offline copies of stuff so the network can go down, and now that's getting full too. Chrome OS could fit in that, but I don't like making it easier for Google to lock in young people to their cloudy apps, so I'd prefer not to see it.

doublelayer Silver badge

Re: Damned if they do, damned if they don't

Doing it sort of right could be done in about an hour. Here, give me one of those laptops from the latest production run. I'm going to boot it up and run a simple check. Does it start, log in, have the software we wanted, and pass a Defender scan? It doesn't. You can't send these out. Any further delay is the fault of getting it wrong in the first place. That does take extra time and money, but preventing the problem would have been a lot faster.

Man arrested after UK school finds wiped hard drives on devices connected to network

doublelayer Silver badge

Also, do they want to tell us what was done and why? So far, all I know is that hard drives got wiped. I'm guessing that was to destroy the evidence from something else, but I don't know. Do they not know either? Or do they have an idea what happened? Or did this guy just like erasing drives and ran out of machines so stopped by? for now, I see little sophistication in the attack or the reporting.

Must 'completely free' mean 'hard to install'? Newbie gripe sparks some soul-searching among Debian community

doublelayer Silver badge

Re: Debian is for left-handers

"An operating system is a way of making computers work. There aren't different kinds of OS people except by preference."

Entirely correct. You have preferences including the following:

1. I want it to boot up with everything working and I'm willing to accept anything for that to happen.

2. I want to control everything and never have the OS do something without telling me.

3. I want to have the OS handle all situations without requiring technical knowledge, even error cases.

4. I want all the code that runs to be code that I can and have the right to modify.

5. I want to take some of the parts and swap them out.

6. I want there to be a convenient support line for any problems.

7. I want it to run a piece of software which only works on <insert OS name here>.

When preferences conflict or are just difficult, different options come up. One OS can't easily do all of those things, especially when the additional preference "It shouldn't cost more than the computer itself" is added in. So developers decide which preferences they care about and make an OS for those. People with the same preferences use it. People with different preferences find an OS that works with those.

doublelayer Silver badge

I can't speak for the Debian devs, but I'd be satisfied to keep it as a base. I don't win by wanting everyone to use Debian alone. I might win by being the basic underpinning of all the popular versions because they contribute upstream, I maintain a base which can easily improve all the downstream builds, and I don't have to make the twenty different versions that people like. If Debian is to be a component in many other versions, why is that a problem? Its users can still use it alone if they want.

doublelayer Silver badge

Re: Two ways of looking at things.

I agree. There is a cultural problem in Linux that assumes everyone knows how to do various things, and that's bad. Unfortunately, I see similar things in Windows too; how many Microsoft knowledge base articles tell people how to edit registry keys when we all know the nontechnical should probably never go in there? Nevertheless, the solution to this is to tell conceited people that Mint is no less powerful than Debian is, not to demand that Debian change it's structure because there are some who find it difficult.

doublelayer Silver badge

Re: I love the way developers...

"As the world changes around them they seem intent to carry on fighting a battle that was won years ago. Some of them seem blind to the fact that real battles now and in the near future will be fought in hardware and the casualties triaged and treated in firmware."

That's the battle they're fighting, at least as far as wanting open firmware is concerned. If your concerns are that an OS on a chip will come along to lock us in, Debian's battles are helping you twice over. First, if they have any success at convincing companies to make more firmware open, then we won't be able to be locked in because we can edit the firmware as we do with software. Second, even if they don't have that effect (and they probably don't if we're realistic), their focus on open means we'd still have an alternative which could be run on something else.

Some people don't care about the interest in having access and rights to edit all the running code. I get that; it's a tricky and complicated thing that involves a lot of minutiae. If you just didn't care and wanted an OS that didn't make anything not work just because the licenses don't line up, I'd understand and I'd tell you to look elsewhere. Instead, you seem to argue a point directly in line with Debian's viewpoint, then turn right around and lambast them for their view.

doublelayer Silver badge

Re: I love the way developers...

"Any software that is not both easily usable and open sourced by this point in time is either an evolutionary dead end or a niche product."

A perfect quote to sum up why I don't understand your point. Factually, it's wrong. Lots of things lack one or the other of those yet are commonly used and are highly developed. The original problem, firmware for peripherals, is often closed-source. Sometimes, it's not convenient or good for usability (and by now I have no clue what you think that means) either. Yet GPUs, often a substantial perpetrator of that, are used all the time by all sorts of people and don't appear to be dying out.

Furthermore, I don't understand why you denounce software that isn't open source while simultaneously decrying Debian's usability problem, which comes from only using open source code. Surely, if anything not open is an evolutionary dead end, then the open-only Debian should be just fine from that standpoint, and anything usability-related would be the fault of Debian-written code, rather than a failure to include dying binaries from others. If your point is just "I don't like Debian", you could have gotten there a lot faster. If you have a different point, I don't know what it is but it likely doesn't make sense.

doublelayer Silver badge

Re: Two ways of looking at things.

Why is it so unreasonable for software developers to develop their software to have the features they value? When they're giving the software away for free and you don't have to use it? It's as if you expect them to change their plans because you don't like them, when they don't work for you or sell stuff to you.

Several years ago, I wrote a basic audio editor because I wanted one that could run on a device with very restrictive specs. I then published the code, which was basic but a few people at least looked at it. Had they come back and informed me that it crashed if they used some of the features, I would have fixed it. Had they suggested a different feature that would make editing audio easier, I'd have considered adding it, but no guarantees. And had they told me to make it a video editor instead, I'd have ignored them. Why? Because I needed an audio editor and I have no reason to write a video editor from scratch just because someone wants one. A video editor would have been better than an audio editor from the number-of-features standpoint. However, it would have been tricky to write given the limits I put on the system, it would have required a bunch of visual interface elements that would take a while to add to the software, and perhaps most importantly, it wouldn't do anything for me because I didn't have any video to edit. So I didn't write one.

The same applies to the Debian developers. They want an operating system for their use case, and they want it to include only code they can legally edit themselves. They made this, and it turns out there are people who want that and people who want something else. Because there are people who want something else, somehow it's now Debian's responsibility to make that too? Or perhaps to discard their original desired product and only make the thing that others want but they don't? Again, why?

doublelayer Silver badge

Re: I love the way developers...

I didn't counter that it allows you to use a computer, because that's sort of the definition of software. I countered that convenience is not the "entire point". Or rather, there may be points that are considered by the developers or the core set of users to be more important than convenience. It's common for software to remove some convenience elements in favor of security, or extra functionality, or extra modularity, or execution speed, or in this case openness of code. It is your choice whether you care about these things. By incorrectly saying that convenience is the entire point and alleging, again incorrectly, that inconvenience is being "shove[d] down your throat", you are misunderstanding why Debian exists, who sets the goals (hint, not you), why people care about openness of code, and many other aspects of the discussion. Your rebuttal does seem to acknowledge these to some extent, but I can only wonder why you missed them so much in the original post.

doublelayer Silver badge

Re: Yes. Hit meet nail head

"Use the Mrs Miggins test. Get the office cleaner and the tea lady to have a go at installing and using. If they can't do it, you've got nothing more than a nerds special product and NOT a serious, polished operating system"

Not a bad test, but try getting someone to install Windows from scratch and you'll find it's harder than you thought. Not for us, but for the general public, when the installer asks whether it should automatically partition and format the disk, with the warning about erasure, they usually come to the technical person and say "Please finish this installation and bring it back". Also, it depends what tasks you expect the nontechnical to be able to do once the computer's up and running. Click on the word processor and type in a document? They will be able to do that on Linux or Windows. Connect to a network folder? Sorry, but you'll find a bunch of nontechnical people don't know how to do that on Windows either. Configure a printer? You're now rolling the dice on whether the printer is a standard kind which will just work on everything or whether you'll end up in driver limbo, and that happens on both OSes albeit with different sets of working printers. Comparing a personal Linux machine to a work-administered Windows machine may make it seem like users know how to make Windows do lots of complex stuff, but usually it's IT which did that and they only know how to use, not enable and configure, that stuff.

doublelayer Silver badge

Re: My personal rant about all Linux variants

Nor do you have to. For a lot of users, there is a Linux variant that includes the stuff they want and is easy to use. That just isn't the same distro as Debian. If you want to use a system that has a lot of stuff included, there are options. That's not saying everything will be easy on that, because if you want to do more technical things,, you'll sometimes have to learn some technical details, but most of the software you talk about will run without fiddling. Expecting every distribution of Linux to do that though is just not going to happen.

Tesla axes software engineer for allegedly pilfering secret Python scripts after just three days on the job

doublelayer Silver badge

Re: How long is a man-year?

We don't know the length of those files. If they're very long, and people have been writing them for years, the time could add up. Also, I'm guessing they have just included all hours worked by the people on the development team who do that, so it's rough. Still,, without knowing the complexity it's hard to know if that's realistic or not.

doublelayer Silver badge

Re: Office 365

I'm not sure whether that's a problem. You could probably do the same by putting those files in your OneDrive. You still need to log in to read them. Meanwhile, I don't think Office365 has any problem with you sending those files, just receiving them. The bounce was likely from whatever was set to receive the files.

doublelayer Silver badge

Re: thief

"My point was that the technical details of how he could get the files do not matter. The legal "details" is a different thing."

And your point is wrong. The technical details are important to Tesla as they figure out how it happened, how damaging it was, and how they're going to prevent it happening again.

"All these commentards trying to justify the theft because he could install Dropbox are wrong, IMO."

It's mostly wrong because nobody's saying technical details absolve him of guilt if reports are true. That would look like "Tesla deserved this and he should go free". Nobody said that. Even the one person trying to argue that maybe he shouldn't be arrested if he did it isn't arguing that way, and I'm not agreeing with them. No justification of the crime is happening, and certainly not about technical details. Meanwhile, this is a technical site, so we care a bit about those details.

"And Tesla's security is not inept, they caught the guy spot on."

Security has lots of goals. "Identify and catch the guy after the crime" is one of them, but another and larger one is "Prevent crimes from happening". They didn't do that, or at least not fast enough to prevent thousands of files being leaked. That doesn't justify anything, but they might want to revisit some of their practices so that can't happen again.

doublelayer Silver badge

Re: Python script as a.Service

"if he stole scripts in bash and Python wouldnt he have to steal the toolchain configs and server setup and pipeline info?"

Probably not, but if those were there, they could be in the collection too. There isn't a lot of toolchain configuration for Python that isn't obvious, although it depends on what structure they decided on. The server may have complex logic, but for all we know it just takes in an item to test and passes it on to the Python backend which does all the work.

Google's Alphabet sticks a pin in its Loon internet broadband service

doublelayer Silver badge

Re: Starlink

Good point, as the signal still has to come down to Earth somewhere. If the downlink facility isn't as close to the markets, then it's likely that just being closer to the market than the downlink is will be faster. Given that a lot of high-frequency trading equipment is already right next to the market servers, does Starlink plan on buying rooftop space in the same building? That cannot be cheap.

Nothing new since the microwave: Let's get those home tech inventors cooking

doublelayer Silver badge

Re: Oh dear!

That would make a lot of sense, but can't be guaranteed. A friend of mine had a key's battery die, which made the car stop recognizing it. They had a backup but requested my assistance to change the battery as I was already there and there was no battery compartment on the key. After prying open the key to get at the battery and replacing it, the key was now recognized by the car as existing, but not as being a valid key. The car's owner was told to see if the internet or manufacturer could help with it. I'm betting that key is still sitting in a cupboard in an unusable state. I don't want to think about what's going to happen when the backup's battery dies.

BOFH: Are you a druid? Legally, you have to tell me if you're a druid

doublelayer Silver badge

Re: Plagiarism

If we're being technical, that line was "I threw a 5 and a 2.", with no "which meant" on the end. In fact, I had to just rewatch that scene for accuracy's sake of course, and none of the rolls previously mentioned were a 3 and a 4. I'm sure this information was very useful to you. I haven't wasted my time, right?