The Register Home Page

* Posts by doublelayer

11394 publicly visible posts • joined 22 Feb 2018

Four or so things we found interesting about Qualcomm's Snapdragon 888, its latest 5G chip for high-end Androids

doublelayer Silver badge

Re: But is it practical?

I'm not sure that's true. I did a search on a phone database. Of the 60 known devices with the 865 or 865+, 53 (all but 7) have dual SIM, 16 have 3.5 mm jacks, a different 16 have micro SD card slots, and 3 have all of those features. I don't think it's the SOC that means you don't often see all those features together.

doublelayer Silver badge

Re: How far behind Apple are they now?

Existing Windows on ARM systems have primarily been using Qualcomm's CPUs already. While those have mostly been chips that use more power than the 888, I can't see a reason Microsoft would prevent an OEM trying to use it. It's possible that there are other reasons why chips at that level don't get used for Windows, but I doubt it's because MS cares too much.

doublelayer Silver badge

Re: Looks a bit crap now we've seen Apple's effort

It should still be remembered that the M1 has a few advantages that this does not. The M1 gets to go in laptops, where it can get more power for longer from the larger battery, while this will go into phones, where the batteries are anemic or ill-designed. The same difference also means that the M1 has an easier way to handle heat production; even in the fanless MacBook Air, the large metal plate under it can work well enough as a heat sink. Phones won't get that. For those reasons, this chip has to spend more time on heat management and providing low-power cores so they can get used for the comparatively easy tasks that phones get asked to do. For the same reason, the A14 cores in the iPhone are clocked lower (and there are half as many fast ones) as the M1.

A comparison may help. For Pi fans, Qualcomm's chip is a lot like the SOC in the Raspberry Pi 4, which overheats often without assistance, whereas the M1 is like the higher speed version in the Pi 400, which gets a large heat dissipation plate. The Pi foundation could afford to clock that up (and so can a user) while the original Pi kept automatically clocking down, even though the base rate was lower.

.org owner Internet Society puts its money where its mouth is with additional IETF funding

doublelayer Silver badge

Compared to the previous model, where they had to ask for money every year, having an announced six-year funding plan is closer to self-sufficiency. Unless ISOC cancels the funding plan they announced, the IETF doesn't have to return to them and possibly get less money than they need because they angered the ISOC board. If the ISOC does cancel their announced funding plan, it will produce a large backlash among members and the general public. As we saw last time, ISOC views that concerted backlash as completely meaningless and will cheerfully ignore it, but still... there must be hope somewhere, right? Please?

Infused with the spirit of Christmas, TalkTalk decides to extend cut-off deadline for Business email domain

doublelayer Silver badge

Re: Web site broken?

On doing a nslookup, it does have an A-record pointing to an IP address in addition to the MX and TXT records. NMapping that to see whether there's anything running on it which responds to pings is left to the reader.

talktalkbusiness.net internet address = 62.24.248.135

Amazon’s cloudy Macs cost $25.99 a day. 77 days of usage would buy you your own Mac

doublelayer Silver badge

Re: Always do the sums

That's important when calculating costs for cloud services which can actually be spun up and shut down in an hour, but it isn't the same for these Macs. AWS requires that you use the Mac for a minimum of 24 hours. That means that, if you need it for an hour per day and five days per week, you have to pay for almost 120 hours (technically, you could cut off the morning of Monday and the afternoon of Friday if you can nicely schedule which hour you need it each day. So approximately a hundred hours rental for the Mac versus five for a different VM, which leads to a very different cost calculation.

'We've heard the feedback...' Microsoft 365 axes per-user productivity monitoring after privacy backlash

doublelayer Silver badge

Re: I don't understand

I bet the process went like this:

Manager 1: I wonder whether we can get organizations using extra tools if we give them metrics and make it look like they're beneficial.

Manager 2: Yes, but it needs a catchy name to indicate that it's not a sales push. And maybe, if we can think of any, some actual useful features.

Manager 1: Well, the optimal use of our services should help with productivity. While paying us for extra services doesn't constitute optimal, the benefits to the customers, if any, are productivity related.

Manager 2: Productivity score. I like it. But what happens if someone adopts a tool, our score says they get extra points, but it doesn't roll out to anyone else. They might figure that out and cancel the thing that only one person uses.

Manager 1: Simple. We'll score all the users individually and show how other people can gain in "productivity". People who want the total productivity score will be able to see who's not using a feature yet and get them to do so.

[months later]

Manager 1: Why are all these privacy things coming up? This isn't really a privacy issue. It's just for sales.

Manager 2: I don't know. I mean you could theoretically extract information about communication frequency, but nothing about communication quality let alone noncommunication productivity. Using this to grade workers would be ridiculously idiotic.

Engineer: You are assigning sortable scores to individuals, calling it "productivity score", and you aren't expecting some crap manager somewhere to use this without understanding what it really means? Think it through.

New study: DNS spoofing doubles in six years ... albeit from the point of naff all

doublelayer Silver badge

Re: Really?

The 1.7% is more concentrated. Some places make it nearly 100%, and some places make it 0%. The places with 100% usually spoof the answer with the correct answer. However, they sometimes choose not to, usually when the correct answer is "don't know that one" and they instead substitute "how about these ads". Their infrastructure for that purpose can also be used to censor something at a later point should they decide they want to do so.

A note: although a lot of ISPs do redirect unknown domains to an ad system, it does not necessarily follow that all of them spoof to do so. Many only do so if the user doesn't change away from the ISP-supplied DNS servers. That approach is annoying, but not the kind of violation of trust that spoofing does.

Bare-metal Macs-as-a-service come to AWS. Intel for now, M1 silicon in 2021

doublelayer Silver badge

Re: What is the use case for this?

That makes sense, but I'm not sure the pricing works out. A day costs $28.99, and two weeks costs $405.89. If we assume that you use the system once every sixty days, and one of four of the times you'll need it for a while, your average yearly bill would end up being $793.65. Even without ever hitting the bad case, your yearly bill would be $176.36. I don't know about other providers, but the AWS prices seem a little unsuited even for your requirements.

doublelayer Silver badge

Re: What is the use case for this?

Not really. With cloud, you're not buying the same thing you buy with a standard computer purchase. For example, cloud offers you the ability to pay for temporary use of hardware which would be very costly to purchase outright, or access to the provider's faster network connections, or geographic distribution. None of those services come from purchasing hardware outright; you'd also have to pay for the administration of the features you want, which the cloud provider would be willing to replace.

The reason this doesn't make sense to me is that I don't see why people would want those services on a Mac. If people routinely used a bunch of Macs as servers, then it might make sense. To the best of my knowledge, they don't. I've only seen Macs as servers where the place is really small and they just put the server on the thing that was available. Similarly, most of the use cases I can think of where a Mac is needed on occasion is for development or testing of a cross-platform application. I don't think the pricing makes sense if that's the expected use case, since a month of access, either continuously or thirty days across a year, would equal the cost of a purchased device.

doublelayer Silver badge

Re: It's not cheap

I really wonder about that. Developing for IOS or Mac OS usually means more than compiling--in fact, if all you want to do is compile, you can hack a different OS to do it if you're motivated enough. If you want to use the restricted components like the simulators, that bit that lets you push the code out to real IOS devices, etc., it will take longer. Also, since you have to rent the device by the day*, you don't get the benefits of paying only for the half hour you use. Meanwhile, you could just buy a single one and set up the remote access to share it among the team if it's not needed very often.

*You don't have to pay by the day, but you have to pay for it for at least a day each time you spin one up. This effectively means that you'll pay continuously or you'll pay for various chunks that are 24 hours long.

On the 11th day of Christmas TalkTalk took from me... the email address of my company

doublelayer Silver badge

Not relevant to the conversation. There's a GMail address behind my domains, but you don't see that if you want to email the domains in question. Using a single mailbox rather than a domain seems unprofessional, and for certain types or sizes of institution, it is. A single mail address usually means a single mailbox, with everyone having access to it. For that reason, I wouldn't send any personal or financial information to a company using one of those. For something smaller, I don't care so much. It's about what address they want me to use, not what addresses they might have behind the scenes.

doublelayer Silver badge

Re: Car Mechanics are not IT people

This comment is mostly good, but then I saw this: "(Also how many hackers would even know how to break into XP anyway?)". The answer: a lot of them. XP has holes, and if it wasn't patched, some really big holes. Someone who didn't update the operating system, even just to Windows 7, probably doesn't have great patching regimes for the XP boxes. Protection against malware which makes it to execution is almost nil. Protection against external penetration is a little better, depending on the firewall settings, but there are bugs which can allow an automated installation of software without needing the user's permission. Put an XP box on the public internet and someone will be attacking it soon. Put an XP box without the emergency patches from 2017 on the public internet and it'll be in a botnet in half an hour. With luck, most XP machines still in use are either kept offline or at least behind a NAT or restrictive firewall.

AWS reveals it broke itself by exceeding OS thread limits, sysadmins weren’t familiar with some workarounds

doublelayer Silver badge

Re: Potential enormous boost for AMD

Only if they find three things: a) they can't get around the one thread per server thing, b) all their threads are putting too much pressure on the CPU, not just the OS's limits, and c) they still can't get around the one thread per server thing. So far, when they increase the CPU power available to the VMs, it's so they can reduce the total number of them rather than to get more concentrated compute. They could solve problem A by using a system that allocates threads to access requests rather than reserving one per server. Having done that, it seems unlikely that they'd experience problem B at all, based on their statements. If they did, they could always try to solve problem C by redesigning the system so it doesn't have quadratic scaling, for example by having certain nodes whose responsibilities are to contact subsets of the servers and keep that data available for servers in other zones. If all of those attempts fail, then AMD may have a cause to celebrate.

Calls for 'right to repair' electronics laws grow louder across Europe

doublelayer Silver badge

Re: @Dwarf

"People buy what they want and they know this by looking at what they care about before purchase."

They do. If they can get said information, which sometimes they can't. You don't know, for example, whether a certain component is going to be easy to replace unless one of the following situations occurs:

1. The manufacturer tells you. They often don't.

2. Someone else buys one and disassembles it so you can watch their discoveries. They mostly do that for only the most popular of devices.

3. The product has been available for long enough that people have broken them and the information about repair policies has been released. This only happens if enough people bought it and often takes months or years.

For certain products, this is easier. A durable expected to last decades can often be researched because you don't have to get the new model. The flagship consumer electronics will get dismantled by somebody on release, so that information will come out at some point. For other products, you won't get it. Maybe not enough get purchased for much information to come from independent repair attempts. Maybe, by the time that information is available, the manufacturer isn't making that product anymore. This is asymmetric information. I want to know details about a variety of options so I can choose which I wish to buy, but the information didn't get released to me so I can't. In this situation, I'm usually faced with the option to buy the one product that did make the information available, even if it's not really my favorite option, or to choose a product that looks like I'd like it more but I don't know many of the details that interest me.

doublelayer Silver badge

Re: @Dwarf

I'll state my point less ambiguously. The information needed to determine repairability is by and large unavailable to me. That's why I asked those questions, but apparently it didn't get through. I can't just look up the repair information for many products because the manufacturer didn't make it available and there aren't enough people who like to buy things and write up what it's like to disassemble them. As for your question of why I'd like to get the details on every option, it's so I can compare them. I also like my products cheap, so if I find two models that can be repaired, I'll likely buy the cheaper one. If I only get one recommendation for a repairable one, I don't have that option. This is why just having a reliable repairability score would be so useful. For those who already care, it makes information available when they wouldn't have it. For those who don't care, it would display the differences more prominently and might convince them that they do care after all.

doublelayer Silver badge

Re: @Dwarf

So much to take apart. Let's get to it:

Original: "You have to take into account asymmetric information"

Reply: "So you dont research what you are going to buy?"

Asymmetric information: noun. A situation where information is not available to both sides of a theoretical transaction. If asymmetric information is part of the experience, then research will not result in the desired information. An example: I do not know when buying a phone whether and for how long its manufacturer plans to release updates for it. The manufacturer does, but I don't. I have to guess based on reputation, previous history, etc. This is unreliable at best. It can often be worse.

Original: "where I do not know that the piece of equipment is difficult to repair"

Reply part 1: "That kind of equipment or specific product?"

Specific product, obviously. For each option. From context, this is what the complaint is about.

Reply part 2: "Did you look or was it not so important to you at the time of purchase?"

See above, under the section entitled "asymmetric information".

Original: "cartel/oligopoly behaviour"

Reply part 1: "Which gets punished."

You have more faith than I do.

Reply part 2: "But not what we are talking about unless you think so many businesses are running such?"

I would like to argue against this, but the first reply has already taken this and done an admirable job.

Original: "Please stop with your A-level economics"

Reply: "Didnt take it but thanks. Should we abandon any economic thought in this discussion or just if our opinion doesnt match yours?"

I'm not sure if you're misunderstanding that point deliberately or because of a regional term. I'll assume the best. If you're unaware, A-levels are the tests taken in the UK by adolescents and cover the basics of a topic. Therefore, to accuse someone of using "A-level economics" means that you are accusing them of having only an elemental understanding of a complex topic and displaying ignorance. The solution to that is not "abandon[ing] any economic thought" but instead to consider more complex parts of economics, among which are the incorrectness of the perfectly competitive free market.

doublelayer Silver badge

Re: @Dwarf

"Ok. So you bought something you were happy with until something broke and the idea of fixing it wasnt on the top of your priorities until it broke. When you buy the next one will you look at how repairable it is?"

Absolutely. When I buy a computer, I read about what repairs are possible and how hard they are. When I buy a washing machine, I'm sure I can get all that information, right? Instead of a few likely options with easy-to-find reviews, I am faced with the choices from local retailers. Should I ask them to let me disassemble one right in the shop to see what I'd be experiencing a few years later? Or maybe I can go to IFixBigEquipment where there's an in-depth review of the repairibility of every model of washing machine released.

In other words, how am I supposed to know how repairable something is unless the manufacturer has published information or someone else has reviewed it? If I can't know how repairable the thing is, how can I take it into account when making a purchase?

doublelayer Silver badge

"have you considered the universal remote controls - they often have all the devices listed and either have the codes or you can download them to the devices."

Not the original poster, but in an unrelated incident, I have tried to do that, but I did not have much success. I was given an old television whose primary defect was that it wasn't as big as the one the previous owner wanted, but also had no remote control. I tried to find the codes to get it running using an old Android phone with an IR transmitter and later an old "programmable" remote control, but it resolutely refused to respond to any of the codes I sent to it. Maybe the phone's IR function required a Google library (this had had Play Services removed). More likely though is that the codes it knew and the random numbers I found online were not the random numbers this television was expecting. Don't count on that information; it's not as good as it seems.

If you're curious, the television now sits on a friend's wall. You have to go up to it to change things, but they seem not to mind. I'm still not sure why the previous owner didn't try to sell it, or why I tried so hard to get it working given that I never wanted to use it, but all's well that ends sort of working.

Marmite of scripting languages PHP emits version 8.0, complete with named arguments and other goodies

doublelayer Silver badge

Re: PHP cost 0

I assume this is an attempt at a joke?

"Cero in compile the code before "production" How much money you save stuff in resources?": Because compiling any number of smallish projects uses so much precious CPU time? This isn't the 1970s. I can type "make" and wait five seconds.

"Cero in time to dev something. Do you need to install jdk, maven, npm, packages, 300 hundreds of line of code and config to say "Hello World".": I have to install PHP and, if I'm using PHP in the most typical way, a webserver configured to use it. Not much different.

"Cero time in changes, hot changes in production.": You're fired. Really. You don't install changes into production. You run it through tests and review first, then it's elevated to production.

"Cero time in learn and spent to get good developers": Ah. Free PHP devs? Sure thing. Send me ten of those; I'll find something for them to do if the work is free.

"Cero resources to mantain his performance": I don't know what this even means.

"Cero time to create a good architecture.": Trust me, whatever you're writing in, you need time to create a good architecture. It's one of the most important things to spend time on.

doublelayer Silver badge

"I expect there is work for code maintenance for PHP, but I assumed nobody in 2021 is going to start a new project with it."

It really depends on the scale. For example, I sometimes work on one-time projects for charities, which usually take the form of some basic web forms glued together. I often end up using PHP for the backend because it doesn't require additional effort to get it running. Nearly every server already supports PHP scripts in the backend. Had I chosen a framework that requires other things, I'd have had to ensure the server they're planning to use supports it, that it's been installed and configured correctly, etc. Since a lot of these nontechnical and small places use a shared hosting plan, it's much easier to say "put these files on your server via FTP in this directory, or give me the credentials and I'll do it for you" rather than "We're using a framework called Flask, so I'll need access to your server to verify that it supports it. Also, we will need your server software to redirect some URLs to the Flask engine so please remember that I did that in case the next person to volunteer for your web tasks doesn't figure that out". Also, while someone might not be starting a new large project from scratch given the CPU limitations of PHP, there are plenty of existing codebases written in it. When people want to add features to those, they'll probably end up writing their new features in PHP too.

Privacy campaigner flags concerns about Microsoft's creepy Productivity Score

doublelayer Silver badge

Re: Design vs Use

It can look at an individual user, but it doesn't show you information about what they're doing at any given moment, but only what they did in each 28-day period. Which is extremely different, because there's no way that any information could be extracted, for example by cycling through new rolling periods and looking at the difference between them, or going into the settings to look at more fine metrics. Yes, definitely the time aggregation will be sufficient to make this difficult to abuse.

Retired engineer confesses to role in sliding Microsoft Bob onto millions of XP install CDs

doublelayer Silver badge

Re: Back in the nineties I worked at a software house

Aren't finance departments wonderful?

Option 1:

Programmers: We were planning to have a unit distribution cost of two floppies, two labels, an envelope, and the initial documentation. We met that target.

Finance: Well done.

Option 2:

Programmers: We were planning to have a unit distribution cost of two floppies, two labels, an envelope, and the initial documentation. We managed to reduce that to one floppy, but still two labels because that was last minute.

Finance: You're wasting money on the extra labels! Even though we were already planning to spend that and you saved us money on the floppies! Let's fire somebody.

doublelayer Silver badge

Re: Duh...

Where's the fun in that? Still, might have been nicer to collect names and messages from the engineers to be irreversably encrypted. I'm sure they would have appreciated that.

Thought the M3 roadworks took a while? Five years on, Vivaldi opens up a technical preview of its email client

doublelayer Silver badge

Re: Fantastic

"A simple one that I find extremely useful is being able to show all mail to/from a particular contact. Can't seem to do that in Thunderbird."

I'm probably misunderstanding what you want, but if I'm not, it's pretty easy in Thunderbird. If what you want is to show messages with someone particular in either the from or to addresses, can't you just do this:

1. Open the message search feature (CTRL+shift+F).

2. Change rule setting to "match any of the following".

3. Add a rule "To contains <the address you care about>".

4. Add a rule "From is <the address you care about>".

5. Activate the filter and look at the results.

Again, I assume I'm just misunderstanding your goal.

Amazon's ad-hoc Ring, Echo mesh network can mooch off your neighbors' Wi-Fi if needed – and it's opt-out

doublelayer Silver badge

Re: The real problem is the data caps

You are correct. I pay my ISP for the resource I use. The difficulty is when they attempt to restrict what I may do with it. For example, I have an agreement with a neighbor who uses a different ISP. Specifically, we each pay our own bill, and if one ISP goes down but the other doesn't, we can use the guest network of the neighbor who still has a connection. I think that's technically against the subscriber agreement I have. ISPs also frequently restrict other things to make it difficult to put several devices on one connection; for example, someone I know had an ISP-supplied modem which didn't allow people to change basically any settings and throttled bandwidth when sent by too many client devices. Or there are the mobile providers who attempt to restrict what can be done with the data access a subscriber already purchased, such as preventing tethering. Without these tactics, I would entirely agree with you. Since they exist, I must only partially agree.

doublelayer Silver badge

Re: The real problem is the data caps

It's actually quite a nice idea, and I'd be all for it but for a couple of things: it has no user control, no security, no accountability, and massively advantages Amazon over everyone else. Offering an open mesh network would be nice, and I'd gladly add some of my resources to it, but only if it could allow me to control what I allow and when. That means that it'd have to be an open standard and controlled centrally by each user without any data collection by a third party. This won't ever happen because a simple internet benefits several types of entities. It benefits ISPs which get to charge each user for a shared resource. It benefits data trackers who can more finely track individuals on the network. With these groups against an open idea, it won't ever really come to fruition. Still, let's keep the dream alive by making sure Amazon's proprietary imitation stays dead.

AMD performance plummets when relying on battery power, says Intel. Let's take a closer look at those stats

doublelayer Silver badge

Re: RUGs

I don't do either of those very often, but converting to a PDF is usually a few-seconds activity in my experience. Extending a 2.5-second task to 4 seconds or a 11-second task to 15 probably doesn't change the user experience much, especially as selecting the options probably took several seconds too. The performance differences I care about fall into three categories:

1. Things that take a long time to run. Adding three minutes to a process can be an important detail. However, I don't do many of those things on battery power.

2. Tasks that get run in batches.

3. Tasks that I do very frequently, such as loading new pages while browsing.

When I'm mobile, I care most about the third category. As long as the slowdown isn't bad enough that I see it while reading or writing things, I doubt I'll have a problem. Most intensive work gets down while the laptop is connected to power. This is why the CPU is rarely the most important detail in a computer purchase in my opinion. Amount of memory, memory speed, storage speed, and repairibility are my metrics of greatest concern.

It's always DNS, especially when a sysadmin makes a hash of their semicolons

doublelayer Silver badge

Re: Me 2

I had a similar experience. I was looking at a config file, with a line I wanted to comment out temporarily, but not sure whether this format supports comments and if it does how to use them. My basic thought process went like this:

It looks like XML, so maybe I can just enclose the line in <!-- ... >. That definitely makes the most sense. Except it doesn't start with an XML tag. Also, after a few levels of XML-style tags, it starts listing key value pairs without tags, so it's probably not XML. I'm also pretty sure that it takes multiple values separated by semicolons, so it can't be that. That only leaves #. Well, I think it uses semicolons for the multiple value separator but I can't check because this file doesn't have any sets of multiple values. In the end, I just copied the file and deleted the line. It was the fastest way to be sure.

Study: While text-generating AI can write like humans, it lacks common sense

doublelayer Silver badge

Re: When are they going to stop pretending ?

Not really. That's mostly what I wanted to avoid. That argument is referring to the difficulty in determining the sentience of a system which may only be simulating sentience. It then argues, mostly without supporting evidence, a fundamental limitation on mechanical devices and an inherent possibility in biological ones. Right now, I don't care about that; it's an interesting philosophical debate, but very difficult to make progress on.

For the moment, I'm just trying to get a good definition of what artificial intelligence is. I've seen people who think that, if code has more than two if statements, it qualifies as AI. I've also seen people who say that nothing using mathematics to arrive at a conclusion can ever be AI. Both these definitions seem highly limited to me. The argument to which I originally responded is close to the second opinion above, and in an attempt to understand why people say it, I'm trying to determine if its adherents think there can ever be such a thing as AI. Maybe some think that a mechanical system can never be intelligent because intelligence requires sentience and they think mechanical devices can't be sentient. If this is their view, they really should phrase it in those terms, I.E. "AI is impossible" rather than "this is not AI". If they do believe there is something they would agree to be AI, I'd like to establish where that begins for them and why certain complex systems which are not simply programmed externally don't qualify. My questions are about the definition of the term AI, not metaphysical discussions about what sentience is and whether we can create it.

doublelayer Silver badge

Re: When are they going to stop pretending ?

On that basis, we can never have AI. A machine that does mathematical stuff could in theory eventually simulate intelligence and sapience very well, but it would be by performing a very large amount of statistical calculations to interpret what just happened, what logical actions would be, the likely consequences of each candidate, and variables that change any of the preceding. At the very strong risk of getting into metaphysics, you could argue that our brains are doing exactly the same thing. If I presented you with a computer which was acting human consistently and without external influence, would you agree that to be AI or would you tell me that, since it's running on essentially mathematical code, it can't be?

I agree with you about this though; these are definitely not intelligence.

Cool stuff: MacBook Air and Pro teardowns show thermal changes and missing T2 chip

doublelayer Silver badge

The iPad processors are more limited for the moment. Consider these spec differences:

M1: 8 cores, 4 high-speed Firestorm at 3.2 GHz and 4 lower-power Icestorm at unknown clock rate (at least I don't know yet). Cores from A14 range.

iPad Air 2020 (4th generation): 6 cores, 2 Firestorm at 3.0 GHz and 4 Icestorm, A14 range.

iPad Pro 2020 (4th generation): 8 cores, but from A12 range instead of A14, high-speed cores (X4) running at 2.5 GHz.

In addition to these technical differences, most users will not hammer the processor as hard on an iPad as they do on a computer. Most tasks requiring a lot of sustained calculating get done on computers with full operating systems, such as compiling code, managing large datasets, or manipulation of visual data. While some such tasks can run on iPads, fewer users intend to do that with them than intend to do it with a laptop.

HTTPS-only mode arrives in Firefox 83 as Mozilla finds new home for Rust-y Servo engine

doublelayer Silver badge

Re: , you can help your users keep information away from any ISP

That is a separate issue. An important issue, but nonetheless a different one. Tracking content placed on the page by the page creator is a privacy issue between the requester of the data and its provider, whereas HTTPS solves a privacy issue between the data requester and a third party which can access network traffic. What you're doing here is dismissing a real privacy issue and its solution because you can name another one. This classic argument (XKCD) doesn't really make any good argument why the HTTPS privacy feature either doesn't work or doesn't matter.

doublelayer Silver badge

It well can be. There are a few historical examples of large ISPs doing it, the most memorable of which is the "great cannon" DDOS tool operated by the Chinese government which allows them to use Chinese residents' network traffic as a targeted cohesive force to knock objectionable sites offline. It did this in a couple of ways, but one easy one is to add references to the victim in any HTTP traffic which the user's browser will access.

It also happens at a much smaller level. Public networks can be set up by malicious people or replaced by an impersonator doing the same thing. Someone who does this could inject scripts into HTTP traffic and get your computer to execute them. There are risks that remain if your connections are through HTTPS, but they both are harder for the attacker to implement and easier for you to detect.

Another issue is that an ISP can record traffic going over unencrypted HTTP, even if they don't modify it. That traffic is usually used for advertising purposes, but could be used for anything nefarious you can imagine. Since you live in the EU, this would be a clear GDPR violation. As we know, data protection authorities find those out immediately and instantly impose major penalties, so there's never a need to worry at all. Other countries which don't have GDPR don't usually even offer any redress if an ISP should do this, and some countries even allow that data to be made available for sale. HTTPS is a very useful guard against things like this.

doublelayer Silver badge

Re: Thank goodness...

So, out of curiosity, what would you like your current browser to do in a situation where you visit a site, it has an HTTPS certificate, which is issued by a random CA nobody's heard of and never got trusted by anyone else. Would you like it to just use the cert and connect you because you don't want your browser warning you about a security risk? Remember that, in both situations, it tells you why there is a risk and gives you a continue anyway button. Why is this one so terrible when I'm guessing you view the other as a reasonable security precaution?

doublelayer Silver badge

Re: "it's about ensuring that what the client receives is what they were supposed to receive"

Basically none of the things you said have any accuracy.

"in this age of cut price self-signed certificates that actually certify Bu**er all."

There's so much wrong in that sentence fragment. I'm going to have to take that apart.

"in this age of cut price": So if the certs are cheap this is a problem? When they were expensive, this wasn't a problem?

"self-signed certificates": Self-signed certs aren't trusted. Let's Encrypt certs are not self-signed. Let's Encrypt certs require verification of domain control, external signing by someone else, and can easily be revoked.

"that actually certify Bu**er all.": They certify that the server which has the private key is able to serve content from the domain at the time of initialization. Some certs additionally audit who has them and that that's the person who owns the domain concerned. This means that a hijacked DNS request can't impersonate my server because the certificate won't match or won't be signed by a trustworthy CA.

"I actually believe that decisions like this should be left to the user.": What part of "turn it on if you want it" is not getting through? Don't worry, even when this becomes on by default, you can still turn it off. We know this for three reasons. First, HTTP is inside of HTTPS, so nobody can remove that part of the code. Second, people will need plain HTTP for things like network administration, so the setting will necessarily be present. Third, Firefox is open source, so anyone who knows how to edit code can hack out this feature and anyone who can download a file can get a new build from that person.

"Having some external self-appointed nanny decide on our behalf what content we can see in our browsers seems a bit too much like loss of independence": I'd agree if certs did that. They don't do that. Few certification authorities will enforce a content restriction on their users. A few will only give you a cert if you appear to be a legitimate, verifiable organization or person, but several including the free Let's Encrypt will give you one for basically anything so long as you can demonstrate control. Nobody at their automated system is running editorial review on your site.

"Add to that a "four week update cycle" and the user has effectively handed away any control they might once have had.": Options, updates, automatically install updates, switch to off. You may have security vulnerabilities now. When new features are ready, they release them. The major possible downside is insufficient testing, but that's it. If you don't want the update, don't install it.

doublelayer Silver badge

The risk of injection attacks on your users has already been detailed above, so I'll give another reason why you might still care, namely your users' privacy. With a certificate, you can help your users keep information away from any ISP or attacker capable of listening to their traffic including things like which pages they visit or form input. You said that they don't log in, but that doesn't mean they don't view the content they get from you as ideally private. It's a courtesy to them to give them the option to fetch these things in an encrypted form. This doesn't mean you have to do it, but it's nicer if you do.

When even a power-cycle fandango cannot save your Windows desktop

doublelayer Silver badge

Re: Too Many Stories!

Do you really want people who don't understand on their own not to push emergency buttons or activate any controls during a tour to operate expensive and dangerous machinery? There's a certain amount of common sense that becomes an absolute requirement when the dangers of lacking it are big enough. To me, that means that if lacking common sense means the person involved is about to end the day greater one permanent disability or less one coworker, demonstrating too large a lack means it's time for them to go before that can happen. This would also apply with a high enough financial cost. Fortunately, I don't work somewhere where those safety risks are experienced, so the worst that a colleague lacking common sense can do is irritate everyone and slow us down; I can try to train that away.

Israeli spyware maker NSO channels Hollywood spy thrillers in appeal for legal immunity in WhatsApp battle

doublelayer Silver badge

Re: Who cares?

I doubt Israel has really put much effort into that. If this were an Israeli government project, it wouldn't have been handed over to the Saudis with no stated restrictions. While Israel and Saudi Arabia have at times collaborated against common enemies like Iran, they otherwise have had a rather tempestuous relationship. NSO has sold this utility to the Saudis, and if Israel was going to do anything about that, it would have been months ago. There are three options here: 1) Israel knew about it and is more willing to help Saudi Arabia and a couple other countries with repression than I thought, 2) NSO didn't ask Israel about it and Israel didn't bother to investigate, or 3) Israel has chosen not to prosecute a company for their own reasons. I would hazard a guess at option 3, with the reasons being that NSO is providing them with some tools and/or providing an ally of theirs who suggested to the Israelis not to do anything.

doublelayer Silver badge

Re: Who cares?

Governments do this kind of thing all the time. I don't like it, you likely don't either, but this is still worse. When a government does it, it's used by that government for ends that can be predicted and it could theoretically be stopped if the populace were sufficiently motivated. When a company does it, they are selling tools to commit crimes to the highest bidder, meaning they have produced a larger number of threats which aren't as easily restrained. The governments at least purport to have some restrictions on what they can do with their toys, while NSO and corporate malware producers like them do not.

Apple rummages through pockets, hands out $113m in change to US states to make iPhone slowdown row go away

doublelayer Silver badge

Re: iPhone slow down versus battery life

"So how was it to force people to upgrade?"

Two ways. First way you already pointed out: "The big issue was that iOS should have flagged up a message explaining that the battery was shot". If they hide that information, it's logical that they might have hidden it so some people would buy a new phone instead of a new battery. The second issue is that most devices aren't built in such a way that their batteries become shot just after the warranty expires. One could assume they did that on purpose so people would have to buy something pretty soon, and hid the information to try to make as many of those somethings as possible a new iPhone. I choose to believe that issue 2 was a design flaw and issue 1 was being too proud to admit the design flaw, but the argument that it was intentional has a lot of logic to it.

doublelayer Silver badge

Re: And you were expecting?

Not sure which part of your comment was intended as the joke, so in case it wasn't the first question, there's a major difference between improving a product and degrading a different one. One encourages people to buy by giving them a better option. One is akin to deliberate vandalism of someone else's property in an effort to get them to buy something new, which is, in fact, a crime. When it's done by planned obsolescence, it's a crime with a much lighter penalty, but still a crime.

Billionaire's Pagani Pa-gone-i after teen son takes hypercar out for a drive, trashes it

doublelayer Silver badge

Re: When you think about the cost of this car ...

"3 million to a billionaire is about the same hit as 3 grand is to a millionaire of the same scale"

Remember the law of decreasing marginal utility, or without the textbook, that more money starts to be less valuable when you have a lot of it. Billionaires don't usually have to worry about running out of money needed for basic living or even an emergency expense (unless they're the type to never think about their needs for money), so it's probably worth even less to him.

The ones who brought you Let's Encrypt, bring you: Tools for gathering anonymized app usage metrics from netizens

doublelayer Silver badge

Re: "could be a sensor on a road for the valid purpose of determining traffic patterns"

The only problem with that is that that's the argument every time someone decides they want more data, including extremely personal data. First argument is that it makes products better for me and I should be grateful that they're not charging me extra for that. Second argument says that it's not that invasive after all; it's just what someone could see if they looked over at me from across the road with an electron microscope. Third argument says that I have agreed to their data collection by consenting to their eighty-page user agreement, and if I didn't agree to that, I still consented by visiting their page, and if I didn't visit their page, then I consented by proxy by using a page which included their content, and if I tried to block their domains to prevent loading their content, then I consented because their content is important and they need to keep others' sites from breaking which is why they took so many expensive steps to include their content anyway and evade the most concerted efforts to stay away from it.

Truly anonymous data collection, from a public place, using methods that would guarantee anonymity, is fine. For that reason, the example of a road pressure sensor is acceptable. Data collection from items that have been voluntarily relinquished to a different person is fine, so the returned product example is acceptable. My computer is not a public place. My computer was not given to someone else. This makes the collection of truly anonymous data very difficult. Even if it is entirely anonymous, there's still the issue of consent, which in many cases is not obtained. No matter how many nice and simple comparisons are made, they're still misleading and imprecise.

Tablets and Chromebooks are hot, towers and desktops are not: El Reg combs through Q3 PC numbers

doublelayer Silver badge

Re: Who NEEDS a desktop?

You could do the same with a mini PC, but you run into a few problems with those and a few upsides of a laptop. The first problem is that most mini PCs are cheap because their CPU is slow. Some of us can use something as low-power as a Raspberry Pi for day-to-day work because we don't need a lot of local processing and we know how to avoid taxing the cores enough to make it feel slow, but many others need more than that or don't need more than that but don't know how to optimize to get it from a low-end chip. Most cheap mini PCs will be a little faster than the Pi, but not very much so. Getting more processing in one of those means your stated price needs to be at least tripled (usually it's quite a bit more than that).

Meanwhile, a laptop not only offers you a similar amount of performance without much price difference (mini PCs lose you the efficiency of a large tower and the prices aren't much different than laptops) but they also let you use the device in many other places. A mini PC does you no good if you can't plug it into a bunch of peripherals, whereas a laptop gives you a basic set and the battery to run them from. The larger size of laptops also helps if you need even more processing as heat management is much easier there than in something designed to be easily hidden from view. For this reason, people can use a laptop with intensive processors and GPUs if they'd like whereas mini PCs top out at some point.

doublelayer Silver badge

They should, and they have. They're still going to break down on occasion and need replacements. Most of the growth this year is with people who need to work from home or whose children need to study from home. I think the latter group is probably the main reason for all the tablets and Chromebooks, as probably many students didn't have a dedicated device when they did their schooling in person but now can't borrow the parents' computer during the day because that's in use for work.

Apple Arm Macs ship, don't expect all open-source apps to work without emulation – here's what you need to know

doublelayer Silver badge

Re: I'm going to be called a Fanboi but...

There are a few things that will only get answered definitely when people have received units and stress-tested them for several days, and those variables might change the experience for some types of users. Such variables include things like whether the fanless nature of the MacBook Air makes the processor throttle performance often and whether doing this leads to degraded performance for certain use cases, whether there are times when emulation is required but it doesn't work right, or whether the shared GPU uses a lot of memory which is more limited on these chips. Some of these things can't really be determined in a numeric benchmark, and existing reviews seem not to have tried a large number of use cases. While these provisos remain, the reports I have seen thus far are promising.

Apple's privacy pledges: We sent dev checks over plain HTTP, logged IP addresses. We bypass firewall apps

doublelayer Silver badge

Re: Check This Out...

Exactly. And the sad part is that it would be very simple to cut out the privacy problems and internet requirement in one update. In fact, if Apple's listening, here's a fix on me:

1. Run up a new service which offers a database of revoked certificates. Put it at the end of an HTTPS API.

2. Write a little tool which downloads this every day.

3. On running any program, check your offline database.

That's not hard, is it? If you want to go for the ultra-sophisticated model, we can add the following extra steps:

1A. Sign the database with a private key you store.

2A. Make sure your tool has the public key corresponding to that so you can verify your database hasn't been messed with. I mean you're already using HTTPS for it so it's not as hideously easy as it would be under your earlier HTTP solution, but still...

1B. Make an extra facility of the API to download incremental database updates.

2B. Update the database every hour now, using the incremental update to keep data consumption low.

I hope this solution works for you, Apple. The next time you need me to suggest something obvious, I'll charge more.

doublelayer Silver badge

Re: Who owns your Mac?

"Being a complete jerk I’d say that if you write windows apps then you’d expect some changes to get those apps working in red hat and further changes to get them running in SEL. Running in OSX requires some adherence to different ways of implementation."

Which misses the point completely. The issue isn't how to write code, it's whether you have to jump through hoops to run it. The answers are:

On your machine: Not hard. Some warnings will have to be skipped and you'll have to have some free developer tools installed, but otherwise you'll be fine.

On someone else's machine: Have fun with that. Unless you get a developer certificate from Apple (you pay every year) you'll see warnings with no override option, misleading text that makes it look like your file got corrupted, and even more warnings about anything you try to do. If it's you running it, just on a different machine, you can bypass these by looking up the solutions online. If you sent your application to somebody else, especially if they're nontechnical, expect at least two support calls.

Heavy-duty case closed: Peli tried to steal peli.co.uk from rightful owner, says Nominet

doublelayer Silver badge

Re: Seems odd

On the surface, that makes sense. I don't like the people who try to sell domain names either. I don't know if anyone likes them apart from registrars. However, I can't really say the process is unfair in any way. If someone gets a site because they saw me get a trademark, that's a legitimate complaint. If they just got it because it was an attractive domain they figured someone would want eventually, can I fault them? It's a lot like buying land in an area where you think someone will want to develop so you can sell it to them later; I'm sure the developer isn't happy with your arbitrage, but is there something wrong with it?

Of course, in this case, the whole point is moot because they lied about how the domain was transferred. Maybe they would have succeeded had they tried a different argument, but their tactics imply that they didn't have a good enough case anyway which led to their decision to lie about the evidence.