The Register Home Page

* Posts by doublelayer

11402 publicly visible posts • joined 22 Feb 2018

Apple rummages through pockets, hands out $113m in change to US states to make iPhone slowdown row go away

doublelayer Silver badge

Re: And you were expecting?

Not sure which part of your comment was intended as the joke, so in case it wasn't the first question, there's a major difference between improving a product and degrading a different one. One encourages people to buy by giving them a better option. One is akin to deliberate vandalism of someone else's property in an effort to get them to buy something new, which is, in fact, a crime. When it's done by planned obsolescence, it's a crime with a much lighter penalty, but still a crime.

Tablets and Chromebooks are hot, towers and desktops are not: El Reg combs through Q3 PC numbers

doublelayer Silver badge

Re: Who NEEDS a desktop?

You could do the same with a mini PC, but you run into a few problems with those and a few upsides of a laptop. The first problem is that most mini PCs are cheap because their CPU is slow. Some of us can use something as low-power as a Raspberry Pi for day-to-day work because we don't need a lot of local processing and we know how to avoid taxing the cores enough to make it feel slow, but many others need more than that or don't need more than that but don't know how to optimize to get it from a low-end chip. Most cheap mini PCs will be a little faster than the Pi, but not very much so. Getting more processing in one of those means your stated price needs to be at least tripled (usually it's quite a bit more than that).

Meanwhile, a laptop not only offers you a similar amount of performance without much price difference (mini PCs lose you the efficiency of a large tower and the prices aren't much different than laptops) but they also let you use the device in many other places. A mini PC does you no good if you can't plug it into a bunch of peripherals, whereas a laptop gives you a basic set and the battery to run them from. The larger size of laptops also helps if you need even more processing as heat management is much easier there than in something designed to be easily hidden from view. For this reason, people can use a laptop with intensive processors and GPUs if they'd like whereas mini PCs top out at some point.

doublelayer Silver badge

They should, and they have. They're still going to break down on occasion and need replacements. Most of the growth this year is with people who need to work from home or whose children need to study from home. I think the latter group is probably the main reason for all the tablets and Chromebooks, as probably many students didn't have a dedicated device when they did their schooling in person but now can't borrow the parents' computer during the day because that's in use for work.

doublelayer Silver badge

Re: Best of both worlds?

Given recent prices, I haven't really found that. Desktops usually fall into three categories: cheap small boxes with little horsepower, mid-range boxes with good performance as long as you don't need to do something intensive, or very powerful with a price tag to match. If you need the very powerful option, a desktop is cheaper than a laptop even if you can find a laptop to match the specs. In the lower range though, laptops are surprisingly price-efficient as long as you compare well before buying.

Israeli spyware maker NSO channels Hollywood spy thrillers in appeal for legal immunity in WhatsApp battle

doublelayer Silver badge

Re: Who cares?

Governments do this kind of thing all the time. I don't like it, you likely don't either, but this is still worse. When a government does it, it's used by that government for ends that can be predicted and it could theoretically be stopped if the populace were sufficiently motivated. When a company does it, they are selling tools to commit crimes to the highest bidder, meaning they have produced a larger number of threats which aren't as easily restrained. The governments at least purport to have some restrictions on what they can do with their toys, while NSO and corporate malware producers like them do not.

Apple Arm Macs ship, don't expect all open-source apps to work without emulation – here's what you need to know

doublelayer Silver badge

Re: I'm going to be called a Fanboi but...

There are a few things that will only get answered definitely when people have received units and stress-tested them for several days, and those variables might change the experience for some types of users. Such variables include things like whether the fanless nature of the MacBook Air makes the processor throttle performance often and whether doing this leads to degraded performance for certain use cases, whether there are times when emulation is required but it doesn't work right, or whether the shared GPU uses a lot of memory which is more limited on these chips. Some of these things can't really be determined in a numeric benchmark, and existing reviews seem not to have tried a large number of use cases. While these provisos remain, the reports I have seen thus far are promising.

Apple's privacy pledges: We sent dev checks over plain HTTP, logged IP addresses. We bypass firewall apps

doublelayer Silver badge

Re: Check This Out...

Exactly. And the sad part is that it would be very simple to cut out the privacy problems and internet requirement in one update. In fact, if Apple's listening, here's a fix on me:

1. Run up a new service which offers a database of revoked certificates. Put it at the end of an HTTPS API.

2. Write a little tool which downloads this every day.

3. On running any program, check your offline database.

That's not hard, is it? If you want to go for the ultra-sophisticated model, we can add the following extra steps:

1A. Sign the database with a private key you store.

2A. Make sure your tool has the public key corresponding to that so you can verify your database hasn't been messed with. I mean you're already using HTTPS for it so it's not as hideously easy as it would be under your earlier HTTP solution, but still...

1B. Make an extra facility of the API to download incremental database updates.

2B. Update the database every hour now, using the incremental update to keep data consumption low.

I hope this solution works for you, Apple. The next time you need me to suggest something obvious, I'll charge more.

doublelayer Silver badge

Re: Who owns your Mac?

"Being a complete jerk I’d say that if you write windows apps then you’d expect some changes to get those apps working in red hat and further changes to get them running in SEL. Running in OSX requires some adherence to different ways of implementation."

Which misses the point completely. The issue isn't how to write code, it's whether you have to jump through hoops to run it. The answers are:

On your machine: Not hard. Some warnings will have to be skipped and you'll have to have some free developer tools installed, but otherwise you'll be fine.

On someone else's machine: Have fun with that. Unless you get a developer certificate from Apple (you pay every year) you'll see warnings with no override option, misleading text that makes it look like your file got corrupted, and even more warnings about anything you try to do. If it's you running it, just on a different machine, you can bypass these by looking up the solutions online. If you sent your application to somebody else, especially if they're nontechnical, expect at least two support calls.

Heavy-duty case closed: Peli tried to steal peli.co.uk from rightful owner, says Nominet

doublelayer Silver badge

Re: Seems odd

On the surface, that makes sense. I don't like the people who try to sell domain names either. I don't know if anyone likes them apart from registrars. However, I can't really say the process is unfair in any way. If someone gets a site because they saw me get a trademark, that's a legitimate complaint. If they just got it because it was an attractive domain they figured someone would want eventually, can I fault them? It's a lot like buying land in an area where you think someone will want to develop so you can sell it to them later; I'm sure the developer isn't happy with your arbitrage, but is there something wrong with it?

Of course, in this case, the whole point is moot because they lied about how the domain was transferred. Maybe they would have succeeded had they tried a different argument, but their tactics imply that they didn't have a good enough case anyway which led to their decision to lie about the evidence.

GitHub restores DMCA-hit youtube-dl code repo after source patched to counter RIAA's takedown demand

doublelayer Silver badge

Re: It might attract less attention if it wasn't called...

Leaving aside the first point for the moment, I want to know how old your browser is. Every browser I've used in the past decade doesn't have any of your subsequent points:

"2) they limit the amount of content downloaded, i.e. browser's download feature has slower than

turtle user interface that allows manually downloading only one file at the time": I don't know whether I've ever had a browser do that. Even the really early one I used on a weak mobile device allowed me to queue files to download which it did in sequence. Everything else downloads files in parallel.

"3) they don't allow downloading all the content, but only selected/small section of the actual data": Mine don't do that either. There's this button which lets me save the whole page and everything displayed on it. It's called "save". Getting the files out of the format the browser likes takes a few seconds. I can also go to the developer tools and access any subset of the data with those utilities.

"4) they have very efficient ways of controlling under which circumstances the downloaded data needs to be deleted.": They do? Mine doesn't seem to do much. It had an "automatically delete downloads after they've sat in the downloads folder for X days" option, but I turned it off. It would help if it were that smart, as I see there's a dataset in there which is now about a month out of date and needs updating. The browser should somehow detect this and delete the out-of-date dataset for me. Why didn't it?

doublelayer Silver badge

Re: youtube-dl is still dubious

We are looking at the market leading browsers. For each of these, the "protections" as you call them either don't exist or exist for an entirely different purpose with no protection purpose whatsoever. Let's look at the ones you listed:

"back-key": The back key doesn't protect anything. It moves you around. If you request to download a file, which it will do for you, the back key will not prevent the download. You get to deletion later, so there will be more to say.

"browser cache": Which is a protection exactly how? It caches stuff for later viewing. It doesn't give the site owner any more control, and it allows users to copy stuff off of it. Not a protection by any means.

"slow user interface for manual downloading": It doesn't take me all that long to look at my "open" and "save" options and select "save". It doesn't even ask me where to store the file. So it's not a slow interface. If some part of it is slow, that's a UI problem which could be fixed, not a protection measure.

"regular deletion of downloaded data (when back key is pressed)": That's because, when I leave a page, I usually don't want any of that data anymore. It's clearing it for me because it doesn't want to use up my disk. I can set it not to do that if I want faster page loads and most browsers will keep some things they think I'll be using again soon.

"limiting downloaded data to transient memory areas instead of persistent storage": Er ... that's not a thing. One of the problems with browsers is that, in an attempt to use less RAM, they store a bunch of cached data on the hard drive and sometimes forget to delete it. You can go through browser profiles and look at a bunch of temporary files they created and forgot to delete unless you have set it to delete all of that when the browser closes.

"encoding of browser cache so that it cannot be used for piracy": Also not a thing. If you go into those temporary directories, you'll find a bunch of stuff. None of it will be encrypted. It may be stored in a way that doesn't make it obvious where it came from, but that's because the browser stores that information in a more compact way, mostly in SQLite databases. They do that in order to have a more organized set of files, easily clean up, and access them with a single database query and disk access rather than several disk accesses. If you want that data, nothing stops you loading up those databases and using them to reassociate files with metadata and do with them as you please.

Apple braces for antitrust woes by letting users select and install third-party apps during setup of iOS 14.3

doublelayer Silver badge

Re: There was a time.…

That's not the point, though. Whether safari is good or bad, the issue is about choices. I see exactly why Apple decided to write Safari. I like it, if only because it has stuck with its own rendering engine while most others have given way to Chromium. If people use it a lot because they really like it, that's fine.

The issue is that, on IOS, users have no choice. They must use a browser that uses WebKit whether they'd prefer to or not. The mobile versions of other browsers just change the skin. This means that users don't get the option to switch to anything else. In many ways, it's similar to the situation you describe on OS X in the 2000s--they get a single choice which might not always be to their liking. In the 2000s, someone could write a browser to run on OS X, just like Apple did. Today, the same is not necessarily true with IOS.

I don't really care whether Apple puts a choice screen into the setup process or just lets people download their desired apps later, but I would like them to reduce the restrictions they place on developers and users. Appealing to security is in many cases a cheap tactic which has little or no factual basis; there are bugs in every rendering engine, but there are also bugs in every similarly-sized codebase and plenty of those get accepted. The restrictions on rendering engine or on payment methods just serve to prioritize Apple's services over user choice. I don't think that should be allowed, and I frankly don't think they need it anyway.

New lawsuit: Why do Android phones mysteriously exchange 260MB a month with Google via cellular data when they're not even in use?

doublelayer Silver badge

Re: Yikes!

On my last phone with Google stuff on it, you could make some voice recognition stuff work offline by going to Settings -> Language and Input -> Voice Search -> Offline speech recognition. That might work in your case. A warning though, that was many years ago. I'm now using de-Googled Lineage OS, which just doesn't have speech recognition in it. I've periodically thought of trying to put it back, but haven't really bothered.

Microsoft unveils a Universal version of Office for Apple silicon

doublelayer Silver badge

Re: This puzzled me a bit

"64-bit is not better than 32-bit, it's just bigger. We're all chasing the word size believing that it's somehow better - while there are a few advantages, the fact is that the application sizes keep doubling, systems need more memory and higher cpu clock speeds each time."

That is not how that works. Applications do not double in anything, be that disk, RAM, or CPU. When an application is recompiled from 32-bit to 64-bit, the only things that need to get larger are pointers. Those do double in size. The instructions either stay the same, not changing in size, or are changed to new ones for more efficiency. Since they're not using any more data, they're still the same size. Some use of pointers means there'll be a slight increase in disk usage for the binary, but it will be small. More importantly, most storage used by a program is in the form of assets. Databases, media, documents, images, and those stay the same.

The programs that do see a difference are those that use a lot of pointers. Ones that use a lot of other types will have no change. The result is that an operating system compiled for 64-bit will have a significantly higher memory footprint because kernels have to store a lot of pointers so everyone else's virtual memory works. That point, I'll grant you. But it's not double even there.

Meanwhile, a 64-bit processor can do some types of things much better. AMD64 supports operations on 64-bit and 128-bit values that can be accomplished in one instruction whereas I386 requires several to do the same thing. What does this mean? It clearly means faster calculations, and that's true. But since you are focused on binary size, it means that each time a program does an operation like that, its disk usage is reduced by a few bytes as it chops out a few other instructions. This increase in efficiency invites programmers to use the faster processing to add features, so you will see larger programs, but you would (and did) see the same thing if they just made a faster 32-bit chip. Such programs get larger because they do more things, not because the architecture change did it to them.

"Does anyone think that switching to 128-bit is going to improve things in a couple of years?"

It won't happen, but absolutely. CPUs have come to the conclusion that 64-bit addressing will continue to work for a very long time, and it will. However, there are other kinds of chips including GPUs and ASICs that already do some parts of a 128-bit architecture or in some cases an even larger one. These are popular among people who want and are willing to pay for very good performance because they run faster for certain mathematical use cases. I fully expect that such chips will become more available in years to come and that they will be adopted by places wanting good performance. You don't need it in a consumer-level machine, but supercomputers will want it quite a lot. Eventually, gamers will get the same kind of chips so they can drive even higher-resolution screens at even faster framerates. While I rarely need either type of improvement, those things would definitely be improvements.

Email-spamming COVID profiteers deleted database with 'key evidence' when UK watchdog came knocking

doublelayer Silver badge

"On the other hand, do we want the ICO to have the power to kick the doors down and seize everything whenever it wants?"

No, we don't. How about we give them the power to kick the doors down and seize everything whenever they've identified a likely criminal and obtained a warrant from a judge. Since they're an organization empowered to investigate crimes, maybe they should have similar powers to other law enforcement, including the power to keep a warrant application quiet so they can get evidence before someone destroys it.

Facebook's anti-trademark bot torpedoes .org website that just so happened to criticize Zuck's sucky ethics board

doublelayer Silver badge

It's bad because Facebook doesn't control the string "facebook". It's worse because I think we all know the bot excuse is just to deflect blame. No actual business has to put "thereal" in their domain to prove who they are; it's clearly to express that the Facebook-named board isn't, in the opinion of the people with the site, doing any oversight.

The name of your site is not the problem. What you do on that site is the problem. If you run a phishing site for Halifax online banking, it doesn't matter if you call it genuine-halifax-online-banking-biz or iwilltakeallyourmoney.gq; what you are doing with it is illegal, so your site will be taken down for that reason. Trademark complaints are different, but that would only be relevant if the people running the site tried to create an otherwise legal enterprise under false pretenses. Not only did they not do that, but Facebook doesn't even allege that they did.

doublelayer Silver badge

Domain Name: FACEBOOK.COM

Registrar: RegistrarSafe, LLC

Registrar IANA ID: 3237

Registrar Abuse Contact Email: abusecomplaints@registrarsafe.com

Registrar Abuse Contact Phone: +1-650-308-7004

Not one I'd ever heard of, so I decided to just visit them:

Mailing address: RegistrarSEC, LLC / RegistrarSafe, LLC

1601 Willow Road

Menlo Park, CA 94025

Phone: +1 650 308 7004

Fax: +1 650 472 9224

Primary Contact: Denise Michel

Officers: David Kling – CEO, President and Secretary; Susan Taylor – Vice President and Treasurer; Michael Johnson – Assistant Secretary

Member: Facebook, Inc.

You can't even buy domains through this registrar. Why they felt the need to create a subsidiary to do this is beyond me.

Here's US Homeland Security collaring a suspected arsonist after asking Google for the IP addresses of folks who made a specific search

doublelayer Silver badge

Re: Hmmm

"Ah yes; the entirely lacking in evidence argument that "they did it legitimately this time means they won't the next time". [...] I am old enough to remember when "innocent until proven guilty" used to be a thing."

They are guilty. The law enforcement entities have been found to have violated laws on data collection and privacy in numerous ways. They started by collecting information they didn't have a legal right to collect. Then they didn't delete information when the courts said they would have to. Then they used data for unwarranted purposes. The only reason those crimes haven't resulted in jail time is that these entities have the ability to decide that they don't want to investigate their own crimes, but they haven't had to hide the information about what they've done. Why do we have to give them the benefit of the doubt when they've already repeatedly proven that they will collect information and use it despite what the law requires of them? The example here was legal and appropriate for the situation, but the inappropriate requests have already come and succeeded.

doublelayer Silver badge

Re: Percentage...

I'm assuming most of their cases are to divulge Gmail messages or files on Google's cloud, with the small percentage being search history. Why Google needs to keep logs of search results going back weeks is perhaps a better question, but that's why we're using DuckDuckGo, isn't it?

doublelayer Silver badge

Re: A narrow search is good

But it is probably not going to be the most successful result. Take the evidence described in this article:

1. He searched for the address.

2. His phone was near the crime scene but he doesn't live there.

3. His truck was speeding away from the scene right after.

Maybe it's just me, but it seems logical to proceed through the evidence in the opposite order. First check security cameras and find vehicles that are speeding away right after the arson. If "speeding away from the scene" from the article really means conspicuous driving, that's not going to produce many suspects. Run each one and see if there's a reason for their vehicle to be there, and when you find a person who doesn't live or work nearby, check whether there's more evidence on that person in particular. This means checking phone location records on that particular person (if you can't establish an alibi for having the car there).

The problem with this approach is that the order of evidence is opposite to the ease of hiding that evidence. He could hide the lookup by searching for a nearby address, by browsing through a map, by driving down a day early, all these being very easy. He could only hide his phone location history by getting a burner phone or not bringing a phone at all, which is doable with a little more effort. Getting a car that isn't connected to him is by far the hardest task. In future investigations, it might make sense to start with that kind of evidence.

BOFH: Rome, I have been thy soldier 40 years... give me a staff of honour for mine age

doublelayer Silver badge

Re: what a classic!

I think that's why he hasn't, because this is actually one of his longterm plans. Had he done something to take over the company, he wouldn't have leverage to use against his witnesses. By keeping his take restrained, he can get rid of evidence by threatening people from the blackmail file. He also doesn't have to worry about a replacement tech finding out any of his secrets.

Keep in mind that he did a similar thing with his own employment contracts, in fact at least twice. He just didn't have the audacity to try one this big.

Apple's T2 custom secure boot chip is not only insecure, it cannot be fixed without replacing the silicon

doublelayer Silver badge

Re: Surprised?

"I don't get why people think Apple will use the transition to ARM to lock down macOS. They could have done it at any time"

You are correct, but I think it's likely. In 2006, they didn't want to lock it down. They wrote BootCamp just to prove that. They still allowed running unsigned binaries. I was very happy with them. It's not the same now. They've taken various small steps toward locking down their OS, and they've created another fork which has already seen much more thorough lockdowns. The reason I think ARM might be a good opportunity for them to lock down is that it's easier to say "We have to drop support for multibooting because our chip doesn't support the operating system images currently available" rather than "We decided we didn't want you to run Windows anymore so we're pulling Bootcamp". In the name of security, they've instituted weird and painful restrictions on disk access that don't work which look a lot more like IOS than they look like any other popular OS. They've hidden the settings needed to run software they haven't signed behind obstructive and meaningless error messages. Their repairability scores have been dropping steadily for most of their machines. These are not good signs to me.

doublelayer Silver badge

Since it requires a cable connection and booting to recovery, it's unlikely to spread without assistance; people rarely connect one computer to another one over a USB cable. The exploit is very serious given the likelihood that someone could do this with minutes access and it could remain resident for a long time. I doubt it's hard to use the access granted here to grab the encryption password and install malware on the victim's system to phone home with the data when the computer is connected to the internet. At least we know about this; had it been someone who doesn't work on security testing with a public interest, it would already be deployed at various countries' border scans.

Teracube whips out cheap, fixable phone with removable battery and four-year warranty

doublelayer Silver badge

Re: Alternate use...

Not at all. There were two points in the post:

1. Pine64 is being silent.

2. They deleted blog posts.

The first point is an opinion, the second one a statement of fact which I couldn't corroborate. I therefore asked for the reasons for the opinion and assistance proving me wrong.

I can't contact Pine64 about their purported silence, because I don't know what you (or a different anonymous person but I'm guessing you're the same) think they're being silent about. So I asked you. You feel they're silent, so you could easily tell me what type of information they could be providing but aren't. I could contact them and ask about their silence. Let's see how that would have gone:

Me: Good morning. I hear that you are being silent, specifically regarding the PinePhone. Why are you doing that?

Them: We're not being silent.

Me: I have a statement from an anonymous person online that says you are.

Them: What does your source say that we're being silent about?

Me: I don't know; they wouldn't tell me.

Them: What evidence was provided that we're being silent?

Me: Not sure. They claimed deleted blog posts but I couldn't find them and they wouldn't point those out either.

Them: So you're asking us about an opinion from a person who wouldn't provide any specifics, whose allegations aren't proven, and you have no reason to think they have special knowledge about this stuff?

Me: Yes, that's what I'm doing. They said you are silent, so you must be. Tell me why.

Them: We've posted blog posts regarding the PinePhone several times in the past months. One in September, two in August, two in July, one in June.

Me: I know you talk about the phone a lot, but you're being silent about some things. Why?

Them: What things?!

Me: I don't know, you tell me.

I thought you actually had something of relevance. You could have pointed me to the deleted blog post. You could have stated your opinion on information that was insufficiently explained. You could have just said "They're being silent about issue X". Want to try any of those?

doublelayer Silver badge

I also appreciate water resistance as a feature of phones I might buy, but it's hard to properly seal a device for waterproofness and keep it this repairable. Some things can be done; waterproof isn't incompatible with SD cards or removable batteries. It does make it a little tricky to take the main board out, put in another one, and still have the result be waterproof. They might instead create a waterproof case to put the phone in, which would make the device bulkier but would mean they could obtain both their goals.

doublelayer Silver badge

Re: Alternate use...

Could you specify the questions that aren't being answered? In an attempt to inform myself, I searched for the blog posts that were deleted, but I couldn't find them. At the time of writing, the official blog contains nineteen posts from 2020. Going to the Internet Archive, I've searched through their historical captures of the blog and I have not found any posts in those captures that don't currently appear on the blog from Pine64. I only looked at posts in 2020, so if they only deleted years-old posts, I didn't search that far. They do bring up phone-related things from time to time, so I'd be curious to hear the things about which they're silent.

doublelayer Silver badge

Re: A suggestion for a long life

Possibly, but even when 5G does happen, it isn't going to make 4G obsolete. It took a long time for 2G and 3G to die, and that's only in some countries. Europe especially has kept these around for several more years yet. Therefore, I'm not sure it's that important to include it since it's not core to the device continuing to function; by the time 4G isn't being used anymore, the biodegradable back cover will probably no longer exist.

doublelayer Silver badge

A suggestion for a long life

To all people developing devices like this, which are supposed to run a long time. There's just one thing you need to do to guarantee my confidence, but it will also help you a lot with extended support. Find a custom version of Android known for releasing updates, my preference would be Lineage OS, and add support for your device there. You probably don't have to worry about updating it to new versions of that either; even if it doesn't happen, people will still be on the latest security update. If your device is popular enough among the community, and being a device with manufacturer-guaranteed support will probably help, someone else will do the update work for you. Meanwhile, I will have confidence to purchase your device.

I use my phones for long periods before replacing them. One of the reasons I can do this is that I use software which continues to have available security patches and even the occasional new feature. I have succeeded thus far without causing damage to the hardware, so the warranty is not the primary concern for me. It is certainly useful, but I'm mostly planning that I won't need it often if at all. Software support is more critical.

doublelayer Silver badge

Re: Alternate use...

You might want to look at the PinePhone. While its specs are worse than this one, it is designed to run a variety of Linux distributions and provides the resources needed to easily port things that aren't yet in the list of thirteen working distributions. It is also easy to repair (Youtube video demonstrating disassembly. If Linux is what you want, this might be a more reliable way of guaranteeing that you'll get it. One note, I don't have one of these and can't vouch for its quality.

ICANN begs Europe: Please fill in the blanks on this half-assed GDPR-compliant Whois we came up with

doublelayer Silver badge

Re: Whois lookups used to be useful

Depending on your country, most likely all large-enough companies and all charities are already registered somewhere. That somewhere is usually the bureaucratic entity responsible for verifying filings, meaning you know that what is there is at least a little verified. It often includes a web address if the company concerned has chosen to provide one.

Using whois as a proxy for this has two primary problems. You're trying to verify details about the company or to verify that the domain belongs to them. Here's how that breaks:

Verify that the domain is theres: If I'm setting up a fake domain, I can easily put in the information for the place I'm impersonating. It's not independently verified and has never been, so nothing prevents me using that mechanism. I can include a phone number that's intentionally mistyped or, if I think my victims are likely to actually test it, I can set up a phone number for the purpose. Or I find a number for the actual organization which nobody answers and include that. But let's be honest, if I'm a scammer I'm probably planning that my victims aren't going to put that much effort in anyway so I could probably ignore those few who are suspicious enough to call a phone number in a whois record.

Find details about the owner: You're not going to find anything of use. If the company wants you to contact them, and they probably do, you'll find addresses, phone numbers, and email addresses or contact forms on their website. If they don't, you can probably find those details on a map or phone book. Meanwhile, lots of places that aren't companies may wish you not to have those details to avoid spam, disruption, or harassment.

It's in their DNA: Nobel Prize in chemistry goes to pioneers of the CRISPR gene-editing tool

doublelayer Silver badge

Re: And electricity will be so cheap it won't be metered!

"'CRISPR doesn’t allow the insertion of new genes, just the modification of existing ones.' is mildly reassuring."

Too bad it's wrong. By removing an old gene and placing a section of DNA nearby, the new section can come to replace the old section. It relies on the cells' standard repair mechanisms working as expected, so it's a fiddly process to run right, but you can absolutely replace large chunks of DNA with custom chunks. You can call this a modification, which it technically is, but it can be a modification along the lines of "delete these three pages and rewrite them from scratch". Even when a length limit is hit, two treatments could perform rewrites right next to one another to double that limit (and so on). The current technology means doing this to humans would be dangerous, because there's always the chance that the new chunk gets read wrong or doesn't insert properly, but experimentation on flies will improve this dramatically. It's also unlikely that people would often want to completely rewrite a section rather than replace it with something known. I don't think this is a cause for fear, but we can only decide on the ethics if we're honest about the scale of changes that could be performed with the tool.

UK privacy watchdog wraps up probe into Cambridge Analytica and... it was all a little bit overblown, no?

doublelayer Silver badge

Re: Your next lesson: How to miss the point 101

Well, there are many points to this article, and the one that got the most words was the ICO's conclusion about the lack of success to the use of the data. That's a valid point. However, since it is the ICO we're talking about, let's look at what they're supposed to do.

"Our role is to uphold information rights in the public interest. Find out more about the legislation we cover. [Data Protection Act] [Freedom of Information Act] [Privacy and Electronic Communications Regulations] [General Data Protection Regulation] [Environmental Information Regulations] [INSPIRE Regulations] [eIDAS Regulation] [Re-use of Public Sector Information Regulations] [NIS Regulations] [Investigatory Powers Act]"

Their point is data handling and privacy, not election security. They have pointed out that some of the things they talked about are really the purview of other parts of the U.K.'s bureaucracy. What is firmly part of their responsibility is data privacy legislation enforcement. In that area, it doesn't matter whether I've succeeded or even tried to do anything malicious after I got your data illegally; if I have the data and shouldn't or did something with the data I have which is not permitted, I'm equally culpable of the crimes the ICO is there to deal with. Since it's the ICO we're talking about, I think this point is quite a bit more important than several others we could talk about from this report.

doublelayer Silver badge

Re: Nothing to see here...

"It was personal data supplied TO CA from Facebook - who were supplied by idiot users who filled in stupid quizzes...."

That's a very poor summary of the way that worked. Try this instead:

It was personal data supplied TO CA from Facebook - who were supplied by idiot users who trusted Facebook to only give data out when the user of the profile made it public and only from profiles which consented to the data release, not a recursive search through a bunch of friends who never agreed or knew anything about this.

The small number of users who agreed to the quiz agreed to a limited data release, not the release of everything (which is what happened). The people they had connections to did not agree to any of their data being released (it was), and were not told that their data had just been sold off. As much as the public should know that Facebook isn't to be trusted, it takes things like this to really demonstrate that fact.

After ten years, the Google vs Oracle API copyright mega-battle finally hit the Supreme Court – and we listened in

doublelayer Silver badge

Re: will have to think about getting a license each time he/she overrides a library method

"No, there's no equivalence between writing your own new function with the same signature and copying 37 files of 11.5 KLOC."

When those 11K lines are a bunch of function declarations, yes there is. If I create enough functions with the same signatures, I'm copying those lines one by one. I want a library that implements archive operations with a different format so I create a class implementing all the same functions that the original .zip one handles, I've copied twenty lines in a row. Then I decide to implement a new module which does mathematical operations faster, so I retype each line in the mathematical module and implement the functions differently. While I'm speeding it up, I think I can get AES functions to take advantage of hardware acceleration, so that's another set of lines copied.

These lines have to look similar because the function name is the same, the parameter names are the same, the parameters have the same types, the parameters appear in the same order, the function returns the same type, and the function is in the same class. Certain other parts might be skippable, for example comments, but if I decide to properly write comments for my functions, they're going to say similar things. Why would I ever do this if I expected the company who wrote the original interfaces to sue me for my hundred copied names?

Google copied the names for a lot of functions and classes. They reimplemented basically all of the ones available. In other words, they did what you just said I could do, and they did it five thousand times. Why am I allowed to do it but Google isn't?

doublelayer Silver badge

Re: almost certainly prevents me writing down the list of names myself and going from there

Except for some mistaken copying of a few lines, what Google copied was a list. A list of functions. Just like my list of functions. Oracle claims that this code, the declarations of the API they own, is theirs to control. Whether someone copies the file containing the list or writes down the list, it's still a list and contains the same items.

Oracle claims that copying that code is a violation of their copyright rights. They're not hinging it on the nine lines accidentally copied; everyone agrees that wasn't allowed and the lines were removed. They're basing it on the 11K lines that remain. Here's the problem with the argument you're making. Either those lines are copyrightable or they're not. If they are, then it doesn't matter whether I reorder them or make slight modifications, whether I copied them with a clipboard or typed them manually, I'm not allowed to copy them without permission. Oracle owns the text and I'm only allowed to use it if they approve. You are arguing that Oracle can copyright just those declarations, but that it would have been just fine had Google somehow written the list themselves. Not only is that impossible, but it is directly contradicted by copyright law; copyright law doesn't care how I duplicated work, whether I ran a book through a photocopier, got a bunch of blank paper and copied it out by hand, or had someone else play a word game to give me each word in sequence.

There are two logical ways to resolve this. The first method is to state that APIs are too basic to copyright, being lists of names. In this case, Google can keep using their file. You seem to disagree with the legality of this option. The alternative is to say that they are copyrightable, and therefore to copy the essence of them without permission is forbidden. In this case, it's not possible to take the steps you suggest to get around that. The two APIs I wrote above are the same. They're reordered a bit and I dropped some comments, that's all. But copyright doesn't care about this. If I dropped every second page from a book and randomized those pages before publishing them, I still committed copyright infringement against the author. Even if I rewrite those pages without reading them myself through some complex arrangement.

doublelayer Silver badge

Re: but reimplementing them is what Oracle thinks they can forbid you from doing

Yes, that is exactly what they think they can do. It's simplified, since they think they can prevent you from doing it if you haven't complied with one of their licenses, either the GPL or one where you pay them, but they think they get to set the terms under which you can create functions with the same names and parameters. They think that, if you don't follow the terms, you aren't allowed to create those functions. They might end up being right according to the legal system, but all we're discussing in this thread is what that could mean later.

Reimplementing an API doesn't require copying code, but it does require writing very similar code. If the original API reads like this:

int factorial(int n); //returns -1 if n is invalid

int fibonacci(int n); //warning: negative numbers means undefined behavior

There's only so much you can do to create a reimplementation. You can change lots of things, but probably the most you can change and have it still work is this:

int fibonacci (int x);

int factorial (int x);

The person who typed that may never have seen the code specifying the previous API, but their code necessarily looks very similar. If copyright prevents me from copying a list of function names, it almost certainly prevents me writing down the list of names myself and going from there. No matter how I change the comments, spacing, or parameter names (and I probably shouldn't be doing that), it's going to end up being basically the same.

doublelayer Silver badge

Re: Nine Laypeople

Judges don't live in isolation, but some things are sort of hard to understand if you've never learned about them. How does one operate a phone? They know that. How do you manufacture a phone? They have a fairly good idea. What is the difference between an API, a language, and a functional implementation? They have no reason to know that.

It's not that they live in isolation but instead that very few people know that kind of detail. Things we assume everyone on the comment board understands are things the general public has never heard of. I present you the following challenge: find ten random people who don't now and haven't before write code or administrate complex computer systems. Ask them the following questions, which I'm sure we could all answer in an instant. One point for understanding what the terms mean, one additional for getting the details right.

1. What does an operating system kernel do and what does it not do?

2. What is the difference between ROM, RAM, and nonvolatile storage?

3. What does compiling code do?

4. What is the difference between little endian and big endian encoding?

5. What is an API?

6. What is the difference between an IP address and a MAC address?

7. What is an ISA and which one or ones are you using?

8. Identify a piece of software you use. What language or languages was it written in?

Run this test on the nontechnical public. I'm guessing you'll see a lot of zeros, the occasional one, and maybe a two. Not a sixteen. You don't need to be isolated to not understand points core to the topic.

doublelayer Silver badge

Re: The devel is in the details

"* OpenGL is under a pretty liberal BSD-style licence. There is a trademark licence treated separately, but that isn't involved in the Oracle vs. Google case."

This one probably holds. Worth keeping in mind that the person you're replying to specifically stated that they hadn't checked, so while this one's choice of license makes it unlikely to take advantage of a precedent, it could have fallen into it had the developer made a slight change to the license chosen.

"* Octave/Matlab; languages, not an API."

A language and an API are very similar. Both take creative effort and specify a way of running things, the implementation of which is provided later. I would not expect them to be treated differently.

"* SQL is an ISO standard and a language, not an API; anyone can buy a copy of the standard."

Anyone can read a copy of Oracle's Java APIs, but reimplementing them is what Oracle thinks they can forbid you from doing. Someone who decided to license SQL could allow you to purchase a copy and read it, but woe to those who try to reimplement it without receiving permission. This is not unusual with standards; if I try to reimplement the LTE specification from its standard without purchasing licenses to the components, they would be very grumpy. I also contest your language-not-API distinction here. I don't think it matters anyway, but I think it's also incorrect in this case. SQL may be both, but it provides a series of functions with parameters. That's effectively an API, it's a list of possible functions which exist. SQL also includes a language in which the functions are called.

doublelayer Silver badge

Re: Status quo?

To clarify, it's the legal status quo in this case because it's what the previous judgement is. When cases go to the Supreme Court, it is to either uphold or overturn the ruling of a lower court (simplification, but close enough). The opinion of that lower court is therefore considered the current approach unless it's overturned. This is why, for example, the opinion of the lower court stays if the court has a tie vote. This is smaller than it sounds; it mostly applies to one case. As a case rises through the appellate system, what the status quo is could flip a few times before the case is finally over. Once the case is over (taken to the Supreme Court and decided there or one side concedes defeat instead of appealing), that decision could become a much larger status quo that applies to lots of other cases and people.

A decades-old lesson on not inserting Excel where it doesn't belong

doublelayer Silver badge

Re: 65536

I'm guessing they didn't want anyone to say they'd overstated what the screens or image formats could do. Then again, it didn't seem to hurt the storage industry much when they used a definition for kilobyte, megabyte, and gigabyte which was not the same as the definition memory manufacturers came up with, or the portable tech industry when they dramatically overstate battery life.

doublelayer Silver badge

Re: Thingies cat

You hire people based on a diligent attempt to establish their abilities and responsibility. Only if you made that effort in good faith can you start deflecting blame. It's not enough to find a person, hire them without checking, and blame them for anything that goes wrong. Similarly, if you hire someone to do a task, it becomes your responsibility to get enough information to determine whether they're doing what they were hired to do. Sometimes you may hire someone else to help you manage that task, but this just increases the size of the tree which you still have to monitor. If you didn't do enough to validate that the people you hired were capable of the job and were actually doing it, you still take the blame for things when it turns out they weren't.

DigitalOcean decides to head rivals off at the PaaS, floats App Platform to deploy, run code without juggling servers

doublelayer Silver badge

Re: Hack attack

It's certainly smaller than a lot of other places, so you're less likely to see it if you just look at who runs the servers for everything you use. However, it's worth looking at all the other attacking IPs in your logs, because they're going to represent a lot of the internet. It's really easy to try automatic logins on your site, and people will use any cloud service, VPN, or botnet to let them do it. Unless some provider makes a point of not taking down the systems of people who are particularly malicious, they're just like any other provider. To the best of my knowledge, DigitalOcean is usually quick to respond to abuse requests and is not at all a bulletproof service provider. People use it when launching attacks because it's cheap and convenient, which is basically the same reason someone else might choose to run things there as well.

UK, French, Belgian blanket spying systems ruled illegal by Europe’s top court

doublelayer Silver badge

Re: Nothing rhymed

I don't think that's how any of that worked. The history seems to be that some people worked out a way for laws to not conflict maybe while others did what they wanted to, in many cases ignoring even those people trying to stretch the letter of the law. Those who created the spying programs didn't care what the law said they could do, or even what their own lawyers said they could contort the text into allowing, but instead did everything they could come up with. When laws changed or courts informed them that they needed to stop, they just didn't and waited for the next case.

Take this chunk from the decision:

“in situations where a Member State is facing a serious threat to national security that proves to be genuine and present or foreseeable, that Member State may derogate from the obligation to ensure the confidentiality of data relating to electronic communications by requiring, by way of legislative measures, the general and indiscriminate retention of that data for a period that is limited in time to what is strictly necessary, but which may be extended if the threat persists.”

Here's how that chunk will get used:

"in situations where a Member State is facing a serious threat to national security that proves to be genuine and present or foreseeable,"

"foreseeable". "Foreseeable"! "FORESEEABLE"! As long as the people at the spying organizations can foresee something bad, they can do many things. I can foresee bad things with ease, and I guarantee you that they can foresee much worse things. Here they have complete authority to activate the powers granted them in the rest of the quote. But of course that section will still impose serious limits:

"that Member State may derogate from the obligation to ensure the confidentiality of data relating to electronic communications"

All good so far, they can throw away their responsibilities. Restrictions are coming, right?

"by requiring, by way of legislative measures,"

Oh no. They'll have to get the legislature's support. This is a major blow, because they'll have to inform the public about what they're doing and why. Except the laws being challenged here already support the measures, so nothing new is required.

"the general and indiscriminate retention of that data"

Well, they didn't hold back about adding sufficient adjectives to let the organizations do whatever they want, did they?

"for a period that is limited in time to what is strictly necessary,"

Ah, they're throwing us a bone. They can do whatever they want, but only for a limited time. Then they have to throw out their data and start over. At least they'll only have a year of my data at any time. Sure it'll be the most recent year, but still, it's nice that they're giving me that.

"but which may be extended if the threat persists."

Remember that the threat will persist for as long as someone can foresee it. And that nobody gets to decide that the foresight is wrong or question whether the threat persisted. I foresee that a new country will form called Evilania, and it will invade our country. As long as I continue to foresee it, I can extend the retention timeline as long as I like.

Big Tech to face its Ma Bell moment? US House Dems demand break-up of 'monopolists' Apple, Amazon, Facebook, Google

doublelayer Silver badge

Re: Sounds like the case against Apple

"What Apple would need to do in the meantime is effectively turn iOS into a hypervisor, and make every app run inside a separate VM so it can't possibly touch another app or the OS except through defined methods."

They already did that. The primary worries about an insecure app is that it might find a vulnerability in that hypervisor, which has happened several times, or that they might find a valuable sandbox that allows access to lots of things. For example, if they get into a sandbox which already has access to contacts, the global filesystem, and the microphones, the insecure code doesn't have to escape the sandbox to do malicious things. To the extent that Apple's review is focused on real security scanning, this is the kind of thing they want to prevent.

doublelayer Silver badge

Re: "AD requires a CAL which means its not financially viable"

Yes, you can. Manufacturers get to choose how they go about it, but some have chosen to sell some of their products with Linux instead of Windows with a corresponding reduction to the price. Dell and Lenovo have done this, but only for specific machines in their lineup. You can of course purchase from a company that specifically focuses on Linux machines, of which there are several.

doublelayer Silver badge

Re: Give the FTC more power?

While I'm not aware of Joseph Simons having done anything to bring on ire, it's possible that the original poster was instead referring to the person who currently has the power to remove and replace commissioners should they wish to mess with something. Maybe the post was intending to call for increased oversight of a bureaucratic entity should its powers be increased. Or maybe it was just an acronym confusion. I'm not sure.

Bad boys bad boys, what you gonna do? Los Angeles Police Department found fibbing about facial recognition use

doublelayer Silver badge

Re: Its coming

No, we do not agree. A working facial recognition system, if it's even possible, would be a nightmare. Imagine what a totalitarian country would do with something like that. Imagine what a malicious operator in a democratic country could do with something like that. It could be awful. What it does is provide a mechanism to track a person wherever they go without alerting them and by providing a smokescreen of a potentially useful purpose.

Lots of things would catch criminals faster and reduce crime rates. Some of those things should be tried. Some of those things need to be avoided, even with the extra crime, to avoid creating a terrible situation for the innocent. Systems which destroy privacy or give the police unchecked power are among those types. A working facial recognition system, for that matter even one which doesn't work, does both.

Institute of Directors survey says most bosses expect no mass return to the office if COVID-19 crisis ever ends

doublelayer Silver badge

"Have we really become such an emotionally weak society that out up-line managers must spend time worrying about out "mental well being" that worrying about getting the job done and making the company more profitable?"

Not quite. It's always been the job of a manager to worry about such things because the workers' mental wellbeing directly affects their productivity. If workers hate you, they'll try to leave and you'll have to hire new ones. Reduced profit. If workers are constantly distracted by a poor working environment, they'll get less done. Reduced profit. If workers are in a combative environment where they have to essentially fight against one another, then they'll spend time defending themselves or planning their own attacks instead of getting stuff done. Reduced profit. If workers are subject to too much work and burn out, expect them to have other health problems, therefore taking more time off and reducing productivity. Reduced profit. It's been known for as long as there have been workers who had a choice about whether to stay working for the company; it is the managers' responsibility to ensure that workers are in a good enough condition to continue doing work, and those who fail to do it usually see productivity slump.

Big IQ play from IT outsourcer: Can't create batch files if you can't save files. Of any kind

doublelayer Silver badge

Re: Classic techie mistake

Again, it doesn't help against anyone else. If he could do it, anyone else could do it. If he was going to do anything dangerous, he'd have done it before, or instead of, telling someone about the problem. It's missing the point and badly to think about sacking him; either you don't care enough about the stuff in the safes to go to the expense of updating the locks in which case you can ignore the problem, or you do in which case your attack landscape is anyone and everyone who could conceivably get to the safes. It sounds like they completely ignored this, and given that their project was being spied on by Soviet agents which they'd rather not have know the information, they probably should have put some thought into it.

Apple seeks damages from recycling firm that didn't damage its devices: 100,000 iThings 'resold' rather than broken up as expected

doublelayer Silver badge

Re: They can't fix it, but I know a man that can..

Welcome to the world of used devices. When you go online and buy a used device, it's usually not from the manufacturer. It's from some user who may or may not have damaged the device, meaning you know you're entering the realm of possibly extensive damage. The same is true if you buy from these recyclers or if you buy from someone random who lives near you; there's always the chance that what they call "lightly used" means "only dropped on concrete three or four times". For this reason, I rarely if ever buy used devices that I think are likely to have become damaged, phones among them. When buying other used devices, I require that I get to test things before payment. Those who choose to enter this market know what they're getting into. I have no reason to believe that the phones sold this time were any worse than the average user-sold used device.

That said, it is still a breech of Apple's contract, which is a legal contract. I would prefer that the contract didn't get made, but it was. I'm not saying here that what the recycler's employees did was right or that they should get away with it without consequence.