The Register Home Page

* Posts by doublelayer

11434 publicly visible posts • joined 22 Feb 2018

Broken your new Surface Go 2 already? Looks like it's a bit more repairable this time

doublelayer Silver badge

Re: I suspect not

I agree that sentence is unclear. I looked at the source. The cameras seem to come out just fine. See approximately 51% through the video to see it. Not that that part is particularly important, but the sentence break should have been after the "along with the cameras" chunk. Probably the clearest phrasing would be "The Micro SDXC socket and cameras can be removed easily, but the other components cannot."

If you're appy and you know it: The Huawei P40 Pro conclusively proves that top-notch specs aren't everything

doublelayer Silver badge

Re: reviewer uses Google extensively

Unless they changed their mind yesterday, the bootloader is locked and I haven't seen anyone successfully break it. So if you get this, you have to accept the Huawei flavor of non-Googled AOSP. That's why I'm not that excited about this--I dislike Google too, but I don't see much benefit in running equally unwanted Huawei code.

doublelayer Silver badge

Re: If you are desperate for Mountain Views spyware

I'm glad that works for you. I've used it as well, although not that often. My experience has been less reliable. Some apps work perfectly. Some are tagged as GSF-dependent but also seem to work fine, but I'm just waiting for a problem. Many others that have been tried work only to request their permissions, then keel over. For me, that's almost always fine. I rarely need an app urgently, and I can usually find an alternative. Also, I know what is happening. I don't think the general public is in a similar situation. If their experience of using a client such as this, assuming someone installs it for them, is that half the apps they want* crash immediately, they won't be that impressed. That would restrict the market for Huawei devices outside of China to two small subsets of the population: 1) Technical people who probably don't want Google anyway and know how to get around it and 2) people who just don't use many apps.

*The estimate of half is quite rough, but I think it's actually higher. Many in the public are big users of social media apps or games, and I think both are likely to make heavy use of Google's APIs. I haven't done a test because I use neither category.

doublelayer Silver badge

Re: Flashy

Oh, it looked like that to me too. I prefer my phones ungoogled, which I mostly get via Lineage OS. So having a manufacturer that doesn't include the Google layer...it sounded like quite the helpful approach. I wouldn't have to wait for a device to become supported. I wouldn't have to build the image myself. I wouldn't get the choices I get with Lineage OS. Uh-oh.

There's the rub. I want Google off my phone because I like the certainty that I'm not being tracked by software I don't have control over. Huawei has removed the Google-specific layer. They have instead added their own layer, and I can't trust it, and I can't remove it. All I have now is two choices for whose untrusted and unverifiable software is preloaded. I will have to go to similar lengths to get rid of it, but unlike certain phones that ship with Google's apps preinstalled (Xiaomi's devices, for example), I have little hope that Huawei will ever let me reflash it. Why should I consider this a benefit? Code that I didn't want and can't trust, but would be generally useful if I had to use it has been removed and replaced with code I still don't want and can't trust but is by most reviews less useful.

You can't have it both ways: Anti-coronavirus masks may thwart our creepy face-recog cameras, London cops admit

doublelayer Silver badge

Re: A solution occurs to me

Yes, for the record if anyone is unsure, my preceding comment was intended as humor. But if some piece of equipment has to be destroyed by idiots, I have a preference as to which type they go after.

doublelayer Silver badge

A solution occurs to me

Hey you conspiracy theory people--sorry, I mean truth-knowers, you've made a mistake. 5G isn't causing the COVID outbreak. No, really. Look at the deployment maps. The masts you're burning are almost all 4G ones, and we've had 4G for quite a while, so that can't be doing it. You know what's new, having been set up right before this started happening and in London, where the U.K. has the most cases? That's right, a bunch of facial recognition cameras. Well, that's what they say they are. All you need is a few devices out there spreading contagion for it to spread from there. These are evil disease-causing equipment. Just look at the facts. You were burning the wrong things. Hint hint.

Note: Obviously, this is untrue. The facts don't support that at all. It'd be ridiculous to think of this. Even these people are intelligent enough to realize this fallacious argument. [Truth-knowers, don't trust the person who put this footnote in my comment.]

Better late than never... Google Chrome to kill off 'tiny' number of mobile web ads that gobble battery, CPU power

doublelayer Silver badge

Re: How about no execution whatsoever?

No autoplaying videos, but if they want to embed a clip into the ad so I can choose to view it after reading their text, that's fine. I won't be doing it, but it's fine if they choose to. HTML5 has support for it already, so I have no problem killing their JS rights.

doublelayer Silver badge

Re: Bugger AdBlock, it's Internet advertising that's theft.

That point is relevant, and I imagine you'll find many who won't accept it, but the analogy still applies. In the case of a collect call from a telemarketing system, they are undoubtedly paying for the line capacity, the phone, the person talking, and for any call where the other party doesn't accept the charges. That fact doesn't make the theoretical practice any less odious. In occasions where the data usage is very extreme, I think there's reasonable grounds for complaint. Not that it would do anything, but nonetheless reasonable.

doublelayer Silver badge

Recently

"We have recently discovered that a fraction of a percent of ads consume a disproportionate share of device resources, such as battery and network data, without the user knowing about it," (Marshall Vale)

This is great news. It isn't that Google just doesn't care and will allow anything through as long as they stand to get some money out of it. They just have a six to eight-year latency period on realizing really obvious things. And here was I thinking that they were ignoring these things on purpose. Fantastic, really. If this pattern holds, we might see the following headlines in the future:

2020: Google recently discovered that Android updates are important, and they need to do something to ensure people get them where they punish noncompliant manufacturers.

2021: Google recently found out that malware embedded in ads is concerning.

2022: Google has become aware following a bit of research that Android users would like extra security in their mobile operating system.

2023: Google recently discovered that, if you have a motto that tells you not to be evil, and you cancel that motto, it sounds really bad.

2024: Google realized not long ago that people seem to care a bit about their privacy.

2025: It has come to Google's attention that people are worried about their copying of certain information without compensating the people they copied it off, and maybe someone should come up with a method that uses neither the crazy suggestions of the original publishers or of Google.

2026: Google has come to the conclusion that becoming the market leader in product obsolescence might not be the nicest thing to do to their customers.

Xiaomi Mi 9 owners furious after dodgy Vodafone software patch bricked their mobes

doublelayer Silver badge

Re: I'm curious

The updates released by carriers are just placed on the carrier's servers, with the phone locked in some way to only get updates from those servers. You can contact those servers however you want, though. If you have a carrier-locked device that you didn't connect to their network, it still gets updates*.

*It actually doesn't get any updates, but that's because the carrier never releases any. If they ever did release one, your phone could download it and install whatever bugs it contains with no difficulty.

doublelayer Silver badge

Re: Worse than that

That's great. But that's because Xiaomi has decided to be nice. The point being that neither Google nor the carrier (I'm assuming this was not associated with a carrier) care at all about providing you updates. Any credit there is for maintaining the phone this far goes to Xiaomi. There is such credit to go out, but not because this is a very long time. Just because most of the competition is lamentably bad at it.

Stop tracking me, Google: Austrian citizen files GDPR legal complaint over Android Advertising ID

doublelayer Silver badge

Corruption is a good consideration, but you don't fix corruption at high government levels with detailed data collection on the average citizen. In fact, that gives you extra methods to maintain corruption, because people might only get privacy if they have sufficient connections, and they now have a massive database which can be sold to lots of people with cash to spend.

You attribute totalitarianism to revolution, and you're often correct. However, it doesn't always work that way. There have been many countries where someone came to power in an election that was somewhat democratic (sometimes with a lot of voter intimidation, but not always), but then turned the country into a totalitarian nightmare. The European example that is most well-known is Italy. Examples can be found elsewhere though, from early 1900s Japan to modern-day Venezuela. The dictators who eventually became beyond democratic removal were able to do that by leveraging powers of previous governments. That's one reason we want lots of limits on governments, but it's not enough to relocate those powers to a business or military area, because then you've just moved the problem around. Tracking citizens would be very useful to a dictatorship, as you've pointed out and as countries like China prove every day.

In my opinion, what leads to totalitarianism is access to power. If a revolution creates a power vacuum, then it is now easier to take over, so people will try. If you destroy a country, there will be a lot of displeasure, meaning that power is easier to get with popular support, so people will try. And if you make the government or anything else all-powerful, then you have increased the potential rewards of controlling that thing, so people will try.

doublelayer Silver badge

Re: In all honesty

"I would rather no one knew what i was browsing or buying and i definitely do NOT want targed ads. Infact i do not want ANY Adds."

I don't like ads either. You and I are perfectly within our rights to try to avoid ads. However, it's quite a hard argument to make that advertising itself violates our rights. If we get everybody to agree, we can try, but I am not going to put much effort into an anti-advertising push. I will put that energy into anti-tracking policy, though, because that causes a lot more harm to everybody and is already legally dubious. The result may be that there are still ads, but they are tailored only to the current environment or to small amounts of data you've knowingly decided to let the advertisers use. Should we get that, I would view it as a profound victory.

doublelayer Silver badge

Re: In all honesty

I agree, and I think my previous restrictions implement that. Namely, the retailer can record the shopping history of people and associate it with the account, but they cannot release that information and they cannot further track. It would be nice for them to offer accountless purchases, but even if they choose not to, a person can get anonymous shopping by setting up multiple accounts. Well, they can get untracked shopping; buying online is almost intrinsically attached to some identifiers because you have to pay and cash doesn't work and you have to get delivery of anything physical.

doublelayer Silver badge

Re: In all honesty

I'm well aware that phones do a lot of tracking. My point was that they don't need to, and we don't need the alternative to be a subscription price for the use of the phone. Most companies make plenty of profit on the phone purchases, and then they are willing to make extra profit off the user data. If one is made illegal, they'll be fine. Even those few who sell their phones at a loss will just have to increase their prices to deal with the fact that a predatory practice of theirs isn't allowed anymore. I am fine with that.

doublelayer Silver badge

In all honesty

In all honesty, everything you said is wrong.

"governments need to decide if targeted advertising is legal or not [...] All of this grey area crap is just vacilliating around the real question. Should you be able to gather data for people for the purposes of monetising them."

There is a grey area, and it's important. Gathering information about what someone does on your platform so you can make recommendations to them on that platform usually doesn't draw much ire. For example, I don't care if Amazon records a history of things I buy and uses it to suggest products while I'm logged into the same account. The problems occur when that data is released or when collection isn't obvious. I'm not happy for Amazon to start selling that information to others, nor am I happy for Amazon to collect information about my browsing elsewhere or when I'm not logged into an account with them. It's a control thing. If Amazon only collects things I do on their platform and connects it to the logged-in account, then I can stop them doing that by not using their platform or anonymize it by using multiple accounts. If they do other things, I have no certainty about what is happening and certainly no control over any of it.

"If the answer is yes, then accept that it means companies hold data on all individuals if they use devices or services offered by those companies"

So if the answer to a very generalized question is yes, we basically give up on all controls? Because a lot of the question isn't about something that clean cut. A lot of the concern is about what the companies do with the data, how they collect it, and how much information and control the consumer has. These are the important questions, but you fail to mention them at all.

"if not, then we've got to be prepared to pay monthly for phones, email, websites etc."

Wrong. We pay for phones. It's called the purchase price and it's quite high. The software comes on those phones, just like there's firmware on your microwave. You don't decide you have to pay a subscription for your microwave, nor would you accept it monetizing you. The same applies to phones. While removal of some of the profitable ways to monetize users might mean more sites have to switch to a subscription model, it isn't guaranteed. Advertising wouldn't be made illegal--advertising tailored to the content or of a general nature is fine. Collecting information in an open and transparent way about what is collected, how, and what is done with it likewise would work. What you're serving us is a false dichotomy, and a very popular one among people who violate our privacy. You're telling us that having our data strip-mined is necessary to an internet of free services. Well, that's not true for all free services, it may prove false for many others about which we have no information, and for those that are left, we might be willing to pay that price.

US piles yet more charges on Theranos CEO, COO. We could do with good blood testing now... and this wasn't it

doublelayer Silver badge

Re: I know they were a bit fraudulent but.....

Let me see. Why might they not be there? Well, a few ideas come to mind:

1. They are very well-connected and used their power to stay away from justice.

2. They didn't know the company was fraudulent.

3. The company lied to them, so they believed the story the investors believed, so they didn't know the company was fraudulent.

4. The company got lucky in scoring so many well-known names to be on the board. They knew they would face major consequences if anyone on the board left it out of concerns, so they put in a lot of effort to lie about the progress so the directors wouldn't find out the truth and expose them, so the directors believed the story the investors believed, so they didn't know the company was fraudulent.

5. The company needed famous names behind them to dupe investors into trusting that they were so innovative, so they went after some people who had a lot of famous and well-regarded friends, so the company got lucky in scoring so many well-known names to be on the board. They knew they would face major consequences if anyone on the board left it out of concerns, so they put in a lot of effort to lie about the progress so the directors wouldn't find out the truth and expose them, so the directors believed the story the investors believed, so they didn't know the company was fraudulent.

One of these doesn't look as likely as the other ones.

The so-called piling on of charges is simple to deal with. Are the people being charged guilty or likely guilty of the things they're charged with? Then they can be charged with those things. If you find out that extra charges without any evidence are coming in, we can argue again. Until then, you're wrong.

doublelayer Silver badge

Re: "[they] argue that the case needs to be moved back to 2021"

They've basically admitted that they lied. They're not pretending all that much anymore, and those minor things they still lie about aren't convincing anyone. I really don't know what their current mindset is, but they're smart enough to realize that crowing about their impending vindication won't help them with anything, and it's time for them to stay in the shadows and protect anything they still have.

doublelayer Silver badge

Re: I know they were a bit fraudulent but.....

This is not an overhyped claim. It is a false claim. Consider the following two strategies for getting investments in a company that does a certain type of test. The example will be a brainwave scanner. In both cases, the company doesn't currently have the ability to do what they want to do, but they think it will be possible.

Claim 1: We have been investigating FMRI scanning and have plans to produce a portable model, approximately the size and weight of a helmet. We're confident that this is possible. We also have several interesting research programs that can take FMRI data, currently from the big lab-type machines, and produce interesting insights into neurological health and user focus. We think this will be a successful product when it's available at a similar price to a smartphone. Imagine all the people who could benefit from it. Our potential customer base could be massive.

Claim 2: We have created an FMRI machine the size of a helmet. We can show it to you but you can't buy one because we need to do some certifications first. Also, we have a program that can determine whether someone's at risk for Alzheimer's or Parkinson's, as well as more consumer-oriented information like focus patterns. We've tested that program on lots of people, but we're also developing new programs as we speak. The device can be sold at the price of a smartphone with a 12% profit margin, but that can be increased with cheaper manufacturing. We already have preorders from a couple retail outlets for a hundred thousand units pending that test.

The first claim is an expression of hope. It may be overhyped. The execs may think that it is a lot more likely than the techs think, but they didn't lie about having something they don't have. An investor who hears that sales pitch understands what is intended, but also that the development isn't finished. They know enough to be aware that there is risk and to ask for more details before they invest. The second claim is a lie. An investor who hears it will think the company can do things that it can't do. It's not hype, because hype is a method of saying true things in a way to make them more exciting than the raw facts. An investor wouldn't know that, and might make decisions based on that lie. There's a really big difference.

Huawei gets misty-eyed for the good old days (of a year ago) with maudlin P30 Pro remaster

doublelayer Silver badge

Re: One more reason...

It might be given the pricepoint, but for most users, neither feature is of utmost importance. Few places have 5G, so unless you're so annoyed with the slow speed of 4G that you feel you need 5G as soon as it is available, you probably don't care. The more modern chipset is faster, but if you don't do a lot of CPU-intensive work on your phone, you likely don't notice that. I'm not sure how many people there out there who do rely on that, but all the people I know don't have a clue what chipset is in their phone and don't really care about a faster one.

For the general public, I've seen people caring about the following features, in descending order of number of people I've heard complain about each feature or plan to buy a different device based on said feature:

1. Physical appearance of device.

2. Screen size and shape (E.G. people who really hate notches).

3. Headphone jack availability.

4. Battery life.

5. Camera quality.

6. Price.

7. Modernity of OS.*

8. Likelihood of continued security updates.*

9. Expandability, including dedicated SD, dual SIM, and replaceable battery.*

10. Support by alternate OS images, E.G. Lineage OS.*

*At least somewhat technical people only.

Incredible how you can steal data via Thunderbolt once you've taken the PC apart, attached a flash programmer, rewritten the firmware...

doublelayer Silver badge

Re: @Doublelayer

You're leaving out some steps:

Steal laptop from user: If they're in the airport, they likely still have the machine right next to them. Good luck with that. Stealing it with enough time to do the rest of the steps and return it unnoticed usually requires them to leave it somewhere from where it can be lifted.

Dismantle laptop: This step is fast. Well, it's fast for my computer as long as you have the correct screwdriver, because you just have to undo all the screws and lift off the backplate. For a computer which uses a lot more glue, it'll be much slower to get at the thunderbolt interface pads.

Attach reprogrammer: This needs to be a reprogrammer that already has the code for this specific Thunderbolt chipset and is wired properly for the interface in the computer. So it's not one-size-fits-all. A criminal can't just carry a simple box that lets them do it to every computer, but a prepared attacker with knowledge of the computer involved can use it.

Upload code: That's fast too.

Connect memory access device to port: This one can be the same device for all victim machines.

Copy memory: Yes, copy memory. A lot of memory. I'm currently using about three gigabytes, and I don't even have much running. Sometimes I'm using eleven gigabytes because I've got VMs running. If you're after sensitive stuff, you want to catch me then because the VMs contain the sensitive information. You aren't going to copy eleven gigabytes onto your portable system in five minutes. Thunderbolt is fast, but you need to also factor in the disk speed of the thing you're righting to, the bus speed of your attack box, any processing you need to do while reading, any delays in getting the memory accessed by the laptop's chipset, and on and on. That takes time. Once again, even if you did manage to steal it from someone in an airport, you need to return it to them quickly. This will add potentially long delays.

Reflash original firmware: This may be optional if your replacement firmware can still operate correctly, but if it doesn't, you have to put back the original code so they won't notice something's wrong as soon as they plug in a different peripheral.

Reassemble computer: Fast for mine. Good luck with some others. See IFixit for details.

Clean evidence of tampering from computer: Oh, and nobody had better have seen you disassembling a laptop in another airport area, because I'm guessing they'd get suspicious about what you're doing there. Having security called to verify you aren't turning a laptop battery into an explosive device wouldn't be great for you.

Return computer to the place where you left it: The user needs to not have noticed that it was ever missing. They also need to not see you put it back. Have fun.

Again, it's not useless. It's not so easy as the paper makes out, though, because they only timed how long it takes to attach an exploit device and prove the exploit successful, not how long it takes from theft to replacement with useful usage of exploit in between.

doublelayer Silver badge

Re: more of a neat trick than infosec Armageddon

Well, sort of. However, it does involve quite a bit of work to access the data, which means that it won't get used all that often. If it's a government doing the accessing, you end up in XKCD 538 territory. Similarly, it won't work unless the person has put the computer to sleep while the attacker has access to it. If it has been shut down or the battery died, the exploit produces nothing. So this also limits the viability of using that attack after the user has run away. The attack is also only needed if the user has encrypted their disks but hasn't done anything else to protect the data--if they also encrypt the file, the attack cannot get the cleartext of that file or the password, and if the user didn't encrypt the disk, then there is no need to do this.

While it's not useless, it only works in a relatively small number of cases, and in many of those cases, there is a more direct method of getting access. It's a good reminder to those who are concerned about an attacker of that level of skill and determination to avoid suspending to memory, but that has been known for some time.

Wanna be a developer? Your coworkers want to learn Go and like to watch, er, Friends and Big Bang Theory

doublelayer Silver badge

Re: Did I miss it, or C wasn't in that list?

I was quite surprised not to see C in the list. Sure, it's painful to write many types of programs in it. But surely people took courses in it at least? Maybe it's just that I took mostly systems courses, so nearly everything was at least partially taught in C, but someone's got to write operating systems, embedded code, drivers, programming language interpreters, ... Did the survey people just skip over all those people?

doublelayer Silver badge

Re: Correlation and causation

Well, at least those happy workers working forever. However, I generally prefer a job that is not paid by the hour over one that is assuming that I know how much time I'll be putting into both. The reason is that those jobs I've had that are paid by the hour have always involved an annoying filling in of timesheets with pointless levels of detail about when I came in, when I went out, what I did for every five minute section of the day, etc. Filling those out involved a healthy amount of trying to remember what I was doing several hours and ten intensive debuggings ago, then putting in some generalities and going home. Meanwhile, non-hourly jobs frequently just care whether the job got done, and if I work weirder hours or do one long and one short day instead of two normal-length days, they don't care and I don't even have to tell them.

Users of Will.i.am's Wink IoT hub ask 'Where is the love?' as they're asked to pay for a new subscription service

doublelayer Silver badge

Re: Tossed mine today

If you mean that literally, it would be preferable for you to bring the device to a place that recycles electronics. Many retailers will accept such equipment, though the list will vary depending on which country you're in. Some components may not just be wasteful to put into landfill, but may also be dangerous.

doublelayer Silver badge

Re: Cue the lawsuits in 3, 2, 1...

That may be the case, but there are still resources they can use to pay the judgement, or rather there are resources that could be given to the lawyers after bankruptcy is declared. All of their code and systems would be a pretty good haul, assuming you could find a way to profit from them. For example, you could release the code to the devices as open source so someone else could build an open services stack around them. Fine, that was wishful thinking. But you could sell the same subscription to the users, and it would be legal for someone else to do it as they never sold the products in the first place.

Alternatively, there is probably more money to be gained by a successful lawsuit than there is in the company at the moment. I'm guessing this subscription system wasn't a spur of the moment decision. It would almost certainly be found illegal. Therefore, it could be expected that doing this would lead to bankruptcy. If these facts are agreed to, then payments made to executives after consideration of the subscription idea could be seen as attempts to syphon remaining resources from a sinking ship, and could be clawed back. Getting those points accepted in court does involve quite a bit of effort, but given that one of the executives in this company is somewhat wealthy, the lawyers may consider it worth it to try.

Fancy some post-weekend reading? How's this for a potboiler: The source code for UK, Australia's coronavirus contact-tracing apps

doublelayer Silver badge

Re: Why?

You are misunderstanding several concepts. We'll start with decentralized data storage. This works, and the government doesn't need access. It works like this:

Your phone knows some random identifiers it's been screaming into the void. It also knows a bunch of identifiers it has heard from others' phones it has been near. So all you need to do to warn people you were near is to send a list of your identifiers to a public system. If they get that list, they can check the identifiers against their own list of the ones they heard, and if there's a match, they get an alert. Your name doesn't need to be attached when you send out the identifiers, and you certainly don't need their names.

Ah, but I see you are concerned that people will report unreliably, causing a bunch of false positives. A reasonable concern. So the solution is to give all the information to the government and have them do all the reporting? No, it isn't. A better solution is to give health providers signing keys. If someone tests positive and reports identifiers, their report is signed with a health provider key. You can't report without a key, or at least a report may not be trusted without a key. Keys only go to health providers.

You also are completely misunderstanding the utility of this app, if it actually has any. You seem to think that it's useful only by sending a bunch of data to the NHS. No, not really. They have information from tests, which they can use. The utility of this app is supposed to be that people know when they have to stay in quarantine. A warning from an app like this is not a positive test. Treating it as one would destroy any dataset. Nor is it a good reason to use limited testing capacity on that person. It would be great if we could get that many tests, but we don't have the capacity now.

For that reason, the app idea is very limited and may possibly cause more harm than good. However, you seem to only acknowledge the extremes--either the app is worthless or the app provides crucial data to health authorities. It is instead intended to provide information of tentative reliability to the public. Given that, there is little or no benefit in centralized data storage. Simultaneously, there is significant risk in centralized data storage. If we are going to have such an app, it is very important that it be decentralized in order to get sufficient uptake.

doublelayer Silver badge

Re: Best option, cheapest option

Warning. Potentially incorrect causal relationship detected.

"In Russia for example, everyone is encouraged at the first sign of symptoms or suspicion of them to get a test, that brings both early isolation and treatment helping to reduce the impact." leading to "So far the percentage of deaths compared to infected seems to be lower than the majority of other countries."

This could be caused by several things. The easiest one is that more people are getting tested, meaning the number of people who we know to be infected in Russia is closer to the total than the number we know to be infected elsewhere. If we acknowledge that there is a significant chunk of the population that is now or has contracted the disease but didn't get tested and either showed no symptoms or thought it was a standard cold, we could also have a higher denominator leading to similar death rates.

There are other methods for arriving at similar statistics. It could be that our lockdowns are being more effective at blocking transmission, meaning fewer people get infected, but those who do are more at risk of dying from it because they are more often elderly people in close proximity. Or that Russia has a test that produces reliable results faster, meaning people are caught earlier in the progression of the disease. Or that Russia has a worse test that produces a lot of false positives, but they are willing to live with that because overactive isolation can't really hurt. Or the thing you said. All are possible. None have been proven.

Go on, hit Reply All. We dare you. We double dare you. Because Office 365 will defeat your server-slamming ways

doublelayer Silver badge

"It's not possible to set up arbitrary email accounts in exchange server...? You know..... for testing...?"

I'm sure it is possible, but there are far too many caveats to want to do so. First, in order to trigger this, you need to set up five thousand such accounts. I don't know whether it's possible to run a batch setup process for that many accounts and then run a batch delete once testing is completed, but if it is at all painful I'd choose not to. Second, having that many test accounts puts a strain on resources. Five thousand mailboxes would take up a lot of disk space, whereas five thousand aliases going to the same place might not be counted as separate recipients for testing. Third, at least some systems are charged per mailbox, meaning you would pay a healthy sum for the privilege of testing.

Behold: The ghastly, preening, lesser-spotted Incredible Bullsh*tting Customer

doublelayer Silver badge

Re: Yes the users are bad

At some point, the world in general must have come to the (incorrect) conclusion that I prefer technical terms babbled out basically at random by users who think they know what these terms mean, but don't. For example, I was helping someone get some remote working up and running when this lockdown got into view, containing the following interaction:

Them: I know the VPN you set up and I'm connected to it, but the network doesn't work.

Me: Do you mean you have no internet access, no access to local resources, or both?

Them: No, the internet is working, but the server isn't.

Me: Ah. Local resources then. Can you go to [internal address deleted] and tell me what it says?

Them: No, that thing works. It's the server that doesn't work.

Me: The server doesn't work?

Them: Yes.

Me: The page you said works is on the server.

Them: I know that. The server is working, but the router isn't pinging the network when I ask it to.

Me: What specifically are you trying to do?

Them: I'm trying to access the network protocol.

Me: What is the end goal for what you're doing?

Them: I have to open the accounting data.

Me: How do you do that?

Them: I open this program and use it to open the database.

Me: And where is the database?

Them: It's online, but the firewall isn't letting me open it.

Me: You read that with an accounting program, right?

Them: Yes. That is working fine.

Me: What happens when you try to open that program?

Them: It crashes with an error message.

Me: What does the message say?

Them: It says the network driver address was invalid. [When finally read verbatim, it says the file couldn't be found]

The issue ended up being a configuration problem in client-side software. I helped solve it. If they could realize that server, router, firewall, and network aren't just catchall words that apply to any kind of technical thing, we could have skipped that and many other sections of that particular conversation. The most useful thing that I think would improve my impromptu support calls would be that error messages are only ever read verbatim and are read fully the first time I ask, without the typical response of "It isn't important" or "That's not the problem". It's surprising how many of these I get given that I don't work in support. These experiences and the many stories here have convinced me to stay away if I can.

Does a .com suffix make a trademark? The US Supreme Court will decide as Booking marks its legal spot

doublelayer Silver badge

Re: What I'm not clear on ...

Sorry to be vague. I was also referring to ownership in an IP sense. Apple doesn't have any ownership over the word "apple" because that would be ridiculous. Also, there are generally limits on how original and thus long you have to be to have any copyright ownership. So in general I think things getting a trademark don't have any other ownership, physical or intellectual, attached to them. Just using it for some purpose and having nobody else use it for a similar purpose is sufficient to ask for one, subject to some extra restrictions about what you'll eventually get.

The reason I think this is the other things that people have trademarked. As the article points out, phone numbers that are attached to a brand can be trademarked, but they don't own that either. Though there are various reasons to balk about granting their trademark request, I don't think that is one of them--if they relinquished the domain name, then they wouldn't be using that trademark anymore (debatable, but almost certainly), and trademark rights expire automatically if you stop using them.

doublelayer Silver badge

Re: What I'm not clear on ...

Well, although they don't own it, nobody else does either and they're the only people who are associated with it. Similarly, Apple as a company does not own anything related to the word "apple", but they are able to trademark it for use with computers because they were the first to use that name. In fact, I don't think trademarked things are ever owned--the trademark is the protection because you can't own short sequences of letters or pixels.

doublelayer Silver badge

It seems simple, but it must not be

The logic would seem to be somewhat straightforward, namely that you cannot trademark an obvious term for an obvious purpose, you can trademark a concatenation of two or more obvious terms as long as that concatenation is not itself an obvious term, and trademarking one term does not give you the rights to terms containing that as a substring. Therefore, Apple can trademark "apple" for computer purposes because it doesn't interact with normal apples, but just by doing that, they don't automatically get the rights to "pineapple".

Since this logic doesn't seem to be completely understood (or possibly completely enacted in the law), there is far too much risk to grant the trademark. If they can, I could do something like register a trademark on short web addresses like g.co or t.co (although those particular ones are already taken by Google and Twitter respectively), and sue bookinG.COm and microsofT.COm for including my trademark in their domain names. So let's find out where the substring rule needs to go in the law or public understand and hammer it in so hard it'll never fall out again.

NUC NUC. Who's there? It's Intel, with a pint-sized 8-core Xeon workstation

doublelayer Silver badge

Re: Have some Mint instead!

"small form factor to me means cheap and cheerful and while this one is certainly cheerful....it ain't cheap"

Out of curiosity, why? Sure, you can get much more powerful if you get a large tower, but machines like the one that started this thread and the one reviewed in this article prove you can get really fast with small profile devices. Assuming issues like heat management aren't problems at that profile, and the reviews don't complain about it so it at least can't be overheating all the time, why should small profiles be limited to the lower end of the price and performance range? I think powerful and small devices have some interesting niches, including local servers and those who need more power portably than they can get in a laptop.

doublelayer Silver badge

Re: Have some Mint instead!

That looks interesting. It's faster than the reviewed NUC by a little bit on single thread and significantly so with all cores running. The MintBox is a bit larger (6.2 cm deeper, 1 cm wider, and 0.5 cm taller), but that's probably not a big deal for anyone. I only have one doubt about it, namely this from the specifications for the processor: "95W, fanless natural airflow cooling". The 95 W is only the CPU (and the Intel-quoted TDP at that, and this machine also has a relatively powerful GPU in it as well. I know they use the metal case as a massive surface for heat dissipation, but I wonder about overheating when under consistent and heavy load.

I don't need that much power near at hand, as most compute-intensive things I might require can be offloaded to a remote server, but if I suddenly get a couple grand I can't use for anything else, this would be very tempting.

Uber, Lyft struck by sue-ball, no, sue-meteorite in California after insisting their apps' drivers aren't employees

doublelayer Silver badge

Re: Uber and Lyft have yet to show a cent of profit, right?

They'll probably have even higher losses. The only profitable thing they do is to arrange these rides, as they earn more from the customer than they pay the driver. They use all that money, as well as plenty from investors, to pay for projects that don't make any money now but theoretically could in the future, such as their self-driving cars. At this point, they have fewer rides making a small amount of profit, but to the best of my knowledge, they're still paying the engineers on the self-driving project, and they're of course continuing to pay the lawyers and managers. They're going to be even farther from profitable now.

UK finds itself almost alone with centralized virus contact-tracing app that probably won't work well, asks for your location, may be illegal

doublelayer Silver badge

Re: It is your duty ^D^D^D^D obligation to install the app

"I'm sure app 'green' screenshots won't be hard to find."

And that will work well for about a week. Then, there will be an emergency addition to the spec:

The QR code on the main app screen must contain the following information:

* The personal ID number of the user.

* The latest test date and result.

* The current health status of the user.

* A compressed representation of the user's criminal history with regards to health testing and app usage.

* The current date and time, using the UTC time zone.

This information must be signed with a device-specific private key whose public key has been registered with the server. Scanning devices must verify this signature. Those that lack sufficient internet access must be frequently updated with new lists of public keys. The suggestion is that this process occurs while charging those devices. Should a signature fail to validate, the attempt to scan must return red.

It has been 20 years since cybercrims woke up to social engineering with an intriguing little email titled 'ILOVEYOU'

doublelayer Silver badge

Re: Never Learn Anything from History

It is still the default in a distressing number of GUIs. Mac OS does it. Some Linux desktop environments' file managers do it. Many Android file browsers do it. Why did this nightmare get so popular in conjunction with automatically opening files based on their extension. The latter makes sense, but if you're going to do it, you have to be really careful.

That awful Butterfly has finally fluttered off: Apple touts 13-inch MacBook Pro with proper keyboard, Escape key

doublelayer Silver badge

Re: Apple have lost it

If you're connected to a bunch of desktop equipment, you have other cables you could also use to drag your machine off the desk if bumped improperly, but fortunately you have more space to place them where they're not in the way. The usefulness of a magnetic connector is for those times when your computer is plugged in in a location that would make it easy for something to put force on the cable, so mostly when you are working portably. The suggestion of magnetic USB-C connectors is good, and I'll have to look at them. My main concern is whether they work well with high-powered devices--for example, I really don't want to end up melting something into my USB port by running 87W through a £5 adapter, so I really hope they've been tested to that level. Similarly, the cable that connects to that magnetic adapter should also be capable of such power levels. If I can find positive test results of that, I think I'll be buying a few of those.

Latvian drone wrests control from human overlords and shuts down entire nation's skies

doublelayer Silver badge

Don't count on that. There are two major reasons to want to look at the tech in a craft like this:

To steal it for your own drones: On this I agree with you. The Russians almost certainly have better and don't want that.

To plan for what you would need if you ever wanted to evade them. This the Russians might want to do. If they want to invade the Baltic states, they can't risk a very rapid NATO response (assuming that could even happen). They can hope for delays in contact to other NATO members, or they can try to do as much as possible before detection. Evading aerial detection would be a good first step. If this drone is meant for combat rather than detection, you could learn to identify and catch it.

All that said, we currently don't know the Russians have stolen it. I'd buy it, but there's also a possibility that the communications system crashed and they have a plane flying off into the middle of nowhere with nobody controlling.

Google Australia says government pulled pin on content-for-cash talks, hands in its homework anyway

doublelayer Silver badge

Re: Hang on there a minute

Also, their argument is just not true. There have been and still are plenty of publishers who write content and then sell it to other places so those other places can have the right to distribute that content. In fact, it applies to pretty much every kind of content. Wire news services, syndicated television programs, music played on radio stations, movies shown by theaters, plays put on by acting groups, the list goes on and on. Now I understand Google's argument that this is a little different, as they're not placing the ads themselves and thus aren't making any money off the content they distribute for free, which was already basically released for free by the owner, except that most of those parts aren't true either. The search page has ads that never benefit the people listed there. The news pages may have ads that benefit the publishers, except that most ad scripts are forbidden based on Google's technical restrictions so it's mostly Google ads and that they still make plenty of money on those. Also, placement in search results results in visitors to a publisher's page to read the content and possibly continue to read more content by that publisher, which the Google News page doesn't tend to do. I tend not to fully support the news organizations when this argument starts up again, but I don't support Google because they offer these transparently false arguments.

Singapore to require smartphone check-ins at all businesses and will log visitors' national identity numbers

doublelayer Silver badge

Re: oh, id checks, welcome back!

""As a thought experiment, consider a hypothetical government that demands that every citizen wears a biometric bracelet that monitors body temperature and heart-rate 24 hours a day. The resulting data is hoarded and analysed by government algorithms. The algorithms will know that you are sick even before you know it, and they will also know where you have been, and who you have met."

And nothing bad can ever come from that. For example, if someone with some power, or a criminal organization, want to track people who they don't like, they only have to read from that database to have perfect tracking information for their soon-to-be victim. And if they're worried about that victim having given information about them to someone else for prosecution or publication, they can use the "who they met" section of the data to get a shortlist and find any possibilities. If the one doing the tracking is a little further up the ladder, being a government member rather than a hacker or a corrupt cop, the person can also be arrested because you can pretty much guarantee that they forgot to charge their permanent tracker sometime, and it would surely be a crime to go about without your monitor in working order. I can solve lots of current problems for you if you don't mind me creating much worse ones.

doublelayer Silver badge

Re: In Singapore, 1984 has arrived.

"OK, but how would you do contact tracing, as it has been shown to be an effective way of containing the spread of COVID-19?"

I favor the complete approach. Make a really big grid of buildings and keep everyone in a specific room. Don't let them leave. Use cameras to monitor the halls so you can see if anyone leaves. Those cameras are watched by a set of guards, each of them in their own room as well. Each camera will be watched by at least two guards and be attached to motion sensing software. Should a person try to leave, they should be presumed to be willing to murder by coming into contact and imprisoned for that crime. Since they probably only bother to do this if they have the disease, you cannot safely detain them, so they should be shot. Follow my advice, and I guarantee COVID will be extinct in your area within a month of full participation.

You can do many things to solve a problem. Instituting a surveillance system that seems straight out of North Korea and, incidentally, in no way guaranteed to have an effect is a very bad way to solve a problem.

But that's not enough. I've stated why it's a bad idea from a human rights perspective, but let's talk about what effect it would actually have from a health one. If you know who went where and when they went in, you know ... not all that much really about who they might infect. You don't know who they passed versus who was on the opposite side of the building. You don't know whether they had a long conversation with anyone. You don't know whether they were wearing protective equipment while inside there, as even if you recorded a picture of them going in, they could remove it a minute later. You don't know what route they used to get to that place from the last place you tracked them. You technically don't even know that they are the person they say they are, if this only involves scanning QR codes; it's easy to copy someone else's QR code and display it, so unless there's an employee whose job it is to take ID cards that have been touched by random people and bring that card close to their face, lying should be somewhat easy.

All privacy issues aside, this plan doesn't really work at all for contact tracing. Tracking apps do, but this doesn't. Now bringing the privacy issues back, this is a perfect method of oppressing a population. There's a reason it's been tried in many a dictatorship--if you can get it working, you can do a lot to your citizens. We now get to see the high tech implementation of a dictator's dream.

It looks like you want a storage appliance for your data centre. Maybe you'd prefer a smart card reader?

doublelayer Silver badge

Re: Bit like Amazon at the moment

Are they different hits? If so, they're probably beating Amazon. My searches often go like this:

Enter search terms: Random things that don't match what I was looking for because the descriptions specify what something has but not what it can do.

Retry search terms: Some actual results pop up. Well, three things. These must be three very good things because they each appear at least four times in the results list. Sometimes this is because there are four different colors and the sellers don't understand how to use the item color selector on one product page. Sometimes, they seem to be identical including identical prices and I have no clue why they're listed multiple times. The rest of the list consists of sponsored unrelated things and refurbished items, which often are not very desirable for many of the things one might want to buy online. Often, the three possible results are all overpriced, which leads to

Sort by price: I think that, for every possible set of search terms, someone has made a product to show up first on a sorted price list. The most frequent tend to be cases or straps. If it's electronics, it can at times be components, but never the kind of component you want to have extras of. Even when there's no real need for a case for something, somebody has made one and published it on Amazon. I don't know if anyone ever buys them, but I wouldn't recommend it as I have no proof the case will actually fit the thing it's being advertised for, assuming they actually tried to advertise for a specific product rather than a class of products. So I realize that I'm just going to have to use the price filter until I am at the lower end of possible prices and see what those look like, which leads to

Price filter: I don't know what Amazon's frontend office looks like, but I know it must have someone there (I imagine it as two laughing interns) whose job it is to monitor my searches and make sure there is never a price filter option on the page when it would be useful. I've seen it on other searches where I didn't need it, but for some reason it will disappear off the page from time to time, and that always happens when I've reached sufficient frustration. I try to find the set of parameters I can append to the query string to put a filter in place, and if I can remember it, it tends to work, but often I give up around now and go elsewhere.

India makes contact-tracing app compulsory in viral hot zones despite most local phones not being smart

doublelayer Silver badge

Re: so what *is* the solution?

I appreciate this clarification. While I haven't used the quote before (at least I don't remember ever having used it), I've heard it used many times and always assumed it to have been meant in the typical context. I learned something today. Have an upvote.

However, I must point out that the sentiments, different though they are, still have parallels to this. The liberty being spoken about in the quote were about a government, sure, but they were about a government against an effective power broker, not the people. Meanwhile, the government concerned was democratic. So to some extent, it was still the people (via representatives) against less representative power (big landowners). The same logic can apply with the people against those who have power over them.

Spyware slinger NSO to Facebook: Pretty funny you're suing us in California when we have no US presence and use no American IT services...

doublelayer Silver badge

Re: But..

How is it any different? Well, they're too different bad things. Facebook's collection is unwarranted and should be illegal everywhere. There's a good case that it is illegal in some places based on how the GDPR specifies they're supposed to do this stuff, but that hasn't yet been tested. Elsewhere, it's legal though extremely odious. NSO's is clearly illegal everywhere, and there is no openness about what they're doing, which we at least have a little bit for Facebook. They both deserve to be fixed. Ideally, my schedule would look like this:

May 2020: NSO finally brought into court.

June 2020: NSO found guilty, made to pay a heavy bill.

July 2020: NSO goes bankrupt.

August 2020: Facebook simultaneously pursued with legal action by those who never agreed to data collection and by data protection authorities.

September 2020: Fines build up to catastrophic levels for Facebook.

October 2020: Facebook files for restructuring bankruptcy.

November 2020: Judge rules against petition to restructure because of illegal activity.

December 2020: Facebook starts dissolution bankruptcy process.

Unfortunately, the legal process doesn't go that fast. I can still hope, can't I?

doublelayer Silver badge

Re: But..

I think you pointed out the problem already. Users agreed to Facebook's snooping. They didn't agree to NSO's. Facebook didn't agree to NSO's. Nobody agreed to NSO's. NSO's is obtained by breaking into systems including user phones and possibly including Facebook's servers. In addition, NSO's malware spies to a much greater extent than does Facebook's. NSO's can reportedly turn on cameras and microphones to record background information. Facebook isn't believed to do that, though I wouldn't put it past them to do so eventually.

I hate Facebook too. Everything about them. I refuse to use any service they run. At least people expect that Facebook will be spying on them if they do choose to use their services. NSO's is worse.

Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers

doublelayer Silver badge

Edwards said he doubts these leaks are accidental.

And they definitely aren't. Just look at the responses. Companies are encrypting their addresses now. Yay. Except the response for someone who doesn't want to leak them would be to change the page source so referer [sic] headers either aren't sent or exclude that information. I can think of three different ways to do that that each can be implemented in about an hour. Nope, they'll encrypt them. They won't bother stating that they've already sent the keys to the provider; they figure we already know that.

Xiaomi what you're working with: Chinese mobe-flinger proffers two Redmi Note phablets for UK market

doublelayer Silver badge

Re: This is more than a little disturbing...

Xiaomi has some positives and some negatives. Among their negatives are that their variant often comes with a lot of bloatware and has advertising throughout most of the included apps. This tracking would be another one to add to that list, and it wouldn't surprise me all that much that one of the bloatware apps they installed is doing it. I usually consider Xiaomi because I'm planning to put Lineage OS on it, rather than for the included software.

doublelayer Silver badge

Re: Play Store?

The entity list which blocks manufacturers from American products only has Huawei on it. Other Chinese manufacturers like Xiaomi, Oppo, and Realme can buy anything they want from the U.S., and they do. If you want Google Play Services, any of these will be fine. If you don't want them, Xiaomi's devices are most likely (though not guaranteed) to be supported by AOSP-based variants like Lineage OS.