The Register Home Page

* Posts by doublelayer

11394 publicly visible posts • joined 22 Feb 2018

Raspberry Pi head honcho Eben Upton talks thermals, stores and who's buying the kit

doublelayer Silver badge

"TBH I'm amazed there aren't knock-off Pi-es out there. Is there anything proprietary or custom to them?"

There are plenty of similar products. Many of them are so obviously meant to be like the raspberry pi that they've called themselves "[insert other name of fruit] pi". Some actually have better specs than the raspberry pi. However, they are less popular for many reasons. One reason is that they don't have as much community support, sometimes supporting fewer operating systems or working in an incompatible way. Another reason is that, while they often support similar hardware modifications, they aren't directly compatible with the ones designed for the raspberry pi. A third reason is that these usually don't have a guarantee of continued manufacture or software support, something all pi models have received since they first came out. But if you're looking for other versions, you'll find them thick on the ground.

"They are verging on being usable low-end computers now."

They passed this point for many users quite a while ago. It depends what you're doing on them, but for traditional office tasks, the version 3 was quite capable of the load. If you need a lot of memory, nothing before the pi 4 gave you more than a gigabyte, but plenty of use cases didn't need that. It won't replace the full desktop for the people who need that amount of performance, but it could probably replace many an old one.

"Perhaps an official PiBook (in the vein of the OLPC XO netbooks) might be in the offing?"

The PiTop people did make one of these. I'm hoping some other people will also do so, as I found their one somewhat overpriced and underwhelming. Unfortunately, for the price of their enclosure, you can get a comparable laptop with better battery life, builtin storage, and a slightly faster processor. I'm hoping that people will start to realize the potential of using the pi as the computer for various form factors.

Everyone remembers their first time: ESA satellite dodges 'mega constellation'

doublelayer Silver badge

Re: Isn't satellite broadband pretty much one-way ?

Short answer: no.

Long answer: Satellite phones. Satellite media uplink stations. Current satellite internet. None are new, none require powerful transmitters on the surface. They don't really require all that powerful transmitters on the satellite either when you compare them to lots of other things.

doublelayer Silver badge

Re: Telecom Companies Rule

You are banking on the speed of light to necessarily generate faster comms. It doesn't. We've had lots of things that used waves traveling at the speed of light to send data back and forth, including nearly every type of radio comms system you could build at the time, and plenty of them were rather slow. The waves move faster through air than through a cable, but what mostly matters is how fast they can be encoded and decoded at the ends. If, for example, the frequencies in use are prone to collisions, that introduces a bunch of latency that wouldn't be there otherwise. Cables don't really have this problem. That's not the only issue either. To illustrate this, consider that modern satellite internet uses the same geostationary orbits that the original ones used, and while latency isn't much improved, bandwidth has been rising rapidly. The electronics have improved; the physics is the same. So just because there are some numbers that look like they make a point, it doesn't necessarily mean they're correct.

In addition, consider how the satellites actually send data. You have to uplink to a satellite. If that satellite isn't in range of the target, it has to send a signal to another one. That might have to happen a number of times before you reach a satellite in the right geographic position, which then downlinks to a ground facility, which uses cable to connect to the host, which then contacts the ground facility with the data, which sends that to the satellite, which has to send the result back to your satellite, and then it arrives at your house. All these factors could introduce latency problems, and some could introduce bandwidth problems. If there isn't a conveniently-located ground facility for your destination, you might end up experiencing most of the cable delay anyway. If you're after a server in a place like Singapore, with a lot of servers and little room for satellite downlink space, you might find that the relatively few satellites there are heavily burdened. A lot of this is difficult to calculate without access to the full documentation that the company has and guessing at part of it. At least, not until it actually goes into service and we can experience it for ourselves. Until then, you might want to think twice before declaring it's definite success with such vigor.

Trade union club calls on UK.gov to extend flexible working to all staff from day one

doublelayer Silver badge

Re: So because you don't want it, no one else should be allowed.

I think the comment meant that it shouldn't be encouraged, or at least "it is not the case that we must encourage it". I'm not sure I agree with that, but I believe the intended point was weaker than you've described. There are many advantages in working remotely, and there are also disadvantages. Enforcing either could be harmful, but encouraging one over the other might not be. Fortunately, I don't think I'll have to decide on that policy at any point in my career.

Huawei new smartphone won't be Mate-y with Google apps as trade sanctions kick in

doublelayer Silver badge

Re: And if Huawei allowed unlocked bootloaders

No, I can't see those at all. I can see a pointless ban by the American government as part of a trade war, nothing else. I don't support that, but just because some people somewhere chose to paint the company as a security risk when they're not, that doesn't make every other possibility true. You've claimed that people are out there bricking devices with intentionally damaged firmware and then claiming refunds, but you can't point to who is doing it or when it's happened. In addition, it's completely illogical.

It'd be similar to saying "There are people out there who go into stores, steal the batteries from phones that have replaceable batteries, and replace them with lookalikes that also contain a tracking function and can be primed to explode if the people who built the replacements want to turn the phones into explosives. Therefore, we should not allow replaceable batteries." That statement and yours are similar in that A) nobody is doing that, B) if someone did do that, it'd be completely pointless, and C) if people did do that for whatever reason, the suggested course of actions would not stop them.

doublelayer Silver badge

Re: And if Huawei allowed unlocked bootloaders

I was responding to "As long as there are companies and secret services that work with mafia methods, you can't afford such liberties. They would be their downfall if they did." Clearly, I misinterpreted it. I misinterpreted it because what you've clarified sounds a bit crazy. Do you have evidence of someone who actually did that? Because other than overworking the company tech support as they reflash their devices, the criminals doing that wouldn't gain anything at all. You only get to claim a refund if the device is manufactured with defects, not if you've deliberately destroyed it.

You don't see, for example, people throwing phones on the ground then shipping the destroyed remnants back and asking for money, because that wouldn't work. And a locked bootloader doesn't really protect against that in any case, because if you really want to render a device unusable, intentionally uploading a corrupted ROM is a relatively time-intensive and very reversible method, I.E. one of the worst options for available frauds. Furthermore, unless you can point to a place that did this, it's a weird argument to make.

I'm sorry that I gave you credit for an argument you didn't make. I thought you were talking about accessing data or preparing a device for resale, because that's the major undesirable thing that criminals do to phones. I apologize for assuming you also considered this aspect, but I believe we are now on the same page. What book this page is in is another question, but one that can wait.

doublelayer Silver badge

Re: And if Huawei allowed unlocked bootloaders

I don't understand your comment. Are you alleging that locked bootloaders are there to protect us from criminals and surveillance systems? If you are, that's pretty laughable. People steal phones all the time. Most of the time, they don't care about the data and are perfectly happy to reflash the device and sell it on. Even if they could replace the firmware with something else, the phone's serial numbers, IMEI, etc would still be present so the phone would be just as easy to identify as stolen. They don't need to care about the bootloader, only whatever antitheft mechanism the manufacturer has. A good antitheft mechanism doesn't have to be incompatible with an unlocked bootloader; a solution as easy as "Please enter phone's encryption unlock code before the bootloader starts" would serve perfectly.

As for surveillance states, they really care about the data on the phone. Not the hardware itself, just the data. There are only really two ways they go about getting data from a device:

Method 1: They have a phone, and they want to extract all its data but the data is encrypted. In that case, they don't need to replace the firmware, because doing that would wipe out data they need (either all the user data or at least the key used to extract it). They might try to copy the old firmware so they can retry encryption codes, but the antitheft system I described above would hamper them from doing so.

Method 2: They have a phone briefly, and they want to install malware on it to track a user who will use the device in the future. In this case, the last thing they'll do is to replace the firmware. If anything looks different, they'll be caught and the person they're tracking will dump the device. They'll use the tracking software they can install above the firmware level, which can be deployed much more quickly. In either case, a properly encrypted device will prevent them.

doublelayer Silver badge

Re: Surely Huawei can just facilitate the user adding these?

This proves my point. You have a phone with the required APIs, and all the apps work. Huawei's phone won't have those. Almost all of the apps from FDroid will work perfectly. Many of the apps on the play store will also work perfectly when sideloaded or retrieved from the store by one of the apps you mentioned. However, if an app uses Play Services or another one of Google's proprietary APIs, and many do, the app won't work when installed. It will install properly, but when you try to launch it, it will reach a point where it crashes or doesn't work properly. In order to fix that, a user has to install the required APIs. These exist, but they're not listed on FDroid or in the Play Store itself as Google thinks they've been shipped as part of the default firmware. So the user will have to look for the APKs online, find the versions that run on their hardware, and install them in the correct order. I have no doubt that, when this phone is released, someone will create those APKs and publish them in a matter of days. Users will just have to find an uninfected copy of those and install them correctly. As I said, it's doable, but not without effort.

doublelayer Silver badge

Re: Surely Huawei can just facilitate the user adding these?

What you need to consider is that none of the proprietary Google APIs are present, meaning most apps in the play store, along with the play store itself, won't work. You'd have to sideload those APIs first, which is doable, but you have to find versions of them somewhere (they're not on FDroid), then load them in the proper order and with some special requirements. Doable, but not without some technical knowledge and having to trust a source of the packages.

doublelayer Silver badge

Re: So an android phone without the built in google spyware?

They also cannot preinstall the Facebook app, so you get your wish there. Unfortunately, we have no guarantee that they haven't just replaced the Google and Facebook spyware with spyware from anyone else, whether Huawei or someone else they got money from. Though it's probably at least a little bit more private than what Huawei used to ship, I'm still going to recommend an open source variant like Lineage OS for real, verifiable privacy.

doublelayer Silver badge

Re: This is more of a problem for Google than for Huawei

It's not a stupid question. Huawei makes a lot of phones for the Chinese market and is making money hand over fist in that market. We all know that. But this Google services cut doesn't really hurt that at all, since China has blocked almost all of Google's services anyway for a decade or more. I'd be concerned that they'd lose market share in China if they dropped AOSP for their own custom and untested OS, but if they stick with effectively the same code as they used before, that's clearly not going to happen.

So the major question is how much it will hurt Huawei's ability to sell their phones overseas, and establishing their current market share in various places is a necessary first step to accurately calculating that. And for some countries, their market share is very low, such that it wouldn't be easy to tell if they've lost many customers. For the record, from statistics I found online, and I'm going to have to trust that the internet has correct data on this, Huawei's market share by country is basically this:

Italy: 24.4%

Russia: 14.1%

France: 13.2%

Mexico: 12%

U.K.: 8.1%

Australia: 7.1%

Japan: 4.3%

Canada: 3.8%

India: ~2%, noted to be falling quickly

U.S.: very low, doesn't show on graph

Brazil: very low, doesn't show on graph

Based on these figures, we can see that it's quite logical to ask about the current market share of Huawei by country. If they lose lots of business in Italy due to the services cut, it's much worse for them than if they lose business in Brazil. Americans probably don't see many Huawei devices when out and about, while Russians probably do. And in addition to the mathematical benefits, it gives us a concept of where Huawei does business and where it has yet to take over. I think the question's well worth the asking.

doublelayer Silver badge

Re: One question.

Should a technically aware person want to sideload the play store, they can probably do so with relative ease. However, that probably won't be as straightforward for the average user, who would have to install the various Google APIs before the store could work. Although it's pretty simple, finding the required files that will run on the hardware involved and installing them properly is just over that line where many won't bother. I can't say whether that will be a problem for Huawei, because we don't quite know how many people will fall into both the categories "don't want to worry about sideloading APKs" and "need apps from the play store". I can say with conviction, however, that should anyone in my family purchase this device and want to use the play store, they'll be asking me to find and install the packages rather than doing it themselves.

doublelayer Silver badge

Re: Things that weren't mentioned by most news about this

They can definitely access the web apps. It wouldn't be feasible or desirable to block them, and if Google tried (or the U.S. government tried to make Google do it), they'd be facing a lot of legal complaints they couldn't easily counter. So that deals with gmail and youtube easily. This AOSP device should also ship with the default android mail client, which can also connect to gmail easily. It would be able to show the web interface for Google Maps, but that probably won't be so popular given that people use it for in-vehicle navigation, which the web version doesn't really do. However, there are many alternatives for that, including some open source ones from FDroid that work pretty well.

No access to the play store might be harder to get around, as most users aren't attracted to a phone where they can't as easily install any app they want. It's no trouble for us, because many, including me, don't have any play store apps installed and don't find the prospect of having to sideload something worrying. But for those who want to be able to quickly type the name of their mobile game of choice, they might find that feature removal irritating.

Coin-mining malware jumps from Arm IoT gear to Intel servers

doublelayer Silver badge

Re: IoT malware targets Intel machines running Linux

It's stated that the access method is SSH, so some options include:

1. SSHing with poor or default credentials to root because not all Linux users are, in your words, self-respecting.

2. SSHing with poor or default credentials to something that isn't root, then elevating to root if the user has sudo privs.

3. SSHing with poor or default credentials to something that isn't root, and therefore installing as a user process. It's not as effective, but it'll mine sometimes and that can't hurt the criminals because why should they care?

I have a public-facing server with SSH enabled. Root can't log in, and anything that can log in has an undisclosed username* and either a seriously difficult password or keys only. Lots of automated login attempts occur, but not all of them are people fruitlessly trying to log in as root. Many are trying things like "admin", "system", "user", or the machine's domain name. The people trying this must be doing it because it sometimes works.

*Undisclosed username: This is not a security measure; I know that security by obscurity doesn't work. What it does let me do is set up a monitor for the SSH logs that can inform me if someone is trying to log into an actual account, thus filtering noise from the pointless attempts. If someone does get a real username, I will know about it and I can figure out where that information came from and where this at least a bit more sophisticated attack is coming from. Unless that filter activates, I don't have to worry about the automatic SSH bots. And while we're on the subject, *checks logs*, nobody's guessed any real usernames since the server was set up two years ago.

doublelayer Silver badge

Re: So..

In many cases, it already does. If you ever try mining on Windows, you'll probably have to whitelist the directory where you put your miner. In fact, Windows Defender even treats the Monero binaries as malware, even though you can't use them to mine, only to transact. But there are fewer traditional antivirus products for Linux, and they're less common, so I don't know if they also treat mining as suspicious.

Uber, Lyft and DoorDash put $30m apiece into ballot battle fund to kill gig-economy employee benefits

doublelayer Silver badge

Re: Taxi Drivers Unite

"I think it's time for some market disruption by the drivers,"

I would really like to see that. In many cases, the companies run at least in large part by employees have some major benefits. There are a few cases where they can fall into error, but that's by no means guaranteed.

"they should stump up a little cash each and commission a generic ride booking app that has a simple flat monthly (tax deductable) subscription charge"

That, however, won't work at all. Neither part of that is going to be feasible. Tax deduction only works if the place is a registered charity or nonprofit. There are lots of ways to file as one, but there are usually requirements about working for some specific charitable goal. By most definitions, giving that group more control over what they earn is unlikely to be accepted under the current rules. However, let's assume that either I'm wrong and it is accepted or the law is edited to allow it. The fee still wouldn't be deductible because it'd be considered a purchase, not a donation. Only donations are considered deductible for the purchaser.

As for the subscription, that will fail for pretty much everyone. For many people who don't frequently use the transportation, it won't be worth the average subscription price for the four rides they take a year. Meanwhile, others may get a ride every day, and be profoundly underpaying for that. Worse still, if I have paid for the subscription, nothing keeps me from getting a ride to absolutely everywhere I go, because I've already paid so it's now free. So many more people will be calling rides that there wouldn't be enough drivers to handle the load, yet their revenue wouldn't increase at all. Meanwhile, potential customers would see that it always takes forever to get a ride because all the current customers are using the service five times a day, and they won't sign up. If I have to pay every time I want a ride, I'll probably not take as many, which means there are more available drivers as well as keeping environmental costs down.

Zapped from the Play store: Another developer gets no sense from Google, appeals to the public

doublelayer Silver badge

Google almost certainly spent a few of their billions on a team of attorneys to draw up a contract that lets them do anything they want, as long as it doesn't break the law, but also some things that do break the law because who's going to check, and insulate themselves from any developer action. Meanwhile, they also have the resources to make sure a challenge in court will last long enough for the other party to run out of money, and if someone smallish challenges them on this contract, I fully expect to see that tactic used.

doublelayer Silver badge

Re: 'Tis a pity he is Canadian

I doubt that would be strong enough for Google to take notice. They'd just let him spiral toward becoming bankrupt trying to have a good enough legal team, than shake their corporate head and continue on without noticing the attempt.

Hong Kong ISPs beg Chinese govt not to impose Great Firewall on them

doublelayer Silver badge

Yes, it is such an argument. If Hong Kong's internet is cut off, all the data centers will become less popular. Nobody will set up new ones, and people wishing to have servers in a place that can be accessed in China but aren't controlled by China will leave for other locations, probably South Korea for the main Eastern connections and eastern India for overflow. The investment in Hong Kong's data lines will have been wasted, and access to approved data inside China will be made slower because fewer lines will have to take the traffic. That's without considering the loss in business when all the people who used to use those datacenters look at all the datacenters in Singapore and figure that those will work just fine.

Today's Resident Evil: Ransomware crooks think local, not global, prey on schools, towns, libraries, courts, cities...

doublelayer Silver badge

Yes, we think backups are the solution. Backups isn't just the big box of tapes with all the data from last weekend on them; it includes everything that allows data recovery when data is lost. Whether that be snapshots, extra copies, or the big box of tapes.

You're right that having to restore from backup at the level of off-site external media is costly in time and money, but there are some things to keep in mind:

1. We only suggest doing that if you have to, I.E. the backups that are online and easy to restore from don't work. Frequently, more persistent ransomware will have found those and screwed them up. Yes, you can configure them not to be vulnerable to the typical attacks, and that will protect you from the majority of lazy ransomware. If it does, that's great. If it doesn't, fall back to offline media.

2. Restoring media may be an expensive DR option, but that's to be expected. This is disaster recovery; you only do it when there's been a disaster. There are lots of other disasters where you'd have to do the same thing, but having to rebuild from scratch would cost much more. If the cost is too high for the business, it might be worth constructing a cheaper backup system or one that restores more easily.

3. Paying the ransom is a terrible idea. It guarantees that you have the same problem that let the ransomware get in. They might also stay resident in order to hit you again in a few months or maybe just to add your machines to a botnet.

4. Paying the ransom is immoral. It funds criminals when there is another option, and increases the probability that an attack like this will happen again. If you pay the ransom, you are making someone else pay the real cost for you. That's bad.

doublelayer Silver badge

They could do that, but they could pretty easily keep an offline backup, whether there or offsite, with relatively similar amounts of effort. If they're not going to do that, they aren't going to do a cloud backup either. If they don't have staff competent enough to keep proper backups, this is going to keep happening.

Apple says sorry for Siri slurping voice commands of unsuspecting users

doublelayer Silver badge

Re: Random identifier

If they're doing what they say they're doing, the random identifier is just that, a random string assigned when the request comes. In that case, it wouldn't be attached to any other data, not by hash or anything else. Then, after six months, the key with the random string is deleted so anyone looking at the data couldn't be connected with other recordings from the same source. And if they did that, things would probably be fine subject to some extra considerations like the aforementioned backups storing strings for longer, which wouldn't identify users but would allow collating recordings for a device.

But we have no way of knowing whether they are keeping to that. And they have to have known previous to this that having people listen to recordings is dubious at best, but they didn't stop doing it until right now. If they do what they say they're going to do, then I'm quite a bit happier with them. And so far, they haven't lied about not doing something they are really doing, but haven't been particularly proactive in determining when something they admit they're doing is problematic. We'll have to watch them; if they decide to do something like this again, we have to nip it in the bud.

Microsoft's only gone and published the exFAT spec, now supports popping it in the Linux kernel

doublelayer Silver badge

Re: My uninformed comment

UDF is the solution? I've had a read through the wikipedia article about UDF, and I have my doubts. We'll start with the problem that it's designed for optical media. As in media that can be written a couple of times at most, not one that might have an operating system boot off it or store frequently changed files. There is a version not specifically designed for limited-writes media, but there are others designed specifically for that purpose. This brings us to the next point.

There are a bunch of revisions of the UDF spec. And we all know what that means: lots of poor implementations that support only some of them. And it's not just different release versions, but multiple types of filesystem inside UDF. The wikipedia page includes many statements about what versions different implementations support. Actually, they don't say that. They instead tell us what different implementations "claim to support". Sometimes, such a statement is followed by a statement that only certain subversions are correctly supported, and much of this is for reading only.

My third point can best be made with this quote: "The UDF specifications[7] allow only one Character Set OSTA CS0". When this is a key point in the summary of a spec, and they follow it with a discussion of when this doesn't play well with other encodings, I know it's not fun to deal too much with this filesystem.

doublelayer Silver badge

Re: Bring compatibility problems to Window, not the other way around

I'm completely fine with you implementing EXT4 support for Windows. But unless it gets installed by default, it's useless for most cases. The average user isn't going to understand that they have to open the partition they see, install the driver, then remove and reinsert the media, probably after restarting, and then it'll work. That will just annoy them. And most people who have EXT4-formatted removable media aren't going to bother partitioning it to include the drivers for Windows, and for that matter Mac OS as well.

For removable media, I want the guarantee that I can plug my disk into anything, and the files will be there without needing to deal with drivers, request extra access to install them, or require reconfiguration. We already have a thing that does that, and it's FAT. The only tiny problem with FAT is that it contains a couple very irritating defects, the most obvious of which is the limit on file size that can quite easily be exceeded. But because we don't have anything else that pretty much every operating system understands, I still use it for most of my removable media. Getting a better version that doesn't have those defects and having that run on everything new would be wonderful. I don't really care which particular filesystem it is; if everyone adopts EXT4 I'd be equally content. But it's got to be built in.

doublelayer Silver badge

A quick check that might be incorrect suggests that they were granted a central patent in 2009 source, and then the patent would expire in 2026. I'm wondering why the patent was granted in 2009 when the filesystem was released in 2006, so there are some other options. But no, it seems they could keep charging for the patent for a few more years, and if they release it under acceptable terms, they're not going to do so.

doublelayer Silver badge

Re: What if ...

While they don't necessarily have to use exFAT for that, it is probably the logical choice. ExFAT is a filesystem that plays very well with external media and most operating systems, Linux included if the package is installed. Most other filesystems don't meet one or both of those requirements. If they're also using Linux, you have many other options including the basic EXTs, but that will be more trouble for them than it's worth if they use Windows or Mac OS. Of course, the code installed to let Linux deal with exFAT at the moment won't be all that fast, which a kernel implementation would fix. I am therefore quite hopeful that this does get implemented soon.

Samsung Note10+ torn apart to expose three 5G antennas: One has to pick up something

doublelayer Silver badge

Re: Ban nontreplaceable batteries

It could easily just be heavier use. If you do more things with your phone, you'll have used up the battery faster (I.E. it doesn't last as long even when new) and put it through more cycles because it kept getting discharged. It could also be that your phone is less power efficient than the one mentioned.

While I'm entirely in favor of phones having more user-replaceable parts, I don't particularly care about anything other than the battery, and I don't care all that much about that either. I know people can replace other parts of phones, but all the devices I've seen this on have been somewhat unstable (E.G. replaced screen panels that don't really feel like staying firmly on the phone). For the battery, I'm really hoping that, after four years or so of use when I'd like a new battery, I can find someone who is making compatible batteries today, rather than shipping compatible ones they've had on the shelf since the release of the phone or releasing batteries that look like they'll probably work, and once they get shipped here individually, I can plug them into my phone I don't want to replace just yet and see if they really do.

In purchasing a phone, I expect that, at some point, it will develop a serious mechanical problem. I could try to fix it or get someone more skilled with a soldering iron to help me, but I know that's likely to make the device function worse. That's why I try to go for cheapness. Modern cheapish Android phones are quite well-built, and I don't feel like I've lost much if it turns out that this one doesn't stay together as long as I hoped and I'll have to replace it after three years instead of six. I can't guarantee any reasonable lifetime of a device, but I can make it so that when the inevitable happens, I'm out much less than I might have been.

doublelayer Silver badge

Re: Typical Corporate Greed

You don't need a headphone jack. I don't need one either. Probably few of the people posting here need one. But plenty of people posting here really want one, and base their purchasing decisions around that desire. I don't see why you have a problem with them when they complain about a lack of a feature they want. In my situation, the jack is sort of handy, but I don't really use it all that often. When my phone breaks and I need to replace it, I won't make a headphone socket a required feature. But why do you seem to have so much hatred for the connector or people who use it?

Biz forked out $115k to tout 'Time AI' crypto at Black Hat. Now it sues organizers because hackers heckled it

doublelayer Silver badge

Re: Junk "science"

"Technically you are correct. But if you compare good arxiv "preprints" with published versions you'll find that many have only very minor changes."

In general, Wikipedia provides a useful, comprehensive, well-researched, and balanced summary of pretty much every topic. It's a great start for gaining some basic knowledge about something. And if I want to, I can go in and mess it all up. So can a lot of other people, so there's always some chance that the page you see there has been recently vandalized to contain incorrect information. Similarly, Arxiv is a great resource, given it allows members of the public to access papers without having to pay a journal that isn't actually doing the important part, and for that I'm quite grateful. Still, Arxiv can be polluted by useless documents, too. I haven't read the "paper" produced by these people, and I don't intend to, but just because they've posted it on a mostly reputable site doesn't mean that its contents are of any use to anyone.

Wait a minute, we're supposed to haggle! ISPs want folk to bargain over broadband

doublelayer Silver badge

Re: Penalising loyal customers - helps competition?

This applies to pretty much every network provider I've seen in any country.

"Get our new UNLIMITED DATA plan just 29.99/month"

"How many lines do you want? 29.99/month/line above four, 43.99 for three and four, 59.99 for the second, and 85.99 for first."

"How much data at usable speeds do you want? 29.99 for 2 GB, 39.99 for 3 GB, etc."

"Do you want to be able to make voice calls with that plan? Add 4.99/month/line above four, 6.99/month for three and four, ..."

"Choose your free phone to go with this plan. Your choices are the latest iPhone at only 54.99/month for the rest of eternity, the Samsung flagship for the same price, a weirdly chosen midrange Android for 34.99/month and wondering why that's the one chosen, the Huawei for 44.99/month, [scrolling, scrolling] [option to choose no device not found in list]"

"Enter discount codes. [These codes may exist, but the most you'll get is a 15% discount on the first month]"

The companies might have a better plan, but I'm too busy hating them to be able to call and ask about it.

Pokemon Go becomes Pokemon No as games biz Niantic agrees to curb trespassing addicts

doublelayer Silver badge

Ethics

I haven't been affected by people doing this, but in the hypothetical situation, how ethical or unethical do you think it would be for me to set up a device that catches requests for WiFi and establishes connections that don't work to mess up the many phones set to prefer known WiFi networks over cellular, then put it so it covers my yard but doesn't have enough power to extend outside of it. Is that too untargeted?

I couldn't possibly tell you the computer's ID over the phone, I've been on A Course™

doublelayer Silver badge

Re: I wish my users protected data like this efficient PA

I take the point about asset lists not always being up to date, and I don't think that's the necessary solution to the problem. Yet it's still not the fault of the user concerned. They were, perhaps annoyingly, sticking stubbornly to their security training. In other words, they were doing exactly what we'd want them to do in the case of an attempt at social engineering. Repeatedly shouting at the user to give you information doesn't help prove the point. Asking the user to call back with a trustworthy number does do that. There are other ways to authenticate as internal and/or trustworthy, but none were mentioned. Worse, the user who acted in compliance with their training and was actually able to provide the required information without leaking potentially secure information was penalized in a frankly pretty irresponsible manner.

Contacts-slurping Android malware sneaked onto Google Play store – twice

doublelayer Silver badge

Re: How it looks to me

It doesn't hurt all that much if other people get slices of the data. Many of them are showing Google ads anyway, and most of the other data collection isn't for ad competition but for spyware purposes. Why should Google care about that?

Also, implementing real checks that catch copied malware code that hasn't been hidden in any way would take, like, a month for a few Google Play engineers. They could be working on something else. Something more useful like ... Android security updates and getting those running on more devices? No, not those. These are cloud engineers after all. How about ... malicious extension detection for Chrome? No, not that either. They're not focused on that type of code. Another idea ... thinking ... thinking ... got it! They could work on preventing ad blockers from working. Sound good to everyone? Well, we've identified the best use of developer time. Go back and get that implemented guys.

Buying a Chromebook? Don't forget to check that best-before date

doublelayer Silver badge

Re: Keep calm and just install something else

It is a tech site. That's why we know about the potential problems with no security updates, and why we aren't happy to see this being sold to unsuspecting purchasers, both technical and nontechnical. And maybe we can install something, but there are lots of points to consider about that:

1. Some may be locked down or lack driver support for anything other than Chrome OS. So in that case, we can't.

2. Some may lack the specifications to run anything else (E.G. really tiny storage). The purchaser probably doesn't care because they just wanted to run Chrome OS, but it would prevent a useful installation of something else. If this specification limit was the reason for dropping support, I'd drop my objection, but it's clearly not.

3. Maybe the thing to replace Chrome OS doesn't work as well for the intended purpose. For people like us, a full Linux installation would probably be much more useful. For someone else, the lack of any complexity in Chrome OS might have been a selling point. They chose to buy the device because of (or in my mind in spite of) the OS, so it stands to reason that they probably want to keep it. This especially applies to schools; they need laptops that can run a browser and are cheap enough that they can be replaced. Of course they could do that with a Linux distro running on that or similar hardware, but that requires a Linux admin who they'd have to pay. The selling point of these that got them adopted in so many schools was that you didn't need to spend as much time on administration. It turns out you have to spend that in money for new hardware that doesn't provide you any benefits.

4. There is no good technical reason for dropping support like this. If they released a new version of the OS and said "Sorry to any chromebook users still stuck with 16 GB of storage, but we'll need some more for this version. We'll give you security updates for this version for a bit longer, but you will probably want to buy a new one or expand the storage if possible eventually", I wouldn't complain. If they released new versions that need more processing so they run slowly on old hardware, I'd complain about poor coding practices but they would have no policy complaints from me. But they're not doing that; they're setting a death date for the devices and then cutting them off at that point for no good reason.

My MacBook Woe: I got up close and personal with city's snatch'n'dash crooks (aka some bastard stole my laptop)

doublelayer Silver badge

Re: A note of CA license plates...

Maybe, but with that description of how the plates work, it doesn't sound all that hard to fake. It wouldn't stop someone who was looking at the stolen car, but works just fine when you're worried about someone taking down the number while the car is in motion, which is exactly the situation in this case.

doublelayer Silver badge

Re: Or

"Floor tiles that aren't glued down, so that if anyone runs then their feet slip and they don't actually move."

Good suggestions except for that one. I don't think health and safety legislation will like that one, and I wouldn't either when an emergency happened.

doublelayer Silver badge

Re: So here's the advantage to soldering down the SSD

Machines can be locked down to that extent, but many noncorporate ones aren't. Thus, the criminals may be surprised to find one with those precautions implemented because their previous ones have not been so encumbered. It doesn't help the victim very much, unless Apple makes that level of security the default. Of course, if they do that, it won't help people who really want to erase a machine they have a right to erase; if a user has forgotten their encryption code, the IT department will much rather have to reimage the machine rather than throw it away.

doublelayer Silver badge

Re: "should risk their necks to protect your shiny tech toy "

I might not have intervened, probably because it'd take long enough for me to understand what was happening that I couldn't do anything. But afterwards, when the victim is asking people to witness, I'd definitely step up, no risk involved. Even if all I can say is "I didn't see much, but I can corroborate that I saw a guy running through here with a laptop, and you were chasing him so it was probably yours", I'll do that. Doing nothing while the crime happened is understandable, as it probably took about twenty seconds. Keeping silent afterwards is not very nice, because you could just say "I'm afraid I was facing the other way and didn't see anything" if that's the case.

doublelayer Silver badge

Re: Serves you right for being a hipster

I have to wonder about the utility of that lock. It's great when you want to leave something on a table, like in a lab, but not as much if you're using it at the time. At best, the thief grabs the machine and runs away, only to find that they can't. Then, they drop the machine and run off. You may still have the machine, but it's now just been dropped, probably with some force. In addition, since they were running and probably tried pulling hard to separate the lock from the machine, it probably also has damage from such forceful tugs on the lock. However, the lock might also signal to someone that you have an expensive machine and they should come get it when you've undone the lock and are putting it away, which wouldn't help at all.

doublelayer Silver badge

Re: That's horrible.

"Re Mac Vs PC.... evidently the thieves consider MacBooks worth stealing, which suggests that Apple's security measures can be circumvented so that it can be used by someone other than the owner."

You're overthinking this. While people like you or me would think about all sorts of technical things when deciding what laptop to steal, this doesn't necessarily apply to all criminals. Some consider that, I'm sure, but many more might simply choose the mac because it looks expensive and Apple products are known to sell at higher prices on secondhand markets than the average device from another manufacturer. While some others like thinkpads also sell well, the criminals might not be able to identify those immediately.

Here's my guess: these people either have heard from others or have discovered from limited experience that people buy Apple machines and pay quite a bit for them. They probably haven't seen that many people activating the security features; just because Apple has done a lot to make them user friendly doesn't mean that users know they exist. Therefore, the criminals have been able, at least most of the time, to erase the disk and sell it on without being caught. This may be their first victim to have locked the machine, encrypted the disk, or given the serial number out.

"Also, they put effort in their plan to steal a MacBook Air, instead of a more expensive Pro model. Does the Pro's security chip (with its formally Verified OS) prevent serial number spoofing (if that is indeed what is happening)?"

Once again, I doubt it. The air and the pro can be told apart, sure, but at a glance from the back they look similar--a thin metal laptop with a glowing Apple logo. There probably weren't any pros in the shop, or the criminals thought the slightly larger air looked more valuable than the smaller pro. Just because they planned their route in and out of the shop doesn't mean they scoped out their target. They might have planned to go in, grab the best looking laptop, and run out again. The security chips in the machines don't help much if the user doesn't enable them, so the criminals may never have had to deal with that before.

There once was a biz called Bitbucket, that told Mercurial to suck it. Now devs are dejected, their code soon ejected

doublelayer Silver badge

Re: Git

"A problem not uncommon in FOSS.... And now that Micros~1 has it, it can only git worse."

Microsoft doesn't write git. It's still fully in the control of an open group. Microsoft just bought Github, which is a site that stores and processes git repos. Github might write some code for git, but they don't control it and their code only gets in if the developers of git approve it. Many other sites, like the one the article is about, can also process git repos, and git works identically with each of them. Don't try to blame Microsoft for something they have nothing to do with.

So your Google Play Publisher account has been terminated – of course you would want to know why exactly

doublelayer Silver badge

I have to admit that I also thought of this passage:

"He [a citizen of Oceania] has no freedom of choice in any direction whatever. On the other hand, his actions are not regulated by law or by any clearly formulated code of behavior. In Oceania there is no law. Thoughts and actions which, when detected, mean certain death are not formally forbidden, and the endless purges, arrests, tortures, imprisonments, and vaporizations are not inflicted as punishment for crimes which have actually been committed, but are merely the wiping-out of persons who might perhaps commit a crime at some time in the future."

It's not directly applicable, but it did come to mind. Do you think I've read this book too many times?

doublelayer Silver badge

When Google places its play store in a position where it controls a lot of the Android app market, it becomes difficult not to rely on them for your business if your business is writing apps that run on Android. The same is true of Apple. Just because you can sideload apps on an Android device doesn't mean that is generally accepted--Google has managed to make it such that almost all users never do that and have put some scary security warning screens in to dissuade users. Admittedly, what the screens say is true, but they've still gone to lengths to promote the play store. As such, although they have a right to be terrible to developers whenever they feel like it, I feel justified in having a problem with their choice to do so. This guy may deserve to have the account closed, although I don't currently know why, but I think Google should tell him their reasoning. Given that it's almost certainly an automatic account closing process, the program must know the reasoning

doublelayer Silver badge

Re: Dancing with the devil

"If you want to stop people gaming the system, telling them the rules isn't a good plan."

If you want people not to violate your rules, telling them the rules means they know what they're not allowed to do. If you don't tell people the rules, but you still have rules, you're just a dictator. It's Google's platform, so they have a right to be a dictator if they want, but that doesn't mean we have to like or accept it.

"Guy in this story freely admits to trying to push things to the limits; that's why they banned him."

Did he? I don't remember that from the article. I remember that he did something unusual which was not strictly banned but caused some concern, then he dealt with that in a professional manner. Then, he tried to figure out what the problem was with another app but couldn't on his own and Google wouldn't say. Maybe he did in fact do something that warrants the account closure, but neither he nor I nor you have an idea what it was.

Apple's WebKit techs declare privacy circumvention to be a security issue

doublelayer Silver badge

Re: The difference bweteen Apple and Mozilla

"Apply [sic] don't want anyone else tracking you because that lowers the value of the information in their posession."

Wrong. They don't want people tracking you because they think that will help them sell more devices to people who like privacy but don't know how to go about getting it themselves. They do collect some information, but their track record with collection is much better than with pretty much any other major tech company. They are doing it for a commercial reason, not out of the goodness of their hearts, but they are at least doing it honestly.

"Mozilla don't want you to be able to track them and their harebraned changes they keep making to Firefox."

Is this a joke? The tracking protection in Firefox blocks trackers from third parties from seeing user information. It doesn't block you from tracking Mozilla. Mozilla releases all their changes in source and documentation form to the public, and they've never seemed to care much whether people like the changes they made. I'm just confused now. What were you trying to say there?

'Hey Google, remind Greg the locks have been changed, and he should find a new place to live. Maybe ask his mistress?'

doublelayer Silver badge

Re: Random

Probably because it wouldn't help much. These devices don't process speech locally, so if the connection goes down, you couldn't tell it to turn on the radio. You could put a normal set of radio controls on top, but now that's a larger change that the manufacturer doesn't care about.

I don't understand your hotspot suggestion. Are you suggesting that the voice assistant should have a WiFi network for radios? Why? And if you're instead suggesting that it broadcast radio signals for a broadcast receiver to pick up, that's illegal. I'm not sure what you want.

doublelayer Silver badge

Re: Family Link

Explanation doesn't work completely for children that young. If the system concerned makes it easy enough, the child will probably go ahead with it, especially as they can't do some things without having an account. Explaining about privacy, legal restraints, etc. doesn't really penetrate their minds, because they don't know how many ways they can be tracked. I remember setting up an account in my childhood thinking that I must be completely safe because I used a different name, an address constructed from a random number, fake street name, and a postal code from a directory site, and a birth date set to make my age 27. That account actually was safe, because it wasn't from a company that did extra tracking, but I would not have had the knowledge to determine safe from unsafe. Discipline might not work either; the parents have to know exactly what the child is doing at all times. If the child doesn't understand the systems well enough to know what is allowed and what isn't, they could end up thinking that all activity online is forbidden. In general, I'd try to ensure that the child already has accounts for things they will want to use, such as email, which can be restricted or audited by the parents until the child has a clearer concept of what can happen online. Explanations might help, but I don't think they will be sufficient on their own.

doublelayer Silver badge

Re: "Parents looking to induct their children into this brave new world of communication"

I suppose the argument could be that these devices, which listen perpetually, are more in keeping with 1984's society than that of Brave New World. On the surface, that makes sense, but on another reading, probably not. In 1984, a malicious government installs the devices and forces their use. In Brave New World, there is a controlling government, but they've gotten everyone in society to never really consider anything. It's still done by force--people didn't give up their old ideas of their own free will--but nobody really cares that that happens and anyone who does care is seen as a weird person who can be ignored, rather than one who needs to be taken away. The use of devices with such a dubious privacy record which people voluntarily decide to purchase and install is on the Brave New World side of the continuum.

doublelayer Silver badge

Re: Dystopia, one improvement at a time

They've taken something we could already do, by scheduling a message being sent or making a voice call, which is already a normal part of life, and managed to write code to make it unbelievably irritating. Congratulations guys. What's next? Maybe, instead of making a mechanism for people to yell at other people about taking out the trash, you could invent something that takes out the trash. Or just stop inventing things. You've gotten overeager again.

Let's see what the sweet, kind, new Microsoft that everyone loves is up to. Ah yes, forcing more Office home users into annual subscriptions

doublelayer Silver badge

Re: Ransomware

Perhaps you didn't like my point, but I think it was sufficiently clear. They are using and recommending the docx file format. Yes, Microsoft designed it, but that's not quite enough. They have put it under an open license, which means that it is not proprietary. They cannot argue, for example, that using another program on it, writing such a program, etc is forbidden. Just because a company designed something doesn't mean it's proprietary. Red Hat designed and wrote large chunks of modern Linux distributions, but its license allows others to use it freely. If Microsoft introduced a new, non-open format, then it could be described as ransomware. As it is, they've merely changed their pricing mechanisms to a more annoying one. I don't support that, and I've already said as much above, but the original statement of having to pay to use your files is factually incorrect.