The Register Home Page

* Posts by doublelayer

11394 publicly visible posts • joined 22 Feb 2018

VMware emits security alerts, Planet Hollywood chain hacked, SWAT death caller gets 20 years in clink, and more

doublelayer Silver badge

Re: SWAT Death

As for police, they should definitely be trained to deal with this. I'm curious, however, what the telecoms companies should do differently? Normally, the person making the fake call simply calls the police department and makes up a story involving a bunch of violence. They might have other reasons to call that police department, though, so the companies couldn't block connections between people and the police. Is there a mechanism to identify this type of call before it gets to the units?

BOFH: Tick tick BOOM. It's B-day! No we're not eating Brussels flouts...

doublelayer Silver badge

Re: "episode 2" ?

Because it follows episode 1, perhaps?

doublelayer Silver badge

Re: Musak

I would. There are some environments where you could get a lot of benefit from music, but there are environments where I could get a lot of despair from having to listen to someone else's music while I'm working. When I want to work to music, which I do at times, I put on some headphones. The headphones do a lot better of a job making sure other people aren't forced to listen to my music than the job they do insulating me from music others are playing on speakers. I've also seen competitions where multiple people attempting to win the bigger-jerk award fight over whose input is going to the speaker.

I understand that there are some jobs where you can't wear headphones. Of course, if you're alone or everyone else also wants to hear the same music, more power to you. Otherwise, please keep in mind that I get annoyed with high volume and/or repetition, and I usually have screwdrivers.

In the West, we're worried about shooting down drones. In Russia, drones shoot you

doublelayer Silver badge

Re: Why do I care?

You care because they could miniaturize this a lot more than you could miniaturize a more standard military weapon. An improvised one of these might be built out of home-made components, and while it would probably be pretty fragile, it would also allow for longer-distance attacks and some ability to evade activities trying to take it down. It's not militaries who will want something like this, and this particular model isn't of much concern, but I don't doubt that someone will try to build a smaller version, and it probably won't be very nice when they succeed.

Lip-reading smart speakers: Just what no one always wanted

doublelayer Silver badge

Re: Pedantic mode on

Good point. I know the difference between them, but I failed to properly check my speeling. Have an upvote.

doublelayer Silver badge

Yes, soundboard is the right word for that part of a piano.

By the way, I own and use a pair of these bone conduction headphones. They're not exactly meant for music with much base, and they're not going to provide extremely high audio fidelity, but I enjoy them for listening to things while outdoors. I can listen to podcasts, music, or just the GPS's spoken directions, but if someone addresses me to ask me something or warn me that I'm about to do something risky, I still hear them. It is a very subjective thing, and plenty of people will not want that. Still, I get benefits from them.

Are you sure you've got a floppy disk stuck in the drive? Or is it 100 lodged in the chassis?

doublelayer Silver badge

Re: CDs were always noted as sub 5 year lifespan.

And I have home-written CDs from the 1990s that also still read fine, but that doesn't mean that the medium is generally reliable. I've heard of several types of tape that disintegrate with relatively short shelf-times. I'm glad yours works, and maybe that type of tape is more reliable as well, but that doesn't mean that tape or even that type of tape is necessarily going to work.

doublelayer Silver badge

Re: CDs were always noted as sub 5 year lifespan.

No storage medium is very good. For important stuff, there is no remedy for having to store it on multiple media. It's annoying, but whenever you don't and the data is important enough or needed after long enough, something will be broken. We could probably have a long discussion of what the most reliable type of media is, but I'm going to stick with my personal observation: redundant media.

Apple redesigns wireless AirPower charger to be world's smallest, thinnest, lightest, cheapest, invisible... OK, it doesn't exist anymore

doublelayer Silver badge

Re: The 'AirPower' name always implied where they wanted to get

I can't say I've seen a charging port break before on a phone except for the time it broke after so much else was already broken that I just threw the device away. My problem with charging pads I've seen is that they are only about as big as the phone itself, require rather precise positioning of the phone on the pad, and don't work if the phone has a case. This makes it easy to put the phone down in what you think is the correct position, not look at it to confirm because it's at night and you're planning to sleep, and get up in the morning to find that you put the phone down at enough of an angle that it didn't charge.

doublelayer Silver badge

Re: Covering Apple now, are we?

No, it is Italian for strong*. To play something fortë is meant in the sense of "use your strength while playing", which results in a louder sound.

*Source (Italian): https://it.wiktionary.org/wiki/forte

Mozilla tries to do Java as it should have been – with a WASI spec for all devices, computers, operating systems

doublelayer Silver badge

Re: If it happens

"Java in the browser died a long time ago."

"That was because of Quality of Implementation issues that led to it being a security nightmare -- that doesn't mean it was a bad idea."

You're correct in your first part. It also so happens that it would have been a bad idea. It would have been javascript on steroids. More leaky, less reliable if that can be imagined, and more difficult to write and debug. Oh, and by the way, even harder to audit for security. You think reading minified javascript is hard? Try compiled java. One layer removed from the stuff they can obfuscate.

In addition, this is one time when licensing is a really important point. I do not plan to have a massive JRE and, most likely, a JDK as well to fix other people's mistakes on every system to browse the web when I need to individually license them with oracle. Nor am I willing to accept every application coming with its own JRE and JDK blobs taking hundreds of megabytes each because they need to handle their own licenses and only work with a very specific version that was released 27 months ago but also includes API headers from releases from 28, 29, 30, 31, 33, 36, 41, and 46 months ago. On that topic, it would be fun to see the sites specifying their functioning java versions so you could go retrieve the JREs from the java.com and oracle.com mazes. If you browsed enough, eventually you'd get the full collection.

Huawei savaged by Brit code review board over pisspoor dev practices

doublelayer Silver badge

No, Huawei are really crappy at security and thus make people worried. That's why we should start doing this level of code review for other suppliers as well. Just because it is possible (and likely, I admit that) that other suppliers did the same kind of thing doesn't mean Huawei is great. Without that review, you cannot make a statement like "not noticeably crappier than many other suppliers", just like you couldn't make the statement "infinitely worse than all other mainstream suppliers". You lack the evidence, and have made a completely unfounded statement. In parallel, there are still concerns about links to Chinese intelligence, which this review has not concerned. The code review has not announced the existence of these threats, nor has it announced the completion of the search.

Tough cookies: MEPs call for EU websites to be scrubbed of trackers

doublelayer Silver badge

Re: What happens if...

They have to defend themselves in court. The rule of law applies, and unless the governments have already placed some measure into the law to protect themselves, they could be held liable if found guilty. Since they aren't companies, the penalty would be more difficult to calculate. Then again, I don't know that there is any precedent at this time that placing trackers from other companies is a GDPR violation, although I think it should be. There are certainly a lot of sites with them on that are based in the EU.

What bugs me the most? World+dog just accepts crap software resilience

doublelayer Silver badge

Re: Who bears the cost ?

That's not sufficient. The problem with the people writing the code being held responsible for every bug isn't the "held responsible" part. Someone should be, and the programmer should be considered. It's the "people writing the code" part. There are a lot of people that could be responsible for the bug. The programmer who wrote it. The people writing test cases who didn't think of it. The people doing code review who didn't see it. The manager who said it wasn't important if they did see it. The customer who said "We can deal with it". The programmer on another team whose library did it. The spec writer who said not to worry about it. Any of those people could be responsible, but for any given bug, it is likely that not many of them are. Tracking down the responsible person may be doable, but in almost all cases, it is wasteful. Finding a convenient person who might be the person to blame and blaming them without checking is not a sufficient solution to the problem.

doublelayer Silver badge

Re: rwe live in a good time of software

But let's be honest. A lot of terrible software exists today, and we have a lot of contact with it. I don't deny that. But a lot of crap software existed ten years ago, twenty years ago, and thirty years ago. At least some of that isn't really the case now. I remember earlyish Linux distributions. They were pretty bad. The kernel was still pretty good, but it had a lot more panics and oops events. You had creaky desktops that would fail and require reconfiguration. Now, we have a more stable OS and a bunch of desktops that, while not being to everyone's taste, at least break a lot less. Ethernet connections required a proprietary driver that might not run and a lot of configuration on pretty much every OS. We may now have a problem once in a while with a WiFi driver, but we can be relatively sure that an ethernet connection will work for installing packages, and the WiFi driver is usually a one-time fix.

We've learned how not to break things at such a low level. Unfortunately, we moved up to a new level and a lot of things on that level are really broken. I'm not saying we should just accept that, but we should also temper our nostalgia with a healthy dose of pain. My suggestion: everyone run up a windows 95 virtual machine. Only give it eight megabytes of memory. Try to use it and nothing else for a day. Switch it out for a 2000 era Linux distro. Don't let it update. Try that one for a day as well. Assuming you didn't do anything too complex, run it for one more day, which it will probably survive. Then go back to whatever your normal system is and remember that every time you're angry at them, you at least don't have the things you saw with the VMs.

doublelayer Silver badge

Re: Speak for yourself!

I mostly agree with you. Consumers are usually quite aware of their poor choices. They are sometimes willing to pay more for the better option. And there are other consumers, including a large majority of businesses, that really do not care about quality.

The issue here is not the realm where there are no good options, as there isn't a choice that a consumer can make to help improve things. The problem that is relevant to this argument is where there are a few options, and there is one with exemplary quality, but people don't buy it because it is more expensive. Take a place I have had some contact with. Their former director wanted to purchase some computers, and went out to find some. There are plenty of computers that would have been fine, and some that would have been extremely reliable and useful. Instead, they bought a bunch of secondhand machines with a few faulty bits. They got a terrible deal. Why did they buy them? The up-front price was lower than most other options, and the description of the units didn't specify enough so the nontechnical director didn't realize how painful they would be to operate.

This type of situation is where it becomes problematic to simply blame the manufacturer or service provider. They could make a product with better quality, but they are going to extract a profit margin on it. Sometimes, they simply decided not to or made a bad version and sold that one. Other times, there is an option, but people don't choose it for the most useless of reasons. And other times, the price is seen as the indicator of quality, where a price that is too low clearly means it's crap, and a price that is too high can't be justified.

Huawei's half-arsed router patching left kit open to botnets: Chinese giant was warned years ago – then bungled it

doublelayer Silver badge

Re: Just crap software

This is almost certainly not a deliberate back door. It is way too basic, and there probably is little interest in back dooring consumer devices. However, while this incident doesn't say anything about whether Huawei is willing to introduce major security flaws in its products for China's government, it shows that they don't care much about their customers' security (not good), they lack the organization required to figure out something this simple so it would be easy for a small group to introduce a vulnerability and not have it discovered by the rest of the company (really not helping them), and they may not have the best security practices for other equipment they produce (which doesn't make them worse than other manufacturers but they have been claiming it a lot after their recent bans). I'm not impressed.

doublelayer Silver badge

Re: How to secure routers 101

That's well and good, but the most I've seen from a consumer level device is a page on the interface, usually buried at least two levels in, with the following contents:

UPNP:

Enabled

Click here to disable

That requires nontechnical users to know what UPNP is, know that it should be disabled, and manually navigate to it and disable it. Keeping in mind that many consumers don't set up their own networking equipment but allow the ISP to do that for them when they're connecting the line anyway, and you have a recipe for your advice to go nowhere because no matter how many of us properly secure our routers, there will be thousands more who haven't. What should really be the case is UPNP off by default and a clearer explanation of what UPNP is and the risks involved. Devices that need UPNP can give a short explanation when they find it turned off, and a properly motivated consumer can log in and turn it back on after reading the security warnings.

Spyware sneaks into 'million-ish' Asus PCs via poisoned software updates, says Kaspersky

doublelayer Silver badge

Re: How did the bad actor identify the MAC addresses?

Six hundred devices is a rather small sample. It's unlikely that they had any desire or need to compromise the manufacturing situation. While it's theoretically possible that the machines were intercepted in shipping as you describe, the malware could just have been installed on them directly at that point. It could be placed at the BIOS level and made almost completely undetectable. The effort to break ASUS's update system and signing keys and the possibility that it would be revealed as it was makes it unlikely that there was any tampering with client hardware. My guess would be that the target's infrastructure was compromised and MAC addresses accessed from that. With the scale, and assuming that these devices were all one target, it is possible that whoever it is bought a bunch of machines at the same time. If that's the case, only ASUS would need to be compromised to access the target. The other possibility is that there are multiple targets here or one really big target, both of which would make the possibility of multiple compromise of manufacturers plausible.

doublelayer Silver badge

Re: Modern times

And a sample of machines running things that are so outdated that practically no malware exists that could run on them let alone is being spread is also a poor sample. Machines running any number of operating systems are ridiculously vulnerable. Windows XP, for example, but you couldn't use the fact that it's old to exonerate it. You've found that niche where security through obscurity is working, and as long as whatever thing this is continues to work for you, you'll be fine. Unfortunately, there are many people, myself included, who need some of the things that were released in the past 25 years.

doublelayer Silver badge

Re: Laptop Measles

"It's not that difficult to buy a machine without an OS on it."

Really? I have not seen many machines not sold with an OS installed. Of course, when buying second-hand, there are many more options. However, for virtually all new machines, I see the following categories:

1. Pre-installed with Windows

2. Macs

3. Your choice of Windows or Ubuntu (not many of these, but they're nice even when you are just going to delete the Ubuntu)

4. Specifically built for Linux (they are usually great machines with a high price tag)

5. Machines without an OS because they're ridiculously underpowered and the company wants to get them sold off fast to the anything-for-cheap crowd before people realize that. Running Linux on these is usually acceptable, but Windows won't like it and power users of Linux won't be that happy either.

6. Machines without an OS because it is only part of a machine and they expect you to populate your own storage.

I have rarely seen machines sold from their manufacturers without an operating system already installed, and that operating system is rarely Linux. I'm going to install whatever I want on it anyway, so I pretty much ignore what it already has unless I am buying it for a person who wants Windows.

Techies take turns at shut-down top trumps

doublelayer Silver badge

Re: Be careful about differentiating by colour

As I recall, it's the other way round. Blue was usually the last name to be given, resulting in a few interesting things. Try this for a source. It's kind of long and they'll be talking about other things that are unrelated, but it's never a bad time to listen to radiolab.

Let's spin Facebook's Wheel of Misfortune! Clack-clack-clack... clack... You've won '100s of millions of passwords stored in plaintext'

doublelayer Silver badge

Re: Two-factor auth

Why yes, yes it is. What might you be suggesting? They only did that by mistake, and fixed it. At least, they have seen no evidence to the contrary. That wall they're looking it is really blank.

Vengeful sacked IT bod destroyed ex-employer's AWS cloud accounts. Now he'll spent rest of 2019 in the clink

doublelayer Silver badge

I didn't downvote, but the attitude is not great. I've had annoying employers, but I don't want to destroy them. I want to not have any connection to them, and I don't really care what happens to them. I'll go as far as making my disdain for them clear to anyone who might use their services. More than that is too vindictive for me, unless they are actively doing something harmful to people.

Carolina coward fesses up: I was a tech support scambag, and I made millions out of defrauding the elderly

doublelayer Silver badge

Re: I get these calls about once a month.

In this case, they didn't initiate the calls but put the number in ads to appear like a support line. So probably it was a toll-free number or, if they weren't that competent, a random American number.

Dead LAN's hand: IT staff 'locked out' of data center's core switch after the only bloke who could log into it dies

doublelayer Silver badge

Re: Read The Phoenix Project!

That may be true, but companies will, at times, ask for documentation under the theory that I'll write down everything that a replacement working with a lot less knowledge and for a smaller bill can simply pick up. That isn't a reason to refuse to document, and I have never done that and would not suggest that anyone else do so. Still, some people don't understand that the hundreds of pages of documentation and procedures, while as organized and clear as I can make them, are long and require thorough reading to understand. I've been praised frequently on the quality and quantity of my documentation, but it has not prevented others from contacting me after I've left to ask questions that were answered in my documentation with more information and clarity.

doublelayer Silver badge

I would suggest, if possible, that you get them to buy new hardware and set up a replacement in parallel. Otherwise, I hope you are good at network administration. I have tried long enough to get a multiple-AP network going with multiple openwrt devices, and I found it to be a terribly long and painful process involving far too much fiddling with DHCP. I'll be the first to say that my network admin experience is suboptimal, but there is still a lot of complexity and ways for that to completely fail.

doublelayer Silver badge

That is true, but it really depends how large the place was. For example, I am mostly a developer, but I volunteer some system administration for a local charity that I appreciate. They used to have an administrator, but they left and they don't have that many systems. When I arrived to look over the systems and start my work, I found the following:

1. A server that contains a domain controller and shared network folders.

2. A UPS for aforementioned server. Not plugged in to the wall socket or, thankfully, the server.

3. A backup system that seemed to be set up properly. It used removable disks that were swapped out every week, when there was an administrator. Since that admin left, they had one disk inside the system that contained the most recent backup and two disks that contained backups from eight months previous.

4. A firewall that nobody had the access codes to. Nobody knew what this firewall was or wasn't doing and I just wanted to get rid of it once I felt confident to rebuild the network.

This is what happens when there is only one person working on the system and the company lacks the ability to manage that person. The charity is small, the director is nontechnical, and the system was consequently chaotic. There wasn't a clear person at fault, but we could all agree that there was a problem.

Renegade Android apps can siphon off your web logins, browser history. So make sure Chrome or OS is patched, friends

doublelayer Silver badge

Re: More information please?

Chrome could also be launched by a malicious link or app, although if you've set Firefox as the default browser that's less likely. I think an app can still select which browser opens a page, though, which could be a potential vector. Still, it's a lot less likely to be done.

Android clampdown on calls and texts access trashes bunch of apps

doublelayer Silver badge

This!

We need to kill the myth that android has any of the good features of open source. AOSP has a few of those features, but not all that many. Google Android drops almost all of this and takes major components and replaces them with closed-source blobs. That doesn't have to be a problem, but Google's methods made it one and it's really annoying hearing people laud it as open when it most assuredly is not.

And nobody tell me about how Android means that Linux is winning or provides us with a wonderful Linux system. I will fight you.

doublelayer Silver badge

Re: When enough apps abuse it...

That's definitely a problem. The solution is to look at those apps and hit them hard if they don't need the data. Remove them from the play store, ban their developers, add the applications to play protect, ... The solution is not to take a feature that they abused and break it for everyone. If I find that a Linux malware has been using the root account, the solution is not to delete sudo.

doublelayer Silver badge

Re: Call recording too.

But that only works if you actually have a recorder on you at all times, and it requires your recorder to allow you to relay audio to it from your side and the other side while continuing to let you hear the call and not causing interference. You can't just buy any recorder and plug it in, and short of putting every call on speakerphone and having a recorder nearby, it is nearly impossible to have the records. An application negates all those problems.

Don't get the pitchforks yet, Apple devs: macOS third-party application clampdown probably not as bad as rumored

doublelayer Silver badge

Re: and the re$t...

And one important point, MacOS does a bad job explaining this to the user*. The error message that you get if you try to open an unsigned application in the normal way states that it cannot be run in a way that makes it sound as if it is a corrupted file or cannot run on the system for some technical reason. Since 10.12, the message does not tell you why it was blocked or how to fix it. I know this as I'm the person everyone comes to when their applications don't run anymore. It's a minor thing, but it's already a wrong move on Apple's part. I don't think this is coming right now, but if it does come, I'll be moving things off the Apple machines.

*It does a bad job explaining this if it wants the user to know what is happening, but a better job if it wants them to become confused and just not use the thing.

doublelayer Silver badge

Re: This.....

Because developers can be terrible means users' choices should be limited? This isn't a warning, and plenty of the terrible things that devs do would pass through a verification process. What this would do (and I doubt Apple is doing it now or in the near future), is to kill independent software, which people, including nontechnical users, use a lot more than companies think.

Let's consider what would really happen with such a policy:

Things that would be blocked

1. Obvious malware

2. Things the verifiers don't like

What wouldn't be blocked:

1. Applications that collect a bunch of users' data and send it off to the developer

2. Applications that show a ton of advertising and do a terrible job

3. Applications that pretend to do something but whose main purpose is to collect data or show advertising before it becomes obvious that they don't do what is desired

4. Applications that the developers can break

You can solve the malware problem by doing this. You can also solve the malware problem by confiscating the machines or turning off the internet. None of these options is the right way to deal with the malware problem.

In a humiliating climbdown, Facebook agrees to follow US laws

doublelayer Silver badge

I have a time machine

I have recently perfected time travel techniques and used them to travel to one year from today. Sadly, the machine broke on the way back, but until I fix it, enjoy this article from next March:

"We had every intention of following the laws. We should not be held accountable for a minor software glitch."

That was part of the statement released today as embattled Facebook fielded a range of complaints from American activist organizations. The whole issue arose about eighteen months ago when lawsuits were filed against Facebook for allowing their advertising platforms to be used in ways that, extremely obviously, violated discrimination laws. Facebook was allowing businesses to limit their advertising by race, gender, and other protected characteristics. Most companies would be sued to within an inch of their lives, but Facebook vowed to do better, and changed their code.

Unfortunately, their code had a few problems. They set up a separate ad portal for ads that were limited by characteristics, and removed those characteristics from the selection lists. This change to their systems required eight months of Facebook engineers' time to implement. A request for the ads using these characteristics during these eight months was submitted to the company, but no reply was received. An interested organization alleged that the change was a very minor procedure and could be completed quickly and argued that the company was intentionally delaying the process. Facebook agreed to pay ten thousand dollars in a settlement, that money being paid to some of its advertisers.

Unfortunately for the business, their changes were not complete. Some advertisers continued to post their ads on the traditional ad platform which allows for discrimination. After some discoveries of this, those ads were removed briefly. In early February, some reports were received that a method of the API, a system allowing programs to use services, allowed the protected categories to be set even though they had been hidden on the main interface. Many advertisers were revealed to have discovered this flaw. Facebook claimed that this was "an amazing coincidence" and "possibly an act of collusion on the part of some of our advertising partners". When asked for a list of businesses using this loophole in order to press charges, the company responded "We take the privacy of our users very seriously. After an internal investigation, we will close the accounts of any user who uses our services to violate our terms of service or applicable laws".

Facebook has announced that the flaw in their software is "one of our top priorities". A spokesperson for the company told us after lengthy discussion that "We have a team hard at work to patch this function. They estimate that it will be fixed some time in October unless there is a difficulty with amortizing the fixed functionality across our tier-1 cloud services systems". There has been some discussion in the American legislature that this issue in Facebook's systems might be a reason to start regulating the company. Given previous scandals, there may soon be a significant exodus of users from Facebook and significant penalties from American and international regulators.

What was that P word? Ah. Privacy. Yes, we'll think about privacy, says FCC mulling cellphone location data overhaul

doublelayer Silver badge

Re: Dealing with the tracking

It depends on your definition of "employee". The FCC people, while being appointed, have a specific task and would probably be counted. Senators are probably better described simply as politicians, and thus not employees. Whatever word you want to use, both categories are subsets of "the people the government doesn't want bad things to happen to". As already stated, this data selling is explicitly against the rules*. If you do things that are against the rules to targets the government does not want to be targets, they go after you. So it's a bad idea to go after the FCC or senators in anything that could land you in prison or have them ask for an extradition. Public opinion is definitely a viable option, but I fear that it will go nowhere.

*If you did do this, you'd probably be buying the data from a company that makes a business of getting and selling it. The resulting attention would probably tank that company, which is a nice start, but there are other companies and the one you used will have no reservations about handing over any information about you that they have. This includes your payment method and the way they sent the data to you. You can anonymize that, but it's harder to anonymize data such that the FBI can't figure it out with time. Unless you live very far away from the U.S., there may be a method of extraditing you there, either from your home country or from a holiday destination.

doublelayer Silver badge

Re: Dealing with the tracking

So your first idea is to do something illegal to a government employee, for which you'd probably be imprisoned, while mine is to go to an entity whose purpose is to be able to enforce the rule that the enforcement agency has been ignoring? Imagine that. I don't relish the idea of going to court, but if it can't be used to protect the public in some cases, with lawyers as there must be, then what good is it.

doublelayer Silver badge

Dealing with the tracking

If there is a case for the class action law suit, surely it's this? The rules don't simply recommend against or ignore the issue of selling this data; it's against the rules. So couldn't both the mobile providers and the FCC be sued on behalf of every mobile customer? Hey lawyers, you like making a bunch of money from class actions that the class never sees? Here's your case. It's fine. Keep the money I'm owed for this. As long as you stop it, you deserve the money. Just make them pay you a lot for every victim.

Apple bestows first hardware upgrades in years upon neglected iPad Mini and Air lines

doublelayer Silver badge

Re: Issues

1. Totally agree.

2. Sure, but that's not a surprise.

3. And the alternative is? I don't know of any tablet with interfaces (yes, you can get a cable to connect a small subset of USB devices to an android tablet, but the IOS devices have one of those too and almost nobody uses either). What interfaces are there that Apple lacks and a comparable small tablet has? This isn't being compared to a laptop.

doublelayer Silver badge

Re: Slipping

A case costs very little, and offers a lot of advantages. The major advantage is that you can choose between them, for aesthetic, functional, or protection purposes. You need no special knowledge to choose one. If you want one and don't want to search, you can go to a shop and look at the shelf of case options, think for a minute, and pick one. The tablet works fine without a case, and isn't going to shatter immediately (although it's a tablet, so it's by no means well-constructed).

Meanwhile, there are reasons not to implement everyone's desired feature into the device itself. I don't want a rubberized phone. In my experience, it doesn't add much protection and does add a lot of pointless volume. It helps the device stay put and not slip, but I have a metal device that already doesn't slip very much. Meanwhile, I do want a case that will protect the device from damage should I accidentally drop it, so I bought one of those. Whatever additional feature you want, you can get the case that does that. There is a difference between making the device resilient enough not to break (every manufacturer should do that) and implementing a feature desired by a small subset of users and forcing it on everybody (no thank you).

Do Martians dream of electric Nimbys? Selling 5G needs steak, not just sizzle

doublelayer Silver badge

The martians don't understand, then

I'm not excited about 5G at all. Let's discuss why, though. The main reason that the companies want it is because it increases speeds and capacity, clear wins for them, as customers will stop complaining for a bit about congestion. That's well and good, and I have no problem with it. However, it requires them to grab all the radio spectrum from the regulators again, which is kind of annoying, and it requires them to put a mast in many more places. I don't have sympathy for people who make up stories about nonexistent health problems, but there is a relatively good argument that a system that requires very close spacing of equipment to work properly may not be sufficiently engineered, especially given the large expanses of empty space where coverage is important, but 5G speeds are not.

You are right that speed is not an important thing. Unfortunately, you seem to believe that the upgrade in speed will cause the companies to start caring about other things. Why? They haven't changed anything else, and they can easily have the mindset that "We just provided you a massive speed boost. Why do you want anything else?". I'd be happier dealing with a trustworthy mobile company that hasn't provided the 5G speed boost than the kind we have now, even with increased speeds in urban areas. Among other reasons, I don't really need fast mobile traffic much of the time because I use WiFi for most connections and don't use high-speed applications on the data connection.

What I do need is coverage, an understandable plan and bill, and some freedom with my connection. For example, a connection that allows me to connect lines that aren't receiving much data most of the time without paying a massive premium for the capacity I don't use. 5G does very little for me, and even for those who need faster speeds, it is only a minor help. It's a nicely engineered solution to the problem that is not a big problem. Giving it credit for solving a problem that it hasn't solved yet and might not solve at all is making it overhyped.

College student with 'visions of writing super-cool scripts' almost wipes out faculty's entire system

doublelayer Silver badge

Re: I too have had that

Another way to do this wrong is to read out terminal commands to people. I remember one particular occasion rather well, when I was at university and helping a beginner student who had a disk quota problem. They had run out of space because their code had many segmentation faults and they hadn't been deleting the resulting core dumps. The problem was that we had a few tools that produced core dumps with different names, so "rm core.*" wouldn't necessarily get them all. So I started reading them a command "rm, then a space, then asterisk core dot asterisk". They didn't quite type that exactly as stated.

You probably know what happened next. I no longer read out terminal commands. I type them in myself or I'll write them down for you with a written notation to confirm before you run it. By the way, I did have extra rights and was able to recover a relatively new copy of their code from the grading system.

All good, leave it with you...? Chap is roped into tech support role for clueless customer

doublelayer Silver badge

Re: "This will only take a second..."

My method when I eventually became too tired to continue disinfecting the machine of a family member was to take their admin rights away. They really didn't complain too much. Then, they decided to upgrade from windows 7 to 10, didn't like 10, and downgraded via the 7 install disk, creating many problems and incidentally creating a new admin account. I was called in to help them find their critical documents, and I made it clear that I would not be working on this computer anymore if they intended to continue using it like that.

What do sexy selfies, search warrants, tax files have in common? They've all been found on resold USB sticks

doublelayer Silver badge

Re: Ah, it was easier before they all had on board cpus

"I've been downvoted here before for pointing out that the flaw in USB that has it "believe" a device is what it says it is cannot be fixed and keep back compatibility. I'm still correct about that."

I didn't see this before and am not downvoting, but that point is somewhere between off the path and wrong. USB devices are what they say they are. A malicious device issuing keyboard commands is a keyboard. It needs to be identified as a keyboard in order to do keyboard things. It might be a physical keyboard with keys, a programmable keyboard, a dongle for a wireless keyboard, or a thing that issues key commands for a malicious purpose. In all cases, it is a keyboard. The computer does not err in trusting it when it says it is a keyboard. It errs when it doesn't ask for verification that the user intends to connect a keyboard. Of course, such verification can be difficult if that is the only input device available, so that is a thing to consider when trying to install a more restrictive policy. However, the "flaw" you have identified is a feature of USB that is required for the thing to be universal. The only way to change that is to have separate incompatible ports for each type of device (I'll vote against that).

doublelayer Silver badge

A good erasure tool: dd. For a typical disk, if=/dev/zero. For a disk that you a) want to sell and b) want to be very sure about*, do a zero pass, a random pass, a 1 pass, another random pass, and a final zero pass. Have fun getting through that.

*In reality, a disk that is old enough such that data can be realistically recovered after zero passing it without government-level hardware is probably not worth reselling. A disk that contains data so critical that you are worried that it might still be recovered after the multiple passes I suggested should be physically destroyed.

Latest Fast Ring build grazes big red button, unintentionally ejects some Windows Insiders

doublelayer Silver badge

Re: Notepad++

I don't use it in pretty much any situation, but I think that a basic text editor should be shipped by default on any OS. Not necessarily one that can cope with a lot of things, but a thing that you can be guaranteed is there when you have to write a script on someone else's machine. For that reason, they should leave it fast, basic, and minimalist.

Don't be too shocked, but it looks as though these politicians have actually got their act together on IoT security

doublelayer Silver badge

Re: This won't stop the flow of cheap consumer Things

All of that is true, but this still has some benefits, namely these:

The government will require places to make secure devices, at least of any type that they intend to buy, and will make a certification process available. That means that consumers who value this have a thing to search for and a certification that indicates a good level. More secure options and more information about exactly how secure the things are can't hurt.

Next, there is some chance that large companies, wanting to sell to the government, will secure and certify some things that weren't secure before. Anyone buying these things gets the benefits of that. Those companies might also focus more on security now that they are partially required to do so, meaning other products they make could become more secure. Again, it's a thing in the "not guaranteed but can't hurt" category.

Finally, a law like this helps to set a precedent for a more restrictive law. If an IOT system is used to harm consumers, the fact that it didn't follow these certifications could be used when explaining why the manufacturers were negligent and should be held responsible. Since America isn't covered by GDPR, this could at least provide a legal basis for a few types of rights that GDPR makes more available.

Amazon may finally get its hands on .amazon after world's DNS overseer loses patience

doublelayer Silver badge

Re: No internet in the Amazon?

Satellites providing internet service orbit in range of the rain forest, and plenty of places that are less urbanized have mobile coverage. The uninhabited areas probably don't, but we're talking about the people who live there, and a lot of them have access to communications tech as much as anyone else.

Radio gaga: Techies fear EU directive to stop RF device tinkering will do more harm than good

doublelayer Silver badge

Re: Industry Lobby

But Apple does care about the 1% who jailbreak. I don't know why they care, but they do. I have to assume that at least some companies would care about their routers being reflashed as well, but most of the ones I've seen couldn't care less what they run as long as you buy it. It's the ISPs who aren't so happy with your own hardware being used.

doublelayer Silver badge

Re: "But there isn't any."

But routers won't be causing it. SDRs will be causing it. And fines and prison terms can be doled out to the people using the SDRs to interfere.

As for open firmware on routers, I can use it to ensure that my installation is secure. At the very least, that's one fewer pier in the botnet. It allows development of software for these devices that improves security for the users and the internet as a whole. Most importantly, there is no good reason to ban it.