The Register Home Page

* Posts by doublelayer

11430 publicly visible posts • joined 22 Feb 2018

Microsoft wares may be UK public sector's only viable option

doublelayer Silver badge

Re: I read this as propaganda

That works better with the Oracle example than it does with the Microsoft example. The difference is that in the case of Oracle, there's still a substantial amount of stuff specifically developed for Birmingham's particular needs by someone, whether that's Oracle themselves, some other business using them, or Birmingham's hired programmers. On that, I agree with you; calculating costs is very difficult for both approaches and trying to claim that one is easy and the other isn't is unconvincing.

But if we're looking at something like Office365, there's a lot less code being written for the individual user. People already know most of the features involved in this, what they cost, and, if they're already using 365, whether they need them. Figuring out how much it costs to add Intune for device management is mostly a licensing question with some calculation of how long it should take to make the policies that will be enforced. Compare that to developing or adapting an open source device management system. The costs for that will be hard to determine, because if you are building it for the new government Linux distro you're also creating, you'll have more things you need to build in but more control over the system so more ability to integrate them during development, whereas if you have to manage fleets of lots of operating systems, you have to develop many different clients and deal with OS makers breaking things you relied on. That is, in fact, more difficult to calculate and it's likely that, if you only consider finances, it's more expensive. A proper comparison needs to also compare the expected features, maintenance cost, risks, and all those complicated things which makes both prices, but especially those for the system that doesn't exist yet, hard to calculate.

Another reason this is hard is that we're not just comparing two alternatives. We haven't decided whether this should be a single government body making all the software they no longer want to buy, a process where other businesses are asked to do it and sell the result to the government, a process where businesses are given cash and asked to make the result open source, a process where existing software is supposed to be used unmodified, or separate methods for different parts of the government. That makes the calculations hard, and although they're well worth doing, many of those who would have to would prefer not to.

doublelayer Silver badge

Re: Do we have to explain the difference between Open Source and Free Software again?

It appears we do, because we've got another person who doesn't know and is making up some definitions. Welcome to the class, coderguy.

When we talk about "open source", we're referring to stuff that is either completely compliant with or very close to the OSI's definition. We may disagree about certain parts of that, but most of that is considered required to qualify. Your definition: "You can read the code. You may not do anything useful with it though. Maintenance is usually done by a single entity." is not that. Those who try to pretend their software is open source when it would qualify only as your definition will earn our scorn because it's not open source. In case you're interested, they can also lose a lawsuit because our definition, the one where you have the right to fork and distribute, is considered so correct that courts have ruled that those who don't intend to provide it are lying about being open source. Now, we've explained.

doublelayer Silver badge

Re: I read this as propaganda

The problem being that deployment costs with something open source can follow the same pattern that the Oracle thing did. The reason for that cost wasn't Oracle coming to Birmingham and telling them they had to pay ten times as much. It was systems not functioning properly, processes being delayed for months or years, having to build the custom parts over and over again. Probably Oracle's business or software can be blamed for some of that, but not all of it. A bad plan can absolutely obtain the same level of breaking things around an open source database, and while that would be less expensive because you're not paying for licensing the database, it doesn't help with the rest.

In some ways, this is an argument against the one from the article, because having a commercial software provider doesn't prevent that kind of implementation cost. You can still have a disaster when changing something, even when Microsoft or Oracle is involved, because neither of them is making sure processes aren't interrupted. However, given the frequent responses implying, or sometimes outright stating, that open source would fix this kind of thing which it has nothing to do with, it's a point which seems to go against both attitudes to what kind of software should be used.

Microsoft pushes Pull print, so you don't have to dash to the printer to grab the 'Fire everyone' memo

doublelayer Silver badge

Re: Er, hasn't this been a feature of grown up printers

Not generally the printers themselves, but networks of printers have had lots of ways to allow users to get their job printed at any printer. In my experience as an infrequent user, not an admin, they never work right. For example, the last time I remember using a system, the process worked like this:

1. Print the document to the geographic work queue because the business had offices on multiple continents. The geographic queue was actually named for a city I wasn't in, but the intranet document said that was still the right one, next to all the warnings about what print settings you could use.

2. Go to the nearby printer and scan my badge. The job should print automatically. I don't know what you would do if you had multiple jobs because there was no screen on this printer to select them from, but I only had one, so that shouldn't be a problem.

3. Try scanning your badge again in case that wasn't working.

4. Look closely at the LEDs on the printer, all of which are not illuminated.

5. Try to look to see if the printer is even plugged in (yes, but it takes a while to see that).

6. Ask the colleague who walked by if they've ever used the printer. Colleague repeats steps 3-5.

7. Walk with colleague to the next closest printer. Repeat steps 2-5 on that printer.

8. Ask team members if any of them have ever successfully used a printer here. They all report no, and a couple of them also try steps 2-5.

9. Accept teammate's offer to print this on his home personal printer and bring it back tomorrow.

10. Try to find the original job in the queue to delete it, but fail because it doesn't work like a print queue; every job sent to it is immediately removed from the simulated print queue and stored somewhere on some server, probably, who knows.

I've seen similar things happen to others. Earlier, a university I knew had printers with a similar scan process, each equipped with a USB cable to plug laptops into because that was by far the most reliable way to get something printed. No doubt the thing works sometimes, and probably those who print frequently know how to make it work, but when multiple IT and software people can't make it work, there's a problem. If the Microsoft version manages to work, that would be great, but I have a feeling it will be as broken as any other version.

Crypto-crasher Do Kwon admits guilt over failed not-so-stablecoin that erased $41 billion

doublelayer Silver badge

Re: erased $41 billion?

Not entirely, although that value is partly notional money. About $18b was invested in the TerraUSD token, and that was supposed to be stable, meaning that the value lost when that token collapsed wasn't the result of prices going up. The rest was mostly based on the collapse of the floating Luna token, so most of the $23b remaining was based on a notional trading price. So if 2/5 counts as a tiny fraction, you have it correct. In terms on who got that money, it's not just the people running the systems involved. Some people who figured out how to break the not-so-stable coin were able to convert their holdings to Luna and cash it out at that high price. A lot of funds ended up going to speculators and blockchain hackers, but the operators of Terraform managed to keep some, probably more than we know.

Marc Andreessen wades into the UK's Online Safety Act furor

doublelayer Silver badge

Re: How Andreessen might have avoided this situation...

"If there was already a widely-adopted solution, regulators could just point to it and tell websites to get with the program."

But they wouldn't. They wouldn't because any OS would come with a place somewhere where you disable your PICS settings. That thing would be locked behind the admin password. Some parent would make the point that their child could get that password somehow, just as you've just suggested your child will use ADB to disable your controls, which they probably won't, you could probably prevent, and is not the kind of problem you think it is, but that was your argument why another thing was needed. More importantly, that's still an opt in solution that needs a parent to think for a few seconds. The people who passed the OSA do not want that. They want a blanket solution which not only isn't opt in but doesn't have any other options. That's why they passed the law they did. We could have that, because it would be just another parental control mechanism like the many that aren't easily bypassed, and it would be as effective or ineffective as those have been.

I started losing my digital privacy in 1974, aged 11

doublelayer Silver badge

Re: Why would you ever delete patient data?

One intrinsic option if you have universal identification is that others start to ask for it, and now you have two problems:

1. People you don't know or trust, assuming that you do trust your government, have copies of your identification information and may be storing it with terrible security procedures.

2. It is now much easier to link all activities you've taken with that single identity, whereas there are various methods available for somewhat anonymizing other identifiers for you if you're motivated to do it.

Meet President Willian H. Brusen from the great state of Onegon

doublelayer Silver badge

Re: I was surprised that ...

My guess is that the "Willian H." comes from "William H. Harrison", an actual president, and the "Brusen" I have no idea. Some of the labels they use clearly have a connection to the right answer, whereas others, if they have one, are far less clear about it.

How OpenAI used a new data type to cut inference costs by 75%

doublelayer Silver badge

Re: "smaller, faster, and more importantly, cheaper"

No, I speak as if FP16 is the original precision, because you're right that you can't go any higher than that. Whatever the original precision they used before quantization, that's as high as you can go, just as my zoom with resolution method won't let you get any more resolution than the camera originally gave you. With the camera, you can degrade it and then recover information later by keeping those copies in parallel. If you can do that usefully with an LLM, then the high precision version will be whatever they had the first time.

doublelayer Silver badge

Re: "smaller, faster, and more importantly, cheaper"

Not at all if you keep both things. Keep the full-res image somewhere, but only send the downscaled one. When a user zooms in, crop the relevant portion, downscale it less, and send that. Result: a picture that looks like you can zoom with a lot more detail than you'd expect but you don't have the bandwidth costs of sending the whole thing down the pipe.

Whether this works for inference is another question. If they train a model on FP16 and quantize it for use, then they still have the unquantized version around somewhere. I don't know whether there's any real ability to or benefit in cutting over from one to the other mid-inference.

doublelayer Silver badge

The problem with answering that is that they have very little information about the quality of any answer and don't care because, if they did care, they would still be trying to improve their models rather than selling them. Quantization on its own means the quality will degrade, but a newer model, trained on better data, could still produce better output quantized than an older model did unquantized. This version of quantization will produce better results than normal FP4 does at the cost of the model being bigger; it's almost as if bits aren't infinitely compressible.

Also, you can't predict losses the way you did because burn rate is not directly proportional to revenue. Although it's expensive to execute their models, most of their expense is in the training process somewhere, so if more people pay them to use the models, their burn ratio will decline.

Your CV is not fit for the 21st century – time to get it up to scratch

doublelayer Silver badge

Re: Surprising lack of pushback ?

Perhaps you're not getting much pushback because that question is mostly unanswerable and unimportant to us. I'm not convinced that the AI is better, but without running three methods in parallel (seeing candidate lists from the AI, human HR parsing, and reading them all myself), there's no way for me to know for sure. I'm not a hiring manager, so I can't do that, if I was I'd only be allowed to run one of those, and so that information is only known by people who did the studies which are probably mostly people who want to sell one of those approaches who are untrustworthy. It's also unimportant because, unless I'm setting HR policy, I have no control over what method is used. From the perspective of the candidate, the one you wrote from, I don't have a way to know what method they use and I can't make any choices based on it.

I'm not convinced because you don't appear to have done anything at all to try to prove or even defend your opinion. You just stated it. I'm not sure where you would get the information needed to attempt a proof of the opinion, and since you did not provide one, I assume you don't have any and that's why you didn't try. But since I don't have any either, who am I to tell you you're wrong, especially when I'm not sure you are wrong? Among other things, AI candidate filtering is probably the only available way to deal with the flood of AI submissions, so it could end up being better merely on the metric of not causing hiring managers to give up and never hire again, even if it is throwing away good candidates ten times as much. Better hiring managers might be the better solution to that, but unless we can make that happen, it's not a realistic one.

doublelayer Silver badge

Re: Master and the slaves

You can try being the person who employers search for. Some people get to be that person. Others who try get nothing because they're really not that unique. When there is an open position, it's more frequently the case that the employer has money and the employee needs it than any of the other squares in that table, so the employer often has the stronger position and can expect candidates to come to them. There are exceptions. Companies known for mistreating workers, underpaying, or looking for unusual skills may find that they can't get anyone to apply, and now it's on them to try to find someone and convince them to apply. That also happens for intense jobs or ones where the employee isn't certain of a long-term option. Startups, for instance, often have to decide whether to do that or to pay large amounts and advertise that they will in order to get talent.

The fact that employees usually have to do more work to get an employer to notice them isn't the law. It's the inevitable result of one party to the interaction wanting something more than the other one. When employees are hard to find, it goes the other way and quickly. Any person can try any level, and they only need to increase the work they put in if they find that the level they're doing now isn't getting them the results they're hoping for. If we all decide to not bother with this, the companies with bad filters will get bad candidates and may eventually clean up their processes. However, for us to all not do this will require that some of us don't get jobs we would have accepted otherwise until the change happens.

doublelayer Silver badge

Re: "Include every damned language, tool, protocol, mathematical technique..."

Because they won't, and finding the amount they're willing to pay requires doing interviews. There's no point doing interviews in and for a thing I don't want to do in the hope that afterward they offer some ludicrous amount of cash that changes my mind. Anyone paying £2.5k per day for that can say that up front. I won't believe them, but that's a bridge we can cross the first time anyone makes the claim.

Intel chief Lip-Bu Tan to visit White House after Trump calls for him to step down

doublelayer Silver badge

Re: Ironically, this is the right thing for the wrong reason.

What would you suggest as Intel's strategy, given that intensive R&D on everything they used to do would, following your analogy, be taking someone with a serious disease and enrolling them in all the olympic sprint events? I don't exactly like Intel's current strategy either, but they are not in a good position where there's an obvious path of success ahead.

The International Obfuscated C Code Contest is back for 2024

doublelayer Silver badge

Re: Devious

It will work on a big endian machine. By the time that the character is sent to putchar, it's already been converted to an integer in the host's preferred byte order by the compiler. The putchar function will cast that to unsigned char, which will take the least significant 8 bits no matter where the CPU chooses to store them. Programmers sometimes learn that to their detriment when trying to use non-Unicode-aware functions like putchar with Unicode strings.

Humans make better content cops than AI, but cost 40x more

doublelayer Silver badge

Re: Complete waste of money.

Advertisers have long decided that there is value in the positioning of their advertisements. They try not to have their advertisements positioned next to things that would degrade its image. Are they right that there's a difference? I don't know. Probably they don't either; advertisers seem uninterested in proving the kinds of things they spend their time and money on, and it's not the easiest question to answer even if they wanted to. But this is far from new, as they've been doing this ever since the time when advertisements were placed out in public.

From their perspective, it doesn't matter if the advertisement is shown to a pro-Hitler person among pro-Hitler imagery; that's probably a positive. The problem is when it's shown to an anti-Hitler person among pro-Hitler imagery, where the viewer's disgust at the surrounding content might, and they're not sure if it does, convert to disgust toward the brand. You may be correct that this doesn't matter, but it's not a new thing that advertisers care.

Tech support team won pay rise for teaching customers how to RTFM

doublelayer Silver badge

Re: Netware

Not necessarily. On the same archive, the version 2.2 image consists of 19 1440k 3.5-inch floppy images. If those also shipped on 360k floppies, that could be almost 80 of those. Any number you may state can be backed up by some of these versions. It seems they added a lot of something between 2.0 and 2.2.

doublelayer Silver badge

Re: Netware

I have never used any version, but to try to answer the how many disks question, I found an archived image of NetWare 2.0 which consists of 13 360k 5.25-inch floppy disks. I'm not sure if that's the only option they had, but if you could use 3.5-inch disks to have fewer, then you could cut that to 8 720k or 4 1440k disks, either of which would probably make for a rather small package if trying to show someone clueless what a lot of money was spent on.

Mexit, not Brexit, is the new priority for the UK

doublelayer Silver badge

Re: The elephant in the room is Brexit

Scale has a lot of advantages. One of the reason Microsoft has so much of the market this intends to replace is that they can write the same software and sell it to lots of people. If the intent was either to encourage Europe-based businesses to compete by only agreeing to buy their software or building it and making it open source, then having more people who can develop it scales very well. One of the nice things about software is that the cost of one more copy are very low, but the downside is that the costs of the first copy are massively high, as are the costs of developing additions and fixes. The more people you can divide that cost among, the lower it is for everybody.

If you tried to do this as a multinational project, then you would have more problems adding to the cost. The UK's version could be English-only as long as Wales's local government isn't using it, but a European version will need better localization. But that kind of thing is a lot smaller than the set of features which would be common. This also depends a lot on exactly what this new software is intended to replace, whether it's Office365, Windows, databases, or any number of other products, because some of those will scale better than others will.

doublelayer Silver badge

Re: Alternatives

Of course M365 or Google Workspace doesn't give you everything you need. They never said it did. What they said is that it gives you more things than LibreOffice does, so if you want to replace it with something, you need more than LibreOffice to manage it. They went on to say that, if you need more stuff, there are two necessary steps:

1. Finding software that does all the things that you used from what the previous thing did

2. Making all those separate pieces of software work well together

Neither of which is impossible, but both of which take some effort. There are some people who insist that it's really just a drop-in replacement, usually only naming Linux and LibreOffice as needed software, and anyone using that argument is unconvincing when they don't have to be. There is a lot of open source software out there that does most of what Office365 provides, but as long as we tell people who know what Office365 provides to use LibreOffice and then stop talking, we look like we have no idea what we're talking about.

doublelayer Silver badge

Re: Alternatives

They didn't say it was. They were pointing to a problem with something which definitely was FOSS, and something that could happen to any other piece of it, and describing it as a problem. Debian looks strong, and let's assume that it is and will stay that way. They asked for far more than an OS stack, and are you confident that any given open source program that is part of that stack is as strong as Debian is? Your simplistic answer is exactly what they were cautioning against.

However, I'm not convinced by their reliability point either. It is a problem for an open source deployment, but it's also a problem for a commercial one. Commercial software gets dropped as well, as schools who used Windows 11 SE devices just found out to their detriment. There is little any user can do to guarantee that the software they rely on won't become unsupported. Between the two, open source has the advantage that others can resume development of it if it is dropped and commercial has the benefit of legal agreements that prevent it from being dropped a week ago and you didn't see the Mastodon post announcing it, assuming you read those agreements in the first place. Neither approach will prevent old tech from needing replacement with something else because development has stopped.

doublelayer Silver badge

Re: On a related note

"Firstly I was talking about new projects so there is no previous work to re-use."

There is almost always stuff to reuse. A lot of tools have been developed specifically to make writing reusable code and then reusing that code really easy, and that happens. And yes, quite a lot of that will be the code the provider wrote, so they are able to assign that copyright to the UK government, at which point they will never be able to use it again because, by assigning copyright, they no longer own it. They certainly won't be able to reuse anything for other places, but they might not even be able to do it for other government software unless they can get whoever controls that to grant them a license to reuse it. Having tried to get permission to use code that the copyright owner wasn't doing anything with and clearly didn't care about, I know from painful experience that this is not easy. If they were going to reuse code, expect prices to go up to deal with that.

There are some cases where there is much less code to reuse, in which case this works better, and although I'm not too familiar with the UK's procedures, government owning code for custom applications developed for them is not very unusual. What is unusual is for them to own the code to other things those applications were built around, such as databases or operating systems. If they were on an open source thing, that will be better, but if they had Oracle databases and specified a program that connects to those, then they'll still be paying Oracle even if they own the code that's writing there. If you want them not to, a company owning the code for a smaller application is not your problem. You want to make government departments design around and specify for your accepted set of software, and whether you can manage that or not, it will only happen if you know which part of the problem you should focus on.

OpenAI’s new model can't believe that Trump is back in office

doublelayer Silver badge

Re: ollama rm gpt-oss:20b

They didn't train it on material saying Trump didn't win. They trained it on material from June 2024 and before, meaning the model has no clue who the president is now. But instead of acting like a human would and saying "I don't know", the model is effectively required to give you an answer. What you are getting isn't the material it's trained on. It's a guess from random jumbled data. And that's what you get from any other model on any topic. Some models will give you the right answer because their data is up to date, but if we copied the model, went to 2029, and asked that who the president was, it wouldn't know, wouldn't find out, and if we manage to convince it to try to answer, the answer would be useless as well.

doublelayer Silver badge

Kind of, and sometimes, that works. Generally, this is implemented with some initial prompting. The prompt isn't as simple as this, but effectively, it ends up saying "If the user asks about something that happened after June 2024, tell the user that training data ended at that point and decline to answer the question". Sometimes, it successfully identifies that the US presidential election was in November, that's after June, and that prompt is honored. Other times, it doesn't get enough weight on that and proceeds down the normal approach which guesses the most likely words.

The problem with any LLM is that they don't know things. I don't mind calling it "lying", but it does suggest that the LLM is aware of information it's not providing, and it is not at all that far. It's using clever random number generators to guess words. If the words make truth, great. If they make falsehood, great. As long as they look like natural sentences on topic, the model part is fine with them, and it doesn't always get that much.

doublelayer Silver badge

It's more likely that the problem is what the model said it was: OpenAI trained it on data ending in June 2024. Why they did that is another question, because there's reason to wonder when they started and stopped training the base model as opposed to the layers of prompts and protections around that which make the thing we have access to. Either they trained this a while ago and have been taking a long time to build the rest or they just didn't bother to update their data when they started, but it means there's no information for the model to even know that Biden had been replaced on the ticket.

Combine this perfect lack of knowledge with likely prompting to prevent it from lying about the outcome of the 2020 election, and you have the perfect way for it to come to a conclusion. Combine that with whatever is causing it to not change its mind, maybe some reaction to other models which change their minds on command, and we have the situation described in the article. All this should indicate yet again that there are many things an LLM can't do and many others which it might do but can't be trusted, so verification is required.

GitHub CEO: Future devs will not code, they will manage AI

doublelayer Silver badge

Re: Fusion

Except that they do spend lots of money on fusion. If that works, it will be wonderful for everybody. If it doesn't, well that's what's happened so far. Be careful whenever making a statement that something is definitely possible with enough money. Most who do find that they're wrong because it takes more than cash. Lack of funding can cause lots of problems, but having funding can't fix all problems.

doublelayer Silver badge

Re: If future devs "will not code"...

That fails for two reasons.

If my C is not right, I have to fix the C by knowing what it does. If my LLM-generated code fails, unless I can fix it only by telling the LLM to do so, then I will need to know what the underlying code does. If the envisioned process is (1) send prompt to LLM to generate Python, (2) test the Python, (3) fix the minor bugs in the Python, (4) release the Python, then unless I can read and write Python, I will fail at step 2. Somehow, that seems to be the general process recommendation from people predicting the demise of programmers as a career.

But the other one is more obvious, which is that occasionally, my Python isn't working, and I try to fix it, and I fail, and eventually I look into it further, and it turns out that the Python is actually fine, but the C that implements the interpreter isn't. I can't do that unless I know C. I can't do the same to a C compiler unless I know assembly. Most of the time, I don't have to do that, but that's because others are doing it for me. Who is going to make the LLM produce working code? So far, they haven't been too active at preventing it from screwing up.

doublelayer Silver badge

Re: If future devs "will not code"...

That's correct, but from the perspective of a user, the problem is in the first part of the analogy: they're not using AI to learn, they're using it to get something done. From that perspective, using a fork lift is a perfectly acceptable solution to wanting something higher than it was and not wanting to do it by strength of muscles. The analogy would need to be corrected to specify a forklift without any of the balancing or containment features that normally exist to prevent the load from dropping off one side and crashing to the ground. Somehow, that one doesn't have the same conciseness. I would use the analogy of outsourcing the task to an unsupervised child, except that with some of the people I'd be using it with, I'd take my chances with the child.

doublelayer Silver badge

Re: Can't wait to be a former developer

But shareholder will care if the code doesn't work and people don't use it. A few companies may be in a position to release whatever buggy crap they feel like and remain powerful, although several have found that they don't after all, but a lot of companies don't have that. If Small Financial Company LTD. finds that their AI investment software has a bug which resulted in them buying far more of something than they wanted to, shareholder will care. If New Mobile App LTD. finds out that users are getting so confused by the account registration process their LLM generated and therefore aren't getting as far as the entering payment details process the LLM also generated, shareholder will care. It will likely take some example cases to get shareholder to be aware that's a risk, so some shareholders are going to find this out after it's done rather than preventing it.

AWS wiped my account of 10 years, says open source dev

doublelayer Silver badge

Re: I'm confused

I could easily believe that they could screw up weirdly, but at their scale, I would expect that if they did, there would be more reactions. More than one account would have a complaint, the AWS response would be more generic to avoid saying anything relevant to many accounts. So far, I'm not seeing anything like that whether in the news or from other people complaining, and I know multiple people with personal, low or intermittent usage AWS accounts.

Meanwhile, there are a lot of parts to this story which suggest that the account user was perhaps using the account in an unusual way, what with the payment from someone else for some reason which AWS didn't like, and that's not explained either because AWS tends to be happy to accept money and, from the scant details available, was accepting it for a while before deciding not to. Combined with the implausible story of a dry run that didn't work because of a mythical missing language feature which isn't a language feature at all unless you misinterpret a different language feature which wouldn't have helped and is only a thing for the one language they were claiming it's not present in, and I agree with the original post. I think we're missing information from both sides of this story. I wouldn't be surprised if AWS ends up getting some blame if we got that information, but I would be surprised if any of the explanations we've gotten for how AWS screwed up end up being the way it actually happened.

Uncle Sam floats tracking tech to keep AI chips out of China

doublelayer Silver badge

Re: AI chip as a service

Again, pursuing this as only a thought exercise, that's not impossible. There are many audit systems that do check for the identity of a company, and there are even audits that check where they got money they're now trying to spend. Nothing would prevent someone from trying to mandate that anyone renewing a license gets a full audit first, and the companies to do it exist. Their solution of having a bank validate a customer is much smaller than that. The problem is not creating a financial system that doesn't exist but instead that this would be costly and not necessarily effective because corporate proxies are relatively easy to create.

doublelayer Silver badge

Re: AI chip as a service

The idea is stupid, but the implementation suggested is probably the closest you can come to it and not be making up technologies that don't exist. A location tracker that transmits is not going to be able to communicate to people to care. One that locks can be spoofed to not or would do nothing if it was simply operated outside China for Chinese users. But requiring cryptographic unlocks on a schedule is something you can implement with a little shim in the controller to be able to transmit them and some microcode to validate them. Of course, in addition to the annoying everybody problem the original comment correctly identified, there's also the problem that this method wouldn't work too well at preventing chips from getting used in China any more than the restrictions on exporting them prevented that, since the people who exported illegally can also proxy activation data. It's mostly a waste of time to try to design the crazy tech magic politicians demand, but sometimes, it can be an interesting exercise anyway.

Network scans find Linux is growing on business desktops, laptops

doublelayer Silver badge

Re: Coluld be good, could be bad

Not a lot of those are kernel vulnerabilities, but few of the attacks on desktop Linux need to be kernel vulnerabilities either. It often starts with user vulnerabilities which may not need any tech vulnerabilities at all but rely on convincing users to do things that the OS was intended to allow but cause problems. But there's a large stack of software above any kernel which can be attacked and people will do it.

And there already are people attacking in the domains you listed, but the problem will get larger with desktop Linux because the attack surface gets larger. People attack Linux servers incessantly and successfully. Linux-based IoT devices find themselves in botnets routinely, and one category of those that's particularly targeted is networking devices. It happens, and it will continue happening.

Perplexity AI accused of scraping content against websites’ will with unlisted IP ranges

doublelayer Silver badge

"if someone chooses to ignore robots.txt, all you can do is shake your fist and mutter curses"

Not quite. It's not too hard to implement a thing that enforced the thing that robots.txt can do. It filters on user agent and, if you've said that a given user agent is disallowed a path, send them a 403. You can do that. The problem is that any bot which wouldn't do it voluntarily is not going to make it that easy for you. Well-behaved bots announce themselves and check the restrictions. Badly behaved bots don't just ignore the restrictions, they also tend not to announce their presence. That means you have a much harder problem because you have to distinguish between a bot saying it's a normal user with a browser from a normal user with a browser. That is an arms race that's a lot less fun. I actually do find it fun the first three times, but when I'm trying to get a bot to go away for the tenth time, it's no longer any fun.

German phone repair biz collapses following 2023 ransomware attack

doublelayer Silver badge

Re: You paid them

There tends to be a difference between someone forced to pay at gunpoint and someone choosing to pay in expectation of receiving a decryption key, even if those were criminals doing it. The other analogy, which is also not very related, is when people pay criminals for illegal things. They never get that money back, even if the confiscation of the funds occurred before the delivery of the contraband. So given these two options, we have to decide where we think the case of paying for a ransom key, which clearly involves more coercion than wanting illegal goods but less than threat of personal violence, should fall between them. The legal situation is relatively well established, but we can argue for that to change.

If I get to decide, I want to make payment of ransoms illegal. If I had passed that one, then paying for the key would become paying for an illegal service and funds would not be returned if they were confiscated. However, since ransoms are not yet illegal, there's a better argument that, until that change becomes law, the funds should be returned.

doublelayer Silver badge

Re: You paid them

It's probably not illegal for the prosecutors to hold the money because, by the time they took it, it wasn't this business's money anymore. That business had willingly paid it to the ransomware criminals, and it was confiscated from them. Of course, that's cold comfort to the people who thought the payment would go to getting a decryption key, didn't get it, and can't have the money back, and it probably feels more tantalizing because it could be but isn't being returned. I'm not sure the special case makes this any different from any other time when a payment is made and the criminals don't hold up their end of the deal.

Millions of age checks performed as UK Online Safety Act gets rolling

doublelayer Silver badge

Re: Alternatives?

No, the number would have a link to the person, although presumably a unidirectional one so individual sites wouldn't automatically know from seeing your number that it was yours. The government who verified it would. Sites, if they checked that number among themselves, could still build up a profile, and you couldn't have another number, so that would be a nice profiling method. That last one would be illegal under GDPR, which is enforced so strongly that only 65% of sites would track it. That's the problem with most systems. Either they have a trackable identity connected to them, or they're very easy to bypass. I don't like the system, so I prefer easy to bypass, but either way you go, someone who wants the system to be perfectly locked and perfectly private is guaranteed to be disappointed.

doublelayer Silver badge

Re: Madness

"Anyone who says parents should parent like their parents did [...] is probably thinking of their parents parenting by taking the TV out the child's bedroom. Tell me how this is done with devices that by definition are movable,"

It's not the only thing that needs to happen, but one important place to start is by deciding what devices the child should have. If that means no smartphone because they aren't trusted to use it properly, then don't buy them a smartphone. Buy them a simple phone, or maybe don't buy them any phone. It's not perfect, but it's a start that, when suggested, some people act like is an impossible idea that they don't understand how anyone could suggest.

"In no business on the planet is the IT department expected to enforce agreed company policies without the ability to administrate devices, software, or company websites, yet patents are told they have to do just that for their children."

Of course they're not. They're the parents' devices, and they can be locked down. In some cases, you might be able to manage without doing so, but there are restrictions. Use them. A lot of complainers have never looked at the options or decided that because they're theoretically bypassable, we'll just ignore those and demand others. There are many management options for mobile and desktop devices, many of them free, and they can be used.

"others will unfortunately have all their friends on Instagram so it becomes necessary for the child to have an account as part of having a social life with other children and for the parent to have a degree of control over what their child does in Instagram [...] This is not possible at the moment."

This is where you see what the various parental options on Instagram allow and decide whether they're sufficient, and if they're not, take it up with Instagram. I don't know what they are as I don't use or administer it, but they certainly claim to have lots of options. But before you rush to legislate, consider that Instagram is not a necessity after all, even if others use it. I had friends who used social media I did not, and somehow I still had a social life with them. If the risks of Instagram are too high, prohibiting it is an option. You have the decision whether it, with parental options enabled, is an acceptable risk or not. It is not our responsibility to lock down everything because Instagram doesn't have a feature you think it needs but you insist on letting your children use it.

One important thing is not to let technological control outweigh all the other important things. Preventing your child from being bullied on social media is important, but if all you do is prevent them from seeing messages, the problem is still there. If they're a target of a bully, they're probably in close proximity to the bully in question. You can do far more good by knowing and responding to that situation, whether that's by teaching the child about ways to respond to raising a complaint against the bully than any social media filter will ever do. When we ask parents to parent, it's often with non-technology solutions which they should use already.

doublelayer Silver badge

Re: Alternatives?

Let's review this:

I submit my identification information and I get a long number, which I can now enter on websites to prove I'm of age.

When a website wants to verify that, they presumably submit that number to the tax authorities who verify that it is linked to an identity that has created it. That means the tax authorities know my identity and what sites I access, and the only question is how long they choose to store it and whether their systems are secure when they collect it. Privacy gone.

Any website can correlate that number with any other website to know that the same user has accessed that site. You specifically recommend they store and check trends on that number to identify reuse. If one of them has a login, they can now associate that number with an email address. I only have one of these as well, making it a perfect fingerprinting tool because I can't have multiple ones and I can't use their site without one, which is great for advertisers and data traffickers. Privacy gone.

Anyone who finds that long number can identify themselves as an adult even if they're not, and I can claim that I didn't know they did it, so those numbers, obtained from willing or unknowing adults, will be readily available to people who want privacy or children who are willing to put a little work into this system. If sites don't check location, those values should work nationwide until they're automatically revoked by being used a hundred times every day. If sites do check location, you'll need individual numbers for people near where you live, which will make it more annoying for people trying to obtain others' numbers but will also make it more annoying for people trying to use their own.

You are right, there are a lot of holes. There will always be a lot of holes. The system as described is trying to verify that a user is within a set of known people, and there is no way of doing that without knowing identities at some point. Even if I was setting it up with a fanatical attention to privacy, it would still break. I might choose not to log anything and take the substantial legal risks that come from that, but that is not enough. Consider, for example, all the systems that process payment cards. They are not supposed to and usually don't log payment card data, because that would lead to fraud. And yet, they get attacked, because if you have software running on them, you can collect that data when it's processed even if it isn't stored. Mathematical tricks to obfuscate the numbers improve things a little, but only against the basics like replaying the same value, not the rest of the problem.

Tech bro denied dev's hard-earned bonus for bug that overcharged a little old lady

doublelayer Silver badge

Re: "...dev's hard-earned bonus..."

Unfortunately, most of the time bonus calculations for technical positions and anything with a similar profile are very discretionary from management down, meaning it's very easy for them to set them however they want them. At least in my experience, contracts tend not to guarantee a bonus on something you can prove you did, because it's based on performance to some undefined standard. Some jobs that have a more mathematical method, like sales or finance, can do this differently, but for a programming job, it's usually tied to subjective assessments of performance. That can be helpful, because if you thought something was going to be a quick task and it ended up dragging on, management can decide that this was reasonable for you to not know and give you a bonus anyway, but it can also go the other way.

In some cases, you might have a case. For example, if you had a goals list written six months before, completed every item on it, and they still denied you a bonus, that could be convincing evidence in a complaint. However, most tech jobs I have seen have these lists but end up changing the plans halfway through, meaning that inevitably some items will not be complete because they were deprioritized or even eliminated, and if the management say you were not productive on the new things, that's much harder to disprove in a complaint even if it's a complete lie. The same thing happens with promotions, pay rises, or anything else where it's at the manager's leisure.

doublelayer Silver badge

Again, you're too happy to assign all responsibility to the boss. Let's try an alternative: I'm hired by a startup who has no tech staff. I tell them that I'm an expert on Linux and can definitely write the kernel module that they're going to make part of their major product. It turns out I'm a basic coder and don't actually know how to do that well. My attempt crashes the hardware, leading to financial losses. Who is at fault?

If the article included a sentence like "Ivan was not familiar with telecoms equipment and had warned the other two members of the company, but they decided that it would be fine and told him to write the software anyway", then that would have changed it. The article does not include that. We don't have anything near enough to assume that exists as you are doing.

In my example, I am at fault for making the mistake, and if the others are, it is for choosing me in the first place. In the case of the article, it's far less clear, because it sounds like Ivan was reasonably competent and happened to have one bug which was triggered exactly once. No matter how competent Ivan was, no matter if he had had a decade in telecoms and was as expert a person as you can find, that could happen. Although I'm in the position of arguing that the dev has responsibility, I'm also in the camp that bugs should be expected and, unless they indicate significant negligence, nobody should be penalized for them. Had they cleaned up properly after that bug, they would have had no problems, and that is why I say that the manager is at fault for the actual problem: the risk of legal action from failing to refund the customer when they made a mistake. But you're going much further and trying to assign automatic responsibility for anything, which is not how that should or does work. You're making up evidence that does not exist to make it more plausible, but your general statements suggest that, even if Ivan was a telecoms expert, you would blame the nontechnical boss for not intuiting that there would be bugs and allowing it to release, which in my opinion is unreasonable and unrealistic.

doublelayer Silver badge

True, but they didn't have a problem with payment systems. All the testing they needed to do is printing "Would charge customer {customer_id} amount {amount}". The part they needed more testing of was the phone disconnection thing, and I don't know how that works, so I don't know if their issue was down to insufficient testing, testing something theoretical that didn't act like real equipment, or just very bad luck with an intermittent phone system bug. The last one would probably have been harder to patch with more failures, so that seems unlikely, but any of those is possible.

doublelayer Silver badge

I'm not sure that's relevant. No matter how much testing was done, the important part to legal action would be who could and was supposed to refund that order. I don't know, but from most places I've seen, that's not something the dev is allowed or even able to do. Refunding orders is usually a manual process run by whoever is doing finance or customer management. The biggest problem here was not the bug, but the failure to refund when the bug was detected which was almost immediately. That is the reason I think the dev is not the blameworthy party here. If the dev did have the authority and responsibility to manage refunds, then I'm willing to blame him again because that should have been obvious; I just don't think that's very likely.

doublelayer Silver badge

Both people are responsible to some extent. The boss doesn't take total responsibility for everything. I'm not sure how this bug cropped up, but if it was deterministic, it evidently didn't show up in the testing they did. Does that mean testing was insufficient? Maybe, in which case it's probably more on the dev than the boss who can't dev/test and hired this person to do it. And the dev was probably the closest thing to telecoms expert they had, and it's not automatically the boss's responsibility to question that. Just because someone said they're ready to turn on doesn't mean they take responsibility for any failures created by others.

In my opinion, using my best assumptions since most data isn't available, the responsibility goes like this:

1. For the bug meaning someone was overbilled: the dev.

2. For not refunding the customer immediately: the boss.

3. Therefore, for the risk of legal action: about 100% the boss, since if the refund was issued immediately, there would be no cause for action.

But in a situation where things worked out differently, if we assumed the existence of a bug that cost the same amount but wasn't mostly due to unethical business practices, that could go very differently. It still wouldn't justify lots of consequences for the dev, because the business has to cover the costs even if the dev is responsible, but it would likely justify losing a bonus, and some businesses fire people for that kind of thing. I don't think that applied to this situation, but your "The boss is paid to take responsibility" theory is unacceptably broad.

doublelayer Silver badge

I agree that this needed to be considered, and I've written a comment to that effect, but I don't know if this is something the dev is responsible for. That sounds more like a finance thing. From the information in the article, I don't know if the dev knew that the money had not been refunded at the time. If that was not the dev's responsibility, I feel more sympathy for them.

doublelayer Silver badge

Re: Lawsuit culture

Except they only refunded the payment after people showed up at their offices. They should have figured this out when the call didn't drop and issue the refund at that time. Keeping the money longer could have caused lots of problems for the payer, and depending on that length of time, that could be argued as a deliberate act rather than an oversight, and from the information we have, we know it was one because they had noticed the problem but evidently didn't choose to fix it then. A lawsuit wouldn't have been justified, and the people clearly didn't choose to pursue one, but there is a reason to think they might have been able to had they proven litigious.

China's IPv6 adoption takes a decent leap forward, especially on fixed networks

doublelayer Silver badge

Re: “Let’s create a world where every interaction with governments is assisted by digital agents”

I doubt it. An LLM can "infer" some of this and can definitely write that down, but it won't be able to make things happen as a result. It's not hard to get an LLM to write a paragraph explaining the consequences of a cable on the ground, but if there is no procedure to report this as an issue, that paragraph is not going anywhere. From the comment, we can be pretty sure there isn't, because a human did hear this, did recognize that something happened, did open a ticket, and still nothing happened. The problem is the lack of response systems for that situation, and whether it's a human or an LLM in front of that, the problem is not fixed.

Microsoft gives in to Chromebook bullies and drops Windows 11 SE

doublelayer Silver badge

From the post where they said they didn't support it, the user had managed to erase it and install Windows 11 which booted, but their problem was drivers for the original hardware. So yes, you can, and I wouldn't be surprised that those drivers can be found somewhere. The specs of one of these (4 GB of RAM, 64 GB of EMMC, and a Celeron N4020) probably aren't too fun to run Windows 11 on, but there are people selling machines with that spec running normal Windows as it is. Hopefully nobody buys them.

Another one bites the dust as KubeSphere kills open source edition

doublelayer Silver badge

Re: Two wrongs don't make a Right...

That is what I was saying. Back when it was open source, if they had to sue someone for violating that license, they could have gotten help, and they probably wouldn't have needed it. That they didn't do that suggests that they didn't need to, which suggests that they are now being dishonest about why they made the change they have.