The Register Home Page

* Posts by doublelayer

11559 publicly visible posts • joined 22 Feb 2018

The 'End of 10' is nigh, but don't bury your PC just yet

doublelayer Silver badge

Re: TODO

You write software and are an electronics engineer. How many people your age globally are electronics engineers? Consider people who might have done different things with the first decades of their lives and consider how likely they are to have used as much Linux, or any at all, as you have. Similarly, there are some very young people who know everything about Linux because they had a Raspberry Pi as their first and only computer and they can tell you all sorts of little details about kernel structures and how they interact with hardware and how software interacts with them. Do you want to take a person at random of that age and trust them to do kernel dev right?

doublelayer Silver badge

Re: TODO

"People of my generation are likely to have run both Windows and Linux, certainly I have since version 0.1 or thereabouts."

Please don't ascribe your experiences to everyone in your generation. When you were testing version 0.1 of Linux, a lot of people of all generations didn't have a home computer yet. No, most of your generation have not run Linux before, just as a lot of people of all generations have never run it on a desktop, have never run servers, and don't interact with the Linux part on any of the embedded devices that have it. When we're on this site, we can assume that most people who were young in the 1980s programmed a ZX81, that people who were students or young adults in the 1960s or 1970s punched cards, that people alive in the 1990s toyed with Linux, BSD, RISC OS, or BeOS. Oh, and often when we assume this of everyone, we're still wrong. But if you make similar assumptions about the world in general, those assumptions are so often wrong that it rounds to always wrong. Most people did not program anything, ever, and they don't want to do it now, and one of the challenges of getting them to run Linux is convincing them that they don't have to program the computer to make it work (they will count CLI commands as programming). These are not people who have already given it a spin.

doublelayer Silver badge

Re: Decision tree?

There's logic in it, but it's a lot more work and there are potential problems, for example:

"Do you use rare functions of Microsoft Excel which won't work well in LibreOffice Calc?"

Some users select yes because they use really complicated features of Excel like the formulas and that box that makes graphs.

Some users select no because LibreOffice looks like it's got a lot of features, so it will probably work.

Most users select "I have no idea" because they've never tested anything in LibreOffice.

It's hard to ask sufficient questions to give a good answer without running the risk of confusing users, possibly causing them to just give up. In some respects, it might be more reliable to simply give them some version that's likely to work and letting them see if it can do what they want, and if I had to recommend something for people who have no support and insufficient knowledge to figure it out for themselves, I might propose that method*. The problem is that it's not easy to coach them through installing it in such a way that, if it doesn't do what they want, they can go back to Windows safely, because it's very easy to break dual booting if you don't know what you're doing during installation and that will just mean a lot of people angry about how Linux broke their computer.

* I have helped people by giving them equipment which I created out of discarded computers and parts. I didn't have Windows license keys just sitting around, so they came with Linux, usually just the latest Ubuntu LTS, and I told users I'd help install Windows if they bought or already had a license and asked for that**. Quite a few of them were able to find the applications they needed. I'm not sure I ever found someone who didn't react with some uncertainty when faced with it, but since many of them just needed a web browser and word processor, Ubuntu was often fine. At least, if it wasn't fine, they would have a specific thing they had tried and didn't work which I could review which was more reliable than asking them beforehand and hoping they gave enough information to predict it.

** I wasn't trying to promote Linux there. Whatever the user wanted and I could provide, I did. I did try to avoid spending a lot of time personally teaching them how to use the machine, though, because that is a nearly infinite time sink. I really respect those who have the time to do that more consistently.

Uncle Sam claims H-1B fraud crackdown is working as registrations drop 25%

doublelayer Silver badge

Re: Scam

It depends how you offshore. The problem you mention happens if you subcontract it to a local company in a different country which is contracted to provide a service, but if you set up your own local subsidiary and employ people as employees, then you do know exactly who is doing the work because you selected and approved them manually. The two are very different, and comparing them as if they all work the same will lead to incorrect conclusions.

VPN Secure parent company CEO explains why he had to axe thousands of 'lifetime' deals

doublelayer Silver badge

Re: How is this legal?

No, that's not how anything works. If I provide you something that I have no obligation to provide you, I don't automatically adopt an obligation to continue providing it. There's no automatic assignment of liabilities. It's all very explicit in the transfer documents of exactly what they're taking and what they're not, and their later actions don't retroactively change it.

doublelayer Silver badge

Because, sometimes, people lie. Evidently, some lifetime VPN systems actually work. I would not have predicted that. However, most of them could not afford anything close to that usage, and I'm guessing your provider no longer offers that option and is paying for your usage from subscriptions of others.

For the same reason, when I was recently advertised an Android phone from Aliexpress with 16 GB of RAM, a terabyte of internal storage, running Android 15 on a high-end processor for about £60, I knew that this was not what I'd receive if I chose to buy it. I would have liked that to be true, and I was tempted to order it if only to see what they actually sent as I could always deny payment for the fraud. It's still illegal for them to do that, but it can pay to opt out of a crime at the start rather than hoping that you can recover your investment after it's completed.

doublelayer Silver badge

Re: How is this legal?

If they are, in fact, two independent companies, then there is no case for fraud against the new ones, but depending what happened to the old ones, there might be. If the old ones sold off the VPN business and took the money, that's fraudulent conveyance, and customers and creditors can sue them. If they sold off the VPN business and are still operating, then customers can sue the old ones for breech of contract, depending on what the contract said which might go either way. If the old ones became insolvent, there's no fraud and no case. If the new ones and the old ones are the same people, that's more obvious fraud.

doublelayer Silver badge

Re: How is this legal?

That's what happens when companies merge everywhere, but they are not claiming to have merged. They are claiming to have acquired the assets, not the company, and possibly not all the assets of the old company but just those for the VPN service. If, for example, the old company was going through bankruptcy, it would be normal to sell off the assets to make money to pay for the liabilities if you couldn't find someone willing to take them both. Of course, if a company tried to sell off their assets and not pay their liabilities outside of bankruptcy, that's illegal. Canada isn't special in this case; the same things are legal and illegal there.

doublelayer Silver badge

Re: How is this legal?

From the sound of it, the previous owners didn't sell on the liabilities, so either the previous owners still have those contracts and could be pursued for the service, or more likely the previous owners went bankrupt in which case those contracts are probably void*. The new owners would own the domain name, the VPN software, and a list of former customers who can become current customers. Of course, if the rumor that these are the same people is true, that would be fraud.

* Depending on the text of the contract, the insolvency of that original company could probably be argued means the lifetime of the company has ended and thus the contracts expired. If they didn't say that, then the company would simply be unable to meet their obligations and the contract holders would be considered creditors, but given the prices of the contracts, creditors unlikely to ever see any of the money that liquidation generates. Either way, it's not coming back and there's almost nothing you can do about it.

Ransomware scum have put a target on the no man's land between IT and operations

doublelayer Silver badge

Re: Back to basics

It will probably take some massive disaster caused by an attack. So far, most criminals don't want to destroy this kind of stuff. They want money, and they won't get it if things are blowing up or bodies are dropping. They get it if all the business computers don't work, so they still mostly aim at those. Most companies have never had an incident like this, so they're going on reports of what happened to someone else, which are much easier to ignore than things that happened to you. Meanwhile, security people are busy running around attaching locks and tape to these systems in the hopes of preventing what they can, and those methods actually work a lot of the time*, so people who look at the effectiveness of current methods don't think they have to do anything more.

* Because, although we're nearly always telling users and employers otherwise, a lot of attackers are opportunistic, and if you have better security mechanisms than someone else, they'll go hit the someone else rather than work at breaking through yours. We're not lying about needing to have good absolute security, not just in comparison, because those attackers will try to hit as many places as they can, but a medium level will often knock out a lot of the attempts. That doesn't work when dealing with someone who actually wants to cause destruction rather than earning the most money from the least effort. Those people can and will break through much more complex things to do it.

doublelayer Silver badge

Re: It's not rocket surgery...

If you decide you want to run your own cabling, it would seem more logical to run it outside but alongside the pipes rather than in the pipes. That would fix most of your concerns. Why you need that and whether there might be a less complicated way to obtain your goals are still legitimate concerns.

Meta's still violating GDPR rules with latest plan to train AI on EU user data, says noyb

doublelayer Silver badge

Re: Consider...

Most of your "what would have happened" examples have no plausible link to having privacy regulations at the start of the internet. I'll agree with your first one: if you want the AI to be a little better, training on reliable data that's relevant would help. I don't particularly care whether it gets better, but I do care about having my personal data considered free for the taking, so I don't mind that tradeoff. Also, I don't think most of my personal data would be helpful training data. Also, even if you did want it, nothing says that the AI companies should be able to get whatever part is useful for free just because. But apart from those three problems, the general theory is right.

That's more than I can say for the rest of them, such as:

"no comment forums like this one" Why? This forum is funded by the paper it's connected to, which is funded by advertising. Advertising would still be permitted. It would be less targeted to your browsing history, and instead it would be targeted based on what's on the site, which worked pretty well in the past, and might actually be better because a lot of targeted advertising isn't targeted well. Why would they be unable or unwilling to run a forum?

"you would be charged per e-mail sent": Why? Because all the email providers that don't use the mail for tracking charge per month or per gigabyte, not per message. Some of them are also free, using the untracked mail as a loss leader to attract people to other businesses. What would change?

"governments would licence and whitelist all websites": Why? Just why? How on earth did you get from privacy regulation to that?

You made up all these things, including the many I didn't bother to list. Almost none of that would have happened.

Linus Torvalds goes back to a mechanical keyboard after making too many typos

doublelayer Silver badge

I do wonder about the many people who post here who have trouble finding a keyboard, because I've got a keyboard much like yours. It's from some no-name manufacturer and I might not be able to find that specific model again, but it's basically what you asked for:

Very standard layout, has a numpad which I could have done without, brown switches, backlight is configurable to all white (I turned it off). I wanted a mechanical keyboard, but I didn't see any significant advantages from the expensive manufacturers, so I went for the cheapest normal-shape keyboard with the kind of switches I like since I don't want my keys making any more noise than they're already going to make with the extra travel. That keyboard has been working fine for the last six years and I expect it will continue to work fine for many more. It cost me about £40, so I'm wondering whether there's some other feature that people are looking for but they consider so obvious that they aren't mentioning.

After more than half a century, the voyage of Kosmos 482 is over

doublelayer Silver badge

Re: no mention of radiation

Other Venera probes were powered by more conventional chemical batteries because Venusian surface conditions weren't great for the same kind of RTG power sources that we use on Mars. That doesn't prove that this one didn't try it, but it seems likely they'd do the same thing they did with previous probes on which the batteries were sufficient for their experiments.

Amazon tested warehouse robots and found they're not ready to replace humans

doublelayer Silver badge

Re: Capitalism is dying

Nobody said that it was always a utopia, just that mechanization did not eliminate jobs leaving people with no option. The industrial revolution was horrific in many ways, but before we put on our rose-colored glasses, the time before it wasn't very nice either. You've focused on people doing the same work. Things got worse for them, with the guild weaver earning more money and living a better life than the factory weaver. The point of the guild, of course, was to make sure that there weren't many guild weavers, and those who could have woven but weren't allowed to had to do other things, things that were often paid worse than and with similar danger levels to the mill workers they would be decades later. They just did them with less commentary because that's how people had lived for a long time, so lots of injuries and deaths was not seen as in any way surprising.

That doesn't tell us a lot about today, but one thing it might is that, when people predicted massive losses of jobs from a technological advancement, they were often wrong. We're not just talking about 1800 with its scattershot record-keeping either. The same predictions were made throughout the 1900s with advancements like more efficient assembly line manufacturing, less labor-intensive materials, and of course, computers which were going to do everyone's job any year now. The first is now seen as heralding one of the most laborer-friendly periods, but that was not obvious at the time and many fought against it on the assumption that lots of workers would lose their jobs, nor was it inherent in the technology, since it's a combination of societal and technological factors that determines how a new situation will be felt. Therefore, maybe we should wait for evidence of massive losses of jobs without replacement before we say it's different this time.

Nextcloud cries foul over Google Play Store app rejection

doublelayer Silver badge

You're right that it's a global requirement, and wrong about everything else. It's a global requirement so it depowers Android applications, making them store as much data as possible in the /data/data folder that users can't access, and user-installed apps can't access, but you know what can access it? That's right, Google sync software and Google backup software, installed and running as root. Now, why do you think they put in that requirement. It's not enough to just tell us that they did. If there's no actual security benefit, then that answer is not good enough. They aren't going after Nextcloud here. They're going after a bunch of different apps, of which Nextcloud is only one. They've taken similar steps to reduce access to users' data through any mechanism other than OEM-installed system apps, for example deprecating ADB backup without replacement.

But maybe this is Nextcloud's problem because they should be using some more secure method. Let's see what other applications use. There are convenient privacy reports that show the permissions apps use. Dropbox has READ_EXTERNAL_STORAGE and WRITE_EXTERNAL_STORAGE, the ones that implement access to all files. OneDrive, Box.com, Amazon Drive (write only for some reason), all have these permissions. But maybe these are just all lazy companies. What does Google use? Google Drive uses exactly the same permissions to do it.

I don't think Google is targeting Nextcloud here. I think Google is trying to target everybody, but if they did the same thing to the big players like Microsoft or Dropbox that they're doing to the small ones, they might get some real legal attention. But if you think this is totally normal, you can explain why Microsoft, who has thousands of programmers at their disposal and updated their OneDrive app lots of times since Android 11 was released, gets to use these.

US, China agree to roll back tariffs – but only for 90 days

doublelayer Silver badge

The reasons differ depending on whose reason you're thinking about. Trump's reason is because he is into mercantilism. That says that exporting is good because you get money from other people and thus have more money, and importing is bad because you give money to other people and thus have less money. It doesn't work because it fails to recognize that there's a lot of stuff with value that isn't money.

His supporters probably have a bunch of different reasons, and some of them like the mercantilism idea too. The other important one, though, is many people who have, either in reality or in their perceptions, lost a quality of life they once had or expected. People who expected that there would be easily-obtained and well-paid employment and found that these were not as simple as they expected are unhappy with their current situation. In some cases, that decline is real, whereas in others, they're actually able to obtain work that compares well in compensation and difficulty to their previous options, but they would prefer it to be easier and are under the misconception that it was better at some previous point. Various other factors, such as the increased prices of expensive things like houses and education have exacerbated this problem. Politicians, searching for a simpler explanation for this situation than the many realities of economic, technological, demographic, and geographic change, have decided that manufacturing in China is a convenient thing to blame it on, because it was at least part of the answer, so it can be stated as the whole answer. Therefore, anything you do that hurts China would have to be pushing the US back to the ideal times of the past where their lives would be better.

US Copyright Office found AI companies sometimes breach copyright. Next day its boss was fired

doublelayer Silver badge

Tell you what. Try that argument in a court. When you are convicted, that will prove how much your opinion matters when there is a law that says these things.

There is code I want to use. I have access to it; somebody posted it. It is copyrighted to a company who has not released it as open source. Guess what will happen if I try to use it for commercial purposes? Maybe they won't notice, in which case I'm fine. Maybe they will, in which case I can be sued. The fact that it's online, whether they intended it or someone posted it illegally (it's unclear) makes no difference at all. no matter how much I might want that to make a difference, it doesn't. Your opinion doesn't matter because this is about facts.

doublelayer Silver badge

No, and if the license sneakily says you're not allowed to read it after you've read it, that's a reasonable excuse. But this is not that. This is being allowed to copy and use it as you like, which is when you have to look for the license. If you didn't know that, this is your official notice. Not everything you can read is free for unlimited and unrestricted use.

Unending ransomware attacks are a symptom, not the sickness

doublelayer Silver badge

Re: Make the management legally liable

It's weird to see calls to make someone legally liable in the same comment where you suggest that you'd ignore a known attack. You do know that, if you got what you asked for, you're the person those bricks would fall on, right? Of course, you could be lucky: the liability might mean that more resources get assigned to security and then you don't have an attack to ignore. If you're unlucky, and your managers don't invest the resources, and you don't ignore the attack, then they will get the punishment for the problem. If they continue to ignore issues, you follow your stated procedure, then they have the perfect scapegoat because you're the incompetent who saw the evidence and promptly went home.

It isn't feasible for the stricter liability policy to only affect management. For example, if management provides tons of resources, hire new people, buy any software you like, overtime is easy, and some IT employee deliberately doesn't use them, then that employee is responsible for failures and would receive the consequences. A law that doesn't make that happen is obviously unjust and would not be passed. This means that, if you have such a law, the aftermath of an attack becomes a race for a scapegoat, a race you will only win if you are very professional despite your limits. Some people would approve of this, as it will at least encourage people to be vigilant to avoid personal consequences. Others recommend against it, using a similar logic to the no-blame investigations used in aviation to focus most of the energy on avoiding recurrences. Some others would be fine with blaming, but they would also argue against this because management generally has an advantage in the scapegoat search than the employees, since it's much easier for them to look for mistakes from the underlings than it is for the employees to get evidence of management's decisions. Arguing for strict consequences, but only on people who aren't you, is an unworkable and dangerous alternative.

If Google is forced to give up Chrome, what happens next?

doublelayer Silver badge

Because the problem is not any search engine owning any browser, but the most dominant search engine owning the most dominant browser. It being owned by Yahoo isn't going to matter because, outside Japan, nobody uses Yahoo search. Until Yahoo becomes the largest search engine by market share, they wouldn't be a concern under antitrust law.

doublelayer Silver badge

Re: Solving the wrong problem

Because a court can't do that. Making targeted advertising illegal requires a law to be passed by legislators who aren't interested in doing that because, should one of them suggest it, they would be buried in letters from interested businesses explaining how that would cost them four trillion dollars per hour and require them to fire every employee they have. Their colleagues would not have much interest in helping get that law passed when ignoring it would be the much easier solution and many of them believe the prognostications of doom and therefore oppose it. The selling Chrome option is an option because it's permitted by laws that have already been passed. If you can convince US politicians to pass that law, your problem will be solved, but you can't, nor can you convince any other countries' politicians to do it. The closest law we have to that is GDPR, which is enforced so halfheartedly that it has little effect, and the one you're proposing is an order of magnitude more drastic.

doublelayer Silver badge

Re: Think

The theory would be that their ad business makes a bunch of money by selling ads and the rest of their business makes a bunch of money by having places for ads to go. If they were separate, then Google (services) would still make most of what they used to make and would sell ad placement to the highest bidder among advertising networks, and Google (ads) would make money by being one of those networks with a lot of customers.

Some parts of Google would work just fine under this arrangement, for example search. Some parts wouldn't but could be kept or spun off as somewhat profitable enterprises of their own. Some things would crash and burn because they don't have enough places to insert ads to make all their money that way and they've been attached to Google (data collection) instead, or they just never made any profit but nobody noticed because all the rest did.

doublelayer Silver badge

Chrome being sold to some types of others might make Google even more desperate to pay Mozilla. If it's sold to someone who will replace Google with a different search engine, then Google will lose search revenue and will want more browsers to default to them. I think Google would prioritize selling it to someone who doesn't run a competing search engine and will keep Google due to popular demand, but maybe they won't get the choice.

doublelayer Silver badge

Re: Where's the standalone value?

It's the data and the users. You can grab and sell the browsing history of a couple billion people [warning, this is illegal, but nobody will stop you] and send the users to places of your choosing. As long as the places you're sending them are other search engines or ad sites and not malware, you'll get away with it. That's why it's worth so much. Of course, companies will probably overvalue how much you can make by doing that, but if Google has to sell it, they'll find the one that values it highest, whether they know what they're talking about or not. If it's not, as it probably will be because I'd bet on OpenAI having the highest bid*, that's the buyer's problem.

* OpenAI is used to having billions at their disposal which the backers don't mind them throwing into the shredder. Most other companies at least sometimes have to justify spending decisions. I'm not sure how long they can continue to find credulous investors, but some of them might see a Chrome purchase as a way to get even more users, because historically, a lot of startups have benefited a lot by throwing their product in front of millions of people and getting more customers this time. Some investors have not realized that the economics of AI-driven businesses are a bit different.

37signals is completing its on-prem move, deleting its AWS account to save millions

doublelayer Silver badge

Re: "Someone Else's Computer" is nonsense

The problem with that analogy is that, for a lot of the time, if you build equity in a house, you can sell it for more than you paid for it, and in many of the cases where that didn't apply, it was at least worth the same amount. After you've paid for a server, it decreases in value until you can't sell it at all and the remaining value is just continuing to operate it until it breaks. Owning a house means that, at the end of the process, you have an asset that someone else will probably buy. Even if you smashed up the house, someone will probably buy the land to build a new house on it. At the end of a server's life, you have some scrap metal and need to buy a replacement.

Renting might still be more expensive, but not necessarily. There are two other things you need to consider in your comparison. One is the different things you get when renting and owning. Renting means the power, space, and some types of hardware maintenance are included. Make sure to include those costs for owning the server when you compare them. The rental option may come with extra costs too. For instance, you're probably paying for data transfer by the gigabyte whereas you may not have any metering on your local connection. Add that one too. In many of these cases, those prices are not identical to what the other side would be paying so you can't eliminate them with the logic that "you're paying them either way". If you're paying indirectly for electricity usage which the cloud provider has optimized for because they run lots of electrical equipment and don't want to pay too much, they may have lower costs than you would. If you've got a lot of traffic to send, their bandwidth pricing might be an order of magnitude more than it costs you to rent usage of a sufficiently wide pipe. You have to know what the numbers are and only then can you compare them. No shortcut will give you that power.

doublelayer Silver badge

Re: "Someone Else's Computer" is nonsense

The context is clear. They were not saying that cloud is better because it actually provides that. They said that avoiding cloud doesn't provide it either, thus that the decision of which one to use shouldn't rely on incorrect assumptions that one will compensate you if it breaks and the other won't.

doublelayer Silver badge

Re: In six months...

"I spent 45 years in the onperm space as a server/database consultant to very large organizations"

Evidently much more professional ones than I've seen because several of the things you've never seen are not so rare in my much shorter experience, also on prem though cloud users got them too. For example, some of the stuff you've never seen:

"storage (say S3 buckets) being left wide open for the world to steal from cause wide open was the default config": I work in security. People leaving things open that they shouldn't because unauthenticated was on by default is really common. Where the server is makes no difference. That's down to config. People are often lazy with configs and it's often a problem.

"customers thinking XXX service meant remote failover but it didnt": Definitely seen it. People who thought that they had built redundancy into their system but they didn't happens whether you're using cloud services or not. Cloud services provide some tools that you have to build yourself for on prem, but it doesn't save you if you don't know how they work and what you have to do to use them properly.

"The BIG difference is your on perm team CARES about the systems they manage... cloud teams not so much.": You just made that up. I've dealt with on prem teams who didn't care, cloud teams who didn't care, dev ops teams that didn't care, managers who didn't care, and occasionally each of those things that did care. What they were doing was not a good indication of whether they would care about it. You can manage cloud services and care about them staying up and functional. You can manage your own servers incompetently. Your allegation that either of those doesn't happen is obviously wrong.

Curl project founder snaps over deluge of time-sucking AI slop bug reports

doublelayer Silver badge

Re: It's the spam effect

No, your downvotes are because nothing related to this has anything to do with advertising. The article and most comments are talking about spam security reports. Those are not adverts. The comment you replied to got closer to adverts, since it was talking about spam email. Yes, those are adverts, but banning all advertising wouldn't do a thing about it because the spam is already not allowed and the spammers are doing it anyway. Thus, whatever we may think about advertising, it isn't relevant.

Also, you have followed your typical pattern and gone too extreme on the negativity. I don't like advertising either, hence why I have a multilayer blocker in place to filter out as much as I can. There's a difference between that and justifying making it illegal, let alone making it illegal and actually enforcing that law to block it. It's much harder to justify that, but I'm not going to bother arguing on either side since you've not tried to do so either. You just called for it without providing reasoning.

doublelayer Silver badge

Re: It's the bug bounty

In addition to the points others have raised, there are two theories for why paying works better than just having an unpaid reporting mechanism, one of which I believe and the other I don't.

The good reason: it convinces people to look for security problems. There are people who will work actively to try to find a problem if they can get paid, whereas if they're working for free, you may only get reports they stumble on by accident. It can be quite cheap, because if they don't find anything, you don't have to pay them. I have not tested this, but I certainly have seen more reports sent when payment was offered, even if many of them were crap.

The less convincing reason: fears that the bad guys will pay for a vulnerability, so profit-oriented people will sell it to them unless they can make money by reporting it. I don't buy this. All of the parts of that are true, but I don't think bug bounty programs make a difference to any one of them. A criminal group will spend more for a good vulnerability than any bug bounty program will pay out. Most people who find one would be unwilling to sell to criminals because they don't like criminals. Most who would be willing don't know how to find them. Those who are willing and able have other reasons to choose not to, such as not having a reliable way of trading their vulnerability for cash when, if they send the details up front, the criminals don't have to pay because they have the vuln now, and if they don't send enough details, the criminals don't pay because they're not sure the thing is real. Someone who can get through all of those hoops will probably not bother trying to see if the company will outbid here.

doublelayer Silver badge

Re: Sorry to nitpick, but...

AI filters for AI text have been tried for a long time and the answer is usually no. You can make a model that takes a guess, and in many cases, that guess will be reliable, but that's all it will ever be. If people realize you're doing it, they can easily make the guess less correct. For example, comparing real bug reports to AI-generated ones, there's often a significant stylistic difference between the two* so I can assume which are which, but if I am a spammer after a bounty, I can customize my prompt to make the AI write its text less professionally and more laconically, and then it will look more like the human-written ones.

* People write bounties in a lot of forms, but they are often writing more informally, meaning more acronyms, a little less jargon, and slightly worse grammar, than the ones LLMs often produce. They are also written more formally, including the reverse of all three of those differences, than human-written ones that turn out to be crap. I can often guess based on the style how likely one is to be useful, but I have to read and test it anyway because the well-written one could be from someone who just likes to speak formally when they're sending a message to someone they don't know and the one with worse grammar might be someone who isn't a proficient speaker of the language they're writing the report in. All you could do with an AI is try to sort them so the useful ones are higher in the stack.

Nip chip smugglers by building trackers into GPUs, US Senator suggests

doublelayer Silver badge

Re: I'm sure...

Most of the time, the locations they track would be pretty obvious datacenters because the denied chips are mostly only viable inside custom servers. The idea is stupid and probably not as feasible as the article, let alone the politician, thinks it is, because there's no magic tracker that would work the way the politician thinks and serial number tracking doesn't do much after the chip's been shipped somewhere else. If they did make a tracker, it wouldn't be good or helpful, but neither would it cause the problems I think you're implying since most places with a bunch of GPUs in them are already findable.

People find amazing ways to break computers. Cats are even more creative

doublelayer Silver badge

Re: Cats and keyboards

A cat I had was very polite about keyboards for some reason. She would walk across my desk to get my attention, but she would always nicely circle around the keyboard rather than tread on a key. However, she had a different experience with another type of keyboard. When she was exploring after a move, she was very interested in a piano and, I think, wanted to look inside it. Several times, she would jump onto the piano, but because I'd left the lid up, the piano would make a noise whenever she stepped on the keyboard. I was going to put down the lid and try to keep her off, but fortunately, she seemed to interpret the piano's noises as a warning, jumped down whenever it made one, and quickly concluded that she would leave the piano alone as it clearly didn't approve of her visits.

BOFH: HR tries to think appy thoughts

doublelayer Silver badge

Re: "HR tries to think appy thoughts"

No, it's the same one, named Stephen, all the way through. I challenge you to find a single example of either of the events you've claimed. You will find a couple attempts by the PFY to leave, which are often reversed in that article or a couple episodes later, and you'll find two attempts by the PFY to replace the BOFH by fire (literally). The challenge isn't serious, as I'm quite confident you won't find it, but you'll read a lot of BOFH stories if you attempt it which is reward enough.

PowerSchool paid thieves to delete stolen student, teacher data. Looks like crooks lied

doublelayer Silver badge

Re: What I do not see here

One reason you're not seeing that is that it's not a great solution. The solution I and others have proposed in comments is a bit similar: make paying ransoms illegal, and then you can basically do the same thing you want to do to them if they pay one.

Your solution is a lot more drastic and puts the CEO and CIO in a position they can't manage, meaning that you can't implement or enforce that. The CIO, or CSO if they have one, is responsible for trying to prevent and respond to incidents, but that doesn't give them total power to prevent them from happening. You can investigate them for negligence in some cases, but deliberately not all cases, because they are not all-powerful. For instance, if a criminal robs an employee at knifepoint of their work laptop and forces them to log in, that's not something worth arresting the CIO over. The same is true if some employee clicks on a phishing link and installs some malware. A successful ransomware attack is a bigger breech, meaning more likely that it's negligence on the part of the employees or management, but it's still not a guarantee of anything. I'd like you to consider whether it would be fair if we through the book at you if tech you're responsible for was involved in an incident, with or without your manager included? A lot of people who want senior management to face serious consequences don't extend that downward even when there are significant problems there as well. That would never fly, because when the CIO is facing prison time, they'd find reasons why someone else should be going instead and some of the time, those reasons would be accurate.

doublelayer Silver badge

Re: Money Laundering

"money laundering is the act of obscuring or obfuscating the destination or source of money."

No, quite the opposite. Money laundering is the act of providing incorrect information about the source or destination of money and specifically applies when that money is, directly or indirectly, from a criminal source. As the Crown Prosecution Service describes it:

Money laundering is defined in the POCA as “the process by which the proceeds of crime are converted into assets which appear to have a legitimate origin, so that they can be retained permanently or recycled into further criminal enterprises”.

You have it backwards. There are many situations where a business transferring funds to someone they don't know is entirely legitimate. For example, if a business buys items from people for cash, they do not have an obligation to identify those people before paying them. They can claim that as an expense on their records. Sadly, paying a ransom is similarly allowed, hence why the UK police haven't descended on anyone who has and extracted massive fines.

doublelayer Silver badge

Some of the larger groups did indeed build up a brand name so they could get more payments, but ransomware has long had lots of people infecting with badly written encrypters that wouldn't decrypt or went with the whole infinite extortion loop. Unfortunately, that didn't happen often enough to convince people that paying didn't help. I'm not sure this example will prove any different. While there are people who can hope that their problem will go away for one short bit of pain, people will pay ransoms. I think we will have to prevent them from paying to make a meaningful dent in the problem.

doublelayer Silver badge

Re: Money Laundering

I'm afraid you were probably mistaken when you explained that, because paying a ransom is not money laundering. It is a bad idea, unethical, possibly illegal depending on your jurisdiction, and should be made illegal where it isn't now, but even when it is, it's not because of money laundering laws which have nothing to do with the money until the criminals have it and want to do something with it. Similarly, it has nothing to do with know your customer laws because:

1. If KYC laws don't apply to whatever type of business you run, they don't affect you. A lot of businesses don't have those regulations in any case.

2. If they do apply to the type of business you run, they require you to identify those who buy services from you, not ones you pay for their services, illegal or otherwise.

If you were a financial institution and you decided to pay the criminals by opening an account for them and depositing funds, KYC applies. If you are or did almost anything else, they don't. If you actually get to choose between these two options, please pick the former in the hopes that the criminals are stupid and will identify themselves to get access to the funds, making them easier to catch. Paying ransoms is legal in a lot of places, including the auditing and tax implications. It is so legal that cyber insurance companies have specialized in doing it, while if it was illegal they'd be storehouses of perpetrators ripe for law enforcement action. I would like to make paying those ransoms illegal so that this stops, but that hasn't happened yet.

If you think using these incorrect legal arguments is helpful in convincing companies not to pay ransoms, I think you're using the wrong path. We have many examples like this article demonstrating how paying doesn't mean the business gets anything, whether the promise is destroying the data or helping with recovery. We can point to PR downsides of even a successful ransom payment which reduce trust. We can point out the consequences to others of propping up a criminal industry. All three of these options has a major advantage which yours lacks: when they call in a lawyer to review the plan, the lawyer won't be able to say "they misunderstood the laws and this actually isn't a problem".

You'll never guess which mobile browser is the worst for data collection

doublelayer Silver badge

The linked report gives those lists. The article doesn't quote the lists for all the apps because that would take up a lot of space and isn't of much interest. The problem, as several people have noted, is that those lists don't contain a lot of information. When it says "collects contact details", does that mean that it will remember phone numbers if you enter them into a form or that it finds everything about you and sends it to the company for later misuse? Either way, can you disable it or do you have to accept it? When is the data shared, with whom, and with what terms? None of that is in the lists you can find in the report, meaning that counting them is pretty close to the amount of information you can find by doing this.

doublelayer Silver badge

Re: Targeted ads

"I have pondered recently about how bad the "i hate your adverts so I am never touching your company again with a bargepole" is, or isn't, for advertisers to persist in ramming their wares into your eyeballs at every opportunity."

We don't know, but more importantly, they don't know. I have a feeling though that that has almost no effect. I don't react like you do to advertisements*. I do my best to avoid them and ignore the rest, but I don't record the ones that get through that filter either to intentionally patronize their business or to punish them. In many cases, an advertisement that you're going to respond that way to is one of the many completely useless ones, ones for products you have no interest in anyway or ones where you have no choice**. Also, most of the people who are as averse to advertisements as you are would be blocking most of them, meaning that most advertisers don't feel the effects of your animosity anyway and wouldn't be able to categorize you into that group if they wanted to.

* The exception is when I get the same advertisement over and over again. The main place I notice this is on podcasts, which I listen to several of. In many ways, podcasts work the way I'd like advertising to: they're run by an individual, there's not much tracking of the downloader to try to target an ad at, and there are only a few attempts at centralized advertising networks for them. Unfortunately, that sometimes means that they don't get many advertisers so you just hear the same one over and over. Even then, I don't automatically develop a grudge against the advertiser. In a couple cases, I have built up a grudge against an advertisement or even a product, but I think those grudges are based on real defects with those rather than just having the advert repeated.

** Sometimes, a product is either the only option or clearly the best one, meaning that grudges against the company are kind of meaningless if you know you want to buy one. My ISP ran some annoying ads, but I need an ISP, this one has better prices and contract terms than the alternatives, so I ignore the ads which I'd be subject to regardless and buy their service anyway.

doublelayer Silver badge

Re: I use Brave

I rate the "turn it off in the settings" arguments based on how feasible it is to do. For example, some of the things I find annoying in Windows are easily turned off in the settings and don't come back, so those don't bother me very much, but other ones either move around, require registry hacks to turn off, or aren't configurable at all. I take those ones much more seriously. I don't know how Brave works, mostly because I'm satisfied with Firefox as it is now and because there seemed to be a longish list of things I didn't want. I probably can turn them off, but why bother when my existing browser doesn't have them in the first place?

Linux kernel to drop 486 and early 586 support

doublelayer Silver badge

Re: junk like the Celeron

Why is having a massive profit margin dishonest marketing? Annoying I get. Choosing to buy someone else's product that's reasonably priced, definitely. But if the answer is that their product is actually better, they can make it cheaply, and they're choosing not to let you buy it cheaply, that's just normal. The same reason that I would probably have accepted a lower salary when my current employer hired me, but they offered a certain number and I accepted it or even negotiated it up. It's how everything works and they aren't lying when they say that this is how much you have to pay to get one of these things.

doublelayer Silver badge

In addition to all the comments about what will still be supported, there's also a lot more choices for embedded systems processors which support Linux just fine. There are probably many cases where an old design does require a 486-compatible chip, but most embedded devices can work as well if not better with a different processor that's running a different ISA with more features, lower power requirements, and because everyone's using them, much cheaper.

doublelayer Silver badge

Re: Hubble Telescope.......

True, but they implied that the presence of that chip inside the telescope was relevant, which it isn't because it doesn't run Linux, and it wouldn't be even if it did run Linux unless they were pushing kernel updates which, for something that's really hard to fix if it ever didn't like a kernel update, they wouldn't be doing. Nor is it relevant for any machine with one of these CPUs unless the users of that machine have actually been updating the kernel version. There are indeed a lot of old machines with these processors in them. Almost all of the ones I've seen are running old software on the old hardware. Linux 6.12's the last LTS version with support? Some of these things are still running 2.6 kernels and the more updated ones are running 4.x ones. If you're running a 486 with a 6.x kernel, I challenge you to explain why, and only then will I start to worry about dropping support for it. If people haven't updated before when they could have, then I won't be bothered about cutting off the stream of updates they didn't use anyway.

Pentagon declares war on 'outdated' software buying, opens fire on open source

doublelayer Silver badge

Re: Enlighten Us !

You won't be able to determine the security of software based on location of the developer. Your country, as well as every other, contains evil people who will intentionally subvert security procedures and incompetent people who will break things by accident. This is why you have to analyze what you're running to some extent, which is indeed difficult. If they decide that doing that with open source software is too hard, they can write everything they run themselves, which will be expensive and means a lot of things they'd get by default with open source they will have to pay for, but maybe it will provide better results. Alternatively, they can use the fact that lots of people should be analyzing open source software when they're running it to distribute the costs of doing this across many organizations running the same stuff, which does happen some of the time already. Alternatively, they can do what most institutions have done so far, they can just not bother to analyze what they're running and hope for the best. Hoping to do it based on nationality guarantees that you'll get bad results while some clueless person thinks they've figured it out.

Top sci-fi convention gets an earful from authors after using AI to screen panelists

doublelayer Silver badge

Re: Detector triggered...

I'm less confident about this, mostly because this is a very public apology. Those will have been written and rewritten about a dozen times before they're released. LLMs could have been used, but you could get the same effect by just shopping around the statement to anyone trying to make sure it contains the right amount of contrition, explanation, and buck-passing. I also have a filter which works most of the time when the human-written text was written in one go and at most self-edited. I wouldn't have confidence in my filter on stuff written by a group of humans who are trying not to anger anyone.

Commodore OS 3 is the loudest Linux yet

doublelayer Silver badge

Re: Sell a usb stick?

Why would you pay for that? I think the optical media by mail service was mostly for people who didn't have a network connection fast enough to download those quickly, but most users can now download a normal distribution overnight or this monster in a couple days, and many can shorten that to a normal one in half an hour and this in four. Most users who would have trouble creating the USB disk themselves would also have trouble using Linux or knowing it existed. What would the convenience element be here compared to just downloading and writing it to a disk you already have?

Redis 'returns' to open source with AGPL license

doublelayer Silver badge

Re: "People moan because it wasn't the open source license they like"

The problem is that, to know whether something is open source, we need a clear definition of what that means. The OSI is not the only place that has a definition, nor do they really get a monopoly on the term. However, I tend not to accept someone else's idea of what it means unless they can provide their own unambiguous definition and apply it consistently. Often, when someone does that, I don't find their alternate definition as convincing or persuasive as the OSI's, which I mostly agree with. This is not for any reverence for the OSI itself. I never check whether the OSI has stamped their seal of approval on a license, and I disagree with them on a lot of things, notably their AI licensing thing which I think is completely wrong. The definition they're using, however, is pretty good.

Most of the faux-open licenses use vagueness to imply that it's basically the same and rely on "it doesn't affect you" to distract from problems. I have a problem with both of those things. A lot of them have their category of people who get extra restrictions if they use the software, a category based on vague conditions like "commercial use", or, in the case of the SSPL, "as part of a service". The licenses do this because the authors want to apply it to certain people, often cloud services. However, it's easy to argue that everything is part of a service unless it's running offline and only used by me personally and everything is commercial use if there's any possibility of money being involved, for example if there's a donation button on the site, even if nobody's ever clicked it. Even if it's only against AWS and Azure today, someone who wants cash could easily change their mind about those terms tomorrow. In all the cases I'm complaining about*, there is already a precedent for this because they just changed their licensing already, so changing their interpretation of "service" is a much smaller change which could cause problems for everyone. That is not a small difference from the AGPL.

* I do not object to someone who writes something from scratch and wants to license it under one of these from the start. I object when someone made their software open source then switches to it, mostly because they are taking the contributions of others to do it, and in some cases, preventing others from using their own contributions without forking.

doublelayer Silver badge

Re: "People moan because it wasn't the open source license they like"

The SSPL is neither free software nor open source. The SSPL license explicitly violates parts of the OSI's definition* and arguably removes one or two of the four freedoms that are core to the FSF's philosophy**. That's why we have a problem with it. Oh, and it's deliberately doing this to be impossible to comply with so that you pay the copyright owner to get out of it, meaning that they're not even doing this for ideological reasons. The other license they used, the RSAL, is even farther from open.

* The OSD is quite clear. The SSPL clearly does not qualify because it violates rule 9 and, to a lesser extent, rule 6. The text explains how with sufficient clarity that I don't have to go into more details.

** I will go into more details about the four freedoms of the FSF's definition, though. They are not as clearly defined, but the way they have been applied makes it clear that the SSPL removes freedom number zero, the freedom to run the software as you want to. Normal free software licenses impose terms on those who make derivative works from them, whether those are slight modifications or massive additions, but they don't do that on anyone who installs it. The SSPL does. Depending on exactly what you want to do with it, those terms may not be important, but unlike actual free software licenses, they're still there. The nondiscrimination element that is so explicit in the OSD may not appear to be there, but it is often included in freedom number zero, itself considered so obvious a requirement that the FSF didn't think it needed to be listed for a while. Of course, we could argue about how much this matters, I think it does, and you might not, but what's more clear is whether the organizations concerned think so. They do, which is why neither of them support the SSPL.

Altman's eyeball-scanning biometric blockchain orbs officially come to America

doublelayer Silver badge

Re: Proof-of-personhood

In almost all cases, the users' desire for anonymity is more important than other users' desire to know who everyone is or the frequent desire of companies to be able to sell that data. There are very few exceptions. Nothing you listed is among them.