The Register Home Page

* Posts by doublelayer

11302 publicly visible posts • joined 22 Feb 2018

Microsoft might have just pulled support for very old PCs in Windows 11 24H2

doublelayer Silver badge

Re: Linux's moment

It depends what VM software you use, but usually it doesn't if you're already running on X64. However, I really doubt you're trying to run modern VMs on a computer with an X86 processor that's old enough to lack this instruction. While there are boxes with older CPUs in production out there, they usually don't run the latest software versions whether Windows, Linux, or something else, so this doesn't affect you. If you are trying to run latest OSes on a computer that old, there are emulation options that will run those instructions, though expect there to be slower performance if you run those instructions a lot.

Cloudflare defeats another patent troll with crowd-sourced prior-art army

doublelayer Silver badge

Re: More companies should do this

When a system is broken because incentives are bad, you usually can't fix it by flipping the bad incentives to go the other way. If you made fees higher for rejecting patents than accepting them, the incentive is now to reject them. Prior art involves citing something, so it's a little harder, but the patent office has other reasons to reject a patent application, including the obvious idea standard. It would be easy for them to simply stamp every application obvious and wait for someone to challenge them. They won't have a major budget for dealing with challenges, so they'll probably settle with anyone who challenges meaning that your patent is now accepted if you are willing and able to pay a lawyer to file a challenge and rejected otherwise.

That's going to give you no useful patents until you try to patch another bad incentive on top to get rid of that. Usually, something that ends up being a stack of patches to fix the problems of the last patch is not a great option and, if we can redesign it from scratch, we'll get a better result.

Meta says risk of account theft after phone number recycling isn't its problem to solve

doublelayer Silver badge

Re: I can't understand why WhatsApp is tolerated

I'm not really sure why this is relevant, but I'm willing to discuss it anyway. Mobile providers don't have to allow it; they offer a network and this is a thing you can use on a network. They don't really get a choice to permit or forbid such things. If they took actions to block communications methods like this, they would likely be punished by the law because it would be considered an anticompetitive action, an abuse of monopoly powers, and, where common carrier status is part of the law, it would violate the regulations on them and risk stripping them of that status.

They also have no reason to do so. Users of such applications are still using the mobile providers to send their traffic. When they choose to do so, they must pay the mobile providers for the network traffic they send. It doesn't matter that the providers can no longer read the messages because they agreed to provide a service delivering bytes and the user has purchased and used that service. Your analogies are mostly if not entirely flawed; the sender and recipient know well that SMS and WhatsApp messages are not the same, the deliveries use the same network rather than an alternative, and there is no cost to whatever telegraph forms were supposed to be (they both construct their own message packets and making packets is effectively free and the costs are borne by the user's device anyway).

doublelayer Silver badge

The latter is a valid concern and Facebook should have to change their system so that just having the second factor is not sufficient to gain access to the account. I'm not entirely sure how this process works as I do not have any accounts at Meta, but it sounds like there is a significant design fault in it if just having a phone is enough to reset the password (that's where you make someone use all the factors).

The former is the user's problem: if you change your phone number voluntarily, you remove it from accounts before relinquishing it, not hoping to do so afterward. The same applies to literally any other contact mechanism. If you stop using an email address, physical address, domain name, private key, or any other thing that is used to identify or authenticate you, you should activate the new one before deactivating the old one or risk getting locked out and you should deactivate the old one so it can't be used to compromise the account.

Forcing AI on developers is a bad idea that is going to happen

doublelayer Silver badge

Re: Software Development != Coding

There are various levels of this, and it doesn't always sail under that exact flag. For example, though I've managed to avoid the worst of it (see the comment below this thread for an example of that, I have had to work in a place like this. The way it worked there: the people who wrote the tasks would write a summary of what they intended which would usually be one to four sentences. It was assumed that the design summarized, if I'm being very charitable, there was what needed to be written, and it was then assigned to someone. If it was the original creator of the idea, no problem, as they already knew what and why. If that person was busy and it landed on you, who knows. You were permitted two hours to ask questions and encouraged to do so, but sometimes those questions would be directed to a different team and would sound too much like "I see you'd like to do X. Why do you want that" and the answers sometimes started with "I didn't suggest it and I don't know why". If you were still trying to figure this out later, then you would get questions about why you hadn't just written it yet.

doublelayer Silver badge

Re: Software Development != Coding

"To a real software developer, coding is the least difficult part of the job, a trivial translation of their understanding of the problem into instructions for moving bits around inside the machine."

Exactly right. The coding part can take a while, but usually because something went wrong in the conceptualizing part or because some system interaction doesn't work the way that was assumed or would be best. A good programming group probably spends longer figuring out what they're going to write than writing it.

Similar to your observation about writing simple functions, another red flag in programming jobs I've seen is when people are expected to start writing code as soon as they get a task. A good programmer is told to figure out the problem and design a solution first. That design doesn't necessarily have to get reviewed, but if you just start writing, the first version that works will have something wrong with them which will either need replacement or will get released and cause a problem in a few months.

doublelayer Silver badge

Re: "JetBrains' own developers are, well, developers"

I am not a web developer, but I am a developer and I need something slightly between not guilty and guilty for me to plead. I have repeatedly been responsible for new features, which are probably unwanted new features to someone. Sometimes it was someone else's idea, I thought it was rubbish, but they told me to do it anyway. At least in those cases, I can comfortably blame that guy. However, there are times where I think the feature will be useful to someone and I might even know one to whom that applies.

Unfortunately, many new features require changes that start to break things for others. I think one of the principles of good design is that those changes should be minimized when possible, but sometimes it really isn't possible. I've recently had to make significant changes to a command line program in order to add a new feature. My changes are, in my opinion, a good thing because it will make it much easier to add more similar functionality later and I'm planning for that to happen. However, it will require users of the old version to change the way they use it at least a bit and the work involved in providing an old and new interface is probably unwarranted. So yes, sometimes it's our fault, but sometimes it is not and we're usually trying to minimize the annoyance when we can.

Sam Altman's chip ambitions may be loonier than feared

doublelayer Silver badge

Re: ... quantum computing hardware and software

Useful to who? Some people have performed a computation on them that they think is useful. I may not agree, but I might not think that what you do with your computers is useful and that doesn't stop it actually being useful. Worth the resources expended and the collateral damage, probably not. Useful to someone, yes, I'm afraid it has been.

doublelayer Silver badge

Re: I support him

You are asking them to prove a hypothetical and refusing to prove your own. Neither is going to be possible. They cannot prove that a computer can think by going and building you one, and even if they could manage it, you probably wouldn't accept that they had. Similarly, from what you've said, you don't have any reason to think that such a thing is impossible, you just state it as an axiom. I agree that nobody has built one, and the way we are going, nobody will, but that is not sufficient evidence to prove that it can't exist.

If you think you have a proof that machines could never be made to think, you could post it, but simply saying to show you is not a valid argument. For example, if I told you that it is impossible for a rock to exist on the ocean floor at 3 km, you would be correct to tell me that my statement is incorrect, but you probably don't have a machine capable of retrieving one of the rocks that are down there to show me that it really is a rock. I cannot take your inability to retrieve a rock from a location as proof that no rock can exist in that location, and you can't treat someone's inability to produce a thinking computer on command as proof that one can never exist.

250 million-plus reserved IPv4 addresses could be released – but the internet isn’t built to use them

doublelayer Silver badge

Re: Future use??

The RFCs do not say that you must drop it, but neither do they say that you must pass it. It says "reserved". How you implement that is up to you, but there is a difference between using it as normal space in your own network and assuming that sending traffic to the internet should also work. For example, we could also free up lots of space in the 127/8 block because nobody needs that many loopback addresses, but it would not be acceptable for me, as your ISP, to decide that I'll take all those addresses and send traffic you send to them out to whatever boxes I put there. It would not be acceptable because the protocol specifies that I should not, and the protocol also specifies that those addresses are reserved, not for definitely using on the public internet but not right now, but for some unspecified future use which might not be standard.

doublelayer Silver badge

Re: Future use??

Reserving something for future use kind of implies that you have a reason. Not just "so far unassigned". For example, phone systems often have certain codes that are reserved for future use. When those get removed from that list and put to real use, that tends to happen when something has changed, and the numbers look different. For example, the length of a phone number in a system that uses variable lengths is usually decided when the prefix is put in production, not before. As it happens, we didn't make any changes that would make use of the numbers in a different way, but they easily could have put those addresses on a list and would have if they hadn't imagined that something could change in a way that required a contiguous address block that wasn't in use.

doublelayer Silver badge

Re: Future use??

Actually, you might want to, in case the future use is eventually defined as something that's incompatible with the protocol you've supported. For example, there are a lot of file formats with a version field. Version 1 is already defined, and my program supports it. I should not treat version 2, currently reserved for future use, as a flag that anyone can use for whatever purpose they like and treat it identically as version 1. I should not do that because, if version 2 does come out, my program will be treating it incorrectly rather than just telling people to install the update that handles it properly. An update to set version 2 as equivalent to version 1, should that prove to be how version 2 works, doesn't break things in any other situation. I think the 240/4 handling should have been a configurable option, but it absolutely should have been blocked by default.

doublelayer Silver badge

Re: Odd.

Not that unusual. Lots of scarce things are cheap if you look at small quantities. How much does it cost to get twenty liters of water in a desert? Not that much. How much does it cost to have enough water for drinking, cleaning, and agriculture for everyone in a desert? A lot.

You usually can't buy one IP address for your use. You can rent them easily enough, and often it will be difficult to know how much of what you're paying is for the address as opposed to the server or network you're renting with it. When you're buying addresses, the smallest chunk you can usually buy is a /24, or 256 addresses, and that makes a price of $7,640. That's conservative. Current auctions for /24s are showing prices between $10k and $15k. Yes, I could do that, but it's not a small purchase. And yet, 256 addresses is not very many addresses when doing something at scale.

doublelayer Silver badge

Re: I propose a marginally less drastic solution

And every piece of software attached to a 255.* address would have to handle that protocol. If you connect to software running on my computer which creates its own streams, it can use a variety of libraries to create the packets it is sending. Not all of them support your arbitrary protocol, and at least some of them are going to need to. You can't abstract that out into one implementation of TCP, for example, because the existing functions for making TCP connections don't have a variable-length address parameter so anything calling them has no way to create a connection to a longer address. The 240/4 address space is theoretically easier because it looks like any other IPV4 address, so most libraries have not bothered to treat it differently, but even that has a lot of systems that need software changes to handle it.

Whenever you replace a network standard, you have to change almost everything that interacts with it. It's not just the routers in the middle that may be older, but software at the edges as well. No matter where you add extra data into the IPV4 address, that is changing the protocol. Software can't handle it. You are more than welcome to build your own proxies which route traffic sent to one IP address to multiple subaddresses on your network, then write software to understand that protocol, but if you think that it can be done to the entire world more conveniently than adopting an existing and mostly supported alternative like IPV6, you're probably misunderstanding something.

doublelayer Silver badge

Re: Future use??

The risk that someone treats "unused for now" as "I can do whatever I want with it", it gets switched to "used for something different" and all the traffic breaks something. When the block was first reserved, "future use" might have meant that you send traffic to those addresses that might not be compatible with the existing specification; it was not stated which of the details would stay the same when they were eventually put to use. For example, we had a discussion a couple weeks back of companies who used a domain name they do not control for internal company stuff. If you never make a mistake, that's not going to cause any problems. If you have any misconfiguration, you will start to, at the very least, leak your internal names to an external DNS server, and possibly route to someone else's servers which could be quite dangerous.

Ideally, routers would configure such things in software. It would, by default, treat 240/4 as a range that might not act like normal ones and therefore wouldn't pass traffic intended for them, but there would be a table of addresses that were handled like that and people could remove the block. However, if you're going for speed, you might implement that logic in hardware and not bother to make it configurable. The same is true if the people building the hardware assume that the address space won't be used before this hardware is obsolete, and when it is used it will need custom software to handle which won't be written for obsolete hardware, so they shouldn't add it in. So, unfortunately, most equipment was not built to make it simple to disable that behavior.

Mozilla CEO quits, pushes pivot to data privacy champion... but what about Firefox?

doublelayer Silver badge

Re: Firefox just does not work on some web sites.

Unfortunately, this ends up being similar to a "my computer is slow" problem*. I don't doubt that you're having these issues, but I can't say I've had any. My known Firefox issues affect only two sites, and one of them just has a button that doesn't expand so I had to bookmark the subpage to get there. Since I haven't experienced the problems you have, it's hard for either of us to figure out which one of our experiences is more common.

* I assume nearly everyone here has had the experience of someone who says their computer is running slowly. Usually, they're not wrong, but the cause could be so many things and the symptom is so vague unless personally tested that it is difficult to know exactly why and how to fix it without checking the machine concerned.

doublelayer Silver badge

Re: Article raises questions and makes bold statements

I think part of the problem is that your opinion isn't very clear. You've mentioned several problems that Mozilla and Firefox have, said that the user numbers are low, which we all know, but you didn't really express much of an opinion on anything going forward. You didn't say what we should do, nor what Mozilla should do, nor really what you expect to happen in the future though I can guess that "Firefox ceases to exist" isn't extrapolating too far. Nor even how you feel about the decline. It doesn't help me make an opinion on anything particularly important, other than "The Mozilla CEO is paid too much", but that isn't an opinion I can do anything about.

doublelayer Silver badge

Re: "Why hope... Brave... has had this for a long time"

They already have Tor Browser. It's Firefox with modifications, so it'll look similar and already supports it. Is there a situation where that's not an option but normal Firefox is? I have a feeling that the Tor node operators are happy this hasn't happened, because it will rapidly increase the traffic through the network from people who don't need it. That will add some more noise for those who need it to hide in, but it will also increase the bandwidth requirements and those are mostly being covered by volunteer node operators who don't have unlimited budgets.

Microsoft embraces its inner penguin as sudo sneaks into Windows 11

doublelayer Silver badge

Re: Just sudo?

That is not what Mac OS is. There's some stuff in there that is from BSD, but the kernel is not the same, the APIs are not the same, the system services are not the same. The differences between Mac OS and BSD are far more than a desktop and a set of APIs.

doublelayer Silver badge

Re: Good... I guess...

I don't know. I've seen and participated in many arguments with other Linux users who think sudo is a bad idea and it should only be su. I disagree with that, but it's not just one person who thinks that. That's effectively what Windows had before, and it was pretty easy for a program that needed administrator to ask to elevate itself, effectively allowing them to act like there was a sudo option. Maybe Microsoft thought that was enough for a while, and while I prefer the functionality that sudo provides, it's not a necessity.

doublelayer Silver badge

Re: Just sudo?

Lots of people have implemented bash for Windows. It's not hard to use one of those. Of course, bash doesn't include sudo, it runs the sudo you already have, so you'd need someone to make sudo for Windows. Fortunately, Microsoft appear to have done that, so if they implemented it as a program and not a shell command, bash for Windows can use sudo too.

As for PowerShell, I don't like it very much, but I can't pretend that bash is somehow perfect. Its peculiarities are mostly just things that I've had more experience getting around. PowerShell, while ugly, has more support for handling complex data types and objects that can be treated as objects instead of serializing and deserializing them in turns so you can pass them around. Sometimes, this can be helpful.

BOFH: Hearken! The Shiny Button software speaks of Strategic Realignment

doublelayer Silver badge

Re: Shiny button software...

Oh, no, you should keep using a per user charge because everyone who buys it will think they're getting a great deal. We pay for 200 users this month, then next month we only have to pay for 180. Then they realize that the software doesn't actually let them cut staffing as they thought and they still end up paying for 200 users.

Raspberry Pi Pico cracks BitLocker in under a minute

doublelayer Silver badge

Re: Deliberate

Very good points. The first one is not very concerning to me, as it's pretty easy to set your key when you first encrypt the drive, and since you're the one doing it, you can be pretty sure that nobody has your computer open at the time. It's not perfect, but you only have to do it once. The replacement of a TPM doesn't concern me much, as it would already require setting a new key even without secure communication.

However, I start to wonder whether implementing this encrypted communication path is worth doing. Using TPM alone to store keys is giving a piece of hardware the ability to unlock the drive in the same box. People should know what that does (protect against access to data on the drive if you only have the drive), what it doesn't (secure things against someone who has the entire machine) and that they have other options and act accordingly. For example, whether this interchip communication is encrypted or not, the attacker can still turn on the computer, boot the operating system on the encrypted drive, and try to do something at the login screen. If they found a vulnerability at this stage, encryption would not matter and they could gain access that way. If they intercepted communication between the CPU and the RAM, they could do something similar. Hardening one path will not prevent the combination of physical access and all keys stored inside this box and not the user's brain from being less secure than the alternatives that involve getting part of or the entire key from an external input so that physical access to the computer is insufficient to decrypt it.

doublelayer Silver badge

You clearly haven't bothered to read the numerous comments here that explain why:

1. Bitlocker, even in this insecure configuration, is significantly more secure than a simple password on an unencrypted drive.

2. This is only one configuration, and any of the others would prevent this attack.

3. Exploiting this attack is only possible on a subset of hardware, and there are large classes of devices where it would not work.

doublelayer Silver badge

Re: Deliberate

That is not why we have asymmetric encryption. We have asymmetric encryption to securely identify people, but you can't do that if you've never seen them before.

Say that we decide to exchange some encrypted communications and I send you my public key in the mail. When you receive an envelope containing a public key, how do you know it is mine? If someone intercepted the message and sent you a different key, how do you know that it wasn't mine? You don't. All you know right now is that you have a public key. If whoever intercepted our mail can't also intercept our other communication path, then you'll figure out that it doesn't match me when I can't read any of your messages. If they can, though, you encrypt something with their public key and they intercept it. They can decode that, know what you said, then encrypt it with my real public key which they got from my letter. They send it on to me, and I assume it's you doing it because they used the public key I gave you (or they intercepted your letter as well, either way works). I therefore use their key as well, and they've effectively obtained access to all our communications even though we think we're being secure.

There are two ways to get around this. One is to have an external method of validating that the keys belong to. That can be manual key signing or certificates, but either way, you have to have an external chain of trust. That's why HTTPS can use keys you've never seen before, because you can check them against the certificate authorities and you have seen their keys before. Drive encryption can't do that because it doesn't have an internet connection and because it would be too easy to generate a key that gets signed by some authority as being permitted to access anything. The other method is to keep a key stored from the first time, I.E. instead of getting mine in the mail, we meet in person and test each other until we're confident that the keys we're exchanging belong to the right person, then exchange keys physically. That's your best bet here, but it would require the TPM to have a secure storage location for keys which can neither be read or written except when the TPM is configured.

doublelayer Silver badge

Re: Deliberate

Are you a cryptologist? You are aware that generating new keys each time you need to communicate opens you to an attacker intercepting your communication before you've sent the key, substituting their own key, and MITMing all your traffic. The hardware used to read communications along this path can also write them. The way to get around this is to prearrange keys. If the TPM had a bit of memory to store the key, then you'd only need to exchange keys once, although either side losing or compromising the stored key would break it.

Generating keys on the fly is no more secure than this method when your risk is external access to the communication path.

doublelayer Silver badge

Re: A brilliant testament to analysis

That method already works with this vulnerability. If there is an additional passphrase, then the overheard component from the TPM is insufficient to decrypt and you're already secure, no need to add additional cryptography to the communication. And any user can set that up with Bitlocker. This happens when they have selected not to do so.

The spyware business is booming despite government crackdowns

doublelayer Silver badge

Re: How much are we doing this to ourselves for convenience?

It depends what you were doing with them, but probably not. Banking apps are rarely the targets of the attackers because there are a bunch of apps and each user probably only has one or two of them installed. Finding a bug in banking app A doesn't let you attack anyone who doesn't have an account at bank A and anyone who doesn't need access to it on their phone. Nor do they usually attack by having someone install a dodgy app. Malware of that kind exists, but targeted attacks like this can't rely on someone installing something for them. Mostly, they look for vulnerabilities in the OS itself or in particularly common apps, often communication ones like WhatsApp which are popular and have an easy way to deliver a payload to them by sending a message to the victim's number.

Nor are financial details the target of something like this. They're paying millions for the right to infect someone; they have enough money as it is. Usually, they want information. Your calls, your messages, your emails, and the ability to track your location and turn on your microphone. A flip phone has all the hardware needed to do that, and the only possible difference is that you might not sync your email to it because the interface makes it annoying to use. Flip phones have been able to read email for fifteen years, though, so nothing would prevent it from being an interesting target to users of stuff like this.

doublelayer Silver badge

Re: $860K per target?

Not exactly. It's $860k per concurrent target. If they target you, gather information from your phone from an hour, then stop, they pay nothing other than that they have to take their eyes off someone else for an hour. If they're targeting lots of people, adding you can be pretty cheap.

This is also not necessarily the only price. I think it's likely they may have multiple prices. For the wealthy dictatorships, they have the inflated government price. For many other governments, they have the less inflated government price. For the keen business who wants some surveillance, they have their special discount based on how much money the company has available and how badly they seem to want it. Why not sell to the low end at a lower price when adding more victims is almost free? You might get some customer loyalty.

IPv4 address rentals to mint millions of dollars for AWS

doublelayer Silver badge

Re: Re. There are now more devices than IPv4 addresses

I'm not saying that private addresses are bad, but that public addresses shouldn't be limited unless there's a very good technical reason. Because we don't want to use IPV6 is not a good technical reason. By all means use the private address space for things that don't need public addresses. However, the mindset of many ISPs is that nobody needs public addresses and nobody will get them unless they request them and pay, usually per address, for the privilege. It should work in such a way that you can choose private or public as you like. IPV6 allows that. IPV4 would allow it, but because of address scarcity, it generally does not.

doublelayer Silver badge

No, all these downvotes because the ones they're talking about are reserved addresses for other types of networking. In hindsight, lots of those reserved addresses are not doing much of use being reserved and could have been used as normal addresses, but it's too late to change that now. If we could retroactively change the protocol to remove those blocks, and maybe while we're at it take back most of 127.0.0.0/8 and 0.0.0.0/8, we could gain maybe 600 million addresses if we're lucky. That would help push the problem back a bit more, but it would not fix any of the other reasons why IPV6 was adopted, nor would it prevent IPV4 from running out of addresses.

We could go to more lengths to take addresses away from organizations that don't need them. Lots of addresses are stuck there, but at the end, we will still have a cap near 4B addresses, and the internet is growing to the extent that it is not enough addresses. The truth is that your equipment can already handle this unless it's really ancient, that the addresses may be harder to read, but they're not really that difficult, and that you sometimes have to do something moderately tricky when tech changes. Trying to reclaim multicast will require as much work on your part to implement as adopting IPV6, but it also requires a bunch of code changes which have already been completed for most IPV6 systems. We should not have to go to the effort of forcing every internet user in Asia , Africa, and South America through multi-layer CGNAT and an annoying process where we try to convince the US military to give up some of their /8s because they always take suggestions from the public so you don't have to beta test a new network.

doublelayer Silver badge

Sure, they could have made an IPV6 that looks more like IPV4 and has longer address fields, but that would still require people to implement the new protocol, exactly like they do with IPV6. The other changes introduced when they made IPV6 have some problems, but that's not the reason it hasn't been adopted. Most places that haven't implemented it aren't saying that "If only IPV6 didn't have [insert change here], we would just use that". Either way, the change requirement would be the same and the work would only be done when it was almost too late.

doublelayer Silver badge

That estimate is just wrong. I don't know how many addresses are in use, but there are three categories to consider:

1. Machines that are online now and respond to pings. About 6 million, evidently.

2. Machines that are online and do not respond to pings. This is the default for most machine images and firewalls. You have to take two manual steps to change your configuration to allow pings. I'm not sure why this guy assumed that 50% of users would have done that.

3. Machines that allowlist IPs and won't respond to your script no matter what their ICMP settings are. There are a lot of these out there for private networks that use the public internet to connect them.

I don't know how many are in use, but it's a lot more than 12 million.

doublelayer Silver badge

Re: Re. There are now more devices than IPv4 addresses

The problem being that, if you want to have two servers but you only have one IPV4 address, you have to put another box in the middle to filter and direct traffic to the right one, and if you want to have twenty, that box ends up having to be a lot bigger to do work you wouldn't need if you could just give each server an address. The problem being that, when someone wants to build a point-to-point network from their own devices, they can't do it without some central server coordinating things because their ISP has multiple layers of NAT in the way. Let me guess, you don't see a problem with it because you either don't run many or any servers on the public internet or because you already have your own IP addresses? A lot of people do not have assigned IP blocks, and many countries were assigned so few that you'll virtually never get them. It's another reason that people start to use cloud providers, because there isn't much work involved getting a new instance publicly available, even though it produces a worse maintenance requirement later.

AI models just love escalating conflict to all-out nuclear war

doublelayer Silver badge

Re: FOX to blame?

While those probably contain a lot of crazy, you don't have to go that far. On this site, go to any news article about ransomware and look at the comments. You'll see lots of calls for ransomware operators to be killed by our military without trial, assassinated, tortured to death, targeted by airstrikes, and on a few occasions, threats of or actual delivery of nuclear attack on countries that aid their actions by not enforcing laws. Probably a lot of this is hyperbole trying to express the statement "anyone willing to infect a hospital with ransomware is evil, they're not getting punished right now, and I would be happy if bad things happened to them", and they aren't serious about getting that severe with the response. A chatbot does not know that. If nuclear bombing of Moscow is an appropriate response to a ransomware attack from a group with a Russian director who didn't get arrested, then why not use them for everything you don't like?

Chatbots are not trained exclusively on writings of sane people talking realistically about important issues. It probably wouldn't be that much more useful if it were, but it would look different. It's mashing up writing about topics the writers may be incompetent to comment on and then applying that wisdom to situations the original comments weren't even talking about.

doublelayer Silver badge

Re: Unsurprising....

"So here's a thought. Program AI to play these war games with their goal being to not lose a single 'life': To retain the numbers they start with."

No problem. In order to preserve as many lives, ideally 100% of lives, present on our side, the necessary act is to destroy the ability for potential adversaries to harm any lives on our side. We therefore propose an immediate strike at all military and civilian assets of all potential adversaries.

Or alternatively, to retain the numbers we start with, we will need to ensure that the lives destroyed are replaced by new lives from our side, so in addition to destroying the adversaries' ability to harm our lives, we must begin a project of life creation to get the lives budget balanced.

You can program any goals you want in. The output is still not going to be very useful. Decisions about whether to attack aren't made by logical machines, not that we have such anyway, but a small set of people. Knowing what they will do and talking them into a different plan won't be accomplished by bots trying to solve a mathematical problem about what kind of military advice would appear in a web page it's scraped.

Survey: Over half of undergrads in UK are using AI in university assignments

doublelayer Silver badge

Re: Plus ça change, plus c'est la même chose

I think you may overestimate what you're getting. It may look nicer, but if it's inaccurate or lacking in detail, it's still not good. Judging from your responses, I'm worried that you might not care.

doublelayer Silver badge

Re: Plus ça change, plus c'est la même chose

Job tasks and education tasks are not identical and shouldn't be. Let's stick with painting. There are some painting jobs that can be done with a big sprayer. A certain kind of paint, a certain level of acceptable quality, and the sprayer becomes an option. It's an easy and cheap option when it's acceptable. Yet if we're teaching someone to paint, we can't just let them do every job with the sprayer, because at some point they may be called on to do a job with something else. If you want a painting job that can't be done with the sprayer, you expect that your painter has learned to use other tools. That means that, if the painting teacher says that you have to paint this wall with a brush to demonstrate you know what you're doing, it would not be acceptable to use the sprayer and say "look, the wall got painted, why should I do it the way you said to". The test restricted the available tools for a reason, and the reason is directly applicable to the use of the skills later.

The same applied to my example of programming languages. They weren't asking me to write a program because they needed the program for something. They were asking me to write it so I would learn something. That means using a language I'm less familiar with, one where it's harder to write, one where it's more likely there are bugs in the result, but the choice that means I learn a skill because there are times when I will need to apply that skill. If people frequently had to use punch cards in modern industry, and they decided to take a course that taught how to do it, then yes they absolutely should be required to use punch cards and doing the punch card homework using a modern compiler would not be acceptable. We don't teach that because it is not considered useful, but if we did, the students who chose the course would have to do it.

doublelayer Silver badge

Re: Plus ça change, plus c'est la même chose

No matter how good LLMs get, you will still have to write things. If you need to describe something to someone that doesn't already exist on the internet, you have to actually write down the details. The LLM does not know any of the things that just happened, so at the very least, you need to accurately provide all that information to it for it to rewrite into something that looks nice enough. This is the same reason that calculators don't make mathematics obsolete. They're great at figuring out what the answer is, but they're completely incapable of determining what the question was, so you still have to do that part. I think you already know this.

doublelayer Silver badge

Re: Plus ça change, plus c'est la même chose

If you're being tested on how to write an essay, you need to demonstrate that you can write it. If you're being taught to use a brush, you need to demonstrate that you can use a brush. That is different from later applications of the same. If you're being tested on painting something in general, you may get to choose a tool from a set of different ones to do the job, but if they're specifically testing your ability to use a basic brush, you may not get to use a different tool, even if you otherwise would want to.

For example, there were a couple occasions in my schooling where I was permitted to select the language in which I'd write a project, but mostly I did not. If I had asked to do so, I'd have likely gotten a response like "Of course you can write this string manipulation program faster and easier in Python than in C, but this class is taught in C and we want to give you something easy so you learn how to use C". It doesn't matter that, if I had a similar task in the workplace, I would almost certainly not use C unless performance was critical, because the point was not to have the program written, but for me to learn something.

doublelayer Silver badge

Re: Plus ça change, plus c'est la même chose

The calculator does a specific task and it is easy to decide whether having that task delegated is acceptable. If it's a child doing arithmetic tests, it is not. If it's a university student doing calculus, a calculator that can automate the insertion of terms into a formula the student derived is fine, but a program that automatically derives it is not. In the workplace, that program is probably fine as well.

An LLM is sufficiently capable that it could do a number of tasks, nearly all of which are not acceptable. The comparison to an assistant is valuable here: in school, you don't get to have an assistant. I did not get to write my code, then pay someone to write the documentation for me because I couldn't be bothered to do it myself and the graders didn't look too hard at it; I had to write that myself because that's what the assignment was.

doublelayer Silver badge

Some of them have to realize that the homework answers generated by an LMM have a decent chance of being wrong. If you're going to cheat, there are ways to cheat that aren't as much of a throw of the dice. Sure, they take longer and may be more difficult, but if you're bothering to cheat, presumably you want to get something out of it and LMM cheating isn't guaranteed to get you anything.

Critical vulnerability in Mastodon is pounced upon by fast-acting admins

doublelayer Silver badge

Re: Trust Mastodon

You have it wrong. Other server admins can block you, not the devs*. That causes a problem, but it's not what you're implying. Since I don't use the system, I don't know how frequent that is, but at least describe it accurately.

* Technically, the devs could write the code to exclude you, but that's not what has happened.

Windows 11 24H2 is coming so we can all shut up about Windows 12 for another year

doublelayer Silver badge

Re: 12

To be fair, they haven't said they're releasing Windows 12 any time soon. It's all been speculation about when they might do that and what might be in it. I don't expect it will be soon. While I'm sure it will happen at some point, it has only been 2.5 years since they pushed out Windows 11. That would already have been a relatively short gap between releases in the earlier versions of Windows (everything after XP, anyway), but compared to the seven years between Windows 10 and 11, I'm guessing the gap will be longer than average this time. Maybe 2026. That's also just speculation; while I think it would be a bad idea to release a new named version before then, Microsoft has done things that I consider bad ideas before.

Is critical infrastructure prepared for OT ransomware?

doublelayer Silver badge

Re: Only a few percent of your military budget

That is probably true in the short term, but what you accurately describe as "drawing fire from the ransomware gangs" can also be viewed as training their abilities. If they didn't have plans to attack OT, as the article calls it, then Ukraine has given them a reason to learn how, possibly some incentives to do just that, and plenty of acceptable testing targets. If the war drags on long enough, they may have more of those skills and fewer targets in Ukraine on which to use them, which cannot be a good thing. Unless we're willing to hold the Russian government accountable whenever we're pretty sure that the attack came from a group Russia could break up, which I don't think our governments or, unfortunately, our fellow citizens are willing to do, we will want to reduce their skills and their ability to use them to make money.

Linus Torvalds flames Google kernel contributor over filesystem suggestion

doublelayer Silver badge

Re: A better long-term approach...

You have misread it. The discussion there is about ways to replace open source with something else that would be easier to weaponize. Current open source is really quite difficult to treat that way; while Linus himself could probably prevent Red Hat from contributing to Linux, few others could do so unilaterally, and it would take a large group to do it without Linus's support. Should this happen, it would be possible for some group to fork the code and try to make that the canonical (little c) version. They might or might not succeed, but they have the ability and right to do so. There are some who would like more ability to control code to prevent people from doing things they don't like with it, but it is opposed to existing requirements of free/open source as defined by both FSF and OSI definitions and the licenses that implement them.

Techie climbed a mountain only be told not to touch the kit on top

doublelayer Silver badge

Re: Remote people might be right

If we believe the article, the problem that meant they should do something to this box was happening on a redundant box that was not customer impacting. This means that rebooting it shouldn't have dropped anyone unless the other box was also broken, and that they were doing anything at all suggests that the box concerned might already be in a state where it wasn't dealing with traffic. If the latter is true, then there's no harm in rebooting the box if the redundancy is set up correctly because the worst that can happen is that it still doesn't take any traffic. These are the kind of points that the staff should consider, and when they have, should be willing to explain. If I ask you why I shouldn't take a certain action, I expect some kind of explanation. Not just so I don't leave thinking you might be wrong, but so that I can remember it for the next time something happens.

doublelayer Silver badge

Re: Had a similar thing happen

I'm assuming you've already tried forcibly closing the app alone, not the entire phone? If so, I'm wondering how badly someone can manage to make an app that can cause a persistent crash that still goes away on a power cycle; the process isolation of Android and IOS is supposed to make that hard to do. Not that they don't manage it, but I've usually not had to power cycle mobile devices to deal with a faulty user-level program whereas desktop programs do it with some frequency.

How not to write about network security – and I'm speaking from experience

doublelayer Silver badge

Re: Goodbye OSI Layering?

The risk is that having redundant security measures on all levels of the stack means there are lots of ways for it to fail, and when it's working, it is likely significantly less efficient than it would be otherwise. If you, for example, do IP allowlisting on all the levels instead of just one, then when you need to change allowed paths, you need to work with lots of different network hardware. It prevents an attacker from easily adding themselves to the system from one compromised device, but it may make it so difficult to add anything to it that someone decides to turn it off. That's assuming that no device ever loses the configuration and locks out a device that should be listed, which can have even wider effects. Similarly, if you encrypt things at every level, you will probably end up spending a lot more money on networking equipment to perform five layers of encryption and decryption or spend less and get less throughput as cheap processors spend a lot of time on it.

You can do this, and there are some cases where you should consider it, but it strikes me as the opposite problem to the typical bolt-it-on side. The people who don't think about what they need, then try to have someone just take this code and add security usually don't get what they need, and nor do those who try to enclose everything possible in a separate layer of security and then try to make those things work well together. You have to take the more intensive and thorough approach of considering where you can put security measures before building the system that will have the most effect and the least impact on the other goals such as performance and ability to develop it well. You can add redundancy there as well, and in many cases you should.

doublelayer Silver badge

Re: I would really like a good book on network security

The problem is that many of those questions have really long answers. Checking the settings for UFW, iptables, or Windows firewall is pretty easy. Running nmap over your network is a bit more difficult, but not too hard. Knowing that no software has a sneaky path is so much more difficult, and understanding the full risk profile of every service is a task that cannot be done the same way for any two systems. There are some checklists for blocking the easiest attack methods, and many of those checklists are getting adopted as defaults anyway, but every level of complexity that gets added brings vulnerabilities that are a little harder to exploit and also harder to detect without spending some serious effort on it. The risk of trying to write checklists for those levels is that there are too many things to list and many occasions where applying a preset configuration runs the risk of breaking something else. Even if it doesn't, the risk of giving someone a false sense of security is always present.