The Register Home Page

* Posts by doublelayer

11402 publicly visible posts • joined 22 Feb 2018

Think tank to UK government: You can't build the future on systems from the past

doublelayer Silver badge

It can be both. But since you asked, let's consider the software part. Why do you think the software is happily running? From what do you get your confidence that the processes haven't changed, especially with government processes that change whenever a new law patches something else, and it has to produce reports to comply with a new regulation and two related court orders that happened fifteen years after the software was first written, and there are new security requirements for government systems which came from real attacks, and there's a potential law being considered by Parliament which, if they pass it, will require core logic to be changed again but the components aren't well-known to most programmers, including those who decided to learn the language, because they were discontinued by their original writers (now deceased) in 2008 (2001 to be honest, but they technically extended support for a bit)? If you decide, on no evidence, that all old software is totally fine, then there is no need to update anything. Unfortunately, your decision would be wrong and the actions you take as a result will be unfounded.

BOFH: Vibe-coded solutions arrive for problems nobody has

doublelayer Silver badge

Re: Ahh

I don't have much sympathy either for you or the boss. It is annoying when people take an example as the only important part, but generally it means that the example was a bad example, which the boss's definitely was and yours might have been, at least your new boss thought so. The solution to that is to either provide another example or a set of them which make the point more clearly or to describe the purpose in general terms which explain the need for it. I'm sure you could have listed many more things you might have to buy which would have justified a budget, whether or not tissues were important. Perhaps you tried, and I'd have more sympathy with you if, after providing more examples, your boss continued to focus only on tissues.

In the case from the article, the boss had a chance to provide any example he pleased about how his app would be useful. He failed. He then got an opportunity to defend his example. He failed. He then got an opportunity to provide more examples. He failed. In my opinion, this doesn't count as hyperfocusing on the first example.

America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames

doublelayer Silver badge

Re: The last job

Another possibility is that someone was asked for the credentials, provided them somehow, and the recipient is the one who posted them to a repo to store them. Even that wouldn't be the most relieving because anyone with too many credentials to store should have a more organized method for doing so securely. Unfortunately, credential management is a thing where many organizations don't have great answers and looking at what they do just shows you a horror which will be very painful to clean up.

Frustrated franchisee sues Pizza Hut over crappy kitchen AI

doublelayer Silver badge

It appears to have happened in 1997, so I'm not sure you can blame management with other restaurants alone for the problems happening now.

The big AI companies are going to see their margins disappear

doublelayer Silver badge

Re: What margins?

I think this is specifically talking about the per-token billing. The companies have realized that they are too stupid to figure out how much something costs and tell people up front, so they've been pushing more people into a "you do whatever you want and we bill you whatever we want" approach. I don't know whether they are making more per token than running the inference costs, but it's likely that they wouldn't make the same mistake twice. That's far from saying they'll be profitable that way as they have very high fixed costs as well, but at least they won't lose more money with each paying customer. If this is true, that's one area where they have a calculable margin.

Google reimburses Register sources who were victims of API fraud

doublelayer Silver badge

Re: smart man Fonseka

As I said already, the limit wasn't that clear which makes fraud charges difficult. It looked enough like a limit that I think devs had plenty of reasons to think it was one. However, it didn't work the way you're describing it. It wasn't set by the user, and in fact it wasn't settable by a user. There's no contract that said it was a limit, and if you intend to prove fraud, you'd need one. I think you have a chance of convincing a jury that Google intended it to look like a limit to mislead people, but since they never promised it would be one, that's a civil, not a criminal claim.

doublelayer Silver badge

A good provider would have a way to control policy when a spending cap was hit, for example continuing to allow ongoing charges for these services while cutting off the other ones. For some strange reason, the only way to actually get anything like that is by building it yourself using cost APIs which, depending on the provider, might really work or might be so time-delayed that you can't get the data in time. Their argument would have a point in that a lot of systems are built such that if you cut off spending at a limit, then all the user's stuff would break instantly and bringing it up would b painful, but that point would be more convincing if there was a way or a user to work around it with forethought.

doublelayer Silver badge

Re: smart man Fonseka

No, it's not fraud, or at least not fraud by Google. The case is a little more complicated than that. The services the users didn't authorize were run using their keys which were stolen, either because Google changed things in a way they shouldn't have or just because they were leaked. Either way, Google can put the blame for that either on the people who used the auth tokens they didn't pay for or the people who should have protected or limited them. I think Google has a good chance of winning on that one, even though this is mostly their fault by changing what a Maps token could do in a dangerous direction, because it's difficult to explain to a jury that yes, the tokens could have been limited and that would have prevented this problem, no, you didn't do that, but it's still Google's fault (it is, but only if you understand why Maps authentication in client-facing JS was required, why that's different from everything else, and what Google did with those tokens).

The place where Google could more easily be charged is with the cost limit thing, but since the limit never worked as a limit, it's not as simple as it would be if they intentionally disabled it. I think Google would probably lose on that, but it would be civil complaints about misleading claims in product marketing rather than something simpler with criminal prosecution helping out.

The class of 2026 has heard enough about AI, thanks

doublelayer Silver badge

Re: My Lord, my Lord, the proles are revolting!

I think it's Google, Amazon, Facebook, Apple. People have tried to make an acronym out of big tech companies, but it runs into the problem that you don't always want to complain about the same subset every time and the letters don't line up very well. For a while, FAANG was the most common, except Netflix didn't really work with complaints about tech when they were more often related to complaints about entertainment and some people didn't have many complaints about that anyway. If you add some other large tech companies you might dislike, then you end up playing jumble to find a pronouncible permutation of FmOGaAINAMASOXt* and modifying it when you want to be more specific.

* Facebook (Meta), OpenAI, Google (Alphabet), Amazon, IBM, Nvidia, Apple, Microsoft, Anthropic, Samsung, Oracle, X (Twitter).

Dutch cops’ shame game works wonders as most wanted scammers now turned in

doublelayer Silver badge

Re: This is how it should be

See the comments on that article for a fuller argument against that, but the short version is that, if that's what the problem was, he'd be charged for extorting the police, not computer intrusion. They wanted to charge him with computer intrusion. Even if the situation is exactly as the police stated*, that's the wrong charge.

* The police didn't specify what was requested. Maybe it was a massive amount of cash, in which case an extortion charge would be pretty likely. Maybe it was something as simple as "please stop threatening me with computer intrusion charges to cover up your mistake" which they decided to interpret as extortion rather than someone who didn't feel like submitting to a "we'll charge you with a crime you didn't commit if we feel like it".

doublelayer Silver badge

Re: This is how it should be

Perhaps, and I think a lot of people would be inclined to do that. I would be one of them. The trouble with complaining about those who don't is that police frequently overstep the bounds of rationality and seek to punish innocent people. The existing comments have made comparisons or assumptions about other countries, but let's stay with the Netherlands and use a case from this year. Anyone remember the story covered in this same paper about the Dutch police that decided that the police making a mistake and sending someone a file they shouldn't meant the recipient should be arrested? The more of that happens, and most importantly the more of that people hear about, the less the community will do to help law enforcement. If you think the community should do more, preventing that kind of thing is the most helpful thing to obtaining that goal.

Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess

doublelayer Silver badge

Re: Impossible?

I don't know how idiotic a policy the UK government will be willing to enact. They've already gone past sense, so the question is where, in the spectrum of where it can go, they decide to stop. While it is impossible to prevent all VPNs without banning encryption, imagine a less extreme proposal. Imagine that they don't outlaw encryption, don't put network monitoring in place, and don't try to block services. Instead, they simply ban VPNs that do not age monitor and make it a crime for any user to operate one, disobedience to that law carrying a prison term. No, that would not break business VPNs; business VPNs would have to age monitor. Your personal VPN would have to be registered with age monitoring in place, likely so onerous a process that it would be impractical to operate it legally.

In practice, this wouldn't prevent you. You could operate a VPN safe in the knowledge that they probably won't find you since they're not inspecting network traffic. Would you, knowing that, if the police ever inspected your computers for any reason, you have a guaranteed sentence? Even if you did, as I likely would, would you recommend that to others who wanted to avoid submitting their ID for the privilege of using the internet? Would you assist them in navigating the more difficult environment where a non-tracking VPN can no longer b legally sold? Bans are as effective as the ability and willingness to enforce them, and something being really simple technically doesn't necessarily prevent or even significantly complicate enforcement, especially when that enforcement doesn't have to be total.

doublelayer Silver badge

Re: Impossible?

No, it's not impossible, just like banning encryption isn't impossible. What is impossible is more frequent claims that you can ban encryption and still have security, but banning encryption or VPNs and losing their benefits is something you can try. You could,, for example, require all ISPs to monitor traffic for known VPN handshakes, block them, and pursue people with criminal charges. That would be a bad thing, and it wouldn't prevent all VPN usage because people would find ways to get around it, but it would substantially reduce it. It's always possible to ban something, and it's usually not that hard to ban something with enough enforcement that it does produce a marked decrease in its usage, whether or not it makes any sense to ban it.

1 in 5 Brits think AI layoffs could trigger civil unrest

doublelayer Silver badge

They wanted people to believe the lies

This is an unsurprising outcome, even though I'm convinced it won't happen. The people who run LLM companies have been making all sorts of statements about what their software will soon be able to do, mostly to distract from the fact that it can't do the things they said it was going to be able to do a couple years ago. When they constantly make statements about extreme numbers of lost jobs in short order, it's no surprise that people believe they have some reason for saying it and therefore assume it might actually happen. If as many jobs were lost in a short period as LLM promoters like to claim, unrest is almost certain. The kind of good news is that the LLM companies are lying as with most of their sales claims, so the promised job losses are unlikely to happen as promised.

I think one of the reasons these claims are more easily believed is a disconnect in attitude between the LLM company salesmen and the general public. When many people hear that LLMs are going to cure cancer, I don't think they believe it as much as they believe claims about job losses. I think the reason for that is that everyone can understand that curing cancer would be a good thing and they understand why someone's promising that while not being able to achieve it, whereas they see job losses as a bad thing and assume that nobody would promise a bad thing unless it was going to happen. It takes some weird logic to understand why LLM companies see predictions of economic collapse, AI war, and dystopian misuse as worth making (a combination of "Look how powerful a thing I made, you should buy it" and "If you tell me what to do or not to do, worse things would happen then when you have such a genius controlling the dangerous tech"). LLM companies directed their catastrophizing sales talk at businesses and governments, but the general public heard it too and that's not very helpful to the AI companies.

To gain root access at this company, all an intruder had to do was ask nicely

doublelayer Silver badge

Re: common sense needed

Those were the first places, not the only places. A lot of information like that is reported whether or not you choose to post it. Companies House is useful, especially in groups like this which include many contractors, but if it happens not to contain your target, there are certainly more places to look. Open source intelligence works very well against a lot of people, so if designing an identity checking system, it's good to make one that isn't trivially bypassed by someone who bothered to do it.

doublelayer Silver badge

Re: First of all

I don't use the phrase in the way you despise, so I'm not an approver. However, if I want to express that and I think "first of all" will be misunderstood, I tend to use "to name one" which has the benefit of being the same number of syllables or, if I want to be clearer, "to name the worst/largest/most important". Perhaps that alternative would be useful? If I want emphasis, I'll stick on a clause suggesting the size of the list: "There are too many problems with that for me to list if I intend to sleep tonight, but to name one..."

doublelayer Silver badge

Re: common sense needed

Fine then, make that everyone who saw a copy of your CV when the system in which a company you applied to got hacked. It isn't that different. That level of information is not something you can count on being private, whether you choose to be that public with it or not, it is far too easy to find. For the same reason, your home address, while you might do your best not to have it listed in public directories, should not be considered secret information because people who want it enough can find it with relative ease.

Dude… where’s my password? Claude reunites forgetful stoner with $400k Bitcoin stash

doublelayer Silver badge

Re: Where has it been in the mean time?

It wasn't anywhere else. He had it but couldn't spend it. For an analogy, consider that you had locked a bunch of cash in a box and could neither find the key nor break through the lock for a decade. It wouldn't earn any more value in that box. That's what was going on, except the box and lock were digital. It was not being held anywhere where it could be lent out, thus there was no interest.

doublelayer Silver badge

Re: Tax

There are a lot of exchanges that will be happy to trade cryptocurrency for real currency for a fee. There's enough of a market that that transaction would be pretty easy. Assuming he's in the United States*, that would be long-term gains of about $399k, which unless he has a lot of other income means a 15% tax rate plus a 3.8% extra on amounts above $200k, so somewhere around $67,500, unless he structured it differently or has a tax accountant who knows more than a glance through a DDG search does. From the little about taxes I know, there are likely ways to pay less, but I somehow doubt that happened for this guy.

* The mentions of US presidents and dollars in his statement suggests this is likely.

Git is unprepared for the AI coding tsunami

doublelayer Silver badge

Re: Git is doing fine.

It's not "just" any of that. I've learned how to rebase, eventually, but it really isn't that simple because people generally only want to rebase when something more complex has occurred. Even in the relatively straightforward example of reordering commits, there's a lot of complexity in handling merge conflicts, and explaining how takes longer than the text file that starts the process.

While it's not what was originally being discussed so I can't fault you for not talking about it, the most common situation where people need to rebase is taking their changes and rebasing them on the latest version of the code so they merge more nicely. This is a thing that I've frequently had to train my more junior colleagues on how to do, usually after they've tried to do it on their own and generated diverging branches which we first have to clean up, and sometimes they've made such a mess that the easier solution is to make a new branch and manually put their code back into it. I am now familiar enough that I don't break my own that way, but when I watch others do it, I can't pretend that rebase is as simple as we can think from more experience.

doublelayer Silver badge

Re: Git is doing fine.

That was not the part I disagreed with. Not only do I agree with you about the desirability of that, but I don't even know which pressing enter episodes the original quote is complaining about; it's simple for me to automate committing, pushing, opening pull requests, for that matter even approving them, so I don't know what they're considering which they think requires too much user interaction. Chances are, if they did specify, I would not want to remove the user interaction part because that's the thing that prevents everything from breaking at the worst time.

doublelayer Silver badge

Re: Live by the sword ...

Your approach with two different upstreams is still centralized, and I still think that's the natural way that people want to use this when they're coordinating nearly all the time. While it's possible for someone to create a web of other devs' machines to push to, I don't think people would do that because it would lead to a lot of problems keeping those pushes in sync, even if we did all have our machines on a public network and always turned on so that structure wouldn't break.

I don't think centralization, in the sense of building something with a server component, is a problem. I think it can be useful to distinguish between that kind of thing and something that intentionally designs without that, as well as between either of those and a platform where there is a central server and it has to be the one operated by the platform.

doublelayer Silver badge

Re: Live by the sword ...

BitTorrent is efficient for the same reason that P2P-Git wouldn't be: the torrent is sending the same data to each peer. That makes a lot of duplication easier, whereas if I'm trying to sync my state, which I have most of, with several others' modifications to the state, all different, is a harder challenge. In a torrent tracker, there is a canonical source giving the only trustworthy information. That works because that source could compute all the chunks and the hashes before anyone started downloading. When they can't do that, that's when you end up with blockchain-style distributed verification, a process which can be attacked and therefore needs more infrastructure to verify it and defend it against attacks.

doublelayer Silver badge

Re: Git is doing fine.

Almost everything there is correct, but I think you have one mistake. Pushing to a local repo is instantaneous unless that repo is large enough, but there are some that are and maintaining state on that can take some time. The important part though isn't pushing your commit to your copy, because even when that requires a lot of work and therefore takes a noticeable time, it's not that high. The cost comes when you're trying to update your copy with a bunch of new things, for example pulling a lot of changes. In particularly large repositories, the time needed to integrate those changes into your tracking, even if your current branch doesn't need to merge any of them, can take a lot longer than retrieving the deltas was in the first place. How much that's a problem will depend on what you do with Git, but there's a reason the people maintaining it think it's worth trying to improve in their own update, and that can also be a reason why others decide to have a try at making an alternative though I expect they'll find it hard to make a system without most of the complexity that Git sees complaints about.

doublelayer Silver badge

Re: Live by the sword ...

I don't think Git is naturally decentralized. Everyone's got a copy of the code, but there's still a single upstream if they're working together, and all the clones and pushes to origin are going to it. It's only decentralized in the sense that you can host that server anywhere, but that's most things. This, whatever we call it, is good, because something truly decentralized with P2P exchange would end up being like blockchains or IPFS: inefficient and fragile.

LocalSend puts your sneakernet out of business

doublelayer Silver badge

Re: What about with no (established) network?

Depending on the system you're running this on, some of them won't have much trouble allowing a program to create that temporary network or WiFi Direct connection for the transfer. The problem comes when trying to make that cross-platform, because IOS won't let you do that and Android makes it quite tricky if there's any restrictions on network rules, most common for devices with some provider-specific hotspot policy. On desktop operating systems, that is more supported, but you run into the opposite problem that, if you have unusual network settings, an app attempting to take more direct control over your WiFi when you might have changed the rules or firewall settings that conflict could break without some careful network configuration, so that's also less likely to be implemented when the program can't know whether they're about to break something. I would prefer that as well, but I understand why it's less common.

doublelayer Silver badge

This sounds nice

I had not heard of this and am now looking forward to trying it. I don't have much problem getting files from one computer to another one either over a network or using sneakernet, but where I think I'll like this is getting files from or to smartphones. While Android is a little nicer than IOS is about getting files on by cable, they both have plenty of files I created which I can't access through their excuses for file systems and need to use the app that created them to export them. This sounds like it will be a little more convenient than uploading individual files over local HTTPS connections.

Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data

doublelayer Silver badge

Probably not. That's the problem with ransoms in general; it's very painful when it's happening to you and it's easy to justify ignoring your principles just this time when you happen to be the victim. The only solution I can see, which I support*, is making paying ransoms illegal and accepting the pain. Unless we can do a lot more to find and punish those conducting the operations, we have no better options.

* Of course, from the same position of not having to do it. While I think there's some value in proactively increasing the cost of something so that it's easier to avoid temptation, I will not pretend it will be easy or perfect.

doublelayer Silver badge

Re: ...but ... but.. they have "shred logs"

I can certainly imagine what they could be, for example a log of someone listing the files on some disks to show that it was your data, then executing the shred command or something similar to destroy that data. I think that's likely similar to whatever they received. Of course, no log can demonstrate whether that data has been copied to a different disk before you shredded it on that disk, and if you're too lazy to do that, you could write a shred simulator that generates that log without actually doing it. Maybe they did it and maybe they didn't (my money's on didn't), but it's impossible to prove that data was deleted, no matter what evidence they purport to provide.

AWS racks M3 Ultra Macs that boast specs you can’t currently buy

doublelayer Silver badge

Re: In the post-consumer world we will own nothing...

Apple will keep making these things as long as someone is willing to buy them. They're not going to refuse to sell you one unless AWS buys them all first. Right now, when they don't have the parts to make that many, AWS actually can buy them all first, but that only works because AWS is willing and able to throw money at this and Apple is unable or unwilling to increase production. Neither can last forever; if the people buying all the RAM run out of money, the crash ends, and if they find a way not to run out of money, the manufacturers will eventually make more, whether by building another fab (they haven't done this so far because, if I had to guess, they don't think this will last long either) or by allowing new competitors to join the market. Once that happens, AWS will stop buying many of these when people who want them can just buy one themselves.

See through local AI lies with Irish eyes

doublelayer Silver badge

That depends how much that person or business needs to get answers and how quickly they need them since you can run both of these things on any CPU with sufficient RAM (16 GB machines should be able to do that, though slowly, and they weren't that rare in the last five years). But if it comes to buying a new Mac Mini with 24 GB of RAM to allow overhead for the OS which you will really want if you're running this on it, that's a thousand pounds. Both individuals and businesses can afford that if they need it enough. I know how painful it is for anyone who wants RAM or storage this year, and it's not going to get fixed any time soon, but don't exaggerate how unobtainable those really are.

AI will soon be capable of telling convincing lies

doublelayer Silver badge

Re: Repeat after me:

"If it is lying, it is because it was programmed to do so. When it is "hallucinating" it is because it was programmed to do so."

I don't think that's the best way to state that. In neither case was that what the programmers wanted. It's just that the programmers, even though they want perfect correctness and stability, didn't and still don't have a clue how to make that happen, so they decided the hallucinating and forgetful version they could make would have to do. I think that still puts the blame in the right place since they were willing to release and sell the broken version, but saying "programmed to do so" suggests they have the ability to make it lie and have planned to use that for their benefit, whereas I think the truth is that they are incompetent* at making something good and dishonest enough to pretend they have anyway.

* Incompetent is also not necessarily the right word, as the problem is really hard to solve. People have tried, but they can't make it work and likely won't be able to make much progress as long as they have to keep making incremental changes rather than changing foundational parts of the tech. Dishonest is definitely the right word, though.

Google users fight for refunds as unauthorized API usage bills soar

doublelayer Silver badge

Re: Clarification

From what I've seen as a non-victim, both of your assumptions are true but with extra context that makes it less clear who should shoulder the original blame.

The API token issue is because, unlike most API tokens, Google required that ones used to access Maps were distributed in public and the tokens were not specific to Maps but could access a bunch of services unless they were limited. It was still on the users to limit those tokens, and some of them made a mistake, but that's a lot harder to do when you can't specify that tokens in code are forbidden because, if you did, Maps access would break. For example, a lot of people might have a token per application and incorrectly assumed that that token should have the permissions required for that application, without considering that they needed a token to be checked into the code and one to be kept private, to be selected between whenever accessing something. I think both sides could get some blame for this situation.

The billing tiers, if my understanding is correct, seems more Google's fault. Not only do they not have functioning spending limits, but their tier system suggests they do. From what I've read, users who thought they were in tier 1 would have been able to check and still seen that they were in tier 1, even though in practice that translated to "we haven't taken you out of tier 1 yet but will do so automatically and, when we do so, instantaneously". Therefore, right up to the moment when their or someone else's usage catapulted them into a higher tier, they had no way of knowing it. That meant they were seeing misleading information about limits that would never have applied to them, but because they were stated as limits, users had a reason to trust that they would apply. Google can probably make some arguments about keeping your tokens secure even though I'd disagree with the spirit in this case, but I don't think their explanation of tier limits that aren't real is going to convince.

Linux kernel maintainers pitch emergency killswitch after CopyFail and Dirty Frag chaos

doublelayer Silver badge

Re: I lack confidence in this

I didn't say everyone should or will. You don't have good choices. You are going to take a risk somehow, and this lets you choose what risk. It's also not as dire as you describe because, if the worry is that something will break because it used to be able to count on some functions working and now can't, that can be solved by rebooting when enabling the kill switch, meaning everything starts up again with the new behavior from invocation. When something this severe happens, there's no solution which fixes it all until the patch is out.

doublelayer Silver badge

Re: I lack confidence in this

Yes, that might happen. The more an admin knows about whether they're using a certain thing, the more certain they can be about whether that's going to break or not. Some software can also plan for kernel functions ceasing to work and having a fallback or at least crashing more nicely. The decision every admin has to make is how much they want to avoid a possible crash and how much they want to avoid a possible attacker with root access, with this being an option allowing you to decide to take a higher chance of crash and a lower chance of attacker if you so choose.

doublelayer Silver badge

That abuse is already possible, as is most other types, for someone with the required access. If I'm trying to break your system and I have enough access to use this kill switch, I can break it in a lot of more problematic or subtle ways. The risk with this is not that an attacker will abuse this but that someone trying to use it will end up breaking their own system and needing to reverse the setting, perhaps at worst from a non-booting system.

Debian 14 cracks down on unreproducible packages

doublelayer Silver badge

Re: Huh

Essentially, it is. If you put exactly the same bytes through the compilers we're generally using in all the places the compiler looks for bytes, the output is identical. The problem with reproducible builds is that there are a lot of those possible places that people don't always script out. Stuff uses manually-set data, files which the builder is expected to obtain and provide on their own, and all that makes it impossible to reproduce the build unless you know what extra steps the builder took.

For example, I've got an open source project. I publish binaries for it. The Windows one recently updated the Python version it was compiled against while the Mac OS one didn't because I happened to update the version on the VM on which I built the Windows version. I hadn't scripted the "build a Windows package of this" process, so what you get depends on what I did, including possible mistakes or, as in that case, changes which work just fine and people don't notice but don't make it simple for someone else to do exactly what I did without reverse-engineering my actions.

Meta fights Ofcom over how many billions count as billions

doublelayer Silver badge

I don't get where Meta are coming from. I suppose there's an argument that, maybe, laws would be nicer if they were structured that way, but you can't win in court by arguing that this is more in the spirit of something politicians should really have been considering at the time. Unless there's some law that prevents the UK from doing this, there's nothing the court can do about it, whether we agree with Meta or not. In the same way, the UK law could have simply written "10% of local revenue or £12 trillion, whichever is higher" and that would be legal too.

doublelayer Silver badge

Re: If Meta wants to be fined on their UK revenues

Your opinion makes no difference to the point the previous comment was making. You might hear "Meta ban" and be pleased about it, but lawyers will be wondering how it's legal (hint, it isn't) and more of your countrymen use it than don't, and each of them gets just as much vote as you do. Therefore, a ban is likely to fail because it's not legal and simultaneously wreck the careers of people who were willing to do it, so who would likely also be willing to do things against Facebook that would actually work. So maybe it's not as pleasant a prospect as it originally seemed?

'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit

doublelayer Silver badge

Re: Maybe I missed it

This is just an exploit. People wanting to abuse it have to build that into something which can take actions once it's been used. They could either go the "run this script for me please" approach or, if they have some other exploits, they can put them together to build some more powerful malware.

doublelayer Silver badge

And what exactly is keeping you from those days? It's as possible now as it ever was, meaning that it's perfectly easy if that's one of the main things you spend your time on and difficult to impossible for everyone else. It's not difficult because anyone is trying to make it so, but because kernels are big complex things* and include a lot of random stuff that can cause problems.

* Or, alternatively, they're microkernels meaning they're exactly the same amount of random stuff but chopped into little separate pieces which get put together so they work. Or alternatively, they're actually small but don't do much or run on your hardware.

Raspberry Pi wants Windows admins to Connect – or it might pull the plug

doublelayer Silver badge

Re: Question

Mixed environments are pretty common, but it's also possible they're one of the, in my experience, tons of companies which operates Windows desktops and Linux for most other things. I'm not sure how useful this would be for them, but there are plenty of admins who have to work on both systems who might appreciate a cross-platform tool.

doublelayer Silver badge

That's not very relevant as this is intended to run on Windows machines, normal ones, not Raspberry Pis running Windows which, while possible, is still not exactly in Microsoft's or, for that matter, Raspberry Pi's supported operations.

Viva la revolución: LinkedIn profile visitor lists belong to the people, says Noyb

doublelayer Silver badge

Re: What data is my data?

I'll need to see your work on that. Why would that be a stupid argument in court? If they can successfully argue that the visit is the data of the visitor, not the visitee, they are off the hook. LinkedIn, like every other company, is required to provide me my data for free on request, not others', so if they get the visit information classified as others', then they can choose to withhold it unless I pay them. The consent issue doesn't matter to this argument, though theoretically people could take issue with whether it's clear enough for the GDPR's purposes. Either way, that's a different case and a different request.

Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking

doublelayer Silver badge

We'll ignore their operations in Europe, driven by their big London office. The reason you've never heard of them is the same reason nobody else has: commercial real estate is boring and nobody bothers much about it unless they have to. There are a lot of industries where, if I choose a random participant, you're likely not to have heard of them.

Hungarian cops cuff suspected swatter after two-year FBI probe

doublelayer Silver badge

Re: What kind of idiot

The kind of idiot who thinks that the recording will only go to their friends, that their friends will think this makes them cool rather than pathetic, and assumes nobody's going to take this "prank" seriously anyway so they won't be tracked down. Fortunately, they were wrong in their assumptions this time.

Taiwan cops say student's radio kit brought bullet trains to a standstill

doublelayer Silver badge

According to the Bleeping Computer article someone else referred to, the part that was cloned was the identifying information of a radio, allowing the student to masquerade his transmissions as from that unit. The actual message was built from reverse engineering and "a 21-year-old accomplice [who] provided Lin with some critical THSR parameters", so it wasn't a complete replay attack. Still not a good setup if it's that easy to forge messages.

1 in 8 employees totally cool with selling work credentials

doublelayer Silver badge

Re: What?

Finding someone willing to buy your access is left as an exercise for the employee wishing to take risks and commit some crimes. As for what the buyer will do with it, likely they'll try to read email of the employee in order to impersonate the employee in communication to someone with the authority to redirect payments, unless they're lucky to get sold access by such an employee directly. Depending on the security policy of the company, the attacker might be able to do that directly from their machine (especially true for companies that don't have network access policies), might need to authorize a device under a BYOD policy, or might need to buy remote access for a specific machine in addition to the credentials.

Brit mathematician lets AI agent loose with credit card – cue password leaks, CAPTCHA chaos and more

doublelayer Silver badge

One reason it's acceptable is to check whether someone else doing it, since these things can and are often configured to communicate with external people, breaks all the protections you tried to build with prompting, which in this case it did. It's necessary to understand the limitations and, if you insist on building the things, try to defend against them.

Also, whether or not you like it or find it acceptable, that kind of threat is quite common directed at actual humans. Not always in the "do this correctly or you're fired immediately" sense, but quite often in the sense that "if you fail to do this correctly, it won't be good for your career here". Notifying people of negative consequences is very common, so if you object to that and want to start advocating against it, you'll have to start somewhere more important.

doublelayer Silver badge

Re: Cassandra

To properly accuse Odysseus of his many crimes, not all of those were his fault. The seven years was with Calypso, not Circe, and unlike with Circe, he wasn't happy about those as she was keeping him captive. You can't exactly count those years against him when he was being held prisoner by someone with magical powers (he had none) which it took a goddess to get him out of.

Less in his defense, nearly everything that happened in the other three years were his fault, some directly and some by either failing to communicate properly with his crew or by having the stupidest subordinates in the history of navies. Some of those were unclear, because either all of his (remaining) sailors didn't understand the concept of "those things belong to a god, so you shouldn't steal them", or he somehow didn't convey this rather important information.