The Register Home Page

* Posts by tip pc

1747 publicly visible posts • joined 7 Mar 2018

Capita is about to sail past deadline to fix civil service pensions scheme

tip pc Silver badge

Time the Home Office insourced these systems

its constant doom and gloom with outsourcers blamed for everything.

its time the government in sourced some of these things.

set up a government of IT department & gather the best minds from the industry to do these IT projects in house.

Costs will go down & liability will remain within government where it actually exists instead of trying to palm it off on 3rd parties who get rewarded with ever more contracts to fail.

The new Siri makes one of Apple's most convenient OS features a cumbersome mess

tip pc Silver badge

as bad as the competitors AI is, Apples was worst.

the corporates beleive we all want more AI so are pushing hard to incorporate AI everywhere regardless if consumers want it or not.

Veteran network architect proposes IPv8 – to improve IPv4, not leapfrog v6

tip pc Silver badge
WTF?

I'm guessing you are relaying all this 3rd hand and have never deliberately set up nat or managed networks.

After billions of hours of wasted sysadmin time setting up NAT and all the partial workarounds for the brokeness, billions of people are now using NAT and just accept for example how they have to use someone else's server and not theirs (NAT makes hosting a website difficult and CGNAT makes it impossible).

nat just translates IP's from 1 to another, its incredibly simple.

stateful firewalls use similar techniques to nat, if you have a stateful firewall then you've got all the ingredients for nat.

clients behind nat don't typically have to do anything to connect to the internet. Yes hosting a server is not straight forwards but the number of people who want to do that is a tiny percentage, those that do want to host servers can with a reverse proxy just like all the major commercial websites use reverse proxies even with IPv6.

no home user is spending any time setting up nat or fixing things because of nat,

billions of hours are not wasted by sysadmins setting up nat, if they are running nat in their corporations then that is a choice their corporation made & what they are employed to do.

you can use a cloudflare tunnel to ensure that your server behind a cgnat connection is reachable from the public internet, its not difficult.

NAT often breaks long running connections with or without pointless keepalive trafic, as NAT implementations tend to have aggressive timeouts and will close a connection because wireguard hasn't sent a packet in a few hours, or even if wireguard has been sending packets for many hours (some NAT implementations seem to decide that the connection is too long running and close it).

firewalls break long running connections. an early firewall exploit was to exhaust connection tables by flooding firewalls with useless traffic. the fix was to employ session timers. modern firewalls use aggressive timers when their session tables reach thresholds.

OS's also have session timers and will also age out sessions that have been running longer than their default time out, again to prevent session exhaustion.

My point was that even if ICMPv4 works, there is no guarantee that TCP will also work.

with firewalls there is no guarantee that ipv6 will work either even if ping works, ipv6 port 443 might work for you and not for me because the firewall is filtering.

firewalls break the end to end connectivity many deem is the IPv6 USP.

tip pc Silver badge

When configuring and managing networks, IPv6 is far easier to handle than IPv4 - you don't need to worry about nasty hacks like CIDR, NAT etc and the resulting breakages - you just slap in the /8, the /48 and the /64's etc.

you clearly have no idea what CIDR is

Testing IPv6 connectivity is as trivial as trying `ping 2600::`, which happens to be less typing than `ping 1.1.1.1`.

that just pings 2600:0000:0000:0000:0000:0000:0000:0000, its a host in T-Mobile/Sprint systems.

you could just ping 8.8.8.8 which achieves a similar thing.

If IPv6 ping works, it is extremely like that IPv6 is working correctly, while IPv4 ping working doesn't necessarily mean that anything else is working, due to all the possible breakages of NAT.If IPv6 ping works, it is extremely like that IPv6 is working correctly, while IPv4 ping working doesn't necessarily mean that anything else is working, due to all the possible breakages of NAT.

you have no idea how NAT works, billions of people use NAT every day with no issues, can you provide an example of NAT breaking ping & explain how it broke ping.

On-call techie decided job was done and hit the bottle – just before his pager went off

tip pc Silver badge

Re: Words that strike terror in the heart of anyone oncall

I was open to doing so right until this comment: "But we don't want you to waste time repeated our troubleshooting. We will tell you where to start".

I’d have seen the $$$$$$ signs and asked to add some sign off clauses to make sure everyone knew their rules if the game.

I’m sure they could have strung the contract out much longer than they intended.

I guess they doing want you to start from the beginning because they wanted to blame your design but could be mitigated from their insistence on their rules.

SpaceX dusts off Falcon Heavy for first flight in 18 months

tip pc Silver badge

Re: delayed till 28/04 due to weather

It’s an unmanned rocket but I do get your point.

tip pc Silver badge
FAIL

delayed till 28/04 due to weather

delayed till 28/04 ~ 3:17pm UK time due to weather today

IPv6 carried half of internet traffic – for one day, according to Google

tip pc Silver badge

Re: IPv6 introduced new problems, so slow uptake shouldn't be curious or confusing

The only reason IPv4 still exists on the global Internet is that ISPs decided to CGNAT your NAT instead of using the much simpler v4 to v6 address translation that's in the standard.

what use is 4 to 6 when there was nothing customers needed on 6? This wasn't done this year, CGNAT has been a thing for decades and served a purpose to connect ipv4 users to ipv4 servers.

\

I have no idea why they went that way, as CGNAT is way more complicated and has a lot of unwanted sideeffects.

CGNAT is not complicated, works for billions of people everyday. also allows ipv4 clients to reach ipv4 websites. would be stupid to use cgnat to reach ipv6 sites using 4 to 6 when you could dual stack.

But then, I'm still seeing customers insisting on static IPv4 addresses and cursing that they need to manually set a number in everything. They still refuse to DHCP because "they need to know the IP". Yet they absolutely don't, it just causes them pain.

yes the ratner principle, its the customers who are wrong, why would the possibly want to run their stuff in their predictable way?

an example is that its useful for your critical infrastructure to have manual IP's so they are reachable when DNS is offline.

Microsoft announces product it doesn't want anyone to buy

tip pc Silver badge
FAIL

Re: Hahaha

The previous company used the Google suite of office & collaboration stuff.

I was astounded that I could do video calls from my web browser.

Worked amazingly well & naturally my email and office apps where in browser to.

Around the time they outsourced us they moved to teams which we all felt was a massive downgrade but they plotted on regardless.

Current company is teams, office360 and outlook.

I have to restart office apps once a week due to app patches, teams is a steaming pile of cack & outlook is a pain seemingly designed to make things harder to do.

Why does teams move my office file to one drive when I send a copy to a colleague? I saved it in my specific folder so I knew where to find it!!!!

If I didn’t have to use ms stuff I wouldn’t.

Apple update looks like Czech mate for locked-out iPhone user

tip pc Silver badge

Re: Cloud storage

Until it becomes very noticeable when $cloudprovider fucks up or changes their T&Cs or goes bust or....

yes but in the interim this guy woudl have access to his data,

All of your data are belong to us.

its 2026, i'd assume anything captured electronically is already known about by the relevant authorities, it'd be naive to assume they don't have access to it if you have access to it especially if you have remote access to it or even some of it.

if you have the free icloud tier then your photos captured today are uploaded to the cloud & iphoto on your mac can download it & back it up for you without needing TB's of icloud storage available.

once its been in the cloud its safe to assume some entity has a backup that you can't access!

Apple's chips are the core of a new landscape, but its biggest win is Windows

tip pc Silver badge

Re: Nope

Fortunately, I like retro computing. On the other hand, I've also become fond of interactive JIT compiled programming languages and data visualization environments and those also require more than 8GB RAM.

that's like buying a fiat 500 & expecting a Ferrari F80 experience, yes they both have 4 wheels/steering wheel/windows/engine but they obviously have different capabilities. the fiat 500 won't be competitive in a road race with cars of the caliber of a Ferrari F80

tip pc Silver badge
Big Brother

like the hardware, hate the direction of OS X

Every year of Apple Silicon, the experience of using a Mac has gotten better. Every year of Windows 11, the experience of using a PC has gotten worse.

OS X looks to be following the privacy eroding path of windows & linux/unix looks to be dragged along that way too.

Mac hardware is very good quality, I just want to run my OS without authoritarian oversight. I have nothing to hide, I just want some privacy & security for my work & documents.

unless OS 27 is exceptionally good and rewinds age checking etc, I will be sticking with 26.3 for the foreseeable.

Brilliant backups that kept data alive for ages landed web developer in big trouble

tip pc Silver badge

the site was only reachable via IP because the DNS name was pointing at the IP of the new site.

General public would never have seen the old site if they used the dns name.

normally pointing dns name to new site would be sufficient & keeping old site about would enable quick fall back if needed.

Not the guys fault the customer IT hard coded an IP into their internal DNS & the guy responsible for approving changes only checked at home.

US struck Iran with copies of its own drones

tip pc Silver badge

Re: Proof this was long planned

The national security advisor, Marco Rubio, explained why they launched preemptive strikes against Iran.

Looks like the dog was wagged.

https://x.com/RapidResponse47/status/2028576202420535469?s=20

Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover

tip pc Silver badge

Re: It's Cisco

You know. The company that sells stuff you can't update without a current certification.

Because you NEED your certification to login to even look for updates and/patches.

i got my certification 20 years ago & never renewed it.

been many jobs since i linked my now expired certification to my work Cisco login.

i have no issues logging in & downloading firmware for equipment we run here.

i think it grumbles if i download software for things we don't run but nit needed to do that for a very long time.

tip pc Silver badge

Re: Completely new and unexplored vector

Cisco are not the only vendor selling sdwan stuff.

Why encrypt over mpls vpn’s? You might as well just do sdwan that isn’t Cisco branded over internet.

If security is that important then mpls vpn should be enough & ensure your apps use ssl/tls or some other certificate based encrypted communications.

You can buy xcryptors and their competitors to secure private links too.

UK data watchdog fines Reddit £14.47M for letting kids slip past the gate

tip pc Silver badge

Re: Age gating is fundamentally incompatible with privacy

Once they’ve done with the popular socials they’ll come for your favourite hangouts.

Won’t be long till it’s here on el reg.

Break free of Ring's servers, earn a five-figure bounty

tip pc Silver badge

Re: I assume that Ring has been asked ...

My Eufy cameras store to a hub on my network

my earlier eufy cameras can store to iCloud but i have diverted them to my eufy hub.

Icloud will do face & motion detection & will alert you to known/unknown persons with actions like turn on a wifi connected light etc.

i had some samsung cameras that stored locally & also swann cameras that stored to a local hdd that had a web portal again locally stored.

You don't have to look to hard to find cameras thats tore locally.

Every day in every way, passwords are getting worse and worse

tip pc Silver badge

Re: Email Login

i think google has an option to logout of all sessions, the miscreant would then have to login again

tip pc Silver badge

Re: I keep all my PWs in a text file called passwords.txt on the desktop

great idea, i will be doing that later

tip pc Silver badge

teh M$ mfa puts a code to the requestor to enter in the MFA on their chosen device.

They won't know the code if they've not made the request & can see the code on their screen.

yes, if the miscreant has access to both the requesting system and& the MFA device then they could defeat the MFA but if they've got all that & got past the password protections to open those devices then surely all bets are off anyway.

i keep getting emails from facebook re someone trying to set up an account using my email address. i keep getting the MFA number to enter into the facebook page to create the account.

Obviously i'm ignoring those MFA requests & have no desire to create a facebook account, i already have 1 on a different email address i don't use (facebook not the email address).

Without entering that code they can't create an account.

tip pc Silver badge
WTF?

i use the same passkey across my personal devices & work devices, its not limited to a single device

They can't be stolen or duplicated, and are strictly a per-device system. That's something that can be explained to anyone, although probably with different words, and the advantages made clear. Use passkeys, and you won't need passwords and you'll be safer.

i use apple passwords to share my passkeys & passwords across my personal (mbp/ipad/iphone) & work (mbp/iphone) devices & they work fine for getting me in to my personal logins on sites across all those systems,

is something going on in the background to create new passkeys per device that i don't know about?

only took a few seconds to share to my work profile & is seamless.

i don't think its being duplicated, works with touchID on those systems that only have that & face ID on my iphone/ipad.

China-linked snoops have been exploiting Dell 0-day since mid-2024, using 'ghost NICs' to avoid detection

tip pc Silver badge

Who hard coded the credential. Dell or Tomcat?

the article states a hard coded credential in Tomcat but doesn't detail if that is a Tomcat thing or Dell thing

I assume a Dell thing else the cve would be for Tomcat version using that hard coded credential.

I'm no coder but even if i where. how could i check for other solutions that might have hard coded credentials in their configs?

I assume the credential was obfuscated somehow & not just sat in a config file in plain text.

with software consuming gigabytes of space, how can anyone be sure whats included & if its actually safe?

I'd say its time for governments & large entities to roll their own code

Capita taps Microsoft Copilot to dig it out from UK pensions backlog

tip pc Silver badge
Headmaster

amazing how like minds find each other

2 peas in a pod etc

Keir Starmer declares 'months' timeline for social media age clampdown in UK

tip pc Silver badge
Holmes

https is effectively a vpn especially when coupled with esni

when MP's and media talk about vpn's they really mean people obfuscating their internet communications from the ISP.

A VPN is a Virtual Private Network & denotes making a secure connection to a remote network so your machine acts like its virtually at the remote end & connecting to the private systems at the remote end.

But the VPN's being spoken about are really proxies as there is nothing at the remote end the user is connecting to, they are using the connection to prevent someone local to them eavesdropping on their private connectivity to the public internet.

I accept that there are some miscreants that will be connecting to private systems to connect to bad stuff but that's not what is being spoken about here, its people accessing resources in the free open internet & deciding they want to use a VPN to prevent their ISP & possibly government from snooping on them.

We've had it drummed into us for years to check the padlock & ensure sites are secure etc. that padlock means that the information on that page is encrypted between you and the end point.

We should all know that thanks to SNI, a single IP can host an unlimited number of web sites. It was still possible for the ISP to know the site you visit by inspecting your dns queries & the sni contained in the site request headers.

Now with DNS Over Https & encrypted SNI its no longer possible for an ISP to determine what site you are looking at, they will just see the IP of the remote site which as mentioned could host an unlimited number of Sites.

Given a vpn can use any port it wants to, there is nothing to stop an ssl vpn using port 443 to convey the traffic and someone scanning the traffic would just see encrypted garbage to say cloudflare. You could be looking at cars or pictures of pine trees or streaming the latest trailer for Star Wars or watching your no brand camera system,

from the network viewpoint it all looks like legitimate encrypted https traffic but the end website would remain unknown.

So how can they stop that connectivity without mandating some kind of client side detection?

is that it?

we will all be mandated to add some kind of government mandated client side scanning app?

This is all very dystopian.

Starmer proimised to tread lightly on our lives but appears top be doing the opposite.

https://youtu.be/xavKVYcYJx8?t=49

If Microsoft made a car... what would it be?

tip pc Silver badge

volvo 340 GLE

Mine would decide to break down every 70 or so miles for no reason, you could crank it till the battery went flat & it wouldn't start, leave it 40 minutes and on its last gasp with an exhausted & flat battery it'll spring into life and waft you on its way like there was no issue.

Heated seats, heated windscreen & headlight washer jets.

sunroof

rear wheel drive

looked like an old gits car which is just what I needed in my 1st year at uni. certainly got me noticed by the girls, much to their amusement.

yes I truly hated that car.

& yes it did crash on me, steering was vague, back end could & would step out & braking was like being on a ferry starboard, then port then starboard then port & repeat

Luckily no blue screen of death but it did roll on me.

I was astounded when the recovery guy jumped in turned the key & it started 1st time.

I hated that car!!

Apple's Creator Studio creates a subscription where free apps used to live

tip pc Silver badge

Unsavoury updates

When they start adding unsavoury items into what should be big fixes & feature bumps, it stands as a warning against upgrading in general.

My stuff is good as it is thanks.

Not upgrading until I absolutely must.

Were telcos tipped off to *that* ancient Telnet bug? Cyber pros say the signs stack up

tip pc Silver badge

Nothing wrong with telnet client, it’s telnet d (server) that is of concern.

tip pc Silver badge

Re: How the ancient Telnet bug worked

The bug was introduced in 2015, most things from then would support ssh, most older things won’t contain the bug!

tip pc Silver badge

Re: Define use.

On ipv4, for telnet to be exploitable from the internet someone would have to port forward from the public ip to the internal ip of the system listening to telnet.

Did you do that?

In IPv6 it’d be directly routable from the internet but hopefully your firewall would drop unsolicited inbound connections, have you done that?

Windows dropped telnet from being installed by default in windows 7 in 2010 & also server 2008 R2.

It’s not unusual to have things in the lab that are initially less secure than in production, especially whilst being built.

There is also secure telnet that uses ssl to secure the connectivity

https://www.ibm.com/docs/en/i/7.4.0?topic=ssl-configuration-details-securing-telnet

I’m glad the people I work with are grown up about things & not instantly dismissive.

The UK government isn't spending much taxpayer cash on X

tip pc Silver badge

So they should not be using windows either

Supermarket sorry after facial recognition alert flags right criminal, wrong customer

tip pc Silver badge

Boycott stores that use this rubbish

Rajah had to submit a copy of his passport and head shot to Facewatch so the company could verify he was not on the offenders' database.

the stores wil lont listen to the public but will listen to shareholders who won't like reduced turnover

New hire fixed a problem so fast, their boss left to become a yoga instructor

tip pc Silver badge
Holmes

Re: Many moons ago now

I got tired of coming up with last-minute desperate solutions to impossible problems created by other fscking people.

google ai says

I understand your frustration. Dealing with the stress of constantly solving crises caused by others is exhausting, and it is completely normal to feel this way when carrying that mental and emotional burden.

When these feelings arise, it might be helpful to:

Set boundaries: Clearly communicate your limits to others to manage expectations and avoid taking on more than you can handle [1].

Prioritize self-care: Engage in activities that help you relax and recharge, even if it's just for a few minutes a day.

Seek support: Talk about your feelings with a trusted friend, family member, or mental health professional. You don't have to manage this all by yourself.

If you find this feeling is persistent and significantly impacting your well-being, reaching out for professional guidance can provide additional coping strategies and support. The National Alliance on Mental Illness (NAMI) offers resources and information, and the Substance Abuse and Mental Health Services Administration (SAMHSA) National Helpline is a free, confidential resource available 24/7.

movie is under siege said by Tommy

https://youtu.be/3Zad8u7Tzi0?si=QTIs5XRL7DKlZcY_&t=80

Notepad++ update service hijacked in targeted state-linked attack

tip pc Silver badge

I simply have zero confidence in the developers.

whats your views on Microsoft & their software including windows OS and Office productivity apps that are known to have issues & vulnerabilities that are constantly exposed?

the notepad++ issue appears to be targeted at certain territories redirecting downloads to a malicious rebuild. That means most people got the correct intended version whilst some got the compromised version.

Unless your in those territories or targeted then its likely versions you & your organisation downloaded where all ok.

How do you guard against other software that could be compromised that know one knows has been compromised?

tip pc Silver badge
Coat

yet another good reason to not update if your version predates the attack

updates are good for new features or bug fixes but if it ain't broke, why update?

if you have a version that predates the problem then why update?

The new update protections do seem worthwhile but then you will get them when you eventually update.

defo worth updating if your current version is within that compromised timespan, prob not worth installing an older version as you have to be extremely sure your getting a none compromised version & the older installer won't tell you.

i had a look at the notepad++ download site and there where adverts looking like the download button that where not the legitimate download further down the page.

The download page should not have any adverts on it to avoid confusion etc.

Capita pension portal 'fiasco' forces Cabinet Office into damage control

tip pc Silver badge

profit from chaos

Capita knew full well what they where getting into.

Sometimes forming a narrative of problems is useful when negotiating extra unforeseen costs / profits down the line.

to lay people it looks like this will be a loss for capita.

Reality is that this will increase their profits.

typically the contract would come with constraints on costs & effort etc, capita can now prove that the constraints where to prohibitive & the contract could not be fulfilled as originally specified and what they & everyone else based their bid on.

So they have a valid reason to increase costs to meet the demand

tip pc Silver badge

Re: Article Understates the Issues

is there some online calculator that could be used to approximate what you would get?

i appreciate its wishful thinking but might get you a ball park

a quick google shows these 2

https://www.civilservicepensionscheme.org.uk/memberhub/knowledge-centre/tools-and-calcs/pension-calculators/

https://www.cfcs.org.uk/help-advice/money/apps-and-support/pension-calculator/

Three is the magic number for Alaska Airlines: triple redundancy

tip pc Silver badge

Re: Failure mode

data at home, encrypted backup in the cloud

ATM flashes a port or two for the enterprising hacker

tip pc Silver badge
Holmes

Hostile environment

The connectivity medium should always be considered hostile when the machine is connecting from an uncontrolled environment.

It would be cost prohibitive to put enough controls in place around the router/cpe/‘physical connection to isp’ so is cheaper & more effective to build it into the atm machine so it can reliably & securely connect via an unsecured network.

Sniff as much as you want it should be safe.

If not the atm owner should find out soon enough & learn about a new hacking method which is likely cheaper discovery than the amount of cash in the machine.

Won’t be as secure once government ban vpn’s though but I suspect there will be many exemptions for things like this forming encrypted tunnels to authorised end points.

Will get tricky when those end points are in the cloud on IP’s shared with other services but that will likely be an edge case because who would build a von to a domain name instead of fixed IP’s (probably a norm nowadays to use fqdn’s instead of IP’s your business owns for p2p vpn’s but I’m old school)

ICE knocks on ad tech’s data door to see what it knows about you

tip pc Silver badge

Re: America, you need to fix your problem

Yep

We need new parties that are not the same traditional parties.

We see negativity in the traditional parties & they are not addressing it

Microsoft admits Outlook might freeze when saving files to OneDrive

tip pc Silver badge
FAIL

makes you wonder why sane people update their systems

i remember when i was much younger i'd always install the latest updates.

when fixing someones PC the 1st thing i'd do is updates.

i've been a mac user since ~91, ive taken the same approach on those too, until recently.

i will be keeping my systems on osx/ios26 & may roll back my laptop to osx 15.

app updates i will make a judgement on, OS updates i will take the service updates but i likely will not be upgrading to osx/iso 27 unless i truly need to.

if i could roll my ios stuff back to ios 18 i would.

There are no new features in iso26 i actually want.

If i'm not having an issue with my apps why do i need to update?

re app vulnerabilities, my personal machines are protected by apples xprotect etc plus the apple firewall, plus home firewall, plus nat so most addressed exploits likely can never be remotely exploited.

unless i'm facing a usability issues or bugs then i likely have no need for the app updates.

Its not like updates fix all bugs or won't introduce new ones as per this article so why would any sane person update unless there is some significant reason to?

NASA's Artemis II Moon rocket arrives at the launch pad

tip pc Silver badge
Coat

fly by

anyone know why its a fly by instead of orbiting?

is it a safety thing where the orbit will return it to earth orbit in case of an issue?

if its that risky why put a manned crew onboard? its 2026, we could put some crash test dummies onboard if need be & run the thing on remote control?

AWS flips switch on Euro cloud as customers fret about digital sovereignty

tip pc Silver badge
Big Brother

took their time seeing it for what it is

European tech leaders are concerned about US laws having jurisdiction over European operations of US companies. For example, under the CLOUD Act, US authorities can compel access to information held by American cloud providers irrespective of where in the world that data is housed.

they weren't that bothered when it started

comprehension of the world is changing and now at pace.

UK backtracks on digital ID requirement for right to work

tip pc Silver badge
Big Brother

Starmer today in parliament said digital ID will be mandatory for working

https://youtu.be/mOK_tNoQEeU?t=76

Mr. Speaker, I'm determined to make it harder for people to work illegally in this country. And that's why there will be checks. They will be digital and they will be mandatory.

I'm sure some will make claims that that is not what he meant, but how do you do those checks without checking everyone? will only those with a certain hue be checked?

Will they import a bunch of ICE agents to do the non mandatory checks?

Starmer looked well lout of his depth today, he needs to go, I'm not sure the others in his camp are up to the job though.

Same statement applies to all the other politicians too.

I'm sure there are some outstanding MP's who do amazing things for their communities, weird how they never make it into cabinet or being PM though.

would be interesting to hear what none UK readers think of that video from the start,

at 1st I thought Starmers quip about the karma sutra was AI, especially in light if this stuff about banning x for images etc, seemed a completely unnecessary thing to put into a joke especially in parliament that was being televised live during the day & that young people have a chance of watching as a guardian may have it on.

tip pc Silver badge

they are just delaying it

UK backtracks on digital ID requirement for right to work

we all knew it'd run into issues & be late anyway.

Government are trying to regain some approval ratings by going slightly softer, it'll still be mandatory for many

We got this far without it, we will survive without it.

I can virtually guarantee that even if a party that says they will scrap it comes into power, it'll still be introduced.

As of jan 2026 the ruling parties in UK/USA/EUc have all done numerous things they promised they wouldn't do when campaigning for office, not little things but major things.

a reminder of Starmers victory speech where he promises to tread more lightly on our lives (6 min mark)

https://youtu.be/CeBF1SHstEY?t=236

Firefox 147 brings GPU boost, tidier tabs, and video that follows you around

tip pc Silver badge

1 button option to turn off AI

There should be a 1 button option to turn off AI.

I just use FF to connect to management pages via a proxy. it can't connect to the Internet via that proxy but somehow knows when a new version is available.

Cloudflare CEO threatens to make the Winter Olympics a political football after Italy slugs it with a fine

tip pc Silver badge

Re: Confused (again)

Define shared hosting system.

AWS is home to a number of successful online streamers

Have you heard of Netflix

https://aws.amazon.com/solutions/case-studies/netflix-case-study/

Or peacock

https://aws.amazon.com/solutions/case-studies/peacock-case-study/

Being generous I’d say you’ve misunderstood how websites & connectivity works.

Some google searches can surface some additional detail on how it all works

And yes a single ip can host an unlimited number of sites and each of those sites can also stream content over that single ip,

tip pc Silver badge

Re: "an IP can host an unlimited number of FQDN's."

I appreciate not every reading the reg is technical, a bit of googling goes a long way to understanding

As a primer have a read of this.

https://en.wikipedia.org/wiki/Server_Name_Indication

Server Name Indication (SNI) is an extension to the Transport Layer Security (TLS) computer networking protocol by which a client indicates which hostname it is attempting to connect to at the start of the handshaking process.[1] The extension allows a server to present one of multiple possible certificates on the same IP address and TCP port number and hence allows multiple secure (HTTPS) websites (or any other service over TLS) to be served by the same IP address without requiring all those sites to use the same certificate. It is the conceptual equivalent to HTTP/1.1 name-based virtual hosting, but for HTTPS. This also allows a proxy to forward client traffic to the right server during a TLS handshake. The desired hostname is not encrypted in the original SNI extension, so an eavesdropper can see which site is being requested. The SNI extension was specified in 2003 in RFC 3546

tip pc Silver badge

Re: Cloudflare hypocrisy

Shared IPs? Residential customers may be behind CG-NAT. People serving pirated contents, and making money from IT, don't use shared IPs. They use some hosting that provide them the resources to access and deliver copyright contents with the speed required to serve enough users to make money. These are not botnets used fos DDoS, or someone sharing torrents.

an IP can host an unlimited number of FQDN's.

the shared IP's is in relation to the fact that a hosting provider can host a number of different domains behind a single public IP.

If the regulator approves the requests, it uses an automated system to inform ISPs and other players that they must block access to certain IP addresses and not provide DNS services to domains suspected of facilitating piracy.

miscreant sets themselves up at a hosting provider that then uses a single public IP for hundreds of domains. Suddenly cloudflare drop resolving the IP & all those other sites can't be reached.

sounds like they are being mandated to do it globally too so those outside of Italy lose access too. Stops Italians using a vpn to bypass the block.

a better way would be to drop resolving for the individual domain from clients originating in Italy rather than everything on an IP globally, won't stop VPN usage to sidestep the block.

Humongous 52-inch Dell monitor will make you feel like king of the internet with four screens in one

tip pc Silver badge

why can't i do virtual displays currently?

i have my mac hooked up to a 42" tv (appropriate 4:4:4)

i wish i could compartmentalise it into 4 virtual screens so each 1/4 can have what i want in it.

i know i can organise different windows from different apps into quarters of the screen but when i change to an app OSx has this annoying habit of hiding other windows when i don't want it to.

& no 'spaces' is not what i want, neither is stage manager