Test volunteer
Can we have Katy Perry test this one when it's ready, please? She's an experienced Blue Origin astronaut.
232 publicly visible posts • joined 7 Jul 2020
Opened to the public (in order to defray the monstrous debts of construction) only 6 weeks after Ludwig II and his attendant mysteriously fell into a lake and drowned themselves.
First Mickey Mouse appeared 42 years later.
See https://boardgamegeek.com/boardgame/155426/castles-of-mad-king-ludwig for building your very own edifice.
It's going to attract fraudsters like crazy. Whatever diligence Meta do (!) for typosquat sign-ups, the fraternity will push those to establish the parameters and then work on variations to circumvent. After all, they have decades of experience doing the same thing with email From lines, etc. It will end in the usual whackamolery between the devs and the crims. Meta won't want to jeopardise genuine sign-ups. Likewise whatever rate-limiting Meta do, those limits will be tested and then coupled to automated WhatsApp sign-ups. The total influx of effluent could make the medium useless. We can hope.
Hmm. Is this a Meta plot to drive people back to Facebook? Or maybe blue-tick monetisation of Z-list celebs?
The problem's not limited to consumer features and this cruft does not magically turn itself off. Too often you will find that the gear managing a 10k+ estate is being run by a tiny band of very "competent people" who have many other things to do and are expected to manage that estate at minimal cost. See the upstream comment about how many extra hours a year now have to be spent combatting these unwanted features. That is a rising cost that your organisation has to meet, not Microsoft.
Of course, you do realise that the organisation-now-trading-under-the-Fujitsu-brand cracked AI many decades ago?
----
The great and good were gathered for a demonstration of a new technical wonder: the world's first voice-controlled computer.
They clustered around the chief engineer of the project, who assured them that the computer would indeed understand and execute human vocal commands. This was of course far, far beyond any scientific expectations to date.
He turned and sat at a table occupied solely by a microphone and a screen.
He then spoke in a low, breathless voice, unwilling himself to believe the stupendous advance his team had achieved.
"George," for this was the name of this fine cyber-intelligence.
"George, XFER Journal.SJfiles."
++++
I'll see how many of you get that one,
SPF just says you authorise the server to act for your domain (or to be more precise, the domain of the envelope your mail uses). Mangling the record just gives a PERMERROR but failing to declare a server you are using will cause a HARDFAIL or SOFTFAIL depending on how you terminated. Adding stupidly wide ranges because your ISP is free to move you anywhere around their ASN will not endear you to pro players either (after Zink).
DKIM would sort out the mess arising from a shared server, if it can be trusted to apply that signature reliably. I saw a 5k fraud last year through a certain German ISP who trades elsewhere on the continent, all properly DKIM signed. The ISP's relay server was vulnerable to some sort of replay. I have no idea how widespread that problem is and tend to assume that DKIM is reliable but does not discount the possibility of a breached sender. PhishPoint, anybody?
DMARC just says what to do when either of the above does not align. It doesn't help your deliverability, but getting it wrong will definitely hinder.
Sharing an IP for sending or even having a dedicated resource from an ISP regularly appearing in spam buckets is always going to be fraught. After enough grief, various admins are going to conclude that your neighbourhood is a bad risk and "escalate" their action. That's been the way of blocklists for many years now, and it's only frustrating if the receiving technology is opaque as it is in the case here.
Population of France circa 67 million
Number of records stolen 1.2 million
All records exposed??? Do the rest of the population manage by bartering onions and packets of Gauloises?
I've read the preamble of the presse.economie.gouv.fr statement, and a better translation might be "the attacker copied 1.2 million records" from a database of all accounts in French banking institutions.
Indeed. "'We forge our bodies in the fire of our will' - that's why I'm the shape I am!"
But getting back to the vuln, the key point in this story is that many folk will miss patches for third-party utilities like WinRAR, 7Zip et al. because they "just work" and don't need updates, until something like this comes along.
Even if you did patch, not many realise that these utilities also massively increase the attack surface of the desktop by adding support for a surprisingly long list of arcane formats, some of which aren't really inspected by some anti-malware systems until execution starts the shenanigans. There are black-hat groups out there exploiting that fact.
That would be the same Microsoft who had their own internal tenancy breached last year?
MitM token thieves are ubiquitous at the moment. Conditional access rules based on first-generation MFA techniques are useless except as a remediation mechanism, and then only if you are in a position to audit your suspected breached users' factors. Phish-proof methods are really the minimum standard, and if they become commonplace then the chapeaux noir will just look for other ways in.
And good luck getting that freemail Chocolate Factory account back if an intruder manages to reset all of your "security information" before you can respond to that notice. Same goes for any other free consumer service where you are the product, not the customer.
Even if the entire stack from hardware up to control software and management infrastructure is sold and given over to the customer, isn't there still a dependency on the Chocolate Factory for software updates and security notices? That's assuming the software has not been quietly backdoored.
In any case "Embargo on!" is going to leave the customer wallowing in pig excrement fairly quickly.
Remember that high pay is something of a moral gradient.
At one end you have recipients who are directly responsible for very high revenues and can't be replaced.
Next you have companies competing for top talent in an (overheated?) marketplace.
Then there are chains of interlocking executive and non-executive roles, where everyone votes in favour of a friend's remuneration at the other company. At best the participating companies are buying into a clique of highly connected and influential leaders. At worst it's legal looting from a balance sheet too big and too complex to notice.
Finally there's dear old akamaduri, also practiced in western societies, where that high pay for doing very little is in fact recompense for years of "friendly treatment" when that individual worked at the relevant public regulator.
Furthermore, the ratio between top, average and median pay in an organisation is going to depend very heavily on the actual work it is doing and the skills needed for its labour pool. Comparisons can only be made between organisations in the same business, but I suspect that that would still prove your point!
I hear you over revenue tax but it's the only way to stop these "disruptors" from exporting their profits through spurious offshore costs.
Example: Hollywood is more evil than Darth Vader. I think I have mentioned that the late David Prowse received nothing from the re-release of the original Star Wars trilogy [1]. His contract which covered his work in the original shooting was for a percentage of the net profits, not the gross.
1. Other stories maintain that it was the original RotJ that denied profitability, in which case Prowse took several decades to burn his Lucasfilm boats.
It's a simple cost bleat. The providers all want zero-liability cost-free ecospheres. The cost to their customers doesn't matter if all of the alternatives are as bad as each other.
Well, it's the same barrier for everyone delivering a service to any given jurisdiction, so the only real problem to watch out for is if a near monopoly has proportionally lower costs than a new entrant.
Typosquats are a trivial problem unless warmed up. A much bigger problem would be spurious trial tenancies or breached ones belonging to established Zendesk customers. A lot of the "free trial" hosts don't want to admit that throttling does not stand up to automated exploitation where an adversary can snowshoe over many spurious tenancies.
BA pleaded pandemic parsimony and saw their Magecart fine reduced from GBP183m to 20m:
https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m
Quite what happened to all of the idiots responsible for Magecart getting in to begin with the stories do not tell. We can hope they all died of the plague, but I suspect not. From memory there were about six levels of mismanagement from the board decision to outsource down to the dodgy devs that let the criminals in. Again the tales do not tell if that was by intent or inept copy-and-paste.
Does Microsoft have to remain an American company? A quick check suggests $39b US vs $37b non-US quarterly revenue.
Departure would certainly be viewed dimly in some quarters, but those customers would face the same problem Europeans do in finding a credible alternative to the desktop application monopoly.
They would also have the same assurance that their data would remain hosted in their case within the continental US. All MS need is a legal home that does not assert the sovereign right to issue a writ for any data it pleases. Candidates?
And of course any of the tech giants might do this, especially if they "fall out of favour" with any given US administration.
I think we'll save full extraterritoriality and private armies for the next decade.
I hate to think how great a disaster that is going to be, even if the signatories on both sides are required to pledge their firstborn's souls never to change the specifications or deliverables.
But think of this: one legacy the HMRC is struggling to replace is a colossal pile of COBOLlers from the previous century. It's mentioned on The Reg somewhere. Yes, I am sure the maintenance cost has been significant but how much value has the HMRC obtained from that code? (Less the odd fiscal catastrophe caused by changes that system could not accommodate.)
How long will that SAP solution last before it requires rewriting? Will the HMRC do a DEFRA and eventually implement an ERP system running in an environment that is already deprecated?
Sad but not unmerited. JD may have been one of the first, but there are many other webcomic authors from that era still going strong.
Of course the politicians responsible for this mess could not find their own loopback addresses with both hands, as Miranda could assure them.
This still begs a few questions.
So M&S move to TCS in 2018, evidently on the basis of a 5-year plan giving savings yada.
But in January 2025 at least a year after that plan completed, they started re-tendering for reasons not mentioned? If this was part of the normal procurement process, should it not have started at some time in 2023? During the first few days of the disastrous April 2025 incident, it seems that no-one could be reached. Was someone's back-to-the-office plan underdelivering? Had it fallen on the same altar as measuring remote productivity?
Of course, the really interesting question from this latest story is whether the decision to leave TCS was taken before or after Easter 2025. It would not have helped morale at TCS if they knew they were on the way out. Perhaps all of the first rate staff were transferred to the JLR account?
Anyone have a link to the Downfall parody Hitler rant created for a major Amazon outage maybe 12 to 15 years ago? Those parodies are still as thick as fleas on Youtube and I find three more recent ones specifically for Amazon but not the original I'm thinking of. It would be a highly apt time to bump it back up the ratings.
"Anyone who works for Cisco, HP or Veeam leave the room!" (it's that old)
The function of a high CVSS score is simply to frighten management into taking action.
For the rest of us, the questions of actual exposure and mitigations are equally important.
More worrying is the possibility that an open source vulnerability will be copied and pasted into a new development where it will not be found by vulnerability or patch managers until the new flaw is discovered (and hopefully not exploited).
A quick search suggests the global Renault IT suppliers are Atos, Cap Gemini, Dassault, Google Cloud, Salesforce and possibly a dash of Azure.
If a Renault UK user was compromised, the data subsequently stolen might well be limited in scope to the UK. I wonder which supplier that points to, if the unnamed guilty party is in the above list ?
And thinking of how these franchises are structured, exactly who is responsible in the above scenario? Renault, certainly, but the global group or the UK franchise ? That could make a difference to getting an adequate response (ha!) if your data is in the pot.
The latest BBC update here https://www.bbc.co.uk/news/articles/c62nv0xx32go links to a story claiming that JLR failed to finalise cyber-insurance brokered [at their request?]. Whether they were simply still quibbling when the incident occurred, whether this was just with one syndicate or if no-one would touch them at all is not clear.
https://www.theinsurer.com/cyber-risk/news/exclusive-jaguar-land-rover-failed-to-secure-cyber-insurance-deal-ahead-of-2025-09-23/
Anyone able to read the full article?
A quick search suggests the annual turnover of JLR was GBP 29b. 2% of 29b is 580m. Funding intervention from a GDPR fine (I understand that there is already proof of personal data leakage) would only work if the JLR supply chain did not include overseas suppliers under the control or influence of Tata.
Amen, see that time and time again with many start-ups and those who should know better but don't care a flying doughnut because of their corpus of paying customers.
Offering a free trial of your production domain or infrastructure should be a guaranteed ticket to 127.0.0.1 from any curated DNS resolver.
If any account in your tenancy is breached and you have not enabled admin consent workflow or any of the equivalent measures, the criminal can subscribe your compromised user to an app that will allow them to copy your GAL programmatically. That means that even unused mail addresses become targets for spam and much worse.The usual goal will be to compromise other tenancies, typically the organisations you do business with who trust your domain. Secondary targets are any information in the compromised account useful for BEC fraud, the right to spin up Azure VMs in your compromised user's name for criminal support and the opportunity to phish VIPs in your organisation from their own domain.
https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-admin-consent-workflow
It's 2025 and phishpoint is still very, very real.
Noble sentiments expressed so far, but they overlook the way the browser wars were fought. A minority browser isn't going to win vs a consumer model that innovates to sabotage and degrade rivals. Palo Alto appears to be betting on corporate users who want to combine the secure browser concept with one that's principled enough not to spy on their business 24/7, and I'm not sure there is enough appetite to make that viable. Of course, if you already have a secure browser and just want to raise your market share...
Crossed my desk at the beginning of the year "unnamed AI providers in privacy policy - block".
I've since seen the same weasel terms [no pun intended] cropping up in similar policies - words to the effect that the publisher expects you the customer to gain permission from all participants, and it's your liability if you do not.