Re: Missing an important detail --
"New Outlook proxies every single mail request through Microsoft servers."
That's going to prove interesting. Better not be scraping content for AI..... Can of worms at the ready!
412 publicly visible posts • joined 28 Oct 2020
Ignoring whether Beeks will impact VMWare or not, ultimately beyond the pale increases in costs, for no apparent increase in services or innovation will always cause users to consider is it worth it.
Enough variations on a theme discussed in this thread for sure, but whoever is advising companies to apply these levels of increases just to improve the bottom line, is still missing the key point: piss your customers off and they will look for alternatives.
In my experience, water companies tend to be incredibly reactionary and less visionary when it comes to Cyber Security.
You only have to see the apathy applied to Sewage spills (Storm Overflows) in the UK industry, to realise something with that level of impact isn't being addressed to realise that's pretty much the approach to anything that could impact the bottom line!
It will be dealt with when the regulator is at the gates threatening action.
Exactly what I was thinking.
Where's the evidence of Businesses want to move to AI PCs ? Just because Gartner says so?
Seems like someone's trying to be relevant and it's not.
There's no rush to have AI anything as far as I can see in my experience to date.
I won't be rushing to get an AI phone either, as it sounds about as useful as a 3D TV does right now.
Having worked in the Middle East for a length of time, some of these payments were seen as the cost of doing business in the region.
I appreciate its hardly the way to do business in an open and transparent way, but has anyone seen the lobbying of politicians recently?
It will be interesting to see what the outcome is of both the SFO and the PNF is.
Just because we can store data and keep doing so until either the cost of the cloud storage goes through the roof, or our NAS/SAN is full, doesn't mean we should.
The problem is as much about scalability without any real thought, as it is about whether we should be collecting so much data in the first place.
Just look at your classic office user, look at how large their email storage is, if it has a quota limit at all. Reams of inboxes have mega/terabytes of crap stored just because "I may need it" and there's no consequences if you don't manage it, until it's full of course.
My analogy to most users is: "If that was physical mail coming through your post box, you would have got rid of most of it within a matter of a day or two, why are you storing emails from 10 years ago?"
"Unlimited storage" is baked into the cost of your licensing most of the time, but it's well hidden to the point it doesn't appear to have an empirical value that can be scrutinised.
So, until we re-educate data users, we've got a long way to go before we can secure it all.
That's not a great deal of spend is it?
Considering the size and footprint of T-Mob and its attack surface......
YMMV, but I don't think having to spend shy of $16 mil on improvements is going to do a great deal of beefing.....
Totally agree Headley Grange.
The consequences aren't sufficient to create the critical mass required for change.
Any significant changes to punitive measures will, I suspect, be a long time in coming never mind being executed.
Unfortunately Data/Information isn't seen as that important yet as the impact is hard to measure.
We can but hope for a new world order, however, I suspect I will be a long way into my retirement before it comes to fruition!
Oh good, that will help won't it?
FFS! This is the response every time there's a data breach.
It's simply not good enough.
Does nobody do encryption of sensitive data?
I know, I know, it's probably a legacy system that can't be upgraded, etc etc, but still.
This is a common theme.
It's easy to blame the end user for not being savvy enough to spot the fraudulent, nefarious activity, but.....
Not all users are as blessed the the El Reg readers are in the common sense and technical savvy that most have.
Ultimately, education and alerting to our fellow citizens is all we can do to upskill them and help combat this scourge of society.
Crims, however, will exploit anything they can to get the rewards they are after and as always, the weakest link is the human that is not fully conversant with these risks and tactics.
It would appear to be a clever use of social engineering and technical tooling that relies on the odd human making a mistake and becoming a victim.
QR codes. Handy and a curse at the same time.
Having had the joy of working with Infosys as a partner, I can totally get onboard with other posters comments.
We had a "technical manager" assigned to our account by Infosys. Never saw the guy, never heard from him, but we did find out he was being billed to the company for his time.....
When challenged it was spun around and made out to be our fault for not using said manager?? Go figure.
I could go on and on about the other tasks that were assigned to Infosys, but there's little point.
I don't blame the teams at Infosys at the coal face, even less so if that's their bosses view of how to deliver.... just throw hours at it until you've killed your staff and get some new ones.....
Apple doesn't have the greatest rationale for keeping people out of their hard earned purchases.
Let's be honest, as we move towards a more universal approach to standards on most electronics, the gap between Mac "superiority" and other platforms will decrease considerably.
Just me 10p's worth, and I am neither a fanboi, nor a nay sayer of Apple products.
There are some arbitrary decisions made in business by old and bold, non technical manglers and directors, who think "they know" tech and will then use their "seniority" to force a business decision based on bias, not knowledge.
For instance, many moons ago, I had a manager demanding to know why "His IP Address" had changed on his work PC, can't remember why said manager knew his IP address, but after 15+ minutes trying to explain what DHCP does and why "His IP Address" doesn't matter in the context of a work network, I had to walk away and ask him to raise a ticket to get it "resolved"...
Some times manglement know better.... apparently!
Some big names in that list.
Being a dinosaur, I still find it surprising, how much poorly protected, incredibly sensitive information is exposed in some of these types of breaches.
One day we'll get our collective heads around strength in depth and security commensurate with the value of the data and/or information.
Will be open to abuse.
The very fact that something so critical, can then be superseded by a Government demand to get information, rarely provides the protection or control it sought to do in the first place.
As is noted by this very article.
Once you have a control in place that can be vaguely understood, or not, people will go to the exceptions process to circumvent the control, if it appears easier.
If you have such Patriotic-Super-Double-Secret process and the ability to scare the crap out of people to comply with it, well you know the certain creek, without a certain paddle you are now navigating.
YMMV obvs!
The last time I saw that being deployed I had to work the extra hours the "Day off" provided......
Not really doing what was intended, insofar, it was adding to the stress.
Then again it was a company based in the USofA and I was a consultant, so it's all about the hours billed.....
Still, having a long weekend, every other week was still good.
The SAAS,PAAS, IAAS (add your **AAS to suit), well know it's a gravy train that will catch and awful lot of businesses out on costs,time, effort etc., etc., but by then, you're stuck between a rock and a hard place whilst you work out who or what needs to change to actually get the "savings" you were promised by the sales team.
For some organisations, Cloud will work, for others, they are pissing in the wind trying to keep up with the Jones'.
Is this type of behaviour typical in US companies?
If there are rules and regulations in place, why or how do the employers think said rules don't apply to them?
I'm on the wrong side of the pond, but I really don't get this abject hostility shown to the very staff that help the organisation's deliver their product or service.
So the obvious thing to do is to try deflect by beginning litigation against the security researcher?
Obviously if said researcher was being a cock and threatening to leak data, then fair enough, but seriously, shit slinging when you've had a significant data breach is a great way to deal with things!
One of the challenges here is getting the issues understood, with the right level of gravitas, then getting those issues in front of the right people, to decide how to "regulate".
The next challenge is defining what Cyber Security means and how to accurately and universally define it so you could regulate it.
I believe the great Grace Hopper once said that the value of data is not understood, or something similar, see this: https://www.youtube.com/watch?v=ZR0ujwlvbkQ1
Cyber Security events also have differing impacts and it would appear that only the fact something bad has happened is the constant, so we would find it hard to regulate Cyber Security.
Currently the myriad international regulators, acts of law and so on are beginning to have a level of Cyber Security baked into them, think DORA, GDPR, NISR, NIS2, NYS the list goes on, but there isn't a unified approach yet.
Now, if you're on about reporting, then there's plenty of that required from various National Competent Authorities, however, the requirements don't specify the public be fully notified.
It's a complex subject without a simple, single silver bullet as a solution.
Before you deal with the troublesome person, just think they may be the only one listening.
Very good point John Miles.
I've never looked at from that angle before and may be something I'll consider when it arises next, in any context.
That's classic, look at the money as the problem, i.e. we want more, or the shareholders do etc., the never ending chase of growth/profit at all costs means anything that appears to demonstrate savings, or better margins will be laser focussed upon.
The standard approach is always kill headcount and buy some new tech that "promises" to show savings......
My kids all of them age range teens to adults..... They simply cannot understand why you'd want to speak and hear each other!
I'd like a Phone OS that's less invasive with it's telemetry and advertising etc etc.
I don't have an issue with my smartphone per se, but I did like the period when every phone manufacturer would produce funky designs and try and grab one's attention that way!
A more simple time for sure!
The best phone I ever had, pre smart phones.
https://en.wikipedia.org/wiki/Nokia_7110
I know I'm a dinosaur, but I use my phone to make calls!
Revolutionary I know, but I don't see the excitement about having your device track your every move and report it to the manufacturer's HQ, and others, for the purposes of making more money out of you.
I'd have another Nokia 7110 any time.
I find reporting pretty much anything to Meta provides nothing tangible.
Personally it takes a lot for me to be pissed off enough to report something, but apparently Meta's Community Guidelines are morally superior to anyone else.
You just get the "Feck you! We don't care what you think!" auto response from their bots.
Playing second fiddle in the business it will often be overlooked.
In my experience to date, Security is seen as a cost centre and is reluctantly funded in some organisations, in others, it's front and centre and is well funded and invested in as business leaders see the indirect benefits.
To be fair, the guidance is a solid place to start, but the messaging is often not getting through.
If you're going hell for leather in the tech space, security is not the first thing that is being considered.
There's not enough substance to this politician's soundbite, yes there is some really slack regulation in this space, but if you hammer US registrars, the miscreants will move to another area with less regulation.
Prevention, not cure is really where the focus should be, at least in the long term.
If so many individuals are that gullible to fake news, what or how do you address that glaringly obvious issue?