* Posts by Havin_it

1227 publicly visible posts • joined 1 May 2008

Bloke flogs $40 B&W printer on Craigslist, gets $12,000 legal bill

Havin_it

Re: Judges and lawyers on heavy drugs are the real criminals here!

Do you have a newsletter?

Millions of 'must be firewalled' services are open to the entire internet – research

Havin_it
Holmes

It's not news TO YOU. The thread immediately following yours shows that it was of interest to someone and the insight gained may just have made the net a better place.

So, y'know, how about you just shut the fuck up if this is all you have to say, huh? Sooo bored of reading this post over and over.

Mark Zuckerberg's Twitter and Pinterest password was 'dadada'

Havin_it
Black Helicopters

Re: Wait.... How does this prove 2-factor has a problem?

My thoughts exactly, AC. It's just a bit too bloody convenient otherwise, especially on the same day FB announce they're nobbling mobile-browser access to FB messaging and expecting everybody to use the app instead...

They already have my number thanks to my nearest'n'dearest using FB/WhatsApp on *their* phones (cheers, y'all) but damned if I'm handing it over directly.

Havin_it

Re: Password strength lesson

>Password re-use is worse than weak passwords.

Weeeeel, it *shouldn't* be, ideally salts and other techniques discussed above should be used so the stored hashes would never be the same from one site to the next. But if they all just blindly do sha1($pw) then of course it's a problem.

Havin_it
Pint

Re: Re-Secured?

Waitaminute, surely it's cheaper than a pint to test your hypothesis...

>clickety-click<

...Ooh, you crafty bugger. You've cracked it, changed the password, and are going to change it back to "dadadada" just in time for whoever's adjudicating to check it. Veeeery clever. You can have this one on the house.

'Windows 10 nagware: You can't click X. Make a date OR ELSE'

Havin_it
Alert

Re: Not Vista

Shitballs. Is that concrete that Vista is in the firing line? I have a manager's BYOD lappy that's on it (yeah, I know, don't start) and I don't have ready access to it to do preventative measures. I'll have to -- oh gods -- talk them through it on the phone! /dies a little inside

Is this authoritatively factual?

Don't panic, says Blue Coat, we're not using CA cert to snoop on you

Havin_it

Time for a bit of democracy?

The flaw in the existing "tree of trust" model is underlined once again. The root CAs prove once again to be unworthy of that trust.

What's needed is a way of democratising the level of trust in a CA or lower-level cert holder. Look at BitTorrent and how its model all but eradicated malicious payloads which had become the bane of earlier p2p networks: admittedly there had to be an initial "sacrificial lamb" to download the malicious payload and identify it as such, but from that point onwards the torrent would never gain traction.

I'd like to see CRLs being used to spank CAs for malfeasance based on user reporting. You signed a cert that got misused? Poof, there goes your own cert. Now enjoy explaining to all your legit customers why their websites are throwing a dirty big warning sign instead of that nice padlock they paid for.

Who would (everyone trust to) manage this process, and how would they guard against malicious false reporting, are the tricky bits. Maybe there's a decentralised, p2p method of going about this part too?

Havin_it

Re: Why is this shocking or even surprising?

This is a step further than that, because they don't need to install the certificate on your machine: it's signed by a root CA that all browsers already trust by default.

Feinstein-Burr's bonkers backdoor crypto law is dead in the water

Havin_it
Coat

Re: Too early to celebrate

200 lb is very weedy for a gorilla. And 5 stone is a child, or maybe a midget.

Just sayin'. I'd still pay good money for ringside seats.

Hulk Hogan's sex tape, a Silicon Valley billionaire, and a $10m revenge plot to destroy Gawker

Havin_it

Re: Not Much Sympathy

While I don't disagree, I think that's pretty unlikely in Thiel's case. Unless he was kicking about in Uganda without his minders or wallet the day the story broke.

Booming sales of flippy detachables offers hope to glum PC market

Havin_it

Re: At which point...

Come off it. Did you ever actually *see* a 1st-gen Windows tablet? They were about as portable as a breezeblock, and about as useful unless you took the power brick everywhere with you. The touchscreens were desperately unresponsive as well. Yuk. There's good reason they were a rarity.

Apple won out because they timed it right; the hardware capability was finally there to make a non-dire product. With convertibles, that ship has largely already sailed. Not that they couldn't leverage a good chunk of the market on the strength of their brand alone, but because they're not first to market this time, there'll be a lot tougher scrutiny from the criticsphere, so they had better not mis-step on the hardware or they'll have their very own Zune experience (which would give me a chuckle).

Hacked in a public space? Thanks, HTTPS

Havin_it
Boffin

While preparing to answer this I realised I wasn't sure either, but I think it goes like this:

Browser generates a random temporary (symmetric) encryption key, encrypts it using the server's certificate (which is its public key) and sends this as part of its request to the server.

Server decrypts the browser's key with private key that only it has, and uses it to encrypt and decrypt everything from there on.

MitM can't communicate back to the browser because they can't decrypt and use the key that the browser is expecting them to use.

(Well they could try, but you'll know they're at it if there's an unusually large fruit-machine in the corner with "D-Wave" written on the side lol).

That was sort of an exercise to self, in case you couldn't guess ;)

Modular phone Ara to finally launch

Havin_it
Boffin

Re: Hobbyists

If you can just get one more upvote you'll be almost bang-on in your percentage :)

10 / (10 + 2) = 0.833(repeating)

The ‘Vaping Crackdown’ starts today. This is what you need to know

Havin_it
Unhappy

Very likely true, sadly. There's a shitstorm of under-funding coming the Treasury's way as vaping gains momentum (much as I hate much of the TPD's content and loathe the interests behind it, I don't think it'll reverse what's happening) so they'll have to raise more cash from somewhere, and vaping's the obvious Daily-Mail-pleasing target.

I just hope our constituency grows enough before they get their arses in gear to start enacting that move, that we can fight it.

Havin_it
Boffin

Re: Regulation is sensible the article is not

>The purpose of an e-cigarette is to introduce a pharmecutical into the body through the lungs.

Ur doin it rong. Depending on your technique, only a very small percentage is likely to be absorbed through the lungs because the particle size of vapour is much larger than that of smoke. The nicotine is much more readily absorbed through the mucous membranes in the mouth and nose; especially the nose, so really the optimised method of vaping is to stick it up your hooter (though I like most vapers find it just a little odd to be doing this in public).

You're right that a lot of the bill is perfectly sensible, but I submit that the regs on bottle and tank volume and concentration are not. We've already heard from one of the MEPs (now a Lord) involved in drafting the EU law admitting to the House that Big Pharma were heavily involved in the process, and this speaks volumes about whom the chosen limits serve. Any bottle I've ever bought has been child-proofed anyway, so I fail to see why volume's a concern; you can do yourself far more harm with a smaller volume of drain-cleaner, and they sell that by the gallon. Same goes for tanks, although even more so as I'm as likely to let children near my e-cig as I was my cigs and lighter. These quantitative limitations serve one purpose only: to make vaping less competitive against traditional NRT.

If I may go anecdotal again (for your benefit as you admit you are not a "vapper"): I smoked heavily for 20 years. Many attempts in that time to quit both with and without conventional NRT products got me absolutely nowhere near that goal. I tried Gen 1 e-cigs when they came on the market, but while promising, they didn't get me there either. (From what I've since read, this may well have been because although I chose 2.4 strength, the delivery was less efficient so the effective dose was much lower.) Late last year I tried again with a modern entry-level system, and within a fortnight I had stopped smoking altogether and didn't miss it. given how entrenched I'd been, I wasn't convinced I really didn't miss it and tried one at Christmas: although it was a "wimpy" budget ciggy compared to the unfiltered rollups I used to smoke, I was too disgusted to finish it.

Would the story have been the same with only 2.0 liquid available? Impossible to say, though I have my doubts. I didn't find the e-cig *more* satisfying (of my cravings) than a cigarette; it simply achieved parity. (The bonuses of smelling better, having more energy and money etc. didn't really kick in until a bit later so they wouldn't have got me there.) And I'm quite certain there are smokers still out there who are hooked harder than I was. If they don't achieve parity, if it's not *as* satisfactory, they won't quit that way and may not at all. That would be a real shame, especially when I know it's only happened so Big Pharma can trouser more cash from the NHS and us with their inferior (for many) solutions.

Can ad biz’s LEAN avert ADPOCALYPSE?

Havin_it

I'd tolerate a lot more behaviour in online ads than it seems like most posters here would: I don't object to some canvas transitions as long as they're at a sedate pace that doesn't induce epileptic fits; video is legitimate as long as it doesn't autoplay and I could even tolerate some level of scripting and tracking as long as it was curated and regulated by an independent overseeing body. Makes me a rare breed around here, I know.

That proviso, by the way, should very much extend to the content of the ads: print and TV ads in the UK are subject to oversight by the ASA (and as uk.gov watchdogs go, it's actually got some teeth). If they make bullshit claims, they get called on it and often fined. I'd like to see this happen at the international level, as is necessary for the nature of the web. Hell, if such an entity existed, it might even be in a position to take some serious action against spammers as well ... well, one can dream...

Havin_it
Alert

Re: Acceptable Ads?

>I use an anti Adblock killer[...]

Wait, that's a thing now? Let me parse that down.

An app that prevents their prevention of your prevention of their ads?

This isn't going to end well...

Chap runs Windows 95 on Apple Watch

Havin_it
Boffin

>what possibilities does it open up?

Office 97, obv. Duh.

I am Craig Wright, inventor of Craig Wright

Havin_it
Trollface

Every one of us has a Craig Wright lurking

He could be working at Burger King, encrypting your onion rings/

Or in the parking lot, circling, screaming "I'm Satoshi!" with his firewall down and his server up...

The EU wants you to log into YouTube using your state-issued ID card

Havin_it
Joke

Re: Estonian ID cards tell you who is snooping

>id.ee

How this wasn't already bought up by a disruptive French hot-desking startup, je ne saura jamais.

Havin_it

Re: Estonian ID cards tell you who is snooping

Wow. That's unexpected to say the least. I'm not sure whether I think it's the greatest bit of transparency and open governance ever, or a recipe for abuse of some kind that I haven't identified yet. Probably moot as our gov wouldn't give such an idea the time of day, but interesting. Must learn more about this...

E-cigarettes help save lives, says Royal College of Physicians

Havin_it
Coffee/keyboard

Re: I don't know.

No nerdgasm has ever felt so shameful :(

Havin_it
Joke

Re: I don't know.

>Now we know. Now we know. Now we know.......

Uh... Are you making a porno while typing that post?

/Mitchell&Webb

Cavium snubs MIPS, picks 64-bit ARM for next-gen network SoCs

Havin_it
Boffin

Re: 8,192-bit keys

I saw this and wondered if the meaning was "8 x 192-bit keys" (which would be rather less fancy in most use cases). I had to check there wasn't a space after the comma.

Reg, find yo'self a better-kerned font! kthx

Gwyneth Paltrow and Richard Branson will lead Sage's 'sexy accounting' shtick

Havin_it

Re: Nice gig and celebs, shame about

Bit harsh. My company have used MSP (then Protx) for more than a decade, and if you met us I hope you wouldn't think we're douchebags. I mean I am, totally, but my colleagues are stout fellows and keep me in check for the most part ;)

We're a very small player and only use the Form off-site processing portal, so can't speak for more heavy duty integrations, but the only problems we've had have been the couple of outages they've had in all that time (and who hasn't?). Re the transparency of what's happening with transactions, I find it very comprehensive in that regard and I actually wonder if the vendor wasn't snowing you there.

I've no idea if the grass is greener among other PSPs, because I've never looked, but any I've heard of have been in these pages for some clusterfuck or other.. We went with Protx on a recommendation from ... a WorldPay sales droid. True story.

Furious customers tear into 123-reg after firm's mass deletion woes

Havin_it
Childcatcher

For some reason I thought of Stewart Lee's delivery on reading that, not the redoubtable Mr. Presley.

[Icon: Thought I'd strayed onto the Grauniad by mistake]

US anti-encryption law is so 'braindead' it will outlaw file compression

Havin_it

Ransomeware

We Didn't Mean To Go To CRC32?

[PS: "HOW marked the harbour?" is a clear nod to the folly of security-by-obscurity.]

Cinema boss gives up making kids turn off phones: 'That's not how they live their life'

Havin_it
Joke

No, that's how we spell "me" here too. We don't use the tildes though; is that because it's an especially important word over there? ;P

And the Faraday cage won't stop them playing Crunchy Birds with the sound up :(

That naked picture on my PC? Not mine. The IT guy put it there

Havin_it

Wow

Much excite

Lipstick is deployed

So fetish

Wow

Havin_it
Unhappy

Re: Senior bods

>www.MassiveTitsOrSomeSuch.com

Must have been years ago, it's down now. I am epic disappoint.

Might buy it myself...

Havin_it
Pint

Re: When I was in a similar position...

>So [IT] sneaked in at lunchtime...

They left the pub? At lunchtime?

Calling BS on this one.

Uninstall QuickTime for Windows: Apple will not patch its security bugs

Havin_it
Boffin

Re: Slowtime

>It and Realplayer would overwrite existing file associations for all media types.

You sure about that? ISTR that a screen on the installer (or possibly on first-run) let me choose the associations. The defaults may as you suggest have been all in QT's favour, but I'm sure there was a "No to all" option, whereafter I could re-enable only the file-types (.mov) I actually needed it for.

Was it all a dream? /wibblylines

The future of Firefox is … Chrome

Havin_it

Re: So, sounds like we're going to be down to just two major rendering engines?

>There's still regular FF with Gecko

Until they bin Gecko for Blink, which is the possibility raised in the article (although Servo is all their own so fingers crossed that works out and gets the nod). Either way, with Gecko will also vanish the current extensions (unless they get ported), that's what troubles me.

>Konqueor uses KHTML.

...which is not something to be overly boastful about, IME; Daddy of WebKit it may be, but the Apple fell quite a long way from the tree (sorry, couldn't resist). As an aside, Konqueror can use WebKit instead of KHTML thanks to its modular architecture; however that's academic, as it has no maintainer now and isn't likely to survive into KDE5. Shame, really; awesome file manager.

Cruz missile slams into DNS overlord ICANN over Chinese censorship

Havin_it
IT Angle

Wow

I realize this is kinda OT and late, but was Cruz REALLY the frontrunner as recently as the beginning of Feb? Crikey.

Microsoft's equality and diversity: Skimpy schoolgirls dancing for nerds at an Xbox party

Havin_it
IT Angle

@Jon Arden Re: Depressing reading this comment section

>Games are consumed by roughly 50% men/women[...]

I don't know many gamers myself (or perhaps more that it's not something we discuss because I'm not one myself) but it surprises that the ratio is that balanced. Are you sure? Is your data personal/anecdotal, or from research by others?

That being the case, to what extent (if at all) do female gamers feel the unbalanced developer ecosystem is thus far letting them down? What are their common complaints about gaming in general as a pastime, or the games on offer? Interested in your observations from within the industry.

Havin_it
Coffee/keyboard

Re: Let's not pretend its just Microsoft

>Silicone Valley

Typo Of The Year nominee, right there.

Linus Torvalds wavers, pauses … then gives the world Linux 4.5

Havin_it

Re: Steady as she goes

Hm, still no better then? I was just clearing some time this week to build the latest releases on my Gentoo box. Maybe I'll skip it and wait for the next :|

I'm sure it will attain tolerability eventually but the regular plasma crashes (although at least it comes back up by itself now) and kded5 going 100% CPU after a suspend or two, are getting a tad bit wearing.

Alternatives? Oodles of choice, but if you want to keep it Qt, then LXQt is in quite good shape by now. I've been using it on my Raspberries for a while now and find it quite pleasingly unobtrusive but equipped with all the basic comforts (although the preferences controls are a bit all-over-the-place). I do miss Klipper though.

Mozilla will emit 'first version' of Servo-based Rust browser in June

Havin_it

Re: Yaya yada yada

>If they let users install crap extensions from crap developers then I feel that might still be a no.

IIRC, the XUL extension system is part of Gecko and is for the chop as well. That'll likely mean a bonfire of the orphaned extensions and all those that are too much work to port to whatever the new extension architecture may be; I haven't heard much about this aspect of the transition and it worries me because I do use and value a few quite niche extensions.

Even now there's another bit of newness called Electrolysis (e10s) which separates content and UI into separate processes or something (I guess this is a necessary part of the Servo roadmap as it features in the diagram in the article). It's present in nightlies already and I gather will break a lot of extensions too.

Havin_it
Joke

Re: "think twice about calling anything Graphene"

Some former users might opine that Mozilla introduced the userbase to Anal Sex quite some time ago ;)

[NB I'm not one of them, I'm all about the Fox]

Want to kick butts? Go cold turkey

Havin_it
Joke

Re: Tobacco = Enlightenment

Sounds a bit like the film "Demolition Man". We'd better get to figuring out how to use those three sea-shells.

Havin_it

Re: We're logical people here...

Unfortunately you have a nose like Rudolph and your liver is fucked!

Microsoft adds 'non-security updates' to security patches

Havin_it

Re: I'm Surprised

To some extent, that's what is happening: The telemetry features are backported (I'm not sure how extensively they mirror those of W10 but there have been a few KBs so far).

But upgrading the whole OS core bit-by-bit is a tall order by any stretch (and remember that, when it comes down to it, MS just aren't that good at software). Considering how many PCs are getting hosed just by the existing monolithic upgrade, doing it in such a complicated and shifty way would just be asking for even bigger chaos IMHO.

Also, seriously: don't wait until you retire. Get a dual-boot sorted out (most Linux distro installers can do this for you these days) and use it whenever you don't need to be using Windows. By the time you do retire, you'll be doing so with more hair left attached to your head!

Havin_it

Re: How bad it must W10 be

You make a fair point. My comment was focused solely on people who use a computer as, y'know, a computer.

Those people, I might help (or snow for the sake of a quiet future, as above) as time and sanity permit. People who buy a PC for gaming just aren't in my natural constituency, so I'll probably just advise them to buy a PlayBoneWeeStationZX, or try dating.

Havin_it

Re: How bad it must W10 be

Just bung Mint on it with a Redmond-esque theme convincingly similar to whichever version they were using, and a couple of shortcuts ("My Documents" et al.) on the desktop. You'll probably never hear from them again, and if you do it'll be a problem you can solve.

Havin_it
Headmaster

Re: Horse has left the barn on that one!

It's MICROS~1 (case insensitive). Everyone shouted back then because there wasn't an Internet to complain about it.

Get it right or don't bother, FFS.

Havin_it
Headmaster

Re: Sigh...

Unless your "Cat" is of the Deeley, Stevens or Red Dwarf variety, don't capitalise it. People will tend to read into that sort of thing ;)

Try mapping all the keys to play some of these babies in your favourite audio player, might work for training. (Leave your webcam on and you might even get twenty quid off Harry Hill for the results!)

Obama puts down his encrypted phone long enough to tell us: Knock it off with the encryption

Havin_it

That's a crap analogy. This "safe" is drill-proof (as far as we're led to believe), so your only way in is by the pre-emptive tactics you outline here (unlikely*) or by coercing the combination out of the owner (impossible without a working ouija board in this case but more often quite viable).

*More accurately, getting the safemaker to design the front door lock with a skeleton-key option.

Havin_it
Joke

Maybe...

But a piece of shit has a thousand eyes. /CoreyFeldman

Havin_it
Thumb Up

Re: Monty Python did a song about Kissinger (the other ultrakill-holding Nobel Peace Prize holder)

Ah yes...

You've got nicer legs than Hitler,

And bigger tits than Cher.

I'm not sure Eric Idle [or was it Neil Innes?] has creativity of this calibre left in him at this point, but would be interesting to see what he'd come up with for Obie-poos.

[Personally preferred their one on Oliver Cromwell, more educational.]

Havin_it
Black Helicopters

Re: Hmmmm. Maybe it's time...

>The goverment couldnt give a shit whether decrypting the phone is legal or illegal. If they could - they would already have done it and this topic would've never made it into the news.

Ed Snowden has claimed that they can, which if true means (A) they're trying to draw heat away from any allegations that they have this capability, and/or (B) this case is simply a pretext to have this debate in public, with a scenario that they reckon plays well to steering that debate in their favour.

One possible inference from this might be that there actually *is* a backdoor, that Apple put it there deliberately on request/under warrant, and that this whole fight is security theatre with their connivance.