* Posts by Lee D

4261 publicly visible posts • joined 14 Feb 2013

Shocked I am. Shocked to find that underground bank-card-trading forums are full of liars, cheats, small-time grifters

Lee D Silver badge

Re: Colour of surprise

Quite.

"Oh, that criminal who was going to sell me a thing to help me commit crimes actually committed fraud and took my money and didn't even give me the thing in return!"

Oh, no. You should go to the police. Oops. You can't. Because what you wanted was illegal in the first place and you were just dropping yourself in it.

I do wonder, though, how they paid them - presumably such payment is Bitcoin or something. I doubt a card-skimming forum would accept credit card or Paypal!

It's like a drug dealer selling them talc. What are they going to do? Dob him in? And face a charge themselves?

Nvidia may be mulling lopping Arm off Softbank: GPU goliath said to have shown interest in acquiring CPU design house

Lee D Silver badge

Merging of CPU/GPU looks to be the only real reason.

AMD is basically ATI/AMD.

nVidia is out there, usually paired with Intel.

Apple is incorporating everything onto an ARM chip and abandoning Intel.

Seems like nVidia/ARM could well be a very powerful combination, bringing proper GPUs to computers and well-established ARM to the fore.

I doubt they can afford it or it would work, but nVidia/ARM (strong GPU, strong CPU) against Intel (rubbish GPU, strong CPU) and AMD (strong GPU, strong CPU) seems to be about the only thing to stop them eventually becoming irrelevant - especially in the mobile/tablet area which they only dabble in (nVidia Shield being their most successful?).

And I say that as someone who just bought a nVidia/Intel gaming laptop that I'm in love with.

Apple to hand out limited-edition iPhones among 1337 h4x0rs because it wants more bug-hunters

Lee D Silver badge

Re: Cognitive Bias?

The last round of hacking on Apple's phones managed to find a remote flaw in browser parsing of a simple website, caused by all kinds of things that just shouldn't be possible - not just technically, but procedurally - that allowed a Mac, iPhone and iPad compromise of the browser to illicitly enable the camera.

https://www.ryanpickren.com/webcam-hacking

This included allowing websites to download arbitrary files, then treat those files as trusted local file: or about:, blob: or even data: protocols (!!), letting you load javascript from them, thus bypassing security permissions, along the way discovering that domains with .- or -. in their name don't appear in the permisisons dialogs, you can do popups and even force a browser password autocomplete, and abuse window history to play clever tricks.

The problem is not the bug you suffer from. The problem is the CLASS of bugs you suffer from. Because they indicate the design of the system, rather than a tiny incidental oversight. It's not an oversight to do the above... it's a completely thoughtless design process. Which is the opposite of security.

As with everything Apple that I've ever touched - design for them means "designer", not good design, not easy-to-use, intuitive, sensible, planned-out, functional, etc.

Capita's bespoke British Army recruiting IT cost military 25k applicants after switch-on

Lee D Silver badge

Re: Why haven't we banned Capita

CANCELLATION CLAUSES and PRESCRIBED METRIC TARGETS (e.g. number of job applications handled by the system, percentage of applications experience technical problems, etc.).

Why does nobody put them in?

You didn't deliver, contract is null and void, you get nothing. Want to get paid? Make it do what you promised.

Computer misuse crimes down 9% on last year in England and Wales, says Office of National Statistics

Lee D Silver badge

Go tell that to your local drug rehabilitation centre.

If you can read this, your Windows 10 2004 PC really is connected to the internet no matter what the OS claims

Lee D Silver badge

https://en.wikibooks.org/wiki/Windows_Troubleshooter_Guide/Network_Location_Awareness

"Note that sometimes, you might get a yellow warning sign/exclamation mark indicating that you have no internet, yet can connect fine. In this case, judging by the above cases, it should mean that #2 failed but #1 works."

That suggests that this would be caused by DNS issues on that given domain.

(Although someone could check Windows 10 2004 if they like and see if that registry entry points somewhere other than the two known values).

It does seem incredibly stupid to have the entire world check a text file on one website to see if they are online or not. That's one of the reasons I changed mine to my own server.

Lee D Silver badge

I think this sounds like MS has changed the NCIS methods they use.

It always used to be that they would try to connect to a given website (www.msftncsi.com, owned by MS) and download a text file whenever it detected a new connection (wifi or Ethernet). If that didn't work, the connection was "limited" instead of "Internet". I know, because in the registry you can change the given website and then use it as a primitive (and completely invisible) monitoring of your devices. If a thief is silly enough to turn it on, it'll connect back to your website and your Apache logs will tell you the IP where it's at, and additionally if that server goes down you'll notice because your Windows PC will say that it's not on the Internet when it clearly is!

In Windows 8/10, they changed the website and the text file and the contents of the text file. That's why you see a ton of connections to msftconnect.com or something... that's every machine on your network trying to see if they are on the Internet or not. It also triggers proxies to prompt you to login, so it does serve some purpose.

I bet either that domain is having problems, they've changed the verification again and it doesn't work the same, or they simply broke the NCIS protocols in the background.

Philippines to install 23,000 free public Wi-Fi hotspots

Lee D Silver badge

$6700 per wifi point.

Makes me wonder what they're deploying and what they're connected to.

Twitter hackers busted 2FA to access accounts and then reset user passwords

Lee D Silver badge

GDPR lawsuit in 3.. 2... 1...

Forget about Wipro chairman saying no one would lose their job due to COVID-19: UK staff told they're facing redundancy

Lee D Silver badge

I remember working in a school that was becoming an academy.

"No jobs would be lost", they said.

I made my way to the door pretty damn quickly.

Because the way they announced no jobs being lost was to pay an outside consultancy thousands upon thousands to sit us all in the main hall (200+ staff), give us all a Bluetooth keyboard (which connected to a bank of USB hubs and Bluetooth dongles larger than the laptop that was running them), and we each got a little box on the screen where we could type suggestions ("anonymously").

I think #1 suggestion was along the lines of "stop with the gimmicks" and " stop wasting our money on this stuff".

And they were technically true - no jobs were *taken* from people, really. But everyone fled. Which left huge holes. Which meant that those who remained were given more responsibility and accountability, and less people to do it with, and they had to get co-operation from fewer people who were less familiar with the roles given them in order to do it, and then blamed when something wasn't done.

They then spent most of the time interviewing for unskilled replacements, at rubbish wages, which meant it often got *worse* after hiring a cheap newbie who knew nothing of what they were supposed to do but came under a manager's remit to train them AND do the trainee's job AND their job in the meantime.

No jobs were lost. Just staff. Left, right and centre. Until the majority were gone (myself included) at which point they inserted their own cronies from elsewhere into those self-same jobs.

In the end, I think we had something like 30+ "deputy heads" (before that, we had five), which just meant "teacher with all the responsibilities other people had, lumped on top of their teaching", but they never realised that. They were still cooing over the new job title, mostly. In a way, that actually pushed them out of the school because they realised the job there was way over their heads, but they could apply to other schools and claim deputy-headship. I don't think that was deliberate, but I wouldn't be surprised if it was.

But "No jobs were lost". If anything, jobs that had never need exist were invented, in effect. And fewer people had more responsibilities than ever while lots of extra new people didn't know what the hell they were supposed to be doing.

As an IT guy, I spotted the kit being deployed for their staff meetings (without consultation!) and knew the game was up and got out of there. The headmaster was surprised and tried to lure me back with half-my-current-pay-packet. The guy had no clue. He said to my boss that he was surprised I didn't take up his offer, at which point my boss informed him that I wasn't a child and the salary offered was a literal demotion of huge proportions. He never upped his offer, even by a tiny bit. But I suppose you could say that my job wasn't "lost". I was just totally unappreciated and my replacement would be paid a pittance. But the job was still there.

Everything must go! Distributors clear shelves of ALL notebooks in Q2, even ones gathering dust over last 12 months

Lee D Silver badge

I don't claim to be in the upper echelons of IT, but I worked my entire career in it, let me describe to you every piece of functional (i.e. turned on and vaguely modern) kit in my house:

1 laptop (until this week, was 2008 model, now I have a 2020 model!).

3 Raspberry Pis (2 x Pi4, 1 x Pi 3)

A laser printer from 2000 (no exaggeration).

A router from 2010.

A 4G box from 2018.

A projector from 2010.

A smartphone (2020 model, but quite budget).

And that's... pretty much... it.

However this week alone I spent £25k+ on Chromebooks for work, not to mention monitors, PCs, laptops, phones, etc.

The reason is quite simple. When I need to do work, I connect to the work stuff. Which is £100k+ of servers and same again just for the networking. When I'm at home, I just need stuff for me, and to connect to work (where the real stuff is).

Hell, I've been issuing junk to people just so they had something to get online with so they could remote in and use their "real" work PCs and so on. Now I wouldn't expect some IT guru to have *nothing* at home like some people, but they don't need to take all the proper kit home - and if they're dealing with data, they damn well shouldn't be!

And I have done my job entirely from a foreign country using a phone before now. It's not fun, but it's possible. Now that we're in the era of HDMI / USB / Bluetooth on phones, connecting a mouse/keyboard/monitor to one and using it as a full PC is more than viable - they are actually damn powerful nowadays! But you don't need to have a lot at home to log in and use the real kit.

There's actually a psychology at work here. I will in preference issue a merely "technically viable" device, over some shiny new expensive kit. It encourages people to actually go out and get their own if they want something better, while removing all "I can't work from home because the company didn't issue me with anything" nonsense. If you gave them Macbook Pros (or whatever), they'd ALL want one, it would cost a fortune, and anything else wouldn't be seen as acceptable, even for the new kid or the IT guy who already has everything at home.

Give them something that is viable - not just minimum spec, but enough that they can't really complain about it. Then if they want something better, they can shell out for it. But if they have nothing at all, they'll be grateful for it. You save tons of money. Everyone is happy. And the techy guy can pay-for and use what he likes (if you have such a daft policy).

I find laptops, especially, to be a status symbol item. Someone gets one not because they need it but because they want to be seen to need it (they're SO important, obviously, that they've got to have a way onto the system even at 3am, etc.). Then others want them because X has got one. Then everyone strives to get one and kicks up a fuss because "Well, X was given one, aren't I as valuable an employee?". And before you know it you're paying for everyone to have laptops that nobody uses, but that many people break or just use for their home browsing despite it being a corporate device.

If you don't go down that route, or if you stop at the "This is perfectly adequate, and that's all you're getting" line, then it works far better.

€13bn wings its way back to Apple after Euro court rules Irish tax deal wasn't 'state aid'

Lee D Silver badge

Re: Apple said the case was not about "how much tax we pay, but where we are required to pay it."

Did that.

Was made to buy a ton of iPads for a workplace.

Got them from some grey import from Singapore in the end. Damn sight cheaper, and I have an invoice from the usual IT supplier to say we paid for them in full - they're legit, and I wouldn't be liable for any taxation reinspection on them, so it's not my business where they have come from.

Signed them all up, they all worked, for many years - some still in use years later despite my protestations. Never had a problem.

The only issue is that Apple won't support them, but given responses received from Apple's support on a number of issues in the past, that's actually one headache less than if I had bought them in this country.

Our usual suppliers threw all kinds of accusations at the company that supplied them (who we obviously went with because they were so much cheaper), but as a customer, that's not my problem - we weren't dealing with cowboys, so where our supplier gets them is their business, and they were very upfront in emails etc. that they were imports from Singapore.

I'm far more concerned that it's cheaper to buy the same product in Singapore, ship it halfway round the world and STILL undercut all your competitors, than it would be to just buy the product direct in this country. That's the issue, as far as I can tell. And I don't believe that whoever imported them didn't actually pay import taxes, etc., as they were quite openly on the record doing so and it's not easy to import thousands of iPads under the radar, I imagine.

When the profit margin for all involved happily ships expensive containers of heavy, valuable items around the world and still wins, there's something wrong with the business model.

TomTom bill bomb: Why am I being charged for infotainment? I sold my car last year, rages Reg reader

Lee D Silver badge

Once of the reasons I bought a new Ford a few years ago.

In-car satnav is just an SD card that you have to buy. It doesn't update online, it has no talk-home functionality - hell you literally can't even purchase the "officially supported" 3G/4G stick in the UK for if you wanted to run the in-car wifi off the car itself (it's just a repeater for your phone wifi otherwise, which is the most useless feature I can imagine) - and none of the ones I own work.

Took it for a recall (silly issues with things like battery clips), they updated the software - it took three hours because, I quote the engineer, "We have to download the software onto the SD card and the download speed here is shite". When you want a new map, you have to buy a new SD card.

Truth be told, the in-car satnav is pretty good, but my phone's CoPilot does a far better job, map updates are free forever after buying it, it has a pittance of a subscription traffic (far better than the RDS-TMC on the Ford), and it works entirely offline, and for walking. So I only really use the Ford for basic re-routing if I can't be bothered to stop and get the phone out.

But an online car sounds like a fecking nightmare of privacy, security, talk-home and "we'll just turn off this account".

Asia’s internet registry APNIC finds about 50 million unused IPv4 addresses behind the sofa

Lee D Silver badge

Re: So, IPv4 addresses are like petroleum

A condition of 4G/5G and DOCSIS cable standards are IPv6 support.

Google gets a ton of IPv6 queries - something like 25+% of their searches are on IPv6.

People are just too lazy to actually deploy it.

(Hey, Reg, any AAAA records yet? About the 6th/7th year of "we're working on it?"

University ordered to stop running women-only job ads

Lee D Silver badge

If the biggest stumbling block is people asking how do we abuse the system, chances are it's a good system.

Lee D Silver badge

Positive discrimination is still discrimination.

Equality is equally (sorry!) not "we have 50% female staff".

Now... I describe my stance as pro-underdog. I get that women are getting a duff deal and aren't on an even footing. But I don't see that shoving them into jobs where they haven't competed on an equal basis to get them is doing anyone any favours. The same for disabled, minorities, etc.

If you put women in the position in preference to men, in order to try to maintain some artificial ratio, that's just going to make people resent them, which will make their jobs harder.

Fred and Philis both apply for the same job, same experience, same qualifications, etc. Philis gets it "because we need more women"? No.

If you want to do this, and do it properly - double-blind interviews. Have the candidates prepare a CV and then strip age, gender, name (often indicator of gender) out of it entirely. The HR department provide made-impartial CVs with code numbers. They're reviewed by an interview panel, and a list of code numbers are invited to interview. HR doesn't even need to know the code-numbers! It could all be automated - "#6 is through to the next stage, send Stage 2 email to invite them to interview".

The candidates are invited to interview, but not in-person. I mean, it's 2020. Live-chat it. They can do that from the HR department if necessary - candidate comes in, someone verifies their identity, sticks them in front of a computer, the people actually *interviewing* have no idea who they are interviewing but get a chat window to ask questions.

You know it's the candidate and not someone else.

They still have to think on their feet and provide answers to arbitrary questions.

You still have their CV to refer to.

It removes all indicators that they are maybe a stutterer, in a wheelchair, have a birthmark, are blind even, black, a woman, whatever it is that you don't want to be accused of discriminating against.

If they have to interview from home for whatever reason, send your HR person to them with a laptop. Nobody will ever know. And if their physical condition doesn't affect the ability to do the job... who cares? Nobody can discriminate against you on that basis.

And if you have difficulty with keyboards, dyslexia etc. - well HR can transcribe what you say for you if it's not affecting the job you're being asked to do.

Maybe the HR section can then make a sanitised recommendation based on the other tangible factors, say, attire worn to interview, visible tattoos, pleasant greeting, whatever it is that you want to look at. And then any statement that needs to be made that is relevant to the job is revealed later: "This person is unable to walk or lift heavy items". "#6 was pleasant, well-dressed (without saying what in), arrived early."

Then this literally isolates you legally in terms of discrimination. There's nothing more you could possibly do. You'd never have a lawsuit again and could provide all kinds of historical data to prove it. Hell, it might even reveal internal prejudices - how many candidates were rejected and were female? How many candidates were rejected but didn't have a degree? Gather that data, analyse it, and it tells you whether people just weren't suited to the job (but just happened to be female) or whether you were subconsciously rejecting perfectly-fitting candidates just because they were female before.

It's this "I'm a better judge of someone face-to-face" nonsense that really kills a company's workforce. I've worked with any number of people who can convince people of anything, but are useless at the job. Because they were interviewed face-to-face and were "our kind" of people.

Think how many prejudices you could weed out almost instantly. From "This guy has a lisp" to "This guy is paraplegic". Who cares? Can he do the job?

LibreOffice community protests at promotion of paid-for editions, board says: 'LibreOffice will always be free software'

Lee D Silver badge

Re: Free Vs Paid

Same, all the time, but sometimes it works out.

We bought a very expensive access control system. It provided only the very barest of reports, in ancient HTML, generated from a Java server-side applet, and they were basically unchangeable.

One of the things we wanted was a firelist - just a list of who is "in" or "out" of the building. It's literally, in coding terms, "what was the last transaction today for each user". Did they last tag out? Or tag in? Or have they not tagged in at all today? That lets you know if someone never came in, if they came in but have definitely left, or if they came in and are still milling around somewhere. All three are important because you often got "Oh, but I've seen X today." - yes, you did, but they've gone since.

Anyway, the software report was useless. It couldn't be triggered at a particular event or time. It had to be accessed with a web browser. It was clunky, took many logins and clicks, and sometimes Java just fell over - oddly if you specified criteria to narrow it down, it used to fall over more often (i.e. "I only care about John"... crash. "Okay, give me EVERYONE." Report comes back just fine).

So I'd been working with the same software at a previous employer and I had written a script. The software was based on a Firebird database (a bit like SQLite - a single flat file is your SQL database, so no install dependencies, etc.). So I just installed a small command line tool to query the database and wrote a script to query everyone's last transaction for that day. Took me about an hour. Ran that software for about 10 years now, over two different employers.

The beauty also is that because you can just make it a "one-file" script, you can make the access control software run it on a particular alert, which you couldn't do with their own reports. So when the fire / lockdown alert is triggered on the system (which would normally open or lock the doors respectively), you can get the software itself to run the script which can print out / email the report automatically. Generally speaking, before we've even got out of the building or - sometimes - before the alarm is even audible in some buildings (there seems to be a slight delay in the fire alarm networking, but I don't touch that) you get an email with everyone's name and what they last did.

Hell, I bought thermal receipt printers and each building gets an automatic printout within seconds. You can literally hear the alarm, RUN for the doors (not that I would recommend that) and on your way out, there'll be a printout ready for you to grab and check off names. (Note that we're not *reliant* on that, but it's a far quicker way to check than manually checking the staff lists that are taken out as part of the fire procedure).

Anyway, did this at one employer. Moved onto the next. Discovered they had the same software (and were serviced by the same friendly engineer! Love that guy). Checked with the employer and implemented the same system again.

Obviously, in those years, people have constantly asked if there's a "supported" method. There is. Pay a fortune to the manufacturer for a "firelist module" for the software, that's not as good, produces a rubbish hard-to-read report, can only print on A4 (you wanna wait for the laser printer to warm up?), is several pages long, etc. etc. Told them to stick it. Free script has worked better for a decade.

The best irony, however, was when my old employer tried to replace the system that I'd left there with the official one. They hated it. Demanded the company change it. A bit of history: I left that employer under such a cloud that I reported them to the authorities (I discovered they were doing illegal things) and many senior managers were forced out of their jobs because of my and other's reports and within a year almost nobody on the staff remained of the original employees and there were a dozen unfair dismissal lawsuits from people like me because they'd basically tried to sack all the dissenters. So they basically tried to scrub everything I'd ever put in place. Anyway...

The access control company were told they needed something better, so they went through all their channels. They told my previous employer that they didn't have an official module but that they could get something working. Something that one of their engineers had seen at a client's place. Said engineer was my friendly engineer. Said client was my new employers. Said system was MY system. That the old workplace literally had before they started changing everything.

I offered to sell them my "supported" version of the same system, for slightly less than the price that the manufacturer would charge for their rubbish firelist module. They then got wind of where it had come from, and sadly didn't take me up on the offer. I was very pleased because I didn't really want anything to do with them, but would have greatly enjoyed having to go back to that place to show them how to put my own system back how it had been when I'd left... at great expense.

Lee D Silver badge

Re: There is a third way

Your argument doesn't address their comment at all.

If you're paying for *support*, who wrote the software doesn't matter. You aren't selling the software. You're selling support.

And that nullifies any LGPL issue. I can sell you support for bash, if I want. Doesn't affect the licence on the code, and I can have literally *nothing* to do with bash whatsoever, or even written a line of code in my life.

That's how everything from Wine (Codeweavers) to Red Hat has always worked. You provide support for another's product and/or for your own product that you give away for free, including the source. Same model for the GLPI helpdesk product, Asterisk, all kinds.

"Here's our paid-for commercial version. We will answer the phone if you buy this, and help you get it running, installed or repaired. By the way, the software is basically just this open-source product which you can download and do what you want with, but you're on your own if you do."

Unfortunately, the very next step is always "And here's a plugin infrastructure, and we now offer a closed-source plugin that only comes with our commercial version. There's nothing stopping you writing an open-source one, because the code for the plugin infrastructure is in both versions. But we aren't giving you the source to own in-house closed-source plugin. Good luck!".

Lee D Silver badge

I don't mind them making money.

I don't mind them selling the product.

But don't mess with the description of the software, pretend it's anything other than an open-source project, or have plans like this behind the scenes without including the community.

I would now literally prefer someone to fork it with another name that does nothing more than take LibreOffice, remove the names and junk like this, and then put it on another website. All because you tried to hide it.

The irony: I have in the past, and would again, pay you money for LibreOffice. I would support fundraisers. I'd pay for a "LibreOffice CD" or whatever. I'd donate just to keep you guys open.

But you already have a strategy that doesn't include things like that.

You decided already.

So I've decided. If that junk is in the next version I download, I go looking for an alternate or stay on the previous version.

I use a ton of OS projects with viable commercial offerings of the same code on the same website by the same company with the same name. Just do that. Don't try and make one software look "worse" to make yours look better when that software is actually "ours"... because I have the source on my hard drive.

£40m wasna enough for ink and toner cartridges in public sector, says Scottish government

Lee D Silver badge

Re: So why do people print stuff out still?

You find an answer to that, you let me know.

I just had to tell a school teaching department that they are using three times the printing of the next nearest department.

They were wondering why they don't have a budget. Because of covid, etc., the budget for the entire subject is now literally less than their printing budget on its own.

Bonus: It's not even Art or English or something that you might expect to do a lot of printing.

Modern 2020 school, with huge fees, complete remote operation for the last few months, and yet we're paying thousands upon thousands for printing, and churning through dozens of trees.

In one of my previous schools, there was one printer. That was it. Everything went to the one printer. And because you had to walk to the printer to pick things up, and large jobs tied up the printer, nobody ever used it or needed to use it.

Three UK: We're sending you this SMS to warn you not to pay attention to unsolicited texts

Lee D Silver badge

Re: Typical

Most of them won't address you by name or even include the account number in the email now. Just in case an email goes astray to the wrong address and they get done under GDPR, one assumes.

My Amazon Mastercard is like that. The emails are non-descript and, rightly, just ask you to log into your account to view your statement.

Lee D Silver badge

Re: Can you explain...

I got this too... see my post below.

Lee D Silver badge

Couple of weeks ago I got a text to an unpublished number - literally the first outside text ever received on it.

It was from Three saying that "MyThree" account was ready and I needed to click the link.

Strange, because I'm not with Three.

That was followed, ten minutes later, by a text thanking me for activating my MyThree account.

I contacted Three, and my real provider - Smarty. Now, Smarty uses Three networks but even they said I was right to ask as Three should never send me any messages and I wouldn't be able to use MyThree with their numbers anyway. Three were quite dismissive, but they did ask for a screenshot. They said it looked scammy.

But, to the casual user, you would have got an SMS from "Three" (no number or other details available because who the hell needs that, right?) that looked like someone was in your account or that you needed to do something. And if you were on a Three-partnered network, that could well have been something you thought you needed to click on.

But at no point did they bother to look at my account (both companies acted only on screenshots/what I told them) to try to determine the source of this text and/or stop someone sending a text claiming to be Three to their customers.

At that point, I just think that it's partly their fault. There's no way for a half-intelligent user to know that the SMS wasn't genuine. Now they shouldn't click links, but the links went via a Three redirector, from what I can see, and looked like links to three.co.uk (I'm not going to click them to find out, but everything "looks" genuine). And they take no efforts to stop such anonymous texts being sent to their customers. They just took a screenshot off me, said "We didn't send that" and told me not to click it.

I wouldn't mind but I've had that number for several months now (it's the data contract on a dual-SIM phone with my real number, so it never gets used except for data) - and that was the first ever text received in all those months.

Something's going on at Three - and they're not doing very much about fixing it.

Euro police forces infiltrated encrypted phone biz – and now 'criminal' EncroChat users are being rounded up

Lee D Silver badge

Re: Use offline encryption/decryption

We have encryption with perfect forward secrecy (so even the encrypted text and the stolen-afterwards private key does not reveal what the message contained).

Any criminal who's just paying a French company for a "secure phone", the same as his mate's "secure phone" is the low-hanging fruit of those who are communicating secretly and don't wish the police to know about it.

Lee D Silver badge

And they can get that metadata by just watching you and him for an afternoon and see if you're both on the phone at the same time.

You can't stop the metadata, but you can't convict on its basis alone.

I have a friend who's close to all the local villains in his area. Does phoning him mean I'm planning something? No, I'm phoning the guy who used to live next to my parents when I was a kid and we were good friends with.

If the metadata is convictable, they don't care about the encryption at all. If it's not, then they need the encrypted data. Either way, you've lost/won just the same.

And, sorry, but no court in the land will convict you *solely* on the basis of being in communication with even the head of the local mafia. The guy could have murdered someone, and then phoned me for a chat, it doesn't mean anything and isn't convictable without a body of evidence that I was actually involved and not just used as an unwitting alibi.

Lee D Silver badge

Re: But private ciphers also exist...even if end-to-end encryption is broken.......

This is what annoys me.

With any half-decent modern encryption, you can publish the cipher text full-page in the Daily Mail for all you care. Nobody should be able to read it. And nobody should be able to "encrypt" anything and claim to be the other side without access to the private key (and, if you have a brain, passphrase too).

Using tech like this would just make me flag you up instantly as someone to watch, if I was doing their job. But you could just send a bog-standard email with a PGP encrypted section on the bottom and exchange public keys with people and it would be basically impossible to crack. Any "compromised" user... just doesn't give up their passphrase.

And with things like perfect-forward secrecy, you can even get schemes where complete compromise of the key does not reveal historically encrypted messages.

The metadata is always present anyway. But without the message it's nothing more than coincidence, and proving that in court is hard to do.

Somewhere there are bunches of mafiosa just encrypting their stuff offline with a basic AES tool, merging the data into an image, and then attaching them to an email or hiding them in DNS lookups or whatever (hey, DNS lookup of an unpublished sub-domain, using DNSSEC/DNS-o-HTTP... that seems pretty secure to me to hold a message inside - and if you didn't know the sub-domain to query, I don't think nameservers will give them up... and if it's encrypted you couldn't snoop them), and are completely off the radar.

Purism's quest against Intel's Management Engine black box CPU now comes in 14 inches

Lee D Silver badge

Re: Assertions that ME is a backdoor

Irony: Some idiot will buy one of these and then slap an antivirus program on it.

Never knowingly under-digitally transformed: Retailer John Lewis outsources tech function to Wipro

Lee D Silver badge

Re: Won't be shopping in John Lewis any more...

"I'm going to pay a middle-man to employ the same staff I used to employ, pay the same tax and pensions as I would have to, to provide the same service, but subject to *their* service levels (i.e. 5pm, we're done mate), when they have dozens of other customers, then add on 20% for their profit margins, who after a year will get rid of all the expensive staff and replace them with minimum wage drones."

Sorry, but outsourcing never made any sense to me at all, unless you're the outsourcing company and getting 20% for doing a job that someone else could have done for themselves anyway.

It's like a homeowner paying a guy to put out their bins. More money than sense.

Lee D Silver badge

Re: That will be 244 people looking for a job very soon

High street is dead.

Just look at the news, another shop-chain going bankrupt, even far before covid, etc.

My town's offering are now pathetic (they were carbon-copies of every other town), Intu is dead so all the big ones are disappearing.

My old street had no less than 4 bookies and 5 pharmacies on it. For a road about half a mile long. The rest were charity shops (basically to fill otherwise-empty shops?), delivery takeaways (by definition can operate from anywhere), and things like estate agents (do people still use those?). Oh, and one cafe that was never open when I go past it but looked to still be in business.

High street was wounded a long time ago by online shopping, hasn't recovered, won't recover and is just in its death-throes. Covid might well be the straw that broke the camels back.

And I can't say I'll miss what it's turned into. I'd much rather all those places were converted to houses and we just spent money online.

Sorry, but I want 24-hour opening, even on a Sunday, or online delivery. It's 2020. I also want to be able to fecking park somewhere near things. That's almost impossible now.

Cafes, restaurants - maybe slightly more desirable - but you can just group them together in one place.

I foresee out-of-town retail parks, with bowling or whatever (cinema will die?), huge supermarkets and a food court, and 10,000 parking spaces. And that's it. Everything in town will just be houses.

One map to rule them all: UK's Ordnance Survey rolls out its Data Hub and the juicy API goodness that lies therein

Lee D Silver badge

Re: Could this become the official UK postcode and address database?

I'd really rather myself (or my courier/parcel) be "lost" within a few hundred metres of my destination because we confused some similar-sounding words than quite literally be unable to determine where on the planet it should have gone without any accuracy at all.

Close verbal matches isn't the problem (you just eliminate "bat" and don't include it or any rhyming word in the system). It's that there's no *order*. "band" and "banana" should be close together, but sound completely unique.

And as soon as we get into such things, then grid references make far more sense for all purposes.

To be honest, you can pretty much text anyone a GPS lat/lon now and they can usually click on it and load it in Google Maps, or a satnav app. Why we needed an extraneous system to "simplify" that in three out of 40,000 possible words (to cover the ocean), each of which is 5+ characters long, I can't fathom.

It's like domain names and IPs. Nobody needs to type in a domain themselves nowadays, or use an IP address. You just send each other a contact detail with the info and let the computers do the work for you. That's kind of their purpose.

Introducing non-ubiquitous, app-requiring, proprietary formats of any kind to add to that confusion is just silly.

Have literally never sent, received, needed or even seen a real-world use of W3W. But I can text my dad a lat/lon and my GPS tracker sends me a Google Maps link with the same info (even inside a .kml if it's live-tracing), and all my favourites on my satnav are shared to the cloud, and all my contacts on my phone have their address so I can just navigate to them if necessary.

It's yet-another-service that the people you want to have it just won't have.

Lee D Silver badge

Re: Could this become the official UK postcode and address database?

So now you have two standards.

Three if you count GPS (accurate to within 1m for most phones nowadays).

Four if you include OS map co-ordinate (way good enough for mail delivery).

XKCD will tell you the next step:

https://xkcd.com/927/

Lee D Silver badge

Re: Could this become the official UK postcode and address database?

My problem with W3W is that even if you remember the three words but put them in the wrong order, you end up on the other side of the planet if you're lucky.

And if you mis-remember the words, you end up somewhere entirely random.

At least with a postcode if you misremember (or the equipment misreads) "W1" as "W2", it stands a chance of still being delivered. With W3W it could be sent ANYWHERE in the country (if you're lucky).

W3W was a great idea but mixing up the words used for adjacent locations, essentially at random, was a stupid idea. "cat egg banana" should be somewhere near "cat egg band" and maybe even "bat egg banana".

One does not simply repurpose an entire internet constellation for sat-nav, but UK might have a go anyway

Lee D Silver badge

Re: Look, they couldn't even cobble together a...

If you mess up a government project, they pay you more to carry on fixing it.

If you keep messing it up, nobody else will touch it so you have a guaranteed income for life.

It's really just a case of following the money. Capita, Serco, etc. - all those places that supply such services operate on the same basis. Get the contract. Throw something out. Spin it down the road long enough that they have moved over and can't abandon it, then provide "fixes" for just slightly cheaper than it would cost to throw the whole thing out and start again. Guaranteed income for decades.

Government Gateway, HMRC, DVLA, Universal benefits, the NHS, schools, all kinds - all in the same trap. And all kept there because certain government ministers can't write a get-out-clause in a contract, especially when they part-own the company in question.

HS2 heading the same way. The NHS app.

If you write something and it actually works, and is good, clean, transportable code, then they could go to ANYONE next year. Write a piece of junk and jam it in quick enough and you have a company income guaranteed for years to come.

Lee D Silver badge

Re: "quantum compass technology"

"The argument for a positioning system, particularly for splashing big sums of cash on it, usually relies also on the civilian navigation aspects, for which we only need UK coverage."

And there are four/five independent, open, free, existing and around-in-the-future system which cover the entire world to that purpose. That's *not* why people keep putting up their own.

And Switzerland literally paid for access to Galileo despite not being in the EU. They just paid, not very much in the grand scheme of things, and got the same as EU members. We refuse to. (And Switzerland helped build it, just like we did!).

It's nothing to do with civilian navigation. All the networks literally give that away as a natural consequence of the technology. It's to do with the value-added features. Everything from search-and-rescue (your boat beacon literally talking to the satellites to announce its position, and receiving notification of help being on the way, which "civilian GPS " cannot do), military, greater accuracy (1cm), encryption, anti-spoofing, and uses for GPS that extend far beyond mere point location (geodesy).

We literally get the civilian navigation NO MATTER WHAT. It's given away. We get it whether we are in Galileo or not. I literally have it now. That's *not* what the UK is trying to replace. The bit it is trying to replace is the literal reason that people pay GNSS manufacturers for the technology - the only thing of actual commercial/military/government value, the thing that's hard to do and costs a fortune, and the bit you don't want to give your enemies.

And that's what we don't have, haven't bought, won't pay the EU for, and for which we bought a satellite system that literally isn't capable of that at this time (and likely never would be).

This is not about your satnav or crashing your boat into the island you didn't see. That's literally just sitting there for us to use. It's about the things you'd use in times of war (encrypted, unspoofable signals, accurate enough to guide a missile - GPS shuts off above certain speeds/heights deliberately!, encrypted communication of a location back to a country [e.g. special forces requesting a pickup after being off the radar for weeks], etc.).

The exact things we don't have, and have bought a system that doesn't do them.

Lee D Silver badge

Re: "quantum compass technology"

Trident: "is guided using an inertial navigation system combined with a star tracker, and is not dependent on the American-run Global Positioning System (GPS)."

It would be incredibly stupid to tie use of a nuclear deterrent to a couple of vulnerable satellites in publicly-announced orbits.

Lee D Silver badge

Re: "quantum compass technology"

I have a normal, ordinary, Samsung phone that receives US GPS, GLONASS, Beidou and Galileo. Now. Today. 1m accuracy, to be upgraded to 1cm when the Galileo constellation officially "goes live", I believe.

You can buy off-the-shelf chips with all four supported now, for pence.

It's nothing to do with satnav/location finding. It's to do with the extra-added-functionality - military, search-and-rescue, two-way comms, encrypted authenticated GPS that can't be spoofed, etc.

Galileo is free to use for you and I, and our TomTom. It's not that for which we paid millions to put into place, because we already have that. It's the other stuff that we *don't* have without reliance on the US and paying people lots of money.

Lee D Silver badge

Re: Why Galileo?

It's the out-of-the-ordinary usage that's affected.

GPS is available to all - to a certain resolution and on a one-way basis (i.e. you can recieve "your location" but you can't talk back to the satellites).

UNLESS you pay for the military, commercial shipping, aviation, etc. services offered by the same network. Which are more accurate, have other features, etc. etc. etc.

Same for Galileo - I have it here, now, in my phone, receiving my location literally as I speak. That can't / won't go away.

But the commercial element, the highly-accurate, military, etc. services won't be available to us because we signed a deal that said "EU members get these features" and we're no longer an EU member.

P.S. Galileo is not officially in full service but is already providing a better signal than GPS. They've had one outage of any substance. Which is amazing for a GNSS that's not even finished. But there are enough things in orbit, and the free services are already functional, that it's more than good enough for your satnav or phone to use.

(All GNSS are the same - I don't pay the Chinese a penny, but I have Beidou. Or the Russians, but I have GLONASS. What I don't have are things like the emergency, military, etc. systems which I would have to pay for).

It's nothing to do with "satnav". That's literally a freebie that everyone in the world gets thrown in. It's all those other extra-added-value services that we're locked out of and don't want to pay the EU again for (which is kinda right... we did pay to put most of them in... we just need better contract drafting lawyers!).

LibreOffice slips out another 7.0 beta: Spreadsheets close gap with Excel while macOS users treated to new icons

Lee D Silver badge

Re: Any news of a Libre_mail client

I would like to know too.

I'm still running Opera 8 (?) purely to collect and sort email (I moved on to other things for my browser, and the "new" Operas have basically abandoned mail functionality.

Massive SQLite database underneath it with 20 years worth of email over a dozen accounts, searchable in a trice.

Tried everything - even Pegasus Mail at one point. Can't find anything that I can get on with or that is as fast when searching that amount of email. An LO alternative to Outlook would be great.

'It's really hard to find maintainers...' Linus Torvalds ponders the future of Linux

Lee D Silver badge

Re: I wonder why?

No problem.

You be nice to everyone and then take responsibility for when your sign-off appears on a 0-day, root-level compromise of the entire world's back-end systems.

Or when it BUG()s in the middle of a driver code because the driver author was too lazy to use the proper path to print debug information (hint: BUG instantly crashes the kernel, with no hope of recovery - no production driver should EVER contain the macro BUG for anything). Which was literally one of those patches commented as such. Yes, that one-line debug script would literally instantly stop millions of machines at a random time if it had hit mainstream deployment, which means data loss on an epic scale, not to mention loss of service.

Sorry, but if you can't handle criticism of such idiocy - however delivered - when you're in charge of even a small part of the world's most widely-deployed and widest-scope OS, then that's the least of your problems.

Especially when - in every case listed - such stupendously ridiculous code was pushed through several levels of review and maintainers and ended up nearly being pulled into the kernel before it was noticed how ridiculous some of it was (e.g. including their untested code in every single kernel config by default because they didn't know how to make a patch, and nobody bothered to check, etc.)

Apple said to be removing charger, headphones from upcoming iPhone 12 series

Lee D Silver badge

Re: Low-voltage DC is just USB now

There's a reason for that - 24W is barely enough to turn those kinds of things on, let alone operate-and-charge at the same time. Even my old laptop would fail to charge on certain 19v chargers - it would accept them, but if you did anything vaguely interesting, the battery charge would fall WHILE it was running on mains... you just need more oomph.

Now, granted, it should warn about that scenario, but there's no way on earth you're ever going to power a laptop in any fashion from an ordinary 500ma/1A/2A USB cable. The voltage is only 5v, for a start, which is not enough to charge a 17/18v battery at all, no matter the current - the physics just isn't there. There's a reason we have 19v chargers and why USB-C's high-power mode is 20v. You'd actually be better off with a PoE charger... at least that can hit 47v!

Phones generally only have a 3.7v or thereabouts battery. That's why they can trickle-charge from just about anything. Hell, you could arrange three AA's and it would charge.

Without voltage transformers (which cause even more loss of power), there's no way "ordinary" USB can charge something like a laptop, especially not if it's running at the same time.

You need the "full" charger, as you say, which is one that provides the 20v negotiation. Not all chargers, cables or devices are capable of utilising it - it was a much later standard and required complete hardware redesign and extra chippery to manage it.

Lee D Silver badge

Re: Low-voltage DC is just USB now

USB-C can deliver 100W.

A lot of modern gaming laptops use USB-C as their only power source.

More than enough for a LCD TV and most other things you mention. USB shavers and toothbrushes already exist. My clock radio actually is a USB charger too. Lights, especially LED lights, are way within USB range.

Lee D Silver badge

I bought a new phone recently and one of the reasons for that was that I'm moving everything from microUSB to USB-C.

So far I have two battery packs (including torch) with both USB-C and microUSB charging, and a USB and USB-C output, a USB-C phone, adaptors from USB->USB-C and vice versa, a USB-C -> HDMI/VGA/Ethernet/Audio/4xUSB/SDcard adaptor, a USB-C fast charger (20V) and more.

The bits have cost me about £30 in total. And provide back and forward compatibility for my old and new devices.

I don't keep Lightning connectors - who the hell uses some mysterious third-party junk that adds nothing? But I have a small bag, about the size of a school exercise book, which has adaptors and cables for just about everything that goes with me if I go on holiday or visit friends. People are always asking for a cable and I can cobble them together almost anything (Sorry, it's an Apple? Yeah, you're on your own).

Let's just say that USB is the standard now. Stop faffing about. Low-voltage DC is just USB now. I'm eyeing up a new laptop - all USB-C charging and USB-C ports. Chromebooks, same.

Less waste, but we also need people to stop being stupid and still bundling "adaptors" rather than just putting a compliant USB-C port on things. That's where the whole Apple thing falls down and they get away with it year after year.

As such, yes, it's good to remove the charger because eventually everyone will have them in their wall-sockets and extension leads anyway. Eventually they'll all be the auto-negotiating 20V fast-charge things too. But let's not pretend that Apple are doing this out of the love of the environment - it'll save them money, and they'll make more back in Lightning patents.

I'm not changing anything again until USB-C is literally obsolete and there are serious advantages to moving to USB-Whatever. Judging by standard USB/microUSB, that's - what... 10-20 years away?

Someone must be bricking it: UK govt website for first-time home buyers snapped up for £40,000 after left to expire

Lee D Silver badge

Re: How is this STILL a thing!?

You mean like repeated emails to the postmaster address, a grace period during which only the owner can renew it even if it goes offline, and an appeal process?

This only happens when people are not just incompetent but government-department-incompetent - signing up with an employee email who leaves, or literally never checking the postmaster mailbox, and not having anything as simple as a calendar entry which would warn the appropriate technical staff.

Don't forget - someone, somewhere is running a server with that content on. Was that still being paid for? Was it hosted in-house? Or was it terminated as part of the same contract as the domain? Who was responsible for it? Who was maintaining it? Who was updating it? Which datacentre did it reside on? Why did they not notice when the domain went into a grace period? Nothing even as simple as one of those free "is your website still working today" automated tests? Were they still paying for it on the server end?

Sorry, but if this happens to you, then you necessarily should not be running Internet-facing servers, especially for government services. It's a symptom of a complete lack of maintenance and interest.

And, more importantly, who authorised the .org.uk in the first place when they could have had a .gov.uk that could not possibly expire? Why was it anything but a redirect for all those years? Why did the *real* gov.uk site not get anywhere near as many links as the original .org.uk for all those years?

It goes far beyond "we need a way for people running small businesses to renew their domain at the scheduled time", and no scenario like that would fix it.

Macs, iPhones, iPads to get encrypted DNS – how'd you like them Apples?

Lee D Silver badge

Re: Idiot-tax ...

"Ancient recycled old rubbish soon loses its comedy value and..."

sells for 3-4 times the price of other kit just because it has an Apple logo on it.

It's hard to write good copy, especially in keeping with your target audience. Do you read every article? No, but someone has to write every one and if the article just said "Apple will enable encrypted DNS", you'd quickly get bored and go elsewhere.

There are thousands of IT news sites out there. I like a little informality. I don't really care about cliche, it doesn't hurt or hinder me. If you're here for original comedy with every article, I really think you've chosen the wrong kind of site.

And I use the words idiot-tax for all kinds of things - parking tickets, speeding tickets, designer gear, etc. etc.

We're no longer helping UK Post Office persecute postal workers with our shonky system, says Fujitsu

Lee D Silver badge

Nowhere near the same scale but my ex used to manage a branch of The Works.

One day they accused her of fiddling the petty cash. They sacked her.

She couldn't afford to fight it with professionals, so she took them to court herself. And won. They had absolutely no evidence that anything was wrong with the petty cash at all. They lost badly in court, despite having fancy lawyers, to an amateur English graduate who managed a cheap bookstore. Purely because their own systems showed no error on her part and no potential for any money to have gone missing, but obviously something/someone ballsed up somewhere.

The ex enjoyed screwing them to the wall so much that she took a law degree and then a barrister qualification.

Apple gives Boot Camp the boot, banishes native Windows support from Arm-compatible Macs

Lee D Silver badge

Told ya so

Had arguments about this all over the web.

Windows for ARM is no more Windows than Windows RT, Windows for DEC Alpha, Windows CE or any other version. "Windows" means "x86 Windows" to most people who want to use it so desperately that they'll set up something like bootcamp.

And as soon as you're running x86 on ARM, it's no longer virtualisation (with small overhead), it's emulation (with huge overhead and crap performance).

Lee D Silver badge

Terminal Services.

You can rent one in the damn cloud on a pittance-per-hour basis now.

US govt: Julian Assange tried to recruit hacker to steal hush-hush dirt and we should know – the hacker was an informant

Lee D Silver badge

Re: Legal jurisdiction

If you hacked, say, the Playstation network in Japan and exposed millions of credit card numbers...

... would you not expect Japan to file an extradition request so you could stand trial in the jurisdiction the offence was committed, rather than one that has no law, evidence or jurisdiction about you breaking into *Japanese* systems?

This is literally the definition and the necessity of extradition.

And Assange is accused of conspiring (at minimum) to hack into US military systems. Which, in at least once instance, resulted in success for a short time, with Assange being the person who published the articles in question.

Chime after chime: Apple restores iconic Mac boot sound removed in 2016

Lee D Silver badge

Re: Meh, sounds, animated effects, transparency

Yup.

And install Open-Shell (formerly Classic Shell).

But to be honest, I turn off the music as the very first action in every game I ever install.

Oh, and my desktop is a plain blue background.

Email innovator Hey extends an olive branch in standoff with Apple, tweaks code to make the iGiant appier

Lee D Silver badge

Re: A subscription fee for email‽

"All" emails at my domain exist - I don't have to create accounts/aliases.

It doesn't mean that they will go anywhere useful until I authorise them to, however. They get held in limbo/quarantine until I allow that alias to deliver mail onwards to the real inbox.

Catch-all on the domain, mailbox storage on the catch-all, forwarding only for listed aliases.

I literally do <companyname/code/made-up-on-the-fly-names>@mydomain.com and email always gets delivered (I have a 5-minute greylisting on new aliases, so obvious-made-up spam rarely delivers even into the holding mailbox).

The worst I ever have to do is override the greylisting if I'm bored of waiting the 5 minutes that they are asked to wait before retrying delivery.