* Posts by Michael Wojcik

12271 publicly visible posts • joined 21 Dec 2007

Biden projected to be the next US President, Microsoft joins rest of world in telling Trump: It looks like... you're fired

Michael Wojcik Silver badge

Re: Good

I thought that most USians would want potable water, affordable healthcare, infrastructure that's not on the verge of crumbling, affordable education and less war.

You're not very familiar with people, I take it.

We're not rational economic actors. We don't act in our own interest. Political activity in particular is heavily influenced by two non-rational factors: ingrained ideology (which for most people seems to become largely fixed early in adulthood) and psychological traps such as the "backfire effect" and the first-person constraint on doxastic explanation.

The dominant ideologies in the US all incorporate themes, typically coded as "freedom", "opportunity", and "industriousness", which discourage acting in group interest where it would conflict with an idealized aggressive individualism. These themes were advantageous to the landed plutocrats and upper-middle-class entrepreneurs who shaped most of the political discourse and structures of the early US, at the expense of most of the rest of the population. They endure because the elite have a powerful vested interest in keeping them in place.

(It's worth noting, as an aside, that those ideological themes are rarely deployed for anything resembling the categories they supposedly name. It's tough to get most of the US population to defend civil rights, for example, in any meaningful way, even though those rights are critical to freedom, necessary for equitable opportunity, and an important constraint on government for industry.)

Michael Wojcik Silver badge

Re: Not if Republicans run the senate

There's an equivalent to Rule 34 for this: Any political conspiracy theory you can imagine has already been posted on the Internet.

My guess is that a really thorough forensic analysis of all the voting equipment in the US would find a fair number of errors and irregularities, and quite possibly the odd case of tampering, but not enough to change many races, if any at all. US election security is lousy but so far from a monoculture that it's expensive (in terms of money, labor, and other resources) to gain control over any decent-sized portion of it.

Again, I'm just guessing (though I have read some academic studies in this area), but I suspect it wouldn't be enough to flip the Senate.

We'll see what happens with mid-terms, but historically those often go against the president's party. As usual, it will mostly depend on turnout, and turnout is mostly psychological - though Republican efforts to disenfranchise voters have certainly been significant in recent years.

City folk vote to each get $100 every time cops, govt officials illegally spy on them with facial-rec AI, minimum $1,000

Michael Wojcik Silver badge

Re: "(...)we are temporarily suspending driving operations in San Francisco on 11/3 and 11/4”

Any date format other than ISO 8601 is anathema. The US convention is particularly dumb (and I write that despite having grown up with it), but any ambiguous form is foolishness in this era of worldwide communication.

Of course if you don't like ISO 8601 (heretic!) you can always employ a longer, unambiguous style, like "the third and fourth day in the month of November, as commonly reckoned in these United States of America, during the fourth and by grace of the electorate final year of the tumultuous reign of Mad Despot Trump".1 No one will confuse that for 11th March.

1I tried writing that on the date line of a check, but I couldn't make it fit. Then I remember that no one uses checks anymore.2

2I kid. Here in the backward USA we still average half a dozen or so paper checks a month. At least that number has dropped substantially; 15 years ago, maybe even 10, I was still writing enough checks to have a date stamp so I could avoid writing the date over and over.

Michael Wojcik Silver badge

Re: Even a stopped clock tells the right time twice a day

Probably a good number. But that doesn't mean this isn't a viable industrial process. Industrial research generally does require testing a large pool of candidates.

The question is whether this approach:

1. Significantly reduced the number of candidates that might otherwise have been tested.

2. Proposed any novel candidates.

If either of those are true, then it may be cost-effective. From the article it sounds like the company is claiming at least #2.

Frankly, this sounds like a perfectly suitable application for a convolutional-neural-network stack. It's just what CNNs do: you have a desired output signal, and the network finds inputs that produce an output that's reasonably close to that signal. The stack lets you translate that from micro-features to macro ones. And unlike a lot of proposed uses for "deep learning" (i.e. ML systems based on a NN stack, typically with mostly CNN layers) this one feeds into a second round of human evaluation, and the cost of false positives and negatives is low. The same can't be said about, oh, autonomous vehicles or medical diagnoses.

In short,1 this looks like a "sure, why not?" use case for the technology. I'm not looking for a new milk substitute myself, but it's a valid pursuit. Computational gastronomy, basically.

1Too late.

Michael Wojcik Silver badge

It might be paid out of insurance.

But in either case it's still going to hit the police department's budget (directly or in increased insurance premiums), and given the relatively small size of Portland that will bring all sorts of political pressures to bear. It seems to me the point of this ballot initiative is really to send a message: a majority of the citizenry do not want this technology used, and they're prepared to make things quite uncomfortable for any agency that does so.

It's a good precedent, anyway.

Michael Wojcik Silver badge

Re: Even a stopped clock tells the right time twice a day

There are plenty of alternatives for the lactose-intolerant. I myself have occasionally used almond milk (I find the consistency more familiar, because I was raised with 1%-milkfat milk1), and I quite like the occasional coconut-milk alternative for ice cream. There's rice milk, cashew milk, soy milk - quite a few to choose from, at least here in the US.

Occasionally I have real ice cream, along with a hefty dose of lactase, and, yes, it's probably a bit better than the analogues; it's hard to precisely duplicate the flavor and mouth feel of a high-quality ice cream, or the nostalgia of soft-serve. But particularly for the severely lactose-intolerant2 cheese is the real casualty.

1The usual story: our pediatrician, concerned about a relatively high heart-attack rate in my mother's family, recommended a low-cholesterol diet for me and my siblings. Now evidence shows no strong correlation between dietary cholesterol and serum cholesterol, much less serum LDL or triglycerides, so we know the whole thing was pointless if not counterproductive. But then much of nutrition "science" is anything but, and medical GPs rarely have the time to follow current research (which is why we have groups like Cochrane doing metastudies and creating clinical recommendations...).

2I can tolerate cheese, at least enough so that I haven't had to give it up. I'd miss cheese a lot more than milk or cream.

Michael Wojcik Silver badge

Re: Even a stopped clock tells the right time twice a day

Then we'll have the usual health freaks giving it to their babies ignoring the evolutionary reason why milk has so many calories.

Is this actually a problem? Milk alternatives have been available for decades (the article notes those based on soy and nuts).

There's the infamous (and ongoing) Nestlé infant-formula scandal, but that's quite different from your claim; it's about formula being aggressively marketed to poor and undereducated populations, not relatively healthy nutrition-tourists jumping on the latest bandwagon.

Network driver issue shaves 12 more hours off Microsoft's '365' infrastructure, and yeah, it was Exchange Online again

Michael Wojcik Silver badge

Actually, this is just the sort of thing I'd like to hear at fireworks parties.

No, I'm not any fun either.

GitHub's new security scanner definitely works, says Jenkins: It found 7 flaws in our plugins

Michael Wojcik Silver badge

Finding flaws in Jenkins plugins is like dynamiting fish in a barrel

Anyone who follows the Jenkins vulnerability announcements knows the Jenkins plugin ecosystem is toxic and ridden with vulnerabilities - many of which remain unfixed long after publication. It's as toxic as other well-known sewers such as NPM and the WordPress plugin collection. You could probably find seven vulnerabilities by printing out a bunch of Jenkins-plugin source at random, pasting it up on a wall, and throwing darts at it.

That said, CodeQL is a good addition to the security tools available to GitHub contributors (though there are plenty of static-analysis tools which people could already be making use of, and very few do). And its approach is different enough from classic static analyzers, and other vulnerability-identification tools such as dynamic analyzers and fuzzers, to provide a different tack on the problem; that helps both with finding different sorts of vulnerabilities and with reducing the fatigue of going through large result sets with a lot of duplicate information.

Now that's a Finnish-ing move: Finland offers free 90-day tryout of Helsinki tech scene with childcare thrown in

Michael Wojcik Silver badge

Re: Finnish Them Off!

Pff. That's not "really cold". According to the climate info in Wikipedia, Helsinki compares favorably with Lansing, Michigan, which I rate as "moderately cold" in the winter. Lansing's generally more comfortable in the winter than some other places I've lived, including Boston, Massachusetts and Lincoln, Nebraska. (And winter nighttime lows here at the Mountain Fastness fall pretty damn low too, though the extremely low humidity means that you lose heat significantly slower, so you don't feel it as much. It might be -25 C but it feels like maybe -5.)

Forget that cold record (which doesn't seem to be in the Wikipedia table, but whatever) and look at the normal lows. They're very reasonable.

Personally, if I were single, I'd be very tempted to give this a try.

The car you buy in 2025 will include a terabyte of storage. Robo-taxis might need 11TB

Michael Wojcik Silver badge

Good luck with that

Thanks!

I don't know about where you live, friend, but here in the US there are a variety of older cars for sale. We call them "used cars".1

I'm already assuming I'll never buy another new car for myself, since they all seem to come with fucking touchscreens now. I hate touchscreens, and having one (for controls the driver might want to use) in an automobile is the height of stupidity.

1Some people refer to some of them as "pre-owned". Those people should of course be forbidden from speaking or writing until they learn to avoid moronic, unnecessary neologisms.

California backs Proposition 22: Great news for Uber, Lyft as their drivers can work as indie contractors

Michael Wojcik Silver badge

Yes, no one has ever worked for two employers simultaneously. We have no idea how that might work. It's inconceivable.

Michael Wojcik Silver badge

Re: It's always better to exploit others than being exploited

It's almost as if people aren't rational economic actors who always make optimal choices based on the information available to them.

Michael Wojcik Silver badge

Re: Tech douche bros rule!

Not a single driver that I personally asked (in excess of 40) wanted me to vote no. The vast majority of the actual workers

The latter claim may be true, but with over half a million Uber and Lyft drivers in California, N=40 is not a statistically significant sample. Particularly not when your sampling method is probably biased by your location, etc.

Personally, I don't find "the drivers are against it" to be a particularly compelling argument anyway. The whole point of the social contract is finding a balance between what an individual wants and what's best for society at large.

In any event, this hasn't made me any more inclined to use gig-economy services.

Feds throw book at eBay execs who deny they had anything to do with cyberstalking of site's critics

Michael Wojcik Silver badge

Yeah, I was quite surprised that high-level execs were physically involved in this, and not just giving orders. They (allegedly) drove to the victims' home? After flying across the country, since presumably they're based at eBay's HQ in California. (And like most of the Boston Metro area, Natick1,2 isn't exactly fun to drive around.)

This whole thing just gets more and more bizarre as the details come out.

1At first I misremembered and thought the victims lived in Nahant, which is more pleasant to drive around, but more tiresome to get to in the first place. Nice beaches, though, by Massachusetts standards.

2For driving around Natick, I recommend listening to "Driving on 9"3 by Ed's Redeeming Qualities. Listening to the cover by the Breeders is also permitted.

3There's some debate about whether "9" refers to Massachusetts Route 9 or the one in California, but the song was released the same year that the band moved from Boston to San Francisco, which suggests to me that it was written before the move. In any case it works for either.

If you're an update laggard, buck up: Chrome zero-days are being exploited in the wild

Michael Wojcik Silver badge

Re: Google Responsibly

Sigh.

The github issue was disclosed to them 104 days ago: 90 days plus the 14-day grace period. That's how responsible disclosure policies work.

github themselves disclosed technical details about the Github Actions vulnerabilities.

Google have disclosed the Chrome issue discussed in the article. They just haven't released technical details.

Are these details really that hard to understand?

Was that November's Patch Tuesday? Already? Oh, no, it's just Adobe issuing 14 emergency security fixes

Michael Wojcik Silver badge

Re: Acrobat.

People go on and on about "Acrobat" (be honest people, it's just PDF)

PDF != Acrobat. It's entirely possible to have a PDF renderer which doesn't support scripting and much other Acrobat idiocy.

I'm not a huge fan of PDF; for the vast majority of documents I'd prefer HTML1, or Markdown2, or plain UTF-8 text.

But there's a place for proper typographic layout. Book-length works, and even many shorter articles, are far more pleasant to read when they're laid out well. HTML+CSS simply can't do that. It can't do proper ligatures or kerning or digits with descenders or micro-protrusions or any of the other things you'll get with, say, pdflatex output.3 And for those applications, PDF remains the best choice. None of the other widely-available formats really handle that properly.

1Real HTML: POSH, cleanly formatted, with minimal CSS, and no scripting. Minimal scripting which degrades gracefully if it's disabled is acceptable for web pages.

2I generally find Markdown unnecessary, but if for some reason people feel compelled to have some markup and formatting in documents that would work just fine as plain text, it's safer and more readable in source than HTML.

3Yes, in principle, you can get some of those things with CSS and fonts, if you can find suitable high-quality fonts and you go through a lot of trouble. But anyone who lets the browser download arbitrary fonts from arbitrary sources ... well, you might as well use Acrobat.

GitHub warns devs face ban if they fork DMCA'd YouTube download tool... while hinting how to beat the RIAA

Michael Wojcik Silver badge

music tracks, such as Taylor Swift's Shake It Off, which irked the RIAA

To be fair, "Shake it Off" irked me too.

Windows Server robocopy to gain auto-compression ahead of big file moves

Michael Wojcik Silver badge

the future of what now?

SMB over QUIC is the future of distributed systems

Good god, I hope not. SMB is a horrible, horrible protocol, and QUIC is only slightly better than the typical "let's reinvent TCP using UDP" attempt.

QUIC solves certain problems, true; that's because it's optimized for different use cases than TCP is. That doesn't mean everything should be switched from TCP to QUIC. And it especially doesn't mean that we should prolong the life of dreadful rubbish like SMB by promoting QUIC as a transport for it.

And, of course, the vast majority of distributed systems don't use SMB, because they're not interested in anything SMB does. Remote filesystems are a niche application, statistically, when the whole of IT is considered.

Remember when the keyboard was the computer? You can now relive those heady days with the Raspberry Pi 400

Michael Wojcik Silver badge

Re: there's no travel on it

How did the sage Strongbad put it? "Your computer has too much television and not enough typewriter!"

X.Org is now pretty much an ex-org: Maintainer declares the open-source windowing system largely abandoned

Michael Wojcik Silver badge

Re: Nobody likes X11

I used SunView, NeWS, and Display Postscript. I'll stick with X11, thanks.

Michael Wojcik Silver badge

Re: Then there's running an X session remotely.....

Agreed. I'm not particularly impressed by Wayland and its orientation toward local, single-user systems.

I was writing X11 applications at IBM in the late 80s / early 90s: clients, a window manager, graphics libraries (XGKS), and extensions (PEX). I wrote the ddx side for some experimental display hardware. While there were some unfortunate choices in the X11 protocol - specifically, it would have been nice if clients could specify strict or relaxed rendering of wide lines and other primitives to make better use of acceleration - X11 was a rather brilliant piece of work.

VNC is just network framebuffers. It's the sort of remote-display technology an undergrad would come up with. It has its uses, but comparing VNC to X11 is like comparing a pedal car to a Ferrari.

I've never looked at RDP closely, but apparently it's based on the ITU's T.120 family of specifications, and those are just as elegant as you'd expect.

Oh, the humanity! Microsoft congratulates itself for Teams inflicted on 115m daily users

Michael Wojcik Silver badge

Re: collaboration platform

To be fair, it also eats a grotesque amount of CPU during conferences.

NSA: We've learned our lesson after foreign spies used one of our crypto backdoors – but we can't say how exactly

Michael Wojcik Silver badge

No one (who knows anything about it) thinks it's "random" at all. "Deterministic Random Bit Generator", the phrase NIST actually uses, is their (unfortunate) term for cryptographically-strong PRNG.

Everyone always knew Dual_EC_DRBG was a CPRNG, which meant it deterministically generated a bit stream with statistical properties that were indistinguishable from random under a series of assumptions. The concerns around Dual_EC_DRBG were, first, there's no way to tell whether there's a backdoor (i.e. whether the default constants provided by the NSA via NIST1 were chosen to allow someone with an additional piece of information to predict the output2); and second, it's a rubbish algorithm anyway and so there's no good reason to use it.

Ever. Even if you don't think there's a back door. And if there isn't a back door, why recommend it in the first place? Probably just an honest mistake.

1It's worth noting that these constants can be changed, and in fact NIST tells you how to compute a suitable set of alternatives and use them in the DRBG. Of course doing so invalidates any backdoor, and the backdoor is the only reason to use Dual_EC_DRBG.

2Specifically, SP800-90 specifies the form of the DRBG and provides parameters P, the curve's generator, and Q, both points on the curve. It's not explained where Q comes from. It's a prime curve, so there's some e such that Qe=P (mod p). Given Q, e is hard to find. But say you're proposing an EC-based DRBG, and instead of picking a random point Q, you set Q to be a multiple of P. Then you can easily compute e. And you can recover the internal state of a Dual_EC_DRBG instance by observing about 32 bytes of output. That is a Bad Thing.

Michael Wojcik Silver badge

Re: This "backdoors" discussion misses an important point......

Sigh.

The problem is not whether a handful of technically-adept parties who already have a secure channel for key distribution can maintain confidentiality, or even confidentiality + integrity + authentication (and, hey, throw in non-repudiation if it makes you happy). That's always been possible.

The problem is government interference with attempts to address the actual difficult questions, like mass cryptography for non-technical parties, key distribution among large groups with no prior secure channel, authentication where there's no existing relationship, and so on.

Your amateur cryptography is not interesting in this context. It's the equivalent of a pen-and-paper cipher. It might be weak, it might be strong; but it doesn't touch on any interesting problems.

One of the world's most prominent distributed ledger projects has been pushed back by a year

Michael Wojcik Silver badge

Re: Security by obscurity?

The main problem with security by obscurity is Kerckhoff's Principle: The information you're trying to keep hidden is in effect part of the secret key, and it's a part that 1) has lower information entropy than key material should have, and 2) can't be managed easily, because it's not pure key material. So it's inefficient security at best. Its contribution to security and resistance to attack can't be easily or accurately measured, and there's no recovery from compromise.

In any case, it's not so much the hardware platform as the OS that matters. The only currently maintained OS for Itanium I'm aware of offhand is HP-UX; I don't know if Linux or FreeBSD are still supported (and OpenVMS?). Because HP-UX is obscure relative to the market leaders there's less total reward for exploiting it, and it has an overall smaller attack surface; the same would be true of other non-Linux alternatives.

But I wouldn't even bother mentioning that, if I were in charge of security for these systems. It might reduce exposure to broad attacks - the typical portscanning script-kiddie stuff - but it won't help with targeted ones.

Palo Alto Networks threatens to sue security startup for comparison review, says it breaks software EULA

Michael Wojcik Silver badge

Re: Is that Barbara Streisand I hear in the background?

Perhaps it will distract people from their awesome parade of vulnerabilities.

Work life balance? We've heard of it. Pandemic means 9-5 shifts are a thing of the past for many

Michael Wojcik Silver badge

Re: They try to flog us donkeys 24/7

Some of us organize our lives on some principle other than financial compensation.

I work when I want, as much as I want. I happen to be well-compensated for it, and that's useful for the other things I do. But I don't feel the need to extract some fixed amount of money for every second I spend improving my employer's position. What a sad mental state that would be.

Of course, most of my work involves thinking about things. It would be tiresome to try to keep track of that.

Hey Reg readers, Happy Spreadsheet day! Because there ain't no party like an Excel party

Michael Wojcik Silver badge

Re: Grammar, please!

The subject of the verb is "none" ("of them" is a prepositional phrase acting as an adjective modifying "none"). Grammatically, "none" has long been either singular or plural depending on the whim of the writer - there's no conventionally dominant number for none in English usage.

And, of course, all of the comments claiming that either a singular or plural verb is "correct" here are prescriptive, and prescriptivist comments on English usage are false pedantry.

In short: none of you is correct, and none of you are correct. Either is acceptable.

LibreOffice rains on OpenOffice's 20th anniversary parade, tells rival project to 'do the right thing' and die

Michael Wojcik Silver badge

Re: Open Letter

I've decided to fork TDF's letter and replace the entire text with "At TDF, we're a bunch of wankers who have decided we know what's best for everyone and will now graciously share that wisdom with the world."

Your web browser running remotely in Cloudflare's cloud. That's it. That's the story

Michael Wojcik Silver badge

Re: 'Sends HTML5...

No, it converts the output of the layout engine into a serialized display list for the renderer, and sends that over the network.

Whether that's a good idea is a separate question (I'm not a fan), and as discussed above it's hardly a new idea, but it is considerably different from sending HTML.

Michael Wojcik Silver badge

Re: 1970s Called

drawing primitives that are then rendered locally is more X-terminal than VT terminal

The 3270 Model 3279 had GDDM support for host graphics rendered locally in 1979. It supported GKS and PHIGS. Then in 1985 IBM came out with the PC-3270/G, which similarly supported GDDM.

If memory serves, the earliest X terminals came out in 1988, with X11R3.

Of course, there are various differences between GDDM and X, such as the latter's openness and availability from multiple sources. In many ways these "hosted browsers" are more similar to X terminals than they are to the 3270 graphics terminals.

And then there were Sun NeWS and Adobe Display Postscript (both based on Postscript but developed independently). Wikipedia gives 1986 for NeWS and 1987 for DPS.

I assume there were other "graphics terminal" protocols in the late '70s and '80s, though none are coming to mind right now.

Oracle starts to lose patience with Solaris holdouts

Michael Wojcik Silver badge

Re: A warning!

No.

First, it's "Micro Focus". Two words.

Novell bought SUSE (2003). The Attachmate Group bought Novell (2011). TAG merged with Micro Focus, with the latter retaining control of the combined entity (2014). Micro Focus spun SUSE off last year.

UK govt advert encouraging re-skilling for cyber jobs implodes spectacularly

Michael Wojcik Silver badge

Re: You missed off...

Yes, Wiener coined "cybernetic" to refer to any self-regulating mechanism.1

Then Clynes and Kline co-opted it for their daft "cyborg" portmanteau, which doesn't even make sense, since all organisms are already self-regulating to some extent. Why they thought "cybernetic" meant "biomechanical" I do not know.

In their article they begin by referring to the "cybernetic aspects" of biological homeostasis, which is fine; but then they coin cyborg to mean "the exogenously extended organizational complex functioning as an integrated homeostatic system functioning unconsciously". Now, I admit the latter phrase is a bit of a mouthful (though I am tempted to drop it into conversation whenever possible2), but surely the "homeostatic" part is not the innovative aspect vis-a-vis the extant a priori organism, as C&K might put it. (Their piece is well worth reading just for the prose, which leaps beyond "turgid" to some new realm of awesomely over-written.)

Anyhoo, Clynes and Kline started the rot in "cybernetic" in 1960 with their "cyborg", which then became popularized by Halacy, Kaidin, and others. Donna Haraway3 introduced it to critical-theory circles in 1985, which then trickled down to middlebrow venues. Meanwhile there was some use of "cyber" and other forms in IT; the CDC Cyber range launched in the early '70s, for example. And "CYBER" was a standard Library of Congress index term in 1990, and probably earlier.

But the term didn't really pick up steam until the early 1990s, judging by Google Books Ngram data, as people began to tire of prefixing everything with "e-" to indicate it had something to do with IT. Then it snowballed.

It was always etymologically unfounded for this use, though. And it carries rather a non-technical whiff; someone who sprinkles their conversation with cyber-this and cyber-that rather comes across as the sort of person whose expertise is derived mostly from reading the popular press.

It's long past time to retire "cyber-".

1From Greek "kybernetes" or "steersman", which now of course has been adopted by the Cloud People.

2It's never possible.

3Much of whose work I like. Not this piece, though.

Facebook doesn't know its onions: Seeds ad banned after machine-learning algo found vegetable pic 'overtly sexual'

Michael Wojcik Silver badge

Another layer of indirection

I looked at the fake-resumé site, and the one it showed me had a reference from "Juan Carlos Carlos Carlos Martins De De De De De De Oliveira". I can't use that. That name needs to be dereferenced five more times.

Backdoorer the Xplora: Kids' smartwatches can secretly take pics, record audio on command by encrypted texts

Michael Wojcik Silver badge

Re: I believe them, don't you?

Yes, this is a loathsome product category. Troy Hunt wrote a good exposé on the TicTocTrack last year.

Michael Wojcik Silver badge

Re: to be able to obtain location imagery in the event of a kidnapping

Statistics in the US are hard to come by. Child abductions are not reported in the UCR and the DoJ's transition to the new system (NIBRS) seems to be having some problems (data for 2018 was "supposed to be available by fall of 2019" but the page still hasn't been updated).

A best guess seems to be that parental abduction - either by the non-custodial parent, or by one parent in a shared-custody situation - happens some hundreds of thousands of times a year. Abduction by strangers appears to be in the hundreds per year. So parental kidnappings are around three orders of magnitude higher.

Given that, it's reasonable for some parents (based on the child's custodial situation) to be concerned about a parental-kidnapping risk. It's not reasonable to take anything more than common-sense measures against the stranger-kidnapping risk; that's simply not a rational response. And with around 73-74 million children in the US, the rate even for parental abduction is low - but individual risk will depend very much on the particular situation, so the average isn't particularly meaningful.

All that said, even for those most at risk I don't think spyware wristwatches are going to be much help.

After ten years, the Google vs Oracle API copyright mega-battle finally hit the Supreme Court – and we listened in

Michael Wojcik Silver badge

Re: Status quo?

I'm not sure that's really a good way of defining the status quo.

It doesn't matter whether it's a good way. It's the court's way, so in the context of the claim in the article - that SCOTUS is likely to uphold the status quo - it's the only relevant definition.

Yes, it's down again: Microsoft's Office 365 takes yet another mid-week tumble, Azure also unwell

Michael Wojcik Silver badge

An offline version of Office 365

What, like a version of Office that you run on your own machine, even if it's not connected to the cloud? Inconceivable!

Though personally I'd be happy if they just stopped at "an off version of Office 365". I've been using Word (reluctantly, when forced to do so) since a floppy with a preview of MS Word 1.0 was bound into issues of PC Magazine, and Excel (with loathing) since the mid-1990s. If I never had to use them again it would be a minor but significant improvement in my life.

Institute of Directors survey says most bosses expect no mass return to the office if COVID-19 crisis ever ends

Michael Wojcik Silver badge

Re: As it could have been done *decades* ago

I did a fair bit of work remotely over a 1200bps dialup link (which was prone to dropping spontaneously; saving your work often, or using an editor that could recover a dropped session, was a good idea).

1200bps sync connections, for example to IBM midrange or mainframe machines, were even better, since they had less overhead than async dialup.

I did a little work over 300bps dialup, but to be honest 300bps was very tiresome. 1200 was where it became reasonable.

Michael Wojcik Silver badge

Re: As it could have been done *decades* ago

It could have been done _a_ decade ago. Two decades ago, most people were still on dial-up and paying 3p per minute in phone charges to access the internet.

Conditions in the UK two decades ago might not be an accurate model of those everywhere else.

I started working exclusively (aside from short visits three or four times a year) from home, as a software developer, in the US, in 1992. I was back in the office briefly, from mid-1996 through early 1998. Since then I've worked exclusively from home.

Initially I had an OS/2 machine, an RS/6000, and a SPARCstation, and a V.32bis modem, which I used primarily for UUCP file transfers and a SLIP link, directly to the office (Ohio to Massachusetts). Pretty soon I switched to a Telebit Trailblazer at each end of the dialup connection. About a year after that, we put in a 56Kbps dedicated digital line from the local telco.

When I left the office again in 1998, we went with Basic Rate ISDN. I was in Nebraska; I don't remember what corporate location I was connecting to at that point.

In 2002 I moved to Michigan, and there cable (DOCSIS) broadband was available. Bandwidth, latency, and reliability were pretty terrible, relative to what people were typically getting in major US cities, due to poor investment by the small cable company that served the area; but that didn't significantly impede my work, because CVS and ssh don't need a whole lot of bandwidth and I grew up with high-latency connections.

Eventually the cable company was bought out by a bigger firm which did a lot of capital investment in the network (shocking, I know).

At my other house, we started off with crap ADSL from CenturyLink, but the local electric cooperative has been running fibre alongside their power delivery infrastructure and selling residential and commercial Internet access on that, so about four years ago we were able to upgrade to FttP and now things are pretty sweet.

My point, though, is that for developers with a workload similar to mine, in the US, working from home has been quite feasible for nearly three decades.

China sets out world domination plan for its digital currency

Michael Wojcik Silver badge

Digital currency? Pfaugh.

I'm tired of all this digital money. I want continuous money. If I make an irrational purchase, I want to pay an irrational amount for it.

And for buying something really good, I'd like a transcendent price. "This lovely automobile can be yours for only $20000π!"

Net neutrality lives... in Europe, anyway: Top court supports open internet rules, snubs telcos and ISPs

Michael Wojcik Silver badge

These days 500MB is not enough

500MB is more than enough for me. Not everyone is you.

Infosys to hire 12,000 more Americans – especially the cheapest ones it can find

Michael Wojcik Silver badge

Re: Credit where credit is due

It is WELL KNOWN that BLOCK CAPITALS make an argument MORE PERSUASIVE, and possibly even MORE FACTUALLY CORRECT.

Ex-Autonomy CFO Sushovan Hussain loses US appeal bid against fraud convictions and 5-year prison sentence

Michael Wojcik Silver badge

Re: "We rather regard any resort to the privilege against self-incrimination as a black mark."

if people ask you all sorts of questions and you refuse to answer, any reasonable person would infer something from that

For example, a reasonable person might infer that you consider civil rights more important than law enforcement's right to conduct bullshit interrogations.

In the US, the right to silence is absolutely critical and should always be exercised, except as specifically advised by counsel, because the federal government has made any misstatement to federal officers a felony, and is very happy to imprison people based on that principle.

The UK version is an institutionalization of the principle that "only the guilty have something to hide", and as such is inherently immoral. That should be obvious to anyone capable of critical thought and with a decent grasp of the human condition.

Michael Wojcik Silver badge

Re: This is still HP's fault

It's entirely possible for both parties to be at fault here. What I've read of the case, in the Reg and elsewhere, suggests that is in fact what we have.

That said, the sentence against Hussein seems rather disproportionate to me. But then I think that's true of a great many sentences in US criminal and civil cases. Unfortunately there is little political will to correct the situation.

'My wife tried to order some clothes tonight. When she logged in, she was in someone else's account ... Now someone's charged her card'

Michael Wojcik Silver badge

Re: Never store your card

Actually, all of the credit-card breaches I can recall, or could find in a few minutes of searching, from the past couple of years were the result of one of:

- A skimming attack against POS terminals or backend systems.

- A web skimming attack (Magecart being the most common).

- An attack against an issuer, credit agency, or some other non-merchant.

All the breaches I found that included credit-card data retained by a merchant were from several years ago.

That doesn't mean no merchants retain CC data, but that particular class of exposure seems to have become much less common than physical or web skimming. The move to dedicated payment processors seems to have more or less have the effect claimed by disgustedoftunbridgewells.

Relatively recent (i.e. going back a couple more years) breaches against merchants that yielded stored CC data are mostly against hotels, most notably the big Marriott breach.

I still think we should recommend virtual cards and/or other payment options (I don't personally like Paypal, but it does provide some protection against card-data theft), but more as a defense against skimming. As for whether you let merchants retain payment-method information in whatever form: that's a different part of the attack tree. Some consumers feel it's worth the risk; others don't, or are willing to assume it only in particular cases. But it's not the same as a CC-data-exposing breach, which is a more serious failure because it lets the attacker clone the card and use it at multiple merchants.

Michael Wojcik Silver badge

Re: step one: ring your card provider

I used one of those cards that allows you to relegate a unique card number to each merchant you buy from

Yeah. I've been using virtual cards from privacy.com for any card-not-present transactions for a while now, and I have to say I've been pleased. Create any number of cards, set various limits (per-transaction, daily/weekly/monthly), restrict to a single merchant, various options for being notified of any transactions, and you can use any name and mailing address you like. It's all tied to a bank account, so if you want an additional layer of security, you can open an account specifically for those cards.

They make their money off the merchant fees, so it's no additional cost to the consumer.

The web UI is fancier than I prefer, but it's not too obnoxious. Works fine with non-Chromium browsers.

I don't have any relationship with them beyond being a user of their service.

'There is no way we can keep coding local': GitPod's cloud development platform released into sunlight of open source

Michael Wojcik Silver badge

Kids these days

There is no way we can keep coding local

Oh yeah? Watch me.

This claim is just a variation on "we can't expect developers to have any discipline".

And, of course, there are no failure modes with remote development that anyone might need to worry about. No one ever loses connectivity.

And we have decades of experience with primarily or exclusively remote development to learn from. I still do plenty of remote development today, though I do it properly (ssh to machines several timezones away, GNU screen, bash or ksh, source in Subversion or git, vim, gdb or dbx...). Browser-based IDEs are fine for people who like that sort of thing, I suppose, just like a 1980s Chrysler was fine for people who didn't want a vehicle that was more efficient, reliable, maneuverable, or practical; but to suggest it's the way everyone should write code is typical All-the-world's-an-X myopia.

50%+ of our office seats are going remote, say majority of surveyed Register readers. Hi security, bye on-prem

Michael Wojcik Silver badge

Re: Loss of human contact

It's almost as if people are not all identical, and generalizations about them are suspect.

I've been working from home for over twenty years. I've worked remotely from my teams for most of my career - about 5/6th of it.

I get plenty of human interaction: In person from family, neighbors, shopkeepers, doctors, strangers I pass on the street; by phone, text, and email from family and friends; many times a day from my co-workers by various means. I have daily calls with members of two of my teams, and weekly calls with others, and ad hoc calls with all sorts of folks. I get quite a bit of work email, which I genuinely enjoy.1

I used to have face-to-face meetings with some of my teams once a year or so, and I did like that, even if (indeed, partly because) it involved international travel. But do I need it? No, I do not.

I'm sure there are many people who work best in a group setting. That may be true of most people. But people are adaptable, and I have yet to see any reliable evidence that a broad shift to working from home will have the dire consequences some are predicting.

1I realize this is unusual, but I'm a compulsive reader. Two of my degrees are in writing.