* Posts by chuBb.

525 publicly visible posts • joined 24 Jun 2008

Page:

.NET 6 LTS and VS 2022: Major releases spoilt by continuing concern about Microsoft's commitment to open source

chuBb.

What's so buggy?

Only real issues I've had is v old projects circa vs2012 format csproj, which once updated to be sdk based csproj have been well behaved and fights between package reference and packages.config which again is solved by upgrading the project format. Only real gripe with that is that an advanced view on project properties would be nice to save having to trawl msdn for all of the various project and build effecting config values, although that's much less of a hassle now you can edit the project file of a loaded project

Resharper is still hobbling vs though, if only I could find as good a test runner as Resharpers* I'd uninstall the performance killing nuisance

*vs's inbuilt test runner just isn't in the same league or even as functional too many times will it fail to start a test run because of a hidden build error and not having to install a nuget package per testing framework lurking in the code base is also a massive bonus i don't see why I should have to deploy a new build just so that a dev time activity works out of the box...

chuBb.

Re: Version confusion

It's not really a shame though,.net on *nix is all about cheap vms in azure running backend services.

Yet to use a cross platform ui framework that's worth the effort, or the endless meetings explaining to crayon botherrers that text boxes look different on mac and pc and that maybe they are confusing Web design with ui design...

You'll never guess who's been exploiting the ManageEngine service to steal passwords

chuBb.

Re: Out of curiosity...

It's not so much the payload that's the problem (plain text interpreted script) it's that it's possible to execute an uploaded file that's the issue.

What must be happening (I've not looked at specifics) is:

Zip is uploaded and extracted

Tomcat is set to engage java for all file requests (typically you would exclude any static files from wasting server resources, manage engine have a very lan centric trusted environment expectation with their out of box configs runs as root and sets the execute bit by default on file permissions on the *nix installer for example)

Because of this misconfiguration the attackers script is executable and good bye server you've been pwned.

The payload zip file would be a couple of kb in size and would require actual inspection to be detected as a zipped pem file and a zipped jsp would look very very similar in a hex editor...

chuBb.

Not relying on a single authentication method for authorisation.

xkcd password with alternating capitisation and if Warrentted numeric substitution, coupled with a pin and or an authenticator app or one use token is my minimum recommendation

As for post it note what ever works for you, although I'd be more inclined to write a mnemonic or an acrostic for an xkcd password than the actual password

chuBb.

It's not really an online password service, I mean some twat will have made it publically available. It's more of a hell desk front end to basic AD user operations password reset account unlock that sort of thing

Basically could be severely hampered by MFA and using a more modern approach to AAA

Won't be surprised to see more efforts directed at "internal" business support systems now external security is generally better in 3rd party solutions than internal

chuBb.

Re: Out of curiosity...

Cert size depends chain size and how many you feeling like cat'ing together

A root ca collection can be a couple of mb

Investment app Robinhood: Extortionist tricked our support desk and made off with customer information

chuBb.

Re: RobinHood, RobinHood...

Or the weetabix advert...

Singaporean minister touts internet 'kill switch' that finds kids reading net nasties and cuts 'em off ASAP

chuBb.
Big Brother

Anyone else get that sinking feeling that this will form the basis of a "Transformative ambitious cyber economy levelling up backdoor, sidedoor, dont you open that trapdoor" policy announcement in Westminster?

Facebook's greatest misses: The five nastiest bits from recent leaks

chuBb.

Re: Having never taken the FB bait

Me either

As far as i can tell its the bastard lovechild of yahoo groups, msn messenger and an RSS feed, which lets people have the geocities lets share with the world warm and fuzzies with even less of a technical on ramp, with hit counters now called likes, and guestbooks are now called walls.

[I have been having fun explaining things in terms of '90s web things to the work experience kid given he is well under 20 and likes tales of the "stoneage", and now understands having been made to work through it on graph paper and not just use the calculator]

chuBb.

Re: Multiple accounts?

Multiple accounts will skew the ad stats, advertisers will pay less if they have reason to doubt the effectiveness of the targeting. Less ad profit less being the ceo bitch

chuBb.
Pint

That was good have a pint!

chuBb.

Re: "to paint a false picture of our company"

Ahhh the metaverse, techno illiterate headline grabbing chod, like the "dark web" or as i call it, the net circa '95-'96 with encryption that would have melted your 486.

We all know it will be a worse version of secondlife with even more racism, sexism and algorithm supplied dog whistles with added ads, captain cyborg (kevin warrick) will be a ubiquitous presence again chatting shit about having a rfid chip implanted (ya know like you would a cat or a dog...) so he can open a door like a harry potter cosplayer with a butchered oyster card can ride the tube.

With endless analogies to the matrix and blade runner [even though bladerunner doesnt feature a metaverse/net/wizzy cool looking ui that would be absolute usability fail, tron would be a better pick just saying] and maybe existenz if they done their homework* in the press clearly showing people writing about the crap were

a) distracted by the sfx and didnt notice the plot (its not avatar there are plots in all 3)

b) the plot went over their heads and failed to notice the corporate distopia/machine overlords

c) still believe if they wish really hard and think magicleap can it will

All to mine for patents and dodge tax, the only good that may eventually come from it will be bionic eyes designed to deliver ads directly to your brain, with a handy secondary function of allowing the blind to see...

*looked at the people also bought suggestions on amazon

chuBb.

Fuck zuck

Simple policy has served me well over the years.

If I want to share photos I use my own site

If people want to get in touch use my email which hasn't changed in over 25 years, or call my phone or if you must txt again same number for over 20 years

If you are worth knowing you know my rules or you fail to get hold of me

chuBb.

When he has to show something to avoid litigation from investors.

SolarWinds attacker on the move: Russia's Nobelium crew has trebled attacks targeting MSPs, cloud resellers, says Microsoft

chuBb.

Are you surprised? If a high turnover min wage call centre operative can perform a remote reset/reconfig then yeah the maintenance network will be wide open.

Just about all firmware sucks at security, and I'm pretty sure there was a bot net arround the time of stuxnet hitting the news that mainly comprised set top boxes and modems and spread by sftp (might have been ftp or samba) ...

It's the main reason I will always provide my own terminating hardware and not do anything but recycle what ever crap the isp sends out. That and you can leap frog to 2nd line support when they can't follow any of the script, failing that you need to get them to try and guess which layer of the osi model we are talking about then inform them they are not qualified to accept your answer and to escalate it...

Microsoft under fire again from open-source .NET devs: Hot Reload feature pulled for sake of Visual Studio sales

chuBb.

Unsurprised at the climb down, my gut always said it would be reinstated in the 2022.1 update because they learnt lessons from shipping ef migrations without a ui.. . The whole justification sounded much more like "can't schedule a working ui before rtm" than "mwahahahaha suckers premium feature only" truth is probably between those two though. Still a lot of 90s bulmerites in senior roles in redmond

As for all the hoo Haa it's just young bloods finding out ms's lipservice to Foss is just that, and they will be first to complain about a "janky workflow" with initial release. Then be shocked to discover ms build is its own dsl, and its always quicker to write a batch file and invoke it during build than to let vs handle it...

Florida man accused of breaking Mastodon's open-source license with botched social network launch

chuBb.

Re: Wonder if there's a software developer somewhere...........

Probably a wix template...

chuBb.

Re: It will be funny to see

Was going to say same thing

Wonder which OSS license will be the first to prohibit retired golf fan from using or deriving any profit from said code

Also wonder how long until SEC drag the loon over coals

We regret to inform you there's an RCE vuln in old version of WinRAR. Yes, the file decompression utility

chuBb.

Re: hijacked dialog box

Yup it's pretty low risk on its own, as a reinfection vector it's pretty nasty.

This sort of thing is exactly the sort of flaw that would let malware back in. I. E. Bot net c2 sends out a disinfect command and so appears to be off the machine, leaves behind any number of methods to fart about with dns, winrar nag screen exploited to call home to c2 or new package dropper and your reinfected. So wouldn't be surprised if similar flaws are actively used to resurrect botnets

HPE's Aruba adopts DPUs, but in a switch, not a server

chuBb.

Makes quite a bit of sense conceptually to me. Especially when using containers, a k8 aware switch would be very handy, and common management would totally work, all dpus I've looked at run Linux so what's not to like about say allowing a switch to operate as a load balancer on a couple of ports, or to run smoke tests on a given connection without needing to be an expert in the intricacies or each vendor and model ranges cli deployed in your network.

Devil will be in the implementation and using it for the right sort of workloads though. Wouldn't be an early adoptor but for a lot of hybrid cloud scenarios I could see these sorts of things becoming super useful. Hell just being able to run tcpdump at switch level per port and dumped to a San while still being a switch could be super useful

Facebook may soon reveal new name – we're sure Reg readers will be more creative than Zuck's marketroids

chuBb.

Sparkling turd

If you can't polish it rollit in glitter

LAN traffic can be wirelessly sniffed from cables with $30 setup, says researcher

chuBb.

Re: New? Bwahaha!

Next headline, "using a cheap clamp multimeter energy consumption can be sniffed from a smart meter (lets ignore thats how smart meters monitor the supply but hey...)"

Or

"Security researcher reads and understands a Primer on RF Principles"

I wonder if his head would literally explode when standing waves and back emf are introduced in a few chapters time, "ZOMG, with 6" of tin foil strategically placed you can blow up a transceiver, think of the power lines!!!!!111!!!!111!!!!!!!"

In all seriousness so what, there is no reason at all to ever send anything over a digital network of any description without good enough* encryption

Also i bet the kit is much fiddlier to install than to strip an inch or so of outer sheathing and just IDC a tap onto the cable, if your good, reckon you could install in under a min, and be able to super glue the sheathing back together again to make it pass a glance test, when you remove the tap...

*Even the weakest SSL1 ciphers would frustrate casual observers enough to make the decryption much more onerous than the capture, and for say a stream of data for a hobby weather station would be sufficient as the data is pretty low value

Twitch increases bug bounty payouts after source code leak by... wait, is that it?

chuBb.

Not really both are "move fast and break things" companies

In other words meet kpis and hope for best, then when it blows up and new managers come in, test until quarterly bonus is threatened, get sloppy, break it again and jump ship to do same shit elsewhere

.NET Foundation focuses on 'issues with the community' after executive director quits

chuBb.

Rock and a hard place

Will be interesting if they can square the circle, I don't think they will have much choice but for MS to either loosen the reigns a little or to change the foundations mission.

Look at something like Json.net* which is a dependency for a lot of the official Azure packages, there was quite a lot of hassle caused when the official nuget packages lagged behind a major version of json.net and broke builds if you accidently updated to an incompatible version (and as its such a widely used package you could update to an incompatible version by updating a different package with a dependency on it, such as StackExhange.Redis which you would want to do to fix a memory leak caused by the old v1 connection multiplexor) which led to us having to postpone a reliability fix until the Azure Storage packages were up to date, same with Azure Services lagging 2 or 3 versions behind its deployed azure storage libs and the latest on nuget

In my opinion the quote of

"It's about enabling Microsoft to recommend and take dependencies on libraries not created by them instead of creating new ones that squash projects,"

is mostly right, but really the Foundation should be instructing/co-ordinating MS to keep its packages up to speed with the latest public OSS packages, not making the OSS packages trustworthy. The foundation should be funnelling back into MS the state of play of the foundations projects and making sure MS isn't the ones effecting the trust in the OSS packages. And on that front they are an abject failure as its MS's fault we ended up with a Faustian choice of no more random crashes but have to run production with pre-release (and breaking changes did happen between pre-release and release ready Azure storage packages) or put up with random crashes but working access to storage knowing that the problem is fixed but unsupportable. FWIW I took a middle option and rearchitected the product to separate the storage aspect into its own project and had a separate redis service which then was re-integrated into one service when the dependencies aligned, basically 4 weeks of unnecessary dev work and 3 deployments because MS couldn't keep up with projects it should have been following....

*It might not have been json.net it was a couple of years ago but pretty sure it was something like that

** And before someone says LOL that's what you get for azure, AWS is no better and decisions were made prior to me joining the company

Microsoft Teams leaves users hanging on the telephone after PSTN integration goes wobbly

chuBb.

Re: Teams and call forwarding

Your sbc isn't handling refer messages properly, once tweaked just so call fed just works

chuBb.

Teams is sfb under the hood with a usable share point interface tacked on top..

All ms have done is remove the pain in the arse on site requirement for sfb pstn connectivity and virtualised it in the o365 cloud everything else works the same (but sfb had a better telephony ui in my opinion)

chuBb.

Because you don't Dr is Ms allowing proper telcos to terminate a sip trunk to teams tenants

For what's its worth been receiving random network congestion errors on connection attempts since Monday...

NSO Group's Pegasus malware was used to spy on Dubai princess's lawyers during child custody dispute

chuBb.

Re: How about Android?

Id argue apart from the valid observations of iphones being status symbols and additional telemetry db's on apple devices, that an android device is much easier to scrub clean and is much more widely understood OS vs iOS due to it being an inherently more open system.

As for combating this sort of thing, given the suspicions of rouge cell towers (or just compromised cell towers its not like security is much better than on a street light) seems tricky without reinventing how urls work, only thing i can think of that might be effective is to effectivly ddos and destroy the signal to noise ratio of the gathered intel through mass infection of devices, but i dont know if an "im sparticus" retaliation would be effective or if it would just cause a lot of collateral damage...

Alternative search providers write letter to EU complaining that Google antitrust action achieved diddly-squat

chuBb.

Re: Compete on function, not whinging

if your not afraid of typing just append "/search?q=thing im looking for" to your google or bing tld of choice

chuBb.

Re: Compete on function, not whinging

Googles results page used to be simple, now i find bing to be less obnoxious and much better highlighting of ads masquerading as results, i never use its homepage so the wallpaper of the day escapes me

chuBb.

Re: Perhaps a "open search engine" is what is needed?

elasticsearch, lucene, and about a dozen other apache projects

its not as simple as build and they will come, indexing is the easy bit, optimising and making it relevant is not, and while you may be able to create a better highly niche search engine for a given topic on average bing or google will be a better more general purpose fit, and its hard to convince people of a business case that is sane when you can just let google or bing do it for you for mostly free vs employ team get nearly as good results and build and run the infrastructure

chuBb.

Re: "invested €100m into building their own search algorithm"

so you mean RTFM on any search engine since altavista?

schottky&diode&reverse|voltage

boolean operators are parsed as expected by them all

exact match just wrap in quotes as you did in your post

"schottky diode"&(cascade|reverse)&"voltage"

or in human exactly schottky diode with cascade or reverse and exactly voltage

https://help.bing.microsoft.com/apex/index/18/en-US/10002

https://docs.google.com/document/d/1ydVaJJeL1EYbWtlfj9TPfBTE5IBADkQfZrQaBZxqXGs/edit

Things that are not PogChamp: Amazon's Twitch has its source code, streamer payout data leaked

chuBb.

Re: Waiting...

im waiting for it to be revealed that even amazon cant secure s3....

Whats reckoning it will be a line of business server that was compromised that happened to backup to a leaky bucket?

chuBb.

Re: House of cards...

Maybe we should just play shithead, and swap shithead for bgp-dns?

Computer shuts down when foreman leaves the room: Ghost in the machine? Or an all-too-human bit of silliness?

chuBb.

Regardless of location the difference in wire guage and the fact that a socket was coming off of a switch live is a dead giveaway you read the wiring chart backwards.

Dont get me started on the US's earth optional wiring, running light and socket spurs off of a single circuit is the least of their problems.

Yes could be a switched faceplate, but that would be really really REALLY out of place in an industrial control room, which circles back to USUALLY sparkys who work or do work in factories are at the "less lethal to selves and others" end of the spectrum, usually....

chuBb.

Hours of fun testing if mate is paying attention when doing an insulation resistance survey...

chuBb.

How on earth did they manage to take a spur off the lighting loop?

I mean I've seen it done by Weekend warriors and day 1 apprentices but in a factory, you usually have sparkys who can at least tell by the wire guage they are doing something dumb....

Tale doesn't quite add up..., most plausible explanation is that there was a fused spur switch next to light switch and eco foreman got a bit flick happy

WTF? Microsoft makes fixing deadly OMIGOD flaws on Azure your job

chuBb.

Re: "fixing deadly OMIGOD flaws on Azure your job"

I assumed everyone unistalled the omi shite from a vm on first boot, mainly as it seems to kill nginx performance and regularly consumes 50% cpu and spawns lots of processes

Tbh (maybe I'm "experienced" enough now) I don't know any self respecting Linux admin who would let anything run they didn't explicitly put there.

Then again I first discovered omi because it was breaking apt, so not surprised Ms are not pushing the fix as it will probably brick more than it secures, still yet to see what it offers over snmp

It's time to delete that hunter2 password from your Microsoft account, says IT giant

chuBb.

Re: No MS account

Bad news that happened with the win 10 creators update 2 years ago, have to jump through quite a few hoops on a fresh win 10 install to create a "limited" local account and not use one linked to azure ad...

chuBb.

No less privacy than logging in to whatever service you need in the first place.

If your really concerned about privacy get proactive, old phone in drawer root it, install a hardened droid os, keep it in flight mode, only connect to trusted WiFi and only install the authenticator app of choice (preferably side loaded and app store is neutered)

By and large this is a good thing for Corp it (phishing and rat attacks will be less effective), and power users will bother for personal accounts, aunty Doris will still rely on rover1966 for everything and be shocked and horrified that the nice African Prince she's been emailing is in fact a scam

Open-source software starts with developers, but there are other important contributors, too. Who exactly? Good question

chuBb.

Although i am biased being a developer, i would say a project lives and dies on its documentation. I have found that projects (everything from libraries to ui applications) which have exemplary documentation, also have the higher quality bug reports (they tend to be bugs and feature requests, not confusion over how to use the thing or triaged out of existence quickly with a link to the relevant doc/wiki/sample), a more active and invested community and generally a better time as a user/consumer of the code. There are some outliers namely audacity but thats more down to politics and doing silly things to annoy the community than anything else.

End of the day the better the docs, the quicker, easier and more predictable it is to use, the more its used the larger the "educated" userbase, the larger the educated userbase the greater the number of people able to authoritatively answer the "how do i" questions in the mailing list, stackexchange site, subreddit etc, which feed back into people using it. From good docs does all the other non code related roles spring

If your project lacks the info to explain the how, when and why you would use it, your probably missing out on a lot of people who would use and possibly contribute to it as your lacking the documentation for use.

GitHub merges 'useless garbage' says Linus Torvalds as new NTFS support added to Linux kernel 5.15

chuBb.

I would suggest transplant or couple are better synonyms than rebase to describe its functionality

chuBb.

I don't blame git for not being friendly enough for hosted services (as you mentioned the better hosted providers have taken steps to help their users who just want version control, SVN/Perforce would fit them better but GIT won), i do blame GIT for being needlessly obtuse at times though.

Frankly its one of the few big FOSS apps that clings to the old 90's RTFM/man git/why havn't you read and memorised thousands of emails in the mailing list response to basic questions. When the answer is the docs suck for most humans and you need to spend a lot more time on the technical authorship and supporting documentation as IT IS a feature of the software, rather than responding with a passive aggressive i'm smarter than you, and i wont help response....

chuBb.

Indeed, but as linus himself uses the term pr I think its safe to say the less clear term won

chuBb.

And in gits defense, at least its not source safe....

chuBb.

Id say the GIT CLI is no harder to learn than any other CLI, what makes git tricky to understand is its choice of nomenclature which activly fights the intent of the command.

While there may well be historical reasons for "pull request", but lets face it the vast vast majority of git users use a hosted repository, so any attempts at names that allow the ambiguity of the distributed aspect of git is pointless these day, it would be much better named "Merge Request" or "Merge Review" in my opinion, as that is effectively how its always been used in any project I've been involved in.

Rebase is another crap name used by GIT, despite having used git for the best part of 20 years i would struggle to explain its function in detail without some form of reference, "magic reset update merge keep working copy changes" command might be better as at least it conveys some of what rebase does, even if it would be a bugger to type on cli (but thats what the tab key is for in your terminal of choice)

HashiCorp runs low on staff, calls a halt to Terraform pull requests

chuBb.

Think tedious codebase is any enterprise or automation software, or pretty much anything which ships

Far more likely a combination of crap pay, AWS hoovering up any cloud engineer daft enough to work for them, rotten manglement of the terraform product team, and not being ansible or what ever the flavour of the month is on medium

US Air Force chief software officer quits after launching Hellfire missile of a LinkedIn post at his former bosses

chuBb.
Devil

Re: Do I hear a deafening chorus?

The BOFH in me would tell them that its a means of charging or being charged for each sucessful SYN/ACK sent by TCP....

I have prior form in getting a technical director (technically he directed any responsibility or accountability for his ill informed decisions away from himself, for example he hired a C and a Java developer to fill two c# roles, because its all the same and uses { }, signed off on an outsourced development project because THEY would project manage it, i left 9 years ago and that 18month project still isnt testable...) to believe that ARSE*, BUM** and VDWARTS*** were widely used acronyms, and proceeded to wax lyrical about his cutting edge arse and bum stack with vdwarts to the bemused heads of IT of a well known British high street bank when he wanted to bluff his way through a risk assessment/DR meeting

*Automated Recovery System Environment

**BackUp Machine

***Virtual Desktop With Advanced RealTime Snapshots

'Worst' AWS service ever? Cloud giant introduces Redis-compatible MemoryDB – to mixed response

chuBb.

Its a "solution" in the same vein as azure cosmos db, yes you can write less code/config to get the benefits of a cached front end on a db, but my god you will pay hand over fist if you actually use it on any meaningful project.

Do a cost analysis and it will be a lot cheaper to cluster a bunch of mid level VM's into a redis service than it is to use any of the cloud providers managed redis offerings, with the added advantage that you can house it in its own segregated vnet to over come the insanely permissive default security settings (redis's security sucks, you know its bad when access did it better and you wish for the "maturity and sensibleness" of mysql </sarcasm>), unlike the managed offerings which expose standard ports and act as a beacon for miscreants scanning with shodan. All it would take is for a s3 style "forgot to secure it" snafu, half dozen lines of python and a few hundred kb's of data to be written to enumerated keys and your looking at being liable for unlimited data charges, would make 4g roaming data charges look cheap

Nevermind that all this new service offers is what is already possible using redis modules as the article states, the fact its redis "compatible" fills me with dread as it makes me think proprietary data structures will come, which means your going to be stuck with it, until they mothball it and then what?...

Given the number of off the shelf redis kubernetes cluster solutions available, and if your data project is truly needing of distributed transaction logging you would be better off in my opinion in investing in the skills to run a cluster, maintain (sorta)portability between cloud vendors and build out your own bespoke solution. It will be cheaper (both in service and data costs) and a less compromised jack of all trades solution.

Cloud load balancer snafu leads to 3D printer user printing on a stranger's kit

chuBb.

Same reason as cisco, ms, oracle etc does, money printing through software licensing

And reducing the support burden when bumblefuck the unlearned fiddles with things they don't understand burns the house down and still bitches on the forum that they couldn't get the hello world cube to print

Page: