* Posts by The Mole

378 posts • joined 18 Apr 2007


Accused hacker Lauri Love to sue National Crime Agency to retrieve confiscated computing kit

The Mole

Re: Why does he want five-year-old kit back?

Well taking all machines and storage probably means he's lost photos and precious documents (unless he had all of them in offsite backups), so yes sentimental reasons seems like a good motivator.

It'll soon be even more illegal to fly drones near UK airports

The Mole

Not flying within 50m of people or 150m of congested areas probably excludes most of the centre of London anyway.

London's Gatwick airport suspends all flights after 'multiple' reports of drones

The Mole

Re: Christmas conspiracy

My thought was more along terrorism investigation lines - a way to keep everyone in the airport whilst they search all the bags (or whatever) and identify who the bag belongs to without tipping the fact they know about the plot.

FYI: Drone maker DJI's 'Get it on Google Play' website button definitely does not get the app from Google Play...

The Mole

Huh? Drones are used routinely by the UK and other police now. As well as seeing the results on TV I've seen the kit and spoken with the actual operators.

Raspberry Pi supremo Eben Upton talks to The Reg about Pi PoE woes

The Mole

Re: Oh dear, a fan

I'm sure you could just switch it out for a stonking big heatsink instead. Or just not do POE and run a real power cable. For many people I doubt the life of the fan in their environment will be a concern whilst they may care more about size/cost.

Security bods: Android system broadcasts enable user tracking

The Mole

Re: don't seem like that much of a threat to me

So there is a malicious app running on your machine with the ability to send arbitrary to its home.

That means the home can track the user based on the public ip address the request is coming from, in many countries this will be enough to locate to a city or closer (dependent on network structure). In fact if that app sometimes have permissions they can get the information and map wifi information to public ip as well.

Without permissions the only additional information that could be useful I can see is more precise location information inferred from the wifi network name (you are on starbucks wifi or in the library). DNS server name probably doesn't tell much useful, mac address gives information about the device, but I believe an app can get that much easier through the standard apis. As people have mentioned if you've got a malicious app on the device the end user probably has given permissions anyway.

US watchdog OKs robo-doc AI that spies eye disease all on its own

The Mole

Re: What about all the other diseases?

I imagine that Macular degeneration may be their next project, which is likely to be quicker and easier now they have proved the technology and get it licensed. And (assuming camera settings are compatible) I'm sure they will be able to roll it out as an upgrade to existing users to also detect other conditions at the same time (the incremental processing cost is likely to be insignificant you imagine). But each new condition will require additional FDA approval which is expensive and time consuming.

The Mole

Re: Trust

Perhaps you should lift the tin foil hat a bit and read the entire paragraph. "The first biz to release an AI-based device that can detect the disease – and was approved by the US Food and Drug Administration (FDA) in April – is less well-known, however." That is, those two big companies aren't involved in this invention, that just also happen to be doing research in the area.

Too many leftover screws? Ikea website backend goes TITSUP

The Mole

As other people have mentioned the site has been unstable for a while, random maintenance pages, stock check not working on the main part of the site (even though ordering apparently shows the stock). There are also issues in the store where they will tell you items are in stock, and when you get to the warehouse they don't have them, but that may just be a dodgy order system that doesn't prevent double sales..

What's in a name? For Cambridge Analytica, about a quid apparently

The Mole

Re: Data Controller

More interestingly the reporting of judgement implies that they are responsible for responding to data access requests:

"First, that the company should retain sufficient data to enable it to respond to any data subject access requests which had been made before the disposal of the data and, second, that the liquidators should retain sufficient data to enable them to deal with any claims that may be made in the liquidation."

So the liquidating company don't become the data controllers, they are merely the agents of the company they are liquidating. However as the agents they've got to comply with the rules and that includes ensuring the data controller within the company responds to subject access requests - and presumably appointing a new agent to act as the data controller if they have gone and made the original one redundant.

Oracle's new Java SE subs: Code and support for $25/processor/month

The Mole

Re: Inspired by Facebook

It appears they already are. Go to the website, when the cookies popup comes up select to only have minimum number of cookies and click "I accept". The message that comes up is:

"We are processing your request, this could take up to a few minutes to process."

And they aren't lying there is a microsoft style* progress bar and it really does take minutes as it talks to all their analytics hosts to update your preferences!

*That is gets to 99% and then just sits there for ages.

User spent 20 minutes trying to move mouse cursor, without success

The Mole

Re: Not Millennials!

You think it would but it doesn't, apparently it's those who 'come of age' near or after the millennium ("a person reaching young adulthood in the early 21st century." according to google).

This means that those born in the early 80's are counted at millennial - which I personally take great offence at being born in the early 80s and not wanting to be associated with them. I do remember the BBC micro so perhaps that is the better definition?

T-Mobile owner sends in legal heavies to lean on small Brit biz over use of 'trademarked' magenta

The Mole

Re: So if I trademark all combinations of RGB..

If you follow T Mobiles playbook you don't even need to trademark all the combinations, just a sufficient number of them to be able to claim 'similarity' with any other colours - 256 colours would probably be sufficient according to MS Paint 'basic' colour selection.

Though I may just trademark black, Red, yellow and cyan, as colours either in solid or as dots and claim all other printed logos are infringing as overlayed trademarked images..

Every major OS maker misread Intel's docs. Now their kernels can be hijacked or crashed

The Mole

Re: I'm impressed

Easy, most people are too lazy to actually read the documentation.

Its a bit more justifiable when you know it is documented somewhere but not which particular document set you have to look in.

And yes documentation (and some test teams) are often the people who get the biggest picture of how a complex system/application works. Most other people are too low level (concentrating on one particular component), or too high level (understand the architecture but not implementation details).

Cisco kicks shrivelling video software unit back to Dr Martens owner

The Mole

History repeats.

When NDS was absorbed into Cisco they gave out mini usb picture frames as a welcome gift to all the employees. A few days later they asked for them all back as the plug sockets were a fire hazard (cheap chinese boards with no real insulation in them). They promised us that they would be replaced but that never happened.

At least Permira get to keep the other $4 billion with this returned, though the remains of NDS may be a bit scorched from the yearly employee layoffs.

AWS sends noise to Signal: You can't use our servers to beat censors

The Mole

Re: Block of flats

If you don't use SNI then the server has to return the default certificate, which if the server is fronting 2000 different domains will almost certainly not be the certificate you are needing.

SNI is the thing that lets the server knows what certificate to return in order to establish the connection.

Normally a standard web server would then tie the hostname in the SNI certificate to the website being served (Host in the http header). In this case the server is actually a proxy fetching content from back-end servers, the same code is serving all websites, looking at the host header and then grabbing the real content from the real origin server. Being the same code running for all websites is how the mismatch could be 'abused'.

We just wanna torque: Spinning transfer boffins say torque memory near

The Mole

Re: Intriguing....

You can already get NVME SSD drives that are RAM DIMM sticks. The ones I've been presented about actually encrypt the content in hardware as well.

Linux already has some support for this depending what you want to do.

They can be mounted either as volatile RAM sticks (actually persistent, but if you reboot it forgets the previous encryption key, effectively wiping it), or be exposed as a disk that is persistent across reboots (a persistent ram-disks so to speak).

The biggest question is what the write endurance is. Current SSDs biggest limitation is the fact the cells stop working over so many writes, where as with RAM applications assume they can write an infinite amount of time. A naive global replacement of NVRAM with nvme storage would soon cause the nvme cells to be worn out. Hopefully this technology could be a complete replacement.

Even then there is a useful distinction between persistent and non-persistent storage of content. Linkers may modify the in-memory image of the application to insert references etc as appropriate, these shouldn't be written onto the persistent copy of the application as they may not be valid the next time it starts.

An os and applications designed for persistent memory would be an interesting evolution, potentially it would allow 'instant' on machines as the state would automatically be preserved at power off (assuming all components support it).

US citizen sues France over France-dot-com brouhaha

The Mole

"When it became clear that the government could not afford to pay a fair price, the Government of France instead set out to expropriate the france.com domain name."

I don't know if it is a bad translation but this makes no sense. For a company the size of France it can always 'afford' to pay a fair price - in the worst case it prints the money/adds it to the national debt. Of course politically it might not want to, or there may be a disagreement of what a fair price was ("The government offered to pay a 'fair' price but it was rejected") but even then after seizing it they should have paid compensation.

Europe fires back at ICANN's delusional plan to overhaul Whois for GDPR by next, er, year

The Mole

Re: I don,t get it.

Because a domain name registration isn't a a company.

Registration and accounts need to be given to companies house primarily so people can make significant financial decisions based on that knowledge (giving credit, paying up front) in b2b type relationship. It isn't typically intended for end consumers as typically consumers don't use it. For doing business with websites you don't need the whois information. it is already the law that companies must display their contact details and registration on the website. For the remaining websites then this is no different to interacting with market traders, Jo Bloggs at a car boot sale or that guy in the pub, they don't need to register at companies house and there is no reason why you should know where they live. Also note companies house doesn't require direct contact information, typically it will be to a registered office at a law firm or office space.

UK watchdog finally gets search warrant for Cambridge Analytica's totally not empty offices

The Mole

My assumption is that they are special order and took a while to be made - hence the delay in processing the search order (they all looked brand new after-all).

Surprise UK raid of Cambridge Analytica delayed: Nobody expects the British information commissioner!

The Mole

Re: A deafening sound of shredding

Not sure which BBC coverage you've been ignoring, but I've seen/read/heard plenty of coverage on the web/newsfeed/tv/radio - although at the start it was slanted towards 'swaying elections' rather than 'stealing all your data'

Go park yourself: Brit firm flashes self-parking car tech

The Mole

Re: All well and good..

I assume it is just an extension of the already existing parking assist technology, as a car is driving round the carpark it detects empty spaces and communicates this to other nearby cars - it doesn't matter what is blocking the space and whether that is a smart car, dumb car or shopping trolley.

Fun may be had by either sending spoof messages sending cars driving round randomly (they will check that the space is still empty when they get there) or by painting random sets of parallel lines on the road and watching cars think they are real parking spaces.

If there is no space in this car park presumably the car will just drive to the next car park (or keep circling like meat drivers, or just park in the lane and mover whenever it is blocking another car) though what happens if it runs out of juice on the journey is an interesting corner case.

Fermi famously asked: 'Where is everybody?' Probably dead, says renewed Drake equation

The Mole

Re: Not useful

Yes. Either the technology has moved on to none EM based transmissions (which may not even exist on earth). Or one can assume the EM technology would be made more and more efficient, either due to energy budget constraints, or minimising interference between a large multitude of devices. It seems to me (not an expert) inconceivable to consider that within 10,000 years (or even 1000) that the civilisation won't have reached a stage where the EM radiation is so low power to make it impossible for us to detect as a coherent signal out of the background noise. Perhaps there will be concentrated beams of higher power EM from longer distance communications (e.g. to probes/other planets) that we could detect, but not a sphere of signals.

Hot NAND: Samsung wheels out 30TB SSD monster

The Mole

If you have high enough throughput even with AES instructions encryption quite definitely isn't free. Though disk bottlenecks are quite likely to kick in first.

Stop calling, stop calling... ICO goes gaga after home improvement biz ignores warnings

The Mole

From the ICO report

"Criminal penalties are imposed by the courts and not the ICO. Direct Choice had paid off £40,500 of its previous civil fine. The ICO has recently been informed that the company has applied to go into liquidation and will be working with the Insolvency Service on recovering the outstanding balance."

Not sure anybody is going to see this as a deterrent though if the punishment is so low - though that may be that they chose to use the lowest possible court who can't impose significant fines.

Destroying the city to save the robocar

The Mole

Re: Obviously the solution is....

Because in a world of mostly automated cars the vast majority of the accidents will be judged the fault of the manual driver (remember the data will be logged to prove this). The cost of insuring the automated car will be lower (as they should be safer due to less driver errror) and many of the current low risk (high profit) drivers will switch to automated cars. Therefore the manual cars will be more complex/specialised for the insurance industry, probably be driven by people who are higher risk takers (they've rejected the safer option), and are more prepared to pay for the privilege (they obviously love driving enough to value it higher).

At first the difference may not be substantial - except due to subsidies from the automated car manufacturers to pursuade people to buy the car, in fact I wouldn't be surprised if they offered to self insure them for free/part of the rental cost. Over time the number of manual drivers will decrease (why pay expensive driving lesson fees) which means the size of the pool decreases meaning higher overheads and more conservative pricing models.

The Mole

Re: Obviously the solution is....

I think what they actually meant to say is ban the manual driving of cars on the road. Not necessarily ban the ability to drive manually off public highways (or in emergency).

Hehe, still writing code for a living? It's 2018. You could be earning x3 as a bug bounty hunter

The Mole

Re: Worth it?

Agreed, my experience is the skills of a 'median' developer are rather mediocre and are unlikely generally to be able to find any bugs eligible for bug bounties. On the other hand the median skills of a bug bounty hunter who has successfully managed to claim at least one bug bounty (let alone be able to make a living out of it) are likely to be at least 2.7 times better, if not more...

Biggest vuln bombshell in forever and storage industry still umms and errs over patches

The Mole

Re: The security folks will say...

It also depends on what access the ssh into the shell gives you. If the only users have system level access (not necessarily root but perhaps same user that all the appliance apps run at) then at that point you've lost. As you and others say meltdown/Spectre is irrelevant as they already have all the access they need. The additional risk of Meltdown is negligible and the cost in terms of performance is high.

UK's Just Eat faces probe after woman tweets chat-up texts from 'delivery guy'

The Mole

Why? The delivery driver works for the restaurant he should be no less trusted than any other member of the take-away. Considering how busy most take-aways are I'd much rather the driver had my number to directly call me then than to spend 20 mins trying to get through to the restaurant to ask which house is mind, for them to call me, then call the driver back and give a garbled message. If you don't trust the driver then you probably shouldn't trust any of the restaurant staff and not give them your number at all.

UK Data Protection Bill tweaked to protect security researchers

The Mole

The problem is that this is hard, very hard.

Take for example of only including the first half of the postcode, that's pretty anonymous, unless of course you have multiple postcodes (home and work, home and holiday home) at which point you will start getting unique or near unique combinations - particularly when you start adding year of birth in.

In isolation that data set may not be a problem, but combined with another one (land register maybe or just knowledge from facebook/friends) you can start to identify some classes of people.

With those people you may then be able to de-anonymize your health provider location (presumably it is a consistent mapping otherwise it is useless), at which point you can then start to identify more people.

Your main point is correct though, unless it has been successfully aggregated and combined much of data should just not be passed.

Yahooooo! says! its! email! is! scrahoooo-ed!

The Mole

Mostly as I have had it for the same amount of time as you (that's now the majority of my life), it does the job (most of the time), is free and I can't be bothered to change given the number of logins that I'd have to update.

Take notebooks: About those new Thinkpads...

The Mole

No difference in data transfer speeds, the SD caddy is purely cabling making the pins of the micro SD card bigger, no additional electronics involved. Now finding the micro card, finding the caddy, putting them together putting in camera, taking photos, taking out micro card on the third attempt, dropping it, finding it again and putting in laptop is likely to take much more time.

Probably better just to give up and just stick a USB cable in the side of the camera.

Microsoft offloads networking to FPGA-powered NICs

The Mole

Machine spec?

Without knowing the spec of the machines the boast is meaningless.

If there is just 1 or 2 CPU cores then the claim is fairly impressive. If they have 24 cores available then it is pretty atrocious.

Fridge killed my baby? Mag-field radiation from household stuff 'boosts miscarriage risk'

The Mole

But did he give birth? No in which case obviously your anecdote proves that he must have been having miscarriages and that the study is accurate.

Or perhaps he would have lived even longer without ionising radiation or been able to be trained to poo where you wanted him to.. we just don't know.

One more credit insurer abandons Maplin Electronics

The Mole

What amazes me is that despite years of problems they still have so towns and cities with multiple stores in them. Places like Southampton really aren't big enough too need two stores, particularly so close to each other, I'd be amazed if either are making a profit. I really don't get why the owners haven't done a round of store closures to remove the duplication.

Erase 2017 from your brain. Face ID never happened. The Notch is an illusion

The Mole

Re: I'd happily own a phone

No that was almost certainly done with the ambient light sensor rather than a full camera

What will drive our cars when the combustion engine dies?

The Mole

Re: Just popping down the battery station for some half dead flowers

The difference is that filling stations will keep a stock of batteries and therefore don't need to recharge them quickly, they can take advantage that the demand for replacement batteries is lower over night or on different days and therefore charge them at a much slower average pace - and probably include doing it with intermittent local power supplies such as wind/solar when available. They also have the option of shipping a new container worth of batteries in if they can't keep up with demand.

Still lots of challenges, not least that with petrol you get consistent mpg from each tank, where as mpb (miles per battery) will vary depending on the health of the battery which makes big issues for billing and user experience.

As Apple fixes macOS root password hole, here's what went wrong

The Mole

Re: Everyone hyping - slow down a little

This doesn't create a new user if the user doesn't exist. What this code is is migration code.

First it checks the newest format password database, if the entry isn't there it checks the old password format database, and upgrades the account password to the new database.

Unfortunately there is a bug that if the password wasn't in the old password database it still does the upgrade with whatever was passed in, which is rather stupid, but isn't the same as creating a new user.

Parity's $280m Ethereum wallet freeze was no accident: It was a hack, claims angry upstart

The Mole

Re: The Blockchain

Because of all the other transactions by other people that have happened in the meantime, you would wipe out all those transactions as well which is going to cause even more confusion. The 'chain' in blockchain is the key word, each transaction is linked to the last so you can't manipulate previous transactions.

Would insurance firms pay out if your driverless car got hacked?

The Mole

Re: A one-way street

FUD, but as with most point has a gem of truth that it allows manufacturers to suddenly introduce new 'features' which suddenly cause the vehicle to share new classes of information that it didn't before. But given how much vehicle movements are tracked in the uk perhaps not the biggest worry.

Transparent algorithms? Here's why that's a bad idea, Google tells MPs

The Mole

Re: Walking directions?

That's pretty much what i do whenever i get into a taxi.

Google slides text message 2FA a little closer to the door

The Mole

Re: Slight problem?

For many people android conveniently shows you your notifications (including new SMS messages) on the lock screen - no unlocking of phone or moving of SIM needed.

Jeff Bezos fires off a blue dart, singes Elon Musk and SpaceX

The Mole

You are right, without competition they would make massive really really fat profits. Having two teams competing against each other is actually a great way to add in the level of urgency to get the engineers concentrating on what needs solving better (and not gold plating) you also potentially double your chances of it working and not ending up down an expensive deadend - afterall look how well Nasa has done getting us out to space quickly in the last 20 years...

Didn't install a safety-critical driverless car patch? Bye, insurance!

The Mole

Re: Credentials

Well considering how much money they charge for the 'real' work I imagine the gaps between cases whilst they wait to find the next whale are more than ample to fit in becoming an 'expert' on this subject!

The Mole

Will there ever be vehicles driving itself?

"a vehicle is "driving itself" if it is operating in a mode in which it is not being controlled, and does not need to be monitored, by an individual"

Whilst sounding like a definition it fails (at least in this part) to actually define anything.

If I tell my car the final destination does that mean I'm controlling it? What if mid journey I tell it to adjust the route to avoid traffic am I now controlling it? What if there is a button to hint it changes lane as that one looks like it is going faster?

What if there is a dashboard indicator 'take manual control' that may flash (or with alarm bells etc) if the car decides it needs human intervention due to an unexpected situation (poor weather, sensor failure, aliens on the road). Even if it only happens once in 10000 miles is the mere possibility of it happening and the requirement to monitor for it occurring sufficient to mean that the car 'needs monitoring' by an individual?

Smartphone SatNavs to get centimetre-perfect GNSS receivers in 2018

The Mole

The reason your sat-nav does that is because at speed the accuracy of gps can easily be +-50m and so it simply doesn't know reliably whether you actually have left the motorway or not. If the accuracy is reduced to +-5m at speed (>1m level when stopped) then it can much more reliably tell the difference between being on the slip road compared to being on the motorway as the hard shoulder/verge now provides sufficient separation of the error radius.

123-Reg customers outraged at automatic .UK domain registration

The Mole

And of course it really does depend what the question is. "Are you concerned about the fact that if you didn't register your .uk domain name then a competitor will steal it and post such terrible stuff on it that the PR backlash will drive you bankrupt in HOURS!?"

- Yes I'm really scared

- No I'm a terrorist sympathiser and that is perfectly fine

It's official: Users navigate flat UI designs 22 per cent slower

The Mole

Re: A serious question.

The simplest example is rather than having a button which is 3d shaded to make it clear and distinctive that it is something special you may click on, a 'flat' design may just have a box surrounding the text which may (if you are lucky) change colour if you hover the mouse over it to show you can interact with it (particularly good when you are using touch screen style of interface). Of course other objects may also have boxes round them, or they may decide the box can be removed just leaving the text that changes colour when you realise you might be able to click over it. Similarly a flat webpage may choose to style a hyperlink so that it isn't underlined, isn't in another colour, if you are lucky it may be bold/italic but possibly only if you hover over it. Or a collapsed tree may not show any sign that it is collapsed, other than maybe the text being bold until you click on it and realise you can expand it.

Basically flat is removing any visual indicators to make it look 'clean'

DJI strips out code badness, reveals some GPL odds 'n sods

The Mole

You do know that remote control model planes have been available for decades don't you? And that building a drone from scratch with a few motors, arduino and gps module isn't exactly difficult.

If it doesn't make a blind bit of difference to the negatives happening then why punish everybody else?


Biting the hand that feeds IT © 1998–2019