* Posts by Brian Scott

33 posts • joined 13 Jun 2007

systemd'oh! DNS lib underscore bug bites everyone's favorite init tool, blanks Netflix

Brian Scott

Underscore?

I thought underscores were illegal in DNS names. I know Microsoft had other ideas in the distant past but now even they frown on them. Why the hell are netflix using them?

Oh, and to echo everyone else: why is an init process doing DNS resolving? An init process should start things and possibly stop and/or monitor them. The tool to do DNS resolving is a DNS resolver. I would be very upset if my DNS (unbound and bind depending on system) resolver started starting processes. The reverse also applies. FFS.

46
0

Git fscked by SHA-1 collision? Not so fast, says Linus Torvalds

Brian Scott

Good software design

The key here isn't whether sha-1 should be used in git in the first place.

Good practice in designing security software should acknowledge that after some time all of these things become obsolete so you need to design in a framework that allows you to easily migrate to future algorithm when the need arises. Baking sha-1 into the design is a mistake if it is then too difficult to change.

Other than that,there is no particular reason to be worried about sha-1. It's just another warning shot to not use it in new products and to start looking at how to turn it off in existing software. This should be simple with well designed software.

9
0

Researcher reports XSS hole in Google France

Brian Scott

"Cupertino slings quick fix."

Isn't that another mob?

4
0

Having offended everyone else in the world, Linus Torvalds calls own lawyers a 'nasty festering disease'

Brian Scott

Re: Easy to get rid of the lawyers

I think that Linus thought the GPL was just like BSD. He now seems to defend the rights of business to use Linux any way they want, without interference from lawyers. That's the BSD model that he probably saw earlier in life.

Mind you, there are probably ways that you could move Linux to a BSD license if they really wanted to but why bother. There are plenty of good operating systems out there with a BSD license on them already.

If Linus really believed in the GPL (perpetually free software) he wouldn't be keeping the whole shooting match licensed under the very outdated and full of holes GPLv2. The GPLv3 does a much better job in the 21st century and other projects have easily migrated to it. Blame the contributors perhaps (contributions under GPLv2, blah, blah, blah)? No, I think that's just a nice scape-goat for keeping it all as BSD like as he can get it.

Remember that it was Linus (I presume) who dropped the 'and later versions' clause from the licensing clause on Linux and created the whole license mess that people are now fighting over. I can't help but think if he had talked to some good lawyers way back then, the world would be much simpler now.

2
5

IBM makes meek apology for Oz #CensusFail, offers no fail detail

Brian Scott

Re: Meh

Geo-blocking DNS? WTF? That's just being stupid.

I saw a lot of screen shots in the media that were actually DNS failures. That explains something I suppose.

0
0

Let's Encrypt in trademark drama

Brian Scott

Law vs. Ethics

I would have expected a Certification Authority to behave ethically as part of its business model.

For the CEO to claim that they were just operating within the law and that this is the cut-and-thrust of business shows that they have confused the two concepts of law and ethics. What they are doing may well be legal (I am not a lawyer, etc) but stealing a name from a non-profit is in absolutely no way ethical.

The list of trusted root authorities in our browsers represent the companies that we trust to a very high standard to make our decisions on the authenticity and legitimacy of domains on the Internet. I expect them to do this both within the bounds of law and with a very high degree of ethics.

A legitimate approach to this would be to remove Comodo from everyone's list of trusted certificate authorities since they clearly are not living up to the high standards demanded of them.

They would then go out business because internet sites could no longer choose to use their now untrusted certificates.

This is business comodo. Sorry to see you go. Don't slam the door.

13
0

Take that, Mom! Turns out Super Mario Bros was all about solving complex math problems

Brian Scott

This is like saying my dog can solve quadratic equations because it can catch a ball.

18
0

Apple assumes you'll toss the Watch after three years

Brian Scott

MacOS

It could just be my old, faulty memory but I thought MacOS was the predecessor of OS/X. This would put the last release (Mac OS/9) somewhere around the turn of the century. I'm too lazy to look it up exactly but that would mean it was all obsolete about 10 years ago.

I don't know anyone still running a pre-OS/X mac. I have one (Mac plus running OS/7) but I certainly don't fire it up and do work with it. It still works though.

0
0

Verisign warns new dot-word domains could make internet unstable

Brian Scott

Re: telling quote

I'm guessing that the available namespace for private networks is now reduced to rude words. This could go do well in some workplaces.

2
0

It's almost time for Australia's fibre fetishists to give up

Brian Scott

Fibre? Copper?

Wow. I'd very happy to have either copper or fibre.

My NBN future (guessing at least the next 10 years) will be wireless delivery. I'm really looking forward to that like a good toothache! Of course at the moment I'm stuck on ADSL 1 unless I switch over to BigPong so maybe I shouldn't complain too much. Friends who have ADSL2 in the region tell me that they are going to be moved off that to wireless in the long term.

A contact doing nbn installs suggests that they are really not very interested in anything other that wireless because it avoids playing in pits.

I'm not sure where they would be bothering to install this stuff. It might just be Malcom Turmbull's place.

2
0

Boffins brew TCP tuned to perform on lossy links like Wi-Fi networks

Brian Scott

Broadcast?

"As an example of how TCP congestion control can get in the way of network performance, the paper cites a broadcast of two packets to multiple receivers:"

I think I see a problem here... (hint for non-network people: TCP is very strictly point-to-point not broadcast).

In fairness I couldn't find the word broadcast in the original paper, on the story.

2
0

Google devs: Tearing Chrome away from OpenSSL not that easy

Brian Scott

"In response to the Heartbleed debacle, a group of NetBSD developers created an OpenSSL fork called LibreSSL."

Actually, that's OpenBSD not NetBSD. OpenBSD forked from NetBSD a long time ago. They have a bit of a history doing this.

1
0

Microsoft admits it's '18 months behind' with Windows 8 slabs

Brian Scott

"But UK director says 'iPad will become marginalised'"

He's right. Eventually the iPad will be marginalised.

Something else will be the next big thing and by then Microsoft might have a competitive tablet OS and no one will care.

If Microsoft wants to survive they need to work out what the next big market will be and start working towards that. They also need to shake the belief that the answer to everything is Windows. It may be that no one will want to buy Windows for Underpants.

The iPad really is crap in an enterprise environment and there may be a few bucks to be made building something better for that market. Unfortunately there wont be big money in it, just a few crumbs for the companies still hanging around in that space.

0
0

Free cloud server self-destructs in 35 minutes

Brian Scott

Re: MiB?

But not GiB.

They've only partly gone over to the dark side.

2
0

Lots more virtualisation, cloud, added to TAFE courses

Brian Scott

Re: Wrong, These are NEW units.

I apologise. It looked like a late announcement for the existing units. I look forward to reading the new units when they become available.

0
0
Brian Scott

Um, sorry about your slow news sources. ICA11 was published in 2011.

This is the second year that we (a TAFE in regional NSW) have been using these units.

0
0

You can help fix patent laws … now!

Brian Scott

Re: I hereby patent making sarcastic article titles

"*No right to hold a patent unless the holder actually uses it."

So I presume in your grand plans if a company were to design processors but not manufacture them, then they shouldn't be able to license others to do the manufacturing (i.e. make money off their design work).

Seems to me that many companies have a valid reason to patent things but not manufacture them. Perhaps the test should be whether they are actively trying to entice others to license the designs.

1
0

Chrome 9 debuts with WebGL, app store, instant annoyance

Brian Scott

Installation still broken?

I presume the installer is still incapable of working if you're behind a proxy. When I've tried to install it on a work machine, the little installer would immediately die because it was incapable of navigating a proxy server (presumably to keep the installer very small). The only option has been to try to find the download that the installer downloads and bring it down manually. A task that google appeared to definitely discourage.

A lot of work and enough to make me think that it isn't a good fit in a business environment.

Then again, I gave up trying back at about version 3 or so.

0
0

Windows 0day allows malicious code execution

Brian Scott
Headmaster

0 Day?

So, information about the vulnerability has been published, microsoft have been made aware of it, and some time later (guessing > 0 days) we will have exploits in the wild.

How on earth is this then a 0-day vulnerability?

0
1

Google open sources Apache server speed mod

Brian Scott

Open source?

For an "Open Source" project there seems to be a pretty big emphasis on binaries. I suppose the source code is there if you look very hard but certainly not on the downloads page.

Shouldn't this be classed as open binaries?

1
1

Microsoft says XP netbooks die on October 22

Brian Scott

re: Ubuntu Linux Netbook Remix

> looks easier on the eye due to being optimised for low resolution screens

That would be except for the dialog boxes that are larger than the screen. How many tab keys to you type blind before hitting space and hoping you got the OK button and not the cancel button? Its fun to guess (often 2 but 3 needed on network manager) but definitely not easier on the eye or optimised for low resolution.

2
1

Woman called Window joins Apple

Brian Scott

or the very famous...

Robert'); Drop Table Students; --

http://xkcd.com/327/

1
0

Anti-Internet Explorer 6 protests grow with online petition

Brian Scott

SVG

Just a little point in favour of IE6.

The old adobe SVG browser plugin worked with IE6 and gave reasonable results for embedded SVGs in web pages. As I recall, when adobe dropped support for their plugin ("all reasonable browsers have native SVG support built in") some years ago, IE7 and IE8 didn't exist and therefore don't work.

Embedded SVG was a good way to crash IE7 in some quite entertaining ways. I haven't tried it with IE8.

I think microsoft are considering adding SVG support to IE9 or 10, so in the meantime if you must access websites using important internet standards you should either use IE6 and the unsupported plugin or any other browser released in the last 5 years.

0
0

Mozilla lights fire under Thunderbird

Brian Scott

Happily using IMAP with Thunderbird

I've been running thunderbird for a few years now, mostly because their IMAP support is better than entourage or apple's mail. I use outlook at work because of an exchange server but find that its IMAP support is a bit clunky when I connect it up to other servers.

Web based email always seems like the poor cousin of real email clients. Its something you do when you are forced to, not because you want to.

On a command line my preference is for mutt.

Thunderbird hangs occasionally (mostly when I sleep my laptop while its checking mail) but not so much that I care.

I would happily move to a better email client if one existed. If that was Thunderbird 3 then good. If someone else gets their act together then they will get a convert.

As the developers of mutt said "All mail clients suck. This one just sucks less."

0
0

IBM lab builds computerized cat brain

Brian Scott
Headmaster

title

"petaFLOPS per second"

<pedant-alert>

The PS at the end of petaFLOPS stands for Per Second. The additional per second isn't required unless we are dealing with an acceleration (i.e. per second per second). Alternatively you could use "petaFLO per second" but nobody would know what you mean.

</pedant-alert>

Only mildly less annoying than people that drop the final S when there is only of them (e.g. 1 petaFLOP).

0
0

Does the Linux desktop need to be popular?

Brian Scott

@Robert Pogson

"The usability issues are gone on a well-configured OEM installation. eeePC showed that."

Have you ever used the rubbish Xandros install on a eeePC? My wife demanded I fix it within a day of getting one. She is now happily using eeebuntu. I look at eeebuntu and think that it is appalling that many of the dialog boxes are too big to fit on the screen so you have to guess how many times to hit the tab key (to select an unseen OK button rather than the equally hidden Cancel button).

Xandros 0/10

Eeebuntu 5/10

*nothing* gets 10/10

This is meant to be a core market for Linux and they don't get it.

0
0

Researchers forge secure kernel from maths proofs

Brian Scott

Title

Unfortunately a mathematical proof of correctness may prove that some set of known types of bugs don't exist and it may prove that the program actually matches the specification. What it doesn't prove is that the program is what the customer wanted (i.e. the specification is never complete and will change over time so insisting on it being complete and static is a very good way to get a disappointed customer).

Does proof of correctness result in code that is optimally able to be maintained (oops, sorry - if it starts out life correct then it never needs maintenance does it?).

More importantly, our happy user needs to use this kernel to do some real work so they install a web server on it, along with php, then hire a cheap programmer that has read a book on PHP to write applications for it.

The eventual end user knows nothing about any of this and compromises the integrity of the system by writing down passwords on sticky pieces of paper or surfing pr0n sites that use have bonus cross site request forgeries embedded in them....

It may be nice to have a more robust Kernel but I think the money would be better spent on researching how to fix the real problems that plague computer systems.

0
0

XML flaws threaten 'enormous' array of apps

Brian Scott

Title

So let me get this straight,

"we tested out some XML frameworks and some of them broke". Good, this is nice to know. Now tell me which ones so I can see if I have a problem. Not telling? The CERN advisory has a very short list but if that is the full extent of what they found then its not much. @Fazal Majid says that expat has a problem - OK, that's interesting to me.

"broke things might run other people's code". True. Do any of these top pieces of software break like that or is this just a statement of general principle? I agree with the principle but not all broken software breaks in the same way.

"here is a list of XML parsing software - we haven't tested most of it but it may all be broken". Or not. I'm having a little trouble with this logic. I want a list of what these guys have tested, not a wikipedia entry on XML.

"We have a piece of software that everyone should be using to test their libraries". OK, now I understand what this article is all about - its an advertisement.

In reality most XML parsing software is regularly tested with broken XML. I do it all the time without even trying. A typo here, a misplaced character there, some broken encoding, whatever. And what happens? I get a message telling me that my XML is broken. Just like it should. Now, if the application using the library is too stupid to realise that something is broken and chugs on regardless then bad things might happen, or if the application lets the library stop the program (very unusual in my experience) then we might have a denial of service attack against the application.

Many applications using XML do so with XML that is completely under control of the software or the local user so there isn't likely to be any direct threat. Its only the applications that process XML from untrusted sources that are at risk.

Maybe not everyone is doomed after all.

0
0

Comcast trials Domain Helper service DNS hijacker

Brian Scott

A good jon for DNSSEC

Roll on DNSSEC aware resolvers and the fraudulent DNS entries for the non-existent domains will result in a local error on the client machine.

Rather than seeing the "Domain Helper" service, users will just see a warning that someone upstream is fraudulently altering their traffic. They will then move to a different ISP to avoid the warning. Eventually the ISPs will work it out or die. Easy.

0
0

AVG scanner blasts internet with fake traffic

Brian Scott
Thumb Down

Not only does it hurt websites and dialup users

I was hurriedly removing this from a friends dialup computer and took the opportunity to trace the network traffic while connected to my broadband connection.

First thing I noticed was a lot of failed POSTs as it tried to tell explabs.net about browsing history. Nice one - people would pay very good money to AVG for this information. Hopefully they have a privacy policy (haven't checked) but it does go over the internet in clear text so it cause save your ISP some trouble. This can be turned off during installation.

What worries me is that it uses 'Cache-Control: no-cache' on its requests. This means they are also causing proxy servers to do more work downloading content. OK, not everyone has a proxy on their home network but I notice that my ISP has a transparent proxy and it must be wrecking their links.

0
0

World economy group gives IPv6 big push

Brian Scott

Re: Death of IPv4??

Actually, I saw a paper a while back explaining why IPv6 addresses would run out much sooner than expected. I forget the details but my understanding was that it was caused by stupid administrative practices.

By convention, the bottom 64 bits is made up from a slightly modified version of the MAC address of the network interface, thus every network is automatically provisioned to be able to have every network device in the whole world connected to it at once. This is possibly overkill.

ISPs would give out /48 addresses so you can do your own subnetting (16 bits, 65536 subnets - should be enough, even for me). We are now down to 2**48 possible connections to ISPs.

The addresses available to an ISP are part of an allocation sold to their upstream providers, and so on up the pole. Everyone in the chain needs a sufficiently large allocation of subnets that they wont run out any time in the future.

I think that this sort of thinking is very similar to the old 'give everyone an A class address so everyone will have lots of flexibility' thinking from the dawn of the internet. We all know the mess that caused when more than 125 companies wanted to play.

IPv6 was never designed to have 2**128 devices connected. The fact that it has 128 bit addresses leads some people to draw the wrong conclusions.

I run IPv6 at home with no thanks to my ISP or router vendor. The only advantages at this stage seem to be the swimming turtle at www.kame.net and learning about something that everyone else will be learning in a hurry in a few years time.

0
0

Patent law passed in US, but Presidential veto could follow

Brian Scott

Won't this make things worse?

I could have misread it but doesn't "first to file" mean we will get a lot more patents for things that are blindingly obvious and in common use just because no one has tried to patent them before? Has breathing been patented or will someone (having read my post) be "first" to file?

It seems to me this only benefits the big companies that can generate patents everytime someone on their payroll has an idea. The rest of us loose out because we don't have the budget to get patents for everything we do - to date we have believed that prior art protected our use of our ideas from subsequent patent applications.

0
0

Apple's Safari 3: a crashing experience for non-US users

Brian Scott

Proxies

I tried it but it crashes. It looks like it can't handle our local proxy setup (configured through a proxy script and then authenticated with NTLM) so it crashes. The only work around seems to be to not load any web pages - not really a viable option for a web browser. You can't turn off the proxy settings (as someone pointed it it just uses IE's settings and my settings at work are locked done by group policy) so I can't even test it on local content. I think the most remarkable thing about this is the complete lack of feedback channel for me to point his out to apple. I'm happy to regard it as a beta and send back feedback but it seems odd to only want feedback from people that it works properly for.

Anyway, its obvious that this is being rushed out because it (or the webkit component) forms some key component in the new version of iTunes for Vista so they need to get most of it working on windows anyway.

0
0

Forums

Biting the hand that feeds IT © 1998–2017