* Posts by EnviableOne

2001 publicly visible posts • joined 28 Jan 2016

DoE digs up molten salt nuclear reactor tech, taps Los Alamos to lead the way back

EnviableOne

Re: Where to Begin

Bill Gates and Warren Buffet are:

https://www.theguardian.com/us-news/2021/jun/03/bill-gates-warren-buffett-new-nuclear-reactor-wyoming-natrium

FTC ponders proper punishment for commercial data 'surveillance' and shoddy security

EnviableOne

Re: 2018?

The original act was the Data Protection Act of 1984

Followed by the Access to Personal Files Act 1987

Then the Data Protection Act 1998 based on the EU directive 95/46/EC

Then the Privacy and Electronic Communications (EC Directive) Regulations 2003 based on 2002/58/EC

Then the DPA 2018 based on the GDPR

In tandem, the Uk started the information security standardisation by developing BS 7799 which evolved into ISO/IEC 17799 that then became the ISO 27001 that we all love

Microsoft tightens Edge security for less visited websites

EnviableOne

Re: That's a nice little website you have there,

like their dominant position in the OS market...

Clean up orbit first, then we can think about space factories, says FCC

EnviableOne

Re: "has the potential to [..] mitigate climate change"

if you can build a static platform in geostationary orbit, you can build a space elevator and do away with all that explosion and death, and nanotubes might just provide the required strength.

EnviableOne

Re: Big problem with limited solutions

looking at the remnants, it appears this may have already happened on Venus, and once earth is finished with, mars will be next...

Yeah, we'll just take that first network handshake. What could possibly go wrong?

EnviableOne

Re: The guiding principle

Surely this is a Qbit.

1,0 or something

maybe a QuantumBoolean or Qlean

EnviableOne

Re: You'd have thought that a company the size of Google would have thought...

yeah but they have the pennies to pay for someone to catch these issues, most of us don't.

The problem is they choose to give those pennies to CXOs or shareholders rather than spend them on making stuff that, you know, works.

Also chances are the code comes from some of us that didn't have the bandwidth to deal with the bugs, but contributed it to some OSS or forum to prove a point.

Nancy Pelosi ties Chinese cyber-attacks to need for Taiwan visit

EnviableOne

bare faced cheek

If Xi wants the world to stick with the "One China" doctrine

why can't he stick to the "One Country, Two Systems" doctrine in Hong Kong

Major IT outage forces UK emergency call handlers to use 'pen and paper'

EnviableOne

Adastra is used by many Ambulance services and Out of Hours doctors too...

not what the NHS needs right now...

Post-quantum crypto cracked in an hour with one core of an ancient Xeon

EnviableOne

to be fair KU Leuven have some chops when it comes to finding vulnerabilities.

they are responsible for Plundervolt, Foreshadow and Krack

they have also displayed vulnerabilities in wearable medical tech, keyless access systems and many others.

Browsers could face two regimes in Europe as UK law set to diverge from EU

EnviableOne

The German government acting in its capacity is able to change the german constitution or initiate actions to that effect, very much "Intra Vires" as in within their power.

This does not affect the previous decisions of the court which are and will continue to be valid under the constitution at the time, but the representatives of the german Volk can and should be able to amend the constitution applying to them.

Twitter launches probe after miscreants claim to have swiped 5.4m users' details

EnviableOne

As always

"As always, we're committed to protecting the privacy and security of the people who use Twitter"

if people were actually committed, there would not be an issue with privacy or security

Windows Start Menu not starting? You're not alone

EnviableOne

Re: Jeez - KIR

It's an admission of failure. we get this wrong so often that we will put code into the product to roll back any change we make, that break things, just so we can keep releasing rollups and not individual patches.

Outlook email users alerted to suspicious activity from Microsoft-owned IP address

EnviableOne

Re: Dumbf***ery abound

running FF ESR with uBlock and NoScript and no adds ... no need for added complexity of pi hole

China seems to have figured out how to make 7nm chips despite US sanctions

EnviableOne

Re: "Close copy"

what people are forgetting is that TSMC have several fabs on the Chinese mainland, namley shanghi and Nanjing

the CCP have eyes and ears in the systems.

Hospital IT melts in heatwave, leaving doctors without patient records

EnviableOne

Re: How is this the fault of "Legacy Systems"?

The NHS dont pay for that, theirs board bonuses to think about

Ex-Coinbase manager charged in first-ever crypto insider trading case

EnviableOne

the point is the dollar and the pound are not backed by gold silver or anything else, just like cryptocurrencies.

The UK won't go to war to protect the value of a pound; if they did, the value of it would fall considerably, the same as the dollar...

both central reserve banks have been creating their respective currencies out of thin air in their trillions, in the process of quantitative easing, that has been going on seriously to get the markets out of the 2008 crash.

I fail to see the reference to the film, about an anti-soviet conspiracy controlled by a computer.

Personally, I see all currency as a bad investment and turn cash into something tangible at the first opportunity.

I was pointing out the fact so-called "real" currencies are just as vulnerable as crypto, look at the countries that have revalued their currencies in recent years, compared to the amount of crypto that has failed.

The Venezuelan Bolivar in 2018 and 2021, the Belarusian Ruble in 2016, the Turkish lira in 2005, the multitude of re-valuations for the Zimbabwe dollar between 2006 and 2009, the Italian lira was on the verge of a re-valuation when the euro came in.

EnviableOne

just like the global currency market they are imitating

The USD, GBP, etc. are all just as intrinsically valuable as BTC, ETH, XMR etc.

they only have the value we collectively decide they do.

USD and GBP are not, despite public presumption, backed by anything.

Huawei under investigation for having tech installed near US missile silos

EnviableOne

Huawei kit is cheap, easy to buy (their finance terms are amazing) its more efficient and less power hungry than the Ericsson, Nokia and Samsung kit and was basically taking over the RAN market

The security issue was moot, the HCSEC the GCHQ offshoot that has oversight of all Huawei kit deployed in the uk, its source code and hardware, has said their coding is so auful and their software standards so bad, that if there were CCP back doors they were indistinguishable from the exploitable bugs in the code that was exploitable by everyone else. This assessment was freely available to all in the US of A and any other of the Five nations separated by a common language.

so basically Uncle Sam shot himself in the foot and the rest of us along with him, causing us all to either keep the cheap kit flowing with the company's stability (due to it no longer being able to get US components) being shot, or rip and replace with inferior more expensive kit

Is Microsoft going back to the future on release cadences?

EnviableOne

Re: Stability is something that has been missing from the Windows world for some time.

Windows 98 SE SP5 FTW!

peak windows, stable as anything and has USB support

Microsoft Teams outage widens to take out M365 services, admin center

EnviableOne

try literally any other collaboration tool.

You'll find that Lync For business AKA teams, is clunky resource hogging and lacking in functionality

Webex, Zoom and Slack are the big guys, but a myriad of smaller providers provide similar or better services at a better quality.

The problem is, as with Excel, "Everyone" uses it, and it's "free" (Included) with your O365 costs, so the PHB and finance wonks, refuse to pay for something that's better because it is good enough...

Amazon buys US healthcare chain One Medical for $3.9bn

EnviableOne

Re: It now owns your store, your doctor, and your shopping history. What's next?

UnitedHealth Group already bought EMIS, which has the Data of 60-70% of UK GPs surgery and a direct API to TPP that have the rest.

British intelligence recycles old argument for thwarting strong encryption: Think of the children!

EnviableOne

UN Declaration of Human rights Article 12

No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.

They all signed up to it, its up to them to abide by it

EnviableOne

Re: Quite apart from online...

Churchill also said "Representative democracy is absolutely the worst form of government, except all those other forms of government we have tried from time to time"

in other words, the system is not perfect but its better than what came before

Security flaws in GPS trackers can be abused to cut off fuel to vehicles, CISA warns

EnviableOne

Re: So basic ---- still!

I am starting to wonder wy OWASP publish the top 10, the original and latest are for the want of a bit of re-phrasing the same issues

Sage accused of strong-arming customers into subscriptions

EnviableOne

Re: Proposal

Never going to happen, Open source only goes so far, until someone forces you to pay for secret sauce

SoftBank reportedly moves London IPO out of Arm's reach

EnviableOne

Re: Trade dispute...

as i said about 5 months ago now:

depends where they list it

New York - Great for US companies

London - Vote of confidence in Post Brexit Britain

Frankfurt - Vote of confidence in Europe (no-confidence in Britain)

Hong Kong - Bad for the US, Good for china

Tokyo - Where SoftBank is at, probably the best neutral location.

but all of them will be competing, and it might end up dual listed

Microsoft's latest security patch troubles Windows 11 users

EnviableOne

Re: "This update is just awful."

the difference is Apple have a test and quality control team that fixed the bugs in the beta.

and it was at least called a beta, rather than a release.

Intel tried selling software before. Will it succeed this time?

EnviableOne

that was Jobs, and how he worked.

Apple is now basically a marketing machine that makes it look like their next minor innovation is gods gift to technology, even though Samsung, Sony or google did it 5 yrs ago

Torvalds: Linux kernel team has sorted Retbleed chip flaw

EnviableOne
Coat

Re: 5.20 versus 6.0

didnt it go up in a puff of smoke...

60 million in the Matrix as users seek decentralized messaging

EnviableOne

Signal + google

might as well use the Signal + Meta integration known to others as "WhatsApp"

EnviableOne
Windows

Teams is "Included" in the solutions businesses already pay for.

Zoom, Webex, Chime, Meet, etc cost on top of that.

Teams like all things Microsoft is full of holes and bloat and its update mechanism looks like an ATP maintaining persistence, but you get what you pay for.

at least its vaguely useable has caught up with most of the features of the easier-to-use systems, doesn't make claims that it has security that it doesn't, and is bringing online new features too...

Basically Teams is here to stay, so you are going to have to get used to it

How data on a billion people may have leaked from a Chinese police dashboard

EnviableOne

Re: It's a shame...

this is the reason there are only 1B data subjects, not the 1.45bn citizens in china

Apple's latest security feature could literally save lives

EnviableOne

Re: And the TLAs?

with this SCOTUS, who knows

Marriott Hotels admits to third data breach in 4 years

EnviableOne
Paris Hilton

Re: "red hat"

never heard of red hats (except them that got bought by big blue) before this article,

as far as I was aware hats only came in shades (Black through white) not colours

FedEx signals 'zero mainframe, zero datacenter' operations by 2024

EnviableOne

Re: This from the company...

UPS - Undoubtably Packages Stolen

DHL - Damaged, Hijacked or Lost

TNT - Take Nothing Today

there are a million more of them

Hermes changed there name to the amount of deliveries they fail (Evri)

EnviableOne

Re: "where it hopes to save an estimated $400 million annually"

they are fully aware of how much they rely on IT c.f. Not Peyta and TNT (a FedEx subsidiary)

Apple's guy in charge of stopping insider trading guilty of … insider trading

EnviableOne

Re: Looking at the more general background

to most companies, ethics is a county to the northeast of London

Beijing probes security at academic journal database

EnviableOne

Re: No such thing

there is private ownership, at the discretion of the the CPC

Just ask Jack Ma (Alibaba) or "Pony" Ma (Tencent)

both got hauled over the coals for not doing things the right way

Don't ditch PowerShell to improve security, say infosec agencies from UK, US, and NZ

EnviableOne

Re: Powershell 7.2 improves on 5.1?

the big advantage 5.1 has over 7 is ISE.

Makes getting into PowerShell a lot easier, and means you don't have to have two windows open...

UK govt promises to sink billions into electronic health records for England

EnviableOne

Re: Our data, not theirs to sell

The Lansley reforms brought in by the Health and social care act 2012 broke the NHS into 3000 organisations with their own boards that had to compete with each other and private providers to provide NHS branded services.

these organisations have their own boards of directors getting paid £100k+ each and have no economies of scale or power when negotiating with suppliers.

if you look NHS-wide, this has driven up costs and down quality and support, according to a study released yesterday, this has also correlated with an increase in avoidable deaths

Basically, the NHS is broken and the Torries did it.

Carnival Cruises torpedoed by US states, agrees to pay $6m after wave of cyberattacks

EnviableOne

Re: rotating passwords

a couple more resources to throw at the auditors:

https://www.ncsc.gov.uk/collection/passwords

https://www.ncsc.gov.uk/blog-post/your-password-expiry-policy-may-have-reached-its-expiry-date

https://www.troyhunt.com/passwords-evolved-authentication-guidance-for-the-modern-era/

EnviableOne

rotating passwords

really doesn't work. it just drives bad behaviour (I'll add 1 to the number on the end)

the AGs should really read the NIST SP 800-63b

"Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).

However, verifiers SHALL force a change if there is evidence of compromise of the

authenticator."

Zero Trust: What does it actually mean – and why would you want it?

EnviableOne

Re: Nomenclature

yeah, but let's not start done the acronym reuse in the same space rabbit hole

Just ask a physicist what rho represents.

I still go back to this quote I found somewhere:

Build your network as if the endpoint is owned.

Build your endpoint as if the network is owned.

– @0DDJ0BB

— SecuriTay (@SwiftOnSecurity) November 21, 2015

Halfords suffers a puncture in the customer details department

EnviableOne

Re: Wassat, then?

Pay Peanuts get muppets...

Mega's unbreakable encryption proves to be anything but

EnviableOne
Megaphone

repeat after me

Thou shalt not roll thy own encryption

Wi-Fi hotspots and Windows on Arm broken by Microsoft's latest patches

EnviableOne

Known Issue Rollbacks

This little-known feature is a marvel of their self-doubt

built into the code for every update is an if statement,

if this registry entry is present "we borked it" so revert to the old code.

if it is borked enough for enough people they let you know the entry to un bork

EnviableOne

Re: Testing?

they dont have a QA department, they cost too much...

They should be upfront about it all, rename the company to Beta, and start referring to the plebians who licence their not-so-intellectual property as Testers rather than customers.

Atos CFO to follow CEO out the door following 'Evidian' split plans

EnviableOne

Another capture for DXC?

Looks like the New Atos will be ripe to be eaten by the behemoth of outsourcers and continue to dwindle together.

Evidian on the other hand might be worth investing in

US lawsuit alleges tool used by hospitals shares patient data with Meta

EnviableOne

for those that are not aware, 90% of GPs in the NHS use either Egton Medical Information Systems (EMIS) Health or TPP's System One and its roughly a 50-50 split

Anyone using the Patient Access App is using EMIS.

This is a huge deal, making all EMIS patient data subject to the US CLOUD act.