* Posts by Darth Poundshop

9 publicly visible posts • joined 10 Jun 2016

Brit MP Dorries: I gave my staff the, um, green light to use my login

Darth Poundshop

Re: Yet if any other civil servant did this

Exactly - I've know people fired from the NHS for this.

The cat that Dorries has let out of the bag is the admission that when you write to your MP regarding anything from matters of national security to fighting extradition to medical matters - anything - it could be read by absolutely bleeding anybody they've shared their password with, or anybody they in turn have shared the password with and so on. And they all think it's OK!!!

It's astounding...I think we all know it goes on, but to hear the sheer flippancy of the MP buffoons is jaw dropping

Darth Poundshop
IT Angle

Re: I don't understand this

"And these are the people who want to legislate as to whether we can use strong encryption. What the fuck is going on in their minds?"

Party politicians don't have 'minds' they have 'hobbyhorses' and 'spin'

Darth Poundshop
Flame

AAAAAAAAAARGAAAAAAAGAHHH

...AAAAAAAAAARAGAAGGAGGGHHH

THESE PARLIAMENTARY DIPSHITS MAKE LAWS...AND DECISIONS ON NATIONAL SECURITY...AND ARE IN CONTROL OF BILLIONS OF OUR MONEY

I can't take it any more, we might as well put a President Putin statue up in Trafalgar Square right now

AAAAAARARARRAGGGH

Looking for scrubs? Nah, NHS wants white hats – the infosec techie kind

Darth Poundshop
Facepalm

Re: Here we go again

Yes and no. It can be done honestly - in effect, our IG Team ask something like 'can you give us evidence of patching and update regime working'. IT, quite honestly, then supply them with the requested evidence. The auditors then check the IG Toolkit submission against the provided real-world activities and Behold! It's a Pass!

However, if IG came to IT and asked, 'can you give us evidence of where you're patching and update regime is catastrophic', IT would be able to supply this just as easily.

In short, auditing is not pentesting, they're all just looking where the light is.

So long – and thanks for all the phish

Darth Poundshop
Unhappy

Re: Phishing Emails

The theory, at least in part, is that we collect phishing emails to try and monitor the volumes or patterns of attacks, whether any particular person or department is being targeted, whether there is any useful information in the headers (e.g. one time we were able to let an IT company know that one of their servers had been compromised) and pass the information to the police as evidence. Also, we can use the email dialogues, between scammer and victim, in our training.

Of course, this being a department within a well known public body, where IT Managers are not chosen either by IT expertise or management skills, the above theory and actual practice seldom coincide.

Regulate, says Musk – OK, but who writes the New Robot Rules?

Darth Poundshop
FAIL

Yep

The actual recipe for AI is 10% statistics, 20% snake oil and 970% media hype.

Also, trying to apply 3 or 4 ridiculously simple laws (wishes, more accurately) to autonomous systems won't work, whether they're a robot, a corporation or any other kind of complex cybernetic entity - "Hey, petrochemical corporation - don't harm humans or by your inactions allow harm to come to humans".

Yeah, that'll work.

Google's Deepmind NHS deal 'inexcusable', says academic paper

Darth Poundshop

The NHS Cash Cow

The NHS herbivore is a constant victim of predatory commercial interests and this is no exception. NHS managers just don't have a mindset that understands the motivations of greedy corporations and how self serving they really are. This is how, anecdotally, we end up paying £45 for a £3 keyboard or get into a £15000 contract for a poxy photocopier. And letting the likes of Google have access to extremely valuable NHS data, that is virtually unique in the world due to the size of the data sets - for free. They should pay what it's worth - millions (assuming the true owners, the patients, are happy to approve). The Google counter argument would probably be that their work will contribute to our health. Google, I'd rather the tax that you should be paying went into the NHS, that would be a hell of a lot more valuable than your imperialist expansion into our data.

EE slapped with £2.7m fine by Ofcom

Darth Poundshop
Devil

A truly lousy company

...that has nothing but disdain for its customers. They helped themselves to money from my bank account and when challenged said that I 'must have clicked on something'. Yet when I asked for evidence, they couldn't provide any at all - just passed me off to their colleagues at Buongiorno who argued that I must have clicked on 'something' but couldn't (or wouldn't) provide any evidence of exactly what. The idea seems to be they take your money and pay it back if you notice. I got my money back, but if you search for the Buongiorno/B!Games/EE Scam you'll see they've had this racket going on for years. For some reason, Ofcom don't seem to think it's anything to do with them

China pledges tighter privacy as it centralises personal health data

Darth Poundshop
Big Brother

Compare and contrast...

China - Government taking control/responsibility and creating a coordinated, integrated national system for social good (and government intelligence)

UK - Government devolving as much responsibility/accountability as possible and creating a disjointed, fragmented system for the benefit of private companies (and corporate intelligence)