* Posts by Pascal Monett

16767 publicly visible posts • joined 10 Apr 2007

Quad nations pledge deeper collaboration on infosec, data-sharing, and more

Pascal Monett Silver badge

"the United State in charge of software security standards"

Typical. The USA gets to tell everybody else how to do their job, then sits back and watches the minions scurry.

Why am I not surprised ?

AI-designed COVID-19 drug nominated for preclinical trial

Pascal Monett Silver badge
Terminator

ROTM anyone ?

So it has started. Machines are now designing drugs to be used on humans.

Indian stock markets given ten day deadline to file infosec report, secure board signoff

Pascal Monett Silver badge

Re: Shirley...?

There is a world of difference between securing a network and documenting it, and another world of difference between documenting it and writing a government-mandated report.

I take it you haven't written any government reports. I have written a few (unfortunately), and it is not something I enjoy doing in the slightest.

Pascal Monett Silver badge

And if it doesn't happen in 10 days ?

What if the companies simply don't respond in the allotted time span ?

Is there any hint of a fine anywhere ?

On the other hand, they could respond with a basic report and mention "See Appendix . . ." for all precisions, the appendices being sent 30 days later.

This whole attitude smacks of useless pressure from administrative busybodies who grant themselves a lot more importance than they have.

Businesses don't want to be hacked. Most of them do want to be secure, and a fair proportion of them actually put money on the table for that. The thought behind this new rule may be commendable, but granting a 90-day delay (given that businesses are already on a 60-day delay for something else) wouldn't kill the donkey.

About half of popular websites tested found vulnerable to account pre-hijacking

Pascal Monett Silver badge

The problem is convenience

Sure, it is very convenient to Sign in With FaceBook/Google/Microsoft.

On the other hand, security experts have been constantly repeating for years that you should not use the same passwords for all sites you sign up for.

How does that compute ? It doesn't. Where does that get us ? To this sort of problem.

I never sign up with any 3rd-party identifier. I manage my own passwords and I don't sign up to social platforms (well, Google signed me up for Hangouts when I got my Gmail account, but I'll be damned if I use it).

I'm glad they found solutions to correct the issue, but I still won't use those kinds of services.

Good luck hijacking my 24-character passwords.

Florida's content-moderation law kept on ice, likely unconstitutional, court says

Pascal Monett Silver badge

Technically, everyone.

And everyone sees noon at his own door.

That is why these sort of discussions very often result in screaming matches. Everyone believes they are right, but not everyone can listen to someone else's arguments.

That said, not everyone is capable of presenting a reasoned argument either.

AWS puts latest homebrew Graviton3 Arm processor in production

Pascal Monett Silver badge
Trollface

Take that, you x86 dinosaurs

We can take that. The Graviton3 is not the comet to end all x86s.

Don't worry, we'll still be around for a loooong time.

Beijing reverses ban on tech companies listing offshore

Pascal Monett Silver badge
Big Brother

Xi Pooh has a big problem

His country needs capitalism to progress, because communism has amply demonstrated its dismal failure, but Xi hates money and the power that goes with it because he wants to be the only one with power.

So he enacts decisions destined to beat down any head that rises out of the ranks, which will keep his country's progress hobbled to a rate that he thinks he can manage.

Nvidia brings liquid cooling to A100 PCIe GPU cards for ‘greener’ datacenters

Pascal Monett Silver badge

NVidia has experience with liquid cooling

I have an RTX 3080 and, although you might say that it is air-cooled, there is still a bunch of liquid in there to get the heat from the GPU to the fans.

I wonder how that will work for the datacenter. For the moment, the A100 doesn't seem to be liquid cooled, but it sure is outrageously expensive.

How to find NPM dependencies vulnerable to account hijacking

Pascal Monett Silver badge

"an opportunity to preempt this threat"

Here's another one : don't download anything to your production server before validating it on your test server.

Because you have a test server, right ?

RIGHT ?

Beware the fury of a database developer torn from tables and SQL

Pascal Monett Silver badge

Re: I've heard all kinds of stories like this

On a much tamer note, I know of a database consultant whe had a thing for the name Alice, and tried to shoehorn that name in somewhere every new job he had. That is why there are a number of servers in the world that are probably still named Alice to this day.

South Korean and US presidents gang up on North Korea's cyber-offensives

Pascal Monett Silver badge

"confrontational"

I'll bet he is. He doesn't want to roll over and let the northern lunatic take over the south.

I'd be pretty confrontational too, if I had a dangerous megalomaniac for a neighbor.

US fears China may have ten exascale systems by 2025

Pascal Monett Silver badge

"declined to make public any [..] figures that would demonstrate their true performance level"

And why would China make figures public ?

Much better to keep everybody guessing.

Microsoft patches the patch that broke Windows authentication

Pascal Monett Silver badge

"patches to fix patches seem to be becoming a little too common"

Okay, I'll be the first to admit that networking is not always easy, especially when you're a vendor with an uncountable number of variations to handle.

Still, I stand by the idea that having a Quality Control team to test and wean out the at least some of the problems would go a long way to make these out-of-band patches rarer than they are.

Microsoft Bing censors politically sensitive Chinese terms

Pascal Monett Silver badge

You still can't have your cake and eat it

"an internet platform cannot facilitate free speech for one demographic of its users while applying extensive political censorship against another demographic of its users"

Well, it seems that Borkzilla (et al) must make a choice : either it is for free speech, or it is for raking in the dough in oppressive dictatorships.

It's going to be interesting to see how this goes.

Failed gambler? How about an algorithm that predicts the future

Pascal Monett Silver badge
Coat

Re: Half full or empty

I reject that argument entirely. As far as I'm concerned, if you're asking the question, the cup needs to be refilled.

US recovers a record $15m from the 3ve ad-fraud crew

Pascal Monett Silver badge

Great news

"A little more than half of the illicit proceeds, $15,111,453.84, has since been transferred from Swiss bank accounts to the US government"

So Uncle Sam gets a windfall, but the companies who paid for the non-existent ad views get what ? The satisfaction that that particular crew isn't scamming them any more ?

Cisco warns of up to $720m sales loss: Blames China lockdown, Russia pullout

Pascal Monett Silver badge
Coat

"meaning a drop of $131 million to $720 million"

I would really like to be able to drop my revenue to 5.5 times its current level.

That's a sacrifice I'm willing to make.

Bing! Microsoft tests search box in the middle of Windows 11 desktop

Pascal Monett Silver badge

"while Microsoft plays with the concept"

Microsoft : playing with every single concept it can think of apart from making its OS streamlined, out of the way, functional and fast.

American Airlines decides to cruise into Azure's cloud

Pascal Monett Silver badge

Wait a minute

"speed up bag tracking, enable preemptive rerouting based on weather conditions"

Isn't that stuff they're already doing now ? With computers ? What exactly is the improvement AA is expecting after having spect weeks, if not months, handing their current system over to the single-point-of-failure platform that is Azure ?

And when Azure is down, will that mean that pre-emptive routing will not work, or will AA keep the existing system as an emergency backup (yeah, as if that would happen) ?

Landmark case recognizes Bored Ape NFT as an asset

Pascal Monett Silver badge

BAYC

Oh, those images I can find in an instant on Google Images ?

And some people paid money for that ?

The depth of human stupidity knows no bounds - especially when they're full of money.

Hot glare of the spotlight doesn’t slow BlackByte ransomware gang

Pascal Monett Silver badge

"living-off-the-land binaries"

Now that's new to me. What on Earth is that ? Notepad ?

Google Russia goes broke after bank account snatched

Pascal Monett Silver badge
FAIL

Re: woke-global-climate-change-bullcrap

You can beat that drum as often as you like, the climate is still changing.

Microsoft-backed robovans to deliver grub in London

Pascal Monett Silver badge

What's the bandwidth on these things ?

A terabyte of data every minute is a rather tall order to transmit via WiFi, even with 5G. Also, 60TB of data is one heck of stack of hard disks to put in the trunk (or boot), and driving for one hour is not all that uncommon. What is the data retention policy ?

So how is the car linked to the Azure server, and what is being sent/received ?

Also, when the learning phase is over, what kit is going to be left in the cars ?

Voyager 1 space probe producing ‘anomalous telemetry data’

Pascal Monett Silver badge
Boffin

"Voyager 1 is now 45 years old"

Dear me, and they're thinking of doing a software update with 160b/s of bandwidth ?

Yikes.

Some people are really hardcore.

Your snoozing iOS 15 iPhone may actually be sleeping with one antenna open

Pascal Monett Silver badge

"wireless chips can no longer be trusted to be turned off after shutdown"

So it is true, the mafia types are right to put smartphones in lead boxes when they meet.

Apple scraps 3-day return to office amid COVID-19 cases

Pascal Monett Silver badge

"not everyone is yet ready to return to the corporate altar"

No kidding.

The one good thing about COVID is that it has amply demonstrated that going to the office is not a requirement to being productive.

Oh sure, for the insecure managers who like counting heads, yes, having all your minions on hand must be very satisfying indeed, but unfortunately, your minions have worked off-site for almost two years and productivity has not gone down.

You're going to have to live with that fact now.

China's vice premier Liu He advocates technology and government cooperation

Pascal Monett Silver badge
Big Brother

"Liu He advocates technology and government cooperation"

Of course, when he says "cooperation", he means "do as I say and you can continue functioning".

Microsoft warns partners to revoke unused authorizations that drive your software

Pascal Monett Silver badge

You don't want that.

Think about it for a minute : why are you authorizing remote access to a 3rd party in the first place ? Most likely, it is because they have the special proficiency you are lacking in your own workforce. That means they'll be coming in with near-admin level privilege. You want to be able to track that, and you don't want to give admin access to someone who clearly will never need it.

Create a specific user for that specific access, and log the interactions. That way, if something fishy happens, you either have proof of origin, or proof that you need to look somewhere else.

China’s COVID lockdowns bite e-commerce players

Pascal Monett Silver badge

Beijing continues to crack down on complaints

And it will have to continue even more, because when people are not happy, they complain.

I would say : instead of cracking down on complaints, listen to them and mend your ways, but this is Beijing. Beijing does not mend its ways.

Monero-mining botnet targets Windows, Linux web servers

Pascal Monett Silver badge

Re: Linux as a target? But is this really the case?

You might be right, but you should avoid thinking that Linux is impervious to infection. Privilege escalation exists, even in Linux world, and malware is capable of taking over a Linux box.

As usual, proceeding with caution is always a good thing.

Surf the web from your parked Renault: Vivaldi comes to OpenR

Pascal Monett Silver badge
Coat

"seven times smoother"

Must have been a really bumpy ride before.

Google keeps legacy G Suite alive and free for personal use

Pascal Monett Silver badge

Office 365 Family is $100/year ?

Dear God, to think that LibreOffice is free.

Infosys skips government meeting – and collecting government taxes

Pascal Monett Silver badge

"the only way out of the churn"

. . is to pay a decent wage, not treat your employees like shit and give them at least the impression that they are useful.

Giving them scraps and piling pressure on them is just how you push them away.

China reveals its top five sources of online fraud

Pascal Monett Silver badge

That is the problem with total oversight

Once you start forbidding some form of online expression, you start a game of whack-a-mole with all the derivatives.

Well Xi Ping, I'm happy that you give plenty of work for your endless pool of administrative busybodies to continue making the lives of Chinese citizens worse.

Way to go.

By the way, you will not suppress dissatisfaction by governmental decree. It will grow and, some day, it will come to bite you in the ass. If you were intelligent, you would let the people vent and listen to what they are venting about. It would give you pointers on what you need to improve.

You cannot dictate how people feel, and there's more of them than there is of you.

Telcos fear Big Tech will bleed them until they can’t afford network builds

Pascal Monett Silver badge

"181.1 petabytes in 2020"

And, during lockdown, that exploded into what ? 300 petabytes ?

Infusion of $3.5bn not enough to revive Terra's 'stablecoin'

Pascal Monett Silver badge

Agreed. A "waterproof" watch is just a watch that can withstand being in the rain or under a fawcet for a short moment. You dry it off and it'll continue ticking.

Divers do not use of-the-shelf watches. They use professional gear that can actually withstand the pressure of 5+ bars under water.

The sad state of Linux desktop diversity: 21 environments, just 2 designs

Pascal Monett Silver badge
Thumb Up

Brilliant and exhaustive work of research

The author here has devoted a lot of time and work to produce this piece. I applaud the effort. I also appreciate the fact that the author has opened my eyes to the fact that, yes, basically almost everybody is implementing the Windows UI.

From a technical point of view, the Windows UI is a Good ThingTM. I remember reading about how Gates & Co really racked their brains over menu management, the homoginization of function keys and ease of use. Once upon a time, if you had access to Help, it could be via a function key, a combination of CTRL-<something>, or whatever else. Now, you just press F1, job done. That is good - except that now help is online, so if your connection is down, you're up shit creek without a paddle, and that is bad. Oh well.

But, concerning the efforts of volunteer developers, I'm sorry but nobody is forcing them to invest themselves. It's their choice, and I'm sure that they are dead set on improving some aspect or another of the user experience. The real issue is that (probably) none of them, or at least not many of them, have a lot of experience in alternative UIs, they just dive in with their idea and go for it.

It's their choice, there's nothing you can do about that. Yes, after reading this article I agree it's largely a waste of time, but it's their time to waste.

Europe moves closer to stricter cybersecurity standards, reporting regs

Pascal Monett Silver badge
WTF?

Does not apply to central banks ?

Why do the security regulations not apply to the most critical part of the entire banking infrastructure ?

I don't get it. Central banks should be the most paranoid institutions in existence. If a central banks gets infiltrated, there's no limit to the mayhem that can follow. So why are they exempt ?

Toshiba says it's talking to 10 suitors about possible sale

Pascal Monett Silver badge

"discussions are under way with §0 parties"

So, after all the drama of the previous weeks, suddenly there is a plethora of companies crawling out of the woodwork to buy Toshiba ?

(Our) hardware is still key in a multicloud world, Dell ISG chief insists

Pascal Monett Silver badge

"75 percent of data will be created at the edge"

Which translates to : 75% of malware attacks will happen at the edge.

I hope they're baking security in from the start, because otherwise this will be a major shitstorm.

China's Kylin Linux targets second RISC-V platform

Pascal Monett Silver badge
Thumb Down

"developed in partnership with Chinese authorities"

AKA : it has state surveillance baked in.

Arm CPU ran on electricity generated by algae for over six months

Pascal Monett Silver badge
Thumb Up

Mayb so, but every little step counts, so I applaud this research.

How ICE became a $2.8b domestic surveillance agency

Pascal Monett Silver badge

Re: Data brokers

Apparently, it's the Government that needs to be regulated.

Microsoft adds unscheduled breaks to most certification exams

Pascal Monett Silver badge

Re: Schooling

Well, at least schooling is supposed to guarantee that whoever it is you hire isn't going to be pissing in the corner and drooling over everyone's workspace.

Hopefully.

BOFH: You'll have to really trust me on this team-building exercise

Pascal Monett Silver badge

Re: Most disappointed!

The boss getting his comeuppance is also rather satisfying.

Elon Musk puts Twitter deal on hold over bot numbers claim

Pascal Monett Silver badge

Re: He might not be stupid

My, are you a generous soul.

He's got money, and that's all he's got.

He's got no class, he's got no refinement, he's barely cultured and he's got no reserve. He's a mouthpiece on steroids and he's got all the money for all the steroids he wants.

There is absolutely nothing interesting in him, if not for the fact that he is almost single-handedly bringing Humanity back into space.

That is his only redeeming feature, and I will give him that.

Pascal Monett Silver badge

"take the team in a different direction"

You can take Twitter in whatever direction you want, buddy. I'll never be interested.

Pascal Monett Silver badge
Trollface

Bad excuse. Bots don't use apostrophes.

Confirmation dialog Groundhog Day: I click OK and it keeps coming back

Pascal Monett Silver badge
Thumb Up

Oh. My. God.

Young Mr Grace ?

Number Two ?

What is this cornucopia of references that people under 30 have no chance of understanding ?

Not to mention the rest of the article.

A resounding thumbs up for a brilliant end of the week.