* Posts by Charles 9

16605 publicly visible posts • joined 10 Jun 2009

Facebook won't nuke deepfakes? OK, let's tear up those precious legal protections from user-posted content, then

Charles 9

Re: Should apply to pubs also

Especially since (fake OR illegal) AND undesirable may well be a contradiction: forbidden fruit and all that. You could be staring at Prohibition all over again.

There's a reason why my cat doesn't need two-factor authentication

Charles 9

Re: figuring out

Or, to put it simpler, no security system in the world can defeat a Perfect Imposter, and AFAIK one can't disprove the possibility of a Perfect Imposter.

Charles 9

Re: Nah.

Does it? Did Kerkhoff consider the possibility that, by knowing the meyhod, one could ATTACK the method via outside-the-box thinking (like using Shor's Algorithm to attack encryption)?

Charles 9

Re: Nah.

Why? Shouldn't a properly secure system be one where you can know everything about and still can't defeat it? Or is that provably impossible?

Charles 9

"Security always seems to exemplify an invalid syllogism: secure systems are inconvenient, therefore inconvenient systems are secure."

I can see where you're going, but can you provide a solid example of a system that is BOTH highly secure AND dead easy to use. The problem being ease of use tends to eat into that security by becoming a weak link.

Charles 9

No, a proper IT pro makes sure the security can't be bypassed. A gate isn't a proper gate unless (a) it's the ONLY way in or out, or (b) ALL ways in or out have the same level of protection.

Charles 9

Re: A pretty simple concept really:

"Security at the expense of usability, comes at the expense of security."

So what happens when usability DIRECTLY opposes security AND there must be a minimum standard of BOTH for it to be usable? Does that mean practical security cannot be made for this situation?

Charles 9

Re: figuring out

"The possibility for an untrickable machine exists but we haven't figured it out yet."

IS it possible? Or does it become a problem of Decidability, which has been proven to not always be possible (the Halting Problem disproof is an example of a problem of Decidability that's proven to be impossible to solve).

These boffins' deepfake AI vids are next-gen. But don't take our word for it. Why not ask Zuck or Kim Kardashian...

Charles 9

It all depends on where the average lies, whether the average is mean or median, and how spread out are these half from the average.

Charles 9

Re: Flashed list of IP addresses.....

They're not. What you're seeing is SVG markup: in this case, it's describing a drawing path (you have the back end of the <path> tag). You'll see commas as well as periods. The numbers are actually floats and seem to be following a pattern of FROM,TO FROM,TO...

Charles 9

Re: Flashed list of IP addresses.....

Those may actually be SVG drawing markup, though it seems weird for the format.

Charles 9

Re: Flashed list of IP addresses.....

I saw it from the outset. It seemed to be associated with an SVG graphics tag. Was also seeing weirdly angled text.

Akamai CEO: Playing games from the cloud? Seems too expensive to be viable right now

Charles 9

Re: Limited Range and Options

That's what he means. Compression and decompression necessarily adds latency, especially at higher rates, simply because the algorithms involved aren't optimized for realtime operation. Lots of multiplayer games are timing-sensitive (so-called "twitch" games where even a frame of lag means kill or be killed--a real buzzkill for battle royale-type games where you only get one chance per game). A lag of over 16.7ms means at least one frame of lag assuming 60fps. Granted, this is true of all gaming, especially those spanning long distances where the speed of electricity puts a physical floor on the lag. Games have had to compensate for uneven lag. Perhaps Google and Sony found a way to get right what OnLive and the like got wrong?

Charles 9

Re: I can see it working tbh

Even with tight data caps? At least locally-owned games only need to pass lean game data around.

This Free software ain't free to make, pal, it's expensive: Mozilla to bankroll Firefox with paid-for premium extras

Charles 9

Re: Oh dear

Did, had to abandon it. Too many sites broke against it, using Waterfox instead, but even that is starting to look dicey. Unless someone very high up requires a return to passive HTML, we could well all be in a handbasket as I speak.

Charles 9

Re: OSS isn't Free Software

What if you have no choice and must sink or swim? Remember, you're in the minority and likely have someone over your head.

Charles 9

Re: OSS isn't Free Software

"Yes, that's called "not understanding your problem"."

Oh? If the boss says JFDI and prospects elsewhere are slim? Do you sink or swim?

Charles 9

Re: OSS isn't Free Software

But what happens when the thing you have to do is "EVERYTHING"?

When it comes to DNS over HTTPS, it's privacy in excess, frets UK child exploitation watchdog

Charles 9

Re: DoH and Privacy

"Conversely, if you implement DoH, how do you propose to avoid malware exploitation? Or intrusive tracking and monetisation by Google and others?"

User your own server, housed nigh anywhere you want, including outside of government control?

"How can you be confident that you can trust the DoH resolver that you've opted to use? The standard currently lacks any form of discovery and authentication."

Again, use your own. If you can't trust yourself, you can't trust anyone and you're already screwed.

"The problem with not using a known port is that it's too easy to hide malware and also causes issues in the corporate environment where the network controller may well decide to block port 853 to stop TLS because it doesn't comply with his/her policy decisions and could cause major issues with the cybersecurity setup."

Similarly, the problem WITH using a known port is that it's too easy for someone up the chain to disrupt you with no recourse (because, again, they're up the chain from you). The trick with DoH is that the ONLY way to block it is to block port 443, the HTTP/S port, which means you practically stop using the Web anymore. Care to tolerate THAT level of collateral damage? Plus, at least this is standardized; what makes you think it hasn't already been used by malware without your knowledge PRIOR to this becoming a standard, because, again, it's too useful a port to block, just as some malware used Realtek's signing key because it's too ubiquitous to invalidate right away?

Basically, you're screwed either way. C'est la vie. Pick your poison.

"And let's not forget that DoH could easily lead to a much more centralised DNS, something which will prove highly attractive to hackers, both private and state-backed."

Why when people can roll their own pretty easily. The thing about Cloudflare and Google offering DoH is to make any attempt to block DoH too politically-sensitive. Do you really think China would be SO bold as to block Cloudflare, Google, AND Amazon wholesale (which is the ONLY way to stop them offering DoH tunneled through their existing services) in order to deny the use of DoH which can tunnel over the HTTP/S protocol the Web needs to work?

"Do you really think your chosen DoH resolver will be able to fend off targeted attacked from well resourced groups?"

If they're that resourced (you're implying state-level), I'd be more concerned with moles.

Charles 9

Re: DoH and Privacy

Then how do you propose a way to keep DNS from getting hijacked or even blocked wholesale by hostile people up the chain, given that anything with a known port can AND ACTUALLY HAS BEEN redirected or blocked at the port?

Charles 9

Re: If you have nothing hide, blah, blah, blah

Anytime someone asks that, reply, "Care to give your benefit/identification/Social Security number, then?"

Charles 9

Re: rinse, repeat

"In a few more years quantum computers will make all encryption worthless anyways,"

Shor's Algorithm is useless on NP-hard problems. Several post-quantum systems use lattices, multivariates, and hashes, which can be reduced to NP-hard problems.

Charles 9

Re: Upgrade the root DNS servers

Which the ISPs can still block (as the port is known).

DoH is meant to obfuscate DNS to prevent hostile ISPs and up from blocking DNS for their own nefarious reasons.

Charles 9

Re: Privacy?

"The clients that has DoH functionality will use an internal list of DNS-servers. You may or may not change this list depending on the whim of the developer (adware and malware will probably not allow you to edit or disable this list)."

Think of it this way. It's very hard to intercept Windows X's telemetry system because it uses an internal IP resolution list which means it never needs to use DNS or anything like it to connect. This combined with always using an encrypted connection (for which you don't know the key for the handshake) means the worst you can do is block the connection at the IP level, which has the potential for collateral damage since at least some of the IPs also resolve to the update system.

DoH is another way for apps to achieve the same feat. It's actually always been possible to tunnel DNS through other protocols (meaning malware could do that if it wanted). DoH simply raised awareness of the technique.

Charles 9

I thought ISPs simply intercepted ANY UDP packet with a destination port 53 regardless of IP address and slapped down attempts to get around them as against their ToS.

Charles 9

""The needs of the many outweigh the needs of the few""

Once upon a time, blacks were few versus the many whites. Does the term "tyranny of the majority" ring a bell?

Charles 9

The ol' Dual-Use Problem

Anything YOU can use to hide from The Man, CROOKS can use to hide from The Man. It's unavoidable: part and parcel. So what's it gonna be: anarchy or the police state?

JavaScript tells all, which turns out not to be so great for privacy: Side-channel leaks can be exploited to follow you around the interweb

Charles 9

Re: "losing a lot of web functionality"

Then it sounds to me like the site cannot be trusted AT ALL and should be blacklisted, if the ONLY ways it can run are security threats. Well, either that or it tediously reloads the entire page as you've described; it's the only way to be sure, it seems.

Charles 9

Re: "losing a lot of web functionality"

Has anyone tried referring the project to your appropriate agency for legal compliance with disabled customers (meaning it has to be screenreader-compatible, high-contrast, etc.), possibly with underpowered machines?

Charles 9

Re: "losing a lot of web functionality"

Not always the case. Many use the JS to load the actual content, meaning unless you let it load, all you get is a script and, as aforesaid, 4/5 of FA.

Charles 9

Re: "losing a lot of web functionality"

That's you. For most people, though, breaking scripting breaks the page which they MUST see (Facebook or Bust, Baby), and they outnumber you.

Unless you can rule the world or at least require a license to use the Internet, we're gonna get shouted down every time.

Americans' broadband access is so screwed up that the answer may lie in tiny space satellites

Charles 9

The view is that NO governing body stays impartial for long; ALL of them inevitably get corrupted from within. Even using opposition techniques can be defeated by cartel behavior.

Musk loves his Starlink sat constellation – but astroboffins are less than dazzled by them

Charles 9

Re: If only...

Not when it comes to radio telescopes, which by necessity (picking up radio emissions from light-years away can be a very hit-or-miss affair) are extremely sensitive. Think a radio version of a quiet room used to analyze someone's hearing. There's simply no other way to do it: ANY noise will interfere with the task at hand, just as ANY radio interference will disrupt the operation of that sensitive radio telescope. Which is why they often operate in radio-quiet zones enforced by law (terrestrially, at least). So, legally, interfering with equipment that requires a quiet zone falls almost-universally to the TRANSMITTER side to deal with, as the receiver has called dibs on radio silence AND holds the legal trump card of an enforceable mandate.

Charles 9

Re: Meh

"I hear all this rhetoric about how we need to bring the Intarwebs to undeveloped nations and how it improves quality of life, but last I checked you can't download antobiotics or clean drinking water."

But ubiquitous communication systems would allow you to make arrangements for the above, especially in situations where time may be crucial. Remember, we're talking areas of the world where telephones (even cellular ones) aren't guaranteed, where you may be lucky to use some kind of semaphore system. It's either this or the (VERY expensive) satellite phone.

Put it this way. One thing that kept remote villages...well, remote...was the lack of communication between them. A lag time of even a day dovetailed into this isolation, which tended to complicate logistics for things that cannot be locally sourced: like water and medicines for some people.

Charles 9

Re: If only...

The trick here is that radio signal quality (for whatever purpose you need) is physically dependent on the frequency. Lower frequencies carry more easily but aren't as dense (they can't hold as much information). Raise the frequency and you trade off the former for the latter. For a satellite mesh like this, there's probably a "sweet spot" frequency that allows it to carry the necessary distance and transfer at a sufficient rate. If that "sweet spot" happens to be the same "sweet spot" radio telescopes use, you're going to end up with a lot of hand-wringing, as radio quiet zones can only be enforced terrestrially: on the ground and in the air, not necessarily in space. And it will be difficult for satellites like this to be able to avoid terrestrial quiet zones in their orbits.

Charles 9

Re: Whoosh!

Not to mention radio telescopes tend to get specifically sited in places with minimal background radiation. It's well-known, for example, that radio silence is enforced near the Green Bank Telescope in West Virginia: to the point you'd be better off Amish or Mennonite living near that thing. It even has a name: The US National Radio Quiet Zone.

The FCC has finally, finally approved a half-decent plan to destroy the robocall scourge... but there's a catch

Charles 9

Re: This is not how telephone service works

And how do you keep these powerful companies from simply greasing palms and/or jumping jurisdictions? As for the robocallers, what's to stop them using other people's money or access to cover themselves with the potential for collateral damage and lawsuits?

Charles 9

Because the network gets used either way, and because of the way the telephone networks ran at the time, I don't think charging back to landlines users (who were just then getting into flat rates on local calls) was an option.

LTO-8 tape media patent lawsuit cripples supply as Sony and Fujifilm face off in court

Charles 9

Re: Bye-bye tape drives

Allow me to update myself. The technology is still out there, but apparently the practicalities of making it temporally stable and high capacity have rendered it extremely niche in nature. An organization called the Arch Mission Foundation seems to hold most of the cutting edge of holographic data storage, which they're currently using for the purposes of information preservation. If the technology matures and becomes cheaper to implement, a version of this for WORM archival purposes may become more practical for firms with large archival needs.

Charles 9

Re: Sony and Fujifilm tape media patents

How about new magnetic substrate materials such as Barium Ferrite (being used now in LTO-7 and up) and perhaps Strontium Ferrite in future?

Bad news from science land: Fast-charging li-ion batteries may be quick to top up, but they're also quick to die

Charles 9

Re: And the reason...

Why not write your legislator to propose such a thing into product safety codes (since nonremovable batteries can render devices a fire risk)?

Charles 9

Re: In Trumpton, it describes a particular style of play in a hockey game

You sometimes hear the adjective "chippy" in America, too. Don't know the exact etymology but it may come from the idiom "chip on his shoulder" (meaning having an unresolved gripe that is angering him). Put a lot of people with angst together and you can create a powder keg situation.

Charles 9

Re: It would be warm for a shorter time

IF you can change them out. Recall one of the big complaints about the trend in phones these days?

Charles 9

Which helps those out in the field HOW?

Charles 9

Re: There's a distinct anti-science bias in many of these comments.

Because the sheer physics and chemistry of fast charging are nigh-universal and thus would apply no matter what the product? Could this be the big thing this report concludes: that there is no free lunch?

Charles 9

Re: It would be warm for a shorter time

Not that much good if an emergency comes up and you unexpectedly need a fully charged phone a few hours early.

Supra smart TVs aren't so super smart: Hole lets hackers go all Max Headroom on e-tellies

Charles 9

I'd like to see where you actually FOUND a dumb unit. I haven't seen a truly-no-frills HDTV since the introduction of BluRays. The only way to go dumb it seems is to use monitors, which tend to be too small, have overkill resolutions for TV purposes, or both.

Charles 9

Re: Bah humbug

Given the market today, you'll be crossing EVERYTHING from your list, leaving you with NOTV instead.

IEEE tells contributors with links to Chinese corp: Don't let the door hit you on Huawei out

Charles 9

Re: @Chris G not quite.

Because the second has real-life, sometimes deadly consequences, and those consequences can affect elections. What do you tell the wife and kids of a man who worked hard for a company for 20 years only for it to suddenly collapse overnight through no fault of his own, and he's not in a position to be able to swing into another career anymore? You always have to consider the collateral damage because YOU may well become collateral damage, too. And desperate people tend to do desperate things, which isn't good for society in general.

Data-spewing Spectre chip flaws can't be killed by software alone, Google boffins conclude

Charles 9

"I know that makes it too easy for me to say things like I did and I can't so easily expect someone else to consider mine a valid approach."

Yes, it makes it easy to say something like that. You only have seven people to deal with with. I have an entire clan which last I checked ran in the neighborhood of around 50 able-bodied people, some of which ARE in tech sector and know this stuff inside and out AND how ubiquitous it is there (to the point it's in DUMB phones over there).

Let's just say, a certain king named Canute springs to mind.