* Posts by John Smith 19

16330 publicly visible posts • joined 10 Jun 2009

Spies do spying, part 97: The CIA has a tool to track targets via Wi-Fi

John Smith 19 Gold badge
Unhappy

"Honey Badger does this https://bitbucket.org/LaNMaSteR53/honeybadger/"

What I think you're missing is a)The lack of consent b)The lack of visibility that it's happening.

John Smith 19 Gold badge
Unhappy

Useful for the list of "Stuff people think can't be done, but can, by compromised PC's."

As a previous poster noted, this does have a use for personalizing spear phishing attacks.

The list is depressingly long.

Fortunately with Windows phones being quite rare beasts the location data is likely to have gaps in it.

NASA tells Curiosity: Quit showing off, no 'wheelies' please

John Smith 19 Gold badge
Unhappy

" I suspect you're confusing Curiosity with the Spirit and Opportunity rovers."

You're right I am, and yes I am aware that JPL tend to be quite conservative on the life expectancy of their probes.

Anything that helps maintain control of something around a metric tonne of Mars rover is a very good idea.

John Smith 19 Gold badge
Thumb Up

This is amazing. I doubt "Wheel wear" was even considered give their original life expectancy

3 months at most?

Also it goes into the repository in case they ever need such an algorithm again.

JPL scientists have experience of "road conditions" most Americans will never encounter.

IOW like the road conditions on the rest of the planet Earth.

Ubuntu 'weaponised' to cure NHS of its addiction to Microsoft Windows

John Smith 19 Gold badge
Unhappy

So do 7 NHS trusts still lack a line item for IT security?

I think they probably do.

But it would still be interesting if they were hit as hard, or less hard, than others that did.

John Smith 19 Gold badge
WTF?

If smartcard support was the long pole in the NHS tent

Why did it take 5 years to get round to it?

I find it very hard to believe there are no other large organisations around the world that wanted smartcard support in a Linux distro. And note, if they feed the changes back upward it will not need to be a "custom" distro, it will the standard Ubunto build.

So Moorfields have an EPR system ready to go?

That is intriguing.

The question is does it cope anything other than eyes?

John Smith 19 Gold badge
Unhappy

"No large organisation..deploy core software without a..plan for managing updates and upgrades."

And yet the NHS seems to have done exactly that.

What is the enterprise cloud?

John Smith 19 Gold badge
Unhappy

You say "utility" I say Project MAC. You say "cloud" I say "Unknown jurisdiction data centre"

And you say "browser," I say "universal dumb terminal."

BTW "on demand" pricing for processors and main memory has been a feature of mainframe OS's (EG IBM and Univac) for decades. So you could say that in Mainframe land "Enterprise cloud" has been around for decades. IOW this is not the first time the IT industry has been around this particular block.

As for "always available" the events at AWS East 1 data center should have been a wake up call that you have to make the effort to get any potential reliability improvement, it's not simple and you have to test it. Otherwise it's just like any other data center failure, with added lack of insight into what's going on.

Cloud vendors, like all tech vendors, are keen on customer lock in. Anyone who hands their core systems data to such a vendor needs to realize they have lost a very large amount of control. While everything is humming along PHB's won't mind. CAPEX eliminated, low monthly charges etc.

It's what happens when everything is not rosy that people realize just how hungry a fox is in the hen house and how little they can do about it.

And I agree, once your dependent for even your processing cycles to an outside vendor I don't expect those low, low introductory price deals will last.

Robots will enable a sustainable grey economy

John Smith 19 Gold badge
Happy

""I'm so sorry Mr. Colnberst, this thing is acting up again. Let me call tech support.""

Ho ho ho. Very nicely done.

The comic possibilities are nearly endless.

What I had in mind was more what "Shadow Robtics" had created for a "robot chef" system. This uses high power to weight pneumatic "muscles" (essentially balloons inside a strong knitted bag)

Such systems can be as strong as hydraulic systems but as the run on compressed air they can be compliant, so if you push back they "give." Handy for safety issues but still able to lift an adult in an emergency.

Lighter "muscles" means lighter structures and lower power needs, a ripple effect throughout the design.

For the UI I was thinking of putting a screen on the front face like those things at conferences, like Segways with web cams, microphones for the back channel.

The goal is to help people stay in their own homes who are still mobile but with limited mobility.

John Smith 19 Gold badge
Unhappy

"We've just seen how hard it is politically to address these issues."

Agreed.

Where the "Grey vote" is concerned it's not just the codgers who are sh***ing themselves over the costs of community care.

My "techno fix" would be a human sized and shaped remotely operated avatar which was strong enough and agile enough to handle elderly care, eliminating the travel problems and allowing enough time to properly tend to peoples needs and without risking serious injury doing so.

But the issue remains where the money comes from. Life expectancy is going up. In the UK it is expected that 25% of the people alive today will live to 100, an astonishing figure that's been quietly creeping up year by year, 1% at a time.

John Smith 19 Gold badge
Unhappy

What a beautiful and glorious vision. Meanwhile...

Across town a carer on minimum wage is performing her third "manual evacuation" of the week on an constipated codger while trying to work out a route to her next appointment that will get here there before she is docked for being late, and which won't need the driving skills of Jason Staitham in The Transporter, or an Audi to do so.

Her employers, who won the contract from the local authority on the faked credentials and bogus social connections of the CEO, will continue to charge the local authority through the nose for this service, because running it in house cannot possibly be a good use of resources because subcon-tractors are soooo much more efficient.

Talk about cutting-edge technology! Boffins fire world's sharpest laser

John Smith 19 Gold badge
Thumb Up

IOW it's at 200THz but deviates from the exact number by +/- 0.01 Hz

IE 1 part in 20 000 trillion.

Which is pretty impressive.

and they hope to get it 10x better still.

Congratulations to all concerned.

Europol, FBI, UK's NCA ride out to Ukraine's cavalry call

John Smith 19 Gold badge
Joke

"Me.Doc software , is one of two accounting packages the country's tax office accepts."

Hmm.

Investigators suspicions are turning to a little known British software house based in North Eastern England.......

US Senators want Kaspersky shut out of military contracts

John Smith 19 Gold badge
Unhappy

As far as 0.5Bn to Ukraine, 0.45 of it will be stolen so no big deal.

That's not even 0.4 DUPes.

Concorde without the cacophony: NASA thinks it's cracked quiet supersonic flight

John Smith 19 Gold badge
Unhappy

"The Tu-144 wasn't 'unreliable'.. Commercial flights ceased quickly, "

While Concorde operated for close to 30 years with a perfect safety record, until it had one crash on takeoff.

John Smith 19 Gold badge

" it will be tough to fit high bypass with large frontal intake into a slippery supersonic shape"

True.

Concorde's noise issues were partly about history. I don't think they expected it would take as long to enter service as it did or that the noise regs would shift as far as they did.

BTW the 17th Concorde onward was planned to be a "block upgrade" using information collected from flight data. Improvements to details aerodynamics (things like wing tips and leading edges, rather than wholesale changes to the planform or wing profile). The goal was to eliminate reheat entirely during both climb and push through transonic IE about M0.9-M1.1. People often forget that Concorde was a "super cruise" aircraft long before the F22, F35 or Typhoon.

That was possible with the technology of the mid 1970's including the 13 "computers," both analogue and digital, running each engine, along with its associate inlet and exhaust).

You're right that AFAIK there are no large pure turbojet engines left. All are in fact low bypass ratio turbo fans (c 1.1 to 1.2x the core turbojet flow).

The joker in the pack is that the operating temperature of the front fan can be extended by cooling the intake airflow with a precooler. Unfortunately that would mean switching to a cold fuel, like Methane or in extreme cases LH2. This is exactly the technology Reaction Engines have been developing and were partly funded by the EU for the LAPCAT I and II programmes, except operating up to M5.

John Smith 19 Gold badge
Unhappy

"nobody will allow..a payload the size of an airliner..on a ballistic suborbital trajectory"

True.

Even reusable first stages are problematical.

John Smith 19 Gold badge
Unhappy

"Do you mean the self-loading cargo?"

Yes.

The downside of such cargo is that it places a minimum size on the whole vehicle, and with that form factor it's going to be biiiig.

Concorde, at 100 seats, was finally accepted by the French as the minimum size for an SST. Most people who've looked at this since have said you need at least 300 passengers (plus baggage) to make this viable. You also need a minimum range from day one of roughly Frankfurt to New York.

One interesting idea is that the maximum use temperature of plastics has been gradually rising. In principle CFC would be viable up to about 250C today. Likewise stainless steel could be an option up to 300c with laser welding or diffusion bonding.

Don't panic, but Linux's Systemd can be pwned via an evil DNS query

John Smith 19 Gold badge
Unhappy

"I'm not sure I'd trust input from inside the code either"

That's a trickier one.

Where do you draw the line?

Your external input has gone through validation functions and you've documented all valid parameter ranges, so later devs know what they can and can't do.

You don't pass huge hundred field data structures around (used in a dozen different ways, set by a control field) because that's been known to be a complex, error prone development approach since the late 1970's.

What more can you do?

John Smith 19 Gold badge
Unhappy

"Never make your code do something that it has no business doing in the first place"

Agreed. Most people would consider it an inappropriate choice for a capability to include in this sort of program. Although I'm sure the same could be said of various other functions in various other programs, where what should have been done was a smooth, common interface to the rest of the system.

However if you have decided to include it to begin with then being suspicious of external input (from anywhere, including stuff that is nominally coming from another program) seems like the basic precaution to follow.

John Smith 19 Gold badge
FAIL

2017 and inaccurately implemented protocols causing buffer overflows are still a thing.

Leaving aside why this particular bit of SW is even doing this function. If fails what seems like it should be rule #1

Never unconditionally trust input from outside your code, in size or content.

Not if it's user input.

Not if it's from removeable media

Not if it's down a wire (or a wireless link) from A.N.Other computer.

I know, this protocol is from the dawn of the internet when all the sysadmins knew each other, all played nice etc. However it's the implementation that's insecure, not the protocol.

That said this option is off by default.

So IRL who has been using it and why?

John Smith 19 Gold badge
Coat

"What's with all the exclaimation marks?"

They don't call him "Mr Bombastic" for nothing.

America throws down gauntlet: Accept extra security checks or don't carry laptops on flights

John Smith 19 Gold badge
Unhappy

"Yeah, let's remove all the security from airports, I agree. "

Non Americans find this absurd level of security hilarious, given that every 9/11 plane was on an internal flight.

We find Trumps travel bans on even more hilarious given the #1 source of the terrorist was Saudi Arabia.

Those facts alone tell you that this is "theatre" in the sense of "A performance put on to entertain an audience."

You, and people like you, are that audience.

John Smith 19 Gold badge
Unhappy

"What do we have to lose?"

Well think what would happen if all those wobble bottomed staff were let out on the streets again with no money in their pockets.

Takings at McDonalds near airports would crash through the floor.

Economic meltdown.

John Smith 19 Gold badge
Unhappy

"and using some low-paid donkey...to plant my device for me. "

It does make you wonder why they would bother, given there are various ways around this.

Unless....

Do you think there could be another reason for doing this?

Of course getting someone to do it for you is not very sporting.

Then again terrorists aren't really known for their good sportsmanship.

John Smith 19 Gold badge
Unhappy

"Gotomeeting and other such companies must be dancing for joy. "

In theory yes, it's the logical thing to do.

But I'm not sure how much it's actually happening.

"We paid for a meeting on our site, and we're going to have it"

<sigh>

John Smith 19 Gold badge
Coat

"Homeland Security won't say precisely what this enhanced screening is going to involve,"

Hiring a load more of the more "gravitationally challenged" members of the job seeking community perhaps?

Think of them as "mobile blast barriers"

The TSA. Keeping America employed secure.

John Smith 19 Gold badge
Unhappy

"And it's politics all the way down to perdition, "

That point is quite correct.

Strip the Jihad rhetorical BS from the issue and you're closer to the mark.

It's estimated the US invasion of Iraq let US companies and individuals steal about $13 000 000 000 000 from the country.

I'd be pi***e if someone came to my country and did that too.

John Smith 19 Gold badge
Unhappy

"having a load of Lithium batteries in the hold sounds like a bad idea to me."

Here's the question.

What is Probability(number of Lithium batteries in hold) Vs Probability(laptop with plastic explosive in battery compartment or elsewhere) ?

My instinct is the former is >> than the latter and if the hold is un-pressurized the pressure and thermal stresses will be much more severe on those batteries.

John Smith 19 Gold badge
Gimp

"It's the people "protecting" me that give me the cold sweats."

And so they should.

Five-eyes nations want comms providers to bust crypto for them

John Smith 19 Gold badge
Unhappy

"sides of the pound which seem to be from parents raised as 'flower children". "

I think you need to re-read my post.

Not turning the country into a police state might be described as the PoV of the "flower children."

It's usually the "ordinary decent law abiding (blah blah)" types who scream at the slightest threat to their life style who demand the most absurdly repressive measures. They don't really cope with anyone who's not exactly like them very well.

People can mistake broad tolerance for weakness. I once drank in bar were most of the regulars were ex-cons. They were very tolerant of casual visitors, provided they were well behaved. The bar did not have door staff because it didn't need them. People who were unwise enough to mistake their tolerance for weakness regretted it.

John Smith 19 Gold badge
Unhappy

"if...., you have to adopt those behaviours that make him your enemy, then your enemy has won "

Exactly.

In the US context Bin Laded must have ROTFLFAO when Congress passed THE PATRIOT Act, with one Congressman refusing (because he'd actually read the 200+ pages of it and thought it was a PoS).

John Smith 19 Gold badge
Unhappy

Your 12 year window includes 7/7 and that resulted in 56 deaths on its own.

No. I chose 12 years as post 7/7 but let's include them.

And while we're at it let's include the Brazillian electrican that got shot for wearing a heavy jacket on the wrong day as well. That's 57, not 56. And the English nutter terrorist that ran into a group of Moslems leaving their Ramadam prayers in North London and killed one as well. That's a "terrorist" incident as well.

And let's not forget Lee Rigby, Victim of a pair of "terrorists," or 2 people with mental health issues who should have been sectioned?

That's 94 people over a 13 year period, who might (not would, might) be alive today if anyone's encrypted traffic could be compromised at will by "The State," for "The Greater Good." BTW Most of them, including the 7/7 bombers were "Known to the authorities" already.

Meanwhile the confirmed death toll of 1 UK tower block due to either inadequate fire regulations, or their enforcement, is up to 80 (the other 18 are still listed as "missing" IE they can't match the remains found to an actual person, yet). Meanwhile every block so far tested (with similar cladding) has failed fire tests. There are about 600 such blocks in the UK.

BTW 94 is just over 10.5Hrs of smoking related deaths in NHS hospitals for 2014.

I think most of the UK readers of this site who lived through the IRA activities of the 1970's, 80's and 90's would consider compromising end to end encryption (as used for home banking and shopping) a grossly disproportionate response against what might be fairly described as a bunch of "shabolic motherf**kers," compared to the activities of the IRA.

The NHS figure (even better housing safety regs) says there are a lot better ways to save lives than this, but I don't think that's what you're concerned with. :-( .

If you, or someone you know, has been a victim of a terrorist incident I have a special message for you and them.

<profanity filter off>

Shit happens.

</profanity filter off>

You or they were very unlucky to be in the wrong place at the wrong time. It was grossly unfair. But that was the event, which has passed.

It's time to start thinking rationally again.

Most people have lost people who've died before they think they should have. Most deaths are preventable if you're prepared to sacrifice enough money, time or effort to do so.

The question is should you?

The purpose of a terrorist is to make you terrified.

If you (or someone you know) are terrified, they have won.

If you live you life making every decision based on wheather it (might) make you being the victim of a terrorist incident more or less likely, they have won.

When you refuse to be terrified, they lose. Fear is your choice. But understand it is your choice, not anyone elses.

A cold hard assessment of what these proposals will do with the reduction in terrorism, versus the reduction in everyone's security and privacy would conclude they are literally not worth the money they will cost.

But I don't believe "security" is the reason this is wanted. I believe it's a convenient excuse to introduce it. They just as happily use the risk of internet paedophiles, money laundering or drug dealing to justify it as well.

Data fetishists have no shame. They will hijack any issue to drive their agenda through.

John Smith 19 Gold badge
Gimp

"And all this effort for what ... to counter a threat that takes less lives than bathtubs, l"

In the UK the entire death toll of terrorist incidents for the last 12 years was 37.

The UK has spent probably several £500m -£1Bn a year and will no doubt point to all the people who would have been killed (but they cannot actually provide an estimate for that number) if they hadn't

It's time to confront the real enemy.

The cabal of data fetishists who have a pathological desire to know everything, about everyone, all the time, forever.

Strong encryption is indeed an enemy of theirs.

But their real enemy are people's desire for privacy. How dare we want to have times when we want to keep our thoughts, our feelings (and finances) private. Don't we know that "Caring is sharing (with them)?"

This communique is exactly the result of the echo chamber you get when these groups get together and reinforce their shared, delusional belief system.

US army spin-off GPU database bags $50m Series A funding

John Smith 19 Gold badge
Unhappy

Horses for courses.

As always the question is how well does this tech fit the job profile you need doing.

For the right kind of work load it might well be the SoA.

The question is of course if your work load fits that profile.

Making that decision may be quite difficult.

Murdoch's £11.7bn Sky takeover referred to competition regulator

John Smith 19 Gold badge
Unhappy

"British media owned by British people paying British taxes."

Or the Daily Express, based actually in Fwance.

UK.gov leaves data dashboard users' details on publicly accessible site

John Smith 19 Gold badge
Unhappy

Actually this sounds like an improvement over the usual UKG clusterf**k

Of course that's not really saying much....

Security bug bounty programs are a nice little earner for hackers

John Smith 19 Gold badge
Unhappy

"an astounding 94%..top publicly traded companies have no vulnerability disclosure policy "

I think that's a fair statement.

How to avoid getting hoodwinked by a DevOps hustler

John Smith 19 Gold badge
Coat

"I am certainly not an expert either."

Possibly the second most honest statement in this article and its comments.

The "experts" were doing this before it had a name.

The "experts" probably don't think what they do is anything like what people describe as "DevOps" so you won't find them in a "DevOps" conference.

There are always (by definition) damm few of them

Idea to encrypt stuff on the web at rest hits the IETF's Standard Track

John Smith 19 Gold badge
Unhappy

"The real challenge for effective privacy with TCP/IP will be the routing data."

The best I can come up with was some kind of token which is compared when the packet gets to its destination (matching token == destination) and a return token that indicates a "direction" in which the packets needs to "diffuse" in order to get it nearer to its destination, rather than an actual path to follow.

Sadly I have no idea how you'd encode that idea of "direction" or wheather that "token" should be the same for all packet streams going to or from the same end point, or different ones for each different session with that end point, or how you stop MIM attacks by token spoofing etc. Not to mention sizing this so it can accommodate the size of the internet, as well as allowing for future growth.

Basically I'm just not smart enough to figure out how to solve this problem.

But I really hope someone can....

Former GDS head Mike Bracken quits Co-op

John Smith 19 Gold badge
Unhappy

"How is it that good and decent..the Co-op can be ransacked by..mob of cocky-knob-twats?"

IIRC the Co-Op Bank CEO was a Methodist minister who had a liking for hiring rentboys, Ketamine and posting about doing both on Face Book.

Which probably explains why they are mostly (or totally) owned by a NY based VC firm.

As for this part of the co-operative movement...

US trade watchdog boss goes all Kendrick Lamar on self-driving cars

John Smith 19 Gold badge
Big Brother

We are Google. All your data belong to us.

That is all.

NATO: 'Cyber' is a military domain

John Smith 19 Gold badge
Coat

Would that require an attack by a member state to be joined by all other members as well?

I'm thinking Stuxnet on Iran, for example?

Kaspersky Lab US staff grilled by Feds in nighttime swoop

John Smith 19 Gold badge
Big Brother

"told them that they weren't under criminal investigation, "

Not yet.

"We'll decide what the charges are based on the results of the interrogations."

Handy hint.

You call on a law abiding citizen at 3am with no search warrant and no reason to call at a time when you expect them to be asleep. They have a perfect right to ask why are you doing this?

In the US Kaspersky needs to realize the correct response is find a law firm and lawyer up.

Northern Ireland bags £150m for broadband pipes in £1bn Tory bribe

John Smith 19 Gold badge
Unhappy

Re: "If <ulster ascent> was a typo, it was quite an aposite one"

Ooops.

Yes you are quite correct.

But you could say it is a deeper truth. The DUP has indeed ascended in power.

A good time Woz had by all: We peeked our head into Primary Data and this is what we saw

John Smith 19 Gold badge
Coat

So it does what was hidden in the bowels of an AS400 with users data?

But is open source and multiple level.

Can it support tape?

Facebook hit two billion users today and SugarCRM reminded us you are Zuck's product

John Smith 19 Gold badge
Trollface

And the rock in question is even called the "Trollpikken "

Excellent.

It seems someone has tried to cut the Trolls cock off.

John Smith 19 Gold badge
Joke

"Creepware As A Service"

And remember your donations (of personal information) make this product possible.

We thank you

Signed

SugarCRM.

Intel launches 64-layer 3D flash client SSD

John Smith 19 Gold badge
Unhappy

I presume this is "early adoptor" pricing.

But I'm not really sure what part of the spec screams "I cannot live without this in my life"

A minister for GDS? Don't talk digital pony

John Smith 19 Gold badge
Unhappy

"..16 different government departmental systems that need to talk to each other..for freight"

In a nutshell why government IT is so very challenging if done properly.

Big system X multiple interfaces X complex data issues X high reliability X multiple jurisdiction X P88s poor formal salary structures. --> Poor candidates + poor implementations

You need some one who's excited, not terrified by that level of complexity. Historically the UK Civil Service did train its in house staff and they could have a career (with associated pension) in the UKG. Naturally that ended decades ago and they thought it a genius grade idea to not just gut themselves of their technical staff, but also their technical management stuff.

Meaning they relied on their con-tractors to tell them what was what.

Like the Australian Tax office trusting HPE.