* Posts by Hans 1

3797 publicly visible posts • joined 11 Aug 2009

Leftover Synaptics debugger puts a keylogger on HP laptops

Hans 1

Re: Can anyone explain

That's why I hate languages that don't have IFDEF or something alike, to easily allow removal of code from production builds.

Feel smart, hey ? In which language were these written, do you think ?

In this case, synaptics f'd up as they left dev stuff in the enduser software. The audio driver, apparently, was another issue entirely causing the same effect, keyloggers on punters systems ....

Tired of despairing of Trump and Brexit? Why not despair about YouTube stars instead?

Hans 1

Re: Well Article'd

But I maintain that there is a significant difference between watching twenty two top athletes working as two teams with talent, determination and occasionally breathtaking skill, and watching an overweight guy on a video game swearing at the screen.

I dunno about these guyz in the top 10, but my son watches youtubers to learn new tricks ... not like a football fan would 90 minutes ...

Hans 1
Paris Hilton

Re: Eish!

@ Sceptic Tank

I was expecting flat earth to come up ...

Hans 1

Re: I too want to scream incoherently into the void...

These very wealthy nobodies produce and contribute artless nothing. The are literally wankers.

The thing is, there hundreds of thousands of youtubers out there, some that do great stuff, others, the vast majority, do garbage. the best at doing garbage somehow climb the ranks ... They must have something to attract all the viewers, like a face, a voice, a style ... no I, for one, am not jealous of them ... they get away with trash, good for them ... ;-) It is not like "you HAVE to watch" ...

Microsoft Dynamics 365 sandbox leaked TLS certificate's private parts

Hans 1
Paris Hilton

Gliwka detailed extensive communications with Microsoft to explain the issue

Ohhh, so I am not the only one having trouble with MS Support, then ...

Customer: "Oh, I found the private key to xxx.yyy on the xxx.yyy system I use for validation."

MS to customer: " Oh! [types privet kay into knowledge base]" Errrm, give me a minute .... [call put on hold]"

MS to Second line: What is a "private key"?

MS to Second line: "Oh, some people own islands south of County Dade, rich blokes ...."

MS to Second line: "Hmmmm, ok, so nothing serious ? Why is this guy so worked up about it ?"

MS to customer: "Thank you very much for that information, we will contact our travel agent and get back to you as soon as possible. Thanks for you interest in Microsoft products, have a nice day, good bye. [call cut off]"

OK Google: A stranger with stash of pirated films is spamming my Google Team Drive

Hans 1

Re: Still somone else's computer

@AdamWill

I think what you are mumbling is you do not understand DevOps or the benefits of it ...

New Capita system has left British Army recruits unable to register online

Hans 1

@Terry 6

No, no, no, Crapita, with the r!

Hans 1

@AzzZarr

upvoted!

This is the kind of thing where the base functionality could be handed to the intern for a summer project

I think you over-estimate the capacity of interns these days, ten years ago, yes, these days with young fellows of late, nope!

It's a decade since DevOps became a 'thing' – and people still don't know what it means

Hans 1

DevOps is way you organize work

Unless you have a system already in place that is not devops and that allows you to release frequently and early, test always, and have automated to hell and back, well done, you, sir (or madam) have earned the right to bash DevOps.

However, if you have not, you are like all those car manufacturers with mechanics walking miles to get nuts, bolts, screws and parts here and there in the factory laughing at Ford's assembly line.

No, you do not need paid for tools for this, you can do it yourself with FOSS.... yes, some DevOps evangelists come with their philosophy, voodoo BS and rules etc ... the thing is, the world is moving fast, your competitors are building those DEV assembly lines, streamlining development, test, and release cycles ... DevOps is a way to achieve that, you do not have to embrace the whole "philosophy" to make it work for you ... one of the central points of DevOps is: "Change is beautiful, if it makes a difference!"

Now, I mentioned dev, test, and release cycles, but you can adapt it to other areas of business .... what most C-types do not realize is that IT is not a cost center, imagine if you could streamline the period close or other financial processes ... most of the time, that will save you a lot of cash ... there are paid for solutions out there that do just that ... or imagine, SAP system copy, a bloody nightmare, get some setting wrong and you can start again ... taking the DevOps methodology, you constantly improve your processes, again, no one tells you you have to go 100% agile and have a SCRUM master, not necessarily needed, you can achieve all these goals without. It does help to start off like that, though, imho ... YMMV

Hans 1

Old-school vendors like BMC are much worse. For example, BMC's site is a mishmash of meaningless buzzwords, all targeted towards "your DevOps team". CA Technologies, for its part, waxes lyrical about its "DevOps solutions" and how they help to "redefine culture" around DevOps. Finally IBM lumbers toward a "Cloud Garage Method".

Thanks, made my day ... BMC are really an easy target for us ;-)

Microsoft emergency update: Malware Engine needs, erm, malware protection

Hans 1

It is 2017, and a Windows box can be owned by specially crafted file

No user action required, just put a site up that serves the file as content of a page, such as, a fake image file. ==> \ - /

YouTuber cements head inside microwave oven

Hans 1

I read somewhere that a study found the average IQ of generations declining, starting with the 80's ...

I do hope the emergency services take this opportunity to teach these pranksters a lesson all while contributing to the effort ... 2 weeks voluntary work at the ER service sounds about right!

Get ready for laptop-tab-smartphone threesomes from Microsoft, Lenovo, HP, Asus, Qualcomm

Hans 1
Happy

Re: More crap for the e-waste facilities?

It's not free and what is included in your normal monthly subscription and what additional usage will cost is determined by your plan...

In my case, absolutely 0 extra, my plan cost 17euro/month.

French activists storm Paris Apple Store over EU tax dispute

Hans 1

Re: Vive la France

France is the highest-taxed country in Europe.

Source, please? French sites don't count!

Hans 1
WTF?

Attac is anti-globalisation ?

https://www.attac.org/

Alt-globalisation, if you want, maybe, but not anti ...

I do think they are a bit extreme, these attac.org guyz, but they definitely have a point here this time, methinks ...

WW2 Enigma machine to be seized from shamed pharma bro Shkreli

Hans 1
Joke

Re: Enigma / Poland

Polish joke, I dunno ... this is good, I think, though ...

https://www.youtube.com/watch?v=uaQfy63mtk0

Voyager 1 fires thrusters last used in 1980 – and they worked!

Hans 1
Boffin

recycles it just for the gold it carries.

Hmmmmm ? what makes you think a civilization that has the tech to hop to solar systems needs to intercept a flying object for mere ounces of gold ... they could easily reach planets with megatons of the stuff ?

Ex-cop who 'kept private copies of data' fingers Cabinet Office minister in pr0nz at work claims

Hans 1
Happy

Re: It is known

That 8 out of 10 people admin to looking at porn on the internet, and the other 2 people are liars.

I, for one, prefer the real thing, am not interested in watching others ! If 20 years ago "counts", then yeah ... I had a look, got envious which made me feel bad, that was that.

I think watching pr0nz, even thumbnails, on a work machine is a big No-No, unless, of course, it is "work-related", good luck with that. I'm testing the new version of the video-decoding library can be done with other material!

Facebook posts put Pharma Bro Martin Shkreli in prison as a danger to society

Hans 1
Angel

You can care about money more than people all you like... but you shouldn't say it!

Exactly, next his lawyers will have him say: "I promise to give 98% of my fortune to charity when I die!" and he will be considered a saint ...

Dirty COW redux: Linux devs patch botched patch for 2016 mess

Hans 1

Re: Huh?

And this isnt to say that commerical UNIX or the BSDs are better, nine years is nothing compared to 25 years, like a bug in dir() that existed from 1983 to 2008.

While I agree with your statement, you are comparing a bug in a function that potentially skipped a file entry in a directory when you were reading the contents of a directory with this privilege escalation bug ?

News flash! All software that has 100's of lines of code has bugs.

Google Chrome vows to carpet bomb meddling Windows antivirus tools

Hans 1

This is according to a post today on the Chromium blog that laid out the July release of Chrome 68 for Windows as the target for new rules that will block all third-party apps from injecting scripts into browser sessions.

I cannot wait for them to do it ... no, I do not use Chrome, but having third parties littering Chome's JavaScript is, of course, F'd up, how could they allow that in the first place. AV or not AV ... of course, I think extensions are treated differently ...

Used iPhone Safari in 2011-12? You might qualify for Google bucks

Hans 1

I guess he's never heard of Uber?

or Facebook, or Microsoft, for that matter.

MS: https://www.windowscentral.com/how-remove-advertising-windows-10

Hans 1
WTF?

*You can claim if, at any time between June 1, 2011 and February 15, 2012 you: had an Apple ID, lawfully owned an iPhone, used Safari to get online, kept the default browser security settings and did not opt out of tracking and collation via Google's ad preference manager. Oh, and you also have to have been resident in England or Wales on May 31, 2017.

any time between June 1, 2011 and February 15, 2012 and Oh, and you also have to have been resident in England or Wales on May 31, 2017.

Oh, come on, you probably missed the "And your 3rd cousin-on-your-mother's side's left-hand neighbour's best mate's toilet paper must have ran out between 2 and 3 PM on June the 12th 1998." ? Seriously, your data has been snatched by Google illegally between those two dates in England/Wales (as above, apple id and visited any google^H^H^H^H^H^Halphabet-owned site), does not matter where you are now, yesterday or last week, if you used an iPhone as said in England Wales between those two dates you were wronged whilst in England or Wales, you should be eligible ... like, your car got stolen on Jan 13th and found again on Jan 27th, damaged, however, since you were not lawful resident of England or Wales on 28th June you cannot get compensation ... WTF ?

English legal system ... alacarte!

IBM figures out it takes longer than a week to re-wire software

Hans 1
WTF?

Thanks for all the silly excuses you regt@rds came up with for running outdated, obsolete, AND vulnerable tech. I've got news for you, NONE of them count.

It is as simple as this: Your software still requires TLS 1.0 support ? Then you have these two options:

1. I will update asap.

2. I will make all versions that cannot be updated obsolete.

It is as simple as that. You should already be planning implementing TLS 1.3!!!

Wondering why your internal .dev web app has stopped working?

Hans 1
WTF?

Re: I must have missed the change in standards bodies.

But they have zero right to enforce any rules about it at all in a private network they don't own.

If you use a TLD privately that is available on the global internet, you get all you deserve, it is as simple as that. It is not YOURS to use.

On the other hand, I think this change is silly and should be reverted.

As Apple fixes macOS root password hole, here's what went wrong

Hans 1

Re: Mistakes happen

You have to try several times for the vuln to trigger, once is not enough. This means that this flaw can remain undetected, as it was, for months ...

Glad to see Apple hasted with the patch.

This is just a silly code blunder

Next time I am in the head office, I will bring my laptop to IT, it runs WinDos 10, I will have a service running as System which will upgrade my account to domain and enterprise admin the second they log on ... let's see what they have to say about that ... I wonder, how long will it take for them to realize the feat ?

I also wonder what will happen to me once they find out ... fun days ;-)

Pro tip: You can log into macOS High Sierra as root with no password

Hans 1
FAIL

Big Christmas bonus for the person who found the photograph to accompany this article :-)

Indeed, have an upvote. (I was 100th)

As for the blunder, this is Windows-like security.

Cupertino, stop hiring devs from Redmond, they know jack-shit about coding, have never heard of tests, let alone unit tests .... crikey, this vuln is EPIC.

How Apple get away with this, I dunno !

Hans 1
FAIL

Re: They are busy setting Root passwords...

Ford Pinto> Major PR disaster. Ford is still in business.

The "Ford Pinto" was no less vulnerable to rear impacts causing the fuel tank to explode than other cars in its category ... this was a planted PR attack on Ford ... after the incident and recalls, Ford Pintos were the least vulnerable to rear impacts causing the fuel tank to explode its category, but the damage was already done,

Note, I hate Ford ...

Hans 1
Joke

Re: This is a deliberate feature and it's because Apple cares.

They've set our boxes so that only root can see anything other than home directories. The result - everyone does sudo su as soon as they log in.

Hm, interesting, how do you run sudo, from your home folders ?

Canadian! fella! admits! hacking! Gmail! inboxes! amid! Yahoo! megahack!

Hans 1
WTF?

striking a plea deal

Baratov confirmed he was pleading guilty and wasn't being coerced

How is this possible, he is denying he entered a plea deal in front of court ?

Oh, a plea deal is not coercion, no, of course not ...

No idea if he can be proven guilty, now, we will never know, for sure.

Elon Musk says he's not Satoshi Nakamoto and is pretty rubbish at Bitcoin

Hans 1
Paris Hilton

Re: El Reg staff

You all thought that PARIS was just an attempt to get some PR with a world record attempt.

You all thought that PARIS was just an attempt to get some PR with a world record SUCCESS.

BTW, when are we going to get moving, we need to reclaim the record ... we will not let a bunch of Yank cadets [I mean USian cousins, in my case, literally] keep it ... come on, lets do it!

Icon: Paris, because we need to reclaim PARIS! Come on, we need to a least try, in Lester Haines' name!

PLEASE DON'T UPVOTE, IF YOU AGREE DOWNVOTE, PLEASE!

If you disagree, I don't know, reply ;-)

Pokémon GO caused hundreds of deaths, increased crashes

Hans 1

Re: Anyone really surprised?

Throwing a car into the mix is just asking for trouble.

You have never been to Holland, with the sales guy (presumably) holding a mobile between shoulder and ear taking notes on a notepad ... all while doing 120 km/h (75 m/h) on the highway then, have you ? Besides, Pokemon Go stops working when you move too fast ... I think 20km/h (12 m/h) is enough to disable the game...

Hans 1
Happy

Re: Presumably, Danny 14 ...

... you also agree that guns don't kill people, people kill people.

Exactly, and that's why we need severe gun laws ...Imho, the people who buy guns need to be locked up, never mind big or small ... but I understand that that is just me ... anybody should be allowed to scare off intruders with military-grade assault rifles, it is in the second modification to the bill of rights.

Seriously, not doing away with over-the-counter assault or automatic rifles is severely brain-dead ... you know, the sort of kit that easily allows you to kill hundreds of people in no time .... who's house gets "invaded" by hundreds of burglars at once ? Besides, are you a responsible gun owner, like, the type that keeps his guns out of reach of children, locked up in a safe ?

For more insightful arguments :

https://www.youtube.com/watch?v=0rR9IaXH1M0

'Gimme Gimme Gimme' Easter egg in man breaks automated tests at 00:30

Hans 1

The article is incorrect ... the bloke was using the -w

As for the issue, obligatory xkcd: https://xkcd.com/1172/

Samba needs two patches, unless you're happy for SMB servers to dance for evildoers

Hans 1
Coat

Really? FreeBSD + Samba is much quicker for me on slower hardware.

0wned!

You selected the incorrect icon!

Hans 1
Holmes

Windows Server is significantly faster on the same hardware.

Source ?

Oh, crap, anon, did not notice ... sorry, troll on ...

Hans 1
Pint

This is what happens when you let young developers write Linux code - no clue how to do memory management and garbage collection.

1. Samba is not Linux, it is userland stuff that runs atop Linux and various other OS'

2. Pure C is better, harder to get right, but better.

Now, if you want to understand what is going on in Linux development, eat this:

https://www.youtube.com/watch?v=vyenmLqJQjs

Go, watch, and think!

Icon => pints for Greg, Andrew, and Linus!

Microsoft to run VMware on Azure, on bare metal. Repeat. Microsoft to run VMware on Azure.

Hans 1

Re: ProxMox is better than VMware!

KVM has been blessed with great performance improvements, lately ... besides, when it comes to supported guest OS', HyperV is a nightmare. Besides, support, how should I put it ... hm, MS support sucks. Their HyperV partners do not really cut it. Anytime you come and try to have a problem understood, you have to start teaching basics computing concepts to an utter n00b, because, well, when you have a problem that is not referenced on Google it certainly is not on the support bloke's checklist. Second line knows a subset of the checklists by heart ... and third line is reserved for enterprise customers ... imho.

Oh, I never managed to get anybody knowledgeable on their end ... and i have tried ...

Uber: Hackers stole 57m passengers, drivers' info. We also bribed the thieves $100k to STFU

Hans 1

Re: Rotten to the core

That these people need a wage to put food on the table, pay the mortgage etc.

We all choose where we work, nobody comes along with a M16 shouting "Sign THAT", they don't threaten your family if you don't obey.

Uber are scum and anybody still working there "deserves" what is to come. There are plenty of much better places to work for and it does not look like there is a shortage of job positions of various types.

I do feel sorry for the non-employees, though, who work their balls off 24/7 for peanuts driving people around and being ripped off by scum, however, pretty sure there is a market for a competitor ... Uber has really blackened its name ...

It was El Reg wot won it: Bing banishes bogus Brit bank banner ad

Hans 1
Holmes

And then there is the greedy domain registrar who did not even do the most basic of address checking before registering the domain

So, first sue MS, they have money, then go after registrar .... because, this has to stop! These guyz have to take responsibility ... and have to be sure they can re-claim from their clients. Easy solution.

Hans 1

Re: What worries me

It's particularly common with the over 60s - many who think that Google is the internet and the only way in is through the search box.

No, no, no ... it has to do with AOL and their keywords ....

Hans 1

Re: Follow the money ...

Prepaid credit card, false box address.

Well, if you got had, I assume that pre-paid credit card is MS' problem, not, hey ?

Hans 1
Joke

Re: Bing?

As many as that?

Well, he counted 7 DuckDuckGo users who would not have seen the ad anyways ....

Microsoft's memory randomization security defense is a little busted in Windows 8, 10

Hans 1

It is 2017

... and Windows manages to use more than 1Gb idle after a week of heavy load ... in fact, it was using 8Gb and as much was used in the page file, even after closing every single little gui app ... no, I only had a single non-MS service running, which was probably using 128Mb of RAM ....

Address Space Layout Randomisation (ASLR) mechanism, designed to severely hamper hackers' attempts to exploit security bugs.

The OS owns itself all by its own, no need to make it any worse ...

DISCLAIMER: Linux and OS X user here, and OS X gave me the "bad habit" of rebooting every 6 months ... Linux never had a problem with that ...

PS: The frequent notepad.exe patches that force a reboot or two are bad enough already ....

Intel finds critical holes in secret Management Engine hidden in tons of desktop, server chipsets

Hans 1
WTF?

I suppose a downgrade to Pentium2 CPU's and OS/2 Warp LAN Server is in order then...

Core 2 Duo's and Core 2 Quad's did not have these ... ;-)

Hans 1
Facepalm

Re: If this wasn't meant as a deliberate backdoor...

Though I don't see why that should need the ability to access all physical RAM, all Ethernet traffic, etc.

How else do you want the NSA to be able to intercept all network traffic from a box ? They need access to RAM to get the encryption keys to decrypt the Ethernet traffic ... d'oh!

Thousand-dollar iPhone X's Face ID wrecked by '$150 3D-printed mask'

Hans 1

Re: haters gonna hate

It doesn't make sense to you because you hate the innovation that apple does.

No, that is not the point. What do you do when your biometrics are compromised ? Finger or face surgery ? Is it allowed to alter your finger prints (is it even possible, no surgeon, here)?

What about compromised password ? Ahhh, easy, just change.

As for unlocking phone, grab the guyz finger, as seen on Qatar Airways or point at face of the victim, held by two accomplices ... BIOMETRICS, on a portable device, IS BRAIN DEAD, no ifs, buts or maybes - yes, as simple as that - doesn't matter who comes up with the "innovation", it is braindead. Android has finger auth as well, it is JUST AS BRAINDEAD.

Hans 1

Re: When will they learn

The glass you used for dinner, chicken wings for dinner, some candle wax, and she could have done so while you were in the shower ....

Lesson, don't mess with other ladies ... they have a sixth sense and, sooner or later, you will make a mistake or some one night stand will fall in love with you .... been there, seen that happen ...

Munich council: To hell with Linux, we're going full Windows in 2020

Hans 1
Coat

Re: Changing the tax location might have helped too

Upvoted, do provide a link, though ... like, this one:

https://mspoweruser.com/microsoft-germany-moves-into-a-new-headquarters/

Icon, because we needed a smoking gun, now we have one ;-)

https://itsfoss.com/wp-content/uploads/2013/12/killed-tux.jpg

Hans 1
Thumb Up

Danke!