nav search
Data Centre Software Security DevOps Business Personal Tech Science Emergent Tech Bootnotes
BOFH
Lectures

* Posts by Pascal

188 posts • joined 25 Dec 2009

Page:

British Airways' latest Total Inability To Support Upwardness of Planes* caused by Amadeus system outage

Pascal

Re: weight calculation

"You do these calculations before you load the cargo into the plane. Having the plane measure it and then say "oops, that's outside the safe limits, you need to unpack and rearrange" is sort of not helpful..."

Then hum... Why were the passengers sitting IN a plane for 3 hours? Surely they should have done the calculations before letting them board?

6
2

Tired sysadmin plugged cable into wrong port, unleashed a 'virus'

Pascal

I looped switches like that too once, except...

.. that when I did it, I also took down a border router of my then-ISP, which apparently disrupted service to a few dozen other customers of theirs.

Happy times :)

3
1

App devs bewildered by last-minute Google GDPR klaxon

Pascal

Technically, because if your app is free and ad-driven, they're not your customers, they're your product. Hasn't that been the generally accepted consensus for a while already?

Anyway I hate ads as much as the next guy and would rather pay for an app than have ads, I think it's the most annoying shit that can ever be put in a mobile app.

But it seems Google also fucked up in the sense that GDPR doesn't require consent to show ads, it would only requires consent to track users (so personalised ads)? Shouldn't their API be about consenting for personalized ads (with tracking) vs generic ads, without forcing the "no ads" option?

15
0

Equifax reveals full horror of that monstrous cyber-heist of its servers

Pascal

Re: And how...

> "It would also break the secondary market for debts as well, because if companies can't share that information, they can't sell your debts to anyone else"

Oh, the humanity! What would we ever do if that insane, mafia-like "secondary debt market" system disappear? We'd have to shutdown society or something.

Secondary debt racketeers are just about as useful to society as pedophiles and murderers, and should be treated the same.

12
0

It's not you, it's Big G: Sneaky spammers slip strangers spoofed spam, swamp Gmail sent files

Pascal

Small subset my arse!

> "We have actively taken measures to protect against a spam campaign that impacted a small subset of Gmail users."

I had dozens of them. They came complete with a (brand new I assume) banner stating that "We can't confirm that you sent this message or not, headers may have been forged".

They have since updated the banner to say the message "seems to be a fake bounces reply to a message I didn't actually send".

From inspecting the message source it seems they spoofed a lot of things, including Message-ID formatted google-style that might have been what tricked Google.

6
1

Cinema voucher-pusher tells customers: Cancel your credit cards, we've been 'attacked'

Pascal

Re: UK Law Must Introduce Guest Checkout

You don't even need guest checkout, just don't save credit card info after payment -- or at the very least, let the customer decide if you should "remember" that credit card.

20
0

2 + 2 = 4, er, 4.1, no, 4.3... Nvidia's Titan V GPUs spit out 'wrong answers' in scientific simulations

Pascal

Re: Shades of the Pentium floating point bug?

I am Pentium of Borg. Division is futile. You will be approximated.

64
0

Programming languages can be hard to grasp for non-English speakers. Step forward, Bato: A Ruby port for Filipinos

Pascal

Re: Nope, it doesn't work

Earlier (before the year-based versioning) it did in fact save "SOMME(...)" and wouldn't load in an english Excel.

1
1
Pascal

Re: Nothing new here

Even Microsoft did it back in the 90s.

VBA was localized so that code written in Excel / Access / etc. would use a french syntax in my version. "SI/ALORS/SINON" instead of "IF/THEN/ELSE" and so on.

And the crazy part was that it wasn't saved in an intermediate form. So an MDB file with code created on a french Access wouldn't work on an english Access.

Then in the early 2000s there was a push by the OQLF here (Office Québécois de la Langue Française) to coerce IT to switch to french; including threads to be barred from government work for including such evil anglo constructs in HTML pages as "é".

Much joy.

13
0

Cluster-f*ck! Etcd DBs spaff passwords, cloud keys to world by default

Pascal

mhmm...

"it seems as if people may not be using etcd's security capabilities and leaving the ports open, which can be a problem with every database"

Yeah but... CAN IT really? Does EVERY database really come with ports open by default that allow access with zero credentials "unless you enable some feature"?

I'm sure we can collectively come up with at least one or two that don't quite work like that...

1
0

XM-Hell strikes single-sign-on systems: Bugs allow miscreants to masquerade as others

Pascal

single point of failure maybe,

But the alternative is requiring people to have 15 login/passwords to 15 systems.

This results in the same password being used everywhere, or passwords written down on post it notes, and so on.

And obviously, 15 actual point of failures within 15 different login processes.

In theory one secure and thoroughly vetted sign-in system should mean less risks.

9
0

Microsoft works weekends to kill Intel's shoddy Spectre patch

Pascal

Re: The WinTel Cartel...

In this context they're passing along microcode updates produced and vetted by Intel, as part of a very urgent, very critical security update. You really want to lay that one at their feet instead of Intel's?

4
0

UK, US govt and pals on WannaCry culprit: It woz the Norks wot done it

Pascal

But he's a government official and he pinky swears it, surely that's proof enough?

20
1

Mailsploit: It's 2017, and you can spoof the 'from' in email to fool filters

Pascal

> DMARC only reports if your policy is set to "none", it can quarantine and reject mails if you like. or am I missing your point?

DMARC lets you broadcast a policy, that tells the world what *should* be done about messages coming from your domain and that are not authenticated a certain way. DKIM is one of those authentication methods and it can actually protect the domain used "from:" (the one in the message, not the smtp envelope). There are a lot of problems still however:

- Adoption rate is very low at the sender level (only a tiny % of domains have proper spf, dkim and dmarc policies in place)

- Adoption rate is still so-so at the received level. It's a much higher %, but there are still stupid situations like Microsoft still not doing shit about DKIM, and *lots* of self-managed smtp servers don't handle these things properly

And of course none of those policies, and use of those policies in email filtering, will do anything about the fact that most email agents are complete garbage. Take Yahoo for instance, you can mangle the subject line so much that it can alter their webmail GUI, still to this day.

2
0

Please activate the anti-ransomware protection in your Windows 10 Fall Creators Update PC. Ta

Pascal

That, or your outlook.exe lacks the proper signature, and isn't the one on the whitelist. Scan for virii? :)

(My Outlook from Office 2013 had no problems writing to my document folders when saving an email attachment after enabling this).

9
0
Pascal

The obvious unfortunately. The unsecured one scrambles the files, syncs them to dropbox, from where they get synced back to the secured device. If only the unsecured device could have read-only access to your cloud data...

10
2

Google slides text message 2FA a little closer to the door

Pascal

"The article says Google now has a system where you have to reply to a text. The act of replying acts as the validation in the server - there is no code to input"

No SMS or reply.

Their new method sends a push notification to the app. The app then prompts the user somehow ("Looks like someone's trying to log into your account from *location*. Is that you?", with allow / block buttons). Upon pressing allow/block, the app calls a Google API to complete the process.

So yeah it's a 2-way street but it's data communications, not SMS, which is the hey as SMS has been proven to be vulnerable to SS7 and it was effectively exploited in the wild already.

End result is extra security because push notification subscription are "secure" (only the owner of the app can push to a specific phone/installation and no known hiijaking of that has happened yet) and the specific install on a phone is the only owner of the key necessary to sign the response message (the public part of which is sent to Google as part of the enrollment process).

In the end it's one more tool in the 2FA toolkit. Google aren't forcing this, they're offering it as a more secure version of SMS. You can still use authenticators that don't require sms or data connections.

6
0

'Israel hacked Kaspersky and caught Russian spies using AV tool to harvest NSA exploits'

Pascal

So... Israeli intelligence, in the process of hacking Kaspersky for (probably exactly the same purpose), discovered that Russian intelligence had beat them to it?

Where's the popcorn icon?

96
1

Apple's iOS password prompts prime punters for phishing: Too easy now for apps to swipe secrets, dev warns

Pascal

One way ...

To truly differentiate system password prompts from application-generated password prompts (including fake password prompts) would be to include contents in the system login prompt that is selected by the used when creating their account, and is never visible to the App landscape under any circumstance.

My bank for instance issues a favorite picture selected from a bank of hundreds along with a "personal saying" type phrase that was entirely typed in by me;

After years of seeing the same picture and text on their login screen, I would say I am phishing-proof (*).

It would be easy to implement by Apple / Google, and would mean the system login prompt is a "personal" thing that always has the small P.S. note "we'll never ask your password without showing those!"

Then give it ~5 years for users to train themselves.

(*) ok, so for varying degrees of "proof", but at least not spoofable unless a seriously bad leak already happened.

11
0

Support team discovers 'official' vendor paper doesn't rob you blind

Pascal

Re: "opting for cheaper 3rd party labels"

I had a very nasty argument with one of those high end audiophile shops when digital stuff started showing up - he was trying really hard to prove to me that his ~$300 gold-plated, HDMI cable was so badass that colors would be brighter, blacks would be darker and general contrast/sharpness would be better.

Complete with 2 TV sets showing the same movies, with "exactly the same things except for good vs cheap hdmi cable", to prove how shitty it was to watch a movie with a cheap $50 HDMI cable vs his expensive one.

9
0

2019: The year that Microsoft quits Surface hardware

Pascal

Re: Surface, the Apple iPad/MacBook wannabe

Another way to see it is that Surface's goal was to give the OEMs a solid kick in the behinds, and wake them up from all the terrible, terrible hardware they were making.

Just look at screen and storage.

As apple was coming out with retina displays and ssd storage in their laptops, it was still considered a premium, high-end, "costs 100s of dollars more" feature to get an 1920x1080 display from Dell, HP and the like: they were very comfortable still peddling those 1366x768 pieces of junk in overweight laptops with storage that felt slower than my old 20 Mb RLL drives from the 1980s.

The current surface line-up clearly has those heat / etc. issues but calling them iPad wannabees is ridiculous.

5
1

Pumpkin bumpkins battle, 800kg monstrosity wins

Pascal

That's an impressive pie!

> "The winning vegetable actually weighed in at 792.5kg, or enough to make 100 pumpkin pies serving around 800 people. Despite this bulk, it still came up well short of last year's 900kg record."

We're talking about 8 Kg of pumpkin per pie!

4
0

Twitter's 280-char blog mode can be enabled client-side. Just sayin'

Pascal

Re: Never understood why ..

Holy crap if SMS is "a technology that most people don't use these days" I must live in a weird place :)

But at any rate twitter limit was in no way technology-related, it was a design choice, they wanted to create an instant short-message feed. It's part of their branding, so to speak.

As another poster said, make it unlimited and they'd be just another Facebook knock off.

8
0

Developer swings DMCA sueball at foul-mouthed streamer PewDiePie

Pascal

Re: Perjury

Is it?

I don't care about pewdiepie or that specific game / developer, but I'm genuinely asking from the legal standpoint.

I'm assuming game developers have some rights / control regarding this, and streamers would need their permission and/or could be asked for some licensing fees? After all, (some) streamers are making a living out of this, in somewhat (and I'm really stretching here probably) the way that cable companies make money off the TV channels they carry, but in exchange for license fees. Of course game developers certainly must be getting lots of sales out of the deal (endless hours of free advertising).

I really don't know (or have any very clear opinion either way), but does anyone know the "legalities" of this?

5
2

SpaceX sneaks in X-37B space plane launch ahead of Hurricane Irma

Pascal

Re: Getting bored now

It's fascinating how in such a short time they went from spectacular explosions to making those perfect landings feel like routine. Soon it'll barely be a footnote to the stories!

Seeing from the onboard camera, coming down from space at 3500+ km/h to land right in the middle of the logo is just amazing!

30
0

US Navy develops underwater wireless battery-charging tech

Pascal

Re: How is this still a thing?

The point of this however is standardisation. They want to develop a standard that they'll impose on their vendors so that they don't end up with incompatible kits (so whatever form their charging stations take, they don't have to deploy 6 versions of them if they have 6 UUV vendors).

1
0

New York Police scrap 36,000 Windows smartphones

Pascal

Still...

You let an underling decide on a technology / supplier / etc. on a multi-million deal because she's difficult to get along with?

Honestly her boss is as much to blame as she is... More, probably.

88
0

Did ROPEMAKER just unravel email security? Nah, it's likely a feature

Pascal

Re: Why Do People Expose Themselves With HTML E-Mail

That's only true for what is nowadays a very small, old-school slice of email users.

Everybody else at the very least can't understand why anyone would tell them they can't have bold, italics, etc. in text they write to someone.

And we're not even talking about the crazy idea that people who get their news, etc. via daily emails should get it in black-and-white text with no headlines / etc. whatsoever.

Email *was* a text medium. Decades ago.

17
2

Sofa-jockeys given crack at virtual Formula 1 world championship

Pascal

Re: Tight squeeze

> Eh? They've still got a brake and accelerator

F1's really high tech now, they scream engine / braking onomatopoeia into their helmet microphone for that.

Vroooom, Vroooooooooom, Vrooooooooooooom, Vroooooooooooooooooooooom!

Screeeeech!

Vroooooooooom!

6
0

Creepy backdoor found in NetSarang server management software

Pascal

Re: IP-Land

That's more or less what your firewalls are for, it's just that most people still assume firewalls are only meant to protect from external threats.

So they still allow, for instance, all servers to connect to any IP in the world using the basic protocols (http/https for instance).

Seems that financial client of Kaspersky was actually doing thing rights, and actually investigated blocked outgoing traffic to the point of hiring Kaspersky to figure out what was causing it.

But in the end your idea is just another approach that would generally not be implemented for the same reasons -- so many people assume traffic originating from their own systems is legitimate by default.

2
0

Hell desk to user: 'I know you're wrong. I wrote the software. And the protocol it runs on'

Pascal

Re: Did you ever hear of the Seattle seven?

The dude abides.

7
0

Bitcoin exchange Coinbase crashes after Asian buying frenzy

Pascal

"Japanese interest rates are actually negative at the moment, meaning it costs money to save"

How is that even a thing?

1
0

UK Home Office warns tech staff not to tweet negative Donald Trump posts

Pascal

Re: Absolutely uncalled for...

"I dunno, Justin Trudeau seems to be doing pretty well on his own."

This is a gross oversimplification but...

Trump got elected because he ran a popularity contest out of his reality TV "star" status / outsider status.

Trudeau got elected because he's cool and popular on social media.

More than ever voters basically make decisions based on popularity contests, this does not bode well for the future of mankind :)

4
0

81's 99 in 17: Still a lotta love for the TI‑99/4A – TI's forgotten classic

Pascal

The first computer I owned...

I had the occasional brush with an Apple IIe before (where I learned some very, well, basic BASIC), when Sears liquidated their stocks in ~83 or 84, my parents bought it for me.

Soon enough, I had scrounged the extra peripherals - the speech synthesizer, the external expansion (with slotted RAM on an external bus AND a floppy) and, the grand prize of them all, an ASSEMBLER cartridge that basically gave you access to assembly coding.

So there I was at ~12 years old, having only a few months of self-training in BASIC, learning assembly on the TI-99/4A with zero resources other than a 4-inches thick manual in english (which I needed a french-english paper dictionnary at the time to understand).

Good times!

That's what got me started anyway, so I still have great memories of this little computer.

4
0

Microsoft's Blue Screen of Death dead in latest Windows 10 preview

Pascal

> It's the new agile, dev ops combination bringing energy and innovation to the customer.

energy? you must mean synergy!

4
0

'Upset' Linus Torvalds gets sweary and gets results

Pascal

Re: Linus needs to start looking for his replacement.

> "Linus needs to start looking for his replacement."

On a somewhat more serious note, this is something I've wondered about from time to time. I only follow Linux Kernel development from articles here so my view is obviously completely skewed, but these articles definitely make it sound like Linux is what it is almost entirely due to Linus Torvald's vigilance and strict refusal to let any shit slip by. In a sense, if feels a lot like a personality cult, him being the glue holding everything together.

What happens when he retires years from now, having properly handed off stewardship and all is one thing.

How would Linux look like 5 years from now however if he died in an accident tomorrow? Is there a clear path of succession, or would things just devolve into 10 forks from people with different ideas?

I'm not criticizing or anything here, mainly I'm curious to hear from people that know about it more than from El Reg's headlines :)

6
0

Trump meets Google – exclusive transcript

Pascal

It's hard to decide which side to root for!

see title ;)

2
0

Persistent ad and dialler trojans found on 28 Android phones

Pascal

Re: So which antivirus is the best for Android

> "Go and get a not-so-cheap android phone."

And what is wrong exactly with a cheap phone?

God forbid some of us see phones as actual, you know, phones, not as a social status symbol to be derided if it's not worth more than a reasonable desktop computer.

10
3

Double-DIMMed XPoint wastes sockets

Pascal

Re: Whats up with those numbers?

Yeah I think there's a math glitch here?

The author is counting 500 cache misses instead of 50,000.

It should be:

((950,000 x 1) = 950,000) + ((50,000 x 5) = 250,000) = 1,200,000 time units

vs

((950,000 x 1) = 950,000) + ((50,000 x 50) = 2,500,000) = 3,450,000 time units

2
0

IFTTT isss notttt afraiddd offf Microsofttt Flowww

Pascal
Trollface

It's fine however because the marketing / business person that created the Flow "App" will also handle support and issues for it, and won't escalate it to IT.

2
0

Boy, 12, gets €100k bill from Google after confusing Adwords with Adsense

Pascal

Are you saying that, growing up as a kid, your parents were keeping things like bank statements safely locked in the family vault because god forbid if the kids got to see those and steal the bank account #?

13
0

Lethal 4-hour-erection-causing spiders spill out of bunch of ASDA bananas

Pascal

> "...every single piece of fruit is checked..."

... from outside the crate, through those tiny hole used for air flow and whatnot, while being loaded 10,000 at a time in a cargo container ...

19
0

FBI overpaid $999,900 to crack San Bernardino iPhone 5c password

Pascal

Re: Fragile evidence...

... but I play one on the internet.

6
0

Windows Update borks PowerShell – Microsoft won't fix it for a week

Pascal

Re: Smile :)

> Then again, if you have 10,000 machines, why are you on Win10AE rather than on Win7?

Or at the very least, if Win10 has to be a thing for you, on the LTSB version!

0
0

Two G4S call centre staff sacked over 999 answering scam

Pascal

Evil staff, scheming so their bosses can hit their goals...

And management was just as surprised as those guys at Volkswagen were when they discovered that all their engineers had been scheming behind their back in a worldwide conspiracy to cheat on those diesel tests without management's knowledge.

47
0

'I found the intern curled up on the data centre floor moaning'

Pascal

Re: "Pete' has omitted some details...

What makes me skeptical on this one is that he has just the *one* call / voice mail? So the intern didn't call 50 times in a panic, just once, left a voice mail, and waited the rest of the day?

5
2

IPO spews email addresses to hundreds of recipients. Twice

Pascal

Re: Why oh why...

Because the user would then simply click yes and think "of course I'm sure, what a stupid question".

After all, they're the one that pasted 100 addresses in "to:" in the first place. That's what they wanted to do.

2
0

Space station to get shiny new ringpiece for automatic penetration

Pascal

Re: Passive?

"Only participating nations on Earth have the plans for the International Docking Standard, so passing Aliens will be completely unable to connect to it."

Unless they have MacBooks which, as we know, include universal Terran-to-Alien protocol converters.

0
0

Google broke its own cloud again

Pascal

Re: The Cloud...

"You mean other people's computers that cost much less to run and are far more reliable than the ones you do have control over? That cloud? Where do I sign."

It's a good debate to have for sure but it's not nearly as "rainbow and unicorns" as that statement claims.

"Cost much less" ?

In some cases. In others, not. We've selectively targeted workloads that would be cheaper in the cloud as candidates, other workloads, not so much - in fact, some would cost many times more.

"far more reliable" ?

Google Compute Engine's SLA is 99.95%. That's a very good claim, but that one 211 minutes alone sets them at 99.5% for that month. A 10% credit towards the next month (as per their SLA) doesn't make up for 3.5 hours of unscheduled chaos.

In the end it depends on how critical your systems are and how good you are at maintaining them. I trust Google to know their shit, obviously, so yeah their cloud is very reliable. But I also understand that my SLA (the one I provide my customers) is the last thing on their mind when things go tits-up (and things invariably do). For these "absolutely must not fail", where you can afford to plan specialised backup / redundency / disaster recovery scenario, you can definitely be more reliable than the cloud. Or at least, when all hell breaks loose, you get direct control of the fixing process.

^^^^^

As you can probably see from that, I'm a bit cloud-shy. I do see it as "another guy's computer, that won't even take your calls when things go wrong" (well, you sure as hell are not going to talk to "the guy" unless you have a lot more clout with Google than I do)!

My general thinking is that I'll happily "cloud" anything that I would have run on a rented server at the local datacenter/colocation facility. Anything more serious than that, and I get scared.

9
0

Page:

The Register - Independent news and views for the tech community. Part of Situation Publishing