* Posts by Halfmad

881 publicly visible posts • joined 16 Jan 2013

Radio nerd who sipped NHS pager messages then streamed them via webcam may have committed a crime

Halfmad

Usually, but not always. People get treatment out of trust area pretty frequently. Think about those who work away from home, even a couple of miles can land you in another trust area or the nearest hospital may simply be closer than your "home" trust.

Delayed, over-budget smart meters will be helpful – when Blighty enters 'Star Trek phase'

Halfmad

Self-inflicted.

I do wonder what'd happen if you just left them there and didn't remove them.There seems to be an understanding that police will do so.. so why not call their bluff.

Halfmad

It's about money

Free money from the government to roll out this nonsense.

More control and flexibility to get every penny out of consumers, after the government has paid to enable them to do so.

Consumer has no benefit from smart meters other than knowing when we'll be least fleeced.

Q. Who's triumphantly slamming barn door shut after horse bolted at warp 9? A. NordVPN

Halfmad

Re: Pentests, audits, and RAM-only servers part of lockdown plan

It also highlights that due diligence wasn't being done prior to this.

Halfmad

Re: Remote Management SYstem

That's entirely irrelevant, managing your assets, having a good up to date audit of what is installed on your endpoints and servers is IT management 101. You can't secure something if you don't know what you have, they didn't know. This is just one of likely many failings on their part.

So likely they had no inventory, no vulnerability scanning, no third party patching solutions etc at a minimum.

Huawei with you! FCC's American Pai proposes rip-and-replace of scary Chinese comms kit

Halfmad

Re: FTFY

and UK law. In fact most countries have laws like this.

It's back: The mercifully normal-looking Moto 360 smartwatch

Halfmad

Benefits?

Still to be convinced smart watches are worth it, having to charge it is a major pain, needing a phone to get the most out of it is another.

So what's the benefit over a normal watch which needs a new battery once in a blue moon, if ever ?

FBI extends voting security push, LA court hacker goes down, and more D-Link failures

Halfmad

There's a couple of them still for same online from big retailers. Crazy.

Former BAE Systems contractor charged with 'damaging disclosure' of UK defence secrets

Halfmad

Re: ??

Honestly compared to the coverage of two footballers wives recently in the mainstream media, this is riveting reading.

GPS cyberstalking of girlfriend brings surveillance and indictment for alleged American mobster

Halfmad

Re: Daniel Capaldo (54, aka "The Wig" and "Shrek")

Maybe he has multiple personalities and they are just trying to accommodate ?

Halfmad

50? More like 40.. Many fond memories of watching the show with my parents!

Twitter: No, really, we're very sorry we sold your security info for a boatload of cash

Halfmad

Re: Well...

ICO doesn't care about special relationships tbh.

If you really can't let go of Windows 7, Microsoft will keep things secure for another three years

Halfmad

Re: Win 7

Linux will not take off like that as people are using MS OS at work. Otherwise it'd be far more common for Linux to be used at home already, another barrier is gaming although that's less of an issue in certain areas.

FBI called in to investigate 2018 Mountain State mobile voting system hacking

Halfmad
IT Angle

Re: Mobile

You get more RAM by just downloading a whole shipping container of it. I mean shesh, basic IT ! /s

If your org hasn't had a security incident in the last year: Good for you, you're in the minority

Halfmad

Re: The (almost) Inevitable

That's because they'd be generating work for themselves, what counts as a "hack attempt"?

Honestly I've bigger worries at this point than generating more stuff for the C-Suite execs to hit me over the head with.

TAG, you're s*!t: Internet advertising industry bods admit self-policing approach is a sham

Halfmad

Youtube

Noticed a real uptick in the number of adverts on my youtube app (not pre-video ads) which are clearly scam based snake oil.

Suppose you need to get money somewhere when you're self-harming over political correctness and running scared for a handful of pressure groups.

Hacker House shoved under UK Parliament's spotlight following Boris Johnson funding allegs

Halfmad

Re: Were they seperated at birth?

So most are behaving like ... politicians?

Seriously, this sh!t again? 24m medical records, 700m+ scan pics casually left online

Halfmad

Re: Managers

Great in theory assuming these companies have them but as most will be smaller private clinics (At least in the UK) I can put money on them not having any in-house IT staff, nevermind CIOs etc.

NHS is very unlikely to be directly affected as DICOM will be at least behind national boundaries like PSN/SWAN etc however that doesn't mean this isn't NHS data and NHS patients..

UK.gov's smart meter cost-benefit analysis for 2019 goes big on cost, easy on the benefits

Halfmad

I just tell them I'm not getting one, I don't see how me powering something for their benefit reduces my electricity bill. I already follow my kids around turning lights off when they leave rooms..

Snoops can bypass iOS 13 lock screen to eyeball your address book. Apple hasn't fix it yet. Valid flaw? You decide

Halfmad

Re: "allow access when locked"

Still needs physical access to the device so personally I don't see this as a huge issue - still an issue though and would prefer it to have to be enabled.

Allowlist, not whitelist. Blocklist, not blacklist. Goodbye, wtf. Microsoft scans Chromium code, lops off offensive words

Halfmad
Stop

Re: Is it wise?

Black/white has a long history in infosec too and is used for other terms. We going to rename "Black Hats" as "Block Hats" now? lol

White hats are not Allow Hats? :)

Bus pass or bus ass? Hackers peeved about public transport claim to have reverse engineered ticket app for free rides

Halfmad

Re: Still too expensive

Cost of a bus journey to my work is greater than a train ride, there are fewer of them (1 bus per hour, 2 trains per hour) and the journey takes longer compared to a train (bus is 45 minutes, train 8) due to the route.

Monthly tickets are cheaper however, but not by much and ironically if the trains aren't running I get a more direct route which is faster by replacement bus service than by bus.. where as if the bus isn't running I get to pay for my own taxi.

Trade union club calls on UK.gov to extend flexible working to all staff from day one

Halfmad

Re: Very general...

Not all departments want to accommodate it, mine doesn't. I work in Infosec, could easily work from home 4 days a week but because my boss wants to see me in the office that's where I am - constantly interrupted as a result. On the couple of days I've been allowed to work from home I have no only got more done but the quality of work has been better IMHO.

I did use to work from home a lot though so I'm very disciplined about it and if anything work harder to keep the perk.. or I did.

Google security crew sheds light on long-running super-stealthy iOS spyware operation

Halfmad
Trollface

Re: Entire populations: State sponsored?

You write about not making a conspiracy theory but your entire post is full of conspiracy ideas.

NATO sharpens its cyber-lances, prepares for war games with virtual jousting tournament

Halfmad

Re: Dear Moderator

You been saying Apple should be reply to requests for comment or something insane that gets you auto moderated?

I post all sorts of drivel and it never happens.

When you think how infamous NHS-pwning malware's still hitting the unwary, it'll make you WannaCry – Kaspersky

Halfmad

Re: Ransomware straining the Internet?

Most commonly used OS will always be the biggest target, doesn't matter which one it is.

GIMP open source image editor forked to fix 'problematic' name

Halfmad

Re: Divide and rule

When I worked in schools the Arts and IT staff were the most chilled there, the name of a software wouldn't have been a problem.

I deployed GIMP to several hundred PCs in high schools, back then "GIMP" was a term used in gaming to say something had been reduced in effectiveness and that's how the kids also used the word.

Today's Resident Evil: Ransomware crooks think local, not global, prey on schools, towns, libraries, courts, cities...

Halfmad

Danegeld

I've said it before on here but the current method of ransomware attacks isn't that dissimilar to old Saxons ponying up the silver to the Vikings in the 800s-900s etc.

Sh!t happens

Person in charge panics or realises they are defeated.

They pay up.

Person in charge doesn't bother improving defences.

Rinse and repeat again later on. They never learn.

Halfmad

Re: Other people's money

Also worked for a UK council, thing is even though there is waste things like backups were still considered incredibly important and has proper processes in place unlike just about everything else. Office backups, regular testing of backups etc was all done.

Room for improvement but the picture is no where near as bad as the US in this one case IMHO.

Halfmad

There's typically a common theme running through these infections - outsourcing.

You look at them and IF they have IT staff there's hardly any of them, most or all services are outsourced so nobody actually "cares" about the IT infrastructure as failures may well generate revenue and use up service tickets to resolve.

Now look at UK councils, most don't outsource and the result is MOST do the basics very well like backups. Those that do outsource will typically keep key services like that in-house specifically to ensure it's done correctly and incident response is so much faster and more effective as a result.

Dixons hits back at McAfee's £30m antivirus sueball: Your AV didn't work on Windows 10S

Halfmad

Re: Windows 10S...as useful as a chocolate teapot

Years ago my parents wanted a laptop. I went online and spec'd them one as any dutiful son would. Even gave them 3 options.

They went to PCW, first I knew about it was when I visited and my Dad said it was a "bit slow". When I saw the laptop I asked where he got it, when he told me I just groaned.

Silly me though I assumed it would be all the crapware that was bogging it down - not entirely. It was one of the slowest HDDs I'd ever seen, far too little RAM for Windows 8 and running on a very "low power" AKA useless CPU.

Sadly by that point they couldn't return it as they'd had it too long and didn't want to cause a fuss. They did however never ignore my advice again and I built my Dad a gaming PC a few years later.. nothing like seeing a 70 year old playing Skyrim!

Security gone in 600 seconds: Make-me-admin hole found in Lenovo Windows laptop crapware. Delete it now

Halfmad

Re: Lenovo crapware

Years ago I use to run IT for a group of schools, during build up to the summer holidays I'd order in PCs to replace existing but ageing ones, I'd always order 2-3% more than needed. When asked why - I explained to management that we expected at least a 1% failure rate on either the base unit or monitor and as the rooms had a fixed number of PCs needed per class, (typically 20 + 1 teacher) we had to ensure those were identical and working. The only way to avoid being a few down, as these would be installed right up until the day before students came back was the over-order and have the faulty units RMA'd and used elsewhere in the schools e.g. admin areas when they came back, the "extra" PCs would be used after all, no money wasted.

Took them a while to get to grips with it but as it was an operational thing and we typically got a larger discount by ordering in greater numbers they were OK with it. As you said singular experiences aren't really helpful. I'd be ordering 1500-1600 PCs for every summer, some years were better than others depending on who we were forced to buy from (Dell/HP etc) but failure rates were always around 0.8-1.1% typically PSU related or damage en-route.

Biz forked out $115k to tout 'Time AI' crypto at Black Hat. Now it sues organizers because hackers heckled it

Halfmad

Re: Openly and fairly...

Simply means treating you like any other exhibitor to be honest, Black Hat isn't known for tolerating nonsense.

Brits are sitting on a time bomb of 40m old electronic devices that ought to be recycled

Halfmad

Re: 49% have no old devices

I still use my Kindle from 2012 or so, has no backlight etc but I like it's dull screen, somehow easy on the eyes in a well lit room and have no desire to replace it.

Doesn't stop Amazon spamming me relentlessly to do so but the fact my kid has stood on mine and it's still going strong has won me over, great little basic device.

Wait a minute, we're supposed to haggle! ISPs want folk to bargain over broadband

Halfmad

Re: How much time would you need to invest?

Hassle of a new router?

If I used it I'd just disable wifi/DHCP/upnp etc, change all credentials. Its not going to impact anything on my network or wifi, it's just there.. doing as little as possible.

Contacts-slurping Android malware sneaked onto Google Play store – twice

Halfmad

Re: How it looks to me

Yeah the permissions especially are simply far too relaxed on the Android store, it should always be the minimum required.

Then again on IOS it's not much better. I have bought an app but because I don't allow it to collect telemetry data it simply keeps putting a banner across the top saying we aren't "supporting them". I mean WTF? I literally bought the app you *****.

Teen TalkTalk hacker ordered to pay £400k after hijacking popular Instagram account

Halfmad

Re: only in the uk

It's not the use of that specific tool that's the problem, he was under and order where he was not permitted to clear information relating to his activity - that's not something which is limited to the UK,.

Halfmad

£407,359.35

That's a lot of Bitcoin to just have sitting there, wonder what he intended to do with £377,759.31 of Bitcoin.

What I would give to have £747,856.91 of Bitcoin kicking about.

Halfmad

It took two weeks for the hapless designer to regain access to it

Victim blaming el'reg? seems a bit of a low blow tbh.

Disgruntled bug-hunter drops Steam zero-day to get back at Valve for refusing him a bounty

Halfmad

Sort of with Valve on this one..

If you need local access to pwn, then you could do just about anything on that PC anyway.

I guess HOW he got access locally may be the question here, did he leverage the Steam client etc? Doesn't sound like it but wierder things have been done via steam chat in the past!

Capital One gets Capital Done: Hacker swipes personal info on 106 million US, Canadian credit card applicants

Halfmad

Re: Grab data, post data, alert world+dog

I wonder if her details were in the bucket of data too, would have meant they have the perp and their details in one handy spot.

Low Barr: Don't give me that crap about security, just put the backdoors in the encryption, roars US Attorney General

Halfmad

Re: THE LIES

Trump voters? Jump lumping them all together now? Wow - blame a group with no power over the decisions being taken.

The voted before the Huawei nonsense came out, should they all be condemned for not having clear enough crystal balls too?

Why is it these days people are collectively blamed without any evidence or consideration of how you group them? Just blame them all.. what a society.

Airbus A350 software bug forces airlines to turn planes off and on every 149 hours

Halfmad

Re: Apple Air

If it was an Apple aircraft it'd be taxiing around the walled garden.

Lancaster Uni data breach hits at least 12,500 wannabe students

Halfmad

They were too busy FOIing the NHS about the use of XP.

Microsoft bungs a billion bucks at biz developing AI that will take our jobs 'for the benefit of all'

Halfmad

Re: Obviously...

"Shuffling songs by the Doors".

Halfmad

Re: For the Benefit of all???? ROFL

It's almost as if they are a private company and not a charity.

UK cops blasted over 'disproportionate' slurp of years of data from crime victims' phones

Halfmad

Re: Meanwhile...

Meanwhile the rates of actually solving crimes.. have been stolen.

Halfmad

Re: Stop using that phone

You don't have to stop, you have to moderate. Use what is useful and stop the instagram/twitter etc nonsense unless it's actually beneficial to you (it is in limited cases).

I don't see technology as the problem, it's how SOME people use it that is.

Many of us have no option but to have a phone on us for work, as a carer etc. If you've ever had parents with dementia you know having your phone on you can save a life.

Excluding Huawei from UK's 5G will harm security, MPs warn

Halfmad

Because the grass is so green on the other side?

Honestly are any of the alternatives in the Tory or Labour parties any better? I mean seriously.. what a state politics in the UK is in.

The pro-privacy Browser Act has re-appeared in US Congress. But why does everyone except right-wing trolls hate it?

Halfmad

Re: "By making people click a lot of pop-ups."

Yeah I'm not suing a site over this. I'll just go elsewhere..