* Posts by EnviableOne

2001 publicly visible posts • joined 28 Jan 2016

Rubbish software security patches responsible for a quarter of zero-days last year

EnviableOne

Re: 24 known zero days.

there are thousands out there, but only 24 were discovered being exploited in the wild.

TBF for some of the 24, while fixing the existing one, they found a couple of related ones and patched them too.

Foundation thrillogy: Rust programming language gets new home and million-dollar spending account

EnviableOne

Re: Abandoned???

Do i seriously have to dig out my Nokia Hammer analogy again.

C compilers allow all those things, as C's main job is manipulating hardware resources, and depending on your use case, you may have to do those things in order to get the system to do the job it needs to do.

US govt drops challenge to California’s net neutrality law, signals shift to once again safeguard connections

EnviableOne

Re: We really need to see a law one way or the other

at the end of good negotiations, neither side is happy, but both can live with the outcome

You'd have told them they should have used Apple/Google app model, right? NHSX seeks willing humans to fill health tech and data roles

EnviableOne

Please stop refering to NHSX as part of the NHS

Its not

the NHS's digital agency is NHS Digital,

NHSX is a quango set up by App Cockup and his friends at DHSC and basically spends all the money for actual digital projects without producing anything useful.

The unanswered question at CentOS community Q&A: How can we trust you now?

EnviableOne

the red has been going purple for a while

this has Blue fingerprints all over it

Nespresso smart cards hacked to provide infinite coffee after someone wasn't too perky about security

EnviableOne

Re: Nespresso...

they never use boiling water now adays its ruined the tea....

More patches for SolarWinds Orion after researchers find flaw allowing low-priv users to execute code, among others

EnviableOne
Terminator

Assimilate and die

the more peoples stuff you hamstring and bolt onto your suite, the more holes you will introduce.

UK internet providers told to mind their MANRS and start following Border Gateway Protocol best practices

EnviableOne

Re: though nobody noticed because they were IPv6

2021 - the year of IPv6, Linux on the desktop, ...

My bad! So you're saying that redacting an on-screen PDF with Tipp-Ex won't work?

EnviableOne

Re: Multi-coloured Tipp-Ex

while that response may be accepable in the 00s or 20s it was definatley not acceptable in the 80s.

you'd have got run over by the 9:18 to bedford

Spoken from the experience of getting a long stand, Tartan Paint, Photocopies of Braile Menus, and some wonderfull substance called "ICE MIX" tha turns water to cubes.

Nominet faces showdown with British internet industry: Extraordinary vote called to oust CEO, board members

EnviableOne

Re: Too little, too late.

Unfortunatley ICANN's board changed the rules so that this couldnt happen to them.

Something about the first priority being persistance....

Severe bug in Libgcrypt – used by GPG and others – is a whole heap of trouble, prompts patch scramble

EnviableOne

C is a specific tool for righting low level code

C is very good at its job

C is too often used not for its job,

Like the Transco engineer usining the Nokia 501 as a hammer, it works, but its not what its designed for.

C is a precision tool for manipulating low-level resources, not something to be used for everyday stuff.

Those complaining that C should be more memory safe, are the same as those complaining that their nokia hammer doesnt apply much force, or their thimble doesnt carry much water.

EnviableOne

its too long

buf_cpy is 7 chars and easily slips into a 64bit register,

why use 7 words when 4 will do

Dell Wyse Thin Client scores two perfect 10 security flaws

EnviableOne

Re: Use KACE

Nah, they spun it out

I was targeted by North Korean 0-day hackers using a Visual Studio project, vuln hunter tells El Reg

EnviableOne

Re: He Got What He Deserved

I got a mate whos got millions stashed in an unknown african country willing to give him a cut if he helps him get it out

EnviableOne

Re: NK Missed a trick

Richard Head works best

The UK's first industrial contribution to the ISS: An end to sneakernet for spacefarers

EnviableOne
Coat

Boeing Jim, Really

Acorns next meeting ....

East London council breaks off 20-year Oracle relationship to shack up with cloud ERP nobodies by year's end

EnviableOne

Yeah because that works really well when they try it: cf NPfIT

Man arrested after UK school finds wiped hard drives on devices connected to network

EnviableOne
Boffin

most schools have Windows Boxen, unless they have been benificiaries of the iThing emporium's Education program,

you'll probably need a few more lines and something like fdisk or diskpart

Fedora's Chromium maintainer suggests switching to Firefox as Google yanks features in favour of Chrome

EnviableOne

Re: Another reason to use Firefox, run your own sync server

They could at least have ported it to Python 3.0

EnviableOne

Re: @nematoad

Murphys Golden rule:

The one with the Gold Makes the rules

So it seems Jeff just lost the rule rights to Elon

Bye-bye Bridenstine: Outgoing chief leaves NASA in good shape, though Boots on Moon by '24 goal looks doubtful

EnviableOne

Re: Lost leadership

very well said, the role of artimis is to funnel large amounts of Cash to Boeing and LM so they keep their plants and offices in states where the senate space commitee's members represent

Indian government slams Facebook over WhatsApp 'privacy' update, wants its own Europe-style opt-out switch

EnviableOne

Re: GDPR

no it wasn't

GDPR does not and never did directly apply to the uk

the Data Protection Act 2018 however implements the controls as listed in the version of the GDPR on its date of publication.

150,000 lost UK police records looking more like 400,000 as Home Office continues to blame 'human error'

EnviableOne

Re: Technical issue?

My first suspicion is the Housekeeping error was a new junior clerk that did just what the court requested

However, its not like people learn from their mistakes

OWASP top 10 2003 ≈ OWASP top 10 2017

Coming in at number 5, it's a blast from the past! Tenable's 2020 security flaw chart show features hits of yesteryear

EnviableOne

Re: Not just Tenable

Checkm8 - people can't afford the new shiny

Epic Games files competition lawsuit against Google in the UK over Fortnite's ejection from Play Store

EnviableOne

I've done this comparison in the past,

you need to compare apples with apples.

App sales are equivalent of an online marketplace IE Amazon Marketplace, Ebay, which charge (all told) IRO 15% on purchases

In game currency is basicaly payment processing, so looking at Square, Paypal, Worldpay, etc.

you are looking at around 7.5%

Google have half (if their lucky) a leg to stand on, as other stores are allowed, but apple have none, as they dont allow any other store on their platform.

Xiaomi hit by US sanctions: Can't list on stock exchanges and investors can't invest

EnviableOne

Re: As long as the UK doesn't copy it

Because Shiney, "its got an apple logo on it, so its better than whatever you have"

Xiaomi, Oppo, Vivo, OnePlus, Huawei, TCL(Alacatel,blackberry), Lenovo(Motorola) all make very good phones at a fraction of the cost, but 50% of right pondians and 60% of left pondians wont buy anything without the fruit based logo

EnviableOne

Re: Doesn't really make sense

theyre all banned at my network level too.

none of that anti-social data slurping in Ma Hoose

Surprising everyone, spending watchdog says the UK's 2025 deadline for nationwide gigabit broadband is 'unreachable'

EnviableOne

Re: Gigabit Broadband

Same with 5G

if everyone could get 10Mbps and 3G it might be worth pushing 1Gbps and 5G, but the so called Universal Service Obligation, is starting to look like a most people something, if you feel like it.

IIRC BT were gearing up to roll out fibre everywhere in the 90s before HMG flogged their remaining 50% they even built fibre fabs in ipswich and birmingham

Buggy code, fragile legacy systems, ill-conceived projects cost US businesses $2 trillion in 2020

EnviableOne

Re: I fail to see the problem

the answer is not detecting the defects and fixing them

the answer is not making the defects in the first place.

this is why you need programmers and engineers, not coders.

Heres an acronym for the Authour of the piece:

Forget Usual Coding Knowledge Or Finding Faults, Treat With Adept Talent

EnviableOne

Re: Blame the management

totally agree

in a software firm you need a core group of Programmers or software engineers to create the program logic and flow a build in the security etc., then you need a miriad of coders to translate this logic into the miriad of languages used across the miriad of platforms.

Manglement in their effort to cut costs said why are we paying the core group so much, why not just pay them the same, so quality did as it does and left the sinking ships, this is why we see less and less inovative features, and more tweaks to current code, building up more and more technical debt....

How good are you at scoring security vulnerabilities, really? Boffins seek infosec pros to take rating skill survey

EnviableOne

which version

now which version were the experts working on?

theres at least 3 to choose from 2,3 or 3.1 and the maths is a nightmare

also its wether they are base temporal or environmental too!!!

Paperless what? Pah! UK government looks to ink £900m in printer deals

EnviableOne

Re: Have any friends of the Government

that and the almighty wet signature.

paper savings from many paperless systems are negated by having to print so much of it out to be signed.

Dems to ISPs: You're not gonna hike broadband prices, slap restrictions on folks in a pandemic, are you?

EnviableOne

Virgin are owned By Liberty Global - says everythiing USAians need to know.

In the UK most people have 2 choices, get something down the withering OpenBreach(Kingston if your in Hull) Copper lines or over Virgin Fibre/COAX network, where available

The rare happy few have a third party provider with their own fibre and a decent service, at a not unreasonable cost. (GigaClear, CityFibre, Hyperoptic, B4RN, and others)

the less-rare unhappy ones either dont have a phone line thats reliable enough to get a connection, are uneconomical to provide to and have to resort to Mobile Internet, if not in a blackspot, or god-forbid Satelite broadband to satisfy their need

Pork-tracking website problems add extra crackling to US-Taiwan-China tensions

EnviableOne

Re: Pompeo rewrote the rules

IMHO, the PRC/ROC issue is one of the biggest threats that could become WW3

with both china an russia very local and USA firmly on the POC side, it could escalate very fast

Trump's gone quiet, Parler nuked, Twitter protest never happened: There's an eerie calm – but at what cost?

EnviableOne

Re: And so Conquests Second Law is proved true yet again..

what you have to understand is that your speech is free, but so is anyone elses

It just so happens that society in america has become so polarised, and your identity defined by Red or Blue, there are no longer shades, there is no purple.

Each exists in its own bubble with out the other, where its view is re-inforced by opinions drressed as facts.

There are now at least 3 sides to every story: yours; mine and the cold hard truth. with the algortihms and partisan media, all that matters to you is yours and all that matters to me is mine, and the truth ceases to be.

EnviableOne

Re: The First Amendment

the president isn't, they require the authorisation of congress to declare war

EnviableOne

Re: AWS now liable?

https://xkcd.com/908/

EnviableOne

Re: AWS now liable?

This is why their is a law and the courts get to rule on intent ....

and ultimatley why these high profile cases were lost.

The right to refuse service depends on the grounds on which you refuse.

EnviableOne

Re: AWS now liable?

fully agree, they are Their T&Cs, THEY set and enforce them as THEY choose

Thou shalt not hack indiscriminately, High Court of England tells Britain's spy agencies

EnviableOne

Re: The great thing about British courts ...

IOW, the courts interpret the law, parliment makes it.

Precedent is great, it fixes all the grey areas,

if i higher court have made a decison like this use it to guide this decision, the problem comes when precident is wrong, and you need to persue it to the top to change it.....

SolarWinds takes a leaf out of Zoom's book, hires A-Team of Stamos and Krebs to sort out its security woes

EnviableOne

Re: Papering over the cracks

Hope it stops them buying decent software and ruining it for a while

ZIP folders were originally a Microsoft engineer's side hustle until bosses figured out he worked for Microsoft

EnviableOne

Azure Amazon Region

its got to be in the works

Brazil South + North + Peru + Columbia + Bolivia, Ecuador, French Guiana, Guyana, Suriname, and Venezuela.

either that or Amazon Web Services Region

UK union pens letter to data watchdog on icky workplace monitoring systems like Microsoft's Productivity Score

EnviableOne

Re: Doing a deal with the devil, or maybe Jesus?

wheras in st.Petersburg, we're frezzing our arses off ....

and no i'm not showing you the rose

UK MoD bungs Boeing £500m to plug gap left by a system it should have provided under £800m contract from 2010

EnviableOne

BDS and BCA are both divisions of the boeing company HQ'd in Chicago, still run under the same parent by the McDD management who have the one guiding principle:

"make me more dollars"

iPhone factory workers riot over unpaid wages in India

EnviableOne

Re: As of December 2020 Apple has a market cap of $2.081 T

I stuggle to find your point, as you are fully contradicting yourself. firstly you need to compare apples and apples, thew a51 probably competes with the SE, but you have to look at the S Series to compare to the iPhone.

OS to OS, iOS counts for 2.69% of mobiles in india, Android 96.28%

Vendor wise Xiaomi have 27.32%, Samsung 20.1% Vivo 13.62% Oppo 11% Realme 8.62% and Apple a lowly 2.69%

(latest from statcounter)

but with the smartphone market penetration at a lowly 36.7% there are a lot of indians who have multiple mobiles and a lot more that dont have any

US aviation regulator issues safety bulletins over flaws in software updates for Boeing 747, 777, 787 airliners

EnviableOne

TBF I'd fly a COMAC run by Aeroflot first and thats says everything you need to know

EnviableOne

Re: A Boeing Spokesperson said:

who said boeings were economical to operate

they just arent for a given generational/type combination, the boeing is probably less economical

McDD execs have one proiority and thats the almighty dollar.

they will show lip service to anythign as long as it increases the margin they can make on each bird the manage to flog

Your ship comms app is 'secured' with a Flash interface, doesn't sanitise SQL inputs and leaks user data, you say?

EnviableOne

Re: Shipping network security

cf Beruit - loading is automated, systems computer controlled, and probably only a handful of servers

We're not saying this is how SolarWinds was backdoored, but its FTP password 'leaked on GitHub in plaintext'

EnviableOne

Re: GE puts default password in radiology devices

in the same way as Health and saftey didnt improve much until CEOs were made criminally responsible

45 million medical scans from hospitals all over the world left exposed online for anyone to view – some servers were laced with malware

EnviableOne

Re: Security model is upside down so they can't implement SSO

NHS records are not online, the only things that are available across the entire NHS (if you can say such a thing still exists) are the Summary care record (which you can opt out of) and the demographic data linked to your NHS Number.

The actual detail of your record is maintained in a miriad of diferent systems, that are generally completley incompatable with each other,) held and operated by GPs, Hospitals, Community Teams, Support Units and other entities that you deal with and the transfer of which is covered by a miriad of controller/processor and controller/controller agreements.

The majority of your information is stored in your GP record, and this gets shuttled around the country when you move doctors or a specialist needs the detail.

This information is dicom images. these are ultrasounds, xrays, cts etc they are transfered in a common format, which is constantly maintained and updated, the current version 2020d, there are usually 5 a year, its even has an ISO Standard 12052.

As with all standards, the majority of issues are not with the actual standard, but its implementation.

This specific incident is more down to an imaging system and vendor implementation. Normally if these are stored in the cloud the demographics are stripped from the images before they leave the organisation and replaced with a unique reference.