* Posts by DontFeedTheTrolls

532 publicly visible posts • joined 4 Apr 2017

Page:

Morrisons tells top court it's not liable for staffer who nicked payroll data of 100,000 employees

DontFeedTheTrolls
Boffin

Re: Depends if decent efforts at data security made by Morrisons

"At some point, somebody has admin privileges. If your admin is intent on committing criminal acts, what can you, as an employer without that expert knowledge, do?"

I work in a place where certain privileged pieces of work are performed under "four eyes" - the policy says you need two people present when the change is made. The admin accounts required are secured against use and must be "checked out", and there's an audit trail of the whole process.

It doesn't guarantee against rogue employees, but it does demonstrate an attempt to prevent an individual rogue using certain admin privileges in unintended ways. It isn't practical for every privilege, however that is a risk assessment each business must make.

DontFeedTheTrolls
Headmaster

Re: Depends if decent efforts at data security made by Morrisons

"Businesses have some responsibility to insure that their workers are acting according to policy"

If they were to "insure that their workers..." then their insurance policy would pay out for their losses from bad workers.

If they "ensure that their workers are acting according to policy" then they wouldn't be in this shit now as they'd have taken the reasonable steps in an attempt to prevent their workers acting against policy.

This pedantry pretty much sums up this case - did they take sufficient steps to absolve themselves from liability?

Blood, snot and fear: Why the travelling lone tech reporter should always knock twice

DontFeedTheTrolls
Childcatcher

No mention of the Comp's granted, I'm guessing one hack doesn't want to make his peers jealous.

We're almost into the third decade of the 21st century and we're still grading security bugs out of 10 like kids. Why?

DontFeedTheTrolls
Boffin

Six Degrees of Kevin Bacon

Perhaps it needs a method to calculate a degrees of separation, how far away from bad bugs is this trivia bug.

I claim it and I'll name it the Tremor Scale of vulnerabilities.

NSA to Congress: Our spy programs don’t work, aren’t used, or have gone wrong – now can you permanently reauthorize them?

DontFeedTheTrolls
Childcatcher

Re: The United Scaredycats of America

#Swordfish

Helen Fospero makes yet another Brit telly presenter to win IR35 case against taxman

DontFeedTheTrolls
Boffin

Re: This is going to hurt Britain

"...they are staff by another name, but without recourse to they are staff by another name, but without recourse to Holiday\Sickpay & other benefits.."

but receiving payment in cash up front in lieu of Holiday\Sickpay & other benefits.

FT Properly FY

The Limited Company engaged to complete a job still has an obligation to meet employment law regards holidays, sick pay, benefits etc for all employees. How it chooses to meet those obligations is a matter for the board of directors to agree with the employees.

From Instagram to insta-banned: Facebook wipes NSO Group workers' personal profiles amid WhatsApp hack rap

DontFeedTheTrolls
Big Brother

"NSO Group has countered that it does not allow its software to be used for any illegal surveillance and only sells its tools to legit governments and agencies that investigate terrorism and crime."

"Here Mr Government, buy our software for spying on terrorists only, it won't work on your political adversaries, Journalists, wikileakers, dissidents or the minorities your government is prejudice against"

And how do they ensure that it's software isn't used for any illegal surveillance? have they a back door that reports to them every purpose for which their software is used?

Get real, stop spouting waffle, spy software is spy software, it spies on people, nothing you can do to stop that other than not produce it in the first place.

'Don’t be so concerned with your image'... US prosecutor lets rip on Uber for hack cover-up as pair plead guilty

DontFeedTheTrolls
Big Brother

Bug Bounty

How long before the DoJ, FBI, or equivalent in other Countries start offering "breach bounty" for details of hacks that companies have hushed up?

Who watches the Watchmen?

The UK's Civil Aviation Authority asked drone orgs to email fliers' data in an Excel spreadsheet

DontFeedTheTrolls
Facepalm

Re: GDPR

So in order to comply with EU legislation, they are breaking EU legislation. Lucky for the CAA we're leaving this European thing and they won't need to comply with EU legislation any more. Except of course for every fucking aircraft, balloon, drone they oversee.

Delayed, over-budget smart meters will be helpful – when Blighty enters 'Star Trek phase'

DontFeedTheTrolls
Headmaster

Re: What was that you said?

Got an email from Scottish Power recently stating the meter "was 20 years old and therefore needed to be replaced for accuracy".

Except my family has owned the house for 42 years, and the meter has a sticker on it from 06/77 confirming a reading when we moved in. Strange they NOW think 20 years is too old but didn't think that 20 years ago before Smart Meters...

DontFeedTheTrolls
Pirate

Re: Yet more bollocks arguments

"no need for the quarterly visit from the meter man"

I was never in, submitted readings online to avoid "estimates", however after two years I got a letter demanding to set an appointment which we duly did, readings were spot on. (It was claimed they have a "safety obligation", but the reality is they're checking for illegal hook-ups and meter bypasses).

Two years later, same again.

Haven't been back for about ten years now. (and have switched twice).

DontFeedTheTrolls
Terminator

Fine if they're gluing themselves to immovable objects like buildings, not so good when its Mass Public Transit.

Or perhaps we can find out just how fast a Vegan can run alongside said vehicle...

Huawei with you! FCC's American Pai proposes rip-and-replace of scary Chinese comms kit

DontFeedTheTrolls
Coat

The only thing surprising is that the FCC haven't claimed they're going to get China to pay for it.

Heads up, private penguins: Tails 4.0 is out. Security-conscious Linux gets updated apps, speed boost

DontFeedTheTrolls
Black Helicopters

How long before X Government attempts to ban live systems due to their potential use by Y/Z bad actors (or at least request they include back doors)?

No extra bank holiday for 75th VE Day, but the pub will be open longer

DontFeedTheTrolls
Coffee/keyboard

"Extending licensing hours will pave the way for commemorative events across the UK, so we can pay tribute to the courage and determination of the millions who fought for our freedom or supported the war effort at home."

Bollocks it will. A few hardened drinkers will get a couple of extra hours in the pub and call in sick the day after. A Public Holiday would have been appropriate. Or are the Government saving the declaring of public holidays so that we can remember Brexit Day in the future?

Republican senators shoot down a triple whammy of proposed election security laws

DontFeedTheTrolls
Flame

Re: No need for ballot security

Why even hold a ballot in the UK and waste time counting votes, Labour do it on a show of hands and decide the result aligned with the directives of the party Executive.

Repairability fiends crack open a Surface Laptop 3: Nice SSD, but shame about the battery

DontFeedTheTrolls
Boffin

Re: Torx plus?

Is that not the Security Torx with the little dimple in the middle of the screw and the hole in the centre of the bit?

DontFeedTheTrolls
Headmaster

Re: Climate Change

"If it can't be easily taken apart for repair, then it also can't be easily recycled"

Not entirely true. Can't easily be recycled by mainstream recyclers, however if the manufacturers take proper responsibility and organise specialist recycling centres they could actually drive better and more efficient recycling practise. Under WEEE manufacturers are partly responsible, although limited evidence of that up to now. Devil's in the detail.

Tor blimey, Auntie! BBC launches dedicated dark web mirror site

DontFeedTheTrolls
Black Helicopters

BBC News

bbcnewsv2vjtpsuy

Because that's obviously a trustworthy name to look for...

Just say the 'magic password': Boffins turn up potential backdoor in SQL Server 2012, 2014

DontFeedTheTrolls
Facepalm

Re: "only expose MSSQL servers to the internet if necessary"

"plug them into the Internet just for the fun of it. For lots of people, it's the only way they can do business."

Then they need to learn how to do it properly. There are LOTS of ways to front the SQLServer and protect it from nefarious actions, and I can't think of a single valid reason for a SQLServer to be connected to the Internet.

n tier architecture folks, its not difficult.

Assange fails to delay extradition hearing as date set for February

DontFeedTheTrolls
Headmaster

Re: Not enough time?

"Assange was convicted of skipping bail and should have been released on 22nd Sept"

As I understand it he was "released" following his sentence. His time was done and he was no longer held for that conviction.

He was however remanded in custody for the extradition charge, and his previous skipping of bail prevented the granting of bail in this instance.

Good news – America's nuke arsenal to swap eight-inch floppy disks for solid-state drives

DontFeedTheTrolls
Coat

NSA, GCHQ, etc?

Who is General Failure and why is he reading my drive?

Help! I bought a domain and ended up with a stranger's PayPal! And I can't give it back

DontFeedTheTrolls
Pint

"so I just set a forwarding address for him"

Good man, have a pint!

DontFeedTheTrolls
Boffin

Re: Whe someone uses my email address...

"in the EU he could report PayPal for violating (GDPR, FCA, etc)) sending him someone else's financial records"

Not sure PayPal would be found in breach here. They did their Know Your Customer due diligence on the records provided (the email address@domain) so why should they not continue to supply said email address with account information unless the customer could prove they provided PayPal with new contact details and PayPal failed to implement such details.

The account owner is at fault by "releasing" their account details, and is probably liable for any losses incurred according to the PayPal T&Cs on keeping account details secure.

A cautionary, Thames Watery tale on how not to look phishy: 'Click here to re-register!'

DontFeedTheTrolls
Headmaster

Re: Why no subdomain!?

"If they can't find the client, what's the betting they've lost the meter too?"

Call me cynical, but if there's one thing you can guarantee they haven't lost its the meters. It will have been number one on the list of requirements to ensure all meters were transferred.

DontFeedTheTrolls
WTF?

"The problem, ..., was that not all data had survived the migration from the company's 40-year-old billing system to something new and shiny"

One of two scenarios:

1. They planned not to migrate all the data, in which case WTF were they doing sending out communications in they way they did; or

2. The migration failed and data was lost (did not survive) in which case WTF were they doing during the testing and trial migrations?

Either way WTF!

Register Lecture: Is space law 'hurting' commercial exploration?

DontFeedTheTrolls
Mushroom

Spexit

I don't care what it is but the United Kingdom will be better off out of it. We must have our own space sovereignty and we need to take back control now.

UK culture sec hints at replacing TV licence fee, defends encryption ban proposals and her boss in Hacker House inquiry

DontFeedTheTrolls
Facepalm

Re: set top boxes are a pain in the arse

You've got a second plug to connect, usually a bulky power adapter that doesn't play nicely with the other plugs behind the telly.

You've got to put the set top box somewhere, and its not going to be on top of the set - they don't fit these days.

You're using up another HDMI socket - TVs that are going to need a set top box only have a couple of HDMI sockets.

You've got yet another remote control to lose down the back of the sofa.

Should I go on?

DontFeedTheTrolls
Coffee/keyboard

£3.7Billion? But we're saving TEN TIMES that not being in the EU, Brexit should give the Government loads of extra cash to cover such things as the BBC.

We're going deeper Underground: Vulture clicks claws over London's hidden tracks

DontFeedTheTrolls
Boffin

Re: Why obsolete?

According to the totally reliable Wikipedia it was five times more expensive to operate than on road vehicles (disputed by the Communications Workers Union who said it was only three times as expensive).

Think your VMware snapshots are all good? Guess again if you're on Windows Server 2019

DontFeedTheTrolls
Boffin

Business Continuity Maturity - what scenarios are you attempting to protect against and can you recover from those scenarios in a timely manner.

"Backup" is an all encompassing word that means very little these days. If you can trumpet "yes we have backups" then you're probably screwed. You need multiple options documenting options appropriate to the failure scenarios. Restoring might be one of those options.

Conspiracy loons claim victory in Brighton and Hove as council rejects plans to build 5G masts

DontFeedTheTrolls
Childcatcher

Yup

Like 56% of Americans saying the teaching of Arabic numerals should be banned in schools.

Snopes validated

DontFeedTheTrolls

I bet every single objector has an existing mobile at least 3G if not 4G. Better switch off all existing cellular services in Brighton then.

Could go down in history as the only not spot that chose to be rather than by lack of delivery of infrastructure by the networks.

How do we stop filling the oceans with Lego? By being a BaaS-tard, toy maker suggests

DontFeedTheTrolls
Childcatcher

Re: Unwanted LEGO?

That's like the ProLifeTip that you can freeze unfinished wine and use it as ice cubes next time.

Like there's ever going to be unfinished wine :O

Sudo? More like Su-doh: There's a fun bug that gives restricted sudoers root access (if your config is non-standard)

DontFeedTheTrolls
Coat

-1 you say?

I know I'm a boring geek, but if I sit at 90 degrees am I elevated to the square root?

UK govt snubs Intel, seeks second-gen AMD Epyc processors for 28PFLOPS Archer2 supercomputer

DontFeedTheTrolls
Boffin

Re: Redundancy?

Redundancy will introduce latency for little benefit if there's no data to lose.

If all the data to be processed can be recreated from the source why introduce latency to all work for a failure resulting in just one failed piece of work.

Her Majesty opens UK Parliament with fantastic tales of gigabit-capable broadband for everyone

DontFeedTheTrolls
Coat

Re: It's no problem...

Awwww, don't be nasty, Boris the Cockroach probably needs comforting now.

They're, their, there.

Oh dear... AI models used to flag hate speech online are, er, racist against black people

DontFeedTheTrolls
Headmaster

Any urban dialect is likely to suffer at the hands of AI misinterpretation.

Nobody could deny the C word is going to be flagged as offensive however in Glasgow it is often used as a term of endearment. "he's a guid c***" is quite common when two people are taking about a third they consider to be an all right person.

Ditch Chef, Puppet, Splunk and snyk for GitLab? That's the pitch from your new wannabe one-stop DevOps shop

DontFeedTheTrolls
Coat

BINGO

I got all the buzzwords first!

Teardown nerds return to the Fold with word of warning: Samsung kit still 'alarmingly fragile'

DontFeedTheTrolls
Headmaster

200,000 folds ?

Given the hundreds of times per day some people access their phone these aren't going to last very long, are they...

Remember the millions of fake net neutrality comments? They weren't as kosher as the FCC made out

DontFeedTheTrolls
Childcatcher

Re: Seems like a clear case of mail fraud

"focus on the harm bad actors do, particularly to the levels of political engagement, levels of trust in institutions (both public and private)"

HEAR, HEAR!

Any bad actor for any side is a problem. Even if a door created for good is open to anyone then anyone can be a bad actor. While the alleged abuse by the EFF may have been proven false, it is entirely possible that a freedom organisation undertook similar tactics to the lobbyists and some of the anti-NN comments were fake (I'm making no allegation, just pointing out that if the opportunity exists).

And if you agree to the above premise that back doors created for good can be exploited for evil, this should be a HELLO wake up call moment to proposed government back doors in encryption!

FBI called in to investigate 2018 Mountain State mobile voting system hacking

DontFeedTheTrolls
Coat

And in other news, a bear has been found in the woods...

IR35 blame game: Barclays to halt off-payroll contractors, goes directly to PAYE

DontFeedTheTrolls
Headmaster

Re: NI is just tax

Yes, it is just tax, hence why it should be absorbed into one straightforward income tax set of rates applied across all income.

"fund the appalling waste that is the NHS"

While the NHS may have its inefficiencies, I'd much rather have the coverage we do than to need to have insurance for everything. Nearly 5 million Americans filed for Bankruptcy between 2011 and 2017 due to medical bills. In the UK, Japan, Norway, France and Taiwan ZERO filed for bankruptcy over medical bills over the same period.

DontFeedTheTrolls
Mushroom

Trade Organisations and Cartels

Are IPSE and the other organisations that promote freelance and contract work going to take these businesses to court?

HSBC and Barclays have announced a restriction on contract workers, I know RBS and Lloyds are about to do the same, and other financial organisations are likely to follow suit. You can guarantee they've been talking to each other about how to approach this change in responsibility by HMRC, and If by all agreeing that the contractors should be inside IR35 are they not

a) admitting they were inside IR35 all along (and I know HMRC have said they won't pursue previous contracts, but that doesn't change the status); and

b) by working in concert to manipulate the contract market have they not formed a cartel?

UK ads watchdog bans Burger King Twitter jibe for condoning chucking milkshakes at politicians

DontFeedTheTrolls
Go

Re: Yes, but

Going to be plenty of spoiling milk available when it all stacks up at the border...

DontFeedTheTrolls
Headmaster

"Throwing things at politicians has a rich and cultured history. ... Long may it continue."

Seriously El Reg, didn't you get the message that this type of encouragement is wrong #snigger

600 armed German cops storm Cyberbunker hosting biz on illegal darknet market claims

DontFeedTheTrolls
Headmaster

Re: Servers in space ?

There's an El Reg article about HP's Supercomputer's return from it ISS. Radiation is a significant problem.

COTS hardware is not up to the job of operating economically in space given there were 200 servers seized in this raid.

DontFeedTheTrolls
Headmaster

"In UK the regular police units don't carry weapons firearms". Batons, Tasers and CS spray are all weapons, albeit generally regarded as non-lethal.

There was a case in the UK a few years ago where Highland officers were routinely armed. It didn't go down well when it hit the media.

A new US-UK data agreement is worrisome but it won’t give access to encrypted comms

DontFeedTheTrolls
Boffin

Re: They're only encrypted whilst in transit

Not on iOS. The entire device is encrypted, the messages are stored within the encrypted device, so without the unlock code/fingerprint/face the message remains encrypted at rest. Read the iOS Security Guide.

I'm not au fait with Android but I'll bet there are ways to keep the messages encrypted there too.

Page: