* Posts by Victor Ludorum

237 publicly visible posts • joined 17 Feb 2010

Page:

Prolific phishing-made-easy emporium LabHost knocked offline in cyber-cop op

Victor Ludorum

Re: Good but...

Of course it is, but it serves two main purposes:

1. Joe Public feels reassured that the authorities are cracking down on this sort of activity.

2. It sends a signal to the ne'er-do-wells that the authorities will find you.

Techie saved the day and was then criticized for the fix

Victor Ludorum

Re: Locks.

Try Covert Instruments for a good selection of quality tools.

'This is the Lock Picking Lawyer, and today I'm going to show you how to open a data cabinet with some simple tools...'

Is Jake the LPL?

V.

Good news: HMRC offers a Linux version of Basic PAYE Tools. Bad news: It broke

Victor Ludorum
Thumb Up

Glad to hear you got it sorted.

It does seem a little odd that it was a locale issue as the software supports at least one other language - Welsh... (which admittedly is a Latin-based language/locale, but still...)

Victor Ludorum

it switched from launching the internally bundled web browser to launching the system browser as a front end. No idea why.

I remember reading somewhere that the switch was to improve accessibility and compatibility with screen readers etc.

Crowning glory of GOV.UK websites updated, sparking frontend upgrades

Victor Ludorum
WTF?

Re: If they *really* want to improve the experience....

Maybe the DVLA's database has unionised and only works specific hours?

Or the last person to leave the office (at 8.01pm) manually starts the overnight backup, and they don't want any stray records appearing overnight...

Curious tale of broken VPNs, the Year 2038, and certs that expired 100 years ago

Victor Ludorum

That might explain why...

I've only had a quick look for long-life certificates, but one of GlobalSign's root certificates expires on...

Tue, 19 Jan 2038 03:14:07 GMT

Spooky!

CERN seeks €20B to build a bigger, faster, particle accelerator

Victor Ludorum
Boffin

Re: Collide at insane speeds

Surely this FCC will be Plaid? (what are we going to call it once it's built? It won't be the Future Collider...)

Seriously though, it often strikes me that we haven't 'discovered' Dark Matter because we don't actually know what we're looking for or how to detect it despite some of the best boffins on the planet using all their collective brain cells to try.

At last: The BBC Micro you always wanted, in Mastodon form

Victor Ludorum

Re: BASIC

Never saw a C compiler for the BEEB (well, I may have seen a TinyC compiler, but I can't remember much about it).

For some reason, I thought there was a C compiler ROM for the BBC. A quick bit of sleuthing turned up BeebugSoft's Micro-C. There may be others.

Victor Ludorum

Re: BASIC

I don't disagree that there were 'better' programming languages by 1981, but the beauty of BASIC was that it appeared to the layman that you could write programs in plain English and they would (mostly) just work. Although admittedly 'Syntax error at line 30' isn't the most informative of error messages!

I'm pretty sure there were other language ROMs you could plug in to your Beeb if you wanted C, Pascal, Forth etc, but I don't think they were aimed at 'beginner' programmers.

WTF? Potty-mouthed intern's obscene error message mostly amused manager

Victor Ludorum
Headmaster

I presume

It's to do with speak and speaking, which should in theory etymologise speach.

Microsoft offers rollback for those affected by Windows wireless futility

Victor Ludorum

Did I have the issue?

Wireless was refusing to work on my laptop the other day. A quick dive into Device Manager, disable then re-enable the wireless adapter worked for me.

Checking Windows Update, I do have both '228 and '375 installed.

Wireless is normally pretty faultless, but it could have been a coincidence...

You don't get what you don't pay for, but nobody is paid enough to be abused

Victor Ludorum

Re: is 10x $$$ normal?

But do you get a business grade SLA?

Money-grubbing crooks abuse OAuth – and baffling absence of MFA – to do financial crimes

Victor Ludorum

Can someone cleverer than me...

Please explain how MFA would stop this. They're capturing session cookies/tokens through a proxy/relay. Even if MFA is enabled the victim could unwittingly use MFA to log in to the account and the MITM relay/proxy would still capture the cookie/token?

Remembering the time Windows accidentally sent Poland to the bottom of the sea

Victor Ludorum

Geopolitics

Plus ça change...!

Why have just one firewall when you can fire all the walls?

Victor Ludorum
Unhappy

Given the corrent state of the economy, maybe the phrase should be exchanging your labour for cost of living vouchers

You snooze, you lose? It's not quite as simple as that

Victor Ludorum

Non 24 hour sleep cycle

My son's sleep pattern started to deteriorate during 2020, when he was about 14. After several false starts with medical professionals, he was finally diagnosed with delayed phase sleep wake disorder. He usually goes to bed at ~11pm, but is never asleep before 3am*. We have to wake him at 12.30 to try and keep some routine in his life otherwise his sleep could end up all over the place.

One of the treatments suggested by a sleep doctor actually made his sleep patterns worse.

There is a risk that he could fall into a 'Non-24 hour' sleep cycle, there is also a slim chance he will grow out of it.

He's also been diagnosed with ADHD, but it's not clear if the two are related.

* Yes, we've done all the screens off, no blue light etc. His bedroom is as dark as we can make it. He just lies there in bed and can't sleep.

Mozilla's midlife crisis has taken it from web pioneer to Google's weird neighbor

Victor Ludorum

Re: Thunderbird Calendar

Haven't used Thunderbird for a while, but ISTR you need the Lightning plugin for calendar functionality.

The home Wi-Fi upgrade we never asked for is coming. The one we need is not

Victor Ludorum

The majority of non-technical customers just want a router that they can plug in and it just worksTM.

The majority of ISPs want as little as possible (with the minimum of configurable options) connected to their service so they don't have to support an endless combination of devices.

Arm's lawyers want to check assembly expert's book for trademark missteps

Victor Ludorum

Re: Time to walk away.

Open source hardware would be good.

Would that be the hardware that a certain company dissed using riscv-basics.com?

V.

Want tech cred? Learn how to email like a pro

Victor Ludorum

Re: Which question did you answer ?

Going OT for a bit...

It's a bit like certain drivers not using their indicators (blinkers). I think they assume that you are telepathic and automatically know which way they want to go. They think they don't need to use their indicators because they already know where they're going...

RIP Kevin Mitnick: Former most-wanted hacker dies at 59

Victor Ludorum
Unhappy

RIP Kevin

The world would have been a much duller place without you.

Apple pushes first-ever 'rapid' patch – and rapidly screws up

Victor Ludorum
Coat

The problem was...

Apple

Rapid

Security

Error

Yes, yes, I'm going...

Thanks for fixing the computer lab. Now tell us why we shouldn’t expel you?

Victor Ludorum

Re: How secure *IS* your system

It was 35 years ago - I just remember it was a BBC network but wasn't Econet.

Victor Ludorum

Re: How secure *IS* your system

That reminds me of the BBC network we had at our school. It wasn't Econet, but very similar.

A friend of mine (yes, really, it wasn't me) reverse engineered the sideways ROM for the network and it turned out that user authentication happened on the client - it looked up a four character (!) password in a special file on the server based on your user number. Cue various students using teacher logins and kicking other users off their machines remotely...

V.

Namecheap admits 'unauthorized emails' pwning its customers

Victor Ludorum
Unhappy

Whose account?

I got the 'DHL' email apparently from Namecheap and ignored it. Headers show it was sent through SendGrid.

Just guessing here, but is it possible Namecheap's SendGrid account was compromised somehow? Weak password, credential stuffing, 2FA fatigue or something else?

Cloudflare engineer broke rules – and a customer's website – with traffic throttle

Victor Ludorum
Joke

Poor engineer

The post does not mention what, if anything, happened to the engineer who applied the throttle.

He was throttled?

Here's a list of proxy IPs to help block KillNet's DDoS bots

Victor Ludorum
WTF?

Use a script carefully

I've just taken a look, it's now up to 17920 entries, BUT some of them are in 0.x.x.x subnet...

And there's at least one in 10.x.x.x.

Sanitise the list before using it.

Twitter tweaks third-party app rules to ban third-party apps

Victor Ludorum
Thumb Up

Re: Plummeting sperm whale?

I came to this comment just as it had received 42 upvotes...

KmsdBot botnet is down after operator sends typo in command

Victor Ludorum
Pint

I was going to say

Ha Ha Ha Ha Ha Ha...

But you basically beat me to it.

Hot, sweaty builders hosed a server – literally – leaving support with an all-night RAID repair job

Victor Ludorum
Headmaster

Re: around ten meters worth

American ones I expect.

Singapore to phase out checks for businesses by 2025

Victor Ludorum

Re: Just realised I DO care about the US spelling, after-all

the meaning of the comment is made ambiguous

That's kind of my point.

I was giving an example of opposite meaning between English and Americanese phrases.

Victor Ludorum
Pint

Re: Just realised I DO care about the US spelling, after-all

As a right-pondian I worry about the US-ification of almost everything. Having been a regular visitor to ElReg since 199x, I am disappointed. My tutting shall become slightly louder, lest I disturb anyone from their Times crossword...

'I realised that this also means El Reg is now likely to visit the horrors of "thru" and "pants" on me, and even worse - may well start using Americanisms that are either unknown to me, or which have referents unknown to me, or which have the opposite meaning to that which I'd expect.'

I expect there are some who could care less...

The one with the Kentish hops, please -->

Loathsome eighties ladder-climber levelled by a custom DOS prompt

Victor Ludorum
Black Helicopters

Re: Crashed most of the time.

Was that your flying or the game?

Senior engineer reported to management for failing to fix a stapler

Victor Ludorum

Re: But I DO want to know!

I think that was Happy Eater.

Linus Torvalds's faulty memory (RAM, not wetware) slows kernel development

Victor Ludorum

Re: Hang on..

There is a possibility it's not the DIMM, but a component on the motherboard that has failed. Soak testing the new memory will help to eliminate that possibility.

Cisco: Yes, Yanluowang leaked our data. No, it's not serious

Victor Ludorum

Re: Once again, a professional company is hacked

There has to be a trade off between ease of use, convenience and security.

Air-gapped data is secure, but convenient? No.

Time-based 2FA (e.g. Google Authenticator) is probably one of the best compromises, but can be MITM-ed.

SMS-based 2FA can also be MITM-ed.

A hardware (U2F/FIDO) key is probably the most secure, but less convenient to use. And it can be lost...

I think the best option is continuously educating the user, but that is often seen more as a cost than a benefit to the company.

OVH opens less flammable datacenter at site of 2021 fire

Victor Ludorum

Neat cabling

It might not be the neatest cabling in Octave's pic, but I think pretty much everyone here has seen a LOT worse!

Scientists pull hydrogen from thin air in promising clean energy move

Victor Ludorum
Joke

Re: Storage ? Transport ?

You, sir, are a genius!

That will use up all those pesky carbon atoms so they don't combine with two (or occasionally just one) oxygen atoms and venting into the atmosphere.

Just one teeny tiny problem. What do we then do with this CH4 to release the stored energy?

(spoilt for choice on the icon with this one -->)

Google CEO Pichai: We need to up productivity by a fifth

Victor Ludorum

Re: Depressing

Don't leave us guessing, what was the reaction?

Bye bye BoJo: Liz Truss named new UK prime minister

Victor Ludorum

Re: Trussed Up

There's Cheddar, and then there's West Country Farnhouse Cheddar (PDO).

Cloudflare: Someone tried to pull the Twilio phishing tactic on us too

Victor Ludorum

Re: Am I missing something ?

I'm not sure a Google Authenticator style 2FA would have stopped them. According to the article the login credentials are sent instantly from the fake login page via Telegram. Assuming the fake login page also then asks for the 2FA code, the man in the middle has a (max 30 second) window of opportunity to capture and use that 2FA code to login.

Original Acorn Arthur project lead explains RISC OS genesis

Victor Ludorum

Wonderful

So that's where ARTHUR got his name from.

I also remember the '!Lander' demo-type game that showed the Archimedes' graphics capability, which was pretty cool for the time, if somewhat limited in actual gameplay.

Password recovery from beyond the grave

Victor Ludorum

Re: Having read this story

I DON'T NEED A FIRST NAME.

Victor Ludorum

Re: Legal issues

Away.

512 disk drives later, Floppotron computer hardware orchestra hits v3.0

Victor Ludorum
Pint

Love it.

I'm an electronics hobbyist and like to do those small projects for learning purposes or just for pure fun.

If that's a small project, what's a big one...?

Definitely deserves one of these -->

Chinese 'Aoqin Dragon' gang runs undetected ten-year espionage spree

Victor Ludorum
Stop

Re: Once again

There are all sorts of ways the scammers could have got useful information. My guess is that the travelling friend used compromised wifi. It's not too difficult to intercept emails.

Google keeps legacy G Suite alive and free for personal use

Victor Ludorum

But many orgs (including GMail and Outlook) sinkhole OVH IP addresses for outgoing mail. How do you get round that?

Victor Ludorum

Re: Gmail's spam filtering is really good

I've noticed they are very fussy with SPF records. I've had various issued, including someone complain that I don't reply to their emails (because their SPF record is slightly wrong). I never even get the emails (not even in the Spam folder). They (and I) use Google Workspace...

The sad state of Linux desktop diversity: 21 environments, just 2 designs

Victor Ludorum

Re: RISC OS

I loved the file save method in RISC OS - you just dragged the save file icon to the folder (directory) you wanted it in. Even now, there are many Windows apps where the file save dialog doesn't seem to remember what folder you were using last, and you have to click through multiple levels to get to the folder you want.

What do you do when all your source walks out the door?

Victor Ludorum
WTF?

Re: sudo shred

Can't find it in my distro

$ sudo apt install thermite

Reading package lists... Done

Building dependency tree

Reading state information... Done

E: Unable to locate package thermite

Any ideas?

Page: