HN user

omh

1,776 karma

Email: hn @ doublegeek.com

Posts24
Comments399
View on HN
www.tomshardware.com 2mo ago

Meta will beam sunlight from space to power AI data centers

omh
3pts1
www.bloomberg.com 7y ago

The $250 Biohack That’s Revolutionizing Life with Diabetes

omh
32pts9
blog.cyber.fund 8y ago

Huge Ethereum mixer

omh
2pts0
www.theverge.com 9y ago

Microsoft releases new XP patches, warns of state-sponsored cyberattacks

omh
1pts0
imgur.com 9y ago

Mulled Wine PC

omh
1pts0
www.bloomberg.com 10y ago

Blythe Masters Tells Banks the Blockchain Changes Everything

omh
8pts0
www.ft.com 10y ago

Financial Times: Banks seek the key to blockchain

omh
1pts0
arstechnica.com 11y ago

Why the head of Mt. Gox Bitcoin exchange should be in jail

omh
5pts0
www.businessweek.com 12y ago

The Trouble With IBM

omh
22pts5
arstechnica.com 12y ago

Antivirus pioneer Symantec declares AV “dead” and “doomed to failure”

omh
3pts0
www.foreo.com 12y ago

Brighter Moon – A solution to the global energy crisis

omh
2pts2
www.theregister.co.uk 12y ago

Microsoft in 1-year Windows XP survival deal with UK govt

omh
1pts0
geography.oii.ox.ac.uk 12y ago

A tube map of the Internet

omh
150pts48
twitter.com 12y ago

UK hospital records data was publicly available online

omh
1pts0
arstechnica.com 13y ago

Tax man trying to figure out a way to outsmart Google

omh
3pts1
www.economist.com 13y ago

What is the impact of the iPhone on the mobile market?

omh
1pts0
blog.jgc.org 14y ago

Tacoli: a simple logging format

omh
15pts2
www.significancemagazine.org 14y ago

Statistics of failures in solving crosswords

omh
1pts0
torrentfreak.com 14y ago

Public consultation on UK's Digital Economy Act was a sham

omh
32pts27
www.bbc.co.uk 15y ago

BBC Worldwide to offer TV episodes to rent for the first time on Facebook

omh
3pts3
www.codinghorror.com 15y ago

Revisiting the Home Theater PC

omh
35pts45
lonesysadmin.net 15y ago

Dear Microsoft: One Central Update Framework

omh
1pts0
blogs.adobe.com 15y ago

New Adobe Reader with Sandboxing

omh
2pts0
googleenterprise.blogspot.com 15y ago

Google Apps adds two-factor authentication via SMS

omh
35pts23

It's mind boggling how bad Microsoft have made this.

I just want to install a few apps and manage their settings. But the combination of Windows, Intune, modern Store apps, multiple similar settings, and licensing, make it a full time job full of footguns.

If they just had one team with responsibility for end user experience they could bring this tech together in amazing ways.

But instead there's probably at least one FTE is every IT department in the world just managing Microsoft's bullshit

There are some SFF PCs that can take USB-C power.

Lenovo have some,but sometimes require adapter cards. And a few of the Chinese N150 units will take PD power

It's great for hot swapping and more portable than a laptop.

I'll take that bait ;-)

IP filtering is a valuable factor for security. I know which IPs belong to my organisation and these can be a useful factor in allowing access.

I've written rules which say that access should only be allowed when the client has both password and MFA and comes from a known IP address. Why shouldn't I do that?

And there are systems which only support single-factor (password) authentication so I've configured IP filtering as a second factor. I'd love them to have more options but pragmatically this works.

Thanks. That wasn't clear from the Mail article above.

But the Times article also says:

A spokeswoman for Leicestershire police said crimes under Section 127 and Section 1 include “any form of communication” such as phone calls, letters, emails and hoax calls to emergency services.

So I think the categorisation is a mess, and probably not even consistent across forces

And Microsoft own the client, so they are the one company who don't need to do this!

If you really want to check every time someone clicks on a link then you can do this in the client and keep the visible link the same for the end user.

But instead there are different teams working on this in Outlook, Teams, Exchange, Defender and god knows where else.

(I'm one of the people in corporate IT trying to turn this off and often struggling)

Good point.

But what's the threat model here?

I didn't think of 2FA as being protection against password reuse. People should still avoid reusing passwords and change them if they know of a breach.

Are there really attackers who are picking up breach databases and then sim-swapping to get the 2FA as well?

The article conflates two issues that have different security implications.

The "1-click login" links are a concern and just having access to the SMS would be enough to take over things like WhatsApp.

But 2FA codes seem notably less worrying. They are the second factor and require an attacker to have the password too. For these cases I'm much more relaxed about the use of SMS and the risks of interception.

I agree that it would be fine to not have phones - we'd all cope.

But when my daughter hasn't got home on time if I can check her GPS and see that she's in the park then I can relax a little.

If she needs to say she's staying out late, using a group chat to let the whole family know is easier than trying to phone mum, then dad, then grandma.

Or she can include a photo showing how much fun she's having.

My life is richer because of communication on things like family group chats. It would be a shame to throw the baby out with the bathwater and lose that

This debate seems to conflate two or three different issues.

1. Use of phones in classrooms 2. Having phones present in schools, but unused 3. The impact of social media on schoolchildren

(1) is undeniably bad and should be banned everywhere.

(2) raises some issues. I don't want (1) but I would like my child to have a phone for the journey to and from school. And a smartphone is much better at this than a dumb phone (group chats are really good!)

(3) is a concern but it seems almost totally unrelated to the other issues. The children who are banned from having a phone at school will use the same social media when they're at home and schools will still have to deal with bullying.

Our school current bans (1) and is consulting on more bans. But from parent discussions it feels like both the school and parents are mixing up these issues and just coming back with "phones are bad".

Also it would be very possible to misread the confirmation.

If I've just entered "0.21" then when the confirmation screen reads "21" it's not immediately obvious that it's wrong.

I've got this Tandem pump and we discussed this exact bug when I received the pump.

To my understanding this isn't the same type of bug. Tandem are just saying "it can be confusing to enter fractional rates".

This bug is for a different pump and is "when you enter a fraction rate it will change the rate". That is much worse

A clearer description of the bug is here:

https://twitter.com/Tims_Pants/status/1730515134731182490

It's wild that this sort of bug got through testing.

As a diabetic it feels like our insulin pump software is very conservative and lacking in features especially compared to what some of the "closed loop" things would like to do.

That seems reasonable if the manufacturers are having to do lots of safety testing.

But if bugs like this are getting through then the testing obviously isn't anywhere near as robust as we'd like.

As a slightly more frivolous use of this website - we're approaching conker season!

Last year my kids wanted to go collecting conkers and I used a similar website (https://www.treetalk.co.uk/) to find a local place with lots of horse chestnuts.

It worked brilliantly and the kids thought I was some kind of genius for finding so many.

I have the Awair Element and I'm reasonably happy with it.

The primary interface is through their app and I think you might need to use this to get it up and running initially. But they have a supported local API feature[1] that has so far worked as I'd expect. In the end I've been happy with their app so have primarily used that so far. The data seems good.

They're quite expensive new. But they were involved in some sort of cryptocurrency (!) that failed. So there are a lot of them available as nearly-new on eBay. In the UK I picked one up for about £60, I think.

[1] https://support.getawair.com/hc/en-us/articles/360049221014-...

Even in this dual-homed setup, there is still the potential for the cameras to infect, or otherwise compromise the recording server

I agree that this is a potential risk.

But if the cameras themselves can't route to the internet in this scenario then how are they infecting the recording server? Is the suggestion that they come shipped from the factory with code to compromise common recording servers? It seems like that would be very significant and something that we'd be able to see in action.

My biggest concern with CCTV networks that I manage is some sort of backdoor access to the cameras themselves. So the dual-homed server design is exactly what I'd choose in order to control things.

[ Disclaimer - I am responsible for a Citrix environment, but I'm reasonably proud of how well it works for our company ]

The technology behind remote desktops is fundamentally limited but I'm amazed at how good the user experience can be on a modern well-configured Citrix environment.

- The protocol responds well even on low bandwidth as long as latency is OK. On the office LAN it feels like a local computer.

- There is offloading for Teams[1], media streams[2] and even entire web browsers[3]. The tech behind this is impressive and it works pretty well (mostly!)

- For most staff it's easier to use a thin client or a minimal laptop.

- I can keep the Citrix environment patched and managed much more easily than a proliferation of laptops and home devices.

It can be a struggle at times and it's definitely not the right fit for developers. But it's got a lot of advantages and most of the time it works amazingly well.

[1] https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/m... [2] https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/m... [3] https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/m...

There is something odd about the battery life on the Ikea motion sensor.

I use it in our bathroom and it's activated multiple times per day. The first battery lasted about 3 months but the second battery has been going for over a year.

There are some reddit threads but I never got a clear answer.

It's not even using more energy than Christmas lights or wash dryers

I can't come up with any reasonable measure by which Christmas lights use more energy than Bitcoin mining. The reports that suggest this seem to extrapolate US figures across the world, which looks unrealistic. And they're old enough that they don't account for the switch to LEDs.

Even if a billion households had 50 strings of LED lights each and kept them lit 24/7 for all of December, they'd still use less energy than the annual usage of Bitcoin.

You're right that an artificial pancreas needs to be super careful.

The diabetes community got started on this before the official manufacturers did. Probably in part because the manufacturers were concerned about being 100% bulletproof whereas (some) people living with diabetes were willing to take a bit more risk. And there's a balance around alarms. Some glucose monitoring tech can be frustrating and lead to "alarm fatigue".

Most of the artificial pancreases I'm aware of mitigate some of the risk by rarely sending large boluses at all. They tend to adjust the background basal rate and only send a bolus when you explicitly tell them you've eaten.

I also have an unhackable pump, unfortunately. I know there were attempts on the later Medtronic pumps by some pretty smart people so it looks unlikely that they'll ever be able to be controller openly.

My next pump will definitely be one that allows remote control and some sort of looping. Whether that's officially from the manufacturer or not.

I suspect you're aware, but there is a significant community effort on communicating with various insulin pumps.

The old Medtronic pumps were hacked years ago and Medtronic responded by making it impossible with newer pumps.

By now there are at least 3 different apps on different platforms and they support a variety of pumps.

Quite a lot of organisations are now running Office 365. It gets updated monthly with new features as well as security updates.

Even more conservative organisations will often be running Office 365 with a lag, still getting features after ~6 months.

If you need 100% compatibility that will always take a while, and I'm sure some big enterprises are on old style office. But it seems like the vast majority of small/medium business is on the Office 365 juggernaut now.

I've been asking the vendor the same question!

They seem to think it's not a drop-in replacement and don't want to rework their code to deal with the changes. I'm not sure to what extent this is Microsoft making compatibility hard or just a lazy vendor.