HN user

oracuk

601 karma

Father.

Security & systems architect.

Uncon Founder.

Enthusiastic amateur photographer.

London, UK.

BLOG: blog.blackswansecurity.com

EMAIL: oracuk (a.t) g-m-a-i-l (d.o.t) c-o-m

PROFILE: uk.linkedin.com/in/huggins/

[ my public key: https://keybase.io/oracuk; my proof: https://keybase.io/oracuk/sigs/_5Eo_nwA6V4TdRUlbeeYRS2OcS6948Ckfyn0Tlb6X3U ]

Posts92
Comments76
View on HN
arstechnica.com 10y ago

Security firm sued for filing “woefully inadequate” forensics report

oracuk
7pts0
www.wsj.com 10y ago

Dell Files Confidentially for IPO of Cybersecurity Unit SecureWorks

oracuk
3pts0
www.bbc.co.uk 11y ago

Brent crude oil price dips below $50 a barrel

oracuk
1pts0
www.theguardian.com 11y ago

Kepler 438b: Most Earth-like planet ever discovered could be home for alien life

oracuk
1pts0
www.zdnet.com 11y ago

Seagate offers low-cost 8TB hard drives

oracuk
2pts0
audio-video.gnu.org 11y ago

Richard Stallman at TEDx Geneva 2014

oracuk
2pts1
www.bbc.co.uk 12y ago

Hacking trial: Coulson guilty, Brooks cleared of charges

oracuk
2pts0
www.pcpro.co.uk 12y ago

Ubuntu 14.04 review

oracuk
2pts0
www.slideshare.net 12y ago

How to think clearly about (cyber) security v2

oracuk
1pts0
igurublog.wordpress.com 12y ago

Julian Assange: Debian Is Owned By The NSA | IgnorantGuru's Blog

oracuk
3pts0
blogs.technet.com 12y ago

New Microsoft Threat Modeling Tool 2014 Now Available

oracuk
1pts0
m.bbc.co.uk 12y ago

Royal pardon for codebreaker Alan Turing

oracuk
2pts2
www.newstatesman.com 12y ago

London's Victorian Hyperloop: the forgotten pneumatic railway

oracuk
1pts0
gigaom.com 12y ago

If you thought the Hadoop war of words was over, think again

oracuk
2pts0
www.bbc.co.uk 12y ago

Warning over 4Chan Xbox One prank

oracuk
13pts9
ascii.textfiles.com 12y ago

The JSMESS Endgame

oracuk
3pts0
prexamples.com 12y ago

Waterstones spoof Amazon

oracuk
2pts0
myscienceacademy.org 12y ago

World Renowned Heart Surgeon Speaks Out On What Really Causes Heart Disease

oracuk
14pts14
talkingpointsmemo.com 12y ago

The House GOP's Little Rule Change That Guaranteed A Shutdown

oracuk
2pts0
www.slideshare.net 12y ago

Measuring Black Boxes (Presentation)

oracuk
1pts0
securitycatalyst.com 12y ago

Include these 3 essential elements to measure what matters

oracuk
1pts0
www.bbc.co.uk 12y ago

New York Times website down after suspected hacking

oracuk
1pts0
www.bbc.co.uk 12y ago

Ask.fm unveils changes to safety policy

oracuk
2pts0
www.bbc.co.uk 12y ago

New insights in to creating ball lightning in the lab

oracuk
1pts0
www.bbc.co.uk 12y ago

Ubuntu sets crowdfund pledge record for Edge smartphone

oracuk
7pts0
wearedata.watchdogs.com 12y ago

Watch_Dogs WeareData

oracuk
2pts0
docs.google.com 12y ago

The White Hat's Dilemma

oracuk
2pts2
www.slideshare.net 12y ago

The Factoring Dead: Preparing for the Cryptopocalypse

oracuk
168pts39
blog.mozilla.org 12y ago

Introducing Minion

oracuk
6pts0
www.bbc.co.uk 12y ago

Coding skills help geeks get top tables

oracuk
3pts0

Completely agree.

41 with two kids, all that time spent working should have been spent experiencing the world and having a lot more fun.

I think a combination of getting more senior at work and having kids reduces your choices in how you can spend your time (To be fair it opens up new options as well). It highlights the value of your time and how little you got in return for it when it was abundant.

It's probably worth remembering that there is an open source exemption. If a piece of 'intrusion software' has been published the export controls no longer apply.

Publish your exploits to github before you send them overseas or travel to the conference to announce them.

This is not a practical distinction with regard to the legislation.

A word document describing the specification for an export controlled technology is as prohibited from export as the implementation.

Having the word document on a laptop you take to another country is as much a breach of the law as shipping a centrifuge.

Why do you dislike Huawei in particular? I could hazard some guesses but most of the reasons I would guess are present in every other manufacturer I can think of. I'm truly interested in why that's a problem for you.

Apparently they signed up Huawei with a contract where they warranted there were no backdoors in the hardware. Guarantees nothing of course but props for the chutzpah to demand such an outrageous clause in the contract.

My guess would the third of your options, it feels like a scanning tool artifact.

However, my point was that even given the age of the OWASP Top 10 and its incredible brand recognition among developers globally, the IBM bulk application scans are still finding (At least some of) these issues.

Interesting point about taxonomies of security flaws, similarly taxonomies of security attacks are also hard (Wicked maybe). This may be due to the difficulty of fully defining the world of unexpected or unwanted application behaviour. There is something complex about the space of possible attacks (or flaws) that resists classification at anything other than at such a level of foundational definition to be practically useless in the real world.

This just made me cry on busy London commuter train. Cathartic but awkward. An incredibly moving story that has reminded me to tell the people that matter to me that they matter to me.

The subject of start-ups and regulators has come up a few times recently and there tends to be a view espoused that regulators are intent on legislating away innovation.

My experience of working alongside or for regulators is that they overwhelmingly do not want to write new law unless they absolutely have to. Law is hard to write, hard to schedule and politically difficult to agree.

Generally regulators prefer industry associations or similar creating 'best practices' that the regulators can then rely on for evidence of recklessness or negligence compared to peers in the industry.

This can lead to established players in a market controlling the regulatory framework for innovation but this is solved through either new players engaging with the industry associations or a truly valuable innovative approach forcing legislators hands.

By not engaging with regulators and industry associations to address best practices the only route left is to be valuable and disruptive enough to require new law which is resisted by all those involved until the last moment possible.

It is always worth remembering that no matter how good your relationship with the regulator is their goals are not yours, they would like you as an industry to be successful but they exist to protect society as a whole and when placed in a position between your success and the perception of harm to society they will enforce regulations strongly.

F-D was mostly awful because it was open. There are plenty of private security forums with a much higher signal to noise ratio.

They perform slightly different functions and rely on a higher level of trust than an open mailing list can deliver but the security community is not uniformly awful.

Anonymous DDoS'd bits of the UK govt (http://www.out-law.com/page-11476). Not critical bits but enough for them to take notice of the threat.

Much of the (UK) law enforcement response to potential civil unrest is to try to prevent escalation, this would seem to be in line with that.

Also the tactics and techniques used are frankly not something any of the other bits of UK govt outside the MOD would understand or be able to deploy.

I think the answer is what didn't motivate GCHQ to review other distributions. I think you're referring to their End User Devices Security review?

https://www.gov.uk/government/collections/end-user-devices-s...

They didn't single Ubuntu out of a crowd, they just only reviewed Ubuntu which is probably due to the brand name recognition in the government departments the advice was aimed at or possibly the experience of the team doing the review.

I have assumed that was what you were referring to and not a different statement?

I have seen the corporate response of only providing remote desktops via browser and SSL to foreign (US) deployed personnel. Means the data never physically crosses the border.

No clear players in this market for consumers though. Where is the consumer remote desktop via browser+SSL that doesn't rely on a US hosted cloud service?

I still don't see that dropping the foreign language requirement would immediately lead to an increased take up of programming languages. I don't understand why foreign languages are what should be dropped.

If there is limited time for learning and there is no space for programming then any changes should be discussed in light of the full current curriculum. The original post suggested that foreign languages should be dropped in favor of programming languages, there may be other subjects of the curriculum that could be dropped instead, especially if the yardstick of economic value is the measure to be used.

I don't think I was being clear. My point about apples and oranges was based on the view that if the programming languages achievements were as limited as the described foreign language achievements then not much would have been gained.

There are a couple of assumptions built into your proposal that I would want to see some data to support:

1: Computer programming competes with foreign languages in high schools and colleges.

2: The economic value of programming languages is greater than the economic value of foreign languages.

Your last sentence also suggests you are comparing apples and oranges, a grade of a foreign language that is dropped against achieving basic computer programming abilities. These are not the same level of achievement.

I think understanding computation is a key 21st century skill that we would do well to invest in but I think foreign languages also have value.

If GDS was the IT department for the whole of government and the departments became a team of policy analysts and ministerial support then you'd be right.

Overwhelmingly the core information management and processing is on the local IT infrastructure of each department. GDS is unifying the web presence and some of the citizen identity systems, its not fundamentally taking over the core information systems of state.

EDIT: To be clear, I think something like GDS should take a long hard look at the core information systems of state and start again with a clean slate breaking the technology and the data out of the policy silos.

The UK government is a 19th Century 'filing cabinet bandwidth' information architecture. The IT systems as always reflect the organisation structure that produces them. The data redundancy and unnecessary domain separation is frustrating and archaic.

Uk.gov is just the cherry on the top of an old and creaky enterprise design that hasn't kept pace with changes to its mission or the world around it.

Thanks for this, I finally succumbed to the 20th Century and bought the CD off of Amazon.co.uk. Just need to dig out a cd player to rip it.

I remain surprised there isn't anyone offering these as paid for MP3 downloads. Seems like the right audience for that.