Showing posts with label commentary. Show all posts
Showing posts with label commentary. Show all posts

Tuesday, March 24, 2026

SDxCentral: FCC bans all foreign-produced routers over ‘unacceptable risks to national security’

No comments:
FCC bans all foreign-produced routers over ‘unacceptable risks to national security’
By Ben Wodecki

Imports of consumer-grade foreign-made routers subject to Covered List over cybersecurity and supply chain vulnerabilities

The Federal Communications Commission (FCC) moved to ban imports of all foreign-produced routers over “unacceptable risks to national security.”

A public notice dated March 23 extends the import ban to consumer-grade devices produced outside the U.S. The move does not impact any previously-purchased consumer-grade routers, the FCC confirmed, with consumers still able to use devices they’ve already acquired.

I'm glad, and surprised it took our government so long.

But are there any US router manufacturers left to buy from?

Monday, March 16, 2026

NY Post: Gun thug busted for peddling stolen Glock to Old Dominion killer for measly $100 profit: feds

No comments:
Gun thug busted for peddling stolen Glock to Old Dominion killer for measly $100 profit: feds
By Ben Kochman, Published March 13, 2026, 6:41 p.m. ET

A Virginia man was busted Friday for swiping a gun from a car and peddling it for a measly $100 profit to Mohamed Jalloh — who then used it in the Old Dominion University terror shooting, authorities said.

And this is one (of many) reasons why gun-control laws don't work. This murderer didn't buy his gun from a licensed firearms dealer. He bought a stolen gun on the black market which, by definition, is not going to obey any laws.

Gun control laws prevent law-abiding citizens (including, possibly the instructor and students in the ROTC class where the shooting occurred) from having the means to shoot back. Fortunately, some of the students had the ability to defend themselves with bare hands and a knife, preventing this from turning into a mass-killing, but it shouldn't have had to come to that.

Monday, March 11, 2024

Federalist: Daylight Savings Is A Scam

No comments:
Daylight Savings Is A Scam
By: Nathan Stone,

Americans don’t get more daylight. Plants don’t enjoy an extra hour of sunshine. The only difference it makes is to harm our health.

A great summary about the origin of Daylight Saving time, what people claim it accomplishes, and references to the inconvenient truth that is doesn't accomplish anything, but does significantly impact our health an well-being.

Friday, February 25, 2022

Comic and a bit of philosophy

No comments:
Saturday Morning Breakfast Cereal for Friday, February 25, 2022
  • How do you stop being jealous of other people?
  • The key is to always do what is true to you. Find your highest ideal and pursue it.
    Then, when other people have more success, you can recast your failure as a heroic struggle for purity or beauty or whatever.

This comic, which portrays a very cynical view of the world (a common feature of comics by its author), calls to mind a very famous quote from the Talmud (Pirkei Avot, aka "Ethics of the Fathers", Chapter 4, mishna 1):

Wednesday, February 23, 2022

Computer Weekly: Backups ‘no longer effective’ for stopping ransomware attacks

No comments:
Backups ‘no longer effective’ for stopping ransomware attacks
By Alex Scroxton. 23 Feb 2022 14:00

...
Data collated from Venafi’s worldwide survey of IT and security decision-makers reveal that 83% of successful ransomware attacks now involve alternative extortion methods – for example, using stolen data to extort customers (38%), leaking data to the dark web (35%), and informing customers that their data has been compromised (32%). A mere 17% of attacks merely ask for money for a decryption key.
...
Venafi also found that cyber criminals are increasingly following through on their threats whether or not they get paid. Indeed, 18% of victims had their data leaked despite paying, while more than the 16% who refused outright to pay anything and had their data leaked. Some 8% refused outright, but then had their customers extorted; and 35% paid, but were left hanging, unable to retrieve their data.

In other words, if you are victim of a ransomware attack, you're screwed no matter what you do. Even if you pay up, there's a good chance you won't get your data back and your confidential data may still be published.

So, (desptie the article's headline), the best you can hope for is to get yourself operational by restoring from a backup (be sure to retain several, in case your most recent one was corrupted by the attack), and don't pay the ransom.

Tuesday, October 05, 2021

The UN's two-faced policies

No comments:
This morning, I heard about this incredible news:
43 countries pledge to combat antisemitism at UNHRC session
i24NEWS.

Statement led by Austria, Czech Republic and Slovakia in coordination with World Jewish Congress

At least 43 countries signed a statement pledging to combat antisemitism that was issued at the 48th session of the United Nations Human Rights Council (UNHRC) in Geneva on Monday.

The statement was led by Austria, the Czech Republic and Slovakia with the coordination of the World Jewish Congress.

Austrian Foreign Minister Alexander Schallenberg warned of the dangers of antisemitism in a video statement, saying that "we will remain steadfast in our pledge, never again."

Which was a very welcome surprise. Then I saw the following article, posted only a few hours later:

UN Cuts Off UN Watch Director for Highlighting UNRWA Antisemitism
Aaron Bandler.

The United Nations Human Rights Council (UNHRC) cut off UN Watch Executive Director Hillel Neuer as he was highlighting antisemitic social media posts from various United Nations Relief and Works Agency for Palestine Refugees in the Near East (UNRWA).

Speaking virtually at the October 2 UNHRC session, Neuer cited UN Watch’s recent report about two UNRWA teachers in the Gaza Strip, one who posted an Adolf Hitler video to Facebook “with quotes to ‘enrich and enlighten your minds’” and another who posted “conspiracy theories” about Jews controlling the world, starting the COVID-19 pandemic aiming “to destroy Islam.” At that point, UNHRC President Nazhat Shameem Khan cut off Neuer’s video feed, accusing Neuer of making “insulting and inflammatory remarks.”

So, apparently, the Human Rights Council opposes Jew hatred, but not when it's coming from other UN agencies. Why am I not the least bit surprised?

Wednesday, September 22, 2021

Netflix acquires Roald Dahl's estate

No comments:
Netflix Acquires Prominent Anti-Semite’s Estate, Announces Epic Content Dump
Andrew Stiles • September 22, 2021 6:30 pm

Netflix, a media conglomerate with ties to former president Barack Obama, announced on Wednesday its acquisition of British author Roald Dahl's estate and promised to produce "a unique universe across animated and live action films and TV, publishing, games, immersive experiences, live theatre, consumer products and more."

In addition to authoring such classics as Matilda and Charlie and the Chocolate Factory, Dahl was a virulent anti-Semite who would have already been ruthlessly canceled by woke scolds if his bigotry had been directed at any other vulnerable minority.

I completely understand the desire to censor all of Dahl's work from history because of his anti-semitism.

On the other hand, with Netflix buying Dahl's estate, I no longer feel uncomfortable buying his famous children's books because the money will no longer be going to his family (which seems to have taken a conspicuously long time to publicly disagree with Roald's statements).

Of course, I don't approve of Netflix's politics very much either, but that's another discussion.

Thursday, June 17, 2021

More Dell sleazy behavior

No comments:
As you may already be aware, Dell is a company I never want to do business with, thanks to very sleazy and capricious behavior.

Well, it appears that I'm not the only one who feels this way. This past December (yes, six months ago - sorry for the delay), Linus Tech Tips reported even worse behavior.

As a part of their Gaming PC Secret Shopper 2 series, the found that the Dell phone sales person was heavily pushing them to buy unwanted antivirus software and extended warranties. And even though they refused these items at every step, Dell included them in the order and billed them for it.

If you thought my rant was just one person with a bad experience, you may want to think again. Watch the video for Linus's rant, which is even cooler than mine:

And this wasn't the first time Dell tried to scam the LTT secret shopper. In October, 2019, their first secret shopper also showed Dell to be pretty bad.

Thursday, May 27, 2021

Clickbait security hole?

No comments:
“Unpatchable” vuln in Apple’s new Mac chip – what you need to know
By Paul Ducklin,

Apple’s brand new Mac has a security hole, right inside the processor itself!

The official name for the bug is CVE-2021-30747, but the developer who discovered it prefers to call it M1RACLES, all in caps.

Like every BWAIN (our own impressive name for bugs with impressive names, short for Bug With An Impressive Name), it has a personalised domain, a logo and a website where you can learn all about it.

The finder of the bug, Hector Martin, writes on the website that:

The vulnerability is baked into Apple Silicon chips, and cannot be fixed without a new silicon revision.

... the bug name M1RACLES expands, rather tortuously, as:

M1ssing Register Access Controls Leak EL0 State

It turns out that Apple’s M1 chip includes a CPU system register known, ineffably, as s3_5_c15_c10_1.

According to Hector Martin, this register can be read from by userland programs running at EL0, though he doesn’t know what the register is actually used for, if anything.

However, userland programs aren’t supposed to be able to write into it, given that it’s a system register and supposedly off-limits to EL0 programs.

But Martin discovered that userland code can write to just two individual bits inside this register – bits that are apparently otherwise unused and therefore might be considered unimportant or even irrelevant...

... and those bits can then be read out from any other userland program.

And that’s it!

That, in a nutshell, is the entirety of the “baked-in” security vulnerability CVE-2021-30747, also known as M1RACLES.
...
There’s nothing that you can do, but fortunately there’s nothing you need to do, so you can relax.

Clearly, if it is possible to access a register you're not supposed to have access to, it's a bug that must be fixed and I suppose it technically counts as a security vulnerability but does this really require creating an entire Internet domain and web site to advertise it?

Sounds like click-bait to me.

Wednesday, May 19, 2021

Fierce Telecom: Learn the No. 1 reason some Americans don't use the internet

No comments:
Learn the No. 1 reason some Americans don't use the internet
By Roger Entner

The U.S. Government, through the NTIA, has been surveying internet usage since 2001. Since 2009, it has also been surveying reasons for not using the internet. Of all the studies that are currently under consideration to be used to justify the broadband stimulus plan, the government’s own NTIA Internet Use Survey, which was done before the conception of the plan, is the most unbiased and insightful. As universal internet access is a foregone conclusion in the current debate, the reasons why people are not using the internet have been reduced to just two factors — lack of availability and cost — when there is a lot more to the story.
...
What is the number one reason why Americans are not connected to the internet?

I know it is hard to believe that 13% of Americans are just not interested or do not need to use the internet, especially to those of us who live and die by the internet and are ultra-connected. No matter how much we spend on a national broadband plan to provide access to broadband internet or how much we subsidize internet access, when people don’t see the need or are just not interested, adoption numbers are not going to go up substantially.

Almost half of the 13% of Americans who are not interested in the internet are age 65 or older. A third is between 45 and 65 years of age, a surprising 1/6th is between 25 and 44 and an unsurprisingly low 2% is age 15 to 24. Another remarkable finding from the NTIA survey is that there is no significant ethnic or gender difference among people who are not interested in using the internet. There is also no statistically significant difference between people in urban and rural areas who don’t see a point in using the internet.

13% of Americans are not using the Internet because they see no need for it or just don't want to.

Friday, March 19, 2021

RCR Wireless: FCC continues its robocall fight with fines, warnings and a new response team

No comments:
FCC continues its robocall fight with fines, warnings and a new response team
By Kelly Hill on

The Federal Communications Commission this week levied its largest-ever fine against a robocalling operation: $225 million, against two companies which the agency says transmitted around 1 billion robocalls shilling short-term health insurance.

The FCC said that many of the calls made in the first half of 2019 by John C. Spiller and Jakob A. Mears (who used business names including Rising Eagle and JSquared Telecom) were illegally spoofed, and that the companies lied to consumers, falsely claiming to offer health insurance plans from companies such as Blue Cross Blue Shield and Cigna. In at least one case, the agency added, the spoofing led to an unassociated company being overwhelmed with call-backs from angry customers.

“Mr. Spiller admitted to the USTelecom Industry Traceback Group that he made millions of spoofed calls per day and knowingly called consumers on the Do Not Call list as he believed that it was more profitable to target these consumers. Rising Eagle made the calls on behalf of clients, the largest of which, Health Advisors of America, was sued by the Missouri Attorney General for telemarketing violations in February 2019,” the FCC added.

“The individuals involved didn’t just lie about who they were when they made their calls—they said they were calling on behalf of well-known health insurance companies on more than a billion calls. That’s fraud on an enormous scale,” said Acting Chairwoman Jessica Rosenworcel.

These people don't just need a fine. They need their entire corporation to be shut down with all the assets confiscated and all the responsible individuals sentenced to years in prison.

Thursday, February 11, 2021

Bleeping Computer: Researcher hacks over 35 tech firms in novel supply chain attack

No comments:
Researcher hacks over 35 tech firms in novel supply chain attack
By Ax Sharma. February 9, 2021, 01:04 PM

A researcher managed to breach over 35 major companies' internal systems, including Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, and Uber, in a novel software supply chain attack.

The attack comprised uploading malware to open source repositories including PyPI, npm, and RubyGems, which then got distributed downstream automatically into the company's internal applications.

Unlike traditional typosquatting attacks that rely on social engineering tactics or the victim misspelling a package name, this particular supply chain attack is more sophisticated as it needed no action by the victim, who automatically received the malicious packages.

This is because the attack leveraged a unique design flaw of the open-source ecosystems called dependency confusion.

For his ethical research efforts, the researcher has earned well over $130,000 in bug bounties.

A remarkably simple attack revealing serious problems in corporations' open source package distribution systems.

Like most companies using open source software, they develop applications containing both public packages (which come from well-known and trusted Internet repositories) and private packages (developed in-house). In order to maximize reuse of private packages, they are deployed using an internal repository system, which automatically installs and an application's dependent packages, regardless of where they come from.

The problem happens because the internal repository system doesn't seem to distinguish between private and public packages. So if your application is using a private package, and later one a public repository adds a new package with the same name, the system may end up replacing your internal package with the one from the public server. And because automatic updates are common (in order to quickly incorporate bug fixes and security patches), these replacement packages may automatically get installed into publicly accessible applications.

Well that's not right.

Fortunately, this test was from a security researcher, who promptly reported the bugs, but this could just as easily been malware.

I don't think this should be hard to fix. Internal package management systems need to distinguish between public and private packages. When a given package name exists as both a public and a private package, the system *must* always give priority to the private package. It must also alert administrators and owners of affected applications to alert them to the conflics, so appropriate action may be taken. This action may be one or more of:

  • Block the public package
  • Rename the private package and update all applications using it so they use the renamed package
  • Allow application developers to explicitly state in their package manifests if they want to use the public or the private version

Friday, December 18, 2020

The Federalist: Ring In Your Holidays By Buying All The Australian Wines The Chinese Won’t

No comments:
Ring In Your Holidays By Buying All The Australian Wines The Chinese Won’t
By Sumantra Maitra, December 18, 2020

In an escalating dispute, Australian Trade Minister Simon Birmingham is taking his nation’s quarrel with China to the World Trade Organization for its tariffs on Australian products.
...
Something else started it all. China, an imperial power throughout nearly its entire history, has finally realized that Australia is fit to be an outpost. The stubborn Aussie refusal to cave to China on all regional concerns eventually led to a crushing tariff over Australian wines.

I'm doing my part. My usual Shabbos wine is Teal Lake Shiraz.

Tuesday, November 10, 2020

Krebs on Security: Ransomware Group Turns to Facebook Ads

No comments:
Ransomware Group Turns to Facebook Ads
Brian Krebs. November 10, 2020

It’s bad enough that many ransomware gangs now have blogs where they publish data stolen from companies that refuse to make an extortion payment. Now, one crime group has started using hacked Facebook accounts to run ads publicly pressuring their ransomware victims into paying up.

Just when you thought Facebook had hit rock bottom. Now their adware network is being used for criminal extortion. And they're not even refunding the money to the victims who had their accounts hijacked in the process.

So glad I drop-kicked them to the curb many years ago.

Tuesday, September 01, 2020

How to deal with a patent troll

No comments:
Lawsuit accusing entire computer industry of patent infringement fails on missed deadline
By Mike Peterson, Apple Insider. September 1, 2020

A lawsuit that accused essentially the entire computer industry of patent infringement has been dismissed because an opening brief wasn't filed by the deadline.

In September 2019, plaintiff Mers Kutt filed a lawsuit in the U.S. District Court for the Eastern District of Texas. It alleged $350 billion in damages against more than 40 technology companies, telecom providers, and financial firms, among others. Apple was included at the top of the list.

After a majority of those companies filed opposing orders, a judge in March 2020 dismissed the case with prejudice. Kutt appealed that decision, but apparently failed to file an opening brief by a July 2 deadline. The lawsuit was tossed on Sept. 1.

In other words:

  • Patent troll sues everybody in the universe for a quarter of a trillion dollars
  • Everybody in the universe tells him to get bent and a judge agrees
  • Patent troll claims he will appeal, but instead slinks off to his cave, not even bothering to file the paperwork to continue his suit
This is the only way to handle a bully. Don't settle out of court. Don't pay a penny. Force him to defend his idiocy and watch him back down. The last thing a troll wants is an actual fight.

Wednesday, August 19, 2020

Horowitz: Coronavirus hospitalizations down to lowest levels of pandemic. So where is our exit strategy?

No comments:
Coronavirus hospitalizations down to lowest levels of pandemic. So where is our exit strategy?
Daniel Horowitz, Conservative Review. August 18, 2020

It’s now becoming clear, from every state and country that has reached saturation levels of the virus, that the virus burns out roughly around the 20% seroprevalence benchmark, not at the 80% threshold the fearmongers predicted. Whether it’s Sweden, New York, or Arizona, the virus is going to do what it does – meaning it spreads for about six weeks in a given region and then moves on. The only question is whether we will continue to destroy our society, mental health, and economy or achieve herd immunity without adding the man-made death toll. Herd immunity is going to happen, whether we aim for it or not.

Please read the entire article. It's full of hard facts and statistics that the media has been actively suppressing in order to keep you panicked and afraid.

Thursday, August 06, 2020

New York City: It will cost you $10,000 to visit our city

No comments:
NYC Mayor de Blasio sets up COVID-19 quarantine checkpoints at city's bridges and tunnels, threatens violators with $10,000 fines
Chris Field, The Blaze. August 05, 2020

New York City Mayor Bill de Blasio announced that the city would be seriously cracking down on anyone coming from the nearly three dozen states that Gov. Andrew Cuomo has placed on a must-quarantine list.

The mayor's crackdown includes randomized checks at bridges and tunnels into the city as well as fines of up to $10,000 for failing to follow quarantine orders.

The mayor declared during a press briefing Wednesday that New York would be immediately instituting a number of checkpoints at major city entry points, WINS-AM reported. The goal is to make sure that people traveling into the city from Cuomo's travel advisory list understand that they must quarantine themselves for 14 days.

Does anyone else think that this is the first step on the road permanently sealing off New York City from the rest of the world a-la that dumb 80's movie, Escape From new York?

Friday, July 31, 2020

IEEE Spectrum: Video Game Approved as Prescription Medicine

No comments:
Video Game Approved as Prescription Medicine
By Mark Anderson. 31 Jul 2020 | 15:00 GMT

U.S. Drug safety agency says EndeavorRx has proven therapeutic effect


On 15 June, the U.S. Food and Drug Administration announced its approval of a first-person racing game called EndeavorRx. Boston-based Akili Interactive Labs, maker of the game, says its racer was originally licensed from the lab of Adam Gazzaley, a neuroscientist at the University of California, San Francisco. The company touts four peer-reviewed studies (in PLOS One, The Lancet Digital Health, The Journal of Autism, and Developmental Disorders) as well as one paper in process as support for its claims that EndeavorRx significantly improves clinical markers of attention in patients with ADHD (attention deficit hyperactivity disorder).

“EndeavorRx looks and feels like a traditional game, but it’s very different,” says Matt Omernick, Akili cofounder and the company’s chief creative officer. “EndeavorRx uses a video-game experience to present specific sensory stimuli and simultaneous motor challenges designed to target and activate the prefrontal cortex of the brain.... As a child progresses in game play, the technology is continuously measuring their performance and using adaptive algorithms to adjust the difficulty and personalize the treatment experience for each individual.”

But is it a fun game? And can you get it without a prescription?

I'm reminded of the early days of Sesame Street. The show was originally invented for the purpose of providing remedial education for those students that couldn't keep up in school. An unexpected bonus was that it also improved the education of students that were not having problems in school.

I wonder if this could end up being similar. While designed to help people with ADHD, I wonder if it could improve various mental/cognitive skills in people without ADHD. And if it's a fun game, then there's really no downside.

Thursday, July 30, 2020

CBS News: Vote-by-mail experiment reveals potential problems within postal voting system ahead of November election

No comments:
Vote-by-mail experiment reveals potential problems within postal voting system ahead of November election
CBS News. July 24, 2020, 8:58 AM

Many Americans are expected to vote by mail for the first time in November 2020 because of coronavirus concerns, so "CBS This Morning" sent out 100 mock ballots, simulating 100 voters in locations across Philadelphia, in an experiment to see how long one should give themselves to make sure their vote counts.
...
For the experiment, a P.O. box was set up to represent a local election office. A few days after the initial ballots were mailed, 100 more were sent.

The mock ballots used the same size envelope and same class of mail as real ballots, and even had mock votes folded in to approximate the weight. The biggest difference: real mail-in ballots have a logo that is meant to expedite them. "CBS This Morning" was unable to include [it in] the trial.

A week after initial ballots were sent, most ballots appeared to be missing from the P.O. box.
...
Out of the initial batch mailed a week earlier, 97 out of 100 votes had arrived. Three simulated persons, or 3% of voters, were effectively disenfranchised by mail by giving their ballots a week to arrive. In a close election, 3% could be pivotal.

Four days after mailing the second batch of mock ballots, 21% of the votes hadn't arrived.

Needless to say, I am not surprised by this. And neither are the Philadelphia residents CBS interviewed. In the video, everybody interviewed said that they wouldn't trust the post office with something as important as their vote. Election officials work very hard to make sure they count every vote they receive by the deadline, but they have no way to make sure the ballots are delivered to them on time.

I, myself, have had critical mail go missing. Not a vote, but one of my estimated tax payments went missing last year. I had to have my bank issue a stop-payment on the cheque and mail another. I'm just glad the government didn't force me to pay a penalty after that screw-up.

My advice to you:

  • If you have to mail something important, send it two weeks before it needs to arrive. Consider paying for a return receipt (as proof that it was delivered) and/or sending it priority mail in order to increase the odds of on-time delivery.
  • Vote in person. I know everybody is worried about getting the coronavirus, but unless you're in a high-risk category, the risk is going to be very low. Especially if you keep your distance from others. I don't know about all locations, but where I live, polling places enforce social distancing. It's less risky than going to the grocery store. If you're OK with going out shopping, then you should be OK with going to vote.

Tuesday, July 28, 2020

Red State: The 1619 Project’s Creator Admits It’s Not Really History

No comments:
The 1619 Project’s Creator Admits It’s Not Really History
Posted at 11:45 am on July 27, 2020 by Joe Cunningham

The 1619 Project, an ideologically-driven revisionist history of the United States, has been getting a lot of attention over the last several days as Arkansas Senator Tom Cotton threatened legislation to defund any school that uses any curriculum based on it.
...
Nikole Hannah-Jones took to Twitter Monday morning to walk back the assertion that the 1619 Project was “a history,” insisting that it was a project of journalism:

"I’ve always said that the 1619 Project is not a history. It is a work of journalism that explicitly seeks to challenge the national narrative and, therefore, the national memory. The project has always been as much about the present as it is the past."

That tweets here are part of a larger thread where Hannah-Jones tries to clarify the purpose of the project. However, the treatment of the 1619 Project has been pushed by her, the New York Times, and supporters as THE definitive history of the United States, arguing that the “true” history of the nation stemmed from the arrival of the first slave ship in 1619, rather than from the actual Declaration of Independence from Great Britain and the subject structuring of the United States Constitution.

Now that the author herself admits that this entire "project" is nothing but revisionist history propaganda, can we stop mandating that the public schools teach it our children?