Showing posts with label Teh Intarwebz. Show all posts
Showing posts with label Teh Intarwebz. Show all posts

Saturday, July 11, 2026

This blog is old enough to vote

Actually it has been for a couple of weeks.  I've had a pretty bad case of blogger burnout - there's been a number of blog worthy topics and I just haven't been feeling it.

Meh. 

Still, 14425 posts and 54948 comments is pretty decent.  Especially the comments.

Thanks to everyone who stops by. 

Wednesday, February 11, 2026

An interesting perspective on AI

Long time Internet Security guy Fred Cohen has some interesting thoughts on how AI can be less obnoxious [PDF]:

The nature of the problem (I think) is that the attempts at safety reflect the behavior of the people who programmed and trained the AI engines, and they are apparently snarky, obnoxious twits that think its better to argue about meta issues than to serve their customers, like me, with the real capabilities they have developed. 

Their version of safety is the opposite of mine. If you want children to be safe from AI, don’t let them use it. 

If you want adults to be safe from AI, don’t make it available. 

If you want a ship to be safe, don’t put it out to sea… but that’s not what ships are for. We trade the utility for the safety, and while making ships that leak like a sieve is a bad idea in my view, making ships that don’t sail is a fruitless effort.

... 

Solution 

The solution is to put someone in charge of these mechanisms in these companies who is not a snarky, obnoxious twit… and I hope this doesn’t exclude me from the candidate pool. 

There are also some rather direct solutions to the problem of providing information to people where the information is not something that should be provided to anybody as a matter of policy. The most obvious solution is not to incorporate any of that sort of policy-violating information in the learning process. 

Of course the snarkiness is the same problem. If you don’t teach the LLM to be snarky by feeding it snarky crap, it will probably not behave that way. It’s no different than a child brought up by respectful parents vs. disrespectful parents. They learn from their teachers. 

Conclusions 

If you don’t want trouble, stop asking for it. If you teach a dog to bite, you are unlikely to be successful at later telling it not to. If you train an LLM with views of pedophiles, fraudsters, and murderers, you are unlikely to get it to not carry that behavior through later on. 

I think that Fred's entirely correct here (note that we ignore the very serious problem of AI Hallucinations here). AI training is generally crap layered on top of the hallucination engine*.

But I wonder if this is an opportunity for AI companies?  If you did a better job training the AI to be well-behaved (like you'd do with your kids or your dogs) would you have a different - and more attractive AI offer?  How about politeand wellbehavedAI.com?  That's a branding that would stand out from all the others.  You could market it to parents worried about their kids, or to old fuddy-duddies like me who hate everything about AI?

I smell a billion dollars of venture capital here ... 

* It seems very likely that the AI algorithms cannot be prevented from hallucinating. 

Thursday, January 29, 2026

Secure Your Home Network: Which of your devices can you trust?

And more importantly, which should you not trust? 

This post is the fourth in a series on how to make your home network harder to attack.  Here are links to posts onetwo, and three.  

Now you might think the question in the post title is a bit strange - after all, these are you devices, so you'd think that they're all trustworthy.  You'd be wrong.  There are at a minimum two different categories of trustworthiness:

Your main computing devices.  These are computers (duh) such as laptops and desktop computers, servers (a future post will talk about why these can be useful to you, and your cell phones (which are nothing but tiny hand held computers).

Now I've been in security for long enough that I get a bit twitchy about mobile phone security (I'll address this in a future post as well).  However, that ship has sailed and even a security nerd like me won't bother making a separate network just for these.  So they're computing devices for this discussion.

Then there's everything else.  It's surprising how any Internet-connected thingies there are these days.  Ring doorbells, Nest thermostats, online appliances (fridges, washing machines, etc).  At this point the Borepatch from four years ago would have told you to just walk away from all this nonsense.  Don't Internet-enable anything in this category.

Today's Borepatch sighs and tells you that this is coming to a home near yours.  It's here in my home.  No, not the thermostat (which was installed by the previous owner and which I have not connected to the WiFi).  However, the TVs all come with streaming apps for Netflix, Prime, and Youtube (among dozens of others).  And The Queen Of The World reminds me that the kids like to stream when they come and visit.  She likes it when they come and visit, as do I.  And so we have to do something for these devices.

Fortunately, you don't need any new kit to do this.  If you remember from the last post on water tight compartments, you don't own the Internet box from your network provider.  Basically, you can't trust it, so you install a new firewall box running DD-WRT.  It's trustworthy because you own it and have your own software and configuration on it.

All of your main computing devices connect to it's WiFi.  All of the other devices (doorbells, thermostats, TVs, appliances) connect to the WiFi from your network provider's box.

What you've done is to put a firewall between your computing devices and your untrusted devices.  It doesn't matter if your TV gets hacked because it can't get through your DD-WRT firewall to your computers.

Likewise, your TV is at least somewhat protected from the outside world because it's behind the firewall in your network provider's box. 

Wednesday, January 14, 2026

"One more war in the West and the civilization of the ages will fall with as great a shock as that of Rome"

Who would have guessed a hundred years ago that Stanley Baldwin was right

 

I dunno - he looks a little Woodrow Wilsonish to me.  But if you're right, you're right.

And Nota Bene: it seems that DuckDuckGo can't find the link to that last post.  Strangely, Google can.  Search sting site:borepatch.blogspot.com best worst presidents on each site. So long, DuckDuckGo, it's been fun.  But I can't trust you, and neither should my readers.

Monday, January 12, 2026

Secure Your Home Network: Watertight Compartments

This post is the third in a series on how to make your home network harder to attack.  Here are links to posts one and two

Post two introduces the concept of a Firewall which is a device that lets you connect to the Internet without letting the Internet connect to you.  Firewall technology comes embedded in your Internet provider's device like a Cable TV modem.  A recent article does a comparison on a number of these devices.

If you look at the device it will look a lot like this:


The red colored connection goes out to the Internet, the yellow ones go to your devices (as does the Wifi).  This one has a connection for a landline telephone as well (ask your parents, kids).

Installing the device is really simple - red (labeled "WAN") goes to the outside which is untrusted, and yellow/WiFi go to your own devices which are trusted. 

Except nothing is as simple as that.  Your Internet provider actually owns the firewall device, it's not really yours.  Some providers run their own WiFi network for other subscribers who happen to be passing by - Verizon is notorious for this, and you will often find all sorts of WiFi networks called "VerizonXYZ" or some such.

So who is outside the firewall, and who is inside?  The question may sound pedantic but it's terribly important.  Fortunately there is something you can do about this.  

Ships used to sink all the time but this is pretty rare these days.  One major reason for this is that they are divided into compartments which are watertight - if the ship hits a rock (or, like the Andrea Doria gets rammed by another ship) only one compartment will flood and the ship can likely make it to port. 

USS South Dakota under construction

The network security analog of this idea is to use more than one firewall.  Don't trust your provider's firewall? (and you really shouldn't)  Buy your own and hook it up to your provider's firewall. The red (WAN) port on your firewall gets connected to the internal (yellow) connector on the provider firewall.  Now anyone that the firewall lets in can't get past your firewall.

And it really is your firewall, although you'll have to buy it with cash money.  But your devices connect to your firewall's yellow network connections, or to your firewall's (NOT your provider's firewall) WiFi.

Now you don't have to trust your provider because their device doesn't have access to your internal "watertight compartment".

Linksys, Netgear, and TP-Link are low cost options, running $30 - $70 or so.

The first thing you should do is replace your firewall's operating system with dd-wrt:

DD-WRT is a Linux based alternative OpenSource firmware suitable for a great variety of WLAN routers and embedded systems. The main emphasis lies on providing the easiest possible handling while at the same time supporting a great number of functionalities within the framework of the respective hardware platform used. 

Here's a step by step tutorial on how to install dd-wrt on a Netgear device:

 


[UPDATE: Rick T in the comments says to check the dd-wrt website before buying a device, to make sure that the software supports that particular hardware.] 

Why go to this hassle?  Product longevity.  Consider a $60 Netgear device.  The profit margin on this to Netgear is probably $5.  You can't pay for a lot of enhancements or security bug fixes with that.  DD-wrt is an open source project with a bunch of passionate contributors.  I like my chances on having a viable, supported software five years down the road with them.  Not so much the device manufacturers.

So now you have a device you can trust for the long term.   We're not done yet, because there's all sorts of new tech evil that people want to use - Ring doorbells, Alexa, etc.  That's tomorrow.

Saturday, January 10, 2026

Secure Your Home Network: What is a Firewall and why do you care?

Forget about the Internet and security for a moment - you already own something with a firewall.  Your car has one between the engine and the passenger compartment, even if your car isn't a sweet 1969 Dodge Charger.

 

The firewall in your car is designed to contain engine fires to the engine compartment, not letting the flames spread to the passengers.  Firewalls have been around cars for a long, long time - certainly since the 1930s, and probably a lot longer.

Now back to the Internet and security.  Internet firewalls are designed to keep bad things (and Bad Guys) out of your network, so they don't burn down all your devices.  Yes, I stretched that metaphor, but that's exactly where the name came from.

An old Internet wag once described a firewall as a device that "keeps the bad guys out while letting the good guys out".  That's a really good description.  Internet firewalls have been around for basically as long as there has been an Internet, say from around 1990.  The technology is very well understood, and very mature.  That's the good news.

The bad news is that there are a million ways to set up your firewall so it's more full of holes than Swiss cheese. This post will try to help you avoid this.

More good news: your Internet Provider almost certainly has a firewall capability in hte box that gives you Internet access.  For example, if you get Internet via cable TV, you have not only a cable box that changes channels, you have a separate box that gives Internet.  That thing has a firewall built in, so yay.

You an check this yourself via a web site that I've linked to a number of times over the years, Steve Gibson's Gibson Research.  You should see something that looks like this:


Green is good. 

So what went on when you ran that?  There are a bunch of Internet services like web, email, and so on.  Each uses a "port" - email is 25, web is 80, there are a bunch of others.  What Gibson's app did was to try to connect to all of these posts on your IP address.  Ideally, your firewall (like mine) dropped these connections in the trash can.

So from a first cut, your firewall is letting you out onto the Internet (so you can read this, hello!) but keeping the Bad Guys out. 

But the devil is in the details of how we (and our devices) use the Internet.  The next post in this series will explore this: Secure Your Home Network: Can (and should) you trust your devices?

Wednesday, December 31, 2025

2025 Blog stats

This was the best year ever for traffic here: 4.5M page views.  This brings the all-time total to 19.5M.  There's quite a market for free Internet blather.

And this year's over 1000 comments from you is (I think) also a record.  Many thanks to everyone who keeps coming by and especially for commenters.

Top referrers:

  1. Knuckledraggin My Life Away (thanks, Wirecutter!)
  2.  The Feral Irishman (thanks, blog brother!) 
  3.  Raconteur Report (thanks, Aesop!)
  4.  Normal American (I hope you haven't hung up your blogging shoes)
  5.  Busted Knuckles (thanks, CederQ!)
  6. The Silicon Graybeard (thanks, buddy!) 

If anyone cares, here is a list of the top posts for traffic.  It's interesting that most are pretty old:

  1. I Am TJIC (after 14 years this still gets a ton of traffic)
  2. I Confess, I'm Not Opposed To Gun Control (this was fun to write)
  3. This Blog Belches Carbon (from all the way back in 2010) 
  4. A Layman's Guide to the Science of Global Warming (needs updating)
  5. Dad Joke CCCLVIIII (I have no idea why this got so much traffic)
  6. Dad Joke CCCLXII (Tuna is doing most of my Dad Joke blogging)
  7. Should You Be A Global Warming Skeptic? (from 2009 but superseded by the Layman's Guide post, above)
  8. Aaaaarrrrrrgh, Matey! Don't be shiverin' me timbers! (A blog meet from 2009)
  9. Google Play Store filled with malware (a post from 2025!)
  10. This.  1000x this. (another post from 2025!  Go figure ...)

So a lot of old posts still drawing traffic.  It's gratifying to read them and see how well they've held up.

So goodbye to 2025 blogging.  On to 2026! 

Wednesday, June 25, 2025

Happy Blogiversary to us

17 years ago I put up my first post here.  Around the same time, ASM826 - my brother from another mother - put up his first post on his blog, Random Acts Of Patriotism.

17 years later, we are still here.  I almost hung up my blogging shoes but realized that the world needed Dad Jokes.  Err, or something.

And ASM826 is still here, too.  And a lonely place it would be, too, without him.  We both need to do more firearms related posts.  Range Reports, that sort of stuff.  I shall endeavour to improve my output here.

It's weird that in another year, this blog would be old enough to vote. 

Wednesday, May 14, 2025

A message to the blog Common Cents

You know, this one here

Dude, you've been coming around here for a long time asking to get added to the blog roll. And when I do add you, you don't seem to notice: not four months after that first link you're back in the comments asking to get blogrolled even though you were already there.

This has been your unique approach to blogging for 15 years.  Weird.

Actually, it's gotten worse.  You've left two links in two days about something entirely unrelated to my posts, pointing to a post on your site. That's comment spam.  I see that you have ads on your site, so I guess that's why.  It doesn't seem that you added me to your blogroll, so reciprocal blog back scratching doesn't seem to be your thing.


Commen Sense, you are not welcome here, because you don't have any manners.  All your comments will be deleted in the future because you are trying to hijack my site.  Not cool.

Tuesday, April 29, 2025

Reliability and the Cloud

Well that's your problem, right there:

Oracle engineers mistakenly triggered a five-day software outage at a number of Community Health Systems hospitals, causing the facilities to temporarily return to paper-based patient records.

CHS told CNBC that the outage involving Oracle Health, the company’s electronic health record (EHR) system, affected “several” hospitals, leading them to activate “downtime procedures.” Trade publication Becker’s Hospital Review reported that 45 hospitals were hit.

The outage began on April 23, after engineers conducting maintenance work mistakenly deleted critical storage connected to a key database, a CHS spokesperson said in a statement. The outage was resolved on Monday, and was not related to a cyberattack or other security incident.

 Everything is "cloud" these days.  Having worked in cloud for a decade, it's really really hard to get good reliability.  The best vendors promise "Five Nines" reliability, i.e. uptime of 99.999%.  The very best vendors have compensation clauses in their contracts and pay penalties to customers when they don't meet the uptime agreement.

Five Nines means that you will have no more than five minutes of downtime in a year.  Like I said, this is really hard stuff.

Oracle Health had this customer down for five days.  This translates to less than 99% uptime - probably 98.5%.  Not a good look for a cloud provider.

Even worse, this isn't the first problem for Oracle Health.  Oracle Health's Federal cloud went down for a day last month, taking 6 VA Hospitals and 26 clinics with them.  

If you're in IT and looking at cloud services (and why wouldn't you?), pay special attention to the Service Level Agreements.  SLAs with penalty clauses mean that the vendor is serious about reliability.

Tuesday, February 25, 2025

Congress pushes back on UK snooping

Maybe there's something in the water in Washington D.C. these days, but this is clearly A Very Good Thing Indeed:

A bipartisan, bicameral pair of lawmakers urged newly confirmed Director of National Intelligence Tulsi Gabbard to reevaluate U.S. cybersecurity and intelligence-sharing relations with the United Kingdom in response to a report revealing that the UK secretly ordered Apple to build a backdoor into encrypted iCloud backups.

The Feb. 7 report from the Washington Post says that the order issued last month demands UK law enforcement and intelligence operatives be granted worldwide, unfettered access to users’ protected cloud data. Apple customers residing in the United States would be cast into that dragnet.

Sen. Ron Wyden, D-Ore., and Rep. Andy Biggs, R-Ariz., asked Gabbard in the Thursday missive if the Trump administration was made aware of the order by stakeholders and whether the White House has understanding of the CLOUD Act, which lets U.S. law enforcement get data stored by American tech companies, even if that data is on servers outside the U.S., by using warrants or subpoenas.

“If Apple is forced to build a backdoor in its products, that backdoor will end up in Americans’ phones, tablets, and computers, undermining the security of Americans’ data, as well as of the countless federal, state and local government agencies that entrust sensitive data to Apple products,” they wrote in their letter to Gabbard.

Remember, Encryption Backdoors are a Very Bad Idea.  It's not just me saying this, it's the former Director of the UK's GCHQ (their NSA equivalent).

And well done to Congresscritters from both parties in both the House and Senate for putting some pressure on the idiots in Blimey.

Monday, January 27, 2025

So Trump pardoned Ross Ulbricht

Ulbricht was the guy who set up the "Dark Web" site The Silk Road.  I am a little conflicted about this.

On the one hand, he made money on each drug deal that went through his site.  There's no question that this was dirty money.

On the other hand, his 2 life sentences without the possibility of parole was hideously excessive.  People have pointed out (rightly) that drug dealers convicted of using the site to sell their wares got much less time.

And on the gripping hand, a place where people can spend their money without the 24/7 government surveillance of everything sure seemed like it was a good thing.

I wonder if Trump would have issued the pardon if he hadn't been railroaded through the legal system himself.  All in all, the "Justice system" here has taken a huge credibility hit.

Wednesday, November 20, 2024

New substack that's worth your time

Randal emails to point out that he's started a Substack.  It's pretty interesting.  Here's an example about trade unions:

For the longest time much of the media has fed us the idea that “union = overpaid/lazy/bad”. Now we should all have the following ingrained in our skulls by now, “the media lies”.

Proceeding from that “law” (it really should be a scientific law at this point) we can deduce that the media is lying about unions. The real question to ask ourselves is, “why?”

Like I said, pretty interesting.

 

Saturday, November 16, 2024

Someone at Netflix is getting fired

So their live streaming of the Mike Tyson fight last night was an unmitigated disaster.  But come on - you'd think that Netflix IT would understand how to spin up capacity to meet demand.  Maybe their replacements will.

For those who like the Sweet Science (or who used to), this is a fascinating episode from Hard Core History about how boxing has changed over time, mostly for the worse.  Dan Carlin interviews Mike Silver, author of The Arc of Boxing which is a terrific read.  I'm in general agreement with both the podcast and the book, although have to admit that I quite enjoyed the Barrios/Ramos bout last night.  It had a very Friday Night Fights feel to it.

Monday, July 8, 2024

Censorship: Action, Reaction

So Youtube hates guns and is trying to demonitize shooting channels.  So one of the channels decided to follow the rules, with hilarious results.

Monday, May 6, 2024

Kaiser Permanente shares user data with Google, Microsoft, and others

Well, well, well:

Millions of Kaiser Permanente patients' data was likely handed over to Google, Microsoft Bing, X/Twitter, and other third-parties, according to the American healthcare giant.

Kaiser told The Register it has started notifying 13.4 million current and former members and patients that "certain online technologies, previously installed on its websites and mobile applications, may have transmitted personal information to third-party vendors," when customers used its websites and mobile applications.

Kaiser has since removed that tech from its websites and apps, and said it is not aware of "any misuse of any member's or patient's personal information."

Yeah, I'll bet.


If you get Kaiser Permanente insurance at work, you might want to ask your HR department for an assessment of whether your data was included in this data sharing scheme.  It's hard to see how at the minimum HIPAA-adjacent data was not shared here.

 

Monday, April 29, 2024

Ring doorbell company fined millions of dollars for privacy violations

Well knock me over with a feather:

The FTC today announced it would be sending refunds totaling $5.6 million to Ring customers, paid from the Amazon subsidiary's coffers.

The windfall stems from allegations made by the US watchdog that folks could have been, and were, spied upon by cybercriminals and rogue Ring workers via their Ring home security cameras.

The regulator last year accused Ring of sloppy privacy protections that allowed the aforementioned spying to occur or potentially occur.

...
 

In the most egregious case, one employee went out of his way to view "thousands of video recordings belonging to at least 81 unique female users," according to the FTC. A coworker reported this behavior to her supervisor, who it's alleged initially said this snooping wasn't that strange until he realized the rogue employee was only reviewing videos of "pretty girls."

The fines work out to $50 per effected Ring customer.  Don't spend it all in one place.

Thursday, April 11, 2024

Security is hard, vol CCLVI

Act the first: Web Security organization suffers data breach:

A misconfigured MediaWiki web server allowed digital snoops to access members' resumes containing their personal details at the Open Web Application Security Project (OWASP) Foundation.

...

"If you were an OWASP member from 2006 to around 2014 and provided your resume as part of joining OWASP, we advise assuming your resume was part of this breach," OWASP said in a Good Friday notification posted on its website.


"We recognize the significance of this breach, especially considering the OWASP Foundation's emphasis on cybersecurity," it added.

Yup.  This shows just how hard security is - OWASP is full to the brim with folks who (a) understand the importance of security, (b) know how to implement security (well, most of the time), and (c) have a lot of reputation at stake.  That reputation took a hit here.

Act the second: OPSEC is a bitch, even for secret squirrels:

Protecting your privacy online is hard. So hard, in fact, that even a top Israeli spy who managed to stay incognito for 20 years has found himself exposed after one basic error.

The spy is named Yossi Sariel allegedly heads Israel's Unit 8200 – a team of crack infosec experts comparable to the USA’s National Security Agency or the UK’s Government Communications Headquarters. Now he's been confirmed as the author of a 2021 book titled "The Human Machine Team" about the intelligence benefits of pairing human agents with advanced AI.

Sariel – who wrote the book under the oh-so-anonymous pen name “Brigadier General YS” – made a crucial mistake after an investigation by The Guardian which found an electronic copy of Sariel's book available on Amazon "included an anonymous email that can easily be traced to Sariel's name and Google account.”
...

Being outed after more than 20 years of anonymity isn't optimal for someone who's supposed to be a top spy

Yup.  And while it's tempting to roll your eyes and chorus Top. Men., remember that this is how they nabbed Ross Ulricht, a.k.a. The Dread Pirate Roberts from The Silk Road.

Yeah, OPSEC is a stone cold bitch of a problem.  You have to be right 100% of the time, and dropping that to 99.99% means that you lose.

Tuesday, March 26, 2024

Youtube Shadowbans Climate: The Movie

The Feral Irishman emails to saw that my post about the climate movie looked weird from his Windows computer.  He could watch the movie but there was nothing displayed about Youtube.  Everything looked normal from Safari on his iPhone.

Well, it turns out that Youtube has shadowbanned the film.  This almost certainly made the post look wonky.  If they disappear it I will update the embed to Rumble or something.

You know that you're over the target when you're taking flak.

Tuesday, February 27, 2024

On Google's untrustworthiness

Lots of folks are posting about the Google AI fiasco, and how it shows that you can't trust Google's search results. 

Um, we've known this for over a decade.  Their political ideology has been on display, right out in the open for a very long time.