Jump to content

PiqueABoo

Members
  • Posts

    2,184
  • Joined

  • Last visited

Everything posted by PiqueABoo

  1. It was still available back whenever so in a moment of weakness I got Sprogette .me which is currently hooked up to Windows Live so no forwarding issues etc. Sprogette who never finds her (really-not-that-unusual) firstname on gift-shop [souvenir mugs|key-rings|tat] was rather pleased... every 8yo should have one... well except they can't so the seriously competitive parents of ~ 1/2 of Sprogette's peers probably weren't so chuffed - if anyone has the right .me I suspect you could make a few quid I didn't want surnames on e-safety/privacy grounds. My only regret about it so far is that Sprogette isn't called Sue.
  2. Here is a FAQ written by folk who are in the (non-profit) business of knowing what they're talking about. Coz some folk don't click links, some choice excerpts: What do we know? Very little. The Communication Capabilities Development Programme (CCDP) is going to be included in the Queen's Speech next month and we still haven't had public confirmation of the details. What we do know is that there have been secret briefings to MPs designed to scare them into compliance, and secret briefings to industry that were originally designed to calm their fears (but in fact have only served to increase their outrage). Why is this happening now? In the days of the old internet, when we used email addresses provided by ISPs like BT, who tended to have servers in the UK, government authorities were able to grab information on who we were emailing and when with ease. Growth in interactivity and international services has meant that new 'third party providers' are enabling our email. Simply put, we now use Gmail and Hotmail to communicate with other people, not a BT address. Gmail and Hotmail are run by companies outside of the UK (Google and Microsoft respectively) and so don't have to automatically comply with UK government requests.... What about security? There are two security nightmares involved here. Firstly, the security of the black boxes at ISPs is suspect. Analagous capabilities have been abused before the use of SSL generates significant problems for these black boxes - they know which service provider you are connecting to, but are unable to access your transactional information. This can be circumvented, but such a step on the government's part would be difficult, controversial and potentially illegal.[1] Will this help prevent terrorism? No. In a terrorism investigation, the police will already have access to all the data they could want. This is about other investigations - it is about the millions of requests made every year by local law enforcement and other authorities in the investigation of serious - and less serious - crime. What’s the big deal? Once the government is allowed to install these black boxes at ISPs, there’s basically no limit on future actions. Could this data be used to track file-sharing and monitor who is visiting specific websites? Absolutely. Could this system be used to restrict access to services? Absolutely. Once this line is crossed, the government will have enormous scope to monitor and control the internet. [1] If they don't address the "significant problem" then these boxes clearly won't be able to fulfil their raison d'etre. Addressing the obvious means SSL MITM type stuff as implemented by Smoothwall and others. In order to get away with the latter they need a sub-CA from a widely recognised CA to spoof normal site certs so they can then grope around in the content to figure out who you put in a To field in a new mail web page etc. "Controversial" is an understatement: PKI has always had woes, but given whats gone on recently it's reputation is in tatters and given some of the subsequent militancy I suspect key browser makers might not find this acceptable i.e. could kick any CA that makes a sub-CA for the gov to do this out of the default set they ship with the browser. Another factor is that there are two parties in an SSL "conversation" - on the server-side some sites may resent UK state interception and refuse to talk to UK clients. See also: Projects like Sovereign Keys which is intended to help fix some of PKI's woes and would drop all MITM'd connections, then there's the rise of several browser add-ons for detecting certificate fiddling etc.
  3. I've always though keeping Windows laptops consistent is hard enough with the Windows manglement e.g. rolling out a new SmartBoard gallery or similar, doesn't exactly suit wireless, or laptops that are sat in a trolley right now etc. [Yes you can get the magic ones in networked trolleys that WOL and do things without frying themselves etc., but it costs] That is the *key* question... just wish more folk who unlike me are supposedly qualified to know, actually asked it.
  4. What makes you think serious Bad Guys will be stupid enough to get caught by net monitoring we all know is happening? I said 'inept', because it seems extremely unlikely that anyone planning a major terrorist act, that's been given serious money to undertake it, would start sending e-mail about it, spend every evening browsing the net for the latest anarchist cookbook, routinely visit anti-US facebook pages or whatever. You reckon? Read this (actually I'll quote the relevant bit): In fact, the whole point of the CCDP is to facilitate the interception of communications streams in order to obtain traffic data, without the requirement of ministerial or judicial warrants. https://www.privacyinternational.org/press-releases/leaked-liberal-democrat-internal-briefing-on-new-government-surveillance-plans-0
  5. That not been true for RIPA has it? And remember last summer, the tabloid press knowing where news-worthy folk are right now (coz of where their mobiles were)? Oh yes, that clearly was, and this will definitely be used 'proportionately' for serious stuff like organised crime, proper terrorism, active paedophiles and the like ... you bet... absolutely because we're different from our predecessors and successors... there's no shadow of a doubt. Spending half of what's likely billions on lots of things would likely keep us "safer" (I vote for seriously criminalising failure to use your car indicators when you should). You have to **ask questions**, for instance: How much safer is that then and does it justify the expense? Let's say we do spend a few billion on this and maybe catch an really inept Bad Guy or two - would seem like a bit of a waste of money for such a small return you could have gotten for a fraction of the price with other humdrum methods, so they'll inevitably lower the proportionate bar a bit to help justify the massive outlay and by-and-by you're living in a fluffy on the outside totalitarian state whose inhabitants deserved what they got for being so bleeping gullible.
  6. Your second link is about updating Data Protection law from 1995 and is nothing to do with Data Retention, except of course they clash... the proposed regulation likely says retention is permitted where it's required by law e.g. Data Retention. Would you mind going and reading The Register's take on this and then explain how that fits with your EU-wot-dunnit case. Note how that and lots of other folk, including the briefing paper that's supposed to be calm the lib dem masses, keep invoking the magic acronym RIPA in relation to *this* story and RIPA is not Data Rentention.
  7. You'll be on The List[tm] then.
  8. :: OH NO IT ISN'T! :: If it were that then we've got it already and they wouldn't need any new law would they? This is different and troublesome, hence all the fabulous 'grassroots' lib dem agony. Talking of Lib Dems I wouldn't vote for one, but Julian Huppert's take is quite rational.
  9. Google Nigeria found on the above list is funny.. once you get to it... Firefox throws up a forgery page.
  10. You definitely know you're a geek when you're amused by the April 1st RFCs: RFC 6592: The Null Packet RFC 6593: Service Undiscovery Using Hide-and-Go-Seek for the Domain Pseudonym System (DPS
  11. Live@Edu:FOPE gets you to some big numbers for the "Network" as opposed to your tenancy. There are more graphs and spam count recently spikes at around 900,000,000. When I first looked at this (a few times over a month end of last summer) the percentage was 80%+ so the current 70% is a significant reduction. Spam counts with graph set for 1 year apparently showing progress (B for billion):
  12. Talking of things that might actually hit the shelves one day... Toshiba Shapes
  13. Not sure if it only comes in chinese, but they also have this: Google ???? Search for something and watch what happens.
  14. That's what I linked ;b "New Puzzle Palaces" points to that and was a ref to the article author's book The Puzzle Palace (about NSA & Fort Meade)
  15. ::sigh:: "Anonymous" don't matter, that concept/meme/whatever was bankrupt long before yet another round of 100% predictable dishonour amongst 1337 haxorz (would have thought some of them might have least watched A Scanner Darkly if not read it). The over-stated 'cyber-war', the Four Horsemen are the driving force, all Anonymous do or rather the media's love-affair with them does, is increase public acceptability of more New Puzzle Palaces <= makes whatever bits the Brits do all by themselves, even less the reaction of a bunch of age-independent juveniles seem a bit irrelevant don't you think?
  16. Fair enough, I've dealt with a few schools who've long had external mail and other external bits & bobs without that sync-magic so not-syncing with Live@Edu is business as usual and doesn't appear to bother them. I've got a split-personality over this.. on the one hand you can manage them (ensure not too crackable), but SSO does have the eggs in one basket problem.
  17. If you're not bothered about syncing passwords, you can do that bit with not very much powershell run as a scheduled task. Are mscrl.microsoft.com, crl.microsoft.com reachable by the relevant account (possibly some service account?) through any local web/content fliltering? [i *think* those are the right CRL points]
  18. Sounds like reasonable behaviour.. we're in the world of hybrid mail where organisations are supposed to move mailboxes between local and cloud at their leisure. I don't know the answer because I haven't done OLSync, but I *suspect* when you migrate a mailbox via the Live@Edu ECP (ensure it is just one test mailbox!) from your local Exchange to Live@edu, the first thing it will do is turn that Live@Edu Mailuser into a Mailbox and then copy the Exchange mailbox content across. Having done that the Exchange mailbox and content still exists, but it is effectively turned into a Mailuser (forwards mail from Exchange to Live@Edu). Again don't know for sure though.. I take it you are planning to move existing mailbox content accross?
  19. Last case I saw did precisely that: Exchange 2003 was set to allow authenticated users to relay from anywhere in the world and one of their users apparently had a rubbish password. Security log was full of zillions of events for that specific user logging on (in two minds about how they got the credentials, but if there were clues in the event logs wrap round had long since vanished them).
  20. My inner-cynic doubts the first bit. In principle it's Office365 for Education is broadly available in the (northern hemisphere) summer, but it was going to be available last year until it wasn't. If you can get it prior to the last day of the UK summer or earlier via some VIP advance access method, then yes there's no point kicking off a Live@Edu especially if the transition to Office365 will have you doing work recreating a few bits, having to reset everyone's passwords etc. Live@Edu migrations apparently happen *after* that broad availability, and unless this is miraculously different from everything else that happens to Live@Edu I'm expecting some kind of 'heavy engineering' that necessarily takes long periods of time e.g. there's something initially called the December 2011 service update for Live@Edu that still hasn't reached at least one UK school tenancy yet... and it's April 2012 in a few days. [ I'm still waiting for an Office365 for Education catch, possibly something related to the sharepoint like there won't be out-of-box friendly templates for education after all or something. And how does that rumoured Office for Education 15 sharepoint app thingy fit in to all this? ] -- Back to OPs question. The most compelling reason I can think of for local Exchange not cloud Exchange is if you have a significant number of Outlook 'power users' e.g. PA opening their own, the Head's, a couple of Deputies mailboxes and casually flitting between them - still works with cloud, but not as quickly, and some PAs can get scary when things like that happen.
  21. Agree with all the above. CC4 shipped exclusively on 2K3 for around 2.5 years. CC4.3 on 2KR2 has been available for around 1.5 years. There's almost certainly more systems on the former than the latter. Personally I wouldn't want to touch unmaintained since 2008 with a barge pole. If you want to keep it then support is definitely required, as is a serious amount of time & effort to get it caught up (if time=money, then recommission to CC4.3 might be more cost efficieint)
  22. May or may not apply in any given case, but check your drivers for NTFS alternate data streams and if they exist try removing them prior to importing. Sysinternals have a util that can seek and destroy those streams, called uhh.. streams. GPP can be used to kill autoruns i.e. you can add entries to remove what you like from the registry Run keys, including the Intel hotkey stuff. Warning: Once upon a time some sound driver didn't play nicely unless it's autorun had run.
  23. Quite. Are you a parent then? The theory goes that the current decoupling and creeping privatisation of schools will inevitably undermine that magic 'community cohesion' stuff you often get with state schools. The theory works for me and thus I'm becoming increasingly defensive about that aspect. As a parent, knowing I could send teacher an e-mail if I have some relevant issue is one part of that glue - haven't used it but I'm more content with the in loco parentis deal having that facility there, than not.
  24. Hmm.. that's apparently a hotmail server saying it can't accept a mail from a @yahoo.in address because your server is sending too many e-mails. Why is your server involved in mail between yahoo and hotmail addresses? First thing to check (soon) is whether you have some kind open-relay (or spam-bot) problem. Google will get you lots of articles about checking/fixing that - offhand I don't know which might be a really good article for Exchange 2003, but someone else might.
  25. Their alleged professionalism, the Malicious Communications Act and the Communications Act ought to cover it. A huge number of people in many professions endure folk, their "customers", letting off steam e.g. Customer Services, Support, Police, Health, Social Services etc. Teachers generally tend to be hardened to steam-letting in person, at least TOH is, so I'm a bit puzzled by the alleged sensitivity to indirect abuse.
×
×
  • Create New...