seanismorris

About

Username
seanismorris
Joined
Visits
102
Last Active
Roles
member
Points
4,012
Badges
2
Posts
1,624
  • Elon Musk uses iPhone email bug to illustrate the importance of software innovation

    Referencing Apple as an example of poor quality is dumb.
    It’s the phone he uses and has personal experience with.  Referencing Android and not being a user would be a bit odd.

    Apple did go through a period where they prioritized new features over stability.  Version 13 was actually much better, but obviously not bug free (which is impossible).

    I mostly disagree with Musk.  Hiring new talent will boost innovation, but it has nothing to do with QC and squashing bugs before software gets released.  I think what he’s getting at, is eventually patching software no longer works and a rewrite is needed.  The problem is that doesn’t fit his example very well.
    muthuk_vanalingamgatorguyDogpersonFileMakerFellercgWerks
  • Japanese 'Behind the Mac' ad shows MacBook appearances in anime

    I just watched something... I’m not sure what...
    FLMusicBeats
  • MI5 head wants 'exceptional access' to encrypted communications

    Why can't companies like Facebook and Apple provide secure End to End communication for US (and/or UK/Canada/etc.) citizens but key-escrowed communication for foreigners (eg, China, Iran, etc.)? All it would take is for Facebook and Apple to write software that determines the nationality of the user. That's a modest technical problem. The problem is primarily that Facebook and Apple actually want to provide secure communications for people who have no such right, and perhaps secondarily also that the government wants key-escrow for nationals who may have a "right" to privacy.

    This solution would be unsatisfactory to Apple and Facebook because SOME of their customers (eg, citizens of Iran, China, Somalia) would be unhappy that their keys were being escrowed. And it would also be unsatisfactory to the governments because SOME of their suspects (eg, citizens of US, Canada, UK) would have keys that are NOT being escrowed. Both sides, government and corporations, aren't willing to settle for a 50% satisfactory solution, which is sad. They both want 100%.

    Some of you may respond to this idea by saying that it's technically impossible for corporations to determine the nationality of its users. That's a false argument which I will ignore. And most of you are unimaginative enough to figure out how to solve this problem. I could explain how it could be done, technically, but I don't want to argue about technical solutions, I want to argue about whether this approach is a useful and legal approach. Is it legal? Very probably. Is it useful? Probably for many situations. But both sides want it all and aren't willing to compromise.
    How are you going to determine if I’m a local good old boy?  If I turn on my VPN it looks like I’m German, when I’m actually in the USA.

    Besides, you haven’t been paying attention, they want your information just as much as they want foreigners.

    If you think these surveillance problems work, here you go.  Yesterday’s news: (you’ll note the US was spying on there own people)

    NSA spent $100M on phone surveillance program that prompted two unique FBI leads

    https://www.washingtonexaminer.com/news/nsa-spent-100m-on-phone-surveillance-program-that-prompted-two-unique-fbi-leads


    You asked me "how" it would be done. I explicitly wrote I don't want to talk about "how it's done" because that would change the topic to a technical topic rather than a policy topic. The link you sent me was not a key escrow issue, so it's irrelevant to my point. (I get the impression that you don't even understand what key escrow is since you are diverting attention from the topic I raised.) But you admit you don't understand "how" nationality could be determined. Let's ignore how it's done and talk about whether it's a good idea to do this. Ask yourself if this method I've described, if it were possible, would be "legal" and "useful". I said it would be very probably legal and probably useful in many situations. You had nothing to say. I was right when I expected that responses to my message would try to address "how" this could be done rather than whether it's a good idea. As I said, corporations ignore this question because they want all their customers to get the same high grade encryption, while governments ignore this question because they want to be able to view everyone's traffic. 
    I never asked you how.  But...

    If you give a key to a 3rd party to unlock a door, you have no idea who that 3rd party is, and if it ends up in some else’s hands.  I can say with absolutely certainty that if that 3rd party is a government, they’re going to lose that key and it will be in someone’s hands shouldn’t have access to it.  All you have to do is read the news to confirm I’m right.  Top Secret information, including government spy tools, have shown up on the dark web.

    Let’s say Apple is ordered to create a back door, and they do it.  How many people will take part in its creation?  There will be committee’s discussing committees both with the government and within Apple.  How many programmers will touch the project?  How many security consultants? After it’s created, who’s going to manage, maintain, and update it.  Where’s the budget?  When the administration comes in will it get the same attention?  What happens when the expert that created it retires, and the next guy got the job on low bid?  The point is every security system, protocol, etc. (SSL, TSL... whatever) becomes obsolete because it’s no longer secure.

    There’s so many issues with backdoors (including your suggestion) it’s laughable.  Backdoors by definition aren’t secure.

    Your key escrow will fail either because a.  The key isn’t secured b. The key isn’t secure c. The implementation isn’t secure (Etc)

    So far, nation states have been hands off in attacking financial systems because of their interconnectedness.  Your key escrow will be open season.  It will fail.  It’s only a matter of when.
    longpathMissNomermailmeofferstoysandme
  • Santander, intel contractor L3Harris Technologies drawn into Apple vs Corellium battle [u]...

    I was initially anti Corellium.  I still think Apple will win, but they’re not going to walk away clean.

    I’d like to see the documents related to their buyout offer.  Apple is coming across as 2 faced.
    williamlondonWarrenBuffduckhprismatics
  • Coronavirus to hit Android's hopes for 5G, folding screens the hardest

    I’m not sure Samsung should be listed with the other manufacturers.
    ”Samsung Mobile Phone Manufacturing Locations
    As of 2019, Samsung has its mobile phone manufacturing factories at 6 locations – Vietnam, China, India, Brazil, Indonesia, and South Korea. 50% of Samsung mobile phones are made in Vietnam and 8% in Korea. Rest is manufactured in India, Brazil, Indonesia and China.Nov 20, 2019”
    gatorguymuthuk_vanalingamviclauyycFileMakerFellerktappe