Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.os.development > #9324 > unrolled thread
| Started by | James Harris <james.harris.1@gmail.com> |
|---|---|
| First post | 2016-03-29 15:09 +0100 |
| Last post | 2016-04-27 07:44 +0100 |
| Articles | 17 on this page of 37 — 7 participants |
Back to article view | Back to alt.os.development
The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-29 15:09 +0100
Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-30 00:03 +0700
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 19:39 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:54 +0100
Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-31 06:16 +0700
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 20:01 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:59 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-03-31 17:47 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 08:11 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-01 18:25 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 23:10 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-02 14:18 +0200
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-04-01 09:58 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 10:06 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-29 17:39 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-31 00:13 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-30 23:18 -0400
Re: The morality of operating system security "Alexei A. Frounze" <alexfrunews@gmail.com> - 2016-03-31 00:31 -0700
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-31 16:57 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 09:22 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-01 20:24 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-09 18:25 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-09 18:57 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-26 09:07 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-26 23:58 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:01 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-27 05:42 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-03 00:05 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-03 16:55 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-04 09:00 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-04 17:22 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-05 17:02 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-05 17:55 -0400
Re: The morality of operating system security "Kerr Mudd-John" <admin@127.0.0.1> - 2016-05-09 14:58 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-12 17:46 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-15 00:11 +0100
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:44 +0100
Page 2 of 2 — ← Prev page 1 [2]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-04-01 20:24 -0400 |
| Message-ID | <20160401202426.293af50b@_> |
| In reply to | #9347 |
On Fri, 1 Apr 2016 09:22:58 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 31/03/2016 04:18, Rod Pemberton wrote: > > On Thu, 31 Mar 2016 00:13:49 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > >> On 29/03/2016 22:39, Rod Pemberton wrote: > >>> On Tue, 29 Mar 2016 15:09:35 +0100 > >>> James Harris <james.harris.1@gmail.com> wrote: ... > Wouldn't it be feasible to say that a certain administrator, using a > certain terminal and a particular program, could access a specific > piece of data in a limited way? That way, access to the data could be > limited by login id, terminal authorisation and accessing program. Yes, but usually the administrator has full access and so is the one setting up the policy that would restrict the terminal access. They could remove the policy or transfer the policy as they desired. Also, since the admin has full access, they can log in as that user via another terminal, or as that user on the restricted terminal if the log in policy prohibits log ins from other terminals. Of course, this is Unix model of 'root' using 'su' and 'sudo' and being able to set user and terminal log in policy. Basically, AISI, you're wanting an admin without full admin privileges, i.e., you'd need two admin's. One higher-level admin for setting up the restricted terminal(s), user log in policies, and user accounts. This higher-level admin would need more privilege than the lower-level admin to prohibit the lower-level admin from modifying the the terminal restrictions, account log in policies, or creating accounts with higher-level privilege. The lower-level admin would also need to be restricted from using other terminals, logging in as other users, or using 'su' and 'sudo' for privilege escalation. If the lower-level admin can escalate privilege or log in as the higher-level admin, you've lost control. However, the lower-level admin would still need to be able to have full access to everything else to do the majority of the system administration. The higher-level admin would need to be blocked from any system administration unrelated to accounts as the admin is likely not qualified for that. I had some Unix SysV administration experience decades ago and a tidbit from Linux nowadays, but I'm not sure how to set this up to work. I never had the "pleasure" of system admin on high security DEC VAXs. Maybe someone else knows how or which systems allow what you want. > > 2) how do you prevent CDs or backups from being made? > > > > Most computers have CDs in them. Those same computers use the CDs, > > or laser-discs, or tape, etc, to make backups. It's usually the > > admin's job to make those backups. I'm not familiar with the > > particulars of the example you cite, but it was probably his job > > to do that, and then mail them to secure storage. He could > > have diverted the CDs, or they could have been lost, misplaced, > > or stolen. It's up to authorities to find out. > > That illustrates that people who "need" access generally get access > to entire files of information - and that there is no restriction on > what they can do with those files. OSes have file permissions and > that is simply not adequate. I think it's more a matter of setting up privileges to restrict access to files is a total PIA. Every time the admin comes back from lunch, someone else needs access to the file or data for some valid reason, e.g., backup, run a report, redo a report, legal department lawsuit, management review, audit, They have to set basic privileges and then lock and unlock the file over and over again, or have to keep adding users to their ACLs. Even on MS-DOS, with minimal 'H' for hidden and 'S' for system flags, trying to backup up a system is problematic if any such privilege flags are set. Linux has even more flag combinations and bunches of specialty settings. DEC VAX had many such flags and per-user ACLs too. You have to remember that the vast, vast majority of people are _lazy_, and not willing to work that hard. Path of least resistance. The same issue affects password choice. > IMO it would be better to give people permission to specific fields > of data. And, as above, if the program accessing the data has to be > authorised to do so, that program can limit itself to, say, > displaying data on a screen, and not provide an option to do anything > else with the data. That would prevent administrators making copies. It's too much work and too many problems. Someone has to decide for each and every field whether each and every person has access. What if you have 10,000 employees? more? 5 million fields? What if you've had 30,000 employees move on to other companies over the past decade? Who removes them or their account from the privileges? A hacker doesn't need to get access, they only need to hack an account which has access, like restoring one of the 30,000 "dead" employee accounts that no one removed from the field privileges because it was too much work putting them on in the first place. > When info that has been certified to be publicly readable is stored > on disc it can be stored unencrypted. All other info should be stored > in an encrypted form. Someone, more specifically, some account, always has access to the unencrypted data. > > AISI, the real problem is either: > > 1) company's aren't willing to pay for good security > > How would they spend more money to improve security? > Security consultants, security firm, administrator experienced with security too, hardware encryption, software encryption, yearly audit with specialists, etc. > Sorry, I don't mean me specifically. I was using "my" as a proxy for > us as a population. To rephrase, I don't mind security services > accessing our computers if it saves our lives from terrorism. > > I cannot actually think of a negative effect of allowing security > services access to our computers. They would not be interested in > most of us, only of people who might be a threat. So, technically, they're not likely to ever be accessing your computer. Therefore, it's acceptable to you that they have access to everyone's computers. > I don't mind a limited group of people seeing my web browsing history > or my emails or my texts etc. What I don't want is that info to > escape and become visible to the wider public. I'm not sure that is possible. Once someone has the data, it will usually propagate, typically, to someone in a foreign country, where you have no legal recourse. Where you do have legal recourse, the data will be taken offline, but kept and archived by those that have it. So, you've stopped some of the regional propagation, but you can't ever eliminate the data from being accessible, or it being in someones possession, e.g. in the "darknet", via P2P filesharing, in NSA or GCHQ data archived by their spy activities. > Actually, I am surprised that Apple is not subject to US laws which > make it compulsory for them to allow the US security services to > access their products. ... > AIUI no one can export strong encryption from the US. Didn't that change? ... Not sure. > Maybe that also gives the lie to Edward Snowden's claims about the > Smurfs he alleges to be contained within people's phones...? Are you joking or serious? ... There was an attempt to install bugging devices in all U.S. phones years ago, e.g., Clipper chip. Officially, it failed, because the U.S. public found out about it. Unofficially, they might have done something. E.g., we know that the NSA Echelon program "wiretapped" world satellites. We know the GCHQ spied on U.S. citizens, which is illegal for the NSA to do, and handed the data over to the NSA, which was ruled legal to do ... CALEA law allows wiretapping of cellphones, broadband, and possibly VoIP. In addition to the NSA, the FBI is known to have all sorts of data harvesting programs and technologies, e.g., email, telephone records, real-time Internet traffic, passwords. The NSA archives all emails in the U.S. post 9/11, including content, not just header information. For phone calls, non-NSA federal agencies can only record the phone metadata without a warrant from a court. They need a warrant to record the conversation. The NSA has been known to perform warrant-less wiretaps, including real-time Internet logging, but they're a classified agency, so no legal recourse ... Even the Library of Congress is in on the act. They've archived all Twitter posts. That's just the "tip of the iceberg" of Big Brother activities in the U.S. Given all such activity, the U.S. is technically a border-line police state, and I think the U.K. and Australia are far worse. There are security cameras everywhere in the U.S., but they are not tied in directly to police stations, where police are monitoring every movement of a citizen in real-time for miles on end, like in the U.K. Police need warrants to access the video here. Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-04-09 18:25 +0100 |
| Message-ID | <nebdns$k1m$1@dont-email.me> |
| In reply to | #9366 |
On 02/04/2016 01:24, Rod Pemberton wrote: > On Fri, 1 Apr 2016 09:22:58 +0100 > James Harris <james.harris.1@gmail.com> wrote: > >> On 31/03/2016 04:18, Rod Pemberton wrote: >>> On Thu, 31 Mar 2016 00:13:49 +0100 >>> James Harris <james.harris.1@gmail.com> wrote: >>>> On 29/03/2016 22:39, Rod Pemberton wrote: >>>>> On Tue, 29 Mar 2016 15:09:35 +0100 >>>>> James Harris <james.harris.1@gmail.com> wrote: > > .... > >> Wouldn't it be feasible to say that a certain administrator, using a >> certain terminal and a particular program, could access a specific >> piece of data in a limited way? That way, access to the data could be >> limited by login id, terminal authorisation and accessing program. > > Yes, but usually the administrator has full access and so is the one > setting up the policy that would restrict the terminal access. They > could remove the policy or transfer the policy as they desired. Also, > since the admin has full access, they can log in as that user via > another terminal, or as that user on the restricted terminal if the > log in policy prohibits log ins from other terminals. Of course, this > is Unix model of 'root' using 'su' and 'sudo' and being able to set > user and terminal log in policy. Sorry, I was previously thinking of 'administrator' in a different sense. For a system admin (your sense of the term) yes, as you say below, I think there would need to be multiple administrators with different privileges. Imagine a sizeable organisation. It would have policies as to who can see what, and would be regularly audited. I would imagine that they would want to see audit-log entries for various things. It would need to be possible to set up the OS to keep an audit trail of any 'interesting' actions. There would probably be a master set of controls and one small team able to change them, and every change they made would be logged. The log would need to show what controls they opened (to specific groups) and closed. Presumably, other people would use the opened controls to grant and revoke privileges between users and data. Those changes may or may not be logged, depending on the company's audit policy. > Basically, AISI, you're wanting an admin without full admin privileges, > i.e., you'd need two admin's. One higher-level admin for setting up the > restricted terminal(s), user log in policies, and user accounts. This > higher-level admin would need more privilege than the lower-level admin > to prohibit the lower-level admin from modifying the the terminal > restrictions, account log in policies, or creating accounts with > higher-level privilege. The lower-level admin would also need to be > restricted from using other terminals, logging in as other users, or > using 'su' and 'sudo' for privilege escalation. If the lower-level > admin can escalate privilege or log in as the higher-level admin, > you've lost control. However, the lower-level admin would still need > to be able to have full access to everything else to do the majority of > the system administration. The higher-level admin would need to > be blocked from any system administration unrelated to accounts as the > admin is likely not qualified for that. I had some Unix SysV > administration experience decades ago and a tidbit from Linux nowadays, > but I'm not sure how to set this up to work. I never had the > "pleasure" of system admin on high security DEC VAXs. Maybe someone > else knows how or which systems allow what you want. As you say, there are different models. For home use I like Unix's simple root/non-root model. I found it a pain when my Linux distribution started to apply security in a more granular way. When I wanted to move a directory I left a pointer to the new place but that broke the app's security model because the file privileges were set up by file location. It was only a web browser but broke because the file locations did not match the security configuration. Grr. Besides, as you mention backups, most conventional OS file permissions are completely swept aside by a system backup program. It has to have read access to everything and thus bypasses read-security on every file on the computer. IMO it would be better to encrypt anything which is about to be stored on disc, except data recognised as public-readable. I know that's a very different model to what's normally done. Also, imagine storing in a file records which consist of fields. You really want to protect different fields differently because some people may be allowed to see some fields but not others. Again, this is very different from what's normal. Finally, if data are encrypted on storage something needs to know how to decrypt them. If a disc is moved from one instance of the OS to another there is a question over whether the new OS should be able to decrypt the same data or not. Gets complicated...! >>> 2) how do you prevent CDs or backups from being made? >>> >>> Most computers have CDs in them. Those same computers use the CDs, >>> or laser-discs, or tape, etc, to make backups. It's usually the >>> admin's job to make those backups. I'm not familiar with the >>> particulars of the example you cite, but it was probably his job >>> to do that, and then mail them to secure storage. He could >>> have diverted the CDs, or they could have been lost, misplaced, >>> or stolen. It's up to authorities to find out. >> >> That illustrates that people who "need" access generally get access >> to entire files of information - and that there is no restriction on >> what they can do with those files. OSes have file permissions and >> that is simply not adequate. > > I think it's more a matter of setting up privileges to restrict > access to files is a total PIA. Every time the admin comes back > from lunch, someone else needs access to the file or data for > some valid reason, e.g., backup, run a report, redo a report, > legal department lawsuit, management review, audit, They have > to set basic privileges and then lock and unlock the file over > and over again, or have to keep adding users to their ACLs. Even > on MS-DOS, with minimal 'H' for hidden and 'S' for system flags, > trying to backup up a system is problematic if any such privilege > flags are set. Linux has even more flag combinations and bunches > of specialty settings. DEC VAX had many such flags and per-user > ACLs too. You have to remember that the vast, vast majority of > people are _lazy_, and not willing to work that hard. Path of > least resistance. The same issue affects password choice. Cannot that stuff all be dealt with by granting privileges to certain groups, and then choosing which users to put in which groups, as is done at the moment? The only thing I would add is a concept of an Organisational Role (O.R.). That is to allow a certain person's userid to work normally and only get extra privileges when required. What the person would do is switch into a different O.R. (for which he/she had already been given permission) to carry out a privileged action. Then he/she could return to normal mode after carrying out the action that needed extra security. As well, am individual user often works in different O.R.s during a working day. >> IMO it would be better to give people permission to specific fields >> of data. And, as above, if the program accessing the data has to be >> authorised to do so, that program can limit itself to, say, >> displaying data on a screen, and not provide an option to do anything >> else with the data. That would prevent administrators making copies. > > It's too much work and too many problems. Someone has to decide for > each and every field whether each and every person has access. What > if you have 10,000 employees? more? 5 million fields? What if you've > had 30,000 employees move on to other companies over the past decade? > Who removes them or their account from the privileges? A hacker > doesn't need to get access, they only need to hack an account which has > access, like restoring one of the 30,000 "dead" employee accounts that > no one removed from the field privileges because it was too much work > putting them on in the first place. If you mean five million different field definitions that is ... a lot! The number of employees would not matter much. They could be assigned to groups and operational roles when their accounts were created. Dealing with that many field definitions, though, would be a lot of work. Of course, given that we are talking about fields and records, we are talking about a very different model from the Unix stream-of-bytes model that is used for files. This is more like a database. Perhaps when file structures are designed the fields could be assigned to groups, and then usergroups and organisational roles given access to those groups of fields..? >> When info that has been certified to be publicly readable is stored >> on disc it can be stored unencrypted. All other info should be stored >> in an encrypted form. > > Someone, more specifically, some account, always has access to the > unencrypted data. AISI the system admins could set up the structures but not be allowed to see all the data. That would be the realm of the data admins, e.g. the people who dealt with customers and updated the data. >>> AISI, the real problem is either: >>> 1) company's aren't willing to pay for good security >> >> How would they spend more money to improve security? >> > > Security consultants, security firm, administrator experienced with > security too, hardware encryption, software encryption, yearly audit > with specialists, etc. OK. >> Sorry, I don't mean me specifically. I was using "my" as a proxy for >> us as a population. To rephrase, I don't mind security services >> accessing our computers if it saves our lives from terrorism. >> >> I cannot actually think of a negative effect of allowing security >> services access to our computers. They would not be interested in >> most of us, only of people who might be a threat. > > So, technically, they're not likely to ever be accessing your computer. > Therefore, it's acceptable to you that they have access to everyone's > computers. I mean they might find something sensitive or personally embarrassing on a person's computer, or some private communication etc, but if they are looking for terrorism-related information they would not be interested in embarrassing stuff and not have any reason to look at it or do anything with it. >> I don't mind a limited group of people seeing my web browsing history >> or my emails or my texts etc. What I don't want is that info to >> escape and become visible to the wider public. > > I'm not sure that is possible. Once someone has the data, it > will usually propagate, typically, to someone in a foreign > country, where you have no legal recourse. Where you do have > legal recourse, the data will be taken offline, but kept and > archived by those that have it. So, you've stopped some of the > regional propagation, but you can't ever eliminate the data > from being accessible, or it being in someones possession, > e.g. in the "darknet", via P2P filesharing, in NSA or GCHQ > data archived by their spy activities. As long as there is only a small team who can see the stuff I don't mind. In the UK that could be a team at GCHQ - the spying agency. They are the kind of people would work with police intelligence officers to place bugging and monitoring in the homes of terror suspects. So the amount of data they would get would be much more than just what was on a computer or phone. >> Actually, I am surprised that Apple is not subject to US laws which >> make it compulsory for them to allow the US security services to >> access their products. > > .... > >> AIUI no one can export strong encryption from the US. > > Didn't that change? ... Not sure. It seems so: "The export of cryptographic technology and devices from the United States was severely restricted by U.S. law until 1992, but was gradually eased until 2000; some restrictions still remain." https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States >> Maybe that also gives the lie to Edward Snowden's claims about the >> Smurfs he alleges to be contained within people's phones...? > > Are you joking or serious? ... I was serious, though I don't know whether Snowden was being truthful or not. For example, see http://www.bbc.co.uk/news/uk-34444233 -- James Harris
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-04-09 18:57 -0400 |
| Message-ID | <20160409185740.51c7ed6d@_> |
| In reply to | #9415 |
On Sat, 9 Apr 2016 18:25:19 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 02/04/2016 01:24, Rod Pemberton wrote: > > On Fri, 1 Apr 2016 09:22:58 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > >> On 31/03/2016 04:18, Rod Pemberton wrote: > >>> On Thu, 31 Mar 2016 00:13:49 +0100 > >>> James Harris <james.harris.1@gmail.com> wrote: > >>>> On 29/03/2016 22:39, Rod Pemberton wrote: > >>>>> On Tue, 29 Mar 2016 15:09:35 +0100 > >>>>> James Harris <james.harris.1@gmail.com> wrote: ... > For a system admin (your sense of the term) yes, as you say below, I > think there would need to be multiple administrators with different > privileges. > > Imagine a sizeable organisation. It would have policies as to who can > see what, and would be regularly audited. > > I would imagine that they would want to see audit-log entries for > various things. It would need to be possible to set up the OS to keep > an audit trail of any 'interesting' actions. > > There would probably be a master set of controls and one small team > able to change them, and every change they made would be logged. > > The log would need to show what controls they opened (to specific > groups) and closed. > > Presumably, other people would use the opened controls to grant and > revoke privileges between users and data. Those changes may or may > not be logged, depending on the company's audit policy. I still see having a "master set of controls" as being an issue. They would likely still have enough privilege to edit, delete, or replace audit logs. Alternately, they may be able to adjust file privileges to temporarily restrict write access to the logs, or block write access to the directory or higher-level directory. They might also be able to redirect output to a file which is deletable or null depending on how the program is invoked. Of course, they may be able to log in to more privileged accounts or use privilege boosting apps like 'su' or 'sudo' or run a privileged app, e.g., privileged editor or shell or privileged OS app which allows terminal, shell, or CLI commands to execute, which has sufficient privileges to do such things. At best, the system would need multiple admin accounts, with each account restricted to different capabilities. This would likely need to be by design, designed into the system directly. I'm unsure if you could convert a root/non-root model to this. It might be possible to delete the root account after the multiple restricted admins were activated, or perhaps use root to delete the root password to block access to the account. Good luck if you messed up! > Besides, as you mention backups, most conventional OS file > permissions are completely swept aside by a system backup program. It > has to have read access to everything and thus bypasses read-security > on every file on the computer. I think that's because it's run as admin or root. If you were to run a backup program as a user on a root/non-root system, it either wouldn't run due to insufficient privilege to execute the app, or the backup app would only backup the files your account has privileges to access. > IMO it would be better to encrypt anything which is about to be > stored on disc, except data recognised as public-readable. I know > that's a very different model to what's normally done. That would be good for transferring securely or storing private data. However, what happens if the password to the encrypted data is lost? What happens if the decryption fails? e.g., due to bad track or sector. What do you do if all copies were mailed at the same time and somehow destroyed? Things like this occur in real life. What do you do if one of two RAID linked drives fails? You always need a backdoor, an additional copy, or an non-encrypted copy somewhere for life's failures. People forget passwords. People forget the answers to security questions. They have to be written down or recorded or you risk being locked out. Murphy's law strikes when least expected. > Finally, if data are encrypted on storage something needs to know how > to decrypt them. If a disc is moved from one instance of the OS to > another there is a question over whether the new OS should be able to > decrypt the same data or not. That's an issue. In some instances, you may want access on the new system, e.g., recovery. In other instances, you may not want access on the new system, e.g., hacked. An additional issue is whether or not the new system has the hardware or software to decrypt the data. It may not. That's a problem if you need to recover data especially in the future once a system becomes obsolete. > >> That illustrates that people who "need" access generally get access > >> to entire files of information - and that there is no restriction > >> on what they can do with those files. OSes have file permissions > >> and that is simply not adequate. > > > > I think it's more a matter of setting up privileges to restrict > > access to files is a total PIA. > > Cannot that stuff all be dealt with by granting privileges to certain > groups, and then choosing which users to put in which groups, as is > done at the moment? Group privileges probably would work for some or most of it. But, you'd still likely have dead or inactive accounts in the group which hackers could attempt to access or reinstate. Imagine a university or medium-sized company. They could have turnover of 1,000 people per year or more. If there isn't an administration tool that helps add and remove accounts in bulk using some criteria, that's a lot of work for somebody. > That is to allow a certain person's userid to work normally and only > get extra privileges when required. What the person would do is > switch into a different O.R. (for which he/she had already been given > permission) to carry out a privileged action. Then he/she could > return to normal mode after carrying out the action that needed extra > security. Personally, I don't like the root/non-root model, but I'm usually in a near admin capacity or I'm the computer's owner. From my perspective, it's generally an impediment to attempt to do any work as non-root, since you'll need root privilege repeatedly to do anything important. Of course, in a multi-user environment, you need some way to control people, and not just basic users, but the admin's too. People make mistakes. People attempt to bypass security to do their job or even out of curiosity. People become greedy or corrupt, when mistreated. Human nature is the flaw here. Perhaps, robotics and AI will be useful in this regards ... > >> IMO it would be better to give people permission to specific fields > >> of data. And, as above, if the program accessing the data has to be > >> authorised to do so, that program can limit itself to, say, > >> displaying data on a screen, and not provide an option to do > >> anything else with the data. That would prevent administrators > >> making copies. > > > > It's too much work and too many problems. > > The number of employees would not matter much. They could be assigned > to groups and operational roles when their accounts were created. What do you to do prevent the need to delete inactive accounts? > Of course, given that we are talking about fields and records, we are > talking about a very different model from the Unix stream-of-bytes > model that is used for files. This is more like a database. Yes. > Perhaps when file structures are designed the fields could be > assigned to groups, and then usergroups and organisational roles > given access to those groups of fields..? Setting, correcting, removing all these privileges seems like a lot of work to me. > AISI the system admins could set up the structures but not be > allowed to see all the data. If they control whom has which privileges, how does that work? ... Privilege escalation is a serious problem if someone has privilege. How do you prevent self-dealing of privileges to the privileged? Raw trust? Bad choice. I think that's true whether discussing computer admins, or law enforcement, or government agencies. Even the most trustworthy people are not perfectly trustworthy. Trust-but-verify? Ok, I just verified that they stole everything ... > That would be the realm of the data admins, e.g. > the people who dealt with customers and updated the data. Ok. > I mean they might find something sensitive or personally embarrassing > on a person's computer, or some private communication etc, but if > they are looking for terrorism-related information they would not be > interested in embarrassing stuff and not have any reason to look at > it or do anything with it. Well, that's not the way it usually works in the U.S. Most things of an embarrassing nature are usually also illegal. Once law enforcement gets their hands on such things, you'll be charged with a crime even if their warrant didn't authorized them to search for such stuff. E.g., they have a warrant to search your house for terrorism and they find something else, say any one of the following: illegal drugs, prohibited weapons, illegal pornography, kidnapping, slavery, or fraud. You'll be charged with crimes. Now, technically, the U.S. has a doctrine, "fruit of the poisonous tree," which prohibits evidence which wasn't legally obtained via warrant or probable cause from being used, but realistically that only causes a small percentage of such cases to be discarded. Judges usually favor law enforcement claims. If the crime is something considered to be heinous, the courts will prohibit or restrict evidence which "stacks-the-deck" in favor of the prosecution. I.e., the judge or prosecutor is "sure" that you're guilty and they "tilt" the system in favor of you being convicted. Another situation which happens is when they have probable cause for something. E.g., a criminal is fleeing law enforcement. The criminal breaks into your house while your on vacation (or holiday). They have probable cause to enter your home to obtain the criminal. You for whatever reason have something illegal to possess. Certain things are illegal to possess while others are illegal to obtain but not possess. They generally don't need a warrant to charge you with a crime for things which are illegal to possess. I.e., illegal possession laws end-run around our fourth amendment rights to unlawful search and seizure. So, you'll be charged with a crime even though law enforcement had no legal reason to search you or your home for criminal activity prior to chasing down a criminal. Another situation which has happened a number of times in the past decade is where people had to be evacuated for forest fires or floods. Authorities were evacuating homes. Authorities usually condemn homes in flood or fire areas in order to have the legal right to enter the homes to ensure they've been evacuated. I.e., they legally entered homes to make sure they were empty for the public good, but they were also charging homeowners and occupants with crimes for stuff they found in their homes during the evacuation process. > >> I don't mind a limited group of people seeing my web browsing > >> history or my emails or my texts etc. What I don't want is that > >> info to escape and become visible to the wider public. > > > > I'm not sure that is possible. Once someone has the data, it > > will usually propagate, typically, to someone in a foreign > > country, where you have no legal recourse. > > As long as there is only a small team who can see the stuff I don't > mind. In the UK that could be a team at GCHQ - the spying agency. This is an issue of trust. Some may not trust them. People trusted the the NSA prior to Snowden, mostly because they didn't know the truth or it couldn't be proven. > >> Maybe that also gives the lie to Edward Snowden's claims about the > >> Smurfs he alleges to be contained within people's phones...? > > > > Are you joking or serious? ... > > I was serious, though I don't know whether Snowden was > being truthful or not. For example, see > > [link] > "named after Smurfs" That I wouldn't doubt. I wouldn't doubt programs named after characters from Disney, Tolkien, or Harry Potter. So, it wasn't a claim of actual Smurfs ... ;-) Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-04-26 09:07 +0100 |
| Message-ID | <nfn7e8$tqn$1@dont-email.me> |
| In reply to | #9418 |
On 09/04/2016 23:57, Rod Pemberton wrote: > On Sat, 9 Apr 2016 18:25:19 +0100 > James Harris <james.harris.1@gmail.com> wrote: ... >> IMO it would be better to encrypt anything which is about to be >> stored on disc, except data recognised as public-readable. I know >> that's a very different model to what's normally done. > > That would be good for transferring securely or storing private data. > However, what happens if the password to the encrypted data is lost? > What happens if the decryption fails? e.g., due to bad track or sector. > What do you do if all copies were mailed at the same time and somehow > destroyed? Things like this occur in real life. What do you do if > one of two RAID linked drives fails? You always need a backdoor, an > additional copy, or an non-encrypted copy somewhere for life's failures. > People forget passwords. People forget the answers to security > questions. They have to be written down or recorded or you risk being > locked out. Murphy's law strikes when least expected. All good questions, though I think some of them relate to data storage generally, not to encryption per se. Re. the encryption issues, rather than the user forgetting the key wouldn't the OS have to know how to decrypt the stored data, and to have the decryption key? If so, then the OS would have to ensure that it only decrypted the data for the correct userids. You could still have multiple copies of the encrypted data for backup. ... >> The number of employees would not matter much. They could be assigned >> to groups and operational roles when their accounts were created. > > What do you to do prevent the need to delete inactive accounts? An organisation would have its own procedures to follow when people leave. Account deletion should be part of that, I would think. In reality it might be best to mothball accounts rather than deleting them. The owner might come back to the company. Or there may be some other reason to reactivate an inactive account. >> Perhaps when file structures are designed the fields could be >> assigned to groups, and then usergroups and organisational roles >> given access to those groups of fields..? > > Setting, correcting, removing all these privileges seems > like a lot of work to me. It would only be once per record type. Or, strictly, as a new field was defined. That raises issues in itself. Let's not go there....! >> AISI the system admins could set up the structures but not be >> allowed to see all the data. > > If they control whom has which privileges, how does that work? ... > Privilege escalation is a serious problem if someone has privilege. > How do you prevent self-dealing of privileges to the privileged? > Raw trust? Bad choice. I think that's true whether discussing > computer admins, or law enforcement, or government agencies. > Even the most trustworthy people are not perfectly trustworthy. > Trust-but-verify? Ok, I just verified that they stole everything ... Again, good questions. Could the organisation have someone senior - even a board member or every member of the board - designated to see a report every day, such that the report could be a single line confirming that there were no suspicious privilege escalations or attempts to interfere with auditing etc? The guard against misuse would be the inability to hide misuse from the audit log, and the report that a senior person or persons would see. As you say, it would not prevent misuse, only highlight it. But that in itself would be a good deterrent. ... > vacation (or holiday) Thank you for the courtesy of translating! But no need. I am used to reading AmE! -- James Harris
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-04-26 23:58 -0400 |
| Message-ID | <20160426235820.1cd18000@_> |
| In reply to | #9456 |
On Tue, 26 Apr 2016 09:07:43 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 09/04/2016 23:57, Rod Pemberton wrote: > > On Sat, 9 Apr 2016 18:25:19 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > Re. the encryption issues, rather than the user forgetting the key > wouldn't the OS have to know how to decrypt the stored data, and to > have the decryption key? If so, then the OS would have to ensure that > it only decrypted the data for the correct userids. I don't see encryption and decryption as something inherent to the OS, if that is what you meant. The specific OS in question would need to have the ability to encrypt or decrypt the specific protocol that was used, e.g., if someone deleted the encrypt/decrypt application, you'd have a problem until the apps were restored. Encryption and decryption can be supported on any platform that can compile said application. This implies that other systems can decrypt your OS' data, if they possess your data and also an appropriate encrypt/decrypt program. The exception is if the OS uses a unique encryption protocol, specific to that OS. I'd doubt any business would use a proprietary encryption protocol due to either time or expense. Various government entities or a military might do so, though. > > What do you to do prevent the need to delete inactive accounts? > > An organisation would have its own procedures to follow when people > leave. Account deletion should be part of that, I would think. > > In reality it might be best to mothball accounts rather than deleting > them. The owner might come back to the company. Or there may be some > other reason to reactivate an inactive account. As mentioned previously, a skilled hacker could re-activate the "mothballed" accounts. Think of a mothballed account as a backdoor to your house which uses a different key than the front door, but where you've also lost the key. The lock can still be picked, as long as it's still present and accessible. More accounts equals more doors to try. To a hacker, it doesn't matter that they're locked. If they know they're there, they'll attempt to pick them. > >> AISI the system admins could set up the structures but not be > >> allowed to see all the data. > > > > If they control whom has which privileges, how does that work? ... > > Privilege escalation is a serious problem if someone has privilege. > > How do you prevent self-dealing of privileges to the privileged? > > Raw trust? Bad choice. I think that's true whether discussing > > computer admins, or law enforcement, or government agencies. > > Even the most trustworthy people are not perfectly trustworthy. > > Trust-but-verify? Ok, I just verified that they stole > > everything ... > > Again, good questions. Could the organisation have someone senior - > even a board member or every member of the board - designated to see > a report every day, such that the report could be a single line > confirming that there were no suspicious privilege escalations or > attempts to interfere with auditing etc? > > The guard against misuse would be the inability to hide misuse from > the audit log, and the report that a senior person or persons would > see. As you say, it would not prevent misuse, only highlight it. But > that in itself would be a good deterrent. Reports can be tampered with. How do you know in advance what to monitor for suspicious activity? Do you assume the hacker will set off some randomly chosen alarm, or should you assume the hacker is skilled enough to avoid 98% of your traps? If the hacker is in the 2%, "extra-devious," then he is in your system without detection. Most good people, like those you'd trust to do your security, simply aren't devious enough to entrap someone who is devious and is experienced too. So, you need to be prepared to clean up the mess such people make. > Thank you for the courtesy of translating! But no need. I am used to > reading AmE! Ok, what are the BrE words that AmE speakers should know but don't? BrE seems to have many more words not in use in AmE. Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-04-27 07:01 +0100 |
| Message-ID | <nfpke2$jgv$1@dont-email.me> |
| In reply to | #9457 |
On 27/04/2016 04:58, Rod Pemberton wrote: > On Tue, 26 Apr 2016 09:07:43 +0100 > James Harris <james.harris.1@gmail.com> wrote: ... >> Thank you for the courtesy of translating! But no need. I am used to >> reading AmE! > > Ok, what are the BrE words that AmE speakers should know but don't? > BrE seems to have many more words not in use in AmE. I'll get back to the more important points in your recent posts but I can answer this one quickly. I don't think there are many important differences but a few spring to mind. BrE - AmE: Braces - Suspenders Suspenders or suspender belt which hold up stockings (I don't know the AmE equivalent) Trousers - Pants Pants or underpants - Underpants Queue - Line Holiday - Vacation Public holiday or bank holiday - Holiday Herbs - Erbs ;-) Lift - Elevator Chemist's - Drugstore Pavement - Sidewalk Dual carriageway or motorway - Freeway Dressing gown - Robe Nappy - Diaper Dummy - Pacifier Rubber or eraser - Eraser Maths - Math Zed - Zee Full stop - Period Car park - Parking lot Chips - French fries Sweets - Candy Biscuit - Cookie Jam - Jelly Jelly - Jello Courgette - Zucchini Car bonnet - Car hood Car boot - Car trunk Toilet or loo or lavatory - Toilet Tap - Faucet Rubbish - Garbage Football - Soccer American football - Football Torch (the electric type with a bulb) - Flashlight Autumn - Fall (the season) Fish (plural) - Fishes etc. Now I think of it there are quite a lot. Many fuller lists pepper the internet. Over time American words are becoming more used in the UK. Many here would know what American terms mean. There could be some confusion over words which have different meanings such as suspenders or jelly. -- James Harris
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-04-27 05:42 -0400 |
| Message-ID | <20160427054214.182c3530@_> |
| In reply to | #9462 |
On Wed, 27 Apr 2016 07:01:44 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 27/04/2016 04:58, Rod Pemberton wrote: > > On Tue, 26 Apr 2016 09:07:43 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > Braces - Suspenders > Suspenders or suspender belt which hold up stockings (I don't know > the AmE equivalent) Mens pants: suspenders Womens nylons: garter belt > Trousers - Pants > Pants or underpants - Underpants Underpants - Underwear > Pavement - Sidewalk Pavement here can mean a road or freeway too, any large body of level concrete for transportation. > Nappy - Diaper Yeah, that one could cause some trouble here ... "Nappy" refers to unkempt curly hair of black people. It's used by black people indicating that they need some work on their grooming, and is usually considered derogatory or offensive if whites use it. > Dummy - Pacifier "Dummy" refers to an idiot and is politically incorrect here. > Rubber or eraser - Eraser "Rubber" refers to a condom here. > Maths - Math Mathmatics, usually. > Biscuit - Cookie Yeah, we have both cookies and biscuits ... So, I'm adding this to your list: Scone - Biscuit > Jam - Jelly > Jelly - Jello We have marmalade, jam, jelly, and Jell-O ... Marmalade usually has rough cuttings of peel. Jam has fruit flesh, usually noticed as bits of seeds or skins, with thicker, rougher texture than Jelly. Jelly is just pectin from the juice, clear. Jell-O is commercial gelatin usually made from cartilage or bones of cows. If your jam is our jelly, and your jelly is our Jell-O, what is our jam? ... Primarily, apple and grape are jelly here, marmalade is orange, and most everything else is jam or preserves, sometimes called spreads, but we do also have fruit sauces and fruit butters. As you can see, you can get some berries as either jelly or jam, but they generally aren't as widely available as jelly. (types from a grocery store website) Jelly: grape apple concord grape strawberry blackberry Jam or Preserves: concord grape strawberry apricots blackberry raspberry peach cherry black cherry red plum Marmalade: orange (fruit) Sauce: applesauce (fruit) Butters: apple pumpkin > Courgette - Zucchini ??? > Fish (plural) - Fishes I think that one is "fish" here too ... Generally, most uses are plural. I.e., "a fish" would be singular, I think. "My fish" would be taken as singular also. It's likely that "group of" or "school of" would be added to "My fish" if it was meant to be plural, e.g., "My school of fish". Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-05-03 00:05 +0100 |
| Message-ID | <ng8m9m$ms2$1@dont-email.me> |
| In reply to | #9469 |
On 27/04/2016 10:42, Rod Pemberton wrote: > On Wed, 27 Apr 2016 07:01:44 +0100 > James Harris <james.harris.1@gmail.com> wrote: ... >> Jam - Jelly >> Jelly - Jello > > We have marmalade, jam, jelly, and Jell-O ... > > Marmalade usually has rough cuttings of peel. > Jam has fruit flesh, usually noticed as bits > of seeds or skins, with thicker, rougher texture > than Jelly. Jelly is just pectin from the juice, > clear. Jell-O is commercial gelatin usually made > from cartilage or bones of cows. > > If your jam is our jelly, and your jelly is our > Jell-O, what is our jam? ... Well, you've given me some info I didn't know about your distinctions between those terms. I think we would call your jam and jelly both jam. So, BrE - AmE: Marmalade - Marmalade Jam - Jam or Jelly Jelly - Jell-O We would use Jelly as part of a compound term such as redcurrant jelly But the word "jelly" on its own would be for your Jell-O. I guess our redcurrant jelly could be used on a savoury food. Whereas anything called jam would go on bread or toast. ... >> Courgette - Zucchini > > ??? Why the question marks? >> Fish (plural) - Fishes > > I think that one is "fish" here too ... > Generally, most uses are plural. I.e., > "a fish" would be singular, I think. > "My fish" would be taken as singular also. > It's likely that "group of" or "school of" > would be added to "My fish" if it was meant > to be plural, e.g., "My school of fish". What about "a dozen fish"? Would you say "a dozen fishes"? -- James Harris
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-05-03 16:55 -0400 |
| Message-ID | <20160503165548.0baa42a3@_> |
| In reply to | #9477 |
On Tue, 3 May 2016 00:05:26 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 27/04/2016 10:42, Rod Pemberton wrote: > > On Wed, 27 Apr 2016 07:01:44 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > >> Courgette - Zucchini > > > > ??? > > Why the question marks? It seemed strange. The others at least made some sense to me. I've never heard or seen the word "courgette" before. It sounds like a French word or a derivative. > >> Fish (plural) - Fishes > > > > I think that one is "fish" here too ... > > Generally, most uses are plural. I.e., > > "a fish" would be singular, I think. > > "My fish" would be taken as singular also. > > It's likely that "group of" or "school of" > > would be added to "My fish" if it was meant > > to be plural, e.g., "My school of fish". > > What about "a dozen fish"? > Would you say "a dozen fishes"? > I'd say "a dozen fish." I'd take "fish" in "a dozen fish" to be singular due to use of "dozen." I seriously wouldn't doubt it that Americans somewhere are using "fishes," but I don't know if you're just messing with me a bit ... I've noticed that "whomever" is being consistently replaced with "whoever" now in AmE, even for news articles. I'm not sure if people just gave up or if this is an accepted change. Most here still can't get the usage of "than" versus "then" correct either. Recently, I read that younger Americans only place one space between sentences. That's just for starters. I keep thinking of "A Fish Called Wanda" for some reason. Searching for that movie, an old American idiom came up: "to sleep with the fishes," meaning that you were murdered. That uses "fishes" as a plural. So, that's at least two exceptions. I'm not sure how frequent the exceptions are in AmE. The real question is why "fishes" would be the plural instead of "fishs" ... What's the point of adding a silent 'e'? Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-05-04 09:00 +0100 |
| Message-ID | <ngca01$24q$1@dont-email.me> |
| In reply to | #9485 |
On 03/05/2016 21:55, Rod Pemberton wrote: > On Tue, 3 May 2016 00:05:26 +0100 > James Harris <james.harris.1@gmail.com> wrote: > >> On 27/04/2016 10:42, Rod Pemberton wrote: >>> On Wed, 27 Apr 2016 07:01:44 +0100 >>> James Harris <james.harris.1@gmail.com> wrote: > >>>> Courgette - Zucchini >>> >>> ??? >> >> Why the question marks? > > It seemed strange. The others at least made some sense to me. I've > never heard or seen the word "courgette" before. It sounds like a > French word or a derivative. Maybe it's a female courg. >>>> Fish (plural) - Fishes >>> >>> I think that one is "fish" here too ... >>> Generally, most uses are plural. I.e., >>> "a fish" would be singular, I think. >>> "My fish" would be taken as singular also. >>> It's likely that "group of" or "school of" >>> would be added to "My fish" if it was meant >>> to be plural, e.g., "My school of fish". >> >> What about "a dozen fish"? >> Would you say "a dozen fishes"? >> > > I'd say "a dozen fish." I'd take "fish" in "a dozen fish" to be > singular due to use of "dozen." I seriously wouldn't doubt it that > Americans somewhere are using "fishes," but I don't know if you're just > messing with me a bit ... I was serious. I thought AmE used fishes rather than fish (plural). I guess there is room for variation in both countries. > I've noticed that "whomever" is being > consistently replaced with "whoever" now in AmE, even for news articles. Here, many - probably most - people don't know grammatically when to say "who" and when to say "whom" and the former is now often used in either place. Similarly, many people don't know when to say "less" and when to say "fewer". English is a complex language. I am continually coming across things about it that I didn't know. > I'm not sure if people just gave up or if this is an accepted change. > Most here still can't get the usage of "than" versus "then" correct > either. That reminds me of another difference. From what I have seen, in America people talk about one thing being different than another. In the UK people say that one thing is different from another. > Recently, I read that younger Americans only place one space > between sentences. So do I. I have noticed that you consistently use two spaces. > That's just for starters. I keep thinking of "A > Fish Called Wanda" for some reason. Searching for that movie, an old > American idiom came up: "to sleep with the fishes," meaning that you > were murdered. That uses "fishes" as a plural. So, that's at least two > exceptions. I'm not sure how frequent the exceptions are in AmE. The > real question is why "fishes" would be the plural instead of "fishs" ... > What's the point of adding a silent 'e'? English, perhaps because of its organic origins, is full of oddities. IMV AmE is more logical than BrE. Perhaps that's because Webster decided to start some things afresh..? OT but I wonder how feasible it would be to design a new language that was usable enough for humans but also logical enough to be understood by machines. -- James Harris
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-05-04 17:22 -0400 |
| Message-ID | <20160504172232.73d32902@_> |
| In reply to | #9489 |
On Wed, 4 May 2016 09:00:00 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 03/05/2016 21:55, Rod Pemberton wrote: > > On Tue, 3 May 2016 00:05:26 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > >> On 27/04/2016 10:42, Rod Pemberton wrote: > >>> On Wed, 27 Apr 2016 07:01:44 +0100 > >>> James Harris <james.harris.1@gmail.com> wrote: > >>>> Courgette - Zucchini > >>> > >>> ??? > >> > >> Why the question marks? > > > > It seemed strange. The others at least made some sense to me. I've > > never heard or seen the word "courgette" before. It sounds like a > > French word or a derivative. > > Maybe it's a female courg. > Ha. Hey, is Lingham's Hot Sauce widely available over there? I picked up some at the local dollar store. Nice stuff. This morning, I made a scrambled egg and spinach breakfast burrito with it. It's not easily found here. I may have to pick up some more since I suspect they won't restock. > I was serious. I thought AmE used fishes rather than fish > (plural). I guess there is room for variation in both countries. > Maybe, it's regional or generational. I don't generally discuss fish with other people. So, maybe I'm out of touch ... > > I've noticed that "whomever" is being > > consistently replaced with "whoever" now in AmE, even for news > > articles. > > Here, many - probably most - people don't know grammatically when to > say "who" and when to say "whom" and the former is now often used in > either place. I have difficulty with both, but had never noticed media outlets not using them properly until recently. > Similarly, many people don't know when to say "less" and when to say > "fewer". As you once noticed, I occasionally use "fewer" to be precise, but "less" is the "standard" usage here too. > English is a complex language. I am continually coming across things > about it that I didn't know. So, it's not easy to parse? ... The school systems here weren't teaching sentence diagramming when I was in school. They found too many students had problems with it. It helped me out immensely, but I'm above average on spatial relations. Unfortunately, I didn't learn it early on. > > I'm not sure if people just gave up or if this is an accepted > > change. Most here still can't get the usage of "than" versus "then" > > correct either. > > That reminds me of another difference. From what I have seen, in > America people talk about one thing being different than another. In > the UK people say that one thing is different from another. Both seem normal to me, but I'd say 75%:25%. > OT but I wonder how feasible it would be to design a new language > that was usable enough for humans but also logical enough to be > understood by machines. In C, I rarely use qualifiers such as "const" or "static" or "restrict" etc. "volatile" is the only one I find to be useful. In English, I am constantly having to use adverbs, adjectives, phrases, etc to modify the base meaning which is easily written. I'm forced to modify the base meaning into the precise meaning that I intend, which is usually similar but different. However, I notice some people automatically discard all such "flowery" usage and assume the base meaning is what I meant to say. English sentences which can be diagrammed, can probably be parsed by computers or generated by computers. I don't diagram anymore, but write what seems to be correct. I don't know if diagramming works for all of English, but it worked for much of it, if not all of it, when I was learning it. There are also chatterbots, parody generators, and Markov chains which might be used to confirm that a computer can parse the resulting language. Without proof, I'm assuming the that the reverse is true, that if it can generate it, then it can also parse it, i.e., reverse the process. Dijkstra's shortest path algorithm might also be of use. I.e., words are defined as sentences which are sequences of other words. So, a shortest path algorithm could programmatically find the definitions of words. These could perhaps be filtered via AI. Or, they could be used as the basis for the language. The first step might be to determine if diagrammed English sentences can be converted into Markov chains. Markov chains are supposed to be representable by FSMs. This would allow for both an engine to generate text and an engine to parse text, or so I'd think/guess ... https://en.wikipedia.org/wiki/Dijkstra's_algorithm https://en.wikipedia.org/wiki/Markov_chain https://en.wikipedia.org/wiki/Chatterbot https://en.wikipedia.org/wiki/Parody_generator Haven't we discussed some of this previously? Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-05-05 17:02 +0100 |
| Message-ID | <ngfqlk$i17$1@dont-email.me> |
| In reply to | #9493 |
On 04/05/2016 22:22, Rod Pemberton wrote: > On Wed, 4 May 2016 09:00:00 +0100 > James Harris <james.harris.1@gmail.com> wrote: > >> On 03/05/2016 21:55, Rod Pemberton wrote: >>> On Tue, 3 May 2016 00:05:26 +0100 >>> James Harris <james.harris.1@gmail.com> wrote: >>>> On 27/04/2016 10:42, Rod Pemberton wrote: >>>>> On Wed, 27 Apr 2016 07:01:44 +0100 >>>>> James Harris <james.harris.1@gmail.com> wrote: > >>>>>> Courgette - Zucchini >>>>> >>>>> ??? >>>> >>>> Why the question marks? >>> >>> It seemed strange. The others at least made some sense to me. I've >>> never heard or seen the word "courgette" before. It sounds like a >>> French word or a derivative. >> >> Maybe it's a female courg. >> > > Ha. > > Hey, is Lingham's Hot Sauce widely available over there? If it is I've never heard of it. We have Tabasco which I guess is an American product. One I buy here is Reggae Reggae X Hot sauce. > I picked up some at the local dollar store. Nice stuff. > This morning, I made a scrambled egg and spinach breakfast > burrito with it. It's not easily found here. I may have > to pick up some more since I suspect they won't restock. Sounds tasty! >>> I've noticed that "whomever" is being >>> consistently replaced with "whoever" now in AmE, even for news >>> articles. >> >> Here, many - probably most - people don't know grammatically when to >> say "who" and when to say "whom" and the former is now often used in >> either place. > > I have difficulty with both, but had never noticed media > outlets not using them properly until recently. I think of it as subject and object or, more easily, the difference between "he" and "him". We always known when to use "he" and "him". The corresponding words are "who" and "whom". E.g. who spoke with whom? Corresponding: he spoke with him. > >> Similarly, many people don't know when to say "less" and when to say >> "fewer". > > As you once noticed, I occasionally use "fewer" to be > precise, but "less" is the "standard" usage here too. I don't remember noticing that but of course I take your word for it. >> English is a complex language. I am continually coming across things >> about it that I didn't know. > > So, it's not easy to parse? ... Various odd things. >> OT but I wonder how feasible it would be to design a new language >> that was usable enough for humans but also logical enough to be >> understood by machines. ... > In English, I am constantly having to use adverbs, adjectives, > phrases, etc to modify the base meaning which is easily written. > I'm forced to modify the base meaning into the precise meaning > that I intend, which is usually similar but different. However, > I notice some people automatically discard all such "flowery" > usage and assume the base meaning is what I meant to say. > > English sentences which can be diagrammed, can probably be parsed > by computers or generated by computers. I don't diagram anymore, > but write what seems to be correct. I don't know if diagramming > works for all of English, but it worked for much of it, if not > all of it, when I was learning it. The main trouble with English, ISTM, is that so much of it is ambiguous. That is, of course, a well known problem with natural languages. Another problem is its idiosyncrasies. For example: I boil water I boil a kettle The latter doesn't mean that the kettle gets boiled....! Another one is prepositions. For example, "Mary spoke to Jane and she was upset." There is no indication who "she" referred to. > Haven't we discussed some of this previously? Quite possibly. -- James Harris
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-05-05 17:55 -0400 |
| Message-ID | <20160505175551.1b9251c6@_> |
| In reply to | #9495 |
On Thu, 5 May 2016 17:02:57 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 04/05/2016 22:22, Rod Pemberton wrote: > > On Wed, 4 May 2016 09:00:00 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > >> On 03/05/2016 21:55, Rod Pemberton wrote: > >>> On Tue, 3 May 2016 00:05:26 +0100 > >>> James Harris <james.harris.1@gmail.com> wrote: > >>>> On 27/04/2016 10:42, Rod Pemberton wrote: > >>>>> On Wed, 27 Apr 2016 07:01:44 +0100 > >>>>> James Harris <james.harris.1@gmail.com> wrote: > > I picked up some at the local dollar store. Nice stuff. > > This morning, I made a scrambled egg and spinach breakfast > > burrito with it. It's not easily found here. I may have > > to pick up some more since I suspect they won't restock. > > Sounds tasty! It was and I don't even like spinach ... Well, if you don't have Lingham's there, it's similar to an Asian style sweet and sour sauce, but it's sweet and spicy, with a mild amount of heat, very syrupy. I thought you might have it there since it seems to be from a British company in Malaysia, e.g., I assumed it would be distributed in the U.K. One of their website pictures shows it used with fried chicken. That would probably be really tasty too. http://www.lingham.com/ Hot sauces became real popular here some years ago with the Buffalo chicken wings craze which uses Frank's Redhot cayenne. So, now, there is a decent selection of hot sauce at most U.S. grocery and larger department stores. For many years, it was basically just Tabasco or a restaurant supplied sauce. My top two favorites are Burman's hot sauce available at U.S. Aldi's for $0.85 a bottle and Cholula which is imported from Mexico. Cholula has the best flavor of any hot sauce I've tried so far (about a dozen brands), but it's expensive and not nearly as hot as sriracha. Huy Fong's Sriracha would be third. Taco Bell's Fire sauce is fourth. Tabasco's Chipotle maybe fifth. Taco Bell's Fire sauce is phenomenal when paired with sliced jalapenos. Of course, I'm not sure if any of these are available over there. > Another problem is its idiosyncrasies. For example: > > I boil water > I boil a kettle > > The latter doesn't mean that the kettle gets boiled....! So, the kettle, which holds a liquid had an implicit phrase such as "full of water/tea/liquid," i.e., non-empty. English has implicit subjects too. E.g., "Go home." Subject is "you." Identifying something absent only works if you can reasonably eliminate all other valid options. That would seem to require either a fixed list of absolute options so you can cross off non-working options, or a knowledge base and reasoning to deduce what was meant. > Another one is prepositions. For example, "Mary spoke > to Jane and she was upset." There is no indication who > "she" referred to. I seem to recall that pronouns refer to the nearest, if it makes sense with the context. If it doesn't, I think I was taught that the sentence should be rearranged so that it does. I know I've run into situations where it could be either. Obviously, there is no way to enforce such a requirement on the writer (or coder). I'm assuming the language compiler would need to identify the ambiguity and report or reject it, either a parse or syntax error. Or, there could be a rule that specifies which one will be used in ambiguous situations. Then, it's up to the coder to enforce the rule. Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | "Kerr Mudd-John" <admin@127.0.0.1> |
|---|---|
| Date | 2016-05-09 14:58 +0100 |
| Message-ID | <op.yg67ruwemsr2db@dell3100.dlink.com> |
| In reply to | #9496 |
On Thu, 05 May 2016 22:55:51 +0100, Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> wrote: []> > It was and I don't even like spinach ... Well, if you don't have > Lingham's there, it's similar to an Asian style sweet and sour sauce, Lingam is erm an Indian word. Be careful if googling for it! use wikipedia, YKIMS https://en.wikipedia.org/wiki/Gudimallam -- Bah, and indeed, Humbug
[toc] | [prev] | [next] | [standalone]
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Date | 2016-05-12 17:46 -0400 |
| Message-ID | <20160512174629.0d6d9b74@_> |
| In reply to | #9495 |
On Thu, 5 May 2016 17:02:57 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 04/05/2016 22:22, Rod Pemberton wrote: > > On Wed, 4 May 2016 09:00:00 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > >> English is a complex language. I am continually coming across > >> things about it that I didn't know. > > > > So, it's not easy to parse? ... > > Various odd things. Well, James, it looks like you got your wish. Google released a parser for English. Some of the issues we've discussed are discussed in the article. Google's Parsey McParseface http://www.businessinsider.com/googles-newest-software-is-named-parsey-mcparseface-no-seriously-2016-5 As a side note on context, take the following line from a movie a few years ago. When read, it is entirely out of context. You don't know who is saying it and what is actually being discussed. "It's been a long time since I smelled beautiful." Now, if you knew or assumed a guy said it, you'd think he was saying that he stinks, and maybe needs a bath or deodorant. But, the guy wasn't talking about himself. His comment was in regards to a woman. This line was in "The Chronicls of Riddick." There is a couple parsing problems here. The first is that "beautiful" can't be smelled. The second is that even if you know a guy is saying this, there is no context that "beautiful" is in regards to a woman, and not the speaker, unless you're watching the movie. The visual context within the movie is unwritten context unknowable to a mere reader. Rod Pemberton
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-05-15 00:11 +0100 |
| Message-ID | <nh8b48$tcm$1@dont-email.me> |
| In reply to | #9518 |
On 12/05/2016 22:46, Rod Pemberton wrote: > On Thu, 5 May 2016 17:02:57 +0100 > James Harris <james.harris.1@gmail.com> wrote: > >> On 04/05/2016 22:22, Rod Pemberton wrote: >>> On Wed, 4 May 2016 09:00:00 +0100 >>> James Harris <james.harris.1@gmail.com> wrote: > >>>> English is a complex language. I am continually coming across >>>> things about it that I didn't know. >>> >>> So, it's not easy to parse? ... >> >> Various odd things. > > Well, James, it looks like you got your wish. Google released a parser > for English. Some of the issues we've discussed are discussed in the > article. Not quite what I was thinking of. IMO there would need to be a new language which removed ambiguities. English is stuck with some of those it has. > Google's Parsey McParseface > http://www.businessinsider.com/googles-newest-software-is-named-parsey-mcparseface-no-seriously-2016-5 There was recently an internet-based campaign to name a new British vessel Boaty McBoatface. Where does this X McXface name idea come from? -- James Harris
[toc] | [prev] | [next] | [standalone]
| From | James Harris <james.harris.1@gmail.com> |
|---|---|
| Date | 2016-04-27 07:44 +0100 |
| Message-ID | <nfpmuo$bcp$1@dont-email.me> |
| In reply to | #9457 |
On 27/04/2016 04:58, Rod Pemberton wrote: > On Tue, 26 Apr 2016 09:07:43 +0100 > James Harris <james.harris.1@gmail.com> wrote: ... All good points (snipped) > Reports can be tampered with. How do you know in advance what to > monitor for suspicious activity? Do you assume the hacker will set off > some randomly chosen alarm, or should you assume the hacker is skilled > enough to avoid 98% of your traps? If the hacker is in the 2%, > "extra-devious," then he is in your system without detection. Most > good people, like those you'd trust to do your security, simply aren't > devious enough to entrap someone who is devious and is experienced too. > So, you need to be prepared to clean up the mess such people make. I don't know for sure but I have an idea in mind. See what you think. The main defence is the audit log. Naturally, it is not possible to prevent someone or a team with privilege from doing something that is not secure. But it should be possible to ensure that any non-secure actions cannot go unnoticed. Of course, people don't have time to go through large audit logs so there needs to be a program to check the log for noteworthy events, and to bring those to the attention of the company's responsible person. Reportable events would be such as reactivating any account with certain privileges or creating an account with those privileges. I have described it as generating a single report. In practice, it would make more sense to examine the audit log with a filter. Then, multiple people could view the log with their own filters. Any good? -- James Harris
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | alt.os.development
csiph-web