Sad to hear of aircraft down at Popham

So sad to hear of the loss of life at Popham today when a small light aircraft came down south of the A303 in poor weather, almost certainly attempting a descent to land on runway 26. One of the three on board survived, and was driven to Southampton hospital in critical condition. Apparently the aircraft wasn’t based at Popham, but had left from Bembridge and was presumably diverting there due to the weather.

Another aircraft came down in about the same place in September 2012, but with no loss of life.

I was flying yesterday in a similar aircraft but thought better of today due to visit; and it’s both sad and sobering. My thoughts are with their relatives and everyone else at the Spitfire Club.


Update: 04-Jan-2015

The names of the occupants have been released as Lewis and Sally Tonkinson, with their six-year-old son as the sole survivor. Looking at the photographs of the crash site in the Isle of Weight County Press, the aircraft in question appears to be very “light”, consistent with a Pioneer 300 Hawk registration G-OWBA, of which Mr Tonkinson is a connected and on which 37 hours have been logged. Curiously, this is a two-seater with a 20Kg luggage capacity. LAA registration number is LAA 330-15155

Update 07-Jan-2015
I’ve seen reported elsewhere that the aircraft in question was a Pioneer 400 G-CGVO, but can’t tie this to Mr Tonkinson. The 400 is a “stretched” 300, with four seats, which would make more sense, but I’ve seen no official confirmation. There’s an AAIB report on G-CGVO (door opened on takeoff), but it was in Herefordshire, and the aircraft was based in Wales. It’s obviously possible that it subsequently changed hands.

Do I have SoapSoap in my WordPress?

Apparently, 100,000 WordPress sites have been compromised by this nasty. It injects redirect code in to WordPress themes.

According to an analysis posted by  Tony Perez on his blog, it’s going to be easy to spot if you’re a server administrator as in injects the code:

php function FuncQueueObject()
add_action("wp_enqueue_scripts", 'FuncQueueObject');

In to wp-includes/template-loader.php


find / -name template-loader.php -exec grep {} swfobject \;

should do the trick. I’m not a PHP nut, but I don’t think swfobject is common in that file.

Update: 06-Jan-2015

The web site linked to above has an on-line scanner that’s supposed to check for this problem, so I’ve just run it against this blog. It found something here. False positive, methinks! I’ve written to them pointing out that the search may be a little naive given the subject matter of that post! Fair play for providing such a tool free of charge though. It’s a little hard to see how such a scanner could work at all, but not pick up text lifted from a compromised site.


Sony and Microsoft games network hack

Both the Sony an Microsoft games network servers have been badly disrupted from Christmas day. The cyber vandals Lizard Squad have admitted responsibility.

This outage has nothing to do with millions of new games consoles being unwrapped and connected at the same time. Oh dear me no. Their network servers would have taken the huge spike in workload in their stride. This is definitely something to blame on those awful hactivists, and any suggestion that it was teetering on the brink and all it needed was a little push is a foul slur on the competence of Microsoft and Sony.

The extent to which Lizard Squad was involved may be in question, but major respect for the expert way they’ve played the media. Again.

BT Parental Controls Hack

In a move of spectacular incompetence, BT Broadband has hacked the HTTP data stream to customers in order to pop up a message concerning it’s “Parental Controls”. It’s done this without seeking any permission from the customer, and to add insult to injury, the code they’re injecting is buggy.

The injected popup  says “How to protect your family online with BT Parental Controls”, with an “Are you keeping your family safe?” online in order to worry the ignorant. It goes on “Safeguard all the computers, tablets and phones(sic) connected to your Home Hub”. The “Home Hub” is the weak and feeble excuse for a router they send you “free” when you sign up, and which anyone who knows anything about networking will have kept in the shrink wrap.

BT Parental Controls Popup
The popup you can’t kill. BT appears to be injecting this in to the HTTP stream of unsuspecting customers

As you can see from the pop-up above , there is a “No thanks” option, but it simply doesn’t work. Several commonly used websites such as Amazon have become unusable as a result – you just can’t get rid of the BT popup. Even clicking on “Yes please, Set it up” leads you nowhere except to a login to which the credentials are a mystery. Quite possibly because I’m not one of the lusers with a “Home Hub” (or business hub).

And this is on a standard Windoze 7 PC running the current version of the Chrome browser. And no software firewall to blame it on.

I called BT to complain and ask for it to be removed. They don’t even know what I’m talking about, which is odd because there was a spate of this stupidity earlier in the year. Fortunately they stopped before a full roll-out, but you can’t keep a good idiot now – the same idiot has resurrected the idea and rolled it out, possibly wholesale this time. Whoever it was should be publicly named and sacked.

Sony Hack – whodunnit?

Details are starting to emerge about how Sony was compromised. Sagie Dulce from Imperva reckons he’s seen the Destover back-door software used before, in 2012 in Saudi and then again in the 2013 Dark Seoul.

A few days ago Jaime Blascoof AlienVault Labs sent me a note about malware samples he’s got hold of, with the following comment:

“From the samples we obtained, we can say the attackers knew the internal network from Sony since the malware samples contain hardcoded names of servers inside Sony’s network and even credentials – usernames and passwords – that the malware uses to connect to systems inside the network. The malware was used to communicate with IP addresses in Europe and Asia, which is common for hackers trying to obscure their location. The hackers who compiled the malware used the Korean language on their systems.”

I’ve had other reports that the malware was compiled using a Korean language development environment. This means nothing to me – a lot of these generic malware kits are.

To me, this is looking more and more like the work of the usual suspects. An inside job – not a sudden and spontaneous lashing out by the North Koreans. This kind of attack requires time to put together.


North Korea Refuses to Deny Sony Cyber Attack

The popular media is in a frenzy – those dastardly North Koreans have launched a cyber-attack on Sony, pinched a lot of films and posted them on-line in revenge against the company for a disrespectful comedy making fun of their glorious leader. According to the BBC, they have refused to deny the attack, with a spokesman saying “Wait and see.”

The north Koreans must be loving this – they were, apparently, pretty hacked off about the depiction of Kim Jong-un. They have no sense of humour as far as he’s concerned. However, this bears all the hallmarks of a bunch of script kiddies ripping off a load of films to add to the pirate haul. The North Korean’s response, when doorstepped about the incident, suggests to me that they think their “enemy’s” predicament is hilarious, but stops well short of taking credit for it. Why would they be so coy? Because when the real culprits break cover they’d look stupid.

Yes, it could have been the North Koreans, but they’re not exactly high-tech. As far as I can tell there are only about a thousand IP addresses for the whole country. If it were China in the frame, I could believe it. Would the Chinese pull a stunt in support of their southern “friends” – I somehow doubt that; not over a film.

Given the extensive nature of the compromise, I wouldn’t be surprised if it was an inside job. Did the people involved set out to purpetrate the hack of the decade? There’ll be trouble now.

Daily Telegraph and The Independent web sites compromised by “Syrian Electronic Army”

I’m getting reports from people reading the Daily Telegraph web site saying that a dialog box saying “You have been hacked by the Syrian Electronic Army (SEA)”. The implication is that their PCs have been compromised, but I have no evidence that this is actually true. The web sites of the newspapers do appear to have been breached, however, in order to cause the pop-ups to appear.

Reports already exist of the problems with the Independent and the Evening Standard, with a time of 12:20 GMT, but the Telegraph problem appears to be new.

The problems don’t appear on all pages of the Telegraph – in fact the problem seems to be on the Alex cartoon only. The Independent has been off-line, but at time of writing is back – but slow.

Given the preponderance of adverts on this page, one possible method of attack could be via the advert feed. It certainly doesn’t happen of every access. However, reports suggest of a redirect to a page showing the Syrian logo. This could be JavaScript, a server change or a DNS hijack. People at the papers probably know which, but they’re a bit busy right now…


Tristram Hunt, Education and New Labour Posh Boys

New Labour posh boy Ed Milliband (Corpus Christi and Oxford) must be so busy worrying about his position that he’s left New Labour posh boy Tristrum Hunt (University College School and Cambridge) to talk about a subject neither can conceivably know about from experience – state education. The latter’s only qualification in this respect is that the former made him Shadow Education Secretary.

I’ve got nothing against so-called Posh Boys, but they shouldn’t speak about matters they don’t understand, and I’ve just been listening to Tristrum Hunt on Today talking about how private schools (which he should know all about) will be forced to provide services to the local state sector – in particular lend their superior teaching staff to local state schools. I wonder how state school teachers feel about this assessment of their relative merit?

I’d also be interested to know whether he and millionaire Milliband had properly checked this with their Trade Union Paymasters. You see the teaching trade unions are currently mounting a campaign against the use of unqualified teachers. “You can’t let unqualified teachers teach our kids!” seems to be the general emotive argument for this closed-shop arrangement. And it sounds reasonable until you consider where teachers might come from. Either they train and obtain the necessary paperwork immediately following their own education, or they have a career, gain life experience and then convert to teaching later in life based on enthusiasm and aptitude.

In spite of government initiatives to attract more experienced people into the “profession”, it’s an up-hill struggle to obtain the paperwork mid-life. We’re talking about scientists and engineers here. Who can afford to take a huge drop income while training once you’re married with responsibilities?

There is an answer, however – the private sector. There it’s up to the head teacher to select teachers on merit, not paperwork. Good teachers need communication skills, a good knowledge of their subject and a transferable enthusiasm to pass it on. They don’t need paperwork.

So what are Ed Milliband and Tristrum Hunt thinking? Have they realised that the NUT is wrong, and this is an attempt to smuggle good “unqualified” teachers in to state classrooms by the back door? Or did they just not think it through?

Incidentally, I don’t share Milliband and Hunt’s assessment that state school teachers need help from the private sector, nor that career teachers are poorer than those bought in from industry, although life experience and hands-on knowledge is definitely an advantage when it comes to engineering and other real-world skills. State school teachers know a lot about education, which isn’t to be underestimated. And private schools have good and bad teachers, just like everywhere else.

People like me already volunteer to help out in state schools out of a desire to spread knowledge and experience to the next generation. In the state sector, however, the NUT has seen to it that we can only be “teaching assistents”; but we do it for the next generation – not the state.

“Right to be forgotten” and police body cam footage posted forever on YouTube

In Europe, the court has decided that people who don’t like search engines like Google turning up embarrassing details about them now have the right to get the offending pages removed from the index. A Spanish lawyer by the name of Mario Costeja Gonzálezping hated people typing his in his name and finding an article in his local rag alluding to his past financial difficulties, and when they refused to pull the historical record he took all and sundry to court until Google (in particular) was forced to stop indexing the page. If you want to read the page from La Vanguardi, click here. Whilst I have some sympathy for the guy, taking Google to the European Court over the matter is not the best way to keep out of the public eye.

This isn’t without controversy – it’s censorship by the back door, handed down by a bunch of un-elected judges and everyone in Europe now has to comply. However, our colonial cousins, with their First Amendment, have e completely different problem – too much free speech.

Someone is exploiting the system, and the fact that publicly generated records in the USA are public, by requesting all police body camera images in order to provide content for a new YouTube channel, as reported by Komo News. Basically they’re slurping all the footage shot by Poulsbo Police in Washington and posting the “best bits”. The privacy issues are mind-boggling! Forget getting drunk and posting an unfortunately selfie on your Facebook page – if you get a visit from the cops in Poulsbo, it could end up on YouTube forever.

What is Google (owner of Facebook) doing about THIS? Absolutely nothing (thus far);  it’s free speech, isn’t it?

Google Apps for Schools – how safe are they?

So-called Group Work is probably the bane of every tutor in higher education, myself included. As to the poor students having to collaborate; it’s always the motivated one dragging the hangers-on and possibly university’s resident idiot along with them. It’s a nightmare. The most common complaint is that they never turn up to meetings to work on the project because it’s too difficult to organise. Yeah, right!

So this week, one of my colleges persuaded me to get them all working with Google Apps. The theory is that they don’t need to be co-located in time or space to work on a common document. I suspect the lack of physical presence will actually make it easier for some of the group to loaf off, but perhaps I’ve been at this too long to be optimistic.

Google Apps, on the other hand, is gaining ground in education. Cloud-based applications that allow easy sharing of documents has to be a good thing, and I have to say I’m very impressed at the ability of several people to edit the same document at once. And it comes with the ultimate feature that will guarantee sales – it’s free.

When I say “free”, that means that Google gets to harvest your personal data instead of hard cash, and feed you targeted advertising. And this is a worry. You may be okay with this, but if it’s to be adopted in colleges or schools, supposing some students aren’t as relaxed about it? Those in the know keep away from Facebook for just this reasons, but it’s optional. If you make Google Apps part of coursework you’re forcing students to accept terms they’d otherwise reject.

So, in 2006, Google announced Google Apps for Education, with the advertising stripped out. It’s actually a pretty good deal. Features may change over time, but it’s basically business version of Google Apps with one difference – it’s also free.

Unsurprisingly, Microsoft is really hacked off about this. They’ve been giving their Windows and Office software to educational establishments at a huge discount (or free) in order to get kids hooked on it, and as a result we have a generation that believes Microsoft Office is necessary to do anything. Kids come out of education knowing nothing else, which forces companies to purchase Microsoft Office at the full price in order to make them feel at home.

So, free or otherwise, Google Apps is probably more suited to college use, and Microsoft isn’t going to like it, so is fighting back with lawyers (no surprise there).

For example, last year Microsoft backed a bill in the US state of Massachusetts to block the use of Google Apps in schools.

To quote: “An Act prohibiting service providers who offer cloud computing services to K-12 educational institutions from processing student data for commercial purposes.”

Pernicious as Microsoft’s education offering is, this bill does have a point and I find myself siding with Microsoft for once. In fact I’d go further – no one should be forced to use applications collecting personal data, even in further or higher education.

This is becoming more relevant as I understand many schools are now considering the use of Google for Education. If their students are under 18, how can they even give informed consent? And once the parents understand the issues, who would give consent on their behalf? In most Judistictions, you need to be 13 or over (or 16+ in some parts of Europe) before you are allowed by Google to have a Google account, so it’s not like Google isn’t sensitive to the issue.

My sources inside the chocolate box tell me that the new Apps for Education will be advert free. When pushed, there was no guarantee that tracking wouldn’t happen – only that no adverts would be shown in the Apps themselves. Whether they will appear, based on tracking data, on other web sites remains to be seen and when the child reaches an “appropriate” age they’ll come with years of profile data. I’m awaiting clarification from Google on this matter.

(Update: Google has now publically declared that they will not scan Apps for Education data for advertising purposes, however the devil is in the detail. They don’t say that they don’t scan it for other profiling reasons. And then I found this court document, unearthed by SafeGov, in which Google’s own lawyers admit that they do profile students email and suchlike, meaning they can target adverts in other circumstances.)

And then there’s the question of whether it’s a secure environment. Well, no, it’s not. But that applies to Office 365, most LMS (see blogs passim) and anything else that has public messaging – in this case GMail. Given the problems I’ve had with users of freemail accounts, including GMail, I can’t help but question of the wisdom of allowing children access to it. When you’re signed up for Apps for Education you are supposed to be getting 24/7 support from Google, unlike Joe Public. Whether this helps resolve the issues remains to be seen. It’s also possible to turn off features centrally, such as Chat (an obvious thing to disable). Unfortunately, if you do turn off GMail there’s no other closed
messaging system to use instead.

As with my earlier papers and articles concerning LMS systems, I’m not saying that Google Apps are inherently insecure. In fact, I’ve got a lot of confidence that Google data centres, in particular, are robust. If Google does deliver on it’s data use policy, and is providing this service free of charge and with no strings attached, that’s great news. Microsoft has had their way for far to long for it to be healthy. Google has stated that as Google was born out of a research project at Stanford, they now want to give something back to education and that’s their only motive. It’s nothing to do with scuppering Microsoft; how could you possibly think that?

Like all Internet connect IT for use in schools, it’s the social risks that worry me the most, such as abuse of Internet email. If your school plans to use Google Apps, Office 365 or any other system with open email, just ask to see the risk assessment first.

That said, I’d still prefer to see educational establishments return to the open source model; Linux if you must, and OpenOffice. Computing by and for the people. Or perhaps those days are gone. We’re already stuck with a generation that now believes computing comes from large companies like Google and Microsoft. Sadly, I feel that it’s unlikely that most will have the technical talent in-house to make it happen.


Some of the concerns expressed here about data usage have now been addressed after Google signed up to this code of conduct IN THE USA.