Showing posts with label observation. Show all posts
Showing posts with label observation. Show all posts

Wednesday, December 04, 2019

PayPal

I've used PayPal for years - it provides a payment platform which means I don't have to share my bank or card details with every organisation. It has - until recently - been good at maintaining an appropriate level of security on the account, and allows use of my preferred 2FA authentication apps.

However recently I've noticed a privacy-hostile attitude which is driving me away from the platform altogether.

One of the key benefits PayPal has created in recent years was linking to bank accounts directly, rather than using cards. This meant that when cards were replaced I would no longer need to update PayPal. If your PayPal account is compromised the attacker would be able to access your verified payment methods and make a load of purchases. If you noticed the hack you might cancel the cards - or cancel the direct debit on the bank account for PayPal.

Card issuers usually apply stronger anti-fraud than direct debit agreements, so it would be easier to make fraudulent payments through PayPal linked to bank accounts - which is why 2FA is really necessary.

If you notice issues, you could get in touch with PayPal and ask them to suspend the account until the issue can be verified.

So far so good.

However as I discovered towards the end of summer this year, and whilst overseas in the US recently, PayPal have become hostile to the kinds of privacy tools I use ... such as the VPN. If I tried to access my account whilst using a VPN that could be identified by PayPal, they would instantly lock my account.

I have MFA set up, and a verification phone number. That means that once I've entered the correct username and password the platform asks for a six digit number generated by an authentication app on one of my devices. That number sequence is unique to that device and cannot be moved to another device. The key (six digit number) is rotated every 30 seconds.

Occasionally I've seen them send me an OTP (one-time password) via SMS too, I would assume they do this both periodically to ensure the method continues to work, and if a string of transactions are unusual - but not totally suspect. However if someone has stolen your phone and unlocked it - don't use patterns, fingerprints or facepalm ID - they'll have access to your MFA key apps and SMS.

This is a standard approach - if you don't use one of these apps I'd recommend FreeOTP, which implements open standards and is open source (published by Red Hat).

I generally use a good level opsec across a number of different topics, and this is largely to remove my traffic data e.g. web and DNS, from access by companies monetising or filtering / traffic-shaping that data. A lot of the security work I do means that I want to reduce the information surface area as much as possible to prevent counter-investigation or intrusion.

When this PayPal account lockout happened the first time I phoned them and went through the security checks to get my account unlocked. Non-SMS MFA was part of that process which I was glad to see. Whilst the call handler was waiting for responses from the security team I asked why the account had been locked to start with.

I was told that the authentication platform had probably detected VPN use and assumed illicit access was being attempted. Although I pointed out that MFA was enabled and that an attacker would have to compromise four distributed devices to get to the information needed, the answer was that "...VPNs are an indicator of dangerous activity.". I've never heard anything so ridiculous.

Some months later I tried to login to PayPal to use a local food ordering service in the US, and again the account was initially blocked. Using a VoiP number for the UK I again spoke to PayPal and this time asked if my account could be marked to allow non-standard access, seeing that MFA was enabled. The call handler claimed that they couldn't do that, and that unless I accessed the website from my own country this would always happen.

Turns out the Android app does something similar and is thus effectively useless. Google also drives a lot of it's app infrastructure to get their permissions and access via Google Play Services, which means many apps no longer need to ask for specific permissions. I'm not 100% clear on whether that means that an app can access Body Sensors on-device via the Play Services service without explicit permission or not.

I've noticed that when using a safe DNS provider (either our own corporate network which strips malvertising or a public anti-ad DoH DNS provider), a number of apps fail authentication with errors. On initial inspection this appears to be because the tracking tools used are embedded in the authentication mechanism, and therefore disabled at a network level. PayPal appeared to have done this for a while as have TSB. Not sure tracking app usage during login is a good idea, especially if the tracking platform is somehow compromised. Tracking is not authentication or authorisation.

None of the security reasons given by PayPal for these approaches seemed to hold any water - why discriminate against VPN or Tor users? PayPal has historically been hack and breach free, it's still possible to get caught by phishing attacks. I don't open any emails alleging to be from PayPal (even payment receipts) as I would normally check the app on a regular basis.

Some configurations and bug bounties paid do make you wonder though.

To solve the problem at the time, I simply used a VPN through an existing tunnel to remote back to the UK and log in to PayPal. Although this time it was to cancel recurring payments and try and remove payment methods.

Despite removing all recurring payments associated with them, I was not allowed to remove any of the payment methods I'd asked to remove. I'll speak to the bank and cancel the direct debits instead - the first stage of replacing PayPal with something more privacy-friendly.

Maybe I'll go back to the protections of credit cards for online transactions, despite having to be concerned that organisations are not fully PCI-DSS compliant (or get hacked themselves).

Tuesday, November 26, 2019

DVLA Statistics - And How to Save £146m over ten years

Information is Free

Since becoming entangled with the DVLA, I'd raised a couple of Freedom of Information requests (FOIRs) and a subject access request (SAR). By law an authority is allowed 20 working days to respond to a FOIR, and can choose to either respond in full; respond in part (perhaps noting another authority which may hold the relevant information); or refuse to respond to the FOIR entirely.

In this last case authorities often hide behind the section 12 requirements, which detail the process to follow where the request exceeds the time or cost limits prescribed for different types of authority. I noted in my previous DVLA post in which instrument of law those limits are defined.

DVLA are set the ceiling of 4.5 man days or £600 - whichever is higher.

The scene is now set for each of the two FOIRs I raised.

FOIR #1 - Budget Information Relating to Physical Post

This should have been a fairly simple call to the DVLA accounts department, in order to get some basic information. I would have been fine with the more detailed item breakdowns being refused or declined, as long as the base figures were provided.

I asked the DVLA for figures relating to both the previous and current fiscal years:
- the DVLA budget for that year
- the amount spent printing documents to send to registered keepers e.g. fines, new V5Cs, reminders etc
- the amount spent on postage / delivery for these items

I expected the fiscal years for n-1 and n-2, rather than current (n) and n-1, as in-flight accounting is unlikely to be available. In the FOIR I was more specific as I thought it would help DVLA scope the request better, and leave less room for clarifications back to me. How wrong I was.

Initially the request was rejected under section 12 as being too onerous, until I pointed out that when working on programme budgets at most of my clients, I could get most of these numbers over the phone whilst I wait. I also pointed out that they'd already responded to my other request with the actual number of documents sent to drivers, which must have involved a similar amount of work (see the FOIR #2 section below).

I requested an internal review and DVLA responded with some of the information I'd asked for.

So the total spend on:
  • all stationary was £1.1m in 2017-18 & £1.2m in 2018-19
  • all postage was £25.9m in 2017-18 & £26.2m in 2018-2019
  • all printing was £14.4m in 2017-18 & £14.2m in 2018-2019
The total expenditure across these items was effectively £41.4m and £41.6m in 2017 and 2018 effectively. Yet they still essentially refused to supply their overall budget for those years. As I couldn't find a reference to this figure anywhere else on gov.uk I was reliant on this single public sector organisation for those numbers.

I then asked them to reconsider their position but expect them to walk away from this request. Their initial response was later than the FOIA allows, and their responses were evasive at best.

You can see the live FOIR here for reference.

FOIR #2 - Document Production and Delivery Statistics

This one went a little better and information was slightly more forthcoming. But it was still a struggle to get basic information from them.

I asked the DVLA to provide statistics / their records for the following:
- The number of physical documents sent to registered keepers
- The number of those documents sent via some form of recorded delivery
- The number of known tracked items that have a "missing", "undelivered" or similar category applied after they have left DVLA

Despite the specificity of the request, three weeks later the DVLA asked me to clarify what documents I was referring to. I clarified regardless and the final (late) response to the FOIR was received almost a month later.

It turns out that the DVLA sent 99,461,763 documents from Jan 2018 to 25th October 2019. Based on 662 days in that period and assuming the report was generated on the same day as the DVLA response letter; the average number of documents sent per day is 150244(.355).

That's a lot of documents. Only about 32k of those in that 622 day period were sent via some sort of recorded delivery, and the DVLA does not track how many of those tracked items were returned or otherwise undelivered. The DVLA did not disclose how much they spent on tracked / recorded delivery, so this is an assumed and unknown uplift on the cost-per-document-sent.

Now if we combine the responses of FOIR #1 and FOIR #2 we can say (quickly excusing my shoddy maths) that:
  1. In 2018-2019 DVLA spend £41,629,644 on document production (excluding 3rd party costs such as GSP)
  2. In 2018-2019 we can infer that in 365 days - and using the docs / day from earlier in this FOIR - the DVLA sent 54839189(.57) docs in this year
  3. Therefore the cost-per-item to the DVLA in 2018-2019 is £0.79
  4. This does not include the DVLA operating expenditure on the processes surrounding this document e.g. hiring staff to manage the processes, interact with the processes and operate processes where necessary, recorded delivery costs, heating, lighting, utilities and other standard OpEx items. The actual cost is probably between £1 and £2 (if the DVLA are operating efficiently).
In the same request I asked the DVLA to explain the QA processes which govern how they ensure the mail service providers (MSP) - UK Mail and Royal Mail - certify that they've collected all the documents produced.

The response on this front have been unclear at best and plain evasive elsewhere. I part of their more recent response the DVLA state:

"Data is input into the DVLA’s systems in accordance with specific parameters,
depending on the type of transaction. This includes a quality assurance check, which allows for work to be appropriately batched ready to send out.
"

That's a very broad description without any specifics, that doesn't really tell us anything at all. What parameters? What QA check is actually performed? They also stated in the same response:

"When a document is printed, it is then tracked electronically through the mailing system. This supports integrity checks until the document is enveloped and transferred to the Quality Assurance (QA) section. Some items of mail may then require reprinting.

The DVLA then hands over the items for despatch to the respective Mail Service
Provider and is reconciled against control document
"

This is more related to the question, and sounds like a proper answer on the face of it. However the portions of sentences I've highlighted should draw attention to the subtle evasion here.

So a document is tracked (per-item?) through the mailing system, so that the QA section can verify it in its envelope. Are they checking every single of the one hundred million items the claim to have sent since Jan 2018?

Finally the point about the "control document" is very vague - is this the DVLA's control document, and one which the MSPs do not interact with? In order words how are the DVLA verifying each letter is accepted by the MSP, instead of just picking up a box or pallet of mail which hopefully includes all the items DVLA has "tracked" to that point?

In fact if we reference a FOIR from 2009, we can see the DVLA admit that the MSP do not verify each item in the batch. I've asked DVLA to clarify a point relating to this as the answer seems a bit more thought out than the one a decade ago. I suspect they have no way of verifying that the MSP is collecting all the items they've printed (so can't entirely blame the postie for lost mail).

You can see the live FOIR here for reference.

Next Steps

Even if my earlier assumptions for calculation were correct (which I know they aren't), the minimum being spent per item is 79p. It's far cheaper for the DVLA to send a prospective fine, on the chase they can intimidate someone into paying than it is to actually review the case properly. It's a cash generation game.

I've largely exhausted options with FOIR as DVLA are likely to essentially ignore further clarifications on the request. Together with their breach of the Data Protection Act (DPA) I'll be putting together a formal document for breaches of FOIA to the regulator, ICO. This complaint will hopefully ensure the DVLA directly answers any outstanding questions.

A grey area has formed between the FOIA and the DPA where automated decision making affecting a living person is at the forefront. GDPR Article 22 deals with ADM - more specifically ensuring that adequate protections are put in place. These protections are aimed at ensuring that an individual suffers no undue harm. In fact Article 22 Section 3 states: "...safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision."

It appears the DVLA has breached this if ADM was at the core of the decision to fine and prosecute me originally. We cannot say that the DVLA has delivered on this requirement by virtue of pressing for prosecution in a case which it later manually determines not to have merit. This is not covered by the FOIA and must be considered by ICO.

In parallel to that I'll be raising complaints with DVLA directly, as was the suggestion of the DVLA prosecutor in the case I won. This complain will focus on recovering damages and distress.

IR35

I can't resist a poke.... the IR35 changes in 2018 will have killed off any IT projects at DVLA reliant on a contingent workforce of consultants. Those same consultants would have been able to build DVLA a digital presence which would remove the need for documents across a conservative estimate of 50% of use cases. A web-based dashboard with services to encapsulate authentication, authorisation and enable notifications to DVLA such as SORN. More and more people have access to the internet via smart-phones, less and less have no access at all - there are still post offices for the rest of the forms.

Eventually other businesses would want to integrate with DVLA data sources, as insurers already do via MID. The motorists data is already held by DVLA in order to support the production of drivers licenses, and therefore the authentication model should focus on driver-based logins. Data security will be key here considering the kinds of information involved. Ideally using MFA such as smartphone authenticator apps should provide a welcome layer of security, and open-source libraries are available to achieve this. The data layer is the most complete layer as it stands today.

Fines, penalties and reminders could all be dealt with in the first instance via the dashboard, with email notifications send to drivers when new 'documents' are sent to them by DVLA. Delivering these digital journeys will need the most engineering & testing effort. The DVLA claims its processes are largely automated so the integration architectures will need to be carefully designed - and probably brought up-to-standard. The DVLA already accepts payments for car tax online if you have a V5C or V11, so existing authentication and payment API's will need to be re-used and expanded upon.

A project of one feature team working on a digital dashboard, authentication model and microservices based on COTS would cost up to £750k for six months. That's a large feature team costing btw, probably one which would operationally be split into two agile teams sharing architect, BA & programme manager. Each team would have it's own scrum master, engineering and QA peeps. Software and licensing for SaaS, for example might stray into the £1m purchase, and £500k annual licence at worst for this kind of thing.

So making some wild assumptions and adding bloat as it's public sector, I did the following in LibreOffice Calc.

Large assumptions ahoy


I made the following assumptions for this:
- I don't know what architecture would be deployed that is compatible with Gov.uk strategy, so upped the IaaS costings for services, services and networks to 75k / year. This increased cost assumes redundancy and performance needed to support the traffic from potentially 90% of motorists in the UK
- I assume the Gov.uk is continuing with vendor-locked arrangements with Oracle, and Oracle are strong-arming Gov.uk as they are with anyone else. Ideally I'd focus on an open-source approach with something like RHEL, Apache, ELK and PostgreSQL, but I don't know how the x-charging works so assumed a DVLA-owned license cost of half a million per annum; plus new costs of authentication and integration of existing Gov.uk payment gateways
- Purchase of cloud and dedicated tin combinations, plus new infrastructure or services hosted for DVLA (assumed re-use from other Gov.uk departments such as MCOL or local government)
- A feature team costing based working over a two-and-a-half year delivery period; including 2 year build and test continual drops, with six months post-live warranty
- These are finger-in-air-estimates for design & development knowing nothing about what really goes on behind the scenes at DVLA

Any of the programme managers I've worked with at my past clients would've fallen off their chairs at those numbers and assumptions, but that's because they work in pragmatic, efficient and competent environments in the private sector.

So based against only a 50% reduction in printed documents - on the assumption that proportion of people register for paperless DVLA services - the DVLA expenditure on disclosed production would be £20,814,822 (ignoring increases with inflationary-associated costs). That's the cost of documents that no longer need to be printed and can be provided direct-to-drive with assured delivery. How many problems does that solve? :)

So the DVLA would save around £20m per annum OpEx, and expend £11m CapEx on rolling out the digital presence? Ok so those savings wouldn't be fully available until year 4. Over the ten year projection that's £145,703,754 cost savings on direct document production alone, versus a £7m run cost estimate over the same period. Still £137m can pay for a lot of tour buses for Boris Johnson.

How to achieve this? Get HMRC on a leash so they no longer exceed their authority under the law and stimulate what's left of the British economy by encouraging the vibrant, consultative small business.

Or keep flushing money down the drain and drive the skilled consultancy workforce out of the UK. You choose.

Sunday, November 24, 2019

Netflix

Streaming Wars Episode III

I've figured out a way Netflix can appease the vast number of people using privacy tools such as VPNs, whilst keeping their noses clean with the distribitors they buy content from.

I'm a regular user of VPNs - I have a policy which excludes open traffic on the UK data networks, and even when I'm not using a VPN I'll use some form of secured (and authenticated) DNS. It's not because I would be doing anything unlawful - I'm a law abiding citizen - but the companies that operate our networks are thriving on our meta-data, filtering our content and injecting malvertising into our web pages and mobile apps.

If you own a second home you want to rent - do you furnish it and offer it for free? No. Your renters pay you rent and then pay their own utilities in most cases. Why should that be different for use of our personal data and meta-data? Data is not "property" in the eyes of the law, but consent to use that data can be deemed as much of a commodity as the subscription services we regularly use. Such as Spotify or Netflix.

You don't own your Spotify or Netflix titles, you effectively rent the right to view them. No different to renting the right to use your personal data or meta-data to companies that use it for profit.

Perhaps four years ago I remember being able to use VPNs to access my regular content on Netflix largely without issue. I'd occasionally see a "You're using a proxy or unblocker" error and have to connect to another VPN server or service.

As the years progressed Netflix were largely forced into a more proactive stance by the film distribution companies, in order to ensure that those market (country) distribution rights were being enforced. Distribution companies make their money by selling distribution of their films in each market e.g. country or region, to the highest bidder in that region. If all regions paid the same slice on a pay-per-view they would lose premium essentially.

Netflix then embarked on an aggressive policy of enumerating as many VPN server IPs as possible - I suspect they buy accounts with many VPN services and catalogue any new IPs. They also watch to see if you stream from one IP then another IP in quick succession. Using probability calculations and geo-IP databases it's easy to work out which is the most frequently used home location, and which are the unusual (out-of-region) IPs. Finally I suspect the Netflix desktop and mobile apps look for network connections associated with VPN. For OpenVPN that's relatively easy as the default is a tun0 adapter. IKE v2 is a little more complex but just as detectable. If your VPN solution DNS leaks, or the DNS servers you're using are known VPN-provider DNS, I'm sure that is factored into the detection algorithm.

You may remember that Netflix then started investing heavily in paying for it's own content to become it's own production and distribution organisation. When pressed for answers about why Netflix continues to block VPN access back to your own country when abroad, or blocks VPN access on hostile networks; you will reach a wall of silence. In one of the help.netflix.com pages it does describe some of the complexities of the distribution (inc. streaming) agreements, which explains some of the inconsistencies for "Netflix Originals".

Basically Netflix has partially adopted the broken distribution rights model, in selling streaming rights to it's own content to other streaming providers. So in some countries you won't be able to see Netflix Originals on Netflix, perhaps you might on Sky or Apple TV.

For me this isn't an answer to the question: "why are you blocking subscribers using privacy tools such as VPN?"

I think there's a simple solution, and one that will help Netflix get an upper hand in the recently started Streaming Wars.

The Solution

When you sign up for an account, you provide a handful of details. The level of information is good for privacy advocates because it isn't burdensome, nor does it require irrelevant information.

You need a username (email), password and payment card. The card can be either a credit or a debit card, and must be authorised with the provider before use.

So if I were to operate the billing department I would then know the following:
- The domain name of the email address, and which country it's registered
- The country of origin of the payment card and it's provider name

Netflix store the card PAN, expiry date and CVV too. From the PAN I can identify the provider and country before I hash and store. I could probably ask the payment gateway API to provide me that information without me having to do it myself - that way I would reduce my compliance requirements for PCI-DSS.

Therefore... I know which country the billing account is based in. Why not associate the account with a home region (my country)? That way if I detect the user to be using a VPN I can restrict the available content to Netflix Originals which Netflix have rights to stream everywhere, and perhaps Originals content Netflix have rights to stream in my home region.

I could still view content from outside my home region if, for example, I was on hols in Spain and using Netflix without a privacy tool (c.f. proxy / VPN). I would be watching the Spanish Netflix library.

Although this dramatically reduces the amount of content I can view whilst using privacy tools, it means everyone is playing by the rules.

We can then also accept the added bonus that people in other countries can't take advantage of geo-unblocking capabilities to view content which breaches the distribution / streaming contracts.

Surely that's a win-win for everyone?

Friday, September 01, 2017

Current Events

This is what it took to get a correct final bill

Some significant time ago, I wrote about our experiences between Scottish Power and Spark Energy. It's taken a lot to get resolved including small claims court, regulator action and a lot of wasted paperwork. Whilst it's difficult to put an exact value on their financial throughput they're certainly able to invest in customer service.

Background


After moving to a 3rd supplier earlier last year and letting the dust settle, we discovered how little honesty had been involved.

Spark essentially refused to relinquish control of one of the supplies, claiming that there was an unpaid bill - actually they had failed to complete their own data entry procedures during the original transfer to them. Because they delayed the transfer one of our energy supplies was put onto the "default" tariff - the more expensive one they're legally obliged to move you off.

To compound the situation they then claimed that they'd never told us the supply was incomplete; so I sent them a subject access request to include all call recordings to prove them wrong. After the usual to-and-fro regarding the £10 access fee - an obstruction that disappears with GDPR - they relented when I suggested they simply add the fee to the outstanding bill.

Any organisation that sees the £10 SAR fee as a realistic way of recouping the cost of answering a SAR has a seriously ineffective accounting approach. This fee was originally instituted in the last century when email was not readily or normally available - so would cover the cost of print & post.

During this process - and without even sending us a final bill - Spark sent two separate debt collection firms after us at the same time. Each were told that there were legal issues relating to the case; that the matter was with Spark and that they were not to contact us again (i.e assumed rights of entry revoked). Some small part of me wished that one of them had attempted to get a CCJ, because I could then raise a counter-claim directly against Spark which included compensation for distress.

Spark made no attempt to reply to the messages above, even though they were included in the CC line.

As a side note, and during the final stages of conversation with the supplier; Spark noted that they had supplied the final bill to a portal - which they had neither told us about, nor notified us of the arrival of any document on it. Despite our standard opt-out of marketing messages this would be considered a "service message" and therefore be exempt from PECR section 22. There's simply no excuse for that level of communication in 2017.

I suggested that Spark use the same document sharing portal that they use for their bills and statements; I suggested that they upload to a file sharing service I would make available to them with credentials I would supply them. No - it would have to be via post.

£10 barely covers postage of a bunch of CD's - even though I pointed out that I don't own a computer that still has a CD / DVD drive - never mind the FTE cost of fulfilling the SAR request. Essentially the £10 fee has become largely meaningless - A business adhering to the law (the DPA in this case) must absorb this as a cost of doing business, based on the risk of how many SAR's they expect to receive vs. the frequency which is reasonable to respond to per customer. Most organisations I even feel the need to SAR often realise something is amiss and waive the fee - SME's usually get some free DPO advice as a reward if there are actually any issues.

After about two months they'd failed to send anything at all - frankly I half expected them to tell me they'd delivered it to a previous address. I wish I'd checked as this is a far more serious breach of the DPA.

However I didn't - and raised a claim in the courts for SAR failure as well as raising the issue with the energy ombudsman. None if this is a quick process and you can expect the company you're dealing with to spin it out as long as possible to try and make you lose interest. Involve the regulator and they start charging the company for every day the complaint is active.

The EO charges roughly £250 per complaint per day back to the supplier for each case, which means that they'll start taking it [slightly] more seriously.

During this process and on regular intervals Spark continued to send more debt collection firms our way. In total five different firms were involved and each were told to jog on. Yet not one direct message from Spark attempting to resolve the issue directly.

The Result


Unsurprisingly, in 2017 Spark were told to compensate us for the trouble, adjust the bill to correct the charge (the tariff we actually signed up for). Spark labelled this in their post-regulator letter as a "goodwill gesture", but they were simply told to compensate us then correct the bill - which then reduced the cost further.

The only admission of failure on Sparks part is highlighted

The EO refused to tell Spark to enhance their customer processes to prevent this happening again saying that it "wasn't within the scope of their powers". I would imagine that with the number of complaints being swept under the rug and emerging with the EO is roughly 85% of complaints lodged with providers, and of those (according to the EO 2016 stats PDF): 63% (of nearly 85k complaints) upheld or settled, with another 30% listed as 'maintained'. Only 7% of complaints lodged with OE were rejected.

Surely something is wrong where a BAU failure demand rate is at 85% of customer complaints being dealt with by a 3rd party?

It cost Spark £250 pd x 3 months for the OE case, plus their lawyers retainer to answer the small claims case (which was eventually struck out when I failed to receive the DQ request from the courts) - I've no idea what their defence was for refusing to fulfil a SAR without grounds to withhold; and most of their claim to the supply liability. Peanuts in comparison to their bottom line - which is why they simply continue not to care at all.

The final bill was around £15 - which still included the £10 SAR fee they had taken last year. At the time of writing Spark never responded to the SAR. They never admitted fault for the switches in either direction; even though both our current supplier, Scottish Power and the regulator conclusively identified them as the cause of the problems.

Saturday, May 21, 2016

Q1 Review

Miami winning 5-4 in the championship series...but it's close
It's been a busy start to the year beginning with having Swiftbiscuit show me how it's done on the kart circuit - even if he didn't bring is own racing boots, gloves or helmet from Miami. The marshals came up to him afterwards and mentioned their awe of his racing line. Total focus and precision - awesome to try and chase through the corners.

(I've also knocked a couple of seconds of my lap times and made it into the elite class since)

My birthday last month was pleasantly uneventful - although managed to get another kart race in on the weekend - there was one less birthday card this year which forced poignant reminder of the events of Jan and Feb.

Dad didn't tell us until it was too late and even though we knew he was ill, he didn't let on about how much pain he was in until right near the end. That was kind of his way of doing things (i.e. refusing to listen to anyone else). It didn't really sink in that he was beyond the point of no return until I got a call from the care home telling me he'd been taken into hospital.

We'll scatter his ashes in his home county of Cornwall this year so he can enjoy the countryside and coast he came to know as a boy. A lesson to all of us to make sure we take care of ourselves and always keep talking. Every hill is a victory in potentia after all.

There's too much to do on the information assurance front and I've re-focused my efforts significantly. The last two months or so has been flat out - no thanks to laptop problems and a 192 mile round-trip commute. This week should allow me to break the surface again whilst migrating corporate accounts to both a different package and different accountants.

All whilst studying for my CEH & CISSP...

I've made significant progress on the spam front too - from hundreds of spam emails a day down to between 20-100 is a big plus. I spend far less time trawling through nonsense looking for potential business or emails from friends & relatives. It's like whack-a-mole though...you get a domain disabled or an ASA complaint upheld against one and another pops up. Eventually the pattern will become obvious as individuals are already being tracked.

One thing I have noticed quite consistently is the attitude of spammers and their lawyers (with a handful of notable exceptions) - I'm becoming less and less surprised by the lack of knowledge surrounding DPA and PECR, as well as case precedent such as Vidal Hall vs. Google. I'm not suggesting an ambulance chasing model is ideal but it seems like the regulators are being restrained whilst the data traders and spammers are not.

Until the balance is restored however, ProtonMail, EFF and WWF will be getting more donations from me after winning or settling my cases.

Hopefully ICO's GDPR education campaign will keep momentum up as it's vitally important to drag the private sector into the current decade (before it finishes).

Fingers crossed that the EU referendum passes with a Stay / Remain vote and we can all get on with commerce again; as well as a wider, considered approach on privacy and information assurance in future.

Monday, March 21, 2016

Surface Pro 3 & Ubuntu Tip

Monday morning is always a bit of a struggle and it seems my SP3 was really feeling it this morning.

It refused to recognise either the SP4 Type Cover or the SP3 Type Cover during boot and OS load. Normally I'm use to swapping out to the older type cover for Ubuntu (real shame - SP4 Type Cover is a massive improvement) when the two stop talking but today...nothing.

No matter how much I shouted, cursed, cleaned the connectors, pleaded or bargained with it, the device would not recognised the keyboard.

This post is to potentially save someone else out there the frustration of the fix - which I found myself as none of the posts out there seem to fix the problem.

Here we go:

  1. Shut down the SP3 in preparation for a boot into the UEFI manager with the type cover attached
  2. Hold down Volume Up + Power and then release only the power button after a couple of seconds
  3. Got to keep the Vol. Up button pressed until you see the UEFI or UEFI login screen
  4. Doesn't really matter what you do at this point as you should be able to navigate / login using your type cover
  5. Select "Exit" and reboot
Should now be back in operation. There's something about going into the UEFI kick starts the connectivity between SP3 and TC.

Friday, November 20, 2015

Beneath The Surface

<abstract surface pun />
As a follow up to my last post I talked a little about how I'd become more open to options and that I'd had reservations about re-applying Windows onto my Surface Pro 3.

Obviously this isn't a default install and most of the concerns weren't because of issues with Windows - eventually I got Win 8.1 Enterprise back in there dual booting with Ubuntu. A couple of minor hitches which were resolved with a bcdedit command to force Windows to use the Grub2 loader after a file copy from the old Ubuntu boot partition to the newly-screwed Windows boot partition.

Still have to register the loaders in the secure boot registry, as is well described by David Elner (just be aware that this is an older version of Ubuntu and I could not get the kernel re-compile to work) but otherwise it's all ok.

However I thought I'd share some issues I have with SP3 and why I'm not likely to buy an SP4. For reference the PCs involved are:
  • Surface Pro 1 128Gb 4Gb i5
  • Surface Pro 3 512Gb 8Gb i7
Firstly the OS.... Windows 10 locked me out and I had no downgrade option other than a manual re-install. Something went horribly wrong after I got my replacement SP3 and for some as yet unknown reason Win10 software protection service started failing after I installed Office 2013 Pro. The knock-on effect was that I couldn't use Office, I couldn't use a lot of the feature changers (add / remove programs, anything that writes changes to registry, etc) nor would any of the safe boot options appear and I couldn't do a refresh or a factory reset either.

I didn't have any choice about Windows 10 - that was what was installed on the replacement unit.

Support simply suggested I return it to the shop and as I'd already burned two weeks for the replacement unit after a screen failure, then another week or so (evenings only) actually re-deploying all the 'stuff' on it, I didn't think the extra effort was worth the pain. After a bit of thought I then realised now would be the perfect time to dual boot it and have a workaround for some of the issues with Windows in general. Not much to lose at that stage.

Of course now I have screen flickering issues on the unit - it seems to be some sort of physical connection issue because when I squeeze the screen in a particular place and wait an undetermined amount of time it sorts itself out. Although often I'm not sure whether the whole thing hasn't just hung and I do a hard reset. It's not a driver or software issue as only physical intervention (pressing and squeezing the unit until the screen springs back into life is not a driver fault or brightness management) and I just don't have time to send it back for another replacement; rebuild and re-deploy only to later find out the same problem might exist.

A very embarrassing problem for a touch screen device.

The pen....the pen....What a brilliant concept yet how did they screw it up so badly? It feels like a real pen, the buttons on the side are fantastic and I no longer need a mouse....just the pen and my fingers. But then all by itself it decides that it needs a rest and goes to sleep. I've tried battery replacements, holding down buttons to try and wake it up and even whacking it over a solid surface (which seems to work most often) and nothing seems to help. Of course if you try and disable power management via Windows you get a BSOD. Nice. And I'm far from alone on this one.

Windows 10 lost it's way and I struggled to get it to flow as Windows 8.1 does. 10 tries to keep the desktoptards from Windows Vista *spits* and 7 happy whilst showing promise to touch-screen owners. Sometimes I think the desktoptards were the only voices complaining about 8.1 and not enough people extolled it's virtues. So now I have 8.1 Enterprise until the end-of-life or when Windows 10 Enterprise catches up so I can access OneNote during meetings and sync my OneDrive repositories. Windows also seems to be the only way to get firmware updates for Surface so it gets a small section of the SSD to park itself. I have too many reservations about the way Microsoft is approaching some aspects of security (such as the changes to BitLocker in 8). I'm not trying to outrun any governments but if someone nicks my SP3 I want to be fairly sure they won't get my data in their lifetimes. Of course dual booting means BitLocker won't encrypt the system drive like LUKS will, so only the OS and some program files are on the open system partition, the rest is on encrypted partitions.

Ubuntu is ok too - but the touch screen integration is extremely basic and there's no handwriting tools that are anywhere good enough. The pen buttons just don't do anything at all and no matter what I try I can't get the kernel re-compile to work. With Wily Wolf the battery indicator suddenly appeared and that was a big step forward - I've also discovered that touch screen scroll & zoom does work in specific applications. At the moment I'm struggling to get routes working under OpenVPN configurations that work fine under Windows so I tend to use Windows for comms and browsing in situations where VPN is a requirement. I will fix the problem but I need to understand it first.

I've also noticed that Network Manager sometimes refuses to use the right password for WiFi networks, resolved only by a mac change and a ifdown-up on the network adapters. That seems a little shoddy to me. Evolution is a pretty good mail app and I'm not really missing Outlook that much so it's evens on that front and with LibreOffice too - there are some issues with .XLSM and the occasional corruption-and-loss of .XLSX which is beginning to get on my nerves. Ubuntu seems ok but the Pen buttons don't work and I tend to end up using a mouse - the horror! - due to that and the SP3 Pen sleepy-time issues.

In short - neither platform is doing a great job at the moment but each has its own strengths.

I'm not going for a SP4 because - as much as I've loved the Surface experience - Surface Book means I can have my cake and eat it. It's more powerful than the overpriced Macintosh (I'd only be replacing OsX with a Win & Linux dual boot anyway) and I get the clipboard & pen with OneNote and Visio that I can't be without in meetings and team updates.

Of course that is assuming they fix the current complaints and I see some indication that the pen behaviour has improved. My Surface Pro 1 is still going strong and I don't mind Windows 10 on there because I don't use it much. The rest of the family don't seem to mind it when they want to use Kodi or play some Xbox games and everyone's forgotten about the Nexus 7 completely.

Tuesday, October 20, 2015

Argh - It Still Hertz!

Ha. Electricians joke-books are fairly rare. Yeh so my humour doesn't get any better and Scottish Power are still....consistent.

Not only did they send us a letter in the last week or so begging us not to go, now they've sent us a bill for the account they haven't closed. They've put my name at the top of the bill so it's not like they don't know who they're mistakenly trying to bill.

Let me rewind the clock: We used to have an account with SP at the old house and after all their flannelling around I told them I didn't want to take our account with us to the new address.

Of course they knew better than us and ignored that request leaving our beleaguered energy supplier to wrench control of the supply from them. I feel sorry for our new supplier - we deliberately moved away from the big six and haven't regretted it for a moment. It's cheaper and we still have gas and electric. Pretty simple relationship.

However after a call with our new supplier, Spark, it seems that SP are just ignoring them completely. Spark sent them a request to re-acquire the supply, which has now been successful on one of the supplies but now they're not getting any response at all from SP. It's not really fair to say that Spark are our new supplier either as we've been living here for most of the year now.

I told the Spark representative that I think they're just sulking. They've been told we don't want to be friends any more and they've taken their ball away.

During the discussion I pointed out that we had contracted the new supplier to supply us gas and electricity; we would not be getting in touch with SP to sort it out. After this incident I may send them a notice before action - we told them where to go before we moved out of the old house and there's just no way we'll be paying them a penny more.

We've been paying the new supplier since signing up so we're happy that this is between the energy companies but ... it's probably time Scottish Power to stop resisting (yes another electrical joke). At least we're staying positive (aha! on a roll).


Monday, October 05, 2015

Shocking Stuff

For the last five months we've been trying to get shot of Scottish Power. We tried every crazy approach you could try - telling them we didn't want to transfer the account to the new address; telling them we no longer wanted to use their services; asking them to close the old account at the previous address (or the current address as it was at the time).

Sadly all of these things were too complicated and meant that SP would ignore our instructions.

We asked them just to close the account at the end of our fixed rate tariff before we moved out of our old house, and enquired about the estimates for our new house.... which made us run away very fast. We also made the mistake of letting SP know our new address. I remember a phone call with one of their representatives that ended with me saying, "So there's no more paperwork needed; I don't need to cancel and house move requests or anything, that's it - you'll close the account and we'll hear nothing more from you?".

"Yes", was the confident reply.

Enter a new supplier (not one of the big six) who had supplied the previous owner; it was easy to sign up and sort out the tariffs, payment details etc and send them meter readings by replying to the emails their system sent us - no need to log in to your account...or rather forget what the password and user name was, request a reset, then reset it all, then login, then try and remember what the hell you were doing to start with and; finally update the meter readings.

However not all was as simple as it could have been ... we started getting letters and emails from SP at the new address saying how nice it will be to move our account for us and could we send our meter readings for the ... er fellas? What are you doing? We said "jog on" a couple of months ago, yet now you seem to have ignored that conversation and followed us home like some sort of deranged acquaintance we talked to that one time in the bar to be polite but were very clear that were not inviting home and...

I called our new supplier and they told us that this is a Tom Jones with the big six (it's not unusual...); often they have to let the other company take the account then claim it back some weeks later. I told them that they absolutely had our consent to do this and that SP had been told to close the account.

"No problem. You don't even have to speak to them again. We'll sort it out for you - but it might take up to 6 weeks or so". And they were true to their word (along with comedic unofficial comments about their competitor).

So now five months after the first calls to SP we're away but still they send us letters asking us to come back - despite being far more expensive that our supplier.

Sorry Scottish Power: It's not us - it's you. We need some time* to ourselves.

Outta here
* Where "time" is measured in periods of no less than twenty five years.

Sunday, May 17, 2015

Progress Part 3

...carrying on from Part 2:

After a fair amount of digging and acquisition of evidence via SAR, I now had enough to make an informed decision on whether or not to take legal action.

To me this was a serious and significant breach far in excess of a normal situation. It was above and beyond the usual spam scenario as I had been subscribed to services I had not consented, and been forced into subscription policies I had not reviewed (or even known about). Essentially as a self-employed worker my resume is my sales pitch - if my competition gets a hold of it they could refactor parts of my resume approach into their own and I would potentially lose my competitive edge (my unique selling points) and therefore lose revenue. Having some unknowns in Pakistan scraping these details from jobs boards for free, then selling them on to the highest bidder beggars belief.

What really pushed the decision for me was when another person with whom I'd had contact reported that another flurry of negative Twitter-verse activity had occurred that week - for exactly the same reason as in December and January. Even after all the correspondence and negative feedback they were still doing it. Someone had to do something.

If you find yourself in a similar situation and decide to press for damages in the courts take the following points into consideration:
  • Have a list of items for damages, each with supporting evidence
  • Make sure you can explain each item on this list to the courts - who may not necessarily share your understanding of data, it's management or ownership
  • Be prepared for legal aggression from the outset. A standard trick across all specialisms of law seems to be an initial threat of return action
  • If there is a clear and describable breach of the DPA and / or PECR with evidence the defendant is still breaking the law, so do not take the defendants legal representatives threats as fact
  • A number of people I know in law - including relatives - have reminded me that there are guidelines for dealing with aggression. The Law Society has this LiP page, of particular interest is section 3.1
  • Get a copy of the consent form you signed for the organisation in question to hold your data. They won't be able to provide this of course, because you never gave your consent
I had some very good opinions from a lawyer I found online who specialises in this particular area of law. Although he was clear that he could not provide guidance or advice he gave me some good, solid facts and great reference material.

So the chain of events was a breach of the DPA and PECR, confirmed with evidence in writing from the defendant. I also maintained a list of damages covering the initial damage claim (£500, plus £35 costs) which was in excess of £1000. The aim were was to provide the courts with a list of items and the courts would decided which of these was recoverable. After no response for four weeks to a Notice-Before-Action (NBA) notification I raised papers via MCOL - which took less than 10 minutes.

I claimed nominal damages from My Job Matcher and we settled for £400 (plus court costs). Most of the time the defendant will try and get you to sign a gag order - it'll have some covenants such as deleting tweets, blog posts or publications, and a form of no-contact directive.

I negotiated the settlement with MJMs legal team (Birketts) without the gag order - One thing I should make clear in the interests of fairness is that they settled without admitting liability to the claim. Whilst I was fully prepared for the day in court it was a relief to settle.

My Job Matchers Twitter profile no longer seems to be under heavy fire from complainants but still sees the occasional "WTF?" sent to it, after a few weeks the SEO team at MJM just stopped replying to them all anyway. I know I'm not the only person to litigate against MJM so perhaps our objective was achieved (update: apparently not).

It's just a shame people have to resort to this to stop the illegal re-use of their personal details; however taking a more aggressive approach is having a substantial effect on my inbox. I'm not going to suggest that direct legal action should be your first approach - in fact it should be your last resort. ICO is almost entirely ineffective from what I've seen so far but the ASA appears to be able to apply some more pressure. I've even involved trading standards in one case.

I got the following email from MJM shortly after the settlement cheque cleared (others got a "How did we do?" support service email), and after the no-contact agreement was exchanged. The irony again here wasn't the email recipient wasn't the account they'd stolen from 2007, nor was it the one from the support email chain.



Progress Part 1


Background

Back in April I mentioned on another blog that I'd encountered a more extreme example of breach of DPA / PECR and would be taking the matter more seriously.

Now the dust has settled I can speak more about it and add details / guidance principals.

In most cases I'm more than happy to rifle through company details, back-check organisation structures and determine the actual origin of the spam. Often it reveals that someone somewhere is trying to make a fast buck from your personal information without consent - and without compensating you for the pleasure.

Usually a combination of ASA and ICO complaints ensure that you'll never hear from the spammers again but occasionally someone really takes the biscuit.

Hand In The Cookie Jar

Twitter is an enourmously useful tool as it can augment your own opinions on a brand, organsiation, person or fact with a vast variety of 140 character masterpieces. When I started getting unsolicited emails from MyJobMatcher in January 2015 I noticed that there was a large group of people in the same situation - having been emailed job adverts from a company we'd never heard of, never subscrubed to and never given any kind of consent for any of the above.

So...no accounts had been compromised but personal information had. Maybe a recruiter got hacked or a jobs board?

Others have also blogged about the specifics of the privacy breach so I'll leave you to read their posts
There were many more simply questioning the approach....
But simply search Twitter for MyJobMatcher from early January to April for more of the same.

I got in touch with MJM with an initial Subject Access Request (SAR) to find out who they were and what personal information they had....And although I got an auto-response from their support system to say the message had been received (v. useful in DPA / PECR cases) I heard nothing for a week, yet continued to get spam about jobs that had very little relevance.

Before raising an ICO or ASA complaint it's better to check what details are involved and how they arrived at their destination. I can say with confidence that I don't subscribe to newsletters nor do I enter prize draws so know the usual flagrant response of "...you must have signed up for it somewhere..." won't fly.

First up someone on Twitter suggested getting in touch with Mandrill at help@mandrill.com - they were nice as pie and sorted out the spam straightaway. I coul dhit "unsubscribe" but it's better to hit the distributor so they know there are other issues with a particular client. In other cases I've been involved with companies have been banned from using marketing distributors entirely because of this.

I'm going to ramble on a fair bit so will break the posts down into chunks.

On to part 2

Sunday, April 19, 2015

The Sting Of Chlorine


We often take the kids swimming and one of the pools is in Harbone. Facilities are good, kids have fun and we get to do some lengths too. However I made the mistake of buying some replacement goggles from the pool shop in the leisure centre - leading to a standoff in the reception area.

During the swim the goggles leaked and no matter what grip or band settings I tried they just kept leaking. After we'd finished I took them back to the reception desk and explained what the fault was (I just wanted either a replacement or a refund).

However the staff claimed that they could not refund the value of the goggles as they were not defective, and that they were not obliged to do so. I pointed out that my statutory rights as a consumer, plus those of standing legislation meant that as I was not happy with the product I could get a full refund. I also pointed out that I would not move from the desk and allow them to serve anyone else until the matter was resolved.

Whilst the staff went into the office for a huddle - I felt a little sorry for them having to deal with their employer's misguided principals - and the queue behind me grew. This is a good way of ensuring that retailers acknowledge their responsibilities and speeding a resolution; it's too easy to email or write letters and take no ownership or involvement due to the dissociative nature of words on paper.

However I got caught out - distracted whilst updating the Twatterverse on minute-by-minute changes to the situation (as if anyone was actually reading my twitter feed), the manager asked me to step over to another area to talk about the resolution.... fell for it.

The spell broken and the other waiting customers started getting to the desk. Bargaining position lost and hat tipped for being bettered.

All I could get was a credit note for the value of the goggles bought that day and the heartfelt promise of a phone call when they had the goggles in stock next. Maybe they're still waiting for the next batch? Either way I'll go to Amazon in future - even if I can't stand at the sales desk and stop other people getting served before they sort out my purchase.

Trotter Lettings Esq.

I had the misfortune to take up residence in a flat managed by Reed Residential last year. The flat itself wasn't bad as a property - although it would have been better had there been heating during winter.

And therein lies the comedy.

The problem with the heating was reported to them during the xmas holidays so the first delay in response was simply due to no-one being in office. As the weeks past though, and as my continued phone calls started being deflected by "Oh I'm sorry, Adam isn't at his desk right now", or "Adams in a meeting at the moment, can I take a message?".

I started imagining that Adam was printing out my emails and then using the paper copies to fuel an open fire - whilst wearing shorts and a t-shirt because of the heat produced - whilst I was shivering under jumpers, paying a premium rent for the pleasure.

Estate agents are a known quantity so it wasn't a Herculean leap of the imagination to realise that the primary contact - Adam - was simply avoiding my calls. There was a visit from an engineer to size up replacements, then the landlord wasn't sure if he wanted to replace them. Then he was getting other quotes, then the engineer visited again to get other measurements.

Nothing was moving in any direction other than a fob off and Adam seemed to be to focused on using my emails for firewood. Until February.

Then I cancelled the rent monthly standing order  and waited. By this point I'd had enough and was moving out but I thought it would be interesting to see how long it took Adam (or anyone else at Reed Residential) to get back to me and start playing nicely.

The response was simply astounding - Almost two days after the rent was due I got two emails and four phone calls (three of those on a Saturday)...of course this wasn't to apologise for months of refrigeration / premium rents; nor was it to ask if there was anything they could do. No - it was simply to chase for missing rent. So I explained that once the flat was in a condition befitting the rent and inventory I would be happy to pay full rent but in the mean time I'd deducted an appropriate amount retrospectively [i.e. since the problem first occurred]- meaning no rent was due that particular month.

And now everything changed - suddenly radiator replacements were being flown in by winged chariots piloted by Valkyrie smoking Romeo y Julieta's; there had been no delay, simply a misunderstanding and should I not pay rent I would be taken to court and flayed by their eight storey tall lawyers.

Of course I'd already moved out at this stage so it was just for my own entertainment (causing them the same inconvenience they caused me).

The net result was that they kept the deposit and probably just about broke even, someone at Reed Residential was apparently relieved of their job (the eponymous Adam) and the world continued unabated. However the real comedy occurred a couple of months later and really highlighted the care taken for all of their customers and tenants.


Now its entertaining astounding for a number of reasons:
  • The apartment doesn't have a microwave, I had my own and never mentioned it to anyone at Reed
  • I'd moved out on 28th February and this email arrived 22nd April
  • I made no request relating to anything other than the basics. Like heating.
  • Pretty sure they're talking about a different apartment
  • Pretty sure that email should have gone to someone else
  • Someone else probably got angry at Reed for not delivering on their promises

Thursday, January 01, 2015

MSXML 3 Control Panel Killer


I've got a few posts in the pipeline at the moment thanks to the generous time I've had on hols, but one thing caught my attention whilst fixing a problem on a Windows 8.1 Enterprise desktop.

I use Secunia to help keep an eye on installed software - it can be difficult to keep track of all the software installed sometimes, and this solution seems to cover various types of installer (including EXE's copied into a folder, without any associated registry settings).

So after running it and getting caught up on some minor version changes it also pointed out that there was a deprecated version of MSXML v4 deployed and after some laborious - but necessary - ownership and permission changes in SysWOW64 / System32 directories, I'd removed the MSXML v4 libraries. Of course that's never enough - Also noticed MSXML v3 so did a bit of digging into the upgrade path to version 6 (most of which dated back to 2007). No indication of warning signs.

So some more ownership & permission changes followed by some deletes. All fine.

Some time later.... I had cause to make a networking change and tried to open the Network and Sharing Center... hmmm. Nothing happens.

I try a few other control panel items and get a mix of results but most of the really important control panel pages aren't working. Some just aren't responding, others open the dialog but have particular tabs throwing exceptions about panel pages.

So aided by a bit of digging around I find the reference to the system file checker (sfc) - Always have a look at the command before you run it (rather than just doing what a web page tells you to...ironic considering this is a blog post). I hadn't connected the dots between MSXML and the problems at this stage so was curious about the log file sfc /scannow would generate.

000007c6 [SR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\WINDOWS\System32"\[l:22{11}]"msxml3r.dll" from store
000007c7 [SR] Repairing corrupted file [ml:520{260},l:46{23}]"\??\C:\WINDOWS\System32"\[l:20{10}]"msxml3.dll" from store
000007c8 [SR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\WINDOWS\SysWOW64"\[l:22{11}]"msxml3r.dll" from store
000007c9 [SR] Repairing corrupted file [ml:48{24},l:46{23}]"\??\C:\WINDOWS\SysWOW64"\[l:20{10}]"msxml3.dll" from store


There it was - literally as simple as that. Of course now everything was working as expected I did what I should have done first and read up on the MS Xml Parser roadmap.

Moral of the story...If it ain't broke, don't fix it. (especially if you have a cold and know you're not operating at 100%)

I'll post less dumb things as soon as I've got Kali set up on my new Pi B+. 

Sunday, July 27, 2014

2014


I've been away from the blog for a long time, but then I've been pretty busy.

I have some new observations to add to the mix - Off on holiday to Italy for a couple of weeks soon and intend to soak up some sun whilst putting pen to paper...assuming there's no WiFi I can crack near the beach :)

Thursday, September 27, 2012

Google+ Integration 'Upgrade'

I was up for the idea of integrating my blog with my G+ account - I wasn't really using it much and only a few of my friends are active on there.

Generally I find social networking useful for two reasons: keeping in touch with friends in other countries and selling business services.

The problem with this integration is that your Google+ profile replaces your blogger profile, which is ok... but  I've got particular settings and appearances on each which don't flow together. Whilst I'd still rather use Google+ than Facebook - I closed my FB account last year and am unlikely even to create a business page - I just feel that the integration between products could use a little more flexibility.

Good idea overall, just a couple of issues stopping me going ahead with it.

Update 15th August 2014

I've gone with it. The benefits of linking the posts to something like Google+ outweigh any foibles and the plus profile is now a lot more flexible. It's a no brainer.
The only think left to do is find something that automatically links new posts by adding a twitter status. The blog itself has gone from a technically focused R&D exercise to a business and architecturally focused observational process, infused with a sprinkling of scenarios from outside of the business world :)
 

Tuesday, September 25, 2012

Information *Is* The Commodity


You're about to set out from the world of permanent employment and embark on contract work. Awesome! You know your tech-stuff and are chomping at the bit to ply your trade as a gun for hire...but are you savvy when it comes to negotiation and recruiters? Sure, you're confident in your technical skills, but do you know how to be a top-class salesperson too?

It struck me recently that there are perhaps less experienced people being taken for a ride by the seedier agents out there. If you've been doing this for some time or have also read the Toe-Rag Recruiter Playbook™ you probably won't be interested in what follows.

All I'd like to do with this post is provide a few tips and explain why some agents might ask some seemingly innocuous questions. After a number of years learning from my own mistakes I've built some very good relationships with particular agents I trust - They've even helped my out by explaining some of these areas, and over the years a few have even become mates.

It should also be pointed out that not all recruiters are used car salesmen, generally it's more likely to be one or two people at a handful of agencies here and there. We each have our own personal preferences about who we like to work with and who gets us the best rate, so I'm not going to insult your intelligence by telling you who to use and who to avoid.

This isn't about naming and shaming either - It turns out the Del Boy stereotypes out there are known to all anyway. A mate of mine (a recruiter) also pointed out that the recruitment industry is there to make peoples lives better - via career and monetary advancement. He's right and he also pointed out that, like anyone, there's bills to pay and sometimes people stoop low to keep the wolves at bay. There's plenty of good websites where people can share their views such as Contractor UK - some particularly good advice across a range of topics and forums.

Before we start though, don't start treating recruiters like cold war-era spies trying to steal the toast off a grannies breakfast plate. Treat recruiters with the same professionalism and respect you'd use for clients or potential new bosses (it doesn't matter whether it's returned, just stay positive and professional). Remember: recruiters are your friends, they're most likely to be the people that'll get you that next job.

Terms and Conditions

Make sure you fully understand the implications of payment terms before you sign a contract. When are time-sheets due? How often are invoices processed and paid? What happens if you miss a time-sheet & invoice deadline by an hour? Are the agency willing to be flexible once or twice?
Ideally look for an agency who accept weekly invoices, pay weekly and don't stipulate daft paperwork requirements like "your time-sheet and invoice have to be in on the Friday lunchtime for the same week".
Once you've signed that contract you can't change it until renewal time looms.
Sometimes you have to compromise to get that rate or a contract to get you commercial experience with something. It all swings in roundabouts.
Another discussion here which may give you some more ideas.

LinkedIn Contacts

Ah, such a good idea.
Ever noticed that pretty much only recruiters write updates on LinkedIn? Sure there's big companies selling stuff, job openings and some great groups but most of the time that recruiter who's just massaged your ego a bit will shortly send you a LinkedIn request.
What you may not realise is that following that they'll probably work their way through your contact list and find your current boss, your previous bosses, colleagues who may be hiring and other potential candidates (i.e. your competition).
It shouldn't have surprised me so much I guess, but when I hid my contacts the next few agencies who sent connection requests called or emailed less than thirty minutes later asking if any of my colleagues were also hiring. Pretty much because they discovered they could't access my contacts or associated profiles.
Hide your contacts list on LinkedIn from everyone and control the flow of information as you see fit. Hide the "Viewers of this profile also viewed..." box in the same way too. It's only used for the same purpose.
This one is up to you, you're potentially offering up information on your own competition.

Job Specifications

This one's a bit trickier as not all vacancies will have a formal job spec. For example, there might just be a company telling a recruiter to find them a Java developer with WebSphere experience. Just be aware that agencies advertising a role that doesn't have a job spec *may* not actually have that role on their books. It's not always the case but they may have used any number of methods to try and get their foot in the door, firing across some prospective candidates to a potential client.
Mind you, there's nothing to stop the agency amalgamating a few existing job specs into one fictitious one so there's plenty of ways around it.
They may also just be trying to fish for candidates to represent for roles that haven't fully materialised yet. Either way ask for a job spec and confirmation of rate / package - If they claim not to have one yet and you've not worked with that particular agent before, be a little cautious.

References

One particularly annoying ploy for a hiring manager is when you get cold calls / emails from an agent you've never worked with, asking what sort of candidate you're looking for with regards a vacancy either you've just filled or have never advertised. How did they find out?
You always get genuine agents you actually want to work with buried under all sorts of tat and unrelated connection requests.
One tactic is to advertise a fictitious role and asked for references from applicants. Maybe a day or so later that role "magically" gets either withdrawn, filled by another agency or the agent "can't get hold of the client" - usually it didn't exist in the first place. However, in that time, the applicant is sent a job spec for another role...But the agent's now got their foot in the door with a new potential client or contractor directed by your references. Granted, that is a worst-case scenario but it does happen.
They may ask your referee for the reference but will tag on a business enquiry offering their services on the end. They may tell you it's a requirement to validate candidates; honest conversations between agencies and hiring managers usually end up with an agreement that an agency can only screen technical candidates so far, the rest is up to the interviewer to assess (i.e. references often have little to do with it).
Bear in mind that this isn't always the case - Speculative applications are very different to applying for live roles. In this scenario if you already have recommendations or testamonials, supply these to the agency omitting the names and organisations of the referees. Often those agencies working on a more pro-active basis will like to create a sales pitch about you, backed up with real-world opinions. This is a great approach for speculative applications on your behalf and has worked well for me in the past.
There is no company in the UK (possibly Europe too) who requires references with an application from an agency. Even government or security-cleared roles with checking processes have a more direct approach to references which are far more formal.
Usually the person at the client organisation interviewing you will ask for references if they're needed at all - It varies, some hiring processes require it post initial interview, some don't at all.
Professional networking sites often have a recommendations feature which is a reasonable compromise (most people are happy to act as referees if they just don't want to make a public recommendation).
You may get into a situation where the agent tells you that they can't submit you for a role without references as it's "a requirement from the client". This is cow poo. Challenge them: Ask them if they're happy for you to approach the client directly as you understand they cannot represent you in this instance due to their own processes.
You'll be surprised how often "all of a sudden" they find a loophole and your resume is on the clients desk for review. More importantly, if that doesn't happen don't reconsider and don't dwell on it. You're almost certain to have a conversation with that agent straight afterwards about another role which "may also suit". If you don't, there's a hell of a lot of agencies out there who will work with you.
Tell agencies who've asked you for this that you'd be very happy to supply a list of referees *directly* to their client when the time comes.


Who Was....

I hate these questions. It's like they're cringing with embarrassment at the other end of the phone for even asking it, just to see if they can get away with it.
You'll be asked who you worked for (sometimes tied in with requests for references), who you worked with, whether they're hiring at the moment or how the business is doing in general.
Don't mention names - or even job titles - This is just another ploy to generate leads / new business by contacting the people you mention in this scenario. It won't make any difference to your application for a role at all.
When you have an interview arranged via another agency be honest about the fact - Just don't disclose which company it's with or who you're going to be interviewed by. Always let them know how it went and where the land lies going forward though. See point #5 in the summary below.

You Don't Want To Work There...

Often when a recruiter knows you're going for an interview they'll ask who it's with, who you're meeting, what kind of role it is, what the interviewers favourite colour is, how many fingers they have....

However, often that follows with something along the lines of:
[Agent] "Well good luck with the interview, I'm sure they'll hire you after spending any length of time speaking to you. If you don't mind me asking, who's it with?"
[Candidate] "It's an interview with Daves Websites Plc in Exeter"
[Agent] "Oh ok, I've heard of them - who's interviewing you?"
[Candidate] "Erm, I think it's a guy called Horatio Hornblower."
[Agent] "Ah right. That's interesting."
-Oscar winning pause and change of tone-
[Agent] "Just so you're aware, I've heard some interesting things about DW Plc, lots of people have left there recently because of the environment"
[Candidate] "What do you mean? Is it really that bad?"

At that point even if you don't believe them it starts making you think. Score one for Johnny Recruiter. It's an age-old tactic and a lot of agents try this at one time or another. For me I see it as an unprofessional mechanism to steer candidates back to their own vacancies. It's a *real* annoyance when you're trying to hire people.
Even if it is the same thing as politicians running negative campaigns against one another,  they're in business to make money from you, the product, so gloss over it and keep the relationship positive. It's just one of those things that's to be expected and it's no big deal.
Try speaking to contacts and getting first-hand opinions if you're getting concerned. For permanent jobs, carefully phrase some difficult questions about working practises during interiews. Disguise questions about how many people have left / joined with topics on how fast the teams are growing, how often people stay late at work and why the role is open in the first place.

If you're a recruiter reading this who's actually tried the steering tactic: Bad dog. No biscuit for you.

Tips and Summary

So as an overview, eight points to consider - Remember it's not a rule book or a doctrine but just some suggestions:

  1. Hide your contacts list from everyone on LinkedIn (or any other professional networking product). Do the same with the "Viewers of this profile also viewed" box too
  2. Never give references to agencies, only ever directly to a potential client. It doesn't benefit you in any way to do otherwise no matter what the recruiter might tell you
  3. Always get a job spec before you hand across too much information
  4. Never disclose who your line manager was, who's job title was what, which directors deal with what, which other managers deal with which area of the business....It's just lead generation. You can always use this info as a bargaining chip if you like as an incentive to get the agent working for you, but that's your choice
  5. Don't disclose the organisation or name of the contact for interviews you will be attending. It's none of their business (they get shirty when you disclose their clients to other agents so it shouldn't work the other way round either). Do let them know you have irons in the fire though, that can help move things along
  6. Any time an agent tells you to avoid or be wary of a particular company, press them for the source of the references and take with pinch of salt. Also realise you should have followed point #5 and slap yourself in the face for not doing so
  7. Never discuss your rate with anyone but the agent and your accountant. Not even your mates or your boss (even though your boss should already know). Bad for business and come negotiation time it'll only hurt you. You never know who your mates' mates are, or who *their* mates know either (the "it's a very small world principal")
  8. Most importantly, be honest with recruiters about yourself, your skill set, what sort of roles you're currently capable of and whether you've been submitted before. You'll only make them look bad and less likely to talk to you again if you don't. That trust relationship works both ways.
If you're reading this and strongly disagree, I'd love to hear from you. The topic is an open book based on both my own experiences and [horror] story swapping with peers.

Conversely, if you're reading this and have your own experiences to add it'd be great to hear from you - Please keep it constructive and informative though :)