Phil B at Green Pike Ltd
Director of Green Pike Ltd (https://www.green-pike.co.uk/ — a computer consultancy) and an information security manager (in the public sector). Former visiting professor and escaped academic.
Infosec, software engineering, F/LOSS and whatever else catches my interest…
BCS, CIISec and IMA
@neil@mastodon.neilzone.co.uk One of the documents says "This consultation was analysed with Consult, an AI tool developed by the government specifically to analyse responses to public consultations." So I expect the thought put in by those who bothered to spend time and effort responding will been wasted when it was never read by a human.
I expect the choice will soon be "hand over ID or be excluded from huge swathes of the Internet". :-(
@neil@mastodon.neilzone.co.uk Finally hit some other places, like https://www.theregister.com/2026/03/16/companies_house_breach/
Now if only Companies House would answer a query from last October….
@becomingwisest@hachyderm.io Thank you -- I will do some more testing, and see which technical policies they will fall foul of!
So passkeys had a few moments in the media spotlight (in the UK) this week. I thought I'd revisit them to test them again.
For those who know the technology well, is there any mechanism for handling cross-device flows where bluetooth is unavailable? I can see it's meant to help with proximity checking... but I can't see a way to make it work without bluetooth in my (limited) tests.
Second, how can we make it work on a single machine with multiple browsers? e.g., Chromium and Firefox both installed, potentially with multiple profiles. A crude method is to install whichever FIDO2 authenticator/sync service on every ... single ... browser ... Better would be a cross-application flow on a single device.
Anyone able to point me to means of handling those use cases?
Making Tax Difficult -- continuing horrors...: https://www.theregister.com/2026/04/10/mtd_hmrc/
Still despair of getting any sensible answers about replacements for CATO that don't require either third party web services or excessive fees.
(If as described in this report) it is not a good look for company governance:
https://taxpolicy.org.uk/2026/03/13/companies-house-security-vulnerability-directors-addresses/
"Companies House flaw exposed five million directors and enabled company hijacking"
Another day, another instance of UK regulators forcing people to buy commercial software just to engage with them.
Companies House writing, “all companies having to file their accounts at Companies House via commercial software”, wef 1 April 2028, “our web and paper routes will be closed for accounts filings from 1 April 2028”.