Introduction About Site Map

XML
RSS 2 Feed RSS 2 Feed
Navigation

Main Page | Blog Index

Tuesday, December 13th, 2022, 7:54 am

Sirius Open Source and Its Money Problem

Video download link | md5sum 998661b08883fcceda48a018ad44c466
Sirius Treats Some Tech Staff Like Peasants
Creative Commons Attribution-No Derivative Works 4.0

Summary: Shortchanging technical staff seems like common practice, but some companies push that very far; As noted last night in this meme, Sirius ‘Open Source’ really does not like this series; but it was forewarned for years already about several issues (before trying to witch-hunt the messenger), including the rights of staff and the standards of pay

THE early parts of this series explained how things were in 2011 and prior to that year. Sirius had generously (or for self-promotional purposes) given money to KDE and to the FSF. It also recruited high-calibre staff which certainly received a decent salary.

When it comes to the NOC, things were different. As we shall see and show later, NOC staff was treated as disposable; no wonder staff turnover was very high there (for a position occupied by 4 or 5 people we’ve had about 20 members of staff already). When recruitment went on the official (but internal) wiki of the company compared NOC staff to “monkeys”. For the same number of hours covered I could easily earn 5 times as much in another company, so surely I’m no “monkey”… my solace was, once upon a time we did in fact support Free/libre software. It felt like an ethical job.

The salary I received in 2011 was higher (per hour) than at the time I left, in spite of being more than 11.5 years apart. How did this happen? How many employers fail or refuse to keep up with inflation (at the very least)? Set aside promotion ladders that typically come with increments in base pay.

Either way, the company really does not want me to talk about this. Last night it sent me a letter after more than 10 days of complete silence. What did the letter say? It is described in the video above, but the impression one gets is that it’s a low-grade censorship attempt. It almost looks like the company “Sirius Open Source” is trying to ‘bribe’ us, basically saying something like (not actual quote), remove all those articles and we’ll pay you for some holidays (that we never took). Well, we’re not sellouts, we won’t stop, and the Sirius ‘UK’ CEO (pretending to be based in two continents) does not seem to grasp what he’s dealing with. Paying (shall we say ‘bribing’?) while making veiled threats is legally bad and makes the company look even worse. Better to just say nothing than send frivolous letters. For sure we’ll return to this at the end of the series, probably some time next month.

Network Operations Center by Alan Levine the from United States

Network Operations Center by Alan Levine the from United States. This file is licensed under the Creative Commons Attribution 2.0 Generic license.

Tuesday, December 13th, 2022, 2:35 am

The Time Sirius Didn’t Cover Expenses for Journeys

Sirius Open Source chat

Summary: The company Sirius ‘Open Source’ paid way below the market standards even back in 2011; incredibly enough, payment increments were discarded in spite of inflation and even travel expenses weren’t always reimbursed

THE signs that a company isn’t functioning are probably universal; one can find many stories about startups that never pay staff or always make verbal promises with delays… until they become insolent (then, recovering the stolen salary is impossible). “Wage theft” as it’s sometimes called it very common in small companies, but Sirius was never that bad. Having said that, as we shall show next month, the financial situation was dire and staff was expected to adapt accordingly. It was hard to compel people to work extra hours; some of them had already worked very strange hours under unusual conditions.

Funds of the company were increasingly redirected to wasteful things, clients were occasionally undercharged, and sometimes even the staff took the brunt of the waste. Today, as well as in tomorrow’s part, we shall revisit some examples of that, citing a report we left this month, just before leaving the company.


Financial Aspects Revisited

As noted above, the current AWS fees are extraordinary and as shall be shown later, an ordinary staff salary is almost laughable. For technical people working at hours like these, including weekends and holidays, the salary would typically be double or treble the “market standard” (which for technical people is rather high). To observe that ordinary employees of Walmart (the world’s largest employer) get paid more than someone who works around the clock, even on holidays, doing technical work, is just unbelievable. In many US states a starter salary for Walmart staff is around $30,000 and some Support Team staff at Sirius receives 21,000 British pound, i.e. only a little above minimum wage. It’s important to stress that in Sirius the management never experiences those erratic sorts of rotas, including mid-week rotations (moving between 5:30PM-1:30AM to 1:00AM-9:00AM and then back again). People at Walmart don’t work overtime or in weekends (if they do, they get paid double or more) and don’t have the same skillset. Some don’t have college/university degrees (or student debt to pay). How can Sirius justify this, especially the lack of increase in salaries, not just adjusted for level of seniority (or length of service) but also inflation? This impedes recruitment prospects. As noted earlier, it is essential to attract “new blood” for the company to remain operational, and later on it will be noted that basic equipment is not being provided either. Employees need to pay for their work equipment and more. This makes Sirius like a low-cost supplier of cheap labour. At Walmart, there is at least a chance of career progression, e.g. supervisor roles and above. Walmart employees don’t receive urgent calls when they’re out for family time away from town, asking for immediate help with some technical matters due to an incident. In Sirius, even low-paid staff was subjected to that. Even getting a holiday approved has become quite hard and sometimes approval is received only a day prior (with a substitute unsuitable to actually fulfil the job). That’s not enough time to make meaningful travel plans.

From clear recollection, the company has a track record of not paying full travel expenses to some colleagues and one may have sued the company over it, based on another colleague. In Roy’s case too, several trips to Leicester (to meet a potential client) around 2014 were never covered (train expenses totaling about 140 pounds). Despite repeated reminders from Roy and repeated assurances from the management (or no reply), Roy never received his expenses reimbursed for either of those trips. At some point Roy simply gave up pursuing that as Roy felt like it required a lot of nagging. Again, where is the accountability for it? That was 8 years ago and still overdue. If not a matter of stinginess, this is a case of gross incompetence and injustice. After about a year it became embarrassing to even bring up the subject again. It’s akin to what’s known as “wage theft” but applicable to travel (long-distance journey) expenses rather than remuneration. This was still several years before vindictive managers started manufacturing fake ‘cases’ against particular members of staff in a rather psychopathic fashion (never bothering to even apologise later, as any truly mature person would do). Habitually the company would distort what employees actually said, either on the record or off the record, to manipulate or trick people into saying things, hinged upon loaded statements or distortion thereof. This will be discussed in this document’s final section.

Monday, December 12th, 2022, 8:27 am

Almost Nothing Left of Sirius ‘Open Source’

Video download link | md5sum 9615f8b17fcd94145474e78b9654c947
Sirius as Just an Account
Creative Commons Attribution-No Derivative Works 4.0

Summary: Sirius ‘Open Source’ has turned into a virtual company; it’s just some AWS account with a bunch of people working on their personal computers (not company computers) from home; even accounting is missing in action (MIA), failing to correctly pay a salary for about a quarter and sometimes missing pension contributions — an indication of extreme negligence or gross mismanagement

THE potentially frustrating vision of “clown computing” is that all computing is centralised, even more so than in the mainframe era. Back in the golden age of mainframes the companies at least got their own mainframes, which could be maintained by locally-sourced and privately-employed staff.

Sadly, the company I left this month is almost entirely centralised — albeit not within itself but rather the opposite. There are virtually no assets left in the company, not even a server or a chair.

Monday, December 12th, 2022, 7:45 am

Births in England and Wales Down 5.2% Since Pre-Pandemic Years, Baby Deaths Down by a Similar Level

Data for this article: Baby deaths [Open Document Format]

deaths-babies-pre-and-post-covid

Hypothesis: babies born into the pandemic are equally likely to survive (but caveats exist, e.g. maybe only more affluent families still have kids and medical treatments continue to improve)

So I’ve decided to check how the pandemic affects babies, specifically people under the age of 1 in England and Wales, for which we have complete data from ONS.

Based on the available data, 2,190 children under the age of 1 died so far this year, compared to 2,322 (132 more) in 2019. Those kids might be born a year earlier, i.e. in 2021 and in 2018.

Births in 2018 were 5.2% higher than in 2021, based on the official figures. 657,076 – 624,828 = 32,248 (fewer births in 2021 than in 2018), representing a big decrease.

Old data can be found here (births in England and Wales). It says: “There were 679,106 live births in England and Wales in 2017, a decrease of 2.5% from 2016 and the lowest number of live births since 2006.”

In 2018 there was a decrease. To quote: “There were 657,076 live births in England and Wales in 2018, a decrease of 3.2% since 2017 and a 9.9% decrease since the most recent peak in 2012.”

More recent data comes from this page (also see “Births by parents’ country of birth, England and Wales: 2021″). To quote: “There were 624,828 live births in England and Wales in 2021, an increase of 1.8% from 613,936 in 2020, but still below the 2019 figure (640,370); 2021 remains in line with the long-term trend of decreasing live births seen before the coronavirus (COVID-19) pandemic.”

It also says: “There were 2,597 stillbirths in 2021, an increase of 226 from 2020; this is similar to the 2,522 stillbirths in 2019. [..]. The stillbirth rate in 2021 increased to 4.1 stillbirths per 1,000 total births compared with 3.8 in 2020; this is also higher than the rate seen before the coronavirus pandemic in 2019 (3.9).”

Based on the available data, the number of babies dying in their first year was similar in the past year to what it was before the COVID-19 outbreak. If adjusted to the total number of births, compensating for disparity and assessing the ratio.

It may be safe to conclude that babies’ mortality rate (at least here) did not worsen in recent years, unlike all the other age groups.

Monday, December 12th, 2022, 5:18 am

When Your Company is Outsourcing Almost Everything

Does/did this happen in your company too? If so, read on…

Sirius Open Source stand

Summary: Sirius ‘Open Source’ has not been keeping up with skills required to self-host, instead demonising/denouncing them as “hobbyist” (actual quote from the CEO) and eventually relaying almost everything to proprietary vendors that put gates and walls on Free software

TODAY we continue a couple of parts that deal with security and privacy issues at Sirius Open Source [sic] — a company that still says “Open Source” although it often recommends to clients that they adopt proprietary things.

Enough has been said already about the nature of the hypocrisy, the double standards, the dishonest marketing, lack of principles, and even some truly unethical clients. Below is part of the report deposited before my wife and I left the company1.


Outsourcing Concerns

Colleagues at Sirius have long worked weekends (unlike client’s staff, which is typically off work on holidays and weekends; there’s no 24/7/365 cover). Some of them finished or started working but could not access an essential gateway machine. When the client does something like an update or makes a release the IP addresses will change, so whenever there is an incident Sirius staff can’t restart, forcibly reboot or investigate the machines, that is unless — or otherwise — Sirius staff are informed (or wiki/documentation becomes up to date again). From what is known, this is more of this particular client’s choice, but Sirius lacks a loophole and that is why Sirius may seem sloppy or slow to update/notify their workers/employees.

This is a typical example of a lack of top-down coordination. How are staff expected to carry out duties if managers don’t do their part or fail to understand how these systems work? In fact, when outsourcing to any third party, this may be inevitable; the people who ‘manage’ the machines have almost no control over them. They merely rent some server space and the hypervisor may change over time, introducing unforeseen but unavoidable complication. This means server can become unavailable, with no resort at all (like accessing the datacentre/s). Back in 2011 and for several years after that Sirius had its own server racks and managed its own instances.

Sirius keeps recommending the outsourcing to proprietary software like AWS and Cloudflare, resulting (sometimes) in a lot of problems. Sirius itself pays in AWS bills almost as much as a small salary. Becoming an AWS ‘reseller’ makes Sirius far less competitive and vastly less unique; companies like these, including Rackspace, have their own support. They have their own ambitions of controlling everything themselves. Companies like Sirius should not become transient migrators. Sirius used to offer its own hosting.

This is one of many issues with “cloud computing”, including AWS, which also caused significant downtimes for that client (hours-long outages) — a client that used to have far more control over the hosting. When it comes to certification, the company actively encourages learning “cloud computing” stuff instead of “Open Source” stuff.
______
1 Many more details will be given, along with further analysis, when the whole report is published. Probably in January.

Sunday, December 11th, 2022, 4:48 pm

Pfizer Lied About Efficacy of the Vaccines It Was Selling, China Takes Different Approach

Just published: Chinese vaccine comparisons

Description:

Chinese and Western vaccines compared

https://www.bbc.co.uk/news/world-asia-china-63855508

Big changes, all of a sudden

Live with the virus

Vice-premier, Sun Chunlan

China entering a new situation

Virus ability to cause disease weakening

Lifting most severe Covid policies

End of quarantine camps

People can isolate at home

No more family separations

Close contacts not taken to camps

Strict ban on blocking fire exits

No need to show tests for venues

Less rules on internal travel

Lateral flow tests to replace PCR tests in most areas

Lockdowns continue in smaller more targeted areas

Foreign travel soon

Cases, 30,000 +

Now

Everyone will be exposed

Will the medical system will be overwhelmed?

National Health Commission

All localities, focus on improving the vaccination rate of people aged 60-79,

accelerating the vaccination rate of people aged 80 and above,

and making special arrangements

Prof Ivan Hung, Hong Kong University

The main way for China to exit Covid with the least damage is via vaccination and three doses of vaccination is a must

Hopefully before Chinese New Year (January 22) Rabbit

Sinopharm

Strategic Advisory Group of Experts on Immunization (SAGE)

https://www.who.int/news-room/feature-stories/detail/the-sinopharm-covid-19-vaccine-what-you-need-to-know

The vaccine is safe and effective for all individuals aged 18 and above.

Individuals may choose to delay vaccination for 3 months following the infection.

An inactivated vaccine with adjuvant

(that is routinely used in many other vaccines)

with a documented good safety profile, including in pregnant women.

Symptomatic SARS-CoV-2 infection and efficacy against hospitalization 79%

Does it prevent infection and transmission?

No substantive data

Does it work against new variants of SARS-
CoV-2 virus?

SAGE currently recommends using this vaccine

Not yet been evaluated in the context of circulation of widespread variants of concern.

How does this vaccine compare to other vaccines already in use?

We cannot compare the vaccines head-to-head,

(different approaches taken in designing the respective studies)

but overall, all of the vaccines that have achieved WHO Emergency Use Listing,

are highly effective in preventing severe disease and hospitalization due to COVID-19.

Comparison with Western vaccines

Pfizer original paper

https://www.nejm.org/doi/full/10.1056/NEJMoa2034577

https://www.nejm.org/doi/suppl/10.1056/NEJMoa2034577/suppl_file/nejmoa2034577_appendix.pdf

BNT162b2 was 95% effective in preventing Covid-19

Later analysis from

Efficacy and effectiveness of covid-19 vaccine – absolute vs. relative risk reduction

https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9115787/

AAR, Pfizer, during the trial period,

0.84%

AAR

https://patient.info/news-and-features/calculating-absolute-risk-and-relative-risk

Absolute risk of a disease is your risk of developing the disease over a time period.

Five to six-months update, AAR

BNT162b2 3.7%

mRNA1273 (Moderna-NIH) 4.9%

Sunday, December 11th, 2022, 5:27 am

Pay Sirius Coporation, Get GAFAM Instead

Sirius Open Source pamphlet

Summary: Sirius ‘Open Source’ has adopted shoddy practices that impede audits, undermine security, and subvert proper inspection of the network; outsourcing is not security, and “clown computing” is more like an “acceptable” security breach (giving some shady companies control over your systems and data), but that’s not something today’s Sirius ‘Open Source’ can still grasp (Intel experienced something similar when geeks left)

THE previous part spoke about a lack of real security and today we turn our attention to GAFAM-friendly policies which wrongly assume that VPN or GAFAM mean security. They don’t. VPN, like a firewall, makes false assumptions. And outsourcing assumes that some other companies are in fact security-oriented and respecting of privacy. They’re neither. Sending passwords from one’s local network (already access-restricted on several levels, namely access credentials and IP address) to something like LastPass is beyond insane. But good luck explaining that to people who worship brands instead of technology and find appeal in anything “new” (for no actual reasons other than perceived novelty).

Here is the relevant part of the report sent at the start of this month.


Band-Aid Instead of Robust Policies

Speaking of security breaches, some of the company’s Ubuntu servers are using very old — even way outdated — versions, as noted by the company itself (it’s also controlled by a host in another country, which poses another attack surface issue).

Security isn’t taken seriously enough and VPN is presented as ad hoc Band-Aid. VPN is not the solution, it’s a hallmark or a symptom of neglect at the intranet (internal) level. Firewalling and restrictions, for instance, have unusual exceptions. Since “Google is your friend”, for instance, Google IP addresses are allowed. As if Google never spies or collaborates with spy agencies (or even suffers security breaches). So Sirius VPN does not trust BBC network, but does trust (or whitelists) Google/Alphabet.

The neglect extends outwards, i.e. outside internal infrastructure of Sirius. For instance, in the past some staff transmitted in plain text messages (via E-mails) with passwords to accounts and servers of a very large client that is the target of foreign operations and aggressive spies (political espionage operations of this type are very common with clients such as these).

There are even very recent examples, so there’s no need to go far back; a colleague who is close to management dared suggest — only months ago — that an entire political Web site (including user details, passwords etc.) be migrated by dumping a lot of data into Google Drive, without any encryption either, clearly not comprehending that “Google is your friend” is a laughable fallacy (an understatement; Google is legally obligated, through US Clarifying Lawful Overseas Use of Data Act or CLOUD Act 2018, to give full access to the US government and more).

It wouldn’t be controversial to state that such practices can be off-putting to clients, e.g. when decision makers in Sirius have rather poor grasp or appreciation for privacy and security, let alone critical care by introspection (staff cautioning about this is subjected to gaslighting at best or even outright threats).

If Sirius views itself as a champion of “Alexa” and “OK Google”, then the company should seriously consider a rebrand.

Real-time Posts

Posts by @schestowitz

Retrieval statistics: 23 queries taking a total of 0.090 seconds • Please report low bandwidth using the feedback form
Original styles created by Ian Main (all acknowledgements) • PHP scripts and styles later modified by Roy Schestowitz • Help yourself to a GPL'd copy
|— Proudly powered by W o r d P r e s s — based on a heavily-hacked version 1.2.1 (Mingus) installation —|