Mar 222012
 

You know anyone would think the media isn’t capable of adding up to more than 10 without taking their socks off given all the fuss about the so-called “granny tax”. By which they mean the gradual elimination of the increased tax allowance that older people get once the increased personal allowance reaches that level.

Either the complaint is that pensioners are paying the same level of tax as working people, or that the tax allowance for pensioners is not going to go up by the level of inflation for a couple of years. Neither are exactly catastrophic for pensioners – the poorest pensioners are not going to reach that level of income anyway, and those that will be effected will hardly notice the difference.

After all there is no guarantee that the tax personal allowance will increase by the level of inflation every year … neither the normal personal allowance nor the “bonus” allowances that older people get on top of their personal allowance. And why should older people get a special taxation allowance merely for being older ?

Eliminating that special case will make the taxation system just a little bit simpler – something to be encouraged.

I’m more likely than most to throw rocks at the Tories and their policies, but I don’t see this as being worth picking up a rock for. There’s quite a few other things about the recent budget to get excited about.

Like reducing the income tax rate for the wealthy from 50% to 45%; whilst the Tories are quite possibly right about it not being a great revenue raiser, it sends out the message that the Tories are on the side of the wealthy. Whilst they have also done a bit of tinkering with tax avoidance, and added a top rate of stamp duty (on residential property purchases), reducing the income tax rate for the top earners feels wrong.

So why is the media making more fuss about the non-issue that is the “granny tax” ? Someone more suspicious than me might suspect that the media is deliberately drawing attention away from the income tax issue – just how much do these journalists earn anyway ?

Mar 202012
 

This is from last week’s day off … which was the one day of the week when the fog was almost entirely solid from beginning to end. Almost but not quite – there was about 5 minutes worth of sun on the train back. But there again, sometimes not so great weather results in sometimes not quite so poor photos …

#1: Flying Over The Fog

Flying Over The Fog

Those distant black blobs in the sky are actually birds – this needs to be seen large.

#2: The Gate

The Gate

#3: Paths Meet

The Paths Meet

Mar 172012
 

This is at least partially an appeal for information – if anyone knows of a web application scanner that does what I describe here, please let me know!

All the web application scanners I have come across so far seem to only try “online” scanning where the work is done by connecting to a web server using the same method as someone with a web browser would use. Or in other words the scanning tools replicate what an attacker might do. Hardly the wrong thing to do – it is probably the best method given that so much can only be determined by going through the web server.

In addition, there are also tools to scan the source code of web applications that you have written yourself. These pick out bits of the application that could do with looking at. Fair enough for a web developer, but I’m after something a bit different.

What I want is a tool that will when given the directory containing the website, will go through it looking for weaknesses like the following :-

  1. Look for problems with the permissions – such as directories and files writeable by the web server owner.
  2. Look for common applications and components – such as WordPress – and identify them, and indicate whether they’re out of date or not.
  3. Look for signs of exploits – PHP ‘shells’ and the like.
  4. Look for content that isn’t linked to as an indication that it shouldn’t be present.

Of course most people could think of a few more things to add to that list! It would be a handy additional source of information when it comes to securing a website.