2015-01-15

Meta spam

FFS, just got junk mail trying to sell me a course on junk mailing people, with things like "What the legal implications really are" as the first key point in the agenda!

I think this one will get a notice in the post as well as email this time.

The same bunch sent emails before so have had the standard email reply from me - that zaps any excuse of having taken reasonable measures to avoid breaking the law as they actually knew my email address was that of an individual subscriber when they sent this one. In fact they have emailed 9 times since July 2013 and had my standard reply each time. I hope they agree to settle, as I'll then use that as basis for claims for the previous 8 times.

Update: Grrr. Letter sent but it is a mailing address in London and nothing on the email or web site actually says who they are as a legal entity. So, for now, reported to trading standards for that.

Update: Arrrg, Trading Standards web site says the trading standards email address for Westminster, but the email address does not work and bounces. So I have ended up writing to trading standards. This means I have spent an hour today, two letters with attachments, one of which is recorded delivery, two emails. Is it any wonder I am asking for £200 for this spam in the first place?!

Update: I did think of registering for the course, and then cancelling for a refund. They say they allow a refund up to 14 days before the course. That would allow me to follow the money to work out who they are. But, of course, none of the courses they list are for which I can book are more than 14 days in the future! It is tempting to book someone on a course and send with hidden camera though.

2015-01-14

Keeping secrets

Cameron has raised awareness of privacy, the Streisand effect at work. If certain apps are banned, the criminals will know exactly which apps are safe to use. So I am working out what we can do to help customers that are concerned over security.

Andrews & Arnold and PGP

A&A have always supported use of PGP/GPG and customers can (and do) send encrypted emails. We sign emails we send from the accounts system. Staff have GPG installed and have keys signed by the company key which I control. Sadly few customers use this, and so staff are perhaps less on-the-ball than they could be, but we are working on improving that too.

I think we can do more though. What I am trying to work on now is a way for customers to tell us that they want encrypted emails from us. We would use the https access to the accounts system to manage this which has some degree of traceable trust but it would mean uploading a public key to us (or perhaps referencing a key server). We'd need to make this simple, and perhaps even have an API, as some people may wish to issue new keys every day and delete old ones in order to thwart the RIPA requirement to hand over keys if you have them.

The challenge I then face is how we manage that preference as we have various systems that send emails as well as staff that could send emails directly. We would need some way for every system to know to use encryption and which key to use. Now, for staff sending emails we can almost certainly integrate this in with the ticketing system as a "direct" email is relatively rare, but that is not ideal. I suspect that it will take some time to ensure every system and every script that sends emails understands this, unless we run an intermediate outgoing mail server for it.

I am interested in the best practice way of managing this though. I am sure this cannot be an uncommon problem. Should we run a key server? Should we put keys in shared SQL databases? We are only talking public keys so not a huge security issue. Maybe some combination of the two. Any advice welcome.

FireBrick and IPsec

The FireBrick products already support IPsec, and any day now we expect to have the EAP elements that will allow things like iPhones and Androids to remote connect to a FireBrick and allow VPN access to your office, etc. Once that is done we will progress on to TL, https and ssh, obviously.

One of the key features of the FireBrick, and one of the main reasons it has taken so long to get these features in place, is that this is written from scratch.*

What this means is that we know there are no back doors in the code. Almost any small router that does https or even IPsec has bought in the code or used open source. It is large and complex and may even be a "binary blob" so it is hard to be sure that it has no back doors. Open source is generally safer as it can be reviewed, and people do, but how do you know the code you downloaded is that reviewed and correct code exactly unless you check it yourself? Well, in our case, we know because it has been written in-house. There is not even a third party operating system below it, we wrote that too. We even use a processor with no hidden boot ROM code and no binary blob device drivers for peripherals (both of which are quite common these days in some types of processor). We even make the FireBricks in the UK and load the code in to them ourselves. All code is signed by us, and our boot loader checks the signature to ensure no rogue code can be issued with back doors added.**

I think it is incredibly rare for any manufacturer to be able to say that. And if some UK law is passed that could compel us to add back doors we would stop.***

Even so, suggestions welcome.

* Some of you may have heard the long standing truth that one should never try and design an encryption system yourself or behind closed doors. They have to be one subject to wide scrutiny to be any good. This is true, but is not the same an implementing these algorithms, which can be done behind closed doors, and the standards provide lots of good test data for doing just that.

** Technically, with physical access and a JTAG interface someone could load other code, but that is highly unlikely and would require that physical access to the FireBrick.

*** In practice we would probably set up in a saner country and make and ship from there, or possibly just emigrate there as the UK really would have lost the plot by then.

2015-01-12

Sorry David Cameron but we have a right to privacy!

David Cameron stating that we cannot allow a means of communications where the government cannot read that communication. [video]

Sorry, but no! This is not acceptable.

His statement is reported as relating to snapchat, but how would he make it so that all communications can be read by the government? If I access a bank that is not in the UK using https then this government cannot read that, which is as it should be.

He would have to ban encryption to achieve what he is saying and that is madness.

1. There are means which can be used to communicate in a way which cannot be read by the government, or anyone else - that is a fact and no amount of laws will change that fact. This is called encryption. Encryption is used every day by most people - Facebook defaults to using encryption, and of course on-line banking uses it.

2. There are means which can be used to communicate where it cannot be proved that any additional message exists if you of not have the key. This is called steganography. It means that one can send private message with no way to prove that you have done so, and so no way to prove you have broken some "no encryption" law.

Making laws against private communications is totally pointless as it does not stop private communications between criminals or suspects. What it does do is impact otherwise law abiding citizens and commerce and our right to a private life.

This issue surrounding David Cameron's statement that he believes that the government should be able to see/hear/read any communication in this country if necessary. He does go on about "in extremis" and how this needs to be signed off by Home Secretary, but even with the controls he mentions, in order to do this he needs it to be technically possible.

Think about that for a second - it means laws in the UK that make it possible for communication between two people to be listened in to by a third party even if those two people do not want that to happen. For the warrant from the Home Secretary to work, that has to be technically possible in the first place for all communication in the UK!

That is a huge thing to say - because if it is technically possible for the government to "listen in" then it is technically possible for criminals and terrorists to do so. What ever the legislation is, its job is to weaken what we do to the extent that the government can snoop. That means is possible, and those criminals will not need a sign off from the Home Secretary. That sort of change would make Britain a laughing stock and ensure nobody does anything sensitive with the UK. Indeed, it is hard to say how such weakening of communications could be consistent to Data Protection laws. In fact, it would mean NO COMPANY DEALING WITH UK CUSTOMERS COULD TAKE CREDIT CARDS ON-LINE as such weakened communications would be against the strict rules imposed and enforced by the card companies.

I have not actually read 1984, but is David Cameron quoting from it?

If you take what he has said literally it would mean whispering to your partner in bed would be illegal in case the government planted microphone could not pick up what you said.

Getting started with PGP.

Remember, Mr Cameron, you work for us, not the other way around. This sort of rhetoric shows you have no clue about basic rights or technology and really should not be running anything.

Update: Loads of responses on twitter along the lines of "Already UK law in RIPA, you have to hand over keys". ONLY IF YOU HAVE THE KEY! That does not help for transient keys. I mean, if you are asked to hand over the transient https key used on your last access to FaceBook so they can decode the TCP traffic they captured - you cannot. Similarly, I can simply make a key, send the public key to someone, receive from them a message, read it, and delete it and the key, then nothing to hand over. I think some chat apps do that inherently with transient keys in memory only, deleted after reading. It is not complex technology and perfectly legal not to have the key - only illegal not to hand it over on demand if you do have it.

Update: Another good blog post on this [Steve's blog].

Update: I have written to my [Conservative] MP.

2015-01-10

Paying to a charity to settle a claim?

This is one on which I am really interested in feedback. I hope people appreciate that some of my blogs I do not even think I have all of the answers and am keen to learn what others think...

The background is simple, I have sued a spammer under The Privacy and Electronic Communications (EC Directive) Regulations 2003, as you do. I sued for £200, as per my normal notice of action emails. This is an interesting one as we are pretty sure the guy called my email provider (not A&A) to suggest someone was using his domain for a scam, and claiming that my email was a known scam, all over the Internet! I think I blogged on it. But I cannot be 100% sure it was him, as I emailed more than one spammer that day, and he refused to identify himself on the call. This is one to which I did get an email reply though, and oddly he stated two things (a) that he bought a mailing list (which confirms that I did not give him permission to send the email, and so not a good thing to have admitted), and (b) that he has insurance for this (odd, and suggests he knows that what he is doing may incur charges for which he should be insured!).

Anyway, simple matter, county court claim, and out of the blue he responds by email to me as a without prejudice negotiation.

He offered to settle, with no admission of guilt, by paying £100 to NSPCC.

I replied pointing out that if I did not feel I had suffered damages then the claim would have been invalid anyway. This is not punitive as that is not allowed for county court claims or the PECR. I am happy to negotiate the level of damages as most are "intangible" losses to me, and would accept £100 (plus my £25 court fees) as settlement, but that paying to a charity makes no sense to settle my damages claim.

He then replies, with a screen shot, to confirm he has paid £125 to NSPCC. I did reply explaining that doing such was silly. He says he will defend the claim. Yay!

Now this is what I do not get. I have seen this a couple of times before - some claim or some debt - I think we have even had people A&A are chasing for a debt say this, that someone would pay to a charity rather than to "me" as a means to "settle" the claim!

I really do not understand this. What am I missing here?

How could paying money to a third party (charity or whatever) be a sensible "offer" in any way to settle a claim for damages?

Update: 16th Jan

He has filed a defence, which predictably says he bought a list that was meant to be opt in, etc... Nothing surprising there, but what is odd is that he says he offered to pay £100 to NSPCC, that I refused and said I wanted £125 paid to me (as I did), that we did not agree, and that he has now paid £125 to NSPCC. I was going to use that, and thought I could not as without prejudice negotiations, so he has made my life a lot easier now!

What is also odd is that he has said no to a mediation call and written "I HAVE MADE AN OFFER". That seems odd, as you would expect that to mean a mediation call is a good idea.

I have written to the court stating that I accept the amount offered and that I would simply like an order to pay *me* the amount offered (£100) to settle the claim. We'll see what happens.

The defence is a tad funny as it states "I believe that [defendant] have shown due diligence and a commitment to abide by the rules of Electronic communications in order try and to grow their business. Therefore I feel Additional Resources Ltd should be protected from this claim by section22 (3) of The privacy and Electronic Communications (EC Directive) Regulation 2003", well 22(3) is nothing to do with "due diligence", it starts "that person has obtained the contact details of the recipient of that electronic mail in the course of the sale or negotiations for the sale of a product or service to that recipient" which simply is not the case and not something he has claimed, so 22(3) simply does not apply.

This should be fun if we go to court. I have the facts clear that I am an individual subscriber (I have an invoice for the email in my name). I have the admission that he bought in my details rather than got than as part of a sale/negotiation (so 22(3) does not apply). He is clearly in breach, leaving only the amount as the problem area, and for that I have the figure he has placed on this (£100) which I am happy to accept.

2015-01-09

Unethical?

So a business customer pays late and we charge late payment penalties. It happens. In fact we have a policy to credit the first instance in the interests of good will, but it makes "paying on time" more important.

But today I have someone getting all stroppy, but in a new way. I may have to update my list of excuses on www.paylate.co.uk.

He started with a rant over the dates - the invoice was for service 1st Dec to 31st Dec but on payment terms of 7 working days (which we extended to allow for a DD on or after 25th). But that makes it advance payment and so he says it is unlawful for us to charge the penalties.

He then goes on to say he will be publishing this so that others can see we are acting unlawfully and can try and reclaim any penalties we have charged!

This all looks like some attempt to intimidate us. As it happens, my accounts team credited the charge anyway as it was the first time, but he is still ranting and saying he is going to publish about our unlawful activity.

So I squashed what he was saying totally. The legislation is quite clear, if we are charging in advance, e.g. services 1st to 31st Dec due on 25th Dec, the the relevant date is when we have completed providing the service, and penalties and interest start from the following day, so 1st Jan. It is all very clear, and surprisingly fair - statutory penalties only apply if paying after agreed term and after the service are actually supplied. The catch is that he paid on 5th Jan!

So, he has one possible excuse in the bag, and changes his rant to that - instead of claiming we broke the rules in the legislation (as we clearly didn't) he is saying that because he pays by DD, we have agreed to collect the money, and we could have as we notified him on the 29th. Looking at it, it looks like it may have been possible to get a DD in sooner - but the banking system needs two banking days, and there are rules on not giving the agreed notice (in our case 5 working days) so in practice it was 5 days and hence 5th Jan. The thing is we make it clear in our terms we are offering to try one collection only within terms, and if that fails it is the customers responsibility to ensure payment is made within terms. The customer even states that we told him on 29th and he could have made a fast payment if we had sent a request for payment - well the invoice sent on the 1st Dec was a request for payment, D'Uh.

Just to clarify - the terms were 7 working days from invoice, which we extended to his preferred date of 25th, and extended to allow for 25th and 26th being bank holidays, and then allowed the time to the end of the month as was billing in advance, so about 3 levels of "grace period" over the agreed terms, all of which were missed.

It is also worth clarifying the DD thing - we only offer to try and collect once. In practice, if someone is not insisting on DD being 25th (or later) we collect on due date, or for people on end of month we collect enough working days before to try and make a second collection. So in most cases that would work. In this case, being December and insisting on 25th collection, we did not have practical time to get a second DD done, but the customer did have time to send a fast payment on there separate days and confirmed they were notified of the DD bounce, but chose not to send payment.

Edit: To clarify further, our response to his initial rant was a credit, but he went on - he said that as we had not responded to his "legal analysis" he would publish anyway, so he asked for my response, which I gave and quashed his argument, and then he went on the "unethical" argument. This is a massive sore loser!

Anyway, long story short, what really bugs me now is that he says "this is not corporate behaviour that meets the ethical standards that we require of our suppliers".

To me that is so hypocritical and just takes the piss... What did they do that is perhaps "unethical"?
  • Apparently they don't have enough money to pay the £23.90 on the agreed and notified date (this is a limited company, and makes me question their creditworthiness somewhat!)
  • Don't send payment when notified of the failure
  • Try and suggest that we acted unlawfully and quote sections of legislations to try and legal/baffle us.
  • Suggest that this unlawful behaviour will be published to get others to reclaim penalties
  • Then, when proved wrong, start suggesting we failed by not collecting a second DD (something we never said we would)
What did we do?
  • Provide service, as agreed
  • Make a DD attempt, as agreed, on agreed date with agreed notice
  • Advise them of the payment failure in time for them to pay and not get a penalty
  • Charge a penalty, as agreed in the terms, and carefully following the legislation
  • Refund the penalty, no questions asked, as a good will gesture
Maybe I simply don't understand "ethics". All I ask for any supplier or customer in a business to business relationship is to do what was agreed - nothing more.

In practice, being such an edge case, we'd have credited this even if it was not the first failure. It is rare to have a late payment penalty for a DD paying customer and requires a complicated set of circumstances and bank holidays and a bounced payment, but not something we did wrong.

Update: Lots of discussion here and on irc, and one thing I can see where we could make one small change that would have helped in this case. Basically this is an edge case where a second DD would not be soon enough. The notice saying the DD failed and when we would collect again gave the wrong impression that "nothing needs to be done". So the change I am planning to work on is that we should never send a "Your DD failed, another is being done on date X" if that date would be too late but paying now by fast payment would be OK. We should be sending "Your DD failed, and we don't have time to do another DD, so please ensure payment by fast payment before date X". Obviously if nothing happens and a penalty is issued and we have over due payments we then do normal DD notice then to collect the balance due. Such notices should be rare as we do normally have time for the second DD attempt.

Update: We have checked, and the timescale of 5 working days for a repeat collection, which in this case did not allow enough time to avoid penalties, is based on BACS recommendations. Thankfully the rules permit two working days and our system can accommodate this, so we have made changes to use 2 working days when 5 would go over the end of the month. Not quite as generic a fix as I would like but something to tackle this edge case, even though we did not guarantee to make a second collection in the terms.

2015-01-07

Reducing carbon emissions?

I could do a blog on global warming climate change, but I would have to do a lot of research as there appears to be a thick layer of hype and politics between the science and what we see on the media, so let's not do that now. What does seem sensible is making things efficient anyway.

As such, it is not a surprise to see an article on Talk Talk reducing their carbon emissions.

I did wonder what people would think of A&A though. It is actually quite hard for us to say we are reducing carbon emissions, mainly because we have always had an attitude of being quite efficient long before it was trendy.

So here are a few things that we do...
  • Our offices (as of about a year ago) have nice efficient LED lighting where lights are on all day. We plan to cover all of the lights eventually.
  • We already have a cycle rack and company bikes for those that want to use them.
  • Office PCs that would not otherwise do so are set to hibernate over night.
  • We already use heat pump / air-con for heating, so over 100% efficiency.
  • We have always sent invoices and statements by email rather than paper.
  • In our core network we use what is probably the lowest power routers available, the FireBrick FB6000 series that handle a gigabit of customer traffic in 0.1A.
  • Some staff work from home where possible to reduce travelling.
Obviously, if we do find more ways to improve efficiency whilst still providing the quality of service, we will consider those, but we are pretty good already. So you are unlikely to see news items about how we have made massive reductions - as doing so is admitting you were massively inefficient before. Suggestions welcome.

2015-01-02

Nuts on a plane

There have been a few articles recently on the behaviour of people on planes. The main ones that come to mind are issues over people putting the seat back and resulting arguments with the person behind, and more recently an article on ultra orthodox jewish men delaying a flight because they cannot sit next to a woman.

So, this got me thinking on what is "acceptable", both on planes and in society in general. As usual this meant a few odd nights composing a blog post in my sleep, and finding, rather annoyingly, that I still have to type the damn thing in the morning.

Freedom of faith

We live in a multicultural society, which means we have people with different faiths interacting with each other, and somehow we want society to continue to work. This is tricky.

Obviously, I could simply take a pop at any religion and pull it to pieces, but let's assume for the moment that it is "human nature" for people to believe stuff like this and there is not a lot we can do about that. Can we come up with rules that allow society to work but also allow some freedom or faith. Can we create impartial rules? Can we decide where to draw lines?

Obviously this is just my rambling views on this, but here goes...

Should we allow people to believe what they like?

Well, in general, I would say yes. As I say, there is human nature, and we cannot do much about it. If you try to ban people thinking in a certain way, they'll do it anyway. However, even this has to have some caveats. As a society we recognise that some people are vulnerable. This may be young people, or people that are stressed, perhaps after the death of a lost one, or people who lack normal emotional maturity. As a general rule we, as a society, want to protect such people and would not want people to get sucked in to some extreme cult any more than falling for some scam artist. It is, however, very difficult to draw any lines here - when is a "cult" an unacceptable scam, rather than a religion?

Believe what you like, in your own head.

I would say that we should not have any sort of "thought police". People with the mental capacity to make up their own minds should be able to believe what they like where it really has no impact on other people. And there is no reason not to allow such people to meet up and discuss things themselves.

Selling religion to others?

One of the things I dislike, but which is inherent in any established religion, is the way that the religion gets sold to others. That the religion tries to encourage others in to the belief. Some are worse than others, and some even go door to door with leaflets!

Personally, I would like to see religion controlled in the same way as any other business. I would like to see adverts subject to the same scrutiny. Saying "you will live on forever in heaven" is not acceptable as an advert, surely. Otherwise, what is to stop me selling broadband with a "guaranteed place in heaven for all customers". How is that different?

That said, there are organised religions that offer a lot of things, and they could advertise those. They offer a social group, with venues and events to allow people to meet and talk to like minded individuals. They offer "make you feel better that your life seems to have a purpose" even. They might organise social and charitable events and carry out community projects. These are all good things that I would have no trouble being advertised and encouraged.

Silly clothes?

Of course, saying people can do what they like as long as it does not affect others, has some issues. Silly clothes is one. I have no trouble with someone dressed up as Captain Kirk all day, but if a religion said you had to be naked at all times, we, as a society, would not find that acceptable. What if you had to cover your face such that you cannot be identified - OK mostly, but what of using a bank or passport check in airport? What if your religion says you have to wear your hair such that you cannot wear a motorcycle helmet? How far do you allow things?

Diet?

Restricted diets in one of those areas that always struck me as odd. Thankfully the issues are almost totally addressed by market forces - if enough people want food a certain way then food vendors cater (literally) for them.

At one end you have people with allergies, where the wrong food can cause serious and even life threatening reactions. We even have laws on food labelling because of this.

But there are also likes and dislikes. I am sure a lot of this comes down to what you are fed as a child - which makes sense - your parents having learned the hard way what is safe to eat, you learn to "like" that food. However I expect some is down to genetics - a group of people that dislike something that happens to be poisenous survive better. However it happens, it is not easy to change. I like marmite but some people do not, and force feeding them will not change their views on the matter.

In some ways restaurants and food providers cater for different tastes, offering a menu. But they are really not so good when asking about details "does this have mushrooms in it, as I don't like mushrooms" often does not work well.

Then we have choices of diet - whether "on a diet", or choosing to be vegetarian. It amazes me how much more catered for vegetarians are than people that like or dislike some foods.

But then you get in to faith based dietary requirements, and it gets complicated. Not just a matter of not eating certain things, perhaps at certain times of year, but rules on how things are prepared or how animals were killed.

As I say, fortunately market forces do handle this - there is a lot of choice of food, usually. Though planes are a slight issue, you can take your own food easily.

Planes...

Well, this is where it gets messy.

Planes have to be one of the worse cases of trying to make a multi-cultural society fit together - you are literally crammed in to a small space with no choice but to be so close that you cannot avoid contact. They are quite horrid - topped maybe by rush hour on the underground, but without the shortness of trip or option to get out!

I was amazed how much debate a recent discussion started simply on seat backs. If I pay for a place on a seat on a plane I surely have the right to use the features of that seat, including, if it does it, reclining the seat a bit to make it easier to sleep. I have been in the position of someone getting cross with me over this and I pointed out that I paid for extra leg room (exit row) and he chose not too - his choice to be packed in so much and he should live with that choice. It was not a very fair thing for me to say, but it did end the argument. There have been reports of much more serious arguments over such things. Some people have very opposite views that it is inconsiderate in the extreme to recline the seat. My real argument here is that the airlines pack people in too tightly, end of story. The people put on the spot are not to blame.

But then we get to the orthodox jewish men that cannot touch a woman unless married so refuse to be seated next to a woman - delaying the flight until other passengers agree to move around.

One of the interesting outcomes of such a debate was the idea that the airlines should be more accommodating - not just asking about special dietary requirements but also special seating requirements. They could then put people in seats that are compatible.

  • Allow people to pay for an exit row seat for more legroom, as some do now
  • Allow people to say if they are orthodox jewish men that cannot sit next to a woman
  • Allow people to say that they must not be sat next to a fat person
  • Allow people to say that they must not be sat next to a black person
Ooops - that escalated quickly - there is a (no doubt made up) story of a woman that complains that she must not be sat next to a black person, and the flight attendant manages to arrange an upgrade ... for the black person - because nobody should be forced to sit next to a bigot.

How is insisting on not being next to a black man any different to insisting to not being next to a woman? Why would we allow it because it is someone's faith. Apparently it is also not allowed for them to flay over a cemetery, but should that mean they can dictate the flight path?

Can I start a religion that does not allow me to have things touching my knees? That way I could always be sure of an exit row seat and leg room?

We had another interesting report of someone that was allergic to nuts and the plane staff announce nobody is to have any nut based food (closed air circulation, and all that). That actually happened on a flight I was on - where we had not booked a meal and had (you can guess!) peanuts, a snickers bar and peanut M&Ms as snacks to eat on the plane, and me going hypo. Thankfully we found some crisps. There have been reports of such a case where someone ignored the warning, caused a reaction, and he was banned from flying (ever!). Now, if banning someone from flying is actually a valid and acceptable option I could argue that banning the person with the allergy actually reduces the inconvenience to passengers as a whole. I know that is not the PC thing to say but it is the maximum passenger benefit equation. Of course, the argument is that the person with the allergy cannot help it - a valid argument. I do wonder if "stressed at being packing in a tin can for 8 hours" would ever count as a disability and mean the guy with the nuts "could not help it" either.

I do wonder if there are conditions which really are incompatible for people packed on the same plane. The nut allergy is not quite one, as people could simply avoid nuts, but what if there are cases where you simply cannot put two people on the same plane for 8 hours without some issue which neither of then can help? Who wins? Who gets kicked off the flight and who stays, and how do you decide.

At the end of the day religion is a choice, as it getting on a plane and subjecting yourself you a set of rules that are unpleasant. My overall view here is that, unless you are prepared for the indignity and inconvenience of a flight, then don't take one. Or pay for better seats. Don't force others to accommodate you. This is not denying your faith - you have a choice to fly or not - make that choice in accordance with your faith. Am I wrong?

Dodecahedron

I was shown a dodecahedron with LEDs inside. Looked great, so decided to have a go. The principle is not that hard - a PCB strip on the insi...