Feed slashdot Slashdot

Favorite IconSlashdot

Link https://slashdot.org/
Feed https://rss.slashdot.org/Slashdot/slashdotMain
Copyright Copyright Slashdot Media. All Rights Reserved.
Updated 2025-04-21 08:33
US Government Expands Sanctions Against Spyware Maker Intellexa
The U.S. government said Monday that it has issued fresh financial sanctions against five individuals and a corporate entity associated with spyware-making consortium Intellexa, months after the government sanctioned its founder. From a report: In its latest statement, the U.S. Treasury said it sanctioned the five people, including senior Intellexa executives and associates, who are alleged to be involved in the sale of Intellexa's phone spyware, dubbed Predator, to authoritarian governments. Predator can be used to hack into fully patched phones nearly invisibly, allowing the organization that deployed the spyware to obtain complete access to the target's device, including their private messages and real-time location. The Treasury said the spyware has been used to target U.S. government officials, journalists, and opposition politicians. The sanctions include Felix Bitzios, who owns an Intellexa consortium company that the Treasury says was used to supply Predator spyware to an unnamed foreign government; Merom Harpaz and Panagiota Karaoli, who hold senior positions in Intellexa's corporate structure, according to the Treasury; and Andrea Nicola Constantino Hermes Gambazzi, who the Treasury says was involved in processing transactions for companies within Intellexa's consortium. The Treasury added that the Aliada Group, a company based in the British Virgin Islands and a member of the Intellexa group of companies, was also sanctioned for enabling tens of millions of dollars in transactions for the spyware-making consortium. A senior U.S. government official told reporters during a background call on Monday that the latest round of sanctions were part of the government's ongoing effort to target the commercial spyware industry. The U.S. official said the government was tracking money flows and movements to determine what entities might be trying to avoid or circumvent the sanctions.Read more of this story at Slashdot.
AI Pioneers Call for Protections Against 'Catastrophic Risks'
AI pioneers have issued a stark warning about the technology's potential risks, calling for urgent global oversight. At a recent meeting in Venice, scientists from around the world discussed the need for a coordinated international response to AI safety concerns. The group proposed establishing national AI safety authorities to monitor and register AI systems, which would collaborate to define red flags such as self-replication or intentional deception capabilities. The report adds: Scientists from the United States, China, Britain, Singapore, Canada and elsewhere signed the statement. Among the signatories was Yoshua Bengio, whose work is so often cited that he is called one of the godfathers of the field. There was Andrew Yao, whose course at Tsinghua University in Beijing has minted the founders of many of China's top tech companies. Geoffrey Hinton, a pioneering scientist who spent a decade at Google, participated remotely. All three are winners of the Turing Award, the equivalent of the Nobel Prize for computing. The group also included scientists from several of China's leading A.I. research institutions, some of which are state-funded and advise the government. A few former government officials joined, including Fu Ying, who had been a Chinese foreign ministry official and diplomat, and Mary Robinson, the former president of Ireland. Earlier this year, the group met in Beijing, where they briefed senior Chinese government officials on their discussion.Read more of this story at Slashdot.
Linux Kernel 6.11 is Out
Linux creator Linus Torvalds has released version 6.11 of the open-source operating system kernel. The new release, while not considered major by Torvalds, introduces several notable improvements for AMD hardware users and Arch Linux developers. ZDNet: This latest version introduces several enhancements, particularly for AMD hardware users, while offering broader system improvements and new capabilities. These include:RDNA4 Graphics Support: The kernel now includes baseline support for AMD's upcoming RDNA4 graphics architecture. This early integration bodes well for future AMD GPU releases, ensuring Linux users have day-one support.Core Performance Boost: The AMD P-State driver now includes handling for AMD Core Performance Boost. This driver gives AMD Core users more granular control over turbo and boost frequency ranges.Fast Collaborative Processor Performance Control (CPPC) Support: Overclockers who want the most power possible from their computers will be happy with this improvement to the AMD P-State driver. This feature enhances power efficiency on recent Ryzen (Zen 4) mobile processors. This can improve performance by 2-6% without increasing power consumption.AES-GCM Crypto Performance: AMD and Intel CPUs benefit from significantly faster AES-GCM encryption and decryption processing, up to 160% faster than previous versions.Read more of this story at Slashdot.
Amazon CEO Tells Employees To Return To Office Five Days a Week
Amazon is instructing corporate staffers to spend five days a week in the office, CEO Andy Jassy wrote in a memo on Monday. From a report: The decision marks a significant shift from Amazon's earlier return-to-work stance, which required corporate workers to be in the office at least three days a week. Now, the company is giving employees until Jan. 2 to start adhering to the new policy. Corporate employees will be expected to be in the office five days a week "outside of extenuating circumstances" or unless they've been granted an exception by their organization's S-team leader, Jassy said, referring to the close-knit group of executives that report to Amazon's CEO. "Before the pandemic, it was not a given that folks could work remotely two days a week, and that will also be true moving forward -- our expectation is that people will be in the office outside of extenuating circumstances," Jassy said. Amazon also plans to simplify its corporate structure by having fewer managers in order to "remove layers and flatten organizations," Jassy said. Each S-team organization will be expected to increase the ratio of individual contributors to managers by at least 15% by the end of the first quarter of 2025, he said. Individual contributors refers to employees who typically don't manage other staffers. It's unclear if the change will result in the elimination of some manager positions.Read more of this story at Slashdot.
How Intel Lost the Sony PlayStation Business
Intel lost a bid to design and manufacture Sony's PlayStation 6 chip in 2022, dealing a blow to its contract manufacturing business. The contract, worth potentially billions in revenue, went to rival AMD after Intel failed to agree on pricing with Sony, Reuters reported Monday. Discussions between the companies spanned months and involved top executives. Intel's loss has hampered CEO Pat Gelsinger's turnaround strategy, which hinges on expanding the company's foundry operations. The PlayStation deal would have provided steady business for Intel's struggling manufacturing arm, which reported $7 billion in operating losses last quarter. Sony's need for backwards compatibility with older PlayStation models complicated Intel's bid, as AMD designed chips for previous console generations, the report adds. Further reading:Intel Foundry Achieves Major Milestones;Intel Weighs Options Including Foundry Split To Stem Losses:Intel's Money Woes Throw Biden Team's Chip Strategy Into Turmoil.Read more of this story at Slashdot.
Nobel Prize-Winner Tallies Two More Retractions, Bringing Total To 13
Retraction Watch: A Nobel prize-winning genetics researcher has retracted two more papers, bringing his total to 13. Gregg Semenza, a professor of genetic medicine and director of the vascular program at Johns Hopkins' Institute for Cell Engineering in Baltimore, shared the 2019 Nobel prize in physiology or medicine for "discoveries of how cells sense and adapt to oxygen availability." Since pseudonymous sleuth Claire Francis and others began using PubPeer to point out potential duplicated or manipulated images in Semenza's work in 2019, the researcher has retracted 12 papers. A previous retraction from 2011 for a paper co-authored with Naoki Mori -- who with 31 retractions sits at No. 25 on our leaderboard -- brings the total to 13.Read more of this story at Slashdot.
Apple Charging 20% More To Replace Batteries in iPhone 16 Pro Models
Apple has increased its out-of-warranty battery replacement fee for iPhone 16 Pro models. From a report: Apple Stores can replace the battery inside an iPhone 16 Pro or iPhone 16 Pro Max for $119 in the U.S., which is up from $99 for the iPhone 15 Pro and iPhone 15 Pro Max. This is a 20% increase to the fee, which includes the cost of a new battery and service by an Apple Store. The fee may vary at third-party Apple Authorized Service Providers. The fee remains $99 for the standard iPhone 16 and iPhone 16 Plus. Customers with AppleCare+ can still get an iPhone 16 Pro battery replaced for free, but only if the battery retains less than 80% of its original capacity. Apple says all four iPhone 16 models are equipped with larger batteries, and all of the devices received an internal redesign for improved heat dissipation, according to the company. A metal enclosure was rumored for at least some iPhone 16 batteries, but we are still waiting for teardowns to get a proper look inside of the devices.Read more of this story at Slashdot.
Microsoft Has Scrapped Edge's Big UI Refresh With Rounded Tabs
Microsoft has abandoned plans to overhaul its Edge browser interface, scrapping the design choice unveiled in February 2023. The redesign -- featuring a sleeker look with rounded tab buttons and increased blur effects -- aimed to give Edge a distinct identity as the company pushed into AI services. The new design never officially launched and the company has no intention to launch it later, according to Microsoft-focused news outlet Windows Central. A Microsoft spokesperson confirmed to Windows Central that the company is moving away from the rounded tabs concept. Some elements of the redesign will remain, including webpage borders and a repositioned user button, but the majority of the proposed changes have been shelved. The decision marks a retreat from Microsoft's efforts to visually differentiate Edge from Google Chrome and align it with Windows 11's design language.Read more of this story at Slashdot.
iPhone 16 Pro Demand Has Been Lower Than Expected, Analyst Says
Ming-Chi Kuo, a high-profile and reliable Apple analyst, says the demand for the iPhone 16 Pro and iPhone 16 Pro Max has been "lower than expected" since the devices became available to pre-order in the U.S. and dozens of other countries on Friday. From a report: Kuo said his data is based on a "supply chain survey" and shipping estimates listed on Apple's online store. Kuo estimated that sales of all four iPhone 16 models reached about 37 million units in the first weekend after Apple began accepting pre-orders, which is down nearly 13% compared to first-weekend sales of the iPhone 15 series last year. The analyst said a key factor for the decline is the lower demand for the Pro models, with first-weekend sales of the iPhone 16 Pro and iPhone 16 Pro Max estimated to be down 27% and 16%, respectively, compared to iPhone 15 Pro and iPhone 15 Pro Max sales during the equivalent period last year.Read more of this story at Slashdot.
China Raises Retirement Age For First Time Since 1950s
China will "gradually raise" its retirement age for the first time since the 1950s, as the country confronts an ageing population and a dwindling pension budget. From a report: The top legislative body on Friday approved proposals to raise the statutory retirement age from 50 to 55 for women in blue-collar jobs, and from 55 to 58 for females in white-collar jobs. Men will see an increase from 60 to 63. China's current retirement ages are among the lowest in the world. According to the plan passed on Friday, the change will set in from 1 January 2025, with the respective retirement ages raised every few months over the next 15 years, said Chinese state media. Retiring before the statutory age will not be allowed, state news agency Xinhua reported, although people can extend their retirement by no more than three years. Starting 2030, employees will also have to make more contributions to the social security system in order to receive pensions. By 2039, they would have to clock 20 years of contributions to access their pensions.Read more of this story at Slashdot.
NASA To Develop Lunar Time Standard for Exploration Initiatives
NASA will coordinate with U.S. government stakeholders, partners, and international standards organizations to establish a Coordinated Lunar Time (LTC) following a policy directive from the White House in April. From a report: The agency's Space Communication and Navigation (SCaN) program is leading efforts on creating a coordinated time, which will enable a future lunar ecosystem that could be scalable to other locations in our solar system. The lunar time will be determined by a weighted average of atomic clocks at the Moon, similar to how scientists calculate Earth's globally recognized Coordinated Universal Time (UTC). Exactly where at the Moon is still to be determined, since current analysis indicates that atomic clocks placed at the Moon's surface will appear to 'tick' faster by microseconds per day. A microsecond is one millionth of a second. NASA and its partners are currently researching which mathematical models will be best for establishing a lunar time. To put these numbers into perspective, a hummingbird's wings flap about 50 times per second. Each flap is about .02 seconds, or 20,000 microseconds. So, while 56 microseconds may seem miniscule, when discussing distances in space, tiny bits of time add up.Read more of this story at Slashdot.
Multiple Attacks Force CISA to Order US Agencies to Upgrade or Remove End-of-Life Ivanti Appliance
On Tuesday Ivanti issued a "high severity vulnerability" announcement for version 4.6 of its Cloud Service Appliance (or CSA). "Successful exploitation could lead to unauthorized access to the device running the CSA." And Friday that announcement got an update: Ivanti "has confirmed exploitation of this vulnerability in the wild." While Ivanti released a security update, they warned that "with the end-of-life status this is the last fix that Ivanti will backport for this version. Customers must upgrade to Ivanti CSA 5.0 for continued support." This prompted a response from CISA (the Cybersecurity and Infrastructure Security Agency, part of the U.S. Department of Homeland Security). The noted that Ivanti is urging customers to upgrade to version 5.0, as "Ivanti no longer supports CSA 4.6 (end-of-life)." But in addition, CISA "ordered all federal civilian agencies to remove CSA 4.6. from service or upgrade to the 5.0. by October 4," reports the Record:Ivanti said users will know they are impacted by exploitation of the bug by looking to see if there are modified or newly added administrative users. They also urged customers to check security alerts if they have certain security tools involved. The issue arose one day after another Ivanti bug caused alarm among defenders. The company pledged a security overhaul in April after a cascade of headline-grabbing nation-state attacks broke through the systems of government agencies in the U.S. and Europe using vulnerabilities in Ivanti products.Read more of this story at Slashdot.
EFF Decries 'Brazen Land-Grab' Attempt on 900 MHz 'Commons' Frequency Used By Amateur Radio
An EFF article calls out a "brazen attempt to privatize" a wireless frequency band (900 MHz) which America's FCC's left " as a commons for all... for use by amateur radio operators, unlicensed consumer devices, and industrial, scientific, and medical equipment." The spectrum has also become "a hotbed for new technologies and community-driven projects. Millions of consumer devices also rely on the range, including baby monitors, cordless phones, IoT devices, garage door openers."But NextNav would rather claim these frequencies, fence them off, and lease them out to mobile service providers. This is just another land-grab by a corporate rent-seeker dressed up as innovation. EFF and hundreds of others have called on the FCC to decisively reject this proposal and protect the open spectrum as a commons that serves all. NextNav [which sells a geolocation service] wants the FCC to reconfigure the 902-928 MHz band to grant them exclusive rights to the majority of the spectrum... This proposal would not only give NextNav their own lane, but expanded operating region, increased broadcasting power, and more leeway for radio interference emanating from their portions of the band. All of this points to more power for NextNav at everyone else's expense. This land-grab is purportedly to implement a Positioning, Navigation and Timing (PNT) network to serve as a US-specific backup of the Global Positioning System(GPS). This plan raises red flags off the bat. Dropping the "global" from GPS makes it far less useful for any alleged national security purposes, especially as it is likely susceptible to the same jamming and spoofing attacks as GPS. NextNav itself admits there is also little commercial demand for PNT. GPS works, is free, and is widely supported by manufacturers. If Nextnav has a grand plan to implement a new and improved standard, it was left out of their FCC proposal. What NextNav did include however is its intent to resell their exclusive bandwidth access to mobile 5G networks. This isn't about national security or innovation; it's about a rent-seeker monopolizing access to a public resource. If NextNav truly believes in their GPS backup vision, they should look to parts of the spectrum already allocated for 5G. The open sections of the 900 MHz spectrum are vital for technologies that foster experimentation and grassroots innovation. Amateur radio operators, developers of new IoT devices, and small-scale operators rely on this band. One such project is Meshtastic, a decentralized communication tool that allows users to send messages across a network without a central server. This new approach to networking offers resilient communication that can endure emergencies where current networks fail. This is the type of innovation that actually addresses crises raised by Nextnav, and it's happening in the part of the spectrum allocated for unlicensed devices while empowering communities instead of a powerful intermediary. Yet, this proposal threatens to crush such grassroots projects, leaving them without a commons in which they can grow and improve. This isn't just about a set of frequencies. We need an ecosystem which fosters grassroots collaboration, experimentation, and knowledge building. Not only do these commons empower communities, they avoid a technology monoculture unable to adapt to new threats and changing needs as technology progresses. Invention belongs to the public, not just to those with the deepest pockets. The FCC should ensure it remains that way. NextNav's proposal is a direct threat to innovation, public safety, and community empowerment. While FCC comments on the proposal have closed, replies remain open to the public until September 20th. The FCC must reject this corporate land-grab and uphold the integrity of the 900 MHz band as a commons.Read more of this story at Slashdot.
Original 'Flappy Bird' Creator Disavows New Version - and Its Possible Crypto Ties
Flappy Bird's original creator hasn't posted anything on social media since 2017. Until today. "This morning, the game's creator Dong Nguyen posted a characteristically terse comment stating that he has nothing to do with the revival," report TechCrunch, "and that he 'did not sell anything.' He added, 'I also don't support crypto'... The post makes it clear that Nguyen is not involved with the new project, and that he doesn't seem particularly happy about it."As for Nguyen's reference to crypto, while the foundation's current PR materials don't mention anything crypto-related, Varun Biniwale did some digging around hidden pages on the Flappy Bird Foundation website and found a reference to Flappy Bird flying "higher than ever on Solana as it soars into Web 3.0," though it's not clear whether that refers to upcoming features or abandoned plans. More from Fortune:Exactly what is going to happen with this zombified version of Flappy Bird is unclear, but digging through data and files has revealed things like different birds, loot boxes, and the idea that this is some sort of crypto play by the company involved. From a page on their website about the new Flappy Bird... "[D]evelopers and creators can build, play and earn from the legendary Flappy Bird IP." Fortune concludes "it's crypto, it's NFTs and everyone is so annoyed by this almost every tweet of the resurrected Twitter account has even been 'Community Noted' revealing its crypto ties and snapping up of Nguyen's trademark." PC Gamer adds that the Foundation acquired the Flappy Bird trademark from Gametech Holdings LLC. "And here there's a slight whiff of skullduggery." Dong Nguyen originally applied for the trademark in 2014, alongside a little drawing of the logo. This application then seemed to sit in limbo for many years, eventually being opposed by a Delaware-based company called Gametech. As this was going on, the U.S. patent office granted a trademark registration for Flappy Bird in 2018 (four years after the game was removed from sale) to another Delaware company called Mobile Media Matters. While I can't be exact on the link between Mobile Media Matters and Gametech, both companies' legal filings give the same Delaware address. Subsequent to this there's been a legal disagreement between Gametech and Dong Nguyen, except Nguyen doesn't seem to have bothered representing himself or standing up for the trademark, which has ultimately led to it being classed as abandoned (a decade after he filed for it) and acquired by Gametech... The Flappy Bird Foundation does have one ready-made comeback. As well as the rights to Flappy Bird it has acquired the rights to Piou Piou vs. Cactus, a mobile title that was the primary inspiration behind Flappy Bird, and employs the game's creator who goes by the handle, ahem, of Kek. "Today is a milestone not just in gaming but for me personally," says Kek. "It's so cool to see how influential Piou Piou has been for developers and hundreds of millions of gamers over the years. It's incredible to work alongside such a dedicated team of fans and creators who are truly passionate about changing the industry narrative and together bringing the original Flappy Bird back to life...." Way back in 2014, Kek said he'd contacted Nguyen about the resemblance, "and he told me he doesn't think he knew about my game when he made Flappy Bird. The games are very similar. And even if I did not invent the gameplay concept, the graphics are very close, and, of course, the concept." The games are undeniably similar, but there are differences, and obviously the most important one is that, for whatever reason, Piou Piou didn't do much while Flappy Bird went stratospheric with a similar idea three years later. Needless to say, the announcement and press release of the Flappy Bird Foundation does not mention Dong Nguyen once.Read more of this story at Slashdot.
17,000 ATT Workers End the Southeast's Longest Telecommunications Strike After 30 Days
For 30 days, 17,000 AT&T workers in nine different states from the CWA union went on strike. As it began one North Carolina newspaper noted some AT&T customers "report prolonged internet outages." Last week an Emory University economist told NPR that "If it wasn't disruptive or it didn't have any kind of negative element towards customers, then AT&T, I suspect, wouldn't feel any kind of pressure to negotiate." The 30-day strike was "the longest telecommunications strike in the region's history," according to the union - announcing today that they'd now negotiated "strong tentative contract agreements" and that workers would report to work for their scheduled shifts tomorrow.The new contract in the Southeast covers 17,000 workers technicians, customer service representatives and others who install, maintain and support AT&T's residential and business wireline telecommunications network in Alabama, Florida, Georgia, Kentucky, Louisiana, Mississippi, North Carolina, South Carolina and Tennessee. Wages and health care costs were key issues at the bargaining table, and the five-year agreement includes across the board wage increases of 19.33%, with additional 3% increases for Wire Technicians and Utility Operations. The health care agreement holds health care premiums steady in the first year and lowers them in the second and third years, with modest monthly increases in the final two years. The statement adds that "CWA members and retirees from every region and sector of our union mobilized in support of our bargaining teams, including by distributing flyers with information about the strike at AT&T Wireless stores." CWA District 3 Vice President Richard Honeycutt added "We know that our customers have faced hardship during the strike as well. We are happy to be getting back to work keeping our communities safe and connected." There's also a separate four-year agreement covering 8,500 AT&T West workers in California and Nevada. "Union members will meet to review the tentative agreements, before holding ratification votes in each region." AT&T's chief operating officer said the Southeast agreement will "support our competitive position in the broadband industry where we can grow and win against our mostly non-union competitors."Read more of this story at Slashdot.
Paraguay Loves Its Cartoon Mouse Mickey. Disney Does Not
The New York Times looks at "a third-generation family firm" in Paraguay "with 280 workers that packages hot sauce, soy beans...and seven kinds of salt for sale in Paraguayan supermarkets." Its mascot - on t-shirts, coffee cups, and "in heavy demand at Paraguayan weddings" - is a mouse named Mickey. 51-year-old Viviana Blasco - one of five siblings who run the business - told the Times that it all began back in 1935:Ms. Blasco's grandfather, Pascual, the son of Italian immigrants, saw an opportunity to spread some joy - and turn a profit. He opened a tiny shop selling fruit and homemade gelato. It was called Mickey... Pascual, she said, often vacationed in Buenos Aires - Argentina's cosmopolitan capital... "On one of his trips, he must have seen the famous mouse," Ms. Blasco said... A few years later, Pascual opened the Mickey Ice Cream Parlor, Cafe and Confectioners. By 1969, Mickey was selling rice, sugar and baking soda in packages now decorated with the eponymous mouse. "Mickey resonates with Paraguayans' sense of nostalgia, said Euge Aquino, a TV chef and social media influencer who uses its ingredients to make comfort food like pastel mandi'o (yuca and beef empanadas)... Mickey's popularity, she said, also has a lot to do with the mascot handing out candy outside the factory gates every Christmas: a tradition dating back to 1983."By now, a "peaceful coexistence" reigns between Mickey and its United States doppelganger, said Elba Rosa Britez, 72, the smaller company's lawyer. This truce was hard-won. In 1991, Disney filed a trademark violation claim with Paraguay's Ministry of Business and Industry that was rejected. The company then filed a lawsuit, but in 1995 a trademark tribunal ruled in Mickey's favor. There, one judge agreed that Paraguayans could easily confuse the Disney Mickey and the Paraguayan Mickey. But Disney didn't reckon on a "legal loophole," Ms Britez explained. The Mickey trademark had been registered in Paraguay since at least 1956 - and Pascual's descendants had since renewed it - without protest from the multinational. In 1998, Paraguay's Supreme Court issued its final ruling. Through decades of uninterrupted use, Mickey had acquired the right to be Mickey. "I jumped for joy," Ms Britez said. Mickey's legal immunity in Paraguay, Ms. Blasco acknowledged, might not extend to selling its products abroad. "We've never tried." "Some lining up to meet the mascot said Mickey's David-vs-Goliath triumph against Disney filled them with national pride..."Read more of this story at Slashdot.
Stephen Hawking Was Wrong - Extremal Black Holes Are Possible
"Even black holes have edge cases," writes Astronomy magazine contributing editor Steve Nadis, in an article in Quanta magazine (republished today by Wired):Black holes rotate in space. As matter falls into them, they start to spin faster; if that matter has charge, they also become electrically charged. In principle, a black hole can reach a point where it has as much charge or spin as it possibly can, given its mass. Such a black hole is called "extremal" - the extreme of the extremes. These black holes have some bizarre properties. In particular, the so-called surface gravity at the boundary, or event horizon, of such a black hole is zero. "It is a black hole whose surface doesn't attract things anymore," said Carsten Gundlach, a mathematical physicist at the University of Southampton. But if you were to nudge a particle slightly toward the black hole's center, it would be unable to escape. In 1973, the prominent physicists Stephen Hawking, James Bardeen and Brandon Carter asserted that extremal black holes can't exist in the real world - that there is simply no plausible way that they can form. Nevertheless, for the past 50 years, extremal black holes have served as useful models in theoretical physics. "They have nice symmetries that make it easier to calculate things," said Gaurav Khanna of the University of Rhode Island, and this allows physicists to test theories about the mysterious relationship between quantum mechanics and gravity. Now two mathematicians have proved Hawking and his colleagues wrong. The new work - contained in a pair of recent papers by Christoph Kehle of the Massachusetts Institute of Technology and Ryan Unger of Stanford University and the University of California, Berkeley - demonstrates that there is nothing in our known laws of physics to prevent the formation of an extremal black hole. Their mathematical proof is "beautiful, technically innovative and physically surprising," said Mihalis Dafermos, a mathematician at Princeton University (and Kehle's and Unger's doctoral adviser). It hints at a potentially richer and more varied universe in which "extremal black holes could be out there astrophysically," he added. That doesn't mean they are. "Just because a mathematical solution exists that has nice properties doesn't necessarily mean that nature will make use of it," Khanna said. "But if we somehow find one, that would really [make] us think about what we are missing." Such a discovery, he noted, has the potential to raise "some pretty radical kinds of questions." Before Kehle and Unger's proof, there was good reason to believe that extremal black holes couldn't exist. Hawking, Bardeen, and Carter believed there was no way an extremal black hole could form, according to the article, and "in 1986, a physicist named Werner Israel seemed to put the issue to rest." But the two mathematicians, studying the formation of electrically charged black holes, stumbled into a counterexample - and along the way "also constructed two other solutions to Einstein's equations of general relativity that involved different ways of adding charge to a black hole.Having disproved Bardeen, Carter and Hawking's hypothesis in three different contexts, the work should leave no doubt, Unger said... "This is a beautiful example of math giving back to physics," said Elena Giorgi, a mathematician at Columbia University.... In the meantime, a better understanding of extremal black holes can provide further insights into near-extremal black holes, which are thought to be plentiful in the universe. "Einstein didn't think that black holes could be real [because] they're just too weird," Khanna said. "But now we know the universe is teeming with black holes." For similar reasons, he added, "we shouldn't give up on extremal black holes. I just don't want to put limits on nature's creativity."Read more of this story at Slashdot.
Linux Developer Swatted and Handcuffed During Live Video Stream
Last October Slashdot reported on Rene Rebe's discovery of a random illegal instruction speculation bug on AMD Ryzen 7000-series and Epyc Zen 4 CPUs - which Rebe discussed on his YouTube channel. But this week's YouTube episode had a different ending, reports Tom's Hardware...Two days ago, tech streamer and host of Code Therapy Rene Rebe was streaming one of many T2 Linux (his own custom distribution) development sessions from his office in Germany when he abruptly had to remove his microphone and walk off camera due to the arrival of police officers. The officers subsequently cuffed him and took him to the station for an hour of questioning, a span of time during which the stream continued to run until he made it back... [T]he police seemingly have no idea who did it and acted based on a tip sent with an email. Finding the perpetrators could take a while, and options will be fairly limited if they don't also live in Germany. Rebe has been contributing to Linux "since as early as 1998," according to the article, "and started his own T2 SD3 Embedded Linux distribution in 2004, as well." (And he's also a contributor to many other major open source projects.) The article points out that Linux and other communities "are compelled by little-to-no profit motive, so in essence, Rene has been providing unpaid software development for the greater good for the past two decades."Read more of this story at Slashdot.
How Amazon's Secret Weapon in Chip Design is Amazon
In 2015 Amazon purchased chip designer Annapurna Labs, remembers IEEE Spectrum, "and proceeded to design CPUs, AI accelerators, servers, and data centers as a vertically-integrated operation." The article argues that while AMD, Nvidia, and other big-name processor companies may also want to control the full stack (purchasing server, software, and interconnect companies) - Amazon Web Services "got there ahead of most of the competition." (IEEE Spectrum interviews Ali Saidi, technical lead for the AWS Graviton series of CPUs, and Rami Sinno, director of engineering at Annapurna Labs, on "the advantage of vertically-integrated design - and Amazon-scale...")Sinno: I was working at Arm, and I was looking for the next adventure, looking at where the industry is heading and what I want my legacy to be. I looked at two things: One is vertically integrated companies, because this is where most of the innovation is - the interesting stuff is happening when you control the full hardware and software stack and deliver directly to customers. And the second thing is, I realized that machine learning, AI in general, is going to be very, very big. I didn't know exactly which direction it was going to take, but I knew that there is something that is going to be generational, and I wanted to be part of that. I already had that experience prior when I was part of the group that was building the chips that go into the Blackberries; that was a fundamental shift in the industry. That feeling was incredible, to be part of something so big, so fundamental. And I thought, "Okay, I have another chance to be part of something fundamental." [...] At the end of the day, our responsibility is to deliver complete servers in the data center directly for our customers. And if you think from that perspective, you'll be able to optimize and innovate across the full stack. It might not be at the transistor level or at the substrate level or at the board level. It could be something completely different. It could be purely software. And having that knowledge, having that visibility, will allow the engineers to be significantly more productive and delivery to the customer significantly faster. We're not going to bang our head against the wall to optimize the transistor where three lines of code downstream will solve these problems, right...? We've had very good luck with recent college grads. Recent college grads, especially the past couple of years, have been absolutely phenomenal. I'm very, very pleased with the way that the education system is graduating the engineers and the computer scientists that are interested in the type of jobs that we have for them. It's an interesting glimpse into the unique world of designing chips at Amazon. Graviton technical lead Saidi: I've been here about seven and a half years. When I joined AWS, I joined a secret project at the time. I was told: "We're going to build some Arm servers. Tell no one... "In chip design, there are many different competing optimization points. You have all of these conflicting requirements, you have cost, you have scheduling, you've got power consumption, you've got size, what DRAM technologies are available and when you're going to intersect them... It ends up being this fun, multifaceted optimization problem to figure out what's the best thing that you can build in a timeframe. And you need to get it right."Read more of this story at Slashdot.
SpaceX's Polaris Dawn Crew Returns to Earth After Historic Spacewalk
"It is with great relief that I welcome you home!" SpaceX COO Gwynne Shotwell posted on X. "This mission was even more extraordinary than I anticipated." "SpaceX's Polaris Dawn crew is home," reports CNN, "capping off a five-day mission to orbit - which included the world's first commercial spacewalk - by splashing down in the Gulf of Mexico."The Crew Dragon capsule carrying four astronauts landed off the coast of Dry Tortugas, Florida, at 3:37 a.m. ET Sunday. The Polaris Dawn mission made history as it reached a higher altitude than any human has traveled in five decades. [870 miles (1,400 kilometers) - beating the 853-mile record set in 1966 by NASA's Gemini 11 mission.] A spacewalk conducted early Thursday morning also marked the first time such an endeavor has been completed by a privately funded and operated mis.sion. But returning to Earth is among the most dangerous stretches of any space mission. To safely reach home, the Crew Dragon capsule carried out what's called a "de-orbit burn," orienting itself as it prepared to slice through the thickest part of Earth's atmosphere. The spacecraft then reached extremely hot temperatures - up to 3,500 degrees Fahrenheit (1,900 degrees Celsius) - because of the pressure and friction caused by hitting the air while still traveling around 17,000 miles per hour (27,000 kilometers per hour). The crew, however, should have remained at comfortable temperatures, protected by the Crew Dragon's heat shield, which is located on the bottom of the 13-foot-wide (4-meter-wide) capsule.Dragging against the air began to slow the vehicle down before the Crew Dragon deployed parachutes that further decelerated its descent. Having hit the ocean, the spacecraft briefly bobbed around in the water until rescue crews waiting nearby hauled it out of the ocean and onto a special boat, referred to as the "Dragon's nest." Final safety checks took place there before the crew disembarked from the capsule and began the journey back to dry land. You can watch video of the splashdown on YouTube. While in space, the crew performed 40 science experiments and research, according to the article. "Gillis, a trained violinist, also brought her instrument along for the mission and delivered a rendition of 'Rey's Theme' from "Star Wars: The Force Awakens." (Slashdot reader SuperKendall points out that the "Rey's Theme" rendition "was not just the astronaut playing violin in space, but was in conjunction with young adult orchestras around the world.") SpaceX's COO said the performance "made me tear up. Thank you all for taking this journey."Read more of this story at Slashdot.
Changing Open Source Licenses to Proprietary? Study Finds 'No Clear Link' to Increased Company Value
An anonymous reader shared this report from DecClass:A report from developer-focused analyst Redmonk finds "there does not seem to be a clear link between moving from an open source to proprietary license and increasing the company's value." Senior analyst Rachel Stevens studied the question of whether the companies that changed from open source to proprietary licenses have since reported better financial positions. In particular, she looked at MongoDB, which changed from AGPL (GNU Affero General Public License) to its SSPL (Server Side Public License) in 2018; Elastic Co, which changed from Apache 2 to SSPL or Elastic License in early 2021; HashiCorp, which changed from MPL (Mozilla Public License 2.0) a year ago, and Confluent, which checked from Apache 2 to its own Confluent Community License in 2018. The report is too recent to take account of Elastic's reversion to AGPL; and the financial impact of that is of course yet to be known, though it is perhaps unlikely that the switch back would have been made if the company considered it detrimental to its finances. Rather, Elastic's latest licensing change reinforces the view that proprietary licenses are not necessarily more profitable... All the companies studied increased their revenue after their license change, Stevens said, but added that the rate of change was similar to that before the change... MongoDB stated in 2018 that "once an open source project becomes interesting or popular, it becomes too easy for the cloud vendors to capture all the value and give nothing back to the community." Six years later, it remains the case that the large cloud vendors are highly profitable, but that these companies who changed their license are not. In February this year, Bruce Perens, creator of the 1998 Open Source Definition, described open source as "a great corporate welfare program" and not at all what he had intended... The new Redmonk report suggests that such license manoeuvres are neither fatal nor beneficial to the finances of the companies involved - though there are so many caveats that it is impossible to draw firm conclusions. The report's final sentence concludes that "there does not seem to be a clear link between moving from an open source to proprietary license and increasing the company's value."Read more of this story at Slashdot.
Sheriff's Facebook Post Announces Sentencing of 70-Year-Old Man For a 1980 Cold Case
In 1980 a 23-year-old woman was shot multiple times by an unknown assailant in a small county in central Kansas. 44 years later, the county sheriff made a Facebook post...Over the years, dozens of law enforcement officers looked at the case to no avail. In mid-2022 I was approached by Detective Sgt. Adam Hales to reopen the case using new techniques and technology that were now available at the time of the murder. In all honesty, it was with some degree of skepticism that I authorized the expenditure of manpower and resources... Many of the witnesses as well as law enforcement officers that were originally involved in the case had died and interviews were not possible. A statement from the Kansas attorney general's office says the police investigation culminated with an interview with Steven Hanks, a neighbor of the woman, who admitted to the killing. Hanks (who is now 70 years old) was arrested and charged with murder and second-degree, according to the county sheriff's Facebook post:On a personal note, I was 18 years old and a senior in high school when this homicide occurred. I remember it well. By 1982 I had started with the Sheriff's Office as a reserve deputy and have been associated with the Barton County Sheriff's Office ever since. I worked for the four Sheriff's that preceded me and this homicide has haunted all of us. It bothers me that many of the people who were so affected by this tragic crime have since passed away prior to bringing the suspect to justice. I consider myself fortunate that I had the resources and the diligent personnel to close this case. The Facebook post ends with a 1980 photo of 23-year-old Mary Robin Walter - who besides being a nursing school student was also a wife and mother - next to a booking photo of 70-year-old Steven Hanks. Hanks has been sentenced to up to 25 years in prisonRead more of this story at Slashdot.
Earthquake Scientists Finally Explain 9-Day Global 'Unidentified Seismic Object'
It was one year ago that "an odd seismic signal appeared at scientific stations around the globe," reports the Washington Post. "A day passed, and the slow tremor still reverberated. When it continued for a third day, scientists worldwide began assembling..."Some initially thought the seismic instruments recording the signal were broken, but that was quickly nixed. Maybe it was a new volcano emerging before their eyes, others said. One jokingly ruled out an alien party. As theories were checked off, the scientists dubbed the signal an "Unidentified Seismic Object," or USO... Nine days later, the vibrations greatly dissipated. But the mystery of the USO lasted much longer. A year later, the puzzle has been solved, according to a study published in the journal Science on Thursday. It took about 70 people from 15 different countries and more than 8,000 exchanged messages (long enough for a 900-page detective novel) to crack the case. The short answer: A mega-tsunami created waves that sloshed back and forth in a fjord in Greenland, creating vibrations that traveled around the world. Extra heat from global warming "thinned a glacier in eastern Greenland over time so much that it could no longer support the mountain rock above it," according to the article. A mile-long avalanche "plunged into the Dickson Fjord, triggering a 650-foot-high tsunami - one of the highest seen in recent history." Like the rhythmic waves in a bathtub, "the mega-tsunami wave traveled back and forth in the inlet," which "radiated seismic waves globally, shaking the planet for nine days before it petered out." In August a German research team had studied the megatsunami, concluding that climate change was speeding the melt of Greenland's glaciers and increasing the chance of landslide-driven megatsunamis. The article reports that an author of that study said when comparing it to this one, "The methods chosen by the teams are different, but the results agree well."Read more of this story at Slashdot.
California New 'Cosm' Immersive Sports-Watching Dome is Amazing - and Expensive
"For 75 years Cosm built planetariums," reports a Texas news station, "and then a few years ago realized this technology could take you from the night sky to anywhere under the sun." So now Los Angeles and Dallas have massive 9,600-square-foot, 8K-resolution screens that one reviewer for SFGate calls "an absolute game-changer" for sports fans. "At its best, Cosm's floor-to-ceiling screen gives anyone with a seat the opportunity to embrace a face full of on-the-field action at such high quality that it can be staggering, almost overwhelming at times - so just be sure to hold on tight, to the handrails and to your wallets." There's also a bar with a 150-foot band of screens and a rooftop area with mounted TV, but they're "not why anyone has come," SFGate points out. Even the Dome has three distinct floors, though it's the second floor "where full visual immersion happens."The action feels so close, I can almost smell it, and all the focus is pulled to the center of the giant screen. Patrons truly do feel at the absolute heart of the action, with better seats than perhaps they could even pay for at Manchester's Old Trafford stadium. From a sports-viewing standpoint, I can't imagine it gets much better than this... Over the course of just a few minutes, the viewing angle flips from corner looks to right up against the goalkeeper's net, and then it widens out to dead center to catch crisp passes. Some angles put me right in the stands, cheering along with the loyalists at a stadium half a world away... To be clear, the premium ticket costs are good for recouping Cosm's substantial investment in this gorgeous technological product, which has been in the works for years. The price tag is also likely to be little issue for any Los Angeles fan with money to spend, but the cost really does lay bare the growing division between the haves and have-nots in American sports society... If you paid $20 for a general admission entry that mostly just grants access to the fringes of the action, well ... good luck getting the most out of the Dome... The edges of the massive screen are stretched to comic effect, making the fisheye perspective more disorienting than fun. At the center of the room, it feels like you're absolutely in the meat of the action; at the fringes, you're left to pick at a few digital bones... [F]or the rest of us, the normal sports fans who like to sway with strangers during the seventh-inning stretch, the ones who want to be able to take their kids to a game without feeling quite so financially wrung out, Cosm is yet another troubling sign of big, expensive things to come. Being a fan of a sports franchise in 2024 is an increasingly costly proposition. Watching your favorite NFL team now requires cable access, as well as multiple streaming services like Amazon Prime... There is no question that Cosm is a unique experience and that it will absolutely have a hand in transforming the modern digital sports-watching landscape, especially for those who want a digital re-creation of the best seat in the house over the camaraderie of a shared, in-person sports experience. The place will be able to charge incredible sums for the Super Bowl or World Series games, and - when at its best, with a prime seat in the middle of the action - the cost will be justifiable for many. But for the folks at the financial fringes, the ones with the most spirit and often the least to spend, Cosm undoubtedly feels like a widening of the economic chasm that is pulling fans and their favorite teams further apart. Besides sports events, Cosm's Dome also offers other immersive experiences like Circque du Soleil's "O" and Planetary Collective's "Orbital". Another Cosm location is planned for Phoenix in 2025.Read more of this story at Slashdot.
Fake Python Coding Tests Installed Malicious Software Packages From North Korea
"New malicious software packages tied to the North Korean Lazarus Group were observed posing as a Python coding skills test for developers seeking a new job at Capital One, but were tracked to GitHub projects with embedded malware," reports SC magazine:Researchers at ReversingLabs explained in a September 10 blog post that the scheme was a follow-on to the VMConnect campaign that they first identified in August 2023 in which developers were lured into downloading malicious code via fake job interviews. More details from The Hacker NewsThese packages, for their part, have been published directly on public repositories like npm and PyPI, or hosted on GitHub repositories under their control. ReversingLabs said it identified malicious code embedded within modified versions of legitimate PyPI libraries such as pyperclip and pyrebase... It's implemented in the form of a Base64-encoded string that obscures a downloader function, which establishes contact with a command-and-control server in order to execute commands received as a response. In one instance of the coding assignment identified by the software supply chain firm, the threat actors sought to create a false sense of urgency by requiring job seekers to build a Python project shared in the form of a ZIP file within five minutes and find and fix a coding flaw in the next 15 minutes. This makes it "more likely that he or she would execute the package without performing any type of security or even source code review first," Zanki said, adding "that ensures the malicious actors behind this campaign that the embedded malware would be executed on the developer's system." Tom's Hardware reports that "The capacity for exploitation at that point is pretty much unlimited, due to the flexibility of Python and how it interacts with the underlying OS. This is a good time to refer to PEP 668 which enforces virtual environments for non-system wide Python installs." More from The Hacker NewsSome of the aforementioned tests claimed to be a technical interview for financial institutions like Capital One and Rookery Capital Limited, underscoring how the threat actors are impersonating legitimate companies in the sector to pull off the operation. It's currently not clear how widespread these campaigns are, although prospective targets are scouted and contacted using LinkedIn, as recently also highlighted by Google-owned Mandiant.Read more of this story at Slashdot.
Google's New Foldable Smartphone Reviewed By a YouTube Tester, an Android Blog, and iFixit
Google's describes their new Gemini-powered foldable phone as "an epic display of Google AI" (also calling it "unfoldgettable"). The Android Authority blog says the phone is "impressive," "incredibly thin" - and, at $1,800, expensive. But long-time Slashdot reader mprindle notes some complaints from the YouTube channel JerryRigEverything ("known for in-depth testing of phones and other devices".) The blog 9to5Google summarizes some of the video's findings:- When exposed to dirt and sand, we hear the hinge start grinding since there's no dust protection... - A closed bend test reveals no problems for the Pixel 9 Pro Fold, but the issues arise when it's open and bent from the back. Despite the left/right back panels meeting and covering the spine of the hinge, "there doesn't appear to be a whole lot of resistance." "Not sure why Google thought it was a good idea to put an antenna line right here at the weakest point in an already thin frame," the video notes (arguing it's "like putting an exhaust port in the Death Star...") But they also tell their 8.8 million subscribers that "One cool thing that Google has done is that they've made every single part of this metal frame from recycled aluminum." And "Out of the box, I'm already a huge fan of how it looks," the video begins. "It feels amazing, and folds completely shut and appears like the hardware has finally caught up to the folding form factor to where it looks just natural." One thing to note... "Moving to the inner display, I start to get the vibe that when Google says 'super durable', they mean 'regular durable', since the inner display is made from the same soft flexible plastic that we've seen on every folding phone so far, which scratches at level two. Even fingernails can leave very permanent marks on the center screen. This is absolutely normal for a folding phone, though, and really not too big of a deal if you take care it, making sure there are no bits of dust or dirt in the screen when you close it will go a long way to keeping things pristine, since there's not a lot of room between the two halves." iFixit makes an interesting observation: "Over half of the phone's internal area is occupied by the lithium polymer battery cells!" (They've also created another teardown video available on YouTube.) "There's no denying that the inner screens are delicate and prone to damage," according to an accompanying iFixit blog post, "and the mechanical nature of the hinge mechanism provides additional avenues for dust and liquid ingress that may eventually become a problem." But it also applauds "the less obvious repairability wins, from repair guides and a detailed Bill of Materials to spare parts that are available without malicious restrictions... [T]he Pixel team has gone to great lengths to support your right to repair the device you paid for and own" - and from Day One.There's really only a single criticism I'd direct at the Pixel 9 Fold from my own disassembly experience: the battery removal tabs. These tabs simply do not work, with or without the application of heat. They are flimsy and break often, require a second pair of hands to secure the device, and they fail to cut through adhesive reliably. Whether they should even try to cut through adhesive is debatable. Stretch release adhesive might age and break over time but at least they give you a chance at removing the adhesive. Pull tabs don't even work when the adhesive is brand new, they literally have no redeeming qualities when compared to other battery release mechanisms. Even the more robust pull tabs Samsung uses in its phones work better than this, though they aren't necessarily the easiest to use either. As for the device itself, it prompted one of my colleagues - an iPhone user since forever - to say "this is nice, I'd switch to Android for this"... Setting aside the downsides of owning a foldable smartphone, I am excited to see Google and the Pixel team devoting so much time and energy towards improving the overall repairability of the device. The effort is seen and appreciated by device owners and as a technician, I look forward to seeing how manufacturers will continue to innovate for repairability. Slashdot reader mprindle reminds us that when it comes to waterproofing, the JerryRigEverything video "noted that the footnotes say the device is rated IP68 yet the Sim tray is rated at IPx8."Read more of this story at Slashdot.
$50M In Counterfeit Vintage Consoles and Videogames Seized From Italian Crime Ring
Police in Italy "smashed" a videogame trafficking ring, reports the BBC. They seized fake vintage Nintendo, Sega and Atari consoles that didn't meet strict safety standards, as well as counterfeit games - including Mario Bros., Street Fighter and Star Wars - that together were worth almost 50m ($55.5m)Around 12,000 consoles holding over 47 million pirated video games were seized by police, Alessandro Langella, head of the economic crime unit for Turin's financial police, told the AFP news agency... They were "all from China" and were imported to be sold in specialised shops or online, Mr Langella said... The seized games have been destroyed. Nine Italian nationals have been arrested and charged with trading in counterfeited goods. If found guilty, they face up to eight years in prison.Read more of this story at Slashdot.
Underfunded, Aging NASA May Be On Unsustainable Path, Report Warns
More details on that report about NASA from the Washington Post:NASA is 66 years old and feeling its age. Brilliant engineers are retiring. Others have fled to higher-paying jobs in the private space industry. The buildings are old, their maintenance deferred. The Apollo era, with its huge taxpayer investment, is a distant memory. The agency now pursues complex missions on inadequate budgets. This may be an unsustainable path for NASA, one that imperils long-term success. That is the conclusion of a sweeping report, titled "NASA at a Crossroads," written by a committee of aerospace experts and published Tuesday by the National Academies of Sciences, Engineering and Medicine. The report suggests that NASA prioritizes near-term missions and fails to think strategically. In other words, the space agency isn't sufficiently focused on the future. NASA's intense focus on current missions is understandable, considering the unforgiving nature of space operations, but "one tends to neglect the probably less glamorous thing that will determine the success in the future," the report's lead author, Norman Augustine, a retired Lockheed Martin chief executive, said Tuesday. He said one solution for NASA's problems is more funding from Congress. But that may be hard to come by, in which case, he said, the agency needs to consider canceling or delaying costly missions to invest in more mundane but strategically important institutional needs, such as technology development and workforce training. Augustine said he is concerned that NASA could lose in-house expertise if it relies too heavily on the private industry for newly emerging technologies. "It will have trouble hiring innovative, creative engineers. Innovative, creative engineers don't want to have a job that consists of overseeing other people's work," he said... The report is hardly a blistering screed. The tone is parental. It praises the agency - with a budget of about $25 billion - for its triumphs while urging more prudent decision-making and long-term strategizing. NASA pursues spectacular missions. It has sent swarms of robotic probes across the solar system and even into interstellar space. Astronauts have continuously been in orbit for more than two decades. The most ambitious program, Artemis, aims to put astronauts back on the moon in a few short years. And long-term, NASA hopes to put astronauts on Mars. But a truism in the industry is that space is hard. The new report contends that NASA has a mismatch between its ambitions and its budget, and needs to pay attention to fundamentals such as fixing its aging infrastructure and retaining in-house talent. NASA's overall physical infrastructure is already well beyond its design life, and this fraction continues to grow," the report states. NASA Administrator Bill Nelson said the report "aligns with our current efforts to ensure we have the infrastructure, workforce, and technology that NASA needs for the decades ahead," according to the article. Nelson added that the agency "will continue to work diligently to address the committee's recommendations."Read more of this story at Slashdot.
The Rust Foundation is Reviewing and Improving Rust's Security
The Rust foundation is making "considerable progress" on a complete security audit of the Rust ecosystem, according to the coding news site I Programmer, citing a newly-released report from the nonprofit Rust foundation:The foundation is investigating the development of a Public Key Infrastructure (PKI) model for the Rust language, including the design and implementation for a PKI CA and a resilient Quorum model for the project to implement, and the report says that language updates suggested by members of the Project were nearly ready for implementation. Following the XZ backdoor vulnerability, the Security Initiative has focused on supply chain security, including work on provenance-tracking, verifying that a given crate is actually associated with the repository it claims to be. The top 5,000 crates by download count have been checked and verified. Threat modeling has now been completed on the Crates ecosystem. Rust Infrastructure, crates.io and the Rust Project. Two open source security tools, Painter and Typomania, have been developed and released. Painter can be used to build a graph database of dependencies and invocations between all crates within the crates.io ecosystem, including the ability to obtain 'unsafe' statistics, better call graph pruning, and FFI boundary mapping. Typomania ports typogard to Rust, and can be used to detect potential typosquatting as a reusable library that can be adapted to any registry. They've also tightened admin privileges for Rust's package registry, according to the article. And "In addition to the work on the Security Initiative, the Foundation has also been working on improving interoperability between Rust and C++, supported by a $1 million contribution from Google." According to the Rust foundation's technology director, they've made "impressive technical strides and developed new strategies to reinforce the safety, security, and longevity of the Rust programming language." And the director says the new report "paints a clear picture of the impact of our technical projects like the Security Initiative, Safety-Critical Rust Consortium, infrastructure and crates.io support, Interop Initiative, and much more."Read more of this story at Slashdot.
Did Online Dating Increase US Income Inequality?
With online dating apps, "Americans have increasingly been marrying someone more like themselves," reports Bloomberg, citing new research that says this accounts for roughly half of the rise in household income inequality between 1980 and 2020: Using data from the Census Bureau's American Community Survey from 2008 to 2021, when online dating quickly became prevalent, the economists found that women became slightly more selective when choosing partners based on age, while men became slightly more selective based on education. But when the researchers compared that with data on married couples from 1960 and 1980, they found that people in the recent period increasingly went for partners with the same wage and education levels... Overall, the predominance of online apps to find a future partner has led to a 3-percentage-point increase in the Gini coefficient - a widely used measure of income inequality, the research shows. The reseachers were from the Federal Reserve Banks of Dallas and St. Louis, and from Haverford College, according to the article - which also includes this quote from their paper. "We find that the increase in income inequality over the past half a century is explained to a large extent by sorting on vertical characteristics, such as income and skill, and their interaction with education."Read more of this story at Slashdot.
What a Google Exec Learned After 7 Years Trying to Give AI a Robot Body
Wired published some thoughts from Hans Peter Brondmo, the former head of "Google's seven-year mission to give AI a robot body". An anonymous reader shared this report from Axios:Building AI-powered robots that can flexibly operate in the real world is going to take much longer than Silicon Valley believes and promises, according to the former head of Google's robotics moonshot project, writing in Wired... Everyday Robotics spent seven years and a small Google fortune developing a one-armed robot on a wheeled platform. By the time Google pulled the plug on the project in February 2023, the robots were helping clean up researchers' desks and sorting trash during the daytime; in the evening, they were improvising dances. [Google hired a professional dancer as an artist-in-residence who teamed with "a few other engineers" to build an AI algorithm trained on the dancer's choreography preferences...] Google founder Larry Page - favored moving directly to "end to end" (e2e) learning, where you'd hand robots a general task and they'd be able to figure out how to execute it. That, Page felt, was a goal worthy of a moonshot. But it also turned out to be out of reach. "I have come to believe," Brondmo writes, "it will take many, many thousands, maybe even millions of robots doing stuff in the real world to collect enough data to train e2e models that make the robots do anything other than fairly narrow, well-defined tasks...." ["Building robots that perform useful services - like cleaning up and wiping all the tables in a restaurant, or making the beds in a hotel - will require both AI and traditional programming for a long time to come. In other words, don't expect robots to go running off outside our control, doing something they weren't programmed to do, anytime soon."] The bottom line: So far, robot hype is outpacing robot reality. Boston Dynamics' back-flipping humanoid and quadruped bots have wowed YouTube viewers - but you wouldn't want to let them anywhere near your office or home. It's an interesting look back. "My job: help figure out what to do with the employees and technology left over from nine robot companies that Google had acquired," Brondmo writes:Andy "the father of Android" Rubin, who had previously been in charge, had suddenly left. Larry Page and Sergey Brin kept trying to offer guidance and direction during occasional flybys in their "spare time...." I knew from firsthand experience how hard it was to build a company that, in Steve Jobs' famous words, could put a dent in the universe, and I believed that Google was the right place to make certain big bets. AI-powered robots, the ones that will live and work alongside us one day, was one such audacious bet. Eight and a half years later - and 18 months after Google decided to discontinue its largest bet in robotics and AI - it seems as if a new robotics startup pops up every week. I am more convinced than ever that the robots need to come. Yet I have concerns that Silicon Valley, with its focus on "minimum viable products" and VCs' general aversion to investing in hardware, will be patient enough to win the global race to give AI a robot body. And much of the money that is being invested is focusing on the wrong things... When I arrived, the lab had already hatched Waymo, Google Glass, and other science-fiction-sounding projects like flying energy windmills and stratospheric balloons that would provide internet access to the underserved... [But] in January 2023, two months after OpenAI introduced ChatGPT, Google shut down Everyday Robots, citing overall cost concerns. The robots and a small number of people eventually landed at Google DeepMind to conduct research. In spite of the high cost and the long timeline, everyone involved was shocked. They'd tackled the problem with earnestness. ("[S]even robots working for months to learn how to pick up a rubber duckling? That wasn't going to cut it... So we built a cloud-based simulator and, in 2021, created more than 240 million robot instances in the sim.ma") Brondmo adds this his mother had advanced Parkinson's disease, and hoped that one day robots could support her. "Our frequent conversations toward the end of her life convinced me more than ever that a future version of what we started at Everyday Robots will be coming. In fact, it can't come soon enough. "So the question we are left to ponder becomes: How does this kind of change and future happen? I remain curious, and concerned."Read more of this story at Slashdot.
'Samba' Networking Protocol Project Gets Big Funding from the German Sovereign Tech Fund
Samba is "a free software re-implementation of the SMB networking protocol," according to Wikipedia. And now the Samba project "has secured significant funding (688,800.00) from the German Sovereign Tech Fund to advance the project," writes Jeremy Allison - Sam (who is Slashdot reader #8,157 - and also a long standing member of Samba's core team):The investment was successfully applied for by [information security service provider] SerNet. Over the next 18 months, Samba developers from SerNet will tackle 17 key development subprojects aimed at enhancing Samba's security, scalability, and functionality. The Sovereign Tech Fund is a German federal government funding program that supports the development, improvement, and maintenance of open digital infrastructure. Their goal is to sustainably strengthen the open source ecosystem. The project's focus is on areas like SMB3 Transparent Failover, SMB3 UNIX extensions, SMB-Direct, Performance and modern security protocols such as SMB over QUIC. These improvements are designed to ensure that Samba remains a robust and secure solution for organizations that rely on a sovereign IT infrastructure. Development work began as early as September the 1st and is expected to be completed by the end of February 2026 for all sub-projects. All development will be done in the open following the existing Samba development process. First gitlab CI pipelines have already been running and gitlab MRs will appear soon! Back in 2000, Jeremy Allison answered questions from Slashdot readers about Samba. Allison is now a board member at both the GNOME Foundation and the Software Freedom Conservancy, a distinguished engineer at Rocky Linux creator CIQ, and a long-time free software advocate.Read more of this story at Slashdot.
Haiku (Originally 'OpenBeOS') Releases Long Awaited R1/Beta5
An anonymous Slashdot reader writes: Haiku (the MIT-licensed operating system, inspired by BeOS) has released its fifth beta for Haiku R1. Some new features include improved UI color management, improved dark mode coloring, Tracker improvements, TUN/TAP support for VPN connections, TCP throughput improvements, performance optimizations, UFS2 (BSD's filesystem) read-only support, new FAT filesystem driver, improved hardware support, improved POSIX compliance, improved performance, and more. Slashdot has been covering the fate of the BeOS since 2000 (as well as the short-lived derivative project ZETA - and Haiku). And now "With a history of over two decades and previously known as OpenBeOS, today's Haiku is pushing forward..." writes the site NotebookCheck:Haiku is a spiritual successor to BeOS, with a focus on a clean and user-friendly design paired with low system requirements. The minimum system requirements are still an Intel Pentium II/AMD Athlon CPU or better, at least 384 MB RAM, an 800x600 screen, and at least 3GB storage. It works on both 32-bit and 64-bit x86 PCs, and the 32-bit version can run many unmodified BeOS applications. It might be the best desktop open-source operating system not based on Linux or Unix... It works well in a virtual machine like VirtualBox or UTM.Read more of this story at Slashdot.
Microsoft Axed 650 Gaming Employees Two Days After Hosting 'AI Labor Summit'
"A two-day AI Labor Summit between AFL-CIO leaders and Microsoft executives this week reflects the tech giant's revamped approach to unions," writes GeekWire, "which includes a pledge by the company to incorporate feedback from labor unions and their members into the development of artificial intelligence." But just two days later, "Microsoft Gaming CEO Phil Spencer announced it was game over for the jobs of another 650 Microsoft staffers (on top of an earlier 1,900 employee staff reduction)," writes long-time Slashdot reader theodp, "cuts that Spencer made clear were related to Microsoft's $69B acquisition of Activision Blizzard in 2023."Interestingly, Microsoft's Smith in October 2023 affirmed a "groundbreaking neutrality agreement" with the Communications Workers of America union (CWA) - designed to go into effect if Microsoft was successful in its acquisition of Activision Blizzard - in which Microsoft acknowledged the rights of its employees to unionize and pledged to work constructively with any who did. At the same time, Microsoft made it clear that it hoped its employees wouldn't feel the need to form or join unions, saying they would "never need to organize to have a dialogue with Microsoft's leaders." In July 2023, the AFL-CIO applauded Microsoft's Activision Blizzard acquisition and the Microsoft-CWA agreement, which AFL-CIO union federation president Liz Shuler said "sets a new standard for respecting workers' rights in the video game industry and the larger technology sector." And in December 2023, Shuler thanked Smith for Microsoft's "absolutely historic partnership" on AI and the Future of the Workforce, which Shuler suggested "can be mutually beneficial for workers, for businesses, and for our country as a whole." Thursday the CWA union issued critical remarks about the layoffs at Microsoft Gaming (which were later retweeted by the @AFLCIO Twitter account). "While we would hope that a company like Microsoft with $88 billion in profits last year could achieve 'long-term success' without destroying the livelihoods of 650 of our colleagues, heartless layoffs like these have become all too common."Read more of this story at Slashdot.
JavaScript, Python, Java: Redmonk's Programming Language Ranking Sees Lack of Change
Redmonk's latest programming language ranking (attempting to gauge "potential future adoption trends") has found evidence of "a landscape resistant to change."Outside of CSS moving down a spot and C++ moving up one, the Top 10 was unchanged. And even in the back half of the rankings, where languages tend to be less entrenched and movement is more common, only three languages moved at all... There are a few signs of languages following in TypeScript's footsteps and working their way up the path, both in the Top 20 and at the back end of the Top 100 as we'll discuss shortly, but they're the exception that proves the rule. It's possible that we'll see more fluid usage of languages, and increased usage of code assistants would theoretically make that much more likely, but at this point it's a fairly static status quo. With that, some results of note: - TypeScript (#6): technically TypeScript didn't move, as it was ranked sixth in our last run, but this is the first quarter in which is has been the sole occupant of that spot. CSS, in this case, dropped one place to seven leaving TypeScript just outside the Top 5. It will be interesting to see whether or not it has more momentum to expend or whether it's topped out for the time being. - Kotlin (#14) / Scala (#14): both of these JVM-based languages jumped up a couple of spots - two spots in Scala's case and three for Kotlin. Scala's rise is notable because it had been on something of a downward trajectory from a one time high of 12th, and Kotlin's placement is a mild surprise because it had spent three consecutive runs not budging from 17, only to make the jump now. The tie here, meanwhile, is interesting because Scala's long history gives it an accretive advantage over Kotlin's more recent development, but in any case the combination is evidence of the continued staying power of the JVM. - Objective C (#17): speaking of downward trajectories and the 17th placement on this list, Objective C's slide that began in mid-2018 continued and left the language with its lowest placement in these rankings to date at #17. That's still an enormously impressive achievement, of course, and there are dozens of languages that would trade their usage for Objective C's, but the direction of travel seems clear. - Dart (#19) / Rust (#19): while once grouped with Kotlin as up and coming languages driven by differing incentives and trends, Dart and Rust have not been able to match the ascent of their counterpart with five straight quarters of no movement. That's not necessarily a negative; as with Objective C, these are still highly popular languages and communities, but it's worth questioning whether new momentum will arrive and from where, particularly because the communities are experiencing some friction in growing their usage. It's important to remember Redmonk's methodology. "We extract language rankings from GitHub and Stack Overflow, and combine them for a ranking that attempts to reflect both code (GitHub) and discussion (Stack Overflow) traction. The idea is not to offer a statistically valid representation of current usage, but rather to correlate language discussion and usage in an effort to extract insights into potential future adoption trends." Having said that, here's the current top ten in Redmonk's ranking: JavaScript Python Java PHP C# TypeScript CSS C++ Ruby CTheir announcement also notes that at the other end of the list, the programming language Bicep "jumped eight spots to #78 and Zig 10 to #87. That progress pales next to Ballerina, however, which jumped from #80 to #61 this quarter. The general purpose language from WS02, thus, is added to the list of potential up and comers we're keeping an eye on."Read more of this story at Slashdot.
Microsoft, Google, Meta, and Amazon Fight Calls to Pay More for Electric Grid Updates
The Washingon Post reports that a regulatory dispute in Ohio may help answer a big question about America's power grid: who will pay for the huge upgrades needed to meet soaring energy demand "from the data centers powering the modern internet and artificial intelligence revolution?"Google, Amazon, Microsoft and Meta are fighting a proposal by an Ohio power company to significantly increase the upfront energy costs they'll pay for their data centers, a move the companies dubbed "unfair" and "discriminatory" in documents filed with Ohio's Public Utility Commission last month. American Electric Power Ohio said in filings that the tariff increase was needed to prevent new infrastructure costs from being passed on to other customers such as households and businesses if the tech industry should fail to follow through on its ambitious, energy-intensive plans. The case could set a national precedent that helps determine whether and how other states force tech firms to be accountable for the costs of their growing energy consumption... The energy demands of data centers have created similar concerns in other hot spots such as Northern Virginia, Atlanta and Maricopa County, Arizona, leaving experts concerned that the U.S. power grid may not be capable of dealing with the combined needs of the green energy transition and the computing boom that artificial intelligence companies say is coming... Energy customers must sometimes make a monthly payment to a utility that is a percentage of the maximum amount of electricity they predict that they could need. In Ohio, data center companies had agreed to pay 60 percent of the projected amount. But in May, the power company proposed a new, 10-year fee structure raising the charges to 90 percent of the expected load, even if they don't end up using that much. The major tech companies - all of whom are increasing spending on data center infrastructure to compete in AI - strenuously opposed the proposed contract in documents filed last month... According to testimony from AEP Ohio Vice President Lisa Kelso, there are 50 pending requests from data center customers seeking electric service at more than 90 sites, a potential 30,000 megawatts of additional load - enough to power more than 20 million households. That additional demand would more than triple the utility's previous peak load in 2023, she said. Between 2020 and 2024, the data center energy load in central Ohio increased sixfold, from 100 to 600 megawatts, her testimony reads. By 2030, that amount will reach 5,000 megawatts, according to the utility's signed agreements, she testified... Meeting that demand will require AEP Ohio to build new transmission lines, an expensive and time-consuming process... Chief among the power company's concerns, according to the documents, is what will happen if it invests billions of dollars into new grid infrastructure only for the data centers to leave for greener pastures, or for the AI bubble to burst and the facilities to need much less power than initially projected. If the power company spends big on new infrastructure but the power demand it was built to serve doesn't materialize, other customers - including business and residential payers - will be stuck with the bill, the utility said... AEP Ohio's testimony in the case also questions whether data centers bring as much to local communities as factories or other high-energy-load businesses. Since 2019, non-data center businesses have created approximately 25 jobs for every megawatt of power requested, while data centers have created less than one job per megawatt, according to Kelso's testimony. The tech companies rejected this criticism, saying the number of jobs they create is not relevant to how much power they have a right to purchase, and highlighted their other contributions to local economies... Amazon said in filings that it pays fees as high as 75 percent of projected demand in some states but that Ohio's proposal to bill it 90 percent goes too far. "Should the Ohio tariff be approved, Microsoft and Google both threatened in their testimony to leave Ohio." (Although at the same time, "pressure on the electric grid is mounting all over the country...") And the article points out that on Thursday, "the White House announced measures intended to speed up data center construction for AI projects, including by accelerating permitting."Read more of this story at Slashdot.
Eminent Officials Say NASA Facilities Some of the 'Worst' They've Ever Seen
Ars Technica's Stephen Clark reports: A panel of independent experts reported this week that NASA lacks funding to maintain most of its decades-old facilities, could lose its engineering prowess to the commercial space industry, and has a shortsighted roadmap for technology development. "NASA's problem is it always seems to have $3 billion more program than it has of funds," said Norm Augustine, chair of the National Academies panel chartered to examine the critical facilities, workforce, and technology needed to achieve NASA's long-term strategic goals and objectives. Augustine said a similar statement could sum up two previous high-level reviews of NASA's space programs that he chaired in 1990 and 2009. But the report released Tuesday put NASA's predicament in stark terms. "In NASA's case, the not-uncommon tendency in a constrained budget environment to prioritize initiating new missions as opposed to maintaining and upgrading existing support assets has produced an infrastructure that would not be viewed as acceptable under most industrial standards," the panel wrote in its report. "In fact, during its inspection tours, the committee saw some of the worst facilities many of its members have ever seen." All of NASA's centers have facilities the agency considers marginal, but Johnson Space Center in Houston has the facilities with the worst average score. Johnson oversees astronaut training and is home to NASA's Mission Control Center for the International Space Station and future Artemis lunar missions. The Jet Propulsion Laboratory in California, which develops and operates many of NASA's robotic interplanetary probes, and Stennis Space Center in Mississippi, used for rocket engine testing, are the only centers without a poor infrastructure score. These ratings cover things like buildings and utilities, not the specific test rigs or instruments inside them. "You can have a world-class microscope and materials lab, but if the building goes down, that microscope is useless to you," [Erik Weiser, NASA's director of facilities and real estate] told the National Academies panel in a meeting last year. The panel recommended that Congress direct NASA to establish an annually replenished revolving working capital fund to pay for maintenance and infrastructure upgrades. Other government agencies use similar funds for infrastructure support. "This is something that will require federal legislation," said Jill Dahlburg, a member of the National Academies panel and former superintendent of the space science division at the Naval Research Laboratory.Read more of this story at Slashdot.
34th First Annual Ig Nobel Prizes Awarded
Longtime Slashdot reader davidwr writes: Winners of the 34th First Annual Ig Nobel Prizes included studies on hair swirling (natural, not from grade-school bathroom torture), mammals that breath through their anal orifices, and a study on pigeon-guided missiles. There were also prizes for the study of the swimming abilities of a formerly-living trout. "Honors" were also bestowed for research in coin-flipping (no, it's not 50/50), why cows spew milk, and drunken worms, among other topics. Prizes included $10,000,000,000 (in now-worthless Zimbabwe dollars) and items related to Murphy's Law. Media coverage includes AP, CNN, Gizmodo, Ars Technica, and by the time you read this, probably much more.Read more of this story at Slashdot.
Stranded Astronauts Make First Public Statement Since Being Left Behind On ISS
An anonymous reader quotes a report from CBC News: Stranded astronauts Butch Wilmore and Suni Williams said Friday it was hard to watch their Boeing capsule return to Earth without them. It was their first public comments since last week's return of the Boeing Starliner capsule that took them to the International Space Station in June. They remained behind after NASA determined the problem-plagued capsule posed too much risk for them to ride back in. "That's how it goes in this business," said Williams, adding that "you have to turn the page and look at the next opportunity." Wilmore and Williams are now full-fledged station crew members, chipping in on routine maintenance and experiments. They, along with seven others on board, welcomed a Soyuz spacecraft carrying two Russians and an American earlier this week, temporarily raising the station population to 12, a near record. NASA astronauts Butch Wilmore and Suni Williams spoke to the press on Friday for the first time since their Boeing Starliner capsule returned to Earth without them. The two, who have been on the International Space Station since June 6, said they are taking the mission's unexpected extension into 2025 in stride -- even if it means they've had to change their voting plans. The transition to station life was "not that hard" since both had previous stints there, said Williams, who will soon take over as station commander. "This is my happy place. I love being up here in space," she said. The two Starliner test pilots -- both retired U.S. navy captains and longtime NASA astronauts - will stay at the orbiting laboratory until late February. They have to wait for a SpaceX capsule to bring them back. That spacecraft is due to launch later this month with a reduced crew of two, with two empty seats for Wilmore and Williams for the return leg. The duo said they appreciated all the prayers and well wishes from strangers back home. Wilmore said he will miss out on family milestones such as being around for his youngest daughter's final year of high school. The astronauts, who prepared for eight days in space, will now be up there for eight months, which could have a greater impact on the body. "It is a bit of a change from a sprint to a marathon," said Dr. Adam Sirek of the Canadian Society of Aerospace Medicine.Read more of this story at Slashdot.
23andMe To Pay $30 Million In Genetics Data Breach Settlement
23andMe has agreed to pay $30 million to settle a lawsuit over a data breach that exposed the personal information of 6.4 million customers in 2023. BleepingComputer reports: The proposed class action settlement (PDF), filed Thursday in a San Francisco federal court and awaiting judicial approval, includes cash payments for affected customers, which will be distributed within ten days of final approval. "23andMe believes the settlement is fair, adequate, and reasonable," the company said in a memorandum filed (PDF) Friday. 23andMe has also agreed to strengthen its security protocols, including protections against credential-stuffing attacks, mandatory two-factor authentication for all users, and annual cybersecurity audits. The company must also create and maintain a data breach incident response plan and stop retaining personal data for inactive or deactivated accounts. An updated Information Security Program will also be provided to all employees during annual training sessions. "23andMe denies the claims and allegations set forth in the Complaint, denies that it failed to properly protect the Personal Information of its consumers and users, and further denies the viability of Settlement Class Representatives' claims for statutory damages," the company said in the filed preliminary settlement. "23andMe denies any wrongdoing whatsoever, and this Agreement shall in no event be construed or deemed to be evidence of or an admission or concession on the part of 23andMe with respect to any claim of any fault or liability or wrongdoing or damage whatsoever."Read more of this story at Slashdot.
Google Is Now Rolling Out Gemini Live For All Android Users
Gemini Live is rolling out its Live Voice Mode for all Android users, allowing them to hold real-time, interactive voice conversations with Gemini. "Previously locked into conventional text-based input and responses, Gemini Live Voice Mode gives hands-free ways to explore ideas, brainstorm, and talk through topics in real-time," reports Tom's Guide. From the report: This new voice feature is integrated into the Android Gemini app, so users need to update their app or download it from the Google Play Store if they haven't already done so. Once installed, users can turn on Live Voice Mode and start talking directly to Gemini. Do you want to get your thoughts sorted out or chat? It's fast and interactive, and no typing is required in this mode. Users can have voice conversations on virtually anything. Suppose one is stuck with a complex project and needs a fresh perspective or researching a new hobby or course of study and wants to flesh out the subject by talking it out with Gemini. It promises to offer rich insight and ideas through conversation so that one's productivity and creativity are enhanced in ways that, up until now, have been possible only with human dialogue. [...] The main advantage of Gemini Live Voice Mode is that it is interactive. A voice assistant would respond to a question you pose in voice, while with the live voice mode in Gemini, the dialogue sounds and feels more natural, with a tone that takes on that of the discussion and facilitates a back-and-forth interaction style. You can ask follow-up questions, clarify misunderstandings, or refine your ideas as you speak, making it more like a collaboration than a simple Q&A.Read more of this story at Slashdot.
US Takes Aim At Shein and Temu With New Import Rule Proposal
The Biden administration is proposing new rules to limit the "de minimis" exemption, which some Chinese e-commerce companies like Shein and Temu use to ship low-cost goods under $800 to U.S. customers without tariffs. The changes would subject certain shipments to closer inspection and tariffs, aiming to protect American consumers and businesses by ensuring a level playing field against Chinese platforms that have exploited this loophole. The Verge reports: Under the proposed rules, the US will prevent companies from claiming the de minimis exemption if their goods are covered by Section 301, Section 232, and Section 201 tariffs, which apply to products from China, steel, and aluminum, as well as washing machines and solar panels. In addition to slapping these shipments with tariffs, the rule change would subject them to closer inspection by US Customs and Border Protection. The Biden administration said the proposal would help "protect consumers from goods that do not meet regulatory health and safety standards." Even though Shein is headquartered in Singapore, it's known for cheap fast fashion that's mainly manufactured in China. The China-based Temu sells clothes, household items, electronics, and a variety of other goods made in the country as well.Read more of this story at Slashdot.
1.3 Million Android-Based TV Boxes Backdoored; Researchers Still Don't Know How
An anonymous reader quotes a report from Ars Technica: Researchers still don't know the cause of a recently discovered malware infection affecting almost 1.3 million streaming devices running an open source version of Android in almost 200 countries. Security firm Doctor Web reported Thursday that malware named Android.Vo1d has backdoored the Android-based boxes by putting malicious components in their system storage area, where they can be updated with additional malware at any time by command-and-control servers. Google representatives said the infected devices are running operating systems based on the Android Open Source Project, a version overseen by Google but distinct from Android TV, a proprietary version restricted to licensed device makers. Although Doctor Web has a thorough understanding of Vo1d and the exceptional reach it has achieved, company researchers say they have yet to determine the attack vector that has led to the infections. "At the moment, the source of the TV boxes' backdoor infection remains unknown," Thursday's post stated. "One possible infection vector could be an attack by an intermediate malware that exploits operating system vulnerabilities to gain root privileges. Another possible vector could be the use of unofficial firmware versions with built-in root access." The following device models infected by Vo1d are: [R4, TV BOX, KJ-SMART4KVIP]. One possible cause of the infections is that the devices are running outdated versions that are vulnerable to exploits that remotely execute malicious code on them. Versions 7.1, 10.1, and 12.1, for example, were released in 2016, 2019, and 2022, respectively. What's more, Doctor Web said it's not unusual for budget device manufacturers to install older OS versions in streaming boxes and make them appear more attractive by passing them off as more up-to-date models. Further, while only licensed device makers are permitted to modify Google's AndroidTV, any device maker is free to make changes to open source versions. That leaves open the possibility that the devices were infected in the supply chain and were already compromised by the time they were purchased by the end user. "These off-brand devices discovered to be infected were not Play Protect certified Android devices," Google said in a statement. "If a device isn't Play Protect certified, Google doesn't have a record of security and compatibility test results. Play Protect certified Android devices undergo extensive testing to ensure quality and user safety." Users can confirm if their device runs Android TV OS via this link and following the steps here.Read more of this story at Slashdot.
Sam Bankman-Fried Files Appeal For Fraud Conviction
Former FTX CEO Sam Bankman-Fried's legal team has filed an appeal challenging his conviction on seven felony counts and his 25-year prison sentence. They argue that he was not presumed innocent, that the jury received incomplete information about FTX user funds, and that the prosecution's narrative was biased. CoinTelegraph reports: In a Sept. 13 filing in the United States Court of Appeals for the Second Circuit, SBF's lawyers filed a 102-page brief claiming that the former FTX CEO was "never presumed innocent," subject to scrutiny that allegedly affected prosecutors, the presiding judge, and treatment by the media. Bankman-Fried's legal team announced in April -- a few weeks after a federal judge sentenced him to 25 years in prison -- that they intended to appeal. According to the appeal, SBF's lawyers alleged the jury was "only allowed to see half the picture" with FTX user funds, claiming prosecutors had "presented a false narrative" that the money was permanently lost and Bankman-Fried intentionally caused that loss. They also claimed that counsel for the FTX debtors worked with the US government in a way that was above and beyond "cooperation," providing information allegedly as an "arm of the prosecution." "From day one, the prevailing narrative -- initially spun by the lawyers who took over FTX, quickly adopted by their contacts at the US Attorney's Office -- was that Bankman-Fried had stolen billions of dollars of customer funds, driven FTX to insolvency, and caused billions in losses," said the appeal. "Now, nearly two years later, a very different picture is emerging -- one confirming FTX was never insolvent, and in fact had assets worth billions to repay its customers. But the jury at Bankman-Fried's trial never got to see that picture." The legal team requested the appellate court grant SBF a new trial with a different judge. It's unclear whether the Second Circuit could rule to affirm Bankman-Fried's conviction in the US District Court for the Southern District of New York or reverse the decision and set the groundwork for a new trial.Read more of this story at Slashdot.
iFixit Launches FixHub Portable USB-C Soldering System To Encourage Repair Projects
iFixit has created its own USB-C soldering iron and portable power station called FixHub, "designed to allow all types of users to handle soldering work wherever they may be," reports MacRumors. From the report: The Portable Power Station serves as the command and power center for FixHub, including a 55-watt-hour battery to support over eight hours of continuous soldering on a single charge. The power supply delivers up to 100 watts to a pair of USB-C ports, allowing it to run two soldering irons simultaneously, and the fact that it's simply a USB-C power output device means you can also use it to power or recharge an array of devices like phones. The solidly built power station includes a handy display to show the status of your soldering iron, along with a convenient dial for adjusting the power being delivered to the iron, supporting temperatures up to 400C (750F). A flip-up bracket raises the front of the power station a bit to make the display easier to see while in use, while attachment points on the left and right side allow you to clip on the soldering iron's cap for convenient access as a stand. A USB-C port on the rear of the power station allows for up to 45 watts of input to recharge the station, and iFixit says it is safe to leave continuously connected to power so it's ready whenever you need it. [...] iFixit is of course known for more than just hardware, and it has hundreds of free soldering guides on its website, ranging from the basics of soldering to specific repair projects. It also wouldn't be an iFixit product without repairability being front of mind, so the FixHub system is designed to allow for easy repairs and iFixit will be releasing a number of guides to help users replace batteries, repair parts, and more. Supplementing the FixHub is an optional Portable Soldering Toolkit, which provides an extensive set of tools and consumables to get you going on soldering projects. The USB Smart Soldering Iron and Portable Soldering Station are priced at $79.95 and $249.95, respectively.Read more of this story at Slashdot.
Apple Vision Pro's Eye Tracking Exposed What People Type
An anonymous reader quotes a report from Wired: You can tell a lot about someone from their eyes. They can indicate how tired you are, the type of mood you're in, and potentially provide clues about health problems. But your eyes could also leak more secretive information: your passwords, PINs, and messages you type. Today, a group of six computer scientists are revealing a new attack against Apple's Vision Pro mixed reality headset where exposed eye-tracking data allowed them to decipher what people entered on the device's virtual keyboard. The attack, dubbed GAZEploit and shared exclusively with WIRED, allowed the researchers to successfully reconstruct passwords, PINs, and messages people typed with their eyes. "Based on the direction of the eye movement, the hacker can determine which key the victim is now typing," says Hanqiu Wang, one of the leading researchers involved in the work. They identified the correct letters people typed in passwords 77 percent of the time within five guesses and 92 percent of the time in messages. To be clear, the researchers did not gain access to Apple's headset to see what they were viewing. Instead, they worked out what people were typing by remotely analyzing the eye movements of a virtual avatar created by the Vision Pro. This avatar can be used in Zoom calls, Teams, Slack, Reddit, Tinder, Twitter, Skype, and FaceTime. The researchers alerted Apple to the vulnerability in April, and the company issued a patch to stop the potential for data to leak at the end of July. It is the first attack to exploit people's "gaze" data in this way, the researchers say. The findings underline how people's biometric data -- information and measurements about your body -- can expose sensitive information and beused as part of the burgeoning surveillance industry. The GAZEploit attack consists of two parts, says Zhan, one of the lead researchers. First, the researchers created a way to identify when someone wearing the Vision Pro is typing by analyzing the 3D avatar they are sharing. For this, they trained a recurrent neural network, a type of deep learning model, with recordings of 30 people's avatars while they completed a variety of typing tasks. When someone is typing using the Vision Pro, their gaze fixates on the key they are likely to press, the researchers say, before quickly moving to the next key. "When we are typing our gaze will show some regular patterns," Zhan says. Wang says these patterns are more common during typing than if someone is browsing a website or watching a video while wearing the headset. "During tasks like gaze typing, the frequency of your eye blinking decreases because you are more focused," Wang says. In short: Looking at a QWERTY keyboard and moving between the letters is a pretty distinct behavior. The second part of the research, Zhan explains, uses geometric calculations to work out where someone has positioned the keyboard and the size they've made it. "The only requirement is that as long as we get enough gaze information that can accurately recover the keyboard, then all following keystrokes can be detected." Combining these two elements, they were able to predict the keys someone was likely to be typing. In a series of lab tests, they didn't have any knowledge of the victim's typing habits, speed, or know where the keyboard was placed. However, the researchers could predict the correct letters typed, in a maximum of five guesses, with 92.1 percent accuracy in messages, 77 percent of the time for passwords, 73 percent of the time for PINs, and 86.1 percent of occasions for emails, URLs, and webpages. (On the first guess, the letters would be right between 35 and 59 percent of the time, depending on what kind of information they were trying to work out.) Duplicate letters and typos add extra challenges.Read more of this story at Slashdot.
Why Do We Crumble Under Pressure? Science Has the Answer
Have you ever been in a high-stakes situation in which you needed to perform but completely bombed? You're not alone. Experiments in monkeys reveal that 'choking' under pressure is linked to a drop in activity in the neurons that prepare for movement. Nature: "You see it across the board, you see it in sports, in all kinds of different sports and outside of sports as well." says Steven Chase, a neuroscientist at Carnegie Mellon University in Pittsburgh, Pennsylvania. Chase and his colleagues investigated what happens in the brain that causes performance to plummet, and published their findings in Neuron on 12 September. Choking under pressure is not unique to humans. In the same way that a tennis player might miss a match-winning shot, monkeys can also underperform in high-reward situations. The team set up a computer task in which rhesus monkeys received a reward after quickly and accurately moving a cursor over a target. Each trial gave the monkeys cues as to whether the reward would be small, medium-sized, large or 'jackpot'. Jackpot rewards were rare and unusually big, creating a high-stakes, high-reward situation. Using a tiny, electrode-covered chip implanted into the monkeys' brains, the team watched how neuronal activity changed between reward scenarios. The chip was situated on the motor cortex, an area of the frontal lobe that controls movement. The researchers found that, in jackpot scenarios, the activity of neurons associated with motor preparation decreased. Motor preparation is the brain's way of making calculations about how to complete a movement -- similar to lining up an arrow on a target before unleashing it. The drop in motor preparation meant that the monkey's brains were underprepared, and so they underperformed. The results "help us understand how reward-outcome-mediated behaviour is not linear," says Bita Moghaddam, a behavioural neuroscientist at Oregon Health & Science University in Portland. To a certain extent, "you just don't perform better as the reward increases," Moghaddam says. It would also be interesting to see how other brain regions respond in jackpot-reward situations, she adds, because multiple regions could be involved.Read more of this story at Slashdot.
PC Giants Predict Delayed but Massive Upgrade Wave
Dell and HP executives have acknowledged a delay in the anticipated commercial PC refresh cycle. Michael Dell, speaking at the Citi 2024 Global TMT conference, stated that the refresh cycle "has been delayed for sure." The Register adds: Without offering any reasons for postponement -- and not being pressed for one by the analyst interviewing him -- the billionaire reckoned the size of the refresh is "going to be even bigger" because of it. "So first of all we have a certain date with Windows 10 end-of-life and we're almost within a one year window of that, and as you get in that one-year window, the enterprise IT people start screwing around and saying, 'Oh, we better do something about this'," said Dell. Enrique Lores, CEO at rival PC maker HP, who spoke at the Goldman Sachs Communacopia + Technology conference this week, agreed enterprises are also about to invest in new lines. "First of all there is a large and aging installed base on PCs. Many of these PCs were bought during COVID and now we are four [or] five years after they were bought and they will have to be replaced. "We also see an opportunity driven by the Windows 11 refresh that is only starting now... this is what is behind some of the strength that we see on the commercial side. Microsofta will start discontinuing their support for the previous versions, and this always ties the replacement and upgrade," he said, adding "this is going to be driving demand in the coming quarters."Read more of this story at Slashdot.
OpenAI Acknowledges New Models Increase Risk of Misuse To Create Bioweapons
OpenAI's latest models have "meaningfully" increased the risk that AI will be misused to create biological weapons [non-paywalled link], the company has acknowledged. From a report: The San Francisco-based company announced its new models, known as o1, on Thursday, touting their new abilities to reason, solve hard maths problems and answer scientific research questions. OpenAI's system card, a tool to explain how the AI operates, said the new models had a "medium risk" for issues related to chemical, biological, radiological and nuclear (CBRN) weapons -- the highest risk that OpenAI has ever given for its models. The company said it meant that the technology has "meaningfully improved" the ability of experts to create bioweapons. AI software with more advanced capabilities, such as the ability to perform step-by-step reasoning, pose an increased risk of misuse in the hands of bad actors, according to experts.Read more of this story at Slashdot.
Japan Rethinks 24/7 Police Boxes With Rise of Cybercrime
Japan is overhauling how its ubiquitous 24-hour mini-police stations are operated nationwide as more crime fighting moves from the streets to the web. From a report: Called koban in Japanese, officers at these small police boxes handle a variety of tasks from responding to crime and patrolling neighborhoods to handling lost items. There are also chuzaisho outposts where police officers live full-time. The National Police Agency will update operational rules on Friday to allow some outposts to shut down at night if necessary. It will also allow greater flexibility on the use of mobile or temporary outposts, depending on local needs and staffing considerations. Prefectural police will decide on changes involving specific outposts. Japan's koban system dates back to 1874 and is believed to have started operating around the clock in the 1880s. There were 6,215 kobans and 5,923 live-in outposts across Japan as of April. They have inspired countries like Singapore and Brazil to set up similar outposts focused on community policing. The change comes amid shifting crime patterns. Roughly 700,000 crime cases were reported in 2023, down more than 70% from the post-World War II peak in 2002. Street crime, like purse-snatching and car break-ins, were down around 80% to 240,000 cases. Instead, online and phone-based crimes, like impersonation scams and romance scams, are on the rise.Read more of this story at Slashdot.
...76777879808182838485...