Slashdot

Subscribe to Slashdot feed Slashdot
News for nerds, stuff that matters
Updated: 1 hour 14 min ago

Blaming Social Media, ACM Publication Argues Computing 'Has Blood On Its Hands'

Sun, 2024-01-07 05:34
Long-time Slashdot reader theodp writes: In the January 2024 Communications of the ACM, Rice University professor and former CACM Editor-in-Chief Moshe Y. Vardi minces no words in Computing, You Have Blood on Your Hands!. He argues that the unintended consequences of the rise of social media and mobile computing include hate mongering on a global scale and a worldwide youth mental health crisis. "How did the technology that we considered 'cool' just a decade ago become an assault weapon used to hurt, traumatize, and even kill vulnerable people?" Vardi asks. "Looking back at my past columns, one can see the forewarnings. Our obsession with efficiency came at the expense of resilience. In the name of efficiency, we aimed at eliminating all friction. In the name of efficiency, it became desirable to move fast and break things, and we allowed the technology industry to become dominated by a very small number of mega corporations. It is time for all computing professionals to accept responsibility for computing's current state. To use Star Wars metaphors, we once considered computing as the 'Rebels,' but it turns out that computing is the 'Empire.' Admitting we have a problem is a necessary first step toward addressing the problems computing has created." Examples cited in the piece include: Amnesty International's 2022 accusation that Meta "substantially contributed" to human rights violations of Myanmar's Rohingya peopleInternal Meta documents saying "We are not actually doing what we say we do publicly" in policing harmful content. So far the ACM's piece has attracted one comment. "Deep thanks for your long-term commitment to ethics and how you articulate clearly its challenges."

Read more of this story at Slashdot.

Categories: Linux fréttir

Can AI-Generated Proofs Bring Bug-Free Software One Step Closer?

Sun, 2024-01-07 02:34
The University of Massachusetts Amherst has an announcement. A team of computer scientists "recently announced a new method for automatically generating whole proofs that can be used to prevent software bugs and verify that the underlying code is correct." It leverages the AI power of Large Language Models, and the new method, called Baldur, "yields unprecedented efficacy of nearly 66%." The idea behind the machine-checking technique was "to generate a mathematical proof showing that the code does what it is expected to do," according to the announcement, "and then use a theorem prover to make sure that the proof is also correct. But manually writing these proofs is incredibly time-consuming and requires extensive expertise. "These proofs can be many times longer than the software code itself," says Emily First, the paper's lead author who completed this research as part of her doctoral dissertation at UMass Amherst... First, whose team performed its work at Google, used Minerva, an LLM trained on a large corpus of natural-language text, and then fine-tuned it on 118GB of mathematical scientific papers and webpages containing mathematical expressions. Next, she further fine-tuned the LLM on a language, called Isabelle/HOL, in which the mathematical proofs are written. Baldur then generated an entire proof and worked in tandem with the theorem prover to check its work. When the theorem prover caught an error, it fed the proof, as well as information about the error, back into the LLM, so that it can learn from its mistake and generate a new and hopefully error-free proof. This process yields a remarkable increase in accuracy. The state-of-the-art tool for automatically generating proofs is called Thor, which can generate proofs 57% of the time. When Baldur (Thor's brother, according to Norse mythology) is paired with Thor, the two can generate proofs 65.7% of the time. Though there is still a large degree of error, Baldur is by far the most effective and efficient way yet devised to verify software correctness, and as the capabilities of AI are increasingly extended and refined, so should Baldur's effectiveness grow. In addition to First and Brun, the team includes Markus Rabe, who was employed by Google at the time, and Talia Ringer, an assistant professor at the University of Illinois — Urbana Champaign. This work was performed at Google and supported by the Defense Advanced Research Projects Agency and the National Science Foundation.

Read more of this story at Slashdot.

Categories: Linux fréttir

America's First Large-Scale Offshore Wind Project Finally Begins Generating Electricity

Sat, 2024-01-06 23:45
A year ago the Washington Post reported "there are only seven working offshore wind turbines in the entire United States," adding that a massive wind project south of Martha's Vineyard, Massachusetts "is years behind schedule amid regulatory delays and litigation from opponents." But this week a local public radio station reported that electricity from America's first large-scale offshore wind project "is officially flowing into Massachusetts and helping to power the New England grid." The Vineyard Wind project achieved "first power" late Tuesday when one operating turbine near Martha's Vineyard delivered approximately five megawatts of electricity to the grid. The company said it expects to have five turbines operating at full capacity in early 2024... Once it's finished sometime in 2024, it will consist of 62 turbines spaced about a mile apart and rising more than 800 feet out of the water. The project will generate up to 800 megawatts of power, or about enough electricity for 400,000 homes in Massachusetts. Another smaller project near Long Island, South Fork Wind, also began producing electricity in early December. When that project is complete, its 12 turbines will generate about 132 megawatts of power... Massachusetts, in partnership with Rhode Island and Connecticut, is currently seeking bids for another 3,600 megawatts of offshore wind power... "This is a historic moment for the American offshore wind industry," wrote Gov. Maura Healey. "This is clean, affordable energy made possible by the many advocates, public servants, union workers, and business leaders who worked for decades to accomplish this achievement. Last year America's seven offshore wind turbines generated "a paltry 42 megawatts," according to the article, "far less than the average natural gas power plant." The CEO of one of the company's behind the project hailed the last 12 months as "a historic year defined by steel in the water and people at work."

Read more of this story at Slashdot.

Categories: Linux fréttir

Neptune Is Much Less Blue Than Depictions

Sat, 2024-01-06 22:45
Long-time Slashdot readers necro81 writes: The popular vision of Neptune is azure blue. This comes mostly from the publicly released images from Voyager 2's flyby in 1989 — humanity's only visit to this icy giant at the edge of the solar system. But it turns out that view is a bit distorted — the result of color-enhancing choices made by NASA at the time. A new report from Oxford depicts Neptune's blue color as more muted, with a touch of green, not much different than Uranus. The truer-to-life view comes from re-analyzing the Voyager data, combined with ground-based observations going back decades. (Add'l links here, here, and here.) This is nothing new: most publicity images released by space agencies — of planets, nebulae, or the surface of Mars — have undergone some color-enhancement for visual effect. (They'll also release "true-color" images, which try to best mimic what the human eye would see.) Many images — such as those from the infrared-seeing JWST — need wholesale coloration of their otherwise invisible wavelengths. The new report is a good reminder, though, to remember that scientific cameras are pretty much always black and white; color images come from combining filters in various ways. Also thanks to long-time Slashdot reader Geoffrey.landis for sharing the story.

Read more of this story at Slashdot.

Categories: Linux fréttir

Jabber Was Announced on Slashdot 25 Years Ago This Week

Sat, 2024-01-06 21:45
25 years ago, Slashdot's CmdrTaco posted an announcement from Slashdot reader #257. "Jabber is a new project I recently started to create a complete open-source platform for Instant Messaging with transparent communication to other Instant Messaging systems (ICQ, AIM, etc). "Most of the initial design and protocol work is done, as well as a working server and a few test clients." You can find the rest of the story on Wikipedia. "Its major outcome proved to be the development of the XMPP protocol." ("Based on XML, it enables the near-real-time exchange of structured data between two or more network entities.") Originally developed by the open-source community, the protocols were formalized as an approved instant messaging standard in 2004 and have been continuously developed with new extensions and features... In addition to these core protocols standardized at the IETF, the XMPP Standards Foundation (formerly the Jabber Software Foundation) is active in developing open XMPP extensions... XMPP features such as federation across domains, publish/subscribe, authentication and its security even for mobile endpoints are being used to implement the Internet of Things. "Designed to be extensible, the protocol offers a multitude of applications beyond traditional IM in the broader realm of message-oriented middleware, including signalling for VoIP, video, file transfer, gaming and other uses..." Slashdot reader #257 turned out to be Jeremie Miller (who at the time was just 23 years old). And according to his own page on Wikipedia, "Currently, Miller sits on the board of directors for Bluesky Social, a social media platform."

Read more of this story at Slashdot.

Categories: Linux fréttir

America's FAA Temporarily Grounds All Boeing 737 Max 9s - After a Window Blows Off In-Flight

Sat, 2024-01-06 20:44
Today America's Federal Aviation Administration "ordered the temporary grounding of Boeing 737 Max 9 aircraft," reports CNN, identifying the aircraft as "the model involved in an Alaska Airlines emergency landing in Oregon on Friday after a section of the plane apparently blew out in midflight." A passenger's video posted to social media shows a side section of the fuselage, where a window would have been, missing — exposing passengers to the outside air. The video, which appears to have been taken from several rows behind the incident, shows oxygen masks deployed throughout the airplane, and least two people sitting near and just behind the missing section... The plane "landed safely back at Portland International Airport with 171 guests and six crew members," the airline said... According to FlightAware, the flight was airborne for about 20 minutes. "There was a really loud bang toward the rear of the plane and a whoosh noise," one passenger told a local news station — and then "all of the masks dropped." The FAA said the planes must be parked until emergency inspections are performed, which will "take around four to eight hours per aircraft." "The FAA is requiring immediate inspections of certain Boeing 737 MAX 9 planes before they can return to flight," FAA Administrator Mike Whitaker said Saturday in a statement. "Safety will continue to drive our decision-making as we assist the (National Transportation Safety Board's) investigation into Alaska Airlines Flight 1282." The order impacts 171 Boeing 737 Max 9 jets, the agency approximates.... Boeing said the company supported the FAA's grounding decision. "Safety is our top priority and we deeply regret the impact this event has had on our customers and their passengers," Boeing said in a statement Thanks to long-time Slashdot reader lsllll for sharing the news.

Read more of this story at Slashdot.

Categories: Linux fréttir

Verizon Customers Could Get Up to $100 in $100M Settlement Over 'Administrative Charge' Fees

Sat, 2024-01-06 19:34
CNN reports that some Verizon customers "might have found an unexpected surprise in the mail this week: An opportunity to receive a refund as part of a proposed $100 million settlement from a class-action lawsuit." Eligible customers are receiving postcards or emails alerting them to file a claim by April 15 to receive up to $100, which is the result of the lawsuit accusing Verizon of charging fees that were "unfair and not adequately disclosed." At issue is Verizon's "administrative charge," which the plaintiffs said were "misleading" because that fee wasn't disclosed in their plan's advertised monthly price and were charged in a "deceptive and unfair manner." Verizon has denied the claims and said in a statement that it "clearly identifies and describes its wireless consumer admin charge multiple times during the sales transaction, as well as in its marketing, contracts and billing." A company spokesperson said that the charge "helps our company recover certain regulatory compliance and network related costs." "The payout is at least $15," adds CNN, "and might be more depending on how long the customer used Verizon and the number of customers who file a claim."

Read more of this story at Slashdot.

Categories: Linux fréttir

SpaceX Has Launched Starlink's First Direct-to-Smartphone Satellites

Sat, 2024-01-06 18:34
Tuesday's launch was different. "SpaceX launched its first batch of Starlink satellites designed to connect directly to unmodified smartphones..." reports SpaceNews, "after getting a temporary experimental license to start testing the capability in the United States." Six of the 21 Starlink satellites that launched on a Falcon 9 rocket at 10:44 p.m. Eastern from Vandenberg Space Force Base, California, carry a payload that the company said could provide connectivity for most 4G LTE devices when in range. SpaceX plans to start enabling texting from space this year in partnership with cellular operators, with voice and data connectivity coming in 2025, although the company still needs regulatory permission to provide the services commercially. Initial direct-to-smartphone tests would use cellular spectrum from SpaceX's U.S. mobile partner T-Mobile. SpaceX has also partnered with mobile operators in Australia, Canada, Chile, Japan, New Zealand, and Switzerland.... Meanwhile, early-stage ventures AST SpaceMobile and Lynk Global are closing in on fundraising deals to expand their dedicated direct-to-device constellations. AST SpaceMobile said January 2 it is seeking to secure funds this month from "multiple parties" ahead of launching its first five commercial satellites early this year on a Falcon 9. Lynk Global, which is currently providing intermittent texting and other low-bandwidth services to phones outside cellular networks in parts of the Solomon Islands, Cook Islands, and Palau, plans to raise funds by merging with a shell company run by former professional baseball player Alex Rodriguez.

Read more of this story at Slashdot.

Categories: Linux fréttir

More than a Third of America's EVs Were Bought Within the Last 12 Months

Sat, 2024-01-06 17:34
More than 4 million electric vehicles are now on America's roads. And Friday the U.S. Energy announced that more than a third of them (1.4 million) were sold within the last year. That's 50% more than were sold in the previous year — and about the same number sold in the entire five years between 2016 and 2021. But the energy secretary's statement also touts the current administrations efforts at "building out a reliable and interoperable nationwide EV charging network — an undertaking never before seen in the United States." Today, the U.S. has close to 170,000 public EV chargers — a 75% increase since the president took office with nearly 900 new chargers coming online per week. These developments are part of an inevitable shift toward a thriving electric transportation sector — a shift that American automakers and battery manufacturers are already carrying forward.

Read more of this story at Slashdot.

Categories: Linux fréttir

Google's Chrome Begins Purging Third-Party Cookies

Sat, 2024-01-06 16:34
"If you have been affected, you will will receive a notification when you open Chrome on either desktop or Android devices," reports Search Engine Land. But they add that "discussions among digital marketers on X indicate that advertisers are still not ready..." An anonymous reader writes: Google started its campaign to phase out of third-party cookies as announced earlier. At the beginning cookies are turned off for 1% of users, and those lucky ones unlock a "tracking protection" in Chrome settings. In agreement with the UK Competitions and Markets Authority, third-party cookies will be completely removed at the end of this year, a move under tight anti-competition scrutiny also in Brussels. Meanwhile, a technology researcher released their privacy audit of Google's third-party cookie replacement, Privacy Sandbox's Protected Audience API, validating its standing against EU data protection, which may even close the ever-present cookie consent popups disliked universally in Europe.

Read more of this story at Slashdot.

Categories: Linux fréttir

After Reports of His Own Wife's Plagiarism, Bill Ackman Threatens Plagiarism Reviews For All MIT Faculty

Sat, 2024-01-06 15:34
This week Harvard's president Claudine Gay resigned "after conservative activists revealed she had plagiarized," writes Business Insider, adding that hedge fund manager/prominent Harvard donor Bill Ackman "helped lead the charge." Then Business Insider "analyzed Ackman's wife's doctoral dissertation and found numerous instances of plagiarism." In most cases Ackman's wife put the author's name and publication date immediately after the material which she used — but did not put quotation marks around it. But according to the Business Insider, "At least 15 passages from her 2010 MIT doctoral dissertation were lifted without any citation from Wikipedia entries." Her husband, Ackman, has taken a hardline stance on plagiarism. On Wednesday, responding to news that Gay is set to remain a part of Harvard's faculty after she resigned as president, he wrote on X that Gay should be fired completely due to "serious plagiarism issues... Students are forced to withdraw for much less," Ackman continued. "Rewarding her with a highly paid faculty position sets a very bad precedent for academic integrity at Harvard." Ackman's wife was a tenured MIT professor from 2017 to 2021, according to the article. "It is unfortunate that my actions to address problems in higher education have led to these attacks on my family," Ackman posted Friday night on Twitter. Then Ackman threatened "a review of the work of all current MIT faculty members. We will begin with a review of the work of all current MIT faculty members, President Kornbluth, other officers of the Corporation, and its board members for plagiarism." Business Insider notes that Ackman "has been vocal about wanting to see MIT's president, Sally Kornbluth, fired since Kornbluth testified on December 5 in front of a congressional panel examining how university presidents handled student protests against Israel's war in Gaza. Kornbluth said in her opening statement that she didn't support 'speech codes' that would restrict what students say during protests."

Read more of this story at Slashdot.

Categories: Linux fréttir

Russian Hackers Were Inside Ukraine Telecoms Giant For Months

Sat, 2024-01-06 13:00
An anonymous reader quotes a report from Reuters: Russian hackers were inside Ukrainian telecoms giant Kyivstar's system from at least May last year in a cyberattack that should serve as a "big warning" to the West, Ukraine's cyber spy chief told Reuters. The hack, one of the most dramatic since Russia's full-scale invasion nearly two years ago, knocked out services provided by Ukraine's biggest telecoms operator for some 24 million users for days from Dec. 12. In an interview, Illia Vitiuk, head of the Security Service of Ukraine's (SBU) cybersecurity department, disclosed exclusive details about the hack, which he said caused "disastrous" destruction and aimed to land a psychological blow and gather intelligence. "This attack is a big message, a big warning, not only to Ukraine, but for the whole Western world to understand that no one is actually untouchable," he said. He noted Kyivstar was a wealthy, private company that invested a lot in cybersecurity. The attack wiped "almost everything", including thousands of virtual servers and PCs, he said, describing it as probably the first example of a destructive cyberattack that "completely destroyed the core of a telecoms operator." During its investigation, the SBU found the hackers probably attempted to penetrate Kyivstar in March or earlier, he said in a Zoom interview on Dec. 27. "For now, we can say securely, that they were in the system at least since May 2023," he said. "I cannot say right now, since what time they had ... full access: probably at least since November." The SBU assessed the hackers would have been able to steal personal information, understand the locations of phones, intercept SMS-messages and perhaps steal Telegram accounts with the level of access they gained, he said. A Kyivstar spokesperson said the company was working closely with the SBU to investigate the attack and would take all necessary steps to eliminate future risks, adding: "No facts of leakage of personal and subscriber data have been revealed." Investigating the attack is harder because of the wiping of Kyivstar's infrastructure. Vitiuk said he was "pretty sure" it was carried out by Sandworm, a Russian military intelligence cyberwarfare unit that has been linked to cyberattacks in Ukraine and elsewhere. A year ago, Sandworm penetrated a Ukrainian telecoms operator, but was detected by Kyiv because the SBU had itself been inside Russian systems, Vitiuk said, declining to identify the company. The earlier hack has not been previously reported. Vitiuk said SBU investigators were still working to establish how Kyivstar was penetrated or what type of trojan horse malware could have been used to break in, adding that it could have been phishing, someone helping on the inside or something else. If it was an inside job, the insider who helped the hackers did not have a high level of clearance in the company, as the hackers made use of malware used to steal hashes of passwords, he said. Samples of that malware have been recovered and are being analysed, he added.

Read more of this story at Slashdot.

Categories: Linux fréttir

Is LinkedIn Becoming the Hottest New Dating Site?

Sat, 2024-01-06 10:00
Business Insider's Kelli Maria Korducki reports on a growing trend happening on LinkedIn: some people are using the professional network for personal connections, fielding romantic offers amid job postings. But that leaves the question: Is it a good idea to mix work and love? From the report: Dustin Kidd, a professor of sociology at Temple University who researches social media and pop culture, said that dating via LinkedIn belonged to a long tradition of "dating hacks" -- using online tools designed for other purposes to snag a date. "In the aughts, this happened with Friendster and then Myspace," Kidd said, but has since spread to myriad platforms that are ostensibly romance-free. Even fitness-tracking sites such as Strava are fair game. The common thread for love-hijacked social-media sites is a single feature, Kidd said: DMs. "The design of LinkedIn helps to maintain its focus on the professional, but any platform with a direct-messaging option is likely to also be used to pursue sex and dating," he told me. The ease and relative privacy of direct messaging help explain how some people are using LinkedIn for romance, but it doesn't explain why. In an age with so many dedicated dating platforms -- from giants such as Tinder, Bumble, and Hinge to niche apps including Feeld (for the unconventional), Pure (for the noncommittal), and NUiT (for the astrologically inclined) -- why mix Cupid's arrow with corporate updates? Any type of social media where you can see people's pictures can turn into a dating app. And LinkedIn is even better because it's not just showing people's fake lives. One answer may be the growing number of Americans who have gotten tired of the roulette-like experience that comes with modern dating apps. In a 2023 Pew survey of US adults, nearly one-third of respondents said they had used an online dating site or app at least once. More than half of women who had used the apps reported feeling overwhelmed by the number of messages they had received in the past year, while 64% of men said they felt insecure from the lack of messages they had gotten. Though an overwhelming majority of men and women said they'd felt excited about people they connected with, an even-larger proportion of respondents said they were sometimes or often disappointed by their matches. [...] LinkedIn's appeal as a dating site, according to people who use it that way, is the platform's ability to give back some of that control and boost the caliber of their prospects. Because the professional-networking site asks users to link to their current and former employers' profile pages, it offers an additional layer of credibility that other social-media platforms lack. Many profiles also include first-person references from former colleagues and managers -- real people with real profile pages. [...] Even for those who shy away from using LinkedIn to angle for dates, the site has become a go-to tool for vetting romantic candidates found through conventional dating apps or in-person encounters. "Social media is just one big dating app," [said Samuela John, a 24-year-old personal organizer in New York City who developed chemistry with an oil-industry man on the platform]. "Any type of social media where you can see people's pictures can turn into a dating app. And LinkedIn is even better because it's not just showing people's fake lives." [...] "I don't think you should go into it like, 'All right, I'm going to find my husband on LinkedIn,'" John said. "I think you should go about it as if you were just networking, like in a casual sense. And then if you end up meeting the person, see the vibes and then go from there."

Read more of this story at Slashdot.

Categories: Linux fréttir

Navajo Nation Objects To Landing Human Remains On Moon, Prompting Last-Minute White House Meeting

Sat, 2024-01-06 07:00
The White House has convened a last-minute meeting to discuss a private lunar mission, Peregrine Mission One, after the Navajo Nation requested a delay due to cultural concerns over the transport of human ashes for burial on the moon. "The moon holds a sacred place in Navajo cosmology," said Navajo Nation President Buu Nygren in a statement. "The suggestion of transforming it into a resting place for human remains is deeply disturbing and unacceptable to our people and many other tribal nations." If successful, the commercial mission scheduled to launch Monday "will be the first time an American-made spacecraft has landed on the lunar surface since the end of the Apollo program in 1972," notes CNN. Longtime Slashdot reader garyisabusyguy shares the report: The private companies providing these lunar burial services, Celestis and Elysium Space, are just two of several paying customers hitching a ride to the moon on Pittsburgh-based Astrobotic Technology's Peregrine lunar lander. The uncrewed spacecraft is expected to lift off on the inaugural flight of the United Launch Alliance's Vulcan Centaur rocket from Florida's Cape Canaveral Space Force Station. Celestis' payload, called Tranquility Flight, includes 66 "memorial capsules" containing "cremated remains and DNA," which will remain on the lunar surface "as a permanent tribute to the intrepid souls who never stopped reaching for the stars," according to the company's website. "We are aware of the concerns expressed by Mr. Nygren, but do not find them substantive," Celestis CEO Charles Chafer told CNN. "We reject the assertion that our memorial spaceflight mission desecrates the moon," Chafer said. "Just as permanent memorials for deceased are present all over planet Earth and not considered desecration, our memorial on the moon is handled with care and reverence, is a permanent monument that does not intentionally eject flight capsules on the moon. It is a touching and fitting celebration for our participants -- the exact opposite of desecration, it is a celebration." Elysium Space has not responded to CNN's request for a comment, but the company's website describes its "Lunar Memorial" as delivering "a symbolic portion of remains to the surface of the Moon, helping to create the quintessential commemoration." "I've been disappointed that this conversation came up so late in the game," John Thornton, Astrobotic Technology CEO, said. "I would have liked to have had this conversation a long time ago. We announced the first payload manifest of this nature to our mission back in 2015. A second in 2020. We really are trying to do the right thing and I hope we can find a good path forward with Navajo Nation." [...] Friday's meeting convened by the White House is scheduled to feature representatives from NASA, the FAA, the US Department of Transportation, and the Department of Commerce. But Navajo Nation officials have little hope that they will be able to stop Monday's launch. "Based off of what we're seeing, and NASA are already having their pre-launch briefing, it doesn't look like they have any intention of stopping the launch or removing the remains," Ahasteen said.

Read more of this story at Slashdot.

Categories: Linux fréttir

Consumer Reports Finds 'Widespread' Presence of Plastics In Food

Sat, 2024-01-06 03:30
An anonymous reader quotes a report from Reuters: Consumer Reports has found that plastics retain a "widespread" presence in food despite the health risks, and called on regulators to reassess the safety of plastics that come into contact with food during production. The non-profit consumer group said on Thursday that 84 out of 85 supermarket foods and fast foods it recently tested contained "plasticizers" known as phthalates, a chemical used to make plastic more durable. It also said 79% of food samples in its study contained bisphenol A (BPA), another chemical found in plastic, and other bisphenols, though levels were lower than in tests done in 2009. Consumer Reports said none of the phthalate levels it found exceeded limits set by U.S. and European regulators. It also said there was no level of phthalates that scientists confirm is safe, but that does not guarantee the safety of foods you eat. Phthalates and bisphenols can disrupt the production and regulation of estrogen and other hormones, potentially boosting the risk of birth defects, cancer, diabetes, infertility, neurodevelopmental disorders, obesity and other health problems. Among tested supermarket foods, Annie's Organic Cheesy Ravioli contained the most phthalates in nanograms per serving, 53,579, followed by Del Monte sliced peaches and Chicken of the Sea pink salmon.

Read more of this story at Slashdot.

Categories: Linux fréttir

Ivanti Warns of Critical Vulnerability In Its Popular Line of Endpoint Protection Software

Sat, 2024-01-06 02:02
Dan Goodin reports via Ars Technica: Software maker Ivanti is urging users of its end-point security product to patch a critical vulnerability that makes it possible for unauthenticated attackers to execute malicious code inside affected networks. The vulnerability, in a class known as a SQL injection, resides in all supported versions of the Ivanti Endpoint Manager. Also known as the Ivanti EPM, the software runs on a variety of platforms, including Windows, macOS, Linux, Chrome OS, and Internet of Things devices such as routers. SQL injection vulnerabilities stem from faulty code that interprets user input as database commands or, in more technical terms, from concatenating data with SQL code without quoting the data in accordance with the SQL syntax. CVE-2023-39336, as the Ivanti vulnerability is tracked, carries a severity rating of 9.6 out of a possible 10. "If exploited, an attacker with access to the internal network can leverage an unspecified SQL injection to execute arbitrary SQL queries and retrieve output without the need for authentication," Ivanti officials wrote Friday in a post announcing the patch availability. "This can then allow the attacker control over machines running the EPM agent. When the core server is configured to use SQL express, this might lead to RCE on the core server." RCE is short for remote code execution, or the ability for off-premises attackers to run code of their choice. Currently, there's no known evidence the vulnerability is under active exploitation. Ivanti has also published a disclosure that is restricted only to registered users. A copy obtained by Ars said Ivanti learned of the vulnerability in October. [...] Putting devices running Ivanti EDM behind a firewall is a best practice and will go a long way to mitigating the severity of CVE-2023-39336, but it would likely do nothing to prevent an attacker who has gained limited access to an employee workstation from exploiting the critical vulnerability. It's unclear if the vulnerability will come under active exploitation, but the best course of action is for all Ivanti EDM users to install the patch as soon as possible.

Read more of this story at Slashdot.

Categories: Linux fréttir

Apple Revives Old Fight With Hey Email App

Sat, 2024-01-06 01:25
Shortly after the premium email service Hey announced a standalone Hey Calendar app, co-founder David Heinemeier Hansson said it was rejected by Apple for violating App Store rules. "Apple just called to let us know they're rejecting the HEY Calendar app from the App Store (in current form)," wrote DHH on X. "Same bullying tactics as last time: Push delicate rejections to a call with a first-name-only person who'll softly inform you it's your wallet or your kneecaps. Since it's clear we're never going to pay them the extortionate 30% ransom, they're back to the bullshit about 'the app doesn't do anything when you download it.' Despite the fact that after last time, they specifically carved out HEY in App Store Review Guidelines 3.1.3 (f)!" The Verge's Amrita Khalid reports: New users can't sign up for Hey Calendar directly on the app -- Basecamp, which makes Hey, makes users first sign up through a browser. Apple's App Store rules require most paid services to offer users the ability to pay and sign up through the app, ensuring the company gets up to a 30 percent cut. The controversial rule has a ton of gray areas and carve-outs (i.e. reader apps like Spotify and Kindle get an exception) and is the subject of antitrust fights in multiple countries. But as Hansson detailed on X and in a subsequent blog post, he found Apple's rejection insulting for another reason. Close to four years ago, the company rejected Hey's original iOS app for its email service for the exact same reason. The outcome of the 2020 fight actually worked out in Hey's favor. After days of back and forth between Apple's App Store Review Board and Basecamp, the Hey team agreed to a rather creative solution suggested by Apple exec Phil Schiller. Hey would offer a free option for the iOS app, allowing new users to sign up directly. But the company had a slight twist -- users who signed up via the iOS app got a free, temporary randomized email address that worked for 14 days -- after which they had to pay to upgrade. Currently, Hey email users can only pay for an account through the browser. Following the saga with Hey, Apple made a carve-out to its App Store rules that stated that free companion apps to certain types of paid web services were not required to have an in-app payment mechanism. But, as Hansson mentions on X, a calendar app wasn't mentioned in the list of services that Apple now makes an exception for, which includes VOIP, cloud storage, web hosting -- and of course -- email. Hansson plans to fight Apple's decision without elaborating on exactly how he intends to do so.

Read more of this story at Slashdot.

Categories: Linux fréttir

ChatGPT Could Soon Replace Google Assistant On Your Android Phone

Sat, 2024-01-06 00:45
Code within the latest version of the ChatGPT Android app suggests that you'll soon be able to set it as the default assistant app, replacing the Google Assistant. Android Authority's Mishaal Rahman reports: ChatGPT version 1.2023.352, released last month, added a new activity named com.openai.voice.assistant.AssistantActivity. The activity is disabled by default, but after manually enabling and launching it, an overlay appears on the screen with the same swirling animation as the one shown when using the in-app voice chat mode. This overlay appears over other apps and doesn't take up the entire screen like the in-app voice chat mode. So, presumably, you could talk to ChatGPT from any screen by invoking this assistant. However, in my testing, the animation never finished and the activity promptly closed itself before I could speak with the chatbot. This could either be because the feature isn't finished yet or is being controlled by some internal flag. [...] However, the fact that the aforementioned XML file even exists hints that this is what OpenAI intends to do with the app. Making the ChatGPT app Android's default digital assistant app would enable users to launch it by long-pressing the home button (if using three-button navigation) or swiping up from a bottom corner (if using gesture navigation). Unfortunately, the ChatGPT app still wouldn't be able to create custom hotwords or respond to existing ones, since that functionality requires access to privileged APIs only available to trusted, preinstalled apps. Still, given that Google will launch Assistant with Bard any day now, it makes sense that OpenAI wants to make it easier for Android users to access ChatGPT so that users don't flock to Bard just because it's easier to use.

Read more of this story at Slashdot.

Categories: Linux fréttir

Drones Are the New Drug Mules

Sat, 2024-01-06 00:02
An anonymous reader quotes a report from VICE News: Last week border officials in the Punjab region of India revealed they intercepted 107 drug-carrying drones sent by smuggling gangs last year over the border from Pakistan, the highest number on record. Most were carrying heroin or opium from Pakistan to be dropped and received by collaborators in the Punjab, notorious for having India's worst levels of opiate addiction. Last year the head of a police narcotics unit in Lahore, a city in Pakistan which borders the Punjab, was dismissed after he was suspected of running a drug trafficking gang sending drones over to India. But the use of cheap flying robots instead of humans to smuggle drugs across borders is a worldwide phenomenon. [...] [D]rones will likely become an everyday part of drug dealing too, according to Peter Warren Singer, author of multiple books on national security and a Fellow at think tank New America, with legit medicines due to be delivered by drone in the U.S. later this year and maybe in the U.K. too. "We are just scraping the surface of what is possible, as drone deliveries become more and more common in the commercial world, it will be the same with delivery of illicit goods. In our book, Burn-In, we explain how a future city will see drones zipping about delivering everything from groceries and burritos to drugs, both prescribed by a doctor or bought off a dealer. Drones have traditionally been used by governments and corporations for what are known as the "3 D's" jobs that are too dull, dirty, or dangerous for humans. For criminals, it is the same, except add in another D: Dependable. A drone doesn't steal the product and can't be arrested or snitch if caught." Liam O'Shea, senior research fellow for organized crime and policing at defense and security thinktank RUSI, said drones were at the moment of limited value to wholesale traffickers and organized criminal gangs because of their range and the weight they can carry. "It makes sense that smugglers would seek to use drones. They are cheap and easy to acquire. They also lower the risks involved in some transactions, as smugglers do not have to be physically present during transactions. They offer opportunities for smuggling in areas where previous routes were too risky, such as prisons and over securitized borders. "I expect them to be of greater value to smaller players and distributors dealing with smaller quantities. Wholesale drug traffickers will still need to use routes that facilitate smuggling at higher volume or using drones to make multiple trips, which entails risks of detection. That may well change as improvements in technology improve drones' carrying capacity and crime groups are better able to access drones with greater capacity."

Read more of this story at Slashdot.

Categories: Linux fréttir

Tesla's First Smart Home Partner Is Samsung SmartThings

Fri, 2024-01-05 23:20
Tesla and Samsung are joining forces to allow users of Samsung's SmartThings platform to connect to Tesla products so they can keep track of energy production and usage. The Verge reports: When connected to the Powerwall, SmartThings Energy can sync with the "Storm Watch" feature so that you're notified of heavy weather on a Samsung phone or TV, for example. In addition to the Powerwall, SmartThings Energy will be able to connect to other Tesla products, including its electric vehicles, Solar Inverter, and Wall Connector charging solutions. The collaboration is possible thanks to Tesla's API, which Samsung claims SmartThings Energy is the first to take advantage of.

Read more of this story at Slashdot.

Categories: Linux fréttir

Pages