Slashdot

Subscribe to Slashdot feed Slashdot
News for nerds, stuff that matters
Updated: 40 min 3 sec ago

Amazon Owes $525 Million In Cloud-Storage Patent Fight, US Jury Says

Fri, 2024-04-12 00:02
A federal jury in Illinois on Wednesday said Amazon Web Services owes tech company Kove $525 million for violating three patents relating to its data-storage technology. From the report: The jury determined (PDF) that AWS infringed three Kove patents covering technology that Kove said had become "essential" to the ability of Amazon's cloud-computing arm to "store and retrieve massive amounts of data." An Amazon spokesperson said the company disagrees with the verdict and intends to appeal. Kove's lead attorney Courtland Reichman called the verdict "a testament to the power of innovation and the importance of protecting IP (intellectual property) rights for start-up companies against tech giants." Kove also sued Google last year for infringing the same three patents in a separate Illinois lawsuit that is still ongoing.

Read more of this story at Slashdot.

Categories: Linux fréttir

Hackable Intel and Lenovo Hardware That Went Undetected For 5 Years Won't Ever Be Fixed

Thu, 2024-04-11 23:20
An anonymous reader quotes a report from Ars Technica: Hardware sold for years by the likes of Intel and Lenovo contains a remotely exploitable vulnerability that will never be fixed. The cause: a supply chain snafu involving an open source software package and hardware from multiple manufacturers that directly or indirectly incorporated it into their products. Researchers from security firm Binarly have confirmed that the lapse has resulted in Intel, Lenovo, and Supermicro shipping server hardware that contains a vulnerability that can be exploited to reveal security-critical information. The researchers, however, went on to warn that any hardware that incorporates certain generations of baseboard management controllers made by Duluth, Georgia-based AMI or Taiwan-based AETN are also affected. BMCs are tiny computers soldered into the motherboard of servers that allow cloud centers, and sometimes their customers, to streamline the remote management of vast fleets of servers. They enable administrators to remotely reinstall OSes, install and uninstall apps, and control just about every other aspect of the system -- even when it's turned off. BMCs provide what's known in the industry as "lights-out" system management. AMI and AETN are two of several makers of BMCs. For years, BMCs from multiple manufacturers have incorporated vulnerable versions of open source software known as lighttpd. Lighttpd is a fast, lightweight web server that's compatible with various hardware and software platforms. It's used in all kinds of wares, including in embedded devices like BMCs, to allow remote administrators to control servers remotely with HTTP requests. [...] "All these years, [the lighttpd vulnerability] was present inside the firmware and nobody cared to update one of the third-party components used to build this firmware image," Binarly researchers wrote Thursday. "This is another perfect example of inconsistencies in the firmware supply chain. A very outdated third-party component present in the latest version of firmware, creating additional risk for end users. Are there more systems that use the vulnerable version of lighttpd across the industry?" The vulnerability makes it possible for hackers to identify memory addresses responsible for handling key functions. Operating systems take pains to randomize and conceal these locations so they can't be used in software exploits. By chaining an exploit for the lighttpd vulnerability with a separate vulnerability, hackers could defeat this standard protection, which is known as address space layout randomization. The chaining of two or more exploits has become a common feature of hacking attacks these days as software makers continue to add anti-exploitation protections to their code. Tracking the supply chain for multiple BMCs used in multiple server hardware is difficult. So far, Binarly has identified AMI's MegaRAC BMC as one of the vulnerable BMCs. The security firm has confirmed that the AMI BMC is contained in the Intel Server System M70KLP hardware. Information about BMCs from ATEN or hardware from Lenovo and Supermicro aren't available at the moment. The vulnerability is present in any hardware that uses lighttpd versions 1.4.35, 1.4.45, and 1.4.51. "A potential attacker can exploit this vulnerability in order to read memory of Lighttpd Web Server process," Binarly researchers wrote in an advisory. "This may lead to sensitive data exfiltration, such as memory addresses, which can be used to bypass security mechanisms such as ASLR." Advisories are available here, here, and here.

Read more of this story at Slashdot.

Categories: Linux fréttir

Code.org Launches AI Teaching Assistant For Grades 6-10 In Stanford Partnership

Thu, 2024-04-11 22:40
theodp writes: From a Wednesday press release: "Code.org, in collaboration with The Piech Lab at Stanford University, launched today its AI Teaching Assistant, ushering in a new era of computer science instruction to support teachers in preparing students with the foundational skills necessary to work, live and thrive in an AI world. [...] Launching as a part of Code.org's leading Computer Science Discoveries (CSD) curriculum [for grades 6-10], the tool is designed to bolster teacher confidence in teaching computer science." EdWeek reports that in a limited pilot project involving twenty teachers nationwide, the AI computer science grading tool cut one middle school teacher's grading time in half. Code.org is now inviting an additional 300 teachers to give the tool a try. "Many teachers who lead computer science courses," EdWeek notes, "don't have a degree in the subject -- or even much training on how to teach it -- and might be the only educator in their school leading a computer science course." Stanford's Piech Lab is headed by assistant professor of CS Chris Piech, who also runs the wildly-successful free Code in Place MOOC (30,000+ learners and counting), which teaches fundamentals from Stanford's flagship introduction to Python course. Prior to coming up with the new AI teaching assistant, which automatically assesses Code.org students' JavaScript game code, Piech worked on a Stanford Research team that partnered with Code.org nearly a decade ago to create algorithms to generate hints for K-12 students trying to solve Code.org's Hour of Code block-based programming puzzles (2015 paper [PDF]). And several years ago, Piech's lab again teamed with Code.org on Play-to-Grade, which sought to "provide scalable automated grading on all types of coding assignments" by analyzing the game play of Code.org students' projects. Play-to-Grade, a 2022 paper (PDF) noted, was "supported in part by a Stanford Hoffman-Yee Human Centered AI grant" for AI tutors to help prepare students for the 21st century workforce. That project also aimed to develop a "Super Teaching Assistant" for Piech's Code in Place MOOC. LinkedIn co-founder Reid Hoffman, who was present for the presentation of the 'AI Tutors' work he and his wife funded, is a Code.org Diamond Supporter ($1+ million). In other AI grading news, Texas will use computers to grade written answers on this year's STAAR tests. The state will save more than $15 million by using technology similar to ChatGPT to give initial scores, reducing the number of human graders needed.

Read more of this story at Slashdot.

Categories: Linux fréttir

Humane AI Pin Review Roundup

Thu, 2024-04-11 22:02
The embargo has lifted for reviews of Humane's AI Pin and the general consensus appears to be that this device isn't ready to usher us into the all-but-inevitable AI future. Starting at $699 with a pricy $24-a-month subscription, the wearable device is designed to incorporate artificial intelligence into everyday scenarios, with the ability to make calls, translate languages, recommend nearby restaurants, and capture photos and videos. "The best description so far is that it's a combination of a wearable Siri button with a camera and built-in projector that beams onto your palm," writes Cherlynn Low via Engadget. While full of potential, the AI Pin creates more problems than it solves and many of the features you'd intuitively expect from it aren't supported at launch. Here's a roundup of some of the first reviews: Engadget: The Humane AI Pin is the solution to none of technology's problems The Verge: Humane AI Pin review: not even close Wired: Humane Ai Pin Review: Too Clunky, Too Limited The Washington Post: I've been living with a $699 AI Pin on my chest. You probably shouldn't. CNET: Humane AI Hands-On: My Life So Far With a Wearable AI Pin

Read more of this story at Slashdot.

Categories: Linux fréttir

US Lawmaker Proposes a Public Database of All AI Training Material

Thu, 2024-04-11 21:25
An anonymous reader quotes a report from Ars Technica: Amid a flurry of lawsuits over AI models' training data, US Representative Adam Schiff (D-Calif.) has introduced (PDF) a bill that would require AI companies to disclose exactly which copyrighted works are included in datasets training AI systems. The Generative AI Disclosure Act "would require a notice to be submitted to the Register of Copyrights prior to the release of a new generative AI system with regard to all copyrighted works used in building or altering the training dataset for that system," Schiff said in a press release. The bill is retroactive and would apply to all AI systems available today, as well as to all AI systems to come. It would take effect 180 days after it's enacted, requiring anyone who creates or alters a training set not only to list works referenced by the dataset, but also to provide a URL to the dataset within 30 days before the AI system is released to the public. That URL would presumably give creators a way to double-check if their materials have been used and seek any credit or compensation available before the AI tools are in use. All notices would be kept in a publicly available online database. Currently, creators who don't have access to training datasets rely on AI models' outputs to figure out if their copyrighted works may have been included in training various AI systems. The New York Times, for example, prompted ChatGPT to spit out excerpts of its articles, relying on a tactic to identify training data by asking ChatGPT to produce lines from specific articles, which OpenAI has curiously described as "hacking." Under Schiff's law, The New York Times would need to consult the database to ID all articles used to train ChatGPT or any other AI system. Any AI maker who violates the act would risk a "civil penalty in an amount not less than $5,000," the proposed bill said. Schiff described the act as championing "innovation while safeguarding the rights and contributions of creators, ensuring they are aware when their work contributes to AI training datasets." "This is about respecting creativity in the age of AI and marrying technological progress with fairness," Schiff said.

Read more of this story at Slashdot.

Categories: Linux fréttir

America's Chip Renaissance Needs Workers

Thu, 2024-04-11 20:43
An anonymous reader shares a report: Last week South Korea's SK Hynix announced it would partner with Purdue University on a $3.9 billion semiconductor complex here, the largest single corporate investment in state history. Now comes the hard part. SK Hynix must not only build the fabrication plant, or fab, which will package high-bandwidth memory chips used in artificial intelligence, and a connected research-and-development center. It also has to staff them. "We need several hundred engineers to operate our advanced-packaging manufacturing fab -- in physics, chemistry, material science, electronics engineering," Kwak Noh-Jung, chief executive of SK Hynix, said in an interview following last week's announcement. Staffing a fab is harder in the U.S. than in South Korea, where SK Hynix has contracts with local universities and its own in-house university. Nonetheless, Kwak said, "the final goal is very clear. We need to have very good engineers for our success in U.S." The U.S. is trying to do something unprecedented: reverse a shrinking share in a key manufacturing sector. Between 1990 and 2020, the U.S. share of world chip making shrank to 12% from 37%, while the combined share of Taiwan, South Korea and China grew to 58%. The federal CHIPS program has showered billions of dollars on Intel for fabs in several states, Taiwan Semiconductor Manufacturing Co.in Arizona and GlobalFoundries in New York and Vermont. SK Hynix hopes for support as well. Subsidies alone won't guarantee a sustainable industry. Fabs need customers, a supply chain and, above all, a skilled, specialized workforce. From 2000 to 2017, U.S. employment in semiconductor manufacturing shrank to 181,000 from 287,000. It has since recovered to about 200,000. Why did the U.S. share of semiconductor production shrink? As in other industries, the U.S. became an expensive place to manufacture. Susan Houseman of the Upjohn Institute, who has studied outsourcing, said this wasn't "primarily a story about offshoring." U.S. companies still lead in chip design: Nvidia in artificial intelligence, Qualcomm in communications and Apple in smartphones. Over time they mostly contracted out fabrication of their chips to foundries such as TSMC who benefited from generous domestic subsidies. The theory behind CHIPS is that, by matching Asia's subsidies, the U.S. can again be competitive in chip making. Nonetheless, there is a chicken-egg problem. Fabs need a ready supply of skilled workers. But without fabs, America's best and brightest have little incentive to pursue careers in the sector.

Read more of this story at Slashdot.

Categories: Linux fréttir

Android 15's First Beta Release is Out

Thu, 2024-04-11 20:04
Android 15's first public beta is available to download now, provided you have a Pixel phone. From a report: It's the first consumer-facing release after two developer previews, and while we have a good idea of what to expect from Google's next mobile OS version, we'll certainly hear more at the company's annual developer conference soon enough. The blog post highlighting updates in today's release covers some pretty pedestrian stuff. Apps will scale edge to edge by default and will draw behind translucent system bars on the top and bottom of the screen, rather than around them. There's OS-level support for app archiving and unarchiving so third-party app stores can take advantage of this feature. Android 15 will also provide better support for Braille displays.M

Read more of this story at Slashdot.

Categories: Linux fréttir

Microsoft Begins Showing Full Screen Windows 11 Ad on Windows 10 PCs as End of Support Date Looms

Thu, 2024-04-11 18:16
Microsoft has started showing full screen warnings about the upcoming end of support date on Windows 10 PCs. From a report: Users on Reddit have reported seeing the prompt, which began appearing after this week's Patch Tuesday updates were installed, and encourages the user to learn more about how they can transition to Windows 11. Windows 10's end of support date is currently set for October 14, 2025. After that date, Windows 10 users will no longer receive critical security and bug fix updates, leaving any Windows 10 PC connected to the internet vulnerable to any newly discovered security exploits. The full screen prompt that is now appearing on some Windows 10 PCs thanks the user for their loyalty using Windows 10, and warns that this end of life (EOL) date is approaching. It also wastes no time advertising Windows 11, encouraging the user to learn more about how they can transition to a new Windows 11 PC. Notably, there's no button to tell the prompt to never show again.

Read more of this story at Slashdot.

Categories: Linux fréttir

Apple Plans To Overhaul Entire Mac Line With AI-Focused M4 Chips

Thu, 2024-04-11 17:25
Apple, aiming to boost sluggish computer sales, is preparing to overhaul its entire Mac line with a new family of in-house processors designed to highlight AI. Bloomberg News: The company, which released its first Macs with M3 chips five months ago, is already nearing production of the next generation -- the M4 processor -- according to people with knowledge of the matter. The new chip will come in at least three main varieties, and Apple is looking to update every Mac model with it, said the people, who asked not to be identified because the plans haven't been announced. The new Macs are underway at a critical time. After peaking in 2022, Mac sales fell 27% in the last fiscal year, which ended in September. In the holiday period, revenue from the computer line was flat. Apple attempted to breathe new life into the Mac business with an M3-focused launch event last October, but those chips didn't bring major performance improvements over the M2 from the prior year. Apple also is playing catch-up in AI, where it's seen as a laggard to Microsoft, Alphabet's Google and other tech peers. The new chips are part of a broader push to weave AI capabilities into all its products. Apple is aiming to release the updated computers beginning late this year and extending into early next year.

Read more of this story at Slashdot.

Categories: Linux fréttir

Computer Scientist Wins Turing Award for Seminal Work on Randomness

Thu, 2024-04-11 16:46
Computational scientist and mathematician Avi Wigderson of the Institute for Advanced Study (IAS) in Princeton has won the 2023 A.M. Turing Award. From a report: The prize, which is given annually by the Association for Computing Machinery (ACM) to a computer scientist for their contributions to the field, comes with $1 million thanks to Google. It is named in honor of the British mathematician Alan Turing, who helped develop a theoretical foundation for understanding machine computation. Wigderson is being honored "for foundational contributions to the theory of computation, including reshaping our understanding of the role of randomness in computation and for his decades of intellectual leadership in theoretical computer science." He also won the prestigious Abel Prize in 2021 for his work in theoretical computer science -- the first person to be so doubly honored.

Read more of this story at Slashdot.

Categories: Linux fréttir

Apple Will Open the iPhone To Repair With Used Parts

Thu, 2024-04-11 16:01
Apple is finally making it easier for users to repair their iPhones with used parts. From a report: In an update on Thursday, the company announced that this fall, owners of "select" iPhone models will be able to repair their devices with used, genuine parts while retaining full functionality. When repairing a phone, Apple requires iPhone users to go through a process called parts pairing, which makes them match the serial number of their device to that of a new part sold by Apple. If a user replaced a part with an aftermarket or used component, the iPhone would display pesky notifications saying that Apple isn't able to verify the newly installed piece. In the case of Face ID and Touch ID sensors, the part might not work at all. This change should do away with these notifications for used parts, as Apple says "calibration for genuine Apple parts, new or used, will happen on device after the part is installed." It also means users and repair shops will no longer have to provide the serial number of the device they're fixing when ordering most parts from the Self Service Repair Store.

Read more of this story at Slashdot.

Categories: Linux fréttir

Amazon Adds AI Expert Andrew Ng To Board as GenAI Race Heats Up

Thu, 2024-04-11 15:22
Amazon on Thursday added Andrew Ng, the computer scientist who led AI projects at Alphabet's Google and China's Baidu, to its board amid rising competition among Big Techs to add users for their GenAI products. From a report: Amazon's cloud unit is facing pressure from Microsoft's early pact with ChatGPT-maker OpenAI and integration of its technology into Azure, while Alexa voice assistant is in race with genAI chat tools from OpenAI and Google. The appointment, effective April 9, also follows job cuts across Amazon, which has seen enterprise cloud spending and e-commerce sales moderate due to macroeconomic factors such as inflation and high interest rates. "As we look toward 2024 (and beyond), we're not done lowering our cost to serve," CEO Andy Jassy said in a letter to shareholders on Thursday.

Read more of this story at Slashdot.

Categories: Linux fréttir

DuckDuckGo Launches Privacy Pro: A 3-in-1 Service That Includes a VPN

Thu, 2024-04-11 14:42
DuckDuckGo, the privacy-focused web search and browser company, announced on today the launch of its first subscription service, Privacy Pro. The service, priced at $9.99 per month or $99.99 per year, includes a browser-based tool that automatically scans data broker websites for users' personal information and requests its removal. The service also includes DuckDuckGo's first VPN and an identity-theft-restoration service. Available initially only in the U.S.

Read more of this story at Slashdot.

Categories: Linux fréttir

Apple Alerts Users in 92 Nations To Mercenary Spyware Attacks

Thu, 2024-04-11 14:02
Apple sent threat notifications to iPhone users in 92 countries on Wednesday, warning them that may have been targeted by mercenary spyware attacks. From a report: The company said it sent the alerts to individuals in 92 nations at 12pm Pacific Time Wednesday. The notification, which TechCrunch has seen, did not disclose the attackers' identities or the countries where users received notifications. "Apple detected that you are being targeted by a mercenary spyware attack that is trying to remotely compromise the iPhone associated with your Apple ID -xxx-," it wrote in the warning to affected customers. "This attack is likely targeting you specifically because of who you are or what you do. Although it's never possible to achieve absolute certainty when detecting such attacks, Apple has high confidence in this warning -- please take it seriously," Apple added in the text.

Read more of this story at Slashdot.

Categories: Linux fréttir

UK Considers Banning Smartphone Sales To Children Under 16

Thu, 2024-04-11 13:00
An anonymous reader quotes a report from The Guardian: Ministers are considering banning the sale of smartphones to children under the age of 16 after a number of polls have shown significant public support for such a curb. The government issued guidance on the use of mobile phones in English schools two months ago, but other curbs are said to have been considered to better protect children after a number of campaigns. [...] A March survey by Parentkind, of 2,496 parents of school-age children in England, found 58% of parents believe the government should ban smartphones for under-16s. It also found more than four in five parents said they felt smartphones were "harmful" to children and young people. Another survey by More in Common revealed 64% of people thought that a ban on selling smartphones to under-16s would be a good idea, compared with 20% who said it was a bad idea. The curb was even popular among 2019 Tory voters, according to the thinktank, which found 72% backed a ban, as did 61% of Labour voters. But the thought of another ban has left some Conservatives uneasy. One Tory government source described the idea as "out of touch," noting: "It's not the government's role to step in and microparent; we're meant to make parents more aware of the powers they have like restrictions on websites, apps and even the use of parental control apps." They said only in extreme cases could the government "parent better than actual parents and guardians."

Read more of this story at Slashdot.

Categories: Linux fréttir

Chechnya Is Banning Music That's Too Fast Or Slow

Thu, 2024-04-11 10:00
Rachel Treisman reports via NPR: Authorities in the Russian republic of Chechnya are banning music they consider either too fast or too slow, effectively criminalizing many genres. The Chechen Ministry of Culture announced the ban on its website last week, by the order of Culture Minister Musa Dadayev and with the agreement of Chechen leader Ramzan Kadyrov. "Musical, vocal and choreographic" works will be limited to a tempo of 80 to 116 beats per minute (BPM) to "conform to the Chechen mentality and sense of rhythm," said Dadayev, according to the Russian state-run news agency TASS. "Borrowing musical culture from other peoples is inadmissible," Dadayev said, per a translation by The Guardian. "We must bring to the people and to the future of our children the cultural heritage of the Chechen people. This includes the entire spectrum of moral and ethical standards of life for Chechens." Russian media report that artists have until June 1 to rewrite any music that doesn't conform to the new rule, though it's not clear how it will be enforced. [...] The government's crackdown on certain musical tempos would silence most modern music genres. Electronic styles of music like house, techno and dubstep all tend to have BPMs of over 116, says the audio tech company Izotope, while the average tempo of 2020's best-selling pop songs was 122 BPM, according to the BBC. The independent Russian news outlet Meduza said the tempo of the Russian national anthem would be considered too slow under the new limit, reports RadioFreeEurope/RadioLiberty. But it would seem to permit hip-hop music, which generally has a BPM of 85 to 95. "Chechnya is a roughly 6,700-square-mile autonomous republic situated in the North Caucasus of southern Russia and home to some 1.5 million people, the vast majority of whom are Muslim," notes NPR. "The U.S. Commission on International Religious Freedom has said Kadyrov's regime 'maintains hegemony through the imposition of a purported 'traditional' version of Islam, which falsely claims to defend local belief and culture, and combat violent extremism.'" "'In reality, Kadyrov has [co-opted] Chechen religion and culture to support his brutal regime, which violates the secular constitution of the Russian Federation and international standards of freedom of religion or belief,' it added."

Read more of this story at Slashdot.

Categories: Linux fréttir

Sierra Space, Valued At $5.3 Billion, Eyes IPO To 'Accelerate the New Space Economy'

Thu, 2024-04-11 07:00
Sierra Space CEO Tom Vice told Yahoo Finance it plans to go public within the next 18 months at a valuation of $5.3 billion. Since being spun out of defense contractor Sierra Nevada Corporation in 2021, the company has "placed its bets on building out the growing space economy, from developing rocket propulsion technology to a commercial space station with Blue Origin." From the report: Its ambitions have fueled the development of its cargo space plane, the Dream Chaser, set to have its inaugural mission to the International Space Station (ISS) in the second half of this year. Built to land on any commercial runway, the plane will lower the barrier to entry into low-earth orbit and open up business opportunities, Vice said. "Since the 1960s, every science experiment or human being that's come back to earth from space, even today, is still landing in a capsule in the ocean," he said. "We think changing and revolutionizing the way that we bring things back from space, both humans and cargo, and landing [the spacecraft] back at a commercial runway will completely accelerate the new space economy." "We believe that the next big breakthrough products in oncology, longevity, and industrialized components like glass will be produced in low Earth orbit," Vice said, noting that many of those opportunities are likely to come from the development of commercial space stations to replace the decades-old ISS. Sierra Space has partnered with Blue Origin to build out the Orbital Reef, a commercially owned and operated space station, though recent reports have hinted at tension between the corporate partners. "We're transitioning from decades of government-run space stations with just a handful of government-trained astronauts to the full commercialization of low Earth orbit," Vice said. "We think that's going to create, we believe, probably the most profound industrial revolution and grow that space economy well over a trillion dollars by 2040."

Read more of this story at Slashdot.

Categories: Linux fréttir

Saudi Arabia 'Forced To Scale Back' Plans For Desert Megacity

Thu, 2024-04-11 03:30
An anonymous reader quotes a report from The Guardian: It was billed as a glass-walled city of the future, an ambitious centerpiece of the economic plan backed by Crown Prince Mohammed bin Salman to transition Saudi Arabia away from oil dependency. Now, however, plans for the mirror-clad desert metropolis called the Line have been scaled down and the project, which was envisaged to stretch 105 miles (170km) is expected to reach just a mile and a half by 2030. Dreamed up as a linear city that would eventually be home to about 9 million people on a footprint of just 13 sq miles, the Line is part of a wider Neom project. Now at least one contractor has begun dismissing workers. The scaling down of Prince Mohammed's most grandiose project was reported by Bloomberg, which said it had seen documents relating to the project.

Read more of this story at Slashdot.

Categories: Linux fréttir

Microsoft Employees Exposed Internal Passwords In Security Lapse

Thu, 2024-04-11 02:02
Zack Whittaker and Carly Page report via TechCrunch: Microsoft has resolved a security lapse that exposed internal company files and credentials to the open internet. Security researchers Can Yoleri, Murat Ozfidan and Egemen Kochisarli with SOCRadar, a cybersecurity company that helps organizations find security weaknesses, discovered an open and public storage server hosted on Microsoft's Azure cloud service that was storing internal information relating to Microsoft's Bing search engine. The Azure storage server housed code, scripts and configuration files containing passwords, keys and credentials used by the Microsoft employees for accessing other internal databases and systems. But the storage server itself was not protected with a password and could be accessed by anyone on the internet. Yoleri told TechCrunch that the exposed data could potentially help malicious actors identify or access other places where Microsoft stores its internal files. Identifying those storage locations "could result in more significant data leaks and possibly compromise the services in use," Yoleri said. The researchers notified Microsoft of the security lapse on February 6, and Microsoft secured the spilling files on March 5. It's not known for how long the cloud server was exposed to the internet, or if anyone other than SOCRadar discovered the exposed data inside.

Read more of this story at Slashdot.

Categories: Linux fréttir

VMS Software Prunes OpenVMS Hobbyist Program

Thu, 2024-04-11 01:45
Liam Proven reports via The Register: Bad news for those who want to play with OpenVMS in non-production use. Older versions are disappearing, and the terms are getting much more restrictive. The corporation behind the continued development of OpenVMS, VMS Software, Inc. -- or VSI to its friends, if it has any left after this -- has announced the latest Updates to the Community Program. The news does not look good: you can't get the Alpha and Itanium versions any more, only a limited x86-64 edition. OpenVMS is one of the granddaddies of big serious OSes. A direct descendant of the OSes that inspired DOS, CP/M, OS/2, and Windows, as well as the native OS of the hardware on which Unix first went 32-bit, VMS has been around for nearly half a century. For decades, its various owners have offered various flavors of "hobbyist program" under which you could get licenses to install and run it for free, as long as it wasn't in production use. Since Compaq acquired DEC, then HP acquired Compaq, its prospects looked checkered. HP officially killed it off in 2013, then in 2014 granted it a reprieve and sold it off instead. New owner VSI ported it to x86-64, releasing that new version 9.2 in 2022. Around this time last year, we covered VSI adding AMD support and opening a hobbyist program of its own. It seems from the latest announcement that it has been disappointed by the reception: "Despite our initial aspirations for robust community engagement, the reality has fallen short of our expectations. The level of participation in activities such as contributing open source software, creating wiki articles, and providing assistance on forums has not matched the scale of the program. As a result, we find ourselves at a crossroads, compelled to reassess and recalibrate our approach." Although HPE stopped offering hobbyist licenses for the original VAX versions of OpenVMS in 2020, VSI continued to maintain OpenVMS 8 (in other words, the Alpha and Itanium editions) while it worked on version 9 for x86-64. VSI even offered a Student Edition, which included a freeware Alpha emulator and a copy of OpenVMS 8.4 to run inside it. Those licenses run out in 2025, and they won't be renewed. If you have vintage DEC Alpha or HP Integrity boxes with Itanic chips, you won't be able to get a legal licensed copy of OpenVMS for them, or renew the license of any existing installations -- unless you pay, of course. There will still be a Community license edition, but from now on it's x86-64 only. Although OpenVMS 9 mainly targets hypervisors anyway, it does support bare-metal operations on a single model of HPE server, the ProLiant DL380 Gen10. If you have one of them to play with -- well, tough. Now Community users only get a VM image, supplied as a VMWare .vmdk file. It contains a ready-to-go "OpenVMS system disk with OpenVMS, compilers and development tools installed." Its license runs for a year, after which you will get a fresh copy. This means you won't be able to configure your own system and keep it alive -- you'll have to recreate it, from scratch, annually. The only alternative for those with older systems is to apply to be an OpenVMS Ambassador.

Read more of this story at Slashdot.

Categories: Linux fréttir

Pages