Linux fréttir

Securing the Untrusted Agentic Development Layer

TheRegister - Tue, 2026-05-12 00:00
Join us to learn how to architect a development environment where your builders and their agents can move fast and securely.
Categories: Linux fréttir

'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit

TheRegister - 2 hours 15 min ago
A fresh Linux privilege escalation bug dubbed "Dirty Frag" has dropped into the wild with no patches, no CVE, and a public exploit that hands attackers root access across major distributions. Security researcher Hyunwoo Kim disclosed the local privilege escalation flaw on Friday after what he said was a broken embargo forced the issue into the open. Kim described Dirty Frag as a "universal LPE" affecting "all major distributions" and warned that it delivers the same kind of immediate root access as the recent CopyFail mess – only this time, defenders do not even have patches to throw at the problem. "As with the previous Copy Fail vulnerability, Dirty Frag likewise allows immediate root privilege escalation on all major distributions," Kim said. "Because the responsible disclosure schedule and embargo have been broken, no patches exist for any distribution." Dirty Frag works by chaining together two separate Linux kernel flaws. One sits in the xfrm-ESP subsystem and dates back to a January 2017 kernel commit, according to Kim, while the second vulnerability affects RxRPC functionality introduced in 2023. Together, the two bugs allegedly let unprivileged local users overwrite protected files in memory and claw their way to root. A long list of distributions in the firing line, according to Kim, including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, Fedora, AlmaLinux, and openSUSE Tumbleweed. Separately, researchers appear to have independently reverse-engineered part of the bug chain from a publicly visible kernel fix commit before the embargo expired, adding to the disclosure mess already surrounding the flaw. One GitHub project titled "Copy Fail 2: Electric Boogaloo" claims to weaponize the ESP/xfrm side of the issue separately from Kim's full Dirty Frag chain. Kim said maintainers signed off on the disclosure of the flaw after somebody else dumped exploit details online first, collapsing the embargo before patches were finished. So now the exploit is public, the fixes are not, and Linux admins get another long week. The disclosure comes as the industry is still dealing with the fallout from CopyFail, another Linux privilege escalation bug that recently landed in CISA's Known Exploited Vulnerabilities catalog after attackers started cashing in on it in the wild. But Dirty Frag makes the recent CopyFail chaos look relatively organized. There's still no CVE, no coordinated patch rollout, and not much in the way of mitigation. Kim published a temporary workaround that disables affected ESP and RxRPC modules before clearing the system page cache. Useful, perhaps, although "turn bits of the kernel off and hope for the best" is not usually the sort of guidance admins enjoy seeing. ®
Categories: Linux fréttir

Trump jumps from 'anything goes' to 'strict regulation' AI policy

TheRegister - 2 hours 55 min ago
OPINION When President Donald Trump returned to power, he cast himself as the anti‑Biden on AI. First, he tore up Biden's Executive Order 14110, which had demanded "safe, secure, and trustworthy" AI. He then replaced it with his own "Removing Barriers to American Leadership in Artificial Intelligence" directive, ordering agencies to rescind or dilute rules seen as obstacles to innovation. In short, American AI vendors could do anything they wanted. That was then. This is now. While Trump has yet to issue a new AI Executive Order, we know his crew is forming an AI working group of tech execs and government officials to bring oversight to AI. Specifically, they're considering requiring all new "high‑risk" AI frontier models to undergo a formal government review before they can be used. That's going to go over well. What we do know is that National Economic Council Director Kevin Hassett has said: "We're studying possibly an executive order to give a clear roadmap to everybody about how this is gonna go, and how future AIs that also potentially create vulnerabilities should go through a process so that they’re released into the wild after they've been proven safe – just like an FDA drug." Considering that people who ignore evidence now regulate healthcare in the United States, that doesn’t fill me with much confidence. Indeed, we now know the FDA blocked the publication of studies showing that COVID-19 and shingles vaccines were safe. Are these the kinds of people we want calling the shots on AI? Be that as it may, the Trump yes-men are framing this shift as a response to escalating cybersecurity and national‑security risks rather than as a broader embrace of EU‑style AI regulation. Yes, they're looking at Anthropic's Mythos and its potential use by hackers. At the same time, they emphasize that they want to avoid "onerous" controls on everyday AI applications. Frontier models that could supercharge cyberwarfare, bio‑threats, or other strategic dangers are another matter. That's quite a change from last summer when Trump babbled: "We have to grow that [AI] baby and let that baby thrive. We can't stop it. We can't stop it with politics. We can't stop it with foolish rules and even stupid rules." Now he seems to think rules would be a good thing. Darrell West, a senior fellow at the Center for Technology Innovation at the Brookings Institution, has suggested that Trump is returning to Biden's policy. Just don't tell him that; he'll have a fit. While Trump and company are still contemplating exactly how they want to rule – sorry, regulate – AI, the Department of Commerce's Center for AI Standards and Innovation (CAISI) announced new agreements with Google DeepMind, Microsoft, and xAI. According to these new policy statements, CAISI will conduct pre-deployment evaluations and targeted research to better assess frontier AI capabilities and advance the state of AI security. CAISI director Chris Fall said: "Independent, rigorous measurement science is essential to understanding frontier AI and its national security implications." How to do this? Who will do this? What will it look like? Good question! Too bad we don’t have any answers yet. You may have noticed that Anthropic was not invited to this cozy policy get-together. Funny, that, since most observers think that Mythos was the model that broke the "do anything you want" AI camel's back in Trump's White House. That's because the months‑long feud between the administration and Anthropic is still simmering. Trump's team moved to block federal agencies from using the company's tools, and Anthropic is now challenging that policy in court. Recently, however, Trump's tone has softened. Trump told CNBC that Anthropic was "shaping up." If he can't get peace with Iran, maybe peace with Anthropic will please him. On the other hand, we also know that the Trumpies are considering forbidding companies from "interfering" with the government's use of AI models. You hear that, Anthropic? You will toe the line! Meanwhile, Gregory Falco, a Cornell assistant professor of mechanical and aerospace engineering, pointed out the obvious: "The federal government does not currently have the in-house technical expertise, infrastructure, or day-to-day insight needed to directly evaluate these systems on its own." Expertise is something Trump's cast of characters sorely lacks across any and all subjects. "At the same time," Falco continued, "a purely voluntary model of self-governance is not enough." After all, foxes are notorious guardians of chicken houses. What I think is going to happen is that AI vendors who play ball with Trump will end up "governing" AI alongside some Trump loyalists. It's going to be ugly. Some regulation is needed, but these are not the people who will do a good job of it. I won't be surprised if one of Trump's goals isn't so much to make AI safer as it is to ensure that the answers AI gives are the ones he and his regime want people to see. Today, for example, when I asked a variety of chatbots who lost the 2020 election, they all agreed Trump had lost. Funnily enough, when the Senate Judiciary Committee asked numerous Trump nominees for federal judgeships the same question, they universally refused to say he lost. For better or worse, most Americans don't pay attention to legal news. What they do, however, is ask AI chatbots for answers. Foolish of them, considering how inaccurate they can be, but there it is. If Trump's allowed to call the shots, I've little doubt that the approved bots will follow in the footsteps of his obedient judges and give the answers he wants and not the truth. ®
Categories: Linux fréttir

Meta U-turns on encryption push for Instagram as DMs go plaintext

TheRegister - 3 hours 9 min ago
Meta has quietly pulled the plug on encrypted Instagram DMs, meaning private messages on one of the world’s biggest social networks are no longer especially private. The change took effect today, according to a revised Meta post first published in 2022. In a statement to The Register, Meta said the feature saw limited adoption and pointed users toward WhatsApp instead. "Very few people were opting in to end-to-end encrypted messaging in DMs, so we're removing this option from Instagram in the coming months," the spokesperson said. "Anyone who wants to keep messaging with end-to-end encryption can easily do that on WhatsApp." It’s quite the reversal for a corporation that spent years telling everyone that encryption was the future of online communications, even as governments pushed back against the company’s wider rollout plans. Much of that pressure centered on child protection. Campaigners and agencies, including the NSPCC UK’s National Crime Agency, argued wider encryption would make it harder to detect grooming, child abuse material, and other criminal activity taking place over private messaging services. Privacy advocates, however, say Meta has just blown a hole in one of the few genuinely private corners of the platform. The Center for Democracy & Technology said it had urged Meta to reverse the decision, alongside members of the Global Encryption Coalition Steering Committee. “Without default encryption, millions of Instagram users are left exposed to surveillance, interception, and misuse of their private communications,” the group said. “These risks fall hardest on people who rely on secure messaging for their safety, including journalists, human rights defenders, and survivors of abuse.” Swiss privacy outfit Proton also questioned what exactly happens to existing chats once encryption disappears. Because properly implemented E2EE prevents platforms from reading message contents, the company noted that Meta has not clarified whether previously encrypted conversations will remain inaccessible, get deleted, or become readable. “For Instagram, dropping E2EE is just an example of how little regard Meta has for the privacy and safety of its community,” Proton said in a blog post. Meta has become increasingly aggressive about monetizing and analyzing user interactions. Last year, the company confirmed that interactions with Meta AI tools, including those inside private conversations, could be used for ad targeting. The company has not publicly said whether ordinary Instagram messages could eventually feed into similar systems now that encryption is gone. ®
Categories: Linux fréttir

Vi clone written in BASIC proves old habits :wq hard

TheRegister - 3 hours 21 min ago
The veteran editor Vi turns 50 this year, and what better way to celebrate than to write a version in BASIC? The code was created by Lee Tusman, who likes to be a little out of step with the latest IT industry fads. Not strictly a professional programmer, Tusman, whose background is in art, began looking at BASIC in 2025. Specifically, Yabasic, an open source BASIC interpreter for Unix and Windows. "For a modern BASIC, it's quite fun to use," Tusman wrote. "I made my own cyber-hoss racing game, a command line game inspired by the UFO50 and Flash game Quibble Race. I also tinkered with the internals of the text version of The Oregon Trail, and built a clone, a simple version of Dope Wars economic simulation game." All of which brought Tusman to code up a version of the veteran text editor Vi, using BASIC because… well… it was there. "I've been using Neovim (and before that, Vim) for years and years. I've never made a text editor before. But I decided it could be fun to try to implement my own." Inspired by tools such as Offpunk, a text-based browser, "I thought I could likely build an ULTRA simple editor with a minimum of Vim commands. How hard could it be?" In this instance, not too hard at all. It only took a few hundred lines of Yabasic code to get a minimal blank page working before Tusman began adding simple commands. Before long, the editor had reached the point where it was possible to open a file, start a new one, and save. "This was satisfying as I was now able to open the actual code for my vi.bas program and poke around and edit it." There's no wrapping in Tusman's editor – 80 characters is the limit – but fire up the code from the GitHub repository, and a reasonable simulacrum of the venerable editor, along with a lot of its sometimes esoteric shortcuts, runs up. The Register asked Tusman why he chose Vi. "I chose Vi because I already use it, and of course, once you're addicted to it, it's hard to want to use any other style of editor." So what's missing? "Many things! But I'm purposefully not trying to rebuild a complete Vim. I just wanted something usable with as much functionality as I could build in as short and straightforward a program as I could write. Notably, most of it is 'if this key is pressed, do this.'" As for future development, "I don't know how much I'd add," Tusman said. "I've only been using the program a week or so, but haven't found much I completely miss from Neovim. I'm speculating here, but maybe I'd optionally add back in line numbers, and I haven't found a way to prevent errors when the screen gets resized that works cross-platform." In his post, Tusman notes that while the code won't win any prizes for its beauty, it is functional and can be tinkered with. It's also in the public domain, and so could be forked if there's a function that a BASIC wrangler can't do without. A look at the source certainly brought back some memories for this hack, who cut his teeth on TI BASIC in the very early 1980s and hasn't gone near the language since uninstalling Visual BASIC 6 decades ago. "It's not only the best Vi clone I've found written in a BASIC implementation," Tusman wrote. "I think it's the only one!" ®
Categories: Linux fréttir

UK abandons police database cloud move after £35M transformation stalls

TheRegister - 3 hours 34 min ago
The UK Home Office is bringing the Police National Database (PND) cloud migration in-house after a transformation program faced an additional £26 million in costs and an 18 months delay. The PND shares information across all police forces, law enforcement agencies, and regulatory bodies. The crucial system was meant to shift to the cloud, but the procurement project was delayed by more than a year, as The Register reported. In a letter to MPs, Home Office Permanent Secretary Gareth Davies said the cloud transition had been based on "delivery assumptions" that had proven incorrect. Davies said the Home Office had expected 80 percent of the code from the system, which went live in 2011, could be reused. In fact, only 20 percent was reusable. As a result, it would miss its June 2025 migration target without significant extra time and funding. "With the support contract expiring in March 2026 and no further direct award available, the programme explored contingency options, but analysis concluded continuation was not value for money ," Davies said in the written response to Parliament's Home Affairs Committee. "The programme decided it would exit the contract, bringing the service into Home Office control and in-house support." The PND was proposed following the 2002 murders of two 10-year-old girls in Soham. The subsequent Bichard Inquiry identified serious weaknesses in police intelligence, including the inability of forces to access potentially important information held outside their own geographic jurisdictions. Those gaps contributed to poor information-sharing about Ian Huntley, who murdered the girls. CGI won the contract in 2009 and the system was launched in April 2011. Elements of the current PND transformation program include a transition to cloud-native architecture, improved usability, and the replacement or updating of obsolete Oracle databases and middleware. A transparency notice published in 2024 said that since 2016, investment in the system was limited to "keeping the lights on" because of the introduction of the National Law Enforcement Data Programme (NLEDP). NLEDP imagined the Police National Computer (PNC) would be combined with the PND, creating a single system. "However, between 2016 and 2020 NLEDP faced some significant challenges that impacted progression and delivery ," the notice said. "Upon various reviews of NLEDP the decision was made for a complete reset of the programme, with PND being removed from the scope of work." "The PND transformation is being delivered to address the technological debt in PND which is causing a failing service." According to Davies' letter, the PND program was set up in 2021 but did not commence until January 2024. "By May 2025, around £35.1m had been spent before the transformation was paused," it said. Running, sustaining, and maintaining the live service cost about £24 million a year, amounting to £111.5 million since FY2021/22. Total PND spend over FY2021/22 to FY2025/26 was £146.6 million. Despite the money invested in the program, the Home Office and CGI were unable to agree a revised plan to move it forward. "Both the Home Office and the supplier worked closely together for many months to understand the depth of the challenges ," the letter said. "We [the Home Office] ultimately put our trust in the supplier's expertise and track record in providing and maintaining PND since 23 June 2011. From July to December 2024, the Home Office held workshops with the supplier to agree a realistic revised Initial Implementation Plan… The two sides could not come to an agreement, however, in particular about the contracted scope, time required for testing and allocation of residual risk." The Home Office said it reached a settlement with the supplier but did not disclose the terms. Davies admitted that the cloud migration work did not result in any improvements to the PND because the project was incomplete, although "upgrades have been made to the live system to ensure its security and stability." The Home Office now plans to move the PND from a CGI site to its datacenter, promising "robust governance drawing on prior transfer experience." It promised to mitigate disruption risks resulting from the "age and complexity of the legacy infrastructure." It is promising to make the on-prem system more secure, stable, and available at a cost of £20.3 million. "These upgrades are expected to extend service continuity by 5-10 years by tackling technical debt, improving resilience and capacity, and supporting enhanced analytics and safeguarding," the letter said. "The service remains stable, with customer-facing availability above 99 percent over the past six months, and the team proactively monitors servers and responds quickly to issues, including known legacy software risks. With the control in place with the addition of the stabilisation plans, the risk of major failure is anticipated to be low." ®
Categories: Linux fréttir

GameStop CEO's eBay account reinstated following takeover PR stunt

TheRegister - 4 hours 4 min ago
GameStop CEO Ryan Cohen has had his eBay account reinstated after the platform suspended him for selling personal items to help fund his takeover bid for the digital auction house. Less than 12 hours after Cohen announced he was selling various memorabilia and vintage wares to fund the proposed $55.5 billion buyout offer made earlier in the week, he shared a screenshot of an email informing him that his PR stunt had landed him a platform ban. "We wanted to let you know that your eBay account has been permanently suspended because of activity that we believe was putting the eBay community at risk," the email read. "We understand that this must be frustrating, but this decision was not made lightly and it's important that we keep our marketplace safe for everyone. For more information, see our article on how and why accounts can be suspended or review our User Agreement." The Register asked eBay why it suspended and reinstated Cohen's account, but the company did not immediately respond. Supporters of GameStop's bid for the auction site can show it via Cohen's page, where they can pick up rare games, tech, and other valuables. Highlights among the 36 listings include genuine GameStop storefront signs, which are currently going for just under $15,000 with bidding still open, and a Halo 2 Master Chief statue going for a similar amount. Cohen's original Apple iPhone is also up for grabs, with bidding now topping $9,100, and he has some baseball trading cards going for several thousand dollars too. He said that the winning bidder on each item will receive a hand-signed "Letter to eBay" as thanks for their support. GameStop's bid GameStop announced its offer to buy eBay on May 3 at $125 per share - a 46 percent increase on its February 4 closing price - which is the date GameStop first started buying eBay shares, taking its ownership stake to 5 percent. Cohen said if the bid is successful, GameStop and eBay will operate as a combined company, and the CEO, who took over the gaming retail business in 2021, would pursue $2 billion in cost reductions in the first year. This would include slashing eBay's current $2.4 billion marketing budget in half, as well as reductions across product development and general administration. While eBay share price rallied following the announcement, GameStop stock fell by around 10 percent following an interview Cohen gave to CNBC. In it, he shied away from calling the buyout proposal "hostile," instead opting to call it "unsolicited," and failed to robustly answer questions about the structure of the deal. Asked about the value in the context of GameStop's $12 billion market cap, Cohen repeated the information previously stated in the initial announcement: the purchase will comprise half cash and half GameStop stock, and it had secured a $20 billion financing letter from TD Bank. He declined to elaborate further. Already widely reported, investor Michael Burry of The Big Short fame dumped his GameStop shares after the company outlined its proposed deal structure, telling his Substack subscribers that it was over-leveraged. eBay acknowledged GameStop's bid on Monday, and said it would discuss it at board level. "Until the Board has further carefully and thoroughly considered the proposal, the company does not intend to comment further at this time." ®
Categories: Linux fréttir

First Segment of the Fehmarnbelt Tunnel Is In Place

Slashdot - 4 hours 51 min ago
Longtime Slashdot reader Qbertino writes: The Fehrmarnbelt tunnel is a European construction megaproject building a tunnel between Denmark and Germany, crossing the Fehmarnbelt in the Baltic sea. The first segment of the tunnel has now successfully been placed in its designated spot. This is a yet-unseen, next-level engineering feat achieved by the Danish Sund & Baelt construction company. It took 14 hours and used a massive pontoon ship built specifically for this project. The tunnel segments are 217 meters long, weigh more than 73,000 metric tons, and have to be placed within a tolerance of 3 mm. The tunnel will eventually consist of 89 of these segments, be 18 km long, and connect the Danish city of Rodby with the German island Fehmarn through five individual tunnel tubes: two for cars, two for trains, and one rescue and maintenance tunnel. Crossing time will be reduced from a 45-minute ferry crossing to seven minutes by train or 10 minutes by car, and cut the travel time between the German city of Hamburg and the Danish capital, Copenhagen, down to 2.5 hours. The project's planned completion is set for the year 2029. German news Tagesschau has some details and a neat animation, while further details are available from the German tech news site Heise.

Read more of this story at Slashdot.

Categories: Linux fréttir

Hackers ate my homework: Educational SaaS Canvas down after cyberattack

TheRegister - 4 hours 52 min ago
Students around the world have an excuse to bunk off after hacking crew ShinyHunters did something nasty to educational SaaS Canvas. Canvas is widely used by schools and universities to communicate with students, publish and store course material, and collect assignments. An outfit called Instructure develops the software and an entry on its Status Page dated May 2 features Chief Information Security Officer Steve Proud stating the org "recently experienced a cybersecurity incident perpetrated by a criminal threat actor." "We are actively investigating this incident with the help of outside forensics experts. We are working quickly to understand the extent of the incident and actively taking steps to minimize its impact," he added. Numerous posts report that attempts to log into Canvas earlier this week failed, but did produce a notice from an entity claiming to be the notorious hacking crew ShinyHunters, who claimed the outage was only possible due to lax patching. The crew also claimed to have stolen data from institutions that use Canvas and threatened to leak it unless a "settlement" is reached by May 12. Canvas has thousands of customers, meaning any confirmed breach could have wide impact. As of Thursday evening US time, Canvas says its wares are now available "for most users" and won't offer further comment. A student of The Register's acquaintance – OK, one of my kids – shared an email advising that his uni has prevented access to Canvas while it tries to understand the situation and the risk of data leakage. We've seen multiple universities posting notices about the incident that say more or less the same thing. Most also warn students of heightened phishing risk and urge caution. Several also advise that as they require students to lodge assignments in Canvas, students can assume they have an extension on deadlines. Your correspondent's offspring does not mind this one little bit. This is an evolving story. The Register will update it as more information becomes available. ®
Categories: Linux fréttir

Meta fights Ofcom over how many billions count as billions

TheRegister - 5 hours 12 min ago
Meta appears to have decided Britain's Online Safety Act would be much easier to swallow if Ofcom stopped counting all the money the social media giant makes everywhere else. The Facebook and Instagram owner has launched a legal challenge against the UK comms regulator, arguing that the way Ofcom calculates fees and potential penalties under the Online Safety Act is fundamentally wrong because it relies on global turnover rather than UK-specific revenue. The law allows Ofcom to fine companies for up to 10 percent of their qualifying worldwide revenue, or £18 million, whichever is higher. For Meta, which brought in about $201 billion last year, that means the numbers stop sounding like regulatory penalties and start sounding like national infrastructure projects. Meta is now seeking a judicial review in the High Court over how Ofcom defines "qualifying worldwide revenue." The dispute boils down to three complaints. First, Meta argues that Ofcom should only consider UK revenue tied to regulated services, not the company’s global income. Second, it objects to rules that treat multiple services under the same corporate umbrella as jointly liable, potentially exposing the wider organization to larger penalties. Third, it is challenging how Ofcom aggregates revenue across services rather than assessing them individually. An Ofcom spokesperson told The Register: "Meta have initiated a judicial review in relation to online safety fees and penalties. Under the Online Safety Act, these are to be set with reference to a provider's 'Qualifying Worldwide Revenue', which we have defined based on a plain reading of the law. "Disappointingly, Meta are objecting to the payment of fees, and any penalties that could be levied on companies in future, that are calculated on this basis. We will robustly defend our reasoning and decisions." A Meta spokesperson told The Register: "We are committed to cooperating constructively with Ofcom as it enforces the Online Safety Act. However, we and others in the tech industry believe its decisions on the methodology to calculate fees and potential fines are disproportionate. We believe fees and penalties should be based on the services being regulated in the countries they're being regulated in. This would still allow Ofcom to impose the largest fines in UK corporate history." The case marks the latest flare-up between Silicon Valley and Britain over the Online Safety Act, which has already triggered complaints from US politicians, free speech campaigners, and tech firms unhappy about the scale of Ofcom’s new powers. The regulator has not been shy about flexing them either. It has already threatened action against Elon Musk's X over sexually explicit AI-generated images linked to Grok and, in March, issued its first fine under the regime against 4chan. Meta appears to have looked at where that enforcement road leads and decided now was the time to argue about the math. ®
Categories: Linux fréttir

BOFH: Nothing says 'business continuity' like a dry wooden broom

TheRegister - 6 hours 1 min ago
EPISODE 9 It's 3:30 am and I'm at work, having been woken up by numerous outage notifications. The Boss – as useful as Jason Statham's method acting coach – is also on site, presumably to offer moral support. The Building Manager – who's so old that his CV likely includes the construction of a vessel for the shipping of pairs of animals – is nowhere to be seen. The PFY is also absent. His excuse will likely be that he "accidentally" put his phone into silent mode. Had any of the alerts been from his rack of Bitcoin mining machines, however, he'd have been in the office in a flash. Security appears to be hard at work protecting the couches in the foyer of the building from being stolen. The rest of the building is in darkness – save for the shining beacon that is Mission Control. "What's happened?" the Boss asks. "Power outage," I reply. "Do we get someone in for that?" "Only if we want to wait till 9am to call our electrical contractors, who'll agree to turn up between 9 and 5 sometime in the next two weeks." "So what do we do?" "We go to the basement!" I reply, "but first we need THE KEYS". "The keys?" "No. THE KEYS." "What are THE KEYS?" he asks. "THE KEYS are what ex-local government buildings like this have for access to places you're not supposed to go. They're for the rooms you 'accidentally' show people if you think they're planning a hostile takeover of the company. You open the door and say something like 'I'm pretty sure that's not asbestos' or 'Why would we have needed all those leaky drums of 2,4,5-Trichlorophenoxyacetic acid ?'" "Are the rooms dangerous?" "Not if you keep the doors closed." "So what are you going to do?" "I'll open a couple of the doors." ...Five minutes later in the basement... "Oooh, there's a clue," I say to the Boss, pointing. "A Bakelite – or, to be specific, phenolic – label. Circa 1970s. There's bound to be something horrible behind that door." >creak< ... >slam< "Moving on," I say. "What was behind the door?" "Something horrible. We're not talking 'three-hour Richard Stallman monologue' horrible, but it was pretty bad. Anyway, let's try door number two." >creeeeeeak< "Ah, now this is promising. Cables from the ceiling. Unless they're snakes." "SNAKES!" the Boss gasps. "Nah, just cables. And, look, ALL METAL service breakers – and not a speck of safety-oriented insulation to be seen!" "What does that mean?" "It means life was cheap back in the '70s. Now, see those four massive breakers, all pointing to the Bakelite ON position, and one ABSOLUTELY MASSIVE breaker over there, in the OFF position?" "Yes. Do we just turn it on?" the Boss asks. "Only if you want to save your loved ones the cremation fees." "?" "The smaller breakers are three-phase 1,000-amp units, but that big one's a 5,000-amp unit. Designed for the days when offices were crammed with people and bar heaters." "So what do we do?" the Boss asks. "We get a broom. A wooden broom. A DRY wooden broom. Then we turn OFF all the massive breakers, then turn ON the REALLY massive breaker." ...Two minutes later... "Is this safe?" the Boss asks nervously. "Not even slightly," I say, brandishing the broom. >CLACK!< >CLACK!< >CLACK!< >CLACK!< "That wasn't so bad," the Boss sighs. "We're not to the good part yet. But maybe you want to move away a little bit." "How far?" "The third floor would be wise, but the doorway will do." .... >CLUNK!< ... "So we're... OK then?" the Boss asks. "In the words of Karen Carpenter, we've only just begun. Now we have to turn all of those smaller breakers on again, one of which will likely trip the massive breaker." "Is that a problem?" "The really massive breaker's over 50 years old, covered in rust, and has probably only ever tripped from a fault once. The miracle here is that it did so without exploding." "So?" "So, sometimes you've just got to spin the potato," I say, raising the broom again. >CLACK!< ... >CLACK!< ... >CLACK!< ... ... >CLACK!< "It worked!" the Boss gasps happily, as light returns to the building. "Yeeeessss," I say, leading the Boss out of the room and shutting the door as quickly as I can. "You... don't seem happy?" "No. There's a fair chance that whatever tripped the big breaker will trip it again the next time whatever it is star-" >FZZZZZ< >CLUNK< "Oh," the Boss says, disappointed. "Do we switch it back on again?" "Did you hear that buzzing sound before the lights went out?" "Uhhh, yes. What does that mean?" "It means we need to (a) go upstairs, (b) turn off the power to a rack of very noisy machines, and (c) switch our phones to silent and pretend we've never been here..." BOFH: Previous episodes on The RegisterThe Compleat BOFH Archives 95-99
Categories: Linux fréttir

Lego throws its own Hail Mary

TheRegister - 6 hours 36 min ago
Lego has released a set to coincide with the Project Hail Mary movie, and it's a clever bit of Technic-style engineering, even if the price is a little high. Usually, we only look at Lego builds of real objects – think Concorde and the recent Artemis set. However, having enjoyed Andy Weir's Project Hail Mary (the book more than the film), I was keen to see what Lego had done with its license. The answer is: it's good, but a bit pricey. The 830-piece set comprises a model of the eponymous spacecraft, a minifig-scale Ryland Grace, and Lego's version of the Rocky character. It also, thankfully, does not have the stickers that have blighted recent Lego sets. This set is not cheap, though Lego has at least invested in some pre-printed components rather than making customers fiddle with sticky transfers that invariably end up looking awful. Lego lists the set's age as 18+, which I'd quibble with. It's a lengthy (at least in terms of steps) but straightforward build. Budget around half a day to a full day for building it, depending on your skill level and how often little bits of Lego get flung around the room. Starting with the spacecraft, it's worth emphasizing that this is essentially a Technic set. If Technic components aren't your thing, this set isn't for you. However, persevere, and it is difficult not to be impressed with the design work. As the spacecraft comes together, so the mechanism reveals itself. Turn a crank, and the crew modules slide out before the entire spacecraft rotates to simulate gravity. Turn the crank in the opposite direction to return the crew modules. No, it's not like the book, but it is like the film, which deviates from the book in several other places too. We'd be tempted to fit a motor to achieve smoother rotation. The spacecraft is mounted on a stand that also includes a place for the Grace minifigure and the Rocky character. Both have pre-printed accessories, such as a tape measure, which will be familiar to those who have seen the film. It's a fun build and an impressive bit of Technic design. The elephant in the room, however, is cost. At £99.99 in the UK, this is not cheap. Certainly not when compared to the Artemis Technic set, which retails for £54.99. Turn the crank there, and the SLS rises, boosters separate, and Orion heads off to the Moon. Yes, there are fewer pieces (and some stickers to deal with), but for our money, it's a better value set. However, if you're a fan of Weir's book or the movie adaptation, there's a lot to like here, and the Technic designer deserves an award for making the mechanics of the spacecraft work. If only it were a little cheaper. ®
Categories: Linux fréttir

Bus station display takes the Windows 10 road to nowhere

TheRegister - 7 hours 21 min ago
BORK, BORK, BORK! There was a time when information boards were handwritten or paper-based affairs. Then departure information was shown on split-flap displays, which made a satisfying tick sound as the display changed. Pixel-based boards followed (we took a look at the excellent take-home-and-keep versions by UK Departure Boards in 2024, but, with the inevitability of death and taxes, Windows of course had to get involved, which brings us to this unhappy example spotted in a Northampton bus station by a Register reader. "This poor main display announcing bus times has been dying for a while," our reader said. "The time has been out by 3-4 minutes, meaning any passenger trying to get somewhere on time would have missed their bus. Now its time info software is not loading." The screen looks like Windows 10 is running in the background, but instead of helpful information for customers taking a bus journey, there's just the default Windows desktop background and a few forlorn icons. The screen has been fitted with spikes to prevent birds from perching and leaving deposits, no such luxury has been afforded to the software. Somebody crueler than us might suggest this is because no feathered friend would deign to perch atop Microsoft's finest, or that a healthy dose of bird droppings could only improve the appearance of Windows. The bus station in question is Northgate, a relatively recent addition to Northampton's architectural landscape, opened in 2014. Windows 10 was released the following year and now clings, limpet-like, to the information boards. Our reader's comment that the display appears to be wheezing its last is, of course, nothing to do with Microsoft's fervent wish that Windows 10 would hurry up and die so that it can notch up more Windows 11 users. The question is, would Northampton's avian chums be any keener on the display if it were running the latest and greatest? Certainly, Windows 11 could use some improvements. Even Microsoft has admitted as much, but we're not sure the rear of a bird is where those improvements should come from. ®
Categories: Linux fréttir

Custom PC worked in the lab, failed on site – and so did the angry client

TheRegister - 8 hours 51 min ago
No week at The Register is complete without a new installment of On Call, the reader-contributed column in which you share tales of the peaks and troughs of the tech support experience. So let's get going and meet this week's contributor, who we shall Regomize as "Gerald." He took us back to an early moment in his career, when he worked for an outfit that configured Windows 98 PCs as "data collectors" for its clients. As part of his job, Gerald built PCs and provided field support. In this story, he built a new data collector, checked that it worked with the usual round of tests, and left it for someone else to install because he had another job to do elsewhere for a different client. That visit was interrupted by his boss, who Gerald said "reamed me out for allowing a non-functional system to leave the shop." After the criticism stopped, Gerald's boss ordered him to fix the stricken PC, ASAP, even though it was 100 km away by car. "The boss man said go, so I went," Gerald told On Call. "About an hour and a half later, I arrived to diagnose the recalcitrant PC. The client was literally hopping mad and asking how I could be so stupid, because his firm was losing money." Gerald got to work and inspected the PC, which was on the shop floor, connected to power and peripherals. It booted and worked well but couldn't reach the network. "A check of devices installed showed the network card," Gerald reported, "and a ping to home worked... but nothing outside the box itself was reachable." Gerald decided the only thing to do was take the PC back to the office for more tests, so he started unplugging the peripherals. "Out came the power cord, display cable, keyboard, mouse..." and then he noticed the network cable wasn't plugged in. "It was neatly coiled and taped to a support column," Gerald told On Call, making it very easily fixed – and quite the embarrassment for the angry client and boss. Have you been abused for a customer's error? If so, click here to send On Call an email so we can share your story on a future Friday. ®
Categories: Linux fréttir

The Canvas Hack Is a New Kind of Ransomware Debacle

Slashdot - 8 hours 51 min ago
Wired describes the recent Canvas breach as an unusually disruptive ransomware-style extortion incident because one attack on Instructure's learning platform temporarily paralyzed thousands of schools during finals and end-of-year assignments. The hackers using the "ShinyHunters" name claim more than 8,800 schools were affected, while Instructure says exposed data included names, email addresses, student ID numbers, and platform messages. From the report: Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States. The widely used digital learning platform Canvas was put into "maintenance mode" on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker "ShinyHunters." Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments. Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture. In a running incident update log that began on May 1, Steve Proud, Instructure's chief information security officer, said that the company had "recently experienced a cybersecurity incident perpetrated by a criminal threat actor." He added on May 2 that "the information involved" for "users at affected institutions" included names, email addresses, student ID numbers, and messages exchanged by users on the platform. The situation was ultimately marked as "Resolved" on Wednesday, with Proud writing that "Canvas is fully operational, and we are not seeing any ongoing unauthorized activity." At midday on Thursday, though, the Instructure status page registered an "issue" where "some users are having difficulties logging into Student ePortfolios." Within a few hours, the company had added another status update: "Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode." Late Thursday evening, the company said that Canvas was available again "for most users." TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools' Canvas portals by injecting an HTML file to display their own message on the schools' Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach. The message from attackers "urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12 -- or else risk their data being leaked," The Crimson reported. "It is unclear what information tied to Harvard affiliates was included in the alleged breach."

Read more of this story at Slashdot.

Categories: Linux fréttir

Cloudflare to fire 1,100 staff whose jobs just aren’t AI enough

TheRegister - 11 hours 53 sec ago
Cloudflare has revealed it will farewell 1,100 staff, due to its current and future use of AI. In a blog post that oozes Orwellian “doublespeak,” CEO Matthew Prince and President/COO Michelle Zatlyn used the headline “Building for the future” to share the email they sent to all employees. That mail opens: “We are writing to let you know directly that we’ve made the decision to reduce Cloudflare’s workforce by more than 1,100 employees globally.” The post explains, “Cloudflare’s usage of AI has increased by more than 600% in the last three months alone. Employees across the company from engineering to HR to finance to marketing run thousands of AI agent sessions each day to get their work done.” All that AI means “we have to be intentional in how we architect our company for the agentic AI era in order to supercharge the value we deliver to our customers and to honor our mission to help build a better Internet for everyone, everywhere.” Sackings are therefore needed, and are “about defining how a world-class, high-growth company operates and creates value in the agentic AI era.” To rub salt into the wounds of sacked staff, the email went out not long before Cloudflare announced quarterly results that included 34 percent year-over-year revenue growth and guidance for 30 percent future growth. Prince opened the company’s earnings call by stating “We had a very strong start to 2026.” Analysts on the earnings call asked Prince to explain the layoffs and whether they will make Cloudflare stronger. “We have seen that there are roles at Cloudflare that are not the roles we need for the future,” Prince responded. “Just because you are fit does not mean you cannot get fitter. Over the last six months especially, the productivity gains from the people directly talking to customers and directly creating code have been incredible, and a lot of the support roles behind them are not going to be the roles that drive companies going forward.” The CEO said Cloudflare has “always lived a little bit in the future” and said the company is an early beneficiary of AI. And he said the company will keep hiring. “The people embracing these tools are so much more productive than we have ever seen before,” he said. “I would guess that in 2027 we will have more employees than we did at any point in 2026, but the roles are changing dramatically, and you have to do something dramatic to make that shift.” “This is not about downsizing or saving costs,” Prince said. “This is about having the right people in the right roles to build the future.” As is often the case these days, the email to staff warned them of a brief doomsday countdown. “Within the next hour, every member of our global team will receive an email from both of us clarifying how this change affects them,” the message states. “For those departing today, we will send this update to both their personal and Cloudflare addresses to ensure they receive the information immediately.” The Register imagines that went down well for workers in time zones where employees might avoid their work email outside 9-5, but sneak an early-morning-or-late-night-glance at their personal inboxes. Prince and Zatlyn told employees they hope “to do this only once” and then contradict themselves by saying they “don’t want to do it again for the foreseeable future.” “By taking decisive action now, we provide immediate clarity to those departing and protect the stability of the team that remains,” they wrote, before adding their view that one deep cut because “dragging a reorganization out over multiple quarters creates prolonged emotional uncertainty for employees and stalls our ability to build.” Firing 1,100 people is therefore “the right thing to do; it’s the honest thing to do; and it reflects the values of the company we are continuing to build.” ®
Categories: Linux fréttir

Sam Altman Had a Bad Day In Court

Slashdot - 12 hours 1 min ago
An anonymous reader quotes a report from Business Insider: As the trial between Elon Musk and OpenAI ended its second week, the Tesla CEO started scoring points against Sam Altman. His witnesses landed three solid punches in testimony about how Altman runs OpenAI as CEO, raising concerns about his dedication to AI safety, the nonprofit's mission, and his honesty as a leader of the organization. [...] This week, Musk's legal team called a parade of witnesses who questioned whether Altman was acting in the interest of the nonprofit. On Thursday, that included a former OpenAI safety researcher, who described a slow erosion of the company's safety teams, which prompted her to leave the company. Witnesses also shared stories about the company launching products without the proper safety reviews -- or the knowledge of the board. Rosie Campbell, a former AI safety researcher at OpenAI, testified that the company became more product-focused during her time there and moved away from the long-term safety work that had initially drawn her in. She said both long-term AI safety teams were eventually eliminated, and that she supported Altman's reinstatement only because she feared OpenAI might otherwise collapse into Microsoft: "It was my understanding at the time that the best way for OpenAI to not disintegrate and fall about would be for Sam to return." Still, Campbell's testimony wasn't entirely favorable to Musk. She also said xAI, Musk's AI company, likely had an inferior approach to safety than OpenAI. Helen Toner, another former OpenAI board member, also testified about the board's concerns leading up to Altman's removal. She said the board was not primarily worried about ChatGPT's safety, but about Altman's leadership and investor relationships, saying, "The issues that we were concerned about in our decision to fire Sam were exacerbated by relationships with investors." Toner also described concerns that Altman was misrepresenting what others had said, telling the court, "We were concerned that Sam was inserting words into other people's mouths in order to get people to do what he wanted." Meanwhile, Tasha McCauley, a former OpenAI board member, described a deep loss of trust in Altman and accused him of creating "chaos" and "crisis" inside the company. She said Altman fostered a "culture of lying and culture of deceit," including allegedly misleading others about whether GPT-4 Turbo needed internal safety review before launch. Musk's lawyers then called to the stand David Schizer, a Columbia Law professor and nonprofit-governance expert, who framed Altman's alleged behavior as a serious governance problem for an organization that was supposed to be mission-driven. Asked about claims that products were launched without full board awareness or safety review, he said, "The board and CEO need to be partnering, working together, to make sure the mission is being followed," adding that "if the CEO is withholding that information, it's a big problem." The day ended with the start of a Microsoft executive's deposition. Microsoft VP Michael Wetter said Azure had integrated OpenAI technology, that Microsoft saw strategic value in having AI developers build on Azure, and that a 2016 agreement allowed OpenAI to use Microsoft tools for free even though it could mean a loss of up to $15 million for Microsoft. Testimony ended early, with no court on Friday and the trial set to resume Monday. Recap: Sam Altman's Management Style Comes Under the Microscope At OpenAI Trial (Day Seven) Brockman Rebuts Musk's Take On Startup's History, Recounts Secret Work For Tesla (Day Six) OpenAI President Discloses His Stake In the Company Is Worth $30 Billion (Day Five) Musk Concludes Testimony At OpenAI Trial (Day Four) Elon Musk Says OpenAI Betrayed Him, Clashes With Company's Attorney (Day Three) Musk Testifies OpenAI Was Created As Nonprofit To Counter Google (Day Two) Elon Musk and OpenAI CEO Sam Altman Head To Court (Day One)

Read more of this story at Slashdot.

Categories: Linux fréttir

AWS warns of EC2 ‘impairment’ as power loss hits notorious US-EAST-1 region

TheRegister - 13 hours 18 min ago
Amazon Web Services is working to address a power outage that has created “impairments” to services served from the notorious US-EAST-1 region. A May 7 incident report time-stamped 5:25 PM PDT (00:25 UTC Friday) states that AWS spotted problems in the use1-az4 availability zone of the US-EAST-1 Region. A subsequent update states “EC2 instances and EBS volumes hosted on impacted hardware are affected by the loss of power during the thermal event.” An update time-stamped 6:47 PM PDT reveals“We continue to work towards mitigating the increased temperatures to its normal levels,” but warns “Other AWS services that depend on the affected EC2 instances and EBS volumes in this Availability Zone may also experience impairments.” At 8:06 PM PDT Amazon said it was "actively working to restore temperatures to normal levels ... though progress is slower than originally anticipated." The cloudy concern said it made "incremental progress to restore cooling systems" but users of EC2 Instances, EBS Volumes, and other services are "experiencing elevated error rates and latencies for some workflows." AWS has also shifted traffic away from the stricken AZ, and suggested companies shift workloads into other US-EAST-1 availability zones. Good luck getting that done because the update admits “Customers may experience longer than usual provisioning times.” US-EAST-1 is arguably AWS’s problem child, as it was the site of major outages that took big chunks of the internet offline in 2021 and then again in October 2025 . AWS execs have told The Register the region isn’t inherently more fragile than other parts of the Amazonian cloud, but often runs things at bigger scale than elsewhere and therefore imposes extra stress on services. The Register will update this story as the situation evolves. ®
Categories: Linux fréttir

HPE drops first Juniper x Aruba collab – self-driving Wi-Fi

TheRegister - 13 hours 51 min ago
HPE has delivered the first fruits of its Juniper acquisition: Wi-Fi access points that users can manage with either Aruba Central or the Mist platform, and “self-driving” tools that use AI to allow some autonomous operations. The access points are the prosaically named HPE Networking 723H, a three-radio Wi-Fi 7 machine the company recommends for hospitality, branch, and teleworker deployments. The APs also represent HPE’s first application of AI-powered autonomous networks. Mittal Parekh, HPE’s marketing lead for campus and branch networking, told The Register one self-driving scenario HPE provides is scanning the local RF environment to detect any frequencies Wi-Fi should avoid because they’re required or in use by military or other organizations that have priority. Self-driving means networks will automatically steer clear of those frequencies when it makes sense to do so. He also pointed to “dynamic capacity optimization,” which he said will see HPE Wi-Fi networks detect a gathering of users for events like an all-hands meeting, and adjust itself as necessary to ensure connections remain strong and steady. Detecting mismatched or missing VLANs, and rebuilding networks before traffic drops, is another self-driving capability. Parekh said those scenarios currently require IT teams to do manual work that might not be possible to complete before the meeting ends, or a military user vacates a frequency. HPE’s tech will also detect and de-fang rogue DHCP servers before they become a problem. Parekh said HPE’s tech allows humans to remain in the loop if they choose but hopes that NetAdmins begin to develop sufficient trust that they let networks take care of their own affairs and spend their time on higher-value tasks. The application that delivers self-driving capabilities runs in the cloud, and uses oodles of data HPE and Juniper collected over decades, plus the Marvis AI Juniper offered when it was an independent outfit. Jeff Aaron, marketing lead for HPE’s networking business unit, pointed out that HPE has delivered a unified product within months of closing its Juniper acquisition, and snarked that Cisco took years to do likewise when merging its own-brand Wi-Fi with Meraki’s. Competitive sniping aside, Aaron said the self-driving tech and Wi-Fi APs show how HPE plans to cross-pollinate its Aruba and Juniper portfolios, without forcing users of either brand to make a jump. HPE is not alone in pursuing agentic network operations, or merging networking brands: Cisco is combining its Catalyst and Meraki management tools, and is betting on AI to detect network issues and automate fixes. ®
Categories: Linux fréttir

Mozilla boasts Mythos boosted Firefox bug cull

TheRegister - Thu, 2026-05-07 23:32
Mozilla fixed 423 Firefox security bugs in April, a repair rate more than five times higher than the 76 fixes issued in March and almost 20 times higher than its 21.5 monthly average last year. The browser maker previously said Anthropic's ballyhooed Mythos Preview model found 271 of these in Firefox 150. Now, a trio of technical types has come forward to provide a bit more detail about what Mythos (and its less storied sibling Opus 4.6) actually found. But they also highlight something that may matter more than the model: the agentic harness – the middleware mediating between AI and the end user. Brian Grinstead, Firefox distinguished engineer, Christian Holler, Firefox tech lead, and Frederik Braun, head of the Firefox security team, observe that over the past few months, AI-generated security reports have gone from slop to rather more tasty. They attribute the transformation to better models and development of better ways of harnessing those models – steering them in a way that increases the ratio of signal to noise. But they also appear to be aware that there's some skepticism in the security community about Mythos. So they've decided to publicize selected wins in an effort to encourage others to jump aboard the AI bug remediation train. "Ordinarily we keep detailed bug reports private for several months after shipping fixes and issuing security advisories, largely as a precaution to protect any users who, for whatever reason, were slow to update to the latest version of Firefox," they said. "Given the extraordinary level of interest in this topic and the urgency of action needed throughout the software ecosystem, we’ve made the calculated decision to unhide a small sample of the reports behind the fixes we recently shipped." The post links to a dozen Firefox bugs with varying degrees of severity. The list includes, for example, a 20-year-old heap use-after-free bug (high severity) that a web page could trigger using the XSLTProcessor DOM API without any user interaction. Many of these bugs are sandbox escapes, they note, which are difficult to find using techniques like fuzzing. AI analysis, they say, helps provide broader security coverage. And they add that it has helped validate prior browser hardening work designed to prevent prototype pollution attacks – audit logs showed AI models making unsuccessful exploitation attempts using this technique. Following Anthropic's announcement of Project Glasswing – a program for companies to gain early access to Mythos because it's touted as too dangerous for public release – security experts expressed skepticism. For example, Davi Ottenheimer, president of security consultancy flyingpenguin, wrote in an April 13 blog post, "The supposedly huge Anthropic 'step change' appears to be little more than a rounding error. The threat narrative so far appears to be ALL marketing and no real results. The Glasswing consortium is regulatory capture dressed up poorly as restraint." He subsequently ran a test in which he strapped Anthropic's lesser models Sonnet 4.6 and Haiku 4.5 into a harness called Wirken with an auditing skill called Lyrik. The result was eight findings in two minutes at a cost of about $0.75, Ottenheimer claims, noting that two of the eight matched bugs Mythos had identified. Other security folk have also reported that bug hunting and exploit development can be quite productive with off-the-shelf models like Opus 4.6, which among other virtues costs about 5x less than Mythos. In an email to The Register, Ottenheimer said, "There's a fundamental philosophical failure in the Mozilla post. A reading and a measurement are not the same thing. I don't see a measurement, but they seem to want us to believe we're looking at one. "When they give us the 'behind the scenes math' it's circular, a trick. 'Mythos found 271 bugs' is what Mythos found, not what other tools could not find against the same code. Why leave it as an assumption if it can be proven?" Ottenheimer said Mozilla advocates that every project adopt a similar approach without proving the merits of that approach. "It's like saying if you don't drink Coca-Cola, you can't run a mile under six minutes, because that's what a guy sponsored by Coca-Cola just did," he said. "The bar moves on rhetoric, marketing, not proper evidence. That is the capture crew again." He notes that the merits of Mythos might be more convincing if Mozilla had reported they couldn't do this work without Mythos. And since they're not saying that, he suggests, it's worth asking why there's no transparent comparison of Mythos to other models. He points to Mozilla's admission that Opus 4.6 was already identifying "an impressive amount of previously unknown vulnerabilities." "Mozilla never quantifies what Opus 4.6 [did] before saying what Mythos added," he said. "So 271 attributed to Mythos doesn't fit the analysis. And there's a deeper reveal when they say 'we dramatically improved our techniques for harnessing these models.' The improvement may be entirely in the harness, not as much in the model. This maps to my own experience. A nail gun has advantages over the hammer, yet without being in the right hands the outputs are as bad or worse." ®
Categories: Linux fréttir

Pages

Subscribe to www.netserv.is aggregator - Linux fréttir