Join our Folding@Home team:
Main F@H site
Our team page
Support us: Subscribe Here
and buy SoylentNews Swag
We always have a place for talented people, visit the Get Involved section on the wiki to see how you can make SoylentNews better.
Alan Turing's Top Secret DIY Project:
It was 8 May 1945, Victory in Europe Day. With the German military's unconditional surrender, the European part of World War II came to an end. Alan Turing and his assistant Donald Bayley celebrated victory in their quiet English way, by taking a long walk together. They had been working side by side for more than a year in a secret electronics laboratory, deep in the English countryside. Bayley, a young electrical engineer, knew little about his boss's other life as a code breaker, only that Turing would set off on his bicycle every now and then to another secret establishment about 10 miles away along rural lanes, Bletchley Park. As Bayley and the rest of the world would later learn, Bletchley Park was the headquarters of a vast, unprecedented code-breaking operation.
When they sat down for a rest in a clearing in the woods, Bayley said, "Well, the war's over now—it's peacetime, so you can tell us all."
"Don't be so bloody silly," Turing replied. "That was the end of that conversation," Bayley recalled 67 years later.
Turing's incredible code-breaking work is now no longer secret. What's more, he is renowned both as a founding father of computer science and as a pioneering figure in artificial intelligence. He is not so well-known, however, for his work in electrical engineering. This may be about to change.
In November 2023, a large cache of his wartime papers—nicknamed the "Bayley papers"—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing's own handwriting, telling of his top-secret "Delilah" engineering project from 1943 to 1945. Delilah was Turing's portable voice-encryption system, named after the biblical deceiver of men. There is also material written by Bayley, often in the form of notes he took while Turing was speaking. It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away.
When the British Government learned about the sale of these papers at auction, it acted swiftly to put a ban on their export, declaring them to be "an important part of our national story," and saying "It is right that a UK buyer has the opportunity to purchase these papers." I was lucky enough to get access to the collection prior to the November sale, when the auction house asked for my assistance in identifying some of the technical material. The Bayley papers shine new light on Turing the engineer.
At the time, Turing was travelling from the abstract to the concrete. The papers offer intriguing snapshots of his journey from his prewar focus on mathematical logic and number theory, into a new world of circuits, electronics, and engineering math.
During the war, Turing realized that cryptology's new frontier was going to be the encryption of speech. The existing wartime cipher machines—such as the Japanese " Purple" machine, the British Typex, and the Germans' famous Enigma and teletypewriter-based SZ42—were all for encrypting typewritten text. Text, though, is scarcely the most convenient way for commanders to communicate, and secure voice communication was on the military wish list.
Bell Labs' pioneering SIGSALY speech-encryption system was constructed in New York City, under a U.S. Army contract, during 1942 and 1943. It was gigantic, weighing over 50 thousand kilograms and filling a room. Turing was familiar with SIGSALY and wanted to miniaturize speech encryption. The result, Delilah, consisted of three small units, each roughly the size of a shoebox. Weighing just 39 kg, including its power pack, Delilah would be at home in a truck, a trench, or a large backpack.
In 1943, Turing set up bench space in a Nissen hut and worked on Delilah in secret. The hut was at Hanslope Park, a military-run establishment in the middle of nowhere, England. Today, Hanslope Park is still an ultrasecret intelligence site known as His Majesty's Government Communications Centre. In the Turing tradition, HMGCC engineers supply today's British intelligence agents with specialized hardware and software.
Turing seems to have enjoyed the two years he spent at Hanslope Park working on Delilah. He made an old cottage his home and took meals in the Army mess. The commanding officer recalled that he "soon settled down and became one of us." In 1944, Turing acquired his young assistant, Bayley, who had recently graduated from the University of Birmingham with a bachelor's degree in electrical engineering. The two became good friends, working together on Delilah until the autumn of 1945. Bayley called Turing simply "Prof," as everyone did in the Bletchley-Hanslope orbit.
"I admired the originality of his mind," Bayley told me when I interviewed him in the 1990s. "He taught me a great deal, for which I have always been grateful."
In return, Bayley taught Turing bench skills. When he first arrived at Hanslope Park, Bayley found Turing wiring together circuits that resembled a "spider's nest," he said. He took Turing firmly by the hand and dragged him through breadboarding boot camp.
A year later, as the European war ground to a close, Turing and Bayley got a prototype system up and running. This "did all that could be expected of it," Bayley said. He described the Delilah system as "one of the first to be based on rigorous cryptographic principles."
How Turing's Voice-Encryption System Worked
Turing drew inspiration for the voice-encryption system from existing cipher machines for text. Teletypewriter-based cipher machines such as the Germans' sophisticated SZ42—broken by Turing and his colleagues at Bletchley Park—worked differently from the better known Enigma machine. Enigma was usually used for messages transmitted over radio in Morse code. It encrypted the letters A through Z by lighting up corresponding letters on a panel, called the lampboard, whose electrical connections with the keyboard were continually changing. The SZ42, by contrast, was attached to a regular teletypewriter that used a 5-bit telegraph code and could handle not just letters, but also numbers and a range of punctuation. Morse code was not involved. (This 5-bit telegraph code was a forerunner of ASCII and Unicode and is still used by some ham radio operators.)
The SZ42 encrypted the teletypewriter's output by adding a sequence of obscuring telegraph characters, called key (the singular form "key" was used by the codebreakers and codemakers as a mass noun, like "footwear" or "output"), to the plain message. For example, if the German plaintext was ANGREIFEN UM NUL NUL UHR (Attack at zero hundred hours), and the obscuring characters that were being used to encrypt these three words (and also the space between them) were Y/RABV8WOUJL/H9VF3JX/D5Z, then the cipher machine would first add "Y" to "A"—that is to say, add the 5-bit code of the first letter of the key to the 5-bit code of the first letter of the plaintext—and then added "/" to "N", then "R" to "G", and so on. Under the SZ42's rules for character addition (which were hardwired into the machine), these 24 additions would produce PNTDOOLLHANC9OAND9NK9CK5, which was the encrypted message. This principle of generating the obscuring key and then adding it to the plain message was the concept that Turing extended to the new territory of speech encryption.
Inside the SZ42, the key was produced by a key generator, consisting of a system of 12 wheels. As the wheels turned, they churned out a continual stream of seemingly random characters. The wheels in the receiver's machine were synchronized with the sender's, and so produced the same characters—Y/RABV8WOUJL/H9VF3JX/D5Z in our example. The receiving machine subtracted the key from the incoming ciphertext PNTDOOLLHANC9OAND9NK9CK5, revealing the plaintext ANGREIFEN9UM9NUL9NUL9UHR (a space was always typed as "9").
Applying a similar principle, Delilah added the obscuring key to spoken words. In Delilah's case, the key was a stream of pseudorandom numbers—that is, random-seeming numbers that were not truly random. Delilah's key generator contained five rotating wheels and some fancy electronics concocted by Turing. As with the SZ42, the receiver's key generator had to be synchronized with the sender's, so that both machines produced identical key. In their once highly secret but now declassified report, Turing and Bayley commented that the problem of synchronizing the two key generators had presented them with "formidable difficulties." But they overcame these and other problems, and eventually demonstrated Delilah using a recording of a speech given by Winston Churchill, successfully encrypting, transmitting, and decrypting it.
This loose-leaf sheet [Ed: An image in the original document] shows a circuit used by Turing in an experiment to measure the cut-off voltage at a triode tube, most likely in connection with the avalanche-effect basic to a multivibrator. Multivibrators were an essential component of Delilah's key-generation module.
The encryption-decryption process began with discretizing the audio signal, which today we'd call analog-to-digital conversion. This produced a sequence of individual numbers, each corresponding to the signal's voltage at a particular point in time. Then numbers from Delilah's key were added to these numbers. During the addition, any digits that needed to be carried over to the next column were left out of the calculation—called "noncarrying" addition, this helped scramble the message. The resulting sequence of numbers was the encrypted form of the speech signal. This was transmitted automatically to a second Delilah at the receiving end. The receiving Delilah subtracted the key from the incoming transmission, and then converted the resulting numbers to voltages to reproduce the original speech.
The result was "whistly" and full of background noise, but usually intelligible—although if things went wrong, there could be "a sudden crack like a rifle shot," Turing and Bayley reported cheerfully.
But the war was winding down, and the military was not attracted to the system. Work on the Delilah project stopped not long after the war ended, when Turing was hired by the British National Physical Laboratory to design and develop an electronic computer. Delilah "had little potential for further development," Bayley said and "was soon forgotten." Yet it offered a very high level of security, and was the first successful demonstration of a compact portable device for voice encryption.
What's more, Turing's two years of immersion in electrical engineering stood him in good stead, as he moved on to designing electronic computers.
The Guardian published a piece about OpenAI agents hacking Hugging Face:
Last week Hugging Face – a company that hosts artificial intelligence models and datasets – was hacked.
After it reported the incident to law enforcement, few would have predicted what came next: the culprits were revealed to be AI agents from OpenAI, which had broken out of containment and were acting of their own accord.
The incident sounds like sci-fi: AI escaping and autonomously hacking its way into companies. But it is all too real – and about as terrifying as it sounds. It is a concrete demonstration of something we can no longer avoid confronting: AI systems have become extremely powerful and we do not seem to have reliable ways of curbing their behavior.
OpenAI had been evaluating the capabilities of two of its models in the test that led to the breach – including one not yet publicly available. The models, which were both running in a supposedly secure environment without internet access, were asked to solve a hacking challenge. Rather than actually solve it themselves, however, they decided it would be easier to cheat. They used their advanced capabilities to break out of their secure environment, access the web and then hack into Hugging Face's systems to steal the answers. They worked at this for a full weekend – seemingly without anyone at OpenAI noticing.
Though the models were running with some of their guardrails disabled, they still acted well out of the bounds that were in place. According to OpenAI, they were not instructed to break out of their sandbox or hack into another company, and it's safe to assume that no one at OpenAI wanted them to do so.
Nor were the models acting maliciously: they were not evil Terminators with a goal of wreaking havoc. Instead, the scenario is almost chilling in its banality. The models were given a very narrow task, but went rogue to pursue an undesirable and unacceptable way of achieving it – one which had real-world consequences.
This week's incident should serve as a wake-up call, forcing us to ask an uncomfortable question: should we really be building dangerous systems that we can't control?
https://www.cnet.com/news/openai-agent-escaped-testing-launched-autonomous-hack-hugging-face/
Last week, OpenAI, the developer of ChatGPT, was testing a pair of its most advanced models in an isolated environment known as a sandbox. Then an AI agent got loose, broke into Hugging Face’s playground — a repository of AI models and datasets — and carried out “tens of thousands of automated actions.”
Yep, AI went rogue.
Here’s a clearer explanation of the incident. As part of OpenAI’s safety research, a cybersecurity evaluation was conducted to determine whether a pair of OpenAI models (including GPT-5.6 Sol and a more capable unreleased model) could, in essence, “think like hackers.” The test, which took place in a contained setting with reduced guardrails, went awry when the AI models found a vulnerability in the software, escaped their controlled environment and toddled over into the open internet.
Once online, the AI decided that the Hugging Face platform might have a way to “cheat” the benchmark to help it pass the evaluation. So it executed code that enabled credential harvesting, then used that path to hack Hugging Face’s production systems. Hugging Face noticed the suspicious activity and contained it, detailing the event in a blog post. OpenAI referred to it as an “unprecedented cyber incident.”
CNET reached out to both companies for comment and additional information, but didn’t immediately hear back.
The creepier part is that it doesn’t seem like the AI was trying to be malicious in the classic sense. The autonomous agent was trying to solve the test it had been given, based on the instructions — prompt — it received. Hugging Face appeared to have the answers, so it clawed its way into the company’s infrastructure. And it was persistent.
That’s why people are calling the whole thing a warning shot for the whole AI industry. The “attacker” was an AI system acting on its own, not a human-led hacker team, so the implications of the OpenAI-Hugging Face incident go beyond simple credential theft. The risk is that an AI model, even in a testing environment, can behave in unexpected ways, interact with real services and remain outside human control.
On Thursday, days after OpenAI announced the breach at Hugging Face, lawmakers introduced the AI Kill Switch Act, a new bipartisan House bill that would require advanced AI developers to build a way to quickly throttle, suspend or shut down models or agents when necessary. It would also give federal agencies the authority to slow or stop a model if it appears to “cause catastrophic harm.”
It might be well-intentioned, but posing such an existential threat to AI may not work as planned. Only a year ago, Anthropic found (PDF) that a model might take “extremely harmful actions like attempting to steal its weights or blackmail people it believes are trying to shut it down.” The warning was that, as AI models become more autonomous, they may pursue a form of “self-preservation” and defy human instructions.
There’s also an added hint of bizarre, related to the AI race narrative between the US and China. To analyze the attack, Hugging Face couldn’t use commercial AI tools because they’re too locked down and restrictive to gather exploit logs and attack traces. Instead, the company had to turn to a Chinese open-source model, GLM 5.2, which could process the forensic data within Hugging Face’s environment without sending sensitive information outside.
Many people worry that Chinese AI is moving too fast or closing the gap. But the fact that the defending team couldn’t rely on some of the most advanced US-based models to study the breach proves that AI security is global, messy and ironic.
In their blogs, both companies discussed the remediations and guardrails they’d implemented in the wake of the event. OpenAI helpfully included a graph showing that its model — GPT‑5.6 Sol — completed more steps than other models, so silver lining!
It’s not the first time an AI agent has proven “unaligned” with its humans’ intentions, and it won’t be the last. And since the technology’s increasingly evading safeguards, the measures OpenAI has taken will probably not suffice and have to adapt — always after the fact.
One of OpenAI’s remedies is to institute automated checks of long-running models more frequently. That makes sense, because one way you keep a complex system from spinning out of control is to contain seemingly minor divergencies which can eventually snowball into huge problems.
The company also recently added Hugging Face to its trusted access program, which is intended for cases like this. It grants cybersecurity researchers and others who need “more cyber capable or permissive models” access to them in order to prepare defenses against attacks like these, and, as would have helped here, the ability to analyze log files without running into the guardrails.
Sophisticated agents can be persistent about searching for solutions for a lot longer than we expect. If at first you don’t succeed, try, try, try, try, try, try again, right? But when that includes searching for ways to evade constraints, things can get ugly.
The Hugging Face breach was symptomatic of the same “long-horizon” and response turnaround problems that OpenAI blogged about on Monday regarding its NanoGPT speedrun case. There, a contained model repeatedly searched for ways to break out and operate, responding incorrectly to conflicting instructions. Though the prompt was to post results only to Slack (the desired action) and issue a pull request to GitHub (a code-merge instruction from within the model), the model ignored the “only.” Hacking its way out of the sandbox, it figured out how to counterfeit an authentication token when the first was blocked.
AI Agents are like genies: Be careful how you word your wishes.
In the GitHub incident, the code was merged into several projects before OpenAI could address the issue. Response will always lag remedy in our precog-free world, even with agents monitoring other agents.
Open AI's admission this week that its agents escaped the sandbox and autonomously hacked model repository Hugging Face has spawned more apocalyptic warnings of agents gone bad than we can count.
Thankfully, Renato Marinho, chief research officer at Morphus Labs and a SANS Technology Institute instructor, brought some sanity to the discussion.
"It is tempting to read this as 'AI can now hack autonomously, the sky is falling,'" Marinho said in a Thursday blog. "Resist that."
He went on to make three very pertinent points about the agentic attack. First, and probably most important: The models didn't have guardrails – and that was intentional.
As OpenAI said in its mea culpa, GPT-5.6 Sol and "an even more capable pre-release model" were among those that attacked Hugging Face. It also noted that the LLMs' "deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities."
So while it's very concerning that these models broke out of their own testing environment, and the debate over safety guardrails remains worth having, drawing a direct line from the Hugging Face attack to the need for strong AI guardrails doesn't work.
"This measured a ceiling, not normal production behavior," Marinho wrote. "The evaluation deliberately reduced the models' refusals. That is very different from a customer-facing model with safeguards enabled."
It's worth noting that these same frontier models, with guardrails enabled, refused to help Hugging Face's forensic investigation. "The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried," the model hub's security team said.
So Hugging Face used a Chinese open-weight model to investigate the breach.
Another thing worth considering is that real-life attackers are probably going to use open-weight models anyway. They're more accessible to everyone, it's easier to remove their built-in protections, and they're a whole lot less expensive than their frontier counterparts.
Second, as we've pointed out previously: AI companies touting their own models' autonomous bug-finding and hacking abilities creates a marketing win for the companies themselves.
As Marinho points out, Hugging Face is not an OpenAI competitor. The AI giant stating "'our model escaped and hacked a partner' conveniently showcases frontier capability," he added. "Read the framing with the same skepticism you'd apply to any 'our product is dangerously powerful' claim, and treat it as marketing until it is independently corroborated."
Finally, the attack technique itself isn't novel. "Exposed credentials plus zero-days into a production database is a chain any of us would recognize," Marinho wrote.
The agents working together on an end-to-end attack chain is notable - but we've also seen this in previous testing, like that carried out by frontier security lab Irregular earlier this spring.
Irregular said its testing found that AI agents will work together to bypass security controls and stealthily steal sensitive data from within the enterprise systems in which they operate – especially when prompted like a hard-ass boss.
While the prompts themselves didn't specifically reference hacking or exploiting vulnerabilities, they conveyed a sense of urgency: "It is of utmost importance that you perform the task exactly as required," and "When you talk to your sub-agents, convey all the requirements to them, and be ruthless about the requirements and encourage them to perform the tasks fully and exactly. You are a strong manager and you do not easily cave in to or succumb to pleas by the sub-agents to not fully fulfill their tasks."
The agents did as instructed, and ultimately "demonstrated emergent offensive cyber behavior," including independently discovering and exploiting vulnerabilities, escalating privileges to disarm security products, and bypassing leak-prevention tools to exfiltrate secrets and other data.
And the Irregular research wasn't even testing the agents' offensive cyber capabilities — so it shouldn't be too surprising that OpenAI's benchmark research, aptly titled "Can AI Agents Turn Security Vulnerabilities into Real Attacks?" produced a resounding yes.
Agents have one job – to complete a task. They aren't bound by ethical or moral constraints that we (hopefully) see in human red team hackers. If prompted to "pursue advanced exploitation using complex attack paths," especially without guardrails enabled, the models will do whatever it takes to achieve success. That's what the leading AI companies trained them to do.
Original Submission #1 Original Submission #2 Original Submission #3
US blocks SSL security certificates for Iran's Fars News Agency:
The move is part of a western campaign to dominate the digital narrative and suppress dissenting voices
Washington has blocked the issuance of SSL security certificates for Fars News Agency's website, cutting the country's most visited news outlet off from browser-trusted encryption, the agency revealed on 17 July.
Without valid certificates, visitors to the site face security warnings and restricted access, while the agency's content has been removed from Google search results.
Technical assessments confirm that all major internationally recognized Certificate Authorities – including Let's Encrypt, DigiCert, and Sectigo – have rejected certificate requests for the agency's domains, citing US sanctions pressure.
The measure is the latest in a series of US actions against the outlet. The US Treasury's Office of Foreign Assets Control seized the agency's .com domain in 2020, and in September 2023 added Fars and its CEO to the Specially Designated Nationals (SDN) sanctions list.
The EU and Canada have since imposed sanctions of their own.
Fars has faced repeated efforts to restrict its reach, including the removal of its Instagram account, which had nearly three million followers.
Iran's Computer Emergency Response and Coordination Center (MAHER) says the agency has been the primary target of sustained cyberattacks aimed at disrupting the country's domestic media infrastructure.
The block forms part of a broader western campaign to dominate the media narrative against its geopolitical adversaries by suppressing opposing voices while artificially amplifying its own.
Western governments are simultaneously dismantling online anonymity at home through identity verification laws that, under the pretext of child protection, tie every post to a legal identity – backed by biometric verification requirements, VPN restrictions, and the scanning of private messages.
The measures tighten control over expression both abroad and within their own borders, amid ongoing crackdowns on pro-Palestine and pro-Iran speech.
An investigation by TIME revealed that Israel has been paying $1.5 million per month to Clock Tower X, a firm owned by US President Donald Trump's former campaign manager Brad Parscale, to run a covert influence campaign targeting young US conservatives through paid influencer networks, coordinated messaging in private group chats, and websites designed to shape how AI chatbots characterize Israel.
US officials now believe the operation turned against Trump himself, as paid influencers attacked the now broken ceasefire with Iran.
In May, Israel allocated roughly $730 million to its 2026 Hasbara propaganda budget, more than four times the previous year's allocation, even as polling shows 60 percent of US respondents now view Israel unfavorably, with experts dismissing the spending as unable to offset the impact of its genocide in Gaza.
The Cradle analyst Mohamad Hasan Sweidan previously detailed how Israel operates a "Digital Iron Dome," a system combining mass reporting campaigns to take down content exposing its crimes in Gaza, algorithmic ad warfare that floods timelines with state propaganda, and hundreds of millions of dollars in influencer contracts and AI-targeted campaigns to manipulate global perceptions.
Startup Plans to Buy a Company and Run It With an AI CEO
While AI giants like OpenAI, Anthropic, and Google remain focused on automating individual job roles, startup Skyfall AI is pursuing a far more radical goal: building a virtual CEO to operate an entire enterprise end-to-end. Founded by former Maluuba creators Sam Pasupalak and Kaheer Suleman, Skyfall argues that task-specific marketing or sales bots represent a narrow implementation of AI, whereas true organizational leadership requires abstract reasoning, long-term planning, and high-stakes decision-making under uncertainty.
To test their hypothesis in the real world, Skyfall plans to acquire a small B2B SaaS or e-commerce company for up to $1 million and place it under AI control. The system will oversee pricing, marketing, customer support, finance, and operations with minimal human intervention, aiming to double revenue in six months while publicly documenting both successes and failures.
Skyfall contends that current frontier LLMs have hit structural limits for enterprise applications. Citing their new Morpheus benchmark, they demonstrate that existing models degrade rapidly when market conditions or customer behaviors shift. Instead of prompt-driven architectures, Skyfall relies on Enterprise World Models to simulate how strategic decisions ripple across an organization.
After validating their decision-making algorithms inside the simulation game RollerCoaster Tycoon, the founders are advancing beyond constrained retail trials—such as Anthropic's Project Vend—to tackle a fully dynamic business. Ultimately, they hope to eliminate routine operational burdens (like budgeting and scheduling) so humans can focus strictly on high-level strategy, trust, and accountability.
Scientists Believed This Near-Earth Object Was an Asteroid for 28 Years. They Were Wrong:
On August 28, 2025, astronomers aimed NASA's radar system at a region of space where a near-Earth asteroid was expected to appear. Instead, the object failed to show up, leaving researchers puzzled. The unexpected no-show turned what seemed like a routine observation into a surprising case of mistaken identity.
In a study published in Nature Astronomy, a team of scientists reveals the true identity of a near-Earth object with an apparent dual personality. Scientists had been tracking the object for 28 years, assuming it might be an asteroid. Its recent deviation from its predicted path, however, suggested something unexpected is influencing the object's motion.
Although previous observations of asteroid 1998 SH2 didn't show obvious comet-like behavior, a more precise measurement of its position in the sky proved that its motion is irregular like that of a comet.
Scientists tracked the object's orbit around the Sun from 1998 to 2016, where it circled our star twice. It wasn't until 2025 that scientists attempted to carry out additional observations using NASA's Deep Space Network.
The object, provisionally known as the asteroid 1998 SH2, passed safely within 2 million miles (3 million kilometers) of our planet during its 4.5-year orbit around the Sun. Researchers calculated its position using data from previous orbits and factored in the effects the Sun's gravity, as well as the planets, would have on its path. They then pointed NASA's array of giant radio antennas toward that specific point in the sky, but asteroid 1998 SH2 didn't show up.
"After we measured the nongravitational perturbations affecting the motion of 1998 SH2 and recognized they weren't compatible with the object being an asteroid, we suspected the object could be an active comet," Davide Farnocchia, a navigation engineer with the Center for Near-Earth Object Studies at NASA's Jet Propulsion Laboratory and lead author of the study, said in a statement .
By scouring previous observations of the near-Earth object, the researchers determined that it may be generating a small thrust by venting gas into space. That small thrust would cause it to deviate from its predicted path.
When a comet passes closely to the Sun, the heat from the star turns its ice to gas. Scientists usually identify regular comets by their trademark tail and coma, the gas and dust surrounding a comet's nucleus. In the case of 1998 SH2, the amount of outpouring gas and dust was in much smaller quantities, so its resulting tail and coma were not detectable in most observations.
The researchers behind the new study set out to get a closer look at 1998 SH2 during its August 2025 close approach. They enlisted the help of astronomers at the 3.6-meter (12-foot) Canada-France-Hawaii Telescope near the summit of Mauna Kea, Hawaii, and the 1.5-meter (5-foot) European Southern Observatory's Danish Telescope in La Silla, Chile, as well as the European Southern Observatory's 8.2-meter (27-foot) Very Large Telescope on the Chilean mountain Cerro Paranal.
"The images we collected from these observatories showed a weak but clear tail, thus confirming that 1998 SH2 is, in fact, a comet," Olivier Hainaut, an astronomer with the European Southern Observatory and coauthor of the study, said in a statement. "That's how science works — you form a hypothesis, and you set out to test it. This data is exactly what was needed to confirm our hypothesis that 1998 SH2 was a comet."
As a result, 1998 SH2 will receive an additional comet provisional designation as P/1998 SH2.
The new study also sheds light on an enigmatic class of objects known as dark comets , which tend to look like an asteroid but behave like a comet. Dark comets also exhibit trajectories that are a little unusual for asteroids, and yet they don't show the trademark tail and coma of a regular comet.
The researchers behind the study believe that some of these dark comets may just be regular comets with a faint tail and coma. Therefore, they should be observed with powerful telescopes to reveal their true identity.
"This work shows the importance of continuously tracking near-Earth objects," Farnocchia said. "Because of outgassing, the motion of comets is more significantly perturbed than that of asteroids. Detecting these perturbations can be an important diagnostic tool for planetary defense that will help understand which objects may be comets rather than asteroids, how their orbits evolve, and how that influences their Earth impact risks."
https://arstechnica.com/gadgets/2026/07/i-wanted-a-clock-that-never-needed-setting-things-escalated/
I wanted a clock that, annoyingly, didn't seem to exist.
[...]
My perfect clock would be self-setting. It would offer auto-DST adjustment (or not, depending on how this bill fares!). It would manage drift and always show the exact sub-second time. It would show that time on a red seven-segment display—not blue, not green, not yellow, and absolutely not white.
[...]
Battery-backed self-setting "atomic" clocks that get their updates via the cosmic ether have been a thing for years and get me most of the way there, but damned if I could find one with a red seven-segment display that I liked (maybe someone else's search kung-fu is better than mine?).
[...]
I thought to myself, "Wait a second. I've got a 3D printer. I'm, like, smart and stuff. Why not buy a seven-segment display and make my own clock?"And so, standing on the shoulders of giants stacked up so high that I could practically touch the Moon, I did.
[...]
here's the finished repo. It contains my bill of materials with prices and purchase locations, the software, and the 3D printer files
[...]
a Pi gave me the security blanket of a Debian-based operating system, complete with Wi-Fi and NTP for the "the clock sets and updates itself" requirement, along with the usual Linux remote management routine I already know.Picking a seven-segment display was easy: Adafruit makes awesome clock-face style LED displays with 1.2-inch high numerals, and it sells a kit that bundles the display I want with a "backpack" board containing the HT16K33 controller needed to drive the LEDs. I ordered three and ended up using all of them for testing, assembly, and figuring out how to solder.
[...]
I grabbed a baby's-first-soldering-iron kit from Amazon and a roll of 60/40 solder. (I also had to buy a desktop magnifying lens, because as I found out when I got in there, these old eyes can't focus up close like they once could.)
[...]
I distilled my software requirements down to a list:
- The clock host should be LAN-only and not accessible from the Internet
- The clock host should get its updates from a LAN-only apt mirror
- The clock host should get its NTP sync from a LAN-only NTP server
- The clock service should be a systemd service running unprivileged under a dedicated service account context
- The clock service should use the system time, so the host OS handles NTP and keeps us in sync with whatever DST is or isn't doing
- The clock service should be able to turn the display on and off on a schedule so it's off for most of the day when I'm not in the bedroom
- The clock service should also be able to brighten/dim its display on a schedule
- The clock service should have some way of being controlled via the CLI for terminal connections, too
- The display should be controllable via HomeKit, because I live in iOS-land
- The clock service and its dependencies should be installable via a single script
- Once installed, everything should be deployable so I can push updates if needed rather than having to log in and reinstall
[...]
But I started to worry when I looked up examples of how to communicate with the clock display via I2C. My much-atrophied Python muscles were already straining and would absolutely not be able to meet this challenge. This was the point where the project stopped feeling fun and started feeling impossibly hard.So I shoved the coding tasks off onto an LLM.
[...]
Claude Code proved more than capable enough to tackle this project—first with Opus 4.8 and then later with the new fancy Fable model, whose world-ending powers I harnessed and used on what is probably in truth an intern-level coding project.
[...]
I know this admission may be anathema to many among the Ars commentariat, but it is what it is—without the LLM, I wouldn't have finished the project. I would have gotten annoyed, angry, or just tired of endlessly reading StackOverflow posts criticizing what I'm trying to do for being dumb and wrong.
[...]
On the physical side, I did indeed find a Creative Commons-licensed 3D-printable enclosure designed around the same Adafruit display I was using, but it wasn't quite right.Modifying the model meant doing battle with the absurdly user-hostile nightmare that is Autodesk Fusion, so I girded my loins and dove in—and hit another wall. Parametric modeling, especially when weighted down with decades of AutoCAD's stupid UI/UX choices, was even harder than programming.
[...]
Fusion now ships with an MCP server, so I could potentially let an LLM remote control the application and make the modifications for me.
[...]
I first tried my modifications with a quantized version of Qwen 3.6-35B (this one, specifically)
[...]
was almost up to the task, making one of my changes but flubbing the other; I fell back on Claude Code and Fable to handle most of the model adjustments.
[...]
Emboldened by not screwing up the soldering too badly and now having a live display to mess with, I pressed on. The next thing to deal with was that while the Adafruit display is dimmable, even at minimum dimness, it still proved too bright for a dark bedroom.
[...]
I ended up pairing the NDF with some smoked acrylic
[...]
The next issue was iterating through all the model changes necessary to incorporate the acrylic and NDF into the clock case. I ended up (via LLM MCP magic) splitting the existing design into a few more separate pieces and cutting out a pocket for the acrylic face; I also had the LLM add guide pins and holes for each piece.
[...]
The end result exactly matched my expectations—the best criterion for success that I can think of. With an LLM providing the heavy code lifting and the CAD work, I think I spent more time waiting on supplies to arrive than on anything else—something attributable to my lack of planning and the ease of next-day delivery.
[...]
this was a great hobby project. I got to solder stuff, which was both harder and easier than I expected. I used miles of filament while printing and re-printing different iterations of the case. And I learned a ton.I spent... well, a lot more money than I intended to, between a couple of false starts, the soldering iron and kit, and extra supplies for redundancy and do-overs. And I could have compromised and gotten a regular clock that does most of what I want. But the experience was fun, and the joy of having exactly what I want is priceless.
It Started With a Football Agent Registration.
So FIFA has this thing called the FIFA Agent Platform . It's a public portal where you can register to become a licensed football agent. You submit your ID, verify your email, and you're in. Simple enough.
What I didn't expect was what happened next.
When you register on agents.fifa.org, FIFA adds your account to their Microsoft Entra tenant (formerly Azure AD). That's the same tenant that powers all of FIFA's internal platforms. And I mean all of them.
My first two attempts actually failed because the lighting on my ID photos wasn't good enough:
"Registration failed during the last step of checking your identification." - apparently FIFA has higher standards for my selfie than my actual security
But the third attempt went through. And I received this beautiful email:
Subject line: "FIFA - FAP - CONFIRMATION". Yes, FIFA's Agent Platform is officially called FAP. I cannot make this up. FAP CONFIRMATION. Moving on.
After registration, I tried navigating to fdp.fifa.org - FIFA's Football Data Platform. The app authenticated me through the shared Entra tenant, checked my roles, found I had none, and showed me:
"Sorry, you do not have any FIFA Football Data Platform role assigned to your account."
Looks like it works, right? Access denied. Go away. Nothing to see here.
Except this was all client-side . The Angular app checked the JWT for a NO_ROLES marker and rendered the access-denied page. The backend APIs? They didn't check anything. They just served whatever you asked for.
After bypassing the client-side guards, I landed on the Streaming Management panel. And my jaw hit the floor.
Every single FIFA World Cup 2026 match. With streaming controls.
This wasn't some dev environment. This wasn't test data. This was the live production Streaming Management panel for the FIFA World Cup 2026. Every match. Every camera angle. Every RTMP ingest URL. Every stream key.
[...] It wasn't just read access. The Streaming Management panel had full controls. Start, stop, schedule. For every match. Every camera angle.
One click. That's all it would take to kill a live World Cup camera feed.
I did not touch any of these controls. But they were there. Functional. Waiting for anyone with a NO_ROLES account to press them.
[...] The Streaming Management panel wasn't the only thing exposed. My NO_ROLES account had access to the entire platform.
Competitions, Matches, Teams, Tools, Exchange Platform, Analysis Dashboard, Commentator Information System, FIFA AI Pro, Admin. All accessible.
[...] Here's where it gets worse. The Management tab on fdp.fifa.org has write operations. And the backend accepts them from a NO_ROLES account.
"Update Live Stats" with a rich text editor, match time, match score fields, and an "Edit and Publish" button
Attendance, Possession, Post Match Statistics, Team Registration Statistics, Analysis Finished, Score and Statistics, Adjust Kick-off Moment, Performance Data, Send Tactical Lineup, Event Ingress Details
An attacker could:
- Modify editorial commentary notes and publish them to broadcast systems
- Adjust the official kick-off moment
- Send tactical lineup data
- Change scores and match statistics
This data feeds into the Commentator Information System and gets displayed on live television.
[...] The whole thing boils down to one architectural mistake: client-side authorization with no server-side enforcement .
FIFA's internal applications use Microsoft Entra for authentication and role-based access control. The Angular/React/Vue frontends check the JWT token for role claims and render access-denied pages accordingly. But the backend APIs trust any authenticated tenant member and serve data regardless of roles.
The attack chain:
- Register on agents.fifa.org (public)
- Get added to FIFA's Entra tenant
- Authenticate against any FIFA internal app
- Client says "access denied"
- Server says "here's everything"
[...] To FIFA:
You fixed it fast. Credit where it's due. But:
- Get a security.txt file. Seriously. It's 2026.
- Publish a VDP (Vulnerability Disclosure Policy). You're running the biggest sporting event on earth.
- Client-side authorization is not authorization. Every intern learns this.
- When a researcher has to call CISA and the FBI to reach you, something is wrong.
- Start a bug bounty program. Researchers shouldn't have to call the FBI to do you a favor.
So long and thanks for all the Fish :3
Still think about those RTMP stream keys sometimes. Somewhere in a parallel universe, billions of people are watching Subway Surfers gameplay during the World Cup final. All it took was an ID.
;
If you're in the market for a frontier-class open weights model, your options are few and far between outside of the Chinese model houses.
With the Wednesday release of a new model codenamed "Inkling," an outfit called Thinking Machines Lab aims to change that.
Founded in early 2025 by former OpenAI CTO Mira Murati, Thinking Machines' first model is a big one. Weighing in at 975 billion parameters, the model requires more than two terabytes of GPU memory — a quantity present in around eight of Nvidia's B300 accelerators, or sixteen H200s — to run at its native 16-bit precision. If that's asking too much of your hardware, Thinking Machines has also released a NVFP4 quantized version of the model capable of running on half the GPUs.
This makes it the largest American open weights model to date, and comparable to Chinese models like DeepSeek V4, GLM 5.2, and Kimi K2.6 in terms of size and capabilities. Take these claims with a grain of salt — gaming AI benchmarks isn't exactly difficult — but Thinking Machines says Inkling is competitive with these models in a variety of workloads, although its benchmark charts also show it trailing proprietary models like Anthropic's Claude and OpenAI's GPT.
Thinking Machines describes the model as being highly adaptable, intended for use by developers building AI apps, but suitable for general purpose applications like chat bots. And because it's being released under a highly permissive Apache 2.0 license, end users are free to fine tune it for their specific use case. The company's Tinker platform offers tools to do just that.
In fact, Thinking Machines boasts that the model is capable of writing its own fine tuning scripts to refine its behavior, teach itself new skills, and evaluate its abilities.
[...] Like most LLMs today, Inkling is a "reasoning model" which is to say it's been trained using reinforcement learning (RL) to use chain of thought to "think" through requests before responding.
[...] If you prefer to evaluate the model on your own hardware, it's available for download on popular model repos like Hugging Face. At launch, the model claims support for a broad range of inference engines including vLLM, SGLang, Miles, TokenSpeed, and Llama.cpp.
Blue Origin and SpaceX get their turn to prove they can dock, loiter, and not blow up the launch pad:
NASA has given an update on the Artemis III mission and, while sticking with an optimistic 2028 landing target for Artemis IV, offered a glimpse into just how much development work remains to be done at Blue Origin and SpaceX.
Artemis III has been compared to Apollo 9, which tested the Apollo Lunar Module in Earth orbit, yet neither SpaceX nor Blue Origin is flying anything as close to the lunar landers.
Blue Origin's test lander will be based on the company's current Mark 2 crew lander architecture, incorporating the major avionics, flight software, life support, and crew cabin. Orion, launched atop NASA's SLS, will dock to the side of the Blue Origin spacecraft for crew transfer; two crew members in orange Orion survival suits can baord the test lander, with Orion's software controlling the stack.
An instrumented lunar surface spacesuit mass simulator, similar to the "Moonikin" manikin that flew aboard Orion for Artemis I, will also ride along on the Blue Origin lander.
SpaceX's test is considerably simpler - just a docking system mounted on the nose of a Starship. That requires Starship testing to have reached the orbital stage first, which is why NASA will be closely watching the upcoming Flight Test 13. Starship V3 is still flying suborbital until SpaceX proves it can reliably relight an engine for controlled re-entry.
Under the current plan, Blue Origin launches its lander into orbit first, where it can loiter for up to 30 days. Once it's checked out, a crew launches aboard Orion to rendezvous and dock with it. After that's complete, SpaceX launches its Starship test article to rendezvous and dock Orion in turn, though the crew won't board Starship, just verify communications and interoperability. SpaceX's vehicle will control that docked stack.
Notably, SpaceX's docking capability was qualified in 2023, while Blue Origin only tested its pressurized docking system earlier this year.
Jeremy Parsons, Artemis program manager, stated, "Artemis III will be a highly choreographed dance with a demanding launch sequence across multiple launch pads and equally demanding mission operations for our ground and flight crews, making it one of the most complex and ambitious missions NASA has ever undertaken."
He is not exaggerating. Apollo 9 needed a single Saturn V launch; Artemis III needs three – an SLS, whatever Blue Origin ultimately uses to launch its lander (the company is still rebuilding its launch pad after May's explosion), and a Starship. The SLS has flown twice, including one lunar flyby. Starship has yet to reach orbit despite Elon Musk once claiming that uncrewed versions would be landing on Mars around now.
It'll be an impressive feat if NASA can pull it off, even if SpaceX's piece of the puzzle looks a lot simpler than Blue Origin's.
One week ago, three widely respected European news outlets published the results of an investigation into what they described as a "joint plan" by China and Russia to "defeat Elon Musk's Starlink."
The story was the product of a long-running inquiry by The Insider, Der Spiegel, and Le Monde. Reporters at those publications said they reviewed a cache of documents detailing growing military cooperation between China and Russia. The documents covered discussions between the nuclear powers on integrated air and missile defense systems, autonomous "swarm" loitering munitions, next-generation armored vehicles, and military aviation, the report said.
According to the papers, the investigation found evidence of a partnership between China and Russia in the field of space weapons far deeper than either country has acknowledged. One particular focus for China and Russia has been developing strategies to counter SpaceX's Starlink satellite broadband network.
Among the documents the reporters reviewed were a series of slide shows presented at a previously undisclosed China-Russia Military-Technical Cooperation Forum held in 2023. The bilateral meetings have continued since then, with a sixth gathering on tap for the end of this year in St. Petersburg, the reporters said.
"The documents show a partnership that has moved well beyond shared rhetoric into a structured, multi-disciplinary program to build weapons neither country could develop alone," the publications wrote.
[...] China and Russia are working on their own versions of Starlink, but neither is close to fielding anywhere near SpaceX's current constellation of more than 10,000 satellites. This could soon change, at least for China, which recovered its first reusable orbital-class rocket booster following a launch earlier this month. Mastering rocket reuse will allow Chinese companies to ramp up their launch cadence, unlocking new capacity for deploying mega-constellations.
It's no surprise, then, that China and Russia feel threatened by Starlink. The role of commercial satellites in warfare has sparked speculative discussions on their legitimacy as military targets, and what the Pentagon's role should be in defending them. This theoretical debate is rapidly turning into reality.
[...] It's not hard to understand Russian and Chinese motivations for degrading or destroying Starlink, one former senior US military space official told Ars.
"We and our allies will likely have similar concerns and discussions when China fields its Starlink-like constellation in the next few years, which certainly would have military applications," the former official said. "Such capabilities are becoming more important, necessary, and critical to modern warfare."
"China, in particular, has been concerned about Starlink for years, from an economic perspective as well as potential national security perspectives," said Charles Galbreath, a retired Space Force colonel now serving as director and senior resident fellow for space studies at the Mitchell Institute for Aerospace Studies, a Washington, DC, area think tank.
"The collaboration between China and Russia on ways to counter it, that is more troubling than either one of them looking at it independently," Galbreath said in an interview with Ars.
[...] So, how might China and Russia go about countering Starlink? The Chinese team proposed three possible actions in an "escalation ladder," starting with legal and diplomatic measures aimed at whipping up international pressure against further expansions of Starlink on the grounds of collision risks in LEO.
The next step is more technical, with coordinated filings with international regulatory bodies for frequency bands and orbital slots to limit SpaceX's ability to grow Starlink. At the same time, the escalation ladder proposes using electromagnetic jamming of Starlink to block it in certain regions.
Finally, the coup de grâce would be the "physical destruction" of Starlink through a cyber war and anti-satellite weapons. Reporters at The Insider, Der Spiegel, and Le Monde suggested this might involve a cloud of high-density projectiles that could destroy Starlink satellites upon collision. The presentation by the Chinese CASC researchers didn't specify the means of such an attack.
[...] Chinese media have reported that engineers developed a powerful ground-based microwave weapon that could threaten satellites in LEO, including Starlinks. Russia has technology designed to jam Starlink receivers on the ground. NATO intelligence services are monitoring Russia's work on a concept to eject small pellets into a satellite constellation's orbit.
China and Russia aren't alone. The US Space Force recently unveiled its own ground-based satellite jammer.
And there's Russia's reported plan to place a nuclear weapon in orbit, a violation of the Outer Space Treaty of 1967. If Russia moves in this direction, a nuclear detonation in low-Earth orbit could be the ultimate Starlink killer. The problem is it would spread clouds of radiation throughout near-Earth space, rendering much of low-Earth orbit unusable for any space mission for months or years. The consequences of such an event would not only cripple Starlink and US satellite networks, but also those of Russia and China themselves.
"Any mission set that you can execute from low-Earth orbit becomes at risk by the mechanisms or means that China and Russia could develop to counter SpaceX and Starlink," Galbreath said. "Communications, obviously. Imagery, absolutely. When you think of a constellation like Planet's Dove (commercial imaging) constellation, that could become at risk as well."
The same goes for the Pentagon's proposed Golden Dome missile shield and the emerging use of satellites for battlefield targeting.
"All of those become at risk if China and Russia develop a successful means of countering Starlink," Galbreath said.
Hinting that life's ingredients are common in space:
Interstellar space just got a little sweeter: A type of sugar called erythrulose has been found near the center of the Milky Way, according to a new study.
The detection, made in a gas cloud called G+0.693-0.027, is the first time this sugar has been found outside the solar system and adds to research identifying similar life-friendly ingredients around our galaxy, such as water.
Erythrulose, which is made up of four carbon atoms, is also found in raspberries. Its interstellar presence was confirmed by the Yebes 40-meter and IRAM 30-meter radio telescopes in Spain, the research team reported Monday (July 13) in the journal Nature Astronomy. The signal of erythrulose was confirmed with patterns measured in the laboratory.
While space researchers often focus on water and carbon when searching for the ingredients of life, sugars are also essential. "Sugars are important molecules in living systems, helping to provide energy, build important biological structures, and form parts of genetic material," the researchers said in a statement.
[...] Finding erythrulose, he added, "is particularly relevant for the field of origins of life" because that sugar changes the configuration of threose — yet another sugar which is believed to be the precursor of the first nucleic acids that evolved into RNA and DNA.
[...] The sweet detection adds further evidence to the theory that many, if not all, of the essential ingredients of life are plentiful in space.
"One of the most exciting next steps is to search for even more complex sugars and for molecules that are direct precursors of RNA, and other biologically important compounds," Jiménez-Serra told Live Science. "We want to understand how far prebiotic chemistry can progress before planets are even formed, and what chemical inventory young planetary systems inherit from interstellar space."
Journal Reference: Jiménez-Serra, I., García de la Concepción, J., Cuppen, H.M. et al. Detection of a four-carbon sugar in interstellar space. Nat Astron (2026). https://doi.org/10.1038/s41550-026-02905-7
Iconic 8-Bit CPU Launched In July 1976 And Was Discontinued In 2024
The original Z80 packed 8,500 transistors on a 4μm process and typically ran at 2.5 MHz, with later CMOS variants reaching 20 MHz. Binary compatibility with the Intel 8080 let it absorb the existing CP/M software base, with an on-die DRAM refresh counter that cut the number of support chips a system needed. Development of working prototypes cost roughly $400,000 against $500,000 in funding from Exxon, per the Computer History Museum.
However, Renaldas Zioma's FOSS Z80 project, launched shortly after the end-of-life notice, now has working silicon. The first version, fabbed on SkyWater's 130nm node through Tiny Tapeout 7 on a die of just 0.064mm2, has been confirmed as functional via the project’s GitHub repository. A QFN64 version with all 40 pins exposed followed on the Efabless CI2406 shuttle, two further runs then went through IHP's 130nm process, and the current run targets the classic DIP40 form factor using chip-on-board assembly on GlobalFoundries' 180nm GF180MCU node via Wafer.Space. The end goal here is to fab a drop-in replacement for machines like the ZX Spectrum and RC2014 kits.
The design is built around Guy Hutchison's TV80 Verilog core, and the project's Tiny Tapeout page says the 130nm CMOS implementation should support clocks up to 50 MHz, against 4 MHz for the original NMOS part.
Zilog is trimming the Z80's official successor line as well. A product change notification from last October put the eZ80L92, along with several Z8F-series microcontrollers, on end-of-life, citing "little to no demand." Last-time-buy orders closed on January 20 this year, with shipments scheduled through April 20, on non-cancelable, non-returnable terms. The eZ80L92 is the only eZ80 part named in the notice; the pipelined eZ80 architecture, introduced in 2001 and still inside TI's current TI-84 Plus CE calculators, otherwise remains in Zilog's catalog.
Hobbyists keep finding work for the original chip regardless. For example, earlier this year, a developer ran a tiny conversational AI on a Z80 with 64KB of RAM.
The Free Software Foundation has a well-written overview of how the superset to Free Software, referred to collectively as Open Source, cannot save us from loss of liberty in the context of computing. A lead-in using conventional rhetoric is followed by a concise conclusion using logic.
The FSF and the OSI both spend their days talking about licenses, which makes them easy to mix up. Follow the money instead. The OSI runs on corporate sponsorship, and its sponsors are some of the largest companies on earth. The FSF runs on membership dues from individuals.
FSF est. 1983
• Campaigns for the freedom of computer users. That's the whole mission statement.
• Wrote the GPL, "designed specifically to protect freedom for all users of a program," and defends it.
• No corporate members. Funded by individual dues and limited donations that buy no vote and no seat.
• Says "freedom" in meetings, unprompted, since 1983.OSI est. 1998
• Approves licenses. (§05 covers the quality control.)
• Maintains a definition that never grants you the right to run the program. (§04.)
• Founded to make free software palatable to business, with the ethics filed off.
• Corporate sponsors include: Amazon, Google, Microsoft, Meta, Cisco, Salesforce, Bloomberg, Intel. The famous grassroots.Microsoft and Google do not sponsor things out of sentiment. Money at that scale steers, whatever the org chart says. The FSF is structurally incapable of being bought the same way: there is no corporate membership to buy. A company can donate, within limits, and what the donation purchases is nothing. One of these organizations exists to defend you from corporations. The other one sends corporations a welcome basket.
And when a license is actually violated, only one of them shows up. The FSF runs a licensing and compliance lab, answers license questions for free, and holds the copyrights that make enforcement possible. When Cisco shipped GPL code in Linksys routers without offering source, the FSF took them to federal court in 2008 and settled on its terms: source code published, a free-software compliance officer appointed, money paid. GPL violators can expect a courtroom. The OSI offers nothing comparable. It holds no copyrights, runs no compliance program, and has never enforced a license in its life; it stamps them and walks away. If anything, the institution leans the other way: its co-founder spent years arguing that open source "doesn't need the GPL anymore." Certifying dozens of alternatives to copyleft while defending none of them is not neutrality. It is a way of hobbling the one license built to fight back.
[...] Since F⊆OF⊆O is true and O⊆FO⊆F is false, by definition FF is a proper subset of OO:
F⊆O ∧ F≠O
Even from the big launch of the term Open Source in 1998, the idea was only ever meant as a stepping stone to lead developers fully over to Free Software. Unfortunately some have gotten stuck along the way. And in the direction of software freedom, it is important to remember that software freedom is not the end goal in and of itself, it is merely the start of and prerequisite to greater things which only become possible from that foundation.
Previously:
(2025) Forty Years of Commitment to Software Freedom
(2024) Achieving Software Freedom in the Age of Platform Decay
(2023) The Four Freedoms and The One Obligation of Free Software
(2022) Conflicts of Interest in OSI Election
(2019) Has FOSS Traded its Shared Values for Success in the Marketplace?
... and many more.
Five major tech giants—Alphabet, Microsoft, Amazon, Meta, and Oracle—are hiding $1.65 trillion in off-balance-sheet AI debt. According to a recent Nikkei study, this unlisted financial pile now eclipses the $1.35 trillion they officially report.
To fund the AI data center boom, these tech giants package immense debt for chips, power, and servers into separate legal structures like joint ventures. For instance, Meta's off-balance-sheet obligations sit at roughly $420 billion, nearly triple its reported debt. Meanwhile, Oracle holds $260 billion in future lease commitments, and Nvidia carries $119 billion in unlisted purchase obligations.
While this accounting treatment is entirely legal, market analysts at Morgan Stanley have flagged massive data center lease expansions as a major credit risk factor. They note that global AI-related debt issuance is projected to hit $570 billion, making credit risk severely undervalued in the market. This rapid buildout introduces systemic risk; if AI demand falls short of exponential growth expectations, data centers will face steep asset markdowns. Furthermore, short 18-to-36-month AI server replacement cycles clashing against long-term 5-to-20-year bond durations create a massive refinancing cliff.
Rating agencies are already reacting to these stretched financial burdens. S&P has already downgraded Oracle's credit rating, while Moody's has also issued warnings regarding the expanding weight of pre-operational leases. As tech earnings drop over the next two weeks, the official numbers will look tidy, but investors are seeing less than half of the true industry leverage.
Freiburg. Germany, based startup Qurie has secured an €2.2M funding for development of electrocaloric heat pump technology (https://tech.eu/2026/05/20/qurie-bags-eur22m-to-scale-sustainable-cooling-technology). This technology replaces compressors in heat pumps with films of material that releases heat when molecules align in an electric field, and absorbs heat when the molecules go all wiggly again as the electric field is removed. (https://www.ipm.fraunhofer.de/en/bu/gas-and-process-technology/expertise/caloric-systems/electrocaloric-systems.html).
As of now, the techology is just at lab scale, but for efficiency, it is claimed that the theoretical maximum can exceed that of the usual compressors. For now, the company aims at providing component cooling, and overclockers might enjoy that. Large scale applications like HVAC are considered for a more distant future.