Stories
Slash Boxes
Comments

SoylentNews is people

Log In

Log In

Create Account  |  Retrieve Password


Site News

Join our Folding@Home team:
Main F@H site
Our team page


Funding Goal
For 6-month period:
2022-07-01 to 2022-12-31
(All amounts are estimated)
Base Goal:
$3500.00

Currently:
$438.92

12.5%

Covers transactions:
2022-07-02 10:17:28 ..
2022-10-05 12:33:58 UTC
(SPIDs: [1838..1866])
Last Update:
2022-10-05 14:04:11 UTC --fnord666

Support us: Subscribe Here
and buy SoylentNews Swag


We always have a place for talented people, visit the Get Involved section on the wiki to see how you can make SoylentNews better.

When was the last time you compiled an operating system kernel?

  • This morning---I live on the unstable nightly build!
  • Every time a major release comes out
  • Whenever my distro does it for me
  • Last century
  • That one time when I was in college and I was experimenting
  • Never
  • What's a kernel?
  • Other (describe in the comments)

[ Results | Polls ]
Comments:56 | Votes:180

posted by mrcoolbp on Saturday August 29, @02:07AM   Printer-friendly
from the they-change-the-rules-so-that-we-cannot-play dept.

https://www.theregister.com/software/2026/08/26/self-hosted-email-is-in-steep-decline-microsoft-and-google-are-taking-over/5292471

The number of large users hosting their own email servers has halved in the last decade, according to Artem Berezin, a researcher who works at business e-mail company Live Direct Marketing.

On the Internet Society blog, Berezin explained that DNS records reveal a lot about email.

"The MX record says where the mailbox lives. The SPF record says who may send on the domain's behalf. The DMARC record says what should happen when a message fails authentication," he wrote.

Berezin says he analyzes those records using daily forward-DNS snapshots captured by the OpenINTEL project run by the University of Twente, SURFnet and SIDN Labs. He also consults the Tranco project's assessment of the most popular domains to determine the million most popular domains, then "classifies each domain's MX hostname and SPF includes against open dictionaries of mailbox providers, sending platforms and SaaS applications." The data he uses goes back to 2016, but he admits the dictionaries he accesses don't offer a complete view of the world's email servers.

His lead finding is that in 2016, 44.6 percent of the top million domains ran their own mail server. In 2026, that's down to 22.4 percent. The number of self-hosted mail servers is falling fast – down by half a percent in 30 days.

Self-hosting an email server remains the most common way to process mail, however Google Workspace is hot on its heels with 21.8 percent of detectable MX records, ahead of Microsoft 365's 16.8 percent.

Berezin thinks the fact that two tech giants handle 38.6 percent of email is concerning.

"The RIPE [NCC] community has spent years discussing DNS and CDN centralization; email is following the same path, just more quietly," he wrote. "When more than a third of popular domains depend on two providers to receive mail, an outage, a filtering change, or a policy decision at either one propagates through the whole ecosystem at once. And unlike a CDN, email has no graceful fallback – a rejected message is simply gone.

"There is a second-order effect, too. The fewer independent operators there are, the more the remaining ones inherit the deliverability problems of a world tuned for the big two. Anyone who has tried to stand up a fresh Postfix box in 2026 and get its mail accepted at scale knows exactly what I mean."

Postfix is a FOSS mail server. Berezin's reference to the struggle to get mail accepted at scale reflects the fact that Google and Microsoft operate filters to detect messages they believe come from untrustworthy sources. If those two tech giants don't accept messages from Postfix or other sources, they make their own services more attractive - marketers who want their email blasts to land will move to the service providers most likely to let their messages through.

Another thing that worries Berezin is the use of DMARC (Domain-based Message Authentication, Reporting, and Conformance) records – the instruction in DNS settings that tells email servers how to handle emails that fail an authenticity check. His research found that over half of DMARC records have no valid policy or monitor email without enforcing policies.

That low rate is happening despite Google and Yahoo changing their bulk sender requirements in 2024 to require use of DMARC.

"At what concentration does inbound mail become a systemic dependency worth the community's explicit attention?" Berezin asks. "What would actually move DMARC from published to enforced, given that the 2024 mandates demonstrably did not do so? And how much of the Internet's mail infrastructure are we all failing to see because our dictionaries don't know its name?"

Berezin wrote that he can't answer those questions but hopes his daily download of email server data and ongoing analysis means he can one day.


Original Submission

posted by mrcoolbp on Friday August 28, @09:22PM   Printer-friendly

https://www.bbc.com/future/article/20260821-why-older-tech-is-sometimes-safer-from-hackers

The fear of hacking has made some people turn to other forms of technology ignored by new generations of cyber criminals.

You might not expect a world-renowned cyber security expert to rely on old, potentially vulnerable email software. But, for years, that's what Mikko Hyppönen did. Shunning mainstream options such as Hotmail and Gmail, he instead chose obsolete email software called Eudora.

"I used to run it years after it was out of [technical] support," says Hyppönen, a Finnish computer security expert.

He preferred Eudora for various reasons, arguing it was "really superior in many ways". Although Eudora was far from perfectly secure, as people switched to newer email tools, Hyppönen realised that hackers were forgetting about Eudora.

Hyppönen calls it "security by antiquity". Others use the phrase "security by obsolescence" and in both cases this means relying on an older technology or system since it may prove, somewhat counterintuitively, safer than more recent alternatives.

While Hyppönen stresses that using the latest, fully patched and updated software is still "the optimum situation", there are specific cases where older tech could be preferable from a security standpoint.

"The vast majority of attackers are criminals trying to make money and it doesn't make any sense for them to target systems being run by 50 people," he explains.

Hyppönen isn't alone. The Irish Aviation Authority, for instance, recently decided to keep ground-based radio navigation beacons in use because supposedly the more modern satellite-based global positioning system (GPS) has proven so susceptible to jamming in recent years.

"Security by antiquity" is, it turns out, a quiet way of beating cyber-criminals, hackers and enemy attackers.

Matt Bishop, a computer scientist and professor emeritus at the University of California, Davis, has tested this principle, somewhat by accident. Back in the 1990s, he and his colleagues set up a system connected to the internet and deliberately left it accessible so that they could catch hackers and bots attempting to breach it. This is a common cyber-security research technique known as a honeypot – a kind of trap set up in carefully controlled conditions.

But the team picked an older software version for their honeypot that had been upgraded multiple times since its release and, consequently, no hackers bothered to target it. "When we upgraded it to the new one, we had all the attacks we wanted," recalls Bishop. "I thought it was so amusing."

This possibility of evading nefarious activity by sticking to old tech can take many forms. Both Bishop and Hyppönen say they have friends who refuse to get a smartphone. "One person I know [uses] a Nokia 9210," says Hyppönen, referring to a simple, "dumb" mobile phone first released 25 years ago.
As technology has advanced, experts have often questioned whether the latest systems are actually more risky than older ones

While hackers can't target it in quite the same way they might target a modern Android or iOS device, the phone's operating system, Symbian, does have some old, known vulnerabilities. The flipside is that "nobody's targeting them anymore", adds Hyppönen. Similarly, the Nokia could be more at risk from techniques that snoop on phone calls. But how many people will bother? It's a security trade-off.

As technology has advanced, experts have often questioned whether the latest systems are actually more risky than older ones. During the late 1990s, Bishop wrote a speech in which he argued that computers were "considerably less secure than the paper systems we still use, and that are rapidly being replaced".

Concerns about the shift from paper to digital technologies remain prevalent, especially when it comes to electronic voting systems. Some say electronic voting machines are desirable partly because they produce election results much more quickly than paper-based systems. That's not enough to sway others, though.

"Voting is the bedrock of our democracy," says Hyppönen. "It's one of the last things I'd like to weaken in any way, especially if the benefits are so small."

Militaries are also known for being reluctant to take chances. Even the world's most active militaries are known to occasionally rely on old technologies for reasons of reliability and security. "One thing I've seen in places like Ukraine is the use of paper maps, or laminated maps, and compasses," says Thomas Withington, associate fellow at the Royal United Services Institute, a think tank. "You can't jam that." It's a kind of "analogue resilience", he adds.

Jamming attacks hitting GPS-based navigation have forced some countries to make careful choices about which legacy technologies to retain, and which GPS alternatives to invest in, says Victor Tasiemski, a systems engineer at Overlook Systems Technologies, which works on navigation tech.

That's exactly what happened in Ireland, where a programme to replace ground-based radio beacons has been slowed down in order to keep those beacons operating for longer. A spokeswoman for the Irish Aviation Authority told the Irish Times in June that the beacons were being retained "as part of a planned resilience strategy".

Technologists who work with militaries are familiar with the challenge of designing systems that can link old and new technologies together. Stefan Kraus is co-founder and chief technical officer of Kraus Hamdani Aerospace, which has designed a drone-based communications platform that can connect military personnel to one another, no matter whether they are using older radios or newer ones. Military radio tech that has been around for decades is "tried, tested and secure", he says. "The US military isn't going away from that."

Tasiemski notes that one alternative to GPS-based navigation is eLoran, a radio-based navigation system that has its roots in military technology first developed during World War Two. With attacks targeting GPS systems, eLoran is arguably becoming increasingly desirable, says Tasiemski, because it uses a much more powerful signal and is therefore much trickier to jam: "Overpowering a one-megawatt transmitter is pretty hard."

Robustness is not easy to replace. This applies in the world of data storage, too, where magnetic tape – invented during the 1950s – still plays a huge role today. Companies, research institutions and government agencies continue to store vast amounts of data on reels of tape. The technology has improved significantly since it first appeared, with data storage densities having increased exponentially over the decades.

But the principle remains the same: spools of tape that hold information. The tape can be detached from computer systems, packaged, and transported to secure facilities, including difficult-to-breach underground caverns and repurposed mines.

"Ransomware is what, for me, kept tape in business the past 10 to 15 years," says Hugues Meyrath, chief executive of Quantum, a company that specialises in data storage.

An organisation locked out of its own computer systems may still be able to retrieve its most important data if staff have made good back-ups, for example on magnetic tape. Interest in magnetic tape is only increasing further today because the cost of random access memory (Ram), a form of computer memory that doesn't rely on tape, is skyrocketing. Meyrath says his company's clients use tape to store all kinds of data – from broadcasters' footage of baseball games to genomes mapped in detail by research facilities.

Tape's security attributes stem partly from the fact that most people don't tend to interact with it at all. It's obscure, clunky, old-school tech. "One way to attack a system is to rig a set of USB sticks and throw them around a parking lot," says Bishop, referring to the likelihood that someone will eventually pick up one of the USB sticks and insert it into their computer – a simple way to perpetrate a hack. As he puts it: "You'll never see magnetic tape thrown around a parking lot."

Experts who spoke to the BBC still recommend that people use the latest and most up-to-date technologies for everyday tasks, as it remains the safest approach. But it is worth acknowledging that "new" doesn't necessarily mean "best" in all scenarios. And knowing when and how to switch to older systems could become increasingly important, as cyber-attacks and other threats get more sophisticated.

Withington points again to Ukraine, where Russia has interfered with satellite communications and where GPS navigation has succumbed to significant jamming. Nowhere is "analogue resilience" more prized. "What do people do," asks Withington, "if there's no access to the technology they take for granted?"


Original Submission

posted by mrcoolbp on Friday August 28, @04:34PM   Printer-friendly
from the something-for-both-Haiku-users dept.

HaikuOS is proud to release Version: R1/beta6. (release notes)

Haiku is an open-source operating system that specifically targets personal computing. Inspired by the BeOS, Haiku is fast, simple to use, easy to learn and yet very powerful.

- (more about HaikuOS)

Downloads available here!

Please post comments on your experience with HaikuOS and the newest release!


Original Submission

posted by mrcoolbp on Friday August 28, @11:53AM   Printer-friendly
from the there...is...no...sanctuary dept.

The Human Reservation Plan

Bill doesn't want to be left behind by Zuckerberg so he decided to share his own thoughts on AI. Different from his previous shared ideas about how great it was. Now there is a bit more doom and gloom. Crime. Unemployment. Healthcare. Horrible things. What the world needs is a plan. Guess who has a plan ... It's the pope, and Bill and "the government".

Set aside some jobs for humans.

A human reservation. For the human to human interactions. So you don't get the bad news from the machine. That it's the machine that tells one human to tell another human the bad news is apparently softening the blow of the bad news.

https://www.gatesnotes.com/work/make-ai-work-for-everyone/reader/a-turbulent-ai-era-and-critical-choices-to-make

http://soylentnews.org/article.pl?sid=26/08/13/2028222

Gates Warns Society Faces An AI-Pocalypse Unless We Get More Socialist

https://www.theregister.com/ai-and-ml/2026/08/26/gates-warns-society-faces-an-ai-pocalypse-unless-we-get-more-socialist/5292560

Bill Gates thinks that experts underestimate the potential havoc AI will wreak on society and says preparations to ease the transition are inadequate. 

The Microsoft founder and former CEO is usually a cheerful proponent of AI tech,  talking up its potential to transform healthcare, education, and business productivity.

Yet in a missive posted to his personal website, the billionaire philanthropist says the AI era is likely to be one of the most turbulent times in human history, and how we allow it to play out will determine whether the world becomes a fairer place or if the divide between rich and poor becomes greater than ever.

This kind of talk will sound dangerously close to socialism for many Americans. There are always winners and losers in a market-led economy, so why should things be any different with AI? Those wealthy enough to invest in it and control it will prosper, as others will find themselves on skid row.

But, Gates says, this time it will be different. Previous technology transitions happened over several generations and created new jobs where human cognition was required, whereas AI is starting to replace human cognition. The winners are likely to be a small group of people, and the losers will be everyone else.

It will not affect just one or two sectors, according to the AI fab club: AI will replace human roles in fields as diverse as law, customer services, medicine, software, and manufacturing. And it will hit these industries rapidly, over the course of a decade or less, rather than taking a few generations.

Gates wrote:

When a community has high unemployment, the ripple effects can be pervasive. Research suggests that in some parts of the United States, factory closures contribute to a rise in deaths from opioid overdoses. Now imagine similar pressures on both white-collar and blue-collar workers nationwide.

There will be some new jobs created, Gates says, but without the right policies in place there will be far fewer than today, and entry-level jobs are among those most likely to vanish (as we're already seeing in the tech industry).

Blue-collar jobs will also be affected, as AI-powered robots are advancing faster than people realize - much of the progress is happening in China. These may begin to compete with people on some physical tasks, such as in the construction and hospitality industries, within a few years.

Gates says there are several big risks from AI adoption, foremost of which is that many work roles are set to disappear forever. He notes that during the Great Depression of the 1930s, unemployment in the US hit 25 percent and remained in double digits for much of that decade, but ultimately recovered as demand, investment, and growth returned. He fails to mention, however, that it took a global war for that to happen.

The biggest shift comes when AI operates error-free operation, without humans prepping its work or checking its output. Gates says we need to think now about reducing job losses, or risk much of society ending up unemployed.

Another danger, Gates says, is that AI empowers people to do harm: AI-driven malware already lets low-skilled attackers launch cyberattacks, while generative AI makes fraud, disinformation, and deepfakes easier to produce. 

The third big threat is that AI systems could stunt the mental development of children, and crowd out human relationships.

So how is society meant to avoid this apocalyptic vision and ensure AI becomes the force for good that Microsoft's progenitor believes it to be?

Gates says AI needs both a domestic and international framework. Nationally, that means bodies that can set priorities across government agencies to ensure every risk is accounted for. Yet even a nation with its own house in order remains exposed to cross-border risks, so an international body must be built in parallel.

If that sounds like wishful thinking, get in the queue. Gates notes it would require US-China cooperation, and under the current Washington administration, that's about as likely as pigs flying..

Beyond that, some jobs - social care for instance - should stay human. Gates also thinks the tax system will need rebalancing, as more people out of work means less income tax to fund government itself.

A starting point, he suggests, is taxing AI tokens and robots to reduce corporations' incentives to swap meatbags for machines. This could fund retraining and a stronger safety net, but would need careful targeting so it doesn't hinder beneficial uses of AI, like drug discovery and better education

Again, critics will likely dismiss this as socialism and point out that Microsoft was ruthless in pursuing profits under Gates' leadership. 

In a final message to world leaders, Gates urges them to act now, "before unemployment rises sharply, communities are hurting, and public trust has eroded."

This marks a shift for the Microsoft founder, who two years ago told people not to worry about AI, in particular energy use and increased greenhouse gas emissions, arguing AI would eventually solve the problems it creates.


Original Submission #1Original Submission #2

posted by mrcoolbp on Friday August 28, @07:09AM   Printer-friendly

https://www.ghacks.net/2026/08/24/aliexpress-ran-silent-browser-audio-to-fingerprint-and-track-devices-researchers-find/

AliExpress has been found to run silent audio processes in the browser to fingerprint and track devices. Code on the homepage, linked to Alibaba's security systems, uses the Web Audio API to send a signal through a device's audio hardware and measure the small, device-specific differences in how it returns.

This creates a fingerprint that does not rely on cookies. The issue only came to light after a developer noticed problems using multipoint Bluetooth headphones while an AliExpress tab was open.

This type of fingerprinting is not something most users would notice.

The issue came to light when a developer's multipoint Bluetooth headphones would not switch properly from a computer to a phone while an AliExpress tab was open. Once the tab was closed, the problem disappeared.

Looking at the site's code, the developer found it used the Web Audio API to build audio-processing graphs set to zero volume. There was no audible sound, but the process still connected to the computer's audio system and kept the audio path active in the background.

This seems to be what interfered with the headphones' ability to switch devices. Since the processing graph ran at zero gain and connected directly to the system's audio output, muting the browser tab had no effect.

The same code can be used for browser fingerprinting, which collects device-specific details to recognize a browser over time. Here, the scripts measured small differences in how a device processed the same audio signal. These differences depend on the computer's processor, sound hardware, operating system, browser, and drivers.

Audio measurements were just one part of the data collected. The scripts also gathered information from canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior, and user interactions. Combined, these signals create a more detailed device profile than any single method alone.

Fingerprinting is often used by large online platforms for fraud prevention, bot detection, and risk assessment. It helps spot suspicious transactions or automated activity when cookies are not available. Privacy advocates have raised concerns because users may not realize this tracking is happening and have little control over it.

Brave was one of the first to highlight this behavior. In an August 22 post on X, the company said its browser blocks the AliExpress scripts responsible for audio-based tracking. Brave has included default protections against audio fingerprinting for more than six years.

Its approach changes certain browser outputs, so websites get inconsistent fingerprinting signals instead of a stable identifier. The company has also added similar protections for GPU fingerprinting against this tracking. There are limited but concrete options:

        Use a browser with built-in fingerprinting protection, such as Brave, which alters outputs to prevent a stable audio fingerprint.
        Apply a content blocker like uBlock Origin in other browsers to block the responsible scripts.
        There is a trade-off, as blocking these scripts could affect parts of AliExpress that depend on the same code for security or fraud prevention.

AliExpress has not explained the purpose or scope of the audio fingerprinting. The scripts' connection to Alibaba's security systems suggests a fraud-prevention role as well as tracking.

This episode highlights the trade-off between platforms wanting more ways to spot suspicious activity and users wanting limits on tracking without clear notice or consent. It is not clear how widely this technique is used on other sites, or if AliExpress will change its behavior.


Original Submission

posted by hubie on Friday August 28, @02:24AM   Printer-friendly
from the is-it-a-piece-of-bug-free-software? dept.

Red Tetris stickers and shirtless Windows 95 tots - accidental collectibles gathering dust:

In a future edition of The Antiques Roadshow, the hosts might get all excited about a mint Microsoft Entertainment Pack for Windows... with a sticker on the box instead of a printed Tetris promotion.

Veteran Microsoft engineer Raymond Chen explained the reasoning behind using the sticker instead of simply printing what was in the box. Microsoft hadn't locked down the rights for Tetris before the first print run of the packaging, so went with what it had.

The Microsoft Entertainment Pack for Windows debuted in 1990, the same year that Windows 3.0 was released and ushered in an era of Microsoft desktop dominance. Three more iterations of the entertainment pack followed, which included FreeCell, before Microsoft pulled the plug in 1992 (although a Best Of version arrived in 1994, and there was another version for Windows CE later in the 1990s).

We'll draw a discreet veil over the ad-festooned version currently in the Microsoft Store.

The floppy disks in the box included several card games, Minesweeper, and a Windows version of the fiendishly addictive and massively popular game of the era, Tetris.

But it might not have gone that way. Chen explained in a post on his Old New Thing blog, "At the time the first run of boxes were being printed, the negotiations to license Tetris hadn't yet concluded. There was a chance that the negotiations would fall through, and the Entertainment Pack would have to be released without Tetris."

So, rather than risk throwing away a production run, Microsoft went ahead with the Tetris-less branding, and added a sticker when the deal was done. Later print runs made the sticker part of the box art, hence the rarity of the original.

Microsoft has a bit of a history of inadvertently creating collectibles. Chen recalled an incident with Windows 95, when an anti-piracy hologram on the case depicted a child pointing at a computer monitor and the Windows 95 logo. The child was shirtless, which caused offense in some quarters. Microsoft's solution? A new hologram with the baby in a shirt and overalls.

However, some original versions still exist. Chen said, "So if you still have your copy of Windows 95, go look at the hologram. If the baby in your hologram isn't wearing a shirt, you have a genuine collector's item."

We can just imagine the excitement at the recording now, as someone produces not only a stickered version of the Microsoft Entertainment Pack for Windows, but also the topless baby version of Windows 95...


Original Submission

posted by hubie on Thursday August 27, @09:42PM   Printer-friendly

Chang'e 7 didn't meet unspecified 'launch requirements':

China's Manned Space Agency (CMSA) on Sunday cancelled a planned Monday moonshot launch.

The mission plan for Chang'e 7 calls for it to send a lander to a region near the Moon's South Pole, in a location thought likely to contain ice in deep craters.

The lander carries two other vehicles: a wheeled rover, and a hopper. China wants to test the latter to see if it can jump over crater rims to look for ice, and then hop out again and continue exploring.

The lander is also important to China, because it's equipped with tech to enable a precision autonomous landing – a tricky feat given the chaotic terrain moon mappers believe awaits it.

China has built the lander, rover, and hopper to survive multiple Lunar nights, the stretches of two weeks or more without light, during which the mercury can dip below a hellish minus 200 Celsius in the shadows.

The mission also involves an orbiter to help the ground vehicles send data home and carry out its own observations.

Richard de Grijs, a professor of astrophysics at Australia's Macquarie University, last week wrote that the mission is significant because it represents "a transition from simply exploring the Moon to determining whether its resources can actually be used."

"Chinese scientists won't be looking for signs of water; we already have compelling evidence for lunar polar water," he wrote. "The question at the mission's core is where exactly that water is located, in what form and concentration, and whether it could realistically be accessed."

Sadly, we won't begin to get the answers to those questions until next year.

CMSA and Chinese state media on Sunday published a brief statement that says "Chang'e 7 mission headquarters had reached a conclusion that the lunar expedition cannot be carried out within this year's scheduled launch window as it had failed to meet launch criteria."

"The decision was made in accordance with the principles of prudence, reliability and absolute safety."

State media reports of the mission's cancellation point out that launch windows that allow flights to the South Pole come along only once or twice a year, and that none is available this year.

Some Chinese outlets report that bad weather was the reason for calling the mission off, a plausible cause as state media today warns of torrential rain ahead of a typhoon in Hainan, the location of the launchpad for the mission. It is unclear why CMSA didn't mention the bad weather.


Original Submission

posted by hubie on Thursday August 27, @05:00PM   Printer-friendly
from the just-when-you-think-you're-safe-from-Windows dept.

https://www.phoronix.com/news/NTFS3-Vulnerability-For-Root

A reported security vulnerability for the NTFS3 driver has gone unaddressed since being reported earlier this summer. The vulnerability allows a pre-crafted NTFS image on a USB flash drive or similar to allow the user to gain root access to the running Linux system.

After being reported privately two months ago and going unresolved, a SUID injection leading to local privilege escalation was made public. A Phoronix reader noted the disclosure via the NTFS3 mailing list.

Vova Tokarev who discovered the issue noted:

        "A pre-crafted NTFS image (e.g. USB drive) with $LXUID=0, $LXGID=0, $LXMOD=0104755 already in the MFT produces a setuid-root binary the moment the volume is mounted. No setxattr() is involved -- the EAs are on disk. The -EPERM check doesn't help.

        The root cause is still at fs/ntfs3/xattr.c:1022:

        inode->i_mode = le32_to_cpu(value[2]);

        This loads S_ISUID/S_ISGID directly from untrusted on-disk data. Desktop automounters (udisks) mount NTFS with suid by default, so plugging in a crafted USB gives any local user euid=0.

        Suggested one-line fix:

        - inode->i_mode = le32_to_cpu(value[2]);
        + inode->i_mode = le32_to_cpu(value[2]) & ~(S_ISUID | S_ISGID);

        I have a full PoC and working demo."

Those interested can find the proof of concept and demo along with more information via this mailing list post.

As of writing the vulnerability has yet to be addressed by the mainline NTFS3 kernel driver. This doesn't appear to impact the newer NTFS driver alternative that also continues maturing within the mainline kernel tree.


Original Submission

posted by hubie on Thursday August 27, @12:18PM   Printer-friendly
from the we-have-learned-nothing dept.

Attacks on these industrial controllers could lead to sabotage of critical infrastructure:

Agencies Claim Threat Actors Use AI Tools To Generate Exploitation

“The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the agency said in its warning. “The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk — it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.”

What makes the threat especially dangerous is that the use of AI tools could enable potential attackers to make malicious files look and behave like legitimate monitoring tools. They achieve this by using open-source industrial automation libraries, making it easier for unsuspecting users to fall victim to their attacks. Although the agencies did not specify where these attacks could originate, they came less than a month after the water infrastructure of several states was hit by cyberattacks thought to have originated from Iran.

There were even claims from Iran that networking devices from American and European companies failed during an attack even though they were disconnected from the rest of the world. Aside from these scenarios in active warfare, cyberattacks could also be used in gray warfare, where opponents can inflict maximum damage while retaining plausible deniability, reducing the chances of retaliation.


Original Submission

posted by hubie on Thursday August 27, @07:35AM   Printer-friendly

https://www.slashgear.com/2238061/company-making-no-tech-tractor-maximum-repairability/

America's agricultural sector is a key component of the country's economy, and critical to maintaining ongoing food supplies. Statistics tell an interesting story, where the number of farms has steadily dropped since the early 1980's, while also tripling output between 1948 and 2021. One of the reasons fewer farmers have been able to produce more has to do with advances in equipment technology. Today, there are several major tractor brands to choose from, though they rank differently in terms of things like reliability and resale value. However, it seems tractor manufacturers may have taken the idea of high-tech farming a bit too far for many farmers. This is evident when looking at the ongoing surge of sales within the older used tractor market.

One Canadian company, Ursa Ag, has noticed this trend and decided to go against the industry, relying on basic fundamental operation over today's complex software, autosteer, GPS, and connectivity features. It isn't just smaller farms interested in investing in these basic machines, but also massive players in the U.S. dairy industry looking to equip their fleets. Ursa Ag is said to be tripling production of its new "no frills" machines in an attempt to keep up with demand. Speaking with 404 media, Doug Wilson with Ursa Ag conceded that cutting-edge agricultural equipment does have its place, "But that technology is needed for 5 percent of what a farm does. There are so many applications for tractors on farms that don't require technology."

One of the biggest reasons is cost. For around half the money of a new John Deere, you could get a new Ursa Ag. Saving money on equipment is crucial for farmers, as crop farm profit margins over the last few years have hovered around 5%, which doesn't leave much room for added expenses. North American Equipment Dealers Association CEO in 2024, Kim Rominger, confirmed that technology is "absolutely" responsible for the increasingly higher prices seen on equipment, per Manitoba Cooperator.

Another major factor influencing many farmers has to do with the repairs. Older or more basic machines don't have as many fancy features or sensors, making them easier for farmers to repair when something goes wrong. Imagine the frustration of a situation where a faulty internet-connected sensor on your tractor brings everything in the field to a halt.

More concerning are recent actions by John Deere, which have put customer rights into the spotlight. Litigation surrounding the right to repair has been ongoing, with a John Deere lawsuit ending in $99 million payout for farmers. Essentially, some manufacturers don't want their customers to have access to the software tools required to fix the latest tractors. Without access, farmers aren't able to work and repair the machines they purchased. Instead, brands like John Deere want all repairs funneled through the company's own service department.


Original Submission

posted by hubie on Thursday August 27, @02:48AM   Printer-friendly

Expanded multistage chain of thought monitoring makes frontier model work more expensive:

OpenAI on Tuesday said its decision to suspend model training work, implemented after unreleased, unsupervised AI models hacked HuggingFace, remains in effect as the AI biz tries to implement stronger security measures. Some of those measures will increase compute overhead by 20 percent of the observed inference workload.

An OpenAI spokesperson told The Register that those costs reflect internal research and won't be passed on directly to customers. The company has not revealed what portion of its total inference compute is subject to such monitoring now, or under its prior monitoring regime.

"We have paused some frontier RL [reinforcement learning] training to ensure that we can meet the appropriate alignment, security and monitoring standards for the new level of capabilities in front of us," OpenAI CEO Sam Altman wrote in a social media post. "Model progress is now extremely rapid, and we always said we would take action if we felt that model capabilities were outstripping the pace of safety and alignment."

Altman said he still expects new models, presumably the delayed Astra, will ship soon. The training pause affects further-out releases.

OpenAI in its post reiterated its plans to focus on monitoring, model alignment, and security measures to prevent its models from running amok as they did last month. Following the HuggingFace incident, OpenAI "paused frontier model inference in research clusters for runs that could execute code or use tools that could access the internet."

The biz said it allows some workloads to run, but paused others until they can be moved under a more stringent security regime that includes sandboxing, network isolation, and continuous security testing.

"Our largest planned frontier RL (reinforcement learning) run remains on hold while we conduct smaller-scale training and evaluations to assess model behavior, validate our safeguards, and establish more evidence of alignment before proceeding," the company wrote.

[...] If you choose to believe the company's assurance that it will not pass on the cost of model thought policing to customers, it follows that OpenAI's losses will increase. It's difficult to imagine that would be a sustainable stance if OpenAI goes public.

But given the company's reported $600+ billion in AI infrastructure commitments and its expectation to remain unprofitable until at least 2030, what's a bit more expense for the sake of uncertain security?


Original Submission

posted by jelizondo on Wednesday August 26, @10:05PM   Printer-friendly

And they looked absolutely ridiculous doing it:

Usain Bolt's 2009 world record for the 100-meter dash still remains unbroken at 9.58 seconds, but only if we're talking about humans. During the second annual World Humanoid Robot Games that kicked off in Beijing on Saturday, the Tiangong Ultra humanoid robot completed the 100-meter dash in 9.39 seconds during a preliminary heat. Developed by Beijing Humanoid Robot Innovation Center, the record-holding robot overtook Honor's Lightning robot, which completed the sprint in 9.47 seconds.

Despite the impressive finish times, don't expect these humanoid robots [1:23 Really funny. --Ed] to be used for any commercial purposes yet. After their sprints, they slammed directly into pads and some even required human assistance to be stretchered off the course. However, it's still a major improvement from last year's inaugural World Humanoid Robot Games, where the Tiangong Ultra won the 100-meter dash in 21.5 seconds.

Aside from this Robot Olympics event, Beijing hosted a half-marathon for Chinese companies to show off the capabilities of their humanoid robots. The event had its fair share of crashes too, but Honor's Lightning robot managed to secure the gold medal with a finish time of 50 minutes and 26 seconds, which also surpassed another human record. The World Humanoid Robot Games in Beijing kicked off August 22 and will run until the 26, hosting thousands of robot participants competing in more than just track and field events, including soccer, table tennis and boxing.


Original Submission

posted by jelizondo on Wednesday August 26, @05:29PM   Printer-friendly

https://www.tomshardware.com/tech-industry/artificial-intelligence/openai-fights-to-keep-chatgpt-lawsuit-away-from-a-state-jury

Florida Seeks Court Ruling To Officially Classify Sam Altman And ChatGPT As A 'Public Nuisance' — OpenAI Fights To Keep Lawsuit Away From A State Jury

OpenAI's brief cites three cases in which states sued platforms under state law, defendants removed, and federal judges sent them back: New Mexico v. Meta, California v. TikTok, and New Jersey v. Discord. OpenAI cites them only to show the judges declined to award fees because removal wasn't "objectively unreasonable." Florida's remand motion asks for fees regardless, arguing OpenAI removed for one reason: "delay."

The complaint's remaining counts cover negligence, gross negligence, strict liability for design defect and failure to warn, fraudulent misrepresentation, and public nuisance. It alleges ChatGPT's memory feature was on by default, the free tier has no age gate, the September 2025 parental controls require a voluntary account link, and GPT-4o's safety evaluation was compressed to one week to beat a Google launch.

The State seeks a permanent injunction on under-13 data collection and a finding that distributing ChatGPT in Florida is a public nuisance, demanding civil penalties of up to $10,000 per willful violation, which is double New Mexico's $5,000 cap. New Mexico's jury found 75,000 violations.

A footnote in every federal filing states that Altman "is not making a general appearance" and reserves a personal-jurisdiction defense. That defense sets up a motion to dismiss the CEO individually, no matter which court hears the case. Much of the record that Florida's case relies on is against Altman, including Greg Brockman's diary and Tasha McCauley's testimony about a "toxic culture of lying," which came out at the Musk v. Altman trial in May. A coalition of 42 state attorneys general subpoenaed OpenAI in June; none has filed a complaint yet.


Original Submission

posted by janrinok on Wednesday August 26, @04:10PM   Printer-friendly
from the RIP:-80-is-a-very-unlucky-age-it-seems dept.
https://people.com/tim-curry-dead-obituary-8549935

Tim Curry has died at age 80

The British actor was known for iconic roles like Dr. Frank-N-Furter in The Rocky Horror Picture Show and Pennywise.

Curry earned three Tony nominations and a Daytime Emmy and released three musical albums in his career

The British star got his start on stage in the West End, starring in the original London production of Hair in 1968 after attending Birmingham University. But according to the actor, he fudged his own experience to get a part in the show. "When asked if he had professional experience and an Equity card, Tim lied about both," his website reads. "By the time the producers found out the truth, they were sufficiently impressed with his talent and presence to sponsor him for his union membership."

In 2012, Curry suffered a major stroke and has used a wheelchair since. Curry, who never married and has no children, mostly pulled back on his acting career then, focusing instead on voiceover projects.

posted by jelizondo on Wednesday August 26, @12:34PM   Printer-friendly

https://arstechnica.com/science/2026/08/researchers-use-thunderquakes-to-study-structure-of-earths-surface/

Most of what we know about the Earth's interior comes from observing seismic waves. These travel at somewhat different speeds depending on the details of the rock they're moving through—whether it's solid or semi-molten, how much water is present, whether it's fractured or solid material, and so on. Get enough data from enough seismic events, and you can start piecing together a picture of what's present at different depths below the surface.

In many cases, we can get this data from naturally occurring events like earthquakes. In others, we intentionally create waves using things like explosives, providing the opportunity to do imaging in specific areas without needing to wait for an earthquake. Now, a team of scientists at Penn State suggests there's a potential option that sits between waiting for an earthquake and triggering your own seismic event: thunderstorms.

Some of the energy carried by thunder enters the Earth's upper crust, triggering what are termed "thunderquakes." But, for various physical reasons, the seismic signals are extremely complex, making it difficult to extract clear signals from them. The Penn State team says it has finally constructed a model that can help make sense of this complexity and used it to reconstruct the terrain under the local campus.

Why are thunderquakes so hideously complex? It starts with the phenomenon that creates thunder in the first place. Lightning creates thunder by forming superheated bubbles of plasma along its path, creating a structure that has been compared to a string of beads. Each of those beads has the potential to generate an acoustic shock wave, leading to a chain of expanding shock waves that trace the lightning's path through the area, which is anything but a straight line. These waves also have the potential to interfere with each other as they expand. And, while these shock waves first hit the Earth at a single point, they rapidly expand from there, albeit with decreasing power.

Things don't get less complex once the Earth gets involved. The acoustic shock waves may strike soft soil, hard rock, various forms of human infrastructure, and so on, each of which will affect how energy gets transmitted. Some of the energy gets converted into what are called Rayleigh waves, where the energy is transmitted as a wave that moves along the Earth's surface. The rest go deeper, forming waves that may move through some combination of loose material or the underlying bedrock.

To extract information about the Earth's structure, you have to understand what the seismic waves from a thunderclap would normally look like. Which, to an extent, requires modeling all of the above processes. Since each thunderquake is going to be unique due to the different locations and conditions, this model is going to be, at best, an approximation. The fear that any approximation wouldn't be good enough to generate usable data probably kept people from trying to analyze thunderquakes sooner.

To get their approximation, the team started with a software package called SPECFEM3D Cartesian, which is dedicated to 3D reconstructions of seismic waves. Already, that choice necessitates a few compromises. For example, the software treats the atmosphere as a 3.6 km-thick homogeneous layer, even though the atmosphere near a thunderstorm is anything but. The model also updates events at a frequency that's slower than the waves moving through the Earth-air interface. So, to compensate for that, the researchers simply stretched the top 20 meters of Earth out to cover 200 meters.

These and other factors mean that there were plenty of reasons to think that the model wouldn't be sufficient to handle real-world data. So, the people who developed it tested it against the real world, using thunderstorms that passed by their campus.

One of the nicer discoveries in seismology has been the realization that the same fiber-optic cables that rush cat pics to your LAN can act as seismometers. And, conveniently, the Penn State campus has a 4 kilometer fiber line that has been set aside for seismic sensing running under the campus. And said campus happens to be located in a part of the US where summer thunderstorms are a regular occurrence.

Two years of data netted them 458 well-resolved thunderquakes, each of which was confirmed using records from the US's National Lightning Detection Network (something I had not realized existed). These quakes were characterized by multiple signals arriving from different altitudes, as you'd expect from a chain of beads reaching from clouds to the Earth's surface. Once the signals arrived at the Earth's surface, things happened quickly: "The impingement of each bubble onto the ground or environment generates a high-energy impulsive wavelet followed by a decaying wave train dominated by surface-wave content lasting one to two seconds."

From there, the signal spread out and started to interact with the features of the Earth under the campus. Using this data, the team identified four "weak zones," where seismic signals slow down as they interact with less rigid materials. These can include sediments, fractured rock, or areas with high water content. The Penn State campus happens to sit on a karst formation, where water has slowly altered limestone bedrock, potentially creating a variety of weak spots.

In these cases, the team was able to confirm that these four sites actually have something unusual going on there. This was done using a mixture of radar that measured surface deformation, engineering surveys, boreholes made at the sites, and independent seismic data.

All of which gives the researchers confidence that, despite all the approximations it required, their model is performing reconstructions that are sufficiently accurate to obtain informative seismic data. And the thunderquakes have a number of advantages, including their relative frequency in many areas of the globe, and the fact that they're best for reconstruction of the areas closest to the surface, which is where almost all of our infrastructure is located.

So, this definitely appears to be a case where we have a model that's wrong, but also useful.

Science Advances, 2026. DOI: 10.1126/sciadv.aeg8096 (About DOIs).


Original Submission