Domain: vice.com
Stories and comments across the archive that link to vice.com.
Stories · 1,377
-
'Why I Bid $700 For a Stolen PSN Account' (vice.com)
Patrick Klepek tells the story of a PlayStation Network user who had their 13-year-old account stolen via what appears to be a social engineering scheme against Sony. Klepek managed to track it down and start negotiating for its release. An anonymous Slashdot reader shares an excerpt from the report: 1,200. That's how much someone is asking for a PlayStation Network account I've been investigating for the past few weeks. "Secure," the person calls it, claiming the account will "never be touched" by the original owner again. "He won't be getting it back," they claim. More than a thousand dollars? That's a little rich for my blood, and so I counteroffer: $700. "Btc?" they respond, accepting my bid. (BTC refers to bitcoin. The majority of transactions like this take place using cryptocurrency; it's generally harder, but not impossible, to trace.) I didn't purchase the account, of course. But I could -- anyone could, if they only knew where to look. This account wasn't on a shady market because someone was clumsy with their digital security. They had a strong password and two-factor authentication. When they were notified about problems with their account, they called Sony and asked for help. Despite all this, despite proving their identity over and over, they lost access to their PSN account, including any trophies earned or any games purchased. It was gone...well, sort of. The original owner no longer had access, but this person -- the individual asking for $1,200 but who quickly and without hesitation dropped to $700 -- did.
[...]
More than likely, Sony itself is a victim of a clever social engineering scheme, in which a user, or series of users, repeatedly spammed their representatives, until it found someone willing to accept the limited information they did have, and calculated the system would eventually lock the account in their favor. Even a "failed" social engineering attempt can be a success, if the person calling comes away with new information about the account. Every company in the world can fall victim to social engineering, as there are no true fail safes. But Sony's setup seems especially ripe for it. Why didn't the system get flagged as "sensitive" sooner? Why can a user flip off two-factor authentication over the phone? How can an account get abandoned, when it's still active? There are ways Sony could have prevented this from happening. In the end, the original account owner was magically handed the account. "Sony promised that they were going to set it up so no reps could make any changes," the account owner said, "but they are still investigating how this happened." -
Walmart Patents Cart That Reads Your Pulse, Temperature (vice.com)
Walmart recently applied to patent biometric shopping handles that would track a shopper's heart rate, palm temperature, grip force, and walking speed. "The patent, titled 'System And Method For A Biometric Feedback Cart Handle' and published August 23, outlines a system where sensors in the cart send data to a server," reports Motherboard. "That server then notifies a store employee to check on individual customers." From the report: Over time, the server can build a database of data compared against store location and stress response, the patent says -- potentially valuable information for store planning. Other uses outlined in the patent include a pulse oximeter, for detecting when a customer's about to pass out, and a weight-triggered assisted push feature for propelling the cart itself. CBInsights suggests that these alerts could warn associates when several shoppers need help at the same time, or anticipate when arguments are about to break out. -
German Art Activists Get Passport Using Digitally Altered Photo of Two Women Merged Together (vice.com)
An anonymous reader shares a report: Last month, an activist from the German art collective Peng! walked into her local government office in Berlin and applied for a new passport. "I probably have broken the law," the woman, a chemist living in the Western Saxony region, told Motherboard, "but our lawyers don't know which one." The woman applied for a passport using a photo of two separate people. Using specialized software created by Peng!, the collective merged the facial vectors from two different faces from two different images into one. Billie Hoffman (a pseudonym used by everyone in the Peng! Collective when talking to journalists), she told me how easy the whole process was: "Officials didn't mention fraud at any point." Hoffman's passport application was approved, and now she has an official German passport using the digitally altered photo. The photo is half her, half Federica Mogherini, an Italian politician who is the High Representative of the European Union for Foreign Affairs and Security Policy. "The software calculated an authentic average of the faces and that's it," Hoffmann recalls.
Hoffman's passport is part of an artwork called "Mask ID," a campaign that's encouraging ordinary citizens to "flood government databases with misinformation" and disrupt mass surveillance programs. Ironically, the project is funded by the Bundeskulturstiftung, the German Federal cultural fund, part one was recently on show in Hamburg accompanied by a photo booth where anyone could upload their image and create their own distorted passport picture in an attempt to confuse government surveillance and circumnavigate facial recognition software. "Passports are tools of oppression" another member of the collective who declined to give me their real name told me. -
Researchers Created 'Quantum Artificial Life' For the First Time (vice.com)
From a report: For the first time, an international team of researchers has used a quantum computer to create artificial life -- a simulation of living organisms that scientists can use to understand life at the level of whole populations all the way down to cellular interactions. With the quantum computer, individual living organisms represented at a microscopic level with superconducting qubits were made to "mate," interact with their environment, and "die" to model some of the major factors that influence evolution. The new research, published in Scientific Reports on Thursday, is a breakthrough that may eventually help answer the question of whether the origin of life can be explained by quantum mechanics, a theory of physics that describes the universe in terms of the interactions between subatomic particles. Modeling quantum artificial life is a new approach to one of the most vexing questions in science: How does life emerge from inert matter, such as the "primordial soup" of organic molecules that once existed on Earth? -
Jeff Bezos Is Planning To Ship 'Several Metric Tons of Cargo' To the Moon (vice.com)
Jeff Bezos' Blue Origin aerospace company is planning to send "several metric tons" of unspecified cargo to the Moon in the next five years. The company reportedly signed a letter of intent with Germany aerospace companies OHB Space Systems and Security and MT Aerospace at the 69th annual International Astronautical Congress (IAC) in Germany on Tuesday. The OHB dubbed the lunar project the "Blue Moon" mission in a press release. Motherboard reports: It's not clear exactly what cargo the Blue Moon mission would transport, but it likely includes infrastructure designed to start private business on the Moon: The IAC also detailed the launch of the "Moon Race," a competition between Blue Origin, Airbus Air and Space, and other space agencies around the world to develop technology that will bring companies around the world to the Moon. According to a press release, the competition could involve manufacturing products and technology, manufacturing energy sources for humans to survive, getting access to water and sustaining biological life, such as plant or agricultural life -- all on the Moon. Blue Origin said in a press release that both the Blue Moon mission and Moon Race are in line with its goal to "land large payloads on the Moon that can access and utilize the resources found there." -
Apple's New Proprietary Software Locks Kill Independent Repair On New MacBook Pros (vice.com)
An anonymous reader quotes a report from Motherboard: Apple has introduced software locks that will effectively prevent independent and third-party repair on 2018 MacBook Pro computers, according to internal Apple documents obtained by Motherboard. The new system will render the computer "inoperative" unless a proprietary Apple "system configuration" software is run after parts of the system are replaced. According to the document, which was distributed to Apple's Authorized Service Providers late last month, this policy will apply to all Apple computers with the "T2" security chip, which is present in 2018 MacBook Pros as well as the iMac Pro. The software lock will kick in for any repair which involves replacing a MacBook Pro's display assembly, logic board, top case (the keyboard, touchpad, and internal housing), and Touch ID board. On iMac Pros, it will kick in if the Logic Board or flash storage are replaced. The computer will only begin functioning again after Apple or a member of one of Apple's Authorized Service Provider repair program runs diagnostic software called Apple Service Toolkit 2. -
Psychedelic Mushrooms Are Closer To Medicinal Use (nytimes.com)
Researchers from Johns Hopkins University have recommended that psilocybin, the active compound in hallucinogenic mushrooms, be reclassified for medical use, potentially paving the way for the psychedelic drug to one day treat depression and anxiety and help people stop smoking. The New York Times: The suggestion to reclassify psilocybin from a Schedule I drug, with no known medical benefit, to a Schedule IV drug, which is akin to prescription sleeping pills, was part of a review to assess the safety and abuse of medically administered psilocybin [Editor's note: the story may be paywalled; alternative source]. Before the Food and Drug Administration can be petitioned to reclassify the drug, though, it has to clear extensive study and trials, which can take more than five years, the researchers wrote. The analysis was published in the October print issue of Neuropharmacology, a medical journal focused on neuroscience.
The study comes as many Americans shift their attitudes toward the use of some illegal drugs. The widespread legalization of marijuana has helped demystify drug use, with many people now recognizing the medicinal benefits for those with anxiety, arthritis and other physical ailments. Psychedelics, like LSD and psilocybin, are illegal and not approved for medical or recreational use. But in recent years scientists and consumers have begun rethinking their use to combat depression and anxiety. -
The Rise of Netflix Competitors Has Pushed Consumers Back Toward Piracy (vice.com)
A new study from network equipment company Sandvine finds that BitTorrent usage and piracy is increasing after years of declines. The reason appears to be due to "an increase in exclusivity deals that force subscribers to hunt and peck among a myriad of streaming services to actually find the content they're looking for," reports Motherboard. From the report: Sandvine's new Global Internet Phenomena report offers some interesting insight into user video habits and the internet, such as the fact that more than 50 percent of internet traffic is now encrypted, video now accounts for 58 percent of all global traffic, and Netflix alone now comprises 15 percent of all internet downstream data consumed. But there's another interesting tidbit buried in the firm's report: after years of steady decline, BitTorrent usage is once again growing.
According to Sandvine, file-sharing accounts for 3 percent of global downstream and 22 percent of upstream traffic, with 97% of that traffic in turn being BitTorrent. While BitTorrent is often used to distribute ordinary files, it remains the choice du jour for those looking to distribute and trade copyrighted content online, made easier via media PCs running Kodi and select plugins. Back in 2011, Sandvine stated that BitTorrent accounted for 52.01% of upstream traffic on fixed broadband networks in North America. By 2015, BitTorrent's share of upstream traffic on these networks had dipped to 26.83 percent, largely thanks to the rise in quality, inexpensive streaming alternatives to piracy. But Sandvine notes that trend is now reversing slightly, with BitTorrent's traffic share once again growing worldwide. That's especially true in the Middle East, Europe, and Africa, where BitTorrent now accounts for 32% of all upstream network traffic. -
DARPA Is Researching Quantized Inertia, a Theory Many Think Is Pseudoscience (vice.com)
dmoberhaus writes: DARPA just awarded a $1.3 million contract to an international team of researchers to study quantized inertia or QI. This is a controversial theory that many physicists think is pseudoscience, but according to the physicist that created it, QI may be the foundation for light-powered space travel that could open the door for interstellar travel. Motherboard looks at the fact and fiction of QI, its relationship to the 'impossible' EmDrive being developed by NASA and how these physicists are going to create experimental light-powered engines.
Quantized inertia (QI) is an alternative theory of inertia, a property of matter that describes an object's resistance to acceleration. QI was first proposed by University of Plymouth physicist Mike McCulloch in 2007, but it is still considered a fringe theory by many, if not most, physicists today. McCulloch has used the theory to explain galactic rotation speeds without the need for dark matter, but he believes it may one day provide the foundation for launching space vehicles without fuel. The DARPA grant will allow McCulloch and a team of collaborators from Germany and Spain to undertake a series of experiments that will apply QI in a laboratory setting for the first time. -
This Solar-Powered, 'Low Tech' Website Goes Offline When It's Cloudy (vice.com)
An anonymous reader shares a report: Every website and product connected to the internet would not be able to exist without a vast network of wireless routers, fiber optic cables running underground and underwater, and data centers that house the servers which bring the internet to life. Data centers in the U.S. alone eat up 70 billion kilowatts of energy per year, according to a 2016 estimate from the Department of Energy -- that's 1.8 percent of all energy use across the country.
The internet is not ethereal, and a new project from the blog Low-Tech Magazine aims to make that issue more tangible. Low-Tech Magazine -- a blog operated by Kris De Decker that has run on Wordpress since 2007 -- launched a "Low-Tech," solar version of the site that's designed from the ground-up to use as little energy as possible. (Check out the solar version of the site here.) In a Skype call with Motherboard, De Decker said that he doesn't think people don't care about how much energy it takes they use the internet, they just don't understand the extent of the problem. "There's this idea that the internet is immaterial, it's somewhere floating in clouds," he said. "Of course, it's a very material thing that uses resources, materials, energy -- and quite a lot actually." -
Richard Stallman Says Linux Code Contributions Can't Be Rescinded (itwire.com)
An anonymous reader quotes iTWire: Linux developers who contribute code to the kernel cannot rescind those contributions, according to the software programmer who devised the GNU General Public Licence version 2.0, the licence under which the kernel is released. Richard Stallman, the head of the Free Software Foundation and founder of the GNU Project, told iTWire in response to queries that contributors to a GPLv2-covered program could not ask for their code to be removed. "That's because they are bound by the GPLv2 themselves. I checked this with a lawyer," said Stallman, who started the free software movement in 1984.
There have been claims made by many people, including journalists, that if any kernel developers are penalised under the new code of conduct for the kernel project -- which was put in place when Linux creator Linus Torvalds decided to take a break to fix his behavioural issues -- then they would ask for their code to be removed from the kernel... Stallman asked: "But what if they could? What would they achieve by doing so? They would cause harm to the whole free software community. The anonymous person who suggests that Linux contributors do this is urging them to [use a] set of nuclear weapons in pique over an internal matter of the development team for Linux. What a shame that would be."
Slashdot reader dmoberhaus shared an article from Motherboard with more perspetives from Eric S. Raymond and LWN.net founder Jonathan Corbet, which also traces the origins of the suggestion. "[A]n anonymous user going by the handle 'unconditionedwitness' called for developers who end up getting banned through the Code of Conduct in the future to rescind their contributions to the Linux kernel 'in a bloc' to produce the greatest effect.
"It is worth noting that the email address for unconditionedwitness pointed to redchan.it, a now defunct message board on 8chan that mostly hosted misogynistic memes, many of which were associated with gamergate." -
An Ex-NSA Hacker Who Has Organized the First-Ever Mac Security Conference (vice.com)
Motherboard's Lorenzo Franceschi-Bicchierai spoke with Patrick Wardle, the ex-NSA hacker who's organizing a security conference exclusively dedicated to Macs. Despite what Apple has famously promoted in the mid 2000s that Macs don't get "PC viruses," Mac computers do in fact have bugs, vulnerabilities, and even malware targeted at them. From the report: "People are peeking behind the curtain and realizing that the facade of Mac security is not always what it's cracked to be," Wardle told Motherboard in a phone interview. "Any company that designs software is going to have issues -- but Apple has perfected the art of a flawless public facade that masks many security issues." Wardle would know. After hacking primarily Windows computers at Fort Meade, for the last few years Wardle been finding several issues in MacOS, so many that he considers himself a "thorn" on Apple's side. But his conference is not an exercise in shaming or finger pointing, Wardle said he hopes to educate and teach people about Mac security, especially now that so many companies are using Macs as their corporate computers.
The conference is called Objective By the Sea, a wordplay on Objective-See, the name of Wardle's suite of free Mac security products (which is itself a wordplay on Apple's main programming language called Objective-C.) It will be held in Maui, Hawaii on November 3 and 4. The conference will be free for residents of Hawaii, and for patrons of Objective-See. That's why Wardle said he can't afford to pay for all speakers to attend, but he had no trouble finding people who wanted to participate. One group that doesn't want to come to Maui, at least for now, is Apple. Wardle said he reached out to the company, essentially offering it carte blanche to talk about whatever it wanted. But the company, so far, has not responded, according to him. -
Scientists Accidentally Blow Up Their Lab With Strongest Indoor Magnetic Field Ever (vice.com)
An anonymous reader quotes a report from Motherboard: Earlier this year, researchers at the University of Tokyo accidentally created the strongest controllable magnetic field in history and blew the doors of their lab in the process. As detailed in a paper recently published in the Review of Scientific Instruments, the researchers produced the magnetic field to test the material properties of a new generator system. They were expecting to reach peak magnetic field intensities of around 700 Teslas, but the machine instead produced a peak of 1,200 Teslas. (For the sake of comparison, a refrigerator magnet has about 0.01 Tesla)
In both the Japanese and Russian experiments, the magnetic fields were generated using a technique called electromagnetic flux-compression. This technique causes a brief spike in the strength of the magnetic field by rapidly "squeezing" it to a smaller size. [...] Instead of using TNT to generate their magnetic field, the Japanese researchers dumped a massive amount of energy -- 3.2 megajoules -- into the generator to cause a weak magnetic field produced by a small coil to rapidly compress at a speed of about 20,000 miles per hour. This involves feeding 4 million amps of current through the generator, which is several thousand times more than a lightning bolt. When this coil is compressed as small as it will go, it bounces back. This produces a powerful shockwave that destroyed the coil and much of the generator. To protect themselves from the shockwave, the Japanese researchers built an iron cage for the generator. However they only built it to withstand about 700 Teslas, so the shockwave from the 1,200 Teslas ended up blowing out the door to the enclosure. While this is the strongest magnetic filed ever generated in a controlled, indoor environment, the strongest magnetic field produced in history belongs to some Russian researchers who created a 2,800 Tesla magnetic field in 2001. -
A 17-Year-Old Has Become Michigan's Leading Right To Repair Advocate (vice.com)
An anonymous reader quotes a report from Motherboard: Surya Raghavendran of Ann Arbor, Michigan isn't your average 17-year-old. Not only does the high school senior run a small business repairing iPhones when he's not in class, but he's raising awareness about people's right to fix their own devices without paying companies like Apple exorbitant fees. "People should be able to choose where they want to get their devices repaired," Raghavendran told me over the phone. "Right to repair will decrease the amount of e-waste and people will retain their devices much longer with suitable repair networks." Raghavendran is doing more than just talking about right to repair, he's become one of the leading advocates for a right to repair law in the state by pushing his lawmakers to introduce legislation that would protect a consumer's right to repair.
Raghavendran started researching the laws around repairing electronics, and he joined up with Environment Michigan -- an environmental activist group -- and started going to Lansing, the state capitol, to ask politicians what they were doing to protect people's right to repair their own devices. Raghavendran sent an email to state senator Rebekah Warren who called him in for a meeting and told him to start a petition. Since July, he's been asking for stories from the public about why the right to repair is important. The right to repair fight is happening all across the country at the local level and Raghavendran's petition has drawn support from people like like Nathan Proctor, the Director of the Campaign for the Right to Repair at US PIRG. Repair.org, a group pushing for right to repair laws all over the country, has draft legislation it wants to get in front of Michigan's state legislature. Proctor has been working with Raghavendran, Environment Michigan, and Michigan legislators to draft right to repair legislation. Proctor wants to pass a right to repair bill that is similar to the one passed in Massachusetts that forced automotive companies to share diagnostic information with third party repair shops. The law passed in 2012 "set a precedent and the industry rolled out the changes nationally," reports Motherboard. -
Space Junk Successfully Captured In Orbit For the First Time (with Video) (surrey.ac.uk)
"The Surrey Space Center successfully used a net to capture a piece of artificial space junk in orbit for the first time in history on Sunday," writes Slashdot reader dmoberhaus. "The video was just released Wednesday and is quite stunning."
"Not only does the net look cool as hell, it's addressing a major problem for the future of space exploration," reports Motherboard: The test was carried about by the RemoveDEBRIS satellite, an experimental space debris removal platform built by an international consortium of space companies and university research centers. There are tens of thousands of pieces of fast-moving space junk in orbit, which range from the centimeter-scale all the way to entire rocket stages. Some of these pieces are moving faster than a bullet and all of them pose a serious danger to other satellites and crewed capsules... Removing this junk from orbit is particularly challenging because of the various sizes of the debris, its erratic tumbling motion, and the fact that some pieces are moving as fast as 30,000 miles per hour.
The successful experiment follows six years of Earth-based testing, according to a professor at the lead research institution, the Surrey Space Centre.
"While it might sound like a simple idea, the complexity of using a net in space to capture a piece of debris took many years of planning, engineering and coordination." -
Did John Deere Just Swindle California's Farmers Out of Their Right to Repair? (wired.com)
An anonymous reader quotes a new Wired opinion piece by Kyle Wiens and Elizabeth Chamberlain from iFixit: A big California farmers' lobbying group just blithely signed away farmers' right to access or modify the source code of any farm equipment software. As an organization representing 2.5 million California agriculture jobs, the California Farm Bureau gave up the right to purchase repair parts without going through a dealer. Farmers can't change engine settings, can't retrofit old equipment with new features, and can't modify their tractors to meet new environmental standards on their own. Worse, the lobbyists are calling it a victory.... John Deere and friends had already made every single "concession" earlier this year...
Just after the California bill was introduced, the farm equipment manufacturers started circulating a flyer titled "Manufacturers and Dealers Support Commonsense Repair Solutions." In that document, they promised to provide manuals, guides, and other information by model year 2021. But the flyer insisted upon a distinction between a right to repair a vehicle and a right to modify software, a distinction that gets murky when software controls all of a tractor's operations. As Jason Koebler of Motherboard reported, that flyer is strikingly similar -- in some cases, identical word-for-word -- to the agreement the Farm Bureau just brokered...
Instead of presenting a unified right-to-repair front, this milquetoast agreement muddies the conversation. More worryingly, it could cement a cultural precedent for electronics manufacturers who want to block third-party repair technicians from accessing a device's software. -
Scientists Find 'Super-Earth' In Star System From 'Star Trek' (vice.com)
In a wonderful example of truth validating fiction, the star system imagined as the location of Vulcan, Spock's home world in Star Trek, has a planet orbiting it in real life. From a report: A team of scientists spotted the exoplanet, which is about twice the size of Earth, as part of the Dharma Planet Survey (DPS), led by University of Florida astronomer Jian Ge. It orbits HD 26965, more popularly known as 40 Eridani, a triple star system 16 light years away from the Sun. Made up of a Sun-scale orange dwarf (Eridani A), a white dwarf (Eridani B), and a red dwarf (Eridani C), this system was selected to be "Vulcan's Sun" after Star Trek creator Gene Roddenberry consulted with astronomers Sallie Baliunas, Robert Donahue, and George Nassiopoulos about the best location for the fictional planet.
"An intelligent civilization could have evolved over the aeons on a planet circling 40 Eridani," Roddenberry and the astronomers suggested in a 1991 letter to the editor published in Sky & Telescope. The three stars "would gleam brilliantly in the Vulcan sky," they added. The real-life exoplanet, known as HD 26965b, is especially tantalizing because it orbits just within the habitable zone of its star, meaning that it is theoretically possible that liquid water -- the key ingredient for life as we know it -- could exist on its surface. -
Cyber Sleuths Find Traces of Infamous iPhone and Android Spyware 'Pegasus' in 45 Countries (zdnet.com)
Security researchers have found evidence that a piece of malware peddled as "lawful intercept" software to government agencies has been deployed against victims located in 45 countries, a number that far outweighs the number of known operators, meaning that some of them are conducting illegal cross-border surveillance. The findings come from a report published by Citizen Lab, a digital rights watchdog at the University of Toronto's Munk School of Global Affairs. ZDNet: The malware, known as Pegasus (or Trident), was created by Israeli cyber-security firm NSO Group and has been around for at least three years -- when it was first detailed in a report over the summer of 2016. The malware can operate on both Android and iOS devices, albeit it's been mostly spotted in campaigns targeting iPhone users primarily. On infected devices, Pegasus is a powerful spyware that can do many things, such as record conversations, steal private messages, exfiltrate photos, and much much more. Citizen Lab's researchers explained how they were able to arrive at the conclusion. They said they identified 1,091 IP addresses that matched their fingerprint for NSO's spyware. Then, they clustered the IP addresses into 36 separate operators with traces in 45 countries where these government agencies "may be conducting surveillance operations" between August 2016 and August 2018. Motherboard adds: Some of the countries where the researchers spotted Pegasus in democratic countries, such as the United States, France, and the UK, but there's also countries with questionable human rights records such as the United Arab Emirates, Bahrain, Mexico, Turkey, and Yemen. There's a caveat though. In some cases, the researchers aren't sure if the traces they found indicate an infection -- thus a target that may have been hacked from a foreign country -- or an operator. [...] "I can only hope that our research is causing these companies to think twice about sales where there is the potential for spyware abuse, causing potential customers to think twice about being associated with a company dealing with repressive governments, and causing potential investors to think twice about the inherently risky business of selling spyware to dictators." The report includes a corroboration of sorts from security firm Lookout, which noted that it had detected "three digits" Pegasus infections around the world. -
Apple Has Started Paying Hackers for iPhone Exploits (vice.com)
Lorenzo Franceschi-Bicchierai, reporting for Motherboard: In 2016, Apple's head of security surprised the attendees of one of the biggest security conference in the world by announcing a bug bounty program for Apple's mobile operating system iOS. At the beginning, Apple struggled to woo researchers and convince them to report high-value bugs. For the researchers, the main issue was that the bugs they discovered were too valuable to report to Apple, despite rewards as high as $200,000. Companies like GrayShift and Azimuth made an entire business out of exploiting vulnerabilities in Apple products, while other researchers didn't want to report bugs so they could keep doing research on iOS. But two years later, some researchers are finally reporting vulnerabilities to Apple, and the company has begun to award some researchers with bounties, Motherboard has learned.
[...] Adam Donefeld, a researcher at mobile security firm Zimperium said that he has submitted several bugs to Apple and received payments for the company. Donefeld was not part of the first batch of security researchers who were personally invited by Apple to visit its Cupertino campus and asked to join the program. But after submitting a few bugs, Donefeld told me, an Apple employee asked him if he wanted to be part of the bounty program in a phone call. "I know Apple pays people," Donefeld said in an online chat. "I'm certainly not the only payout." Another researcher, who asked to remain anonymous because they are worried about souring their relationship with Apple, said that they have submitted a few bugs and been awarded bounties, but has yet to be paid. [...] Two other researchers told Motherboard they also have concerns with or have had trouble with the program. One said they weren't paid for a bug they submitted (Motherboard could not independently confirm that the researcher did not get a payment), and another said they didn't want to participate in it at all, even after being invited. Further reading: Google Bug Hunter Urges Apple To Change Its iOS Security Culture; Asks Tim Cook To Donate $2.45 Million To Amnesty For His Unpaid iPhone Bug Bounties. -
The EU Can Still Be Saved From Its Internet-Wrecking Copyright Plan (vice.com)
An anonymous reader quotes a report from Motherboard: While the European Union voted this week to pass its widely-criticized new Copyright Directive, activists and members of European Parliament say there's still a chance of keeping the EU from fully implementing the worst parts of the troubling proposal. The most controversial aspects of the plan remain twofold: Article 11, which would require EU News outlets to pay a "link tax" just to share anything more than "insubstantial" snippets of published content, and Article 13, which would require that EU member countries implement the kind of automated copyright filters that have been a chaotic mess here in the States. Other problematic measures were passed as well, including Article 12a, which prohibits sports fans from posting their own photos or videos of sporting events online, while stating that only event "organizers" have the right to do so.
That said, all hope is not lost. While some variant of Article 11 and Article 13 is likely be approved next spring, public pressure could force inclusion of additional safeguards for end users, Member of the European Parliament Julia Reda told me in an email. "While the overall bill was adopted with a comfortable majority, the outcome was more narrow for the two controversial articles (366:297 and 393:279)," Reda said. "Since the final vote will be close to the next European elections, that leaves open a small chance that massive public protest against these provisions may still convince MEPs to kill the entire bill." If passed, individual EU countries will be able to interpret the Directive as they see fit, though Reda believes they will likely steer toward stricter interpretation. "The real hope for repeal in my opinion is in the courts," author and activist Cory Doctorow said. "There's simply no way this passes EU Constitutional muster -- it's generalized filtering and mass surveillance by another name. The fact that they claim to be looking for 'infringement' doesn't change that."
Longtime Slashdot reader Lauren Weinstein adds: [...] These articles now enter a period of negotiation with EU member states, and then are subject to final votes next year, probably in the spring. So now's the time for the rest of the world to show Europe some special "tough love" -- to help them understand what their Internet island universe will look like if these terrible articles are ever actually implemented.
UPDATE: The Electronic Frontier Foundation issued a report slamming the proposal, offering a number of ways people can fight back. -
Farmer Lobbying Group Sells Out Farmers, Helps Enshrine John Deere's Tractor Repair Monopoly (vice.com)
Jason Koebler writes: The California Farm Bureau, a group that lobbies on behalf of farmers, reached a "right to repair" agreement with the Equipment Dealers Association (which represents John Deere and other manufacturers) last week. But the specifics of the agreement were written by the manufacturers, and falls far short of providing the types of change that would be needed to make repairing tractors easier. In fact, the agreement makes the same concessions that the Equipment Dealers Association announced in February it would voluntarily give to all farmers. The agreement will not allow farmers to buy repair parts, break firmware DRM, or otherwise alter software for the purposes of repair. -
Farmer Lobbying Group Sells Out Farmers, Helps Enshrine John Deere's Tractor Repair Monopoly (vice.com)
Jason Koebler writes: The California Farm Bureau, a group that lobbies on behalf of farmers, reached a "right to repair" agreement with the Equipment Dealers Association (which represents John Deere and other manufacturers) last week. But the specifics of the agreement were written by the manufacturers, and falls far short of providing the types of change that would be needed to make repairing tractors easier. In fact, the agreement makes the same concessions that the Equipment Dealers Association announced in February it would voluntarily give to all farmers. The agreement will not allow farmers to buy repair parts, break firmware DRM, or otherwise alter software for the purposes of repair. -
The EU Could Vote To Wreck the Internet Tomorrow (vice.com)
The EU is preparing to vote Wednesday on sweeping new copyright guidelines that could dramatically reshape the internet and potentially harm your ability to share content online. From a report: As noted previously, the proposal is being driven by rights holders frightened by technological change, including brick and mortar publishers eager to blame companies like Google for their failure to evolve in the modern internet era. And while the EU's new Copyright Directive may be a well intentioned effort to modernize EU copyright rules, it still contains numerous provisions that could significantly harm the open internet. Most of those provisions remain largely intact despite a July vote that sent the proposal back to the drawing board in the wake of widespread activist backlash. The most problematic provisions of the plan include new licensing fees for sharing anything more than "insubstantial" portions of content. Such a "link tax" could prove costly for small news outlets, and, depending on final wording, could put volunteer-centric organizations like Wikipedia at risk since the original proposal failed to include a noncommercial exception.
The most controversial component of the plan mandates that any website that lets users upload text, sounds, images, code, or other copyrighted works for public consumption (read: most of them) would need to employ automated copyright systems that filter these submissions against a database of copyrighted works at the website owner's expense. As we've consistently highlighted, such filters routinely don't work very well. -
Creator of TempleOS, Terry Davis, Has Passed Away (osnews.com)
OSNews reports: Terrence Andrew Davis, sole creator and developer of TempleOS (née LoseThos), has passed away at age 48. Davis suffered from mental illness -- schizophrenia -- which had a severe impact on his life. He claimed he created his operating system after having spoken with and receiving instructions from god, and he was a controversial figure, also here on OSNews, for his incomprehensible rants and abrasive style towards OSNews readers and staff. We eventually had to ban him, but our then-editor Kroc Kamen worked with him in 2010 to publish an article about his operating system despite his ban.... I hope he found peace -- wherever he may be.
Davis spent 10 years building "an operating system to talk to God," according to a 2014 profile in Motherboard, which described its welcome screen as "a riot of 16-color, scrolling, blinking text" resembling early DOS-based GUIs. (Wikipedia describes its interface as "a mixture of DOS and Turbo C.") To build his operating system, Terry wrote 121,176 lines of code.
An anonymous reader writes: Davis learned assembly language on a Commodore 64 before he'd graduated from high school. He eventually got a master's degree in electrical engineering from Arizona State University, and as an undergrad he worked briefly at Ticketmaster, programming operating systems. His later life included time in mental hospitals and some homelessness, as well as living at home with his parents after his schizophrenia was diagnosed and treated.
In 2014 Motherboard pieced together his lifestyle from emailed updates Terry sent from his Ubuntu desktop. They concluded he was living on disability, and spent most of his time coding, surfing the web, "or using the output from the National Institute of Standards and Technology randomness beacon to talk to God -- he posts the results on his webpage as 'Terry Davis' Rants.'" Their article describes him as "God's lonely programmer," saying Davis "offered the world a temple to a God who speaks only to him, and is still waiting for everyone else to listen."
Terry's death was confirmed by a local Oregon newspaper, and the official web site for TempleOS now also includes this death notice:
In the wake of Terry A. Davis' passing his family has requested supporters of his donate to "organizations working to ease the pain and suffering caused by mental illness" such as -
Valve Explains How It Decides Who's a 'Straight Up Troll' Publishing Video Games On Steam (vice.com)
An anonymous reader quotes a report from Motherboard: Wednesday, Valve, the company that operates the huge online video game store Steam, shared more details about how it plans to control and moderate the ever-increasing number of games published on its platform. In the post published Wednesday, Valve shared more details about how it determines what it considers "outright trolling." "It is vague and we'll tell you why," Valve wrote. "You're a denizen of the internet so you know that trolls come in all forms. On Steam, some are simply trying to rile people up with something we call 'a game shaped object' (ie: a crudely made piece of software that technically and just barely passes our bar as a functioning video game but isn't what 99.9% of folks would say is "good.")
Valve goes on to explain that some trolls are trying to scam folks out of their Steam inventory items (digital items that can be traded for real money), while others are trying to generate a small amount of money through a variety of schemes that have to do with how developers use keys to unlock Steam games, while others are trying to "incite and sow discord." "Trolls are figuring out new ways to be loathsome as we write this," Valve said. "But the thing these folks have in common is that they aren't actually interested in good faith efforts to make and sell games to you or anyone. When a developer's motives aren't that, they're probably a troll." One interesting observation Valve shares in the blog post is that it rarely bans individual games from Steam, and more often bans developers and/or publishers entirely. [...] Valve said that its review process for determining that something may be a "troll game" is a "deep assessment" that involves investigating who the developer is, what they've done in the past, their behavior on Steam as a developer, as a customer, their banking information, developers they associate with, and more. -
Researchers Used Sonar Signal From a Smartphone Speaker To Steal Unlock Passwords (vice.com)
An anonymous reader quotes a report from Motherboard: On Thursday, a group of researchers from Lancaster University posted a paper to arXiv that demonstrates how they used a smartphone's microphone and speaker system to steal the device's unlock pattern. Although the average person doesn't have to worry about getting hacked this way any time soon, the researchers are the first to demonstrate that this kind of attack is even possible. According to the researchers, their "SonarSnoop" attack decreases the number of unlock patterns an attacker must try by 70 percent and can be performed without the victim ever knowing they're being hacked. The attack begins when a user unwittingly installs a malicious application on their phone. When a user downloads the infected app, their phone begins broadcasting a sound signal that is just above the human range of hearing. This sound signal is reflected by every object around the phone, creating an echo. This echo is then recorded by the phone's microphone. By calculating the time between the emission of the sound and the return of its echo to the source, it is possible to determine the location of an object in a given space and whether that object is moving -- this is known as sonar.
The researchers were able to leverage this phenomenon to track the movement of someone's finger across a smartphone screen by analyzing the echoes recorded through the device's microphone. There are nearly 400,000 possible unlock patterns on the 3x3 swipe grid on Android phones, but prior research has demonstrated that 20 percent of people use one of 12 common patterns. While testing SonarSnoop, the researchers only focused on these dozen unlock combinations. Ten volunteers were recruited for the study and were asked to draw each of the 12 patterns five different times on a custom app. The researchers then tried a variety of sonar analysis techniques to reconstruct the password based on the acoustic signatures emitted by the phone. The best analysis technique resulted in the algorithm only having to try 3.6 out of the 12 possible patterns on average before it correctly determined the pattern. -
Google Has Notified At Least Dozens of People Targeted by Secret FBI Investigation (vice.com)
At least dozens of people have received an email from Google informing them that the internet giant responded to a request from the FBI demanding the release of user data, news outlet Motherboard reported Tuesday, citing several people who claimed to have received the email. The email did not specify whether Google released the requested data to the FBI. From the report: The unusual notice appears to be related to the case of Colton Grubbs, one of the creators of LuminosityLink, a $40 remote access tool (or RAT), that was marketed to hack and control computers remotely. Grubs pleaded guilty last year to creating and distributing the hacking tool to hundreds of people. Several people on Reddit, Twitter, and on HackForums, a popular forum where criminals and cybersecurity enthusiast discuss and sometimes share hacking tools, reported receiving the email. [...] The email included a legal process number. When Motherboard searched for it within PACER, the US government's database for court cases documents, it showed that it was part of a case that's still under seal. -
Open Source Devs Reverse Decision to Block ICE Contractors From Using Software (vice.com)
An anonymous reader quotes Motherboard: Less than 24 hours after a software developer revoked access to Lerna, a popular open-source software management program, for any organization that contracted with U.S. immigrations and Customs Enforcement, access has been restored for any organization that wishes to use it and the developer has been removed from the project... The modified version specifically banned 16 organizations, including Microsoft, Palantir, Amazon, Northeastern University, Johns Hopkins University, Dell, Xerox, LinkedIn, and UPS... Although open-source developer Jamie Kyle acknowledged that it's "part of the deal" that anyone "can use open source for evil," he told me he couldn't stand to see the software he helped develop get used by companies contracting with ICE.
Kyle's modification of Lerna's license was originally assented to by other lead developers on the project, but the decision polarized the open-source community. Some applauded his principled stand against ICE's human rights violations, while others condemned his violation of the spirit of open-source software. Eric Raymond, the founder of the Open Source Initiative and one of the authors of the standard-bearing Open Source Definition, said Kyle's decision violated the fifth clause of the definition, which prohibits discrimination against people or groups. "Lerna has defected from the open-source community and should be shunned by anyone who values the health of that community," Raymond wrote in a blog post on his website.
The core contributor who eventually removed Kyle also apologized for Kyle's licensing change, calling it a "rash decision" (which was also "unenforceable.")
Eric Raymond had called the decision "destructive of one of the deep norms that keeps the open source community functional -- keeping politics separated from our work." -
Open Source Devs Reverse Decision to Block ICE Contractors From Using Software (vice.com)
An anonymous reader quotes Motherboard: Less than 24 hours after a software developer revoked access to Lerna, a popular open-source software management program, for any organization that contracted with U.S. immigrations and Customs Enforcement, access has been restored for any organization that wishes to use it and the developer has been removed from the project... The modified version specifically banned 16 organizations, including Microsoft, Palantir, Amazon, Northeastern University, Johns Hopkins University, Dell, Xerox, LinkedIn, and UPS... Although open-source developer Jamie Kyle acknowledged that it's "part of the deal" that anyone "can use open source for evil," he told me he couldn't stand to see the software he helped develop get used by companies contracting with ICE.
Kyle's modification of Lerna's license was originally assented to by other lead developers on the project, but the decision polarized the open-source community. Some applauded his principled stand against ICE's human rights violations, while others condemned his violation of the spirit of open-source software. Eric Raymond, the founder of the Open Source Initiative and one of the authors of the standard-bearing Open Source Definition, said Kyle's decision violated the fifth clause of the definition, which prohibits discrimination against people or groups. "Lerna has defected from the open-source community and should be shunned by anyone who values the health of that community," Raymond wrote in a blog post on his website.
The core contributor who eventually removed Kyle also apologized for Kyle's licensing change, calling it a "rash decision" (which was also "unenforceable.")
Eric Raymond had called the decision "destructive of one of the deep norms that keeps the open source community functional -- keeping politics separated from our work." -
Justice Department Warns It Might Not Be Able To Prosecute Voting Machine Hackers (vice.com)
An anonymous reader quotes a report from Motherboard: After more than a decade of headlines about the vulnerability of U.S. voting machines to hacking, it turns out the federal government says it may not be able to prosecute election hacking under the federal law that currently governs computer intrusions. Per a Justice Department report issued in July from the Attorney General's Cyber Digital Task Force, electronic voting machines may not qualify as "protected computers" under the Computer Fraud and Abuse Act, the 1986 law that prohibits unauthorized access to protected computers and networks or access that exceeds authorization (such as an insider breach).
The report says the law generally only prohibits against hacking computers "that are connected to the Internet (or that meet other narrow criteria for protection)" and notes that voting machines generally do not meet this criteria "as they are typically kept off the Internet." Consequently, "should hacking of a voting machine occur, the government would not, in many conceivable circumstances, be able to use the CFAA to prosecute the hackers." Aside from the fact that the assertion about voting machines not being connected is incorrect -- many voting machines are connected in that they use cellular and landline modems that connect with cell towers and backend telecom networks to transmit results on election night -- the government's assertion that the CFAA applies only to connected machines is news to legal experts. -
The 'Scunthorpe Problem' Has Never Really Been Solved (vice.com)
dmoberhaus writes: Yesterday, a writer for SB Nation named Natalie Weiner posted a screenshot of a rejection form she received when she tried to sign up for a website. Her submission was rejected because a spam algorithm considered her last name "offensive." After she posted about this, hundreds of other people with similarly "offensive" last names sounded off about how they had experienced similar issues. As it turns out, this phenomenon is so widespread that it has a name among computer scientists. It's called the Scunthorpe problem and it's been a scourge of the internet since the beginning. Motherboard spoke to content moderation experts about its origins and why it's such a hard problem to solve 20 years later. A big reason why the problem has yet to be solved is "because creating effective obscenity filters depends on the filter's ability to understand a word in context," reports Motherboard. "Despite advances in [AI], this is something that even the most advanced machine-learning algorithms still struggle with today."
"This works both ways around," Michael Veale, a researcher studying responsible machine learning at University College London, told Motherboard. "Cock (a bird) and Dick (the given name) are both harmless in certain contexts, even in children's settings online, but in other cases parents might not want them used. Equally, those wanting to abuse a system can find ways around it." -
Big Telecom Is Using Robocalls To Fight a Net Neutrality Bill in California (vice.com)
A group with financial ties to AT&T is sending automated messages claiming the law would raise cell phone bills. From a report: Big Telecom is once again trying to disrupt a net neutrality bill in California, this time by robocalling seniors to spread misinformation about the bill. "Your Assembly member will be voting on a proposal by San Francisco politicians that could increase your cellphone bill by $30 a month and slow down your data," says a voice on an automated call paid for by legal reform group the Civil Justice Association of California (CJAC). "We can't afford higher cell phone bills. We can't afford slower data. We can't afford Senate Bill 822 (more popularly known as SB822)."
The call urges constituents to contact their state representative and ask them to vote no on the bill, which passed a senate committee last week and will be heard in the Assembly this week. It even provides an option to automatically connect to the recipients' Assembly member. At the top of the call, it cites the non-profit Congress of California Seniors, leading many -- including state senator Scott Wiener, the net neutrality bill's author -- to believe the calls are targeting senior citizens specifically. "The industry has engaged in a massive misinformation campaign around this bill for months," Wiener told me over the phone.
But the claim that cell phone bills will go up is not based on anything in the actual bill, which would simply restore the federal rules that telecom companies operated under from 2015 until the 2017 repeal, which only went into effect a few months ago. -
Scientists Warn the UN of Capitalism's Imminent Demise (vice.com)
Capitalism as we know it is over, an anonymous reader writes. So suggests a new report commissioned by a group of scientists appointed by the UN Secretary-General. From a report: The main reason? We're transitioning rapidly to a radically different global economy, due to our increasingly unsustainable exploitation of the planet's environmental resources. Climate change and species extinctions are accelerating even as societies are experiencing rising inequality, unemployment, slow economic growth, rising debt levels, and impotent governments. Contrary to the way policymakers usually think about these problems, the new report says that these are not really separate crises at all. Rather, these crises are part of the same fundamental transition to a new era characterized by inefficient fossil fuel production and the escalating costs of climate change. Conventional capitalist economic thinking can no longer explain, predict, or solve the workings of the global economy in this new age, the paper says [PDF]. -
Hackers Stole Personal Data of 2 Million T-Mobile Customers (vice.com)
On late Thursday, T-Mobile revealed that hackers stole some of the personal data of 2 million people in a new data breach. From a report: In a brief intrusion, hackers stole "some" customer data including names, email addresses, account numbers, and other billing information. The good news is that they did not get credit card numbers, social security numbers, or passwords, according to the company. In its announcement, T-Mobile said that its cybersecurity team detected an "unauthorized capture of some information" on Monday, Aug. 20. A company spokesperson told me that the breach affected "about" or "slightly less than" 3% of its 77 million customers. -
Spyware Company Leaves 'Terabytes' of Selfies, Text Messages, and Location Data (vice.com)
An anonymous reader writes: Spyfone, a company that sells surveillance software to parents and employers left 'terabytes of data' including photos, audio recordings, text messages and web history, exposed in a poorly-protected Amazon S3 bucket. News outlet Motherboard verified that the researcher could access anyone's data by creating a free account and installing the spyware on a test device. After a few hours, the researcher sent me back a picture I took. -
It's Time to End the 'Data Is' vs 'Data Are' Debate (vice.com)
dmoberhaus writes: After receiving too many irate emails about using "data" in the singular, a reporter spoke to two lexicographers about how the language changes over time and why it's perfectly acceptable and perhaps even "standard" to use data as a singular noun, rather than a plural noun in an attempt to settle an old debate. Peter Sokolowski, a lexicographer for the Merriam-Webster Dictionary, told the reporter that data's transition between its historical roots and contemporary use is related to a lexical phenomenon called "semantic bleaching," where a word's original meaning is lost or diminished over time. An example of semantic bleaching include the contemporary use of the word "literally," whose Latin root, littera, means "letter." In the case of "data," it has transitioned from "things given" to mean something like "a collection of information in aggregate" when used in everyday speech. -
It's Time to End the 'Data Is' vs 'Data Are' Debate (vice.com)
dmoberhaus writes: After receiving too many irate emails about using "data" in the singular, a reporter spoke to two lexicographers about how the language changes over time and why it's perfectly acceptable and perhaps even "standard" to use data as a singular noun, rather than a plural noun in an attempt to settle an old debate. Peter Sokolowski, a lexicographer for the Merriam-Webster Dictionary, told the reporter that data's transition between its historical roots and contemporary use is related to a lexical phenomenon called "semantic bleaching," where a word's original meaning is lost or diminished over time. An example of semantic bleaching include the contemporary use of the word "literally," whose Latin root, littera, means "letter." In the case of "data," it has transitioned from "things given" to mean something like "a collection of information in aggregate" when used in everyday speech. -
OpenAI Is Beating Humans At 'Dota 2' Because It's Basically Cheating (vice.com)
Motherboard's Matthew Gault provides another possibility for how OpenAI's bots managed to beat professional human players in two consecutive games of Data 2. Gault argues that "it was only possible thanks to significant guardrails and an inhuman advantage" -- not necessarily because the AI was more clever than the humans. From the report: The OpenAI Five bots consisted of algorithms known as neural networks, which loosely mimic the brain and "learn" to complete tasks after a process of training and feedback. The research company put its Dota 2-playing AI through 180 days worth of virtual training to prepare it for the match, and it showed. However, the bots had to play within some highly specific limitations. Dota 2 is a complicated game with more than 100 heroes. Some of them use quirky and game-changing abilities. For this exhibition, the hero pool was limited to just 18. That's an incredible handicap because so much of Dota 2 involves a team picking the proper group composition and reacting to what its opponents pick. Reducing the number of champions from more than 100 to 18 made things much simpler for the AI.
The OpenAI Five bots also played Dota 2 by reading the game's information directly from its application programming interface (API), which allows other programs to easily interface with Dota 2. This gives the AI instant knowledge about the game, whereas human players have to visually interpret a screen. If a human was able to do this in a competitive match against other humans, we'd probably call it cheating. Even with this AI advantage, Walsh and his team beat the bots in the third game, when the match organizers turned hero selection over to the crowd, which gave the AI a weak hero composition. Walsh thinks he and his team could eventually beat the AI in a fair right, even given the limited hero pool and other restrictions. -
The Psychedelic Drug DMT Can Simulate a Near-Death Experience, Study Suggests (vice.com)
dmoberhaus writes: In the first study of its kind, [published this week in the journal Frontiers in Psychology,] researchers dosed 13 people with the potent psychedelic dimethyltryptamine (DMT) to investigate its similarity to near-death experiences. As the researchers found, DMT does in fact induce experiences that are qualitatively similar to NDEs, [but the intensity of these NDEs largely depend on context]. Motherboard spoke with an independent researcher who pioneered DMT research in the 90s to discuss the possible implications of this research. While tricky to define due to their subjective nature, "NDEs tend to share many common elements, such as feelings of inner peace, the experience of traveling through a tunnel, out of body experiences, and encounters with sentient beings," reports Motherboard. A psychiatrist not involved with the study "suggested that the overlap between DMT and NDEs could possibly be explained on a biological level since DMT is naturally produced in small quantities by the human body and has been shown to minimize neuronal damage due to hypoxia (insufficient oxygen) in test tubes," reports Motherboard. "Thus, [the psychiatrist said] 'one could construct a coherent scenario where endogenous DMT rises in response to cardiac arrest/hypoxia in order to protect the brain as long as possible.'" -
A Paper Posted Last Month Claims To Have Achieved Superconductivity at Room Temperature, But Other Physicists Say the Data May Be Incorrect (vice.com)
dmoberhaus writes: Last month, two Indian physicists posted a paper to arxiv claiming to have demonstrated superconductivity at room temperature. If this paper is legitimate, it would represent a breakthrough in a problem that has existed for superconductivity for 100 years. Understandably, the paper shook the physics world, but when researchers started digging into the data they noticed something wasn't quite right -- the noise patterns in two independent measurements exactly correlated, which is basically impossible in a random system. The Indian researchers have doubled down on their data, and things only got weirder from there. This is a look inside what could be the biggest drama to happen in physics in nearly a decade. -
A Look at Facebook's Presence in Myanmar Where Despite Public Outcries, Facebook is Still Struggling To Contain Hate Speech (reuters.com)
More than 1,000 anti-Rohingya posts featuring calls for their murder among other hate speech were live on Facebook last week, Reuters reported Wednesday. A probe by the news agency indicates that the network is still being used to encourage violence against the Muslim group in Myanmar despite the tech firm promising to tackle the issue. Reuters reports some of the material had been online for six years. Facebook's rules prohibit "violent or dehumanizing" attacks on ethnic groups. However, the US-based firm mostly relies on users to flag related offending posts rather than hunting them out itself, in part because its software has not had enough training to reliably interpret Burmese text.
Vice reports that Facebook has hired an outside company to look into its role in spreading hate speech and enabling ethnic cleansing in Myanmar. -
A Community-Run ISP Is the Highest Rated Broadband Company In America (vice.com)
An anonymous reader quotes a report from Motherboard: A new survey by Consumer Reports once again highlights how consumers are responding positively to [community-run broadband networks]. The organization surveyed 176,000 Consumer Reports readers on their experience with their pay TV and broadband providers, and found that the lion's share of Americans remain completely disgusted with most large, incumbent operators. The full ratings are paywalled but available here to those with a Consumer Reports subscription. All the usual suspects including Comcast, Charter (Spectrum), AT&T, Verizon, and Optimum once again fell toward the bottom of the barrel in terms of overall satisfaction, reliability, and value, largely mirroring similar studies from the American Customer Satisfaction Index.
One of the lone bright spots for broadband providers was Chattanooga's EPB, a city-owned and utility operated broadband provider we profiled several years back as an example of community broadband done well. The outfit, which Comcast attempted unsuccessfully to sue into oblivion, was the only ISP included in the study that received positive ratings for value. "EPB was the top internet service provider in our telecom ratings two times in the past three years," Christopher Raymond, electronics editor at Consumer Reports told Motherboard. "Consumer Reports members have given it high marks for not only reliability and speed, but also overall value -- and that's a rare distinction in an arena dominated by the major cable companies," he said. -
A Community-Run ISP Is the Highest Rated Broadband Company In America (vice.com)
An anonymous reader quotes a report from Motherboard: A new survey by Consumer Reports once again highlights how consumers are responding positively to [community-run broadband networks]. The organization surveyed 176,000 Consumer Reports readers on their experience with their pay TV and broadband providers, and found that the lion's share of Americans remain completely disgusted with most large, incumbent operators. The full ratings are paywalled but available here to those with a Consumer Reports subscription. All the usual suspects including Comcast, Charter (Spectrum), AT&T, Verizon, and Optimum once again fell toward the bottom of the barrel in terms of overall satisfaction, reliability, and value, largely mirroring similar studies from the American Customer Satisfaction Index.
One of the lone bright spots for broadband providers was Chattanooga's EPB, a city-owned and utility operated broadband provider we profiled several years back as an example of community broadband done well. The outfit, which Comcast attempted unsuccessfully to sue into oblivion, was the only ISP included in the study that received positive ratings for value. "EPB was the top internet service provider in our telecom ratings two times in the past three years," Christopher Raymond, electronics editor at Consumer Reports told Motherboard. "Consumer Reports members have given it high marks for not only reliability and speed, but also overall value -- and that's a rare distinction in an arena dominated by the major cable companies," he said. -
Putting Stickers On Your Laptop is Probably a Bad Security Idea (vice.com)
From border crossings to hacking conferences, that Bitcoin or political sticker may be worth leaving on a case at home. From a report: Plenty of hackers, journalists, and technologists love to cover their laptop in all manner of stickers. Maybe one shows off their employer, another flaunts that local cryptoparty they attended, or others may display the laptop owner's interest in Bitcoin. That's all well and good, but a laptop lid full of stickers also arguably provides something of a red flag to authorities or hackers who may want to access sensitive information stored on that computer, or otherwise cause the owner hassle.
"Conferences, border crossing[s], airports, public places -- stickers will/can get you targeted for opposition research, industrial espionage, legal or investigative scrutiny," Matt Mitchell, director of digital safety and privacy for technology and activism group Tactical Tech, told Motherboard in an online chat. Mitchell said political stickers, for instance, can land you in secondary search or result in being detained while crossing a border. In one case, Mitchell said a hacker friend ended up missing a flight over stickers. -
Hundreds of Researchers From Harvard, Yale and Stanford Were Published in Fake Academic Journals (vice.com)
In the so-called "post-truth era," science seems like one of the last bastions of objective knowledge, but what if science itself were to succumb to fake news? From a report: Over the past year, German journalist Svea Eckert and a small team of journalists went undercover to investigate a massive underground network of fake science journals and conferences. In the course of the investigation, which was chronicled in the documentary "Inside the Fake Science Factory," the team analyzed over 175,000 articles published in predatory journals and found hundreds of papers from academics at leading institutions, as well as substantial amounts of research pushed by pharmaceutical corporations, tobacco companies, and others. Last year, one fake science institution run by a Turkish family was estimated to have earned over $4 million in revenue through conferences and journals.
Eckert's story begins with the World Academy of Science, Engineering and Technology (WASET), an organization based in Turkey. At first glance, WASET seems to be a legitimate organization. Its website lists thousands of conferences around the world in pretty much every conceivable academic discipline, with dates scheduled all the way out to 2031. It has also published over ten thousand papers in an "open science, peer reviewed, interdisciplinary, monthly and fully referred [sic] international research journal" that covers everything from aerospace engineering to nutrition. To any scientist familiar with the peer review process, however, WASET's site has a number of red flags, such as spelling errors and the sheer scope of the disciplines it publishes. -
Watch Fish Swim By Petabytes of Data At Microsoft's Underwater Data Center (vice.com)
An anonymous reader quotes a report fro Motherboard: In June, Microsoft announced that it had placed a self-sufficient, waterproof data center off the coast of the Orkney Islands in Scotland. The data center, loaded with 864 servers capable of handling 27.6 petabytes of data, represented the culmination of nearly four years of research and development on the project, codenamed Natick. The underwater data center is the first of its kind. It's a proof of concept that aims to cut down on one of the biggest costs of running a data center on land -- cooling -- and can be rapidly deployed anywhere in the world. Due to the experimental nature of the project, however, Microsoft needed to keep a close eye on its pilot project. In order to monitor the environmental conditions around the tank, it placed two cameras nearby that livestream from the bottom of the ocean 24/7. -
Nintendo's Offensive, Tragic, and Totally Legal Erasure of ROM Sites (vice.com)
"The damage that removing ROMs from the internet could do to video games as a whole is catastrophic." From a report: In July, Nintendo sued two popular ROM sites, LoveROMS and LoveRetro.co, for what it called "brazen and mass-scale infringement of Nintendo's intellectual property rights." Both sites have since shut down. On Wednesday, another big, 18-year-old ROM site, EmuParadise, said it would no longer be able to allow people to download old games due to "potentially disastrous consequences." Nintendo owns the intellectual property for its games, and when people pirate them instead of buying a Nintendo Super NES Classic Edition or a downloading a copy from one of its digital storefronts, it can argue it's losing money. According to Nintendo's official site, ROMs and video game emulation also represent "the greatest threat to date to the intellectual property rights of video game developers," and "have the potential to significantly damage" tens of thousands of jobs. Even when a Nintendo game isn't for sale, it's still the company's intellectual property, and it can enforce its copyright if it wants.
But the damage that removing ROMs from the internet could do to video games as a whole is catastrophic. Many game developers and people who have otherwise made video games a major part of their lives, especially those who grew up in low-income households or outside a Western country, wouldn't have been inspired to take that path if it wasn't for ROMs. Entire chapters of video game history would be lost if ROMs and emulation didn't preserve games where publishers failed to. And perhaps most importantly, denying people access to ROMs makes the process of educating them in game development much more difficult, potentially hobbling future generations of video game makers. -
'It's Time to End the Yearly Smartphone Launch Event' (vice.com)
Owen Williams, writing for Motherboard: Thursday, at a flashy event in New York, Samsung unveiled yet another phone: the Galaxy Note 9. Like you'd expect, it's rectangular, it has a screen, and it has a few cameras. While unveiling what it hopes will be the next hit, it unknowingly confirmed something we've all been wondering: the smartphone industry is out of ideas. Phones are officially boring: the only topic that's up for debate with the Galaxy Note 9 is the lack of the iconic notch found on the iPhone X, and that it has a headphone jack. The notch has been cloned by almost every phone maker out there, and the headphone jack is a commodity that's unfortunately dying. However, the fact that we're comparing phones with or without a chunk out of the screen or a hole for your headphones demonstrates just how stuck the industry is.
It's clear that there's nothing really to see here. Yeah, the Note is a big phone, and it has a larger battery too. It's in different colors, it's faster than last year, and it has wireless charging. Everything you see here is from a laundry list of features that other smartphone manufacturers also have, and the lack of differentiation becomes clearer every year. It's the pinnacle of technology, and it's a snooze-fest. This isn't exclusively a Samsung problem: Every manufacturer from Apple to Xiaomi faces the same predicament. The iPhone's release cycle that Apple trained the world to be accustomed to, with splashy yearly releases and million-dollar keynotes, is clearly coming to an end as consumers use their existing phones for longer every year. -
Scientists Claim To Have Solved the Mystery of the Bermuda Triangle (vice.com)
Slashdot reader MyrddinBach shares a report that claims the mystery of the Bermuda Triangle has been solved. The Bermuda Triangle is a loosely-defined region of water between the southernmost tip of Florida, Puerto Rico, and the island of Bermuda to the north. British oceanographers now believe that "rogue waves" are responsible for the disappearance of a number of ships in the region. VICE News reports: So what are rogue waves? Basically, they're abnormally large and unexpected waves in open sea. Dr Simon Boxall, an Oceanographer from the University of Southampton who led the new study, explained on a Channel 5 documentary The Bermuda Triangle Enigma: "there are storms to the South and North, which come together... we've measured waves in excess of 30 meters. The bigger the boat gets, the more damage is done." His team re-created the intense surges of the 30 meter waves by using indoor simulators. Then to see what such a wave would do to a large ship, they built a model of the USS Cyclops, a carrier that went missing in the Bermuda Triangle in 1918 and claimed the lives of 309 people. -
Google Bug Hunter Urges Apple To Change Its iOS Security Culture; Asks Tim Cook To Donate $2.45 Million To Amnesty For His Unpaid iPhone Bug Bounties (threatpost.com)
secwatcher writes: Prolific Google bug hunter Ian Beer ripped into Apple on Wednesday, urging the iPhone maker to change its culture when it comes to iOS security. The Verge: "Their focus is on the design of the system and not on exploitation. Please, we need to stop just spot-fixing bugs and learn from them, and act on that," he told a packed audience. Per Beer, Apple researchers are not trying to find the root cause of the problems. "Why is this bug here? How is it being used? How did we miss it earlier? What process problems need to be addressed so we could [have] found it earlier? Who had access to this code and reviewed it and why, for whatever reason, didn't they report it?" He said the company suffers from an all-too-common affliction of patching an iOS bug, but not fixing the systemic roots that contribute to the vulnerability. In a provocative call to Apple's CEO Tim Cook, Beer directly challenged him to donate $2.45 million to Amnesty International -- roughly the equivalence of bug bounty earnings for Beer's 30-plus discovered iOS vulnerabilities.