Skip to main content
Home
www.herd-of-neurons.com
No more neurons? Use mine

Main navigation

  • Home
  • Cortex
  • Aggregator
User account menu
  • Log in

Breadcrumb

  1. Home
  2. Aggregator
  3. Sources

Slashdot

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses

Slashdot
1 hour 18 minutes ago
Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay. [...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal. "Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.

Read more of this story at Slashdot.

BeauHD

Lawmaker Who Wants Data Center Pause Wins Kansas Democratic Primary

Slashdot
2 hours 18 minutes ago
Kansas Democrats nominated State Senator Cindy Holscher for governor after she defeated party-backed rival Ethan Corson. "The race became a test of what sort of candidate Democratic voters prefer in what is expected to be a challenging general election race: a more moderate candidate like Mr. Corson with endorsements from party leaders or an outspoken populist like Ms. Holscher, who spoke out against data centers and the political establishment," reports The New York Times. From the repot: Even in a national political environment that could favor Democrats, Republicans see the Kansas governorship as among their best opportunities for flipping a seat. President Trump carried Kansas by 16 percentage points in 2024, and Republicans hold supermajorities in the State Legislature. Voters in the Republican primary for governor nominated Ty Masterson, the president of the Kansas Senate and the recipient of Mr. Trump's endorsement, according to The A.P. Ms. Holscher, who is from suburban Kansas City, sought out a lane to Mr. Corson's political left and made inroads with some of the state's progressive voters. She emphasized her role in unwinding former Gov. Sam Brownback's tax policies and called for a moratorium on data centers. She also spoke against a final deal to lure the Kansas City Chiefs across the state line from Missouri. Ms. Holscher presented an implicit critique of Ms. Kelly's stewardship of Kansas, referring to Mr. Corson as part of a political establishment that was too cozy with corporations and out of touch with the party's voters. "I'm the only Democrat in this race to call for a moratorium on data centers because we have to get these guardrails in place," said Holscher in an interview. "We are having our people and our resources exploited."

Read more of this story at Slashdot.

BeauHD

Google Overhauls AI Leadership As DeepMind CEO Steps Aside

Slashdot
3 hours 18 minutes ago
Google is reshuffling its AI leadership as Demis Hassabis steps away from day-to-day management of DeepMind to become chairman and Alphabet's chief scientist, while CTO Koray Kavukcuoglu takes operational control. Meanwhile, longtime chief scientist Jeff Dean and several prominent researchers are leaving to launch their own company. Axios reports: Hassabis will add the title of chief scientist for Google parent company Alphabet and also continue to lead Isomorphic Labs, the company's AI drug discovery spinoff. Koray Kavukcuoglu, the current chief technology officer of Google DeepMind will serve as senior VP of the unit, reporting to CEO Sundar Pichai. Dean, a 27-year Google veteran is starting Discovery Loop, an independent publicity benefit corporation in which Google will be an investor and cloud provider. Joining him in that effort are Google senior fellow Sanjay Ghemawat as well as Oriol Vinyals, a DeepMind VP and Quoc Le, a Google Brain co-founder. [...] In an interview with The New York Times, Dean indicated that leaving Google, a public company, gives him more leeway to focus on scientific discoveries associated with AI as well. "We might make decisions that are not necessarily in the company's purist financial interests," he told NYT. "I've been working towards AGI my whole life and now, like many of you, I feel it is close at hand," Hassabis wrote. "It's critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder." "With this backdrop, I've decided that now is the right time for me to hand over my day-to-day operational responsibilities at GDM, so that I have the time and space to focus on the big picture and help influence what is to come to the best of my ability"

Read more of this story at Slashdot.

BeauHD

Cloudflare Announces Open-Source Cloudflare OS As AI 'Operating System'

Slashdot
4 hours 18 minutes ago
Cloudflare has open-sourced Cloudflare OS, an Apache 2.0-licensed platform that lets organizations build AI agents, apps, and workflows using curated company data and tools within isolated, governed environments. Despite the name, it is not a traditional operating system but a framework for securely managing organizational AI workloads. Phoronix reports: Cloudflare OS is already used internally at Cloudflare and is described in today's announcement as: "Cloudflare OS starts with a conversation in your browser, like many other AI tools. What makes it different is that each conversation is grounded in the context and skills your organization has curated. Give your workspace a goal, and it can draw on that knowledge and work with the tools and data your organization already uses to achieve it. Cloudflare OS combines three parts: - An agent workspace grounded in context and skills your company curates, with an isolated runtime where agents can write and run code. - A new security and governance framework for safe access to internal data and services. - A platform for personal, modifiable apps that people can build, share, and continue changing. What begins as a conversation can become a doc, an app, or a workflow that continues doing the work." You can learn more at os.cloudflare.app.

Read more of this story at Slashdot.

BeauHD

The Days of Walking Into a T-Mobile Store May Be Numbered

Slashdot
5 hours 18 minutes ago
A leaked roadmap suggests T-Mobile plans to make its T-Life app the primary way customers manage their accounts by the end of 2026, "gradually moving one feature at a time into the app" and away from physical stores, reports Android Authority. That includes upgrades, new-line activations, and eventually new-account sign-ups. From the report: According to an image shared by a Reddit user, the carrier has mapped out the next phase of its app-first strategy. This clearly shows that the T-Life app is set to become the primary way customers manage nearly every aspect of their account by the end of 2026. The roadmap suggests T-Mobile isn't flipping the switch overnight. Instead, it's gradually moving one feature at a time into the app. The concierge experience has already made that transition, while phone upgrade transactions are currently being shifted over. Next on the list is support for adding new lines, followed by what appears to be the biggest change yet. By the fourth quarter of 2026, the roadmap indicates that all new customer accounts will be handled entirely through T-Life. So, many of the tasks that traditionally required a trip to a T-Mobile store could soon be completed from your phone instead. [...] The roadmap also reinforces a direction T-Mobile has been moving toward for quite some time: making T-Life the center of the customer experience. If the timeline holds, the app may soon become a requirement for managing your account.

Read more of this story at Slashdot.

BeauHD

Senators Demand Crackdown On Wildfire 'Prediction Markets'

Slashdot
6 hours 18 minutes ago
An anonymous reader quotes a report from Ars Technica: Several US senators have written a letter to the Commodity Futures Trading Commission (CFTC), inquiring about the agency's "plans to crack down on prediction markets" that offer "contracts for individuals to bet on wildfires." "Offering bets on destructive wildfires threatens to minimize communities' suffering, all so the rich and powerful can profit," wrote (PDF) the group of senators, who represent Oregon, California, Nevada, Minnesota, and New Hampshire. The document specifically cites that Polymarket hosted bets in January 2025 on the wildfires in Los Angeles, and it mentions another website which specifically accepts "simulated bets" exclusively on California wildfires. "There's also the heightened risk -- according to state and local fire officials -- that individuals could be tempted to commit arson in order to make sure their bets are successful," the letter continues. "By offering contracts on fires, prediction market sites run the risk of encouraging people to influence fires that have already started, creating additional concerns around public safety and insider trading." [...] Kalshi spokesperson Elisabeth Diana told Ars by email that the company does not allow such wildfire markets "because they create perverse incentives." But its primary rival, Polymarket, has taken a different approach. A spokesperson for Polymarket told Ars in an emailed statement that the company does not "profit from outcomes," adding that people "come to Polymarket for information." "While we are not blind to the risks, removing these markets does not prevent a tragedy but makes the most accurate information less accessible to the people who need it most," he wrote.

Read more of this story at Slashdot.

BeauHD

NVMe Polishes Its Specs, Brings Virtualization to Locally Attached SSDs

Slashdot
10 hours 18 minutes ago
The latest NVMe specifications add SSD-level virtualization that can simplify live VM migration by preserving storage identities across servers. The updates also introduce support for post-quantum cryptography, controller-based rate limiting, voltage monitoring, and factory-reset capabilities. The Register reports: Announced by the NVM Express consortium, all 11 of the suite of NVMe specs have been updated with new features and engineering change notices. These represent the next step in the evolution of the standard, it says, which was created as a protocol to support storage devices connected to a system's PCIe bus. Perhaps the most significant new capability is PCIe Exported NVM Subsystem Migration. This extends existing NVMe virtualization to locally-attached PCIe SSDs. It does this by abstracting the physical drives into host-defined virtualized NVM subsystems, to allow for virtual machine (VM) mobility without storage reconfiguration. When a VM moves from one server to another, its storage also needs to move with it in a way that's non-disruptive to any applications running in that VM. "With NVM Subsystem Migration, NVMe SSDs can present exported NVM subsystems that hide the complexity of the underlying hardware," says Mike Allison, a senior director at SSD maker Samsung and NVM Express board member. "Instead of interacting with physical controllers and namespaces, the host only sees exported controllers and namespaces. This creates a clean separation between what the VM sees and what's happening under the hood," Allison explains on an NVM Express blog. "One of the key innovations here is providing the host with control over exported identifiers. During migration, those identifiers can be carried over exactly from the source to the destination. That consistency is crucial: even if the underlying hardware uses different internal IDs, the VM sees no change and can pick up right where it left off with no storage reconfiguration required," he says. In effect, the NVMe layer now enables the virtual machine manager (VMM) to rely on virtualization built into the SSD. The flash drive itself exposes logical, virtualized storage constructs, offloading this complexity from the VMM. You can learn more about the updated NVMe specifications here.

Read more of this story at Slashdot.

BeauHD

Watch a SpaceX Rocket Crash Into the Moon

Slashdot
15 hours 18 minutes ago
A four-ton SpaceX Falcon 9 upper stage left drifting after a 2025 lunar mission is expected to crash into the Moon at about 5,400 mph, likely striking Einstein Crater. The impact should occur at approximately 2:35 a.m. ET (0635GMT). Reuters reports: Such stages typically fall back into Earth's atmosphere and burn up or plunge into the ocean after boosting the rocket's payload to a precise spot in orbit. But because the January lunar lander mission required more thrust than missions closer to Earth, the rocket's second stage remained in space, floating aimlessly among thousands of other pieces of space junk that active satellites must steer clear of. It was not until earlier this year that astronomers determined that the rocket stage, which had dumped its remaining fuel and cannot be controlled, was on an orbital trajectory ending at the moon. "What has happened is essentially a mixture of solar activity and gravity forces have put it on a path toward the moon," Julianna Scheiman, SpaceX director of NASA science and Dragon programs, told reporters on Monday. "This may be of some -- probably minor -- scientific interest, and we may learn some things from it," said Bill Gray, creator of widely used astronomy software who published a report on the stage's impact in April. "It doesn't present any danger to anyone, though it does highlight a certain carelessness about how leftover space hardware (space junk) is disposed of." You can try to watch the impact via a livestream on YouTube; however, the area it's expected to hit (Einstein Crater) is on the moon's western limb, "which is often difficult to see from Earth," notes Reuters. It will also likely "kick up a plume of lunar dust that will likely be illuminated by sunlight but difficult to spot with the naked eye from Earth."

Read more of this story at Slashdot.

BeauHD

Texas Halts Data Center Connections To Power Grid Amid Overwhelming Demand

Slashdot
17 hours 48 minutes ago
An anonymous reader quotes a report from Ars Technica: Nowhere is the US data center boom bigger than in Texas. But less than a year after declaring Texas the "epicenter of AI development," Governor Greg Abbott has declared a moratorium on all new power grid connections for data centers -- at least until developers provide more information about their projects' potential impacts on the grid and communities. The Republican governor directed regulators in an August 3 announcement at the Public Utility Commission of Texas and the grid operators at the Electric Reliability Council of Texas (ERCOT) to perform a "comprehensive verification and audit of all data centers advancing through ERCOT's interconnection process." As an independent system operator, ERCOT oversees a power grid that operates separately from the rest of the United States and provides services to most of Texas. Texas has aggressively courted data center development with its availability of cheap land and relatively abundant energy resources, along with offering state incentives, like tax breaks and fewer regulations. That puts the state on track to surpass Virginia in becoming the largest US data center market. But the recent AI boom and the accompanying frenzy of data center development threaten to overwhelm the Texas grid on paper, despite the state leading the country in adding new power generation. The ERCOT interconnection queue currently includes more than 1,800 projects representing over 474 gigawatts' worth of requests to connect to the Texas grid -- more than five times Texas' record peak electricity demand -- and about 90 percent of those power connection requests come from data centers. "That unprecedented load growth could endanger the reliability and stability of the Texas electric grid," according to the statement from Abbott's office. Many of those data center projects may never materialize for various reasons. But ERCOT has still forecast that data center demand and other factors could drive statewide electricity demand to double the current demand record by 2032, according to The Texas Tribune. The review will examine each project's projected electricity consumption, reliance on the grid and state incentives, ownership, and water use. It will also assess measures intended to "reduce impacts on neighboring property owners and communities," including noise controls, lighting, traffic improvements, setbacks, and emergency planning. Ars Technica notes that the directive does not address air pollution or greenhouse-gas emissions and does not apply to data centers generating their own power on-site.

Read more of this story at Slashdot.

BeauHD

EA Is Now Officially Privately Owned

Slashdot
22 hours 18 minutes ago
Longtime Slashdot reader neoRUR shares a report from Game Developer: EA Sports FC and Battlefield publisher EA has been taken private by an investor consortium led by Saudi Arabia's sovereign Public Investment Fund (PIF). The move means the U.S. juggernaut is no longer a publicly-traded entity and is now majority owned by the Kingdom of Saudi Arabia through its PIF investment arm. Other investors include Silver Lake and Affinity Partners, the latter of which was established by U.S. president Donald Trump's son-in-law Jared Kushner. The $55 billion transaction was financed via a combination of cash from PIF, Silver Lake, and Affinity Partners as well as roll-over of PIF's existing stake in EA -- constituting an equity investment of approximately $36 billion. Notably, $20 billion of debt financing was provided by JPMorgan Chase Bank. The deal cleared the necessary regulatory hurdles in July, paving the way for its completion at the close of trading on August 4, 2026. It was approved by regulators in major markets such as the European Union and the United States without incident, despite lawmakers and union leaders in the U.S. calling on the Federal Trade Commission to heavily scrutinize the leveraged buyout over geopolitical and employment concerns.

Read more of this story at Slashdot.

BeauHD

Apple Limits Bug Bounty Submissions After Flood of AI Slop

Slashdot
23 hours 18 minutes ago
Apple has capped the number of open bug-bounty reports researchers can submit after being flooded with low-quality and sometimes entirely fabricated vulnerabilities generated by AI. MacRumors reports: The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction. Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions. While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.

Read more of this story at Slashdot.

BeauHD

Bending Spoons to Buy Airtable For $1.28 Billion

Slashdot
1 day ago
Bending Spoons has made its first acquisition since going public last month at an $18 billion valuation, agreeing to buy spreadsheet and database startup Airtable for $1.28 billion in cash. Airtable joins a growing portfolio of notable brands owned by the Italian app developer, including Evernote, WeTransfer, EventBrite, and Vimeo. TechCrunch reports: Founded in 2013, Airtable has so far raised more than $1.4 billion over multiple funding rounds. At its peak, during the boom days of 2021, it was valued at over $11 billion, but earlier this year, its shares were said to be trading on the secondary markets at a valuation of $4 billion. With its current net cash-and-cash-equivalents balance, Airtable is now valued at about $2.25 billion, Bending Spoons said. "Airtable is a pioneering brand reshaping how teams organize data and manage critical workflows. The value being delivered is reflected in annual recurring revenue growing over 20% YoY to approximately $480 million as of June 2026, and joining forces with Bending Spoons will accelerate innovation even further," Bending Spoons' founder Luca Ferrari said in a statement.

Read more of this story at Slashdot.

BeauHD

Microsoft Tells Engineers 'Tokenmaxxing Is Not What We Are Optimizing For'

Slashdot
1 day 1 hour ago
Microsoft is introducing AI token budgets for employees, making the cheaper GPT-5.6 its default internal model and telling engineers to focus on business results rather than maximizing AI usage. 404 Media reports: "As we accelerate our use of GitHub Copilot to deliver on our goals, we all need to be aware of how we consume tokens," Jay Parikh, an executive vice president at Microsoft said in an email to Microsoft employees. GitHub is owned by Microsoft, and GitHub Copilot is an AI coding tool. "Tokenmaxxing is not what we are optimizing for. I want all of us focused on maximizing outcomes that move the needle for our customers and our business." "As such, we are updating our internal guidance and managing token spend with the same discipline we apply to every other critical resource," Parikh said in the email. Parikh's email says that in an effort to "get greater value from our token investment" Microsoft is making OpenAI GPT-5.6, which is cheaper to use than other models, the default model for internal use. His email also links to updated internal Copilot guidelines stating that, as of July 2026, Microsoft divisions will have an "AI token budget target," and that employees can track their individual AI spending. "While there is no target spend value being shared at this time. The data shows that many engineers spend in the range of hundreds of dollars a month to a few thousand dollars in tokens," the guidelines say. They also say that some decisions may place further restrictions as they monitor spend. [...] Parikh's email said Microsoft will keep learning and adjusting its AI policies as models and products evolve, and stressed that he doesn't want to slow down the company's progress towards becoming "AI-first." "We are not optimizing for fewer tokens," he said. "We are optimizing for more impact per token.

Read more of this story at Slashdot.

BeauHD

Trump Begins Selling $100,000 Monthly Subscription Service to Wall Street

Slashdot
1 day 2 hours ago
Trump Media has officially launched its $100,000-per-month data feed giving trading firms machine-readable access to Truth Social posts milliseconds before the public. According to Fortune, five Wall Street firms have already signed up for the service, which "would generate about $500,000 in monthly revenue, or $6 million annually." Critics argue the service could let President Trump, who owns about 41% of the company, profit from early access to market-moving presidential communications. "I'll be blunt," Gian Luca Clementi, an economics professor at NYU Stern School of Business, told Fortune. "This is insider trading by definition." "He's going to monetize the role of the office of the president of the United States," he said. "The undisputable fact is that somebody is going to earn some more money than before, and that's the president of the United States." From the report: Trump's media venture has struggled to build a profitable social media business despite its lofty valuation. Truth Social has reported significant operating losses since going public. According to the company's earnings report for Q1 2026, Trump Media & Technology Group netted a roughly $405 million loss and raised less than $900,000 in sales. Not everyone agrees the arrangement meets the legal bar for insider trading. Shannon Devine, a spokeswoman for Trump Media & Technology Group, has pushed back on the characterization, telling Quartz that Truth API "offers customers the fastest way to ingest publicly available Truth Social data" and that critics "must have invented a new theory of 'insider trading' based on publicly available information." Classic insider trading law hinges on trading on secret, material information in breach of a fiduciary duty, and Truth Social posts are, by design, meant to become public within moments -- raising real doctrinal uncertainty about whether faster access alone qualifies. But other legal experts argue the greater risk lies ahead. Richard Painter, former White House chief ethics counsel, has argued that the arrangement could violate federal law once Trump posts genuinely market-moving news -- on tariffs, military action, or other policy decisions -- before it's public, with Truth Social effectively acting as a paid "tipper" on the president's behalf. Sen. Alex Padilla (D-Calif.) said he plans to introduced legislation Tuesday to ban the president from selling expedited access to his statements.

Read more of this story at Slashdot.

BeauHD

Trump Administration Drafting Ban On Chinese Data Center Devices

Slashdot
1 day 3 hours ago
Longtime Slashdot reader schwit1 shares a report from Reuters: The Federal Communications Commission, which oversees the U.S. telecom industry, is working on the measure to bar imports of new Chinese optical transceivers, which allow data to travel over fiber-optic cables at the speed of light within data centers. Officials hope to publish it this year, when it would take effect. The move, not previously reported, aims to prevent Chinese firms from stealing data, installing malware or disrupting service at U.S. data centers, which house the chips to train and run AI models. The FCC could still modify or shelve the restriction, the sources stressed, speaking on condition of anonymity to discuss sensitive matters. [...] A U.S. ban on new models of Chinese data center devices would likely hit China's Zhongji Innolight, one of the biggest global sellers of transceivers, which was added to the Pentagon's list of alleged Chinese military-backed companies in June. The list can be a harbinger of tougher action. A ban could also raise costs for American cloud firms such as Amazon Web Services, as it may force them to transition to other producers such as U.S.-based Coherent and Lumentum.

Read more of this story at Slashdot.

BeauHD

Apple Says More Ex-Employees May Have Taken Confidential Data to OpenAI

Slashdot
1 day 3 hours ago
Apple is now seeking a preliminary injunction to prevent OpenAI and Jony Ive's io startup from developing AI hardware allegedly based on stolen Apple trade secrets. "The iPhone maker also claims that more of its former employees may be involved with the trade secrets theft," reports TechCrunch. From the report: In a new filing, Apple is requesting expedited discovery from the accused OpenAI employees, senior systems engineer Chang Liu and Chief Hardware Officer Tang Yew Tan; OpenAI, and its foundation; and io, the device startup co-founded by Apple's former lead designer Jony Ive. Apple also notes that its continued investigation has so far revealed 11 other former Apple employees beyond Liu and Tan may have been witnesses or otherwise involved in the case, and others who were previously named in the original complaint, like OpenAI employee Yu-Ting Peng. The filing marks an escalation in Apple's legal battle with OpenAI, as it suggests Apple has uncovered new evidence that the misconduct goes beyond the former employees named in the original complaint. "For example, another former Apple employee seems to have met with Mr. Liu and Ms. Peng in advance of Ms. Peng's interview at OpenAI and discussed with them during that meeting Apple proprietary information relating to unannounced products," the filing states. "Yet another former Apple employee took screenshots of confidential Apple documents relating to an unannounced Apple product before an interview at OpenAI." "And, after Apple filed its complaint, multiple former Apple employees now working at OpenAI reached out to discuss returning Apple-issued work devices they kept when they left Apple," Apple claims, suggesting there were more who were possibly involved with the scheme. Apple is pushing the court to allow for expedited discovery because it believes it has good cause to suspect that there are others involved in the theft of its intellectual property. The company noted that its motion for a preliminary injunction is also pending. Apple's request for a preliminary injunction is "both based on false information and completely unnecessary because we do not have, nor want, any of their trade secrets," said OpenAI in a blog post. "We're much more interested in building innovative products and technologies that push the frontier," OpenAI's statement reads.

Read more of this story at Slashdot.

BeauHD

Apple Launches Legal Challenge Against UK Demand To Access Encrypted User Data

Slashdot
1 day 5 hours ago
An anonymous reader quotes a report from The Guardian: Apple has launched a new legal challenge against a UK government demand to access its customers' highly encrypted data, a year after the Home Office agreed to abandon its previous request. The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully. The UK government had made a second request to Apple to grant it a "back door" to encrypted iCloud data belonging to British users, according to an order issued by the court. Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington. UK authorities subsequently issued a new "technical capability notice" (TCN) to Apple that did not apply to American users. Apple is seeking to challenge the British government's powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times. [...] The original TCN issued last year asked Apple for the right to see users' encrypted data protected by its advanced data protection (ADP) program in the event of a national security risk. Apple said the removal of the tool -- which not even it can access -- would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a "back door" would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant. As a result, Apple withdrew UK customers' access to its ADP program in January 2025. The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.

Read more of this story at Slashdot.

BeauHD

Sandisk and SK Hynix Publish First Open High Bandwidth Flash Standard

Slashdot
1 day 6 hours ago
BrianFagioli writes: Sandisk and SK hynix have published the first open technical specification for High Bandwidth Flash (HBF) through the Open Compute Project. HBF is designed to create a new memory tier between High Bandwidth Memory and traditional SSD storage, giving AI inference systems more near compute capacity without relying entirely on expensive HBM. The specification supports capacities up to 512GB using 8-high and 16-high NAND stacks, with bandwidth tiers ranging from about 0.4TB per second to 3.0TB per second. It also uses the UCIe chiplet interface, which could make HBF easier to integrate with CPUs, GPUs, and other accelerators. Google and Tenstorrent participated in the standardization effort, but commercial products and independent benchmarks are still missing.

Read more of this story at Slashdot.

BeauHD

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

Slashdot
1 day 10 hours ago
A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals. A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector. [...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Read more of this story at Slashdot.

BeauHD

Spain Offers $1.14 Billion To Get Thirty Meter Telescope Moved To Canary Islands

Slashdot
1 day 14 hours ago
Longtime Slashdot reader schwit1 shares a report from Behind the Black: In a new bid to get the Thirty Meter Telescope (TMT) to move from Hawaii, which has blocked its construction for more than a decade, the Spanish government has put together a $1.14 billion package that would not only pay for construction on the Canary Islands, but would finance an additional half century of operations. Tech Times provides some additional details: The package is conditional on the TMT International Observatory formally choosing La Palma as its construction site. The financing architecture has three pillars and two additional contingent instruments. The first pillar is 400 million euros (approximately $456 million USD) from Spain's Ministry of Science, Innovation and Universities, routed through the Centre for Technological Development and Innovation (CDTI). This figure was first pledged a year ago in July 2025 as Spain's initial bid. The second pillar is a 300 million-euro (approximately $342 million USD) loan from the EIB [European Investment Bank] itself -- subject to satisfactory completion of the bank's technical, financial, and legal due diligence and approval by its governing bodies. The third is a potential 300 million-euro (approximately $342 million USD) participation from the Instituto de Credito Oficial (ICO), Spain's state development finance institution, evaluated under equivalent conditions to the EIB loan but subject to its own separate analysis. Spain's export credit agency, Cesce, may also provide coverage instruments, and the EIB has left open the possibility of expanding its support through intermediated financing mechanisms or guarantees.

Read more of this story at Slashdot.

BeauHD

Pagination

  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Page 9
  • Next page
  • Last page
Checked
23 minutes 48 seconds ago
News for nerds, stuff that matters
URL
https://slashdot.org/
Slashdot feed
Powered by Drupal