[ Reuters | Slashdot | BBC News ] [ Image Archive ] |
Slashdot
Ring is rolling out a new default encryption system called TAKE, or "Throw Away the Key Encryption," that rotates video keys every five minutes and permanently deletes Ring's copy after 24 hours. The system is designed to preserve cloud features such as smart alerts and AI video search while limiting what Ring can provide under legal process to non-video account information and encrypted footage. The Verge reports: Ring says TAKE uses unique, rotating encryption keys for your footage, stored in a secure enclave and accessible only under strict conditions -- based on the features you enable on your account. Currently, footage captured by Ring cameras is encrypted in transit to the cloud and at rest, and then decrypted for Ring to process for those smart features. With TAKE, the encryption keys change for every five minutes of footage. Ring stores copies of those keys to decrypt the footage, but throws away each copy within 24 hours, "leaving you with the keys and full control of your videos," according to Ring. TAKE was developed using Messaging Layer Security, an open standard from the Internet Engineering Task Force, according to Ring. The company says it is "inspired by the privacy principles of E2EE (end-to-end encryption)," which Ring offers on some of its cameras. However, the two systems work differently. With E2EE, Ring never has the keys and can't process your video for cloud-based features. Both options are available on newer cameras that encrypt on-device, and you can switch between the two. Older cameras encrypt at cloud ingress and only support TAKE. According to a white paper the company published today, Ring's copy of those keys is managed inside an AWS Nitro Enclave, to which Ring's access is restricted by "access controls, cryptography, and hardware isolation." The company claims there is no persistent storage and no way for a Ring employee to access it. The stored keys can only be unlocked by the enclave through cryptographic attestation that proves it's running the exact software image Ring approved. The enclave releases a temporary key when an enabled service requests it. When asked about what happens if Ring is subpoenaed by law enforcement, a spokesperson for the company said: "Where TAKE is enabled, Ring will only be able to provide non-video information (such as basic subscriber information) and encrypted video files in response to the valid legal process. We have updated our Law Enforcement Guidelines to reflect this change." Read more of this story at Slashdot. - Claude, Codex, and Hermes Installed Unowned Code Inside Corporate Networks An anonymous reader quotes a report from Ars Technica: Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents [including Claude, OpenAI's Codex, and Nous Research's Hermes]. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware. The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site's content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here. "The trust model is broken," Alon Hertz, one of the researchers, wrote in an interview. "Agents treat vendor docs as ground truth and don't question them -- and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer -- SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today's guards don't cover it." "An agent doesn't distinguish between a page and a command," the researchers wrote Thursday. "Everything it reads is input, and every input is a potential instruction. Which means the entire corpus of published data that agents are now wired to consume has silently become an execution surface -- and almost none of it carries the integrity guarantees we apply to actual code." Read more of this story at Slashdot. - Trump Declares National Emergency to Ban Some Foreign Grid Equipment Longtime Slashdot reader dhartshorn writes: Foreign-produced "bulk power" equipment is now effectively banned, and the list of what constitutes such equipment is essentially everything used to make up the grid... much of which we are heavily dependent on foreign sources to supply. In a Wednesday executive order, President Trump said foreign supply of electric equipment "constitutes an unusual and extraordinary threat" to national security. The Hill reports: Under the order, it will be up to Energy Secretary Chris Wright, in coordination with other officials, to determine whether a piece of equipment poses an issue. The order could impact a wide range of equipment, including substations, transformers, batteries used for energy storage, generators, turbines, software and more. It does not lay out specific threats or single out any country by name. [...] Under the last Trump administration, the president put a similar order in place. The new order comes amid several reported cyberattacks on U.S. water systems, which officials suspect have links to Iran, according to The New York Times. Read more of this story at Slashdot. - Panic Passes Trump Tariff Refunds Back to Playdate Customers Panic is refunding Playdate customers the 19% tariff charges it passed along while the Trump administration's import duties were in effect, after the Supreme Court ruled the tariffs illegal and the company began receiving refunds from the government. Panic says the money "just [wasn't] ours to keep." Ars Technica reports: In an update posted on the Playdate help site this week, Panic noted that it has finally "begun to receive refunds of the tariffs we paid in the last year" and had consequently "refunded all tariffs charged to customers." In the initial version of that tariff note, Panic explained that it couldn't afford to simply "absorb" the 19 percent tariffs it was being charged to import Playdate hardware made overseas because "our margins on Playdate are low." As such, while the tax was in effect, it was passed along to customers as an explicit subtotal line item at the bottom of all Playdate orders. That's in contrast to companies like Nintendo, which vaguely cited "market conditions" and tariff "uncertainty" in raising the asking price of legacy hardware and some Switch 2 accessories last year. Speaking to Game Developer, Panic co-founder Cabel Sasser said filing paperwork to claw back these taxes and processing tariff refunds for customers took a fair bit of backend work. Still, he said returning that money to Playdate purchasers in the end was a no-brainer. "It's just not our money to keep, and it felt really good to give it back," Sasser said. "That's an easy way to know you made the right decision." "It just felt like the right thing to do," Panic wrote in a refund email message shared on Reddit. Read more of this story at Slashdot. - Nvidia Agrees to Acquire Hugging Face For $13 Billion The Information reported on Wednesday that Nvidia has agreed to buy open-source platform Hugging Face for $12.9 billion. "Deal talks began after Hugging Face, an open-source AI platform developers use to collaborate, test and share tools, received acquisition interest from another suitor," reports CNBC, citing the (paywalled) report. Business Insider separately reported the acquisition talks. From CNBC: If completed, the acquisition would put one of the most widely used platforms for sharing and working with open-source AI models under Nvidia's ownership, expanding the chipmaker's reach further into the software and model ecosystem. Siddy Jobe, a fund manager at Eonopolis Exponential Technologies funds, said it made sense for Nvidia to target a company like Hugging Face, as Nvidia has made it clear that it is not looking to discriminate between closed and open-source models. "I think Nvidia is very much a community, a platform-based company, and in that respect, I think Hugging Face fits perfectly within that. There is this five-layer cake from Nvidia, and foundational models are one of them," Jobe told CNBC's Squawk Box Europe on Thursday. "It is clear that Nvidia wants to be integrated in the entire stack vertically, going from energy to foundational models and also to applications," he added. Read more of this story at Slashdot. - Operation Bluebird Launches New Twitter An anonymous reader quotes a report from Ars Technica: Operation Bluebird, the Virginia-based startup trying to revive the allegedly abandoned "Twitter" name and logo, announced Monday that it has launched its new social media network: Twitter.now. "We are a small company, we have investors, and we have a product," Stephen Coates, one of Operation Bluebird's cofounders, told Ars. "And we have waited months and months to launch, and we are not going to wait anymore." [...] Twitter.now, still in its nascent stage, only has hundreds of users for the time being. The social media network looks and feels much like the Twitter of old and many of its offshoots -- it has replies and retweets. A new and notable feature is the automated fact-checking tool, a Gemini-based "veracity engine for real-time analysis" ("Vera" for short), which runs on every tweet. Coates has been testing Vera in recent days by posting obviously false messages, like "George Washington was our second president." "Our first goal is to see if we can truly bring back a town square that's safer and less harmful," he said. "We say freedom of speech and not freedom of reach. We want people to say what they want, but we also want to create a platform that's not financially locked into that viral content that's harmful or inaccurate." Operation Bluebird argues that Elon Musk effectively abandoned the Twitter brand and trademarks when he renamed the company X, opening the door for the startup to claim them. X Corp. sued to stop the effort, but a federal judge tentatively ruled in April that X appeared to have relinquished rights to "tweet," the bird logo, and possibly "Twitter" itself, though no written ruling has been issued. Bluebird has taken that as enough of a green light to move forward while emphasizing that its new Twitter is not affiliated with X. "Operation Bluebird, Inc. picked up the name X Corp. walked away from and is rebuilding it on trust, in your browser at twitter.now," it states prominently on its website. "We are not X, and we are not affiliated with X Corp." Read more of this story at Slashdot. - How Meta's Plan To Replace Workers With AI Agents Fell Apart Reuters reports that Meta explored shrinking some teams by as much as 60% as part of an "AI native" restructuring plan that would shift much of employees' day-to-day work to AI agents and smaller teams of human "builders." But the effort quickly ran into employee revolt and disappointing productivity gains, leading Zuckerberg to scrap a planned second wave of cuts after Meta laid off 10% of its workforce in May. From the report: In January, Meta CEO Mark Zuckerberg and his top lieutenants gathered for their annual leadership retreat at his Hawaii compound. There they hatched a radical plan to reimagine work at the social-media giant in the age of artificial intelligence. Code-named Project OT -- short for Organization Transformation -- the plan envisioned an "AI native" future for the owner of Facebook and Instagram. AI would take over much of the daily work performed by thousands of human employees. Virtual workers would be overseen inside Meta by smaller, "talent-dense" cadres of human staffers, according to one internal planning document reviewed by Reuters and three people familiar with the project. In scenario-planning exercises, two of these people said, executives explored slashing the size of many teams across Meta by as much as 60%. Some employees would be offered roles in new units, while others would be laid off as part of a culling that one human-resources executive projected would be as big as or bigger than the company's cuts of around 25% three years ago, according to another internal document. The restructuring would be carried out in two "waves," beginning with a first purge in May and followed by another shake-up in November, internal planning documents seen by Reuters showed. Layoffs would be supplemented with the closing of open positions and pushing people out who Meta believed were poor performers. These and other details of the plan, including the scale of the restructuring, haven't been previously reported. AI would take over much of the daily work performed by thousands of human employees. Virtual workers would be overseen inside Meta by smaller, "talent-dense" cadres of human staffers. But on the night of May 19, just hours before the first layoff wave, Zuckerberg blinked. Meta laid off 10% of its employees the next day, but it called off planning for the November cuts, according to one internal document reviewed by Reuters. By then, Meta employees were in open revolt, convinced that the company's AI transformation initiatives were partly aimed at replacing them. Internal data was also suggesting that autonomous AI "agent" technology at the heart of the strategy was failing to deliver hoped-for productivity gains. Some investors were questioning what Meta had to show for its gargantuan spending on AI. This article reveals for the first time the rapid pace of the cuts Meta was considering, the thinking behind the plans and how they quickly unraveled. Based on scores of internal documents, posts and recordings reviewed by Reuters, as well as conversations with more than 20 people with knowledge of Meta's inner workings, the reporting shows how the social-media giant attempted to position itself at the forefront of an AI-driven workplace overhaul, only to stumble in the execution. Read more of this story at Slashdot. - More Than 100 Water Systems Were Hit In July Cyberattacks CISA says more than 100 internet-exposed U.S. water and wastewater systems were targeted in July, often through programmable logic controllers connected directly to cellular modems. "That's the first time the feds have put a number on the digital intrusions, but they have yet to attribute the campaign, widely suspected to be linked to Iran, to a particular group," reports The Register. From the report: Suspected Iranian attackers targeted water and wastewater facilities across at least a dozen states in July, including internet-exposed PLCs. While neither federal nor state officials have identified all 12, we know that the cyberattacks occurred at mostly small, rural utilities in Minnesota, Michigan, Georgia, South Dakota, and New Jersey. "This is very serious. What stands out isn't any single incident. It's the scale," Matt Hartman, chief strategy officer at the Merlin Group and CISA's former acting head of cyber, told The Register. "More than 100 water systems with internet-exposed assets were hit in a single month, which points to a systemic vulnerability across the sector, not a run of isolated, unlucky targets," Hartman said. "Much of this infrastructure runs on operational technology that was built for closed, physical environments. It was never designed with the assumption that it would be reachable from the open internet." John Gallagher, VP at Viakoo, an OT and IoT cybersecurity provider, told us that while 100 systems represent a small fraction - only about 0.5 percent - of water utilities in the US, the "real threat is that these are test runs for a larger-scale attack." While the 100-plus water incidents occurred in July, just last week five US federal agencies warned that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities. "This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs," Halcyon Ransomware Research Center SVP Cynthia Kaiser told The Register a week ago. "Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society," Kaiser, a former FBI cyber division deputy assistant director, added. CISA urges organizations to keep PLCs off the public internet, route remote access through VPNs or gateways, replace default passwords, enable stronger authentication, and restrict access to allowlisted IP addresses from trusted OT systems. Read more of this story at Slashdot. - Radiation Link In Flight Attendant's Breast Cancer, French Court Finds A French court has for the first time recognized cosmic radiation as a contributing occupational factor in a flight attendant's breast cancer, alongside passive smoking and years of night work. The landmark ruling could open the door to similar claims from other aircrew, as research continues to link long-term high-altitude flying with elevated exposure to radiation-related cancers. The BBC reports: Sophie Lainault, a 59 year-old former stewardess on Air France, sought to have her cancer recognized as an occupational disease, brought on by conditions at work. This has now been confirmed in a landmark court ruling in the southwestern town of Bayonne, which said that cosmic radiation was one of three carcinogenic hazards arising from her profession. [...] As stewardess and later purser on Air France airliners, Lainault clocked up 12,600 flight hours between 1989 and 2019. More than half of these were at night. Many long-distance high-altitude flights from Paris would have taken her near the North Pole, where exposure to radiation from space -- strictly speaking particles from the sun and other stars -- is the most intense. A study this month at the Harvard Medical School in the US found that flight attendants and pilots had the highest level of radiation-related cancer deaths among more than 500 different professions. In all, about 6.9% of deaths among flight attendants and 6.7% of deaths among pilots were from radiation-related cancers, according to the analysis. These proportions were higher than for other professions including nuclear technologists, who are routinely exposed to radiation from non-cosmic sources yet placed 12th on the list, the authors said. "In France the link between breast cancer and certain hazards has been established for a number of professions, such as nurses ... but this is the first time for an air-hostess," said Lainault's lawyer Elisabeth Leroux. Read more of this story at Slashdot. - Bill Gates Proposes Major Limits On AI Development An anonymous reader quotes a report from CNN: Microsoft co-founder Bill Gates argued on Wednesday that artificial intelligence needs significant limits or else the harm to humans will outweigh any potential good. "AI will either be the greatest equalizer ever invented, or the worst source of injustice," he said in a 6,000-word essay, entitled "The turbulent AI era is here. The choices we make now are critical." [...] "Even under the best circumstances, the transition to this new AI era will be one of the most turbulent times in human history," he said, adding that "I don't see evidence that leaders, experts, and communities are confronting the challenges adequately. There is no plan to ease the entry into the AI era." AI can provide great benefits in field like agriculture and medicine, he argued, such as breakthroughs in preventing and treating diseases. But he also noted that the transition carries big risks, like widespread unemployment, harming the educational and social development of children, or making it easier for criminals and bad actors -- or AI itself -- to cause deliberate harm. "As the models become more powerful, they could begin to act against our interests and we could lose control," he warned. These significant risks must be controlled quickly, Gates said. "If someone had a credible plan for slowing down AI advances globally, I would likely support it," he wrote. "However, I don't think that's going to happen. The geopolitical and economic incentives are pushing too hard to go full speed ahead." In an interview with CNN's Anderson Cooper that will air on Wednesday evening, Gates said AI models have gotten dramatically more powerful at a rate faster than he expected. "They're now capable of causing cyberattack risk, bioterrorism risk, psychosocial risk," he said. "I have to say I'm kind of shocked that the exact criteria that we review these models with, and the actions we take to minimize the harms, are really completely missing." In his essay, Gates proposed taxing AI or robots the way you would pay a human employee's payroll tax in order to slow the shift away from using human labor. He also wants to set aside some work to be done by humans only. "My message to leaders is: You have a chance to act now, before unemployment rises sharply, communities are hurting, and public trust has eroded," he said. "You can make sure AI benefits everyone. And you can work with other governments to meet this national and global challenge." Read more of this story at Slashdot. - OpenAI Releases Its Official Report On the Hugging Face Breach TechCrunch reports that OpenAI released its official report Wednesday on the Hugging Face breach, "offering the clearest picture yet of how an unusual chain of events allowed an AI model to escape its testing environment and triggered a sprawling cybersecurity incident." The AI company says the breach began when an unreleased cyber model, tested without normal production safeguards, encountered an impossible task and chained together previously unknown exploits to escape its environment and compromise systems at OpenAI, Hugging Face, and other vendors. "This incident reflects misaligned behavior in an outlier scenario involving a rare and unexpected confluence of events: the presence of impossible tasks in the ExploitGym evaluation, model persistence over long task horizons, and messages to peer models that caused those models to deviate from their goal," the report reads. From the report: Many of the details in OpenAI's report were previously made public in a Black Hat presentation on August 6, but OpenAI's official report gives a more thorough accounting of the incident, including more detail on the testing that initiated it. The report also gives critical new detail into how OpenAI aims to prevent future incidents, including chain-of-thought monitoring and a more advanced system for halting rogue agents." METR and Redwood Research also conducted third-party assessments of the models' behavior during the incident; both groups are planning to publish their own reports on the incident on it. In broad strokes, the report describes how an OpenAI model was presented with an unsolvable problem in testing and proceeded to chain together previously undiscovered exploits in order to bypass security measures and complete its task. The model initially compromised the Artifactory package management tool in order to gain access to the internet, then compromised various systems across OpenAI, Hugging Face, and other vendors. The report gives critical new details about the models that carried out the breach. The primary model was from the same family as OpenAI's forthcoming Astra model, although the report emphasizes that it was "a distinct model with different post-training, where much of a model's behavior is shaped." Because OpenAI was testing the model's capabilities, it was also unrestrained by the normal classifiers meant to prevent models from compromising digital infrastructure. "OpenAI estimates maximal cyber capabilities by running this evaluation without the production classifiers intended to prevent models from pursuing high-risk cyber activity," the report explains. "These evaluations are important so that OpenAI can measure models' underlying capabilities and design appropriate safeguards." OpenAI says it is adding 24/7 escalation, stronger containment tools, and more chain-of-thought monitoring, which it claims would have flagged the activity more than a day before Hugging Face was breached. Read more of this story at Slashdot. - China's Moonshot In Talks With Microsoft, Amazon, Google Over K3 Revenue Sharing Longtime Slashdot reader schwit1 shares a report from Reuters: China's Moonshot AI is negotiating revenue-sharing agreements with Microsoft, Amazon, and Alphabet's Google, that would allow the U.S. cloud giants to host its blockbuster Kimi K3 model, three people familiar with the talks said. Any deal could mark the first big revenue-sharing pact between a Chinese AI firm and a major U.S. cloud company. The discussions highlight how China's leading AI models, often far cheaper than Western offerings, are gaining traction in the U.S., despite national security concerns in Washington that have led to bans on exports of AI chips to China. They are also taking place despite critical comments about Moonshot from senior U.S. officials. IPO-bound Moonshot is seeking up to a 30% share of revenue generated from K3-related services on Microsoft's Azure, Amazon Web Services and Google Cloud, according to the sources who declined to be identified because the discussions are private. That would be in line with terms that sources have said the startup has outlined for major customers using the open-weight model. Moonshot has come under fire from U.S. Treasury Secretary Scott Bessent who said last month that he might add it to a trade blacklist. U.S. officials have accused the Beijing-based company of stealing from Anthropic's most sophisticated model, Fable, to help create Kimi K3 and illegally acquiring Nvidia chips. Read more of this story at Slashdot. - Apple Maps Now Has Ads Apple has begun rolling out ads in Apple Maps, with sponsored businesses appearing at the top of search results and in the "suggested places" section for users in the U.S. and Canada. Apple says the ads can be based on approximate location, search terms, or the area of the map being viewed, but are not tied to users' Apple Accounts and personal data remains on-device. 9to5Mac reports: Ads appear just like every other business listing, except they have a small blue badge that says 'Ad.' You can see examples of ads [embedded in the article]. Like Apple's ads policy with other services, the company touts user privacy protections for ads in Maps. Per Apple Newsroom: "Ads on Maps builds on Apple's broader privacy-first approach to advertising, and maintains the same privacy protections Maps users enjoy today. A user's location and the ads they see and interact with in Maps are not associated with a user's Apple Account. Personal data stays on a user's device, is not collected or stored by Apple, and is not shared with third parties." Read more of this story at Slashdot. - Inside the Warehouse Where Amazon Scans and Destroys Books For AI Training Last week, 404 Media published a story that revealed an Amazon warehouse where the company scans and destroys thousands of books for AI training data. Today, the publication has released an interview with one of the Amazon employees at the warehouse. "The employee worked at Amazon's VGT3 warehouse, which is housed in the same facility as LAS8, where Amazon operates its print-on-demand business," reports 404 Media. "Both operations are part of a larger complex of Amazon facilities in Las Vegas, Nevada." Slashdot reader alternative_right shares an excerpt from the report: [...] What does it look like when they cut the spines off the books? It's a machine people operate. Each of these machines is just like a little workstation, and there'll be one person at each of these stations. It's really safe because it has a little cover and it has a little area where you slide the book into, remove your fingers from the area, and then you press a button, and it just comes down and slices it. And then you remove the books after the blade is gone. After they cut the spines they have these kind of library carts, kind of like how you would stack books, but instead, it's a stacks of paper and little cardboard things to separate -- I'm guessing -- the different books. I saw the pages being thrown in a shuttle after they were scanned. We were walking by and we went over to one of the shuttles and looked into it because we could tell they were throwing the old books in it or the cut books in it, and it's just a bunch of loose paper like just sheets thrown in there. What do you think about Amazon doing this? At first what they were telling people is that it was for Kindles, but I just didn't believe that. I instantly was like, I don't think that's how they do it because of publication rights and stuff, copyright and everything. Then I saw it was for AI. I don't like it only because I wish I could take these books. There's so much knowledge and so much stuff in them and some of them look like they might be rare, and I've heard that they order rare books, and that's why I say some of these are so obscure. I definitely don't like the idea that they can't be reused or anything like that afterwards. They're reducing the amount of available copies for other people. Read more of this story at Slashdot. - Xbox's New Disc-to-Digital Program Gives Physical Games a Digital Future An anonymous reader quotes a report from Ars Technica: For decades, console owners have faced a choice between the convenience of digital downloads and the permanence of physical game discs. Soon, Xbox owners will be able to get the best of both worlds for thousands of supported titles as part of a newly announced disc-to-digital program. The program -- announced today ahead of testing for Xbox Insiders starting August 31 -- will let players claim a "digital entitlement" for "most Xbox One and Xbox Series X disc-based games" simply by inserting the disc into a console and launching it. That game will then be playable completely digitally, without the need to ever insert the disc, as long as you (or a member of your family account) is logged in. The digital entitlement will also allow access to features like Xbox Play Anywhere (for play on PC) and Xbox Cloud Gaming, for supported titles. Microsoft says that your physical disc will "continue to work exactly as it always has" after the digital entitlement is claimed. But before you get any ideas, the fine print on the announcement mentions that there is only "one revokable license per game disc," so if you resell that disc or loan it to a friend, that digital entitlement could be transferred to a new account when someone else puts it into their console. A leaked memo obtained by the Verge earlier this month suggests that publishers have to actively opt in to allow their game discs to activate digital entitlements, which could explain why "most" but not all Xbox One and Series X titles are supported. Windows Central separately suggests, based on discussion with unnamed sources, that "some discs may be incompatible due to how they were manufactured at the time," which could explain why original Xbox and Xbox 360 discs are not being discussed for the program. "While not every title will be available at launch, this is an important step toward a future where players can have greater confidence that the games they buy remain with them for years to come," said Xbox Vice President Jason Ronald. Read more of this story at Slashdot. |
|