


Belgium Becomes First EU Country To Ban Sale of Disposable Vapes (theguardian.com) 110
Announcing the ban last year, Belgium's health minister, Frank Vandenbroucke, described electronic cigarettes as an "extremely harmful" product that damages society and the environment. "Disposable e-cigarettes is a new product simply designed to attract new consumers," he told the Associated Press. "E-cigarettes often contain nicotine. Nicotine makes you addicted to nicotine. Nicotine is bad for your health."

Finland Finds Drag Marks Near Broken Undersea Cable. Russia's 'Shadow Fleet' Suspected (msn.com) 160
In an interesting twist, the New York Times reports that the ship "bears all the hallmarks of vessels belonging to Russia's shadow fleet, officials said, and had embarked from a Russian port shortly before the cables were cut." If confirmed, it would be the first known instance of a shadow fleet vessel being used to intentionally sabotage critical infrastructure in Europe — and, officials and experts said, a clear escalation by Russia in its conflict with the West... NATO's general secretary, Mark Rutte, responding to requests from the leaders of Finland and Estonia, both member nations, said the Atlantic alliance would "enhance" its military presence in the Baltic Sea...
Since Russia began assembling its fleet, the number of shadow vessels traversing the oceans has grown by hundreds and now makes up 17 percent of the total global oil tanker fleet... Nearly 70 percent of Russia's oil is being transported by shadow tankers, according to an analysis published in October by the Kyiv School of Economics Institute, a research organization based in Ukraine... The authorities in Finland are still investigating whether the "Eagle S" engaged in a criminal act. But the sheer size of the shadow fleet might have made using some of these vessels for sabotage irresistible to Russia, [said Elisabeth Braw, a senior fellow at the Atlantic Council who has researched and written about shadow fleets]...
While it's still not certain that this week's cable cutting was done intentionally, the Baltic Sea, for a number of reasons, is an ideal arena to carry out sabotage operations. It is relatively shallow and is crisscrossed with essential undersea cables and pipelines that provide energy, as well as internet and phone services, to a number of European countries that are NATO members. Russia has relatively unfettered access to the sea from several ports, and its commercial vessels, protected by international maritime law, can move around international waters largely unmolested... The suspicions that Russia was using shadow vessels for more than just escaping sanctions existed before this week's cable cutting. Last April, the head of Sweden's Navy told a local news outlet that there was evidence such ships were being used to conduct signals intelligence on behalf of Russia and that some fishing vessels had been spotted with antennas and masts not normally seen on commercial vessels. Since the war began, there has also been an uptick in suspicious episodes resulting in damage to critical undersea infrastructure...
Hours after Finland's energy grid operator alerted the police that an undersea power cable was damaged on Wednesday, Finnish officers descended by helicopter to the ship's deck and took over the bridge, preventing the vessel from sailing farther. By Friday, it remained at anchor in the Gulf of Finland, guarded by a Finnish Defense Forces missile boat and a Border Guard patrol vessel.
The cable incident happened just weeks after the EU issued new sanctions targetting Russia's shadow fleet, Euronews reports. "A handful of Chinese companies suspected of enabling Russia's production of drones are also blacklisted as part of the agreement, a diplomat told Euronews." The "shadow fleet" has been accused of deceptive practices, including transmitting falsified data and turning off their transporters to become invisible to satellite systems, and conducting multiple ship-to-ship transfers to conceal the origin of the oil barrels...

The USB-C Charging Mandate Arrives in the EU (theverge.com) 107
The requirement for USB-C is just the surface of this directive though. It also includes regulations on fast charging, unbundling charging bricks from retail devices, and the introduction of improved labelling -- and it has the potential to make life for gadget enthusiasts in the EU a whole lot simpler. If it works, of course.

Germany Joins EU's 'Ultra-Low' Fertility Club 175
Estonia and Austria also passed under the 1.4 threshold, joining the nine EU countries -- including Spain, Greece and Italy -- that in 2022 had fertility rates below 1.4 children per woman. The fall in birth rates partially reflects the "postponement of parenthood until the 30s," which involves a "higher likelihood that you will not have as many children as you would like because of the biological clock," said Willem Adema, senior economist at the OECD.

'2024 Was the Year Gamers Really Started Pushing Back On the Erosion of Game Ownership' (pcgamer.com) 50

Critics Decry Vietnam's 'Draconian' New Internet Law (theguardian.com) 22
She warned that the new decree "may encourage self-censorship, where people avoid expressing dissenting views to protect their safety -- ultimately harming the overall development of democratic values" in the country. Le Quang Tu Do, of the ministry of information and communications (MIC), told state media that decree 147 would "regulate behavior in order to maintain social order, national security, and national sovereignty in cyberspace." [...]
Human Rights Watch is calling on the government to repeal the "draconian" new decree. "Vietnam's new Decree 147 and its other cybersecurity laws neither protect the public from any genuine security concerns nor respect fundamental human rights," said Patricia Gossman, HRW's associate Asia director. "Because the Vietnamese police treat any criticism of the Communist party of Vietnam as a national security matter, this decree will provide them with yet another tool to suppress dissent."

EU Wants Apple To Open AirDrop and AirPlay To Android (9to5google.com) 47
As our sister site 9to5Mac points out, Apple has responded (PDF) to this EU document, prominently criticizing the EU for putting out a mandate that "could expose your private information." Apple's document primarily focuses in on Meta, which the company says has made "more interoperability requests" than anyone else. Apple says that opening AirPlay to Meta would "[create] a new class of privacy and security issues, while giving them data about users homes." The EU is taking consultation on this case until January 9, 2025, and if Apple doesn't comply when the order is eventually put into effect, it could result in heavy fines.

Apple Pulls Lightning-Equipped iPhones From Swiss Stores Ahead of EU USB-C Mandate (macrumors.com) 33
The devices, which use Apple's proprietary Lightning port, disappeared from Swiss online stores today. Switzerland, while not an EU member, follows EU market rules. Apple-authorized resellers can continue selling existing stock until depleted. A new USB-C compatible iPhone SE is expected in March.

EU Pushes Apple To Make iPhones More Compatible With Rival Devices (theverge.com) 98
Apple has responded [PDF] with warnings about security risks, particularly citing Meta's requests for access to Apple's technology. The Commission seeks industry feedback by January 2025, with final measures expected by March. Non-compliance could trigger EU fines up to 10% of Apple's global annual sales.

EU Opens Investigation Into TikTok Over Election Interference (reuters.com) 69

Meta Fined $263 Million Over 2018 Security Breach That Affected 3 Million EU Users (techcrunch.com) 24
The breach it relates to dates back to July 2017 when Facebook, as the company was still known then, rolled out a video upload function that included a "View as" feature which let the user see their own Facebook page as it would be seen by another user. A bug in the design allowed users making use of the feature to invoke the video uploader in conjunction with Facebook's 'Happy Birthday Composer' facility to generate a fully permissioned user token that gave them full access to the Facebook profile of that other user. They could then use the token to exploit the same combination of features on other accounts -- gaining unauthorized access to multiple users' profiles and data, per the DPC.

EU Signs $1 Billion Deal For Sovereign Satellite Constellation To Rival Starlink (techcrunch.com) 109
First announced in 2022, Iris^2 (Infrastructure for Resilience, Interconnectivity and Security by Satellite) is a public-private partnership whose initial cost estimate (6 billion euros) leapt 76% through a fraught negotiation process. In the end, the program will be 61% funded from the public purse; an industry consortium called SpaceRise, selected in October, is making up the difference. This grouping includes French satellite giant Eutelsat, which merged with European rival OneWeb back in 2022.

Scientists Advise EU To Halt Solar Geoengineering 149
Proponents argue that this can help in the fight against climate change, especially as planet-heating greenhouse gas emissions continue to climb. But small-scale experiments have triggered backlash over concerns that these technologies could do more harm than good. The European Commission asked its Group of Chief Scientific Advisors (GCSA) and European Group on Ethics in Science and New Technologies (EGE) to write up their opinions on solar geoengineering, which were published today alongside a report synthesizing what little we know about how these technologies might work.
There's "insufficient scientific evidence" to show that solar geoengineering can actually prevent climate change, says the opinion written by the GCSA. "Given the currently very high levels of scientific and technical uncertainty ... as well as the potential harmful uses, we advocate for a moratorium on all large-scale [solar geoengineering] experimentation and deployment," writes the EGE in the second highly anticipated opinion.

Slashdot's Interview with Bruce Perens: How He Hopes to Help 'Post Open' Developers Get Paid (slashdot.org) 61
But first, "One of the things that's clear from the Slashdot patter is that people are not aware of what I've been doing, in general," Perens says. "So, let's start by filling that in..."
Read on for the rest of his wide-ranging answers....

Is Europe Better Prepared to Protect Undersea Internet Cables? (carnegieendowment.org) 64
Even before the October 2023 incident, NATO, the EU, and certain European governments began to increase their efforts to boost subsea cable resilience and security. In February 2023, NATO stood up a new Critical Undersea Infrastructure Coordination Cell in Brussels to convene stakeholders and enhance coordination between the public and private sectors. In July 2023, NATO allies at the Vilnius Summit established a Maritime Center for the Security of Critical Undersea Infrastructure as part of the alliance's Maritime Command in Northwood, UK. In October 2023, after the first incident, NATO defense ministers endorsed a new Digital Ocean Vision, an initiative aimed at improving undersea surveillance. And in February 2024, the European Commission released its first "Recommendation on Secure and Resilient Submarine Cable Infrastructures," encouraging member states to conduct regular stress tests, improve information sharing amongst themselves, and improve cable maintenance and repair capabilities.
The article points out that the Chinese ship suspected in the 2023 cable cutting "ignored requests from Finnish and Estonian authorities to halt" and returned to China. But the Chinese ship suspected in November's cable-cutting "remains in international waters in the Kattegat, with naval and coast guard vessels from Denmark, Germany, and Sweden circling close by." Yet "Under international maritime law, these countries' authorities are not allowed to board..." Current provisions of international law are neither formulated to adequately protect subsea data cables from sabotage nor hold perpetrators accountable. This reality should lead the EU, as a body inherently focused on the resilience of international legal regimes, to push for updates that are better suited for the current geopolitical reality... Lawmakers should also explore ways to increase penalties for subsea cable damage, in part to deter acts of sabotage in the first place....
A forthcoming Carnegie Endowment report will detail more in-depth recommendations on how Europe can both protect itself against future subsea cable damage and help expand trusted networks around the world.
The article also notes that "Of the hundreds of disruptions to cables that occur each year, the vast majority are caused by accidental human activity, like fishing, or natural events, like earthquakes."

Ask Bruce Perens Your Questions About How He Hopes to Get Open Source Developers Paid (postopen.org) 93
To make it all happen, he envisions software developers owning (and controlling) a not-for-profit corporation developing a body of software called "the Post Open Collection" and collecting its licensing fees to distribute among developers. The hope? To "make it possible for an individual developer to stay at home and code all day, and make their living that way without having to build a company."
The not-for-profit entity — besides actually enforcing its licensing — could also:
- Provide tech support, servicing all Post-Open software through one entity.
- Improve security by providing developers with cryptographic-hardware-backed authentication guaranteeing secure software chain-of-custody.
- Handle onerous legal requirements like compliance with the EU Cyber Resilience Act "on behalf of all developers in the Post Open Collection".
- Compensate documentation writers.
- Fund lobbying on behalf of developers, along with advocacy for their software's privacy-preserving features.
"We've started to build the team," Perens said in a recent interview, announcing weeks ago that attorneys are already discussing the structure of the future organization and its proposed license.
But what do you think? Perens has agreed to answer questions from Slashdot readers...
He's also Slashdot reader #3,872. (And Perens is also an amateur radio operator, currently on the board of M17 — a community of open source developers and radio enthusiasts — and in general support of Open Source and Amateur Radio projects through his non-profit HamOpen.org.) But more importantly, Perens "was the person to announce 'Open Source' to the world," according to his official site. Now's your chance to ask him about his next new big idea...
Ask as many questions as you'd like, but please, one per comment. We'll pick the very best questions — and forward them on to Bruce Perens himself to answer!
UPDATE: Bruce Perens has answered your questions!

UN Plastic Treaty Talks Collapse Without a Deal (politico.eu) 67
The EU, alongside more than 100 other countries that included the U.K., on Thursday had backed a new proposal spearheaded by Panama pushing for a global target to reduce plastic production to "sustainable levels", drawing a clear battle line for the talks. But three negotiators from countries in the High Ambition Coalition to End Plastic Pollution — granted anonymity to discuss closed-door talks — told POLITICO Saudi Arabia had coordinated a push from oil-rich and plastic-producing countries to block any proposals for the treaty that threatened to reduce plastic production. The vast majority of plastic is made from oil or natural gas...
Along with disagreements over plastic production, countries were also unable to agree on whether and how to target particularly polluting plastic products, and how to finance the treaty. Two of the "high-ambition" negotiators referenced above suggested the talks were doomed to fail from the beginning, arguing that there was never going to be enough time given the scope of the mandate. "I think the pressure on us to deliver that in 18 months ... was kind of stupid then, and it's still stupid now," said one. "Usually these processes take a number of years — beyond what we are doing...." But many observers and some delegates said the summit's collapse demonstrated the failures of consensus-based environmental multilateralism, arguing that requiring all countries to agree by consensus gave reluctant nations too much veto power. NGOs like the Center for International Environmental Law hope this week's failed talks will serve as a lesson for future U.N. talks...
The date and time of the next round of talks is yet to be announced.
Greenpeace issued a statement saying "over 100 Member States, representing billions of people, rejected a toothless deal that would have accomplished nothing, and stood before the world committing to an ambitious treaty."
And they argued that the message is clear. "Ambitious countries must not allow the fossil fuel and petrochemical industries, backed by a small minority of countries, to prevent the will of the vast majority. A strong agreement that protects people and the planet is our only option."

Bluesky Passes Threads for Active Website Users, But Confronts 'Scammers and Impersonators' (engadget.com) 145
But "the influx of new users has opened up new opportunities for scammers and impersonators," Engadget reported this week: A recent analysis by Alexios Mantzarlis, director of the Security Trust and Safety Initiative at Cornell Tech found that 44 percent of the top 100 most-followed accounts on Bluesky had at least one "doppelganger," with most looking like "cheap knock-offs of the bigger account, down to the same bio and profile picture," Mantzarlis wrote in his newsletter Faked Up.
The article highlighted issues with Bluesky's loose account verification policies. And then, Bluesky announced a new change-of-policy Friday. Engadget reports: The Bluesky Safety account said that the social media service is removing accounts that are impersonating other people and those squatting on handles... Bluesky now requires parody, satire or fan accounts to label themselves as such in both their handles and their bio. If they don't, or if they only indicate the nature of their account in one of those elements, then they'll be treated as an impersonator and will be removed from the platform. Bluesky now explicitly prohibits identity churning, as well. Accounts that start as impersonators with the purpose of gaining new users, and who then switch to a different identity in an attempt to circumvent the ban, will still get booted off the app. Finally, it says it's exploring "additional options to enhance account verification," though they're not quite ready for rollout.
Bluesky says they've "quadrupled the size of our moderation team, in part to action impersonation reports more quickly. We still have a large backlog of moderation reports due to the influx of new users as we shared previously, though we are making progress." And in addition, "We are working behind the scenes to help many organizations and high-profile individuals set up their verified domain handles."
And there's another problem. "The EU's executive arm on Monday said Bluesky didn't provide information it was required to share under the bloc's Digital Services Act," reports Bloomberg. Bluesky responded that it's working to comply, " consulting with its lawyer to follow the EU's information disclosure rules, a Bluesky spokesperson wrote on Tuesday in an email." "All platforms in the EU have to have a dedicated page on their websites where it says how many user numbers they have in the EU and where they are legally established," Thomas Regnier, the commission's spokesperson on digital matters, told reporters. "This is not the case with Bluesky, so this is not followed...."
Under the DSA, platforms with more than 45 million users in the bloc qualify as "very large online platforms" and need to follow stricter content moderation rules under the commission's supervision. Breaches can result in fines of up to 6% of their global annual sales... Smaller platforms are still required to comply with the law, but are regulated by the EU country where they have a legal presence. That's so far unclear in the case of Bluesky, which was created expressly to avoid a centralized ownership structure.
The commission asked EU member countries' national authorities to investigate "and see if they can find any trace of Bluesky" in their jurisdictions, Regnier said

Plastics Lobbyists Make Up Biggest Group at Vital UN Treaty Talks (theguardian.com) 34
New analysis by the Center for International Environmental Law (CIEL) shows 220 fossil fuel and chemical industry representatives -- more plastic producers than ever -- are represented at the UN talks in Busan, South Korea. Taken as a group, they would be the biggest delegation at the talks, with more plastic industry lobbyists than representatives from the EU and each of its member states, (191) or the host country, South Korea (140), according to the Centre for International Environmental Law. Their numbers overwhelm the 89 delegates from the Pacific small island developing states (PSIDs), countries that are among those suffering the most from plastic pollution.
Sixteen lobbyists from the plastics industry are at the talks as part of country delegations. China, the Dominican Republic, Egypt, Finland, Iran, Kazakhstan and Malaysia all have industry vested interests within their delegations, the analysis shows. The plastic producer representatives outnumber delegates from the Scientists' Coalition for an Effective Plastics Treaty by three to one. Approximately 460m tonnes of plastics are produced annually, and production is set to triple by 2060 under business-as-usual growth rates.