×
AI

Thousands of Authors Urge AI Companies To Stop Using Work Without Permission (npr.org) 118

Thousands of writers including Nora Roberts, Viet Thanh Nguyen, Michael Chabon and Margaret Atwood have signed a letter asking artificial intelligence companies like OpenAI and Meta to stop using their work without permission or compensation. From a report: It's the latest in a volley of counter-offensives the literary world has launched in recent weeks against AI. But protecting writers from the negative impacts of these technologies is not an easy proposition. According to a forthcoming report from The Authors Guild, the median income for a full-time writer last year was $23,000. And writers' incomes declined by 42% between 2009 and 2019. The advent of text-based generative AI applications like GPT-4 and Bard, that scrape the Web for authors' content without permission or compensation and then use it to produce new content in response to users' prompts, is giving writers across the country even more cause for worry.

"There's no urgent need for AI to write a novel," said Alexander Chee, the bestselling author of novels like Edinburgh and The Queen of the Night. "The only people who might need that are the people who object to paying writers what they're worth." Chee is among the nearly 8,000 authors who just signed a letter addressed to the leaders of six AI companies including OpenAI, Alphabet and Meta. "It says it's not fair to use our stuff in your AI without permission or payment," said Mary Rasenberger, CEO of The Author's Guild. The non-profit writers' advocacy organization created the letter, and sent it out to the AI companies on Monday. "So please start compensating us and talking to us."

Businesses

Can Airline Seating Get Any Worse? 'A New Form of Torture Chamber' (wsj.com) 182

Passengers have flooded the FAA with complaints about narrow seats and scant legroom. From a report: Passengers have been sounding off for years about airline seating -- no legroom, thin cushions, too narrow. Now politicians are listening. A bill introduced in Congress last month to update aircraft evacuation standards would compel federal regulators to study seat sizes and spacing. Tito Echeverria, who used to travel frequently as a plant manager for a manufacturing company, has had too many awkward interactions with other squished travelers. "You end up having to consistently rub legs with someone, even though you're not really trying to," said Echeverria, 32, from Ontario, Calif. "You're just freaking there next to them."

U.S. regulations cover aisle width and the number of seats allowed on planes, but not minimum seat sizes. The Federal Aviation Administration has said in court it isn't required to set seat standards unless it finds they are necessary to protect passenger safety. In late 2019 and early 2020, it simulated emergency evacuations and found seat size and spacing didn't adversely affect the process. Last year, the FAA sought public feedback on whether seat sizes posed safety issues, and it got an earful. More than 26,000 public comments poured in over a three-month stretch. "Airplane seat sizes are appalling," one commenter wrote. "They are built for people from the '40s and '50s. They cannot remotely accommodate a person over 6 feet or 200 pounds. It's literally painful to fly today."

Privacy

Typo Leaks Millions of US Military Emails To Mali Web Operator (ft.com) 52

Millions of US military emails have been misdirected to Mali through a "typo leak" that has exposed highly sensitive information, including diplomatic documents, tax returns, passwords and the travel details of top officers. Financial Times: Despite repeated warnings over a decade, a steady flow of email traffic continues to the .ML domain, the country identifier for Mali, as a result of people mistyping .MIL, the suffix to all US military email addresses. The problem was first identified almost a decade ago by Johannes Zuurbier, a Dutch internet entrepreneur who has a contract to manage Mali's country domain.

Zuurbier has been collecting misdirected emails since January in an effort to persuade the US to take the issue seriously. He holds close to 117,000 misdirected messages -- almost 1,000 arrived on Wednesday alone. In a letter he sent to the US in early July, Zuurbier wrote: "This risk is real and could be exploited by adversaries of the US."

GUI

Is Wayland Becoming the Favored Way to Get a GUI on Linux? (theregister.com) 210

The Register shares its collection of "signs that Wayland is becoming the favored way to get a GUI on Linux." - The team developing Linux for Apple Silicon Macs said they didn't have the manpower to work on X.org support.

- A year ago, the developers of the Gtk toolkit used by many Linux apps and desktops said that the next version may drop support for X11...

- One of the developers of the Budgie desktop, Campbell Jones, recently published a blog post with a wildly controversial title that made The Reg FOSS desk smile: "Wayland is pretty good, actually." He lays out various benefits that Wayland brings to developers, and concludes: "Primarily, what I've learned is that Wayland is actually really well-designed. The writing is on the wall for X, and Wayland really is the future." Partly as a result of this, it looks likely that the next version of the Budgie desktop, Budgie 11, will only support Wayland, completely dropping support for X11. The team point out that this is not such a radical proposition: there was a proposal to make KDE 6 sessions default to Wayland as long ago as last October...

- The GNOME spin of Fedora has defaulted to Wayland since version 25 in 2017, and the GNOME flavor of Ubuntu since 21.04.

- [T]here's now an experimental effort to get Wayland working on OpenBSD. The effort happened at the recent OpenBSD hackathon in Tallinn, Estonia, and the developer's comments are encouraging. It's already available as part of FreeBSD.

Transportation

Teenager Denied Flight Boarding for 'Skiplagging', the Money-Saving Lifehack Airlines Hate (ktla.com) 338

"Logan Parson's first flight by himself ended with airport officials taking the teenager into custody and whisking him away into an interrogation room," reports the Independent. The teen was "denied boarding to an American Airlines flight," reports the Washington Post. "He hadn't committed a crime, nor was he accused of being unruly.

"His offense? Attempting to make use of a money-saving hack that gutsy fliers use every year." Direct flights to major cities are so expensive, it can actually be cheaper to book a flight with stops in two cities — and then skip the flight to that second city. The Post points out that while passengers can save money with this so-called "hidden-city ticket" trick — or skiplagging — "most carriers regard it as a form of fraud."

From North Carolina TV station WJZY: In a statement to WJZY, American Airlines said, "Purchasing a ticket without intending to fly all flights to gain lower fares (hidden city ticketing) is a violation of American Airlines terms and conditions and is outlined in our Conditions of Carriage online...." Other major airlines, like Delta and United, also prohibit hidden city ticketing. Even [skip-lagging resource] Skip Lagged warns there may be consequences of hidden city ticketing, like your checked luggage moving on to the final destination instead of where you stop or losing frequent flyer miles you've accrued.
The Arizona Republic adds: According to American and Southwest's contracts of carriage, they can cancel any unused part of a ticket, refuse to let the passenger and their bags fly, not issue a refund and charge the customer for what the ticket would have cost for the full route. Airlines may ban a passenger from flying with them in the future.

Some airlines have challenged the practice in court but without success. In November 2014, United Airlines sued Skiplagged.com and its founder in court, claiming trademark infringement, according to court documents. A judge dismissed the suit the following year.

The Washington Post shares another warning: Chris Dong, a Los Angeles-based travel writer and points expert who used to skiplag, says you especially can't do this on a round-trip flight. "Airlines will cancel your return flight if you're a 'no show' for any segment of a booked itinerary," Dong said in an email.
While the teen's father told WJZY that his son was "interrogated a little bit" before being "taken to a security room," American Airline says their records don't show that the teen was taken to a security room. Instead, they've told the Post that "Our records indicate the customer was questioned only at the ticket counter about their travel, while attempting to check-in for their flight." The fact that the teen was denied boarding underscores how serious airlines take skiplagging. It makes sense, since the practice saps revenue from them on two fronts: Not only do passengers underpay — potentially by hundreds of dollars per ticket — but the seat on the tossed leg could have been sold to someone else. Most contracts of carriage from major airlines expressly forbid skiplagging as a result.
The Post also got this quote from Clint Henderson, an industry expert and managing editor for the Points Guy. "The airlines are getting increasingly sophisticated and smart about it. I expect that will get even more prevalent as technology improves further."
Transportation

Is There Still Room to Improve ICE Technology? (thedrive.com) 247

Here's how long-time Slashdot reader Baron_Yam summarizes a radically new tiny-but-powerful "opposed-piston engine" created by INNengine of Granada, Spain. "500cc, 120 horsepower, under 40 kilograms (85 pounds). No cylinder head in the motor, no camshaft, no crankshaft, no valves, and no oil mixed in with the fuel."

The company calls it "a single-stroke combustion cycle," though the engine itself still has a compression stroke and an exhaust stroke, reports The Drive: Despite having four cylinder banks, the INNengine (depending on its configuration) actually has eight pistons. This is because the engine is an opposed-piston motor, meaning that each piston's compression stroke is performed against a second piston placed in the same cylinder bank rather than a static cylinder head. It still only has four combustion chambers, though, which means it sounds similar to a four-cylinder engine... The mechanical configuration also allows for better engine balance. That means typical drawbacks of an internal combustion motor (often referred to as noise, vibration, and harshness) are minimalized. Once combustion happens, the piston is pushed back against the plate and forces the plate to rotate. This motion is synced between each half of the motor via a shared shaft — meaning, no extra timing components...

Is it likely that we'll see INNengine's combustion tech powering the wheels of a car? Probably not, at least not directly hooked up to a gearbox. The Mazda featured in INNengine's demo video was a great concept, but the company seems to be instead targeting the EV market as a range extender, especially since that's the way the industry is ultimately headed.

If the tech had debuted a few decades ago or more, perhaps there would have been a chance of adoption in the main market (cue Felix Wankel's notorious rotary). But messing with perfection in this day and age, especially as combustion tech could be on the way out, seems a bit unlikely to take off. That's why a range extender would appear to be the most logical path forward for this tech, especially if we want more lightweight, cost-effective EVs.

Windows

Malicious Microsoft Drivers Could Number in the Thousands, Says Cisco Talos (esecurityplanet.com) 36

An anonymous reader shared Thursday's report from eSecurity Planet: After Microsoft warned earlier this week that some drivers certified by the Windows Hardware Developer Program (MWHDP) are being leveraged maliciously, a Cisco Talos security researcher said the number of malicious drivers could number in the thousands.

Talos researcher Chris Neal discussed how the security problem evolved in a blog post. "Starting in Windows Vista 64-bit, to combat the threat of malicious drivers, Microsoft began to require kernel-mode drivers to be digitally signed with a certificate from a verified certificate authority," Neal wrote. "Without signature enforcement, malicious drivers would be extremely difficult to defend against as they can easily evade anti-malware software and endpoint detection." Beginning with Windows 10 version 1607, Neal said, Microsoft has required kernel-mode drivers to be signed by its Developer Portal. "This process is intended to ensure that drivers meet Microsoft's requirements and security standards," he wrote.

Still, there are exceptions — most notably, one for drivers signed with certificates that expired or were issued prior to July 29, 2015. If a newly compiled driver is signed with non-revoked certificates that were issued before that date, it won't be blocked. "As a result, multiple open source tools have been developed to exploit this loophole," Neal wrote. And while Sophos reported that it had uncovered more than 100 malicious drivers, Neal said Cisco Talos "has observed multiple threat actors taking advantage of the aforementioned Windows policy loophole to deploy thousands of malicious, signed drivers without submitting them to Microsoft for verification...."

"Microsoft, in response to our notification, has blocked all certificates discussed in this blog post," he noted.

AI

Driverless Taxis are Causing More 'Disruptions', San Francisco Officials Complain (sfchronicle.com) 88

After a severe rainstorm, two Cruise robotaxis drove past several downed trees and power lines, and then through caution tape, reports the San Francisco Chronicle. And then one of the Cruise vehicles caught on a low-hanging power wire for the city's bus system, "dragging it upward the rest of the block."

The article notes that the transit agency "had already de-energized the lines by the time the Cruise taxi hit them." But the cars only stopped "after driving through another set of caution tape and sandwich boards." Cruise personnel who retrieved the entangled car had to manually back it up a half block "to release the tension on the wire," according to a San Francisco Fire Department report. No one was inside the cars at the time, and no one was hurt...

But for city officials who oppose the rapid expansion of driverless taxi companies Cruise and Waymo, the episode reflects a recent and troubling trend. As driverless taxis ramp up operations in San Francisco, their disruption and close calls have increased in frequency and severity as well, officials say. "It really, really concerns me that something is going to go horribly wrong," Fire Chief Jeanine Nicholson said.

Cruise and Waymo say city officials have mischaracterized their safety track records. Their driverless taxis, the companies say, have lower collision rates than human drivers and public transit. Their self-driving cars, they argue, help improve traffic safety in San Francisco because their cars are programmed to follow posted speed limits.

The Fire Department has tallied 44 incidents so far this year in which robotaxis entered active fire scenes, ran over fire hoses or blocked fire trucks from responding to emergency calls. That count is double the figure from last year's informal count, which Nicholson said does not include all incidents.

Meanwhile the city's transit agency tallied 96 incidents just in March "where driverless cars disrupt traffic, transit and emergency responders," according to the article — and then another 91 in April.

But the issue is drawing more attention now because next month California's state regulatory agency and DMV "will vote on whether to allow Cruise and Waymo to charge for rides at all hours with no restrictions."
DRM

Internet Archive Targets Book DRM Removal Tool With DMCA Takedown (torrentfreak.com) 20

The Internet Archive has taken the rather unusual step of sending a DMCA notice to protect the copyrights of book publishers and authors. The non-profit organization asked GitHub to remove a tool that can strip DRM from books in its library. The protective move is likely motivated by the ongoing legal troubles between the Archive and book publishers. TorrentFreak reports: The Internet Archive sent a takedown request to GitHub, requesting the developer platform to remove a tool that circumvents industry-standard technical protection mechanisms for digital libraries. This "DeGouRou" software effectively allows patrons to save DRM-free copies of the books they borrow. "This DMCA complaint is about a tool made available on github which purports to circumvent technical protections in violation of the copyright act section 1201," the notice reads. "I am reporting a Git which provides a tool specifically used to circumvent industry standard library TPMs which are used by Internet Archive, and other libraries, to permit patrons to borrow an encrypted book, read the encrypted book, and return an encrypted book."

Interestingly, an IA representative states that they are "not authorized by the copyright owners" to submit this takedown notice. Instead, IA is acting on its duty to prevent the unauthorized downloading of copyright-protected books. It's quite unusual to see a party sending takedown notices without permission from the actual rightsholders. However, given the copyright liabilities IA faces, it makes sense that the organization is doing what it can to prevent more legal trouble. Permission or not, GitHub honored the takedown request. It removed all the DeGourou repositories that were flagged and took the code offline. [...] After GitHub removed the code, it soon popped up elsewhere.

AI

Meta To Release Open-Source Commercial AI Model To Compete With OpenAI, Google 16

An anonymous reader quotes a report from ZDNet: Meta, formerly known as Facebook, is set to release a commercial version of LLaMA, its open-source large language model (LLM) that uses artificial intelligence (AI) to generate text, images, and code. LLaMA, which stands for Large Language Model Meta AI, was publicly announced in February as a small foundational model, and made available to researchers and academics. Now, the Financial Times is reporting that Meta is prepared to release the commercial version of the model, which would enable developers and businesses to build applications using the foundational model.

Since it's an open-source AI technology, commercial access to LLaMA gives businesses of all sizes the opportunity to adapt and improve the AI, accelerating technological innovation across various sectors and potentially leading to more robust models. Meta's LLaMA is available in 7, 13, 33, and 65 billion parameters, compared to ChatGPT's LLM, GPT-3.5, which has been confirmed to have 175 billion parameters. OpenAI hasn't said how many parameters GPT-4 has, but it's estimated to have over 1 trillion parameters -- the more parameters, the better the model can understand input and generate appropriate output.

Though open-source AI models already exist, launching Meta's LLaMA commercially is still a significant step, due to it being larger than many of the available open-source LLMs on the market, and the fact that it is from one of the biggest tech companies in the world. The launch means Meta is directly competing with Microsoft-backed OpenAI and Google, and that competition could mean significant advancements in the AI field. Closed or proprietary software, like that used in OpenAI's ChatGPT, has drawn criticism over transparency and security.
Open Source

AlmaLinux No Longer Aims For 1:1 Compatibility With RHEL (phoronix.com) 39

Long-time Slashdot reader Amiga Trombone shares a report from Phoronix: With Red Hat now restricting access to the RHEL source repositories, AlmaLinux and other downstreams that have long provided "community" rebuilds of Red Hat Enterprise Linux with 1:1 compatibility to upstream RHEL have been left sorting out what to do. Benny Vasquez, Chair of the Board for the AlmaLinux OS Foundation, wrote in a blog post yesterday: After much discussion, the AlmaLinux OS Foundation board today has decided to drop the aim to be 1:1 with RHEL. AlmaLinux OS will instead aim to be Application Binary Interface (ABI) compatible*.

We will continue to aim to produce an enterprise-grade, long-term distribution of Linux that is aligned and ABI compatible with RHEL in response to our community's needs, to the extent it is possible to do, and such that software that runs on RHEL will run the same on AlmaLinux.

For a typical user, this will mean very little change in your use of AlmaLinux. Red Hat-compatible applications will still be able to run on AlmaLinux OS, and your installs of AlmaLinux will continue to receive timely security updates. The most remarkable potential impact of the change is that we will no longer be held to the line of "bug-for-bug compatibility" with Red Hat, and that means that we can now accept bug fixes outside of Red Hat's release cycle. While that means some AlmaLinux OS users may encounter bugs that are not in Red Hat, we may also accept patches for bugs that have not yet been accepted upstream, or shipped downstream."

Social Networks

One of Reddit's Biggest Communities Is Suggesting Users Move To Discord (theverge.com) 59

r/malefashionadvice, one of the biggest Reddit communities that's still private as part of the Reddit protest, is encouraging its users to move to Discord and Substack. The subreddit has more than 5 million subscribers. The Verge reports: Specifically, the Discord lets members of the community chat amongst themselves and post about things like fits and inspiration, while the Substack hosts a lot of guides. "One of the other mods writes "I will never go back, it's way better on Discord,' and that sentiment is pretty shared," the mod, who asked to go by Zach, says in an email to The Verge. "The community does a lot better job of self-moderating, owing largely to the fact that the ratio of existing regulars to new people is currently extremely high."

The Substack isn't intended to "be a subscription-based thing"; instead, it was a good place to bring over the subreddit's guides and maintain formatting, Zach says. The biggest guide, Building a Basic Wardrobe, is at more than 2,000 views that came "almost entirely from Discord." That said, both the Discord and Substack are far smaller than r/malefashionadvice's subscriber base: the Discord has north of 2,000 users, while the Substack has nearly 560 subscribers.

Reddit seemingly isn't happy that r/malefashionadvice is still private. On Thursday, the subreddit's moderators received the following message from a Reddit admin (employee) telling the team they would be replaced if they don't reopen the community [...]. Despite the message, the moderation team plans to stick around until they are removed. "We expect that we will be removed from [r/malefashionadvice] as a mod team relatively soon based on communications from the admins," Walker wrote in a message on the Discord. "We'd like to take this time to thank everyone who has contributed so much time and effort over almost 14 years of the sub's history."

If Reddit installs new mods that reopen the community, Zach believes that while many people will go back, "most of the regulars probably won't return," he says. "Dozens of bots (and human bad actors) plague [r/malefashionadvice] on the daily, and without proper mod tools, it'll get even harder to keep them out." More than 2,000 subreddits are still dark in protest, according to the Reddark tracker.

United States

Ancient Lead-Covered Telephone Cables Have US Lawmakers Demanding Action (arstechnica.com) 65

An anonymous reader quotes a report from Ars Technica: Newly raised concerns about lead-covered telephone cables installed across the US many decades ago are putting pressure on companies like AT&T and Verizon to identify the locations of all the cables and account for any health problems potentially caused by the toxic metal. US Sen. Edward Markey (D-Mass.) wrote a letter to the USTelecom industry trade group this week after a Wall Street Journal investigative report titled, "America Is Wrapped in Miles of Toxic Lead Cables." The WSJ said it found evidence of more than 2,000 lead-covered cables and that there "are likely far more throughout the country."

WSJ reporters had researchers collect samples as part of their investigation. They "found that where lead contamination was present, the amount measured in the soil was highest directly under or next to the cables, and dropped within a few feet -- a sign the lead was coming from the cable," the article said. Markey wrote to USTelecom, "According to the Wall Street Journal's investigation, 'AT&T, Verizon and other telecom giants have left behind a sprawling network of cables covered in toxic lead that stretches across the US, under the water, in the soil and on poles overhead... As the lead degrades, it is ending up in places where Americans live, work and play.'"

Markey wants answers to a series of questions by July 25: "Do the companies know the locations and mileage of lead-sheathed cables that they own or for which they are responsible -- whether aerial, underwater, or underground? Are there maps of the locations and installations? If not, what plans do the companies have to identify the cables? Why have the companies that knew about the cables -- and the potential exposure risks they pose -- failed to monitor them or act?" Markey also asked what plans telcos have to address environmental and public health problems that could arise from lead cables. He asked the companies to commit to "testing for soil, water, and other contamination caused by the cables," to remediate any contamination, and warn communities of the potential hazards. Markey also asked USTelecom if the phone companies will guarantee "medical treatment and compensation to anyone harmed by lead poisoning caused by the cables."
"There is no safe level of lead exposure -- none -- which is why I'm so disturbed by these reports of lead cable lines throughout the country," added US Rep. Frank Pallone Jr. (D-NJ). "It is imperative that these cables be properly scrutinized and addressed."

Another Congressman, Rep. Patrick Ryan (D-NY), said he is considering legislation on remediating contamination from the cables and that telecom companies should "do the right thing and clean up their mess." The Wall Street Journal said its testing in a playground in Ryan's district "registered high levels of lead underneath an aerial cable running along the perimeter of the park."
United States

Florida Barn Will Be the World's Largest 3D-Printed Building (axios.com) 38

A luxury horse barn in Florida is primed to be the world's largest 3D-printed building. From a report: Once it's complete, the 3D-printed luxury equestrian barn in Wellington, Florida will overtake a building in Oman as the world's largest 3D-printed structure. According to Printed Farms, the Florida-based startup developing the project, the building will have a total floor area of 10,678 square feet. While the team finished the 3D-printing portion of the site build Wednesday, the installation of doors, windows, electrical fittings and other structural components is still needed.

Printed Farms founder Jim Ritter told Axios construction is expected to be finished by the end of August -- refuting other reports that the build was already completed. What they're saying: The climate case for 3D-printing buildings, according to Ritter, lies in waste reduction. "America is a very wasteful society. We have to start keeping things longer. Our clothing, our cars, everything. That's the whole point of a greener, more sustainable building system," said Ritter.

Social Networks

Reddit is Getting Rid of Its Gold Awards System (theverge.com) 44

Reddit is sunsetting its current coins and awards systems, meaning you soon won't be able to thank a kind stranger for giving you Reddit Gold for one of your posts. From a report: Awards are little icons on posts you might have come across while scrolling around Reddit, and they're given by other users to show appreciation for a post. Perhaps the most commonly-known award is Reddit Gold, which shows up as a gold medal with a star, but there also reaction awards and awards specific to certain communities.

[...] Reddit does have plans for some kind of award system in the future, but the post only provides vague hints about what that might look like. "Rewarding content and contribution (as well as something golden) will still be a core part of Reddit," venkman01 said. "In the coming months, we'll be sharing more about a new direction for awarding that allows redditors to empower one another and create more meaningful ways to reward high-quality contributions on Reddit." In a reply, venkman01 said that "we want to create a system that is simple, easy to use, and easy to understand."

Social Networks

Reddit Removes Years of Chat and Message Archives From Users' Accounts (mashable.com) 50

An anonymous reader shares a report: The Reddit blackout protests didn't quite force the company to reverse course on its API changes that resulted in the shutdown of many popular third-party apps, but it did succeed in dominating the conversation around the platform for weeks. However, while everyone was paying attention to the protests, Reddit made some other big changes to its platform. One of those changes resulted in the removal of years of users' private conversations on the platform.

Over the past few weeks, many Redditors have reported the disappearance of their private chat logs and messages shared between other Reddit users over the years. Mashable also noticed the same on two reporters' personal accounts. Messages and live chats from before 2023 are no longer accessible by users. Mashable confirmed with Reddit that messages and chat history are no longer available if they were made prior to January 1, 2023.

AI

AI Junk Is Starting To Pollute the Internet (wsj.com) 55

Online publishers are inundated with useless article pitches as websites using AI-generated content multiply. From a report: When she first heard of the humanlike language skills of the artificial-intelligence bot ChatGPT, Jennifer Stevens wondered what it would mean for the retirement magazine she edits. Months later, she has a better idea. It means she is spending a lot of time filtering out useless article pitches. People like Stevens, the executive editor of International Living, are among those seeing a growing amount of AI-generated content that is so far beneath their standards that they consider it a new kind of spam.

The technology is fueling an investment boom. It can answer questions, produce images and even generate essays based on simple prompts. Some of these techniques promise to enhance data analysis and eliminate mundane writing tasks, much as the calculator changed mathematics. But they also show the potential for AI-generated spam to surge and potentially spread across the internet. In early May, the news site rating company NewsGuard found 49 fake news websites that were using AI to generate content. By the end of June, the tally had hit 277, according to Gordon Crovitz, the company's co-founder. "This is growing exponentially," Crovitz said. The sites appear to have been created to make money through Google's online advertising network, said Crovitz, formerly a columnist and a publisher at The Wall Street Journal.

Researchers also point to the potential of AI technologies being used to create political disinformation and targeted messages used for hacking. The cybersecurity company Zscaler says it is too early to say whether AI is being used by criminals in a widespread way, but the company expects to see it being used to create high-quality fake phishing webpages, which are designed to trick victims into downloading malicious software or disclosing their online usernames and passwords. On YouTube, the ChatGPT gold rush is in full swing. Dozens of videos offering advice on how to make money from OpenAI's technology have been viewed hundreds of thousands of times. Many of them suggest questionable schemes involving junk content. Some tell viewers that they can make thousands of dollars a week, urging them to write ebooks or sell advertising on blogs filled with AI-generated content that could then generate ad revenue by popping up on Google searches.

Transportation

Drones Reach Stratospheric Heights in Race To Fly Higher, Longer 24

New military and commercial craft aim to go far higher than jumbo jets and stay there for months, offering more flexible alternative to satellites. From a report: This month a drone took off from a missile range in New Mexico and climbed into the stratosphere, joining a race to deliver unmanned aerial vehicles that can fly higher and longer than ever before. Drones have already shaken up warfare, recently playing a prominent role in the war in Ukraine. But militaries have long sought craft that can provide intelligence at a height beyond the reach of most radar and missile-defense systems, and for extended periods. For commercial users, high-altitude drones can be a way to beam internet services into areas with low connectivity.

A handful of military drones have for years operated at some 60,000 feet, far higher than jumbo jets. Now companies are developing craft that can go even higher and stay there for months, offering a cheaper and more flexible alternative to satellites. BAE Systems, the British weapons maker that produced the drone that flew in New Mexico, said its solar-powered craft is designed to stay in the air for as long as a year. "It allows us to enter the race to operationalize the stratosphere," said Dave Corfield, chief executive of Prismatic, the BAE unit that developed the drone. In the recent test flight, the PHASA-35 drone climbed above 65,000 feet and flew for 24 hours before landing. It is expected to enter service as soon as late 2026. Elsewhere, a unit of plane maker Airbus has developed a drone called the Zephyr that has already flown up to 70,000 feet for 64 days.
Networking

Li-Fi, Light-Based Networking Standard Released (tomshardware.com) 87

An anonymous reader quotes a report from Tom's Hardware: Today, the Institute of Electrical and Electronics Engineers (IEEE) has added 802.11bb as a standard for light-based wireless communications. The publishing of the standard has been welcomed by global Li-Fi businesses, as it will help speed the rollout and adoption of the data-transmission technology standard. Advantages of using light rather than radio frequencies (RF) are highlighted by Li-Fi proponents including pureLiFi, Fraunhofer HHI, and the Light Communications 802.11bb Task Group. Li-Fi is said to deliver "faster, more reliable wireless communications with unparalleled security compared to conventional technologies such as Wi-Fi and 5G." Now that the IEEE 802.11bb Li-Fi standard has been released, it is hoped that interoperability between Li-Fi systems with the successful Wi-Fi will be fully addressed.

Of course, Li-Fi isn't going to sweep away Wi-Fi and 5G alternatives (nor wired networks). Radio waves still have a distinct advantage with regard to transmission through the atmosphere at great distance, and though opaque objects. Instead, work must concentrate on using horses for courses -- with Li-Fi advantages being harvested where possible. [...] Now the IEEE 802.11bb standard is published, manufacturers can have greater confidence in the ecosystem and start integrating the tech, where suitable. One of the big wheels of Li-Fi, pureLiFi, has already prepared the Light Antenna ONE module for integration into connected devices. This 14.5mm long component is currently being provided to OEMs for evaluation. In its promotional materials the firm suggests that Li-Fi is preferable over Wi-Fi for: more connections without congestion, greater security and privacy, and doing the heavy lifting for the highest bandwidth tasks. We expect to see a far fuller gamut of Li-Fi network devices, and user devices which support the standard, emerge between now and MWC next February.

Privacy

SEO Expert Hired and Fired By Ashley Madison Turned on Company, Promising Revenge (krebsonsecurity.com) 28

In July 2015, the marital infidelity website AshleyMadison.com was hacked by a group called the Impact Team, threatening to release data on all 37 million users unless the site shut down. In an article published earlier today, security researcher Brian Krebs explores the possible involvement of a former employee and self-describe expert in search engine optimization (SEO), William Brewster Harrison, who had a history of harassment towards then-CEO Noel Biderman and may have had the technical skills to carry out the hack. However, Harrison committed suicide in 2014, raising doubts about his role in the breach. Here's an excerpt from the report: [...] Does Harrison's untimely death rule him out as a suspect, as his stepmom suggested? This remains an open question. In a parting email to Biderman in late 2012, Harrison signed his real name and said he was leaving, but not going away. "So good luck, I'm sure we'll talk again soon, but for now, I've got better things in the oven," Harrison wrote. "Just remember I outsmarted you last time and I will outsmart you and out maneuver you this time too, by keeping myself far far away from the action and just enjoying the sideline view, cheering for the opposition." Nothing in the leaked Biderman emails suggests that Ashley Madison did much to revamp the security of its computer systems in the wake of Harrison's departure and subsequent campaign of harassment -- apart from removing an administrator account of his a year after he'd already left the company.

KrebsOnSecurity found nothing in Harrison's extensive domain history suggesting he had any real malicious hacking skills. But given the clientele that typically employed his skills -- the adult entertainment industry -- it seems likely Harrison was at least conversant in the dark arts of "Black SEO," which involves using underhanded or else downright illegal methods to game search engine results. Armed with such experience, it would not have been difficult for Harrison to have worked out a way to maintain access to working administrator accounts at Ashley Madison. If that in fact did happen, it would have been trivial for him to sell or give those credentials to someone else. Or to something else. Like Nazi groups. As KrebsOnSecurity reported last year, in the six months leading up to the July 2015 hack, Ashley Madison and Biderman became a frequent subject of derision across multiple neo-Nazi websites.

Some readers have suggested that the data leaked by the Impact Team could have originally been stolen by Harrison. But that timeline does not add up given what we know about the hack. For one thing, the financial transaction records leaked from Ashley Madison show charges up until mid-2015. Also, the final message in the archive of Biderman's stolen emails was dated July 7, 2015 -- almost two weeks before the Impact Team would announce their hack. Whoever hacked Ashley Madison clearly wanted to disrupt the company as a business, and disgrace its CEO as the endgame. The Impact Team's intrusion struck just as Ashley Madison's parent was preparing go public with an initial public offering (IPO) for investors. Also, the hackers stated that while they stole all employee emails, they were only interested in leaking Biderman's. Also, the Impact Team had to know that ALM would never comply with their demands to dismantle Ashley Madison and Established Men. In 2014, ALM reported revenues of $115 million. There was little chance the company was going to shut down some of its biggest money machines. Hence, it appears the Impact Team's goal all along was to create prodigious amounts of drama and tension by announcing the hack of a major cheating website, and then let that drama play out over the next few months as millions of exposed Ashley Madison users freaked out and became the targets of extortion attacks and public shaming.

After the Impact Team released Biderman's email archives, several media outlets pounced on salacious exchanges in those messages as supposed proof he had carried on multiple affairs. Biderman resigned as CEO of Ashley Madison on Aug. 28, 2015. Complicating things further, it appears more than one malicious party may have gained access to Ashley's Madison's network in 2015 or possibly earlier. Cyber intelligence firm Intel 471 recorded a series of posts by a user with the handle "Brutium" on the Russian-language cybercrime forum Antichat between 2014 and 2016. Brutium routinely advertised the sale of large, hacked databases, and on Jan. 24, 2015, this user posted a thread offering to sell data on 32 million Ashley Madison users. However, there is no indication whether anyone purchased the information. Brutium's profile has since been removed from the Antichat forum.
Note: This is Part II of a story published last week on reporting that went into a new Hulu documentary series on the 2015 Ashley Madison hack.

Slashdot Top Deals