Cellphones

As Wireless Carriers 'Rip and Replace' Chinese-Made Telecom Equipment, Who Pays? (sanjuandailystar.com) 82

"Deep in a pine forest in Wilcox County, Alabama, three workers dangled from the top of a 350-foot cellular tower," reports the New York Times. "They were there to rip out and replace Chinese equipment from the local wireless network..." As the United States and China battle for geopolitical and technological primacy, the fallout has reached rural Alabama and small wireless carriers in dozens of states. They are on the receiving end of the Biden administration's sweeping policies to suppress China's rise, which include trade restrictions, a $52 billion package to bolster domestic semiconductor manufacturing against China and the divestiture of the video app TikTok from its Chinese owner. What the wireless carriers must do, under a program known as "rip and replace," has become the starkest physical manifestation of the tech Cold War between the two superpowers. The program, which took effect in 2020, mandates that American companies tear out telecom equipment made by the Chinese companies Huawei and ZTE. U.S. officials have warned that gear from those companies could be used by Beijing for espionage and to steal commercial secrets.

Instead, U.S. carriers have to use equipment from non-Chinese companies. The Federal Communications Commission, which oversees the program, would then reimburse the carriers from a pot of $1.9 billion intended to cover their costs. Similar rip-and-replace efforts are taking place elsewhere. In Europe, where Huawei products have been a key part of telecom networks, carriers in Belgium, Britain, Denmark, the Netherlands and Sweden have also been swapping out the Chinese equipment because of security concerns, according to Strand Consult, a research firm that tracks the telecom industry. "Rip-and-replace was the first front in a bigger story about the U.S. and China's decoupling, and that story will continue into the next decade with a global race for A.I. and other technologies," said Blair Levin, a former F.C.C. chief of staff and a fellow at the Brookings Institution.

But cleansing U.S. networks of Chinese tech has not been easy. The costs have already ballooned above $5 billion, according to the F.C.C., more than double what Congress appropriated for reimbursements. Many carriers also face long supply chain delays for new equipment. The program's burden has fallen disproportionately on smaller carriers, which relied more on the cheaper gear from the Chinese firms than large companies like AT&T and Verizon. Given rip-and-replace's difficulties, some smaller wireless companies now say they may not be able to upgrade their networks and continue serving their communities, where they are often the only internet providers. "For many rural communities, they are faced with the disastrous choice of having to continue to use insecure networks that are ripe for surveillance or having to cut off their services," said Geoffrey Starks, a Democratic commissioner at the F.C.C.

Last month, Senator Deb Fischer, a Republican of Nebraska, introduced a bill to close the gap in rip-and-replace funding for carriers... In January, the F.C.C. said it had received 126 applications seeking funding beyond what it could reimburse. Lawmakers had underestimated the costs of shredding Huawei and ZTE equipment, and new equipment and labor costs have risen. The F.C.C. said it could cover only about 40 percent of the expenses. Some wireless carriers immediately paused their replacement efforts. "Until we have assurance of total project funding, this project will continue to be delayed as we await the necessary funding required to build and pay for the new network equipment," United Wireless of Dodge City, Kansas, wrote in a regulatory filing to the F.C.C. in January.

Transportation

Lithium-Ion Battery Fires on Aircraft are Happening 'Much More Frequently' (cbsnews.com) 86

As smoke began filling the cabin, an airplane passenger saw sparks and fire bursting from a bag in the seat directly behind her — which turned out to be a "smoky flashing lithium battery, which had begun smoldering in a carry-on bag," according to CBS News.

The flight crew contained the situation, and "Airport fire trucks met the plane on the runway and everyone evacuated safely." But a CBS News Investigation "has discovered similar incidents have been happening much more frequently in the skies over the United States." The FAA verifies the number of lithium-Ion battery fires jumped more 42% in the last five years. A CBS News analysis of the FAA's data found that since 2021 there's been at least one lithium battery incident on a passenger plane somewhere in the U.S., on average, once every week...

Some airlines are taking action to control the growing number of fires. They are using specialized "thermal containment" bags designed for flight crews to use if a lithium battery starts heating up to the point where it's smoking or burning. Mechanical engineers at the University of Texas at Austin say the bags can effectively contain fire and keep it from spreading, but don't extinguish it.

In a video accompanying the article, an engineering professor at the university's Fire Research Group even showed a lithium-ion battery fire that continued burning undewater. "You can't put it out. It's a fire within the cell. So, you've got fuel, oxygen, heat in the cell, all." (The article also notes a startup called Pure Lithium is working on a new kind of non-flammable battery using lithium metal cells instead of lithium ion).

Guidelines from America's Federal Aviation Administration require spare lithium-ion batteries be kept with passengers (and not checked) — and prohibits passengers from bringing onboard damaged or recalled batteries and battery-powered devices.

Thanks to long-time Slashdot reader khb for sharing the article.
Government

Three Companies Faked Millions of Comments Supporting 2017 Repeal of 'Net Neutrality' Rules (yahoo.com) 77

Three companies "supplied millions of fake public comments to influence a 2017 proceeding by the Federal Communications Commission (FCC) to repeal net neutrality rules," announced New York's attorney general this week.

Their investigation "found that the fake comments used the identities of millions of consumers, including thousands of New Yorkers, without their knowledge or consent," as well as "widespread fraud and abusive practices" Collectively, the three companies have agreed to pay $615,000 in penalties and disgorgement. This is the second series of agreements secured by Attorney General James with companies that supplied fake comments to the FCC... As detailed in a report by the Office of the Attorney General, the nation's largest broadband companies funded a secret campaign to generate millions of comments to the FCC in 2017. These comments provided "cover" for the FCC to repeal net neutrality rules. To help generate these comments, the broadband industry engaged commercial lead generators that used advertisements and prizes, like gift cards and sweepstakes entries, to encourage consumers to join the campaign.

However, nearly every lead generator that was hired to enroll consumers in the campaign instead simply fabricated consumers' responses. As a result, more than 8.5 million fake comments that impersonated real people were submitted to the FCC, and more than half a million fake letters were sent to Congress. Two of the companies, LCX and Lead ID, were each engaged to enroll consumers in the campaign. Instead, each independently fabricated responses for 1.5 million consumers. The third company, Ifficient, acted as an intermediary, engaging other lead generators to enroll consumers in the campaign. Ifficient supplied its client with more than 840,000 fake responses it had received from the lead generators it had hired.

The Office of the Attorney General's investigation also revealed that the fraud perpetrated by the various lead generators in the net neutrality campaign infected other government proceedings as well. Several of the lead generation firms involved in the broadband industry's net neutrality comment campaigns had also worked on other, unrelated campaigns to influence regulatory agencies and public officials. In nearly all of these advocacy campaigns, the lead generation firms engaged in fraud. As a result, more than 1 million fake comments were generated for other rulemaking proceedings, and more than 3.5 million fake digital signatures for letters and petitions were generated for federal and state legislators and government officials across the nation.

LCX and Lead ID were responsible for many of these fake comments, letters, and petition signatures. Across four advocacy campaigns in 2017 and 2018, LCX fabricated consumer responses used in approximately 900,000 public comments submitted to the Environmental Protection Agency (EPA) and the Bureau of Ocean Energy Management (BOEM) at the U.S. Department of the Interior. Similarly, in advocacy campaigns between 2017 and 2019, Lead ID fabricated more than half a million consumer responses. These campaigns targeted a variety of government agencies and officials at the federal and state levels...

LCX and its principals will pay $400,000 in penalties and disgorgement to New York and $100,000 to the San Diego District Attorney's Office.

Thanks to Slashdot reader gkelley for sharing the news.
Social Networks

Former ByteDance Exec Claims CCP 'Maintained' Access to US Data (axios.com) 26

An anonymous Slashdot reader shared this report from Axios: The Chinese Communist Party "maintained supreme access" to data belonging to TikTok parent company ByteDance, including data stored in the U.S., a former top executive claimed in a lawsuit Friday...

In a wrongful dismissal suit filed in San Francisco Superior Court, Yintao Yu said ByteDance "has served as a useful propaganda tool for the Chinese Communist Party." Yu, whose claim says he served as head of engineering for ByteDance's U.S. offices from August 2017 to November 2018, alleged that inside the Beijing-based company, the CCP "had a special office or unit, which was sometimes referred to as the 'Committee'." The "Committee" didn't work for ByteDance but "played a significant role," in part by "gui[ding] how the company advanced core Communist values," the lawsuit claims... The CCP could also access U.S. user data via a "backdoor channel in the code," the suit states...

In an interview with the New York Times, which first reported the lawsuit, Yu said promoting anti-Japanese sentiment was done without hesitation.

"The allegations come as federal officials weigh the fate of the social media giant in the U.S. amid growing concerns over national security and data privacy," the article adds.

Yu also accused ByteDance of a years-long, worldwide "scheme" of scraping data from Instagram and Snapchat to post on its own services.
AI

Google Makes Its Text-To-Music AI Public (techcrunch.com) 16

An anonymous reader quotes a report from TechCrunch: Google [on Wednesday] released MusicLM, a new experimental AI tool that can turn text descriptions into music. Available in the AI Test Kitchen app on the web, Android or iOS, MusicLM lets users type in a prompt like "soulful jazz for a dinner party" or "create an industrial techno sound that is hypnotic" and have the tool create several versions of the song. Users can specify instruments like "electronic" or "classical," as well as the "vibe, mood, or emotion" they're aiming for, as they refine their MusicLM-generated creations.

When Google previewed MusicLM in an academic paper in January, it said that it had "no immediate plans" to release it. The coauthors of the paper noted the many ethical challenges posed by a system like MusicLM, including a tendency to incorporate copyrighted material from training data into the generated songs. But in the intervening months, Google says it's been working with musicians and hosting workshops to "see how [the] technology can empower the creative process." One of the outcomes? The version of MusicLM in AI Test Kitchen won't generate music with specific artists or vocals. Make of that what you will. It seems unlikely, in any case, that the broader challenges around generative music will be easily remedied.
You can sign up to try MusicLM here.
Android

Bluetooth Tags For Android's 3 Billion-Strong Tracking Network Are Here (arstechnica.com) 23

An anonymous reader quotes a report from Ars Technica: After the release of Apple's AirTags, Google suddenly has interest in the Bluetooth tracker market. The company has already quietly rolled out what must be the world's largest Bluetooth tracking network via Android's 3 billion active devices, and now trackers are starting to plug in to that network. Google is taking the ecosystem approach and letting various companies plug in to the Android Bluetooth tracking network, which has the very derivative name of "Find My Device." While these Bluetooth trackers are great for finding your lost car keys on a messy desk, they can also work as worldwide GPS trackers and locate items much farther away, even though they don't have GPS. The IDs of Bluetooth devices are public, so Tile started this whole idea of crowdsourced Bluetooth tracker location, called the "Tile Network." Every phone with the Tile app installed scans Bluetooth devices in the background and, using the phone GPS, uploads their last seen location to the cloud. This location data is only available to the person who owns the Tile, but every Tile user works to scan the environment and upload any Tiles the app can see. [...]

Now, third-party Bluetooth trackers for Android's network are starting to arrive. The two companies that have announced products are Chipolo and Pebblebee, both of which seem to be cloning the Tile line of products. Both offer normal keychain tracker tags and slim credit card format trackers. The worst habits of Tile include making completely disposable products because the batteries can't be changed, but it looks like our clones have mostly avoided that. All of Pebblebee's Find My Device products are rechargeable, which is great, while the Chipolo keychain tracker has a replaceable CR2032 battery. Only the Chipolo wallet tracker is disposable (boo!). All these tags will show up in the Find My Device app, right alongside your Android phones, headphones, and whatever else you have that plugs in to the network. They also have a speaker, like normal, so you can make them ring when you're near them. Both sets of products are up for preorder now.

Firefox

Microsoft Wants Firefox To Make Bing Its Default Search Engine (androidpolice.com) 52

According to The Information, Microsoft wants to bid to make Bing Firefox's default search engine. Android Police reports: The browser's contract with Google is set to expire this year, at which point Mozilla could either renew it or switch to a different search engine. Microsoft would very much like to take Google's place in Firefox. It's not a guarantee that it will actually help boost Bing's usage -- after all, Firefox users who don't want to use Bing could just switch to a different search engine, as Yahoo found out a few years ago -- but Microsoft sees potential in such a deal.

The report also notes that there's also a potentially more juicy opportunity coming up for Microsoft if it really wants to get serious about pushing Bing. Apple's Safari browser, which is the main web browser on Apple devices, will have its Google contract expire next year. Despite throwing shade constantly, Google really benefits from the deal it currently has with Apple, and Microsoft could sweep in and try to get Bing to become the main browser on iPhones.

Social Networks

Reddit Will Allow Users To Upload NSFW Images From Desktop 21

Ahead of Imgur's ban of sexually explicit content, Reddit announced Thursday that it will allow users to upload NSFW images from desktops in adult subreddits. The feature was already available on the social network's mobile app. TechCrunch reports: "This now gives us feature parity with our mobile apps, which (as you know) already has this functionality. You must set your community to 18+ if your community's content will primarily be not safe for work (NSFW)," the company said.

Reddit's announcement comes days after Imgur said that the image hosting platform was banning explicit photos from May 15. At that time, the company said that explicit content formed a risk to Imgur's "community and its business." Banning this type of content would "protect the future of the Imgur community." Many of Reddit's communities rely on Imgur's hosting services. However, the social network allowing native NSFW uploads through desktop might be the most logical solution going forward.
Security

Microsoft Will Take Nearly a Year To Finish Patching New 0-Day Secure Boot Bug (arstechnica.com) 48

An anonymous reader quotes a report from Ars Technica: Earlier this week, Microsoft released a patch to fix a Secure Boot bypass bug used by the BlackLotus bootkit we reported on in March. The original vulnerability, CVE-2022-21894, was patched in January, but the new patch for CVE-2023-24932 addresses another actively exploited workaround for systems running Windows 10 and 11 and Windows Server versions going back to Windows Server 2008. The BlackLotus bootkit is the first-known real-world malware that can bypass Secure Boot protections, allowing for the execution of malicious code before your PC begins loading Windows and its many security protections. Secure Boot has been enabled by default for over a decade on most Windows PCs sold by companies like Dell, Lenovo, HP, Acer, and others. PCs running Windows 11 must have it enabled to meet the software's system requirements.

Microsoft says that the vulnerability can be exploited by an attacker with either physical access to a system or administrator rights on a system. It can affect physical PCs and virtual machines with Secure Boot enabled. We highlight the new fix partly because, unlike many high-priority Windows fixes, the update will be disabled by default for at least a few months after it's installed and partly because it will eventually render current Windows boot media unbootable. The fix requires changes to the Windows boot manager that can't be reversed once they've been enabled. Additionally, once the fixes have been enabled, your PC will no longer be able to boot from older bootable media that doesn't include the fixes. On the lengthy list of affected media: Windows install media like DVDs and USB drives created from Microsoft's ISO files; custom Windows install images maintained by IT departments; full system backups; network boot drives including those used by IT departments to troubleshoot machines and deploy new Windows images; stripped-down boot drives that use Windows PE; and the recovery media sold with OEM PCs.

Not wanting to suddenly render any users' systems unbootable, Microsoft will be rolling the update out in phases over the next few months. The initial version of the patch requires substantial user intervention to enable -- you first need to install May's security updates, then use a five-step process to manually apply and verify a pair of "revocation files" that update your system's hidden EFI boot partition and your registry. These will make it so that older, vulnerable versions of the bootloader will no longer be trusted by PCs. A second update will follow in July that won't enable the patch by default but will make it easier to enable. A third update in "first quarter 2024" will enable the fix by default and render older boot media unbootable on all patched Windows PCs. Microsoft says it is "looking for opportunities to accelerate this schedule," though it's unclear what that would entail.

EU

EU Plans Black Sea Internet Cable To Reduce Reliance on Russia (ft.com) 71

The EU is planning an undersea internet cable to improve connectivity to Georgia and reduce dependence on lines running through Russia, amid growing concerns about vulnerabilities to infrastructure transmitting global data. From a report: The $49mn cable will link EU member states to the Caucasus via international waters in the Black Sea, stretching a span of 1,100km. The project aims to reduce the region's "dependency on terrestrial fibre-optic connectivity transiting via Russia," the European Commission said in a policy document. The EU and Georgia jointly identified the need for the Black Sea internet cable in 2021 to improve Georgia's digital connectivity. However, the war in Ukraine has added impetus to the project, given the need to avoid relying on "connections that are not secure or stable," said a person with knowledge of the proposal.

Internet cables have come under scrutiny because of global concerns around espionage, as land-based lines and the stations where submarine cables come ashore are seen as vulnerable to interception by governments, hackers and thieves. Concerns around intentional sabotage of undersea cables and other maritime infrastructure have also grown since multiple explosions on the Nord Stream gas pipelines last September, which media reports recently linked to Russian vessels. Two cables off the coast of Norway were cut in 2021 and 2022, sparking concerns about malicious attacks.

EU

Google Bard Isn't Available in Any European Union Countries and Canada (9to5google.com) 20

At I/O 2023 earlier this week, Google announced that it's expanding its AI chatbot Google Bard to 180 countries. However, what Google didn't mention is that Bard still isn't available in the European Union. From a report: On a support page, Google details the full list of 180 countries in which Bard is now available. This includes countries all over the globe, but very noticeably not any countries that are a part of the European Union. It's a big absence from what is otherwise a global expansion for Google's AI. The reason why isn't officially stated by Google, but it seems reasonable to believe that it's related to GDPR. Just last month, Italy briefly banned ChatGPT over similar concerns that the AI couldn't comply with the regulations. Google also slyly hints this might be the case saying that further Bard expansions will be made "consistent with local regulations."
Technology

US Chamber of Commerce Slams SEC, Backs Coinbase in Legal Fight (decrypt.co) 36

The U.S. Chamber of Commerce called out the Securities and Exchange Commission (SEC) on Thursday, slamming the financial watchdog for its regulatory approach toward the digital asset industry. From a report: It filed an amicus brief in support of Coinbase, which took the SEC to court last month. The exchange wants a court to force the SEC to respond to its so-called "petition for rulemaking" filed last July. The petition asks the SEC to propose and adopt rules for digital assets and answer questions related to regulation. Now Coinbase has one of the largest business organizations in the world standing behind it.

The U.S. Chamber of Commerce represents the interests of more than 3 million businesses and organizations throughout the country, from small businesses to global corporations, according to its website. Amicus briefs are legal documents containing information or advice related to a specific court case and are provided by third parties. And the U.S. Chamber of Commerce accused the SEC of intentionally sewing uncertainty to keep the digital assets industry on ice. "The SEC has deliberately muddied the waters by claiming sweeping authority over digital assets while deploying a haphazard, enforcement-based approach," it wrote. "This regulatory chaos is by design, not happenstance."
Further reading: Coinbase CEO Says SEC is On 'Lone Crusade'
Security

Google Brings Dark Web Monitoring To All US Gmail Users (bleepingcomputer.com) 28

At Google I/O on Wednesday, Google said that all Gmail users in the U.S. will soon be able to discover if their email address has been found on the dark web. The dark web report security feature will roll out over the coming weeks, and will be expanded to select international markets. BleepingComputer reports: Once enabled, it will allow Gmail users to scan the dark web for their email addresses and take action to protect their data based on guidance provided by Google. For instance, they'll be advised to turn on two-step authentication to protect their Google accounts from hijacking attempts. Google will also regularly notify Gmail users to check if their email has been linked to any data breaches that ended up on underground cybercrime forums.

"Dark web report started rolling out in March 2023 to members across all Google One plans in the United States, providing a simple way to get notified when their personal information was discovered on the dark web. "Google One's dark web report helps you scan the dark web for your personal info -- like your name, address, email, phone number and Social Security number -- and will notify you if it's found," said Google One Director of Product Management Esteban Kozak in March when the feature was first announced. The company says all the personal info added to the profile can be deleted from the monitoring profile or by removing the profile in the dark web report settings.

AI

Will AI Become the New McKinsey? (newyorker.com) 29

Sci-fi writer Ted Chiang, writing for New Yorker: So, I would like to propose another metaphor for the risks of artificial intelligence. I suggest that we think about A.I. as a management-consulting firm, along the lines of McKinsey & Company. Firms like McKinsey are hired for a wide variety of reasons, and A.I. systems are used for many reasons, too. But the similarities between McKinsey -- a consulting firm that works with ninety per cent of the Fortune 100 -- and A.I. are also clear. Social-media companies use machine learning to keep users glued to their feeds. In a similar way, Purdue Pharma used McKinsey to figure out how to "turbocharge" sales of OxyContin during the opioid epidemic. Just as A.I. promises to offer managers a cheap replacement for human workers, so McKinsey and similar firms helped normalize the practice of mass layoffs as a way of increasing stock prices and executive compensation, contributing to the destruction of the middle class in America.

A former McKinsey employee has described the company as "capital's willing executioners": if you want something done but don't want to get your hands dirty, McKinsey will do it for you. That escape from accountability is one of the most valuable services that management consultancies provide. Bosses have certain goals, but don't want to be blamed for doing what's necessary to achieve those goals; by hiring consultants, management can say that they were just following independent, expert advice. Even in its current rudimentary form, A.I. has become a way for a company to evade responsibility by saying that it's just doing what âoethe algorithmâ says, even though it was the company that commissioned the algorithm in the first place.

Android

Android 14 Will Add More Customization To Your Home and Lock Screens 21

At Google I/O on Wednesday, VP of Engineering at Android David Burke new customization features coming to Android 14 later this year. Engadget reports: The tools build on the Material You design system Google introduced in 2021 by allowing users to create a custom wallpaper by picking a few of their favorite emojis. One of the new tools allows you to add up to 14 emojis to a single wallpaper. You can then pick a pattern and a color to bring everything together. Once the wallpaper is on your home screen, the characters will react when you tap on them. If you want something more sentimental, there's a separate option to create "Cinematic" wallpapers. The feature uses on-device neural networks to animate your favorite photos. Once the photo is on your home screen, tilting your device will cause it to move, giving the image more depth and life than it would have had you not used the new feature. Burke said both cinematic and emoji wallpapers would arrive on Pixel devices next month.

Come the fall, Google will also introduce a built-in AI image generator within Android's customization menu. You can use the tool to create wallpapers you can't find online. It comes with pre-populated prompts you can tweak to make the process of guiding the AI easier. Once you add an AI wallpaper to your home screen, Android's Material You system will automatically color-match all the user interface elements, including any app icons, so they don't clash with one another. Android 14 will further augment those tools with the addition of new clocks and shortcuts you can add to your lock screen. And if colors aren't your thing, Google also plans to add a new monochromatic theme for those who prefer a more understated look. At I/O, Burke also previewed Magic Compose, a Messages feature that will use Google's generative AI technology to write texts for you. The tool comes with multiple style settings you can use to give your messages a different flair. Google plans to beta test Magic Compose this summer. Separately, Google said after the keynote that Android 14 will add support for Ultra HDR, allowing for photos that feature more vivid colors and detailed shadows.
Windows

First Rust Code Shows Up in the Windows 11 Kernel 42

According to Azure CTO Mark Russinovich, the most recent Windows 11 Insider Preview build is the first to include the memory-safe programming language Rust. Thurrott reports: "If you're on the Win11 Insider ring, you're getting the first taste of Rust in the Windows kernel," Russinovich tweeted last night. It's not clear which Insider channel he is referring to, however.

Regardless, that that was quick: Microsoft only went public with its plans to replace parts of the Windows kernel with Rust code in mid-April at its BlueHat IL 2023 security conference in Israel. At that event, Microsoft vice president David Weston said that "we're using Rust on the operating system along with other constructs" as part of an "aggressive and meaningful pursuit of memory safety," a key source of exploits. And it's not just the Windows kernel. Microsoft is bringing Rust to its Pluton security processor as well.
IT

Leak of MSI UEFI Signing Keys Stokes Fears of 'Doomsday' Supply Chain Attack (arstechnica.com) 62

A ransomware intrusion on hardware manufacturer Micro-Star International, better known as MSI, is stoking concerns of devastating supply chain attacks that could inject malicious updates that have been signed with company signing keys that are trusted by a huge base of end-user devices, a researcher said. From a report: "It's kind of like a doomsday scenario where it's very hard to update the devices simultaneously, and they stay for a while not up to date and will use the old key for authentication," Alex Matrosov, CEO, head of research, and founder of security firm Binarly, said in an interview. "It's very hard to solve, and I don't think MSI has any backup solution to actually block the leaked keys."

The intrusion came to light in April when, as first reported by Bleeping Computer, the extortion portal of the Money Message ransomware group listed MSI as a new victim and published screenshots purporting to show folders containing private encryption keys, source code, and other data. A day later, MSI issued a terse advisory saying that it had "suffered a cyberattack on part of its information systems." The advisory urged customers to get updates from the MSI website only. It made no mention of leaked keys. Since then, Matrosov has analyzed data that was released on the Money Message site on the dark web. To his alarm, included in the trove were two private encryption keys. The first is the signing key that digitally signs MSI firmware updates to cryptographically prove that they are legitimate ones from MSI rather than a malicious impostor from a threat actor. This raises the possibility that the leaked key could push out updates that would infect a computer's most nether regions without triggering a warning. To make matters worse, Matrosov said, MSI doesn't have an automated patching process the way Dell, HP, and many larger hardware makers do. Consequently, MSI doesn't provide the same kind of key revocation capabilities.

Businesses

Tech Startups Find One of Their Last Funding Sources Is Drying Up (bloomberg.com) 27

A key form of financing that startups rely on is shrinking, hurting new companies that are already starved for capital. From a report: The volume of venture debt, a type of loan that younger companies line up to help pay the bills, plunged to $3.5 billion in the US in the first quarter, according to PitchBook, the lowest level since 2017. Climbing interest rates have made the funding more expensive for companies, and one of the biggest venture lenders, Silicon Valley Bank, faced a run on the bank that forced government regulators to seize it and sell it.

First Citizens BancShares, Silicon Valley Bank's buyer, says its appetite for venture financing hasn't changed. On a conference call on Wednesday, the company's president said First Citizens is better positioned to serve venture-backed companies now. But many of the biggest lenders across the economy are less willing to take risk as economic growth slows. Companies drove venture lending to record levels last year as revenue was under pressure and other forms of financing were drying up. VCs pulled back dramatically on equity investments in the second half of 2022, squeezed by rising interest rates and falling market values across the tech industry. By the first quarter of 2023, venture firms invested $79 billion in startups, less than half the $178 billion a year earlier, according to PitchBook. Raising equity in public markets is harder too: There were just $2.5 billion of initial public offerings in the US in the first quarter, the lowest for the first three months of the year since 2016, according to data compiled by Bloomberg.

AI

AI Needs Specialized Processors. Crypto Miners Say They Have Them (bloomberg.com) 23

When the Ethereum blockchain moved away from using a technique for verifying transactions known as proof of work last September, crypto market demand for the specialized processors that performed these calculations disappeared virtually overnight. Companies that used and hosted GPUs, or graphics processing units, saw a key part of their once-booming business vanish against an increasingly difficult backdrop for crypto. But now mining infrastructure companies like Hive Blockchain and Hut 8 Mining are finding opportunities to repurpose their GPU-based equipment for another industry on the precipice of a possible boom: artificial intelligence. From a report: "If you can reapply some of that investment in the GPU mining infrastructure and convert it to new cards and workloads, it makes sense," Hut 8 Chief Executive Officer Jaime Leverton said in an interview. GPUs -- designed to accelerate graphics rendering -- require constant maintenance and physical infrastructure not all users are prepared to provide. As such, Hut 8 and a few other miners have been using the chips to power high-performance computing, or HPC, services for clients across a range of industries. But inroads with the burgeoning and much-hyped AI sector -- which requires huge amounts of computing power -- represent the kind of transformational opportunity miners had been seeking when they originally bought the processors.
Android

Google's New Pixel Tablet Is a $500 Slate For the Home (theverge.com) 81

Google has announced the Pixel Tablet after teasing it during last year's Google I/O conference. The Verge reports: The Pixel Tablet is designed from the ground up to be good at what people typically use tablets for: watching video or playing games in the comfort of their own home. It is not, however, making any statements about the future of computing. The looks of the Pixel Tablet are relatively generic. It has an 11-inch, 16:10, 2560 x 1600 pixel LCD display, even bezels all around, and a matte back. It comes in three colors: white, dark green, and light pink, with the dark green model featuring a black bezel. Though it looks like plastic from a distance, the Pixel Tablet has an aluminum frame with a nanotexture coating, not unlike what Google did with the Pixel 5 smartphone.

Bundled in the box with the Pixel Tablet is a magnetic speaker dock. This serves multiple purposes and is meant to prevent the dreaded "dead tablet in a drawer" syndrome: it's a place to store the Pixel Tablet when it's not in use; it charges the battery; and it has a louder, fuller speaker better suited for communal listening than the speakers that are built into the tablet. If you're playing music or watching a video on the tablet when you put it on the dock, it will seamlessly transfer the audio to the dock's speaker. Pull the tablet off the dock while something is playing, and it will instantly switch to the tablet's speakers.

When mounted on the speaker dock, the Pixel Tablet looks an awful lot like the Nest Hub Max, a $250 smart display that Google released back in 2019. But make no mistake, the Pixel Tablet is an Android tablet and not a smart display -- it runs completely different software and has different capabilities compared to the Nest Hub. That said, when the tablet is docked on the speaker, it can show a slideshow of images from your Google Photos albums just like the Nest Hub. It also has a quick access button to the Google Home app so you can control smart home devices, and it can accept voice commands from a distance for hands-free Google Assistant queries. The lock screen won't show any personal information like notifications -- for that, you'll have to unlock the tablet to access the accounts that are set up on it.
The $499 slab is available for preorder starting today, and will begin shipping on June 20th.

Slashdot Top Deals