
How Electric Cars are Already Upending America (msn.com) 472

"Electric cars are already upending America," argues a new article in the Atlantic, citing booming sales and new models that are "finally starting to push us into the post-gas age." Americans are on track to buy a record 1.44 million of them in 2023, according to a forecast by BloombergNEF, about the same number sold from 2016 to 2021 total. "This was the year that EVs went from experiments, or technological demonstrations, and became mature vehicles," Gil Tal, the director of the Electric Vehicle Research Center at UC Davis, told me.... Nearly 40 new EVs have debuted since the start of 2022, and they are far more advanced than their ancestors. For $40,000, the Hyundai Ioniq 6, released this year, can get you 360 miles on a single charge; in 2018, for only a slightly lower cost, a Nissan Leaf couldn't go half that distance....

All of these EVs are genuinely great for the planet, spewing zero carbon from their tailpipes, but that's only a small part of what makes them different. In the EV age, cars are no longer just cars. They are computers... The million-plus new EVs on the road are ushering in a fundamental, maybe existential, change in how to even think about cars — no longer as machines, but as gadgets that plug in and charge like all the others in our life. The wonderful things about computers are coming to cars, and so are the terrible ones: apps that crash. Subscription hell. Cyberattacks... If cars are gadgets now, then carmakers are also now tech companies. An industry that has spent a century perfecting the internal combustion engine must now manufacture lithium-ion batteries and write the code to govern them. Imagine if a dentist had to pivot from filling cavities to performing open-heart surgery, and that's roughly what's going on here.

"The transition to EVs is completely changing everything," Loren McDonald, an EV consultant, told me. "It's changing the people that automotive companies have to hire and their skills. It's changing their suppliers, their factories, how they assemble and build them. And lots of automakers are struggling with that...." Job cuts are already happening, and more may come — even after the massive autoworker strike this year that largely hinged on electrification. Such a big financial investment is needed to electrify the car industry that from July to September, Ford lost $60,000 for every EV it sold. Or peel back one more onion layer to car dealerships: Tesla, Rivian, and other EV companies are selling directly to consumers, cutting them out. EVs also require little service compared with gas vehicles, a reality that has upset many dealers, who could lose their biggest source of profit.

None of this is the future. It is happening right now.

Open Source

2023 and 'the Eternal Struggle Between Proprietary and Open Source Software' (techcrunch.com) 55

TechCrunch argues that in 2023, "established technologies relied on by millions hit a chaos curve, making people realize how beholden they are to a proprietary platform they have little control over." The OpenAI fiasco in November, where the ChatGPT hit-maker temporarily lost its co-founders, including CEO Sam Altman, created a whirlwind five days of chaos culminating in Altman returning to the OpenAI hotseat. But only after businesses that had built products atop OpenAI's GPT-X large language models (LLMs) started to question the prudence of going all-in on OpenAI, with "open" alternatives such as Meta's Llama-branded family of LLMs well-positioned to capitalize.

Even Google seemingly acknowledged that "open" might trump "proprietary" AI, with a leaked internal memo penned by a researcher that expressed fears that open source AI was on the front foot. "We have no moat, and neither does OpenAI," the memo noted.

Elsewhere, Adobe's $20 billion megabucks bid to buy rival Figma — a deal that eventually died due to regulatory headwinds — was a boon for open source Figma challenger Penpot, which saw signups surge amid a mad panic that Adobe might be about to unleash a corporate downpour on Figma's proverbial parade. And when cross-platform game engine Unity unveiled a controversial new fee structure, developers went berserk, calling the changes destructive and unfair. The fallout caused Unity to do a swift about turn, but only after a swathe of the developer community started checking out open source rival Godot, which also now has a commercial company driving core development.

Thanks to wiggles (Slashdot reader #30,088) for sharing the article.

Documentarians Secure Original 'ReBoot' Master Tapes, But Need Help To Play Them (globalnews.ca) 60

"Predating even Toy Story, ReBoot was the first 3D animated television show," writes longtime Slashdot reader sandbagger, sharing a new report from Global News. "The master tapes have been located in storage but the hardware needed to play the 1990s-era media has yet to be located." From the report: Produced in Vancouver by Mainframe Entertainment, it aired on YTV between 1994 and 2001, and decades later still has a committed fan base. Among those super fans are Jacob Weldon and Raquel Lin, a B.C. duo now crafting a documentary about the creation of the show and its impact in the film and TV world. Weldon said he wants to see ReBoot recognized for its place in the evolution of computer animation -- recognition he said it rarely gets.

When ReBoot was finally cancelled -- cut short in its fourth and final season -- its protagonists were left in peril and the show ended on a cliffhanger. It's another factor that Lin and Weldon say has helped immortalize the show and has helped fans hoping for a revival that might finally explain the characters' fate. Earlier this month, the documentary also got a potential major boost. Mainframe allowed Lin and Weldon to come to the studio to look for the show's original master tapes, recordings some believed might have been permanently lost. They struck gold. "They had boxes upon boxes upon boxes, hundreds of tapes," Lin said. "It's original resolution, original frame rate, uncompressed. If we could get a deck to play these, they would look beautiful," Weldon said.

Finding that deck, however, is the pair's next major challenge. The recordings are on a rare digital tape format called D1, a technology that Weldon said was cutting edge and rare when Mainframe was using it. It's even harder to find today, and even Mainframe doesn't have the equipment to play the tapes back. Weldon and Lin have since put out a call on social media for a working Bosch BTS D1 deck that would allow them to play the tapes, and incorporate them into their documentary. "I can't tell you how many people have called us, DM'd us, emailed us -- people from all over the world," Lin said. While the pair still haven't secured the deck, they're aiming to release their documentary by next summer. They're hoping it will help renew interest in the show, introduce it to new generations and perhaps see it get new life on a streaming platform.


AI-Created 'Virtual Influencers' Are Stealing Business From Humans (ft.com) 122

An anonymous reader quotes a report from the Financial Times: Pink-haired Aitana Lopez is followed by more than 200,000 people on social media. She posts selfies from concerts and her bedroom, while tagging brands such as haircare line Olaplex and lingerie giant Victoria's Secret. Brands have paid about $1,000 a post for her to promote their products on social media -- despite the fact that she is entirely fictional. Aitana is a "virtual influencer" created using artificial intelligence tools, one of the hundreds of digital avatars that have broken into the growing $21 billion content creator economy. Their emergence has led to worry from human influencers their income is being cannibalized and under threat from digital rivals. That concern is shared by people in more established professions that their livelihoods are under threat from generative AI -- technology that can spew out humanlike text, images and code in seconds. But those behind the hyper-realistic AI creations argue they are merely disrupting an overinflated market.

"We were taken aback by the skyrocketing rates influencers charge nowadays. That got us thinking, 'What if we just create our own influencer?'" said Diana Nunez, co-founder of the Barcelona-based agency The Clueless, which created Aitana. "The rest is history. We unintentionally created a monster. A beautiful one, though." Over the past few years, there have been high-profile partnerships between luxury brands and virtual influencers, including Kim Kardashian's make-up line KKW Beauty with Noonoouri, and Louis Vuitton with Ayayi. Instagram analysis of an H&M advert featuring virtual influencer Kuki found that it reached 11 times more people and resulted in a 91 per cent decrease in cost per person remembering the advert, compared with a traditional ad. "It is not influencing purchase like a human influencer would, but it is driving awareness, favorability and recall for the brand," said Becky Owen, global chief marketing and innovation officer at Billion Dollar Boy, and former head of Meta's creator innovations team.
"Influencers themselves have a lot of negative associations related to being fake or superficial, which makes people feel less concerned about the concept of that being replaced with AI or virtual influencers," said Rebecca McGrath, associate director for media and technology at Mintel.

"For a brand, they have total control versus a real person who comes with potential controversy, their own demands, their own opinions," McGrath added.

Fake Plane Parts Scandal Shows Peril of Antiquated Paper System (bloomberg.com) 39

After falsified records for spare aircraft parts set off a frantic global search for suspect pieces, the aviation industry now faces another daunting task: adapting the archaic paperwork for 100 million components to the digital age. From a report: Since the middle of the year, maintenance shops and aerospace manufacturers have found thousands of engine parts with falsified records linked to a distributor called AOG Technics. Airlines from China to the US and Europe have had to pull planes from service and extract the dubious components, leaving jets grounded and racking up millions of dollars in costs.

The episode has prodded carriers and maintenance shops to bolster scrutiny of their vendors and the parts they receive. And it's given fresh weight to an ongoing push to digitize the paper-based records still prevalent in the industry to document the lifespan of every piece of an aircraft from the time that it's made to when it lands in a scrap heap. But any structural reforms to thwart would-be copycats of the scheme of which AOG is suspected are likely years away. The industry is accustomed to following standardized methods and only making fundamental changes after a detailed and often lengthy examination of potential safety risks -- and costs.


Korea To Launch New 'Digital Nomad' Visa on Jan 1 (koreaherald.com) 7

South Korea will start issuing new "digital nomad" visas starting Monday, which will allow some foreign residents to stay for up to two years while maintaining a job back home, officials said Friday. From a report: "To make remote work and vacation of foreigners in Korea smoother, we have decided to launch a new digital nomad visa," the Justice Ministry said, highlighting the rise of the "workcation" trend, where employees work remotely from a different location. "So far, foreigners were required to apply for tourist visas or just stay for less than 90 days without a visa for workcation in Korea. The new system will allow employees and employers in overseas firms to tour and work remotely in Korea for a longer period of time," it added.

Those seeking to apply must submit documents to the Korean embassy in their respective country proving that they earn an annual income of over 84.96 million won ($65,860). The figure is double the amount of Korea's gross national income per capita as of 2022, which stood at 42.48 million won. Applicants must submit additional documents including verification of employment, details of their criminal record and proof of private health insurance. They are required to hold private health insurance with coverage of at least 100 million won to ensure the ability to travel back home in an emergency situation. Applicants must also be 18 or older and have worked in their current field for at least a year.


EU Competition Chief Defends AI Act After Macron's Attack (ft.com) 10

The EU's competition and digital chief has defended the bloc's landmark law on AI, saying the move would create "legal certainty" for tech start-ups building the technology, even as it comes under fire from critics including French President Emmanuel Macron. From a report: Margrethe Vestager told the Financial Times that the EU's proposed AI Act would "not harm innovation and research, but actually enhance it." That is because the legislation, for the first time, provides a clear set of rules for those building so-called foundation models -- the technology that underpins generative AI products such as OpenAI's ChatGPT, which can churn out humanlike text, images and code in seconds.

"[The AI Act] creates predictability and legal certainty in the market when things are put to use," said Vestager, the commission's executive vice-president who oversees competition and the EU's strategy dubbed "Europe fit for the digital age." She added: "If you do foundational models, but also if you want to apply foundational models, you know exactly what you are going to look for once it is put into use. It is important that you do not have any regulatory over-reach, that innovation and research is promoted again." Her defence of the AI Act comes after Macron argued the legislation risks leaving European tech companies lagging behind those based in the US and China.


India Targets Apple Over Its Phone Hacking Notifications (washingtonpost.com) 100

In October, Apple issued notifications warning over a half dozen India lawmakers of their iPhones being targets of state-sponsored attacks. According to a new report from the Washington Post, the Modi government responded by criticizing Apple's security and demanding explanations to mitigate political impact (Warning: source may be paywalled; alternative source). From the report: Officials from the ruling Bharatiya Janata Party (BJP) publicly questioned whether the Silicon Valley company's internal threat algorithms were faulty and announced an investigation into the security of Apple devices. In private, according to three people with knowledge of the matter, senior Modi administration officials called Apple's India representatives to demand that the company help soften the political impact of the warnings. They also summoned an Apple security expert from outside the country to a meeting in New Delhi, where government representatives pressed the Apple official to come up with alternative explanations for the warnings to users, the people said. They spoke on the condition of anonymity to discuss sensitive matters. "They were really angry," one of those people said.

The visiting Apple official stood by the company's warnings. But the intensity of the Indian government effort to discredit and strong-arm Apple disturbed executives at the company's headquarters, in Cupertino, Calif., and illustrated how even Silicon Valley's most powerful tech companies can face pressure from the increasingly assertive leadership of the world's most populous country -- and one of the most critical technology markets of the coming decade. The recent episode also exemplified the dangers facing government critics in India and the lengths to which the Modi administration will go to deflect suspicions that it has engaged in hacking against its perceived enemies, according to digital rights groups, industry workers and Indian journalists. Many of the more than 20 people who received Apple's warnings at the end of October have been publicly critical of Modi or his longtime ally, Gautam Adani, an Indian energy and infrastructure tycoon. They included a firebrand politician from West Bengal state, a Communist leader from southern India and a New Delhi-based spokesman for the nation's largest opposition party. [...] Gopal Krishna Agarwal, a national spokesman for the BJP, said any evidence of hacking should be presented to the Indian government for investigation.

The Modi government has never confirmed or denied using spyware, and it has refused to cooperate with a committee appointed by India's Supreme Court to investigate whether it had. But two years ago, the Forbidden Stories journalism consortium, which included The Post, found that phones belonging to Indian journalists and political figures were infected with Pegasus, which grants attackers access to a device's encrypted messages, camera and microphone. In recent weeks, The Post, in collaboration with Amnesty, found fresh cases of infections among Indian journalists. Additional work by The Post and New York security firm iVerify found that opposition politicians had been targeted, adding to the evidence suggesting the Indian government's use of powerful surveillance tools. In addition, Amnesty showed The Post evidence it found in June that suggested a Pegasus customer was preparing to hack people in India. Amnesty asked that the evidence not be detailed to avoid teaching Pegasus users how to cover their tracks.
"These findings show that spyware abuse continues unabated in India," said Donncha O Cearbhaill, head of Amnesty International's Security Lab. "Journalists, activists and opposition politicians in India can neither protect themselves against being targeted by highly invasive spyware nor expect meaningful accountability."

Infosys Loses Ten-Year, $1.5 Billion AI Contract (theregister.com) 23

Infosys has lost a ten-year, $1.5 billion deal it announced just three months ago in September 2023. From a report: The Indian services giant advised investors of the deal on September 14th, describing it as "a Memorandum of Understanding with a global company to provide enhanced digital experiences, along with modernization and business operations services, leveraging Infosys platforms & AI solutions" with a total client target spend of $1.5 billion over 15 years.

That announcement included the caveat that Infosys and the unnamed company would have to conclude a Master Agreement to seal the deal. A December 23rd filing revealed that didn't happen. "The global company has now elected to terminate the Memorandum of Understanding and the parties will not be pursuing the Master Agreement," the statement revealed. Infosys's annual revenue topped $18 billion last year, so losing this deal won't cause massive pain.


Employers Are Offering a New Worker Benefit: Wellness Chatbots (wsj.com) 61

More workers feeling anxious, stressed or blue have a new place to go for mental-health help: a digital app. Chatbots that hold therapist-like conversations and wellness apps that deliver depression and other diagnoses or identify people at risk of self-harm are snowballing across employers' healthcare benefits. From a report: "The demand for counselors is huge, but the supply of mental-health providers is shrinking," said J. Marshall Dye, chief executive officer of PayrollPlans, a Dallas-based provider of benefits software used by small and medium-size businesses, which began providing access to a chatbot called Woebot in November. PayrollPlans expects about 9,400 employers will use Woebot in 2024. Amazon about a year ago gave employees free access to Twill, an app that uses artificial intelligence to track the moods of users and create a personalized mental-health plan. The app offers games and other activities that the workers can play, as well as live chats with a human "coach."

The app "allows you to address mental health concerns the moment they arise and can be used as a supplement to your daily well-being routine," the company said in a blog post. Amazon declined to comment. About a third of U.S. employers offer a "digital therapeutic" for mental-health support, according to a survey of 457 companies this past summer by professional services company WTW. An additional 15% of the companies were considering adding such an offering in 2024 or 2025. Supporters say the mental-health apps alleviate symptoms such as anxiety, loneliness and depression. Because they are available at any time, the apps can also reach people who might not be able to fit traditional therapy into their schedules or can't find a therapist who has an opening. Yet some researchers say there isn't sufficient evidence the programs work, and the varied security and safety practices create a risk that private information could be leaked or sold.


Nigerian Central Bank Lifts Ban on Crypto Trading (reuters.com) 21

Nigeria's central bank has lifted a ban on transacting in cryptocurrencies, while saying global trends had shown a need to regulate such activities, the bank said in its latest circular. From a report: The Central Bank of Nigeria (CBN) in Feb. 2021 barred banks and financial institutions from dealing in or facilitating transactions in crypto assets, citing money laundering and terrorism financing risks. Subsequently Nigeria's Securities and Exchange Commission (SEC) in May last year published regulations for digital assets that signalled Africa's most populous country was trying to find a middle ground between an outright ban on crypto assets and their unregulated use.

In a circular dated Dec. 22, the CBN said current trends globally have shown there is a need to regulate the activities of virtual asset service providers (VASPs), which include cryptocurrencies and crypto assets. The latest guidelines spell out how banks and financial institutions (FI) should open accounts, provide designated settlement accounts and settlement services and act as channels for forex inflows and trade for firms transacting in crypto assets. VASPs would need to be licensed by the Nigerian SEC to engage in the crypto business.

United States

To Stem North Korea's Missiles Program, White House Looks To Its Hackers (politico.com) 19

The Biden administration has spent much of the last two years bracing key U.S. networks and infrastructure against crippling cyberattacks from Russia, Iran and China. But it is following a different playbook as it ramps up its efforts to thwart digital threats from North Korea: Follow the crypto -- and stop it. From a report: Convinced North Korea primarily sees hacking as a way to funnel money back to the cash-strapped Kim Jong Un regime, the White House has focused on blocking the country's ability to launder the cryptocurrency it steals through its cyberattacks. In the last year, the administration has unveiled a flurry of sanctions against North Korean hacking groups, front companies and IT workers, and blacklisted multiple cryptocurrency services they use to launder stolen funds. Earlier this month, national security adviser Jake Sullivan announced a new partnership with Japan and South Korea aimed at cracking down on Pyongyang's crypto bonanza -- thereby choking off money to its nuclear and conventional weapons programs.

"In countering North Korean cyber operations, our first priority has been focusing on their crypto heists," Anne Neuberger, the National Security Council's top cybersecurity official, said in an interview. The stepped-up effort to blunt North Korea's cyber operations is fueled by growing alarm about where the fruits of those attacks are going, Neuberger said. Hacking, she argued, has enabled North Korea to "either evade sanctions or evade the steps the international community has taken to target their weapons proliferation ... their missile regime, and the growth in the number of launches we've seen."

Electronic Frontier Foundation

EFF Warns: 'Think Twice Before Giving Surveillance for the Holidays' (eff.org) 28

"It's easy to default to giving the tech gifts that retailers tend to push on us this time of year..." notes Lifehacker senior writer Thorin Klosowski.

"But before you give one, think twice about what you're opting that person into." A number of these gifts raise red flags for us as privacy-conscious digital advocates. Ring cameras are one of the most obvious examples, but countless others over the years have made the security or privacy naughty list (and many of these same electronics directly clash with your right to repair). One big problem with giving these sorts of gifts is that you're opting another person into a company's intrusive surveillance practice, likely without their full knowledge of what they're really signing up for... And let's not forget about kids. Long subjected to surveillance from elves and their managers, electronics gifts for kids can come with all sorts of surprise issues, like the kid-focused tablet we found this year that was packed with malware and riskware. Kids' smartwatches and a number of connected toys are also potential privacy hazards that may not be worth the risks if not set up carefully.

Of course, you don't have to avoid all technology purchases. There are plenty of products out there that aren't creepy, and a few that just need extra attention during set up to ensure they're as privacy-protecting as possible. While we don't endorse products, you don't have to start your search in a vacuum. One helpful place to start is Mozilla's Privacy Not Included gift guide, which provides a breakdown of the privacy practices and history of products in a number of popular gift categories.... U.S. PIRG also has guidance for shopping for kids, including details about what to look for in popular categories like smart toys and watches....

Your job as a privacy-conscious gift-giver doesn't end at the checkout screen. If you're more tech savvy than the person receiving the item, or you're helping set up a gadget for a child, there's no better gift than helping set it up as privately as possible.... Giving the gift of electronics shouldn't come with so much homework, but until we have a comprehensive data privacy law, we'll likely have to contend with these sorts of set-up hoops. Until that day comes, we can all take the time to help those who need it.


'What Kind of Bubble Is AI?' (locusmag.com) 100

"Of course AI is a bubble," argues tech activist/blogger/science fiction author Cory Doctorow.

The real question is what happens when it bursts?

Doctorow examines history — the "irrational exuberance" of the dotcom bubble, 2008's financial derivatives, NFTs, and even cryptocurrency. ("A few programmers were trained in Rust... but otherwise, the residue from crypto is a lot of bad digital art and worse Austrian economics.") So would an AI bubble leave anything useful behind? The largest of these models are incredibly expensive. They're expensive to make, with billions spent acquiring training data, labelling it, and running it through massive computing arrays to turn it into models. Even more important, these models are expensive to run.... Do the potential paying customers for these large models add up to enough money to keep the servers on? That's the 13 trillion dollar question, and the answer is the difference between WorldCom and Enron, or dotcoms and cryptocurrency. Though I don't have a certain answer to this question, I am skeptical.

AI decision support is potentially valuable to practitioners. Accountants might value an AI tool's ability to draft a tax return. Radiologists might value the AI's guess about whether an X-ray suggests a cancerous mass. But with AIs' tendency to "hallucinate" and confabulate, there's an increasing recognition that these AI judgments require a "human in the loop" to carefully review their judgments... There just aren't that many customers for a product that makes their own high-stakes projects betÂter, but more expensive. There are many low-stakes applications — say, selling kids access to a cheap subscription that generates pictures of their RPG characters in action — but they don't pay much. The universe of low-stakes, high-dollar applications for AI is so small that I can't think of anything that belongs in it.

There are some promising avenues, like "federated learning," that hypothetically combine a lot of commodity consumer hardware to replicate some of the features of those big, capital-intensive models from the bubble's beneficiaries. It may be that — as with the interregnum after the dotcom bust — AI practitioners will use their all-expenses-paid education in PyTorch and TensorFlow (AI's answer to Perl and Python) to push the limits on federated learning and small-scale AI models to new places, driven by playfulness, scientific curiosity, and a desire to solve real problems. There will also be a lot more people who understand statistical analysis at scale and how to wrangle large amounts of data. There will be a lot of people who know PyTorch and TensorFlow, too — both of these are "open source" projects, but are effectively controlled by Meta and Google, respectively. Perhaps they'll be wrestled away from their corporate owners, forked and made more broadly applicable, after those corporate behemoths move on from their money-losing Big AI bets.

Our policymakers are putting a lot of energy into thinking about what they'll do if the AI bubble doesn't pop — wrangling about "AI ethics" and "AI safety." But — as with all the previous tech bubbles — very few people are talking about what we'll be able to salvage when the bubble is over.

Thanks to long-time Slashdot reader mspohr for sharing the article.

Remembering 'The Tech That Died in 2023' (pcmag.com) 117

"10 years later, the demise of Google Reader still stings," writes PC Magazine. But "Time marches on and corporate priorities shift. Here are the products and services that took a final bow in 2023..."

Some of the highlights? 'Clubhouse' Clones
In the early days of the pandemic, when Zoom happy hours and sourdough starters proliferated, Clubhouse burst onto the scene with an app that facilitated audio-only chats between groups large and small. Tech giants quickly churned out their own Clubhouse clones, but these party-line throwbacks were not long for this world. Facebook was the first to go, ditching its Live Audio Rooms in December 2022, but 2023 also saw the end of Reddit Talk, Spotify Live, and Amazon's live radio DJ Amp app. [X Spaces is still around]

Amazon Smile
Launched in 2013, AmazonSmile saw Amazon donate 0.5% of the price of eligible purchases made through smile.amazon.com to charity, with consumers able to choose from over a million charitable organizations to support. On Feb. 20, however, the program shut down because it "has not grown to create the impact that we had originally hoped," Amazon said at the time.

NFTs on Facebook and Instagram
Remember non-fungible tokens (NFTs)? Somehow, crypto bros convinced people to spend big bucks on what are essentially JPEGs. (Don't try to convince me otherwise.) Meta got in on the action in 2022, allowing Instagram users to create NFTs and Facebook users to share them. It didn't exactly set either social network on fire and Meta said in March it would be "winding down digital collectibles."

Cortana on Windows
In June, AI claimed its latest victim by coming after Microsoft's Cortana. The voice assistant never really made a splash compared to Amazon's Alexa or Apple's Siri, and with the launch of Bing Chat (now Copilot), Microsoft removed Cortana as a built-in app on Windows.

Also on the list are Blizzard's Overwatch League, third-party Reddit clients, and Venmo as a payment option on Amazon (effective this January 10).

Looking further into the future, Gmail's Basic HTML View disappears in 2024, while Wordpad will eventually be removed in an unspecified future release of Windows.
United States

US Water Utilities Hacked After Default Passwords Set to '1111', Cybersecurity Officials Say (fastcompany.com) 84

An anonymous reader shared this report from Fast Company: Providers of critical infrastructure in the United States are doing a sloppy job of defending against cyber intrusions, the National Security Council tells Fast Company, pointing to recent Iran-linked attacks on U.S. water utilities that exploited basic security lapses [earlier this month]. The security council tells Fast Company it's also aware of recent intrusions by hackers linked to China's military at American infrastructure entities that include water and energy utilities in multiple states.

Neither the Iran-linked or China-linked attacks affected critical systems or caused disruptions, according to reports.

"We're seeing companies and critical services facing increased cyber threats from malicious criminals and countries," Anne Neuberger, the deputy national security advisor for cyber and emerging tech, tells Fast Company. The White House had been urging infrastructure providers to upgrade their cyber defenses before these recent hacks, but "clearly, by the most recent success of the criminal cyberattacks, more work needs to be done," she says... The attacks hit at least 11 different entities using Unitronics devices across the United States, which included six local water facilities, a pharmacy, an aquatics center, and a brewery...

Some of the compromised devices had been connected to the open internet with a default password of "1111," federal authorities say, making it easy for hackers to find them and gain access. Fixing that "doesn't cost any money," Neuberger says, "and those are the kinds of basic things that we really want companies urgently to do." But cybersecurity experts say these attacks point to a larger issue: the general vulnerability of the technology that powers physical infrastructure. Much of the hardware was developed before the internet and, though they were retrofitted with digital capabilities, still "have insufficient security controls," says Gary Perkins, chief information security officer at cybersecurity firm CISO Global. Additionally, many infrastructure facilities prioritize "operational ease of use rather than security," since many vendors often need to access the same equipment, says Andy Thompson, an offensive cybersecurity expert at CyberArk. But that can make the systems equally easy for attackers to exploit: freely available web tools allow anyone to generate lists of hardware connected to the public internet, like the Unitronics devices used by water companies.

"Not making critical infrastructure easily accessible via the internet should be standard practice," Thompson says.

Social Networks

As Reddit CEO Defends Their Controversial API Decision, It Dominates Reddit's Own 'Recaps' (fastcompany.com) 52

"Reddit CEO Steve Huffman says that he stands by the company's decision to charge for API access," writes the blog 9to5Mac, "despite the fact that it was massively unpopular, and led to the demise of the leading Reddit app, Apollo." In an interview with FastCo, Huffman is unrepentant about the API decision, but says it could have been better communicated... "[H]e defended the company's decision to limit free access to its API as a necessary measure to foil AI-training freeloaders. 'Reddit is an open platform, and we love that,' he told me. 'At the same time, we have been taken advantage of by some of the largest companies in the world.'"
The incident ended up reappearing in Reddit's own "recap" pages showing highlights from its popular subreddits. For its Technology subreddit, the official recap shows that two most popular posts were "Apollo for Reddit is shutting down" and "Reddit sparks outrage after a popular app developer said it wants him to pay $20 million a year for data access."

And Reddit's official recap also shows that discussion leading to the second-most popular comment of the entire year for the subreddit. "Users supply all the content, and reddit turns around with this huge fuck you to its users, without whom it's just another crappy link aggregator. No, reddit, fuck you and your money grab."

The first most-popular comment appeared in a related discussion, headlined "Reddit Threatens to Remove Moderators From Subreddits Continuing Apollo-Related Blackouts." The comment?

Reddit: You're fired!
Moderator: I don't even work here.

The topic also dominated the official recap for the Programming subreddit, where it was the subject of all three of the top comments — and all three of the year's top posts:

Ironically, FastCo headlined its interview "As the AI era begins, Reddit is leaning into its humanity." ("Rebellious moderators. Large language models' peril and promise. Maybe a long-awaited IPO. Amid it all, Reddit CEO Steve Huffman says the web megacommunity is on a roll.") Other work has addressed concerns that bubbled to the surface during the moderator dust-up, such as accessibility issues: "I told the team, 'Just show up and ship,'" Huffman says. The official Reddit apps are finally compatible with screen readers used by users with vision impairments, with full compliance with the World Wide Web Consortium's accessibility guidelines planned by the end of 2024.

As for AI's potential to transform the Reddit experience, Huffman is less prone to exuberant overpromising than the average tech company CEO. But the same attributes that led third-party assemblers of large language models to crave access to the company's corpus of information could help it leverage the technology to its own benefit... Rather than involving the most obvious AI functionality, like a Reddit chatbot, the examples he provides relate to moderation of problem content. For instance, the latitude that individual moderators have to govern their communities means that they can set rules that Huffman describes as "sometimes strict and sometimes esoteric." Newbies may run afoul of them by accident and have their posts yanked just as they're trying to join the conversation. In response, Reddit is currently prototyping an AI-powered feature called "post guidance." It'll flag rule-violating material before it's ever published: "The new user gets feedback, and the mod doesn't have to deal with it," says Huffman. He adds that Reddit will also use AI to crack down on willful bad behavior, such as bullying and hate speech, and that he expects progress on that front in 2024...

Members already engage in acts of commerce such as tipping Photoshop wizards to remove ex-boyfriends from images; he says the company plans to facilitate these transactions with a payment system "that will basically involve users sending money to users, whether it's rewarding them for content or paying for digital services or digital goods or [physical] services." "People are trying to start businesses on Reddit, but it wasn't really built for that," he adds. "So just trying to flesh out that ecosystem, I think that'll be very powerful."


The Race to Shield Secrets from Quantum Computers (reuters.com) 67

An anonymous reader shared this report from Reuters: In February, a Canadian cybersecurity firm delivered an ominous forecast to the U.S. Department of Defense. America's secrets — actually, everybody's secrets — are now at risk of exposure, warned the team from Quantum Defen5e (QD5). QD5's executive vice president, Tilo Kunz, told officials from the Defense Information Systems Agency that possibly as soon as 2025, the world would arrive at what has been dubbed "Q-day," the day when quantum computers make current encryption methods useless. Machines vastly more powerful than today's fastest supercomputers would be capable of cracking the codes that protect virtually all modern communication, he told the agency, which is tasked with safeguarding the U.S. military's communications.

In the meantime, Kunz told the panel, a global effort to plunder data is underway so that intercepted messages can be decoded after Q-day in what he described as "harvest now, decrypt later" attacks, according to a recording of the session the agency later made public. Militaries would see their long-term plans and intelligence gathering exposed to enemies. Businesses could have their intellectual property swiped. People's health records would be laid bare... One challenge for the keepers of digital secrets is that whenever Q-day comes, quantum codebreakers are unlikely to announce their breakthrough. Instead, they're likely to keep quiet, so they can exploit the advantage as long as possible.

The article adds that "a scramble is on to protect critical data. Washington and its allies are working on new encryption standards known as post-quantum cryptography... Beijing is trying to pioneer quantum communications networks, a technology theoretically impossible to hack, according to researchers...

"In a quantum communications network, users exchange a secret key or code on subatomic particles called photons, allowing them to encrypt and decrypt data. This is called quantum key distribution, or QKD."

Are Phones Making the World's Students Dumber? (msn.com) 123

Long-time Slashdot reader schwit1 shared this article from the Atlantic: For the past few years, parents, researchers, and the news media have paid closer attention to the relationship between teenagers' phone use and their mental health. Researchers such as Jonathan Haidt and Jean Twenge have shown that various measures of student well-being began a sharp decline around 2012 throughout the West, just as smartphones and social media emerged as the attentional centerpiece of teenage life. Some have even suggested that smartphone use is so corrosive, it's systematically reducing student achievement. I hadn't quite believed that last argument — until now.

The Program for International Student Assessment, conducted by the Organization for Economic Co-operation and Development in almost 80 countries every three years, tests 15-year-olds est scores have been falling for years — even before the pandemic. Across the OECD, science scores peaked in 2009, and reading scores peaked in 2012. Since then, developed countries have as a whole performed "increasingly poorly" on average. "No single country showed an increasingly positive trend in any subject," PISA reported, and "many countries showed increasingly poor performance in at least one subject." Even in famously high-performing countries, such as Finland, Sweden, and South Korea, PISA grades in one or several subjects have been declining for a while.

So what's driving down student scores around the world? The PISA report offers three reasons to suspect that phones are a major culprit. First, PISA finds that students who spend less than one hour of "leisure" time on digital devices a day at school scored about 50 points higher in math than students whose eyes are glued to their screens more than five hours a day. This gap held even after adjusting for socioeconomic factors... Second, screens seem to create a general distraction throughout school, even for students who aren't always looking at them.... Finally, nearly half of students across the OECD said that they felt "nervous" or "anxious" when they didn't have their digital devices near them. (On average, these students also said they were less satisfied with life.) This phone anxiety was negatively correlated with math scores.

In sum, students who spend more time staring at their phone do worse in school, distract other students around them, and feel worse about their life.


New AI Transistor Works Just Like the Human Brain (studyfinds.org) 44

Longtime Slashdot reader FudRucker quotes a report from Study Finds: Researchers from Northwestern University, Boston College, and the Massachusetts Institute of Technology (MIT) have developed a new synaptic transistor that works just like the human brain. This advanced device, capable of both processing and storing information simultaneously, marks a notable shift from traditional machine-learning tasks to performing associative learning -- similar to higher-level human cognition. This study introduces a device that operates effectively at room temperatures, a notable improvement over previous brain-like computing devices that required extremely cold conditions to keep their circuits from overheating. With its fast operation, low energy consumption, and ability to retain information without power, the new transistor is well-suited for real-world applications.

"The brain has a fundamentally different architecture than a digital computer," says study co-author Mark Hersam, the Walter P. Murphy Professor of Materials Science and Engineering at Northwestern's McCormick School of Engineering, in a university release. "In a digital computer, data move back and forth between a microprocessor and memory, which consumes a lot of energy and creates a bottleneck when attempting to perform multiple tasks at the same time. On the other hand, in the brain, memory and information processing are co-located and fully integrated, resulting in orders of magnitude higher energy efficiency. Our synaptic transistor similarly achieves concurrent memory and information processing functionality to more faithfully mimic the brain."

Hersam and his team employed a novel strategy involving moire patterns, a type of geometric design formed when two patterns are overlaid. By stacking two-dimensional materials like bilayer graphene and hexagonal boron nitride and twisting them to form a moire pattern, they could manipulate the electronic properties of the graphene layers. This manipulation allowed for the creation of a synaptic transistor with enhanced neuromorphic functionality at room temperature. The device's testing involved training it to recognize patterns and similarities, a form of associative learning. For instance, if trained to identify a pattern like "000," the transistor could distinguish that "111" is more similar to "000" than "101," demonstrating a higher level of cognitive function. This ability to process complex and imperfect inputs has significant implications for real-world AI applications, such as improving the reliability of self-driving vehicles in challenging conditions.
The study has been published in the journal Nature.

Slashdot Top Deals