Books

Bill Gates Recommends Four Books That 'Make Sense of the World' (gatesnotes.com) 130

This month Bill Gates recommended four books about making sense of the world, including The Coming Wave, by Mustafa Suleyman. Gates calls it "the book I recommend more than any other on AI — to heads of state, business leaders, and anyone else who asks — because it offers something rare: a clear-eyed view of both the extraordinary opportunities and genuine risks ahead." After helping build DeepMind from a small startup into one of the most important AI companies of the past decade, [Suleyman] went on to found Inflection AI and now leads Microsoft's AI division. But what makes this book special isn't just Mustafa's firsthand experience — it's his deep understanding of scientific history and how technological revolutions unfold. He's a serious intellectual who can draw meaningful parallels across centuries of scientific advancement. Most of the coverage of The Coming Wave has focused on what it has to say about artificial intelligence — which makes sense, given that it's one of the most important books on AI ever written. And there is probably no one as qualified as Mustafa to write it...

But what sets his book apart from others is Mustafa's insight that AI is only one part of an unprecedented convergence of scientific breakthroughs. Gene editing, DNA synthesis, and other advances in biotechnology are racing forward in parallel. As the title suggests, these changes are building like a wave far out at sea — invisible to many but gathering force. Each would be game-changing on its own; together, they're poised to reshape every aspect of society... [P]rogress is already accelerating as costs plummet and computing power grows. Then there are the incentives for profit and power that are driving development. Countries compete with countries, companies compete with companies, and individuals compete for glory and leadership. These forces make technological advancement essentially unstoppable — and they also make it harder to control...

How do we limit the dangers of these technologies while harnessing their benefits? This is the question at the heart of The Coming Wave, because containment is foundational to everything else. Without it, the risks of AI and biotechnology become even more acute. By solving for it first, we create the stability and trust needed to tackle everything else... [Suleyman] lays out an agenda that's appropriately ambitious for the scale of the challenge — ranging from technical solutions (like building an emergency off switch for AI systems) to sweeping institutional changes, including new global treaties, modernized regulatory frameworks, and historic cooperation among governments, companies, and scientists...

In an accompanying Christmas-themed video, Gates adds that "Of all the books on AI, that's the one I recommend the most."

Gates also recommends The Anxious Generation by Jonathan Haidt, saying it "made me reflect on how much of my younger years — which were often spent running around outside without parental supervision, sometimes getting into trouble — helped shape who I am today. Haidt explains how the shift from play-based childhoods to phone-based childhoods is transforming how kids develop and process emotions." (In the video Gates describes it as "kind of a scary book, but very convincing. [Haidt] writes about the rise of mental illness, and anxiety in children. He, unlike some books, actually has some prescriptions, like kids not using phones until much later, parenting style differences. I think it's a super-important book.")

Gates goes into the book's thesis in a longer blog post: that "we're actually facing two distinct crises: digital under-parenting (giving kids unlimited and unsupervised access to devices and social media) and real-world over-parenting (protecting kids from every possible harm in the real world). The result is young people who are suffering from addiction-like behaviors — and suffering, period — while struggling to handle challenges and setbacks that are part of everyday life." [Haidt] makes a strong case for better age verification on social media platforms and delaying smartphone access until kids are older. Literally and figuratively, he argues, we also need to rebuild the infrastructure of childhood itself — from creating more engaging playgrounds that encourage reasonable risk-taking, to establishing phone-free zones in schools, to helping young people rediscover the joy of in-person interaction.
Gates also recommends Engineering in Plain Sight, by Grady Hillhouse, a book which he says "encourages curiosity." ("Hillhouse takes all of the mysterious structures we see every day, from cable boxes to transformers to cell phone towers, and explains what they are and how they work. It's the kind of read that will reward your curiosity and answer questions you didn't even know you had.")

And finally, Gates recommends an autobiography by 81-year-old Pulitzer Prize-winning historian/biographer/former sports journalist Doris Kearns Goodwin, who assesses the impact of President Lyndon Johnson's policies in a surprising "personal history of the 1960s."
AI

Protecting 'Funko' Brand, AI-Powered 'BrandShield' Knocks Itch.io Offline After Questionable Registrar Communications (polygon.com) 48

Launched in 2013, itch.io lets users host and sell indie video games online — now offering more than 200,000 — as well as other digital content like music and comics. But then someone uploaded a page based on a major videogame title, according to Game Rant. And somehow this provoked a series of overreactions and missteps that eventually knocked all of itch.io offline for several hours...

The page was about the first release from game developer 10:10 — their game Funko Fusion, which features characters in the style of Funko's long-running pop-culture bobbleheads. As a major brand, Funko monitors the web with a "brand protection" partner (named BrandShield). Interestingly, BrandShield's SaaS product "leverages AI-driven online brand protection," according to their site, to "detect and remove" things like brand impersonations "with over 98% success. Our advanced takedown capabilities save you time..." (Although BrandShield's CEO told the Verge that following AI reports "our team of Cybersecurity Threat hunters and IP lawyers decide on what actions should be taken.") This means that after automatically spotting the itch.io page with its web-crawling software, it was BrandShield's "team of Cybersecurity Threat hunters and IP lawyers" who decided to take action (for that specific page). But itch.io founder Leaf Corcoran commented on social media: From what I can tell, some person made a fan page for an existing Funko Pop video game (Funko Fusion), with links to the official site and screenshots of the game. The BrandShield software is probably instructed to eradicate all "unauthorized" use of their trademark, so they sent reports independently to our host and registrar claiming there was "fraud and phishing" going on, likely to cause escalation instead of doing the expected DMCA/cease-and-desist. Because of this, I honestly think they're the malicious actor in all of this.
Corcoran says he replied to both his registrar (iwantmyname) and to his site's host, telling them he'd removed the offending page (and disabled its uploader's account). This satisfied his host, Corcoran writes — but the registrar's owner later told him they'd never received his reply.

"And that's why they took the domain down."

In an interview with Polygon, Corcoran points out that the web page in question had already been dealt with five days before his registrar offlined his entire site. "No communication after that.... No 'We haven't heard from you, we're about to shut your domain down' or anything like that."

Defending themselves over the incident, BrandShield posted on X.com that they'd identified an "infringement" (also calling it an "abuse"), and that they'd requested "a takedown of the URL in question — not of the entire itch.io domain." They don't say this, but it seems like their concern might've been that the page looked official enough to impersonate Funko Fusion. But X.com readers added this context. "Entire domains do not go down on the basis of a copyright takedown request of an individual URL. This is the direct result of a fraudulent claim of malicious activity."

And Corcoran also posted an angry summation on X.com: I kid you not, @itchio has been taken down by @OriginalFunko because they use some trash "AI Powered" Brand Protection Software called @BrandShieldltd that created some bogus Phishing report to our registrar, @iwantmyname, who ignored our response and just disabled the domain.
The next day Funko's official account on X.com also issued their own statement that they "hold a deep respect and appreciation for indie games, indie gamers, and indie developers." (Though "Added Context" from X.com readers notes Funko's statement still claimed a "takedown request" was issued, rather than what Corcoran says was a false "fraud and phishing" report.)

Funko.com also posted that they'd "reached out" to itch.io "to engage with them on this issue." But this just led to another angry post from Corcoran. "This is not a joke, Funko just called my mom." Cocoran then posted what looks like a screenshot of a text message his mother sent him. Though she doesn't say which company was involved, his mother's text says she "Got a strange call from a company about accusatory statements on your social media account. Call me..."

Thanks to ewhac (Slashdot reader #5,844) for sharing the news.
Cellphones

A Fake Uber Driver Borrowed Phones, Then Stole $200K in Cryptocurrency, Police Say (gizmodo.com) 48

"A man is accused of several felony charges after he allegedly posed as an Uber driver and then stole hundreds of thousands of dollars in cryptocurrency from customers in Scottsdale," reports Arizona news channel Fox 10.

"Prosecutors have called it an 'extremely sophisticated electronic fraud,'" reports Gizmodo, " and it's a strange approach to scamming that makes it sound unique in several ways." Nuruhussein Hussein, 40, allegedly picked up two unsuspecting people who were looking for Uber rides they'd ordered in Scottsdale — one in March and the other in October according to Fox 10 — by shouting their names on the street outside a hotel. It's not clear how Hussein may have known these people were looking for rides and court documents give no indication how he accomplished this or knew the victims would have crypto accounts, according to Fox 10, though a hotel does make sense as a target-rich environment for those looking to get picked up.

Once the victims were in the car, Hussein allegedly obtained the phones of the victims through some kind of pretense, including problems with his own phone and the need to look something up as well as a need to connect with the Uber app, according to NBC News. Hussein would then allegedly open up the victim's Coinbase account. "While manipulating the unsuspecting victim's phone the suspect transferred cryptocurrency from their digital wallet to his digital wallet," police reportedly explained in a statement.

Displays

Donald Bitzer, a Pioneer of Cyberspace and Plasma Screens, Dies At 90 (msn.com) 18

The Washington Post reports: Years before the internet was created and the first smartphones buzzed to life, an educational platform called PLATO offered a glimpse of the digital world to come. Launched in 1960 at the University of Illinois at Urbana-Champaign [UIUC], it was the first generalized, computer-based instructional system, and grew into a home for early message boards, emails, chatrooms, instant messaging and multiplayer video games.

The platform's developer, Donald Bitzer, was a handball-playing, magic-loving electrical engineer who opened his computer lab to practically everyone, welcoming contributions from Illinois undergrads as well as teenagers who were still in high school. Dr. Bitzer, who died Dec. 10 at age 90, spent more than two decades working on PLATO, managing its growth and development while also pioneering digital technologies that included the plasma display panel, a forerunner of the ultrathin screens used on today's TVs and tablets. "All of the features you see kids using now, like discussion boards or forums and blogs, started with PLATO," he said during a 2014 return to Illinois, his alma mater. "All of the social networking we take for granted actually started as an educational tool."

Long-time Slashdot reader theodp found another remembrance online. "Ray Ozzie, whose LinkedIn profile dedicates more space to describing his work as a PLATO developer as a UIUC undergrad than it does to his later successes as a creator of Lotus Notes and as Microsoft's Chief Software Architect, offers his own heartfelt mini-obit." Ozzie writes: It's difficult to adequately convey how much impact he had on so many, and I implore you to take a few minutes to honor him by reading a bit about him and his contributions. Links below. As an insecure young CS student at UIUC in 1974, Paul Tenczar, working for/with Don, graciously gave me a chance as a jr. systems programmer on the mind-bogglingly forward thinking system known as PLATO. A global, interactive system for learning, collaboration, and community like no other at the time. We were young and in awe of how Don led, inspired, and managed to keep the project alive. I was introverted; shaking; stage fright. Yeah I could code. But how could such a deeply technical engineer assemble such a strong team to execute on such a totally novel and inspirational vision, secure government funding, and yet also demo the product on the Phil Donahue show?

"Here's to the crazy ones. The misfits. The rebels. The troublemakers. The ones who see things differently. They're not fond of rules." You touched so many of us and shaped who we became and the risks we would take, having an impact well beyond that which you created. You made us think and you made us laugh. I hope we made you proud."

Social Networks

Tech Platforms Diverge on Erasing Criminal Suspects' Digital Footprints (nytimes.com) 99

Social media giants confronted a familiar dilemma over user content moderation after murder suspect Luigi Mangione's arrest in the killing of UnitedHealthcare's CEO on Monday, highlighting the platforms' varied approaches to managing digital footprints of criminal suspects.

Meta quickly removed Mangione's Facebook and Instagram accounts under its "dangerous organizations and individuals" policy, while his account on X underwent a brief suspension before being reinstated with a premium subscription. LinkedIn maintained his profile, stating it did not violate platform policies. His Reddit account was suspended in line with the platform's policy on high-profile criminal suspects, while his Goodreads profile fluctuated between public and private status.

The New York Times adds: When someone goes from having a private life to getting public attention, online accounts they intended for a small circle of friends or acquaintances are scrutinized by curious strangers -- and journalists.

In some cases, these newly public figures or their loved ones can shut down the accounts or make them private. Others, like Mr. Mangione, who has been charged with murder, are cut off from their devices, leaving their digital lives open for the public's consumption. Either way, tech companies have discretion in what happens to the account and its content. Section 230 of the Communications Decency Act protects companies from legal liability for posts made by users.

The Internet

Russia Tests Cutting Off Access To Global Web, and VPNs Can't Get Around It (pcmag.com) 123

An anonymous reader shares a report: Russia has reportedly cut some regions of the country off from the rest of the world's internet for a day, effectively siloing them, according to reports from European and Russian news outlets reshared by the US nonprofit Institute for the Study of War (ISW) and Western news outlets.

Russia's communications authority, Roskomnadzor, blocked residents in Dagestan, Chechnya, and Ingushetia, which have majority-Muslim populations, ISW says. The three regions are in southwest Russia near its borders with Georgia and Azerbaijan. People in those areas couldn't access Google, YouTube, Telegram, WhatsApp, or other foreign websites or apps -- even if they used VPNs, according to a local Russian news site.

Russian digital rights NGO Roskomsvoboda told TechRadar that most VPNs didn't work during the shutdown, but some apparently did. It's unclear which ones or how many actually worked, though. Russia has been increasingly blocking VPNs more broadly, and Apple has helped the country's censorship efforts by taking down VPN apps on its Russian App Store. At least 197 VPNs are currently blocked in Russia, according to Russian news agency Interfax.

Science

New Magnetic Flow Has Potential To Revolutionise Electronic Devices (ft.com) 40

An international research team has for the first time imaged and controlled a type of magnetic flow called altermagnetism, which physicists say could be used to develop faster and more reliable electronic devices. Financial Times: A groundbreaking experiment at a powerful X-ray microscope in Sweden provides direct proof of the existence of altermagnetism, according to a paper published in Nature on Wednesday. Altermagnetic materials can sustain magnetic activity without themselves being magnetic.

The team from the UK's Nottingham university that led the research said the discovery has revolutionary potential for the electronics industry. "Altermagnets have the potential to lead to a thousand-fold increase in the speed of microelectronic components and digital memory, while being more robust and energy-efficient," said senior author Peter Wadley, Royal Society research fellow at Nottingham.

Hard disks and other components underpinning the modern computers industry process data in ferromagnetic materials, whose intrinsic magnetism limits their speed and packing density. Using altermagnetic materials will allow current to flow in non-magnetic products.

Open Source

Slashdot's Interview with Bruce Perens: How He Hopes to Help 'Post Open' Developers Get Paid (slashdot.org) 61

Bruce Perens, original co-founder of the Open Source Initiative, has responded to questions from Slashdot readers about a new alternative he's developing that hopefully helps "Post Open" developers get paid.

But first, "One of the things that's clear from the Slashdot patter is that people are not aware of what I've been doing, in general," Perens says. "So, let's start by filling that in..."

Read on for the rest of his wide-ranging answers....
China

America's Phone Networks Could Soon Face Financial - and Criminal - Penalties for Insecure Networks (msn.com) 55

The head of America's FCC "has drafted plans to regulate the cybersecurity of telecommunications companies," reports the Washington Post, and the plans could include financial penalties phone network operators with insufficient security — "the first time the agency has asserted such powers under federal wiretapping law." Rosenworcel said the FCC's authority in this matter comes from Section 105 of the Communications Assistance for Law Enforcement Act [passed in 1994] — a single sentence that stipulates, without elaboration, that telecommunications carriers should ensure systems security "in accordance with regulations prescribed by the Commission." As one of the measures, she is seeking to require network providers to submit an annual certification to the FCC that they are implementing a cybersecurity risk management plan. In addition to imposing fines, the FCC could coordinate with other agencies to pursue criminal penalties against carriers deemed too careless on cybersecurity...

Biden administration officials said voluntary efforts to protect against aggressive Chinese hacking activity have fallen short. "We've had for the last decade voluntary public-private partnership efforts," Neuberger told The Post in a recent interview. "But we continue to see successful breaches, and in many cases, as with ransomware attacks, we continue to see pretty basic cybersecurity practices not being followed." With China's hackers becoming more brazen, pre-positioning themselves in U.S. critical networks, "we need to lock our digital doors," Neuberger said...

Cyber requirements can make a difference, she said. After the Colonial Pipeline ransomware attack in 2021 shut down one of the nation's largest energy pipelines for several days, creating a national security scare, the Transportation Security Administration issued several security directives, and today, all of the country's several dozen critical pipeline companies are in compliance, she said. Similar directives were subsequently issued for rail and aviation sectors, and the compliance rates in those industries are now at 68 and 57 percent respectively, she said.

Businesses

Drones, Surveillance, and Facial Recognition: Startup Named 'Sauron' Pitches Military-Style Home Security (msn.com) 124

The Washington Post details a vision of home security "pitched by Sauron, a Silicon Valley start-up boasting a waiting list of tech CEOs and venture capitalists." In the future, your home will feel as safe from intruders as a state-of-the-art military base. Cameras and sensors surveil the perimeter, scanning bystanders' faces for potential threats. Drones from a "deterrence pod" scare off trespassers by projecting a searchlight over any suspicious movements. A virtual view of the home is rendered in 3D and updated in real time, just like a Tesla's digital display. And private security agents monitor alerts from a central hub.... By incorporating technology developed for autonomous vehicles, robotics and border security, Sauron has built a supercharged burglar alarm [argued Sauron co-founder Kevin Hartz, a tech entrepreneur and former partner at Peter Thiel's venture firm Founders Fund]...

For many tech elites, security is both a national priority and a growing concern in their personal lives... After the presidential election last month, the start-up incubator Y Combinator put out a request for "public safety technology" companies, such as those that produce tools that facilitate a neighborhood watch or technology that uses computer vision to identify "suspicious activities or people in distress from video feeds...." Sauron has raised $18 million in funding from executives behind Flock Safety and Palantir, the data analytics firm, [and] defense tech investors such as 8VC, a venture firm started by Palantir co-founder Joe Lonsdale... Sauron is targeting homeowners at the high end of the real estate market, beginning with a private event at Abraham's home on Thursday, during Art Basel Miami Beach, the annual art exhibition that attracts collectors from around the world. The company plans to launch in San Francisco early next year, before expanding to Los Angeles and Miami...

Big Tech companies haven't deployed tools such as facial recognition as aggressively as Hartz would like. "If somebody comes onto my property, I feel like I should know who that is," Hartz said... In recent years massive investments have driven down the cost of drones, high-resolution cameras and lidar sensors, which use light detection to create 3D maps. Sauron uses lower-cost hardware and tools like facial recognition, combined with custom-built software adapted for residential use. For facial recognition, it will use a third-party service called Paravision... Sauron is still figuring out how to incorporate drones, but it is already imagining more aggressive countermeasures, Hartz said. "Is it a machine that could take out a bad actor with a bullet or something?"

Mozilla

What Do You Think of Mozilla's New Branding? (itsfoss.com) 101

As a "global crew of activists, technologists and builders," Mozilla open-sourced Firefox more than 25 years ago, notes a new blog post — and their president says Mozilla's mission is the same today: "build and support technology in the public interest, and spark more innovation, more competition and more choice online along the way."

But "Even though we've been at the forefront of privacy and open source, people weren't getting the full picture of what we do. We were missing opportunities to connect with both new and existing users." So this week the company announced a branding refresh, "making sure people know Mozilla for its broader impact, as well as Firefox."

The open-source blog It's FOSS writes: Meant to symbolize their activist spirit, the new brand identity of Mozilla involves a custom semi-slab typeface that spells Mozilla, followed by a flag that was taken from the M of their name. Mozilla points out that this is not just a rebranding, but something that will lay the foundation for the next 25 years, helping them promote the ideals of privacy and open source.
Mozilla teamed up with the design agency used by major brands like Uber and Burger King, for a strategy they say will "embody our role as a leader in digital rights and innovation, putting people over profits through privacy-preserving products, open-source developer tools, and community-building efforts..." We back people and projects that move technology, the internet and AI in the right direction. In a time of privacy breaches, AI challenges and misinformation, this transformation is all about rallying people to take back control of their time, individual expression, privacy, community and sense of wonder... [T]he new brand empowers people to speak up, come together and build a happier, healthier internet — one where we can all shape how our lives, online and off, unfold...

- The flag symbol highlights our activist spirit, signifying a commitment to 'Reclaim the Internet.' A symbol of belief, peace, unity, pride, celebration and team spirit — built from the 'M' for Mozilla and a pixel that is conveniently displaced to reveal a wink to its iconic Tyrannosaurus rex symbol designed by Shepard Fairey. The flag can transform into a more literal interpretation as its new mascot in ASCII art style, and serve as a rallying cry for our cause...

- The custom typefaces are bespoke and an evolution of its Mozilla slab serif today. It stands out in a sea of tech sans. The new interpretation is more innovative and built for its tech platforms. The sans brings character to something that was once hard working but generic. These fonts are interchangeable and allow for a greater degree of expression across its brand experience, connecting everything together.

The blog post at It's FOSS ends with a "trip down memory lane" — showing Mozilla's two previous logos. "I will be honest, I liked the Dino better," they write "the 2024 logo is a nice mix of a custom typeface and a flag, which looks really neat in my opinion."
Microsoft

Thanks to Microsoft Collaboration, iFixit Now Sells Genuine Xbox Repair Parts (theverge.com) 20

"We're excited to be working with Microsoft to keep Xboxes running longer and out of the waste heap," iFixit's director of sustainability told The Verge. iFixit now sells genuine Xbox parts you can use to repair your Xbox Series X or S and offers official guides to help with fixes [including both the all-digital and disk drive editions]...

iFixit's Microsoft Repair Hub also features iFixit's parts for repairing Microsoft Surface devices, which it started selling in 2023. "Since we launched our Surface parts collaboration with Microsoft last year, we've been helping our customers repair their own Microsoft laptops and tablets — and it's awesome to be able to offer Xbox owners the same opportunity," says Elizabeth Chamberlain, iFixit's director of sustainability.

The article points out that iFixit also sells "nearly every part of the Steam Deck" and "a bunch of repair guides for Valve's handheld PC, too," along with genuine repair parts for Google's Pixel phones and the Pixel Tablet.

"With Microsoft, we've created a one-stop place for guides, tools, and spare parts to make self-service repair accessible to anyone," says iFixit's new web page. "Imagine how different the world would be if repairing every device could be this easy."
The Military

NATO Considers Watching Undersea Internet Cables with a Fleet of Unmanned Boats (defensenews.com) 93

An anonymous reader shared this report from Defense News: Following a pattern of undersea cable damage across European waters in the last year, with the most recent disruptions happening just weeks ago, top NATO officials have begun envisioning a capability that would allow the alliance to have permanent eyes above and under the waterline. In an interview with Defense News, Admiral Pierre Vandier, the alliance's Norfolk, Virginia-based commander for concepts and transformation, likened the idea to police CCTV cameras installed on street lights in urban trouble spots for recording evidence of crimes. "The technology is there to make this street-lighting with USVs," he said, using the military's shorthand for unmanned surface vessel. Vandier said his team is in the early stages of developing an unmanned surface vessel fleet so that "NATO can see and monitor daily its environment."

The first step would be to achieve this at a surface level, and then later under water... According to Vandier, the goal is to launch the drone surveillance fleet before the next NATO Summit, which will be held in the Netherlands next June.

The article notes the U.S. Navy's Task Force 59 (launched in 2021) is already "dedicated to integrating unmanned systems and AI in the U.S. Navy's 5th Fleet area of operations." This prompted Admiral Vandier to say the technology for an unmanned cable-watching fleet "already exists... everything is known and sold, so it is much more a matter of adoption than technology."
The Almighty Buck

Backdoor in Compromised Solana Code Library Drains $184,000 from Digital Wallets (bleepingcomputer.com) 22

The Solana JavaScript SDK "was temporarily compromised yesterday in a supply chain attack," reports BleepingComputer, "with the library backdoored with malicious code to steal cryptocurrency private keys and drain wallets." Solana offers an SDK called "@solana/web3.js" used by decentralized applications (dApps) to connect and interact with the Solana blockchain. Supply chain security firm Socket reports that Solana's Web3.js library was hijacked to push out two malicious versions to steal private and secret cryptography keys to secure wallets and sign transactions... Solana confirmed the breach, stating that one of their publish-access accounts was compromised, allowing the attackers to publish two malicious versions of the library... Solana is warning developers who suspect they were compromised to immediately upgrade to the latest v1.95.8 release and to rotate any keys, including multisigs, program authorities, and server keypairs...

Once the threat actors gain access to these keys, they can load them into their own wallets and remotely drain all stored cryptocurrency and NFTs... Socket says the attack has been traced to the FnvLGtucz4E1ppJHRTev6Qv4X7g8Pw6WPStHCcbAKbfx Solana address, which currently contains 674.86 Solana and varying amounts of the Irish Pepe , Star Atlas, Jupiter, USD Coin, Santa Hat, Pepe on Fire, Bonk, catwifhat, and Genopets Ki tokens. Solscan shows that the estimated value of the stolen cryptocurrency is $184,000 at the time of this writing.

For anyone whose wallets were compromised in this supply chain attack, you should immediately transfer any remaining funds to a new wallet and discontinue the use of the old one as the private keys are now compromised.

Ars Technica adds that "In social media posts, one person claimed to have lost $20,000 in the hack."

The compromised library "receives more than ~350,000 weekly downloads on npm," Socket posted. (Although Solana's statement says the compromised versions "were caught within hours and have since been unpublished."
The Internet

Is Europe Better Prepared to Protect Undersea Internet Cables? (carnegieendowment.org) 64

The Carnegie Endowment for Peace, a nonpartisan international affairs think tank, points out that when subsea internet cables were cut in November, Europe was more prepared: Where in the past there were no contingency plans for sabotage, there are now more maritime patrols, an attempt to forge deeper intelligence connections, and the beginnings of a new relationship with the private sector...

Even before the October 2023 incident, NATO, the EU, and certain European governments began to increase their efforts to boost subsea cable resilience and security. In February 2023, NATO stood up a new Critical Undersea Infrastructure Coordination Cell in Brussels to convene stakeholders and enhance coordination between the public and private sectors. In July 2023, NATO allies at the Vilnius Summit established a Maritime Center for the Security of Critical Undersea Infrastructure as part of the alliance's Maritime Command in Northwood, UK. In October 2023, after the first incident, NATO defense ministers endorsed a new Digital Ocean Vision, an initiative aimed at improving undersea surveillance. And in February 2024, the European Commission released its first "Recommendation on Secure and Resilient Submarine Cable Infrastructures," encouraging member states to conduct regular stress tests, improve information sharing amongst themselves, and improve cable maintenance and repair capabilities.

The article points out that the Chinese ship suspected in the 2023 cable cutting "ignored requests from Finnish and Estonian authorities to halt" and returned to China. But the Chinese ship suspected in November's cable-cutting "remains in international waters in the Kattegat, with naval and coast guard vessels from Denmark, Germany, and Sweden circling close by." Yet "Under international maritime law, these countries' authorities are not allowed to board..." Current provisions of international law are neither formulated to adequately protect subsea data cables from sabotage nor hold perpetrators accountable. This reality should lead the EU, as a body inherently focused on the resilience of international legal regimes, to push for updates that are better suited for the current geopolitical reality... Lawmakers should also explore ways to increase penalties for subsea cable damage, in part to deter acts of sabotage in the first place....

A forthcoming Carnegie Endowment report will detail more in-depth recommendations on how Europe can both protect itself against future subsea cable damage and help expand trusted networks around the world.

The article also notes that "Of the hundreds of disruptions to cables that occur each year, the vast majority are caused by accidental human activity, like fishing, or natural events, like earthquakes."
AI

Elon Musk's xAI Plans Massive Expansion of AI Supercomputer in Memphis (usnews.com) 135

An anonymous reader shared this report from Reuters: Elon Musk's artificial intelligence startup xAI plans to expand its Memphis, Tennessee, supercomputer to house at least one million graphics processing units (GPUs), the Greater Memphis Chamber said on Wednesday, as xAI races to compete against rivals like OpenAI.

The move represents a massive expansion for the supercomputer called Colossus, which currently has 100,000 GPUs to train xAI's chatbot called Grok. As part of the expansion, Nvidia, which supplies the GPUs, and Dell and Super Micro, which have assembled the server racks for the computer, will establish operations in Memphis, the chamber said in a statement.

The Greater Memphis chamber (an economic development organization) called it "the largest capital investment in the region's history," even saying that xAI "is setting the stage for Memphis to become the global epicenter of artificial intelligence." ("To facilitate this massive undertaking, the Greater Memphis Chamber established an xAI Special Operations Team... This team provides round-the-clock concierge service to the company.")

Reuters calls the supercomputer "a critical component of advancing Musk's AI efforts, as the billionaire has deepened his rivalry against OpenAI..." And the Greater Memphis chamber describes the expansion by Nvidia/Dell/Super Micro as "further solidifying the city's position as the 'Digital Delta'... Memphis has provided the power and velocity necessary for not just xAI to grow and thrive, but making way for other companies as well."
The Courts

Internet Archive: We Will Not Appeal 'Hachette v. Internet Archive' Ruling (archive.org) 62

In March, 2023 the Internet Archive lost in court, with a judge ruling they couldn't scan entire books and then lend them as ebooks. The Internet Archive appealed to a higher court, which also ruled against them in September of 2024.

Today, the Internet Archive made an announcement: that "While we are deeply disappointed with the Second Circuit's opinion in Hachette v. Internet Archive, the Internet Archive has decided not to pursue Supreme Court review." We will continue to honor the Association of American Publishers agreement to remove books from lending at their member publishers' requests.

We thank the many readers, authors and publishers who have stood with us throughout this fight. Together, we will continue to advocate for a future where libraries can purchase, own, lend and preserve digital books.

Businesses

Monday Americans Spent $13.3 Billion in Biggest Cyber Monday Ever (cnn.com) 50

"$15.8 million every 60 seconds. That's how much US consumers spent in two hours on Monday night," reports CNN, "capping off a five-day spending spree that smashed previous records." U.S. consumers spent a total of $13.3 billion on Cyber Monday, up 7.3% from the previous year, according to Adobe Analytics... Consumers spent a record $41.1 billion across the five days beginning Thanksgiving Day, according to Adobe. "While Cyber Monday remained the season's and year's biggest online shopping day, year-over-year growth was stronger on both Thanksgiving and Black Friday," Vivek Pandya, lead analyst at Adobe Digital Insights, said in a statement... The company's data projects that holiday spending from November 1 to December 31 will surpass $240 billion, up 8.4% from the previous year.

The record sales on Cyber Monday were boosted by US consumers shopping on their mobile devices, which accounted for $7.6 billion in spending. This year, 57% of online sales came through a mobile device, compared to 33% in 2019, as shopping on mobile phones has surged in popularity... Buy now, pay later" programs also contributed nearly $1 billion in spending on Cyber Monday, a record high. About 75% of these types of transactions occurred through a mobile device.

Cyber Monday shopping wasn't just confined to the US, either. Global sales reached $49.7 billion, up 3% from the previous year, according to data from Salesforce.

The top-selling items included consumer electronics like the PlayStation 5, Xbox Series X and Nintendo Switch OLED, the article points out (adding that "About 78% of all consumer smartphones and 87% of consoles were imported from China in 2023, according to a report from the Consumer Technology Association.")

More interesting statistics from CNN:
  • "Discounts on apparel peaked at just over 23% off, while TVs and computers peaked at almost 22% off, according to Adobe. And the discounts might last: Adobe projects discounts of up to 18% off computers through the end of the year... "
  • "For US retail sites, the share of revenue from affiliates and partners like social media influencers was 20.3% on Cyber Monday, up almost 7% from the previous year. "
  • "Additionally, companies employed AI chatbots to assist consumers, like Amazon's Rufus. Traffic to retail sites from chatbots increased by nearly 2,000% on Cyber Monday, according to Adobe."

Idle

Enron has Been Resurrected in What Appears to Be an Elaborate Joke (cnn.com) 47

Have you been to Enron.com lately?

"It's the comeback story no one asked for," reports CNN, "the resurrection of a brand so toxic it remains synonymous with corporate fraud more than two decades after it collapsed in bankruptcy.

"That's right, folks: Enron is back. But only kind of." TL;DR: A company that makes T-shirts bought the Enron trademark and appears to be trying to sell some merch on behalf of the guy behind the satirical conspiracy theory "Birds Aren't Real...."

On Monday, the 23rd anniversary of Enron's filing for bankruptcy, rumors began to spread that the former Texas energy giant had come back from the dead. A sleek new website, enron.com, appeared to show that the company had done some serious soul-searching and, inexplicably, reincorporated under its original brand. As a modern energy company, it would be dedicated to "solving the global energy crisis," its press statement reads. The site is packed with the kind of stock art and benign corporate platitudes that lend it credibility. There's a link to job openings, employee testimonials and even a minute-long video titled "I am Enron," a movie-trailer-style mashup of cityscape time lapses, rockets launching into space, a ballerina twirling on a beach — a mess of imagery and baritone voiceover so trite it's almost believable.

But the site and its associated social media accounts are, like Enron's balance sheets, mostly fiction. Unlike the Enron scandal, however, this one appears to be little more than performance art designed to sell branded hoodies. Publicly available documents show that an Akansas-based LLC called The College Company bought the Enron trademark for $275 in 2020... You can tab over to the site's "Company Store" page to browse a selection of Enron-branded hoodies ($118 before tax and shipping), puffer vests ($89), tees ($40) baseball hats ($40), beanies ($30) and water bottles emblazoned with the slogan "you've got great energy."

Somewhere on the site CNN spotted a list of "key pillars" which included a commitment to "permissionless innovation," which CNN took to be "a nod that prompted some speculation online that the new 'Enron' would launch some kind of digital token." That phrase has apparently been changed now to "continuous innovation." An Enron-branded X account posted and later deleted a message teasing at a crypto offering, saying "we do not have any token or coin (yet). Stay tuned, we are excited to show you more soon."
But sharp-eyed X.com users also found the key context to add: that the Terms of Use at Enron.com declare the site's information "is First Amendment-protected parody, represents performance art, and is for entertainment purposes only."

Still, the site includes this testimonial from someone it says is a current employee. "Like many of my peers in the Enron family, I was skeptical at first.

"Now, not only do I have complete confidence in the integrity of the company, I also genuinely believe that we are leading the way for a new chapter of American business."
Encryption

US Officials Urge Americans to Use Encrypted Apps Amid Unprecedented Cyberattack (nbcnews.com) 58

An anonymous reader shared this report from NBC News: Amid an unprecedented cyberattack on telecommunications companies such as AT&T and Verizon, U.S. officials have recommended that Americans use encrypted messaging apps to ensure their communications stay hidden from foreign hackers...

In the call Tuesday, two officials — a senior FBI official who asked not to be named and Jeff Greene, executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency — both recommended using encrypted messaging apps to Americans who want to minimize the chances of China's intercepting their communications. "Our suggestion, what we have told folks internally, is not new here: Encryption is your friend, whether it's on text messaging or if you have the capacity to use encrypted voice communication. Even if the adversary is able to intercept the data, if it is encrypted, it will make it impossible," Greene said. The FBI official said, "People looking to further protect their mobile device communications would benefit from considering using a cellphone that automatically receives timely operating system updates, responsibly managed encryption and phishing resistant" multi-factor authentication for email, social media and collaboration tool accounts...

The FBI and other federal law enforcement agencies have a complicated relationship with encryption technology, historically advocating against full end-to-end encryption that does not allow law enforcement access to digital material even with warrants. But the FBI has also supported forms of encryption that do allow some law enforcement access in certain circumstances.

Officials said the breach seems to include some live calls of specfic targets and also call records (showing numbers called and when). "The hackers focused on records around the Washington, D.C., area, and the FBI does not plan to alert people whose phone metadata was accessed."

"The scope of the telecom compromise is so significant, Greene said, that it was 'impossible" for the agencies "to predict a time frame on when we'll have full eviction.'"

Slashdot Top Deals