×
Privacy

Hackers Claim Vast Access To Western Digital Systems (techcrunch.com) 29

An anonymous reader quotes a report from TechCrunch: The hackers who breached data storage giant Western Digital claim to have stolen around 10 terabytes of data from the company, including reams of customer information. The extortionists are pushing the company to negotiate a ransom -- of "minimum 8 figures" -- in exchange for not publishing the stolen data. On April 3, Western Digital disclosed "a network security incident" saying hackers had exfiltrated data after hacking into "a number of the Company's systems." At the time, Western Digital provided few details about exactly what data the hackers stole, saying in a statement that the hackers "obtained certain data from its systems and [Western Digital] is working to understand the nature and scope of that data."

One of the hackers spoke with TechCrunch and provided more details, with the goal of verifying their claims. The hacker shared a file that was digitally signed with Western Digital's code-signing certificate, showing they could now digitally sign files to impersonate Western Digital. Two security researchers also looked at the file and agreed it is signed with the company's certificate. The hackers also shared phone numbers allegedly belonging to several company executives. TechCrunch called the numbers. Most of the calls rang but went to automated voicemail messages. Two of the phone numbers had voicemail greetings that mentioned the names of the executives that the hackers claimed were associated with the numbers. The two phone numbers are not public.

Screenshots shared by the hacker show a folder from a Box account apparently belonging to Western Digital, an internal email, files stored in a PrivateArk instance (a cybersecurity product), and a screenshot of a group call where one of the participants is identified as Western Digital's chief information security officer. They also said they were able to steal data from the company's SAP Backoffice, a backend interface that helps companies manage e-commerce data. The hacker said that their goal when they hacked Western Digital was to make money, though they decided against using ransomware to encrypt the company's files. [...] If Western Digital doesn't get back to them, the hacker said, they are ready to start publishing the stolen data on the website of the ransomware gang Alphv. The hacker said they are not directly affiliated with Alphv but "I know them to be professional."
Western Digital said they're declining to comment or answer questions about the hacker's claims.
The Military

Leader of Online Group Where Secret Documents Leaked Is Air National Guardsman (nytimes.com) 182

An anonymous reader quotes a report from the New York Times: The leader of a small online gaming chat group where a trove of classified U.S. intelligence documents leaked over the last few months is a 21-year-old member of the intelligence wing of the Massachusetts Air National Guard, according to interviews and documents reviewed by The New York Times. The National Guardsman, whose name is Jack Teixeira, oversaw a private online group called Thug Shaker Central, where about 20 to 30 people, mostly young men and teenagers, came together over a shared love of guns, racist online memes and video games. On Thursday afternoon, about a half-dozen F.B.I. agents pushed into a residence in North Dighton, Mass. Attorney General Merrick B. Garland later said in a short statement that Airman Teixeira had been arrested "without incident." Federal investigators had been searching for days for the person who leaked the top secret documents online.

Starting months ago, one of the users uploaded hundreds of pages of intelligence briefings into the small chat group, lecturing its members, who had bonded during the isolation of the pandemic, on the importance of staying abreast of world events. [...] The Times spoke with four members of Thug Shaker Central, one of whom said he had known the person who leaked for at least three years, had met him in person and referred to him as the O.G. The friends described him as older than most of the group members, who were in their teens, and the undisputed leader. One of the friends said the O.G. had access to intelligence documents through his job. While the gaming friends would not identify the group's leader by name, a trail of digital evidence compiled by The Times leads to Airman Teixeira. The Times has been able to link Airman Teixeira to other members of Thug Shaker Central through his online gaming profile and other records. Details of the interior of Airman Teixeira's childhood home -- posted on social media in family photographs -- also match details on the margins of some of the photographs of the leaked secret documents.

Members of Thug Shaker Central who spoke to The Times said that the documents they discussed online were meant to be purely informative. While many pertained to the war in Ukraine, the members said they took no side in the conflict. The documents, they said, started to get wider attention only when one of the teenage members of the group took a few dozen of them and posted them to a public online forum. From there they were picked up by Russian-language Telegram channels and then The Times, which first reported on them. The person who leaked, they said, was no whistle-blower, and the secret documents were never meant to leave their small corner of the internet. "This guy was a Christian, antiwar, just wanted to inform some of his friends about what's going on," said one of the person's friends from the community, a 17-year-old recent high school graduate. "We have some people in our group who are in Ukraine. We like fighting games; we like war games."

Privacy

The US Cracked a $3.4 Billion Crypto Heist - and Bitcoin's Anonymity (wsj.com) 59

Federal authorities are making arrests and seizing funds with the help of new tools to identify criminals through cryptocurrency transactions. From a report: James Zhong appeared to have pulled off the perfect crime. In December 2012, he stumbled upon a software bug while withdrawing money from his account on Silk Road, an online marketplace used to hide criminal dealings behind the seemingly bulletproof anonymity of blockchain transactions and the dark web. Mr. Zhong, a 22-year-old University of Georgia computer-science student at the time, used the site to buy cocaine. "I accidentally double-clicked the withdraw button and was shocked to discover that it resulted in allowing me to withdraw double the amount of bitcoin I had deposited," he later said in federal court. After the first fraudulent withdrawal, Mr. Zhong created new accounts and with a few hours of work stole 50,000 bitcoins worth around $600,000, court papers from federal prosecutors show.

Federal officials closed Silk Road a year later on criminal grounds and seized computers that held its transaction records. The records didn't reveal Mr. Zhong's caper at first. Authorities hadn't yet mastered how to track people and groups hidden behind blockchain wallet addresses, the series of letters and numbers used to anonymously send and receive cryptocurrency. One elemental feature of the system was the privacy it gave users. Mr. Zhong moved the stolen bitcoins from one account to another for eight years to cover his tracks. By late 2021, the red-hot crypto market had raised the value of his trove to $3.4 billion. In November 2021, federal agents surprised Mr. Zhong with a search warrant and found the digital keys to his crypto fortune hidden in a basement floor safe and a popcorn tin in the bathroom. Mr. Zhong, who pleaded guilty to wire fraud, is scheduled to be sentenced Friday in New York federal court, where prosecutors are seeking a prison sentence of less than two years.

Mr. Zhong's case is one of the highest-profile examples of how federal authorities have pierced the veil of blockchain transactions. Private and government investigators can now identify wallet addresses associated with terrorists, drug traffickers, money launderers and cybercriminals, all of which were supposed to be anonymous. Law-enforcement agencies, working with cryptocurrency exchanges and blockchain-analytics companies, have compiled data gleaned from earlier investigations, including the Silk Road case, to map the flow of cryptocurrency transactions across criminal networks worldwide. In the past two years, the U.S. has seized more than $10 billion worth of digital currency through successful prosecutions, according to the Internal Revenue Service -- in essence, by following the money. Instead of subpoenas to banks or other financial institutions, investigators can look to the blockchain for an instant snapshot of the money trail.

Apple

Make Something Wonderful: Steve Jobs in His Own Words (stevejobsarchive.com) 54

Steve Jobs Archive: The official ebook edition of Make Something Wonderful: Steve Jobs in his own words is free to read on Apple Books and from participating libraries through our partners at Libby. You can also download the book to view it on any compatible e-reader: our EPUB file works on almost all tablets, smartphones, desktop computers, and digital reading devices. From a speech in 2007: There's lots of ways to be, as a person. And some people express their deep appreciation in different ways. But one of the ways that I believe people express their appreciation to the rest of humanity is to make something wonderful and put it out there.

And you never meet the people. You never shake their hands. You never hear their story or tell yours. But somehow, in the act of making something with a great deal of care and love, something's transmitted there. And it's a way of expressing to the rest of our species our deep appreciation. So we need to be true to who we are and remember what's really important to us."

Software

Crypto's Ethereum Blockchain Completes Its Key Shanghai Software Upgrade (bloomberg.com) 17

The Ethereum blockchain, the most important commercial highway in the digital-asset sector, successfully implemented a widely anticipated software upgrade. From a report: The so-called Shanghai update enables investors to queue up to withdraw Ether coins that they had pledged to help operate the network in return for rewards, a process called staking. Tim Beiko, who helps to co-ordinate the development of Ethereum, posted on Twitter on Wednesday that the upgrade is now "official." The network revamp -- also known as Shapella -- is designed to let people exit an Ether staking investment and has stirred debate on whether the appeal of the largest token after Bitcoin will increase over time.

"Ethereum is updating and navigating with great skill -- so far anyway -- and cementing its position as the No. 2 crypto," said Aaron Brown, a crypto investor who writes for Bloomberg Opinion. He added that the network is "moving to the future much faster than Bitcoin." About 1.2 million of Ether tokens -- worth approximately $2.3 billion at current prices -- are expected to be withdrawn over the next five days, according to researcher Coin Metrics. Some $36.7 billion of Ether is locked up for staking, data from Staking Rewards shows.

Television

HBO Max To Be Renamed 'Max' With Addition of Discovery+ Content, Launch Date and Pricing Revealed (variety.com) 68

It's not HBO Max -- soon it's just going to be Max. From a report: Warner Bros. Discovery officially announced Max as the new name of its flagship streamer, lopping off the HBO part of the name as it mixes in a big bucket of new content from Discovery+ and other new original series. The company announced the name change at a press event Wednesday, where it also revealed a slate of upcoming projects. The rebuilt Max (on the web at max.com) is set to launch first in the U.S. on May 23, featuring what the company promises will be an average of more than 40 new titles and TV show seasons every month. "Max is the one to watch," WBD CEO David Zaslav said on stage at the event, featuring thousands of shows and movies on the service for every member of the household.

According to the service's website, Max will be available in three different versions. The first two plans align with the existing HBO Max pricing, and WBD said current HBO Max customers will not see their pricing change (for now) when the new service debuts. The third tier, "Max Ultimate," expands to up to four streams and includes 4K content. The trio of options are:
Max Ad-Lite ($9.99/month or $99.99/year): Two concurrent streams, 1080p HD resolution, no offline downloads, 5.1 surround sound quality
Max Ad Free ($15.99/month or $149.99/year): Two concurrent streams, 1080p HD, up to 30 offline downloads, 5.1 surround sound quality
Max Ultimate Ad Free ($19.99/month or $199.99/year): Four concurrent streams, up to 4K Ultra HD resolution, 100 offline downloads, Dolby Atmos sound quality

Apple

France Eyeing Antitrust Action Against Apple (axios.com) 25

The French Competition Authority is likely to move forward soon with an antitrust investigation into Apple over complaints tied to 2021 changes to its app tracking policies, Axios reported, citing sources. From the report: A formal investigation would mark the first major government move taken globally against Apple related to privacy rule changes that upended the digital advertising world. French regulators are favoring issuing a formal "Statement of Objections" to parties involved in the matter in coming weeks, sources told Axios.

That step would signal to groups that issued initial complaints about Apple's actions and Apple that the authority found evidence of illegal anticompetitive behavior in its initial review of the complaints it received. The 2020 complaint argues that Apple's app tracking changes did not adequately adhere to European Union privacy rules and that Apple failed to hold itself to the same ad targeting standards that it forced on its competitors because it targeted iOS users with ads from app tracking data. The complaint was filed jointly by four French advertising trade groups -- IAB France, Mobile Marketing Association (MMA), SRI and UDECAM.

Security

Mercenary Spyware Hacked iPhone Victims With Rogue Calendar Invites, Researchers Say (techcrunch.com) 10

Hackers using spyware made by a little known cyber mercenary company used malicious calendar invites to hack the iPhones of journalists, political opposition figures, and an NGO worker, according to two reports. From a report: Researchers at Microsoft and the digital rights group Citizen Lab analyzed samples of malware they say was created by QuaDream, an Israeli spyware maker that has been reported to develop zero-click exploits -- meaning hacking tools that don't require the target to click on malicious links -- for iPhones. QuaDream has been able to mostly fly under the radar until recently. In 2021, Israeli newspaper Haaretz reported that QuaDream sold its wares to Saudi Arabia. The next year, Reuters reported that QuaDream sold an exploit to hack iPhones that was similar to one provided by NSO Group, and that the company doesn't operate the spyware, its government customers do -- a common practice in the surveillance tech industry.

QuaDream's customers operated servers from several countries around the world: Bulgaria, Czech Republic, Hungary, Romania, Ghana, Israel, Mexico, Singapore, United Arab Emirates (UAE), and Uzbekistan, according to internet scans done by Citizen Lab. Both Citizen Lab and Microsoft published groundbreaking new technical reports on QuaDream's alleged spyware on Tuesday. Microsoft said it found the original malware samples, and then shared them with Citizen Lab's researchers, who were able to identify more than five victims -- an NGO worker, politicians, and journalists -- whose iPhones were hacked. The exploit used to hack those targets was developed for iOS 14, and at the time was unpatched and unknown to Apple, making it a so-called zero-day. The government hackers who were equipped with QuaDream's exploit used malicious calendar invites with dates in the past to deliver the malware, according to Citizen Lab.

Censorship

The Open Source VPN Out-Maneuvering Russian Censorship (wired.com) 16

An anonymous reader quotes a report from Wired: The Russian government has banned more than 10,000 websites for content about the war in Ukraine since Moscow launched the full-scale invasion in February 2022. The blacklist includes Facebook, Twitter, Instagram, and independent news outlets. Over the past year, Russians living inside the country have turned to censorship circumvention tools such as VPNs to pierce through the information blockade. But as dozens of virtual private networks get blocked, leaving users scrambling to maintain their access to free information, local activists and developers are coming up with new solutions. One of them is Amnezia VPN, a free, open source VPN client.

"We even do not advertise and promote it, and new users are still coming by the hundreds every day," says Mazay Banzaev, Amnezia VPN's founder. Unlike commercial VPNs that route users through company servers, which can be blocked, Amnezia VPN makes it simple for users to buy and set up their own servers. This allows them to choose their own IP address and use protocols that are harder to block. "More than half of the commercial VPNs in Russia have been blocked because it's easy enough to block them: They do not block them by protocols, but by IP addresses," says Banzaev. "[Amnezia] is an order of magnitude more resilient than a typical commercial VPN." Amnezia VPN is similar to Outline, a free and open source tool developed by Jigsaw, a subsidiary of Google. Amnezia was created in 2020 during a hackathon supported by Russian digital rights organization Roskomsvoboda. Even then, "it was clear that things were moving toward stricter censorship," says Banzaev. [...]

It is unclear how many users the service has, since the organization doesn't have a way to monitor user numbers, Banzaev says. However, Amnezia offers a Telegram bot called AmneziaFree, which shares VPN configurations that help users access blocked platforms and news; it has almost 100,000 users. The bot is currently struggling with overload, and users are complaining about spotty service. Banzaev says the Amnezia team is working to add new servers on a limited budget, and that they are also working on a new version of the service.
"Amnezia is not only used in Russia," notes Wired. "The service has spread to Turkmenistan, Iran, China, and other countries where users have been struggling with free access to the web."
Social Networks

Arkansas House Wants You To Show ID To Use Social Media (arktimes.com) 42

With no discussion, the Arkansas House of Representatives overwhelmingly approved a bill that would require social media users in The Natural State to verify they're 18 years old or older to use the platforms. Arkansas Times reports: The proposal, backed by Gov. Sarah Sanders, is aimed at shielding minors from the harmful effects of social media. Young folks could use the platforms, but only if parents provide consent. Senate Bill 396, sponsored by Sen. Tyler Dees (R-Springdale) and Rep. Jon Eubanks (R-Paris), would require social media companies including Facebook, Instagram, Twitter and TikTok to contract with third-party companies to perform age verification. Users would have to provide the third-party company with a digital driver's license. Dees also sponsored a bill, now law, that requires anyone who wants to watch online pornography to verify they're an adult.

The social media bill squeaked through the Senate with 18 yes votes, the bare minimum, but passed the House 82-10 with four voting present (same as no). No one asked any questions of Eubanks -- who assured his colleagues that Facebook had "the AI and algorithms" to keep track of what users had parental consent without holding on to sensitive data -- but because it was amended (to among other things exempt LinkedIn, the most boring social media platform), the bill has to go back to the Senate, where perhaps it will meet some resistance.
Utah's governor signed two bills into law last month requiring companies like Meta, Snap and TikTok to get parents permission before teens could create accounts on their platforms. "The laws also require curfew, parental controls and age verification features," adds Engadget.
Businesses

Unilever Claims It's a 'Cloud-Only Enterprise' (theregister.com) 63

Multi-brand consumer megacorp Unilever says it has become a "cloud-only enterprise" with the help of Accenture and Microsoft. From a report: One of the largest and most complex cloud migrations in the retail goods industry, according to the company, will give Unilever "resilient, secure and optimised operations" as well as "a platform to drive innovation and growth." The Anglo-Dutch biz owns more than 400 brands, which include everything from ice cream to shampoo to toilet cleaner, and is set to use Microsoft's Azure as its "primary cloud platform."

According to the corporate blurb, the move will see Unilever employ "industrial metaverse technologies" that use real-time data from factory digital twins. It musn't have got the memo from Microsoft, which recently put a bullet in its own industrial metaverse masterplan. The cloud contract is also expected to help "achieve perpetual breakthroughs in research and development," says Unilver. Lastly, through Microsoft's partnership with the controversial GPT maker, it will use "Azure OpenAI Service across Unilever's business to drive increased automation, enabling better customer and employee experiences."

Security

Flipper Zero Banned By Amazon for Being a 'Card Skimming Device' 50

Amazon has banned the sale of the Flipper Zero portable multi-tool for pen-testers as it no longer allows its sale on the platform after tagging it as a card-skimming device. From a report: The Flipper Zero is a compact, portable, and programmable pen-testing tool that can help experiment with and debug various digital and hardware devices via various protocols, including RFID, radio, NFC, infrared, Bluetooth, and others. Since its launch, users have showcased Flipper Zero's capabilities demonstrating its capacity to activate doorbells, conduct replay attacks to unlock cars and open garage doors, and clone a wide range of digital keys. According to notices sent to sellers on Thursday evening, Amazon has now banned Flipper Zero on its platform, tagging it as a "restricted product." Card-skimming devices are listed on Amazon's Seller Central portal under the Lock Picking & Theft Devices restricted product category, next to key duplicating devices and shoplifting devices, such as sensormatic detachers. Currently, some links to previously available Amazon pages selling Flipper Zero tools are dead and displaying "Sorry, we couldn't find that page. Try searching or go to Amazon's home page." errors, while others list it as "Unavailable."
Nintendo

Mario Is Moving Away From Mobile Games (variety.com) 18

In an exclusive interview with Variety, legendary video game designer, Nintendo fellow and self-proclaimed "Mario's mom", Shigeru Miyamoto, said: "Mobile apps will not be the primary path of future Mario games." From the report: After two moderately successful but dwindling iOS games, plus another that shuttered after two years, Nintendo is pulling Mario away from the mobile market. Released in 2016, Super Mario Run grossed $60 million in its first year, while 2019's Mario Kart Tour has generated $300 million (compared to Mario Kart 8's $3 billion and counting). Without explanation, Nintendo removed 2019's Dr. Mario World from app markets two years after its release.

"First and foremost, Nintendo's core strategy is a hardware and software integrated gaming experience," said Miyamoto, who played a pivotal role in designing the Wii, among other Nintendo consoles. "The intuitiveness of the control is a part of the gaming experience. When we explored the opportunity of making Mario games for the mobile phone -- which is a more common, generic device -- it was challenging to determine what that game should be. That is why I played the role of director for Super Mario Run, to be able to translate that Nintendo hardware experience into the smart devices."

Elaborating on the merits of Run and Tour, Miyamoto continued, "Having Mario games as mobile apps expands the doorway for far more audience to experience the game, and also expands the Mario gaming experience, where you only need your thumb on one hand." Referencing the innovation of the Super Mario Maker series and Super Mario Odyssey, which Miyamoto called "the ultimate evolution of a Mario adventure game on a typical 3D platformer," the Nintendo exec laid out how the company begins to develop a Mario game: "We try to define what is the gameplay, what is the method, and then define what devices we go on."
When asked when fans can expect the next mainline Mario game, Miyamoto chuckled and said: "All I can say is please stay tuned for future Nintendo Directs."
Sony

Sony Worries Microsoft Will Only Give It a 'Degraded' Call of Duty (arstechnica.com) 67

An anonymous reader quotes a report from Ars Technica: Late last month, UK regulators said they no longer believed a proposed Microsoft-owned Activision would bar Call of Duty games from PlayStation platforms, a reversal of earlier preliminary findings. Even if you grant that premise, though, Sony says that it's still worried Microsoft could give PlayStation owners a "degraded" version of new Call of Duty games in an effort to make the Xbox versions look better.

In a newly published response (PDF) to the UK's Competition and Markets Authority, Sony says the regulators' recent turnaround is "surprising, unprecedented, and irrational." The company takes specific issue with the regulators' "lifetime value" modeling, which Sony says heavily undervalues what an Xbox-exclusive Call of Duty would be worth to Microsoft. Beyond those technical concerns, though, Sony says it worries that Microsoft might subtly undermine PlayStation "simply by not making it as good as it could be." That could include small changes to the game's "performance [or] quality of play," but also secondary moves to "raise [Call of Duty's] price [on PlayStation], release the game at a later date, or make it available only on Game Pass." Microsoft would also "have no incentive to make use of the advanced features in PlayStation not found in Xbox," Sony says, an apparent reference to the PS5 controller's advanced haptics and built-in audio capabilities.

In its own newly filed response (PDF), Microsoft reiterated that it has "no intention to withhold or degrade access to Call of Duty or any other Activision content on PlayStation." That follows on a March filing where Microsoft promised Sony parity on Call of Duty's "release date, content, features, upgrades, quality, and playability." But Sony's response reflects a continued lack of trust in such promises. The company cites detailed analyses from the likes of Digital Foundry in saying that "the technical quality of Modern Warfare II was similar across platforms" in today's market. After a merger, though, Sony argues that "Microsoft would have different incentives because degrading the experience on PlayStation would benefit Xbox, PlayStation's 'closest rival.'"
"This kind of 'partial foreclosure' strategy might 'trigger fewer gamer complaints' than full Xbox exclusivity for Call of Duty, Sony says, while also allowing Microsoft to 'still secure revenues from sales of Call of Duty on PlayStation for a transitional period,'" reports Ars. "But Sony says the long-term results of this kind of 'degraded' PlayStation version would be the same as a full PlayStation ban: Call of Duty players abandoning Sony and moving to Microsoft's platforms."

"Such a move would 'seriously damage our reputation,' Sony Interactive Entertainment CEO Jim Ryan told the CMA in a recent hearing. 'Our gamers would desert our platform in droves and network effects would exacerbate the problem. Our business would never recover.'"
Facebook

India To Require Social Media Firms Rely on Government's Own Fact Checking (techcrunch.com) 48

India amended its IT law on Thursday to prohibit Facebook, Twitter and other social media firms from publishing, hosting or sharing false or misleading information about "any business" of the government and said the firms will be required to rely on New Delhi's own fact-check unit to determine the authenticity of any claim in a blow to many American giants that identify the South Asian market as their largest by users. From a report: Failure to comply with the rule, which also impacts internet service providers such as Jio and Airtel, risks the firms losing their safe harbour protections. The rule, first proposed in January this year, gives a unit of the government arbitrary and overbroad powers to determine the authenticity of online content and bypasses the principles of natural justice, said New Delhi-headquartered digital rights group Internet Freedom Foundation.
AI

India Opts Against AI Regulation 24

India does not plan to regulate the growth of AI within the South Asian market, identifying the sector as a "significant and strategic" area for the nation. This stance arrives at a time when numerous voices are calling for increased scrutiny of the rapidly advancing technology. From a report: The Ministry of Electronics and IT said in a long written response on Wednesday that it has assessed the ethical concerns and risks of bias and discrimination associated with AI. The ministry said it's implementing necessary policies and infrastructure measures to cultivate a robust AI sector in the country, but does not intend to introduce legislation to regulate its growth. The expansion of AI will have a "kinetic effect" on entrepreneurship and business development in India, the ministry asserted. "AI is a kinetic enabler of the digital economy and innovation ecosystem. Government is harnessing the potential of AI to provide personalized and interactive citizen-centric services through digital public platforms."
Privacy

Alcohol Recovery Startups Shared Patients' Private Data With Advertisers (techcrunch.com) 46

An anonymous reader quotes a report from TechCrunch: For years, online alcohol recovery startups Monument and Tempest were sharing with advertisers the personal information and health data of their patients without their consent. Monument, which acquired Tempest in 2022, confirmed the extensive years-long leak of patients' information in a data breach notification filed with California's attorney general last week, blaming their use of third-party tracking systems developed by ad giants including Facebook, Google, Microsoft and Pinterest. When reached for comment, Monument CEO Mike Russell confirmed more than 100,000 patients are affected.

In its disclosure, the companies confirmed their use of website trackers, which are small snippets of code that share with tech giants information about visitors to their websites, and often used for analytics and advertising. The data shared with advertisers includes patient names, dates of birth, email and postal addresses, phone numbers and membership numbers associated with the companies and patients' insurance provider. The data also included the person's photo, unique digital ID, which services or plan the patient is using, appointment information and assessment and survey responses submitted by the patient, which includes detailed responses about a person's alcohol consumption and used to determine their course of treatment.

Monument's own website says these survey answers are "protected" and "used only" by its care team. Monument confirmed that it shared patients' sensitive data with advertisers since January 2020, and Tempest since November 2017. Both companies say they have removed the tracking code from their websites. But the tech giants are not obligated to delete the data that Monument and Tempest shared with them.

Privacy

Labor To Consider Age-Verification 'Roadmap' For Restricting Online Pornography Access (theguardian.com) 122

An anonymous reader quotes a report from The Guardian: The federal government is considering a "roadmap" on how to restrict access to online pornography to those who can prove they are 18 or older, but there are warnings that any system could come at the cost of Australians' privacy online. On Friday, the eSafety commissioner provided a long-awaited roadmap to the government for how to verify users' ages online, which was commissioned by the former Morrison government nearly two years ago. The commissioner's office said the roadmap "explores if and how age verification and other measures could be used to prevent and mitigate harm to children from online pornography" but that any action taken will be a decision of government.

There were a variety of options to verify people's ages considered during the consultation for the roadmap, such as the use of third-party companies, individual sites verifying ages using ID documents or credit card checks, and internet service providers or mobile phone operators being used to check users' ages. Digital rights groups have raised concerns about the potential for any verification system to create a honeypot of people's personal information. But the office said any technology-based solution would need to strike the right balance between safety, privacy and security, and must be coupled with education campaigns for children, parents and educators. [...]

It comes as new industry codes aimed at tackling restricted-access content online, developed by groups representing digital platforms, and software, gaming and telecommunications companies were submitted to the eSafety commissioner for approval. The content covered includes child sexual abuse material, terrorism, extreme crime and violence, and drug-related content. The commissioner, Julie Inman Grant, will now decide whether the voluntary codes meet her expectations or whether she needs to enforce mandatory codes. [...] The second phase of the codes will set out how the platforms restrict access to pornography on their sites -- separate from the use of age verification systems.

Apple

Apple's Tim Cook Says AR and VR Are For 'Connection' and 'Communication' (theverge.com) 44

Tim Cook's vision for AR and VR hasn't changed. "For almost a decade, Apple's CEO has been banging the drum that AR is more important than VR and that AR is fundamentally about bringing people together," reports The Verge. "And he's still at it." From the report: "If you think about the technology itself with augmented reality, just to take one side of the AR/VR piece, the idea that you could overlay the physical world with things from the digital world could greatly enhance people's communication, people's connection," Cook told GQ's Zach Baron in a long and very interesting profile just published by the magazine. Cook told Baron that he's interested in collaboration; he said something about measuring glass walls; he said his thinking on glasses-as-gadget has changed over the years.

None of this is a product announcement, of course, only the latest in a long string of hints about what Apple sees in this space. Cook's been on this particular line since at least 2016, when he said on Good Morning America that AR "gives the capability for both of us to sit and be very present, talking to each other, but also have other things -- visually -- for both of us to see." [...] At various times over the years, Cook has said AR is a powerful technology for education, that he thinks it'll be as common as "eating three meals a day," and that he thinks AR is as big an idea as the smartphone. But he keeps coming back to the idea that AR should be meant to bring people together in the real world, not keep them apart or transport them to another universe entirely.

Cook also offered what sounds like an explanation for why the headset, which has been heavily rumored over the last couple of years, has taken so long to come out. "I'm not interested in putting together pieces of somebody else's stuff," he told GQ. "Because we want to control the primary technology. Because we know that's how you innovate." Maybe the most revealing thing in the story is the way Cook explains Apple -- or at least explains the way he hopes you'll see Apple. He talks frequently about Apple's environmental commitments, its loud fight against "the data-industrial complex," and the way Apple is trying to help people have better relationships with technology. (Conveniently ignoring that Apple is perhaps more responsible for our phone addictions than any other company, of course.) "Because my philosophy is, if you're looking at the phone more than you're looking in somebody's eyes, you're doing the wrong thing."
Apple plans to unveil a mixed-reality headset on June 5th at its annual Worldwide Developers Conference (WWDC).
Businesses

Hong Kong's Crypto Ambitions Get a Boost From US Crackdown (wsj.com) 13

Hong Kong's attempt to attract cryptocurrency companies is getting help from an intensifying crackdown by American regulators. From a report: The city was once home to a number of prominent companies, including Crypto.com, BitMEX and now-bankrupt FTX. But increasing competition from Singapore, concerns about China's tough approach to crypto and Hong Kong's prolonged and strict response to Covid-19 meant many companies in the sector left. Hong Kong is now determined to bring some of that action back, in contrast with the U.S. In the past few weeks alone, U.S. regulators have cut off access to crypto products and services, targeted crypto friendly banks, brought civil charges against celebrities said to have touted digital assets and sued exchanges including Binance, the operator of the world's largest crypto exchange. Prosecutors have also accused FTX founder Sam Bankman-Fried, who was based in Hong Kong at one point, of conspiring to bribe Chinese government officials in their latest indictment.

"The U.S. being more stringent these days than ever on crypto and Hong Kong regulating in a more favorable way...is going to clearly shift the center of gravity of crypto assets trading and investments more towards Hong Kong," said Ambre Soubiran, chief executive of Kaiko, a digital assets data provider based in Paris. "We want to be where our clients are," she said. Hong Kong's Securities and Futures Commission proposed a new licensing framework in February, focusing on investor protection. A senior official said at a briefing that the regulator wanted to prevent a recurrence of the problems that brought down FTX, as well as other fraudulent behavior. More than 20 crypto and blockchain companies from mainland China, Europe, Canada and Singapore have told the government they are planning to establish a presence in Hong Kong, while over 80 firms have expressed interest in doing so, according to official figures.

Slashdot Top Deals