×
AI

In America, A Complex Patchwork of State AI Regulations Has Already Arrived (cio.com) 13

While the European Parliament passed a wide-ranging "AI Act" in March, "Leaders from Microsoft, Google, and OpenAI have all called for AI regulations in the U.S.," writes CIO magazine. Even the Chamber of Commerce, "often opposed to business regulation, has called on Congress to protect human rights and national security as AI use expands," according to the article, while the White House has released a blueprint for an AI bill of rights.

But even though the U.S. Congress hasn't passed AI legislation — 16 different U.S. states have, "and state legislatures have already introduced more than 400 AI bills across the U.S. this year, six times the number introduced in 2023." Many of the bills are targeted both at the developers of AI technologies and the organizations putting AI tools to use, says Goli Mahdavi, a lawyer with global law firm BCLP, which has established an AI working group. And with populous states such as California, New York, Texas, and Florida either passing or considering AI legislation, companies doing business across the US won't be able to avoid the regulations. Enterprises developing and using AI should be ready to answer questions about how their AI tools work, even when deploying automated tools as simple as spam filtering, Mahdavi says. "Those questions will come from consumers, and they will come from regulators," she adds. "There's obviously going to be heightened scrutiny here across the board."
There's sector-specific bills, and bills that demand transparency (of both development and output), according to the article. "The third category of AI bills covers broad AI bills, often focused on transparency, preventing bias, requiring impact assessment, providing for consumer opt-outs, and other issues."

One example the article notes is Senate Bill 1047, introduced in the California State Legislature in February, "would require safety testing of AI products before they're released, and would require AI developers to prevent others from creating derivative models of their products that are used to cause critical harms."

Adrienne Fischer, a lawyer with Basecamp Legal, a Denver law firm monitoring state AI bills, tells CIO that many of the bills promote best practices in privacy and data security, but said the fragmented regulatory environment "underscores the call for national standards or laws to provide a coherent framework for AI usage."

Thanks to Slashdot reader snydeq for sharing the article.
Privacy

Four Baseball Teams Now Let Ticket-Holders Enter Using AI-Powered 'Facial Authentication' (sfgate.com) 42

"The San Francisco Giants are one of four teams in Major League Baseball this season offering fans a free shortcut through the gates into the ballpark," writes SFGate.

"The cost? Signing up for the league's 'facial authentication' software through its ticketing app." The Giants are using MLB's new Go-Ahead Entry program, which intends to cut down on wait times for fans entering games. The pitch is simple: Take a selfie through the MLB Ballpark app (which already has your tickets on it), upload the selfie and, once you're approved, breeze through the ticketing lines and into the ballpark. Fans will barely have to slow down at the entrance gate on their way to their seats...

The Philadelphia Phillies were MLB's test team for the technology in 2023. They're joined by the Giants, Nationals and Astros in 2024...

[Major League Baseball] says it won't be saving or storing pictures of faces in a database — and it clearly would really like you to not call this technology facial recognition. "This is not the type of facial recognition that's scanning a crowd and specifically looking for certain kinds of people," Karri Zaremba, a senior vice president at MLB, told ESPN. "It's facial authentication. ... That's the only way in which it's being utilized."

Privacy advocates "have pointed out that the creep of facial recognition technology may be something to be wary of," the article acknowledges. But it adds that using the technology is still completely optional.

And they also spoke to the San Francisco Giants' senior vice president of ticket sales, who gushed about the possibility of app users "walking into the ballpark without taking your phone out, or all four of us taking our phones out."
United States

US Invests $20 Billion More to Finance Clean-Energy Projects (msn.com) 86

Thursday America's Environmental Protection Agency "awarded $20 billion to help finance clean-energy projects across the country," reports the Washington Post. The money comes from the Greenhouse Gas Reduction Fund established by President Biden's signature climate law, the Inflation Reduction Act. The fund seeks to leverage public and private dollars to invest in clean-energy technologies such as solar panels, heat pumps and more.

The program is potentially one of the most consequential — yet least understood — parts of the climate law...

Simply put, the program allows people to access low-interest loans for clean-energy projects that they might not otherwise have received. Imagine a community group that wants to install electric vehicle charging stations at its neighborhood recreation center but can't get a loan from a bank or a lender. As is often the case, potential lenders say they're hesitant to support a novel green technology or a business without a track record of success. Low-income and minority communities have long encountered such obstacles in trying to attract private capital. The program aims to overcome this problem by providing a huge influx of federal cash — $27 billion in total — for nonprofit organizations to dole out to clean-energy projects nationwide. Each nonprofit will serve as a "green bank" that offers more favorable lending rates than commercial banks. "It's just really hard to get banks to bring capital into low-income communities, especially for these new projects that they're not used to financing," said Adrian Deveny, the founder of the firm Climate Vision and the former director of energy and environmental policy for Senate Majority Leader Charles E. Schumer (D-N.Y.), a key architect of the Inflation Reduction Act....

The EPA is awarding money to eight nonprofits, which have committed to leverage nearly $7 in private capital for every $1 of federal investment. The nonprofits have also pledged to ensure that at least 70 percent of the funds will benefit disadvantaged communities, and that the financed projects will reduce up to 40 million metric tons of carbon dioxide a year — equivalent to the annual emissions of nearly 9 million gasoline-powered cars... [The nonprofit] Coalition for Green Capital, will use a $5 billion award to establish a "national green bank," co-founder and CEO Reed Hundt said. "We're going to be able to cause about $100 billion of total additional investment over a seven-year time period with that number, because we can leverage it," Hundt said.

United States

Is The US About To Pass a Landmark Online Privacy Bill? (msn.com) 35

Leaders from two key committees in the U.S. Congress "are nearing an agreement on a national framework aimed at protecting Americans' personal data online," reports the Washington Post.

They call the move "a significant milestone that could put lawmakers closer than ever to passing legislation that has eluded them for decades, according to a person familiar with the matter, who spoke on the condition of anonymity to discuss the talks." The tentative deal is expected to broker a compromise between congressional Democrats and Republicans by preempting state data protection laws and creating a mechanism to let individuals sue companies that violate their privacy, the person said. Rep. Cathy McMorris Rodgers (R-Wash.) and Sen. Maria Cantwell (D-Wash.), the chairs of the House Energy and Commerce Committee and the Senate Commerce Committee, respectively, are expected to announce the deal next week...

Lawmakers have tried to pass a comprehensive federal privacy law for more than two decades, but negotiations in both chambers have repeatedly broken down amid partisan disputes over the scope of the protections. Those divides have created a vacuum that states have increasingly looked to fill, with more than a dozen passing their own privacy laws... [T]heir expected deal would mark the first time the heads of the two powerful commerce committees, which oversee a broad swath of internet policy, have come to terms on a major consumer privacy bill...

The federal government already has laws safeguarding people's health and financial data, in addition to protections for children's personal data, but there's no overarching standard to regulate the vast majority of the collection, use and sale of data that companies engage in online.

Space

Biden Takes Aim At SpaceX's Tax-Free Ride In American Airspace (nytimes.com) 222

Whenever a rocket launch occurs, air traffic controllers ensure the safety of commercial flights by managing airspace closures and monitoring rocket debris, without receiving compensation from commercial space companies like SpaceX for these services. The Biden administration's budget proposal aims to change this by suggesting that for-profit space companies begin paying for their use of government air traffic control resources. The New York Times reports: Commercial space companies are exempt from aviation excise taxes that fill the coffers of the Airport and Airway Trust Fund, which pays for the F.A.A.'s work and will get roughly $18 billion in tax revenues for the current fiscal year. The taxes are paid primarily by commercial airlines, which are charged 7.5 percent of each ticket price and an additional fee of about $5 to $20 per passenger, depending on the destination of each flight. Mr. Biden's budget proposal vows to work with Congress to overhaul the tax structure and split the cost of operating the nation's air traffic control system. His promise is based in part on an independent safety review report commissioned by the F.A.A., which advises that the federal government update the excise taxes to charge commercial space companies.

Mr. Biden's call for revising the decades-old excise tax structure is part of his push to make richer Americans and wealthy corporations "pay their fair share." In his State of the Union speech last month, Mr. Biden also called for raising taxes on private and corporate jet users, including increasing the tax that they pay on jet fuel to $1.06 per gallon from 21.8 cents per gallon over five years. That tax on fuel currently makes up around 3 percent of the annual revenue of the trust fund, which depends heavily on what commercial airlines and its passengers pay. Yet commercial space companies do not contribute to that fund or share any of the cost that the public bears when rockets are launched, said William J. McGee, a former F.A.A.-licensed aircraft dispatcher and a senior fellow at the American Economic Liberties Project, a consumer advocacy group. "This is a question of fundamental fairness," Mr. McGee said. "It would be the equivalent of having a toll system on a highway and waving through certain users and not others."

Printer

Trudeau Pushes 3D-Printed Homes To Solve Canada Housing Crisis (dailyhive.com) 174

An anonymous reader quotes a report from the Daily Hive: It is now the third consecutive day a major housing funding announcement has been made by Prime Minister Justin Trudeau. Friday's announcement entails over $600 million in investments targeted to help lower the construction cost of homes and speed up building timelines, with a new focus on creating new building innovation technologies. This includes a new $50 million Homebuilding Technology and Innovation Fund, which the federal government aims to leverage an additional $150 million from the private sector and other levels of government. Another $50 million will be invested in ideas and technology such as prefabricated housing factories, mass timber production, panelization, 3D printing, and pre-approved home design catalogues -- specifically projects already funded.

As well, $11.6 million will go towards the federal government's previously announced Housing Design Catalogue to create a standardized home structure design for simplicity as well as construction and cost efficiencies. The vast majority of today's announced funding will go into the federal Apartment Construction Loan Program, which provides low-cost financing to support new rental housing projects using innovative construction techniques from prefabricated and modular housing manufacturers as well as other homebuilders.
Prime Minister Justin Trudeau said in a statement: "We're changing the way we build homes in Canada. In Budget 2024, we're supporting a new approach to construction, with a focus on innovation and technology. This will make it easier and more cost-effective to build more homes, faster. You should be able to live in the community you love, at a price you can afford."
Privacy

Academics Probe Apple's Privacy Settings and Get Lost and Confused (theregister.com) 24

Matthew Connatser reports via The Register: A study has concluded that Apple's privacy practices aren't particularly effective, because default apps on the iPhone and Mac have limited privacy settings and confusing configuration options. The research was conducted by Amel Bourdoucen and Janne Lindqvist of Aalto University in Finland. The pair noted that while many studies had examined privacy issues with third-party apps for Apple devices, very little literature investigates the issue in first-party apps -- like Safari and Siri. The aims of the study [PDF] were to investigate how much data Apple's own apps collect and where it's sent, and to see if users could figure out how to navigate the landscape of Apple's privacy settings.

The lengths to which Apple goes to secure its ecosystem -- as described in its Platform Security Guide [PDF] -- has earned it kudos from the information security world. Cupertino uses its hard-earned reputation as a selling point and as a bludgeon against Google. Bourdoucen and Janne Lindqvist don't dispute Apple's technical prowess, but argue that it is undermined by confusing user interfaces. "Our work shows that users may disable default apps, only to discover later that the settings do not match their initial preference," the paper states. "Our results demonstrate users are not correctly able to configure the desired privacy settings of default apps. In addition, we discovered that some default app configurations can even reduce trust in family relationships."

The researchers criticize data collection by Apple apps like Safari and Siri, where that data is sent, how users can (and can't) disable that data tracking, and how Apple presents privacy options to users. The paper illustrates these issues in a discussion of Apple's Siri voice assistant. While users can ostensibly choose not to enable Siri in the initial setup on macOS-powered devices, it still collects data from other apps to provide suggestions. To fully disable Siri, Apple users must find privacy-related options across five different submenus in the Settings app. Apple's own documentation for how its privacy settings work isn't good either. It doesn't mention every privacy option, explain what is done with user data, or highlight whether settings are enabled or disabled. Also, it's written in legalese, which almost guarantees no normal user will ever read it. "We discovered that the features are not clearly documented," the paper concludes. "Specifically, we discovered that steps required to disable features of default apps are largely undocumented and the data handling practices are not completely disclosed."

Bitcoin

Terraform Labs and Founder Do Kwon Found Liable In US Civil Fraud Trial (reuters.com) 12

Terraform Labs and its founder Do Kwon have been found liable on civil fraud charges on Friday by a jury in Manhattan. The jury agreed with the SEC that the two misled investors before their stablecoin's 2022 collapse shocked crypto markets around the world. Reuters reports: The SEC accused the company and Kwon of misleading investors in 2021 about the stability of TerraUSD, a stablecoin designed to maintain a value of $1. The regulator also accused them of falsely claiming Terraform's blockchain was used in a popular Korean mobile payment app. SEC attorney Laura Meehan said during closing arguments that the platform's success story was "built on lies." "If you swing big and you miss, and you don't tell people that you came up short, that is fraud," Meehan said.

Louis Pellegrino, an attorney for Terraform, told the jury on Friday the SEC's case relied on statements taken out of context and that Terraform and Kwon had been truthful about their products and how they worked, even when they failed. "Terraform is still out there, trying to rebuild and make purchasers whole," he said. The regulator is seeking civil financial penalties and orders barring Kwon and Terraform from the securities industry. Kwon, who was arrested in Montenegro in March 2023, did not attend the trial, which began March 25. Both the U.S. and South Korea, where Kwon is a citizen, have sought his extradition on criminal charges.

Privacy

Commercial Bank of Ethiopia Names and Shames Customers Over Bank Glitch Money (bbc.com) 26

An Ethiopian bank has put up posters shaming customers it says have not returned money they gained during a technical glitch. From a report: Notices bearing their names and photos could be seen outside branches of the Commercial Bank of Ethiopia (CBE) on Friday. The bank says it has recovered almost three-quarters of the $14m it lost, its head said last week. He warned that those keeping money that is not theirs will be prosecuted. Last month, an hours-long glitch allowed customers at the CBE, Ethiopia's largest commercial bank, to withdraw or transfer more than they had in their accounts.
Advertising

Roku's New HDMI Tech Could Show Ads When You Pause Your Game (kotaku.com) 119

An anonymous reader quotes a report from Kotaku: A new patent recently filed by TV and streaming device manufacturer Roku hints toward a possible future where televisions could display ads when you pause a movie or game. For Roku, the time in which the TV is on but users aren't doing anything is valuable. The company has started leasing out ad space in its popular Roku City screensaver -- which appears when your TV is idle -- to companies like McDonald's and movies like Barbie. As tech newsletter Lowpass points out, Roku finds this idle time and its screensaver so valuable that it forbids app developers from overriding the screensaver with their own. But, if you plug in an Xbox or DVD player into the HDMI port on a Roku TV, you bypass the company's screensaver and other ads. And so, Roku has been figuring out a way to not let that happen.

As reported by Lowpass on April 4, Roku recently filed a patent for a technology that would let it inject ads into third-party content -- like an Xbox game or Netflix movie -- using an HDMI connection. The patent describes a situation where you are playing a video game and hit pause to go check your phone or grab some food. At this point, Roku would identify that you have paused the content and display a relevant ad until you unpaused the game. Roku's tech isn't designed to randomly inject ads as you are playing a game or watching a movie, it knows that would be going too far and anger people. Instead, the patent suggests several ways that Roku could spot when your TV is paused, like comparing frames, to make sure the user has actually paused the content. Roku might also use the HDMI's audio feed to search for extended moments of silence. The company also proposes using HDMI CEC -- a protocol designed to help devices communicate better -- to figure out when you pause and unpause content. Similarly, Roku's patent explains that it will use various methods to detect what people are playing or watching and try to display relevant ads. So if it sees you have an Xbox plugged in, it might try to serve you ads that it thinks an Xbox owner would be interested in.

Piracy

Plex Asks GitHub to Take Down 'Reshare' Repository Over Piracy Fears (torrentfreak.com) 60

Plex is a multi-functional streaming platform that allows users to watch, organize, and curate their favorite media entertainment. Sharing Plex libraries is also an option; one that comes with piracy concerns. In an effort to "avoid the growth of piracy," Plex asked GitHub to remove a repository that allows people to reshare libraries that were not originally theirs. TorrentFreak reports: The Swiss company, which is headquartered in the U.S., asked GitHub to remove a "Plex Reshare" repository, alleging that it may contribute to its piracy problem. "Plex Reshare" doesn't host any copyright-infringing material and, as far as we've seen, it doesn't reference any either. Its main purpose is to allow Plex users to make shared Plex directories browsable on the web, which allows people to "reshare" them without being the original owner. "The reason behind this project is to make available your PLEX shares to other friends unrelated to the person who owns the original library," Plex Reshare developer Peter explains.

While the repository doesn't host or link to copyright-infringing material, Plex argues that it can be used to 'grow' piracy. "We have found infringing material in your website which indeed is OTHER 'Plex Server'. The material that is claimed to be infringing is to be removed or access to which is to be disabled immediately and avoid the growth of piracy," the takedown notice reads. The first part of the sentence is somewhat confusing. Plex-reshare is not a Plex server but the company may use "OTHER Plex Server" as an internal classification category. In any case, Plex alleges that the repository can contribute to the growth of piracy on its platform.

Citing the Online Copyright Infringement Liability Limitation Act, Plex urges GitHub to take immediate action, or else it may be held liable. It's not clear what this liability claim rests on, as there are no actual copyright infringements mentioned in the takedown notice. Despite the broad nature of this claim, GitHub has indeed taken the repository offline, replacing it with a DMCA takedown reference. This likely wasn't a straightforward decision as GitHub is known to put developers first with these types of issues. In this case, it took more than three weeks before GitHub took action, which is much longer than usual. This suggests that GitHub allowed the developer to respond and may have sought legal advice from in-house lawyers, to ensure that the rights of all parties are properly considered.
The report notes that the Plex-reshare code is listed on Docker Hub as well, which means it may face a similar fate.
Cellphones

Feds Finally Decide To Do Something About Years-Old SS7 Spy Holes In Phone Networks 32

Jessica Lyons reports via The Register: The FCC appears to finally be stepping up efforts to secure decades-old flaws in American telephone networks that are allegedly being used by foreign governments and surveillance outfits to remotely spy on and monitor wireless devices. At issue are the Signaling System Number 7 (SS7) and Diameter protocols, which are used by fixed and mobile network operators to enable interconnection between networks. They are part of the glue that holds today's telecommunications together. According to the US watchdog and some lawmakers, both protocols include security weaknesses that leave folks vulnerable to unwanted snooping. SS7's problems have been known about for years and years, as far back as at least 2008, and we wrote about them in 2010 and 2014, for instance. Little has been done to address these exploitable shortcomings.

SS7, which was developed in the mid-1970s, can be potentially abused to track people's phones' locations; redirect calls and text messages so that info can be intercepted; and spy on users. The Diameter protocol was developed in the late-1990s and includes support for network access and IP mobility in local and roaming calls and messages. It does not, however, encrypt originating IP addresses during transport, which makes it easier for miscreants to carry out network spoofing attacks. "As coverage expands, and more networks and participants are introduced, the opportunity for a bad actor to exploit SS7 and Diameter has increased," according to the FCC [PDF].

On March 27 the commission asked telecommunications providers to weigh in and detail what they are doing to prevent SS7 and Diameter vulnerabilities from being misused to track consumers' locations. The FCC has also asked carriers to detail any exploits of the protocols since 2018. The regulator wants to know the date(s) of the incident(s), what happened, which vulnerabilities were exploited and with which techniques, where the location tracking occurred, and -- if known -- the attacker's identity. This time frame is significant because in 2018, the Communications Security, Reliability, and Interoperability Council (CSRIC), a federal advisory committee to the FCC, issued several security best practices to prevent network intrusions and unauthorized location tracking. Interested parties have until April 26 to submit comments, and then the FCC has a month to respond.
AI

George Carlin Estate Forces 'AI Carlin' Off the Internet For Good (arstechnica.com) 31

An anonymous reader quotes a report from Ars Technica: The George Carlin estate has settled its lawsuit with Dudesy, the podcast that purportedly used a "comedy AI" to produce an hour-long stand-up special in the style and voice of the late comedian. Dudesy's "George Carlin: Dead and Loving It" special, which was first uploaded in early January, gained hundreds of thousands of views and plenty of media attention for its presentation as a creation of an AI that had "listened to all of George Carlin's material... to imitate his voice, cadence and attitude as well as the subject matter I think would have interested him today." But even before the Carlin estate lawsuit was filed, there were numerous signs that the special was not actually written by an AI, as Ars laid out in detail in a feature report.

Shortly after the Carlin estate filed its lawsuit against Dudesy in late January, a representative for Dudesy host Will Sasso told The New York Times that the special had actually been "completely written by [Dudesy co-host] Chad Kultgen." Regardless of the special's actual authorship, though, the lawsuit also took Dudesy to task for "capitaliz[ing] on the name, reputation, and likeness of George Carlin in creating, promoting, and distributing the Dudesy Special and using generated images of Carlin, Carlin's voice, and images designed to evoke Carlin's presence on a stage." The resulting "association" between the real Carlin and this ersatz version put Dudesy in potential legal jeopardy, even if the contentious and unsettled copyright issues regarding AI training and authorship weren't in play.

Court documents note that shortly after the lawsuit was filed, Dudesy had already "taken reasonable steps" to remove the special and any mention of Carlin from all of Dudesy's online accounts. The settlement restrains the Dudesy podcast (and those associated with it) from re-uploading the special anywhere and from "using George Carlin's image, voice, or likeness" in any content posted anywhere on the Internet. Archived copies of the special are still available on the Internet if you know where to look. While the settlement notes that those reposts are also in "violat[ion] of this order," Dudesy will not be held liable for any reuploads made by unrelated third parties.

Privacy

Missouri County Declares State of Emergency Amid Suspected Ransomware Attack (arstechnica.com) 41

An anonymous reader quotes a report from Ars Technica: Jackson County, Missouri, has declared a state of emergency and closed key offices indefinitely as it responds to what officials believe is a ransomware attack that has made some of its IT systems inoperable. "Jackson County has identified significant disruptions within its IT systems, potentially attributable to a ransomware attack," officials wrote Tuesday. "Early indications suggest operational inconsistencies across its digital infrastructure and certain systems have been rendered inoperative while others continue to function as normal."

The systems confirmed inoperable include tax and online property payments, issuance of marriage licenses, and inmate searches. In response, the Assessment, Collection and Recorder of Deeds offices at all county locations are closed until further notice. The closure occurred the same day that the county was holding a special election to vote on a proposed sales tax to fund a stadium for MLB's Kansas City Royals and the NFL's Kansas City Chiefs. Neither the Jackson County Board of Elections nor the Kansas City Board of Elections have been affected by the attack; both remain open.

The Jackson County website says there are 654,000 residents in the 607-square-mile county, which includes most of Kansas City, the biggest city in Missouri. The response to the attack and the investigation into it have just begun, but so far, officials said they had no evidence that data had been compromised. Jackson County Executive Frank White, Jr. has issued (PDF) an executive order declaring a state of emergency. The County has notified law enforcement and retained IT security contractors to help investigate and remediate the attack.
"The potential significant budgetary impact of this incident may require appropriations from the County's emergency fund and, if these funds are found to be insufficient, the enactment of additional budgetary adjustments or cuts," White wrote. "It is directed that all county staff are to take whatever steps are necessary to protect resident data, county assets, and continue essential services, thereby mitigating the impact of this potential ransomware attack."
AI

UK and US Sign Landmark Agreement On AI Safety (bbc.com) 6

The UK and US have signed a landmark deal to work together on testing advanced artificial intelligence (AI) and develop "robust" safety methods for AI tools and their underlying systems. "It is the first bilateral agreement of its kind," reports the BBC. From the report: UK tech minister Michelle Donelan said it is "the defining technology challenge of our generation." "We have always been clear that ensuring the safe development of AI is a shared global issue," she said. "Only by working together can we address the technology's risks head on and harness its enormous potential to help us all live easier and healthier lives."

The secretary of state for science, innovation and technology added that the agreement builds upon commitments made at the AI Safety Summit held in Bletchley Park in November 2023. The event, attended by AI bosses including OpenAI's Sam Altman, Google DeepMind's Demis Hassabis and tech billionaire Elon Musk, saw both the UK and US create AI Safety Institutes which aim to evaluate open and closed-source AI systems. [...]

Gina Raimondo, the US commerce secretary, said the agreement will give the governments a better understanding of AI systems, which will allow them to give better guidance. "It will accelerate both of our Institutes' work across the full spectrum of risks, whether to our national security or to our broader society," she said. "Our partnership makes clear that we aren't running away from these concerns - we're running at them."

Medicine

'Russia Might Have Caused Havana Syndrome' (washingtonpost.com) 188

An anonymous reader quotes an opinion piece from the Washington Post, published by the Editorial Board: A just-published investigation by Russian, American and German journalists has unearthed startling new information about the so-called Havana syndrome, or "Anomalous Health Incidents," as the government calls the unexplained bouts of painful disorientation that U.S. diplomats and intelligence officers have suffered in recent years. The new information suggests but does not prove that Russia's military intelligence agency is responsible. Earlier, agencies in the U.S. intelligence community had concluded that "it is very unlikely a foreign adversary is responsible." They need to look again. [...]

[T]he new investigation by the Insider, a Russian investigative news outlet, in collaboration with CBS's "60 Minutes" and Germany's Der Spiegel, paints a different picture. It identifies the possible culprit as Unit 29155, a "notorious assassination and sabotage squad" of the GRU, Moscow's military intelligence service. Senior members of the unit received "awards and political promotions for work related to the development of 'non-lethal acoustic weapons'" -- a term used in the Russian military-scientific literature to describe both sound- and radiofrequency-based directed energy devices. The investigation found documentary evidence that Unit 29155 "has been experimenting with exactly the kind of weaponized technology" experts suggest is a plausible cause. Moreover, the Insider reported, geolocation data shows that operators attached to Unit 29155, traveling undercover, were present in places where Havana syndrome struck, just before the incidents took place.

Even more concerning, the investigation found that a commonality among the Americans targeted was their work history on Russia issues. This included CIA officers who were helping Ukraine build up its intelligence capabilities in the years before Russia's full-scale invasion in 2022. One veteran of the CIA Kyiv station was named the new chief of station in Vietnam and was hit there. A second veteran of the CIA in Ukraine was hit in his apartment in Tashkent, Uzbekistan. Both these intelligence officers had to be medevaced and were treated at Walter Reed National Military Medical Center. The wife of a third CIA officer who had served in Kyiv was hit in London. "Of all the cases" examined by the news organizations, they said, "the most well-documented involve U.S. intelligence and diplomatic personnel with subject matter expertise in Russia or operational experience in countries such as Georgia and Ukraine," both of which were the scene of popular pro-Western uprisings in the past two decades. The news organizations point out that Russian President Vladimir Putin has often blamed these "color revolutions" on the CIA and the State Department. They conclude, "Putin would have every interest in neutralizing scores of U.S. intelligence officers he deemed responsible for his loss of the former satellites."
The Editorial Board is advocating for a thorough and aggressive investigation by the U.S. intelligence community that "takes into account all aspects of the incidents."

"If the incidents are a deliberate attack, the perpetrator must be identified and held to account. Along with sending a message to those who might harm American personnel, the United States needs to show all those who might join the diplomatic and intelligence services that the government will protect them abroad and at home from foreign adversaries, no matter what."
The Internet

FCC To Vote To Restore Net Neutrality Rules (reuters.com) 60

An anonymous reader quotes a report from Reuters: The U.S. Federal Communications Commission will vote to reinstate landmark net neutrality rules and assume new regulatory oversight of broadband internet that was rescinded under former President Donald Trump, the agency's chair said. The FCC told advocates on Tuesday of the plan to vote on the final rule at its April 25 meeting. The commission voted 3-2 in October on the proposal to reinstate open internet rules adopted in 2015 and re-establish the commission's authority over broadband internet.

Net neutrality refers to the principle that internet service providers should enable access to all content and applications regardless of the source, and without favoring or blocking particular products or websites. FCC Chair Jessica Rosenworcel confirmed the planned commission vote in an interview with Reuters. "The pandemic made clear that broadband is an essential service, that every one of us -- no matter who we are or where we live -- needs it to have a fair shot at success in the digital age," she said. "An essential service requires oversight and in this case we are just putting back in place the rules that have already been court-approved that ensures that broadband access is fast, open and fair."

Security

New XZ Backdoor Scanner Detects Implants In Any Linux Binary (bleepingcomputer.com) 33

Bill Toulas reports via BleepingComputer: Firmware security firm Binarly has released a free online scanner to detect Linux executables impacted by the XZ Utils supply chain attack, tracked as CVE-2024-3094. CVE-2024-3094 is a supply chain compromise in XZ Utils, a set of data compression tools and libraries used in many major Linux distributions. Late last month, Microsoft engineer Andres Freud discovered the backdoor in the latest version of the XZ Utils package while investigating unusually slow SSH logins on Debian Sid, a rolling release of the Linux distribution.

The backdoor was introduced by a pseudonymous contributor to XZ version 5.6.0, which remained present in 5.6.1. However, only a few Linux distributions and versions following a "bleeding edge" upgrading approach were impacted, with most using an earlier, safe library version. Following the discovery of the backdoor, a detection and remediation effort was started, with CISA proposing downgrading the XZ Utils 5.4.6 Stable and hunting for and reporting any malicious activity.

Binarly says the approach taken so far in the threat mitigation efforts relies on simple checks such as byte string matching, file hash blocklisting, and YARA rules, which could lead to false positives. This approach can trigger significant alert fatigue and doesn't help detect similar backdoors on other projects. To address this problem, Binarly developed a dedicated scanner that would work for the particular library and any file carrying the same backdoor. [...] Binarly's scanner increases detection as it scans for various supply chain points beyond just the XZ Utils project, and the results are of much higher confidence.
Binarly has made a free API available to accomodate bulk scans, too.
Piracy

The Pirate Bay's Oldest Torrent Is Now 20 Years Old (torrentfreak.com) 15

An anonymous reader quotes a report from TorrentFreak: Today, more than two decades have passed and most of the files shared on The Pirate Bay in the early years are no longer available. BitTorrent requires at least one person to share a full file copy, which is hard to keep up for decades. Surprisingly, however, several torrents have managed to stand the test of time and remain available today. A few days ago the site's longest surviving torrent turned 20 years old. While a few candidates have shown up over the years, we believe that an episode of "High Chaparral" has the honor of being the oldest Pirate Bay torrent that's still active today. The file was originally uploaded on March 25, 2004, and several people continue to share it today. The screenshot [here] only lists one seeder but according to information passed on by OpenTrackr.org, there are four seeders with a full copy. This is quite a remarkable achievement, especially since people complained about a lack of seeders shortly after it was uploaded.

Over the years, the "High Chaparral" torrent achieved cult status among a small group of people who likely keep sharing it, simply because it's the oldest surviving torrent. This became evident in the Pirate Bay comment section several years ago, when TPB still had comments. Record or not, other old torrents on The Pirate Bay also continue to thrive. On March 31, 2004, someone uploaded a pirated copy of the documentary "Revolution OS" to the site which is alive and kicking today.

While these torrents are quite old, they're not the oldest active torrents available on the Internet. That honor goes to "The Fanimatrix", which was created in September 2003 and, after being previously resurrected, continues to be available today with more than 100 people seeding. Ten years ago, we were surprised to see that any of the mentioned torrents were still active. By now, however, we wouldn't be shocked to see these torrents survive for decades. Whether The Pirate Bay will still be around then is another question.

Google

Google Pledges To Destroy Browsing Data To Settle 'Incognito' Lawsuit (wsj.com) 35

Google plans to destroy a trove of data that reflects millions of users' web-browsing histories, part of a settlement of a lawsuit that alleged the company tracked millions of users without their knowledge. WSJ: The class action, filed in 2020, accused Google of misleading users about how Chrome tracked the activity of anyone who used the private "Incognito" browsing option. The lawsuit alleged that Google's marketing and privacy disclosures didn't properly inform users of the kinds of data being collected, including details about which websites they viewed. The settlement details, filed Monday in San Francisco federal court, set out the actions the company will take to change its practices around private browsing. According to the court filing, Google has agreed to destroy billions of data points that the lawsuit alleges it improperly collected, to update disclosures about what it collects in private browsing and give users the option to disable third-party cookies in that setting.

The agreement doesn't include damages for individual users. But the settlement will allow individuals to file claims. Already the plaintiff attorneys have filed 50 in California state court. Attorney David Boies, who represents the consumers in the lawsuit, said the settlement requires Google to delete and remediate "in unprecedented scope and scale" the data it improperly collected. "This settlement is an historic step in requiring honesty and accountability from dominant technology companies," Boies said.

Slashdot Top Deals