Government

Does the World Need Publicly-Owned Social Networks? (elpais.com) 122

"Do we need publicly-owned social networks to escape Silicon Valley?" asks an opinion piece in Spain's El Pais newspaper.

It argues it's necessary because social media platforms "have consolidated themselves as quasi-monopolies, with a business model that consists of violating our privacy in search of data to sell ads..." Among the proposals and alternatives to these platforms, the idea of public social media networks has often been mentioned. Imagine, for example, a Twitter for the European Union, or a Facebook managed by media outlets like the BBC. In February, Spanish Prime Minister Pedro Sánchez called for "the development of our own browsers, European public and private social networks and messaging services that use transparent protocols." Former Spanish prime minister José Luis Rodríguez Zapatero — who governed from 2004 until 2011 — and the left-wing Sumar bloc in the Spanish Parliament have also proposed this. And, back in 2021, former British Labour Party leader Jeremy Corbyn made a similar suggestion.

At first glance, this may seem like a good idea: a public platform wouldn't require algorithms — which are designed to stimulate addiction and confrontation — nor would it have to collect private information to sell ads. Such a platform could even facilitate public conversations, as pointed out by James Muldoon, a professor at Essex Business School and author of Platform Socialism: How to Reclaim our Digital Future from Big Tech (2022)... This could be an alternative that would contribute to platform pluralism and ensure we're not dependent on a handful of billionaires. This is especially important at a time when we're increasingly aware that technology isn't neutral and that private platforms respond to both economic and political interests.

There's other possibilities. Further down they write that "it makes much more sense for the state to invest in, or collaborate with, decentralized social media networks based on free and interoperable software" that "allow for the portability of information and content." They even spoke to Cory Doctorow, who they say "proposes that the state cooperate with the software systems, developers, or servers for existing open-source platforms, such as the U.S. network Bluesky or the German firm Mastodon." (Doctorow adds that reclaiming digital independence "is incredibly important, it's incredibly difficult, and it's incredibly urgent."

The article also acknowledges the option of "legislative initiatives — such as antitrust laws, or even stricter regulations than those imposed in Europe — that limit or prevent surveillance capitalism." (Though they also figures showing U.S. tech giants have one of the largest lobbying groups in the EU, with Meta being the top spender...)
Open Source

SerenityOS Creator Is Building an Independent, Standards-First Browser Called 'Ladybird' (thenewstack.io) 40

A year ago, the original creator of SerenityOS posted that "for the past two years, I've been almost entirely focused on Ladybird, a new web browser that started as a simple HTML viewer for SerenityOS." So it became a stand-alone project that "aims to render the modern web with good performance, stability and security." And they're also building a new web engine.

"We are building a brand-new browser from scratch, backed by a non-profit..." says Ladybird's official web site, adding that they're driven "by a web standards first approach." They promise it will be truly independent, with "no code from other browsers" (and no "default search engine" deals).

"We are targeting Summer 2026 for a first Alpha version on Linux and macOS. This will be aimed at developers and early adopters." More from the Ladybird FAQ: We currently have 7 paid full-time engineers working on Ladybird. There is also a large community of volunteer contributors... The focus of the Ladybird project is to build a new browser engine from the ground up. We don't use code from Blink, WebKit, Gecko, or any other browser engine...

For historical reasons, the browser uses various libraries from the SerenityOS project, which has a strong culture of writing everything from scratch. Now that Ladybird has forked from SerenityOS, it is no longer bound by this culture, and we will be making use of 3rd party libraries for common functionality (e.g image/audio/video formats, encryption, graphics, etc.) We are already using some of the same 3rd party libraries that other browsers use, but we will never adopt another browser engine instead of building our own...

We don't have anyone actively working on Windows support, and there are considerable changes required to make it work well outside a Unix-like environment. We would like to do Windows eventually, but it's not a priority at the moment.

"Ladybird's founder Andreas Kling has a solid background in WebKit-based C++ development with both Apple and Nokia,," writes software developer/author David Eastman: "You are likely reading this on a browser that is slightly faster because of my work," he wrote on his blog's introduction page. After leaving Apple, clearly burnt out, Kling found himself in need of something to healthily occupy his time. He could have chosen to learn needlepoint, but instead he opted to build his own operating system, called Serenity. Ladybird is a web project spin-off from this, to which Kling now devotes his time...

[B]eyond the extensive open source politics, the main reason for supporting other independent browser projects is to maintain diverse alternatives — to prevent the web platform from being entirely captured by one company. This is where Ladybird comes in. It doesn't have any commercial foundation and it doesn't seem to be waiting to grab a commercial opportunity. It has a range of sponsors, some of which might be strategic (for example, Shopify), but most are goodwill or alignment-led. If you sponsor Ladybird, it will put your logo on its webpage and say thank you. That's it. This might seem uncontroversial, but other nonprofit organisations also give board seats to high-paying sponsors. Ladybird explicitly refuses to do this...

The Acid3 Browser test (which has nothing whatsoever to do with ACID compliance in databases) is an old method of checking compliance with web standards, but vendors can still check how their products do against a battery of tests. They check compliance for the DOM2, CSS3, HTML4 and the other standards that make sure that webpages work in a predictable way. If I point my Chrome browser on my MacBook to http://acid3.acidtests.org/, it gets 94/100. Safari does a bit better, getting to 97/100. Ladybird reportedly passes all 100 tests.

"All the code is hosted on GitHub," says the Ladybird home page. "Clone it, build it, and join our Discord if you want to collaborate on it!"
First Person Shooters (Games)

New 'Doom: The Dark Ages' Already Adjusted to Add Even More Dangerous Demons (windowscentral.com) 23

Doom: The Dark Ages just launched on May 15. But it's already received "difficulty" balance changes "that have made the demons of Hell even more dangerous than ever," writes Windows Central: According to DOOM's official website Slayer's Club, these balance adjustments are focused on making the game harder, as players have been leaving feedback saying it felt too easy even on Nightmare Mode. As a result, enemies now hit harder, health and armor item pick-ups drop less often, and certain enemies punish you more severely for mistiming the parry mechanic.
It reached three million players in just five days, which was seven times faster than 2020's Doom: Eternal," reports Wccftech (though according to analytics firm Ampere Analysis (via The Game Business), more than two million of those three million launch players were playing on Xbox, while only 500K were playing on PS5.") "id Software proves it can still reinvent the wheel," according to one reviewer, "shaking up numerous aspects of gameplay, exchanging elaborate platforming for brutal on-the-ground action, as well as the ability to soar on a dragon's back or stomp around in a giant mech."

And the New York Times says the game "effectively reinvents the hellish shooter with a revamped movement system and deepened lore" in the medieval goth-themed game... Double jumping and dashing are ditched and replaced with an emphasis on raw power and slow, strategic melee combat. Doom Slayer's arsenal features a brand-new tool, the powerful Shield Saw, which Id Software made a point to showcase across its "Stand and Fight" trailers and advertisements. Used for absorbing damage at the expense of speed, the saw also allows players to bash enemies from afar and close the gap on chasms too wide to jump across. While previous titles allowed players to quickly worm their way through bullet hell, The Dark Ages expects you to meet foes head on. "If you were an F-22 fighter jet in Doom Eternal, this time around we wanted you to feel like an Abrams tank," Hugo Martin, the game's creative director, has told journalists.

And Doom Slayer's beefy durability and unstoppable nature does make the gameplay a refreshing experience. The badassery is somehow ratcheted to new heights with the inclusion of a fully controllable mech, which has only a handful of attacks at its disposal, and actual dragons. Flight in a Doom game is entirely surprising and fluid, and the dragons feel relatively easy to maneuver through tight spots. They can also engage in combat more deliberately with the use of dodges and mounted cannons...

One of my favorite additions is the skullcrusher pulverizer. Equal parts heinous nutcracker and demonic woodchipper, the gun lodges skulls into a grinder and sends shards of bones flying at enemies. The animation is both goofy and satisfying.

Another special Times article notes that Doom's fans "resurrect the original game over and over again on progressively stranger pieces of hardware: a Mazda Miata, a NordicTrack treadmill, a French pharmacy sign." But what many hard-core tech hobbyists want to know is whether you can play it on a pregnancy test. The answer: positively yes. And for the first time, even New York Times readers can play Doom within The Times's site [after creating a free account]...

None of this happened by accident, of course. Ports were not incidental to Doom's development. They were a core consideration. "Doom was developed in a really unique way that lent a high degree of portability to its code base," said John Romero, who programmed the game with John Carmack. (In our interview, he then reminisced about operating systems for the next 14 minutes.) Id had developed Wolfenstein 3D, the Nazi-killing predecessor to Doom, on PCs. To build Doom, Carmack and Romero used NeXT, the hardware and software company founded by Steve Jobs after his ouster from Apple in 1985. NeXT computers were powerful, selling for about $25,000 apiece in today's dollars. And any game designed on that system would require porting to the more humdrum PCs encountered by consumers at computer labs or office jobs.

This turned out to be advantageous because Carmack had a special aptitude for ports. All of Id's founders met as colleagues at Softdisk, which had hired Carmack because of his ability to spin off multiple versions of a single game. The group decided to strike out on its own after Carmack created a near-perfect replica of the first level of Super Mario Bros. 3 — Nintendo's best-selling platformer — on a PC. It was a wonder of software engineering that compensated for limited processing power with clever workarounds. "This is the thing that everyone has," Romero said of PCs. "The fact that we could figure out how to make it become a game console was world changing...."

Romero founded a series of game studios after leaving Id in 1996 and is working on a new first-person shooter, the genre he and Carmack practically invented. He has no illusions about how it may stack up. "I absolutely accept that Doom is the best game I'll ever make that has that kind of a reach," he said. "At some point you make the best thing." Thirty years on, people are still making it.

And in related news, PC Gamer reports... As part of a new "FPS Fridays" series on Twitch, legendary shooter designer John Romero streamed New Blood's 2018 hit, Dusk, one of the first and most influential indie "boomer shooters" in the genre's recent revitalization. The short of it? Romero seems to have had a blast.
Windows

MCP Will Be Built Into Windows To Make an 'Agentic OS' - Bringing Security Concerns (devclass.com) 64

It's like "a USB-C port for AI applications..." according to the official documentation for MCP — "a standardized way to connect AI models to different data sources and tools."

And now Microsoft has "revealed plans to make MCP a native component of Windows," reports DevClass.com, "despite concerns over the security of the fast-expanding MCP ecosystem." In the context of Windows, it is easy to see the value of a standardised means of automating both built-in and third-party applications. A single prompt might, for example, fire off a workflow which queries data, uses it to create an Excel spreadsheet complete with a suitable chart, and then emails it to selected colleagues. Microsoft is preparing the ground for this by previewing new Windows features.

— First, there will be a local MCP registry which enables discovery of installed MCP servers.

— Second, built-in MCP servers will expose system functions including the file system, windowing, and the Windows Subsystem for Linux.

— Third, a new type of API called App Actions enables third-party applications to expose actions appropriate to each application, which will also be available as MCP servers so that these actions can be performed by AI agents. According to Microsoft, "developers will be able to consume actions developed by other relevant apps," enabling app-to-app automation as well as use by AI agents.

MCP servers are a powerful concept but vulnerable to misuse. Microsoft corporate VP David Weston noted seven vectors of attack, including cross-prompt injection where malicious content overrides agent instructions, authentication gaps because "MCP's current standards for authentication are immature and inconsistently adopted," credential leakage, tool poisoning from "unvetted MCP servers," lack of containment, limited security review in MCP servers, supply chain risks from rogue MCP servers, and command injection from improperly validated inputs. According to Weston, "security is our top priority as we expand MCP capabilities."

Security controls planned by Microsoft (according to the article):
  • A proxy to mediate all MCP client-server interactions. This will enable centralized enforcement of policies and consent, as well as auditing and a hook for security software to monitor actions.
  • A baseline security level for MCP servers to be allowed into the Windows MCP registry. This will include code-signing, security testing of exposed interfaces, and declaration of what privileges are required.
  • Runtime isolation through what Weston called "isolation and granular permissions."

MCP was introduced by Anthropic just 6 months ago, the article notes, but Microsoft has now joined the official MCP steering committee, "and is collaborating with Anthropic and others on an updated authorization specification as well as a future public registry service for MCP servers."


Privacy

Ask Slashdot: Do We Need Opt-Out-By-Default Privacy Laws? 92

"In large, companies failed to self-regulate," writes long-time Slashdot reader BrendaEM: They have not been respected the individual's right to privacy. In software and web interfaces, companies have buried their privacy setting so deep that they cannot be found in a reasonable amount of time, or an unreasonable amount of steps are needed to attempt to retain data. These companies have taken away the individual's right to privacy --by default.

Are laws needed that protect a person's privacy by default--unless specific steps are taken by that user/purchaser to relinquish it? Should the wording of the explanation be so written that the contract is brief, explaining the forfeiture of the privacy, and where that data might be going? Should a company selling a product be required to state before purchase which rights need to be dismissed for its use? Should a legal owner who purchased a product expect it to stop functioning--only because a newer user contract is not agreed to?

Share your own thoughts and experiences in the comments. What's your ideal privacy policy?

And do we need opt-out-by-defaut privacy laws?
Java

Java Turns 30 (theregister.com) 100

Richard Speed writes via The Register: It was 30 years ago when the first public release of the Java programming language introduced the world to Write Once, Run Anywhere -- and showed devs something cuddlier than C and C++. Originally called "Oak," Java was designed in the early 1990s by James Gosling at Sun Microsystems. Initially aimed at digital devices, its focus soon shifted to another platform that was pretty new at the time -- the World Wide Web.

The language, which has some similarities to C and C++, usually compiles to a bytecode that can, in theory, run on any Java Virtual Machine (JVM). The intention was to allow programmers to Write Once Run Anywhere (WORA) although subtle differences in JVM implementations meant that dream didn't always play out in reality. This reporter once worked with a witty colleague who described the system as Write Once Test Everywhere, as yet another unexpected wrinkle in a JVM caused their application to behave unpredictably. However, the language soon became wildly popular, rapidly becoming the backbone of many enterprises. [...]

However, the platform's ubiquity has meant that alternatives exist to Oracle Java, and the language's popularity is undiminished by so-called "predatory licensing tactics." Over 30 years, Java has moved from an upstart new language to something enterprises have come to depend on. Yes, it may not have the shiny baubles demanded by the AI applications of today, but it continues to be the foundation for much of today's modern software development. A thriving ecosystem and a vast community of enthusiasts mean that Java remains more than relevant as it heads into its fourth decade.

AI

America's Leading Alien Hunters Depend on AI to Speed Their Search (bloomberg.com) 14

Harvard University's Galileo Project is using AI to automate the search for unidentified anomalous phenomena, marking a significant shift in how academics approach what was once considered fringe research. The project operates a Massachusetts observatory equipped with infrared cameras, acoustic sensors, and radio-frequency analyzers that continuously scan the sky for unusual objects.

Researchers Laura Domine and Richard Cloete are training machine learning algorithms to recognize all normal aerial phenomena -- planes, birds, drones, weather balloons -- so the system can flag genuine anomalies for human analysis. The team uses computer vision software called YOLO (You Only Look Once) and has generated hundreds of thousands of synthetic images to train their models, though the software currently identifies only 36% of aircraft captured by infrared cameras.

The Pentagon is pursuing parallel efforts through its All-domain Anomaly Resolution Office, which has examined over 1,800 UAP reports and identified 50 to 60 cases as "true anomalies" that government scientists cannot explain. AARO has developed its own sensor suite called Gremlin, using similar technology to Harvard's observatory. Both programs represent the growing legitimization of UAP research following 2017 Defense Department disclosures about military encounters with unexplained aerial phenomena.
Data Storage

Internet Archive Now Livestreams History As It's Being Preserved (9to5mac.com) 2

The Internet Archive has begun livestreaming its microfiche digitization center on YouTube, showcasing the real-time preservation of fragile film cards into searchable public documents. The work is part of Democracy's Library, a global initiative to digitize and share millions of government records. 9to5Mac reports: The livestream was brought to life by Sophia Tung, who previously gained attention for her viral robotaxi depot stream. Her new video explains how and why this new livestream project came together [...].

The livestream features five scanning stations at work, with one shown in close-up as operators digitize microfiche cards in real time. Each card holds up to 100 pages of public records. High-resolution cameras capture the images, software stitches and crops the pages, and the results are made text-searchable and freely accessible through Democracy's Library. Live scanning takes place Monday through Friday, 7:30 a.m. to 3:30 p.m. PT, excluding U.S. holidays, with a second shift expected to begin soon.

Graphics

Nvidia's RTX 5060 Review Debacle Should Be a Wake-Up Call (theverge.com) 67

Nvidia is facing backlash for allegedly manipulating the review process of its GeForce RTX 5060 GPU by withholding drivers, selectively granting early access to favorable reviewers, and pressuring media to present the card in a positive light. As The Verge's Sean Hollister writes, the debacle "should be a wake-up call for gamers and reviewers." Here's an excerpt from the report: Nvidia has gone too far. This week, the company reportedly attempted to delay, derail, and manipulate reviews of its $299 GeForce RTX 5060 graphics card, which would normally be its bestselling GPU of the generation. Nvidia has repeatedly and publicly said the budget 60-series cards are its most popular, and this year it reportedly tried to ensure it by withholding access and pressuring reviewers to paint them in the best light possible.

Nvidia might have wanted to prevent a repeat of 2022, when it launched this card's predecessor. Those reviews were harsh. The 4060 was called a "slap in the face to gamers" and a "wet fart of a GPU." I had guessed the 5060 was headed for the same fate after seeing how reviewers handled the 5080, which similarly showcased how little Nvidia's hardware has improved year over year and relies on software to make up the gaps. But Nvidia had other plans. Here are the tactics that Nvidia reportedly just used to throw us off the 5060's true scent, as individually described by GamersNexus, VideoCardz, Hardware Unboxed, GameStar.de, Digital Foundry, and more:

- Nvidia decided to launch its RTX 5060 on May 19th, when most reviewers would be at Computex in Taipei, Taiwan, rather than at their test beds at home.
- Even if reviewers already had a GPU in hand before then, Nvidia cut off most reviewers' ability to test the RTX 5060 before May 19th by refusing to provide drivers until the card went on sale. (Gaming GPUs don't really work without them.)
- And yet Nvidia allowed specific, cherry-picked reviewers to have early drivers anyhow if they agreed to a borderline unethical deal: they could only test five specific games, at 1080p resolution, with fixed graphics settings, against two weaker GPUs (the 3060 and 2060 Super) where the new card would be sure to win.
- In some cases, Nvidia threatened to withhold future access unless reviewers published apples-to-oranges benchmark charts showing how the RTX 5060's "fake frames" MFG tech can produce more frames than earlier GPUs without it.

Some reviewers apparently took Nvidia up on that proposition, leading to day-one "previews" where the charts looked positively stacked in the 5060's favor [...]. But the reality, according to reviews that have since hit the web, is that the RTX 5060 often fails to beat a four-year-old RTX 3060 Ti, frequently fails to beat a four-year-old 3070, and can sometimes get upstaged by Intel's cheaper $250 B580. And yet, the 5060's lackluster improvements are overshadowed by a juicier story: inexplicably, Nvidia decided to threaten GamersNexus' future access over its GPU coverage. Yes, the same GamersNexus that's developed a staunch reputation for defending consumers from predatory behavior, and just last month published a report on "GPU shrinkflation" that accused Nvidia of misleading marketing. Bad move! [...]

Nvidia is within its rights to withhold access, of course. Nvidia doesn't have to send out graphics cards or grant interviews. It'll only do it if it's good for business. But the unspoken covenant of product reviews is that the press, as a whole, gets a chance to warn the public if a movie, video game, or GPU is not worth their money. It works both ways: the media also gets the chance to warn that a product is so good you might want to line up in advance. That unspoken rule is what Nvidia is trampling here.

Privacy

Destructive Malware Available In NPM Repo Went Unnoticed For 2 Years (arstechnica.com) 6

An anonymous reader quotes a report from Ars Technica: Researchers have found malicious software that received more than 6,000 downloads from the NPM repository over a two-year span, in yet another discovery showing the hidden threats users of such open source archives face. Eight packages using names that closely mimicked those of widely used legitimate packages contained destructive payloads designed to corrupt or delete important data and crash systems, Kush Pandya, a researcher at security firm Socket, reported Thursday. The packages have been available for download for more than two years and accrued roughly 6,200 downloads over that time.

"What makes this campaign particularly concerning is the diversity of attack vectors -- from subtle data corruption to aggressive system shutdowns and file deletion," Pandya wrote. "The packages were designed to target different parts of the JavaScript ecosystem with varied tactics." [...] Some of the payloads were limited to detonate only on specific dates in 2023, but in some cases a phase that was scheduled to begin in July of that year was given no termination date. Pandya said that means the threat remains persistent, although in an email he also wrote: "Since all activation dates have passed (June 2023-August 2024), any developer following normal package usage today would immediately trigger destructive payloads including system shutdowns, file deletion, and JavaScript prototype corruption."
The list of malicious packages included js-bomb, js-hood, vite-plugin-bomb-extend, vite-plugin-bomb, vite-plugin-react-extend, vite-plugin-vue-extend, vue-plugin-bomb, and quill-image-downloader.
Businesses

VMware Price Hikes? Between 800 and 1,500% Since Acquisition By Broadcom, Claim Euro Customers (theregister.com) 44

Broadcom has upped VMware licensing costs by between eight to 15 times since it took over the organization, and a lack of alternatives in the tech industry means trade and end customers have no choice but to play ball. From a report: This is the according to the European Cloud Competition Observatory (ECCO), an independent body formed by customer organizations, and CISPE -- a trade association of 37 cloud providers in the region -- to monitor the behavior of software vendors accused of abusing their monopoly position. The report also calls for regulatory intervention. The current subscription model "creates a material risk for the company and their shareholders should Regulators investigate and challenge the legality of such model," the report adds.
Books

Usage of Semicolons In English Books Down Almost Half In Two Decades (theguardian.com) 122

An anonymous reader quotes a report from The Guardian: "Do not use semicolons," wrote Kurt Vonnegut, who averaged fewer than 30 a novel (about one every 10 pages). "All they do is show you've been to college." A study suggests UK authors are taking Vonnegut's advice to heart; the semicolon seems to be in terminal decline, with its usage in English books plummeting by almost half in two decades -- from one appearing in every 205 words in 2000 to one use in every 390 words today. Further research by Lisa McLendon, author of The Perfect English Grammar Workbook, found 67% of British students never or rarely use the semicolon. Just 11% of respondents described themselves as frequent users.

Linguistic experts at the language learning software Babbel, which commissioned the original research, were so struck by their findings that they asked McLendon to give the 500,000-strong London Student Network a 10-question multiple-choice quiz on the semicolon. She found more than half of respondents did not know or understand how to use it. As defined by the Oxford Dictionary of English, the semicolon is "a punctuation mark indicating a pause, typically between two main clauses, that is more pronounced than that indicated by a comma." It is commonly used to link together two independent but related clauses, and is particularly useful for juxtaposition or replacing confusing extra commas in lists where commas already exist -- or where a comma would create a splice.
The Guardian has a semicolon quiz at the end of the article where you can test your semicolon knowledge.
Microsoft

The Information: Microsoft Engineers Forced To Dig Their Own AI Graves 71

Longtime Slashdot reader theodp writes: In what reads a bit like a Sopranos plot, The Information suggests some of those in the recent batch of terminated Microsoft engineers may have in effect been forced to dig their own AI graves.

The (paywalled) story begins: "Jeff Hulse, a Microsoft vice president who oversees roughly 400 software engineers, told the team in recent months to use the company's artificial intelligence chatbot, powered by OpenAI, to generate half the computer code they write, according to a person who heard the remarks. That would represent an increase from the 20% to 30% of code AI currently produces at the company, and shows how rapidly Microsoft is moving to incorporate such technology. Then on Tuesday, Microsoft laid off more than a dozen engineers on Hulse 's team as part of a broader layoff of 6,000 people across the company that appeared to hit engineers harder than other types of roles, this person said."

The report comes as tech company CEOs have taken to boasting in earnings calls, tech conferences, and public statements that their AI is responsible for an ever-increasing share of the code written at their organizations. Microsoft's recent job cuts hit coders the hardest. So how much credence should one place on CEOs' claims of AI programming productivity gains -- which researchers have struggled to measure for 50+ years -- if engineers are forced to increase their use of AI, boosting the numbers their far-removed-from-programming CEOs are presenting to Wall Street?
Security

Most AI Chatbots Easily Tricked Into Giving Dangerous Responses, Study Finds (theguardian.com) 46

An anonymous reader quotes a report from The Guardian: Hacked AI-powered chatbots threaten to make dangerous knowledge readily available by churning out illicit information the programs absorb during training, researchers say. [...] In a report on the threat, the researchers conclude that it is easy to trick most AI-driven chatbots into generating harmful and illegal information, showing that the risk is "immediate, tangible and deeply concerning." "What was once restricted to state actors or organised crime groups may soon be in the hands of anyone with a laptop or even a mobile phone," the authors warn.

The research, led by Prof Lior Rokach and Dr Michael Fire at Ben Gurion University of the Negev in Israel, identified a growing threat from "dark LLMs", AI models that are either deliberately designed without safety controls or modified through jailbreaks. Some are openly advertised online as having "no ethical guardrails" and being willing to assist with illegal activities such as cybercrime and fraud. [...] To demonstrate the problem, the researchers developed a universal jailbreak that compromised multiple leading chatbots, enabling them to answer questions that should normally be refused. Once compromised, the LLMs consistently generated responses to almost any query, the report states.

"It was shocking to see what this system of knowledge consists of," Fire said. Examples included how to hack computer networks or make drugs, and step-by-step instructions for other criminal activities. "What sets this threat apart from previous technological risks is its unprecedented combination of accessibility, scalability and adaptability," Rokach added. The researchers contacted leading providers of LLMs to alert them to the universal jailbreak but said the response was "underwhelming." Several companies failed to respond, while others said jailbreak attacks fell outside the scope of bounty programs, which reward ethical hackers for flagging software vulnerabilities.

Android

Android XR Glasses Get I/O 2025 Demo (9to5google.com) 20

At I/O 2025, Google revealed new details about Android XR glasses, which will integrate with your phone to deliver context-aware support via Gemini AI. 9to5Google reports: Following the December announcement, Google today shared how all Android XR glasses will have a camera, microphones, and speakers, while an "in-lens display" that "privately provides helpful information right when you need it" is described as being "optional." The glasses will "work in tandem with your phone, giving you access to your apps without ever having to reach in your pocket." Gemini can "see and hear what you do" to "understand your context, remember what's important to you and provide information right when you need it." We see it accessing Google Calendar, Maps, Messages, Photos, Tasks, and Translate.

Google is "working with brands and partners to bring this technology to life," specifically Warby Parker and Gentle Monster. "Stylish glasses" are the goal for Android XR since they "can only truly be helpful if you want to wear them all day." Meanwhile, Google is officially "advancing" the Samsung partnership from headsets to Android XR glasses. They are making a software and reference hardware platform "that will enable the ecosystem to make great glasses." Notably, "developers will be able to start building for this platform later this year." On the privacy front, Google is now "gathering feedback on our prototypes with trusted testers."
Further reading: Google's Brin: 'I Made a Lot of Mistakes With Google Glass'
Windows

Windows 11 To Get Apple-Style App Continuity (windowscentral.com) 27

Microsoft is introducing a new "Cross Device Resume" feature for Windows 11, enabling app developers to let users seamlessly continue activity between devices in a manner closely mirroring Apple's Handoff for Macs and iPhones. Unveiled at Build 2025 during a session titled "Create Seamless Cross-Device Experiences with Windows for your app," the feature was demonstrated -- before the session was quietly edited to remove this segment -- by showing Spotify playing a song on an Android phone, then surfacing the Spotify app in the Windows taskbar with a phone icon; clicking this launches Spotify on the PC at precisely the same point in the app as on the phone, preserving playback position for uninterrupted use.
Space

Starfish Space Announces Plans For First Commercial Satellite Docking (nasaspaceflight.com) 10

Starfish Space plans to perform the first commercial satellite docking in orbit with its Otter Pup 2 mission, aiming to connect to an unprepared D-Orbit ION spacecraft using an electrostatic capture mechanism and autonomous navigation software. NASASpaceFlight.com reports: This follows the company's first attempt, which saw the Otter Pup 1 mission unable to dock with its target due to a thruster failure. The Otter Pup 2 spacecraft will be deployed from a quarter plate on the upper stage adapter of the SpaceX Falcon 9 rocket, placing it into a sun synchronous orbit altitude of 510 km inclined 97.4 degrees. The target will be a D-Orbit ION spacecraft which will simulate a client payload, which is not equipped with a traditional docking adapter or capture plate as you might see aboard a space station or other rendezvous target. Instead, Starfish Space's Nautilus capture mechanism will feature a special end effector connected to the end of the capture mechanism. This end effector will enable Otter Pup 2 to dock with the ION through electrostatic adhesion.

"An electromagnet will be integrated into the end effector and will be used as a backup option to the electrostatic end effector, to dock with the ION through magnetic attraction," the company notes. The goal is to eventually commission its Otter satellite servicing vehicle to allow for servicing of previously launched satellites. The company's first Otter missions include customers such as NASA, the U.S. Space Force, and Intelsat, with the goal of flying those missions as soon as 2026. [...] Following the thruster issues on the first mission, this flight will feature two ThrustMe thrusters, which use an electric propulsion system based on gridded ion thruster technology.

Transportation

Japan's Honda To Scale Back On EVs, Focus On Hybrids (reuters.com) 244

An anonymous reader quotes a report from Reuters: Honda said on Tuesday that it was scaling back its investment in electric vehicles given slowing demand and would be focusing on hybrids, now far more in favor, with a slew of revamped models. Japan's second-biggest automaker after Toyota also dropped a target for EV sales to account for 30% of its sales by the 2030 financial year. "It's really hard to read the market, but at the moment we see EVs accounting for about a fifth by then," CEO Toshihiro Mibe told a press conference.

Honda has slashed its planned investment in electrification and software by that year by 30% to 7 trillion yen ($48.4 billion). It's one of a number of global car brands dialing back EV investment due to the shift in demand in favor of hybrids and as governments around the world ease timelines to meet emission rules and EV sales targets. Honda plans to launch 13 next-generation hybrid models globally in the four years from 2027. At the moment it sells more than a dozen hybrid models worldwide, though just three in the U.S. -- the Civic, which comes in hatchback and sedan versions, the Accord and the CR-V. It will also develop a hybrid system for large-size models that it plans to launch in the second half of the decade.

The automaker is aiming to sell 2.2 million to 2.3 million hybrid vehicles by 2030, a huge jump from 868,000 sold last year. That also compares with a total of 3.8 million vehicles sold overall last year. Earlier this month, Honda announced it had put on hold for about two years a $10.7 billion plan to build an EV production base in Ontario, Canada, due to slowing demand for electric cars. Honda said, however, that it still plans to have battery-powered and fuel-cell vehicles make up all of its new car sales by 2040.

Businesses

Delta Can Sue CrowdStrike Over Global Outage That Caused 7,000 Canceled Flights (reuters.com) 63

Delta can pursue much of its lawsuit seeking to hold cybersecurity company CrowdStrike liable for a massive computer outage last July that caused the carrier to cancel 7,000 flights, a Georgia state judge ruled. From a report: In a decision on Friday, Judge Kelly Lee Ellerbe of the Fulton County Superior Court said Delta can try to prove CrowdStrike was grossly negligent in pushing a defective update of its Falcon software to customers, crashing more than 8 million Microsoft Windows-based computers worldwide.
AI

Apple's Next-Gen Version of Siri Is 'On Par' With ChatGPT 41

According to Bloomberg's Mark Gurman (paywalled), Apple has big plans to turn Siri into a true ChatGPT competitor. "A next-generation, chatbot version of Siri has reportedly made significant progress during testing over the past six months; some executives allegedly now see it as 'on par' with recent versions of ChatGPT," reports MacRumors. "Apple is also apparently discussing giving Siri the ability to access the internet to gather and synthesize data from multiple sources, just like ChatGPT." From the report: The report added that Apple now has artificial intelligence offices in Zurich, where employees are working on an all-new software architecture for Siri. This "monolithic model" is entirely built on an LLM engine that will eventually replace Siri's current "hybrid" architecture that has been incoherently layered up with different functionality over many years. The new model will make Siri more conversational and better at synthesizing information.

Google's Gemini is expected to be added to iOS 19 as an alternative to ChatGPT in Siri, but Apple is also apparently in talks with Perplexity to add their AI service as another option in the future, for both Siri and Safari search.

Slashdot Top Deals