United States

New CIA Director Touts 'Low Confidence' Assessment About Covid Lab Leak Theory (cnn.com) 196

Slashdot reader DevNull127 writes: "Every US intelligence agency still unanimously maintains that Covid-19 was not developed as a biological weapon," CNN reported today.

But what about the possibility of an accidental leak (rather than Covid-19 originating in wild animal meat from the Wuhan Market)? "The agency has for years said it did not have enough information to determine which origin theory was more likely."

CNN notes there's suddenly been a new announcement "just days" after the CIA's new director took the reins — former lawyer turned Republican House Representative John Ratcliffe. While the market-origin theory remains a possibility according to the CIA, CNN notes that Ratcliffe himself "has long favored the theory that the pandemic originated from research being done in China and vowed in an interview published in Breitbart on Thursday that he would make the issue a Day 1 priority."

"We have low confidence in this judgement," the CIA says in the complete text of its announcement, "and will continue to evaluate any available credible new intelligence reporting or open-source information that could change CIA's assessment."

After speaking to a U.S. official, CNN added these details about the assessment: It was not made based on new intelligence gathered by the US government — officials have long said such intelligence is unlikely to surface so many years later — and instead was reached after a review of existing information.

"CIA continues to assess that both research-related and natural origin scenarios of the COVID-19 pandemic remain plausible," a CIA spokesperson said in a statement Saturday.

CNN adds that "Many scientists believe the virus occurred naturally in animals and spread to humans in an outbreak at a market in Wuhan, China...."
Social Networks

Oracle and US Investors (Including Microsoft) Discuss Taking Control of TikTok in the US (npr.org) 53

A plan to keep TikTok available in the U.S. "involves tapping software company Oracle and a group of outside investors," reports NPR, "to effectively take control of the app's global operations, according to two people with direct knowledge of the talks..."

"[P]otential investors who are engaged in the talks include Microsoft." Under the deal now being negotiated by the White House, TikTok's China-based owner ByteDance would retain a minority stake in the company, but the app's algorithm, data collection and software updates will be overseen by Oracle, which already provides the foundation of TikTok's web infrastructure... "The goal is for Oracle to effectively monitor and provide oversight with what is going on with TikTok," said the person directly involved in the talks, who was not authorized to speak publicly about the deliberations. "ByteDance wouldn't completely go away, but it would minimize Chinese ownership...." Officials from Oracle and the White House held a meeting on Friday about a potential deal, and another meeting has been scheduled for next week, according to the source involved in the discussions, who said Oracle is interested in a TikTok stake "in the tens of billions," but the rest of the deal is in flux...

Under a law passed by Congress and upheld by the Supreme Court, TikTok must execute what is known as "qualified divestiture" from ByteDance in order to stay in business in the U.S... A congressional staffer involved in talks about TikTok's future, who was not authorized to speak publicly, said binding legal agreements from the White House ensuring ByteDance cannot covertly manipulate the app will prove critical in winning lawmakers' approval. "A key part is showing there is no operational relationship with ByteDance, that they do not have control," the Congressional staffer said. "There needs to be no backdoors where China can potentially gain access...."

Chinese regulators, who have for years opposed the selling of TikTok, recently signaled that they would not stand in the way of a TikTok ownership change, saying acquisitions "should be independently decided by the enterprises and based on market principles." The statement, at first, does not seem to say much, but negotiators in the White House believe it indicates that Beijing is not planning to block a deal that gives American investors a majority-stake position in the company.

"Meanwhile, Apple and Google still have not returned TikTok to app stores..."
United States

America Lags on Renewable Energy. Blame Regulations and Grid Connection Issues (msn.com) 127

"For years, renewable energy proponents have hoped to build a U.S. electric grid powered by wind, solar, geothermal and — to a lesser extent — nuclear power..." writes the Washington Post. In America's power markets "the economics of clean energy are strong," with renewable energy cheaper than fossil fuel plants in many jurisdictions.

But the Post spoke to the "electricity modeling" director at nonpartisan clean energy think tank Energy Innovation, who offered this assessment. "The technology is ready, and the financial services are ready — but the question nobody really put enough thought into was, could the government keep up? And at the moment, the answer is no." [R]enewable developers say that the new technologies are stymied by complicated local and federal regulations, a long wait to connect to the electricity grid, and community opposition... "The U.S. offshore wind business is at a very nascent stage versus Europe or China," Rob Barnett, a senior analyst at Bloomberg Intelligence, said in an email. "With the new permitting pause, it's doubtful much progress for this emerging industry will be made...." After the Inflation Reduction Act passed, Rhodium Group — an independent clean energy research firm — estimated that between 2023 and 2025, on average, the country would add between 36 and 46 gigawatts of clean electricity to the grid every year. Late last year, however, the group found that the country only installed around 27 gigawatts in 2023. The U.S.'s renewable growth is now expected to fall on the low end of that range — or miss it entirely.

"It actually is really hard to build a lot of this stuff fast," said Trevor Houser, partner in climate and energy at Rhodium Group. As a result, Rhodium found, the country only cut carbon emissions by 0.2 percent in 2024... A significant amount of this lag has come from wind power, where problems with supply chains and getting permits and approval to build has put a damper on development. But solar construction is also on the low end of what experts were expecting...

Developers point to lags in the interconnection queue — a system that gives new solar, wind or fossil fuel projects permission to connect to the larger electricity grid. According to a report from Lawrence Berkeley National Laboratory, it can now take nearly 3 years for a project to get through the queue. The grid operator that covers the Mid-Atlantic and parts of the Midwest, PJM, had over 3,300 projects in its queue at the end of 2023. The vast majority of these applications are for renewables — more than the entire number of active wind farms in the nation... There are possible solutions. Some developers hope to reuse old fossil fuel sites, like coal plants, that are already connected to the grid — bypassing the long queue entirely. The Federal Energy Regulatory Commission has instated new rules to make it easier to build transmission lines.

Part of the problem is that wind and solar facilities "sometimes need to be built hundreds or even thousands of miles away" — requiring long transmission lines. Sandhya Ganapathy, CEO of EDP Renewables North America, tells the Post that in America, "The grid that we have was never designed to handle this kind of load." And yet last year just 255 miles of new transmission line were built in the U.S., according to the American Clean Power Association. And Ganapathy also complains that approval for a new renewable energy project takes "anywhere between six to eight years" — which makes developers hesitant to build. "Why are we taking a big risk of a massive investment if I will not be able to sell the electrons?"

The end result? The Washington Post writes that "Experts once hoped that by the end of the decade the United States could generate up to 80 percent of its power with clean power... Now, some wonder if the country will be able to reach even 60 percent."
Transportation

US Reviewing Automatic Emergency Braking Rule (reuters.com) 178

An anonymous reader quotes a report from Reuters: A U.S. auto safety agency said on Friday it is reconsidering a landmark rule from the administration of former President Joe Biden requiring nearly all new cars and trucks by 2029 to have advanced automatic emergency braking systems. The National Highway Traffic Safety Administration said it would delay the effective date to March 20 to give the new Trump administration time to further review the regulation.

The Alliance for Automotive Innovation, representing General Motors, Toyota Motor, Volkswagen and other automakers, last week filed suit to block the rule, saying the regulation is "practically impossible with available technology." The group asked the U.S. Court of Appeals for the District of Columbia to overturn the rule, saying the requirement that cars and trucks must be able to stop and avoid striking vehicles in front of them at up to 62 miles per hour (100 kph) is unrealistic. It unsuccessfully asked NHTSA last year to reconsider the rule.
Come 2029, all cars sold in the U.S. "must be able to stop and avoid contact with a vehicle in front of them at speeds up to 62 mph," reports Car and Driver."

"Additionally, the system must be able to detect pedestrians in both daylight and darkness. As a final parameter, the federal standard will require the system to apply the brakes automatically up to 90 mph when a collision is imminent, and up to 45 mph when a pedestrian is detected."

According to the NHTSA, the rule will save at least 360 lives annually and prevent more than 24,000 injuries.
Privacy

UnitedHealth Data Breach Hits 190 Million Americans in Worst Healthcare Hack (techcrunch.com) 27

Nearly 190 million Americans were affected by February's cyberattack on UnitedHealth's Change Healthcare unit, almost double initial estimates, the company disclosed Friday. The breach, the largest in U.S. medical history, exposed sensitive data including Social Security numbers, medical records, and financial information.

UnitedHealth said it has not detected misuse of the stolen data or found medical databases among compromised files. Change Healthcare, a major U.S. healthcare claims processor, paid multiple ransoms after Russian-speaking hackers known as ALPHV breached its systems using stolen credentials lacking multi-factor authentication, according to CEO Andrew Witty's testimony to Congress.
Security

Backdoor Infecting VPNs Used 'Magic Packets' For Stealth and Security (arstechnica.com) 17

An anonymous reader quotes a report from Ars Technica: When threat actors use backdoor malware to gain access to a network, they want to make sure all their hard work can't be leveraged by competing groups or detected by defenders. One countermeasure is to equip the backdoor with a passive agent that remains dormant until it receives what's known in the business as a "magic packet." On Thursday, researchers revealed that a never-before-seen backdoor that quietly took hold of dozens of enterprise VPNs running Juniper Network's Junos OS has been doing just that. J-Magic, the tracking name for the backdoor, goes one step further to prevent unauthorized access. After receiving a magic packet hidden in the normal flow of TCP traffic, it relays a challenge to the device that sent it. The challenge comes in the form of a string of text that's encrypted using the public portion of an RSA key. The initiating party must then respond with the corresponding plaintext, proving it has access to the secret key.

The lightweight backdoor is also notable because it resided only in memory, a trait that makes detection harder for defenders. The combination prompted researchers at Lumin Technology's Black Lotus Lab to sit up and take notice. "While this is not the first discovery of magic packet malware, there have only been a handful of campaigns in recent years," the researchers wrote. "The combination of targeting Junos OS routers that serve as a VPN gateway and deploying a passive listening in-memory only agent, makes this an interesting confluence of tradecraft worthy of further observation." The researchers found J-Magic on VirusTotal and determined that it had run inside the networks of 36 organizations. They still don't know how the backdoor got installed.

Privacy

Federal Court Rules Backdoor Searches of 702 Data Unconstitutional (eff.org) 42

A federal district court has ruled that backdoor searches of Americans' private communications collected under Section 702 of FISA are unconstitutional without a warrant. "The landmark ruling comes in a criminal case, United States v. Hasbajrami, after more than a decade of litigation, and over four years since the Second Circuit Court of Appeals found that backdoor searches constitute 'separate Fourth Amendment events' and directed the district court to determine a warrant was required," reports the Electronic Frontier Foundation (EFF). "Now, that has been officially decreed." Longtime Slashdot reader schwit1 shares the report: Hasbajrami involves a U.S. resident who was arrested at New York JFK airport in 2011 on his way to Pakistan and charged with providing material support to terrorists. Only after his original conviction did the government explain that its case was premised in part on emails between Mr. Hasbajrami and an unnamed foreigner associated with terrorist groups, emails collected warrantless using Section 702 programs, placed in a database, then searched, again without a warrant, using terms related to Mr. Hasbajrami himself.

The district court found that regardless of whether the government can lawfully warrantlessly collect communications between foreigners and Americans using Section 702, it cannot ordinarily rely on a "foreign intelligence exception" to the Fourth Amendment's warrant clause when searching these communications, as is the FBI's routine practice. And, even if such an exception did apply, the court found that the intrusion on privacy caused by reading our most sensitive communications rendered these searches "unreasonable" under the meaning of the Fourth Amendment. In 2021 alone, the FBI conducted 3.4 million warrantless searches of US person's 702 data.

The Courts

Microsoft's LinkedIn Sued For Disclosing Customer Information To Train AI Models 14

LinkedIn has been sued by Premium customers alleging the platform disclosed private messages to third parties without consent to train generative AI models. The lawsuit seeks damages for breach of contract and privacy violations, accusing LinkedIn of attempting to minimize scrutiny over its actions. Reuters reports: According to a proposed class action filed on Tuesday night on behalf of millions of LinkedIn Premium customers, LinkedIn quietly introduced a privacy setting last August that let users enable or disable the sharing of their personal data. Customers said LinkedIn then discreetly updated its privacy policy on Sept. 18 to say data could be used to train AI models, and in a "frequently asked questions" hyperlink said opting out "does not affect training that has already taken place."

This attempt to "cover its tracks" suggests LinkedIn was fully aware it violated customers' privacy and its promise to use personal data only to support and improve its platform, in order to minimize public scrutiny and legal fallout, the complaint said. The lawsuit was filed in the San Jose, California, federal court on behalf of LinkedIn Premium customers who sent or received InMail messages, and whose private information was disclosed to third parties for AI training before Sept. 18. It seeks unspecified damages for breach of contract and violations of California's unfair competition law, and $1,000 per person for violations of the federal Stored Communications Act.
LinkedIn said in a statement: "These are false claims with no merit."
Crime

Silk Road Creator Ross Ulbricht Pardoned (bbc.com) 339

Slashdot readers jkister and databasecowgirl share the news of President Donald Trump issuing a pardon to Silk Road creator Ross Ulbricht. An anonymous reader shares a report from the BBC: US President Donald Trump says he has signed a full and unconditional pardon for Ross Ulbricht, who operated Silk Road, the dark web marketplace where illegal drugs were sold. Ulbricht was convicted in 2015 in New York in a narcotics and money laundering conspiracy and sentenced to life in prison. Trump posted on his Truth Social platform that he had called Ulbricht's mother to inform her that he had granted a pardon to her son. Silk Road, which was shut down in 2013 after police arrested Ulbricht, sold illegal drugs using Bitcoin, as well as hacking equipment and stolen passports.

"The scum that worked to convict him were some of the same lunatics who were involved in the modern day weaponization of government against me," Trump said in his post online on Tuesday evening. "He was given two life sentences, plus 40 years. Ridiculous!" Ulbricht was found guilty of charges including conspiracy to commit drug trafficking, money laundering and computer hacking. During his trial, prosecutors said Ulbricht's website, hosted on the hidden "dark web", sold more than $200 million worth of drugs anonymously.

Government

Trump To Announce Up To $500 Billion In AI Infrastructure Investment 129

According to CBS News, President Trump plans to announce billions of dollars in private sector investment to build AI infrastructure in the United States. From the report: OpenAI, Softbank and Oracle are planning a joint venture called Stargate, according to multiple people familiar with the deal. SoftBank CEO Masayoshi Son is expected at the White House Tuesday afternoon, along with Sam Altman of OpenAI and Larry Ellison of Oracle. Executives from the companies are expected to say they plan to commit $100 billion initially and pour up to $500 billion into Stargate over the next four years.

Other details of the new partnership were not immediately available. Stargate will start with a data center project in Texas, sources said, and eventually expand to other states. Other investors are expected to join the venture, but it was not immediately clear which ones.
Further reading: Scale AI CEO To Trump: 'America Must Win the AI War'
AI

Trump Revokes Biden Executive Order On Addressing AI Risks (msn.com) 123

An anonymous reader quotes a report from Reuters: U.S. President Donald Trump on Monday revoked a 2023 executive order signed by Joe Biden that sought to reduce the risks that artificial intelligence poses to consumers, workers and national security. Biden's order required developers of AI systems that pose risks to U.S. national security, the economy, public health or safety to share the results of safety tests with the U.S. government, in line with the Defense Production Act, before they were released to the public. Four days before leaving office, Biden issued a comprehensive cybersecurity executive order that also targeted AI usage. The directive aimed to leverage AI's security benefits, implement digital identities for citizens, and address vulnerabilities that have allowed Chinese and Russian intrusions into U.S. government systems, among other things. It's unclear at this time if it, too, will be revoked.
Government

Executive Order Delays TikTok Ban For 75 Days 173

President Donald Trump signed an executive order today delaying the TikTok ban for 75 days. The Verge reports: The order, issued on Trump's first day of office, is meant to effectively extend the deadline established by The Protecting Americans from Foreign Adversary Controlled Applications Act for ByteDance to sell its stake by undercutting penalties on American companies like Apple and Google working with TikTok. It directs the Attorney General "not to take any action to enforce the Act for a period of 75 days from today to allow my Administration an opportunity to determine the appropriate course forward in an orderly way." The AG is supposed to "issue a letter to each provider stating that there has been no violation of the statute and that there is no liability for any conduct that occurred."

The order furthermore instructs the Department of Justice to "take no action to enforce the Act or impose any penalties against any entity for any noncompliance with the Act" and says they should be barred from doing so "for any conduct that occurred during the above-specified period or any period prior to the issuance of this order, including the period of time from January 19, 2025, to the signing of this order."
It remains unclear whether Trump can legally pause the ban. It's also unclear how he plans to enforce a 50 percent "joint venture" ownership with the company, a move he announced on Sunday.
Security

HPE Investigating Breach Claims After Hacker Offers To Sell Data (securityweek.com) 3

The notorious hacker IntelBroker claims to have stolen data from HPE systems, including source code, private repositories, digital certificates, and access to certain services. SecurityWeek reports: The compromised data allegedly includes source code for products such as Zerto and iLO, private GitHub repositories, digital certificates, Docker builds, and even some personal information that the hacker described as "old user PII for deliveries." IntelBroker is also offering access to some services used by HPE, including APIs, WePay, GitHub and GitLab. Contacted by SecurityWeek, HPE said it's aware of the breach claims and is conducting an investigation.

"HPE became aware on January 16 of claims being made by a group called IntelBroker that it was in possession of information belonging to HPE. HPE immediately activated our cyber response protocols, disabled related credentials, and launched an investigation to evaluate the validity of the claims," said HPE spokesperson Adam R. Bauer. "There is no operational impact to our business at this time, nor evidence that customer information is involved," Bauer added.

AI

CIA's Chatbot Stands In For World Leaders 37

The CIA has developed a chatbot to talk to virtual versions of foreign presidents and prime ministers. "Understanding leaders around the world is one of the CIA's most important jobs. Teams of analysts comb through intelligence collected by spies and publicly available information to create profiles of leaders that can predict behaviors," reports the New York Times. "A chatbot powered by artificial intelligence now helps do that work." From the report: The chatbot is part of the spy agency's drive to improve the tools available to CIA analysts and its officers in the field, and to better understand adversaries' technical advances. Core to the effort is to make it easier for companies to work with the most secretive agency. William Burns, CIA director for the past four years, prioritized improving the agency's technology and understanding of how it is used. Incoming Trump administration officials say they plan to build on those initiatives, not tear them down. [...]

The CIA has long used digital tools, spy gadgets and even AI. But with the development of new forms of AI, including the large language models that power chatbots, the agency has stepped up its investments. Making better use of AI, Burns said, is crucial to US competition with China. And better AI models have helped the agency's analysts "digest the avalanche of open-source information out there," he said. The new tools have also helped analysts process clandestinely acquired information, Burns said. New technologies developed by the agency are helping spies navigate cities in authoritarian countries where governments use AI-powered cameras to conduct constant surveillance on their population and foreign spies.
AI

Authors Seek Meta's Torrent Client Logs and Seeding Data In AI Piracy Probe (torrentfreak.com) 15

An anonymous reader quotes a report from TorrentFreak: Meta is among a long list of companies being sued for allegedly using pirated material to train its AI models. Meta has never denied using copyrighted works but stressed that it would rely on a fair use defense. However, with rightsholders in one case asking for torrent client data and 'seeding lists' for millions of books allegedly shared in public, the case now takes a geeky turn. [...] A few weeks ago, the plaintiffs asked for permission to submit a third amended complaint (PDF). After uncovering Meta's use of BitTorrent to source copyright-infringing training data from pirate shadow library, LibGen, the request was justified, they argued. Specifically, the authors say that Meta willingly used BitTorrent to download pirated books from LibGen, knowing that was legally problematic. As a result, Meta allegedly shared copies of these books with other people, as is common with the use of BitTorrent.

"By downloading through the bit torrent protocol, Meta knew it was facilitating further copyright infringement by acting as a distribution point for other users of pirated books," the amended complaint notes. "Put another way, by opting to use a bit torrent system to download LibGen's voluminous collection of pirated books, Meta 'seeded' pirated books to other users worldwide." Meta believed that the allegations weren't sufficiently new to warrant an update to the complaint. The company argued that it was already a well-known fact that it used books from these third-party sources, including LibGen. However, the authors maintained that the 'torrent' angle is novel and important enough to warrant an update. Last week, United States District Judge Vince Chhabria agreed, allowing the introduction of these new allegations. In addition to greenlighting the amended complaint, the Judge also allowed the authors to conduct further testimony on the "seeding" angle. "[E]vidence about seeding is relevant to the existing claim because it is potentially relevant to the plaintiffs' assertion of willful infringement or to Meta's fair use defense," Judge Chhabria wrote last week.

With the court recognizing the relevance of Meta's torrenting activity, the plaintiffs requested reconsideration of an earlier order, where discovery on BitTorrent-related matters was denied. Through a filing submitted last Wednesday, the plaintiffs hope to compel Meta to produce its BitTorrent logs and settings, including peer lists and seeding data. "The Order denied Plaintiffs' motion to compel production of torrenting data, including Meta's BitTorrent client, application logs, and peer lists. This data will evidence how much content Meta torrented from shadow libraries and how much it seeded to third parties as a host of this stolen IP," they write. While archiving lists of seeders is not a typical feature for a torrent client, the authors are requesting Meta to disclose any relevant data. In addition, they also want the court to reconsider its ruling regarding the crime-fraud exception. That's important, they suggest, as Meta's legal counsel was allegedly involved in matters related to torrenting. "Meta, with the involvement of in-house counsel, decided to obtain copyrighted works without permission from online databases of copyrighted works that 'we know to be pirated, such as LibGen," they write. The authors allege that this involved "seeding" files and that Meta attempted to "conceal its actions" by limiting the amount of data shared with the public. One Meta employee also asked for guidance, as "torrenting from a corporate laptop doesn't feel right."

Slashdot Top Deals