×
Encryption

Almost Every Chinese Keyboard App Has a Security Flaw That Reveals What Users Type (technologyreview.com) 66

An anonymous reader quotes a report from MIT Technology Review: Almost all keyboard apps used by Chinese people around the world share a security loophole that makes it possible to spy on what users are typing. The vulnerability, which allows the keystroke data that these apps send to the cloud to be intercepted, has existed for years and could have been exploited by cybercriminals and state surveillance groups, according to researchers at the Citizen Lab, a technology and security research lab affiliated with the University of Toronto.

These apps help users type Chinese characters more efficiently and are ubiquitous on devices used by Chinese people. The four most popular apps -- built by major internet companies like Baidu, Tencent, and iFlytek -- basically account for all the typing methods that Chinese people use. Researchers also looked into the keyboard apps that come preinstalled on Android phones sold in China. What they discovered was shocking. Almost every third-party app and every Android phone with preinstalled keyboards failed to protect users by properly encrypting the content they typed. A smartphone made by Huawei was the only device where no such security vulnerability was found.

In August 2023, the same researchers found that Sogou, one of the most popular keyboard apps, did not use Transport Layer Security (TLS) when transmitting keystroke data to its cloud server for better typing predictions. Without TLS, a widely adopted international cryptographic protocol that protects users from a known encryption loophole, keystrokes can be collected and then decrypted by third parties. Even though Sogou fixed the issue after it was made public last year, some Sogou keyboards preinstalled on phones are not updated to the latest version, so they are still subject to eavesdropping. [...] After the researchers got in contact with companies that developed these keyboard apps, the majority of the loopholes were fixed. But a few companies have been unresponsive, and the vulnerability still exists in some apps and phones, including QQ Pinyin and Baidu, as well as in any keyboard app that hasn't been updated to the latest version.

Security

'ArcaneDoor' Cyberspies Hacked Cisco Firewalls To Access Government Networks (wired.com) 21

An anonymous reader quotes a report from Wired: Network security appliances like firewalls are meant to keep hackers out. Instead, digital intruders are increasingly targeting them as the weak link that lets them pillage the very systems those devices are meant to protect. In the case of one hacking campaign over recent months, Cisco is now revealing that its firewalls served as beachheads for sophisticated hackers penetrating multiple government networks around the world. On Wednesday, Cisco warned that its so-called Adaptive Security Appliances -- devices that integrate a firewall and VPN with other security features -- had been targeted by state-sponsored spies who exploited two zero-day vulnerabilities in the networking giant's gear to compromise government targets globally in a hacking campaign it's calling ArcaneDoor.

The hackers behind the intrusions, which Cisco's security division Talos is calling UAT4356 and which Microsoft researchers who contributed to the investigation have named STORM-1849, couldn't be clearly tied to any previous intrusion incidents the companies had tracked. Based on the group's espionage focus and sophistication, however, Cisco says the hacking appeared to be state-sponsored. "This actor utilized bespoke tooling that demonstrated a clear focus on espionage and an in-depth knowledge of the devices that they targeted, hallmarks of a sophisticated state-sponsored actor," a blog post from Cisco's Talos researchers reads. Cisco declined to say which country it believed to be responsible for the intrusions, but sources familiar with the investigation tell WIRED the campaign appears to be aligned with China's state interests.

Cisco says the hacking campaign began as early as November 2023, with the majority of intrusions taking place between December and early January of this year, when it learned of the first victim. "The investigation that followed identified additional victims, all of which involved government networks globally," the company's report reads. In those intrusions, the hackers exploited two newly discovered vulnerabilities in Cisco's ASA products. One, which it's calling Line Dancer, let the hackers run their own malicious code in the memory of the network appliances, allowing them to issue commands to the devices, including the ability to spy on network traffic and steal data. A second vulnerability, which Cisco is calling Line Runner, would allow the hackers' malware to maintain its access to the target devices even when they were rebooted or updated. It's not yet clear if the vulnerabilities served as the initial access points to the victim networks, or how the hackers might have otherwise gained access before exploiting the Cisco appliances.
Cisco advises that customers apply its new software updates to patch both vulnerabilities.

A separate advisory (PDF) from the UK's National Cybersecurity Center notes that physically unplugging an ASA device does disrupt the hackers' access. "A hard reboot by pulling the power plug from the Cisco ASA has been confirmed to prevent Line Runner from re-installing itself," the advisory reads.
Oracle

Oracle Is Moving Its World Headquarters To Nashville (cnbc.com) 66

Oracle Chairman Larry Ellison said Tuesday that the company is moving its world headquarters to Nashville, Tennessee, to be closer to a major health-care epicenter. CNBC reports: In a wide-ranging conversation with Bill Frist, a former U.S. Senate Majority Leader, Ellison said Oracle is moving a "huge campus" to Nashville, "which will ultimately be our world headquarters." He said Nashville is an established health center and a "fabulous place to live," one that Oracle employees are excited about. "It's the center of the industry we're most concerned about, which is the health-care industry," Ellison said. The announcement was seemingly spur-of-the-moment. "I shouldn't have said that," Ellison told Frist, a longtime health-care industry veteran who represented Tennessee in the Senate. The pair spoke during a fireside chat at the Oracle Health Summit in Nashville.

Nashville has been a major player in the health-care scene for decades, and the city is now home to a vibrant network of health systems, startups and investment firms. The city's reputation as a health-care hub was catalyzed when HCA Healthcare, one of the first for-profit hospital companies in the U.S., was founded there in 1968. HCA helped attract troves of health-care professionals to Nashville, and other organizations quickly followed suit. Oracle has been developing its new $1.2 billion campus in the city for about three years, according to The Tennessean. "Our people love it here, and we think it's the center of our future," Ellison said.

Security

Change Healthcare Finally Admits It Paid Ransomware Hackers (wired.com) 28

Andy Greenberg reports via Wired: More than two months after the start of a ransomware debacle whose impact ranks among the worst in the history of cybersecurity, the medical firm Change Healthcare finally confirmed what cybercriminals, security researchers, and Bitcoin's blockchain had already made all too clear: that it did indeed pay a ransom to the hackers who targeted the company in February. And yet, it still faces the risk of losing vast amounts of customers' sensitive medical data. In a statement sent to WIRED and other news outlets on Monday evening, Change Healthcare wrote that it paid a ransom to a cybercriminal group extorting the company, a hacker gang known as AlphV or BlackCat. "A ransom was paid as part of the company's commitment to do all it could to protect patient data from disclosure," the statement reads. The company's belated admission of that payment accompanied a new post on its website where it warns that the hackers may have stolen health-related data that would "cover a substantial proportion of people in America."

Cybersecurity and cryptocurrency researchers told WIRED last month that Change Healthcare appeared to have paid that ransom on March 1, pointing to a transaction of 350 bitcoins or roughly $22 million sent into a crypto wallet associated with the AlphV hackers. That transaction was first highlighted in a message on a Russian cybercriminal forum known as RAMP, where one of AlphV's allegedly jilted partners complained that they hadn't received their cut of Change Healthcare's payment. However, for weeks following that transaction, which was publicly visible on Bitcoin's blockchain and which both security firm Recorded Future and blockchain analysis firm TRM Labs told WIRED had been received by AlphV, Change Healthcare repeatedly declined to confirm that it had paid the ransom.

Change Healthcare's confirmation of that extortion payment puts new weight behind the cybersecurity industry's fears that the attack -- and the profit AlphV extracted from it -- will lead ransomware gangs to further target health care companies. "It 100 percent encourages other actors to target health care organizations," Jon DiMaggio, a researcher with cybersecurity firm Analyst1 who focuses on ransomware, told WIRED at the time the transaction was first spotted in March. "And it's one of the industries we don't want ransomware actors to target -- especially when it affects hospitals." Compounding the situation, a conflict between hackers in the ransomware ecosystem has led to a second ransomware group claiming to possess Change Healthcare's stolen data and threatening to sell it to the highest bidder on the dark web. Earlier this month that second group, known as RansomHub, sent WIRED alleged samples of the stolen data that appeared to come from Change Healthcare's network, including patient records and a contract with another health care company.

Earth

Europe Baked in 'Extreme Heat Stress' Pushing Temperatures To Record Highs (theguardian.com) 111

Scorching weather has baked Europe in more days of "extreme heat stress" than its scientists have ever seen. The Guardian: Heat-trapping pollutants that clog the atmosphere helped push temperatures in Europe last year to the highest or second-highest levels ever recorded, according to the EU's Earth-watching service Copernicus and the World Meteorological Organization (WMO). Europeans are suffering with unprecedented heat during the day and are stressed by uncomfortable warmth at night. The death rate from hot weather has risen 30% in Europe in two decades, the joint State of the Climate report from the two organisations found.

"The cost of climate action may seem high," said WMO secretary-general Celeste Saulo, "but the cost of inaction is much higher." The report found that temperatures across Europe were above average for 11 months of 2023, including the warmest September since records began. The hot and dry weather fuelled large fires that ravaged villages and spewed smoke that choked far-off cities. The blazes that firefighters battled were particularly fierce in drought-stricken southern countries such as Portugal, Spain and Italy. Greece was hit by the largest wildfire recorded in the EU, which burned 96,000 hectares of land, according to the report. Heavy rain also led to deadly floods. Europe was about 7% wetter in 2023 than the average over the last three decades, the report found, and one-third of its river network crossed the "high" flood threshold. One-sixth hit "severe" levels.

Mars

The Ingenuity Mars Helicopter Just Sent Its Last Message Home (livescience.com) 27

Two months ago the team behind NASA's Ingenuity Helicopter released a video reflecting on its historic explorations of Mars, flying 10.5 miles (17.0 kilometers) in 72 different flights over three years. It was the team's way of saying goodbye, according to NASA's video.

And this week, LiveScience reports, Ingenuity answered back: On April 16, Ingenuity beamed back its final signal to Earth, which included the remaining data it had stored in its memory bank and information about its final flight. Ingenuity mission scientists gathered in a control room at NASA's Jet Propulsion Laboratory (JPL) in California to celebrate and analyze the helicopter's final message, which was received via NASA's Deep Space Network, made up of ground stations located across the globe.

In addition to the remaining data files, Ingenuity sent the team a goodbye message including the names of all the people who worked on the mission. This special message had been sent to Perseverance the day before and relayed to Ingenuity to send home.

The helicopter, which still has power, will now spend the rest of its days collecting data from its final landing spot in Valinor Hills, named after a location in J.R.R. Tolkien's "The Lord of the Rings" books.

The chopper will wake up daily to test its equipment, collect a temperature reading and take a single photo of its surroundings. It will continue to do this until it loses power or fills up its remaining memory space, which could take 20 years. Such a long-term dataset could not only benefit future designs for Martian vehicles but also "provide a long-term perspective on Martian weather patterns and dust movement," researchers wrote in the statement. However, the data will be kept on board the helicopter and not beamed back to Earth, so it must be retrieved by future Martian vehicles or astronauts.

"Whenever humanity revisits Valinor Hills — either with a rover, a new aircraft, or future astronauts — Ingenuity will be waiting with her last gift of data," Teddy Tzanetos, an Ingenuity scientist at JPL, said in the statement.

Thursday NASA's Jet Propulsion Laboratory released another new video tracing the entire route of Ingenuity's expedition over the surface of Mars.

"Ingenuity's success could pave the way for more extensive aerial exploration of Mars down the road," adds Spacae.com: Mission team members are already working on designs for larger, more capable rotorcraft that could collect a variety of science data on the Red Planet, for example. And Mars isn't the only drone target: In 2028, NASA plans to launch Dragonfly, a $3.3 billion mission to Saturn's huge moon Titan, which hosts lakes, seas and rivers of liquid hydrocarbons on its frigid surface. The 1,000-pound (450 kg) Dragonfly will hop from spot to spot on Titan, characterizing the moon's various environments and assessing its habitability.
The Almighty Buck

How a Renewable Energy-Powered Bitcoin Startup Helps Electrify Rural Africa (cnbc.com) 66

CNBC visited a small group of bitcoin miners who "set up shop at the site of an extinct volcano" near Kenya's Hell's Gate National Park.

Their mine "consists of a single 500-kilowatt mobile container that, from the outside, looks like a small residential trailer." But what's more interesting is it's operated by a startup called Gridless. (According to its web site Gridless "designs, builds, and operates bitcoin mining sites alongside small-scale renewable energy producers in rural Africa where excess energy is not utilized...") Backed by Jack Dorsey's Block, Gridless electrifies its machines with a mix of solar power and the stranded, wasted energy from a nearby geothermal site. It's one of six mines run by the company in Kenya, Malawi and Zambia, powered by a mix of renewable inputs and working toward a broader mission of securing and decentralizing the bitcoin network... In early 2022, [the three Gridless co-founders] began brainstorming creative solutions for the divide between power generation and capacity, and the lack of access to electricity in Africa. They landed on the idea of bitcoin mining, which could potentially solve a big problem for renewable energy developers by taking their stranded power and spreading it to other parts of the continent.

In Africa, 43% of the population, or roughly 600 million people, lack access to electricity.... Africa is home to an estimated 10 terawatts of solar capacity, 350 gigawatts of hydro and another 110 gigawatts of wind. Some of this renewable energy is being harnessed already, but a lot isn't because building the specialized infrastructure to capture it is expensive. Even with 60% of the best solar resources globally, Africa only has 1% of installed solar PV capacity.

Enter bitcoin miners.

Bitcoin gets a bad rap for the amount of energy it consumes, but it can also help unlock these trapped renewable sources of power. Miners are essentially energy buyers, and co-locating with renewables creates a financial incentive to bolster production. "As often happens, you'll have an overage of power during the day or even at night, and there's nobody to soak that power up," said Hersman. He said his company's 50-kilowatt mining container can "take up whatever is extra throughout the day...." Demand from bitcoin miners on these semi-stranded assets is making renewables in Africa economically viable. The power supplier benefits from selling energy that previously had been discarded, while the energy plants will sometimes lower costs for the customer. At one of the Gridless pilot sites in Kenya, the hydro plant dropped the price of power from 35 cents per kilowatt hour to 25 cents per kWh.

The buildout of capacity is also electrifying households. Gridless says its sites have powered 1,200 houses in Zambia, 1,800 in Malawi and 5,000 in Kenya. The company's mines also have delivered power for containerized cold storage for local farmers, battery charging stations for electric motorcycles and public WiFi points.

United States

Insufficient Redundancy? Light-Pole Installation Cut Fiber Line, Triggered Three-State 911 Outage (apnews.com) 90

"Workers installing a light pole in Missouri cut into a fiber line," reports the Associated Press, knocking out 911 phone service "for emergency agencies in Nebraska, Nevada and South Dakota, an official with the company that operates the line said Thursday." In Kansas City, Missouri, workers installing a light pole for another company Wednesday cut into a Lumen Technologies fiber line, Lumen global issues director Mark Molzen said in an email to The Associated Press. Service was restored within 2 1/2 hours, he said. There were no reports of 911 outages in Kansas City...

The Dundy County Sheriff's Office in Nebraska warned in a social media post Wednesday night that 911 callers would receive a busy signal and urged people to instead call the administrative phone line. About three hours later, officials said mobile and landline 911 services had been restored. In Douglas County, home to Omaha and more than a quarter of Nebraska's residents, officials first learned there was a problem when calls from certain cellphone companies showed up in a system that maps calls but didn't go through over the phone. Operators started calling back anyone whose call didn't go through, and officials reached out to Lumen, which confirmed the outage. Service was restored by 4 a.m.

Kyle Kramer, the technical manager for Douglas County's 911 Center, said the outage highlights the potential problems of having so many calls go over the same network. "As things become more interconnected in our modern world, whether you're on a wireless device or a landline now, those are no longer going over the traditional old copper phone wires that may have different paths in different areas," Kramer said. "Large networks usually have some aggregation point, and those aggregation points can be a high risk."

Kramer said this incident and the two previous 911 outages he has seen in the past year in Omaha make him concerned that communications companies aren't building enough redundancy into their networks.

South Dakota officials called the state-wide outage "unprecedented," with their Department of Public Safety reporting the outage lasted two hours (though texting to 911 still worked in most locations — and of course, people could still call local emergency services using their non-emergency lines.) America's FCC has already begun an investigation.



The article notes that "The outages, ironically, occurred in the midst of National Public Safety Telecommunicators Week."

Thanks to long-time Slashdot reader davidwr for sharing the article.
Portables

Volla Successfully Crowdfunds a Privacy-Focused Tablet on Kickstarter (kickstarter.com) 33

It's "the new generation of Tablet for simplicity and privacy..." according to its Kickstarter page. "Top-tier performance, lightweight design and completely Google-free." And it's already reached its funding goal of $53,312 — climbing to over $75,000 from 115 backers with another 26 days still to go. 9to5Linux reports: Volla, the maker of the Volla Phone smartphones, has launched a crowdfunding campaign on Kickstarter for their first tablet device, the Volla Tablet, which will also support the Ubuntu Touch mobile OS.

Featuring a 12.3-inch Quad HD display with 2650Ã--1600 pixel resolution, the Volla Tablet uses a powerful MediaTek Gaming G99 8-core processor, 12 GB RAM, and 256 GB internal storage. It also comes with a long-lasting 10,000 mAh battery, 2G/3G/4G cellular network support, Wi-Fi, Bluetooth, and a 13+5 MP main camera.

By default, Volla Tablet ships with Volla OS 13, Volla's in-house operating system based on the free Android Open Source Project (AOSP), but users will be able to buy the tablet with Ubuntu Touch featuring built-in convergence and support for Android apps with WayDroid container.

"Users will also be able to use desktop apps like Firefox or LibreOffice thanks to the help of the Libertine container," according to the article. ("Volla says that Volla Tablet with Ubuntu Touch is ideal for Linux enthusiasts and minimalists seeking a simplified, efficient, and familiar operating system experience.")

Its Kickstarter page points out the tablet even offers options like "hide.me VPN" and private speech recognition that's "cloud-independent for secure, confidential interactions."

("For U.S. users, please note that only roaming SIM cards from abroad can be used.")
Math

A Chess Formula Is Taking Over the World (theatlantic.com) 27

An anonymous reader quotes a report from The Atlantic: In October 2003, Mark Zuckerberg created his first viral site: not Facebook, but FaceMash. Then a college freshman, he hacked into Harvard's online dorm directories, gathered a massive collection of students' headshots, and used them to create a website on which Harvard students could rate classmates by their attractiveness, literally and figuratively head-to-head. The site, a mean-spirited prank recounted in the opening scene of The Social Network, got so much traction so quickly that Harvard shut down his internet access within hours. The math that powered FaceMash -- and, by extension, set Zuckerberg on the path to building the world's dominant social-media empire -- was reportedly, of all things, a formula for ranking chess players: the Elo system.

Fundamentally, what an Elo rating does is predict the outcome of chess matches by assigning every player a number that fluctuates based purely on performance. If you beat a slightly higher-ranked player, your rating goes up a little, but if you beat a much higher-ranked player, your rating goes up a lot (and theirs, conversely, goes down a lot). The higher the rating, the more matches you should win. That is what Elo was designed for, at least. FaceMash and Zuckerberg aside, people have deployed Elo ratings for many sports -- soccer, football, basketball -- and for domains as varied as dating, finance, and primatology. If something can be turned into a competition, it has probably been Elo-ed. Somehow, a simple chess algorithm has become an all-purpose tool for rating everything. In other words, when it comes to the preferred way to rate things, Elo ratings have the highest Elo rating. [...]

Elo ratings don't inherently have anything to do with chess. They're based on a simple mathematical formula that works just as well for any one-on-one, zero-sum competition -- which is to say, pretty much all sports. In 1997, a statistician named Bob Runyan adapted the formula to rank national soccer teams -- a project so successful that FIFA eventually adopted an Elo system for its official rankings. Not long after, the statistician Jeff Sagarin applied Elo to rank NFL teams outside their official league standings. Things really took off when the new ESPN-owned version of Nate Silver's 538 launched in 2014 and began making Elo ratings for many different sports. Some sports proved trickier than others. NBA basketball in particular exposed some of the system's shortcomings, Neil Paine, a stats-focused sportswriter who used to work at 538, told me. It consistently underrated heavyweight teams, for example, in large part because it struggled to account for the meaninglessness of much of the regular season and the fact that either team might not be trying all that hard to win a given game. The system assumed uniform motivation across every team and every game. Pretty much anything, it turns out, can be framed as a one-on-one, zero-sum game.
Arpad Emmerich Elo, creator of the Elo rating system, understood the limitations of his invention. "It is a measuring tool, not a device of reward or punishment," he once remarked. "It is a means to compare performances, assess relative strength, not a carrot waved before a rabbit, or a piece of candy given to a child for good behavior."
Windows

Microsoft Does Not Want You To Use iPerf3 To Measure Network Performance on Windows 60

An anonymous reader shares a report: iPerf is a fairly popular cross-platform tool that is used by many to measure network performance and diagnose any potential issues in this area. The open-source utility is maintained by an organization called Energy Sciences Network (ESnet) and officially supports Linux, Unix, and Windows. However, Microsoft has now published a detailed blog post explaining why you should not use the latest version, iPerf3, on Windows installations.

Microsoft has highlighted three key reasons to discourage the use of iPerf3 on Windows. The first is that ESnet does not support this version on Windows, and recommends iPerf2 instead. On its website, ESnet has emphasized that CentOS 7 Linux, FreeBSD 11, and macOS 10.12 are the only supported platforms. Another very important reason not to use iPerf3 on Windows is that it does not make native OS calls. Instead, it leverages Cygwin as an emulation layer, which obviously comes with a performance penalty. This alone means that iPerf3 on Windows isn't really an ideal candidate for benchmarking your network. While Microsoft has praised the maintainers who are trying to get iPerf3 to run on Windows via emulation, another flaw with this approach is that some advanced networking options simply aren't available on Windows or may behave in unexpected ways.
Communications

Northrop Grumman Working With SpaceX On US Spy Satellite System (reuters.com) 10

Longtime Slashdot reader SonicSpike shares a report from Reuters: Aerospace and defense company Northrop Grumman is working with SpaceX [...] on a classified spy satellite project already capturing high-resolution imagery of the Earth, according to people familiar with the program. The program, details of which were first reported by Reuters last month, is meant to enhance the U.S. government's ability to track military and intelligence targets from low-Earth orbits, providing high-resolution imagery of a kind that had traditionally been captured mostly by drones and reconnaissance aircraft. The inclusion of Northrop Grumman, which has not been previously reported, reflects a desire among government officials to avoid putting too much control of a highly-sensitive intelligence program in the hands of one contractor, four people familiar with the project told Reuters. 'It is in the government's interest to not be totally invested in one company run by one person,' one of the people said.

It's unclear whether other contractors are involved at present or could join the project as it develops. Northrop Grumman is providing sensors for some of the SpaceX satellites, the people familiar with the project told Reuters. Northrop Grumman, two of the people added, will test those satellites at its own facilities before they are launched. At least 50 of the SpaceX satellites are expected at Northrop Grumman facilities for procedures including testing and the installation of sensors in coming years, one of the people said. In March, Reuters reported that the National Reconnaissance Office, or NRO, in 2021 awarded a $1.8 billion contract to SpaceX for the classified project, a planned network of hundreds of satellites. So far, the people familiar with the project said, SpaceX has launched roughly a dozen prototypes and is already providing test imagery to the NRO, an intelligence agency that oversees development of U.S. spy satellites.

Security

Frontier Communications Shuts Down Systems After Cyberattack (bleepingcomputer.com) 6

U.S. telecom provider Frontier Communications shut down its systems after a cybercrime group breached some of its IT systems in a recent cyberattack. BleepingComputer reports: Frontier is a leading U.S. communications provider that provides gigabit Internet speeds over a fiber-optic network to millions of consumers and businesses across 25 states. After discovering the incident, the company was forced to partially shut down some systems to prevent the threat actors from laterally moving through the network, which also led to some operational disruptions. Despite this, Frontier says the attackers could access some PII data, although it didn't disclose if it belonged to customers, employees, or both.

"On April 14, 2024, Frontier Communications Parent, Inc. [..] detected that a third party had gained unauthorized access to portions of its information technology environment," the company revealed in a filing with the U.S. Securities and Exchange Commission on Thursday. "Based on the Company's investigation, it has determined that the third party was likely a cybercrime group, which gained access to, among other information, personally identifiable information." Frontier now believes that it has contained the breach, has since restored its core IT systems affected during the incident, and is working on restoring normal business operations.

Privacy

Colorado Bill Aims To Protect Consumer Brain Data (nytimes.com) 15

An anonymous reader quotes a report from the New York Times: Consumers have grown accustomed to the prospect that their personal data, such as email addresses, social contacts, browsing history and genetic ancestry, are being collected and often resold by the apps and the digital services they use. With the advent of consumer neurotechnologies, the data being collected is becoming ever more intimate. One headband serves as a personal meditation coach by monitoring the user's brain activity. Another purports to help treat anxiety and symptoms of depression. Another reads and interprets brain signals while the user scrolls through dating apps, presumably to provide better matches. ("'Listen to your heart' is not enough," the manufacturer says on its website.) The companies behind such technologies have access to the records of the users' brain activity -- the electrical signals underlying our thoughts, feelings and intentions.

On Wednesday, Governor Jared Polis of Colorado signed a bill that, for the first time in the United States, tries to ensure that such data remains truly private. The new law, which passed by a 61-to-1 vote in the Colorado House and a 34-to-0 vote in the Senate, expands the definition of "sensitive data" in the state's current personal privacy law to include biological and "neural data" generated by the brain, the spinal cord and the network of nerves that relays messages throughout the body. "Everything that we are is within our mind," said Jared Genser, general counsel and co-founder of the Neurorights Foundation, a science group that advocated the bill's passage. "What we think and feel, and the ability to decode that from the human brain, couldn't be any more intrusive or personal to us." "We are really excited to have an actual bill signed into law that will protect people's biological and neurological data," said Representative Cathy Kipp, Democrat of Colorado, who introduced the bill.

Network

Nigeria To Criminalise Fiber Cable Damage Costing Telecoms Billions (bloomberg.com) 19

Nigeria will criminalize the destruction of broadband fiber cables following repeated complaints by MTN Nigeria and other telecommunications companies that they are losing billions of naira, Bloomberg News reported, citing people familiar with the matter. From the report: Nigeria's works ministry, which supervises federal road constructors, is finalizing the regulation that will be signed as an executive order by President Bola Tinubu, said the people, asking not to be identified as they weren't authorized to comment. While there are presently laws against vandalism, the authorities are aiming to regulate construction firms more closely. The order will enforce stiff penalties on offenders, said the people, declining to provide more details or say when it will be signed. "Telecom assets are critical backbone that supports the economy across sectors," said Temitope Ajayi, a senior presidential aide, who noted that the Association of Telecommunications Companies has been demanding the classification for years. New rules will provide "further assurance that the Nigerian government will protect their investments against vandals and criminal elements."
Television

Trump Media Shares Down 14% After Company Says Truth Social To Launch TV Streaming (cnbc.com) 124

Trump Media & Technology Group Corp., which has been called the "mother of all meme stocks" after it made its stock market debut in late March, announced that its Truth Social platform is moving to launch a live TV streaming platform. Following the news, shares of DJT closed more than 14% lower Tuesday. They ended trading Monday down by more than 18%. CNBC reports: The stock's price has dropped by a whopping 67.7% since Trump Media began trading as a public company on March 26, erasing more than $5 billion in market capitalization. Trump Media's majority shareholder is former President Donald Trump, who holds nearly 60% of its stock.

Earlier Tuesday, Trump Media in a press release said it "has finished the research and development phase of its new live TV streaming platform and will begin scaling up its own content delivery network." The company said it will roll out streaming content in three phases, the first of which will introduce Truth Social's content delivery network for streaming live TV to the app for Android, iOS and web. Phase two will release stand-alone Truth Social streaming apps for phones, tablets and other devices, while phase three will release such apps for home television, Trump Media said.
"The streaming content is expected to focus on live TV including news networks, religious channels, family-friendly content including films and documentaries; and other content that has been cancelled, is at risk of cancellation, or is being suppressed on other platforms and services," Trump Media said in its release.

"We're excited to move forward with the next big phase for Truth Social," added CEO Devin Nunes in a statement. "With our streaming content, we aim to provide a permanent home for high-quality news and entertainment that face discrimination by other channels and content delivery service. There is a lot of great content that simply can't find an audience for unjust reasons, and we want to let these creators know they'll soon have a guaranteed platform where they won't be cancelled."
Security

Cloudflare DDoS Threat Report For 2024 Q1 10

Cloudflare, in a blog post: Key insights from the first quarter of 2024 include:
1. 2024 started with a bang. Cloudflare's defense systems automatically mitigated 4.5 million DDoS attacks during the first quarter -- representing a 50% year-over-year (YoY) increase.
2. DNS-based DDoS attacks increased by 80% YoY and remain the most prominent attack vector.
3. DDoS attacks on Sweden surged by 466% after its acceptance to the NATO alliance, mirroring the pattern observed during Finland's NATO accession in 2023.

We've just wrapped up the first quarter of 2024, and, already, our automated defenses have mitigated 4.5 million DDoS attacks -- an amount equivalent to 32% of all the DDoS attacks we mitigated in 2023. Breaking it down to attack types, HTTP DDoS attacks increased by 93% YoY and 51% quarter-over-quarter (QoQ). Network-layer DDoS attacks, also known as L3/4 DDoS attacks, increased by 28% YoY and 5% QoQ. When comparing the combined number of HTTP DDoS attacks and L3/4 DDoS attacks, we can see that, overall, in the first quarter of 2024, the count increased by 50% YoY and 18% QoQ. In total, our systems mitigated 10.5 trillion HTTP DDoS attack requests in Q1. Our systems also mitigated over 59 petabytes of DDoS attack traffic -- just on the network-layer.
The Internet

ISPs Can Charge Extra For Fast Gaming Under FCC's Internet Rules, Critics Say (arstechnica.com) 29

An anonymous reader quotes a report from Ars Technica: Some net neutrality proponents are worried that soon-to-be-approved Federal Communications Commission rules will allow harmful fast lanes because the plan doesn't explicitly ban "positive" discrimination. FCC Chairwoman Jessica Rosenworcel's proposed rules for Internet service providers would prohibit blocking, throttling, and paid prioritization. The rules mirror the ones imposed by the FCC during the Obama era and repealed during Trump's presidency. But some advocates are criticizing a decision to let Internet service providers speed up certain types of applications as long as application providers don't have to pay for special treatment. Stanford Law Professor Barbara van Schewick, who has consistently argued for stricter net neutrality rules, wrote in a blog post on Thursday that "harmful 5G fast lanes are coming."

"T-Mobile, AT&T and Verizon are all testing ways to create these 5G fast lanes for apps such as video conferencing, games, and video where the ISP chooses and controls what gets boosted," van Schewick wrote. "They use a technical feature in 5G called network slicing, where part of their radio spectrum gets used as a special lane for the chosen app or apps, separated from the usual Internet traffic. The FCC's draft order opens the door to these fast lanes, so long as the app provider isn't charged for them." In an FCC filing yesterday, AT&T said that carriers will use network slicing "to better meet the needs of particular business applications and consumer preferences than they could over a best-efforts network that generally treats all traffic the same."

Van Schewick warns that carriers could charge consumers more for plans that speed up specific types of content. For example, a mobile operator could offer a basic plan alongside more expensive tiers that boost certain online games or a tier that boosts services like YouTube and TikTok. Ericsson, a telecommunications vendor that sells equipment to carriers including AT&T, Verizon, and T-Mobile, has pushed for exactly this type of service. In a report on how network slicing can be used commercially, Ericsson said that "many gamers are willing to pay for enhanced gaming experiences" and would "pay up to $10.99 more for a guaranteed gaming experience on top of their 5G monthly subscription."

Earth

World's Coral Reefs Hit By a Fourth Mass Bleaching Event, NOAA Says (nbcnews.com) 57

The National Oceanic and Atmospheric Administration on Monday declared that Earth is in the midst of a "4th global coral bleaching event" that's been documented over the last 14 months in every major ocean basin, including off Florida in the United States, in Australia's Great Barrier Reef and in the South Pacific. "As the world's oceans continue to warm, coral bleaching is becoming more frequent and severe," said Derek Manzello, a coral reef ecologist who coordinates NOAA's Coral Reef Watch Program, in a news release. "When these events are sufficiently severe or prolonged, they can cause coral mortality, which hurts the people who depend on the coral reefs for their livelihoods." NBC News reports: Corals are critical ecosystems that support a vast array of fish and aquatic species, which help feed coastal communities and attract tourists. The economic value of reefs is estimated at $2.7 trillion per year, according to a 2020 report from the Global Coral Reef Monitoring Network. "They protect our coastline. They offer protection from storms and hurricanes. They have a great value for our economy and safety," [Ana Palacio, an assistant scientist at the Cooperative Institute for Marine and Atmospheric Studies, a research institute that is based at the University of Miami in partnership with NOAA] said.

In Florida, as sea surface temperatures spiked, bleaching started early in the season, experts said. "Normally, bleaching will be observed in the Northern Hemisphere around August and September. We started to observe bleaching in July last year," said Phanor Montoya-Maya, a marine biologist with the Coral Restoration Foundation, an organization that collects, restores and repopulates corals. Palacio said the region saw widespread mortality of elkhorn and staghorn corals, two species that have been the focus of restoration efforts. "In some locations, about 20% of those populations survived," Palacio said of restored corals. "We're concentrating our hope on why those corals survived and what they can tell us about resistance and how corals can be more resilient."

The last global coral bleaching event happened in 2014 and lasted until 2017. More than 56% of global reef areas saw temperatures that could cause bleaching during that time period. In an email on Monday, Manzello said that 54% of the world's coral reef areas had experienced bleaching-level heat stress in the past year and that the event was poised to become the worst bleaching event in history. "The percentage of reef areas experiencing bleaching-level heat stress has been increasing by roughly 1% per week," Manzello said. "It is likely that this event will surpass the previous peak."

Montoya-Maya said a bleaching alert is already in effect in Florida, even earlier than last year. He said the Coral Restoration Foundation was preparing for a busy summer responding to another bleaching event. The natural pattern of El Nino has begun to dissipate and NOAA's Climate Prediction Center estimates there is a 60% chance La Niaa develops this summer, which could help cool Atlantic waters and allow some corals to recover, at least temporarily.

Transportation

Emissions Dropped 1.8% Every Year in California's Bay Area. Researchers Credit EVs (yahoo.com) 164

An anonymous reader shared this report from the Los Angeles Times: A network of air monitors installed in Northern California has provided scientists with some of the first measurable evidence quantifying how much electric vehicles are shrinking the carbon footprint of a large urban area. Researchers from UC Berkeley set up dozens of sensors across the Bay Area to monitor planet-warming carbon dioxide, the super-abundant greenhouse gas produced when fossil fuels are burned. Between 2018 and 2022, the region's carbon emissions fell by 1.8% each year, which the Berkeley researchers concluded was almost exclusively owed to drivers switching to electric vehicles, according to a study published in the journal Environmental Science & Technology.

In that time, Californians purchased about 719,500 zero-emission or plug-in hybrid vehicles, more than triple the amount compared to the previous five years, according to the California Department of Energy. The Bay Area also had a higher rate of electric vehicle adoption than the state as a whole.

While the findings confirm the state's transition to zero-emission vehicles is substantially lowering carbon emissions, it also reveals these reductions are still not on pace to meet the state's ambitious climate goals. Emissions need to be cut by around 3.7% annually, or nearly twice the rate observed by the monitors, according to Ronald Cohen, UC Berkeley professor of chemistry. Although cars and trucks are the state's largest source of carbon emissions, it underscores the need to deploy zero-emission technology inside homes and for the power grid.

"I think what we see right now is evidence of strong success in the transportation sector," Cohen said. "We're going to need equally strong success in home and commercial heating, and in the [industrial] sources. We don't yet see significant movement in those, but policy pushing on those is not as far ahead as policy on electric vehicles." Although cities only cover roughly 3% of global surface area, they produce about 70% of carbon emissions.

Slashdot Top Deals