The Military

Before Chinese Spy Balloon, Classified US Report Highlighted Foreign Aerial Spying (msn.com) 79

That Chinese spy balloon floating over the continental U.S. "generated deep concern," reports the New York Times — "in part because it came on the heels of a classified report to Congress that outlined incidents of American adversaries potentially using advanced technology to spy on the country.

"The classified report to Congress last month discussed at least two incidents of a rival power conducting aerial surveillance with what appeared to be unknown cutting-edge technology, according to U.S. officials." While the report did not attribute the incidents to any country, two American officials familiar with the research said the surveillance probably was conducted by China.

The report on what the intelligence agencies call unidentified aerial phenomena focused on several incidents believed to be surveillance. Some of those incidents have involved balloons, while others have involved quadcopter drones.... U.S. defense officials believe China is conducting surveillance of military training grounds and exercises as part of an effort to better understand how America trains its pilots and undertakes complex military operations. The sites where unusual surveillance has occurred include a military base in the United States and a base overseas, officials said. The classified report mentioned Naval Air Station Fallon in Nevada and Marine Corps Air Station Iwakuni in Japan as sites where foreign surveillance was believed to have occurred, but did not explicitly say China had been behind the actions, a U.S. official said.

Since 2021, the Pentagon has examined 366 incidents that were initially unexplained and said 163 were balloons. A handful of those incidents involved advanced surveillance balloons, according to a U.S. official, but none of them were conducting persistent reconnaissance of the U.S. military bases. (However, spy balloons that the U.S. government immediately identifies are not included in the unidentified aerial phenomenon tracking, according to two U.S. officials.) Because spy balloons are relatively basic collection devices and other balloons have not lingered long over U.S. territory, they previously have not generated much concern with the Pentagon or intelligence agencies, according to two officials.

The surveillance incidents involving advanced technology and described in the classified report were potentially more troubling, involving behaviors and characteristics that could not be explained. Officials said that further investigation was needed but that the incidents could potentially indicate the use of technology that was not fully understood or publicly identified. Of the 171 reports that have not been attributed to balloons, drones or airborne trash, some "appear to have demonstrated unusual flight characteristics or performance capabilities, and require further analysis."

The Internet

79-Year-Old Vint Cerf Receives IEEE Medal of Honor (circleid.com) 21

Long-time Slashdot reader penciling_in shared this special report from CircleID: Vinton Cerf, widely known as the 'Father of the Internet,' has been awarded the IEEE Medal of Honor in 2023 for his contributions to the development of the Internet architecture and for his leadership in its growth as a critical infrastructure for society.

In 1974, Robert Kahn and Cerf, who was working as program manager at the U.S. Defense Advanced Research Projects Agency (DARPA) Information Processing Techniques Office, jointly designed the Transmission Control Protocol and the Internet Protocol. Together they make up the Internet's core architecture and enable computers to connect and exchange traffic....

Since 2005, Cerf has been vice president and chief Internet evangelist at Google in Reston, Va., promoting the usage of the Internet for the benefit of the public. Cerf is also in charge of locating new technologies and creating policies that assist the production of Internet-based products and services.

IEEE Spectrum shares this quote from one of the endorsers of the award. "Cerf's tireless commitment to the Internet's evolution, improvement, oversight, and evangelism throughout its history has made an indelible impact on the world. It is largely due to his efforts that we even have the Internet, which has changed the way society lives.
Chrome

Google Is Working On Blink-Based iOS Browser, Contrary To Apple's WebKit Rule (theregister.com) 73

Longtime Slashdot reader Dotnaught writes: "Google's Chromium developers have begun work on an experimental web browser for Apple's iOS using the search giant's Blink engine," reports The Register. "That's unexpected because the current version of Chrome for iOS uses Apple's WebKit rendering engine under the hood. Apple requires every iOS browser to use WebKit and its iOS App Store Review Guidelines state, 'Apps that browse the web must use the appropriate WebKit framework and WebKit Javascript.'"

Google insists this is an experiment and isn't intended for release. But the stripped-down, Blink-based browser could be preparation for European competition rules that look like they will require Apple to stop requiring that other browser makers use its WebKit engine.
"This is an experimental prototype that we are developing as part of an open source project with the goal to understand certain aspects of performance on iOS," said a Google spokesperson. "It will not be available to users and we'll continue to abide by Apple's policies."
Privacy

Dashlane Publishes Its Source Code To GitHub In Transparency Push (techcrunch.com) 8

Password management company Dashlane has made its mobile app code available on GitHub for public perusal, a first step it says in a broader push to make its platform more transparent. TechCrunch reports: The Dashlane Android app code is available now alongside the iOS incarnation, though it also appears to include the codebase for its Apple Watch and Mac apps even though Dashlane hasn't specifically announced that. The company said that it eventually plans to make the code for its web extension available on GitHub too. Initially, Dashlane said that it was planning to make its codebase "fully open source," but in response to a handful of questions posed by TechCrunch, it appears that won't in fact be the case.

At first, the code will be open for auditing purposes only, but in the future it may start accepting contributions too --" however, there is no suggestion that it will go all-in and allow the public to fork or otherwise re-use the code in their own applications. Dashlane has released the code under a Creative Commons Attribution-NonCommercial 4.0 license, which technically means that users are allowed to copy, share and build upon the codebase so long as it's for non-commercial purposes. However, the company said that it has stripped out some key elements from its release, effectively hamstringing what third-party developers are able to do with the code. [...]

"The main benefit of making this code public is that anyone can audit the code and understand how we build the Dashlane mobile application," the company wrote. "Customers and the curious can also explore the algorithms and logic behind password management software in general. In addition, business customers, or those who may be interested, can better meet compliance requirements by being able to review our code." On top of that, the company says that a benefit of releasing its code is to perhaps draw-in technical talent, who can inspect the code prior to an interview and perhaps share some ideas on how things could be improved. Moreover, so-called "white-hat hackers" will now be better equipped to earn bug bounties. "Transparency and trust are part of our company values, and we strive to reflect those values in everything we do," Dashlane continued. "We hope that being transparent about our code base will increase the trust customers have in our product."

Google

Think Twice Before Using Google To Download Software, Researchers Warn (arstechnica.com) 54

Searching Google for downloads of popular software has always come with risks, but over the past few months, it has been downright dangerous, according to researchers and a pseudorandom collection of queries. Ars Technica reports: "Threat researchers are used to seeing a moderate flow of malvertising via Google Ads," volunteers at Spamhaus wrote on Thursday. "However, over the past few days, researchers have witnessed a massive spike affecting numerous famous brands, with multiple malware being utilized. This is not "the norm.'"

The surge is coming from numerous malware families, including AuroraStealer, IcedID, Meta Stealer, RedLine Stealer, Vidar, Formbook, and XLoader. In the past, these families typically relied on phishing and malicious spam that attached Microsoft Word documents with booby-trapped macros. Over the past month, Google Ads has become the go-to place for criminals to spread their malicious wares that are disguised as legitimate downloads by impersonating brands such as Adobe Reader, Gimp, Microsoft Teams, OBS, Slack, Tor, and Thunderbird.

On the same day that Spamhaus published its report, researchers from security firm Sentinel One documented an advanced Google malvertising campaign pushing multiple malicious loaders implemented in .NET. Sentinel One has dubbed these loaders MalVirt. At the moment, the MalVirt loaders are being used to distribute malware most commonly known as XLoader, available for both Windows and macOS. XLoader is a successor to malware also known as Formbook. Threat actors use XLoader to steal contacts' data and other sensitive information from infected devices. The MalVirt loaders use obfuscated virtualization to evade end-point protection and analysis. To disguise real C2 traffic and evade network detections, MalVirt beacons to decoy command and control servers hosted at providers including Azure, Tucows, Choopa, and Namecheap.
"Until Google devises new defenses, the decoy domains and other obfuscation techniques remain an effective way to conceal the true control servers used in the rampant MalVirt and other malvertising campaigns," concludes Ars. "It's clear at the moment that malvertisers have gained the upper hand over Google's considerable might."
Businesses

Meta Soars by Most in Decade, Adding $100 Billion in Value (nytimes.com) 12

Meta's stock surged on Thursday after the company reported better-than-expected earnings, said it would buy back billions of dollars in its stock, and overcame a court challenge to its ambitions in the so-called metaverse. The New York Times reports: Shares of the tech giant, the owner of Facebook, Instagram and WhatsApp, climbed more than 23 percent, its biggest daily gain in nearly 10 years. And it was a huge move for a company its size, adding nearly $100 billion in market value in a single day, or about as much as Citigroup's entire market capitalization.

After ending last year with a loss of more than 60 percent, Meta's stock is up more than 50 percent this year, as the mood among tech investors has brightened. The Nasdaq Composite, an index that includes many tech companies, including Meta, has risen nearly 20 percent this year.
The report notes that plenty of challenges remain for the company. "Meta faces setbacks in digital advertising as clients rein in spending because of higher interest rates and inflation," reports The New York Times. "The company is also fighting to retain users drawn to newer apps like TikTok, the short-form video app that Mr. Zuckerberg considers one of his most formidable rivals. The billions that Meta is spending pursuing its founder's vision of the metaverse may not pay off."

In November, Meta laid off more than 11,000 employees in what was the most significant job cuts since its founding in 2004.
Social Networks

Wikipedia Blocked in Pakistan Over 'Sacrilegious' Content (bloomberg.com) 112

Pakistan has blocked Wikipedia services in the South Asian nation after the platform failed to remove "sacrilegious" content. From a report: The action was taken because some of the content is still available on Wikipedia after the expiry of a 48-hour deadline, Malahat Obaid, spokesperson for Pakistan Telecommunication Authority, said by phone.
AI

Google To Unveil Its ChatGPT Rival Next Week (arstechnica.com) 47

Next week Google is hosting what can only be described as an "emergency" event. From a report: According to an invite sent to The Verge, the event will revolve around "using the power of AI to reimagine how people search for, explore and interact with information, making it more natural and intuitive than ever before to find what you need" -- in other words, Google's going to fire up its photocopier and stick OpenAI's ChatGPT onto the platen. The 40 minute event will, of course, be live on YouTube on February 8.

Google's parent company, Alphabet, had its earnings call yesterday, and Google/Alphabet CEO Sundar Pichai promised that "very soon people will be able to interact directly with our newest, most powerful language models as a companion to Search in experimental and innovative ways." Earlier this year the company declared a "code red" over the meteoric rise of ChatGPT and even dragged co-founders Larry Page and Sergey Brin out of retirement to help.

IT

Netflix Says Strict New Password Sharing Rules Were Posted in Error (appleinsider.com) 58

New Netflix rules that would have enforced a limitation on users' sharing passwords are reportedly a mistake and don't apply in the US -- for now. From a report: Netflix has long been planning to cut down on password sharing, or letting friends share one paid account. The company appeared to go further, however, with the inclusion in its help pages of a new set of rules.

Broadly, anyone at a subscriber's physical address could continue using the service. But the paying subscriber would have to confirm every 31 days that a user away from their residence -- such as at college -- was part of the household. According to The Streamable, Netflix says it was all a mistake -- for the United States. "For a brief time yesterday, a help center article containing information that is only applicable to Chile, Costa Rica, and Peru, went live in other countries," a Netflix spokesperson told the publication. "We have since updated it."

Businesses

FTC Prepares Antitrust Suit Against Amazon (wsj.com) 29

The Federal Trade Commission is preparing a potential antitrust lawsuit against Amazon that in the coming months could challenge an array of the tech giant's business practices as anticompetitive, WSJ reported Friday, citing people familiar with the matter. From the report: The timing of any case remains in flux, some of the people said. The commission also could opt not to proceed, and doesn't always bring cases even when it is making preparations to do so. Amazon officials haven't had individual late-stage meetings with each of the FTC commissioners to make their arguments against a legal challenge, those people said.

The commission in recent years has been examining Amazon practices including whether it favors its own products over competitors' on its platforms and how it treats outside sellers on Amazon.com, according to some of the people familiar with the matter. The FTC also has been scrutinizing the company's Amazon Prime subscription service's bundling practices, some of the people said. Exactly which aspects of the business the FTC would target in a potential Amazon lawsuit couldn't be learned. Amazon and the FTC declined to comment.

Google

Google Invests $300 Million in AI Startup Anthropic (ft.com) 7

Google has invested about $300mn in artificial intelligence startup Anthropic, making it the latest tech giant to throw its money and computing power behind a new generation of companies trying to claim a place in the booming field of "generative AI." From the report: The terms of the deal, through which Google will take a stake of around 10 per cent, requires Anthropic to use the money to buy computing resources from the search company's cloud computing division, according to three people familiar with the arrangement. Google's move highlights the influence that a small number of Big Tech companies have assumed over other companies working on AI, which need access to cloud computing platforms to handle the giant AI models developed by groups such as Anthropic. The search company's investment also echoes the $1bn cash-for-computing investment that Microsoft made in OpenAI three years ago.
Communications

ISP Admits Lying To FCC About Size of Network To Block Funding To Rivals (arstechnica.com) 88

Ryan Grewell, who runs a small wireless Internet service provider in Ohio, last month received an email that confirmed some of his worst suspicions about cable companies. From a report: Grewell, founder and general manager of Smart Way Communications, had heard from some of his customers that the Federal Communications Commission's new broadband map falsely claimed fiber Internet service was available at their homes from another company called Jefferson County Cable. Those customer reports spurred Grewell to submit a number of challenges to the FCC in an attempt to correct errors in Smart Way's service area.

One of Grewell's challenges elicited a response from Jefferson County Cable executive Bob Loveridge, who apparently thought Grewell was a resident at the challenged address rather than a competitor. "You challenged that we do not have service at your residence and indeed we don't today," Loveridge wrote in a January 9 email that Grewell shared with Ars. "With our huge investment in upgrading our service to provide xgpon we reported to the BDC [Broadband Data Collection] that we have service at your residence so that they would not allocate addition [sic] broadband expansion money over [the] top of our private investment in our plant."

The email is reminiscent of our November 2022 article about a cable company accidentally telling a rival about its plan to block government grants to competitors. Speaking to Ars in a phone interview, Grewell said, "This cable company happened to just say the quiet part out loud." He called it "a blatant attempt at blocking anyone else from getting funding in an area they intend to serve." It's not clear when Jefferson County Cable plans to serve the area. Program rules do not allow ISPs to claim future coverage in their map submissions. Jefferson County Cable ultimately admitted to the FCC that it filed incorrect data and was required to submit a correction. The challenge that the ISP conceded was for an address on State Route 43 in Bergholz, Ohio. The town is not one of the coverage areas listed on Jefferson County Cable's website.

Software

BMW Owner Discovers Car's Software Update Won't Install When Parked on Incline (thedrive.com) 127

An anonymous reader shares a report: BMW i4 owner was rightfully puzzled when their car flashed a strange alert on the screen, saying its parking spot was "too steep" to perform an over-the-air software upgrade. How does that happen? And why is it a problem in the first place? As Clare Eliza found out, it simply isn't possible to remotely update any of the i4's software if the car isn't parked on flat ground. And instead of allowing the operator to override this, it will wait until you physically move it somewhere more level to continue. As it turns out, BMW doesn't have one singular reason why the vehicle can't perform this task on an incline. Rather, the limitation is there as a safety blanket.

"The vehicle has all sorts of sensors (pitch, yaw, lateral and longitudinal acceleration and deceleration, etc.) that allow it to understand its orientation, so it knows when it's on an incline," a BMW spokesperson told The Drive. "It's likely a catchall, every-worst-case-no-matter-how-unlikely scenario safety precaution to try to prevent any chance of the vehicle moving should the programming be interrupted or go wrong." Essentially, it's there just in case something unexpected happens; it's better to plan for the worst, after all.

The Military

Pentagon Elects Not To Shoot Down Chinese Spy Balloon Traveling Over Montana (washingtonpost.com) 209

"A Chinese spy balloon is floating over the continental United States," writes Slashdot reader q4Fry. "As it headed over Montana, 'civilian flights in the area were halted and U.S. military aircraft, including advanced F-22 fighter jets, were put in the air.'" The Washington Post reports: The balloon's flight path takes it over "a number of sensitive sites," the senior [Pentagon] official said, but it appears it does not have the ability collect information that is "over and above" other tools at China's disposal, like low-orbit satellites. Nevertheless, the Pentagon is taking undisclosed "mitigation steps" to prevent Beijing from gathering additional intelligence.

"We put some things on station in the event that a decision was made to bring this down," the official said. "So we wanted to make sure we were coordinating with civil authorities to empty out the airspace around that potential area. But even with those protective measures taken, it was the judgment of our military commanders that we didn't drive the risk down low enough. So we didn't take the shot."
"The US believes Chinese spy satellites in low Earth orbit are capable of offering similar or better intelligence, limiting the value of whatever Beijing can glean from the high-altitude balloon, which is the size of three buses," reports CNN, citing a defense official.

"It does not create significant value added over and above what the PRC is likely able to collect through things like satellites in low Earth orbit," the senior defense official said. Nevertheless, House Speaker Kevin McCarthy called for a briefing of the "Gang of Eight" -- the group of lawmakers charged with reviewing the nation's most sensitive intelligence information.
Networking

Decentralized Social Media Project Nostr's Damus Gets Listed On Apple App Store (coindesk.com) 24

Nostr, a startup decentralized social network, got its Twitter-like Damus application listed on Apple's App Store. CoinDesk reports: Nostr is an open protocol that aims to create a censorship-resistant global social network. Media commentators have described it as a possible alternative to Elon Musk's Twitter. According to an article in Protos, Nostr is popular with bitcoiners partly because most implementations of it support payments over Bitcoin's Lightning Network.

Former Twitter CEO Jack Dorsey, who last year donated roughly 14 BTC (worth $245,000 at the time) to fund Nostr's development, hailed the debut of Damus on Apple's App Store as a "milestone for open protocols," in a tweet posted late Tuesday. As of press time, the tweet had been viewed 2.1 million times. According to the Nostr website, Damus is one of several Nostr projects, including Anigma, a Telegram-like chat; Nostros, a mobile client; and Jester, a chess application.
You can download the iOS app here.
Facebook

Documents Show Meta Paid For Data Scraping Despite Years of Denouncing It (engadget.com) 11

An anonymous reader quotes a report from Engadget: Meta has routinely fought data scrapers, but it also participated in that practice itself -- if not necessarily for the same reasons. Bloomberg has obtained legal documents from a Meta lawsuit against a former contractor, Bright Data, indicating that the Facebook owner paid its partner to scrape other websites. Meta spokesperson Andy Stone confirmed the relationship in a discussion with Bloomberg, but said his company used Bright Data to build brand profiles, spot "harmful" sites and catch phishing campaigns, not to target competitors.

Stone added that data scraping could serve "legitimate integrity and commercial purposes" so long as it was done legally and honored sites' terms of service. Meta terminated its arrangement with Bright Data after the contractor allegedly violated company terms when gathering and selling data from Facebook and Instagram. Neither Bright Data nor Meta is saying which sites they scraped. Bright Data is countersuing Meta in a bid to keep scraping Facebook and Instagram, arguing that it only collects publicly available information and respects both European Union and US regulations.

Google

Back At Google Again, Cofounder Sergey Brin Just Filed His First Code Request In Years (forbes.com) 14

After years of day-to-day absence, Google cofounder Sergey Brin filed a request for access to code related to the company's natural language chatbot, LaMDA. Forbes reports: Two sources said the request was related to LaMDA, Google's natural language chatbot -- a project initially announced in 2021, but which has recently garnered increased attention as Google tries to fend off rival OpenAI, which released the popular ChatGPT bot in November. Brin filed a "CL," short for "changelist," to gain access to the data that trains LaMDA, one person who saw the request said. It was a two line change to a configuration file to add his username to the code, that person said. Several dozen engineers gave the request LGTM approval, short for "looks good to me." Some of the approvals came from workers outside of that team, seemingly just eager to be able to say they gave code review approval to the company cofounder, that person added.

The move was a small technical change, but underscores how seriously the company is taking the looming threat from OpenAI and other competitors. Brin and cofounder Larry Page have been largely absent from the company since 2019, when Page handed the reins over to Sundar Pichai to become CEO of Google parent Alphabet. But Pichai has recently called in the company founders to review the company's AI strategy and help form a response to ChatGPT, according to the New York Times. Brin's tinkering highlights the level of involvement the cofounders have taken.

EU

EU Lawmakers Launch Tips Hotline To Catch Big Tech's 'Shady' Lobbying (techcrunch.com) 6

An anonymous reader shares a report: 'Astroturfing' and other non-transparent lobbying tactics used to target digital policymakers in the European Union in recent years -- including during a blitz of spending aimed at influencing major new pan-EU rules like the Digital Services Act (DSA) -- have inspired a group of MEPs and NGOs to fight back by launching a hotline for reporting attempts at indirectly influencing the bloc's tech policy agenda. The new tips line, which was first reported by the Guardian, is being called LobbyLeaks.

The office of one of the MEPs co-leading the effort, Paul Tang of the S&D Group, said the idea is to gather data on underhand lobbying efforts that may be targeting the EU's digital policymaking -- such as the use of third party 'industry associations' or consultancies without clear disclosures, or even academics being quietly funded to author favorable research -- in order that they can be studied and called out. They also want to ensure EU lawmakers are better informed about the myriad ways tech giants may be seeking to influence them as they work on shaping the rules platform giants will have to play by.

Google

Google Expands Open Source Bounties, Will Soon Support Javascript Fuzzing Too (zdnet.com) 6

Google has expanded OSS-Fuzz Reward Program to offer rewards of up to $30,000 for researchers who find security flaws in open source programs. From a report: The expanded scope of the program now means the total rewards possible per project integration rise from $20,000 to $30,000. The purpose of OSS-Fuzz is to support open source projects adopt fuzz testing and the new categories of rewards support those who create more ways of integrating new projects.

Google created two new reward categories that reward wider improvements across all OSS-Fuzz projects. It offers up to $11,337 available per category. It's also offering rewards for notable FuzzBench fuzzer integrations, and for integrating new sanitizers or 'bug detectors' that help find vulnerabilities. "We hope to accelerate the integration of critical open source projects into OSS-Fuzz by providing stronger incentives to security researchers and open source maintainers," explains Oliver Chang of Google's OSS-Fuzz team.

Microsoft

Microsoft Will Use OpenAI Tech To Write Emails For Busy Salespeople (bloomberg.com) 56

Microsoft is adding artificial intelligence capabilities from ChatGPT maker OpenAI to another of its products -- this time a customer-relationship app that's meant to help win revenue from Salesforce. From a report: Viva Sales, which connects Microsoft's Office and video conferencing programs with customer relations management software, will be able to generate email replies to clients using OpenAI's product for creating text. The AI tools, which include OpenAI's GPT 3.5 -- the system that is the basis for the ChatGPT chatbot -- will cull data from customer records and Office email software. That information will then be used to generate emails containing personalized text, pricing details and promotions. The Viva Sales app was initially released in October and works with Microsoft's Dynamics customer management program and that of rival Salesforce. It's free for users who sign up for the premium versions of Dynamics and $40 per user per month for Salesforce customers.

Slashdot Top Deals