Robotics

Google Demos Soda-Fetching Robots (reuters.com) 41

Alphabet's Google is combining the eyes and arms of physical robots with the knowledge and conversation skills of virtual chatbots to help its employees fetch soda and chips from breakrooms with ease. From a report: The mechanical waiters, shown in action to reporters last week, embody an artificial intelligence breakthrough that paves the way for multipurpose robots as easy to control as ones that perform single, structured tasks such as vacuuming or standing guard. Google robots are not ready for sale. They perform only a few dozen simple actions, and the company has not yet embedded them with the "OK, Google" summoning feature familiar to consumers.

While Google says it is pursuing development responsibly, adoption could ultimately stall over concerns such as robots becoming surveillance machines, or being equipped with chat technology that can give offensive responses, as Meta Platforms and others have experienced in recent years. Microsoft and Amazon are pursuing comparable research on robots. "It's going to take a while before we can really have a firm grasp on the direct commercial impact," said Vincent Vanhoucke, senior director for Google's robotics research. When asked to help clean a spill, Google's robot recognizes that grabbing a sponge is a doable and more sensible response than apologizing for creating the mess.

Windows

Windows 11's Next Big Update Arrives Next Month With Start Menu Folders, New Gestures (theverge.com) 84

Microsoft is planning to release its next big Windows 11 update, version 22H2, on September 20th. The Verge: Sources familiar with Microsoft's plans tell The Verge Microsoft will roll out Windows 11 22H2 through Windows Update on September 20th, a week after the company's regular Patch Tuesday fixes. Microsoft has been testing Windows 11 22H2 for months, and it will include a number of new improvements, like app folders in the Start menu, drag and drop on the taskbar, and new touch gestures and animations. Microsoft is also adding a new Live Captions accessibility feature with 22H2, which is ideal for people who are deaf, hard of hearing, or anyone who wants to caption audio automatically. Similarly, a new Voice Access tool that allows people to control their PCs by using voice commands is part of 22H2.

The Task Manager is also being overhauled in Windows 11 22H2, with a new dark mode and a far better layout that includes a new command bar and an efficiency mode to limit apps from consuming resources. Snap Layouts will also be greatly improved in 22H2, making it easier to drag and app to reveal all the layouts you can use to arrange apps. Microsoft is also working on tabs for File Explorer, which will arrive a little later than September 20th.

Transportation

American Airlines Agrees To Buy 20 Supersonic Planes from Boom (cnbc.com) 116

American Airlines has agreed to purchase 20 supersonic Overture planes from Boom Supersonic, the companies announced Tuesday. From a report: The deal is the second firm order in the last two years for Boom, still years from building its first commercial airplane. United Airlines made a commitment last year to buy 15 Overture jets. "Passengers want flights that are faster, more convenient, more sustainable and that's what Overture delivers," Boom CEO Blake Scholl told CNBC. "Flight times can be as little as half as what we have today, and that works great in networks like American where we can fly Miami to London in less than five hours." Boom says the Overture jet will fly as fast as Mach 1.7, or 1,304 mph, dramatically cutting trans-Atlantic and trans-Pacific flight times. For example, a flight from Seattle to Tokyo, which typically takes just over 10 hours, could be completed in six hours in an Overture, according to Boom.
Intel

Intel Drops DirectX 9 Support On Xe, Arc GPUs, Switches To DirectX 12 Emulation (tomshardware.com) 45

An anonymous reader quotes a report from Ars Technica: Native DX9 hardware support is officially gone from Intel's Xe integrated graphics solutions on 12th Gen CPUs and A-Series Arc Alchemist discrete GPUs. To replace it, all DirectX 9 support will be transferred to DirectX 12 in the form of emulation. Emulation will run on an open-source conversion layer known as "D3D9On12" from Microsoft. Conversion works by sending 3D DirectX 9 graphics commands to the D3D9On12 layer instead of the D3D9 graphics driver directly. Once the D3D9On12 layer receives commands from the D3D9 API, it will convert all commands into D3D12 API calls. So basically, D3D9On12 will act as a GPU driver all on its own instead of the actual GPU driver from Intel. Microsoft says this emulation process has become a relatively performant implementation of DirectX 9. As a result, performance should be nearly as good, if not just as good, as native DirectX 9 hardware support.
Operating Systems

Linux 6.0 Arrives With Performance Improvements and More Rust Coming (zdnet.com) 24

Linux creator Linus Torvalds has announced the first release candidate for the Linux kernel version 6.0, but he says the major number change doesn't signify anything especially different about this release. ZDNet: While there is nothing fundamentally different about this release compared with 5.19, Torvalds noted that there were over 13,500 non-merge commits and over 800 merged commits, meaning "6.0 looks to be another fairly sizable release." According to Torvalds, most of the updates are improvements to the GPU, networking and sound. Torvalds stuck to his word after releasing Linux kernel 5.19 last month, when he flagged he would likely call the next release 6.0 because he's "starting to worry about getting confused by big numbers again."

On Sunday's release of Linux 6.0 release candidate version 1 (rc-1), he explained his reasoning behind choosing a new major version number and its purpose for developers. Again, it's about avoiding confusion rather than signaling that the release has major new features. His threshold for changing the lead version number was .20 because it is difficult to remember incremental version numbers beyond that. "Despite the major number change, there's nothing fundamentally different about this release - I've long eschewed the notion that major numbers are meaningful, and the only reason for a 'hierarchical; numbering system is to make the numbers easier to remember and distinguish," said Torvalds.
Torvalds lamented some Rust-enabling code didn't make it into the release. The Register adds: "I actually was hoping that we'd get some of the first rust infrastructure, and the multi-gen LRU VM, but neither of them happened this time around," he mused, before observing "There's always more releases. This is one of those releases where you should not look at the diffstat too closely, because more than half of it is yet another AMD GPU register dump," he added, noting that Intel's Gaudi2 Ai processors are also likely to produce plenty of similar kernel additions. "The CPU people also show up in the JSON files that describe the perf events, but they look absolutely tiny compared to the 'asic_reg' auto-generated GPU and AI hardware definitions," he added.
Android

Google Releases Android 13, Rolling Out First To Pixel Phones (theverge.com) 23

This year's major Android update, Android 13, is officially releasing today for Google's Pixel phones, the search giant has announced. From a report: The annual update is getting an official release a little earlier than usual, following Android 12's release last October and Android 11's release in September 2020. The list of updates arriving with this year's version of Android is likely to be familiar if you've been keeping up with Android 13's beta releases. There's the ability to customize non-Google app icons to match your homescreen wallpaper that we saw in Android 13's first developer preview, a new permission to cut down on notification spam, and a new option to limit which of your photos and videos an app can access.

Back in January, we wrote that Google planned to spend this year catching up with Apple's ecosystem integrations, and there's more evidence of this in Android 13's official release. The update includes support for spatial audio with head tracking, which is designed to make sounds appear as though they're coming from a fixed point in space when you move your head while wearing compatible headphones, similar to a feature Apple offers for its AirPods. Today's post doesn't say exactly which headphones this will work with, but Google previously announced it would be updating its Pixel Buds Pro to offer support for spatial audio. Secondly, there's the ability to stream messages from apps including Google Messages directly to a Chromebook, similar to iMessage on the Mac.

The Internet

Faster Internet Is Coming To America - as Soon as the Government Knows Where To Build It (wsj.com) 48

The government's $42.5 billion plan to expand internet service to underserved communities is stuck in a holding pattern nearly nine months after approval, largely because authorities still don't know where gaps need to be filled. From a report: The broadband plan, part of the $1 trillion infrastructure bill signed by President Biden last November, stipulates that money to improve service can't be doled out until the Federal Communications Commission completes new maps showing where homes and businesses lack fast service. Lawmakers demanded new maps after flawed data in past subsidy programs caused construction projects across the country to bypass many of the Americans that they were supposed to serve. Officials warn, however, that getting the mapping right will take time.

"We understand the urgency of getting broadband out there to everyone quickly," said Alan Davidson, chief of the Department of Commerce office in charge of allocating the broadband funding. "We also know that we get one shot at this and we want to make sure we do it right." That could mean a delay in the expansion of service to people who have long struggled with slow internet. Internet providers including AT&T, Charter Communications, Comcast and Verizon have yet to include any of the 2021 infrastructure law's broadband funding in their public financial projections for the coming years. "The maps are not going to be issued from the FCC until a little bit later this year, and until that happens, the money really can't start to flow at the state level," AT&T Chief Executive John Stankey told analysts on a July conference call.

Facebook

Gen Z is Over Facebook, Finds Pew Research. But YouTube Dominates Among Teens (nbcnews.com) 57

NBC News reports: Facebook, once the go-to social media platform for many, has plummeted in popularity among younger users, according to a new Pew Research Center survey.... The share of 13- to 17-year-olds who said they use Facebook dropped from 71% in the 2015 study to 32% today, Pew found.

As Facebook's popularity sinks, YouTube has become the dominating platform among teens, who are also using social media apps like TikTok, Snapchat and [Meta-owned] Instagram... While Facebook still beats out Twitter among Gen Z teens, Snapchat and Instagram have dwarfed its popularity. Sixty-two percent of teens use Instagram and 59% use Snapchat, according to Pew. TikTok also beats Facebook in popularity, with 67% of respondents saying they use the short-form video app, Pew reported....

The most popular platform among 13- to 17-year-olds is YouTube, which is used by 95% of teens, the research found.

There's an interesting graph showing trends in Pew's announcement. It's handy way to visualize that over the last seven years usage has dropped for Facebook, Twitter, and Tumbler — while usage increased for Instagram and Snapchat.

But YouTube hovers above them all with 95% usage.
Transportation

California Startup Sells 'Subscriptions' to Electric Vehicles (bnnbloomberg.ca) 121

In January a California startup named Autonomy began "stocking up on EVs from pretty much every company that makes them," reports Bloomberg (including Tesla, Ford, and Polestar). Their plan? Collect a $5,900 "start fee," then charge $490 to $690 a month for an electric vehicle subscription with up to 1,000 miles of driving (but with no maintenance or registration fees): The subscription model has some logic for consumers. In part because of fast-evolving technology, EVs have traditionally shed value much quicker than gas-powered cars. On a depreciation scale, consumers typically lump them in with cell phones.... But EV ownership is also looking better by the day. The depreciation curve is flattening thanks to longer-range machines, and car companies are getting more vocal about things like battery longevity. A three-year-old Chevrolet Bolt, for example, will recoup 84% of its value today, in line with the average resale of all three-year-old cars in North America, according to CarEdge.com, a consumer-facing market research platform.

That could be why auto executives are pushing to round up that sweet, sweet software revenue in smaller chunks. BMW, to much outcry, is selling an $18-a-month subscription for heated seats in the UK, and General Motors turned its OnStar voice navigation into a $1,500 "mandatory" subscription on every new Buick, GMC and Cadillac Escalade. Even without a la carte add-ons, one of the major forces propping up prices for used EVs is, ironically, their ability to update remotely — the same technology carmakers are using to nickel-and-dime drivers with subscription services.

A contemporary car is nothing if not a dense stack of software, which means subscriptions on wheels are not entirely bonkers. But a car is also an appliance, and consumers aren't accustomed to renting a refrigerator, let alone paying a monthly fee to use the ice-maker. Luckily for Autonomy, the simplest pitch may be the best one. If it can bigfoot individual EV orders by jumping to the head of the queue, the startup could find scads of subscribers — simply because it will have available cars.

The Military

Parts of Europe's Largest Nuclear Plant 'Knocked Out' By Russia-Ukraine Fighting (cnn.com) 202

On Thursday the International Atomic Energy Agency's director "warned that parts of the Zaporizhzhia nuclear plant had been knocked out due to recent attacks, risking an 'unacceptable' potential radiation leak," according to CNN: "IAEA experts believe that there is no immediate threat to nuclear safety," but "that could change at any moment," Grossi said.... Ukraine's nuclear agency Energoatom said 10 shells landed near the complex on Thursday, preventing a shift handover. "For the safety of nuclear workers, the buses with the personnel of the next shift were turned back to Enerhodar," the agency said. "Until the situation finally normalizes, the workers of the previous shift will continue to work."

Energoatom said radiation levels at the site remained normal, despite renewed attacks.

Several Western and Ukrainian officials believe that Russia is using the giant nuclear facility as a stronghold to shield their troops and mount attacks, because they assume Kyiv will not return fire and risk a crisis.

Later CNN added: Ukraine and Russia again traded blame after more shelling around the plant overnight on Thursday, just hours after the United Nations called on both sides to cease military activities near the power station, warning of the worst if they didn't.

"Regrettably, instead of de-escalation, over the past several days there have been reports of further deeply worrying incidents that could, if they continue, lead to disaster," UN secretary general, António Guterres, said in a statement....

Energoatom, Ukraine's state-run nuclear power company, accused Russian forces on Thursday of targeting a storage area for "radiation sources," and shelling a fire department nearby the plant. A day later, the company said in a statement on its Telegram account that the plant was operating "with the risk of violating radiation and fire safety standards."

Ukraine's Interior Minister, Denys Monastyrskyi, said Friday that there was "no adequate control" over the plant, and Ukrainian specialists who remained there were not allowed access to some areas where they should be.... Last weekend, shellfire damaged a dry storage facility — where casks of spent nuclear fuel are kept at the plant — as well as radiation monitoring detectors, making detection of any potential leak impossible, according to Energoatom. Attacks also damaged a high-voltage power line and forced one of the plant's reactors to stop operating.

Tonight the BBC reported on a response from Ukraine's president. In his nightly address on Saturday, Volodymyr Zelensky said any soldier firing on or from the plant would become "a special target" for Ukraine. He also accused Moscow of turning the plant into a Russian army base and using it as "nuclear blackmail"...

Zelenskiy added that "every day" of Russia's occupation of the plant "increases the radiation threat to Europe"....

A BBC investigation revealed earlier this week that many of the Ukrainian workers at the site are being kept under armed guard amid harsh conditions.

UPDATE (8/14): "Ukraine's military intelligence agency said that on Saturday, Russian artillery fire hit a pump, damaged a fire station and sparked fires near the plant that could not be immediately extinguished because of the damage to the fire station," reports the New York Times: Engineers say that yard-thick reinforced concrete containment structures protect the reactors from even direct hits. International concern, however, has grown that shelling could spark a fire or cause other damage that would lead to a nuclear accident.

The six pressurized water reactors at the complex retain most sources of radiation, reducing risks. After pressurized water reactors failed at the Fukushima nuclear complex in Japan in 2011, Ukraine upgraded the Zaporizhzhia site to enable a shutdown even after the loss of cooling water from outside the containment structures, Dmytro Gortenko, a former plant engineer, said in an interview....

"Locals are abandoning the town," said the former engineer, who asked to be identified by only his first name, Oleksiy, because of security concerns. Residents had been leaving for weeks, but the pace picked up after Saturday's barrages and fires, he said.

Canada

Why Alphabet's 'Smart City' in Toronto Failed (technologyreview.com) 111

Alphabet's "urban innovation" arm Sidewalk Labs planned to build a model "smart city" along a 12-acre patch of Toronto waterfront known as Quayside.

But they abandoned the project in 2020, points out MIT's Technology Review, "at the tail end of years of public controversy over its $900 million vision for a data-rich city within the city."

Sidewalk's big idea was flashy new tech. This unassuming section of Toronto was going to become a hub for an optimized urban experience featuring robo-taxis, heated sidewalks, autonomous garbage collection, and an extensive digital layer to monitor everything from street crossings to park bench usage. Had it succeeded, Quayside could have been a proof of concept, establishing a new development model for cities everywhere. It could have demonstrated that the sensor-Âladen smart city model embraced in China and the Persian Gulf has a place in more democratic societies. Instead, Sidewalk Labs' two-and-a-half-year struggle to build a neighborhood "from the internet up" failed to make the case for why anyone might want to live in it....

The project's tech-first approach antagonized many; its seeming lack of seriousness about the privacy concerns of Torontonians was likely the main cause of its demise. There is far less tolerance in Canada than in the U.S. for private-sector control of public streets and transportation, or for companies' collecting data on the routine activities of people living their lives. "In the U.S. it's life, liberty, and the pursuit of happiness," says Alex Ryan, a senior vice president of partnership solutions for the MaRS Discovery District, a Toronto nonprofit founded by a consortium of public and private funders and billed as North America's largest urban innovation hub. "In Canada it's peace, order, and good government. Canadians don't expect the private sector to come in and save us from government, because we have high trust in government."

With its very top-down approach, Sidewalk failed to comprehend Toronto's civic culture. Almost every person I spoke with about the project used the word "hubris" or "arrogance" to describe the company's attitude. Some people used both.

In February Toronto announced new plans for the area, the article points out, with "800 affordable apartments, a two-acre forest, a rooftop farm, a new arts venue focused on indigenous culture, and a pledge to be zero-carbon.... Indeed, the philosophical shift signaled by the new plan, with its emphasis on wind and rain and birds and bees rather than data and more data, seems like a pragmatic response to the demands of the present moment and the near future."

The article calls it "a conspicuous disavowal not only of the 2017 proposal but of the smart city concept itself."
Bug

Google's New Bug Bounties Include Their Custom Linux Kernel's Experimental Security Mitigations (theregister.com) 5

Google uses Linux "in almost everything," according to the leader of Google's "product security response" team — including Chromebooks, Android smartphones, and even Google Cloud.

"Because of this, we have heavily invested in Linux's security — and today, we're announcing how we're building on those investments and increasing our rewards." In 2020, we launched an open-source Kubernetes-based Capture-the-Flag (CTF) project called, kCTF. The kCTF Vulnerability Rewards Program lets researchers connect to our Google Kubernetes Engine (GKE) instances, and if they can hack it, they get a flag, and are potentially rewarded.

All of GKE and its dependencies are in scope, but every flag caught so far has been a container breakout through a Linux kernel vulnerability.

We've learned that finding and exploiting heap memory corruption vulnerabilities in the Linux kernel could be made a lot harder. Unfortunately, security mitigations are often hard to quantify, however, we think we've found a way to do so concretely going forward....

First, we are indefinitely extending the increased reward amounts we announced earlier this year, meaning we'll continue to pay $20,000 — $91,337 USD for vulnerabilities on our lab kCTF deployment to reward the important work being done to understand and improve kernel security. This is in addition to our existing patch rewards for proactive security improvements.

Second, we're launching new instances with additional rewards to evaluate the latest Linux kernel stable image as well as new experimental mitigations in a custom kernel we've built. Rather than simply learning about the current state of the stable kernels, the new instances will be used to ask the community to help us evaluate the value of both our latest and more experimental security mitigations. Today, we are starting with a set of mitigations we believe will make most of the vulnerabilities (9/10 vulns and 10/13 exploits) we received this past year more difficult to exploit. For new exploits of vulnerabilities submitted which also compromise the latest Linux kernel, we will pay an additional $21,000 USD. For those which compromise our custom Linux kernel with our experimental mitigations, the reward will be another $21,000 USD (if they are clearly bypassing the mitigations we are testing). This brings the total rewards up to a maximum of $133,337 USD.

We hope this will allow us to learn more about how hard (or easy) it is to bypass our experimental mitigations.....

With the kCTF VRP program, we are building a pipeline to analyze, experiment, measure and build security mitigations to make the Linux kernel as safe as we can with the help of the security community. We hope that, over time, we will be able to make security mitigations that make exploitation of Linux kernel vulnerabilities as hard as possible.

"We don't care about vulnerabilities; we care about exploits," Vela told the Register. "We expect the vulnerabilities are there, they will get patched, and that's nice and all. But the whole idea is what do to beyond just patching a couple of vulnerabilities." In total, Google paid out $8.7 million in rewards to almost 700 researchers across its various VPRs last year. "We are just one actor in the whole community that happens to have economic resources, financial resources, but we need the community to help us make the Kernel better," Vela said.

"If the community is engaged and helps us validate the mitigations that we have, then, we will continue growing on top of that. But the whole idea is that we need to see where the community wants us to go with this...."

[I]t's not always about the cash payout, according to Vela, and different bug hunters have different motivations. Some want money, some want fame and some just want to solve an interesting problem, Vela said. "We are trying to find the right combination to captivate people."

Facebook

Facing Privacy Concerns, Facebook Begins Testing End-to-End Encrypted Chats, Secure Backups (cnbc.com) 19

Thursday Meta published a blog post by their "product management director of Messenger Trust," who emphasized that they've begun at least testing end-to-end encryption by default for Messenger chats. But Meta also announced plans "to test a new secure storage feature for backups of your end-to-end encrypted chats on Messenger...."

"As with end-to-end encrypted chats, secure storage means that we won't have access to your messages, unless you choose to report them to us."

CNBC provides some context: The announcement comes after Facebook turned over Messenger chat histories to Nebraska police as part of an investigation into an alleged illegal abortion. Meta spokesperson Andy Stone said the feature has been in the works for a while and is not related to the Nebraska case...

The feature is rolling out on Android and iOS devices this week, but it isn't yet available on the Messenger website. The company has been discussing full-scale deployment of end-to-end encryption since 2016, but critics have said the security measure would make it much more difficult for law enforcement to catch child predators....Meta said in the release that it is making progress toward the global rollout of default end-to-end encryption for personal messages and calls in 2023.

Other privacy enhancements announced Thursday by Meta:
  • "We plan to bring end-to-end encrypted calls to the Calls Tab on Messenger."
  • Meta announced that the deleting of messages will start syncing across your other devices "soon."
  • Messenger will continue offering the option of "Disappearing" messages, in which viewed messages in an end-to-end encrypted chat automatically then disappear after a pre-specified period of time.

And there's more, according to Meta's announcement:.

"This week, we'll begin testing default end-to-end encrypted chats between some people. If you're in the test group, some of your most frequent chats may be automatically end-to-end encrypted, which means you won't have to opt in to the feature. You'll still have access to your message history, but any new messages or calls with that person will be end-to-end encrypted. You can still report messages to us if you think they violate our policies, and we'll review them and take action as necessary....

"Last year, we started a limited test of opt-in end-to-end encrypted messages and calls on Instagram, and in February we broadened the test to include adults in Ukraine and Russia. Soon, we'll expand the test even further to include people in more countries and add more features like group chats....

"We will continue to provide updates as we make progress toward the global rollout of default end-to-end encryption for personal messages and calls in 2023."


Communications

The Hacking of Starlink Terminals Has Begun (wired.com) 48

AmiMoJo shares a report from Wired: Since 2018, ELON Musk's Starlink has launched more than 3,000 small satellites into orbit. This satellite network beams internet connections to hard-to-reach locations on Earth and has been a vital source of connectivity during Russia's war in Ukraine. Thousands more satellites are planned for launch as the industry booms. Now, like any emerging technology, those satellite components are being hacked. Today, Lennert Wouters, a security researcher at the Belgian university KU Leuven, will reveal one of the first security breakdowns of Starlink's user terminals, the satellite dishes (dubbed Dishy McFlatface) that are positioned on people's homes and buildings. At the Black Hat security conference in Las Vegas, Wouters will detail how a series of hardware vulnerabilities allow attackers to access the Starlink system and run custom code on the devices.

To access the satellite dish's software, Wouters physically stripped down a dish he purchased and created a custom hacking tool that can be attached to the Starlink dish. The hacking tool, a custom circuit board known as a modchip, uses off-the-shelf parts that cost around $25. Once attached to the Starlink dish, the homemade printed circuit board (PCB) is able to launch a fault injection attack -- temporarily shorting the system -- to help bypass Starlink's security protections. This 'glitch' allows Wouters to get into previously locked parts of the Starlink system. The researcher notified Starlink of the flaws last year and the company paid Wouters through its bug bounty scheme for identifying the vulnerabilities. Wouters says that while SpaceX has issued an update to make the attack harder (he changed the modchip in response), the underlying issue can't be fixed unless the company creates a new version of the main chip. All existing user terminals are vulnerable, Wouters says.
Wouters is making his hacking tool open source on GitHub. Following his presentation, Starlink says it plans to release a "public update" to address the issue but additional details were not shared.
Windows

Microsoft Urges Windows Users To Run Patch For DogWalk Zero-Day Exploit (computerworld.com) 15

joshuark shares a report from Computerworld: Despite previously claiming the DogWalk vulnerability did not constitute a security issue, Microsoft has now released a patch to stop attackers from actively exploiting the vulnerability. [...] The vulnerability, known as CVE-2022-34713 or DogWalk, allows attackers to exploit a weakness in the Windows Microsoft Support Diagnostic Tool (MSDT). By using social engineering or phishing, attackers can trick users into visiting a fake website or opening a malicious document or file and ultimately gain remote code execution on compromised systems. DogWalk affects all Windows versions under support, including the latest client and server releases, Windows 11 and Windows Server 2022.

The vulnerability was first reported in January 2020 but at the time, Microsoft said it didn't consider the exploit to be a security issue. This is the second time in recent months that Microsoft has been forced to change its position on a known exploit, having initially rejected reports that another Windows MSDT zero-day, known as Follina, posed a security threat. A patch for that exploit was released in June's Patch Tuesday update.

Operating Systems

NetBSD 9.3: A 2022 OS That Can Run On Late-1980s Hardware (theregister.com) 41

Version 9.3 of NetBSD is here, able to run on very low-end systems and with that authentic early-1990s experience. The Register reports: Version 9.3 comes some 15 months after NetBSD 9.2 and boasts new and updated drivers, improved hardware support, including for some recent AMD and Intel processors, and better handling of suspend and resume. The next sentence in the release announcement, though, might give some readers pause: "Support for wsfb-based X11 servers on the Commodore Amiga." This is your clue that we are in a rather different territory from run-of-the-mill PC operating systems here. A notable improvement in NetBSD 9.3 is being able to run a graphical desktop on an Amiga. This is a 2022 operating system that can run on late-1980s hardware, and there are not many of those around.

NetBSD supports eight "tier I" architectures: 32-bit and 64-bit x86 and Arm, plus MIPS, PowerPC, Sun UltraSPARC, and the Xen hypervisor. Alongside those, there are no less than 49 "tier II" supported architectures, which are not as complete and not everything works -- although almost all of them are on version 9.3 except for the version for original Acorn computers with 32-bit Arm CPUs, which is still only on NetBSD 8.1. There's also a "tier III" for ports which are on "life support" so there may be a risk Archimedes support could drop to that. This is an OS that can run on 680x0 hardware, DEC VAX minicomputers and workstations, and Sun 2, 3, and 32-bit SPARC boxes. In other words, it reaches back as far as some 1970s hardware. Let this govern your expectations. For instance, in VirtualBox, if you tell it you want to create a NetBSD guest, it disables SMP support.

Transportation

Baidu Has China's First Permits For Fully Driverless Robotaxi Services (newatlas.com) 32

China's first fully autonomous, commercial robotaxi rides -- with no safety drivers -- are about to open for public passengers in Wuhan and Chongqing, marking an inflection point for one of the key technological revolutions of the 21st century. New Atlas reports: The two newly-issued permits allow Baidu to charge for driverless rides within a 13-sq-km (5-sq-mi) area in Wuhan, between 9 am and 5 pm, and within a larger 30-sq-km (11.6-sq-mi) zone in Chonqing's Yongchuan district between 9.30 am and 5.30 pm -- so while they're currently set to avoid peak hours, they'll be mixing it up with plenty of daytime traffic. Each zone will run five 5th-generation Apollo cars, with remote drivers ready to assume control if the vehicles get themselves into any sticky situations. Home base will be watching closely through the cars' camera systems, particularly in these early days.

Baidu's Apollo Go is already the world's biggest robotaxi company, with operations already live in all tier-one Chinese cities using the same 5th-gen car, with backup drivers on board. The company recently revealed its 6th-gen design, its first ground-up fully autonomous car for mass production. The Apollo RT6 will cost just RMB 250,000 (US$37,000) to manufacture, says Baidu, and its optional, removable steering wheel and generous, configurable cabin space will make it one of the first proper mobility pod-type services when it hits the streets commercially in 2023.

Encryption

Facebook Will Begin Testing End-To-End Encryption As Default On Messenger App (theguardian.com) 13

Facebook announced on Thursday it will begin testing end-to-end encryption as the default option for some users of its Messenger app on Android and iOS. The Guardian reports: Facebook messenger users currently have to opt in to make their messages end-to-end encrypted (E2E), a mechanism that theoretically allows only the sender and recipient of a message to access its content. Facebook spokesperson Alex Dziedzan said on Thursday that E2E encryption is a complex feature to implement and that the test is limited to a couple of hundred users for now so that the company can ensure the system is working properly. Dziedzan also said the move was "not a response to any law enforcement requests." Meta, Facebook's parent company, said it had planned to roll out the test for months. The company had previously announced plans to make E2E encryption the default in 2022 but pushed the date back to 2023. "The only way for companies like Facebook to meaningfully protect people is for them to ensure that they do not have access to user data or communications when a law enforcement agency comes knocking," Evan Greer, the director of the digital rights group Fight for the Future, said. "Expanding end-to-end encryption by default is a part of that, but companies like Facebook also need to stop collecting and retaining so much intimate information about us in the first place."
Cellphones

'Samsung Still Hasn't Given Us a Good Reason To Buy a Foldable Phone' (theverge.com) 73

Earlier this week, Samsung unveiled their new Z Fold 4 and Z Flip 4 -- two of the most refined and polished foldable smartphones on the market. However, what Samsung hasn't done (or any other phone manufacturer for that matter) "is make the case for why you'd actually want a foldable phone," writes David Pierce via The Verge. "And until it can explain why it's worth all the extra cost and tradeoffs, I'm having a hard time figuring out why you'd be willing to give up the phone you know and love to get one." From the report: What Samsung needs to do with the Galaxy Fold (and the rest of the industry will eventually need to do with their own foldables) is convince people that it's worth buying a phone that's more expensive, more fragile, and takes up more room in your pocket. Right now, the worst thing about foldables is that they force you to make significant sacrifices on the most important device you own: your smartphone. The new Fold 4 is a little shorter, about an ounce heavier, and about twice as thick as the Galaxy S22 Ultra. It's also $600 more expensive. The Ultra has a bigger battery, better camera specs, and a 6.8-inch screen that supports an S Pen. The Fold 4, when opened, is noticeably larger, but the candy bar phones still get plenty big. And Fold makes a lot of sacrifices for some more real estate.

It's not even clear to me that Samsung knows why you should make all of those sacrifices. On its website, one of the first selling points the company offers is that you can prop up the screen on a table by opening it halfway for watching or taking videos hands-free. Here in reality, we call that a kickstand, and this is an awfully expensive one. In this mode, you're also only using half the screen, which sort of defeats the whole purpose. So far, multitasking seems to be the foldable's one actual advantage. Open up your Galaxy Fold, and you can run two apps side by side or even three or four on the screen at once! This, I agree, is a delightful thing. Being able to use my browser and my notes app side by side or see my calendar and my email together is much better than constantly swiping between two full-screen apps. And seeing two pages at a time in the Kindle app is the best. And you know what? Big screens are just good -- good for games, good for reading, good for watching Netflix.

But these aren't just arguments for foldables; they're arguments for tablets. And so far, the arguments for Android tablets don't seem to be convincing many users. While Android has gotten better as a large-screen operating system, and the Fold 4's software being based on Android 12L is a good sign, too many apps that are "optimized" for foldables are actually just sticking a giant sidebar onto one side, which doesn't accomplish much. Others just streeeetch everything to fit the larger screen. Don't even get me started on how the vast majority of apps deal with Microsoft's approach of two separate screens attached with a hinge. Samsung has done an admirable job of wrangling all of Android's weirdness onto the Fold's screen, and in general, it's not that the Fold doesn't work; it's that there's nothing about the Fold that is dramatically better than the phone or tablet you might already be carrying around. And shoving them into a single device actually makes them both a little worse.

Google

US Approves Google Plan To Let Political Emails Bypass Gmail Spam Filter (arstechnica.com) 94

The US Federal Election Commission approved a Google plan to let campaign emails bypass Gmail spam filters. From a report: The FEC's advisory opinion adopted in a 4-1 vote said Gmail's pilot program is permissible under the Federal Election Campaign Act and FEC regulations "and would not result in the making of a prohibited in-kind contribution." The FEC said Google's approved plan is for "a pilot program to test new Gmail design features at no cost on a nonpartisan basis to authorized candidate committees, political party committees, and leadership PACs." On July 1, Google asked the FEC for the green light to implement the pilot after Republicans accused the company of giving Democrats an advantage in its algorithms. Republicans reportedly could have avoided some of their Gmail spam problems by using the proper email configuration. At a May 2022 meeting between Senate Republicans and Google's chief legal officer, "the most forceful rebuke" was said to come "from Sen. Marco Rubio (R-Fla.), who claimed that not a single email from one of his addresses was reaching inboxes," The Washington Post reported in late July. "The reason, it was later determined, was that a vendor had not enabled an authentication tool that keeps messages from being marked as spam, according to people briefed on the discussions."

Slashdot Top Deals