Crime

FBI Says Fraud on LinkedIn a 'Significant Threat' To Platform and Consumers (cnbc.com) 19

Fraudsters who exploit LinkedIn to lure users into cryptocurrency investment schemes pose a "significant threat" to the platform and consumers, according to Sean Ragan, the FBI's special agent in charge of the San Francisco and Sacramento, California, field offices. From a report: "It's a significant threat," Ragan said in an exclusive interview. "This type of fraudulent activity is significant, and there are many potential victims, and there are many past and current victims." The scheme works like this: A fraudster posing as a professional creates a fake profile and reaches out to a LinkedIn user. The scammer starts with small talk over LinkedIn messaging, and eventually offers to help the victim make money through a crypto investment. Victims interviewed by CNBC say since LinkedIn is a trusted platform for business networking, they tend to believe the investments are legitimate. Typically, the fraudster directs the user to a legitimate investment platform for crypto, but after gaining their trust over several months, tells them to move the investment to a site controlled by the fraudster. The funds are then drained from the account.
Facebook

Facebook Unveils Future 'Near Retina-Quality' VR Headsets (theverge.com) 47

Artem S. Tashkinov writes: Meta's Reality Labs division has revealed new prototypes in its roadmap toward lightweight, hyper-realistic virtual reality graphics. The breakthroughs remain far from consumer-ready, but the designs -- codenamed Butterscotch, Starburst, Holocake 2, and Mirror Lake -- could add up to a slender, brightly lit headset that supports finer detail than its current Quest 2 display.

Yet to be released headsets have features which have been sorely missing previously: near-retina-quality image offering about 2.5 times the resolution of the Quest 2's (sort of) 1832 x 1920 pixels per eye, letting users read the 20/20 vision line on an eye chart, high dynamic range (HDR) lighting with 20,000 nits of brightness and eye tracking. "The goal of all this work is to help us identify which technical paths are going to allow us to make meaningful enough improvements that we can start approaching visual realism." says the Meta CEO.

Apple

iOS 16 Will Let iPhone Users Bypass CAPTCHAs in Supported Apps and Websites (macrumors.com) 34

Tapping on images of traffic lights or deciphering squiggly text to prove you are human will soon be a much less common nuisance for iPhone users, as iOS 16 introduces support for bypassing CAPTCHAs in supported apps and websites. From a report: The handy new feature can be found in the Settings app under Apple ID > Password & Security > Automatic Verification. When enabled, Apple says iCloud will automatically and privately verify your device and Apple ID account in the background, eliminating the need for apps and websites to present you with a CAPTCHA verification prompt.
Firefox

Is Firefox OK? (wired.com) 225

At the end of 2008, Firefox was flying high. Twenty percent of the 1.5 billion people online were using Mozilla's browser to navigate the web. In Indonesia, Macedonia, and Slovenia, more than half of everyone going online was using Firefox. "Our market share in the regions above has been growing like crazy," Ken Kovash, Mozilla's data analytics team manager at the time, wrote in a blog post. Almost 15 years later, things aren't so rosy. From a report: Across all devices, the browser has slid to less than 4 percent of the market -- on mobile it's a measly half a percent. "Looking back five years and looking at our market share and our own numbers that we publish, there's no denying the decline," says Selena Deckelmann, senior vice president of Firefox. Mozilla's own statistics show a drop of around 30 million monthly active users from the start of 2019 to the start of 2022. "In the last couple years, what we've seen is actually a pretty substantial flattening," Deckelmann adds.

In the two decades since Firefox launched from the shadows of Netscape, it has been key to shaping the web's privacy and security, with staff pushing for more openness online and better standards. But its market share decline was accompanied by two rounds of layoffs at Mozilla during 2020. Next year, its lucrative search deal with Google -- responsible for the vast majority of its revenue -- is set to expire. A spate of privacy-focused browsers now compete on its turf, while new-feature misfires have threatened to alienate its base. All that has left industry analysts and former employees concerned about Firefox's future. Its fate also has larger implications for the web as a whole. For years, it was the best contender for keeping Google Chrome in check, offering a privacy-forward alternative to the world's most dominant browser.

Communications

Did Telegram's Founder Lose a Million Dollar Bet Over a Prediction for Signal? (pcmag.com) 36

While he couldn't even ethically accept the million dollars, PC Magazine's senior security analyst Max Eddy writes that "how this happened in the first place is indicative of some of the information security industry's worst impulses. It doesn't have to be this way." Back in 2017, Telegram founder Pavel Durov and I had a disagreement... Durov tweeted about how the Signal secure messaging app had received money from the U.S. government. This is true; Signal received funds from the Open Technology Fund (OTF) — a nonprofit that previously was part of the US-backed Radio Free Asia. According to the OTF's website, it gave nearly $3 million to between 2013 and 2016. It's entirely legitimate to be suspicious of government funding (even if TOR, OpenVPN, and WireGuard also received OTF money), and even take a moral stand against recipients of money from governments you disagree with.

But Durov went far beyond that. He seemed to think this meant Signal was bought off by the feds and predicted that a backdoor would be found within five years.

That's quite an accusation to make, especially without real proof, and it made me mad. Not because people were mouthing off on Twitter — that seems to be that platform's primary function. It made me mad that companies ostensibly working to better people's lives by protecting their security and privacy were trying to drag each other down publicly. This is not new; the VPN industry is full of whisper campaigns and counter-accusations. I can't tell you how many conversations I've had with VPN vendors that start with "first off, everything you heard is a lie...." But generally the message from companies in this industry is one of cooperation and protecting everyone. It's a common theme to keynotes at the RSA Conference and Black Hat that the people who work in infosec have a higher calling to protect other people first and do business second.

And then this happened (on Twitter):


Max Eddy: It's one thing to point out funding and another to say that a "backdoor will be found within five years."

Pavel Durov: I am certain of what I'm saying and am willing to bet $1M (1:1) on it.



While Eddy didn't have a million dollars, "I knew there was no way I would lose. This would be the easiest million-dollar bet I ever make." I was confident Durov was wrong because Signal, like many companies, has made an effort toward transparency that I can have some confidence in. Signal has made its code available, has registered as a nonprofit, has a fairly comprehensive privacy policy, and has made abundantly clear that it has no information to provide in response to law enforcement requests. Signal's protocol is also used by competitors, such as WhatsApp and Facebook Messenger, which have surely done their homework when selecting a method for encrypting messages. Most recently, a document revealed that even the FBI has been frustrated in its attempts to get data from Signal (and Telegram, too).
It's been five years, and Eddy now writes that Signal "continues to be recommended by advocacy groups of all kinds as a safe and secure way to communicate..."

"Neither Durov nor Telegram responded to my attempts to contact them for this story."
AI

Ukraine is Using AI to Catch People Sabotaging Its Resistance (newsweek.com) 55

Newsweek reports: Artificial intelligence has become one of Ukraine's most "effective tools" in identifying potential saboteurs amid the ongoing war with Russia, according to the Ukrainian Ministry of Internal Affairs. The ministry issued a report Wednesday on law enforcement's anti-sabotage activities aimed at stopping people in Ukraine who may compromise the counteroffensive or aid Russia in its assault.

Officers have been using software on tablets to check if a person they view as "suspicious" is already listed in databases, including a police database of about 2 million people suspected of holding positions in paramilitary units from the far-right faction known as the Liberal Democratic Party of Russia (LDPR)... The ministry said that Ukrainian police have been fighting against such saboteurs ever since Russia invaded Ukraine. "More than 123 counter-sabotage groups were set up, and at least 1,500 people were involved," First Deputy Minister of Internal Affairs Yevgeny Yenin said in a statement, according to an English translation. "And the result was not long in coming: More than 800 people suspected of sabotage and intelligence activities were detained and handed over to the SBU (Security Service of Ukraine) for investigation."

The report, citing Yenin, said that the police database on people with suspected ties to the LDPR alone contains a "huge amount" of operational information that law enforcement and partners have compiled. This includes more than 10 billion photos, it said...

Russia has also reportedly contended with sabotage from supporters of Ukraine within its borders.

Social Networks

Reaching 700M Active Users, Telegram Announces 'Premium' Tier (techcrunch.com) 33

"Telegram became one of the top-5 downloaded apps worldwide in 2022 and now has over 700 million monthly active users," they announced this weekend. "This growth is solely from personal recommendations — Telegram has never paid to advertise its apps."

But they add significantly that "As Telegram keeps growing at rocket speed, many users have expressed their will to support our team." And so Telegram is now adding a premium tier, TechCrunch reports. "The firm did not disclose how much it is charging for the premium tier, but the monthly subscription appears to be priced in the range of $5 to $6." The premium tier adds a range of additional and improved features to the messaging app, which topped 500 million monthly active users in January 2021. Telegram Premium enables users to send files as large as 4GB (up from 2GB) and supports faster downloads, for instance, Telegram said. Paying customers will also be able to follow up to 1,000 channels, up from 500 offered to free users, and create up to 20 chat folders with as many as 200 chats each. Telegram Premium users will also be able to add up to four accounts in the app and pin up to 10 chats.

The move is Dubai-headquartered firm's attempt to keep its development "driven primarily by its users, not advertisers," it said. It's also the first time an instant messaging app with hundreds of millions of users has rolled out a premium tier. Signal, WhatsApp, Facebook Messenger, Apple's Messages and Google's Messages, some of Telegram's top rivals, don't offer a premium tier.

Some analysts had earlier hoped that Telegram would be able to monetize the platform through its blockchain token project. But after several delays and regulatory troubles, Telegram said in 2020 that it had abandoned the project and offered to return $1.2 billion it had raised from investors....

"Today is an important day in the history of Telegram — marking not only a new milestone, but also the beginning of Telegram's sustainable monetization," the firm said in a blog post Sunday.

Premium users will also get animated profile videos and new home screen icons, along with a special chat-list badge, animated stickers, and additional reaction emojis, according to Telegram's blog post. (And of course, no ads.) Telegram's premium tier "will allow us to offer all the resource-heavy features users have asked for over the years," according to the blog post, "while preserving free access to the most powerful messenger on the planet..."

"The contributions of premium subscribers will help improve and expand the app for decades to come, while Telegram will remain free, independent and uphold its users-first values, redefining how a tech company should operate."
Communications

Discord Adds a Twitch-like Auto-Moderating Feature (engadget.com) 74

On Thursday, Discord introduced AutoMod, "a feature that can automatically detect and block harmful messages before they're posted," reports Engadget: Accessible through Discord's "Server Settings" menu, the tool allows admins and moderators to create a list of words and phrases they want Discord to look for, along with a set of repercussions for those who use them... Discord has put together three starting lists that cover "certain categories of not-nice words or phrases." Moderators can add up to three additional custom filter lists to suit the needs of their users. At launch, AutoMod is only available to Community servers.
"Moderating your growing community should feel rewarding and fulfilling, not add constant stress from dealing with bad actors or unruly members," Discord said in a blog post Thursday.

To introduce the feature, Discord created a cartoon where chicken superheroes thank AutoMod for patrolling their egg server.

Edgadget notes that Discord also has created "a dedicated admin community server run by Discord staff. Here, the company says moderators can gather to chat and learn from one another. Discord also plans to run educational events and share news through the space." Gizmodo adds that Discord also announced this summer's expansion of premium memberships, "a feature that allows a community's creators and owners to put their server behind a paid subscription."
United States

US Probes How American Electronics Wound Up in Russian Military Equipment in Ukraine (msn.com) 174

America's federal agents "have begun questioning U.S. technology companies on how their computer chips ended up in Russian military equipment recovered in Ukraine," reports the Washington Post: Commerce Department agents who enforce export controls are conducting the inquiries together with the FBI, paying joint visits to companies to ask about Western chips and components found in Russian radar systems, drones, tanks, ground-control equipment and littoral ships, according to people familiar with the matter, who spoke on the condition of anonymity to discuss sensitive investigations. "Our goal is to actually try to track that back, all the way back to the U.S. supplier" to determine "how did it find its way into that weapons system," one Commerce Department official said of the probes....

It isn't clear which specific components are being probed. But investigators from a variety of countries have identified Western electronics in Russian weaponry found in Ukraine. Many of those components appear to have been manufactured years ago, before the United States tightened export restrictions after Russia seized Crimea in 2014. But others were manufactured as recently as 2020, according to Conflict Armament Research (CAR), a research group in London that has examined some of the parts....

CAR last month sent investigators to Ukraine to examine Russian weaponry and communications equipment, and reported finding components from 70 companies based in the United States and Europe. They found the parts in military radios, airborne defense systems and in remnants of cruise missiles that the Ukrainians recovered in various towns and villages, Damien Spleeters, one of the CAR investigators, said in an interview.

An associate professor of electrical/computer engineering at Purdue tells the Post "Most of the items they are listing are available through any commercial computer parts supplier or digital parts supplier."

But the Post spoke to a lawyer representing one of the contacted technology companies. "Among the questions federal agents are asking: whether tech companies sold their products to a specific list of companies, including middlemen, that may have been involved in the supply chain."
Social Networks

A New Student Movement Wants You to Log Off 50

Two years ago a college sophomore started "the Log Off movement." This week the New York Times explored its progress — starting with how their mission's been affected by negative news stories about social media: "The first article I read that really launched me into it was Have Smartphones Destroyed a Generation. I found study after study showing the possible correlation between increased rates of anxiety, suicide rates and eating disorders tracking alongside increased rates of usage... The most powerful thing to me was not the studies. It was the fact that personal stories were not being told and there was not an epicenter where people could come together and say: "Here's my personal experience." "Here's how I was harmed." "These were the accounts that made me feel worse about myself." I knew that was necessary. The genie's out of the bottle.

As members of Gen Z, we understand that there are positive attributes and there are negative attributes to social media, but right now, in its current usage, it can be really harmful.

Q: How does the Log Off Movement address these issues?

Through our podcast, a leadership council, an educational curriculum on how to use online spaces safely and blogs, we are discussing ways we can move forward with technology and allow it to become a tool again rather than a controller.

What we are asking for teens to do is to be comfortable talking about their experiences so that we can educate legislators to understand a Gen Z perspective, what we need from technology, what privacy concerns we're having, what mental health concerns we're having. We have an advocacy initiative through Tech[nically] Politics, which pushes for laws that help ensure teens have a safe online experience, specifically the California Age Appropriate Design Code Bill....

Q: How have you adjusted your own relationship to social media? What methods have worked?

Whenever I go through a stressful period with exams, I delete Instagram. I know that in periods of stress, I'm going to lean towards mindlessly using it as a form of coping. Another thing that's worked for me is Grayscale, which makes the phone appear only in black and white.

I always suggest Screentime Genie, which provides solutions on how to limit screen time. I use Habit Lab for Chrome, which helps you reduce your time online. It creates a level of friction between you and addictive technology.

One app they still enjoy is BeReal (which notifies you and your friends to take an unstaged picture of what you're genuinely doing at one randomly-chosen moment each day). But the group's founder still remembers the "horrific loop" of using social media apps six hours a day (starting with Instagram at the age of 12) — and "feeling as though I could not stop scrolling because it has this weird power over me..." One teenager who'd spent six hours a day on social media later shared their observation that logging off improved their vision — but also made the world more clear mentally.

The group's founder says the ultimate hope is their project "results in a kind of pivot prioritizing the well-being of users in these online environments."
Social Networks

Is Social Media Really Harmful? (newyorker.com) 202

Social media has made us "uniquely stupid," believes Jonathan Haidt, a social psychologist at the New York University's School of Business. Writing in the Atlantic in April, Haidt argued that large social media platforms "unwittingly dissolved the mortar of trust, belief in institutions, and shared stories that had held a large and diverse secular democracy together."

But is that true? "We're years into this, and we're still having an uninformed conversation about social media," notes Dartmouth political scientist Brendan Nyhan (quoted this month in a new article in the New Yorker).

The article describes how Haidt tried to confirm his theories in November with Chris Bail, a sociologist at Duke and author of the book "Breaking the Social Media Prism." The two compiled a Google Doc collecting every scholarly study of social media — but many of the studies seemed to contradict each other: When I told Bail that the upshot seemed to me to be that exactly nothing was unambiguously clear, he suggested that there was at least some firm ground. He sounded a bit less apocalyptic than Haidt.

"A lot of the stories out there are just wrong," he told me. "The political echo chamber has been massively overstated. Maybe it's three to five per cent of people who are properly in an echo chamber." Echo chambers, as hotboxes of confirmation bias, are counterproductive for democracy. But research indicates that most of us are actually exposed to a wider range of views on social media than we are in real life, where our social networks — in the original use of the term — are rarely heterogeneous. (Haidt told me that this was an issue on which the Google Doc changed his mind; he became convinced that echo chambers probably aren't as widespread a problem as he'd once imagined....)

[A]t least so far, very few Americans seem to suffer from consistent exposure to fake news — "probably less than two per cent of Twitter users, maybe fewer now, and for those who were it didn't change their opinions," Bail said. This was probably because the people likeliest to consume such spectacles were the sort of people primed to believe them in the first place. "In fact," he said, "echo chambers might have done something to quarantine that misinformation."

The final story that Bail wanted to discuss was the "proverbial rabbit hole, the path to algorithmic radicalization," by which YouTube might serve a viewer increasingly extreme videos. There is some anecdotal evidence to suggest that this does happen, at least on occasion, and such anecdotes are alarming to hear. But a new working paper led by Brendan Nyhan, a political scientist at Dartmouth, found that almost all extremist content is either consumed by subscribers to the relevant channels — a sign of actual demand rather than manipulation or preference falsification — or encountered via links from external sites. It's easy to see why we might prefer if this were not the case: algorithmic radicalization is presumably a simpler problem to solve than the fact that there are people who deliberately seek out vile content. "These are the three stories — echo chambers, foreign influence campaigns, and radicalizing recommendation algorithms — but, when you look at the literature, they've all been overstated." He thought that these findings were crucial for us to assimilate, if only to help us understand that our problems may lie beyond technocratic tinkering. He explained, "Part of my interest in getting this research out there is to demonstrate that everybody is waiting for an Elon Musk to ride in and save us with an algorithm" — or, presumably, the reverse — "and it's just not going to happen."

Nyhan also tells the New Yorker that "The most credible research is way out of line with the takes," adding, for example, that while studies may find polarization on social media, "That might just be the society we live in reflected on social media!" He hastened to add, "Not that this is untroubling, and none of this is to let these companies, which are exercising a lot of power with very little scrutiny, off the hook. But a lot of the criticisms of them are very poorly founded. . . . The lack of good data is a huge problem insofar as it lets people project their own fears into this area." He told me, "It's hard to weigh in on the side of 'We don't know, the evidence is weak,' because those points are always going to be drowned out in our discourse. But these arguments are systematically underprovided in the public domain...."

Nyhan argued that, at least in wealthy Western countries, we might be too heavily discounting the degree to which platforms have responded to criticism... He added, "There's some evidence that, with reverse-chronological feeds" — streams of unwashed content, which some critics argue are less manipulative than algorithmic curation — "people get exposed to more low-quality content, so it's another case where a very simple notion of 'algorithms are bad' doesn't stand up to scrutiny. It doesn't mean they're good, it's just that we don't know."

Verizon

Verizon, AT&T Agree to Delay Some 5G Rollouts Near Airports (apnews.com) 21

The Associated Press reports: Federal regulators say Verizon and AT&T will delay part of their 5G rollout near airports to give airlines more time to ensure that equipment on their planes is safe from interference from the wireless signals, but the airline industry is not happy about the deal. An airline industry trade group said federal regulators are taking a "rushed approach" to changing equipment on planes under pressure from the telecommunications companies.

The Federal Aviation Administration said Friday that the wireless companies agreed to delay some of their use of the C-Band section of the radio spectrum until July 2023. "We believe we have identified a path that will continue to enable aviation and 5G C-band wireless to safely co-exist," said the FAA's acting administrator, Billy Nolen. However, aviation groups say the C-Band service could interfere with radio altimeters — devices used to measure a plane's height above the ground....

Nolen said planes most susceptible to interference — smaller, so-called regional airline planes — must be retrofitted with filters or new altimeters by the end of this year. Components to retrofit larger planes used by major airlines should be available by July 2023, when the wireless companies expect to run 5G networks in urban areas "with minimal restrictions," he said. Airlines for America, a trade group for the largest U.S. carriers, said the FAA hasn't approved necessary upgrades and manufacturers have not yet produced the parts. "It is not at all clear that carriers can meet what appears to be an arbitrary deadline," trade group CEO Nicholas Calio said in a letter to Nolen....

Verizon said the agreement will let the company lift voluntary limits on its 5G rollout around airports "in a staged approach over the coming months." AT&T said it agreed to take "a more tailored approach" to controlling the strength of signals near runways so airlines have more time to retrofit equipment.

Botnet

A Linux Botnet That Spreads Using Stolen SSH Keys (zdnet.com) 40

ZDNet is warning that Linux users need to watch out for "a new peer-to-peer (P2P) botnet that spreads between networks using stolen SSH keys and runs its crypto-mining malware in a device's memory." The Panchan P2P botnet was discovered by researchers at Akamai in March and the company is now warning it could be taking advantage of collaboration between academic institutions to spread by causing previously stolen SSH authentication keys to be shared across networks.

But rather than stealing intellectual property from these educational institutions, the Panchan botnet is using their Linux servers to mine cryptocurrency, according to Akamai... "Instead of just using brute force or dictionary attacks on randomized IP addresses like most botnets do, the malware also reads the id_rsa and known_hosts files to harvest existing credentials and use them to move laterally across the network...." Akamai found 209 peers, but only 40 of them are currently active and they were mostly located in Asia.

And why is the education sector more impacted by Panchan? Akamai guesses this could be because of poor password hygiene, or that the malware moves across the network with stolen SSH keys.

Akamai writes that the malware "catches Linux termination signals (specifically SIGTERM — 0xF and SIGINT — 0x2) that are sent to it, and ignores them.

"This makes it harder to terminate the malware, but not impossible, since SIGKILL isn't handled (because it isn't possible, according to the POSIX standard, page 313)."
KDE

KDE Plasma 5.25 Released (kde.org) 27

Long-time Slashdot reader jrepin describes Plasma as "a popular desktop environment, which is also powering the desktop mode on the Steam Deck portable gaming console."

And this week the KDE Community announced the release of KDE Plasma 5.25: This new version brings many improvements...

- The accent colour can now be set based on the prominent colour from the current desktop background image (it updates if you use slide-show wallpapers) and it applies to more graphical elements.

- Floating Panels add a margin all around the panel to make it float while no window is maximised.

- Touch-screen mode can now be activated by detaching the screen, rotating it 360, or enabling it manually.

- The Global Theme settings page lets you pick and choose which parts to apply.

- The Application page for Discover has been redesigned and gives you links to the application's documentation and website, and shows what system resources it has access to.

- Panels can now be navigated with the keyboard, and you can assign custom shortcuts to focus individual panels.

Lilputing.com adds that "There's a new Overview effect that zooms out to display previews of all currently-running apps and virtual desktops. You can access this view with a four-finger pinch on a touchscreen or touchpad, and from this view, you can also search for apps, documents, or browser tabs or add, remove, or rename virtual desktops."
Transportation

World's Most Efficient Passenger Plane Gets Hydrogen Powertrain (newatlas.com) 59

Otto's Celara 500L -- "the most fuel-efficient, commercially viable business aircraft in the world" -- is about to get a hydrogen fuel cell powertrain. New Atlas reports: The Celera 500L is a truly remarkable design. Otto Aviation says its odd shape delivers an astonishing 59 percent reduction in drag, and a massive leap in efficiency and range compared to traditional plane geometries. [...] The whole thing is designed to maximize laminar flow -- smooth layers of airflow with little to no mixing of adjacent layers moving at different speeds. This avoids the swirls and eddies that lead to air turbulence at speed, causing aerodynamic drag and wasted energy. Laminar flow is by no means a new concept, but Otto says it's pushed the idea so far forward with the Celera design that it uses 80 percent less fuel than a traditional design. No, that's not a typo. [...]

Now clearly, an 80 percent reduction in fossil fuel use is an environmental win in and of itself. But if there's one sector in aviation that's crying out for brain-busting efficiency figures like the Celera promises, it's the emerging zero-emissions sector, which is currently struggling against poor range figures thanks to the low energy density of lithium batteries. Indeed, when we first wrote about the Celera 500L back in 2020, many questioned why the heck this thing wasn't electric from the get go. And it seems Otto is on board with the idea, as it's now announced a collaboration with hydrogen aviation pioneers ZeroAvia to develop a fuel cell-electric powertrain specific to the Celera's requirements.

This airframe's bulbous shape works well with a hydrogen concept -- hydrogen powertrains can weigh much less than battery-electric ones, but they tend to take up a bit of space. Still, ZeroAvia is being relatively humble with its ambitions to begin with, aiming for a range of just 1,000 nautical miles (1,852 km) of zero-emissions range for a hydrogen-fueled Celera. Still, that's a very useful distance, and pretty extraordinary for a clean electric passenger plane.

Transportation

Boring Company Receives Approval For Expanding Its Tunnels To Downtown Las Vegas (theverge.com) 88

Elon Musk's Boring Company has received unanimous approval to expand its system of tunnels beneath downtown Las Vegas. The Verge reports: The expansion will add stops at landmarks like the Stratosphere and Fremont Street, letting customers hop aboard a Tesla and travel from one part of the city to the next. The network of tunnels, called the Vegas Loop, is supposed to span 29 miles and have 51 stops when finished. But for now, only 1.7-mile tunnels are operational beneath the Las Vegas Convention Center (LVCC), turning what would be a 25-minute walk across the convention center into a two-minute ride.

This most recent expansion gets The Boring Company closer to its goal of building a transportation system that spans the most popular destinations in Las Vegas. "Thanks to the entire team at the City of Last Vegas!" The Boring Company wrote on Twitter in response to the city's approval. "Great discussion today, and TBC is excited to build a safe, convenient, and awesome transportation system in the City." [...] According to the Las Vegas Review-Journal, Steve Hill, the president and CEO of the Las Vegas Convention and Visitors Authority, expects the tunnel system beneath the Strip to start serving customers in 2023. Hill says the portion connecting the LVCC and Resorts World should be operational by the end of this year.

The Internet

Brave Roasts DuckDuckGo Over Bing Privacy Exception (theregister.com) 23

Brave CEO Brendan Eich took aim at rival DuckDuckGo on Wednesday by challenging the web search engine's efforts to brush off revelations that its Android, iOS, and macOS browsers gave, to a degree, Microsoft Bing and LinkedIn trackers a pass versus other trackers. The Register reports: Eich drew attention to one of DuckDuckGo's defenses for exempting Microsoft's Bing and LinkedIn domains, a condition of its search contract with Microsoft: that its browsers blocked third-party cookies anyway. "For non-search tracker blocking (e.g. in our browser), we block most third-party trackers," explained DuckDuckGo CEO Gabriel Weinberg last month. "Unfortunately our Microsoft search syndication agreement prevents us from doing more to Microsoft-owned properties. However, we have been continually pushing and expect to be doing more soon."

However, Eich argues this is disingenuous because DuckDuckGo also includes exceptions that allow Microsoft trackers to circumvent third-party cookie blocking via appended URL parameters. "Trackers try to get around cookie blocking by appending identifiers to URL query parameters, to ID you across sites," he explained. DuckDuckGo is aware of this, Eich said, because its browser prevents Google, Facebook, and others from appending identifiers to URLs in order to bypass third-party cookie blocking. "[DuckDuckGo] removes Google's 'gclid' and Facebook's 'fbclid'," Eich said. "Test it yourself by visiting https://example.org/?fbclid=sample in [DuckDuckGo]'s macOS browser. The 'fbclid' value is removed." "However, [DuckDuckGo] does not apply this protection to Microsoft's 'msclkid' query parameter," Eich continued. "[Microsoft's] documentation specifies that 'msclkid' exists to circumvent third-party cookie protections in browsers (including in Safari's browser engine used by DDG on Apple OSes)." Eich concluded by arguing that privacy-focused brands need to prioritize privacy. "Brave categorically does not and will not harm user privacy to satisfy partners," he said.

A spokesperson for DuckDuckGo characterized Eich's conclusion as misleading. "What Brendan seems to be referring to here is our ad clicks only, which is protected in our agreement with Microsoft as strictly non-profiling (private)," a company spokesperson told The Register in an email. "That is these ads are privacy protected and how he's framed it is ultimately misleading. Brendan, of course, kept the fact that our ads are private out and there is really nothing new here given everything has already been disclosed." In other words, allowing Bing to append its identifier to URLs enables Bing advertisers to tell whether their ad produced a click (a conversion), but not to target DuckDuckGo browser users based on behavior or identity.

DuckDuckGo's spokesperson pointed to Weinberg's attempt to address the controversy on Reddit and argued that DuckDuckGo provides very strong privacy protections. "This is talking about link tracking which no major browser protects against (see https://privacytests.org/), however we've started protecting against link tracking, and started with the primary offenders (Google and Facebook)," DuckDuckGo's spokesperson said. "To note, we are planning on expanding this to more companies, including Twitter, Microsoft, and more. We are not restricted from this and will be doing so."

Software

Microsoft Updates Store Rules To Ban Paid Copycat Open-Source Projects (ghacks.net) 37

Microsoft updated the Microsoft Store policies yesterday to prohibit publishers from charging fees for software that is open source or generally available for free. They're also no longer allowed to set irrationally high price tags for their products. gHacks reports: If you have been to the Microsoft Store in the past couple of years, you may have noticed that it is home to more and more open source and free products. While that would be a good thing if the original developer would have uploaded the apps and games to the store, it is not, because the uploads have been made by third-parties. Even worse is the fact that many of these programs are not freely available, but available as paid applications. In other words: Microsoft customers have to pay money to buy a Store version of an app that is freely available elsewhere. Sometimes, free and paid versions exist side by side in the Store. Having to pay for a free application is bad enough, but this is not the only issue that users may experience when they make the purchase. Updates may be of concern as well, as the copycat programs may not be updated as often or as quickly as the source applications.

Open source and free products may not be sold anymore on the Microsoft Store, if generally available for free, and publishers are not allowed to set irrationally high price tags for their products anymore. The developers of open source and free applications may charge for their products on the Microsoft Store, the developer of Paint.net does that, for example. If Microsoft enforces the policies, numerous applications will be removed from the Store. Developers could report applications to Microsoft before, but the new policies give Microsoft control over application listings and submissions directly.

Crime

Stolen Goods Sold on Amazon, eBay and Facebook Are Causing Havoc for Major Retailers (cnbc.com) 106

Over the past year, large-scale robberies have swept through stores like Louis Vuitton in San Francisco's Union Square and a nearby Nordstrom, which was robbed by 80 people. Law enforcement and retailers have warned the public that this isn't traditional shoplifting. Rather, what they're seeing is theft organized by criminal networks. And there's a reason it's on the rise. From a report: "What fuels this as an enterprise is the ease of reselling stolen merchandise on online marketplaces," said Illinois Attorney General Kwame Raoul, who convened a national task force of state attorneys to make it easier to investigate across state lines. "It's no longer the age where it's done at flea markets or in the alley or in parking lots." Retailers say a total of $68.9 billion of products were stolen in 2019. In 2020, three-quarters said they saw an increase in organized crime and more than half reported cargo theft. Some big chains blame organized theft for recent store closures or for their decisions to limit hours.

For the U.S. Government's Homeland Security Investigations unit, organized retail crime probes are on the rise. Arrests and indictments increased last year from 2020, along with the value of stolen goods that was seized. While data is imprecise about the perpetrators, there's growing consensus that an entirely different group should be held accountable: e-commerce sites. Amazon, eBay and Facebook are the places where these stolen goods are being sold, and critics say they're not doing enough to put an end to the racket. The companies disagree.

Businesses

Leaked Amazon Memo Warns the Company is Running Out of People To Hire in Its Warehouses (vox.com) 128

Amazon is facing a looming crisis: It could run out of people to hire in its US warehouses by 2024, according to leaked Amazon internal research from mid-2021 that Recode reviewed. If that happens, the online retailer's service quality and growth plans could be at risk, and its e-commerce dominance along with it. From a report: Raising wages and increasing warehouse automation are two of the six "levers" Amazon could pull to delay this labor crisis by a few years, but only a series of sweeping changes to how the company does business and manages its employees will significantly alter the timeline, Amazon staff predicted. "If we continue business as usual, Amazon will deplete the available labor supply in the US network by 2024," the research, which hasn't previously been reported, says.

The report warned that Amazon's labor crisis was especially imminent in a few locales, with internal models showing that the company was expected to exhaust its entire available labor pool in the Phoenix, Arizona, metro area by the end of 2021, and in the Inland Empire region of California, roughly 60 miles east of Los Angeles, by the end of 2022. Amazon's internal report calculated the available pool of workers based on characteristics like income levels and a household's proximity to current or planned Amazon facilities; the pool does not include the entire US adult population.

Slashdot Top Deals