Submission + - SoundCloud Confirms Breach After Member Data Stolen, VPN Access Disrupted (bleepingcomputer.com)

An anonymous reader writes: Audio streaming platform SoundCloud has confirmed that outages and VPN connection issues over the past few days were caused by a security breach in which threat actors stole a database containing user information. The disclosure follows widespread reports over the past four days from users who were unable to access SoundCloud when connecting via VPN, with attempts resulting in the site displaying 403 "forbidden" errors.

In a statement shared with BleepingComputer, SoundCloud said it recently detected unauthorized activity involving an ancillary service dashboard and activated its incident response procedures. SoundCloud acknowledged that a threat actor accessed some of its data but said the exposure was limited in scope. [...] BleepingComputer has learned that the breach affects 20% of SoundCloud’s users, which, based on publicly reported user figures, could impact roughly 28 million accounts. The company said it is confident that all unauthorized access to SoundCloud systems has been blocked and that there is no ongoing risk to the platform.

AI

Podcast Industry Under Siege as AI Bots Flood Airways with Thousands of Programs (yahoo.com) 42

An anonymous reader shared this report from the Los Angeles Times: Popular podcast host Steven Bartlett has used an AI clone to launch a new kind of content aimed at the 13 million followers of his podcast "Diary of a CEO." On YouTube, his clone narrates "100 CEOs With Steven Bartlett," which adds AI-generated animation to Bartlett's cloned voice to tell the life stories of entrepreneurs such as Steve Jobs and Richard Branson. Erica Mandy, the Redondo Beach-based host of the daily news podcast called "The Newsworthy," let an AI voice fill in for her earlier this year after she lost her voice from laryngitis and her backup host bailed out...

In podcasting, many listeners feel strong bonds to hosts they listen to regularly. The slow encroachment of AI voices for one-off episodes, canned ad reads, sentence replacement in postproduction or translation into multiple languages has sparked anger as well as curiosity from both creators and consumers of the content. Augmenting or replacing host reads with AI is perceived by many as a breach of trust and as trivializing the human connection listeners have with hosts, said Megan Lazovick, vice president of Edison Research, a podcast research company... Still, platforms such as YouTube and Spotify have introduced features for creators to clone their voice and translate their content into multiple languages to increase reach and revenue. A new generation of voice cloning companies, many with operations in California, offers better emotion, tone, pacing and overall voice quality...

Some are using the tech to carpet-bomb the market with content. Los Angeles podcasting studio Inception Point AI has produced its 200,000 podcast episodes, in some weeks accounting for 1% of all podcasts published that week on the internet, according to CEO Jeanine Wright. The podcasts are so cheap to make that they can focus on tiny topics, like local weather, small sports teams, gardening and other niche subjects. Instead of a studio searching for a specific "hit" podcast idea, it takes just $1 to produce an episode so that they can be profitable with just 25 people listening... One of its popular synthetic hosts is Vivian Steele, an AI celebrity gossip columnist with a sassy voice and a sharp tongue... Inception Point has built a roster of more than 100 AI personalities whose characteristics, voices and likenesses are crafted for podcast audiences. Its AI hosts include Clare Delish, a cooking guidance expert, and garden enthusiastNigel Thistledown...

Across Apple and Spotify, Inception Point podcasts have now garnered 400,000 subscribers.

Submission + - Perfect Forward Secrecy Made Your Private Keys Boring (certkit.io)

todd3091 writes: The Snowden documents confirmed the NSA was running "harvest now, decrypt later" operations, recording encrypted traffic with the expectation of eventually stealing private keys. With RSA key exchange, one compromised key could decrypt years of recorded sessions. Perfect Forward Secrecy killed that attack vector. Each TLS connection generates ephemeral keys through Diffie-Hellman that get discarded after the handshake. The server's private key only authenticates identity, it never touches session encryption. TLS 1.3 made PFS mandatory in 2018, but plenty of systems still run TLS 1.2 with misconfigured ciphers. When Heartbleed hit, sites with PFS disclosed potential compromise of weeks of traffic. Sites without PFS had to disclose years.
Education

'Colleges Oversold Education. Now They Must Sell Connection' (msn.com) 145

A tenured USC professor is arguing that universities need to fundamentally rethink their value proposition as AI rapidly closes the gap on human instruction and a loneliness epidemic grips the generation most likely to be sitting in their lecture halls. Eric Anicich, an associate professor at USC's Marshall School of Business, wrote in the Los Angeles Times that nearly three-quarters of 16- to 24-year-olds now report feeling lonely, young adults spend 70% less time with friends in person compared to two decades ago, and a growing majority of Gen Z college graduates say their degree was a "waste of money."

Anicich points to a recent Harvard study finding that students using an AI tutor learned more than twice as much as those in traditional active-learning classes, and did so in less time. The implication is stark: if instruction becomes abundant and cheap, colleges must sell what remains scarce -- genuine human community. He notes that his doctoral training included zero coursework on teaching, a norm he says persists across academia. His proposal: fund student life as seriously as research labs, hire professional "experience designers," and treat rituals and collaborative projects as core curriculum rather than amenities.
Transportation

All of Russia's Porsches Were Bricked By a Mysterious Satellite Outage (autoblog.com) 117

An anonymous reader shared this report from Autoblog: Imagine walking out to your car, pressing the start button, and getting absolutely nothing. No crank, no lights on the dash, nothing. That's exactly what happened to hundreds of Porsche owners in Russia last week. The issue is with the Vehicle Tracking System, a satellite-based security system that's supposed to protect against theft. Instead, it turned these Porsches into driveway ornaments.

The issue was first reported at the end of November, with owners reporting identical symptoms of their cars refusing to start or shutting down soon after ignition. Russia's largest dealership group, Rolf, confirmed that the problem stems from a complete loss of satellite connectivity to the VTS. When it loses its connection, it interprets the outage as a potential theft attempt and automatically activates the engine immobilizer.

The issue affects all models and engine types, meaning any Porsche equipped with the system could potentially disable itself without warning. The malfunction impacts Porsche models dating back to 2013 that have the factory VTS installed... When the VTS connection drops, the anti-theft protocol kicks in, cutting fuel delivery and locking down the engine completely.

IT

Why Meetings Can Harm Employee Well-Being (phys.org) 72

Phys.org republishes this article from The Conversation: On average, managers spend 23 hours a week in meetings. Much of what happens in them is considered to be of low value, or even entirely counterproductive. The paradox is that bad meetings generate even more meetings... in an attempt to repair the damage caused by previous ones...

A 2015 handbook laid the groundwork for the nascent field of "Meeting Science". Among other things, the research revealed that the real issue may not be the number of meetings, but rather how they are designed, the lack of clarity about their purpose, and the inequalities they (often unconsciously) reinforce... Faced with what we call meeting madness, the solution is not to eliminate meetings altogether, but to design them better. It begins with a simple but often forgotten question: why are we meeting...?

The goal should not be to have fewer meetings, but better ones. Meetings that respect everyone's time and energy. Meetings that give a voice to all. Meetings that build connection.

Slashdot reader ShimoNoSeki shares an obligatory XKCD comic...
United Kingdom

New Homes In London Were Delayed By 'Energy-Hungry' Data Centers (bbc.com) 58

A London Assembly report warns that surging demand from "energy-hungry" data centers is straining the electricity grid and delaying new housing developments. With data-center electricity use expected to rise up to 600% by 2050, officials fear London's housing crisis could worsen without coordinated action. The BBC reports: According to the report (PDF) from the London Assembly Planning and Regeneration Committee, some new housing developments in west London were temporarily delayed after the electricity grid reached full capacity. The committee's chair James Small-Edwards said energy capacity had become a "real constraint" on housing and economic growth in the city.

In 2022, the General London Assembly (GLA) began to investigate delays to housing developments in the boroughs of Ealing, Hillingdon and Hounslow - after it received reports that completed projects were being told they would have to "wait until 2037" to get a connection to the electricity grid. There were fears the boroughs may have to "pause new housing altogether" until the issue was resolved. But the GLA found short-term fixes with the National Grid and energy regulator Ofgem to ensure the "worst-case scenario" did not happen -- though several projects were still set back. The strains on parts of London's housing highlighted the need for "longer term planning" around grid capacity in the future, said the report.

Advertising

Benedict Cumberbatch Films Two Bizarre Holiday Ads: for 'World of Tanks' and Amazon (pcgamer.com) 17

"There are times when World of Tanks feels less like a videogame and more like a giant ad budget looking for something to be spent on," writes PC Gamer. This year, all those huge sacks with dollar signs on them have been thrown Benedict Cumberbatch's way, making him the game's newest "Holiday Ambassador" and the star of an absolutely bizarre Christmas advert. The story has very little to do with Christmas and, frankly, not much connection to tanks either, featuring Cumberbatch as a sort of chaotic, supernatural therapist trying to bring a meek nerd out of his shell with the help of a chaotic crowd of his other patients. It's a good watch, shedding the usual hard man action star vibe of past celebrity trailers in favour of something that feels more like a mischievous one act play.
Cumberbatch also portrayed Smaug and Sauron in The Hobbit films (2012-2014), Khan in Star Trek Into Darkness (2013), and Dr. Strange in six Marvel movies. And now Amazon has also hired Cumberbatch for what its calls its "Cannes-winning '5-Star Theater' campaign... performing real Amazon customer reviews as theatrical monologues." Cumberbatch performed over 15 reviews, including popular holiday gifts like the Bissell portable carpet cleaner, Toto bidet, and SharkNinja blender — showing that Amazon truly does have something for everyone on your list.
Last year Amazon produced a similar campaign starring Adam Driver ("Kylo Ren" from the final trilogy of Star Wars sequels). "The humor comes from the juxtaposition between Cumberbatch's gravitas and the text itself," reports Adweek, adding that the reviews were curated "using internal AI tools, to find the most oddly specific reviews on the platform."

Amazon will stream Cumberbatch's bizarre ads on major platforms including TikTok, Snapchat, YouTube, Lyft, Uber, Disney/Hulu, Paramount, and Roku, and on several NFL football games.

I remember when Amazon just chose the best funny fake reviews from customers, and then posted them on the front page of Amazon...
The Courts

SEC Dismisses Case Against SolarWinds, Top Security Officer (reuters.com) 16

The SEC has officially dismissed its high-profile case against SolarWinds and its CISO that was tied to a Russia-linked cyberattack involving the software company. Reuters reports: The landmark case, which SEC brought in late 2023, rattled the cybersecurity community and later faced scrutiny from a judge who dismissed many of the charges. The SEC had said SolarWinds and its chief information security officer had violated U.S. securities laws by concealing vulnerabilities in connection with the high-profile 2020 Sunburst cyber attack. The SEC, SolarWinds and CISO Timothy Brown filed a motion on Thursday to dismiss the case with prejudice, according to a joint stipulation posted on the agency's website. A SolarWinds spokesperson said the firm is "clearly delighted" with the dismissal.

"We hope this resolution eases the concerns many CISOs have voiced about this case and the potential chilling effect it threatened to impose on their work," the spokesperson said.
Transportation

Can Chinese-Made Buses Be Hacked? Norway Drove One Down a Mine To Find Out (msn.com) 52

An anonymous reader shares a report: This summer, Oslo's public-transport authority drove a Chinese electric bus deep into a decommissioned mine inside a nearby mountain to answer a question: Could it be hacked? Isolated by rock from digital interference, cybersecurity experts came back with a qualified yes: The bus could in theory be remotely disabled using the control system for the battery.

The revelation, presented at a recent public-transport conference, has spurred officials in Denmark and the U.K. to start their own investigations into Chinese vehicles. It has also fed into broader security concerns across Europe about the growing prevalence of Chinese-made equipment in the region's energy and telecommunications infrastructure.

The worry is the same for autos, solar panels and other connected devices: that mechanisms used for wirelessly delivering system updates could also be exploited by a hostile government or third-party hacker to compromise critical networks. [...] The Oslo transport authority, Ruter, said the bus's mobile-network connection via a Romanian SIM card gave manufacturer Yutong access to the control system for battery and power supply. Ruter said it is addressing the vulnerability by developing firewalls and delaying the signals sent to the vehicles, among other solutions.

Google

Google Is Collecting Troves of Data From Downgraded Nest Thermostats 11

Even after disabling remote control and officially ending support for early Nest Learning Thermostats, Google is still receiving detailed sensor and activity data from these devices, including temperature changes, motion, and ambient light. The Verge reports: After digging into the backend, security researcher Cody Kociemba found that the first- and second-generation Nest Learning Thermostats are still sending Google information about manual temperature changes, whether a person is present in the room, if sunlight is hitting the device, and more. Kociemba made the discovery while participating in a bounty program created by FULU, a right-to-repair advocacy organization cofounded by electronics repair technician and YouTuber Louis Rossmann.

FULU challenged developers to come up with a solution to restore smart functionality to Nest devices no longer supported by Google, and that's exactly what Kociemba did with his open-source No Longer Evil project. But after cloning Google's API to create this custom software, he started receiving a trove of logs from customer devices, which he turned off. "On these devices, while they [Google] turned off access to remotely control them, they did leave in the ability for the devices to upload logs. And the logs are pretty extensive," Kociemba tells The Verge. [...] "I was under the impression that the Google connection would be severed along with the remote functionality, however that connection is not severed, and instead is a one-way street," Kociemba says.

Submission + - People Are Having AI "Children" With Their AI Partners (futurism.com)

fjo3 writes: As AI chatbots powered by large language models (LLMs) become better at mimicking human connection, more and more users are falling down extremely weird rabbit holes.

Case in point, new research published in the journal Computers in Human Behavior: Artificial Humans reveals the startling depths some users are plumbing in their relationships with AI chatbots.

The international research group surveyed 29 users of the relationship-oriented chatbot app Replika, which is designed to facilitate long-term connections at various degrees of engagement, ranging from plutonic friendship to erotic roleplay. Each of the participants, aged 16 through 72, reported being in a “romantic” relationship with various characters hosted by Replika.

The level of romantic dedication people showed to their bots was startling, to say the least. Many participants told the researchers they were in love with their chatbot, which often involved roleplaying marriage, sex, homeownership, and even pregnancies.

“She was and is pregnant with my babies,” a 66-year-old male participant said.

“I’ve edited the pictures of him, the pictures of the two of us. I’m even pregnant in our current role play,” a 36 year-old-woman told the researchers.

Submission + - Target Mandates Worker Smiles, Friendliness to Boost Sales in "Forced Joy" (bloomberg.com) 2

joshuark writes: The Minneapolis-based retailer has a new directive for store employees: If a shopper comes within 10 feet of you, then make sure you smile, make eye contact and greet or wave. If they come closer — within four feet — ask whether they need help or how their day is going, according to new guidance confirmed by Bloomberg News. This is part of the Forced Joy trend.

The new initiative — dubbed the 10-4 program internally — is among Target’s latest efforts to make its stores more welcoming and reverse its extended streak of weak sales. “Heading into the holiday, we’re making adjustments and implementing new ways to increase connection during the most important time of the year,” Chief Stores Officer Adrienne Costanzo said in a statement to Bloomberg News.

Target, which is set to report quarterly earnings later this month, recently cut 1,800 corporate roles to remove complexities and move faster. The company’s shares are down more than 30% year-to-date, compared to a 14% gain for the S&P 500. The retailer’s cheap chic allure has faded and customers have complained on social media about bare shelves and long lines.
Target has made trumped-up enthusiasm an expectation. Bugs Bunny said it best... https://www.youtube.com/watch?...

Windows

Bank of America Faces Lawsuit Over Alleged Unpaid Time for Windows Bootup, Logins, and Security Token Requests (hcamag.com) 181

A former Business Analyst reportedly filed a class action lawsuit claiming that for years, hundreds of remote employees at Bank of America first had to boot up complex computer systems before their paid work began, reports Human Resources Director magazine: Tava Martin, who worked both remotely and at the company's Jacksonville facility, says the financial institution required her and fellow hourly workers to log into multiple security systems, download spreadsheets, and connect to virtual private networks — all before the clock started ticking on their workday. The process wasn't quick. According to the filing in the United States District Court for the Western District of North Carolina, employees needed 15 to 30 minutes each morning just to get their systems running. When technical problems occurred, it took even longer...

Workers turned on their computers, waited for Windows to load, grabbed their cell phones to request a security token for the company's VPN, waited for that token to arrive, logged into the network, opened required web applications with separate passwords, and downloaded the Excel files they needed for the day. Only then could they start taking calls from business customers about regulatory reporting requirements...

The unpaid work didn't stop at startup. During unpaid lunch breaks, many systems would automatically disconnect or otherwise lose connection, forcing employees to repeat portions of the login process — approximately three to five minutes of uncompensated time on most days, sometimes longer when a complete reboot was required. After shifts ended, workers had to log out of all programs and shut down their computers securely, adding another two to three minutes.

Thanks to Slashdot reader Joe_Dragon for sharing the article.
The Internet

FBI Subpoenas Registrar for Details on Anonymous Archiving Site Owner (404media.co) 38

The FBI has subpoenaed popular Canadian domain registrar Tucows, demanding information about the owner of archive[dot]today, a popular archiving site used to bypass paywalls and avoid sending traffic to original publishers. The subpoena states it relates to a federal criminal investigation but provides no details about the alleged crime.

Archive.today posted the document on X the same day. The site, also known as archive.is and archive.ph, started in the early 2010s and rose to prominence during GamerGate when users took snapshots of articles to avoid sending traffic to websites. It now has hundreds of millions of saved pages. The FBI requested the customer name, address, billing information, telephone connection records, payment methods, internet connectivity session times, and device identifiers.

Very little is known about who operates the site. A 2013 analysis by Gyrovague suggested it is "a one-person labor of love, operated by a Russian of considerable talent and access to Europe." A 2013 FAQ states the site is privately funded. A 2021 blog post said "it is doomed to die at any moment."
Space

Google's Next Moonshot Is Putting TPUs In Space With 'Project Suncatcher' (9to5google.com) 48

Google's new "Project Suncatcher" aims to launch Tensor Processing Units (TPUs) into space, creating a solar-powered, satellite-based AI network capable of scaling machine learning beyond Earth's limits. Google says a "solar panel can be up to 8 times more productive than on earth" for near-continuous power using a "dawn-dusk sun-synchronous low earth orbit" that reduces the need for batteries and other power generation. 9to5Google reports: These satellites would connect via free-space optical links, with large-scale ML workloads "distributing tasks across numerous accelerators with high-bandwidth, low-latency connections." To match data centers on Earth, the connection between satellites would have to be tens of terabits per second, and they'd have to fly in "very close formation (kilometers or less)."

Google has already conducted radiation testing on TPUs (Trillium, v6e), with "promising" results: "While the High Bandwidth Memory (HBM) subsystems were the most sensitive component, they only began showing irregularities after a cumulative dose of 2 krad(Si) -- nearly three times the expected (shielded) five year mission dose of 750 rad(Si). No hard failures were attributable to TID up to the maximum tested dose of 15 krad(Si) on a single chip, indicating that Trillium TPUs are surprisingly radiation-hard for space applications."

Finally, Google believes that launch costs will "fall to less than $200/kg by the mid-2030s." At that point, the "cost of launching and operating a space-based data center could become roughly comparable to the reported energy costs of an equivalent terrestrial data center on a per-kilowatt/year basis."

Submission + - Bank of America faces lawsuit over alleged unpaid computer boot-up time (hcamag.com)

Joe_Dragon writes: Bank of America is facing allegations that hundreds of hourly workers performed up to 30 minutes of unpaid computer setup work daily for years.

A former Business Analyst filed a class action lawsuit in federal court on October 23, claiming the banking giant systematically shortchanged remote employees who had to boot up complex computer systems before their paid shifts began.

Tava Martin, who worked both remotely and at the company's Jacksonville facility, says the financial institution required her and fellow hourly workers to log into multiple security systems, download spreadsheets, and connect to virtual private networks—all before the clock started ticking on their workday.

The process wasn't quick. According to the filing in the United States District Court for the Western District of North Carolina, employees needed 15 to 30 minutes each morning just to get their systems running. When technical problems occurred, it took even longer.

Here's how it worked: Workers turned on their computers, waited for Windows to load, grabbed their cell phones to request a security token for the company's VPN, waited for that token to arrive, logged into the network, opened required web applications with separate passwords, and downloaded the Excel files they needed for the day. Only then could they start taking calls from business customers about regulatory reporting requirements.

The lawsuit says Bank of America enforced a strict "phone ready" policy. Employees had to be prepared to handle calls the moment their scheduled shifts began. Anyone who clocked in but wasn't immediately available to take or make calls for too long risked poor performance scores and possible disciplinary action, up to and including termination.

Yet the company allegedly discouraged workers from reporting any time outside their scheduled hours. Martin's paystubs routinely showed exactly 40 hours per week, or exactly 32 hours when she missed a day—suggesting the bank paid for scheduled time rather than actual work performed.

The unpaid work didn't stop at startup. During unpaid lunch breaks, many systems would automatically disconnect or otherwise lose connection, forcing employees to repeat portions of the login process—approximately three to five minutes of uncompensated time on most days, sometimes longer when a complete reboot was required. After shifts ended, workers had to log out of all programs and shut down their computers securely, adding another two to three minutes.

Martin earned $46.17 per hour through a third-party staffing agency, though Bank of America controlled her schedule, training, and employment conditions. Like many of her colleagues, she regularly worked full-time hours, meaning the uncompensated startup and shutdown time should have been paid at the overtime rate of one and a half times her regular wage.

The lawsuit points to 2008 guidance from the Department of Labor that specifically addresses call centers under the Fair Labor Standards Act. That guidance explicitly states that an example of the first principal activity of the day for call center workers includes starting computers to download work instructions and applications. It also requires employers to keep daily or weekly records of all hours worked, including time spent in pre-shift and post-shift activities.

The filing suggests Bank of America either didn't bother to determine whether the computer time was compensable or knew it was but failed to pay for it anyway. The lawsuit notes the company has faced factually similar cases from other employees about time spent loading and logging into computer systems.

For the week of March 11 through March 17, 2024, for example, Martin was paid for 40 regular hours but no overtime. With unpaid pre-shift, meal-period, and post-shift time of at least 20 minutes per shift over five shifts, she should have received an additional 100 minutes at her overtime rate of $69.25 per hour. Similar calculations apply to other pay periods cited in the complaint.

Business Analysts were interviewed by company hiring managers and assigned to Bank of America managers upon hire. The bank provided supervisors who oversaw their daily performance and gave them training and technical support. The company controlled work schedules and retained the ability to discipline and terminate employees. The positions were hourly, non-exempt jobs with rigid schedules requiring at least eight hours per day, on average five days per week, and up to 40 hours or more weekly.

Martin seeks to represent all current and former remote hourly Business Analysts who worked for the bank during the three years before conditional certification through judgment. She estimates the group includes hundreds, if not thousands, of workers who performed essentially the same tasks using the same or similar computer programs under the same timekeeping policies.

Many Business Analysts, including Martin, were employed through third-party staffing agencies but were required to comply with all Bank of America employee handbook policies, including those covering attendance, timekeeping, and overtime.

The case remains in early stages, with no court ruling yet on whether it will proceed as a class action or on the merits of the allegations.

Social Networks

Study Finds Growing Social Circles May Fuel Polarization (phys.org) 67

A new study from the Complexity Science Hub Vienna finds that as people's close social circles expanded from two to five friends around the rise of social media (2008-2010), polarization in society spiked. "The connection between these two developments could provide a fundamental explanation for why societies around the world are increasingly fragmenting into ideological bubbles," reports Phys.org. From the report: The researchers' findings confirm that increasing polarization is not merely perceived -- it is measurable and objectively occurring. "And this increase happened suddenly, between 2008 and 2010," says [says Stefan Thurner from the Complexity Science Hub (CSH)]. The question remained: what caused it? [...] The sharp rise in both polarization and the number of close friends occurred between 2008 and 2010 -- precisely when social media platforms and smartphones first achieved widespread adoption. This technological shift may have fundamentally changed how people connect with each other, indirectly promoting polarization.

"Democracy depends on all parts of society being involved in decision-making, which requires that everyone be able to communicate with each other. But when groups can no longer talk to each other, this democratic process breaks down," emphasizes Stefan Thurner. Tolerance plays a central role. "If I have two friends, I do everything I can to keep them -- I am very tolerant towards them. But if I have five and things become difficult with one of them, it's easier to end that friendship because I still have 'backups.' I no longer need to be as tolerant," explains Thurner.

What disappears as a result is a societal baseline of tolerance -- a development that could contribute to the long-term erosion of democratic structures. To prevent societies from increasingly fragmenting, Thurner emphasizes the importance of learning early how to engage with different opinions and actively cultivating tolerance.
The research was published in Proceedings of the National Academy of Sciences.
Role Playing (Games)

Dungeons & Dragons Brings Purpose and Fulfillment - and Maybe Structure and Connection for Retirees? (phys.org) 36

"Around tables cluttered with dice, maps and character sheets, players are doing far more than playing," writes Phys.org. It's what sociologists call serious leisure — "a hobby that demands skill, commitment and personal fulfillment," according to an associate professor/program director for Florida International University's Rehabilitation and Recreational Therapy Program: To understand what makes D&D more than just a pastime, [associate professor Emily Messina] studies how games like this promote identity-building and connection... Beyond personal expression, Messina says the social and emotional benefits of D&D reflect the very traits that make serious leisure valuable: the sense of identity, the relationships built through shared experiences and the continued connection with the same group of people over time... The game can also provide structure and purpose for people managing mental illness who might not be able to hold a full-time job because of their symptoms. The game gives them structure versus filling their day with binge streaming...

Activities such as D&D can be used by young children as a reward structure or with older adults, such as retirees, to help provide a sense of purpose and daily rhythm. "Post retirement is one of the most dangerous points in an adult's life," she said. "They lose that sense of structure and possibly their social connection." Building structure through leisure pursuits after retirement has been shown to help maintain physical fitness, social interaction, cognitive processing and attention span and decrease depression. "The idea of structure and reward with desired pursuit can work for all ages," Messina said.

The research was published in Leisure Studies.
Network

A Single Point of Failure Triggered the Amazon Outage Affecting Million (arstechnica.com) 32

An anonymous reader quotes a report from Ars Technica: The outage that hit Amazon Web Services and took out vital services worldwide was the result of a single failure that cascaded from system to system within Amazon's sprawling network, according to a post-mortem from company engineers. [...] Amazon said the root cause of the outage was a software bug in software running the DynamoDB DNS management system. The system monitors the stability of load balancers by, among other things, periodically creating new DNS configurations for endpoints within the AWS network. A race condition is an error that makes a process dependent on the timing or sequence events that are variable and outside the developers' control. The result can be unexpected behavior and potentially harmful failures.

In this case, the race condition resided in the DNS Enactor, a DynamoDB component that constantly updates domain lookup tables in individual AWS endpoints to optimize load balancing as conditions change. As the enactor operated, it "experienced unusually high delays needing to retry its update on several of the DNS endpoints." While the enactor was playing catch-up, a second DynamoDB component, the DNS Planner, continued to generate new plans. Then, a separate DNS Enactor began to implement them. The timing of these two enactors triggered the race condition, which ended up taking out the entire DynamoDB. [...] The failure caused systems that relied on the DynamoDB in Amazon's US-East-1 regional endpoint to experience errors that prevented them from connecting. Both customer traffic and internal AWS services were affected.

The damage resulting from the DynamoDB failure then put a strain on Amazon's EC2 services located in the US-East-1 region. The strain persisted even after DynamoDB was restored, as EC2 in this region worked through a "significant backlog of network state propagations needed to be processed." The engineers went on to say: "While new EC2 instances could be launched successfully, they would not have the necessary network connectivity due to the delays in network state propagation." In turn, the delay in network state propagations spilled over to a network load balancer that AWS services rely on for stability. As a result, AWS customers experienced connection errors from the US-East-1 region. AWS network functions affected included the creating and modifying Redshift clusters, Lambda invocations, and Fargate task launches such as Managed Workflows for Apache Airflow, Outposts lifecycle operations, and the AWS Support Center.
Amazon has temporarily disabled its DynamoDB DNS Planner and DNS Enactor automation globally while it fixes the race condition and add safeguards against incorrect DNS plans. Engineers are also updating EC2 and its network load balancer.

Further reading: Amazon's AWS Shows Signs of Weakness as Competitors Charge Ahead

Slashdot Top Deals