Businesses

Saudi Arabia To Invest $37 Billion in Gaming (axios.com) 41

Saudi Arabia's government-funded gaming conglomerate The Savvy Gaming Group will invest $37.8 billion in gaming as part of a controversial effort to expand the kingdom's role in the sector. From a report: Savvy is primed to buy up a lot of gaming companies and start many of its own. Savvy has earmarked more than $13 billion "for the acquisition and development of a leading game publisher to become a strategic development partner," according to the kingdom's press agency. Another $18 billion is pegged for minority investments. Savvy's efforts are expected to establish 250 game companies and create 39,000 jobs, the press agency noted. The investments are announced by Saudi Crown Prince Mohammed bin Salman.
Media

Google Wants To Take On Dolby With New Open Media Formats (protocol.com) 56

An anonymous reader quotes a report from Protocol: Google is gunning for Dolby Atmos and Dolby Vision: The company is looking to introduce two new media formats to offer HDR video and 3D audio under a new consumer-recognizable brand without the licensing fees hardware manufacturers currently have to pay Dolby. Google shared plans for the media formats, which are internally known as Project Caviar, at a closed-door event with hardware manufacturers earlier this year. In a video of the presentation that was leaked to Protocol, group product manager Roshan Baliga describes the goal of the project as building "a healthier, broader ecosystem" for premium media experiences. The company's primary focus for Project Caviar is YouTube, which does not currently support Dolby Atmos or Dolby Vision. However, Google also aims to bring other industry players on board, including device manufacturers and service providers. This makes Project Caviar one of Google's most ambitious pushes for open media formats since the company began working on royalty-free video codecs over a decade ago.

Google's open media efforts have until now primarily focused on the development of codecs. The company acquired video codec maker On2 in 2009 to open source some of its technology; it has also played a significant role in the foundation of the Alliance for Open Media, an industry consortium that is overseeing the royalty-free AV1 video codec. Project Caviar is different from those efforts in that it is not another codec. Instead, the project focuses on 3D audio and HDR video formats that make use of existing codecs but allow for more rich and immersive media playback experiences, much like Dolby Atmos and Dolby Vision do. Baliga didn't mention Dolby by name during his presentation, but he still made it abundantly clear that the company was looking to establish alternatives to the Atmos and Vision formats. "We realized that there are premium media experiences where there aren't any great royalty-free solutions," he said, adding that the licensing costs for premium HDR video and 3D audio "can hurt manufacturers and consumers."

Dolby makes most of its money through licensing fees from hardware manufacturers. The company charges TV manufacturers $2 to $3 to license Dolby Vision, according to its Cloud Media Solutions SVP Giles Baker. Dolby hasn't publicly disclosed licensing fees for Atmos; it charges consumers who want to add immersive audio to their Xbox consoles $15 per license, but the fee hardware manufacturers have to pay is said to be significantly lower. Still, in an industry that long has struggled with razor-thin margins, every extra dollar matters. That's especially true because Dolby already charges virtually all device makers a licensing fee for its legacy audio codecs. A manufacturer of streaming boxes that wholesale for $50 has to pay around $2 per unit for Dolby Vision and Dolby Digital, according to a document an industry insider shared with Protocol. "For lower-cost living room devices, the cost may be prohibitive," Baliga said during his presentation.

Mozilla

DuckDuckGo, Proton, Mozilla Throw Weight Behind Bill Targeting Big Tech 'Surveillance' (techradar.com) 5

A group of privacy-focused organizations have signed a letter imploring US Congress leaders to schedule a vote on a bill that would hamper data collection by tech giants and promote user access to online privacy tools. From a report: In its letter to Congress, addressed to the likes of Mitch McConnell and Nancy Pelosi, the alliance argued that the continued suppression of the American Innovation and Choice Online Act (AICOA) allows "dominant firms" to "limit competition and restrict user choice" when accessing privacy-focused technologies and products. It also accused tech giants of forcing users into accepting their policies of "perpetual surveillance" because of their positions as "gatekeepers," and of using their "influence in society" to steer users away from rival services more committed to privacy. Signatories included the likes of DuckDuckGo, Proton, Brave and Mozilla, among others, representing sectors ranging from VPN and search to web browsers, office software, and more. The letter to Congress fighting for the revival of the AICOA hit back at the idea that the US technology industry is a free market. The 13 signatories, all of which are relatively small in stature, claim the tech giants deliberately wield the depth and breadth of their product portfolios to establish unassailable monopolies.
Android

Will Google's 'Cross-Device' Development Kit Bring Android Apps to Non-Android Devices? (theverge.com) 20

Google is trying "to make it easier for developers to create Android apps that connect in some way across a range of devices," reports the Verge. Documentation for the software development kit says it will simplify development for "multi-device experiences."

"The Cross device SDK is open-source and will be available for different Android surfaces and non-Android ecosystem devices (Chrome OS, Windows, iOS)," explains the documentation, though the current developer preview only works with Android phones and tablets, according to the Verge.

But they report that Google's new SDK "contains the tools developers need to make their apps play nice across Android devices, and, eventually non-Android phones, tablets, TVs, cars, and more." The SDK is supposed to let developers do three key things with their apps: discover nearby devices, establish secure connections between devices, and host an app's experience across multiple devices. According to Google, its cross-device SDK uses Wi-Fi, Bluetooth, and ultra-wideband to deliver multi-device connectivity.... [I]t could let multiple users on separate devices choose items from a menu when creating a group food order, saving you from passing your phone around the room. It could also let you pick up where you left off in an article when swapping from your phone to a tablet, or even allow the passengers in a car to share a specific map location with the vehicle's navigation system.

It almost sounds like an expansion of Nearby Share, which enables users on Android to transfer files to devices that use Chrome OS and other Androids. In April, Esper's Mishaal Rahman spotted an upcoming Nearby Share update that could let you quickly share files across the devices that you're signed into Google with. Google also said during a CES 2022 keynote that it will bring Nearby Share to Windows devices later this year.

"This SDK abstracts away the intricacies involved with working with device discovery, authentication, and connection protocols," argues Google's blog post, "allowing you to focus on what matters most — building delightful user experiences and connecting these experiences across a variety of form factors and platforms."
Sci-Fi

Congress Admits UFOs Not 'Man-Made,' Says 'Threats' Increasing 'Exponentially' (vice.com) 286

After years of revelations about strange lights in the sky, first hand reports from Navy pilots about UFOs, and governmental investigations, Congress seems to have admitted something startling in print: it doesn't believe all UFOs are "man-made." Motherboard reports: Buried deep in a report that's an addendum to the Intelligence Authorization Act for Fiscal Year 2023, a budget that governs America's clandestine services, Congress made two startling claims. The first is that "cross-domain transmedium threats to the United States national security are expanding exponentially." The second is that it wants to distinguish between UFOs that are human in origin and those that are not: "Temporary nonattributed objects, or those that are positively identified as man-made after analysis, will be passed to appropriate offices and should not be considered under the definition as unidentified aerospace-undersea phenomena," the document states.

The admission is stunning chiefly because, as more information about the U.S. government's study of UFOs has become public, many politicians have stopped just short of claiming the unidentified objects were extraterrestrial or extradimensional in origin. The standard line is typically that, if UFOs exist, then they're likely advanced -- although human-made -- vehicles. Obama refused to confirm the existence of aliens but did say that people have seen a lot of strange stuff in the sky lately when asked directly on The Late Show with James Corden, for example. But now Congress seems to want to specifically distinguish between objects that are "man-made" and those that are not. The admission is stunning chiefly because, as more information about the U.S. government's study of UFOs has become public, many politicians have stopped just short of claiming the unidentified objects were extraterrestrial or extradimensional in origin.

A large question, of course, is why Congress is seemingly admitting this now, in public. After all, lawmakers are privy to classified information that the general public isn't. "It strains credulity to believe that lawmakers would include such extraordinary language in public legislation without compelling evidence," Marik von Rennenkampff, an Obama-era DoD official, said in an op-ed in The Hill about the budget. According to the op-ed, the comments were first noticed by UFO researcher Douglas Johnson. "This implies that members of the Senate Intelligence Committee believe (on a unanimous, bipartisan basis) that some UFOs have non-human origins," von Rennenkampff continued. "After all, why would Congress establish and task a powerful new office with investigating non-'man-made' UFOs if such objects did not exist?" "Make no mistake: One branch of the American government implying that UFOs have non-human origins is an explosive development."

Government

After Signing US Climate Bill, Biden Plans More Executive Actions to Cut Emissions (spokesman.com) 90

Senior White House officials say even more action is coming on climate change. They're telling the New York Times that U.S. President Joe Biden plans "a series of executive actions to further reduce greenhouse gas emissions and help keep the planet from warming to dangerous temperatures."

Biden is on track to deploy a series of measures, including new regulations on emissions from vehicle tailpipes, power plants and oil and gas wells, the officials said.

In pushing more executive action, Mr. Biden is trying to make up for the compromises his party made on climate measures to pass the Inflation Reduction Act, which includes the largest single American investment to slow global warming. Democrats had to scale back some of their loftiest ambitions, including by agreeing to fossil fuel and drilling provisions, as concessions to Senator Joe Manchin III, Democrat of West Virginia, a holdout from a conservative state that is heavily dependent on coal and gas. Gina McCarthy, the White House climate adviser, said that regulatory moves, combined with the new legislation and action from states, could help Mr. Biden meet his promise to cut greenhouse gas emissions by 50 percent, compared to 2005 levels, by the end of the decade. The climate bill, she said, was "a starting point."

"The president has not chosen to just look at Congress, he's chosen to recognize that he has presidential authorities and responsibilities under the law to keep moving this forward," she said. "And he's going to continue to use those." [...] Ms. McCarthy noted the E.P.A. still has "broad authority" to regulate emissions from electricity generation. She also said the government is forging ahead with new regulations on soot and other traditional air pollutants, which will have the side benefit of cutting carbon emissions.... Mr. Biden has the executive authority to issue regulations through federal agencies, and under the Clean Air Act of 1970 can establish rules to address air pollution.

Crime

Police Used a Baby's DNA To Investigate Its Father For a Crime (wired.com) 74

An anonymous reader quotes a report from Wired: If you were born in the United States within the last 50 or so years, chances are good that one of the first things you did as a baby was give a DNA sample to the government. By the 1970s, states had established newborn screening programs, in which a nurse takes a few drops of blood from a pinprick on a baby's heel, then sends the sample to a lab to test for certain diseases. Over the years, the list has grown from just a few conditions to dozens. The blood is supposed to be used for medical purposes -- these screenings identify babies with serious health issues, and they have been highly successful at reducing death and disability among children. But a public records lawsuit filed last month in New Jersey suggests these samples are also being used by police in criminal investigations. The lawsuit, filed by the state's Office of the Public Defender and the New Jersey Monitor, a nonprofit news outlet, alleges that state police sought a newborn's blood sample from the New Jersey Department of Health to investigate the child's father in connection with a sexual assault from the 1990s.

Crystal Grant, a technology fellow at the American Civil Liberties Union, says the case represents a "whole new leap forward" in the misuse of DNA by law enforcement. "It means that essentially every baby born in the US could be included in police surveillance," she says. It's not known how many agencies around the country have sought to use newborn screening samples to investigate crimes, or how often those attempts were successful. But there is at least one other instance of it happening. In December 2020, a local TV station reported that police in California had issued five search warrants to access such samples, and that at least one cold case there was solved with the help of newborn blood. "This increasing overreach into the health system by police to get genetic information is really concerning," Grant says.

The New Jersey lawsuit alleges that police obtained the blood sample of a newborn child (who is now elementary-school aged) to perform a DNA analysis that linked the baby's father to a crime. This was done using a technique called investigative genetic genealogy, or forensic genealogy. It usually involves isolating DNA left at a crime scene and using it to create a digital genetic profile of a suspect. Investigators can upload this profile to genealogy websites where other people have freely shared their own DNA information in the hope of connecting with family members or learning about their ancestry. Because DNA is shared within families, investigators can use relative matches to map out a suspect's family tree and narrow down their identity. According to the New Jersey lawsuit, police had reopened an investigation into a cold case and had used genetics to place the suspect within a single family: one of several adults or their children. But police didn't yet have probable cause to obtain search warrants for DNA swabs from any of them. Instead, they asked the state's newborn screening lab for a blood sample of one of the children. Analysis of this genetic information revealed a close relationship between the baby's DNA and the DNA taken at the crime scene, indicating that the baby's father was the person police were seeking. That was enough to establish probable cause in the assault investigation, so police sought a warrant for a cheek swab from the father. After analyzing his DNA, the suit contends, police found that it was a match to the crime scene DNA.
"Because there are no federal laws governing newborn screening programs, states set their own policies on which diseases they test for, how long samples are stored, and how they can be used," notes Wired. "Some states hold on to blood samples for months, others for years or decades. Virginia only keeps samples from infants with normal results for six months, while Michigan retains them for up to 100 years. New Jersey stores samples for 23 years before destroying them."
Earth

India To Order Use of Cleaner Fuels Under Push for Net-Zero (bloomberg.com) 26

India plans to order consumers to use cleaner fuels and aims to establish a carbon market under legislation to bolster the country's push to hit net-zero greenhouse gas emissions by 2070. From a report: The world's third-biggest emitter will seek to mandate the use of a minimum share of non-fossil fuel sources including biomass, ethanol, green hydrogen and ammonia, both for power generation or as a feedstock for manufacturing, according to a document introduced in Parliament on Wednesday. New laws would also penalize industrial operations, vehicles, ships and large buildings for not meeting energy consumption standards.

Changes to the Energy Conservation (Amendment) Bill have a "special focus on the promotion of new and renewable energy" and the country's so-called National Hydrogen Mission, a strategy aimed at establishing India as a key global hub for development of the nascent zero-emissions fuel, according to the legislation. The proposed policy changes come as India chases Prime Minister Narendra Modi's target to cut 1 billion tons of carbon emissions by the end of this decade, and to reach to net-zero by 2070. They also coincide with the country's pledge to cut emissions by 45% from 2005 levels and use non-fossil fuel sources to power half its installed generation capacity by the end of this decade.

Businesses

Leaked Amazon Memo Reveals Anti-Union PR Idea: Score Points by Hiring Former Inmates (vox.com) 89

Someone leaked an internal Amazon memo to Vox's Recode. The May 2021 memo "offers rare insights into the anti-union strategies of one of the world's most powerful companies," Recode writes: The memo laid out two crucial goals for Amazon: establish and deepen "relationships with key policymakers and community stakeholders" and improve "Amazon's overall brand...." To achieve these goals, the memo proposed strategies to help Amazon boost its reputation and simultaneously "neutralize" company critics by befriending these critics' own allies and by launching feel-good initiatives to turn the media and local politicians into company boosters....

Amazon staff acknowledged in the memo that the Teamsters' "economic argument is ... currently stronger," with union truck drivers, warehouse workers, and grocery store staff earning better or equal compensation packages as Amazon employees in the Southern California region the memo focused on. (A few months later, in September 2021, Amazon announced it had raised its average starting wage for front-line workers to $18 an hour, though many workers make less than that....) Amazon shrewdly planned to "intentionally seek partnerships with some organizations that work closely with our opposition." Those included organizations dedicated to helping incarcerated people find stable work upon reentry into society, such as the Anti-Recidivism Coalition, Homeboy Industries, and Defy Ventures, all named in the memo....

Taken together, these proposals are an unsurprising but stark reminder that, as is the case with many corporations, Amazon's public-facing actions are overwhelmingly in service of promoting or protecting the company, often in reaction to critics demanding that the company improve its labor practices. The billboards and TV commercials selling the narrative of Amazon as a great place to work, and the PR-friendly community partnerships in towns across the country where Amazon wants to set up shop, are developed for these reasons. Altruism this is not....

Overall, the memo highlights the extent to which union-led criticisms are creating sizable obstacles to Amazon's growth plans in its most crucial US market. But they also serve as a clear reminder that the company possesses vast resources to combat critics, and cunning strategies to portray reputation makeovers as corporate benevolence.

China

HSBC Becomes First Foreign Bank To Launch Chinese Communist Party Committee (fortune.com) 83

One of the world's biggest banks, and Europe's second-largest lender, is showing that it's playing by China's rules. From a report: London-headquartered HSBC has become the first international bank to establish a Chinese Communist Party (CCP) committee, according to a new Financial Times report. China's companies law requires firms to set up CCP committees, but this rule has been loosely enforced among global financial institutions -- until now. HSBC's move could pave the path for other global lenders to follow suit, and underscores the delicate line that China-based foreign banks are now toeing between Beijing and the West. HSBC's China investment bank, known as HSBC Qianhai Securities, recently formed the CCP committee, as per the FT report that cited two people familiar with the decision. In China, company employees can initiate CCP committees, which are typically made up of three or more staff. The committees have two functions: to act as a workers' union, and to facilitate installing a party representative to a company's top ranks.
United States

Biden Administration Pushes To Close the Growing Cybersecurity Workforce Gap (cnn.com) 104

The Biden administration is pushing to fill hundreds of thousands of cybersecurity jobs in the United States as part of a bid to close a talent shortage US officials describe as both a national security challenge and an economic opportunity. From a report: On Tuesday, the administration announced a multi-agency plan to create hundreds of registered apprenticeship programs with the private sector to flesh out the nation's cybersecurity workforce -- and defend against a rising tide of data breaches, ransomware attacks and other hacking incidents. In a 120-day sprint, the US government will work with employers to establish apprenticeship programs in the cybersecurity industry, said Labor Secretary Marty Walsh, vowing to launch the joint program with the Department of Commerce "in as little as 48 hours."

The initiative draws funding from a wider $500 million Commerce Department program known as the Good Jobs Challenge, and will particularly focus on recruiting young people, women and minorities to train and work in the cybersecurity field, said Walsh and Commerce Secretary Gina Raimondo at a White House event on Tuesday focused on broader cyber workforce issues. The US government commitment highlights what officials describe as a critical lack of cybersecurity professionals in both government and the private sector who can help protect the nation from foreign adversaries and cybercriminals. Months ago, there were an estimated 500,000 unfilled cybersecurity positions in the United States, Raimondo said, but today that figure has exploded to more than 700,000, a 40% increase.

Earth

MIT Scientists Propose 'Space Bubbles' to Deflect Solar Radiation, Ease Climate Change (popularmechanics.com) 86

Popular Science reports: A raft of thin-film silicon bubbles deployed from Earth into outer space and stretching to the size of Brazil could potentially block the Sun's solar radiation from further warming Earth, possibly helping to not only stave off climate change, but potentially reverse it.

This new "space bubbles" plan offered by scientists at the Massachusetts Institute of Technology rifts off a concept first offered by astronomer Roger Angel. The multidisciplinary team of architects, civil and mechanical engineers, physicists and material scientists have worked on the technical and social aspects of what the group calls a "planetary-scale project" in an effort to find a non-Earth-bound solution to climate change.

The MIT group believes that if the raft of bubbles can deflect 1.8 percent of incident solar radiation before it hits Earth, they can fully reverse today's global warming. Even if they can't establish a 1.8 percent shading, they trust a smaller percentage provides enough benefit to help mitigate global warming.

To make it happen, the group proposes deploying small, inflatable bubbles into outer space that they could then manufacture into a space raft the size of Brazil and suspend near the L1 Lagrangian Point, the location between the Earth and Sun where the gravitational influence of both bodies cancel out. The team does suggest having some sort of system to ensure the raft stays in place and that may provide the ability to move the bubbles closer to the Sun for optimal impact....

MIT cautions they don't view the project as a replacement to current adaption and mitigation efforts, but as a backup solution should climate change spin out of control...

They plan to investigate low vapor-pressure materials to rapidly inflate and assemble the rafts, whether with a silicon-based melt or a graphene-reinforced ionic liquid... The team also believes a bit of science fiction may help in finding "novel ways" of shipping the material to space, such as a magnetic accelerator, known as a railgun.

Sci-Fi

UFO Whistleblowers Would Get Immunity Under New Amendment (thedrive.com) 59

Howard Altman writes via The Drive: In an effort to protect those with information about unidentified aerial phenomena (UAP) and increase the influx of reports about them, Rep. Mike Gallagher (R-Wisc) has introduced (PDF) an amendment to the Fiscal Year 2023 National Defense Authorization Act. "The amendment would establish a process within the government for reporting UAPs and provide whistleblower-like protections," Gallagher's spokesman Jordan Dunn told The War Zone Thursday morning. For a multitude of reasons, U.S. troops and government contractors have traditionally been reluctant to come forward with information about these incidents, regardless of their validity. Beyond that, there have also been long-standing allegations that the government and defense contractors could be hiding previous UFO-related programs and evidence. This would allow those with information to come forward without retribution. Some have even posited that language like that in Gallagher's amendment could lead to "UFO disclosure."

In essence, it says that regardless of any previous written or oral non-disclosure agreements "that could be interpreted as a legal constraint on reporting by a witness of an unidentified aerial phenomena," those with information about UAPs, more commonly known as UFOs, would not be violating federal classified information laws if they come forward. The amendment also calls for the head of the new Airborne Object Identification and Management Synchronization Group (AOIMSG), tasked with investigating UAPs on behalf of the Defense Secretary and Director of National Intelligence, to establish "a secure system" for receiving reports of "any events relating to" UAPs and any government or government contractor activity or program related to UAPs. The reporting system shall be administered by "designated and widely known, easily accessible, and appropriately cleared Department of Defense and intelligence community employees or contractors" as part of AOIMSG, which is a much enhanced and more deeply mandated effort that replaced the Unidentified Aerial Phenomena Task Force.

Any information would first be screened "to prevent unauthorized public reporting or compromise of properly classified military and intelligence systems, programs, and related activity, including all categories and levels of special access and compartmented access programs, current, historical, and future." However, federal agencies and contractors working with the government would be precluded from taking actions, including suspending security clearances, for those who report UAP incidents and information. And those who are retaliated against "may bring a private civil action for all appropriate remedies, including injunctive relief and compensatory and punitive damages, against the Government or other employer who took the personnel action, in the United States Court of Federal Claims," the amendment states.

United States

Online Privacy Bill Clears Early Hurdle in House (wsj.com) 33

Bipartisan legislation to establish broad privacy rights for consumers won approval from a House subcommittee on Thursday, adding to its momentum. From a report: Lawmakers approved the bill, the American Data Privacy and Protection Act, on a voice vote with no dissent. It now moves to the full Energy and Commerce Committee for a vote. The bill still faces a long and potentially difficult path, particularly in the Senate. Rep. Frank Pallone (D., N.J.), the committee chairman and a sponsor of the bill, termed it "a massive step forward."

"Every American knows it is long past time for Congress to protect their data privacy and security," he said. "The modern world demands it." Republicans also praised the legislation, while suggesting more changes might be needed. "This bill protects all Americans, regardless of ZIP Code, and provides certainty for businesses so they clearly understand their obligations," said Rep. Cathy McMorris Rodgers (R., Wash.), the committee's top Republican. She said the legislation also would strengthen national security by requiring companies such as TikTok -- owned by Beijing-based ByteDance -- to specify when they are transferring and storing consumers' data in countries such as China.

Moon

NASA Taps Three Companies To Design Nuclear Power Plants For the Moon (techcrunch.com) 246

NASA announced on Tuesday that it's contracting three suppliers to provide concept designs for nuclear fission energy systems designed for use on the moon. TechCrunch reports: The winning bids for this award came from Lockheed Martin, Westinghouse and IX (a joint venture from Intuitive Machines and X-Energy). Each will be working with a few partners to develop their systems, which will be "initial concepts" only for the purposes of satisfying this particular contract, and each will receive roughly $5 million for their work, expected to take around 12 months.

NASA is aptly partnering with the Department of Energy (DOE) on this project, and the specs include a 40-kilowatt power generation capability, capable of generating that for at least a decade. That's about what a full charge on a current entry-level Nissan Leaf contains -- but as a fission generator it would obviously provide that continuously. It may not seem like much, but deployed singularly or in groups to support a lunar base, it could solve a lot of the challenges of the kind of prolonged occupancy of the moon that NASA plans to eventually establish through its Artemis program, which seeks to return humans to our largest natural satellite for ongoing science missions. NASA also notes that the work done for this contract could have other future applications for propulsion systems for long-range spacecraft for deep space explorations.

Intel

A New Vulnerability in Intel and AMD CPUs Lets Hackers Steal Encryption Keys (arstechnica.com) 30

Microprocessors from Intel, AMD, and other companies contain a newly discovered weakness that remote attackers can exploit to obtain cryptographic keys and other secret data traveling through the hardware, researchers said on Tuesday. From a report: Hardware manufacturers have long known that hackers can extract secret cryptographic data from a chip by measuring the power it consumes while processing those values. Fortunately, the means for exploiting power-analysis attacks against microprocessors is limited because the threat actor has few viable ways to remotely measure power consumption while processing the secret material. Now, a team of researchers has figured out how to turn power-analysis attacks into a different class of side-channel exploit that's considerably less demanding.

The team discovered that dynamic voltage and frequency scaling (DVFS) -- a power and thermal management feature added to every modern CPU -- allows attackers to deduce the changes in power consumption by monitoring the time it takes for a server to respond to specific carefully made queries. The discovery greatly reduces what's required. With an understanding of how the DVFS feature works, power side-channel attacks become much simpler timing attacks that can be done remotely. The researchers have dubbed their attack Hertzbleed because it uses the insights into DVFS to expose -- or bleed out -- data that's expected to remain private. The vulnerability is tracked as CVE-2022-24436 for Intel chips and CVE-2022-23823 for AMD CPUs. The researchers have already shown how the exploit technique they developed can be used to extract an encryption key from a server running SIKE, a cryptographic algorithm used to establish a secret key between two parties over an otherwise insecure communications channel.

Bitcoin

New York Passes a Bill To Limit Bitcoin Mining (engadget.com) 84

New York lawmakers have passed a bill that would temporarily ban new bitcoin mining operations. Early on Friday, state senators voted 36-27 to pass the legislation. It's now bound for the desk of Governor Kathy Hochul, who will sign it into law or veto the bill. The law would come into effect immediately after it's signed. From a report: An attempt to enact similar legislation last year hit a wall when the New York State Senate passed it but Assembly members did not. The latest bill passed the Assembly in April. The legislation seeks to establish a two-year moratorium on licenses for cryptocurrency mining operations that use power-hungry proof-of-work authentication methods for validating blockchain transactions. Right now, bitcoin and ethereum (the two largest cryptocurrencies) fall under that category, though the latter is shifting to a different setup. The moratorium only covers mining operations that run on carbon-based power sources. Any that harness entirely renewable energy sources or an alternative to proof of work that requires less power won't be affected. Existing operations and those already going through a permit renewal process won't be impacted either.
Canada

Tim Hortons App Violated Laws In Collection of 'Vast Amounts' of Location Data (www.cbc.ca) 117

An anonymous reader quotes a report from CBC News: The federal privacy commissioner's investigation into the Tim Hortons mobile app found that the app unnecessarily collected extensive amounts of data without obtaining adequate consent from users. The commissioner's report, which was published Wednesday morning, states that Tim Hortons collected granular location data for the purpose of targeted advertising and the promotion of its products but that the company never used the data for those purposes. "The consequences associated with the App's collection of that data, the vast majority of which was collected when the App was not in use, represented a loss of Users' privacy that was not proportional to the potential benefits Tim Hortons may have hoped to gain from improved targeted promotion of its coffee and associated products," the report read.

The joint investigation was launched about two years ago by the Office of the Privacy Commissioner of Canada in conjunction with similar authorities in British Columbia, Quebec and Alberta. It came after reporting from the Financial Post found that the Tim Hortons app tracked users' geolocation while users were not using the app. According to a presentation to investors shared in May, the restaurant chain's app has four million active users.

Tim Hortons was using a third-party service provider, Radar, to collect geolocation data of users. In August 2020, Tim Hortons stopped collecting location data. However, the investigation found that there was a lack of contractual protections for users' personal information while being processed by Radar. The report describes the language in the contractual clauses to be "vague and permissive," which could have allowed Radar to use the personal information collected in aggregated or de-identified form for its own business. [...] The report states that Tim Hortons also agreed to delete all granular location data and to have third-party service providers do so as well, as per recommendations from the privacy authorities. The company also agreed to establish a privacy management program for its app and all future apps to ensure they are compliant with federal and provincial privacy legislation. Given these remedies, the report found that while the Tim Hortons app was not compliant with privacy laws, the company has since taken measures to resolve the issues.
"We've strengthened our internal team that's dedicated to enhancing best practices when it comes to privacy and we're continuing to focus on ensuring that guests can make informed decisions about their data when using our app," a statement from Tim Hortons released on Wednesday said.
Technology

Singapore Starts Digital-Asset Initiative (bloomberg.com) 11

Singapore has begun a project to investigate potential uses of asset tokenization as the city state looks to establish itself as a hub for decentralized finance after several key crypto players left. From a report: "Project Guardian," a collaboration between the Monetary Authority of Singapore and the finance industry, will test the feasibility of applications in asset tokenization and decentralized finance (DeFi) while working to manage risks to financial stability and integrity, according to a statement from Deputy Prime Minister Heng Swee Keat on Tuesday.

The project aims to develop and pilot use cases in areas including open, interoperable networks; trust anchors; and institutional-grade DeFi protocols. The first pilot in the project will explore potential DeFi applications in wholesale funding markets. The pilot, led by DBS Bank, JPMorgan Chase and Marketnode, involves the creation of a permissioned liquidity pool comprising tokenized bonds and deposits. The MAS was relatively early among regulators to look at uses of blockchain technology, and Singapore set up a licensing regime a few years ago. However, applicants have been frustrated by the slowness of approvals, and a crypto advertising ban caught the industry off guard.

PlayStation (Games)

Sony Readies For 'Metaverse Revolution' With Cross-Platform Push (reuters.com) 32

Japanese conglomerate Sony said it is well-positioned to play a leading role in the metaverse, or immersive virtual worlds, which commentators speculate will massively disrupt industries and establish new powerhouses. From a report: "The metaverse is at the same time a social space and live network space where games, music, movies and anime intersect," Chief Executive Kenichiro Yoshida said at a strategy briefing on Wednesday, pointing to the use of free-to-play battle royale title Fortnite from Epic Games as an online social space. Sony's game, music and movie units contributed two-thirds of operating income in the year ended March, underscoring the group's transformation from consumer electronics maker into a metaverse-ready entertainment juggernaut under Yoshida and predecessor Kazuo Hirai. The firm is a gaming gatekeeper with its PlayStation 5 console, however observers point to the risk presented by the growth of cross-platform, cloud-based titles and their potential to reduce the influence of proprietary platforms. Sony has been adjusting its approach, enabling cross-play in Fortnite in 2018.

Slashdot Top Deals