Power

Hyundai and LG Announce $4.3 Billion Plant in Georgia To Build Batteries for Electric Vehicles (apnews.com) 19

Hyundai Motor and LG Energy have announced they will build a $4.3 billion electric battery plant as part of Hyundai's new electric vehicle assembly plant in southeast Georgia. From a report: The companies will split the investment, starting production as soon as late 2025. Hyundai Motor CEO Jaehoon Chang said in a statement that the battery plant would "create a strong foundation to lead the global EV transition," explaining the company wants to speed up efforts to produce electrified Hyundai and Kia vehicles in North America. "Hyundai Motor Group is focusing on its electrification efforts to secure a leadership position in the global auto industry," Chang said. The South Korean automaker said in 2022 it would invest $5.5 billion to assemble electric vehicles and batteries in Ellabell, just west of Savannah. The site is supposed to have 8,100 employees and is slated to begin producing vehicles in 2025.
The Courts

Supreme Court Declines To Hear Challenge To Warrantless Pole Camera Surveillance (aclu.org) 120

An anonymous reader shares a press release from the American Civil Liberties Union (ACLU): The U.S. Supreme Court [Monday] declined to hear Moore v. United States, leaving in place a patchwork of lower court decisions on an important and recurring question about privacy rights in the face of advancing surveillance technology. In this case, police secretly attached a small camera to a utility pole, using it to surveil a Massachusetts home 24/7 for eight months -- all without a warrant. Law enforcement could watch the camera's feed in real time, and remotely pan, tilt, and zoom close enough to read license plates and see faces. They could also review a searchable, digitized record of this footage at their convenience. The camera captured every coming and going of the home's residents and their guests over eight months. As a result, the government targeted the home of a community pillar -- a lawyer, respected judicial clerk, devoted church member, and a grandmother raising her grandkids -- to cherry-pick images from months of unceasing surveillance in an effort to support unwarranted criminal charges against an innocent person.

Federal courts of appeals and state supreme courts have divided on the question of whether such sweeping surveillance is a Fourth Amendment search requiring a warrant. The highest courts of Massachusetts, Colorado, and South Dakota have held that long-term pole camera surveillance of someone's home requires a warrant. In Moore v. United States, the members of the full en banc U.S. Court of Appeals for the First Circuit split evenly on the question, with three judges explaining that a warrant is required, and three judges expressing the belief that the Fourth Amendment imposes no limit on this invasive surveillance. This issue will continue to arise in the lower courts; the ACLU filed an amicus brief on the question in the U.S. Court of Appeals for the Tenth Circuit earlier this month.
"The Supreme Court's decision not to hear this case means that people across the country remain vulnerable to law enforcement's claim of unfettered authority to surveil any of us at our homes, for as long as they wish, with no judicial oversight," said Nathan Freed Wessler, deputy director of the ACLU's Speech, Privacy, and Technology Project. "As the cost of surveillance technology falls and its use by law enforcement expands, the need to resolve whether the Fourth Amendment poses any constraint has become all the more urgent. We will continue fighting for essential privacy protections."
Hardware

Raspberry Pi CEO Eben Upton Discusses Stock Updates, Industry Prioritization (tomshardware.com) 59

An anonymous reader quotes a report from Tom's Hardware: YouTuber Jeff Geerling recently flew over to the UK to sit down with Raspberry Pi CEO Eben Upton for a chat about shortages, predictions, the Raspberry Pi Pico and other hot topics. The short of it is that stock levels are improving, close to Upton's 2022 prediction and that we are now seeing better stock levels than 2022 as Raspberry Pi slowly catches up with the backlog. Upton explained the reasoning behind prioritizing OEM customers over consumers, and addresses some of the negativity that was levied on Raspberry Pi by a minority of the passionate and vocal community.

The video starts with Geerling candidly explaining that his trip to the UK was not funded by Raspberry Pi, rather it was funded via sponsorship and Patreon supporters. With that out of the way Geerling covers a series of topics with Upton, and we've been through the video and pulled out the key points, with timestamps for you to listen to.
In regard to the company's product and shipment progress, Upton said: "So quarter one this year was our worst quarter in terms of production and shipment. [...] We did about 750 to 800,000 units in Q1 this year [due to shifting production during the Christmas period]."

With progress being made on filling backlog and availability, Upton said the company expects to move two million units in the second quarter, with the third and fourth quarters of 2023 being "unconstrained."
AI

Hippocratic Is Building a Large Language Model For Healthcare 36

An anonymous reader quotes a report from TechCrunch: AI, specifically generative AI, has the potential to transform healthcare. At least, that's the sales pitch from Hippocratic AI, which emerged from stealth today with a whopping $50 million in seed financing behind it and a valuation in the "triple-digit millions." The tranche, co-led by General Catalyst and Andreessen Horowitz, is a big vote of confidence in Hippocratic's technology, a text-generating model tuned specifically for healthcare applications.

Hippocratic -- hatched out of General Catalyst -- was founded by a group of physicians, hospital administrators, Medicare professionals and AI researchers from organizations including Johns Hopkins, Stanford, Google and Nvidia. After co-founder and CEO Munjal Shah sold his previous company, Like.com, a shopping comparison site, to Google in 2010, he spent the better part of the next decade building Hippocratic. "Hippocratic has created the first safety-focused large language model (LLM) designed specifically for healthcare," Shah told TechCrunch in an email interview. "The company mission is to develop the safest artificial health general intelligence in order to dramatically improve healthcare accessibility and health outcomes."

Shah emphasized that Hippocratic isn't focused on diagnosing. Rather, he says, the tech -- which is consumer-facing -- is aimed at use cases like explaining benefits and billing, providing dietary advice and medication reminders, answering pre-op questions, onboarding patients and delivering "negative" test results that indicate nothing's wrong. [...] Shah claims that Hippocratic's AI outperforms leading language models including GPT-4 and Claude on more than 100 healthcare certifications, including the NCLEX-RN for nursing, the American Board of Urology exam and the registered dietitian exam.
Hippocratic aims to have its LLM detect tone and communicate empathy better than its rivals -- in part by "building in" good bedside manner, says Shah. They have designed a benchmark to evaluate their model's humanistic qualities, and it scored higher than other models, including GPT-4.

As for whether or not it can replace a healthcare worker, Hippocratic argues that their models, trained under medical professionals' supervision, possess high capabilities.

"We're only releasing each role -- dietician, billing agent, genetic counselor, etc. -- once the people who actually do that role today in real life agree the model is ready," Shah said. "In the pandemic, labor costs went up 30% for most health systems, but revenue didn't. Hence, most health systems in the country are financially struggling. Language models can help them reduce costs by filling their current large level of vacancies in a more cost-effective way."
Google

Google Drops Waitlist for AI Chatbot Bard, Expands To Over 180 Countries (theverge.com) 26

Google is adding a smorgasbord of new features to its AI chatbot Bard, including support for new languages (Japanese and Korean), easier ways to export text to Google Docs and Gmail, visual search, and a dark mode. Most significantly, the company is removing the waitlist for Bard and making the system available in English in 180 countries and territories. From a report: It's also promising future features like AI image generation powered by Adobe and integration with third-party web services like Instacart and OpenTable. Collectively, the news is a shot in the arm for Bard, which was released two months ago for select users in the US and UK. The chatbot -- which Google still stresses is an experiment and not a replacement to its search engine -- has compared poorly to rivals like OpenAI's ChatGPT and Microsoft's new Bing chatbot. Notably, Bard made a factual error in its first-ever public demo (though this problem is common to all such bots). Now, Google is adding a lot of new features as well as upgrading Bard to use its new PaLM 2 language model. This should improve its general answers and usability.

Google says the upgraded Bard is particularly good at tackling coding queries, including debugging and explaining chunks of code in more than 20 languages, so some of today's upgrades are focused on this use case. These include the new dark mode, improved citations for code (which will not only offer sources but also explain the snippets), and a new export button. This can already be used to send code to Google's Colab platform but will now also work with another browser-based IDE, Replit (starting with Python queries).

Social Networks

Pornhub Blocks All of Utah From Its Site 219

In response to a new law that requires porn sites to verify users' ages, Pornhub has completely disabled its websites for people located in Utah. From a report: As of today, anyone accessing Pornhub from a Utah-based IP address doesn't see the Pornhub homepage, but instead is met with a video of Cherie DeVille, adult performer and member of the Adult Performer Advocacy Committee, explaining that they won't be able to visit the site. "As you may know, your elected officials in Utah are requiring us to verify your age before allowing you access to our website," DeVille says. "While safety and compliance are at the forefront of our mission, giving your ID card every time you want to visit an adult platform is not the most effective solution for protecting our users, and in fact, will put children and your privacy at risk."
Privacy

Proton Launches an End-to-End Encrypted Password Manager (theverge.com) 30

Proton, the company behind Proton Mail, has announced the launch of a new password manager: Proton Pass. While the service will eventually become free for everyone to use, it's currently only available as a beta to Proton's Lifetime and Visionary users for now. From a report: As is the case with Proton's other products, Proton Pass uses end-to-end encryption (E2EE) that's supposed to keep your personal information away from prying eyes, including third parties and Proton itself. In addition to letting you store your usernames, passwords, and notes, you can also add any randomly generated email aliases that you can use as a replacement for your real address. Proton's new password manager not only applies E2EE to your passwords but also the usernames, web addresses, and all the other fields associated with your login information. In a blog post explaining the service's security model, Proton notes that "all cryptographic operations, including key generation and data encryption," happen locally on your device, which Protons says it can't decrypt, even if a third party requests it.
Security

'Vulkan Files' Leak Reveals Putin's Global and Domestic Cyberwarfare Tactics (theguardian.com) 42

"The Gaurdian reports on a document leak from Russian cyber 'security' company Vulkan," writes Slashdot reader Falconhell. From the report: Inside the six-storey building, a new generation is helping Russian military operations. Its weapons are more advanced than those of Peter the Great's era: not pikes and halberds, but hacking and disinformation tools. The software engineers behind these systems are employees of NTC Vulkan. On the surface, it looks like a run-of-the-mill cybersecurity consultancy. However, a leak of secret files from the company has exposed its work bolstering Vladimir Putin's cyberwarfare capabilities.

Thousands of pages of secret documents reveal how Vulkan's engineers have worked for Russian military and intelligence agencies to support hacking operations, train operatives before attacks on national infrastructure, spread disinformation and control sections of the internet. The company's work is linked to the federal security service or FSB, the domestic spy agency; the operational and intelligence divisions of the armed forces, known as the GOU and GRU; and the SVR, Russia's foreign intelligence organization.

One document links a Vulkan cyber-attack tool with the notorious hacking group Sandworm, which the US government said twice caused blackouts in Ukraine, disrupted the Olympics in South Korea and launched NotPetya, the most economically destructive malware in history. Codenamed Scan-V, it scours the internet for vulnerabilities, which are then stored for use in future cyber-attacks. Another system, known as Amezit, amounts to a blueprint for surveilling and controlling the internet in regions under Russia's command, and also enables disinformation via fake social media profiles. A third Vulkan-built system -- Crystal-2V -- is a training program for cyber-operatives in the methods required to bring down rail, air and sea infrastructure. A file explaining the software states: "The level of secrecy of processed and stored information in the product is 'Top Secret'."

Advertising

Microsoft Slips Ads Into AI-Powered Bing Chat (theverge.com) 56

An anonymous reader quotes a report from The Verge: Microsoft is "exploring" putting ads in the responses given by Bing Chat, its new search agent powered by OpenAI's GPT-4. Microsoft confirmed this is happening, albeit in an experimental form, in a blog post published today. Here's the relevant bit from the very end after "a bit of context" explaining no one should be surprised: "We are also exploring additional capabilities for publishers including our more than 7,500 Microsoft Start partner brands. We recently met with some of our partners to begin exploring ideas and to get feedback on how we can continue to distribute content in a way that is meaningful in traffic and revenue for our partners.

As we look to continue to evolve the model together, we shared some early ideas we're exploring including:

- An expanded hover experience where hovering over a link from a publisher will display more links from that publisher giving the user more ways to engage and driving more traffic to the publisher's website.
- For our Microsoft Start partners, placing a rich caption of Microsoft Start licensed content beside the chat answer helping to drive more user engagement with the content on Microsoft Start where we share the ad revenue with the partner. We're also exploring placing ads in the chat experience to share the ad revenue with partners whose content contributed to the chat response."

Youtube

Documentary Film Aims To Dispel the Mysteries and Myths of Blockchain Technology (youtube.com) 43

Long-time Slashdot reader mabu writes: Adam R. Smith, a software engineer with 40+ years of experience reportedly became frustrated with his friends and associates' claims about the potential of crypto technology and their subsequent losses of money in various schemes, and set out to write a series of articles explaining what blockchain is and whether it lives up to its claims. This ended up morphing into a passion project that produced an 84 minute documentary entitled, "Blockchain — Innovation or Illusion?

The film, which is currently making the rounds at various film festivals, has recently been released online in its entirety on YouTube. In it, Smith, who goes by the alias, "American Scream" explains what blockchain is in layman's terms, how it relates to conventional databases and tech, and how the crypto industry seems more dependent upon coercive psychology, than innovation. The film addresses a wide variety of topics including, "Is blockchain disruptive?", "Is de-centralization even worthwhile?", and explains the how and why tokens, mining, and other blockchain-based elements like smart contracts and NFTs operate.

In the second half of the film, Smith goes into specific claims and scenarios such as, "Is blockchain really immutable?" and "Can blockchain verify authenticity?" identifying common issues like "The Oracle problem" and whether arguments like, "Crypto helps bank the unbanked" and "Crypto is digital gold" really make sense?

John Reed Stark, former Chief of the SEC Office of Internet Enforcement called Smith one of his favorite technologists and that the film was "spot on" in its characterization of the technology.

Watch the full documentary here.

The Military

Playing Military Sim War Thunder May Get You Classed As a National Security Risk (pcmag.com) 27

Playing the military simulation War Thunder is now reportedly considered an official risk on background checks. PCMag reports: As GamesRadar reports, a user going by the name Add Fiat 6616 Pls posted on the War Thunder subreddit earlier this week explaining how a friend of his had applied for a job at aerospace and defense conglomerate Raytheon Technologies. As part of the security clearance process, a private investigator is used to contact the candidates "witnesses," which is shorthand for their friends. Add Fiat 6616 Pls was one of those friends and therefore received a call to answer a range of questions in an attempt to discover if the candidate's lifestyle raised any red flags. One of those question was: "Does he play War Thunder?"

The question makes sense as part of a security check and national security assessment after you realize how much classified information has leaked via the game over the past few years. War Thunder is a free-to-play vehicular combat online multiplayer game developed by Russian game developer Gaijin Entertainment (which relocated to Budapest in 2015). Since 2021, there have been six incidents of restricted or classified documents being leaked during discussions about the accuracy of the vehicles used in the game.

AI

Google Calls In Help From Larry Page and Sergey Brin For AI Fight (nytimes.com) 56

An anonymous reader quotes a report from the New York Times: Last month, Larry Page and Sergey Brin, Google's founders, held several meetings with company executives. The topic: a rival's new chatbot, a clever A.I. product that looked as if it could be the first notable threat in decades to Google's $149 billion search business. Mr. Page and Mr. Brin, who had not spent much time at Google since they left their daily roles with the company in 2019, reviewed Google's artificial intelligence product strategy, according to two people with knowledge of the meetings who were not allowed to discuss them. They approved plans and pitched ideas to put more chatbot features into Google's search engine. And they offered advice to company leaders, who have put A.I. front and center in their plans.

The re-engagement of Google's founders, at the invitation of the company's current chief executive, Sundar Pichai, emphasized the urgency felt among many Google executives about artificial intelligence and that chatbot, ChatGPT. The bot, which was released by the small San Francisco company OpenAI two months ago, amazed users by simply explaining complex concepts and generating ideas from scratch. More important to Google, it looked as if it could offer a new way to search for information on the internet. The new A.I. technology has shaken Google out of its routine. Mr. Pichai declared a "code red," upending existing plans and jump-starting A.I. development. Google now intends to unveil more than 20 new products and demonstrate a version of its search engine with chatbot features this year, according to a slide presentation reviewed by The New York Times and two people with knowledge of the plans who were not authorized to discuss them.
"This is a moment of significant vulnerability for Google," said D. Sivakumar, a former Google research director who helped found a start-up called Tonita, which makes search technology for e-commerce companies. "ChatGPT has put a stake in the ground, saying, 'Here's what a compelling new search experience could look like.'"

Further reading: Google Axes 12,000 Jobs
Education

Tech-Backed Code.org Bringing BBC Micro:bit To US K-5 Classrooms 21

theodp writes: On Tuesday, the Micro:bit Educational Foundation, a UK-based education non-profit "on a mission to inspire all children to achieve their best digital future," announced a partnership with US-based and tech giant-backed nonprofit Code.org to offer teachers computing resources to complement use of the handheld BBC micro:bit physical computing device as an extension to the Code.org CS Fundamentals curriculum, which is aimed at introducing Computer Science to children in Kindergarten-5th Grade.

"Physical computing is a great way to engage students in computer science, and I'm excited that Code.org is expanding its offerings in this maker education space," said Code.org CEO Hadi Partovi. "We're delighted to partner with micro:bit to provide physical computing extensions to our existing courses." Micro:bit Educational Foundation CEO Gareth Stockdale added, "Growing a diverse pipeline of tech talent who contribute to the creation of better technology in the world begins in the classroom. We are invested in excellence in computer science education for younger students and are excited by the size of the impact we can create together with Code.org to bring the benefits of physical computing to young learners."

Back in 2015, Microsoft -- a Founding Partner of both the Micro:bit Educational Foundation and Code.org -- partnered with the BBC to provide an estimated 1 million free BBC micro:bits to every 11 or 12 year old in the UK. "The chance to influence the lives of a million children does not come often," Microsoft Research wrote in a 2016 paper explaining the efforts to get the micro:bit into the hands of UK schoolchildren and make it part of the CS curriculum. The paper also cited Code.org and the UK's Computing at School (a Micro:bit Educational Foundation partner that was "born at Microsoft Research Cambridge") as "two significant success at the coding level" of "scaling out an initiative to influence an entire country of students, or even globally."
Security

Identity Thieves Bypassed Experian Security To View Credit Reports (krebsonsecurity.com) 40

Identity thieves have been exploiting a glaring security weakness in the website of Experian, one of the big three consumer credit reporting bureausBrian Krebs reported Monday. From the report: Normally, Experian requires that those seeking a copy of their credit report successfully answer several multiple choice questions about their financial history. But until the end of 2022, Experian's website allowed anyone to bypass these questions and go straight to the consumer's report. All that was needed was the person's name, address, birthday and Social Security number. In December, KrebsOnSecurity heard from Jenya Kushnir, a security researcher living in Ukraine who said he discovered the method being used by identity thieves after spending time on Telegram chat channels dedicated to the cashing out of compromised identities.

"I want to try and help to put a stop to it and make it more difficult for [ID thieves] to access, since [Experian is] not doing shit and regular people struggle," Kushnir wrote in an email to KrebsOnSecurity explaining his motivations for reaching out. "If somehow I can make small change and help to improve this, inside myself I can feel that I did something that actually matters and helped others." Kushnir said the crooks learned they could trick Experian into giving them access to anyone's credit report, just by editing the address displayed in the browser URL bar at a specific point in Experian's identity verification process.

AI

Top AI Conference Bans Use of ChatGPT and AI Language Tools To Write Academic Papers (theverge.com) 64

One of the world's most prestigious machine learning conferences has banned authors from using AI tools like ChatGPT to write scientific papers, triggering a debate about the role of AI-generated text in academia. From a report: The International Conference on Machine Learning (ICML) announced the policy earlier this week, stating, "Papers that include text generated from a large-scale language model (LLM) such as ChatGPT are prohibited unless the produced text is presented as a part of the paper's experimental analysis." The news sparked widespread discussion on social media, with AI academics and researchers both defending and criticizing the policy. The conference's organizers responded by publishing a longer statement explaining their thinking.

According to the ICML, the rise of publicly accessible AI language models like ChatGPT -- a general purpose AI chatbot that launched on the web last November -- represents an "exciting" development that nevertheless comes with "unanticipated consequences [and] unanswered questions." The ICML says these include questions about who owns the output of such systems (they are trained on public data, which is usually collected without consent and sometimes regurgitate this information verbatim) and whether text and images generated by AI should be "considered novel or mere derivatives of existing work."

Transportation

The Shameful Open Secret Behind Southwest's Failure? Software Shortcomings (nytimes.com) 159

Computer programmer Zeynep Tufekci now writes about the impact of technology on society. In an opinion piece for the New York Times, Tufekci writes on "the shameful open secret" that earlier this week led Southwest airlines to suddenly cancel 5,400 flights in less than 48 hours. "The recent meltdown was avoidable, but it would have cost them."

Long-time Slashdot reader theodp writes that the piece "takes a crack at explaining 'technical debt' to the masses." Tufekci writes: Computers become increasingly capable and powerful by the year and new hardware is often the most visible cue for technological progress. However, even with the shiniest hardware, the software that plays a critical role inside many systems is too often antiquated, and in some cases decades old. This failing appears to be a key factor in why Southwest Airlines couldn't return to business as usual the way other airlines did after last week's major winter storm. More than 15,000 of its flights were canceled starting on Dec. 22, including more than 2,300 canceled this past Thursday — almost a week after the storm had passed.

It's been an open secret within Southwest for some time, and a shameful one, that the company desperately needed to modernize its scheduling systems. Software shortcomings had contributed to previous, smaller-scale meltdowns, and Southwest unions had repeatedly warned about it. Without more government regulation and oversight, and greater accountability, we may see more fiascos like this one, which most likely stranded hundreds of thousands of Southwest passengers — perhaps more than a million — over Christmas week.

And not just for a single company, as the problem is widespread across many industries.

"The reason we made it through Y2K intact is that we didn't ignore the problem," the piece argues. But in comparison, it points out, Southwest had already experienced another cancellation crisis in October of 2021 (while the president of the pilots' union "pointed out that the antiquated crew-scheduling technology was leading to cascading disruptions.") "In March, in its open letter to the company, the union even placed updating the creaking scheduling technology above its demands for increased pay."

Speaking about this week's outage, a Southwest spokesman concedes that "We had available crews and aircraft, but our technology struggled to align our resources due to the magnitude and scale of the disruptions."

But Tufekci concludes that "Ultimately, the problem is that we haven't built a regulatory environment where companies have incentives to address technical debt, rather than passing the burden on to customers, employees or the next management.... For airlines, it might mean holding them responsible for the problems their miserly approach causes to the flying public."
Crime

Software Engineer Charged For Theft Inspired By the Movie 'Office Space' (komonews.com) 99

An anonymous reader quotes a report from KOMO: Ermenildo Castro, 28, of Tacoma, allegedly told detectives that he was inspired by the 90's movie "Office Space" when he devised a plan to divert customer fees from his employer, Zulily.com, into his own bank accounts. According to court documents, Castro wrote software code that manipulated the online retailer's checkout page to send the shipping fees into his own account. The charges allege Castro netted $260,000 in stolen shipping fees. Seattle police detectives said Castro also used his position as a software engineer to manipulate prices on Zulily to purchase approximately $41,000 in merchandise for 'pennies on the dollar'.

According to police, the company's cybersecurity staff found a document on Castro's laptop titled 'OfficeSpace project', which outlined Castro's scheme to 'cleanup evidence' by manipulating audit logs and disabling alarm logging. The theft began in February and by March the company had identified discrepancies in the shipping fees being charged to customers, an SPD report states. Castro was part of the team assigned to investigate the discrepancies in shipping fees, according to the report. Zulily investigators eventually caught on to Castro's scheme and went to his house in Tacoma where they found boxes of merchandise piled up outside the front door and driveway, the report states. In total, Zulily's team said Castro had sent over 1,000 items sent to his house.
Seattle police detectives wrote a narrative explaining how Castro's alleged scheme related to the movie "Office Space," including the plot outline on IMDB.com.

"In the Initech office, the insecure Peter Gibbons hates his job. His best friends are two software engineers Michael Bolton and Samir Nagheenanajar, that also hate Initech. When he discovers that Michael and Samir will be downsized, they decide to plant a virus in the banking system to embezzle fraction of cents on each financial operation into Peter's account. However[,] Michael commits a mistake in the software on the decimal place and they siphon off over $300,000. The desperate trio tries to fix the problem, return the money and avoid going to prison."
Security

The LastPass Disclosure of Leaked Password Vaults Is Being Torn Apart By Security Experts (theverge.com) 78

Last week, LastPass announced that attackers stole customer vault data after breaching its cloud storage earlier this year using information stolen during an August 2022 incident. "While the company insists that your login information is still secure, some cybersecurity experts are heavily criticizing its post, saying that it could make people feel more secure than they actually are and pointing out that this is just the latest in a series of incidents that make it hard to trust the password manager," reports The Verge. Here's an excerpt from the report: LastPass' December 22nd statement was "full of omissions, half-truths and outright lies," reads a blog post from Wladimir Palant, a security researcher known for helping originally develop AdBlock Pro, among other things. Some of his criticisms deal with how the company has framed the incident and how transparent it's being; he accuses the company of trying to portray the August incident where LastPass says "some source code and technical information were stolen" as a separate breach when he says that in reality the company "failed to contain" the breach. He also highlights LastPass' admission that the leaked data included "the IP addresses from which customers were accessing the LastPass service," saying that could let the threat actor "create a complete movement profile" of customers if LastPass was logging every IP address you used with its service.

Another security researcher, Jeremi Gosney, wrote a long post on Mastodon explaining his recommendation to move to another password manager. "LastPass's claim of 'zero knowledge' is a bald-faced lie," he says, alleging that the company has "about as much knowledge as a password manager can possibly get away with." LastPass claims its "zero knowledge" architecture keeps users safe because the company never has access to your master password, which is the thing that hackers would need to unlock the stolen vaults. While Gosney doesn't dispute that particular point, he does say that the phrase is misleading. "I think most people envision their vault as a sort of encrypted database where the entire file is protected, but no -- with LastPass, your vault is a plaintext file and only a few select fields are encrypted."

Palant also notes that the encryption only does you any good if the hackers can't crack your master password, which is LastPass' main defense in its post: if you use its defaults for password length and strengthening and haven't reused it on another site, "it would take millions of years to guess your master password using generally-available password-cracking technology" wrote Karim Toubba, the company's CEO. "This prepares the ground for blaming the customers," writes Palant, saying that "LastPass should be aware that passwords will be decrypted for at least some of their customers. And they have a convenient explanation already: these customers clearly didn't follow their best practices." However, he also points out that LastPass hasn't necessarily enforced those standards. Despite the fact that it made 12-character passwords the default in 2018, Palant says, "I can log in with my eight-character password without any warnings or prompts to change it."

Hardware

Raspberry Pi 5 Not Launching Until After 2023 (tomshardware.com) 83

Les Pounder writes via Tom's Hardware: Raspberry Pi CEO Eben Upton announced via a recent blog post that 100,000 units would be making their way into the supply chain, and that the in the latter-half of 2023 we can expect stock levels to return to pre-pandemic normality. That said, the supply chain shortage has impacted the normal cadence of Raspberry Pi releases, and according to Upton in an interview with Christopher Barnatt from Explaining Computers it means we sadly won't be seeing a Raspberry Pi 5 in 2023.

In the interview, Explaining Computers host Barnatt asks Upton about the future of the Raspberry Pi and if there are new models on the horizon. Upton then talks about how the past couple of years have been "weird" (pandemic and global chip shortage) and it has disrupted the cadence of Raspberry Pi development and release. Upton states that "the platform [Raspberry Pi 4] has been around longer than any Raspberry Pi platform has been around before, I think." At 29 minutes and 30 seconds Upton breaks the bad news, "Don't expect a Pi 5 next year [2023]" Upton then expands and explains that 2023 is a "recovery year". The recovery year is there to help Raspberry Pi and the technology industry recover from the double-punch of a pandemic and a global chip shortage which has caused a slowdown across the world.

Upton explains "What would really be a disaster would be if we tried to introduce some kind of Raspberry Pi 5 product" Upton provides a scenario akin to that of the Raspberry Pi Zero 2 W, launched midway through the pandemic. It has been relatively unobtainium since release. Upton said he is very concerned about the consequences "if we introduced a Raspberry Pi 5 product and it couldn't ramp properly because of constraints, or if we introduced some Raspberry Pi 5 product and it somehow cannibalized some supply chain element." Upton then explains how cannibalization could impact the recovery of Raspberry Pi 4 and the 3 / 3+ and that Raspberry Pi has to be "ginger" as they move forward with its recovery. "The good news is the second half of next year, 2024 onwards, some of those things start to abate. And that's the point where we can start to think about what might be a sensible Raspberry Pi 5 platform," Upton said.

Crime

Secret Software Change Allowed FTX To Use Client Money (reuters.com) 62

An anonymous reader shares a report: In mid-2020, FTX's chief engineer made a secret change to the cryptocurrency exchange's software. He tweaked the code to exempt Alameda Research, a hedge fund owned by FTX founder Sam Bankman-Fried, from a feature on the trading platform that would have automatically sold off Alameda's assets if it was losing too much borrowed money. In a note explaining the change, the engineer, Nishad Singh, emphasized that FTX should never sell Alameda's positions. "Be extra careful not to liquidate," Singh wrote in the comment in the platform's code, which it showed he helped author. Reuters reviewed the code base, which has not been previously reported.

The exemption allowed Alameda to keep borrowing funds from FTX irrespective of the value of the collateral securing those loans. That tweak in the code got the attention of the U.S. Securities and Exchange Commission, which charged Bankman-Fried with fraud on Tuesday. The SEC said the tweak meant Alameda had a "virtually unlimited line of credit." Furthermore, the billions of dollars that FTX secretly lent to Alameda over the next two years didn't come from its own reserves, but rather were other FTX customers' deposits, the SEC said.

The auto-liquidation exemption written into FTX code allowed Alameda to continually increase its line of credit until it "grew to tens of billions of dollars and effectively became limitless," the SEC complaint said. It was one of two ways that Bankman-Fried diverted customer funds to Alameda. The other was a mechanism whereby FTX customers deposited over $8 billion in traditional currency into bank accounts secretly controlled by Alameda. These deposits were reflected in an internal account on FTX that was not tied to Alameda, which concealed its liability, the complaint said.

Slashdot Top Deals