Science

Insects Could Give Meaty Taste To Food and Help Environment, Scientists Say 211

Insects can be turned into meat-like flavors, helping provide a more environmentally friendly alternative to traditional meat options, scientists have discovered. From a report: Mealworms, the larval form of the yellow mealworm beetle, have been cooked with sugar by researchers who found that the result is a meat-like flavoring that could one day be used on convenience food as a source of protein. While mealworms have until now mostly been used as snacks for pets or as bait while fishing, they have potential as a food source for humans to help get the recognizable flavors of meat without the harmful impacts upon the climate, as well as direct air and water pollution, of raising beef, pork and other animal-based foods. "Insects are a nutritious and healthy food source with high amounts of fatty acids, vitamins, minerals, fiber and high-quality protein, which is like that of meat," says In Hee Cho, a researcher at Wonkwang University in South Korea who led the study.

"Many consumers seriously like and need animal protein in our diet. However, traditional livestock farming produces more greenhouse gas emissions than cars do. On the other hand, insect farming requires just a fraction of the land, water and feed in comparison to traditional livestock farming." Cho said that edible insects, such as mealworms and crickets, were "superfoods" that have long been enjoyed by communities in Asia, Africa and South America. However, people in Europe and North America are generally more squeamish about eating insects, despite recent forays by several restaurants and supermarkets into providing insect options for consumers.
Sci-Fi

Congress Admits UFOs Not 'Man-Made,' Says 'Threats' Increasing 'Exponentially' (vice.com) 286

After years of revelations about strange lights in the sky, first hand reports from Navy pilots about UFOs, and governmental investigations, Congress seems to have admitted something startling in print: it doesn't believe all UFOs are "man-made." Motherboard reports: Buried deep in a report that's an addendum to the Intelligence Authorization Act for Fiscal Year 2023, a budget that governs America's clandestine services, Congress made two startling claims. The first is that "cross-domain transmedium threats to the United States national security are expanding exponentially." The second is that it wants to distinguish between UFOs that are human in origin and those that are not: "Temporary nonattributed objects, or those that are positively identified as man-made after analysis, will be passed to appropriate offices and should not be considered under the definition as unidentified aerospace-undersea phenomena," the document states.

The admission is stunning chiefly because, as more information about the U.S. government's study of UFOs has become public, many politicians have stopped just short of claiming the unidentified objects were extraterrestrial or extradimensional in origin. The standard line is typically that, if UFOs exist, then they're likely advanced -- although human-made -- vehicles. Obama refused to confirm the existence of aliens but did say that people have seen a lot of strange stuff in the sky lately when asked directly on The Late Show with James Corden, for example. But now Congress seems to want to specifically distinguish between objects that are "man-made" and those that are not. The admission is stunning chiefly because, as more information about the U.S. government's study of UFOs has become public, many politicians have stopped just short of claiming the unidentified objects were extraterrestrial or extradimensional in origin.

A large question, of course, is why Congress is seemingly admitting this now, in public. After all, lawmakers are privy to classified information that the general public isn't. "It strains credulity to believe that lawmakers would include such extraordinary language in public legislation without compelling evidence," Marik von Rennenkampff, an Obama-era DoD official, said in an op-ed in The Hill about the budget. According to the op-ed, the comments were first noticed by UFO researcher Douglas Johnson. "This implies that members of the Senate Intelligence Committee believe (on a unanimous, bipartisan basis) that some UFOs have non-human origins," von Rennenkampff continued. "After all, why would Congress establish and task a powerful new office with investigating non-'man-made' UFOs if such objects did not exist?" "Make no mistake: One branch of the American government implying that UFOs have non-human origins is an explosive development."

Google

Dad Photographs Son for Doctor. Google Flags Him as Criminal, Notifies Police (yahoo.com) 241

"The nurse said to send photos so the doctor could review them in advance," the New York Times reports, decribing how an ordeal began in February of 2021 for a software engineer named Mark who had a sick son: Mark's wife grabbed her husband's phone and texted a few high-quality close-ups of their son's groin area to her iPhone so she could upload them to the health care provider's messaging system. In one, Mark's hand was visible, helping to better display the swelling. Mark and his wife gave no thought to the tech giants that made this quick capture and exchange of digital data possible, or what those giants might think of the images. With help from the photos, the doctor diagnosed the issue and prescribed antibiotics, which quickly cleared it up....

Two days after taking the photos of his son, Mark's phone made a blooping notification noise: His account had been disabled because of "harmful content" that was "a severe violation of Google's policies and might be illegal." A "learn more" link led to a list of possible reasons, including "child sexual abuse & exploitation...." He filled out a form requesting a review of Google's decision, explaining his son's infection. At the same time, he discovered the domino effect of Google's rejection. Not only did he lose emails, contact information for friends and former colleagues, and documentation of his son's first years of life, his Google Fi account shut down, meaning he had to get a new phone number with another carrier. Without access to his old phone number and email address, he couldn't get the security codes he needed to sign in to other internet accounts, locking him out of much of his digital life....

A few days after Mark filed the appeal, Google responded that it would not reinstate the account, with no further explanation. Mark didn't know it, but Google's review team had also flagged a video he made and the San Francisco Police Department had already started to investigate him.... In December 2021, Mark received a manila envelope in the mail from the San Francisco Police Department. It contained a letter informing him that he had been investigated as well as copies of the search warrants served on Google and his internet service provider. An investigator, whose contact information was provided, had asked for everything in Mark's Google account: his internet searches, his location history, his messages and any document, photo and video he'd stored with the company. The search, related to "child exploitation videos," had taken place in February, within a week of his taking the photos of his son.

Mark called the investigator, Nicholas Hillard, who said the case was closed. Mr. Hillard had tried to get in touch with Mark but his phone number and email address hadn't worked....

Mark appealed his case to Google again, providing the police report, but to no avail.... A Google spokeswoman said the company stands by its decisions...

"The day after Mark's troubles started, the same scenario was playing out in Texas," the Times notes, quoting a technologist at the EFF who speculates other people experiencing the same thing may not want to publicize it. "There could be tens, hundreds, thousands more of these."

Reached for a comment on the incident, Google told the newspaper that "Child sexual abuse material is abhorrent and we're committed to preventing the spread of it on our platforms."
Transportation

Lincoln's Concept Car Replaces Steering Wheel with Mouse-Like 'Controller' (thedrive.com) 63

Engadget reports that the annual "Monterey Car Week "has been a hotbed of EV debuts this year with unveilings from Dodge, Acura, DeLorean and a host of other automakers." But then on Thursday, Lincoln unveiled its Model L100, paying homage to the opulence of Lincoln's original 1922 luxury car by "redefining" vehicle controls.

A video on CNN explains that "the fully autonomous vehicle has no steering wheel or pedals," emphasizing that it's a "concept car" — a show piece. ("It's not set for production and won't be sold to customers.") But yes, it's an electric car that replaces the steering wheel with what Lincoln is calling a "chess piece controller," a hand-held, car-shaped piece of crystal that sits on a table in the center of the car. Drivers "grab it and move it around and move the actual vehicle," Kemal Curic, Global Design Director for Lincoln Motor Company, tells the Drive. (The table-top surface apparently functions like a kind of map, with the hand-held piece acting as an avatar.) Or as the Drive puts it, "Remember being a kid and pushing a toy car around on a city rug? Lincoln designers do."

The site ultimately concludes that the designs "really speak to one's natural instinct of movement. As humans, whenever we want to move something we just pick it up and move it; so why should our cars be any different...? [C]oncept cars don't have to make sense. They just need to be a cool representation of our wildest ideas."

In addition, CNN explains, "Because the car drives itself, the front row seats can be turned to face the rear passengers."

There's other futuristic features. CNN's video shows what Lincoln is calling "smart wheel covers" which fully encase the tires while offering a decorative electric light show (which doubles as a battery indicator). Even the floor is a massive digital screen, and there's also a full-length hinged glass roof — an upper canopy which according to Engadget "can project realistic animated scenes onto the floor and ceiling."

"Unfortunately many of the ideas presented here will inevitably be cut, going the way of Mercedes' awesome, Avatar-inspired trunk hatch wigglers."
Star Wars Prequels

Why Return of the Jedi's Last Scene is Darker Than It Seems (screenrant.com) 80

Slashdot reader alaskana98 writes: You may remember it — at the end of Return of the Jedi: Special Edition, a rare glimpse of Coruscant — the seat of the galactic empire — is shown in a celebratory state as news of the empire's defeat at Endor reverberated throughout the patchwork of worlds that make up the Star Wars universe.

One might imagine that most viewers at that time might have thought — "Oh, cool, so that's what Coruscant looks like" — then went on with their lives rarely to think about that scene ever again. In a recent ScreenRant article ,they take a deeper dive into what happened on Coruscant...

Yes, it turns out that both the later movies and licensed books revealed that Darth Vader's Galactic Empire survived: [C]itizens who set off fireworks, toppled statues of the Empire, and attacked stormtroopers were met with violent retaliation from Imperial forces, resulting in numerous extrajudicial killings and executions of civilians. Coruscant continued to serve as an Imperial stronghold until its liberation by the New Republic, which happened a year later in canon and two years later in Legends.... [T]he X-Wing novels mention that the Empire brutally quelled this initial uprising, and the Star Wars: Mara Jade — By the Emperor's Hand comic series showed Stormtroopers executing civilians via firing squad. Aftermath similarly describes civilians fighting against Imperial security forces after toppling a statue of Palpatine....
Robotics

A Robot Quarterback Could Be the Future of Football Practice (msn.com) 25

Here's an interesting story from the Washington Post. (Alternate URL here...) When the Green Bay Packers walked onto the practice field this week, they were greeted by an unusual new teammate: a robot. In videos on Twitter, a 6-foot tall white robotic machine simulates a punter, kicking balls at a rapid pace to players downfield. The robot, which holds six balls in a revolving cartridge, could also imitate a quarterback's style including the speed, arc and timing of a throw.

The Seeker is a robotic quarterback, kicker and punter rolled into one. It's a modern day version of a piece of football equipment, called a JUGS machine, that's been used to simulate throws and kicks to football players for decades. The Seeker, company officials say however, is a more accurate thrower and runs software to let players practice more advanced gameplay scenarios. he robot, created by Dallas-based Monarc Sport, is starting to gain adoption. Top college football programs, such as Louisiana State University, the University of Oklahoma and the University of Iowa, all count the Seeker as part of their training strategy. The Green Bay Packers are the first team in the National Football League to try the technology.

The Seeker's software allows players to customize how they practice with it. Athletes can catch balls from close to the machine to improve hand-eye coordination. They can also program the robot to throw a ball to a spot on the field, or simulate more-lifelike conditions by over or underthrowing a ball. Players wear a pager-like tag which allows the robot to track their location on the field, and throw a ball accurately within inches. "It gives so much opportunity for our guys to get reps without the need of having a quarterback there," said Ben Hansen, the director of football administration at Iowa, where the technology was first tested. "That's a huge plus...."

One of the most helpful parts of the technology, he said, is being able to program it to throw passes that simulate game day conditions. Unlike the JUGS machine, he said, which doesn't have software to pass in random patterns, the Seeker can purposefully throw passes that aren't perfect.... A case study published in April by Microsoft, which provides the software ecosystem for the robot, noted that West Virginia University's dropped passes rate fell to four percent in 2021, down from 53 percent the past season after introducing the robot into training.

The university's senior athletic director said the robot deserved a "share of the credit" for that outcome.

Transportation

Buttons Beat Touchscreens In Cars, and Now There's Data To Prove It (arstechnica.com) 142

An anonymous reader quotes a report from Ars Technica: [Swedish car publication Vi Bilagare] tested 11 new cars alongside a 2005 Volvo C70, timing how long it took to perform a list of tasks in each car. These included turning on the seat heater, increasing the cabin temperature, turning on the defroster, adjusting the radio, resetting the trip computer, turning off the screen, and dimming the instruments. The old Volvo was the clear winner. "The four tasks is handled within ten seconds flat, during which the car is driven 306 meters at 110 km/h [1,004 feet at 68 mph]," VB found. Most of the other cars required twice as long, or more, to complete the same tasks. VB says that "one important aspect of this test is that the drivers had time to get to know the cars and their infotainment systems before the test started." VB lays the blame for the shift from buttons to screens with designers who "want a 'clean' interior with minimal switchgear."

Even with touchscreens, though, we can see in the spread of scores VB gave to different all-touch cars that design matters. You'll find almost no buttons in a Tesla Model 3, and we called out the lack of buttons in the Subaru Outback in our review, but both performed quite well in VB's tests. And VW's use of capacitive touch (versus physical) for the controls on the center stack appears to be exactly the wrong decision in terms of usability, with the ID.3 right at the bottom of the pack in VB's scores. I'm not surprised that the BMW iX scored well; although it has a touchscreen, you're not obligated to use it. BMW's rotary iDrive controller falls naturally to hand, and there are permanent controls arrayed around it under a sliver of wood that both looks and feels interesting. It's an early implementation of what the company calls shy tech, and it's a design trend I am very much looking forward to seeing evolve in the future.

NASA

The James Webb Space Telescope Runs JavaScript, Apparently (theverge.com) 60

It turns out that JavaScript had a hand in delivering the stunning images that the James Webb Space Telescope has been beaming back to Earth. From a report: I mean that the actual telescope, arguably one of humanity's finest scientific achievements, is largely controlled by JavaScript files. Oh, and it's based on a software development kit from 2002. According to a manuscript (PDF) for the JWST's Integrated Science Instrument Module (or ISIM), the software for the ISIM is controlled by "the Script Processor Task (SP), which runs scripts written in JavaScript upon receiving a command to do so." The actual code in charge of turning those JavaScripts (NASA's phrasing, not mine) into actions can run 10 of them at once.

The manuscript and the paper (PDF) "JWST: Maximizing efficiency and minimizing ground systems," written by the Space Telescope Science Institute's Ilana Dashevsky and Vicki Balzano, describe this process in great detail, but I'll oversimplify a bit to save you the pages of reading. The JWST has a bunch of these pre-written scripts for doing specific tasks, and scientists on the ground can tell it to run those tasks. When they do, those JavaScripts will be interpreted by a program called the script processor, which will then reach out to the other applications and systems that it needs to based on what the script calls for. The JWST isn't running a web browser where JavaScript directly controls the Mid-Infrared Instrument -- it's more like when a manager is given a list of tasks (in this example, the JavaScripts) to do and delegates them out to their team.

The Almighty Buck

Google's Investing Arms Are Pumping $1.56 Billion Into Blockchain Companies (gizmodo.com) 60

An anonymous reader quotes a report from Gizmodo: Blockdata, a crypto research firm, released an updated blog post Tuesday showing who's been the most active investors in the crypto scene from September 2021 through June 2022. Researchers noted big tech firms including the likes of Tencent, Microsoft, PayPal, Samsung, and Alphabet (Google) are putting big money into crypto companies and startups. Some of these companies, like PayPal, have been a longtime and verbal supporter of blockchain tech (thanks in part to its co-founder Peter Thiel). Still others, like Google, have been much more subdued. [...] What Google chooses to invest in may help answer where the company wants to see blockchain tech go, or what it may want to incorporate into its own tech infrastructure. In the report, Alphabet, the parent company of Google, sat at the top of the pile showing it had put over $1.5 billion into crypto companies over four rounds of investment. Some of the company's overall funds went to the likes of Dapper Labs, the company that was behind the NBA's Top Shot and UFC Strike licensed video NFTs. The company was also behind CryptoKitties, a NFT-based game that's seen the price of its products tank.

What makes this more complicated is there are actually two of Google's investing arms involved in this fundraising. GV (Google's investing arm once called Google Ventures) helped fund Dapper Labs and another crypto infrastructure company Voltage, which got $6 million in total investments at the start of 2022. CapitalG, the company's independent private equity firm, had a hand in the $550 million raised by Fireblock, a crypto custody firm, as well as investments with digital currency venture capital company Digital Currency Group Of course, this was all before the most recent crypto crash, which has seen a multitude of once-strong crypto companies layoff thousands of workers. Though it's not like this is the first time we've heard about Google's parent company Alphabet with their big financial interest in blockchain companies. They've been investing in this tech since 2016, according to the Blockdata report. Previous reports showed they had put money into crypto companies like Ripple (which just like many small altcoins since the recent crypto crash, isn't doing too hot). Google had previously made much wider investments across a wider variety of blockchain-based companies. That was then, and this is now. Blockdata analysts said this limited slate of investments is an attempt to make concentrated bets on a small set of companies, but even with executive's stated hopes for blockchain tech, it's hard to see all investments truly panning out.

Though it was fourth in the size of its contributions, Samsung was leading the pack in the number -- and eye-twitching variety -- of crypto ventures it was making it rain on over an incredible 13 rounds of investing. A total of $979.26 million went to the likes of Dank Bank, a NFT platform for trying to monetize "memes and other iconic moments in internet history." They put more of their funds behind Yuga Labs, the creators of the Bored Ape Yacht Club NFTS. They put down their investment in March, but in April, users on the group's official Instagram and Discord were scammed of nearly $13.7 million worth of NFTs. Still, founders said many of BAYC's rather strange initiatives like a Bored Ape "Metaverse" are still moving full steam ahead. They also put money into Sky Mavis, the makers of the crypto-based "play-to-earn" game Axie Infinity. That investment probably didn't do them any wonders considering its token bridge suffered one of the biggest hacks in crypto history earlier this year. The game has struggled to recover after that blow, though players had already been leaving the platform before hackers snatched away bridge funds.
"Blockdata's research shows that 81 of the top 100 public companies have made some kind of past or present crypto investment," adds Gizmodo. "2021 showed the absolute highest amount of overall investment in blockchain companies. Funding totals have increased by a factor of 14 from 2019 to last year."
Google

Google Adds Instant Cloud-Streaming Button To Web Searches For Games (arstechnica.com) 12

An anonymous reader shares a report: The earliest sales pitch for Stadia, the Google streaming service that beams high-end video games to web browsers via the cloud, included the idea that it might work as simply as Googling your favorite game. You might search for a popular game to learn more about it, only to immediately see an option to start playing it inside your web browser, no additional hardware required -- and perhaps no payment, either. Nearly three years after Stadia's official launch -- and 18 months after the service's massive internal downgrade -- that scenario has finally begun to play out. What's more, the feature appears to be streamer-agnostic, as multiple Stadia-like streaming services have started appearing in search results.

This week, Google rolled out a limited launch of a "Play Now" tab that appears on searches for select video games on desktop browsers. (As of press time, out of three Google accounts tested, the search results shown in this article only appear on one of them.) This tab can be found in the right-hand "knowledge panel" that is otherwise automatically populated with user reviews, game details, and digital download purchase links. When a Google game search returns a Play Now tab, it will include as many compatible streaming services as possible, including Google Stadia, Microsoft Xbox Cloud Gaming, Amazon Luna, and Nvidia GeForce Now. Each entry shows what kind of fee may be required to play the game. Conveniently enough, many Google Stadia games can now be played for free for the first 30 minutes or as long as 120 minutes, and supported free-trial Stadia games get a bright-green flash of italicized text: "trial available." Other games and services that have appeared thus far have included tags like "premium subscription" or "free-to-play."

Privacy

Amazon Begins Large-Scale Rollout of Palm Print-Based Payments (arstechnica.com) 25

An anonymous reader quotes a report from Ars Technica: Amazon will expand its Amazon One palm print checkout system to dozens of Whole Foods locations, marking the most significant expansion of the technology that was introduced in 2020. Amazon One allows customers to speedily check out at retail locations using only their palm prints after storing a scan of their hand via an interface at Amazon's kiosks. The palm print data is encrypted and stored on Amazon's servers. And before you worry too much about COVID-19 transmission or future pandemics, Amazon One works when you hover your palm over the scanner -- unlike some handprint tech.

Amazon initially added the technology in its Amazon Go stores and the now-shuttered Amazon Books retail locations. It then made its way to several Whole Foods locations in the Seattle area. (Amazon has owned the Whole Foods grocery chain since 2017.) Now, Amazon Go will expand to 65 Whole Foods stores across California. The rollout starts in Malibu and Santa Monica, with more locations adopting it in Los Angeles, Santa Cruz, and the Bay Area over the next few weeks. Amazon previously rolled the tech out to a few select locations in California, but never at this scale.

Robotics

Hacker Finds Kill Switch For Submachine Gun-Wielding Robot Dog (vice.com) 44

An anonymous reader quotes a report from Motherboard: In July, a video of a robot dog with a submachine gun strapped to its back terrified the internet. Now a hacker who posts on Twitter as KF@d0tslash and GitHub as MAVProxyUser has discovered that the robot dog contains a kill switch, and it can be accessed through a tiny handheld hacking device. "Good news!" d0tslash said on Twitter. "Remember that robot dog you saw with a gun!? It was made by @UnitreeRobotic. Seems all you need to dump it in the dirt is @flipper_zero. The PDB has a 433mhz backdoor."

In the video, d0tslash showed one of the Unitree robot dogs hooked up to a power supply. A hand comes into the frame holding a Flipper Zero, Tamagotchi-like multitool hacking device that can send and receive wireless signals across RFID, Bluetooth, NFC, and other bands. A button is pushed on the Flipper and the robot dog seizes up and falls to the ground. Motherboard reached out to d0tslash to find out how they hacked the robot dog. The power supply in the video is an external power source. "Literally a 24-volt external power supply, so I'm not constantly charging battery while doing dev," d0tslash said.

d0tslash got their hands on one of the dogs and started going through the documentation when they discovered something interesting. Every dog ships with a remote cut-off switch attached to its power distribution board, the part of a machine that routes power from the battery to its various systems. The kill switch listens for a particular signal at 433mhz. If it hears the signal, it shuts down the robot. Some of the Unitree robot dogs even ship with the wireless remote that shuts the dog down instantly. d0tslash then used Flipper Zero to emulate the shutdown, copying the signal the robot dog's remote broadcasts over the 433MHz frequency.
Anyone with a Flipper Zero or similar device can shut down these robot dogs, thanks to the work d0tslash has shared on Github.
Businesses

The Crypto Collapse Has Flooded the Market With Rolex and Patek (bloomberg.com) 109

The collapse in cryptocurrencies is easing supply of the most sought after watches on the second-hand market, depressing prices for hard-to get-Patek Philippe and Rolex models. From a report: The supply of trophy watches such as the Rolex Daytona or Patek Nautilus 5711A "is now much larger," online-watch trading platform Chrono24 said in an emailed statement. The recent swoon in cryptocurrency valuations "has directly impacted pricing of luxury watches from brands like Rolex and Patek Philippe," said the company, which is based in Karlsruhe, Germany, and has more than half a million watches listed for sale on its website. The price decline for the most sought after models is the latest indication that the once soaring second-hand luxury watch market is starting to lose pace. Surging valuations for crypto currencies had minted a new class of luxury buyers, leading to an unprecedented price increase for models particularly from brands like Rolex, Audemars Piguet and Patek. Now that many digital tokens have been hammered, these consumers are going into reverse.
ISS

Russia Tells NASA Space Station Pullout Less Imminent Than Indicated Earlier (reuters.com) 48

Russian space officials have informed U.S. counterparts that Moscow would like to keep flying its cosmonauts aboard the International Space Station (ISS) until their own orbital outpost is built and operational, a senior NASA official told Reuters on Wednesday. Reuters reports: Taken together with remarks from a senior Russian space official published on Wednesday, the latest indications are that Russia is still at least six years away from ending an orbital collaboration with the United States that dates back more than two decades.

A schism in the ISS program seemed to be closer at hand on Tuesday, when Yuri Borisov, the newly appointed director-general of Russia's space agency Roscosmos, surprised NASA by announcing that Moscow intended to withdraw from the space station partnership "after 2024." Kathy Lueders, NASA's space operations chief, said in an interview that Russian officials later on Tuesday told the U.S. space agency that Roscosmos wished to remain in the partnership as Russia works to get its planned orbital outpost, named ROSS, up and running. "We're not getting any indication at any working level that anything's changed," Lueders told Reuters on Wednesday, adding that NASA's relations with Roscosmos remain "business as usual."

Privacy

Google's Nest Will Provide Data to Police Without a Warrant (petapixel.com) 81

As reported by CNET, Google will allow law enforcement to access data from its Nest products -- or theoretically any other data you store with Google -- without a warrant. PetaPixel reports: "If we reasonably believe that we can prevent someone from dying or from suffering serious physical harm, we may provide information to a government agency -- for example, in the case of bomb threats, school shootings, kidnappings, suicide prevention, and missing person cases," reads Google's TOS page on government requests for user information. "We still consider these requests in light of applicable laws and our policies."

An unnamed Nest spokesperson did tell CNET that the company tries to give its users notice when it provides their data under these circumstances. Google "reserves the right" to make emergency disclosures to law enforcement even when there is no legal requirement to do so. "A provider like Google may disclose information to law enforcement without a subpoena or a warrant 'if the provider, in good faith, believes that an emergency involving danger of death or serious physical injury to any person requires disclosure without delay of communications relating to the emergency,'" a Nest spokesperson tells CNET.

While Amazon and Google have both said they would hand over a user's data to law enforcement without a warrant, Arlo, Apple, Wyze, and Anker, owner of Eufy, all confirmed to CNET that they won't give authorities access to a user's smart home camera's footage unless they're shown a warrant or court order. These companies would be legally bound to provide data to the authorities if they were shown a legal document. But, unlike Google and Amazon, they will not otherwise share camera footage with law enforcement, even if they had an emergency request for data. Apple's default setting for video cameras connected via Homekit is end-to-end encryption which means the company is unable to share user video at all.
In an updated statement, a Google spokesperson clarified that they have never sent Nest data to authorities, "but it's important that we reserve the right to do so."

They added: "To reiterate, and as we've specified in our privacy commitments, we will only share video footage and audio recordings with third-party apps and services that work with our devices if you or a member of your home explicitly gives us permission, and we'll only ask for this permission in order to provide a helpful experience from an approved partner (such as a home security service provider)."
Programming

Protestware On the Rise: Why Developers Are Sabotaging Their Own Code (techcrunch.com) 149

"If combating attacks and hijackings of legitimate software on open source registries like npm weren't challenging enough, app makers are increasingly experiencing the consequences of software self-sabotage," writes security researcher and reporter Ax Sharma via TechCrunch. "A developer can, on a whim, change their mind and do whatever they want with their open source code that, most of the time anyway, comes 'as is' without any warranty. Or, as seen by a growing trend this year, developers deliberately sabotaging their own software libraries as a means of protest -- turning software into 'protestware.'"

One of the many examples Sharma mentions happened during the first week of 2022, when thousands of applications that rely on the heavily used npm projects colors and faker broke and began printing gibberish text on users' screens. "It wasn't a malicious actor hijacking and altering these legitimate libraries," writes Sharma. "It turned out the projects' developer Mark Squires had intentionally corrupted his own work to send a message of protest to big corporations..." An anonymous reader shares an excerpt from his report: Open source developers are discovering new and creative avenues that no longer limit them to implementing new features for their projects, but to actively express their views on larger social matters by modifying their projects for a cause. And, unlike proprietary code that has to function in line with a paying customer's expectations, most open source licenses are quite permissive -- both for the consumer and the developer -- offering their code with licenses that offer no guarantees as to what a developer is not supposed to and will never do with their code, making protestware a gray area for defenders. In fact, as a security researcher at Sonatype, I observed how protestware posed a challenge for us in the early stages and how we would tweak our automated malware detection algorithms to now catch self-sabotages with projects like colors and faker. Traditionally, the system was designed to spot typosquatting malware uploaded to open source repositories, but cases like malicious hijacks or developers modifying their own libraries without warning required a deeper understanding of the intricacies of how protestware works.

The theme has also put major open source registries like npm -- owned by GitHub, a Microsoft subsidiary -- at a crossroads when having to deal with these edge cases. Socket's founder Feross Aboukhadijeh told TechCrunch that registries like GitHub are in a difficult position. "On the one hand, they want to support maintainers' right to freedom of expression and the ability to use their platform to support the causes they believe in. But on the other hand, GitHub has a responsibility to npm users to ensure that malicious code isn't served from npm servers. It's sometimes a difficult balancing act," said Aboukhadijeh. A simple solution to ensuring you are getting only vetted versions of a component in your build is to pin your npm dependency versions. That way, even if future versions of a project are sabotaged or hijacked, your build continues to use the "pinned" version as opposed to fetching the latest, tainted one. But this may not always be an effective strategy for all ecosystems, like PyPI, where existing versions of a component can be republished -- as we saw in the case of the hijacking of the ctx PyPI project.

"The conversation around 'protestware' is really a conversation about software supply chain security. You can't trust what you can't verify," Dan Lorenc, the co-founder and chief executive at Chainguard, a startup that specializes in software supply chain security, told TechCrunch. Lorenc's advice against preventing protestware is to follow good open source security hygiene and best practices that can help developers develop protestware more easily and early on. "Knowing and understanding your dependencies, conducting regular scans and audits of open source code you are using in your environments are a start." But Lorenc warns the debate about protestware could draw in copycats who would contribute to the problem and detract open source software defenders from focusing on tackling what's truly important -- keeping malicious actors at bay. And with protestware there remain unknown unknowns. What issue is too small -- or too big -- for protestware? While no one can practically dictate what an open source developer can do with their code -- it is a power developers have always possessed, but are now just beginning to harness.

Lord of the Rings

Comic-Con Gets Clips and a New Three-Minute Trailer for Amazon Prime Series 'Lord of the Rings' (go.com) 120

The San Diego Comic-Con is "back in full force for the first time since 2019" reports the Associated Press. And Amazon's Prime Video used the occasion to unveil a lush new three-minute trailer for their upcoming series The Lord of the Rings: The Rings of Power. ("If the evil rising is left unchecked, it will take us all...")

Over the weekend it's already been viewed nearly 7 million times.

"Beginning in a time of relative peace, the series follows an ensemble cast of characters, both familiar and new, as they confront the long-feared re-emergence of evil to Middle-earth," explains the video's description on YouTube. "From the darkest depths of the Misty Mountains, to the majestic forests of the elf-capital of Lindon, to the breathtaking island kingdom of Númenor, to the furthest reaches of the map, these kingdoms and characters will carve out legacies that live on long after they are gone."

Comic-Con also hosted several panels on Amazon's Lord of the Rings series, including an 80-minute cast Q&A hosted by Patton Oswalt, Felicia Day, and Tiffany Smith. And the Associated Press reports that Stephen Colbert, "a self-proclaimed Tolkien fan, was also on hand to moderate a panel teasing the series on the fan convention's biggest stage," interviewing showrunners and executive producers J.D. Payne and Patrick McKay: The eight-part series will debut on Prime Video on Sept. 2, with new episodes arriving weekly. It is said to be the most expensive series ever made, with a reported budget of $465 million.... Jennifer Salke, the head of Amazon Studios, told The Hollywood Reporter last year that while the number is a "crazy headline that's fun to click on," "that is really building the infrastructure of what will sustain the whole series" which she called a "huge, world-building show."

Salke also said that a "giant, global audience needs to show up to it as appointment television" but that they were "pretty confident that will happen."

Five clips were also revealed to the Comic-Con audience and were "very well received by the crowd," reports USA Today. "They featured Galadriel and Elrond; Elrond and Durin getting ready for a friendly fight; hobbit ancestors the Harfoots; the Atlantis-like kingdom of Numenor; and an elves-versus-orcs battle." "It's a human story: We want you to take a step back and imagine your home .. and imagine that it's about to be taken away, that it's under threat," Payne said. "How far would you go" to protect that?"

When asked how they approached bringing characters to life that hadn't been described by Tolkien, Payne said, "We had the privilege of working with Tolkien scholars. Tolkien gave us all these amazing clues about characters in the Second Age. When Tolkien was silent, (we) try to invent things in as Tolkienian a way as possible." The producers and cast were quick to express respect and admiration for Jackson's films, but firm in their conviction that the show is something very different.

One important distinction was about dwarves. "We feel like dwarves are the butt of jokes, but we're going to take dwarves really seriously," Payne said.

Open Source

Can Google's New Programming Language 'Carbon' Replace C++ Better Than Rust? (thenewstack.io) 185

It's difficult for large projects to convert existing C++ codebases into Rust, argue Google engineers — so they've created a new "experimental" open source programming language called Carbon.

Google Principal Software Engineer Chandler Carruth introduced Carbon this week at the "CPP North" C++ conference in Toronto. TechRadar reports: The newly announced Carbon should be interoperable with the popular C++ code, however for users looking to make the full switch, the migration should be fairly easy. For those unsure about a full changeover, Carruth delved into more detail about some of the reasons why Carbon should be considered a powerful successor to the C++ language, including simpler grammar and smoother API imports.
Google's engineers are already building tools to translate C++ into this new language. "While Carbon began as a Google internal project, the development team ultimately wants to reduce contributions from Google, or any other single company, to less than 50% by the end of the year," reports The New Stack, adding that Google ultimately wants to hand off the project to an independent software foundation where development will be led by volunteers: Long the language of choice for building performance-critical applications, C++ is plagued with a number of issues that hamper modern developers, Carruth explained on a GitHub page. It has accumulated decades of technical debt, bringing with it many of the outdated practices that were part of the language's predecessor, C. The keepers of C++ prioritize backward compatibility, in order to continue to support widely-used projects such as Linux and its package management ecosystem, Carruth charged.

The language's evolution is also stymied by a bureaucratic committee process, oriented around standardization rather than design. Which can make it difficult to add new features. C++ has largely a sequestered development process, in which a select committee makes the important decisions, in a waterfall process that can take years. "The committee structure is designed to ensure representation of nations and companies, rather than building an inclusive and welcoming team and community of experts and people actively contributing to the language," Carruth wrote. "Access to the committee and standard is restricted and expensive, attendance is necessary to have a voice, and decisions are made by live votes of those present."

Carruth wants to build Carbon by a more open community-led environment. The project will be maintained on GitHub, and discussed on Discord.... The design team wants to release a core working version ("0.1") by the end of the year.

Carbon will boast modern features like generics and memory safety (including dynamic bounds checks), the article points out. And "The development team will also set out to create a built-in package manager, something that C++ sorely lacks."
Facebook

Zuckerberg and Sandberg Ordered To Testify Over Alleged Involvement In Cambridge Analytica Scandal (gizmodo.com) 35

An anonymous reader quotes a report from Gizmodo: Meta CEO Mark Zuckerberg and former COO Sheryl Sandberg will have to provide testimony to a federal court to discuss their alleged involvement in the company's notorious Cambridge Analytica scandal, over half a decade since it first captured the world's attention. [...] Cambridge Analytica was a British political consulting firm that used Facebook user data to target and lobby potential voters ahead of the 2016 election in favor of Donald Trump. The ensuing scandal helped trigger an investigation from the Federal Trade Commission that resulted in Facebook agreeing to a record-setting $5 billion settlement over its privacy practices.

A new filing (PDF) in the Northern District of California Tuesday shows Zuckerberg and Sandberg agreed to be deposed for six and five hours respectively in September of this year. This comes as part of a class action lawsuit filed against Meta, claiming the company violated consumer privacy laws when it shared user data with Cambridge Analytica back in 2015. [...] In addition to Zuckerberg and Sandberg, the court's also seeking to depose Meta's newly named CTO Javier Olivan -- who previously served as the company's Chief Growth Officer -- as well as a handful of other "key witnesses." Olivan's deposition is expected to last three hours. According to Tuesday's filing Meta will also hand over 1,200 documents "previously withheld as privileged." Plaintiffs in the case previously accused Meta and the law firm representing it of "stonewalling," during the court's discovery phase.

The Courts

Glassdoor Ordered To Reveal Identity of Negative Reviewers To New Zealand Toymaker (theguardian.com) 142

A California court has ordered employer-rating site Glassdoor to hand over the identities of users who claimed they had negative experiences working for New Zealand toy giant Zuru. The Guardian reports: In a decision that could prompt unease for online platforms that rely on anonymity to attract candid reviews, Glassdoor was ordered to provide the information so Zuru could undertake defamation proceedings against the reviewers in New Zealand. Glassdoor is an international website where people post anonymous reviews of their current or former employers. Zuru is an international toy manufacturer that was founded in New Zealand and now has a billion-dollar turnover. After an anonymous person or people wrote reviews alleging that Zuru was a "toxic" workplace, the company began pursuing a defamation suit against them -- but first had to find out their identities.

California district court judge Alex Tse wrote in his decision that the reviews refer to Zuru as a "[b]urn out factory" with a "toxic culture," where an "incompetent" management team "consistently talk[s] down" to employees and treats them like "dirt." The judge wrote that the reviews make Zuru "sound like a horrible place to work." Zuru says these and similar statements in the reviews are false and have cost them financially. The company argued that it "has had to expend money, time, and resources in combatting the negative publicity, negative perception, and harm to [Zuru's] reputation that the [r]eviews have caused."

It wants to sue the reviewers for defamation in New Zealand, the country where the company was founded and where the reviewer or reviewers allegedly worked. Tse ruled that New Zealand's defamation laws are the relevant ones in this case, and ordered that Glassdoor hand over identifying information. New Zealand has stricter defamation laws than the US, where there are far greater free speech protections. Tse wrote: "There's good reason to tread lightly in applying US free-speech principles abroad. Our country's commitment to free speech isn't universally shared; and even in other countries that protect free speech, a different balance is often struck between the right to free speech and the right to protect one's reputation. Glassdoor wants to safeguard anonymous speech on its website. Zuru wants to protect its reputation. Both interests can't simultaneously be accommodated."
In a statement, Glassdoor said it was "deeply disappointed in the court's decision, which was effectively decided under New Zealand law." They added: "In this and many other cases worldwide, Glassdoor fights vigorously to protect and defend the rights of our users to share their opinions and speak freely and authentically about their workplace experiences."

Glassdoor said it had fought a number of defamation-type cases, and they "prevail in the vast majority of these types of cases. To date, we have succeeded in protecting the anonymity of our users in more than 100 cases filed against our users."

Slashdot Top Deals