Chrome

Chrome Will Now Silence Many of Those Annoying Notification Permission Prompts on the Web (techcrunch.com) 83

Google today announced a set of new and updated security features for Chrome, almost all of which rely on machine learning (ML) models, as well as a couple of nifty new ML-based features that aim to make browsing the web a bit easier, including a new feature that will suppress notification permission prompts when its algorithm thinks you're unlikely to accept them. From a report: Starting with the next version of Chrome, Google will introduce a new ML model that will silence many of these notification permission prompts. And the sooner the better. At this point, they have mostly become a nuisance. Even if there are some sites -- and those are mostly news sites -- that may offer some value in their notifications, I can't remember the last time I accepted one on purpose. Also, while legitimate sites love to push web notifications to remind readers of their existence, attackers can also use them to send phishing attacks or prompt users to download malware if they get users to give them permission. "On the one hand, page notifications help deliver updates from sites you care about; on the other hand, notification permission prompts can become a nuisance," Google admits in its blog post today. The company's new ML model will now look for prompts that users are likely to ignore and block them automatically. And as a bonus, all of that is happening on your local machine, so none of your browsing data makes it onto Google's servers.
Power

Will Electric Cars Transform the Workforce? (laist.com) 181

Gas-powered vehicles "have hundreds of moving parts and other components" that keep mechanics busy, argues CalMatters (which describes itself as a "nonpartisan and nonprofit news organization.")

"By 2040, the state projects that nearly 32,000 auto mechanics jobs will be lost in California, since electric vehicles need far less maintenance and repair than conventional combustion engines." And they base that prediction on statistics from the state's own Air Resources Board (part of California's Environmental Protection Agency): Throughout the economy, an estimated 64,700 jobs will be lost because of the mandate, according to the California Air Resources Board's calculations. On the other hand, an estimated 24,900 jobs would be gained in other sectors, so the estimated net loss is 39,800 jobs, a minimal amount across the state's entire economy, by 2040. But no single workforce in the state would be hurt more than auto mechanics: California has about 60,910 auto service technicians and mechanics, and more than half of those jobs would be lost over the next two decades if the mandate goes into effect, the air board calculates....

Some industries gain jobs while others lose them as the state shifts to zero-emission vehicles. The retail trade sector, which includes gas station workers and automobile and parts dealers, would lose 38,669 jobs by 2040 or about 2% of the retail workforce. Most of the losses would be at gasoline stations. As the electric vehicle fleet grows, air board officials project gas stations could provide charging to offset the losses.... Another 20,831 jobs in state and local government would be eliminated because of the decrease in gas tax revenue.

But the transition to electric cars also will create thousands of jobs. Southern California Edison, Pacific Gas & Electric and other power industry companies would benefit most, with the creation of about 5,600 jobs by 2040 as car owners spend more on electricity to power their vehicles. Insurance carriers will benefit from about 1,700 new jobs, while the construction industry is expected to gain about 3,600.... Mechanics who work on internal combustion engines would still have plenty of work: The rule would not ban sales of used cars, and it wouldn't force the state's residents to stop driving the roughly 29 million gas-powered cars that are already on the road. Californians also could keep importing new or used vehicles from out of state.

That means Californians will still own a lot of gas-powered cars past 2035, softening the blow for car mechanics and industries dependent on fossil fuels, said James Sallee, an economist and research associate at the Energy Institute at University of California, Berkeley's Haas School of Business. Sallee said the changes wouldn't occur fast enough to trigger a sharp economic slowdown within the auto repair industry.

One 67-year-old mechanic still tells CalMatters that "The electric vehicle repair market is just about nonexistent."

But another mechanic tells them "I'm not against electric vehicles. I've always loved cars and I'll work on them until I can't anymore. So we have to adjust. We have to get out of our comfort zones."
The Almighty Buck

NFT Conference Founder Predicts 97% of Current Projects Will Lose Value Through 2024 (twincities.com) 60

"Serial entrepreneur" Gary Vaynerchuk launched a four-day conference "exploring digital ownership and the way emerging technologies could interact with art, sports and entertainment," reports the Pioneer Press: It's billed as an event "featuring icons of business, sports, music, arts, Web3, and popular culture in conversation to build lasting relationships, share ideas, and connect with the community." VeeCon is expected to draw over 10,000 visitors from around world who will hear from 150 speakers, from New Age guru Deepak Chopra to filmmaker Spike Lee and the ubiquitous rapper Snoop Dogg. [Also speaking: Randi Zuckerberg, Mark Zuckerberg's sister]

Tickets were sold in the form of NFTs, which are non-fungible tokens sold on the blockchain, a digital ledger of transactions. Much of the conference will dive into the potential applications for NFTs.

Ami Barzelay, chief product officer of Crinkle, a shopping rewards optimizer, described NFT ownership as "digital bragging rights." An NFT, which could be an image, song or video, can be copied and enjoyed by anyone in the world, but it may have just one owner. The NFT market, still in its infancy, has seen wild swings in what people are willing to pay for digital assets, which Barzelay has experienced first-hand. He said that for fun, he paid $100 for a video clip of Tiger Woods and later sold it for $5,000.

There is inherent skepticism and fear around buying and selling things that don't exist in the physical world, which VeeCon aims to address.

The article quotes Vaynerchuk as saying "Education and communication solve everything," adding later that "NFTs are really fun for collectability, but it is a tiny part of the consumer blockchain."

CNBC points out that holders of the NFT-format tickets "also are given exclusive access to the annual event for three years after the NFT's purchase." Though they also end on a skeptical note: "Right now the overwhelming energy of the space is very short term. I would call it greed. Many are not spending their time on education," Vaynerchuk said.

"The reality is that all that behavior is going to lead to 97-98% of these current projects losing value over the next 24-36 months because the supply and demand curves will not work out."

The event's schedule included happy hours that were officially hosted by Johnnie Walker and Captain Morgan.

On Twitter one attendee reported from the festival that digital artist Beeple "just got caked in the face in front of 7,000 people by Steve Aoki and it was incredible."
Apple

Apple's Headset Said To Feature 14 Cameras Enabling Lifelike Avatars (macrumors.com) 15

Citing a report from The Information's Wayne Ma (paywalled), MacRumors reports Apple's long-rumored AR/VR headset is said to feature 14 cameras that enable lifelike avatars with accurate facial expressions. The company is also working with former design chief Jony Ive on the project. From the report: For starters, one of the headset's marquee features is said to be lifelike avatars with accurate facial expressions captured by 14 cameras: "Other challenges, such as incorporating 14 cameras on the headset, have caused headaches for hardware and algorithm engineers. The cameras include those that will track the user's face to ensure virtual avatars accurately represent their expressions and mouth movements, a marquee feature."

The report adds that Apple's former design chief Jony Ive has remained involved with the headset project as an external consultant to the company: "One person familiar with the matter said Ive's consulting work for Apple since he left includes the headset, adding that he is often brought in to help his former team push through their preferences in areas such as battery, camera placement and ergonomics over those of engineers. Two people said even after Ive left Apple, some employees on the headset project were still required to make the trek from Cupertino to San Francisco, where Ive has a home, to get his approval on changes. Ive has continued to tweak the headset's design. While earlier prototypes had the battery in the headband, he prefers a design that would tether the headset to a battery the user wears, similar to Magic Leap's headset design. It couldn't be learned if this approach will make it into the final design."

The initial version of Apple's headset is said to lack a focus on gaming: "Four people who have worked on the project also criticized its lack of focus on gaming, a category of software that appeals to early adopters, which was important to the success of the iPhone and has been a big priority for Meta's VR group. Those people said Rockwell's group almost never mentioned games in internal presentations about possible uses for the headset. Apple isn't developing game controllers for the device and is aiming to use hand tracking or in combination with a clothespin-like finger clip as inputs for the device, multiple people familiar with the project say."
On Thursday, Bloomberg reported that Apple executives previewed the upcoming headset to the company's board last week, "indicating that development of the device has reached an advanced stage."
Canada

Canada Set To Ban Chinese Tech Giant Huawei From 5G Network 70

Canada is planning to ban Huawei from working on Canada's fifth-generation networks. CBC.ca reports: The move puts Canada in line with key intelligence allies like the United States which have expressed concerns about the national security implications of giving the Chinese tech giant access to key infrastructure. [...] Critics have warned that Huawei's participation in Canada's 5G networks could give the company an inside look at how, when and where Canadians use internet-connected devices -- and that the Chinese government could force the company to hand over that personal information. China's National Intelligence Law says Chinese organizations and citizens must support, assist and co-operate with state intelligence work. [...] Huawei insists it is a fiercely independent company that does not engage in espionage for anyone, including Beijing.

Huawei already supplies some Canadian telecommunications firms with 4G equipment. As Global News has reported, telecommunication companies spent hundreds of millions of dollars on Huawei equipment while the federal government's review of 5G was ongoing -- although that number has waned over the years. It's not clear whether Ottawa's decision to bar Huawei from 5G will require those companies to rip out existing Huawei equipment, or whether compensation would be provided.
Wireless Networking

New Bluetooth Hack Can Unlock All Kinds of Devices (arstechnica.com) 123

An anonymous reader quotes a report from Ars Technica: When you use your phone to unlock a Tesla, the device and the car use Bluetooth signals to measure their proximity to each other. Move close to the car with the phone in hand, and the door automatically unlocks. Move away, and it locks. This proximity authentication works on the assumption that the key stored on the phone can only be transmitted when the locked device is within Bluetooth range. Now, a researcher has devised a hack that allows him to unlock millions of Teslas -- and countless other devices -- even when the authenticating phone or key fob is hundreds of yards or miles away. The hack, which exploits weaknesses in the Bluetooth Low Energy standard adhered to by thousands of device makers, can be used to unlock doors, open and operate vehicles, and gain unauthorized access to a host of laptops and other security-sensitive devices.
[...]
[The] attack uses custom software and about $100 worth of equipment. [Sultan Qasim Khan, a principal security consultant and researcher at security firm NCC Group] has confirmed it works against the Tesla Model 3 and Model Y and Kevo smart locks marketed under the Kwikset and Weiser brand names. But he says virtually any BLE device that authenticates solely on proximity -- as opposed to also requiring user interaction, geolocation querying, or something else -- is vulnerable. "The problem is that BLE-based proximity authentication is used in places where it was never safe to do so," he explained. "BLE is a standard for devices to share data; it was never meant to be a standard for proximity authentication. However, various companies have adopted it to implement proximity authentication."

Because the threat isn't caused by a traditional bug or error in either the Bluetooth specification or an implementation of the standard, there's no CVE designation used to track vulnerabilities. Khan added: "In general, any product relying on BLE proximity authentication is vulnerable if it does not require user interaction on the phone or key fob to approve the unlock and does not implement secure ranging with time-of-flight measurement or comparison of the phone/key fob's GPS or cellular location relative to the location of the device being unlocked. GPS or cellular location comparison may also be insufficient to prevent short distance relay attacks (such as breaking into a home's front door or stealing a car from the driveway, when the owner's phone or key fob is inside the house)."
There's a few countermeasures one can take to mitigate this attack. "One mechanism is to check the location of the authenticating device to ensure that it is, in fact, physically close to the locked car or other device," reports Ars.

"Another countermeasure is to require the user to provide some form of input to the authenticating device before it's trusted." The phone's accelerometer could also be used to measure its movements.

The advisories published by NCC Group can be found here, here, and here.
Python

Is Python About to Get Faster? (zdnet.com) 134

"Python 3.11 will bear the fruits of CPython's multi-year effort to make Python a faster programming language," reports ZDNet.

"Core Python (CPython) developer Mark Shannon shared details about the project to make Python faster at the PyCon 2022 conference this week..." Last year, Microsoft funded a project for the Python Software Foundation (PSF), led by Python creator Guido van Rossum and Shannon, to make Python twice as fast as the current stable 3.10 series. The vision is to nudge Python towards the performance of C. Microsoft hired van Rossum in 2020 and gave him a free hand to pick any project. At last year's PyCon 2021 conference, he said he "chose to go back to my roots" and would work on Python's famed lack of performance....

The Faster CPython Project provided some updates about CPython 3.11 performance over the past year. Ahead of PyCon 2022, the project published more results comparing the 3.11 beta preview to 3.10 on dozens of performance metrics, showing that 3.11 was overall 1.25 times faster than 3.10. Shannon is realistic about the project's ability to improve Python performance, but believes the improvements can extend Python's viable use to more virtual machines. "Python is widely acknowledged as slow. Whilst Python will never attain the performance of low-level languages like C, Fortran, or even Java, we would like it to be competitive with fast implementations of scripting languages, like V8 for Javascript or luajit for lua," he wrote last year in the Python Enhancement Proposal (PEP) 659.

"Specifically, we want to achieve these performance goals with CPython to benefit all users of Python including those unable to use PyPy or other alternative virtual machines...."

On the question of a just-in-time (JIT) compiler for Python's performance, Shannon suggested it was not a priority and would likely not arrive until Python 3.13, according to the Python Software Foundation's coverage of the event.... According to the Faster Python implementation plan, CPython 3.12 might gain a "simple JIT compiler for small regions" that compiles small regions of specialized code, while 3.13 would enhance the compiler to extend the regions for compilation.

AT&T

AT&T Is About To Get Away With Its Bogus $1.99 'Administrative Fee' (theverge.com) 24

Sean Hollister writes via The Verge: Since 2013, AT&T has quietly bilked customers out of hundreds of millions of dollars with a bogus "administrative fee," a fee it more than doubled to $1.99 a month in 2018. For a few years there, a California class-action lawsuit made it seem like AT&T might finally get taken to task. But this week, both sides told a judge they'd settle for just $14 million -- meaning customers may get less than 10 percent of what they paid AT&T, while AT&T gets to keep on charging them. According to the proposed settlement agreement in Vianu v. AT&T Mobility -- which still needs to be approved by a judge -- just about every AT&T Wireless postpaid customer in California since 2015 will be eligible for an estimated payment of between $15 and $29.

But again, that's only a fraction of what AT&T's own records show it charged: $180 per customer on average since 2015, according to documents. The settlement "represents a refund of approximately 6-11 months of the average fees," they read. Meanwhile, the lawyers are likely to get $3.5 million. "The estimated payment amount represents a strong result for the Settlement Class, particularly given the substantial risks, costs, and delay of continued litigation," reads the proposed settlement agreement, going on to list all the ways that the lawyers suing AT&T believe that AT&T might still win the case. [...]

Oh, and you won't even get a check in the mail if you're still an AT&T customer, assuming this version of the settlement is approved. The money will be credited back to your AT&T account, where AT&T can dip its hand right back in again for that $1.99 -- or more if it feels emboldened enough to increase the fee yet again. (Admittedly, the AT&T account could be a more reliable way to make sure customers get money back.)
The settlement websites can be found here.

An AT&T spokesperson issued the following response: "We deny the allegations in this lawsuit because we clearly disclose all fees that are charged to our customers. However, we have decided to settle this case to avoid lengthy, expensive litigation."
Businesses

'Crypto Muggings': Thieves in London Target Digital Investors By Taking Phones (theguardian.com) 68

Thieves are targeting digital currency investors on the street in a wave of "crypto muggings," police have warned, with victims reporting that thousands of pounds have been stolen after their mobile phones were seized. From a report: Anonymised crime reports provided to the Guardian by City of London police, as part of a freedom of information request, reveal criminals are combining physical muscle with digital knowhow to part people from their cryptocurrency. One victim reported they had been trying to order an Uber near Londonâ(TM)s Liverpool Street station when muggers forced them to hand over their phone. While the gang eventually gave the phone back, the victim later realised that $6,150-worth of ethereum digital currency was missing from their account with the crypto investing platform Coinbase.

In another case, a man was approached by a group of people offering to sell him cocaine and agreed to go down an alley with them to do the deal. The men offered to type a number into his phone but instead accessed his cryptocurrency account, holding him against a wall and forcing him to unlock a smartphone app with facial verification. They transferred $7,400-worth of ripple, another digital currency, out of his account. A third victim said he had been vomiting under a bridge when a mugger forced him to unlock his phone using a fingerprint, then changed his security settings and stole $35,300, including cryptocurrency.

Books

Free Comic Book Day Celebrates Big 20th Year with Many Geek-Friendly Titles (mashable.com) 34

"Comic book nerd Christmas has arrived," quips Mashable, noting this is the big 20th anniversary of Free Comic Book Day. Basically if you walk into your local comic book store on the first Saturday in May: they'll hand you some free comic books. Bleeding Cool points out that several stores are even having free signings from famous comic book artists and writers.

Although in 2017 NPR had this advice for visiting comics fans. "While you're there, buy something... The comics shops still have to pay for the 'free' FCBD books they stock, and they're counting on the increased foot traffic to lift sales."

The official site includes a comic-shop locator — but many of the comics are also available online as free downloads. (For example, as free ebooks in Amazon's Kindle store.) This year's free offerings include a special issue of a new Sleepy Hollow comic and a unique "yearbook" commemorating the 25th anniversary of Buffy the Vampire Slayer.

Other geek-friendly choices include:

And in addition — and perhaps inevitably.... "A new dawn of Archie is upon us!"


Transportation

Mercedes-Benz Opens Sales of Level 3 Self-Driving System In Germany (motor1.com) 71

An anonymous reader quotes a report from Motor1: The two flagship models from Mercedes-Benz, the S-Class and the all-electric EQS, will soon be able to be ordered with conditional self-driving tech in Germany. Starting from May 17, the so-called Drive Pilot system will be offered as an extra-cost option for the two sedans, allowing the driver to hand the entire control of the machine over to the system under certain conditions. The Stuttgart-based automaker became the first in the industry to receive international approval for Level 3 autonomous tech in December last year. Releasing the system on the market now becomes the next logical step and Mercedes will ask 5,000 euros for Drive Pilot on the S-Class and 7,430 euros on the EQS, respectively around $5,260 and $7,813 at the current exchange rates. These figures include both the required hardware and software and for now, no further subscriptions are needed.

It's important to note that Level 3 doesn't mean a fully autonomous vehicle. The system used by Mercedes allows the driver to hand all driving tasks to the tech in heavy traffic or on suitable motorways in Germany with speeds of up to 60 kilometers per hour. Under these conditions, the driver can fully disengage from driving with the system controlling the speed and distance, as well as guiding the vehicle within its lane. More importantly, the system also reacts to unexpected traffic situations and avoids dangerous maneuvers.
Mercedes is currently working on receiving certification in the United States, notes Motor1.
AI

Swarming Drones Autonomously Navigate a Dense Forest (techcrunch.com) 15

Chinese researchers show off a swarm of drones collectively navigating a dense forest they've never encountered. TechCrunch reports: Researchers at Zheijang University in Hangzhou have succeeded, however, with a 10-strong drone swarm smart enough to fly autonomously through a dense, unfamiliar forest, but small and light enough that each one can easily fit in the palm of your hand. It's a big step toward using swarms like this for things like aerial surveying and disaster response.

Based on an off-the-shelf ultra-compact drone design, the team built a trajectory planner for the group that relies entirely on data from the onboard sensors of the swarm, which they process locally and share with each other. The drones can balance or be directed to pursue various goals, such as maintaining a certain distance from obstacles or each other, or minimizing the total flight time between two points, and so on.

The drones can also, worryingly, be given a task like "follow this human." We've all seen enough movies to know this is how it starts ... but of course it could be useful in rescue or combat circumstances as well. A part of their navigation involves mapping the world around them, of course, and the paper includes some very cool-looking 3D representations of the environments the swarm was sent through. Zhou et alThe study is published in the most recent issue of the journal Science Robotics, which you can read here, along with several videos showing off the drones in action.

Communications

VPN Providers Threaten To Quit India Over New Data Law (wired.com) 26

VPN companies are squaring up for a fight with the Indian government over new rules designed to change how they operate in the country. Wired: On April 28, officials announced that virtual private network companies will be required to collect swathes of customer data -- and maintain it for five years or more -- under a new national directive. VPN providers have two months to accede to the rules and start collecting data. The justification from the country's Computer Emergency Response Team (CERT-In) is that it needs to be able to investigate potential cybercrime. But that doesn't wash with VPN providers, some of whom have said they may ignore the demands.

"This latest move by the Indian government to require VPN companies to hand over user personal data represents a worrying attempt to infringe on the digital rights of its citizens," says Harold Li, vice president of ExpressVPN. He adds that the company would never log user information or activity and that it will adjust its "operations and infrastructure to preserve this principle if and when necessary." Other VPN providers are also considering their options. Gytis Malinauskas, head of Surfshark's legal department, says the VPN provider couldn't currently comply with India's logging requirements because it uses RAM-only servers, which automatically overwrite user-related data. [...] ProtonVPN is similarly concerned, calling the move an erosion of civil liberties.

United States

The US Birth Rate Is Bouncing Back From the Pandemic (marketwatch.com) 145

An anonymous reader quotes a report from MarketWatch: When the pandemic hit, the stay-at-home orders didn't give American families more babies, instead, it generated a "baby bust." Now, economists found that the so-called bust recovered just as quickly as the economy picked up. Recessions and a decline in birth rates go hand-in-hand in history -- as seen with the 2008 financial crisis and the 1918 influenza, when the pandemic started in early 2020. Similarly, economists predicted that a sharp decrease in jobs and household spending would result in a fall in conception rates.

Job cuts and business shutdowns resulted in 62,000 "missing births" in the U.S. from January 2020 to May 2020, the paper found. The lowest dip in approximate conception numbers happened in April, when the country saw the highest COVID-era unemployment rate at 14.7%. But the "baby bust" was short-lived due to a rebound of 51,000 conceptions later in 2020, driven by fast growth in the labor market and the arrival of government relief programs to individuals and households. The paper, which was distributed this week by the National Bureau of Economic Research, used five years of monthly birth data from October 2016 through September 2021, the most recent month available when the researchers conducted their analysis.

The immediate drop in conception rate in the U.S. at the beginning of the COVID-19 outbreak was part of a bigger global trend for countries with higher incomes. Arnstein Aassve, professor of social and political science at Bocconi University, has found that seven out of 22 countries with higher incomes experienced a sharp decline in birth rates at the beginning of the pandemic. He attributed the explanation to a sense of uncertainty. "You may not forego childbearing totally, but at least you might postpone it until you see that times are a bit better," Aassve told Scientific American. He also attributed the sentiment to people's unfamiliarity with a new disease at the time. Kearney said the NBER findings confirm this pattern. By comparing data from different states, she pointed out that although the number of COVID-19 cases in the region also contributed to the reduction of birth rates early in the pandemic, people started having more babies later in the year regardless of the number of new COVID-19 cases. However, Levine said that the changes in 2020 are "far less significant" compared to the general U.S. trend in the last 15 years, which results in a roughly 20% drop in births. The decline in birth rates indicates a challenge ahead for labor supply.

Earth

Documentary Explores How Big Oil Stalled Climate Action for Decades (theguardian.com) 174

Slashdot reader XXongo brings word of a new three-part documentary — streaming free now — that tries to understand America's early inaction on climate change. Looking back over the last few decades, The Power of Big Oil explores how the fuel industry "successfully set up a campaign to discredit climate science and targetting individual politicians to vote against measures to curb climate change."

The Guardian notes that the series includes an interview with a U.S. senator who they say "blames the oil industry for malignly claiming the science of climate change was not proved when companies such as Exxon and Shell already knew otherwise from their own research."

As far back as 25 years ago, the senator says, "they had evidence in their own institutions that countered what they were saying publicly. I mean — they lied." The documentary's makers have dug out a parade of former oil company scientists, lobbyists and public relations strategists who lay bare how the US's biggest petroleum firm, Exxon, and then the broader petroleum industry, moved from attempting to understand the causes of a global heating to a concerted campaign to hide the making of an environmental catastrophe. Over three episodes — called Denial, Doubt, Delay — the series charts corporate manipulation of science, public opinion and politicians that mirrors conduct by other industries, from big tobacco to the pharmaceutical companies responsible for America's opioid epidemic.

Some of those interviewed shamefacedly admit their part in the decades-long campaign to hide the evidence of climate change, discredit scientists and delay action that threatened big oil's profits.

Others almost boast about how easy it was to dupe the American public and politicians, with consequences not just for the US but every country on the planet.

In one video clip an aide to a climate-conscious senator remembers that "You had reams of material coming out of the government. They were at the National Oceanic and Atmospheric Administration, at NASA — this expanding network of people, working on this day in and day out, saying that this was a legitimate issue, and that we needed to do something about it. And on the other hand, you had two or three guys who went around to conferences and said, 'Oh, I'm not sure. Oh, maybe there's clouds....' It quickly became apparent that these were private interests who had a stake in the status quo." He refers to it as "emerging industry of nay-sayers."

There's also a discouraged assessment from climate activist looking back over a lack of progress in the early decades. "You want to make an assumption that it's a meritocracy — a good argument will prevail, and it will displace a bad argument. But, what the geniuses at the PR firms who work for these big fossil-fuel companies know is that truth has nothing to do with who wins the argument. If you say something enough times, people will begin to believe it."
Android

North Koreans Are Jailbreaking Phones To Access Forbidden Media (wired.com) 23

An anonymous reader quotes a report from Wired: For most of the world, the common practice of "rooting" or "jailbreaking" a phone allows the device's owner to install apps and software tweaks that break the restrictions of Apple's or Google's operating systems. For a growing number of North Koreans, on the other hand, the same form of hacking allows them to break out of a far more expansive system of control -- one that seeks to extend to every aspect of their lives and minds. On Wednesday, the North Korea-focused human rights organization Lumen and Martyn Williams, a researcher at the Stimson Center think tank's North Korea -- focused 38 North project, together released a report on the state of smartphones and telecommunications in the Democratic People's Republic of Korea, a country that restricts its citizens' access to information and the internet more tightly than any other in the world. The report details how millions of government-approved, Android-based smartphones now permeate North Korean society, though with digital restrictions that prevent their users from downloading any app or even any file not officially sanctioned by the state. But within that regime of digital repression, the report also offers a glimpse of an unlikely new group: North Korean jailbreakers capable of hacking those smartphones to secretly regain control of them and unlock a world of forbidden foreign content.

Learning anything about the details of subversive activity in North Korea -- digital or otherwise -- is notoriously difficult, given the Hermit Kingdom's nearly airtight information controls. Lumen's findings on North Korean jailbreaking are based on interviews with just two defectors from the country. But Williams says the two escapees both independently described hacking their phones and those of other North Koreans, roughly corroborating each others' telling. Other North Korea -- focused researchers who have interviewed defectors say they've heard similar stories. Both jailbreakers interviewed by Lumen and Williams said they hacked their phones -- government-approved, Chinese-made, midrange Android phones known as the Pyongyang 2423 and 2413 -- primarily so that they could use the devices to watch foreign media and install apps that weren't approved by the government. Their hacking was designed to circumvent a government-created version of Android on those phones, which has for years included a certificate system that requires any file downloaded to the device to be "signed" with a cryptographic signature from government authorities, or else it's immediately and automatically deleted. Both jailbreakers say they were able to remove that certificate authentication scheme from phones, allowing them to install forbidden apps, such as games, as well as foreign media like South Korean films, TV shows, and ebooks that North Koreans have sought to access for decades despite draconian government bans.

In another Orwellian measure, Pyongyang phones' government-created operating system takes screenshots of the device at random intervals, the two defectors say -- a surveillance feature designed to instill a sense that the user is always being monitored. The images from those screenshots are then kept in an inaccessible portion of the phone's storage, where they can't be viewed or deleted. Jailbreaking the phones also allowed the two defectors to access and wipe those surveillance screenshots, they say. The two hackers told Lumen they used their jailbreaking skills to remove restrictions from friends' phones, as well. They said they also knew of people who would jailbreak phones as a commercial service, though often for purposes that had less to do with information freedom than more mundane motives. Some users wanted to install a certain screensaver on their phone, for instance, or wipe the phone's surveillance screenshots merely to free up storage before selling the phone secondhand.
As for how the jailbreaking was done, the report says both jailbreakers "described attaching phones to a Windows PC via a USB cable to install a jailbreaking tool."

"One mentioned that the Pyongyang 2423's software included a vulnerability that allowed programs to be installed in a hidden directory. The hacker says they exploited that quirk to install a jailbreaking program they'd downloaded while working abroad in China and then smuggled back into North Korea." The other hacker might've obtained his jailbreaking tool in a computer science group at Pyongyang's elite Kim Il Sung University where he attended.
Music

Researchers Develop a Paper-Thin Loudspeaker (mit.edu) 66

MIT engineers have developed a paper-thin loudspeaker that can turn any surface into an active audio source. MIT News reports: This thin-film loudspeaker produces sound with minimal distortion while using a fraction of the energy required by a traditional loudspeaker. The hand-sized loudspeaker the team demonstrated, which weighs about as much as a dime, can generate high-quality sound no matter what surface the film is bonded to. To achieve these properties, the researchers pioneered a deceptively simple fabrication technique, which requires only three basic steps and can be scaled up to produce ultrathin loudspeakers large enough to cover the inside of an automobile or to wallpaper a room.

A typical loudspeaker found in headphones or an audio system uses electric current inputs that pass through a coil of wire that generates a magnetic field, which moves a speaker membrane, that moves the air above it, that makes the sound we hear. By contrast, the new loudspeaker simplifies the speaker design by using a thin film of a shaped piezoelectric material that moves when voltage is applied over it, which moves the air above it and generates sound. [...]

They tested their thin-film loudspeaker by mounting it to a wall 30 centimeters from a microphone to measure the sound pressure level, recorded in decibels. When 25 volts of electricity were passed through the device at 1 kilohertz (a rate of 1,000 cycles per second), the speaker produced high-quality sound at conversational levels of 66 decibels. At 10 kilohertz, the sound pressure level increased to 86 decibels, about the same volume level as city traffic. The energy-efficient device only requires about 100 milliwatts of power per square meter of speaker area. By contrast, an average home speaker might consume more than 1 watt of power to generate similar sound pressure at a comparable distance.
The researchers showed the speaker in action, playing "We Are the Champions" by Queen. You can listen to it here.
Facebook

Facebook Doesn't Know What It Does With Your Data, Or Where It Goes (vice.com) 59

em1ly shares a report from Motherboard: Facebook is facing what it describes internally as a "tsunami" of privacy regulations all over the world, which will force the company to dramatically change how it deals with users' personal data. And the "fundamental" problem, the company admits, is that Facebook has no idea where all of its user data goes, or what it's doing with it, according to a leaked internal document obtained by Motherboard. "We've built systems with open borders. The result of these open systems and open culture is well described with an analogy: Imagine you hold a bottle of ink in your hand. This bottle of ink is a mixture of all kinds of user data (3PD, 1PD, SCD, Europe, etc.) You pour that ink into a lake of water (our open data systems; our open culture) ... and it flows ... everywhere," the document read. "How do you put that ink back in the bottle? How do you organize it again, such that it only flows to the allowed places in the lake?" (3PD means third-party data; 1PD means first-party data; SCD means sensitive categories data.)

The document was written last year by Facebook privacy engineers on the Ad and Business Product team, whose mission is "to make meaningful connections between people and businesses," and which "sits at the center of our monetization strategy and is the engine that powers Facebook's growth," according to a recent job listing that describes the team. This is the team that is tasked with building and maintaining Facebook's sprawling ads system, the core of the company's business. And in this document, the team is both sounding an alarm, and making a call to change how Facebook deals with users' data to prevent the company from running into trouble with regulators in Europe, the US, India, and other countries that are pushing for more stringent privacy constraints on social media companies. "We do not have an adequate level of control and explainability over how our systems use data, and thus we can't confidently make controlled policy changes or external commitments such as 'we will not use X data for Y purpose.' And yet, this is exactly what regulators expect us to do, increasing our risk of mistakes and misrepresentation," the document read. In other words, even Facebook's own engineers admit that they are struggling to make sense and keep track of where user data goes once it's inside Facebook's systems, according to the document. This problem inside Facebook is known as "data lineage."

NASA

NASA's Space Telecoms Network May Soon Be Outsourced (space.com) 23

vm shares a report from Space.com: SpaceX is among companies that might replace services of NASA's aging space telecoms constellation that has kept the International Space Station connected to Earth for decades. For years, NASA's Tracking and Data Relay Satellite (TDRS) constellation has served as the main link between the International Space Station and Earth, providing astronauts with constant connection to ground control as well as the ability to engage with the public and stay in touch with their loved ones. The American space agency, however, plans to retire the six aging satellites in the next decade and hand over their task to commercial companies. This month, the agency announced partnerships with six commercial satellite operators including SpaceX, U.K. company Inmarsat, American Viasat and Switzerland-based SES, to demonstrate how they could take care of NASA's space communication needs in the future. "We don't plan to launch any new TDRS satellites in the future," Eli Naffah, the manager of NASA's Commercial Services Project, who oversees the partnership with the commercial companies, told Space.com. "The plan is to allow the constellation to basically [reach the end of its life]. At some point later in this decade, we are going to have some diminished capability and the plan is for the [commercial companies] to come up with a different way of providing communication services to our missions."

"Back in the 1980s, when we developed TDRS, there really wasn't an ability on the commercial side to be able to provide this service," Naffah said. "But since then, the industry has far outpaced NASA's investment in this area. There's a lot of infrastructure, both on the ground and in orbit that is capable of providing these types of services to a spacecraft. [...] Hopefully, we can achieve some cost efficiencies in buying commercial services, get out of the business of operating networks, and really put more focus on science and exploration." According to Naffah, NASA will invest $278 million into the project over the next five years, with the agency's industry partners contributing a total of about $1.5 billion.
Government

Open-Source Intelligence: How Bellingcat Uses Data Gathered by Authoritarian Governments (cnn.com) 52

CNN profiles Bellingcat, a Netherlands-based investigative group specializing in "open-source intelligence". And investigator Christo Grozev tells CNN that authoritarian governments make their work easier, because "they love to gather data, comprehensive data, on ... what they consider to be their subjects, and therefore there's a lot of centralized data."

"And second, there's a lot of petty corruption ... within the law enforcement system, and this data market thrives on that." Billions have been spent on creating sophisticated encrypted communications for the military in Russia. But most of that money has been stolen in corrupt kickbacks, and the result is they didn't have that functioning system... It is shocking how incompetent they are. But it was to be expected, because it's a reflection of 23 years of corrupt government.
Interestingly there's apparently less corruption in China — though more whistleblowers. But Bellingcat's first investigation involved the 2014 downing of a Boeing 777 over eastern Ukraine that killed 283 passengers. (The Dutch Safety Board later concluded it was downed by a surface-to-air missile launched from pro-Russian separatist-controlled territory in Ukraine.) "At that time, a lot of public data was available on Russian soldiers, Russian spies, and so on and so forth — because they still hadn't caught up with the times, so they kept a lot of digital traces, social media, posting selfies in front of weapons that shoot down airliners. That's where we kind of perfected the art of reconstructing a crime based on digital breadcrumbs..."

"By 2016, it was no longer possible to find soldiers leaving status selfies on the internet because a new law had been passed in Russia, for example, banning the use of mobile phones by secret services and by soldiers. So we had to develop a new way to get data on government crime. We found our way into this gray market of data in Russia, which is comprised of many, many gigabytes of leaked databases, car registration databases, passport databases. Most of these are available for free, completely freely downloadable from torrent sites or from forums and the internet." And for some of them, they're more current. You actually can buy the data through a broker, so we decided that in cases when we have a strong enough hypothesis that a government has committed the crime, we should probably drop our ethical boundaries from using such data — as long as it is verifiable, as long as it is not coming from one source only but corroborated by at least two or three other sources of data. That's how we develop it. And the first big use case for this approach was the ... poisoning of Sergei and Yulia Skripal in 2018 (in the United Kingdom), when we used this combination of open source and data bought from the gray market in Russia to piece together who exactly the two poisoners were. And that worked tremendously....

It has been what I best describe as a multilevel computer game.... [W]hen we first learned that we can get private data, passport files and residence files on Russian spies who go around killing people, they closed the files on those people. So every spy suddenly had a missing passport file in the central password database. But that opened up a completely new way for us to identify spies, because we were just able to compare older versions of the database to newer versions. So that allowed us to find a bad group of spies that we didn't even know existed before.

The Russian government did realize that that's maybe a bad idea to hide them from us, so they reopened those files but just started poisoning data. They started changing the photographs of some of these people to similar looking, like lookalikes of the people, so that they confused us or embarrass us if we publish a finding but it's for the wrong guy. And then we'll learn how to beat that.

When asked about having dropped some ethical boundaries about data use, Grozev replies "everything changes. Therefore, the rules of journalism should change with the changing times." "And it's not common that journalism was investigating governments conducting government-sanctioned crimes, but now it's happening." With a country's ruler proclaiming perpetual supreme power, "This is not a model that traditional journalism can investigate properly. It's not even a model that traditional law enforcement can investigate properly." I'll give an example. When the British police asked, by international agreement, for cooperation from the Russian government to provide evidence on who exactly these guys were who were hanging around the Skripals' house in 2018, they got completely fraudulent, fake data from the Russian government....

So the only way to counter that as a journalist is to get the data that the Russian government is refusing to hand over. And if this is the only way to get it, and if you can be sure that you can prove that this is valid data and authentic data — I think it is incumbent on journalists to find the truth. And especially when law enforcement refuses to find the truth because of honoring the sovereign system of respecting other governments.

It was Bellingcat that identified the spies who's poisoned Russian opposition leader Alexey Navalny. CNN suggests that for more details on their investigation, and "to understand Vladimir Putin's stranglehold on power in Russia, watch the new film Navalny which premieres Sunday at 9 p.m. ET on CNN."

The movie's tagline? "Poison always leaves a trail."

Slashdot Top Deals