Windows

Microsoft Is Plugging More Holes That Let You Use Windows 11 Without an Online Account 215

Microsoft is eliminating all known workarounds that let users install Windows 11 without an internet connection or Microsoft account, forcing everyone through the online setup process. The Verge reports: "We are removing known mechanisms for creating a local account in the Windows Setup experience (OOBE)," says Amanda Langowski, the lead for the Windows Insider Program. "While these mechanisms were often used to bypass Microsoft account setup, they also inadvertently skip critical setup screens, potentially causing users to exit OOBE with a device that is not fully configured for use."

The changes mean Windows 11 users will need to complete the OOBE screens with an internet connection and Microsoft account in future versions of the OS. Microsoft already removed the "bypassnro" workaround earlier this year, and today's changes also disable the "start ms-cxh:localonly" command that Windows 11 users discovered after Microsoft's previous changes. Using this command now resets the OOBE process and it fails to bypass the Microsoft account requirement.
Security

Redis Warns of Critical Flaw Impacting Thousands of Instances (bleepingcomputer.com) 3

An anonymous reader quotes a report from BleepingComputer: The Redis security team has released patches for a maximum severity vulnerability that could allow attackers to gain remote code execution on thousands of vulnerable instances. Redis (short for Remote Dictionary Server) is an open-source data structure store used in approximately 75% of cloud environments, functioning like a database, cache, and message broker, and storing data in RAM for ultra-fast access. The security flaw (tracked as CVE-2025-49844) is caused by a 13-year-old use-after-free weakness found in the Redis source code and can be exploited by authenticated threat actors using a specially crafted Lua script (a feature enabled by default). Successful exploitation enables them to escape the Lua sandbox, trigger a use-after-free, establish a reverse shell for persistent access, and achieve remote code execution on the targeted Redis hosts.

After compromising a Redis host, attackers can steal credentials, deploy malware or cryptocurrency mining tools, extract sensitive data from Redis, move laterally to other systems within the victim's network, or use stolen information to gain access to other cloud services. "This grants an attacker full access to the host system, enabling them to exfiltrate, wipe, or encrypt sensitive data, hijack resources, and facilitate lateral movement within cloud environments," said Wiz researchers, who reported the security issue at Pwn2Own Berlin in May 2025 and dubbed it RediShell.

While successful exploitation requires attackers first to gain authenticated access to a Redis instance, Wiz found around 330,000 Redis instances exposed online, with at least 60,000 of them not requiring authentication. Redis and Wiz urged admins to patch their instances immediately by applying security updates released on Friday, "prioritizing those that are exposed to the internet." To further secure their Redis instances against remote attacks, admins can also enable authentication, disable Lua scripting and other unnecessary commands, launch Redis using a non-root user account, enable Redis logging and monitoring, limit access to authorized networks only, and implement network-level access controls using firewalls and Virtual Private Clouds (VPCs).

Submission + - Redis Warns of Critical Flaw Impacting Thousands of Instances (bleepingcomputer.com)

An anonymous reader writes: The Redis security team has released patches for a maximum severity vulnerability that could allow attackers to gain remote code execution on thousands of vulnerable instances. Redis (short for Remote Dictionary Server) is an open-source data structure store used in approximately 75% of cloud environments, functioning like a database, cache, and message broker, and storing data in RAM for ultra-fast access. The security flaw (tracked as CVE-2025-49844) is caused by a 13-year-old use-after-free weakness found in the Redis source code and can be exploited by authenticated threat actors using a specially crafted Lua script (a feature enabled by default). Successful exploitation enables them to escape the Lua sandbox, trigger a use-after-free, establish a reverse shell for persistent access, and achieve remote code execution on the targeted Redis hosts.

After compromising a Redis host, attackers can steal credentials, deploy malware or cryptocurrency mining tools, extract sensitive data from Redis, move laterally to other systems within the victim's network, or use stolen information to gain access to other cloud services. "This grants an attacker full access to the host system, enabling them to exfiltrate, wipe, or encrypt sensitive data, hijack resources, and facilitate lateral movement within cloud environments," said Wiz researchers, who reported the security issue at Pwn2Own Berlin in May 2025 and dubbed it RediShell.

While successful exploitation requires attackers first to gain authenticated access to a Redis instance, Wiz found around 330,000 Redis instances exposed online, with at least 60,000 of them not requiring authentication. Redis and Wiz urged admins to patch their instances immediately by applying security updates released on Friday, "prioritizing those that are exposed to the internet." To further secure their Redis instances against remote attacks, admins can also enable authentication, disable Lua scripting and other unnecessary commands, launch Redis using a non-root user account, enable Redis logging and monitoring, limit access to authorized networks only, and implement network-level access controls using firewalls and Virtual Private Clouds (VPCs).

Businesses

Cory Doctorow Explains Why Amazon is 'Way Past Its Prime' (theguardian.com) 116

"It's not just you. The internet is getting worse, fast," writes Cory Doctorow. Sunday he shared an excerpt from his upcoming book Enshittification: Why Everything Suddenly Got Worse and What to Do About It.

He succinctly explains "this moment we're living through, this Great Enshittening" using Amazon as an example. Platforms amass users, but then abuse them to make things better for their business customers. And then they abuse those business customers too, abusing everybody while claiming all the value for themselves. "And become a giant pile of shit."

So first Amazon subsidized prices and shipping, then locked in customers with Prime shipping subscriptions (while adding the chains of DRM to its ebooks and audiobooks)... These tactics — Prime, DRM and predatory pricing — make it very hard not to shop at Amazon. With users locked in, to proceed with the enshittification playbook, Amazon needed to get its business customers locked in, too... [M]erchants' dependence on those customers allows Amazon to extract higher discounts from those merchants, and that brings in more users, which makes the platform even more indispensable for merchants, allowing the company to require even deeper discounts...

[Amazon] uses its overview of merchants' sales, as well as its ability to observe the return addresses on direct shipments from merchants' contracting factories, to cream off its merchants' bestselling items and clone them, relegating the original seller to page umpty-million of its search results. Amazon also crushes its merchants under a mountain of junk fees pitched as optional but effectively mandatory. Take Prime: a merchant has to give up a huge share of each sale to be included in Prime, and merchants that don't use Prime are pushed so far down in the search results, they might as well cease to exist. Same with Fulfilment by Amazon, a "service" in which a merchant sends its items to an Amazon warehouse to be packed and delivered with Amazon's own inventory. This is far more expensive than comparable (or superior) shipping services from rival logistics companies, and a merchant that ships through one of those rivals is, again, relegated even farther down the search rankings.

All told, Amazon makes so much money charging merchants to deliver the wares they sell through the platform that its own shipping is fully subsidised. In other words, Amazon gouges its merchants so much that it pays nothing to ship its own goods, which compete directly with those merchants' goods.... Add all the junk fees together and an Amazon seller is being screwed out of 45-51 cents on every dollar it earns there. Even if it wanted to absorb the "Amazon tax" on your behalf, it couldn't. Merchants just don't make 51% margins. So merchants must jack up prices, which they do. A lot... [W]hen merchants raise their prices on Amazon, they are required to raise their prices everywhere else, even on their own direct-sales stores. This arrangement is called most-favoured-nation status, and it's key to the U.S. Federal Trade Commission's antitrust lawsuit against Amazon...

If Amazon is taxing merchants 45-51 cents on every dollar they make, and if merchants are hiking their prices everywhere their goods are sold, then it follows you're paying the Amazon tax no matter where you shop — even the corner mom-and-pop hardware store. It gets worse. On average, the first result in an Amazon search is 29% more expensive than the best match for your search. Click any of the top four links on the top of your screen and you'll pay an average of 25% more than you would for your best match — which, on average, is located 17 places down in an Amazon search result.

Doctorow knows what we need to do:
  • Ban predatory pricing — "selling goods below cost to keep competitors out of the market (and then jacking them up again)."
  • Impose structural separation, "so it can either be a platform, or compete with the sellers that rely on it as a platform."
  • Curb junk fees, "which suck 45-51 cents on every dollar merchants take in."
  • End its most favoured nation deal, which forces merchants "to raise their prices everywhere else, too.
  • Unionise drivers and warehouse workers.
  • Treat rigged search results as the fraud they are.

These are policy solutions. (Because "You can't shop your way out of a monopoly," Doctorow warns.) And otherwise, as Doctorow says earlier, "Once a company is too big to fail, it becomes too big to jail, and then too big to care."

In the mean time, Doctorow also makes up a new word — "the enshitternet" — calling it "a source of pain, precarity and immiseration for the people we love.

"The indignities of harassment, scams, disinformation, surveillance, wage theft, extraction and rent-seeking have always been with us, but they were a minor sideshow on the old, good internet and they are the everything and all of the enshitternet."

Thanks to long-time Slashdot readers mspohr and fjo3 for sharing the article.


Submission + - Way past its prime: how did Amazon get so rubbish? (theguardian.com)

fjo3 writes: It’s not just you. The internet is getting worse, fast. The services we rely on, that we once loved? They’re all turning into piles of shit, all at once. Ask any Facebook user who has to scroll past 10 screens of engagement-bait, AI slop and surveillance ads just to get to one post by the people they are on the service to communicate with. This is infuriating. Frustrating. And, depending on how important those services are to you, terrifying.

In 2022, I coined a term to describe the sudden-onset platform collapse going on all around us: enshittification. To my bittersweet satisfaction, that word is doing big numbers. In fact, it has achieved escape velocity. It isn’t just a way to say something got worse. It’s an analysis that explains the way an online service gets worse, how that worsening unfolds, and the contagion that’s causing everything to get worse, all at once.

This moment we’re living through, this Great Enshittening, is a material phenomenon, much like a disease, with symptoms, a mechanism and an epidemiology. When doctors observe patients who are sick with a novel pathogen, their first order of business is creating a natural history of the disease. This natural history is an ordered catalogue of the disease’s progress: what symptoms do patients exhibit, and in which order?

Android

Google Confirms Android Dev Verification Will Have Free and Paid Tiers, No Public List of Devs (arstechnica.com) 29

An anonymous reader quotes a report from Ars Technica: As we careen toward a future in which Google has final say over what apps you can run, the company has sought to assuage the community's fears with a blog post and a casual "backstage" video. Google has said again and again since announcing the change that sideloading isn't going anywhere, but it's definitely not going to be as easy. The new information confirms app installs will be more reliant on the cloud, and devs can expect new fees, but there will be an escape hatch for hobbyists.

Confirming app verification status will be the job of a new system component called the Android Developer Verifier, which will be rolled out to devices in the next major release of Android 16. Google explains that phones must ensure each app has a package name and signing keys that have been registered with Google at the time of installation. This process may break the popular FOSS storefront F-Droid. It would be impossible for your phone to carry a database of all verified apps, so this process may require Internet access. Google plans to have a local cache of the most common sideloaded apps on devices, but for anything else, an Internet connection is required. Google suggests alternative app stores will be able to use a pre-auth token to bypass network calls, but it's still deciding how that will work.

The financial arrangement has been murky since the initial announcement, but it's getting clearer. Even though Google's largely automated verification process has been described as simple, it's still going to cost developers money. The verification process will mirror the current Google Play registration fee of $25, which Google claims will go to cover administrative costs. So anyone wishing to distribute an app on Android outside of Google's ecosystem has to pay Google to do so. What if you don't need to distribute apps widely? This is the one piece of good news as developer verification takes shape. Google will let hobbyists and students sign up with only an email for a lesser tier of verification. This won't cost anything, but there will be an unclear limit on how many times these apps can be installed. The team in the video strongly encourages everyone to go through the full verification process (and pay Google for the privilege). We've asked Google for more specifics here.

Submission + - Google Confirms Android Dev Verification Will Have Free and Paid Tiers (arstechnica.com)

An anonymous reader writes: As we careen toward a future in which Google has final say over what apps you can run, the company has sought to assuage the community's fears with a blog post and a casual "backstage" video. Google has said again and again since announcing the change that sideloading isn't going anywhere, but it's definitely not going to be as easy. The new information confirms app installs will be more reliant on the cloud, and devs can expect new fees, but there will be an escape hatch for hobbyists.

Confirming app verification status will be the job of a new system component called the Android Developer Verifier, which will be rolled out to devices in the next major release of Android 16. Google explains that phones must ensure each app has a package name and signing keys that have been registered with Google at the time of installation. This process may break the popular FOSS storefront F-Droid. It would be impossible for your phone to carry a database of all verified apps, so this process may require Internet access. Google plans to have a local cache of the most common sideloaded apps on devices, but for anything else, an Internet connection is required. Google suggests alternative app stores will be able to use a pre-auth token to bypass network calls, but it's still deciding how that will work.

The financial arrangement has been murky since the initial announcement, but it's getting clearer. Even though Google's largely automated verification process has been described as simple, it's still going to cost developers money. The verification process will mirror the current Google Play registration fee of $25, which Google claims will go to cover administrative costs. So anyone wishing to distribute an app on Android outside of Google's ecosystem has to pay Google to do so. What if you don't need to distribute apps widely? This is the one piece of good news as developer verification takes shape. Google will let hobbyists and students sign up with only an email for a lesser tier of verification. This won't cost anything, but there will be an unclear limit on how many times these apps can be installed. The team in the video strongly encourages everyone to go through the full verification process (and pay Google for the privilege). We've asked Google for more specifics here.

The Internet

What Happened When a Pacific Island Was Cut Off From the Internet (theguardian.com) 38

The Hunga Tonga-Hunga Ha'apai volcano erupted on January 15, 2022. The pyroclastic flow severed both of Tonga's underwater internet cables. The eruption cut sixty-five miles from the domestic cable and fifty-five miles from the international link to Fiji. Tonga lost all internet access. The cables sit on the ocean floor and carry 95% of the world's international internet traffic.

The Guardian has a long read on what happened in the aftermath. A.T.M.s (cash machines) stopped working because banks could not verify account balances. Businesses could not file export paperwork. Foreign remittances made up 44% of the country's G.D.P. The government found old satellite phones. Three or four days later, officials restored a hundred and twenty megabytes per second of bandwidth for essential work. A month after the eruption, SpaceX donated fifty Starlink terminals. SubCom's repair ship Reliance took five weeks to restore the international cable. Vava'u did not get broadband back until August, 2023. Another earthquake in the summer of 2024 severed the domestic cable again.
The Internet

A Bullet Crashed the Internet In Texas (404media.co) 104

alternative_right writes: Last week, thousands of people in North and Central Texas were suddenly knocked offline. The cause? A bullet. The outage hit cities all across the state, including Dallas, Irving, Plano, Arlington, Austin, and San Antonio. The outage affected Spectrum customers and took down their phone lines and TV services as well as the internet.

"The outage stemmed from a fiber optic cable that was damaged by a stray bullet," Spectrum told 404 Media. "Our teams worked quickly to make the necessary repairs and get customers back online. We apologize for the inconvenience."

Spectrum told 404 Media that it didn't have any further details to share about the incident so we have no idea how the company learned a bullet hit its equipment, where the bullet was found, and if the police are involved.

Television

Cable Nostalgia Persists As Streaming Gets More Expensive, Fragmented (arstechnica.com) 35

An anonymous reader quotes a report from Ars Technica: TiVo's Q2 2025 Video Trends Report: North America released today points to growth in cord reviving. It reads: "The share of respondents who cut the cord but later decided to resubscribe to a traditional TV service has increased about 10 percent, to 31.9 percent in Q2 2025." TiVo's report is based on a survey conducted by an unspecified third-party survey service in Q2 2025. The respondents are 4,510 people who are at least 18 years old and living in the US or Canada, and the survey defines traditional TV services as pay-TV platforms offering linear television via cable, satellite, or managed IPTV platforms.

It's important to note that TiVo is far from an impartial observer. In addition to selling an IPTV platform, its parent company, Xperi, works with cable, broadband, and pay-TV providers and would directly benefit from the existence or perception of a cord reviving "trend." When reached for comment, a TiVo spokesperson said via email that cord reviving is driven by a "mixture of reasons, with internet bundle costs, familiarity of use, and local content (sports, news, etc.) being the primary drivers." The rep noted that it's "likely" that those re-subscribing to traditional TV services are using them alongside some streaming subscriptions. "It's possible that users are churning off some [streaming] services where there is overlap with traditional TV services," TiVo's spokesperson said.

Submission + - Cable Nostalgia Persists As Streaming Gets More Expensive, Fragmented (arstechnica.com)

An anonymous reader writes: TiVo's Q2 2025 Video Trends Report: North America released today points to growth in cord reviving. It reads: "The share of respondents who cut the cord but later decided to resubscribe to a traditional TV service has increased about 10 percent, to 31.9 percent in Q2 2025." TiVo’s report is based on a survey conducted by an unspecified third-party survey service in Q2 2025. The respondents are 4,510 people who are at least 18 years old and living in the US or Canada, and the survey defines traditional TV services as pay-TV platforms offering linear television via cable, satellite, or managed IPTV platforms.

It’s important to note that TiVo is far from an impartial observer. In addition to selling an IPTV platform, its parent company, Xperi, works with cable, broadband, and pay-TV providers and would directly benefit from the existence or perception of a cord reviving "trend." When reached for comment, a TiVo spokesperson said via email that cord reviving is driven by a “mixture of reasons, with internet bundle costs, familiarity of use, and local content (sports, news, etc.) being the primary drivers.” The rep noted that it’s “likely” that those re-subscribing to traditional TV services are using them alongside some streaming subscriptions. “It’s possible that users are churning off some [streaming] services where there is overlap with traditional TV services,” TiVo’s spokesperson said.

The Almighty Buck

Filipinos Are Addicted to Online Gambling. So Is Their Government (msn.com) 27

The Philippines became Asia's second-largest gambling hub after Macau last year as online betting proliferated across the archipelagic nation. Almost half of the country's 69 million working-age population is now registered on gambling apps, an exponential rise from less than half a million users in 2018. The government has become increasingly dependent on the industry.

Philippine Amusement and Gaming Corp. collects 30% of gross gaming revenue and has become the second-biggest revenue contributor among state-run companies after Land Bank of the Philippines. Revenue from online casino license fees is projected to reach $1 billion in 2025. More than 60 operators are regulated by the government.

Industry revenue almost tripled in 2024 from 2023 to 154.5 billion pesos. Revenue from internet betting eclipsed physical casinos for the first time this year. The central bank recently ordered e-wallets to remove links to betting sites, halving bets within days. President Ferdinand Marcos Jr. rejected calls for a complete ban and said outlawing online betting would only spawn illicit operations that would be more difficult to eradicate.

Submission + - A Bullet Crashed the Internet in Texas (404media.co) 2

alternative_right writes: The outage hit cities all across the state, including Dallas, Irving, Plano, Arlington, Austin, and San Antonio. The outage affected Spectrum customers and took down their phone lines and TV services as well as the internet.

“The outage stemmed from a fiber optic cable that was damaged by a stray bullet,” Spectrum told 404 Media. “Our teams worked quickly to make the necessary repairs and get customers back online. We apologize for the inconvenience.”

Spectrum told 404 Media that it didn’t have any further details to share about the incident so we have no idea how the company learned a bullet hit its equipment, where the bullet was found, and if the police are involved.

Submission + - Afghanistan's cellphone, internet services down after Taliban ordered cut

RoccamOccam writes: The Taliban have ordered internet and mobile phone data services to be cut across Afghanistan, diplomatic and industry sources said on Tuesday, as residents and monitoring services reported no connectivity and disruption to flights and financial services.

The Taliban administration offered no immediate explanation for the outage and could not be reached for comment.

The UN called on authorities to fully restore connections.
The Internet

Curiosity Drives Viewers To Ignore Trigger Warnings (phys.org) 155

alternative_right shares a report from Phys.org: For the first time, a new study has tested the effectiveness of trigger warnings in real life scenarios, revealing that the vast majority of young adults choose to ignore them. A new Flinders University study has found that nearly 90% of young people who saw a trigger warning still chose to view the content, saying that they did so out of curiosity, rather than because they felt emotionally prepared or protected. The findings published in the Journal of Behavior Therapy and Experimental Psychiatry aligned with a growing body of lab-based research suggesting that trigger warnings rarely lead to the avoidance of potentially distressing material.
Privacy

Reddit Mods Sued By YouTuber Ethan Klein Fight Efforts To Unmask Them (404media.co) 104

alternative_right shares a report from 404 Media: Critics of YouTuber Ethan Klein are pushing back on subpoenas that would reveal their identities as part of an ongoing legal fight between Klein and his detractors. Klein is a popular content creator whose YouTube channel has more than 2 million subscribers. He's also involved in a labyrinthine personal and legal beef with three other content creators and the moderators of a subreddit that criticizes his work. Klein filed a legal motion to compel Discord and Reddit to reveal the identities of those moderators, a move their lawyers say would put them in harm's way and stifle free speech on the internet forever.

[...] On July 31, a judge allowed Klein's lawyers to file a subpoena with Reddit and Discord that would reveal the identities of the people running r/h3snark and an associated Discord server. On September 22, lawyers for the defendants filed a motion to quash the subpoenas. "On its face, the Action is about copyright infringement," the latest filing said. "At its heart, however, the Action is about stifling criticism and seeking retribution by unmasking individuals for perceived reputational harms TEI [Klein's production company] attributes to [John Doe moderators] unrelated to TEI's intellectual property rights." [...]

The anonymity of places like Reddit and Discord grant a layer of protection to people seeking to critique power. This case could set a dangerous precedent, the lawyers believe. "If the court allows TEI's Subpoenas, it would enable TEI to impose a considerable price on Does' use of the vehicle of anonymous speech -- including public exposure, real risks of retaliation and actual harm, and the financial and other burdens of defending the Action," the filing said. The filing added: "Very few would-be commentators are prepared to bear costs of this magnitude. So, when word gets out that the price tag of criticizing Ethan is this high -- that speech will disappear. But that is precisely what Ethan Klein wants."

Submission + - Reddit Mods Sued by YouTuber Ethan Klein Fight Efforts to Unmask Them (404media.co)

alternative_right writes: Critics of YouTuber Ethan Klein are pushing back on subpoenas that would reveal their identities as part of an ongoing legal fight between Klein and his detractors. Klein is a popular content creator whose YouTube channel has more than 2 million subscribers. He’s also involved in a labyrinthine personal and legal beef with three other content creators and the moderators of a subreddit that criticises his work. Klein filed a legal motion to compel Discord and Reddit

to reveal the identities of those moderators, a move their lawyers say would put them in harm’s way and stifle free speech on the internet forever.

Klein is most famous for his H3 Podcast and collaborations with Hasan Piker and Trisha Paytas which he produced through his company Ted Entertainment Inc. Following a public falling out with Piker, Klein released a longform video essay critiquing his former podcast partner. As often happens with long video essays about YouTube drama, other content creators filmed themselves watching Klein’s essay.

The Internet

Afghanistan Hit By Nationwide Internet Blackout As Taliban Cuts Fiber Optic Cables (bbc.com) 76

The Taliban have imposed a nationwide telecommunications shutdown in Afghanistan, severing fibre-optic connections and cutting off internet, mobile, and satellite services as part of "morality" measures. Netblock is currently tracking the outages. The BBC reports: Since seizing power in 2021, the Taliban have imposed numerous restrictions in accordance with their interpretation of Islamic Sharia law. Flights from Kabul airport have also been disrupted, according to reports. Several people in Kabul have told the BBC that their fibre-optic internet stopped working towards the end of the working day, around17:00 local time (12:30 GMT). Because of this, it is understood many people will not notice the impact until Tuesday morning, when banking services and other businesses are due to resume. [...]

The Taliban earlier said an alternative route for internet access would be created, without giving any details. Business leaders at the time warned that if the internet ban continued their activities would be seriously hit. Hamid Haidari, former editor-in-chief of Afghan news channel 1TV, said after the shutdown that "loneliness enveloped the entire country." "Afghanistan has now officially taken first place in the competition with North Korea for [internet] disconnection" he said on X.

Science

Wall Street Journal Decries 'The Rise of Conspiracy Physics' (msn.com) 213

"The internet is full of people claiming to uncover conspiracies in politics and business..." reports the Wall Street Journal.

"Now an unlikely new villain has been added to the list: theoretical physicists," they write, saygin resentment of scientific authority figures "is the major attraction of what might be called 'conspiracy physics'." In recent years, a group of YouTubers and podcasters have attracted millions of viewers by proclaiming that physics is in crisis. The field, they argue, has discovered little of importance in the last 50 years, because it is dominated by groupthink and silences anyone who dares to dissent from mainstream ideas, like string theory... Most fringe theories are too arcane for listeners to understand, but anyone can grasp the idea that academic physics is just one more corrupt and self-serving establishment... In this corner of the internet, the scientist Scott Aaronson has written, "Anyone perceived as the 'mainstream establishment' faces a near-insurmountable burden of proof, while anyone perceived as 'renegade' wins by default if they identify any hole whatsoever in mainstream understanding...

As with other kinds of authorities, there are reasonable criticisms to be made of academic physics. By some metrics, scientific productivity has slowed since the 1970s. String theory has not fulfilled physicists' early dreams that it would become the ultimate explanation of all forces and matter in our universe. The Large Hadron Collider, the world's largest particle accelerator, has delivered fewer breakthroughs than scientists expected when it turned on in 2010. But even reasonable points become hard to recognize when expressed in the ways YouTube incentivizes. Conspiracy physics videos with titles like "They Just Keep Lying" are full of sour sarcasm, outraged facial expressions and spooky music...

Leonard Susskind, director of the Stanford Institute for Theoretical Physics, says physicists need to be both more sober and more forceful when addressing the public. The limits of string theory should be acknowledged, he says, but the idea that progress has slowed isn't right. In the last few decades, he and other physicists have figured out how to make progress on the vast project of integrating general relativity and quantum mechanics, the century-old pillars of physics, into a single explanation of the universe.

The bitter attacks on leading physicists get a succinct summary in the article from Chris Williamson, a "Love Island" contestant turned podcast host. "This is like 'The Kardashians' for physicists — I love it."
The Internet

Tim Berners-Lee Urges New Open-Source Interoperable Data Standard, Protections from AI (theguardian.com) 29

Tim Berners-Lee writes in a new article in the Guardian that "Somewhere between my original vision for web 1.0 and the rise of social media as part of web 2.0, we took the wrong path Today, I look at my invention and I am forced to ask: is the web still free today? No, not all of it. We see a handful of large platforms harvesting users' private data to share with commercial brokers or even repressive governments. We see ubiquitous algorithms that are addictive by design and damaging to our teenagers' mental health. Trading personal data for use certainly does not fit with my vision for a free web. On many platforms, we are no longer the customers, but instead have become the product. Our data, even if anonymised, is sold on to actors we never intended it to reach, who can then target us with content and advertising...

We have the technical capability to give that power back to the individual. Solid is an open-source interoperable standard that I and my team developed at MIT more than a decade ago. Apps running on Solid don't implicitly own your data — they have to request it from you and you choose whether to agree, or not. Rather than being in countless separate places on the internet in the hands of whomever it had been resold to, your data is in one place, controlled by you. Sharing your information in a smart way can also liberate it. Why is your smartwatch writing your biological data to one silo in one format? Why is your credit card writing your financial data to a second silo in a different format? Why are your YouTube comments, Reddit posts, Facebook updates and tweets all stored in different places? Why is the default expectation that you aren't supposed to be able to look at any of this stuff? You generate all this data — your actions, your choices, your body, your preferences, your decisions. You should own it. You should be empowered by it...

We're now at a new crossroads, one where we must decide if AI will be used for the betterment or to the detriment of society. How can we learn from the mistakes of the past? First of all, we must ensure policymakers do not end up playing the same decade-long game of catchup they have done over social media. The time to decide the governance model for AI was yesterday, so we must act with urgency. In 2017, I wrote a thought experiment about an AI that works for you. I called it Charlie. Charlie works for you like your doctor or your lawyer, bound by law, regulation and codes of conduct. Why can't the same frameworks be adopted for AI? We have learned from social media that power rests with the monopolies who control and harvest personal data. We can't let the same thing happen with AI.

Berners-Lee also says "we need a Cern-like not-for-profit body driving forward international AI research," arguing that if we muster the political willpower, "we have the chance to restore the web as a tool for collaboration, creativity and compassion across cultural borders.

"We can re-empower individuals, and take the web back. It's not too late."

Berners-Lee has also written a new book titled This is For Everyone.

Slashdot Top Deals