Privacy

Thousands of Exposed GitHub Repositories, Now Private, Can Still Be Accessed Through Copilot (techcrunch.com) 19

An anonymous reader quotes a report from TechCrunch: Security researchers are warning that data exposed to the internet, even for a moment, can linger in online generative AI chatbots like Microsoft Copilot long after the data is made private. Thousands of once-public GitHub repositories from some of the world's biggest companies are affected, including Microsoft's, according to new findings from Lasso, an Israeli cybersecurity company focused on emerging generative AI threats.

Lasso co-founder Ophir Dror told TechCrunch that the company found content from its own GitHub repository appearing in Copilot because it had been indexed and cached by Microsoft's Bing search engine. Dror said the repository, which had been mistakenly made public for a brief period, had since been set to private, and accessing it on GitHub returned a "page not found" error. "On Copilot, surprisingly enough, we found one of our own private repositories," said Dror. "If I was to browse the web, I wouldn't see this data. But anyone in the world could ask Copilot the right question and get this data."

After it realized that any data on GitHub, even briefly, could be potentially exposed by tools like Copilot, Lasso investigated further. Lasso extracted a list of repositories that were public at any point in 2024 and identified the repositories that had since been deleted or set to private. Using Bing's caching mechanism, the company found more than 20,000 since-private GitHub repositories still had data accessible through Copilot, affecting more than 16,000 organizations. Lasso told TechCrunch ahead of publishing its research that affected organizations include Amazon Web Services, Google, IBM, PayPal, Tencent, and Microsoft. [...] For some affected companies, Copilot could be prompted to return confidential GitHub archives that contain intellectual property, sensitive corporate data, access keys, and tokens, the company said.

Submission + - Thousands of Exposed GitHub Repositories Can Still Be Accessed Through Copilot (techcrunch.com)

An anonymous reader writes: Security researchers are warning that data exposed to the internet, even for a moment, can linger in online generative AI chatbots like Microsoft Copilot long after the data is made private. Thousands of once-public GitHub repositories from some of the world’s biggest companies are affected, including Microsoft’s, according to new findings from Lasso, an Israeli cybersecurity company focused on emerging generative AI threats.

Lasso co-founder Ophir Dror told TechCrunch that the company found content from its own GitHub repository appearing in Copilot because it had been indexed and cached by Microsoft’s Bing search engine. Dror said the repository, which had been mistakenly made public for a brief period, had since been set to private, and accessing it on GitHub returned a “page not found” error. “On Copilot, surprisingly enough, we found one of our own private repositories,” said Dror. “If I was to browse the web, I wouldn’t see this data. But anyone in the world could ask Copilot the right question and get this data.”

After it realized that any data on GitHub, even briefly, could be potentially exposed by tools like Copilot, Lasso investigated further. Lasso extracted a list of repositories that were public at any point in 2024 and identified the repositories that had since been deleted or set to private. Using Bing’s caching mechanism, the company found more than 20,000 since-private GitHub repositories still had data accessible through Copilot, affecting more than 16,000 organizations. Lasso told TechCrunch ahead of publishing its research that affected organizations include Amazon Web Services, Google, IBM, PayPal, Tencent, and Microsoft. [...] For some affected companies, Copilot could be prompted to return confidential GitHub archives that contain intellectual property, sensitive corporate data, access keys, and tokens, the company said.

Privacy

Google Is Making It Easier To Remove Personal Info On Search (engadget.com) 6

Google has updated its Results About You tool with a redesigned hub, easier removal requests directly from Search, and the ability to refresh outdated results. Engadget reports: Today, the tech giant is announcing the latest changes, including a redesigned hub and the ability to update outdated search results to reflect the latest changes.

The redesign isn't only for show. You can now submit removal requests directly from Search with fewer actions by clicking or tapping the three dots beside a search result. If you manage to have content about you deleted or changed from a website but Google Search hasn't caught up, you can refresh the search, which will "recrawl the page and obtain the latest information." In other words, you can always see the most up-to-date results about you.

Encryption

ExpressVPN Gets Faster and More Secure, Thanks To Rust (zdnet.com) 55

ZDNet's Steven Vaughan-Nichols shares some of the latest improvements to ExpressVPN following its codebase transition from C to Rust. An anonymous reader quotes an excerpt from the report: ExpressVPN is one of ZDNET's favorite Virtual Private Networks (VPNs). The popular VPN's transformation of its Lightway codebase from C to Rust promises to make the service faster and more secure. For now, the updated Lightway 2.0 is only available via ExpressVPN's Aircove router with the February 4 AircoveOS v5 update. The Aircove, which we rate as the best VPN router, costs $189. With this device, you can protect your tech from unwanted snoopers without installing a VPN on each gadget. So, how much faster is the updated ExpressVPN? In my tests, I connected to the internet via my updated router over my 2 Gigabit per second (Gbps) AT&T Internet using a 2.5 Gbps Ethernet-connected Linux Mint desktop with a Wi-Fi 6 connection over my Samsung Galaxy 25 Plus smartphone.

Without the VPN engaged, I saw 1.6 Gbps speeds, which is about par. With the VPN switched on and using Lightway 2.0, I saw speeds in the 290 to 330 Megabit per second (Mbps) range to Toronto and London, England. Farther afield, I saw speeds around 250 to 280Mbps to Hong Kong and Seoul. That's about 20% faster than I had seen with earlier Lightway versions. I was impressed. This version of the VPN should also be more secure. As Pete Membrey, ExpressVPN's chief research officer, said in a statement: "At ExpressVPN, we innovate to solve the challenges of tomorrow. Upgrading Lightway from its previous C code to Rust was a strategic and straightforward decision to enhance performance and security while ensuring longevity."

The updated Lightway VPN protocol also uses ML-KEM, the newly finalized NIST standard for post-quantum encryption. This feature, wrote Membray in a blog post, "ensures your connection is secured by encryption designed not just for today's threats but for the quantum-powered challenges of the future." To ensure the integrity of the recoded Lightway protocol, ExpressVPN commissioned two independent security audits from cybersecurity firms Cure53 and Praetorian. Both audits yielded positive results, with only minor vulnerabilities identified and promptly addressed by ExpressVPN. In short, ExpressVPN is technically about as safe a VPN as they come.

Submission + - ExpressVPN Gets Faster and More Secure, Thanks To Rust (zdnet.com)

An anonymous reader writes: ExpressVPN is one of ZDNET's favorite Virtual Private Networks (VPNs). The popular VPN's transformation of its Lightway codebase from C to Rust promises to make the service faster and more secure. For now, the updated Lightway 2.0 is only available via ExpressVPN's Aircove router with the February 4 AircoveOS v5 update. The Aircove, which we rate as the best VPN router, costs $189. With this device, you can protect your tech from unwanted snoopers without installing a VPN on each gadget. So, how much faster is the updated ExpressVPN? In my tests, I connected to the internet via my updated router over my 2 Gigabit per second (Gbps) AT&T Internet using a 2.5 Gbps Ethernet-connected Linux Mint desktop with a Wi-Fi 6 connection over my Samsung Galaxy 25 Plus smartphone.

Without the VPN engaged, I saw 1.6 Gbps speeds, which is about par. With the VPN switched on and using Lightway 2.0, I saw speeds in the 290 to 330 Megabit per second (Mbps) range to Toronto and London, England. Farther afield, I saw speeds around 250 to 280Mbps to Hong Kong and Seoul. That's about 20% faster than I had seen with earlier Lightway versions. I was impressed. This version of the VPN should also be more secure. As Pete Membrey, ExpressVPN's chief research officer, said in a statement: "At ExpressVPN, we innovate to solve the challenges of tomorrow. Upgrading Lightway from its previous C code to Rust was a strategic and straightforward decision to enhance performance and security while ensuring longevity."

The updated Lightway VPN protocol also uses ML-KEM, the newly finalized NIST standard for post-quantum encryption. This feature, wrote Membray in a blog post, "ensures your connection is secured by encryption designed not just for today's threats but for the quantum-powered challenges of the future." To ensure the integrity of the recoded Lightway protocol, ExpressVPN commissioned two independent security audits from cybersecurity firms Cure53 and Praetorian. Both audits yielded positive results, with only minor vulnerabilities identified and promptly addressed by ExpressVPN. In short, ExpressVPN is technically about as safe a VPN as they come.

The Internet

ISPs Brace For State-Level Price Regulation as New York's $15 Broadband Law Sets Precedent 117

A New York law mandating low-cost broadband is inspiring similar legislation across multiple states, despite industry opposition. The law requires ISPs with over 20,000 customers to offer $15 plans with 25Mbps speeds or $20 plans with 200Mbps to income-eligible residents.

Vermont, Massachusetts, and California legislators have introduced comparable bills following New York's success. Vermont's proposal mirrors New York's pricing structure, while Massachusetts goes further by requiring 100Mbps speeds for the $15 tier. AT&T responded by withdrawing its 5G home internet service from New York rather than complying with the mandate.

Industry lobby groups continue fighting these regulations, with USTelecom warning that state-level price controls will "undermine connectivity progress" and "discourage investment."
United Kingdom

1,000 Artists Release 'Silent' Album To Protest UK Copyright Sell-Out To AI 142

An anonymous reader quotes a report from TechCrunch: The U.K. government is pushing forward with plans to attract more AI companies to the region through changes to copyright law that would allow developers to train AI models on artists' content on the internet -- without permission or payment -- unless creators proactively "opt out." Not everyone is marching to the same beat, though. On Monday, a group of 1,000 musicians released a "silent album," protesting the planned changes. The album -- titled "Is This What We Want?" -- features tracks from Kate Bush, Imogen Heap, and contemporary classical composers Max Richter and Thomas Hewitt Jones, among others. It also features co-writing credits from hundreds more, including big names like Annie Lennox, Damon Albarn, Billy Ocean, The Clash, Mystery Jets, Yusuf / Cat Stevens, Riz Ahmed, Tori Amos, and Hans Zimmer.

But this is not Band Aid part 2. And it's not a collection of music. Instead, the artists have put together recordings of empty studios and performance spaces -- a symbolic representation of what they believe will be the impact of the planned copyright law changes. "You can hear my cats moving around," is how Hewitt Jones described his contribution to the album. "I have two cats in my studio who bother me all day when I'm working." To put an even more blunt point on it, the titles of the 12 tracks that make up the album spell out a message: "The British government must not legalize music theft to benefit AI companies." [...] The solution, say the artists, is to produce work in other markets where there might be better protections for it. Hewitt Jones -- who threw a working keyboard into a harbor in Kent at an in-person protest not long ago (he fished it out, broken, afterwards) -- said he's considering markets like Switzerland for distributing his music in the future.
Encryption

VPN Providers Consider Exiting France Over 'Dangerous' Blocking Demands (torrentfreak.com) 44

An anonymous reader quotes a report from TorrentFreak: In France, rightsholders have taken legal action to compel large VPN providers to support their pirate site blocking program. The aim is to reinforce existing blocking measures, but VPN providers see this as a dangerous move, leading to potential security issues and overblocking. As a result, some are considering leaving France altogether if push comes to shove. [...] Earlier this month, sports rightsholders Canal+ and LFP requested blocking injunctions that would require popular VPNs to start blocking pirate sites and services. The full requests are not public, but the details available show that Cyberghost, ExpressVPN, NordVPN, ProtonVPN, and Surfshark are listed as respondents. [...]

The blocking request has yet to be approved and several of the targeted VPN providers have reserved detailed commentary, for now. That said, the VPN Trust Initiative (VTI), which includes ExpressVPN, NordVPN and Surfshark as members, has been vocal in its opposition. VTI is part of the i2Coalition and while it doesn't speak directly for any of the members, the coalition's Executive Director Christian Dawson has been in regular discussions with VPN providers. From this, it became clear that VPN providers face difficult decisions. If VPN providers are ordered to block pirate sites, some are considering whether to follow in the footsteps of Cisco, which discontinued its OpenDNS service in the country, to avoid meddling with its DNS resolver.

Speaking with TorrentFreak, VTI's Dawson says that VPNs have previously left markets like India and Pakistan in response to restrictive requirements. This typically happens when privacy or security principles are at risk, or if the technical implementation of blocking measures is infeasible. VTI does not rule out that some members may choose to exit France for similar reasons, if required to comply with blocking measures. "We've seen this before in markets like India and Pakistan, where regulatory requirements forced some VPN services to withdraw rather than compromise on encryption standards or log-keeping policies," Dawson says. "France's potential move to force VPN providers to block content could put companies in a similar position -- where they either comply with measures that contradict their purpose or leave the market altogether."
"This case in France is part of a broader global trend of regulatory overreach, where governments attempt to control encrypted services under the guise of content regulation. We've already seen how China, Russia, Myanmar, and Iran have imposed VPN restrictions as part of broader censorship efforts."

"The best path forward is for policymakers to focus on targeted enforcement measures that don't undermine Internet security or create a precedent for global Internet fragmentation," concludes Dawson. "As seen in other cases, blanket blocking measures do not effectively combat piracy but instead create far-reaching consequences that disrupt the open Internet."
The Courts

Google's AI Previews Erode the Internet, Edtech Company Says In Lawsuit (reuters.com) 38

Chegg has filed a lawsuit against Google, accusing the tech giant of using AI-generated overviews to undermine publishers by reducing site traffic and eroding financial incentives for original content. Chegg claims this practice violates antitrust laws and threatens the integrity of the online information ecosystem. Reuters reports: This will eventually lead to a "hollowed-out information ecosystem of little use and unworthy of trust," the company said. The Santa Clara, California-based company has said Google's AI overviews have caused a drop in visitors and subscribers. Chegg was trading at around $1.63 on Monday, down more than 98% from its peak price in 2021.

The company announced it would lay off 21% of its staff in November. Nathan Schultz, CEO of Chegg, said on Monday that Google is profiting off the company's content for free. "Our lawsuit is about more than Chegg -- it's about the digital publishing industry, the future of internet search, and about students losing access to quality, step-by-step learning in favor of low-quality, unverified AI summaries," he said.

Publishers allow Google to crawl their websites to generate search results, which Google monetizes through advertising. In exchange, the publishers receive search traffic to their sites when users click on the results, Chegg said. But Google has started coercing publishers to let it use the information for AI overviews and other features that result in fewer site visitors, the company said. Chegg argued the conduct violates a law against conditioning the sale of one product on the customer selling or giving its supplier another product.

The Internet

Perplexity Teases AI Web Browser Called Comet 32

AI-powered search engine Perplexity is developing its own web browser named Comet. "Just like Perplexity reinvented search, we're also reinventing the browser," a Perplexity spokesperson told TechCrunch. "Stay tuned for updates." From the report: In a post on X on Monday, the company launched a sign-up list for the browser, which isn't yet available. It's unclear when it might be -- or what the browser will look like, even. But we do have a name: Comet. [...] Perplexity may be betting that it can leverage its search engine user base to quickly ramp up and make some sort of a dent in the space with Comet.
China

OpenAI Bans Chinese Accounts Using ChatGPT To Edit Code For Social Media Surveillance (engadget.com) 21

OpenAI has banned a group of Chinese accounts using ChatGPT to develop an AI-powered social media surveillance tool. Engadget reports: The campaign, which OpenAI calls Peer Review, saw the group prompt ChatGPT to generate sales pitches for a program those documents suggest was designed to monitor anti-Chinese sentiment on X, Facebook, YouTube, Instagram and other platforms. The operation appears to have been particularly interested in spotting calls for protests against human rights violations in China, with the intent of sharing those insights with the country's authorities.

"This network consisted of ChatGPT accounts that operated in a time pattern consistent with mainland Chinese business hours, prompted our models in Chinese, and used our tools with a volume and variety consistent with manual prompting, rather than automation," said OpenAI. "The operators used our models to proofread claims that their insights had been sent to Chinese embassies abroad, and to intelligence agents monitoring protests in countries including the United States, Germany and the United Kingdom."

According to Ben Nimmo, a principal investigator with OpenAI, this was the first time the company had uncovered an AI tool of this kind. "Threat actors sometimes give us a glimpse of what they are doing in other parts of the internet because of the way they use our AI models," Nimmo told The New York Times. Much of the code for the surveillance tool appears to have been based on an open-source version of one of Meta's Llama models. The group also appears to have used ChatGPT to generate an end-of-year performance review where it claims to have written phishing emails on behalf of clients in China.

Piracy

ISP Must Unmask 100 Alleged BitTorrent Pirates In RIAA Lawsuit (torrentfreak.com) 31

An anonymous reader quotes a report from TorrentFreak: Altice, parent company of Internet provider Optimum, must disclose the personal details of a hundred alleged music pirates. The request comes from a group of prominent record labels and is part of an ongoing copyright infringement liability lawsuit (PDF). Altice, meanwhile, will receive anti-piracy information, including that related to a letter the RIAA previously sent to BitTorrent Inc., the owner of popular torrent client uTorrent. [...] Details are scarce, but the group will likely consist of subscribers who were repeatedly warned over alleged piracy activity. The music labels could use this information to gather further evidence to support their allegations. For example, subscriber testimony could help to strengthen the argument that the ISP failed to take effective measures against repeat infringers.

There's nothing to suggest that these people will be approached with any claims directly. The names, emails, and addresses of the subscribers are marked as "highly confidential" and can only be viewed by attorneys acting for the music companies. The subscribers will be informed about the forthcoming disclosure of their personal details and any objections will be heard by the court. [...] Subscriber details are just a fraction of the information requested by the parties during discovery. Altice, for example, will also gain access to some non-privileged documents and communications between the music companies and their anti-piracy partners, including the RIAA, OpSec, and Audible Magic.

This includes information regarding a letter (PDF) the RIAA sent to the company behind the uTorrent and BitTorrent clients in 2015. [...] The nature of information sought by Altice isn't clear. The company previously said that if music labels are concerned about piracy, they are free to go after developers of 'piracy' software. While neutral torrent clients don't fall into that category, the ISP will be interested in any related legal considerations that took place behind the scenes.

IT

Dark Mode Might Be Burning More Juice Than You Think (theregister.com) 82

Using apps and websites in dark mode can actually use more energy than standard mode, according to researchers, as it causes people to crank up the brightness. From a report: This counterintuitive finding is claimed by BBC Research & Development (R&D), which says that despite the popular energy saving recommendation to cut electricity consumption by switching to dark mode, doing so might actually make things worse. "Dark mode is a popular dark-theme colour content scheme and research has found that, for some devices, switching to dark mode can reduce device power consumption. Energy conscious internet users are therefore encouraged to browse in dark mode," say the authors of a BBC R&D blog post.

"The catch is that the advertised energy savings haven't been tested in the wild, where user behavior can cause unexpected consequences." So the BBC's R&D engineers put participants in front of the BBC Sounds home page and asked them to adjust the device brightness until they were comfortable with it, repeating this for both light and dark mode versions of the page.

Robotics

China's Electric-Vehicle-To-Humanoid-Robot Pivot (technologyreview.com) 37

"[O]ur intrepid China reporter, Caiwei Chen, has identified a new trend unfolding within China's tech scene: Companies that were dominant in electric vehicles are betting big on translating that success into developing humanoid robots," writes MIT Technology Review's James O'Donnell. "I spoke with her about what she found out and what it might mean for Trump's policies and the rest of the globe..." An anonymous reader quotes an excerpt from the report: Your story looks at electric-vehicle makers in China that are starting to work on humanoid robots, but I want to ask about a crazy stat. In China, 53% of vehicles sold are either electric or hybrid, compared with 8% in the US. What explains that?

Price is a huge factor -- there are countless EV brands competing at different price points, making them both affordable and high-quality. Government incentives also play a big role. In Beijing, for example, trading in an old car for an EV gets you 10,000 RMB (about $1,500), and that subsidy was recently doubled. Plus, finding public charging and battery-swapping infrastructure is much less of a hassle than in the US.

You open your story noting that China's recent New Year Gala, watched by billions of people, featured a cast of humanoid robots, dancing and twirling handkerchiefs. We've covered how sometimes humanoid videos can be misleading. What did you think?

I would say I was relatively impressed -- the robots showed good agility and synchronization with the music, though their movements were simpler than human dancers'. The one trick that is supposed to impress the most is the part where they twirl the handkerchief with one finger, toss it into the air, and then catch it perfectly. This is the signature of the Yangko dance, and having performed it once as a child, I can attest to how difficult the trick is even for a human! There was some skepticism on the Chinese internet about how this was achieved and whether they used additional reinforcement like a magnet or a string to secure the handkerchief, and after watching the clip too many times, I tend to agree.

President Trump has already imposed tariffs on China and is planning even more. What could the implications be for China's humanoid sector?

Unitree's H1 and G1 models are already available for purchase and were showcased at CES this year. Large-scale US deployment isn't happening yet, but China's lower production costs make these robots highly competitive. Given that 65% of the humanoid supply chain is in China, I wouldn't be surprised if robotics becomes the next target in the US-China tech war.

In the US, humanoid robots are getting lots of investment, but there are plenty of skeptics who say they're too clunky, finicky, and expensive to serve much use in factory settings. Are attitudes different in China?

Skepticism exists in China too, but I think there's more confidence in deployment, especially in factories. With an aging population and a labor shortage on the horizon, there's also growing interest in medical and caregiving applications for humanoid robots.

DeepSeek revived the conversation about chips and the way the US seeks to control where the best chips end up. How do the chip wars affect humanoid-robot development in China?

Training humanoid robots currently doesn't demand as much computing power as training large language models, since there isn't enough physical movement data to feed into models at scale. But as robots improve, they'll need high-performance chips, and US sanctions will be a limiting factor. Chinese chipmakers are trying to catch up, but it's a challenge.

United States

Groups Ask US Court To Reconsider Ruling Blocking Net Neutrality Rules (reuters.com) 69

Public interest groups on Tuesday asked the full 6th U.S. Circuit Court of Appeals to reconsider a ruling that the Federal Communications Commission lacked legal authority to reinstate landmark net neutrality rules. From a report: The decision by a three-judge panel blocked the FCC under then President Joe Biden that had sought to reinstate the open internet rules implemented in 2015 but later repealed by the agency under President Donald Trump. The groups -- Free Press, Public Knowledge, Open Technology Institute and the Benton Institute for Broadband & Society -- argue the appeals court decision conflicts with an earlier decision by another court.

The groups said the case centers on the FCC's decades-long effort to prevent broadband internet providers "from abusing their gatekeeping power, in furtherance of the providers' economic or political interests, to constrain their users' access to third-party websites."

AI

DeepSeek Expands Business Scope in Potential Shift Towards Monetization (scmp.com) 6

Chinese AI startup DeepSeek has updated its business registry information with key changes to personnel and operational scope, signaling a shift towards monetizing its cost-efficient-yet-powerful large language models. From a report: The Hangzhou-based firm's updated business scope includes "internet information services," according to business registry service Tianyancha. The move is the first sign of DeepSeek's desire to monetise its popular technology, according to Zhang Yi, founder and chief analyst at consultancy iiMedia.

With eyes on developing a business model, DeepSeek intends to shift away from being purely focused on research and development, Zhang added. "The move reflects that for a company like DeepSeek, which managed to accumulate technology and develop a product, monetisation is becoming a necessary next step," Zhang said. DeepSeek's previous business scope said it engages in engineering and AI software development, among others, hinting at a more research-driven approach.

Privacy

Nearly 10 Years After Data and Goliath, Bruce Schneier Says: Privacy's Still Screwed (theregister.com) 57

Ten years after publishing his influential book on data privacy, security expert Bruce Schneier warns that surveillance has only intensified, with both government agencies and corporations collecting more personal information than ever before. "Nothing has changed since 2015," Schneier told The Register in an interview. "The NSA and their counterparts around the world are still engaging in bulk surveillance to the extent of their abilities."

The widespread adoption of cloud services, Internet-of-Things devices, and smartphones has made it nearly impossible for individuals to protect their privacy, said Schneier. Even Apple, which markets itself as privacy-focused, faces limitations when its Chinese business interests are at stake. While some regulation has emerged, including Europe's General Data Protection Regulation and various U.S. state laws, Schneier argues these measures fail to address the core issue of surveillance capitalism's entrenchment as a business model.

The rise of AI poses new challenges, potentially undermining recent privacy gains like end-to-end encryption. As AI assistants require cloud computing power to process personal data, users may have to surrender more information to tech companies. Despite the grim short-term outlook, Schneier remains cautiously optimistic about privacy's long-term future, predicting that current surveillance practices will eventually be viewed as unethical as sweatshops are today. However, he acknowledges this transformation could take 50 years or more.

Submission + - Thailand shuts power to Myanmar's scam hub (youtube.com) 1

Required Snark writes: From the South China Morning Post.

Thai authorities have cut off internet, power and fuel along the Thailand and Myanmar border in a bid to thwart the operation of scam centres there. The move on February 5, 2025, came amid growing pressure for Thailand to do more to help clamp down on the illegal compounds that have ensnared vast numbers of people from many jurisdictions. The Thai Provincial Electricity Authority disconnected power supplies at five points along the northern border, including Myawaddy in Myanmar’s Shan state.

The scam centers have massive power backup and may also be able to tap power from Laos. Hundreds of thousands of people have been trafficked to work at the centers.

Graphics

Why A Maintainer of the Linux Graphics Driver Nouveau Stepped Down (phoronix.com) 239

For over a decade Karol Herbst has been a developer on the open-source Nouveau driver, a reverse-engineered NVIDIA graphics driver for Linux. "He went on to become employed by Red Hat," notes Phoronix. "While he's known more these days for his work on the Mesa 3D Graphics Library and the Rusticl OpenCL driver for it, he's still remained a maintainer of the Nouveau kernel driver."

But Saturday Herbst stepped down as a nouveau kernel maintainer, in a mailing list message that begins "I was pondering with myself for a while if I should just make it official that I'm not really involved in the kernel community anymore, neither as a reviewer, nor as a maintainer." (Another message begins "I often thought about at least contributing some patches again once I find the time, but...")

Their resignation message hints at some long-running unhappiness. "I got burned out enough by myself caring about the bits I maintained, but eventually I had to realize my limits. The obligation I felt was eating me from inside. It stopped being fun at some point and I reached a point where I simply couldn't continue the work I was so motivated doing as I've did in the early days." And they point to one specific discussion on the kernel mailing list February 8th as "The moment I made up my mind."

It happened in a thread about whether Rust would create difficulty for maintainers. (Someone had posted that "The all powerful sub-system maintainer model works well if the big technology companies can employ omniscient individuals in these roles, but those types are a bit hard to come by.") In response, someone else had posted "I'll let you in a secret. The maintainers are not 'all-powerful'. We are the 'thin blue line' that is trying to keep the code to be maintainable and high quality. Like most leaders of volunteer organization, whether it is the Internet Engineerint Task Force (the standards body for the Internet), we actually have very little power. We can not *command* people to work on retiring technical debt, or to improve testing infrastructure, or work on some particular feature that we'd very like for our users. All we can do is stop things from being accepted..."

Saturday Herbst wrote: The moment I made up my mind about this was reading the following words written by a maintainer within the kernel community:

"we are the thin blue line"

This isn't okay. This isn't creating an inclusive environment. This isn't okay with the current political situation especially in the US. A maintainer speaking those words can't be kept. No matter how important or critical or relevant they are. They need to be removed until they learn. Learn what those words mean for a lot of marginalized people. Learn about what horrors it evokes in their minds.

I can't in good faith remain to be part of a project and its community where those words are tolerated. Those words are not technical, they are a political statement. Even if unintentionally, such words carry power, they carry meanings one needs to be aware of. They do cause an immense amount of harm.

The phrase thin blue line "typically refers to the concept of the police as the line between law-and-order and chaos," according to Wikipedia, but more recently became associated with a"countermovement" to the Black Lives Matter movement and "a number of far-right movements in the U.S."

Phoronix writes: Lyude Paul and Danilo Krummrich both of Red Hat remain Nouveau kernel maintainers. Red Hat developers are also working on developing NOVA as the new Rust-based open-source NVIDIA kernel driver leveraging the GSP interface for Turing GPUs and newer.
Social Networks

Are Technologies of Connection Tearing Us Apart? (lareviewofbooks.org) 88

Nicholas Carr wrote The Shallows: What the Internet Is Doing to Our Brains. But his new book looks at how social media and digital communication technologies "are changing us individually and collectively," writes the Los Angeles Review of Books.

The book's title? Superbloom: How Technologies of Connection Tear Us Apart . But if these systems are indeed tearing us apart, the reasons are neither obvious nor simple. Carr suggests that this isn't really about the evil behavior of our tech overlords but about how we have "been telling ourselves lies about communication — and about ourselves.... Well before the net came along," says Carr, "[the] evidence was telling us that flooding the public square with more information from more sources was not going to open people's minds or engender more thoughtful discussions. It wasn't even going to make people better informed...."

At root, we're the problem. Our minds don't simply distill useful knowledge from a mass of raw data. They use shortcuts, rules of thumb, heuristic hacks — which is how we were able to think fast enough to survive on the savage savanna. We pay heed, for example, to what we experience most often. "Repetition is, in the human mind, a proxy for facticity," says Carr. "What's true is what comes out of the machine most often...." Reality can't compete with the internet's steady diet of novelty and shallow, ephemeral rewards. The ease of the user interface, congenial even to babies, creates no opportunity for what writer Antón Barba-Kay calls "disciplined acculturation."

Not only are these technologies designed to leverage our foibles, but we are also changed by them, as Carr points out: "We adapt to technology's contours as we adapt to the land's and the climate's." As a result, by designing technology, we redesign ourselves. "In engineering what we pay attention to, [social media] engineers [...] how we talk, how we see other people, how we experience the world," Carr writes. We become dislocated, abstracted: the self must itself be curated in memeable form. "Looking at screens made me think in screens," writes poet Annelyse Gelman. "Looking at pixels made me think in pixels...."

That's not to say that we can't have better laws and regulations, checks and balances. One suggestion is to restore friction into these systems. One might, for instance, make it harder to unreflectively spread lies by imposing small transactional costs, as has been proposed to ease the pathologies of automated market trading. An option Carr doesn't mention is to require companies to perform safety studies on their products, as we demand of pharmaceutical companies. Such measures have already been proposed for AI. But Carr doubts that increasing friction will make much difference. And placing more controls on social media platforms raises free speech concerns... We can't change or constrain the tech, says Carr, but we can change ourselves. We can choose to reject the hyperreal for the material. We can follow Samuel Johnson's refutation of immaterialism by "kicking the stone," reminding ourselves of what is real.

Slashdot Top Deals