Cellphones

Parents' Phone Addiction Affects Bond With Kids, New Study Finds (bloomberg.com) 52

An anonymous reader quotes a report from Bloomberg: Parents' attachment to screens and smartphones can have negative, long-lasting developmental and psychological effects on their children, according to new research. Caregivers who mismanage their devices can both exacerbate "insecure attachment" and make healthy relationships more anxious and avoidant for children, according to the findings, which were published last month in Frontiers in Psychology, a peer-reviewed journal. The study, which surveyed 600 minors in the US from 12 to 17 years old, found that kids reported feeling marginalized or neglected by parents glued to their screens. "A child with insecure attachment may lack confidence or display a lower sense of self; demonstrate difficulty with interpersonal relationships and intimacy; and possess an unwillingness to take risks necessary to achieve success," reports Bloomberg, citing one of the study's researchers.

This type of behavior has become normalized: 2024 Pew data found that nearly half of U.S. teens say their parents are at least sometimes distracted by phones during interactions. "When parents were asked about their own behavior, far fewer said this was an issue," the report adds. "Still, earlier Pew data from 2020 found most parents feel their phones can interfere with quality family time, with 68% reporting being 'at least sometimes' distracted by them.

Submission + - FCC to end Biden-era rule that forces ISPs to list all their fees (arstechnica.com)

An anonymous reader writes: The Federal Communications Commission will vote to eliminate a rule that requires Internet service providers to list all of their so-called “passthrough” fees on an easily accessible broadband price label. The FCC vote could also make the price labels themselves a bit harder for consumers to find.

ISPs routinely advertise prices much lower than those actually charged to consumers on their monthly bills. One method of raising monthly bill prices above advertised rates is to tack on fees that, ISPs claim, are used to offset charges imposed by local governments.

ISPs would be well within their rights to advertise accurate monthly prices and charge those exact prices on monthly bills. But because ISPs rarely do that, the FCC has required them to make specific price disclosures to consumers for the past decade.

The Biden-era FCC updated the broadband-label rules to require that ISPs “itemize on the label all discretionary monthly fees that the provider passes through to the consumer.” The change drew protest from Comcast and other ISPs that complained bitterly about the complexity of listing all the hidden fees they had chosen to charge.

Under Chairman Brendan Carr, the Trump FCC has steadily whittled away at requirements imposed under Democrats. An order released in draft form last week would eliminate the requirement to itemize passthrough fees and let ISPs list them in a single “up to” amount. The “up to” amount can include both government fees and fees charged by non-government entities such as owners of utility poles.

“Rather than continuing to require providers to itemize ‘passthrough fees’ that can vary by location, we allow providers to display such fees in the aggregate, either as a maximum or ‘up to’ amount for the total fees applicable in any location where the service plan is offered, or as the exact total of such fees assessed in a particular location,” the FCC draft order said.

The Federal Communications Commission will vote to eliminate a rule that requires Internet service providers to list all of their so-called “passthrough” fees on an easily accessible broadband price label. The FCC vote could also make the price labels themselves a bit harder for consumers to find.

ISPs routinely advertise prices much lower than those actually charged to consumers on their monthly bills. One method of raising monthly bill prices above advertised rates is to tack on fees that, ISPs claim, are used to offset charges imposed by local governments.

ISPs would be well within their rights to advertise accurate monthly prices and charge those exact prices on monthly bills. But because ISPs rarely do that, the FCC has required them to make specific price disclosures to consumers for the past decade.

The Biden-era FCC updated the broadband-label rules to require that ISPs “itemize on the label all discretionary monthly fees that the provider passes through to the consumer.” The change drew protest from Comcast and other ISPs that complained bitterly about the complexity of listing all the hidden fees they had chosen to charge.

Under Chairman Brendan Carr, the Trump FCC has steadily whittled away at requirements imposed under Democrats. An order released in draft form last week would eliminate the requirement to itemize passthrough fees and let ISPs list them in a single “up to” amount. The “up to” amount can include both government fees and fees charged by non-government entities such as owners of utility poles.

“Rather than continuing to require providers to itemize ‘passthrough fees’ that can vary by location, we allow providers to display such fees in the aggregate, either as a maximum or ‘up to’ amount for the total fees applicable in any location where the service plan is offered, or as the exact total of such fees assessed in a particular location,” the FCC draft order said.

For purposes of this Report and Order, “passthrough fees” are monthly charges that 1) are imposed by a government entity or third-party infrastructure owner rather than set by the provider itself; 2) represent costs the provider chooses to pass through to consumers rather than rolling them into the base monthly price; and 3) vary by consumer location. For example, “passthrough fees” include state and local right-of-way fees, pole attachment fees imposed by third-party pole owners, and similar charges. “Passthrough fees” do not include taxes.

If ISPs wanted to make things simpler for consumers, they could treat these non-tax expenses as the cost of doing business and incorporate them into their advertised monthly prices. The prices consumers ultimately pay might not change if advertised prices were accurate, but it would be easier for regular people to figure out what they’ll pay when they sign up for service.

A planned change mentioned earlier in this article will likely result in fewer consumers seeing the price labels at all. Instead of displaying the full label at the point of sale and in each customer’s account portal, ISPs will be allowed to use hyperlinks to direct potential buyers and current customers to the labels displaying the full price information.

“While using hyperlinks to broadband labels instead of displaying the labels automatically may result in fewer consumers reading the label, interested consumers still have the opportunity to view the broadband label,” the FCC said.

It may become more difficult for third parties to collect price data because the FCC intends to eliminate the requirement that ISPs provide the price-label contents separately in machine-readable spreadsheet files on their websites. ISPs will still have to make the information accessible to people with disabilities by making the labels compatible with screen readers and other assistive technologies.

Public interest groups urged the FCC to scrap the planned changes during the comment period. The changes will make “the problem of junk fees, hidden charges, and difficult-to-understand billing worse, which could result in the widening of the digital divide. The Commission must not weaken oversight by allowing ISPs to operate without transparency, evade accountability, and entrench abusive practices,” a January 2026 filing said.

The filing was submitted by Public Knowledge, the National Digital Inclusion Alliance, the Open Technology Institute at New America, the National Consumer Law Center, the Benton Institute for Broadband & Society, and the Leadership Conference on Civil and Human Rights. The groups said that scrapping the fee-itemization rule “would strip consumers of critical pricing transparency and invite providers to mask charges they choose to pass along to consumers. Allowing providers to forgo itemization is similar to permitting hospitals to send bills to patients with no explanation of charges, medication, or facility fees.”

The groups urged the FCC to preserve machine-readable price information, saying it “clearly benefits consumers by aiding in the development of comparison shopping tools and aggregate market research.” The groups also said that “telephone-based disclosures remain essential to informed consumer decision-making” because they “serve as an important safeguard against scams and misleading offers that may reach consumers via mailers, e-mail, text messages, fake/scam websites, or robocalls.”

Another planned change will eliminate a requirement that providers archive all labels for at least two years after a service plan is no longer available. The Utility Reform Network, an advocacy group, told the FCC that the archived labels provide crucial data about how prices and services change over time, and that machine-readable labels are important for affordability research and information accessibility.

The Utility Reform Network also said that itemization of passthrough fees helps prevent bill shock. Displaying an “up to” price instead “would only serve to dilute the effectiveness of the label and increase consumer confusion around how the final price they pay is calculated,” the group said.

Cable and telecom lobby groups submitted comments supporting the FCC plan to eliminate or relax various requirements.

“The Commission correctly highlights the complexity and burdens providers have had to undertake to display all ‘charges that providers impose at their discretion, i.e., charges not mandated by a government’—including the passthrough of government-imposed fees,” USTelecom said. “To comply with this government-imposed fees requirement, providers must create and update hundreds of different labels to account for geographic variability and to ensure that their systems properly queue the label specific to the proper location when the customer inputs their address.”

USTelecom said that requiring machine-readable information is only helpful for “third-party researchers who are not the intended beneficiaries of the label” and “has no clear purpose or benefit except for third parties seeking to mine this information.”

Urging the FCC to stop requiring the listing of all fees, cable lobby group NCTA said it is burdensome “to create and maintain labels for each and every combination of government passthrough fees.” The NCTA complained that this rule and others “are unnecessary or unhelpful in informing consumers about the services that providers offer and impose an outsized compliance burden on providers.”

AI

Big Companies That Invest Heavily in AI Also Hire More People, Report Suggests (techcrunch.com) 29

"Companies spending heavily on AI are growing headcount faster, even in the entry-level roles that many fear are doomed," writes TechCrunch. That's the conclusion of new report tracking AI spending from Ramp's corporate card/bill pay data as well as Revelio Labs' workforce records from 21,599 U.S. firms: According to the report, "high-intensity adopters" — firms that spend on average $30 per employee per month on AI in the first three months — saw headcount increase 10.2%. Headcount also rose across functions, including engineering, sales, administration, customer service, finance, marketing, and scientist roles. The strongest job growth among high-intensity adopters was in the information sector, which includes software, internet, media, and tech-adjacent firms.

Despite these positive signals, the data isn't as rosy as it seems. It skews heavily toward tech-forward, knowledge-work firms — ones that might have VC-backing and are growing fast anyway, making it difficult to say whether AI is contributing to the hiring or just showing up at companies that are expanding anyway. "This paper does not show that AI universally creates jobs," the paper's authors admit, "but it does counter claims that AI will lead to broad job losses."

It also counters claims that AI is killing all junior jobs. Recent research from Goldman Sachs found that AI has already erased about 16,000 net jobs per month over the past year, with Gen Z and entry-level workers taking the brunt of the burden. But in tech-forward firms, the report finds that entry-level headcount actually rose by 12%... "For software and technology firms, AI can make core output cheaper or faster to produce: writing code, debugging, building internal tools, producing technical documentation, and supporting product development," the report reads. "Lower production costs in these workflows can raise the return to expanding the whole firm, not just the engineering team."

But companies that buy subscriptions and run pilots, yet did not go on to make sustained investments, don't tend to see any gains in headcount, per the report. That sets up the potential for a widening gap between firms that have the resources — like capital, technical staff, founder networks, and management bandwidth — to turn AI adoption into actual business gains and those that are stuck experimenting with subscriptions. In other words, this report suggests that firms that already have the resources are the ones that will see the largest gains.

CNBC argues another AI "narrative" was challenged this week: that open source can't make money. "The assumption was that giving your model away for free meant no business. That's breaking too, as open-model companies start posting real revenue and enterprises move from renting AI to running their own."
Crime

Windows 11 Identifier Code Used to Arrest 19-Year-Old Over Alleged Ransomware Spree (tomshardware.com) 69

America's Justice Department and FBI teamed joined Finland's National Bureau of Investigation to arrest a teenager they say is part of one of the world's biggest cybercrime syndicates, reports Tom's Hardware. The "Scattered Spider" syndicate has extorted over $100 million in ransom payments, according to Department of Justice figures: 19-year-old Peter Stokes is a dual U.S.-Estonian citizen who was trying to board a flight to Japan from Helsinki, when law enforcement caught up with him. [T]he main criminal complaint against Stokes stems from a May 2025 attack on a luxury jewelry dealer based in the United States. The attackers apparently called the company's IT helpdesk using Google Voice, posing as employees. They were able to convince the help desk into resetting their credentials, which allowed them to infiltrate three accounts, two of which had admin privileges. From there, the group, allegedly including Stokes, stole important data and held the jeweler at ransom, demanding an $8 million payment in crypto. The company ultimately regained access to their infrastructure and avoided paying the ransom, but the operational disruption still caused a purported $2 million in losses. This served as the spark that led to Stokes' eventual arrest in Helsinki, as the prosecutors slowly followed the paper and digital trail laid by the attackers.

Microsoft played a key role in the process by providing GDID [Global Device Identifier] data to the FBI to help them apprehend the alleged criminal... [I]t's a unique identifier assigned to every Windows install that tracks device-specific telemetry. It's the reason why sometimes changing a major component in your PC can revoke your Windows license... [T]he court documents from the case reveal that Stokes used Windows, from which investigators were able to link his physical hardware to specific internet activity and locations... Stokes' web activity, videogame history, IP addresses, tool usage (including Ngrok), Azure status, and more were logged with timestamps, and were provided to the investigators by Microsoft...

Stokes was carrying two hard drives full of incriminating evidence with him when boarding his flight to Japan... His real identity has actually been known since 2024, but since he was a minor living across Estonia and the UAE at the time, he could only be monitored until the time was right.

The official criminal complaint even includes a selfie photo that Stokes posted on Snapchat (hiding his face behind dozens of hundred dollar bills). It then notes that behind Stokes the wallpaper, carpet, and furniture match New York's Empire Hotel — and that Stokes had visited the hotel's web site in Germany before then flying to New York...

"Following the arrest, Stokes was extradited to the U.S., where he appeared in front of a federal court in Chicago for the first time on June 30, 2026, and he remains in custody," adds Tom's Hardware.

"The accused is now awaiting trial, having been charged with conspiracy, cyber intrusion, and fraud..."
The Internet

GoDaddy Warns India's Crackdown on Fake Site Registrars Could Upend Internet Privacy Everywhere (reuters.com) 20

"The internet is filled with fakes," writes Gizmodo. "A court in India is setting out to address the problem by requiring more transparency from domain registrars to make it easier to crack down on fraud. And while the intentions might be good, Reuters is reporting that major American domain registrar GoDaddy is sounding the warning bells that the court's decision could fundamentally reshape the internet well beyond India's borders."

GoDaddy argues the move would even make the internet less safe, reports Reuters : [Online fraud] is a key challenge for Prime Minister Narendra Modi's government, which last year received 2.4 million complaints of alleged cyber fraud amounting to $2.4 billion. Starting in 2019, lawsuits were brought by dozens of Indian and global firms — Amazon against fake shopping sites trading on its name and McDonald's complaining against bogus sites offering franchises. [More than 20 companies filed a complaint, the article notes, including Microsoft.] In December, an Indian court blocked more than 1,100 such websites. The New Delhi judge however went further, ordering sweeping new measures that tech experts say have rewritten rules of internet governance: Domain sellers should not offer buyers free privacy protection by default, the buyer's details should be released to anyone with a "legitimate interest" within 72 hours, and website addresses that are variations of protected brand names must be prohibited.

U.S.-based GoDaddy has challenged the directives before a larger bench of judges at the Delhi High Court, according to a Reuters review of non-public filings. It says the ruling will affect legitimate businesses that have names similar to big brands. Stopping privacy-by-default features, GoDaddy said, will result in public disclosure of name, address, telephone and email of legitimate website owners, exposing them to "foreseeable privacy and security risks" such as stalking and harassment.

As domain names operate globally, not locally, the order could force GoDaddy to regulate website addresses across the world, it said. On the court's order imposing a 72-hour deadline on companies to provide registration details to anyone with "legitimate interest", GoDaddy argues it has no wherewithal to assess who has legitimate interest or not. The "commercially destabilising" directives may force domain name companies to "exit India", said one of GoDaddy's appeal documents that ran into 5,121 pages... GoDaddy rivals, Arizona-based Namecheap and Netherlands-based Hosting Concepts, have also challenged the New Delhi ruling, court records show, although Reuters could not ascertain details of their appeals...

GoDaddy argues that diluting the privacy feature will run contrary to India's data protection law and the European Union GDPR law which mandates a "privacy by default" approach. Farzaneh Badii, a New York-based researcher on internet governance, criticised the New Delhi ruling, noting that Europe redacted such details because publishing them had been abused by harassment and targeted phishing. "The people exposed will be journalists, activists, small business owners, and private individuals. The brand impersonators will not," she said...

While the sweeping December directives were issued by a court, they followed government's submissions, documents showed... The judges will hear the appeals on July 16.

GoDaddy manages 80 million domains and serves over 20 million users, the article points out, with annual revenue over $5 billion.
The Internet

Amazon Has Enough Satellites To Launch Its Starlink Competitor (theverge.com) 47

Amazon says its Leo satellite network now has enough spacecraft in orbit to begin limited commercial internet service, with 396 satellites providing "continuous service across initial latitudes." Early performance will likely be uneven, however, and well behind Starlink. "It'll be years before Amazon can boast similar performance numbers as it continues to launch a planned 3,232 Leo satellites," reports The Verge. From the report: SpaceX went live with its "Better than nothing beta" back in 2020 when it had almost 900 satellites operating in low-Earth orbit. It initially served a narrow band of users in the upper US and Canada, who complained about frequent service interruptions and high sensitivity to obstructions, with speeds between 50Mbps and 150Mbps, and latency from 20ms to 40ms. By 2022, the service and coverage areas had already dramatically improved. [...]

SpaceX currently has over 10,000 Starlink satellites in operation, providing robust internet connectivity on land, sea, and air in over 160 countries. Performance varies by the dish, service level paid for, time of day, and location of the user, but we're now talking 200Mbps median download speeds, 10Mbps to 40Mbps uploads, and latency hovering around 25ms.

Security

AI Agent Executes 'First' End-To-End Ransomware Attack 36

Sysdig says it has documented the first ransomware attack carried out end to end by an AI agent, which autonomously exploited exposed systems, stole credentials, established persistence, compromised a production database, and destroyed data. The research team named the attacker "JadePuffer" and said it gained initial access to an internet-facing Langflow instance by exploiting CVE-2025-3248. "The most striking characteristic, however, was the LLM's behavior," Sysdig director of threat research Michael Clark said in a blog post. An anonymous reader quotes an excerpt from The Register: JadePuffer's "self-narrating" payloads "contained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don't often write but LLM-generated code produces reflexively," Clark added. "The operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds." After exploiting CVE-2025-3248, a missing authentication vulnerability in Langflow that allows remote, unauthenticated attackers to execute arbitrary Python on the host, the AI agent began scanning for and collecting secrets, including LLM provider API keys, cloud credentials "with explicit coverage of Chinese providers" including Alibaba, Aliyun, Tencent, and Huawei, while also scanning for AWS, Azure and Google Cloud Platform, cryptocurrency wallets, and database credentials.

The AI also installed a crontab entry on the Langflow server to maintain persistence and call back to the attacker's infrastructure every 30 minutes. JadePuffer's intended target was a separate internet-exposed production server running a MySQL database and an Alibaba Nacos configuration service, we're told. Nacos is an open-source service-discovery and dynamic configuration platform developed by Alibaba and used in the cloud provider's microservices applications. The agent connected to the server's exposed MySQL port using root credentials, although Sysdig doesn't know how the attacker obtained them. These credentials weren't stolen from the victim's environment.

JadePuffer then attacked Nacos via multiple vectors including an authorization bypass flaw (CVE-2021-29441) and forging a valid JSON web token (JWT) using Nacos's default signing key. Additionally, using its root database access, the LLM injected a backdoor administrator into the Nacos backing database. It ultimately encrypted all 1,342 Nacos service configuration items using MySQL's built-in AES encryption function, and created an extortion demand, ransom note, Bitcoin payment address, and a Proton Mail contact [...]. However, according to the threat hunters, the victim can't recover the encrypted data, even if they paid the ransom demand, because the agent escalated "from row-level deletion to dropping entire database schemas, narrating its own targeting rationale," without backing up any of the encrypted data.

Submission + - AI Agent Executes 'First' End-To-End Ransomware Attack (theregister.com)

An anonymous reader writes: They're not bad; they're just prompted that way. Sysdig threat hunters documented what they say is the first-ever documented agentic ransomware infection with an LLM — not a human — driving the entire extortion operation, from gaining initial access to compromising a production database server and destroying data. The security shop’s research team named the agentic intruder JadePuffer and said it gained initial access to an internet-facing Langflow instance by exploiting CVE-2025-3248, and then ran a fully automated attack. “The most striking characteristic, however, was the LLM's behavior,” Sysdig director of threat research Michael Clark said in a blog about the agentic ransomware and extortion operation.

JadePuffer’s “self-narrating” payloads “contained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don’t often write but LLM-generated code produces reflexively,” Clark added. “The operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds.” After exploiting CVE-2025-3248, a missing authentication vulnerability in Langflow that allows remote, unauthenticated attackers to execute arbitrary Python on the host, the AI agent began scanning for and collecting secrets, including LLM provider API keys, cloud credentials “with explicit coverage of Chinese providers” including Alibaba, Aliyun, Tencent, and Huawei, while also scanning for AWS, Azure and Google Cloud Platform, cryptocurrency wallets, and database credentials.

The AI also installed a crontab entry on the Langflow server to maintain persistence and call back to the attacker’s infrastructure every 30 minutes. JadePuffer’s intended target was a separate internet-exposed production server running a MySQL database and an Alibaba Nacos configuration service, we’re told. Nacos is an open-source service-discovery and dynamic configuration platform developed by Alibaba and used in the cloud provider’s microservices applications. The agent connected to the server's exposed MySQL port using root credentials, although Sysdig doesn’t know how the attacker obtained them. These credentials weren’t stolen from the victim’s environment.

JadePuffer then attacked Nacos via multiple vectors including an authorization bypass flaw (CVE-2021-29441) and forging a valid JSON web token (JWT) using Nacos's default signing key. Additionally, using its root database access, the LLM injected a backdoor administrator into the Nacos backing database. It ultimately encrypted all 1,342 Nacos service configuration items using MySQL's built-in AES encryption function, and created an extortion demand, ransom note, Bitcoin payment address, and a Proton Mail contact [...]. However, according to the threat hunters, the victim can’t recover the encrypted data, even if they paid the ransom demand, because the agent escalated “from row-level deletion to dropping entire database schemas, narrating its own targeting rationale,” without backing up any of the encrypted data.

Submission + - Dopamine websites are the internet's bleakest new obsession (metro.co.uk)

fjo3 writes: Essentially, these are fake websites that allow people to chase the dopamine hit they get before making a purchase, be it ordering a takeaway or shopping.

However, the key difference between these and regular websites is that you’re not actually spending any money, and your order will never arrive. The whole experience is gamified from start to finish, allowing you to satisfy your cravings without indulging.

AI

Microsoft Slammed for Building Copyright-Infringing Supercomputer for OpenAI in New Court Filing (arstechnica.com) 88

The New York Times alleges Microsoft actively encouraged OpenAI to steal its copyrighted work, reports Ars Technica, citing a new (and heavily redacted) court filing Thursday: NYT's motion comes after the [U.S.] Supreme Court sided with Cox Communications in a case where Sony tried and failed to claim that Cox was contributing to music piracy as an Internet service provider, which set a new standard for contributory infringement. Moving forward, plaintiffs will have to prove that parties intentionally acted to induce illegal conduct. Recognizing that the legal precedent has changed, the NYT now wants to amend its complaint to align its contributory infringement claim against Microsoft with that new standard... A Microsoft spokesperson told Ars that the company views the amended complaint as "a last-ditch effort by the plaintiff to save its claim from unfavorable precedent set in other recent rulings..."

The updated complaint seeks to specify that [Microsoft's] supercomputer was tailor-made to help OpenAI infringe and allege that it was built for the explicit purpose of training AI on copyrighted works without permission. And as the NYT alleged, its articles were more heavily weighted by this system, as both firms hoped to train models on the highest-quality journalism possible, so that level of writing could be confidently mimicked in outputs. By building this "unusually complex" machine, Microsoft not only helped select the works that were infringed but also provided a means to seize copyrighted works without permission, the NYT alleged. "Microsoft specifically designed it for the purpose of using essentially the whole Internet — curated to disproportionately feature Times Works — to train the most capable LLM in history," the NYT alleged... Similarly as problematic for the NYT are hallucinations where Microsoft and OpenAI models falsely cite the NYT for content that they never published... "Users who ask a search engine what The Times has written on a subject should be provided with neither an unauthorized copy nor an inaccurate forgery of a Times article, but a link to the article itself," the NYT alleged...

In a statement provided to Ars, OpenAI spokesperson Drew Pusateri reiterated the AI firm's often-repeated claims that AI training on copyrighted works is indisputably fair use... OpenAI has argued that "ChatGPT is not a substitute for a Times subscription," the NYT reported, partly because "they transformed the material for a different use."

An OpenAI spokesperson told Ars Technica that OpenAI's models "empower innovation," while a New York Times spokesperson insisted that Microsoft "actively encouraged OpenAI to steal our copyrighted works... [O]ur core claims remain the same from the day we filed this lawsuit — that Microsoft and OpenAI stole millions of The Times's copyrighted works to compete with our products and illegally enrich themselves."

The article speculates that the case's most extreme outcome "could require OpenAI and Microsoft to wipe models and start over. The NYT has also asked for permanent injunctive relief to prevent future infringement, as well as extensive damages..."
The Almighty Buck

Are Checks Sent Through the Mail Vulnerable to Theft? (nytimes.com) 183

The New York Times tells the story of a 63-year-old retiree who wrote a check for several thousand dollaras to pay her taxes. But she discovered much later that her taxes were never paid because that check had been intercepted and then altered to be payable to someone else: In some cases, thieves may pilfer one or more checks from local mailboxes. Adam Rust, director of financial services for the Consumer Federation of America, said thieves sometimes "fish" for checks at free-standing drop boxes, using long tools with sticky pads on the ends to grab letters. In other cases, more sophisticated criminals may steal large batches of checks, copy them and then sell them on the internet. Often, the purloined checks are chemically altered in what's known as "check washing" to remove the name of the recipient. The thief replaces it with a fraudulent name, and often increases the amount of the check, before cashing or depositing it.
The 63-year-old retiree's bank told her she'd waited too long to recover the funds: Schwab's "security guarantee," outlined on its website , says that "Schwab will cover losses in any of your Schwab accounts due to unauthorized activity." But fine print at the bottom of the page notes that reimbursement "requires your timely reporting of unauthorized activity to Schwab," and that Schwab "will not be liable for additional or increased losses resulting from a failure to report unauthorized activity in a timely manner." It notes that more details are available in account agreements... Notify your bank as soon as possible, said Scott Anchin, senior vice president of strategic initiatives and policy at the independent bankers association. Banks generally allow at least 30 days and sometimes up to 90 days from the time your statement is made available to you to report suspected check fraud, he said.
So how can you avoid check fraud? Adam Rust, director of financial services for the Consumer Federation of America, just suggests that "No one should ever mail a check." If you must write a check, he said, try to deliver it in person or take it inside a post office to mail rather than relying on your own mailbox or public drop boxes. The American Bankers Association recommends using permanent "gel" ink pens when you do write checks to reduce the risk of tampering... And if you don't already, consider using your bank's online bill payment service.
The article notes that even the U.S. federal government "has been moving away from paper checks for things like benefit payments and income tax refunds, saying digital payment methods are more secure."
Science

Max Planck Slapped With Two Paper Retractions By Suspected Rogue Algorithm (science.org) 21

Max Planck won 1918's Nobel Prize for physics. Yet two of his papers were retracted — a move now being criticized by Yves Gingras, a historian of physics at the University of Quebec and Mahdi Khelfaoui, a fellow historian of science at UQ Trois-Rivières. Science reports: The papers, both quietly retracted in 2011, originally appeared in the early 1940s in Naturwissenschaften, a German journal now owned by publishing giant Springer Nature. After some sleuthing, Khelfaoui determined one of the Planck pieces, a philosophical essay from 1942 titled "Sinn und Grenzen der exakten Wissenschaft" ("Meaning and Limits of Exact Science"), about how to achieve certainty in scientific knowledge, had also appeared in two other journals and been reprinted twice in books. Repackaging the same work multiple times is considered "self-plagiarism" and frowned upon today — the practice produces copyright conflicts and inflates scholars' publication records. The Naturwissenschaften site gives "copyright violation" as the reason for the retraction.

Yet publishing identical material in multiple journals was widespread before the internet. "Science was more fragmented" then, Khelfaoui says. "You wanted different audiences ... to have access to your work." The practice was especially common for luminaries like Planck. Albert Einstein did the same (but escaped retractions). Springer Nature's "anachronistic" application of modern standards to a 1942 paper "distort[s] the historical record," Gingras and Khelfaoui argue in a preprint posted last month on arXiv. Any concerns about copyright violations are largely moot anyway: Because Planck died in 1947, his works are in the public domain in most countries.

Gingras was especially incensed that Springer Nature deviated from the normal practice of merely slapping the word RETRACTED across the digital version of the paper while still allowing scholars to read the text. Instead, the publisher posted a blank white page with the cryptic phrase, "This article has been withdrawn due to article violation." Springer Nature is nevertheless still selling the empty PDF for $39.95. Suzanne Scarlata, a chemist and biochemist at the Worcester Polytechnic Institute and editor-in-chief of The Science of Nature, as Naturwissenschaften is now known, had not heard about the retractions before being contacted for this story... Scarlata suspects Springer Nature's internal policing software removed the paper and posted the retraction notice unilaterally, without human supervision: "I think it just happened with their algorithm," she says. "It's a mistake they should probably rectify."

A second Planck paper was apparently removed because its response to a 1940 paper had used an identical title.

Thanks to our long-time Slashdot reader He Who Has No Name for sharing the article.

Submission + - Should AI Ban Users Without Human Review? (medium.com)

VTAndrew writes: Artificial intelligence is rapidly becoming part of content moderation and account enforcement across major online platforms. While AI can help identify spam, scams, and harmful content at internet scale, what happens when the system gets it wrong?

A recently published Medium article examines this question through the experience of a Facebook account suspension that was reportedly initiated by an automated system, followed by an automated appeal denial and no meaningful path to human review.

The article argues that the issue isn't AI itself—it's allowing AI to become investigator, decision-maker, and appeals process without effective human oversight.

The broader concern is that platforms like Meta have evolved into critical pieces of modern infrastructure. They host community groups, school communications, local government announcements, business pages, political discussions, and years of personal history. Their ecosystems also span multiple interconnected services, meaning a single enforcement action can affect Facebook, Instagram, Messenger, Threads, and Meta hardware tied to the same account.

This concern extends beyond a single user's experience. A growing advocacy effort at People Over Platforms documents thousands of reports from users who say they were wrongfully locked out of their accounts and calls for stronger transparency, meaningful appeals, and human oversight.

The movement originated with a Change.org petition that has gathered more than 63,000 supporters before transitioning to an independent nonprofit focused on digital rights and platform accountability.

Media outlets in multiple countries have also reported on users who say they were wrongly disabled by Meta's automated enforcement systems, with some accounts later restored after additional review.

Rather than asking whether AI should be used for moderation, the article asks a different question:

If AI is empowered to make decisions that can revoke a person's digital identity, communications, communities, and purchased ecosystem, should there always be a meaningful human appeal available?

Medium article:

https://medium.com/@vtadorsett...

People Over Platforms:

https://www.peopleoverplatform...

Original Change.org petition:

https://www.change.org/p/hold-...

Hardware

A 25-Year-Old Blog Looks Back At 40 Years of Computing (markround.com) 79

Ancient Slashdot reader Mark Round writes: Longtime reader here (since mid-1999 -- Hot Grits! Oog the Caveman! Beowulf clusters!), and I can still remember posting back on Slashdot's own 5th anniversary. Time's rolled on: my own blog just turned 25, and it's now roughly 40 years since I first sat down at a computer. So I went digging through archive.org, old backups, and a box of ZIP disks, and wrote up a long look back at four decades of computing through the one website that's been my online home along the way.

It runs from my first 8-bit micro and a 1,200-baud modem through discovering the actual Internet at university (and burning far too many hours on Slashdot and sister sites like freshmeat.net), past gloriously pimped-out Enlightenment Linux desktops, all the way to the modern cloud-native world. Plenty of dodgy screenshots, terrible code, and fond memories of long-gone haunts like kuro5hin.org and Linux Coffee Talk along the way.

Security

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests (thehackernews.com) 19

A 29-year-old bug in the Squid web proxy, dubbed Squidbleed and tracked as CVE-2026-47729, can let an authorized proxy user retrieve fragments of another user's cleartext HTTP requests, including credentials and session tokens. The security researcher who reported the flaw credited Anthropic's Claude Mythos Preview for the discovery. The Hacker News reports: Squid describes this as an attack by a trusted client: someone already permitted to use the proxy, not any random host on the internet. That matches Squid's usual home, shared networks like schools, offices, and public Wi-Fi. In those setups, the attacker is just another user of the same proxy. The leak also only reaches traffic that Squid can read. Normal HTTPS rides an opaque CONNECT tunnel, so Squid never sees inside it; the exposed traffic is cleartext HTTP, plus TLS-terminating setups where Squid decrypts and inspects. The attacker also needs the proxy to reach an FTP server they control on port 21. Both FTP and that port are on by default.

[...] If you patch, verify the fix, not just the version. Confirm the guard is in FtpGateway.cc, or check your distribution's backport, since distros ship their own builds (Debian packages Squid 5.7). The public thread is still inconsistent: maintainer Amos Jeffries first said Squid 7.6 carried the fix, then corrected that to 7.7, and on June 22 Debian's Salvatore Bonaccorso noted the referenced commit looks like it is already in 7.6. The fix is small, a null-terminator check before the vulnerable strchr calls, merged to the development branch in April and v7 in May. Squid 7.6 does separately patch CVE-2026-50012, an unrelated cache_digest heap overflow.

The cleaner move is the one the researchers recommend anyway: turn FTP off. Chromium dropped FTP years ago, and most networks carry almost none of it, so disabling it removes this attack surface for free, whatever build you run. The risk is real but bounded. SUSE rates it moderate, CVSS 6.5, and the vector explains the score: the attacker needs proxy access (low privileges), and the only impact is confidentiality, nothing on integrity or availability.

Social Networks

UK Considers Forcing Social Media Firms To Prioritize Trusted News (reuters.com) 134

An anonymous reader quotes a report from Reuters: Britain is considering forcing social media companies to prioritize what the government called trusted news sources as part of its broader push to tighten regulation of the sector. The culture department said on Monday it was considering requiring platforms such as Meta's Facebook, Alphabet-owned YouTube and TikTok to make content from public service media -- including the BBC, ITV and Channel 4 -- and other trusted news providers easier to find in users' feeds and searches.

Boosting the visibility of regulated news providers could help tackle misinformation, particularly during crises, the government said. However, any move to influence how platforms rank content is likely to face scrutiny from the social media firms, which say such rules could override user choice and disadvantage other creators. The proposals form part of a broader overhaul of Britain's public service media system to help broadcasters compete with streaming platforms and shifting viewing habits. Ministers are also considering widening public service media status to include online-only providers, extending free-to-air protections for major sporting events to on-demand viewing, and consulting on a shift to internet-based TV from 2034 or 2044.
"It is vital that we make sure that people have better access to trusted and accurate news and that our regulated public service media is seen and heard in the fierce battle against mis- and disinformation," culture minister Lisa Nandy said in a statement.

The move follows the UK's recently-announced ban on social media use for those under 16.

Submission + - A 25-Year-Old Blog Looks Back at 40 Years of Computing (markround.com)

Mark Round writes: Longtime reader here (since mid-1999 — Hot Grits! Oog the Caveman! Beowulf clusters!), and I can still remember posting back on Slashdot's own 5th anniversary. Time's rolled on: my own blog just turned 25, and it's now roughly 40 years since I first sat down at a computer. So I went digging through archive.org, old backups and a box of ZIP disks, and wrote up a long look back at four decades of computing through the one website that's been my online home along the way.

It runs from my first 8-bit micro and a 1,200-baud modem, through discovering the actual Internet at university (and burning far too many hours on Slashdot and sister sites like freshmeat.net), past gloriously pimped-out Enlightenment Linux desktops, all the way to the modern cloud-native world. Plenty of dodgy screenshots, terrible code, and fond memories of long-gone haunts like kuro5hin.org and Linux Coffee Talk along the way.

Submission + - UK Considers Forcing Social Media Firms To Prioritize Trusted News (reuters.com)

An anonymous reader writes: Britain is considering forcing social media companies to prioritize what the government called trusted news sources as part of its broader push to tighten regulation of the sector. The culture department said on Monday it was considering requiring platforms such as Meta's Facebook, Alphabet-owned YouTube and TikTok to make content from public service media — including the BBC, ITV and Channel 4 — and other trusted news providers easier to find in users' feeds and searches.

Boosting the visibility of regulated news providers could help tackle misinformation, particularly during crises, the government said. However, any move to influence how platforms rank content is likely to face scrutiny from the social media firms, which say such rules could override user choice and disadvantage other creators. The proposals form part of a broader overhaul of Britain's public service media system to help broadcasters compete with streaming platforms and shifting viewing habits. Ministers are also considering widening public service media status to include online-only providers, extending free-to-air protections for major sporting events to on-demand viewing, and consulting on a shift to internet-based TV from 2034 or 2044.

Ubuntu

Canonical's Upcoming AI Tool: Talk to Ubuntu Instead of Typing (itsfoss.com) 58

This week the Ubuntu desktop's director of engineering announced they're bringing speech-to-text dictation to Ubuntu Desktop, aiming for an experience "that feels like a natural part of the desktop while respecting user privacy and running entirely on local hardware."

"Speech recognition has become a common feature on modern platforms, and we think it should be a first-class experience on Ubuntu Desktop as well."

More details from the blog It's FOSS: For Ubuntu 26.10, the initial version of Myna is expected to be a desktop dictation tool built around GNOME on Wayland with a push-to-talk mechanism gatekeeping when your microphone accepts input. Using it means holding a hotkey, speaking, and letting go. A small activity indicator shows while it is listening, and the transcribed text lands wherever the cursor was sitting when dictation started.

Recognition itself happens inside a sandboxed component called the Canonical Inference Snap, while a Speech Orchestrator manages the session and an Audio Adapter handles whatever the microphone picks up, denoising and chunking it before it ever reaches the model... Speech recognition will happen locally, and an internet connection is not needed once the appropriate model is installed... The audio data won't be sticking around either, being stored in a small in-memory buffer that gets discarded the moment the session ends. Features like dictation into password fields, wake words, continuous listening, voice assistants, voice commands, translation, speaker identification, and automatic language detection are all off the table...

You should also know that Canonical is looking for feedback before the specs for Myna are finalized, especially from people who already rely on dictation or assistive tools on Linux.

Security

How Millions of Digital Home Devices Are Secretly Powering Cyberattacks (yahoo.com) 33

The Wall Street Journal reports on internet-connected devices — and how every year millions of them "can contain a secret digital backdoor that opens up access to your home internet, so that anyone... can surf the web as if they were you." (And this is especially true for "knockoffs that you buy online"...)

In a video report this week they tested two digital picture frames from Amazon and three streaming devices from Walmart "because we heard that they often ship with backdoor software used in cyberattacks. Security experts believe manufacturers are being paid to add this malware, but many people also get tricked into downloading the software onto their phones or computers... Within minutes of turning the devices on, there was a surge of internet traffic... Visits to gambling, porn, cryptocurrency and loads of other sketchy web sites started pouring in from users around the world." (And remote visitors also tried to access Outlook and Gmail accounts...)

Residential proxy companies even rent out access to "tens of millions of home networks around the world," according to the report. "But the problem is actually worse than that. Hackers figured out a way to seize control of these backdoors, and they started taking over these residential networks. Last month authorities arrested a 23-year-old Ottawa man, saying he'd taken control of more than a million devices to launch some of the largest cyberattacks anyone had ever seen.."

After a couple months the Journal's reporter collected logs of all the traffic, and sent it to an investigator at Comcast, who said both were conducting DDoS attacks. But estimate for the number of infected devices are as low as tens of millions or as high 500 million-plus. "We've seen nation state attacks launched through these kind of endpoints, which means your device sitting in your house is part of a nation state attack against another nation state... We've seen ad fraud, we've seen ticket scalping, we've seen financial fraud."

But more importantly, "We have seen some of the largest computer attacks — meaning computers attacking other computers at human request — ever recorded in our digital history in the last several months." At cybersecurity conferences, some are warning "there are much larger ones on the horizon if we don't get a hold of this problem."

The company making the picture frame "couldn't be reached for comment," while Amazon said it's been out of stock since last year. Both Amazon and Walmart said they take action when they confirm malware on a third-party product.

Slashdot Top Deals