The Almighty Buck

Senator Tries To Block Frontier's FCC Funding, Citing ISP's Various Failures (arstechnica.com) 34

An anonymous reader quotes a report from Ars Technica: A Republican US senator from West Virginia has asked the government to block broadband funding earmarked for Frontier Communications, saying that the ISP is not capable of delivering gigabit-speed Internet service to all required locations. Sen. Shelley Moore Capito (R-W.Va.) outlined her concerns in a letter to Federal Communications Commission Chairman Ajit Pai last week. Capito told Pai that Frontier has mismanaged previous government funding and seems to lack both the technological capabilities and financial ability to deliver on its new obligations.

Frontier, which filed for bankruptcy in April, is one of 180 ISPs that won funding in the FCC's Rural Digital Opportunity Fund (RDOF) reverse-auction results announced last week. Frontier is due to receive $370.9 million over 10 years to bring broadband to 127,188 homes and businesses in eight states. Frontier's biggest payout is in West Virginia, where it is due to receive $247.6 million over 10 years to expand its broadband network to 79,391 locations. Frontier won over two-thirds of the funding that the FCC allocated to West Virginia despite failing to hit FCC deadlines for a previous round of subsidized broadband deployment in West Virginia and other states. Under the previous funding allocated in 2015 via the FCC's Connect America Fund, Frontier was originally required to meet the build deadlines by the end of 2020. Frontier told Ars today that it will now meet that deadline "by the end of 2021."

Capito urged Pai to block Frontier's new funding by rejecting the ISP's long-form application, which must be completed by winning bidders in order to receive the allocated money. "The stakes are simply too high to provide nearly $250 million to a company that does not have the capability to deliver on the commitments made to the FCC," she wrote. Under FCC rules, winning bidders must deploy broadband to 40 percent of required locations in each state within three calendar years, to 60 percent within four years, 80 percent within five years, and 100 percent within six years. Because Frontier won funding in the gigabit tier, it is required to offer download speeds of 1Gbps and upload speeds of 500Mbps along with monthly usage allowances of at least 2TB.

Microsoft

Software Freedom Conservancy: Microsoft Should Resign from RIAA Over Youtube-DL Takedown Demand (sfconservancy.org) 48

"We believe that youtube-dl has substantial non-infringing uses," argues the non-profit Software Freedom Conservancy. But while that software faces a DMCA takedown notice from the Recording Industry Association of America (RIAA), GitHub's owner Microsoft is also a paying member of the RIAA.

The Software Freedom Conservancy argues that this leaves Microsoft "stuck between their industry association's abuses of the law and the needs of FOSS projects for which they provide infrastructure." While under current law (which we object to), complying with the takedown notice is admittedly the fastest way to limit Microsoft's liability, we view Microsoft's membership in the RIAA as a much bigger liability to our community, now that Microsoft controls GitHub. We call on Microsoft to resign from the RIAA and remove their conflict of interest in this matter.

This is an important opportunity for Microsoft to stand up for the values of software freedom...

To build a strong community of FOSS developers, we need confidence that our software hosting platforms will fight for our rights. While we'd prefer that Microsoft would simply refuse to kowtow to institutions like the RIAA and reject their DMCA requests, we believe in the alternative Microsoft can take the easy first step of resigning from RIAA in protest. We similarly call on all RIAA members who value FOSS to also resign.

AI

Google's Breast Cancer-Predicting AI Research is Useless Without Transparency, Critics Say (venturebeat.com) 24

An anonymous reader shares a report: Back in January, Google Health, the branch of Google focused on health-related research, clinical tools, and partnerships for health care services, released an AI model trained on over 90,000 mammogram X-rays that the company said achieved better results than human radiologists. Google claimed that the algorithm could recognize more false negatives -- the kind of images that look normal but contain breast cancer -- than previous work, but some clinicians, data scientists, and engineers take issue with that statement. In a rebuttal published today in the journal Nature, over 19 coauthors affiliated with McGill University, the City University of New York (CUNY), Harvard University, and Stanford University said that the lack of detailed methods and code in Google's research "undermines its scientific value."

Science in general has a reproducibility problem -- a 2016 poll of 1,500 scientists reported that 70% of them had tried but failed to reproduce at least one other scientist's experiment -- but it's particularly acute in the AI field. At ICML 2019, 30% of authors failed to submit their code with their papers by the start of the conference. Studies often provide benchmark results in lieu of source code, which becomes problematic when the thoroughness of the benchmarks comes into question. One recent report found that 60% to 70% of answers given by natural language processing models were embedded somewhere in the benchmark training sets, indicating that the models were often simply memorizing answers. Another study -- a meta-analysis of over 3,000 AI papers -- found that metrics used to benchmark AI and machine learning models tended to be inconsistent, irregularly tracked, and not particularly informative.

Ubuntu

Lenovo Begins Selling 30 Linux ThinkPads and ThinkStation PCs (zdnet.com) 74

"More top-tier computer OEMs are now offering a broad assortment of Linux desktops," reports ZDNet.

"In the latest move, Lenovo, currently the top PC vendor in the world according to Gartner, will roll Ubuntu Linux 20.04 LTS out across 30 of Lenovo's ThinkPads and ThinkStations..." While Lenovo started certifying most of its laptop and PC line on the top Linux distributions since June 2020, this is a much bigger step. Now, instead of simply acknowledging its equipment will be guaranteed to run Linux, Lenovo's selling Ubuntu Linux-powered hardware to ordinary Joe and Jane users.

Previously, you could only buy most of these machines if you were a business and had specified you wanted Ubuntu on a customized bid. Now, nearly 30 Ubuntu-loaded devices will now be available for purchase via Lenovo.com. These include 13 ThinkStation and ThinkPad P Series Workstations and an additional 14 ThinkPad T, X, X1, and L series laptops, all with the 20.04 LTS version of Ubuntu...

No one's predicting a "Year of the Linux desktop." Companies such as Dell and Lenovo aren't predicting such a game-changing event, but they're selling largely to enterprise companies, which have seen the virtues of using high-end Linux desktops for powerful, forward-looking technologies such as AI, ML, containers, and cloud-native computing.

"Our announcement of device certification in June was a step in the right direction to enable customers to more easily install Linux on their own," explains Lenovo's vice president of PCSD software and cloud — but now they're going even further.

"Our goal is to remove the complexity and provide the Linux community with the premium experience that our customers know us for. This is why we have taken this next step to offer Linux-ready devices right out of the box."
Android

Android 11 Is Taking Away the Camera Picker, Forcing People To Only Use the Built-In Camera (androidpolice.com) 156

In the name of security and privacy, Google is taking away the ability for users to select third-party camera apps in Android 11, forcing users to rely on the built-in camera app. Android Police reports: At the heart of this change is one of the defining traits of Android: the Intent system. Let's say you need to take a picture of a novelty coffee mug to sell through an auction app. Since the auction app wasn't built for photography, the developer chose to leave that up to a proper camera app. This where the Intent system comes into play. Developers simply create a request with a few criteria and Android will prompt users to pick from a list of installed apps to do the job.

However, things are going to change with Android 11 for apps that ask for photos or videos. Three specific intents will cease to work like they used to, including: VIDEO_CAPTURE, IMAGE_CAPTURE, and IMAGE_CAPTURE_SECURE. Android 11 will now automatically provide the pre-installed camera app to perform these actions without ever searching for other apps to fill the role. Google describes the change in a list of new behaviors in Android 11, and further confirmed it in the Issue Tracker. Privacy and security are cited as the reason, but there's no discussion about what exactly made those intents dangerous. Perhaps some users were tricked into setting a malicious camera app as the default and then using it to capture things that should have remained private.

Not only does Android 11 take the liberty of automatically launching the pre-installed camera app when requested, it also prevents app developers from conveniently providing their own interface to simulate the same functionality. I ran a test with some simple code to query for the camera apps on a phone, then ran it on devices running Android 10 and 11 with the same set of camera apps installed. Android 10 gave back a full set of apps, but Android 11 reported nothing, not even Google's own pre-installed Camera app.

The Courts

Cities Sue Netflix, Hulu, Disney+, Claim They Owe Cable 'Franchise Fees' (arstechnica.com) 111

Four cities in Indiana are suing Netflix and other video companies, claiming that online video providers and satellite-TV operators should have to pay the same franchise fees that cable companies pay for using local rights of way. Ars Technica reports: The lawsuit was filed against Netflix, Disney, Hulu, DirecTV, and Dish Network on August 4 in Indiana Commercial Court in Marion County. The cities of Indianapolis, Evansville, Valparaiso, and Fishers want the companies to pay the cable-franchise fees established in Indiana's Video Service Franchises (VSF) Act, which requires payments of 5 percent of gross revenue in each city.

The lawsuit is based on an unusual legal argument and doesn't seem likely to succeed. Essentially, the cities are claiming that Netflix and similar providers use the public rights of way simply by offering video streaming services over the Internet: "Defendants transmit video programming to Indiana subscribers using Internet protocol and other technologies. When doing so, Defendants transmit their programming through facilities located at least in part in public rights of way within the geographic boundaries of Indiana Units, including public rights of way located within Plaintiffs' geographic boundaries. Therefore, Defendants are required by the VSF Act to pay the Plaintiffs -- and all other Indiana Units in which Defendants transmit video programming through facilities located at least in part in a public right-of-way -- "franchise fees."

But streaming companies don't have to build physical infrastructure in each city to offer online video, so they aren't deploying their own wires on public rights of way. US law defines a cable system as "a facility, consisting of a set of closed transmission paths and associated signal generation, reception, and control equipment that is designed to provide cable service." Local franchising rules and fees are based on cities' authority to manage their local rights of way. Netflix, Hulu, and Disney+ are Internet-only services. Dish and DirecTV are primarily satellite operators but also offer online access. The cities' lawsuit never mentions the word "satellite" and doesn't fully explain how DirecTV and Dish use the public rights of way.

Transportation

Uber Drivers To Launch Legal Bid To Uncover App's Algorithm (theguardian.com) 31

AmiMoJo shares a report from The Guardian: Minicab drivers will launch a legal bid to uncover secret computer algorithms used by Uber to manage their work in a test case that could increase transparency for millions of gig economy workers across Europe. Two UK drivers are demanding to see the huge amounts of data the ride-sharing company collects on them and how this is used to exert management control, including through automated decision-making that invisibly shapes their jobs. The case is being brought on Monday by the UK-based App Drivers and Couriers Union in the district court in Amsterdam, where the international headquarters of the $56 billion ride-hailing firm is located. The union said transparency was essential in checking if Uber was exercising discrimination or unequal treatment between drivers. It will also allow drivers to organize and build collective bargaining power over terms of work and pay in a way that is currently impossible.

The claim says Uber uses tags on drivers' profiles, for example "inappropriate behavior" or simply "police tag." Reports relate to "navigation -- late arrival / missed ETA" and "professionalism -- cancelled on rider, inappropriate behavior, attitude." The drivers complain they were not being provided with this data or information on the underlying logic of how it was used. They want to how that processing affects them, including on their driver score. The union members Azeem Hanif and Alfie Wellcoat claim Uber has failed to fulfill its obligations in its response to their requests under general data protection regulations (GDPR). They want to see their detailed driver profiles, comments about them made by Uber staff and how more than two dozen categories of data gathered about them are processed, legal papers show.
A spokesperson for Uber said: "Our privacy team works hard to provide any requested personal data that individuals are entitled to. We will give explanations when we cannot provide certain data, such as when it doesn't exist or disclosing it would infringe on the rights of another person under GDPR. Under the law, individuals have the right to escalate their concerns by contacting Uber's data protection officer or their national data protection authority for additional review."
Government

America's Border Patrol 'Can Track Everyone's Car' By Buying License Plate-Reader Data (arstechnica.com) 142

America's border-protection agency "can track everyone's cars all over the country thanks to massive troves of automated license plate scanner data, a new report reveals," reports Ars Technica.

And they didn't need to request search warrants from the courts, the article explains, since "the agency did just what hundreds of other businesses and investigators do: straight-up purchase access to commercial databases." U.S. Customs and Border Protection (CBP) has been buying access to commercial automated license plate-reader databases since 2017, TechCrunch reports, and the agency says bluntly that there's no real way for any American to avoid having their movements tracked. "CBP cannot provide timely notice of license plate reads obtained from various sources outside of its control," the agency wrote in its most recent privacy assessment. "The only way to opt out of such surveillance is to avoid the impacted area, which may pose significant hardships and be generally unrealistic...."

CBP already buys cell phone location data, even though it would not legally be able to hoover it up on a wide scale directly. Police also purchase hacked and breached data from third-party vendors that they can then use to track and identify individuals in ways that otherwise might have required a warrant.

Although hundreds of jurisdictions nationwide use automated plate-scanning technology, fewer than 20 states have laws of any kind on their books governing the collection, use, and storage of automated license plate-reader (ALPR) data. Even fewer of those laws specify what private entities can collect ALPR data and what can be done with that information. The software also seems to become more granular almost by the day.

Theoretically, CBP only has authority to operate within 100 miles of the US border. The data it purchases, however, may allow it to track any given license plate basically anywhere in the country.

The Military

'If War Breaks Out on Top of the World' (popularmechanics.com) 83

The United States Air Force's elite "PJ" pararescue units and Alaska National Guard units "are ready to respond if war breaks out on top of the world," reports a new article in Popular Mechanics: With much of the ice cap melted, the Arctic is teeming with competitive activity because it's no longer an impenetrable land of glaciers — void of economic or strategic military advantages. In fact, quite the opposite. The U.S., Russia, and China all recognize that new shipping lanes and natural resources, worth trillions of dollars, are becoming more viable every day in the Arctic. Each nation has its own economic interests and the competition for control in the Arctic is only increasing.

Lt. Gen. Tom Bussiere says simply: "Whoever holds Alaska holds the region, and that impacts the globe," and according to the U.S. Senator of Alaska Dan Sullivan, "we have fallen behind in the race with China and Russia." Russia is reviving Soviet-era Arctic bases, increasing its fleet of Arctic icebreakers to a whopping 41 vessels (the U.S. has only two though this shortage is getting more attention), and Russian TU-95 "Bear" bombers frequently test F-22A Raptors' readiness near U.S. airspace.

And China has its own plans. Though not an Arctic nation like the U.S. or Russia, China's economic clout gained the nation an observer seat in the Arctic Council under the claims that they are a "near-Arctic state." China is positioning itself to stake a greater claim to the bountiful resources that the Arctic can provide, based on a bold plan they call the "Polar Silk Road." If completed, the plan will create an economic network beneficial to China through the once-frozen ocean.

In response to Russian operations and Chinese advances, the U.S. Air Force is battling for air superiority in the Arctic with its most valuable — and lethal — assets in Alaska, including the F-22A Raptor and F-35A Joint Strike Fighter.

By "battling" I think they mean "spending." A related side note: The article was co-authored by the producer of the TV series War On Top of The World
Open Source

Google Open Sources Trademarks With the Open Usage Commons (zdnet.com) 6

An anonymous reader quotes a report from ZDNet: Google has announced it is launching a new organization, Open Usage Commons (OUC), to host the trademarks for three of its most important new open-source projects. These are Angular, a web application framework for mobile and desktop; Gerrit, a web-based team code-collaboration tool; and Istio, a popular open mesh platform to connect, manage, and secure microservices. While it only covers three Google projects, for now, OUC is meant to give open-source projects a neutral, independent home for their project trademarks. The organization will also assist with conformance testing, establishing mark usage guidelines, and handling trademark usage issues. The organization will not provide services that are outside the realm of usage, such as technical mentorship, community management, project events, or project marketing. "Having an entity like this does make some sense for a certain number of use cases," says Andrew "Andy" Updegrove, open-source standards and patent expert and founding partner of top-technology law firm Gesmer Updegrove. "The most obvious one is an unincorporated OSS project. An amorphous group of individuals can't own a trademark efficiently, so there's no way to protect the project name unless they agree on a singular owner. There are many cases where an individual member has owned a project mark, and that has often led to downstream problems. So simply having a neutral owner is a community good without going any farther than that."

Updegrove also said noted trademarks have usually been achieved by a project "approaching a host, like The Apache Foundation or Linux Foundation and asking them to take over as host. But that usually requires taking the project under the umbrella, and subject to the rules, of that foundation."

Updegrove wonders if there's "more to the story than meets the eye." He notes there is one important difference by only handing over the trademarks: "A project that is primarily important to a single vendor and primarily staffed and controlled by developers employed by that employer can continue to exercise effective control while avoiding the market suspicion that might arise if the vendor owned the mark." He suspects Google is doing this "to up the credibility of some of its projects [to the open-source community] while not taking the more extreme step of turning the project over to a foundation in connection with which a new and more independent governance structure is put in place."
Businesses

Basecamp's Hey, a New Email Product, Claims Apple is Rejecting Bug Fixes to the iPhone App Unless the Firm Agrees To Pay 15-30% Commission (twitter.com) 121

Basecamp launched its email product Hey earlier this week. David Heinemeier Hansson, the co-founder of Basecamp, tweeted on Tuesday that Apple is already creating challenges for the firm. In a series of tweets, he said: Apple just doubled down on their rejection of HEY's ability to provide bug fixes and new features, unless we submit to their outrageous demand of 15-30% of our revenue. Even worse: We're told that unless we comply, they'll remove the app. On the day the EU announced their investigation into Apple's abusive App Store practices, HEY is subject to those very same capricious, exploitive, and inconsistent policies of shakedown. It's clear they feel embolden to tighten the screws with no fear of regulatory consequences. He adds: Apple has been capriciously, inconsistently, and in a few cases, cruelly, enforcing their App Store policies for years. But most of the abuses were suffered by smaller developers without a platform and without recurse. Apple saw that it worked, and that it paid. Now moving up. This is exactly the issue I gave testimony in front of congress earlier this year! We hadn't yet launched HEY, but I said it worried me, what Apple might do, if you're in direct competition with them. And now we know what they'd do. Attempt to crush us. But while I'm sure Apple's attempt to cut off the air supply to the likes of Spotify is board-room stuff, I think what we're facing is simply the banality of bureaucracy. Apple has publicly pivoted to services for growth, so KPIs and quarterly targets trickle down. And frankly, it's hard to see what they have to fear. Who cares if Apple shakes down individual software developers for 30% of their revenue, by threatening to destroy their business? There has been zero consequences so far! Most such companies quietly cave or fail. We won't. There is no chance in bloody hell that we're going to pay Apple's ransom. I will burn this house down myself, before I let gangsters like that spin it for spoils. This is profoundly, perversely abusive and unfair.

We did everything we were supposed to with the iOS app. Try downloading it (while you can?). You can't sign up, because Apple says no. We don't mention subscriptions. You can't upgrade. You can't access billing. We did all of it! Wasn't enough. We've been in the App Store with Basecamp for years. We know the game. It was always rigged. It was always customer-hostile, deeply confusing, but the unstated lines were reasonably clear. Now Apple has altered the deal, and all we can do is pray they don't alter it further.

Wireless Networking

MIT Develops a Way To Use Wireless Signals From In-Home Appliances To Better Understand Your Health (techcrunch.com) 16

[R]esearchers at MIT's Computer Science and Artificial Intelligence Lab (CSAIL) have developed a new system (PDF) that can figure out when and where in-home appliances like hair dryers, stoves, microwaves and washing machines are being used, and they believe that info could help inform healthcare practitioners about the habits and challenges of people under their care. TechCrunch reports: The researchers devised a system called "Sapple" that uses just two sensors placed in a person's home to determine use patterns of devices including stoves, hair dryers and more. There's one location sensor that works using radio signals to figure out placement, with a user able to calibrate it to cover their area by simply walking the bounds of their space. A second sensor measures energy usage through the home, and combines that data with movement information to matching energy use signals with physical locations of specific applicants, to provide data both when a person is using the appliances around the house, and for how long.

This gets around a lot of the issues raised by similar systems, including more simple voltage meters used on their own. While appliances do tend to have specific energy use patterns that mean you can identify them just based on consumption, it's hard to tell when and how they're being used with that data on its own. This info can let health professionals know if a patient is taking proper care of hygiene, food preparation and intake and more.

The Internet

Comcast Resists Call To Open Home Wi-Fi Hotspots, Cites Potential Congestion (arstechnica.com) 99

Three U.S. senators today urged Comcast to open all of its Wi-Fi hotspots to children who lack Internet access at home during the pandemic. Ars Technica reports: A letter (PDF) from Sens. Ron Wyden (D-Ore.), Kamala Harris (D-Calif.), and Cory Booker (D-N.J.) says that Comcast recently refused a request to do so because it would cause congestion for subscribers. But the senators argue that "Comcast's excuse simply does not add up." Comcast has been praised by advocates for its pandemic response, which includes two free months of home-Internet service for new low-income subscribers, temporary suspension of its data cap, and making many of its hotspots free to the general public. But while Comcast opened up 1.5 million hotspots located at businesses and other public areas, there's another category of Comcast Wi-Fi hotspots that still require a Comcast login and subscription. Those are the hotspots that are enabled by default on Xfinity routers used by home-Internet subscribers.

Since 2013, Xfinity gateways have broadcasted a separate network that other Comcast subscribers can log in to with a Comcast username and password. Unless you've disabled the functionality, anyone within range of your Comcast router can get Internet access if they have a Comcast subscription or have paid for a temporary Wi-Fi pass. Wyden, Harris, and Booker argue that Comcast should open these hotspots to children without Internet access during the pandemic so that kids can get free broadband at home instead of having to go to a parking lot or other public places.
In the letter, the senators ask Comcast to answer a list of questions by May 22. They also want the company to provide specific details on how opening up the hotspots would affect network performance.

"Please identify the specific performance issues that you anticipate would impact Comcast subscribers and their ability to get the level of service for which they pay if Comcast removed the paywall on its residential public Wi-Fi networks," the senators wrote. "For each issue you identify, please explain why the use today of a subscriber's public network by someone who has purchased an access pass from Comcast does not cause the same problem."
Medicine

Medical Device 'Jailbreak' Could Help Solve the Dangerous Shortage of Ventilators (arstechnica.com) 116

An anonymous reader quotes a report from Ars Technica: Security researcher Trammell Hudson analyzed the AirSense 10 -- the world's most widely used CPAP -- and made a startling discovery. Although its manufacturer says the AirSense 10 would require "significant rework to function as a ventilator," many ventilator functions were already built into the device firmware. Its manufacturer, ResMed, says the $700 device solely functions as a continuous positive airway pressure machine used to treat sleep apnea. It does this by funneling air into a mask. ResMed says the device can't work as a bilevel positive airway pressure device, which is a more advanced machine that pushes air into a mask and then pulls it back out. With no ability to work in both directions or increase the output when needed, the AirSense 10 can't be used as the type of ventilator that could help patients who are struggling to breathe. After reverse-engineering the firmware, Hudson says the ResMed claim is simply untrue.

To demonstrate his findings, Hudson on Tuesday is releasing a patch that he says unlocks the hidden capabilities buried deep inside the AirSense 10. The patch is dubbed Airbreak in a nod to jailbreaks that hobbyists use to remove technical barriers Apple developers erect inside iPhones and iPads. Whereas jailbreaks unlock functions that allow the installation of unauthorized apps and the accessing of log files and forensic data, Airbreak allows the AirSense 10 to work as a bilevel positive airway pressure machine, a device that many people refer to as a BiPAP. "Our changes bring the AirSense S10 to near feature parity with BiPAP machines from the same manufacturer, boost the maximum pressure output available, and provide a starting point to add more advanced emergency ventilator functionality," Hudson and other researchers wrote on their website disclosing the findings.
The researchers say Airbreak isn't ready to be used on any device to treat a patient suffering from COVID-19 -- it's simply to prove that the AirSense 10 does have the ability to provide emergency ventilator functions, and to push ResMed to release its own firmware update that unlocks the ventilator functions.
Security

OpenWRT Code-Execution Bug Puts Millions of Devices At Risk (arstechnica.com) 60

Dan Goodin writes via Ars Technica: For almost three years, OpenWRT -- the open source operating system that powers home routers and other types of embedded systems -- has been vulnerable to remote code-execution attacks because updates were delivered over an unencrypted channel and digital signature verifications are easy to bypass, a researcher said. Security researcher Guido Vranken, however, recently found that updates and installation files were delivered over unencrypted HTTPs connections, which are open to attacks that allow adversaries to completely replace legitimate updates with malicious ones. The researcher also found that it was trivial for attackers with moderate experience to bypass digital-signature checks that verify a downloaded update as the legitimate one offered by OpenWTR maintainers. The combination of those two lapses makes it possible to send a malicious update that vulnerable devices will automatically install.
[...]
The researcher said that OpenWRT maintainers have released a stopgap solution that partially mitigates the risk the bug poses. The mitigation requires new installations to be "set out from a well-formed list that would not sidestep the hash verification. However, this is not an adequate long-term solution because an attacker can simply provide an older package list that was signed by the OpenWRT maintainers." From there, attackers can use the same exploits they would use on devices that haven't received the mitigation. OpenWRT maintainers didn't immediately respond to questions asking why installation and update files are delivered over HTTP and when a longer-term fix might be available. In the meantime, OpenWRT users should install either version 18.06.7 or 19.07.1, both of which were released in February. These updates provide the stopgap mitigation.

Supercomputing

D-Wave Makes Its Quantum Computers Free To Anyone Working On Coronavirus Crisis 18

An anonymous reader quotes a report from VentureBeat: D-Wave today made its quantum computers available for free to researchers and developers working on responses to the coronavirus (COVID-19) crisis. D-Wave partners and customers Cineca, Denso, Forschungszentrum Julich, Kyocera, MDR, Menten AI, NEC, OTI Lumionics, QAR Lab at LMU Munich, Sigma-i, Tohoku University, and Volkswagen are also offering to help. They will provide access to their engineering teams with expertise on how to use quantum computers, formulate problems, and develop solutions.

Quantum computing leverages qubits to perform computations that would be much more difficult, or simply not feasible, for a classical computer. Based in Burnaby, Canada, D-Wave was the first company to sell commercial quantum computers, which are built to use quantum annealing. D-Wave says the move to make access free is a response to a cross-industry request from the Canadian government for solutions to the COVID-19 pandemic. Free and unlimited commercial contract-level access to D-Wave's quantum computers is available in 35 countries across North America, Europe, and Asia via Leap, the company's quantum cloud service. Just last month, D-Wave debuted Leap 2, which includes a hybrid solver service and solves problems of up to 10,000 variables.
Businesses

Yelp To Stop Auto-Creating GoFundMe Fundraisers After Outrage From Business Owners (theverge.com) 53

Yelp has paused an effort in partnership with GoFundMe that automatically opted tens of thousands of small businesses into fundraisers after complaints from restaurant and bar owners, the company tells The Verge. From the report: Yelp launched the initiative earlier this week in response to the ongoing coronavirus pandemic, but it did so without informing any of participants. Some business owners said the process for opting out -- in the event they were hosting their own fundraisers or simply did not want one automatically set up by Yelp -- was unnecessarily cumbersome.

"On Tuesday, Yelp announced a partnership with GoFundMe to provide a fast and easy way for people to support their favorite local businesses by donating to a GoFundMe fundraiser directly on the Yelp pages of eligible businesses. In an effort to get businesses help quickly and easily, a GoFundMe fundraiser was automatically added to the Yelp pages of an initial group of eligible businesses, with information provided on how to claim it or opt out should a business choose to do so," a spokesperson said in a statement. "However, it has come to our attention that some businesses did not receive a notification with opt-out instructions, and some would have preferred to actively opt-in to the program," the statement goes on to say. "As such, we have paused the automatic rollout of this feature, and are working with GoFundMe to provide a seamless way for businesses to opt into the program moving forward, as we have received a great deal of interest and support for the program from both consumers and businesses alike."

Yelp said in its original announcement of the GoFundMe partnership that it would be waiving fees and that both companies would match the first $1 million donated. However, critics of the partnership fast discovered that GoFundMe was setting the recommended tip, which is how GoFundMe funds its own operations, at 15 percent. "Yelp does not get any portion of the donations. Donations through the GoFundMe platform may be subject to payment processing fees in some instances per the terms of the GoFundMe platform," reads an FAQ page for the program.

Programming

Microsoft Plots the End of Visual Basic (thurrott.com) 66

Microsoft said this week that it will support Visual Basic on .NET 5.0 but will no longer add new features or evolve the language. From a report: "Starting with .NET 5, Visual Basic will support Class Library, Console, Windows Forms, WPF, Worker Service, [and] ASP.NET Core Web API ... to provide a good path forward for the existing VB customer who want [sic] to migrate their applications to .NET Core," the .NET team wrote in a post to the Microsoft DevBlogs. "Going forward, we do not plan to evolve Visual Basic as a language ... The future of Visual Basic ... will focus on stability, the application types listed above, and compatibility between the .NET Core and .NET Framework versions of Visual Basic."

When Microsoft released the .NET version of Visual Basic, originally called Visual Basic .NET, alongside C# at the beginning of the .NET era, the two languages were evolved together and had roughly identical feature sets. But this changed over time, with professional developers adopting C# and many fans of classic VB simply giving up on the more complex but powerful .NET versions of the environment. Today, virtually all of Microsoft's relevant developer documentation is in C# only, with VB source code examples ever harder to find.

Government

America Proposes New Rules Requiring Drones to Broadcast Their Location Online (arstechnica.com) 120

LetterRip (Slashdot reader #30,937) shares a report from Ars Technica: More than 34,000 people have deluged the Federal Aviation Administration with comments over a proposed regulation that would require almost every drone in the sky to broadcast its location over the Internet at all times. The comments are overwhelmingly negative, with thousands of hobbyists warning that the rules would impose huge new costs on those who simply wanted to continue flying model airplanes, home-built drones, or other personally owned devices...

The new rules are largely designed to address safety and security concerns raised by law enforcement agencies. They worry that drones flying too close to an airport could disrupt operations or even cause a crash. They also worry about terrorists using drones to deliver payloads to heavily populated areas. To address these concerns, the new FAA rule would require all new drones weighing more than 0.55 pounds to connect over the Internet to one of several location-tracking databases (still to be developed by private vendors) and provide real-time updates on their location. That would enable the FAA or law enforcement agencies to see, at a glance, which registered drones are in any particular area...

The rules require that the drone itself have an Internet connection. That will instantly render many existing drones obsolete, forcing hobbyists to upgrade or discard them. And it will also make it significantly more expensive to own a drone, since you'll need to sign up for a data plan.... Apparently anticipating a backlash, the FAA does offer a workaround for people with existing or custom-built aircraft: special FAA-designated areas where people could fly non-compliant aircraft. These would be run by "community-based organizations" — most likely existing model airplane clubs that already operate fields for hobbyists to fly their aircraft.

Facebook

Twitter and Facebook Criticized For Not Removing False Claims About Iowa Voters (siliconvalley.com) 109

What happened when conservative activist Tom Fitton issued an inaccurate press release last week about Iowa's voter registration rolls? After being debunked by Republican state officials -- and identified as "false" by the Associated Press -- the false claims simply remained on both Facebook and Twitter.

The Associated Press reports: Fitton, founder of Judicial Watch, tweeted a report claiming that eight Iowa counties have more people registered to vote than are actually eligible to vote. [Republican] Iowa Secretary of State Paul Pate moved quickly to counter the false information... Pate tweeted a link to the secretary of state's website, for those who wanted to check the numbers. "The county population numbers you claim are way too low. Dallas County's population, according to the U.S. Census Bureau, is nearly 9,000+ more than you claim, and Johnson County's is nearly 7,000 higher," Pate tweeted.

But the false information circulated Sunday and throughout the day on social media.

One tweet was retweeted over 40,000 times. But according to another report, that was just the beginning... The claim was amplified on Twitter by Fox TV host Sean Hannity, a close confidant of President Donald Trump... Fitton admitted in an interview that he "used older statistics and census numbers to reach his conclusion," the Associated Press reported. Judicial Watch's posts were still on Twitter and Facebook as of Wednesday afternoon.

A Twitter spokesperson said the Judicial Watch tweet was "not in violation of our election integrity policy as it does not suppress voter turnout or mislead people about when, where, or how to vote." Twitter last year banned political advertising on its platform.

Facebook, which controversially allows politicians to lie in political ads, did not provide a response to this news organization's inquiry about the Judicial Watch post. Facebook's director of product management has said the firm does not fact-check political ads for truthfulness and that those ads should be regulated by the federal government, not social media companies.

The Republican Secretary of State said in a statement that the false claims "erode voter confidence in elections."

Slashdot Top Deals