NASA

NASA Is Tracking a Vast, Growing Anomaly In Earth's Magnetic Field (sciencealert.com) 59

fahrbot-bot shares a report from ScienceAlert: NASA is actively monitoring a strange anomaly in Earth's magnetic field: a giant region of lower magnetic intensity in the skies above the planet, stretching out between South America and southwest Africa. This vast, developing phenomenon, called the South Atlantic Anomaly, has intrigued and concerned scientists for years, and perhaps none more so than NASA researchers. The space agency's satellites and spacecraft are particularly vulnerable to the weakened magnetic field strength within the anomaly, and the resulting exposure to charged particles from the Sun.

The primary source is considered to be a swirling ocean of molten iron inside Earth's outer core, thousands of kilometers below the ground. A huge reservoir of dense rock called the African Large Low Shear Velocity Province, located about 2,900 kilometers (1,800 miles) below the African continent, disturbs the field's generation, resulting in the dramatic weakening effect -- which is aided by the tilt of the planet's magnetic axis. It's not just moving, however. Even more remarkably, the phenomenon seems to be in the process of splitting in two, with researchers this year discovering that the SAA appears to be dividing into two distinct cells, each representing a separate centre of minimum magnetic intensity within the greater anomaly. Just what that means for the future of the SAA remains unknown, but in any case, there's evidence to suggest that the anomaly is not a new appearance.

Android

Android 11 Is Taking Away the Camera Picker, Forcing People To Only Use the Built-In Camera (androidpolice.com) 156

In the name of security and privacy, Google is taking away the ability for users to select third-party camera apps in Android 11, forcing users to rely on the built-in camera app. Android Police reports: At the heart of this change is one of the defining traits of Android: the Intent system. Let's say you need to take a picture of a novelty coffee mug to sell through an auction app. Since the auction app wasn't built for photography, the developer chose to leave that up to a proper camera app. This where the Intent system comes into play. Developers simply create a request with a few criteria and Android will prompt users to pick from a list of installed apps to do the job.

However, things are going to change with Android 11 for apps that ask for photos or videos. Three specific intents will cease to work like they used to, including: VIDEO_CAPTURE, IMAGE_CAPTURE, and IMAGE_CAPTURE_SECURE. Android 11 will now automatically provide the pre-installed camera app to perform these actions without ever searching for other apps to fill the role. Google describes the change in a list of new behaviors in Android 11, and further confirmed it in the Issue Tracker. Privacy and security are cited as the reason, but there's no discussion about what exactly made those intents dangerous. Perhaps some users were tricked into setting a malicious camera app as the default and then using it to capture things that should have remained private.

Not only does Android 11 take the liberty of automatically launching the pre-installed camera app when requested, it also prevents app developers from conveniently providing their own interface to simulate the same functionality. I ran a test with some simple code to query for the camera apps on a phone, then ran it on devices running Android 10 and 11 with the same set of camera apps installed. Android 10 gave back a full set of apps, but Android 11 reported nothing, not even Google's own pre-installed Camera app.

Privacy

Researchers Can Duplicate Keys From the Sounds They Make In Locks (kottke.org) 33

Researchers have demonstrated that they can make a working 3D-printed copy of a key just by listening to how the key sounds when inserted into a lock. Slashdot reader colinwb writes: While you cannot hear the shape of a drum it seems you can hear the shape of one type of key from the sound it makes in the lock. That says it all really, but [here's how Soundarya Ramesh and her team at the National University of Singapore accomplished this feat]: "[The NUS team developed and tested what it calls SpiKey, an end-to-end attack technique for, as its name suggests, spying on Yale/Schlage type keys and using signal processing software to infer their correct shapes.] Once they have a key-insertion audio file, SpiKey's inference software gets to work filtering the signal to reveal the strong, metallic clicks as key ridges hit the lock's pins [and you can hear those filtered clicks online here]. These clicks are vital to the inference analysis: the time between them allows the SpiKey software to compute the key's inter-ridge distances and what locksmiths call the 'bitting depth' of those ridges: basically, how deeply they cut into the key shaft, or where they plateau out. If a key is inserted at a nonconstant speed, the analysis can be ruined, but the software can compensate for small speed variations.

The result of all this is that SpiKey software outputs the three most likely key designs that will fit the lock used in the audio file, reducing the potential search space from 330,000 keys to just three. 'Given that the profile of the key is publicly available for commonly used [pin-tumbler lock] keys, we can 3D-print the keys for the inferred bitting codes, one of which will unlock the door,' says Ramesh." The article has a link to a 15-minute video presentation of the research and to another article on the research.

Medicine

Facebook and NYU Set Out To Develop AI-Powered 5-Minute MRI Scan 30

Researchers at NYU Langone Health and Facebook's artificial intelligence division have teamed up to develop an AI model that uses less data and creates images faster than traditional MRI techniques, according to a Wall Street Journal report. From a report: The goal of the project is to create a five-minute MRI as an alternative to the 20 minutes to an hour it takes for current MRI machines to scan a patient, Michael Recht, MD, told the publication. Dr. Recht is professor and chair of New York City-based NYU Langone Health's radiology department and also a co-author of the research project. The combination of AI and MRI technology aims to construct images with less data rather than diagnose a medical condition. The project uses different technology and standards than those used to create AI-generated or synthetic media. Because it centers on constructing MRI scans, Facebook said the project must create images "that are accurate to the ground truth," compared to synthetic media, which usually needs to create a believable image, according to the report.

For the experiment, researchers created 108 patient images using standard MRI techniques as well as a second set of images in which some of the image data was thrown out. Facebook's AI model was then applied to construct the images with less data. Researchers used commercially available MRI machines, and data was collected from patients from various points of their bodies. Six MRI readers reviewed both sets of images, and readings were spaced out across a four-week period to ensure the readers could not recall important details from previous sets. Dr. Recht told the Journal that all six engineers concluded that the quality of the AI model-generated images was "as good [as] or better" than the conventional images. The AI system still needs regulatory approval, but NYU Langone is now using it to treat patients as part of an institutional review board study, according to the report.
Google

Google Maps Is Getting a Lot More Detail (theverge.com) 65

An anonymous reader quotes a report from The Verge: Google Maps is being redesigned to make it easier to distinguish between natural features in the environment, whether they're mountainous ice caps, deserts, beaches, or dense forests. Google says the new maps will be available in the 220 countries and territories currently supported by Google Maps, "from the biggest metropolitan areas to small, rural towns." Google says that street maps are also getting more detailed in select cities. Google says it used satellite imagery as the basis for its redesigned maps and that this has had a "new color-mapping algorithmic technique" applied to it. The end result does a much better job of showing off the differences between natural features, such as between snowy peaks and dense forests or green fields and sandy beaches. The comparison shots below give an idea of what the new color-mapping technique is capable of.

Along with the changes it's made to the natural world, Google is also making its street maps more detailed in select cities. While previously its maps simply showed the streets themselves, in New York, San Francisco, and London, they'll soon distinguish between different street features like roadways, sidewalks, crosswalks, and pedestrian islands. Google says the new design shows the shape and width of any given road "to scale." Google says the more detailed maps of natural features will be rolling out starting this week around the world, and it adds that you'll need to "zoom out" to be able to see them. The improved street designs for New York, San Francisco, and London are getting released in the coming months, with plans to add more cities over time.

AI

AI Company Leaks Over 2.5 Million Medical Records 23

Secure Thoughts reports that artificial intelligence company Cense AI, which specializes in "SaaS-based intelligent process automation management solutions," has leaked nearly 2.6 million medical records on the internet. PCMag reports: [O]n July 7 security researcher Jeremiah Fowler discovered two folders of medical records available for anyone to access on the internet. The data was labeled as "staging data." Fowler believes the data was made public because Cense AI was temporarily hosting it online before loading it into the company's management system or an AI bot.

The medical records are quite detailed and include names, insurance records, medical diagnosis notes, and payment records. It looks as though the data was sourced from insurance companies and relates to car accident claims and referrals for neck and spine injuries. The majority of the personal information is thought to be for individuals located in New York, with a total of 2,594,261 records exposed. Fowler sent a responsible disclosure notice to Cense AI and public access to the folders was restricted soon after. However, the damage has potentially already been done if others had previously discovered the data was available. Fowler points out that medical data is the most valuable on the black market, fetching as much as $250 per record. If someone willing to act maliciously came across this data you can guarantee it is, or has been sold.
Facebook

Facebook Wanted to Be a Force for Good in Myanmar. Now It Is Rejecting a Request to Help With a Genocide Investigation (time.com) 57

Just when it seemed like Facebook's controversies might have peaked, the company now appears to be obstructing a genocide investigation, and it's using U.S. law to do it. From a report: The West African nation The Gambia is seeking to hold Myanmar accountable for charges of genocide against the Rohingya people, an ethnic and religious minority. In 2016 and 2017, Myanmar soldiers and their civilian proxies massacred Rohingya men, women and children, raped women and girls and razed villages, forcing more than 800,000 to flee into neighboring Bangladesh. Facebook's role in these atrocities isn't news. In 2018, Facebook acknowledged it was used to "foment division and incite offline violence" in Myanmar, where the social media platform is so ubiquitous it's often synonymous with the internet. An independent report commissioned by the company documented the same, as did independent fact-finders appointed by the U.N. In response, Facebook took down the account of the commander-in-chief of the Myanmar military, Senior General Min Aung Hlaing, and other military officials and organizations. In 2018 alone it shut down numerous networks that sought to incite violence against Rohingya, removing 484 pages, 157 accounts, and 17 groups for "coordinated inauthentic behavior."

To its credit, Facebook preserved the data and content it took down, and the company committed to cleaning up its act. "We know we need to do more to ensure we are a force for good in Myanmar," a company representative said in an official statement in 2018. Now, two years later, the company is doing exactly the opposite. In June, The Gambia filed an application in U.S. federal court seeking information from Facebook that would help it hold Myanmar accountable at the International Court of Justice (ICJ). Specifically, The Gambia is seeking documents and communications from Myanmar military officials as well as information from hundreds of other pages and accounts that Facebook took down and preserved. The Gambia is also seeking documents related to Facebook's internal investigations into the matter as well as a deposition of a relevant Facebook executive. All of this information could help to prove Myanmar's genocidal intent. Back in May, The Gambia filed a similar application in U.S. court against Twitter. The case disappeared quickly because The Gambia pulled its application shortly after submitting it, presumably because Twitter agreed to cooperate. Not Facebook. Earlier this month, the company filed its opposition to The Gambia's application. Facebook said the request is "extraordinarily broad," as well as "unduly intrusive or burdensome."

Cloud

New Toyotas Will Upload Data To AWS To Help Create Custom Insurance Premiums Based On Driver Behavior (theregister.com) 206

KindMind shares a report from The Register: Toyota has expanded its collaboration with Amazon Web Services in ways that will see many of its models upload performance data into the Amazonian cloud to expand the services the auto-maker offers to drivers and fleet owners. [...] Toyota reckons the data could turn into "new contextual services such as car share, rideshare, full-service lease, and new corporate and consumer services such as proactive vehicle maintenance notifications and driving behavior-based insurance."

The two companies say their joint efforts "will help build a foundation for streamlined and secure data sharing throughout the company and accelerate its move toward CASE (Connected, Autonomous/Automated, Shared and Electric) mobility technologies." Neither party has specified just which bits of the AWS cloud Toyota will take for a spin but it seems sensible to suggest the auto-maker is going to need lots of storage and analytics capabilities, making AWS S3 and Kinesis likely candidates for a test drive. Whatever Toyota uses, prepare for privacy ponderings because while cheaper car insurance sounds lovely, having an insurer source driving data from a manufacturer has plenty of potential pitfalls.

Privacy

'Landlord Tech Watch' Site Lets You Report Landlords Using Tech To Screw Over Tenants (vice.com) 114

An anonymous reader quotes a report from Motherboard: A group of activists have released Landlord Tech Watch, a site that allows anyone to report where this "landlord tech" is being used and plot it on a map -- like a version of Nextdoor that turns the tables to hold property owners and real estate companies accountable. The project is the effort of technologists and tenants rights advocates, who say they're aiming to use data to shed light on the use of biometric locks, tenant screening systems, and other technology used by landlords to exert power over tenants.

"It just became apparent that these technologies are increasingly being deployed in residential spaces, and there's so little public information about them," Erin McElroy, a postdoctoral researcher at the AI Now Institute and co-founder of the Anti-Eviction Mapping Project, told Motherboard. McElroy said the project came together following a prominent tenant dispute at Atlantic Plaza Towers, a rent-stabilized building in Brownsville, Brooklyn. The landlord, Robert Nelson, was trying to replace physical key fobs with a facial recognition system, a technology which has been repeatedly shown to exhibit racial bias. The project was abandoned after 136 tenants rallied in protest, filing a legal complaint with the New York State Department of Housing and Community Renewal.
"We want to be able to collectively organize tenants from multiple buildings," adds McElroy. "That's the ultimate goal -- whether it be for direct action or policy reform or both."
Medicine

WHO Blasts 'Vaccine Nationalism' in Last-Ditch Push Against Hoarding (reuters.com) 100

Nations that hoard possible COVID-19 vaccines while excluding others will deepen the pandemic, World Health Organization (WHO) chief Tedros Adhanom Ghebreyesus said on Tuesday, issuing a last-ditch call for countries to join a global vaccine pact. From a report: The WHO has an Aug. 31 deadline for wealthier nations to join the "COVAX Global Vaccines Facility" for sharing vaccine hopefuls with developing countries. Tedros said he sent a letter to the WHO's 194 member states, urging participation. The global health agency also raised concerns that the pandemic's spread was being driven now by younger people, many of whom were unaware they were infected, posing a danger to vulnerable groups. Tedros' push for nations to join COVAX comes as the European Union, Britain, Switzerland and the United States strike deals with companies testing prospective vaccines. Russia and China are also working on vaccines, and the WHO fears national interests could impede global efforts.
Medicine

'Covid-19 Is Creating a Wave of Heart Disease' 163

Haider Warraich, a cardiologist, writing for the New York Times: An intriguing new study from Germany offers a glimpse into how SARS-CoV-2 affects the heart. Researchers studied 100 individuals, with a median age of just 49, who had recovered from Covid-19. Most were asymptomatic or had mild symptoms. An average of two months after they received the diagnosis, the researchers performed M.R.I. scans of their hearts and made some alarming discoveries: Nearly 80 percent had persistent abnormalities and 60 percent had evidence of myocarditis. The degree of myocarditis was not explained by the severity of the initial illness.

Though the study has some flaws, and the generalizability and significance of its findings not fully known, it makes clear that in young patients who had seemingly overcome SARS-CoV-2 it's fairly common for the heart to be affected. We may be seeing only the beginning of the damage. Researchers are still figuring out how SARS-CoV-2 causes myocarditis -- whether it's through the virus directly injuring the heart or whether it's from the virulent immune reaction that it stimulates. It's possible that part of the success of immunosuppressant medications such as the steroid dexamethasone in treating sick Covid-19 patients comes from their preventing inflammatory damage to the heart. Such steroids are commonly used to treat cases of myocarditis. Despite treatment, more severe forms of Covid-19-associated myocarditis can lead to permanent damage of the heart -- which, in turn, can lead to heart failure.
Facebook

You'll Need a Facebook Account To Use Future Oculus Headsets (theverge.com) 120

Oculus will soon require all of its virtual reality headset users to sign up with a Facebook account. The Facebook-owned company says it will start removing support for separate Oculus accounts in October, although users can maintain an existing account until January 1st, 2023. All users can maintain a distinct "VR profile" with a separate friends list. From a report: Starting later this year, you'll only be able to sign up for an Oculus account through Facebook. If you already have an account, you'll be prompted to permanently merge your account. If you don't, you'll be able to use the headset normally until 2023, at which point official support will end. Old headsets using non-linked accounts will still work, but some games and apps may no longer function. Developers can keep using an unlinked developer account without social functionality, and the Oculus for Business platform uses a separate login process that will remain unchanged. Facebook also says that all future unreleased Oculus devices will require a Facebook login, even if you've got a separate account already.
Transportation

Uber and Lyft Consider Franchise-Like Model in California (nytimes.com) 169

Uber and Lyft, which are facing mounting pressure to classify their freelance drivers as full-time employees in California, are looking for another way. From a report: One option that both companies are seriously discussing is licensing their brands to operators of vehicle fleets in California, according to three people with knowledge of the plans. The change would resemble an independently operated franchise, allowing Uber and Lyft to keep an arms-length association with drivers so that the companies would not need to employ them and pay their benefits.

The idea would effectively be a return to the days of how groups of black cars were run. Lyft has presented the plan to its board of directors, one person said. Uber, which already works with fleet operators in Germany and Spain, is also familiar with the business model. The companies have not committed to the franchise-like plans, said the people with knowledge of the discussions, who asked to remain anonymous because the details are confidential. Uber and Lyft are waiting to see how California's legal situation around drivers, who have been treated as independent contractors, plays out first, they said.

Oracle

Oracle Enters Race To Buy TikTok's US Operations (ft.com) 78

phalse phace writes: Oracle has entered the race to acquire TikTok [Editor's note: the link may be paywalled; alternative source], the popular Chinese-owned short video app that President Donald Trump has vowed to shut down unless it is taken over by a US company by mid-November, people briefed about the matter have said. The tech company co-founded by Larry Ellison had held preliminary talks with TikTok's Chinese owner, ByteDance, and was seriously considering purchasing the app's operations in the US, Canada, Australia and New Zealand, the people said. Oracle was working with a group of US investors that already own a stake in ByteDance, including General Atlantic and Sequoia Capital, the people added.

Microsoft has been the lead contender to buy TikTok since it publicly said in early August that it had held discussions to explore a purchase of the app's US, Canada, Australia and New Zealand businesses. Microsoft has also seriously considered a bid to take over TikTok's global operations beyond the countries it outlined this month, people briefed on the company's thinking have said. The Redmond, Washington-based company is particularly interested in buying TikTok in Europe and India, where the video app has been banned by Narendra Modi, Indian prime minister. ByteDance is opposed to selling any assets beyond those in the US, Canada, Australia and New Zealand, said a person close to the company.

Businesses

Amazon Will Add 3,500 Tech and Corporate Jobs Across Six US Cities (techcrunch.com) 16

Amazon today announced an upcoming hiring spree set to bring 3,500 jobs to a half-dozen U.S. cities. The news is, of course, particularly notable amid a pandemic that has cause many industries to freeze hiring, while unemployment claims have soared across the country. It also finds the company doing that hiring in cities -- many of which have seen citizens looking to move to less densely populated areas. From a report While many businesses have suffered the knock-on effects of COVID-19-related lockdowns, however, Amazon has found continued success. The company's massive e-commerce platform has been deemed an essential service and its AWS platform has taken on an outsized role as the push for businesses to go all online has further accelerated. The new jobs are "corporate and tech" per the company's description, across a number of divisions, including AWS, Alexa, Amazon Advertising, Amazon Fashion, OpsTech and Amazon Fresh. The list of cities includes Dallas, Detroit, Denver, New York Phoenix and San Diego, accounting for around 900,000 square feet of office space in all.
Privacy

Secret Service Paid To Get Americans' Location Data Without a Warrant, Documents Show (gizmodo.com) 68

An anonymous reader quotes a report from Gizmodo: A newly released document shows the U.S. Secret Service went through a controversial social media surveillance company to purchase the location information on American's movements, no warrant necessary. Babel Street is a shadowy organization that offers a product called Locate X that is reportedly used to gather anonymized location data from a host of popular apps that users have unwittingly installed on their phones. When we say "unwittingly," we mean that not everyone is aware that random innocuous apps are often bundling and anonymizing their data to be sold off to the highest bidder.

Back in March, Protocol reported that U.S. Customs and Border Protection had a contract to use Locate X and that sources inside the secretive company described the system's capabilities as allowing a user "to draw a digital fence around an address or area, pinpoint mobile devices that were within that area, and see where else those devices have traveled, going back months." Protocol's sources also said that the Secret Service had used the Locate X system in the course of investigating a large credit card skimming operation. On Monday, Motherboard confirmed the investigation when it published an internal Secret Service document it acquired through a Freedom of Information Act (FOIA) request. (You can view the full document here.) The document covers a relationship between Secret Service and Babel Street from September 28, 2017, to September 27, 2018. In the past, the Secret Service has reportedly used a separate social media surveillance product from Babel Street, and the newly-released document totals fees paid after the addition of the Locate X license as $1,999,394.

Chrome

Chrome 86 Will Warn Users About Insecure Forms On HTTPS Pages (9to5google.com) 37

While there's wide HTTPS adoption today, HTTP content on secure pages still persists. Google has been working to stamp that out, and Chrome is now turning its attention to and warning about insecure forms. "These 'mixed forms' (forms on HTTPS sites that do not submit on HTTPS) are a risk to users' security and privacy," says Google in a blog post. "Information submitted on these forms can be visible to eavesdroppers, allowing malicious parties to read or change sensitive form data." 9to5Google reports: The Google browser today removes the address bar's lock icon from sites with mixed forms. However, this proved to deliver an "unclear" experience that "did not effectively communicate the risks associated with submitting data in insecure forms." Starting in version 86, due to hit stable in October, Chrome will provide a more aggressive warning about insecure forms. Autofill will be disabled, but the built-in password manager will continue to offer "unique passwords." The company argues it's safer than reusing credentials. Next, the form will show red warning text underneath the field: "This form is not secure. Autofill has been turned off. The last measure will throw up a full-page warning communicating the potential risks. It gives users an option to cancel the action, but there will be a "Send anyway" button.
Power

Rolling Blackouts in California Have Power Experts Stumped (nytimes.com) 260

Energy experts are bewildered as to why the manager of California's electric grid called on utilities to cut power to hundreds of thousands of customers over the weekend. "They said that the utilities had plenty of power available and that the blackouts weren't necessary," writes Ivan Penn via The New York Times. From the report: "They set it up like this is a historic event," said Bill Powers, a San Diego engineer who provides expert testimony on utility matters before the state's regulators. "This should not have triggered blackouts." The California Independent System Operator, the nonprofit entity that controls the flow of electricity for 80 percent of California, said it acted after three power plants shut down and wind power production dropped. It also cited a lack of access to electricity from out-of-state sources.

The energy experts noted that the peak electricity use over the weekend fell below peaks in other years, when utilities were able to handle the demand. They also said the operating reserves of power available to the utilities were higher than the 3 percent level where California ISO has traditionally ordered a reduction in electricity use. "It's just misleading to say that it was because it was a hot day," said [David Marcus, an energy consultant and former adviser at the California Energy Commission]. "I think they were being overly cautious." Saturday's peak demand, according to Mr. Marcus, reached 44,947 megawatts, much lower than the 46,797 he saw on Friday. But both of those amounts fell below the peak year for electricity use, 2006, when demand reached 50,270 megawatts, followed by 2017 with 50,116, according to data from California ISO. [...] What happens in the days ahead will continue to test Californians and the electric grid as California ISO forecast electricity demand Monday at near all-time peak levels.

Slashdot Top Deals