Earth

The World is Running Out of Sand, and People Are Dying as a Result (medium.com) 180

You may be thinking: But sand is everywhere, there are whole deserts filled with the stuff. The sand in a desert, though, is useless as a construction material. The grains are out in the open and blow around for thousands of years. From a report: This rounds them off until they become useless as building blocks. Imagine trying to make a building with golf balls. In order to build, sand with angular edges must be used. The preferential type is the kind found in a river bed, sea, or beach. The fact that desert sand is useless makes for some unexpected situations. Despite being surrounded by endless miles of sand, the tallest building in the world, the Burj Khalifa in Dubai, was built with sand imported from Australia. Dubai also imports sand for its beaches from Australia. Apparently desert sand doesn't do well in a beach atmosphere either. Sand also regenerates slowly. It takes thousands upon thousands of years for rock and sediment to break down into the usable grains we all rely on.

The world has seen a construction boom in recent years. The base that boom is built on, quite literally, is concrete. The United Nations estimates that the world consumes more than 40 billion tons of building aggregate -- sand, gravel, and crushed stone -- each year. Some estimates predict consumption will top 50 billion tons by next year, with China alone gobbling up much of the world's concrete supply as it undergoes a massive urbanization. According to data from the U.S. Geological Survey, between 2011 and 2013 China used more concrete than the U.S. used throughout the entire 20th century. Other parts of Asia, such as India, are rapidly expanding as well. The urbanization driving this construction boom, and increasing reliance on concrete, shows no signs of slowing. By 2030 the U.N. expects 60 percent of the world's population to live in urban areas.

[...] One of the prime issues with sand is that it's heavy. Heavy items incur large transportation costs, especially over a long distance. The scarcity and high prices attract the attention of criminals. Why go to a legal mining area when sand can be extracted for next to nothing elsewhere? "Sand mafias" are groups of criminals that illegally dredge sand from areas where extraction is prohibited. Since they're not following laws, all environmental protocols are ignored. Often rivers are illegally mined, destroying the habitat for fish and fishermen. Sometimes land from private villages is even taken over by these mafias. If they're confronted, violence often results. And according to a 2015 Wired story on sand mafias in India, police are typically of little help: "The conventional wisdom says that many local authorities accept bribes from the sand miners to stay out of their business -- and not infrequently, are involved in the business themselves."

Businesses

China's Alibaba Sets New Singles' Day Sales Record With More Than Eight Hours To Go in 24-Hour Shopping Festival (scmp.com) 34

Alibaba Group surpassed last year's Singles' Day record with more than eight hours to go before the end of the 24-hour shopping festival, cementing its position as the world's biggest retail event and assuaging concerns that Chinese consumer sentiment is softening. From a report: The gross merchandise value surpassed last year's tally of 168.2 billion yuan ($25.3 billion) at 3:49 pm on Sunday. Also known as Double 11, the shopping extravaganza will draw to a close at midnight. Consumers spent a total of 168.5 billion yuan (US$24.3 billion) as of 3:53 pm. Sales were helped by the participation of Alibaba's Southeast Asia unit Lazada, as well as subsidiaries Ele.me, Koubei, supermarket chain Hema and other business units. The total gross merchandise volume (GMV) for this year's Singles' Day -- or the value of total transactions on the platform -- is keenly watched as a barometer of consumer spending and retail health in the world's second-biggest economy.
Facebook

Can Facebook Keep Large-Scale Misinformation From the Free World? (sfgate.com) 189

You can have a disaster-free Election Day in the social media age, writes New York Times columnist Kevin Roose, "but it turns out that it takes constant vigilance from law enforcement agencies, academic researchers and digital security experts for months on end." It takes an ad hoc "war room" at Facebook headquarters with dozens of staff members working round-the-clock shifts. It takes hordes of journalists and fact checkers willing to police the service for false news stories and hoaxes so that they can be contained before spreading to millions. And even if you avoid major problems from bad actors domestically, you might still need to disclose, as Facebook did late Tuesday night, that you kicked off yet another group of what appeared to be Kremlin-linked trolls...

Most days, digging up large-scale misinformation on Facebook was as easy as finding baby photos or birthday greetings... Facebook was generally responsive to these problems after they were publicly called out. But its scale means that even people who work there are often in the dark... Other days, combing through Facebook falsehoods has felt like watching a nation poison itself in slow motion. A recent study by the Oxford Internet Institute, a department at the University of Oxford, found that 25 percent of all election-related content shared on Facebook and Twitter during the midterm election season could be classified as "junk news"...

Facebook has framed its struggle as an "arms race" between itself and the bad actors trying to exploit its services. But that mischaracterizes the nature of the problem. This is not two sovereign countries locked in battle, or an intelligence agency trying to stop a nefarious foreign plot. This is a rich and successful corporation that built a giant machine to convert attention into advertising revenue, made billions of dollars by letting that machine run with limited oversight, and is now frantically trying to clean up the mess that has resulted... It's worth asking, over the long term, why a single American company is in the position of protecting free and fair elections all over the world.

Despite whatever progress has been made, the article complains that "It took sustained pressure from lawmakers, regulators, researchers, journalists, employees, investors and users to force the company to pay more attention to misinformation and threats of election interference. Facebook has shown, time and again, that it behaves responsibly only when placed under a well-lit microscope.

"So as our collective attention fades from the midterms, it seems certain that outsiders will need to continue to hold the company accountable, and push it to do more to safeguard its users -- in every country, during every election season -- from a flood of lies and manipulation."
Security

Credit Card Chips Have Failed to Halt Fraud (So Far) (fortune.com) 229

An anonymous reader quotes Fortune: New chip-enabled credit cards, which were rolled out to U.S. consumers starting in 2015, were supposed to put an end to rampant credit card fraud. So much for that. A new report from the research firm Gemini Advisory has found that, of more than 60 million cases of credit card theft in the last 12 months, a whopping 93% of the stolen cards had the new chip technology...

In theory, EMV should reduce fraud because every card transaction requires an encrypted connection between the chip card and the merchant's point-of-sale terminal... But while the EMV standard is supposed to ensure the card data cannot be captured, many merchants are failing to properly configure their systems, according to a Gemini Advisory executive who spoke with Fortune... The upshot is that criminals have been able to insert themselves into the transaction data steam, either by hacking into merchant networks or installing skimmer devices in order to capture card information... The report concludes by noting that big merchants have begun to tighten up their implementation of the EMV system, which will make them less of a target. Instead, criminals are likely to begin focusing on smaller businesses.

The report estimates that in just the last twelve months, 41.6 million records have been stolen from chip-enabled cards.
Social Networks

A 'Clippy'-Style Chatbot -- and Other Creepy Online Dating Innovations (yahoo.com) 47

An anonymous reader quotes Yahoo Finance: The dating site eharmony is hoping to launch a chatbot to stop people from ghosting, or cutting off communication with potential matches, CEO Grant Langston exclusively tells Yahoo Finance. The would-be feature, which eharmony has yet to start development on, would pop up in the user interface after an online conversation with another user drops off after several days or weeks. The dating bot could analyze information on both users' dating profiles and recommend they reinitiate contact by prompting them to "Say something" or suggesting something more helpful... . "It's astounding really how many people need help. We think we can do that in an automated way..."

Langston acknowledges the business has a lot to troubleshoot with the feature before it eventually rolls it out, including addressing possible user concerns around user privacy. While having a feature like the date bot could hypothetically increase the odds of a user scoring that first date, it could also unnerve some other users wondering how their prospective suitor knew to ask about their favorite musician, movie or music to begin with. Such concerns could theoretically call for privacy options regulating what kind of profile information the bot can grab and serve up as an icebreaker. The dating site could also decide to generally reign in what the dating bot suggests based on user testing. "Just because you can doesn't necessarily mean you should do," adds Langston.

Meanwhile, a Michigan-based startup has launched what one alternative newsweekly describes as a "Yelp for humans" -- a new browser extension that syncs with a user's pre-existing dating profile on sites like Match.com, OkCupid, PlentyOf Fish, eHarmony, Zoosk or Badoo. "Once installed, a user can leave anonymous comments regarding someone's profile based on dates or interactions gone wrong and those comments can be viewed by other DateAha! users to better inform whether or not the person is a total creep."

And of course, Facebook is testing a new dating app in two more countries, People reports. In order to use the new online dating service, Facebook users will be tasked with creating a new profile that will exist separately from the one that all of your friends and family can see... The dating service will send you suggested matches based "on your preferences, interests, and things you do on Facebook," but the app won't try to make a love connection with any of your Facebook friends (or anybody you have blocked), Facebook promises... You will also have the ability to block or hide anybody -- including specific friends of friends -- from your suggested matches.
Government

Were Russian Hackers Deterred From Interfering In America's Election? (omaha.com) 240

"Despite probing and trolling, a Russian cyberattack is the dog that did not bark in Tuesday's midterm elections," writes national security columnist Eli Lake. This is the assessment of the Department of Homeland Security, which says there were no signs of a coordinated campaign to disrupt U.S. voting. This welcome news raises a relevant and important question: Were cyber adversaries actually deterred from infiltrating voter databases and changing election results...?

In September the White House unveiled a new policy aimed at deterring Russia, China, Iran and North Korea from hacking U.S. computer networks in general and the midterms in particular. National security adviser John Bolton acknowledged as much last week when he said the U.S. government was undertaking "offensive cyber operations" aimed at "defending the integrity of our electoral process." There aren't many details. Reportedly this entailed sending texts, pop-ups, emails and direct messages warning Russian trolls and military hackers not to disrupt the midterms. U.S. officials tell me much more is going on that remains classified. It is part of a new approach from the Trump administration that purports to unleash U.S. Cyber Command to hack the hackers back, to fight them in their networks as opposed to America's.

Bolton has said the policy reverses previous restrictions on military hackers to disrupt the networks from which rival powers attack the U.S. Sometimes this is called "persistent engagement" or "defend forward." And it represents a shift in the broader U.S. approach to engaging adversaries in cyberspace.... The difference now is that America's cyber warriors will routinely try to disrupt cyberattacks before they begin... The object of cyberdeterrence is not to get an adversary to never use cyberweapons. It's to prevent attacks of certain critical systems such as voter registration databases, electrical grids and missile command-and-control systems. The theory, at least, is to force adversaries to devote resources they would otherwise use to attack the U.S. to better secure their own networks.

Jason Healey, a historian of cyber conflicts at Columbia University's School for International and Public Affairs, asks "How much of cyberspace will survive the war?" warning that "persistent engagement" could lead to a dangerous miscalculation by an adversarial nation-state -- or even worse, a spiral of escalation, with other state's following America's lead, changing the open Internet into more of a battleground.
Bitcoin

Principal Fired For Using School's Computer Room To Mine Cryptocurrency (bbc.com) 54

"A Chinese headmaster has been fired after a secret stack of crypto-currency mining machines was found connected to his school's electricity supply," writes the BBC. An anonymous reader quotes their report: Teachers at the school in Hunan became suspicious of a whirring noise that continued day and night, local media report. This led to the discovery of the machines, which were mining the crypto-currency Ethereum. They racked up an electricity bill of 14,700 yuan [£1,600, or about $2,100]...

The headmaster had originally spent 10,000 yuan on a single machine for use at home, but allegedly decided to move it to the school after he saw how much electricity it consumed... A total of eight mining machines were installed in the Hunan school's computer room between summer 2017 and summer 2018... The deputy headmaster also became involved in the scheme and allegedly acquired a ninth machine for himself in January, which was also installed at the school. The computer network in the building became overloaded as a result of the mining activity, according to reports, and this "interfered" with teaching.

All the money earned through the mining operation has now been claimed by the local official responsible for "discipline inspection."
Businesses

Tesla Worker Charged With Embezzling More Than $9 Million (siliconvalley.com) 55

An anonymous reader quotes the Bay Area Newsgroup: A former Tesla global supply manager was indicted Thursday by federal prosecutors alleging he embezzled more than $9 million from the Palo Alto electric car maker. Salil Parulekar, 32, is charged with felony wire fraud and aggravated identity theft. Parulekar oversaw Tesla's dealings with certain auto parts and services vendors, and used that position to divert to a German auto parts company $9.3 million in payments intended for a Taiwanese supplier, according to the indictment. ... Parulekar, who was living in San Jose and working for Tesla in 2016 and 2017, falsified invoices, created fake accounts-payable documents, and impersonated an employee of the Taiwanese supplier to trick Tesla's accounts-payable department into switching the bank account information of the Taiwanese and German companies, the indictment alleged.

That Taiwanese firm's complaints to Tesla about missing money went to Parulekar, who responded by sending fake documents purporting to show the payments were made, the indictment claimed.

Transportation

VW Plans A $ 22K Electric Car To Compete With Tesla, Transition From Combustion Engines (reuters.com) 317

An anonymous reader quotes Reuters: Volkswagen intends to sell electric cars for less than 20,000 euros ($22,836) and protect German jobs by converting three factories to make Tesla rivals, a source familiar with the plans said... Plans for VW's electric car, known as "MEB entry" and with a production volume of 200,000 vehicles, are due to be discussed at a supervisory board meeting on Nov. 16, the source said... The November 16 strategy meeting will discuss Volkswagen's transformation plan to shift from being Europe's largest maker of combustion engine vehicles into a mass producer of electric cars, another source familiar with the deliberations said.

VW's strategy shift comes as cities start to ban diesel engine vehicles, forcing carmakers to think of new ways to safeguard 600,000 German industrial jobs, of which 436,000 are at car companies and their suppliers.... The shift from combustion engines to electric cars would also cost 14,000 jobs at VW by 2020 as it takes less time to build an electric car than a conventional one and because jobs will shift overseas to battery manufacturers.

Facebook

Only 22% of Americans Now Trust Facebook's Handling of Personal Info (fortune.com) 75

An anonymous reader quotes Fortune: Facebook is the least trustworthy of all major tech companies when it comes to safeguarding user data, according to a new national poll conducted for Fortune, highlighting the major challenges the company faces following a series of recent privacy blunders. Only 22% of Americans said that they trust Facebook with their personal information, far less than Amazon (49%), Google (41%), Microsoft (40%), and Apple (39%)....

In question after question, respondents ranked the company last in terms of leadership, ethics, trust, and image... Public mistrust extended to Zuckerberg, Facebook's public face during its privacy crisis and who once said that Facebook has "a responsibility to protect your information, If we can't, we don't deserve it." The company subsequently fell victim to a hack but continued operating as usual, including debuting a video-conferencing device intended to be used in people's living rooms or kitchens and that further extends Facebook's reach into more areas outside of personal computers and smartphones. Only 59% of respondents said they were "at least somewhat confident" in Zuckerberg's leadership in the ethical use of data and privacy information, ranking him last among four other tech CEOS...

As for Facebook, the social networking giant may have a difficult time regaining public trust because of its repeated problems. Consumers are more likely to forgive a company if they believe a problem was an aberration rather than a systemic failure by its leadership, Harris Poll CEO John Gerzema said.

The article concludes that "For now, the public isn't in a forgiving mood when it comes to Facebook and Zuckerberg."
Space

Did We Miss an Interstellar Comet Four Years Ago? (arxiv.org) 59

Long-time Slashdot reader RockDoctor writes: A paper published on Arxiv last week reports on a project to redetermine the "orbits of long period comets... We recently attempted to check, whether the assumption of a parabolic orbit for hundreds of comets discovered after 1950 is fully justified in all cases." The full work by Królikowska & Dybczynski remains in preparation (which is perfectly normal), but this intriguing result deserved early attention.

During this research we found an interesting case of the comet C/2014 W10 PANSTARRS.

(that's the 10th reported comet in fortnight W of year 2014, source : the PANSTARRS team)

After discovery on 2014-11-25, fourteen observations were made over three days, giving a first-estimate orbit with an eccentricity of 0.6039453. So far, so boring — as the temporary designation suggests, these get found on most days. But that orbit is subject to uncertainty so some more measurements were made on 2014-12-22 from a different observatory. When all of the data is considered, it becomes impossible to clearly assign an orbit to this object (this is possible if, for example, there is a fragmentation of the object between observations), but many of the solutions which can be obtained have a hyperbolic orbit — that is, the object is extra-solar.

If correct, this "post-covery" would double the size of the catalogue of interstellar objects known.

Unfortunately, the quality of the original data remains poor — estimates of the orbital eccentricity vary between 1.22 and 1.65 — which is in contrast to the prompt recognition and intense observation campaign for 'Oumuamua. The report's main conclusion is that

Our main purpose is to show that similar cases should be treated in future with greater care by more reliable preliminary orbit determination and alerting observers about the importance of the object to initiate more follow-up observations.

Which is exactly what happened with 'Oumuamua.

Oracle

Disgruntled Security Researcher Publishes Major VirtualBox 0-Day Exploit (zdnet.com) 130

"A Russian security researcher has published details about a zero-day vulnerability affecting VirtualBox, an Oracle software application for running virtual machines," reports ZDNet. According to a text file uploaded on GitHub, Saint Petersburg-based researcher Sergey Zelenyuk has found a chain of bugs that can allow malicious code to escape the VirtualBox virtual machine (the guest OS) and execute on the underlying (host) operating system. Once out of the VirtualBox VM, the malicious code runs in the OS' limited userspace (kernel ring 3), but Zelenyuk said that attackers can use many of the already known privilege escalation bugs to gain kernel-level access (ring 0). "The exploit is 100% reliable," Zelenyuk said. "It means it either works always or never because of mismatched binaries or other, more subtle reasons I didn't account."

The Russian researcher says the zero-day affects all current VirtualBox releases, works regardless of the host or guest operating system the user is running, and is reliable against the default configuration of newly created VMs. Besides a detailed write-up of the entire exploit chain, Zelenyuk has also published video proof, showing the zero-day in action against an Ubuntu VM running inside VirtualBox on an Ubuntu host OS.

Long-time Slashdot reader Artem Tashkinov warns that the exploit utilizes "bugs in the data link layer of the default E1000 network interface adapter which makes this vulnerability critical for everyone who uses virtualization to run untrusted code." According to ZDNet, the same security researcher "found and reported a similar issue in mid-2017, which Oracle took over 15 months to fix."

"This lengthy and drawn-out patching process appears to have angered Zelenyuk, who instead of reporting this bug to Oracle, has decided to publish details online without notifying the vendor."
Businesses

Apple Blocks Linux From Booting On New Hardware With T2 Security Chip (phoronix.com) 373

AmiMoJo writes: Apple's new-generation Macs come with a new so-called Apple T2 security chip that's supposed to provide a secure enclave co-processor responsible for powering a series of security features, including Touch ID. At the same time, this security chip enables the secure boot feature on Apple's computers, and by the looks of things, it's also responsible for a series of new restrictions that Linux users aren't going to like.

The issue seems to be that Apple has included security certificates for its own and Microsoft's operating systems (to allow running Windows via Bootcamp), but not for the certificate that was provided for systems such as Linux. Disabling Secure Boot can overcome this, but also disables access to the machine's internal storage, making installation of Linux impossible.

AI

AI Researchers Predict Alzheimer's Years Before Diagnosis (sciencedaily.com) 43

Slashdot reader pgmrdlm quotes Science Daily: Timely diagnosis of Alzheimer's disease is extremely important, as treatments and interventions are more effective early in the course of the disease. However, early diagnosis has proven to be challenging. Research has linked the disease process to changes in metabolism, as shown by glucose uptake in certain regions of the brain, but these changes can be difficult to recognize... Researchers trained [a] deep learning algorithm on a special imaging technology known as 18-F-fluorodeoxyglucose positron emission tomography (FDG-PET). In an FDG-PET scan, FDG, a radioactive glucose compound, is injected into the blood. PET scans can then measure the uptake of FDG in brain cells, an indicator of metabolic activity.

The researchers had access to data from the Alzheimer's Disease Neuroimaging Initiative (ADNI), a major multi-site study focused on clinical trials to improve prevention and treatment of this disease. The ADNI dataset included more than 2,100 FDG-PET brain images from 1,002 patients. Researchers trained the deep learning algorithm on 90 percent of the dataset and then tested it on the remaining 10 percent of the dataset. Through deep learning, the algorithm was able to teach itself metabolic patterns that corresponded to Alzheimer's disease. Finally, the researchers tested the algorithm on an independent set of 40 imaging exams from 40 patients that it had never studied. The algorithm achieved 100 percent sensitivity at detecting the disease an average of more than six years prior to the final diagnosis.

"We were very pleased with the algorithm's performance," Dr. Sohn said. "It was able to predict every single case that advanced to Alzheimer's disease

IBM

What Does It Take To Keep a Classic IBM 1401 Mainframe Alive? (ieee.org) 60

"Think your vintage computer hardware is old?" writes long-time Slashdot reader corrosive_nf. "Ken Shirriff, Robert Garne, and their associates probably have you beat.

"The IBM 1401 was introduced in 1959, and these guys are keeping one alive in a computer museum... [T]he volunteers have to go digging through historical archives and do some detective work to figure out solutions to pretty much anything!" Many things that we take for granted are done very differently in old computers. For instance, the IBM 1401 uses 6-bit characters, not bytes. It used decimal memory addressing, not binary. It's also interesting how much people could accomplish with limited resources, running a Fortran compiler on the 1401 with just 8K of memory. Finally, working on the 1401 has given them a deeper understanding of how computers really work. It's not a black box; you can see the individual transistors that are performing operations and each ferrite core that stores a bit.
"It's a way of keeping history alive," says one of the volunteers at Silicon Valley's Computer History museum. "For museum visitors, seeing the IBM 1401 in operation gives them a feeling for what computers were like in the 1960s, the full experience of punching data onto cards and then seeing and hearing the system processing cards....

"So far, things are breaking slowly enough that we can keep up, so it's more of a challenge than an annoyance."

Slashdot Top Deals