AI

The Defense Department Has Produced the First Tools For Catching Deepfakes (technologyreview.com) 45

Fake video clips made with artificial intelligence can also be spotted using AI -- but this may be the beginning of an arms race. From a report: The first forensics tools for catching revenge porn and fake news created with AI have been developed through a program run by the US Defense Department. Forensics experts have rushed to find ways of detecting videos synthesized and manipulated using machine learning because the technology makes it far easier to create convincing fake videos that could be used to sow disinformation or harass people. The most common technique for generating fake videos involves using machine learning to swap one person's face onto another's. The resulting videos, known as "deepfakes," are simple to make, and can be surprisingly realistic. Further tweaks, made by a skilled video editor, can make them seem even more real. Video trickery involves using a machine-learning technique known as generative modeling, which lets a computer learn from real data before producing fake examples that are statistically similar. A recent twist on this involves having two neural networks, known as generative adversarial networks, work together to produce ever more convincing fakes. The tools for catching deepfakes were developed through a program -- run by the US Defense Advanced Research Projects Agency (DARPA) -- called Media Forensics. The program was created to automate existing forensics tools, but has recently turned its attention to AI-made forgery.
Hardware

The Ultra-Pure, Super-Secret Sand That Makes Your Phone Possible (wired.com) 160

The processor that makes your laptop or cell phone work was fabricated using quartz from this obscure Appalachian backwater. From a report: Alex Glover is a recently retired geologist who has spent decades hunting for valuable minerals in the hillsides and hollows of the Appalachian Mountains that surround Spruce Pine, North Carolina. Spruce Pine is not a wealthy place. Its downtown consists of a somnambulant train station across the street from a couple of blocks of two-story brick buildings, including a long-closed movie theater and several empty storefronts. The wooded mountains surrounding it, though, are rich in all kinds of desirable rocks, some valued for their industrial uses, some for their pure prettiness. But it's the mineral in Glover's bag -- snowy white grains, soft as powdered sugar -- that is by far the most important these days. It's quartz, but not just any quartz. Spruce Pine, it turns out, is the source of the purest natural quartz -- a species of pristine sand -- ever found on Earth.

This ultra-elite deposit of silicon dioxide particles plays a key role in manufacturing the silicon used to make computer chips. In fact, there's an excellent chance the chip that makes your laptop or cell phone work was made using sand from this obscure Appalachian backwater. "It's a billion-dollar industry here," Glover says with a hooting laugh. "Can't tell by driving through here. You'd never know it." In the 21st century, sand has become more important than ever, and in more ways than ever. Most of the world's sand grains are composed of quartz, which is a form of silicon dioxide, also known as silica. High-purity silicon dioxide particles are the essential raw materials from which we make computer chips, fiber-optic cables, and other high-tech hardware -- the physical components on which the virtual world runs.

Mozilla

Mozilla Debuts Firefox Extension that Recommends Content Based on Your Browsing Activity (venturebeat.com) 102

Mozilla on Tuesday began testing a Firefox extension that shows you its best guesses for what you want to see on the web. From a report: The Advance web extension is available for anyone from today and can analyze content on current active web pages to recommend related tidbits you may want to "read next" from other websites. It will also surface recommendations based on your recent browsing history in a "for you" section. With the extension installed, you just browse the web as you normally would and the little sidebar will show things that are relevant to what you've been looking at. The extension is powered by Laserlike, a VC-funded, machine learning-powered "interest search engine" that delivers personalized content. As such, Laserlike will receive users' browsing history -- something Mozilla wants people to understand before they install the extension. But the company has also built in some tools to boost control and data transparency.
Government

West Virginia To Introduce Mobile Phone Voting For Midterm Elections (cnn.com) 215

West Virginians serving overseas will be the first in the country to cast federal election ballots using a smartphone app, a move designed to make voting in November's election easier for troops living abroad. But election integrity and computer security experts expressed alarm at the prospect of voting by phone, and one went so far as to call it "a horrific idea." CNN: The state's decision to pioneer mobile voting comes even as the United States grapples with Russian interference in its elections. A recent federal indictment outlined Russia's attempts to hack US voting infrastructure during the 2016 presidential race, and US intelligence agencies have warned of Russian attempts to interfere with the upcoming midterm election. Still, West Virginia Secretary of State Mac Warner and Voatz, the Boston company that developed the app, insist it is secure. Anyone using it must first register by taking a photo of their government-issued identification and a selfie-style video of their face, then upload them via the app. Voatz says its facial recognition software will ensure the photo and video show the same person. Once approved, voters can cast their ballot using the Voatz app.
Operating Systems

Palm-branded Smartphones Could Return This Year (techcrunch.com) 42

Palm's smartphone return appears to still be on track for 2018. From a report: Last year, an executive at TCL confirmed that the dearly departed mobile brand would be making a comeback as part of the smartphone conglomerate's portfolio, and with a little under five months left in the year, the 'PVG100' has hit the FCC and WiFi alliance. The handset was spotted by Android Police, but we don't really have much more to go on than a name and a couple of WiFi bands. As the site notes, however, the absence of 5GHz support leads one to surmise that this won't exactly be a barn-burning flagship. The handset also looks to be running Android 8.1 -- not really a surprise, given that Android Pie is still limited to Pixel and a smattering of other devices.
Security

92 Percent of Enterprises Struggle To Integrate Security Into DevOps (betanews.com) 90

A large majority of organizations are struggling to implement security into their DevOps processes, despite saying they want to do so, according to a new report. From a report: The study commissioned by application security specialist Checkmarx looks at the biggest barriers to securing software today depending on where organizations sit on the DevOps maturity curve. The report finds 96 percent of respondents believe it is 'desirable' or 'highly desirable' for developers to be properly trained on how to produce secure code.

As developers take responsibility for the security of their software, respondents believe it is more important to educate developers and empower them than it is to educate other stakeholders in the organization like ops specialists and security specialists. However, 41 percent agree that defining clear ownership and responsibility in relation to software security remains a big challenge, and just 11 percent say they have adequately addressed the need for developer education. Software security is a boardroom issue according to 57 percent of respondents, it's a matter of business risk.

Security

Let's Encrypt Is Now Officially Trusted by All Major Root Certificates (bleepingcomputer.com) 92

Let's Encrypt has announced that it is now directly trusted by all major root certificates including those from Microsoft, Google, Apple, Mozilla, Oracle, and Blackberry. With this announcement, Let's Encrypt is now directly trusted by all major browsers and operating systems. From a report: While Let's Encrypt has already been trusted by almost all browsers, it was done so through intermediate certificate that were cross-signed by IdenTrust. As IdenTrust was directly trusted by all major browser vendors and operating systems, it also allowed Let's Encrypt to be trusted as well. With Let's Encrypt now being directly trusted, if there is ever a problem with IdenTrust and they themselves become untrusted, Let's Encrypt users will still be able to function properly.
The Military

Pentagon Restricts Use of Location-Logging Fitness Trackers (cnn.com) 32

In the beginning of the year, Strava released a data visualization map that showed all the activity tracked by users of its app. The map was detailed enough to potentially give away extremely sensitive information about military personnel on active service in locations across the world. After reviewing their GPS policies, the Pentagon is banning soldiers and other personnel at sensitive bases and warzone areas from using location features on fitness trackers and other devices. Engadget reports: The Department of Defense is not issuing an outright ban on GPS devices and apps, but declared that the location features must be turned off in certain areas. "These geolocation capabilities can expose personal information, locations, routines, and numbers of DOD personnel, and potentially create unintended security consequences and increased risk to the joint force and mission," a memo obtained by the Associated Press said. It's up to ranking officers in less-sensitive areas to decide whether their charges can use GPS functions, based on the threat level in that location. The Defense Department will also provide training on the risks that fitness trackers bring.
Piracy

BBC Wants Microsoft To Expose 'Doctor Who' Leaker (torrentfreak.com) 219

Last month, the BBC headed to court to track down the person who leaked an incomplete scene featuring Jodie Whittaker's Thirteenth Doctor. New court documents suggest that the British broadcaster has yet to find the perpetrator, and is hoping Microsoft can help. At a federal court in Washington, the BBC requested a DMCA subpoena targeted at a OneDriver user who shared the infringing material online late June. TorrentFreak reports: In an effort to track down the source of the leak the BBC has taken the matter to the U.S. courts. Last month it obtained a DMCA subpoena from a California federal court, ordering the forum tool Tapatalk to identify the source of an infringing post. Whether this resulted in any useful information is unknown, but a few days ago it became clear that BBC is still investigating the matter. In a separate effort, BBC Studios have filed a request for a DMCA subpoena at a Federal court in Washington. This time it's directed at Microsoft. According to the BBC, a user of Microsoft's OneDrive stored and shared a copy of the leaked file, titled "IMG_ l563.TRIM.MOV."

"The infringing material includes, without limitation, an unauthorized copy of copyrighted video content from Season 11, Episode 1 of Doctor Who, for which BBC Worldwide Limited t/a BBC Studios (Distribution) is the exclusive licensee," the BBC writes. According to the BBC, the footage in question was stolen from the studio. Through the subpoena, the company hopes to find out more about the source of this leak, to prevent similar situations going forward. It asks Microsoft to hand over any relevant information that can help to identify the account holder who uploaded the video, which was added to OneDrive back in June. This includes "any name, account name, address, telephone number, email address, birth date, profile photo, device information, browser information, location information, information from others (e.g., Facebook or Google+) and time posted."

Communications

SpaceX Successfully Launches Its Used Block 5 Rocket (theverge.com) 85

SpaceX successfully launched one of its used Falcon 9 rockets from Cape Canaveral tonight at 1:18AM ET, deploying the Merah Putih communications satellite just over half an hour later. This marks the first time that SpaceX reused one of its new powerful Block 5 boosters -- the final upgrade of the Falcon 9 that is supposed to be able to go to space and back up to 100 times. "The Falcon 9's first stage booster also performed another successful landing on one of the company's drone ships in the Atlantic, becoming the 28th booster that SpaceX has ever recorded," The Verge adds. From the report: For this mission, SpaceX is using the very first Falcon 9 Block 5 rocket it's flown, a vehicle that sent up a large communications satellite for Bangladesh in May from Florida. The vehicle landed on one of SpaceX's drone ships after the flight, and the company has since done inspection and refurbishment on the vehicle over the last three months to get it ready for flight again. Eventually, SpaceX hopes to do as little refurbishment on these Block 5 vehicles as possible, if any at all. Limiting the amount of inspection and tweaking needed between re-flights could significantly up the cost savings that SpaceX gets from reusing its rockets. Less money is needed if fewer people and materials are needed to turn around the rockets each time. Ultimately, SpaceX hopes to fly each Block 5 vehicle a total of 10 times before any refurbishment is needed. As for the satellite, it will reportedly provide telecommunications services to parts of Indonesia and South Asia.
Earth

Planet At Risk of Heading Towards Irreversible 'Hothouse Earth' State (vice.com) 1159

An anonymous reader quotes a report from Motherboard: What we do in the next 10-20 years will determine whether our planet remains hospitable to human life or slides down an irreversible path to what scientists in a major new study call "Hothouse Earth" conditions. Hothouse Earth is an apocalyptic nightmare where the global average temperatures is 4 to 5 degrees Celsius higher (with regions like the Arctic averaging 10 degrees C higher) than today, according to the study, "Trajectories of the Earth System in the Anthropocene," published Monday in the Proceedings of the National Academy of Sciences. Sea levels would eventually be 10-60 meters higher as much of the world's ice melts. In these conditions, large parts of the Earth would be uninhabitable. Cutting carbon emissions to limit climate change to 2 degrees C, as proposed in the Paris climate agreement, won't be enough to avoid a "Hothouse Earth," said co-author Johan Rockstrom, executive director of Stockholm Resilience Centre. The reality is that global temperatures aren't driven by human emissions of carbon alone, says Rockstrom -- natural systems such as forests and oceans also play a major role. If global warming reaches 2 degrees C it could trigger a feedback, or "tipping element," in one or more of our natural systems and drive further warming, Rockstrom told Motherboard. To put that into perspective, the recent heat waves and wildfires are being linked to climate change that has raised the global average temperature 1 degree C. The researchers conclude the study on a more uplifting note, saying: "We have the knowledge and ability to act. This is within our control." There are three main areas of action that need to be taken within the next two decades. "The top priority in the coming decade is to aggressively cut carbon emissions and decarbonize our energy systems as quickly as possible," reports Motherboard. "The second priority is to halt deforestation and conversion of nature areas into agricultural production. Forests and other natural areas currently absorb 25 percent of our carbon emissions and this needs to grow." The third action is "to continue to develop technologies to pull carbon from the atmosphere and safely store it for thousands of years." While this last action can be costly, we're starting to see some companies give it a try. A startup called Climeworks recently inaugurated the first system that captures CO2 from the air and converts the emissions into stone, thus ensuring they don't escape back into the atmosphere for the next millions of years.
Botnet

Researchers Discover Large Twitter Botnet Pushing Ethereum Scam (techcrunch.com) 43

Trailrunner7 writes: Twitter has something of a bot problem. Anyone who uses the platform on even an occasional basis likely could point out automated accounts without much trouble. But detecting bots at scale is a much more complex problem, one that a pair of security researchers decided to tackle by building their own classifier and analyzing the characteristics and behavior of 88 million Twitter accounts. Using a machine learning model with a set of 20 distinct characteristics such as the number of tweets relative to the age of the account and the speed of replies and retweets, the classifier is able to detect bots with about 98 percent accuracy. The tool outputs a probability that a given account is a bot, with anything above 50 percent likely being a bot.

During their research, conducted from May through July, Jordan Wright and Olabode Anise of Duo Security discovered an organized network of more than 15,000 bots that was being used to promote a cryptocurrency scam. The botnet, which is still partially active, spoofs many legitimate accounts and even took over some verified accounts as part of a scheme designed to trick victims into sending small amounts of the cryptocurrency Ethereum to a specific address. Unlike most botnets, the Ethereum network has a hierarchical structure, with a division of labor among the bots. Usually, each bot in a network performs the same task, whether that's launching a DDoS attack or mining Bitcoin on a compromised machine. But the Ethereum botnet had clusters of bots with a three-tier organization. Some of the bots published the scam tweets, while others amplified those tweets or served as hub accounts for others to follow. Wright and Anise mapped the social media connections between the various accounts and looked at which accounts followed which others to create a better picture of the network. Anise and Wright will discuss the results of their research during a talk at the Black Hat USA conference on Wednesday and will release their detection tool as an open source project that day, too.

Movies

MoviePass Limiting Subscribers To 3 Movies Per Month (npr.org) 105

nolaguy shares a report from NPR: Movie theater subscription service MoviePass will not be raising prices, as it had announced last week, but will instead be capping the number of times that subscribers can visit movie theaters. For $9.95 per month, MoviePass subscribers used to be able to see a movie in theaters every day, if they so chose. Beginning on August 15, the service will instead provide three movies per month. The change replaces a previously announced plan to raise prices to $14.95 a month. The beleaguered movie theater subscription company is also canceling two other recent changes -- "peak pricing" surcharges for popular movies and a ticket verification process -- that were intended to stop the company from bleeding money.
Microsoft

Microsoft Won't Force You To Use the New Skype Just Yet (neowin.net) 94

A few weeks ago, Microsoft launched Skype version 8.0 to replace Skype classic, or version 7. The company initially said that Skype classic would stop working on September 1st, but today, it extended the deadline and said it would continue to support the older application for the time being. Neowin reports: Spotted by Brad Sams of Thurrott.com, the information was posted as an update to a support forum that originally said when Skype v7 would be killed off. The update says the following: "Based on customer feedback, we are extending support for Skype 7 (Skype classic) for some time. Our customers can continue to use Skype classic until then. Thanks for all your comments - we are listening. We are working to bring all the features you've asked for into Skype 8. Watch this space." Microsoft didn't provide a new end of life date for Skype v7, but there's no doubt that it's still coming. Eventually, you'll have to move to Skype v8, or the UWP app if you're on Windows 10.
Security

FCC Admits It Was Never Actually Hacked (techcrunch.com) 214

An anonymous reader quotes a report from TechCrunch: The FCC has come clean on the fact that a purported hack of its comment system last year never actually took place, after a report from its inspector general found a lack of evidence supporting the idea. Chairman Ajit Pai blamed the former chief information officer and the Obama administration for providing "inaccurate information about this incident to me, my office, Congress, and the American people." It was so galling to everyone looking for answers that the GAO was officially asked to look into it. The letter requesting the office's help at the time complained that the FCC had "not released any records or documentation that would allow for confirmation that an attack occurred, that it was effectively dealt with, and that the FCC has begun to institute measures to thwart future attacks and ensure the security of its systems." That investigation is still going on, but one conducted by the FCC's own OIG resulted in the report Pai cites.

Pai's statement was issued before the OIG publicized its report, as one does when a report is imminent that essentially says your agency has been clueless at best or deliberately untruthful at worst, and for more than a year. To be clear, the report is still unpublished, though its broader conclusions are clear from Pai's statement. In it he slathers Bray with the partisan brush and asserts that the report exonerates his office: "I am deeply disappointed that the FCC's former [CIO], who was hired by the prior Administration and is no longer with the Commission, provided inaccurate information about this incident to me, my office, Congress, and the American people. This is completely unacceptable. I'm also disappointed that some working under the former CIO apparently either disagreed with the information that he was presenting or had questions about it, yet didn't feel comfortable communicating their concerns to me or my office. On the other hand, I'm pleased that this report debunks the conspiracy theory that my office or I had any knowledge that the information provided by the former CIO was inaccurate and was allowing that inaccurate information to be disseminated for political purposes."
UPDATE: The complete Office of Inspector General report has been released, refuting claims that a cyberattack was responsible for disrupting the FCC's comment system last year.

Slashdot Top Deals