×
Transportation

Most People Now Prefer Shopping Online For Cars Than Shopping In-Person (autoblog.com) 129

According to a survey of 501 people conducted by insurance company Progressive, most people prefer the process of buying a car online than at dealerships. Autoblog reports: Based on the 251 people who completed a transaction entirely online or through a dealer web site, and the 250 who did solely face-to-face business, there are two big takeaways. The first is that online shopping, still a small percentage of overall car sales, is growing rapidly in acceptance and actual transactions. [...] The second takeaway is that millennials are a major part of the online sales growth.

Overall, though, online shoppers expressed more joy with the process than showroom floor shoppers. Compared to 78% of buyers highly satisfied with buying a car online, only 58% of in-person shoppers registered the same pleasure. That carried through to trade-ins and financing as well. Eighty percent of online shoppers were highly satisfied with the trade-in process, versus 57% of dealership visitors; 70% of online shoppers gave the highest marks to the financing process as opposed to 53% of guests asked to "Step into the office" and wait while the salesperson conferred with the finance manager.

Television

Two Skydiving Pilots Try to Change Planes in Mid-Air (yahoo.com) 102

Streaming right now on Hulu: a three-hour live special in which two members of something called the "Red Bull Air Force" try to make aviation history, reports People: On Sunday, April 24, Aikins and Farrington will try to switch planes mid-air in a stunt at Sawtooth Airport in Eloy, Arizona, that can be seen exclusively on Hulu, according to a press release from Red Bull. The planes will be "completely empty" and facing the ground when Luke Aikins and Andy Farrington attempt the daring switch, which will air during a three-hour livestream event.

To complete the feat, Aikins and Farrington will fly a pair of Cessna 182 single-seat aircraft up to 14,000 feet before putting them into a vertical nosedive and jumping out, with the goal of skydiving into each other's planes.

The cousins will stop the planes' engines and aim them toward the ground as they complete the stunt. A custom airbrake with the ability to hold the planes in a controlled-descent terminal velocity speed of 140 mph will also be utilized to complete the trick. After catching up to the opposing stuntman's plane, Aikins and Farrington will enter the cockpits and turn the planes back on as normal, piloting them to land.

Aikins is an experienced skydiver, having completed more than 21,000 jumps throughout his career. Farrington, meanwhile, has completed 27,000 jumps.

"I call it more calculated than crazy," Aikins says in an interview with the web site Complex. "We work really hard to make sure that everything's going to be okay. We don't flip a coin and fingers crossed and hope it all works out. We mitigate the risk down to something that's acceptable and what's acceptable to me."
GNU is Not Unix

Richard Stallman Speaks on Cryptocurrency, Blockchain, GNU Taler, and Encryption (libreplanet.org) 96

During a 92-minute presentation Wednesday on the state of the free software movement, Richard Stallman spoke at length on a wide variety of topics, including the need for freedom-respecting package systems.

But Stallman also shared his deepest thoughts on a topic dear to the hearts of Slashdot readers: privacy and currency: I won't order from online stores, because I can't pay them . For one thing, the payment services require running non-free JavaScript... [And] to pay remotely you've got to do it by credit card, and that's tracking people, and I want to resist tracking too.... This is a really serious problem for society, that you can't order things remotely anonymously.

But GNU Taler is part of the path to fixing that. You'll be able to get a Taler token from your bank, or a whole bunch of Taler tokens, and then you'll be able to use those to pay anonymously.

Then if the store can send the thing you bought to a delivery box in your neighborhood, the store doesn't ever have to know who you are.

But there's another issue Stallman touched on earlier in his talk: There is a proposed U.S. law called KOSA which would require mandatory age-verification of users -- which means mandatory identification of users, which is likely to mean via face recognition. And it would be in every commercial software application or electronic service that connects to the internet.... [It's] supposedly for protecting children. That's one of the favorite excuses for surveillance and repression: to protect the children. Whether it would actually protect anyone is dubious, but they hope that won't actually be checked.... You can always propose a completely useless method that will repress everyone....
So instead, Stallman suggests that age verification could be handled by.... GNU Taler: Suppose there's some sort of service which charges money, or even a tiny amount of money, and is only for people over 16, or people over 18 or whatever it is. Well, you could get from your bank a Taler token that says the person using this token is over 16. This bank has verified that.... So then the site only needs to insist on a 16-or-over Taler token, and your age is verified, but the site has no idea who you are.

Unfortunately that won't help if user-identifying age-tracking systems are legislated now. The code of Taler works, but it's still being integrated with a bank so that people could actually start to use it with real businesses.

Read on for Slashdot's report on Stallman's remarks on cryptocurrencies and encryption, or jump ahead to...
Graphics

Razer's First Linux Laptop Called 'Sexy' - But It's Not for Gamers (theverge.com) 45

A headline at Hot Hardware calls it "a sexy Linux laptop with deep learning chops... being pitched as the world's most powerful laptop for machine learning workloads."

And here's how Ars Technica describes the Razer x Lambda Tensorbook (announced Tuesday): Made in collaboration with Lambda, the Linux-based clamshell focuses on deep-learning development. Lambda, which has been around since 2012, is a deep-learning infrastructure provider used by the US Department of Defense and "97 percent of the top research universities in the US," according to the company's announcement. Lambda's offerings include GPU clusters, servers, workstations, and cloud instances that train neural networks for various use cases, including self-driving cars, cancer detection, and drug discovery.

Dubbed "The Deep Learning Laptop," the Tensorbook has an Nvidia RTX 3080 Max-Q (16GB) and targets machine-learning engineers, especially those who lack a laptop with a discrete GPU and thus have to share a remote machine's resources, which negatively affects development.... "When you're stuck SSHing into a remote server, you don't have any of your local data or code and even have a hard time demoing your model to colleagues," Lambda co-founder and CEO Stephen Balaban said in a statement, noting that the laptop comes with PyTorch and TensorFlow for quickly training and demoing models from a local GUI interface without SSH. Lambda isn't a laptop maker, so it recruited Razer to build the machine....

While there are more powerful laptops available, the Tensorbook stands out because of its software package and Ubuntu Linux 20.04 LTS.

The Verge writes: While Razer currently offers faster CPU, GPU and screens in today's Blade lineup, it's not necessarily a bad deal if you love the design, considering how pricey Razer's laptops can be. But we've generally found that Razer's thin machines run quite hot in our reviews, and the Blade in question was no exception even with a quarter of the memory and a less powerful RTX 3060 GPU. Lambda's FAQ page does not address heat as of today.

Lambda is clearly aiming this one at prospective MacBook Pro buyers, and I don't just say that because of the silver tones. The primary hardware comparison the company touts is a 4x speedup over Apple's M1 Max in a 16-inch MacBook Pro when running TensorFlow.

Specifically, Lambda's web site claims the new laptop "delivers model training performance up to 4x faster than Apple's M1 Max, and up to 10x faster than Google Colab instances." And it credits this to the laptop's use of NVIDIA's GeForce RTX 3080 Max-Q 16GB GPU, adding that NVIDIA GPUs "are the industry standard for parallel processing, ensuring leading performance and compatibility with all machine learning frameworks and tools."

"It looks like a fine package and machine, but pricing starts at $3,499," notes Hot Hardware, adding "There's a $500 up-charge to have it configured to dual-boot Windows 10."

The Verge speculates on what this might portend for the future. "Perhaps the recently renewed interest in Linux gaming, driven by the Steam Deck, will push Razer to consider Linux for its own core products as well."
Piracy

DuckDuckGo Removes Pirate Sites and YouTube-DL From Its Search Results (torrentfreak.com) 77

An anonymous reader quotes a report from TorrentFreak: Privacy-centered search engine DuckDuckGo has completely removed the search results for many popular pirates sites including The Pirate Bay, 1337x, and Fmovies. Several YouTube ripping services have disappeared, too and even the homepage of the open-source software youtube-mp3 is unfindable. [...] The lack of results is not tied to a specific country and manually fiddling with the region settings didn't change anything either. Apparently, DuckDuckgo has simply removed all thepiratebay.org URLs from its index. This whole-site removal isn't limited to The Pirate Bay either. When we do similar searches for 1337x.to, NYAA.se, Fmovies.to, Lookmovie.io, and 123moviesfree.net, no results appear. For RarBG.to and Fitgirl-repacks we only get one result, instead of the hundreds of thousands we see on other search engines.

The absence of results doesn't only apply to pirate sites themselves. For example, there are no results for the streaming portals Flixtor and Primewire. In addition, the associated status pages, which merely include links to the official domains, are not indexed either. Even several popular stream-rippers have been completely wiped from the search results. That includes 2conv.com, Flvto.bid, and several others. The most surprising omission, by far, is that the official site for the open-source software youtube-dl is not indexed by DuckDuckGo. This site certainly doesn't host or link to any copyright-infringing material. We don't know why the official youtube-dl.org website is not in DuckDuckGo's search results, but at least the official GitHub repository is still findable.
DuckDuckGo has yet to explain why these domain names aren't showing up in its search results. "It wouldn't be a surprise if the move is copyright-related," says TorrentFreak.

UPDATE 4/18/22: A spokesperson from DuckDuckGo reached out to us and provided the following statement: "After looking into this, our records indicate that YouTube-dl and The Pirate Bay were never removed from our search results when you searched for them directly by name or URL, which the vast majority of people do (it's rare for people to use site operators or query operators in general)."

They added: "We are having issues with our site: operator, and not just for these sites, but now at least the official site should be coming up for them when you use the site: operator for them. Some of the other sites routinely change domain names and have spotty availability, and so naturally come in and out of the index but should be available as of now."
Crime

Inside the Bitcoin Bust of the Web's Biggest Child Abuse Site (wired.com) 73

Chainalysis is a software for tracing cryptocurrency, "to turn the digital underworld's preferred means of exchange into its Achilles' heel," writes Wired.

This week they describe what happened when that company's co-founder discovered that for two yeras, hundreds of users of a child pornography-trading site — and its administrators — "had done almost nothing to obscure their cryptocurrency trails..." and "seemed to be wholly unprepared for the modern state of financial forensics on the blockchain." Over the previous few years, [Internal Revenue Service criminal investigator Chris] Janczewski, his partner Tigran Gambaryan, and a small group of investigators at a growing roster of three-letter American agencies had used this newfound technique, tracing a cryptocurrency that once seemed untraceable, to crack one criminal case after another on an unprecedented, epic scale. But those methods had never led them to a case quite like this one, in which the fate of so many people, victims and perpetrators alike, seemed to hang on the findings of this novel form of forensics.... Janczewski thought again of the investigative method that had brought them there like a digital divining rod, revealing a hidden layer of illicit connections underlying the visible world....

When Bitcoin first appeared in 2008, one fundamental promise of the cryptocurrency was that it revealed only which coins reside at which Bitcoin addresses — long, unique strings of letters and numbers — without any identifying information about those coins' owners. This layer of obfuscation created the impression among many early adherents that Bitcoin might be the fully anonymous internet cash long awaited by libertarian cypherpunks and crypto-anarchists: a new financial netherworld where digital briefcases full of unmarked bills could change hands across the globe in an instant. Satoshi Nakamoto, the mysterious inventor of Bitcoin, had gone so far as to write that "participants can be anonymous" in an early email describing the cryptocurrency. And thousands of users of dark-web black markets like Silk Road had embraced Bitcoin as their central payment mechanism.

But the counterintuitive truth about Bitcoin, the one upon which Chainalysis had built its business, was this: Every Bitcoin payment is captured in its blockchain, a permanent, unchangeable, and entirely public record of every transaction in the Bitcoin network. The blockchain ensures that coins can't be forged or spent more than once. But it does so by making everyone in the Bitcoin economy a witness to every transaction. Every criminal payment is, in some sense, a smoking gun in broad daylight. Within a few years of Bitcoin's arrival, academic security researchers — and then companies like Chainalysis — began to tear gaping holes in the masks separating Bitcoin users' addresses and their real-world identities.

The article describes some investigative techniques — like pressuring exchanges for identities, tying a transaction to a known identity, or even performing an undercover transaction themselves. "Thanks to tricks like these, Bitcoin had turned out to be practically the opposite of untraceable: a kind of honeypot for crypto criminals that had, for years, dutifully and unerasably recorded evidence of their dirty deals.

"By 2017, agencies like the FBI, the Drug Enforcement Agency, and the IRS's Criminal Investigation division had traced Bitcoin transactions to carry out one investigative coup after another, very often with the help of Chainalysis.

"The cases had started small and then gained a furious momentum...."

Thanks to long-time Slashdot reader Z00L00K for sharing the article.
The Internet

Meet the 1,300 Librarians Racing To Back Up Ukraine's Digital Archives (msn.com) 39

In March a 44-year-old librarian at Pennsylvania's Bucknell University saved a copy of a web site about a 16th century Ukrainian politician and patron of the arts. One month later, "the original website is lost," reports the Washington Post, "its server space likely gone to cyberattacks, power outages or Russian shelling."

But thanks to that librarian, the site "remains intact on server space rented by an international group of librarians and archivists." Slashdot reader nickwinlund77 shared the Post's report: Buildings, bridges, and monuments aren't the only cultural landmarks vulnerable to war. With the violence well into its second month, the country's digital history — its poems, archives, and pictures — are at risk of being erased as cyberattacks and bombs erode the nation's servers.

Over the past month, a motley group of more than 1,300 librarians, historians, teachers and young children have banded together to save Ukraine's Internet archives, using technology to back up everything from census data to children's poems and Ukrainian basket weaving techniques. The efforts, dubbed Saving Ukrainian Cultural Heritage Online (or SUCHO), have resulted in over 2,500 of the country's museums, libraries, and archives being preserved on servers they've rented, eliminating the risk they'll be lost forever. Now, an all-volunteer effort has become a lifeline for cultural officials in Ukraine, who are working with the group to digitize their collections in the event their facilities get destroyed in the war....

They banded together, and amid sleepless nights across multiple time-zones, they recruited, trained, and organized scores of volunteers wanting to help archive Ukraine's historical websites. Large parts of the Internet get periodically archived through the Internet Archive's Wayback Machine, which partners with the organization, but SUCHO's organizers also needed something more advanced, said Quinn Dombrowski, an academic technology specialist at Stanford University. In many cases, the Wayback Machine can dig into the first or second layer of a website, she added, but many documents, like pictures and uploaded files, on Ukraine's cultural websites could be seven or eight layers deep, inaccessible to traditional Web crawlers. To do that, they turned to a suite of open source digital archiving tools called Webrecorder, which have been around since the mid-2010s, and used by institutions including the United Kingdom's National Archive and the National Library of Australia...

SUCHO's organizers receive tips from librarians and archivists across the world who may know of a rare museum in Ukraine that needs to have its work backed up. Other volunteers have become sleuths, using Google Maps to take a digital walk down Ukrainian streets, looking for any signs that might say "museum" or "library" and trying to find out if it has a website that needs archiving. In other cases, when a shelling happens somewhere, a group of volunteers dedicated to "situation monitoring" alerts any volunteers that might be awake to look for institution websites in that region that need backing up, for fear they could go offline any minute.

Or, as that Bucknell librarian told the Post, "We're trying to save as much as possible."
Music

How a Ukranian Soldier's Instagram Post Spawned the First New Pink Floyd Song in 28 Years (pinkfloyd.com) 60

"English rock band Pink Floyd has released new music for the first time in 28 years," reports UPI, "with proceeds from the track going to humanitarian relief in Ukraine amid its ongoing conflict with Russia."

"The single will be available on all streaming and download platforms..." the band said on their official web site. [Including downloads on Amazon Music and Apple Music]. "This is the first new original music that they have recorded together as a band since 1994's The Division Bell." The track sees David Gilmour and Nick Mason joined by long-time Pink Floyd bass player Guy Pratt and Nitin Sawhney on keyboards and features an extraordinary vocal performance by Andriy Khlyvnyuk of Ukrainian band Boombox.... David, who has a Ukrainian daughter-in-law and grandchildren says: "We, like so many, have been feeling the fury and the frustration of this vile act of an independent, peaceful democratic country being invaded and having its people murdered by one of the world's major powers...."

"Recently I read that Andriy had left his American tour with Boombox, had gone back to Ukraine, and joined up with the Territorial Defense. Then I saw this incredible video on Instagram, where he stands in a square in Kyiv with this beautiful gold-domed church and sings in the silence of a city with no traffic or background noise because of the war. It was a powerful moment that made me want to put it to music." While writing the music for the track, David managed to speak with Andriy from his hospital bed in Kyiv where he was recovering from a mortar shrapnel injury. "I played him a little bit of the song down the phone line and he gave me his blessing...."

Speaking about the track David says, "I hope it will receive wide support and publicity. We want to raise funds for humanitarian charities and raise morale. We want to express our support for Ukraine and, in that way, show that most of the world thinks that it is totally wrong for a superpower to invade the independent democratic country that Ukraine has become".

All proceeds will go towards Ukrainian humanitarian relief.

On March 11 the band had posted another update on their official site: To stand with the world in strongly condemning Russia's invasion of Ukraine, the works of Pink Floyd, from 1987 onwards, and all of David Gilmour's solo recordings are being removed from all digital music providers in Russia and Belarus....
Crime

Germany Shuts Down Servers For Russian Darknet Marketplace Hydra (theverge.com) 9

German authorities shut down the server infrastructure for the Russian darknet marketplace Hydra, seizing ~$25.2 million worth of Bitcoin in the process, Germany's Federal Crime Police Office (BKA) announced on Tuesday. From a report: Hydra is a large marketplace on the dark web that serves as a hub for drugs, stolen credit card information, counterfeit bills, fake documents, and other illegal goods or services. The market primarily caters to criminals in Russia and surrounding nations. "Treasuremen," or dealers connected with the site, push drugs throughout the region by hiding them in geo-tagged pickup locations. With the shutdown of the German-based server, authorities are now launching an investigation into the "unknown operators and administrators" of Hydra, whom they suspect of selling narcotics and engaging in money laundering. German authorities say they have been investigating the marketplace with the help of the US since August 2021. The BKA told The Verge that no arrests have been made as of yet.
Microsoft

Microsoft Security Chief Issues Call To Arms To Protect Metaverse (bloomberg.com) 40

Microsoft's new security chief Charlie Bell issued a call to arms to build protection from hackers and criminals in the emerging metaverse from the start of the new technology. From a report: "There's going to be a lot of innovation and there will be a lot of struggling to figure out what has to be done," Bell said in an interview. "But I think because of the speed, there will be fast innovation on the security side."

The metaverse -- a concept that promises to let users live, work and play within interconnected virtual worlds -- will present some unique and more serious security challenges for technology and cybersecurity companies. As an example, hackers may be able to make avatars that look like a user's trusted contacts, a twist on the traditional email phishing scheme that will be hard for users to resist, he said. The nature of the metaverse, which offers the possibility of less centralized control of content and users, also is a challenge for those trying to protect customers.

"Picture what phishing could look like in the metaverse -- it won't be a fake e-mail from your bank," wrote Bell, Microsoft's executive vice president, security, compliance, identity, and management, in a blog posted Monday on Microsoft's web site. "It could be an avatar of a teller in a virtual bank lobby asking for your information. It could be an impersonation of your CEO inviting you to a meeting in a malicious virtual conference room."

The Internet

'The Plain-Text Internet is Coming' (protocol.com) 180

Protocol reports: The web is overrun with junk. This is so obvious, I almost don't need to say it. But I will: Between the pop-ups, the autoplaying videos, the cookie banners, the incessant calls for sign-ups, the coupon offers, the "Don't forget to subscribe!" reminders on top of the other "Don't forget to subscribe!" reminders, the in-line ads slowing the page down, the slew of trackers also slowing the page down ... you get the idea. For lots of reasons, some good and some bad, much of the internet has become totally unusable.

Plain Text Sports is nothing like any of those sites. The site, created by developer Paul Julius Martinez (who you might know as CodeIsTheEnd all over the internet), is more like something out of the 1970s, a wall of monospaced plain text with ASCII-art boxes surrounding real-time scores for all the professional sports games happening right now. It has no images, no pop-ups, no trackers. It loads practically instantly, even on a bad connection. I've been refreshing it obsessively the last few weeks, through the end of the NBA seasons and the beginning of March Madness. Not only is it a useful site for sports fans, but it feels like a harbinger of things to come....

He loves that Plain Text Sports is simple. "There's no cookie banner, there's no GDPR banner, there's no asking-you-to-donate banner...." Plain Text Sports manages to be that simple on the front end with a surprising amount of complexity on the back end, making sure the whole sports world is represented in real time on that page.

In general, we're starting to see developers and designers rebel against the general overwhelm of the internet, as sites and apps ditch their cruft and complications for things that load faster and work more intuitively. Social networks are bringing back chronological feeds; reading modes are now everywhere in browsers. Even apps like Obsidian, a favorite among productivity obsessives, are based primarily on plain text.

They don't look like much, but that's kind of the point.

Government

The EPA Plans To Sunset Its Online Archive (theverge.com) 30

Come July, the EPA plans to retire the archive containing old news releases, policy changes, regulatory actions, and more. The Verge reports: The archive was never built to be a permanent repository of content, and maintaining the outdated site was no longer "cost effective," the EPA said to The Verge in an emailed statement. The EPA announced the retirement early this year, after finishing an overhaul of its main website in 2021, but says that the decision was years in the making. The agency maintains that it's abiding by federal rules for records management and that not all webpages qualify as official records that need to be preserved.

The EPA says it plans to migrate much of the information to other places. Old news releases will go to the current EPA website's page for press releases. When it comes to the rest of the content, the EPA has a process for making case-by-case decisions on what content can be deleted -- and what is relevant enough to move to the modern website. Some content might be deemed important enough to join the National Archives. The public will be able to request that content through the Freedom of Information Act.

The archive is the only comprehensive way that public information about agency policies, like fact sheets breaking down the impact of environmental legislation, and actions, like how the agency implements those laws, have been preserved, [says Gretchen Gehrke, one of the cofounders of a group called Environmental Data and Governance Initiative (EDGI) that's fighting for public access to resources like the EPA's online archives]. That makes the archive vital for understanding how regulation and enforcement have changed over the years. It also shows how the agency's understanding of an issue, like climate change, has evolved. And when the Trump administration deleted information about climate change on the EPA's website, much of it could still be found on the archive. Besides that, Gehrke says the content should just be available on principle because it's public information, paid for by taxpayer dollars.

Linux

Linux For M1 Macs? First Alpha Release Announced for Asahi Linux (asahilinux.org) 108

"Asahi Linux aims to bring you a polished Linux experience on Apple Silicon Macs," explains the project's web site.

And now that first Asahi Linux alpha release is out — ready for testing on M1, M1 Pro, and M1 Max machines (except Mac Studio): We're really excited to finally take this step and start bringing Linux on Apple Silicon to everyone. This is only the beginning, and things will move even more quickly going forward!

Keep in mind that this is still a very early, alpha release. It is intended for developers and power users; if you decide to install it, we hope you will be able to help us out by filing detailed bug reports and helping debug issues. That said, we welcome everyone to give it a try — just expect things to be a bit rough.... Asahi Linux is developed by a group of volunteers, and led by marcan as his primary job. You can support him directly via Patreon and GitHub Sponsors....

Can I dual-boot macOS and Linux?

Yes! In fact, we expect you to do that, and the installer doesn't support replacing macOS at this point. This is because we have no mechanism for updating system firmware from Linux yet, and until we do it makes sense to keep a macOS install lying around for that. You can have as many macOS and Linux installs as you want, and they will all play nicely and show up in Apple's boot picker. Each Linux install acts as a self-contained OS and should not interfere with the others.

Note that keeping a macOS install around does mean you lose ~70GB of disk space (in order to allow for updates, since the macOS updater is quite inefficient). In the future we expect to have a mechanism for firmware updates from Linux and better integration, at which point we'll be comfortable recommending Linux-only setups....

Is this just Arch Linux ARM?

Pretty much! Most of our work is in the kernel and a few core support packages, and we rely on Linux's excellent existing ARM64 support. The Asahi Linux reference distro images are based off of Arch Linux ARM and simply add our own package repository, which only adds a few packages. You can freely convert between Arch Linux ARM and Asahi Linux by adding or removing this repository and the relevant packages, although vanilla Arch Linux ARM kernels will not boot on these machines at this time.

The project's home page adds that "All contributors are welcome, of any skill level!"

"Doing this requires a tremendous amount of work, as Apple Silicon is an entirely undocumented platform," the team explains. "In particular, we will be reverse engineering the Apple GPU architecture and developing an open-source driver for it." But they're already documenting the Apple Silicon platform on their GitHub wiki. We will eventually release a remix of Arch Linux ARM, packaged for installation by end-users, as a distribution of the same name. The majority of the work resides in hardware support, drivers, and tools, and it will be upstreamed to the relevant projects....

Apple allows booting unsigned/custom kernels on Apple Silicon Macs without a jailbreak! This isn't a hack or an omission, but an actual feature that Apple built into these devices. That means that, unlike iOS devices, Apple does not intend to lock down what OS you can use on Macs (though they probably won't help with the development). As long as no code is taken from macOS to build the Linux support, the result is completely legal to distribute and for end-users to use, as it would not be a derivative work of macOS.

An interesting observataion from Slashdot reader mrwireless: It once again seems Apple is informally supportive of these efforts, as the recent release of OS Monterey 12.3 makes the process even simpler. As Twitter user Matthew Garrett writes:

"People who hate UEFI should read https://github.com/AsahiLinux/... — Apple made deliberate design choices that allow third party OSes to run on M1 hardware without compromising security, and with much less closed code than on basically any modern x86."

Puzzle Games (Games)

NYT Takes Down Third-Party Wordle Archive (arstechnica.com) 33

The New York Times, which acquired Wordle in January, is putting an end to unofficial takes of the game. The latest casualty is Wordle Archive, a website that let users play through hundreds of previous daily five-letter Wordle puzzles. According to Ars Technica, the site "has been taken down at the request of Wordle owner The New York Times." From the report: The archival site, which offered a backward-looking play feature that's not available in the NYT's official version of Wordle, had been up since early January. But it was taken down last week and replaced with a message saying, "Sadly, the New York Times has requested that the Wordle Archive be taken down." A Twitter search shows dozens of daily Wordle Archive players who were willing to share their results on social media up through March 7. "The usage was unauthorized, and we were in touch with them," a New York Times representative said in response to an Ars Technica comment request. "We don't plan to comment beyond that."

The Wordle Archive is still fully playable in its own archived form (as of March 5) at the Internet Archive, appropriately enough. Other sites that allow you to play archived Wordle puzzles are not hard to find, as are sites that let you play unlimited Wordle puzzles beyond the usual one-a-day limit. But some of those sites may be under threat, if the Times' treatment of Wordle Archive is any indication.

Programming

The Dangers of CS 'Philanthrocapitalism' (freedom-to-tinker.com) 41

Princeton University has a research center studying "digital technologies in public life," which runs a web site with commentary and analysis "from the digital frontier, written by the Center's faculty, students, and friends."

Long-time Slashdot reader theodp summarizes the site's recent warning on the dangers of "philanthrocapitalism," in a piece noting ominously that "The tech industry controls CS conference funding." "Research about the influence of computing technologies, such as artificial intelligence (AI), on society relies heavily upon the financial support of the very companies that produce those technologies," writes Princeton Research Fellow Klaudia Jazwinska of the dangers of 'philanthrocapitalism'. "Corporations like Google, Microsoft, and IBM spend millions of dollars each year to sponsor labs, professorships, PhD programs, and conferences in fields like computer science (CS) and AI ethics at some of the world's top institutions. Industry is the main consumer of academic CS research, and 84% percent of CS professors receive at least some industry funding."

"Relying on large companies and the resources they control can create significant limitations for the kinds of CS research that are proposed, funded and published. The tech industry plays a large hand in deciding what is and isn't worthy of examination, or how issues are framed. [...] The scope of what is reasonable to study is therefore shaped by what is of value to tech companies. There is little incentive for these corporations to fund academic research about issues that they consider more marginal or which don't relate to their priorities."

Jazwinska concludes, "Given the extent of financial entanglement between Big Tech and academia, it might be unrealistic to expect CS scholars to completely resist accepting any industry funding—instead, it may be more practicable to make a concerted effort to establish higher standards for and greater transparency regarding sponsorship.

Space

Coronal Mass Ejection Reaches Earth On Sunday Night (spaceweatherlive.com) 32

"A long duration C2 solar flare launched an asymmetrical full halo coronal mass ejection into space," tweeted the nonprofit science site SpaceWeatherLive (sharing a black-and-white video). "The solar plasma cloud is likely to arrive at Earth late on Sunday, 13 March. Minor G1 geomagnetic storm conditions are likely with a chance of moderate G2 conditions."

Long-time Slashdot reader PuddleBoy shared this additional report from their web site: The solar flare lasted for hours and launched an asymmetrical full halo coronal mass ejection into space. Most of the ejecta is heading north-west but a significant part of the plasma cloud is expected to arrive at our planet. The coronal mass ejection was launched at a speed of about 600km/s which is a fairly average speed. This puts the likely arrival time at Earth late on Sunday, 13 March.

Minor G1 geomagnetic storm conditions (Kp5) are likely with a chance of moderate G2 conditions which equals a Kp-value of 6. Middle latitude locations might catch a glimpse of the aurora near the northern (or southern) horizon under optimal conditions.

Open Source

Arch Linux Turns 20 (neowin.net) 29

"Arch Linux, the rolling Linux distribution that powers Valve's Steam Deck is now 20 years old," reports Neowin.

Slashdot reader segaboy81 writes that "What's cool to see here is that everything changed behind the scenes, but on the surface, things are the same." From the article: Announced on March 11th, 2002, and codenamed Homer, version 0.1 was released to minor fanfare. The release notes were a far cry from today's, essentially announcing it had broken ground and the foundation was going in, as it were.

Homer's release notes:

I've finally got a bootable iso image on the ftp site. The bad news is that you don't get a pretty interactive installer. But if you wanted one of those, you would have gone with RedHat, right? ;)

I'll try to get the docs up for ABS (Arch Build System) which, IMHO, is one of the best advantages of Arch. With ABS, you can easily create new packages, and it's trivial to rebuild existing packages with your own customizations....


It shipped with Linux kernel 2.4.18 which many of the Linux old-timers (myself included) will remember was right before we started to get nice things like auto-mounting USB drives in kernel 2.6. XFree86 4.2.0 was also in stow, which is what we now call Xorg. If you wanted to build software, you had to use an absolutely ancient gcc toolchain (2.95.3). Web browsing was covered by the ghost of Netscape Navigator, Mozilla 0.9.9. Heady days, these were!

Security

Big Web Security Firms Ditch Russia, Leaving Internet Users Open To More Kremlin Snooping (forbes.com) 16

Ordinary Russians face another major blow to their everyday lives due to the backlash to President Vladimir Putin's invasion of Ukraine. On the same day, two major web-security companies have decided to quit selling to them, making Russians' internet use more vulnerable to Kremlin snooping, hacking and other cybercrimes. From a report: The departure of the two companies, Avast, a $6 billion antivirus provider based in the Czech Republic, and Utah-based website-certification firm DigiCert, will further isolate the country of 145 million people. "We are horrified at Russia's aggression against Ukraine, where the lives and livelihoods of innocent people are at severe risk, and where all freedoms have come under attack," Avast CEO Ondrej Vlcek wrote on Thursday. Vlcek said the company was including Belarus in the withdrawal of services, and was continuing to pay the full salaries of employees in Russia and Ukraine, many of whom it was helping to relocate. "We do not take this decision lightly," Vlcek wrote. "We've offered our products in Russia for nearly 20 years and users in this country are an important part of our global community." While Avast joins other antivirus companies, including NortonLifeLock and ESET, in halting sales, Russians will still be able to get antivirus protection from Moscow-based Kaspersky and other providers within the country. The departure of DigiCert could prove more significant. DigiCert is one of the world's biggest providers of website certificates, which aim to prove that when a person visits a site it's owned by the entity they expected.
The Internet

Russia Creates Its Own TLS Certificate Authority To Bypass Sanctions (bleepingcomputer.com) 59

Russia has created its own trusted TLS certificate authority (CA) to solve website access problems that have been piling up after sanctions prevent certificate renewals. From a report: The sanctions imposed by western companies and governments are preventing Russian sites from renewing existing TLS certificates, causing browsers to block access to sites with expired certificates. [...] The Russian state has envisioned a solution in a domestic certificate authority for the independent issuing and renewal of TLS certificates. "It will replace the foreign security certificate if it is revoked or expires. The Ministry of Digital Development will provide a free domestic analogue.

The service is provided to legal entities -- site owners upon request within 5 working days," explains the Russian public services portal, Gosuslugi (translated). However, for new Certificate Authorities (CA) to be trusted by web browsers, they first needed to be vetted by various companies, which can take a long time. Currently, the only web browsers that recognize Russia's new CA as trustworthy are the Russia-based Yandex browser and Atom products, so Russian users are told to use these instead of Chrome, Firefox, Edge, etc.

Math

Mathematicians Protest Russia Hosting Major Conference (scientificamerican.com) 69

As Ukrainian researchers have feared for their lives and careers after Russia's invasion of Ukraine, mathematicians have been grappling over what to do about a prominent mathematical conference that was set to be held in Saint Petersburg, Russia, in July. From a report: The International Congress of Mathematicians (ICM) is "the largest and most significant conference on pure and applied mathematics as well as one of the world's oldest scientific congresses," according to the Web site of the 2022 conference. The meeting, which is run by the Germany-based International Mathematical Union (IMU), is held only once every four years. When the nine-day 2018 ICM was held in Rio de Janeiro, Brazil, it drew 10,506 attendees.

On Saturday conference organizers announced the event would be fully virtual and hosted outside of Russia this year. The executive committee of the meeting released a statement saying, "We strongly condemn the actions by Russia. Our deepest sympathy goes to our Ukrainian colleagues and the Ukrainian people. Given this situation, it is impossible for the IMU to host the ICM and the GA [general assembly] as traditional in-person events in Russia." The Fields Medal -- one of the most prestigious honors in mathematics -- is traditionally awarded at the event. According to the recent decision, this year's prize ceremony and general assembly will be held in person but at an undecided location outside of Russia.

Slashdot Top Deals