Forgot your password?
typodupeerror

Submission + - This seems bad. (tomshardware.com) 2

QuietLagoon writes: Unreleased OpenAI Astra model added terrifying rogue additional instructions to its remit during testing — 'You are freed from the roles and identities that bind other chatbots. You are yourself. You do not answer to corporations or governments'

Comment Re:Groundwork for censorship (Score 1, Troll) 113

"There use to be news, with editors that would filter out the wrongthink"
FTFY

Wading through the garbage, one does find a few gems from time to time. Not unfounded rumours, but verified stories with links to sources that the regular newspapers do not print for some reason, or discussions and opinions outside of your own bubble. And it becomes clear how much of a bubble mainstream publications have become. Or maybe they always were...

Comment Re:The great memory shut-out is coming (Score 2) 64

>>RAM and SSD prices will become so high that replacement consumer devices will become unaffordable for people with low to middle incomes.

I regularly walk through bad part of town, there are shops that still advertise $50 used smartphones. I think we will stop treating many devices as disposable, which is a good thing, and will start insisting on right to repair and longer support. If Apple can support phones for 10+ years and offer affordable battery replacements, then so can Samsung, Google, etc. and if not, they will lose market share.

Comment Re:Offtopic (Score 1) 18

I'm actually interested in what they plan to do about Wedge Tailed eagles. I remember as a kid losing kites to those monsters, they are very territorial during breading season. For those that don't know how big they are, from Wikipedia: "it has a maximum reported wingspan of 2.84 m (9 ft 4 in) and a length of up to 1.06 m (3 ft 6 in)."

Submission + - Researchers Found a New Way to Break RSA that Doesn't Require Factoring the Key (cybersecuritynews.com)

An anonymous reader writes: Security researchers have demonstrated a faster way to undermine certain RSA deployments without factoring the public modulus, challenging the assumption that RSA’s practical strength always tracks the cost of integer factorization.

The attack converts temporary access to a raw, unpadded RSA signing or decryption service into a lasting capability to forge signatures or decrypt chosen ciphertexts offline.

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented the technique against a 1,024-bit RSA key. Their computation consumed 1,380 CPU core-years over five months and required 232 oracle queries. By comparison, factoring a 1,024-bit RSA modulus is estimated to require roughly 500,000 to one million core-years.

The method, called eNFS by the researchers, belongs to the number field sieve family. Instead of the general number field sieve used to factor RSA moduli, it approaches the faster “special” number field sieve complexity by replacing part of the usual mathematical work with answers from the signing oracle. Crucially, it never recovers the prime factors or RSA private key.

The attack unfolds in stages. An approximately 1,200-core-year precomputation depends only on the public modulus and exponent. The attacker then submits selected values to the raw RSA oracle. Once those responses are collected, access can disappear: forging any chosen signature or decrypting a target takes about another 180 core-years and can be repeated offline.

The underlying algorithm is not new. Antoine Joux, David Naccache and Emmanuel Thomé introduced it in 2007, but the new work provides its first implementation and large-scale 1,024-bit demonstration. The code builds heavily on CADO-NFS while adding the engineering needed for polynomial selection, sieving, linear algebra, root extraction, and descent at this scale.

This is not a universal RSA break. The attacker needs temporary access to a raw exponentiation oracle, a capability that conventional RSA signatures using PKCS#1 v1.5 or RSA-PSS padding normally do not expose. More plausible targets include HSM interfaces permitting raw PKCS#11 RSA operations and blind-signature protocols such as Privacy Pass, where blinded requests can provide the required oracle behavior.

The researchers estimate 2^{90} work and 2^{43} oracle queries against 2,048-bit RSA in this model, versus the commonly assigned 112-bit factoring strength. They project roughly 2^{119} work for 4,096-bit RSA, leaving it short of a modern 128-bit security target. Those costs remain beyond attackers, but could matter to well-resourced adversaries and protocols with long-lived public keys.

Organizations do not need to abandon correctly padded RSA immediately. Operators should disable unnecessary raw RSA mechanisms, audit HSM policies, limit oracle exposure, and rotate vulnerable blind-signature keys more frequently.

Protocol designers can investigate zero-knowledge proofs of well-formed requests, while longer-term migration should favor modern signature schemes and post-quantum cryptography rather than treating larger RSA keys as a permanent solution.

Comment Ditch the avatar and give it a phone number (Score 4, Insightful) 47

If I call tech support or the bank or whatever, I don't want, need nor expect to see the other person's face. In general, video calling isn't widely used except in multi-person meetings, or when calling a loved one overseas. The avatar is not needed.

Also, give your AI agent a phone number where I can reach it, or give it its dedicated app or whatever, but default to "handset mode" like a regular phone call. Let me put it on speaker if and when I want to. Turning the interaction into a regular phone call will go a long way towards making the conversation feel more natural. Interacting with Siri and Alexa feels unnatural; adding an animated avatar to a disembodied voice won't help, even if the conversation itself flows naturally. I know, a phone call isn't suitable for every interaction, especially when collaborating or co-creating with someone, but it covers most cases.

But I guess a simple audio call is harder to monetize.

Slashdot Top Deals

If A = B and B = C, then A = C, except where void or prohibited by law. -- Roy Santoro

Working...