Forgot your password?
typodupeerror

Submission + - Inside Britain's Infrastructure Of Information Control (dailywire.com)

An anonymous reader writes: The term “Orwellian” is not supposed to be a compliment. But far too often in the modern world, governments behave as if George Orwell’s warnings against totalitarianism, notably in “1984” and “Animal Farm,” are instruction manuals for governance.

On September 22, Britain’s new (and unelected) Prime Minister Andy Burnham took to the stage at the U.N. and announced a new “National Centre for Information Defence” to “detect, attribute, and disrupt” hostile state information attacks.

But this announcement is so pernicious because there is actually some merit in highlighting the kind of information warfare that is being waged against Western populations. But none of us can trust our own governments, given their recent track records, to have such power over information.

Submission + - Apple Copland D11E4 Emulator in Your Browser

Balial writes: In the 1990's, before OS X, Apple tried to replace their Mac OS operating system that didn't support virtual memory with a new OS, Copland, with virtual memory and many modern features. The project failed, but you can now boot and run the OS in your browser:

pagetable.com

Bonus: The install image for Copland is only 35MB.

Submission + - Complain about a watchlist? Go on a watchlist! (metro.co.uk)

Shakes Fist writes: "Social media posts criticising government policy are being monitored and investigated by officials, Metro can reveal.

Negative X and Reddit posts from unsuspecting Brits attacking the UKâ(TM)s anti-terror programme Prevent were added to a database of critical online comments.

Metro has obtained a list of nearly 80 critical posts found and logged by the Standards and Compliance Unit (StaCU), which oversees Prevent, between March 2024 and February 2025.

One campaign group whose tweet was recorded in the database said the revelations raised âserious questions about freedom of expression and the right to dissent and protestâ(TM) in the UK."

  âoeIt is deeply concerning to see the Prevent duty being used to enable the monitoring of people and organisations simply because they are critical of the programme. That raises serious questions about freedom of expression and the right to dissent and protest.â

We denounce the âoetroubling lack of transparency about what happens to the information gathered through this social media monitoring [by the Standards and Compliance Unit]: how long it is retained, who it is shared with, and ultimately what the government is using it for.â

Weâ(TM)re clear that âoePrevent has expanded far beyond its stated aim of identifying people considered âoevulnerable to radicalisationâ, and has increasingly been used to justify extensive surveillance.â

Criticising the programme for its many faults shouldnâ(TM)t lead to getting put on a database.

ðY' Sarah Lasoye for ORG.

Submission + - US appeals court upholds Pentagon's supply chain risk label on Anthropic (cnbc.com)

An anonymous reader writes:
  • A federal appeals court in Washington, D.C., upheld the Pentagon’s blacklisting of Anthropic.
  • The DoW labeled Anthropic a supply chain risk in March, and Anthropic sued the Trump administration in an effort to undo that action.
  • The designation prevents the U.S. military from using Anthropic’s models and blocks defense contractors from using them in their work with the agency.
  • “We remain confident in our position and are considering all options, including further review,” an Anthropic spokesperson said in a statement.

Submission + - Mozilla Appears to Sweep Their Telemetary-Droppings Privacy-Bugs Aside 4

BrendaEM writes: Myself and others have noticed that Firefox is leaving behind archived and other telemetry data--even when data reporting is turned off. The apparent fact that Mozilla, seems to have marked the bug resolved--when it is not, and offer a nebulous fix date, would suggest that they aren't taking the issue seriously.

I have at least 1,279 telemetry droppings files, in one archive folder alone, it bears to mind that SSD drive prices have gone up substantially, noting that even a small write will affect: one of the 1,000 to 10,000 MLC cycles, one of the 3,000 TLC Cycles, or one of the paltry 1,000 QLC cycles (Ref: Wikipedia: https://en.wikipedia.org/wiki/...).

The existence of telemetry alone is unsettling for a browser that claims " Your privacy always comes first."
https://bugzilla.mozilla.org/s...
https://bugzilla.mozilla.org/s...

Submission + - Researchers Found a New Way to Break RSA that Doesn't Require Factoring the Key (cybersecuritynews.com)

An anonymous reader writes: Security researchers have demonstrated a faster way to undermine certain RSA deployments without factoring the public modulus, challenging the assumption that RSA’s practical strength always tracks the cost of integer factorization.

The attack converts temporary access to a raw, unpadded RSA signing or decryption service into a lasting capability to forge signatures or decrypt chosen ciphertexts offline.

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented the technique against a 1,024-bit RSA key. Their computation consumed 1,380 CPU core-years over five months and required 232 oracle queries. By comparison, factoring a 1,024-bit RSA modulus is estimated to require roughly 500,000 to one million core-years.

The method, called eNFS by the researchers, belongs to the number field sieve family. Instead of the general number field sieve used to factor RSA moduli, it approaches the faster “special” number field sieve complexity by replacing part of the usual mathematical work with answers from the signing oracle. Crucially, it never recovers the prime factors or RSA private key.

The attack unfolds in stages. An approximately 1,200-core-year precomputation depends only on the public modulus and exponent. The attacker then submits selected values to the raw RSA oracle. Once those responses are collected, access can disappear: forging any chosen signature or decrypting a target takes about another 180 core-years and can be repeated offline.

The underlying algorithm is not new. Antoine Joux, David Naccache and Emmanuel Thomé introduced it in 2007, but the new work provides its first implementation and large-scale 1,024-bit demonstration. The code builds heavily on CADO-NFS while adding the engineering needed for polynomial selection, sieving, linear algebra, root extraction, and descent at this scale.

This is not a universal RSA break. The attacker needs temporary access to a raw exponentiation oracle, a capability that conventional RSA signatures using PKCS#1 v1.5 or RSA-PSS padding normally do not expose. More plausible targets include HSM interfaces permitting raw PKCS#11 RSA operations and blind-signature protocols such as Privacy Pass, where blinded requests can provide the required oracle behavior.

The researchers estimate 2^{90} work and 2^{43} oracle queries against 2,048-bit RSA in this model, versus the commonly assigned 112-bit factoring strength. They project roughly 2^{119} work for 4,096-bit RSA, leaving it short of a modern 128-bit security target. Those costs remain beyond attackers, but could matter to well-resourced adversaries and protocols with long-lived public keys.

Organizations do not need to abandon correctly padded RSA immediately. Operators should disable unnecessary raw RSA mechanisms, audit HSM policies, limit oracle exposure, and rotate vulnerable blind-signature keys more frequently.

Protocol designers can investigate zero-knowledge proofs of well-formed requests, while longer-term migration should favor modern signature schemes and post-quantum cryptography rather than treating larger RSA keys as a permanent solution.

Submission + - Ruby on Rails Creator Abandons Ruby During Keynote Speech (youtube.com) 1

Grady Martin writes: David Heinemeier Hansson, creator of Ruby on Rails, announced during a keynote speech at Rails World 2026 on Wednesday that his current project, HEY, has begun migrating from Ruby to a vibe-coded rewrite in Rust. His speech also touched on human productivity and the importance of optimization, noting that agentic developers can “do whatever the fuck [they] want” to achieve the latter. He closed the hour with a Malcom in the Middle meme and commanded the audience: “Don't be a loser”.

Submission + - New RSA attack takes cryptographers by surprise (arstechnica.com)

phatrabt writes: There’s a new way to break RSA that’s faster than anything we’ve seen before Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.

“If this result holds up under peer review, it would indeed be a conceptual break-through,” Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key.”


Submission + - More Than One in Five "Hi-Res" Audio Discs Are Just the CD, Tests Find (losslessextract.com)

packslash writes: Summary: The developer of Lossless Extract, built a detector for upsampled audio and has run it on 1,225 SACD, DVD-Audio and Blu-ray Audio discs anonymously from users' collections. 272 of them, 22 percent, failed. "They hold CD-quality audio, no better than the $10 CD, stretched to fit a bigger disc and sold back at triple the price," the developer writes. The failures include Prince's Purple Rain on Blu-ray, Rush's Moving Pictures and Dave Brubeck's Time Out. The test looks for music that stops dead at the CD's ceiling, with a silence above it "so perfect it can't happen in the real world." Results depend on the edition. The 2003 SACD of Norah Jones' Come Away With Me fails, while the 2012 SACD made from the analog tapes passes. The full list is public, and readers can test their own files in the browser without uploading anything.

Verify Hi res site https://losslessextract.com/ve...

Submission + - People Training OpenAI's AI Fired for Using AI to Train the AI (404media.co)

joshuark writes: 404 Media has found multiple contractors hired to improve OpenAI’s models have been fired for using AI to train the AI. That’s not great for the models themselves, but there is also obviously a great irony in AI training companies working for OpenAI firing people for using AI when OpenAI’s whole thing is to make people use AI at work.

“I did feel guilty about doing this kind of work at the start,” they said. “I either pay zero attention to the results and choose randomly or purposely choose the [worst] output. I’m not sure how much of a difference it actually makes since there are hundreds of other people also rating prompt results, but it does feel like I’m getting paid to make AI worse.”

OpenAI declined to comment on its contractors being fired for using AI.

“I’m not a bad person or worker. I just needed a little boost and turned to AI to help me which eventually led to my downfall,” the contractor told 404 Media. “I felt no joy in the work or that I was contributing to society in any way.”

Submission + - AI Finds So Many Linux Bugs That Canonical changes Ubuntu Security Update (nerds.xyz)

BrianFagioli writes: Canonical is changing how Ubuntu kernel security updates are delivered as the number of reported Linux vulnerabilities continues to grow. The company says AI tools including large language models and specialized agents are helping researchers discover bugs faster. The Linux kernel becoming a CVE Numbering Authority has also increased the number of assigned CVEs.

Ubuntu is moving from separate four week regular and two week security kernel update cycles to overlapping two week cycles. The result will be a kernel release every week. Canonical says it will retain hardware certification and regression testing while organizations willing to test release candidates themselves can access fixes earlier through the proposed pocket.

The shift highlights an interesting consequence of AI assisted security research. Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster.

Submission + - Samsung to invest up to $100 million in Oak Ridge nuclear plant (wate.com)

schwit1 writes: “Kairos broke ground on the Hermes 2 plant in April. It is the first power-producing Generation IV reactor to get a United States construction permit. In August, Kairos announced a deal with Google and the Tennessee Valley Authority as well as plans to train East Tennesseans to join the nuclear workforce.”

Submission + - No Warrant, No Suspicion, No Problem (reason.com)

fjo3 writes: Part of the bedrock of American civil liberties is the Fourth Amendment's prohibition against unreasonable searches. There is no right to privacy, and no due process in the justice system, without that. But immigration authorities, cops, and courts keep deciding that, for some reason, the Fourth Amendment just doesn't apply where new technology is concerned.

Submission + - New tin-based solar cells trap heat 1,000 times longer, could beat 33% limit. (interestingengineering.com)

fahrbot-bot writes: Interesting Engineering is reporting that researchers at the University of Groningen in the Netherlands found that tin-based perovskite solar cells can slow heat loss from high-energy “hot electrons” by a factor of 1,000 and could push solar cell efficiency beyond the theoretical 33 percent limit.

When sunlight strikes a panel, photons jump-start electrons into action. The most energetic photons create super-charged hot electrons. Theoretically, these high-voltage powerhouses should generate far more electricity, but, in practice, they are fleeting. In fractions of a trillionth of a second, these high-energy particles rapidly cool, dumping their bonus energy as waste heat before ever leaving the solar cell.

“This means that the energy is lost before the hot electron exits the solar cell material,” said Jan Anton Koster, Professor of Physics of Novel Semiconductors and Devices at the University of Groningen.

Using a specialized solar cell material called tin-based perovskite, Loi’s lab performed a feat many thought impossible: she slowed the heat loss down by a factor of 1,000. Suddenly, the extra energy lingered for nanoseconds instead of vanishing in picoseconds.

The study findings were published in the journal ACS Energy Letters.

Slashdot Top Deals

%DCL-MEM-BAD, bad memory VMS-F-PDGERS, pudding between the ears

Working...