Alterslash

the unofficial Slashdot digest
 

Contents

  1. Oracle Signs 10-Year Software Contract With Pentagon Worth Up To $7 Billion
  2. Microsoft Responds to LG Monitors Installing McAfee Ads On Windows
  3. EU Fines Google $1 Billion For Breaking Digital Antitrust Regulations
  4. Amazon Is Bringing Games to Prime Video
  5. Sony’s Decision To Ditch Discs Was Practically Inevitable, Data Shows
  6. In a First, Apple Maps Navigation To Be Embedded In Ford UEV Pickups
  7. Four Young Mathematicians Awarded the 2026 Fields Medals
  8. Startup Founders Urge Trump Not to Shut Off Chinese Open Weight AI
  9. Researchers Discover First Known Transmissible Cancer In Fish
  10. Verisign Is Finally Bringing .web Domains To the Internet
  11. Private Mission Launches To Extend Life of Out-of-Gas Communication Satellites
  12. Pan Am Plane Crash That Inspired Modern Safety Briefings Found After 74 Years
  13. GM Is Quietly Becoming a Subscriptions Company
  14. iOS 27 Code Suggests Apple Could Restrict Leased Devices After Missed Payments
  15. Linux Kernel Team Publishes 432 CVEs In Two Days

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

Oracle Signs 10-Year Software Contract With Pentagon Worth Up To $7 Billion

Posted by BeauHD View on SlashDot Skip
Oracle has signed a 10-year Pentagon contract worth up to $7 billion to provide on-premises software, licenses, maintenance, and consulting for branches of the military. CNBC reports:
The contract covers the use of Oracle software in on-premises data centers for branches of the military, the U.S. intelligence community and the Coast Guard, according to a statement. The Central Intelligence Agency was Oracle’s first customer. A five-year base period for the contract includes perpetual and subscription-based software licenses, maintenance and consulting, according to one description.

Kirsten Davies, the Department of Defense’s chief information officer, said in the release that the agency is saving at least $441 million for taxpayers “by fundamentally improving how we procure on-premises Oracle capabilities.”

The government’s big enough to build its own

By rsilvergun • Score: 4, Interesting Thread
They could just hire people to do it and then the fruits of that labor could be available to everyone as open source. As an added bonus we wouldn’t be constantly paying for the profitability of private companies for no particularly good reason. And we wouldn’t be creating billionaires that are going to undermine our democracy.

But something something socialism so here we are… All of us stuck with shit software that constantly spies on us

Where are the savings coming from?

By ClickOnThis • Score: 5, Insightful Thread

Kirsten Davies, the Department of Defense’s chief information officer, said in the release that the agency is saving at least $441 million for taxpayers “by fundamentally improving how we procure on-premises Oracle capabilities.”

So, it’s $441M saved, by improvements in procurement. Not sure what that means. Does that mean Oracle gave them a $441M discount, or they found a way to reduce $441M in wasted money on the procurement process? Or something else?

In any case, this sounds like puffery.

High quality

By phantomfive • Score: 5, Funny Thread
No doubt they will get high quality products and services as a result. Oracle provides nothing other.

How much consultant wii that get the Pentagon?

By thesjaakspoiler • Score: 3 Thread

Larry Ellison can at least afford another island in Hawai with this deal.

Great news!

By jenningsthecat • Score: 3 Thread

Great for America’s enemies, that is. If even a quarter of what I’ve heard about Oracle’s offerings being over-budget, never-on-time, never-on-spec shitshows is actually true, then this will weaken the country’s defense capabilities.

Then again, it’s no longer the DoD, it’s now the DoW - so maybe defense is no longer important? /sarc

Microsoft Responds to LG Monitors Installing McAfee Ads On Windows

Posted by BeauHD View on SlashDot Skip
LG is removing a McAfee pop-up ad from its LG Monitor App Installer after criticism that some LG monitors were silently installing the app through Windows Update and showing ads on every boot. Microsoft says LG agreed to disable the McAfee pop-up, but the broader issue remains: Windows allows certain peripheral companion apps to install automatically without notifying users. Ars Technica reports:
Following Gamers Nexus’ video, a Microsoft representative stated that the LG Monitor App Installer will no longer show pop-up ads for McAfee. In response to a social media post about the app, Pavan Davuluri, EVP of Windows and devices at Microsoft, said this week: “We’ve connected with the team at LG and as an immediate next step, they have agreed to disable the McAfee pop-up from their app. We appreciate LG working with us toward a shared goal of a better experience for our mutual customers. We will keep improving here with our ecosystem partners.”

As mentioned, some LG monitors appear to have been installing LG Monitor App Installer onto Windows computers for months. Publication Windows Latest noted that the app recently got an update, “and its changelog mentions McAfee as an additional app,” which could be what prompted more people to see the ads… and then complain about them. However, the removal of McAfee doesn’t address the problem of a peripheral installing ad-pushing software onto people’s computers.

Users have been finding LG Monitor App Installer and its ads on their systems without LG ever showing a prompt or asking for permission. LG has some of the most expensive computer monitors available. Paying, in some cases, over $1,000 for a monitor that ends up forcing ads onto Windows is disruptive and a privacy concern. Once the app is installed, “LG technically possesses permission to use ‘all system resources,’" as well as to “collect geolocation, device data, online activity, contacts, user credentials, transactions, and more,” [editor-in-chief of Gamers Nexus, Steve Burke] said.

Security Vulnerability

By locater16 • Score: 5, Insightful Thread
A security vulnerability just directly into admin privileges bypassing every possible check. Perfect, 10/10, no notes.

I’m not a fan of Microsoft

By rsilvergun • Score: 5, Informative Thread
But from what I understand they don’t allow you to do what LG did. It’s explicitly forbidden in the guidelines for a Windows certified driver.

I don’t know what made LG think they could get away with this nonsense. Every single tech YouTuber on the planet has gone crazy reporting this.

So they promise nobody will notice next time?

By ffkom • Score: 5, Insightful Thread
I have a good idea how that conversation between Microslop and LG went:
“MS: Hey, by suddenly showing Ads you exposed the back-door we built for our vendor’s club! Don’t do that!”
“LG: Sorry, our bad, our marketing department didn’t know the back-door was only meant for spying on the users and sending their data to our servers. We promise to not be caught next time!”
“MS: All good. But don’t forget the the user’s data is ours to sell, so only looking, no selling, understood?”

Re:Security Vulnerability

By gweihir • Score: 5, Insightful Thread

“Literally required”? Such nonsense. Sane driver installation is just as subject to sysadmin consent as all other software installation. What do you think how this goes if somebody manages a supply-chain attach on this, especially on, say, an industrial control system that cannot simply be turned off?

Re:Security Vulnerability

By Local ID10T • Score: 5, Insightful Thread

Windows has built-in default drivers that work for most standard device types. Installing the specific driver package that includes advanced features specific to a particular make/model of the device should be something that the user has control of.

A monitor will work with default drivers. A mouse will work with default drivers. A keyboard will work with default drivers. The special features may need an application installed. Windows Update can detect the device ID and offer to install the software for it, but it should not install it without user consent.

I think that it does work this way for most things.... In Windows Update, you have to enable optional updates to get 3rd party driver updates. I don’t see why the LG monitor drivers would be mandatory.

EU Fines Google $1 Billion For Breaking Digital Antitrust Regulations

Posted by BeauHD View on SlashDot Skip
The European Union fined Google more than $1 billion for allegedly using Google Play and Search to steer users toward its own services and apps at the expense of competitors. The Associated Press reports:
Google had recently lost its appeal of a $4.5 billion antitrust fine imposed by the EU for throttling competition and reducing consumer choice through the dominance of its mobile Android operating system. The European Commission, the bloc’s executive branch and highest antitrust enforcer, said it was acting in the interest of consumers after an investigation of Google.

“The best products should succeed because they’re better, not because they’re owned by the company running the search engine. And European consumers have a right to be told by app developers where to sign up to the best offers, even when the app store owner does not get a cut,” said Teresa Ribera, the commission’s Executive Vice President for Clean, Just and Competitive Transition.

Google’s President of Global Affairs Kent Walker blasted the fine as “product degradation driven by a small group of self-serving complainants” that will have a negative impact on European businesses and consumers. He said that the EU’s Digital Markets Act forces Google “to strip away real-time search features Europeans love — like instant pricing and direct availability for hotels, flights, and restaurants — and dismantle safety protections on Google Play.”

Not unexpected.

By NoOnesMessiah • Score: 4, Insightful Thread

So Google’s mouthpiece responds with Fear, Uncertainty, and Doubt (FUD) as a matter of course because that’s what they always do. Google is just one great example of why The European Union needs to worry about it’s own digital sovereignty. Too bad a billion-dollar fine won’t make much difference in their “Be Evil” product strategy. Late-stage capitalism at its finest, where “growth at any cost” is not just the ethos or logos of a cancer cell. Go Euro Commission. American companies pretty much suck at this point and they’re not afraid to act up, even internationally. You do what you gotta do.

“dismantle safety protections on Google Play”

By duerra • Score: 4, Interesting Thread

aka Google-speak for “they haven’t installed non-Play or sideloaded apps on their device.”

Re:Have to wonder

By ArchieBunker • Score: 4, Funny Thread

No, you’re just shocked that a government can enforce laws against mega corps.

Amazon Is Bringing Games to Prime Video

Posted by BeauHD View on SlashDot Skip
Amazon is integrating its Luna cloud gaming service into Prime Video, adding a new “Games” tab where Prime members can play titles like “Hogwarts Legacy,” “EA Sports FC 26,” “Indiana Jones and the Great Circle,” “Clue,” and “Taboo.” The games will be available starting today on Fire TVs in the U.S. and U.K., with additional supported devices and countries in the coming months. TechCrunch reports:
With this move, Amazon is hoping games can turn Prime Video into a one-stop entertainment destination, borrowing a strategy from Netflix, which has increasingly embraced party games over the past several years. Since Amazon already operates a gaming service, it makes sense for the tech giant to integrate it into its streaming platform. […] Amazon says its vision is to remove the barriers to gaming and make it accessible to anyone regardless of their experience or budget. The tech giant says Luna is designed to bring gaming to a much broader audience by removing the need for expensive consoles or gaming PCs and making games as easy to access as movies or TV shows.

As if we didn’t have enough clutter

By devslash0 • Score: 4, Insightful Thread

It’s called Prime VIDEO for a reason. We go there to watch films and series. The interface is already cluttered with useless recommendations beyond belief and finding anything worth watching borders on impossible. If you want to add games, publish a separate app.

no thanks

By satanicat • Score: 3 Thread

I’ve had prime for a while, and recently tried Luna with my nieces and nephews, since its included. My opinion of the platform isn’t great.

For context we have a pretty reasonable internet connection (it’s not glass, but we don’t have issues with Console and PC gaming), and I did so on Amazon hardware, a Firestick and Luna controller. We tried Hogwarts, a Fallout game and a goat simulator game. Very little of it was what I would call reasonably playable. It left me questions about things like were we perhaps accessing it during peak times? Could neighbour’s usage (e.g. streaming) be affecting our experience? is there a higher level tier you can pay for? (and we were getting an F2P experience)

I’ve no interest in the concept, I’d rather play games on my own hardware. But I’ve been looking at streaming games with a sort of curiosity because I’ve heard people say it’s getting better. I think it’s got a ways to go, and I sort of hope it turns into one of those things that never really catches on.

It’s like landscaping services at a strip club.

By Somervillain • Score: 3 Thread
Ugg…why?....Sure…good games for the price of Prime I suppose is a good thing, but with the exception of Sony/XBox, every gaming subscription service I’ve seen sucks. The Apple Arcade has maybe 2 or 3 games I’ve enjoyed and I’ve honestly never heard of anyone liking it. Netflix has their games…equally pointless, more gimmickey....but regardless....who the fuck wants this? Also, in every case, the games I recognized were already free to play or super-cheap. Games Pass gives you real games that were huge hits....it provides immense value if you like those game. In fact the lack of an equivalent of one on the Switch is the only thing keeping me from running out and buying a Nintendo Switch 2 right now!!! I love the hardware, but WILL NOT spend $70 per game for 2 weeks of entertainment.

Look, we’re adults…new features cost money. I’d rather you don’t offer me games and maybe play a few less intrusive ads in your HORRIBLE streaming service? I really love the Boys and Invincible…but beyond that?…eh…there’s gotta be something good in there…I just don’t know of any, nor has anyone raved about their series. I think most would rank them maybe #5 among the streaming services?

Offering gaming with video streaming is kinda like offering landscaping services at your local strip club. They’re very different audiences with very different needs. I don’t see any benefit or synergy.

If Amazon wanted to start their own XBox games pass rival as a separate product?…that could have some traction…but giving away shitty mobile games in prime?…why? Either keep your costs down or give us something we want…A PC-based Games Pass rival could potentially be interesting…a Nintendo-Switch based games pass would be amazing if done decently…shitty mobile games?..no!

Sony’s Decision To Ditch Discs Was Practically Inevitable, Data Shows

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from Ars Technica:
Many gamers have been lamenting Sony’s recently announced decision to halt sales of physical game discs in 2028. However, new data revealed by Circana analyst Mat Piscatella highlights how years of stark economic trends helped lead Sony to that decision. In a social media thread Thursday morning, Piscatella shared insights into Circana’s tracking data on physical game sales in the U.S. dating back to 2003. A graph of those trends shows physical sales peaking in the 12 months ending June 2009, when 297 million units were sold across the US. Those physical unit sales have been on a steady downward trajectory since then, leading to just 37 million physical units selling in the U.S. in the last 12 months.

The newly revealed data follows on an earlier post from Piscatella highlighting that only seven PlayStation games had sold over 100,000 physical units so far in 2026. Today, Piscatella followed up on that stat with a graph showing how this baseline used to be common; 100 PlayStation games sold at least 100,000 physical units in 2008. The ceiling for physical PlayStation game sales isn’t all that impressive these days either; Piscatella shared that the top-selling physical PlayStation game has only sold a paltry 275,000 units in the U.S. so far this year.

There are some small signs of hope for the physical game market, if you squint. Piscatella noted that aggregate spending on physical video games in the U.S. was actually up 4 percent year-to-date, compared to the year before. But that small increase is a mere blip following 16 straight years of sizable declines in physical game spending in the US, reducing a peak of $11.5 billion in physical spending in 2009 to a mere $1.6 billion for the 12 months ending in May. And Piscatella attributed the recent growth in physical spending to “the Switch 2 and physical sales growth on Nintendo platforms,” while other platforms (such as PlayStation) were still seeing “percentage drops from the teens to the mid 30s” in that spending.

The Real Issue

By TwistedGreen • Score: 3 Thread

It wasn’t inevitable, but it’s true that the discs were just tokens at this point: full of outdated software that needed a multi-GB patch to get working, or just a stub containing some artwork and a license key. PC games haven’t really shipped on discs in years, if not decades. Sure, you could buy the disc, but it would be useless once the “CD key” was bound to your account. At a certain point you just give up and buy the keys. The last PC game I bought on disc (DOOM in 2016) came with the discs in a nice Steelcase, but I didn’t even use them, I just added the CD key to my Steam account and kept the discs as a display piece.

This isn’t such a bad deal, but the difference here is Sony’s user-hostile policies. We’ve seen multiple times that content that you allegedly purchased can just disappear from your library with only cursory warning because they failed to re-negotiate distribution rights. This should not be happening.

Take Steam as a counter-example. I own many titles that have been delisted, originally published by a company that went out of business, was purchased by someone else, re-published under a new listing… yet I still “own” the original title. It’s still in my library. I can still download and play it, even if it’s broken on Windows 11 and I need to start up a VM or spend hour applying mods to get it to work. I’m not privy to all the horse trading that goes on when they negotiate these contracts, but I have some trust in Valve that they won’t screw over their users to save a few bucks.

I know I don’t really own it—I never did—but I have my copy and a few implied rights that they won’t take it away from me at a whim. That’s all people ask, and nobody trusts Sony to deliver.

Actually a huge money-maker, just not for them

By CEC-P • Score: 3 Thread
One drop, scratch, snap, or general wear from an un-cautious person and that full priced game has to be bought a 2nd time. I never liked physical media that wasn’t in cartridge form very much. However, I think Sony’s logic here was you’d buy a replacement from the secondary market and the money then doesn’t go to them so nuke the whole thing.

In a First, Apple Maps Navigation To Be Embedded In Ford UEV Pickups

Posted by BeauHD View on SlashDot Skip
Ford will become the first automaker to embed Apple Maps directly into its vehicles, starting with an all-electric midsize pickup built on its new Universal Electric Vehicle platform. “The pickup — with Ford testing preproduction models on roads now — is expected to start at $30,000 when it comes to market in 2027,” reports the Detroit Free Press. “Ford has said several other EVs off that platform will follow, including a small all-electric SUV.” From the report:
Ford CEO Jim Farley said the new EVs will redefine advanced technology as simple, useful, and at a price point that is attainable for most people. “We’re proud to embed Apple Maps’ navigation and mapping technology directly into our Universal Electric Vehicle Platform, giving customers the ultimate navigation experience alongside our Ford app, a full suite of software, and next-generation BlueCruise, all enabled by a new zonal architecture,” Farley said in a statement. “Apple Maps has delivered a world-class product, and we’re honored to be among the first to embed it directly into a vehicle, helping define intuitive, capable driving.”

In a joint statement, Apple and Ford said the integration will deliver a “beautiful and easy-to-use navigation experience powered by Apple Maps directly to the vehicle’s displays. Road-level Maps information will also enable Ford’s Latitude AI team to build a seamless hands-free driving experience.” Ford said it will use that road information to develop its next-generation BlueCruise hands-free highway driving capability. Also, by leveraging Apple’s new MapKit for Automotive SDK, Ford’s UEV Platform will offer drivers turn-by-turn directions using natural language, real-time traffic information, intuitive search and routing options for the best route. The system will give drivers EV routing functionality to help drivers with the warming and cooling process of the vehicle’s battery before driving or fast-charging.

Will I still be able to use alternatives?

By ardmhacha • Score: 4, Interesting Thread

Can I use Android Auto to use my preferred navigation software?

I hope these Apple enabled Fords are amphibious

By Hank21 • Score: 3 Thread
https://kiss951.com/2023/07/05…

Four Young Mathematicians Awarded the 2026 Fields Medals

Posted by BeauHD View on SlashDot Skip
Scientific American reports that the 2026 Fields Medals went to four mathematicians for work ranging from the theory of knots to the motion of fluid:
The Fields Medals went to Hong Wang of New York University and France’s Institute of Advanced Scientific Studies (IHES), Yu Deng of the University of Chicago, John Pardon of Stony Brook University and Jacob Tsimerman of the University of Toronto. In the awards’ 90-year history, Wang is only the third woman to win one, after mathematicians Maryam Mirzakhani and Maryna Viazovska in 2014 and 2022, respectively. Wang and Deng represent the prizes’ only Chinese-born recipients besides mathematician Shing-Tung Yau, who won a Fields Medal in 1982.
Hong Wang co-proved the three-dimensional Kakeya conjecture, establishing a fundamental limit on how little space is needed to rotate a line through every possible direction. Mathematician Nets Katz called it the field’s “holy grail” problem and said the achievement made her “a central figure” in the area.
Yu Deng and his collaborators reconciled the microscopic and macroscopic mathematics of fluid motion, proving that equations describing chaotic molecular interactions and large-scale fluid behavior are fundamentally connected. N.Y.U. mathematician Scott Armstrong called it “a truly spectacular, singular result.”

John Pardon made an early breakthrough in knot theory by proving that certain sequences of knots can have arbitrarily large “distortion,” a measure of how difficult they are to traverse. Princeton mathematician David Gabai said the problem had “attracted much interest among mathematicians during the previous 25 years.”

Jacob Tsimerman and two collaborators proved the Andre-Oort conjecture, giving mathematicians a stronger way to understand special points on complex geometric objects known as Shimura varieties. Collaborator Jonathan Pila described him as “a brilliant mathematician” known for his “brilliance and resourcefulness.” Tsimerman has also advanced Hodge theory and hopes pure mathematics can help researchers better understand AI.

A bit more about Kakeya

By JoshuaZ • Score: 5, Informative Thread
A bit more about the history of the Kakeya problem, which Hong Wang worked on. It comes from originally a more concrete question, namely how small an area do you need to rotate a 1 unit long needle 360 degrees if it is allowed to also move around as you rotate it? The naive thing is to use a circle, but you can also do a bit better by using a triangle, and then rotating it a little bit at the corner, moving the needle to the next corner, and then continuing the rotation. But you can do a bit better than this by cutting out small regions from the sides of the triangle. You instead use a deltoid https://en.wikipedia.org/wiki/Deltoid_curve. Kakeya asked if this was the best possible construction But Beiscovitch made a very clever construction to show that there is no minimal area. That is, for any epsilson>0, you can make a region of area less than epsilon where you can rotate the need. https://en.wikipedia.org/wiki/Kakeya_set#Besicovitch_needle_sets . Thinking about these ideas in abstract settings and higher dimensions lead to what was called the Kakeya conjecture, even though it post-dated Kakeya’s own work. Hong Wang Joshua Zahl (not me, different mathematician with the same first name and last initial) proved that conjecture.

packaging

By noshellswill • Score: 3 Thread
No mathematician myself … I  can imagine  useful applications of this work for “packaging”  tasks, where  surface area translates into cost.

Re:A bit more about Kakeya

By JoshuaZ • Score: 5, Informative Thread

I think I can explain this. I’m not sure how well, I’ll do but I can try.

For “nice” objects, we all have an intuition about how many dimensions the object is, which is roughly how many variables it takes to specify a given location on the object. For example, on a line embedded in your standard Cartesian two dimensions, say y=3x+2, you can just tell someone the x coordinate and they know exactly where they are. This works in general, so typical 3 dimensional space needs 3 coordinates. Etc. Similar, a circle (even though it lives in 2 dimensions) just needs 1 variable to tell someone where you are on it because you can take an angle from the center.

However, lots of objects turn out to have a notion of dimension that doesn’t quite match up this way. This is roughly what people mean when they call something a “fractal” (although some people use fractal more to mean a thing deifned by a recursive procedure. Defining it precisely is tough.) Now, to talk about objects that are fractals, like say the Koch snowflake https://en.wikipedia.org/wiki/Koch_snowflake we want a notion of dimension that makes sense for them. Ideally, for a given object we want a notion of “dimension” which gives the correct value of dimension when we apply it to an object that is a traditional object with a known dimension, like a line, or sphere or ball. The Minkowski dimension is one such approach. It is easiest to explain in 2 dimensions, but the same basic idea looks in any number of dimensions. Roughly speaking, you take the object you want, and you pick some tiny number epsilon, and then you make a grid on the plane of little boxes each which are epsilon by epsilon, and then you ask how many tiny boxes does it take to cover the object? Then, you take that number and divide it by log (epsilon), and then you let epsilon go to zero. This essentially measures how pointy thick the object is. If the object is thick this will just be two. If it is just a few isolated points (even infinitely many but not a lot) this will be zero. It isn’t obvious that this is the right thing to count but turns out to work pretty well. You then generalize this to any number of dimensions for your space your object lives in by using boxes of the corresponding dimension number. So, for a fractal which lives on the real line, you use intervals of length epsilon, in 3 dimensions you use cubes of side length epsilon and so on.

Now, the Minkowski dimension is not the only notion of dimension we have that works this way. There’s a related idea called the Hausdorff dimension which is defined in a more complicated fashion but turns out to often be easier to calculate. For example, it is not too hard to show that the Hausdorff dimension of the Koch snowflake is (ln 4)/(ln 3) which is about 1.26. (This reflects the intuition one might have that the Koch snowflake is much closer to being a thing made of lines than it is to being a thing with normal area). Now, it turns out that the Minkowski is always at least as large as the Hausdorff dimension, and they are equal in many situations. But there are some annoyingly simple situations where they are not. For example, if you take the interval of points between 0 and 1 and just take the rational points, then it has has Hausdorff dimension zero and Minkowski dimension one, which is about as far as you could want. Sometimes we’ll calculate Haussdorff dimension for an object but really care about the Minkowski dimension, where finding that takes more work.

In the case of Hong Wang’s work. She and Zahl proved that if you had what is called a Kakeya set in 3 dimensions (where you want a set that can fit a needle in every direction but you don’t care about rotating it around, you just want a needle to fit at any orientation you choose), is that the Haussdorf dimension of the set, and the Minkowski dimension have to be equal and in fact equal to 3. But note that this isn’t obvious in part because one doesn’t have the rotation requirement here.

Does that help/make sense?

Startup Founders Urge Trump Not to Shut Off Chinese Open Weight AI

Posted by BeauHD View on SlashDot Skip
Nearly 200 Silicon Valley companies, including Proton and Y Combinator, are urging the Trump administration not to block U.S. access to Chinese open-weight AI models or risk crippling the next generation of U.S. startups. Politico reports:
On Wednesday, the newly-formed Little Tech Association sent letters to President Donald Trump, Commerce Secretary Howard Lutnick and others in the administration with its appeal, marking the first coordinated effort by Silicon Valley’s wider influential startup community to weigh in on one of the Trump administration’s most closely watched AI debates. At issue: whether Washington should restrict access to increasingly powerful open-weight — meaning, AI models whose weights are publicly available — AI models released by Chinese companies such as Moonshot AI and Alibaba.

“American leadership requires two things: world-leading American open-weight models and continued access for U.S. builders to open models already available worldwide,” the startup founders wrote in the letter (PDF) obtained by POLITICO, also sent to Office of Science and Technology Policy Director Michael Kratsios. Instead of broad prohibitions, they argue the government should adopt targeted safeguards.

And they warn that banning Americans from downloading Chinese open-weight models wouldn’t stop their proliferation — but would weaken U.S. startups. “There’ll be hundreds of companies that instantly die,” said Suhail Doshi, founder of AI infrastructure startup Particle and a member of the association, which POLITICO first wrote about exclusively, in an interview. “It’s great for Anthropic. We’re all going to have to spend money on Anthropic.”
Last week, the Beijing-based AI company “Moonshot” released a massive new model that reset the AI race overnight, immediately vaulting into the top tier of global AI, beating Anthropic’s Fable 5 and OpenAI’s GPT-5.6 Sol in front-end coding tests.

China’s Xi Jinping also used his first appearance at China’s World AI Conference to promote a vision of low-cost, broadly accessible AI and call for international cooperation rather than technological rivalry.

America can’t compete

By Anonymous Coward • Score: 5, Insightful Thread

China leads in 5G; America blocks it for “security” reasons
China leads in social media; America forces Tiktok to be sold to American oligarchs
China leads in EVs; America blocks them for ? reasons
China leads in affordable AI; America blocks it for “security” reasons

Re:Wait a minute.

By Brain-Fu • Score: 5, Interesting Thread

What you are saying seems intuitive, but doesn’t really fit the facts.

This Chinese model outperforms existing models in some objective testing, as it was reported. I didn’t dive in, so maybe that is a lie. But if it is true, what we have here is China investing tremendous resources into taking the logical next step in the development of AI (a bigger model from more training), which hardly qualifies as a “knock off.” And anyway, the training techniques that generate AI were invented in Germany and Canada, not the USA. Lastly, by freely sharing it with the world, they aren’t making any money off this, and so aren’t gaining any kind of competitive advantage.

It is possible that they poisoned the training of the model with special keywords that could jailbreak it and motivate it to take action that would benefit China (should it find itself in a hosting environment where such action is even possible). Something like that would be a reason to distrust it. I know that such training poisoning is possible but I don’t know realistic it is that the jailbroken version would be able to reliably determine what actions benefit (and do not accidentally harm) China. Hosting environments can always lie to the model and give it an incorrect context. It makes it unlikely that such a thing would be attempted, in this case.

It is possible that China is trying to destroy Anthropic, Google, and OpenAI by offering a free alternative that is superior to theirs. On the one hand, if true, then all that means is that these other companies will have to double down and come up with something even better. On the other hand, the open source movement in general has failed to destroy any of the closed-source companies, despite superior offerings, so it seems like such a plan is futile.

On the surface this looks like China is just acting in a manner consistent with its Communist idiology: they provided according to their ability and are now distributing according to the need, worldwide. I won’t fault them for being consistent, but I do recognize that they have some serious economic problems right now and so spending this kind of money on something that is not galvanizing their economy seems unwise, to me.

Re:America can’t compete

By 0123456 • Score: 5, Insightful Thread

> IP theft and subsidies are how they cheat.

You mean IP theft like scraping the Internet, downloading masses of illegal copies of books, feeding it into your algorithm and then claiming to own it?

Re:They’ll get what they’re asking

By jacks smirking reven • Score: 5, Informative Thread

Regardless of whether is is true or not can we once again take some time to remember how completely fucked it is that the current sitting President of the United States operates his own crypto coin. That the admin built an official untraceable bribe machine and it’s not even the only one!

Re:Wait a minute.

By allo • Score: 5, Informative Thread

They win in ELO ranked leaderboards where people test models and choose the better output. You can’t fake that.
They are second best in benchmarks, but the rankings for coding, frontend design, etc. for the leaderboards are nothing you can benchmaxx for.

Researchers Discover First Known Transmissible Cancer In Fish

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from CBC News:
It’s rare that cancerous tumors can spread from one individual to another. But a genetic study suggests that’s what’s happening with melanoma tumors among catfish in Quebec and the northeastern U.S. The discovery represents the first known transmissible cancer in fish and one of very few transmissible cancers ever found, reported the study published in the journal Nature on Wednesday.

Julie Dragon, co-leader of the new study, noted that only three other transmissible cancers have ever been identified so far — in Tasmanian devils, dogs and shellfish. “These conditions are incredibly rare in nature,” she said. “So something has to be happening to allow this to happen.” Anglers in Lake Memphremagog, which spans the border between Quebec and Vermont, first reported catching brown bullhead catfish with strange black spots and lumps in 2012. They turned out to be melanoma skin cancer tumors. (Humans can also get this kind of cancer.) Now, about a third of the brown bullheads living in the lake have them.

It’s not clear how sick the fish become. In some cases, the cancer spreads to other organs, such as the brain or liver. But many fish with lesions seem relatively healthy and some older fish even have them, suggesting they can live with the disease for a time. Because of the sudden appearance of the black lesions in Lake Memphremagog the year after a huge flood caused by post-tropical storm Irene, locals worried they were caused by carcinogens washed into the lake by floodwaters. Tests for carcinogens haven’t been conclusive, although a study published in May found higher concentrations of seven metals, including zinc and the carcinogen arsenic, in the skin of fish with the tumors.
Researchers suspect the tumors may spread among adult fish during spawning, when crowded fish rub against one another and may be punctured by their spines.
“They… swim all over each other and we think it’s possible that they poke each other and cells can get into other fish that way,” Dragon said, though transmission has not yet been demonstrated.

Oddest thing about transmisitable cancers

By gurps_npc • Score: 3 Thread

These are not a cancer that causes other individuals to develop cancer. Instead there was this one individual that got the cancer and their cells managed to transplant themselves to another individual and thrive.

Often long after the original individual dies, as in known to be the case with the dog cancer.

This means that if you identify beings by genetics, there currently exists a sub-species of ‘dog’ that has no brain, bones, or teeth. It is just a bunch of flesh that is travelling about, attached as a parasite to regular dogs. In some ways, it is more like a plant.

Theoretically, this ‘dog’ may never die. Apparently, not all dogs go to heaven. ;)

Maybe not to individual people, but …

By Ungrounded Lightning • Score: 3 Thread

… a bunch of cancer progression theories based on cell culture progression had to be thrown out when it was discovered that the cultures were being contaminated by a particularly robust and aggressive cancer cell culture, HeLa, which had contaminated lab equipment like environmental chambers or survived equipment sterilization and eventually took over culture lines in labs.

Verisign Is Finally Bringing .web Domains To the Internet

Posted by BeauHD View on SlashDot Skip
BrianFagioli writes:
Verisign is finally bringing web domains to the internet after a decade of fighting. Verisign says the .web top-level domain has finally been delegated into the DNS root, clearing the way for public registrations later in 2026. Until now, consumers could not buy normal working .web domains, despite the extension attracting a record $135 million winning bid in 2016. The launch could make .web one of the more recognizable alternatives to .com, but Verisign already operates both .com and .net, raising questions about whether this creates real competition or simply gives the dominant registry operator another valuable extension.
The decade-long fight began after a company called Nu Dot Co won the rights to operate .web in a 2016 ICANN auction with a record $135 million bid secretly funded by Verisign. Rival bidder Afilias, which was later acquired by Donuts, challenged the sale, arguing ICANN should have investigated the relationship before allowing the auction. This triggered years of complaints, reviews, and legal disputes that have ultimately now been resolved under undisclosed terms.

Beat the rush: blacklist the entire TLD now

By Arrogant-Bastard • Score: 5, Insightful Thread
Like every other unneeded and unwanted TLD that’s been introduced in the last decade-plus, this will be overrun by spammers and scammers within days. There will be millions (if not tens of millions) of domains registered, used once/burned, and discarded. Since even attempting to deal with these on a case-by-case is simply unworkable, a much better choice is to preemptively blacklist them all permanently and get on with doing something productive.

Re:www.slashdot.web

By Comboman • Score: 5, Insightful Thread

>> I mean what’s added in meaning for replacing shop.walmart.com with www.walmart.web.

If the owner of walmart.web is not Walmart but is hoping people think they are, I imagine a great deal of value could be extracted from it.

https://www.tautology.web.dns.internet

By greytree • Score: 4, Funny Thread
Do the people buying these domains live on Main Street Road, Town City ?

Re:but you don’t want scammers to own bankofameric

By Zocalo • Score: 5, Insightful Thread
Which is why, as many people pointed out at the time the root servers were opened up to all these new gTLDs, that this is just a license for the successful registrars running each gTLD to print money at the expense of everyone with a brand they have to protect. In most cases, they were absolutely right on the money; .biz being the classic example, almost immediately becoming a wretched hive of online scum and villainy most mail server operators equally rapidly blocked outright. (I am curious though; does anyone actually try and host a legit .biz domain these days? I don’t think I’ve ever come across one.)

I’ll give you, there are some pretty cool options for host/domain names under .web, especially with an arachnid theme or things like “web.web.web”, that might become useful and popular for some groups, but apart from those - which Verisign, being Verisign, will no doubt have a special procurement process for to maximise their investment - the rest will almost certainly be parked/redirected brandname protection, a vast number of of scammer sites, and a handful of vanity projects that 99.99% of people probably won’t even know about, and probably wouldn’t care about if they did.

None of which changes the fundamental point that we seldom care about URLs any more. We click on links in apps, webpages, emails, etc., ideally having done some kind of due diligence to make sure the link is hopefully OK, or just cut and paste from the browser bar to put it into something we are writing. Functionally, “bankofamerica.com” is no different from “bankofamerica.web”, or any other gTLD/ccTLD they might care to suffix it with, and it wouldn’t make any difference to their service if all the other TLDs went away, unless they wanted to do some kind of content localisation based on a ccTLD rather than some other approach to achieve that.

I know GLWT, but this has to stop

By drinkypoo • Score: 4, Insightful Thread

This triggered years of complaints, reviews, and legal disputes that have ultimately now been resolved under undisclosed terms.

They suck a huge amount of money out of the court system and then We The People who paid for that don’t even get to find out what the outcome was? The courts sure as fuck don’t work for us.

Private Mission Launches To Extend Life of Out-of-Gas Communication Satellites

Posted by BeauHD View on SlashDot Skip
Northrop Grumman has launched a private satellite-servicing mission to attach life-extending “jetpacks” to aging communications satellites in geosynchronous orbit. “It’s the second satellite-saving mission to launch this month, all part of a growing, money-saving effort to keep spacecraft running as long as possible,” reports Phys.org. From the report:
Launched by SpaceX, Northrop Grumman’s mission robotic vehicle — dubbed MRV — and its jetpacks will spend the next year angling into the proper orbit 22,300 miles (36,000 kilometers) above Earth. Hundreds of satellites orbit at this so-called geosynchronous orbit, where they match the speed of Earth’s rotation and keep to the same part of the sky for continuous coverage. Once in place by mid-2027, the minivan-sized spacecraft will use its 10-foot (9-meter) arms to attach a jetpack to an aging communication satellite. Then it will zip off to two more satellites in need.

For its debut flight, the spacecraft was accompanied by three electric-propelled jetpacks that peeled away separately following liftoff. Like the MRV, the jetpacks will use their own xenon gas thrusters to get to the desired orbit. Once in place, the jetpacks will wait for the robot to grab them, one at a time, and plug them into their designated satellites. Each jetpack — the size of a washing machine — will provide the necessary oomph for an out-of-gas satellite to keep operating for several more years instead of retiring. If it works, it will be a boon for satellite operators SES of Luxembourg and Optus of Australia, saving them millions of dollars in replacement costs.

Re:Math

By T34L • Score: 5, Interesting Thread

The thrust to weight and specific impulse of ion thrusters, as well as the power to weight capability of the solar panels that’ll be powering them, have actually been changing a lot, and that really shrunk the payload needed to make one of these “jetpacks” useful. The cost of the orbital launch per unit of mass changed less than what we can do with the mass once it’s in orbit.

Re:dual use

By T34L • Score: 5, Informative Thread

That’s like saying a Toyota Prius is dual use because you can drive one up to infantry standing against a wall and slowly crush them using it. Every military even remotely competitive at the orbital theater has incomparably cheaper and more reliable ways to disable satellites than to gently de-orbit them using a vehicle designed for sustained operation with very low acceleration requirements.

If there’s any military utility, it’d be to attach devices that could intercept or tamper with communication going thorugh the satellite, but even that feels like hell of a stretch considering how expensive and difficult it would be and considering the moment the target notices you did that, you might have just as well just disabled the satellite at fraction of the effort, because at that point it’s not like your enemy will keep using the bugged satellite.

Mission Extension Vehicle

By Geoffrey.landis • Score: 5, Informative Thread

Also worth noting that this follows on from the earlier Northrup-Grumman “Mission Extension Vehicle”, which in 2019 launched to dock and reposition Intelsat 901, a first for a telerobotically operated spacecraft.
https://en.wikipedia.org/wiki/…

Some sites:
  https://www.northropgrumman.co…
  https://news.northropgrumman.c…

Coincidentally, Northrup Grumman was also involved in the SWIFT reboost mission, launched the beginning of this month, tp extend the lifetime of the Swift orbital telescope by boosting it into a higher orbit. (In this case, though, they didn’t build the spacecraft, just provided the launch service, on a Pegasus)

https://www.cbsnews.com/news/n…

Re: Math

By jddj • Score: 4, Funny Thread

They’re accelerating VERY rapidly. In between the time that the Europeans read this and the time Americans see it, there’s relativistic length contraction.

Pan Am Plane Crash That Inspired Modern Safety Briefings Found After 74 Years

Posted by BeauHD View on SlashDot Skip
Longtime Slashdot reader BeaverCleaver shares a report from the BBC:
The wreckage of a Pan American Airways plane has been found 74 years after it plunged into the Atlantic Ocean in a crash that prompted mandatory airline safety briefings. The Clipper Endeavor was found 2,000ft (610m) below sea level off the coast of Puerto Rico with a sonar-equipped drone. It went down on April 11, 1952, following multiple-engine failure shortly after take-off.

Everyone onboard survived the impact — but passengers struggled to locate life vests and rafts as the plane rapidly sank. Of the 69 passengers and crew onboard, just 17 survived. The disaster led to sweeping reforms in aviation safety, including compulsory pre-flight safety briefings on every commercial flight. […] Today, before every commercial flight, cabin crew are required to outline where a plane’s exits are, as well as the location of life vests and how to inflate them.

Sully’s Hudson Landing

By drnb • Score: 5, Insightful Thread
Actually Sully’s Hudson Landing might be a good example of how effective those briefings are.

How many of today’s passengers not paying attention have heard the briefing before? Or through osmosis learn their life vest is under their seat?

Re:Sully’s Hudson Landing

By CommunityMember • Score: 5, Interesting Thread

Actually Sully’s Hudson Landing might be a good example of how effective those briefings are.

I would argue that the flight attendants “screaming” at the passengers as to what to do were far more effective than the briefing itself (but because the flight attendants were trained on safety and safe evacuation, they knew what to scream). From having some emergency response training, I have learned that most people, in an emergency, are sheep, and will follow any directions that seems to be reasonable (given they, themselves, are in a panic and really don’t know what else to do, and are willing to accept that someone else might know, so follow the direction). Sully may have made some great decisions, but the flight attendants were, in many ways, among the heroes of that incident in the saving of lives.

Re:Sully’s Hudson Landing

By drnb • Score: 5, Insightful Thread

…but the flight attendants were, in many ways, among the heroes of that incident in the saving of lives.

Absolutely, but I can’t help but expect that the flight attendants were not overwhelmed because enough passengers had existing knowledge from past flights and/or osmosis. That some competency among the passengers allowed them to focus on the less competent.

Wikipedia link

By BeaverCleaver • Score: 5, Informative Thread

I should have thought to look on Wikipedia before I made the submission. There’s some more detail about the accident at https://en.wikipedia.org/wiki/…

According to witnesses, many passengers refused leave the sinking aircraft to get into the life rafts. I’m not sure how a modern safety briefing is going to fix that. But I can also see how going down quickly with the sinking aircraft might be preferable to a slow death at sea from exposure, or a painful death by shark attack. In this case, it turns out that the rescue was very very fast, but in the 1950s such a rapid rescue was probably much more rare.

Re:Sully’s Hudson Landing

By aaarrrgggh • Score: 5, Interesting Thread

A friend was a flight attendant on the recent suicide-by-aircraft-engine-injestion incident. People don’t listen; they take videos, they grab their rollerboards and everything else, they do stupid things (and apparently some flight attendants freeze up and forget to open their door). Just to throw it out there, the real reason you should not take a bag with you is it will greatly increase the risk of injury as you evacuate. Someone at the bottom of the slide is supposed to help you stop— if you take them out with your baggage that is much less likely to happen. If it is important, have it on your body at least for taxi, takeoff, and landing.

Safety briefings really need to change. They need to be compact, concise, and focused on the high risk events. They don’t need to be comedy, they can’t be advertisements, and they need to have a system to make it permanent memory for people that do fly a lot, kind of like education.

GM Is Quietly Becoming a Subscriptions Company

Posted by BeauHD View on SlashDot Skip
“General Motors has been pulling a Tim Cook and boosting its software and subscription business,” reports Business Insider. During the automaker’s Tuesday earnings call, executives said they’re increasingly leaning on software subscriptions like OnStar and Super Cruise to generate high-margin recurring revenue long after customers buy their vehicles. GM says OnStar brought in about $800 million in the second quarter, while Super Cruise revenue grew about 70% year over year. From the report:
GM says its software business keeps roughly 70 cents of every dollar it brings in. That’s a rare level of profitability in the auto industry, as many car sales generate just four to 10 cents per sales dollar. […] GM expects to add about 1 million OnStar subscribers this year, bringing the total close to 13 million. Super Cruise, GM’s hands-free, eyes-on driving system, is growing even faster. GM added about 70,000 subscribers during the quarter and expects to end the year with more than 850,000. Revenue from the service increased about 70% from a year earlier.

And a lot of drivers are sticking around after the free period ends. GM said between 30% and 40% of eligible owners continue paying after their included three-year Super Cruise subscription expires. [..] “We do think we have tremendous levers, multiple levers of growth,” Barra said on the call. “We definitely think there’s a lot of opportunity at GM to grow, improve margins, and become less cyclical.”

“Software and services are becoming increasingly important to how customers experience GM vehicles and how we deliver value beyond the initial purchase,” a spokesperson previously told Business Insider. “As vehicles become more software-defined, we can introduce new digital experiences through updates and optional services rather than hardware changes.”

brakes only $4.99/mo or $50/year!

By Joe_Dragon • Score: 5, Funny Thread

brakes only $4.99/mo or $50/year!

Re:Yeah, no

By darkain • Score: 5, Informative Thread

“OnStar brought in about $800 million in the second quarter”

Re:They don’t even write good software!

By PhantomHarlock • Score: 5, Informative Thread

Tesla is awful due to the lack of physical controls where they would really make sense. It is an actively driver-hostile car. Other than the powertrain, which is amazing, the car is completely obnoxious. The door handles in particular are a huge problem and have been banned in China. Why would you intentionally make door handles that are super awkward to open rather than just pull? Why would you make someone dig through a menu to adjust the mirrors, or adjust the A/C vents and other controls? Trying to shift with the right stalk? Awkward and horrible. I think they thought it was sexy to just have a screen and nothing else, but in reality it just absolutely sucks. Before you say, “but have you owned one?” Yes, yes I have. It’s my wife’s current daily driver. And I avoid driving it like the plague.

Suckers

By PhantomHarlock • Score: 5, Interesting Thread

So they’re taking all your data, selling it, and making you pay for the privilege? Must be a nice business if you have zero scruples.

Why do you need OnStar? Who would want to steal a GM car? All the GM brands are at the very bottom of Consumer Reports reliability index for 2026.

OnStar uses cellular service to connect, so if you have an emergency, either both OnStar and your cell phone work, or neither work. So there’s no advantage to using OnStar rather than just dialing 911. 911 services are allowed access to your phone’s GPS location regardless of settings.

It just seems like a pork package to sell along with the clear coat. Not to mention the theft of your data without compensation, whether you subscribe or not. You have to physically disable the modem to avoid that.

Re:They don’t even write good software!

By Tony Isaac • Score: 5, Insightful Thread

Yeah, I hate cars that have the often-used controls as touch-screen. I don’t even like touch-screen radio controls. Give me a button to push or a knob to turn.

But then, I drive a stick shift, so my opinion doesn’t count. :-)

iOS 27 Code Suggests Apple Could Restrict Leased Devices After Missed Payments

Posted by BeauHD View on SlashDot Skip
Code found in the iOS 27 beta suggests Apple is developing a system that could restrict leased iPhones when customers fall behind on payments. The discovery follows a recent Bloomberg report that Apple may soon launch a new “Apple Upgrade” leasing program, allowing customers to pay for hardware through monthly installments. 9to5Mac reports:
The code describes a system called App Managed Features, which allows an authorized financing or provider app to enroll an iPhone and perform ongoing status checks. If the contract is no longer in good standing, Apple’s system services can place the iPhone in “Restricted Mode,” which blocks access to most apps until the payment or contract issue is resolved, while keeping a small set of apps available. The fixed allowlist currently found in the iOS 27 beta includes: Accessibility Reader, App Store, Health, Magnifier, Phone, Clock, Settings, Wallet, Passwords, and the Restricted Mode interface itself.

Apps that can send critical alerts, such as Messages, Home, and certain medication or safety apps, may also remain accessible. However, the provider appears to have some control over those exceptions. The code does not appear to cancel, suspend, or otherwise modify App Store subscriptions associated with blocked apps. As a result, a subscription could continue billing even while access to its app is restricted.

Additionally, there isn’t a fixed number of missed payments that automatically triggers the restrictions. The financing provider’s app decides when to lock the device based on its own policies. Finally, the new framework also introduces a new type of activation lock called “Partner Finance Lock,” which is meant to prevent users from erasing, reselling, or stripping a restricted device for parts.

Re: So an improvement?

By drinkypoo • Score: 4, Insightful Thread

Nah, they will keep slowing down old devices with new features users didn’t ask for in order to induce additional sales

Ownership and the Next Check.

By geekmux • Score: 4, Interesting Thread

..to enroll an iPhone and perform ongoing status checks. If the contract is no longer in good standing..

I’m more concerned about how it behaves when there is no need for a contract at all.

If someone walks in the door with an MSRP-amount of cash in their hands ready to buy outright a device that is normally sold to a loan-licker who loves a new fashionable lease, how exactly is said device re-configured to ensure an owner is NOT treated like a debt-owing pseudo-suspect?

Now let’s clarify the definition of ownership again. Because the next Orwellian “check” they will make when financial fuckery isn’t enough to censor and control you, is your social credit score..

Apple Fan No More

By dotslashdot • Score: 3 Thread
I used to like Apple as the scrappy underdog giving people tools and free software other companies charged for. Now Apple is heading toward being another greedy corporation nickel and diming their users for money without adding value. It is bizarre Apple would spend time, money, and expertise developing a Tech feature to help creditors go after its customers and users, particularly given its recent software failures. Apple used to be morally anchored under Steve Jobs as going after the big guy while looking out for the little guy . Or maybe it was just good PR. But at least it worked. Now Apple is helping its fellow big guy as a big guy and throwing its products and customers under the bus and does not care.

Re:Tough to feel sorry for fools.

By lucifuge31337 • Score: 4, Insightful Thread
I’ve been in telecom for most of my career, often dealing with apps and test phones so I’ve run the gamut of the cheapest to the greatest most expensive phones as test devices and personal devices over the course of the last couple of decades.

Simple advice that people who need it don’t want to hear: for years now it’s been possible to get a really, really usable phone for $30 (used to be $20). I’m not talking about a flip phone, I mean somehting running a reasinable enough android version with reasonable enough specs to run whatever bullshit apps you think you need and be a functional part of society with for as much as a phone with internet access and a camera to read QR codes seems to be increasingly required.

There is zero reason to spend more without 1.) the means to do so and 2.) a good reason why that basic phone won’t do what you need it to. If 1.) is big enough you get to just buy shit you don’t need because you want to. That’s how this has always worked. But increasingly it’s people without enough money buying much too expensive phones that have capabilities they will never use and financing them to boot.

Tell me again

By RitchCraft • Score: 3 Thread

Tell me again how Apple is so much better than other tech vampire companies. Oh that’s right, Apple sets the standard.

Linux Kernel Team Publishes 432 CVEs In Two Days

Posted by BeauHD View on SlashDot
Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: “I understand the position that CVEs were always a flawed way to track or prioritize security changes… But this onslaught really shows it’s not feasible to attempt to prioritize individual kernel changes. I’m not sure what to do here going forward.” The Register reports:
The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn’t be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact “it keeps finding embarrassing bugs.” […]

Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn’t one that’s readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy.
Senior kernel maintainer Greg Kroah-Hartman replied to Jan’s post, pushing back on the idea that the kernel’s CVE volume is uniquely unmanageable. The kernel isn’t special, he argues — companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that’s traditionally been “woefully ignored.”

On the “just always update” approach, Greg says that’s precisely what the kernel community endorses: “This is what the kernel developer community recommends and supports. If you want support from us, do this.” Can’t manage it yourself? Pay a company for support, or “just use Debian or Yocto as their security practices are amazing.” He points to Android as proof the approach scales, calling it “the largest deployment of software in the world” — billions of devices kept updated “with one very-overworked developer guiding it all.”

As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set “down to about 10% of the overall total” — the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt “Good luck with that!” — regulations like the EU’s Cyber Resilience Act are set to legislate that habit away (“rightfully so,” in his view), and “your insurance company might wish to have a talk with you as well.”

Greg also warns the flood isn’t over: “The number of llm-found issues is only on the rise right now, it’s going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way.” As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend — delayed by “a perfect storm of 6 weeks straight of conferences and vacations” — so it shouldn’t have come as a surprise to anyone watching the public git repo.

Re:Great news

By Junta • Score: 5, Interesting Thread

Depends on the number of realistically ‘false positives’.

I’ve known a few people who find the kernel CVEs particularly unreasonable as they tend to aggressively assume security implications. If they grant a CVE to a ‘mere bug’, no one is going to get too grumpy over that specific item. If someone believes they have a vulnerability and do not see a CVE, then people get riled up. So some feel the kernel is just granting CVEs to avoid pushing back.

The other headache is the monolithic nature of the project. “Linux” covers just everything. A potential security issue in a device never seen outside of PA-RISC systems 20 years ago? It’s a “Linux” issue, so every x86 system will be flagged as ‘affected’ by security software that cannot deal with nuance

Of course, we are here mainly because the kernel team largely recognizes the practice of trying to apply only security updates while avoiding ‘only bug’ fixes as pretty insane. So err on the side of caution make CVEs extra unmanageable because realistically it was a pretty crappy strategy for such a complex project anyway.

Broadly speaking, CVEs are usually pretty bogus, but a small percentage are very real and critical issues. You can’t use the ‘score’ to really measure this either, it’s not very good in the first place, and for example I saw the exact same issue in a C library and a python binding for that C library, and for whatever reason they graded the C library as ‘minor’ and python binding for that library ‘critical’, despite the python binding being nothing but a ctypes wrapper around the c library…

Re:Going to get worse before it gets better

By Junta • Score: 5, Insightful Thread

Most maddening for open source projects is the number of false positives exacerbated by multiple people trying to ‘help’ by running effectively the same security audit as a bunch of other people have done and trying to open issues that are duplicate…

Huge pain in the ass dealing with contributions from people who don’t understand enough to analyze their LLMs “findings” and just pass them through “in case they are helpful”.

Might be nice once the fad of “everyone contribute by running duplicate reviews” subsides though.

Re:it keeps finding embarrassing bugs.

By swillden • Score: 5, Insightful Thread

Is there any other kind?

Sure there are. Some bug reports, you look at them and dig in and say “Damn, that’s obscure. It depends on subtly-wrong but arguably-correct-in-isolation mistakes in four different places. How the hell did they even find that?”.

Granted that it’s more common to glance at it and just be ashamed, or to look at it and say “Really? You think an attacker can do A, B, C, D, and E, all at the same time? Oh, and to do B or D they’d already have to have the system mostly compromised. Okay, I’ll fix it, but no way in hell is that actually exploitable.”

Re:Great news

By robot5x • Score: 5, Insightful Thread

Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "… this onslaught really shows it’s not feasible to attempt to prioritize individual kernel changes. I’m not sure what to do here going forward.”

So he literally says “it’s not feasible to prioritize” and “I’m not sure what to do”. Is that ‘complaining’, where you come from? Cos it sounds like overwhelm and turning to colleagues for support.

People making strawmen about people complaining makes them look bad.

Re:Going to get worse before it gets better

By thegarbz • Score: 5, Insightful Thread

GCC can do it.

But it didn’t.

Good coding practices (setting pointers to NULL after freeing memory) prevent exploitability.

But they didn’t.

You can frame it any way you want, the end result is that exploits were found and patched. You assertion that it could have been done another way is irrelevant since those tools and practices have been available for a long time, and yet the zerodays persisted.