Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.
DoorDash Is Building Its Own Drone Delivery Business
DoorDash has launched DoorDash Air, an in-house drone-delivery program that has just received FAA certification for commercial operations. “This does not mean DoorDash’s custom-built drones will be delivering burritos tomorrow, or even next month,” notes TechCrunch. “The company didn’t provide a detailed timeline for when its aircraft would be used in operations.” From the report:
[I]t will likely begin with limited pilot programs in which the unmanned aircraft will travel short distances while remaining within the line of sight of the operator. If DoorDash wants its drones to fly autonomously over longer distances, it will need the FAA to approve its Beyond Visual Line of Sight technology, a certification that companies like Amazon, Wing, and Zipline have received in recent years.
Despite the new program, the food and grocery delivery company is maintaining its existing partnerships with Wing and Flytrex. DoorDash partnered with Alphabet’s Wing in 2022 for a drone delivery program in Australia, and later expanded the partnership to a couple of U.S. cities, including Dallas-Fort Worth, in 2024.
Russia Charges Telegram Founder Durov With Facilitating Terrorism
Russia has charged Telegram founder Pavel Durov with facilitating terrorism, alleging the platform was used by Ukrainian intelligence “to prepare and co-ordinate acts of sabotage and terror” inside Russia. An international arrest warrant has been issued for Durov, who currently lives in Dubai, United Arab Emirates, where Telegram keeps its main office. The BBC reports:
Shortly after the charge was announced, Telegram’s account on X posted an image showing Durov holding up his middle finger. He has previously accused Russian authorities of “fabricating new pretexts to restrict Russians’ access to Telegram.”
[…] Multi-billionaire Durov, 41, has lived outside of Russia for many years and holds French and United Arab Emirates (UAE) passports. It is unclear whether other countries or authorities would comply with an arrest warrant issued by Russia.
Durov left Russia in 2014 after refusing to comply with government demands to shut down opposition communities on the platform. He had previously founded popular Russian social media company VKontakte - dubbed the “Facebook of Russia.”
In 2024, Durov was arrested and investigated by the French government in connection with criminal activity on the platform and a lack of cooperation with law enforcement. “He was allowed to go home months later, with the investigation continuing,” notes the BBC.
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
An anonymous reader quotes a report from Wired:
OpenAI said Tuesday that the rogue AI agent that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack. It’s now clear that the unprecedented security incident, which arose during an internal test of OpenAI’s latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that “four accounts” tied to “publicly available services” were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.
OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at “the level of severity or scale of what we’ve shared related to Hugging Face.” One of the additional accounts compromised by OpenAI’s agent was used as an “outbound relay and staging path,” potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI’s rogue agent also used another account for data storage to assist with the hack.
Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI’s agent. In a statement to WIRED, Modal’s chief technology officer Akshat Bubna confirmed that OpenAI’s agent exploited a vulnerability in one of its customer’s codebases, which was running on Modal’s infrastructure. However, Bubna says, “Modal’s platform was not compromised in any way.” The identity of the customer could not be determined.
More Than 30 Minnesota Water Systems Targeted In Cyberattack
jrnvk shares a report from KMSP:
Minnesota IT Services reports that a “coordinated cyberattack” targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.
On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.
State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota’s critical infrastructure.
Your Brain Can Rewire Itself To Allow True Multitasking
alternative_right shares a report from ScienceAlert:
[I]n a new study published in the Journal of Cognitive Neuroscience, researchers from Georgetown University Medical Center in the U.S. have revealed that we can put certain tasks on autopilot in a way that enables something closer to true multitasking. Driving is the perfect example: When you take your test, your entire mental and physical energy is concentrated on executing the right combinations of movements and thoughts. After a decade behind the wheel, the brain is no longer consciously thinking everything through in great detail.
In the new study, the researchers found that after extensive practice, the brain can effectively reroute some tasks around the brain’s main computing center — like a bypass road around a city — to reduce mental overload and improve multitasking capability. “We have another stepping stone in our understanding of how the brain learns,” says neuroscientist Maximilian Riesenhuber, senior author of the study. “The encouraging part is that you really can learn to multitask. There is actually a way to remodel your brain architecture and use other parts of your brain.”
[…] “Previous studies have shown that parts of the temporal cortex can be activated by particular object categories in experienced observers — birds, cars, even Pokemon — but a limitation of all of those studies is that they only looked after people became experts,” says psychologist Patrick Cox, first author of the study. “We measure before and after training, so we can see that extensive training essentially put a category-selective area in the temporal lobe that was not there before.” The study culminated in a dual-task experiment, in which the participants were asked to identify cars and take on another challenge. The individuals whose brains had offloaded more car-sorting work to the temporal cortex did better at the second task.
Trump Administration Bans New Chinese Humanoid Robots
The Trump administration has banned newly authorized foreign-made humanoid and four-legged robots, along with power inverters, citing “unacceptable risks” to the country’s national security. FCC chairman Brendan Carr said the agency was doing its part “to secure America’s critical supply chains.” The BBC reports:
The FCC has added the items to its Covered List — a register of goods and services that are deemed a risk to US national security. The ban applies to new foreign-produced advanced robotic devices and power inverters and does not prevent the sale or import of any existing models that had been previously authorized by the FCC.
The FCC cited concerns that the use of foreign-made inverters could allow overseas firms to turn them off, steal data, facilitate remote access and surveillance by “foreign government actors, or be otherwise exploited through a cyberattack.” It added that the use of robots made outside the US could allow “malign actors to surveil Americans, enhance the capabilities of foreign intelligence services, or to remotely commandeer the robots.”
Workplaces Look For Cheaper AI As ‘Tokenmaxxing’ Fades As a Corporate Fad
An anonymous reader quotes a report from the Associated Press:
A corporate fad of “tokenmaxxing” on artificial intelligence technology is hitting its limits as workplaces throwing AI at everything are seeing the costs rise without a similar spike in productivity. What started as tech industry-fueled springtime hype over squeezing as much AI-generated work as possible out of products like OpenAI’s ChatGPT and Anthropic’s Claude has shifted to a summertime backlash. […] Just a few months ago, Silicon Valley executives were promoting high token consumption as a signal of high-performing employees. The stereotypical tokenmaxxer was staying up late — perhaps ignoring their significant other — while orchestrating an army of 24-hour AI agents performing work on their behalf. […] The trend boosted revenue for leading AI large language model developers like Anthropic and OpenAI, but it fizzled as it became apparent it wasn’t necessarily the best strategy for everyone else.
[…] Bain & Company management consultant Jue Wang said many of the big businesses her firm advises have been taking a closer look at returns on their AI investments. “The token cost for them has been doubling, almost every other month,” she said. “Let’s say $200 per developer per month. Multiply that by 20,000 developers, which is often what we’re dealing with at these companies, and that quickly gets you to a number that is not a line item that any general manager has planned for.” Sometimes that just means not using the AI equivalent of a sledgehammer to crack a nut. “Not everything needs a Claude Opus 4.6,” she said of one of Anthropic’s more capable models suited to software engineering or deep research. “And yet you see so many companies, so many users, default to using Opus for everything, including generating emails.” That’s led to a search for tools that do AI “model routing” — in which easier queries get automatically sent to cheaper and more efficient AI systems and more complex tasks go to more powerful models.
[…] At the same time, those who favor racking up as many tokens as possible are having a field day with new open-source models from Chinese startups like Moonshot’s Kimi or Zhipu’s GLM, which nearly match the capabilities of top U.S. models at a fraction of the price. “There is some validity to the theory that this could push tokenmaxxing a little bit further,” said Raffi Krikorian, the chief technology officer at Mozilla. “But if we look at the industry overall, I think it’s realizing that tokenmaxxing is a dumb thing.” It’s similar, Krikorian said, to how software companies once considered how many lines of code a programmer wrote to be a good metric of productivity. That later fell out of favor. “I think tokenmaxxing is moving through the exact same pattern,” he said. “I think this is going to be an interesting blip that we’re all going to look back to laugh at in a year.”
Apple Retires iPhone Upgrade Program For Klarna-Backed Leases
Apple has replaced its iPhone Upgrade Program with Apple Upgrade, a Klarna-backed U.S. leasing service covering most iPhones, iPads, Macs, and Apple Watches. MacRumors reports:
Apple Upgrade has lower base prices than the iPhone Upgrade Program, with iPhones available starting at $17.99 per month and the Apple Watch available starting at $11.99 per month. Macs can be leased starting at $24.99 per month, and iPads start at $11.99 per month. AppleCare+ is optional and not included in the lease price, with customers also able to opt for AppleCare One. There are 12-month and 24-month leasing options for the iPhone and Apple Watch, along with 24-month and 36-month leasing options for the Mac and iPad. Lease cost varies based on device, and is lower with a device trade-in that’s applied on a monthly basis. […]
When leasing an iPhone, customers are required to choose a plan from AT&T, Verizon, or T-Mobile, and prepaid plans are not eligible. iPhones need to be leased with a carrier plan, but the iPhones are unlocked so customers can switch carriers if desired. MVNOs like Mint Mobile or Visible are not supported. At the end of the leasing period, customers can choose to return the device and exit the program, pay off the remaining amount owed on the device with a one-time payment and keep it, or return it and upgrade to a new device with a new lease.
The payoff amount is the difference between what was paid during the leasing period and the retail price of the device, minus any remaining trade-in credits. Klarna is not charging a fee for the leasing program, so an iPhone that’s $1,099 can be leased and then purchased for $1,099 with no extra cost beyond taxes. As with trade-ins, Apple will send a pre-labeled and prepaid shipping box for device returns or upgrades. If you don’t opt to pay the purchase fee at the end of the leasing program, you will not own the device and must return it.
Last week, after Bloomberg reported on Apple’s upcoming leasing program, 9to5Mac uncovered code in the iOS 27 beta suggesting the company was developing a system that could restrict leased iPhones when customers fall behind on payments. Apple has now told The Verge that the new “Restricted Mode” will not be activated in response to a missed lease payment. What the new system is actually meant for remains unclear.
AI-Found Bugs Aren’t Proving Any Easier to Exploit Despite the Hype
AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is “almost identical to the rate across all vulnerabilities in VulnCheck’s dataset,” reports The Register. “That’s a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers’ favor by churning out instantly weaponizable bugs.” The findings suggest AI is currently better at increasing the volume of bugs found than making them easier to weaponize. From the report:
The report takes particular aim at Anthropic’s much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there’s remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic’s public disclosure record has seen little movement since Project Glasswing launched.
But that doesn’t mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. “AI-assisted vulnerability discovery clearly has value for both attackers and defenders,” Garrity wrote. “The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods.” Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there.
Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. “The data so far, including Anthropic’s own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today,” he wrote. “That doesn’t mean the risk is imaginary. It means the impact has been real but modest.”
eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019
eBay and several former executives have agreed to pay $56 million to Ina and David Steiner, the newsletter writers targeted in a 2019 corporate harassment campaign that involved threats, surveillance attempts, and deliveries of live insects and other disturbing items. The settlement closes the couple’s civil case after seven former employees pleaded guilty to criminal charges related to the scheme. TechCrunch reports:
Ina and David Steiner, a married couple and the co-authors of EcommerceBytes, inspired the ire of high-level eBay executives after occasionally criticizing the company in their newsletter. In 2019, a plot was concocted to intimidate the couple into halting their negative coverage. Executives used sock puppet social media accounts to harass the couple, while also sending them anonymous threatening letters and bizarre items in the mail — including live spiders and cockroaches, pornographic magazines, a bloody pig mask, a funereal wreath, and a book about surviving the death of a spouse. According to previously released court documents, a plan that was attempted but never successfully carried out involved affixing a GPS tracking device to the couple’s car. Yet another internally broached plan involved sending a “Samoan gang” to the Steiners’ home.
The settlement this week resolves a 2021 civil case brought by the couple against eBay. The law office representing the Steiners writes that the settlement includes $46.15 million paid to the couple by eBay itself, as well as $2 million from former eBay executive CEO Devin Wenig. Additionally, $500,000 will be paid out to the couple from former eBay executive Wendy Jones, as well as $50,000 from former eBay executive Steve Wymer. Additional funds are being paid to various non-profits. In 2022, seven former eBay employees were criminally charged and pled guilty in relation to the plot, including the company’s former security chief, James Baugh — who was sentenced to nearly five years in prison. Others indicted by the U.S. Department of Justice include David Harville, Brian Gilbert, Stephanie Popp, Stephanie Stockwell, Philip Cooke, and former eBay contractor Veronica Zea.
Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms
Anthropic’s Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet,” reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report:
The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic’s technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet.
[…] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct.
“Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won’t be threatened?” said Glenn S. Gerstell, the former general counsel at the National Security Agency.
“Mathematicians would tell you that it shouldn’t be possible given current computing powers to break strong encryption in any meaningful time,” added Mr. Gerstell, who helped write a report on cryptology in 2022. “But I don’t think the capabilities of future models in the medium term — before quantum computing or quantum-proof cryptography — should be dismissed as trivial in this context.”
Judge Blocks First State Law That Would Have Banned Prediction Markets
An anonymous reader quotes a report from Ars Technica:
Minnesota, the first US state to prohibit prediction markets, was prevented from enforcing the law by a federal court ruling just days before the ban was scheduled to take effect. But while Minnesota was stopped from enforcing a total ban, the state may ultimately be allowed to prohibit some types of prediction-market wagers. The Trump administration and the two largest prediction markets — Kalshi and Polymarket — sued Minnesota after the state enacted the law in May. The cases were consolidated, and a ruling (PDF) issued yesterday imposed a preliminary injunction blocking the law that was scheduled to take effect on August 1.
Minnesota lawmakers saw prediction markets as indistinguishable from gambling, but the US Commodity Futures Trading Commission (CFTC) argues it has exclusive authority to regulate the platforms under federal law. One of the primary legal questions is whether event contracts are “swaps,” which are regulated by the CFTC. Swaps are defined broadly in US law to include contracts in which payment “is dependent on the occurrence, nonoccurrence, or the extent of the occurrence of an event or contingency associated with a potential financial, economic, or commercial consequence.” US District Judge Katherine Menendez in the District of Minnesota, a Biden appointee, said Minnesota’s total ban on prediction markets is likely to violate US law because many trades on Kalshi and Polymarket are swaps.
Menendez wrote: “Specifically, it appears that whether the Minnesota statute is expressly preempted turns on whether the state law attempts to regulate trades in event contracts that qualify as “swaps” within the meaning of the CEA [Commodity Exchange Act]. And there are several examples of event contracts hosted by Kalshi and Polymarket US that fit that definition because they concern the occurrence of events with clear potential economic, financial, or commercial consequences that are neither remote or unattenuated. Kalshi and Polymarket US are designated contract markets, so the CFTC has exclusive jurisdiction to regulate transactions involving those ‘swaps.’"
Menendez said the CFTC, Kalshi, and Polymarket met their burden of showing they are likely to succeed on the merits, so she issued “a preliminary injunction barring enforcement of Minnesota’s prediction market statute until a final decision on the merits is reached.” But she said Minnesota may be able to prohibit some types of event contracts offered on Kalshi and Polymarket because not all of them appear to meet the definition of swaps. For example, Menendez doesn’t think prediction-market bets on the outcome of Love Island USA meet the legal definition of swaps. Minnesota could continue litigating the case in district court or ask a federal appeals court to overturn the preliminary injunction.
DEF CON Bans Meta-Style ‘Pervert Glasses’
DEF CON has banned “Meta-style glasses with recording capabilities,” with no exceptions being made even for those with prescription versions. “Be sure to pack non-violating eyewear if you need them,” DEF CON said. The Register reports:
[The conference’s official photo policy] has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s).
“Love to see a ‘no pervert glasses’ policy at DEF CON,” said EFF director of cybersecurity Eva Galperin.
GrapheneOS Defends Data-Wiping Function That Blocked US Border Search
GrapheneOS is defending its duress-password feature after an environmental activist used it to wipe his Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The nonprofit says the operating system is "completely legal,” cannot recover the erased data, and should not be weakened with encryption backdoors. Meanwhile, the activist faces up to five years in prison if found guilty. PCMag reports:
In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the "auto-reboot timer" that’ll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted.
The group’s post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. “People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device,” the nonprofit wrote. “GrapheneOS doesn’t require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device.”
On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick’s phone. “Data cannot be recovered after the key derivation material is reliably wiped. It’s not possible and there’s nothing we can do to assist with it,” the group wrote. “Similarly, it’s not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it.”
Review Roundup: Framework Laptop 13 Pro
The review embargo has lifted for the new Framework Laptop 13 Pro, and the consensus across the board is that it is a massive leap forward in terms of build quality and battery life. The main issue reviewers complained about is the sky-high price, with the higher-end model jumping dramatically from $2,100 up to $2,900 due to the memory shortage crisis. (Some note that the price “nearly doubled” overnight while they were in the middle of testing.)
In his video review, Marques Brownlee says, “This is their best build yet. They’re finally doing what people have been asking for: a premium… modular… laptop.” ZDNET agrees that this device “represents a new approach for Framework and a maturation of the brand’s catalog,” noting that the new construction is “sleek and airtight, with no gaps, spaces, or evidence that was even put together by your hands at all.” Tom’s Hardware echoes this enthusiasm, declaring that “The Framework Laptop 13 Pro’s sturdy design, haptic trackpad, and bigger battery feel like they should have been there all along”.
Battery life, which has historically been a weak point for Framework, is now a standout feature. Ars Technica points out that the combination of Intel’s efficient Panther Lake chips and a new 74-watt-hour battery is “finally long enough to decisively eliminate ‘mediocre-to-poor battery life’ as the laptop’s biggest downside.” They also said it’s “Framework’s nicest-looking, nicest-feeling, most polished laptop design.”
For Linux users, the machine appears to deliver on its promises. Phoronix says the device “is designed with great Linux compatibility in mind,” offering a seamless out-of-the-box experience for distributions like Ubuntu and Fedora.
As mentioned above, the overarching complaint is the extreme cost. Ars Technica notes that Framework unfortunately “switched to an exotic new upgradeable LPDDR5X RAM format just in time for those modules to become astronomically expensive.” Still, Marques Brownlee summarizes the long-term value proposition perfectly: while it might be painfully expensive on day one, “the longer you keep this laptop, the more it feels worth it” because you can easily repair and upgrade it over time. Compared to Apple’s flagship, the Framework is “80% of the quality, way more modular,” he says.
FBI should be visiting.