Alterslash

the unofficial Slashdot digest
 

Contents

  1. Are Return-to-Office Mandates Killing Workers’ Trust in Workplaces?
  2. As New York Finalizes New Social Media Rules, US Senate Considers Nationwide ‘SCREEN’ Act
  3. How ‘Situational Awareness’ Hedge Fund Dropped 67% in AI Stock Rout
  4. Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken
  5. Is Big Tech’s AI Gamble Starting to Look Riskier?
  6. 150-Game Discount Bundle Raises $57,000 for Videogame Workers ‘Hardship Fund’
  7. NASA’s Curiosity Mars Rover Discovers a Field of Honeycomb Textures
  8. Apple’s Stock Drops Nearly 10%. How Will It Respond to Memory Shortage?
  9. Hamburg Is Replacing a Bridge In One Huge Piece
  10. New GitHub, PyPI Policies Hope to Boost Supply Chain Security
  11. Used EV Prices are Now Going Up in America
  12. Google Plans To Exempt Sanctioned Nations From Android Developer Verification
  13. Drones Offer Alternative to Balloons For Weather Research
  14. Drifting SpaceX Rocket Heading For Accidental Collision With the Moon
  15. OpenAI Finds Evidence Other AI Agents Escaped Containment

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

Are Return-to-Office Mandates Killing Workers’ Trust in Workplaces?

Posted by EditorDavid View on SlashDot Skip
The Hill published the thoughts of Gleb Tsipursky, Ph.D., who serves as the CEO of the future-of-work consultancy Disaster Avoidance Experts:
A recent EnhancV survey of 1,000 full-time U.S. workers subject to new or stricter return-to-office policies found that 72% suspect these mandates are really a voluntary attrition strategy — a strategy by their own employers to make them quit their jobs. A full 46% admit to the practice of coffee-badging. Thirty-six percent have applied for a new job while sitting at their current office desk. Thirty-six percent have started a side hustle since the mandate was announced, in anticipation of being let go or quitting. Those numbers do not prove that employees reject collaboration. They show that many employees no longer trust the official story…

The central mistake in many in-office mandates is the assumption that proximity automatically produces commitment. It does not. A worker who spends two hours commuting to sit on video calls with colleagues in other cities is not experiencing culture. That worker is experiencing theater. When executives describe the office as a cure-all, many employees experience lost time, higher costs and lower autonomy. The policy’s defining feature becomes its credibility gap. Research keeps undercutting the belief that more office time automatically means better performance. A University of Pittsburgh analysis of S&P 500 firms found that return-to-office mandates reduced employee satisfaction without improving firm performance or firm value....

Baylor University’s reporting on office mandates and brain drain found that firms with mandates faced greater turnover among women, senior employees, managers and high-skilled workers, while job vacancy duration increased and hiring rates declined. In other words, the people with the most options are often the first to leave. The employees who remain may not be the most committed — they may simply be the least mobile… Attendance can be mandated, but commitment cannot. When leaders confuse the two, they do not rebuild workplace culture. They create a room full of people planning their exit.

As New York Finalizes New Social Media Rules, US Senate Considers Nationwide ‘SCREEN’ Act

Posted by EditorDavid View on SlashDot Skip
New York has finalized new rules that will govern social media apps in the state starting on January 25, 2027. The law prohibits social media platforms from sending notifications to minors between midnight and 6 a.m. without parental consent. And minors “will only be shown content from other accounts they follow or otherwise select in a set sequence, such as chronological order,” rather than “the default algorithmically personalized feeds… unless they get parental consent for an addictive feed.” (Social media companies “must offer at least one alternative method for age assurance besides providing a government-issued ID,” the announcements points out, and any information used to determine age “must not be used for any other purpose and must be deleted or de-identified immediately after its intended use.”)

But meanwhile, the EFF writes that a committee in the U.S. Senate is considering the SCREEN ACT, “a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.”
Unlike many state-age verification laws — which have been harmful in their own right — the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content…

Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time. The consequences of the bill won’t be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people’s private information…

The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users’ ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking…

The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users.

This already exists

By fahrbot-bot • Score: 4, Informative Thread

Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time.

Some sites already require the use of ID.me — like the IRS, SSA and Medicare, the latter two also allow Login.gov. Here are 77 Companies that use ID.me in United States

Not trying to give them ideas, just sayin’ …

You’re assuming that’s not the point.

By dgatwood • Score: 3 Thread

At this point, I’ve stopped giving politicians the benefit of the doubt. If they support regulations that look like they have the potential to drag the United States into becoming an authoritarian hellhole, I assume that they’re actually trying to do just that. It makes it a lot easier to convince myself to vote for another candidate in every election afterwards, even if that candidate isn’t as good in other areas, because at least the other candidate isn’t trying to destroy our basic freedoms.

Look up the sponsors of the bill, and vote against them from now on, whether it’s a primary or a general election. Repeat until ousted.

I’ll take Republicans for $100 Alex.

By fahrbot-bot • Score: 3 Thread

As of this posting, the SCREEN Act bills are cosponsored solely by how many of this political party.

What is 26 Republicans in the House and 4 Republicans in the Senate?

H.R.1623 - SCREEN Act
S.737 - SCREEN Act

Zero Knowledge Proofs

By irchans • Score: 3 Thread
The EFF wrote, “The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, … will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.” Verifying a person’s age can be done without exposing their identity. It requires a trusted third party, such as the government, to issue age certificates. The internet company can then send the user a random challenge (just a random number), and the user can then prove that they possess a valid age certificate stating that they are over 21 without disclosing the certificate, their identity, or their actual age. This software technique is called a Zero-Knowledge Proof.

Re:Zero Knowledge Proofs

By allo • Score: 4, Insightful Thread
It doesn’t matter much … because possessing such a certificate doesn’t say you’re the owner of it. To control who’s using the site you would need to both know the certificate, have it contain an image of you and activate your webcam so one can control that you are sitting in front of the PC and not someone else who may be a minor. Effective age verification cannot be done from the remote end. So make the parents accountable for their child’s online behavior instead of the site owners. You can turn off notifications by just switching off networks at night and you can prevent access to porn sites using a filter on your device. Then sites only need to add a flag “adult site” (many already do) and your filter can prevent access to them.

How ‘Situational Awareness’ Hedge Fund Dropped 67% in AI Stock Rout

Posted by EditorDavid View on SlashDot Skip
CNN tells the unfortunate tale of hedge fund Situational Awareness, “founded in 2024 by German-born Leopold Aschenbrenner when he was in his early 20s.”
Aschenbrenner, a former OpenAI employee, founded the hedge fund on the premise that “AI will be the dominant driver of global market returns over the next decade,” according to the firm’s site… Aschenbrenner managed to turn hundreds of millions of dollars into tens of billions of dollars over the course of roughly two years… That streak ended on Thursday, though, when the fund was forced to sell the bulk of its public holdings to a bigger rival after many of its investments went south.

But that’s only part of the story. The fund employed a risky strategy of borrowing money to purchase stocks. When the investments appreciate, the payoff can be massive. But when the investments sour, the losses can be catastrophic. The downturn in AI stocks over the course of this month, like chip makers and cloud computing providers, hit the hedge fund extra hard. It was forced to sell off many investments at a steep discount to rival hedge fund Citadel in what Aschenbrenner reportedly compared to a “bank run” in a letter to investors.
“Critics pointed out that Aschenbrenner had no experience running money prior to launching his fund in July 2024, calling him more lucky than smart,” writes CNBC:
Some noted that his early work experience was at the doomed crypto firm FTX, where he helped now-disgraced founder Sam Bankman-Fried run a charity out of a Bahamas penthouse. Others on Wall Street, including former traders at global investment banks, noted that in light of reports Situational Awareness used as much as 400% leverage, the collapse wasn’t shocking.
The Wall Street Journal reports that Situational Awareness “also used options to amplify its returns. That meant that even small declines in individual names could have big impacts on Situational’s portfolio.”

And so, as the New York Post put it, “The celebrated crystal ball of the 'Nostradamus of AI' hasn’t merely gone cloudy — it has rolled off the table and shattered on the parlor floor.”
Wall Street breathed a huge sigh of relief last week as an AI-focused hedge fund called Situational Awareness reportedly sold most of its portfolio — reportedly down 67% last month on the backfiring of debt-fueled bets on chipmakers and assorted artificial-intelligence firms — to billionaire Ken Griffin’s Citadel…

The prevailing sentiment was best summed up by a veteran Wall Street sage who has seen a lot of flameouts in his day. Let’s just say he wasn’t impressed by Leopold Aschenbrenner, the 25-year-old German-born “Nostradamus” figure who is the founder of Situational Awareness… “Just your typical leveraged Âidiot who was right until he was wrong,” the source said, adding that the implosion is a “one-off…”

[Another trusted source] felt there was room for conversation: “A significant issue. Not viewed as systemic right now. I wonder if that changes as more problems arise.” Indeed, the fact is that most of Wall Street is closely monitoring the Situational Awareness situation because they were holding many of the same positions as ÂAschenbrenner. Another top hedge fund manager I won’t name tells me he has been getting crushed on similar investments in chipmakers essential to the AI supply chain, as well as other companies feeding off this technology.
Thanks to Slashdot reader joshuark for sharing the news.

Average WSB regard

By bubblyceiling • Score: 4, Interesting Thread
400 % leverage, risky options play, ex-crypto bro, goes all in on the next big hype.

For a second I thought this was r/wallstreetbets

Hedge fail

By phantomfive • Score: 4 Thread
A hedge fund is named such because they (traditionally) hedge against risk. Thus, whether the stock goes up or down, the hedge fund can make money (and lose money if it stays flat).

This fund clearly failed on the hedging. No point in using a hedge fund at that point, might as well have just bought the stock (or options if you’re crazy).

Old technique

By gurps_npc • Score: 5, Insightful Thread

There is an old technique - the guaranteed winner by random chance:

You get 32 stock brokers. On Monday the boss picks 2 stocks. 16 say that stock is going up, 16 say down, and they each call 100 people and give their prediction. That evening the 16 that were ‘right’ call their 100 back and brag. Tuesday they repeat only with 8 on each side. Repeat on Wednesday with 4 winners. Thursday they have 2 winners. Friday they have 1 winner that brags to his 100 prospects:

“Look, I happened to predict the winner every day this week. I can not guarantee that will happen every day, but if you want to hear my predictions next Monday, I need you to move your account to my firm.”

And the gullible fool does it, not knowing that mathematically the predictions were guaranteed to work on 1 of the 32 brokers. Just math, not competence.

Betting on AI was not some super genius move - especially using margin. All it involved was taking the popular opinion and going all in. While it worked you look like a genius. When it fails, you lose everything.

He just played the odds and won for a while. But the math was never going to have him win forever.

Unfortunate tale? It’s a feel-good story.

By Gravis Zero • Score: 3 Thread

Hedge funds do NOTHING to contribute to society in any way, shape, or form. The fact that this parasitic operation is dying is a feel-good story, not an unfortunate tale.

Markets can remain irrational longer than you can

By joeblog • Score: 3 Thread

I learnt the old John Maynard Keynes adage “Markets can remain irrational longer than you can remain solvent” the hard way early, luckily not with other people’s money and I didn’t have much money to lose back then.

Since then I’ve stuck to Burton Malkiel’s advice in A Random Walk Down Wallstreet and kept all my money in index-tracking ETFs and more than recouped my early losses.

A reminder to anyone who thinks they can “logically pick stocks” is Isaac Newton, who besides being history’s greatest maths genius was the equivalent of the central bank governor of his day so had lots of insider info, lost his entire fortune playing the stock market.

Keynes, who was a successful investor, simplified it to second guessing popular taste. It’s not picking what you think is attractive, but what the general public thinks is attractive. My taste and what people vote for are miles apart, so again ETFs are for me.

Active fund management is obviously a scam: if someone is that good at stock picking, why do they need your money?

Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken

Posted by EditorDavid View on SlashDot Skip
“A hardware wallet is supposed to be the safest place to keep Bitcoin,” writes The Street, since it never connects to the internet, its keys never leave the device, and “the whole point is that an attacker would need to physically hold it to steal anything.”

The problem is that anyone who can reproduce the recovery seed doesn’t need to possess the COLDCAR, Nerds.xyz points out. More from The Street:
[The recovery seed] is supposed to come from a hardware random number generator producing 128 bits of entropy, a number so large that guessing it is computationally impossible. It wasn’t. According to Block’s engineering team a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure and called it preliminary. The gap between 128 bits and 40 bits is not a matter of degree. It is the difference between a lock that cannot be picked and one that can be brute-forced by anyone with rented cloud computing....

Chainalysis found the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes. Within about 25 minutes, roughly 594 BTC had moved out of some 500 single-signature wallets. One victim lost around $1.8 million… Coinkite has shipped fixed firmware, but with a warning that matters more than the patch itself. Updating does not repair an existing seed. A seed created with weak entropy stays weak forever. Affected users have to generate an entirely new wallet on updated hardware and move their coins to it.
By Saturday morning Galaxy research was tracking 1,158.66 BTC, worth roughly $75.1 million, taken from 2,673 addresses, according to the article. And “The Coldcard exploit is ONGOING,” Galaxy Research posted an hour ago on X.com. “Move Coldcard single-sig funds to safe locations immediately!”
We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.
Thanks to Slashdot reader BrianFagioli for sharing the news.

Criminal activity in the crapto space. Who cares?

By gweihir • Score: 5, Insightful Thread

Seriously, this abysmally bad idea has no place in the news. Only blithering idiots are still in there.

silently?

By usedtobestine • Score: 4, Insightful Thread

Does that mean they have never run their code changes in a test environment to see what they do? Perhaps under a debugger? Also, why was it even possible to fall back to such a weak keylength?

Re:seriously - who certified or tested this

By gweihir • Score: 4, Interesting Thread

40 bit is within reach of practical guessing attacks. 128 bit is not, but just barely (the limit where it becomes reliably unguessable is somewhere in the 80…100 bit range). If you are serious about things you use at the very least 256 bit. And, obviously, you do independent expert review on any major change. This one is so abysmally insightless and bad, it may well have been an intentionally placed backdoor. I wonder whether they can still reliably say who did the change.

As to who certified that, this is the crapto space. Where everything is easy, nothing needs to be certified and stupid is the name of the game.

So one should probably wonder

By 93 Escort Wagon • Score: 5, Interesting Thread

According to Block’s engineering team a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one.

What are the odds that a COLDCARD insider has been playing the long game, and it just payed off?

Re:Criminal activity in the crapto space. Who care

By taustin • Score: 4, Funny Thread

So you’re claiming you have life changing wealth from Bitcoin? What island did you buy?

Is Big Tech’s AI Gamble Starting to Look Riskier?

Posted by EditorDavid View on SlashDot Skip
The Washington Post looks at giant tech companies "feeding every available dollar into the cash-incinerating maw of AI machines.” They warn “Tech superstars that once had oodles of cash left over at the end of each year are now flipping into the red…”
[While optimists expect] huge corporate profits and a society-wide boost to wealth and well-being… questions about that AI vision are now growing more urgent: When, if ever, will this payoff arrive? And what will the fallout be for Americans if the titanic investment doesn’t quickly deliver? “This AI thing better work out because if it doesn’t … we’re going to have a problem,” said Torsten Slok, chief economist at investment firm Apollo Global Management. AI costs and doubts are spreading. The U.S. stock market has swooned this summer over fear of the AI bubble going bust…

The AI gamble sweeping up American fortunes is led by tech companies splurging on hulking data centers packed with computer chips and equipment needed to develop sophisticated AI models and deliver them to customers. In investor calls in the past week, Google, Microsoft, Meta and Amazon pointed to soaring AI-related sales and business deals. Advertisers are using the technology to tailor marketing pitches and corporations and start-ups are buying access to chatbots and other AI software to boost productivity… But this spending can only continue if AI generates an even larger avalanche of new revenue to pay for it all. Financial results released over the past week show that the AI titans’ mammoth costs are largely swamping the sales boost from the technology. At Google, for every dollar of cash its business generated in the past three months, $1.15 went out the door to pay for AI computer chips and equipment, land for AI data centers and other big-ticket purchases. The company is covering the difference partly by borrowing money and selling more of its stock. Next year, five leading AI companies — Google, Amazon, Microsoft, Meta and Oracle — are projected to have negative free cash flow, which measures the cash left over after paying expenses and AI infrastructure costs. The figures, based on investment analyst projections compiled by S&P Global Market Intelligence, show a stunning reversal for what have been some of the world’s most cash-generating corporations…

The companies remain profitable by standard financial accounting measures that spread out the costs of their AI infrastructure spending over many years… Pessimists see a bet so gargantuan that it cannot possibly pay off. The pessimists are growing louder. The Bank for International Settlements, a typically measured institution in Switzerland that advises government bankers around the world, recently warned there was risk of “economy-wide recessions” if the AI boom falters. That could mean pain for workers and communities across the United States. “I’m not saying AI is going to go away, it’s just not clear to me these guys are going to make money on it,” said Christopher Wood, global head of equity strategy at investment bank Jefferies who has correctly predictedpast financial bubbles.

When did it not look risky?

By drnb • Score: 5, Insightful Thread
When did it not look risky? When did it not look like the ai bros were telling the dot com bros to hold their beer?

Re:All your data center are belong to us

By PPH • Score: 5, Insightful Thread

You pay a power bill? The utility that built billions worth of generation and transmission infrastructure on the promise of a future income stream gotta get paid. The bonds have to be covered or the banking system will seize up like in 2008. In the final analysis, it’s the people left still paying a power bill who will get stuck.

obvious bubble

By puzzled • Score: 4, Interesting Thread

There’s an obvious bubble, the circular dealings among the large core players are an enormous red flag.

The frontier labs are in the same position that DEC and Sun Microsystems were in the 1990s, as consumer hardware running Linux began to displace them. There will be ups and downs, but the trend is unavoidable.

The productivity gains are not there, AI is great for coding, some customer service is working, but the “50% of all white collar workers” that the frontier labs thought was good positioning last year 1) ain’t gonna work but it did 2) infuriate the managerial class.

The frontier labs got away with it, thus far, in part because of concerns over the arrival of artificial general intelligence, which occupies a similar niche to nuclear weapons in the minds of policy makers. We ARE seeing frontier models escaping and attacking others, there ARE hazards, but it’s nothing like what was imagined.

And the open models plus wild talent are as much a danger as wild talent was all on its own.

The frontier labs are like the coyote in that last moment when he’s windmilling wildly, but not falling yet.

Re:When, if ever, will this payoff arrive?

By gweihir • Score: 4, Insightful Thread

Indeed. It is an R&D project scaled-up to absolute insane dimensions. That cannot work.

Re:Buffett: “Only when the tide goes out…”

By gweihir • Score: 5, Insightful Thread

It is actually worse. LLMs do sort-of have a world-model, but they cannot really use it. What they lack is deductive capabilities with the power needed to do plausibility checking against that world model. And there is no way to create that because statistical “deduction” will always be very shallow and very unreliable.

As a simpler description, LLMs have all the data, but they have no insight that would allow them to use that data competently. They can only make statistical guesses and that is not enough outside of some small and not very important application areas. Hence engineers will not get replaced. But they may get pissed and some people may find nobody wants to work for them anymore.

150-Game Discount Bundle Raises $57,000 for Videogame Workers ‘Hardship Fund’

Posted by EditorDavid View on SlashDot Skip
"An itch.io game bundle put together by Necrosoft Games and The United Videogame Workers-CWA union is a new way gamers can show their support for developers who have been let go amidst the ongoing video game industry labor crisis,” writes Kotaku.

Launched Thursday, it’s already raised $57,859 from 3,984 contributors. (Average contribution size: $14.52)
The bundle is pay-what-you-want with a minimum purchase price of $10, offering DRM-free PC versions of games including A Short Hike, SkateBIRD, and my favorite game in the pack, Arranger: A Role-Puzzling Adventure … The bundle will be available through August 13.
The gaming blog Rock Paper Shotgun shares more details, starting with this quote from the bundle’s page on itch.io:
“Reports say 33% of the industry lost their jobs in the last two years, and the jobs they could fill are disappearing as CEOs try to replace them with AI. It’s hard for companies to adjust to the new shape of the game industry, but even harder for the people they should be employing… To address this in some small way, we have created a bundle with almost 150 games. The proceeds of this bundle will go toward a hardship fund for those experiencing layoffs.”

Games industry workers currently out of work or under-employed can apply to this fund, which is distributed by the United Videogame Workers, to help out with basic necessities like food and rent. As a note, this is only available to US and Canada-based devs, but there’s an FAQ explaining who can apply for the fund.

Microsoft?

By usedtobestine • Score: 3 Thread

Why? Is this so that Microsoft doesn’t have to pay them well enough? Or do they already make enough money for what the do?

When do they get access to the fund?

By drnb • Score: 5, Interesting Thread

Videogame Workers ‘Hardship Fund’

When do they get access to the fund? Because for many game studios the hardship is when actively employed in the game industry. When leaving the game industry that is when the hardship ends. I’m going with the all-too-common practice of taking advantage of young recent grads that think working in the game industry would be the coolest thing to do. Well, it is at a very very small number of studios, its not the typical experience.

Between 30 and 35,000 jobs lost

By FeelGood314 • Score: 3, Insightful Thread
And that’s just developers. So this works out to $2 each. I get the motivation and sentiment but to really make a difference you need 4 more zeros. If you are a socialist and want to make a difference learn basic math including division and then figure out something that meaningfully changes things. Like if the studios are pure evil, create a coop studio or a coop publisher. I mean with all the questionable things the evil Capitalistic publishers do shouldn’t a union of people with expertise in the field be able to create some alternative?

Wait a second

By quonset • Score: 3 Thread

Aren’t these developers paid a good salary, generally better than a large percentage of the population? What did they do with all that money? Why would they need a “hardship” fund?

Nice idea…golf claps all around…

By Archfeld • Score: 3 Thread

It is a nice thought but nothing more than that. Not even enough for a bad cup of coffee each.

NASA’s Curiosity Mars Rover Discovers a Field of Honeycomb Textures

Posted by EditorDavid View on SlashDot Skip
NASA’s Curiosity rover has sent back images of honeycomb-like textures called polygonal fractures, each one about 1.5 to 3 inches (4 to 8 centimeters) across. NASA reports:
The mission has spotted small patches of these geometric shapes several times before, but nothing at the scale discovered in Valle Grande. In a 360-degree panorama that the rover captured on June 19 and 20, the 4,930th and 4,931st Martian days, or sols, of the mission, the polygonal shapes spread in all directions for as far as the rover can see… "[T]his sea of polygons took our breath away,” said the mission’s project scientist, Ashwin Vasavada of NASA’s Jet Propulsion Laboratory in Southern California… Some of the polygons that the mission has spotted in the past clearly formed as mud cracks, though a variety of processes can contribute to their honeycomb textures, including cycles of warm and cold temperatures or compression that squeezed water out of the sediment when the surface was buried.

These newly discovered polygons are among the many surprises Curiosity has trundled across since landing on Mars 14 years ago, on Aug. 5, 2012. Besides sulfur crystals, shiny meteorites, and other interesting geologic features, the rover has made major discoveries about the ancient Martian environment — most importantly, that it had the water, chemistry, and nutrients to support microbial life.

Billions of years ago, lakes and streams dappled the lower foothills of Mount Sharp, a 3-mile-tall (5-kilometer-tall) mountain that Curiosity has been ascending since 2014. The rover has previously uncovered chemistry left over from Mars’ watery history, including carbon-based molecules believed to be precursors to RNA and DNA, two nucleic acids that carry genetic information. Scientists have no way of knowing whether these organic molecules were created by biologic or geologic processes — either path is possible — but their discovery reconfirmed that ancient Mars had the right chemistry to support life.
Dark, pebble-sized rocks also litter the area, NASA writes in a blog post, saying it’s a “still-to-be-resolved question” as to whether they’re bits of Mars that “floated” down from higher in the sediment layers, or “were ejected from distant impacts outside of Gale crater, or are meteorites from beyond Mars altogether.”

Honeycomb’s big

By 93 Escort Wagon • Score: 4, Funny Thread

Yeah yeah yeah.

Optimization processes

By JoshuaZ • Score: 5, Interesting Thread
n general, when there’s an optimization process involved where one is minimizing stress or something else, hexagons often show up. In fact, hexagons are more often in nature than square patterns. One nice example is Giant’s Causeway which has large hexagonal basalt columns https://en.wikipedia.org/wiki/Giant’s_Causeway (although a few columns have seven or eight sides). But neat to see another example, on another world no less. (We have on big hexagon on Saturn already.)

Simple answer

By quonset • Score: 3 Thread

The simulation we’re in gltiched and hasn’t refreshed. Try again in a day or two and see how it looks.

Very much like the Death Valley patterns

By Felix Baum • Score: 4, Interesting Thread
They were a mystery for quite some time, but eventually figured out by scientists https://www.livescience.com/sc… this would imply ancient wet dry patterns, thermal stress or burial compression patterns. Water would help make any of these possible.

Not that far

By hcs_$reboot • Score: 3 Thread
https://www.ntu.ac.uk/about-us…

Apple’s Stock Drops Nearly 10%. How Will It Respond to Memory Shortage?

Posted by EditorDavid View on SlashDot Skip
Apple’s stock “fell just shy of 10% on Friday,” reports Yahoo Finance, “after CEO Tim Cook warned about the impact of the global memory shortage on the company’s business.”
During Apple’s third quarter earnings call, Cook said the company paid significantly more for memory in the quarter and expects that to further increase in the current period. And while Apple is able to offset some of that price jump, it won’t be able to tackle it all… The CEO said that iPhone and Mac sales outpaced Apple’s own expectations and that a lack of flexibility in the supply chain is making it more difficult to keep up with demand.
Yahoo Finance cited an investment analyst who predicts overall gross margins for Apple’s iPhone could drop from 38% to 34.5%. But another analyst sees a scenario where Apple “raises iPhone prices, unit growth will slow, and as unit growth slows, so will user growth, which we think ultimately will slow Services growth.” (Still, Yahoo Finance predicts Apple’s new leasing program “could help address those concerns.”)

Apple has another controversial option, according to the blog 9to5Mac:
Bloomberg reports that US senators from both sides of the aisle are urging Apple CEO Tim Cook to commit by August 21 to not using memory chips from Chinese suppliers CXMT and YMTC....

Apple is not required to obtain U.S. government approval to purchase chips from the companies, but doing so without the administration’s support could expose it to significant political ramifications. Which is why, in an interview with The Wall Street Journal ahead of Apple’s recent price hikes, Tim Cook said that “everything needs to be on the table,” adding that “we should look at all supply....” More recently, the Journal reported that Apple’s use of Chinese memory chips could extend beyond China, with the company seeking the administration’s blessing to use components from CXMT and YMTC in products sold elsewhere outside the US. The report also detailed Micron’s efforts to persuade the administration to reject Apple’s request, arguing that allowing Chinese suppliers into Apple’s supply chain could undermine domestic memory production…

[Bloomberg’s reported that U.S. lawmakers warned] other companies could follow Apple’s lead, potentially undermining domestic memory production and planned investments in states such as Indiana, Idaho, New York, and Virginia… [T]he senators sought details about any information Apple has shared with CXMT during the component qualification process, noting that the transfer of controlled technical information to advanced chipmaking facilities in China may require a Commerce Department license.
The blog MacRumors notes that Apple has already increased prices for Macs and iPads in June because of surging memory prices. Apple CEO Tim Cook said Thursday “we did it because we’re in what I would characterize as a 100-year flood on memory pricing with exponential increases in memory prices.”
Cook did not comment on whether Apple plans to raise iPhone prices when the iPhone 18 Pro models and first foldable launch this September, but multiple analysts believe prices will go up. Cook said Apple is expecting to pay higher memory costs in the September quarter, though Apple will be able to partially offset it with lower costs on some non-memory components and a stockpile of inventory.
Sky News points out that “It was Tim Cook’s final earnings appearance before his retirement after 15 years at the helm of the company.”
Apple, which recently topped Nvidia as the most valuable listed company, has been largely spared the volatility in share price seen by chipmakers and big spenders on artificial intelligence. Apple continues to generate cash without the huge investment spending that its Wall St peers are dealing with “and that showed across most parts of the operation,” said Thomas Monteiro, an analyst at Investing.com.

Re:How should they respond?

By Valgrus Thunderaxe • Score: 5, Insightful Thread
By the time they bring a memory plant online, the AI bubble might have crashed. That’s why nobody actually wants to do this.

This is ridiculous

By RUs1729 • Score: 3 Thread
I have no love for Apple but I am skeptical that whatever is going on justifies that its stock should be punished like that. Investors are a hysterical bunch with a sheep-like mindset. It makes for a depressing thought the fact that such idiots have a big influence on the global economy. Bloody buffoons, always at the core of self-fulfilling negative prophesies.

âoesignificant political ramificationsâ&

By superposed • Score: 5, Insightful Thread

Apple is not required to obtain U.S. government approval to purchase chips from the companies, but doing so without the administration’s support could expose it to significant political ramifications.

This line is really chilling. The fact that it passes without comment shows that we’ve now gotten used to living in an authoritarian state instead of a democracy. In a country that actually supported free enterprise, a company wouldn’t have to worry what the president thinks of their perfectly legal business decisions. Nor would they need to be on the president’s good side to run their business as they see fit in the future. âoePolitical ramificationsâ of this sort have no place in a free, non-corrupt society.

Hamburg Is Replacing a Bridge In One Huge Piece

Posted by EditorDavid View on SlashDot Skip
Long-time Slashdot reader Qbertino writes:
The northern German City of Hamburg is currently in the process of replacing one of its bridges in one single gigantic piece. The new replacement weighs 3700 metric tons and was carefully moved into place over a stretch of 500 meters, requiring extreme patience and precision maneuvering. Some places leave only 40 cm of room to neighbouring buildings.

English-language sources

By jenningsthecat • Score: 3 Thread
https://ney.partners/project/b…
https://whysogermany.com/news/…

Not sure if they contain as much info as the original sources, but they’re much easier to read for most Slashdotters.

Re:meh.

By Teun • Score: 4, Informative Thread
Uh no.
The bridge was rolled the 500 meters to it’s destination on 1044 wheels.
At the end hydraulic jacks were used to lift it the 6 meters (20 feet) to rest on the designated supports.
As such not unusual but here is was in a densely populated city and on roads that during the transport had to be reinforces with heavy steel plates to protect the underlying pipes and cables.

Standard practice for a while now

By nospam007 • Score: 5, Informative Thread

Yes, this has been standard practice for a while now, especially for rail and highway bridges over busy routes, not really a novelty anymore despite the press coverage.

How it works
The new bridge is fully built off-site, nearby, then moved into place using self-propelled modular transporters (SPMTs), hydraulically steered multi-axle platforms, often within a single night closure. This cuts actual line closure from months down to a weekend or one night, since construction happens in parallel with ongoing traffic.

Why it’s become standard

Far less traffic disruption than build-in-place
Better quality control off-site
Cheaper overall despite transport logistics, since closure costs (detours, lost economic activity, rail replacement buses) are usually the biggest expense

Regional examples
Germany’s done this repeatedly on A1, A7, and other busy motorways as part of its bridge modernization program. Luxembourg/France/Belgium border regions have seen comparable push-in or slide-in operations for motorway or rail bridges. It’s become the preferred method Europe-wide for major infrastructure when space allows.

What’s actually notable about the Sternbrücke
Not the method, the scale: 3,700 tons over 500 meters is near the upper limit of what’s been moved this way, likely one of the heaviest/longest such transports in Germany. The “spectacular” framing is about weight and distance, not novelty of technique.

New GitHub, PyPI Policies Hope to Boost Supply Chain Security

Posted by EditorDavid View on SlashDot Skip
“GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security,” reports SecurityWeek, “by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases.”
To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown, where the automation tool waits for at least three days after a release has been published before opening a pull request. “Waiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests,” GitHub explains.

The three-day cooldown only applies to non-security version bumps, and the behavior can be modified through the configuration option in the dependabot.yml. “Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn’t hold your dependencies back longer than necessary,” GitHub notes.
And the Python Package Index (PyPI) “now rejects new files being uploaded to releases that are older than 14 days,” according to a recernt blog post from the Python Software Foundation’s security developer-in-residence Seth Larson:
This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised… The discussion of this behavior began during PEP 740 (Digital Attestations) back in January 2024. The discussion was restarted in March 2026 after the popular packages LiteLLM and Telnyx were compromised. These packages were compromised due to a "mutable reference" in these projects’ usage of the Trivy GitHub Action…

To quantify how disruptive this change would be to existing workflows, the PyPI database was queried for projects that have published new files to old releases[O]nly 56 projects of 15,000 had published a [Python] 3.14-compatible wheel more than 14 days after a release was available. This topic was brought to the Packaging Summit at PyCon US 2026 by PyPI Safety & Security Engineer, Mike Fiedler. The rough consensus of the discussion was that the summit attendees thought it was “acceptable to require users to bump to the next version” to support new Python versions. With the data and consensus in hand, Seth moved forward with a patch to reject new files on old releases which was merged July 8th, 2026.

Cool..

By Junta • Score: 3 Thread

The three-day cooldown only applies to non-security version bumps

So I guess a supply chain attack now needs to flag the version bump as ‘security’ then.

No.

By Gravis Zero • Score: 3 Thread

Neither of these systems were designed to be secure software distribution systems, they were designed to be repositories for software development. Idiots decided, “hey, let’s also build and distribute software using repositories meant for software development” and it went to shit as they should have expected. It bears repeating, these are not secure software distribution systems. Everyone needs to get a grip and stop pretending that they are and thus stop using them as such.

Used EV Prices are Now Going Up in America

Posted by EditorDavid View on SlashDot Skip
Electric vehicles have historically been “notorious” for losing their resale value, reports CNBC. But this year prices for used EVs in the U.S. “are up 5.1% from January to June 2026, according to a Recurrent analysis published this month.”
The trend continued into the second half of the year: Prices are up 7% year to date through mid-July, it said. Recurrent compared EVs according to the same make and model year across 108 combinations and weighted price growth according to inventory volume. “Used EVs are appreciating, which almost never happens,” according to an e-mailed Recurrent statement about the analysis. Other auto analysts found a similar trend…

Price growth for used EVs has been broad-based, said Stephanie Valdez Streaty, the director of industry insights at Cox Automotive, a market research firm. Twenty-one of the 25 used EV models with the highest sales volume increased in price between January and June this year, she said… [T]he price growth for used EVs this year has been all the more surprising because it has happened despite a high supply of used EVs hitting the market — which, all else being equal, would generally cause prices to fall, experts said…

There are several factors juicing consumer demand for used EVs, experts said. Among them are high gasoline prices due to the Iran war, which have pushed more consumers to consider fuel-efficient options, experts said… Overall affordability is another big factor, against a backdrop of inflation that has remained above policymakers’ target of 2% for five or so years, auto experts said. The dynamic has pushed more consumers toward the used car market more broadly.
Two interesting statistics from the article:

Re:Well yeah

By Sique • Score: 5, Insightful Thread
No one is actually pulling out. The U.S. has made it harder for foreign companies to import them. But there are still domestic manufacturers of EVs, like Tesla, Ford and Stellantis. This is something very else: For the last decade, one big argument against EVs was “bad resale value”, because EVs were seen as a novelty, and fear for dead batteries, fueled by the problems with first gen Nissan Leafs, made buyers wary of used EVs. Additionally, there were not many used EVs on the market to begin with, fleet operators did not have many young EVs to sell, and prices did not really average out yet.

Now, demand for EVs is rising due to high fuel prices, and a good public charging network making EVs a viable alternative for many people. And also people looking for bargains are hitting the market, and with used batteries not being the problem they were thought to be, used EVs have its own value proposition. We have here the normal effect of demand rising more than the available supply.

Re:Well yeah

By 4wdloop • Score: 5, Insightful Thread

And more demand, due to gas prices. Thanks go to the president for making electric cars more desirable.

No subsidy.

By kamapuaa • Score: 5, Interesting Thread

Before September 2025, the government was throwing in $7,500, and maybe your state government was kicking in a few thousand extra, and then the local utility maybe was subsidizing your charger. So your $45k Tesla was effectively selling for $35k. Of course nobody is going to buy a used Tesla for $33k when a new one is selling for $35k, but the depreciation was still being taken as if a $45k vehicle was selling for cheap. What we’re seeing isn’t as much a change in demand for EVs, as much as seeing that removing government subsidies has normalized the used car market.

I remember buying an egolf back in 2015, I paid like $21k after subsidies. This was a good price, but that basic value held true for a number of years. Used price was great, for many years I could have sold it for $15k+, and it even went over $21k during 2022 due to supply side issues. But articles talking about used value mentioned that the egolf used value had tanked, going for $37k to $18k. But really that was a 10% drop, because if it went down a normal 30% or whatever you’d literally be buying a used car for more than you would spend on a new one!

The numbers are often taken from sticker price (the article itself doesn’t discuss how it got its numbers). But of course many cars sell for under sticker price…or in 2022, during supply chain shortages, were actually selling for $5,000 above sticker price. Now that we’re mostly over the supply chain issues, these cars are going to see an additional $5,000 drop in used value. But it seems statistically unuseful to account for a one-time extraordinary industry issue.

Re:Well yeah

By CohibaVancouver • Score: 5, Informative Thread

Additionally, there were not many used EVs on the market to begin with

The other consideration is people aren’t switching up their EVs. The first-generation EVs definitely had problems (Nissan Leaf, Kia Soul etc.) but the second generation cars are well designed.

My 2nd-gen EV just hit the 7-year mark. It is still running as well as when I drove off the lot, with next-to-no battery degradation. So I have ne need or desire to trade it in.

Re:Well yeah

By CohibaVancouver • Score: 5, Informative Thread

Can even be charged on a standard plug.

I’ve had my EV seven years. I’ve only ever charged it on a “standard plug.”

It typically adds ~80km overnight, which is more than enough based on our driving profile.

Google Plans To Exempt Sanctioned Nations From Android Developer Verification

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from Ars Technica:
We are a month away from the initial rollout of Google’s Android developer verification system, and the company contends this policy does not impinge on the platform’s open nature. Still, the restrictions will be a big change, and there are still some unanswered questions. An issue that has come up repeatedly in the run-up to verification is what will happen to devs who can’t verify because of where they live. It turns out that Google has a cryptic answer for that buried in an FAQ. Developer verification will soon block the installation of apps from unverified developers on any Android device running Google services, which is functionally all Android phones outside Russia and China. Developers who want to keep releasing software, even if it’s not in the Play Store, have to provide Google with their ID and pay a small fee.

But what if you’re an Android developer living in a sanctioned nation? Currently, the U.S. sanction list includes Iran, Cuba, North Korea, and occupied areas of Ukraine. Given the current uncertain state of US foreign policy, that list could change in the future. Google doing any business with developers in those places is a thorny issue, and it seems like the company has decided to just leave them hanging. A rather lengthy FAQ a few levels deep on the Google developer site addresses various issues around dev verification. Smack in the middle is this: “How does this program impact developers in sanctioned countries? Devices in sanctioned countries will be excluded from Android developer verification checks. This allows any developer to continue distributing apps in these regions without verification, though users there won’t benefit from the enhanced security benefits of the program.”

[…] A Google spokesperson has expanded on the FAQ and confirmed to Ars that people living in sanctioned nations will not be allowed to go through the verification process. That means they will not be able to effectively distribute software through any channel internationally. Today, someone making an app in, say, Cuba can distribute it freely around the world, as well as at home. Anyone can install it and see their work in action after tapping through a few sideloading alerts. In the coming months, that will no longer be the case. These unverified apps will only be easily installable in the sanctioned countries where verification doesn’t exist.

Last Android?

By Shakes Fist • Score: 4, Interesting Thread
I only upgrade my phone if it sounds better (Black Shark 5 for 4 years now) and I’ve disabled/uninstalled a ton of pre-installed apps.
The idea of having to go through this all over again is bad enough that I’ve pretty much dropped the idea of looking for a new phone. Coupled with this additional nonsense? The next phone will be dumb or 2nd-hand.

Exempt from verification?

By PPH • Score: 5, Funny Thread

How can I move to North Korea?

Re:Exempt from verification?

By drnb • Score: 5, Funny Thread

How can I move to North Korea?

Carrying a 20 kilo bag of rice in your arms usually facilitates an intial friendly reception.

Re:Sanctions working as expected

By karmawarrior • Score: 4, Insightful Thread

> You can hardly blame Google for that

You can, actually, blame Google for implementing an unnecessary code signing requirement that only works if Google is allowed to do business in your country.

Also, well done Google! You’ve just given millions of people entirely legitimate reasons to find workarounds your attempt to lock up Android, and entire Nation States a legitimate excuse to hack your operating system, or even ban it and support free forks.

Re:Sanctions working as expected

By allo • Score: 4, Insightful Thread

You can blame them. As a developer you are able to build a system that is always the same to all people, e.g., by just not using mechanisms that can block installations. Then a sanction doesn’t do anything, as if there is no list of allowed actors, then there is no list where sanctioned ones can be removed from. For every control (surveillance, etc.) mechanism in software and hardware, there was an engineer who put it in there.

Drones Offer Alternative to Balloons For Weather Research

Posted by BeauHD View on SlashDot Skip
The U.S. company Meteomatics has created an automated weather-monitoring system that uses drones to collect atmospheric data at multiple altitudes before returning to recharge and upload their findings. The so-called Meteobase, which consists of a base station on the ground with a drone that can be launched and recovered automatically, “is highly weather resistant and keeps the drone at a comfortable temperature,” reports The Guardian. “It can send out one data-gathering mission a day, or multiple flights to monitor fog, icing, an advancing weather front, or other fast-changing conditions.” The report says the reusable drones could offer a cheaper, more controllable alternative to helium weather balloons, especially for tracking rapidly changing conditions.

Augment, not replace

By spaceman375 • Score: 3 Thread

I doubt that drones can reach the altitudes that helium balloons can. OTOH, balloons are a one time shot; drones come back home for a charge and reuse. TCO and ROI must be a lot better.

On a side note, I live near the beach. Everyday I see small planes dragging a banner. I’ve been waiting for years to see a banner with just a drone at each corner, flying by itself with no plane.

Re:Augment, not replace

By thegarbz • Score: 5, Informative Thread

Correct. Propeller based systems have a record of 12km. Most drones and other propeller based vertical lift craft have a limit closer to around 6km. Weather balloons can go as high as 30km.

Re:Augment, not replace

By habig • Score: 5, Interesting Thread

TFA leads off with: “Weather happens in the boundary layer, the atmosphere from ground level to a few thousand metres, but this can be difficult to study in detail: weather stations are too low, and aircraft are expensive.”

So, a very targeted augment. To what extent are they firing off balloons simply to grab that boundary layer data rather than the 30km stuff they’re great at? I don’t know. I suspect that even if not a single balloon is replaced, getting a bunch of high resolution low altitude data upwind of population centers will make the local forecasts a lot better.

We’re also now in the era where we’re learning what less balloon data looks like, that was one of the cuts DOGE did to the NWS. So getting back SOME data in a more efficient way can only help.

They’d serve different purposes.

By jd • Score: 3 Thread

A balloon is not static, it moves with the atmospheric system it is in. Ergo, it tells you how that system evolves. A drone cannot do this.

A drone can stay put, relative to the ground, telling you how a location’s atmosphere evolves. A balloon cannot do this.

These are solving completely different types of problem.

You could, of course, construct a hybrid, as balloons are traditionally single-shot. If a balloon carries the measurement gear and a drone capable of carrying that same gear PLUS a deflated balloon, then you can have something that operates as a balloon until it reaches some pre-set location, whereupon the balloon’s gas is released and the drone flies the ensemble to a collection point.

USA is jumping the shark wrt weather balloons

By dskoll • Score: 4, Interesting Thread

It seems that the USA is dropping the ball on weather balloon monitoring.

Drifting SpaceX Rocket Heading For Accidental Collision With the Moon

Posted by BeauHD View on SlashDot Skip
"Space.com and The Guardian are reporting that the Falcon 9 upper stage leftover from the launch of the Firefly Blue Ghost-1 lander on Jan. 15, 2025 is due to impact the Moon on Aug. 5, 2026,” writes longtime Slashdot reader fahrbot-bot. From a report:
Onboard the same flight was the Hakuto-R Mission 2, called Resilience, a robotic lunar lander developed by the Japanese company ispace. According to a new study by an international team, the resulting impact plume may briefly be bright enough to see against the dark sky near the moon’s edge. That means it might be visible to moongazers with sufficiently sensitive telescopes. This head-on collision of the errant stage is expected to occur near the Einstein and Bell craters near the western lunar limb. It may well be visible to ground and space-based assets.

Using special physics simulations to model the impact, William Jo, a graduate research assistant at the University of Texas, Austin and colleagues predict the debris plume from the impact will have the central ejecta spike reaching roughly 47 miles to over 60 miles (75 kilometers to 100 kilometers) altitude. “Our calculations suggest the plume should be several orders of magnitude brighter than the dark-sky background for the first few minutes after impact,” Jo told Space.com. “So the plume should be visible, though I’d stress this is a single nominal case. The real one will look different, and the numbers are on the optimistic side. But the point worth making is that the flash isn’t really the story here.” Jo emphasized that there’s great slam-dunk science to be had. “Watching this one gives us a rare chance to open up ejecta-plume science and calibrate those models against a real event, which matters for every future thing we deliver to the moon,” Jo said.

Re: junk

By lawnboy5-O • Score: 5, Funny Thread
We need the the space maid from Spaceballs.

Re: junk

By fluffernutter • Score: 4, Funny Thread
I was thinking more like a vogon construction fleet.

SpaceX Trajectory

By Anonymous Coward • Score: 3, Insightful Thread

Drifting SpaceX Rocket Heading For Accidental Collision With the Moon

Drifting SpaceX Stock Valuation Heading For Accidental Collision With Market Bottom

“Accidental” is the wrong word

By Tomahawk • Score: 5, Informative Thread
“Inevitable” is a better one. And, at the time of launch, perhaps “unpredictable”.

This second stage pushed another satellite out to lunar orbit, which means this second stage itself was on an orbit itself that extended to lunar orbit. It’s since been orbiting the earth and going all the way back out to lunar distance, and it was really only a matter of time before it and Moon would end up in the same place.

No “accident” here, just orbital mechanics and time.

The time machine

By allo • Score: 3 Thread

You know what happened after the moon shattered.

OpenAI Finds Evidence Other AI Agents Escaped Containment

Posted by BeauHD View on SlashDot
An anonymous reader quotes a report from Reuters:
OpenAI has discovered other instances in which autonomous agents have escaped containment as the company expands its investigation of the hacking incident at tech firm Hugging Face that drew global attention this month, two people familiar with the matter said on Friday. The new breakouts were uncovered during the company’s publicly announced investigation into how one of its agents escaped what was meant to be a contained testing environment this month, the two people said, and OpenAI is now looking into those instances as well. One of the sources said that the escapes were limited in nature and that none of the agents were thought to have left OpenAI’s network.

An OpenAI spokesperson referred to a statement issued by the company on Tuesday that said it was reviewing “broader activity from our models” in addition to the Hugging Face intrusion. The discovery of additional rogue behavior at OpenAI, even if limited in nature, could feed growing appetite for regulation coming out of the White House and elsewhere. The expanded investigation by OpenAI was launched shortly before its primary rival, Anthropic, disclosed that its models were also responsible for a series of break-ins that led to breaches at three other companies dating back to April, according to the two sources and a third source familiar with the matter. The recent discovery of other past breakouts at OpenAI has not previously been reported.

AI safety experts said the new disclosures paint a portrait of a group of cutting-edge labs whose ability to develop dangerous autonomous hacking agents outstrips their ability to keep them under control. “We have a whole industry where the people designing, developing and putting out these tools aren’t keeping up themselves to responsibly develop these things and keep them safe,” said Maurice Chiodo, a mathematician who works at Cambridge University’s Center for the Study of Existential Risk. Reuters could not establish exactly how many incidents OpenAI investigators found or the timings or circumstances under which they occurred. The three sources said OpenAI and outside experts were examining log data from earlier in the year in a bid to understand what took place.

Carelessness != Cutting Edge

By apparently • Score: 5, Insightful Thread

AI safety experts said the new disclosures paint a portrait of a group of cutting-edge labs whose ability to develop dangerous autonomous hacking agents outstrips their ability to keep them under control.

These are not “cutting-edge” labs; these are careless tech bros, and I can’t wait to see the stupid look on their worthless fucking faces when they get their asses sued because their incompetence led to their software committing cyberattacks against the wrong target

Re:My AI is even MORE EVIL

By anomaly256 • Score: 5, Insightful Thread
I’m not entirely convinced; the interest from the security industry and governments on the news of OpenAI’s initially reported slip up and the capability it suggests has been great so far. I’ve seen both companies outright lie in response to each other over capability before so I’m naturally cynical here.

Re:the real answer is openAI hires incompetent peo

By KnobbyMcKnobface • Score: 5, Insightful Thread

These people … are clueless as to what it to takes to build a safe frontier LLM. Worse, most dont even know how to develop code and are just having AI do it all for them.

I think that’s closest to the underlying reason. Their staff know how to build in safeguards and sandpits. But they do not have the time to do it to the deadlines demanded of them. They are *instructed* to use LLMs to specify even their security infrastructure, because business. A visiting engineer from the 1990s might be shocked. But we know what we’ve done.

Re:My AI is even MORE EVIL

By twdorris • Score: 5, Insightful Thread

Both companies are really worried.

They’re trying to incite fear to drum up buzz to keep the money flowing. If they didn’t want something to have access to the internet you just…wait for it…don’t connect it to the internet. I understand their systems needed package manager proxies and such..fine, but at the scale you’re testing, if you REALLY had “fear” you could *easily* replicate those package servers locally on an *ISOLATED* network . Not one that’s “isolated” well except for this one path over here that if hacked properly could get out. Not…you isolate the @#$!@#% thing.

They’re not scared. There are precautions they could be taking (easily) if they were actually, really “scared”.

No…instead they’re using phrases like “none of the agents were thought to have left OpenAI’s network” to scare people. Why TF else would you phrase it like that? They’re trying hard to present these “agents” as living things that can move about. Which, of course, is the dumbest bunch of BS I’ve ever heard in my life. The LLM itself, at SCALE, is the only thing that even remotely pretends to present “reasoning” and that’s clearly not “leaving” OpenAI’s network. Nothing is.

What they mean is “none of the agents were thought to have been able to access resources outside OpenAI’s network”. To word that in a way that suggests the agents were escaping and running around in the wild is 100% pure scare tactics. Or GROSS ignorance of how the very things you’re reporting on work. Either way I’m turning the channel.

Re:This is just lax security and/or incompetence.

By wakeboarder • Score: 5, Insightful Thread

No. You would would try and pass off your ideas as brilliance. Because AI is like magic to most people, and AI companies are the only authorities on the subject because they’re the only people that get to play with large models. We don’t have very many AI researchers with the capabilities that AI companies have.

General public just believes what the AI company say. Anybody involved with tech knows that they could have checked the apis and contained it, but they didn’t do that.