Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.
Hamburg Is Replacing a Bridge In One Huge Piece
Long-time Slashdot reader Qbertino writes:
The northern German City of Hamburg is currently in the process of replacing one of its bridges in one single gigantic piece. The new replacement weighs 3700 metric tons and was carefully moved into place over a stretch of 500 meters, requiring extreme patience and precision maneuvering. Some places leave only 40 cm of room to neighbouring buildings.
New GitHub, PyPI Policies Hope to Boost Supply Chain Security
“GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security,” reports SecurityWeek, “by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases.”
To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown, where the automation tool waits for at least three days after a release has been published before opening a pull request. “Waiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests,” GitHub explains.
The three-day cooldown only applies to non-security version bumps, and the behavior can be modified through the configuration option in the dependabot.yml. “Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn’t hold your dependencies back longer than necessary,” GitHub notes.
And the Python Package Index (PyPI) “now rejects new files being uploaded to releases that are older than 14 days,” according to a recernt blog post from the Python Software Foundation’s security developer-in-residence Seth Larson:
This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised… The discussion of this behavior began during PEP 740 (Digital Attestations) back in January 2024. The discussion was restarted in March 2026 after the popular packages LiteLLM and Telnyx were compromised. These packages were compromised due to a "mutable reference" in these projects’ usage of the Trivy GitHub Action…
To quantify how disruptive this change would be to existing workflows, the PyPI database was queried for projects that have published new files to old releases… [O]nly 56 projects of 15,000 had published a [Python] 3.14-compatible wheel more than 14 days after a release was available. This topic was brought to the Packaging Summit at PyCon US 2026 by PyPI Safety & Security Engineer, Mike Fiedler. The rough consensus of the discussion was that the summit attendees thought it was “acceptable to require users to bump to the next version” to support new Python versions. With the data and consensus in hand, Seth moved forward with a patch to reject new files on old releases which was merged July 8th, 2026.
Used EV Prices are Now Going Up in America
Electric vehicles have historically been “notorious” for losing their resale value, reports CNBC. But this year prices for used EVs in the U.S. “are up 5.1% from January to June 2026, according to a Recurrent analysis published this month.”
The trend continued into the second half of the year: Prices are up 7% year to date through mid-July, it said. Recurrent compared EVs according to the same make and model year across 108 combinations and weighted price growth according to inventory volume. “Used EVs are appreciating, which almost never happens,” according to an e-mailed Recurrent statement about the analysis. Other auto analysts found a similar trend…
Price growth for used EVs has been broad-based, said Stephanie Valdez Streaty, the director of industry insights at Cox Automotive, a market research firm. Twenty-one of the 25 used EV models with the highest sales volume increased in price between January and June this year, she said… [T]he price growth for used EVs this year has been all the more surprising because it has happened despite a high supply of used EVs hitting the market — which, all else being equal, would generally cause prices to fall, experts said…
There are several factors juicing consumer demand for used EVs, experts said. Among them are high gasoline prices due to the Iran war, which have pushed more consumers to consider fuel-efficient options, experts said… Overall affordability is another big factor, against a backdrop of inflation that has remained above policymakers’ target of 2% for five or so years, auto experts said. The dynamic has pushed more consumers toward the used car market more broadly.
Two interesting statistics from the article:
- “Used EV sales were up 20% in June versus a year earlier, while sales of new EVs were down about 28%, according to Cox Automotive data.”
- New EVs accounted for 5.4% of total new-vehicle sales in June, while the market share for used EVs was just 2.4%, according to Cox Automotive data.
Google Plans To Exempt Sanctioned Nations From Android Developer Verification
An anonymous reader quotes a report from Ars Technica:
We are a month away from the initial rollout of Google’s Android developer verification system, and the company contends this policy does not impinge on the platform’s open nature. Still, the restrictions will be a big change, and there are still some unanswered questions. An issue that has come up repeatedly in the run-up to verification is what will happen to devs who can’t verify because of where they live. It turns out that Google has a cryptic answer for that buried in an FAQ. Developer verification will soon block the installation of apps from unverified developers on any Android device running Google services, which is functionally all Android phones outside Russia and China. Developers who want to keep releasing software, even if it’s not in the Play Store, have to provide Google with their ID and pay a small fee.
But what if you’re an Android developer living in a sanctioned nation? Currently, the U.S. sanction list includes Iran, Cuba, North Korea, and occupied areas of Ukraine. Given the current uncertain state of US foreign policy, that list could change in the future. Google doing any business with developers in those places is a thorny issue, and it seems like the company has decided to just leave them hanging. A rather lengthy FAQ a few levels deep on the Google developer site addresses various issues around dev verification. Smack in the middle is this: “How does this program impact developers in sanctioned countries? Devices in sanctioned countries will be excluded from Android developer verification checks. This allows any developer to continue distributing apps in these regions without verification, though users there won’t benefit from the enhanced security benefits of the program.”
[…] A Google spokesperson has expanded on the FAQ and confirmed to Ars that people living in sanctioned nations will not be allowed to go through the verification process. That means they will not be able to effectively distribute software through any channel internationally. Today, someone making an app in, say, Cuba can distribute it freely around the world, as well as at home. Anyone can install it and see their work in action after tapping through a few sideloading alerts. In the coming months, that will no longer be the case. These unverified apps will only be easily installable in the sanctioned countries where verification doesn’t exist.
Drones Offer Alternative to Balloons For Weather Research
The U.S. company Meteomatics has created an automated weather-monitoring system that uses drones to collect atmospheric data at multiple altitudes before returning to recharge and upload their findings. The so-called Meteobase, which consists of a base station on the ground with a drone that can be launched and recovered automatically, “is highly weather resistant and keeps the drone at a comfortable temperature,” reports The Guardian. “It can send out one data-gathering mission a day, or multiple flights to monitor fog, icing, an advancing weather front, or other fast-changing conditions.” The report says the reusable drones could offer a cheaper, more controllable alternative to helium weather balloons, especially for tracking rapidly changing conditions.
Drifting SpaceX Rocket Heading For Accidental Collision With the Moon
"Space.com and The Guardian are reporting that the Falcon 9 upper stage leftover from the launch of the Firefly Blue Ghost-1 lander on Jan. 15, 2025 is due to impact the Moon on Aug. 5, 2026,” writes longtime Slashdot reader fahrbot-bot. From a report:
Onboard the same flight was the Hakuto-R Mission 2, called Resilience, a robotic lunar lander developed by the Japanese company ispace. According to a new study by an international team, the resulting impact plume may briefly be bright enough to see against the dark sky near the moon’s edge. That means it might be visible to moongazers with sufficiently sensitive telescopes. This head-on collision of the errant stage is expected to occur near the Einstein and Bell craters near the western lunar limb. It may well be visible to ground and space-based assets.
Using special physics simulations to model the impact, William Jo, a graduate research assistant at the University of Texas, Austin and colleagues predict the debris plume from the impact will have the central ejecta spike reaching roughly 47 miles to over 60 miles (75 kilometers to 100 kilometers) altitude. “Our calculations suggest the plume should be several orders of magnitude brighter than the dark-sky background for the first few minutes after impact,” Jo told Space.com. “So the plume should be visible, though I’d stress this is a single nominal case. The real one will look different, and the numbers are on the optimistic side. But the point worth making is that the flash isn’t really the story here.” Jo emphasized that there’s great slam-dunk science to be had. “Watching this one gives us a rare chance to open up ejecta-plume science and calibrate those models against a real event, which matters for every future thing we deliver to the moon,” Jo said.
OpenAI Finds Evidence Other AI Agents Escaped Containment
An anonymous reader quotes a report from Reuters:
OpenAI has discovered other instances in which autonomous agents have escaped containment as the company expands its investigation of the hacking incident at tech firm Hugging Face that drew global attention this month, two people familiar with the matter said on Friday. The new breakouts were uncovered during the company’s publicly announced investigation into how one of its agents escaped what was meant to be a contained testing environment this month, the two people said, and OpenAI is now looking into those instances as well. One of the sources said that the escapes were limited in nature and that none of the agents were thought to have left OpenAI’s network.
An OpenAI spokesperson referred to a statement issued by the company on Tuesday that said it was reviewing “broader activity from our models” in addition to the Hugging Face intrusion. The discovery of additional rogue behavior at OpenAI, even if limited in nature, could feed growing appetite for regulation coming out of the White House and elsewhere. The expanded investigation by OpenAI was launched shortly before its primary rival, Anthropic, disclosed that its models were also responsible for a series of break-ins that led to breaches at three other companies dating back to April, according to the two sources and a third source familiar with the matter. The recent discovery of other past breakouts at OpenAI has not previously been reported.
AI safety experts said the new disclosures paint a portrait of a group of cutting-edge labs whose ability to develop dangerous autonomous hacking agents outstrips their ability to keep them under control. “We have a whole industry where the people designing, developing and putting out these tools aren’t keeping up themselves to responsibly develop these things and keep them safe,” said Maurice Chiodo, a mathematician who works at Cambridge University’s Center for the Study of Existential Risk. Reuters could not establish exactly how many incidents OpenAI investigators found or the timings or circumstances under which they occurred. The three sources said OpenAI and outside experts were examining log data from earlier in the year in a bid to understand what took place.
The Major Labels Propose Rules to Keep AI Slop Off the Charts
Major record labels including Universal, Sony, and Warner have proposed excluding AI-generated songs from official charts unless they are “substantially human made,” properly labeled, legally produced, and free from manipulation concerns. The Verge reports:
The proposal goes quite a bit further than a labeling proposal put forth by the RIAA, the International Federation of the Phonographic Industry (IFPI), SAG-AFTRA, and others. That would create a set of standardized labels for AI-generated and AI-assisted music. The labels’ proposal would require songs be clearly labeled, but it would also keep them off international charts unless they met specific criteria, including being “substantially human made.”
To be eligible, the songs would also have to respect the terms of service of whatever AI service was used, the model would have to have the rights to any data it was trained on, and “not raise stream or chart manipulation concerns.” What sort of concerns and what constitutes “substantially human made” are currently vague. Sony Music, UMG, and Mom+Pop Music did not immediately respond to a request for clarification. The IFPI has thrown its weight behind the labels’ proposal, though no charting organization has signaled any immediate plan to adopt the rules […].
Most Australian Teens Still On Social Media Three Months After Ban
More than 81% of Australian children ages 10 to 15 were still using social media three months after the country’s under-16 ban took effect, with roughly half saying platforms never checked their age. Reuters reports:
In a study published on Friday, eSafety also found most children aged between 10 and 15 were using social media just as frequently in March as they had before the ban came into force on December 10 last year, while parental awareness of their habits decreased. Children’s continued social media use took place even as account ownership declined to 42% from 52%, with “statistically significant” reductions across YouTube, Snapchat and TikTok in particular, the report said.
“Most under-16s who had social media accounts before commencement were able to either retain them or create new ones at the three-month mark, with social media platforms’ failure to implement effective age assurance measures cited as the main reason,” eSafety said in a statement […] Before the ban, nearly 86% of children surveyed reported using at least one age-restricted platform. Three months later, that figure remained above 81%, the report said. About 58% of teenagers reported using social media daily or more often, barely down from roughly 60% before the ban, it found. The report showed minimal change in “sports and physical activity, arts and music, spending time with friends and family, and attendance at community events.”
Around half the children who retained their accounts said platforms had not checked their age, the most common reason they were able to stay on the services. Others said their accounts listed them as aged 16 or older or that age-checking systems had incorrectly determined they were older. The findings broadly matched snapshot data eSafety published in late March.
Sony Heard Backlash Over Dropping PlayStation Discs, Plans to Press Ahead
Sony says it will proceed with ending PlayStation disc sales in January 2028 despite petitions, boycott threats, and concerns about digital ownership and the disappearance of the secondhand market. PCMag reports:
After Sony’s recent earnings call, an investor Q&A session saw analysts ask about its controversial decision to end disc production across all of its consoles. The company hadn’t publicly commented since its announcement and had reduced activity on social accounts and other marketing channels. Sony’s chief financial officer, Lin Tao, broke that silence during the Q&A. “There are various reasons we made this decision,” she said through an interpreter. “The biggest being that the digitalization of content overall has been progressing. That’s the big factor. It’s not just for PlayStation, but for all kinds of content, digitalization is progressing. “And so when we think about the future, and we put in a lot of thought and time, and we cautiously considered this, and we came to this conclusion, and we’re going to cautiously move this forward,” Tao said.
“We have received various opinions, and people have strong views, and we understand that the community has put forth those views to us,” said Tao. […] Tao says Sony wants to “consider” the emotions of disgruntled customers, especially as titles are “connected to people’s fond memories in many cases.” Tao also alluded to the possibility of future measures to lessen the blow for anyone unhappy with the decision, but it appears Sony hasn’t yet finalized what those may be. “In the future digital ecosystem, how do we engage the gamers is something that we would like to continue to explore,” she said.
Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says
An anonymous reader quotes a report from NBC News:
Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure. In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states.
The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation. A spokesperson for Minnesota’s information technology services agency said Thursday there was no indication the breaches contaminated any municipal water supplies. The federal Cybersecurity and Infrastructure Security Agency said in a separate alert that some larger attacks on water infrastructure had “resulted in boil water notices and sustained manual operations,” though it did not say where.
[…] The federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions. […] The agencies said the hackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities. The federal advisory calls on system operators to remove programmable logical controllers, or PLCs, from direct internet exposure by putting them behind secure gateways and firewalls; use strong passwords; and limit communications between authorized control system devices through access control lists.
New Google Earth AI Tool Could Fuel Misinformation, Experts Say
Google has integrated its Nano Banana 2 image generator into Google Earth, allowing users to place AI-generated events and objects onto real satellite imagery. The company says its AI-generated images contain invisible watermarks detectable through Gemini or Lens, but the BBC found those safeguards and some third-party detection tools can be fooled into labeling manipulated Google Earth images as real. From the report:
A collapsed Eiffel Tower, a sinkhole swallowing the Great Pyramid of Giza and Russian tanks in Ukraine’s capital were among the images BBC Verify was able to create when testing the feature, which was rolled out on Thursday. Google has not yet responded to questions based on BBC Verify’s tests, but in a social media post the company said they “take misinformation seriously” and that “we prevent image creation on harmful topics and are continually updating our protections.”
AI and misinformation expert Henk van Ess has highlighted the risks this feature poses, creating fake images of a non-existent nuclear power plant in Iran, a refugee camp on the US-Mexico border and a fake hospital in Gaza with a bomb crater next to it. He said Google was allowing “invented” imagery to be “welded to genuine coordinates, drawn on genuine imagery.” “The forgery does not have to look convincing on its own. It inherits the credibility of the map it was born on,” van Ess added.
UPDATE 7/31/26 10:54 AM: Google is rolling back the image generation inside of Google Earth: “We know that people uniquely trust Google Earth for a reliable view of the world. We’ve seen geospatial professionals using this feature for a range of useful purposes, however we’ve also seen people sharing screenshots of generated imagery that appear to violate our policies. So we’re rolling back this feature in Google Earth while we work on implementing stronger guardrails. It’s important to note that generated images didn’t appear in the main Google Earth experience for others to see and were watermarked as AI generated.”
Publishers Are Losing Google Traffic As AI Answers Replace Links
alternative_right shares a report from Axios:
Google has basically stopped sending people to websites (including our site) for answers and information. Instead, it’s using AI to answer them on its platform, in its words. Chartbeat data shared with Axios shows Google Search traffic to publishers fell 34% over the past year. That pain is regressive. Over the past two years, small publishers lost 60% of referrals from search overall, medium publishers 47%, large publishers 22%.
New York Sues Kalshi For Running ‘Illegal Gambling Operation’
New York has sued prediction-market platform Kalshi, alleging it operates an “illegal gambling operation” without state authorization. “No matter what they call themselves, prediction markets like Kalshi are gambling platforms, plain and simple,” said New York Attorney General Letitia James in a press release announcing the lawsuit. “By ignoring our laws, Kalshi is running an illegal operation and harming New Yorkers in the process.” CNBC reports:
In a case filed in a Manhattan state court (PDF), the lawsuit claims that Kalshi accepts wagers as a gambling business in disregard for the state’s constitution and laws by not being registered with the New York State Gaming Commission. Governor Kathy Hochul in the press release said the state is taking the action to stop what it views as illegal behavior and bring the company into compliance with New York law. The lawsuit is seeking a permanent injunction against Kalshi.
The suit by the state is also seeking a total restitution to users who have placed trades on the platform, a $100,000 penalty for each attempt to offer sports wagering, and another penalty three times the amount the company has gained while allegedly operating in violation of New York law. The state estimates that could total $36 billion.
Chrome Is Using AI To Fix Hundreds of Bugs, Eliminate Full Browser Restarts
Google says AI-assisted workflows helped Chrome fix 1,072 security bugs across versions 149 and 150, more than the previous 23 releases combined. The company is also testing twice-weekly security updates and “dynamic patching,” which could apply most fixes without requiring users to restart the entire browser. “By leveraging Chrome’s multi-process architecture, dynamic patching sequentially replaces background child processes (like the Renderer and GPU) with updated binaries on the fly,” says Google in a blog post. PiunikaWeb reports:
Alongside dynamic patching, Google is rolling out smarter background updates during periods of minimal user disruption. Starting with Chrome 150 on macOS, the browser takes advantage of the operating system’s windowless state. If all Chrome windows are closed but the app remains running in the background, the browser will quietly auto-restart to apply pending updates.
For enterprise environments, IT admins can continue to manage fleet-wide deployments through Chrome Enterprise Core or enforce update prompts using the RelaunchNotification policy. Google’s long-term vision is a browser that remains continuously protected in the background without interrupting your daily browsing session. In the meantime, you can manually trigger pending updates by clicking the update prompt in the top-right corner of Chrome.
No subsidy.
Before September 2025, the government was throwing in $7,500, and maybe your state government was kicking in a few thousand extra, and then the local utility maybe was subsidizing your charger. So your $45k Tesla was effectively selling for $35k. Of course nobody is going to buy a used Tesla for $33k when a new one is selling for $35k, but the depreciation was still being taken as if a $45k vehicle was selling for cheap. What we’re seeing isn’t as much a change in demand for EVs, as much as seeing that removing government subsidies has normalized the used car market.
I remember buying an egolf back in 2015, I paid like $21k after subsidies. This was a good price, but that basic value held true for a number of years. Used price was great, for many years I could have sold it for $15k+, and it even went over $21k during 2022 due to supply side issues. But articles talking about used value mentioned that the egolf used value had tanked, going for $37k to $18k. But really that was a 10% drop, because if it went down a normal 30% or whatever you’d literally be buying a used car for more than you would spend on a new one!
The numbers are often taken from sticker price (the article itself doesn’t discuss how it got its numbers). But of course many cars sell for under sticker price…or in 2022, during supply chain shortages, were actually selling for $5,000 above sticker price. Now that we’re mostly over the supply chain issues, these cars are going to see an additional $5,000 drop in used value. But it seems statistically unuseful to account for a one-time extraordinary industry issue.