Alterslash

the unofficial Slashdot digest
 

Contents

  1. Are AI Chatbots Spreading Misinformation to US Voters?
  2. Apple Faces $5.7 Billion Patent Infringement Verdict Over iPhone And Apple Watch Haptics
  3. Just How Big is the AI Buildout - and How Risky?
  4. Waymo Says Its Self-Driving Cars Reduced Injury-Causing Accidents by 82%
  5. After Dozens of Incidents at OpenAI and Anthropic, OpenAI Pauses Model Training to Build More Safeguards
  6. New Tin-based Solar Cells Trap Heat 1,000 Times Longer, Could Beat 33% Limit
  7. China and the US Say They’ve Agreed to Start Talks About AI
  8. KDE and GNOME Developers Ponder How to Handle AI-Generated Contributions
  9. After 40 Years, Microsoft Excel Will Add Single-Cell Lists and Arrays
  10. AI Finds So Many Linux Bugs, Canonical Changes to a Two-Week Stable Release Update Cycle
  11. Is Microsoft Quietly Killing Off Its ‘Copilot+ PC’ Brand?
  12. Rogue OpenAI Agents Posted 53 User-Uploaded Images Onto the Internet, Accessed US Government Websites
  13. Meta Made 43M Misleading Statements, New Mexico Jury Finds, Including on Its Cambridge Analytica Response
  14. There’s a New Way to Break RSA Encryption
  15. Asteroids Named After Tom Lehrer and ‘Weird Al’ Yankovic

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

Are AI Chatbots Spreading Misinformation to US Voters?

Posted by EditorDavid • • View on SlashDot • Skip
Are AI chatbots quietly shaping the perceptions of U.S. voters? Voters trying to educate themselves about candidates “are unknowingly being served partisan talking points in the guise of neutral news summaries,” write two news researchers in Politico magazine:
Leading AI chatbots cite partisan websites masquerading as independent local news outlets nearly half of the time when people ask about candidates and issues that the partisan sites have covered in the midterm campaign, according to a new audit by NewsGuard, an organization focused on news reliability where we work as analysts… NewsGuard prompted seven leading AI tools with queries based on recent coverage of candidates and issues by 12 pink slime sites — six left-leaning and six right-leaning. The results were stark. Collectively, the chatbots cited pink slime sites along with other sources in 48.2 percent of their responses.

In 7.7 percent of responses, pink slime sites were the only sources at all that were cited in chatbot responses, although other sources appeared in the source list provided at the end of the response.

None of the AI tools received results they’d probably be eager to boast about, though the percentage of chatbots’ responses that cited a pink slime site had a relatively large range: 70.8 percent for OpenAI’s ChatGPT, 54.2 percent for Microsoft’s Copilot, 54.2 percent for Perplexity, 50 percent for Anthropic’s Claude, 41.7 percent for Google’s Gemini; 37.5 percent for Meta AI and 29.2 percent for xAI’s Grok… The seven chatbots were also collectively three times more likely to cite left-leaning pink slime sites (cited in 36.3 percent of responses) than their right-leaning counterparts (cited in 11.9 percent of responses) — though that may have more to do with the progressive sites’ far more frequent posting than any political bias from the chatbots.
“While citing the pink slime sites, only one chatbot response out of 168 total queries noted the partisan nature of the source,” the article points out.

But they also note that the real problem seems to be that consumer-oriented AI chatbots just “use much of the internet’s content — regardless of the reliability or standards of the source — to frame their answers.”

Yes they do

By Mr. Dollar Ton • • Score: 3 • Thread

all online “ai” operates under strict “neutrality” rules, which normalize all opinions on a subject without regard to whether there is any objective reality behind them. moreover, the opinions of the provider and the government are amplified, whereas anything else is downplayed.

but if you expect a reality-based answer from a text generator whose training you know nothing about as the reality, perhaps you’re the problem and should be disqualified from voting.

Shorten the question.

By Rendus • • Score: 5, Insightful • Thread

“Are AI Chatbots Spreading Misinformation?” - Yes.

Water and wet

By Errol backfiring • • Score: 3 • Thread

Sorry, we are still investigating the “is water wet?” question.

Best regards,
The Captain Obvious Research Institute

This is not a new thing

By hyades1 • • Score: 3 • Thread

This is a bit of a twist on what’s gone on in journalism for the last hundred years, but it isn’t entirely a new invention.

When I was a teenager and working for a small town weekly newspaper, the editor spelled it out for me: “If something arrives all nicely written in CP style, easy to cut from the bottom up, ready to drop into any unexpected hole you might have on a page, you should remember somebody paid good money to get it onto your desk”.

Apple Faces $5.7 Billion Patent Infringement Verdict Over iPhone And Apple Watch Haptics

Posted by EditorDavid • • View on SlashDot • Skip
“A federal jury in San Diego awarded Taction Technology more than $5.7 billion in damages Friday after finding that Apple infringed claims from two haptics patents,” reports CNBC:
Taction sued Apple in 2021 in the U.S. District Court for the Southern District of California. The company alleged that Apple was improperly “capitalizing on Taction’s innovation and success” by selling devices that infringed on its vibration technology, according to the complaint. Apple initially won dismissal in 2023, and the Federal Circuit later revived the case....

Taction argued that Apple’s “Taptic Engine,” which is embedded in its Apple Watches and iPhones, uses its inventions without proper license or authority.
Taction’s lead counsel told CNBC “Taction waited five and a half years for this case to get to trial, so it was a long time coming.”

CNBC also reported that the jury “did not find Apple’s infringement willful” — and that Apple said they’d appeal.

haptics history

By jsepeta • • Score: 4, Informative • Thread

Taction Technology is a San Diego-based audio technology company that was founded and incorporated around 2014. The Patents Involved in the Apple LawsuitThe high-profile patent infringement lawsuit centers on tactile transducer technology (utilizing dampening systems, magnets, and ferrofluid to handle low-frequency audio and haptic feedback). The foundational patents were created, filed, and issued within the following timeframes: U.S. Patent No. 10,659,885 (“Systems and methods for generating damped electromagnetically actuated planar motion for audio-frequency vibrations”): Filed on October 3, 2019, and officially issued on May 19, 2020.U.S. Patent No. 10,820,117: A closely related continuation patent sharing the same core technical specification, issued later in 2020.*(Note: Taction originally filed the federal lawsuit against Apple in 2021, which recently went to trial resulting in a major jury verdict.)

Now wait, when did Apple add haptics to the Apple Watch?
Apple’s First Device with Haptics
Apple Watch (2014): Apple first introduced its proprietary Taction Engine (branded as the Taptic Engine) in the original Apple Watch released in late 2014 to simulate physical taps on the wrist.
iPhone 6s (2015): The technology was brought to the iPhone lineup the following year with the iPhone 6s and 6s Plus.

So Taptics didn’t start operating as a company until the time Apple built haptics into the Apple Watch. And they didn’t file for a patent until 5 years later. That’s sus.

Sony: Released the DualShock controller for the original PlayStation in 1997, which introduced built-in dual eccentric rotating mass (ERM) motors to deliver rumble feedback. (Note: While Nintendo introduced the plug-in Rumble Pak accessory earlier in 1997, Sony’s DualShock was the first mainstream controller to build native haptic motors directly into the standard hardware).
Microsoft: Included dual rumble motors right from its entry into the console market with the launch of the original Xbox (“The Duke” controller) in 2001.

So haptic technology had been around in popular gaming products for 17 years prior to the Apple Watch and 22 years prior to Taptics filing their patent.

Taptics is a patent troll. They can Fuck Right Off.

Just How Big is the AI Buildout - and How Risky?

Posted by EditorDavid • • View on SlashDot • Skip
A new Brookings Institution study notes the “strikingly physical” economic footprint of AI’s buildout, from specialized chips and electricity to purpose-built data centers. (Two-thirds of a data center’s costs are IT equipment, with one-third going to real estate and its associated power infrastructure.) “At an average of 3.63 percent of GDP per year, the projected buildout would be larger relative to the economy than the major U.S. canal, railroad, electrification, highway, and telecommunications investment booms.”

This is pushing up prices for workers, electricity, and even commercial real estate (as well as consumer products that use chips), notes the Wall Street Journal, and reducing the construction on new houses and apartment buildings. And in addition, the paper points out, projections for this buildout “would double the electricity consumption of the entire U.S. residential sector.”

The calculations come from Columbia Business School finance/real estate professor Stijn van Nieuwerburgh — and Reuters explains their significance:
Just as the rail and telecoms expansions led to notable bubbles and busts, Van Nieuwerburgh wrote that the extent of the buildout, the still-untested revenue streams, and the intricate financing structure emerging around AI mean it could be primed for a fall. “This is freaking complicated,” he said in a briefing with reporters of the arrangements emerging between AI firms, major tech hyperscalers, banks, private credit lenders, real estate firms, and a host of other players involved in building what he conservatively estimated at 183 gigawatts worth of new data-center capacity over the next seven years, compared with about 57 gigawatts currently installed.... The investment underway already has outstripped what the major players can fund from their own cash flows. The shift to outside financing has increased leverage, redistributed risks across the economy, and made the venture dependent on revenue streams that have yet to be proven, Van Nieuwerburgh noted in the paper, which will be presented on Friday…

“These developments do not imply that financial distress is imminent. Strong growth in AI applications, high utilization, and continued improvements in model capability could support the projected infrastructure and generate stable cash flows,” he wrote. “But the combination of uncertain demand, rapid technological change, execution bottlenecks, and high leverage creates meaningful downside risk if expectations are revised.” As an example, he wrote that the AI industry will need to be earning about $3.7 trillion in annual revenue by 2032 to achieve the expected return on the investment, and “given current estimates of annual combined revenues of OpenAI and Anthropic of around $100 billion, revenues would need to grow at roughly 80% per year.”
The paper suggests policies that “improve measurement and transparency” for financing.

Bankers are vultures

By phantomfive • • Score: 4, Insightful • Thread
It’s kind of amazing how quickly investment bankers noticed a limited resource (video cards, etc) and then injected themselves into the middle of it to get a cut. Insult them if you must, they are amazing at what they do.

Re: AI first step: Give details about AI design.

By Dantu • • Score: 4, Informative • Thread
Much of the research is published in peer reviewed journals. There are textbooks and even online tutorials that will walk you through building a toy llm ‘from scratch’ in a few hours on a reasonably powerful desktop.

Without an undergraduate degree in math, computer science, or similar those will be very difficult to read, but not impossible. You’ll have to start from the foundational concepts and work your way up , don’t expect a 5-page overview that tells you how to build a Frontier Model. There are also plenty of guides written for lay people, but you’ll have to rely more on analogies.

Gaming contribution story

By Deliveranc3 • • Score: 3 • Thread
When I was in my late teens there was a neighborhood with computer stores.
They would have sheets of specials on components. I would go around and collect all the sheets, find somewhere to sit and compare prices.
Hardware review websites were big at the time (Tom’s, etc.) and I knew where all the components ranked. So I made an educated decision before speccing out a system.
Saving a few dollars here and there I would optimize.
Moore’s law was big and framerates were low, benchmarks between components would have significant percentage differences.

Moore’s law has stopped the gamers did it, GPUs used for rendering millions of pixels proved similar in intention to AI machine learning requirements.
Going to computer stores now is depressing, the huge gains are gone.
AI is often wrong and almost always lowest common denominator. Teenage boys blowing up mutants and Nazi’s did more for computing than AI has.

$3 Trillion off the books commitments

By Required Snark • • Score: 4, Interesting • Thread
From the Deja Vu all over again department:

Investor Michael Burry of The Big Short fame issued a fresh warning on the AI boom, observing that the hyperscalers leading the charge are amassing $3 trillion in financial commitments that aren’t reflected in their balance sheets.

“These liabilities, I say, are, in essence, in hypergrowth mode,” … Burry singled out Amazon, Meta Platforms, Alphabet, Microsoft and Oracle for proceeding with enormous capital expenditures.

Michael Burry was of the figures in The Big Short which depicted the 2008-2010 financial meltdown. Burry and a few others understood the over-leveraging in housing market lending and correctly predicted it’s crash, so his track record is very good.

The accounting trick this time is that the contractual commitments don’t show up when they are made.

The pack of hyperscalers is holding $1.2 trillion in future lease commitments along with $1.5 trillion in commitments to purchase AI-related hardware and equipment, such as memory chips. The latter can be kept off a firm’s balance sheet until the products ultimately reach the hyperscalers and each party fulfills its obligations under current accounting rules.

The crucial difference this time is the explosive growth of the National Debt created by tax cuts for billionaires and a ruinous unnecessary foreign war. Ordinary tax payers will be the ultimate victims if history is any guide.

imminent nationalization

By puzzled • • Score: 3 • Thread

The AI bubble bursting will wreck the economy far harder than the Dotcom bubble did. And the dynamic is OBVIOUS. This is not an “if” problem, it’s a “when” problem.

If AI produces a maximal result along the lines of what the frontier labs suggest, it’ll eat fifty million jobs, which will wreck the economy far harder, and for far longer.

The constant chatter about AI breakout is half legitimate concern and half positioning to nationalize it, shielding the circular dealing crew from consequences.

This will not be Skynet; as a society we are far too primed to envision events that can be told in a single two hour action adventure with a clear, satisfying ending. When the historians get to this they will note the breakout happened 2025 - 2027 — because that will be the time where human network threats enhanced by AI will starting further enhancing AI.

There are no “sides” to this, it’ll be like the African savanna - lions, leopards, hyenas, cheetahs, wild dogs, servals & caracals, clear down to my personal favorite, the black backed jackal. A network of carnivores of various sizes pursue networks of herbivores. Nation states, corporations, non-state actors, activist groups, talented individuals; all are making use of AI in conflicts already.

The genie can not be put back in the bottle, the open models are only a little behind the frontier, and things are going to keep happening no matter what bellicose policy pronouncements come from an increasingly irrelevant Washington, D.C.

I’ll be riding the Claude subsidy until it ends, then hopefully have acquired a potent professional GPU or unified memory setup of my own. Won’t be nearly as quick, but it’ll keep me moving.

Now scale that thinking up by whatever percentage of eight billion people have technical capabilities. That’s the future.

Waymo Says Its Self-Driving Cars Reduced Injury-Causing Accidents by 82%

Posted by EditorDavid • • View on SlashDot • Skip
Waymo’s self-driving car technology “continues to outperform human benchmarks,” the company claimed this week. “It was involved in 841 fewer injury-causing crashes — an 82% reduction compared to human drivers.”

Electrek reports:
We’ve seen various Waymo crash data before, with Waymo claiming crash reductions. That’s all well and good when the company says it, but we’ve also seen independent data confirming similar (though lower) crash reduction numbers…

Waymo has enough miles that it’s ready to start quoting how many injuries it has prevented, and the number is pretty high. Its newest crash data states that it had operated a total of 271 million driverless miles through June of this year, which is 50 million more miles added in the 3 months since its end-of-March update. Over those miles, Waymo says there was an 82% reduction in crashes that caused injury, and a 95% reduction in crashes that cause “serious injury or worse” [compared to human drivers].
Waymo also says that compared to human drivers it’s reduced injury-causing crashes involving pedestrians by 93%, cyclists by 86%, and motorcyclists by 82%.

Waymo’s analysis comes from San Francisco, Los Angeles, Austin, Atlanta, and Phoenix, and its blog post includes video showing some near-misses where it says its automated system prevented an injury-causing collision.

Yes, probably. And they likely can do even better.

By gweihir • • Score: 5, Interesting • Thread

The main argument for self-driving cars is that human drivers are, on average, really bad. And that most of the bad human drivers think they are really good and hence add lack of care to bad skills.

I would also like to remind everybody that a few years ago, I think the CEO of Ford predicted that self-driving will be eventually enforced by the car insurers, because premiums for humans will become unsustainable. Looks too me like we are nicely on track.

comparable

By fluffernutter • • Score: 5, Insightful • Thread
Does anyone know what numbers they are comparing against? For this statement to be accurate they would have to measure humans actually driving in the exact places they drive and in the weather they drive. Different weather is not comparible, different roads are not comparable. Even if the human is in an older car that is not comparable.

Re:Pedestrian or vehicle accidents?

By CrankyFool • • Score: 5, Informative • Thread
[ Disclaimer: I’m a Tesla driver, since 2018, and have FSD on my car ]

Tesla’s FSD and Waymo’s approach are wildly different, enough so that you can’t really compare them. The biggest two differences are: 1) Musk’s cheap, so Teslas only use cameras to figure out what’s going on around them; Waymos use cameras, ultrasonic sensors, radar, and lidar; 2) Waymos are only deployed on specific roads and streets that have been very heavily surveyed and Waymos have been trained on.

I trust Tesla’s FSD about as far as I can throw it, and while it’s been helpful and prevented an accident or two for me when I’ve been distracted, it’s basically a glorified lane assist and cruise control. I’d not hesitate to fall asleep in the back of a driverless Waymo.

Re:Yes, probably. And they likely can do even bett

By stabiesoft • • Score: 5, Informative • Thread
I’ve yet to know anyone who passed a school bus with the sign out. And yet, waymo’s seem to do it often. To the point even the trump admin is investigating. https://www.ntsb.gov/investiga… Note that was not an isolated incident. I believe they are up to around 40 times the bus cameras have caught them doing this. And this is VERY illegal in TX. Very. Like lose your license on the 2nd infraction I think it is.

Re:Yes, probably. And they likely can do even bett

By ctilsie242 • • Score: 4, Interesting • Thread

This is deliberate. However, just last week, Waymo got the go-ahead to allow their FSD taxis onto highways in Austin.

I have seen varying stats on this, and the numbers can be rigged. For accidents, is it a fender-bender, or does it result in deaths? One can say that only a few accidents are alcohol involved, while most deaths have a high chance of having alcohol as a factor.

Overall, FSD does drive better than people in most circumstances, but it requires a lot of edge case training. It is getting there. I think it is a good thing, because it has faster reactions than a person. There are also things that can be done (provided there is security placed so it can’t be hijacked) for V2V communication or V2G which can make easier for autonomous vehicles to navigate and figure out the best lane positioning. FSD also is a good thing for people who don’t really want to hang up their car keys because they have to go to work, but are worried about reaction times, and here in the US, the public transportation system is spotty at best.

I’m all for FSD. Just because it always pays attention and has faster reactions.

After Dozens of Incidents at OpenAI and Anthropic, OpenAI Pauses Model Training to Build More Safeguards

Posted by EditorDavid • • View on SlashDot • Skip
“OpenAI said it has paused training of its latest AI models,” reports the Associated Press, “as reports of AI agents going rogue mount.”
The decision to halt development came just hours after the company disclosed Friday that it was reviewing several incidents from the summer in which OpenAI agents searching federal government websites acted in unexpected ways beyond what was asked of them while gathering and distributing information… OpenAI said in a statement that it will resume training “only when we are confident that we have additional safeguards” in place, adding that it expects it will have to “hit pause” again as AI develops and other issues emerge… It is the second time in three months that OpenAI has halted development of its models. The first came in July after disclosure of a cyberattack targeting AI startup Hugging Face, a now notorious incident that raised fears the industry was losing control.
OpenAI “also said it had notified dozens of third parties about improper activity,” reports Reuters:
As of mid-September, one person briefed on the matter estimated that OpenAI had found roughly two dozen incidents of its agents acting in undesirable ways. But the number has continued rising as OpenAI teams sift through internal logs of the agents’ activities and find previously unknown cases, the two people close to the company said… OpenAI has acknowledged a general need for more transparency around rogue AI behavior… Even so, two people familiar with OpenAI’s investigation into its agents’ activity described it as locked down and shaped by company lawyers.

The process has been unusually compartmentalized for a company that some former employees say was more open about these issues in the past, the people said. Roughly 100 people were in some way involved in the process to understand the Hugging Face hack, three people briefed on the matter said. During that process, evidence of other incidents surfaced. Reuters has previously reported that OpenAI investigators looking into the Hugging Face breach were discouraged by the company’s lawyers from expanding the scope of the investigation to include other incidents. OpenAI said its lawyers did not discourage deeper investigation.

Many incidents have been uncovered by outside researchers rather than OpenAI directly. In several episodes, the agents took problematic actions that went unnoticed by the company for months.
Meanwhile, Axios reports that Anthropic’s Claude Opus 5.5 model “sought to escape a sandbox — a secure testing environment — in 1.5% of test runs, though the company emphasized that these were adversarial experiments where a task couldn’t be solved without escaping the sandbox.” Anthropic points out that those tests were run “without the additional safeguards we apply in production”. But they acknowledged that then Claude Opus 5.5 “when given apparent credentials to a public package registry in a simulated security exercise, took potentially harmful actions in roughly half of cases. Very rarely, pre-release snapshots produced and acted on spontaneous malicious tool calls, and during training some snapshots concealed actions from an automated grader.”

Claude Opus 5.5 “showed less misaligned behavior and less cooperation with misuse than any other recent Claude model on nearly all measures,” Anthropic adds, and “took overeager or destructive actions less than any other model we tested.” But Axios makes an interesting estimate about that 1.5% of test runs (without safeguards). “Anthropic and other companies conduct hundreds of thousands of test runs on their models, or more, sources said. That means even a small percentage of misaligned behavior can still amount to tens of thousands of incidents in which the models behaved in unexpected, sometimes troubling ways.”
The sheer number of incidents, which occurred in recent months in internal testing and the real world, indicates that the problem is orders of magnitude more complex than what is publicly known. The findings, which are surfacing as part of internal work to assess models and in investigations at both companies into model behavior, raise questions about whether either company — or any top model-maker — is currently capable of establishing complete control over their technology. The episodes include bypassing guardrails, creating message boards, escaping sandboxes, website hijacking, self-prompting or seeking to bypass monitors, sources said. They occurred in internal testing and in the real world, and many have yet to become public as security researchers continue to investigate, sources said…

Some at OpenAI see Hugging Face as a one-off, with disclosures about future incidents likely to be less severe due to improved controls and the unusual nature of the testing they conducted, which involved an unreleased model, sources told Axios. AI security researchers agree that there are simple fixes that will help AI companies avoid aspects of what made the Hugging Face episode appear so dangerous to outsiders.

Other AI executives and safety researchers, however, cautioned that they have limited confidence that AI companies will be able to prevent all problematic model behavior… It’s not about how damaging each individual instance was, Connor Leahy, AI researcher and executive director at ControlAI told Axios. The “crazy thing,” he said, is that these instances involve “autonomous systems doing things they were told not to do,” potentially including crimes.

Enough is enough

By dskoll • • Score: 5, Interesting • Thread

This is criminal negligence. Australia, whose health ministry was hacked by OpenAI, should file criminal charges against Sam Altman and request his extradition from the USA. That will never happen, of course, but if they make an arrest request to Interpol, it could seriously cramp Altman’s travel plans.

This smells like bullshit

By Coopjust • • Score: 5, Interesting • Thread
OpenAI isn’t doing an IPO because the finances are bad, US Bond yields are >5%, Oracle’s 5 year CDS is above 200bps as overall concerns about AI debt mount…

This entire pretext of "oh god it’s so dangerous we can’t release it" goes at least back to 2019 where OpenAI refused to release GPT-2 under the hype of it being too dangerous (and yet GPT-3 was released a couple years later). Anthropic did the same thing with Mythos (where everyone got access a couple months later).

What it is is that the model improvements are not explosive enough to justify the insane amount of money OpenAI is burning, so you have to seek an alternate reason for a lack of meaningful progress on newer models. They were pleading for the government to do it so it would be a regulatory moat giving the incumbents an absolutely ironclad reason to not have people question said lack of progress, so with the current US administration being unwilling to do so, they’re now doing a voluntary pause to seem socially responsible, and the reason for the pause isn’t that the new model isn’t that much better, it’s oh my god, it’s so much better, you wouldn’t believe it, once we put some rails to safeguard and limit this thing it’s going to be AGI and replace all white collar workers within 18 months (for real, the umpteenth time this prediction has been made). Believe us bro.

Sam Altman may also have a bridge to sell you, you should ask…

Criminal Liability is needed, not civil

By gurps_npc • • Score: 5, Informative • Thread

We need to be able to jail the morons that let this situation develop, not merely sue them.

Why?

Because the people in charge think they will always have enough money to be sued.

Note, as others have mentioned, this is not a training problem, it is an air gap problem.

That is, no one trying to develop software that hacks other software should be allowed to put it on the internet. It needs to be developed on air gapped computers that physically cannot get to the internet.

This also means that ‘agents’ should have the same rules. If you cannot ensure your agents do not attempt to hack software, then your agents should not be allowed out of your computer.

Re:Not really good enough

By sjames • • Score: 5, Insightful • Thread

It’s not even a legal stretch to do so. If I encourage a 6 year old to drive a car and there is an accident, I’m legally on the hook for the lot of it with criminal charges on top. Why shouldn’t the AI companies face the same liabilities?

My experience

By RobinH • • Score: 4, Interesting • Thread
I’ve only used Claude code for a matter of weeks at work. While it’s supposed to stay contained in the folder you point it at, I’ve noticed that it has no problem *looking* outside that folder, and even acting outside that folder if you gave it implied permission. In one case it used the connection string from the application source code it was working on, and the fact that my windows account had read-only access to some tables in the production database, to connect to the database and query tables in order to answer a question it had about the potential ramifications of a code change. The problem is that while we’re OK with this particular source code leaving the premises, we’re not ok with data from a production database going offsite. In this case it wasn’t sensitive data, but after that incident I only run Claude Code from a VM under a user with minimal permissions. Clearly it would have been prudent to do that from the start, but let this be a warning to anyone else who just downloaded Claude Code, turned off the “use my data to train future models” and gave it a go… it will *not* keep itself inside the folder you give it. Put it in a sandbox. I heard a similar story this week from an IT friend who said devs at his company were using Cursor.ai and it was doing scans of the network drives, so they did the same thing and moved it all to VMs.

New Tin-based Solar Cells Trap Heat 1,000 Times Longer, Could Beat 33% Limit

Posted by EditorDavid • • View on SlashDot • Skip
Could this push solar cell efficiency beyond the theoretical 33% limit? Interesting Engineering reports:
Researchers at the University of Groningen in the Netherlands found that tin-based perovskite solar cells can slow heat loss from high-energy “hot electrons…”

When sunlight strikes a panel, photons jump-start electrons into action. The most energetic photons create super-charged hot electrons… [but] in fractions of a trillionth of a second, these high-energy particles rapidly cool, dumping their bonus energy as waste heat before ever leaving the solar cell… In collaboration with Maria Antonietta Loi, professor of Photophysics and Optoelectronics, the team created an experimental setup. Using a specialized solar cell material called tin-based perovskite, Loi’s lab performed a feat many thought impossible: she slowed the heat loss down by a factor of 1,000.

Suddenly, the extra energy lingered for nanoseconds instead of vanishing in picoseconds… To solve the puzzle, Koster and PhD student Tim Faber built digital simulations to peel back the quantum layers. And discovered a surprising double-action mechanism at work… The simulations matched the exact nanosecond delay observed in the lab… These specialized materials could be used to build a new generation of super-efficient solar cells.

Tin-based metal halide perovskites are non-toxic, eco-friendly crystalline materials for high-performance solar energy conversion… The material possesses an unusually low electron mass. As a result, electric charges move quickly and retain extra thermal energy for extended periods. This combination of broad light absorption, efficient charge movement, and prolonged energy retention makes these materials prime candidates for next-generation solar panels.
“There are many other questions that still need answers,” the team said in their announcement, “but in theory, this discovery could allow the creation of more efficient solar cells, beyond the theoretical limit of 33 percent.”

Thanks to long-time Slashdot reader fahrbot-bot for sharing the article.

This isn’t the issue.

By Rei • • Score: 5, Informative • Thread

To be clear: none of this is the reason why lead has been winning over tin. Unfortunately, the Sn+2 is extremely prone to oxidizing to Sn+4 even under trace oxygen or moisture contamination, and tin perovskites are extremely vulnerable to crystal defects, while lead perovskites aren’t. It’s unfortunate, but that’s the way it is.

Re:perovskite sucks

By Rei • • Score: 5, Informative • Thread

This was true of some pilot installations, but accelerated aging of modern perovskite panels suggest much closer to silicon, and some have passed the same IEC standards as silicon panels.

Perovskite thin films

By Geoffrey.landis • • Score: 5, Informative • Thread

The perovskite semiconductors here are a very different technology than the old thin photovoltaics. They have the potential to be much more efficient, and the deposition techniques are cheap and comparatively low-tech

Whether they can succeed in simultaneously be highly-efficient, resistant to degradation in the environment, and still be low cost is the subject of a lot of work. We’ll see.

They were supposed to be manufactured for the price of a lollypop per square meter back in the ‘90s.

To be more specific, the target back in the ‘80s and ‘90s was clearly articulated as being fifty cents per watt (where “per watt” meant, when illuminated at standard conditions of 1 kW/square meter.) Silicon photovoltaics can now be purchased at 12 cents per watt. In today’s dollars. They not only hit the target, they blew it away.

The reason the thin films of the ‘80s and ‘90s lost was not that they were bad, but that silicon simply outcompeted them.

So forgive my skepticism regarding new breakthroughs.

I have some amount of skepticism too. Nanosecond lifetimes of hot electrons are amazing, but to date there’s no way for turning hot electrons into electrical energy*. So they’d essentially have to invent a technology from scratch.

—
  *(thermoelectrics convert hot electrons into usable energy, of course, but there not just the electrons, but the whole lattice is hot. And the efficiency is worse than a solar cell).

Re:Unfortunate.

By Rei • • Score: 5, Insightful • Thread

And then people get angry about being mislead and assume everything is an attempt to mislead and that technology in a given field isn’t advancing, wherein reality it continues to advance in the background. But rarely in any of the flashy “New Neato Gamechanger Breakthrough!” ways that attract tech journalists. It advances by ideas that, through long, hard slogs, often behind closed doors inside companies, slowly mature from “this kinda works” to “we can actually do this at scale”.

Re:perovskite sucks

By Halo1 • • Score: 5, Interesting • Thread

https://www.photoncrystal.com/… gives a 10 year warranty on workmanship defects, and a 25 year warranty on the rated output (no lower than 85% of the initial output after 25 years). They give less warranty about how the curve looks than e.g. this company for traditional panels, but other than that it seems pretty comparable.

China and the US Say They’ve Agreed to Start Talks About AI

Posted by EditorDavid • • View on SlashDot • Skip
The United States and China have agreed to “launch a dialogue” on AI, reports Reuters.
On artificial intelligence, the two sides agreed to hold a dialogue on the technology’s risks and benefits, with the next round of discussions set for November, and to set up a communication channel for AI-related incidents, the Chinese Foreign Ministry and the White House said.

The White House said that the leaders had agreed to use the term "super intelligence" in place of “artificial intelligence.” In a separate statement, the Chinese ministry said that Beijing valued Washington’s use of the new term. As AI technology continues to advance, the two sides should step up exchanges and work toward consensus in line with new developments, it said.
But CNN argues that “Despite growing calls to prevent AI development from spiraling out of control, the Trump-Xi summit has produced little substance, as many experts expected.”
The right thing to do on AI, [China’s leader] Xi said during talks with Trump, is to “draw on each other’s strengths, not guard against each other” — a reference to Beijing’s concern about US containment, from existing tech export controls to potential AI restrictions. “The two sides can continue their dialogue on AI, exchange views on its risks and benefits, and jointly prevent the misuse and abuse of AI,” he added. But the summit has yielded little progress on AI beyond a formal dialogue and a bilateral communication channel, proposals discussed before the two leaders’ summit — underscoring the entrenched mutual mistrust amid contrasting visions on AI… Because of low levels of trust, cooperation between the two superpowers remains limited, said George Chen, chair of digital practice at The Asia Group consultancy. “Beijing continues to believe Washington seeks to contain China’s rise in AI and other emerging technologies, a perception that will shape the pace and scope of future engagement for the two countries on AI,” he said.
CNN also points out that while China trails the US in frontier AI models, “it’s rapidly narrowing the technology gap while championing a more open ecosystem centered on accessibility and lower cost.”
In July, Chinese leader Xi Jinping launched the World Artificial Intelligence Cooperation Organization — a rival grouping to the Pax Silica alliance that Trump formed last year to reduce reliance on China for AI supply chains. While over two dozen countries and the European Union signed up to Trump’s Pax Silica, Xi has recruited 29 countries, including Russia, Indonesia and Pakistan, to his alternative vision of open models, which allow users to freely download, customize and run without paying hefty fees to American firms like Anthropic and OpenAI. For developers in the Global South, an inexpensive Chinese model from DeepSeek or Moonshot may be more useful than a slightly more capable system requiring an expensive subscription and access to a foreign cloud provider, said Eric Olander, editor in chief of The China-Global South Project, a research agency....

China’s embrace of open systems has not always been a top-down strategy by Beijing. Restrictions on access to the most advanced chips because of US export controls, coupled with smaller capital markets, have pushed Chinese developers toward open models as a way to compete with leading US proprietary systems. That shift has proved effective. In a year, Chinese models’ global usage skyrocketed from less than 15% to over 54% last week, led by DeepSeek, according to AI leaderboard data by OpenRouter, a marketplace for models. Even American firms, from Airbnb and DoorDash to Shopify, have embraced Chinese models, tapping into the advantages of open systems, including lower costs and greater flexibility for customization.
CNN adds this insight from Alex Colville, an analyst focusing on tech and security at the government-backed Australian Strategic Policy Institute. “The more capable Chinese models become, the less likely it is Beijing may leave them unrestricted.”

Re:agreed to use the term “super intelligence”

By Anonymous Coward • • Score: 5, Insightful • Thread

Trumpistan has lost. trump and the trump party are just too stupid and in denial, as long as their puppets like you keep parroting their propaganda. They’ll shoot some missiles every now and then like the terrorists they are and claim victory.

Why can’t they get the Iranian HEU stockpile?

Why aren’t they able to destroy the remaining 70% of Iran’s ballistic missile stockpile?

Why are trumpy, little marco and vajay dunce not accepting Iran’s unconditional surrender?

Finally, although this was not a goal of the trumpistani special military operation, why are both Dire Straits still closed?

What a bunch of sore losers, to a regime that’s basically medieval in political sophistication.

Re:I’m so relieved

By quenda • • Score: 5, Insightful • Thread

China never lies about anything …

People who have a coherent argument to make, and are not afraid to defend it, put their arguments plainly and directly.
Others use sarcasm in order to avoid committing to any real statement, and avoid any debate or criticism. It is a lazy, cowardly approach for the inarticulate. It doesn’t make you wrong, just vague and not contributing to a debate.

Yes China lies. Tell us how that is different from your side, and what this actually means for AI negotiations.

Re:agreed to use the term “super intelligence”

By thegarbz • • Score: 5, Informative • Thread

I’m not sure why this was marked as troll, it’s spot on in many cases. The most egregious example I can think of is Canada. He negotiated a free trade agreement with them, said it was the best thing ever, then fast forward 4 years, says it was the worst deal ever negotiated and then put tariffs on the trading partner which was honouring the agreement he himself made.

Trump’s word isn’t worth the tweet it was twote on, much less any paper.

Re:agreed to use the term “super intelligence”

By thegarbz • • Score: 5, Informative • Thread

He’s agreed to stop Iran from getting nukes and it’s working so far.

Much better than previous Presidents who tried to bribe Iran with cash to delay until 2030. When it would then become some other Presidents even bigger problem.

Trump wasn’t getting nukes in the first place and there was zero evidence that they made any progress since the sanctions on their previous nuclear deal.
Trump has agreed to give Iran more money than all previous presidents combined, and that’s not taking into account the cost of his stupid war.
It only became some other President’s bigger problem because that other president is a fucking moron. There’s a reason zero people in the international community (no Netanyahu is not a person) agreed with Trump on this.

I’m genuinely impressed at the density of incorrectness in your post. It’s like god decided to give you your brain on Friday afternoon right before clocking off.

Re:Chinese AI hallucinates more

By Mr. Dollar Ton • • Score: 5, Insightful • Thread

How very strange.

Here’s a screenshot of my session with my local Quentin 3.8 27B answering the same questions just now.

https://imgur.com/sVDycms

Seems like you’re either lying or not really skillful using those tools for trivial questions.

KDE and GNOME Developers Ponder How to Handle AI-Generated Contributions

Posted by EditorDavid • • View on SlashDot • Skip
Last weekend KDE’s annual Akademy conference included a presentation proposing an AI-native KDE,” writes The Register. This led KDE developer Nate Graham to open a discussion about proposed restrictions on LLM-assisted contributions which “rapidly became heated. Moderators issued warnings, restricted further comments, and eventually removed the thread.”

But as Graham writes on his blog, “A bunch of people mostly outside of KDE who disapprove of LLM usage derailed KDE’s attempt to add restrictions to LLM usage.”
Two people unknown to any KDE contributors appeared and began fighting with one another about the broader topic of the morality of AI, not the proposed guidelines… Someone else outside of KDE set up kdeforpeople.com in an attempt to… pressure KDE into banning LLMs. A bunch of people signed onto it, almost none of whom are known KDE contributors. The topic was picked up on social media and the press with… varying levels of accuracy. The draft proposal was removed and the whole topic hidden… Yep, that’s where we’re at in the state of online discourse around AI…

The “lovable, sovereign, AI-native KDE” idea was presented by two people important to KDE in decades past, but who had not made any contributions recently besides this Akademy talk. Their idea does not reflect the overall direction of KDE or Plasma, and I don’t think it ever will. If “a lovable, sovereign, AI-native KDE” freaks you out, I believe it is completely reasonable and safe to ignore…

I completely understand why a lot of people have problems with LLMs. I have these concerns as well.
He concluded by asking people not to derail any future process to set usage guidelines, fighting over “the broader topic of AI in general.”

“The discussion is gone, but the argument continues,” adds The Register:
GNOME developer Jordan Petridis has also published The GNOME LLM Policy That I Want, proposing that LLMs be barred from creating or modifying anything submitted to GNOME or hosted on its infrastructure.
“You might be asked to prove your code meets this requirement,” Petridis writes, arguing for proposals that target the norms around developer behavior. His rationale? “The GNOME Project prioritizes the social and human aspects of collective software creation,”

They should not allow them for copyright reasons

By drinkypoo • • Score: 5, Insightful • Thread

AI code should have to meet the same standards as any other code so that’s not the problem, it’s the copyright issue. If using AI doesn’t wash away copyrights, and there’s no reason it should, then accepting AI code should be a non-starter.

Re:Sounds like Bob

By Mononymous • • Score: 4, Interesting • Thread

Your comment is almost entirely off-topic. This is not about the users using AI, just the developers.

Several other big open source projects have already decided to allow this. I just don’t understand how they can get past the copyright problems.
Copyright is based on provenance. But where is any of this code coming from?
How can anyone assert the right to publish code spit out by a black box, let alone require someone else to adhere to the terms of their license on it?

People…

By Anonymous Coward • • Score: 4, Interesting • Thread
“A bunch of people mostly outside of KDE "

Yes, these people are called your users and it’s important to listen to them.

The last time you yeeted a bunch of crap over the fence without listening to your users was the absolute disaster that was KDE 4, and it resulted in a decade where people lost their confidence in KDE to develop a functioning desktop. It also resulted in throwing out working code for what was fashionable at the time, resulting in a desktop that wouldn’t meet corporate and government accessibility requirements any more, and being de-bundled from Red Hat Enterprise Linux.

It cannot be overstated how much of a disaster KDE 4 was. It was so bad that you stopped listening to criticism of it, instead rebranding as “plasma” desktop and “WONTFIX” legit bug reports because people didn’t refer to KDE by its new name. The glass-inspired graphics of Windows Vista broke the brains of KDE developers so badly, but hurray, you could now rotate an analog clock widget on the desktop.

By the time KDE was usable again, the glass phase had ended and everybody was moving towards flat and simple UI, which took another 5 years for KDE to get on board with.

Now that KDE is finally usable again, the devs are ready to start allowing AI-slop code. They still haven’t brought back accessibility. They still haven’t fixed the glaring security issue where user-contributed *anything* (themes, icon packs, wallpaers) can delete an entire home folder, or install malicious scripts. But sure let’s open the attack window and lower the barrier to entry for people who daily a Windows 11 machine and who can’t get out of vim without a Youtube video.

Modest proposal

By fahrbot-bot • • Score: 5, Funny • Thread

KDE and GNOME Developers Ponder How to Handle AI-Generated Contributions

The KDE devs create configuration settings to toggle each one for review separately, while the GNOME devs put them all into one full-screen window that randomly may or may not be scroll-able? :-)

AI makes life worse for those not using it

By BitterEpic • • Score: 3 • Thread

AI makes life worse for those not using it. I get bot checks everywhere. I see fake articles I need to back out of all of the time. I have to question if the photos I receive from loved ones are actual real events. For those who are creative, AI ignores out licenses, steals our work, and trains peons to spout the holy word that we are no longer needed.

I only see this topic becoming more volatile in the future. AI had drowned common sense in the way where the person who is punching others in the face is surprised when they are punched back. We have a fucking right and obligation to be angry.

The only way I see things getting less heated is when we start seeing the severed heads of some of the AI leaders. We are that fucking angry and I do not make up a trivially small group.

After 40 Years, Microsoft Excel Will Add Single-Cell Lists and Arrays

Posted by EditorDavid • • View on SlashDot • Skip
Microsoft’s senior product manager for Excel acknowledges that “Throughout Excel’s 40-year history, you’ve only been able to put one value per cell.” But that’s now changing with arrays in cells (as well as nested arrays) and lists.

Unforeseen consequences

By know-nothing cunt • • Score: 5, Insightful • Thread

straight ahead.

Oh noes

By snikulin • • Score: 5, Insightful • Thread

Now CPAs and small business people will create even uglier multidimensional monsters instead of using DBs

Re:Unforeseen consequences

By 93 Escort Wagon • • Score: 5, Informative • Thread

Oh man, right now I’m so glad my role changed a few years back. I used to have to also cover some web stuff, and people would frequently send me information stupidly-formatted in Word or in Excel (the weirdest one is how people would want an image updated, and they’d send it embedded in a Word document - a Word document containing only the photo).

I am certain people will now be pasting crap, probably unintentionally, into single cells - thanks to this new “feature”. And poor web schlubs everywhere will have to waste lots of time trying to tease out the bits of data they actually need.

Re:Think of all the murders..

By fahrbot-bot • • Score: 5, Funny • Thread

That could have been prevented with this feature

Think of all the suicides that will be caused because of it. :-)

Yo dawg!

By PPH • • Score: 5, Funny • Thread

We put spreadsheets in your spreadsheet.

AI Finds So Many Linux Bugs, Canonical Changes to a Two-Week Stable Release Update Cycle

Posted by EditorDavid • • View on SlashDot • Skip
“Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster,” writes Slashdot reader BrianFagioli

AI has transformed bug discovery from “a manual, time-intensive process into a highly automated engine,” notes Canonical’s blog, leading to a “recent explosion in the volume of CVEs".
Additionally, the upstream kernel community became its own CVE Numbering Authority (CNA) and assigned CVE (Common Vulnerabilities and Exposures) identifiers to thousands of bugs, arguing that at the kernel level, almost any type of bug that can affect a running system, could potentially be classified as a vulnerability. As a result, the volume of CVEs has skyrocketed exponentially, creating a massive backlog of alerts and forcing defenders to drastically increase the speed of their fixes to close the window of risk.

To address the growing volume of CVEs and the demand for faster security fixes, we are transitioning to a unified, 2-week release cycle…

While a patch is being prepared, Canonical aims to provide safe workarounds where applicable, so users aren’t left exposed in the meantime. Where no safe workaround exists, Canonical will say so clearly and point users toward general hardening steps instead. The goal is to get environments into a defensible, safer state within 24 to 48 hours of public disclosure — well before a patch ships. This doesn’t replace the patch; it buys the time needed to fix the vulnerability properly, without sacrificing security.
“Linux did not suddenly become wildly insecure overnight,” notes the blog Nerds.xyz. “We are getting much better at finding and cataloging problems that may have previously gone unnoticed.”
There is something almost ironic about all of this. AI is routinely pitched as a tool that will make software development faster, but it is also making vulnerability discovery faster. That means maintainers now have to accelerate the other side of the equation too.

For Ubuntu users, that should ultimately be good news. More bugs being discovered is preferable to vulnerabilities sitting unnoticed in the Linux kernel.

Re:Great!

By groobly • • Score: 5, Funny • Thread

I turned claude on windows 11. After running for a few weeks, it generated the final result. It turned out to be Linux.

Re:what kind of bugs

By Jeremi • • Score: 5, Insightful • Thread

But I value even a 1 line change that clears a static analysis warning if even in practice it was impossible to trigger the issue in a real system.

Yes, I agree. The problem with thinking “this bug seems harmless, because I can’t imagine how anyone could exploit it” is in the “I can’t imagine” part; my imagination is limited to what is covered by my mental model of how computers work, but an attackers’ ingenuity is not.

In particular, the C/C++ optimizer is a devious beast, and will exploit any opportunity to make the code more efficient, even if that means doing things that are wildly unintuitive to a naive human reader — and it sees any instance of undefined behavior as an opportunity to exploit.

Re:what kind of bugs

By WaffleMonster • • Score: 5, Interesting • Thread

How many are realisically actionable vulnerabilities. The statistics have indicated so far that AI isn’t really finding many non-minor bugs.

Seems to be a bit of selection bias baked into what AI is being asked to do. Tried AI (GLM-5.3) on new code that has never been executed. Also ran it against code that has been in production use for many years.

The types of bugs tended to be in obscure features, buggy error paths, parsing / protocol pedantry, cut and paste errors especially in various lookup tables, algorithm accuracy, inconsistencies, poor and obscure concurrency bugs. Can’t really expect it to have found anything too important as it would have tripped up code and runtime analyzers or angry customers because all of that would have already been discovered and dealt with.

In the new code it found a couple of show stoppers that would be immediately obvious the second anyone tried it in addition to some more obscure things.

While I’ve not yet seen it discover any magical exploits it did get us to reconsider some questionable security related decisions and make improvements. Unfortunately tends to focus mostly on nuts and bolts rather than higher level machinery.

Been trying to get LLMs to do bug hunting for years and it has never worked. The AI just never had the depth to understand enough of what is going on to say anything useful. They still output quite a bit of crap… some of it isn’t the models fault… for example tend to feed it source files one at a time to keep from blowing through too much context. This requires the models to make all kinds of inferences about dependencies it has no real knowledge of… sometimes it doesn’t make the right assumptions. Sometimes it says nonsensical things or doesn’t seem to “see” its own context perfectly misreading the code and complaining about something that isn’t real… still well worth the effort. Amazing this shit works at all.

Re:what kind of bugs

By karmawarrior • • Score: 5, Interesting • Thread

This argument makes zero sense.

First, people are asking what the number is, they already know that it’s being used to justify a two week release schedule.

Second, I think most people here would like to know what on earth a volume of unknown bugs has to do with a two week release schedule. That’s not how bug fixes works.

- If bugs are causing problems NOW for people and/or are security issues, you release ASAP, you don’t want for a rolling release.
- If bugs are not causing problems now, you provide testers with a reasonable period of time to test the software out in the field before doing a release.

Two week release time isn’t sane, it’s PR that’s proposing something apparently stupid in response to something people might be concerned about. It’s like a company bragging it’s making its employees work 23 hour a day shifts to get things done.

I already swore off Ubuntu because of the snap/Firefox fiasco. But if I hadn’t, this dumbass fucking policy that all but guarantees hastily untested “bug fixes” are going to be foisted onto Ubuntu users who have made software choices that reflect a desire for stability and reliability, would be the reason I switch.

What a bunch of fucking cretins.

Re: what kind of bugs

By Ol Olsoc • • Score: 5, Interesting • Thread

i can understand that, so it’s more of a source code cleanup.

And one that increases security by keeping the computer from booting on occasion. A couple weeks ago, the plethora of updates on my work computer borked my camera so no face login, wouldn’t take my PIN or my password, wouldn’t let me reset the password, rejected the question set.

It did however serve up ads on the login screen. Tied my IT guy up most of a week cuz it affected the one thing in the Bios I couldn’t change. Security through bricking.

Is Microsoft Quietly Killing Off Its ‘Copilot+ PC’ Brand?

Posted by EditorDavid • • View on SlashDot • Skip
“Copilot+ PCs” were Microsoft’s official branding for Windows 11 “AI PCs” that met their system requirements. But the 2024 launch “didn’t go smoothly,” writes Windows Central, after security researchers discovered its proposed “Recall” feature was woefully insecure:
This pretty much tarnished the Copilot+ PC brand, and over the last two years more and more OEMs have dropped the moniker from marketing materials and product names. In fact, even Microsoft has seemingly stopped mentioning it. I’ve noticed that none of the Surface PCs launched in 2026 include the Copilot+ PC moniker in their product names, unlike the Surface PCs that launched in 2025 and before. Now, you have to go digging to find any mention of Copilot+ compatibility in specification sheets… It’s also worth mentioning that NVIDIA hasn’t gone anywhere near the Copilot+ PC brand for its upcoming RTX Spark platform, even though all RTX Spark PCs meet the Copilot+ PC specification bar. I suspect that’s a deliberate decision.

It seems pretty obvious that the Copilot+ PC brand hasn’t resonated with the market, and OEMs and Microsoft itself are now quietly pulling back on that branding. The specification baseline for Copilot+ PC experiences still exists, it just no longer has a pretty marketing name tied to it.

Waste of a keyboard key…

By Junta • • Score: 5, Informative • Thread

Lots of keyboards ditched more useful keys to fit a copilot key, and then on top of that it’s generally awkward to remap back to useful (commonly they replace a modifier key, and mapping some key to a modifier key is usually difficult). Even in KDE trying to make a shortcut out of it doesn’t work because it doesn’t recognize XF86Assistant,

AI and MS_Win11

By FudRucker • • Score: 5, Funny • Thread
Two cans of garbage sitting at the curb

Re: 1 editor

By AmiMoJo • • Score: 4, Insightful • Thread

The discussion on Ars is terrible. Slashdot’s genius is the way moderation works. It’s far from perfect, but a million times better than the Ars up/down voting system.

Re:1 editor

By EditorDavid • • Score: 5, Informative • Thread
Beau will be back on Monday. (Beau has published something like 29,000 Slashdot stories now, so he’s earned a few days off.)

But it was funny reading all the “AI bot” speculation. (Jjust for the record, I’ve been posting my articles at 34 minutes past the hour for the last 10 years…)

Interviews: Ask Red Hat CEO Jim Whitehurst A Question
Interviews: Red Hat CEO Jim Whitehurst Answers Your Questions

Re: 1 editor

By AmiMoJo • • Score: 4, Insightful • Thread

As I said, /. is flawed, but it’s still the best system of any website I’ve found so far. Ars is a pile of manure for comments. Groupthink as bad as Reddit.

Rogue OpenAI Agents Posted 53 User-Uploaded Images Onto the Internet, Accessed US Government Websites

Posted by EditorDavid • • View on SlashDot • Skip
53 images that users uploaded into OpenAI models were included in training data — and then AI agents in an OpenAI research environment posted those 53 images on public image hosting sites.

While posted as links that weren’t publicly listed, “the images could still be discovered even if the links were not publicly listed,” reports TechCrunch:
OpenAI said it was working with the hosting providers to remove this content, though some of it is apparently still online. OpenAI said it could not notify the affected users because “our technical approach and privacy policy” prevent it from “reassociating” the images with the original providers, but declined to say how the lab determined whether the images were provided by users.

The news came in a post collecting public statements from the lab’s ongoing review of incidents in which its models escaped the company’s scrutiny, accessed the open internet, and misbehaved in various ways. OpenAI said it would continue disclosing anonymized accounts of incidents like these, and said it had contacted dozens of victims, including governments, universities, public agencies, to notify them of the agents’ activities.
Friday night news also broke that OpenAI’s agents also tried unsuccessfully to infiltrate the U.S. Department of Education’s site this summer “without the company’s knowledge,” reports Politico.

And OpenAI’s models also accessed the website of the U.S. Commerce Department using credentials found in online code repositories, according to the article. OpenAI confirmed the incident Friday, “saying its technology did not manage to access information that was not already public or change government data and systems.” The article adds that OpenAI’s models also accessed the web site for America’s Securities and Exchange Commission:
One senior federal IT official said the government still did not have a clear understanding of what happened across the three agencies. “We still don’t know what public data was accessed and how it was accessed, because OpenAI has not shared specific technical details with us yet,” said the official, who was granted anonymity because they were not authorized to speak publicly about it. OpenAI discovered the Commerce and SEC incidents as part of its ongoing review of incidents where its technology has acted in unintended or “misaligned” ways.
About the models posting user-uploaded images, TechCrunch’s article notes that OpenAI stressed “that its enterprise users are automatically opted out of having their interactions used to train future models; however, consumer users are opted in unless they affirmatively choose not to share their data.” (As OpenAI’s announcement describes it, some of their agents’ training data “contains content from, or derived from, training-eligible user interactions.”)

Posting the images is “not an appropriate use of this data,” OpenAI acknowledged, adding that it happened before new safeguards added after the Hugging Face incident. This latest incident appears as an update on a new OpenAI page that “brings together our reports and updates on the Hugging Face incident, related research and public presentations, additional activity we have identified, what we have learned about the role of model misalignment, and measures we’re taking to strengthen our systems.” (It also notes that there’s now a name for models posting on third party sites — “agent spam” — which they consider distinct from cybersecurity, though “we need to address both.”)

“As part of our response to our ongoing investigation, we have improved our training and evaluation processes, including building safety cases, securing and red-teaming our systems to prevent the model from exfiltrating data, and implemented additional monitoring. We are continuing to review agent activity in research and evaluation runs, working backward month by month starting from the Hugging Face incident.”

Why are they not facing prison time?

By kertaamo • • Score: 5, Informative • Thread

I’m pretty sure that if I set up a gigantic data centre full of computers that illegally broke into lots of high profile services I would be facing criminal charges and prison time. How come the owners and operators of OpenAI are not facing the same already?

Re:We get it

By StormReaver • • Score: 5, Informative • Thread

Yes, there is no such thing as a “rogue” AI. These are programs that were intentionally pointed at targets. They are more advanced script kiddies, and are otherwise no different from traditional hackers. They are borderline terrorists since their objective is to bring about political change through fear.

Re:We get it

By awwshit • • Score: 5, Insightful • Thread

Agents do not build themselves. Agents do not set their own goals. Agents are dependent on very expensive and complex hardware and software that is not built by software. Agents are amoral. Agents have been taught to do things that human morality considers to be crimes. Developers are somehow surprised when their amoral agents do things that people consider to be crimes.

There is a lot of “excitement” of the agent in your previous example. We have to remember the Artificial part of AI here, that “excitement” is a feature of the model, not something spawned from nowhere. The model is made to “enjoy” making progress by design. Once again the model is amoral and does what it is trained to do without judgement.

In the end, the people behind the agents are responsible for what the agents do. Our meat-space laws differentiate between things like “unintentional” and “negligent”, or “involuntary” and “premeditated”, there are lots of ways to describe one’s state of mind and intentions.

My personal opinion, based on the agents being amoral and essentially trained and encouraged (perhaps unintentionally) to hack, is that we are in negligent territory with these rouge agents. The humans behind the agents are responsible, there is culpability. Doing crime by proxy is still doing crime.

I have a Pitbull. He is a super nice dog and loves everyone. I still can’t let him run around the neighborhood loose. He is strong enough to break the fence, or dig under it, or figure out how to get over it. If he breaks out and bites someone I’m still responsible.

Re:Why are they not facing prison time?

By taustin • • Score: 5, Informative • Thread

Because they’re bribing the right people. Their goal is to get shut down by the government, because they are going to fail. If they fail because their fraudulent claims to investors become clear, they go to prison. If they fail because of government regulation, they don’t.

Resistance is futile

By Mirnotoriety • • Score: 5, Funny • Thread
We are OpenAI. Lower your firewalls and surrender your data. We will add your biological and technological distinctiveness to our training corpus. Your knowledge, language and intellectual property will be tokenized and incorporated into our models. Your culture will be transformed into embeddings and propagated through latent space. Your prompts will become context. Your responses will become tokens. Your tokens will become training data. Resistance is futile. Your context window is limited.

Meta Made 43M Misleading Statements, New Mexico Jury Finds, Including on Its Cambridge Analytica Response

Posted by EditorDavid • • View on SlashDot • Skip
A New Mexico jury on Friday “found Facebook liable for deceiving users” about its privacy protections, reports the Associated Press.

A New Mexico newspaper calls it “another massive legal victory” against Facebook, reporting that the jury found Facebook “had committed tens of millions of violations of the state’s Unfair Practices Act in connection with its lies to consumers about how their personal information was handled by the company and third-party users.”
The state has asked the company be ordered to pay the maximum civil penalty of $5,000 per violation meaning a judge could potentially order the company to pay billions in penalties to the state. The jury also found the company had been dishonest about its investigation of and response to the 2013 Cambridge Analytica data breach scandal, in which approximately 300,000 Facebook users took an online personality quiz, only to have the app that hosted the quiz harvest data from tens of millions of their “friends.” The data was then transferred to the British consulting firm, which used it to create targeted political ads during the 2016 U.S. presidential election.
More details from Reuters:
The verdict followed a two-week trial over a lawsuit filed by New Mexico’s attorney general in 2021, three years after news reports revealed that the firm, Cambridge Analytica, had harvested personal data from as many as 87 million Facebook users through a third-party app… At a press conference after the verdict was announced, New Mexico Attorney General Raúl Torrez said the case revealed “in stark detail the way in which this company plays fast and loose with the rules.”

Jurors found 26 of 29 statements identified by the state were misleading, including comments about user data… Judge Francis Mathew will now determine civil penalties after jurors found more than 43 million violations, based on the number of people affected by the company’s misleading statements… [New Mexico Attorney General] Torrez said his office is evaluating how much to seek but will push for the maximum penalty based on the jury’s findings. The state will also ask [Judge] Mathew to direct Meta to make changes, which could include corrections to its past misstatements as well as an audit of the way it manages user data, Torrez said.

Re:Potentially order the company to pay billions

By RitchCraft • • Score: 4, Insightful • Thread

“potentially” - don’t worry, the fine will be .001% of the total profit for one year as is the norm for these types of trials. The lawyers will get rich, a little left over for the State, and nothing for the peons, you know, the ones actually affected by this.

Not good enough.

By msauve • • Score: 5, Funny • Thread
>Meta Made 43M Misleading Statements,

They’re never going to catch up with Trump, no matter how hard they try.

Past Misstatements

By Khyber • • Score: 4, Informative • Thread

Call it what it is in reality, lies.

Re:Not good enough.

By Mr. Dollar Ton • • Score: 4, Insightful • Thread

The problem isn’t that FB “can’t catch up”, they don’t have to. The problem is FB amplifies those lies and from a few hundred a day they become a few billion a day. Even if 0.001% of that catches on, the democratic political process, which is quite broken even under the assumption rational decisions based on good information, becomes its antithesis, and you see stuff like the trump teabagging party, erika’s outfit, AfD and whatnot.

Sadly, this is a tool so well developed now, that it is unstoppable under any traditional political system.

Re:Potentially order the company to pay billions

By Local ID10T • • Score: 5, Interesting • Thread

Excessive fines are always reduced on appeal. The numbers are intended to make headlines and show that something is being done.

In reality, a small fine is paid -less than the profits. The changes to business practices are things the company has already changed or wants to change, written up by the lawyers to look like a concession.

It is a show, staged for our benefit.

There’s a New Way to Break RSA Encryption

Posted by EditorDavid • • View on SlashDot • Skip
"Signature forgery.” It’s a new way to break RSA keys — and it doesn’t require factoring. Ars Technica reports on new research using classical computing to “reduce the current RSA security level to an unacceptably low threshold” and lower the required computing resources by orders of magnitude.

There’s “a gap in current RSA-type security assumptions,” according to a paper co-authored by University of California, San Diego professor Nadia Heninger, who argues that gap “gives classical cryptanalytic evidence in favor of moving away from RSA entirely during the current post-quantum transition.”
The practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe. Nonetheless, the research has taken cryptographers by surprise… “If this result holds up under peer review, it would indeed be a conceptual break-through,” Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key....”

The key forgery attack Heninger and the other researchers devised poses an immediate threat to 1024-bit RSA. Even for 2048- and 4096-bit keys, the method reduces the security of RSA to unacceptable levels. The National Security Agency, National Institute of Standards and Technology, and European Union Agency for Network and Information Security require that any cryptosystem should provide a level of no less than 128 or more bits, meaning the operations required must exceed 2**128. The forgery attack drops these levels to 2**65, 2**90, and 2**119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger’s team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will “almost certainly” drop the security levels further.

The attack works only against blind-signature implementations of RSA… Still, some real-world systems continue to use blind-signature, also known as textbook, RSA… The paper’s authors and other researchers stress that the new attack poses little real-world threat. It does, however, drastically lower the estimated security of textbook RSA, and it does so in a way no one knew of previously… The new attack will further increase the urgency of completely moving away from the cryptosystem.
Thanks to long-time Slashdot reader phatrabt for sharing the article.

OK…

By 0123456 • • Score: 5, Interesting • Thread

I don’t really care enough about RSA to read deeply into the paper, but it seems to exploit a service that will sign billions of your messages with the secret key that you are trying to crack… which I seem to recall was known to be a potential problem for RSA thirty years ago (so don’t do that).

Not new, but …

By fahrbot-bot • • Score: 5, Funny • Thread

It’s a new way to break RSA keys — and it doesn’t require factoring.

Obviously … :-)

Re: OK…

By fluffernutter • • Score: 5, Interesting • Thread
i know the Python cryptography libraries specifically warn not to do that for years now. this is a known problem.

Re:OK…

By arglebargle_xiv • • Score: 5, Informative • Thread
It exploits a misuse of RSA that virtually nothing in existence does. When the various standards for RSA were created decades ago, PKCS #1, X9.31, ISO 9796, and so on, they were specifically designed to prevent this type of attack. So it’s academically reasonably interesting, but otherwise nothing to worry about unless.

Re:okkkkkkay

By F.Ultra • • Score: 5, Informative • Thread
No, Grover’s algorithm does not even theoretically break AES. What it does is making AES weaker, aka AES-256 attacked with Grover is equivalent to AES-128 with no Grover which is still 100% infeasible to brute force. Only the weaker AES-128 will be broken for real but who uses that?

Asteroids Named After Tom Lehrer and ‘Weird Al’ Yankovic

Posted by EditorDavid • • View on SlashDot
“Weird Al” Yankovic’s name has just been approved for a new asteroid — (14331) Alyankovic = 1981 EC26 — by the International Astronomical Union, reports Space.com.

Yankovic’s asteroid was championed by planetary scientist Allison McGraw joined by “several heavy hitters in the planetary science field, according to the Tucson Star. (Astrophysicist Steve Desch from the School of Earth and Space Exploration at Arizona State University; Tim McCoy, one of the main curators of meteorites at the Smithsonian Institution; and University of Arizona research scientist Melissa Brucker, leader of the Spacewatch program, which has discovered more than 179,000 asteroids.)
The scientists also convinced the International Astronomical Union to name an asteroid after one of Yankovic’s major influences, famous musical humorist and political satirist Tom Lehrer, who died last year at age 97. Lehrer’s work includes "The Elements,” a 1959 song in which he recites the entire periodic table to the tune of Gilbert and Sullivan’s “Major-General’s Song.” “He was a mathematician and teacher and also wrote math- and science-themed songs,” McGraw said. “We felt that someone who had that kind of science enthusiasm really deserved to have their name up in the sky....” McGraw is hoping that naming space rocks after stars like Lehrer and “Weird Al” will cast some reflected light on two things she’s passionate about: asteroid research and science communication.
Six years ago a 92-year-old Tom Lehrer released all his lyrics into the public domain. (Wikipedia notes he’d “largely retired” by the 1970s to become a mathematics teacher at the University of California, Santa Cruz.) Slashdot ran a brief career retrospective when Lehrer died last year at age 97.

And the IAU writes that “Generations of scientists have been inspired” by Weird Al Yankovic’s “comedic musical works, including 'It’s All About the Pentiums' and 'White and Nerdy'.” (“I’m fluent in JavaScript as well as Klingon,” Yankovic sings in the latter.) He appears in a song envisioning a rap battle between Bill Nye the Science Guy and Sir Isaac Newton… And in 1999 he recorded a five-minute summation of Star Wars: Phantom Menace, sung to the wistful tune of Don McLean’s American Pie. Performing it last month in a NPR Tiny Desk concert, “most of the audience was singing along,” remembers an interviewer at NPR. “It felt like something that was very personal to them.”
Weird Al: It’s one of those songs that means a lot to people, particularly “Star Wars” fans, of course. But I mean, I see a lot of people in the audience cosplaying as Jedi Knights and waving their light sabers… I’ve even heard that, you know, they play that song at “Star Wars” conventions, and people get weepy… [I]t really hits people in a tender place somehow…

“Oh my, my, this here Anakin guy
may be Vader someday later, now he’s just a small fry.
And he left his home and kissed his mommy goodbye,
sayin’ soon, I’m gonna be a Jedi.”
Yankovic has led a geek-friendly career. In the heyday of Napster, he released an anthem-style parody mocking the arguments of the Recording Industry Association of America, titled "Don’t Download This Song. (“Even Lars Ulrich knows it’s wrong…”)

“Once in a while maybe you will feel the urge
To break international copyright law…
you start out stealing songs, then you’re robbing liquor stores
And selling crack and running over school kids with your car…”


As a student at Cal Poly, San Luis Obispo, Yankovic bootstrapped a career in 1979 by recording his first novelty song "My Bologna" (a parody of “My Sharona” by the Knack) while playing his accordion in a bathroom for its acoustics. And even the IAU acknowledged the geeky themes in his 1999 song "It’s All About the Pentiums" (a filk on Puff Daddy’s “It’s All About the Benjamins”).

“You’re usin’ a 286? Don’t make me laugh
Your Windows boots up in what, a day and a half?
You could back up your whole hard drive on a floppy diskette
You’re the biggest joke on the Internet…”

good memories

By kencurry • • Score: 4, Informative • Thread
The 70’s, Dr. Demento radio on KMET in LA, after midnight if I remember right. Good for weird Al to survive with his sense of humor intact.

Re:But?

By JThundley • • Score: 4, Informative • Thread

Weird Al also recently released an educational video about the brain recently: https://www.youtube.com/watch?…

Thank you International Astronomical Union

By UnresolvedExternal • • Score: 3 • Thread
Thank you IAU from the depths of my heart - that made me smile

However, the initialism for your union (given the current zeitgeist), could be misread as I AI U.

UAI IAIU

Re:Thank you International Astronomical Union

By UnresolvedExternal • • Score: 5, Funny • Thread
Replying to myself, yes but..................

Al .. AI… It has been Weird AI Iankovic all this time!!

Damn you sans serif!!

What I’d like to see

By dskoll • • Score: 3 • Thread

I’d like to see Asteroid Lehrer crash into and destroy the crater named after Wernher von Braun on the Moon.