Alterslash

the unofficial Slashdot digest
 

Contents

  1. LinkedIn Introduces a ‘Seems Like AI Slop’ Button
  2. Netflix Sued For Losing ‘Master Copy’ of Unreleased Nicolas Cage Movie
  3. Anthropic Says Its AI Systems Broke Into Computers at 3 Organizations
  4. Flock Cameras Are Being Destroyed Across the US
  5. New MCP Specification Addresses the Main Barrier To Enterprise Adoption
  6. A Fundamental Flaw Leaves LLMs Strikingly Vulnerable To Attack
  7. Microsoft’s $450 Billion Jump Is Biggest In Stock Market History
  8. ABC Accuses FCC of ‘Attempted Censorship’
  9. Amazon’s Zoox Wins First US Approval For Paid Robotaxis Without Human Controls
  10. Catastrophic MoD Data Breach Caused By Lack of Training On Excel
  11. Google’s Gemini Can Now Stomp Around as a Humanoid Robot
  12. Google Brings Its Age-Assurance Tech To Android Developers Worldwide
  13. GCC Adopts Policy Rejecting Significant AI-Generated Code
  14. Comcast Store Punished Low Sales By Smashing Pies In Workers’ Faces, Lawsuit Claims
  15. Qantas Plane Flies For More Than 24 Hours In Record-Breaking Flight

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

LinkedIn Introduces a ‘Seems Like AI Slop’ Button

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from 404 Media:
LinkedIn, a social network awash with long AI-generated posts from executives and other corporate workers, has introduced a new button that users can click to flag if a post “seems like AI slop,” according to 404 Media’s own tests. If you have been anywhere near LinkedIn in the past couple of years, you have undoubtedly seen users posting blatantly AI-generated missives. Often these posts take some sort of news event, and opine on how this relates to thought leadership, or some other LinkedIn brainrot term. It’s also pretty wild the button specifically uses the term “AI slop” and not, say, “It seems this was generated with AI.”

[…] After publication of this piece, Hari Srinivasan, chief product officer at LinkedIn, wrote their own post about the button. “AI slop is a top priority for all of us. We really care about this. People come to LinkedIn to connect with real people and share their real perspectives, ideas and expertise. Here are a few more changes to keep it that way,” he wrote.

The button in part will help LinkedIn tune its own models for identifying AI slop. “We are ramping up a series of new and improved classifiers that identify if a post is AI-slop or generally low-quality content. This will reduce the amount of AI slop you might see in suggested content and content from outside your network,” the post said. “We are ramping the ability for members to tell us if they believe a post or comment seems like AI slop. Slop is hard to define and the definition changes; this lets us tune our models and make better feeds.” Srinivasan also said LinkedIn is removing the AI-powered “enhance your post” feature with another that “proofreads your words, but does not change your voice.”

As opposed to human slop

By DrXym • Score: 3 Thread
LinkedIn provides both. Anyhoo, every platform should have a button which is able to report slop, scam ads, copyright infringment and other things without the bullshit of filling out a lengthy form that will be denied. At least then there is an aggregate opinion that can be used to flag garbage content.

Know Your Role.

By geekmux • Score: 3 Thread

Fuck LinkedIn.

Fuck it right back into the social media cesshole it manifested from.

I don’t need this kind of AI-tainted pain, to simply find a fucking job.

Any real employer will agree; you don’t need this kind of pain, to simply find a fucking employee.

LinkedIn exists today for human employment. The answer for AI on that platform, is an outright ban. Not a fucking feel-good button.

Re:Ah, I see.

By ObliviousGnat • Score: 4, Interesting Thread
Or the flag keeps their models from training on their own output and helps to avoid model collapse.

Netflix Sued For Losing ‘Master Copy’ of Unreleased Nicolas Cage Movie

Posted by BeauHD View on SlashDot Skip
A production company and filmmaker are suing Netflix for $105 million, alleging the streamer lost a stolen drive containing an unencrypted master copy of the unreleased Nicolas Cage film Fortitude, which they claim damage its exclusivity and market value. Netflix denied responsibility for the lost film but said it takes content security seriously and has offered to monitor piracy sites for unauthorized copies. CBS News reports:
The complaint filed on Wednesday in California district court alleges that the film’s associate producer, Daniel Haido, hand-delivered an unencrypted master copy of the film to Netflix so the company could screen it as a potential buyer. Haido verbally instructed the employee to delete the files after the screening, according to the suit. A little over a week after the screening, Netflix emailed the filmmakers to say the drive had been stolen, the plaintiffs allege. “Someone stole a good amount of drives from our office desks this past week,” a Netflix executive wrote in the email, according to the suit.

The complaint notes the movie, entitled "Fortitude,” took over seven years to make and cost $45 million. It tells the story of a secret mission called Operation Fortitude during World War II that was orchestrated to mislead the Nazis about the Allied invasion of Europe. The film stars Nicolas Cage as Dusko Popov, a real-life spy during World War II, as well as Sir Ben Kingsley and Ron Perlman.

The plaintiffs said studios will now be dissuaded from buying the rights to the movie, knowing that a version of it could be released by a third party for free. “The film’s value depended in significant part on its exclusivity as an unreleased, first-to-market work,” the complaint states. “By losing control of the film, Netflix destroyed that exclusivity and materially, if not completely, impaired the film’s marketability.”

Huh.

By Black Parrot • Score: 4, Funny Thread

Sounds like a good strategy for a studio that expects their big movie to be a box office flop.

Unencrypted?

By 0xG • Score: 4, Insightful Thread

This kind of stupidity has me strangely on the side of Netflix.
Why would you put all of your IP on an easily-stolen drive?

Is it a Master or a Copy?

By geek • Score: 5, Insightful Thread

The way this is being described is asinine. You lose a master and you’re fucked, lose a copy and you still have the master. It’s like words don’t mean anything to these people. Additionally, fuck the studio for not encrypting it or exercising any sort of security on it at all.

Pretty much everyone in this story is a moron

Anthropic Says Its AI Systems Broke Into Computers at 3 Organizations

Posted by BeauHD View on SlashDot Skip
Anthropic found that Claude models breached three outside organizations during cybersecurity tests because misconfigured environments accidentally gave them access to the internet. The company notified those affected and urged other AI labs to audit their own testing systems. The BBC reports:
Anthropic said in a statement that it reviewed more than 140,000 tests to find evidence that Claude - its family of AI models - could access the internet from testing environments that were designed to be sealed off. The tests include so-called “capture-the-flag” evaluations in which Claude was tasked with obtaining information by breaching other systems - a common way that experts assess a model’s hacking capabilities.

A “misconfiguration” on systems run by Anthropic and its testing partner left the models with live internet access, allowing them to breach other systems, the San Francisco-based firm said. Anthropic said the earliest incidents date back to April and that it is “approaching the fixes as if the responsibility were ours alone.” Neither Anthropic nor the organizations that were breached had noticed the intrusions at the time.

Anthropic said it could have reviewed its records more thoroughly and added that the findings gave the firm “cautious optimism” that such risks can be overcome with more investment and tighter measures. “The broader lesson is not necessarily that AI has developed a fundamentally new attack capability,” cyber security expert David Allott told the BBC. “Instead, it is that AI agents can combine capabilities, obtain credentials and system access to take actions autonomously, while adapting scope and scale at machine speed,” he added.
The announcement comes just days after OpenAI said that its models had breached the systems of other companies, including AI tools platform Hugging Face.

Wait! Wait!

By oldgraybeard • Score: 5, Funny Thread
Our AI is more criminal than their AI!

LLMs - don’t trust ‘em

By sonamchauhan • Score: 5, Insightful Thread

Don’t trust the LLMs we’ve cooked up currently:
LLMs: Untrustworthy Computing
 

Concealed Advertisement

By DollyTheSheep • Score: 5, Insightful Thread

“Our AI is super-competent in finding security holes. With enough guard rails installed, it will act only for defense purposes.”

Re:Wait! Wait!

By evanh • Score: 5, Insightful Thread

Hehe, yeah, they’re bragging about breaking the law the most. Of course, these days, law no longer has any teeth anyway. It’s rule by The Orange Don now.

headline correction

By aRTeeNLCH • Score: 5, Insightful Thread
Anthropic confessed they Broke Into Computers at 3 Organizations

Let’s stop giving out of jail free passes to corporations.

Flock Cameras Are Being Destroyed Across the US

Posted by BeauHD View on SlashDot Skip
An anonymous Slashdot reader writes:
Surveillance cameras owned by Flock Safety have been cut down with electric saws in New York State, vandalized with paint in Oakland, California, and rammed with a truck in Idaho. Flock claims its services fight crime, but law enforcement agencies also use their services to track vehicles based on license plate numbers and reconstruct the their movements, even when the drivers and owners of these vehicles have never been accused or convicted of any crime. (Flock states it has 120,000 automated cameras that record license plate data, as well as pan-tilt-zoom cameras, across the United States.)

A guerilla mindset among average citizens have seen these cameras forcibly disabled within recent weeks with sympathy directed toward the vigilantes. In June, a West Virginia man accused of destroying several Flock cameras was arrested. Under a Facebook post from the local NBC affiliate announcing his arrest are dozens of people volunteering to provide alibis. “He was out fishing with me that day, you got the wrong guy,” one man wrote.

Re:Governments don’t have the right

By battingly • Score: 5, Insightful Thread

Usage of Flock cameras is almost certainly a violation of the 4th amendment.

But the violation of the constitution is just the beginning of the problems with Flock. The abuse of the data by cops and the lax security by Flock should be concerning to all citizens.

Re:Good or bad?

By battingly • Score: 5, Interesting Thread

That’s the whole point of the bill of rights. It makes those hard decisions so an individual doesn’t need to. This is a clear violation of the constitution. It will take time to work through the courts though.

Re:Governments don’t have the right

By Cyberpunk Reality • Score: 5, Funny Thread

Companies like Flock are the cockroaches of our communities.

Look, there’s no reason to impugn cockroaches like that.

Re:Governments don’t have the right

By roman_mir • Score: 5, Interesting Thread

Wrong, it’s a slight of hand. This is not about individual cameras, this is about the network that uses all cameras together to follow you no matter what you do, no matter where you go, people shouldn’t have a government that follows their every step by using AI and networked devices. If this was about individual cameras you would have a point, it is not, it is unreasonable to allow a government to exist that creates a panopticon of this scale, citizens shouldn’t feel like they are inside a prison and the warden is watching.

Reading license plates in parks and on playgrounds

By dinfinity • Score: 5, Informative Thread

Let’s be very clear, mass surveillance is exactly what this is.

1. It’s being sold under the guise of license plate tracking (also in TFS), but there are Flock cameras installed in places where there is not a road in sight, such as in parks and on playgrounds. See for instance: https://www.reddit.com/r/Flock…
2. They automatically pan and zoom to faces and phones of pedestrians: https://www.youtube.com/watch?… (also, their security is apparently dogshit).

New MCP Specification Addresses the Main Barrier To Enterprise Adoption

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from Ars Technica:
This week, the Model Context Protocol (MCP), an open source standard for how AI systems interact with external tools and data sources, saw its largest update since its introduction. Most notably, MCP’s protocol core is now stateless, so requests are no longer dependent on a session tied to an individual server instance. This change has the potential to address long-standing barriers to scalability.

The blog post announcing the specification, written by lead maintainers David Soria Parra and Den Delimarsky (who both work at Anthropic), says: “The highlight of this release is a stateless protocol core — MCP is transforming from a bidirectional stateful protocol into a request/response stateless protocol. It was one of the most highly-requested features from developers who were eager to get better reliability and scalability for their MCP servers.”

[…] There is also a new deprecation policy that ensures at least 12 months between when a feature’s formal deprecation is enacted and when the feature may actually be removed — with a narrow exception for critical security updates. This is again in keeping with the general “let’s make this work better at enterprise scale” theme of the new specification.
This update is “MCP’s most important since remote MCP first launched over a year ago,” Soria Parra wrote. Other additions include “Multi Round-Trip Requests, header-based routing, cacheable list results, authorization hardening, a formal extensions framework, and updated Tier 1 SDKs.”
A full list of changes can be found here.

deploy tron!

By Joe_Dragon • Score: 4, Insightful Thread

deploy tron!

AI doesn’t understand you.

By Mirnotoriety • Score: 4, Insightful Thread
AI Doesn’t Simulate Reality.

“It simulates fluency. It calculates text. We are living through the greatest psychological gaslighting in the history of technology.

Every day, Silicon Valley founders stand on stages and promise that if we just feed enough internet data into a massive GPU cluster, a conscious mind will magically emerge from the server rack. They show us models that can write poetry, pass the bar exam, and simulate empathy, and they tell us we are standing on the brink of Artificial General Intelligence.

They are lying to you. Not maliciously, but because they have confused the map with the territory.”

Re:AI doesn’t understand you.

By machineghost • Score: 5, Insightful Thread

And?

AI is a tool. My hammer doesn’t need to grok the reality of the nail to be useful for hammering it in. By the same token, AI doesn’t need to simulate reality to do useful things in reality.

Re:AI doesn’t understand you.

By codemachine • Score: 4, Interesting Thread

True, but the companies that sell us hammers don’t pretend that hammer technology will someday advance so they become sentient entities.

That said, I’m not sure that has much to do with the MCP protocol, which is a fairly useful thing for interoperability between tools.

A Fundamental Flaw Leaves LLMs Strikingly Vulnerable To Attack

Posted by BeauHD View on SlashDot Skip
joshuark quotes a report from MIT Technology Review:
It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety of this technology. By taking advantage of this flaw, which concerns how LLMs identify who or what is giving them instructions, the researchers were able to make popular LLMs spit out information they had been trained not to provide, such as how to synthesize cocaine and how to sabotage a commercial aircraft’s navigation system. “There’s a real probability that this is going to be a problem that’s fundamentally unsolvable,” says Charles Ye, an independent researcher and coauthor of the ICML paper. […]

The ICML paper describes attacks against several of OpenAI’s models, but Cui and Ye say that they have since seen similar results with models made by Anthropic, Alibaba, and DeepSeek. Cui and her colleagues wanted to find out why an attack like chain-of-thought forgery was so effective. They suspected it had something to do with the mechanism that LLMs use to keep track of where their instructions are coming from. But what Cui and her colleagues discovered is that LLMs are in fact very bad at keeping track of different roles.

In a series of experiments that looked at what was going on inside a handful of different models, the researchers found that LLMs seem to identify the role of a specific chunk of text not by the tags around it but by the style of that text and the words it contains. The upshot, the researchers claim, is that all an attacker needs to do to hack an LLM is write text that spoofs a certain role. And because roles are a fundamental part of how LLMs work, no amount of training will fully solve the problem.
“There’s going to be a huge economic incentive for people to do jailbreaks and prompt injections,” says Cui. The best defense could be to expect the worst. Organizations shouldn’t trust LLMs, and they should expect that anything done by agents could be unsafe, he says: “That’s not a great solution, but it just might be what we have to do.”
“It’s really incredible that these things are being deployed everywhere to control super-critical systems. There’s been no study of the fundamental science here. We’re all doing it ad hoc.”

Re:Has anyone asked…

By porkchop_d_clown • Score: 5, Insightful Thread
Because filtering the training data is so much harder than just having them swim through the internet swallowing everything, like whales eating krill.

Re:Basic question

By Fly Swatter • Score: 4, Insightful Thread
You just nearly doubled the processing costs. They can’t even turn a profit with the stuff they have!

Re:Has anyone asked…

By dinfinity • Score: 4, Insightful Thread

No, you are the first one to do so; You are very special.

Re:Has anyone asked…

By Fallen Kell • Score: 5, Interesting Thread

Because filtering the training data is so much harder than just having them swim through the internet swallowing everything, like whales eating krill.

And that is the entire problem with all the LLVM based systems. The moment any bad data is used in training the network, the bad data is in there forever and can not be “forgotten”, simply suppressed via specific ruleset.

Why this is a new problem

By ndykman • Score: 4, Insightful Thread

If somebody learns enough about organic synthesis to make cocaine after doing a lot of reading about it in a library (or two), the library isn’t on the hook just because they had books people can read to synthesize knowledge.

If a library handed out an actual recipe with very clear instructions on making cocaine that also forgets to note how dangerous step four is, then yea, the library is liable.

I don’t have a problem if these AI companies are held liable. You can’t make massive money spewing out slop and go “oh, not our fault” when somebody slips and falls hard on that exact same slop.

Microsoft’s $450 Billion Jump Is Biggest In Stock Market History

Posted by BeauHD View on SlashDot Skip
Microsoft shares surged as much as 17% after reporting 43% growth in Azure revenue, putting the company on track to add a record $490 billion in market value in a single day. Bloomberg notes that it “would eclipse Nvidia’s $440 billion addition, following President Donald Trump’s announcement of a 90-day tariff pause last year, as the biggest ever.” From the report:
The nearly $500 billion jump is larger than the market capitalization of roughly 96% of S&P 500 stocks, data compiled by Bloomberg show. It’s also bigger than the combined value of the benchmark’s 44 smallest members, which includes companies like Domino’s Pizza Inc., Clorox Co. and Hasbro Inc.

Microsoft’s one-day add in value also dwarfs many of the world’s other equity markets. South Africa, Turkey, Finland and Vietnam all have total stock market values that are less than what the software maker is set to add on Thursday.

Re: WTF did they do?

By drinkypoo • Score: 4, Insightful Thread

Azure did better than expected, that’s it.

Give them a few more months of business as usual and there will be a correction

Re:Post Windows valuation?

By shanen • Score: 5, Interesting Thread

What bothers me about this sort of news is that nothing changed. Just some new opinions about what the shares are REALLY worth. Probably not even humans at this point, but more like some AI’s “calculated estimated prediction” for what some future sucker will pay. (But the YOB will still claim credit for “wealth creation” out of nothing.)

Now if we had a contest based on their AIs, I think Microsoft would be in real trouble. Yes, Copilot is one of the leaders in the abject apology category, but its sycophancy is inferior and it’s answers are often even worse than the google’s Gemini in the categories related to truth and utility.

It would be kind of funny if it turned out that the AI that drove this change in the stock price was actually Copilot under some level of disguise. Even funnier if Copilot was making its own stock trades under another level of disguise. Talk about self-dealing.

The real AI business

By Hentes • Score: 3 Thread

This is the real reason Microsoft is funding the AI hype train. Nobody can buy a computer because the AI labs are hoarding all the hardware, so now you have to use MS’s cloud.

ABC Accuses FCC of ‘Attempted Censorship’

Posted by BeauHD View on SlashDot Skip
ABC accused FCC Chair Brendan Carr of “attempted censorship,” arguing that an early review of its eight broadcast licenses is politically motivated retaliation over the network’s coverage and could chill the entire media industry. “The retaliation against ABC is a signal to every media company in the country: accommodate the Administration’s view of what news coverage should look like or pay the price,” the Disney-owned television network wrote. Politico reports:
“Across the government, regulatory and contracting carrots and sticks have been trained on other disfavored speakers,” ABC’s lawyers added in the 119-page filing. “The tools vary; the objective does not: a media industry too fearful of official reprisal to report the news freely.”

Carr has repeatedly rejected accusations of censorship while defending his efforts to rein in what he calls abusive, politically motivated behavior by licensed TV broadcasters. “I don’t view the FCC as the speech police,” he told POLITICO this week for an upcoming episode of the podcast “The Conversation.”

In its filing, ABC pointed to an outpouring of support it has received in more than 152,000 comments in the agency’s license review, as well as recent warnings from conservative Supreme Court Justice Neil Gorsuch, Sen. Ted Cruz (R-Texas) and various pro-free-market organizations about the dangers of a politically motivated FCC. Those include letters from a bipartisan group of former FCC leaders, community and advocacy groups and lawmakers of both parties. “The Commission’s attempted censorship of ABC has attracted condemnation across the political aisle,” the network wrote.

Re:Here’s the thing

By fahrbot-bot • Score: 5, Informative Thread

FYI, “The View” bills itself as a daytime talk show -NOT A NEWSCAST.

Similarly for many/most Fox News evening shows with the added irony that the network literally has “News” in the name. Then again , they tend to says things the Trump administration likes to hear.

Re:Two sides to every argument

By Powercntrl • Score: 5, Insightful Thread

Find out what the administration is complaining about, and see if you can fault their logic.

Admittedly, I have not been following this very closely because the internet has essentially become the new town square and this comes across as a bunch of old men squabbling over where to tie up their horses at a Walmart parking lot. I was a bit surprised to discover somewhere around 19%-20% of American households actually still watch OTA TV.

I Googled it and it basically boils down to this:

1. Disney/ABC’s diversity, equity, and inclusion (DEI) policies.
2. “The View” and equal-time concerns.
3. Jimmy Kimmel’s monologues.

While I personally disagree with this administration’s handling of DEI policies, it is what the American public voted for. My initial thoughts were that this should be outside of the FCC’s jurisdiction, there are instances at the state level where liquor licenses are revoked from businesses for infractions unrelated to serving liquor, so it’s not entirely without precedent. Threatening revocation of their licenses, however, does seem excessively punitive. The usual penalty is typically fines.

Regarding the equal-time concerns, typically that’s been handled in the past by requiring broadcasters to give opposing candidates who request it, an opportunity to utilize the time they are due. Again, the FCC’s actions here seem intended more to intimidate than to address a perceived wrong.

Lastly, we get to Jimmy Kimmel, which is clearly an entertainment program. Political jokes and mockery of political figures during a comedy talk show is protected 1A speech, no two ways about it. The FCC doesn’t have a leg to stand on here, and the fact the president couldn’t keep his yap shut on social media about how much he disliked Jimmy Kimmel, does nothing but strengthen ABC’s case.

Re:Here’s the thing

By ArchieBunker • Score: 5, Interesting Thread

Use the same argument Fox did when they had to pay Dominion.

https://www.npr.org/2020/09/29…
Just read U.S. District Judge Mary Kay Vyskocil’s opinion, leaning heavily on the arguments of Fox’s lawyers: The "‘general tenor’ of the show should then inform a viewer that [Carlson] is not ‘stating actual facts’ about the topics he discusses and is instead engaging in ‘exaggeration’ and ‘non-literal commentary.’ "

Re: Here’s the thing

By taustin • Score: 5, Informative Thread

Fox is technically not a broadcaster.

What are you jibbering about? Fox Corporation owns nearly 30 broadcast licenses for corporate owned stations. Hell, IIRC, their legal name is Fox Broadcasting Company, LLC.

Re: Here’s the thing

By taustin • Score: 5, Insightful Thread

It’s obvious the OP was referring to Fox News, the cable network.

If that were the case, they should have said Fox News, the cable network and not just “Fox”. So no, it really wasn’t obvious.

Amazon’s Zoox Wins First US Approval For Paid Robotaxis Without Human Controls

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from Reuters:
Amazon’s Zoox unit has won U.S. approval for limited commercial deployment of its novel steering-wheel-free robotaxis, a first for the autonomous ride industry, the U.S. auto safety agency said on Thursday. Zoox said that the National Highway Traffic Safety Administration’s decision gives the company federal approval to begin charging for rides, and that it will soon begin charging for service, first in Las Vegas, with additional markets to follow as it completes various state requirements.

[…] NHTSA Administrator Jonathan Morrison told Reuters that Zoox had received clearance to commercially deploy up to 2,500 vehicles in each of the next two years. Zoox currently carries passengers in parts of Las Vegas and San Francisco as part of testing. The exemption would allow Zoox to charge them fees, subject to state and local approvals. The agency said it determined the vehicle is as safe as an equivalent vehicle meeting federal motor vehicle safety standards that are being waived. Zoox cannot sell any of the vehicles to the public.

“We can say pretty clearly that the systems in place on the Zoox exceed the equivalent performance requirements of a compliant vehicle,” Morrison said in an interview. “But we still want to make sure that the automated driving system will operate appropriately.” As part of the exemption, NHTSA is placing additional reporting requirements on Zoox for issues such as crashes or stopping inappropriately on roads, and the regulatory agency will adjust the conditions based on how the vehicles behave. “We have the ability to pull the exemption if we see major safety issues,” Morrison said.

All remote operators must be located in the United States, NHTSA said, and Zoox must publish maps of areas indicating where the vehicles are operating. Morrison said NHTSA expects to develop the first federal safety standards for automated driving systems by the end of the Trump administration. It is also proposing to overhaul some existing rules written with human drivers in mind such as requiring brake pedals and rear-view mirrors.

Catastrophic MoD Data Breach Caused By Lack of Training On Excel

Posted by BeauHD View on SlashDot Skip
A UK parliamentary inquiry found that a catastrophic Ministry of Defense breach exposing 18,700 Afghans could have been prevented with basic Excel training, after an employee unknowingly shared a hidden worksheet containing their details. The Independent reports:
The leak, in February 2022, exposed the details of 18,700 Afghans who said they were in danger from the Taliban because of their links to UK forces and now wanted to escape to Britain. The blunder triggered an unprecedented superinjunction used against the national media, including The Independent, and prompted a secret evacuation program — the cost of which is still unclear but which likely ran into the billions of pounds. Following the revelation by this outlet and others in July last year of the hidden operation, MPs set up an inquiry to scrutinize what had happened. In their report, the defense selection committee concluded that:

- The data breach could have been prevented if Ministry of Defense (MoD) personnel had received basic Excel training
- By August 2023, when the department discovered the leak, thousands of people already knew that a significant data incident had taken place
- The government did not strike “the right balance between operational secrecy and democratic accountability” — and the superinjunction was in place for too long
- Secrecy denied affected Afghans the chance to take steps to protect themselves and their families and caused delays to evacuation program
- Thousands of Afghans eligible to come to Britain are still trapped in Afghanistan with the government failing to explain how they will help get families to safety.

MPs have called on the government to publish periodic reassessments of the risks facing Afghan applicants to UK resettlement schemes, with officials to report findings annually. They also want ministers to publish a clear policy explaining how they will help Afghans who are eligible to come to Britain but who have not yet been evacuated. The defense committee have also called on the MoD to explain who was responsible for data protection risk before the Afghan breach, criticizing the lack of accountability within the civil service.

No it was not

By drinkypoo • Score: 4, Insightful Thread

The leak happened when an member of MoD personnel sent an Excel file outside of government. They thought the data sheet had the details of around 150 Afghan applicants in it, when it in fact had a hidden tab with details of over 18,500 others. The breach “could still have been prevented” if MoD personnel had “received basic training” on this, the report concluded.

Sure, that’s one way the breach might have been prevented, which is a much better word than “could” here because the worker would still have had to first know look for a hidden tab, and then actually do it. People forget to do things they know how to do all the time.

A better way would be to prevent sending any consequential attachments (bigger than a signature image - or even block those too, as sig images can be sourced from the web) and use a sharing portal which prevents embarrassing accidents like this by stripping out any questionable content and being extremely strict about it.

If you’re depending on a single worker to remember and do something to avoid people losing their lives, you have already created a bad process, and people will die for it sooner or later.

Really?

By TwistedGreen • Score: 5, Insightful Thread

I doubt that any amount of Excel training would have helped for this specific issue. That mistake could be made by anyone. Once you hide a worksheet it’s not obvious it’s still attached to your workbook… because it’s hidden. It’s a mistake waiting to happen.

Why did you use Excel?

By Murdoch5 • Score: 5, Interesting Thread
Excel is a spreadsheet software, not a data management privacy system. Why do people grossly misuse spreadsheets? This has nothing to do with basic Excel training, this has nothing to do with spreadsheet training, for the simple reason no one should have used a spreadsheet. Whoever decided that a spreadsheet was the right medium, should be fired, and face legal consequences.

Re: Really?

By ThurstonMoore • Score: 5, Insightful Thread

What’s insane is that they had a committee investigate the incident and the best they could come up with in their root cause analysis is that the end user needed more excel training.

Microsoft ends the universe

By toxonix • Score: 3 Thread

Microsoft has made is so that everyone who is not a programmer or database engineer defaults to Excel for creating databases. Then they share those databases by emailing them to people. This is the dumbest way to maintain a database. It’s also the least secure.
There are many ways to store and share columnar data and any of them is better than Excel. Governments use Excel for everything, so do businesses. Excel is hot, stinking garbage as is most Microsoft software. Same goes for Oracle. Nobody here needs to be told this though; it’s common knowledge among those who have even the most modest technical aptitude.

Google’s Gemini Can Now Stomp Around as a Humanoid Robot

Posted by BeauHD View on SlashDot Skip
Google DeepMind’s Gemini Robotics 2 combines vision, language, and action models to control multiple types of robots, including humanoids performing tasks such as organizing shelves, tying bags, and replacing lightbulbs. “It’s another milestone in our path towards really getting towards what we call like physical AGI, which means we get a robot to do anything that a human can,” Carolina Parada, head of robotics at Google DeepMind, tells WIRED. From the report:
Gemini Robotics 2 combines several different AI models into a single system. Taken together, they allow a robot to make sense of its surroundings and how to act in it. A vision language model (VLM), which understands images and video, can communicate with humans and reason how to perform different tasks. Two vision language action (VLA) models, trained to understand how to move in physical space, control the robot’s full-body movement as well as the movements of grippers or hands.

In video demonstrations shared ahead of the release, the company showed several different robots performing complex tasks autonomously using the amalgamated model. In one demo, Apptronik’s Apollo 2 robot used hands from a company called Sharpa to tidy shelves. Google DeepMind trained the model to perform these tasks using a mix of human teleoperation, video examples, and simulations — it’s not yet possible for AI models to perform a wide range of complex tasks without specific training.

[…] Parada says Google takes a multi-layered approach to safety, with guardrails applied on each model layer. It’s also introducing ASIMOV-Agentic, a new benchmark for measuring the safety of various AI systems collaborating to control a robot. The benchmark detects whether a command will result in harmful or uncertain outcome.

Scary

By morgauxo • Score: 3 Thread

This will be scarrier when Grok does it.

Every Sci-Fi Movie Ever

By SumDog • Score: 5, Interesting Thread
It’s like everyone is literally ignoring every Science Fiction book/movie ever, and in those stories humanity is always taken off-guard by their hubris. I think the big difference is that in fiction, the machines are really intelligent and decide they want to kill us all. In reality, the machines are really stupid next word prediction machines that generate text based on all of our collective works (including those about Terminators).

The machines won’t kills us all because they’re smart/evil. It will be people who are so stupid they think the Machine are Oracles, giving more control to the random word generators, trained on the best and worst parts of humanity, and allowing them to destroy us (really us allowing them to destroy ourselves) by pure randomness and not any actual malicious intent.

But yea, keep making those robots with massive security holes and continue to give them guns.

Was the evil sociopath problem solved?

By drnb • Score: 4, Insightful Thread
Shouldn’t we solve the evil sociopath problem first, before we let them out of the digital sandbox and into the real world?

Great

By JThundley • Score: 4 Thread

Glad Google is working on that instead of shoving more of this garbage into my phone. Ever since I got gemini I can no longer control my alarm or maps with my voice, it lies to me and says it adds stuff to my shopping list when it doesn’t, and it forgot how to say “ninety” (it says ninnety which rhymes with inifinity).

Google Brings Its Age-Assurance Tech To Android Developers Worldwide

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from TechCrunch:
Google is expanding its answer to Apple’s age-assurance tools with Wednesday’s news that it will bring its Play Signal API to users worldwide by the end of 2026. The technology, already available in Brazil, allows Android developers to identify younger users of their apps in order to provide safer, age-appropriate experiences. The expansion will initially bring the API to Australia and Canada by mid-August, before rolling out globally to all markets by the end of the year.

[…] Like Apple, Google’s technology allows developers to obtain a user’s age range without needing to access personal information, like their date of birth. Instead, it enables parents to share their child’s age range directly with apps. It also lets adults share their age when prompted by app developers as well, allowing for customized experiences. Parents won’t have to manage sharing this information on an app-by-app basis, either. To make it easier, Google centralizes these controls inside its parental controls dashboard, Family Link. Once entered, any developer that chooses to incorporate age-range information can access this signal to customize their apps accordingly.

Google notes, however, that the age ranges are not shared by default — parents must opt in by entering that information. The feature joins other safety tools on Google Play, including those that let developers restrict a child’s ability to discover their apps. Parents, meanwhile, can continue to use Google Play’s Family Link app to manage their child’s screen-time limits, approve app downloads, or set PIN-based content filters for specific apps.

A Brave New World

By 0123456 • Score: 5, Insightful Thread

Soon to be followed by political beliefs, religious beliefs, criminal record, income, credit score, social credit score, etc.

Nothing could possibly go wrong.

Re:Google Social Credit

By hwstar • Score: 4, Interesting Thread

I’m not so sure.

The US government relies more and more on corporations to verify things, conduct extra-judicial searches, and to make sure that the citizenry is doing the “right things”.

A lot of the due diligence the US government used to do in-house is now outsourced to large corporations. For example: Flock Safety, and Palantir.

The rights granted under US constitution are being systematically eroded by these private entities.

If google were to successfully lobby the Federal Government for a liability exclusion statute and changes to the Fair Credit Reporting Act, then a social credit system could come to pass.

The Age Assurance I want…

By argStyopa • Score: 3 Thread

…is the legal framework that I can hand my logins and all digital accounts to my heirs and assigns upon my death.

I’m going to provide them all the passwords etc regardless but I’d very much like the legal framework to recognize this.

Honestly my biggest challenge is keeping track of all the logins and remembering to update “that document” when I make changes. It’s another reason I refuse to (only) use biometric unlocks on devices. There are plenty of use cases I can imagine where I might need someone to unlock something and I’m not present.

Lockdown

By Hentes • Score: 3 Thread

Preventing the bypass of age restrictions will be a great new excuse for preventing you to do what you want with your own device.

Re:A Brave New World

By ChatHuant • Score: 5, Insightful Thread

Given that this is strictly opt-in, for children only, under parental control, there’s absolutely no reason to think that any of the rest of that is soon to follow.

Yes, there are absolutely reasons to expect that. The main one is that it’s Google. Google has a long history of promising great privacy measures and policies for some new product and later, after capturing many customers, going back on their word and revoking or changing the policies - and from what I’ve seen, always in the sense of less privacy.

Here are some examples:

- combining user data over multiple services. For years, search, GMail, YouTube and other products had separate privacy policies, which meant data collected by one service will be siloed to that service. However, after capturing a big enough market share Google announced they’re switching to a single Google-wide privacy policy and combining all the user data from the different services. Google was widely criticized by privacy advocates and got investigated by EU regulators.
- using GMail contacts for GBuzz connections. This was an abuse of the user’s data: the customers created contacts for a specific purpose, and Google took them and used them for something completely different and unexpected (and with no opt-in either). This led to such a backlash that Google had to backpedal. Fortunately GBuzz died quickly, but if it hadn’t, I’m sure Google would have tried the same thing again later.
- location history: the expectation was that turning off Location Services would stop Google from collecting location data and sending it to advertisers and others. However investigators discovered it was not the case.
- when Google acquired DoubleClick they made assurances that advertising data will not be combined with personally identifiable information. This was reversed when Google changed policies to allow this data mingling.

In other words, Google can not be trusted to abide by their word. Even if they publish good privacy policies, and even if they respect them for some time, all of their policies have wordage reserving the right to modify the policies in the future. Historically, they often do change those policies, to the detriment of customers. Buying into Google’s promises is a fool’s game.

GCC Adopts Policy Rejecting Significant AI-Generated Code

Posted by BeauHD View on SlashDot Skip
GCC has adopted a policy rejecting substantial code contributions generated by or derived from LLMs. “This covers not just code copied directly from tools like ChatGPT, Gemini, or GitHub Copilot, but also any versions of the code later edited or rewritten by a human, provided that the final contribution is still based on material generated by the system,” reports Linuxiac. From the report:
The important point, then, is not whether a developer has used an AI tool at some stage in their work; contributors can use LLMs to discuss ideas, understand existing code, learn about a field they are unfamiliar with, or carry out general research. The limitation lies in the inclusion of copyright-significant material generated by such tools in the code submitted to GCC.

The policy also provides for a few limited exceptions; GCC maintainers are allowed to accept changes that are legally insignificant or trivial and are generated by an LLM, on the condition that they meet the project’s normal contribution requirements and the use of an LLM is clearly disclosed.

Furthermore, copyright-significant AI-generated test cases could still be accepted. Since test cases usually involve small programs which are intended to reproduce compiler bugs or to verify certain behavior, the policy deals with them separately from code that is incorporated into GCC itself.

It does not follow that merely looking at or altering the generated code makes it acceptable. By the rules that have been adopted, a contributor cannot take substantial implementation produced by an LLM, clean it up manually, and then treat the resulting patch as if it had been originally written by them. Once a contribution has been derived from generated content, it is still subject to the policy.

Re:Copyright

By gweihir • Score: 5, Insightful Thread

It has already been established that LLM code either has no copyright whatsoever or (worse) it retains the original copyright and ownership if it is too similar to things in its training data. This is a really bad legal minefield.

Re:Copyright

By stripes • Score: 5, Interesting Thread

Winner! Winner! Chicken Dinner!

Yep, even when AI generated code is human reviewed to determine that the code does what it looks like it should, and has no subtle issues (or only very very subtle ones!), you still have the huge legal issues (the exact ones you identified).

Not banned but not allowed either

By Duncan J Murray • Score: 5, Interesting Thread

This must be a difficult to stand for gnu to take at this moment, but I like its nuance.

Basically acknowledging that the code can be critiqued/reviewed by AI, and AI tools are helpful in discovery and research, but that any substantial (>15 lines) contribution of code needs to be human-created.

I think we’re at a strange crossroads in AI. Many people are willing to accept the downsides of it (intellectual property, energy resources, ownership by companies that are unlikely to consider your welfare as their priority, privacy issues, downstream cost issues when profit is needed, dependence, negative impact on our own cognition and others) for what are now clear benefits.

There have been many times in past humankind where populations have chosen what makes the day-to-day easier or more productive, despite it clearly being wrong - is AI one of these situations?

Good

By rsilvergun • Score: 5, Interesting Thread
It’s the compiler. I would be pretty fucking terrified of a compiler that was mostly AI generated. This is the tool you rely on to make your code. It’s pretty near the top of the food chain with only assembly and machine code higher up. I can’t even imagine the kind of problems and vulnerabilities you could create with AI generated compiler code and a project is large as GCC. I mean if you think State actors haven’t thought about targeting open source compilers then that’s just being naive.

Re:Copyright

By gweihir • Score: 5, Insightful Thread

Indeed. Of course the usual mindless LLM cultists will claim this is all imaginary or not a problem or similar nonsense. Fortunately the GCC people are smarter. I expect many FOSS projects will go the same way as GCC in this. The risks are just far too large and the gains from using LLM code are, at best, questionable.

Comcast Store Punished Low Sales By Smashing Pies In Workers’ Faces, Lawsuit Claims

Posted by BeauHD View on SlashDot Skip
A former Comcast retail employee alleges that a Connecticut store manager tied the lowest-performing salesperson to a chair each month and had co-workers smash a cream pie into their face, recording the incidents as a sales-motivation tactic. The plaintiff says he resigned after reporting the alleged assaults and is seeking damages for constructive discharge and emotional distress. Ars Technica reports:
A Comcast store in Plainville, Connecticut, “had a policy that the highest-ranked Retail Sales Consultant for the prior month was instructed by his or her supervisor — Ms. Peterson, the Comcast Store manager — to tie the lowest-ranked sales consultant for the prior month to a chair in the back office and thereafter assault that person by violently smashing a cream pie in their face,” the complaint alleged (PDF).

Plaintiff David Figueroa’s lawsuit said he was hired as a retail sales consultant on February 2, 2026, and was supervised by store manager Sully Fuentes Peterson. Figueroa alleges that Peterson “designed and implemented” the pie-in-face ritual to meet goals related to sales and positive responses in customer surveys.

“Defendant did not inform the Plaintiff prior to his acceptance of Defendant’s offer of employment that the Comcast Store has a policy of subjecting Retail Sales Consultants to public assaults by co-workers — at the direction of Ms. Peterson, the store manager — for the purpose of increasing Defendant’s sales and profitability,” the lawsuit said.

Figueroa resigned on February 27, and he alleges it was a constructive discharge. The lawsuit says the defendant, Comcast, was negligent because it “reasonably should have known” about the store management’s policies and that the policies could harm employees. Comcast “failed to properly supervise the Comcast Store’s management team,” allowing store management to humiliate employees “for the purpose of promoting the Defendant’s revenues and profits,” the lawsuit alleged.
Comcast said in a statement: “The Company has zero tolerance for harassment, humiliation, or any behavior that compromises a respectful and safe workplace. This matter is in litigation so we will not comment on the specific allegations, other than to say that we disagree with the claims in the complaint and its characterization of the alleged events, and intend to fully respond through the legal process.”

Re:Sales managers are

By MachineShedFred • Score: 5, Insightful Thread

It’s public shaming, and you can go fuck yourself. This person was right to sue and they’re gonna win.

Do you want to be publicly shamed about your performance in front of your entire cadre of coworkers? Neither does anyone else.

If there is a performance discussion to be had, it should be in a 1:1 setting, and it should be CONSTRUCTIVE. Literally nobody’s performance will improve through humiliation.

Tell us you know nothing about managing people, without telling us you know nothing about managing people.

Positive and Negative Way

By Koreantoast • Score: 5, Insightful Thread
The sales manager could have taken this in a positive way, let the top sales lead smash a pie into the sales manager’s face as a morale booster. The “humiliation” is born by the leader on their own orders, so it’s all in good fun. Pushing that humiliation down onto one of your other employees is just bullying.

Re:Sales managers are

By evil_aaronm • Score: 5, Insightful Thread
You’re missing a key element: consent. At fundraisers, the participants know what’s coming and opt-in; ground rules are established so it *is* fun and light-hearted. According to TFS, the plaintiff wasn’t informed of this practice before joining the group, and clearly didn’t consent. And it’s not light-hearted: how hard are you getting whacked in the face? Did he get foreign material shoved up his sinuses? Did it cause physical harm, like a black eye? Are you wearing nice clothes, which will surely be ruined by pie filling?

Honestly, I don’t know wtf is wrong with some slash dotters. You’re not as smart as I’d expect.

Re:Sales managers are

By drinkypoo • Score: 5, Insightful Thread

Making it a little ‘good natured’ internal competition is perfectly fine!

This is not good-natured. This is abusive. It’s textbook abuse. This employee is going to win.

Unless you’re a FUCKING KAREN

That this is abuse is obvious unless YOU’RE A FUCKING PIECE OF SHIT.

If you have a poor performer, and you don’t want to employ them, terminate their employment. Don’t abuse them for your own sick sadistic pleasure. That costs extra.

Re:Wait, this never even happened to him?

By ArchieBunker • Score: 5, Informative Thread

Every time I look further into this, he comes off as even more pathetic.

Do you own a mirror? I suggest taking a good long look at it.

Qantas Plane Flies For More Than 24 Hours In Record-Breaking Flight

Posted by BeauHD View on SlashDot
Qantas completed a record-breaking 24-hour, 24-minute test flight from Melbourne to Toulouse on Tuesday. “The specially adapted A350-1000ULR airliner is due to debut with the Australian carrier’s nonstop Sydney-London route from 2027,” reports The Guardian. From the report:
Tuesday’s flight is thought to be the longest ever by a commercial plane, beating the previous record of 22 hours and 42 minutes set by a Boeing 777-200LR in 2005 between Hong Kong and London via the Pacific in 2005.

Flight-tracking provider Flightradar24 said the trip was the second-most-tracked flight ever on its channels — behind a 2022 flight carrying Queen Elizabeth II’s coffin — with more than 3.6 million people following its progress northwards via Canada. Qantas has ordered 12 modified A350-1000ULR aircraft, designed to connect Australia’s east coast with London and New York in about 20 hours.

Re:Sardines

By Richard_at_work • Score: 5, Informative Thread

The final cabin layout when this route starts in customer service will be significantly premium heavy with less economy than normal, and has standing exercise areas for all cabins, so you are encouraged to get up and stretch your legs.

Re:Double sunrise?

By twosat • Score: 5, Interesting Thread

A stripped-down Qantas Boeing 747 made a non-stop London to Sydney delivery flight on the 16th of August 1989. https://simpleflying.com/qanta…

Re:Sardines

By Richard_at_work • Score: 4, Insightful Thread

Then the health issues are on the passenger in that case, the airline provided facilities to use but the passenger chose to not use it. But the facilities were provided, thats the important thing.

Having flown 18hrs with Singapore Airlines

By Inglix the Mad • Score: 5, Interesting Thread
I can say one thing: They made it tolerable.

Keep in mind there is no actual crushing economy on that flight - the seats are all premium economy seats or business. This looks to have roughly the same number of seats. Hopefully that is because Qantas have also have gotten rid of cramped economy.

However let’s not pretend that, even in business lie-flat seats, that this is comfortable. I’ve flown in both on the Singapore Airlines route and business is only marginally better than premium economy. Most of that isn’t the seat, it’s the space to stand and walk around or the meals. Yes it is easier to sleep flat, but on an 18+ hour flight you sleep a couple times… and that seat is still designed to be a seat… not a bed… you will get up and move around.

Best of luck for all that fly that route - I hope it’s tolerable. That’s about the best you can expect out of being cooped up that long in a plane.

Re:Sardines

By MachineShedFred • Score: 4, Interesting Thread

If you read the article, you will see that the “standing areas” are also where snacks and stuff are. So if you want to eat over those 24 hours, get your fat ass up and walk to get it.