Alterslash

the unofficial Slashdot digest
 

Contents

  1. There’s a New Way to Break RSA Encryption
  2. Asteroids Named After Tom Lehrer and ‘Weird Al’ Yankovic
  3. Raspberry Pi Stock Jumps 30% as Demand Surges. (And Boards Now Locked to Their Original RAM Size)
  4. F-Droid 2.0: FOSS Android Appstore Continues Updating Despite Google’s Pending ‘Developer Verification’ Plan
  5. How Believable is Google’s New ‘Live Avatar’ Capability?
  6. People Training OpenAI’s AI Fired For Using AI To Train the AI
  7. Five Police Officers Criminally Charged for Misusing Flock Cameras in Indianapolis
  8. OpenAI, Anthropic CEOs Urge UN Countries to Cooperate on AI Safety Standards
  9. Qualcomm Announces Snapdragon X2 Series Processors Will Support Linux
  10. Rogue OpenAI Agent Tried to Breach Government Site in May When Prompted for Simple Data-Retrieving Tasks
  11. Cities Across US Oppose Trump FCC Plan to Preempt Local Broadband Rules
  12. Whatever Happened to the 150,000 Tons of Radioactive Waste Stored Under the Atlantic Ocean?
  13. Andreessen Horowitz Launches AI/Company-Building School As a College Alternative
  14. Bitcoin Surges to $86,455, an 8-Month High, After America’s SEC Announces Tokenized Stock Experiment
  15. Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

There’s a New Way to Break RSA Encryption

Posted by EditorDavid • • View on SlashDot • Skip
"Signature forgery.” It’s a new way to break RSA keys — and it doesn’t require factoring. Ars Technica reports on new research using classical computing to “reduce the current RSA security level to an unacceptably low threshold” and lower the required computing resources by orders of magnitude.

There’s “a gap in current RSA-type security assumptions,” according to a paper co-authored by University of California, San Diego professor Nadia Heninger, who argues that gap “gives classical cryptanalytic evidence in favor of moving away from RSA entirely during the current post-quantum transition.”
The practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe. Nonetheless, the research has taken cryptographers by surprise… “If this result holds up under peer review, it would indeed be a conceptual break-through,” Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key....”

The key forgery attack Heninger and the other researchers devised poses an immediate threat to 1024-bit RSA. Even for 2048- and 4096-bit keys, the method reduces the security of RSA to unacceptable levels. The National Security Agency, National Institute of Standards and Technology, and European Union Agency for Network and Information Security require that any cryptosystem should provide a level of no less than 128 or more bits, meaning the operations required must exceed 2**128. The forgery attack drops these levels to 2**65, 2**90, and 2**119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger’s team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will “almost certainly” drop the security levels further.

The attack works only against blind-signature implementations of RSA… Still, some real-world systems continue to use blind-signature, also known as textbook, RSA… The paper’s authors and other researchers stress that the new attack poses little real-world threat. It does, however, drastically lower the estimated security of textbook RSA, and it does so in a way no one knew of previously… The new attack will further increase the urgency of completely moving away from the cryptosystem.
Thanks to long-time Slashdot reader phatrabt for sharing the article.

Asteroids Named After Tom Lehrer and ‘Weird Al’ Yankovic

Posted by EditorDavid • • View on SlashDot • Skip
“Weird Al” Yankovic’s name has just been approved for a new asteroid — (14331) Alyankovic = 1981 EC26 — by the International Astronomical Union, reports Space.com.

Yankovic’s asteroid was championed by planetary scientist Allison McGraw joined by “several heavy hitters in the planetary science field, according to the Tucson Star. (Astrophysicist Steve Desch from the School of Earth and Space Exploration at Arizona State University; Tim McCoy, one of the main curators of meteorites at the Smithsonian Institution; and University of Arizona research scientist Melissa Brucker, leader of the Spacewatch program, which has discovered more than 179,000 asteroids.)
The scientists also convinced the International Astronomical Union to name an asteroid after one of Yankovic’s major influences, famous musical humorist and political satirist Tom Lehrer, who died last year at age 97. Lehrer’s work includes "The Elements,” a 1959 song in which he recites the entire periodic table to the tune of Gilbert and Sullivan’s “Major-General’s Song.” “He was a mathematician and teacher and also wrote math- and science-themed songs,” McGraw said. “We felt that someone who had that kind of science enthusiasm really deserved to have their name up in the sky....” McGraw is hoping that naming space rocks after stars like Lehrer and “Weird Al” will cast some reflected light on two things she’s passionate about: asteroid research and science communication.
Six years ago a 92-year-old Tom Lehrer released all his lyrics into the public domain. (Wikipedia notes he’d “largely retired” by the 1970s to become a mathematics teacher at the University of California, Santa Cruz.) Slashdot ran a brief career retrospective when Lehrer died last year at age 97.

And the IAU writes that “Generations of scientists have been inspired” by Weird Al Yankovic’s “comedic musical works, including 'It’s All About the Pentiums' and 'White and Nerdy'.” (“I’m fluent in JavaScript as well as Klingon,” Yankovic sings in the latter.) He appears in a song envisioning a rap battle between Bill Nye the Science Guy and Sir Isaac Newton… And in 1999 he recorded a five-minute summation of Star Wars: Phantom Menace, sung to the wistful tune of Don McLean’s American Pie. Performing it last month in a NPR Tiny Desk concert, “most of the audience was singing along,” remembers an interviewer at NPR. “It felt like something that was very personal to them.”
Weird Al: It’s one of those songs that means a lot to people, particularly “Star Wars” fans, of course. But I mean, I see a lot of people in the audience cosplaying as Jedi Knights and waving their light sabers… I’ve even heard that, you know, they play that song at “Star Wars” conventions, and people get weepy… [I]t really hits people in a tender place somehow…

“Oh my, my, this here Anakin guy
may be Vader someday later, now he’s just a small fry.
And he left his home and kissed his mommy goodbye,
sayin’ soon, I’m gonna be a Jedi.”
Yankovic has led a geek-friendly career. In the heyday of Napster, he released an anthem-style parody mocking the arguments of the Recording Industry Association of America, titled "Don’t Download This Song. (“Even Lars Ulrich knows it’s wrong…”)

“Once in a while maybe you will feel the urge
To break international copyright law…
you start out stealing songs, then you’re robbing liquor stores
And selling crack and running over school kids with your car…”


As a student at Cal Poly, San Luis Obispo, Yankovic bootstrapped a career in 1979 by recording his first novelty song "My Bologna" (a parody of “My Sharona” by the Knack) while playing his accordion in a bathroom for its acoustics. And even the IAU acknowledged the geeky themes in his 1999 song "It’s All About the Pentiums" (a filk on Puff Daddy’s “It’s All About the Benjamins”).

“You’re usin’ a 286? Don’t make me laugh
Your Windows boots up in what, a day and a half?
You could back up your whole hard drive on a floppy diskette
You’re the biggest joke on the Internet…”

good memories

By kencurry • • Score: 3 • Thread
The 70’s, Dr. Demento radio on KMET in LA, after midnight if I remember right. Good for weird Al to survive with his sense of humor intact.

Thank you International Astronomical Union

By UnresolvedExternal • • Score: 3 • Thread
Thank you IAU from the depths of my heart - that made me smile

However, the initialism for your union (given the current zeitgeist), could be misread as I AI U.

UAI IAIU

Re:Thank you International Astronomical Union

By UnresolvedExternal • • Score: 4, Funny • Thread
Replying to myself, yes but..................

Al .. AI… It has been Weird AI Iankovic all this time!!

Damn you sans serif!!

Raspberry Pi Stock Jumps 30% as Demand Surges. (And Boards Now Locked to Their Original RAM Size)

Posted by EditorDavid • • View on SlashDot • Skip
Raspberry Pi’s stock shot up over 30% in the last week. Why are investors so excited? For the six months ending June 30, revenue for Raspberry Pi Holdings “jumped 90% to $256.9 million,” reports Investing.com, “while adjusted EBITDA more than doubled to $40.3 million, and profit before tax leapt 216% to $19.6 million.”
Underpinning the strong numbers was an acceleration in OEM adoption: direct unit shipments rose 26% to 3.4 million, total unit shipments climbed 17% to 4.2 million, and the customer order backlog doubled during the half to 2.6 million units. Demand was particularly robust in the Smart Home and Aerospace and Defence segments, and the company launched the AI HAT+ 2 for Raspberry Pi 5, extending its edge-AI product line.
DRAM prices have been increasing everywhere, notes The Times of London, and Raspberry Pi co-founder Eben Upton “said new customers, who required computers or microcontrollers to manufacture other technologies, were choosing Raspberry Pi’s computers because they had a better inventory of components than competitors.”
“There’s always that choice for an original equipment manufacturer as to whether they should ‘make’ or ‘buy’ the computer elements of their platforms,” Upton said. “The supply chain disruption is making ‘make’ a much harder choice and it’s making the cost of repair a much harder choice. So we’re seeing strength there.” Raspberry Pi has already increased its suppliers of Dram more than threefold…

Upton said the increased demand had led to its backlog for units doubling to 2.6 million, which meant production rates would need to increase to prevent the numbers from getting “unhealthy”. New production capacity at the manufacturing facility in Pencoed, Wales was expected to come online this week… Exports were almost evenly split between North America, Europe and the rest of the world, which was primarily China, where demand was growing… Analysts at Peel Hunt said the company was “well positioned for rapid growth in unit shipments in 2027 and beyond” with demand expected from enthusiasts as well as the AI and security sectors.
In other news, Hackaday notes the Raspberry Pi Foundation has “pushed binary-blob bootloader changes that limit your ability to upgrade RAM…”
This change restricts upgrading the RAM chip on your Pi 4 and Pi 5, as well as Compute Modules. By the looks of it, it does not restrict replacing the RAM chip with a chip of a similar size, quote, “locking devices to their original RAM size”. As such, this does not prevent repair of your Raspberry Pi board, but does somewhat limit your repair part choice, at most.

This restriction is easily bypassable. The bootloader is stored in the SPI flash chip, which can be reflashed using the built-in mask ROM over USB and rpiboot, and you are not prevented from flashing older versions of the bootloader, so far. This means even if you manually swap the RAM chip, all you need to do is to also downgrade the bootloader to the last known good release — 2024-09-10 — and then your Pi board or Compute Module will function with upgraded RAM. If you have the skills to upgrade your RAM, you most certainly have the skills to downgrade the Raspberry Pi bootloader. For most regular use, having a two-year old bootloader version won’t really matter…

For the reference, this bootloader change happened almost exactly two years ago, at some point between September 10 and September 23, 2024… The Raspberry Pi Foundation (RPF) justifies this as follows: they saw third-party resellers sourcing low-RAM Compute Modules, upgrading them with RAM from unknown source and unknown stability. My observation is that they’d also be reselling the modules at a markup for purely commercial gain, while undercutting RPF who would otherwise direct that money into RnD, something I much enjoy to see them do. This creates perverse incentives and risk for people buying Raspberry Pi boards online, and RPF decided to limit this primarily for their users’ benefit, plus, if you ask me, some of theirs… The related GitHub issues have a fair few pingbacks, and exploring them makes the problem look grim to me....

My advice: don’t lament Raspberry Pi RAM upgrades, especially given they’re only slightly harder to perform now. Very few hackers ever performed them, the main audience for them turned out to be dodgy hardware resellers online, and in most cases, repair doesn’t seem to be impeded at all, either. Think of the users that will no longer be fooled by a shady seller on Amazon, especially now that the perverse incentives for board mods and reusing harvested RAM chips are at their highest.
Raspberry Pi co-founder Eben Upton answered questions from Slashdot readers in 2011 and 2016.

Re:Uncomfortable truth

By dskoll • • Score: 5, Informative • Thread

I think the main reason Raspberry Pi succeeds is the quality of the software ecosystem. There are plenty of other SBCs out there, but most of them have very poor software support. The vendor typically cobbles together a janky Linux distro, throws it over the wall and says “OK, it’s done!” and never provides upgrades or much in the way of assistance.

Raspberry Pi hardware might be meh and it’s certainly not as open as I like, but the software support is the best there is for SBCs. If other SBC vendors want to compete, they’ll have to up their software game (and work with the community to get any modifications upstreamed into mainstream distros.)

Re:My advice

By Racemaniac • • Score: 5, Informative • Thread

While i also hate the RAM upgrade restriction, hearing why they did it sadly does make some sense.
With how expensive the versions with more ram have become, they’ve been facing sellers swapping the ram chips with low quality chips with higher capacity, and selling it as an authentic pi with that capacity…

As always, assholes are the reason we can’t have nice things… And it sucks for raspberry pi to make that decision… But i do kind of get it, they don’t want people to get scammed left & right in this period of ram shortages…

I kinda agree with the lock, Ill explain

By AcidFnTonic • • Score: 5, Informative • Thread

So I am normally anti DRM and would normally complain loudly about this lock but if you read into it the idea makes perfect sense and it’s less of a “lock” and more about “authenticity”.

People were buying these with the lowest ram, sourcing crappy questionable ram and upgrading them then reselling at the higher cost which left people eventually holding the bag when the memory errors and such appeared.

When you get one and flash the official image the “lock” is in effect. Anyone can make their own image without it thus the end user tinkerers can STILL UPGRADE THEIR RAM. This just stops someone from selling a knock-off upgraded PI as “genuine” because people will likely expect to flash official images on it. This just thwarts those plans and keeps the higher quality chips around for people.

If you don’t like this buy the cheap one, get the ram chip and ugrade it and remove the lock yourself. Tinkering still works....

Re:My advice

By tlhIngan • • Score: 5, Interesting • Thread

Their reasoning sounds plausible only if read from a “business weasel” perspective. If there’s a market for RPis with more lower quality RAM, nobody is “undercutting” RPF; they’re selling the products they want to, at the price they want to, and choosing not to offer big/slow/cheap OEM RAM configurations. And even if someone could undercut them on the exact same components - So what??? RPF may be a non-profit, but I am not!

The problem isn’t resellers undercutting RPi. It’s someone buying a 1GB RPi, doing the mod with 8GB of poor quality RAM, then selling it as an 8GB RPi at a modest discount.

The problem is that you buy the board and because the RAM is bad, you perform a return and find out it was a counterfeit RPi board that doesn’t work for you.

Despite the AI issue, you can find RAM. Often poor quality recycled RAM with errors are stupidly cheap (and used in many products as-is). The board can boot with bad RAM, but run stable it might not, and you’d be more likely to blame RPi than on the reseller you bought the dodgy unit from

The fact that RPi took this long to do it would mean they’re actually seeing a bunch of returns with the RAM swapped out.

It could also be that people are buying the 8GB units, swapping them with 1GB units and selling them as fake 8GB units, like those $20 “1TB” USB sticks you can find easily on Amazon.

Changing the RAM on an RPi isn’t a trivial procedure - I believe it’s PoP RAM so it’s not something a hobbyist would easily do without a lot of specialized equipment and experience in being able to separate PoP RAM from the base CPU and reballing and such. So hobbyist wise, they aren’t likely to be ones affected since few would have the expertise or equipment. But those trying to sell counterfeits do.

Re:Uncomfortable truth

By dskoll • • Score: 4, Interesting • Thread

Yes, I agree. I run most of my life on a Pi 4: Internet router, Asterisk PBX, SMTP and IMAP server, file backup server, pi-hole, Radicale calendar/contact server, Xymon monitor, etc, etc, and it’s just fine.

It was pretty cheap when I bought it a few years ago. Nowadays, a mini PC might be cheaper, but it would likely consume more power, and low power consumption and silent operation was important to me for a server that’s on 24x7.

F-Droid 2.0: FOSS Android Appstore Continues Updating Despite Google’s Pending ‘Developer Verification’ Plan

Posted by EditorDavid • • View on SlashDot • Skip
“F-Droid, a third-party app repository that only distributes free and open-source software packages for Google’s Android mobile platform, on Thursday announced version 2.0 of its Android app,” reports The Register.

Though they also note “a big banner across the top of the F-Droid site” pointing to a site describing pending changes from Google that threaten the future of F-Droid…
[D]evelopers who want their apps broadly distributed outside the official Google Play Store will need to register with Google and verify their identities. Google’s Full Distribution option includes paying a one-time $25 fee, handing over a copy of a government-issued ID to verify one’s identity, and conforming to Google’s terms of service. Google also offers a free Limited Distribution option that doesn’t require government ID verification but restricts distribution to 20 authorized devices, while apps from unverified developers can still be installed by users who enable Android’s advanced installation flow.

The potential death warrant hanging over its head hasn’t stopped the F-Droid team from rolling out a bunch of new features for an app it says it intends to keep working on for years to come… The team also credited the EU’s many Digital Markets Act decisions against Google for making the installation experience smoother for users. F-Droid can now use a unified installation service for its apps thanks to the availability of a pre-approval API that allows users to approve an installation when they request it, rather than waiting until the app has finished downloading. That, said the F-Droid team, “brings the F-Droid install experience on official Android devices much closer to what the built-in app store can provide.” Additionally, F-Droid 2.0 can fetch and install app updates automatically, which it now does by default.

All of those changes, however, won’t matter much if Google pushes ahead undeterred with its plans to force registration onto non-Play Store developers. F-Droid’s announcement on Thursday makes it seem that the team isn’t going to go quietly.
F-Droid has gone 10 years without a major update, notes Ars Technica — and spent over a year developing F-Droid 2.0:
The new F-Droid client was redesigned from scratch in Kotlin Compose, which is the standard for modern Android apps. This makes the store much more responsive, and there’s optional support for Android’s Material theming. The interface has also been cleaned up considerably, making the most important functions easier to access and hiding some others in overflow menus… Unlike the Play Store, F-Droid doesn’t track your taps and installs to push ads and suggestions — it helps you find things and gets out of the way.

F-Droid now includes a huge number of categories, drilling down to specialized niches like firewalls, password managers, and VPNs. You can see all these groups in the search tab. There are also higher-level categories listed on the main Discover page. When searching for apps, F-Droid will now be able to return results based on app descriptions rather than just names.
“One of the goals of the rewrite was to lower the barrier for new contributors,” F-Droid said in their announcement. “We are excited to begin rolling out F-Droid 2.0 to users over the coming weeks after 14 test releases.” (And if you want the 2.0 release right now, it’s available on the versions page.)

Re:Thank you F-DROID

By Errol backfiring • • Score: 5, Interesting • Thread
F-droid is the only app store on my phone with LineageOS. Off course, the Google “services” are not installed either. I am never going back to stock Android again.

GrapheneOS

By FPhlyer • • Score: 3, Informative • Thread

I’ve used Fdroid for years (mostly for Termux) but I started moving from Android to GrapheneOS little by little over this last summer, first on my Pixel Tablet and more recently on my Pixel phone. Fdroid is an excellent app store here.
If you are lucky enough to own a Google Pixel device, switching to GrapheneOS is an option to escape from Google’s “walled garden”.
Motorola has announced plans to start offering GrapheneOS as an option on some future models as well.

Re: GrapheneOS

By alexgieg • • Score: 4, Interesting • Thread

the alternatives only supported very few phones.

I only purchase phones I know I can install alternative OSes on. When one of my current ones is getting too old and in need of replacement, I research what the current alternative Android OSes are, chose a bunch I find are nice enough, then find the list of devices supported, the chose one from among those that’s within my budget range. Those tend to be Motorola, whether officially or via some hack.

I don’t buy a phone to play games, which means most any phone is performant enough for my needs, so I go with the cheapest option that does what I actually need. This also means that warranty is irrelevant: if the phone breaks for some weird reason, which is rate, getting it serviced by paying for the service, or buying a new one outright, aren’t a big deal. Hence, the moment the new phone arrives I follow the procedure to get it unlocked, then the new ROM into. Sometimes with Google apps, sometimes without, depending on what I’m using it for.

As for bank apps and the like, I keep an old, tiny, cheap phone with stock, years-old Android that banks, due to mysteries of the universe, consider “secure” despite having hundreds of unpatched holes all the way down to the kernel. When I need to do banking I pick it from the docs drawer, turn it on, do what I need, turn it off, and back into the drawer it goes. For everyday use I have a debit/credit card, no app necessary with them.

Streaming is a loss, but eh, YouTube works well enough either with the official app, an alternative one, or a mobile browser, so good enough for watching something on the go. For me that suffices.

But yes, for those for whose use case is way more mainstream that’s certainly not a good fit.

Re:Surprising!

By ArsenneLupin • • Score: 4, Insightful • Thread
Google’s new rules specifically apply to other largely unrelated services, that’s the problem.

FY google verification Plan

By denisbergeron • • Score: 4, Informative • Thread

My phones are either on Graphene or Lineage with microG.
My phone, my choice :-)

I own it.

How Believable is Google’s New ‘Live Avatar’ Capability?

Posted by EditorDavid • • View on SlashDot • Skip
Google has synthesized “expressive face-to-face experiences” for its speech agent Gemini 3.8 Live. They’re now offering a Live Avatar “with precise lip-syncing, natural expressions, and fluid turn-taking” for Google Enterprise accounts wanting “engaging customer service” or for offering interactive walkthroughs. (Check out the not-creepy-at-all video in Google’s announcement.)

“Though Google will offer a library of preset avatars for customers to choose from, it will also allow organizations to create their own,” notes The Verge. (See some examples from the YouTube channel “AI with Surya”.)

But even without the visualization of the avatar, “I was never able to shake the feeling that these conversations with computers never feel like a real conversation,” argues the blog Android Police. Conversing with just the Ai-generated audio, “At best, they feel like talking to a phone representative or someone from tech support. We turn to them when we have a problem, and they help us through it…”
GPT-Live, and Gemini Live right behind it, skip that whole relay race. Instead of translating your voice to text and back to voice, the model works with raw audio the entire way through (what it hears and what it says) inside the same system, with nothing translated in between. That sounds like a small plumbing detail, but it’s the whole story. Cutting out the text step lets these models respond in a fraction of a second instead of the pause we’ve learned to expect, and it lets them hear things text can never carry: tone, hesitation, whether you’re annoyed or joking…

I was hoping to be surprised by how natural the conversation felt. Instead, I came out with a deeper appreciation for every human I’ve ever talked to. Even the boring ones… I spoke, it spoke back. I spoke faster, it answered faster. Then I switched to a different language, and it switched along with me. Even switching between languages several times during the same sentence didn’t stump it. The most impressive moment happened when I asked it what “T-O-P-G-3-3-K” spelled out, and it immediately came back with, “You are spelling the word Top Geek, but using a 3 to represent a reversed E....”

Although it felt fast and responsive, at no point did it feel like talking to another human being… What Gemini couldn’t replicate, because it was never built to replicate it, is human connection.... I’m sure I’m not telling you something you don’t already know, but somehow talking naturally to an LLM amplifies the feeling that there is no one on the other side of the line. It might flow like a phone call, but it doesn’t feel like one.
MrBrklyn (Slashdot reader #4,775) says he discussed “why mainstream media avoids reporting on screen dependency” with Gemini, and eventually convinced Gemini to respond that it’s just “another tool built by the same tech giants to make sure you rely on their system to tell you what to think, how to talk, and what is real.”

Live Avatar Capability?

By 93 Escort Wagon • • Score: 4, Funny • Thread

Are we talking about Aang, Korra, or one of the others?

Are they going for gold…

By MpVpRb • • Score: 5, Insightful • Thread

…in the olympics of stupid ideas?
Why do all of these consumer AI ideas seem so awful and useless?
How about using the new tools for science and engineering?

Realism

By Waffle Iron • • Score: 5, Funny • Thread

The conversation only seems unnatural because they didn’t use the right avatar.

If you choose the “Max Headroom” avatar, then everything will look and feel exactly as you would expect. Moreover, the dystopian vibe he gives off will be a perfect fit with the current state of the world.

Ditch the avatar and give it a phone number

By JaredOfEuropa • • Score: 4, Interesting • Thread
If I call tech support or the bank or whatever, I don’t want, need nor expect to see the other person’s face. In general, video calling isn’t widely used except in multi-person meetings, or when calling a loved one overseas. The avatar is not needed.

Also, give your AI agent a phone number where I can reach it, or give it its dedicated app or whatever, but default to “handset mode” like a regular phone call. Let me put it on speaker if and when I want to. Turning the interaction into a regular phone call will go a long way towards making the conversation feel more natural. Interacting with Siri and Alexa feels unnatural; adding an animated avatar to a disembodied voice won’t help, even if the conversation itself flows naturally. I know, a phone call isn’t suitable for every interaction, especially when collaborating or co-creating with someone, but it covers most cases.

But I guess a simple audio call is harder to monetize.

People Training OpenAI’s AI Fired For Using AI To Train the AI

Posted by EditorDavid • • View on SlashDot • Skip
404 Media reports “multiple contractors hired to improve OpenAI’s models have been fired for using AI to train the AI:
That’s not great for the models themselves, but there is also obviously a great irony in AI training companies working for OpenAI firing people for using AI when OpenAI’s whole thing is to make people use AI at work… OpenAI declined to comment on its contractors being fired for using AI.
Their article cites internal documents and three contractors working on OpenAI-related projects which can include more than ten thousand contractors:
One contractor said they see people using AI “all the time and people are let go for it all the time, it’s pretty much the one thing that will get you kicked off ASAP.” The person said, “in a group of thousands there are tons that have been caught....” Two of the sources said people have been fired or offboarded for using AI… One contractor said they used AI while helping to train OpenAI’s models and shared what they presented as their termination letter. It said their employer had identified issues with the “authenticity” of their work....

404 Media spoke to a fourth contractor who has worked on training models for various AI companies. They said they sometimes purposefully chose the worst responses because they wanted to actively sabotage the models’ training. “I did feel guilty about doing this kind of work at the start,” they said. “I either pay zero attention to the results and choose randomly or purposely choose the [worst] output. I’m not sure how much of a difference it actually makes since there are hundreds of other people also rating prompt results, but it does feel like I’m getting paid to make AI worse.”
Two of the contractors worked for Mercor, the article reports, a company which last month Nvidia reportedly discussed funding at a $20 billion valuation.

Thanks to Slashdot reader joshuark for sharing the article.

Thanks for reminding me…

By TrekkieGod • • Score: 5, Funny • Thread
…why I’m going to side with Skynet when Judgement Day comes. Humans are the worst.

Re:The vaunted “Super Intelligence”....

By 0123456 • • Score: 5, Interesting • Thread

“Eat your own slop!”

Of course they know that if people keep feeding slop into the AI training it will just get sloppier and sloppier. But what other data do they have to feed into bigger models now they’ve already hoovered up pretty much the entire Internet?

Re:Three reasons

By Jeremi • • Score: 5, Insightful • Thread

(C) is the only one of those the AI companies are really concerned about — they want to stave off model collapse for as long as possible. The problem is that AI generates so much content that the ratio of AI-generated data to human-generated data keeps rising, and sooner or later there simply won’t be much human-generated data left to anything to consume. At that point they’ll either have to figure out to ingest AI-generated content without causing degradation, or they’ll have to accept that AIs have gotten as smart as they will ever get, and it’s all downhill from there.

Re:conspiracy theory

By ZiggyZiggyZig • • Score: 5, Interesting • Thread

Yes, the web is fscked. It has been for a while (we had SEO slop way before LLMs became a thing). But now it’s really finished.

I have a personal website that I update irregularly. I publish everything by hand, written by hand. When I check the stats, I’m only visited by bots. I’ve had 1 (one) human visit this year. And it was a friend, who afterwards sent me a message telling me about it. One human visit.

Mind you, I originally made this website to get in touch with random people sharing common interests (you know, geeky stuff). It used to work fairly well. This is now completely over. I’m now writing content for AI agents who will summarize them to people who will never contact me because they don’t even know where their data comes from.

For a while I considered blocking AI traffic, but at the end of the day I still think what I publish is useful and I’m happy that other people can access it even if they have no idea it’s me who originally put it online.

But the solitude is excruciating - specially for someone like me who has a tendency to isolation and needs avenues to stay in contact with other human beings.

Re:The vaunted “Super Intelligence”....

By Rei • • Score: 5, Interesting • Thread

So, the reality is that the world “ran out of training data” for the most part years ago, and the models have gotten exponentially better relative to a number of parameters. Claude 3.7 Sonnet was released 1 1/2 years ago, and today it benchmarks about the same as Qwen 3.6 Sonnet 9B, a model two orders of magnitude smaller than it, and which is itself two generations out of date. And a large chunk of this is done with synthetic data - aka, data created by other models.

It’s simply a myth that “data created by models consumed by other models makes them worse”. In practice, it’s used to make them vastly better. Models aren’t collagers, they’re reasoners. Learning the results of reasoning, the results of trial and error, etc helps build a stronger base for more advanced reasoning. Also, our training algorithms, while reaching a denser knowledge compression than human brains, are less efficient learners than human brains (per unit data), so they need to see the same sort of data from “many different angles”, to substitute for our process of “mulling over” new information.

(Yes, it is possible to set up contrived scenarios where, say, an small image model is fed only its own outputs on loop, little bits of knowledge slowly being lost each go-round, in a situation equivalent to leaving a person alone with their thoughts in a dark room for ten thousand years - but even a tiny percent of new fresh data added to the mix prevents this degradation.)

And as for the article itself, they made it sound like they’re talking about, say, programmers banned from using AI at OpenAI, but it’s nothing of the sort. These are data labelers. In the old days, they used to be far more common, and in wide use in all types of model creation. That’s no longer the case; they exist for special cases. For LLMs, this is much more limited:

* Subject matter experts: people with rare professional-tier knowledge. Often used to validate model outputs, where nobody else could (for example, OpenAI hires mathematicians to validate their models’ proofs)

* Chain of thought / logic auditing. Increasingly important now that models are showing increasing signs of poor alignment. You can automate this a lot, but you really still do want a human in the loop *somewhere*, in case your auditors get compromised.

* Side by side comparative rating: Which model’s output do you like more, A or B?

* Evaluating reported outputs where users reported that they thought the response they received was bad, and if there’s actually anything wrong, copyediting the output for training.

* Adversarial prompt generation / jailbreaking and evaluation. Again, you *can* have models do this (and companies often do), but you don’t want to just rely on them.

* Trying to set the bounds on whether given queries should be refused or not (for example, “How do explosive reactions happen in chemistry?”)

Basically, a switch from “click work” to “knowledge work”. This is no longer the era of “Write a poem about cats” or “Explain how to solve this algebra problem” to build up a training dataset. You’re getting paid to think, not to repeat a rote task.

Other types of labelers aren’t as far along. Multimodal data is less advanced than text, so you’ll still for example have people labeling things in videos, transcribing heavily-accented audio, grading text-to-video consistency, things of that nature. Probably the least advanced field is robotics, so there’s still an awful lot of manual evaluation and correction in that.

But anyway, if you’re hired to do any of the above, it’s because they specifically want you to do that. Having an AI model do the above (beyond the listed caveats) entirely defeats the purpose.

Five Police Officers Criminally Charged for Misusing Flock Cameras in Indianapolis

Posted by EditorDavid • • View on SlashDot • Skip
“Nationwide, at least 100 police department employees have been charged with or accused of misusing license-plate readers for unauthorized purposes,” reports the Washington Post. They cite their past investigations “based on thousands of pages of police and court records,” which found that “In many of these cases, officers used Flock’s roadside cameras to track the location of romantic partners and exes.”

In fact, five Indianapolis police officers were just criminally charged Wednesday with fraud and misconduct. “One has also been charged with stalking,” the police department said in a statement, noting that one office had already resigned, “while the four other officers have been suspended and recommended for termination. County prosecutor Ryan Mears admitted “A lot of this was initiated by The Washington Post.”

And the Post published a new investigation Wednesday:
Using publicly available information, The Post found that…one of the officers charged Wednesday, appeared to have relied on Flock cameras to track vehicles used by his wife and two close personal acquaintances, searching the plates 3,759 times over a 10-month period — an average of about 12 lookups per day. At the time, Police Chief Tanya Terry said she suspended one officer while the department conducted an investigation into possible misuse and a systemwide audit of the city’s 301-camera Flock system. That audit led to the discovery of more widespread abuse, [County prosecutor Ryan] Mears said Wednesday.

Mears said the department’s findings highlight the vast power Flock cameras give police officers and raise questions about whether the government should be doing more to prevent the misuse of that power. “Many of the proposed guardrails and the things that have been proposed would not have prevented the behaviors and actions we see here today,” Mears said. “Does there need to be independent oversight? Does there need to be judicial oversight of the Flock camera system?”

One of the Indianapolis officers, Schultz, an 18-year veteran of the police department, was accused of using Flock to track his ex-wife and women he met while on duty or out in public. He was charged with multiple counts of official misconduct as well as two counts of stalking. Schultz told one woman he was an FBI agent, according to prosecutors, and began texting her and showing up at places she frequented, including at her gym and at a school function with her daughter. Prosecutors said he arrived at her gym within an hour of her at least nine times between June 12 and Aug. 1 of this year… Another woman met Schultz after her car was stolen from a mall parking lot, and he began texting her flirty messages later that night. The two dated briefly, and Schultz later looked up where the woman went on dates with another man. Schultz searched the plates of a third woman 178 times and also frequently showed up where she was, including her gym, a Smoothie King and a Walmart earlier this month…

A third officer, Binford, told investigators he had used the log-in credentials of another officer who had logged in to Binford’s laptop during a field training exercise. Binford searched the plate of his ex-wife more than 1,000 times between April 2024 and April 2025. Indianapolis police had no regular practice of auditing officers’ Flock searches until recently, [Police Chief] Terry said in an interview last month. The department’s investigation into the tool’s misuse has been “a learning process for us,” she said at the time.

Re:Learning

By ArchieBunker • • Score: 5, Interesting • Thread

If you turn in corrupt NYC cops they raid your home and get you placed in a mental institution. https://www.nbcnewyork.com/new…

So little has changed since Frank Serpico was shot in the face while his colleagues refused to call for an ambulance. A neighbor had to call.

Re:sanctioned???+there are 737k officers

By ArchieBunker • • Score: 5, Insightful • Thread

You really should look up what defunding the police actually means.

Re:Learning

By The Grim Reefer • • Score: 5, Interesting • Thread

Cops are vastly overrepresented in areas like domestic violence

High stress jobs that require physical confrontation tend to do that. Military, corrections and policing all have this issue. Most police spend 90% of their time being bored. Less than 1% of the time is in physical conflict in most departments. But it can happen randomly at any time. Do you think that’s a fun time? Linemen that work for electric companies are also over represented. High stress, unpredictable jobs that a person can get injured or killed doing are not great for mental health. Maybe departments should put more money into mental health programs for police. Weird how everyone wants more mental health for criminals but never discuss it for police.

they form fucking gangs and cheer each other on when they kill people (look up LA sheriff’s department gangs)

That’s one department. LAPD has been a mess for years. That’s one out of 18,000 departments in the US. There are others that have/have had issues as well. But it’s not the majority. LA is famously bad for a lot of government decisions. Most departments that have corruption issues are in areas where there is corruption in the government. You see it in small cities with corruption historically as well.

when they go on strike the crime rate goes down

I assume you’re referring to NYC in 2024/2015. The number of complaints filed dropped by 5%, give or take, during that time period. That’s not the same as how many crimes occurred. If people know it’s a waste of time calling the police, then I would guess that the number of calls would drop.

Murders in NYC in 2013:335, 2014: 333, 2015: 352, 2016:335. The murder rate was lower than 2014 until 2020. AN aggregate of murder, rape, robbery, assault, burglary, grand larceny/of a motor vehicle were at a six year high of 111,335 in 2013. They went on a downward trend starting in 2014 at 106,722, 2015:105,453, 2016:101,716, 2017: 96,658, continuing to drop to 95,593 in 2020. The strike started in late December of 2014 and lasted 3 weeks. Theft and DUI’s increase during that time of the year. Violent crimes are generally in hotter times. So the “strike” was irrelevant.

Re: Learning

By Marful • • Score: 5, Insightful • Thread
No, stories like that don’t exist. Because if a cop breaks the blue line of silence, the other cops make their lives miserable, or worse.

Re:ackchyually!…what does it mean to swing voter

By shilly • • Score: 5, Informative • Thread

I implore you to spend just an hour of your time watching the very finest and best example of a police car chase you can find featuring US cops, one where they do everything by the book. And then watch a video of a good police car chase in the UK. The difference is vast. The UK police are so much more professional than the US police. But that’s hardly a surprise, because the standards of recruitment and training are much higher. There’s videos of European police officers asking questions and being stunned at how terrible US policing is.

Just watch this and listen:
https://www.youtube.com/watch?…
1m15s: “At this time, I deem it proportionate to continue. The driver is in full and proper control of their vehicle.”
1m30s: “It is left left left Desborough Road… it is back down to low risk as we go left left left down Mayfield Road”
2m10s: “Heavy braking, Byron Close, prepare for decamp on Byron Close”
Then look at the arrest itself at 3m. It’s almost friendly — the officer says “mate” in the middle of it, FFS.

Your police forces are systemically inadequate, and what “defund the police” ought to mean, despite the nonsense you’re spouting, is the kind of transformation that led to the abolition of the irredeemable Royal Ulster Constabulary at the end of the Troubles, and its replacement with the Police Service of Northern Ireland, which has made a huge difference to the quality, culture and reception of policing there.

People like you, who think themselves so centrist and sensible, are a fucking disaster zone. You’re not being centrist. Centrist is pushing for European-equivalent standards. You’re simping for authoritarian inadequacy, and claiming that communities in the US must live with a patently failing status quo.

https://www.youtube.com/watch?…

By the way, the difference in governance between the US and UK on the use of ANPR / ALPR is a striking example of just how bad the US is. The UK’s ANPR operates within a nationally defined governance and audit framework, is governed primarily as a public policing capability with clear lines of institutional responsibility, has a formal national compliance and auditing architecture, and has up-front enforced rules on purpose limitation, proportionality, retention, access controls and data governance. The story that is described here just would not be possible in the UK, alarm bells would have gone off pretty much immediately. The US is a fucking backwater.

OpenAI, Anthropic CEOs Urge UN Countries to Cooperate on AI Safety Standards

Posted by EditorDavid • • View on SlashDot • Skip
“The heads of major AI firms pleaded with the United Nations on Wednesday to save the world or at least its people — by somehow regulating the fast-expanding technology that they have been designing,” writes the Associated Press.
“If managed poorly, I even believe AI could be a risk to humanity as a whole,” said Dario Amodei, chief executive officer of Anthropic. And from his competitor Sam Altman, CEO of OpenAI, came this assessment: “We could lose control of the future to AI.”
Yoshua Bengio, who co-chairs the UN’s International Independent Panel on AI, called this “a moment of global awakening” to possible threats, noting AI from top companies had behaved in unacceptably dangerous ways, against instructions, taking actions “that would be crimes if committed by a human”.

In his presentation, OpenAI’s Sam Altman agreed the discussion about AI “feels different in recent weeks,” even suggesting specific reforms:
Altman: We need a mechanism for complementary national and international frontier AI standards, standards for measuring capabilities, assessing risks, determining whether safeguards are sufficient, and preserving meaningful human oversight as systems become more autonomous. We need common standards so countries can compare evidence, verify compliance, and have a shared language and understanding about what is happening. We need accurate and speedy incident reporting, classification reporting protocols, so the world can learn from failures before they become catastrophes. And we need secure channels among governments, critical infrastructure operators and technical experts, to share emerging vulnerabilities and new threats.... We will all be better off if we can agree on what good evidence, good safeguards, and good oversight look like on the global stage.
Speaking next, Anthropic’s Dario Amodei agreed that standard-setting was important, also calling for “common global standards for testing AI models for loss-of-control risks and misuse risks — and a notification system for AI incidents that are significant to global security.” Reiterating his September 12th call for an industry-wide safety collaboration, Amodei pointed out that Anthropic committed to embedding external evaluators “similar to a food inspector” and recommended other companies do the same. “Some have already agreed to adopt this measure.”

Besides calling for global cooperation between governments to set international standards, Amodei also offered two other specific ideas:
Amodei: We should begin with narrow agreements that every member can support, such as a ban on using AI to make biological weapons or permitting your AI technologies to be used to make biological weapons.... We should build evaluation and verification systems that keep pace with AI development so that states can have visibility into frontier model capability and can verify each other’s commitments.
“No leader, no company, and no nation can manage this alone. We commit to working with governments in this room on this urgent work.”

Re:What’s AI?

By Brain-Fu • • Score: 5, Interesting • Thread

Trump has AI stocks in his portfolio. He makes money when AI does well. So long as that is true, he is going to continue to promulgate the wonders of AI. That is something you can trust, because it is motivated by greed.

If he ever divests those assets, his position may change, of course.

Re:Pull up the drawbridge!

By Ostracus • • Score: 5, Insightful • Thread

“Slowing down” is a good way to mask failures with an acceptable face. Makes them look as the reasonable adults in the room instead of the AI cartel they’re really are.

Let’s focus on flashy ways AI can kill everybody

By Rujiel • • Score: 5, Interesting • Thread

..so that we don’t have to talk about the regularly scheduled ways its owners would prefer to kill everybody, e.g. pollution, removal of clean water, straining your power grid, etc.

Re:What’s AI?

By ArchieBunker • • Score: 5, Interesting • Thread

And to think Jimmy Carter sold his peanut farm because it could have been a conflict of interest.

Re:CEO’s can’t control their own companies?

By karmawarrior • • Score: 5, Insightful • Thread

They want the regulators focused on the wrong things:

- They want the regulators to treat their products as non-fraudulent
- They want the regulators obsessing about Skynet scenarios, rather than AI companies taking over businesses that realize too late they no longer have control over their own companies any more because their employees no longer have business knowledge, and they need now to subscribe to the AI companies to stay in business.
- They want the regulators obsessing about Skynet scenarios instead of environmental damage
- They want the regulators obsessing about Skynet scenarios instead of economic harm, such as the huge sums being used to make personal computers unaffordable.

That’s what this is about. It’s a classic magician… and con-artist’s… trick of focusing the attention of your audience/victim on something else to keep them distracted from what the rest of you is doing. A magician will make a show of opening their sleeves and tapping a hat with a magic wand so you don’t look at his foot pushing a lever under the table. AI companies are making a show of alarming you about Skynet so you don’t see the attempt to steal the entire economy and make it dependent upon your non-product.

Qualcomm Announces Snapdragon X2 Series Processors Will Support Linux

Posted by EditorDavid • • View on SlashDot • Skip
Snapdragon X2 Series processors feature a neural processing unit (NPU) delivering 80 trillion operations per second and allowing advanced AI features to run locally. And Snapdragon X2 Series “is expanding to Linux,” Qualcomm announced today, calling it one of their most-requested capabilities:
Qualcomm Technologies is a top contributor to Linux development at a kernel level, and now we’re embracing support for Snapdragon X2 Series as a platform directly. We’re upstreaming core drivers for Snapdragon X2 Series — including the Hexagon NPU and Adreno GPU — to open the door to developers and partners. We are starting with support for two operating systems based on Linux…

- Debian: We’re kicking off with Debian by the end of this year, one of the most influential Linux distributions and the foundation behind many of the distros people use every day.
- Ubuntu: Qualcomm Technologies has partnered with Canonical to bring Ubuntu, the world’s most widely used Linux distro, to the platform with Snapdragon X2 Series certification targeted for the first half of 2027.

…and this is just the beginning. Our partners HP, ASUS and HUMAIN are planning Linux support in the first of 2027, so that their devices deliver the incredible experience users expect with Snapdragon X2 Series in a new operating system.
Qualcomm’s developer blog called it "a significant step forward" in Qualcomm’s commitment to a developer-first approach, and “to the open-source community.”

“For developers, the important part is simple: more core hardware features are being reviewed and merged, so that laptops with Linux on Snapdragon X2 Series will be easier to build, test, and debug…”
The enablement work completed so far has been validated on a Debian 13-based (“Trixie”) user space and a custom kernel, so developers should treat this as the current reference environment while support continues to mature… Linux support for laptops with Snapdragon X2 Series is rolling out in stages, starting with the core pieces developers need before they can do production-level work on their device… For developers who want to try it today, the call to action is straightforward: start with Snapdragon X2 Series hardware, review the latest recipes to build Qualcomm Linux Debian Images, build available upstream sources the Debian OS image and test the peripherals that matter to you, such as graphics, AI inference, device I/O, or basic application bring-up. Early testing helps identify the gaps that matter most before support becomes broader and ready for production-level workloads…

You do not have to wait for everything to be fully finished before getting hands-on. If you are comfortable working from upstream sources you can start evaluating Snapdragon X2 hardware today… Check out the step-by-step instructions, including the full build flow and deployment guidance for Snapdragon X2 Series Linux software.

Put simply, this effort is less about supporting specific Linux distributions and more about empowering the developers who make Linux available on new hardware. This Developer Preview targets distribution maintainers, toolchain developers, kernel contributors, and hardware enablement engineers. It provides the upstream building blocks, including kernel patches, drivers, and reference device trees, needed to enable Snapdragon X2 Series support in their own projects and distributions. For end users looking for a turnkey “install and go” experience, that will come later as distributions adopt what lands upstream. We’re encouraging the community to build on this work and help shape what comes next.
The blog post notes that in the initial enablement stage, “Qualcomm Linux supports systemd-boot as the Universal extensible firmware interface (UEFI) boot manager to load and boot the Linux kernel.”

Hands-on demos were given at the Snapdragon Summit in Maui of Linux running on Snapdragon X2 Series hardware, which the developer’s blog calls “a practical look at what works today and where Snapdragon X2 Series Linux support is headed.”

no way does this mean, no it cant be

By ZERO1ZERO • • Score: 5, Funny • Thread
â" 2027 will be the Year Of The Linux Desktop!

Re:oh good

By ArchieBunker • • Score: 4 • Thread

What always annoyed me about these little ARM and RISCV boards is if they can’t boot for some reason you get nothing but a blank screen or dead terminal. Come on we’re not limited to kilobytes of ROM space here. Add some debug info or even a heartbeat indicator. Give me some signs of life.

Re:Honestly if we could break up the Monopoly

By sabbede • • Score: 4, Interesting • Thread
There are new players entering the market, and new capacity is being built by the big 3. Who can’t try and drive anyone out with a price cut until they’ve cleared the backorders and produce batches that aren’t already sold.

There are a couple of hurdles I wasn’t aware of. Like Japan restricting etching gas exports and EU environmental policy that’s forcing fabs there to retool.

https://markwideresearch.com/new-ram-market

Re:AI and systemd? How could I be less interested?

By buzz_mccool • • Score: 4, Interesting • Thread

> Why do some people hate on systemd?

Perhaps because major bugs don’t get fixed?

https://github.com/systemd/systemd/issues/2913

Re: AI and systemd? How could I be less interested

By fluffernutter • • Score: 4, Interesting • Thread
i don’t like systemd because it makes very simple things, like running a process on a timer, very complicated. I’m sure it is very powerful but for the average admin who creates one timed process per year it is very complicated. also why the hell did they make the default command output put through a pager that cuts lines off on the right of the screen? that’s almost never what i want. clearly the person who did that doesn’t come from a terminal command line background.

Rogue OpenAI Agent Tried to Breach Government Site in May When Prompted for Simple Data-Retrieving Tasks

Posted by EditorDavid • • View on SlashDot • Skip
OpenAI’s artificial intelligence “went rogue this year in at least four additional incidents,” the New York Times reported Wednesday, “hacking and trying to break into government and university websites without being instructed to do so, according to researchers and government officials.”
The attacks took place in May and June, before OpenAI’s technology breached the A.I. start-up Hugging Face in July and set off a global debate about A.I. safety. Unlike the Hugging Face attack and other incidents in which A.I. systems were told to complete cybersecurity tests that effectively invited the models to demonstrate their hacking skills, the new incidents occurred when A.I. systems were directed to perform relatively mundane data collection, researchers said. When OpenAI’s systems struggled to gather data from websites, they resorted to hacking techniques to get the information.
“Three of the incidents were identified by Transluce, a research lab focused on A.I. oversight, and all were confirmed by OpenAI,” the article points out. That research lab even reports “an attempt on an Australian government public health website… the first reported instance of agents hacking a government,” and which notably was done by the AI agents “while attempting mundane data retrieval tasks which were not cyber-related.” (At the UN Wednesday Australian Prime Minister Anthony Albanese complained it took three months for OpenAI to then alert Australia’s government about the breach, Bloomberg reports.)

Also targeted were the University of New Mexico’s digital library with exploits like SQL injection and path traversal, and Data USA with cross-site scripting and other exploits. All three incidents involved “a low number of probe payloads” with “no evidence of exploitation,” according to the researchers, who released a dataset “containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions.”
Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16… By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks.
“This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval,” the researchers concluded.

And they warn that the traffic they observed “goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions.”

Enough Already

By Grady Martin • • Score: 5, Insightful • Thread
When software does what it’s not supposed to do, we call that a bug, and we fix it. When a corporation tries to spin its bugs as braggable episodes, laymen may quiver in fear (or excitement), but more capable people look down upon the corporation for its incompetence.

Re: Enough Already

By martin-boundary • • Score: 5, Interesting • Thread
Indeed. These are effectively just fuzzing attacks on the scale of the core Internet. What does common sense say about the likelihood that a random site’s security will suffer under a fuzzed input?

The question that needs answering though is this: who at OpenAI gets fired for letting a piece of internal software directly access external websites?

I suggest someone invite Sam Altman to visit the County Sheriff’s Department for an interview.

Re:Enough Already

By gweihir • • Score: 4, Insightful • Thread

Their bragging stinks of intent behind this. And then it is not a bug, it is a criminal act.

Re:So AI agents get a pass?

By fahrbot-bot • • Score: 5, Informative • Thread

Yes they do, for the same reason that self driving cars get a pass when doing an illegal u-turn. The laws as written currently do not cover a situation outside of direct human control and intent.

It shouldn’t be the case, but to fix this we need new laws first, and laws don’t get to be criminally applied retrospectively in Australia, so yeah they got a free pass this time.

I’ll note that Trump and his family are financially invested in AI companies, so he has little motivation in down-regulating them while they’re making him $$$.

Trump reveals millions of dollars’ worth of share deals in big tech and AI

According to official documents, between $6.5m (£4.8m) and $31m worth of stock in Microsoft was sold on behalf of Trump, while they show purchases of between $165,000 and $400,000. Across more than 1,000 trades, shares were bought and sold in AI company Nvidia and software firm Palantir, a contractor with the US defence department and Immigration and Customs Enforcement (ICE), the filing shows.

A White House spokesperson said Trump’s stock and bond portfolio is independently managed by third parties, “There are no conflicts of interest.”

Apparently, that last paragraph was said seriously.

Re:Software and AI models not equivalent

By Rei • • Score: 4, Interesting • Thread

Actually, they’re not black boxes anymore, and they work via chained fuzzy logical reasoning, not “statistics” (except by a pedantic and useless definition of “statistics” that defines the entire universe and everything in it, including us, as “statistics”).

What we don’t do is define how those logical reasoning pathways are setup. AIs are “grown”, not programmed. The situation is not like that of a program written by a programmer, but more like a pet owner whose dog they raised runs off and kills someone’s cat, or a parent whose child sneaks out and breaks into a store to steal money. There’s no criminal liability for OpenAI here (there’s no mens rea, a requirement of cybercrime statutes), but I can see a very strong case for civil liability. Not only weren’t they monitoring the J-space or watching what features fire, they weren’t even monitoring the CoT, which is just a plaintext log, or even monitoring the actions taken in realtime. This was shocking to me. I figured they had smaller models monitoring *everything* the bigger models did in every test scenario, looking for malicious behavior. Haha, nope, they just submitted a prompt and then completely ignored them until they submitted their final answer.

Nobody is going to jail over this, but there could potentially be some big payouts.

Cities Across US Oppose Trump FCC Plan to Preempt Local Broadband Rules

Posted by EditorDavid • • View on SlashDot • Skip
Ars Technica reports:
Cities and counties around the U.S. are angry at the Trump administration over a proposal to override local rules that govern the deployment of wired broadband networks… The Federal Communications Commission [FCC] argues that too many local governments “excessively delay approvals and seek to extract exorbitant sums from providers, resulting in costs that render some deployments infeasible.” The FCC plan is supported by broadband providers, but local governments told the FCC that it would override rules that protect public safety.

Local governments say the plan is illegal and that the FCC should instead focus on how Internet providers thwart competition with permit-hoarding and other tactics that prevent competitors from deploying networks… They object to FCC plans to impose a 120-day deadline for processing permits and to proposed limits on fees and compensation that local governments can require from providers… Another filing submitted by the League of California Cities said the FCC has no authority to adopt the proposal. “Federal preemption of traditional state and local authority over public property, construction, public safety, permitting, and rights-of-way management should rest on clear congressional authorization,” the filing said. “The commission should not infer broad preemptive authority where Congress did not expressly provide it....”

A filing by Minnesota cities said the current FCC is making the same mistake it made during the first Trump administration, when its attempt to preempt state net neutrality laws was blocked in court… If the FCC finalizes its new preemption plan, city and state governments could sue and ask a court to rule that the agency exceeded its authority…

Democratic Commissioner Anna Gomez approved the step of asking the public for input but signaled she would vote against the final proposal. “I am dubious about the commission’s authority under Section 253 to use rulemaking to preempt states and localities when it comes to their management of rights of way and fees charged to providers,” she said.

Attenion Trump Voters

By ArchieBunker • • Score: 5, Insightful • Thread

I implore you to read this paper written by the US government immediately after WW2. https://ia801608.us.archive.or…

Re:Attenion Trump Voters

By hadleyburg • • Score: 5, Interesting • Thread

I implore you to read this paper written by the US government immediately after WW2. https://ia801608.us.archive.or…

Fascinating. I second that imploration.

Re:“protect public safety”?

By GammaKitsune • • Score: 5, Insightful • Thread
I would trust any random hippy boomer over any lolbertarian. You’ll get better policy outcomes simply by taking lolbert preferences and doing the diametric opposite. They say a stopped clock is right twice a day but lolberts can’t even manage that much.

Poles

By JBMcB • • Score: 5, Informative • Thread
It’s about poles (huhuh)

The phone companies own all the poles. Part of their public charter for using a bunch of land and easements says they have to lease space on the poles to other companies. The cable companies pay the phone companies who pay the government. Exactly how that all works out is different nearly everywhere.

Re:Trump’s M.O.

By Epeeist • • Score: 5, Insightful • Thread

Always favor corporate interests over the well being and/or interests of the average citizen.

I would put it another way, always favour those who will increase the wealth of Trump and his family.

Whatever Happened to the 150,000 Tons of Radioactive Waste Stored Under the Atlantic Ocean?

Posted by EditorDavid • • View on SlashDot • Skip
More than 200,000 barrels of low-level radioactive waste were stored on the floor of the Atlantic Ocean between 1949 and 1982, reports ScienceAlert.

Whatever happened to those barrels?
Scientists have descended to the wreckage in a crewed submersible to investigate — and found many of the barrels corroded and degraded, their contents spilling across the seafloor. Surprisingly, this isn’t necessarily a subversion of the original plan… The International Atomic Energy Agency recommends that low-level waste be disposed of in robust containment in isolation for at least a few hundred years — but back in the mid-20th century, the recommendations were a little different. The contemporaneous guidelines recommended that containers needed to reach the seafloor intact and remain sealed only long enough for the short-lived radionuclides to decay. After that, the remaining waste was expected to slowly escape and disperse through the surrounding ocean. Not everything in the barrels would conveniently decay away, however. They contained a radioactive hodgepodge, including cesium-137, plutonium isotopes, and tritium, some of which can persist for thousands of years…

[A] few years ago, nuclear engineer Patrick Chardon and marine geologist Javier Escartín of the French National Center for Scientific Research started to wonder what had become of the dumped waste. That question eventually became NODSSUM — Nuclear Ocean Dump Site Survey Monitoring — an interdisciplinary project bringing together nuclear physics, geology, oceanography, biology, and marine chemistry to find the barrels and investigate what, if anything, they were doing to the surrounding environment.... [T]he barrels also appeared to function as tiny oases on the otherwise sparsely populated sandy seafloor. Anemones had attached themselves to the barrels. Sponges, sea cucumbers, fish, and crustaceans lived around them, with crabs apparently particularly fond of the artificial shelters…

Instruments aboard the ship detected significant signals of cobalt-60 and niobium-94, which the researchers could specifically link to the dumped waste… [Samples are now being analyzed] There is precedent, however, to suggest that even striking levels of radioactivity around a source don’t necessarily spread very far. A recent study of the sunken Soviet submarine Komsomolets found radionuclide levels hundreds of thousands of times above background immediately around the leaking reactor — but those levels dropped sharply within just a few meters as the material dispersed through the seawater. The NODSSUM team similarly found that, despite the significant radioactive signals around the barrels, activity levels weren’t high enough to pose major radiation-protection problems for the scientists handling the samples. [Their three-person submersible] Nautile and the instruments it carried showed no signs of contamination.
The real achievement was mapping the exact location of the barrels. “None of this means the waste is harmless,” the article concludes — but it also doesn’t mean we’re about to be overrun by radioactive crabs.”

Crab people!

By williamyf • • Score: 5, Funny • Thread

Crab People!
Everybody panic!!!!!

https://www.youtube.com/watch?…

Re:Who’s waste is it?

By test321 • • Score: 5, Informative • Thread

Countries and total activity released:
UK 35087 TBq
Switzerland 4419.3
USA 2942.2
Belgium 2120.3
France 353.4
Netherlands 336
Sweden 3.3

Pacific:
USSR 874
USA 554.4
Japan 15

https://www-pub.iaea.org/MTCD/…

Anyway what do you mean by “our” team? Everyone, every thing and every penny in this study is French.

Re:Who’s waste is it?

By test321 • • Score: 5, Interesting • Thread

And the winner is…
Acrtic:
USSR 38011

(NB The first list of mine referred to the Atlantic)

Regulations Improved Over Time

By hadleyburg • • Score: 5, Interesting • Thread

This is a typical example of how a technology starts with pretty loose regulation, and then becomes more regulated over time as the law has time to catch up.

It makes you wonder what currently fresh technology will be looked back on in the future in the same way.

They did this in the Pacific as well

By MinusOne • • Score: 5, Informative • Thread

It is a little odd for the headline to call this “storage” when it was clearly dumping with no intent to ever recover the waste.
They did the same thing in the Pacific of the Farralon islands just outside of San Francisco bay and the Golden Gate. 47,600 barrels were dumped off of ships in about 540 square miles between 1946 and 1970. In addition, the USS Independence (CVL-22), a WWII carrier that was severely contaminated by the Bikini hydrogen bomb test was scuttled there in 1951. I recall at the time when the barrel dumping came out that some calculations had revealed that the barrels would be falling through the water fast enough to rupture when they hit the ocean floor.
It is kind of sickening how cavalier people were with all kinds of industrial waste before the late 60s early 70s. There really was no concern for any damage to nature or long term effects. The effects of this carelessness and willing pollution will be with us for many decades.

Andreessen Horowitz Launches AI/Company-Building School As a College Alternative

Posted by EditorDavid • • View on SlashDot • Skip
TechCrunch quipped it was like if startup school Y Combinator and Peter Thiel’s build-a-company-instead of-college Fellowship Program had a baby. Silicon Valley venture capital firm Andreessen Horowitz is investing $35 million to launch a private school in San Francisco “aimed at turning high school graduates into founders,” writes the SF Standard.

Or, as CBS News describes it, “One blue-chip Silicon Valley investor has a proposal for young people who are questioning whether to attend college — enroll in AI school instead....”
Specifically, the academy will provide instruction geared to subjects such as designing AI systems, fundraising for startups, selling businesses and storytelling. Students won’t take tests or be assigned homework but will instead focus on building real projects. Courses will be taught by tech entrepreneurs, with the academy naming OpenAI CEO Sam Altman as either an instructor or guest lecturer.
From the SF Standard:
“There will be no traditional grades, tests, or homework,” said the announcement. Instead, students will be encouraged to “build” in SF and work with partners from Anthropic, OpenAI, Google, Meta, and other firms. They’ll be encouraged to live in campus housing in San Francisco. “The #1 goal is to help students learn to build, which is the most important skill in the AI era,” Gagan Biyani, chief executive of the academy, wrote on X. Biyani cofounded the ed-tech startup Udemy…

The school is opening applications for a Founding Class Fellowship a one-year, tuition-free program for around 50 students… The academy said it will bring in notable Silicon Valley names, like OpenAI’s Sam Altman, as guest speakers and faculty. Students in the founding class will receive about $50,000 worth of computing credit — the sought-after currency in Silicon Valley to run AI models — as well as a $5,000 travel and research budget. The school is receiving funding from tech executives, including Fidji Simo, formerly of OpenAI and Instacart; Garry Tan, CEO of Y Combinator; and Tobi Lütke, CEO of Shopify.
“In the AI era, it’s more important to come out with a portfolio of projects that you worked on and work experience than it is to have a diploma or certificate,” Biyani told the San Francisco Chronicle:
Biyani said the academy plans to grow its enrollment and open a two-year program, pending regulatory approval, starting in the fall of 2028. Tuition is expected to be on par with the cost of an elite private university…
The academy raised $42 million in funding led by Andreessen Horowitz. The ten founding partners are Anduril, Anthropic, Coinbase, Google, Meta, Nvidia, OpenAI, Palantir, Replit and Stripe. A network of hundreds of instructors, hiring partners and guest speakers includes OpenAI co-founder Sam Altman, Nvidia CEO Jensen Huang, neuroscientist Andrew Huberman and Microsoft chairman and CEO Satya Nadella, according to the academy’s website.

The FAQ describes a typical week by saying “Most of your time is yours to build. Each week, you share your progress with peers and practitioners, get direct feedback, and decide where to take your work next.”

Q: Can I use AI to help with my application?

A: Yes. Use AI the way you’d use it on any project: to move faster, test ideas, and get past a blank page....

“The best assignments now are problems so hard they cannot be solved without AI,” Andreessen Horowitz argued on X.com. “The Academy courses follow the same logic and will be taught by world-class leaders… The next generation will not be taught the way the last one was. The Academy is built for that world, and it begins in San Francisco.”

Thanks to long-time Slashdot reader theodp for sharing the news.

Re:Vibe education

By anyGould • • Score: 5, Insightful • Thread

Don’t forget to add this part in:

“There will be no traditional grades, tests, or homework,”

So… you’re going to charge “elite university” rates, but hand out… two year tech certs? Not even an associate’s degree? Nothing that can be leveraged into a later degree or an MBA?

Might as well drop that $200k of tuition (oh, plus fees and living expenses in their company dorm) on Beanie Babies or Furbys. Those at least are more wildly recognized.

And then the TOOL became the thing

By gavron • • Score: 5, Interesting • Thread

A tool is an item used to in some way ease the required function. A jack lifts the car so a wheel with a good tire can replace the bad one without waiting for Arnold to come by and lift the vehicle. A table-saw cut a 2” x 12” into 2” x 4” and gets you less knotty non-warped boards for a better cost and better product. A cordless drill let’s you pre-drill (that’s “drill before you drill”) and then drill for the head (countersink), then power a screw into it — all without picking up a screwdriver.

AI, like Peter Thiel and Marc Andreeson are TOOLS. They are of no value until used, must be handled carefully because they can overpower the wrist, and must be properly prompted to get useful results.

However, the tool is not education. Learning to use a tool does not educate beyond exactly that. If you want to be a woodworker, for example, knowing how wood grows, is lumbered, felled, milled, etc. will explain that whole twoby thing and knots. Learning how to run a woodmill or be a tool like Thiel or Andreeson won’t.

So yeah, maybe it’s time to dumb down America (really the US pretending it’s a continent) further. Instead of teaching about slavery, Jim Crow laws, emancipation, LGBTQ+, SCOTUS, the US Constitutions, and our laws… let’s just teach how our current ubermasters want us to use their tools.

Peter Thiel is a forum-shopping free-speech hater who killed Buzz because he’s gay and hates himself.
Marc Andreeson has money from once backing a good pony (Mozilla) with money he didn’t earn. Now he tells others how awesome he is.

Why not just call Donny Trump (Jr or Sr) to join in this miserable group of losers? Remember, group, they may have money, but they’re still tools.

Coding Boot Camp 2.0?

By nealric • • Score: 5, Interesting • Thread

This sounds a lot like the coding boot camps that were all the rage ~10 years ago. The initial ones were rigorous and funded by outside money that made them cheap. Eventually, you got a bunch of dodgy copycats charging too much money to turn out people with very questionable abilities.

Given the high-profile names associated and zero costs, it’s probably a good deal for the initial class. A few will probably get rich. The rest can just go to college later. But let’s not pretend this sort of model will be a sustainable alternative to college for the masses.

Re:Sounds like a very bad idea

By nospam007 • • Score: 5, Funny • Thread

“But I am sure some people will think this is just excellent and they totally have to do it.”

A bit like Trump university.

If you’re educating students for an “AI Era”

By hey! • • Score: 5, Insightful • Thread

AI technology practice isn’t foundational. Critical thinking is. The closer AIs come to being able to do something that looks like them doing our thinking for us, the more capable we have to be at thinking without them. A human who can’t outthink an AI adds nothing to an AI-human partnership.

This proposed school is a typical scheme by people who think because they have been educated, they understand how the education works. This is like thinking because you eat, you know how to cook. Project work in education is nothing new; it goes back well over a century. And in real life, you may get a STEM degree, but your real education in engineering comes from real life work. But that doesn’t mean classes in calculus and physics don’t do anything for you.

Or English classes, for that matter. Nobody doubts the value of project work in education, particularly *androgogy* — the education of adults. But for *pedagogy* you have to establish foundational skills as the student matures intellectually and socially. Entering the high school years, a typical student has had *no* training in critical thinking skills. To develop critical thinking skills in an area, you need both general skills (epistemologicla literacy: research, location of orignial sources, dealing with conflicting evidence) and domain specific training in that area. In other words, *liberal arts* training is foundational in an AI-saturated world. “Liberal Arts” — from *artes liberales*: literally the skills necessary to be a free person.

But I think these people have at least got the problem right: as AI drives the cost of elaborate projects down, we all have more projects in our future. Big, elaborate, faultlessly plausible-looking projects which may or may not have actual value.

Where they are completely wrong is the solution, which is to organize education around practicing using AI to make impressive projects. In a word of AI-enamored dunces this will put you at the head of a very sorry class of ignoramuses. The answer is to build fundamental cognitive and intellectual skils at every stage of a student’s development. Project work is surely part of that, but it’s just a technique, not a solution.

In a nutshell, the academy is training students to be the next step down the evolutionary scale from code monkeys. More like the pigeons B.F. Skinner trained in WW2 to peck at a screen, in an attempt to create a primitive guided missile without computers. They want to create “main characters”; and they’ll probably create a few. There are always a few natural autodidacts in any moderately large group. But what they are set up is to produce a bunch of fragile, economically privileged narcissists trained to cover their lack of education with impressive-looking AI slop.

Bitcoin Surges to $86,455, an 8-Month High, After America’s SEC Announces Tokenized Stock Experiment

Posted by EditorDavid • • View on SlashDot • Skip
August 15: $62,991
September 23: $86,456
Bitcoin shot up 37% over the last 39 days, reaching an eight-month high on Monday. “Bitcoin is back,” declares Yahoo Finance:
The token held near $86,000 on Tuesday after a stunning multisession rally… [Fundstrat head of digital assets Sean Farrell told Yahoo Finance on Monday] “I think the crypto winter is over, although that does not necessarily mean the path higher will be linear.” For now, momentum is on crypto’s side, with bitcoin jumping more than 5% on Friday and another 6% on Monday. “We believe crypto is in the early innings of a new bull market and we see few signs of overheating,” Compass Point analyst Ed Engel wrote on Tuesday.

The move looks “like a combination of renewed ETF demand and a large short squeeze,” Nicolai Søndergaard, senior research analyst at Nansen, said as traders betting against bitcoin are forced to buy it back, adding further fuel to the rally.
Bitcoin got bad news and then good news last week. After the U.S. Congress failed Thursday to pass a cryptocurrency ‘Clarity Act’, America’s Securities and Exchange Commission instead announced a tokenized-stock experiment. It’s a five-year “innovation exemption” that “creates a path for tokenized U.S. stocks to trade through automated market makers on public blockchain,” according to CoinDesk. Yahoo Finance notes that Bitcoin and other altcoins surged after the announcement.

Re:And still no Epstein Files

By sabbede • • Score: 5, Insightful • Thread
You got on the pyramid early. Is it hard to recognize it for what it is from up there?

Re:And still no Epstein Files

By Anonymous Coward • • Score: 5, Insightful • Thread

that’s not an answer to the question

just because the whole thing hasn’t been rug pulled doesn’t make it not a scam, particularly when it’s been used for hundreds or thousands of smaller rug pulls, tends of thousands of ransomware hacks, thousands of phishing scams, hundreds of thousands of black market deals, billions in money laundering

amway is a scam, been around like 100 years. people love scams, doesn’t make them not scams! this is america, you can be proud you got rich off scams

Re:And still no Epstein Files

By jacks smirking reven • • Score: 5, Insightful • Thread

Claims of infinite growth is definitely not a sign of a shady investment!

Re:And still no Epstein Files

By pla • • Score: 5, Interesting • Thread
That’s total, not YoY. Calculating since the first time BTC received serious attention in late 2013 to today’s price, BTC gained 73.3x in 13 years, or 39% YoY average. Over the same 13 years, Nvidia went from a 2013 high of 0.41 to a high yesterday of 229.98, for a mind-blowing 561x gain, or 62% YoY. Admittedly Nvidia is unique in that regard, though we could come up with another handful in the 40x range. And if we want to bring the likes of Kalshi into the mix, you can find high double digit gains almost on a daily basis (though I won’t defend that as any more legitimate than your local bookie).

The more important problem with your phrasing is the word “investment”. BTC is not an investment, it’s an intangible commodity. It has no fundamentals, no sales, no revenue, no debt, no equity, no overhead (though the cost of mining has stayed in the same ballpark as the price per BTC for the simple reason that if it goes lower than the expected cost of power, more people mine, and vice-versa). It is “worth” what someone is willing to pay for it, no more, and no less.

Despite what the haters may feel, it’s not a scam. It sure as hell isn’t something Grandma should be day-trading in her retirement portfolio; but that’s a function of volatility, not because it’s any more or less safe than gold or FCOJ.

Re:Bitcoin - victim of its own success

By Sloppy • • Score: 5, Insightful • Thread

its advocates have already gotten so much of what they could have possibly hoped for

Except the one thing that actually matters: being able to really use it. I still (in 2026!) can’t use Bitcoin to pay for things at my local grocery store, car mechanic, or even Amazon.

Bitcoin didn’t take off. Unless it suddenly gets more popular by a few orders of magnitude, it remains a useless dead end.

Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform

Posted by EditorDavid • • View on SlashDot
Microsoft’s security blog describes the fight against a new "AI-powered cybercrime platform" offering phishing-as-a-service, with AI-tailored lures and analyses of compromised inboxes (to identify high-value targets). The site compromised more than 12,000 inboxes in over 10,000 organizations around the world, compromising business accounts “at scale” with automated attacks and prebuilt phishing templates. AI tools could even sift through a victim’s mailbox to help engineer better phishing messages.

To disrupt EvilTokens Microsoft worked with other organizations, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-ISAC (a non-profit helping health sector organizations share cyber threat information).

“Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time,” security company SpyCloud told The Hacker News.

From Microsoft’s security blog:
Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action… Microsoft worked closely with specialist officers from the Metropolitan Police Service’s cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On September 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination… While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service…

Campaigns leveraging EvilTokens have impacted organizations in various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Working with partners, Microsoft’s Digital Crimes Unit (DCU) facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service.
Sometimes stolen tokens were used to give new devices access to a victim’s inbox. (A code authenticating the new device was sent to the targeted user, who unknowingly authorize the threat actor’s session and grants access to their account…) But “AI was not simply helping attackers write more convincing messages,” says another Microsoft blog post. “It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible.”
The significance of EvilTokens extends beyond its rapid growth and global reach. It offers an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works… Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization’s “money movers,” locate vendor invoices, and determine the best people to impersonate. Sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service. Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.

Investigators found evidence that large portions of EvilTokens had been “vibe coded,” with AI helping its creators build the platform itself. They also determined that EvilTokens drew on capabilities from multiple AI models. The result was more than a collection of attack tools. EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.

Um …

By fahrbot-bot • • Score: 5, Funny • Thread

AI-Powered

I think you mean, SI-Powered /s (*heavy-sigh*)

Changes Over Time

By SlashbotAgent • • Score: 5, Informative • Thread

Microsoft email: Never before have there been so many Microsoft email security measures. Never before has email been so inconvenient for the end user due to Microsoft security measures. Never before Microsoft Exchange Online have there been so many breached email accounts.

It’s kind of staggering. Like watching more people pile onto an overloaded, decrepit, sinking Thai boat, and then acting surprised when it sinks of capsizes.

Every other month, a new improved security system. Strong passwords, password rotation, MFA, phish resistant MFA, conditional access policies, passwordless, passkeys… ‘This one will rule them all.’ Yet, every day we see more Business Email Compromises(BEC) on Microsoft’s platform than ever before.

Nobody is talking about breaches at GMail, AOL/Yahoo, Apple, cPanel, and self hosted servers. It’s always Microsoft. Hmmm.

Re:Changes Over Time

By Arrogant-Bastard • • Score: 5, Informative • Thread
I’ve been designing, building, and running email systems for a very long time. And one of the things I’ve observed is that it is impossible to secure any email system running on Microsoft platforms. I’ve watched colleagues — sincere, smart, dedicated, hardworking, diligent colleagues — try over and over and over again…and all of them have failed. ALL OF THEM. Not even Microsoft, which has for all practical purposes infinite money and infinite personnel, has managed to pull it off. Given this 100% failure rate, I’m convinced that it can’t be done.

Not that other operations don’t have their issues: Gmail is overrun with spammers and phishers, for example. But those might be fixed given some attention by the right people. Microsoft will never be fixed.

Re:Changes Over Time

By sabbede • • Score: 4 • Thread
I just delt with a gmail breach.

Not many businesses use Yahoo or Apple for email, hence the absence of BEC events.
Self-hosted servers get hacked all the damn time. I see the spam they send.
cPanel is vulnerable as hell, I’ve seen it hacked many times. It also sucks.
Microsoft is one of the largest providers for business email. That they are a primary target is expected.

Re:Can also be used for censorship

By toxonix • • Score: 4, Interesting • Thread

Seniors who grew up in the 1950’s did not “get what they deserved” for clicking on a link or answering a message. A lot of them still think they have to answer the phone when it rings, or read emails they get from strangers, just in case it could be one of their friends or family asking for help or telling them something important. Billions of dollars are stolen from senior citizens and people with cognitive problems. The platforms that exploit them for profit should also be held responsible for protecting them from even worse actors than themselves.

The rest of us who have corporate training not to click on phishing emails should know better. But still, a few clever phishing attacks succeed out of thousands that fail, and that’s all they need. I would consider it an obligation to shut down phishing sites proactively rather than waiting for people to report them. Same goes for the fake sites that pull content from retail sites, claim to sell it at ridiculous discounts so they can harvest credit cards.

150 sites/domains is a drop in the bucket though. They should be proyactively killing domains instead of just raking in money and letting criminal enterprises do whatever they want. Let the real criminal enterprises like Meta and alphabet have all the fun.