Alterslash

the unofficial Slashdot digest
 

Contents

  1. New Zealand Introduces Under-16 Social Media, AI Companion Ban
  2. FDA Approves First Wearable Device to Monitor Glucose, Ketone Levels
  3. Canadian Streaming Content Becomes a US Trade Issue
  4. Perplexity and Nvidia Launch Fully Local AI Agent With Zero Token Costs
  5. AI Is Hitting Entry-Level Jobs Hardest, Stanford Study Finds
  6. Waymo Is Expanding to Germany
  7. Apple Announces New Mac Mini With M6 and M5 Pro Chips
  8. Motorola’s 2027 Flagships Will Officially Support GrapheneOS
  9. Windows Backdoor ‘Sleepwalker’ Hides in Memory Until Activated by a ‘Magic Packet’
  10. AliExpress Leverages User Audio Systems For Fingerprinting
  11. World’s Oceans Hit Highest Temperature On Record As El Nino Grows
  12. Amazon Hikes Hardware Prices By 60%, Blaming Memory Shortage
  13. SEC Investigating Near-Implosion of AI Hedge Fund
  14. Trump Admin Moves to Impose More Than $100K Fee For H-1B Worker Visas
  15. Raspberry Pi Shares Its Official Tutorial For Making a Cyberdeck

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

New Zealand Introduces Under-16 Social Media, AI Companion Ban

Posted by BeauHD View on SlashDot Skip
New Zealand has introduced legislation that would ban children under 16 from social media platforms and AI companion services. “We have protections to keep children safe in the real world and we need them in the virtual world too,” said Prime Minister Christopher Luxon in announcing the bill. Jurist.org reports:
The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill would require an age restriction on platforms with harmful features for children. These features include recommender systems, endless feeds, feedback features and time-limited features. The bill also seeks to restrict underage users from accessing AI companion services. However, it explicitly excludes messaging apps, professional networking sites, gaming and music platforms, and other educational and health tools.

Notably, age verification through self-declared dates of birth and formal identification does not satisfy the platforms’ duty under the law. It also requires platforms to verify their users’ age through other methods such as facial scans and user activity patterns. The bill would also require platforms to conduct child safety risk assessments for all users under 18 and protect them from harmful content such as bullying, violence, and sexually explicit materials.

FDA Approves First Wearable Device to Monitor Glucose, Ketone Levels

Posted by BeauHD View on SlashDot Skip
The FDA has authorized the first wearable in the U.S. to continuously monitor ketone levels and the first device globally to track both ketones and glucose together in a single system. From a report:
[Abbott’s] Libre Duo 10 Day continuously measures both glucose and ketone levels in the fluid just beneath the skin every minute, day and night. Readings are transmitted wirelessly to a compatible smartphone, where users can view current glucose and ketone levels and whether those values are trending up or down. The device also can send automatic alerts if ketone levels reach a concerning threshold. The FDA noted that ketone information should be interpreted in the context of glucose readings and symptoms.

Ketones are produced when the body uses fat instead of glucose for energy. When ketone levels rise too high, patients with diabetes can develop diabetic ketoacidosis (DKA), a serious complication that can progress quickly and become life-threatening without prompt treatment. Until now, patients who needed ketone monitoring had to test separately using methods that provided a single measurement at one point in time. Those tests could not show whether ketone levels were rising or falling. For patients with diabetes — particularly those at higher risk for DKA — continuous glucose and ketone monitoring may provide earlier warning of metabolic deterioration and support timelier sick-day management, hydration, insulin adjustment, and escalation of care when clinically appropriate.

Canadian Streaming Content Becomes a US Trade Issue

Posted by BeauHD View on SlashDot Skip
Canada’s cultural-content rules have become a flashpoint in its trade fight with the U.S., after American negotiators reportedly demanded that Ottawa drop requirements for streaming services to promote Canadian and French-language content. Canada refused, even as it has already backed away from some financial levies on streamers. “We were not prepared to compromise on our sovereignty, the protection of the French language, and our culture,” Prime Minister Mark Carney said in a speech on Saturday after trade talks collapsed. CBC.ca reports:
Ottawa has long required broadcasters to promote and support Canadian content (Cancon), all the way back to song quotas for AM radio stations. In 1991, the government brought in the Broadcasting Act. The law states that “the Canadian broadcasting system shall be effectively owned and controlled by Canadians” and that the Canadian broadcasting system should “serve to safeguard, enrich and strengthen the cultural, political, social and economic fabric of Canada.” But decades later, the rising popularity in Canada of streaming platforms such as Netflix, YouTube, Amazon Prime and Spotify raised questions about Cancon and broadcasting rules. Video and audio streaming services were not, for example, required to support and promote Cancon, but their TV and radio counterparts were.

Looking to address the imbalance, the former Trudeau government brought forward a bill in 2022 to update the Broadcasting Act, called the Online Streaming Act. “Canadian broadcasters have invested in and introduced us to the incredible Canadian programs that so many of us love. We are updating our laws so online streamers have to contribute in a similar and equitable way,” a 2022 government news release said. The legislation was controversial from the start, with the government and supporters saying it was a necessary evolution of Canada’s media laws in the digital age, while opponents expressed concerns that it was overreach and an attempt to regulate the internet.

American streamers and digital media companies opposed the legislation fiercely. The bill passed with amendments and became law in April 2023, but the government delegated much of its interpretation — including how much money streamers would have to contribute to Cancon — to Canada’s broadcast regulator, the Canadian Radio-television and Telecommunications Commission (CRTC). But getting streaming companies to pay up has been a long and confusing saga. […].
As for why the U.S. government is so invested in the issue? Mariane Bourcheix-Laporte, a postdoctoral fellow in the communication studies and media arts department at McMaster University in Hamilton, said it could be about power.
“The Americans have had, since after World War II, a very strong cultural policy of pushing out American content into the world,” Bourcheix-Laporte, who has worked with the CRTC, said. “This has been a strategy — a soft-power strategy — for the American government, in parallel to their military strategies and political alliances strategies.”

Go Doug Ford!

By ArchieBunker • Score: 3, Informative Thread

Ontario Premier Doug Ford doubled down on saying U.S. President Donald Trump could “kiss my ass” https://www.cbc.ca/news/canada…

“Trade issue” my ass

By dskoll • Score: 5, Informative Thread

Donald Trump negotiated and signed CUSMA in 2018, calling it the most modern, up-to-date, and balanced trade agreement in the history of our country.

Then he unilaterally breaks the deal, applies illegal tariffs on Canadian goods (by the way, tariffs are consumption taxes on American consumers, in case you didn’t realize that) and then tries strong-arming Canada into giving up its sovereignty.

No wonder our negotiators walked away. Fuck that shit. At this point, it’s a trade war, and Canada’s not going to talk without an attitude adjustment from the USA. For sure, Canada will feel a ton of economic pain… a lot more than the USA. We will definitely suffer. But Canadians are united and willing to take pain, while Americans are hopelessly divided and completely unwilling to endure any sort of economic pain.

I assume Canadian tariffs will target swing states and MAGA states. Anything we can do to hurt the MAGA bastards and hurt the Republicans’ chances in the mid-terms is the most productive thing we can do to get the US-Canada trading relationship back on track.

Don’t push Canada content, and no to the french!

By Murdoch5 • Score: 4, Informative Thread
I live in Ontario, Canada.

Canadians are sick and tired of the French being whiney cry babies, who throw hissy fits every time someone even questions their superiority. I don’t know if this is the same across Canada, but, in primary school and secondary school, in Ontario, you’re forced to take French. Not French as in European French, the kind spoken in France, Canadianized French, which is effectively a dead, and dying language, importantly considering that Canadian French is a dialect. I have no problem with French being optional, in secondary school, but if we want to prepare kids for the real world, teach Mandarin, Spanish, Hindi, or Arabic, and leave the Islamic nonsense behind before you comment.

Someone or some people, will bring up the fact that Quebec exists and people with that “dying” Canadianized French should have a right to their language being respected. I don’t have an issue with that, but to think it’s useful to force that onto all Canadians, when it’s overall reach and usefulness is ridiculously small, is just stupid. ~22% (I’ll round it to 25%) of Canadians speak French as a first language, and using rough numbers that would be ~10 million Canadians, which equates to 1/8th of 1% of the world population. If forcing kids to learn a language that ~0% of the world uses seems rational, you’ve lost the point of education.

When it comes to Canadian content, we don’t need forced adoption, either your content is or is not worth consuming. If it’s not, why force it? If it is, you should naturally reap the rewards. Some Canadian content is spectacular, some of it is crap, and what these pro-Canadian force adoption policies actually cause, is media that wouldn’t be given time, due to lack of quality or substance being over-represented, how does help Canadian culture?

We have culture in Canada, a brilliant culture, with a unique English dialect that gets stomped on and thrown out, without consideration. No one care, effectively, when our English dialect is thrown in the trash, but throw the Canadian French dialect in the trash, and holy bleep the CBC will run segments for months. If you’ve never listened to Canadian radio, you better LOVE, and I mean to a creepy extent The Tragically Hip. A subpar, just okay rock band, with a few bangers, that at best is lukewarm. If you get lucky, some stations will play Rush, but it’s only their hits, and it’s the same loop of songs, so you better enjoy Tom Sawyer, Spirit of the Radio, and if you’re really lucky, Working Man. There all good songs, I like Rush, but come on, they don’t really play the Canadian bands, they play the Canadian over market saturate hype songs, that we’ve all heard a million times. When was the last time you heard 3 Inches of Blood on the radio in Canada? To spite the name, they’re just a heavy metal band, and they’re awesome, but you’ll never hear them on mainstream radio over FM.

The forced Canadian adoption nonsense isn’t about premoting Canadian content, based on value, and substance, it’s about hand waving, and in many cases selling crap painted gold, and try to force respect for something that doesn’t deserve it. I know this is getting long, but Canadian authors, for instance, the amount of marginalized low value works on the market, in classrooms, libraries, e-stores, that just don’t have substance has tipped far past reasonable. To be an award winning Canadian author, just don’t be white and male, and the CBC will sell you like a pimp with a fresh street walker.

Re:“Trade issue” my ass

By Kernel Kurtz • Score: 5, Insightful Thread

Donald Trump negotiated and signed CUSMA in 2018, calling it the most modern, up-to-date, and balanced trade agreement in the history of our country [archives.gov].....Then he unilaterally breaks the deal

Yes, the lack of a deal in the current case is tempered by the fact that any deal with Trump is meaningless anyway, his word is worth less than nothing and agreements with him might as well be written on toilet paper. Rest assured the entire world knows this and couches their expectations appropriately.

Re:“Trade issue” my ass

By shilly • Score: 4, Insightful Thread

I would actually go further, and say that signing a deal with him isn’t merely not worth the paper it’s written on, it’s actively harmful: people waste time and effort negotiating, end up agreeing to a lot of stuff that’s really bad for them, and he still fucks them over and they are very often taken by surprise, despite the fact they shouldn’t be, because people are used to deals having some kind of binding effect and it’s tough to break away from that psychology.

Perplexity and Nvidia Launch Fully Local AI Agent With Zero Token Costs

Posted by BeauHD View on SlashDot Skip
Perplexity and Nvidia have launched "Portable Computer,” a local-first version of Perplexity’s agent platform that runs AI models, files, tools, and workflows directly on Nvidia-powered Linux hardware. Local tasks incur no token charges and keep data on-device by default, with users asked for permission before the system escalates a step to a cloud model. VentureBeat reports:
For Nvidia, which has spent the past two years selling the world on trillion-dollar AI data centers, the announcement signals something subtler but strategically important: the chipmaker believes local AI has crossed a threshold from hobbyist curiosity to practical tool — and it wants to sell the hardware that runs it.

“Local AI reached an inflection point,” said Nader, Nvidia’s director of developer technology, who focuses on developer tooling and open source. “For the longest time, it was hobbyists and enthusiasts, and they were running these quantized models that were quantized down to be super tiny… And while that’s cool, it’s not super practical. But all that changed with a lot of these new open source models that have come out that are super useful.”

[…] Portable Computer arrives today for Pro, Max, Enterprise Pro, and Enterprise Max subscribers on Linux, with Windows support following in September. Any RTX GPU with at least 24GB of VRAM — roughly a GeForce RTX 3090 or newer — clears the bar, a threshold Nate called “sort of the floor where we really want to make sure that we can deliver a great experience, but balance that with making it broadly available.”

Re:Fully local my arse.

By bsolar • Score: 4, Insightful Thread

Let me know when those models stop calling home with telemetry and can run at full capability without access to the internet.

Try something like Ollama + OpenCode. Or even Claude Code with CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC, if you trust them enough.

Re:Fully local my arse.

By EvilSS • Score: 4, Interesting Thread

Let me know when those models stop calling home with telemetry and can run at full capability without access to the internet.

What local models are sending telemetry? And how exactly are they doing that? None of the ones I use do that, nor can they, and they work perfectly offline.

AI Is Hitting Entry-Level Jobs Hardest, Stanford Study Finds

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from Ars Technica:
For years, AI industry watchers of all stripes have been warning of a coming jobs apocalypse driven by ultra-intelligent AI systems that will be able to replicate most human tasks more cheaply. Now, newly updated research from Stanford University economists suggests AI seems to be causing significant entry-level job losses for younger workers in some fields, even as older workers appear largely unaffected so far.

The August 2026 edition of “Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of Artificial Intelligence” updates and revises a paper of the same name published last year with fresh data and refined statistics. In that update, the Stanford researchers find the employment trends they identified for entry-level workers last year are persisting and expanding. Specifically, employment levels for workers ages 22 to 25 in the most “AI-exposed” occupations are now 19 percent below those of their peers in fields less exposed to AI disruption. Last year, that gap measured just 13 percent.

[…] Digging deeper into the data, the researchers found that this phenomenon is mainly manifesting itself through lower hiring rates for entry-level workers in AI-impacted fields, rather than increased firings or employees quitting. They also found that the labor market effects among this age group were mostly seen in lower overall employment, rather than reduced pay rates. But not all jobs that show potential for AI “disruption” are created equal, the researchers found. In its Economic Index, Anthropic differentiates between queries related to tasks that are “automative” (i.e., fully replacing work previously done by a human) or “augmentative” (i.e., helping human workers be more effective at tasks they are still needed for). By this measure, jobs like “accountants and auditors” and “receptionists and information clerks” were among those judged most susceptible to AI automation, while jobs like “chief executive” and “registered nurse” were among those using AI augmentation most often.

Unsurprisingly, jobs where AI automation is prevalent are the ones showing the worst relative employment levels for entry-level workers these days. “The findings are consistent with automation-oriented uses of AI substituting for labor while complementary uses are associated with flat or rising employment,” the researchers write.
Interestingly, the researchers found that the impact is strongest in entry-level jobs built around “codified” knowledge, which is the formal, documented skills that AI can more easily replicate. Meanwhile, experienced workers in roles relying on tacit, practice-based knowledge have seen stronger employment growth.

Entropy phase

By geek • Score: 4, Interesting Thread

Ancient Rome made amazing aqueducts. One day they had built all the ones they really needed and with no new projects for a new generation to learn from, they quickly just forgot how to make aqueducts.

“Big Tech” is now entering this phase. In a generation all innovation will be gone.

Re: Not only that but very very very soon we’re a

By drinkypoo • Score: 4 Thread

Why do you keep asking the stupidest possible questions?

Cuckservatives always regurgitate only the dumbest part of quotes, which is why you think it’s “my country right or wrong” and forgot the part which followed, “and if wrong, to be set right”. And that was said by a conservative back when they were actually real and not just child rape enthusiasts.

Waymo Is Expanding to Germany

Posted by BeauHD View on SlashDot Skip
Waymo plans to launch its robotaxi service in Munich by the end of 2027, marking the Google-owned company’s first expansion into the European Union. “It already operates in 11 cities in the United States and has applied for a license in the United Kingdom to launch its robotaxis in London this year,” notes Reuters. From the report:
The Google subsidiary will start rolling out vehicles in the German city this year, which will be manually driven while the company “starts with high-definition mapping of local street networks” and testing with safety drivers, Waymo said in a statement.

“Bavaria is determined to live up to its pioneering role and be an international leader in autonomous driving,” Florian Herrmann, the head of the Bavarian state chancellery, said in the statement. “Now we need to move quickly from testing to real-world deployment.”

[…] German authorities gave autonomous vehicles the green light in 2021 to operate in the country in approved geographical areas. Other countries are looking at following suit, though the EU’s broader autonomous driving rules are set by the U.N.

That must be a joke

By angel’o’sphere • Score: 3 Thread

Not going to happen.

They are using “AI” as in artificial neural networks (ANN) to run their cars.

Hence there is no single requirement the car is supposed to follow, no issue tracker ticket, no line of code, no test, no review, no confirmation.

Hence: it does not formally fulfil any requirement to be allowed on a European street.

All European self driving cars: use standard algorithms, build on top of a specc, implemented and tested and reviewed - with *millions* of miles of save travel under supervision.

Why the need?

By dskoll • Score: 3 Thread

Now we need to move quickly from testing to real-world deployment.

Really? That is a need? Why, what’s the hurry?

You know another company that moved really quickly from testing to real-world deployment? OceanGate.

Apple Announces New Mac Mini With M6 and M5 Pro Chips

Posted by BeauHD View on SlashDot Skip
Apple has unveiled a new Mac mini with either its new M6 chip or the M5 Pro chip released earlier this year. It adds faster CPU, GPU, storage, and AI performance along with Wi-Fi 7, Bluetooth 6, and 2.5Gb Ethernet as standard. There’s also a new higher starting price of $899, which is up from the previous $799 base price and far above the $599 starting price of the 2024 model. MacRumors reports:
The M6 chip is equipped with a 12-core CPU and a 12-core GPU, up from a 10-core CPU and 10-core GPU in the M5 chip. In addition, the M6 chip features the first-ever dual Neural Engine with two 16-core engines, up from one in previous chips. The M6 chip has up to 170GB/s memory bandwidth, up from 153GB/s for the M5 chip.

Apple said the Mac mini with the M6 chip delivers up to 40% faster CPU performance, up to 4x faster performance for AI tasks in particular, up to 2x faster graphics performance, and up to 2x faster storage speeds compared to the previous-generation model with the 10-core M4 chip, 32GB of unified memory, and 2TB of storage.

There are two M5 Pro configurations available, including one with a 15-core CPU and a 16-core GPU, and another with an 18-core CPU and a 20-core GPU. Both of these models are equipped with a single 16-core Neural Engine for AI tasks. For both the M6 and M5 Pro configurations, Apple said the Mac mini now includes Neural Accelerators in each GPU core for the first time.

Needs an official Linux boot camp

By xack • Score: 4, Interesting Thread
Especially with AI and ARM64 server development. Having to go through brew, containers and Apple’s notarization process makes MacOS not a serious platform compared to bare metal Linux. In a twist of fate it is MacOS that is not ready for the AI desktop. Asahi is stuck on M1 and M2 so can’t help you with M6 Macs.

Re:New higher price

By Powercntrl • Score: 4, Insightful Thread

which Apple blames on higher component costs due to the current AI bubble.... which Apple is itself contributing to.

I thought it was mostly Nvidia making the hardware for AI data centers? Yeah, Apple has leaned into AI on the consumer side of things (and supposedly some people were buying up all the Mac Minis to run OpenClaw), but I doubt they’re the driving force behind the RAMpocalypse.

So one could say…

By Powercntrl • Score: 3 Thread

Apple Jacks up the Price of the New Mac Mini

Yes, I realize the hypocrisy of using AI to criticize market conditions resulting from AI. The way I see it, might as well get a laugh out of this whole situation, because I sure as hell ain’t getting cheaper hardware anytime soon.

Motorola’s 2027 Flagships Will Officially Support GrapheneOS

Posted by BeauHD View on SlashDot Skip
Motorola is working with GrapheneOS to officially support the privacy-focused Android alternative on its 2027 flagship phones, starting with a non-folding model and later expanding to the next Razr Fold and Razr Ultra. “These will ship with Motorola’s normal Android skin, but you will be able to switch to GrapheneOS later if you want to,” notes GSMArena.com. GrapheneOS says the devices will “meet or exceed” its hardware and update requirements, and will include seven years of “proper updates.” Interestingly, Motorola will be doing much of the porting work itself.

Looking for new markets

By Qbertino • Score: 4, Informative Thread

This is Motorola looking for new markets in mid- to upper range phones. It’s not the dumbest move to go after opinion leaders that know what GrapheneOS is and how to install it. Good for reputation too.

Re:Apps that break from using it

By sabbede • Score: 5, Informative Thread
The you’re probably interested in this: https://grapheneos.org/article…

There’s a list of specific applications that ban Graphene, with links so you can complain about it. There aren’t actually that many, and the only one I use is Authy.

Re:Only the “flagships”? What a ripoff

By bill_mcgonigle • Score: 4, Funny Thread

> Only the richest of us are worthy of privacy, right?

  I put GrapheneOS on a $179 Pixel I got off eBay. Works fine. Battery is at 97%.

You only buy new phones? Must be nice, moneybags.

Windows Backdoor ‘Sleepwalker’ Hides in Memory Until Activated by a ‘Magic Packet’

Posted by BeauHD View on SlashDot Skip
“The Register has a story about a Windows backdoor that waits silently in memory for a ‘magic packet’ before springing into action,” writes Slashdot reader fred133. “No outgoing traffic, just waiting…” From the report:
Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware’s 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer. Malware researcher Dominik Reichel discovered the passive backdoor, which also has its own command language, and detailed Sleepwalker in a technical analysis on Monday. “What makes it worth writing up is what that packet carries: not a readable command, but a short program written in a command language of the backdoor’s own design,” Reichel said. “Its 23 instructions cover scheduling, several ways to move data, staged file delivery and running code directly in memory. Recovering the encryption key is not enough to understand one of these programs. The internal command language must be reverse engineered as well.”

In addition to having its own command language, it’s also notable that the remote host can be a VMware VMCI target instead of a normal network address. “Taken as a whole, the approach here is consistent with a targeted, well-resourced operation rather than an opportunistic one,” Reichel wrote. The malware, hidden inside a 64-bit Windows DLL file, impersonates Microsoft’s dpapi.dll, part of Windows’ data protection API for protecting sensitive data. It exports the same seven functions as the real dpapi.dll, but attempts to forward calls to a file named dpapisvc.dll, which is not a real Windows component. The file also has a forged ESET Management Agent version resource, and loads via side-loading into ERAAgent.exe, the Windows executable for ESET Management Agent. After confirming that its host process is named ERAAgent.exe, Sleepwalker goes to sleep inside the computer’s memory, which also helps it remain hidden from traditional anti-virus tools.

Unlike most backdoors, which call back to an attacker-controlled command-and-control (C2) server and start receiving commands, Sleepwalker lies in wait, checking every packet that passes through the network looking for a specific pattern - this is called a magic packet. Once it sniffs out a packet that matches the exact pattern, the backdoor decrypts the data and treats it as a command. “Because the backdoor never sends anything out on its own and does not open any obvious listening port by default, tools that watch for connections to known-bad domains or unusual outbound traffic will not see anything unusual,” Reichel wrote. “The absence of outbound connections to known-bad infrastructure does not rule out an infection, either. A machine can be fully compromised by this backdoor while producing nothing at all for a network monitor to flag.”

Re:Help Me Understand

By Errol backfiring • Score: 5, Informative Thread
Maybe, maybe not. Wake-on-LAN works from a remote system, without an outgoing request first. If this malware is so sophisticated, it could wait for any other program to call to the outside world. If the attacker has access to the network, it can inject something in the answer, thus bypassing a firewall. This could trigger the action and be otherwise seen as a defective network package, which is just asked for again. Nobody would notice a defective network package. This sounds quite scary.

Re:Help Me Understand

By clovis • Score: 5, Informative Thread

It sounds very similar to how a Wake-on-LAN trigger works. Based on how that works, it requires another machine on the LAN with a foothold to send the magic packet?

So, we’re looking for the machine with the foothold and anything that even vaguely related to that PoS ESET?

The real problem here is the eternal Windows problem of dll side-loading.
That allows a system dll to be impersonated and evade sfc scannow protection. How it gets activated is by far less of a problem than that the bad code is already resident in memory waiting for instruction.
Also, there’s the problem that someone has gotten the privilege to put it there.

Re:Help Me Understand

By Bert64 • Score: 5, Informative Thread

This.
It doesn’t need to be a special packet, it could be a specific pattern hiding inside any packet received by the host. You don’t need the ability to send traffic directly to the target, just the ability to interact with a traffic flow in or out of the system.

I’m curious.

By fuzzyfuzzyfungus • Score: 4, Interesting Thread
This sounds like it was written by someone who actually knows what they are doing, so I assume that they know better than I; but I am surprised to hear that it is impersonating a system dll; since (in all comparatively recent windows versions) system components are signed. Absolutely tons of fuckery you can do to them and around them; but if dpapi.dll doesn’t have a signature that checks out the mechanisms that try to keep OSes up and running on marginal hardware subject to random power loss will likely eventually object and attempt a repair, even if there isn’t any more paranoid EDR tooling in place.

Is the on-disk copy of dpapi.dll untouched and only the in-memory instance tampered with?

so

By awwshit • Score: 3 Thread

You get infected by running ESET?

AliExpress Leverages User Audio Systems For Fingerprinting

Posted by BeauHD View on SlashDot Skip
A developer says AliExpress is using the browser’s WebAudio API to help fingerprint users by playing inaudible audio and measuring tiny differences in how their devices process it. CyberNews reports:
The developer, “laserphile,” wrote on their blog that they recently ran into some weird issues with their Bluetooth headphones. They couldn’t play music via their phone when, at the same time, the AliExpress website was open on their PC. The headphones, laserphile explained, support multipoint Bluetooth audio so they can be connected to the PC and phone at the same time, for instance, playing music on the phone and announcing notifications through the PC. “Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately,” the developer said in the blog post.

“Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page. This seemed suspicious enough to investigate.” It turns out that Alibaba has been secretly leveraging AliExpress users’ audio systems to track them and build detailed fingerprints of them. […] The AliExpress site was using the browser’s WebAudio API to run invisible sound waves at zero volume. By measuring tiny hardware differences in how each PC processed those signals, the site created a unique digital fingerprint to track devices — without user knowledge or consent.

The secret audio path froze the developer’s Bluetooth connection while covertly scraping hardware memory, screen dimensions, and network data in the background. The data collection extends beyond audio. Further inspection revealed that the same scripts also measure canvas, WebGL, hardware specs, WebRTC, mouse/touch events, and automation indicators. All of these form a broad device fingerprint that is sent back to Alibaba’s telemetry servers.
The simplest fix is to use a privacy-focused browser such as Firefox or Brave, which can limit or block this kind of fingerprinting. Brave goes further by randomizing fingerprint data and blocking the AliExpress tracking scripts involved.

No....

By YetanotherUID • Score: 5, Insightful Thread
No, the simplest fix is to not patronize AliExpress.

Re:No....lol

By fishfrys • Score: 4, Funny Thread
I was going to reply with “but I need…” and insert a ridiculous item. I then went to AliExpress for a suitable example and quickly realized it was beyond parody, and, frankly, the $0.33 fpv drones and the $0.99 “Softness Silicone Squeezer Grippers Flexible Durable Forearm Rings Hand Exerciser Easy To Clean Silicone” seem like compelling products.

Re:No....

By AmiMoJo • Score: 5, Insightful Thread

First, I thought everyone knew about this, the same as using the HTML canvas and CSS to do fingerprinting. I’m sure they aren’t the first to do it. That’s one reason why audio permission has defaulted to off in my browsers for as long as I can remember.

Second, even if you for some reason trust Amazon and the like more, AliExpress is how you avoid getting shafted by middle men. 90% of the stuff on Amazon is just AliExpress resellers and a 1000% mark-up. Boycotting them is going to be very, very expensive.

new old browsing

By znrt • Score: 4, Informative Thread

i would like peace on earth :-)

you can try. if you build your own browser from scratch (or alternatively use something like lynx) you could “mitigate” to the greatest extent, but subtleties in http header values and handshake and the very fact that you deny everything will make you stand out, not to mention you would likely be tagged as a bot and denied access to begin with.

Re:No....

By DrXym • Score: 4, Interesting Thread
The problem is the leak is very hard to plug. Sites legitimately need to know your screen dimensions for stuff like layout. They legitimately need to know your OS for recommending the right download links. They legitimately need to know your graphics capabilities to render the right thing. And so on. The problem is that in aggregate all these things basically make your machine and your browser unique and distinguishable from another.

As for why Aliexpress wants this uniqueness, it’s probably to do with their business model of blasting offers at people and wanting to track engagement, fraud, bots and so on.

World’s Oceans Hit Highest Temperature On Record As El Nino Grows

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from the BBC:
The world’s oceans are hotter than ever recorded, new data suggests, as they suffer from human-caused climate change and the growing El Nino weather phenomenon. The average surface temperature of the planet’s seas outside the polar regions hit 21.1C (70F) on Saturday, according to figures from the European Copernicus climate change service. That edges past the 21.09C recorded on three separate days in March 2024, and is far above average for the time of year. […] The data is based on sea temperatures 10m (32ft 10in) below the surface, using measurements from buoys, ships and satellites, which are combined to produce a global estimate.

While the margin of record is currently very small and any global estimate comes with uncertainties, scientists say its timing is particularly notable. Average worldwide sea temperatures tend to reach their yearly peak in March or April, which corresponds to the end of summer in the southern hemisphere — and not in August. The southern hemisphere contains more of the planet’s ocean surface than the northern hemisphere and so exerts a bigger influence on average sea temperatures. What is especially concerning to scientists is that the oceans are already so hot when the natural El Nino weather phenomenon is still some way off its expected peak.
“The fact that we are already breaking records is an early indicator of how strong the El Nino is becoming,” said Dr Jeremy Grist, senior research fellow at the National Oceanography Centre in Southampton. “All things being equal we might expect the ocean temperature record to be broken again in March [or] April 2027,” he added.

Re:It’s going to cause inflation

By dargaud • Score: 5, Insightful Thread
Silent ? He can’t seem to shut the fuck up about anything.

Re: It’s going to cause inflation

By Tomahawk • Score: 5, Insightful Thread
Us “older generation” guys did the science and told the people and told the politicians. We were ignored. Don’t blame us. We didn’t want you to have to inherit this. And we’re still here to be able to say “we told you so”. Alas, politicians and the billionaire class are still ignoring us. And you.

Oh give it a fucking rest

By Viol8 • Score: 5, Interesting Thread

I’m not a boomer (Gen-X) but blaming a single generation from a period of 25 years for climate change is beyond purile - its fucking moronic. Blame the georgians - they discovered the coal that kicked off the industrial revolution! Or what about the victorians who turbocharged it and brought electricity to the masses requiring coal power to generate it??

But I suppose a hero like you would have said at the time “No, we won’t advance technology, we’ll stick with our agrarian society and horsepower just like the last 5000 years thanks very much and I never want to travel more than 3 miles from where I was born so whats the problem!”

Idiot.

Re:Something is missing

By Smidge204 • Score: 5, Insightful Thread

> The measures taken did - nothing.

“The doctor said I needed surgery to treat this cancer. I took some aspirin instead. The measures I took did nothing, so clearly the doctor lied to me.”

> Perhaps it is time to exercise our collective masses of grey matter (and our AIs) to figure out some feasible coping measures and implement them.

We know what to do. We’ve known what to do for decades. He simply have not done them, mostly because there’s too much money and power to be had in maintaining the status quot. We don’t need “AI” to solve this already solved problem and, in fact, “AI” is sucking up the resources we need to solve it while also making the problem worse, faster.
=Smidge=

Re:Oh give it a fucking rest

By AmiMoJo • Score: 5, Insightful Thread

The boomers introduced many of the policies that screwed things up, largely based on the assumption that every subsequent generation would be larger (more people) and wealthier. Climate change when they knew it was causing problems is a part of it, but so is the pension system that is basically a ponzi scheme, and house prices.

Every subsequent generation was smaller and less well off, but the boomers are still demanding what they promised themselves. They aren’t willing to use any of their oil-based wealth to mitigate climate change either. In fact a lot of them seem to want to accelerate it.

Amazon Hikes Hardware Prices By 60%, Blaming Memory Shortage

Posted by BeauHD View on SlashDot Skip
Amazon has raised the prices of its hardware devices by as much as 60%, blaming “significant increases in memory and storage component costs.” TechCrunch reports:
The price explosion impacted Fire TVs, Echos, Kindles, and Eeros. One egregious example that’s been cited is that of the Echo Dot, one of Amazon’s cheapest smart speakers, the price of which jumped 60% overnight, from $49.99 to $79.99. Price-tracking sites like CamelCamelCamel show the stark uptick, which has previously hovered much lower. […] The company also said that it would continue to offer occasional promotions to customers over the course of the next year.
Amazon said in a statement: “The consumer electronics industry is facing significant increases in memory and storage component costs. After absorbing these increases for as long as we could, we recently adjusted pricing across our product lines.”

Irritating but not really surprising

By thephydes • Score: 5, Insightful Thread
The subject says it all ....

I’m Not Anti-AI

By machineghost • Score: 5, Interesting Thread

I use AI daily to write code … a lot. And I love the technology.

However … the narrative that “AI makes things better” is increasingly looking like an (industry-motivated) myth to me.

Pros: I can write code faster and easier (and generate diagrams and poorly-written English text). That *is* nice.

Cons: AI is adding adding trillions of gallons of greenhouse gases to a planet that is already starting to die (plus all the other costs of data centers). We’re making all other electronics more expensive, slowing the pace of all other tech development. We’re losing our ability to read and write (both code and English), our ability to assess academic achievement, and our ability to monetize the web (in a sustainable way).

Honestly, despite being very pro AI, I do question whether its benefits actually outweigh its costs.

Saving my upgrades…

By zurkeyon • Score: 4, Interesting Thread
All Win10-Win11 upgrades are dumping a massive amount of DDR4 higher end hardware on my doorstep these days… Bet your rear end I’m hanging onto it like its money. Got an ITS system swap out, perfect condition, the other day with 128gb of DDR4 Sodimms in it… Felt like nerd Xmas ;-D

And who is to blame for the memory shortage?

By karmawarrior • Score: 5, Informative Thread

I’m pretty sure that Amazon is one of those institutions that’s all-in on AI so they can join in the attempts to take over every business in the country.

Maybe they should just say “We’re upping our prices because of our own greed and lust for power, just not in the usual way.”

Pause non-essential purchases

By linuxguy • Score: 5, Insightful Thread

I think most of us should try to pause our non-essential purchases. I can understand that Amazon has to increase prices because of component costs going up. But, we are not forced to play this game. Most of us can hold out with the gear we already have. If enough of us did that, and I think many will, it will cause a sharp decline in demand. And that might actually help the component shortage problem after a while.

The frontier AI labs are losing billions of dollars every quarter. The open source Chinese models are getting really really good. The music will eventually stop.

SEC Investigating Near-Implosion of AI Hedge Fund

Posted by BeauHD View on SlashDot Skip
The SEC is investigating the near-collapse of AI-focused hedge fund Situational Awareness, sending subpoenas to major Wall Street banks for details about the fund’s trades, borrowing, and communications with lenders. The fund, founded by former OpenAI researcher Leopold Aschenbrenner, managed over $30 billion and borrowed tens of billions more before leveraged bets unraveled, forcing it to sell most of its stock portfolio to Citadel at a discount. The New York Times reports:
The subpoenas asked for details on the timing of Situational Awareness’s trades and for its communications with lenders about the money it was borrowing, also known as “leverage,” two of those people said. The subpoenas additionally warned the banks to preserve any information regarding the San Francisco hedge fund. The S.E.C. oversees financial markets with an eye toward protecting small investors, and has brought civil cases regularly against investment firms that produced large losses. Any investigation into Situational Awareness would be at its earliest stages, and it’s no guarantee that it would lead to fines or other punishment. The hedge fund has not been accused of wrongdoing.

[…] Situational Awareness had a fast rise and an even quicker retreat. Founded just two years ago by Leopold Aschenbrenner, a former researcher at OpenAI, it rode the A.I. boom to soaring investment returns. To achieve those results, however, the fund relied on heavy borrowing, as well as complicated and expensive financial instruments that magnify gains — and losses. The latter piled up quickly last month when the stock prices of publicly traded, high-flying A.I. companies dipped. At the same time, shares in more traditional technology companies — which the hedge fund had been betting against — rose, compounding the problem. Situational Awareness was forced into a fire sale. It wound up selling most of its stock portfolio to a rival, Citadel, at a discount.

Re:Couch change

By Locke2005 • Score: 5, Interesting Thread
NO company should be allowed to be “too big too fail”. If you’re too big to fail, then immediate antitrust breakup of your company should be mandatory. Are the people implementing the circular finance scheme creating the bubble expecting to get rich on the government bailout? Absolutely! They assume if the government spent tax dollars to cover the billionaire’s losses before, they will do it again. I’m sticking to my original strategy: don’t invest anything in crypto or AI.

Re:Not a pop yet

By Mspangler • Score: 5, Informative Thread

Look up margin loan.

An example, The bank loaned you 80% of the purchase price. The stock went down, so now the bank’s share of the investment is 90%, so they notify you and you can either add money of your own to get the bank’s share back to 80%, or pay off the loan which you clearly could do only by liquidating the entire investment.

Margin loans (leverage) are great when prices are going up, but terrible for you when prices go down.

Re:Couch change

By rsilvergun • Score: 5, Insightful Thread
The problem is once you accumulate that much money you have a ton of power. The only way to do away with too big to fail companies is to do away with billionaires and trillionaires.

And you cannot get the public at large to understand that just because you aren’t going to let Elon Musk have a trillion dollars doesn’t mean you’re going to steal their house and give it to one of “those” people (insert whichever those people you prefer here).

Seriously I cannot get people to understand that just because Elon Musk can’t have a trillion dollars doesn’t mean you can’t have a toothbrush. I think the problem is that people have a hard time understanding the difference between the couple million dollars they have saved for retirement and the trillion dollars of power that Elon Musk commands that lets him casually drop a quarter billion dollars on the midterm elections…

If it’s one thing I’ve learned in the last few years though it’s Americans hate nuance. Even if the nuances slapping them upside the forehead.

Re:Not a pop yet

By Tailhook • Score: 5, Insightful Thread

Bubble pops don’t happen all at once. They progress, first from the weak sisters to the big, name brand to-big-to-fail “omg my pension!” deals. Media exaggeration about historical finance collapses create the misperception that it happens very rapidly, with no warning. That’s never the case; there are always precursors.

I don’t know if this “Situational Awareness” is such a case, and you don’t either. But this is exactly how the start of a larger collapse looks: a nasty little headline about some sketchy outfit no one has heard of, goes unnoticed outside finance or other narrow media sources. Then more, a couple months later. Then something happens that rocks the world.

Re:Couch change

By Beeftopia • Score: 5, Informative Thread

The problem is once you accumulate that much money you have a ton of power. The only way to do away with too big to fail companies is to do away with billionaires and trillionaires.

Getting the money out of politics is critical to restoring representative government.
Ending gerrymandering is critical to restoring representative government.

The people telling us it’s impossible to get the money out of politics are the people benefiting: the media, highly organized interest groups, corporations, etc.

If money is speech, the wealthy have a lot more of it than you. Each individual in the top 1 percent has as much speech as nearly 100 people in the bottom 90 percent:

“The 3 million people who make up the wealthiest 1% of Americans are collectively worth more than the 291 million that make up the bottom 90%.”

They often look at the top three people. Back in 2017, it was Gates, Buffett and Bezos who had more money-speech than the bottom 50 percent. Today it’s Elon, Zuck and Bezos. 3 people who have more money-speech than 165 million people. Money makes that not a representative government.

Trump Admin Moves to Impose More Than $100K Fee For H-1B Worker Visas

Posted by BeauHD View on SlashDot Skip
The Trump administration is proposing to make permanent a $103,265 fee on certain new H-1B visas, dramatically increasing costs for employers that rely on highly skilled foreign workers in tech, education, and research. “A federal judge in June ruled that the fee was illegal and blocked the Trump administration from collecting it,” reports Reuters. “A Boston-based appeals court is reviewing that decision while a different court considers whether a judge properly rejected a challenge to the fee by a major business group.” From the report:
Trump’s temporary fee increase expires in September, one year after it was issued. The proposed rule by the U.S. Department of Homeland Security, posted in the Federal Register on Monday, would make a fee of $103,265 permanent. It could be finalized by the end of the year. The H-1B program allows U.S. employers to hire foreign workers with training in specialty fields and offers 65,000 visas annually, with another 20,000 for workers with advanced degrees, approved for three to six years. Those visas typically came with fees between $2,000 and $5,000 before Trump’s order. The fee would not apply to visas granted to foreign citizens already in the United States on student visas, who make up a large share of new H-1B recipients, or to renewals of current visas.

Re:Uhoh

By ukoda • Score: 5, Insightful Thread
The proper way to do this is not a big fee, that is just a government money grab. The proper way is to force a minimum pay rate for H1B employees such that they are paid inline with local rate. This means they are employed because their skills are needed and not available locally, not to save money over employing a local person with the needed skills. The big catch is ensuring creative accounting is not used to under pay the H1B working while pretending to pay them similar rates to local employees.

Re:Uhoh

By TWX • Score: 5, Insightful Thread

its not meant to make them stop using it. its meant to stop them from using it to replace there entire workforce with them. if someone is Reilly talented and worth the money there gonna have to pay for it. otherwise hire local.

You know what would work better than that?

Subpoenaing the hiring managers and HR staff and their records to see what sorts of applicants they’ve received domestically and to interview existing staff of the company and any ‘heathunter’ types they’ve used to fill jobs before to find out if they’re actually having trouble filling jobs or if instead they’re simply trying to replace more expensive domestic employees with foreign workers at reduced salaries.

There have been far too many examples where laid-off or soon-to-be-laid-off employees described the active process of training their replacements with great detail. If they wanted to really make a dent they would take those claims seriously and investigate accordingly, and levy heavy, heavy penalties. I’m thinking something like 10x the original employees’ salaries kinds of fines.

Re: Uhoh

By Brownstar • Score: 5, Informative Thread

Not the president’s job. Congress drafts law.

Re:Uhoh

By rsilvergun • Score: 5, Insightful Thread
Get rid of the pedophile in the white house and my mental health would improve substantially. Get rid of the weird creepy couch fucker too and that sell out mother fucker running the House of Representatives and keep going down until we hit a Democrat to take over the White House and then maybe impeach six supreme Court justices and I think then I could stop Doom scrolling.

But we’re not going to do any of that. If I’m really lucky the Republicans will lose the House of Representatives and the Democrats will slow down the damage until 2028 and voters will somehow both be allowed to vote and can stop freaking out about trans girls long enough to not let fascists take over the country and then maybe just maybe I can die in peace.

Because right now dying in peace is the American dream. It’s all the trillionaires left us. Well that and raging against trans girls and complaining about ethics and games journalism. Of course in a few years we won’t have video games because memory will be too expensive but whatever.

Re: Uhoh

By ToasterMonkey • Score: 5, Insightful Thread

Dude we know you don’t even have a theory of how this is supposed to work. This is a money grab and won’t change how the system works. The money will 100% not go to a good cause. H-1B workers will still be exploited once they get here after Trump takes his cut, and it will not lower your groceries, your rent, your gas or pay one dime of federal debt. It will probably be invested in AI data centers and justify even more H-1B workers. Because the goal is to help a few people get rich, not fix anything.

Raspberry Pi Shares Its Official Tutorial For Making a Cyberdeck

Posted by BeauHD View on SlashDot
Raspberry Pi has published an official guide for building a cyberdeck, leaning into a viral trend of homemade portable computers built from repurposed cases, purses, and other oddball hardware. The guide uses a Raspberry Pi 5, keyboard, battery, and Pelican-style case. The Verge reports:
Raspberry Pi’s head of social, Ashley Whittaker, acknowledged the cyberdeck trend today, saying “we haven’t been able to get away from cyberdecks this year.” Raspberry Pi has also increased its prices multiple times this year due to rising costs for RAM and other components, which could be another reason to support this growing market of active and would-be hobbyists. The 16GB version of the Raspberry Pi 5 included in the company’s official cyberdeck guide got a $100 price hike in April, nearly as much as the board’s original $120 price.

I have a CM5 cyberdeck…

By dskoll • Score: 5, Informative Thread

I have a Hackberry Pi, which is a cyberdeck built around the CM5. It’s… ok. The biggest problem is that Raspberry Pis don’t really have a power-saving mode, so you get maybe 4-5 hours of battery life.

And without active cooling, the thing gets really hot

But, it’s a cool gadget and reasonable if you want an ultra-portable computing device.

Too expensive

By RitchCraft • Score: 4, Interesting Thread

RasPis have become too expensive to be considered hobby or maker any longer. Of course this is mostly due to the AIpocalypse but even before this prices were creeping too high. You are better off picking up a used i7 ThinkPad. Just my opinion though. I’ve had lots of fun playing with RasPis over the years until the prices became absurd.

New prices make this unattractive

By Ritz_Just_Ritz • Score: 3 Thread

I don’t find the rpi 5 and equivalents to be particularly attractive at current price points. I have a few around that do things like my media server, pihole, Homeassistant, etc and that’s pretty much it. For only a little bit more, you can get a decently configured AMD Ryzen sff box and call it a day.

Not ultra-portable, but more useful for things that I need to get done.

I knew the RAMpocalypse raised prices but

By Powercntrl • Score: 3 Thread

I read that as “Tutorial For Making a Cybertruck”. Figured it went something like:

1. Sell Pi on eBay.
2. Buy Cybertruck.

Cyberdeck

By spaceman375 • Score: 3 Thread

Even more capable than a pi5, with built-in battery, wifi, bluetooth, no need for cooling, etc, I think it would be more fun to make a cyberdeck that looks like it’s built on an RPi but is really hiding an old cellphone inside.