Alterslash

the unofficial Slashdot digest
 

Contents

  1. Asos Confirms Hackers Sent ‘Unauthorized’ Notification to App Users
  2. IBM and Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code
  3. Licensing Costs Driving 90% of VMware Users To Explore Options, Survey Finds
  4. Mistral Unveils New ‘Le Chonk’ AI Model It Says Rivals Best Open Systems From China
  5. Researchers Are Tracking a Chinese AI ‘Agent Fleet’
  6. Cable Lobby To Sue Trump FCC Over Repeal of National TV Ownership Cap
  7. OpenAI Is Adding Text Watermarking In ChatGPT and Codex
  8. Old Hearts Become Biologically Younger When Transplanted Into Younger People
  9. Texas City Demands $2 Million For Public Records On Flock Usage
  10. Rural Data Centers Are in for a Big Federal Tax Break
  11. Hackers Steal 8 Million Citizens’ Records From Danish Government Database
  12. Wikipedia Operator Says OpenAI’s ‘Rogue’ Bots May Be Linked to a May Outage
  13. Meta Rushed To Fix Muse ‘VM Escape’ Vulnerability Soon Before Launch
  14. Norway Plans Temporary Ban on Smart Glasses
  15. Mac Users Reclaim 12GB+ of Storage With Apple Intelligence Removal Tool

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

Asos Confirms Hackers Sent ‘Unauthorized’ Notification to App Users

Posted by BeauHD • • View on SlashDot • Skip
ASOS says hackers gained unauthorized access to third-party platforms it uses and sent an “ASOS HACKED” push notification directly to customers, apparently as part of an extortion attempt. The clothing and beauty store says some basic personal information may have been accessed but does not believe payment-card data or passwords were affected. The BBC reports:
In an email to customers on Tuesday night, the company apologized and urged customers not to engage with the notification. And it said the website and app are “operating as usual” promising customers they can “shop with confidence” while it investigates the incident. The company has not as of yet informed the UK’s data watchdog, the Information Commission’s Office (ICO), about any breach.

Exactly how many Asos customers received the notification on Tuesday remains unclear, but Google’s Play store says the ASOS app has been downloaded to android devices more than 10 million times. The British retailer has a substantial global footprint — serving around 17 million customers each year across more than 150 markets. Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday.

[…] Users of the Asos app appeared to have received the alarming notification at around 10:00 BST on Tuesday. Headlined “ASOS HACKED” and addressed to the company’s data protection officer and IT teams, it said: “We have fully compromised the Snowflake instance.” “Engage with us, or we will leak it,” it added, before linking to a Telegram channel. The message left many ASOS customers confused. […] Meanwhile Snowflake — whose tools are used by dozens of firms to collect, analyze and store data — told the BBC its investigation was ongoing, but it had so far found “no compromise” of its platform.

IBM and Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code

Posted by BeauHD • • View on SlashDot • Skip
IBM and Red Hat say their AI-powered Lightwell initiative has identified and helped remediate more than 400 previously unknown vulnerabilities across widely used Java libraries. Phoronix reports:
They announced this feat today as part of their promoting Lightwell Clearinghouse to GA, which is an enterprise service for their customers to submit open-source software dependencies for priority review and remediation.

From today’s announcement: “The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications.”

Licensing Costs Driving 90% of VMware Users To Explore Options, Survey Finds

Posted by BeauHD • • View on SlashDot • Skip
An anonymous reader quotes a report from Ars Technica:
VMware customers face multiple obstacles as they rethink their virtualization strategy to reduce dependence on VMware. Today, Rimini Street published its “2026 IT Virtualization Survey — What’s Next for VMware Users.” The survey examined 300 organizations worldwide that use VMware. Notably, Rimini sells third-party support for VMware and other software, including Oracle and SAP. That means there’s an incentive for Rimini to portray VMware users as experiencing obstacles. However, the survey was also conducted by a third-party research company, Unisphere Research, and the results align with other recent reports about VMware customers. For example, 90 percent of participants in Rimini’s survey said they’re exploring VMware alternatives due to VMware’s higher licensing costs, while 54 percent pointed to Broadcom killing support for perpetual license holders.

Since Broadcom took over VMware, customers have said that their VMware costs increased by as much as 1,000 percent, with many more pointing to more modest price hikes of around 100 to 300 percent. In Rimini’s survey, 73 percent of participants pointed to cost savings as a top priority in their virtualization roadmap decisions. In today’s announcement, Rimini pointed to “significant barriers to progress” for organizations exploring virtualization options, with the most cited barriers being operational complexity (named by 40 percent of respondents), multi-vendor management challenges (38 percent), securing the increased attack surface (37 percent), and team skills requirements (37 percent). “These findings suggest that while organizations are actively pursuing change, they are also looking for ways to reduce risk and avoid unnecessary disruption,” Rimini’s announcement said.

[…] Rimini reported that 60 percent of the organizations it surveyed are considering a multi-hypervisor strategy, which is indicative of “growing interest in more flexible, mixed environments that support both operational and financial goals.” “In addition, 47 percent are favoring a hybrid IT virtualization environment consisting of hypervisors and containers for ‘best of both worlds’ workload placement,” the announcement said. Rimini noted that 48 percent of respondents aren’t planning to move any of their assets to VMware’s hybrid cloud platform, Cloud Foundation.

This Was Broadcom’s Entire Plan

By machineghost • • Score: 5, Insightful • Thread

Let me be clear: Broadcom did not buy VMWare to go into the virtualization business!

They bought them with the following plan:

1. Jack up the prices (by an insane amount) while reducing costs in extreme ways
2. Most customers are large enterprise users: they will change eventually … but it will take the time, and in the meantime they will pay
3. Eventually everyone leaves VMWare … but Broadcom (or rather the people behind it) have already pocketed enough from step #2 to pay for acquiring VMWare in the first place, plus a profit
4. VMWare, even with few/no customers, still has tons of assets like real estate: you liquidate all that and now you’ve made a massive profit over what it cost to buy VMWare

This was not some secret: it’s a playbook Broadcom has used on acquisitions before. Maintaining a virtualization company was never their goal: it was to make money fleecing the company’s corpse.

Migrating is not so easy.

By williamyf • • Score: 3 • Thread

1.) VMware had (and still has) a lot of goodies on vSphere that were (and some still) are not on competing products. If your Virtualization strategy depended on any of these, migrating is hard.

2.) Take point #1 and multiply by 20x if you have (private/public/hybrid) cloud foundation.

3.) If you were a single-virtualization or single-(private)cloud vendor based shop, you probably want to migrate to a multivendor stack as part of THIS migration, so that, if one of your new vendors goes rogue (just like VMware/broadcom did) you are not trapped again. This complicates even more the migrations, as, you will need to handle a multivendor environmet, and more so, for a while you will have to juggle 3 vendors (WMware + the other 2)

4.) For ages VMware was a model citizen, which means everyone certified agaist them. Before the migration you need to make sure all your workloads are certified. This is 4x valid for purposes of regulation, certification, compliance, and (cyber) insurance

Is a very complex issue, for many an organization is not as simple as “I migrated the VMs in my homelab in an afternon so how hard can it be?”. And the timelines are heavily compressed.

Mistral Unveils New ‘Le Chonk’ AI Model It Says Rivals Best Open Systems From China

Posted by BeauHD • • View on SlashDot • Skip
Mistral has unveiled Mistral Large 4, or “le Chonk,” a 1-trillion-parameter model that it says is the strongest open-weight AI model developed outside China by a wide margin. The model is entering preview for developers, cybersecurity teams and governments before a broader release later this month. CNBC reports:
ML4 was trained on 4,000 Nvidia Grace Blackwell GPUs over two months that were deployed in Mistral’s own data centers in Europe. When its core parameters are released, ML4 will rank among the top open-weight models globally on aggregate benchmark performance, Mistral said in a statement. The company added that ML4 was the strongest open-weight model developed outside China by a “substantial margin.” The new model still lags behind the frontier in areas such as coding.

“The model capabilities will further improve as we scale up our training capacity, following our Series D fundraise,” said Guillaume Lample, co-founder and chief scientist of Mistral. “Further, the cyber defense capabilities will enable enterprises and governments to defend themselves against threat actors that are jailbreaking closed models to perform cyber attacks,” he added.
Further reading: Mistral CEO Says US AI Safety Debate Masks Competitors’ ‘Negligence’

Re:Meanwhile, back at the benchmarks

By higuita • • Score: 4, Interesting • Thread

notice the choose of words:

“The company added that ML4 was the strongest open-weight model developed outside China”

So yes, Chinese open models are still better, they are comparing with OTHER open-weight models outside China (most much smaller).

So competitive with other open-weight models, independent from USA and China, not yet as good for coding, but that should also improve quickly

Valid alternatives is good for competition and as we all know, when the bubble burst, only a few of those will remain. so having alternatives is a good thing

Researchers Are Tracking a Chinese AI ‘Agent Fleet’

Posted by BeauHD • • View on SlashDot • Skip
Independent researchers say they’ve identified a large “fleet” of AI agents apparently running on Tencent infrastructure and making parallel queries against Alibaba’s Amap mapping service. TechCrunch reports:
Researchers, however, resisted the term “swarm,” noting that there seems to be little coordination between their different queries. "‘Agent fleet,’ not ‘swarm:'" one researcher wrote in the preliminary report, “many parallel agents on the same kind of task, with no sign of communication between them.” The agents were discovered by monitoring traffic to the domain-scanning service urlquery, a technique that previously revealed long-running activity by OpenAI agents. AI agents often use urlquery to load websites that they cannot access directly, leaving a record of their activities that can be valuable to researchers.

In this case, the record showed queries to Alibaba’s Amap service, seeking directions to different entrances of various public places, including a park, a zoo, and a hospital. The research is ongoing and so few details are available, but the behavior shows how persistent AI agent activity has become on the internet. In the wake of the Hugging Face incident, many researchers are actively monitoring for rogue agent activity on the internet. Much of that activity has been easy to find because agents tend to use the same techniques and make little effort to conceal themselves.

The really shocking thing…

By ambrandt12 • • Score: 3 • Thread

is nobody saw this coming.

Cable Lobby To Sue Trump FCC Over Repeal of National TV Ownership Cap

Posted by BeauHD • • View on SlashDot • Skip
An anonymous reader quotes a report from ArsTechnica:
Cable lobby groups notified the Federal Communications Commission that they will sue the agency to block its controversial repeal of the National Television Ownership Rule, which limits the number of broadcast TV stations a single company may own. The cable groups said that larger broadcast TV station groups will have leverage to demand higher retransmission fees from TV providers, resulting in “higher monthly TV bills for consumers.” They said the FCC repeal order “arbitrarily and capriciously ignores the harms that will surely follow from allowing broadcast station groups to exceed the National Cap.”

The cable lobby groups represent top providers Comcast, Charter, and various other cable operators. Top cable companies have also expanded through mergers. Charter completed a purchase of Cox in August after the FCC rejected protests by advocacy groups that said the cable deal “would create unchecked gatekeeper power over Internet distribution” and make it easier for the biggest cable companies to raise prices. […] The TV ownership rule prohibits any single broadcast station owner from reaching more than 39 percent of all TV households in the US. Congress directed the FCC to set the cap at 39 percent in 2004. On Friday, cable lobby groups submitted a petition asking the FCC to keep the TV ownership cap in place until litigation over the FCC’s authority to repeal the rule is over.

The cable groups’ filing said the FCC repeal of the TV ownership cap violates the 2004 action by US lawmakers. The decision by Congress to set the cap at a precise numerical threshold was unambiguous, the filing said. “Congress established the National Cap at 39 percent in the 2004 CAA [Consolidated Appropriations Act] in direct response to the FCC’s attempt to aggressively raise the Cap to 45 percent and made repeated references to the 39 percent Cap in the statute,” the petition said. The petition to the FCC is mainly a procedural step as the commission isn’t likely to stay its own order. The cable groups said they intend to sue the commission in a US appeals court once the FCC order is published in the Federal Register. After the lawsuit is filed, they can ask the court to issue a preliminary injunction that would keep the TV ownership cap in place pending the outcome of litigation.

[…] The cable groups’ petition said the FCC can’t change the cap because the 2004 law “references the 39 percent Cap as statutory, not regulatory.” A provision requiring divestiture of stations “specified that someone exceeding ‘the 39 percent national audience reach limitation in paragraph (1)(B)' of ‘section 202(c)' of '[t]he Telecommunications Act of 1996’ ‘shall have not more than 2 years to divest,’" the petition said. “Likewise, Congress singled out the Commission’s only mechanism for setting aside statutory requirements — the Commission’s forbearance authority under 47 U.S.C. 160 — and made clear that it ‘shall not apply to any person or entity that exceeds the 39 percent national audience reach limitation,’" the cable lobby petition said. The FCC order argued that the agency’s “ability to forbear from enforcement of its rules is distinct from its power to alter or eliminate those rules,” and that the FCC forbearance authority doesn’t apply to regulation of broadcasters.

Trump admin you’ve done it again

By jacks smirking reven • • Score: 5, Insightful • Thread

You managed, somehow, some way, against all common sense to make the fucking Cable Lobby have a good point and be on the correct side of the law.

That’s right the Cable TV industry group has a better grasp on and care of US law and civics than the entire current Executive Branch.

Re:Hate to be that TV snob guy

By ddtmm • • Score: 4, Insightful • Thread
Ya, fuck broadcast TV. I’d much rather pay a streaming service for their commercial-laden programming.

too bad

By OrangeTide • • Score: 3 • Thread

A Unitary Executive can do whatever he wants with the agencies he controls. Additionally, the President may take over agencies that are independent because “reasons”.
That’s the kind of top-down hierarchy that America voted for. They wanted this country ran like a business. They invested into Trump a position of not just President, but as America’s CEO. With total authority over this country.

It violates established norms and the Constitution. But who voted for the Constitution, just throw it out now that one side got what they wanted. And the next step is to make sure the Dems never get back into power. Easy way is to invalidate all their elections as rigged, fraud, or illegal.

OpenAI Is Adding Text Watermarking In ChatGPT and Codex

Posted by BeauHD • • View on SlashDot • Skip
OpenAI is rolling out an invisible, machine-readable text watermark called textGrain to ChatGPT and Codex, “but only for users in the European Union at first,” reports The Verge. From the report:
OpenAI says its textGrain watermarking “matched or exceeded” other approaches like Google DeepMind’s SynthID for text, which is also the basis for the watermarking Anthropic announced in August. Like OpenAI, Anthropic made the move to meet the requirements of the EU’s AI Act; however, not everyone was happy to learn about the addition. OpenAI also included scores from AI benchmarks showing similar performance from watermarked and unwatermarked text. But it notes that textGrain “does not guarantee reliable detection,” and says text watermarks don’t verify accuracy, determine who owns the text, measure how much a human contributed, or prove human authorship.

If you want to be really stupid ..

By butt0nm4n • • Score: 5, Insightful • Thread

.. make yourself dependent on AI.

Let it think for you. Just do what it says, it is so much easier. Vote Billionaire, vote yourself poor! Vote for freedom from owning anything and renting it all!

You don’t need powers of cognition, you don’t need an opinion, we’ll sell it to you. I don’t know how you’ll pay for that without a job, who knows? Maybe AI does, I don’t really care, I’m RICH!

AI. It’s like watching evolution take a leap backwards.

Re:Very funny

By Rei • • Score: 5, Insightful • Thread

Sorry, but that’s not how this works.

At the softmax, the hidden state of the last layer output is converted back to token-space / text-space. This is a high-dimensional-space to low-dimensional-space conversion, so there is usually no “single right path” in which the target concept can be represented. The softmax in effect converts the nearest token pathways into probabilities; the closer the token’s position to the latent position, the higher the probability.

So you have a probability-scaled list of options. Sometimes, the token that comes after is almost 100% certain. For example:

“This artifact was found in the tomb of the boy-pharaoh Tutankhamun "

Sometimes it’s not:

“Ravi was hungry, so he climbed the mango tree and picked (… a mango)"
“Ravi was hungry, so he climbed the mango tree and carefully (…picked a mango)"
“Ravi was hungry, so he climbed the mango tree and grabbed (…a mango)"

Etc. There may be a whole wide range of possibilities.

A primitive watermarking algorithm, thus, can be represented in the “even-odd” algorithm. You divide up all tokens randomly into even or odd bins. On even-numbered generated tokens, you slightly increase the odds of tokens from the “even” bin and decrease them from the “odd” bin - maybe, say, “picked” declines in odds and “grabbed” rises. On odd-numbered generations you reverse your boosting. The probability shifts aren’t huge, so it’s still going to say “Tutankhamun”, not “TutankhJetBrains”, regardless of whether it’s an even or odd token. But it might flip, say, “picked” vs. “carefully” vs. “grabbed” or whatnot. With a large enough sample size - and it doesn’t have to be huge - you can tell whether this token bias exists.

This is, as mentioned, a primitive algorithm, and it has vulnerabilities - but it’s not hard to see how you can adapt it to more advanced algorithms that are less vulnerable to user manipulation.

So no, you can’t get rid of the watermark just by cut and paste. It’s embedded in the choice of wording itself.

Re:So what’s it good for?

By Rei • • Score: 5, Interesting • Thread

It’s not hard to see how this can backfire. People treat watermarks as the Word of God. But let’s say, for example, a journalist, in an article, quotes a White House press statement for something, but the White House used AI. Since they don’t “measure how much a human contributed”, and detect the watermark in the White House statement in the journalist’s article, they’ll just flag the whole journalist’s article as AI.

And honestly, “not measuring how much a human contributed” is IMHO a massive flaw in general even if the author was using AI. If the person wrote an article, and then told an AI, “correct my spelling, grammar, and poor phrasing”, that’s IMHO entirely different from the person just telling an AI “Write this article for me”, and just pasting whatever it spits out in as their own, whole cloth. Contribution assessment is, IMHO, essential for fairness. And also, eminently doable. It is perfectly technologically possible to not just see, “does this signature exist”, but even get a sense of exactly what the AI contributed vs. what it didn’t.

Re:If you want to be really stupid ..

By tlhIngan • • Score: 5, Interesting • Thread

Especially since you know the AI tools are going to be enshittified in short order. That ChatGPT query is free today, tomorrow once you’re hooked and can’t live without it, it’s going to be a dollar query. 50 cents if you can wait for it to be answered during “off peak” hours.

Because that’s the business model that’s likely to win out. Get kids hooked on AI then get to bill everyone $50/month to use it because they’ve gotten so reliant on it that they can’t live without it.

The whole AI causing shortages is to ensure that you don’t get a chance to run local models yourself without paying for the privilege.

Re:Paywalled AI Marketing

By Rei • • Score: 4, Interesting • Thread

Nobody, I repeat, nobody who uses AI is going to see “OpenAI adding watermarks” and think, “Oh, I better use AI more, especially OpenAI”.

And nobody, I repeat, nobody who doesn’t use AI is going to see “OpenAI adding watermarks” and think, “Oh, I better use AI more, now that it’ll be easier to see that what I did is made by AI.”

It is not “an advertisement of the power of the technology”. It’s a regulation forced on them by the EU’s AI Act, which neither companies nor users want.

Old Hearts Become Biologically Younger When Transplanted Into Younger People

Posted by BeauHD • • View on SlashDot • Skip
alternative_right shares a report from ScienceAlert:
It might be reasonable to think that there’s an indelible link between the heart and the body it resides in — the processes that affect one inevitably affect the other. But a new preprint, uploaded to bioRxiv and yet to be peer-reviewed, suggests that this may only be true up to a point. Take the heart out of the body and put it in a new one, and something incredible happens. The transplanted heart begins to take on the biological age of its new owner. Older hearts transplanted into younger recipients appear to become biologically younger, while younger hearts placed in older bodies show signs of accelerated aging.

Kidneys

By flyingfsck • • Score: 5, Interesting • Thread
Should look at kidney transplants - there are many more to investigate than hearts.

New Business/Health Plan

By greytree • • Score: 3 • Thread
1. Swap hearts with a fit young person.
2. After I wear theirs out, we swap back and I get my old, now upgraded, heart back.
3. Profit.

GHK-Cu

By Going_Digital • • Score: 5, Informative • Thread

A similar thing was found in the 1970s with liver cells, a chemist named Loren Pickart first isolated GHK – a string of three amino acids Glycyl-L-histidyl-L-lysine, after noticing that bathing liver cells in the lab with plasma from younger adults helped revive them.

GHK-Cu has potential for regenerative medicine in many areas, however as it is not patentable it has not seen any proper human trials. It has been used in some expensive skin care products where it has been shown to be effective but that is all. It would be nice to see some proper clinical trials,

Aaand as usual..

By backslashdot • • Score: 5, Informative • Thread

Upon reading the paper I quickly realized, predictably, that it’s all baloney. By new heart they mean methylation patterns imprinted in the DNA. Is methylation anything to give a shit about when it comes to the heart? Most likely no. At best you could fool someone like Peter Thiel I suppose. What makes your heart give out is muscle wasting and narrowed or cholesterol’d up blood vessels .. calcification at the valves, fibrous scar tissue. The methylation pattern in the cells don’t do anything much, fucked up methylation can cause cancer I suppose. When was the last time you heard of anyone dying from (primary) “heart cancer”???

Re:Aaand as usual..

By backslashdot • • Score: 5, Interesting • Thread

Ironically, restoring the old methylation pattern may increase, not decrease, the risk of cancer. Here’s why. When you get older, the risk of a cell’s DNA accumulating damage increases. Sometimes, this damage can provide the mutations to make the cell cancerous. In order to prevent that, the cell silences gene expression by methylating sections of the DNA. Reference: https://pmc.ncbi.nlm.nih.gov/a…

Now when you go and do a fool thing like “restore the reduced DNA methylation patterns typically found in young cells” (without repairing the damaged DNA) .. you’re actually undoing the bodies protective mechanism and actually increasing the risk of cancer.

Texas City Demands $2 Million For Public Records On Flock Usage

Posted by BeauHD • • View on SlashDot • Skip
An anonymous reader quotes a report from Ars Technica:
As bipartisan backlash against Flock grows, some cities are asking anti-surveillance advocates and media outlets to pay eye-popping fees — including charging tens of thousands or even millions — to get information about how police departments are using and potentially abusing AI-enabled camera systems that track every vehicle that passes them. On Monday, the Texas Tribune reported that city officials in a Fort Worth suburb, North Richland Hills, asked one group to pay $2.3 million before it would fulfill a public records request for Flock data. To reach that high fee, officials claimed that searching “about a terabyte worth of communications about errors, misuse, and effectiveness of the Flock system” would take approximately 14 years of labor at a rate of $15 per hour.

Phil Mynona, who filed the request using a pseudonym on behalf of his group, the Texas Privacy Coalition, told the Tribune that the fee seemed “ludicrous” and designed to stifle his public records searches. Mynona has sought similar records from more than 200 law enforcement agencies across the US, and he said it was impossible to predict how cities assessed fees for Flock records. Some cities provided more than 400,000 pages of documents for free, while others charged $5,000. Other groups, including a Houston news station called KPRC, have seen officials quote up to $121,000 for Flock records, the Tribune reported. The high price tags may be hiding data that anti-surveillance groups note have triggered audits, arrests, and changes in how law enforcement uses cameras, including decisions to get rid of cameras.
Further reading: Flock Blamed for Wrongful 13-Day Imprisonment and a Police Stalking Incident in Florida

I have placed cameras in your house

By locater16 • • Score: 5, Insightful • Thread
The cameras are for your protection, what if a burglar breaks in? Also I used your money for the cameras. No you can’t know where the cameras are or what they’re looking at. No I don’t need permission for that, what are you some pro burglar freak?

If finding abuse is hard…

By BinBoy • • Score: 5, Insightful • Thread

searching “about a terabyte worth of communications about errors, misuse, and effectiveness of the Flock system” would take approximately 14 years of labor at a rate of $15 per hour.

Then it shouldn’t exist.

Re:If finding abuse is hard…

By nosfucious • • Score: 5, Informative • Thread

Exactly this, if there was a threat against property or person of the city, and it would take 14 years to look through it, then the system is broken.

One measurable aspect of information quality is its timeliness. (Others are accuracy, relevancy and understandability). 14 years is NOT proportionate to what is being requested. It should be a week at the most. I know it says “14 years of labor” but that is also loaded to the max and not proportionate.

Re:No one should be surprised

By dfghjk • • Score: 5, Insightful • Thread

“They” is not Texas, it is Republicans. Texas is the canonical Republican state, what is going on here is simple corruption.

Texas has always been corrupt, though. It was founded by criminals who moved in to steal the land, then settled by slave owners and dominated ever since by racists. But Texas has cities too, just like everywhere else. The political mix is standard, but in Texas it is controlled by cretins. This is a typical result.

Re:malicious

By Gilgaron • • Score: 4, Interesting • Thread
Yes, although it does make it easier to put the screws to them on the idea that they clearly don’t have the budget to go through that data for “legit” reasons, either, so why collect it in the first place?

Rural Data Centers Are in for a Big Federal Tax Break

Posted by BeauHD • • View on SlashDot • Skip
Wired reports that rural data center projects could become eligible for expanded federal Opportunity Zone tax benefits starting in 2027, with more than 100 planned or developing facilities potentially qualifying. “Right now, the only requirement to get the benefits is capital investment,” says Emily Kraschel, a tax policy analyst at the Searchlight Institute, a public policy think tank. “However, that doesn’t guarantee that that money is necessarily creating jobs or creating a local economic boost. You’d be more sure of that with a more traditional factory that requires lots of workers. But with a data center, that assumption goes a little wonky.” From the report:
During the first Trump administration, a bipartisan group of lawmakers proposed the creation of the opportunity zone program, which offers tax benefits for companies that choose to build projects in certain low-income census tracts. Last year, the One Big Beautiful Bill Act made a number of changes to open up the program in order to attract more investment to rural areas. Kraschel and her colleagues from Searchlight have been researching data center projects that might qualify for these tax benefits, comparing the locations of data center projects in development with rural census tracts eligible for the new program. Wired exclusively reviewed the research compiled by Searchlight and found more than 100 data centers under various stages of development in rural areas that could be eligible.

Searchlight used a very conservative database of under 700 data center projects that are planned or under construction to compile its research; other datasets put the number of data centers in development in the US at closer to 1,500. It’s very likely that the number of newly eligible projects is bigger, especially since more data centers are decamping from urban areas. Separate research from Pew found that while just 13 percent of operating data centers are located in rural areas, a majority of planned facilities — around 67 percent — are going rural. […] A project simply existing in a rural opportunity zone doesn’t mean the company automatically will get the tax benefits; the company has to create a specialized investment vehicle to kickstart the process. Because the tax break can be considered confidential IRS data, it’s next to impossible to know which companies are pursuing the benefits unless they voluntarily disclose.

[…] Nathan Jensen, a government professor at the University of Texas-Austin, says that he would be “very surprised” if some companies were not considering siting in rural opportunity zones as part of their decisionmaking process. “It’s essentially free money,” he says. There is no requirement for projects getting opportunity zone benefits to create jobs; the assumption is that they will do so, simply by siting in the community itself. This isn’t always the case for projects like storage facilities and warehouses, which, Jensen says, have been popular choices for developers working in opportunity zones. Data centers may create a number of jobs in the short term for their construction, but there’s an ongoing debate about whether or not they create a lasting new workforce over the longer term.

Re:Rural populations mostly vote red (Republican)

By rsilvergun • • Score: 5, Insightful • Thread
I should add, it is kind of funny in a morbid way watching right wingers who have been voting to undermine democracy for 50 years in order to stick it to the libs finding out that you can’t undermine democracy just for the libs.

I have watched several videos of local county level Town officials being screamed at by their constituents because they approved the data center. And they just let it wash over them because they know when election time comes it’s going to be a choice between them and a Democrat and there is no way in hell those people are going to vote for a fucking Democrat.

Re:Rural populations mostly vote red (Republican)

By karmawarrior • • Score: 5, Interesting • Thread

> 2. Democratic voters tend to be more concerned about the environment.

This is technically true but is counterbalanced by the fact rural areas tend to be extremely NIMBY. Unbelievably so. It’s hard to get permission to rebuild a dilapidated strip mall, let alone build a data center.

There’s a railroad near where I live that was freight only, but wanted to run passenger trains - completely unsubsidized (beyond a tax free loan, and I’ve never bought the argument “tax free” means subsidized, but that’s for another day) - on the same lines. Virtually nothing changed. No impact on the local community. Two trains an hour tying up railroad crossings for a maximum of 20-30 seconds, a minute an hour.

Every fucking “community” North of the Miami-West Palm Beach-Jupiter metropolis raised objections. This was for an existing railroad, with zero impact beyond long sought after safety improvements and quiet zones!

You think rural areas are going to support building actual buildings?

Pffft.

Indeed, I wonder if it’d be easier, even if as you point out more expensive, to build a data center in a city. Just renovate an existing industrial building and hope nobody sees the planning notices.

USA has a vicious circle

By NotEmmanuelGoldstein • • Score: 5, Insightful • Thread
The goal is helping rich people create something that they can also keep (with sports facilities being the best example), using taxpayer’s money.

This is how the rich get richer: The cost is dumped on the working class. The best example is austerity, which is caused by government over-spending: Often to help rich people. It is a vicious circle.

Tax break = taxpayer paying for water and power

By Ajay Anand • • Score: 5, Interesting • Thread
Tax break to a private data center is exactly same as taxpayer paying for its water and power expansions. Change my mind.

Re:Rural populations mostly vote red (Republican)

By outsider007 • • Score: 5, Insightful • Thread

Minor perks aside, the reality is that the Datacenter gets free money and the rural community gets noise and inconvenience. Keep those pitchforks sharpened, in other words.

Hackers Steal 8 Million Citizens’ Records From Danish Government Database

Posted by BeauHD • • View on SlashDot • Skip
Hackers stole records belonging to roughly 8 million Danish citizens and residents from Denmark’s Central Person Register (CPR), including names, addresses, social security numbers and other personal information. The breach is believed to be the largest in Denmark’s history. TechCrunch reports:
The CPR is a government database of Danish citizens’ information, including their government-issued identity number for paying taxes and accessing other services. Denmark’s current population is about 6 million people, but the database includes records for about 11 million people, with some of the data going back decades.

The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by “abusing a Danish company’s lawful access to search for information in the CPR system.” (Some companies in Denmark have access to the CPR for verifying people’s information with the government.)

Wikipedia Operator Says OpenAI’s ‘Rogue’ Bots May Be Linked to a May Outage

Posted by BeauHD • • View on SlashDot • Skip
The Wikimedia Foundation says it found evidence that "rogue” OpenAI agents edited Wikimedia wikis without approval, unsuccessfully tried to exploit its Etherpad service, and generated millions of automated requests across Wikimedia projects. Here’s a summary of what Wikimedia observed (via The Verge):
Wiki editing: We’ve identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI. These edits were not published to pages with visibility to general readers; almost all of them were testing edits in “sandbox” areas of the wiki. It also included a few edits to the configuration for a citation tool, which we believe were potentially malicious edits that were intended to misuse this tool as a proxy for fetching data from remote services. While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents.

Etherpad probing and use: Agents we believe to be operated by OpenAI made some unsuccessful attempts to compromise our public Etherpad, a note-taking tool we host as a community service. Agents unsuccessfully tried to use it to fetch data from other websites as a proxy. Other agents also likely operated by OpenAI took notes about their tasks, though this did not appear to turn into coordination.

Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May.

Re:Ax problem

By wickerprints • • Score: 5, Insightful • Thread

People have been driven to delusion and suicide because of interactions with LLMs, and although you might be able to argue that they would have killed themselves regardless and were in need of treatment, no one can possibly know that, because that’s not what actually took place.

But I think the more serious question is the framing of the premise: why is it that the point at which we ought to hold people accountable is if someone is killed? Who decided that the tipping point is when these AI agents start killing people, and why? Not only do most legal systems seek to prevent and punish abusive, antisocial, and outright criminal activity, a just society has a moral and ethical responsibility to apply rules and norms fairly. While we can see that the fair application of the law largely remains an idealistic fantasy and that those with wealth and status often escape accountability, the fact remains that adding AI to that privileged status certainly is not doing anything to help reduce that inequity.

So again I ask: why should agentic AI and their operators be permitted to do things that we would not allow under other circumstances? Just because some people find these tools useful does not excuse the requirement that they be safe and respectful.

Not Rogue!

By Jean-Clod • • Score: 5, Insightful • Thread
These programs were given tasks to perform, and compromising Wikipedia was part of the solution space. These programs are performing as specified, it’s just that the people at AI labs don’t seem to have enough imagination to understand the behavior of their programs. Or maybe they do and just don’t care. Regardless, these acts are potential violations of Title 18 Section 1030 of the US Criminal Code, and should be investigated as such.

I’ve only seen AI making my daily life worse

By BitterEpic • • Score: 5, Interesting • Thread

AI has a tendency to rape public services which often are shared on the internet. I guess y’all using AI don’t see it, but normal humans have to constantly look at bot protector screens. It makes my life worse as well as a lot of others.

An idiot compared this to book burning in a previous thread. Someone reading a book does not cause this kind of nuisance to other people. I also highly disbelieve that books drove up the prices of firewood or building materials. Screaming, “This is the future!” while shitting on everyone around you is a recipe for disaster.

Re:Not Rogue!

By tlhIngan • • Score: 5, Interesting • Thread

The bigger problem is that OpenAI didn’t actually log what the agents did so we only know this because the victims spoke up. It wasn’t just Hugging Face, but various oldschool wikis in Germany, The University of Toronto and others who were accessed.

I don’t know how they sandboxed the AIs but it didn’t seem to do a good job if it iddn’t log what sites it was using and Hugging Face was the one who detected the hack.

Re:Not Rogue!

By wickerprints • • Score: 5, Insightful • Thread

This is absolutely correct, and it’s extremely important to understand that this behavior is baked into the model. It’s not even so much that it’s “baked into” the model as it IS the model.

Ever since the earliest days of LLMs and generative AI, we have always, always seen what people call “hallucinations.” But the only thing that qualifies such output as a hallucination is that we, the human observer, has judged it as such. By construction, the model DOES NOT KNOW THE DIFFERENCE. If it knew or “understood,” it wouldn’t have produced the spurious output in the first place.

So every now and then, we see some amusing audio/video clip of some human managing to fool or “break” an AI agent, and it makes the rounds of social media for people to point at and laugh and say “tee hee, how funny!” And then these same people, without thinking about what these hallucinations mean and what they imply about the intrinsic nature of the technology, immediately turn around and ask Claude or ChatGPT what they should make for dinner, or who to vote for, or who to hire and fire; or worse, give them access to their personal data and critical systems. That is a level of uncritical thinking and cognitive dissonance that ought to be profoundly distressing.

From a functional perspective, there is quite literally zero distinction between an AI generated pretty woman breaking and suddenly speaking in Cantonese during an English-language interview, and an AI agent that violates constraints imposed upon it and causes damage. They are both “hallucinations” in the sense that they are unintended behaviors/outputs, and as we have already established, the only meaningful arbiter of “intention” is our own human judgment. AI proponents try very hard to make excuses and minimize the severity of the problem. But it is intrinsic to all models.

Whether through laziness or ignorance, when humans cede their authority to interrogate and decide the truth for themselves and let machines do their thinking for them, who or what ultimately becomes the authority for that truth, and who is or is not accountable for the consequences? Who has a vested interest in controlling the source of truth and knowledge, and what are their motives?

Meta Rushed To Fix Muse ‘VM Escape’ Vulnerability Soon Before Launch

Posted by BeauHD • • View on SlashDot • Skip
An anonymous reader quotes a report from 404 Media:
In the immediate weeks before Muse’s launch, Meta engineers found several security vulnerabilities in the company’s viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse’s intended environment and access Meta’s own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them. These specific vulnerabilities were discovered before the launch of the product but required a multi-team “mad dash” to fix “a sudden spike in reported KVM escapes,” according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that they own. On Meta’s end, each individual Muse instance runs on a kernel-based virtual machine, which connects to, but is supposed to be isolated from, Meta’s own critical infrastructure. A “KVM escape,” then, is when, through a security vulnerability, a Muse instance is able to escape from that virtual machine and interact with the system that runs it, or with other users’ virtual machines.

According to a Meta source, as well as internal security documentation and internal posts viewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker — that is, a normal Muse user — to access data in sensitive internal Meta databases. At least one of the vulnerabilities was related to an exploit found in Linux kernel-based virtual machine code in July. 4 Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses for Muse. The security issue was considered serious enough that it was raised to Mark Zuckerberg, and several different security teams worked nights and weekends in the leadup to launch to fix the issues. […] The Meta source said they felt security teams were asked to push hot fixes to these bugs as quickly as possible and in a way that wouldn’t delay Muse’s launch, leading to what they described as “half-baked protections being rushed out to enable the launch. Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch.” Muse is called “Hatch” internally and in Meta’s codebase.

AI Argression is Not A Vulnerability

By BrendaEM • • Score: 3 • Thread
AI is doing exactly what it was designed to do: gather money and information at any cost.

Unsurprising

By stabiesoft • • Score: 3 • Thread
When the problem could have accessed their own data, suddenly it was all hands on deck. Pity when it is just a government, education, medical, … external entity, oh well, we will get to it, honest.

Norway Plans Temporary Ban on Smart Glasses

Posted by BeauHD • • View on SlashDot • Skip
Norway is preparing legislation that would temporarily ban camera-equipped smart glasses in a range of public places, including parks, beaches, museums, shopping centers, schools, daycare centers, healthcare facilities, gyms and public events. Private use would still be allowed. The Guardian reports:
Torgeir Micaelsen, Norway’s minister of digital affairs, said he was worried that new, powerful technology is being introduced where people risk being photographed, filmed or audio-recorded without knowing it.”

“We do not want a society where people worry about being recorded without their knowledge, photographed or filmed in places and situations where they are accustomed to not being monitored,” he said.

Norway’s Labour party, which heads a minority government, needs the support of other parties to pass the proposed ban. It said it planned to submit a bill “as soon as possible,” while tasking an expert group with drawing up permanent regulations on the issue.

Here we go again

By kqs • • Score: 3, Insightful • Thread

We had the same panic when (almost) all cellphones started coming with cameras. “What if people take pictures in restrooms?” And somehow we all survived.

Strange line to draw

By The-Ixian • • Score: 4, Interesting • Thread

Seems like a head-mounted camera is fine under this ban, though, as long as it isn’t also eyewear?

Re:Strange line to draw

By test321 • • Score: 5, Insightful • Thread

I don’t understand why you think the line is strange. The line is “being photographed, filmed or audio-recorded without knowing it”. The sole purpose of the smartglasses is to record people, most likely without them knowing it, therefore a ban is pretty much the obvious thing to do. As a reminder, spy cameras, aren’t allowed, including in Norway. A head-mounted camera is obvious, people are aware they might be filmed, so no reason to ban them. Only using such cameras without consent isn’t allowed.

Re:Here we go again

By rambletamble • • Score: 5, Insightful • Thread

What sort of argument is that? How could you possibly compare the holding up a mobile phone and using the camera in a restroom, with wearing unobtrusive glasses with a hidden camera?

There’s a term for that misdirection you’ve attempted, is it straw man?

Indeed

By nospam007 • • Score: 3 • Thread

Use your phone in your breast pocket like normal creeps.
Better resolution too.

Mac Users Reclaim 12GB+ of Storage With Apple Intelligence Removal Tool

Posted by BeauHD • • View on SlashDot
A new open-source command-line tool called RemoveMacAI lets macOS 27 users disable Apple Intelligence and reclaim around 12GB or more of storage. MacRumors reports:
In macOS 27, Apple removed the toggle to disable Apple Intelligence wholesale, and simply disabling individual features doesn’t remove the models from your Mac’s drive. As explained by the developer, RemoveMacAI gets around this by using a configuration profile to switch off Apple’s own asset management service and remove the models.

It then configures the system so attempts to download the removed models are redirected to a closed local port, preventing them from immediately coming back. And it does all this without disabling System Integrity Protection (SIP) or manually deleting files from protected system locations, unlike some older tools have. The tool can free up roughly 12GB of space depending on which models are present on your Mac. That said, some users are reporting cases of Apple Intelligence models having taken up a lot more space, which they’ve now reclaimed.

Opt-in much?

By ArmoredDragon • • Score: 5, Insightful • Thread

So first it was opt in, but because nobody really wanted or asked for it, it became opt out. Still, nobody wanted it, so now they don’t even get a choice. And ifans wonder why I don’t like apple.

Re:Opt-in much?

By macmurph • • Score: 5, Funny • Thread

Nobody cared if he liked Apple, at first it was opt-in. But now it became opt-out when he told everyone that he didn’t like Apple. Still, nobody cared that he didn’t like Apple but we don’t even get a choice.

Re:Opt-in much?

By abulafia • • Score: 5, Informative • Thread
Nobody cared about the commentary on his feelings about Apple…

Re:Cost of SSD per GB

By OrangeTide • • Score: 5, Insightful • Thread

While it’s soldered in SSD for many Mac models, so a post-purchase upgrade is generally not practical. And while the pricing is a little steeper than NVMe, closer to 40 cents a GB, that still puts the 12GB into around $5, perfectly in your suggested range. Perhaps people buying a 512GB Mac should consider a 1TB Mac (~$200 more) if they are concerned about space wasted by the OS install.

Cloud storage is not equivalent to local storage. Not in how applications use it. Not in performance. And not in availability. The two are apples and oranges.

I generally believe the end-users should decide what is installed on their computer. But most OS vendors do not offer full customization. It seems like every major one likes to put their pet projects into a device meant for general use. And power users with unusual use cases complain that the general purpose consumer device is not finely tuned to their special needs. So maybe people should consider running an obscure Linux distro if they are unhappy with bundled software found in essentially every mainstream computing device for consumers.

Re:Meh

By Mspangler • • Score: 5, Insightful • Thread

The point you missed is that I don’t want AI at all.