Databases

Say Hello To GoogleSQL (nerds.xyz) 32

BrianFagioli writes: Google has quietly retired the ZetaSQL name and rebranded its open source SQL analysis and parsing project as GoogleSQL. This is not a technical change but a naming cleanup meant to align the open source code with the SQL dialect already used across Google products like BigQuery and Spanner. Internally, Google has long called the dialect GoogleSQL, even while the open source project lived under a different name.

By unifying everything under GoogleSQL, Google says it wants to reduce confusion and make it clearer that the same SQL foundation is shared across its cloud services and open source tooling. The code, features, and team remain unchanged. Only the name is different. GoogleSQL is now the single label Google wants developers to recognize and use going forward.

Businesses

Nvidia CEO Denies OpenAI's $100B Investment from Nvidia is 'Stalled' (msn.com) 19

Saturday Nvidia CEO Jensen Huang said they still planned a "huge" investment in OpenAI, according to CNBC.

Friday the Wall Street Journal had reported that Nvidia's plan to invest up to $100 billion in OpenAI "has stalled after some inside the chip giant expressed doubts about the deal, people familiar with the matter said..." [T]he talks haven't progressed beyond the early stages, some of the people said. Now, the two sides are rethinking the future of their partnership, some of the people said. The latest discussions, they said, include an equity investment of tens of billions of dollars as part of OpenAI's current funding round. Nvidia CEO Jensen Huang has privately emphasized to industry associates in recent months that the original $100 billion agreement was nonbinding and not finalized, people familiar with the matter said. He has also privately criticized what he has described as a lack of discipline in OpenAI's business approach and expressed concern about the competition it faces from the likes of Google and Anthropic, some of the people said...

OpenAI is laying the foundation to go public by the end of 2026, and has spent much of the past year racing to secure large amounts of computing capacity to help power OpenAI's future products and growth. The stalled Nvidia pact is a blow to this effort and shows how Chief Executive Sam Altman's penchant for announcing flashy big-ticket deals carries the potential to backfire if the terms have yet to be finalized. In a joint announcement unveiling the September deal with Altman and OpenAI President Greg Brockman, Huang called the deal "the largest computing project in history...." OpenAI went on to sign a string of other agreements with chip and cloud companies that helped fuel a global stock market rally.

But investors have since grown jittery about the startup's ability to pay for these deals, leading to a sell-off in some tech stocks tied to OpenAI. Altman has said that the deals put the startup on the hook for $1.4 trillion in computing commitments — more than 100 times the revenue it was on pace to generate last year. OpenAI executives say the total commitments are lower when you account for overlap in some of the deals, and that the agreements will take place over a long period of time.... Huang has indicated to associates that he still believes it's crucially important to provide OpenAI with financial support in one form or another, in part because OpenAI is one of the chip designer's largest customers, people familiar with the matter said. If OpenAI were to fall behind other AI developers, it could dent Nvidia's sales.

"Speaking to reporters in Taipei, Huang said it was 'nonsense' to say he was unhappy with OpenAI," CNBC reported Saturday: "We are going to make a huge investment in OpenAI. I believe in OpenAI, the work that they do is incredible, they are one of the most consequential companies of our time and I really love working with Sam," he said, referring to OpenAI CEO Sam Altman. "Sam is closing the round (of investment) and we will absolutely be involved," Huang added. "We will invest a great deal of money, probably the largest investment we've ever made."

Asked whether it would be over $100 billion, he said: "No, no, nothing like that."

Elsewhere the Journal has reported that Amazon is in talks to invest up to $50 billion in OpenAI. Thanks to Slashdot reader sinij for sharing the article.
Wireless Networking

Belkin's Wemo Smart Devices Will Go Offline On Saturday 26

Belkin is shutting down cloud support for most Wemo smart home devices on January 31, leaving only Thread-based models and devices already set up in Apple HomeKit functional. Everything else will lose remote access, voice assistant integrations, and future app updates. The Verge reports: The shut down was first announced in July and impacts most Wemo devices, ranging from smart plugs to a coffee maker, with the exception of a handful of Thread-based devices: the 3-way smart light switch (WLS0503), stage smart scene controller (WSC010), smart plug with Thread (WSP100), and smart video doorbell camera (WDC010). Wemo devices configured through Apple's HomeKit will also continue to work, but you have to set them up in HomeKit before January 31st if you want to use that option.

Other affected devices will only work manually after Saturday. If your Wemo device is still under warranty, you may be able to get a partial refund for it after cloud services shut down.
Businesses

'Call Screening is Aggravating the Rich and Powerful' (msn.com) 97

Apple's call-screening feature, introduced in iOS 26 last year, was designed to combat the more than 2 billion robocalls placed to Americans every month, but as WSJ is reporting, it is now creating friction for the rich and powerful who find themselves subjected to automated interrogation when dialing from unrecognized numbers.

The feature uses an automated voice to ask unknown callers for their names and reasons for calling, transcribes the responses, and lets recipients decide whether to answer -- essentially giving everyone a pocket-sized executive assistant.

Venture capitalist Bradley Tusk said his first reaction when encountering call screening is irritation, though he understands the necessity given the spam problem. Ben Schaechter, who runs cloud-cost management company Vantage, said the feature "dramatically changed my life" after his personal number ended up in founding paperwork and attracted endless sales calls.
The Courts

Former Google Engineer Found Guilty of Stealing AI Secrets For Chinese Firms (cbsnews.com) 34

Longtime Slashdot reader schwit1 shares a report from CBS News: A former Google engineer has been found guilty on multiple federal charges for stealing the tech giant's trade secrets on artificial intelligence to benefit Chinese companies he secretly worked for, federal prosecutors said. According to the U.S. Attorney's Office for the Northern District of California, a jury on Thursday convicted Linwei Ding on seven counts of economic espionage and seven counts of theft of trade secrets, following an 11-day trial. The 38-year-old, also known as Leon Ding, was hired by Google in 2019 and was a resident of Newark.

According to evidence presented at trial, Ding stole more than 2,000 pages of confidential information containing Google AI trade secrets between May 2022 and April 2023. He uploaded the information to his personal Google Cloud account. Around the same time, Ding secretly affiliated himself with two Chinese-based technology companies. Around June 2022, prosecutors said Ding was in discussions to be the chief technology officer for an early-stage tech company. Several months later, he was in the process of founding his own AI and machine learning company in China, acting as the company's CEO. Prosecutors said Ding told investors that he could build an AI supercomputer by copying and modifying Google's technology.

In late 2023, prosecutors said Ding downloaded the trade secrets to his own personal computer before resigning from Google. According to the superseding indictment, Google uncovered the uploads after finding out that Ding presented himself as CEO of one of the companies during an Beijing investor conference. Around the same time, Ding told his manager he was leaving the company and booked a one-way flight to Beijing.
"Silicon Valley is at the forefront of artificial intelligence innovation, pioneering transformative work that drives economic growth and strengthens our national security. The jury delivered a clear message today that the theft of this valuable technology will not go unpunished," U.S. Attorney Craig Missakian said in a statement.
Games

Nvidia GeForce NOW Is Now Available Natively On Linux (phoronix.com) 17

NVIDIA has officially launched a native GeForce NOW client for Linux as a Flatpak, giving Linux gamers access to cloud-rendered RTX gaming. Phoronix reports: While confined to a Flatpak, for now NVIDIA is just "officially" supporting it on Ubuntu 24.04 LTS and later. Granted, thanks to Flatpak it should run on other non-Ubuntu distributions too but in terms of the official support and where they are qualifying their builds they are limiting it just to Ubuntu 24.04 LTS and later. [...] At launch the Flatpak build is also just for x86_64 Linux with no AArch64 Linux builds or similar at this time.

Running GeForce NOW on Linux while games are rendered in NVIDIA's cloud with Blackwell GPUs, you still need to be using a modern GPU with H.264 or H.265 Vulkan Video support NVIDIA isn't yet supporting Vulkan Video AV1 with GeForce NOW on Linux but just H.264/H.265. If you are using NVIDIA graphics the NVIDIA R580 series or newer is recommended while using the X.Org session. If you are using Intel or AMD Radeon graphics, Mesa 24.2+ is recommended and using the Wayland session.

When you are up and running with GeForce NOW on Linux, you have access to over 4,500 games. The free tier of GeForce NOW provides standard access to the gaming servers and limited session caps for an introductory-level experience. It's with the performance tier where you can enjoy RTX ray-tracing and 1440p @ 60 FPS performance and up to six hour sessions. With GeForce NOW's Ultimate tier is where you are running on GeForce RTX 5080 GPU servers with support for up to 5K @ 120 FPS gaming or 1080p @ 360 FPS with up to eight hour gaming sessions in length.

Businesses

Amazon Cuts Another 16,000 Jobs (aboutamazon.com) 40

Amazon announced on Wednesday that it is eliminating approximately 16,000 roles across the company as part of organizational changes that began in October 2025 and are only now being finalized by certain teams. Senior Vice President Beth Galetti shared the news in a memo to employees, framing the reductions as an effort to reduce layers, increase ownership, and remove bureaucracy. The memo follows another memo that the company accidentally sent to employees.
Businesses

Amazon Inadvertently Announces Cloud Unit Layoffs In Email To Employees (cnbc.com) 21

Amazon appears to have prematurely acknowledged layoffs inside AWS after an internal email referencing "organizational changes" and "impacted colleagues" was mistakenly sent to cloud employees. CNBC reports: "Changes like this are hard on everyone," Colleen Aubrey, senior vice president of applied AI solutions at Amazon Web Services, wrote in an email viewed by CNBC. "These decisions are difficult and are made thoughtfully as we position our organization and AWS for future success." The note also references a post from Amazon's HR boss Beth Galetti and said the company notified "impacted colleagues in our organization." The subject of the email mentions "Project Dawn," and the email says it was "canceled," possibly indicating it was recalled by the sender after the fact. It's unclear what Project Dawn refers to.

The job cuts come after Amazon announced in October that it would lay off 14,000 corporate employees. At the time, the company indicated the cuts would continue in 2026 as it found "additional places we can remove layers." Amazon CEO Andy Jassy said the layoffs were meant to reduce management layers and bureaucracy inside the company. He also predicted last June that efficiency gains from AI would shrink Amazon's corporate staff in the coming years.

Science

OpenAI Releases Prism, a Claude Code-Like App For Scientific Research (engadget.com) 15

OpenAI has launched Prism, a free scientific research app that aims to do for scientific writing what coding agents did for programming. Engadget reports: Prism builds on Crixet, a cloud-based LaTeX platform the company is announcing it acquired today. For the uninitiated, LaTeX is a typesetting system for formatting scientific documents and journals. Nearly the entire scientific community relies on LaTeX, but it can make some tasks, such as drawing diagrams through TikZ commands, time-consuming to do. Beyond that, LaTeX is just one of the software tools a scientist might turn to when preparing to publish their research.

That's where Prism comes into the picture. Like Crixet before it, the app offers robust LaTeX editing and a built-in AI assistant. Where previously it was Crixet's own Chirp agent, now it's GPT-5.2 Thinking. OpenAI's model can help with more than just formatting journals -- in a press demo, an OpenAI employee used it to find and incorporate scientific literature that was relevant to the paper they were working on, with GPT-5.2 automating the process of writing the bibliography. [...] Later in the same demo, the OpenAI employee used Prism to generate a lesson plan for a graduate course on general relativity, as well as a set of problems for students to solve. OpenAI envisions these features helping scientists and professors spend less time on the more tedious tasks in their professions.

AI

Pinterest Cuts Up To 15% Jobs To Redirect Resources To AI (reuters.com) 19

Pinterest said on Tuesday it would trim its workforce by less than 15% and reduce office space, as the social media company looks to reallocate resources to AI-focused roles and initiatives. From a report: The announcement comes as the company competes with TikTok and Meta-owned Facebook and Instagram for digital advertising budgets, as these platforms continue to draw marketers with their extensive user base.

Pinterest had 5,205 full-time employees as of September 2025. The latest job cut would translate to less than 780 positions. Top executives at the World Economic Forum's annual meeting said while jobs would disappear, new ones would spring up, with two telling Reuters that AI would be used as an excuse by companies which were planning layoffs anyway. Last week, design software maker Autodesk also announced a 7% job cut to redirect investments to its cloud platform and AI efforts.

XBox (Games)

Microsoft Is Refreshing the Xbox Cloud Gaming Web Experience (thurrott.com) 3

An anonymous reader quotes a report from Thurrott: Microsoft is testing a refresh of the Xbox Cloud Gaming web experience in public preview. "This preview is a first look at our new web interface on your browser and lets you try the updated design and product flow before it is rolled out broadly," Microsoft's Patrick Siu explains. "Players who opt in to this preview will see some changes to their experience including updated navigation features and a refreshed look and feel. As this is a preview, some functions may not yet be available or may behave differently than the current web experience. We will continue iterating during the preview period and changes may be made over time."

[...] There's no real info about what's in the new experience, oddly. Microsoft notes only that it "lays the foundation for accelerating [their] ability to build new experiences for players," and that it "helps [them] validate the new web platform and refine the experience for everyone."
The public preview can be found at xbox.com/play.
AI

Microsoft's Latest AI Chip Claims Performance Edge Over Amazon and Google (geekwire.com) 18

An anonymous reader quotes a report from GeekWire: Microsoft on Monday announced Maia 200, the second generation of its custom AI chip, claiming it's the most powerful first-party silicon from any major cloud provider. The company says Maia 200 delivers three times the performance of Amazon's latest Trainium chip on certain benchmarks, and exceeds Google's most recent tensor processing unit (TPU) on others. The chip is already running workloads at Microsoft's data center near Des Moines, Iowa. Microsoft says Maia 200 is powering OpenAI's GPT-5.2 models, Microsoft 365 Copilot, and internal projects from its Superintelligence team. A second deployment at a data center near Phoenix is planned next.

It's part of the larger trend among cloud giants to build their own custom silicon for AI rather than rely solely on Nvidia. [...] The company says Maia 200 offers 30% better performance-per-dollar than its current hardware. Maia 200 also builds on the first-generation chip with a more specific focus on inference, the process of running AI models after they've been trained. [...] Microsoft is also opening the door to outside developers. The company announced a software development kit that will let AI startups and researchers optimize their models for Maia 200. Developers and academics can sign up for an early preview starting today.

Printer

Washington State May Mandate 'Firearm Blueprint Detection Algorithms' For 3D Printers (adafruit.com) 123

Adafruit managing director Phillip Torrone (also long-time Slashdot reader ptorrone ) writes: Washington State lawmakers are proposing bills (HB 2320 and HB 2321) that would require 3D printers and CNC machines to block certain designs using software-based "firearms blueprint detection algorithms." In practice, this means scanning every print file, comparing it against a government-maintained database, and preventing "skilled users" from bypassing the system.

Supporters frame this as a response to untraceable "ghost guns," but even federal prosecutors admit the tools involved are ordinary manufacturing equipment. Critics warn the language is overbroad, technically unworkable, hostile to open source, and likely to push printing toward cloud-locked, subscription-based systems—while doing little to stop criminals.

Microsoft

Microsoft 365 Endured 9+ Hours of Outages Thursday (crn.com) 36

Early Friday "there were nearly 113 incidents of people reporting issues with Microsoft 365 as of 1:05 a.m. ET," reports Reuters. But that's down "from over 15,890 reports at its peak a day earlier, according to Downdetector." Reuters points out the outage affected antivirus software Microsoft Defender and data governance software Microsoft Purview, while CRN notes it also impacted "a number of Microsoft 365 services" including Outlook and Exchange online: During the outage, Outlook users received a "451 4.3.2 temporary server issue" error message when attempting to send or receive email. Users did not have the ability to send and receive email through Exchange Online, including notification emails from Microsoft Viva Engage, according to the vendor. Other issues that cropped up include an inability to send and receive subscription email through [analytics platform] Microsoft Fabric, collect message traces, search within SharePoint online and Microsoft OneDrive and create chats, meetings, teams, channels or add members in Microsoft Teams...

As with past cloud outages with other vendors, even after Microsoft fixed the issues, recovery efforts by its users to return to a normal state took additional time... Microsoft confirmed in a post on X [Thursday] at 4:14 p.m. ET that it "restored the affected infrastructure to a (healthy) state" but "further load balancing is required to mitigate impact...." The company reported "residual imbalances across the environment" at 7:02 p.m., "restored access to the affected services" and stable mail flow at 12:33 a.m. Jan. 23. At that time, Microsoft still saw a "small number of remaining affected services" without full service stability. The company declared impact from the event "resolved" at 1:29 p.m. Eastern. Microsoft sent out another X post at 8:20 a.m. asking users experiencing residual issues to try "clearing local DNS caches or temporarily lowering DNS TTL values may help ensure a quicker remediation...."

Microsoft said in an admin center update that [Thursday's] outage was "caused by elevated service load resulting from reduced capacity during maintenance for a subset of North America hosted infrastructure." Furthermore, Microsoft noted that during "ongoing efforts to rebalance traffic" it introduced a "targeted load balancing configuration change intended to expedite the recovery process, which incidentally introduced additional traffic imbalances associated with persistent impact for a portion of the affected infrastructure." US itek's David Stinner said it appears that Microsoft did not have enough capacity on its backup system while doing maintenance on its main system. "It looks like the backup system was overloaded, and it brought the system down while they were still doing maintenance on the main system," he said. "That is why it took so many hours to get back up and running. If your primary system is down for maintenance and your backup system fails due to capacity issues, then it is going to take a while to get your primary system back up and running."

"This was not Microsoft's first outage of 2026," the article notes, "with the vendor handling access issues with Teams, Outlook and other M365 services on Wednesday, a Copilot issue on Jan. 15 plus an Azure outage earlier in the month..."
Encryption

Microsoft Gave FBI a Set of BitLocker Encryption Keys To Unlock Suspects' Laptops (techcrunch.com) 88

An anonymous reader quotes a report from TechCrunch: Microsoft provided the FBI with the recovery keys to unlock encrypted data on the hard drives of three laptops as part of a federal investigation, Forbes reported on Friday. Many modern Windows computers rely on full-disk encryption, called BitLocker, which is enabled by default. This type of technology should prevent anyone except the device owner from accessing the data if the computer is locked and powered off.

But, by default, BitLocker recovery keys are uploaded to Microsoft's cloud, allowing the tech giant -- and by extension law enforcement -- to access them and use them to decrypt drives encrypted with BitLocker, as with the case reported by Forbes. The case involved several people suspected of fraud related to the Pandemic Unemployment Assistance program in Guam, a U.S. island in the Pacific. Local news outlet Pacific Daily News covered the case last year, reporting that a warrant had been served to Microsoft in relation to the suspects' hard drives.

Kandit News, another local Guam news outlet, also reported in October that the FBI requested the warrant six months after seizing the three laptops encrypted with BitLocker. [...] Microsoft told Forbes that the company sometimes provides BitLocker recovery keys to authorities, having received an average of 20 such requests per year.

EU

EU Parliament Calls For Detachment From US Tech Giants (heise.de) 102

The European Parliament is calling on the European Commission to reduce dependence on U.S. tech giants by prioritizing EU-based cloud, AI, and open-source infrastructure. The report frames "European Tech First," public procurement reform, and Public Money, Public Code as necessary self-defense against growing U.S. control over critical digital infrastructure. Heise reports: In terms of content, the report focuses on a strategic reorientation of public procurement and infrastructure. The compromise line adopted stipulates that member states can favor European tech providers in strategic sectors to systematically strengthen the technological capacity of the Community. The Greens even called for a stricter regulation here, where the use of products "Made in EU" should become the rule and exceptions would have to be explicitly justified. They also pushed for a definition for cloud infrastructure that provides for full EU jurisdiction without dependencies on third countries.

With the decision, the MEPs want to lay the foundation for a European digital public infrastructure based on open standards and interoperability. The principle of Public Money, Public Code is anchored as a strategic foundation to reduce dependence on individual providers. Software specifically developed for administration with tax money should therefore be made available to everyone under free licenses. For financing, the Parliament relies on the expansion of public-private investments. A "European Sovereign Tech Fund" endowed with ten billion euros was discussed beforehand, for example, to specifically build strategic infrastructures that the market does not provide on its own. The shadow rapporteur for the Greens, Alexandra Geese, sees Europe ready to take control of its digital future with the vote. As long as European data is held by US providers subject to laws such as the Cloud Act, security in Europe is not guaranteed.

Microsoft

Microsoft's Xbox Cloud Gaming May Soon Let You Stream Your Own Games for Free - If You Watch Ads (windowscentral.com) 6

Microsoft appears to be preparing an ad-supported tier for Xbox Cloud Gaming that would let players stream games they've purchased digitally without needing a Game Pass subscription, according to a Windows Central report citing sources familiar with the plans. Users last week began noticing a new message pop up while launching cloud games that referenced "1 hour of ad supported play time per session," though no such tier currently exists.

The ad-supported option, expected to launch sometime this year, would specifically target the hundreds of games available for digital purchase through Xbox Cloud Gaming -- titles that currently require at least one tier of Game Pass to stream despite being owned outright by the player.
Businesses

ERP Isn't Dead Yet - But Most Execs Are Planning the Wake (theregister.com) 33

Seven out of ten C-suite executives believe traditional enterprise resource planning software has seen its best days, though the category remains firmly entrenched in corporate IT and opinion is sharply divided on what comes next. A survey of 4,295 CFOs, CISOs, CIOs and CEOs worldwide found 36% expect ERP to give way to composable, API-driven best-of-breed systems, while 33% see the future in "agentic ERP" featuring autonomous AI-driven decision-making.

The research was commissioned by Rimini Street, a third-party support provider for Oracle and SAP. Despite the pessimism, 97% said their current systems met business requirements. Vendor lock-in remains a sore point: 35% cited limited flexibility and forced upgrades as frustrations. Kingfisher, operator of 2,000 European retail stores including Screwfix and B&Q, recently eschewed an SAP upgrade in favor of using third-party support to shift its existing application to the cloud. Gartner analyst Dixie John cautioned that while third-party support may work in the short or medium term, organizations will eventually need to upgrade.
EU

Hundreds Answer Europe's 'Public Call for Evidence' on an Open Digital Ecosystem Strategy (helpnetsecurity.com) 30

The European Commission "has opened a public call for evidence on European open digital ecosystems," writes Help Net Security, part of preparations for an upcoming Communication "that will examine the role of open source in EU's digital infrastructure." The consultation runs from January 6 to February 3, 2026. Submissions will be used to shape a Commission Communication addressed to the European Parliament, the Council, and other EU bodies, which is scheduled for publication in the first quarter of 2026... The call for evidence links Europe's reliance on digital technologies developed outside the EU to concerns over long term control of infrastructure and software supply chains... Open digital ecosystems are discussed in the context of technological sovereignty and the use of technologies that can be inspected, adapted, and shared.
Long-time Slashdot reader Elektroschock describes it as the European Commission "stepping up its efforts behind open-source software" Building on President von der Leyen's political guidelines, the initiative will review the Commission's 2020-2023 open-source approach and set out concrete actions to strengthen Europe's open-source ecosystem across key areas such as cloud, AI, cybersecurity and industrial technologies. The strategy will be presented alongside the upcoming Cloud and AI Development Act, forming a broader policy package aimed at reducing strategic dependencies and boosting Europe's digital resilience.
And "In just a few days, over 370 submissions have already been filed, indicating that the issue is touching a nerve across the EU," writes CyberNews.com: "Europe must regain control over its software supply chain to safeguard freedom, security, and innovation," suggests an individual from Slovakia. Similar perspectives appear to be widely shared among respondents...

The document doesn't mention US tech giants specifically, but rather aims to support tech sovereignty and seek "digital solutions that are valid alternatives to proprietary ones...."

"This is not a legislative initiative. The strategy will take the form of a Commission communication. The initiative will set out a general approach and will propose: actions relying on further commitments and an implementation process," the EC explains. Policymakers expect the strategy to help EU member states identify the necessary steps to support national open-source companies and communities.

Security

To Pressure Security Professionals, Mandiant Releases Database That Cracks Weak NTLM Passwords in 12 Hours (arstechnica.com) 34

Ars Technica reports: Security firm Mandiant [part of Google Cloud] has released a database that allows any administrative password protected by Microsoft's NTLM.v1 hash algorithm to be hacked in an attempt to nudge users who continue using the deprecated function despite known weaknesses.... a precomputed table of hash values linked to their corresponding plaintext. These generic tables, which work against multiple hashing schemes, allow hackers to take over accounts by quickly mapping a stolen hash to its password counterpart... Mandiant said it had released an NTLMv1 rainbow table that will allow defenders and researchers (and, of course, malicious hackers, too) to recover passwords in under 12 hours using consumer hardware costing less than $600 USD. The table is hosted in Google Cloud. The database works against Net-NTLMv1 passwords, which are used in network authentication for accessing resources such as SMB network sharing.

Despite its long- and well-known susceptibility to easy cracking, NTLMv1 remains in use in some of the world's more sensitive networks. One reason for the lack of action is that utilities and organizations in industries, including health care and industrial control, often rely on legacy apps that are incompatible with more recently released hashing algorithms. Another reason is that organizations relying on mission-critical systems can't afford the downtime required to migrate. Of course, inertia and penny-pinching are also causes.

"By releasing these tables, Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1," Mandiant said. "While tools to exploit this protocol have existed for years, they often required uploading sensitive data to third-party services or expensive hardware to brute-force keys."

"Organizations that rely on Windows networking aren't the only laggards," the article points out. "Microsoft only announced plans to deprecate NTLMv1 last August."

Thanks to Slashdot reader joshuark for sharing the news.

Slashdot Top Deals