The Almighty Buck

Filipinos Are Addicted to Online Gambling. So Is Their Government (msn.com) 27

The Philippines became Asia's second-largest gambling hub after Macau last year as online betting proliferated across the archipelagic nation. Almost half of the country's 69 million working-age population is now registered on gambling apps, an exponential rise from less than half a million users in 2018. The government has become increasingly dependent on the industry.

Philippine Amusement and Gaming Corp. collects 30% of gross gaming revenue and has become the second-biggest revenue contributor among state-run companies after Land Bank of the Philippines. Revenue from online casino license fees is projected to reach $1 billion in 2025. More than 60 operators are regulated by the government.

Industry revenue almost tripled in 2024 from 2023 to 154.5 billion pesos. Revenue from internet betting eclipsed physical casinos for the first time this year. The central bank recently ordered e-wallets to remove links to betting sites, halving bets within days. President Ferdinand Marcos Jr. rejected calls for a complete ban and said outlawing online betting would only spawn illicit operations that would be more difficult to eradicate.
The Internet

Curiosity Drives Viewers To Ignore Trigger Warnings (phys.org) 155

alternative_right shares a report from Phys.org: For the first time, a new study has tested the effectiveness of trigger warnings in real life scenarios, revealing that the vast majority of young adults choose to ignore them. A new Flinders University study has found that nearly 90% of young people who saw a trigger warning still chose to view the content, saying that they did so out of curiosity, rather than because they felt emotionally prepared or protected. The findings published in the Journal of Behavior Therapy and Experimental Psychiatry aligned with a growing body of lab-based research suggesting that trigger warnings rarely lead to the avoidance of potentially distressing material.
Privacy

Reddit Mods Sued By YouTuber Ethan Klein Fight Efforts To Unmask Them (404media.co) 104

alternative_right shares a report from 404 Media: Critics of YouTuber Ethan Klein are pushing back on subpoenas that would reveal their identities as part of an ongoing legal fight between Klein and his detractors. Klein is a popular content creator whose YouTube channel has more than 2 million subscribers. He's also involved in a labyrinthine personal and legal beef with three other content creators and the moderators of a subreddit that criticizes his work. Klein filed a legal motion to compel Discord and Reddit to reveal the identities of those moderators, a move their lawyers say would put them in harm's way and stifle free speech on the internet forever.

[...] On July 31, a judge allowed Klein's lawyers to file a subpoena with Reddit and Discord that would reveal the identities of the people running r/h3snark and an associated Discord server. On September 22, lawyers for the defendants filed a motion to quash the subpoenas. "On its face, the Action is about copyright infringement," the latest filing said. "At its heart, however, the Action is about stifling criticism and seeking retribution by unmasking individuals for perceived reputational harms TEI [Klein's production company] attributes to [John Doe moderators] unrelated to TEI's intellectual property rights." [...]

The anonymity of places like Reddit and Discord grant a layer of protection to people seeking to critique power. This case could set a dangerous precedent, the lawyers believe. "If the court allows TEI's Subpoenas, it would enable TEI to impose a considerable price on Does' use of the vehicle of anonymous speech -- including public exposure, real risks of retaliation and actual harm, and the financial and other burdens of defending the Action," the filing said. The filing added: "Very few would-be commentators are prepared to bear costs of this magnitude. So, when word gets out that the price tag of criticizing Ethan is this high -- that speech will disappear. But that is precisely what Ethan Klein wants."

The Internet

Afghanistan Hit By Nationwide Internet Blackout As Taliban Cuts Fiber Optic Cables (bbc.com) 76

The Taliban have imposed a nationwide telecommunications shutdown in Afghanistan, severing fibre-optic connections and cutting off internet, mobile, and satellite services as part of "morality" measures. Netblock is currently tracking the outages. The BBC reports: Since seizing power in 2021, the Taliban have imposed numerous restrictions in accordance with their interpretation of Islamic Sharia law. Flights from Kabul airport have also been disrupted, according to reports. Several people in Kabul have told the BBC that their fibre-optic internet stopped working towards the end of the working day, around17:00 local time (12:30 GMT). Because of this, it is understood many people will not notice the impact until Tuesday morning, when banking services and other businesses are due to resume. [...]

The Taliban earlier said an alternative route for internet access would be created, without giving any details. Business leaders at the time warned that if the internet ban continued their activities would be seriously hit. Hamid Haidari, former editor-in-chief of Afghan news channel 1TV, said after the shutdown that "loneliness enveloped the entire country." "Afghanistan has now officially taken first place in the competition with North Korea for [internet] disconnection" he said on X.

Science

Wall Street Journal Decries 'The Rise of Conspiracy Physics' (msn.com) 213

"The internet is full of people claiming to uncover conspiracies in politics and business..." reports the Wall Street Journal.

"Now an unlikely new villain has been added to the list: theoretical physicists," they write, saygin resentment of scientific authority figures "is the major attraction of what might be called 'conspiracy physics'." In recent years, a group of YouTubers and podcasters have attracted millions of viewers by proclaiming that physics is in crisis. The field, they argue, has discovered little of importance in the last 50 years, because it is dominated by groupthink and silences anyone who dares to dissent from mainstream ideas, like string theory... Most fringe theories are too arcane for listeners to understand, but anyone can grasp the idea that academic physics is just one more corrupt and self-serving establishment... In this corner of the internet, the scientist Scott Aaronson has written, "Anyone perceived as the 'mainstream establishment' faces a near-insurmountable burden of proof, while anyone perceived as 'renegade' wins by default if they identify any hole whatsoever in mainstream understanding...

As with other kinds of authorities, there are reasonable criticisms to be made of academic physics. By some metrics, scientific productivity has slowed since the 1970s. String theory has not fulfilled physicists' early dreams that it would become the ultimate explanation of all forces and matter in our universe. The Large Hadron Collider, the world's largest particle accelerator, has delivered fewer breakthroughs than scientists expected when it turned on in 2010. But even reasonable points become hard to recognize when expressed in the ways YouTube incentivizes. Conspiracy physics videos with titles like "They Just Keep Lying" are full of sour sarcasm, outraged facial expressions and spooky music...

Leonard Susskind, director of the Stanford Institute for Theoretical Physics, says physicists need to be both more sober and more forceful when addressing the public. The limits of string theory should be acknowledged, he says, but the idea that progress has slowed isn't right. In the last few decades, he and other physicists have figured out how to make progress on the vast project of integrating general relativity and quantum mechanics, the century-old pillars of physics, into a single explanation of the universe.

The bitter attacks on leading physicists get a succinct summary in the article from Chris Williamson, a "Love Island" contestant turned podcast host. "This is like 'The Kardashians' for physicists — I love it."
The Internet

Tim Berners-Lee Urges New Open-Source Interoperable Data Standard, Protections from AI (theguardian.com) 29

Tim Berners-Lee writes in a new article in the Guardian that "Somewhere between my original vision for web 1.0 and the rise of social media as part of web 2.0, we took the wrong path Today, I look at my invention and I am forced to ask: is the web still free today? No, not all of it. We see a handful of large platforms harvesting users' private data to share with commercial brokers or even repressive governments. We see ubiquitous algorithms that are addictive by design and damaging to our teenagers' mental health. Trading personal data for use certainly does not fit with my vision for a free web. On many platforms, we are no longer the customers, but instead have become the product. Our data, even if anonymised, is sold on to actors we never intended it to reach, who can then target us with content and advertising...

We have the technical capability to give that power back to the individual. Solid is an open-source interoperable standard that I and my team developed at MIT more than a decade ago. Apps running on Solid don't implicitly own your data — they have to request it from you and you choose whether to agree, or not. Rather than being in countless separate places on the internet in the hands of whomever it had been resold to, your data is in one place, controlled by you. Sharing your information in a smart way can also liberate it. Why is your smartwatch writing your biological data to one silo in one format? Why is your credit card writing your financial data to a second silo in a different format? Why are your YouTube comments, Reddit posts, Facebook updates and tweets all stored in different places? Why is the default expectation that you aren't supposed to be able to look at any of this stuff? You generate all this data — your actions, your choices, your body, your preferences, your decisions. You should own it. You should be empowered by it...

We're now at a new crossroads, one where we must decide if AI will be used for the betterment or to the detriment of society. How can we learn from the mistakes of the past? First of all, we must ensure policymakers do not end up playing the same decade-long game of catchup they have done over social media. The time to decide the governance model for AI was yesterday, so we must act with urgency. In 2017, I wrote a thought experiment about an AI that works for you. I called it Charlie. Charlie works for you like your doctor or your lawyer, bound by law, regulation and codes of conduct. Why can't the same frameworks be adopted for AI? We have learned from social media that power rests with the monopolies who control and harvest personal data. We can't let the same thing happen with AI.

Berners-Lee also says "we need a Cern-like not-for-profit body driving forward international AI research," arguing that if we muster the political willpower, "we have the chance to restore the web as a tool for collaboration, creativity and compassion across cultural borders.

"We can re-empower individuals, and take the web back. It's not too late."

Berners-Lee has also written a new book titled This is For Everyone.
Facebook

Facebook and Instagram Offer UK Users an Ad-Stopping Subscription Fee (bbc.com) 24

"Facebook and Instagram owner Meta is launching paid subscriptions for users who do not want to see adverts in the UK," reports the BBC: The company said it would start notifying users in the coming weeks to let them choose whether to subscribe to its platforms if they wish to use them without seeing ads. EU users of its platforms can already pay a fee starting from €5.99 (£5) a month to see no ads — but subscriptions will start from £2.99 a month for UK users.

"It will give people in the UK a clear choice about whether their data is used for personalised advertising, while preserving the free access and value that the ads-supported internet creates for people, businesses and platforms," Meta said. But UK users will not have an option to not pay and see "less personalised" adverts — a feature Meta added for EU users after regulators raised concerns...

Meta said its own model would see its subscription for no ads cost £2.99 a month on the web or £3.99 a month on iOS and Android apps — with the higher fee to offset cuts taken from transactions by Apple and Google... [Meta] reiterated its critical stance on the EU on Friday, saying its regulations were creating a worse experience for users and businesses unlike the UK's "more pro-growth and pro-innovation regulatory environment".

"Meta said its own model would see its subscription for no ads cost £2.99 a month on the web or £3.99 a month on iOS and Android apps," according to the BBC, "with the higher fee to offset cuts taken from transactions by Apple and Google."

Even users not paying for an ad-free experience have "tools and settings that empower people to control their ads experience," according to Meta's announcement. The include Ad Preferences which influences data used to inform ads including Activity Information from Ad Partners. "We also have tools in our products that explain 'Why am I seeing this ad?' and how people can manage their ad experience. We do not sell personal data to advertisers."
Transportation

SFMTA Scambles To Shut Down Viral Parking Ticket Tracker (sfgate.com) 34

An anonymous reader quotes a report from SFGATE: It had all the makings of a viral X post, and viral it did go, with over 8 million views in under 24 hours. The message was straightforward: "I reverse engineered the San Francisco parking ticket system. I can see every ticket seconds after it's written." Underneath it was a familiar image for any iPhone user -- an Apple map of the city dotted with gray, initialed bubbles, and an explanation: "So I made a website. Find My Friends?" No. "AVOID THE PARKING COPS." The anarchy, however, was short-lived. [...]

Given the potential lost revenue at stake, the San Francisco Municipal Transportation Agency caught on like the rest of the internet, and by Tuesday afternoon, the site had been quickly rendered obsolete. Undeterred, [creator of the site, Riley Walz] restored the site again after 10 p.m., though this, too, didn't last. By his estimation, it was only active for a few more hours. "We made sure that all access to citation data was via authorized routes," said Erica Kato, a spokesperson for SFMTA, in an email to SFGATE. "But when our staff's safety, and personal information of people who have received parking citations, is at risk, we must act on that swiftly."

Yet the saga wasn't over. By Wednesday, the official SFMTA ticket payment site was also down, citing "maintenance." "I'm curious what was going on there," said Walz over the phone. "If it is even because of me." As of Wednesday afternoon, that site is functional and the chaos seems over for now. According to SFMTA, there is no need for a site like Walz's."The official way to access our parking citation data is via our public website on DataSF," Kato said. "Anyone is still able to see [the] type of citation, date of issuance and data that can be mapped and analyzed on DataSF daily."

United States

Did the US Successfully Take Over TikTok, Or Not? (apnews.com) 58

Longtime Slashdot reader hackingbear writes: President Donald Trump signed an executive order Thursday that he says will allow TikTok to continue operating in the United States in a way that meets national security concerns. Trump's order will enable an American-led of group of investors to "buy the app" (up to 80% ownership) from China's ByteDance, though the deal is not yet finalized and also requires China's approval. However, much about the deal is still unknown. So, did the U.S. successfully snatch TikTok from ByteDance? It is probably up to individual's interpretation.

As with any deals between U.S. and China, the devil is in the details. According Shen Yi, an internet influencer and a professor at Shanghai's Fudan University, what the U.S. investor will eventually take control of is an entity known as TikTok U.S. Data Security Company ("USDS"), which is a subsidiary of TikTok U.S. and is exclusively responsible to handle data security in the U.S.. ByteDance will continue, through its U.S. subsidiary "ByteDance TikTok U.S. Company," to operate business and other related activities (such as e-commerce, advertising for brands, and cross-border commercial activities). It is important to stress that "Byte TikTok U.S. Company" remains 100% owned by ByteDance through its global TikTok subsidiary -- this arrangement has not changed. The TikTok algorithm remains the property of ByteDance, only licensed to USDS for use. This point was in fact explicitly clarified by a relevant official of China's Cyberspace Administration at the press conference following the Madrid talks.

After reaching the TikTok deal, Beijing and Washington are now selling it to their respective domestic audience, each highlighting the part of the deal that it can characterize as a win. Shen's details are not in conflict with the widely-reported account given by Karoline Leavitt, the White House Press Secretary, who emphasized "a new board with six American directors out of seven." Observers can also find the TikTok arrangement being very similar to that of Apple's iCloud operation in China being run by GCBD (AIPO Cloud (Guizhou) Technology Co. Ltd.) while Apple retain controls of the brand and business.

The Internet

Cloudflare To Launch Stablecoin for AI-Driven Internet Economy (nerds.xyz) 21

Cloudflare announced plans Thursday to launch NET Dollar, a U.S. dollar-backed stablecoin designed to enable autonomous AI agents to conduct instant financial transactions. The company says the stablecoin will support microtransactions and pay-per-use models as AI agents take over tasks like booking flights and ordering groceries. BrianFagioli comments: A U.S. dollar-backed cryptocurrency from Cloudflare feels unusual to me, and I'm still surprised by it. The decision shows just how much the Internet is shifting in response to artificial intelligence.

CEO Matthew Prince said, "For decades, the business model of the Internet ran on ad platforms and bank transfers. The Internet's next business model will be powered by pay-per-use, fractional payments, and microtransactions -- "tools that shift incentives toward original, creative content that actually adds value." He added that by using its global network, Cloudflare aims to "help modernize the financial rails needed to move money at the speed of the Internet."

Facebook

Facebook Data Reveal the Devastating Real-World Harms Caused By the Spread of Misinformation (theconversation.com) 174

An anonymous reader quotes a report from The Conversation: Twenty-one years after Facebook's launch, Australia's top 25 news outlets now have a combined 27.6 million followers on the platform. They rely on Facebook's reach more than ever, posting far more stories there than in the past. With access to Meta's Content Library (Meta is the owner of Facebook), our big data study analysed more than three million posts from 25 Australian news publishers. We wanted to understand how content is distributed, how audiences engage with news topics, and the nature of misinformation spread. The study enabled us to track de-identified Facebook comments and take a closer look at examples of how misinformation spreads. These included cases about election integrity, the environment (floods) and health misinformation such as hydroxychloroquine promotion during the COVID pandemic. The data reveal misinformation's real-world impact: it isn't just a digital issue, it's linked to poor health outcomes, falling public trust, and significant societal harm. [...]

Our study has lessons for public figures and institutions. They, especially politicians, must lead in curbing misinformation, as their misleading statements are quickly amplified by the public. Social media and mainstream media also play an important role in limiting the circulation of misinformation. As Australians increasingly rely on social media for news, mainstream media can provide credible information and counter misinformation through their online story posts. Digital platforms can also curb algorithmic spread and remove dangerous content that leads to real-world harms. The study offers evidence of a change over time in audiences' news consumption patterns. Whether this is due to news avoidance or changes in algorithmic promotion is unclear. But it is clear that from 2016 to 2024, online audiences increasingly engaged with arts, lifestyle and celebrity news over politics, leading media outlets to prioritize posting stories that entertain rather than inform. This shift may pose a challenge to mitigating misinformation with hard news facts. Finally, the study shows that fact-checking, while valuable, is not a silver bullet. Combating misinformation requires a multi-pronged approach, including counter-messaging by trusted civic leaders, media and digital literacy campaigns, and public restraint in sharing unverified content.

The Internet

Europe's Cookie Law Messed Up the Internet. Brussels Wants To Fix It. (politico.eu) 102

In a bid to slash red tape, the European Commission wants to eliminate one of its peskiest laws: a 2009 tech rule that plastered the online world with pop-ups requesting consent to cookies. From a report: It's the kind of simplification ordinary Europeans can get behind. European rulemakers in 2009 revised a law called the e-Privacy Directive to require websites to get consent from users before loading cookies on their devices, unless the cookies are "strictly necessary" to provide a service. Fast forward to 2025 and the internet is full of consent banners that users have long learned to click away without thinking twice.

"Too much consent basically kills consent. People are used to giving consent for everything, so they might stop reading things in as much detail, and if consent is the default for everything, it's no longer perceived in the same way by users," said Peter Craddock, data lawyer with Keller and Heckman. Cookie technology is now a focal point of the EU executive's plans to simplify technology regulation. Officials want to present an "omnibus" text in December, scrapping burdensome requirements on digital companies. On Monday, it held a meeting with the tech industry to discuss the handling of cookies and consent banners.

Botnet

Record-Breaking DDoS Attack Peaks At 22 Tbps and 10 Bpps 24

Cloudflare blocked the largest-ever DDoS attack against a European network infrastructure company, which peaked at 22.2 Tbps and 10.6 Bpps. The hyper-volumetric attack has been linked to the Aisuru botnet and lasted just 40 seconds, but was double the size of the previous record. SecurityWeek reports: Cloudflare told SecurityWeek that the attack was aimed at a single IP address of an unnamed European network infrastructure company. Cloudflare has yet to determine who was behind the attack, but believes it may have been powered by the Aisuru botnet, which was also linked earlier this year to a massive 6.3 Tbps attack on the website of cybersecurity blogger Brian Krebs. Aisuru has been around for more than a year. The botnet is powered by hacked IoT devices such as routers and DVRs that have been compromised through the exploitation of known and zero-day vulnerabilities.

According to Cloudflare, the 22 Tbps attack was traced to over 404,000 unique source IPs across over 14 ASNs worldwide. "Based on internal analysis using a proprietary system, the source IPs were not spoofed," the company explained. The security firm described it as a UDP carpet bomb attack targeting an average of 31,000 destination ports per second, with a peak of 47k ports, all of a single IP address. Cloudflare revealed in July that the number of DDoS attacks it blocked in the first half of 2025 had already exceeded all the attacks mitigated in 2024.
The Internet

Cloudflare Launches Content Signals Policy To Fight AI Crawlers and Scrapers 24

BrianFagioli shares a report from NERDS.xyz: Cloudflare has unveiled the Content Signals Policy, a free addition to its managed robots.txt service that aims to give website owners and publishers more control over how their content is accessed and reused by AI companies. The idea is pretty simple: robots.txt already lets site operators specify which crawlers can enter and where. Cloudflare's new policy adds a layer that signals how the data may be used once accessed, with plain-language terms for search, AI input, and AI training. "Yes" means allowed, "no" means not allowed, and no signal means no preference.

Matthew Prince, Cloudflare's co-founder and CEO, said: "The Internet cannot wait for a solution, while in the meantime, creators' original content is used for profit by other companies. To ensure the web remains open and thriving, we're giving website owners a better way to express how companies are allowed to use their content." Cloudflare says more than 3.8 million domains already use its robots.txt tools to signal they don't want their content used for AI training. Now, the Content Signals Policy makes those preferences clearer and potentially enforceable.
Further reading: Cloudflare Flips AI Scraping Model With Pay-Per-Crawl System For Publishers
Google

Google Experiences Deja Vu As Second Monopoly Trial Begins In US 4

An anonymous reader quotes a report from The Guardian: After deflecting the US Department of Justice's attack on its illegal monopoly in online search, Google is facing another attempt to dismantle its internet empire in a trial focused on abusive tactics in digital advertising. The trial that opened Monday in an Alexandria, Virginia, federal court revolves around the harmful conduct that resulted in US district Judge Leonie Brinkema declaring parts of Google's digital advertising technology to be an illegal monopoly in April. The judge found that Google has been engaging in behavior that stifles competition to the detriment of online publishers that depend on the system for revenue.

Google and the justice department will spend the next two weeks in court presenting evidence in a "remedy" trial that will culminate in Brinkema issuing a ruling on how to restore fair market conditions. If the justice department gets its way, Brinkema will order Google to sell parts of its ad technology -- a proposal that the company's lawyers warned would "invite disruption and damage" to consumers and the internet's ecosystem. The justice department contends a breakup would be the most effective and quickest way to undercut a monopoly that has been stifling competition and innovation for years. [...]

The case, filed in 2023 under Joe Biden's administration, threatens the complex network that Google has spent the past 17 years building to power its dominant digital advertising business. Digital advertising sales account for most of the $305 billion in revenue that Google's services division generates for its corporate parent Alphabet. The company's sprawling network of display ads provide the lifeblood that keeps thousands of websites alive. Google believes it has already made enough changes to its "ad manager" system, including providing more options and pricing options, to resolve the problems Brinkema flagged in her monopoly ruling.
Microsoft

Microsoft Will Let Copilot Take Control of Your Browser, Navigate Tabs and Complete Tasks As You Watch (theverge.com) 80

Microsoft AI CEO Mustafa Suleyman told The Verge today that the company plans to transform Edge into an "agentic browser" where Copilot controls tabs, navigates websites and completes tasks while users watch. Unlike The Browser Company's new Dia browser, Microsoft will integrate these capabilities directly into Edge.

Suleyman described Copilot opening tabs, reading multiple pages simultaneously and performing research transparently in real-time. The AI visits websites directly, preserving publisher traffic. Current Copilot features include tab navigation, page scrolling and content highlighting. Users will have the option to disable AI features entirely. Suleyman predicted that within years, AI companions will handle most browsing tasks while users provide oversight and feedback.
The Internet

MI6 Launches Dark Web Portal To Attract Spies In Russia (reuters.com) 20

An anonymous reader quotes a report from Reuters: A new dark web portal to recruit spies for the UK was launched last Friday (19th September), as the UK steps up its commitment to national security. Harnessing the anonymity of the dark web for the first time, MI6's new secure messaging platform -- Silent Courier -- enables anyone, anywhere in the world with access to sensitive information relating to terrorism or hostile intelligence activity to securely contact the UK and offer their services. Instructions on how to access the portal will be publicly available on MI6's verified YouTube channel as the UK reaches out to potential new agents in Russia and around the world. MI6 advises individuals accessing its portal to use trustworthy VPNs and devices not linked to themselves, to mitigate risks which exist in some countries.

The announcement was made by the outgoing Chief of MI6, Sir Richard Moore, in Istanbul where he stated that the platform will make it easier for MI6 to recruit agents online. As MI6 establishes its official presence on the dark web to reach new recruits and tackle hostile actors seeking to undermine UK security, Sir Richard said that the UK's intelligence services are "critical to calibrating risk and informing decisions" in navigating threats from hostile actors -- making platforms like these even more important in keeping our country safe. Sir Richard said: "Today we're asking those with sensitive information on global instability, international terrorism or hostile state intelligence activity to contact MI6 securely online. Our virtual door is open to you."
Foreign Secretary Yvette Cooper said: "National security is the first duty of any government and the bedrock of the Prime Minister's Plan for Change. As the world changes, and the threats we're facing multiply, we must ensure the UK is always one step ahead of our adversaries. Our world class intelligence agencies are at the coalface of this challenge, working behind the scenes to keep British people safe. Now we're bolstering their efforts with cutting-edge tech so MI6 can recruit new spies for the UK - in Russia and around the world."
Programming

Secure Software Supply Chains, Urges Former Go Lead Russ Cox (acm.org) 19

Writing in Communications of the ACM, former Go tech lead Russ Cox warns we need to keep improving defenses of software supply chains, highlighting "promising approaches that should be more widely used" and "areas where more work is needed." There are important steps we can take today, such as adopting software signatures in some form, making sure to scan for known vulnerabilities regularly, and being ready to update and redeploy software when critical new vulnerabilities are found. More development should be shifted to safer languages that make vulnerabilities and attacks less likely. We also need to find ways to fund open source development to make it less susceptible to takeover by the mere offer of free help. Relatively small investments in OpenSSL and XZ development could have prevented both the Heartbleed vulnerability and the XZ attack.
Some highlights from the 5,000-word article:
  • Make Builds Reproducible. "The Reproducible Builds project aims to raise awareness of reproducible builds generally, as well as building tools to help progress toward complete reproducibility for all Linux software. The Go project recently arranged for Go itself to be completely reproducible given only the source code... A build for a given target produces the same distribution bits whether you build on Linux or Windows or Mac, whether the build host is X86 or ARM, and so on. Strong reproducibility makes it possible for others to easily verify that the binaries posted for download match the source code..."
  • Prevent Vulnerabilities. "The most secure software dependencies are the ones not used in the first place: Every dependency adds risk... Another good way to prevent vulnerabilities is to use safer programming languages that remove error-prone language features or make them needed less often..."
  • Authenticate Software. ("Cryptographic signatures make it impossible to nefariously alter code between signing and verifying. The only problem left is key distribution...") "The Go checksum database is a real-world example of this approach that protects millions of Go developers. The database holds the SHA256 checksum of every version of every public Go module..."
  • Fund Open Source. [Cox first cites the XKCD cartoon "Dependencies," calling it "a disturbingly accurate assessment of the situation..."] "The XZ attack is the clearest possible demonstration that the problem is not fixed. It was enabled as much by underfunding of open source as by any technical detail."

The article also emphasized the importance of finding and fixing vulnerabilities quickly, arguing that software attacks must be made more difficult and expensive.

"We use source code downloaded from strangers on the Internet in our most critical applications; almost no one is checking the code.... We all have more work to do."


AI

There Isn't an AI Bubble - There Are Three 76

Fast Company ran a contrarian take about AI from entrepreneur/thought leader Faisal Hoque, who argues there's three AI bubbles.

The first is a classic speculative bubble, with asset prices soaring above their fundamental values (like the 17th century's Dutch "tulip mania"). "The chances of this not being a bubble are between slim and none..." Second, AI is also arguably in what we might call an infrastructure bubble, with huge amounts being invested in infrastructure without any certainty that it will be used at full capacity in the future. This happened multiple times in the later 1800s, as railroad investors built thousands of miles of unneeded track to serve future demand that never materialized. More recently, it happened in the late '90s with the rollout of huge amount of fiber optic cable in anticipation of internet traffic demand that didn't turn up until decades later. Companies are pouring billions into GPUs, power systems, and cooling infrastructure, betting that demand will eventually justify the capacity. McKinsey analysts talk of a $7 trillion "race to scale data centers" for AI, and just eight projects in 2025 already represent commitments of over $1 trillion in AI infrastructure investment. Will this be like the railroad booms and busts of the late 1800s? It is impossible to say with any kind of certainty, but it is not unreasonable to think so.

Third, AI is certainly in a hype bubble, which is where the promise claimed for a new technology exceeds reality, and the discussion around that technology becomes increasingly detached from likely future outcomes. Remember the hype around NFTs? That was a classic hype bubble. And AI has been in a similar moment for a while. All kinds of media — social, print, and web — are filled with AI-related content, while AI boosterism has been the mood music of the corporate world for the last few years. Meanwhile, a recent MIT study reported that 95% of AI pilot projects fail to generate any returns at all.

But the article ultimately argues there's lessons in the 1990s dotcom boom: that "a thing can be hyped beyond its actual capabilities while still being important... When valuations correct — and they will — the same pattern will emerge: companies that focus on solving real problems with available technology will extract value before, during, and after the crash." The winners will be companies with systematic approaches to extracting value — adopting mixed portfolios with different time horizons and risk levels, while recognizing organizational friction points for a purposeful (and holistic) integration.

"The louder the bubble talk, the more space opens for those willing to take a methodical approach to building value."

Thanks to Slashdot reader Tony Isaac for sharing the article.
The Internet

Africa's Only Internet Cable Repair Ship Keeps the Continent Online (restofworld.org) 6

The Leon Thevenin, Africa's only permanently stationed cable repair ship, maintains over 60,000 kilometers of undersea internet infrastructure from Madagascar to Ghana. The 43-year-old vessel employs a 60-person crew who perform precision repairs on fiber-optic cables that carry data for Alphabet, Meta, and Amazon -- companies that consumed 3.6 billion megabits per second of bandwidth in 2023.

Operating costs range from $70,000 to $120,000 daily, according to owner Orange Marine. The ship has experienced increased demand due to unusual underwater landslides in the Congo Canyon causing frequent cable breaks. Cable jointer Shuru Arendse and his team spend up to 48 hours on repairs that require fusing hair-thin glass fibers in conditions where a speck of dust can ruin the joint. The vessel gained Starlink connectivity last year after decades of relying on satellite phones and shared computers for crew communication. Sixty-two cable repair ships operate globally to maintain the infrastructure supporting streaming media and AI applications.

Slashdot Top Deals