AI

ChatGPT Back in Italy After Meeting Watchdog Demands (apnews.com) 9

ChatGPT's maker said Friday that the artificial intelligence chatbot is available again in Italy after the company met the demands of regulators who temporarily blocked it over privacy concerns. From a report: OpenAI said it fulfilled a raft of conditions that the Italian data protection authority wanted satisfied by an April 30 deadline to have the ban on the AI software lifted. "ChatGPT is available again to our users in Italy," San Francisco-based OpenAI said by email. "We are excited to welcome them back, and we remain dedicated to protecting their privacy."

Last month, Italian watchdog, known as Garante, ordered OpenAI to temporarily stop processing Italian users' personal information while it investigated a possible data breach. The authority said it didn't want to hamper AI's development but emphasized the importance of following the European Union's strict data privacy rules. OpenAI said it "addressed or clarified the issues" raised by the watchdog. The measures include adding information on its website about how it collects and uses data used to train the algorithms that power ChatGPT, giving European Union users a new form they can use to object to having their data used for training, and adding a tool to verify users' ages when signing up.

Transportation

Daimler Is Setting Up a $650 Million Charging Network For Commercial EVs (arstechnica.com) 26

An anonymous reader quotes a report from Ars Technica: There's a new fast-charging network coming to North America. It's called Greenlane, and it's a $650 million joint venture between Daimler, NextEra Energy Resources, and a BlackRock investment fund. But it's unlikely you'll recharge your passenger EV at a Greenlane site any time soon -- this new network is being designed specifically for medium- and heavy-duty commercial EVs. [...] Based on the company's renderings, Greenlane's sites will be much more comfortable for big rigs. The first of these sites will be in Southern California, and Greenlane says it will build out a network along critical freight routes on the East and West Coasts, as well as in Texas. To begin with, the company will focus on commercial EV recharging, but refueling infrastructure for hydrogen fuel cell EVs will follow. In time, Greenlane plans to add chargers for passenger (or light-duty) EVs. "Greenlane is designed to begin to tackle one of the greatest hurdles to the trucking industry's decarbonization -- infrastructure," said John O'Leary, Daimler Trucks North America's president and CEO.

"The nation's fleets can only transform with the critical catalyst of publicly accessible charging designed to meet the needs for medium- and heavy-duty vehicles. Together with our strong partners, BlackRock and NextEra Energy Resources, we are launching Greenlane to address the unique demands of the industry, support our mutual customers, and provide a dual benefit to all electric vehicle drivers who will be able to utilize this new network. We're excited to take this next step and look forward to sharing more of Greenlane's plans in the future," O'Leary said.
Microsoft

Microsoft is Busy Rewriting Core Windows Code in Memory-safe Rust (theregister.com) 150

Microsoft is rewriting core Windows libraries in the Rust programming language, and the more memory-safe code is already reaching developers. From a report: David "dwizzle" Weston, director of OS security for Windows, announced the arrival of Rust in the operating system's kernel at BlueHat IL 2023 in Tel Aviv, Israel, last month. "You will actually have Windows booting with Rust in the kernel in probably the next several weeks or months, which is really cool," he said. "The basic goal here was to convert some of these internal C++ data types into their Rust equivalents."

Microsoft showed interest in Rust several years ago as a way to catch and squash memory safety bugs before the code lands in the hands of users; these kinds of bugs were at the heart of about 70 percent of the CVE-listed security vulnerabilities patched by the Windows maker in its own products since 2006. The Rust toolchain strives to prevent code from being built and shipped that is exploitable, which in an ideal world reduces opportunities for miscreants to attack weaknesses in software. Simply put, Rust is focused on memory safety and similar protections, which cuts down on the number of bad bugs in the resulting code. Rivals like Google have already publicly declared their affinity for Rust.

Businesses

Tech Companies Are Colluding To Cheat H1-B Visa Lottery (wsj.com) 121

The Biden administration says it has found evidence that several dozen small technology companies have colluded to increase the chances that their prospective foreign hires will win a coveted H-1B visa for skilled foreign workers in this year's lottery. From a report: U.S. Citizenship and Immigration Services, the federal agency that awards H-1B visas, said it has found that a small number of companies are responsible for entering the same applicants into the lottery multiple times, with the alleged goal of artificially boosting their chances of winning a visa. The findings were laid out in a notice to employers viewed by The Wall Street Journal and set to be released Friday. That practice, according to the agency, is in large part responsible for inflating demand for the visas to a record high this year, with 781,000 entries into the lottery for 85,000 visa slots. Some of that increase in demand is organic, government data shows. About 350,000 applicants for H-1B visas submitted one entry into the lottery this year, compared with about 307,000 last year.

A much greater share of the increase, the data shows, can be attributed to applicants whose names were submitted by multiple companies. A large proportion of the duplicate entries, the immigration agency says, were submitted by a handful of the same companies. Some 96,000 people submitted multiple visa entries, for a total of about 408,000 entries. Though it isn't technically illegal for a foreign worker to have multiple companies submit visa applications on their behalf, companies submitting applications must attest that they have a real job for the employee in question if they win a visa. If companies that win a visa then quickly contract an employee out to third parties, or lay off an employee on the visa so he or she can switch companies, that could potentially amount to fraud.

Crime

Former Apple Employee Must Repay $19 Million After Defrauding the Company (theverge.com) 19

A former Apple employee has been sentenced to three years in prison and must pay back over $19 million in restitution for stealing around $17 million from the tech giant through mail and wire fraud schemes. From a report: Dhirendra Prasad, 55, was originally charged in March 2022 and later pleaded guilty to conspiring to defraud Apple and related tax crimes back in November last year. Prasad was employed at the company between 2008 and 2018, mostly working as a buyer in Apple's global service supply chain, purchasing parts and services from vendors. In his written plea agreement, Prasad admitted he started siphoning money from his employer around 2011 by accepting kickbacks, stealing parts, inflating invoices, and fraudulently charging Apple for goods that were never delivered. He also admitted to evading tax on the proceeds of his schemes and conspiring on these activities with the owners of two vendor companies, who have been charged in separate cases.
Privacy

Many Public Salesforce Sites are Leaking Private Data (krebsonsecurity.com) 7

A shocking number of organizations -- including banks and healthcare providers -- are leaking private and sensitive information from their public Salesforce Community websites, KrebsOnSecurity has learned. From the report: The data exposures all stem from a misconfiguration in Salesforce Community that allows an unauthenticated user to access records that should only be available after logging in. Salesforce Community is a widely-used cloud-based software product that makes it easy for organizations to quickly create websites. Customers can access a Salesforce Community website in two ways: Authenticated access (requiring login), and guest user access (no login required). The guest access feature allows unauthenticated users to view specific content and resources without needing to log in.

However, sometimes Salesforce administrators mistakenly grant guest users access to internal resources, which can cause unauthorized users to access an organization's private information and lead to potential data leaks. Until being contacted by this reporter on Monday, the state of Vermont had at least five separate Salesforce Community sites that allowed guest access to sensitive data, including a Pandemic Unemployment Assistance program that exposed the applicant's full name, Social Security number, address, phone number, email, and bank account number.

Microsoft

Microsoft is Done With Major Windows 10 Updates 163

Windows 10 22H2 will be the final version of the operating system, Microsoft said in a blog post on Thursday. From a report: Moving forward, all editions of Windows 10 will be supported with monthly security updates until October 14th, 2025, when Microsoft will end support. (Some releases on the Long-Term Servicing Channel, or LTSC, will get updates past that end of support date.) Microsoft is encouraging users to now transition to Windows 11 because Windows 10 won't be getting any new features.
Businesses

Mastercard Seeks To Expand Crypto Card Tie-ups (reuters.com) 12

Mastercard will expand its cryptocurrency payment card programme by seeking more partnerships with crypto firms, the company's head of crypto and blockchain said, even as the sector comes under closer scrutiny from regulators and banks grow wary. From a report: Mastercard has already partnered with crypto exchanges including Binance, Nexo and Gemini to offer crypto-linked payment cards in some countries. The Binance cards allow users to make payments in traditional currencies, funded by their cryptocurrency holdings on the exchange. "We have dozens of partners around the world who offer crypto card programmes and they continue to expand," Raj Dhamodharan, Mastercard's head of crypto and blockchain, told Reuters on Thursday.

"Providing access to crypto in a safe way is also part of our value proposition and we're continuing to do that." Banks have become wary of crypto clients after a number of big crypto firms collapsed last year, including the bankruptcy of major exchange FTX. Meanwhile, U.S. regulators are increasingly cracking down on what they say is a lack of compliance in the market.

The Courts

Google Gets Court Order To Take Down CryptBot That Infected Over 670,000 Computers (thehackernews.com) 14

An anonymous reader quotes a report from The Hacker News: Google on Wednesday said it obtained a temporary court order in the U.S. to disrupt the distribution of a Windows-based information-stealing malware called CryptBot and "decelerate" its growth. The tech giant's Mike Trinh and Pierre-Marc Bureau said the efforts are part of steps it takes to "not only hold criminal operators of malware accountable, but also those who profit from its distribution." CryptBot is estimated to have infected over 670,000 computers in 2022 with the goal of stealing sensitive data such as authentication credentials, social media account logins, and cryptocurrency wallets from users of Google Chrome. The harvested data is then exfiltrated to the threat actors, who then sell the data to other attackers for use in data breach campaigns. CryptBot was first discovered in the wild in December 2019.

The malware has been traditionally delivered via maliciously modified versions of legitimate and popular software packages such as Google Earth Pro and Google Chrome that are hosted on fake websites. [...] The major distributors of CryptBot, per Google, are suspected to be operating a "worldwide criminal enterprise" based out of Pakistan. Google said it intends to use the court order, granted by a federal judge in the Southern District of New York, to "take down current and future domains that are tied to the distribution of CryptBot," thereby kneecapping the spread of new infections.

AI

Palantir Demos AI To Fight Wars (vice.com) 80

An anonymous reader quotes a report from Motherboard: Palantir, the company of billionaire Peter Thiel, is launching Palantir Artificial Intelligence Platform (AIP), software meant to run large language models like GPT-4 and alternatives on private networks. In one of its pitch videos, Palantir demos how a military might use AIP to fight a war. In the video, the operator uses a ChatGPT-style chatbot to order drone reconnaissance, generate several plans of attack, and organize the jamming of enemy communications. In Palantir's scenario, a "military operator responsible for monitoring activity within eastern Europe" receives an alert from AIP that an enemy is amassing military equipment near friendly forces. The operator then asks the chatbot to show them more details, gets a little more information, and then asks the AI to guess what the units might be.

"They ask what enemy units are in the region and leverage AI to build out a likely unit formation," the video said. After getting the AI's best guess as to what's going on, the operator then asks the AI to take better pictures. It launches a Reaper MQ-9 drone to take photos and the operator discovers that there's a T-80 tank, a Soviet-era Russia vehicle, near friendly forces. Then the operator asks the robots what to do about it. "The operator uses AIP to generate three possible courses of action to target this enemy equipment," the video said. "Next they use AIP to automatically send these options up the chain of command." The options include attacking the tank with an F-16, long range artillery, or Javelin missiles. According to the video, the AI will even let everyone know if nearby troops have enough Javelins to conduct the mission and automate the jamming systems. [...]

What Palantir is offering is the illusion of safety and control for the Pentagon as it begins to adopt AI. "LLMs and algorithms must be controlled in this highly regulated and sensitive context to ensure that they are used in a legal and ethical way," the pitch said. According to Palantir, this control involves three pillars. The first claim is that AIP will be able to deploy these systems into classified networks and "devices on the tactical edge." It claims it will be able to parse both classified and real-time data in a responsible, legal, and ethical way. According to the video, users will then have control over what every LLM and AI in the Palantir-backed system can do. "AIP's security features what LLMs and AI can and cannot see and what they can and cannot do," the video said. "As operators take action, AIP generates a secure digital record of operations. These capabilities are crucial for mitigating significant legal, regulatory, and ethical risks in sensitive and classified settings.

Encryption

Google Plans To Add End-To-End Encryption To Authenticator (theverge.com) 24

After security researchers criticized Google for not including end-to-end encryption with Authenticator's account-syncing update, the company announced "plans to offer E2EE" in the future. "Right now, we believe that our current product strikes the right balance for most users and provides significant benefits over offline use," writes Google product manager Christiaan Brand on Twitter. "However, the option to use the app offline will remain an alternative for those who prefer to manage their backup strategy themselves." The Verge reports: Earlier this week, Google Authenticator finally started giving users the option to sync two-factor authentication codes with their Google accounts, making it much easier to sign into accounts on new devices. While this is a welcome change, it also poses some security concerns, as hackers who break into someone's Google account could potentially gain access to a trove of other accounts as a result. If the feature supported E2EE, hackers and other third parties, including Google, wouldn't be able to see this information.

Security researchers Mysk highlighted some of these risks in a post on Twitter, noting that "if there's ever a data breach or if someone obtains access to your Google Account, all of your 2FA secrets would be compromised." They added that Google could potentially use the information linked to your accounts to serve personalized ads and also advised users not to use the syncing feature until it supports E2EE. Brand pushed back against the criticism, stating that while Google encrypts "data in transit, and at rest, across our products, including in Google Authenticator," applying E2EE comes at the "cost of enabling users to get locked out of their own data without recovery."

United States

Coinbase Offers a Fiery Response To SEC's Threat of Enforcement Action (cnbc.com) 49

Crypto exchange Coinbase offered a fiery response on Thursday to last month's Wells notice from the SEC, telling the federal regulator that an enforcement action against the crypto exchange would pose "major programmatic risks" to the SEC that would "fail on the merits." From a report: "Coinbase does not list, clear, or effect trading in securities," the company's response said. The analysis SEC did staffers to justify an enforcement action "appears to rest on superficial and incorrect analogies to products and services offered by others," Coinbase wrote in a blog post from chief legal officer Paul Grewal. Separately, Grewal told CNBC, "At the time when we went public we had detailed discussions with the SEC about the very aspects of our business that are now -- two years later -- the subject of the Wells notice. Nothing has changed."

The SEC indicated to Coinbase in a March wells notice that its spot trading, staking, custody and institutional trading businesses were at risk. The SEC's warning to Coinbase noted that the regulator would allege Coinbase was offering and selling unregistered securities, in violation of federal law. The SEC has used unregistered offering and sale violations to force other crypto exchanges to close services in the U.S., including the crypto exchange Kraken's staking-as-a-service product.

Graphics

New Intel Linux Graphics Driver Patches Released, Up To 10-15% Better Performance (phoronix.com) 7

A new set of patches have been released for the Intel Linux graphics driver that "can provide 10-15% better performance when operating in the tuned mode," reports Phoronix. From the report: The set of Intel i915 Linux kernel graphics driver patches are about exposing the Intel RPS (Requested Power State) up/down thresholds. Right now the Intel Linux kernel driver has static values set for the up/down thresholds between power states while these patches would make them dynamically configurable by user-space. Google engineer Syed Faaiz Hussain raised the issue that they experimented with the Intel RPS tuning and were able to manage up to 15% better performance. With Counter-Strike: Global Offensive with OpenGL was a 14.5% boost, CS:GO with Vulkan was 12.9% faster, and Civilization VI with OpenGL was 11% faster while Strange Brigade was unchanged. No other game numbers were provided.

But as this is about changing the threshold for how aggressively the Intel graphics hardware switches power states, the proposed patches leave it up to user-space to adjust the thresholds as they wish. Google engineers are interested in hooking this into Feral's GameMode so that the values could be automatically tuned when launching games and then returning to their former state when done gaming, in order to maximize battery life / power efficiency. The only downside with these current patches are that they work only for non-GuC based platforms... So the latest Alder/Raptor Lake notebooks as well as Intel DG2/Alchemist discrete graphics currently aren't able to make use of this tuning option.

EU

ASML, Europe's Most Valuable Tech Firm, Is at the Heart of the US-China Chip War (bloomberg.com) 49

The low-profile firm that has become crucial to a half-trillion-dollar global industry. From a report: In 1984, Martin van den Brink, a young Dutch engineer, joined a newly created venture in a quiet corner of the Netherlands. Little did he know then that about 40 years on the company would be so crucial to the $580 billion semiconductor industry that it would be the epicenter of a US-China chip war. ASML Holding NV, where Van den Brink is now the chief technology officer, practically owns the market for a critical piece of equipment needed to produce the brains of everything that makes modern life possible -- from cars and smartphones to computers, microwaves and airplanes. With the company's high-end machines churning out chips that can also go into state-of-the-art weapons and artificial intelligence devices, ASML is effectively being treated as critical infrastructure for US national security and has become a target of industrial espionage for China. "I never expected to be where we are today," said Van den Brink.

Over his nearly four decades at the company, ASML has gone from a bit player competing with the likes of Nikon, Canon and Ultratech to the world's only maker of very high-end semiconductor lithography equipment. Its ascent has made it Europe's most valuable technology company, with a market capitalization of over $247 billion -- more than twice that of its customer Intel. In an industry where devices typically cost $10 million, ASML commands about $180 million for its current top-end machine. And although the chip market has softened recently, ASML is still growing and its long-term outlook seems intact, thanks to the insatiable demand for computing power.

"This is a company that the world can't exist without," said Jon Bathgate, a fund manager at NZS Capital in Denver, which has about $2 billion under management, with ASML as one of its biggest holdings. "They've got a 20-year head start... Investors have clearly realized how important ASML is as a company and how difficult it would be to replicate. It's a natural monopoly with secular growth winds. That's unique." As chips become for geopolitics in the 21st century what oil was in the last one, ASML's singular success has thrust it squarely in the crosshairs of the intensifying tensions between the US and China. With the US focused on the strategic importance of semiconductors, Presidents Donald Trump and Joe Biden have done everything to ensure that China is a couple of generations behind in chips. No company is more critical to that effort than ASML.

Microsoft

Microsoft's Mice, Keyboards, and Webcams Are Being Discontinued in Favor of Surface Accessories (theverge.com) 35

Microsoft will no longer manufacture mice, keyboards, and webcams that are Microsoft-branded. Instead, Microsoft is now focusing on its Surface-branded PC accessories, which include mice, keyboards, pens, and more. From a report: It brings an end to the legacy of Microsoft-branded PC hardware after the company first launched its first mouse in 1983 and bundled it with Microsoft Word and Notepad. "Going forward, we are focusing on our Windows PC accessories portfolio under the Surface brand," says Dan Laycock, senior communications manager at Microsoft, in a statement to The Verge. "We will continue to offer a range of Surface branded PC Accessories -- including mice, keyboards, pens, docks, adaptive accessories, and more. Existing Microsoft branded PC accessories like mice, keyboards, and webcams will continue to be sold in existing markets at existing sell-in prices while supplies last."
Social Networks

The Imgur Apocalypse Is Going To Break Large Parts of the Internet (vice.com) 61

An anonymous reader quotes a report from Motherboard: Imgur, a popular photo-uploading service that has been informally tied to Reddit since its 2009 founding, will remove two types of content from its platform starting next month: explicit or pornographic imagery, and images uploaded anonymously -- the latter with a lean on unused images, according to the company. While technically banned from Imgur for years through its community rules, adult content hasn't been actively removed (and is incredibly popular). Until now.

The move is also going to be disastrous for the continuity of the internet. Like Photobucket before it, Imgur has been widely used to host millions of photos that are linked to, embedded, or used elsewhere, and lots of these photos were uploaded by people who didn't bother to sign up for accounts. Imgur is especially popular as a host for Reddit, meaning the content of those old posts could suddenly disappear off the internet. The move will likely also break embeds in various forum posts and blog posts all over the internet, creating an unpleasant form of link rot. (The Archive Team, generally a harbinger of shuttering sites, is working on backing up this material, according to an announcement on Reddit.)

AI

The Rapid Rise of Generative AI Threatens To Upend US Patent System (ft.com) 60

Intellectual property laws cannot handle possibility artificial intelligence could invent things on its own. From a report: When members of the US supreme court refused this week to hear a groundbreaking case that sought to have an artificial intelligence system named as the inventor on a patent, it appeared to lay to rest a controversial idea that could have transformed the intellectual property field. The justices' decision, in the case of Thaler vs Vidal, leaves in place two lower court rulings that only "natural persons" can be awarded patents. The decision dealt a blow to claims that intelligent machines are already matching human creativity in important areas of the economy and deserve similar protections for their ideas. But while the court's decision blocked a potentially radical extension of patent rights, it has done nothing to calm growing worries that AI is threatening to upend other aspects of intellectual property law.

The US Patent and Trademark Office opened hearings on the issue this week, drawing warnings that AI-fuelled inventions might stretch existing understandings of how the patent system works and lead to a barrage of litigation. The flurry of concern has been prompted by the rapid rise of generative AI. Though known mainly from OpenAI's ChatGPT, the same technology is already being used to design semiconductors and suggest ideas for new molecules that might form the basis of useful drugs. For now, such uses of AI do not appear to pose a serious challenge to the patent system since the technology is being used as a tool to help humans shape ideas rather than operating independently, said Chris Morgan, an IP partner at law firm Reed Smith. However, referring to the possibility that AI systems might one day come up with inventions on their own, she added: "Our laws are not equipped, the way they're written right now, to handle that scenario."

Facebook

Zuckerberg Says Meta Wants To 'Introduce AI Agents To Billions of People' (theverge.com) 37

Meta sees "an opportunity to introduce AI agents to billions of people in ways that will be useful and meaningful," CEO Mark Zuckerberg told investors Wednesday. From a report: While he was vague about how exactly Meta will add generative AI to its apps, Zuckerberg gave the most detailed preview yet during the company's earnings call for the first quarter of this year, when it reported $28.6 billion in revenue and a record 2 billion daily users of the Facebook app, beating Wall Street's estimates. Meta's profit for the quarter was $5.7 billion, a 24 percent decrease from the same time last year. "We're exploring chat experiences in WhatsApp and Messenger, visual creation tools for posts in Facebook and Instagram and ads, and over time video and multi-modal experiences as well," Zuckerberg said on the earnings call. "I expect that these tools will be valuable for everyone from regular people to creators to businesses. For example, I expect that a lot of interest in AI agents for business messaging and customer support will come once we nail that experience. Over time, this will extend to our work on the metaverse, too, where people will much more easily be able to create avatars, objects, worlds, and code to tie all of them together."
EU

EU Sets Out Patent Rules for Smart Technology To Limit Lawsuits (reuters.com) 8

The European Commission proposed rules on Thursday to govern patents increasingly in demand for technologies used in smart devices such as drones, connected cars and mobile phones, to try to reduce litigation. From a report: The Commission said the system for what are known as standard-essential patents (SEPs), was fragmented, lacked transparency, led to lengthy disputes and that self-regulation had not worked. SEPs protect technology such as for 5G, Wi-Fi or Bluetooth that is needed by equipment producers to comply with international standards.

Slashdot Top Deals