Government

'How California's Bullet Train Went Off the Rails' (nytimes.com) 289

In 2008 California's voters approved the first bonds for a $33 billion San Francisco-to-Los Angeles bullet train.

14 years later, the New York Times is now calling the project "a case study in how ambitious public works projects can become perilously encumbered by political compromise, unrealistic cost estimates, flawed engineering and a determination to persist on projects that have become... too big to fail...." Political compromises, the records show, produced difficult and costly routes through the state's farm belt. They routed the train across a geologically complex mountain pass in the Bay Area. And they dictated that construction would begin in the center of the state, in the agricultural heartland, not at either of the urban ends where tens of millions of potential riders live. The pros and cons of these routing choices have been debated for years. Only now, though, is it becoming apparent how costly the political choices have been. Collectively, they turned a project that might have been built more quickly and cheaply into a behemoth so expensive that, without a major new source of funding, there is little chance it can ever reach its original goal of connecting California's two biggest metropolitan areas in two hours and 40 minutes....

Fourteen years later, construction is now underway on part of a 171-mile "starter" line connecting a few cities in the middle of California, which has been promised for 2030. But few expect it to make that goal. Meanwhile, costs have continued to escalate. When the California High-Speed Rail Authority issued its new 2022 draft business plan in February, it estimated an ultimate cost as high as $105 billion. Less than three months later, the "final plan" raised the estimate to $113 billion. The rail authority said it has accelerated the pace of construction on the starter system, but at the current spending rate of $1.8 million a day, according to projections widely used by engineers and project managers, the train could not be completed in this century....

As of now, there is no identified source of funding for the $100 billion it will take to extend the rail project from the Central Valley to its original goals, Los Angeles and San Francisco, in part because lawmakers, no longer convinced of the bullet train's viability, have pushed to divert additional funding to regional rail projects....

The Times's review, though, revealed that political deals created serious obstacles in the project from the beginning. Speaking candidly on the subject for the first time, some of the high-speed rail authority's past leaders say the project may never work.

Social Networks

Research Shows Recommender Systems Can Use AI To Manipulate Our Preferences (ieee.org) 11

Slashdot reader silverjacket writes: Research presented at the International Conference on Machine Learning shows that when recommender systems use reinforcement learning to increase engagement, they can have the side effect of shifting our preferences to increase engagement. The researchers also showed ways to detect and reduce such manipulation. Google and Facebook have used reinforcement learning in their recommender systems but didn't respond to questions.
Encryption

VPN, Tor Use Increases in Iran After Internet 'Curfews' (cnbc.com) 22

Iran's government is trying to limit internet access, reports CNBC — while Iranians are trying a variety of technologies to bypass the blocks: Outages first started hitting Iran's telecommunications networks on September 19, according to data from internet monitoring companies Cloudflare and NetBlocks, and have been ongoing for the last two and a half weeks. Internet monitoring groups and digital rights activists say they're seeing "curfew-style" network disruptions every day, with access being throttled from around 4 p.m. local time until well into the night. Tehran blocked access to WhatsApp and Instagram, two of the last remaining uncensored social media services in Iran. Twitter, Facebook, YouTube and several other platforms have been banned for years.

As a result, Iranians have flocked to VPNs, services that encrypt and reroute their traffic to a remote server elsewhere in the world to conceal their online activity. This has allowed them to restore connections to restricted websites and apps. On September 22, a day after WhatsApp and Instagram were banned, demand for VPN services skyrocketed 2,164% compared to the 28 days prior, according to figures from Top10VPN, a VPN reviews and research site. By September 26, demand peaked at 3,082% above average, and it has continued to remain high since, at 1,991% above normal levels, Top10VPN said....

Mahsa Alimardani, a researcher at free speech campaign group Article 19, said a contact she's been communicating with in Iran showed his network failing to connect to Google, despite having installed a VPN. "This is new refined deep packet inspection technology that they've developed to make the network extremely unreliable," she said. Such technology allows internet service providers and governments to monitor and block data on a network. Authorities are being much more aggressive in seeking to thwart new VPN connections, she added....

VPNs aren't the only techniques citizens can use to circumvent internet censorship. Volunteers are setting up so-called Snowflake proxy servers, or "proxies," on their browsers to allow Iranians access to Tor — software that routes traffic through a "relay" network around the world to obfuscate their activity.

Earth

Why Hurricane Ian Killed So Many People (cnn.com) 174

It was Florida's deadliest hurricane in 87 years, tied for the fifth-strongest hurricane to make landfall in the continental U.S. and killing more than 100 people after veering south into unexpected areas.

But a Rutgers University health psychologist suggests other factors might've made Hurricane Ian more deadly: Ian also underwent rapid intensification, perhaps influenced by climate change, which meant that its wind speeds increased dramatically as it passed over the warm waters of the Gulf of Mexico before landfall.

Emergency managers typically need at least 48 hours to successfully evacuate areas of southwest Florida. However, voluntary evacuation orders for Lee County were issued less than 48 hours prior to landfall, and for some areas were made mandatory just 24 hours before the storm came ashore. This was less than the amount of time outlined in Lee County's own emergency management plan.

While the lack of sufficient time to evacuate was cited by some as a reason why they stayed behind, there are other factors that may also have suppressed evacuations in some of the hardest hit areas. In order to correctly follow evacuation orders, people need to first know their evacuation zone. Research from other areas of the country indicates that many people don't. That's why the evacuation zone locator websites in the affected counties were crucial. However, so many people were checking their zones that some of these websites crashed in the days before the storm.

The article asks whether the early voluntary evacuation order "lulled some residents into being less concerned" and ultimately compounded problems. "In areas where evacuation orders were issued later, people who weren't expecting to evacuate needed to find and understand this evacuation zone information quickly...."

"People need to know that they are in an area being asked to evacuate — and waiting until the storm is on its way to find out their zone may be too late. Emergency managers need to educate people in advance of imminent storms while also developing more robust websites to handle the queries in the days before the storm."
Microsoft

New Windows 11 Insider Build Supports Third-Party Widgets, Slick New Teams Video Feature (theverge.com) 33

Microsoft is rolling out support for third-party widget development and new video calling functions for Chat from Microsoft Teams in its latest developer build of Windows 11. The new features in Preview Build 25217 are available for folks enrolled in the Windows Insider program. The Verge reports: Now, developers can create and test widgets that can be added to the Windows 11 widgets panel. New third-party widgets can only be tested locally on the latest Insider Preview build for now, but can later appear in the Microsoft Store for the shipping version of their apps once the build is formally released to the public. Microsoft says that Widgets can only be created for packaged Win32 apps at this time, but support for Progressive Web App (PWA) Widgets is planned as part of Microsoft Edge 108.

The Insider preview also includes a sneak peek (for a limited group of Insiders) at a new video calling experience for Chat from Microsoft Teams on Windows 11. When you open Chat from the taskbar, you'll soon be able to see a preview of your own video feed, allowing you to fix your appearance or spot any background issues before starting a call. Microsoft hopes to make this experience more broadly available in the coming months, but a 'small subset of users' will already have access to the feature as part of a sneak preview release. You can launch Chat from your Windows 11 taskbar yourself to check if you're one of the lucky few selected.

The Insider Preview Build 25217 also contains a few other feature updates, including improved cloud suggestions and integrated search suggestions for Simplified Chinese, and some design changes to the Microsoft Store. Now, the store makes it clearer if a game is included as part of Game Pass to spare you from accidentally purchasing a game you may have free access to. The Game Pass library is also getting a performance boost and some more simplified options.

Twitter

Twitter Knows You Took a Screenshot, Asks You To Share Instead (arstechnica.com) 54

An anonymous reader quotes a report from Ars Technica: Twitter is seemingly working to remind people that interesting tweets are something you should click, load, and view while logged into the company's ad-funded service, not merely see in a screenshot. That's why some users are seeing a "Share Tweet?" pop-up whenever the Twitter app notices them taking a screenshot. Social media analyst Matt Navarra noted the two kinds of nudge prompts in a tweet: "Copy link" and "Share Tweet." TechCrunch noted that some of its staff members were receiving the prompt and pointed to another tweet in which Twitter provided both "Copy link" and "Share Tweet" buttons.

Twitter makes money when people visit the site in a browser or load it in Twitter's official apps, then see sponsored tweets or pre-roll advertisements on native videos (users can also sign up for a Twitter Blue subscription). Screenshots, whether shared directly or on competing social platforms, don't create revenue. Engaging with Twitter itself could encourage people to sign up and do more of that. Twitter reported 237.8 million "average monetizable daily active usage" in Q2 2022, up 16.6 percent compared to the same quarter in 2021. The company claims this increase was driven by "ongoing product improvements" and "global conversation around current events." It makes sense why Twitter, the corporate entity, prefers tweet links to screenshots, enough so to A/B/C test a prompt that can make users feel like the Twitter app is both closely watching and scolding them. But for Twitter, the cultural entity, screenshots are enormously valuable, likely more so than links alone. If you've been engaging in Internet culture for years, you've seen why.

Transportation

Tesla Starts Production of Electric Semi Truck (engadget.com) 95

Tesla's long-delayed semi-truck has started production, and the company will begin making deliveries as soon as December 1st, Elon Musk has announced on Twitter. Engadget reports: The first batch of Semis will be delivered to Pepsi, which ordered 100 vehicles from the company back in December 2017. As TechCrunch notes, other big companies had also ordered trucks from the automaker, including Walmart and UPS. And in May this year, the automaker opened reservations to more customers for a deposit of $20,000. A Semi costs between $150,000 and $180,000, depending on the range, and it could go as far as 500 miles on a single charge. The Tesla Semi was unveiled back in 2017, with production expected to start by 2019. "While that obviously didn't happen, Musk told employees in an email back in early 2020 that the vehicle was already in limited production and that it was 'time to go all out and bring the Tesla Semi to volume production,'" notes Engadget.

Deliveries were delayed yet again to 2021 and then to 2022 due to the global supply chain shortages affecting the tech and auto industries.
The Courts

Papa John's Sued For 'Wiretap' Spying on Website Mouse Clicks, Keystrokes (theregister.com) 60

Papa John's is being sued by a customer -- not for its pizza but for allegedly breaking the US Wiretap Act by snooping on the way he browsed the pie-slinger's website. From a report: The titan of greasy wheels is accused of falling foul of wiretapping rules by using so-called session replay software on its website. This software records and phones home everything a user does on the site, beyond what fetching pages and placing an order would submit, we're told. For instance, it tells Papa John's where the mouse is moved and clicked, and what's typed into the page, it's claimed [PDF]. This info can be used to figure out where users get stuck, bail out of a sale, get lost, and so on. Session replay tools have been a privacy concern due to their indiscriminate capturing of data, sometimes poor security, and failures to get user consent to track and store this data, not to mention having analysts going over your every move to see how they can optimize their webpages and boost sales. On the other hand, you may not see it as that much of a concern given all the other material data a website might have on you -- such as name, email and home address, date of birth, orders placed, payment details, etc etc.
Google

Google To Open First Japan Data Center To Accelerate Asia Push (bloomberg.com) 2

An anonymous reader quotes a report from Bloomberg: Alphabet's Google will open its first data center in Japan next year as part of increasing investment in the world's third-biggest economy. The new facility, based in Inzai City, Chiba, will accelerate the operation of Google tools and services and support economic activity and jobs, Chief Executive Officer Sundar Pichai wrote in a blog post Friday. It's part of a broader $730 million investment in local infrastructure by the US company, which began last year and will extend through 2024. Google is also leading the construction of a new subsea cable linking Japan and Canada, called Topaz. The Chiba data center will be the company's third location in Asia, after Taiwan and Singapore, and will support its efforts to connect Japan to the rest of the global economy, Pichai said. "Google's partnership in Japan is now deeper than ever," Pichai said in a surprise appearance at Google's Pixel 7 and Pixel Watch launch event in Tokyo. "Japan has a history of being at the forefront of the world's most advanced technologies."
Facebook

Facebook Warns 1 Million Users Whose Logins Were Stolen By Scam Mobile Apps (theverge.com) 15

Meta is warning Facebook users about hundreds of apps on Apple and Google's app stores that were specifically designed to steal login credentials to the social network app. From a report: The company says it's identified over 400 malicious apps disguised as games, photo editors, and other utilities and that it's notifying users who "may have unknowingly self-compromised their accounts by downloading these apps and sharing their credentials." According to Bloomberg, a million users were potentially affected. In its post, Meta says that the apps tricked people into downloading them with fake reviews and promises of useful functionality (both common tactics for other scam apps that are trying to take your money rather than your login info). But upon opening some of the apps, users were prompted to log in with Facebook before they could actually do anything -- if they did, the developers were able to steal their credentials.
Businesses

Helium, the a16Z-backed Crypto Unicorn, Spars With Binance Over Delisting (forbes.com) 21

A token created by Helium, a much-hyped crypto project hailed as one of the best use cases of Web3 technology, will be partially delisted from major cryptocurrency exchange Binance amid reports of poor revenue and misleading marketing at its parent company, as well as the network's abandonment of its native blockchain last month. From a report: In a blog post Thursday, Binance said that it would cease trading Helium Network Tokens, or HNT, with multiple trading pairs over the next week, effectively preventing token holders from exchanging HNT for Bitcoin or other tokens. Binance "strongly advised" people to close out their positions, or else it would "conduct an automatic settlement and cancel all pending orders" relating to HNT and its trading pairs on October 12. Users may continue to spot trade with the HNT/Binance USD (Binance's stablecoin, BUSD) pair.

In a statement to Forbes, Binance spokesperson Jessica Jung said the exchange periodically reviews "each digital asset we list to ensure that it continues to meet a high level of standard. When a coin or token no longer meets this standard or there are changes in the industry, we conduct a more in-depth review and potentially delist it in order to protect our users." In response, Scott Sigel, COO at the Helium Foundation, which manages the community, said in a statement to Forbes that "there is no basis for Binance to delist several HNT pairs. There has been no change to the integrity of HNT and it continues to meet all of the standards the exchange sets."

The Internet

Biden Order Brings New Transatlantic Data Pact Ever Closer (bloomberg.com) 22

The European Union and U.S. moved a step closer to securing the privacy of transatlantic data flows as President Joe Biden moved to end years of uncertainty and allow thousands of companies to legally move customer data across the Atlantic. From a report: Biden signed an executive order Friday that'll create an independent court system in the US for EU citizens who think their data was unlawfully accessed or used by intelligence agencies. Decisions by the Data Protection Review Court will be binding and force the likes of the CIA to limit data collection to the "pursuit of defined national security objectives," according to a White House fact sheet.

The EU Court of Justice in 2020 toppled the so-called Privacy Shield over concerns that user data wasn't safe from prying eyes once on US soil. The ruling meant thousands of businesses that ship commercial data to the U.S. had to figure out an alternative and EU-U.S. negotiators were forced back to the drawing table. The prospect of no accord led Meta Platforms to say it would may have no choice but to pull its Facebook and Instagram services from the EU. The order is designed to address concerns about the ability of American spies to access EU data, which led to two previous data transfer accords being struck down by the bloc's top court. The EU and US have been working on a new deal for months and in March reached a breakthrough with an agreement in principle. The order gives the European Commission a tool to "restore an important, accessible, and affordable" data transfer mechanism while also providing greater legal certainty for companies shipping data across the Atlantic, the White House said.

Facebook

Zuckerberg's Metaverse Rush Pauses For 'Quality Lockdown' (ft.com) 69

A year after Meta announced its metaverse push, it has yet to demonstrate that its $10bn a year bet on an immersive virtual world will be a success. From a report: According to memos and conversations with 10 current and former employees, his 3bn user-strong social media empire is experiencing disruption and challenges as part of the pivot to Meta, and has already been forced to delay future launches and adjust expectations. In a September memo seen by the Financial Times, Vishal Shah, the vice-president of Meta's metaverse arm, warned that users and creators had complained that Horizon Worlds -- its social virtual reality experience and the closest thing it has to a metaverse so far -- was low quality and full of bugs.

He ordered a "quality lockdown" for the rest of the year, telling staff that they need to improve fundamentals before any aggressive expansion. Staffers working on the product had to "reprioritise or slow some things we had planned," said Shah, adding that he was lowering its user numbers target for the second half of the year. Some employees warned morale was suffering as teams got restructured to accommodate Zuckerberg's new vision, which many have not yet bought into. "There are a lot of people internally who have never put on a [virtual reality] headset," said one metaverse employee.

Displays

Google Shows Off Wireless Charging Dock That Turns the Pixel Tablet Into a Smart Display (theverge.com) 9

Alongside today's launch of the Pixel 7, Pixel 7 Pro, and Pixel Watch, Google revealed more details about its upcoming Pixel Tablet that was first announced earlier this year at Google I/O. The biggest new feature is it's ability to transform into a smart display when paired with a magnetic wireless charging speaker dock. "When docked, it looks like a Nest Hub Max, responds to Google Assistant queries, and lets you control your smart home from the redesigned Home app," adds The Verge.

Other features include the Google Tensor G2 processor, which is powering the new Pixel 7 smartphones, a user interface that's based on the Material You design language, and a nano-ceramic coating on top of the 100 percent recycled aluminum body. Unfortunately, there's still no concrete release date as the company would only say the tablet is coming in 2023.
China

China Upgrades Great Firewall To Defeat Censor-Beating TLS Tools (theregister.com) 20

Great Firewall Report (GFW), an organization that monitors and reports on China's censorship efforts, has this week posted a pair of assessments indicating a crackdown on TLS encryption-based tools used to evade the Firewall. The Register reports: The group's latest post opens with the observation that starting on October 3, "more than 100 users reported that at least one of their TLS-based censorship circumvention servers had been blocked. The TLS-based circumvention protocols that are reportedly blocked include trojan, Xray, V2Ray TLS+Websocket, VLESS, and gRPC." Trojan is a tool that promises it can leap over the Great Firewall using TLS encryption. Xray, V2ray and VLESS are VPN-like internet tunneling and privacy tools. It's unclear what the reference to gRPC describes -- but it is probably a reference to using the gRPC Remote Procedure Call (RPC) framework to authenticate client connections to VPN servers.

GFW's analysis of this incident is that "blocking is done by blocking the specific port that the circumvention services listen on. When the user changes the blocked port to a non-blocked port and keep using the circumvention tools, the entire IP addresses may get blocked." Interestingly, domain names used with these tools are not added to the Great Firewall's DNS or SNI blacklists, and blocking seems to be automatic and dynamic. "Based on the information collected above, we suspect, without empirical measurement yet, that the blocking is possibly related to the TLS fingerprints of those circumvention tools," the organization asserts. An alternative circumvention tool, naiveproxy, appears not to be impacted by these changes.
"It's not hard to guess why China might have chosen this moment to upgrade the Great Firewall: the 20th National Congress of the Chinese Communist Party kicks off next week," notes the Register. "The event is a five-yearly set piece at which Xi Jinping is set to be granted an unprecedented third five-year term as president of China."
Movies

Court Blocks 13,445 'Pirate' Sites Proactively To Protect One Movie (torrentfreak.com) 30

An anonymous reader quotes a report from TorrentFreak: A court in India has granted what appears to be the most aggressive site-blocking injunction in the history of copyright law. In advance of the movie 'Vikram Vedha' premiering in cinemas last Friday, a judge handed down an injunction that ordered 40 internet service providers to proactively and immediately block an unprecedented 13,445 sites. [...] India began blocking pirate sites in 2011 but the public had no idea it was coming. In an early case, movie company Reliance Entertainment went to court to protect the movie 'Singham' and came away with an order that compelled ISPs to temporarily block sites including Megaupload, Megavideo, Rapidshare, Putlocker, Hotfile and Fileserve. Having obtained one injunction, to the surprise of no one Reliance Entertainment immediately sought and obtained another. From there, the site-blocking train gathered steam and hasn't looked back. [...]

After obtaining certification for its new movie 'Vikram Vedha' last Monday, Reliance Entertainment filed an injunction application the next day. The goal was to protect the movie from online piracy following its premiere last Friday. Given that courts in other countries can take months over a decision, the Madras High Court needed to act quickly. On September 30, the day of the movie's release, the Court published its orders, noting that substantial sums had been invested in 'Vikram Vedha' and the movie was expected to screen in 3,000 cinemas worldwide. With words such as "imminent" and "threat" featured early on, it was already clear which way the judge was leaning. How far he was prepared to go still came as a surprise. After reading through the Reliance application, the judge declared that Reliance had made its case and that an injunction was appropriate. The judge said that if an interim injunction wasn't immediately granted, it would "result in alleged piracy being completed in all and every aspect of the matter." That would in turn lead to an "irreversible situation" and "irreparable legal injury incapable of compensation."

Due to the urgency, the respondents in the case – including 40 internet service providers -- weren't notified of the legal action. Nevertheless, the injunction was handed down via two separate orders, which together prohibit anyone from copying, recording, camcording, making available, uploading, downloading, exhibiting or playing the movie without a license. After specifically prohibiting copying to CD, DVD, pen drives, hard drives or tapes, the orders move on to the issue of ISP blocking. It appears that Reliance asked for a lot and the judge gave them everything. According to one of the orders, the websites put forward for blocking are all "non-compliant" operations, in that they have no reporting and take down mechanisms in place, at least according to Reliance. Interestingly, Reliance also informed the court that all of the websites were infringing its copyrights in respect of the movie 'Vikram Vedha', even though it was yet to be released and when the application was filed, no copies were available online. This means that Reliance couldn't have provided any infringing URLs even if it wanted to. Nevertheless, the judge did consider more limited blocking.

Ultimately, the judge granted an interim injunction and ordered all of the ISPs (list below) to immediately and proactively block a grand total of 13,445 websites. While the names of the websites were made available to the court, the court did not make the schedule available on the docket. As a result we have no way of confirming which domains are on the list. The ISPs weren't informed about the injunction application either, so presumably they're also in the dark. The idea that the judge tested all 13,445 domains seems wishful thinking at best. That leaves Reliance Entertainment as the sole entity with any knowledge of the submitted domains, all of which have been labeled in court as infringing the movie's copyright, even though no copy was available when the application was made.

Google

The Pixel Watch Is Official: $349, Good Looks, and a Four-Year-Old SoC 78

An anonymous reader quotes a report from Ars Technica: Google is clawing its way back into wearable relevance. Today the company took the wraps off what is officially its first self-branded smartwatch: the Pixel Watch. Google started revamping its wearable platform, Wear OS, in partnership with Samsung. While Wear OS 3, the new version of Google's wearable platform, technically launched with the Galaxy Watch 4 last year, this is the first time we'll be seeing an unskinned version on a real device. First up: prices. Google is asking a lot here, with the Wi-Fi model going for $349 and the LTE version clocking in at $399. The Galaxy Watch 4, which has a better SoC, and the Apple Watch SE, which has a way, way better SoC, both start at $250. Google is creating an uphill battle for itself with this pricing.

Google and Samsung's partnership means the Pixel Watch is running a Samsung Exynos 9110 SoC, with a cheap Cortex M33 co-processor tacked on for low-power watch face updates and 24/7 stat tracking. This SoC is a 10 nm chip with two Cortex A53 cores and an Arm Mali T720 MP1 GPU. If you can't tell from those specs, this is a chip from 2018 that was first used in the original Samsung Galaxy Watch. For whatever reason, Google couldn't get Samsung's new chip from the Galaxy Watch 4, an Exynos W920 (a big upgrade at 5 nm, dual Cortex A55s, and a Mali-G68 MP2 GPU). It's hard to understand why this is so expensive.

The display is a fully circular 1.6-inch OLED with a density of 320 ppi (that should mean around 360 pixels across). The only size available is 41 mm, the cover is Gorilla Glass 5, and the body is stainless steel in silver, black, or gold. It has 2GB of RAM, 32GB of eMMC storage, NFC, GPS, only 2.4 GHz Wi-Fi 802.11n support (Wi-Fi 4), and a 294 mAh battery. For sensors, you get SPO2 blood oxygen, heart rate, and an ECG sensor. It's water-resistant to 5 ATM, which means you're good for submersion, hand washing, and most normal water exposure. Usually 10 ATM is preferred for serious sports swimming, but the Apple Watch is 5 ATM, and Apple does all sorts of swimming promos. Google's black UI background does a good job of hiding exactly how large the display is in relation to the body, but a few screenshots reveal just how big the bezels are around this thing. They are big. Real big. Like, hard-to-imagine-we're-still-doing-this-in-2022 big.
Other things to note: the watch bands are proprietary, it'll be able to charge to 50 percent in 30 minutes, will work with any Android phone running version 8.0 and newer, and features Fitbit integration.

"Unlike the Pixel 7, which is expanding to 17 markets, the Pixel Watch is only for sale in eight countries: the US, Canada, UK, Germany, France, Australia, Japan, and Taiwan," adds Ars. "The watch is up for preorder today and ships October 13."

Further reading: Google Unveils Pixel 7 and Pixel 7 Pro Smartphones
Businesses

Celsius' Top 3 Execs Cashed Out $42M in Crypto Before Bankruptcy (coindesk.com) 37

Crypto lender Celsius' top three executives withdrew $42.13 million in cryptocurrency between May and June 2022, right before the company suspended withdrawals and filed for bankruptcy, new court records show. From a report: According to a Statement of Financial Affairs filed late Wednesday, former CEO Alex Mashinsky, former CSO Daniel Leon and CTO Nuke Goldstein withdrew the funds largely from custody accounts in the form of bitcoin (BTC), ether (ETH), USDC (USDC) and CEL tokens (CEL). Over a dozen other executives, including the company's Chief Compliance Officer, Oren Blonstein, Chief Risk Officer Rodney Sunada-Wong and new CEO Chris Ferraro did not make any significant withdrawals during that time period, according to the document, one of several filed to the Bankruptcy Court for the Southern District of New York. Mashinsky withdrew about $10 million in cryptocurrency in May 2022. Leon withdrew about $7 million (and an additional $4 million worth of CEL denoted as "collateral") between May 27 and May 31. Goldstein withdrew around $13 million (and an additional $7.8 million worth of CEL also denoted "collateral").
Data Storage

Big Tech, Banks, Government Departments Shred Millions of Storage Devices They Could Reuse (ft.com) 80

Companies such as Amazon and Microsoft, as well as banks, police services and government departments, shred millions of data-storing devices each year, the Financial Times has learnt through interviews with more than 30 people who work in and around the decommissioning industry and via dozens of freedom of information requests. From the report: This is despite a growing chorus of industry insiders who say there is another, better option to safely dispose of data: using computer software to securely wipe the devices before selling them on the secondary market. "From a data security perspective, you do not need to shred," says Felice Alfieri, a European Commission official who co-authored a report about how to make data centres more sustainable and is promoting "data deletion" over device destruction. Underpinning the reluctance to move away from shredding is the fear that data could leak, triggering fury from customers and huge fines from regulators.

Last month, the US Securities and Exchange Commission fined Morgan Stanley $35mn for an "astonishing" failure to protect customer data, after the bank's decommissioned servers and hard drives were sold on without being properly wiped by an inexperienced company it had contracted. This was on top of a $60mn fine in 2020 and a $60mn class action settlement reached earlier this year. Some of the hardware containing bank data ended up being auctioned online. While the incident stemmed from a failure to wipe the devices before selling them on, the bank now mandates that every one of its data-storing devices is destroyed -- the vast majority on site. This approach is widespread. One employee at Amazon Web Services, who spoke on condition of anonymity, explained that the company shreds every single data-storing device once it is deemed obsolete, usually after three to five years of use: "If we let one [piece of data] slip through, we lose the trust of our customers." A person with knowledge of Microsoft's data disposal operations says the company shreds everything at its 200-plus Azure data centres.

China

Popular Censorship Circumvention Tools Face Fresh Blockade By China (techcrunch.com) 9

Tools helping China's netizens to bypass the Great Firewall appear to be facing a fresh round of crackdowns in the run-up to the country's quinquennial party congress that will see a top leadership reshuffle. From a report: Greater censorship is not at all uncommon during countries' politically sensitive periods, but the stress facing censorship circumvention tools in China appears to be on a whole new level. "Starting from October 3, 2022 (Beijing Time), more than 100 users reported that at least one of their TLS-based censorship circumvention servers had been blocked," writes GFW Report, a censorship monitoring platform focused on China, in a GitHub post.

TLS, or transport layer security, is a ubiquitous internet security protocol used for encrypting data sent across the internet. Because data shared over a TLS connection is encrypted and cannot be easily read, many censorship circumvention apps and services use TLS to keep people's conversations private. A TLS-based virtual private network, or VPN, directs internet traffic through a TLS connection instead of pushing that traffic to one's internet provider. But Chinese censors seem to have found a way of compromising this strategy. "The blocking is done by blocking the specific port that the circumvention services listen on. When the user changes the blocked port to a non-blocked port and keeps using the circumvention tools, the entire IP address may get blocked," GFW Report says in the post.

Slashdot Top Deals