Security

Anonymous Hacktivists Breach Russian Databases, Leak 'Massive' Amounts of Data (cnbc.com) 80

"The Anonymous declaration of cyberwar was a top news story despite no evidence," writes cybersecurity specialist Jeremiah Fowler (an American who worked in Kyiv for the last 10 years — until fleeing in February to Poland). To investigate, Fowler performed a random sampling of 100 exposed Russian databases — and discovered that 92 of them had indeed been compromised. "Anti-Russian hackers used a similar script to the infamous 'MeowBot' that changed the name of folders and deleted the contents of the files. " (For example, renaming the folders to "putin_stop_this_war".)

And that was just the beginning, reports CNBC: Anonymous has claimed to have hacked over 2,500 Russian and Belarusian sites, said Fowler. In some instances, stolen data was leaked online, he said, in amounts so large it will take years to review. "The biggest development would be the overall massive number of records taken, encrypted or dumped online," said Fowler. Shmuel Gihon, a security researcher at the threat intelligence company Cyberint, agreed that amount of leaked data is "massive."

"We currently don't even know what to do with all this information, because it's something that we haven't expected to have in such a short period of time," he said....

The more immediate outcome of the hacks, Fowler and Gihon agreed, is that Russia's cybersecurity defenses have been revealed as being far weaker than previously thought.

Fowler's report argues that Anonymous has "rewritten the rules of how a crowdsourced modern cyberwar is conducted" — with the group also offering penetration testing to Ukraine, "finding vulnerabilities before Russia could exploit them." But in addition, Fowler writes, Anonymous's efforts have also "transformed into a larger operation that spread far beyond the Russian government, companies, or organizations, and included an information campaign aimed at Russian citizens."

Some examples: Hacking Printers — Russian censorship has blocked many inside the country from knowing the true scale of the war and Russian losses. Anonymous hacked printers across Russia and printed uncensored facts or anti-propaganda and pro-ukrainian messages. The group claims to have printed over 100,000 documents. This also includes barcode printers at grocery stores where prices were changed and product names were changed to anti-war or pro-Ukrainian slogans....

RoboDial, SMS, and Email Spam — Almost everyone on earth has received some form of spam in the form of a phone call, text, or email message. These usually try to sell a service or scam victims out of money. Now this same technology has been used to bypass Russian censorship and inform citizens of news and messages they are forbidden to learn on state sponsored propaganda channels. Anonymous affiliated Squad303 claimed to have sent over 100 million messages to Russian devices.

Social Networks

CERN Is Totally Not Opening a Portal To Hell (usatoday.com) 214

"Ten years on from discovery, there's still a lot left to learn about the Higgs boson!" tweeted a researcher anticipating their experiment on the Large Hadron Collider.

But on Facebook, there's posts calling CERN "a demonic/Evil machine that opens up portals to other dimensions/Hell/other spiritual worlds" and "brings in demons wicked spirits/High Evil Principalities." And USA Today reports that similar posts making that same claim "have amassed hundreds of interactions on Facebook and Twitter." (Their article then goes on to assure readers that "the claim is baseless.")

In fact, USA Today's "Fact Check" feature spent some time investigating the claims of a demonic machine opening portals to hell, and after exhaustive research can report that at this time "There is no evidence scientists at CERN are engaged in anything other than scientific-related activities." Physics experts told USA TODAY scientists use the Large Hadron Collider to collide particles at very high energies to study matter. There is no truth to the claim that scientists at CERN are communicating with demonic entities and using the collider to open up a portal to hell, Dejan Stojkovic, a physics professor at the University at Buffalo, told USA TODAY in an email.
The physics behind his explanation is interesting: "To create a black hole or a wormhole, even microscopic ones, with our current technology, in the context of our standard theories of gravity, we need an accelerator as big as the whole universe," Stojkovic said. "So there is no chance whatsoever to create such a portal at the [Large Hadron Collider]."

"Since these are previously unexplored energies in a controlled environment, we might expect production of some new elementary particles that we did not know if they existed," Stojkovic said. "However, these are microscopic particles, so there is no chance such a portal would open."

Facebook has now attached a warning to its user's post about a demonic machine opening up portals to hell, notifying users that the post contains "False information." (It adds that this assertion has been "checked by independent fact-checkers," linking back to USA Today's article for support.)

USA Today ends its analysis with a definitive summation: Based on our research, we rate FALSE the claim that scientists at CERN are communicating with demonic entities and opening a portal to hell. There is no evidence scientists at CERN are engaged in anything other than scientific-related activities. The collider cannot open up portals to other dimensions. Experts said scientists use the machine to collide particles at very high energies to study matter....

Our fact-check work is supported in part by a grant from Facebook.


Thanks to Slashdot reader Iamthecheese for sharing the story!
Debian

The Story Behind Google's In-house Desktop Linux (computerworld.com) 60

"For more than a decade, Google has been baking and eating its own homemade Linux desktop distribution," writes Computerworld.

Long-time Slashdot reader waspleg shared their report: The first version was Goobuntu. (As you'd guess from the name, it was based on Ubuntu.) In 2018, Google moved its in-house Linux desktop from the Goobuntu to a new Linux distro, the Debian-based gLinux. Why? Because, as Google explained, Ubuntu's Long Term Support (LTS) two-year release "meant that we had to upgrade every machine in our fleet of over 100,000 devices before the end-of-life date of the OS."

That was a pain. Add in the time-consuming need to fully customize engineers' PCs, and Google decided that it cost too much. Besides, the "effort to upgrade our Goobuntu fleet usually took the better part of a year. With a two-year support window, there was only one year left until we had to go through the same process all over again for the next LTS. This entire process was a huge stress factor for our team, as we got hundreds of bugs with requests for help for corner cases."

So, when Google had enough of that, it moved to Debian Linux (though not just vanilla Debian). The company created a rolling Debian distribution: GLinux Rolling Debian Testing (Rodete). The idea is that users and developers are best served by giving them the latest updates and patches as they're created and deemed ready for production.

Google's using what appears to be an automated build system (along with virtualized test suites, and eventually "incremental canarying"), the article points out. The end result?

"The entire gLinux development team consists of a single on-duty release engineer position that rotates among team members."
Government

Prior to Invasion, Russian Agents May Have Infilitrated Chernobyl Nuclear Disaster Site (reuters.com) 211

Reuters investigated the strange thing that happened when Russia's invading armored vehicles reached Chernobyl, "a key staging post on the approach to Kyiv," on February 24th. "In less than two hours, and without a fight, the 169 members of the Ukrainian National Guard laid down their weapons."

The fall of Chernobyl, site of the world's worst nuclear disaster, stands out as an anomaly in the five-month old war: a successful blitzkrieg operation in a conflict marked elsewhere by a brutal and halting advance by Russian troops and grinding resistance by Ukraine. Now a Reuters investigation has found that Russia's success at Chernobylwas no accident, but part of a long-standing Kremlin operation to infiltrate the Ukrainian state with secret agents....

One source with direct knowledge of the Kremlin's invasion plans told Reuters that Russian agents were deployed to Chernobyl last year to bribe officials and prepare the ground for a bloodless takeover. Reuters couldn't independently verify the details of this assertion. However, Ukraine's State Bureau of Investigation has said it is investigating a former top intelligence official, Andriy Naumov, on suspicion of treason for passing Chernobyl security secrets to a foreign state.... A review of Ukrainian testimony and court documents and an interview with a local official show that Kyiv is conducting at least three investigations into the conduct of people who worked at Chernobyl. The investigations have identified at least two people suspected of providing information to Russian agents or otherwise helping them seize the plant, according to these documents....

For Russia's war planners, seizing Chernobyl was just a stepping stone to the main objective: taking control of the Ukrainian national government in Kyiv. There, too, the Kremlin expected that undercover agents in positions of power would play a crucial part, according to four sources with knowledge of the plan.

It's been said that journalism is a first draft of history. And Reuters is already wondering how this affected the invasion's ultimate outcome: Five people with knowledge of the Kremlin's preparations said war planners around President Vladimir Putin believed that, aided by these agents, Russia would require only a small military force and a few days to force Ukrainian President Volodymyr Zelenskiy's administration to quit, flee or capitulate.... At a national level, sources with knowledge of the Kremlin's plans said Moscow was counting on activating sleeper agents inside the Ukrainian security apparatus...

Though Russia captured Chernobyl, its plan to take power in Kyiv failed. In many cases, the sleeper agents Moscow had installed failed to do their job, according to multiple sources in Russia and Ukraine.... People the Kremlin counted on as its proxies in Ukraine overstated their influence in the years leading up to the invasion, said four of the sources with knowledge of the Kremlin's preparations. The Kremlin relied in its planning on "clowns — they know a little bit, but they always say what the leadership wants to hear because otherwise they won't get paid," said one of the four, a person close to the Moscow-backed separatist leadership in eastern Ukraine.

Putin now finds himself in a protracted, full-scale war, fighting for every inch of territory at huge cost.

Communications

Nokia, AST SpaceMobile Join Forces For Broadband From Space (bloomberg.com) 29

Nokia Oyj will provide equipment to connect AST SpaceMobile Inc. satellites to the global telecommunications network, creating a crucial link in a planned space-based broadband network designed to work with standard mobile phones, the companies said in a statement Thursday. Bloomberg reports: In addition to AirScale base stations, Espoo, Finland-based Nokia will provide its NetAct network management systems and technical support, the companies said. Terms of the five-year deal with Austin, Texas-based AST SpaceMobile weren't disclosed. AST's BlueWalker 3 test satellite, an array of antennas that measures 693 square feet (64 square meters), is planned for launch in early to mid-September. Eventually the network will consist of 168 satellites, the company told investors in a March 31 filing.

With BlueWalker 3 aloft, AST plans to conduct testing on five continents in coordination with mobile network operators such as Vodafone Group Plc, Rakuten Mobile and Orange SA. AST and Nokia said the network is intended to offer connections to people and places without digital services. "Connectivity should be considered an essential service like water, electricity or gas," said Tommi Uitto, Nokia's president of mobile services. "Everyone should be able to have access to universal broadband services that will ensure that no one is left behind."
Unlike the offerings from Elon Musk's SpaceX or OneWeb and Eutelsat, which recently announced plans to merge in the hopes of becoming a stronger competitor, is that SpaceMobile's service is designed to connect to "standard, unmodified cellular phones without the requirement of special software, ground terminals or hardware," says the company in its annual filing.
Twitter

Twitter Warns of 'Record Highs' In Account Data Requests (engadget.com) 7

In Twitter's 20th transparency report, the company says it saw "record highs" in the number of account data requests during the July-December 2021 reporting period, with 47,572 legal demands on 198,931 accounts. Engadget reports: The media in particular faced much more pressure. Government demands for data from verified news outlets and journalists surged 103 percent compared to the last report, with 349 accounts under scrutiny. The largest slice of requests targeting the news industry came from India (114), followed by Turkey (78) and Russia (55). Governments succeeded in withholding 17 tweets. As in the past, US demands represented a disproportionately large chunk of the overall volume. The country accounted for 20 percent of all worldwide account info requests, and those requests covered 39 percent of all specified accounts. Russia is still the second-largest requester with 18 percent of volume, even if its demands dipped 20 percent during the six-month timeframe.

The company said it was still denying or limiting access to info when possible. It denied 31 percent of US data requests, and either narrowed or shut down 60 percent of global demands. Twitter also opposed 29 civil attempts to identify anonymous US users, citing First Amendment reasons. It sued in two of those cases, and has so far had success with one of those suits. There hasn't been much success in reporting on national security-related requests in the US, however, and Twitter is still hoping to win an appeal that would let it share more details.

Technology

Iran Ramps Up Drone Exports, Signaling Global Ambitions (nytimes.com) 16

Iran has made steady advances in the design and production of military drones in recent years, and has stepped up their transfer to militant groups across the Middle East as it seeks to shift the dynamics of battlefields from Yemen to Gaza. Those efforts have now extended far beyond the region. From a report: Iran is now seeking to build its global clout and sell increasingly sophisticated weapons-capable drones commercially to other nations, including those that have been subject to various sanctions in recent years, like Venezuela and Sudan, according to Iranian news media, satellite images and defense experts inside and outside Iran.

That has provided an important source of funds and political influence for Iran, which is itself isolated and struggling under U.S. financial restrictions. Now, Russia may be a potential client. Washington said this month that it had intelligence that Moscow planned to purchase hundreds of drones from Iran to bolster its arsenal for the war in Ukraine. U.S. officials have urged Iran not to sell drones to Russia and warned of consequences for both countries. Iran's foreign ministry said in a statement that its military cooperation with Russia predated the war, without providing details, and its foreign minister, Hossein Amir-Abdollahian, said in an interview with the Italian daily La Repubblica in July that the country had no plans to provide military equipment to either side of the conflict.

Businesses

Metaverse Jobs Are Disappearing as Hiring Slows at Google, Facebook (bloomberg.com) 37

Meta Platforms, grappling with its first-ever quarterly sales slump, now has another problem: Jobs in the metaverse are disappearing. From a report: New monthly job postings across all industries with "metaverse" in the title declined 81% between April and June, according to workplace researcher Revelio Labs, after surging in the months following Facebook's rebranding last fall. The dropoff coincides with a broader slowdown across the tech sector, which has prompted layoffs and hiring freezes, leaving workers from the Bay Area to Bangalore increasingly rattled. Job postings in tech hubs like San Francisco and Austin, Texas, dropped 8.4% in the past four weeks, according to job site Indeed.

Meta Chief Executive Officer Mark Zuckerberg's big bet on virtual reality and other nascent, immersive technologies encouraged companies of all stripes to look for experts in those fields, which may have created "short-lived hype from the demand side," Revelio Labs economist Jin Yan said. Now, as employers recalibrate their hiring needs and labor budgets amid growing concerns of a recession, that hype has come face to face with a sobering, and fully non-virtual, reality.

Facebook

Facebook Approved Pro-Genocide Ads in Kenya (gizmodo.com) 28

Kenya's national cohesion watchdog threatened to suspend Facebook from the country Friday if it doesn't mitigate hate speech ahead of the country's general elections next month. From a report: The regulator has given the company one week to remediate the problem, which included Facebook's approval of ads advocating for ethnic cleansing. Human rights organizations and the Facebook whistleblower are calling on Facebook to immediately suspend all advertising in Kenya and take other emergency steps. The National Cohesion and Integration Commission (NCIC), a Kenyan agency founded to mitigate ethnic violence and promote national healing in the wake of the 2007-08 post-election crisis, told reporters on Friday that Facebook was "in violation of the laws of our country."
Cloud

Amazon is Shutting Down Its Cloud Storage Service Amazon Drive (geekwire.com) 29

Amazon sent emails out Friday morning to Amazon Drive users to notify them that the company is shutting down its cloud storage service on Dec. 31, 2023. From a report: "We are taking the opportunity to more fully focus our efforts on Amazon Photos to provide customers a dedicated solution for photos and video storage," Amazon says in an FAQ. Amazon says photos and videos in Amazon Drive accounts have been automatically saved to Amazon Photos. "If you rely on Amazon Drive for your file storage, you will need to go to the Amazon Drive website and download your files by December 31, 2023," Amazon noted.
Google

Google Stadia May Shut Down, Report Says 69

An anonymous reader shares a report: Google Stadia hasn't been as successful as the Internet super-giant wanted it to be. While the game streaming service did end up getting its foot in the door for a little while, it hasn't been making waves since its release, and many have theorized that Google would end up scuttling the service entirely in the relatively near future. This idea isn't without precedent, either, as Google is known to shut down underperforming services in surprisingly short order, and Google Stadia, in particular, isn't doing all that well in the grand scheme of things. The latest rumors suggest that the plans to shut down Stadia may be further along than some would think, with Google aiming to close it down before the end of 2022.

Google Stadia was originally announced in 2019, and while it was presented as the next big thing for gaming, it barely made a splash in the end. According to Twitter account Killed by Google, which keeps track of all the services that Google closes down, it might not be long before Stadia's time is up. It's a "he said, she said" situation, to be fair, but according to the account holder's sources, Google may shut down Stadia "by the end of summer." The source also claims that there'd be no license transfer of any sort, which means that any purchases made on Stadia would effectively be nullified as the service closes down.
China

Chinese Government Asked TikTok for Stealth Propaganda Account (bloomberg.com) 43

A Chinese government entity responsible for public relations attempted to open a stealth account on TikTok targeting Western audiences with propaganda, according to internal messages seen by Bloomberg. From a report: The attempt, which met with push-back from TikTok executives, highlights the internal tensions within the fast-growing social media app, owned by Beijing-based ByteDance, which has constantly attempted to distance itself from Chinese state influence. In an April 2020 message addressed to Elizabeth Kanter, TikTok's head of government relations for the UK, Ireland, Netherlands and Israel, a colleague flagged a "Chinese government entity that's interested in joining TikTok but would not want to be openly seen as a government account as the main purpose is for promoting content that showcase the best side of China (some sort of propaganda)."

The messages indicate that some of ByteDance's most senior government relations team, including Kanter and US-based Erich Andersen, Global Head of Corporate Affairs and General Counsel, discussed the matter internally but pushed back on the request, which they described as "sensitive." TikTok used the incident to spark an internal discussion about other sensitive requests, the messages state. "We declined to offer support for this request, as we believed the creation of such an account would violate our Community Guidelines," said a TikTok spokeswoman, who downplayed the incident as an informal request from a friend of an employee. TikTok has rules against "coordinated inauthentic behavior," where accounts conceal their true identity to exert influence or sway public opinion, and against political advertising, the spokeswoman said.

Transportation

Senate Moves Forward With EV Tax Credit Reform (electrek.co) 220

An anonymous reader quotes a report from Electrek: The US Senate is going to move forward with a sweeping new bill after Senator Joe Manchin finally accepted to include investments to curb climate change. The new bill is going to include the long-awaited electric vehicle tax credit reform that is going to give back access to the tax credit to Tesla GM vehicles, along with other changes. Last year, the US House of Representatives passed the $1.9 trillion "Build Back Better" legislation, but it has been stuck in the divided Senate ever since. The bill is interesting to the EV community because it includes a long-needed reform to the federal tax credit for electric vehicles. Even though it is technically a small part of the overall bill, it is a point of contention.

The main goal of the reform, and the one most people agree on, is the need to eliminate the tax credit cap after automakers hit 200,000 EVs sold, since it is putting automakers that were early in pushing electric vehicles at a disadvantage. It also happens that those automakers are American automakers, like Tesla and GM, while many foreign automakers still have access to the credit. Joe Manchin, a Democrat and senior United States senator from West Virginia, has been holding his vote, which is the deciding vote since the Democrats need every single one of their votes in the Senate to pass anything. The senator, who comes from a very conservative state, has proven to be difficult to deal when it comes to initiatives that deal with climate change, but in a reversal today, he announced that he accepted a new version of the bill, now called "Inflation Reduction Act of 2022."
Here are some of the key changes to the EV federal tax credit in the new bill (as confirmed by Electrek):

- Federal tax credit for EVs maintained at $7,500
- Eliminates tax credit cap after automakers hit 200,000 EVs sold, making GM and Tesla once again eligible
- The language in the bill indicates that the tax credit would be implemented at the point of sale instead of on taxes.
- In order to get the full credit, the electric vehicle needs to be assembled in North America, the majority of battery components need to come from North America, and contain a certain percentage of minerals from countries with free trade agreements with the US
- A new federal tax credit of $4,000 for used EVs
- Zero-emission vans, SUVs, and trucks with MSRPs up to $80,000 qualify
- Electric sedans priced up to $55,000 MSRP qualify
- The full EV tax credit will be available to individuals reporting adjusted gross incomes of $150,000 or less, $300,000 for joint filers
Security

0-Days Sold By Austrian Firm Used To Hack Windows Users, Microsoft Says (arstechnica.com) 25

Longtime Slashdot reader HnT shares a report from Ars Technica: Microsoft said on Wednesday that an Austria-based company named DSIRF used multiple Windows and Adobe Reader zero-days to hack organizations located in Europe and Central America. Members of the Microsoft Threat Intelligence Center, or MSTIC, said they have found Subzero malware infections spread through a variety of methods, including the exploitation of what at the time were Windows and Adobe Reader zero-days, meaning the attackers knew of the vulnerabilities before Microsoft and Adobe did. Targets of the attacks observed to date include law firms, banks, and strategic consultancies in countries such as Austria, the UK, and Panama, although those aren't necessarily the countries in which the DSIRF customers who paid for the attack resided.

"MSTIC has found multiple links between DSIRF and the exploits and malware used in these attacks," Microsoft researchers wrote. "These include command-and-control infrastructure used by the malware directly linking to DSIRF, a DSIRF-associated GitHub account being used in one attack, a code signing certificate issued to DSIRF being used to sign an exploit, and other open source news reports attributing Subzero to DSIRF."
Referring to DSIRF using the work KNOTWEED, Microsoft researchers wrote: In May 2022, MSTIC found an Adobe Reader remote code execution (RCE) and a 0-day Windows privilege escalation exploit chain being used in an attack that led to the deployment of Subzero. The exploits were packaged into a PDF document that was sent to the victim via email. Microsoft was not able to acquire the PDF or Adobe Reader RCE portion of the exploit chain, but the victim's Adobe Reader version was released in January 2022, meaning that the exploit used was either a 1-day exploit developed between January and May, or a 0-day exploit. Based on KNOTWEED's extensive use of other 0-days, we assess with medium confidence that the Adobe Reader RCE is a 0-day exploit. The Windows exploit was analyzed by MSRC, found to be a 0-day exploit, and then patched in July 2022 as CVE-2022-22047. Interestingly, there were indications in the Windows exploit code that it was also designed to be used from Chromium-based browsers, although we've seen no evidence of browser-based attacks.

The CVE-2022-22047 vulnerability is related to an issue with activation context caching in the Client Server Run-Time Subsystem (CSRSS) on Windows. At a high level, the vulnerability could enable an attacker to provide a crafted assembly manifest, which would create a malicious activation context in the activation context cache, for an arbitrary process. This cached context is used the next time the process spawned.

CVE-2022-22047 was used in KNOTWEED related attacks for privilege escalation. The vulnerability also provided the ability to escape sandboxes (with some caveats, as discussed below) and achieve system-level code execution. The exploit chain starts with writing a malicious DLL to disk from the sandboxed Adobe Reader renderer process. The CVE-2022-22047 exploit was then used to target a system process by providing an application manifest with an undocumented attribute that specified the path of the malicious DLL. Then, when the system process next spawned, the attribute in the malicious activation context was used, the malicious DLL was loaded from the given path, and system-level code execution was achieved.
Microsoft recommends a number of security considerations to help mitigate this attack, including patching CVE-2022-22047, updating Microsoft Defender Antivirus to update 1.371.503.0 or later, and enabling multifactor authentication (MFA).
Graphics

As Intel Gets Into Discrete GPUs, It Scales Back Support For Many Integrated GPUs (arstechnica.com) 47

An anonymous reader quotes a report from Ars Technica: Intel is slowly moving into the dedicated graphics market, and its graphics driver releases are looking a lot more like Nvidia's and AMD's than they used to. For its dedicated Arc GPUs and the architecturally similar integrated GPUs that ship with 11th- and 12th-generation Intel CPUs, the company promises monthly driver releases, along with "Day 0" drivers with specific fixes and performance enhancements for just-released games. At the same time, Intel's GPU driver updates are beginning to de-emphasize what used to be the company's bread and butter: low-end integrated GPUs. The company announced yesterday that it would be moving most of its integrated GPUs to a "legacy support model," which will provide quarterly updates to fix security issues and "critical" bugs but won't include the game-specific fixes that newer GPUs are getting.

The change affects a wide swath of GPUs, which are not all ancient history. Among others, the change affects all integrated GPUs in the following processor generations, from low-end unnumbered "HD/UHD graphics" to the faster Intel Iris-branded versions: 6th-generation Core (introduced 2015, codenamed Skylake), 7th-generation Core (introduced 2016, codenamed Kaby Lake), 8th-generation Core (introduced 2017-2018, codenamed Kaby Lake-R, Whiskey Lake, and Coffee Lake), 9th-generation Core (introduced 2018, codenamed Coffee Lake), 10th-generation Core (introduced 2019-2020, codenamed Comet Lake and Ice Lake), and various N4000, N5000, and N6000-series Celeron and Pentium CPUs (introduced 2017-2021, codenamed Gemini Lake, Elkhart Lake, and Jasper Lake).

Intel is still offering a single 1.1GB driver package that supports everything from its newest Iris Xe GPUs to Skylake-era integrated graphics. However, the install package now contains one driver for newer GPUs that are still getting new features and a second driver for older GPUs on the legacy support model. The company uses a similar approach for driver updates for its Wi-Fi adapters, including multiple driver versions in the same download package to support multiple generations of hardware.
"The upshot is that these GPUs' drivers are about as fast and well-optimized as they're going to get, and the hardware isn't powerful enough to play many of the newer games that Intel provides fixes for in new GPU drivers anyway," writes Ars Technica's Andrew Cunningham. "Practically speaking, losing out on a consistent stream of new gaming-centric driver updates is unlikely to impact the users of these GPUs much, especially since Intel will continue to fix problems as they occur."
Social Networks

Instagram Is Walking Back Its Changes For Now (theverge.com) 27

An anonymous reader quotes a report from The Verge: Instagram will walk back some recent changes to the product following a week of mounting criticism, the company said today. A test version of the app that opened to full-screen photos and videos will be phased out over the next one to two weeks, and Instagram will also reduce the number of recommended posts in the app as it works to improve its algorithms. "I'm glad we took a risk -- if we're not failing every once in a while, we're not thinking big enough or bold enough," Instagram chief Adam Mosseri said in an interview. "But we definitely need to take a big step back and regroup. [When] we've learned a lot, then we come back with some sort of new idea or iteration. So we're going to work through that."

The changes come amid growing user frustration over a series of changes to Instagram designed to help it better compete with TikTok and navigate the broader shift in user behavior away from posting static photos toward watching more video. Redesigns often incur the wrath of users who are hostile to change, but in this case the high-profile dissatisfaction was backed up by Instagram's own internal data, Mosseri said. The trend toward users watching more video is real, and pre-dated the rise of TikTok, he said. But it's clear that people actually do dislike Instagram's design changes. "For the new feed designs, people are frustrated and the usage data isn't great," he said. "So there I think that we need to take a big step back, regroup, and figure out how we want to move forward."

The company also plans to show users fewer recommendations. On Wednesday, Meta CEO Mark Zuckerberg said [on an earnings call (PDF)] that recommended posts and accounts in feeds currently account for about 15 percent of what you see when you browse Facebook, and an even higher percentage on Instagram. By the end of 2023, that figure will be around 30 percent, Zuckerberg said. But Instagram will temporarily reduce the amount of recommended posts and accounts as it works to improve its personalization tools. (Mosseri wouldn't say by how much, exactly.) "When you discover something in your field that you didn't follow before, there should be a high bar -- it should just be great," Mosseri said. "You should be delighted to see it. And I don't think that's happening enough right now. So I think we need to take a step back, in terms of the percentage of feed that are recommendations, get better at ranking and recommendations, and then -- if and when we do -- we can start to grow again." ("I'm confident we will," he added.) Mosseri made clear that the retreat Instagram announced today is not permanent.

Businesses

JetBlue Announces a Deal To Buy Spirit Airlines. Fares Could Surge (cnn.com) 41

JetBlue Airways on Thursday announced it would purchase Spirit Airlines, a combination that would create America's fifth-largest airline. From a report: The announcement comes a day after Spirit pulled the plug on a deal to merge with Frontier. JetBlue had been pursuing a hostile bid for Spirit even while Spirit sought shareholder approval for a lower-priced deal with Frontier. Spirit had continually expressed concern whether regulators would approve a deal with JetBlue. But shareholders had balked at accepting Frontier's less-valuable cash-and-stock offer when they had JetBlue's all-cash offer on the table. JetBlue CEO Robin Hayes said the deal will be fruitful for investors and passengers. "We are excited to deliver this compelling combination that turbocharges our strategic growth, enabling JetBlue to bring our unique blend of low fares and exceptional service to more customers, on more routes," he said in a statement. The companies said the deal is worth $3.8 billion.
Businesses

Senate Bill Takes Aim at Visa and Mastercard's Rising Credit Card Fees For Merchants (marketwatch.com) 78

Two U.S. senators are preparing legislation that would give merchants power to process many Visa and Mastercard credit cards over different networks. From a report: The bill, which could be introduced as soon as this week, aims to create more competition among U.S. credit-card networks, a sector where Visa and Mastercard have long dominated. Sen. Dick Durbin, an Illinois Democrat, and Sen. Roger Marshall, a Kansas Republican, are expected to introduce the bill. Mr. Marshall said banks and major card networks lobbied his office to not sign onto the bill. He decided to move forward after hearing from a growing number of merchants, including small businesses, restaurants, gas stations and convenience stores, about the toll of the rising credit-card fees set by Visa and Mastercard that are often pocketed by large banks.
Security

Discovery of New UEFI Rootkit Exposes an Ugly Truth: The Attacks Are Invisible To Us (arstechnica.com) 118

joshuark writes: Dan Goodin of Ars Technica reports that security researchers have found that rootkits for Unified Extensible Firmware Interface (UEFI) are not rare, and difficult to detect. Kaspersky researchers profiled CosmicStrand, the security firm's name for a sophisticated UEFI rootkit that the company detected and obtained through its antivirus software. They state: "The most striking aspect of this report is that this UEFI implant seems to have been used in the wild since the end of 2016 -- long before UEFI attacks started being publicly described." The researchers warned that "the multiple rootkits discovered so far evidence a blind spot in our industry that needs to be addressed sooner rather than later."
United States

Apple and Google Come Under Scrutiny For Scammy Crypto Apps (theverge.com) 15

An anonymous reader shares a report: From Elon Musk Twitter impersonators to dubious Discord chats, cryptocurrency and non-fungible token (NFT) scammers have stolen billions of dollars from investors over the last few years. But now, politicians and law enforcement are turning their attention to Apple and Google -- companies that operate huge app stores -- and how they review fraudulent crypto apps.

In letters to Apple CEO Tim Cook and Google CEO Sundar Pichai on Thursday, Sen. Sherrod Brown (D-OH) asked that the companies explain their processes in reviewing and approving crypto trading and wallet apps for download on their app stores. Brown's inquiry follows a recently released FBI report warning that 244 investors have been scammed out of $42.7 million from fraudulent cryptocurrency apps claiming to be credible investment platforms in under a year. "Crypto mobile apps are available to the public through app stores, including Apple's App Store," the senator wrote to Cook on Thursday. "While cryptocurrency apps have offered investors easy and convenient ways to trade cryptocurrency, reports have emerged of fake crypto apps that have scammed hundreds of investors."

Slashdot Top Deals