The Military

DARPA Is Worried About How Well Open-Source Code Can Be Trusted (technologyreview.com) 85

An anonymous reader quotes a report from MIT Technology Review: "People are realizing now: wait a minute, literally everything we do is underpinned by Linux," says Dave Aitel, a cybersecurity researcher and former NSA computer security scientist. "This is a core technology to our society. Not understanding kernel security means we can't secure critical infrastructure." Now DARPA, the US military's research arm, wants to understand the collision of code and community that makes these open-source projects work, in order to better understand the risks they face. The goal is to be able to effectively recognize malicious actors and prevent them from disrupting or corrupting crucially important open-source code before it's too late. DARPA's "SocialCyber" program is an 18-month-long, multimillion-dollar project that will combine sociology with recent technological advances in artificial intelligence to map, understand, and protect these massive open-source communities and the code they create. It's different from most previous research because it combines automated analysis of both the code and the social dimensions of open-source software.

Here's how the SocialCyber program works. DARPA has contracted with multiple teams of what it calls "performers," including small, boutique cybersecurity research shops with deep technical chops. One such performer is New York -- based Margin Research, which has put together a team of well-respected researchers for the task. Margin Research is focused on the Linux kernel in part because it's so big and critical that succeeding here, at this scale, means you can make it anywhere else. The plan is to analyze both the code and the community in order to visualize and finally understand the whole ecosystem.

Margin's work maps out who is working on what specific parts of open-source projects. For example, Huawei is currently the biggest contributor to the Linux kernel. Another contributor works for Positive Technologies, a Russian cybersecurity firm that -- like Huawei -- has been sanctioned by the US government, says Aitel. Margin has also mapped code written by NSA employees, many of whom participate in different open-source projects. "This subject kills me," says d'Antoine of the quest to better understand the open-source movement, "because, honestly, even the most simple things seem so novel to so many important people. The government is only just realizing that our critical infrastructure is running code that could be literally being written by sanctioned entities. Right now." This kind of research also aims to find underinvestment -- that is critical software run entirely by one or two volunteers. It's more common than you might think -- so common that one common way software projects currently measure risk is the "bus factor": Does this whole project fall apart if just one person gets hit by a bus?
SocialCyber will also tackle other open-source projects too, such as Python which is "used in a huge number of artificial-intelligence and machine-learning projects," notes the report. "The hope is that greater understanding will make it easier to prevent a future disaster, whether it's caused by malicious activity or not."
United Kingdom

UK's Online Safety Bill On Pause Pending New PM (techcrunch.com) 24

An anonymous reader quotes a report from TechCrunch: A major populist but controversial piece of U.K. legislation to regulate internet content through a child safety-focused frame is on pause until the fall when the government expects to elect a new prime minister, following the resignation of Boris Johnson as Conservative Party leader last week. PoliticsHome reported yesterday that the Online Safety Bill would be dropped from House of Commons business next week with a view to being returned in the autumn. The Department for Digital, Culture, Media and Sport (DCMS) denied the legislation was being dropped altogether but the fate of the bill will clearly now rest with the new prime minister -- and their appetite for regulating online speech.

Reached for comment, DCMS confirmed that the bill's final day of report stage will be rescheduled to after the summer recess -- suggesting it had lost out to competing demands for remaining parliamentary time (without specifying to what). The department also made a point of reiterating that the legislation intends to deliver on the government's manifesto commitment to make the U.K. the safest place in the world to be online while defending freedom of speech. But critics of the bill continue to warn it vastly overreaches on content regulation while saddling the U.K.'s digital sector with crippling compliance costs.

Windows

Microsoft Moves To New Windows Development Cycle (windowscentral.com) 122

Microsoft is shifting to a new engineering schedule for Windows which will see the company return to a more traditional three-year release cycle for major versions of the Windows client, while simultaneously increasing the output of new features shipping to the current version of Windows on the market. Zac Bowden writes via Windows Central: The news comes just a year after the company announced it was moving to a yearly release cadence for new versions of Windows. According to my sources, Microsoft now intends to ship "major" versions of the Windows client every three years, with the next release currently scheduled for 2024, three years after Windows 11 shipped in 2021. This means that the originally planned 2023 client release of Windows (codenamed Sun Valley 3) has been scrapped, but that's not the end of the story. I'm told that with the move to this new development schedule, Microsoft is also planning to increase the output of new features rolling out to users on the latest version of Windows.

Starting with Windows 11 version 22H2 (Sun Valley 2), Microsoft is kicking off a new "Moments" engineering effort which is designed to allow the company to rollout new features and experiences at key points throughout the year, outside of major OS releases. I hear the company intends to ship new features to the in-market version of Windows every few months, up to four times a year, starting in 2023. Microsoft has already tested this system with the rollout of the Taskbar weather button on Windows 11 earlier this year. That same approach will be used for these Moments, where the company will group together a handful of new features that have been in testing with Insiders and roll them out to everyone on top the latest shipping release of Windows. Many of the features that were planned for the now-scrapped Sun Valley 3 client release will ship as part of one of these Moments on top of Sun Valley 2, instead of in a dedicated new release of the Windows client in the fall of 2023.

EU

EU Lawmakers Slam 'Radical Proposal' To Let ISPs Demand New Fees From Websites (arstechnica.com) 42

An anonymous reader quotes a report from Ars Technica: Fifty-four members of the European Parliament (MEPs) are protesting what they call a "radical proposal" to require payments from online service providers to Internet service providers. Noting that Europe's 2015 "Open Internet Regulation ensures that citizens are free to use whichever apps and websites they wish," the MEPs said they have "deep concern about the European Commission's plans to change our net neutrality legislation in the upcoming Connectivity Infrastructure Act to be proposed in autumn, without having consulted the public, technology experts, academics, civil society, or expert regulatory agencies."

No specific proposal has been released, but "statements to the press indicate that a new provision would require payments from online service providers to broadband providers -- ostensibly to fund the rollout of 5G and fiber to the home," the MEPs wrote in the letter yesterday (PDF) to the European Commission. The letter cited a May 2 Reuters article that said, "Tech giants such as Google, Meta, and Netflix may have to bear some of the cost of Europe's telecoms network, Europe's digital chief Margrethe Vestager said on Monday, following EU telecoms operators' complaints." The MEPs' list of references also includes two Ars Technica articles from 2012 when a similar proposal was being discussed.

Vestager reportedly said at a news conference that "there are players who generate a lot of traffic that then enables their business but who have not been contributing actually to enable that traffic. They have not been contributing to enabling the investments in the rollout of connectivity... and we are in the process of getting a thorough understanding of how could that be enabled." [...] The MEPs' letter further argued that charging websites for access to broadband consumers would help ISPs abuse their monopolies: "Adopting a model that allows for or mandates access fees would be a disastrous return to the economic model for telephony, where telecommunications companies and countries leveraged their termination access monopolies to make communication expensive. Because phone companies had a monopoly over their customers, they could charge exorbitant prices to anyone seeking to call their customers. Broadband providers have the same monopoly over their customers. Allowing them to charge content providers for access could cause significant harm to the Internet economy." The MEPs also doubt such fees would improve broadband connectivity, saying that "factors such as permits or construction capacities can act as more severe barriers than lack of funding." They urged the European Commission to take its time and open an official consultation, saying, "There is no emergency that requires action in autumn 2022."

Music

New Windows Media Player App Travels Back in Time, Gains the Ability To Rip CDs (arstechnica.com) 65

In March, Microsoft enabled audio CD playback in the new version of Media Player, something that the old version had supported for pretty much as long as it had existed. And now, Microsoft is rolling out support for CD ripping in the new version of Media Player, presumably so that we can all convert our old Weezer and Matchbox 20 CDs into files we can copy over to our iPods and Zunes. From a report: By default, CDs can be ripped to AAC files at constant bitrates ranging between 96 and 320kbps. The WMA, FLAC, and ALAC formats are also supported. MP3 support and variable bitrate support, two features that are still included in the "Media Player Legacy" app, are notably absent.
Technology

Samsung Develops GDDR6 DRAM With 24Gbps Speed for Graphics Cards (zdnet.com) 20

Samsung said on Thursday that it has developed a new GDDR6 (graphics double data rate) DRAM with a data transfer rate of 24 gigabits per second (Gbps). From a report: A premium graphics card that packs the chips will support a data processing rate of up to 1.1 terabytes (TB), equivalent to processing 275 movies in Full HD resolution within a second, the South Korean tech giant said. Samsung said the DRAM was comprised of 16Gb chips using its third-generation 10nm process node, which also incorporates extreme ultraviolet (EUV) lithography during their production. The company also applied high-k metal gates, or the use of metals besides silicon dioxide to make the gate hold more charge, on the DRAM. Samsung said this allowed its latest DRAM to operate at a rate over 30% faster than its 18Gbps GGDR6 DRAM predecessor.
Your Rights Online

India Proposes Right To Repair Framework for Mobile Phones, Consumer Durables (techcrunch.com) 7

India has proposed to introduce a right to repair law, aiming to provide consumers the ability to have their devices repaired by third parties to fight the growing "culture of planned obsolescence" in a move that follows similar deliberations in the U.S. and the UK. From a report: The Indian Department of Consumer Affairs said Wednesday that it had set up a committee to develop a right to repair framework. The committee identified mobile phones, tablets, consumer durables, automobiles and farming as important sectors for the framework, the ministry said. "The pertinent issues highlighted during the meeting include companies avoiding the publication of manuals that can help users make repairs easily," the ministry said in a statement.
Technology

Stripe Cuts Internal Valuation by 28% To $74 Billion (wsj.com) 10

Payments giant Stripe, last valued by private investors at $95 billion, cut the internal value of its shares by 28%, WSJ reported Thursday, citing people familiar with the matter. From the report: Stripe told employees in an email Friday that the internal share price was about $29, compared with $40 in the most previous internal valuation, known as a 409A valuation, the people said. The move lowered the implied valuation of those shares to $74 billion, according to one of the people, which is calculated separately from the stock owned by major shareholders. Stripe said in the email that the board approved the lower share price effective June 30, the people said. The payments processor to startups and fast-growing internet companies didn't explain the decision to lower its internal valuation, the people said. The decision comes amid a prolonged market selloff that has slowed down the pace of private fundraising and pushed startups to slash costs and cut jobs.
Operating Systems

Google's Chrome OS Flex is Now Available for Old PCs and Macs (theverge.com) 60

Google is releasing Chrome OS Flex today, a new version of Chrome OS that's designed for businesses and schools to install and run on old PCs and Macs. From a report: Google first started testing Chrome OS Flex earlier this year in an early access preview, and the company has now resolved 600 bugs to roll out Flex to businesses and schools today. Chrome OS Flex is designed primarily for businesses running old Windows PCs, as Google has been testing and verifying devices from Acer, Asus, Dell, HP, Lenovo, LG, Toshiba, and many more OEMs. Flex will even run on some old Macs, including some 10-year-old MacBooks. The support of old hardware is the big selling point of Chrome OS Flex, as businesses don't have to ditch existing hardware to get the latest modern operating system. More than 400 devices are certified to work, and installation is as easy as using a USB drive to install Chrome OS Flex.
Intel

Intel's 12th Gen CPU Can't Handle the Bar Exam (theverge.com) 101

Law students getting ready to take the Bar exam digitally may run into a serious issue: one of the nation's most frequently-used test-taking software packages, Examplify, is incompatible with Intel's latest generation of processors. From a report: In a notice to users, ExamSoft, the company that owns Examplify, writes that 12th Gen Intel processors aren't compatible with its software. "New Windows devices containing the Intel 12th generation chipset are triggering Examplify's automatic virtual machine check," Examplify's notice reads. "These are NOT currently supported. Therefore, they cannot be used for the upcoming July 2022 bar exam." One user drew attention to the issue in a post on Twitter, and included a screencap of what appears to be a notice given to Bar applicants.
United States

Ex-CIA Engineer Convicted in Biggest Theft Ever of Agency Secrets (nytimes.com) 50

A former Central Intelligence Agency software engineer was convicted by a federal jury on Wednesday of causing the largest theft of classified information in the agency's history. From a report: The former C.I.A. employee, Joshua Schulte, was arrested after the 2017 disclosure by WikiLeaks of a trove of confidential documents detailing the agency's secret methods for penetrating the computer networks of foreign governments and terrorists. The verdict came two years after a previous jury failed to agree on eight of the 10 charges he faced then.

At the earlier trial, Mr. Schulte, 33, was found guilty of contempt of court and of making false statements to the F.B.I. He was convicted on Wednesday on nine counts, which included illegally gathering national defense information and illegally transmitting that information. Damian Williams, the United States attorney in Manhattan, where the trial was held, hailed the verdict. Mr. Schulte has been convicted of "one of the most brazen and damaging acts of espionage in American history," Mr. Williams said in a statement.

Twitter

Twitter Outage Hits Thousands, Downdetector Reports (bloomberg.com) 46

Twitter faced a brief outage on Thursday, leaving thousands of users without service for about an hour. From a report: At the peak, at 8:20 a.m. in New York, 54,582 users reported problems on Downdetector.com, an outage tracking platform. Twitter's website displayed an error message and prompted users to reload the page. It wasn't immediately clear what caused the outage. A message on Twitter's support account posted at 9:10 a.m. said: "Some of you are having issues accessing Twitter and we're working to get it back up and running for everyone. Thanks for sticking with us." By 9:16 a.m., about 1,600 users reported they were still having trouble. The last time Twitter faced an outage was in February, when the site crashed due to a "technical bug" on the page. In its early days, Twitter was famous for crashing amid high traffic, leading to the iconic "fail whale" image that popped up when service was down.
Books

A Copyright Lawsuit Threatens To Kill Free Access To Internet Archive's Library of Books (popsci.com) 50

An anonymous reader quotes a report from Popular Science: Internet Archive, a non-profit digital library and a massive repository of online artifacts, has been collecting mementos of the ever-expanding World Wide Web for over two decades, allowing users to revisit sites that have since been changed or deleted. But like the web, it too has evolved since its genesis, and in the aughts, it also began to offer a selection of ebooks that any internet user can check out with the creation of a free account. That latter feature has gotten the organization in some trouble. Internet Archive was sued by a suite of four corporate publishers in 2020 over copyright controversies -- with one side saying that what Internet Archive does is preservation, and the other saying that it's piracy, since it freely distributes books as image files without compensating the author. Last week, the ongoing case entered a new chapter as the nonprofit organization filed a motion for summary judgment, asking a federal judge to put a stop to the lawsuit, arguing that their Controlled Digital Lending program "is a lawful fair use that preserves traditional library lending in the digital world" since "each book loaned via CDL has already been bought and paid for." On Friday, Creative Commons issued a statement supporting Internet Archive's motion.

In 2006, Internet Archive started a program for digitizing books both under copyright and in the public domain. It works with a range of global partners, including other libraries, to scan materials onto its site (Cornell University made a handy guide on what works fall under copyright vs. the public domain). For copyrighted books, Internet Archive owns the physical books that they created the digital copies from and limits their circulation by allowing only one person to borrow a title at a time. Book publishers, namely Hachette Book Group, HarperCollins, John Wiley Sons, and Penguin Random House, were not keen on this practice, and they have been seeking financial damages for the 127 books (PDF) shared under copyright. Vox estimated that if the publishers win, Internet Archive would have to pay $19 million, which is about "one year of operating revenue."

In the most recent filings, the publishers accused Internet Archive of amassing "a collection of more than three million unauthorized in-copyright ebooks -- including more than 33,000 of the Publishers' commercially available titles -- without obtaining licenses to do so or paying the rightsholders a cent for exploiting their works. Anybody in the world with an internet connection can instantaneously access these stolen works via IA's interrelated archive.org and openlibrary.org websites." In its defense, Internet Archive, which is being represented by the Electronic Frontier Foundation, says that "libraries have been practicing CDL in one form or another for more than a decade," and that Internet Archive lends its digitized books on an "owned-to-loaned basis, backstopped by strong technical protections to enforce lending limits."

Software

Ex-Google Chief's Venture Aims To Save Neglected Science Software (nature.com) 23

David Matthews writes via Nature: See whether this sounds familiar: you build a piece of software to solve a research question. But when you move on to the next project, there's no one to maintain it. As it ages, it becomes obsolete, and the next academic to tackle a similar problem finds themselves having to reinvent the wheel. [...] Now, a funding initiative hopes to help ease that burden. [...] In January, Schmidt Futures, a science and technology-focused philanthropic organization founded by former Google chief executive Eric Schmidt and his wife Wendy, launched the Virtual Institute for Scientific Software (VISS), a network of centers across four universities in the United States and the United Kingdom. Each institution will hire around five or six engineers, says Stuart Feldman, Schmidt Futures' chief scientist, with funding typically running for five years and being reviewed annually. Overall, Schmidt Futures is putting US$40 million into the project, making it among the largest philanthropic investments in this area. The aim is to overcome a culture of relative neglect in academia for open-source scientific software, Feldman says, adding that support for software engineering is "a line item, just like fuel" at organizations such as NASA. "It's only in the university research lab environment where this is ancillary," he says. [...]

Those setting up VISS centers say Schmidt Futures' steady, relatively long-term funding will help them to overcome a range of problems endemic to academic software. Research grants rarely provide for software development, and when they do, the positions they fund are seldom full-time and long-term. "If you've got all of this fractional effort, it's really hard to hire people and provide them with a real career path," says Andrew Connolly, an astronomer who is also helping to set up the Washington centre. What's more, software engineers tend to be scattered and isolated across a university. "Peer development and peer community is really important to those types of positions," says Stone. "And that would be extraordinarily rare in academia." To counter this, VISS centers hope to create cohesive, stable teams that can learn from one another. [...]

Dario Taraborelli, who helps to coordinate another privately funded scientific-software project at the Chan Zuckerberg Initiative (CZI) in California, says that such initiatives fill a key gap in the scientific-software ecosystem, because funding agencies too often fail to prioritize crucial software infrastructure. Although there are now "substantial" grants dedicated to creating software, he says, there's precious little funding available to maintain what is built. Computer scientist Alexander Szalay, who is helping to set up a VISS centre at Johns Hopkins, agrees, noting that very few programs get to a point where enough researchers use and update them to remain useful. "They don't survive this 'Valley of Death,'" he says. "The funding stops when they actually develop the software prototype."

Google

Google Files a Lawsuit That Could Kick Tinder Out of the Play Store (engadget.com) 59

Google has counter-sued Match seeking monetary damages and a judgement that would let it kick Tinder and the group's other dating apps out of the Play Store, Bloomberg has reported. Engadget reports: Earlier this year, Match sued Google alleging antitrust violations over a decision requiring all Android developers to process "digital goods and services" payments through the Play Store billing system. Following the initial lawsuit in May, Google and Match reached a temporary agreement allowing Match to remain on the Play Store and use its own payments system. Google also agreed to make a "good faith" effort to address Match's billing concerns. Match, in turn, was to make an effort to offer Google's billing system as an alternative.

However, Google parent Alphabet claims that Match Group now wants to avoid paying "nothing at all" to Google, including its 15 to 30 percent Play Store fees, according to a court filing. "Match Group never intended to comply with the contractual terms to which it agreed... it would also place Match Group in an advantaged position relative to other app developers," the document states. Match group said that Google's Play Store policies violate federal and state laws. "Google doesn't want anyone else to sue them so their counterclaims are designed as a warning shot," Match told Bloomberg in a statement. "We are confident that our suit, alongside other developers, the US Department of Justice and 37 state attorneys general making similar claims, will be resolved in our favor early next year."

Wikipedia

A Bored Chinese Housewife Spent Years Falsifying Russian History On Wikipedia (vice.com) 106

An anonymous reader writes: Posing as a scholar, a Chinese woman spent years writing alternative accounts of medieval Russian history on Chinese Wikipedia, conjuring imaginary states, battles, and aristocrats in one of the largest hoaxes on the open-source platform. The scam was exposed last month by Chinese novelist Yifan, who was researching for a book when he came upon an article on the Kashin silver mine. Discovered by Russian peasants in 1344, the Wikipedia entry goes, the mine engaged more than 40,000 slaves and freedmen, providing a remarkable source of wealth for the Russian principality of Tver in the 14th and 15th centuries as well as subsequent regimes. The geological composition of the soil, the structure of the mine, and even the refining process were fleshed out in detail in the entry.

Yifan thought he'd found interesting material for a novel. Little did he know he'd stumbled upon an entire fictitious world constructed by a user known as Zhemao. It was one of 206 articles she has written on Chinese Wikipedia since 2019, weaving facts into fiction in an elaborate scheme that went uncaught for years and tested the limits of crowdsourced platforms' ability to verify information and fend off bad actors. "The content she wrote is of high quality and the entries were interconnected, creating a system that can exist on its own," veteran Chinese Wikipedian John Yip told VICE World News. "Zhemao single-handedly invented a new way to undermine Wikipedia."

Yifan was tipped off when he ran the silver mine story by Russian speakers and fact-checked Zhemao's references, only to find that the pages or versions of the books she cited did not exist. People he consulted also called out her lengthy entries on ancient conflicts between Slavic states, which could not be found in Russian historical records. "They were so rich in details they put English and Russian Wikipedia to shame," Yifan wrote on Zhihu, a Chinese site similar to Quora, where he shared his discovery last month and caused a stir. The scale of the scam came to light after a group of volunteer editors and other Wikipedians, such as Yip, combed through her past contributions to nearly 300 articles.
"As a punishment, Zhemao and her affiliated accounts were suspended permanently," adds VICE World News. "Most of her articles were deleted based on community consensus. Some Wikipedians even wrote to experts, seeking help to separate the wheat from the chaff." A spokesperson of the Wikimedia Foundation told VICE World News in an email that volunteers are still "continuing to review additional articles that may have been affected."

The report goes on to say that Zhemao speaks neither English nor Russian and is a housewife with only a high school degree. She came clean in an apology letter issued on her Wikipedia account last month. "The hoax started with an innocuous intention," reports VICE. "Unable to comprehend scholarly articles in their original language, she pieced sentences together with a translation tool and filled in the blanks with her own imagination. [...] Before long, they had accumulated into tens of thousands of characters, which she was reluctant to delete."

"The alternative accounts were imaginary friends she 'cosplayed' as she was bored and alone, given her husband was away most of the time and she didn't have any friends. She also apologized to actual experts on Russia, whom she had attempted to cozy up to and later impersonated."
Spam

Gmail Users 'Hard Pass' On Plan To Let Political Emails Bypass Spam Filters (arstechnica.com) 62

An anonymous reader quotes a report from Ars Technica: Earlier this month, Google sent a request (PDF) to the Federal Election Commission seeking an advisory opinion on the potential launch of a pilot program that would allow political committees to bypass spam filters and instead deliver political emails to the primary inboxes of Gmail users. During a public commenting period that's still ongoing, most people commenting have expressed staunch opposition for various reasons that they're hoping the FEC will consider. "Hard pass," wrote a commenter called Katie H. "Please do not allow Google to open up Pandora's Box on the people by allowing campaign/political emails to bypass spam filters."

Out of 48 comments submitted (PDF) as of July 11, only two commenters voiced support for Google's pilot program, which seeks to deliver more unsolicited political emails to Gmail users instead of marking them as spam. The rest of the commenters opposed the program, raising a range of concerns, including the potential for the policy to degrade user experience, introduce security risks, and even possibly unfairly influence future elections. Business Insider reported that the period for public commenting ends on Saturday, July 16, which is longer than what was shared in conflicting reports that said the initial deadline to comment was July 11. That means there's still time for more Gmail users and interested parties to chime in.
"For some opposing commenters, it's about rejecting unnecessary strains on the Gmail user experience," adds Ars. "In short: People don't want emails coming to their inbox that they did not sign up for."

"Other commenters were more concerned over a perceived government overreach." There were also commenters that said the move could introduce security risks, influence elections, and make Gmail more vulnerable to "emotionally charged" messaging that they never signed up for.
The Internet

For Blind Internet Users, the Fix Can Be Worse Than the Flaws (nytimes.com) 31

Hundreds of people with disabilities have complained about issues with automated accessibility web services, whose popularity has risen sharply in recent years because of advances in A.I. and new legal pressures on companies to make their websites accessible. From a report: Over a dozen companies provide these tools. Two of the largest, AudioEye and UserWay, are publicly traded and reported revenues in the millions in recent financial statements. Some charge monthly fees ranging from about $50 to about $1,000, according to their websites, while others charge annual fees in the several-hundred-dollar or thousand-dollar range. (Pricing is typically presented in tiers and depends on how many pages a site has.) These companies list major corporations like Hulu, eBay and Uniqlo, as well as hospitals and local governments, among their clients. Built into their pitch is often a reassurance that their services will not only help people who are blind or low vision use the internet more easily but also keep companies from facing the litigation that can arise if they don't make their sites accessible. But it's not working out that way.

Users like Mr. Perdue [an anecdote in the linked story] say the software offers little help, and some of the clients that use AudioEye, accessiBe and UserWay are facing legal action anyway. Last year, more than 400 companies with an accessibility widget or overlay on their website were sued over accessibility, according to data collected by a digital accessibility provider. "I've not yet found a single one that makes my life better," said Mr. Perdue, 38, who lives in Queens. He added, "I spend more time working around these overlays than I actually do navigating the website." Last year, over 700 accessibility advocates and web developers signed an open letter calling on organizations to stop using these tools, writing that the practical value of the new features was "largely overstated" and that the "overlays themselves may have accessibility problems." The letter also noted that, like Mr. Perdue, many blind users already had screen readers or other software to help them while online.

Technology

Global PC Shipments Down 15% in Q2 2022 Due To Chinese Production Crunch (canalys.com) 7

The second quarter of 2022 brought major disruption to the PC market, as COVID lockdowns in China stymied manufacturing. Research firm Canalys: The latest Canalys data shows total shipments of desktops and notebooks fell 15.0% annually to 70.2 million units, the lowest level since a similar disruption occurred in Q1 2020. Demand headwinds, especially from consumers, have also ramped up as inflation remains unchecked in many of the world's largest PC markets. Notebook shipments fell 18.6% in Q2 2022 at 54.5 million units, down for a third consecutive quarter as education procurement remained muted compared with the same quarter a year ago. Desktops fared much better, posting modest growth of 0.6% to 15.6 million units as the strength of commercial demand amid the further opening of economies helped spur investment in desktop refreshes and upgrades. The premium commercial segment will remain a bright spot for the overall PC market this year, despite mounting challenges in the global macroeconomic outlook.
Security

Almost Everyone Faced an Industrial Attack in the Last Year (csoonline.com) 9

A report commissioned by cloud security company Barracuda found that 94% of respondents have experienced some form of attack on their industrial IoT (IIoT) or operational technology (OT) systems during the last 12 months. From a report: The State of Industrial Security in 2022 report surveyed 800 senior IT and security officers responsible for these industrial systems. "In the current threat landscape, critical infrastructure is an attractive target for cybercriminals, but unfortunately IIoT/OT security projects often take a backseat to other security initiatives or fail due to cost or complexity, leaving organizations at risk," said Tim Jefferson, senior vice president for data protection, network, and application security at Barracuda said in a statement accompanying the report.

Recent attacks such as those targeted through the SolarWinds attack, and the Russian DDoS attack on Lithuania last month, have raised concerns over nation state-backed attacks on industrial systems. As a result, the survey found that 89% of the respondents are very or fairly concerned about the current geopolitical situation. Constellation Research analyst Liz Miller acknowledged that "the Russian invasion of Ukraine set the world on high alert as it anticipated vulnerabilities in IIoT devices becoming prime targets should the battle enter the cyberspace."

Slashdot Top Deals