Verizon

Verizon, AT&T Agree to Delay Some 5G Rollouts Near Airports (apnews.com) 21

The Associated Press reports: Federal regulators say Verizon and AT&T will delay part of their 5G rollout near airports to give airlines more time to ensure that equipment on their planes is safe from interference from the wireless signals, but the airline industry is not happy about the deal. An airline industry trade group said federal regulators are taking a "rushed approach" to changing equipment on planes under pressure from the telecommunications companies.

The Federal Aviation Administration said Friday that the wireless companies agreed to delay some of their use of the C-Band section of the radio spectrum until July 2023. "We believe we have identified a path that will continue to enable aviation and 5G C-band wireless to safely co-exist," said the FAA's acting administrator, Billy Nolen. However, aviation groups say the C-Band service could interfere with radio altimeters — devices used to measure a plane's height above the ground....

Nolen said planes most susceptible to interference — smaller, so-called regional airline planes — must be retrofitted with filters or new altimeters by the end of this year. Components to retrofit larger planes used by major airlines should be available by July 2023, when the wireless companies expect to run 5G networks in urban areas "with minimal restrictions," he said. Airlines for America, a trade group for the largest U.S. carriers, said the FAA hasn't approved necessary upgrades and manufacturers have not yet produced the parts. "It is not at all clear that carriers can meet what appears to be an arbitrary deadline," trade group CEO Nicholas Calio said in a letter to Nolen....

Verizon said the agreement will let the company lift voluntary limits on its 5G rollout around airports "in a staged approach over the coming months." AT&T said it agreed to take "a more tailored approach" to controlling the strength of signals near runways so airlines have more time to retrofit equipment.

Botnet

A Linux Botnet That Spreads Using Stolen SSH Keys (zdnet.com) 40

ZDNet is warning that Linux users need to watch out for "a new peer-to-peer (P2P) botnet that spreads between networks using stolen SSH keys and runs its crypto-mining malware in a device's memory." The Panchan P2P botnet was discovered by researchers at Akamai in March and the company is now warning it could be taking advantage of collaboration between academic institutions to spread by causing previously stolen SSH authentication keys to be shared across networks.

But rather than stealing intellectual property from these educational institutions, the Panchan botnet is using their Linux servers to mine cryptocurrency, according to Akamai... "Instead of just using brute force or dictionary attacks on randomized IP addresses like most botnets do, the malware also reads the id_rsa and known_hosts files to harvest existing credentials and use them to move laterally across the network...." Akamai found 209 peers, but only 40 of them are currently active and they were mostly located in Asia.

And why is the education sector more impacted by Panchan? Akamai guesses this could be because of poor password hygiene, or that the malware moves across the network with stolen SSH keys.

Akamai writes that the malware "catches Linux termination signals (specifically SIGTERM — 0xF and SIGINT — 0x2) that are sent to it, and ignores them.

"This makes it harder to terminate the malware, but not impossible, since SIGKILL isn't handled (because it isn't possible, according to the POSIX standard, page 313)."
KDE

KDE Plasma 5.25 Released (kde.org) 27

Long-time Slashdot reader jrepin describes Plasma as "a popular desktop environment, which is also powering the desktop mode on the Steam Deck portable gaming console."

And this week the KDE Community announced the release of KDE Plasma 5.25: This new version brings many improvements...

- The accent colour can now be set based on the prominent colour from the current desktop background image (it updates if you use slide-show wallpapers) and it applies to more graphical elements.

- Floating Panels add a margin all around the panel to make it float while no window is maximised.

- Touch-screen mode can now be activated by detaching the screen, rotating it 360, or enabling it manually.

- The Global Theme settings page lets you pick and choose which parts to apply.

- The Application page for Discover has been redesigned and gives you links to the application's documentation and website, and shows what system resources it has access to.

- Panels can now be navigated with the keyboard, and you can assign custom shortcuts to focus individual panels.

Lilputing.com adds that "There's a new Overview effect that zooms out to display previews of all currently-running apps and virtual desktops. You can access this view with a four-finger pinch on a touchscreen or touchpad, and from this view, you can also search for apps, documents, or browser tabs or add, remove, or rename virtual desktops."
Transportation

World's Most Efficient Passenger Plane Gets Hydrogen Powertrain (newatlas.com) 59

Otto's Celara 500L -- "the most fuel-efficient, commercially viable business aircraft in the world" -- is about to get a hydrogen fuel cell powertrain. New Atlas reports: The Celera 500L is a truly remarkable design. Otto Aviation says its odd shape delivers an astonishing 59 percent reduction in drag, and a massive leap in efficiency and range compared to traditional plane geometries. [...] The whole thing is designed to maximize laminar flow -- smooth layers of airflow with little to no mixing of adjacent layers moving at different speeds. This avoids the swirls and eddies that lead to air turbulence at speed, causing aerodynamic drag and wasted energy. Laminar flow is by no means a new concept, but Otto says it's pushed the idea so far forward with the Celera design that it uses 80 percent less fuel than a traditional design. No, that's not a typo. [...]

Now clearly, an 80 percent reduction in fossil fuel use is an environmental win in and of itself. But if there's one sector in aviation that's crying out for brain-busting efficiency figures like the Celera promises, it's the emerging zero-emissions sector, which is currently struggling against poor range figures thanks to the low energy density of lithium batteries. Indeed, when we first wrote about the Celera 500L back in 2020, many questioned why the heck this thing wasn't electric from the get go. And it seems Otto is on board with the idea, as it's now announced a collaboration with hydrogen aviation pioneers ZeroAvia to develop a fuel cell-electric powertrain specific to the Celera's requirements.

This airframe's bulbous shape works well with a hydrogen concept -- hydrogen powertrains can weigh much less than battery-electric ones, but they tend to take up a bit of space. Still, ZeroAvia is being relatively humble with its ambitions to begin with, aiming for a range of just 1,000 nautical miles (1,852 km) of zero-emissions range for a hydrogen-fueled Celera. Still, that's a very useful distance, and pretty extraordinary for a clean electric passenger plane.

Transportation

Boring Company Receives Approval For Expanding Its Tunnels To Downtown Las Vegas (theverge.com) 88

Elon Musk's Boring Company has received unanimous approval to expand its system of tunnels beneath downtown Las Vegas. The Verge reports: The expansion will add stops at landmarks like the Stratosphere and Fremont Street, letting customers hop aboard a Tesla and travel from one part of the city to the next. The network of tunnels, called the Vegas Loop, is supposed to span 29 miles and have 51 stops when finished. But for now, only 1.7-mile tunnels are operational beneath the Las Vegas Convention Center (LVCC), turning what would be a 25-minute walk across the convention center into a two-minute ride.

This most recent expansion gets The Boring Company closer to its goal of building a transportation system that spans the most popular destinations in Las Vegas. "Thanks to the entire team at the City of Last Vegas!" The Boring Company wrote on Twitter in response to the city's approval. "Great discussion today, and TBC is excited to build a safe, convenient, and awesome transportation system in the City." [...] According to the Las Vegas Review-Journal, Steve Hill, the president and CEO of the Las Vegas Convention and Visitors Authority, expects the tunnel system beneath the Strip to start serving customers in 2023. Hill says the portion connecting the LVCC and Resorts World should be operational by the end of this year.

The Internet

Brave Roasts DuckDuckGo Over Bing Privacy Exception (theregister.com) 23

Brave CEO Brendan Eich took aim at rival DuckDuckGo on Wednesday by challenging the web search engine's efforts to brush off revelations that its Android, iOS, and macOS browsers gave, to a degree, Microsoft Bing and LinkedIn trackers a pass versus other trackers. The Register reports: Eich drew attention to one of DuckDuckGo's defenses for exempting Microsoft's Bing and LinkedIn domains, a condition of its search contract with Microsoft: that its browsers blocked third-party cookies anyway. "For non-search tracker blocking (e.g. in our browser), we block most third-party trackers," explained DuckDuckGo CEO Gabriel Weinberg last month. "Unfortunately our Microsoft search syndication agreement prevents us from doing more to Microsoft-owned properties. However, we have been continually pushing and expect to be doing more soon."

However, Eich argues this is disingenuous because DuckDuckGo also includes exceptions that allow Microsoft trackers to circumvent third-party cookie blocking via appended URL parameters. "Trackers try to get around cookie blocking by appending identifiers to URL query parameters, to ID you across sites," he explained. DuckDuckGo is aware of this, Eich said, because its browser prevents Google, Facebook, and others from appending identifiers to URLs in order to bypass third-party cookie blocking. "[DuckDuckGo] removes Google's 'gclid' and Facebook's 'fbclid'," Eich said. "Test it yourself by visiting https://example.org/?fbclid=sample in [DuckDuckGo]'s macOS browser. The 'fbclid' value is removed." "However, [DuckDuckGo] does not apply this protection to Microsoft's 'msclkid' query parameter," Eich continued. "[Microsoft's] documentation specifies that 'msclkid' exists to circumvent third-party cookie protections in browsers (including in Safari's browser engine used by DDG on Apple OSes)." Eich concluded by arguing that privacy-focused brands need to prioritize privacy. "Brave categorically does not and will not harm user privacy to satisfy partners," he said.

A spokesperson for DuckDuckGo characterized Eich's conclusion as misleading. "What Brendan seems to be referring to here is our ad clicks only, which is protected in our agreement with Microsoft as strictly non-profiling (private)," a company spokesperson told The Register in an email. "That is these ads are privacy protected and how he's framed it is ultimately misleading. Brendan, of course, kept the fact that our ads are private out and there is really nothing new here given everything has already been disclosed." In other words, allowing Bing to append its identifier to URLs enables Bing advertisers to tell whether their ad produced a click (a conversion), but not to target DuckDuckGo browser users based on behavior or identity.

DuckDuckGo's spokesperson pointed to Weinberg's attempt to address the controversy on Reddit and argued that DuckDuckGo provides very strong privacy protections. "This is talking about link tracking which no major browser protects against (see https://privacytests.org/), however we've started protecting against link tracking, and started with the primary offenders (Google and Facebook)," DuckDuckGo's spokesperson said. "To note, we are planning on expanding this to more companies, including Twitter, Microsoft, and more. We are not restricted from this and will be doing so."

Software

Microsoft Updates Store Rules To Ban Paid Copycat Open-Source Projects (ghacks.net) 37

Microsoft updated the Microsoft Store policies yesterday to prohibit publishers from charging fees for software that is open source or generally available for free. They're also no longer allowed to set irrationally high price tags for their products. gHacks reports: If you have been to the Microsoft Store in the past couple of years, you may have noticed that it is home to more and more open source and free products. While that would be a good thing if the original developer would have uploaded the apps and games to the store, it is not, because the uploads have been made by third-parties. Even worse is the fact that many of these programs are not freely available, but available as paid applications. In other words: Microsoft customers have to pay money to buy a Store version of an app that is freely available elsewhere. Sometimes, free and paid versions exist side by side in the Store. Having to pay for a free application is bad enough, but this is not the only issue that users may experience when they make the purchase. Updates may be of concern as well, as the copycat programs may not be updated as often or as quickly as the source applications.

Open source and free products may not be sold anymore on the Microsoft Store, if generally available for free, and publishers are not allowed to set irrationally high price tags for their products anymore. The developers of open source and free applications may charge for their products on the Microsoft Store, the developer of Paint.net does that, for example. If Microsoft enforces the policies, numerous applications will be removed from the Store. Developers could report applications to Microsoft before, but the new policies give Microsoft control over application listings and submissions directly.

Crime

Stolen Goods Sold on Amazon, eBay and Facebook Are Causing Havoc for Major Retailers (cnbc.com) 106

Over the past year, large-scale robberies have swept through stores like Louis Vuitton in San Francisco's Union Square and a nearby Nordstrom, which was robbed by 80 people. Law enforcement and retailers have warned the public that this isn't traditional shoplifting. Rather, what they're seeing is theft organized by criminal networks. And there's a reason it's on the rise. From a report: "What fuels this as an enterprise is the ease of reselling stolen merchandise on online marketplaces," said Illinois Attorney General Kwame Raoul, who convened a national task force of state attorneys to make it easier to investigate across state lines. "It's no longer the age where it's done at flea markets or in the alley or in parking lots." Retailers say a total of $68.9 billion of products were stolen in 2019. In 2020, three-quarters said they saw an increase in organized crime and more than half reported cargo theft. Some big chains blame organized theft for recent store closures or for their decisions to limit hours.

For the U.S. Government's Homeland Security Investigations unit, organized retail crime probes are on the rise. Arrests and indictments increased last year from 2020, along with the value of stolen goods that was seized. While data is imprecise about the perpetrators, there's growing consensus that an entirely different group should be held accountable: e-commerce sites. Amazon, eBay and Facebook are the places where these stolen goods are being sold, and critics say they're not doing enough to put an end to the racket. The companies disagree.

Businesses

Leaked Amazon Memo Warns the Company is Running Out of People To Hire in Its Warehouses (vox.com) 128

Amazon is facing a looming crisis: It could run out of people to hire in its US warehouses by 2024, according to leaked Amazon internal research from mid-2021 that Recode reviewed. If that happens, the online retailer's service quality and growth plans could be at risk, and its e-commerce dominance along with it. From a report: Raising wages and increasing warehouse automation are two of the six "levers" Amazon could pull to delay this labor crisis by a few years, but only a series of sweeping changes to how the company does business and manages its employees will significantly alter the timeline, Amazon staff predicted. "If we continue business as usual, Amazon will deplete the available labor supply in the US network by 2024," the research, which hasn't previously been reported, says.

The report warned that Amazon's labor crisis was especially imminent in a few locales, with internal models showing that the company was expected to exhaust its entire available labor pool in the Phoenix, Arizona, metro area by the end of 2021, and in the Inland Empire region of California, roughly 60 miles east of Los Angeles, by the end of 2022. Amazon's internal report calculated the available pool of workers based on characteristics like income levels and a household's proximity to current or planned Amazon facilities; the pool does not include the entire US adult population.

The Internet

Internet Explorer Gravestone Goes Viral in South Korea (reuters.com) 36

An anonymous reader shares a report: For Jung Ki-young, a South Korean software engineer, Microsoft's decision to retire its Internet Explorer web browser marked the end of a quarter-century love-hate relationship with the technology. To commemorate its demise, he spent a month and 430,000 won ($330) designing and ordering a headstone with Explorer's "e" logo and the English epitaph: "He was a good tool to download other browsers." After the memorial went on show at a cafe run by his brother in the southern city of Gyeongju, a photo of the tombstone went viral.
United States

The US Needs a Common Charger, Dems Say (theverge.com) 271

A group of Senate Democrats is calling on the US Commerce Department to follow Europe's lead in forcing all smartphone manufacturers to build devices that adhere to a universal charging standard. From a report: In a Thursday letter addressed to Commerce Secretary Gina Raimondo, Sen. Ed Markey (D-MA) -- along with Sens. Elizabeth Warren (D-MA) and Bernie Sanders (I-VT) -- demanded that the department develop a strategy to require a common charging port across all mobile devices. The letter comes a week after European Union lawmakers reached a deal on new legislation forcing all smartphones and tablets to be equipped with USB-C ports by fall 2024. "The EU has wisely acted in the public interest by taking on powerful technology companies over this consumer and environmental issue," the senators wrote. "The United States should do the same."
Hardware

TSMC Reveals 2nm Node: 30% More Performance by 2025 (tomshardware.com) 56

Taiwan Semiconductor Manufacturing Co. today officially introduced its N2 (2nm class) manufacturing technology, its first node that will use gate-all-around field-effect transistors (GAAFETs), at its 2022 TSMC Technology Symposium. From a report: The new fabrication process will offer a full-now performance and power benefits, but when it comes to transistor density, it will barely impress in 2025 when it comes online. Being an all-new process technology platform, TSMC's N2 brings in two essential innovations: nanosheet transistors (which is what TSMC calls its GAAFETs) and backside power rail that both serve the same goal of increasing performance-per-watt characteristics of the node. GAA nanosheet transistors feature channels surrounded by gates on all four sides, which reduces leakage; furthermore, their channels can be widened to increase drive current and boost performance or shrunken to minimize power consumption and cost. To feed these nanosheet transistors with enough power and now waste any of it, TSMC's N2 uses backside power delivery, which the foundry considers to be among the best solutions to fight resistances in the back-end-of-line (BEOL).

Indeed, when it comes to performance and power consumption, TSMC's nanosheet-based N2 node can boast of a 10% to 15% higher performance at the same power and complexity as well as a 25% to 30% lower power consumption at the same frequency and transistor count when compared to TSMC's N3E. However, the new node increases chip density by only around 1.1X compared to N3E. In general, TSMC's N3 does offer full-node performance increases and power consumption reductions. But density-wise, the new technology can hardly impress. For example, TSMC's N3E node offers a 1.3X chip density increase over N5, which is a substantial increase.

Google

How a Religious Sect Landed Google in a Lawsuit (nytimes.com) 111

A video producer claims he was fired after he complained that an obscure group based in the Sierra foothills dominated a business unit at Google. From a report: In a tiny town in the foothills of the Sierra Nevada, a religious organization called the Fellowship of Friends has established an elaborate, 1,200-acre compound full of art and ornate architecture. More than 200 miles away from the Fellowship's base in Oregon House, Calif., the religious sect, which believes a higher consciousness can be achieved by embracing fine arts and culture, has also gained a foothold inside a business unit at Google. Even in Google's freewheeling office culture, which encourages employees to speak their own minds and pursue their own projects, the Fellowship's presence in the business unit was unusual. As many as 12 Fellowship members and close relatives worked for the Google Developer Studio, or GDS, which produces videos showcasing the company's technologies, according to a lawsuit filed by Kevin Lloyd, a 34-year-old former Google video producer.

Many others staffed company events, working registration desks, taking photographs, playing music, providing massages and serving wine. For these events, Google regularly bought wine from an Oregon House winery owned by a member of the Fellowship, according to the lawsuit. Mr. Lloyd claimed he was fired last year because he complained about the influence of the religious sect. His suit also names Advanced Systems Group, or ASG, the company that sent Mr. Lloyd to Google as a contractor. Most of the Google Developer Studio joined the team through ASG as contractors, including many members of the Fellowship. The suit, which Mr. Lloyd filed in August in California Superior Court, accuses Google and ASG of violating a California employment law that protects workers against discrimination. It is in the discovery stage. The New York Times corroborated many of the lawsuit's claims through interviews with eight current and former employees of the Google business unit and examinations of publicly available information and other documents. These included a membership roster for the Fellowship of Friends, Google spreadsheets detailing event budgets and photos taken at these events.

Software

The Collapse of Complex Software 317

Nolan Lawson, writing in a blogpost: Anyone who's worked in the tech industry for long enough, especially at larger organizations, has seen it before. A legacy system exists: it's big, it's complex, and no one fully understands how it works. Architects are brought in to "fix" the system. They might wheel out a big whiteboard showing a lot of boxes and arrows pointing at other boxes, and inevitably, their solution is... to add more boxes and arrows. Nobody can subtract from the system; everyone just adds. This might go on for several years. At some point, though, an organizational shakeup probably occurs -- a merger, a reorg, the polite release of some senior executive to go focus on their painting hobby for a while. A new band of architects is brought in, and their solution to the "big diagram of boxes and arrows" problem is much simpler: draw a big red X through the whole thing. The old system is sunset or deprecated, the haggard veterans who worked on it either leave or are reshuffled to other projects, and a fresh-faced team is brought in to, blessedly, design a new system from scratch.

As disappointing as it may be for those of us who might aspire to write the kind of software that is timeless and enduring, you have to admit that this system works. For all its wastefulness, inefficiency, and pure mendacity ("The old code works fine!" "No wait, the old code is terrible!"), this is the model that has sustained a lot of software companies over the past few decades. Will this cycle go on forever, though? I'm not so sure. Right now, the software industry has been in a nearly two-decade economic boom (with some fits and starts), but the one sure thing in economics is that booms eventually turn to busts. During the boom, software companies can keep hiring new headcount to manage their existing software (i.e. more engineers to understand more boxes and arrows), but if their labor force is forced to contract, then that same system may become unmaintainable. A rapid and permanent reduction in complexity may be the only long-term solution.

One thing working in complexity's favor, though, is that engineers like complexity. Admit it: as much as we complain about other people's complexity, we love our own. We love sitting around and dreaming up new architectural diagrams that can comfortably sit inside our own heads -- it's only when these diagrams leave our heads, take shape in the real world, and outgrow the size of any one person's head that the problems begin. It takes a lot of discipline to resist complexity, to say "no" to new boxes and arrows. To say, "No, we won't solve that problem, because that will just introduce 10 new problems that we haven't imagined yet." Or to say, "Let's go with a much simpler design, even if it seems amateurish, because at least we can understand it." Or to just say, "Let's do less instead of more."
United States

Why Rural Americans Keep Waiting for Fast Internet, Despite Billions Spent (wsj.com) 169

The U.S. government has spent billions of dollars on several rounds of programs to upgrade internet speeds in rural areas over the past decade. Despite those efforts, many residents are still stuck with service that isn't fast enough to do video calls or stream movies -- speeds that most take for granted. From a report: Many communities have been targeted for broadband upgrades at least twice already, but flaws in the programs' design have left residents wanting. The Wall Street Journal analyzed 1.4 million largely rural census blocks that were included in a series of nationwide Federal Communications Commission broadband programs over the past decade. In the latest program, the Rural Digital Opportunity Fund, rolled out in 2020, internet service providers won rights to public funding in about 750,000 census blocks, covering every state except Alaska. The Journal's analysis found that more than half of those census blocks -- areas with a combined population of 5.3 million people -- had been fully or partially covered by at least one previous federal broadband program.

Most U.S. households today have access to internet download speeds of at least 100 megabits per second and upload speeds of 10 Mbps, according to government data. Although the FCC's programs have made progress, some rural Americans still can't get 4 Mbps download and 1 Mbps upload speeds -- the level of service that was the federal standard in 2011. The broadband saga around Heavener, Okla., illustrates some of the problems. Heavener, with a population of around 3,000, is surrounded by cattle pastures and forested hills. Today some buildings on the main streets have good broadband service, but the internet deteriorates outside town, residents say. Much of the area, in Le Flore County, was slated for upgrades under the Rural Digital Opportunity Fund in 2020 -- and some of those areas had already been part of prior programs.

Communications

Europe Cracks Down on Data Cap Exemptions in Update To Net Neutrality Rules (arstechnica.com) 32

European telecom regulator BEREC has updated its net neutrality guidelines to include a strict ban on zero-rating practices that exempt specific apps or categories of apps from data caps imposed by Internet service providers. From a report: The document published Tuesday provides guidance to national regulatory authorities on their "obligations to closely monitor and ensure compliance with the rules to safeguard equal and non-discriminatory treatment of traffic in the provision of Internet access services and related end-users' rights." BEREC stands for Body of European Regulators for Electronic Communications.

"Despite intense lobbying from big carriers and giant platforms, BEREC voted to clearly ban zero-rating offers that benefit select apps or categories of apps by exempting them from people's monthly data caps," Stanford Law Professor Barbara van Schewick wrote. "The ban applies whether the app pays to be included or not, closing a loophole in the draft guidelines." While Europe strengthens its net neutrality regime, the US hasn't had any federal net neutrality rules since they were removed under former Federal Communications Commission Chairman Ajit Pai. The FCC won't be re-imposing net neutrality rules any time soon because it still has a 2-2 partisan deadlock, and President Biden's nomination of Gigi Sohn has languished in the Senate.

Bitcoin

Finblox Imposes $1.5K Monthly Withdrawal Limit Amid Three Arrows Capital Uncertainty (coindesk.com) 62

Crypto staking and yield generation platform Finblox has imposed a $1,500 monthly withdrawal limit and paused rewards in light of uncertainty surrounding crypto hedge fund Three Arrows Capital, which made a $3.6 million investment in the Hong Kong-based platform last December. From a report: According to a statement shared on Twitter, Finblox has made the changes as it evaluates the impact of Three Arrow Capital's reported issues. It was reported on Wednesday that Three Arrows Capital is facing possible insolvency after incurring at least $400 million in liquidations.
Businesses

Google Privacy Lawsuit Over Ad Bidding Process To Go Forward (reuters.com) 3

Google has failed to convince a California federal judge to dismiss a privacy lawsuit that alleges the Alphabet Inc unit sells or gives personal information to third parties through its digital advertising system, without informing users. From a report: In a Monday opinion, U.S. District Judge Yvonne Gonzalez Rogers in Oakland said Google account holders have sufficiently alleged most of their claims in the lawsuit over the company's "real-time bidding" process. A Google spokesperson said in a statement Tuesday that privacy and transparency are "core" to its ad services. "We never sell people's personal information, we have strict policies specifically prohibiting personalized ads based on sensitive categories of information, and sensitive user data like health, race, or religion is not shared with our partners," the spokesperson said.
Facebook

Facebook Is Receiving Sensitive Medical Information from Hospital Websites (themarkup.org) 92

A tracking tool installed on many hospitals' websites has been collecting patients' sensitive health information -- including details about their medical conditions, prescriptions, and doctor's appointments -- and sending it to Facebook. From a report: The Markup tested the websites of Newsweek's top 100 hospitals in America. On 33 of them we found the tracker, called the Meta Pixel, sending Facebook a packet of data whenever a person clicked a button to schedule a doctor's appointment. The data is connected to an IP address -- an identifier that's like a computer's mailing address and can generally be linked to a specific individual or household -- "creating an intimate receipt of the appointment request for Facebook. The Markup found 33 of Newsweek's top 100 hospitals in the country sending sensitive data to Facebook via the pixel. Data accurate as of June 15, 2022. On the website of University Hospitals Cleveland Medical Center, for example, clicking the "Schedule Online" button on a doctor's page prompted the Meta Pixel to send Facebook the text of the button, the doctor's name, and the search term we used to find her: "pregnancy termination." Clicking the "Schedule Online Now" button for a doctor on the website of Froedtert Hospital, in Wisconsin, prompted the Meta Pixel to send Facebook the text of the button, the doctor's name, and the condition we selected from a dropdown menu: "Alzheimer's."
Ubuntu

Ubuntu Core 22 Brings Real-Time Linux Options To IoT (venturebeat.com) 22

An anonymous reader shares a report: Embedded and internet of things (IoT) devices are a growing category of computing, and with that growth has come expanded needs for security and manageability. One way to help secure embedded and IoT deployments is with a secured operating system, such as Canonical's Ubuntu Core. The Ubuntu Core provides an optimized version of the open-source Ubuntu Linux operating system for smaller device footprints, using an approach that puts applications into containers. On June 15, Ubuntu Core 22 became generally available, providing users with new capabilities to help accelerate performance and lock down security.

Ubuntu Core 22 is based on the Ubuntu 22.04 Linux operating system, which is Canonical's flagship Linux distribution that's made available for cloud, server and desktop users. Rather than being a general purpose OS, Ubuntu Core makes use of the open-source Snap container technology that was originally developed by Canonical to run applications. With Snaps, an organization can configure which applications should run in a specific IoT or embedded device and lock down the applications for security. Snaps provide a cryptographically authenticated approach for application updates.

Slashdot Top Deals