×
The Internet

Months After Its 20th Anniversary, OpenStreetMap Suffers an Extended Outage (openstreetmap.org) 1

Monday long-time Slashdot reader denelson83 wrote: The crowdsourced, widely-used map database OpenStreetMap has had a hardware failure at its upstream ISP in Amsterdam and has been put into a protective read-only mode to avoid loss or corruption of data. .
The outage had started Sunday December 15 at 4:00AM (GMT/UTC), but by Tuesday they'd posted a final update: Our new ISP is up and running and we have started migrating our servers across to it. If all goes smoothly we hope to have all services back up and running this evening...

We have dual redundant links via separate physical hardware from our side to our Tier 1 ISP. We unexpectedly discovered their equipment is a single point failure. Their extended outage is an extreme disappointment to us.

We are an extremely small team. The OSMF budget is tiny and we could definitely use more help. Real world experience... Ironically we signed a contract with a new ISP in the last few days. Install is on-going (fibre runs, modules & patching) and we expect to run old and new side-by-side for 6 months. Significantly better resilience (redundant ISP side equipment, VRRP both ways, multiple upstream peers... 2x diverse 10G fibre links).

OpenStreetMap celebrated its 20th anniversary in August, with a TechCrunch profile reminding readers the site gives developers "geographic data and maps so they can rely a little less on the proprietary incumbents in the space," reports TechCrunch, adding "Yes, that mostly means Google."

OpenStreetMap starts with "publicly available and donated aerial imagery and maps, sourced from governments and private organizations such as Microsoft" — then makes them better: Today, OpenStreetMap claims more than 10 million contributors who map out and fine-tune everything from streets and buildings, to rivers, canyons and everything else that constitutes our built and natural environments... Contributors can manually add and edit data through OpenStreetMap's editing tools, and they can even venture out into the wild and map a whole new area by themselves using GPS, which is useful if a new street crops up, for example...

OpenStreetMap's Open Database License allows any third-party to use its data with the appropriate attribution (though this attribution doesn't always happen). This includes big-name corporations such as Apple and VC-backed unicorns like MapBox, through a who's who of tech companies, including Uber and Strava... More recently, the Overture Maps Foundation — an initiative backed by Microsoft, Amazon, Meta and TomTom — has leaned heavily on OpenStreetMap data as part of its own efforts to build a viable alternative to Google's walled mapping garden.

The article notes that OpenStreetMap is now overseen by the U.K.-based nonprofit OpenStreetMap Foundation (supported mainly by donations and memberships), with just one employee — a system engineer — "and a handful of contractors who provide administrative and accounting support."

In August its original founder Steve Coast, returned to the site for a special blog post on its 20th anniversary: OpenStreetMap has grown exponentially or quadratically over the last twenty years depending on the metric you're interested in... The story isn't so much about the data and technology, and it never was. It's the people... OpenStreetMap managed to map the world and give the data away for free for almost no money at all. It managed to sidestep almost all the problems that Wikipedia has by virtue of only representing facts not opinions. The project itself is remarkable. And it's wonderful that so many are in love with it.
"Two decades ago, I knew that a wiki map of the world would work," Coast writes. "It seemed obvious in light of the success of Wikipedia and Linux..."
Earth

10 Years Later: Malaysia To Resume Hunt For Flight MH370 (reuters.com) 64

An anonymous reader quotes a report from Reuters: Malaysia has agreed to resume the search for the wreckage of missing Malaysia Airlines Flight MH370, its transport minister said on Friday, more than 10 years after it disappeared in one of the world's greatest aviation mysteries. Flight MH370, a Boeing 777 carrying 227 passengers and 12 crew, vanished en route from Kuala Lumpur to Beijing on March 8, 2014.

[...] MH370's last transmission was about 40 minutes after it took off from Kuala Lumpur for Beijing. The pilots signed off as the plane entered Vietnamese air space over the Gulf of Thailand and soon after its transponder was turned off.
"Our responsibility and obligation and commitment is to the next of kin," Transport Minister Anthony Loke told a press conference. "We hope this time will be positive, that the wreckage will be found and give closure to the families."

Further reading: Could Sea Explosions Finally Locate the 2014 Crash Site of Flight MH370?
Books

Cory Doctorow's Prescient Novella About Health Insurance and Murder (theguardian.com) 168

Five years ago, journalist and sci-fi author Cory Doctorow published a short story that explored the radicalization of individuals denied healthcare coverage. As The Guardian notes in a recent article, the story "might seem eerily similar" to the recent shooting of UnitedHealthcare's CEO. While it appears that the alleged shooter never read the story, Doctorow said: "I feel like the most important thing about that is that it tells you that this is not a unique insight." Doctorow continued: "that the question that I had is a question other people have had." As an activist in favor of liberalizing copyright laws and a proponent of the Creative Commons organization, it's important to note that Doctorow advocates for systemic reform through collective action rather than violence. Here's an excerpt from the The Guardian's article: In Radicalized, one of four novellas comprising a science fiction novel of the same name, Doctorow charts the journey of a man who joins an online forum for fathers whose partners or children have been denied healthcare coverage by their insurers after his wife is diagnosed with breast cancer and denied coverage for an experimental treatment. Slowly, over the course of the story, the men of the forum become radicalized by their grief and begin plotting -- and executing -- murders of health insurance executives and politicians who vote against universal healthcare.

In the wake of the December 4 shooting of UnitedHealthcare CEO Brian Thompson, which unleashed a wave of outrage at the U.S. health system, Doctorow's novella has been called prescient. When the American Prospect magazine republished the story last week, it wrote: "It is being republished with permission for reasons that will become clear if you read it." But Doctorow doesn't think he was on to something that no one else in the U.S. understood. [...]

In one part of the story, a man whose young daughter died after an insurance company refused to pay for brain surgery bombs the insurer's headquarters. "It's not vengeance. I don't have a vengeful bone in my body. Nothing I do will bring Lisa back, so why would I want revenge? This is a public service. There's another dad just like me," he shares in a video message on the forum. "And right now, that dad is talking to someone at Cigna, or Humana, or BlueCross BlueShield, and the person on the phone is telling that dad that his little girl has. To. Die. Someone in that building made the decision to kill my little girl, and everyone else in that building went along with it. Not one of them is innocent, and not one of them is afraid. They're going to be afraid, after this."

"Because they must know in their hearts," he goes on. "Them, their lobbyists, the men in Congress who enabled them. They're parents. They know. Anyone who hurt their precious children, they'd hunt that person down like a dog. The only amazing thing about any of this is that no one has done it yet. I'm going to make a prediction right now, that even though I'm the first, I sure as hell will not be the last. There's more to come."

AI

'Yes, I am a Human': Bot Detection Is No Longer Working 89

The rise of AI has rendered traditional CAPTCHA tests increasingly ineffective, as bots can now "[solve] these puzzles in milliseconds using artificial intelligence (AI)," reports The Conversation. "How ironic. The tools designed to prove we're human are now obstructing us more than the machines they're supposed to be keeping at bay." The report warns that the imminent arrival of AI agents -- software programs designed to autonomously interact with websites on our behalf -- will further complicate matters. From the report: Developers are continually coming up with new ways to verify humans. Some systems, like Google's ReCaptcha v3 (introduced in 2018), don't ask you to solve puzzles anymore. Instead, they watch how you interact with a website. Do you move your cursor naturally? Do you type like a person? Humans have subtle, imperfect behaviors that bots still struggle to mimic. Not everyone likes ReCaptcha v3 because it raises privacy issues -- plus the web company needs to assess user scores to determine who is a bot, and the bots can beat the system anyway. There are alternatives that use similar logic, such as "slider" puzzles that ask users to move jigsaw pieces around, but these too can be overcome.

Some websites are now turning to biometrics to verify humans, such as fingerprint scans or voice recognition, while face ID is also a possibility. Biometrics are harder for bots to fake, but they come with their own problems -- privacy concerns, expensive tech and limited access for some users, say because they can't afford the relevant smartphone or can't speak because of a disability. The imminent arrival of AI agents will add another layer of complexity. It will mean we increasingly want bots to visit sites and do things on our behalf, so web companies will need to start distinguishing between "good" bots and "bad" bots. This area still needs a lot more consideration, but digital authentication certificates are proposed as one possible solution.

In sum, Captcha is no longer the simple, reliable tool it once was. AI has forced us to rethink how we verify people online, and it's only going to get more challenging as these systems get smarter. Whatever becomes the next technological standard, it's going to have to be easy to use for humans, but one step ahead of the bad actors. So the next time you find yourself clicking on blurry traffic lights and getting infuriated, remember you're part of a bigger fight. The future of proving humanity is still being written, and the bots won't be giving up any time soon.
The Courts

Qualcomm Processors Properly Licensed From Arm, US Jury Finds (yahoo.com) 15

Jurors delivered a mixed verdict on Friday, ruling that Qualcomm had properly licensed its central processor chips from Arm. This decision effectively concludes Arm's lawsuit against Qualcomm, which had the potential to disrupt the global smartphone and PC chip markets.

The dispute stemmed from Qualcomm's $1.4 billion acquisition of chip startup Nuvia in 2021. Arm claimed Qualcomm breached contract terms by using Nuvia's designs without permission, while Qualcomm maintained its existing agreement covers the acquired technology. Arm demanded Qualcomm destroy the Nuvia designs created before the acquisition. Reuters reports: An eight-person jury in U.S. federal court deadlocked on the question of whether Nuvia, a startup that Qualcomm purchased for $1.4 billion in 2021, breached the terms of its license with Arm. But the jury found that Qualcomm did not breach Nuvia's license with Arm.

The jury also found that Qualcomm's chips created using Nuvia technology, which have been central to Qualcomm's push into the personal computer market, are properly licensed under its own agreement with Arm, clearing the way for Qualcomm to continue selling them.

Iphone

Apple Pulls Lightning-Equipped iPhones From Swiss Stores Ahead of EU USB-C Mandate (macrumors.com) 30

Apple has started pulling its iPhone SE and iPhone 14 models from sale in Switzerland, signaling broader discontinuation across the European Union ahead of new USB-C charging requirements taking effect December 28.

The devices, which use Apple's proprietary Lightning port, disappeared from Swiss online stores today. Switzerland, while not an EU member, follows EU market rules. Apple-authorized resellers can continue selling existing stock until depleted. A new USB-C compatible iPhone SE is expected in March.
AI

OpenAI Unveils o3, a Smarter AI Model With Improved Reasoning Skills (openai.com) 25

OpenAI has unveiled a new AI model that it says takes longer to solve problems but gets better results, following Google's similar announcement a day earlier. The model, called o3, replaces o1 from September and spends extra time working through questions that need step-by-step reasoning.

It scores three times higher than o1 on ARC-AGI, a test measuring how well AI handles complex math and logic problems it hasn't seen before. "This is the beginning of the next phase of AI," CEO Sam Altman said during a livestream Friday.

The Microsoft-backed startup is keeping o3 under wraps for now but plans to let outside researchers test it.
Power

US Data-Center Power Use Could Nearly Triple By 2028, DOE-Backed Report Says (reuters.com) 37

U.S. data center power demand could nearly triple in the next three years, and consume as much as 12% of the country's electricity, as the industry undergoes an AI transformation, according to an unpublished Department of Energy-backed report seen by Reuters. The publication adds: The Lawrence Berkeley National Laboratory report, which is expected to be released on Friday, comes as the U.S. power industry and government agencies attempt to understand how the sudden rise of Big Tech's data-center demand will affect electrical grids, power bills and the climate.

By 2028, data-center annual energy use could reach between 74 and 132 gigawatts, or between 6.7% and 12% of total U.S. electricity consumption, according to the Berkeley Lab report. The industry standard-setting report included ranges that depended partly on the availability and demand for a type of AI chip known as GPUs. Currently, data centers make up a little more than 4% of the country's power load. "This really signals to us where the frontier is in terms of growing energy demand in the U.S.," said Avi Shultz, director of the DOE's Industrial Efficiency and Decarbonization Office.

Google

Google Cuts Managers and VPs in Efficiency Drive (businessinsider.com) 42

Google has reduced its senior management positions by 10% as part of an ongoing efficiency initiative, CEO Sundar Pichai announced during a company-wide meeting earlier this week.

The restructuring affected managers, directors, and vice presidents, with some roles eliminated and others converted to non-management positions, a Google spokesperson told BusinessInsider. The move follows Google's January 2023 layoff of 12,000 employees and Pichai's September 2022 goal to improve company efficiency by 20%.
Transportation

Waymo's Driverless Cars Are Apparently an Insurance Company's Dream (engadget.com) 150

A study by reinsurer Swiss Re found that Waymo's autonomous vehicles have demonstrated significantly fewer property damage and bodily injury claims compared to human-driven cars, with reductions of up to 92% in some metrics. Engadget reports: Swiss Re analyzed liability claims from collisions covering 25.3 million miles driven by Waymo's autonomous cars. The study also compared Waymo's liability claims to human driver baselines based on data from over 500,000 claims and over 200 billion driving miles. The results found that Waymo Driver "demonstrated better safety performance when compared to human-driver vehicles." The study found cars operated by Alphabet's Waymo Driver resulted in 88 percent fewer property damage claims and 92 percent fewer bodily injury claims.

Swiss Re also invented a new metric to compare Waymo Driver against only newer vehicles with advanced safety tech, like driver assistance, automated emergency braking and blind spot warning systems, instead of against the whole corpus of those 200 billion driving miles. In this comparison, Waymo still came out ahead with an 86 percent reduction in property damage claims and a 90 percent reduction on bodily damage claims.

AI

Google Releases Its Own 'Reasoning' AI Model (techcrunch.com) 5

An anonymous reader quotes a report from TechCrunch: Google has released what it's calling a new "reasoning" AI model -- but it's in the experimental stages, and from our brief testing, there's certainly room for improvement. The new model, called Gemini 2.0 Flash Thinking Experimental (a mouthful, to be sure), is available in AI Studio, Google's AI prototyping platform. A model card describes it as "best for multimodal understanding, reasoning, and coding," with the ability to "reason over the most complex problems" in fields such as programming, math, and physics. [...]

Built on Google's recently announced Gemini 2.0 Flash model, Gemini 2.0 Flash Thinking Experimental appears to be similar in design to OpenAI's o1 and other so-called reasoning models. Unlike most AI, reasoning models effectively fact-check themselves, which helps them avoid some of the pitfalls that normally trip up AI models. As a drawback, reasoning models often take longer -- usually seconds to minutes longer -- to arrive at solutions. Given a prompt, Gemini 2.0 Flash Thinking Experimental pauses before responding, considering a number of related prompts and "explaining" its reasoning along the way. After a while, the model summarizes what it considers to be the most accurate answer.

Communications

Starlink's First Nationwide Satellite Texting Service Goes Live In New Zealand (engadget.com) 22

SpaceX has partnered with telecommunications company One NZ to offer satellite-to-cell Starlink texting service to customers in New Zealand. It marks the first time a nationwide satellite text messaging service has been powered by Starlink. Engadget reports: Now onto the caveats, and there are a couple of big ones. Starlink texting is incredibly slow when compared to traditional methods. One NZ says that most messages should be sent and received within three minutes during the initial rollout, but admits that timeframe could increase to "10 minutes or longer." It is for this reason that the company continues to urge folks to carry a personal locator beacon when traveling to a remote area.

The service is also only supported by four smartphone models, which includes the Samsung Galaxy Z Flip 6, Samsung Galaxy Z Fold 6, Samsung Galaxy S24 Ultra and OPPO Find X8 Pro. This list of eligible devices is expected to grow next year. The company also intends to eventually expand the service to include voice calling and data. The satellite service is free for existing One NZ customers on paid-monthly plans, but we don't know the pricing scheme for new customers or for those signed up for other types of contracts.
Starlink is working with T-Mobile to do something similar in the U.S. Last month, the FCC approved a license for T-Mobile and SpaceX's Starlink to provide supplemental telecommunications coverage from space.
Security

Hackers Can Jailbreak Digital License Plates To Make Others Pay Their Tolls, Tickets (wired.com) 72

Longtime Slashdot reader sinij shares a report from Wired with the caption: "This story will be an on-going payday for traffic ticket lawyers. I am ordering one now." From the report: Digital license plates, already legal to buy in a growing number of states and to drive with nationwide, offer a few perks over their sheet metal predecessors. You can change their display on the fly to frame your plate number with novelty messages, for instance, or to flag that your car has been stolen. Now one security researcher has shown how they can also be hacked to enable a less benign feature: changing a car's license plate number at will to avoid traffic tickets and tolls -- or even pin them on someone else.

Josep Rodriguez, a researcher at security firm IOActive, has revealed a technique to "jailbreak" digital license plates sold by Reviver, the leading vendor of those plates in the US with 65,000 plates already sold. By removing a sticker on the back of the plate and attaching a cable to its internal connectors, he's able to rewrite a Reviver plate's firmware in a matter of minutes. Then, with that custom firmware installed, the jailbroken license plate can receive commands via Bluetooth from a smartphone app to instantly change its display to show any characters or image. That susceptibility to jailbreaking, Rodriguez points out, could let drivers with the license plates evade any system that depends on license plate numbers for enforcement or surveillance, from tolls to speeding and parking tickets to automatic license plate readers that police use to track criminal suspects. "You can put whatever you want on the screen, which users are not supposed to be able to do," says Rodriguez. "Imagine you are going through a speed camera or if you are a criminal and you don't want to get caught."

Worse still, Rodriguez points out that a jailbroken license plate can be changed not just to an arbitrary number but also to the number of another vehicle -- whose driver would then receive the malicious user's tickets and toll bills. "If you can change the license plate number whenever you want, you can cause some real problems," Rodriguez says. All traffic-related mischief aside, Rodriguez also notes that jailbreaking the plates could also allow drivers to use the plates' features without paying Reviver's $29.99 monthly subscription fee. Because the vulnerability that allowed him to rewrite the plates' firmware exists at the hardware level -- in Reviver's chips themselves -- Rodriguez says there's no way for Reviver to patch the issue with a mere software update. Instead, it would have to replace those chips in each display. That means the company's license plates are very likely to remain vulnerable despite Rodriguez's warning -- a fact, Rodriguez says, that transport policymakers and law enforcement should be aware of as digital license plates roll out across the country. "It's a big problem because now you have thousands of licensed plates with this issue, and you would need to change the hardware to fix it," he says.

The Courts

Nebraska Sues UnitedHealth Unit Over 100 Million Patient Data Breach 16

Nebraska's attorney general has sued Change Healthcare over a massive data breach that exposed sensitive medical information of more than 100 million Americans following a February ransomware attack. The lawsuit alleges the UnitedHealth-owned company failed to implement basic security measures, including multi-factor authentication, allowing hackers to breach its systems using credentials from a customer support employee that were posted on Telegram.

The Russian-speaking ALPHV ransomware group accessed personal health records, financial data and treatment information across Change Healthcare's poorly segmented network, according to the complaint filed by Attorney General Mike Hilgers.
Encryption

Australia Moves To Drop Some Cryptography By 2030 (theregister.com) 31

An anonymous reader shares a report: Australia's chief cyber security agency has decided local orgs should stop using the tech that forms the current cryptographic foundation of the internet by the year 2030 -- years before other nations plan to do so -- over fears that advances in quantum computing could render it insecure.

The Land Down Under's plans emerged last week when the Australian Signals Directorate (ASD) published guidance for High Assurance Cryptographic Equipment (HACE) -- devices that send and/or receive sensitive information -- that calls for disallowing the cryptographic algorithms SHA-256, RSA, ECDSA and ECDH, among others, by the end of this decade.

Bill Buchanan, professor in the School of Computing at Edinburgh Napier University, wrote a blog post in which he expressed shock that the ASD aims to move so quickly. "Basically, these four methods are used for virtually every web connection that we create, and where ECDH is used for the key exchange, ECDSA or RSA is used to authenticate the remote server, and SHA-256 is used for the integrity of the data sent," he wrote. "The removal of SHA-256 definitely goes against current recommendations."

Slashdot Top Deals