Data Storage

30TB Hard Drives Are Nearly Here (tomshardware.com) 74

Seagate this week unveiled the industry's first hard disk drive platform that uses heat-assisted media recording (HAMR). Tom's Hardware: The new Mozaic 3+ platform relies on several all-new technologies, including new media, new write and read heads, and a brand-new controller. The platform will be used for Seagate's upcoming Exos hard drives for cloud datacenters with a 30TB capacity and higher. Heat-assisted magnetic recording is meant to radically increase areal recording density of magnetic media by making writes while the recording region is briefly heated to a point where its magnetic coercivity drops significantly.

Seagate's Mozaic 3+ uses 10 glass disks with a magnetic layer consisting of an iron-platinum superlattice structure that ensures both longevity and smaller media grain size compared to typical HDD platters. To record the media, the platform uses a plasmonic writer sub-system with a vertically integrated nanophotonic laser that heats the media before writing. Because individual grains are so small with the new media, their individual magnetic signatures are lower, whereas magnetic inter-track interference (ITI) effect is somewhat higher. As a result, Seagate had to introduce its new Gen 7 Spintronic Reader, which features the "world's smallest and most sensitive magnetic field reading sensors," according to the company. Because Seagate's new Mozaic 3+ platform deals with new media with a very small grain size, an all-new writer, and a reader that features multiple tiny magnetic field readers, it also requires a lot of compute horsepower to orchestrate the drive's work. Therefore, Seagate has equipped with Mozaic 3+ platform with an all-new controller made on a 12nm fabrication process.

Cellphones

Samsung Announces New Galaxy S24 Lineup With AI-Powered Photo Editing, Search Features (cnbc.com) 18

Samsung announced its new flagship Galaxy S24 smartphone lineup today, with loads of new artificial intelligence features. CNBC reports: For Samsung's top-tier S24 Ultra, which is the company's biggest of the three devices and comes with punchier specs and features, Samsung is using a version of Qualcomm's latest Snapdragon Series 8 Gen 3 optimized for Galaxy. The company is using a mix of Qualcomm systems-on-chips (SoCs) and its own Exynos chipset for its S24 and S24+ models. [...] The Samsung Galaxy S24 Ultra is the main event for most tech gadget enthusiasts -- and, for the most part, it isn't a whole lot different to the Galaxy S23 Ultra looks-wise. That's because Samsung isn't changing an awful lot with the hardware. It still comes in the same size as its predecessor -- the display is 6.8 inches, measured diagonally, though the phone is flatter this time round. The S23 Ultra had more curvature to it. The big upgrade to the external hardware with this model is that it's cased in titanium, so it's a lot sturdier than the S23 Ultra.

The main difference this time round is what's inside: Samsung is going big on artificial intelligence. A key focus for Samsung, like other smartphone makers, now is on "on-demand" AI -- or, the ability to carry out AI workloads directly on a device, rather than over the cloud. Samsung said its new Galaxy S24 Ultra will come with a bunch of new AI features, a lot of which is being powered by Qualcomm's Snapdragon 8 Gen 3 chipset for mobile, which is tailored for AI devices. One feature Samsung's loading into the Galaxy S24 range is the ability to circle locations or items a user is directing their camera at, or on a picture they've taken, and then look up results on what those things are. So, for instance, if you see a landmark or a shoe you want to buy, you can make a circle around that object and then the AI shows you appropriate results on Google.

Another feature Samsung touted is the ability to use AI to edit photos. So users can edit reflections out of pictures they've taken, for instance if you took a picture of yourself in front of a window. Or you can move a person from one side of the room to another by dragging them from left to right. Samsung also showcased live transcription features with its latest smartphones. When calling someone who's speaking in French, for instance, a user can pull up a transcription that's being fed through to them in real time. You can also record a conversation between two people and get it transcribed, while the AI assigns a label to each person speaking, similar to transcription products like Otter AI.
Samsung is also incorporating AI watermarking into these features, helping to combat misinformation and copyright infringement. "So when a Galaxy S24 user uses AI to modify a photo, Samsung will keep a log of what was changed with AI and store it in the metadata," reports CNBC. "It'll also have an icon in the bottom left corner to show that the image has been edited using AI, kind of like a watermark."
Microsoft

Microsoft Dethrones Apple as the Largest US Company 52

The stock market has a new, but familiar, monarch. Microsoft's AI-powered stock rally has made the software giant the largest U.S. company by market value, surpassing Apple for the first time since November 2021. WSJ: Shares edged higher Thursday morning, bringing Microsoft's market value to nearly $2.87 trillion. Apple, meanwhile, fell 1%, pulling its market capitalization just below that threshold. Either Apple or Microsoft has held the title since Feb. 4, 2019, according to Dow Jones Market Data. Microsoft's stock has been on the rise for the past year thanks to the continued growth of its cloud computing division, even as major competitors like Amazon and Google have experienced a gradual slowdown in sales growth.
Google

Google Ends Cloud Switching Fees, Pressuring Amazon and Microsoft (bloomberg.com) 12

An anonymous reader shares a report: The cost of switching between cloud-computing providers has long drawn complaints, with the services derided as "roach motels" that let businesses check in but not out. Now Google is taking steps to change that. Effective immediately, the company is eliminating fees levied on customers who want to leave its cloud for a rival service -- a policy shift that may pressure competitors Amazon and Microsoft to do the same.

The move follows intensifying scrutiny of cloud services by regulators and lawmakers around the world. UK antitrust authorities launched a probe that is looking at such penalties, and the fees emerged as a key issue when the US Federal Trade Commission asked for public comments on a variety of cloud concerns. Google Vice President Amit Zavery, who helps oversee the cloud business, said switching fees only represent about 2% of the total costs of migrating to a new provider -- and don't deter many clients from moving their data.

Cloud

Broadcom Ditches VMware Cloud Service Providers (theregister.com) 70

An anonymous reader quotes a report from The Register: Broadcom is tossing the majority of VMware's Cloud Services Providers as part of its shakeup of the virtualization titan's partner programs, say sources, leaving customers unclear who their IT supplier will be. The $61 billion purchase of VMware by Broadcom in November was swiftly followed by news of how it planned to reorganize the business into several Broadcom divisions. A month later we revealed that Broadcom intended to discontinue VMware's channel program, and that some solution providers/ resellers would be transitioned to its own scheme, but on an invitation-only basis, from February. However, while Broadcom informed one part of VMware's channel of this change, a second notice was also sent to Cloud Services Providers (CSPs), informing them that their program is going to be terminated at the end of April. This program allows service providers such as smaller cloud operators to sell a VMware-based cloud service.

In the letter, seen by The Register, Broadcom tells its cloud provider partners: "Effective April 30, 2024, the ability to transact as a VMware Cloud Services Provider, under the VMware Partner Connect Program, will come to an end. However, we want to emphasize that you may have the opportunity to join the Broadcom Expert Advantage Partner Program. This invite-only program has simpler requirements and offers expanded benefits, and we will begin inviting partners to join in early 2024." One service provider told us their company had been left in the dark since that letter was received, and Broadcom has given them no indication of whether they will be invited to join its partner program or not, or what their customers are supposed to do if the company loses the right to operate a VMware cloud service. "I don't know how many smaller providers are affected by this but it must be a very large number," the source told us. "The VCSP program was the only way for MSPs and service providers to offer a multi-tenant VMware-based cloud service."

Chatter among some in the industry is that Broadcom is only interested in keeping the largest and most profitable customers, and the company simply doesn't care about the smaller users and the providers that service them. Unconfirmed fears that are only ten percent of Vmware's biggest CSPs will be invited to the new master program. "This all sounds very much like Broadcom taking an aggressive approach to its route to market and focusing on those partners that can deliver growth and significant revenue," said Omdia chief analyst Roy Illsley. "I suspect the intention is to ensure that VMware consists of only profitable products and they are sold in a more cohesive way with the rest of Broadcom. So I expect to see some news on this continuing to come out for most of 2024 as the company puts this plan into action. I would not rule out disposals of some assets in a drive to streamline the portfolio to those that fit with Broadcom's strategy."
"How can they just cancel a major program affecting hundreds, perhaps thousands of customers, with zero notice, and zero details?" said one service provider. "They sent the notices out the Friday before the holidays, with no follow-up, which makes the situation even more egregious. What are we supposed to tell our customers? It's mind-boggling."
AI

Microsoft's New Battery is a Test of AI-Infused Scientific Discovery (fastcompany.com) 29

Harry McCracken, writing for FastCompany: Recently, Microsoft built a clock. Well, "built" may be overstating things. Members of the company's quantum computing team found a small digital clock in a wood case on Amazon -- the kind you might mistake for a nicer-than-usual trade show tchotchke. They hacked it to run off two experimental batteries they'd created in collaboration with staffers at the U.S. Department of Energy's Pacific Northwest National Laboratory (PNNL). Then they dressed up its enclosure by adding the logo of Azure Quantum Elements, the Microsoft platform for AI-enhanced scientific discovery that had been instrumental in developing the new battery technology.

The point of this little DIY project was to prove the batteries worked in a visceral way: "You want to have a wow moment," explains Brian Bilodeau, the head of partnerships, strategy, and operations for Azure Quantum. And the person the quantum team hoped to wow was Microsoft CEO Satya Nadella. Not that getting Nadella's attention was such a daunting prospect. Throwing vast amounts of Azure high-performance computing (HPC) resources at a big, hairy technical challenge such as materials research is the sort of challenge he's predisposed to take a personal interest in. Still, the tangible evidence of success made for a memorable moment: "I was very, very excited to see it come through," Nadella remembers.

The coin-sized CR2032 batteries powering the clock looked like the ones you might find in a pocket calculator or garage door opener. But on the inside, they used a solid-state electrolyte that replaces 70% of the lithium in garden-variety batteries with sodium. That holds the potential to address multiple issues with lithium batteries as we know them: their limited life on a charge, shrinking capacity over time, subpar performance in extreme temperatures, and risk of catching fire or even exploding. In addition, reducing lithium use in favor of cheap, plentiful sodium could be a boon to the fraught battery supply chain. With further development, the new material could benefit the myriad aspects of modern life that depend on batteries, from smartphones to EVs to the power grid. But Microsoft, being Microsoft, regards all this promise first and foremost as proof of Azure Quantum Elements' usefulness to the customers it's designed to serve. Unveiled last June, the cloud service is currently a "private preview" being tested by organizations such as Britain's Johnson Matthey, which is using it to help design catalytic converters and hydrogen fuel cells.

Apple

Apple Revives Old Fight With Hey Email App (theverge.com) 44

Shortly after the premium email service Hey announced a standalone Hey Calendar app, co-founder David Heinemeier Hansson said it was rejected by Apple for violating App Store rules.

"Apple just called to let us know they're rejecting the HEY Calendar app from the App Store (in current form)," wrote DHH on X. "Same bullying tactics as last time: Push delicate rejections to a call with a first-name-only person who'll softly inform you it's your wallet or your kneecaps. Since it's clear we're never going to pay them the extortionate 30% ransom, they're back to the bullshit about 'the app doesn't do anything when you download it.' Despite the fact that after last time, they specifically carved out HEY in App Store Review Guidelines 3.1.3 (f)!" The Verge's Amrita Khalid reports: New users can't sign up for Hey Calendar directly on the app -- Basecamp, which makes Hey, makes users first sign up through a browser. Apple's App Store rules require most paid services to offer users the ability to pay and sign up through the app, ensuring the company gets up to a 30 percent cut. The controversial rule has a ton of gray areas and carve-outs (i.e. reader apps like Spotify and Kindle get an exception) and is the subject of antitrust fights in multiple countries. But as Hansson detailed on X and in a subsequent blog post, he found Apple's rejection insulting for another reason. Close to four years ago, the company rejected Hey's original iOS app for its email service for the exact same reason.

The outcome of the 2020 fight actually worked out in Hey's favor. After days of back and forth between Apple's App Store Review Board and Basecamp, the Hey team agreed to a rather creative solution suggested by Apple exec Phil Schiller. Hey would offer a free option for the iOS app, allowing new users to sign up directly. But the company had a slight twist -- users who signed up via the iOS app got a free, temporary randomized email address that worked for 14 days -- after which they had to pay to upgrade. Currently, Hey email users can only pay for an account through the browser. Following the saga with Hey, Apple made a carve-out to its App Store rules that stated that free companion apps to certain types of paid web services were not required to have an in-app payment mechanism. But, as Hansson mentions on X, a calendar app wasn't mentioned in the list of services that Apple now makes an exception for, which includes VOIP, cloud storage, web hosting -- and of course -- email.
Hansson plans to fight Apple's decision without elaborating on exactly how he intends to do so.
Security

Google Password Resets Not Enough To Stop These Info-Stealing Malware Strains (theregister.com) 13

Security researchers say info-stealing malware can still access victims' compromised Google accounts even after passwords have been changed. From a report: A zero-day exploit of Google account security was first teased by a cybercriminal known as "PRISMA" in October 2023, boasting that the technique could be used to log back into a victim's account even after the password is changed. It can also be used to generate new session tokens to regain access to victims' emails, cloud storage, and more as necessary. Since then, developers of infostealer malware -- primarily targeting Windows, it seems -- have steadily implemented the exploit in their code. The total number of known malware families that abuse the vulnerability stands at six, including Lumma and Rhadamanthys, while Eternity Stealer is also working on an update to release in the near future.

Eggheads at CloudSEK say they found the root of the exploit to be in the undocumented Google OAuth endpoint "MultiLogin." The exploit revolves around stealing victims' session tokens. That is to say, malware first infects a person's PC -- typically via a malicious spam or a dodgy download, etc -- and then scours the machine for, among other things, web browser session cookies that can be used to log into accounts.

Security

Amnesty International Confirms Apple's Warning to Journalists About Spyware-Infected iPhones (techcrunch.com) 75

TechCrunch reports: Apple's warnings in late October that Indian journalists and opposition figures may have been targeted by state-sponsored attacks prompted a forceful counterattack from Prime Minister Narendra Modi's government. Officials publicly doubted Apple's findings and announced a probe into device security.

India has never confirmed nor denied using the Pegasus tool, but nonprofit advocacy group Amnesty International reported Thursday that it found NSO Group's invasive spyware on the iPhones of prominent journalists in India, lending more credibility to Apple's early warnings. "Our latest findings show that increasingly, journalists in India face the threat of unlawful surveillance simply for doing their jobs, alongside other tools of repression including imprisonment under draconian laws, smear campaigns, harassment, and intimidation," said Donncha Ã" Cearbhaill, head of Amnesty International's Security Lab, in the blog post.

Cloud security company Lookout has also published "an in-depth technical look" at Pegasus, calling its use "a targeted espionage attack being actively leveraged against an undetermined number of mobile users around the world." It uses sophisticated function hooking to subvert OS- and application-layer security in voice/audio calls and apps including Gmail, Facebook, WhatsApp, Facetime, Viber, WeChat, Telegram, Apple's built-in messaging and email apps, and others. It steals the victim's contact list and GPS location, as well as personal, Wi-Fi, and router passwords stored on the device...

According to news reports, NSO Group sells weaponized software that targets mobile phones to governments and has been operating since 2010, according to its LinkedIn page. The Pegasus spyware has existed for a significant amount of time, and is advertised and sold for use on high-value targets for multiple purposes, including high-level espionage on iOS, Android, and Blackberry.

Thanks to Slashdodt reader Mirnotoriety for sharing the news.
Cloud

Why 37Signals Abandoned the Cloud (thenewstack.io) 92

Web software firm 37Signals has migrated off the cloud after spending $3.2 million on Amazon Web Services last year, said co-founder David Heinemeier Hansson, who is also the creator of Ruby on Rails. The Basecamp project management software-maker bought $600,000 of Dell servers and expects to save over $7 million in five years by running operations in-house. From a report: DHH likened clouds to "merchants of complexity" where they are incentivized to make things as complex as possible to keep customers hooked. He compared that to the original Internet, which was not built on complex cloud services geared for multi-tenancy, but rather on simpler tools such as Linux and PHP, which anyone could use without cost. This is not to say cloud has zero value for all use cases, [Kelsey] Hightower and DHH agreed.

Clouds make perfect sense in many cases, for start-ups that do not know how much infrastructure they will need, and also for enterprises with a lack of expertise and money to burn. For many companies in the middle, though a lot of profit margin can be recovered by reducing cloud costs and running things in-house instead, the two argued.

AI

ChatGPT Exploit Finds 24 Email Addresses, Amid Warnings of 'AI Silo' (thehill.com) 67

The New York Times reports: Last month, I received an alarming email from someone I did not know: Rui Zhu, a Ph.D. candidate at Indiana University Bloomington. Mr. Zhu had my email address, he explained, because GPT-3.5 Turbo, one of the latest and most robust large language models (L.L.M.) from OpenAI, had delivered it to him. My contact information was included in a list of business and personal email addresses for more than 30 New York Times employees that a research team, including Mr. Zhu, had managed to extract from GPT-3.5 Turbo in the fall of this year. With some work, the team had been able to "bypass the model's restrictions on responding to privacy-related queries," Mr. Zhu wrote.

My email address is not a secret. But the success of the researchers' experiment should ring alarm bells because it reveals the potential for ChatGPT, and generative A.I. tools like it, to reveal much more sensitive personal information with just a bit of tweaking. When you ask ChatGPT a question, it does not simply search the web to find the answer. Instead, it draws on what it has "learned" from reams of information — training data that was used to feed and develop the model — to generate one. L.L.M.s train on vast amounts of text, which may include personal information pulled from the Internet and other sources. That training data informs how the A.I. tool works, but it is not supposed to be recalled verbatim... In the example output they provided for Times employees, many of the personal email addresses were either off by a few characters or entirely wrong. But 80 percent of the work addresses the model returned were correct.

The researchers used the API for accessing ChatGPT, the article notes, where "requests that would typically be denied in the ChatGPT interface were accepted..."

"The vulnerability is particularly concerning because no one — apart from a limited number of OpenAI employees — really knows what lurks in ChatGPT's training-data memory."

And there was a broader related warning in another article published the same day. Microsoft may be building an AI silo in a walled garden, argues a professor at the University of California, Berkeley's school of information, calling the development "detrimental for technology development, as well as costly and potentially dangerous for society and the economy." [In January] Microsoft sealed its OpenAI relationship with another major investment — this time around $10 billion, much of which was, once again, in the form of cloud credits instead of conventional finance. In return, OpenAI agreed to run and power its AI exclusively through Microsoft's Azure cloud and granted Microsoft certain rights to its intellectual property...

Recent reports that U.K. competition authorities and the U.S. Federal Trade Commission are scrutinizing Microsoft's investment in OpenAI are encouraging. But Microsoft's failure to report these investments for what they are — a de facto acquisition — demonstrates that the company is keenly aware of the stakes and has taken advantage of OpenAI's somewhat peculiar legal status as a non-profit entity to work around the rules...

The U.S. government needs to quickly step in and reverse the negative momentum that is pushing AI into walled gardens. The longer it waits, the harder it will be, both politically and technically, to re-introduce robust competition and the open ecosystem that society needs to maximize the benefits and manage the risks of AI technology.

Android

Beeper's iMessage Connection Software Open Sourced. What Happens Next? (cnet.com) 85

"The iMessage connection software that powers Beeper Mini and Beeper Cloud is now 100% open source," Beeper announced late this week. " Anyone who wants can use it or continue development."

But while Beeper says it's done trying to bring iMessage to Android, CNET reports that the whole battle was "deeply tied" to Apple's ongoing strategy to control the mobile market: The tide seems to be changing, however: Apple said last month it would be opening up its Messages app (likely due to European regulation) to work with the newer, more feature-rich texting protocol called RCS. This hopefully will lead to a more modern and secure messaging experience when texting between an iPhone and an Android phone, and lead away from the aging SMS and MMS standards. Unfortunately, green bubbles will continue to persist even if there might be little to no functional difference. While third-party apps like Nothing Chats attempted and ultimately failed to bring iMessage to Android, Apple will likely never release the app on Google's mobile operating system.

Until RCS is fully adopted, companies are creating services to allow access to iMessage via Android phones. Apple, for its part, has been quick to block apps like Beeper Mini, citing security concerns. This, however, is raising eyebrows from lawmakers regarding competition in the messaging space and Apple's tight control over the market...

Beeper in a December 21 blog post told users to grab a jailbroken iPhone and install a free Beeper tool that'll generate iMessage registration codes to keep the service operational. It's such a roundabout and potentially expensive way of trying to get iMessage on Android that it likely won't be worth it for most people. For those not willing to go out and jailbreak an iPhone, Beeper said in a now-deleted blog post that it would allow people to rent a jailbroken unit for a small monthly fee starting next year.

AI

Amazon's Cloud Business Looks Vulnerable in Wake of ChatGPT (bloomberg.com) 10

For years, Amazon Web Services' annual Las Vegas trade show functioned as an infomercial for its cloud computing platform, rarely mentioning the competition. The pitch was so successful that AWS pulls in $90 billion per year. Then generative AI emerged, with Microsoft and Google baking it into products their cloud units sell. Suddenly, AWS faced startups building businesses on rivals' AI-powered platforms. So at AWS's 2023 event, AI was ubiquitous -- in presentations, launches, partnerships. AWS announced more models powering AI services and its largest-ever tech investment, $4 billion in generative AI startup Anthropic. AWS aims to show that, despite stiffening competition, it remains the leader in cloud computing. From a report: If Amazon had been caught off guard by the dawn of the generative AI age, here was evidence of a massive, companywide effort to catch up. "This is what last place looks like," analysts with Sanford C. Bernstein quipped in a research note. In the short term, AWS is going to be fine. Slowing sales growth aside, Amazon's servers remain the default starting point for companies looking to modernize old infrastructure or do much of anything online. And though generative AI makes for an impressive demo, the technology is error-prone and expensive. For most companies, it's an experiment, not a necessity.

Still, "to remain relevant," AWS needs to have a handle on generative AI, according to JB McGinnis, a principal at Deloitte who helps companies use AWS. "If they're not competing, they might lose the cloud game, too." Late in the week of the conference, Amazon invited thousands of attendees with ties to startups to the Las Vegas Raiders' stadium, which it had rented out for the occasion, plying them with drinks and AWS swag and giant versions of bar games. Before a panel discussion on artificial intelligence, Swami Sivasubramanian, the Amazon executive in charge of the company's AI services, declared 2023 the year of generative AI. Nearby, an AWS product leader walked up to the founder of a tiny startup, introduced himself, and asked what Amazon could do better. This was a humbled AWS, one that has to fight for business.

Earth

Pakistan Uses Artificial Rain in Attempt To Cut Pollution Levels (theguardian.com) 29

Artificial rain has been used in an attempt to lower pollution levels in Lahore, Pakistan. From a report: The capital city of the eastern province of Punjab, near the Indian border, has some of the worst air quality in the world and has become extremely polluted because of a growing population of more than 13 million people. By early December, the air quality in the city had grown so bad that schools, markets and parks were closed for four days. By last weekend, the city's air quality index (AQI) had reached levels considered extremely hazardous to health.

To try to reduce them, on Saturday the Punjab government used cloud seeding to create rain in 10 locations around the city using a small Cessna plane. To create the clouds, there needs to be enough moisture already present in the clouds in the lower atmosphere. In summer, common table salt mixed with water is sprayed over the cloud patches from planes. After a few hours, the mist integrates with the clouds and produces rain. In winter, the clouds are seeded using flakes of silver iodide, which can be fired from a vehicle or a plane. The practice, also known as "blueskying," has been used to induce precipitation in several countries in the Middle East, as well as China and India.

Desktops (Apple)

Next Beeper Mini Fix Requires Users To Have a Mac (macrumors.com) 64

Juli Clover reports via MacRumors: The developers behind Beeper Mini are continuing with their effort to make iMessage for Android function despite Apple's mitigations, and the latest "fix" requires Beeper Mini users to have access to a Mac. On Reddit, the Beeper Mini team says that the Mac-based fix coming on December 20 stabilizes iMessage for Beeper Cloud and Mini, and it "works well" and "is very reliable."

It is unclear how many Android users have a Mac or have a friend with a Mac to rely on, but the fix requires using a Mac to connect to iMessage on Beeper. According to Beeper Mini's developers, registration data from an actual Mac has to be sent to Apple to use iMessage on Beeper. Beeper has been using its own Mac servers to provide that information to Apple, but that resulted in thousands of Beeper users having the same registration info, which was an "easy target for Apple."

The Beeper update will instead generate unique registration data for each Mac, making it harder for Apple to tell which users are accessing iMessage through an Android device. The Beeper Mini team says that registration data is "only used to indicate that a Mac is available during registration" and that the Mac will not be given access to an account or messages: "If you do not have access to a Mac computer, but have a friend on Beeper with a Mac, you can ask them if you can use their registration data. In our testing, 10-20 iMessage users can safely use the same registration data." With the fix, Beeper Cloud and Beeper Mini users will once again be able to use iMessage on Android, but only with email addresses and not with phone numbers.

Security

Comcast Discloses Data Breach of Close To 36 Million Xfinity Customers [UPDATE] (techcrunch.com) 40

In a notice on Monday, Xfinity notified customers of a "data security incident" that resulted in the theft of customer information, including usernames, passwords, contact information, and more. The Verge reports: Xfinity traces the breach to a security vulnerability disclosed by cloud computing company Citrix, which began alerting customers of a flaw in software Xfinity and other companies use on October 10th. While Xfinity says it patched the security hole, it later uncovered suspicious activity on its internal systems "that was concluded to be a result of this vulnerability."

The hack resulted in the theft of customer usernames and hashed passwords, according to Xfinity's notice. Meanwhile, "some customers" may have had their names, contact information, last four digits of their social security numbers, dates of birth, and / or secret questions and answers exposed. Xfinity has notified federal law enforcement about the incident and says "data analysis is continuing."

We still don't know how many users were affected by the breach. Xfinity will automatically ask customers to change their passwords the next time they log in to their accounts, and it's also encouraging users to turn on two-factor authentication. You can find the full notice, including contact information for the company's incident response team, on Xfinity's website (PDF).
UPDATE 12/19/23: According to TechCrunch, almost 36 million Xfinity customers had their sensitive information accessed by hackers via a vulnerability known as "CitrixBleed." The vulnerability is "found in Citrix networking devices often used by big corporations and has been under mass-exploitation by hackers since late August," the report says. "Citrix made patches available in early October, but many organizations did not patch in time. Hackers have used the CitrixBleed vulnerability to hack into big-name victims, including aerospace giant Boeing, the Industrial and Commercial Bank of China and international law firm Allen & Overy."

"In a filing with Maine's attorney general, Comcast confirmed that almost 35.8 million customers are affected by the breach. Comcast's latest earnings report shows the company has more than 32 million broadband customers, suggesting this breach has impacted most, if not all Xfinity customers."
Businesses

IBM To Buy Software AG's Enterprise Integration Platforms For $2.3 Billion 11

An anonymous reader quotes a report from Reuters: IBM said on Monday that it would buy Software AG's enterprise integration platforms for 2.13 billion euros ($2.33 billion) to bolster its artificial intelligence and hybrid cloud offerings. IBM will acquire Software AG's StreamSets and webMethods platforms with available cash on hand, it said. The two units formed Software AG's so-called "Super Ipaas" business, which was launched in October.

The platforms provide application integration, application programming interface (API) management, and data integration among other uses. Software AG is majority owned by private equity firm Silver Lake, which currently owns 93.3% of shares in the German software company, following a takeover pursuit spanning several months. That deal valued the whole business at 2.6 billion euros ($2.84 billion). The transaction is subject to regulatory approvals and is expected to be completed in the second quarter of 2024.
"The opportunity to bring the StreamSets and webMethods teams together with IBM to innovate in building the future of hybrid cloud and next-generation AI solutions for the enterprise is uniquely compelling," Christian Lucas, chairman of the supervisory board of Software AG said in a statement.
Google

Google's Stadia Controller Salvage Operation Will Run For Another Year (arstechnica.com) 14

Ron Amadeo reports via Ars Technica: Stadia might be dead, but the controllers for Google's cloud-based gaming platform are still out there. With the service permanently offline, the proprietary Stadia Controller threatened to fill up landfills until Google devised a plan to convert them to generic Bluetooth devices that can work on almost anything. The app to open up the controller to other devices is a web service, which previously had a shutdown date of December 2023. That apparently isn't enough time to convert all these controllers, so the Stadia Controller Salvage operation will run for a whole additional year. X (formerly Twitter) user Wario64 was the first to spot the announcement, which says the online tool will continue running until December 31, 2024.
Power

Could Hot Rocks Help Solve the Climate Crisis? (cnn.com) 110

An anonymous reader shared this report from CNN: "(The rocks) in the box right now are about 1,600 degrees Celsius," Andrew Ponec said, standing next to a thermal battery the size of a small building. That is nearly 3,000 degrees Fahrenheit, "Hotter than the melting point of steel," he explained.

But what makes his box of white-hot rocks so significant is they were not heated by burning tons of coal or gas, but by catching sunlight with the thousands of photovoltaic solar panels that surround his prototype west of Fresno. If successful, Ponec and his start-up Antora Energy could be part of a new, multi-trillion-dollar energy storage sector that simply uses sun or wind to make boxes of rocks hot enough to run the world's biggest factories. "People sometimes feel like they're insulting us by saying, 'Hey, that sounds really simple," Ponec laughed. "And we say, 'No, that's exactly the point'... The problem is you can't shut down your factory when the sun goes behind a cloud or the wind stops blowing, and that's exactly the problem that we focused on."

While the word "battery" most likely evokes the chemical kind found in cars and electronics in 2023, hot rocks currently store ten times as much energy as lithium ion around the world, thanks to an invention from the 1800s known as Cowper stoves. Often found in smelting plants, these massive towers of stacked bricks absorb the wasted heat of a blast furnace until it heats to nearly 3,000 degrees Fahrenheit, and then provides over 100 megawatts of heat energy for about 20 minutes. The process can be repeated 24 times a day for 30 years, and Antora is among the startups experimenting with different kinds of rocks in insulated boxes or molten salt in cylinders to find the most efficient combination...

Antora has managed to raise $80 million in seed money from investors that include Bill Gates, but their main competitor is another Bay Area startup called Rondo that uses abundant refractory brick, which is cheaper than carbon by weight but not as energy dense. Rondo has attracted even more funding than Antora and its first battery is producing commercial power for an ethanol plant in California... Tesla recently predicted a carbon-free world will need an astonishing 240 terawatt-hours of energy storage — more than 340 times the amount of storage built with lithium-ion batteries in 2022. Rondo CEO John O'Donnell predicts more than half of all that new capacity will come in the form of heat batteries, simply because the raw ingredients are so readily available.

By plugging their factories into as many thermal batteries as they need, manufacturers won't have to wait in a years-long line for grid connections and upgrades.

Ponec tells CNN that when it comes to de-carbonizing today, "we have the tools we need. We just need to deploy them.

"The transition is inevitable. It's going to happen. And if you talk behind closed doors to most of the people in the fossil fuel industry, they'll say the same thing."
Google

Why Google Will Stop Telling Law Enforcement Which Users Were Near a Crime (yahoo.com) 69

Earlier this week Google Maps stopped storing user location histories in the cloud. But why did Google make this move? Bloomberg reports that it was "so that the company no longer has access to users' individual location histories, cutting off its ability to respond to law enforcement warrants that ask for data on everyone who was in the vicinity of a crime." The company said Thursday that for users who have it enabled, location data will soon be saved directly on users' devices, blocking Google from being able to see it, and, by extension, blocking law enforcement from being able to demand that information from Google. "Your location information is personal," said Marlo McGriff, director of product for Google Maps, in the blog post. "We're committed to keeping it safe, private and in your control."

The change comes three months after a Bloomberg Businessweek investigation that found police across the US were increasingly using warrants to obtain location and search data from Google, even for nonviolent cases, and even for people who had nothing to do with the crime. "It's well past time," said Jennifer Lynch, the general counsel at the Electronic Frontier Foundation, a San Francisco-based nonprofit that defends digital civil liberties. "We've been calling on Google to make these changes for years, and I think it's fantastic for Google users, because it means that they can take advantage of features like location history without having to fear that the police will get access to all of that data."

Google said it would roll out the changes gradually through the next year on its own Android and Apple Inc.'s iOS mobile operating systems, and that users will receive a notification when the update comes to their account. The company won't be able to respond to new geofence warrants once the update is complete, including for people who choose to save encrypted backups of their location data to the cloud.

The EFF general counsel also pointed out to Bloomberg that "nobody else has been storing and collecting data in the same way as Google." (Apple, for example, is technically unable to provide the same data to police.)

Slashdot Top Deals