Cloud

Google VP Calls Out Microsoft's Cloud Software Licensing 'Tax' (theregister.com) 42

Google is very publicly adding to the chorus of complaints about Microsoft's alleged restrictive cloud software licensing policies, claiming that unless the European Union formally tackles it, the industry and customers will suffer lasting damage. From a report: Amit Zavery, vice president, general manager, and head of platform at Google Cloud, says antitrust regulators are "starting to understand the situation" and are asking questions. "Any enterprise company will be impacted negatively if things are not resolved properly," he told The Register. "I think there should be appetite [from the regulators] and I think there should be movement in that area to really put some kind of checks and balances on Microsoft's policies." One bone of contention for Google, the third-largest public cloud provider globally and in Europe, is that it simply costs more to run Microsoft software on third-party providers' clouds. This is due to extra licensing costs levied by Microsoft when you run its applications on non-Microsoft clouds, we're told. "Microsoft publicly touts that if you run their software on Azure versus other vendors like AWS and GCP, it's five times cheaper or it's more expensive to run on us 5x basically because of the tax customers have to pay to Microsoft," Zavery told us.
Government

New Report Says American Government Agencies Are Using Malware Similar To Banned Pegasus Spyware (digitalinformationworld.com) 77

A new report has revealed that a government agency in the US, namely the Drug Enforcement Agency (DEA), is allegedly using a spyware called Paragon Graphite that shares similarities with the notorious Pegasus spyware. From a report: Pegasus was sold off to the government and other law firms. Moreover, we saw the firm making plenty of purchases through the likes of hackers. The software tends to give in to exploitation that can be achieved through zero clicks, all thanks to the great skill of hackers. Moreover, such software can produce its target without any interaction. [...] New reports by the Financial Times stated how the American Government makes use of this technology as it can pierce all sorts of protections linked to modern-day smart devices. Similarly, it can evade various forms of encryption for messaging applications such as WhatsApp and harvest data thanks to the likes of cloud backups. And yes, it's very similar to its counterpart Pegasus in this ordeal.

For now, the DEA is awfully hushed on the matter and not releasing any more comments on this situation. But it did reveal how its agency ended up purchasing Graphite to be used by agencies in Mexico so they could curb the drug cartel situation.
"According to four [industry figures], the US Drug Enforcement and Administration Agency is among the top customers for Paragon's signature product nicknamed Graphite," reports the Financial Times. "The malware surreptitiously pierces the protections of modern smartphones and evades the encryption of messaging apps like Signal or WhatsApp, sometimes harvesting the data from cloud backups -- much like Pegasus does."

The report adds: "Congressman Adam Schiff, the chair of the House Intelligence Committee, wrote to the DEA in December asking for more details on the purchase. Mexico is among the worst abusers of NO's Pegasus which it bought nearly a decade ago.

Schiff wrote: "such use [of spyware] could have potential implications for US national security, as well as run contrary to efforts to deter the broad proliferation of powerful surveillance capabilities to autocratic regimes and others who may misuse them."
The Internet

Brave Releases Its Search API (thurrott.com) 8

Brave has launched its Brave Search API, allowing third parties to integrate its privacy-preserving and ad-free search results into their applications through a simple API call. Thurrott reports: Brave notes that its Search API is inexpensive and that it's a great fit for Artificial Intelligence (AI) and Large Language Models developers in particular because it provides access to a collection of high-quality, Web-scale data including recent events. Brave claims that its standalone Brave Search offering now delivers over 8 billion annualized queries, which makes it the fastest-growing search engine since Microsoft Bing. And in sharp contrast to the market leaders, Brave Search is private and transparent. Plus, it's fueled by opt-in users of the Brave browser's Web Discovery Project, which adds millions of new web pages to the index every single day and keeps it current and fresh. The Brave web browser has over 60 million active users now, the company adds.

A free version of the Brave Search API provides one search query per second and up to 2,000 queries per month. Paid tiers start at $3 CPM (cost per one thousand) for 20 queries per second and up to 20 million queries per month, with access to web search, Goggles, news cluster, and videos cluster, plus added cost access to autosuggest and spellcheck at $5 per 10,000 requests. Higher-price tiers add more queries per second and per month, plus additional capabilities like schema-enriched web results, infobox, FAQ, discussions, locations, and more.

Cloud

Apple's Original Cloud Photo Sync Service Shuts Down This Summer (theverge.com) 17

My Photo Stream, the free cloud-based photo syncing feature Apple launched in 2011, is shutting down on July 26th, according to an Apple Support page spotted by Bloomberg's Mark Gurman. The Verge reports: The end of My Photo Stream won't come as too much of a surprise. Although it was free, it came with a long list of restrictions on the amount of photos you could upload, and these were only saved on Apple's servers for 30 days. Photos saved in the cloud then had to be manually saved locally if you wanted to keep them on a secondary device and, perhaps worst of all, 9to5Mac notes that high-quality photos weren't synced in their original resolution.

iCloud's free storage may be relatively limited at just 5GB, but at least it acts like a modern cloud storage service with photos and videos stored in their full resolution. Apple's support page notes that new photo uploads to My Photo Stream will come to an end on June 26th, and that the feature will disappear entirely a month later. "The photos in My Photo Stream are already stored on at least one of your devices," Apple's page notes, "So as long as you have the device with your originals, you won't lose any photos as part of this process."

Intel

Intel Says AI is Overwhelming CPUs, GPUs, Even Clouds, So All Meteor Lakes Get a VPU (theregister.com) 63

Intel will use the "VPU" tech it acquired along with Movidius in 2016 to all models of its forthcoming Meteor Lake client CPUs. From a report: Chipzilla already offers VPUs in some 13th-gen Core silicon. Ahead of the Computex conference in Taiwan, the company briefed The Register on their inclusion in Meteor Lake. Curiously, Intel didn't elucidate the acronym, but has previously said it stands for Vision Processing Unit. Chipzilla is, however, clear about what it does and why it's needed -- and it's more than vision. Intel Veep and general manager of Client AI John Rayfield said dedicated AI silicon is needed because AI is now present in many PC workloads. Video conferences, he said, feature lots of AI enhancing video and making participants sounds great -- and users now just expect that PCs do brilliantly when Zooming or WebExing or Teamising. Games use lots of AI. And GPT-like models, and tools like Stable Diffusion, are already popular on the PC and available as local executables.

CPUs and GPUs do the heavy lifting today, but Rayfield said they'll be overwhelmed by the demands of AI workloads. Shifting that work to the cloud is pricey, and also impractical because buyers want PCs to perform. Meteor Lake therefore gets VPUs and emerges as an SoC that uses Intel's Foveros packaging tech to combine the CPU, GPU, and VPU. The VPU gets to handle "sustained AI and AI offload." CPUs will still be asked to do simple inference jobs with low latency, usually when the cost of doing so is less than the overhead of working with a driver to shunt the workload elsewhere. GPUs will get to do jobs involving performance parallelism and throughput. Other AI-related work will be offloaded to VPUs.

Windows

Microsoft Announces Cloud-Powered OS Backup and Restore for Windows 11, Better ARM Support (windowscentral.com) 50

Microsoft's annual developer event Build 2023 unveiled ChatGPT's integration into Bing and an AI 'personal assistant' for Windows 11.

But Windows Central also notes two more big (non-AI) announcements: Windows 11 is getting cloud-powered OS backup and restore Smartphone owners have long enjoyed a similar functionality, where you could buy a new device and upon the first start, simply log in to your platform account and select "Restore my apps" from the cloud backup. And now Windows will be able to do the same. ["If the user chooses yes, Windows will automatically apply the old wallpaper and settings and even begin preloading apps you had installed on your old PC. Once the user hits the desktop, they'll see all their previously pinned apps already in the Taskbar, and clicking on them will initiate an automatic download from the Microsoft Store."]

Windows 11 on ARM devices gets a big boost [B]ecause Microsoft has no intention of dropping x86 support, they have been slow in adopting ARM architecture to make it a viable alternative for Windows users. With Build 2023, this is moving ahead...

Elsewhere Windows Central argues that "should result in a better experience on devices like the Surface Pro 9 (ARM), Surface Pro X, and the new Dell Inspiron 14 with a Snapdragon 8cx 2 processor.

On the gaming side of things, Unity with native Windows on ARM support will become available in early June. Once launched, the tool will let developers target Windows on ARM devices for current and future games, resulting in better performance. Unity is a very popular development platform for games, and native support for Windows on ARM is a welcome addition...

Visual Studio having Multi-platform App UI (MAUI) support for Arm will give developers another way to target Windows on ARM PCs.

Even Node.js v20.0.0 now officially supports ARM64 Windows, "allowing for native execution on the platform. The MSI, zip/7z packages, and executable are available from the Node.js download site along with all other platforms."

And in addition, Visual Studio 17.71 Preview 1 now ships with support for Linux development with C++.
Open Source

Peplum: F/OSS Distributed Parallel Computing and Supercomputing At Home With Ruby Infrastructure (ecsypno.com) 20

Slashdot reader Zapotek brings an update from the Ecsypno skunkworks, where they've been busy with R&D for distributed computing systems: Armed with Cuboid, Qmap was built, which tackled the handling of nmap in a distributed environment, with great results. Afterwards, an iterative clean-up process led to a template of sorts, for scheduling most applications in such environments.

With that, Peplum was born, which allows for OS applications, Ruby code and C/C++/Rust code (via Ruby extensions) to be distributed across machines and tackle the processing of neatly grouped objects.

In essence, Peplum:

- Is a distributed computing solution backed by Cuboid.
- Its basic function is to distribute workloads and deliver payloads across multiple machines and thus parallelize otherwise time consuming tasks.
- Allows you to combine several machines and built a cluster/supercomputer of sorts with great ease.

After that was dealt with, it was time to port Qmap over to Peplum for easier long-term maintenance, thus renamed Peplum::Nmap.

We have high hopes for Peplum as it basically means easy, simple and joyful cloud/clustering/super-computing at home, on-premise, anywhere really. Along with the capability to turn a lot of security oriented apps into super versions of themselves, it is quite the infrastructure.

Yes, this means there's a new solution if you're using multiple machines for "running simulations, to network mapping/security scans, to password cracking/recovery or just encoding your collection of music and video" -- or anything else: Peplum is a F/OSS (MIT licensed) project aimed at making clustering/super-computing affordable and accessible, by making it simple to setup a distributed parallel computing environment for abstract applications... TLDR: You no longer have to only imagine a Beowulf cluster of those, you can now easily build one yourself with Peplum.
Some technical specs: It is written in the Ruby programming language, thus coming with an entire ecosystem of libraries and the capability to run abstract Ruby code, execute external utilities, run OS commands, call C/C++/Rust routines and more...

Peplum is powered by Cuboid, a F/OSS (MIT licensed) abstract framework for distributed computing — both of them are funded by Ecsypno Single Member P.C., a new R&D and Consulting company.

AI

JPMorgan Developing ChatGPT-Like AI Service For Investment Advice (cnbc.com) 25

JPMorgan Chase has applied to trademark a product called IndexGPT, indicating its development of a ChatGPT-like software service that uses artificial intelligence (AI) to select investments for customers. CNBC reports: IndexGPT will tap "cloud computing software using artificial intelligence" for "analyzing and selecting securities tailored to customer needs," according to the filing. [...] But JPMorgan may be the first financial incumbent aiming to release a GPT-like product directly to its customers, according to Washington D.C.-based trademark attorney Josh Gerben.

"This is a real indication they might have a potential product to launch in the near future," Gerben said. "Companies like JPMorgan don't just file trademarks for the fun of it," he said. The filing includes "a sworn statement from a corporate officer essentially saying, 'Yes, we plan on using this trademark.'" JPMorgan must launch IndexGPT within about three years of approval to secure the trademark, according to the lawyer. Trademarks typically take nearly a year to be approved, thanks to backlogs at the U.S. Patent and Trademark Office, he said. The applications are typically vaguely written to give companies the broadest possible protections, Gerben said.

But JPMorgan's filing does specify that IndexGPT uses the same flavor of A.I. popularized by ChatGPT; the bank plans to use A.I. powered by "Generative Pre-trained Transformer (GPT) models." "It's an A.I. program to select financial securities," Gerben said. "This sounds to me like they're trying to put my financial advisor out of business."

Businesses

Amazon To Close China App Store (scmp.com) 12

Amazon.com will close its official app store in China in July, the latest retreat from the Chinese market by the US tech giant following last year's announcement that its Kindle e-book service would also shut. From a report: An Amazon representative said the Amazon Appstore, launched in 2011 as an alternative to Google for Android phone users to install apps and games, will be "discontinued." However, its official shopping site Amazon.cn will remain operational, as will other services such as Amazon Global Selling, Amazon Global Store and cloud unit Amazon Web Services (AWS). The app store service will shut down on July 17, according to Chinese media The Paper, citing a Tuesday email from Amazon Appstore sent to users, which did not elaborate on the reasons for quitting the market. The Amazon Appstore could not be downloaded from its official Chinese site as of Tuesday.
Businesses

Lenovo Profits Sink 75% As PC Demand Continues Nosedive (theregister.com) 100

Lenovo, the world's largest PC maker, is facing a significant decline in revenue and profit due to decreased demand for personal computers in a post-pandemic world. According to The Register, the company "reported (PDF) revenue of $12.635 billion for Q4 of its fiscal 2023 ended March 31, down a brutal 24 percent year-on-year. Pre-tax profit was down 75 percent to $130 million on the back of workforce restructuring charges." From the report: The Intelligent Devices Group -- the PC and smart gadget division -- was most devastated by shifting buying patterns: revenue fell to $9.79 billion versus $14.69 billion a year earlier, a 33.3 percent decline, and one that may mark a bottoming out of shipments. [...] According to Gartner, PC shipments declined 30 percent to 55.154 million across the industry in calendar Q1, which tracks with Lenovo's Q4. Vendors used discounts to drive sales.

In its previous quarter, Lenovo reported its first profit decline in three years and hatched a plan to save $850 million in annual overheads. One of the levers was cutting jobs. During this latest quarter, it recorded a one-time restructuring charge of $249 million. Lenovo is trying to emphasize other divisions to seek out higher growth in areas including servers and tech services.

The Infrastructure Solutions Group grew to $2.2 billion in the latest quarter, up from $1.408 billion, selling servers and the like to SMEs, larger enterprises, and cloud service providers. The Solutions and Services Group, which includes managed services, grew to $6.66 billion for $5.441 billion a year earlier. For the full year, Lenovo revenues fell to 14 percent to $61.94 billion and it reported a profit before tax of $2.136 billion, down 23 percent.
"By the end of this quarter or early next, the inventory digestion will come to an end so that the activation number and the shipment number will be more consistent," said Lenovo CEO Yanqing Yang.
AI

Amazon's Answer To ChatGPT Seen as Incomplete (bloomberg.com) 7

Amazon's cloud customers are clamoring to get their hands on the ChatGPT-style technology the company unveiled six weeks ago. But instead of being allowed to test it, many are being told to sit tight, prompting concerns the artificial intelligence tool isn't fully baked. From a report: Amazon's announcement that it had entered the generative AI race was uncharacteristically vague, according to longtime employees and customers. Amazon Web Services product launches typically include glowing testimonials from three to five customers, these people said. This time the company cited just one: Coda, a document-editing startup.

Coda Chief Executive Officer Shishir Mehrotra said that after testing the technology he awarded Amazon an "incomplete" grade. The company's generative AI tools are "all fairly early," he said in an interview. "They're building on and repackaging services that they already offered." Mehrotra added that he expected AWS's AI tools to be competitive long-term. People familiar with AWS product launches wondered if Amazon released the AI tools to counter perceptions it has fallen behind cloud rivals Microsoft and Alphabet's Google. Both companies are using generative AI -- which mines vast quantities of data to generate text or images -- to revamp web search and add AI capabilities to a host of products. The technology is unrefined and error-prone, but no one denies its potential to revolutionize computing.

AI

Adobe Photoshop's New 'Generative Fill' AI Tool Lets You Manipulate Photos With Text (arstechnica.com) 38

Adobe has introduced a new tool called "Generative Fill" in the Photoshop beta, which utilizes cloud-based image synthesis and AI-generated content to fill selected areas of an image based on a text description. Ars Technica reports: Powered by Adobe Firefly, Generative Fill works similarly to a technique called "inpainting" used in DALL-E and Stable Diffusion releases since last year. At the core of Generative Fill is Adobe Firefly, which is Adobe's custom image-synthesis model. As a deep learning AI model, Firefly has been trained on millions of images in Adobe's stock library to associate certain imagery with text descriptions of them. Now part of Photoshop, people can type in what they want to see (i.e., "a clown on a computer monitor"), and Firefly will synthesize several options for the user to choose from. Generative Fill uses a well-known AI technique called "inpainting" to create a context-aware generation that can seamlessly blend synthesized imagery into an existing image.

To use Generative Fill, users select an area of an existing image they want to modify. After selecting it, a "Contextual Task Bar" pops up that allows users to type in a description of what they want to see generated in the selected area. Photoshop sends this data to Adobe's servers for processing, then returns results in the app. After generating, the user has the option to select between several options of generations or to create more options to browse through. When used, the Generative Fill tool creates a new "Generative Layer," allowing for non-destructive alterations of image content, such as additions, extensions, or removals, driven by these text prompts. It automatically adjusts to the perspective, lighting, and style of the selected image.

Google

Google CEO: Building AI Responsibly is the Only Race That Really Matters (ft.com) 53

Sundar Pichai, CEO of Google and Alphabet, writing at Financial Times: While some have tried to reduce this moment to just a competitive AI race, we see it as so much more than that. At Google, we've been bringing AI into our products and services for over a decade and making them available to our users. We care deeply about this. Yet, what matters even more is the race to build AI responsibly and make sure that as a society we get it right. We're approaching this in three ways. First, by boldly pursuing innovations to make AI more helpful to everyone. We're continuing to use AI to significantly improve our products -- from Google Search and Gmail to Android and Maps. These advances mean that drivers across Europe can now find more fuel-efficient routes; tens of thousands of Ukrainian refugees are helped to communicate in their new homes; flood forecasting tools are able to predict floods further in advance. Google DeepMind's work on AlphaFold, in collaboration with the European Molecular Biology Laboratory, resulted in a groundbreaking understanding of over 200mn catalogued proteins known to science, opening up new healthcare possibilities.

Our focus is also on enabling others outside of our company to innovate with AI, whether through our cloud offerings and APIs, or with new initiatives like the Google for Startups Growth program, which supports European entrepreneurs using AI to benefit people's health and wellbeing. We're launching a social innovation fund on AI to help social enterprises solve some of Europe's most pressing challenges. Second, we are making sure we develop and deploy the technology responsibly, reflecting our deep commitment to earning the trust of our users. That's why we published AI principles in 2018, rooted in a belief that AI should be developed to benefit society while avoiding harmful applications. We have many examples of putting those principles into practice, such as building in guardrails to limit misuse of our Universal Translator. This experimental AI video dubbing service helps experts translate a speaker's voice and match their lip movements. It holds enormous potential for increasing learning comprehension but we know the risks it could pose in the hands of bad actors and so have made it accessible to authorised partners only. As AI evolves, so does our approach: this month we announced we'll provide ways to identify when we've used it to generate content in our services.

AI

Google Colab Promises 'AI-Powered Coding, Free of Charge' (blog.google) 24

Google Colab hosts free cloud-based "executable documents" that, among other things, let you write and run code in your browser (in dozens of languages, including Python).

Over 7 million people, including students, already use Colab, according to a recent post on Google's blog, "and now it's getting even better with advances in AI [with] features like code completions, natural language to code generation and even a code-assisting chatbot."

Google says it will "dramatically increase programming speed, quality, and comprehension." Our first features will focus on code generation. Natural language to code generation helps you generate larger blocks of code, writing whole functions from comments or prompts. [For example: "import data.csv as a dataframe."] The goal here is to reduce the need for writing repetitive code, so you can focus on the more interesting parts of programming and data science. Eligible users in Colab will see a new "Generate" button in their notebooks, allowing them to enter any text prompt to generate code.

For eligible paid users, as you type, you'll see autocomplete suggestions.

We're also bringing the helpfulness of a chatbot directly into Colab. Soon, you'll be able to ask questions directly in Colab like, "How do I import data from Google Sheets?" or "How do I filter a Pandas DataFrame?"

Anyone with an internet connection can access Colab, and use it free of charge... Access to these features will roll out gradually in the coming months, starting with our paid subscribers in the U.S. and then expanding into the free-of-charge tier.

It's powered by Google's "next generation" machine-learning language model PaLM 2 (announced earlier this month), which "excels at popular programming languages like Python and JavaScript, but can also generate specialized code in languages like Prolog, Fortran and Verilog." Colab will use Codey, a family of code models built on PaLM 2... fine-tuned on a large dataset of high quality, permissively licensed code from external sources to improve performance on coding tasks. Plus, the versions of Codey being used to power Colab have been customized especially for Python and for Colab-specific uses.
Businesses

Alibaba To Spin Off Its Cloud, AI and Business Messenger Unit (techcrunch.com) 1

An anonymous reader quotes a report from TechCrunch: Seven weeks after Alibaba announced its historic restructuring plan to split itself into six independent companies, the juggernaut is gearing up to spin off its intelligence group. Alibaba went public in New York back in 2014, marking the largest IPO at the time. Not long after Hong Kong relaxed rules around dual-class structures, which allow founders to retain certain control while opening the company to outside investment, in 2019, Alibaba sought a secondary listing in the city. Rising tensions between the U.S. and China also prompted many Chinese companies to retreat from the NASDAQ and NYSE in recent years.

"We are taking concrete steps towards unlocking value from our businesses and are pleased to announce that our board has approved a full spin-off of the Cloud Intelligence Group via a stock dividend distribution to shareholders, with intention for it to become an independent publicly listed company," Daniel Zhang, chairman and chief executive officer of Alibaba Group, announced in the firm's earnings report today. Zhang is also one of the cloud arm's board of directors. Alibaba aims to complete the spinoff in the next 12 months and plans to include external strategic investors in the group through private financings.

You might not be familiar with Alibaba's cloud intelligence group, but think of its main product lines roughly as "AWS+Slack+OpenAI". Its cloud business Alibaba Cloud dominates China's market. Globally, Alibaba Cloud was the third largest infrastructure-as-a-service (IaaS) public cloud provider in 2021, according to market research firm Gartner. Add platform-as-a-service (PaaS) and private cloud to the mix, Alibaba came in fourth in Q4 2021, according to another market insight firm Synergy Research Group. Alibaba's Dingtalk, an enterprise chat app and productivity platform, surpassed 600 million users as of Q3 2022, with 15 million paid daily active users and 23 million enterprise users, the company said previously. [...] It makes sense that Alibaba is grouping its cloud business and AI research team under one umbrella as these two go hand in hand. With each new breakthrough in AI, the amount of computational power needed to train data increases exponentially -- so does the cost.
"The cloud business generated $2.7 billion in revenue during the first quarter, making up 9% of Alibaba's total revenues," notes TechCrunch. You can read a deep dive into the cloud spinout here.
Cloud

AWS To Invest $12.7 Billion in India (techcrunch.com) 14

Amazon plans to invest $12.7 billion into its cloud business in India by 2030, the e-commerce group said Thursday, as it pushes ahead to scale up the AWS infrastructure in the key overseas market at a time when it has pared back several other services in the region. From a report: The U.S. giant, which earlier invested $3.7 billion on AWS infra in India and currently maintains two data center regions in the South Asian market, said its spendings will support 131,700 full-time jobs across roles such as engineering, telecommunications and construction. Thursday's announcement is a noteworthy escalation in AWS's initial strategy. The cloud giant had earlier said that it will invest $4.4 billion on AWS in the South Asian economy.
Microsoft

Microsoft Is Scanning the Inside of Password-Protected Zip Files For Malware (arstechnica.com) 130

An anonymous reader quotes a report from Ars Technica: Microsoft cloud services are scanning for malware by peeking inside users' zip files, even when they're protected by a password, several users reported on Mastodon on Monday. Compressing file contents into archived zip files has long been a tactic threat actors use to conceal malware spreading through email or downloads. Eventually, some threat actors adapted by protecting their malicious zip files with a password the end user must type when converting the file back to its original form. Microsoft is one-upping this move by attempting to bypass password protection in zip files and, when successful, scanning them for malicious code.

While analysis of password-protected in Microsoft cloud environments is well-known to some people, it came as a surprise to Andrew Brandt. The security researcher has long archived malware inside password-protected zip files before exchanging them with other researchers through SharePoint. On Monday, he took to Mastodon to report that the Microsoft collaboration tool had recently flagged a zip file, which had been protected with the password "infected." "While I totally understand doing this for anyone other than a malware analyst, this kind of nosy, get-inside-your-business way of handling this is going to become a big problem for people like me who need to send their colleagues malware samples," Brandt wrote. "The available space to do this just keeps shrinking and it will impact the ability of malware researchers to do their jobs."

Fellow researcher Kevin Beaumont joined the discussion to say that Microsoft has multiple methods for scanning the contents of password-protected zip files and uses them not just on files stored in SharePoint but all its 365 cloud services. One way is to extract any possible passwords from the bodies of email or the name of the file itself. Another is by testing the file to see if it's protected with one of the passwords contained in a list. "If you mail yourself something and type something like 'ZIP password is Soph0s', ZIP up EICAR and ZIP password it with Soph0s, it'll find (the) password, extract and find (and feed MS detection)," he wrote.
"A Google representative said the company doesn't scan password-protected zip files, though Gmail does flag them when users receive such a file," notes Ars.

"One other thing readers should remember: password-protected zip files provide minimal assurance that content inside the archives can't be read. As Beaumont noted, ZipCrypto, the default means for encrypting zip files in Windows, is trivial to override. A more dependable way is to use an AES-256 encryptor built into many archive programs when creating 7z files."
Microsoft

Microsoft Cloud Service Under Scrutiny From EU Antitrust Arm (bloomberg.com) 10

Microsoft's Azure cloud business has been targeted by the European Union's antitrust arm, amid concerns the US software firm is leveraging its market power to squeeze out rivals. From a report: As part of an informal probe, regulators are quizzing competitors and customers about how Microsoft may be abusing its access to business-sensitive information belonging to cloud firms it has commercial dealings with, according to documents seen by Bloomberg. EU antitrust enforcers want to know whether Microsoft then leverages such confidential information to compete with cloud-service providers on the market, said two people familiar with the matter, who spoke on condition of anonymity.

The EU's escalation follows on the heels of a series of complaints from cloud firms over Microsoft's behavior -- including CISPE, an industry group with links to Amazon.com's Amazon Web Services. The scrutiny of cloud competition coincides with Microsoft's efforts to convince regulators around the world to approve its $69 billion acquisition of Activision Blizzard, publisher of blockbuster game Call of Duty. The European Commission, the EU watchdog, on Monday conditionally approved the tie-up, just weeks after the UK's competition authority vetoed it.

Microsoft

EU Approves Microsoft's Deal To Buy Activision Blizzard (cnn.com) 47

European regulators have approved Microsoft's $69 billion acquisition of Activision Blizzard, handing the technology giant a victory at a time when the deal is being challenged in other countries. From a report: While the merger could harm competition in some respects, particularly in the fast-growing market for cloud gaming services, concessions by Microsoft were enough to mitigate antitrust concerns stemming from the deal, the European Commission said in a statement. Among Microsoft's offers were a 10-year commitment letting European consumers play Activision titles on any cloud gaming service. Microsoft also committed that it would not downgrade the quality or content of its games made available on rival streaming platforms.
Open Source

Somehow Amazon's Open Source Fork of ElasticSearch Has Succeeded (infoworld.com) 23

Long-time open source advocate Matt Asay writes in InfoWorld: OpenSearch shouldn't exist. The open source alternative to Elasticsearch started off as Amazon Web Services' (AWS) answer to getting outflanked by Elastic's change in Elasticsearch's license, which was in turn sparked by AWS building a successful Elasticsearch service but contributing little back. In 2019 when AWS launched its then Open Distro for Elasticsearch, I thought its reasons rang hollow and, frankly, sounded sanctimonious. This was, after all, a company that used more open source than it contributed. Two years later, AWS opted to fork Elasticsearch to create OpenSearch, committing to a "long-term investment" in OpenSearch.

I worked at AWS at the time. Privately, I didn't think it would work.

Rather, I didn't feel that AWS really understood just how much work was involved in running a successful open source project, and the company would fail to invest the time and resources necessary to make OpenSearch a viable competitor to Elasticsearch. I was wrong. Although OpenSearch has a long way to go before it can credibly claim to have replaced Elasticsearch in the minds and workloads of developers, it has rocketed up the search engine popularity charts, with an increasingly diverse contributor population. In turn, the OpenSearch experience is adding a new tool to AWS' arsenal of open source strengths....

As part of the AWS OpenSearch team, David Tippett and Eli Fisher laid out a few key indicators of OpenSearch's success as they gave their 2022 year in review. They topped more than 100 million downloads and gathered 8,760 pull requests from 496 contributors, a number of whom don't work for AWS. Not stated were other success factors, such as Adobe's earlier decision to replace Elasticsearch with OpenSearch in its Adobe Commerce suite, or its increasingly open governance with third-party maintainers for the project. Nor did they tout its lightning-fast ascent up the DB-Engines database popularity rankings, hitting the Top 50 databases for the first time.

OpenSearch, in short, is a bonafide open source success story. More surprisingly, it's an AWS open source success story. For many who have been committed to the "AWS strip mines open source" narrative, such success stories aren't supposed to exist. Reality bites.

The article notes that OpenSearch's success "doesn't seem to be blunting Elastic's income statement." But it also points out that Amazon now has many employees actively contributing to open source projects, including PostgreSQL and MariaDB. (Although "If AWS were to turn forking projects into standard operating procedure, that might get uncomfortable.")

"Fortunately, not only has AWS learned how to build more open source, it has also learned how to partner with open source companies."

Slashdot Top Deals