Massive rugby ball-shaped exoplanet spotted 1,500 ly away

Just over 1,500 light-years away in the constellation of Hercules there’s a rugby ball-shaped exoplanet orbiting a star. It’s the first time astronomers have been able to detect such an unusual shape of an alien world.

Most planets are more or less spherical due to gravitational forces that pull matter equally in from all sides, yet WASP-103b appears to be elongated. The planet is in an orbit close to its host star, and experiences strong tidal forces that appear to have deformed its surface.

[…]

The findings were published in a paper in Astronomy & Astrophysics on Tuesday.

[…]

Tidal interactions between a star and its companions can suck exoplanets in, making the time it takes for a complete orbit to shorten over time. But the orbital period for WASP-103b appears to be increasing, meaning its getting further away from its star.

The team isn’t quite sure why the planet seems to be getting more distant, and are trying to confirm the data in future observations.

Source: Massive rugby ball-shaped exoplanet spotted 1,500 ly away • The Register

The AI software that could turn you in to a music star

If you have ever dreamed of earning money from a stellar music career but were concerned you had little talent, don’t let that put you off – a man called Alex Mitchell might be able to help.

Mr Mitchell is the founder and boss of a website and app called Boomy, which helps its users create their own songs using artificial intelligence (AI) software that does most of the heavy lifting.

You choose from a number of genres, click on “create song”, and the AI will compose one for you in less than 30 seconds. It swiftly picks the track’s key, chords and melody. And from there you can then finesse your song.

A man using the Boomy appImage source, Boomy
Image caption,

The Boomy app can be used on the move

You can do things such as add or strip-out instruments, change the tempo, adjust the volumes, add echoes, make everything sound brighter or softer, and lay down some vocals.

California-based, Boomy, was launched at the end of 2018, and claims its users around the world have now created almost five million songs.

The Boomy website and app even allows people to submit their tracks to be listed on Spotify and other music streaming sites, and to earn money every time they get played.

While Boomy owns the copyright to each recording, and receives the funds in the first instance, the company says it passes on 80% of the streaming royalties to the person who created the song.

Mr Mitchell adds that more than 10,000 of its users have published over 100,000 songs in total on various streaming services.

[…]

But, how good are these Boomy created songs? It has to be said that they do sound very computer generated. You wouldn’t mistake them for a group of people making music using real instruments.

[…]

Mr Mitchell says that what has changed in recent years is that technological advancements in AI have meant song-writing software has become much cheaper.

So much so that Boomy is able to offer its basic membership package for free. Other AI song creator apps, such as Audoir’s SAM, and Melobytes, are also free to use.

[…]

general director of the San Francisco Opera, and it could no longer have “two singers, or even a singer and pianist, in the same room”.

But when he tried running rehearsals with his performers online, “traditional video conference platforms didn’t work”, because of the latency, or delays in the audio and video. They were out of sync.

So, Mr Shilvock turned to a platform called Aloha that has been developed by Swedish music tech start-up Elk. It uses algorithms to reduce latencies.

Elk spokesman, Björn Ehler, claims that while video platforms like Zoom, Skype, and Google Meet have a latency of “probably 500 to 600 milliseconds”, the Swedish firm has got this down to just 20.

Mr Shilvock says that, when working remotely, Aloha has “allowed me to hear a singer breathe again”.

[…]

in Paris, Aurélia Azoulay-Guetta says that, as an amateur classical musician, she “realised how painful it is to just carry, store, and travel with a lot of physical sheet music for rehearsals, and how much time we waste”.

So she and her fellow co-founder “decided to junk our jobs” and launch a start-up called Newzik, which allows music publishers and composers to digitally distribute their sheet music to orchestras. […] her solution replaces the stress of musicians having to turn physical, paper pages with their hands during performance or rehearsal. Instead, they now turn a turn a digital page via a connected pedal.

[…]

Portuguese start-up Faniak.

Founder and chief executive, Nuno Moura Santos, describes its app as “like a Google Drive on steroids”, allowing musicians – who are often freelancers -to more easily do their admin all in one place, “so they can spend more time writing and playing music”.

[…]

 

Source: The AI software that could turn you in to a music star – BBC News

Microsoft warns of destructive cyberattack on Ukrainian computer networks

Source: Microsoft warns of destructive cyberattack on Ukrainian computer networks | bdnews24.com

Canon can’t get enough toner chips, so it’s telling customers how to defeat its DRM

[.,..]To enforce the use of first-party cartridges, manufacturers typically embed chips inside the consumables for the printers to “authenticate.” But when chips are in short supply, like today, manufacturers can find themselves in a bind. So Canon is now telling German customers how to defeat its printers’ warnings about third-party cartridges.

“Due to the worldwide continuing shortage of semiconductor components, Canon is currently facing challenges in procuring certain electronic components that are used in our consumables for our multifunction printers (MFP),” a Canon support website says in German. “In order to ensure a continuous and reliable supply of consumables, we have decided to supply consumables without a semiconductor component until the normal supply takes place again.”

[…]

The software on these printers comes with a relatively simple way to defeat the chip checks. Depending on the model, when an error message occurs after inserting toner, users can press either “I Agree,” “Close,” or “OK.” When users press that button, the world does not end. Rather, Canon says users may find that their toner cartridge doesn’t give them a low-toner warning before running empty.

“Although there are no negative effects on print quality when consumables are used without electronic components, certain additional functions, such as the detection of the toner level, may be impaired,” Canon’s support site says.

Source: Canon can’t get enough toner chips, so it’s telling customers how to defeat its DRM | Ars Technica

Developer Bricks Open-Source Apps Colors and Faker – used in 20k projects – no reason given, world of crazy

The eccentric developer behind two immensely popular open-source NPM coding libraries recently corrupted them both with a series of bizarre updates—a decision that has led to the bricking of droves of projects that relied upon them for support.

Marak Squires is the creator behind the popular JavaScript libraries Faker and Colors—the likes of which are key instruments for developers the world over. To give you an idea of how widely used these are, Colors reportedly sees more than 20 million downloads a week and Faker gets about 2 million. Suffice it to say, they see a lot of use.

However, Squires recently made the bizarre decision to mess all that up when he executed a number of malicious updates that sent the libraries haywire—taking a whole lot of dependent projects with it. In the case of Colors, Squires sent an update that caused its source code to go on an endless repeating loop. This caused apps using it to emit the text “Liberty Liberty Liberty,” followed by a splurge of meaningless, garbled data, effectively crippling their functionality. With Faker, meanwhile, a new update was recently introduced that basically nuked the library’s entire code. Squires subsequently announced he would no longer be maintaining the program “for free.”

The whole episode, which sent developers that rely on both programs into panic mode, appears to have been first observed by researchers with Snyk, an open-source security company, as well as BleepingComputer.

[…]

The most perplexing thing about this whole episode is that it’s not entirely clear why Squires did this. Some online commentators attributed the decision to a blog post he published in 2020, in which he railed against big companies’ use of open-source code from developers like himself. It’s true that corporate America tends to cut fiscal corners by exploiting freely available coding tools (just look at the recent log4j debacle, for example), though, if you’re an open-source coder, you would ostensibly know and expect that.

Indeed, the way in which Squires blitzed his libraries seems to defy simple explanation. For one thing, the commits that messed with the libraries were accompanied by odd text files that, in the case of the Faker update, referenced Aaron Swartz. Swartz is a well-known computer programmer who was found dead in his apartment in 2013 of an apparent suicide. Squires also made a number of other odd public references to Swartz around the time of the malicious commits.

[…]

Source: Developer Bricks Open-Source Apps Colors and Faker, Causes Chaos

Did you always want to hack an ESA satellite? Now’s your chance

The European Space Agency (ESA) is inviting applications from attackers who fancy having a crack at its OPS-SAT spacecraft.

It’s all in the name of ethical hacking, of course. The plan is to improve the resilience and security of space assets by understanding the threats dreamed up by security professionals and members of the public alike.

OPS-SAT has, according to ESA, “a flight computer 10 times more powerful than any current ESA spacecraft” and the CubeSat has been in orbit since 2019, providing a test bed for software experiments.

It is therefore the ideal candidate for l33t h4x0rs to turn their attention to, while ESA engineers ensure the environment is kept under control.

“The in-built robustness of OPS-SAT makes it the perfect flying platform for ethical hackers to demonstrate their skills in a safe but suitably realistic environment,” explained Dave Evans, OPS-SAT mission manager.

Ideas need to be submitted by 18 February and the successful applicants will be given controlled, technical access to OPS-SAT during the April CYSAT conference. It’ll be a challenge since teams will only have six-minute communication slots available with the satellite in which to unleash their creations.

Running code submitted by the public in space is not a particularly new concept – the AstroPi hardware on board the International Space Station (ISS) is a great example of such outreach.

However, the engagement with cybersecurity experts via the OPS-SAT demo will give space agencies an opportunity to learn what works – and what does not – from a security standpoint as satellites become ever more complicated and the surface area for attack grows.

Interestingly, ESA’s announcement had originally been made a month ago and then hurriedly pulled. Possibly because the original title “Hack an ESA spacecraft” caused at least one of the agency’s bosses to pass their morning caffeinated beverage through a nostril. Or, as an ESA insider put it, seek to “review” the emission.

Source: Hack our spacecraft, says ESA • The Register

Robinhood Must Pay User $29,460 Over Meme Stock Trading Halt

In January 2021, stock trading app Robinhood infuriated users when it responded to surging trades of so-called meme stocks, by halting trades—effectively preventing users from selling shares until the prices had collapsed. Congressional hearings, regulatory probes, and a deluge of regulatory complaints and lawsuits ensued, which was at least one cause of its initial public offering’s wretched post-IPO performance. A year later, at least one investor has finally succeeded in forcing Robinhood to pay out for the fiasco.

As Marketwatch first reported, on Jan. 6, an arbitrator for the Financial Industry Regulatory Authority (FINRA) ruled in favor of 27-year-old truck driver Jose Batista’s May 2021 complaint that the restrictions caused him to lose significant amounts of money, finding the stock-trading app owes him nearly $29,500 in restitution. FINRA has previously slapped Robinhood with roughly $70 million in penalties for system outages in March 2020, issuing false and/or misleading information to investors, and failing to abide by rules designed to protect investors; the Securities and Exchange Commission also fined the company $65 million in 2020 on similar grounds. But according to Marketwatch, this is the first time any retail investor complaints specifically related to the 2021 meme stock restrictions have resulted in a monetary judgment.

That’s perhaps because previous attempts to get the company to pay up have relied on elaborate theories Robinhood halted the trades in order to please partner Citadel Securities, its prime market maker. The exact nature of Robinhood’s relationship with Citadel attracted attention from both angry investors and members of Congress. FINRA has previously concluded the accusations of collusion had no merit.

[…]

Batista made a “narrow and specific case” against Robinhood, according to Marketwatch, saying that he focused on how the restrictions made him unable to manage his investments in headphone maker Koss and fast-fashion retailer Express Inc. Shortly before the restrictions went into place, Koss was trading at $58 a share and Express was trading at $9.55; by the time Robinhood lifted them, Koss was down to $35 and Express shares were just $5. (While he had Gamestop stock, he had no intention of selling at that point, he told Marketwatch.)

“My plan was to sell Koss and Express that day,” Batista told the site. “I had a lot, but no one could buy it… They basically left me with no other option. They were saying ‘You’re just stuck. If you want to sell it. Sell it.’”

[…]

Batista made a “narrow and specific case” against Robinhood, according to Marketwatch, saying that he focused on how the restrictions made him unable to manage his investments in headphone maker Koss and fast-fashion retailer Express Inc. Shortly before the restrictions went into place, Koss was trading at $58 a share and Express was trading at $9.55; by the time Robinhood lifted them, Koss was down to $35 and Express shares were just $5. (While he had Gamestop stock, he had no intention of selling at that point, he told Marketwatch.)

“My plan was to sell Koss and Express that day,” Batista told the site. “I had a lot, but no one could buy it… They basically left me with no other option. They were saying ‘You’re just stuck. If you want to sell it. Sell it.’”

[…]

Source: Robinhood Must Pay User $29,460 Over Meme Stock Trading Halt

Raspberry Pi Can Detect Malware By Scanning for EM Waves

A team of researchers at France’s Research Institute of Computer Science and Random Systems created an anti-malware system centered around a Raspberry Pi that scans devices for electromagnetic waves. As reported by Tom’s Hardware, the security device uses an oscilloscope (Picoscope 6407) and H-Field probe connected to a Raspberry Pi 2B to pick up abnormalities in specific electromagnetic waves emitted by computers that are under attack, a technique the researchers say is used to “obtain precise knowledge about malware type and identity.”

The detection system then relies on Convolution Neural Networks (CNN) to determine whether the data gathered indicates the presence of a threat. Using this technique, researchers claims they could record 100,000 measurement traces from IoT devices infected by genuine malware samples, and predicted three generic and one benign malware class with an accuracy as high as 99.82%.

Best of all, no software is needed and the device you’re scanning doesn’t need to be manipulated in any way. As such, bad actors won’t be successful with their attempts to conceal malicious code from malware detection software using obfuscation techniques.

“Our method does not require any modification on the target device. Thus, it can be deployed independently from the resources available without any overhead. Moreover, our approach has the advantage that it can hardly be detected and evaded by the malware authors,” researchers wrote in the paper.

Keep in mind that this system was made for research purposes, not to be released as a commercial product, though it may inspire security teams to look into novels way of using EM waves to detect malware. The research is currently in its early stages and the neural network will need to be further trained before it could have any practical uses.

[…]

Source: Raspberry Pi Can Detect Malware By Scanning for EM Waves

Oscilloscope used costs loads of money and needs to be mounted at 45o to the processor. Lots of work needed to turn this into a viable system.

Facebook Pixel Hunt – Mozilla Rally want to track the trackers

In a collaboration between journalists at The Markup and Mozilla researchers, this study seeks to map Facebook’s pixel tracking network and understand the kinds of information it collects on sites across the web. The Markup will use the data collected in this study to create investigative journalism around the kinds of information Facebook collects about you, and where.

The study will run until July 13, 2022.

Goals of the Study

According to its own privacy policy, Facebook may collect information about you across the web even if you don’t have a Facebook account. One way Facebook performs this tracking is through a network of “pixels” that may be installed on many of the sites you visit. By joining this study, you will help Rally and The Markup investigate and report on where Facebook is tracking you and what kind of information they are collecting.

This Study Will Collect:

This Study will Collect:

  • The data sent to Facebook pixels as you browse
  • The URLs of the web pages you browse
  • The time you spend browsing pages
  • The presence of Facebook login cookies in your browser
  • A study survey that the user completes
  • Metadata on the URLs your visit:
    • The full URL of each webpage that you are on
    • Time spent browsing and playing media on each webpage
    • How far down the webpage you scrolled

In addition, your Rally demographics survey responses will be combined with study data for the analysis.

Note: Only deidentified metrics and models will be exported from our secure environment. For additional information about our data collection, view our metrics definition file in our open source codebase.

Source: Facebook Pixel Hunt

Earth Is in a 1,000-Light-Year-Wide Bubble That Cooks Up Stars

In a study published today in Nature, they describe an amorphous, 1,000-light-year-wide bubble ensconcing Earth that is responsible for those stars.

Called the Local Bubble, the researchers believe it formed from a series of large explosions that blasted energy into space over the last 14 million years. Those explosions were supernovae—spectacular collapses of stars that sometimes leave behind beautiful nebulae. In this case, the supernovae also shaped our galactic neighborhood, 500 light-years in any direction from Earth.

“We find that all nearby, young stars formed as powerful supernova explosions triggered an expanding shockwave, sweeping up interstellar clouds of gas and dust into a cold dense shell that now forms the surface of the Local Bubble,” said study co-author Catherine Zucker in an email to Gizmodo.

“Astronomers have theorized for many decades that supernovae can ‘sweep up’ gas into dense clouds that ultimately form new stars, but our work provides the strongest observational evidence to date in support of this theory,” added Zucker, an astronomer at the Center for Astrophysics | Harvard & Smithsonian.

The team modeled how the explosions likely took place over millions of years, pushing gas outward like a broom sweeping up dust. At its genesis, the bubble was probably moving outward at about 60 miles per second, Zucker said. It’s still expanding today, but at a more leisurely 4 miles per second. Interactive figures of the bubble can be seen here.

Our Solar System is at the center of the bubble, rather than at its edge. That’s because, unlike the stars on the Local Bubble’s periphery, our solar system was born much longer ago than the last 14 million years.

A bright orange halo surrounds the white core of NGC2392, the remains of a star that went supernova.
NGC2392, a nebula left by a supernovae some 5,000 light-years from Earth, taken by the Hubble Space Telescope in 2002.
Image: NASA

“When the Local Bubble first started forming, the Earth was over 1,000 light-years away,” Zucker said. “We think the Earth entered the bubble about 5 million years ago, which is consistent with estimates of radioactive iron isotope deposits from supernova in the Earth’s crust from other studies.”

Source: Earth Is in a 1,000-Light-Year-Wide Bubble That Cooks Up Stars

Dutch Athletes Warned To Keep Phones and Laptops Out of China

Dutch athletes competing in next month’s Beijing Winter Olympics will need to leave their phones and laptops at home in an unprecedented move to avoid Chinese espionage, Dutch newspaper De Volkskrant reported on Tuesday. The urgent advice to athletes and supporting staff to not bring any personal devices to China was part of a set of measures proposed by the Dutch Olympic Committee (NOCNSF) to deal with any possible interference by Chinese state agents, the paper said citing sources close to the matter. NOCNSF spokesman Geert Slot said cybersecurity was part of the risk assessment made for the trip to China, but declined to comment on any specific measure. “The importance of cybersecurity of course has grown over the years”, Slot said. “But China has completely closed off its internet, which makes it a specific case.”

Source: Dutch Athletes Warned To Keep Phones and Laptops Out of China – Slashdot