About Robin Edgar

Organisational Structures | Technology and Science | Military, IT and Lifestyle consultancy | Social, Broadcast & Cross Media | Flying aircraft

Epic Games CEO Tim Sweeney calls out Apple for promoting its services in the iPhone Settings screen

Epic Games CEO Tim Sweeney, whose high-profile antitrust lawsuit against Apple is now under appeal, is today calling out the iPhone maker for giving itself access to an advertising slot its competitors don’t have: the iPhone’s Settings screen. Some iOS 15 users noticed Apple is now advertising its own services at the top of their Settings, just below their Apple ID. The services being suggested are personalized to the device owner, based on which ones they already subscribe to, it appears.

For example, those without an Apple Music subscription may see an ad offering a free six-month trial. However, current Apple Music subscribers may instead see a prompt to add on a service they don’t yet have, like AppleCare coverage for their devices.

Sweeney suggests this sort of first-party advertising is an anticompetitive risk for Apple, as some of the services it’s pushing here are those that directly compete with third-party apps published on its App Store. But those third-party apps can’t gain access to the iPhone’s Settings screen, of course — they can only bid for ad slots within the App Store itself.

Writes Sweeney: “New from the guys who banned Fortnite: settings-screen ads for their own music service, which come before the actual settings, and which aren’t available to other advertisers like Spotify or Sound Cloud.”

[…]

Source: Epic Games CEO Tim Sweeney calls out Apple for promoting its services in the iPhone Settings screen | TechCrunch

And in the meantime, US judges are blind and deaf to obvious monopolies in plain sight.

Facebook Banned Creator of Unfollow Everything App That Made Facebook Less Toxic

A developer who created a browser extension designed to help Facebook users reduce their time spent on the platform says that the company responded by banning him and threatening to take legal action.

Louis Barclay says he created Unfollow Everything to help people enjoy Facebook more, not less. His extension, which no longer exists, allowed users to automatically unfollow everybody on their FB account, thus eliminating the newsfeed feature, one of the more odious, addictive parts of the company’s product. The feed, which allows for an endless barrage of targeted advertising, is powered by follows, not friends, so even without it, users can still visit the profiles they want to and navigate the site like normal.

The purpose of bucking the feed, Barclay says, was to allow users to enjoy the platform in a more balanced, targeted fashion, rather than being blindly coerced into constant engagement by Facebook’s algorithms.

How did Facebook reward Barclay for trying to make its user experience less toxic? Well, first it booted him off of all of its platforms—locking him out of his Facebook and Instagram accounts. Then, it sent him a cease and desist letter, threatening legal action if he didn’t shut the browser extension down. Ultimately, Barclay said he was forced to do so, and Unfollow Everything no longer exists. He recently wrote about his experience in an op-ed for Slate, saying:

If someone built a tool that made Facebook less addictive—a tool that allowed users to benefit from Facebook’s positive features while limiting their exposure to its negative ones—how would Facebook respond?

I know the answer, because I built the tool, and Facebook squashed it.

Source: Facebook Banned Creator of App That Made Facebook Less Toxic

England’s Data Guardian warns of plans to grant police access to patient data

England’s National Data Guardian has warned that government plans to allow data sharing between NHS bodies and the police could “erode trust and confidence” in doctors and other healthcare providers.

Speaking to the Independent newspaper, Dr Nicola Byrne said she had raised concerns with the government over clauses in the Police, Crime, Sentencing and Courts Bill.

The bill, set to go through the House of Lords this month, could force NHS bodies such as commissioning groups to share data with police and other specified authorities to prevent and reduce serious violence in their local areas.

Dr Byrne said the proposed law could “erode trust and confidence, and deter people from sharing information, and even from presenting for clinical care.”

Meanwhile, the bill [PDF] did not detail what information it would cover, she said. “The case isn’t made as to why that is necessary. These things need to be debated openly and in public.”

In a blog published last week, Dr Byrne said the bill imposes a duty on clinical groups in the NHS to disclose information to police without breaching any obligation of patient confidentiality.

“Whilst tackling serious violence is important, it is essential that the risks and harms that this new duty pose to patient confidentiality, and thereby public trust, are engaged with and addressed,” she said.

[…]

Source: England’s Data Guardian warns of plans to grant police access to patient data • The Register

Microsoft said it mitigated a 2.4 Tbps DDoS attack, the largest ever

Microsoft said its Azure cloud service mitigated a 2.4 terabytes per second (Tbps) distributed denial of service attack this year, at the end of August, representing the largest DDoS attack recorded to date.

Amir Dahan, Senior Program Manager for Azure Networking, said the attack was carried out using a botnet of approximately 70,000 bots primarily located across the Asia-Pacific region, such as Malaysia, Vietnam, Taiwan, Japan, and China, as well as the United States.

Dahan identified the target of the attack only as “an Azure customer in Europe.”

The Microsoft exec said the record-breaking DDoS attack came in three short waves, in the span of ten minutes, with the first at 2.4 Tbps, the second at 0.55 Tbps, and the third at 1.7 Tbps.

Dahan said Microsoft successfully mitigated the attack without Azure going down.

Prior to Microsoft’s disclosure today, the previous DDoS record was held by a 2.3 Tbps attack that Amazon’s AWS division mitigated in February 2020.

Dahan said the largest DDoS attack that hit Azure prior to the August attack was a 1 Tbps attack the company saw in Q3 2020, while this year, Azure didn’t see a DDoS attack over 625 Mbps all year.

Record for largest volumetric DDoS attack broken days later too

Just days after Microsoft mitigated this attack, a botnet called Meris broke another DDoS record — the record for the largest volumetric DDoS attack.

According to Qrator Labs, the operators of the Meris botnet launched a DDoS attack of 21.8 million requests per second (RPS) in early September. Sources told The Record last month that the attack targeted a Russian bank that was hosting its e-banking portal on Yandex Cloud servers.

Security firm Rostelecom-Solar sinkholed around a quarter of the Meris botnet later that month.

It is unclear if the Meris botnet was behind the attack detected and mitigated by Microsoft in August. An Azure spokesperson did not return a request for comment.

Source: Microsoft said it mitigated a 2.4 Tbps DDoS attack, the largest ever

Neiman Marcus Breach Exposes Data Of 4.6 Million Users

Another day, another massive privacy breach nobody will do much about. This time it’s Neiman Marcus, which issued a statement indicating that the personal data of roughly 4.6 million U.S. consumers was exposed thanks to a previously undisclosed data breach that occurred last year. According to the company, the data exposed included login in information, credit card payment information, virtual gift card numbers, names, addresses, and the security questions attached to Neiman Marcus accounts. The company is, as they always are in the wake of such breaches, very, very sorry:

“At Neiman Marcus Group, customers are our top priority,” said Geoffroy van Raemdonck, Chief Executive Officer. “We are working hard to support our customers and answer questions about their online accounts. We will continue to take actions to enhance our system security and safeguard information.”

As is par for the course for this kind of stuff, the actual breach is likely much worse than what’s first being reported here. And by the time the full scope of the breach becomes clear, the press will have largely lost interest. The company set up a website for those impacted to get more information. In this case, impacted consumers didn’t even get free credit reporting, the standard mea culpa hand out after these kinds of events (which is worthless since consumers have received free credit reporting for countless hacks and leaks over the last five to ten years).

[…]

Source: Neiman Marcus Breach Exposes Data Of 4.6 Million Users | Techdirt

Texas abortion: Judge temporarily blocks enforcement of law

A US judge has temporarily blocked a new law in Texas that effectively bans women from having an abortion.

District Judge Robert Pitman granted a request by the Biden administration to prevent any enforcement of the law while its legality is being challenged.

The law, which prohibits women in Texas from obtaining an abortion after six weeks of pregnancy, was drafted and approved by Republican politicians.

The White House praised the latest ruling as an important step.

“The fight has only just begun, both in Texas and in many states across this country where women’s rights are currently under attack,” White House Press Secretary Jen Psaki said.

Texan officials immediately appealed against the ruling, setting the stage for further court battles.

Judge Pitman, of Austin, wrote in an 113-page opinion that, from the moment the law came into effect on 1 September, “women have been unlawfully prevented from exercising control over their lives in ways that are protected by the Constitution”.

“This court will not sanction one more day of this offensive deprivation of such an important right,” he said on Wednesday.

Whole Woman’s Health, which runs a number of clinics in Texas, said it was making plans to resume abortions “as soon as possible”.

But the anti-abortion group Texas Right to Life, accused judges of “catering to the abortion industry” and called for a “fair hearing” at the next stage.

[…]

Source: Texas abortion: Judge temporarily blocks enforcement of law – BBC News

WHO Endorses ‘Breakthrough’ Childhood Vaccine For Malaria

The fight against malaria, one of the world’s worst diseases for decades, is likely to get much easier as the World Health Organization has endorsed the wide use of a malaria vaccine developed by GlaxoSmithKline, the first ever to win such approval. The vaccine will be recommended for children in sub-Saharan Africa and other high-risk areas as a four-dose schedule starting at age 5 months.

[…]

“This is a historic moment. The long-awaited malaria vaccine for children is a breakthrough for science, child health and malaria control,” said WHO Director-General Tedros Adhanom Ghebreyesus in a statement announcing their endorsement of the vaccine. “Using this vaccine on top of existing tools to prevent malaria could save tens of thousands of young lives each year.”

Despite the good news, GlaxoSmithKline’s vaccine, which is currently code-named RTS,S/AS01 but will be branded as Mosquirix, is only modestly effective. In the clinical trials evaluated for WHO approval, it was found to prevent around half of severe cases caused by P. falciparum malaria, compared to the control group. But this level of efficacy was only seen in the first year of vaccination, and by the fourth year, protection had waned to very low levels. At roughly 55% efficacy, the vaccine meets the bare minimum for WHO endorsement.

A major study this year did find that a combination of the vaccine and anti-malarial drugs can further reduce the risk of severe disease and death by 70%, a much more appealing target for public health programs. But even as is, one study has projected that the vaccine would prevent millions of cases and over 20,000 deaths annually in sub-Saharan Africa if deployed widely.

Like other vaccines before it, Mosquirix may also represent the first step toward more effective vaccines in the future. There are several other candidates in development already, including one from Moderna that’s relying on the same mRNA platform as the company’s successful covid-19 vaccine.

Source: WHO Endorses ‘Breakthrough’ Childhood Vaccine For Malaria

EU to file NFC antitrust charges against Apple Pay

Apple’s decision to only allow Apple Pay to access the NFC chip in iPhones could result in the Silicon Valley giant paying hefty anti-monopoly fines in Europe.

The EU is set to file anti-competitive charges against Cupertino regarding its tap-to-pay system, Reuters reported, citing sources. Euro antitrust watchdogs are apparently not happy that the NFC chips in iPhones and iPads are restricted to the iGiant’s Pay software, unfairly locking out alternative wireless payment apps.

The charges will be the result of a European Commission investigation that started last year into Apple’s terms and conditions with merchants, the limited access to the NFC hardware, and more.

“It is important that Apple’s measures do not deny consumers the benefits of new payment technologies, including better choice, quality, innovation and competitive prices,” said Competition Commissioner Margrethe Vestager in 2020. “I have therefore decided to take a close look at Apple’s practices regarding Apple Pay and their impact on competition.”

[…]

Source: Report: EU to file NFC antitrust charges against Apple Pay • The Register

The International Energy Agency publishes the detailed, global energy data we all need, but its funders force it behind paywalls. Let’s ask them to change it.

To make the transition to low-carbon energy sources and address climate change we need open data on the global energy system. High-quality data already exists; it is published by the International Energy Agency. But despite being an international institution that is largely publicly funded, most IEA data is locked behind paywalls. This makes it unusable in the public discourse and prevents many researchers from accessing it. Beyond this, it hinders data-sharing and collaboration; results in duplicated research efforts; makes the data unusable for the public discourse; and goes against the principles of transparency and reproducibility in scientific research. The high costs of the data excludes many from the global dialogue on energy and climate and thereby stands in the way of the IEA achieving its own mission. 

We suggest that the countries that fund the IEA drop the requirement to place data behind paywalls and increase their funding – the benefits of opening this important data are much larger than the costs.

[…]

In 2018, the annual budget of the IEA was EUR 27.8 million. According to the IEA’s budget figures, revenues from its data and publication sales finance “more than one-fifth of its annual budget”. That equates to EUR 5.6 million per year. To put this figure in perspective, it is equal to 0.03% of the total public energy RD&D budget for IEA countries in 2018, which was EUR 20.7 billion. Or on a per capita basis split equally across IEA member countries: 0.44 cents per person per year.

We believe that the relatively small revenues that the paywalls generate do not justify the very large downsides that these restrictions cause.

[…]

The statistical work of the IEA is of immense value. It is the only source of energy data that captures the full range of metrics needed to understand the global energy transition: from primary energy through to final energy use by sub-sector. It is the go-to source for most researchers and forms the basis of the energy systems modelling in the Intergovernmental Panel on Climate Change (IPCC) Assessment Reports. It is also heavily utilised in energy policy, collaborating with the United Nations Framework Convention on Climate Change (UNFCCC) on developments in energy data and analytics.

Some alternative data sources on energy exist, but none come close to the coverage and depth of the IEA data. The BP Statistical Review of World Energy, published by the multinational oil and gas company BP is the most commonly used alternative. As a freely available dataset it is widely used in research and is where the IEA would want to be – ‘at the heart of the global dialogue on energy’. But as it is published by a private fossil fuel company it has some obvious drawbacks.

One is that it focuses on commercially-traded fuels; this means most high- and middle-income countries are included but lower-income countries are almost completely absent even from very basic metrics such as primary energy. It also focuses on primary energy statistics and does not offer insight into the breakdown in final energy or sector-specific allocations.

The series of maps show the comparative geographical coverage of primary and final energy between the publicly available dataset from BP, and the private licensed dataset from the IEA.

[…]

Source: The International Energy Agency publishes the detailed, global energy data we all need, but its funders force it behind paywalls. Let’s ask them to change it. – Our World in Data

World Of Warcraft Update Removes Suggestive Flirts & Jokes – cancel culture wins against humor

Blizzard’s work on cleaning up World of Warcraft in the wake of historical allegations of harassment at the company continues, with the latest round targeting a series of suggestive jokes and flirts that are being removed as part of update 9.1.5.

As detailed by Wowhead, there are a lot of changes, some of them leaving characters with as few as two lines of dialogue to cycle through. And while some are clearly the result of combing back through the archives and removing content that, in the wake of Blizzard’s current crisis, is clearly inappropriate, other cuts are simply down to the fact that it’s now 2021 and some of this stuff is either horribly dated or simply bad.

Some examples of jokes that are being removed are:

Draenei Male: If you could get your hands on my family jewels I would be deeply appreciative.

Goblin Female: I’m a modern goblin woman. Independent? I still let men do nice things to me. But I stopped giving them any credit.

Orc Female: What’s estrogen? Can you eat it?

Tauren Male: Homogenized? No way, I like the ladies.

Meanwhile here are some of the flirts being cut:

Blood Elf Demon Hunter Male: Are you sure you’re not part-demon? I find myself wanting to stalk you.

Blood Elf Female: Normally, I only ride on epic mounts… But, let’s talk.

Dwarf Male: You look pretty, I like your hair, here’s a drink… Are you ready now?

Goblin Male: I got what you need. *sound of zipper*

Highmountain Tauren Female: Are you staring at my rack?

Nightborn Male: Mmmm, I wanna tap that ley line.

Orc Male: Um… You look like a lady.

Troll Female: When enraged, and in heat, a female troll can mate over 80 times in one night. Be you prepared?

Source: World Of Warcraft Update Removes Suggestive Flirts & Jokes

Fine, they are not super clever jokes – but humor is allowed to be bad.

GitHub Removes GTA Fan Projects re3 and reVC Following New Take-Two DMCA Notice

After Take-Two Interactive sent a legal letter to Github referencing a copyright infringement lawsuit against the people behind the popular re3 and reVC Grand Theft Auto fan projects, Github has now removed the repositories for a second time. Take-Two has also demanded the removal of many project forks and wants Github to take action under its repeat infringer policy. TorrentFreak reports: Just before the weekend, a new entry in Github’s DMCA repository revealed the existence of a letter (PDF) sent to Github from Take-Two’s legal team. Dated September 9, 2021 (a week after the copyright lawsuit was filed) it informs Github that legal action is underway and it has come to the company’s attention that the contentious content (and numerous ‘fork’ repositories) continue to be made available on Github’s website. “We request that Github take expeditious action to remove or disable access to the materials [in the attached exhibit], together with any other instances of the same materials available within the same primary ‘GTAmodding/re3’ fork network (e.g. in ‘private’ or newly-created repositories),” it reads.

In common with the first DMCA notice, Github has responded by taking the project’s repositories down. Given that the defendants in the case already stand accused of previously sending ‘bad faith’ counter-notices, it seems unlikely that they will follow up with another set of similar responses that will soon be under the scrutiny of the court. Take-Two also follows up with a line that is becoming more and more popular in copyright infringement matters, one that references so-called ‘repeat infringers.’ “Furthermore, it is requested that Github take appropriate measures to prevent further infringement by the parties responsible, including pursuant to any ‘repeat infringer’ policies maintained by Github.”

This means that if any of the contentious content is reposted to Github, Take-Two would like the code repository to implement its own ‘repeat infringer’ process. It states that “in appropriate circumstances and in its sole discretion, [Github will] disable and terminate the accounts of users who may infringe upon the copyrights or other intellectual property rights of GitHub or others.” The letter also provides a laundry list of repository forks that, on the basis they are also infringing, should be removed. While Github appears to have complied in many cases, there are two notable exceptions. After being targeted by earlier DMCA takedowns, Github users ‘td512‘ and ‘erorcun‘ filed DMCA counter-notices to have their repositories restored. The former previously informed TorrentFreak that he believed Take-Two’s infringement claims to be incorrect. At the time of writing, both repos are still online.

Source: GitHub Removes GTA Fan Projects re3 and reVC Following New Take-Two DMCA Notice – Slashdot

Well done alienating your biggest fans, TakeTwo

MEPs support curbing police use of facial recognition, border biometric data trawling drastically

Police should be banned from using blanket facial-recognition surveillance to identify people not suspected of crimes. Certain private databases of people’s faces for identification systems ought to be outlawed, too.

That’s the feeling of the majority of members in the European Parliament this week. In a vote on Wednesday, 377 MEPs backed a resolution restricting law enforcement’s use of facial recognition, 248 voted against, and 62 abstained.

“AI-based identification systems already misidentify minority ethnic groups, LGBTI people, seniors and women at higher rates, which is particularly concerning in the context of law enforcement and the judiciary,” reads a statement from the parliament.

“To ensure that fundamental rights are upheld when using these technologies, algorithms should be transparent, traceable and sufficiently documented, MEPs ask. Where possible, public authorities should use open-source software in order to be more transparent.”

As well as this, most of the representatives believe facial-recognition tech should not be used by the police in automatic mass surveillance of people in public, and monitoring should be restricted to only those thought to have broken the law. Datasets amassed by private companies, such as Clearview AI, for identifying citizens should also be prohibited along with systems that allow cops to predict crime from people’s behavior and backgrounds.

[…]

The vote is non-biding, meaning it cannot directly lead to any legislative change. Instead, it was cast to reveal if members might be supportive of upcoming bills like the AI Act, a spokesperson for the EU parliament told The Register.

“The resolution is a non-exhaustive list of AI uses that MEPs within the home affairs field find problematic. They ask for a moratorium on deploying new facial recognition systems for law enforcement, and a ban on the narrower category of private facial recognition databases,” the spokesperson added.

It also called for border control systems to stop using biometric data to track travelers across the EU, too.

Source: MEPs support curbing police use of facial recognition • The Register

A French company is using enzymes to recycle one of the most common single-use plastics – PET

In late September, Carbios, a French startup, opened a demonstration plant in central France to test this idea. The facility will use enzymes to recycle PET, one of the most common single-use plastics and the material used to make most beverage bottles.

[…]

Carbios’s new reactor measures 20 cubic meters—around the size of a cargo van. It can hold two metric tons of plastic, or the equivalent of about 100,000 ground-up bottles at a time, and break it down into the building blocks of PET—ethylene glycol and terephthalic acid—in 10 to 16 hours.

The company plans to use what it learns from the demonstration facility to build its first industrial plant, which will house a reactor about 20 times larger than the demonstration reactor. That full-scale plant will be built near a plastic manufacturer somewhere in Europe or the US, and should be operational by 2025, says Alain Marty, Carbios’s chief science officer.

Carbios has been developing enzymatic recycling since the company was founded in 2011. Its process relies on enzymes to chop up the long chains of polymers that make up plastic. The resulting monomers can then be purified and strung together to make new plastics. Researchers at Carbios started with a natural enzyme used by bacteria to break down leaves, then tweaked it to make it more efficient at breaking down PET.

Carbios’s demonstration facility in Clermont-Ferrand, France. Image courtesy of SkotchProd.

Carbios estimates that its enzymatic recycling process reduces greenhouse gas emissions by about 30% compared to virgin PET. Marty says he expects that number to increase as they work out the kinks.

[…]

Source: A French company is using enzymes to recycle one of the most common single-use plastics | MIT Technology Review

How Apple Can Read Your Encrypted iMessages

If you have an iPhone, and your friends mostly have iPhones, you probably use Apple’s Messages app to communicate with them. That’s the nature of things. And aside from the platform’s convenience and ubiquity, one of the iMessage platform’s selling points is that its end-to-end encryption should theoretically ensure that only you and those you text can read your conversations. However, that might not be the case: Apple can likely access the messages for many, many iMessage users, even with end-to-end encryption in place.

[…]

How you back up your messages matters

So yes, your texts are encrypted as sent and received. But few of us delete every text as it comes in; we keep them around in case we want to revisit them later, which means we need to back them up somehow. And as it turns out, how you back up your messages might mean the difference between having an truly secure iMessage history, and giving Apple the key to unlock all your conversations.

[…]

iCloud Backup is not a secure method for saving your messages

Here’s the tricky thing; Messages in iCloud is end-to-end encrypted, just as you’d expect—that’s why there’s no way to access your messages on the web, such as by logging in to icloud.com. There’s one big problem, though: your iCloud Backup isn’t end-to-end encrypted—and Apple stores the key to unlock your encrypted messages within that backup.

[…]

It’s not just your messages; besides Keychain, Screen Time, and Health data, Apple has the key to decrypt all of your iCloud data

[…]

Source: How Apple Can Read Your Encrypted Messages

Search providers compaining that EU Google antitrust measures didn’t achieve anything

Four search providers – DuckDuckGo, Ecosia, Qwant, and Lilo – have penned an open letter to the European Commission claiming that Google is suppressing search engine competition.

The EU has made a number of efforts to counter Google’s search monopoly, including a July 2018 fine and ruling that the company engaged in “illegal tying of Google’s search and browser apps” and “illegal payments conditional on exclusive pre-installation of Google Search.”

Google responded with some licensing changes. In August 2019, it agreed with the EU to provide an Android Choice screen, which included selling spots on the new menu via auction – leading to participants like privacy-centric DuckDuckGo complaining that they were priced out.

Google's new Android Choice screen

Google’s new Android Choice screen

The Android Choice screen has since been revised by further agreement with the European Commission, and now features more options and free participation. The new choice screen includes up to 12 search services, with the five most popular search engines in the local country listed first, as recorded by StatCounter, and is free for search providers.

Third-party search providers are not happy. Today’s open letter [PDF] states that “despite recent changes, we do not believe it will move market share significantly.” The providers say that the new Android Choice menu is “only shown once, in a Google-designed, Google-owned onboarding process. If [users] later decide to switch defaults, they must labour through 15+ clicks or factory-reset their phone.” They also complain that Chrome desktop and other operating systems are not included, and worry that “it doesn’t apply to all search aspects points in Android.”

[…]

“In the meantime, at least one search company went bankrupt. A German company called Cliqz invested €100m into building their own search algorithm and they went bankrupt. Google playing on time is a big problem.”

Cliqz said in its farewell post last year: “We failed to convince the political stakeholders, that Europe desperately needs an own independent digital infrastructure. Here we can only hope that someone else picks up the ball… the world needs a private search engine that is not just using Bing or Google in the backend.”

In Russia, Kroll said: “Yandex went down to a 20 per cent market share. Then they had a real choice screen on a fixed date and it went back to 60 per cent. I’m not saying we should do everything like Russia does, but it shows that it can have an effect.”

[…]

Source: Existence of Bing ‘essential’ to non-Google search engines • The Register

The entirety of Twitch has reportedly been leaked – change your password!

An anonymous hacker claims to have leaked the entirety of Twitch, including its source code and user payout information.

The user posted a 125GB torrent link to 4chan on Wednesday, stating that the leak was intended to “foster more disruption and competition in the online video streaming space” because “their community is a disgusting toxic cesspool”.

VGC can verify that the files mentioned on 4chan are publicly available to download as described by the anonymous hacker.

One anonymous company source told VGC that the leaked data is legitimate, including the source code for the Amazon-owned streaming platform.

Internally, Twitch is aware of the breach, the source said, and it’s believed that the data was obtained as recently as Monday. We’ve requested comment from Twitch and will update this story when it replies.

[UPDATE: Twitch has confirmed the leak is authentic: “We can confirm a breach has taken place. Our teams are working with urgency to understand the extent of this. We will update the community as soon as additional information is available. Thank you for bearing with us.”]

he leaked Twitch data reportedly includes:

  • The entirety of Twitch’s source code with commit history “going back to its early beginnings”
  • Creator payout reports from 2019
  • Mobile, desktop and console Twitch clients
  • Proprietary SDKs and internal AWS services used by Twitch
  • “Every other property that Twitch owns” including IGDB and CurseForge
  • An unreleased Steam competitor, codenamed Vapor, from Amazon Game Studios
  • Twitch internal ‘red teaming’ tools (designed to improve security by having staff pretend to be hackers)

Some Twitter users have started making their way through the 125GB of information that has leaked, with one claiming that the torrent also includes encrypted passwords, and recommending that users enable two-factor authentication to be safe.

If you have a Twitch account, it’s recommended that you also turn on two-factor authentication, which ensures that even if your password is compromised, you still need your phone to prove your identity using either SMS or an authenticator app.

To turn on two-factor identification:

  • Log on to Twitch, click your avatar and choose Settings
  • Go to Security and Privacy, then scroll down to the Security setting
  • Choose Edit Two-Factor Authentication to see if it’s already activated. If not, follow the instructions to turn it on (you’ll need your phone)

Source: The entirety of Twitch has reportedly been leaked | VGC

BMW’s New Factory Robots Can Paint Complex Designs on Cars

[…]

BMW is taking the next step with customization with a newly developed robot that can quickly paint vehicles with complex designs like a giant inkjet printer.

[…]

BMW worked with another German company, Duerr, to create a new factory robot that can paint two-tone finishes, or create elaborate designs on a vehicle, without any in-between masking required. The robot’s called the EcoPaintJet Pro and instead of a traditional paint sprayer on the business end, it uses a contraption that’s not unlike the print head on your inkjet printer. Jets of ink, as small as half a millimeter in thickness, are sprayed through an orifice plate which creates defined edges as it hits the vehicle. When combined with the precision movements of the EcoPaintJet Pro’s robotic arm, intricate designs can be created with transitions between colors that look as crisp as if masking techniques, such as tape or stencils, had been used.

At the BMW Dingolfing plant in Munich, the new robot and paint technique is being piloted on 19 new BMW M4 Coupés that roll out of the factory with a special two-tone finish featuring M4 branding on the hood and tailgate

[…]

The precision of the applied paint means there’s no overspray—excess paint that ends up inside a painting room that has to be cleared away and disposed of, resulting in wasted materials and the use of harsh chemicals. BMW also believes the EcoPaintJet Pro will result in lower energy consumption as it will change how the sealed and highly ventilated painting rooms in its factories operate. “Since paint separation is no longer required, the amount of air needed is also lower. At around 7,000 operating hours, this results in energy savings of more than 6,000 megawatt-hours and reduces the carbon footprint by nearly 2,000 tonnes per year.”

Source: BMW’s New Factory Robots Can Paint Complex Designs on Cars

Telegraph newspaper exposes 10TB of server, user data online

The Telegraph newspaper managed to leak 10TB of subscriber data and server logs after leaving an Elasticsearch cluster unsecured for most of September, according to the researcher who found it online.

The blunder was uncovered by well-known security researcher Bob Diachenko, who said that the cluster had been freely accessible “without a password or any other authentication required to access it.”

After sampling the database to determine its owner, Diachenko saw the personal details of at least 1,200 Telegraph subscribers along with a substantial quantity of internal server logs, he told The Register.

“A significant portion of the records were unencrypted,” he said. Screenshots he provided showed information including the user-agent string and device type, while categories of personal data included subscribers’ first and last names, email addresses, subscriber status, IP addresses and device type and operating system.

Affected users “should be on the lookout for targeted phishing and scams,” Diachenko advised. “Names and emails in the database can be used to send readers targeted scam messages.”

Aside from potential scam emails, the risk from this breach is relatively low unless having your news-reading habits collated in one place might cause professional embarrassment: Diachenko highlighted that in the data sample he viewed were a handful of gov.uk email addresses.

[…]

Source: Telegraph newspaper exposes 10TB of server, user data online • The Register

Oculus Quest VR Goggles Becomes a Paperweight When Facebook Goes Down

When Facebook went down yesterday for nearly six hours, so did Oculus’ services. Since Facebook owns VR headset maker Oculus, and controversially requires Oculus Quest users to log in with a Facebook account, many Quest owners reported not being able to load their Oculus libraries. “[A]nd those who just took a Quest 2 out of the box have reported that they’re unable to complete the initial setup,” adds PCGamer. As VRFocus points out, “the issue has raised another important question relating to Oculus’ services being so closely linked with a Facebook account, your Oculus Quest/Quest 2 is essentially bricked until services resume.” From the report: This vividly highlights the problem with having to connect to Facebook’s services to gain access to apps — the WiFi connection was fine. Even all the ones downloaded and taking up actual storage space didn’t show up. It’s why some VR fans began boycotting the company when it made all mandatory that all Oculus Quest 2’s had to be affiliated with a Facebook account. If you want to unlink your Facebook account from Oculus Quest and don’t want to pay extra for that ability, you’re in luck thanks to a sideloadable tool called “Oculess.” From an UploadVR article published earlier today: You still need a Facebook account to set up the device in the first place and you need to give Facebook a phone number or card details to sideload, but after that you could use Oculess to forgo Facebook entirely — just remember to never factory reset. The catch is you’ll lose access to Oculus Store apps because the entitlement check used upon launching them will no longer function. System apps like Oculus TV and Browser will also no longer launch, and casting won’t work. You can still sideload hundreds of apps from SideQuest though, and if you want to keep browsing the web in VR you can sideload Firefox Reality. You can still use Oculus Link to play PC VR content, but only if you stay signed into Facebook on the Oculus PC app. Virtual Desktop won’t work because it’s a store app, but you can sideload free alternatives such as ALVR.

To use Oculess, just download it from GitHub and sideload it using SideQuest or Oculus Developer Hub, then launch it from inside VR. If your Quest isn’t already in developer mode or you don’t know how to sideload you can follow our guide here.

Source: Oculus Quest Becomes a Paperweight When Facebook Goes Down – Slashdot

Scientists Have Successfully Recorded Data to DNA in Minutes not hours

[…]

researchers at Northwestern University have devised a new method for recording information to DNA that takes minutes rather than hours or days.

The researchers utilized a novel enzymatic system to synthesize DNA that records rapidly changing environmental signals straight into its sequences, and this method could revolutionize how scientists examine and record neurons inside the brain.

A faster and higher resolution recording

To record intracellular molecular and digital data to DNA, scientists currently rely on multipart processes that combine new information with existing DNA sequences. This means that, for an accurate recording, they must stimulate and repress the expression of specific proteins, which can take over 10 hours to complete.

The new study’s researchers hypothesized they could make this process faster by utilizing a new method they call “Time-sensitive Untemplated Recording using Tdt for Local Environmental Signals”, or TURTLES. This way, they would synthesize completely new DNA rather than copying a template of it. The method enabled the data to be recorded into the genetic code in a matter of minutes.

[…]

Source: Scientists Have Successfully Recorded Data to DNA in a Few Short Minutes

Millions of AMD PCs affected by new CPU driver flaw need to be patched ASAP

After finding several security flaws in Intel’s System Guard Extensions (SGX), security researchers have now revealed a flaw in AMD’s Platform Security Processor (PSP) chipset driver that makes it easy for attackers to steal sensitive data from Ryzen-powered systems. On the upside, there’s already patches available from both Microsoft and AMD to shut the exploit.

Recently, AMD disclosed a vulnerability in the AMD Platform Security Processor (PSP) chipset driver that allows malicious actors to dump memory pages and exact sensitive information such as passwords and storage decryption keys.

The flaw is tracked under CVE-2021-26333 and is considered medium severity. It affects a wide range of AMD-powered systems, with all Ryzen desktop, mobile, and workstation CPUs being affected. Additionally, PCs equipped with a 6th and 7th generation AMD A-series APU or modern Athlon processors are vulnerable to the same attack.

Security researcher Kyriakos Economou over at ZeroPeril discovered the flaw back in April. His team tested a proof-of-concept exploit on several AMD systems and found it relatively easy to leak several gigabytes of uninitialized physical memory pages when logged in as a user with low privileges. At the same time, this attack method can bypass exploitation mitigations like kernel address space layout randomization (KASLR).

The good news is there are patches available for this flaw. One way to ensure you get them is to download the latest AMD chipset drivers from TechSpot Drivers page or AMD’s own website. The driver was released a month ago, but at the time AMD chose not to fully disclose the security fixes contained in the release.

[…]

Source: Millions of AMD PCs affected by new CPU driver flaw need to be patched ASAP | TechSpot

Pandora Papers: World leaders deny wrongdoing after leaks

Several world leaders have denied wrongdoing after featuring in a huge leak of financial documents from offshore companies.

Dubbed the Pandora Papers, the 12 million files constitute the biggest such leak in history.

Russian President Vladimir Putin and Jordan’s King Abdullah II bin Al-Hussein are among some 35 current and former leaders linked to the files.

Both have issued statements saying they have done nothing wrong.

Jordan’s royal palace said it was “not unusual nor improper” that King Abdullah owned property abroad.

Leaked documents show the leader secretly spent more than £70m ($100m) on a property empire in the UK and US since taking power in 1999.

Kremlin spokesman Dmitry Peskov meanwhile questioned the reliability of the “unsubstantiated” information, after it detailed hidden wealth linked to President Putin and members of his inner circle.

[…]

The data was obtained by the International Consortium of Investigative Journalists (ICIJ) in Washington DC, which has been working with more than 140 media organisations on its biggest ever global investigation.

BBC Panorama and the Guardian have led the investigation in the UK.

Other leaders linked to the leak include:

  • Czech Prime Minister Andrej Babis, who allegedly failed to declare an offshore investment company used to purchase two villas for £12m in the south of France
  • Kenyan President Uhuru Kenyatta, who – along with six members of his family – has been linked to 13 offshore companies
  • Chile’s President Sebastián Piñera, a billionaire businessman, who is accused of selling a copper and iron mine in an environmentally sensitive area to a childhood friend, as detailed in Spain’s El Pais newspaper
  • And Azerbaijan’s President Ilham Aliyev, whose family and close associates have allegedly been secretly involved in property deals in the UK worth more than £400m

[…]

Source: Pandora Papers: World leaders deny wrongdoing after leaks – BBC News

There’s a Murky Multibillion-Dollar Market for Your Phone’s Location Data

Companies that you likely have never heard of are hawking access to the location history on your mobile phone. An estimated $12 billion market, the location data industry has many players: collectors, aggregators, marketplaces, and location intelligence firms, all of which boast about the scale and precision of the data that they’ve amassed.

Location firm Near describes itself as “The World’s Largest Dataset of People’s Behavior in the Real-World,” with data representing “1.6B people across 44 countries.” Mobilewalla boasts “40+ Countries, 1.9B+ Devices, 50B Mobile Signals Daily, 5+ Years of Data.” X-Mode’s website claims its data covers “25%+ of the Adult U.S. population monthly.”

In an effort to shed light on this little-monitored industry, The Markup has identified 47 companies that harvest, sell, or trade in mobile phone location data. While hardly comprehensive, the list begins to paint a picture of the interconnected players that do everything from providing code to app developers to monetize user data to offering analytics from “1.9 billion devices” and access to datasets on hundreds of millions of people. Six companies claimed more than a billion devices in their data, and at least four claimed their data was the “most accurate” in the industry.

The Location Data Industry: Collectors, Buyers, Sellers, and Aggregators

The Markup identified 47 players in the location data industry

The logo of 1010Data

1010Data
The logo of Acxiom

Acxiom
The logo of AdSquare

AdSquare
The logo of ADVAN

ADVAN
The logo of Airsage

Airsage
The logo of Amass Insights

Amass Insights
The logo of Alqami

Alqami
The logo of Amazon AWS Data Exchange

Amazon AWS Data Exchange
The logo of Anomaly 6

Anomaly 6
The logo of Babel Street

Babel Street
The logo of Blis

Blis
The logo of Complementics

Complementics
The logo of Cuebiq

Cuebiq
The logo of Datarade

Datarade
The logo of Foursquare

Foursquare
The logo of Gimbal

Gimbal
The logo of Gravy Analytics

Gravy Analytics
The logo of GroundTruth

GroundTruth
The logo of Huq Industries

Huq Industries
The logo of InMarket / NinthDecimal

InMarket / NinthDecimal
The logo of Irys

Irys
The logo of Kochava Collective

Kochava Collective
The logo of Lifesight

Lifesight
The logo of Mobilewalla

Mobilewalla

“40+ Countries, 1.9B+ Devices, 50B Mobile Signals Daily, 5+ Years of Data”

The logo of Narrative

Narrative
The logo of Near

Near

“The World’s Largest Dataset of People’s Behavior in the Real-World”

The logo of Onemata

Onemata
The logo of Oracle

Oracle
The logo of Phunware

Phunware
The logo of PlaceIQ

PlaceIQ
The logo of Placer.ai

Placer.ai
The logo of Predicio

Predicio
The logo of Predik Data-Driven

Predik Data-Driven
The logo of Quadrant

Quadrant
The logo of QueXopa

QueXopa
The logo of Reveal Mobile

Reveal Mobile
The logo of SafeGraph

SafeGraph
The logo of Snowflake

Snowflake
The logo of start.io

start.io
The logo of Stirista

Stirista
The logo of Tamoco

Tamoco
The logo of THASOS

THASOS
The logo of Unacast

Unacast
The logo of Venntel

Venntel
The logo of Venpath

Venpath
The logo of Veraset

Veraset
The logo of X-Mode (Outlogic)

X-Mode (Outlogic)
Created by Joel Eastwood and Gabe Hongsdusit. Source: The Markup. (See our data, including extended company responses, here.)

“There isn’t a lot of transparency and there is a really, really complex shadowy web of interactions between these companies that’s hard to untangle,” Justin Sherman, a cyber policy fellow at the Duke Tech Policy Lab, said. “They operate on the fact that the general public and people in Washington and other regulatory centers aren’t paying attention to what they’re doing.”

Occasionally, stories illuminate just how invasive this industry can be. In 2020, Motherboard reported that X-Mode, a company that collects location data through apps, was collecting data from Muslim prayer apps and selling it to military contractors. The Wall Street Journal also reported in 2020 that Venntel, a location data provider, was selling location data to federal agencies for immigration enforcement.

A Catholic news outlet also used location data from a data vendor to out a priest who had frequented gay bars, though it’s still unknown what company sold that information.

Many firms promise that privacy is at the center of their businesses and that they’re careful to never sell information that can be traced back to a person. But researchers studying anonymized location data have shown just how misleading that claim can be.

[…]

Most times, the location data pipeline starts off in your hands, when an app sends a notification asking for permission to access your location data.

Apps have all kinds of reasons for using your location. Map apps need to know where you are in order to give you directions to where you’re going. A weather, waves, or wind app checks your location to give you relevant meteorological information. A video streaming app checks where you are to ensure you’re in a country where it’s licensed to stream certain shows.

But unbeknownst to most users, some of those apps sell or share location data about their users with companies that analyze the data and sell their insights, like Advan Research. Other companies, like Adsquare, buy or obtain location data from apps for the purpose of aggregating it with other data sources

[…]

Companies like Adsquare and Cuebiq told The Markup that they don’t publicly disclose what apps they get location data from to keep a competitive advantage but maintained that their process of obtaining location data was transparent and with clear consent from app users.

[…]

Yiannis Tsiounis, the CEO of the location analytics firm Advan Research, said his company buys from location data aggregators, who collect the data from thousands of apps—but would not say which ones.

[…]

Into the Location Data Marketplace 

Once a person’s location data has been collected from an app and it has entered the location data marketplace, it can be sold over and over again, from the data providers to an aggregator that resells data from multiple sources. It could end up in the hands of a “location intelligence” firm that uses the raw data to analyze foot traffic for retail shopping areas and the demographics associated with its visitors. Or with a hedge fund that wants insights on how many people are going to a certain store.

“There are the data aggregators that collect the data from multiple applications and sell in bulk. And then there are analytics companies which buy data either from aggregators or from applications and perform the analytics,” said Tsiounis of Advan Research. “And everybody sells to everybody else.”

Some data marketplaces are part of well-known companies, like Amazon’s AWS Data Exchange, or Oracle’s Data Marketplace, which sell all types of data, not just location data.

[…]

companies, like Narrative, say they are simply connecting data buyers and sellers by providing a platform. Narrative’s website, for instance, lists location data providers like SafeGraph and Complementics among its 17 providers with more than two billion mobile advertising IDs to buy from

[…]

To give a sense of how massive the industry is, Amass Insights has 320 location data providers listed on its directory, Jordan Hauer, the company’s CEO, said. While the company doesn’t directly collect or sell any of the data, hedge funds will pay it to guide them through the myriad of location data companies, he said.

[…]

Oh, the Places Your Data Will Go

There are a whole slew of potential buyers for location data: investors looking for intel on market trends or what their competitors are up to, political campaigns, stores keeping tabs on customers, and law enforcement agencies, among others.

Data from location intelligence firm Thasos Group has been used to measure the number of workers pulling extra shifts at Tesla plants. Political campaigns on both sides of the aisle have also used location data from people who were at rallies for targeted advertising.

Fast food restaurants and other businesses have been known to buy location data for advertising purposes down to a person’s steps. For example, in 2018, Burger King ran a promotion in which, if a customer’s phone was within 600 feet of a McDonalds, the Burger King app would let the user buy a Whopper for one cent.

The Wall Street Journal and Motherboard have also written extensively about how federal agencies including the Internal Revenue Service, Customs and Border Protection, and the U.S. military bought location data from companies tracking phones.

[…]

Outlogic (formerly known as X-Mode) offers a license for a location dataset titled “Cyber Security Location data” on Datarade for $240,000 per year. The listing says “Outlogic’s accurate and granular location data is collected directly from a mobile device’s GPS.”

At the moment, there are few if any rules limiting who can buy your data.

Sherman, of the Duke Tech Policy Lab, published a report in August finding that data brokers were advertising location information on people based on their political beliefs, as well as data on U.S. government employees and military personnel.

“There is virtually nothing in U.S. law preventing an American company from selling data on two million service members, let’s say, to some Russian company that’s just a front for the Russian government,” Sherman said.

Existing privacy laws in the U.S., like California’s Consumer Privacy Act, do not limit who can purchase data, though California residents can request that their data not be “sold”—which can be a tricky definition. Instead, the law focuses on allowing people to opt out of sharing their location in the first place.

[…]

“We know in practice that consumers don’t take action,” he said. “It’s incredibly taxing to opt out of hundreds of data brokers you’ve never even heard of.”

[…]

 

Source: There’s a Multibillion-Dollar Market for Your Phone’s Location Data – The Markup

Chinese AI gets ethical guidelines for the first time

[…]

Humans should have full decision-making power, the guidelines state, and have the right to choose whether to accept AI services, exit an interaction with an AI system or discontinue its operation at any time. The document was published by China’s Ministry of Science and Technology (MOST) last Sunday.

The goal is to “make sure that artificial intelligence is always under the control of humans,” the guidelines state.

“This is the first specification we see from the [Chinese] government on AI ethics,” said Rebecca Arcesati, an analyst at the German think tank Mercator Institute for China Studies (Merics). “We had only seen high-level principles before.”

The guidelines, titled “New Generation Artificial Intelligence Ethics Specifications”, were drafted by an AI governance committee, which was established under the MOST in February 2019. In June that year, the committee published a set of guiding principles for AI governance that was much shorter and broader than the newly released specifications.

[…]

The document outlines six basic principles for AI systems, including ensuring that they are “controllable and trustworthy”. The other principles are improving human well-being, promoting fairness and justice, protecting privacy and safety, and raising ethical literacy.

The emphasis on protecting and empowering users reflects Beijing’s efforts to exercise greater control over the country’s tech sector. One of the latest moves in the year-long crackdown has been targeting content recommendation algorithms, which often rely on AI systems built on collecting and analysing massive amounts of user data.

[…]

The new AI guidelines are “a clear message to tech giants that have built entire business models on recommendation algorithms”, Arcesati said.

However, the changes are being done in the name of user choice, giving users more control over their interactions with AI systems online, an issue other countries are also grappling with. Data security, personal privacy and the right to opt out of AI-driven decision-making are all mentioned in the new document.

Preventing risks requires spotting and addressing technical and security vulnerabilities in AI systems, making sure that relevant entities are held accountable, the document says, and that the management and control of AI product quality are improved.

The guidelines also forbid AI products and services from engaging in illegal activities and severely endangering national security, public security or manufacturing security. Neither should they be able to harm the public interest, the document states.

[…]

Source: Chinese AI gets ethical guidelines for the first time, aligning with Beijing’s goal of reining in Big Tech | South China Morning Post

Facebook, Instagram, and WhatsApp hit by 6 hr + global outage, stock tanks

Facebook offered “sincere apologies” Monday afternoon as a sweeping outage of its site and various other properties, including Instagram, WhatsApp and Messenger, stretched for more than six hours and helped to wipe more than $50 billion off Facebook’s market cap — the stock’s worst day of trading in almost a year.

The issues started around 11:45 a.m. ET, according to DownDetector, and hit users globally, taking out critical communications platforms that billions of people and businesses rely on everyday. Service began to return at around 6 p.m.

While Facebook has yet to identify the root of the issue, cybersecurity experts said it does not appear to be a cyberattack and instead seems to be linked to internal issues with Facebook’s systems.

[…]

As Facebook scrambled to solve the issue, investors ditched the stock, sending almost 5 percent lower to $326.23 per share. It was the stock’s biggest one-day plummet since Nov. 9, 2020.

Facebook founder Mark Zuckerberg’s personal wealth took a more than $6 billion hit on Monday, sending him below Microsoft founder Bill Gates to No. 5 on Bloomberg’s Billionaires Index. Zuckerberg is now worth about $121.6 billion, down from almost $140 billion just a couple weeks ago, according to Bloomberg.

The outage also disrupted internal Facebook systems, including security, a company calendar and scheduling tools, The Times reported, adding that some Facebook employees weren’t even able to enter buildings due to the outage.

[…]

In a curious twist, by early afternoon, the domain name “Facebook.com” was listed for sale by Domain Tools. The organization behind the domain registration was still listed as Facebook, Inc. and it’s unclear why the site’s address would be listed for sale.

[…]

Other popular sites — including Gmail and Microsoft-owned LinkedIn –also began to experience some issues throughout the day, according to DownDetector.

[…]

Oculus, the Facebook-owned virtual reality gaming platform, was having issues, too.

“We’re aware that some people are having trouble accessing our apps and products. We’re working to get things back to normal as quickly as possible, and we apologize for any inconvenience,” Oculus tweeted.

As social media fanatics flocked to Twitter, the Facebook rival joked, “hello literally everyone,” in a tweet that racked up nearly half a million retweets.

But Twitter itself saw some outages Monday afternoon, according to DownDetector, with several thousand people reporting issues on the site.

[…]

The outage comes a day after a Facebook whistleblower who leaked a trove of damning internal documents to the Wall Street Journal came forward and identified herself as Frances Haugen, a former product manager at Facebook.

[…]

Source: Facebook, Instagram, and WhatsApp hit by global outage, stock tanks