About Robin Edgar

Organisational Structures | Technology and Science | Military, IT and Lifestyle consultancy | Social, Broadcast & Cross Media | Flying aircraft

FTC fines Amazon $61.7 million for withholding tips from Flex drivers

Amazon will pay a $61.7 million fine to settle allegations the company had failed to properly pay out tips to its Flex delivery drivers, the Federal Trade Commission (FTC) announced on Tuesday. The fine stems from a payment change the company implemented in late 2016. At the time, Amazon said Flex drivers, which use their own cars to deliver packages and groceries for Prime Now and Whole Foods, could earn $18 to $25 per hour, plus tips for their work. That same year, it put into place a new payment policy, which the FTC says Amazon did not properly disclose to drivers, that saw it pay Flex drivers a lower hourly rate. Over a timeframe of two-and-a-half years, it used the tips they earned to make up the difference between the rate it had promised and the one it was actually paying out.

According to the agency, not only did Amazon “intentionally” fail to notify drivers of its policy changes, it actively took steps to obscure them as well and used the tips drivers earned. The entire time it also continued to advertise Flex drivers could earn tips and $18 to $25 per hour. The company only went back to the previous payment model after it became aware of the FTC’s investigation in 2019.

[…]

Source: FTC fines Amazon $61.7 million for withholding tips from Flex drivers | Engadget

India’s government threatens to jail Twitter employees unless they block critics

India’s government has warned Twitter that it must obey its orders to remove “inflammatory content” or employees will face potential jail time, Buzzfeed has reported. The government, under Prime Minister Narendra Modi, made the edict after Twitter unblocked 257 accounts criticizing Modi’s government around farmer protests, after initially blocking them.

The accounts in question come from government opposition leaders, investigative journalism site The Caravan, along with other critics, journalists and writers. Some used the hashtag #ModiPlanningFarmerGenocide, referencing controversial proposed laws that farmers have said will reduce their income and make them more reliant on corporations.

After initially blocking the accounts, Twitter reversed its decision, saying the tweets constituted free speech and were newsworthy. In response, the IT ministry ordered them blocked again. “Twitter is an intermediary and they are obliged to obey directions of the government. Refusal to do so will invite penal action,” it told Twitter in a notice. It added that the hashtag was being used to “abuse, inflame and create tension in society on unsubstantiated grounds.”

The Caravan, which didn’t use the hashtag, said it was merely doing its job. “We don’t understand why suddenly the Indian government finds journalists should not speak to all sides of an issue,” executive editor Vinod K. Jose, told BuzzFeed News. “This is really problematic,” added internet activist and MediaNama editor Nikhail Pahwa.

Modi’s government was also incensed by western celebrities including Rhianna and Greta Thunberg who tweeted their support. Some Modi supporters railed against the tweets, including Bollywood actor Kangana Ranaut. “No one is talking about it because they are not farmers, they are terrorists who are trying to divide India,” she wrote.

The latest development means Twitter, once again, must choose to either protect its employees and commercials interests, or be accused of aiding censorship in a volatile political situation. However, it may be forced to comply due to India’s IT laws that force social media platforms to remove “any information generated, transmitted, received, stored or hosted in any computer resource” that could affect “public order.”

Source: India’s government threatens to jail Twitter employees unless they block critics | Engadget

British Troops Get Small Swarming Drones They Can Fire From 40mm Grenade Launchers

British Army troops in Mali are now reportedly using tiny unmanned aircraft that can be fired from standard 40mm grenade launchers. These diminutive quad-copter-type drones can be fitted with various payloads, ranging from full-motion electro-optical video cameras to small high-explosive or armor-piercing warheads, and that can fly together as a swarm after launch.

Overt Defense was first to report that members of the U.K. Task Group in Mali had received “several hundred” Drone40s from Australian firm DefendTex. British forces are in Mali as part of the country’s Operation Newcombe, which provides support to Operation Barkhane, a French-led regional counter-terrorism effort, and the United Nation’s Multidimensional Integrated Stabilization Mission in Mali, also known by its French acronym MINUSMA.

Crown Copyright

A British Army soldier holds a Drone40 during an exercise.

The Drone40, which DefendTex unveiled publicly in 2019, was among various new systems that British Army troops from the Light Dragoons and Royal Anglian Regiment were seen training with during a Mission Rehearsal Exercise (MRX) in October 2020. That MRX was part of the workup for members of those units that headed for Mali in December. It’s not clear if the British Army has decided to acquire Drone40s for widespread use among its units or if it is conducting an operational evaluation through Operation Newcombe.

The Drone40 can be fired from launchers designed to fire standard 40mm low-velocity grenades. Its overall length is variable depending on the type of payload installed, but DefendTex says the length of the core body is close to five inches. As such, a launcher designed to fire over-sized 40mm cartridges, such as variants of the Heckler & Koch AG36 under-barrel grenade launcher, which are in service with U.K. and U.S. forces, among others, is necessary to employ them. Some older launchers, most notably the very popular American-made M203, can only accommodate relatively short 40mm rounds.

Crown Copyright

A British Army soldier holds an L85 assault rifle equipped with a variant of the Heckler & Koch AG36 40mm under-barrel grenade launcher.

The Drone40 can also be deployed by hand, as was demonstrated during the British Army’s MRX in 2020, as seen in the video below. Its design would mean that, regardless of the employment method, troops could carry them in web gear intended to carry standard 40mm grenades.

While Drone40s configured with the video camera payload were shown in videos from the MRX, it’s not clear if British troops in Mali have received any other types. DefendTex says that payload can be readily swapped in the field and that when fitted with the cameras, the drones can be recovered and reused.

The feed from Drone40s equipped with the cameras is transmitted back to the operator via a line-of-sight link and is on a hand-held tablet-like device. This is also how the drone’s movements are controlled after launch, via a GPS-enabled navigation system.

The camera configuration by itself would be an obvious boon for troops, especially those operating in small units. Drone40s with these payloads offer a way to scout ahead for enemy forces or other hazards, especially in areas full of natural or man-made cover, such as dense urban environments.

In addition, though, DefendTex offers high-explosive and anti-armor warhead options, as well as smoke and less-than-lethal flash-bang payloads. There is also an option to fit the drones with small electronic warfare jammers or laser designators to mark targets.

DefendTex

The official Drone40 product sheet from DefendTex.

These other payloads would give units equipped with Drone40s a host of other capabilities. Friendly units safely behind cover could send out armed examples to fly over enemy positions and launch attacks from above. They could also deploy smoke screens to shield their movements or jam enemy communications systems or sensors to confuse or disorient them. Laser pointer-equipped types could paint targets for other units to engage with precision-guided munitions.

On top of all this, DefendTex says that Drone40s can operate together as at least semi-autonomous swarms after launch. They also offer was it described as multiple round simultaneous impact (MSRI) capabilities.

What this means is that a single individual could fire multiple Drone40s with kinetic payloads and then they could be directed to fly to a designated point, after which they would all drop at the same time. With a mix of different warhead types, this could allow for more effective engagement of complex and dispersed targets all at once, such as troops standing in the open near light armored vehicles.

Combined with a camera-equipped type, the Drone40s could act as loitering munitions, hovering over a certain area, waiting for targets to emerge, and then being directed to engage them when they do. DefendTex says that the unmanned aircraft have a range of at least 12 miles and can remain airborne for 30 to 60 minutes, all depending on what type of payloads they’re carrying. Of course, line-of-sight restrictions exist for the command links between the operator and the drones, but it may be possible to use another drone to work as a relay.

For British troops in Mali, who are tasked with conducting patrols over broad areas in a region where various militant groups are very active, the benefits of just having small drones to provide additional immediate situational awareness are obvious. If they have received other types of payloads for their Drone40s beyond the camera package, it could provide them with an additional means of engaging enemies in the event of an ambush or any other kind of firefight.

For these exact reasons, very small so-called nano-drones are becoming increasingly popular among military forces around the world. Interestingly, the U.K. armed forces had previously employed early versions of the Black Hornet, a tiny hand-launched drone helicopter, in Afghanistan, starting in 2012, before withdrawing them from service in favor of larger individually-launched types sometime between 2016 and 2017. You can read more about the Black Hornet, variants of which are now in service in almost 20 different countries, in this past War Zone piece.

The Drone40 is also not the only drone intended to be launched from a 40mm grenade launcher presently on the market. The U.S. Army evaluated another type, Skyborne Technologies’ Cerberus GL, during its annual Army Expeditionary Warfare Experiment AEWE in 2019. It’s interesting to note that Skyborne Technologies is also based in Australia.

Last year, researchers at the Army Research Laboratory (ARL) filed a patent on another camera-equipped 40mm drone design, known simply as the Grenade Launched Unmanned Aerial System (GLUAS). That unmanned aircraft can remain aloft for up to 90 minutes, but has a maximum range of just over one mile, indicating that it may be slower than the Drone40 and more limited in range in terms of its command and control interface options.

US Army

A rendering of the US Army-developed Grenade Launched Unmanned Aerial System (GLUAS) drone.

All told, the British Army’s fielding of the Drone40, even in limited numbers with forces in Mali, is another example of how drones and other unmanned capabilities are only becoming more and more ubiquitous, including at the very lowest operational levels, among military forces around the world.

Source: British Troops Get Small Swarming Drones They Can Fire From 40mm Grenade Launchers

How to Restore Recently Deleted Instagram Posts – because deleted means: stored somewhere you can’t get at them

Instagram is adding a new “Recently deleted” folder to the app’s menu that temporarily stores posts after you remove them from your profile or archive, giving you the ability to restore deleted posts if you change your mind.

The folder includes sections for photos, IGTV, Reels, and Stories posts. No one else can see your recently deleted posts, but as long as a photo or video is still in the folder, it can be restored. Regular photos, IGTV videos, and Reels remain in the folder for up to 30 days, after which they’re gone forever. Stories stick around for up to 24 hours before they’re permanently removed, but you can still access them in your Stories archive.

[…]

Source: How to Restore Recently Deleted Instagram Posts

It’s nice how they’re framing the fact that they don’t delete your data as a “feature”

Amazon Plans to Install Creepy Always-On Surveillance Cameras in Delivery Vans

Not content to only wield its creepy surveillance infrastructure against warehouse workers and employees considering unionization, Amazon is reportedly gearing up to install perpetually-on cameras inside its fleet of delivery vehicles as well.

A new report from The Information claims that Amazon recently shared the plans in an instructional video sent out to the contractor workers who drive the Amazon-branded delivery vans.

In the video, the company reportedly explains to drivers that the high-tech video cameras will use artificial intelligence to determine when drivers are engaging in risky behavior, and will give out verbal warnings including “Distracted driving,” “No stop detected” and “Please slow down.”

According to a video posted to Vimeo a week ago, the hardware and software for the cameras will be provided through a partnership with California-based company Netradyne, which is also responsible for a platform called Driveri that similarly uses artificial intelligence to analyze a driver’s behavior as they operate a vehicle.

While the camera’s automated feedback will be immediate, other data will also reportedly be stored for later analysis that will help the company to evaluate its fleet of drivers.

Although it’s not clear when Amazon plans to install the cameras or how many of the vehicles in the company’s massive fleet will be outfitted with them, the company told The Information in a statement that the software will be implemented in the spirit of increasing safety precautions and not, you know, bolstering an insidious and growing surveillance apparatus.

Source: Amazon Plans to Install Always-On Surveillance Cameras in Delivery Vans

These 3D-Printed Fish Bots Can Swarm and School

Researchers have made a smart school of robotic fish that swarm and swim just like the real deal, and they offer promising insights into how developers can improve decentralized, autonomous operations for other gizmos like self-driving vehicles and robotic space explorers. Also, they’re just pretty stinking cute.

These seven 3D-printed robots, or Bluebots, can synchronize their movements to swim in a group, or Blueswarm, without any outside control, per research published in Science Robotics this month from the Harvard John A. Paulson School of Engineering and Applied Sciences and the Wyss Institute for Biologically Inspired Engineering.

Equipped with two wide-angle cameras for eyes, each bot navigates their tank by tracking the LEDs lights on their peers. Based on the cues they observe, each robot reacts accordingly using an onboard Raspberry Pi computer and custom algorithm to gauge distance, direction, and heading.

“Each Bluebot implicitly reacts to its neighbors’ positions,” explains Florian Berlinger, a PhD candidate at SEAS and Wyss and first author of the research paper, per a press release. “So, if we want the robots to aggregate, then each Bluebot will calculate the position of each of its neighbors and move towards the center. If we want the robots to disperse, the Bluebots do the opposite. If we want them to swim as a school in a circle, they are programmed to follow lights directly in front of them in a clockwise direction.”

Previous robotic swarms could navigate in two-dimensional spaces, but operating in three-dimensional spaces like air or water has proven tricky. The goal of this research was to create a robofish swarm that could move in sync all on their own without the need for WiFi or GPS and without input from their human handlers.

Source: These 3D-Printed Fish Bots Can Swarm and School

Synology to enforce use of validated disks in enterprise NAS boxes. And guess what? Only its own disks exceed 4TB

Synology has introduced its first-ever list of validated disks and won’t allow other devices into its enterprise-class NAS devices. And in a colossal coincidence, half of the disks allowed into its devices – and the only ones larger than 4TB – are Synology’s very own HAT 5300 disks that it launched last week.

Seeing as privately held Synology is thought to have annual revenue of around US$350m, rather less than the kind of cash required to get into the hard disk business, The Register inquired if it had really started making drives or found some other way into the industry.

The Taiwanese network-attached-storage vendor told us the drives are Synology-branded Toshiba kit, though it has written its own drive firmware and that the code delivers sequential read performance 23 per cent beyond comparable drives. Synology told us its branded disks will also be more reliable because they have undergone extensive testing in the company’s own NAS arrays.

[…]

So to cut a long story short, if you want to get the most out of Synology NAS devices, you’ll need to buy Synology’s own SATA hard disk drives.

The new policy applies as of the release of three new Synology NAS appliances intended for enterprise use and will be applied to other models over time.

The new models include the RS3621RPxs, which sports an unspecified six-core Intel Xeon processor and can handle a dozen drives, then move data over four gigabit Ethernet ports. The middle-of-the-road RS3621xs+ offers an eight-core Xeon and adds two 10GE ports. At the top of the range, the RS4021xs+ stretches to 3U and adds 16GB of RAM, eight more than found in the other two models.

[…]

Source: Synology to enforce use of validated disks in enterprise NAS boxes. And guess what? Only its own disks exceed 4TB • The Register

I guess HDD vendor lock in is a really really good reason to not buy Synology then.

Jeff Bezos To Step Down as Amazon CEO, Andy Jassy AWS Boss to succeed

Amazon announced on Tuesday that AWS CEO Andy Jassy will replace Jeff Bezos as CEO during the third quarter of this year. Bezos will transition to executive chair of Amazon’s board. In a statement, Bezos said: I’m excited to announce that this Q3 I’ll transition to Executive Chair of the Amazon Board and Andy Jassy will become CEO. In the Exec Chair role, I intend to focus my energies and attention on new products and early initiatives. Andy is well known inside the company and has been at Amazon almost as long as I have. He will be an outstanding leader, and he has my full confidence. This journey began some 27 years ago. Amazon was only an idea, and it had no name. The question I was asked most frequently at that time was, “What’s the internet?” Blessedly, I haven’t had to explain that in a long while. Today, we employ 1.3 million talented, dedicated people, serve hundreds of millions of customers and businesses, and are widely recognized as one of the most successful companies in the world. How did that happen? Invention. Invention is the root of our success. We’ve done crazy things together, and then made them normal. We pioneered customer reviews, 1-Click, personalized recommendations, Prime’s insanely-fast shipping, Just Walk Out shopping, the Climate Pledge, Kindle, Alexa, marketplace, infrastructure cloud computing, Career Choice, and much more. If you get it right, a few years after a surprising invention, the new thing has become normal. People yawn. And that yawn is the greatest compliment an inventor can receive.

Source: Jeff Bezos To Step Down as Amazon CEO – Slashdot

Musk see: Watch SpaceX’s latest Starship rocket explode while trying to touch down • The Register

The latest prototype of SpaceX’s Starship rocket, the SN9, burst into flames as the vehicle attempted to land on Earth on Tuesday.

All eyes were on the craft after its predecessor, the SN8, exploded during touchdown in December in Boca Chica, Texas. You can watch today’s detonation in the video below. The accident occurs after six minutes into the flight (skip to 11:51 to see it burst into flames).

Like the previous launch, SN9 was also a high-altitude flight test. The vehicle got ten kilometres (32,800 feet) into the sky before shifting to a near-horizontal position to descend but, unfortunately, it exploded in the air before it could flip the right way up and touch down.

spacex

Let’s just say not an ideal landing … the SN9’s explosion Source: SpaceX. Click to enlarge

It’s not clear what caused the rapid unscheduled disassembly this time. It’s possible the rocket suffered the same mishap as SN8, considering how similar both launches unfolded. SpaceX CEO Elon Musk blamed SN8’s blowout on low pressure in the rocket’s fuel tank that caused it to meet the ground at a faster-than-desired velocity.

Rules? Pah

It has also emerged SpaceX asked the FAA for a waiver to exceed the limits of US federal public safety regulations during the SN8 launch. The regulator declined to issue the waiver, and SpaceX went ahead anyway with the fateful experiment.

As a result of that non-compliance, as the FAA put it, the agency demanded SpaceX carry out an investigation of the explosion and make changes to its public safety procedures in light of the failure. Those changes were approved by the regulator this week, and SpaceX was thus permitted to launch its SN9 craft.

[…]

 

Source: Musk see: Watch SpaceX’s latest Starship rocket explode while trying to touch down • The Register

wouldn’t be too happy getting on Musk’s rockets

Air Force Says KC-46 Is A “Lemon” That It’s Trying To Make Lemonade Out Of

The U.S. Air Force has described its bedeviled KC-46A Pegasus tanker as a “lemon,” amid ongoing problems that prevent it from performing its primary aerial refueling mission on a day-to-day basis. Now the Air Force is trying to find other ways to make use of these aircraft, of which it has already received 42 examples located at four operating bases.With deliveries set to continue at a rate of two aircraft per month, the service is now looking to put the Pegasus to work by fast-tracking at least some of the aircraft already delivered into “limited operations,” but probably not involving its core mission set of aerial refueling. Nevertheless, the move could enable the Pegasus to at least provide some utility during real-world operations as the Air Force counts down to the declaration of full operational capability, which won’t happen until late 2023 or 2024 at the earliest.U.S. Air Force/Louis BrisceseA KC-46A Pegasus arrives at Travis Air Force Base, California, in March 2017.“As I look over the 10 years, I have to say… right now where we’re at in the program is we’re making lemonade out of lemons,” General Jacqueline Van Ovost, the head of Air Mobility Command, told members of the press, as reported by the Defense One website. The embarrassing setbacks that have become an all-too-familiar aspect of the next-generation tanker program were also highlighted yesterday in an unusually candid tweet from the U.S. Transportation Command (USTRANSCOM), which admitted that problems with the tanker put “America’s ability to effectively execute day-to-day operations and war plans at risk.”

Source: Air Force Says KC-46 Is A “Lemon” That It’s Trying To Make Lemonade Out Of

Tesla Claims Failing Touchscreens in 135000 car NHTSA Recall Were Only Meant to Last 5-6 Years Anyway

his week, Tesla finally gave in to the National Highway Traffic Safety Administration’s request to recall its Model S sedans and Model X SUVs over flash memory failures that will cause the cars’ signature 17-inch portrait-oriented central touchscreens to fail after a certain length of time—but not without pushback on the very definition of the word “defect,” according to a letter from Tesla’s legal department made public today.

Addressing federal regulators, Tesla Vice President of Legal Al Prescott made the case that the touchscreen failures didn’t constitute a defect worthy of a recall because the parts were only expected to last five to six years in the first place, which is certainly a novel strategy.

[…]

“[The eMMC flash memory] is inherently subject to wear, has a finite life (as NHTSA itself acknowledges), and may need replacement during the useful life of the vehicle…While the wear rate is heavily influenced by the active use of the center display system, even more so when the vehicle is in drive or charging, given a reasonable average daily use of 1.4 cycles, the expected life would be 5-6 years. NHTSA has not presented any evidence to suggest that this expected life is outside industry norms.”

Further, Prescott argued that it was wrong for the NHTSA to assert that the touchscreen “should last at least the useful life of the vehicle, essentially double its expected lifespan.” The fact that the average age of vehicles on U.S. roads hit an all-time high of 11.6 years in 2020, per CNBC.

He went on to call the eMMC “state of the art” for the time when it was designed and claimed the NHTSA’s regulations around defective parts were “anachronistic,” pushing back further on the NHTSA’s lifespan expectations

[…]

The fact that the flash memory device was only rated to handle half the lifespan of the average vehicle on the road raises numerous questions around new vehicles’ technology and planned obsolescence. If this was only expected to last five or six years, what else on the roads could fail earlier than consumers expect?

As the Washington Post notes, the way in which Teslas’ high-tech components wear could have dire consequences on the vehicles’ resale value. Unless there’s a way to recycle and reuse these throwaway components, the disposable nature of them could also leave a bad taste in eco-conscious consumers’ mouths.

Furthermore, why should consumers be expected to think that an internal component that’s required to access key safety features of the car should be a wear item? While Tesla has since added alerts that warn owners of a pending eMMC failure, a processor embedded in the internal components of a car isn’t something you can easily check on like a set of brake pads or tires, nor is it something that most consumers know to watch out for after so many miles of use.

The recall includes 134,951 Model S and Model X cars, making it Tesla’s biggest recall to date. It encompasses 2012 through 2018 Model S sedans as well as 2016 through 2018 Model X crossovers. This is fewer than the 158,000 cars requested by the NHTSA for recall, as Tesla excluded the vehicles that have already had memory upgrades or touchscreen replacements, reports the Washington Post.

Failures of the recalled memory chips are not the only issues that have dogged Model S and Model X touchscreens. Tesla CEO Elon Musk once bragged about sourcing the then-groundbreaking 17-inch screens outside of the usual automotive supply chain to save costs. Unfortunately, the screens weren’t built to handle the vibration loads and temperature fluctuations found in a car’s interior, causing them to prematurely yellow, bubble and even leak.

Source: Tesla Claims Failing Touchscreens in NHTSA Recall Were Only Meant to Last 5-6 Years Anyway

Wow, you really do get a piece of shit for buying a car from the most valuable car company in the world. Whilst Toyota has just stolen the crown from VW for selling the most cars per year.

CNBC, others tell you redditors want to pump SLV, others. They don’t. SLV is owned by Citadel, the people redditors hate. It’s only about GME, AMC, BB.

Below is from the CNBC website. SLV spiked yesterday and some people will have you believe it’s the Gamestop buying and holding redditors from wallstreetbets that are pushing it. They are not. SLV is being pushed up by Capital Investments, the people the redditors are trying to destroy.

Below is a list of stories from CNBC – explicitly saying that redditors are going after this.

It doesn’t take much in the way of research to find out that this is nonsense:

https://www.reddit.com/r/wallstreetbets/search?q=slv&restrict_sr=1

Just search the wallstreetbets subreddit, which is where the GME holders are concentrated

You will see loads of bots with almost no posts mentioning to buy SLV, NOC and others with people deriding them. But the main theme is absolutely to stay away from them and to hold GME, BB and AMC

For a good list of people running the redditors pursuing SLV misinformation (and thus in the pockets of the hedge funds), check out this reddit thread

Diamondhands GME! Hold that stonk!

Google side with Hedge funds, wipes Play Store reviews of RobinHood by pissed off GameStop traders

Google has removed a wave of negative reviews of popular stock-market trading apps targeted by furious investors.

Platforms such as Robinhood have been hit after preventing independent traders buying GameStop and AMC shares.

Users of a Reddit message board had managed to upset the market by buying the shares and inflating their value, hitting established hedge funds.

Many online traders, feeling betrayed by Robinhood’s restrictions, have hit back with critical reviews of the app.

Google has removed tens of thousands of one-star reviews for the widely-used trading app – which had previously had a four-star average.

It says it takes action when it sees “fake ratings”, designed to manipulate a product’s average score.

But more one-star ratings – the minimum possible – have continued to appear.

While Robinhood stopped independent users from buying some shares after the surge in investment by independent traders, they still remained available to large, professional traders elsewhere- leading to accusations that Robinhood was effectively protecting big investors and manipulating the stock market.

Robinhood said that the restrictions were put in place for “risk-management” reasons – and not because it had been told to limit activity by anyone else.

But as first reported by 9to5Google, it prompted a co-ordinated campaign to hit the app with a barrage of one-star reviews.

The site reported that more than 100,000 negative reviews had brought the average rating from four stars down to just one.

Hours later, Google intervened to delete roughly 100,000 reviews, according to the review counter, restoring the app’s high rating.

A selection of three one-star reviews pulled from the Google Play Storeimage copyrightGoogle Play

Google rules are designed to prevent so-called “review bombing” – when reviewers co-ordinate to drag down an app’s rating, usually because of some external scandal or political disagreement.

It has not yet responded to requests to comment on its Play Store decision.

‘Unacceptable’

While there had been calls on social media to review Robinhood negatively, many investors feel they have a legitimate grievance.

Some users of the Reddit WallStreetBets community, which is at the centre of the movement, believe they are taking a principled stance against hedge funds short-selling the stocks, hoping the company will fail.

The concern is also reflected by some major US politicians from both parties.

The BBC is not responsible for the content of external sites.View original tweet on Twitter

Democrat congresswoman Alexandria Ocasio-Cortez has said Congress should investigate Robinhood, calling the app’s decision to block small traders “unacceptable”.

Her long-time political enemy, Republican Ted Cruz, tweeted that he fully agreed, as did entrepreneur Elon Musk.

Within hours, Senator Sherrod Brown – who runs the Senate Banking Committee – said he planned to hold a hearing on the current state of the US stock market.

“People on Wall Street only care about the rules when they’re the ones getting hurt,” he said.

Source: Google halts Play Store ‘review bombing’ by GameStop traders – BBC News

Let’s be clear – these guys have a very legitimate grievance with RobinHood.

ProtonMail, Tutanota among authors of letter urging EU to reconsider encryption rules

Encrypted service providers are urging lawmakers to back away from a controversial plan that critics say would undercut effective data protection measures.

ProtonMail, Threema, Tresorit and Tutanota — all European companies that offer some form of encrypted services — issued a joint statement this week declaring that a resolution the European Council adopted on Dec. 14 is ill-advised. That measure calls for “security through encryption and security despite encryption,” which technologists have interpreted as a threat to end-to-end encryption. In recent months governments around the world, including the U.S., U.K., Australia, New Zealand, Canada, India and Japan, have been reigniting conversations about law enforcement officials’ interest in bypassing encryption, as they have sporadically done for years.

In a letter that will be sent to council members on Thursday, the authors write that the council’s stated goal of endorsing encryption, and the council’s argument that law enforcement authorities must rely on accessing electronic evidence “despite encryption,” contradict one another. The advancement of legislation that forces technology companies to guarantee police investigators a way to intercept user messages, for instance, repeatedly has been scrutinized by technology leaders who argue there is no way to stop such a tool from being abused.

The resolution “will threaten the basic rights of millions of Europeans and undermine a global shift towards adopting end-to-end encryption,” say the companies, which offer users either encrypted email, file-sharing or messaging.

“[E]ncryption is an absolute, data is either encrypted or it isn’t, users have privacy or they don’t,” the letter, which was shared with CyberScoop in advance, states. “The desire to give law enforcement more tools to fight crime is obviously understandable. But the proposals are the digital equivalent of giving law enforcement a key to every citizens’ home and might begin a slippery slope towards greater violations of personal privacy.”

[…]

Source: ProtonMail, Tutanota among authors of letter urging EU to reconsider encryption rules

Robinhood, TD Ameritrade restrict buying of GameStop, AMC stock – shorters continue game, killing pumpers. Reps + Dems agree market manipulation. The shorters are big customers and are reloading their short positions.

GameStop’s stock has continued to make big moves, briefly crossing $450 a share on Thursday, fueled by Reddit users collectively taking on the Wall Street establishment. But individual investors looking to make trades have faced multiple issues on trading sites and apps over recent days, with many experiencing service disruptions, according to Bloomberg. The frenzy over GameStop stock has led to TD Ameritrade restricting certain trades, while Robinhood froze any new purchases of particular stocks (GameStop and AMC, among others). It also led to the Wall Street Bets subreddit temporarily getting locked and a Discord server getting shut down for violating terms of service. Watch this: What does GameStop’s skyrocketing stock have to do with…10:15On Thursday morning, Twitter users began posting screenshots of their Robinhood app that showed a message appended to the stocks of GameStop, AMC, Nokia and Bed, Bath and Beyond: “This stock is not supported on Robinhood.”Editors’ top picksSubscribe to CNET Now for the day’s most interesting reviews, news stories and videos.Yes, I also want to receive the CNET Insider newsletter, keeping me up to date with all things CNET.By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.Robinhood explained the move in a blog post Thursday morning, just before the stock exchanges opened: “In light of recent volatility, we are restricting transactions for certain securities to position closing only, including $AMC, $BB, $BBBY, $EXPR, $GME, $KOSS, $NAKD and $NOK.”The @wsbmod Twitter account (which is tied to the Wall Street Bets subreddit community driving recent trades), responded in a tweet: “Individual investors are being stripped of their ability to trade on [the Robinhood app]. Meanwhile, hedge funds and institutional investors can continue to trade as normal.”

Source: Robinhood, TD Ameritrade restrict trading of GameStop, AMC stock – CNET

Here comes the slander: Discord Bans r/WallStreetBets For Hate Speech Violations

After kicking off a historic rally around GameStop stock that has incited the ire of hedge fund tycoons and the SEC, the r/wallstreetbets channel was banned from Discord on Wednesday over apparent hate speech violations.

While some on Reddit were quick to speculate that the server had been taken down by hackers as part of a covert attempt to disrupt their push to drive the stock’s price higher, a Discord spokesperson told Gizmodo that the channel had been banned “for continuing to allow hateful and discriminatory content after repeated warnings.” On both Discord and Reddit, wallstreetbets users frequently refer to themselves collectively as “retards” and “autists,” and have been known to deploy the kinds of racial slurs and deliberately offensive language that have become commonplace in 4chan-style posting forums.

This is slightly disengenious at the very least. Just saying “shit” somewhere puts you in this category.

Here’s the full statement from Discord:

The server has been on our Trust & Safety team’s radar for some time due to occasional content that violates our Community Guidelines, including hate speech, glorifying violence, and spreading misinformation. Over the past few months, we have issued multiple warnings to the server admin.

Today, we decided to remove the server and its owner from Discord for continuing to allow hateful and discriminatory content after repeated warnings.

To be clear, we did not ban this server due to financial fraud related to GameStop or other stocks. Discord welcomes a broad variety of personal finance discussions, from investment clubs and day traders to college students and professional financial advisors. We are monitoring this situation and in the event there are allegations of illegal activities, we will cooperate with authorities as appropriate.

Moments after confirmation of the Discord ban surfaced online, the official r/wallstreetbets subreddit was set to private by its moderators, but has since been made public again. In a new post, moderators for r/wallstreetbets argued that the staggering growth of the community in just a few days’ time had made moderating it effectively impossible, and blamed Discord and Reddit’s software for any shortcomings in cracking down on offensive language.

Source: Discord Bans r/WallStreetBets For Hate Speech Violations

Note there is no statement from anyone from wallstreetbets. I recommend you read the  reddit yourself.

Very poor reporting, Gizmodo.

Solar material can ‘self-heal’ imperfections, new research shows

A material that can be used in technologies such as solar power has been found to self-heal, a new study shows.The findings—from the University of York—raise the prospect that it may be possible to engineer high-performance self-healing materials which could reduce costs and improve scalability, researchers say.The substance, called antimony selenide (Sb2Se3), is a solar absorber material that can be used for turning light energy into electricity.Professor Keith McKenna from the Department of Physics said: “The process by which this semi-conducting material self-heals is rather like how a salamander is able to re-grow limbs when one is severed. Antimony selenide repairs broken bonds created when it is cleaved by forming new ones.

Source: Solar material can ‘self-heal’ imperfections, new research shows

Firefox 85 removes support for Flash and adds protection against supercookies

Mozilla has released Firefox 85 ending support for Adobe Flash Player plugin and has brought in ways to block supercookies to enhance a user’s privacy. Mozilla, in a blog post, noted that supercookies are store user identifiers, and are much more difficult to delete and block. It further noted that the changes it is making through network partitioning in Firefox 85 will “reduce the effectiveness of cache-based supercookies by eliminating a tracker’s ability to use them across websites.”

“Trackers can abuse caches to create supercookies and can use connection identifiers to track users. But by isolating caches and network connections to the website they were created on, we make them useless for cross-site tracking,” Mozilla noted.

It explained that the network partitioning works by splitting the Firefox browser cache on a per-website basis, a technical solution that prevents websites from tracking users as they move across the web. Mozilla also noted that by removing support for Flash, there was not much impact on the page load time. The development was first reported by ZDNet.

[…]

Source: Firefox 85 removes support for Flash and adds protection against supercookies – Technology News

Update Your iPhone and iPad Right Now

Do you have an iPhone or iPad? You should update your device right now to iOS 14.4. No, not later today or after lunch or whatever. Update now.Why is it so crucial to update your iOS software as soon as possible? As TechCrunch first reported, Apple is reporting three security vulnerabilities that “may have been actively exploited” by hackers.We don’t have any real details yet, but Apple rarely has to admit such stunning vulnerabilities. The researchers who reported the security flaws have been granted anonymity by Apple.As Apple explains: Kernel Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited. Description: A race condition was addressed with improved locking. CVE-2021-1782: an anonymous researcher WebKit Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. Description: A logic issue was addressed with improved restrictions. CVE-2021-1871: an anonymous researcher CVE-2021-1870: an anonymous researcher

Source: Update Your iPhone and iPad Right Now

Decade-old bug in Linux world’s sudo can be abused by any logged-in user to gain root privileges

Security researchers from Qualys have identified a critical heap buffer overflow vulnerability in sudo that can be exploited by rogue users to take over the host system.

Sudo is an open-source command-line utility widely used on Linux and other Unix-flavored operating systems. It is designed to give selected, trusted users administrative control when needed.

The bug (CVE-2021-3156) found by Qualys, though, allows any local user to gain root-level access on a vulnerable host in its default configuration. Qualys is disclosing its findings in a coordinated release with operating systems vendors, and has bestowed the errant code with the memorable name of the mythical mischief-maker Baron Samedi.

The following versions of sudo are affected: 1.8.2 through 1.8.31p2 and 1.9.0 through 1.9.5p1. Qualys developed exploits for several Linux distributions, including Ubuntu 20.04 (Sudo 1.8.31), Debian 10 (Sudo 1.8.27), and Fedora 33 (Sudo 1.9.2), and the security biz believes other distributions are vulnerable, too.

Ubuntu and Red Hat have already published patches, and your distro may have as well, so get to it.

In their write-up, Qualys researchers explain, “set_cmnd() is vulnerable to a heap-based buffer overflow, because the out-of-bounds characters that are copied to the ‘user_args’ buffer were not included in its size.”

[…]

The bug was introduced in July 2011 (commit 8255ed69) and has persisted unfixed until now.

[…]

Source: Decade-old bug in Linux world’s sudo can be abused by any logged-in user to gain root privileges • The Register

Fedora’s Chromium maintainer suggests switching to Firefox as Google yanks features in favour of Chrome

Fedora’s maintainer for the open-source Chromium browser package is recommending users consider switching to Firefox following Google’s decision to remove functionality and make it exclusive to its proprietary Chrome browser.The comments refer to a low-key statement Google made just before the release of Chrome 88, saying that during an audit it had “discovered that some third-party Chromium-based browsers were able to integrate Google features, such as Chrome sync and Click to Call, that are only intended for Google’s use… we are limiting access to our private Chrome APIs starting on March 15, 2021.”Tom Callaway (aka “spot”), a former Fedora engineering manager at Red Hat (Fedora is Red Hat’s bleeding-edge Linux distro), who now works for AWS, remarked when describing the Chromium 88 build that: “Google gave the builders of distribution Chromium packages these access rights back in 2013 via API keys, specifically so that we could have open-source builds of Chromium with (near) feature parity to Chrome. And now they’re taking it away.”The reasoning given for this change? Google does not want users to be able to ‘access their personal Chrome Sync data (such as bookmarks)… with a non-Google, Chromium-based browser.’ They’re not closing a security hole, they’re just requiring that everyone use Chrome.”Features in Chromium like data sync depend on Google APIs which are soon to be blockedFeatures in Chromium like data sync depend on Google APIs which are soon to be blockedCallaway predicted that “many (most?) users will be confused/annoyed when API functionality like sync and geolocation stops working for no good reason.” Although API access is not yet blocked, he has disabled it immediately to avoid users experiencing features that suddenly stop working for no apparent reason.He said he is no longer sure of the value of Chromium. “I would say that you might want to reconsider whether you want to use Chromium or not. If you want the full ‘Google’ experience, you can run the proprietary Chrome. If you want to use a FOSS browser that isn’t hobbled, there is a Firefox package in Fedora,” he said.Ahem, just ‘discovered’ this?There is more information about these APIs on the Chromium wiki. Access to the APIs is documented and Google’s claim that it has only just “discovered” this is an oddity. The APIs cover areas including sync, spelling, translation, Google Maps geolocation, Google Cloud Storage, safe browsing, and more.The situation has parallels with Android, where the Android Open Source Project (AOSP) is hard to use as a mobile phone operating system because important functions are reserved for the proprietary Google Play Services. The microG project exists specifically as an attempt to mitigate the absence of these APIs from AOSP.Something similar may now be necessary for Chromium if it is to deliver all the features users have come to expect from a web browser. It is not a problem for companies in a position to provide their own alternative services, such as Microsoft with Chromium-based Edge, but more difficult for Linux distros like Fedora.There are other ways to look at Google’s move, though. “Some people might even consider the removal of this Google-specific functionality an improvement,” commented a Fedora user. Microsoft reportedly removed more than 50 Google-specific services from Chromium as used in Edge, including data sync, safe browsing, maps geolocation, the Google Drive API, and more.Users who choose Chromium over Chrome to avoid Google dependency may not realise the extent of this integration, which is likely now to reduce. The Ungoogled Chromium project not only removes Google APIs but also “blocks internal requests to Google at runtime” as a failsafe measure.

Source: Fedora’s Chromium maintainer suggests switching to Firefox as Google yanks features in favour of Chrome • The Register

Apple hit with another European class action over throttled iPhones

A third class action lawsuit has been filed in Europe against Apple seeking compensation — for what Italy’s Altroconsumo consumer protection agency dubs “planned obsolescence” of a number of iPhone 6 models.The action relates to performance throttling Apple applied several years ago to affected iPhones when the health of the device’s battery had deteriorated — doing so without clearly informing users. It later apologized.The class action suit in Italy is seeking €60 million in compensation — based on at least €60 in average compensation per iPhone owner. Affected devices named in the suit are the iPhone 6, 6s, 6 Plus and 6s Plus, per a press release put out by the umbrella consumer organization Euroconsumers, which counts Altroconsumo as a member.The suit is the third to be filed in the region over the issue — following suits filed in Belgium and Spain last month.A fourth — in Portugal — is slated to be filed shortly.The tech giant settled similar charges in the U.S. last year — where it was accused of intentionally slowing down the performance of older iPhones to encourage customers to buy newer models or fresh batteries — shelling out $500 million, or around $25 per phone, to settle that case (while denying any wrongdoing).“When consumers buy Apple iPhones, they expect sustainable quality products. Unfortunately, that is not what happened with the iPhone 6 series. Not only were consumers defrauded, and did they have to face frustration and financial harm, from an environmental point of view it is also utterly irresponsible,” said Els Bruggeman, Euroconsumers’ head of policy and enforcement, in a statement.

Source: Apple hit with another European class action over throttled iPhones | TechCrunch

Dutch COVID-19 patient and testing data sold on the criminal underground

Dutch police have arrested two individuals on Friday for allegedly selling data from the Dutch health ministry’s COVID-19 systems on the criminal underground.

The arrests came after an investigation by RTL Nieuws reporter Daniel Verlaan who discovered ads for Dutch citizen data online, advertised on instant messaging apps like Telegram, Snapchat, and Wickr.

The ads consisted of photos of computer screens listing data of one or more Dutch citizens.

The reporter said he tracked down the screengrabs to two IT systems used by the Dutch Municipal Health Service (GGD) — namely CoronIT, which contains details about Dutch citizens who took a COVID-19 test, and HPzone Light, one of the DDG’s contact-tracing systems.

Verlaan said the data had been sold online for months for prices ranging from €30 to €50 per person.

Buyers would receive details such as home addresses, emails, telephone numbers, dates of birth, and a person’s BSN identifier (Dutch social security number).

Two men arrested in Amsterdam within a day

In a press release today, Dutch police said they started an investigation last week when they learned of the ads and arrested two suspects within 24 hours of the complaint.

Both men were arrested in Amsterdam on Friday, and were identified as a 21-year-old man from the city of Heiloo and a 23-year-old man from the city of Alblasserdam. Their homes were also searched, and their computers seized, police said.

According to Verlaan, the two suspects worked in DDG call centers, where they had access to official Dutch government COVID-19 systems and databases.

Source: Dutch COVID-19 patient data sold on the criminal underground | ZDNet

It turns out you can buy searched subsets of the information, eg people from Amsterdam or search by name.

Millions of people – basically everyone who’d ever had a corona test – were affected.

Original sauce: Illegale handel in privégegevens miljoenen Nederlanders uit coronasystemen GGD (RTL news)

It also turns out that the GGD was warned repeatedly of their poor security measures over the years and nothing was done about it. Andre Rouwvoet, the boss of the GGD was also warned and says it’s one of those things that couldn’t be helped. This is simply not true. The most obvious questions are:

  1. Why wasn’t the data deleted after no longer being relevant (it’s kept  for traceability of other people exposed and so loses relevance after 10 – 14 days)
  2. Why could helpdesk people access all of this huge database?
  3. Why wasn’t there a system op alarms in place to shout out when people were bulk exporting data?

 

Myopia correcting ‘smart glasses’ from Japan to be sold in Asia – Snake Oil or …?

Can a pair of unique spectacles banish nearsightedness without surgical intervention? Japan’s Kubota Pharmaceutical Holdings says its wearable device can do just that, and it plans to start releasing the product in Asia, where many people grapple with myopia.

The device, which the company calls Kubota Glasses or smart glasses, is still being tested. It projects an image from the lens of the unit onto the wearer’s retina to correct the refractive error that causes nearsightedness. Wearing the device 60 to 90 minutes a day corrects myopia according to the Japanese company.

Kubota Pharmaceutical has not disclosed additional details on how the device works. Through further clinical trials, it is trying to determine how long the effect lasts after the user wears the device, and how many days in total the user must wear the device to achieve a permanent correction for nearsightedness.

[…]

Kubota began clinical trials on the device last July after confirming the therapeutic effect of the mechanism using a desktop system. It is also developing a contact lens-type myopia correction device.

Kubota, which made its debut on the Tokyo Stock Exchange’s Mothers market for startups in December 2016, develops drugs and devices for the treatment of vision problems.

Source: Myopia correcting ‘smart glasses’ from Japan to be sold in Asia – Nikkei Asia

A Telegram Bot Is Selling Stolen Facebook User Info (500m of them1) for $20 a Pop

The phone numbers (and corresponding site IDs) of some 500 million Facebook users now appear to be for sale on a dark web cybercrime forum.

The criminal or group of criminals responsible have constructed a Telegram bot to act as a search function for the data. Potential buyers can now use the bot to sift through the data to find phone numbers that correspond to user IDs—or vice versa—with the full information being unlocked after paying for query “credits.” Those credits start at $20 for a single search and get cheaper if bought in bulk.

The activity was discovered by Alon Gal, co-founder and CTO of cybersecurity firm Hudson Rock, who posted about the scheme on his Twitter account, and reported by Joseph Cox, at Motherboard.

An insecure Facebook server containing account information on millions of users appears to be the source of the data for sale here—though that vulnerability was discovered by researchers in 2019 and Facebook has since fixed it. Gal has claimed that the vulnerability was exploited to create “a database containing the information 533m users across all countries.” (For reasons unknown, the bot itself only claims to sell information for users in 19 countries.)

Source: A Telegram Bot Is Selling Stolen Facebook User Info for $20 a Pop

Yay centralised databases