The Linkielist

Linking ideas with the world

The Linkielist

BMW System Malfunction Takes Out Apple CarPlay, Tells Some Owners to Pay for It

BMW’s much-loathed idea to charge owners a subscription fee for Apple CarPlay in its 2019 and 2020 models strikes again, one year after BMW reversed that decision after considerable blowback. Some owners of those cars reported that Apple CarPlay would not work over the weekend, and some were even prompted to pay for the feature, Autoevolution reports.

Some features like CarPlay go through BMW ConnectedDrive Services, which allows users to pair devices, monitor their cars from afar and sign up for additional apps or services. It’s a customer portal, and that’s where some BMW owners whose CarPlay quit working encountered some confusing messages. Bacster007 on Reddit’s r/BMW explained:

I spoke with my sales rep at the dealership and verified issues are going on. Had me check the customer portal website which has the car and all the information/apps on it. It shows that I’m subscribed to CarPlay. He said for some people who lost the feature it shows that they have to pay for the app all of a sudden, and some like myself are still showing a valid subscription.

[…]

Source: BMW System Malfunction Takes Out Apple CarPlay, Tells Some Owners to Pay for It

Hackers are trying to disrupt the COVID-19 vaccine supply chain

Since the start of the coronavirus pandemic, we’ve seen hackers target efforts to develop a COVID-19 vaccine, but it now seems they’re shifting their attention to the supply chain that will distribute those vaccines to people across the world.

IBM says it recently uncovered a highly coordinated global phishing campaign focused on the companies and organizations involved with the upcoming “cold chain” distribution of COVID-19 vaccines. That’s the part of the supply network that ensures those vaccines stay cold enough so that they don’t go bad. It’s a critically important aspect of the two leading vaccine candidates from Pfizer and Moderna, as they need to be kept at minus 94 degrees Fahrenheit and minus 4 degrees Fahrenheit, respectively.

The hackers impersonated an executive with Haier Biomedical, a Chinese company that styles itself as “the world’s only complete cold chain provider.” They sent meticulously researched phishing emails that included an HTML attachment asking the recipient to input their credentials. They could have used that information later to gain access to sensitive networks.

The campaign, which IBM says has “the potential hallmarks” of a state-sponsored effort, cast a wide net. The company only named one target explicitly — the European Commission’s Directorate-General for Taxation and Customs Union — but said the campaign targeted at least 10 different organizations, including a dev shop that makes websites for pharmaceutical and biotech companies. The company doesn’t know if any of the attacks were ultimately successful in their goal.

[…]

Source: Hackers are trying to disrupt the COVID-19 vaccine supply chain | Engadget

Japan sticks the landing: Asteroid sample recovered from Hayabusa2 probe

Vids’n’pics Japanese and Australian astroboffins have successfully recovered samples taken from Asteroid Ryugu by the Hayabusa2 probe.

Hayabusa2 has had quite a ride and has more adventures ahead of it.

The probe launched in 2014 and spent three-and-a-half years travelling to near-Earth asteroid 162173 Ryugu, which has a diameter of about 1km and occasionally passes within 100,000km of the planet upon which you are (presumably) reading this story.

Hayabusa2 carried four rovers, one of which was used after the spacecraft shot a bullet at the asteroid to disturb its surface and stir up some matter to bring home in a sealed capsule designed to survive the rigours of re-entry to Earth’s atmosphere.

The probe bade farewell to Ryugu in November 2019 and early on Sunday morning, Australian time, the recovery capsule was spotted streaking across the sky as it made its way towards the Woomera prohibited area for a pre-dawn landing.

[…]

The capsule carried the samples from Ryugu, plus a radar-reflective parachute and a radio beacon designed to make it easier to find in the very hot, dry, and nasty conditions often found in the region.

As it happened, everything worked, and news of the capsule’s retrieval emerged before lunchtime.

[…]

Japan Aerospace Exploration Agency staff approached the capsule wearing protective gear and what looks like some trepidation.

Japanese space agency staff approach the returned sample capsule

Click to enlarge

Before long, the capsule becamse safe to handle and was popped into a shiny box.

The returned sample from Hayabusa2

The sample return capsule in its box.
Click to enlarge

The precious cargo was soon on its way to the facility established to handle the landing.

[…]

Another story we’ll have to wait for is news of Hayabusa2’s ongoing adventures, because the probe skipped off past Earth and has enough fuel aboard to line up a 2026 rendezvous with another asteroid, the mysteriously ruddy 2001 CC. Japan’s space agency has even contemplated a third asteroid visit, in 2030, and even a possible fly-by of Venus. As it flits about the inner solar system, the probe’s cameras will also be used for observations of exoplanets and other phenomena

Source: Japan sticks the landing: Asteroid sample recovered from Hayabusa2 probe • The Register

Data of 243 million Brazilians exposed online via govt website source code

The personal information of more than 243 million Brazilians, including alive and deceased, has been exposed online after web developers left the password for a crucial government database inside the source code of an official Brazilian Ministry of Health’s website for at least six months.

The security snafu was discovered by reporters from Brazilian newspaper Estadao, the same newspaper that last week discovered that a Sao Paolo hospital leaked personal and health information for more than 16 million Brazilian COVID-19 patients after an employee uploaded a spreadsheet with usernames, passwords, and access keys to sensitive government systems on GitHub.

Estadao reporters said they were inspired by a report filed in June by Brazilian NGO Open Knowledge Brasil (OKBR), which, at the time, reported that a similar government website also left exposed login information for another government database in the site’s source code.

Since a website’s source code can be accessed and reviewed by anyone pressing F12 inside their browser, Estadao reporters searched for similar issues in other government sites.

They found a similar leak in the source code of e-SUS-Notifica, a web portal where Brazilian citizens can sign up and receive official government notifications about the COVID-19 pandemic

[…]

Source: Data of 243 million Brazilians exposed online via website source code | ZDNet

Alphabet’s internet Loon balloon kept on station in the sky using AI that beat human-developed control code

Loon, known for its giant billowing broadband-beaming balloons, says it has figured out how to use machine-learning algorithms to keep its lofty vehicles hovering in place autonomously in the stratosphere.

The 15-metre-wide balloons relay internet connections between people’s homes and ground stations that could be thousands of kilometres apart. To form a steady network that can route data over long distances reliably, the balloons have to stay in place, and do so all by themselves.

Loon’s AI-based solution to this station-keeping problem has been described in a research paper published in Nature on Wednesday, and basically it works by adjusting the balloons’ altitude to catch the right wind currents to ensure they are where they need to be.

The machine-learning software, we’re told, managed to successfully keep the Loon gas bags bobbing up and down in the skies above in the Pacific Ocean in an experiment that lasted 39 days. Previously, the Loon team used a non-AI controller that used a handcrafted algorithm known as StationSeeker to do the job, though decided to experiment to see whether it could find a more efficient method using machine learning.

“As far as we know, this is the world’s first deployment of reinforcement learning in a production aerospace system,” said Loon CTO Salvatore Candido.

The AI is built out of a feed-forward neural network that learns to decide whether a balloon should fly up or go down by taking into account variables, such as wind speed, solar elevation, and how much power the equipment has left. The decision is then fed to a controller system to move the balloon in place.

By training the model in simulation, the neural network steadily improved over time using reinforcement learning as it repeated the same task over and over again under different scenarios. Loon tested the performance of StationSeeker against the reinforcement learning model in simulation.

“A trial consists of two simulated days of station-keeping at a fixed location, during which controllers receive inputs and emit commands at 3-min intervals,” according to the paper. The performance was then judged by how long the balloons could stay within a 50km radius of a hypothetical ground station.

The AI algorithm scored 55.1 per cent efficiency, compared to 40.5 per cent for StationSeeker. The researchers reckon that the autonomous algorithm is near optimum performance, considering that the best theoretical models reach somewhere between 56.8 to 68.7 per cent.

When Loon and Google ran the controller in the real experiment, which involved a balloon hovering above the Pacific Ocean, they found: “Overall, the [reinforcement learning] system kept balloons in range of the desired location more often while using less power… Using less power to steer the balloon means more power is available to connect people to the internet, information, and other people.”

[…]

Source: Alphabet’s internet Loon balloon kept on station in the sky using AI that beat human-developed control code • The Register

China’s first fully driverless robotaxis hit the streets of Shenzhen

Fully driverless robotaxis are now a practical reality on Chinese roads. AutoX has become the first company to put a fleet of the completely driver-free vehicles on the country’s streets, with the cars now roaming Shenzhen. They’re not yet available to the public, a spokesperson told TechCrunch, but it’s still a significant move.

AutoX claims this is possible thanks to a “5th generation” autonomous driving system that includes a pair of LiDAR sensors on the sides, “4D” radar sensors and thorough blind spot sensing. The robotaxis can react to even the smaller objects around them, and the company is touting a battle-tested platform that knows how to navigate everything from illegally-parked cars through to unprotected U-turns.

The firm’s machines have been in testing in other places, including California, but a “much larger number of road users” in China helped it rapidly refine its technology.

Self-driving taxis are still far from becoming ubiquitous. Regulations in the US and many other parts of the world have yet to adapt, and the cars themselves are unsurprisingly using exotic, expensive hardware. AutoX’s rollout is a large step forward, though, and it might just be a question of when you hop into an unoccupied taxi rather than “if.”

Source: China’s first fully driverless robotaxis hit the streets of Shenzhen | Engadget

The first phone with an under-display camera goes on sale December 21st

You won’t have to wait much longer to buy the first phone with an under-display camera — if you live in the right country. ZTE now plans to release the Axon 20 5G in 11 countries and regions on December 21st, including the UK, European Union, Japan and South Korea. The company didn’t reveal pricing, but said it would be available “soon.”

The centerpiece remains an uninterrupted 6.92-inch FHD+ OLED screen that uses a combination of materials, display syncing and a “special matrix” to hide a 32-megapixel selfie camera. You won’t find a cutout or notch here. It’s a thoroughly mid-range phone beyond that, though. The Axon 20 5G runs on a Snapdragon 765G chip with 8GB of RAM, and its stand-out features beyond the front camera include a 90Hz refresh rate and DTS:X Ultra 3D sound.

You can expect a 64MP main rear camera, an 8MP ultra-wide, a 2MP macro cam and a 2MP depth sensor. The 4,220mAh battery is also unspectacular given the size and 5G, although 30W fast charging should help it top up quickly.

5G, although 30W fast charging should help it top up quickly.

Source: The first phone with an under-display camera goes on sale December 21st | Engadget

Good stuff! I absolutely hate the cut out notch!

As if Productivity Score wasn’t creepy enough, Microsoft has patented tech for ‘meeting quality monitoring devices’ – PS is being defanged though

The slightly creepy “Productivity Score” may not be all that’s in store for Microsoft 365 users, judging by a trawl of Redmond’s patents.

One that has popped up recently concerns a “Meeting Insight Computing System“, spotted first by GeekWire, created to give meetings a quality score with a view to improving upcoming get-togethers.

It all sounds innocent enough until you read about the requirement for “quality parameters” to be collected from “meeting quality monitoring devices”, which might give some pause for thought.

Productivity Score relies on metrics captured within Microsoft 365 to assess how productive a company and its workers are. Metrics include the take-up of messaging platforms versus email. And though Microsoft has been quick to insist the motives behind the tech are pure, others have cast more of a jaundiced eye over the technology.

[…]

Meeting Insights would take things further by plugging data from a variety of devices into an algorithm in order to score the meeting. Sampling of environmental data such as air quality and the like is all well and good, but proposed sensors such as “a microphone that may, for instance, detect speech patterns consistent with boredom, fatigue, etc” as well as measuring other metrics, such as how long a person spends speaking, could also provide data to be stirred into the mix.

And if that doesn’t worry attendees, how about some more metrics to measure how focused a person is? Are they taking care of emails, messaging or enjoying a surf of the internet when they should be paying attention to the speaker? Heck, if one is taking data from a user’s computer, one could even consider the physical location of the device.

[…]

Talking to The Reg, one privacy campaigner who asked to remain anonymous said of tools such as Productivity Score and the Meeting Insight Computing System patent: “There is a simple dictum in privacy: you cannot lose data you don’t have. In other words, if you collect it you have to protect it, and that sort of data is risky to start with.

“Who do you trust? The correct answer is ‘no one’.”

Source: As if Productivity Score wasn’t creepy enough, Microsoft has patented tech for ‘meeting quality monitoring devices’ • The Register

Since then, Microsoft will remove user names from ‘Productivity Score’ feature after privacy backlash ( Geekwire )

Microsoft says it will make changes in its new Productivity Score feature, including removing the ability for companies to see data about individual users, to address concerns from privacy experts that the tech giant had effectively rolled out a new tool for snooping on workers.

“Going forward, the communications, meetings, content collaboration, teamwork, and mobility measures in Productivity Score will only aggregate data at the organization level—providing a clear measure of organization-level adoption of key features,” wrote Jared Spataro, Microsoft 365 corporate vice president, in a post this morning. “No one in the organization will be able to use Productivity Score to access data about how an individual user is using apps and services in Microsoft 365.”

The company rolled out its new “Productivity Score” feature as part of Microsoft 365 in late October. It gives companies data to understand how workers are using and adopting different forms of technology. It made headlines over the past week as reports surfaced that the tool lets managers see individual user data by default.

As originally rolled out, Productivity Score turned Microsoft 365 into a “full-fledged workplace surveillance tool,” wrote Wolfie Christl of the independent Cracked Labs digital research institute in Vienna, Austria. “Employers/managers can analyze employee activities at the individual level (!), for example, the number of days an employee has been sending emails, using the chat, using ‘mentions’ in emails etc.”

The initial version of the Productivity Score tool allowed companies to see individual user data. (Screenshot via YouTube)

Spataro wrote this morning, “We appreciate the feedback we’ve heard over the last few days and are moving quickly to respond by removing user names entirely from the product. This change will ensure that Productivity Score can’t be used to monitor individual employees.”

DeepMind’s A.I. can now predict protein shapes from their DNA sequences | Fortune

Researchers have made a major breakthrough using artificial intelligence that could revolutionize the hunt for new medicines.

The scientists have created A.I. software that uses a protein’s DNA sequence to predict its three-dimensional structure to within an atom’s width of accuracy.

The achievement, which solves a 50-year-old challenge in molecular biology, was accomplished by a team from DeepMind, the London-based artificial intelligence company that is part of Google parent Alphabet.

[…]

Across more than 100 proteins, DeepMind’s A.I. software, which it called AlphaFold 2, was able to predict the structure to within about an atom’s width of accuracy in two-thirds of cases and was highly accurate in most of the remaining one-third of cases, according to John Moult, a molecular biologist at the University of Maryland who is director of the competition, called the Critical Assessment of Structure Prediction, or CASP. It was far better than any other method in the competition, he said.

[…]

DeepMind had not yet determined how it would provide academic researchers with access to the protein structure prediction software or whether it would seek commercial collaborations with pharmaceutical and biotechnology firms. He said the company would announce “further details on how we’re going to be able to give access to the system in a scalable way” sometime next year.

“This computational work represents a stunning advance on the protein-folding problem,” Venki Ramakrishnan, a Nobel Prize–winning structural biologist who is also the outgoing president of the Royal Society, Britain’s most prestigious scientific body, said of AlphaFold 2.

Janet Thornton, an expert in protein structure and former director of the European Molecular Biology Laboratory’s European Bioinformatics Institute, said that DeepMind’s breakthrough opened up the way to mapping the entire “human proteome”—the set of all proteins found within the human body. Currently, only about a quarter of human proteins have been used as targets for medicines, she said. Now, many more proteins could be targeted, creating a huge opportunity to invent new medicines.

[…]

As part of CASP’s efforts to verify the capabilities of DeepMind’s system, Lupas used the predictions from AlphaFold 2 to see if it could solve the final portion of a protein’s structure that he had been unable to complete using X-ray crystallography for more than a decade. With the predictions generated by AlphaFold 2, Lupas said he was able to determine the shape of the final protein segment in just half an hour.

AlphaFold 2 has also already been used to accurately predict the structure of a protein called ORF3a that is found in SARS-CoV-2, the virus that causes COVID-19, which scientists might be able to use as a target for future treatments.

Lupas said he thought the A.I. software would “change the game entirely” for those who work on proteins. Currently, DNA sequences are known for about 200 million proteins, and tens of millions more are being discovered every year. But 3D structures have been mapped for less than 200,000 of them.

AlphaFold 2 was only trained to predict the structure of single proteins. But in nature, proteins are often present in complex arrangements with other proteins. Jumper said the next step was to develop an A.I. system that could predict complicated dynamics between proteins—such as how two proteins will bind to one another or the way that proteins in close proximity morph one another’s shapes.

[…]

Source: DeepMind’s A.I. can now predict protein shapes from their DNA sequences | Fortune

How use science to fight back against anti-maskers, climate deniers and anti-vaxxers? Let people read their research

[..]

The shift to online science communication from conventional news platforms has been going on for a while. There is a need for credible and accurate reporting because the miscommunication of science in the media is causing lasting damage to the public’s understanding of science.

Misinformation has consequences, as seen during the ongoing COVID-19 pandemic. Ignoring public health advice to wear masks and physically distance has cost thousands of lives and livelihoods in countries such as the United States, Brazil and Russia. Yet, resources in science journalism are dwindling. Budget cuts have slashed the number of journalists in conventional news outlets; this often affects specialized reporters like science journalists.

We need to equip scientists with science journalism skills. At Concordia University,

[…]

This withdrawal of conventional news outlets from conducting science journalism and the increasing role of universities and scientists doing so introduce new challenges.

[…]

Because there are fewer science journalists in conventional news outlets, the public is less able to access the scientific information they need to make informed decisions. This is further exacerbated by the flaws of the existing model.

Currently, scientists communicate their research via private publishing groups. Due to paywalls, this research is very hard to access by the taxpayers who fund that research. Meanwhile, research funded by industry is freely accessible to the public via the publication of patents

Open access is often discussed as a way to ease public access to scientific findings. However, some publishing groups lobby against possible open access government regulation.

But scientists are fighting back. Psychologist Tal Yarkoni, who has been an outspoken critic of the academic publishing model, and other researchers are boycotting journals that engage in this lobbying. In January 2019, the entire editorial board at Elsevier’s Journal of Infometrics resigned in protest of commercial control of scholarly work.

[…]

When it comes to communicating research, there is an inherent conflict of interest between scientists and the universities that employ them.

That’s not to say that universities have sinister intentions. Universities are heavily invested in enhancing their reputations, which is closely tied to their success in raising funds through student recruitment, government grants and philanthropic endowments.

Universities view science communication as a fundraising activity, directed at funding sources, rather than the general public.

[…]

Universities should equip scientists with the knowledge-translation skills necessary to communicate their own science critically and credibly

[…]

Universities should also find a way to engage students in scientific communication. For example, there should be funding for internships for communications students, where those hired can manage Twitter accounts and blogs for research labs, update websites and write research publications in a more compelling, accessible and critical way

[…]

Source: Here’s how to fight back against anti-maskers, climate deniers and anti-vaxxers, according to scientists

Defeat COVID-19: put positive spin to a grim 2020 by showing global covid recoveries on screen

The campaign was conceived by DOOH firm Orb Screen, produced by Creative Conscience and L&CO, developed by Voodooh and Nicole Yershon, and designed by advertising graduate Megan Williams. It has now made its way to Asia, with Location Media Xchange (LMX), the supply-focused arm of Moving Walls Group, amplifying the creatives on partner screens across Singapore, Malaysia, Indonesia, Philippines and India.

The displays run a tally of individuals known to have recovered from COVID-19 worldwide, while showcasing inspiring messages of how survivors have defeated it by refocusing some of the grim language often associated with the pandemic. A+M has reached out to Moving Walls for comment.

image 7.0 jalan maluri by spectrum outdoorimage 7.0 jalan maluri by spectrum outdoorimage 7.0 jalan maluri by spectrum outdoorimage 7.0 jalan maluri by spectrum outdoor

Among the list of media owners in Asia Pacific that ran the dynamic creatives include Dana Intelek, VGI Global Media Malaysia, Visual Retale, Vestigia Malaysia, LOOKhere Network, Titanium Compass, Spectrum Outdoor Marketing, 3thirds Inc, LEDtronics Media, Danendra Abyudaya Adika, KALMS, Pitchworks Incorporated Philippines and Nexyite Entertainment.

Source: Defeat COVID-19: APAC OOH firms put positive spin to a grim 2020

The data comes from John Hopkins University and apparently you can find a PDF brief from Orbscreen containing HTML code.

Poland’s Bid To Get Upload Filters Taken Out Of The EU Copyright Directive Suddenly Looks Much More Hopeful

one of the biggest defeats for users of the Internet — and for online freedom of expression — was the passage of the EU Copyright Directive last year. The law was passed using a fundamentally dishonest argument that it did not require upload filters, because they weren’t explicitly mentioned in the text. As a result, supporters of the legislation claimed, platforms would be free to use other technologies that did not threaten freedom of speech in the way that automated upload filters would do. However, as soon as the law was passed, countries like France said that the only way to implement Article 17 (originally Article 13) was through upload filters, and copyright companies started pushing for legal memes to be blocked because they now admitted that upload filters were “practically unworkable“.

This dishonesty may come back to bite supporters of the law. Techdirt reported last August that Poland submitted a formal request for upload filters to be removed from the final text. The EU’s top court, the Court of Justice of the European Union (CJEU) has just held a public hearing on this case, and as the detailed report by Paul Keller makes abundantly clear, there are lots of reason to be hopeful that Article 17’s upload filters are in trouble from a legal point of view.

The hearing was structured around four questions. Principally, the CJEU wanted to know whether Article 17 meant that upload filters were mandatory. This is a crucial question because the court has found in the past that a general obligation to monitor all user uploads for illegal activities violates the fundamental rights of Internet users and platform operators. This is why proponents of the law insisted that upload filters were not mandatory, but simply one technology that could be applied

[…]

Poland also correctly pointed out that the alternatives presented by the European institutions, such as fingerprinting, hashing, watermarking, Artificial Intelligence or keyword search, all constitute alternative methods of filtering, but not alternatives to filtering.

This is the point that every expert has been making for years: there are no viable alternatives to upload filters, which means that Article 17 necessarily imposes a general monitoring requirement, something that is not permitted under current EU law. The fact that the Advocate General Øe, who will release his own recommendations on the case early next year, made his comment about the lack of any practical alternative to upload filters is highly significant. During the hearing, representatives of the French and Spanish governments claimed that this doesn’t matter, for the following remarkable reason:

The right to intellectual property should be prioritized over freedom of expression in cases of uncertainty over the legality of user uploads, because the economic damage to copyright-holders from leaving infringements online even for a short period of time would outweigh the damage to freedom of expression of users whose legal uploads may get blocked.

The argument here seems to be that as soon as even a single illegal copy is placed online, it will be copied rapidly and spread around the Internet. But this line of reasoning undermines itself. If placing a single illegal copy online for even a short time really is enough for it to be shared widely, then it only requires a copy to be placed on a site outside the EU’s reach for copies to spread around the entire Internet anyway — because copying is so easy — which makes the speed of the takedown within the EU irrelevant.

[…]

In other words, what seemed at the time like a desperate last attempt by Poland to stop the awful upload filters, with little hope of succeeding, now looks to have a decent chance because of the important general issues it raises — something explored at greater length in a new study written by Reda and others (pdf). That’s not to say that Article 17’s upload filters are dead, but it seems like the underhand methods used to force this legislation through could turn out to be their downfall.

Source: Poland’s Bid To Get Upload Filters Taken Out Of The EU Copyright Directive Suddenly Looks Much More Hopeful | Techdirt

Privacy campaigner flags concerns about Microsoft’s creepy Productivity Score now in 365

Microsoft’s Productivity Score has put in a public appearance in Microsoft 365 and attracted the ire of privacy campaigners and activists.

The Register had already noted the vaguely creepy-sounding technology back in May. The goal of it is to use telemetry captured by the Windows behemoth to track the productivity of an organisation through metrics such as a corporate obsession with interminable meetings or just how collaborative employees are being.

The whole thing sounds vaguely disturbing in spite of Microsoft’s insistence that it was for users’ own good.

As more details have emerged, so have concerns over just how granular the level of data capture is.

Vienna-based researcher (and co-creator of Data Dealer) Wolfie Christl suggested that the new features “turns Microsoft 365 into an full-fledged workplace surveillance tool.”

Christl went on to claim that the software allows employers to dig into employee activities, checking the usage of email versus Teams and looking into email threads with @mentions. “This is so problematic at many levels,” he noted, adding: “Managers evaluating individual-level employee data is a no go,” and that there was the danger that evaluating “productivity” data can shift power from employees to organisations.

Earlier this year we put it to Microsoft corporate vice president Brad Anderson that employees might find themselves under the gimlet gaze of HR thanks to this data.

He told us: “There is no PII [personally identifiable information] data in there… it’s a valid concern, and so we’ve been very careful that as we bring that telemetry back, you know, we bring back what we need, but we stay out of the PII world.”

Microsoft did concede that there could be granularity down to the individual level although exceptions could be configured. Melissa Grant, director of product marketing for Microsoft 365, told us that Microsoft had been asked if it was possible to use the tool to check, for example, that everyone was online and working by 8 but added: “We’re not in the business of monitoring employees.”

Christl’s concerns are not limited to the Productivity Score dashboard itself, but also regarding what is going on behind the scenes in the form of the Microsoft Graph. The People API, for example, is a handy jumping off point into all manner of employee data.

For its part, Microsoft has continued to insist that Productivity Score is not a stick with which to bash employees. In a recent blog on the matter, the company stated:

To be clear, Productivity Score is not designed as a tool for monitoring employee work output and activities. In fact, we safeguard against this type of use by not providing specific information on individualized actions, and instead only analyze user-level data aggregated over a 28-day period, so you can’t see what a specific employee is working on at a given time. Productivity Score was built to help you understand how people are using productivity tools and how well the underlying technology supports them in this.

In an email to The Register, Christl retorted: “The system *does* clearly monitor employee activities. And they call it ‘Productivity Score’, which is perhaps misleading, but will make managers use it in a way managers usually use tools that claim to measure ‘productivity’.”

He added that Microsoft’s own promotional video for the technology showed a list of clearly identifiable users, which corporate veep Jared Spataro said enabled companies to “find your top communicators across activities for the last four weeks.”

We put Christl’s concerns to Microsoft and asked the company if its good intentions extended to the APIs exposed by the Microsoft Graph.

While it has yet to respond to worries about the APIs, it reiterated that the tool was compliant with privacy laws and regulations, telling us: “Productivity Score is an opt-in experience that gives IT administrators insights about technology and infrastructure usage.

It added: “Insights are intended to help organizations make the most of their technology investments by addressing common pain points like long boot times, inefficient document collaboration, or poor network connectivity. Insights are shown in aggregate over a 28-day period and are provided at the user level so that an IT admin can provide technical support and guidance.”

Source: Privacy campaigner flags concerns about Microsoft’s creepy Productivity Score • The Register

Prolonged AWS outage takes down a big chunk of the internet

Amazon Web Services (AWS), Amazon’s internet infrastructure service that is the backbone of many websites and apps, experienced a multi-hour outage on Wednesday that affected a large portion of the internet. The service has been nearly fully restored as of 4:18AM ET on Thursday morning, according to Amazon.

Source: Prolonged AWS outage takes down a big chunk of the internet – The Verge

IRS contracted to Search Warrantless Location Database Over 10,000 Times

The IRS was able to query a database of location data quietly harvested from ordinary smartphone apps over 10,000 times, according to a copy of the contract between IRS and the data provider obtained by Motherboard.

The document provides more insight into what exactly the IRS wanted to do with a tool purchased from Venntel, a government contractor that sells clients access to a database of smartphone movements. The Inspector General is currently investigating the IRS for using the data without a warrant to try to track the location of Americans.

“This contract makes clear that the IRS intended to use Venntel’s spying tool to identify specific smartphone users using data collected by apps and sold onwards to shady data brokers. The IRS would have needed a warrant to obtain this kind of sensitive information from AT&T or Google,” Senator Ron Wyden told Motherboard in a statement after reviewing the contract.

[…]

Venntel sources its location data from gaming, weather, and other innocuous looking apps. An aide for the office of Senator Ron Wyden, whose office has been investigating the location data industry, previously told Motherboard that officials from Customs and Border Protection (CBP), which has also purchased Venntel products, said they believe Venntel also obtains location information from the real-time bidding that occurs when advertisers push their adverts into users’ browsing sessions.

One of the new documents says Venntel sources the location information from its “advertising analytics network and other sources.” Venntel is a subsidiary of advertising firm Gravy Analytics.

The data is “global,” according to a document obtained from CBP.

[…]

Source: IRS Could Search Warrantless Location Database Over 10,000 Times

GM launches OnStar Insurance Services – uses your driving data to calculate insurance rate

Andrew Rose, president of OnStar Insurance Services commented: “OnStar Insurance will promote safety, security and peace of mind. We aim to be an industry leader, offering insurance in an innovative way.

“GM customers who have subscribed to OnStar and connected services will be eligible to receive discounts, while also receiving fully-integrated services from OnStar Insurance Services.”

The service has been developed to improve the experience for policyholders who have an OnStar Safety & Security plan, as Automatic Crash Response has been designed to notify an OnStar Emergency-certified Advisor who can send for help.

The service is currently working with its insurance carrier partners to remove biased insurance plans by focusing on factors within the customer’s control, which includes individual vehicle usage and rewarding smart driving habits that benefit road safety.

OnStar Insurance Services plans to provide customers with personalised vehicle care and promote safer driving habits, along with a data-backed analysis of driving behaviour.

Source: General Motors launches OnStar Insurance Services – Reinsurance News

What it doesn’t say is whether it could raise insurances or deny them entirely, how transparent the reward system will be or what else they will be doing with your data.

Struggling electric jet startup Zunum sues Boeing for fraud, misuse of trade secrets, poaching talent

In 2017, Zunum Aero was flying high. The Kirkland, Washington-based aviation startup came out of stealth mode with bold plans to build a fleet of 12-seat hybrid electric jets for short, regional hops between cities. The company, which had received millions of dollars from the venture arms of Boeing and JetBlue, said it would be ready to fly by 2022.

Not long after, those dreams came crashing down to earth. In 2018, Zunum ran out of cash, forcing it to lay off nearly all of its employees and vacate its headquarters. It struggled to raise additional funds that it needed to get its plans back in motion. And now, Zunum is striking back at one of its former investors. The company filed a lawsuit in Washington Superior Court this week accusing aerospace giant Boeing of fraud, technology theft, breach of contract, and misappropriation of trade secrets.

Zunum said that Boeing “colluded with other key aerospace manufacturers and funders” to sabotage its efforts to raise additional cash and tried to poach Zunum’s engineers during the process. The startup claims that Boeing saw its superior technology and potential to disrupt air travel as a threat to its own dominance in the aviation world and sought to undermine it. Using its due diligence as an investor as subtext, Zunum said Boeing gained access to its business plan and proprietary technology, and “exploited” Zunum for its own benefit.

“Boeing saw an innovative venture, with a dramatically improved path to the future, and presented itself as interested in investing and partnering with Zunum,” the company claims in court filings. “But instead, Boeing stole Zunum’s technology and intentionally hobbled the upstart entrant in order to maintain its dominant position in commercial aviation by stifling competition.”

It’s rare that a startup would sue one of its investors after failing to deliver on its promises. But Zunum said its setbacks weren’t because of bad technology or a faulty business plan. Rather, the company claims it was sabotaged by Boeing, which misused its position as an investor to pillage its talent and patents before eventually scuttling the company’s ability to continue to raise money.

Zunum also names HorizonX, Boeing’s venture capital arm, and French engine supplier Safran as co-defendants. The company is seeking compensatory and punitive damages. A spokesperson for Boeing said the lawsuit was without merit and that the company would “vigorously” contest it in court.

[…]

Zunum puts the blame on Boeing. The Chicago-based company repeatedly reneged on promises for additional funds and dissuaded other investors from putting money in, the lawsuit alleges.

“Boeing also kept Zunum beholden to it for much-needed capital and market validation, stringing Zunum along with the prospects of an anchor investment and providing leadership on further fundraising,” the lawsuit says. “Although Zunum also sought investments elsewhere, Boeing actively interfered with and undermined those business relationships while inducing Zunum to continue its reliance on Boeing by holding out the prospect of a strategic partnership or merger.”

[…]

“Zunum discovered that Boeing was secretly developing a replica prototype of Zunum’s flagship aircraft design, staffed by the very same engineers and other professionals whom Boeing had assigned to conduct extensive due diligence on Zunum, under non-disclosure and non-use obligations,” the lawsuit reads.

Source: Struggling electric jet startup Zunum sues Boeing for fraud and misuse of trade secrets – The Verge

Australia’s spy agencies caught collecting COVID-19 app data

Australia’s intelligence agencies have been caught “incidentally” collecting data from the country’s COVIDSafe contact-tracing app during the first six months of its launch, a government watchdog has found.

The report, published Monday by the Australian government’s inspector general for the intelligence community, which oversees the government’s spy and eavesdropping agencies, said the app data was scooped up “in the course of the lawful collection of other data.”

But the watchdog said that there was “no evidence” that any agency “decrypted, accessed or used any COVID app data.”

Incidental collection is a common term used by spies to describe the data that was not deliberately targeted but collected as part of a wider collection effort. This kind of collection isn’t accidental, but more of a consequence of when spy agencies tap into fiber optic cables, for example, which carries an enormous firehose of data. An Australian government spokesperson told one outlet, which first reported the news, that incidental collection can also happen as a result of the “execution of warrants.”

The report did not say when the incidental collection stopped, but noted that the agencies were “taking active steps to ensure compliance” with the law, and that the data would be “deleted as soon as practicable,” without setting a firm date.

For some, fears that a government spy agency could access COVID-19 contact-tracing data was the worst possible outcome.

[…]

Source: Australia’s spy agencies caught collecting COVID-19 app data | TechCrunch

Amazon’s ad-hoc Ring, Echo mesh network can mooch off your neighbors’ Wi-Fi if needed – and it’s opt-out

Amazon is close to launching Sidewalk – its ad-hoc wireless network for smart-home devices that taps into people’s Wi-Fi – and it is pretty much an opt-out affair.

The gist of Sidewalk is this: nearby Amazon gadgets, regardless of who owns them, can automatically organize themselves into their own private wireless network mesh, communicating primarily using Bluetooth Low Energy over short distances, and 900MHz LoRa over longer ranges.

At least one device in a mesh will likely be connected to the internet via someone’s Wi-Fi, and so, every gadget in the mesh can reach the ‘net via that bridging device. This means all the gadgets within a mesh can be remotely controlled via an app or digital assistant, either through their owners’ internet-connected Wi-Fi or by going through a suitable bridge in the mesh. If your internet goes down, your Amazon home security gizmo should still be reachable, and send out alerts, via the mesh.

It also means if your neighbor loses broadband connectivity, their devices in the Sidewalk mesh can still work over the ‘net by routing through your Sidewalk bridging device and using your home ISP connection.

[…]

Amazon Echoes, Ring Floodlight Cams, and Ring Spotlight Cams will be the first Sidewalk bridging devices as well as Sidewalk endpoints. The internet giant hopes to encourage third-party manufacturers to produce equipment that is also Sidewalk compatible, extending meshes everywhere.

Crucially, it appears Sidewalk is opt-out for those who already have the hardware, and will be opt-in for those buying new gear.

[…]

if you already have, say, an Amazon Ring, it will soon get a software update that will automatically enable Sidewalk connectivity, and you’ll get an email explaining how to switch that off. When powering up a new gizmo, you’ll at least get the chance to opt in or out.

[…]

We’re told Sidewalk will only sip your internet connection rather than hog it, limiting itself to half a gigabyte a month. This policy appears to live in hope that people aren’t on stingy monthly data caps.

[…]

Just don’t forget that Ring and the police, in the US at least, have a rather cosy relationship. While Amazon stresses that Ring owners are in control of the footage recorded by their camera-fitted doorbells, homeowners are often pressured into turning their equipment into surveillance systems for the cops.

Source: Amazon’s ad-hoc Ring, Echo mesh network can mooch off your neighbors’ Wi-Fi if needed – and it’s opt-out • The Register

Disney (Disney!) Accused Of Trying To Lawyer Its Way Out Of Paying Royalties To Alan Dean Foster, Star Wars and Alien book writer

Disney, of course, has quite the reputation as a copyright maximalist. It has been accused of being the leading company in always pushing for more draconian copyright laws. And then, of course, there’s the infamous Mickey Mouse curve, first designated a decade ago by Tom Bell, highlighting how copyright term extensions seemed to always happen just as Mickey Mouse was set to go into the public domain (though, hopefully that’s about to end):

Whether accurate or not, Disney is synonymous with maximizing copyright law, which the company and its lobbyists always justify with bullshit claims of how they do it “for the artist.”

Except that it appears that Disney is not paying artists. While the details are a bit fuzzy, yesterday the Science Fiction & Fantasy Writers of America (SFWA) and famed author Alan Dean Foster announced that Disney was no longer paying him royalties for the various Star Wars books he wrote (including the novelization of the very first film back in 1976), along with his novelizations of the Aliens movies. He claims he’d always received royalties before, but they suddenly disappeared.

Foster wrote a letter (amusingly addressed to “Mickey”) in which he lays out his side of the argument, more or less saying that as Disney has gobbled up various other companies and rights, it just stopped paying royalties:

When you purchased Lucasfilm you acquired the rights to some books I wrote. STAR WARS, the novelization of the very first film. SPLINTER OF THE MIND’S EYE, the first sequel novel. You owe me royalties on these books. You stopped paying them.

When you purchased 20th Century Fox, you eventually acquired the rights to other books I had written. The novelizations of ALIEN, ALIENS, and ALIEN 3. You’ve never paid royalties on any of these, or even issued royalty statements for them.

All these books are all still very much in print. They still earn money. For you. When one company buys another, they acquire its liabilities as well as its assets. You’re certainly reaping the benefits of the assets. I’d very much like my miniscule (though it’s not small to me) share.

[…]

In a video press conference, Foster and SFWA […] said that Disney is claiming that it purchased “the rights but not the obligations” to these works.

Source: Disney (Disney!) Accused Of Trying To Lawyer Its Way Out Of Paying Royalties To Alan Dean Foster | Techdirt

Scientists Produce Rare Diamonds In Minutes At Room Temperature

While traditional diamonds are formed over billions of years deep in the Earth where extreme pressures and temperatures provide just the right conditions to crystalize carbon, scientists are working on more expedient ways of forging the precious stones. An international team of researchers has succeeded in whittling this process down to mere minutes, demonstrating a new technique where they not only form quickly, but do so at room temperature.

This latest breakthrough was led by scientists at the Australian National University (ANU) and RMIT University, who used what’s known as a diamond anvil cell, which is a device used by researchers to generate the extreme pressures needed to create ultra-hard materials. The team applied pressure equal to 640 African elephants on the tip of a ballet shoe, doing so in a way that caused an unexpected reaction among the the carbon atoms in the device. “The twist in the story is how we apply the pressure,” says ANU Professor Jodie Bradby. “As well as very high pressures, we allow the carbon to also experience something called ‘shear’ — which is like a twisting or sliding force. We think this allows the carbon atoms to move into place and form Lonsdaleite and regular diamond.”

These regular diamonds are the type you might find in an engagement ring, while Lonsdaleite diamonds are rarer and found at meteorite impact sites. Using advanced electron microscopy, the team was able to examine the samples in detail, and found that the materials were formed within bands they liken to “rivers” of diamond. The team hopes the technique can enable them to produce meaningful quantities of these artificial diamonds, particularly Lonsdaleite, which is predicted to be 58 percent harder than regular diamonds. “Lonsdaleite has the potential to be used for cutting through ultra-solid materials on mining sites,” Bradby says. The research was published in the journal Small, while you can hear from the researchers in this video.

Source: Scientists Produce Rare Diamonds In Minutes At Room Temperature – Slashdot

Split-Second ‘Phantom’ Images Can Fool Tesla’s Autopilot

one group of researchers has been focused on what autonomous driving systems might see that a human driver doesn’t—including “phantom” objects and signs that aren’t really there, which could wreak havoc on the road.

Researchers at Israel’s Ben Gurion University of the Negev have spent the last two years experimenting with those “phantom” images to trick semi-autonomous driving systems. They previously revealed that they could use split-second light projections on roads to successfully trick Tesla’s driver-assistance systems into automatically stopping without warning when its camera sees spoofed images of road signs or pedestrians. In new research, they’ve found they can pull off the same trick with just a few frames of a road sign injected on a billboard’s video

[…]

“The driver won’t even notice at all. So somebody’s car will just react, and they won’t understand why.”

In their first round of research, published earlier this year, the team projected images of human figures onto a road, as well as road signs onto trees and other surfaces. They found that at night, when the projections were visible, they could fool both a Tesla Model X running the HW2.5 Autopilot driver-assistance system—the most recent version available at the time, now the second-most-recent —and a Mobileye 630 device. They managed to make a Tesla stop for a phantom pedestrian that appeared for a fraction of a second, and tricked the Mobileye device into communicating the incorrect speed limit to the driver with a projected road sign.

In this latest set of experiments, the researchers injected frames of a phantom stop sign on digital billboards, simulating what they describe as a scenario in which someone hacked into a roadside billboard to alter its video. They also upgraded to Tesla’s most recent version of Autopilot known as HW3.

[…]

an image that appeared for 0.42 seconds would reliably trick the Tesla, while one that appeared for just an eighth of a second would fool the Mobileye device. They also experimented with finding spots in a video frame that would attract the least notice from a human eye, going so far as to develop their own algorithm for identifying key blocks of pixels in an image so that a half-second phantom road sign could be slipped into the “uninteresting” portions.

[…]

Source: Split-Second ‘Phantom’ Images Can Fool Tesla’s Autopilot | WIRED

Nintendo Continues Cracking Down On People Selling Switch Hacks: jailbraking w RCM = piracy in their minds

Nintendo filed a lawsuit Wednesday against an Amazon Marketplace user who was allegedly selling devices called RCM loaders. Used to help people jailbreak their Switch, shutting these down is the latest in the company’s efforts to stop players from pirating its games.

As first reported by Polygon, the lawsuit against reseller Le Hoang Minh seeks “relief for unlawful trafficking in circumvention devices in violation of the Digital Millennium Copyright Act (DMCA).” In addition to having the Seattle District Court order Minh to stop selling the devices, Nintendo also wants $2,500 in damages for each one already sold.

“Piracy of video game software has become a serious, worsening international problem,” Nintendo’s lawyers write (without offering any further detail), arguing that the RCM loaders and other devices like them are are a big contributor to that. While jailbreaking a Switch isn’t necessarily itself against the law, pirating games is, and devices whose primary purpose is to facilitating that are also prohibited. The loaders aren’t hard to find on Amazon and other resellers, but it’s essentially the code the loaders are running to jailbreak the Switch that people buy them for and which Nintendo wants to stop the spread of.

According to the legal complaint Nintendo filed, the company originally sought to have Minh’s listings removed from Amazon by issuing DMCA-related takedowns, but Minh filed a counter-notification with Amazon to keep the listings up, forcing Nintendo to take the matter to court.

Source: Nintendo Continues Cracking Down On People Selling Switch Hacks

Just because a device can somehow be used for jailbraking doesn’t mean it always is. A bit like a phone can be used to plot a bank heist, but that isn’t the sole purpose of a phone.

Oppo’s X 2021 rollable concept phone expands in your hand

Today’s Inno Day 2020 event unveiled the Oppo X 2021 concept smartphone, which is all about its “continuously variable OLED display.” With a simple swipe on a button, the phone is able to transform between a regular 6.7-inch size and a tablet-like 7.4-inch size, and the software interface adapts accordingly for optimal experience — be it for single-hand usage or for multi-tasking.

Oppo X 2021 rollable concept phone demo.

Oppo

In a demo shown to Engadget, the prototype magically toggled between two screen sizes, with the video resizing itself on the fly to fill the screen. Similarly, the system menus and Twitter also switched between their phone interface and tablet interface to match the screen size. Oppo added that the user can freely customize the screen size, so you’re not just limited to either 6.7 inches or 7.4 inches. Hence the “continuously variable” label.

Oppo X 2021's Warp Track and 2-in-1 Plate.

Oppo

Oppo wasn’t afraid to explain the magic here. The phone is essentially a motorized scroll, with a large part of the OLED panel laminated onto a “Warp Track” for improved strength, as it goes around a “Roll Motor” (with a 6.8mm scroll diameter) on the left to tuck itself into a hidden compartment. The phone itself consists of a “2-in-1 Plate” body construction: these two parts roll out simultaneously and evenly for better structural support.

Oppo applied for 122 patents for this project, 12 of which were on the scroll mechanism alone. The company stopped short at providing further details — no word on the screen specs, the panel’s supplier nor durability figures. Levin Liu, OPPO Vice President and Head of OPPO Research Institute, stressed that the Oppo X 2021 is still in concept stage, but he hopes to bring this technology to consumers “at the right time.”

Source: Oppo’s X 2021 rollable concept phone expands in your hand | Engadget