Category Archives: News

Shared items and notes from my feeds and browsing. Subscribe as feed.

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

Source: Hacker News

Article note: Neeeeeat. It's a physically invasive and destructive attack that requires a quarter million dollars of equipment to locate and modify a register in the silicon, but the fact that the RPi folks are encouraging this kind of research into what you can actually protect in a re-programmable IC is very cool.
Comments
Posted in News | Leave a comment

Artificial Intelligence, Quote Unquote

Source: Penny Arcade

Article note: A man who has made a career of writing the text bubbles for funny pictures on the internet is seeing through the AI rhetoric better than about a third of my PhD-in-EE/CPE/CS colleagues.

Let's go over a few things.

1. If OpenAI or Anthropic breaches another company's systems, even if no money changed hands, these are Federal and State crimes. Currently, these narratives are being deployed essentially as a mode of advertising to "pump those numbers." This is why I don't believe anything remotely like what they describe occurred. At all. In any way. They are, in plain terms, "lies." Lies in the context of an IPO are called Securities Fraud - now the SEC is involved. It's astonishing what we're being asked to believe. Listen to these pinchy-faced fucking weasels talk. You would only endure these transhuman idolaters if you thought there was an upside. For you.

2. When they say shit - and they do say shit - like "there's a greater than ten percent chance our product will kill all humans within the next decade," you black bag the leadership of these companies. Again - this is how you know it's a bag pump; an op. First it was like, "Yup, we're spinning up a Jobpocalypse." I guess that stopped moving the needle, huh? A machine that recreates the conditions for feudalism? Every one of its thoughts manufactured, in part or in whole, by the disenfranchised? There's no way to overstate the hideousness they proudly emit. Now it's like, yeah, our Demon Engine might kill your kids - the ones we didn't kill already I guess. It's not serious, I'm sorry. It's Doctor Doom shit. Except in this case, Doctor Doom isn't a techno-sorcerer with Diplomatic Immunity. It's a guy who works in an air-conditioned office whenever he isn't telecommuting or warping capital markets with every breath. Black Bag.

3. Let's say we do need National AI to do battle with the AI of foreign adversaries - sounds like a great anime. If it's as crucial as we're being told, if we stand on the precipice of some great invisible conflict - like the "spirit war" my Church used to rail about - none of it would look this way. They would seize these companies via Eminent Domain, just as they did in World War II. If they did the shit these people say they do, it's not like fucking Coca-Cola. If they can batter any system or kill the world or any of this shit they aren't normal companies and they wouldn't be treated with the deference they are. They're already a cartel, clearly, which gives the government even more potent tools. Fucking come on.

4. All the hokey, handwavey parts of Cyberpunk that you just accept - the origin story of the neofeudal, technocratic state - you always wonder what that looks like. How the interests converge, how they're allowed to converge. I can tell you.

It looks like this.

(CW)TB

Posted in News | Leave a comment

25 Years of Mass Surveillance Is Enough

Source: Schneier on Security

Article note: Truly we lost our collective minds around 2001 (and _before_ 9/11, it was just a convenient excuse to put shit into overdrive. Remember that Joseph P. Nacchio of Qwest Communications refused to be party to the panopticon and went to jail for it because the feds rugpulled some contracts in retaliation for not installing intercept devices in telecom infrastructure, then accused him of insider trading based on those rugpulls). Bruce was warning us about dragnet surveillance and security theater and convenient excuses to consolidate power at the time, and not enough of us listened. While we're all looking at the shitty behavior of Flock and other creepy public-private surveillance partnerships and their use for political ends now, let's fix that shit. Let's systematically regulate the data brokers. Let's define and restrict the government's ability to engage in dragnet behavior via the 3rd party doctrine. Let's make the penalties for mishandling information onerous enough that no one will retain it in the first place.

This essay was written with Cindy Cohn, and originally appeared in Lawfare.

One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in immigration actions and against people exercising their First Amendment rights to protest. It’s also increasingly part of private security systems, such as facial recognition at venues such as Madison Square Garden and networked Flock license plate capture systems on roads and in parking lots.

The interrelation between private and governmental mass surveillance is worth examining. Surveillance is the business model of the internet; companies like Google and Facebook constantly spy on their users’ behavior. From the National Security Agency relying on data collected by telecommunication and internet companies, to local sheriffs and ICE agents relying on cellphone location data and privately managed automatic license plate readers, governments primarily obtain the mass surveillance information through private companies. Increasingly, access doesn’t just come through legal processes, either. FBI Director Kash Patel recently confirmed in congressional testimony that the agency is purchasing information on Americans from data brokers and intends to continue to do so.

This pipeline from private collection to governmental collection means that as companies collect more information for surveillance capitalism purposes, more is available to law enforcement as well. And as the technology for mass surveillance and analysis improves, especially with the increased use of AI technologies, the problems attendant to mass surveillance grow as well.

After 9/11, the idea that the government could surveil the population to safety took hold. In 2001, the fear of terrorism reached a frequency and intensity never before seen. Along with that came the fear that the enemy could be anyone, anywhere. As a result, the government’s response was to watch everyone, everywhere. This line of reasoning underpinned the shift from targeted to mass surveillance. Or, in the words of an internal National Security Agency (NSA) presentation that was made public as part of Edward Snowden’s 2013 disclosures, a government that can “Collect it All,” “Process it All,” “Exploit it All,” “Partner it All,” and “Sniff it All,” will ultimately, “Know it All.” Similar rationales support the rise of domestic mass surveillance: if law enforcement could see and hear everything, it could more effectively interdict and solve serious crimes.

The national security community has never provided a full analysis of the costs and benefits of these mass surveillance programs, either in terms of taxpayer dollars or diversion of resources from other efforts—or any demonstration that those techniques stopped attacks that otherwise they would not have been able to prevent. While the NSA occasionally presents examples of the successes due to its mass surveillance programs, especially when those techniques are under public pressure, the examples also regularly fall apart upon serious scrutiny. And even if some utility exists, it must be seriously weighed against the costs.

Similarly, there has never been any comprehensive analysis about whether domestic immigration or law enforcement’s use of these techniques actually makes people safer, or whether other techniques could produce the same results. Instead, both the police and the companies selling these tools float anecdotes and dubious data. For example, Flock’s data equates the number of law enforcement hits in their database with actually solving crimes.

Twenty-five years after 9/11, it seems reasonable to step back and evaluate the costs of this shift to mass surveillance, especially in terms of Americans’ rights and freedoms.

The Shift

The easiest place to see a shift to mass surveillance was in the government’s decision immediately after 9/11 to collect Americans’ telephone records. The program started under an argument of pure executive power as the “President’s Surveillance Program.” But in 2006, that argument secretly shifted to a novel interpretation of Section 215 of the Patriot. Act which had only previously authorized more targeted access to record. While some media and public interest organizations struggled to force the government to reveal the program as early as late 2005, the government only officially confirmed it after the 2013 Snowden disclosures. In 2015, the Second Circuit Court of Appeals rejected the government’s interpretation of Section 215 as allowing mass collection of telephone records. Later the same year, Congress passed the USA Freedom Act. While this new law still allows collection of a tremendous amount of domestic telephone records, it ended the indiscriminate mass collection that had occurred for nearly fourteen years.

Other shifts to mass surveillance continue through today. The NSA launched its Upstream program, which involved intercepting both metadata and content from key telecommunications junctures inside the U.S., soon after 9/11. It was also initially conducted under a claim of purely presidential authority. This program was brought under marginal congressional and programmatic (not targeted) Foreign Intelligence Surveillance Act (FISA) court review via Section 702 of the 2008 FISA Amendments Act. In 2017, more than15 years after its inception, the NSA ended content searches due to FISA court pressure, but the mass collection continues.

Despite the stated goal of conducting mass spying only on people outside the U.S.—which itself is problematic given international law’s requirement that surveillance be both necessary and proportionate—mass surveillance collects a tremendous amount of U.S. persons’ communications. This can happen because people communicate with people abroad, or because of overcollection—when government agencies gather far more personal data on non-targeted US persons than authorized by law. The concerns about collecting Americans’ data on U.S. soil led Congress to allow the program to officially expire in 2026, although the previously-approved mass surveillance itself continues until at least Spring of 2027.

The shift to mass surveillance would be notable enough even if it remained only a strategy of the intelligence community. It has not. Americans are awash in mass surveillance. Networks of automated license plate readers such as those offered by Flock and Vigilant Solutions blanket both public and private roadways and parking lots. These networks often allow searches by law enforcement, including across jurisdictions. They are, for example, being used to track people seeking abortions across state lines. Facial recognition tools, once the province of only the more elite parts of federal law enforcement, are increasingly used by Immigration and Customs Enforcement agents on immigrants and protesters, in airports by the Transportation Security Administration, as well as by private entities. And, of course, modern phones track users’ locations constantly—and that information is readily available to law enforcement, often with only minimal process protections.

Constitutional Costs

Regardless of the murkiness of its actual usefulness, the shift from targeted to mass surveillance has profound implications for Americans’rights. It has created risks that have become increasingly evident, especially under the Trump administration.

At a basic level, the Fourth Amendment guarantees that citizens can be secure in their “persons, houses, papers and effects” from unreasonable searches. Warrants breaching that security should be supported by probable cause and particular descriptions of the place to be searched and items to be seized. Mass surveillance turns that promise on its head, allowing access to our “papers and effects” by the government without individualized suspicion or a particularized description of what data is being seized, much less probable cause. This protection was in response to colonial British misuse of writs of assistance, which authorized indiscriminate searches rather than targeted ones.

The justifications for exempting mass surveillance from constitutional protection vary. For Section 702, the government has taken the position that U.S. persons’ communications caught up in the dragnet, either due to overcollection or because they were communicating with someone outside the United States, do not require a warrant prior to initial collection or secondary access by the FBI and several other agencies. The argument is that if the initial collection was not aimed at Americans, the information is free from constitutional protection for any later uses, even for reasons far afield from the initial rationale for collection.

Other arguments rest on the claim that metadata is outside the Fourth Amendment, despite its demonstrated ability to reveal intimate details of all of our lives. Still others rest on the Supreme Court-created Third Party Doctrine, which holds that the Fourth Amendment does not apply to data shared with companies that provide us with services. Some turn on whether analysis by machine counts, claiming that only “human eyes” matter—a particularly troubling argument with the rise of artificial intelligence. What’s more, the government has used doctrines like standing to limit the ability of those subjected to mass surveillance to seek constitutional protection. No matter the argument, the goal is the same: to place the mechanisms and fruits of mass surveillance outside the protections of the Fourth Amendment.

The overarching truth is that, due to the concerted efforts by the government since 9/11, and the rise of technologies in recent years, the slice of Americans’ lives and data that are actually protected by the Fourth Amendment has shrunk significantly in the past 25 years. Together, with the technical capabilities of mass surveillance and the increased ability for that data to be analyzed using AI tools, the “security in our papers and effects” that the constitution promises seems increasingly illusory.

In addition to the Fourth Amendment, mass surveillance creates tensions with the First Amendment. The Constitution has long recognized that the right to freedom of speech requires a zone of privacy against governmental surveillance. The right to anonymous speech as well as the right of association both recognize the chilling effect that surveillance creates for people saying unpopular things or attempting to organize for political or other societal change. Mass surveillance grants the authorities the ability to track those people, both in real time and historically, that is inconsistent with actual techniques of freedom of speech and assembly.

That is why the recently released 2026 U.S. Counterterrorism Strategy is so troubling. On page seven, the White House expressly states that it intends to target domestic activists with its heretofore foreign-targeted powers. It says that the government “will prioritize the rapid identification and neutralization of violent secular political groups whose ideology is anti-American, radically pro-transgender and anarchist” and “will use all the tools constitutionally available to us to map them at home, identify their membership, map their ties to international organizations like Antifa.” While framed as targeting “violent” groups, it’s clear that the government intends to use its national security tools, presumably including the tools of mass surveillance, against Americans in ways that will create profound tensions with the First Amendment rights of people to organize and communicate privately.

Costs Due to Mistakes and Abuse

Even assuming some utility from mass surveillance—a fact we do not dispute, even if the public record is shaky and conclusory—the history of both the national security and domestic uses of mass surveillance confirms that these tools are inevitably misused, and that mistakes have impacted huge numbers of Americans. The past twenty-five years have demonstrated that it is not possible to surveil the entire US population while staying within the bounds of even a very generous legal framework like Section 702.

As Rep. Zoe Lofgren (D-Calif.) recently stated in discussion of Section 702 in an interview with Tech Policy Press: “backdoor searches have been used improperly for protestors, 19,000 campaign donors, members of Congress, journalists, government officials, a state court judge who had complained to the FBI about police misconduct. It has been abused substantially in the past.” The NSA experienced so much abuse of its mass surveillance tools by actual or aspiring romantic partners and ex-spouses that an internal name emerged for it: “LOVEINT,” or Love Intelligence.

That same pattern of abuse is now emerging at the domestic law enforcement level. A Texas police officer misused, and then lied about, using license plate readers to track a woman suspected of seeking an abortion. Multiple law enforcement officials have been accused of tracking people they either wished to have a relationship with or who were their exes. And mass surveillance technologies have been used to track both immigration targets and citizens engaging in their First Amendment-protected right to track and record the police.

Mistakes are inevitable with collections of data of this size and scope. The history of the FISA court’s reviews of Section 702 is littered with examples of the NSA not being able to follow its own rules limiting the scope of what it collects and analyzes, even after having been given multiple chances by the court. On the local level, the technical protections that Flock, for example, put in place have repeatedly been insufficient to stop “accidental” sharing its data with out-of-state law enforcement. These mistakes have fueled growing efforts by local communities across the country to remove license plate readers. Those efforts should be the first step in a broader reconsideration of mass surveillance.

More generally, ubiquitous surveillance carries a real societal cost. The chilling effects are real and pervasive, and they tend to fall hardest on the most marginalized members of society. Moreover, social progress requires the ability to experiment in secret. It’s hard to imagine a society progressing morally to the point of accepting and legalizing things like marijuana use or gay marriage if the earliest signs of that shift are snuffed out because of overzealous surveillance.

Reversing Course

While a cost-benefit analysis is not the best frame for deciding constitutional rights, it is a place to start to evaluate government policies. If the costs are too high and the benefits too small, what should the public do? While the policy and legal frameworks can be individually complex, mass surveillance is a problem in all of its applications. So too should solutions be comprehensive rather than piecemeal.

One comprehensive strategy is to reset the promise of the Fourth Amendment and recognize that a warrant is required prior to collection, access or use of information gathered through mass surveillance. This would apply to collections that include U.S. persons, whether done for national security or domestic purposes. This protection would apply regardless of whether the information is in the form of metadata. It would apply regardless of whether the information is held in homes or by services people rely on, such as telephones, internet or social network providers, or by private entities utilizing mass surveillance for their own purposes. By passing this legislation, Congress could ensure this rejection of mass surveillance, and include real enforcement such as a private right of action and an automatic exclusionary remedy in criminal prosecutions. The courts could also recognize this protection of “papers and effects” directly as a plain language interpretation of the Fourth Amendment.

There are already a number of efforts that take on pieces of mass surveillance. Section 702 has expired and should remain so. This was due largely to efforts to block the “back door” access to Section 702-collected data without warrants. The bipartisan “Fourth Amendment is Not for Sale Act” would prevent the government from purchasing data that it would otherwise need a warrant to obtain. The Supreme Court itself has already been chipping away at the Third Party Doctrine, with a recent step in the rejection of mass geofence warrants—warrants seeking the identities of individuals based upon their proximity to a crime—in Chatrie v. United States. Now, such warrants fall, at least initially, under the Fourth Amendment.

A more comprehensive approach would also address mass surveillance carried out by private companies, and to ensure that Americans have the right to encrypt and secure their data. There are many reasons the United States would benefit from a comprehensive privacy law—and curbing mass surveillance is one of them. Addressing mass surveillance is certainly one of them. Ideas such as the banning of secondary uses of data—with roots in the Fair Information Practice Principles from the 1970s—are worth pushing forward. So are moves such as creating fiduciary duties for mass data collectors. There are many more ways to curtail private companies’ mass surveillance while staying within constitutional boundaries. But addressing the costs of mass surveillance by both companies and governments is even more important in a world where AI agents are making decisions both about the public and on their behalf based on their data and observed behavior.

Twenty-five years after the U.S. government embraced mass surveillance, it’s time to evaluate it as a whole, and consider responses that address the problem as a whole. Americans must ask: Is it consistent with a self-governing democracy to have systems that watch everyone everywhere? Is the public comfortable with governments—federal, state, local—that seek to “know it all” about its citizens? Is the public comfortable with private mass surveillance in its own right and as it’s being increasingly used to fuel government surveillance? These questions have long needed serious consideration. But as it becomes increasingly evident that the Trump administration is using mass surveillance to keep itself in power, stifle dissent, and undermine political opponents, these questions are now more urgent than ever.

Posted in News | Leave a comment

Blizzard Revives ‘StarCraft’ Franchise with Open-World Sci-Fi Shooter

Source: Hacker News

Article note: Any other olds remember when Blizzard announced StarCraft:Ghost as a FPS in the StarCraft setting in 2002, put it on hold in 2006, and finally officially cancelled it in 2014? The announced release date is 2030. Temper your expectations accordingly.
Comments
Posted in News | Leave a comment

CERN Transitioning To Debian After Being A Longtime RHEL Institution – Phoronix

Source: Published articles

Article note: My ongoing assertion that "Debian is Forever" continues to be substantiated. The (single controlling commercial interest related) churn of the last ~decade within the RHELatives has continued to make them less appealing.
Posted in News | Leave a comment

German Konrad Zuse Museum shutting down due to lack of funding

Source: Hacker News

Article note: That's a bummer, Zuse is a _fascinating_ figure who tends to get passed over for (understandable) geopolitical issues of the time.
Comments
Posted in News | Leave a comment

Omarchy: 1Password and 37signals become Distinguished Corporate Patrons

Source: Hacker News

Article note: I hope most of that money is going to upstream projects, because a sloppily vibe-configured Arch install with choices more hype-and-flash than practical doesn't need massive financial resources.
Comments
Posted in News | Leave a comment

IBM announces dual-ISA processor: ARM and IBM Z code running natively on the same cores

Source: OSNews

Article note: This is very IBM. Dual-architecture parts with insane memory corner-turning hardware to keep them consistent, like they were doing with BlueGene Power CPU+Nvidia GPU on single memory machines a decade or two ago. Kind of weird that it's AArch64 and now Power since the Z and big Power lines already share a lot of functional units, but Arm is obviously the bigger platform at this point. And, of course, you can still run Cobol-on-MVS jobs that were written in the 70 as though it were native.

Built on a 2 nanometer technology node, the processor’s design will contain 11 high-performance cores operating at more than 5.7 GHz, AI inference accelerators for in-transaction fraud detection, a dedicated on-chip data processing unit for I/O acceleration, and a large cache architecture for demanding enterprise workloads. The chip is architected to not contain separate Arm and IBM cores: each processor core can natively execute Arm and IBM Z, or Arm and LinuxONE, instructions concurrently while prioritizing the platform’s established performance, security, encryption, and availability characteristics. IBM Z and LinuxONE platforms are capable of scaling to hundreds of cores and tens of terabytes of memory.

↫ IBM press release

IBM is still doing some amazing chip architecture design. ServeTheHome has more details of how this works:

A key choice here is that IBM implemented AArch64 in full hardware rather than through translation. This design uses a little-endian Arm implementation alongside big-endian z/Architecture, with AArch64 v9.3, SVE and SVE2 support, and 2,792 implemented AArch64 instructions. IBM also claims Arm SystemReady compliance, which matters for how much off-the-shelf Arm software this core can absorb. This is absolutely crazy technology. Arm software sees a native Arm processor. Arm runs unmodified, out-of-the-box, and onto a standard Arm platform. IBM said the 2792 AArch64 instructions are more than twice the Z instructions. IBM made a funny quip about “reduced” in RISC.

↫ Patrick Kennedy at ServeTheHome

This is bonkers technology. We can only dream of this ever serving a home.

Posted in News | Leave a comment

Haiku R1/beta6 released

Source: OSNews

Article note: BeOS/Haiku is always one of my favorite alternate timelines that you can actually experience. Beyond the fundamental neat of Be, the Haiku folks have been doing cool things informed by experiences of other platforms, and building amazing Be-ish package management schemes and whatnot. It doesn't sound like there are ton of changes to B6 since whatever Nightly I currently have in a VM to play with, but the sign of progress and confidence is great. I'm ever more tempted to try doing some real work on a Haiku box.

It’s always a special day on OSNews when Haiku has a new release. While OSNews was founded in 1997, it wasn’t until 2001, when Eugenia took over and relaunched the site, that we really got going. Eugenia came from BeNews, a popular BeOS news website, which shut down in the wake of Be, Inc’s infamous “focus shift” away from BeOS as a general purpose desktop operating system. BeOS continues to have a special place on OSNews ever since.

Today marks the release of Haiku R1/beta6, the first official Haiku release in two years. As such, this new beta covers a monumental amount of progress since beta5, progress I’ve reported on diligently. The highlights of this new beta include a port of Firefox (including branding) and many of its forks, much improve support for Qemu, a new memory allocated largely based on the one from OpenBSD, and improved support for various filesystems. Of course, there’s a massive list of performance improvements, memory management changes, as well as a truly massive number of new application ports.

It’s important to note, as I usually do, that while these Haiku beta releases serve as patches of calm in rough seas, Haiku is generally stable and capable enough that using the project’s nightly releases is usually a totally acceptable way of installing and running the operating system. If you’re not comfortable running nightly releases, however, and haven’t tried Haiku since the previous beta, you’re in for a massive overall improvement.

Everybody loves Haiku.

Posted in News | Leave a comment

Ring says its new encryption limits what it can give police

Source: The Verge - All Posts

Article note: Sooo, what's the completely privacy breaking loophole? Interception requests can hold the key after the next time a routine process silently and automatically queries the key from the user?
All Ring cameras will soon use TAKE encryption by default. | Photo by Jennifer Pattison Tuohy / The Verge

Ring has a new way to protect your videos. It's developed an encryption method called TAKE, short for Throw Away the Key Encryption, that the Amazon-owned company says will protect your videos without traditional end-to-end encryption. TAKE limits when and why Amazon's cloud can access those videos, while still providing features like smart alerts for people and packages, AI-powered video search, and video descriptions.

The feature is rolling out gradually starting in September, regardless of whether you have a subscription, and will become the default encryption for all Ring customers.

TAKE arrives during a year of intense scrutiny for R …

Read the full story at The Verge.

Posted in News | Leave a comment