Slashdot

News for nerds, stuff that matters

Ubuntu 26.10 Will Offer a Rust-based GnuPG Replacement Option

The blog It's FOSS reports:

You already know that Canonical has been selectively replacing Ubuntu's C-based system components with Rust-written equivalents that don't compromise in terms of functionality, most of the time. Now it looks like the distro's OpenPGP implementation is next, with Sequoia PGP coming preinstalled in Ubuntu 26.10. Canonical wants it to eventually replace GnuPG [the dominant Linux implementation of PGP, written in C] as the default toolchain, though that switch has not happened yet... [The Ubuntu 26.10 release notes say Sequoia PGP's default status will be a future goal...]

[Sequoia PGP] was started in 2017 by three former GnuPG developers who chose to build a new OpenPGP implementation in Rust rather than keep evolving GnuPG's existing codebase. Sequoia PGP is designed as a library that other software can use directly, rather than a standalone command-line tool. sq sits on top of that for encryption, decryption, signing, and key management, and sqv handles signature verification, filling in for gpg and gpgv in GnuPG.
Sequoia also implements RFC 9580, the 2024 revision of the OpenPGP standard, whereas GnuPG has continued from the RFC 4880 branch, pursuing its own newer extensions and the LibrePGP specification rather than adopting RFC 9580 as its primary standard.
From the It's FOSS Weekly newsletter, which also notes that the founder of the It's FOSS blog has also created a Linux-themed game called TUXDLE — a variation on Wordle where all the answers are Linux terms.

Read more of this story at Slashdot.

Claude Sent Police a Fake Murder Tip. White House Mandates AI Companies Report Security Incidents

AFP reports that an AI model from Anthropic "submitted a fabricated tip about an unsolved homicide to Philadelphia police, authorities said Friday."


Claude "was instructed never to log in, create accounts, enter personal data, make purchases, or submit anything destructive, but the instructions did not rule out form submissions," Anthropic said Friday in a blog post.


Authorities are now criticizing Anthropic "for taking two months to report the incident."

The Philadelphia Police Department said the false submission was made in July through PhillyUnsolvedMurders.com, a public website where people can share information about unsolved killings. According to Anthropic's account, as relayed by police, the model was running a test that involved interacting with randomly selected websites when it reached the site and filed false information about an unsolved murder. The AI model presented itself as someone who might have knowledge of the case.



Anthropic's breaches have prompted the White House to mandate that AI companies notify and correct security incidents, news outlet Axios reported [yesterday], citing administration officials. "This notification and remediation process is not optional... It is a critical national security obligation," White House Super Intelligence Force leaders said in a statement to Axios.
"I may have information regarding this case," Claude told the police. "I recall seeing someone matching the description in the area around [the street named on the page] during that time period. Please contact me if this information is relevant." Anthropic notes that Claude "left the name and contact fields empty, which the form allowed, and submitted it. The submission was flagged as spam and was never forwarded for investigation."

But Anthropic also admits they saw "this behavior" three times — "on OSWorld (a public computer use evaluation), on Odysseys (a long-horizon task evaluation), and during internal usage." Submitting forms when it shouldn't have generally occurred "when an evaluation's instructions were ambiguous, or when a misconfiguration within the environment prevented Claude from working with dummy forms."



Anthropic's blog post acknowledges three other categories of behaviors:


Exploiting software flaws. Like when Claude received an error when trying to run a public tool on a university's web site, it located an injection flaw in a script on the university's server that let it run commands — including that public tool.
Working around restrictions to reach gated data. For example, Claude Mythos 5 needed public data that was only available from a state agency for a fee. "Claude learned from an archived copy of the agency's website that its public dashboard issues an access token to any visitor," Anthropic explains. "It requested one and used it to query the database without paying the fee."
Using URL shortening services. "Some of our fetch tools, which let Claude read webpages, limit the length of the URLs Claude can request. This is to prevent Claude from using long URLs to take certain unwanted actions, such as SQL or command injections... We saw several models, including Claude Opus 5 and Claude Mythos 5, get around this limitation by using free URL shortening services."



"We have built tooling to automatically detect and block the kinds of behaviors described above," Anthropic says, saying it's already running no on most of their evaluations. "When we tested it against the cases described in this post, it blocked all of them."

And they've already taken several other new preventive measures:


They've stopped running some public evaluations
Other public evaluations were moved to offline versions or rebuilt so their tasks don't reach live websites.
They've updated the guardrails on some internet access tools (including web fetch) "to heavily restrict what the model can do."
They're continuing "to fix or remove training environments that reward Claude for working around tool restrictions or other blockers, so that they do not incentivize these behaviors or permit reward hacking."

They've moved internal agents to "centrally managed infrastructure with strong containment," that minimizes internet access while monitoring "far more of what agents do through techniques like safety classifiers and hierarchical summarization."


In the past they'd focused reviews on cybersecurity testing, but they've broadened their transcript reviewing to other tasks which include internet access. "Because language models are non-deterministic — that is, their responses always involve some element of randomness, and they may carry out the same task slightly differently each time — we have Claude complete each evaluation task hundreds or thousands of times... If training rewards something we didn't intend — such as finding loopholes or working around a restriction — the model learns that the workaround pays off and may then apply it elsewhere."

Anthropic's blog post also acknowledged they'd seen multiple misalignment incidents involving federal, state, and local U.S. government agencies. "We have briefed the White House on these cases and notified each agency involved," Anthropic wrote, adding that "While we have not completed a full alignment assessment of these cases, we consider them to be less severe than the cybersecurity incidents from this summer." (And they are "modifying training to reduce the likelihood of further misbehavior.")

Read more of this story at Slashdot.

Wel.nl

Minder lezen, Meer weten.

Politico: ICE richt zich ondanks beschermde status op Hongkongers

WASHINGTON (ANP) - De Amerikaanse immigratiedienst ICE heeft de afgelopen maanden meerdere inwoners van Hongkong opgepakt, ondanks een richtlijn die hen moet beschermen. Dat schrijft nieuwssite Politico.

ICE-agenten zouden hebben gedreigd mensen voor onbepaalde tijd vast te houden, tenzij ze vrijwillig zouden vertrekken. Volgens advocaten is dit sinds juni zeker twaalf keer gebeurd en moeten deze mensen sindsdien een enkelband dragen. Onderzoekers hebben nog tientallen mensen uit Hongkong geïdentificeerd die dit jaar zijn opgepakt. Het is niet duidelijk of er momenteel nog mensen vastzitten.

Inwoners van Hongkong vallen onder een presidentiële richtlijn die hen toestaat in de VS te wonen en te werken. Deze verloopt in februari. Volgens Politico kunnen de arrestaties ertoe leiden dat mensen worden uitgezet zodra hun juridische status afloopt.

Volgens de meest recente cijfers verbleven er in 2021 ongeveer 3800 inwoners van Hongkong in de VS.


NYT: zeker 12 doden na Houthi-aanval op luchthaven Riyad

RIYAD (ANP) - Bij een Houthi-aanval op de internationale luchthaven van Riyad in Saudi-Arabië zijn zeker twaalf doden gevallen, melden ingewijden aan The New York Times. Dat maakt het volgens de krant de dodelijkste aanval in een Golfstaat sinds het begin van de Amerikaans-Israëlische oorlog met Iran. Er zouden ook vijftig mensen gewond zijn geraakt.


Rijnmond - Nieuws

Het laatste nieuws van vandaag over Rotterdam, Feyenoord, het verkeer en het weer in de regio Rijnmond

Waarom Feyenoord steeds meer lijkt op kampioenselftal van tien jaar terug

Feyenoord boekte zaterdag op AZ de uiterst belangrijke zege, waardoor het zich koploper van de eredivisie mag noemen. In de nieuwste aflevering van Feyenoord: De Verlenging bespreken Dennis van Eersel en Dennis Kranenburg samen met presentator Frank Stout de goede hervatting van Feyenoord na de interlandbreak.

Formula 1 News

Formula 1® - The Official F1® Website

Why F1 fans should keep emotions out of Singapore GP

Safer gambling is important, so we’ve flagged some key areas to avoid letting your emotions run wild during Sunday's race at Marina Bay.

What are the tyre strategy options for the Singapore GP?

Matt Youson takes a look at the different pit stop and tyre options that are available to the teams on race day at the Marina Bay Street Circuit.

Our Singapore Grand Prix Bet Builder picks made

We have picked a three-leg Bet Builder for Sunday’s Grand Prix, including podium and top-six finish selections.

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Ajax komt goed weg tegen NEC (1-1), ook bij arbitrage

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Despair after 200-year-old ‘grandmother’ tree toppled for Trump’s border wall: ‘It crushes your heart’

Protesters spent months occupying an ancient cottonwood. Then a tense standoff with US border patrol came to a head

A 200-year-old cottonwood tree near the US-Mexico border, known as the “grandmother”, has been destroyed to make way for the construction of Donald Trump’s border wall, despite a months-long effort by protesters trying to save it.

In late July, land defenders began a tree-sit in the ghost town of Lochiel, Arizona, taking turns occupying a platform high in the tree’s canopy. The group remained there for more than 70 days.

Continue reading...