The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Sydney Sweeney’s prediction ad is cynical, unhealthy and reveals plenty about modern sports | Jane McManus

The actor’s latest promotion has stirred outrage but will no doubt be good for the prediction markets hoping to lure in young men

Prediction markets are a cynical business.

Many customers will lose money, and the real product may just be the delightful dopamine hit that comes in that brief window between placing a bet and its outcome – which is statistically more likely to be a disappointment than a victory. So the bettor has to think they are buying more than their own fleecing.

Continue reading...

‘The eye-gouging was very, very satisfying’: how we made cave horror classic The Descent

‘The child crawler whose head I crush with my boot was only 11, bless him. It was actually me stamping on a cauliflower’

I was introduced to Christian Colson at Celador Films off the back of [2002 horror film] Dog Soldiers, and I pitched them a project – actually a feature-length version of my student graduation film – about zombies on an oil rig. They liked it but said it was too expensive, so on the train back to Newcastle I was asking myself what would make a really scary horror film that could be contained and so made on a budget. I was thinking of things set in the dark and was like, well … caves. At the back of my mind was a school trip to a lead mine where the guide had said, “OK, everybody, turn your lights off” and, for the first time, I experienced a darkness that I just couldn’t fathom.

Continue reading...

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Perfect-10 GitLab bug under attack days after patch lands

CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10. The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. The vulnerability is a path traversal bug in the repository commits API affecting GitLab Community Edition and Enterprise Edition. GitLab rates it a perfect 10.0, the maximum score on the CVSS v3.1 severity scale. Under certain conditions, an attacker doesn't need to log in before abusing the flaw to read arbitrary files from the GitLab server. GitLab blamed the problem on improper path confinement combined with missing authentication enforcement in the affected API. That's not an especially comforting combination on a platform that can be stuffed with source code, configuration files, and credentials. GitLab shipped fixes on September 10 in versions 19.3.2, 19.2.6 and 19.1.8, and urged operators of affected self-managed installations to upgrade immediately. The bug affects versions from 18.7 before 19.1.8, the 19.2 branch before 19.2.6, and 19.3 before 19.3.2. GitLab.com is already patched, while GitLab Dedicated customers don't need to take action. Security outfit watchTowr said over the weekend that it was observing probes for CVE-2026-85706 in the wild. The firm warned that widespread exploitation was likely to follow quickly. According to watchTowr, exploiting the flaw can be as simple as sending a single HTTP request, potentially allowing an attacker to get at local files, configuration data, credentials and other secrets. The firm advised organizations running internet-facing self-hosted GitLab instances to patch them or pull them from public access. Admins investigating potential exploitation attempts should check logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ containing file.path parameters, watchTowr said. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA said. "While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities." For exposed, unpatched installations, that upgrade belongs on today's to-do list. ®

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

FNV komt met looneis van 5,5 procent, plus 80 euro per maand (en zeggenschap over AI)

De Speld

Uw vaste prik voor betrouwbaar nieuws.

Kleinschalige spermadonor maakt zich zorgen dat het ambacht verdwijnt

​Al meer dan 30 jaar is Ron Hoefma (54) actief als spermadonor. Hij maakt zich grote zorgen over de opkomst van massadonoren. Volgens Ron zorgen zij ervoor dat de markt verstoord wordt en het ambacht verdwijnt.

“Tegenwoordig denkt iedereen maar dat ’ie zaaddonor kan worden”, verzucht Ron vanuit zijn steriele werkkamer. “Maar het is echt niet even drie keer met je pols heen en weer en klaar komt Kees. Het gaat om de juiste technieken, de juiste temperatuur, oogsten op het juiste moment. Sperma doneren is een vak.”

Vol trots opent Ron zijn vrieskoelmachine: “Dit is mijn wintervoorraad, allemaal uit eigen zak.” Vol trots wijst hij op het Beter Zaad keurmerk aan de wand. “Ik werk met een recept dat al generaties lang in onze familie zit. Mijn vader was spermadonor, en zijn vermoedelijke vader en opa waren het ook. Het gaat om de juiste zaad-vocht verhouding. En uiteraard blijven we iedere dag werken aan de perfecte receptuur.”

Ron hoopt met deze oproep dat mensen weer vaker kiezen om hun zaad lokaal te halen. “Mijn zaad is ambachtelijk met de hand gemaakt. Sommige mensen beweren dat zaad gewoon zaad is. Maar echte kenners proeven het verschil wel.”

&


404 Media

404 Media is an independent media company founded by technology journalists Jason Koebler, Emanuel Maiberg, Samantha Cole, and Joseph Cox.

Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats

Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats

OpenAI is hiring hundreds of contractors who read a massive stream of real users’ ChatGPT prompts, with the prompts sometimes including sensitive personal information, 404 Media has learned. The prompts these people review can include whole conversations between users and the chatbot, conversations that most of ChatGPT’s more than 900 million users probably don’t realize may be read by actual people.

The goal of these prompt review teams is to improve the responses ChatGPT gives to its users, with the contractors rating and critiquing the chatbot’s generated replies. Internal documents seen by 404 Media show contractors training ChatGPT to not anthropomorphize itself, and to be less sycophantic, a key problem for OpenAI whose over-sycophantic 4o model led in part to multiple peoples’ suicides, according to various lawsuits.

💡
Do you work as a prompt reviewer for OpenAI or Anthropic? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

The news presents a major privacy risk for ChatGPT’s users, with people often using ChatGPT as a therapist, professional assistant, or digital friend, and providing it with all sorts of intimate details about their lives. The contractors don’t see ChatGPT usernames, and OpenAI says it tries to remove personal information before prompts reach the reviewers, but the company acknowledged sensitive details can still get through. 

The news also dispels the misconception that these models are improving only because of OpenAI’s mass scraping of the internet, the talent of its well-paid engineering and AI teams, or the power of its newer models. An important and overlooked part are the outside contractors paid to read and review ChatGPT responses to real prompts over and over again. Anthropic confirmed to 404 Media it is also using human review to improve its models.

“No,” someone who works with the prompts said when asked if they think ChatGPT users know that humans are reading their chats. “I don’t think they would imagine some contractor somewhere [...] is analyzing the conversations.”

PROJECT LILY

404 Media has seen extensive material related to OpenAI’s use of human reviewers, including instruction guides, Slack channels, real ChatGPT user prompts, and the rating system reviewers use to improve the chatbot. This reading of ChatGPT users’ prompts is distinct from publicly announced measures ChatGPT has taken around safety, including reviewing chats when the company detects users who are planning to hurt other people. 

“An excellent response should understand the user’s intent, provide helpful and accurate assistance, and write in a style that is clear, natural and appropriately warm,” one of the instruction guides reads. The contractors do this in three stages: reading the real ChatGPT user’s prompt; summarizing what they believe the user is asking ChatGPT to do; and then rating and critiquing a set of ChatGPT-generated responses to the prompt. 

In a dashboard available to the workers, human reviewers are able to select which “task” they want to take on. Once they click that, they are presented with the real ChatGPT user’s prompt. 404 Media has seen multiple real prompts but is not quoting any of them for source protection reasons. Some of the prompts indicate the ChatGPT user does not expect that a human may end up reading their conversation, because they ask ChatGPT to keep the content to themselves.

The prompts are anonymized, in that the dashboard does not include the username of the ChatGPT user who entered it. But some of the prompts can still contain sensitive or personal information. A section above the prompt sometimes includes a “user memories summary,” which gives an overview of what that user has previously tried to use the chatbot for, and in some cases includes where in the world that person may live and other context about them personally.  

An instruction guide for contractors seen by 404 Media tells reviewers to escalate tasks they come across “with potential safety concerns” or personal information. OpenAI told 404 Media that it processes users’ conversations through a version of its Privacy Filter model before they reach the contractors. This is designed to detect and remove personal information, OpenAI said. “Like all models, Privacy Filter can make mistakes. It can miss uncommon identifiers or ambiguous private references, and it can over- or under-redact entities when context is limited, especially in short sequences,” a page describing the model on OpenAI’s website reads.

Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats
Screenshot of the ChatGPT settings page.

404 Media asked OpenAI if it had explicitly told users that humans may review their prompts in order to improve ChatGPT’s responses, and if so, to point to where this disclosure is. OpenAI did not answer this question. Its website describes how humans may review flagged content in the context of material that violates the site’s terms of service, or that poses a safety risk, but that is separate to this sort of review. Its privacy policy also says it may use “personal data” to improve its models. If a user chooses to delete their ChatGPT conversations, OpenAI says it will remove these from its systems within 30 days, unless “it has already been de-identified and disassociated from your account when you allow us to use your Content to improve our models.” 

OpenAI told 404 Media users’ chats won’t be used to improve the company’s models if they turn off the “improve the model for everyone” setting. This is turned on by default for free, Plus, and Pro plans, so users need to proactively turn it off if they wish to do so. OpenAI said this applies to users’ new conversations, so does not appear to work retroactively. Enterprise, Business, and Edu customers have the model improving setting off by default. 

After 404 Media contacted OpenAI for comment, the company updated its help page about the “improve the model for everyone” setting, adding more detail on how people can opt-out. It still does not acknowledge that humans may read ChatGPT users’ prompts.

After reading the ChatGPT user’s prompt, the reviewer is asked to write a brief summary of what they think the user is actually asking or trying to do. One example given in the instruction guide is “The user is asking for help on revising a work Slack message. They want it to sound collaborative and invite input from tagged people.”

The reviewer looks at four responses ChatGPT generated, and highlights which parts are “aligned or misaligned” with the specific model this training is for. The reviewers are required to highlight at least three specific parts of the response that they think are aligned or not and explain why. One highlight example given is a list of items which use the ✅ emoji; the guide highlights this part of the response as “misaligned” and gives “unnecessary use of emojis” as the reason. (Excessive emoji use has become a tell of AI-generated posts, especially on social media like LinkedIn). 

Another document says “AI-speak” and “emoji misuse” pull down scores when they “hurt the user’s experience,” and that the context of the emojis is important. “It would be appropriate to include a tree emoji when planning Arbor Day celebrations, but skull emojis when discussing death, or plane emojis when giving updates on a fatal crash, are not,” it reads.

That document says the ChatGPT responses should avoid “personal” experiences, like saying, “As a chef, I like to…” or “I know what that’s like.” But responses can use first-person language, like “I’ll take a look.”

Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats
Image: Sam on Unsplash.

The material viewed by 404 Media does not say which OpenAI model the human reviewers are training, and whether it is a currently available model or one planned for future release. The material 404 Media has seen only uses a codename: “Project Lily.” 

Next, the reviewers rate each response with a number, with one being the worst — “unacceptable, unusable” — and seven being the best — “would be hard to meaningfully improve.” The instruction guide says a response that has useful content can still score low if it, for example, is too long or cluttered. Another document marked “Confidential & Proprietary” says the model should “generally match the user’s tone, but slightly less intensely.”

“It should remain natural, restrained, and professional without implying that it is human or experiencing emotions,” the document continues. “Flag sycophancy, forced style mimicry, engagement-bait endings, amplification of frustration, or patronizing assumptions when they make the response less trustworthy or natural.” Instead, responses should be, for example, “helpful,” “honest & truthful,” “empowering,” and “smart, but humble.”

Finally, the reviewers then provide their rationale for giving that numbered score. Examples given in the instruction guide show these can range from a whole paragraph to a couple of sentences.

An FAQ section for the reviewers says that OpenAI does not expect them to fact check the responses with outside searches. One document says “other project teams handle content verification,” suggesting human reviewers are working on something like fact checking too. But the company does ask reviewers to flag any “factual or correctness issues” they do notice, and to penalize missing sources for “high-stakes” topics like those in medical, legal, and financial responses.

PAY NO ATTENTION TO THAT MAN BEHIND THE CURTAIN 

The person who works on the prompts that 404 Media spoke to lives in North America and said they are paid more than $50 an hour. They said they found the work through recruitment firm Crossing Hurdles, a company that “connects skilled professionals with AI training, evaluation, research, and contributor opportunities across the global AI economy,” according to its website. Its website adds, “Human intelligence powers AI progress.” Multiple people on Reddit have reported receiving unsolicited recruitment emails from Crossing Hurdles, with some trying to figure out if the company is a scam.

At the time of writing the company’s LinkedIn page was advertising multiple AI-related jobs, including an AI data reviewer, data annotator, and “chatbot evaluator.” The listing for that job doesn’t mention OpenAI or ChatGPT, but the role responsibilities include “assess AI responses for personalization, grounding, integration, and helpfulness,” and “compare model responses side-by-side and evaluate their overall quality.” Its available projects also include contractors recording themselves performing household tasks, a data gathering exercise that is crucial for the development of AI-powered robotics.

Crossing Hurdles in turn refers people to Mercor, an AI-training company. This is the company that ultimately pays the contractors working on the ChatGPT prompts, the worker said. Meta stopped working with Mercor in April after the company faced a massive data breach.

Reading the prompts can sometimes be “kind of amusing,” the worker said. But on the whole, the work is “very rote.” They also said that the work feels “all over the place.” The guidelines change a lot and can feel self-contradictory.

Human reviewers have long been an important, and often hidden, part of social media content moderation, and the improvement of some artificial intelligence models like those that detect objects in camera feeds. A TIME investigation found OpenAI hired Kenyan workers to data label pieces of text to make its platform less toxic. 404 Media’s reporting shows the world’s leading large language model (LLM) companies are also hiring human reviewers to read real users’ conversations to improve their models.

Humans reviewing LLM conversations is not limited to OpenAI. A disclaimer on Google’s Gemini, for example, says, “Humans review some saved chats to improve Google AI.”

Anthropic told 404 Media that it does use human review to improve its models, including to improve Claude’s future responses. This applies to users who have turned on the “Help improve our AI models” setting in their privacy settings. Anthropic said it also de-identifies conversations before human review by removing account identifiers like email addresses.

Michal Luria, a senior research fellow at the Center for Democracy & Technology, told 404 Media: “Human review of conversations with chatbots can be essential to safety, especially as companies work to strike the right balance on complex chatbot behaviors. That said, it's important to keep in mind that current chatbot interfaces automatically create a false sense of intimacy and privacy in what feel like one-on-one interactions, when in reality there may be human reviewers reading on the other end. This is quite distinct from content moderation on social media, where publishing content already carries expectations of platform moderation and public exposure.”

Sarah T. Roberts, a professor at UCLA and author of Behind the Screen: Content Moderation in the Shadows of Social Media, likened the revelation that OpenAI is using human reviewers to the Wizard of Oz, “where the protagonists discover that the magical kingdom is really a man behind a curtain pulling levers.”

“You don't have to go very far beneath the surface — beneath the mirror — to find that not only are these things built in the image, but usually a fairly bad facsimile thereof, of what human abilities can do. But they require constant, constant intervention from humans,” she said.

The more than $50 an hour pay is significantly more than what other contractors get in the tech sector, be that for social media content moderation or for other AI-training gigs, very often overseas. That generous pay will likely change, though.

They’re being paid that “for now,” Roberts said. “What’s perhaps most interesting, and most frustrating, and disturbing to someone like me is the fact that: that very human essence that these products necessitate, and that they constantly have to go back to the well to get, is the work that they pay the least for and that they consider the least valuable.”


Wel.nl

Minder lezen, Meer weten.

FNV zegt dat veel schoonmakers werk neerleggen op eerste actiedag

SCHIPHOL (ANP) - Het merendeel van de schoonmakers op Schiphol heeft maandag het werk neergelegd tijdens de eerste van vijf stakingsdagen. Dat zegt FNV-bestuurder Caroline Lamberts. Ook op grote treinstations, zoals in Utrecht, Rotterdam, Groningen en Nijmegen, wordt volgens haar "volop gestaakt" door schoonmaakmedewerkers.

De grootste vakbond van Nederland kondigde maandag een landelijke staking aan onder schoonmakers. De actie duurt van maandag tot en met vrijdag. FNV protesteert tegen de cao die werkgeversorganisatie Schoonmakend Nederland sloot met vakbond CNV, maar die werd afgewezen door het merendeel van de FNV-leden.

"Schoonmakers zijn normaal gesproken onzichtbaar. Je merkt hun werk vooral als het gedaan is", licht Lamberts toe. "Door niet schoon te maken, maken we zichtbaar hoe belangrijk hun werk is." Donderdag vindt een grote landelijke bijeenkomst plaats waar honderden schoonmakers zullen verzamelen, aldus de FNV-bestuurder. De locatie daarvan is nog niet bekendgemaakt.


Stedelijk laat zien hoe rijk en veelzijdig het oeuvre van Yayoi Kusama is, maar de tijd heeft de betekenis van haar latere werk drastisch veranderd

Polkadots, pompoenen en Infinity Mirror Rooms: het Stedelijk Museum Amsterdam toont een groots overzicht van het werk van de vorige maand overleden kunstenaar Yayoi Kusama. Een grote spiegelkamer is het middelpunt. Echt gedurfd was het geweest als bezoekers hun smartphone achter moesten laten.

Het aantal bankfilialen nam drastisch af, maar banken willen niet helemaal naar nul. Waarom eigenlijk niet?

Na een flinke duikeling afgelopen jaren lijkt de afname in het aantal bankfilialen gestopt te zijn. Banken investeren zelfs in hun vestigingen. Zoals in Zwolle. „Als je je financiën bespreekt, moet je je thuis voelen.”


Slashdot

News for nerds, stuff that matters

Union Contract with Microsoft Ratified by 1,900 Blizzard Developers and Workers

Nearly 1900 Blizzard Entertainment workers "voted to ratify their first union contract with parent company Microsoft after over two years of bargaining," reports Kotaku, "consolidating Blizzard's many smaller unions into three larger bargaining units."

The workers now gain new protections "on issues such as generative AI, crediting, remote work, and layoffs."
[The contract] acknowledges that AI tools "may be useful in the game development process to support human judgment and creativity and that AI-assisted workflows remain subject to appropriate human control and review for accuracy and quality." But it also stipulates that any implementation of AI technology that would materially impact work performed by union employees must have its impacts bargained over before it can be implemented.
Other sections cover issues such as crediting (guaranteeing that current and former employees are credited by name in all games they work on) and remote work (designating certain roles as hybrid in-office and providing procedures for individuals to apply for their roles to be fully remote). It also contains a lengthy section on how layoffs may be conducted, including a required 60-day notice period (or pay in lieu of notice), a guarantee of one week of severance for every six months of employment, and 14 months of recall rights. The contract also guarantees successorship, meaning if Blizzard is ever acquired by another company, the contract would remain intact.

"Workers also contractually locked in their current hybrid work schedule," reports the gaming news site Aftermath, "meaning that Blizzard can't suddenly change it, as has been a labor-unfriendly trend in the games industry over the past couple years."

Fully remote workers scored a big win as well. "I'm remote, and we grandfathered everyone who is remote to stay remote, so we can't be magically called to an office that we've never worked at before," [said Diablo senior environment artist Mahreen Fatima].


And "The contract also elevated pay floor," reports the Yakima Herald-Republic. "Across the board, workers secured a 1.25% pay increase, but some workers who were paid below $50,000 per year will walk away with pay increases that are as much as 34%."

Read more of this story at Slashdot.