VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Olympisch kampioen Jutta Leerdam dit schaatsseizoen niet in actie

Olympisch kampioen Jutta Leerdam komt dit schaatsseizoen niet in actie

Golf van repressie in Turkije: politie arresteert tientallen lhbti-activisten

xiffy

Public posts from @xiffy@mastodon.nl

@Pepijn
Server software, lyrion of navidrome is mijn suggestie, een android touchscreen, voor beide servers is een app, orangesqueeze voor lyrion, ik gebruik navic voor navidrome.
Op je nas kan in elk geval lyrion draaien, ik gok navidrome zou ook moeten lukken.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Europe must build own AI or risk getting cut off by US or China, says ECB’s Lagarde

Central bank chief says continent’s AI dependency could give trade partners unprecedented leverage in negotiations

Europe must develop its own AI technology and build more datacentres in order to nullify the threat of being cut off by the US or China, according to the president of the European Central Bank.

Christine Lagarde said the continent needed AI models – the technology that powers AI tools such as chatbots – that were “good enough” to carry out most tasks and run from domestic datacentres. If Europe invests in its own AI tech, said Lagarde, “the threat of being cut off loses its force”.

Continue reading...

Bob Mackie, costume designer to stars daring to be noticed, dies aged 87

Famous for his flamboyant outfits, he helped celebrities including Cher, Tina Turner and Elton John cause a stir

Bob Mackie, the costume designer behind some of the most sexy and glamorous outfits worn by celebrities in the past 50 years, has died at the age of 87.

“He lived his 87 years to the fullest, fulfilling his dream of being a fashion and costume designer, which is all he ever wanted to do,” read a statement posted on his Instagram account. “His genius and extraordinary designs will live on forever, continuing to bring beauty into this world.”

Continue reading...

kottke.org

Jason Kottke's weblog, home of fine hypertext products

Rocky Sleep, You Watch, Question?

Project Hail Mary is already on my list of movies that I can just throw on in the backround while I do a bit of work or puttering around. (Not sure whether that’s an endorsement or not…I like the movie!) Anyhoo, if you get tired of the movie, you can watch Rocky sleep for 2+ hours with the PHM soundtrack playing in the background.

Tags: movies · music · Project Hail Mary · video

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

New hardware device can RAM into encrypted memory, expose your data

Computer security researchers have identified a design flaw in modern encryption hardware that allows access to protected memory in notionally confidential computing environments. But the attacker would need physical access to the victim system. Boffins affiliated with KU Leuven, ETH Zurich, Durham University, and Google have found that scalable memory encryption hardware fails to check whether the data in memory is fresh. As a result, they've been able to devise a small hardware interposer, dubbed DDRop, that when wired to an appropriate circuit board, interferes with DDR5 write operations. Unable to tell that memory isn't fresh, a protected VM becomes vulnerable to a replay attack that uses stale, attacker-selected data. They describe their work in a paper titled, "DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes." Their attack requires physical access and so it is relevant mainly in scenarios where confidential computing guarantees have been made to tenants by cloud service providers. "DDRop uses a custom-built 'interposer': a small, custom-designed circuit board, costing under $200, that sits between the processor and a memory module," explained Jo Van Bulck, a professor in the DistriNet lab at KU Leuven, Belgium, in an email to The Register. "It corrupts commands on the high-speed DDR5 memory bus to silently drop writes to encrypted memory. The protected VM keeps computing on old data that still decrypts perfectly. We are releasing the complete interposer design as open-source hardware." The attack breaks the integrity of Intel TDX, Scalable SGX, and AMD SEV-SNP, used in trusted execution environments (TEEs). Van Bulck and colleagues Jesse De Meulemeester, Stefan Gloor, Patrick Jattke, Daniel Moghimi, David Oswald, Martin Thompson, Kaveh Razavi, and Ingrid Verbauwhede developed a proof-of-concept attack on a current Intel TDX server. "By injecting maliciously crafted secure page-table entries, we can force any protected VM into debug mode and read out its private memory in plaintext," said Van Bulck. "Furthermore, writing to critical TDX metadata structures enables forged attestation reports, so that a backdoored VM appears trusted to the remote user." Both attacks, said Van Bulck, succeed deterministically in under two minutes without crashing the machine. Several of these researchers developed a similar attack on DDR4. But Van Bulck said this is the first active interposer attack on DDR5. "DDR5’s redesigned command bus prevents the address-aliasing tricks used by Battering RAM, and until now, only considerably weaker passive attacks had been demonstrated on DDR5: TEE.fail monitors the data bus using bulky, second-hand logic analyzers that are easier to detect and require slowing the memory bus to its lowest speed to observe ciphertext patterns, which can be masked in software," he explained. DDRop differs in that it alters DDR5 bus traffic at full speed. According to Van Bulck, it's the first attack to subvert TDX's trusted management interface without exploiting a software bug. It also reduces the cost of prior interposition attacks that took an estimated $170,000 in lab equipment to perform. There's no easy fix for Intel's and AMD's current scalable memory-encryption designs, said Van Bulck, and no simple software or hardware patch that can address the root cause. "Scalable memory encryption deliberately trades cryptographic freshness (e.g., available in early Intel SGX offerings supporting only 128/256 MB of protected memory) for the ability to protect large amounts of memory in cloud systems," he said. Noting that Intel's Simon Johnson recently discussed memory-interposer attacks at an industry conference, Van Bulck said that planned mitigations like "cache line versioning" still appear to be vulnerable to DDRop. In a security bulletin released on Monday, Intel acknowledged the DDRop disclosure and said the attack is out of scope for its cloud computing threat model. The company said it is "evaluating additional architectural hardening options and detection mechanisms as part of ongoing platform security improvements…" AMD also said the attack is out of scope and no mitigation is planned. ®

Formula 1 News

Formula 1® - The Official F1® Website

5 Winners and 5 Losers from Madrid

Lawrence Barretto picks out his winners and losers from the Spanish Grand Prix weekend

Slashdot

News for nerds, stuff that matters

No Rolling Power Outages for California Since 2020 - Thanks to 17,000 MW of New Battery Storage

"Californians just made it through the hottest August on record without having to endure any rolling power outages," reports the Los Angeles Times. In fact, the state hasn't implemented rotating power outages since 2020.

Because "Over the last few years, California has quietly but dramatically increased the resiliency of its electrical grid through a significant expansion in battery energy storage."

These batteries hold onto solar energy captured during the day, so it can be sent to the grid as demand peaks in the evening and morning, when most people are at home running air conditioners and other appliances.
During the August heat wave of 2020, the California Independent System Operator, which manages the flow of electricity for most of the state, declared a Stage 3 Emergency and hundreds of thousands of households lost power in rolling outages. At the time, the system had less than 100 megawatts of battery storage available, according to system spokesperson Jayme Ackemann. Today, it has more than 17,000 megawatts available....

According to Ackemann, the system seeks to add 20,000 to 25,000 megawatts of battery storage capacity by 2045 — the same year it has set a goal of achieving carbon neutrality. That means the state would remove as many carbon emissions from the atmosphere as it emits.


In recent years, California has steadily grown the share of electrical power generated by renewable sources — such as solar, wind, geothermal and hydropower — which bolstered the resiliency of the grid by increasing the overall amount of energy available. An uptick in people installing rooftop solar panels has provided an additional power boost, Ackemann said. In May, California became the first known large-scale power system in the world to have relied on more than 50% solar power for an entire month.... California's grid is also now integrated with electrical systems across much of the Western United States. This means that if there is an extreme heat event in Southern California, energy from a cooler area such as the Pacific Northwest can be imported to help meet regional demand. All of this has collectively helped the state's electrical system weather this year's long-lasting heat.

"Southern California continued to break temperature records this week when Long Beach and Anaheim reached a blistering 107 degrees and Escondido hit 112 degrees..."

Read more of this story at Slashdot.