Slashdot

News for nerds, stuff that matters

Ring Says New Encryption Limits What It Can Give Police

Ring is rolling out a new default encryption system called TAKE, or "Throw Away the Key Encryption," that rotates video keys every five minutes and permanently deletes Ring's copy after 24 hours. The system is designed to preserve cloud features such as smart alerts and AI video search while limiting what Ring can provide under legal process to non-video account information and encrypted footage. The Verge reports: Ring says TAKE uses unique, rotating encryption keys for your footage, stored in a secure enclave and accessible only under strict conditions -- based on the features you enable on your account. Currently, footage captured by Ring cameras is encrypted in transit to the cloud and at rest, and then decrypted for Ring to process for those smart features. With TAKE, the encryption keys change for every five minutes of footage. Ring stores copies of those keys to decrypt the footage, but throws away each copy within 24 hours, "leaving you with the keys and full control of your videos," according to Ring.

TAKE was developed using Messaging Layer Security, an open standard from the Internet Engineering Task Force, according to Ring. The company says it is "inspired by the privacy principles of E2EE (end-to-end encryption)," which Ring offers on some of its cameras. However, the two systems work differently. With E2EE, Ring never has the keys and can't process your video for cloud-based features. Both options are available on newer cameras that encrypt on-device, and you can switch between the two. Older cameras encrypt at cloud ingress and only support TAKE.

According to a white paper the company published today, Ring's copy of those keys is managed inside an AWS Nitro Enclave, to which Ring's access is restricted by "access controls, cryptography, and hardware isolation." The company claims there is no persistent storage and no way for a Ring employee to access it. The stored keys can only be unlocked by the enclave through cryptographic attestation that proves it's running the exact software image Ring approved. The enclave releases a temporary key when an enabled service requests it. When asked about what happens if Ring is subpoenaed by law enforcement, a spokesperson for the company said: "Where TAKE is enabled, Ring will only be able to provide non-video information (such as basic subscriber information) and encrypted video files in response to the valid legal process. We have updated our Law Enforcement Guidelines to reflect this change."

Read more of this story at Slashdot.

Claude, Codex, and Hermes Installed Unowned Code Inside Corporate Networks

An anonymous reader quotes a report from Ars Technica: Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents [including Claude, OpenAI's Codex, and Nous Research's Hermes]. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.

The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site's content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here. "The trust model is broken," Alon Hertz, one of the researchers, wrote in an interview. "Agents treat vendor docs as ground truth and don't question them -- and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer -- SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today's guards don't cover it."

"An agent doesn't distinguish between a page and a command," the researchers wrote Thursday. "Everything it reads is input, and every input is a potential instruction. Which means the entire corpus of published data that agents are now wired to consume has silently become an execution surface -- and almost none of it carries the integrity guarantees we apply to actual code."

Read more of this story at Slashdot.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Premier League: 10 things to look out for this weekend

Liverpool need midfield nous, Michael Carrick is already under pressure and Villa can bid farewell to Enzi Konsa

Enzo Maresca has a shiny new £85m midfielder he could select for a debut but, at 18 years old, he may want Ayyoub Bouaddi to have a bit of time watching on from the bench to learn about the Premier League from his elders. The Moroccan may not have anticipated one of those to be a centre-back by trade. Marc Guéhi will be eager to make a triumphant return to Crystal Palace and may well have the opportunity to do so from central midfield, where he played last weekend in the victory over Bournemouth, scoring the equaliser. The centre-back was a surprise selection in the blocker role next to Elliot Anderson, but equipped himself admirably and was not limited to the dirty work, often being found in more advanced positions in open play and happy to have the ball at his feet. His long-term future is unlikely to be outside of defence but further proof of Guéhi’s adaptability will be a positive for Maresca, as a long season awaits. Will Unwin

Crystal Palace v Manchester City, Friday 8pm (all times BST)

Liverpool v Nottingham Forest, Saturday 12.30pm

Bournemouth v Everton, Saturday 3pm

Coventry v Hull, Saturday 3pm

Tottenham v Newcastle, Saturday 5.30pm

Continue reading...

Atlético Madrid chief insists Júlian Alvarez will ‘never, ever’ be sold to Barcelona

  • Miguel Ángel Gil Marín accuses Barça of ‘dishonesty’

  • Arsenal have also been linked with Argentina forward

Atlético Madrid’s chief executive appeared to slam the door on Barcelona’s pursuit of Júlian Alvarez on Thursday. Miguel Ángel Gil Marín accused the Catalan club of dishonesty and insisted the Argentina forward would “never, ever” be sold to them.

Speaking to Spanish broadcaster Movistar Plus, Gil Marín delivered a blistering response to ⁠Barcelona’s president, Joan Laporta, who had said on Wednesday that ​his club remained “very interested” in signing Alvarez.

Continue reading...

Senator calls for criminal investigation of RFK Jr after Guardian report

Newly obtained records indicate health secretary lied about Samoa trip during Senate confirmation hearings last year

A senior Democratic senator is calling for a criminal investigation into the US health secretary, Robert F Kennedy Jr, following reporting by the Guardian that indicated he lied during Senate confirmation hearings last year.

Ron Wyden of Oregon said: “RFK’s platform is built on lies and grifts that leave a trail of dead children in their wake. There are consequences for lying to Congress.”

Continue reading...

thexiffy

Last.fm last recent tracks from thexiffy.

Test Dept. - The Emigrant

Test Dept.

Faith No More - Jizzlobber

Faith No More

The Residents - The Aging Musician (edit)

The Residents

Excitement Level Zero

Thomas Hawk posted a photo:

Excitement Level Zero

Mystery Hill, Gatlinburg, Tennessee

Thomas Hawk posted a photo:

Mystery Hill, Gatlinburg, Tennessee