kottke.org

Jason Kottke's weblog, home of fine hypertext products

John Thomson’s photos of China (1860s-70s) ....

John Thomson’s photos of China (1860s-70s). “Unlike many other early photographers he didn’t spend all his time photographing palaces and ruins. He also captured a lot of daily life including peasants, merchants, and criminals.”

Nederland krijgt precies wat het niet wil in de Brusselse begrotingsdiscussie: meer geld, minder vernieuwing

Cyprus heeft als roulerend EU-voorzitter een begrotingsvoorstel gepresenteerd. Volgens critici, waaronder Nederland, is daarbij te weinig terechtgekomen van een voornemen voor een kleinere begroting. Ook een beloofde modernisering van het budget hapert.

In Dallas is voetbal overal, maar kaartjes voor het WK zijn nauwelijks te betalen

In Dallas, de eerste speelstad van het Nederlands elftal komende zondag tegen Japan, is de liefde voor sport enorm. Behalve de grote Amerikaanse sporten is ook voetbal populair. ‘Er is hier vrijwel niets anders te doen.’


Varen langs Hitlers roeitribune in het kielzog van Theodor Fontane

In het idyllische rivierenlandschap van de Spree en de Dahme is de schrijver Theodor Fontane overal aanwezig en is de geschiedenis extra voelbaar.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Mexico v South Africa: World Cup 2026 opening match – live

⚽️ Kick-off time: 1pm local/8pm BST/3pm EDT/5am AEST
⚽️ Player guide | Bracketology | Wallchart | Email Daniel

“That ITV studio is spectacular,” reckons Kev the Poet. “Almost as spectacular as the nark-off between Roy Keane and anyone else. The BBC is going to have The Ghost Of Barry Davies coming out of the Manchester Ship Canal to compete.”

It is – it’s outdoors on the Hudson, with a sensational view of Manhattan. But I’d take Barry Davies coming out of anywhere.

Continue reading...

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Microsoft's worst 'Nightmare' unleashes BitLocker bypass 0-day

Nightmare Eclipse, the prolific zero-day vulnerability hunter with an axe to grind against Microsoft, released yet another exploit late Wednesday that the researcher claims will spawn a command prompt that provides total access to the BitLocker volume. This bug, called GreatXML, was “an accidental discovery,” according to the researcher, who said it only took four hours to find. They claim this exploit (published on GitHub and Git-based code-hosting platforms) can bypass BitLocker on any system that has ever run a Microsoft Defender Offline scan at any point in the past. GreatXML comes just a day after Nightmare released exploit code for RoguePlanet, which allows local privilege escalation and leads to SYSTEM-level control over an affected machine. This brings the researcher’s zero-day count to eight. The earlier six - RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma - all have patches as of this week’s Patch Tuesday event. Redmond on Wednesday told The Register that it is aware of RoguePlanet, and “actively investigating the validity and potential applicability of these claims.” The Windows giant didn’t immediately respond to our inquiries about GreatXML, including when it planned to issue a patch. Microsoft has said none of the vulnerabilities were reported via its official channels prior to being made public. The company also banned Nightmare’s earlier GitHub account, and seemingly threatened legal action before dialing back its rhetoric after steep backlash from the security community. Nightmare Eclipse, who some researchers suggest is an ex-Microsoft employee, harbors a very personal grudge against the Windows giant and its communications with bug hunters. They have promised to keep the zero-days coming, but waffle on the timing. Last month, the researcher pledged a big July 14 drop: “I will make sure your bones are shattered that day,” and then added, “nothing will be released this June (or maybe I will release smtg, depending on circumstances).” On Tuesday, they changed course. “I will be unable to mass disclose zerodays in July 14th, RoguePlanet took way more time than expected and truly drained me. I might take a break but I can't say for sure what I will be doing for next month, maybe it's nothing, maybe it's smtg.” A day later, Nightmare released the “accidental” GreatXML BitLocker bypass. According to the researcher, the BitLocker bypass first requires copying “unattend.xml” and the “Recovery” directory to the root of the recovery partition. The next step is rebooting into WinRE by Shift-clicking Restart. “If everything was done correctly, a shell with unrestricted access to the bitlocker volume will spawn,” Nightmare wrote. Also, if the scan hasn’t even been initiated on the Windows system, first you’d need to either log in and initiate it, or “figure out a way to boot into WinRE in offline scan state.” Security sleuth Will Dormann followed Nightmare’s steps to reproduce GreatXML, and said the writeup seems “flawed.” In his testing, Dormann said the command prompt appeared the next time a Defender Offline scan ran. “And in order to trigger a Microsoft Defender Offline scan, you both need to be logged in to Windows, and also have admin credentials,” he wrote on social media. “And if you've already got that level of access, you can just turn off bitlocker.” “The writeup for GreatXML suggests that the prerequisite is that Windows Defender Offline has been executed at some point in the past,” Dormann added. “And that after planting two files in WinRE, all you need to do is [Shift]-reboot into WinRE, and Windows will automatically go into Microsoft Defender Offline scan mode. But this is not the case in any of the 3 lineages of Win11 that I have handy.” ®

Slashdot

News for nerds, stuff that matters

OpenAI Says China Launched Influence Campaign To Shape US Attitudes On AI Datacenters

An anonymous reader quotes a report from Politico: China was likely behind an online influence operation to sway U.S. perceptions of artificial intelligence technology and reshape the debate in Washington around the infrastructure needed to support it, according to research from OpenAI published Wednesday. OpenAI said it caught the influence campaign because China-backed operatives were using ChatGPT to create content for the social media campaign. [...] OpenAI's researchers identified two clusters of ChatGPT users "likely originating from China" who used the AI chatbot to generate social media content "in support of apparent covert influence operations" promoting certain narratives about AI. This includes claims that data center build-outs are raising electricity costs for the average American family and that President Donald Trump has weaponized tariffs to keep the U.S. ahead in the global tech race. These accounts have since been banned, the report said.

One cluster of users asked ChatGPT to generate images and comments pushing these narratives. These comments were then posted on social media by "batches of accounts" posing as Americans, [said Ben Nimmo, principal investigator of intelligence and investigations at OpenAI]. Another cluster identified by researchers used AI to generate social media content criticizing the Trump administration's tariffs as an attempt to "dominate technological competition." Prompts used for this campaign were submitted in Simplified Chinese and asked that AI-generated content not include Chinese President Xi Jinping and focus solely on Trump -- a possible tell that China was behind the operation, according to the report. Nimmo said that the influence campaign amplified existing public backlash in the U.S. against the creation of new AI data centers, which has resulted in dozens of proposed moratoriums at the local, state and national level. "Neither campaign appears to have gained much authentic engagement," Nimmo said. "They're important for what they reveal about the intentions of influence operators from China, and the narratives they're testing and seeking to amplify, but not for the impact."

Read more of this story at Slashdot.

thexiffy

Last.fm last recent tracks from thexiffy.

Dead Can Dance - The Fatal Impact

Dead Can Dance

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Word ik als belegger in de toekomst niet te zwaar belast?

Liveblog oorlog Iran. Trump: 'Geplande aanvallen en bombardementen op Iran gaan niet door, deal op komst'

Social

En daarrrrr is de zoekgeraakte Vredespresident alweer! Vanavond wil Donald Trump alleen vuurwerk zien bij de opening van het WK. Op Truth schrijft hij dat er op het hoogste niveau met Iran overeenstemming is over de belangrijkste punten voor een DEAL. Voor de volledigheid: "Gebaseerd op het feit dat de besprekingen met de Islamitische Republiek Iran naar het hoogste niveau van de Iraanse leiding zijn gebracht en goedgekeurd, heb ik, als President van de Verenigde Staten van Amerika, de geplande aanvallen en bombardementen tegen Iran vanavond geannuleerd. De besprekingen en laatste punten zijn, zowel in concept als in grote details, goedgekeurd door alle betrokken partijen, inclusief de Verenigde Staten, Israël, Saoedi-Arabië, VAE, Qatar, Turkije, Pakistan, Bahrein, Koeweit, Jordanië, Egypte, en anderen. De Marineblokkade zal in volle kracht en werking blijven totdat deze Transactie is afgerond — Tijd en plaats van de ondertekening worden binnenkort aangekondigd." De beloofde HARDE KLAP blijkt dus vooral een keiharde handjeklap met de ayatollah en z'n islamitische broeders.