The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Greens must avoid ‘capture by extremists and racists’, says party MP

Ellie Chowns says vote for ‘Zionism is racism’ policy by 0.4% of members shows party processes are not working

A Green Party MP has said she wants to make sure her party is not “vulnerable to capture by extremists and racists” amid the continuing fallout from the “Zionism is racism” vote.

The party faces a political maelstrom over its policy decision last week to treat Zionism, the movement for a Jewish state, as any other form of racism, and to back a single Palestinian state over a two-state solution. The motion was passed at the annual party conference with just over 1,000 votes, approximately 0.4% of the total membership.

Continue reading...

‘They looked like two curtain-twitchers, though not very subtle ones’: Peter Crome’s best phone picture

The photographer was walking home in London when he caught the attention of a pair of canine snoops

Walking home after dropping his little girl at school, Peter Crome sensed he was being watched. A former professional ballet dancer now living in London, he had supplemented his income with photography work for 20 years. “But since having my daughter, my Nikon gear has sat idly by,” he says. “I got so used to lugging my heavy equipment around with me, it’s been quite refreshing to go somewhere just with a phone and still come back with wonderful pictures. My iPhone has also been a blessing for keeping in touch with family back home in Sydney,” Crome adds.

The cause of his disquiet that day was, to his happy surprise, these two dogs. “It was such a comical moment,” he says. “They looked like two curtain-twitchers, though not very subtle ones. I liked how they were perfectly framed with the different layers of window frames, and the brickwork and hedge provided some pleasing textures, but it was the disapproving expression on their faces that made the photo for me.”

Continue reading...

UK must not be beholden to foreign AI, says head of Alan Turing Institute

George Williamson says ‘national resilience’ is key focus of ATI amid US and China’s runaway leadership in field

The UK must not become dependent on foreign AI systems that can be switched off at short notice and must develop its own versions of the technology, according to the head of the Alan Turing Institute.

The country needs a stronger domestic position in AI in response to the US and China’s runaway leadership in the field, with “national resilience” a key focus for ATI said George Williamson.

Continue reading...

Jon Davis on job titles in the age of AI – cartoon

Continue reading...

Don’t rebuild the dam: Ukrainian experts urge Unesco to protect site uncovered by Russian sabotage

As archaeologists find treasure trove along new floodplain, conservationists say another Nova Kakhovka would be ecocide

On a warm September day, a group of underwater archaeologists and researchers were boiling water for tea on their campfire on the banks of the Dnipro River, tents pitched on the sandy shoreline. They were three weeks into an archaeological expedition of the waters around Khortytsia – a rocky island 12.5km long and 2.5km wide that lies just downstream of the city of Zaporizhzhia, in south-eastern Ukraine.

High above the island, a Shahed drone whined on its way. A Ukrainian interceptor, and small-arms fire from the ground, tried, unsuccessfully, to bring it down. The archaeologists ignored it. This is life as normal, 28 miles (45km) from the combat zone in Russia’s war on Ukraine.

Continue reading...

Vijftien doden bij Russische aanval op Zaporizja, inslagen op meerdere plekken

Bij een Russische luchtaanval op de Oekraïense stad Zaporizja zijn in de vroege ochtend van zaterdag ten minste vijftien doden gevallen. Dat melden Oekraïense autoriteiten.

Wel.nl

Minder lezen, Meer weten.

Burgemeester Oldebroek aanwezig bij hijsen regenboogvlag

WEZEP (ANP) - In de Gelderse gemeente Oldebroek is zaterdag bij de Kruiskerk de regenboogvlag gehesen door de dominee. Dat gebeurde in het dorp Wezep, dat onder Oldebroek valt, in het bijzijn van burgemeester Tanja Haseloop-Amsing. "Iedereen is voor mij gelijk en daar wilde ik heel graag op deze manier uiting aan geven", zegt Haseloop-Amsing na afloop.

In Oldebroek is dit jaar een conservatief college aangetreden dat het lhbtq+-beleid heeft ingetrokken en afgesproken heeft dat het hijsen van de regenboogvlag door de gemeente niet meer gebeurt.

Dat de burgemeester besloot toch aanwezig te zijn bij het hijsen van de vlag bij de kerk leverde haar "positieve en negatieve reacties" op. "En die mogen er allemaal zijn. Het is aan mij om te proberen zoveel mogelijk van die meningen te begrijpen en te duiden." Ze benadrukt dat ze burgemeester is "van alle inwoners" en dus ook van mensen die tot de lhbtiq+-groep behoren.

Bij het hijsen van de vlag waren volgens initiatiefnemer Kjeld Mooi ongeveer tweehonderd mensen aanwezig.


Tesla geeft rijassistent in Europa een nieuwe naam na kritiek

DEN HAAG (ANP/DPA) - Tesla heeft de naam van zijn rijassistentiesysteem in Europa veranderd, na jarenlange kritiek dat het Amerikaanse bedrijf het systeem te veel zou hebben aangeprezen als volledig zelfrijdend. Op de websites van de fabrikant van elektrische auto's in Nederland en andere Europese landen heet het systeem nu 'Tesla Assisted Driving'. Daarmee wordt direct duidelijk dat het slechts om een rijassistentiesysteem gaat.

Tesla noemde het systeem voorheen 'Full Self-Driving (Supervised)'. Het bedrijf heeft jarenlang tegengesproken dat die naam de indruk wekt dat de auto volledig autonoom kan rijden, terwijl de bestuurder op elk moment klaar moet staan om de controle over te nemen en volledig aansprakelijk blijft.

Tesla schrapte eerder al de oorspronkelijke naam 'Autopilot' voor zijn basistechnologie voor rijassistentie, na juridische geschillen.


Politie onderzoekt of spoorbrand sabotage of kattenkwaad is

ROTTERDAM (ANP) - De politie hoopt onder meer op basis van camerabeelden meer te weten te komen over de brandstichting bij het spoor in de nacht van vrijdag op zaterdag. Waarom in een technische ruimte bij een spoorbrug brand is gesticht, is nog onduidelijk.

De politie houdt met meerdere scenario's rekening, waaronder sabotage en kattenkwaad. Vooralsnog zijn er geen verdachten in beeld. De recherche en de Forensische Opsporing doen onderzoek.

Ook ProRail moet nog onderzoeken hoe groot de schade is die de brand heeft veroorzaakt. Dan zal ook pas duidelijk worden hoelang de herstelwerkzaamheden gaan duren voordat er weer treinen over het traject kunnen.

Treinuitval

ProRail kreeg rond 02.30 uur een melding binnen van een storing aan de spoorbrug bij de Schuttevaerweg in Rotterdam Delfshaven. Toen een aannemer van de spoorbeheerder ter plaatse kwam, werd duidelijk dat er brand was gesticht.

Door de brand rijden in ieder geval heel de zaterdag geen treinen tussen de stations Rotterdam Centraal en Delft Campus.


Ambassadeur VS wil stappen bondgenoten na sancties tegen ICC

DEN HAAG (ANP) - De Amerikaanse ambassadeur in Nederland, Joe Popolo, staat achter de nieuwe sancties van de Verenigde Staten tegen het Internationaal Strafhof (ICC), dat in Den Haag is gevestigd. "Ik roep onze nauwste bondgenoten op om gebruik te maken van deze mogelijkheid om de Amerikaanse zorgen weg te nemen", laat Popolo zaterdag weten op X.

De Amerikaanse minister van Buitenlandse Zaken Marco Rubio kondigde de maatregelen vrijdag aan, kort nadat de voormalige ICC-rechter Navi Pillay de Nobelprijs voor de Vrede had gekregen. De details van de sancties zijn nog niet bekend en ze gaan pas over een half jaar in.

Popolo zegt waardering te hebben voor "het sterke standpunt van minister Rubio om Amerikanen en Amerikaanse soevereiniteit te verdedigen".

De Verenigde Staten liggen al jaren in de clinch met het ICC. Dat vervolgt onder meer verdachten van misdaden tegen de menselijkheid. In 2002, onder de toenmalige president George W. Bush, namen de Verenigde Staten een wet aan waarmee het land zichzelf het recht gaf om Nederland binnen te vallen om Amerikaanse verdachten te bevrijden uit gevangenschap van het ICC.


NSC doet volgend jaar niet mee aan provinciale verkiezingen

BREDA (ANP) - NSC doet niet mee aan de provinciale verkiezingen van volgend jaar. Dat heeft waarnemend partijvoorzitter Ronald de Bruin gezegd tijdens een ledenbijeenkomst in Breda. Het partijbestuur heeft volgens hem bij alle provinciale besturen gepolst of er voldoende "draagvlak en draagkracht" is om deel te nemen. "Uiteindelijk is het antwoord daarop in alle provincies geweest: nee."

NSC kende een stormachtige opkomst. De partij van oud-CDA'er Pieter Omtzigt kwam in 2023 vanuit het niets met twintig zetels in de Tweede Kamer en nam samen met PVV, VVD en BBB deel aan het kabinet-Schoof. Na de val van dat kabinet verloor de partij amper twee jaar later al haar zetels. Bij de gemeenteraadsverkiezingen van vorig jaar deed NSC in een aantal gemeenten mee, maar zonder succes.

"Komen wij nog een keer in de gelegenheid om de kiezer te vragen om een tweede kans?", vroeg De Bruin zich hardop af. "Vandaag zijn we daar niet toe in staat, maar we kunnen het ons niet veroorloven achterover te gaan zitten."


The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Two characters open up a world of typosquatting opportunities in Chromium browsers

Researchers say two characters available to typosquatters and phisherfolk can trick Chromium browsers into displaying lookalike URLs as genuine web addresses. Wangling a domain name to look an awful lot like that of a popular website is nothing new. We’ve all encountered phishing sites such as macrosoft[.]com and applle[.]com before in our daily struggles against spam. However, as browsers mature, new characters are always being made available for use. This opens up new opportunities for those whose languages contain characters/homoglyphs that aren’t ASCII-compliant, but it also introduces new ways for attackers to abuse display logic quirks in programs like Chrome and Edge. According to Ian Muscat and Leanne Briffa of Have I Been Squatted, there are still characters available to cyber-imposters that can reliably fool web users into trusting URLs that they certainly should not. The latest glyphs bypassing browser safety checks allow tricksters to run websites from a clearly fake domain name (when displayed in Punycode), although they appear just like the real deal in Unicode. The characters of note, in this case, are ө, which is found in various Cyrillic languages such as Kazakh, Mongolian, and Tatar, and the Latin K with hook, ƙ, used in Hausa and Karai-karai. Both are visually similar to the letters e/o, i, and k, respectively, and allowed the researchers to register 20 lookalike domain names. These included: aррӏө[.]com sрасөх[.]com oƙta[.]com niƙe[.]com Below are the URLs’ Punycode equivalents – how browsers should display them safely: xn--80a6aa68c8d.com xn--80a5aeq0fr0c.com xn--ota-f6a.com xn--nie-g6a.com You can try them out; they’re registered by Have I Been Squatted and are safe to visit. They take you to research demo pages set up by the researchers, and each page explains how exactly they bypass browser protections. Crucially, they all bypass the key security measures deployed by Chromium-based browsers. How the bypasses work Browsers deploy two main defense layers. The first is a set of seven sequential checks run by Chromium’s SafeToDisplayAsUnicode function, which check for a range of common spoofing methods. Vendors began introducing these checks in 2017 after researcher Xudong Zheng registered аррӏе.com – a domain consisting of all-Cyrillic characters. Chromium’s checks, which factor in a hardcoded list of known Cyrillic characters known to be used in place of Latin letters, can be seen as "all or nothing." Built to detect all-Cyrillic strings, the measure only takes action against domain names if every character in the string is on its hardcoded list. If one character is missing, the check is bypassed. Characters such as ө, ї, and ү, are known as “breakers,” as these are not present in the lookalike list, as of Chrome 154 (released to stable channel on September 22). Failing any of the seven display checks tells the browser that the characters are unsafe to display as Unicode and to instead display the Punycode, revealing just how dissimilar they are to the genuine domains they try to imitate. The second measure browsers take is to compare the domain name against a list of popular websites to see if it is trying to imitate one of them. In Chromium, these checks are handled by the GetSimilarTopDomain() function. This step converts a supplied domain name into a "skeleton," stripping its characters of diacritics, such as accents (ó becomes o), and checking the skeleton URL against a hardcoded list of popular websites. Chromium checks against almost 8,500, and if the skeleton matches any of them, then it displays Punycode. However, the Latin K with hook, ƙ, does not have an accent, and is added to the skeleton as a Latin k with an added combining mark, bypassing the security check. In this case, the skeleton is formed as: [o k ‘ t a . c o r n]. (The skeleton maps "m" to "rn"). Likewise, with аррӏө.com, the Cyrillic barred o retains its bar in the skeleton as a combining mark, meaning it does not match the genuine Apple domain. Its skeleton is formed as: [a p p l o - . c o r n]. Browsers are always working to stymie these tools of imposterment. Chrome 148 put an end to attackers being able to use ҏ and ӿ as breakers to imitate their Latin lookalikes, for example. The two main security checks are not the only lines of defense. Chromium also deploys warnings at the time of navigation called Safety Tips. An example domain that would bypass the two main checks is ínstagarm[.]com. The inflection on the beginning character is removed and what’s left is essentially the real Instagram domain with two letters swapped. The Instagarm domain does not match any of the hardcoded sites, nor does it contain any banned characters. In this case, Chrome will display one of two popups, asking the user if they meant to visit the genuine domain, warning that the current direction of travel appears fake. However, there are limits to this extra security layer. The warnings only trigger when an imitation domain is an exact-character match, a one-edit match, or a match with an adjacent swap from the genuine URL. Two or more changes, like with аррӏө[.]com, which has all-Cyrillic characters preceding the ".com," will not trigger these warnings. The warnings will also not trigger with domains consisting of fewer than five characters. Domains such as oƙta.com, which is only one edit from the real Okta, may not trigger defenses because of the one-edit rule and the fact that it is only four characters. Safety Tips also checks the skeleton against the sites users visit regularly, not just the hardcoded list of trusted sites. Frequently visited sites may trigger the same warnings, but for users who do not have a comprehensive visit history, the defense layer may fail. The defenses described here only apply to browsers. Email clients are even less picky with imitation domain strings. Websites like Gmail displayed each of the 20 domains HIBS fed the clients, which were a mix of lookalikes and genuine internationalized domain names (IDNs), as an attacker would want it to, all in Unicode. Outlook Web showed all 20 as Punycode, even the harmless ones, suggesting neither apply the right checks to properly inform users. To quantify the scale of the issue, the researchers looked at ICANN’s list of every .com domain. There are around 167 million of them, approximately 733,000 of which are IDNs, those that contain non-ASCII characters and are stored in Punycode form. The researchers took each of the IDNs and swapped their non-ASCII characters for ASCII equivalents to determine how many matches there were. They found around 162,000 pairs – IDNs that resemble plain ASCII domains. It should be said that this does not mean there are circa 162,000 typosquatted domains, just that many yield lookalikes. Some may be registered by businesses for defensive purposes; others may be owned by the same business that wants to operate multiple websites catering to different languages. However, organizations should be aware of the means available to typosquatters, and monitor registered domains accordingly. ®

TOKYO STATION, rain stops

ajpscs has added a photo to the pool:

TOKYO STATION, rain stops

東京で雨
OFF
© ajpscs

osanpo_2013

gnsk has added a photo to the pool:

osanpo_2013

TOKYO STATION, rain stops

ajpscs posted a photo:

TOKYO STATION, rain stops

東京で雨
OFF
© ajpscs

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Ik laat mannen niet meer door me heen praten, ik ben aan het woord

Early October, Tolmie garden. Young male king parrot changing plumage.

Lesley A Butler has added a photo to the pool:

Early October, Tolmie garden. Young male king parrot changing plumage.

Early October, Tolmie garden

Rijnmond - Nieuws

Het laatste nieuws van vandaag over Rotterdam, Feyenoord, het verkeer en het weer in de regio Rijnmond

Erasmus MC weer telefonisch bereikbaar na storing bij KPN

Het Erasmus MC is zaterdagmiddag weer telefonisch bereikbaar via de vaste nummers. Door een storing bij KPN was het ziekenhuis sinds vrijdagavond niet telefonisch bereikbaar. Er werd een tijdelijk noodnummer ingesteld. De zorg kon gewoon doorgaan.

Erasmus MC telefonisch niet bereikbaar door storing bij KPN

Het Erasmus MC is sinds vrijdagavond telefonisch niet bereikbaar via de vaste nummers. De oorzaak is een storing bij KPN. Het ziekenhuis heeft daarom een tijdelijk noodnummer ingesteld.

The Moscow Times - Independent News From Russia

The Moscow Times offers everything you need to know about Russia: Breaking news, top stories, business, analysis, opinion, multimedia

Rosatom Says it Wins Tribunal Ruling in Finnish Nuclear Plant Dispute

Rosatom said the International Chamber of Commerce agreed that a Finnish firm wrongly terminated the contract for a new nuclear power plant.