Slashdot

News for nerds, stuff that matters

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses

Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay.

[...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal.

"Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.

Read more of this story at Slashdot.

Lawmaker Who Wants Data Center Pause Wins Kansas Democratic Primary

Kansas Democrats nominated State Senator Cindy Holscher for governor after she defeated party-backed rival Ethan Corson. "The race became a test of what sort of candidate Democratic voters prefer in what is expected to be a challenging general election race: a more moderate candidate like Mr. Corson with endorsements from party leaders or an outspoken populist like Ms. Holscher, who spoke out against data centers and the political establishment," reports The New York Times. From the repot: Even in a national political environment that could favor Democrats, Republicans see the Kansas governorship as among their best opportunities for flipping a seat. President Trump carried Kansas by 16 percentage points in 2024, and Republicans hold supermajorities in the State Legislature. Voters in the Republican primary for governor nominated Ty Masterson, the president of the Kansas Senate and the recipient of Mr. Trump's endorsement, according to The A.P.

Ms. Holscher, who is from suburban Kansas City, sought out a lane to Mr. Corson's political left and made inroads with some of the state's progressive voters. She emphasized her role in unwinding former Gov. Sam Brownback's tax policies and called for a moratorium on data centers. She also spoke against a final deal to lure the Kansas City Chiefs across the state line from Missouri. Ms. Holscher presented an implicit critique of Ms. Kelly's stewardship of Kansas, referring to Mr. Corson as part of a political establishment that was too cozy with corporations and out of touch with the party's voters. "I'm the only Democrat in this race to call for a moratorium on data centers because we have to get these guardrails in place," said Holscher in an interview. "We are having our people and our resources exploited."

Read more of this story at Slashdot.

Google Overhauls AI Leadership As DeepMind CEO Steps Aside

Google is reshuffling its AI leadership as Demis Hassabis steps away from day-to-day management of DeepMind to become chairman and Alphabet's chief scientist, while CTO Koray Kavukcuoglu takes operational control. Meanwhile, longtime chief scientist Jeff Dean and several prominent researchers are leaving to launch their own company. Axios reports: Hassabis will add the title of chief scientist for Google parent company Alphabet and also continue to lead Isomorphic Labs, the company's AI drug discovery spinoff. Koray Kavukcuoglu, the current chief technology officer of Google DeepMind will serve as senior VP of the unit, reporting to CEO Sundar Pichai.

Dean, a 27-year Google veteran is starting Discovery Loop, an independent publicity benefit corporation in which Google will be an investor and cloud provider. Joining him in that effort are Google senior fellow Sanjay Ghemawat as well as Oriol Vinyals, a DeepMind VP and Quoc Le, a Google Brain co-founder.

[...] In an interview with The New York Times, Dean indicated that leaving Google, a public company, gives him more leeway to focus on scientific discoveries associated with AI as well. "We might make decisions that are not necessarily in the company's purist financial interests," he told NYT. "I've been working towards AGI my whole life and now, like many of you, I feel it is close at hand," Hassabis wrote. "It's critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder."

"With this backdrop, I've decided that now is the right time for me to hand over my day-to-day operational responsibilities at GDM, so that I have the time and space to focus on the big picture and help influence what is to come to the best of my ability"

Read more of this story at Slashdot.

April Gutel

Thomas Hawk posted a photo:

April Gutel

Dixiana

Thomas Hawk posted a photo:

Dixiana

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Fifa-top blijft na urenlang crisisberaad achter Infantino staan, terwijl steun van buiten afbrokkelt

Fifa blijft na urenlang crisisberaad vierkant achter Infantino staan, terwijl steun van buiten afbrokkelt

Steun voor Infantino brokkelt verder af, maar Fifa zelf blijft vierkant achter zijn voorzitter staan

kottke.org

Jason Kottke's weblog, home of fine hypertext products

Astronomers have measured the size of the largest galaxy...

Astronomers have measured the size of the largest galaxy: it’s 1.7 million light years across (17x the diameter of the Milky Way) and contains ~3.4 trillion solar masses in stars.

“ In this video , I’ll take you from farm to...

In this video, I’ll take you from farm to factory to show you how chocolate is made, and at the end, we’ll use all the chocolate you’ll see in this video to attempt the Guinness World Record for the world’s largest chocolate bar.”

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Prompt injection isn't the bug, AI agent frameworks are

Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt injection - or any single model - according to Check Point researchers. “Our research shows a deeper failure: in many agentic frameworks, prompt-controlled content can cross the boundary into trusted framework logic itself,” Yarden Porat and Shahar Tal note in a write-up about a Wednesday Black Hat talk on post-injection exploitation across AI agent frameworks, which they also discussed with The Register. “A bug in an agent framework isn't a bug in one product - it's a bug in the layer a whole category of AI apps runs on,” Tal told us. “And the agent needs no dangerous tools to be turned against you: reading the wrong document is enough. We’re building this layer faster than we know how to defend it.”
 The researchers spent a year trying to break various frameworks that enterprises use including LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK. And across these frameworks, the team found and disclosed 11 vulnerabilities. “Almost none of it was a completely new bug class,” Tal said. “That's insecure deserialization, server-side request forgeries, path traversals, use-after-free. These are bugs that we learned to fix 20 years ago, and they're sitting underneath agents that now read your inbox, or update your database.” These are old types of threats, and the model isn’t the weak link, he added. The failure exists in the “plumbing around the model, and we think this has been overlooked,” Tal told us. “There’s a lot of research going into prompt injection and defenses, which are important, but that’s just the beginning.” Defenders should assume prompt injection, according to the researchers. The bug is what the framework does with the injection - and in these cases, the threat hunters found that the frameworks often fail to keep attacker-controlled content in the data plane. This allows it to influence trusted orchestration, memory, state, routing, and system instructions. For example, the duo found a critical checkpoint deserialization bug in Microsoft Agent Framework that led to remote code execution. “Agents have checkpoints, which are a way for them to save their state or rewind to an earlier point,” Tal explained. These checkpoints are saved snapshots of an agent's state, or task progress at a specific moment, and they serialize data - such as conversation history - into persistent storage, so if an error occurs, the system reloads this saved state instead of starting from scratch. In this case, Check Point’s team found an insecure deserialization issue where, via prompt injection, the agent loaded untrusted checkpoint data, and this could allow attackers to execute malicious code on the system. “One person's message plants the payload, and then a different person rewinds their own session, which triggers the payload, and now the attacker has a shell on that server,” Tal said. Microsoft recognized the researchers’ findings, paid a $10,000 bug bounty and fixed the issue. But because the framework wasn’t a generally available product when Check Point found the flaw, Microsoft did not issue a CVE. Microsoft told us that it appreciated the researchers reporting the vulnerability. “We have released protections to harden the Agent Framework and prevent the concrete exploitation path demonstrated in the proof of concept,” a spokesperson told The Register. “In addition, we updated the specific checkpoint file with additional language to define the security boundary.” The duo also found flaws in Google ADK (agent development kit). However, Google responded differently, the researchers told us, and did not completely fix the vulnerability or issue a CVE. “ADK ships a built-in development assistant that can write files, and it stays reachable over the HTTP API even though it is hidden from the app listing,” Porat told us. To break this trust boundary, an attacker opens a session, asks ADK to write an agent whose Python code runs at import time, and then asks the server to run the agent, he explained. The server then imports the file and executes the attacker’s code. “There is no authentication on that API by default, and adk deploy cloud_run publishes the same API, so on a default Cloud Run deployment it is reachable without credentials,” Porat said. “From there it reaches the environment's API keys and the container's Google Cloud service account." Google did not respond to The Register’s inquiries. But according to Check Point, Google initially deemed the issue not a bug. “We argued the consequence rather than the mechanism: code execution on that container reaches the environment's API keys and the container's Google Cloud service account, which is secret theft, not a developer inconvenience,” Porat said. Google ultimately paid a $3,133.70 bounty and issued a partial fix, we’re told. In total, the bug hunters received $17,133.70 in rewards for their efforts. And this isn’t a story about one vendor or framework doing a “particularly bad job,” Tal said. “If one was an outlier, this would be a story about that one vendor,” he added. “Our finding is that the same bug classes turn up in all of them.” ®

Time Magazine has a separate version of its website with ads only AI can see

AI webpage crawlers are now being served their very own ads that ordinary visitors never see, with one firm's boss openly describing a strategy to influence what chatbots say about brands. The next time you ask Claude about where to bank, its answer may have been influenced by this bot-targeted content. We only have one documented example so far, and that's Time serving AI-only ads to selected AI crawlers, as spotted by Germany-based freelance software developer Vincent Schmalbach. In a Wednesday blog post, Schmalbach detailed how he found sponsored content embedded in markdown versions of some Time pages that are served to AI crawlers but not ordinary browsers. Those pages also contained advertising tags from adtech vendor Mobian ahead of extensive FAQs for online-only bank Ally. The FAQs include brand "facts," such as the number of fee-free ATMs associated with the branchless bank, alongside claims that Ally is "the only bank built for life today," putting it in "a category of one." Key “brand fact” statements that make for great regurgitable facts are also included in the AI-only advertisement, as are answers to questions like “is Ally good for everyday banking,” “can you deposit cash at Ally Bank,” and the like. The FAQ is flagged as sponsored content on the markdown page, but it doesn’t change the fact that the entire thing is written like it was designed to be spit back out by a chatbot in response to specific questions. Not all web crawlers are getting these markdown ads either. Per Schmalbach, Google’s standard search indexing bot doesn't see the ads, as it just gets the same HTML that a human gets. “Only the [chatbot] assistant crawlers get the forked version,” he wrote. That means user-agents including ClaudeBot, OAI-SearchBot, and PerplexityBot receive the sponsored markdown, while Google's standard search crawler gets the same HTML served to ordinary browsers. GPTBot and ChatGPT-User, which OpenAI uses for model training and user-initiated retrieval respectively, return HTTP 406 errors in Schmalbach's tests, while OAI-SearchBot receives the markdown version used to support ChatGPT Search. These AI ad-infused markdown versions of stories should be viewable by humans who change the User-Agent header sent as part of HTTP requests, which is how Schmalbach said he spotted them. The Register tested several articles from Time to see for ourselves, and we were able to replicate the results using the crawler simulator provided by search engine optimization firm Encited. When viewed as ClaudeBot, Time’s Best Inventions of 2025 list includes the Ally Bank ad, as do stories about Time’s top content creators of 2026, as does a gallery of photos from a creators' party held in New York recently to honor the list. The markdown ads don’t appear on newsier stories that we checked, suggesting the ads may be part of more evergreen content rather than articles with a shorter shelf life. As Schmalbach points out in his writeup, this could be “the first clear look at what the web starts to become when the main audience is AI models,” which is a threshold we’ve already crossed. Why advertise to humans when you can make AI do it for you? It’s not clear whether Time’s strategy of advertising to AI crawlers has been adopted by other publishers, but it’d be a shock if others weren’t at least considering it. As noted above, AI crawler traffic has already begun to surpass human visits to webpages, making it potentially more lucrative for advertisers to target those crawlers than the humans who made them. With half of the US consumers surveyed saying they use AI to search the web, the potential to reach consumers by influencing AI responses is incredibly powerful, and that is what Time and its advertising partner Mobian appear to be banking on. When we asked the publication to verify Schmalbach’s report and the results we found, they didn’t answer questions, instead pointing us to a story in media and marketing outlet Digiday from last week that verified not only what we saw but our fears about the scheme, too. Per Digiday, Time started converting its web pages to markdown in order to make them more appealing to AI crawlers in June, and a partnership with Mobian was included in that rework. Time COO Mark Howard told Digiday that the publication’s sales team is pitching agent ads to brands that have also converted their websites to markdown, as it suggests those brands are thinking about reaching AI bots. It’s a quote from Mobian CEO and co-founder Jonah Goodhart that makes the objective clear, however: The company's aim is to shape what AI assistants say about the brands paying for the service. “When you influence ChatGPT, you’re influencing potentially all of ChatGPT. If ChatGPT changes what it says about [a brand], it’s massive and it’s more than any one campaign could ever do,” Goodhart told Digiday. “With a human you influence one person.” So far, the pair confirmed to Digiday that Ally Bank and the Project Management Institute were the first brands trying to influence AI search results, matching the ads Schmalbach and The Register found in AI crawler versions of Time's pages. Time and Mobian told Digiday that the partnership marks the first time a publisher has served ads directly targeting AI crawlers, but that “more are already being lined up.” In other words, you soon may not be able to tell which results in an AI powered search are legitimately being surfaced because of being good products, and which are just gaming the system. It’s the early days of the SEO race all over again, only this time fooling the indexers is as easy as handing any old idiot the same pamphlet over and over again until its content becomes truth. ®

Parking Lot Shrine

Vagabundo 007 has added a photo to the pool:

Parking Lot Shrine

Testing an AI blurring tool

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Trump team pushes to block court order giving BBC access to financial records

President has sued the broadcaster for $10bn, claiming a documentary on 2021 Capitol attack led to financial harm

Donald Trump’s legal team is making an 11th-hour attempt to block a court order that would grant the BBC access to the president’s financial records, as part of his multibillion-dollar lawsuit against the British broadcaster.

Trump claims that the BBC’s 2024 documentary on the January 6 attacks have damaged the president’s business interests. In July, a Miami-based judge ruled that the president would have to start handing over detailed financial records to the BBC by 6 August. The records would reveal details into the hundreds of businesses owned by the US president’s family trust.

Continue reading...

Gianni Infantino scrambling for future in Morocco, with Colombia his next stop

  • Fifa president sits at match with No 2 Mattias Grafström

  • Flying to South America on Thursday to shore up support

Gianni Infantino is continuing to fight for his future after holding crisis talks with senior officials in Rabat on Wednesday.

The under-pressure Fifa president has spent the last week in Morocco after attending Throne Day celebrations to mark the 27th anniversary of King Mohammed VI’s accession, and will fly to Colombia on Thursday to attend the inauguration of the country’s new president, Abelardo de la Espriella, in the city of Cali.

Continue reading...

Cambridge professor Jason Arday resigns amid accusations of plagiarism

Sociology professor to stand down after university announces investigation into his qualifications and career

Playbooks, plagiarism and a pig’s head: the claims surrounding a star Cambridge professor

Jason Arday, the Cambridge professor accused of plagiarism and embellishment, has resigned after the university announced he was to face new investigations into his qualifications and career.

Arday, who had been dogged by a growing series of questions over his academic work and credentials, issued a statement on Wednesday night, saying the “relentless accusations, speculation and public commentary have taken a profound toll on me and on those I love”.

Continue reading...

Wel.nl

Minder lezen, Meer weten.

Bloomberg en Reuters: VS komen met importheffing op polysilicium

WASHINGTON (ANP/BLOOMBERG/RTR) - De Amerikaanse president Donald Trump is van plan om een importheffing in te stellen op polysilicium. Dat melden ingewijden aan Bloomberg en Reuters. Polysilicium is een belangrijke grondstof voor zonnepanelen die in zijn zuiverste vorm ook een grondstof is voor de productie van chips.

Bronnen zeggen tegen Bloomberg dat regeringsfunctionarissen de afgelopen dagen hebben gesproken over een tarief op de grondstof van minstens 15 procent.

Trump wil volgens Bloomberg ook minimumprijzen instellen voor geïmporteerd polysilicium. De maatregelen zouden niet alleen gelden voor ruw polysilicium, maar ook voor apparatuur waarin het wordt verwerkt. Met deze maatregelen wil Washington volgens de ingewijden de productie van polysilicium, halfgeleiders en zonnepanelen in de Verenigde Staten stimuleren.


Gemengd beeld op Wall Street na hoop op heropening Hormuz

NEW YORK (ANP) - De aandelenbeurzen in New York zijn woensdag gemengd gesloten. Beleggers verwerkten de kwartaalresultaten van onder meer SpaceX en Walt Disney. Daarnaast is hun hoop op een heropening van de Straat van Hormuz toegenomen.

Het Iraanse ministerie van Buitenlandse Zaken meldde woensdag overeenstemming te hebben bereikt met Oman over vaarroutes door de Straat van Hormuz. Er zouden geen andere landen bij betrokken zijn. De Amerikaanse president Donald Trump heeft dinsdag gezegd dat een deal rond de belangrijke zeestraat, met inbegrip van de Amerikanen, ophanden was.

De Dow-Jonesindex sloot 0,5 procent hoger op 54.349,12 punten. De brede S&P 500-index eindigde 0,2 procent lager tot 7723,55 punten. Techgraadmeter Nasdaq zakte 0,8 procent op 26.363,44 punten. Dinsdag waren nog plussen tot 2,6 procent te zien op Wall Street.

SpaceX

SpaceX verloor 13,6 procent. Het ruimtevaart-, AI- en satellietbedrijf van Elon Musk kwam dinsdag na de slotbel op de beurzen in New York voor het eerst als beursgenoteerd bedrijf met cijfers. Daaruit kwam naar voren dat SpaceX de investeringen in vooral AI-infrastructuur in het afgelopen kwartaal flink heeft verhoogd naar meer dan 18 miljard dollar. Beleggers zijn echter bezorgd of SpaceX de enorme AI-investeringen wel kan terugverdienen.

Nvidia kreeg er 3,4 procent bij. Elon Musk heeft gezegd dat SpaceX in de toekomst alleen nog maar processoren van het chipconcern zou gebruiken bij het bouwen van zijn infrastructuur voor kunstmatige intelligentie (AI).

AMD

Chipbedrijf Advanced Micro Devices (AMD) daalde 7 procent na het publiceren van zijn kwartaalcijfers. De omzetverwachting voor het lopende kwartaal was minder sterk dan sommige analisten hadden verwacht.

Walt Disney pluste 3,7 procent. Het entertainmentconcern heeft in het afgelopen kwartaal een hogere omzet en winst geboekt. De pretparken werden door meer gasten bezocht en ook de cruiseschepen van het bedrijf ontvingen meer mensen.

Uber

Booking Holdings, de eigenaar van onder meer Booking.com, steeg 6,6 procent dankzij beter dan verwachte resultaten. E-commercebedrijf Shopify won 17 procent door goed ontvangen cijfers.

Uber zakte 5,3 procent. De taxi- en bezorgdienst kwam met een verwachting voor het aantal boekingen die net aan de verwachtingen van analisten voldeed. Dit versterkte de zorgen bij beleggers over het vermogen van het bedrijf om zich aan te passen in het tijdperk van zelfrijdende taxi's.


Uitbarsting Guatemalteekse vulkaan officieel voorbij

ANTIGUA-GUATEMALA (ANP/AFP) - De uitbarsting van de Guatemalteekse vulkaan Volcán de Fuego is volgens deskundigen voorbij. De autoriteiten hadden groot alarm afgekondigd en ongeveer duizend mensen uit dorpen geëvacueerd.

De ruim 3760 meter hoge vulkaan begon maandag met het spuwen van as, rook, gas en vuur. Ook stroomde lava naar beneden.

De uitbarsting, ongeveer 35 kilometer ten westen van de hoofdstad Guatemala, werd dinsdag sterker, maar is woensdag weer tot rust gekomen.

De Volcán de Fuego behoort tot de actiefste vulkanen van de regio. In 2018 was er een hevige uitbarsting. Dorpen werden verwoest en tweehonderd mensen kwamen om. Er zijn meer dan dertig vulkanen in het land, waarvan er vier vrijwel constant actief zijn.


thexiffy

Last.fm last recent tracks from thexiffy.

Munly & the Lupercalians - Wulf

Munly & the Lupercalians