Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 10 juin 2024Slashdot

Apple is Bringing RCS To the iPhone in iOS 18

Par : msmash
10 juin 2024 à 18:44
Apple has announced that its Messages app will support RCS in iOS 18. From a report: The new standard will replace SMS as the default communication protocol between Android and iOS devices. The move comes after years of taunting, cajoling, and finally, some regulatory scrutiny from the EU. Right now, when people on iOS and Android message each other, the service falls back to SMS -- photos and videos are sent at a lower quality, messages are shortened, and importantly, conversations are not end-to-end encrypted like they are in iMessage. Messages from Android phones show up as green bubbles in iMessage chats and chaos ensues.

Read more of this story at Slashdot.

Apple Unveils Apple Intelligence

Par : msmash
10 juin 2024 à 18:33
As rumored, Apple today unveiled Apple Intelligence, its long-awaited push into generative artificial intelligence (AI), promising highly personalized experiences built with safety and privacy at its core. The feature, referred to as "A.I.", will be integrated into Apple's various operating systems, including iOS, macOS, and the latest, VisionOS. CEO Tim Cook said that Apple Intelligence goes beyond artificial intelligence, calling it "personal intelligence" and "the next big step for Apple." Apple Intelligence is built on large language and intelligence models, with much of the processing done locally on the latest Apple silicon. Private Cloud Compute is being added to handle more intensive tasks while maintaining user privacy. The update also includes significant changes to Siri, Apple's virtual assistant, which will now support typed queries and deeper integration into various apps, including third-party applications. This integration will enable users to perform complex tasks without switching between multiple apps. Apple Intelligence will roll out to the latest versions of Apple's operating systems, including iOS and iPadOS 18, macOS Sequoia, and visionOS 2.

Read more of this story at Slashdot.

Apple Unveils macOS 15 'Sequoia' at WWDC, Introduces Window Tiling and iPhone Mirroring

Par : msmash
10 juin 2024 à 18:10
At its Worldwide Developers Conference, Apple formally introduced macOS 15, codenamed "Sequoia." The new release combines features from iOS 18 with Mac-specific improvements. One notable addition is automated window tiling, allowing users to arrange windows on their screen without manual resizing or switching to full-screen mode. Another feature, iPhone Mirroring, streams the iPhone's screen to the Mac, enabling app use with the Mac's keyboard and trackpad while keeping the phone locked for privacy. Gamers will appreciate the second version of Apple's Game Porting Toolkit, simplifying the process of bringing Windows games to macOS and vice versa. Sequoia also incorporates changes from iOS and iPadOS, such as RCS support and expanded Tapback reactions in Messages, a redesigned Calculator app, and the Math Notes feature for typed equations in Notes. Additionally, all Apple platforms and Windows will receive a new Passwords app, potentially replacing standalone password managers. A developer beta of macOS Sequoia is available today, with refined public betas coming in July and a full release planned for the fall.

Read more of this story at Slashdot.

Malicious VSCode Extensions With Millions of Installs Discovered

Par : msmash
10 juin 2024 à 17:23
A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to "infect" over 100 organizations by trojanizing a copy of the popular 'Dracula Official theme to include risky code. Further research into the VSCode Marketplace found thousands of extensions with millions of installs. From a report: Visual Studio Code (VSCode) is a source code editor published by Microsoft and used by many professional software developers worldwide. Microsoft also operates an extensions market for the IDE, called the Visual Studio Code Marketplace, which offers add-ons that extend the application's functionality and provide more customization options. Previous reports have highlighted gaps in VSCode's security, allowing extension and publisher impersonation and extensions that steal developer authentication tokens. There have also been in-the-wild findings that were confirmed to be malicious.

Read more of this story at Slashdot.

Mandiant Says Hackers Stole a 'Significant Volume of Data' From Snowflake Customers

Par : msmash
10 juin 2024 à 16:44
Security researchers say they believe financially motivated cybercriminals have stolen a "significant volume of data" from hundreds of customers hosting their vast banks of data with cloud storage giant Snowflake. TechCrunch: Incident response firm Mandiant, which is working with Snowflake to investigate the recent spate of data thefts, said in a blog post Monday that the two firms have notified around 165 customers that their data may have been stolen. It's the first time that the number of affected Snowflake customers has been disclosed since the account hacks began in April. Snowflake has said little to date about the attacks, only that a "limited number" of its customers are affected. The cloud data giant has more than 9,800 corporate customers, like healthcare organizations, retail giants and some of the world's largest tech companies, which use Snowflake for data analytics.

Read more of this story at Slashdot.

Microplastics Found in Every Human Semen Sample Tested in Study

Par : msmash
10 juin 2024 à 16:02
Microplastic pollution has been found in all human semen samples tested in a study, and researchers say further research on the potential harm to reproduction is "imperative." From a report: Sperm counts in men have been falling for decades and 40% of low counts remain unexplained, although chemical pollution has been implicated by many studies. The 40 semen samples were from healthy men undergoing premarital health assessments in Jinan, China. Another recent study found microplastics in the semen of six out of 10 healthy young men in Italy, and another study in China found the pollutants in half of 25 samples. Recent studies in mice have reported that microplastics reduced sperm count and caused abnormalities and hormone disruption. Research on microplastics and human health is moving quickly and scientists appear to be finding the contaminants everywhere. The pollutants were found in all 23 human testicle samples tested in a study published in May. Microplastics have also recently been discovered in human blood, placentas and breast milk, indicating widespread contamination of people's bodies. The impact on health is as yet unknown but microplastics have been shown to cause damage to human cells in the laboratory.

Read more of this story at Slashdot.

Study Finds a Quarter of Bosses Hoped Return-To-Office Would Make Employees Quit

Par : msmash
10 juin 2024 à 15:21
An anonymous reader shares a report: A study claims to have proof of what some have suspected: return to office mandates are just back-channel layoffs and post-COVID work culture is making everyone miserable. HR software biz BambooHR surveyed more than 1,500 employees, a third of whom work in HR. The findings suggest the return to office movement has been a poorly-executed failure, but one particular figure stands out - a quarter of executives and a fifth of HR professionals hoped RTO mandates would result in staff leaving. While that statistic essentially admits the quiet part out loud, there was some merit to that belief. People did quit when RTO mandates were enforced at many of the largest companies, but it wasn't enough, the study reports. More than a third (37 percent) of respondents in leadership roles believed their employers had undertaken layoffs in the past 12 months as a result of too few people quitting in protest of RTO mandates, the study found. Nearly the same number thought their management wanted employees back in the office to monitor them more closely. The end result has been the growth of a different office culture, one that's even more performative, suspicious, and divisive than before the COVID pandemic, the study concludes.

Read more of this story at Slashdot.

Micrsoft Confirms Cheaper All-Digital Xbox Series X As It Marches Beyond Physical Games

Par : msmash
10 juin 2024 à 14:46
Microsoft has announced a new lineup of Xbox consoles, including an all-digital white Xbox Series X with a 1TB SSD, priced at $450. The company is also retiring the Carbon Black Series S, replacing it with a white version featuring a 1TB SSD and a $350 price point. Additionally, a new Xbox Series X with a disc drive and 2TB of storage will launch for $600. The move comes as Microsoft continues to focus on digital gaming and subscription services like Game Pass, with reports suggesting that the PS5 is outselling Xbox Series consoles 2:1. The shift has led to minimal physical Xbox game sections in stores and some first-party titles, like Hellblade 2, not receiving physical releases. Despite rumors of a multiplatform approach, Microsoft maintains its commitment to its own gaming machines, promising a new "next-gen" console in the future, potentially utilizing generative-AI technology. Further reading: Upcoming Games Include More Xbox Sequels - and a Medieval 'Doom'.

Read more of this story at Slashdot.

Nokia Unveils 'Future of Voice Calls'

Par : msmash
10 juin 2024 à 14:02
Nokia CEO Pekka Lundmark made the world's first phone call using "immersive audio and video" technology, which improves call quality with "three-dimensional" sound. The technology, part of the upcoming 5G Advanced standard, makes interactions more lifelike and is the biggest leap forward in voice calling since monophonic telephony. Nokia aims to license the technology, but widespread availability may take a few years.

Read more of this story at Slashdot.

SpaceX Hopes to Eventually Build One Starship Per Day at Its Texas 'Starfactory'

Par : EditorDavid
10 juin 2024 à 11:34
SpaceX's successful launch (and reentry) of Starship was just the beginning, reports Space.com: SpaceX now aims to build on the progress with its Starship program as continues work on Starfactory, a new manufacturing facility under construction at the company's Starbase site in South Texas... "When you step into this factory, it is truly inspirational. My heart jumps out of my chest," Kate Tice, manager of SpaceX Quality Systems Engineering, said [during SpaceX's livestream of the Starship flight test]. "Now this will enable us to increase our production rate significantly as we build toward our long-term goal of producing one Ship per day and coming off the production line soon, Starship Version Two." This new version of Starship is designed to be more easy to mass produce, SpaceX CEO Elon Musk said on social media. Space.com argues that the long-term expansion comes as SpaceX "looks to use Starship to eventually make humanity interplanetary."

Read more of this story at Slashdot.

When Paying in Cash Costs Extra: America's Reverse ATMs Convert Money into Debit Cards

Par : EditorDavid
10 juin 2024 à 07:34
At a New York Yankees baseball game, one fan discovered its concession stand doesn't accept cash. "An employee directed him to a kiosk that could convert his greenbacks into plastic," reports the Wall Street Journal, where the fan, "fed $200 into the reverse ATM, which subtracted a $3.50 fee and spat out a debit card with a balance of $196.50." Paying with cash used to be a way to get a discount. These days it can often cost an extra $1 to $6 — the sort of transaction fees once limited to swiping a credit card or using an out-of-network ATM. Reverse ATMs like those at Yankee Stadium are now common at cashless venues and restaurants across the country as a way to cater to those who prefer paying in cash. People who want to pay their parking tickets, tolls, taxes or phone bills in cash, meanwhile, often learn that government agencies and businesses have outsourced that option to companies that usually charge a fee. All that can amount to a penalty on the people who prefer paying cash. Though it is more common to buy things with cards and mobile devices, cash remains the third-most popular way to pay, accounting for 16% of all payments in 2023, according to the Federal Reserve. That's down 2 percentage points from the year before, continuing a steady decline that accelerated during the pandemic. "It's unbelievable that we actually have to tell retailers, 'This is U.S. currency and it's something that should be accepted,' " said Jonathan Alexander, executive director of the Consumer Choice in Payment Coalition, a group of businesses and nonprofits lobbying for the continued acceptance of cash. There aren't federal laws that require businesses to accept cash. States like Colorado and Rhode Island and cities like New York banned cashless retail establishments after many stores shifted to card-only transactions to reduce the spread of Covid-19, speed up transactions and cut back on theft. In 2023, lawmakers in the House of Representatives and the Senate introduced bills requiring that businesses accept cash for all in-person purchases under $500, unless they provide devices like a reverse ATM that don't charge fees. The bills haven't passed. Cashless businesses can be a burden for older or lower-income shoppers who are less likely to have access to digital payments. They also pose challenges for younger people who haven't yet set up credit cards or bank accounts. The article includes the story of an 18-year-old who earned cash by babysitting, then went to a hockey game and "was charged a 50-cent fee after putting $20 into a reverse ATM...to order chicken nuggets and a bottle of water." (Others who prefer cash "say paper money is anonymous, helps them keep spending under control and is better for tips," the article adds noting that roughly six in 10 Americans use cash for at least some of their purchases, according to Pew Research Center.) The makers of one "reverse ATM" tell the Journal that whether or not someone gets charged a fee actually depends on what state they're in — and on the preferences of the venue that installed the ATM machine.

Read more of this story at Slashdot.

Teams of Coordinated GPT-4 Bots Can Exploit Zero-Day Vulnerabilities, Researchers Warn

Par : EditorDavid
10 juin 2024 à 04:44
New Atlas reports on a research team that successfuly used GPT-4 to exploit 87% of newly-discovered security flaws for which a fix hadn't yet been released. This week the same team got even better results from a team of autonomous, self-propagating Large Language Model agents using a Hierarchical Planning with Task-Specific Agents (HPTSA) method: Instead of assigning a single LLM agent trying to solve many complex tasks, HPTSA uses a "planning agent" that oversees the entire process and launches multiple "subagents," that are task-specific... When benchmarked against 15 real-world web-focused vulnerabilities, HPTSA has shown to be 550% more efficient than a single LLM in exploiting vulnerabilities and was able to hack 8 of 15 zero-day vulnerabilities. The solo LLM effort was able to hack only 3 of the 15 vulnerabilities. "Our findings suggest that cybersecurity, on both the offensive and defensive side, will increase in pace," the researchers conclude. "Now, black-hat actors can use AI agents to hack websites. On the other hand, penetration testers can use AI agents to aid in more frequent penetration testing. It is unclear whether AI agents will aid cybersecurity offense or defense more and we hope that future work addresses this question. "Beyond the immediate impact of our work, we hope that our work inspires frontier LLM providers to think carefully about their deployments." Thanks to long-time Slashdot reader schwit1 for sharing the article.

Read more of this story at Slashdot.

Birmingham's $125M 'Oracle Disaster' Blamed on Poor IT Project Management

Par : EditorDavid
10 juin 2024 à 01:44
It was "a catastrophic IT failure," writes Computer Weekly. It was nearly two years ago that Birmingham City Council, the largest local authority in Europe, "declared itself in financial distress" — effectively declaring bankruptcy — after the costs on an Oracle project costs ballooned from $25 million to around $125.5 million. But Computer Weekly's investigation finds signs that the program board and its manager wanted to go live in April of 2022 "regardless of the state of the build, the level of testing undertaken and challenges faced by those working on the programme." One manager's notes "reveal concerns that the program manager and steering committee could not be swayed, which meant the system went live despite having known flaws." Computer Weekly has seen notes from a manager at BCC highlighting a number of discrepancies in the Birmingham City Council report to cabinet published in June 2023, 14 months after the Oracle system went into production. The report stated that some critical elements of the Oracle system were not functioning adequately, impacting day-to-day operations. The manager's comments reveal that this flaw in the implementation of the Oracle software was known before the system went live in April 2022... An insider at Birmingham City Council who has been closely involved in the project told Computer Weekly it went live "despite all the warnings telling them it wouldn't work".... Since going live, the Oracle system effectively scrambled financial data, which meant the council had no clear picture of its overall finances. The insider said that by January 2023, Birmingham City Council could not produce an accurate account of its spending and budget for the next financial year: "There's no way that we could do our year-end accounts because the system didn't work." A June 2023 report to cabinet "stated that due to issues with the council's bank reconciliation system, a significant number of transactions had to be manually allocated to accounts rather than automatically via the Oracle system," according to the article. But Computer Weekly has seen a 2019 presentation slide deck showing the council was already aware that Oracle's out-of-the-box bank reconciliation system "did not handle mixed debtor/non-debtor bank files. The workaround suggested was either a lot of manual intervention or a platform as a service (PaaS) offering from Evosys, the Oracle implementation partner contracted by BCC to build the new IT system." The article ultimately concludes that "project management failures over a number of years contributed to the IT failure."

Read more of this story at Slashdot.

Hier — 9 juin 2024Slashdot

Virgin Galactic Completes Final 'Space Tourists and Research' Flight Before Two-Year Pause

Par : EditorDavid
9 juin 2024 à 22:44
"Virgin Galactic launched six people to suborbital space on Saturday, launching a Turkish astronaut and three space tourists," reports Space.com, "on what was the final voyage of the VSS Unity space plane." Unity, attached to the belly of its carrier plane Eve, took off from runway at Spaceport America in New Mexico at 10:31 a.m. EDT (1431 GMT) and carried to an altitude of 44,562 feet (13,582 meters) over the next hour, where it was dropped and ignited its rocket engine to carry two pilots and four passengers to space and back. The mission, called Galactic 07, reached an altitude of 54.4 miles (87.5 km) and marked the seventh commercial spaceflight by Virgin Galactic on Unity, which is being retired to make way for the company's new "Delta" class of spacecraft rolling out in 2026. "I will need much more time to try and process what just happened," Tuva Atasever, the Turkish Space Agency astronaut on the flight, said in a post-flight press conference, adding that the view of Earth was indescribable. "It's not something you can describe with adjectives. It's an experiential thing ... you just feel it in your gut." One of the space tourists was a principal propulsion engineer at SpaceX, who wore the flags of the U.S. and India on his spacesuit to honor both his home country and that of his parents. The other two were a New York-based real estate developer and a London-based hotel and resort investment strategy advisor. The flight landed 70 minutes later at 11:41 a.m. EDT (1541 GMT), according to the article, "marking only its seventh commercial spaceflight for Virgin Galactic and 12th crewed spaceflight overall." In all, Virgin Galactic flew the space plane just 32 times, including non-space test flights... "This vehicle was revolutionary," Virgin Galactic president Mike Moses said in the post-launch press conference. "We tested it, we flew it, we demonstrated and prove to the world that commercial human spaceflight is possible with private funding for private companies... Seven commercial space flights, a single vehicle flying six times in six months last year, that's groundbreaking," Moses said. "The fact that we can take this vehicle back to back to back on a monthly basis is is really revolutionary." The new Delta class of spacecraft will be able to fly at least twice a week, about eight times the rate of SpaceShipTwo, with Virgin Galactic planning to build at least two to start its new fleet. "We're going to field in 2026 two spaceships, our mothership Eve, that's 750 astronauts a year going to space," Moses said of the new fleet's flight capacity. "That's more than have gotten to space in the 60 year history of spaceflight to date...." Since 2018, Virgin Galactic has flown payloads as part of NASA's Flight Opportunities program and most recently was selected to be a contracted flight provider for NASA for the next five years. Phys.org reports that with the Delta-class rockets, "The future of the company is at stake as it seeks at long last to get into the black. Virgin is burning through cash, losing more than $100 million in each of the past two quarters, with its reserves standing at $867 million at the end of March." It also laid off 185 people, or 18 percent of its workforce, late last year. Its shares are currently trading at 85 cents, down from $55 in 2021, the year Branson himself flew, garnering global headlines. Saturday's flight also became "a suborbital science lab" for microgravity research, according to a statement from the company. Phys.org reports that during the flight, astronaut Atasever "wore custom headgear with brain activity monitoring sensors to collect physiological data, a dosimeter, and two commercially available insulin pens to examine the ability to administer accurate insulin doses in microgravity, Virgin said in a statement." And Virgin Galactic said their flight also carried "rack-mounted" autonomous payloads from both Purdue ("to study propellant slosh in fuel tanks of maneuvering spacecraf") and U.C. Berkeley ("testing a new type of 3D printing"), as well as "multiple human-tended experiments." "Discovery and innovation are central to our mission at Virgin Galactic," said Michael Colglazier, CEO of Virgin Galactic. "We're excited to build on our successful record of facilitating scientific experiments in suborbital space, and we look forward to continuing to expand our role in suborbital research going forward."

Read more of this story at Slashdot.

Big Copyright Win in Canada: Court Rules Fair Use Beats Digital Locks

Par : EditorDavid
9 juin 2024 à 21:44
Michael Geist Pig Hogger (Slashdot reader #10,379) reminds us that in Canadian law, "fair use" is called "fair dealing" — and that Canadian digital media users just enjoyed a huge win. Canadian user rights champion Michael Geist writes: The Federal Court has issued a landmark decision on copyright's anti-circumvention rules which concludes that digital locks should not trump fair dealing. Rather, the two must co-exist in harmony, leading to an interpretation that users can still rely on fair dealing even in cases involving those digital locks. The decision could have enormous implications for libraries, education, and users more broadly as it seeks to restore the copyright balance in the digital world. The decision also importantly concludes that merely requiring a password does not meet the standard needed to qualify for copyright rules involving technological protection measures. Canada's 2012 "Copyright Modernization Act" protected anti-copying technology from circumvention, Geist writes — and Blacklock's Reports had then "argued that allowing anyone other than original subscriber to access articles constituted copyright infringement." The court found that the Blacklock's legal language associated with its licensing was confusing and that fair dealing applied here as well... Blacklock's position on this issue was straightforward: it argued that its content was protected by a password, that passwords constituted a form of technological protection measure, and that fair dealing does not apply in the context of circumvention. In other words, it argued that the act of circumvention (in this case of a password) was itself infringing and it could not be saved by fair dealing. The Federal Court disagreed on all points... For years, many have argued for a specific exception to clarify that circumvention was permitted for fair dealing purposes, essentially making the case that users should not lose their fair dealing rights the moment a rights holder places a digital lock on their work. The Federal Court has concluded that the fair dealing rights have remained there all along and that the Copyright Act's anti-circumvention rules must be interpreted in a manner consistent with those rights. "The case could still be appealed, but for now the court has restored a critical aspect of the copyright balance after more than a decade of uncertainty and concern."

Read more of this story at Slashdot.

T2 Linux 24.6 Goes Desktop with Integrated Windows Binary Support

Par : EditorDavid
9 juin 2024 à 20:44
T2's open development process and the collection of exotic, vintage and retro hardware can be followed live on YouTube and Twitch. Now Slashdot reader ReneR writes: Embedded T2 Linux is known for its sophisticated cross compile features as well as supporting all CPU architectures, including: Alpha, Arc, ARM(64), Avr32, HPPA(64), IA64, M68k, MIPS(64), Nios2, PowerPC(64)(le), RISCV(64), s390x, SPARC(64), SuperH, x86(64). But now it's going Desktop! 24.6 comes as a major convenience update, with out-of-the-box Windows application compatibility as well as LibreOffice and Thunderbird cross-compiled and in the default base ISO for the most popular CPU architectures. Continuing to keep Intel IA-64 Itanium alive, a major, up-to-3x performance improvement was found for OpenSSL, doubling crypto performance for many popular algorithms and SSH. The project's CI unit testing was further expanded to now cover the whole installation in two variants. The graphical desktop defaults were also polished -- and a T2 branded wallpaper was added! ;-) The release contains 606 changesets, including approximately 750 package updates, 67 issues fixed, 80 packages or features added, 21 removed and 9 other improvements.

Read more of this story at Slashdot.

Upcoming Games Include More Xbox Sequels - and a Medieval 'Doom'

Par : EditorDavid
9 juin 2024 à 19:44
Announced during Microsoft's Xbox Games Showcase, Doom: The Dark Ages is id Software's next foray back into hell. [Also available for PS5 and PC.] Doom: The Dark Ages is a medieval spin on the Doom franchise, taking the Doom Slayer back to the beginning. It's coming to Xbox Game Pass on day one, sometime in 2025. Microsoft's first trailer for Doom: The Dark Ages shows the frenetic, precision gameplay we've come to expect from the franchise — there's a lot of blasting and shooting and a chainsaw. Oh, and the Doom Slayer can ride a dragon? "Before he became a hero he was the super weapon of gods and kings," says the trailer (which showcases the game's crazy-good graphics...) The 2020 game Doom Eternal sold 3 million copies in its first month, according to Polygon, with its game director telling the site in 2021 that "our hero is somewhat timeless — I mean, literally, he's immortal. So we could tell all kinds of stories..." Other upcoming Xbox games were revealed too. Engadget is excited about the reboot of the first-person shooter Perfect Dark (first released in 2000, but now set in the near future). There's also Gears of War: E-Day, Indiana Jones and the Great Circle, State of Decay 3, and Assassin's Creed Shadows, according to Xbox.com — plus "the announcement of three new Xbox Series X|S console options." [Engadget notes it's the first time Microsoft has offered a cheaper all-digital Xbox Series X with no disc drive.] "And on top of all that, we also brought the gameplay reveal of a brand-new Call of Duty game with Call of Duty: Black Ops 6." Meanwhile, Friday's Summer Game Fest 2024 featured Star Wars Outlaws footage (which according to GamesRadar takes place between Empire Strikes Back and Return of the Jedi, featuring not just card games with Lando Calrissian but also Jabba the Hutt and a frozen Han Solo.) Engadget covered all the announcements from Game Fest, including the upcoming game Mixtape, which Engadget calls a "reality-bending adventure" with "a killer '80s soundtrack" about three cusp-of-adulthood teenagers who "Skate. Party. Avoid the law. Make out. Sneak out. Hang out..." for Xbox/PS5/PC.

Read more of this story at Slashdot.

Researcher Finds Side-Channel Vulnerability in Post-Quantum Key Encapsulation Mechanism

Par : EditorDavid
9 juin 2024 à 18:44
Slashdot reader storagedude shared this report from The Cyber Express: A security researcher discovered an exploitable timing leak in the Kyber key encapsulation mechanism (KEM) that's in the process of being adopted by NIST as a post-quantum cryptographic standard. Antoon Purnal of PQShield detailed his findings in a blog post and on social media, and noted that the problem has been fixed with the help of the Kyber team. The issue was found in the reference implementation of the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) that's in the process of being adopted as a NIST post-quantum key encapsulation standard. "A key part of implementation security is resistance against side-channel attacks, which exploit the physical side-effects of cryptographic computations to infer sensitive information," Purnal wrote. To secure against side-channel attacks, cryptographic algorithms must be implemented in a way so that "no attacker-observable effect of their execution depends on the secrets they process," he wrote. In the ML-KEM reference implementation, "we're concerned with a particular side channel that's observable in almost all cryptographic deployment scenarios: time." The vulnerability can occur when a compiler optimizes the code, in the process silently undoing "measures taken by the skilled implementer." In Purnal's analysis, the Clang compiler was found to emit a vulnerable secret-dependent branch in the poly_frommsg function of the ML-KEM reference code needed in both key encapsulation and decapsulation, corresponding to the expand_secure implementation. While the reference implementation was patched, "It's important to note that this does not rule out the possibility that other libraries, which are based on the reference implementation but do not use the poly_frommsg function verbatim, may be vulnerable — either now or in the future," Purnal wrote. Purnal also published a proof-of-concept demo on GitHub. "On an Intel Core i7-13700H, it takes between 5-10 minutes to leak the entire ML-KEM 512 secret key using end-to-end decapsulation timing measurements."

Read more of this story at Slashdot.

Bill Gates Taking Pre-Orders For 'Source Code', a Memoir of His Early Years

Par : EditorDavid
9 juin 2024 à 17:44
Long-time Slashdot reader theodp writes: If you devoured the Childhood of Famous Americans book series as a kid and are ready for a longer read, Bill Gates has a book for you. "I'm excited to announce my new book, Source Code, which will be published next February," Gates wrote Tuesday in a GatesNotes blog post. "It's a memoir about my early years, from childhood through my decision to leave college and start Microsoft with Paul Allen. I write about the relationships, lessons, and experiences that laid the foundation for everything in my life that followed." GeekWire explains the timing of the book release is notable: January 2025 marks the 50th anniversary of the Popular Electronics magazine issue that featured the early Altair 8800 personal computer, which inspired Gates and Allen to start the company. Proceeds from book sales will be donated to the nonprofit United Way Worldwide, in recognition of Gates' late mother Mary's longtime work as a volunteer and board member with the organization. "Hey, this thing is happening without us," Allen famously said to Bill Gates (who had just turned 19). When Gates finished reading the Popular Electronics article, "he realized that Allen was right," according to one biographer. "For the next eight weeks, the two of them embarked on a frenzy of code writing that would change the nature of the computer business."

Read more of this story at Slashdot.

❌
❌