Vue normale

Reçu aujourd’hui — 18 mai 2025

Taiwan Shuts Down Its Last Nuclear Reactor

18 mai 2025 à 16:34
The only nuclear power plant still operating in Taiwan was shut down on Saturday, reports Japan's public media organization NHK: People in Taiwan have grown increasingly concerned about nuclear safety in recent years, especially after the 2011 nuclear disaster in Fukushima, northeastern Japan... Taiwan's energy authorities plan to focus more on thermoelectricity fueled by liquefied natural gas. They aim to source 20 percent of all electricity from renewables such as wind and solar power next year. AFP notes that nuclear power once provided more than half of Taiwan's energy, with three plants operating six reactors across an island that's 394 km (245 mi) long and 144 km (89 mi) wide. So the new move to close Taiwan's last reactor is "fuelling concerns over the self-ruled island's reliance on imported energy and vulnerability to a Chinese blockade," — though Taiwan's president insists the missing nucelar energy can be replace by new units in LNG and coal-fired plants: The island, which targets net-zero emissions by 2050, depends almost entirely on imported fossil fuel to power its homes, factories and critical semiconductor chip industry. President Lai Ching-te's Democratic Progressive Party has long vowed to phase out nuclear power, while the main opposition Kuomintang (KMT) party says continued supply is needed for energy security... [The Ma'anshan Nuclear Power Plant] has operated for 40 years in a region popular with tourists and which is now dotted with wind turbines and solar panels. More renewable energy is planned at the site, where state-owned Taipower plans to build a solar power station capable of supplying an estimated 15,000 households annually. But while nuclear only accounted for 4.2 percent of Taiwan's power supply last year, some fear Ma'anshan's closure risks an energy crunch.... Most of Taiwan's power is fossil fuel-based, with liquefied natural gas (LNG) accounting for 42.4 percent and coal 39.3 percent last year. Renewable energy made up 11.6 percent, well short of the government's target of 20 percent by 2025. Solar has faced opposition from communities worried about panels occupying valuable land, while rules requiring locally made parts in wind turbines have slowed their deployment. Taiwan's break-up with nuclear is at odds with global and regional trends. Even Japan aims for nuclear to account for 20-22 percent of its electricity by 2030, up from well under 10 percent now. And nuclear power became South Korea's largest source of electricity in 2024, accounting for 31.7 percent of the country's total power generation, and reaching its highest level in 18 years, according to government data.... And Lai acknowledged recently he would not rule out a return to nuclear one day. "Whether or not we will use nuclear power in the future depends on three foundations which include nuclear safety, a solution to nuclear waste, and successful social dialogue," he said. DW notes there's over 100,000 barrels of nuclear waste on Taiwan's easternmost island "despite multiple attempts to remove them... At one point, Taiwan signed a deal with North Korea so they could send barrels of nuclear waste to store there, but it did not work out due to a lack of storage facilities in the North and strong opposition from South Korea... "Many countries across the world have similar problems and are scrambling to identify sites for a permanent underground repository for nuclear fuel. Finland has become the world's first nation to build one." Thanks to long-time Slashdot reader AmiMoJo for sharing the news.

Read more of this story at Slashdot.

Firefox Announces Same-Day Update After Two Minor Pwn2Own Exploits

18 mai 2025 à 15:34
During this year's annual Pwn2Own contest, two researchers from Palo Alto Networks demonstrated an out-of-bounds write vulnerability in Mozilla Firefox, reports Cyber Security News, "earning $50,000 and 5 Master of Pwn points." And the next day another participant used an integer overflow to exploit Mozilla Firefox (renderer only). But Mozilla's security blog reminds users that a sandbox escape would be required to break out from a tab to gain wider system access "due to Firefox's robust security architecture" — and that "neither participating group was able to escape our sandbox..." We have verbal confirmation that this is attributed to the recent architectural improvements to our Firefox sandbox which have neutered a wide range of such attacks. This continues to build confidence in Firefox's strong security posture. Even though neither attack could escape their sandbox, "Out of abundance of caution, we just released new Firefox versions... all within the same day of the second exploit announcement." (Last year Mozilla responded to an exploitable security bug within 21 hours, they point out, even winning an award as the fastest to patch.) The new updated versions are Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1 and Firefox for Android. "Despite the limited impact of these attacks, all users and administrators are advised to update Firefox as soon as possible...." To review and fix the reported exploits a diverse team of people from all across the world and in various roles (engineering, QA, release management, security and many more) rushed to work. We tested and released a new version of Firefox for all of our supported platforms, operating systems, and configurations with rapid speed.... Our work does not end here. We continue to use opportunities like this to improve our incident response. We will also continue to study the reports to identify new hardening features and security improvements to keep all of our Firefox users across the globe protected.

Read more of this story at Slashdot.

OSU's Open Source Lab Eyes Infrastructure Upgrades and Sustainability After Recent Funding Success

18 mai 2025 à 14:34
It's a nonprofit that's provide hosting for the Linux Foundation, the Apache Software Foundation, Drupal, Firefox, and 160 other projects — delivering nearly 430 terabytes of information every month. (It's currently hosting Debian, Fedora, and Gentoo Linux.) But hosting only provides about 20% of its income, with the rest coming from individual and corporate donors (including Google and IBM). "Over the past several years, we have been operating at a deficit due to a decline in corporate donations," the Open Source Lab's director announced in late April. It's part of the CS/electrical engineering department at Oregon State University, and while the department "has generously filled this gap, recent changes in university funding makes our current funding model no longer sustainable. Unless we secure $250,000 in committed funds, the OSL will shut down later this year." But "Thankfully, the call for support worked, paving the way for the OSU Open Source Lab to look ahead, into what the future holds for them," reports the blog It's FOSS. "Following our OSL Future post, the community response has been incredible!" posted director Lance Albertson. "Thanks to your amazing support, our team is funded for the next year. This is a huge relief and lets us focus on building a truly self-sustaining OSL." To get there, we're tackling two big interconnected goals: 1. Finding a new, cost-effective physical home for our core infrastructure, ideally with more modern hardware. 2. Securing multi-year funding commitments to cover all our operations, including potential new infrastructure costs and hardware refreshes. Our current data center is over 20 years old and needs to be replaced soon. With Oregon State University evaluating the future of this facility, it's very likely we'll need to relocate in the near future. While migrating to the State of Oregon's data center is one option, it comes with significant new costs. This makes finding free or very low-cost hosting (ideally between Eugene and Portland for ~13-20 racks) a huge opportunity for our long-term sustainability. More power-efficient hardware would also help us shrink our footprint. Speaking of hardware, refreshing some of our older gear during a move would be a game-changer. We don't need brand new, but even a few-generations-old refurbished systems would boost performance and efficiency. (Huge thanks to the Yocto Project and Intel for a recent hardware donation that showed just how impactful this is!) The dream? A data center partner donating space and cycled-out hardware. Our overall infrastructure strategy is flexible. We're enhancing our OpenStack/Ceph platforms and exploring public cloud credits and other donated compute capacity. But whatever the resource, it needs to fit our goals and come with multi-year commitments for stability. And, a physical space still offers unique value, especially the invaluable hands-on data center experience for our students.... [O]ur big focus this next year is locking in ongoing support — think annualized pledges, different kinds of regular income, and other recurring help. This is vital, especially with potential new data center costs and hardware needs. Getting this right means we can stop worrying about short-term funding and plan for the future: investing in our tech and people, growing our awesome student programs, and serving the FOSS community. We're looking for partners, big and small, who get why foundational open source infrastructure matters and want to help us build this sustainable future together. The It's FOSS blog adds that "With these prerequisites in place, the OSUOSL intends to expand their student program, strengthen their managed services portfolio for open source projects, introduce modern tooling like Kubernetes and Terraform, and encourage more community volunteers to actively contribute." Thanks to long-time Slashdot reader I'm just joshin for suggesting the story.

Read more of this story at Slashdot.

YouTube Announces Gemini AI Feature to Target Ads When Viewers are Most Engaged

18 mai 2025 à 11:34
A new YouTube tool will let advertisers use Google's Gemini AI model to target ads to viewers when they're most engaged, reports CNBC: Peak Points has the potential to enable more impressions and a higher click-through rate on YouTube, a primary metric that determines how creators earn money on the video platform... Peak Points is currently in a pilot program and will be rolling out over the rest of the year. The product "aims to benefit advertisers by using a tactic that aims to grab users' attention right when they're most invested in the content," reports TechCrunch: This approach appears to be similar to a strategy called emotion-based targeting, where advertisers place ads that align with the emotions evoked by the video. It's believed that when viewers experience heightened emotional states, it leads to better recall of the ads. However, viewers may find these interruptions frustrating, especially when they're deeply engaged in the emotional arc of a video and want the ad to be over quickly to resume watching. In related news, YouTube announced another ad format that may be more appealing to users. The platform debuted a shoppable product feed where users can browse and purchase items during an ad.

Read more of this story at Slashdot.

9 Months Later, Microsoft Finally Fixes Linux Dual-Booting Bug

18 mai 2025 à 07:34
Last August a Microsoft security update broke dual-booting Windows 11 and Linux systems, remembers the blog Neowin. Distros like Debian, Ubuntu, Linux Mint, Zorin OS, and Puppy Linux were all affected, and "a couple of days later, Microsoft provided a slightly lengthy workaround that involved tweaking around with policies and the Registry in order to fix the problem." The update "was meant to address a GRUB bootloader vulnerability that allowed malicious actors to bypass Secure Boot's safety mechanisms," notes the It's FOSS blog. "Luckily, there's now a proper fix for this, as Microsoft has quietly released a new patch on May 13, 2025, addressing the issue nine months after it was first reported... Meanwhile, many dual-boot users were left with borked setups, having to use workarounds or disable Secure Boot altogether."

Read more of this story at Slashdot.

Ask Slashdot: Would You Consider a Low-Latency JavaScript Runtime For Your Workflow?

18 mai 2025 à 03:34
Amazon's AWS Labs has created LLRT an experimental, lightweight JavaScript runtime designed to address the growing demand for fast and efficient serverless applications. Slashdot reader BitterEpic wants to know what you think of it: Traditional JavaScript runtimes like Node.js rely on garbage collection, which can introduce unpredictable pauses and slow down performance, especially during cold starts in serverless environments like AWS Lambda. LLRT's manual memory management, courtesy of Rust, eliminates this issue, leading to smoother, more predictable performance. LLRT also has a runtime under 2MB, a huge reduction compared to the 100MB+ typically required by Node.js. This lightweight design means lower memory usage, better scalability, and reduced operational costs. Without the overhead of garbage collection, LLRT has faster cold start times and can initialize in milliseconds—perfect for latency-sensitive applications where every millisecond counts. For JavaScript developers, LLRT offers the best of both worlds: rapid development with JavaScript's flexibility, combined with Rust's performance. This means faster, more scalable applications without the usual memory bloat and cold start issues. Still in beta, LLRT promises to be a major step forward for serverless JavaScript applications. By combining Rust's performance with JavaScript's flexibility, it opens new possibilities for building high-performance, low-latency applications. If it continues to evolve, LLRT could become a core offering in AWS Lambda, potentially changing how we approach serverless JavaScript development. Would you consider Javascript as the core of your future workflow? Or maybe you would prefer to go lower level with quckjs?

Read more of this story at Slashdot.

Google Restores Nextcloud Users' File Access on Android

18 mai 2025 à 01:34
An anonymous reader shared this report from Ars Technica: Nextcloud, a host-your-own cloud platform that wants to help you "regain control over your data," has had to tell its Android-using customers for months now that they cannot upload files from their phone to their own servers. Months of emails and explanations to Google's Play Store representatives have yielded no changes, Nextcloud . That blog post — and media coverage of it — seem to have moved the needle. In an update to the post, Nextcloud wrote that as of May 15, Google has offered to restore full file access permissions. "We are preparing a test release first (expected tonight) and a final update with all functionality restored. If no issues occur, the update will hopefully be out early next week," the Nextcloud team wrote.... [Nextcloud] told The Register that it had more than 800,000 Android users. The company's blog post goes further than pinpointing technical and support hurdles. "It is a clear example of Big Tech gatekeeping smaller software vendors, making the products of their competitors worse or unable to provide the same services as the giants themselves sell," Nextcloud's post states. "Big Tech is scared that small players like Nextcloud will disrupt them, like they once disrupted other companies. So they try to shut the door." Nextcloud is one of the leaders of an antitrust-minded movement against Microsoft's various integrated apps and services, having filed a complaint against the firm in 2021.

Read more of this story at Slashdot.

Reçu hier — 17 mai 2025

Stack Overflow Seeks Realignment 'To Support the Builders of the Future in an AI World'

17 mai 2025 à 22:34
"The world has changed," writes Stack Overflow's blog. "Fast. Artificial intelligence is reshaping how we build, learn, and solve problems. Software development looks dramatically different than it did even a few years ago — and the pace of change is only accelerating." And they believe their brand "at times" lost "fidelity and clarity. It's very much been always added to and not been thought of holistically. So, it's time for our brand to evolve too," they write, hoping to articulate a perspective "forged in the fires of community, powered by collaboration, shaped by AI, and driven by people." The developer news site DevClass notes the change happens "as the number of posts to its site continues a dramatic decline thanks to AI-driven alternatives." According to a quick query on the official data explorer, the sum of questions and answers posted in April 2025 was down by over 64 percent from the same month in 2024, and plunged more than 90 percent from April 2020, when traffic was near its peak... Although declining traffic is a sign of Stack Overflow's reduced significance in the developer community, the company's business is not equally affected so far. Stack Exchange is a business owned by investment company Prosus, and the Stack Exchange products include private versions of its site (Stack Overflow for Teams) as well as advertising and recruitment. According to the Prosus financial results, in the six months ended September 2024, Stack Overflow increased its revenue and reduced its losses. The company's search for a new direction though confirms that the fast-disappearing developer engagement with Stack Overflow poses an existential challenge to the organization. DevClass says Stack Overflow's parent company "is casting about for new ways to provide value (and drive business) in this context..." The company has already experimented with various new services, via its Labs research department, including an AI Answer Assistant and Question Assistant, as well as a revamped jobs site in association with recruitment site Indeed, Discussions for technical debate, and extensions for GitHub Copilot, Slack, and Visual Studio Code. From the official announcement on Stack Overflow's blog: This rebrand isn't just a fresh coat of paint. It's a realignment with our purpose: to support the builders of the future in an AI world — with clarity, speed, and humanity. It's about showing up in a way that reflects who we are today, and where we're headed tomorrow. "We have appointed an internal steering group and we have engaged with an external expert partner in this area to help bring about the required change," notes a post in Stack Exchange's "meta" area. This isn't just about a visual update or marketing exercise — it's going to bring about a shift in how we present ourselves to the world which you will feel everywhere from the design to the copywriting, so that we can better achieve our goals and shared mission. As the emergence of AI has called into question the role of Stack Overflow and the Stack Exchange Network, one of the desired outputs of the rebrand process is to clarify our place in the world. We've done work toward this already — our recent community AMA is an example of this — but we want to ensure that this comes across in our brand and identity as well. We want the community to be involved and have a strong voice in the process of renewing and refreshing our brand. Remember, Stack Overflow started with a public discussion about what to name it! And another another post two months ago Stack Exchange is exploring early ideas for expanding beyond the "single lane" Q&A highway. Our goal right now is to better understand the problems, opportunities, and needs before deciding on any specific changes... The vision is to potentially enable: - A slower lane, with high-quality durable knowledge that takes time to create and curate, like questions and answers. - A medium lane, for more flexible engagement, with features like Discussions or more flexible Stack Exchanges, where users can explore ideas or share opinions. - A fast lane for quick, real-time interaction, with features like Chat that can bring the community together to discuss topics instantly. With this in mind, we're seeking your feedback on the current state of Chat, what's most important to you, and how you see Chat fitting into the future. In a post in Stack Exchange's "meta" area, brand design director David Longworth says the "tension mentioned between Stack Overflow and Stack Exchange" is probably the most relevant to the rebranding. But he posted later that "There's a lot of people behind the scenes on this who care deeply about getting this right! Thank you on behalf of myself and the team."

Read more of this story at Slashdot.

Intel Struggles To Reverse AMD's Share Gains In x86 CPU Market

17 mai 2025 à 21:34
An anonymous reader shared this report from CRN: CPU-tracking firm Mercury Research reported on Thursday that Intel's x86 CPU market share grew 0.3 points sequentially to 75.6 percent against AMD's 24.4 percent in the first quarter. However, AMD managed to increase its market share by 3.6 points year over year. These figures only captured the server, laptop and desktop CPU segments. When including IoT and semicustom products, AMD grew its x86 market share sequentially by 1.5 points and year over year by 0.9 points to 27.1 percent against Intel's 72.9 percent... AMD managed to gain ground on Intel in the desktop and server segments sequentially and year over year. But it was in the laptop segment where Intel eked out a sequential share gain, even though rival AMD ended up finishing the first quarter with a higher share of shipments than what it had a year ago... While AMD mostly came out on top in the first quarter, [Mercury Research President Dean] McCarron said ARM's estimated CPU share against x86 products crossed into the double digits for the first time, growing 2.3 points sequentially to 11.9 percent. This was mainly due to a "surge" of Nvidia's Grace CPUs for servers and a large increase of Arm CPU shipments for Chromebooks. Meanwhile, PC Gamer reports that ARM's share of the PC processor market "grew to 13.6% in the first quarter of 2025 from 10.8% in the fourth quarter of 2024." And they note the still-only-rumors that an Arm-based chip from AMD will be available as soon next year. [I]f one of the two big players in x86 does release a mainstream Arm chip for the PC, that will very significant. If it comes at about the same time as Nvidia's rumoured Arm chip for the PC, well, momentum really will be building and questioning x86's dominance will be wholly justified.

Read more of this story at Slashdot.

Is the Altruistic OpenAI Gone?

17 mai 2025 à 20:34
"The altruistic OpenAI is gone, if it ever existed," argues a new article in the Atlantic, based on interviews with more than 90 current and former employees, including executives. It notes that shortly before Altman's ouster (and rehiring) he was "seemingly trying to circumvent safety processes for expediency," with OpenAI co-founder/chief scientist Ilya telling three board members "I don't think Sam is the guy who should have the finger on the button for AGI." (The board had already discovered Altman "had not been forthcoming with them about a range of issues" including a breach in the Deployment Safety Board's protocols.) Adapted from the upcoming book, Empire of AI, the article first revisits the summer of 2023, when Sutskever ("the brain behind the large language models that helped build ChatGPT") met with a group of new researchers: Sutskever had long believed that artificial general intelligence, or AGI, was inevitable — now, as things accelerated in the generative-AI industry, he believed AGI's arrival was imminent, according to Geoff Hinton, an AI pioneer who was his Ph.D. adviser and mentor, and another person familiar with Sutskever's thinking.... To people around him, Sutskever seemed consumed by thoughts of this impending civilizational transformation. What would the world look like when a supreme AGI emerged and surpassed humanity? And what responsibility did OpenAI have to ensure an end state of extraordinary prosperity, not extraordinary suffering? By then, Sutskever, who had previously dedicated most of his time to advancing AI capabilities, had started to focus half of his time on AI safety. He appeared to people around him as both boomer and doomer: more excited and afraid than ever before of what was to come. That day, during the meeting with the new researchers, he laid out a plan. "Once we all get into the bunker — " he began, according to a researcher who was present. "I'm sorry," the researcher interrupted, "the bunker?" "We're definitely going to build a bunker before we release AGI," Sutskever replied. Such a powerful technology would surely become an object of intense desire for governments globally. The core scientists working on the technology would need to be protected. "Of course," he added, "it's going to be optional whether you want to get into the bunker." Two other sources I spoke with confirmed that Sutskever commonly mentioned such a bunker. "There is a group of people — Ilya being one of them — who believe that building AGI will bring about a rapture," the researcher told me. "Literally, a rapture...." But by the middle of 2023 — around the time he began speaking more regularly about the idea of a bunker — Sutskever was no longer just preoccupied by the possible cataclysmic shifts of AGI and superintelligence, according to sources familiar with his thinking. He was consumed by another anxiety: the erosion of his faith that OpenAI could even keep up its technical advancements to reach AGI, or bear that responsibility with Altman as its leader. Sutskever felt Altman's pattern of behavior was undermining the two pillars of OpenAI's mission, the sources said: It was slowing down research progress and eroding any chance at making sound AI-safety decisions. "For a brief moment, OpenAI's future was an open question. It might have taken a path away from aggressive commercialization and Altman. But this is not what happened," the article concludes. Instead there was "a lack of clarity from the board about their reasons for firing Altman." There was fear about a failure to realize their potential (and some employees feared losing a chance to sell millions of dollars' worth of their equity). "Faced with the possibility of OpenAI falling apart, Sutskever's resolve immediately started to crack... He began to plead with his fellow board members to reconsider their position on Altman." And in the end "Altman would come back; there was no other way to save OpenAI." To me, the drama highlighted one of the most urgent questions of our generation: How do we govern artificial intelligence? With AI on track to rewire a great many other crucial functions in society, that question is really asking: How do we ensure that we'll make our future better, not worse? The events of November 2023 illustrated in the clearest terms just how much a power struggle among a tiny handful of Silicon Valley elites is currently shaping the future of this technology. And the scorecard of this centralized approach to AI development is deeply troubling. OpenAI today has become everything that it said it would not be.... The author believes OpenAI "has grown ever more secretive, not only cutting off access to its own research but shifting norms across the industry to no longer share meaningful technical details about AI models..." "At the same time, more and more doubts have risen about the true economic value of generative AI, including a growing body of studies that have shown that the technology is not translating into productivity gains for most workers, while it's also eroding their critical thinking."

Read more of this story at Slashdot.

Researchers Finally Link Long Covid 'Brain Fog' to Inflammation

17 mai 2025 à 19:34
An anonymous reader shared this report from The Hill: A new study indicates the debilitating "brain fog" suffered by millions of long COVID patients is linked to changes in the brain, including inflammation and an impaired ability to rewire itself following COVID-19 infection. United Press International reported this week that the small-scale study, conducted by researchers at Corewell Health in Grand Rapids, Michigan, and Michigan State University, shows that altered levels of a pair of key brain chemicals could be the culprit. The study marks the first time doctors have been able to provide scientific proof that validates the experiences of the approximately 12 million COVID "long-haulers" in the U.S. who have reported neurological symptoms. Researchers looked at biomarkers in study participants and found that those complaining of brain fog had higher levels of an anti-inflammatory protein that is crucial to regulating a person's immune system, UPI reported. They also showed lower serum levels of nerve growth factor, a protein vital to the brain's plasticity... One of the biggest issues involving long COVID has been doctors' inability to find physical proof of the symptoms described by patients. The study has changed that, according to co-author Dr. Bengt Arnetz.

Read more of this story at Slashdot.

The Most Promising Ways to Destroy 'Forever Chemicals'

17 mai 2025 à 18:34
"Researchers are seeking a breakthrough in technologies to tackle PFAS contamination," reports the Washington Post — including experiments with ultraviolet light, plasma and sound waves: "We're in a good spot," said Christopher Higgins, a professor of civil and environmental engineering at the Colorado School of Mines who researches PFAS. "There's a lot of things being tested. ... Around the world, everyone is trying to work on this topic...." PFAS destruction technologies are beginning to show potential. Some methods have been licensed by companies that are rolling out the systems in real-world settings. "There's been a lot of research happening over the past few years looking at advanced destruction technologies, and there's been a lot of improvements and advancements, and we're now starting to see some of them actually at scale," said Anna Reade [a senior scientist and director of PFAS advocacy at the Natural Resources Defense Council]. An approach known as supercritical water oxidation is one of the more developed technologies, Reade and other experts said. It involves heating and pressurizing water to a specific point that creates the ideal conditions to break every carbon fluorine bond, said Amy Dindal [a PFAS expert with Battelle, a science and technology nonprofit that has developed a PFAS destruction technology]. The process used in a patented technology created by Battelle produces carbon dioxide and a form of fluorine that can be quickly neutralized to become a harmless salt. "It's a complete destruction and mineralization technology, because we're actually breaking all of the carbon fluorine bonds," Dindal said, adding that the technology is "PFAS agnostic...." Another promising approach using heat and pressure was developed by researchers at the Colorado School of Mines [and already licensed by a company in Washington]. Known as hydrothermal alkaline treatment, or HALT, it involves adding a low-cost chemical reagent such as sodium hydroxide to superheated liquid water.... A destruction method that harnesses ultraviolet light has also emerged as a contender [has licensed by a company in Michigan]. When UV light oxidizes an electron-generating compound, it produces a powerful electron that's very reactive and strong enough to break carbon fluorine bonds... Other technologies are experimenting with the use of plasma, which can generate reactive electrons to break down PFAS but tends to require a large amount of energy. Researchers are also experimenting with a process that uses sound waves. High-intensity sound waves create small bubbles in a water system or liquid waste stream, Higgins said. As those bubbles collapse, they can generate the high temperatures and pressure needed to degrade PFAS. But "At the end of the day, not using these chemicals unless it's absolutely necessary is the actually most effective tool in our toolbox," Reade said.

Read more of this story at Slashdot.

Curl Warns GitHub About 'Malicious Unicode' Security Issue

17 mai 2025 à 17:34
A Curl contributor replaced an ASCII letter with a Unicode alternative in a pull request, writes Curl lead developer/founder Daniel Stenberg. And not a single human reviewer on the team (or any of their CI jobs) noticed. The change "looked identical to the ASCII version, so it was not possible to visually spot this..." The impact of changing one or more letters in a URL can of course be devastating depending on conditions... [W]e have implemented checks to help us poor humans spot things like this. To detect malicious Unicode. We have added a CI job that scans all files and validates every UTF-8 sequence in the git repository. In the curl git repository most files and most content are plain old ASCII so we can "easily" whitelist a small set of UTF-8 sequences and some specific files, the rest of the files are simply not allowed to use UTF-8 at all as they will then fail the CI job and turn up red. In order to drive this change home, we went through all the test files in the curl repository and made sure that all the UTF-8 occurrences were instead replaced by other kind of escape sequences and similar. Some of them were also used more or less by mistake and could easily be replaced by their ASCII counterparts. The next time someone tries this stunt on us it could be someone with less good intentions, but now ideally our CI will tell us... We want and strive to be proactive and tighten everything before malicious people exploit some weakness somewhere but security remains this never-ending race where we can only do the best we can and while the other side is working in silence and might at some future point attack us in new creative ways we had not anticipated. That future unknown attack is a tricky thing. In the original blog post Stenberg complained he got "barely no responses" from GitHub (joking "perhaps they are all just too busy implementing the next AI feature we don't want.") But hours later he posted an update. "GitHub has told me they have raised this as a security issue internally and they are working on a fix."

Read more of this story at Slashdot.

Despite Success of New 'Assassin's Creed' Game, Ubisoft Stock Tumbles 18%

17 mai 2025 à 16:34
"Shares of Ubisoft sank 18% on Thursday," reports CNBC, "after the French video game firm reported full-year earnings that disappointed investors... The company's shares have lost almost 60% of their value in the past 12 months, as the firm faced financial struggles, development hurdles, and underperformance of some of its key titles." Ubisoft said its latest Assassin's Creed game "delivered the second-highest Day 1 sales revenue in franchise history and set a new record for Ubisoft's Day 1 performance on the PlayStation digital store," according to Reuters. And AFP notes that according to data from consultancy Circana, that game become the second-best-selling game of the year so far in the U.S. But... [A] string of disappointing releases undermined this year's performance, with a net loss of 159 million euros ($178 million) on revenues of 1.9 billion — down 17.5 percent year-on-year. Over the past 12 months, Ubisoft's would-be blockbuster "Star Wars Outlaws" fell short of sales expectations on release, while it cancelled multiplayer first-person shooter "XDefiant" for lack of players. "This year has been a challenging one for Ubisoft, with mixed dynamics across our portfolio, amid intense industry competition," chief executive Yves Guillemot said in a statement. But a string of disappointing releases undermined this year's performance, with a net loss of 159 million euros ($178 million) on revenues of 1.9 billion — down 17.5 percent year-on-year. The group expects the measure to hold steady in the coming 2025-26 financial year, during which it will release a new "Prince of Persia" game, strategy title "Anno 117: Pax Romana" and mobile versions of shooters "Rainbow Six" and "The Division"... Moving to address its business woes, Ubisoft said in late March that it would create a new subsidiary to manage its three top franchises: "Assassin's Creed", "Far Cry" and "Rainbow Six". "Since January, the shares have lost more than 12 percent, touching their lowest price in over a decade in April."

Read more of this story at Slashdot.

Paleontologists Identify Tiny Three-Eyed 'Sea Moth' Predator in Fossils

17 mai 2025 à 15:34
"With the help of more than five dozen fossils, paleontologists have uncovered a tiny three-eyed predator nicknamed the 'sea moth'," reports CNN, "that swam in Earth's oceans 506 million years ago." Tiny as in 15 to 61 mm in total body length. (That's 0.60 to 2.4 inches...) But check out the illustration in CNN's article... Mosura fentoni, as the species is known, belongs to a group called radiodonts, an early offshoot of the arthropod evolutionary tree, according to a new study published Tuesday in the journal Royal Society Open Science. While radiodonts are now extinct, studying their fossilized remains can illuminate how modern arthropods such as insects, spiders and crabs evolved. One of the most diverse animal groups, arthropods are believed to account for more than 80% of living animal species, said lead study author Dr. Joe Moysiuk, curator of paleontology and geology at the Manitoba Museum in Winnipeg. Well-preserved specimens of the previously unknown Mosura fentoni also reveal something that's never been seen in any other radiodont: an abdomen-like body region with 16 segments that include gills at its rear. This part of the creature's anatomy is similar to a batch of segments bearing respiratory organs at the rear of the body found in distant modern radiodont relatives like horseshoe crabs, woodlice and insects, Moysiuk said.... No animal living today quite looks like Mosura fentoni, Moysiuk said, although it had jointed claws similar to those of modern insects and crustaceans. But unlike those critters, which can have two or four additional eyes used to help maintain orientation, Mosura had a larger and more conspicuous third eye in the middle of its head. "Although not closely related, Mosura probably swam in a similar way to a ray, undulating its multiple sets of swimming flaps up and down, like flying underwater," Moysiuk said in an email. "It also had a mouth shaped like a pencil sharpener and lined with rows of serrated plates, unlike any living animal." About the size of an adult human's index finger, Mosura and its swimming flaps vaguely resemble a moth, which led researchers to call it the "sea moth." The Royal Society publication notes the etymology of the species name (Mosura fentoni is "from the name of the fictional Japanese monster, or kaiju... also known as 'Mothra'...in reference to the moth-like appearance of the animal." Thanks to long-time Slashdot reader walterbyrd for sharing the news.

Read more of this story at Slashdot.

Rust Creator Graydon Hoare Thanks Its Many Stakeholders - and Mozilla - on Rust's 10th Anniversary

17 mai 2025 à 14:34
Thursday was Rust's 10-year anniversary for its first stable release. "To say I'm surprised by its trajectory would be a vast understatement," writes Rust's original creator Graydon Hoare. "I can only thank, congratulate, and celebrate everyone involved... In my view, Rust is a story about a large community of stakeholders coming together to design, build, maintain, and expand shared technical infrastructure." It's a story with many actors: - The population of developers the language serves who express their needs and constraints through discussion, debate, testing, and bug reports arising from their experience writing libraries and applications. - The language designers and implementers who work to satisfy those needs and constraints while wrestling with the unexpected consequences of each decision. - The authors, educators, speakers, translators, illustrators, and others who work to expand the set of people able to use the infrastructure and work on the infrastructure. - The institutions investing in the project who provide the long-term funding and support necessary to sustain all this work over decades. All these actors have a common interest in infrastructure. Rather than just "systems programming", Hoare sees Rust as a tool for building infrastructure itself, "the robust and reliable necessities that enable us to get our work done" — a wide range that includes everything from embedded and IoT systems to multi-core systems. So the story of "Rust's initial implementation, its sustained investment, and its remarkable resonance and uptake all happened because the world needs robust and reliable infrastructure, and the infrastructure we had was not up to the task." Put simply: it failed too often, in spectacular and expensive ways. Crashes and downtime in the best cases, and security vulnerabilities in the worst. Efficient "infrastructure-building" languages existed but they were very hard to use, and nearly impossible to use safely, especially when writing concurrent code. This produced an infrastructure deficit many people felt, if not everyone could name, and it was growing worse by the year as we placed ever-greater demands on computers to work in ever more challenging environments... We were stuck with the tools we had because building better tools like Rust was going to require an extraordinary investment of time, effort, and money. The bootstrap Rust compiler I initially wrote was just a few tens of thousands of lines of code; that was nearing the limits of what an unfunded solo hobby project can typically accomplish. Mozilla's decision to invest in Rust in 2009 immediately quadrupled the size of the team — it created a team in the first place — and then doubled it again, and again in subsequent years. Mozilla sustained this very unusual, very improbable investment in Rust from 2009-2020, as well as funding an entire browser engine written in Rust — Servo — from 2012 onwards, which served as a crucial testbed for Rust language features. Rust and Servo had multiple contributors at Samsung, Hoare acknowledges, and Amazon, Facebook, Google, Microsoft, Huawei, and others "hired key developers and contributed hardware and management resources to its ongoing development." Rust itself "sits atop LLVM" (developed by researchers at UIUC and later funded by Apple, Qualcomm, Google, ARM, Huawei, and many other organizations), while Rust's safe memory model "derives directly from decades of research in academia, as well as academic-industrial projects like Cyclone, built by AT&T Bell Labs and Cornell." And there were contributions from "interns, researchers, and professors at top academic research programming-language departments, including CMU, NEU, IU, MPI-SWS, and many others." JetBrains and the Rust-Analyzer OpenCollective essentially paid for two additional interactive-incremental reimplementations of the Rust frontend to provide language services to IDEs — critical tools for productive, day-to-day programming. Hundreds of companies and other institutions contributed time and money to evaluate Rust for production, write Rust programs, test them, file bugs related to them, and pay their staff to fix or improve any shortcomings they found. Last but very much not least: Rust has had thousands and thousands of volunteers donating years of their labor to the project. While it might seem tempting to think this is all "free", it's being paid for! Just less visibly than if it were part of a corporate budget. All this investment, despite the long time horizon, paid off. We're all better for it. He looks ahead with hope for a future with new contributors, "steady and diversified streams of support," and continued reliability and compatability (including "investment in ever-greater reliability technology, including the many emerging formal methods projects built on Rust.") And he closes by saying Rust's "sustained, controlled, and frankly astonishing throughput of work" has "set a new standard for what good tools, good processes, and reliable infrastructure software should be like. "Everyone involved should be proud of what they've built."

Read more of this story at Slashdot.

Reçu avant avant-hier

Is There Water on Mars?

12 mai 2025 à 11:34
Evidence is mounting for "a vast reservoir of liquid water" on Mars, according to a new article by Australian National University professor Hrvoje TkalÄiÄ and geophysics associate professor Weijia Sun from the Chinese Academy of Geological Sciences, announcing their recently published paper. "Using seismic data from NASA's InSight mission, we uncovered evidence that the seismic waves slow down in a layer between 5.4 and 8 kilometres below the surface, which could be because of the presence of liquid water at these depths." Mars is covered in traces of ancient bodies of water. But the puzzle of exactly where it all went when the planet turned cold and dry has long intrigued scientists... Billions of years ago, during the Noachian and Hesperian periods (4.1 billion to 3 billion years ago), rivers carved valleys and lakes shimmered. As Mars' magnetic field faded and its atmosphere thinned, most surface water vanished. Some escaped to space, some froze in polar caps, and some was trapped in minerals, where it remains today. But evaporation, freezing and rocks can't quite account for all the water that must have covered Mars in the distant past. Calculations suggest the "missing" water is enough to cover the planet in an ocean at least 700 metres deep, and perhaps up to 900 metres deep. One hypothesis has been that the missing water seeped into the crust. Mars was heavily bombarded by meteorites during the Noachian period, which may have formed fractures that channelled water underground. Deep beneath the surface, warmer temperatures would keep the water in a liquid state — unlike the frozen layers nearer the surface. In 2018, NASA's InSight lander touched down on Mars to listen to the planet's interior with a super-sensitive seismometer. By studying a particular kind of vibration called "shear waves", we found a significant underground anomaly: a layer between 5.4 and 8 kilometres down where these vibrations move more slowly. This "low-velocity layer" is most likely highly porous rock filled with liquid water, like a saturated sponge. Something like Earth's aquifers, where groundwater seeps into rock pores. We calculated the "aquifer layer" on Mars could hold enough water to cover the planet in a global ocean 520-780m deep. InSight's seismometer captured vibrations between the crust of Mars and its lower layers from two meteorite impacts in 2021 and a Marsquake in 2022. "These signatures let us pinpoint boundaries where rock changes, revealing the water-soaked layer 5.4 to 8 kilometres deep." It's an exciting possibility. "Purified, it could provide drinking water, oxygen, or fuel for rockets." And since microbes thrives on earth in deep rocks filled with water, "Could similar life, perhaps relics of ancient Martian ecosystems, persist in these reservoirs?"

Read more of this story at Slashdot.

US Copyright Office to AI Companies: Fair Use Isn't 'Commercial Use of Vast Troves of Copyrighted Works'

12 mai 2025 à 07:34
Business Insider tells the story in three bullet points: - Big Tech companies depend on content made by others to train their AI models. - Some of those creators say using their work to train AI is copyright infringement. - The U.S. Copyright Office just published a report that indicates it may agree. The office released on Friday its latest in a series of reports exploring copyright laws and artificial intelligence. The report addresses whether the copyrighted content AI companies use to train their AI models qualifies under the fair use doctrine. AI companies are probably not going to like what they read... AI execs argue they haven't violated copyright laws because the training falls under fair use. According to the U.S. Copyright Office's new report, however, it's not that simple. "Although it is not possible to prejudge the result in any particular case, precedent supports the following general observations," the office said. "Various uses of copyrighted works in AI training are likely to be transformative. The extent to which they are fair, however, will depend on what works were used, from what source, for what purpose, and with what controls on the outputs — all of which can affect the market." The office made a distinction between AI models for research and commercial AI models. "When a model is deployed for purposes such as analysis or research — the types of uses that are critical to international competitiveness — the outputs are unlikely to substitute for expressive works used in training," the office said. "But making commercial use of vast troves of copyrighted works to produce expressive content that competes with them in existing markets, especially where this is accomplished through illegal access, goes beyond established fair use boundaries." The report says outputs "substantially similar to copyrighted works in the dataset" are less likely to be considered transformative than when the purpose "is to deploy it for research, or in a closed system that constrains it to a non-substitutive task." Business Insider adds that "A day after the office released the report, President Donald Trump fired its director, Shira Perlmutter, a spokesperson told Business Insider."

Read more of this story at Slashdot.

Videogame's Players Launch Boycott Over Bugs, Story Changes, Monetization

12 mai 2025 à 04:34
It's been a mobile-only game for decades. Then a little more than a week ago Infinity Nikkireleased its 1.5 update (which introduced multiplayer and customization options) and launched the game on Steam. But it "didn't go over as planned," writes the worker-owned gaming site Aftermath, citing some very negative reactions on Reddit. (Some players say that in response the game's publisher is now even censoring the word "boycott" on its official forums and community spaces...) Infinity Nikki players were immediately incensed by a bevy of bugs and general game instability, and made even more angry by several baffling changes to both the story and its monetization structure... Players globally are vowing to stay off the game until Infold Games addresses their concerns, including at least one Infinity Nikki creator who is part of the game's partner program... [T]he Chinese Infinity Nikki community — as well as others — has been flooding Steam with negative reviews of the game... [T]he complaints are also impacting Infinity Nikki's review score on the Google Play Store... The company said it's working to fix the patch's performance issues, which have caused game-breaking bugs for some players.... [T]he Infinity Nikki team also gave players some free currency, but there's been problems there, too: Players say Infold had a bug in this distribution, which awarded players too much free currency. Instead of letting players keep that — it was Infold's mistake, after all — they deducted the currency, some of which players had already spent, putting them in the negative. But the community is looking for more from the studio; it wants an acknowledgement of the "dumpster fire" of a situation, as one Infinity Nikki player told Aftermath, but also wants some of the biggest problems reversed... Beyond the problematic monetization strategy, players Aftermath spoke with said they're also pissed off at a major change to the start of the game... Infold Games removed the game's original start with the update; the new intro drops players into Infinity Nikki with little context and a new, unexplained character who is supposed to be a guide as Nikki is dropped into intergalactic limbo. While the spend-to-upgrade-your-character model has always been inherently predatory, as one player put it, the new update pushed the system "much too far for a lot of players," according to the article — "something made more egregious by the numerous bugs and strange gameplay changes." The article now describes some players as "upset that the trust they've given Infold Games thus far has been broken." "Infold Games has not responded to a request for comment."

Read more of this story at Slashdot.

Apple's iPhone Plans for 2027: Foldable, or Glass and Curved. (Plus Smart Glasses, Tabletop Robot)

12 mai 2025 à 01:46
An anonymous reader shared this report from the Verge: This morning, while summarizing an Apple "product blitz" he expects for 2027, Bloomberg's Mark Gurman writes in his Power On newsletter that Apple is planning a "mostly glass, curved iPhone" with no display cutouts for that year, which happens to be the iPhone's 20th anniversary... [T]he closest hints are probably in Apple patents revealed over the years, like one from 2019 that describes a phone encased in glass that "forms a continuous loop" around the device. Apart from a changing iPhone, Gurman describes what sounds like a big year for Apple. He reiterates past reports that the first foldable iPhone should be out by 2027, and that the company's first smart glasses competitor to Meta Ray-Bans will be along that year. So will those rumored camera-equipped AirPods and Apple Watches, he says. Gurman also suggests that Apple's home robot — a tabletop robot that features "an AI assistant with its own personality" — will come in 2027... Finally, Gurman writes that by 2027 Apple could finally ship an LLM-powered Siri and may have created new chips for its server-side AI processing. Earlier this week Bloomberg reported that Apple is also "actively looking at" revamping the Safari web browser on its devices "to focus on AI-powered search engines." (Apple's senior VP of services "noted that searches on Safari dipped for the first time last month, which he attributed to people using AI.")

Read more of this story at Slashdot.

❌