Agregátor RSS

Put not your trust in Windows — or CrowdStrike

Computerworld.com [Hacking News] - 20 Červenec, 2024 - 14:09

What do the Boll Weevil, Cavendish bananas, and the recent Windows/CrowdStrike fiasco all have in common? They’re all economic disasters that occurred because far too many people put their trust in a monoculture.

I’m serious.

Indeed, I warned you years ago about Windows when I first mentioned Mr. Boll Weevil. After the Civil War, the US South became more dependent on cotton production than ever before to make money in the region in the late 19th century. 

Then, in the mid-1890s, Boll Weevils arrived and almost destroyed the cotton crop and the South’s economy. With only one cash crop, the South was vulnerable to this one bug as it destroyed crops — and hundreds of thousands of people’s livelihoods.

Today, the banana you get for breakfast every morning is in danger. Almost half of the bananas in your grocery store are Cavendish bananas, which are being devastated by the Fusarium wilt. This fungal disease might well drive Cavendishs into extinction; then what will you do for your banana split??

And now, we come to Windows and the disaster that unfolded on Friday. (This time ,Microsoft’s poor security wasn’t to blame for the problem for once.) The proximate “credit” for the ongoing mess goes to CrowdStrike, which released a truly awful security update to its Falcon Sensor program, which scans Windows computers for intrusions and signs of hacking. 

All it took was a single faulty content update — not really even code — to fry Windows computers from Afghanistan to Zimbabwe. Just as bad, undoing the problem requires manual fixes to every computer, PC by PC. IT staffers will be up to all hours over the weekend and beyond deleting the fouled-up data file and the system reference that called it. (Those overworked IT folks will be happy learn the CEO has apologized.)

Why was the update so awful? Why did it cause hundreds of millions — perhaps billions — of PCs around the world to crash and get locked into endless reboot loops? Because just like cotton and Cavendish bananas, we depend all too much on a single product: Windows.

I told you so; let me reiterate: “Windows bad, Linux good.

I wasn’t surprised to learn that, according to the folks at QR Code Generator, “Analysis of Google search data has revealed that online searches for “Microsoft alternative,” “MacOS,” “Debian,” “Ubuntu,“ and “Linux” soared by up to 290% worldwide during Microsoft’s global IT outage.”

Once more, and with feeling, I suggest you seriously consider switching your computers from Windows to Linux and contemplate moving from PCs to Macs. 

Leaving that smart-aleck attitude aside, we really do depend too much on Windows, period. If we were all using Macs or Linux, we might have encountered the same problem, but it’s less likely. Linux is more secure by design, but it’s had its security breaches, as well. It just doesn’t have them nearly as often as Windows does. 

To a lesser degree, it’s the same story with CrowdStrike. You’re unlikely to use Falcon Sensor on your home PC. Still, according to the business data analysis company  6sense.com, CrowdStrike is the No. 1 business endpoint security company with more than 3,500 customers. 

If you’re playing the “What Happened to Whom Game at home,” that’s about one in four companies that use endpoint security. These tend to be big companies. For example, my friends stuck in airports on Friday kept telling me it included most of the major airlines and all the airport flight scheduling screens. It was not a good day to fly. 

Or, to buy groceries, or get paid, or… you get the idea. I’m sure you have your own story. 

Me? Yes, I was fine with all my Linux desktops and servers…, as long as I stayed in my home/office. 

That’s the problem, you see. In this interconnected world of ours, even open-source fans like me are affected when Windows goes down. We all are.

Windows has become a single point of failure for the world’s IT infrastructure. We really must move on, not to a world where everyone uses Macs or desktop Linux, but one where we use a multitude of different operating systems.

Yes, this will be a pain. But at least this way, we won’t have days like Friday when all too much of the day-to-day technology we depend on goes down. 

Kategorie: Hacking & Security

Navigating the Cybersecurity Maze: Advanced Linux Security Practices for Professionals

LinuxSecurity.com - 20 Červenec, 2024 - 13:00
As cyber threats rapidly advance, Linux administrators and InfoSec professionals are essential defenders against increasingly sophisticated threats. Protectors of critical infrastructure and sensitive data, these experts must implement a wide array of security practices designed specifically to their unique challenges.
Kategorie: Hacking & Security

Open Source Vulnerability Assessment Tools & Scanners

LinuxSecurity.com - 20 Červenec, 2024 - 13:00
Computer systems, software, applications, and other interfaces are vulnerable to network security threats. Failure to find these cybersecurity vulnerabilities can lead to the downfall of a company. Therefore, businesses must utilize vulnerability scanners regularly within their systems and servers to identify existing loopholes and weaknesses that can be resolved through security patching.
Kategorie: Hacking & Security

55 let od prvního přistání na Měsíci. Podívejte se na 39 nádherných fotografií z misí Apollo

Živě.cz - 20 Červenec, 2024 - 12:45
Tisíce fotografií z misí Apollo, které měly dopravit člověka na Měsíc a zpátky, byly zveřejněné v originální formě. Podívejte se na ty nejzajímavější.
Kategorie: IT News

Není to tak, že by Ukrajinci otočili kohoutem, ale Družba stejně umírá. Češi se od ruské ropy odříznou do roka

Živě.cz - 20 Červenec, 2024 - 10:45
Z Družby zmizela kvůli sankcím ropa od Lukoilu • Družba ale už v roce 2022 zásobovala Česko méně než z poloviny • Brzy veškeré dodávky přebere ropovod TAL-PLUS
Kategorie: IT News

CrowdStrike CEO apologizes for crashing IT systems around the world, details fix

Computerworld.com [Hacking News] - 20 Červenec, 2024 - 10:17

CrowdStrike CEO has apologized to the company’s customers and partners for crashing their Windows systems, and the company has described the error that caused the disaster.

“I want to sincerely apologize directly to all of you for today’s outage. All of CrowdStrike understands the gravity and impact of the situation,” CrowdStrike founder and CEO George Kurtz wrote in a blog post on the company’s website titled “Our Statement on Today’s Outage.”

He reiterated the company’s earlier message that the incident, which brought down computers around the world on Friday, July 19, was not the result of a cyberattack.

Kategorie: Hacking & Security

Největší výpadek počítačových systémů v historii. Odpovídáme na nejdůležitější otázky

Živě.cz - 20 Červenec, 2024 - 09:21
Informace v článku průběžně doplňujeme a upřesňujeme o nové skutečnosti. Naposledy oživeno 20. července v 7:10. Těžko se to hodnotí, ale pravděpodobně opravdu jde o největší výpadek počítačových systémů, jaký se kdy přihodil. Páteční kolaps ochromil leteckou dopravu, finanční sektor, zdravotnická ...
Kategorie: IT News

Největší výpadek počítačových systémů v historii. Odpovídáme na nejdůležitější otázky

Zive.cz - bezpečnost - 20 Červenec, 2024 - 09:21
Informace v článku průběžně doplňujeme a upřesňujeme o nové skutečnosti. Naposledy oživeno 20. července v 7:10. Těžko se to hodnotí, ale pravděpodobně opravdu jde o největší výpadek počítačových systémů, jaký se kdy přihodil. Páteční kolaps ochromil leteckou dopravu, finanční sektor, zdravotnická ...
Kategorie: Hacking & Security

Aiťákův týden: Cloudová apokalypsa, chatbot se schopnostmi doktoranda a jeskyně na Měsíci

Živě.cz - 20 Červenec, 2024 - 08:45
Do AI jsme nahráli články, které na Živě vyšly v uplynulém týdnu • Požádali jsme o výběr nejzajímavějších témat a jejich shrnutí • Dnešní článek připravil Claude 3.5 Sonnet, obrázek je z Midjourney.
Kategorie: IT News

17-Year-Old Linked to Scattered Spider Cybercrime Syndicate Arrested in U.K.

The Hacker News - 20 Červenec, 2024 - 06:28
Law enforcement officials in the U.K. have arrested a 17-year-old boy from Walsall who is suspected to be a member of the notorious Scattered Spider cybercrime syndicate. The arrest was made "in connection with a global cyber online crime group which has been targeting large organizations with ransomware and gaining access to computer networks," West Midlands police said. "The arrest is part of
Kategorie: Hacking & Security

17-Year-Old Linked to Scattered Spider Cybercrime Syndicate Arrested in U.K.

The Hacker News - 20 Červenec, 2024 - 06:28
Law enforcement officials in the U.K. have arrested a 17-year-old boy from Walsall who is suspected to be a member of the notorious Scattered Spider cybercrime syndicate. The arrest was made "in connection with a global cyber online crime group which has been targeting large organizations with ransomware and gaining access to computer networks," West Midlands police said. "The arrest is part of Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Celosvětový kolaps Windows infrastruktury

AbcLinuxu [zprávičky] - 20 Červenec, 2024 - 00:56
Světem se valí vlna BSOD počítačů s operačním systémem Windows v kombinaci s bezpečnostním agentem CrowdStrike. Částečně jsou ochromeny letiště, banky, burzy, Microsoft Cloud apod. Zatím je znám jen workaround v podobě nabootování do recovery režimu a smazání jednoho souboru.
Kategorie: GNU/Linux & BSD

Událo se v týdnu 29/2024

AbcLinuxu [články] - 20 Červenec, 2024 - 00:01
Ucelený přehled článků, zpráviček a diskusí za minulých 7 dní.
Kategorie: GNU/Linux & BSD

Ultralehký solární elektrostatický dron může létat (téměř) věčně

OSEL.cz - 20 Červenec, 2024 - 00:00
Čínský miniaturní vrtulník ColoumbFly má pouhých 4,21 gramů. Pohání ho ultralehký elektrostatický motor se solárními panely. Teoreticky může ColoumbFly létat neustále, tedy pokud svítí slunce nebo se dron nerozbije. Konstrukce se zdá být stabilní a po vylepšení ovládání a zvětšení kapacity pro náklad by dron mohl díky své výdrži a nenápadnosti najít široké uplatnění.
Kategorie: Věda a technika

Těžba síry na Mélu – odedávna do roku 1958

OSEL.cz - 20 Červenec, 2024 - 00:00
Surovinové bohatství ostrova od nejstarší doby po současnost, teď se zřetelem k síře. Popis výletu k sirným dolům s ruinami fabriky, která krachla roku 1958. Taková nostalgická průmyslová památka.
Kategorie: Věda a technika

UK cops arrest teen suspect in MGM Resorts cyberattack probe

The Register - Anti-Virus - 19 Červenec, 2024 - 23:51
17-year-old cuffed as FBI says it will 'relentlessly pursue' miscreants around the globe

Cops in the UK have arrested a suspected member of the notorious Scattered Spider crime gang, which is accused of crippling MGM Resorts in Las Vegas with ransomware last summer.…

Kategorie: Viry a Červi

OpenAI’s Project Strawberry Said to Be Building AI That Reasons and Does ‘Deep Research’

Singularity HUB - 19 Červenec, 2024 - 21:44

Despite their uncanny language skills, today’s leading AI chatbots still struggle with reasoning. A secretive new project from OpenAI could reportedly be on the verge of changing that.

While today’s large language models can already carry out a host of useful tasks, they’re still a long way from replicating the kind of problem-solving capabilities humans have. In particular, they’re not good at dealing with challenges that require them to take multiple steps to reach a solution.

Imbuing AI with those kinds of skills would greatly increase its utility and has been a major focus for many of the leading research labs. According to recent reports, OpenAI may be close to a breakthrough in this area.

An article in Reuters claimed its journalists had been shown an internal document from the company discussing a project code-named Strawberry that is building models capable of planning, navigating the internet autonomously, and carrying out what OpenAI refers to as “deep research.”

A separate story from Bloomberg said the company had demoed research at a recent all-hands meeting that gave its GPT-4 model skills described as similar to human reasoning abilities. It’s unclear whether the demo was part of project Strawberry.

According, to the Reuters report, project Strawberry is an extension of the Q* project that was revealed last year just before OpenAI CEO Sam Altman was ousted by the board. The model in question was supposedly capable of solving grade-school math problems.

That might sound innocuous, but some inside the company believed it signaled a breakthrough in problem-solving capabilities that could accelerate progress towards artificial general intelligence, or AGI. Math has long been an Achilles’ heel for large language models, and capabilities in this area are seen as a good proxy for reasoning skills.

A source told Reuters that OpenAI has tested a model internally that achieved a 90 percent score on a challenging test of AI math skills, though it again couldn’t confirm if this was related to project Strawberry. But another two sources reported seeing demos from the Q* project that involved models solving math and science questions that would be beyond today’s leading commercial AIs.

Exactly how OpenAI has achieved these enhanced capabilities is unclear at present. The Reuters report notes that Strawberry involves fine-tuning OpenAI’s existing large language models, which have already been trained on reams of data. The approach, according to the article, is similar to one detailed in a 2022 paper from Stanford researchers called Self-Taught Reasoner or STaR.

That method builds on a concept known as “chain-of-thought” prompting, in which a large language model is asked to explain the reasoning steps behind its answer to a query. In the STaR paper, the authors showed an AI model a handful of these “chain-of-thought” rationales as examples and then asked it to come up with answers and rationales for a large number of questions.

If it got the question wrong, the researchers would show the model the correct answer and then ask it to come up with a new rationale. The model was then fine-tuned on all of the rationales that led to a correct answer, and the process was repeated. This led to significantly improved performance on multiple datasets, and the researchers note that the approach effectively allowed the model to self-improve by training on reasoning data it had produced itself.

How closely Strawberry mimics this approach is unclear, but if it relies on self-generated data, that could be significant. The holy grail for many AI researchers is “recursive self-improvement,” in which weak AI can enhance its own capabilities to bootstrap itself to higher orders of intelligence.

However, it’s important to take vague leaks from commercial AI research labs with a pinch of salt. These companies are highly motivated to give the appearance of rapid progress behind the scenes.

The fact that project Strawberry seems to be little more than a rebranding of Q*, which was first reported over six months ago, should give pause. As far as concrete results go, publicly demonstrated progress has been fairly incremental, with the most recent AI releases from OpenAI, Google, and Anthropic providing modest improvements over previous versions.

At the same time, it would be unwise to discount the possibility of a significant breakthrough. Leading AI companies have been pouring billions of dollars into making the next great leap in performance, and reasoning has been an obvious bottleneck on which to focus resources. If OpenAI has genuinely made a significant advance, it probably won’t be long until we find out.

Image Credit: gemenuPixabay

Kategorie: Transhumanismus

CrowdStrike Windows patchpocalypse could take weeks to fix, IT admins fear

The Register - Anti-Virus - 19 Červenec, 2024 - 19:54
Our vultures gather to review this very freaky Friday

Kettle  If you're an IT administrator with Windows boxes on your network, Friday can't have been a lot of fun. What's likely millions of systems were or still are stuck in blue-screen boot loop hell, mostly requiring manual intervention to fix.…

Kategorie: Viry a Červi

Klimatické změny zpomalují otáčení Země, prodlužují délku dne a mění osu rotace

Živě.cz - 19 Červenec, 2024 - 19:45
Probíhající klimatické změny mají celou řadu dopadů na život na naší planetě. Vědci z ETH Zürich zjistili, že tání ledovců ovlivňuje způsob, jakým se Země otáčí, působí na zemskou osu rotace a délku dne. Tvrdí, že rychlost rotace, která byla dosud ovlivňována hlavně Měsícem, může v budoucnosti ...
Kategorie: IT News
Syndikovat obsah