Computerworld.com [Hacking News]

Syndikovat obsah
Making technology work for business
Aktualizace: 17 min 6 sek zpět

Virginia Tech researchers raise red flags about mixed-reality security

39 min 33 sek zpět

In a new study, researchers at Virginia Tech spelled out a variety of security hazards that could compromise mixed-reality systems.

The researchers highlighted security threats involving the manipulation of virtual objects when users collaborated via mixed reality headsets. The work involved 20 participants from the school, with most having little or no experience with mixed-reality headsets. In many cases, the participants did not know they were being attacked; instead, they blamed technical glitches or latency issues for the problems they encountered.

“Malicious entities could exploit vulnerabilities to disrupt critical collaborations, manipulating users’ perception of the environment, and impairing their ability to coordinate, potentially resulting in physical or psychological harm to users and bystanders,” the researchers said.

There has not been enough focus on potential vulnerabilities within the XR platforms, said Anshel Sag, principal analyst at Moor Insights & Strategy.

“The reality is that a lot of these platforms are pretty closed and it’s hard to evaluate the code,” Sag said.

The study was done using a HoloLens 2 headset, which Microsoft discontinued last year. The HoloLens 2 platform is out of date, Sag noted, something the researchers acknowledged.

“There are only a few collaboration platforms in use today for enterprise and defense, and a good chunk of the potentially vulnerable collaboration tools most likely don’t connect to the open internet,” Sag said. “That’s why I think a lot of the implementations that the government wants to use — or any kind of secure applications like enterprises [rely on] — need to have code evaluations and audits.”

The researchers said the attacks would be difficult for users to comprehend and identify. “An attack might alter the environment for one user without affecting the view of others or disrupt communication between users at a critical moment,” the researchers said. 

They noted the possibility of a “click redirection attack,” which they likened to web-based clickjacking. In this case, a malicious party could attack a 3D object in a collaborators’ field of view. When the person tries to move the object, the action affects another 3D object instead.

“The collaborative environment can make the unintended movement of virtual objects a potential cause of mistrust and confusion between the collaborators,” the researchers wrote.

Another attack — called an “object occlusion attack”— involved placing an invisible barrier on 3D objects to prevent interaction from a distance. And a “spatial occlusion attack” expanded that concept by placing an invisible boundary over a larger region and blocking interaction with multiple objects. 

Occlusion attacks could affect productivity in projects as collaborators might not have similar fields of view. That kind of attack would force headset users to get closer to virtual objects before they interact with them.

The researchers also launched a latency attack by slowing network speeds between participants’ headsets. The network attack significantly undermined the user experience.

To safeguard virtual systems, the researchers recommended educating users about potential security threats and building in security by design. Safety measures could include auditory cues to identify the location of objects and a warning system to identify security threats.

Additionally, headset developers could include UI changes with toggles and controls that “highlight all objects in the environment similar to basic 3D view management,” the researchers wrote.

The research study was written by Maha Sajid, Syed Ibrahim Mustafa Shah Bukhari, Bo Ji, and Brendan David-John. They could not be reached for comment.

Kategorie: Hacking & Security

AI-created disinformation could bring down banks

2 hodiny 30 min zpět

A new report by UK analyst firm Say No to Disinfo and communications firm Fenimore Harper indicates a high risk that AI-generated disinformation could create bank runs that could bring down financial institutions, according to Reuters.

In an experiment, a number of UK customers were shown AI-generated rumors about their bank. Afterwards, a third said they were “very likely” to withdraw their money, with 27% saying they were “quite likely” to do so.

According to the report, spending as little as £10 (about $12.60) on a fake AI message would be enough to persuade customers to withdraw more than $1 million from the bank in question.

Two years ago, false rumors that spread on social media sites about Silicon Valley Bank led customers to withdraw $42 billion in one day. The bank ended up being closed down.

Kategorie: Hacking & Security

Elon Musk doesn’t work for DOGE, says White House as battle for government servers intensifies

3 hodiny 53 min zpět

Attempts to challenge the power of Elon Musk and his DOGE team to close down government departments have hit an unexpected complication: according to the White House, the entrepreneur is not even in charge of the operation.

That surprising claim was made in court papers filed by the White House on Monday. Far from running DOGE, Musk is simply another “senior adviser to the president,” with no greater authority than any other advisor, according to an affidavit filed by the White House’s Director of the Office of Administration, Joshua Fisher.

“Like other senior White House advisors, Mr. Musk has no actual or formal authority to make government decisions himself. Mr. Musk can only advise the President and communicate the President’s objectives,” Fisher declared in the affidavit.

Musk is not an employee of DOGE, nor its administrator; his status is that of an employee of the White House, Fisher added.

His filing was in response to a complaint filed Feb. 13 by the attorneys general of 14 US states against “Elon Musk in his official capacity,” the US DOGE Service and its temporary organization, and President Trump himself, questioning the apparently unchecked power DOGE and Musk have been handed by Trump.

Their wording didn’t hold back, drawing an unflattering parallel between his behavior and the “despotic power” wielded by Britain’s King George III over the American colonies in the 18th century.

“Mr. Musk’s seemingly limitless and unchecked power to strip the government of its workforce and eliminate entire departments with the stroke of a pen or click of a mouse would have been shocking to those who won this country’s independence,” they said.

Musk did not occupy an office of state and had not been confirmed by the Senate, the states argued. This rendered his actions unconstitutional.

DOGE playbook

If Musk isn’t running DOGE, who is running it? And does this even matter? Unhelpfully, President Trump’s executive order bringing it into existence on day one of his administration never named a head. Nor, as critics have pointed out, did it explain how a department could have so much power or even be called a “department” without having to obtain approval from Congress first.

This is surely deliberate. If it’s not a department, it is not therefore bound by legislation governing freedom of information, privacy and administration. However, the White House’s refusal to acknowledge Musk as the head of DOGE is probably simply a delaying tactic. They will know that successfully identifying Musk as the person directing DOGE is important for his opponents’ legal arguments.

If Musk is not running DOGE, then who should be held responsible for its actions? It’s likely that a judge will eventually point out that someone, somewhere must be accountable for what DOGE is doing.

Exploiting a loophole

The problem with trying to stop Musk and DOGE is that he has attacked the system on several fronts simultaneously, often using unsubstantiated claims of fraud as his motivation. This includes turning up unannounced at the Treasury Department on January 20 and demanding access to payment servers which store the tax returns, social security data and bank account numbers of every adult US citizen. That access was blocked by a judge.

The same modus operandi has been repeated in other departments, creating a moving target for anyone trying to stop him. In response, some officials have chosen to resign rather than give Musk’s team access to data in a way that might not comply with existing data security and privacy rules.

What remains unclear is how much access has been granted, and to whom within DOGE. This has left a feeling of strained uncertainty.

“An internal email sent to BFS [Bureau of the Fiscal Services] IT personnel by the BFS threat intelligence team has identified DOGE access as “the single greatest insider threat risk the Bureau of the Fiscal Service has ever faced,” argued the state attorneys general as part of their recent legal challenge.

Furthermore, “The intelligence team recommended the DOGE members be monitored as an insider threat. Critically, they called for “suspending” any access to payment systems and “conducting a comprehensive review of all actions they may have taken on these systems,” it continued.

“Mr. Musk has gained sweeping and unprecedented access to sensitive data, information, systems, and technological and financial infrastructure across the federal government. This access is seemingly limitless and dependent upon Mr. Musk’s discretion.”

For now, there is nothing to stop Musk beyond a flurry of disconnected lawsuits by organizations and individuals. For its part, DOGE continues to hide in plain sight, exploiting the loophole that by avoiding being a formal department, it sits strangely beyond the usual rules.

Kategorie: Hacking & Security

The unbearable lateness of Apple Intelligence

9 hodin 52 min zpět

Apple has apparently delayed what is arguably its most important Apple Intelligence feature, contextual intelligence, by at least another month. It’s the latest chapter in what history will remember as the company’s most painfully slow, yet strategically significant, introduction yet. 

Bloomberg says Apple has hit a variety of obstacles in developing these tools, with the smart features the company wants to introduce not working consistently. 

The company is attempting to build on-screen awareness so Siri can act with the content you are seeing — it might save a message address or even run a series of nested commands such as pulling out a half remembered article from those you read the day before to send to a friend.

Apple has one example in which the intelligence extends to person recognition, so Siri might be able to tell you when your mom’s flight is landing, based on an old email containing her flight number and recognition of your relationship.

These are all sophisticated features, but ensuring they work consistently is essential. You don’t want families waiting forlornly for the wrong flight, or mom waiting for a ride that never arrives. Unlike AI-generated news headlines, these tools really need to work before they ship.

And word is, they don’t, at least not yet….

“Hey Siri, what’s that paperclip in Windows called?”

The inevitability of WWDC

The update had been expected to show its face in April with iOS 18.4. Now it won’t appear until one month before WWDC 2025, in iOS 18.5 in May.

That’s almost one full year since those features were first discussed at WWDC and shows the extent to which Apple has been forced to play for time in this deployment. It has managed to make that time, but the delay can’t be a good thing for the company, given it should also be pouring resources into improvements across all its operating systems as it prepares for its annual developer conference in June.

It begs questions such as just how much of the company’s resources are being spent on AI, and what, if any, additional Apple Intelligence tools it will be in position to announce this year.

One thing we do know is that Apple must announce something at WWDC. Developers will want to know the company is moving forward on AI. That means that merely reprising the features the company managed to ship slowly across the last 12 months won’t do. Nor will pointing enthusiastically at the new support for additional languages Apple is expected to introduce.  

To maintain relevance amid the clamor about Deep Seek or Open AI, Apple needs to justify what CEO Tim Cook promised in late 2024, when he said: “We’re pouring all of ourselves in here, and we work on things that are years in the making.”

Betting the bank

Apple understands this. Despite shuttering its Apple Car project, the company spent more on research and development in its just-past quarter than it did a year ago. ($8.2 billion versus $7.6 billion). R&D spending goes up most every year at the company and you can bet your bottom dollar (in comparison to Apple’s near infinite ones) that AI is part of that spending plan.

Throwing money at problems doesn’t always yield results, however. 

You need resource allocation and tight control to ensure all the different research teams are working effectively together. This has plainly been a challenge at Apple, given the company recently put one of its best, Kim Vorrath, in charge of getting Apple Intelligence to ship on time. Vorrath is working with John Giannandrea, Apple’s senior vice president for machine learning and AI, whose team was reportedly sidelined for access to developer resources until early 2023, according to an earlier Wall Street Journal report. This is no longer true.

Facing the challenge

While Giannandrea’s team builds on the AI-driven tools Apple already has in place, the challenges faced by his group mean they must not only deliver AI in an Apple way, but do so in a way that visibly competes with the larger pure AI companies its rivals are already partnering with.

With so much at stake, it is perhaps better to delay rather than ship anything that does not work. But people’s patience with such delays will not be infinite and with Open AI still threatening to introduce its own device designed by iPod designer Jony Ive, Apple’s execs surely feel a degree of performance anxiety as they struggle to be the real artists they are reputed to be.

Real artists, as Steve Jobs once said, are the people who ship.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon, and MeWe

Kategorie: Hacking & Security

Trump and EU Commission set course for confrontation on big tech

11 hodin 5 min zpět
width="2193" height="1234" sizes="(max-width: 2193px) 100vw, 2193px">With the second Trump administration, very different cultures are once again clashing in the transatlantic relationship.

rawf8 – shutterstock.com

The recently inaugurated US President Donald Trump has turned the trusting relationship between the United States and Europe on its head, according to the EU’s new Competition Commissioner, Teresa Ribera. Brussels must now ensure reliability and stability, factors that no longer exist in Washington. In an interview with the Reuters news agency, the politician called on Europe to continue negotiating with the White House and listen to the US government’s concerns on trade issues, but not to allow any changes to EU laws to be forced upon it.

“We need to stick to our strengths and principles,” Ribera told Reuters. “We need to be flexible but we cannot transact on human rights nor are we going to transact on the unity of Europe, and we are not going to transact on democracy and values.”

Trump and his followers in the US government had recently criticized the EU for its rules and regulations. The fines imposed by the EU on US technology companies are a kind of punitive tax.

JD Vance: EU restricts freedom of speech

US Vice President J.D. Vance used his appearance at the Munich Security Conference in mid-February for a general reckoning with Europe. He said EU Commissioners were suppressing freedom of expression and restricting access to online platforms and search engines in certain situations with the help of the Digital Services Act.

Ribera reacted to the accusations with incomprehension. “If there is a problem, a point of concern, please explain that,” the EU Commissioner said. “That doesn’t make sense.”

Volker Wissing, Federal Minister for Digital Affairs and Transport, also made it clear that European values are not negotiable, neither through political pressure nor through market dominance. “Anyone who believes that European rules can be dictated from outside is very much mistaken,” emphasized the politician. “The EU Commission must consistently enforce the Digital Services Act (DSA) – without compromises and without deals. Anyone who confuses freedom of expression with the freedom to spread hate and disinformation is misjudging the foundations of our values.”

Ribera announced that the EU will issue decisions in March 2025 on whether Apple and Meta have complied with European rules. Both US companies have been under observation by antitrust watchdogs for around a year. They could face heavy fines if it turns out that they have violated the Digital Markets Act. The EU Commissioner rejected speculation that the decisions could be delayed in view of the massive criticism from the US administration.

The Spanish politician also announced that Trump buddy Elon Musk’s social media platform X would remain under observation. Musk’s role within the US government plays no role in this, she said.

Amazon faces billions in fines in Italy

Amazon is finding out that European authorities don’t take kindly to rules and laws being violated. Public prosecutors in Italy are investigating whether the world’s largest online retailer has cheated tax authorities there out of €1.2 billion in value-added tax (VAT). Since 2019, a law in Italy has obliged e-commerce platforms to pay the VAT incurred by third-party sellers outside the EU if they sell goods in Italy via the platform.

The investigations by the public prosecutor’s office cover the period from 2019 to 2021 and were concluded in December, according to various media reports. Amazon is facing a penatly of over €3 billion, according to the Guardia di Finanza. Amazon will not comment on the investigations, according to a report by the French news portal France 24. However, the online retailer asserts that it is committed to complying with all applicable tax laws.

Amazon’s tax practices have been criticized for years. Despite billions in sales, the company shifts its profits to tax havens such as Luxembourg in order to avoid taxes, complained British Labour MP Margret Hodge back in 2022. The EU Commission, on the one hand, and Amazon and Luxembourg, on the other, have been arguing for years about whether Amazon’s tax advantages in Luxembourg are illegal or compliant with EU state aid rules. Amazon itself asserts that it works in full compliance with local tax laws everywhere.

Kategorie: Hacking & Security

Q&A: ManpowerGroup exec explains how to manage an AI workforce

11 hodin 47 min zpět

Generative AI (genAI) projects will move from pilot phase to production for many companies this year, which means the workforce will be affected in ways never before imagined. One of those ways will involve onboarding AI agents as new digital employees.

One of the focus areas for global staffing firm ManpowerGroup has been its proprietary platform, Sophie, which leverages AI to tackle talent screening tasks. The staffing firm sees AI agents as playing a central role in sifting through job applicant data for clients, identify market trends, and offer job applicant suggestions. When Sophie provides a recommendation — either for or against a candidate — it also explains the reasoning behind it. 

“We view Sophie as a partner to help you focus on what truly matters: finding the right people and building a workplace grounded in honesty, respect, and mutual confidence,” said Carolyn Balkin, general manager for Global Client Solutions at ManpowerGroup.

Professional services firm Accenture has even developed a program for onboarding agentic AI digital “employees” to help “agents make the right connections and provide feedback to improve their performance.”

The company borrowed a page from its HR best practices on team integration to ensure agents were introduced to the marketing team and understood their roles. It also created feedback loops that enabled simple, two-way feedback between human marketers and agents, which turned out to be key in establishing “collaboration and mutual learning.”

AI adoption also means that practically every employee, whether they’re part of an IT organization or a business group, must become familiar with chatbots and other large language model-related technology to better do their jobs.

What organizations are seeking in new talent has shifted as AI continues to take on the more repetitive predictable tasks, requiring workers to focus more on creating new business value.

ManpowerGroup’s Balkin manages IT, technology and telecommunications industry vertical clients, and she has been advising organizations about what it means to manage AI employees. One of the biggest challenges: finding the kind of talent they’ll need that can work with AI and figuring out how to integrate agents across business groups.

Carolyn Balkin, general manager for Global Client Solutions at staffing firm ManpowerGroup

ManpowerGroup

How has managing employees changed since the adoption of AI in the workplace? “I think you know that’s where the soft skills have really come into play, because it is not just a technology. I was at the Davos Conference recently, and a lot of the conversations were about AI, and a number of organizations talked about. It’s not just a technology anymore. We are looking for individuals that have the industry experience. We can take somebody with industry experience and train them on the technical part of the job.

“It’s a lot harder for us to take somebody with the technical skills and teach them how the industry works. I think there’s a focus on looking at the soft skills: the problem solving, the complex reasoning ability, and communications. Because it’s not just developing AI for the sake of software technology; it’s to address that larger business problem. It’s about looking at all of the business functions, and taking all of that into consideration.

“So, I think it is more than just the technology play now. And therefore, when managing these people, it’s not just managing a technical group anymore. You’re managing people who are bringing a different perspective, a different experience, and different soft skills to play, and it’s about how do you pull all of that together.”

How do you go about managing that other type of AI employee — the digital agent, or the AI itself that is becoming another kind of employee? “We do have some early adopters that have put in place these agent workforces. I do know it has changed how they’re looking at workforce management. It’s about what can my agents do? You’re almost looking at agents as the new intern of the company. What can the agents do transactionally, and then what skills do I need to manage that on top of the agents? So, what technical skills do I need, and what soft skills do I need in my employees to manage those agents? And that becomes the workforce plan.

“Then it’s looking at location strategy. In the past, organizations have led with location in the past; now, it’s about getting the agent strategy right. First, figure out what you can take from your transactional workers and then focus on what skills you need.

“Then you have to consider employee upskilling or reskilling. I think organizations are going to have to become much more proactive on their upskilling and reskilling programs. We’ve heard so much about this for the last couple of years, and I think there’s a gap where organizations believe they have strong programs. But when you talk to employees within these companies, they don’t feel there’s been the opportunities to upskill and reskill. So, I think we’re going to have to see more structure around those programs.”

So, how are you managing the digital employee you call Sophie? “Behind Sophie is a cross-functional group that bridges technical expertise and real-world understanding. AI and machine learning experts collaborate with sales and operational professionals, along with individuals who study how people interact with technology. Together, they work toward maintaining our commitment to fairness and trust by:”

  • Running ongoing checks to spot hidden biases in how Sophie interprets data.
  • Protecting personal information through strong security protocols and compliance practices.
  • Offering transparent decision-making details so you always see why Sophie has chosen a particular path.

So would you say managing your digital workforce or managing your agentic workforce is kind of the next frontier? “I definitely think so. I mean, it’s just a collaboration across the agents. And look how fast AI came on board, and now it’s just getting smarter and harder. You know how it’s collaborating with each other. And you know, you have to teach it, too. It’s not going to be just like humans. It’s not going to be 100% accurate, so you need to monitor it; it’s going to create different jobs. You know, back to your question, will it create jobs or kill jobs? Don’t know yet.

“I think they’ll definitely be different, though, because now you have people looking at the quality of what’s coming out of the agents, testing to see if it’s accurate, training the agent. So it will create a whole new set of roles, and it’s going to affect every industry. In manufacturing, for example, organizations are using AI agents for quality control, and doing things significantly faster than they’ve been able to do in the past.”

What industries are being affected the most quickly? “I would say it’s your tech companies that are probably the early adopters, because for them to sell something, clients want a case study. They want to know where you’ve done this and what the impact has been. So, the tech companies see themselves as client zero in order to demo a lot of these new tools and technologies.”

What kinds of problems is AI introducing from an employee management standpoint? Do you believe every company is a technology company and every employee is a technologist to some extent? “Technically, yes, I do believe that. The problem is [that] the gap is getting wider between those employees who understand AI technology and are willing to learn more about it and those who don’t want to have anything to do with it. But I think everybody will be a technologist, eventually. It’s going to be talent augmented by technology.

“I was recently talking to a business manager, and he said while there’s always going to be an IT group, it’s no longer going to be the harbinger, or the only ones who own the technology.”

You have people in marketing, in advertising, in customer support, all the various branches of a business that need to be tech savvy. What’s needed to manage a workforce where everyone is using AI in one form or another? “I think you need a lot more collaboration across the workforce, because historically it has always operated in a very siloed way. You’d roll technology out from one place to the rest of the organization. As you adopt more AI, you can’t do that anymore.

“A big topic at the Davos conference was agentic AI, and that is really all about collaboration. A lot of the large language models — generative AI — have been historically working in a silo. You ask it a query; it shoots out an answer to you.

“The AI that’s under development at a lot of these organizations today is more the agentic AI, which is collaboration of various AI apps and a collaboration of your various data sets. So, that creates a lot more questions because you’ve got to have governance of all those agents. You’ve got to have platforms and the technology behind that.

“There has to be the governance model in play. You need to look at the business holistically in order to manage AI across all of those areas, so you don’t have department doing one thing that might conflict with what another may be doing. They all really need to be aligned so that they’re functioning with each other.”

Anecdotally, when I talk to folks who are out of work, even people who have years of experience technology, they’re having a hard time finding jobs. What do you see happening? Is it harder to get a technology job now, and what skills are companies looking for? “I think it is harder to land a technology job right now. And I think part of that might just be a reflection on where the market is. I know there’s been a lot of stability in the IT tech sector, but organizations haven’t been hiring on additional talent. And some of that is 2024 seemed to be a settling period where there was a lot of adoption of AI. This year it’s about the impact of AI. And I think organizations, No. 1 are trying to figure out. What does their workforce look like? Where do they need to bring in additional talent?

“And then No. 2, what does that talent look like? And I don’t think they’re there yet. Then you throw in the whole agent workforce, and that adds to the problem.

“There are more mature companies when it comes to AI — the IBMs of the world, the Accentures, the Salesforces; they’re looking at how AI agents are becoming part of their workforce planning. When understanding what your needs are, you first have to consider what the agents will cover those needs, and then figure out what employee skills are needed on top of them.

“And I think that’s the other piece — from a management perspective, it’s become more multifaceted in the approach that companies are taking. They’re not looking for job- centric people anymore. It’s more about the skills-people have.”

When you say less job-centric, what does that mean? “In the past, you would post a job and it would list the tasks of the job. Now, managers are focused more on skills needed to perform in their business. So, these are the skills that we need to support the project.

“I actually had an interesting conversation with a client yesterday, and they were even talking about soft skills, with AI becoming more front and center when it comes to reasoning and problem solving. You assess that along with the technical skills an employee brings to the job. Businesses are looking at assessments that can help them evaluate the soft skills, some of the cognitive reasoning skills [potential hires have].”

Data shows that the number and types of jobs are growing with the advance of AI, but at the same time, there is evidence AI is reducing employee headcount — taking on tasks formerly done by employees. Which do you believe it is? Or is it both? “Is AI is going to reduce workforce sizes, lead to more people being laid off, or is it going to create more opportunities? It’s hard to say. I mean, it could go either way. But I think it’s going to impact more of the transactional roles. It will take a lot of the low-level transactional work away, but what it will also do is allow people to focus on those specialized skills.

“We’ve been talking about how software development is happening so much faster with AI. So, companies are looking for more specialized skill sets. I think there’ll be a shift from the generic skills that companies brought on in the past to more specialized skills that they’re going to need in the future.”

Can you give me some examples of the specialized skill sets? “For example, SAP engineers, SAP architect, AWS skills, and Salesforce skills. Those are some of the software areas that companies are looking for more specialized talent.”

So, you’re saying hiring will be based on skills that are specific to the applications and the AI that is becoming a part of that? “Even cybersecurity. While we’ve been talking about software, cybersecurity is another area that’s going to be very important because you’re opening up some doors with AI related to security and data privacy.”

Where do you even start with that cybersecurity and AI? It seems almost amorphous if AI is in every corner of a business. “There are so many things, and it’s happening so fast. So, we are still learning as fast as we can. We’re trying to understand what the impact of AI will be, and how it will change our business models. Even from a talent organization like ours, which is providing global talent solutions, what does that do for us?

“Now, our company is going to start looking for your talent plus the AI agents you’ll need. So AI becomes part of a hiring solution. There are a lot of companies that are developing AI boot camps for the C-suite executives and opening their eyes to what’s out there. Think about it. At universities like MIT, it used to take teams of scientists years to develop what can now be done in a matter of seconds.

“Right now, companies are taking a step back to discover what the business challenges are that need to be solved because of AI automation. They’re trying to discover the best way to do that. I don’t think there’s a lot of academia programs developed for that. I think a lot of it is pilot programs that involve peers talking about the issues.”

Kategorie: Hacking & Security

Musk’s xAI launches Grok 3, expanding AI capabilities with deep search and reasoning

12 hodin 22 min zpět

Elon Musk’s AI startup xAI has introduced Grok 3, the latest version of its chatbot model, which Musk describes as the most advanced AI system yet.

xAI claims Grok 3 outperforms rival AI models from Alphabet’s Google Gemini, DeepSeek’s V3, Anthropic’s Claude, and OpenAI’s GPT-4o in benchmarks for math, science, and coding.

“About a month ago, Grok 3’s pre-training was completed, and since then, we’ve been working hard to integrate reasoning capabilities into the current Grok 3 model,” the company said during its launch event on Monday.

Musk, speaking alongside three xAI engineers in a live-streamed presentation, said Grok 3 has more than ten times the compute power of its predecessor.

DeepSearch and enterprise push

xAI also introduced DeepSearch, an AI-powered intelligent search engine that functions as a reasoning-based chatbot, explaining its thought process when interpreting queries and formulating responses.

Building on these capabilities, the company plans to roll out Grok-3’s API in the coming weeks, expanding its reasoning and deep search features.

The move signals xAI’s broader push into the enterprise and developer markets, where AI-driven automation and decision-making tools are in high demand.

“Grok 3 is stepping into a fiercely competitive arena alongside ChatGPT and Microsoft Copilot, and its success will depend on real-world performance in code generation, automation, and enterprise AI workflows,” said Abhivyakti Sengar, senior analyst at Everest Group. “If xAI delivers on its promises, it could disrupt the market. However, before enterprises integrate Grok 3, CIOs must rigorously evaluate its security and compliance measures.” 

Grok 3 is now available to Premium Plus subscribers on X. xAI is also launching a new subscription tier, SuperGrok, which will provide access via the Grok mobile app and website.

The company is also developing a voice interaction feature aimed at enhancing conversational AI experiences, further expanding its capabilities beyond text-based interactions.

Intensifying AI competition

Grok 3’s launch comes as competition in the AI sector intensifies, with companies racing to develop more powerful and efficient models. Industry analysts see Grok-3’s release as a pivotal moment in this landscape.

“With Grok 3, we expect to see a significant acceleration in R&D innovation across the AI landscape, as it solidifies its leadership position against established players like OpenAI and Google,” said Prabhu Ram, VP of the industry research group at Cybermedia Research. “Grok 3’s advanced capabilities will drive heightened enterprise interest in AI solutions, enabling greater efficiency and smarter decision-making.”

As xAI expands into search and enterprise AI applications, the battle for dominance in generative AI is set to escalate further.

Musk founded xAI in 2023 as a rival to OpenAI, a company he has openly criticized for shifting toward a for-profit model.

With Grok-3’s introduction and upcoming API launch, xAI is positioning itself as a serious contender in the AI market. However, its long-term success will depend on adoption rates, performance benchmarks, and its ability to meet enterprise security and compliance demands. “Understanding how it processes and stores data, ensuring confidentiality, and aligning with regulations like GDPR will be critical,” Sengar said. “A thorough security audit and close collaboration with xAI’s team can help mitigate risks and ensure a smooth deployment.”

Kategorie: Hacking & Security

Neudesic seeks to speed up AI adoption for IT teams

22 hodiny 57 min zpět

Artificial intelligence (AI) has gained significant traction among business leaders keen to explore ways it can drive operational efficiencies and cost savings.

But while top leadership is sold on its potential, it’s a different tale for IT teams working the ground. In Australia, the challenges of implementing AI are particularly pronounced, ranging from limited expertise and siloed operations to the rising tide of cybersecurity risks. It’s no surprise then that in the face of complexity, companies are not sure how to take the first step towards smooth and successful AI deployments.

Australia’s AI challenges

Access to skilled resources, funding issues and keeping ahead of AI’s rapid evolution are just some of the challenges that make it difficult to implement AI solutions uniformly in Australia. For mid-market companies in highly regulated industries, such as finance, energy, and utilities, addressing cybersecurity concerns and responsible AI implementation are also on the list.

“From an AI context, their challenges are similar to other sectors. This includes access to talent, quality of data, integration with legacy systems, change management, and ethical and regulatory concerns. However, they also face heightened cyber threats and fraud, driven by threat actors leveraging AI to become more sophisticated. The consequence of a breach can be significant from both a financial and consumer trust perspective,” explains John Hanna, Neudesic Australia

Ultimately, the breadth of data mid-market companies in finance, energy, and utilities need to deal with is beyond the capabilities of existing systems that rely on the identification of known patterns or human analysis. “By adopting AI, these companies gain the capability to analyse information at scale and speed to identify and stop these threats before they significantly impact the business,” adds Hanna.

To overcome these challenges, Neudesic helps organisations through its expertise, cutting-edge technology, and strong partnerships with Microsoft, having won the Microsoft Partner of the Year award over 20 times. As a global professional services firm, Neudesic is now bringing decades of experience delivering capabilities spanning data and AI, cloud migration and modernisation, application development, and business strategy to Australia.

Hanna shares Neudesic’s approach, which comprises four pillars.

  • People: Its diverse array of internal experts spanning industries, skillsets, and Microsoft Azure and OpenAI solutions help clients address a wide spectrum of business challenges for any organisation
  • Approach: It achieves results not only by implementing Microsoft and OpenAI solutions, but also by addressing today’s challenges, identifying tomorrow’s opportunities, and designing the best path forward
  • Technology: It focuses on innovation to develop solutions that meet clients’ needs while accelerating time to value
  • Expertise: With 20 years of expertise in Microsoft’s stack, it offers clients expert knowledge to tackle critical IT challenges and unlock new opportunities

Neudesic’s process starts with understanding each client’s business needs, followed by collaborative workshops and rapid prototyping. The team will then develop a roadmap aligned with a client’s goals and ensure ongoing model refinement, data updates, and process improvements.

“We are also backed by IBM and Microsoft. What this means for customers is access to the expertise and experience of experts across both tech stacks dedicated to solving the most critical IT challenges of Australian businesses and capturing new growth opportunities,” says Hanna.

Simplifying critical industry processes with AI

A clear example of how Neudesic is driving AI is in simplifying the Know Your Customer (KYC) process in finance, also known as identity verification.

KYC is where good customer experience is critical, but traditional KYC processes can take days or even weeks. According to a report conducted by financial compliance software company Fenergo, eight out of ten survey respondents would lose clients to an inefficient onboarding process. More than ever, there is a need for streamlined and intelligent document processing solutions to stay competitive.  

Neudesic’s Document Intelligence Platform helps automate the KYC process by capturing customer data from various formats, cross-referencing it with databases, and validating the information in real-time. It also streamlines compliance with customer identification programs. 

What does this mean for financial organisations? They can now handle high volumes of KYC checks without additional staffing, while automation cuts operational costs. Real-time verification speeds up processes like account openings and loan approvals so that banks can acquire and manage customer assets sooner. What’s more, the platform integrates seamlessly with existing systems like Fenergo for a more robust and efficient workflow.

By partnering with integrators like Neudesic, Australian businesses can deploy AI through a proven, logical methodology and unlock the ability to invest and accelerate AI use based on business demand and available capital.

“Every business dreams big with AI but can stumble when turning ambition into action. Success demands strategy, tailored solutions, and expert guidance. With a trusted partner, businesses can avoid common pitfalls and mistakes that will result in less investment remorse and create business confidence in AI faster than would otherwise be possible,” concludes Hanna.

Learn more about how Neudesic can help Australian organisations go forward in AI, confidently.

Kategorie: Hacking & Security

Court ban on Google AI stakes would hurt Anthropic clients, say analysts

17 Únor, 2025 - 15:44

Anthropic has asked a US court for permission to intervene in the remedy phase of an antitrust case against Google, arguing that the US government’s call for a ban on Google investing in AI developers could hurt it.

Analysts suggest the AI startup’s fears are founded, and that it risks losing customers if the government’s proposal is adopted.

“Its enterprise clients might face uncertainties regarding the continuity of services and support, potentially affecting their operations,” said Charlie Dai, principal analyst at Forrester.

The government’s proposed remedies including the ban on AI investments after the US District Court for the District of Columbia found the search giant guilty of maintaining a monopoly in online search and text advertising markets in August 2024.

The proposed investment ban is aimed at stopping Google from gaining control over products that deal with or control consumer search information, and in addition to preventing further investment in any AI startup would also force it to sell stakes it currently holds, including the $3 billion one in Anthropic.

On Friday, Anthropic filed a request to participate in the remedy phase of the trial as an amicus curiæ or friend of the court.

“A forced, expedited sale of Google’s stake in Anthropic could depress Anthropic’s market value and hinder Anthropic’s ability to raise the capital needed to fund its operations in the future, seriously impacting Anthropic’s ability to develop new products and remain competitive in the tight race at the AI frontier,” the AI startup said in a court filing justifying the request.

It said it had contacted representatives for the plaintiffs in the case — the US government and several US states — seeking to influence the proposal.

Remedy wouldn’t just affect Google

While Anthropic’s primary concern is that the proposed investment ban could hurt the value of the company, it is also worried that it could put it on the back foot against rivals.

“This would provide an unjustified windfall to Anthropic’s much larger competitors in the AI space —including OpenAI, Meta, and ironically Google itself, which (through its DeepMind subsidiary) markets an AI language model, Gemini, that directly competes with Anthropic’s Claude line of products,” the company said in the filing.

Abhivyakti Sengar, senior analyst at Everest Group also shares Anthropic’s view on the effect of the proposed ban.

“Forcing Google to sell its stake in Anthropic throws a wrench into one of the AI industry’s most significant partnerships,” Sengar said, adding that while it might not cause an immediate loss of customers, any disruption to the performance or reliability of Anthropic’s models or its innovation speed could drive business towards its rivals.

The AI startup, additionally, tried to differentiate itself with rivals, such as OpenAI, by pointing out that unlike its competitors it is not owned or dominated by a single technology giant.

“While both Amazon and Google have invested in Anthropic, neither company exercises control over Anthropic. Google, in particular, owns a minority of the company and it has no voting rights, board seats, or even board observer rights,” it said in the filing.

Further, it said that Google doesn’t have any exclusive rights to any of its products despite investing nearly $3 billion since 2022 in two forms, direct equity purchase and purchases of debt instruments that can be converted into equity.

AI was “never part of the case”

Among the arguments that Anthropic makes against the proposed remedy, it notes that neither it nor Google’s other AI investments were ever a part of the case.

“Neither complaint alleged any anticompetitive conduct related to AI, and neither mentioned Anthropic. The only mention of AI in either complaint was a passing reference in the US Plaintiffs’ complaint to AI ‘voice assistants’ as one of several ‘access points’ through which mobile-device users could access Google’s search services,” it said in the filing.

In addition, it claimed that forcing Google to sell its stake could diminish Anthropic’s “ability to fund its operations and potentially depress its market value” as alternative investors deal in millions and not the billions Google invested.

“Forcing Google to sell its entire existing stake in Anthropic within a short period of time would flood the market, sating investors who would otherwise fund Anthropic in the future,” it said in the filing.

Analysts too warned that the future of Anthropic’s operations and its ability to retain customers will depend on the startup’s ability to secure investment if the proposal is adopted.

That, said Everest’s Sengar, “will determine whether it will be a setback or an opportunity for greater independence in the AI race.”

Forrester’s Dai agreed, adding that if Anthropic can quickly reassure its customers and demonstrate a clear plan for continuity and innovation, it may retain their trust and loyalty.

Kategorie: Hacking & Security

Why enterprises are choosing smart glasses that talk — not overwhelm

17 Únor, 2025 - 13:34

Meta’s Ray-Ban smart glasses have quietly achieved a milestone that its enterprise-focused competitors could only dream of — selling over two million pairs since their debut in October 2023.

EssilorLuxottica, the eyewear giant that manufactures glasses for Meta, has recently announced that two million pairs of Meta Ray-Bans have been sold since their October 2023 launch. The company also aims to produce 10 million Meta glasses annually by the end of 2026.

In contrast, Microsoft’s HoloLens and Apple’s Vision Pro have struggled to gain traction despite their advanced mixed-reality capabilities. (Microsoft has reportedly discontinued production of its HoloLens 2 headset, although existing units are still available for purchase.)

The answer may lie not just in features or branding but in the fundamental user interface itself — Meta’s lightweight, audio-focused design seems to align more with enterprise needs than fully immersive mixed-reality headsets.

“The biggest barriers to AR headset adoption have been cost, efficiency, and battery life, all of which become more challenging with higher levels of immersivity,” said Neil Shah, VP for research and partner at Counterpoint Research. “Additionally, the lack of a standardized OS or UI has made enterprise integration more fragmented.”

“Rather than pushing an entirely new wearable concept, Meta retrofitted VR capabilities into an existing accessory that people were already comfortable with,” said Faisal Kawoosa, founder and lead analyst at Techarc. “The partnership with Ray-Ban also played a key role in making these smart glasses more socially acceptable.”

Enterprise adoption: simplicity over immersion?

While Microsoft’s HoloLens and Apple’s Vision Pro pushed the boundaries of augmented and virtual reality, their enterprise adoption remained limited due to cost, complexity, and user resistance. HoloLens found some traction in industrial training and fieldwork, and Vision Pro positioned itself as the future of spatial computing, but neither saw mass adoption.

“The failure of AR-heavy wearables such as HoloLens and Vision Pro highlights a fundamental mismatch with workplace needs,” said Riya Agrawal, senior analyst at Everest Group. “High costs, complexity of use, and extensive training requirements have slowed deployment. Furthermore, frontline workers—especially in field services—typically need quick, hands-free AI assistance rather than distracting digital overlays.”

Meta’s smart glasses, in contrast, take a different approach. They offer an audio-centric interface with a discreet camera, enabling hands-free communication, real-time guidance, and live transcription without overwhelming users with AR overlays.

This approach fits naturally into enterprise workflows where workers need digital assistance without obstructing their physical environment.

“Enterprise users ideally seek more immersion for use cases like design and development, but current AR/VR limitations make mainstream adoption difficult,” Shah pointed out. “While immersive headsets promise to overlay the digital world onto the physical, limited app integrations and power-hungry designs hinder their viability in real-world enterprise settings.”

“In the enterprise space, VR applications tend to be highly specialized and customized to specific business needs,” Kawoosa added. “Unlike consumer VR, which benefits from broad applications, enterprises see AR as a layer within their existing tech stack rather than a standalone solution. This means generic, one-size-fits-all AR/VR products may struggle in the long run.”

Why do enterprise users prefer audio-centric wearables?

Seamless integration into daily workflows has been a major reason for the success of Meta’s smart glasses. Unlike bulky AR headsets, they resemble traditional eyewear, making them more socially and professionally acceptable in meetings, fieldwork, and customer interactions. Open-ear speakers allow users to receive AI-powered insights, instructions, or language translations while staying engaged with their surroundings.

“In many enterprise use cases, HoloLens and Vision Pro offer more computational power than necessary, which only drives up costs without delivering proportional benefits,” Agrawal said. “Smart glasses or audio-driven interfaces solve this by being more cost-effective and practical, aligning better with enterprise workflows.”

The cost has been another decisive factor.

Vision Pro and HoloLens come at steep prices — Apple’s headset costs $3,499, and HoloLens 2 starts at around $3,500. Meanwhile, Meta’s Ray-Ban smart glasses start at a fraction of that price — less than $380, making them more viable for enterprise deployment at scale. Lower costs encourage broader experimentation, allowing businesses to deploy smart glasses across departments rather than limiting them to niche applications.

For field workers, hands-free assistance is critical. Remote guidance and real-time AI-driven instructions are invaluable in sectors like logistics, healthcare, and maintenance.

“For frontline agents, minimizing visual overload is key,” Agrawal said. “The lightweight design and better battery life of smart glasses make them truly wearable all day, unlike bulkier AR headsets that drain power quickly.”

Meta’s smart glasses enable professionals to stream video to remote experts without interrupting their workflow. In contrast, Vision Pro and HoloLens often require users to engage with floating screens or hand gestures, which may not be practical for workers who need to stay focused on manual tasks.

“Simple, AI-driven smart glasses — such as Meta’s Ray-Ban models — offer a hands-free and ear-free approach that feels natural,” said Shah. “Features like real-time guidance for warehouse workers, last-mile delivery directions, and field service assistance make them useful in enterprise settings without the complexity of AR overlays.”

Another key advantage is the ease of adoption. Employees are less likely to resist using audio-centric glasses compared to full-fledged AR headsets, which can feel intrusive or overwhelming.

“The appeal of smart glasses extends beyond cost — they also offer faster adoption and return on investment,” Agrawal pointed out. “Compared to full AR headsets, they require minimal training, making enterprise-wide deployment easier and more scalable.”

Training time is minimal, as users can interact naturally through voice commands and AI-based responses, making enterprise adoption smoother.

“Audio-based interfaces make even more sense in enterprise settings, where they function like an AI-powered assistant — essentially a ‘machine colleague’ that can provide real-time guidance, transcriptions, and hands-free instructions,” Kawoosa pointed out.

The future: will more enterprises embrace smart audio glasses?

With plans to scale up production to 10 million units annually by 2026, Meta’s strategy suggests that audio-first smart glasses could become a staple in enterprise environments.

Meanwhile, reports indicate that Meta is working on a version with an integrated display, potentially bringing a hybrid approach that balances visual AR with the audio-first experience that has proven successful.

“While AR and VR can augment meaningful enterprise use cases, their economic and ergonomic limitations have slowed adoption,” Counterpoint’s Shah said. “Simpler AI-powered glasses are serving as an entry point, building familiarity before AR technology matures.”

As immersive AR headsets struggle to find their footing, the rapid success of Meta’s smart glasses may signal a shift in how enterprises perceive wearable technology. Instead of seeking full virtual immersion, businesses may prioritize frictionless, real-world interactions — an area where audio-first smart glasses appear to have the upper hand. “While enterprises currently prefer augmentation over full immersion, AI-driven advancements could accelerate VR adoption in the long term,” Kawoosa said, adding, “However, we are still in the early stages of that transition.”

Kategorie: Hacking & Security

GenAI can make us dumber — even while boosting efficiency

17 Únor, 2025 - 12:00

Generative AI (genAI) tools based on deep learning are quickly gaining adoption, but their use is raising concerns about how they affect human thought.

A new survey and analysis by Carnegie Mellon and Microsoft of 319 knowledge workers who use genAI tools (such as ChatGPT or Copilot) at least weekly showed that while the technology improves efficiency, it can also reduce critical thinking engagement, could lead to over-reliance, and might diminish problem-solving skills over time.

“A key irony of automation is that by mechanizing routine tasks and leaving exception-handling to the human user, you deprive the user of the routine opportunities to practice their judgement and strengthen their cognitive musculature, leaving them atrophied and unprepared when the exceptions do arise,” the study found.

Overall, workers’ confidence in genAI’s abilities correlates with less effort in critical thinking. The focus of critical thinking shifts from gathering information to verifying it, from problem-solving to integrating AI responses, and from executing tasks to overseeing them. The study suggests that genAI tools should be designed to better support critical thinking by addressing workers’ awareness, motivation, and ability barriers.

The research specifically examines the potential impact of genAI on critical thinking and whether “cognitive offloading” could be harmful. Cognitive offloading, or the process of using external devices or processes to reduce mental effort, is not new; it’s been used for centuries.

For example, something as simple as writing things down, or relying on others to help with remembering, problem-solving, or decision-making is a form of cognitive offloading. So is using a calculator instead of mental math.

The paper examined how genAI’s cognitive offloading, in particular, affects critical thinking among workers across various professions. The focus was on understanding when and how knowledge workers perceive critical thinking while using genAI tools and whether the effort required for critical thinking changes with their use.

The researchers classified critical thinking into six categories: knowledge, comprehension, application, analysis, synthesis, and evaluation. Each of those six cognitive activities was scored with a one-item, five-point scale, as has been done in similar research.

The study found that knowledge workers engage in critical thinking primarily to ensure quality, refine AI outputs, and verify AI-generated content. However, time pressures, lack of awareness, and unfamiliarity with domains can hinder reflective thinking.

At college, signs of a decline in thinking abilities

David Raffo, a professor at the Maseeh College of Engineering and Computer Science at Portland State University, said he noticed over a six-year-period that students’ writing skills were dropping.

“Year after year, the writing got worse,” he said. “Then, during Covid, I noticed that papers started getting better. I thought, maybe staying at home had a positive effect. Maybe students were putting more energy and effort into writing their papers and getting better at their communication skills as a result.”

Raffo met with one student to discuss their A- grade on a paper. During the Zoom meeting, however, the student struggled to form grammatically correct sentences. Raffo began to question whether they had written the paper themselves, considering their communication skills didn’t match the quality of their work.

“I wondered if they had used a paid service or generative AI tools. This experience, about three years ago, sparked my interest in the role of technology in academic work and has motivated my ongoing study of this topic,” said Raffo, who is also editor-in-chief of the peer-reviewed Journal of Software Evolution and Process.

The difference between using genAI compared to the use of calculators and Internet search engines lies in which brain functions are engaged and how they affect daily life, said Raffo, who was not involved in the latest study.

GenAI tools offload tasks that involve language and executive functions. The “use it or lose it” principle applies: engaging our brains in writing, communication, planning, and decision-making improves these skills.

“When we offload these tasks to generative AI and other tools, it deprives us of the opportunity to learn and grow or even to stay at the same level we had achieved,” Raffo said.

How AI rewires our brains

The use of technology, in general, rewires brains to think in new ways — some good, some not so good, according to Jack Gold, principal analyst at tech industry research firm J. Gold Associates. “It’s probably inevitable that AI will do the same thing as past rewiring from technology did,” he said. “I’m not sure we know yet just what that will be.”

As Agentic AI becomes common, people may come to rely on it for problem-solving — but how will we know it’s doing things correctly, Gold said. People might accept its results without questioning, potentially limiting their own skills development by allowing technology to handle tasks.

Lev Tankelevitch, a senior researcher with Microsoft Research, said not all genAI use is bad. He said there’s clear evidence in education that it can enhance critical thinking and learning outcomes. “For example, in Nigeria, an early study suggests that AI tutors could help students achieve two years of learning progress in just six weeks,” Tankelevitch said. “Another study showed that students working with tutors supported by AI were 4% more likely to master key topics.”

The key, he said, is that it was teacher-led. Educators guided the prompts and provided context, showing how a collaboration between humans and AI can drive real learning outcomes, according to Tankelevitch.

The Carnegie Mellon/Microsoft study determined the use of genAI tools shifts knowledge workers’ critical thinking skills in three main ways: from information gathering to verification, from problem-solving to integrating AI responses, and from task execution to task stewardship.

While genAI automates tasks such as information gathering, it also introduces new cognitive tasks, such as assessing AI-generated content and ensuring accuracy. That shift changes the role of workers from doing the work of research to overseeing results, with the responsibility for quality still resting on the human.

Pablo Rivas, assistant professor of Computer Science at Baylor University, while it’s true if a machine’s output goes unchecked, you risk skipping the hard mental work that sharpens problem-solving skills, AI doesn’t have to undermine human intelligence.

“It can be a boost if individuals stay curious and do reality checks. One simple practice is to verify the AI’s suggestions with outside sources or domain knowledge. Another is to reflect on the reasoning behind the AI’s output rather than assuming it’s correct,” he said. “With healthy skepticism and structured oversight, generative AI can increase productivity without eroding our ability to think on our own.”

A right way to use genAI?

To support critical thinking, organizations training workforces should focus on information verification, response integration, and task stewardship, while maintaining foundational skills to avoid overreliance on AI. The study highlights some limitations, such as potential biases in self-reporting and the need for future research to consider cross-linguistic and cross-cultural perspectives and long-term studies to track changes in AI use and critical thinking.

Research on genAI’s impact on cognition is key to designing tools that promote critical thinking. Deep reasoning models are helping by making AI processes more transparent, allowing users to better review, question, and learn from its insights, he said.

“Across all of our research, there is a common thread: AI works best as a thought partner, complementing the work people do,” Tankelevitch said. “When AI challenges us, it doesn’t just boost productivity; it drives better decisions and stronger outcomes.”

The Carnegie Mellon-Microsoft study isn’t alone in its findings. Verbal reasoning and problem-solving skills in the US have been steadily dropping, according to a paper published in June 2023 by US researchers Elizabeth Dworak, William Revelle and David Condon. And while IQ scores had been increasing steadily since the beginning of the 20th century — as recently as 2012, IQ scores were rising about 0.3 points a year — a study by Northwestern University in 2023 showed a decline in three key intelligence testing categories.

All technology affects our abilities in various ways, according to Gold. For example, texting undermines the ability to write proper sentences, calculators reduce long division and multiplication skills, social media affects communication, and a focus on typing has led to neglecting cursive and signature skills, he noted.

“So yes, AI will have effects on how we problem solve, just like Google did with our searches,” Gold said. “Before Google, we had to go to the library and actually read multiple source materials to come up with a concept, which required our brain to process ideas and form an opinion. Now it’s just whatever Google search shows. AI will be the same, only accelerated.”

Kategorie: Hacking & Security

Net neutrality under Trump? Not so neutral

17 Únor, 2025 - 12:00

Even before President Donald J. Trump returned to office last month, net neutrality took a punch to the jaw. On Jan. 2, the US Court of Appeals for the Sixth Circuit struck down the Federal Communications Commission’s (FCC) net neutrality rules

Oh well, it was nice while it lasted.

The latest set of rules, the FCC’s 2024 “Safeguarding and Securing the Open Internet Order,” would have established the three rules of net neutrality:

  • No blocking: Broadband providers may not block access to legal content, applications, services, or non-harmful devices.
  • No throttling: Broadband providers may not impair or degrade lawful Internet traffic on the basis of content, applications, services, or non-harmful devices.
  • No paid prioritization: Broadband providers may not favor some lawful Internet traffic over other lawful traffic in exchange for consideration — in other words, no “fast lanes.” This rule also bans ISPs from prioritizing the content and services of their partners.

There’s nothing new about these rules. They’ve been the cornerstone of the internet you’ve known and used for decades. In 1992, the Commercial Internet Exchange (CIX) brought the first Internet Service Providers (ISPs) together to agree to let traffic run back and forth between them without restrictions. The rules they adopted would become what we call net neutrality. 

It only makes sense, right? As Jessica Rosenworcel, former chairperson of the Federal Communications Commission (FCC) and a Democrat, said: “Consumers across the country have told us again and again that they want an internet that is fast, open, and fair.”

In a way, the court decision doesn’t matter. With Trump back in charge, there was no way net neutrality would survive. 

After all, the Republicans argue, we can trust ISPs to do the right thing for their customers. As Brendan Carr, current FCC chairperson and a Republican, crowed: “[The January] decision is a good win for the country. Over the past four years, the Biden Administration has worked to expand the government’s control over every feature of the Internet ecosystem. You can see it in the Biden Administration’s efforts to pressure social media companies into censoring the free speech rights of everyday Americans.”

Funny that. Since Carr took over as chairperson, he’s launched investigations of American-led media companies and organizations such as NPR, PBS, Disney, CBS, NBC, and Comcast. Why? Because they’re not kowtowing to Trump and they’ve broadcast news that annoys him.

Nothing is surprising about this. Before Trump was elected again, he and his pack of billionaire buddies were already threatening to revoke network TV broadcast licenses because they didn’t like their news coverage. Carr, of course, is all in favor of this; as he said in a pre-election interview, “The law is very clear. The Communications Act says you have to operate in the public interest. And if you don’t, yes, one of the consequences is potentially losing your license.” 

He then listed ABC, NBC, and CBS — but not Fox for some curious reason — as potentially running afoul of his take on the Communications Act of 1934, from which the FCC derives its authority. 

As Nilay Patel, editor-in-chief of The Verge, recently wrote: “The FCC is pretty much the only government agency with some authority to directly regulate speech in America because it controls the spectrum used to broadcast radio and television. Carr has started using that authority to punish broadcasters for speech Trump doesn’t like or even for having internal business practices that don’t align with the administration.”

Aside from the national networks, there’s nothing saying Carr, directed by Trump’s sidekick Elon Musk, couldn’t restrict independent social networks such as BlueskyCounter.social, and Mastodon while leaving XThreads, and Truth.Social to do what they want. 

This could be done, for example, by abusing Section 230 of the Communications Decency Act. In Project 2025‘s FCC section, which Carr authored, he stated: “FCC should work with Congress to ensure that anti-discrimination provisions are applied to Big Tech — including ‘back-end’ companies that provide hosting services and DDoS protection. Reforms that prohibit discrimination against core political viewpoints are one way to do this.” 

Core political viewpoints, in this case, means, of course, pro-Trump speech. What this might look like is charging Universal Service Fund fees to non-Trump-friendly network owners

Speaking of money and networks, Carr also happens to be a big satellite internet supporter. We all know, of course, that Musk’s Starlink is the only major satellite ISP.   

What all this means for you is you can expect ISP fees to go ever higher and for there to be even less choice between ISPs in your neighborhood. Of course, that’s mostly the same old, same old, I’m sorry to say. The internet under Trump will come with more restrictions on news and, in all likelihood, even what you can say about the news.

Freedom of news and speech depends on a free Internet; under the current regime, we’re already losing it. 

Kategorie: Hacking & Security

Microsoft’s Patch Tuesday updates: Keeping up with the latest fixes

14 Únor, 2025 - 21:11

Long before Taco Tuesday became part of the pop-culture vernacular, Tuesdays were synonymous with security — and for anyone in the tech world, they still are.  Patch Tuesday, as you most likely know, refers to the day each month when Microsoft releases security updates and patches for its software products — everything from Windows to Office to SQL Server, developer tools to browsers.

The practice, which happens on the second Tuesday of the month, was initiated to streamline the patch distribution process and make it easier for users and IT system administrators to manage updates.  Like tacos, Patch Tuesday is here to stay.

In a blog post celebrating the 20th anniversary of Patch Tuesday, the Microsoft Security Response Center wrote: “The concept of Patch Tuesday was conceived and implemented in 2003. Before this unified approach, our security updates were sporadic, posing significant challenges for IT professionals and organizations in deploying critical patches in a timely manner.”

Patch Tuesday will continue to be an “important part of our strategy to keep users secure,” Microsoft said, adding that it’s now an important part of the cybersecurity industry.  As a case in point, Adobe, among others, follows a similar patch cadence.

Patch Tuesday coverage has also long been a staple of Computerworld’s commitment to provide critical information to the IT industry. That’s why we’ve gathered together this collection of recent patches, a rolling list we’ll keep updated each month.

In case you missed a recent Patch Tuesday announcement, here are the latest six months of updates.

For February’s Patch Tuesday, Microsoft rolls out 63 updates

Microsoft released 63 patches for Windows, Microsoft Office, and developer platforms in this week’s Patch Tuesday update. The February release was a relatively light update, but it comes with significant testing requirements for networking and remote desktop environments. Two zero-day Windows patches (CVE-2025-21391 and CVE-2025-21418) have been reported as exploited and another Windows update (CVE-2025-21377) has been publicly disclosed — meaning IT admins get a “Patch Now” recommendation for this month’s Windows updates. More info on Microsoft Security updates for February 2025.

2025’s first Patch Tuesday: 159 patches, including several zero-day fixes

Microsoft began the new year with a hefty patch release for January, addressing eight zero-days with 159 patches for Windows, Microsoft Office and Visual Studio. Both Windows and Microsoft Office have “Patch Now” recommendations (with no browser or Exchange patches) for January. Microsoft also released a significant servicing stack update (SSU) that changes how desktop and server platforms are updated, requiring additional testing on how MSI Installer, MSIX and AppX packages are installed, updated, and uninstalled. More info on Microsoft Security updates for January 2025.

For December’s Patch Tuesday, 74 updates and a zero-day fix for Windows

Microsoft released 74 updates with this Patch Tuesday update, patching Windows, Office and Edge — but none for Microsoft Exchange Server or SQL server. One zero-day (CVE-2024-49138) affecting how Windows desktops handle error logs requires a “Patch Now” warning, but the Office, Visual Studio and Edge patches can be added to your standard release schedule. There are also several revisions this month that require attention before deployment. More info on Microsoft Security updates for December 2024.

November: This Patch Tuesday release includes 3 Windows zero-day fixes

Microsoft’s November Patch Tuesday update addresses 89 vulnerabilities in Windows, SQL Server, .NET and Microsoft Office — and three zero-day vulnerabilities in Windows that mean a patch now recommendation for Windows platforms. Unusually, there are a significant number of patch “re-releases” that might also require IT admin attention. More info on Microsoft Security updates for November 2024.

October: A haunting Patch Tuesday: 117 updates (and 5 zero-day flaws)

This month’s Patch Tuesday delivers a large set of patches from Microsoft that fix 117 flaws, including five zero-day vulnerabilities. Though there are patches affecting Windows, SQL Server, Microsoft Excel and Visual Studio, only the Windows updates require a “Patch Now” schedule — and they’ll need a significant amount of testing because they cover a lot of features: networking, kernel and core GDI components and Microsoft Hyper-V. Printing should be a core focus for enterprise testing and the SQL Server updates will require a focus on internally developed applications. More info on Microsoft Security updates for October 2024

September: Latest Patch Tuesday update fixes 4 zero-days

Addressing four zero-days flaws (CVE-2024-38014, CVE-2024-38217, CVE-2024-43491 and CVE-2024-38217), this month’s Patch Tuesday release from Microsoft includes 79 updates to the Windows platform. There are no patches to Microsoft Exchange Server or the company’s development tools (Visual Studio or .NET). And Microsoft addressed a recently exploited vulnerability in Microsoft Publisher with two critical updates and nine patches rated important for Microsoft Office. More info on Microsoft Security updates for September 2024.

Kategorie: Hacking & Security

For February’s Patch Tuesday, Microsoft rolls out 63 updates

14 Únor, 2025 - 21:06

Microsoft released 63 patches for Windows, Microsoft Office, and developer platforms in this week’s Patch Tuesday update. The February release was a relatively light update, but it comes with significant testing requirements for networking and remote desktop environments. 

Two zero-day Windows patches (CVE-2025-21391 and CVE-2025-21418) have been reported as exploited and another Windows update (CVE-2025-21377) has been publicly disclosed — meaning IT admins get a “Patch Now” recommendation for this month’s Windows updates. (All other Microsoft platforms can be handled with a standard update schedule — and there were no updates for Microsoft Exchange and SQL Server.)

To navigate these changes, the team from Readiness has provided a detailed infographic exploring the deployment risks.

(For information on the last six months of Patch Tuesday releases, see our round-up here.)

Known issues 

Microsoft identified three ongoing issues affecting users of Windows 10, Citrix, and Windows Server 2022 this month, including:

  • Windows 10/11 and Sever 2022: Enterprise Windows customers are still reporting SSH connection issues since the October 2024 update. Microsoft is investigating the issue, but has no published fixes or mitigating actions. It’s a challenge for Microsoft since the service failure does not generate logs or error messages.
  • Citrix: Microsoft’s January updates — and potentially this month’s releases — are still affected by the Citrix Session Recording Agent (SRA) preventing the successful installation of Microsoft patches. This is an ongoing issue with no fixes yet, though we expect the number of users affected is much lower than the SSH service issue.
  • Microsoft’s System Guard Runtime Monitor Broker Service (SGMBS) may be causing system level crashes and telemetry issues with the event viewer log since last month’s Patch Tuesday release. Microsoft technical support has offered a registry level change to update the service and mitigate the issue. We expect an update from Microsoft later this month on a more permanent resolution. 
Major revisions and mitigations

As of Feb. 14, the Readiness team has not received any published revisions or updates. Microsoft did offer a mitigation for a serious vulnerability in Microsoft Outlook (CVE-2025-21298). Perhaps less helpful than you’d expect, Microsoft recommends viewing emails in plain text to mitigate this critical remote code execution (RCE) vulnerability, which could otherwise grant attackers control over the target system.

Windows lifecycle and enforcement updates

Microsoft published no enforcement updates this month, but the following products are nearing  their end-of-service life cycles:

  • Windows 11 Enterprise and Education, Version 22H2 — Oct. 14, 2025
  • Windows Server Annual Channel, Version 23H2 — Oct. 24, 2025
  • Windows 11 Home and Pro, Version 23H2 — Nov. 11, 2025

Each month, the Readiness team provides detailed, actionable testing guidance for the latest Patch Tuesday updates based on assessing a large app portfolio and a offering comprehensive analyses of the patches and their potential impact on Windows and application deployments.

For this cycle, we grouped the critical updates and required testing efforts into different functional areas, including:

Networking and Remote Desktop services
  • Winsock: Microsoft advises that a multipoint socket (type c_root) is created and employed with the following operations: bind, connect, and listen. The socket should close successfully.
  • DHCP: Create test scenarios to validate Windows DHCP client operations (discover, offer, request, and acknowledgment (ACK)).
  • RDP: Ensure that you can configure Microsoft RRAS servers through netsh commands.
  • ICS: Ensure that Internet Connection Sharing (ICS) can be configured over Wi-Fi.
  • FAX/Telephony: Ensure that your test scenarios include TAPI (Telephony Application Programming Interface) initialization and shutdown operations. Since these tests require an extended runtime, allocate extra time for them.
Local Windows File System and storage
  • Ensure that File Explorer correctly renders URL file icons. Microsoft recommends testing the Storage Sense clean-up tool. If disk quotas are enabled, confirm that all I/O workloads function as expected.
Local and domain security
  • Domain controllers should continue to support certificate logons after applying the updates.
  • Kerberos: Microsoft recommends creating authentication scenarios for domain-joined systems, using local and encrypted login methods.

If you have the time and resources (VMs and networking), the Readiness team strongly recommends building a test Remote Desktop environment that includes a connection broker, remote desktop gateway, and remote desktops on virtual machines. After setting up each component, verify that all RDP connections are established successfully.

This month, testing Microsoft’s ICS functionality requires an extended test plan covering the following areas:

  • Usability testing: Create test scenarios to verify that the process of enabling/disabling ICS functions as expected.
  • Validation: Microsoft recommends confirming that Network Address Translation (NAT) correctly translates private IP addresses to that of the shared connection.
  • Security: Ensure that ICS traffic adheres to existing firewall rules and does not create unintended security risks.

Each month, we break down the update cycle into product families (as defined by Microsoft) with the following basic groupings: 

  • Browsers (Microsoft IE and Edge) 
  • Microsoft Windows (both desktop and server) 
  • Microsoft Office
  • Microsoft Exchange and SQL Server 
  • Microsoft Developer Tools (Visual Studio and .NET)
  • Adobe (if you get this far) 

Browsers

Microsoft released a larger-than-normal number of patches for the Edge browser this month — 10, all rated important. These updates are a mix of Chromium (CVE-2025-0444CVE-2025-0445 and CVE-2025-0451) and Edge patches that deal with memory related security vulnerabilities. All of these low-profile changes can be added to your standard release calendar.

Microsoft Windows

These areas have been updated with two critical patches and 35 important patches this patch cycle:

  • Win32 and Kernel Services
  • Remote Desktop, RAS  and Internet Connection Sharing (ICS)
  • Kerberos, DHCP  and Windows Networking
  • Microsoft Active Directory and Windows Installer

Though the Windows NTLM patch (CVE-2025-21377) has been rated important, it has been publicly disclosed. Two more updates (both rated important) affecting storage (CVE-2025-21391) and networking (CVE-2025-21418) have reportedly been exploited in the wild. These reports raise the stakes for an otherwise low-profile Windows update, so the Readiness team recommends a “Patch Now” schedule for these.

Microsoft Office

Microsoft released a single critical update for Microsoft Excel and nine more rated as important for Microsoft Office and the SharePoint platforms. None of these  vulnerabilities have been reported as exploited or publicly disclosed. So, add these Office updates to your standard release calendar.

Microsoft Exchange and SQL Server

No updates were released for either Microsoft Exchange or SQL Server this month. 

Developer Tools

Microsoft released four updates to Microsoft Visual Studio, all of which are rated important. One of these updates (CVE-2023-32002) may look a little odd as the date refers to 2023, not 2025. However, it appears legitimate. Though it has been categorized under Microsoft’s Visual Studio product grouping, this patch attempts to resolve a vulnerability in Node.js. Add these updates (even the funny looking ones) to your standard developer release schedule.

Adobe (and 3rd party updates)

Microsoft did not push out any Adobe updates. However, HackerOne required a patch to the developer framework Node.js to resolve a network related vulnerability (CVE-2025-21418). 

Kategorie: Hacking & Security

Arm secures Meta as first customer in chip push, challenging industry giants

14 Únor, 2025 - 13:57

In a landmark shift, Arm has secured Meta as the first major customer for its internally designed server CPUs, a move that signals its entry into direct chip sales and places it in direct competition with its biggest customers, including Qualcomm and Nvidia.

The company, known for licensing its chip designs to industry heavyweights like Apple, Nvidia, and Qualcomm, is now stepping directly into the silicon market, a move that could put it in direct competition with the very customers it once served.

This strategic shift marks one of the most significant transformations in Arm’s history, potentially destabilizing long-standing partnerships and reshaping the power dynamics within the semiconductor industry, reported Finacial Times.

Meta bets on Arm’s first server chip, raising questions for IT buyers

Arm’s first internally designed semiconductor is expected to be a server CPU aimed at the data center market, with Meta as its first major customer. This would mark a direct challenge to Intel and AMD, the long-standing leaders in server chip manufacturing. If successful, Arm’s entry into the data center CPU space could disrupt the traditional x86-based server ecosystem, which has historically been dominated by Intel.

Arm is now directly competing with one of its biggest customers, Qualcomm, for data center CPU deals. Qualcomm was in discussions with Facebook’s parent company, Meta, to supply processors based on Arm’s architecture. However, Arm has already secured at least part of the deal, marking a major shift from its role as a neutral IP supplier to an active market player, reported Reuters.

Arm’s first internally designed semiconductor is expected to be a server CPU aimed at the data center market, with Meta as its first major customer, reported Financial Times. This marks a direct challenge to Intel and AMD, the long-standing leaders in server chip manufacturing. If successful, Arm’s entry into the data center CPU space could disrupt the traditional x86-based server ecosystem, which has historically been dominated by Intel.

While discussions between Meta and Qualcomm are ongoing, Arm’s move raises concerns among enterprise customers who now face the possibility of competing with the very company they rely on for chip designs.

A spokesperson for Arm declined to comment on the matter.

Hiring from customers and entering the market

Arm has started recruiting executives from its own licensees, signaling a strategic transformation. Arm is actively hiring talent to expand beyond designing processor architecture to also selling its own silicon, with a focus on AI-powered data center chips and other applications, reported Reuters, citing sources familiar with the matter.

Arm’s strategic transformation is not just about hiring from licensees, it represents a fundamental shift in its business model. The company, which has long dominated the smartphone processor market, is now focusing on high-performance computing (HPC) and AI-driven chips for data centers. While Arm will design its own semiconductors, it will continue outsourcing production to foundries like TSMC, a move that aligns with the business models of fabless chip companies like Nvidia, the FT report added.

A shift that could reshape the industry

“Near-term mass migration away from Arm seems unlikely due to its established ecosystem and the complexity of shifting architectures,” said Rachita Rao, senior analyst at Everest Group. “However, companies like Qualcomm are already exploring alternatives such as RISC-V, and some firms have begun in-house efforts to reduce reliance on Arm. While some players might transition away, Arm remains the primary architect of these chips, with differentiation largely occurring at the SoC design level.”

“SoftBank’s potential acquisition of Oracle-backed chip designer Ampere could further accelerate Arm’s efforts in this segment,” Rao added. “The Meta deal lends credibility to Arm’s push into chip manufacturing, but while the company has financial and technical backing, it will take time to reach the level of established competitors. Even existing players are struggling to keep up with Nvidia.”

Arm’s business shift mirrors Nvidia’s model, where chip designs are developed in-house but actual manufacturing is outsourced to foundries like TSMC. This approach allows Arm to enter new markets while reducing capital expenditure on chip fabrication. However, the move could create tensions with long-time partners like Apple, Qualcomm, and Nvidia, who must now consider whether their reliance on Arm’s technology puts them in direct competition with it.

“Arm already holds a near-monopoly in certain semiconductor IP segments, and regulators closely scrutinize its licensing policies and potential acquisitions,” Rao noted. “If Arm expands further into direct chip sales, regulators may require a clear separation between its IP licensing and chip manufacturing divisions. Any perceived preference for its own products or sudden licensing fee hikes could invite antitrust investigations.”

“As AI chip development accelerates, chipset makers will likely pursue both backward and forward integration, aiming to control more of the design and development process while still relying on foundries for manufacturing,” said Faisal Kawoosa, founder and lead analyst at Techarc. “Arm’s move into chipmaking is a natural response to this trend, but it also introduces challenges. Competing with firms like Nvidia and Qualcomm requires more than just strong design expertise—it demands deep market knowledge, customer relationships, and extensive front-end integration, areas where its competitors currently have an edge.”

Arm’s business shift mirrors Nvidia’s model, where chip designs are developed in-house but actual manufacturing is outsourced to foundries like TSMC. This approach allows Arm to enter new markets while reducing capital expenditure on chip fabrication. However, the move could create tensions with long-time partners like Apple, Qualcomm, and Nvidia, who must now consider whether their reliance on Arm’s technology puts them in direct competition with it.

Potential challenge to Nvidia in AI chips

Beyond server CPUs, Arm is setting its sights on the booming AI chip market, where Nvidia is currently the dominant player. Arm is also a part of SoftBank’s Stargate initiative, a large-scale project to develop AI-focused data centers in the US in collaboration with OpenAI and Oracle.

If Arm moves aggressively into AI hardware, it could challenge Nvidia’s stronghold on AI-specific GPUs, a sector currently experiencing exponential demand due to advancements in generative AI. Arm may also be positioning itself to compete with Nvidia, a dominant force in the AI chip market.

Besides, Arm and its parent company, SoftBank, are working with Broadcom to develop a custom-built AI chip for SoftBank’s data centers. The project is estimated to be worth as much as $30 billion in revenue for Broadcom, reported Reuters citing a research note from JP Morgan analyst Harlan Sur.

The note further suggests that if Arm aggressively moves into AI hardware, it could position itself as a direct competitor to chip giants such as Nvidia and AMD. While Arm has not publicly confirmed these ambitions, its efforts to recruit top chip executives and win strategic deals suggest a clear intent to expand beyond its traditional licensing business.

For decades, Arm has been seen as a neutral provider of chip design technology, licensing its IP to major semiconductor firms without directly competing with them. That model is now changing, and the ripple effects could be significant.

If Arm continues to expand into chip sales, enterprise customers may need to rethink their reliance on its technology. Companies that once viewed Arm as a partner may now see it as a rival, potentially reshaping the semiconductor market and altering supply chain strategies across the industry.

Queries seeking comment from Qualcomm and Meta remain unanswered.

Kategorie: Hacking & Security

Apple and the big store

14 Únor, 2025 - 13:46

Apple has made a small but significant move by introducing its Apple TV app to Android. It might seem like a minor step, but it marks a major pivot in strategy as the company expands its services beyond its own ecosystem. Across the years, rumors and recruitment ads show it has been putting this plan together for some time.

Outside the walled garden

That all this speculation has become reality shouldn’t be a big surprise. It’s not as if Android is the first platform to see Apple services support. Windows has many, including iCloud, Music, TV — and Apple Music is already available on Android.

What this means for most of us is limited: It means all the movies and TV shows you’ve purchased from Apple can be accessed on your Android device, which will also stream the full TV+ catalog. It also opens the doors to potential new subscribers to Apple’s growing selection of sports content, at present including Major League Soccer and Friday Night Baseball. Given that Apple was also in the running to pick up streaming rights for key soccer leagues, you should not underestimate the breadth of its ambition in sports entertainment. 

What Apple has also done with this move is weaken arguments against its traditional “walled garden” for services.

  • It isn’t forcing vendor lock-in through your purchased movie collection anymore. 
  • It means switchers can access the Apple services they have become accustomed to. 
  • It means potential Android to iPhone switchers can dip into Apple’s content services during their migration.
Content is king — and available for a fee

Apple TV on Android also hints at the future. You see, as Apple is forced to open its own ecosystem to competitors, it is also being forced to intensify the degree to which it competes against those competitors.

That means Apple Music is now in an all-platform competition with Spotify; and in the future it will also mean Apple TV+ has to compete with other streaming services. 

While TV+ arguably lacks a deep enough library of content to compete effectively, it’s plausible Apple might choose to widen its content library now that its service is available on multiple devices and platforms.

Licensed content could bolster the company’s own unique offerings and be made immediately available to a potential audience of billions. Apple has experimented with this – it licensed a catalog of 50 movies for showing in the US last year, and now has a licensing team in place.

Roblox for tiny humans

While doing so would be highly complex from a development point of view, Apple has another service it could potentially bring across to Android: Arcade.

Apple Arcade is a collection of casual games made available free to subscribers, built to work across Apple’s platforms (including Apple TV). Its big advantages include a distinct lack of built-in data trackers and info stealers and a sensible approach to advertising that means parents aren’t forever claiming refunds or coughing up cash as their kids “accidentally” purchase in-game currencies.

Combined with a decent selection of professionally produced content, Arcade has plenty of potential — all it needs is its Ted Lasso or iPhone moment, a game so popular and pervasive gamers on all platforms want it. Think about something better than Roblox, but more wholesome.

While Apple waits for that game to appear, it could offer up Arcade to other platforms, creating an ecosystem for game discovery and purchase that competes directly with those forcing it to open its platforms up to them. It could then be in the cat bird seat once it finds its pervasive gaming hit.

One more thing

For all the criticism it gets, the enduring success of the App Store shows there is a substantial public appetite for curated apps and services. People are hungry for games, apps, and services that meet trust and quality standards.

Given this is true, perhaps Apple could expand its App Store to distribute strictly vetted software and services for other platforms, including those from competitors. 

While unlikely, one day the most popular version of Fortnite might be the one sold via the App Store with an Apple imprimatur to denote verified trust and security. Perhaps you’ll visit the Apple App Store to get your Windows and Android software, confident it has been put through strict quality and security testing. I imagine IT would be pleased with that extra layer of verification, particularly in regulated industries.

After all, as Apple’s entire history shows, if you can’t beat them, you join them.  You just do it better.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon, and MeWe

Kategorie: Hacking & Security

Apple’s emotional lamp and the future of robots

14 Únor, 2025 - 12:00

Pixar Animation Studios has an unusual logo. The basic logo is the word “Pixar.” But sometimes, an animated lamp named Luxo Jr. hops into the frame and jumps on the letter “i.” The lap exudes personality and represents Pixar’s ability to turn any object into a compelling character. 

Inspired by Luxo Jr., Apple’s Machine Learning Research division decided to create a personality-expressive lamp of their own. Apple’s ELEGNT research project explores what’s possible with an expressive physical user interface for non-humanoid robots

Based on the situation and context of the user, as well as voice interaction, gestures and touch, the lamp can appear to express itself through a variety of movements, including nodding or shaking its “head,” lowering its head to convey sadness, “tail wagging” to signify excitement, “sitting down” to imply relaxation, head tilting to show curiosity, leaning forward to show interest, gazing to direct attention, adjusting speed and pausing to communicate attitudes and emotions, and moving forward or away to show interest or disinterest. 

It can do some of the things smartphone apps can do but with a greater sense of fun. For example, smartphone apps can remind you to drink water, but the ELEGNT can do this by physically pushing a cup of water toward you. 

As you can see in this video, Apple’s project is fascinating. But as with all robot makers in Silicon Valley, as far as I can tell, the company loses the plot when dealing with any robot designed to simulate human communication. 

In their paper, they say: “The framework integrates function-driven and expression-driven utilities, where the former focuses on finding an optimal path to achieve a physical goal state, and the latter motivates the robot to take paths that convey its internal states —s uch as intention, attention, attitude, and emotion — during human-robot interactions.”

Did you catch the lie (or worse, a possibly self-delusional claim)? They’re falsely saying that their expression-driven utilities “motivate” the lamp to convey its “internal states,” and among those internal states is “emotion.” 

They toss out the falsehood with shocking casualness, considering how big the statement is and how formal the research paper is. If Apple had actually invented a lamp that can feel emotions, that would be the computer science event of the century, a singularity of world-historic import. It would challenge our laws and our definition of sentience, throwing into question religious and philosophical questions that have been settled for 10,000 years. 

(I’ve reached out to Apple for comment on this point, but haven’t heard back.) 

It’s clear that Apple’s lamp is programmed to move in a way that deludes users into believing that the it has internal states that it doesn’t actually have. 

(I admire Apple’s research; I don’t understand why companies lie about humanoid robotics and play make-believe in their research papers about what’s going on with their robots. In the future, it will be hard enough for people to understand the nature of AI and robotics without the researchers lying in formal, technical research papers.)

But if you ignore the lie, Apple’s lamp research definitely sheds light on where our interaction with robots may be heading—a new category of appliance that might well be called the “emotional robot.” 

A key component of the research was a user study comparing how people perceived a robot using functional and expressive movements versus one that uses only functional movements. 

The study found that movements incorporating expressive qualities boosted user “ratings,” especially during social-oriented tasks. But when users wanted some specific useful action to take place — for example, to shine light on an object so the user could take a picture of it — study participants found the lamp’s “personality” distracting. 

The researchers drew upon the concept of Theory of Mind, the human ability to attribute mental states to others, to help design the lamp’s movements. Those movements were intended to simulate intention, attention, attitude, and emotion. 

The movements aren’t specifically human but rather the body language of a person, a monkey, or a dog — a sentient mammal generally.

The biggest takeaway from Apple’s ELEGNT research is likely that neither a human-like voice nor a human-like body, head, or face is required for a robot to successfully trick a human into relating to it as a sentient being with internal thoughts, feelings, and emotions. 

ELEGNT is not a prototype product; it is instead a lab and social experiment. But that doesn’t mean a product based on this research will not soon be available on a desktop near you. 

Apple’s emotional robot 

Apple is developing a desktop robot project, codenamed J595, and is targeting a launch within two years. According to reports based on leaks, the robot might look a little like Apple’s iMac G4, which was a lamp-like form factor featuring a screen at the end of a moveable “arm.” The device would function like an Apple HomePod with a screen but with additional intelligence courtesy of large language model-based generative AI. 

The estimated $1,000 robot would provide a user interface for home smart products and doorbell cams, answer questions, display photos and incoming messages, and function as a camera and screen for FaceTime calls. 

But here’s the most interesting part. Although there’s no direct evidence for this claim, it makes sense for Apple to incorporate ELEGNT research into the desktop robot project. The robot is expected to move, lean, and tilt as part of its interaction with users. 

Apple’s next appliance might be an emotional robot. 

The consumer market for emotional robots

The idea of a consumer electronics product advertising “personality” through physical movements isn’t new. Among others, there’s:

  • Jibo: A social robot with expressive movements and a rotating body.
  • Anki’s Cozmo: A small robot toy with a movable arm and LED eyes for emotional expression.
  • Sony Aibo: A robotic dog using its entire body to express emotions.
  • Kuri: A home robot using head tilts, eye expressions, and sounds for communication.
  • Lovot: A companion robot from Japan expressing affection through body movements.
  • Amazon Astro: A home robot with a periscope camera and digital eyes for engagement.

The latter product is worthy of an update since I first mentioned it in 2021.

Amazon discontinued its Astro for Business program on July 3, 2024, less than a year after launch. The business robots were remotely deactivated by Amazon last Sept. 25, and now Amazon is exclusively focusing on Astro for consumers. 

The $1,599 consumer version of Astro, introduced in 2021, is still available (by invitation only).

The business market for emotional robots

No major company has tried emotional robots for business except Amazon, and it killed that program. 

Meanwhile, the European Union’s AI Act prohibits the use of AI systems for emotion recognition in workplaces or educational settings, except in cases of medical or safety necessity. This ban became effective on Feb. 2.

So, from a business, legal, and cultural standpoint, it appears that appliances that can read your emotions and respond with gestures expressing fake emotions are not imminent. 

We’ll see whether users bring their emoting Apple desktop robots or other emotional robots to the office. We could be facing a bring-your-own-emotional-robot movement in the workplace.

BYOER beware!

Kategorie: Hacking & Security

Your new Android notification superpower

14 Únor, 2025 - 11:45

It may seem like a paradox, but notifications are both the best and the worst part of owning an Android device.

On the one hand, notifications let us stay on top of important incoming info — be it a critical Slack message, a personal family text, or an email from a high-priority client or colleague.

On the other hand, man alive, can they be menacing — both distracting and also sometimes ineffective, when something significant comes in and you don’t notice it right away.

To be fair, Android’s got all sorts of smart systems for taming your notifications and making ’em more manageable and effective — both official and by way of crafty workaround. The software’s oft-overlooked notification channels make it easy to control specific sorts of notifications and turn down the noise on less important stuff. And just last week, we talked about a creative way to bring custom vibration patterns to any Android device so you can tell what type of info is alerting you without even having to glance at your screen.

But there’s still the issue of especially important info coming in and falling through the cracks. After all, it’s all too easy to miss a single incoming notification and then fail to notice it until hours later — when it might be too late.

Today, I’ve got a scrumptiously slick ‘n’ simple tool that can help. It’s a new Android notification superpower, and all you’ve gotta do is embrace it.

[Don’t stop here: Get my free Android Notification Power-Pack next and send your Android notification intelligence to soaring new heights.]

Android notifications, amplified

The tool I want to tell you about is an easy-as-can-be way to amplify especially important notifications and make sure you always see ’em right away.

It does that primarily by creating a custom alarm of sorts for your highest-priority notifications — those coming from specific apps and/or with specific keywords in their bodies. When those conditions are met, the system vibrates your phone continuously until you acknowledge it and optionally makes an ongoing sound, too. That way, there’s zero chance you’ll overlook it.

You can even get incredibly nuanced with how and when those actions happen, if you want, and have the alarm active only during certain days and times. If you’re really feeling saucy, you can also have the app read certain notifications aloud when they come in as another way to ensure they catch your attention.

The app that makes all of this happen is a cool little creation called, fittingly enough, NotiAlarm. It’s a free download that’ll work on any Android device.

Now, notably, NotiAlarm does overlap with another tool we’ve talked about before — an extremely versatile power-user tool called BuzzKill that lets you create all sorts of crafty custom filters for your phone’s notifications. If you’re already using BuzzKill, you can accomplish these same sorts of feats with it, and you don’t need NotiAlarm in addition.

But fantastic as it is, BuzzKill is a bit complex. It falls more in the power-user camp, and it also costs four bucks to use. So all in all, it isn’t for everyone.

NotiAlarm, in contrast, is super-simple and also free. Even if you aren’t inclined to create an entire array of custom filters for your notifications, it does this one thing and does it well — and it’s remarkably easy to get going.

The app does have some mildly annoying ads throughout its configuration interface, but that’s it. You can opt to disable those and support the developer with a one-time $10 upgrade, if you want, but you don’t have to do that in order to put it to work.

Capisce? Capisce. Lemme show you how to get it up and running now, in a matter of minutes.

Your 2-minute Android notification upgrade

All right — here’s all there is to it:

  • First, download NotiAlarm from the Play Store (obviously, right?).
  • Open ‘er up, then follow the prompts to grant the app the various forms of access it needs.
    • NotiAlarm requires permissions to manage your notifications, display over other apps, and run in the background — for reasons that should all be fairly obvious and are absolutely necessary for what it needs to do. Its privacy policy is clear about the fact that it doesn’t collect or store any personal data or share any manner of info with any third parties.
  • Once you’re on its main screen, tap the circular plus icon in the lower-right corner to configure your first alarm. That’ll take you to a screen that looks a little somethin’ like this:
NotiAlarm’s configuration screen doesn’t take long at all to get through.

JR Raphael, IDG

  • Tap the plus sign next to the word “Keyword,” then type in whatever keyword you want to act as a trigger for your notification alarm. Maybe it’s a specific person’s name, a specific email address, or some specific term that you know demands your immediate attention. Whatever it is, type it in there, then tap the word “Add” to confirm and save it.
    • By default, NotiAlarm will trigger your alarm for any notifications that include your keyword. You can also, however, ask it to trigger the alarm for any notifications that don’t include the keyword — so in other words, for all notifications except those containing that keyword. If you’d rather go that route, tap the toggle next to “Keyword Filter Type” to switch its behavior.
The “Keyword” field is the key to making your most important notifications unmissable.

JR Raphael, IDG

  • Next, tap the plus sign alongside the word “App” and select which app or apps you want to be included — Messages, Slack, Gmail, Calendar, or whatever the case may be.
Once you’ve selected an app (or multiple apps), you’ll see the final setup for your new notification rule.

JR Raphael, IDG

  • Now, in the next box down, tap the toggle next to “Alarm” and configure exactly how you want your alarm to work.
    • You can activate and select a specific sound, via the “Alarm Sound” toggle.
    • Or you can stick solely with an ongoing vibration, via the active-by-default “Vibration” toggle.
    • If you want to limit the alarm to certain times, tap the toggle next to “Do Not Disturb Time Range.” And if you want to limit it to certain days, tap the day names under “Repeat Days.” Otherwise, just ignore those fields.
You’ve got ample options for exactly how and when you want your notification alarm to activate.

JR Raphael, IDG

And hey, how ’bout that? For most purposes and scenarios, you should now be set! If you want to explore some other options — such as having a notification automatically read aloud, automatically marking a notification as read, or automatically replying to a message-oriented notification with some prewritten response — look a little lower on that same screen.

Otherwise, just tap the “Save” text in the upper-right corner, and that’s it: Your new alarm is now active. And you’ll see it with an active toggle on NotiAlarm’s main screen.

A NotiAlarm notification alarm in its final, fully configured state.

JR Raphael, IDG

Now, anytime a notification comes in that meets the conditions you specified, your phone will do exactly what you asked — and an important alert will never go unnoticed again.

???? NEXT: Snag my free Android Notification Power-Pack to discover six especially awesome enhancements that’ll take your Android notification intelligence to the next level.

Kategorie: Hacking & Security

Windows 10 Insider Previews: A guide to the builds

14 Únor, 2025 - 10:27

Microsoft never sleeps. In addition to its steady releases of major and minor updates to the current version of Windows 10, the company frequently rolls out public preview builds to members of its Windows Insider Program, allowing them to test out — and even help shape — upcoming features.

Although Windows Insiders can choose to receive Windows 11 preview builds in one of four channels — the Canary, Dev, Beta, or Release Preview Channel — Microsoft currently offers Windows 10 Insider previews in the Beta and Release Preview Channels only.

The Release Preview Channel typically doesn’t see action until shortly before a new feature update is rolled out; it’s meant for final testing of an upcoming release and is best for those who want the most stable builds. The Beta Channel previews features that are a little further out.

Below you’ll find information about recent Windows 10 preview builds. For each build, we’ve included the date of its release, which Insider channel it was released to, a summary of what’s in the build, and a link to Microsoft’s announcement about it.

Note: If you’re looking for information about updates being rolled out to all Windows 10 users, not previews for Windows Insiders, see “Windows 10: A guide to the updates.”

Releases for Windows 10 version 22H2 Windows 10 Build 19045.5552 (KB5052077)

Release date: February 13, 2025

Released to: Release Preview Channel

This build fixes a variety of bugs, including one in which Open Secure Shell (OpenSSH) refused to start, stopping SSH connections.

(Get more info about Build 19045.5552.)

Windows 10 22H2 Build 19045.5435 (KB5050081)

Release date: January 17, 2025

Released to: Release Preview Channel

This update introduces a new calendar and the new Outlook app. It also fixes a variety of bugs, including one that depleted virtual memory, causing some apps to fail, and another in which the Capture Service and Snipping Tool stopped responding you pressed Windows key + Shift + S several times while Narrator was on.

(Get more info about Build 19045.5435.)

Windows 10 22H2 Build 19045.5194 (KB5046714)

Release date: November 14, 2024

Released to: Beta Channel and Release Preview Channel

For Windows Insiders in the Beta Channel, the recommended section of the Start menu will show some Microsoft Store apps from a small set of curated developers. If you want to turn this off, go to Settings > Personalization > Start. Turn off the toggle for Show suggestions occasionally in Start. Note that this feature is being rolled out gradually.

Windows Insiders in the Beta and Release Preview Channels get several bug fixes, including for a bug in which when you dragged and dropped files from a cloud files provider folder, it might have resulted in a move instead of a copy.

(Get more info about Build 19045.5194.)

Windows 10 22H2 Build 19045.5070 (KB5045594)

Release date: October 14, 2024

Released to: Beta and Release Preview Channels

In this build, those in the Beta Channel who have chosen to get features as soon as they are rolled out get new top cards that highlight key hardware specifications of their devices.

Insiders in both the Beta and Release Preview Channels get a new account manager on the Start menu. The new design makes it easy to view your account and access account settings. Those in the Beta and Release Preview Channels also get fixes for a variety of bugs, including one in which a scanner driver failed to install when you used a USB cable to connect to a multifunction printer.

(Get more info about Windows 10 22H2 Build 19045.5070.)

Windows 10 22H2 19045.4955 (KB5043131)

Release date: September 16, 2024

Released to: Beta Channel and Release Preview Channel

This build fixes several bugs, including one in which playback of some media could have stopped when you used certain surround sound technology, and another in which Windows Server stopped responding when you used apps like File Explorer and the taskbar.

(Get more info about Windows 10 22H2 Build 19045.4955.)

Windows 10 22H2 19045.4842 (KB5041582)

Release date: August 22, 2024

Released to: Beta Channel and Release Preview Channel

This build fixes several bugs, including one in which when a combo box had input focus, a memory leak sometimes occurred when you closed that window, and another in which some Bluetooth apps stopped responding because of a memory leak in a device.

(Get more info about Windows 10 22H2 19045.4842.)

Windows 10 22H2 Build 19045.4713 (KB5040525)

Release date: July 11, 2024

Released to: Beta Channel and Release Preview Channel

In this build, Insiders in the Beta Channel get a fix in which they will see a search box on their secondary monitors when the setting for search on the taskbar is set to “Search box.”

Insiders in the Beta Channel and Release Preview Channel get fixes for a variety of bugs, including one in which the TCP send code often causes a system to stop responding during routine tasks, such as file transfers. This issue leads to an extended send loop.

(Get more info about  Windows 10 22H2 19045.4713.)

Windows 10 22H2 Build 19045.4593

Release date: June 13, 2024

Released to: Beta Channel and Release Preview Channel

In this build, Insiders in the Beta Channel get bug fixes for Windows Backup. Insiders in both the Beta and Release Preview Channels get a new feature for mobile device management in which when you enroll a device, the MDM client sends more details about the device. The MDM service uses those details to identify the device model and the company that made it.

Insiders in the Beta Channel and Release Preview Channel also get a variety of bug fixes, including for a bug that could have stopped systems from resuming from hibernation after BitLocker was turned on.

(Get more info about  Windows 10 22H2 19045.4593.)

Windows 10 22H2 Build 19045.4472 (KB5037849)

Release date: May 20, 2024

Released to: Release Preview ChannelThis build fixes a variety of bugs, including one in which TWAIN drivers stopped responding when you used them in a virtual environment, and another in which the Windows Presentation Foundation (WPF) app stopped responding.

(Get more info about  Windows 10 22H2 19045.4472.)

Windows 10 22H2 Build 19045.4353 (KB5036979)

Release date: April 15, 2024

Released to: Release Preview Channel

This build introduces account-related notifications for Microsoft accounts in Settings > Home. A Microsoft account connects Windows to your Microsoft apps. This feature displays notifications across the Start menu and Settings. You can manage your Settings notifications in Settings > Privacy & security > General.

A wide variety of bugs have been fixed, including one in which when your device resumed from Modern Standby you might have gotten the stop error, “0x9f DRIVER_POWER_STATE_FAILURE, and another in which the Windows Local Administrator Password Solution’s (LAPS) Post Authentication Actions (PAA) did not happen at the end of the grace period. Instead, they occurred at restart.

(Get more info about  Windows 10 22H2 Build 19045.4353.)

Windows 10 22H2 Build 19045.4233 (KB5035941)

Release date: March 14, 2024

Released to: Release Preview Channel

This build adds Windows Spotlight, which displays new images as your desktop wallpaper. If you want to know more about an image, click or tap the Learn More button, which takes you to Bing. To turn on this feature, go to Settings > Personalization > Background > Personalize your background and choose Windows spotlight. The update also adds sports, traffic, and finance content to the lock screen. To turn it on, go to Settings > Personalization > Lock screen. Note that these two features will roll out to users gradually.

In addition, in Windows Hello for Business IT admins can now use mobile device management (MDM) to turn off the prompt that appears when users sign in to an Entra-joined machine. To do it, turn on the “DisablePostLogonProvisioning” policy setting. After a user signs in, provisioning is off for Windows 10 and Windows 11 devices.

A wide variety of bugs have been fixed, including one in which some applications that depend on COM+ component had stopped responding. Also fixed was a deadlock issue in CloudAP that occurred when different users signed in and signed out at the same time on virtual machines.

(Get more info about Windows 10 22H2 Build 19045.4233.)

Windows 10 22H2 Build 19045.4116 (KB5034843)

Release date: February 15, 2024

Released to: Release Preview Channel

In this build, using Windows share, you can now directly share URLs to apps like WhatsApp, Gmail, Facebook, and LinkedIn. Sharing to X (formerly Twitter) is coming soon.

The build fixes several bugs, including one in which you weren’t able to use Windows Hello for Business to authenticate to Microsoft Entra ID on certain apps when using Web Access Management (WAM).

(Get more info about  Windows 10 22H2 Build 19045.4116.)

Windows 10 22H2 Build 19045.3992 (KB5034203)

Release date: January 11, 2024

Released to: Release Preview Channel

This update adds eye control system settings. You can back up these settings from the former device while you set up a new device. Then those settings will install automatically on the new device so you can use them when you reach the desktop.

The build fixes a wide variety of bugs, including one in which an MDM service such as Microsoft Intune might not get the right data from BitLocker data-only encryption, and another in which some single-function printers are installed as scanners.

(Get more info about  Windows 10 22H2 Build 19045.3992 (KB5034203).)

Kategorie: Hacking & Security

Adobe Firefly expands with ‘commercially safe’ video generator

13 Únor, 2025 - 19:20

Adobe has released a video generator in public beta in its generative AI (genAI) tool, Adobe Firefly. The company calls the tool the first “commercially safe” video generator on the market. It has been trained on licensed content and public domain material, meaning it should not be able to generate material that could infringe someone else’s copyright.

Firefly can generate clips either from text instructions or by combining a reference image with text instructions. There are also settings to customize things such as camera angles, movements, and distances.

A paid subscription is required to use the video generator. Firefly Standard, which costs about $11 a month, gives access to 2000 credits; that should be enough for 20 five-second videos with a 1080p picture resolution and a frame rate of 24 frames per second.

Firefly Pro, which costs three times more than the standard version, allows a user 7000 credits, which should be enough for 70 five-second clips in 1080p at 24 frames per second.

Adobe plans to eventually release a model for videos with lower resolution but faster image updates, as well as a model with 4k resolution for Pro users.

Kategorie: Hacking & Security