Feds Finally Decide To Do Something About Years-Old SS7 Spy Holes In Phone Networks
SS7, which was developed in the mid-1970s, can be potentially abused to track people’s phones’ locations; redirect calls and text messages so that info can be intercepted; and spy on users. The Diameter protocol was developed in the late-1990s and includes support for network access and IP mobility in local and roaming calls and messages. It does not, however, encrypt originating IP addresses during transport, which makes it easier for miscreants to carry out network spoofing attacks. “As coverage expands, and more networks and participants are introduced, the opportunity for a bad actor to exploit SS7 and Diameter has increased,” according to the FCC [PDF].
On March 27 the commission asked telecommunications providers to weigh in and detail what they are doing to prevent SS7 and Diameter vulnerabilities from being misused to track consumers’ locations. The FCC has also asked carriers to detail any exploits of the protocols since 2018. The regulator wants to know the date(s) of the incident(s), what happened, which vulnerabilities were exploited and with which techniques, where the location tracking occurred, and — if known — the attacker’s identity. This time frame is significant because in 2018, the Communications Security, Reliability, and Interoperability Council (CSRIC), a federal advisory committee to the FCC, issued several security best practices to prevent network intrusions and unauthorized location tracking. Interested parties have until April 26 to submit comments, and then the FCC has a month to respond.
Read more of this story at Slashdot.
Scientists Complete Construction of the Biggest Digital Camera Ever
To do this, the team needed a Rolls Royce of a digital camera. Mind you, the camera actually cost many million times that of an actual Royce Royce, and at 6,200 pounds (2,812 kilograms), it weighs a lot more than a fancy car. Each of the 21 rafts that makes up the camera’s focal plane is the price of a Maserati, and are worth every penny if they collect the sort of data scientists expect them to. “I’m personally most excited to study the expansion of the Universe using gravitational lenses to better understand Dark Energy,” said Aaron Roodman, a physicist at SLAC and lead on the camera program, in an email to Gizmodo. “That means two things: 1) measuring the brightness in all six of our filters of literally billions of galaxies and very carefully measuring their shape, which has been subtly altered by the bending of light by matter, and 2) discovering and studying very special objects where a distant quasar is almost perfectly lined up with a more nearby galaxy.”
Speaking through a SLAC release, Rodman said the camera’s images could “resolve a golf ball from around 15 miles away, while covering a swath of the sky seven times wider than the full moon.” The first images from the Rubin Observatory are slated to be publicly released in March 2025, which feels like a long way away. But several important agenda items still need to happen. For one, the SLAC team has to ship the LSST camera safely to Chile from its current lodgings in northern California. (Don’t worry — they’ve made a test run of the journey.) Then, the observatory’s mirrors need to be readied for testing and the observatory’s dome has to be completed, among some other tasks. But whenever all that is complete, the legacy survey will launch into a decade’s worth of scientific discovery. Rubin Observatory estimates suggest that LSST could “increase the number of known objects by a factor of 10,” according to a SLAC release.
Read more of this story at Slashdot.
ChatGPT Customers Can Now Use AI To Edit DALL-E Images
Read more of this story at Slashdot.
Intel Discloses $7 Billion Operating Loss For Chip-Making Unit
Partially as a result of the missteps, Intel has outsourced about 30% of the total number of wafers to external contract manufacturers such as TSMC, Gelsinger said. It aims to bring that number down to roughly 20%. Intel has now switched over to using EUV tools, which will cover more and more production needs as older machines are phased out. “In the post EUV era, we see that we’re very competitive now on price, performance (and) back to leadership,” Gelsinger said. “And in the pre-EUV era we carried a lot of costs and (were) uncompetitive.”
Read more of this story at Slashdot.
Bitcoin Tumbles $5,000 In 24 Hours As Interest Rates Jump
Bitcoin’s move may have been exacerbated by a large bitcoin holder, or “whale,” who transferred more than 4,000 bitcoin to the Bitfinex exchange late Monday night. Data from CryptoQuant shows a spike in that exchange’s reserves — which typically signals a boost in selling activity — that coincides with the sudden drop in bitcoin price late Monday night. Stocks tied to the performance of bitcoin were dragged down but traded off their lows to end the day.
Read more of this story at Slashdot.
Jon Stewart Claims Apple Wouldn’t Let Him Interview FTC Chair On His Podcast
Stewart returned to “The Daily Show” in February after leaving in 2015 as its executive producer and host on Monday evenings through the 2024 election cycle. Stewart’s Apple TV+ show ended late last year after Stewart and Apple executives parted ways over creative differences, including the comedian’s desire to cover topics such as China and AI, the New York Times reported.
Read more of this story at Slashdot.
Yahoo Is Buying Artifact, the AI News App From the Instagram Co-Founders
Artifact, the app, will go away once the acquisition is complete. But Artifact’s underlying tech for categorizing, curating, and personalizing content will soon start to show up on Yahoo News — and eventually on other Yahoo platforms, too. “You’ll see that stuff flowing into our products in the coming months,” says Downs Mulder. It sounds like there’s also a good chance that Yahoo’s apps might get a bit of Artifact’s speed and polish over time, too. Both Systrom and Downs Mulder say the integration will take time, that you can’t just drop an Artifact algorithm into Yahoo News and call it a day. But they see a possibility to get everybody into the future a little faster. Yahoo can develop a personalized content ecosystem, the “TikTok for text” that was so alluring to Artifact users. And Artifact can power a news service of the future.
Read more of this story at Slashdot.
VMware By Broadcom Plots Pair of Cloud Foundation Releases
Turner explained those features as exemplifying the sort of simplification VMware by Broadcom thinks is needed to make Cloud Foundation easier to implement. A bigger release Turner hopes will debut in early 2025 — though he would commit to only a H1 launch — will be a “unified” release in which more of VCF is better integrated. Today, Turner admitted, VMware customers may have implemented vSphere and the Aria management suite, but might still need or choose discrete storage for each. Future VCF releases will increasingly unify the products so that silos aren’t needed. Prashanth Shenoy, vice president for VMware by Broadcom’s cloud platform, infrastructure, and solutions marketing, told The Register the release will be called VCF 9 and will represent “the fullest expression of Broadcom’s vision for product integration.” “When customers deploy VCF there are seams — when they deploy networking and storage, they feel like they do not have a unified developer or operator experience,” Shenoy admitted. VCF 9 will tidy that sort of thing up and make the process “seamless.” Buyers can also expect improved log file analysis, the ability to acquire templates from a marketplace and adopt them as PaaS, and plenty more.
Turner and Shenoy told The Register that the two releases are hoped to make VCF adoption easier, and by doing so demonstrate the value of the bundle. Today, they argue, would-be hybrid cloud adopters using VCF are in reality integrating siloed products — which doesn’t prove the value of the vStack well. VCF 9’s planned integrations, they argue, should demonstrate the power of the stack and the wisdom of Broadcom’s decision to create a VMware unit dedicated to VCF. That team, they explained, means developers for each of the bundle’s components work together on a unified experience, rather than to create their own product. It may also demonstrate the value of VMware by Broadcom’s new licenses – which some users have complained are considerably more expensive now that subscriptions are required, and products are only sold in bundles. Sylvain Cazard, president of Broadcom Software for Asia-Pacific, told The Register that complaints about higher prices are unwarranted since customers using at least two components of VMware’s flagship Cloud Foundation will end up paying less. He also noted that the new pricing includes support, which VMware didn’t include previously.
Read more of this story at Slashdot.
New XZ Backdoor Scanner Detects Implants In Any Linux Binary
The backdoor was introduced by a pseudonymous contributor to XZ version 5.6.0, which remained present in 5.6.1. However, only a few Linux distributions and versions following a “bleeding edge” upgrading approach were impacted, with most using an earlier, safe library version. Following the discovery of the backdoor, a detection and remediation effort was started, with CISA proposing downgrading the XZ Utils 5.4.6 Stable and hunting for and reporting any malicious activity.
Binarly says the approach taken so far in the threat mitigation efforts relies on simple checks such as byte string matching, file hash blocklisting, and YARA rules, which could lead to false positives. This approach can trigger significant alert fatigue and doesn’t help detect similar backdoors on other projects. To address this problem, Binarly developed a dedicated scanner that would work for the particular library and any file carrying the same backdoor. […] Binarly’s scanner increases detection as it scans for various supply chain points beyond just the XZ Utils project, and the results are of much higher confidence. Binarly has made a free API available to accomodate bulk scans, too.
Read more of this story at Slashdot.
Phil Spencer Wants Epic Games Store and Others On Xbox Consoles
Spencer explained how, in the past, console makers would typically subsidize the cost of expensive hardware, knowing that a portion of every dollar spent on games for the platform over the years would eventually make it back to the console maker. Then, in time, the console maker would recoup the subsidy — and hopefully more. But, Spencer said, “Moore’s Law has slowed down. The price of the components of a console aren’t coming down as fast as they have in previous generations.” Worse, he explained, the console market isn’t growing, with more gamers moving to PC and handheld options. Now, the notion of subsidizing a console — and forcing players to purchase games through the official storefront to help recoup costs — might not make sense. The walls meant to lock people into consoles might be motivating them to stay out.
“[Subsidizing hardware] becomes more challenging in today’s world,” Spencer said. “And I will say, and this may seem too altruistic, I don’t know that it’s growing the industry. So I think, what are the barriers? What are the things that create friction in today’s world for creators and players? And how can we be part of opening up that model?” The answer, in part, is scrapping exclusivity on more and more Xbox games. Spencer explained that the game experience is hindered when it matters what consoles we play on or what shops sell us our games. As an example, he pointed to Sea of Thieves. A player, he explained, shouldn’t have to worry about what hardware they or their friends own. They should just know if their friends have and want to play Sea of Thieves. Now, Spencer said, “if I want to play on a gaming PC, then I feel like I’m more a continuous part of a gaming ecosystem as a whole. As opposed to [on console], my gaming is kind of sharded — to use a gaming term — based on these different closed ecosystems that I have to play across.”
Read more of this story at Slashdot.