Apple Blocks Update of ChatGPT-Powered App

Apple has delayed the approval of an email-app update with AI-powered language tools over concerns that it could generate inappropriate content for children, according to communications Apple sent to the app maker. The software developer disagrees with Apple’s decision. From a report: The dispute shows the broad concerns about whether language-generating artificial-intelligence tools, such as ChatGPT, are ready for widespread use. Apple took steps last week to block an update of email app BlueMail because of concerns that a new AI feature in the app could show inappropriate content, according to Ben Volach, co-founder of BlueMail developer Blix, and documents viewed by The Wall Street Journal. BlueMail’s new AI feature uses OpenAI’s latest ChatGPT chatbot to help automate the writing of emails using the contents of prior emails and calendar events. ChatGPT allows users to converse with an AI in seemingly humanlike ways and is capable of advanced long-form writing on a variety of topics.

“Your app includes AI-generated content but does not appear to include content filtering at this time,” Apple’s app-review team said last week in a message to the developer reviewed by the Journal. The app-review team said that because the app could produce content not appropriate for all audiences, BlueMail should move up its age restriction to 17 and older, or include content filtering, the documents show. Mr. Volach says it has content-filtering capabilities. The app’s restriction is currently set for users 4 years old and older. Apple’s age restriction for 17 and older is for categories of apps that may include everything from offensive language to sexual content and references to drugs. Mr. Volach says that this request is unfair and that other apps with similar AI functions without age restrictions are already allowed for Apple users.

Read more of this story at Slashdot.

Apple Suppliers Are Racing To Exit China, AirPods Maker Says

Apple’s Chinese suppliers are likely to move capacity out of the country far faster than many observers anticipate to pre-empt fallout from escalating Beijing-Washington tensions, according to one of the US company’s most important partners. From a report: AirPods maker GoerTek is one of the many manufacturers exploring locations beyond its native China, which today cranks out the bulk of the world’s gadgets from iPhones to PlayStations. It’s investing an initial $280 million in a new Vietnam plant while considering an India expansion, Deputy Chairman Kazuyoshi Yoshinaga said in an interview. US tech companies in particular have been pushing hard for manufacturers like GoerTek to explore alternative locations, said the executive, who oversees GoerTek’s Vietnamese operations from northern Bac Ninh province.

“Starting from last month, so many people from the client side are visiting us almost every day,” Yoshinaga said from his offices at GoerTek’s sprawling industrial complex north of Hanoi. The topic that dominates discussions: “When can you move out?” The expanding conflict between the US and China, which began with a trade war but has since expanded to encompass sweeping bans on the exchange of chips and capital, is spurring a rethink of the electronics industry’s decades-old supply chain. The world’s reliance on the Asian nation became starkly clear during the Covid Zero years, when Beijing’s restrictions choked off the supply of everything from phones to cars.

Read more of this story at Slashdot.

Scientist Finds Rare Jurassic Era Bug At Arkansas Walmart, Kills It and Puts It On a Pin

Longtime Slashdot reader theshowmecanuck shares a report from CBS News: A 2012 trip to a Fayetteville, Arkansas, Walmart to pick up some milk turned out to be one for the history books. A giant bug that stopped a scientist in his tracks as he walked into the store and he ended up taking home turned out to be a rare Jurassic-era flying insect. Michael Skvarla, director of Penn State University’s Insect Identification Lab, found the mysterious bug — an experience that he says he remembers “vividly.”

“I was walking into Walmart to get milk and I saw this huge insect on the side of the building,” he said in a press release from Penn State. “I thought it looked interesting, so I put it in my hand and did the rest of my shopping with it between my fingers. I got home, mounted it, and promptly forgot about it for almost a decade.”

[I]n the fall of 2020 when he was teaching an online course on insect biodiversity and evolution, Skvarla was showing students the bug and suddenly realized it wasn’t what he originally thought. He and his students then figured out what it might be — live on a Zoom call. “We were watching what Dr. Skvarla saw under his microscope and he’s talking about the features and then just kinda stops,” one of his students Codey Mathis said. “We all realized together that the insect was not what it was labeled and was in fact a super-rare giant lacewing.” A clear indicator of this identification was the bug’s wingspan. It was about 50 millimeters — nearly 2 inches — a span that the team said made it clear the insect was not an antlion. His team’s molecular analysis on the bug has been published in the Proceedings of the Entomological Society of Washington.

theshowmecanuck captioned: “To be fair, he said he didn’t know what it was so [he] just collected it and took it home, and then figured it out later. My thought that I added to the title was because of this quote in the story (which tickled my cynicism in humanity): “It could have been 100 years since it was even in this area — and it’s been years since it’s been spotted anywhere near it…”

Read more of this story at Slashdot.

First PCIe 5.0 M.2 SSDs Are Now Available, Predictably Expensive

The first PCIe 5.0 SSDs are slated to ship this year with massive heatsinks and predictably high prices. Tom’s Hardware reports: There are multiple M.2 PCIe 5.0 SSDs slated to ship this year, and the first model looks to be the Gigabyte Aorus Gen5 10000, which as the name inventively implies can deliver up to 10,000 MB/s. Earlier rumors suggested the drive would be able to hit 12,000 MB/s reads and 10,000 MB/s writes, so performance was apparently reigned in while getting the product ready for retail. The Gigabyte Aorus SSD uses the Phison E26 controller, which will be common on a lot of the upcoming models. Silicon Motion is working on its new SM2508 controller that may offer higher overall performance, but it’s a bit further out and may not ship this year. The other thing to note with the Aorus is the massive heatsink that comes with the drive, which seems to be the case with all the other Gen5 SSD prototypes we’ve seen as well. Clearly, these new drives are going to get just a little bit warm.

The Gigabyte drive is currently listed on Amazon and Newegg, though the latter is currently sold out while the former is only available via a third-party marketplace seller — at a whopping $679.89 for the 2TB model. That’s almost certainly not the MSRP or a reflection of what MSRP might end up being once the drive becomes more widely available, which should happen in the coming month or two.

The other PCIe 5.0 M.2 SSD that’s now available is the Inland TD510 2TB, available at Microcenter for just $349.99 — assuming you have a Microcenter within driving distance. Inland is Microcenter’s own brand of drive, and while the cooler that comes with the SSD isn’t quite as large as the Aorus, it does feature a small fan for active cooling. Word is that the fan can be quite loud for something this small, so not a great feature in other words. Like the Aorus 10000, the Inland TD510 uses the Phison E26 controller and has the same 10,000 MB/s reads and 9,500 MB/s writes specification. Where Gigabyte doesn’t currently list random read/write speeds, the Microcenter page lists up to 1.5 million IOPS read and 1.25 million IOPS write for the Inland drive. Both drives also have an endurance rating of 1,400 TBW, with read/write power use of around 11W.

Read more of this story at Slashdot.

BitTorrent Seedbox Provider Handed Criminal Conviction Over Users’ Piracy

A man who rented out servers configured for BitTorrent file-sharing use has been handed a three-month suspended sentence in Denmark. Known as ‘seedboxes’, these pre-configured servers are not illegal per se, but when customers used the devices to break copyright law on known pirate sites, rightsholders held the server provider liable. TorrentFreak reports: Local anti-piracy group Rights Alliance (Rettigheds Alliancen) mitigates all types of piracy but for the past few years, has maintained a keen focus on torrent sites. Working in partnership with the Danish government’s SOIK IP-Task Force, Rights Alliance forced several sites to close down and successfully prosecuted site operators, staff members, and users who uploaded content to those sites. In 2021, Rights Alliance targeted specialized servers that not only supply content to torrent sites but also play a role in boosting download times while improving security.

In 2021, news broke that six people had been arrested in Denmark due to their alleged connections to several local torrent sites. Among them was Kasper Nielsen of internet services company HNielsen Networks, a supplier of servers under various brands that could be configured for ‘seedbox’ purposes. Available information indicated that the servers had been used by an unknown number of users to share content on private torrent sites ShareUniversity, Superbits and DanishBytes. […] When Rights Alliance filed its criminal complaint against HNielsen Networks, the anti-piracy group referenced the landmark Filmspeler case which involved the sale of piracy-configured media players.

According to statements published by Rights Alliance and NSK (Saerlig Kriminalitet) Denmark’s Special Crime Unit, Nielsen was convicted yesterday for selling seedboxes in the knowledge they were being used by others to share movies, TV shows, eBooks and other content, without permission from rightsholders. “On February 28, the Court in Aalborg ruled against the Danish owner behind a seedbox company for, in the period November 2020 to May 2021, having sold seedboxes and server capacity to an unknown number of people, knowing that they were used for illegal sharing of no less than 3,838 copyright-protected works on the Danish and Nordic file sharing services ShareUniversity, Superbits and DanishBytes,” Rights Alliance reports. Nielsen was handed a three-month conditional (suspended) sentence and a confiscation order for DKK 300,000 (around $42,600), the amount users had paid his company to access the seedbox servers. The 35-year-old must also pay compensation of DKK 298,660 to Rights Alliance. “Providers of seedboxes have a responsibility to ensure that their services are not used for illegal uploading and downloading of copyrighted content, which the Rights Alliance can clearly see that they are doing,” says Maria Fredenslund, Director of Rights Alliance. “Therefore, this case helps to send a signal to other providers that you cannot deliberately sell services to the illegal market.”

Since Neilsen took a plea deal at an early stage, none of the claims made by Rights Alliance were needed to be proven in court. “The 3,838 figure and any evidence related to ‘knowledge’ of infringement carried out by seedbox customers on the sites, were accepted as true,” reports TorrentFreak.

Read more of this story at Slashdot.

Dish Network Confirms Network Outage Was a Cybersecurity Breach

Dish Network, one of the largest television providers in the United States, confirmed on Tuesday that a previously disclosed “network outage” was the result of a cybersecurity breach that affected the company’s internal communications systems and customer-facing support sites. CNBC reports: “Certain data was extracted,” the company said in a statement Tuesday. The acknowledgment is an evolution from last week’s earnings call, where it was described as an “internal outage.” Dish Networks’ website was down for multiple days beginning last week, but the company has now disclosed that “internal communications [and] customer call centers” remain affected by the breach. Dish said it had retained outside experts to assist in evaluating the problem.

The intrusion took place on the morning of Feb. 23, the same day the company reported its fourth-quarter earnings. “This morning, we experienced an internal outage that’s continuing to affect our internal servers and IT telephony,” Dish CEO W. Erik Carlson said at that time. “We’re analyzing the root causes and any consequences of the outage, while we work to restore the affected systems as quickly as possible.” According to Bleeping Computer, the Black Basta ransomware gang is behind the attack, first breaching Boost Mobile and then the Dish corporate network.

Read more of this story at Slashdot.

YouTube Video Causes Pixel Phones To Instantly Reboot

An anonymous reader writes quotes a report from Ars Technica: Did you ever see that movie The Ring? People who watched a cursed, creepy video would all mysteriously die in seven days. Somehow Google seems to have re-created the tech version of that, where the creepy video is this clip of the 1979 movie Alien, and the thing that dies after watching it is a Google Pixel phone. As noted by the user ‘OGPixel5″ on the Google Pixel subreddit, watching this specific clip on a Google Pixel 6, 6a, or Pixel 7 will cause the phone to instantly reboot. Something about the clip is disagreeable to the phone, and it hard-crashes before it can even load a frame. Some users in the thread say cell service wouldn’t work after the reboot, requiring another reboot to get it back up and running.

The leading theory floating around is that something about the format of the video (it’s 4K HDR) is causing the phone to crash. It wouldn’t be the first time something like this happened to an Android phone. In 2020, there was a cursed wallpaper that would crash a phone when set as the background due to a color space bug. The affected phones all use Google’s Exynos-derived Tensor SoC, so don’t expect non-Google phones to be affected by this. Samsung Exynos phones would be the next most-likely candidates, but we haven’t seen any reports of that. According to CNET, the issue has been addressed and a full fix will be deployed in March.

Read more of this story at Slashdot.

LastPass Says Home Computer of DevOps Engineer Was Hacked

wiredmikey shares a report from SecurityWeek: Password management software firm LastPass says one of its DevOps engineers had a personal home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud storage resources. LastPass on Monday fessed up a “second attack” where an unnamed threat actor combined data stolen from an August breach with information available from a third-party data breach, and a vulnerability in a third-party media software package to launch a coordinated attack. […]

LastPass worked with incident response experts at Mandiant to perform forensics and found that a DevOps engineer’s home computer was targeted to get around security mitigations. The attackers exploited a remote code execution vulnerability in a third-party media software package and planted keylogger malware on the employee’s personal computer. “The threat actor was able to capture the employee’s master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer’s LastPass corporate vault,” the company said. “The threat actor then exported the native corporate vault entries and content of shared folders, which contained encrypted secure notes with access and decryption keys needed to access the AWS S3 LastPass production backups, other cloud-based storage resources, and some related critical database backups,” LastPass confirmed. LastPass originally disclosed the breach in August 2022 and warned that “some source code and technical information were stolen.”

SecurityWeek adds: “In January 2023, the company said the breach was far worse than originally reported and included the theft of account usernames, salted and hashed passwords, a portion of Multi-Factor Authentication (MFA) settings, as well as some product settings and licensing information.”

Read more of this story at Slashdot.