Electronic Frontier Foundation

Cops Searched Thousands of Flock Cameras for Reasons of 'LMAO,' 'IDK,' 'Hehe,' And 'Asdfg' (eff.org) 170

404 Media reports: Last summer, a cop with the Lake County, Indiana Sheriff's Department used Flock's surveillance search engine to look for a license plate across more than 19,000 cameras in 1,558 cities and towns. The cop's stated reason for the search, according to a record of Flock's system, was "LMAO."

The cop is one of dozens who put gibberish, jokes, or other nonsense into Flock's "reason" box, highlighting the casualness and lack of care some cops have when searching an incredibly powerful surveillance system. This is on top of the thousands upon thousands of cops who simply wrote something like "investigation," "test," or left the box blank as their search "reason," according to a new analysis by the Electronic Frontier Foundation and shared with 404 Media. EFF's investigation found cops across dozens of jurisdictions writing "LMAO," "LOL," "Hehe," "Haha," "idk," "blah," "TBD," and "robbery I don't remember the case number leave me alone" in Flock's "reason" box for searches.

They found cops writing "idiot," "fuck this new search engine," "dickhead," "shithead," and "WEIRD KID" in the reason box. And they found an entire class of police button mashers, who ran searches for reasons of "asdfg," "gyghkkghghjkghjk," "jhjhjkhj," "jkhhkjhjk," "nmbvcbnm," and so on and so forth. The searches came from police departments across the country from 2023 through late 2025, when Flock changed how the "reason" box in its search system functions...

Each time a search is performed, a record of it is saved in the Flock system, which can be obtained by the public using government records requests. These audit logs show hundreds of thousands of searches of the system; after 404 Media and other news outlets used these types of logs to show police using the Flock system to look for undocumented immigrants on behalf of ICE, a woman in Texas who had an abortion, and protesters, cops were warned by government surveillance centers to be "as vague as permissible" about the reasons for their searches...

A police department said it investigated a cop who wrote "driving around being weird" in the reason field but found it was for "legitimate public safety purposes."

If a police chief "stood in front of a city council and asked for permission to install hundreds of cameras just so his officers could investigate the high crime of 'haha,' they would be laughed out of the room," argues the EFF blog post, calling this proof that agencies can't be trusted to oversee themselves.

But judges aren't being asked to authorize searches or review evidence, which the EFF post argues shows laws and courts haven't caught up yet with a new technology. Whatever auditing happens is clearly "deficient," the EFF warns, and while many jurisdictions require by law an actual reason for searches, "this keeps happening because police use automated license plate readers as a convenient shortcut around constitutional privacy safeguards." The EFF sees police officers "making a mockery of our civil liberties" by logging reasons like "LOL", "LMAO", "sexy", and "idk" while accessing sensitive location data.

In fact, they argue the warrant-less databases fostered a culture of abuse that "allowed police to treat a mass surveillance network like their own personal search engine, permitting the tracking of the movements of everyday citizens for low-level complaints, personal whims, and sometimes, seemingly, for the lols." Flock Safety claims it has improved its system by requiring officers to select from a dropdown list of crimes before running a search-but that only makes it easier for officers to hide improper searches behind the veneer of uniformity. The system does not require proof that the dropdown reason actually matches the true purpose of the search... Since this update, officers are no longer required to type out why they are digging through a driver's movement history, and instead can select a pre-packaged option like "Traffic infraction" or "Other" in half a second...

Mass surveillance is incompatible with a free society, and especially so when the people with access to this data are treating it like a joke. This ALPR mass surveillance — the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion — should not exist. But because it does, EFF continues to urge courts and state legislatures to immediately step in and impose strict, enforceable restrictions to rein in this abuse. At an absolute minimum, this means mandating rigid data deletion deadlines and an ironclad warrant requirement.

If police want the power to track a person's movements, they must be required to convince a judge with evidence and probable cause. They should not be able to bypass the Constitution with a search for "haha."

Censorship

ABC Show Won't Air Interview With Democrat Because of FCC Threats (arstechnica.com) 279

An anonymous reader quotes a report from Ars Technica: ABC's Jimmy Kimmel said he will be interviewing a Democratic candidate for Senate tonight, but the interview will be on YouTube only and not broadcast on TV because of threats made by the Federal Communications Commission. Kimmel has been a prime target in the Trump FCC's attacks on ABC and its owner, Disney. In his monologue last night, Kimmel said he'll be interviewing Democrat James Talarico, a state representative who is running against Texas Attorney General Ken Paxton for a seat in the US Senate.

In previous years, such an interview would have aired on the broadcast show via local stations throughout the country, Kimmel said. This time, it will only be on the Jimmy Kimmel Live YouTube channel in order to prevent further trouble for individual stations that hold FCC licenses, he said. "I'll be interviewing James Talarico tomorrow night under unusual circumstances," Kimmel told the audience on Wednesday. "For a lot of years, for the whole 20-plus years of our show, in fact, I've been interviewing Americans who are running for office with no problem at all, just like Letterman did, Leno did, Arsenio, et cetera, et cetera. I've interviewed a lot of political candidates, from Hillary Clinton to Ted Cruz to Donald Trump himself." But as Kimmel said, "something has changed." Disney suspended Kimmel briefly last year after FCC Chairman Brendan Carr threatened to revoke the licenses of ABC stations for "news distortion" if they continued to air Kimmel's show. [...]

Kimmel said the decision to put the interview on YouTube was made out of consideration for local stations that could face FCC threats to their broadcast licenses. "And so out of consideration for our local stations, especially our ABC affiliates in Texas who would have to deal with this nonsense, my interview tomorrow with James Talarico will not air on television," Kimmel said. "It will be posted on YouTube instead. It will not be on TV. So if you want to learn about a candidate for the Senate tomorrow, you will have to go to the Jimmy Kimmel Live YouTube channel where you will see it in its entirety, and thank goodness we have that because in the America we live in right now, that is the best that we can do, until November, of course."
"Jimmy Kimmel's decision to keep his interview with a Senate candidate off the air shows just how far this administration's campaign of censorship and control has gone," FCC Commissioner Anna Gomez, the commission's only Democrat, said today. Gomez said the FCC "has no lawful authority to threaten broadcast licenses over guest bookings or editorial decisions," and that "no host, local affiliate, or network should have to weigh federal retaliation before booking a guest for a newsworthy interview. Any attempt to pressure broadcasters into self-censorship undermines both press freedom and the public's right to hear from candidates in their communities seeking public office."

The report notes a similar controversy that occurred in February when Stephen Colbert said CBS forbade him from interviewing Talarico. CBS denied prohibiting the interview but said it gave Colbert "legal guidance that the broadcast could trigger the FCC equal-time rule for two other candidates [...] and presented options for how the equal time for other candidates could be fulfilled." That interview also ended up being published on YouTube.
Privacy

LG TVs Caught Spying Even When Offline or On Standby (theverge.com) 160

A Gamers Nexus investigation found that LG smart TVs are almost constantly logging and uploading data about owners and their homes, even while they are offline or in standby mode. "The company's TV sets scan Wi-Fi networks for nearby devices, record audio logs through their microphones, and use audio and video sampling to recognize exactly what you're watching from across the TV inputs," reports The Verge. From the report: Gamers Nexus partnered with fellow YouTubers Level1Techs and independent security researchers for the investigation, which involved testing retail LG OLEDs. Packet captures showed the TVs scanning the local area network for nearby hardware like phones or smartwatches, as well as logging location data and details of nearby Wi-Fi networks, and feeding the information back to LG Ad Solutions. Perhaps more concerningly, the TVs were capable of recording microphone audio when in standby; this continued even after the TV was disconnected from the internet, with audio files stored offline and uploaded once a connection was restored. Earlier this year, LG was found to be silently installing an adware-like app on Windows PCs that ran pop-up ads for other LG apps and even McAfee antivirus.
Chromium

Does Brave Browser Load Faster Than Chrome, Firefox, and Microsoft Edge? (linuxiac.com) 61

The Brave web browser published a new round of benchmarks claiming its desktop browser uses less system resources than Chrome, Microsoft Edge, and Firefox — and also loads pages faster. The blog Linuxiac reports: According to Brave's testing, the browser used 44% less CPU, 28% less memory, and 10% less energy on average compared with the three competing browsers. It also completed page loads 20% faster while transferring 26% less inbound data and 39% less outbound data...

- Brave averaged about 33% CPU usage, while Chrome used 47%, Edge 53%, and Firefox 78%.

- For memory, Brave used about 1.2 GB, compared to 1.75 GB for Chrome, 1.62 GB for Edge, and 1.65 GB for Firefox.

By stopping ads, analytics scripts, tracking pixels, and other third-party requests from loading, the browser has less network traffic and less work to do. In page-loading tests, Brave took about 4.4 seconds to fully load a page. Chrome took 5.1 seconds, Firefox 5.3 seconds, and Edge 6 seconds. However, when measuring Largest Contentful Paint, which is when the main content appears, Brave and Chrome both averaged about 2.4 seconds, with Edge and Firefox just behind at 2.5 seconds. This means Brave's main advantage comes after the main content is visible, since there are fewer background ads, trackers, analytics requests, and delayed scripts to process.

Biotech

'She Lost Her Sight. Her Billionaire Father Bet On a Daring New Treatment.' (msn.com) 118

"Billionaire Bill Ackman's life was upended this February when his 26-year-old daughter collapsed in her Brooklyn apartment, suffering a brain hemorrhage that would render her unable to move, speak or see," writes the Washingon Post. But then... The hedge fund manager did what any good father would do — at least, any father with vast financial resources and what friends describe as a "Mr. Fix-It" tendency. He sprung into action, getting her topline care at New York City's Mt. Sinai Hospital and consulting a network of well-connected friends all over the world. He helped her access a novel cell therapy that has been gaining traction among longevity enthusiasts, who are seeking ways to prolong human life. And then — motivated by a newfound desire to accelerate scientific research — he vowed to spend more than $400 million to launch an institute dedicated to longevity and brain health... He posted this week that the U.S. Food and Drug Administration, in May, gave his daughter Lucy's medical team a first-time emergency authorization to transplant mitochondria — the energy-producing part of human cells — from her leg muscle to her eyes, in the hopes that the tiny cell powerhouses would facilitate healing in her optic nerves and perhaps even restore her vision.

Ackman's story highlights the increasingly prominent role of the ultra-wealthy in making expensive medical bets on longevity treatments and other novel therapies, altering the direction of research as federal funding for science declines in the second Trump administration. But his saga is a deeply personal one, spurred by his daughter's medical crisis. The focus on longevity by Ackman, who made billions on Wall Street as a hedge fund manager, is aligned with similarly ambitious efforts from some of Silicon Valley's biggest names. OpenAI CEO Sam Altman has backed Retro Biosciences, a start-up whose goal is to add 10 healthy years to the human lifespan through cellular reprogramming. Amazon founder Jeff Bezos is reportedly a funder of Altos Labs, which focuses on cellular rejuvenation and resilience... Billionaire investor Peter Thiel, Google co-founder Sergey Brin and Oracle co-founder Larry Ellison are also deeply invested in life-extension methods and attempts to rewrite the biology of aging...

The therapy given to Ackman's daughter Lucy, known as mitochondrial transplantation, is of great interest not only to people who have suffered injuries, but to longevity-focused scientists who believe that mitochondria may hold promise for reversing some of the effects of aging... In recent years, scientists have discovered that mitochondria have many other functions beyond converting food into energy. They serve as clearinghouses for damaged cells, opening up the possibility that they can help with cell regeneration and healing, said Daria Mochly-Rosen, professor of chemical and systems biology at the Stanford University School of Medicine and co-author of " The Life Machines: How Taking Care of Your Mitochondria Can Transform Your Health."

"I am one of those who believes that focusing on mitochondrial health is a way to address many human diseases, including aging itself," she said. "It's exciting."

Bitcoin

Bitcoin-based Liquid Network Says $320 Million Withdrawn in Hack (reuters.com) 41

Reuters reports: Liquid Network, a Bitcoin-based payments and settlement network, said on Sunday that about $320 million was withdrawn from its federation wallet in a hack. "Purported white-hat hackers" withdrew around 4,000 of the 4,200 bitcoin held in its Liquid Federation wallet, Liquid Network said in a post on X.
"Liquid wallets will be impacted," their post concluded, adding "and we're sorry for any inconvenience."
Power

Where a Massive Solar Storm Could Take Down the US Power Grid for Millions (cnn.com) 51

A new study published Friday in AGU Advances "depicts the most advanced picture yet of how a rare but massive solar storm could affect some US industries and electric systems more than others," reports CNN.

"During a 250-year solar storm, the East Coast would have widespread potential for grid failure." Researchers modeled what a Carrington Event — a 1-in-150-year geomagnetic storm or even rarer — could mean for the modern day. They estimate the US economy would lose about $1.5 billion to $2 billion per day from direct and indirect costs, as millions of people face power outages. The findings show the most vulnerable areas are the Northeast and the Northern Plains, especially locations at higher latitudes.

No one knows when the next big storm will hit. While the most severe geomagnetic storms are labeled as once-in-a-century or rarer, these events don't follow a fixed schedule. "That timing only averages out on very long timescales," said Anna Kelbert, a geophysicist at the Harvard-Smithsonian Center for Astrophysics, who was not involved in the study but previously studied solar storm effects on power grids. "The event can occur at any time, as soon as a week from now, or centuries later...." [Shawn Dahl, service coordinator at the Space Weather Prediction Center operated by the National Oceanic and Atmospheric Administration in Boulder, Colorado], said the sun is now coming down from a period of heightened activity, which is also when some of the biggest storms to hit Earth have occurred in the past. "We still need a lot of work to be ready...."

"We haven't really seen events like this size in the modern era, where we've had all of this high technology and we've had the power grid of this size," said Ed Oughton, researcher at George Mason University and lead author of the new study... Because the US grid's actual structure is proprietary for security reasons, the team used engineering models to create various network and transformer setups including the 10,464 substations and 16,256 transmission lines found across the country... The grid structure also contributes to higher risk in some areas. For instance, the eastern US is linked together in a single grid interconnection. A voltage issue in Maine, if not isolated early, could cascade through the grid to Washington, DC. The West works similarly, whereas the Texas interconnection operates mostly within the state...

Power is restored over time depending on any alternative electrical paths that could bypass the substation or availabilities of spare transformers, for instance. "This nationwide analysis shows that we are currently ill-prepared to face a major magnetic storm, and that the societal impacts would be catastrophic," Kelbert said.

"The study estimates power disruptions for 5.1 million people and 135,000 businesses," according to the article, and "The outages could last from hours to days to weeks depending on the damage and resources available to get back online, said Oughton."
Government

Flock Offered Webinar Teaching Cops How to Surveil 'No Kings' Protesters (404media.co) 107

Thursday 404 Media reported that Flock taught America's cops "how they could surveil the No Kings protests" against President Trump (as well as "small parades") in a webinar last year that described "using a mix of Flock's technology and law enforcement's own databases." In the webinar, Flock's director of market management Caity Peak explains how real time crime centers — which are police surveillance centers that utilize Flock cameras and other surveillance cameras — can be used for emergency response, but can also be used to surveil "established events" like 4th of July fireworks displays, parades, bike races, Mardi Gras, and protests. The webinar shows just how routine the idea of always-on surveillance has become, and how casually it is used during extremely innocuous events. Peak explains that police can use FlockOS, a software platform that combines Flock's automatic license plate readers (ALPR), drones, gunshot detectors, 911 data, and other surveillance cameras (including ones Flock does not own) into a "single pane of glass" or single piece of software to look at various types of surveillance in one place during both emergencies and relatively mundane events in a city or town.

"Imagine that you're an incident commander, and you're working this No Kings Protest," Peak explains while a dashboard shows a series of surveillance tools overlaying the city of Denver. "If I'm somebody assigned a traffic post that's working this No Kings Protest, I really don't have time to go in [...] and look at all these places [for different intelligence]. This is an example of viewing all of that in one place...." The dashboard Peak shows includes traffic information, a "response plan" for the protest, the floor plans of nearby buildings, as well as a series of video feeds of both outdoor-mounted cameras and cameras inside businesses and government buildings.

404 Media and the Electronic Frontier Foundation previously showed that police have specifically used Flock cameras to monitor the No Kings protests and other First Amendment-protected activity... This webinar shows this type of surveillance is not anomalous, and is specifically taught by Flock. The webinar also shows that Flock's latest public stance — that its ALPR cameras are noninvasive technology, that they take only static images at a single place and time, and that they are primarily used to solve the worst crimes — is wildly misleading. Flock has time and time again pitched itself to police as a sort of operating system to solve crime and do real-time surveillance and predictive policing. ALPRs are just one part of this broader surveillance apparatus that Flock has created, markets to police, and teaches them how to use.

GNU is Not Unix

FSF is Now on Bluesky - But Won't Advocate Signing Up Due to Nonfree JavaScript (fsf.org) 38

The Free Software Foundation (FSF) is now on Bluesky, they announced this week. But "We can't advocate that you sign up for a Bluesky account like we do with Mastodon or PeerTube since signing up for Bluesky means loading the registration page's nonfree JavaScript..." While federated, Bluesky is generally not considered part of the "fediverse" network of social media services like Mastodon and PeerTube, as it uses its own AT protocol rather than ActivityPub... Hosting your own Bluesky "Personal Data Server (PDS)" and relay is technically possible, but generally far more difficult and resource-intensive than spinning up an instance of Mastodon, let alone any of the lighter-weight ActivityPub servers like Akkoma or Starling.

Much of the Bluesky codebase is freely licensed. This allows users to run, copy, modify, and share large parts of the codebase. However, Bluesky's web client still serves nonfree JavaScript to users, just like its registration page. (Since our script was written for us specifically, we have not extensively vetted all available clients.)

Why did we sign up? Simply put, we have to continue to reach people where they are. Bluesky is a decent choice for us that evades many of the issues of other, more problematic networks... We accepted running Bluesky's nonfree JavaScript a single time if it meant being able to reach people who have never heard of software freedom.

The FSF's blog post advises supporters "If you're on social media, follow the FSF on Bluesky and on Mastodon today."

Slashdot also has an account on Blueky.
Supercomputing

Nvidia Launches Free Tool That Links Idle Computers Into a Personal AI Data Center 48

Nvidia has launched PAIR, a free open-source tool that links compatible computers on a home network so they can pool idle processing power for local AI inference and agentic workloads. "While the compatible devices are mostly Nvidia GeForce GPUs (PAIR works with RTX 20-series cards and newer, as well as RTX Pro GPUs and DGX Spark systems), Apple's M4 chips or newer will also work," reports The Verge. From the report: The key thing here is that PAIR uses your in-home systems when they're idle to avoid interfering with other tasks. And this disaggregated system of computers can work in parallel to chew through lots of processing requests -- which should be helpful for an agentic workflow that breaks complex tasks into smaller jobs. This should prevent large bottlenecks on a single GPU, and Nvidia says PAIR can adapt as devices join or leave the network -- including if a user does something like start playing a game on their desktop PC.

[...] Nvidia says PAIR is secured by pairing all devices through a six digit code and then securing the channel via mTLS (Mutual Transport Layer Security), to create an encrypted communication line that's trusted in both directions between computers. The Nvidia PAIR beta is available today, with support for Windows, Linux, and macOS.
The Courts

Google Defeats US Bid to Force Ad Tech Sale (yahoo.com) 29

An anonymous reader quotes a report from Reuters: Alphabet's Google escaped a breakup of its advertising technology business on Wednesday, when a judge in Virginia rejected U.S. antitrust enforcers' bid to force a sale of Google's online advertising exchange. While the ad exchange is a small part of Google's business, the ruling is the second powerful symbolic victory against the U.S. Department of Justice in its efforts to force Google to sell assets to address illegal monopolies. U.S. Judge Leonie Brinkema in Alexandria, Virginia, declined to make Google sell AdX, where publishers pay Google a 20% fee to sell ads in auctions that happen instantly when users load websites. She accepted most of the parties' proposed behavioral remedies.

The DOJ and a broad coalition of states sued Google in 2023 over its dominance in markets for advertising technology used by online publishers and websites. In April 2025, Brinkema ruled that Google holds illegal monopolies on servers that host publisher ads and ad exchanges which sit between buyers and sellers. Google unlawfully locked publishers on its ad server into using its AdX, the judge found. The tech giant's anticompetitive conduct "substantially harmed Google's publisher customers, the competitive process, and, ultimately, consumers of information on the open web," Brinkema said at the time.

At a trial last year on remedies in the case, the DOJ argued that Google cannot be trusted to run AdX, given its past behavior. Google argued that a forced sale would be technically difficult and result in a long and painful transition that would hurt customers. During the remedies trial, Google's lawyers warned that forcing it to sell parts of its ad-tech business would cause disruption and damage. [...] The ruling is the third time in a row that a judge has rejected a bid by U.S. antitrust enforcers to break up Big Tech in a crackdown that started during President Donald Trump's first term. In another major Google antitrust case, a judge similarly rejected the DOJ's push to force Google to sell Chrome. It is likely to fuel questions about whether courts are up to the task of checking the industry's unprecedented power over the U.S. economy.

Mars

NASA Selects Blue Origin As Mars Telecommunications Network Provider (nasa.gov) 64

NASA has awarded Blue Origin a contract worth up to $700 million to build and operate a dedicated Mars telecommunications network for current and future missions to the Red Planet. Blue Origin is expected to deliver the spacecraft by the end of 2028, with the network targeted to become operational by 2030. From a press release: Blue Origin will design, develop, integrate, launch, and operate the network as a part of the agency's broader space communications and navigation infrastructure. The architecture will consist of a high-performance telecommunications spacecraft orbiting Mars, transmitting science data, imagery, navigation information, and critical mission communications for spacecraft operating on and around the planet.

The award marks a milestone in NASA's strategy to expand communications and navigation services beyond Earth and the Moon, establishing the foundation for sustained exploration of Mars in the coming decades.

The Almighty Buck

BT's Old Copper Landline Network Could Be Worth Over $2 Billion (engadget.com) 59

BT could make more than $2.7 billion by recycling copper from its aging UK landline network as BT subsidiary Openreach replaces legacy wiring with full-fiber broadband. Engadget reports: BT's recovered copper was previously valued at around $2 billion. But prices have surged, thanks to rising global demand tied to AI data centers, renewable energy and electrification. With global demand expected to grow sharply over the next decade, the value of BT's copper could potentially exceed even that $2.7 billion estimate.

The BT subsidiary Openreach is in the process of replacing its legacy copper network with full-fiber broadband, with plans to connect 30 million residences by the end of the decade. It's already recovered nearly 10,000 metric tons of copper in its latest financial year and over 22,000 metric tons since 2023. "Copper has become one of the most strategic materials in the modern economy," according to Openreach's head of sustainability, Abby Chicken.

Unsurprisingly, BT isn't waiting to profit from the recovered metal. It has an agreement with EMR, a cable recycling company, and recently received $133 million up front for recovered copper.

Social Networks

Operation Bluebird Launches New Twitter (arstechnica.com) 111

An anonymous reader quotes a report from Ars Technica: Operation Bluebird, the Virginia-based startup trying to revive the allegedly abandoned "Twitter" name and logo, announced Monday that it has launched its new social media network: Twitter.now. "We are a small company, we have investors, and we have a product," Stephen Coates, one of Operation Bluebird's cofounders, told Ars. "And we have waited months and months to launch, and we are not going to wait anymore."

[...] Twitter.now, still in its nascent stage, only has hundreds of users for the time being. The social media network looks and feels much like the Twitter of old and many of its offshoots -- it has replies and retweets. A new and notable feature is the automated fact-checking tool, a Gemini-based "veracity engine for real-time analysis" ("Vera" for short), which runs on every tweet. Coates has been testing Vera in recent days by posting obviously false messages, like "George Washington was our second president."

"Our first goal is to see if we can truly bring back a town square that's safer and less harmful," he said. "We say freedom of speech and not freedom of reach. We want people to say what they want, but we also want to create a platform that's not financially locked into that viral content that's harmful or inaccurate."
Operation Bluebird argues that Elon Musk effectively abandoned the Twitter brand and trademarks when he renamed the company X, opening the door for the startup to claim them. X Corp. sued to stop the effort, but a federal judge tentatively ruled in April that X appeared to have relinquished rights to "tweet," the bird logo, and possibly "Twitter" itself, though no written ruling has been issued.

Bluebird has taken that as enough of a green light to move forward while emphasizing that its new Twitter is not affiliated with X. "Operation Bluebird, Inc. picked up the name X Corp. walked away from and is rebuilding it on trust, in your browser at twitter.now," it states prominently on its website. "We are not X, and we are not affiliated with X Corp."
Space

SpaceX Plans to Build a $100 Billion Spaceport In Louisiana (cnbc.com) 179

SpaceX plans to spend up to $100 billion building a new Starship launch facility in Vermilion Parish, Louisiana, which the state says could eventually "support thousands of launches annually." CNBC reports: Once built, Starbase, LA will serve as the main launch facility for Starship, SpaceX's in-development rocket that's the largest ever built and designed to be fully reusable. Musk has aspirations to massively expand SpaceX's Starlink satellite network, to launch orbital data centers and to someday colonize Mars. Those ambitions, and justification for SpaceX's nearly $2 trillion market cap, hinge on the success of Starship.

SpaceX said, in a video posted to its website on Tuesday, that the search for a site to build launch pads and have access to ample fuel for its operations took about seven years. Musk said in the video that the company would bring "probably 10,000 really exciting jobs" to Louisiana with the spaceport. A fact sheet posted online by the state of Louisiana said SpaceX is expected to generate an estimated "3,000 direct new jobs over the next 10 years" in the state, and "8,100 indirect new jobs." SpaceX said it would work on a "historic coastal restoration" in Louisiana, in partnership with the state to "bring the marsh back" and ensure the wetlands around its new facility will have "storm protection."

Security

Windows Backdoor 'Sleepwalker' Hides in Memory Until Activated by a 'Magic Packet' (theregister.com) 39

"The Register has a story about a Windows backdoor that waits silently in memory for a 'magic packet' before springing into action," writes Slashdot reader fred133. "No outgoing traffic, just waiting..." From the report: Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer. Malware researcher Dominik Reichel discovered the passive backdoor, which also has its own command language, and detailed Sleepwalker in a technical analysis on Monday. "What makes it worth writing up is what that packet carries: not a readable command, but a short program written in a command language of the backdoor's own design," Reichel said. "Its 23 instructions cover scheduling, several ways to move data, staged file delivery and running code directly in memory. Recovering the encryption key is not enough to understand one of these programs. The internal command language must be reverse engineered as well."

In addition to having its own command language, it's also notable that the remote host can be a VMware VMCI target instead of a normal network address. "Taken as a whole, the approach here is consistent with a targeted, well-resourced operation rather than an opportunistic one," Reichel wrote. The malware, hidden inside a 64-bit Windows DLL file, impersonates Microsoft's dpapi.dll, part of Windows' data protection API for protecting sensitive data. It exports the same seven functions as the real dpapi.dll, but attempts to forward calls to a file named dpapisvc.dll, which is not a real Windows component. The file also has a forged ESET Management Agent version resource, and loads via side-loading into ERAAgent.exe, the Windows executable for ESET Management Agent. After confirming that its host process is named ERAAgent.exe, Sleepwalker goes to sleep inside the computer's memory, which also helps it remain hidden from traditional anti-virus tools.

Unlike most backdoors, which call back to an attacker-controlled command-and-control (C2) server and start receiving commands, Sleepwalker lies in wait, checking every packet that passes through the network looking for a specific pattern - this is called a magic packet. Once it sniffs out a packet that matches the exact pattern, the backdoor decrypts the data and treats it as a command. "Because the backdoor never sends anything out on its own and does not open any obvious listening port by default, tools that watch for connections to known-bad domains or unusual outbound traffic will not see anything unusual," Reichel wrote. "The absence of outbound connections to known-bad infrastructure does not rule out an infection, either. A machine can be fully compromised by this backdoor while producing nothing at all for a network monitor to flag."

Privacy

AliExpress Leverages User Audio Systems For Fingerprinting (cybernews.com) 83

A developer says AliExpress is using the browser's WebAudio API to help fingerprint users by playing inaudible audio and measuring tiny differences in how their devices process it. CyberNews reports: The developer, "laserphile," wrote on their blog that they recently ran into some weird issues with their Bluetooth headphones. They couldn't play music via their phone when, at the same time, the AliExpress website was open on their PC. The headphones, laserphile explained, support multipoint Bluetooth audio so they can be connected to the PC and phone at the same time, for instance, playing music on the phone and announcing notifications through the PC. "Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately," the developer said in the blog post.

"Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page. This seemed suspicious enough to investigate." It turns out that Alibaba has been secretly leveraging AliExpress users' audio systems to track them and build detailed fingerprints of them. [...] The AliExpress site was using the browser's WebAudio API to run invisible sound waves at zero volume. By measuring tiny hardware differences in how each PC processed those signals, the site created a unique digital fingerprint to track devices -- without user knowledge or consent.

The secret audio path froze the developer's Bluetooth connection while covertly scraping hardware memory, screen dimensions, and network data in the background. The data collection extends beyond audio. Further inspection revealed that the same scripts also measure canvas, WebGL, hardware specs, WebRTC, mouse/touch events, and automation indicators. All of these form a broad device fingerprint that is sent back to Alibaba's telemetry servers.
The simplest fix is to use a privacy-focused browser such as Firefox or Brave, which can limit or block this kind of fingerprinting. Brave goes further by randomizing fingerprint data and blocking the AliExpress tracking scripts involved.
United Kingdom

Iran-linked Cyberattackers Shut Down a UK Power Plant for Four Days (bbc.co.uk) 39

"Iran shut down a British power plant for four days in an unprecedented cyber attack," reports the Telegraph.

More details from the BBC: The government said that at no point was there a risk to the UK's energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of cyber attacks... DESNZ said the incident had affected a small-scale generator and at no point had there been a risk to the wider energy system. The UK's power network has a number of smaller gas generators which provide short-term power when needed.
Thanks to Alain Williams (Slashdot reader #2,972) for sharing the news.
Government

Slovakia Finds Russian Backdoor In Traffic Speed Cameras (tomshardware.com) 44

Slovakia acquired speed cameras to modernize its traffic control-- but there was a surprise. Tom's Hardware cites this story from the Risky Bulletin Newsletter: Unfortunately, the country's national security service, the NBU, has discovered that the cameras have multiple security issues. Firstly, they have SMS-activated Russian backdoors. Secondly, live camera feeds can be accessed by anyone with the device IP, no password necessary...

[The cameras] are thought to be rebranded Russian CORDON PRO.M traffic cameras, produced by a St. Petersburg-based firm called Semicon... reportedly bought via a Cyprus-based shell company with fake certifications. Reports also suggest that pressure from the opposition political party in Slovakia led to the NBU investigations... Probably most seriously, in terms of national security, these cameras contain a hardcoded list of Russian phone numbers, which can be used to open a backdoor. An SMS from one of these numbers can open shell and network access... [T]he SecureBoot feature is ineffective, and the web management portal can be accessed, exposing live streams, by anyone with the camera IP.

Cameras that have been installed and set up have since been deactivated by the Slovak Ministry of the Interior. Meanwhile, for due diligence, an independent auditor will be called in to confirm the NBU's findings. It is thought that Croatia, and some other countries in Eastern Europe, may have undiscovered issues with traffic control cameras of similar origin.

Games

23 Years After SimCity 4's Release, 'Eternal Commuter' Bug Finally Fixed (pcgamesn.com) 9

"It began life just a year after SimCity 4's 2003 launch," writes the blog PCGamesN. "Now, over 20 years later, it's still going strong with the arrival of Network Addon Mod update 50." The SimCity 4 Network Addon Mod, or simply 'NAM' among the community, has long been a de facto recommendation to anyone looking to pick up the classic city builder. It's a comprehensive overhaul to the game's transportation and infrastructure networks that combines key fixes with a vast set of additional build pieces such as overpasses, intersections, on-ramps, roundabouts, and so on.... [Y]ou'll be able to place down elements adjacent to one another that might previously have needed a one-tile gap between them. Streets can be dragged diagonally, slope tolerances have been improved, and you can build tunnels with the street network.

The new version also includes a fix for the 'Eternal Commuter Loop' bug, which might sound fairly innocuous if you're not deep in the weeds. In actuality, it's a 23-year-long frustration that has plagued modders ever since launch. Essentially, it's a problem with the regional pathfinding across city boundaries in certain layouts, causing your Sims to bounce from location to location in search of work without actually taking up a job in any of them. Your zone demand is ruined, traffic builds to unsustainable levels, and the economy falls to pieces before your very eyes. Until now, the only real solution was to simply avoid building layouts that gave your commuters the chance to loop between locations. Now, by blocking specific neighbor-to-neighbor routes while allowing the rest to run as normal, the problem has been resolved...

Equally impressively, the mandatory implementation of the DLL has reduced the size of the NAM codebase "by almost 90% and by more than ten million lines, making it easier to maintain and reducing the chance of bugs."

Thanks to long-time Slashdot reader Striek for sharing the news.

Slashdot Top Deals