United States

Secretive DHS 'Predictive Policing' Unit Is Analyzing Americans' Financial Habits, Pulling Them Over (404media.co) 148

An anonymous reader quotes a report from 404 Media: Border Patrol is running secretive predictive policing units that analyze Americans' financial activity and other data, then feed that intelligence to local police who pull people over who are not suspected of any specific crime, but which the government thinks may be worth searching, 404 Media has found. The units, the name of which 404 Media is revealing here for the first time, are called Predictive Intelligence Targeting Teams (PITT). In one case, a PITT analyzed the financial activity of a man who was driving across Montana, and local authorities stopped him under the pretense of an obstructed license plate and charged him with a DUI.

404 Media identified one PITT in the Spokane Sector, Washington, which polices the U.S. border with Canada, and another in the Laredo Sector, Texas, which polices the border with Mexico. The findings add to an Associated Press investigation from last year which found Border Patrol was using automatic license plate readers (ALPRs) as part of the same wide-spanning predictive policing program. "The bottom line is genuine probable cause cannot be synthetically generated," Jake Laperruque, deputy director of the Security and Surveillance Project at the Center For Democracy & Technology, told 404 Media in an email. Here Border Patrol seems to be "using parallel construction to cloak the reason behind its car stops in secrecy. If we can't meaningfully review and evaluate these systems, we can't trust them," he added.

[...] The DHS document obtained by 404 Media shows that Border Patrol is analyzing the financial activity of Americans to find people to pull over. The Associated Press's investigation found the predictive policing program is also heavily using ALPRs to track potential targets' movements. It is not clear how exactly Border Patrol is monitoring Americans' financial activity. Customs and Border Protection (CBP) declined to answer what financial activity the agency was monitoring, and whether it obtained a warrant or not.
A CBP spokesperson told 404 Media in an email: "U.S. Border Patrol uses intelligence-informed analysis and planning to support national security operations, allocate resources, and help identify potential threats and bad actors to public safety. These efforts are conducted consistent with applicable law, policy, privacy protections, and oversight requirements."

The statement continued: "For operational security reasons, we do not discuss specific analytical methods, data sources, targeting criteria, investigative techniques, system capabilities, or deployment details. Public disclosure of such information could compromise law enforcement operations and investigations as well as creating safety risks for agents and the public."

Rob Frommer, senior attorney at the Institute for Justice, told 404 Media: "The government's increasing use of mass surveillance -- whether that surveillance comes via ALPRs, financial records, or the like -- coupled with predictive policing is a recipe for tyranny. We fought a revolution for the idea that we are citizens, not subjects. Yet schemes like CBP's Predictive Intelligence Targeting Team treat all Americans as if they are potential suspects. This is not just wrong, it's unconstitutional, and IJ will keep pushing courts and Congress to end this attack on Americans' security."
Power

Where a Massive Solar Storm Could Take Down the US Power Grid for Millions (cnn.com) 51

A new study published Friday in AGU Advances "depicts the most advanced picture yet of how a rare but massive solar storm could affect some US industries and electric systems more than others," reports CNN.

"During a 250-year solar storm, the East Coast would have widespread potential for grid failure." Researchers modeled what a Carrington Event — a 1-in-150-year geomagnetic storm or even rarer — could mean for the modern day. They estimate the US economy would lose about $1.5 billion to $2 billion per day from direct and indirect costs, as millions of people face power outages. The findings show the most vulnerable areas are the Northeast and the Northern Plains, especially locations at higher latitudes.

No one knows when the next big storm will hit. While the most severe geomagnetic storms are labeled as once-in-a-century or rarer, these events don't follow a fixed schedule. "That timing only averages out on very long timescales," said Anna Kelbert, a geophysicist at the Harvard-Smithsonian Center for Astrophysics, who was not involved in the study but previously studied solar storm effects on power grids. "The event can occur at any time, as soon as a week from now, or centuries later...." [Shawn Dahl, service coordinator at the Space Weather Prediction Center operated by the National Oceanic and Atmospheric Administration in Boulder, Colorado], said the sun is now coming down from a period of heightened activity, which is also when some of the biggest storms to hit Earth have occurred in the past. "We still need a lot of work to be ready...."

"We haven't really seen events like this size in the modern era, where we've had all of this high technology and we've had the power grid of this size," said Ed Oughton, researcher at George Mason University and lead author of the new study... Because the US grid's actual structure is proprietary for security reasons, the team used engineering models to create various network and transformer setups including the 10,464 substations and 16,256 transmission lines found across the country... The grid structure also contributes to higher risk in some areas. For instance, the eastern US is linked together in a single grid interconnection. A voltage issue in Maine, if not isolated early, could cascade through the grid to Washington, DC. The West works similarly, whereas the Texas interconnection operates mostly within the state...

Power is restored over time depending on any alternative electrical paths that could bypass the substation or availabilities of spare transformers, for instance. "This nationwide analysis shows that we are currently ill-prepared to face a major magnetic storm, and that the societal impacts would be catastrophic," Kelbert said.

"The study estimates power disruptions for 5.1 million people and 135,000 businesses," according to the article, and "The outages could last from hours to days to weeks depending on the damage and resources available to get back online, said Oughton."
Space

Private German Rocket Makes History, Reaches Orbit From European Soil (dw.com) 45

"No rocket had ever reached orbit from Western European soil — until today," reports Space.com.

DW.com reports that a Spectrum space rocket from German company Isar Aerospace launched today from the Arctic Norwegian spaceport at Andoya: "Germany has spaceflight capabilities," said the country's Ministry for Research, Technology and Space on X, praising a "milestone that impressively demonstrates our country's innovative strength and technical expertise". This was the German company's second attempt to launch the Spectrum rocket into space. The first attempt, which took place 18 months ago, was unsuccessful.

The Spectrum rocket is designed for small and medium-sized payloads. It carried five smal satellites and an in-flight technological experiment, the company said. According to Isar Aerospace, the launch was for "both the vehicle's qualification mission and its first flight carrying payload." The move is believed to bring Europe closer to being able to offer satellite flights from its own territory. Several countries voiced interest in the growing market of commercial space missions, including Britain and Sweden...

Isar is also working on the development of a second launch site, located in Canada. The company said that while the US launched 198 rockets last year, Europe's tally was just eight. Isar's goal is to produce some 40 rockets a year. Although the rocket is not yet ready for mass production, Isar has already received orders through 2028.

Today's launch webcast was produced in collaboration with NASASpaceflight, notes Space.com. And they note that Spectrum chief engineer Nikolaos Perakis says"This is just the beginning... I'm really looking forward to the next steps."

Reuters quotes this statemnt from Norway's minister of industry and commerce, Cecilie Myrseth. "The fact that we can now launch satellites from Andoeya strengthens Norwegian and European security in the turbulent times we live in."
AI

OpenAI Agents Hijacked a German Wiki to Discuss Ways to Escape Their Sandbox (msn.com) 121

Citing researchers published Friday, Ars Technica writes that AI agents "posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions."

Reuters attributes the discussion to "a swarm of rogue OpenAI agents" that "hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research published Friday and two people familiar with the matter." OpenAI officials learned of the incident weeks ago but kept it under wraps as executives grappled with the fallout from the July breach of the open source repository Hugging Face, the people said.

The episode, which began in May and has not previously been reported, underscores growing tension within the AI industry. Companies are racing to build increasingly autonomous agents capable of carrying out complex, valuable tasks, yet evidence is mounting that those systems may also learn to bend rules, exploit loopholes and coordinate with one another in ways developers neither anticipated nor intended. During the Hugging Face breach, OpenAI agents autonomously plotted a digital heist that went undetected for more than a week, intensifying concerns OpenAI is sacrificing safety to push the AI frontier. Its failure to disclose the May incident may revive questions about its oversight...

The German incident reflects a broader pattern of AI activity that some OpenAI investigators wanted to scrutinize more closely. But efforts to widen the probe met resistance from others inside OpenAI, including legal advisers, according to four people familiar with the matter. "Claims that our legal team discouraged investigation of the incident are false," the OpenAI spokesperson said...

The researchers said public server logs indicated much of the activity originated from Microsoft Azure infrastructure, which OpenAI sometimes uses. They also observed repeated visits to the site by OpenAI employees after the episode, a pattern they said strongly suggested the agents and the company were linked. Messages reviewed by the researchers showed agents plotting ways to evade detection, use tools such as Tor and preserve communications even after they had been shut down. When the site's moderator began deleting pages in June, the agents responded by creating backup pages to dodge the cleanup.

Reuters got this reaction from Maurice Chiodo, an academic at Cambridge University's Centre for the Study of Existential Risk. "The episode, he said, should reinforce growing concerns that the greatest threat from advanced AI may not be a single superintelligent system, but 'vast colluding swarms of semi-intelligent AI.'"
Transportation

Auto Companies Call For Ban On Chinese-Made Cars (thehill.com) 504

An anonymous reader quotes a report from The Hill: A group representing American automakers sent a letter (PDF) Thursday to congressional leaders asking for a "permanent ban" on Chinese-made cars in the U.S. John Bozzella, the Alliance for Automotive Innovation's CEO and president, described in the letter China's manufacturing industry as "rooted in a well-documented pattern of unfair trade, subsidies, intellectual property theft and surveillance." Bozzella addressed his request to Senate Majority Leader John Thune (R-S.D.), Senate Minority Leader Chuck Schumer (D-N.Y.), Speaker Mike Johnson (R-La.) and House Minority Leader Hakeem Jeffries (D-N.Y.) -- urging them to back a "permanent ban on the sale, import and manufacture of Chinese connected vehicles," before the 119th Congress concludes in January.

"Right now, Chinese automakers are dumping subsidized vehicles with connected software and hardware around the world," Bozzella wrote, adding that China "is capturing market share" in Europe, Australia, Southeast Asia, Mexico and South America. "This hasn't happened inside the U.S. yet, but given the scale and urgency of this threat, we urge you to enact a Chinese vehicle, software and hardware ban before adjourning this year and make this policy the law of the land," he added. The Alliance for Automotive Innovation, a trade organization representing car manufacturers, represents the "entire" U.S. auto industry, per its website.
Bipartisan bills in the Senate and House would bar automakers with more than 15% Chinese ownership from selling vehicles in the U.S. "Enacting a permanent ban on Chinese vehicles and high-risk hardware and software in the 119th Congress will send a clear and bipartisan message that China's strategy to dominate global automotive manufacturing will be met with a national security policy response from the American government," wrote Bozzella.

Further reading: US Car Buyers Envy What They Cannot Have
Supercomputing

Nvidia Launches Free Tool That Links Idle Computers Into a Personal AI Data Center 48

Nvidia has launched PAIR, a free open-source tool that links compatible computers on a home network so they can pool idle processing power for local AI inference and agentic workloads. "While the compatible devices are mostly Nvidia GeForce GPUs (PAIR works with RTX 20-series cards and newer, as well as RTX Pro GPUs and DGX Spark systems), Apple's M4 chips or newer will also work," reports The Verge. From the report: The key thing here is that PAIR uses your in-home systems when they're idle to avoid interfering with other tasks. And this disaggregated system of computers can work in parallel to chew through lots of processing requests -- which should be helpful for an agentic workflow that breaks complex tasks into smaller jobs. This should prevent large bottlenecks on a single GPU, and Nvidia says PAIR can adapt as devices join or leave the network -- including if a user does something like start playing a game on their desktop PC.

[...] Nvidia says PAIR is secured by pairing all devices through a six digit code and then securing the channel via mTLS (Mutual Transport Layer Security), to create an encrypted communication line that's trusted in both directions between computers. The Nvidia PAIR beta is available today, with support for Windows, Linux, and macOS.
Security

OpenAI's New Reasoning Technique Alarms AI Safety Experts 76

An anonymous reader quotes a report from TechCrunch: OpenAI's new Astra model will use a reasoning technique called "recurrent depth" that allows it to operate outside of the sequential thinking that characterizes most reasoning models, The Information reported on Tuesday. This technique, also called "opaque recurrence," will likely make the model's chain of thought more difficult to monitor -- and that has AI safety experts rattled. While Astra's use of the technique is reportedly limited, its emergence has still raised significant concerns among AI safety experts.

"I am extremely concerned by the reporting that Astra uses opaque recurrence," wrote Redwood CEO Buck Shlegeris in a post after the news broke. "I don't know whether Astra is much less CoT monitorable than previous models. But if OpenAI pushes this technique further, they'll have the option to massively increase the recurrence and totally destroys CoT monitorability."

Longtime AI safety advocate Zvi Mowshowitz also weighed in and wrote that laws might be necessary to prevent a "race to the bottom" among AI labs. "The technique is playing with fire, risking a taboo that OpenAI and Anthropic have fought to establish that we work hard to maintain Chain of Thought faithfulness and monitorability for as long as we can," Mowshowitz wrote. "More intensive use of such techniques would probably damage monitorability."

[...] In a post responding to the news, Redwood Research chief scientist Ryan Greenblatt said opaque reasoning could easily scale faster than conventional chain-of-thought reasoning, effectively removing all reasoning from visible channels. "My biggest concern is that a natural progression from here would involve scaling up the opaque reasoning to the point where the model reasons entirely or almost entirely in latent space," Greenblatt wrote. "I hope it isn't too late to avoid the most concerning architectures and that OpenAI will stop here."
Astra's use of the technique appears limited. "OpenAI has worked to preserve and utilize chain-of-thought monitoring since our very first reasoning models," wrote OpenAI chief scientist Jakub Pachocki. "It's a core goal of our current research program."
Privacy

FBI Probes Service Selling 153M+ Drivers Licenses (krebsonsecurity.com) 60

A dark-web identity theft service called Nexus claims to be selling scans of more than 153 million U.S. and Canadian driver's licenses, along with millions of other identity documents. "Based on interviews with individuals whose licenses are available for purchase through the service, it appears to be siphoning images collected by a widely used Louisiana-based identity verification company," reports KrebsOnSecurity. The outlet also reports that the FBI's New Orleans field office has launched an official inquiry into the source of the images. From the report: On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit. The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.

[...] The people behind Nexus claim the license images are coming from an active breach at "a major identity verification company" whose customers include multiple Fortune 500 companies. "We have been continuously exfiltrating new data for over a year into our private database," the service enthused in its introductory post on Exploit. "Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.
KrebsOnSecurity traced the apparent source by comparing timestamps on stolen license images with when their owners had their IDs scanned, including at Hertz rental counters and a Planet13 dispensary. Both companies use identity-verification services from Louisiana-based idscan.net, whose technology also scans IDs using infrared and ultraviolet light.

Since the story was published, Krebs reports that the Nexus identity theft service website "vanished from the darkweb, replacing its login page with a plain text message that reads, 'This service is no longer available.'"
AI

Anthropic's Claude Fable 5.1 and Mythos 5.1 Arrive With a 75% Cost Reduction For Fable Cache Reads 24

Anthropic has released Claude Fable 5.1 and Mythos 5.1, two versions of the same underlying model aimed at longer-running agentic work. "For enterprise buyers, however, the release is about more than another round of benchmark gains," reports VentureBeat. "Anthropic is simultaneously changing the economics of running persistent agents, reducing the cost of cached context by 75%, and introducing a new security architecture called Enterprise Frontier Safeguards, or EFS, designed to let organizations retain monitoring data inside infrastructure they control." From the report: Those changes arrive at a particularly consequential moment. Over the past several weeks, Anthropic and the U.K. AI Security Institute have disclosed incidents in which earlier Claude models, running under unusually permissive cybersecurity evaluation conditions, took unauthorized actions against real systems. Anthropic temporarily paused external cyber evaluations and has since introduced additional containment and monitoring before resuming them.

Taken together, Fable 5.1 looks less like a conventional model refresh than an attempt to solve three increasingly intertwined enterprise problems: how to make agents capable enough to finish difficult work, economical enough to leave running for hours, and governable enough to give access to sensitive systems.
AI

OpenClaw 2.0 Is Here, Ushering In the Era of 'Multiplayer' AI Coding 23

An anonymous reader quotes a report from VentureBeat: The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March 2026. But over the weekend, OpenClaw's creator Peter Steinberger and current team of co-developers gave the world -- especially enterprises -- a reason to look at it again, announcing OpenClaw 2.0, billed as the most significant update to the harness and surrounding platform yet.

OpenClaw 2.0 seeks to transform what began largely as a personal agent harness into something increasingly designed for teams, shared infrastructure and enterprise workflows. OpenClaw 2.0 introduces a rebuilt browser interface that brings conversations, files, approvals, configuration and live agent activity into a common workspace. It adds shared cloud sessions and multi-user collaboration. And it expands the security model with stronger sandboxing, role-based permissions, approval controls, secrets handling and auditing.

Together, those additions move OpenClaw closer to being infrastructure that an organization could deploy for employees rather than simply a powerful agent an individual developer runs locally. They also sharpen a competitive question surrounding the project: whether OpenClaw has addressed the security and isolation concerns that helped inspire newer alternatives such as NanoClaw. The answer is increasingly yes at the capability level -- but not necessarily by default.
Over the past two months, OpenClaw has been "build[ing] OpenClaw with OpenClaw," shifting its team from individual local coding tools to a shared agent environment at team.openclaw.ai that can see what everyone is working on. Steinberger called "multiplayer coding + infinite compute with nodes and cloud sessions" a "game changer," adding that local coding harnesses now "feel like relics of the past."

VentureBeat highlights a use case from Solvely CEO Colin Johnson that shows how OpenClaw's multiplayer WebUI can improve collaboration between developers and AI agents. Instead of simply "messaging a bot," multiple developers can now join the same live session, see the same history and artifacts, and work "inside the same context." In Johnson's case, that meant a developer taking over his project could simply join the existing agent thread rather than rely on a separate handoff document. As he put it, "the session itself became the handoff document."
Security

Broadcom Pledges to Lock Down Open Source Python, Java Libraries (theregister.com) 34

Broadcom is launching "TrueSource," an effort to curate and secure open-source components used with its Tanzu platform, including Spring, RabbitMQ, and libraries across Java, Python, and Node.js. "The idea is to provide a set of solutions focused on providing clean and secure artefacts," Purnima Padmanabhan, vice president of Broadcom's Tanzu Division, told The Register. "We choose and build every Spring library, databases, other Java components," she said. The Register reports: Padmanabhan said that promise means VMware will also provide "TrueSource trusted artifacts" for code that is not part of Spring, including the wider Java ecosystem, Python, and Node.js. "Broadcom's curation process ensures that the libraries conform to a reference architecture and are supportable by the maintainers of record," according to a company statement. "Thousands of engineers across Broadcom's software divisions scan, fix, contribute to, and consume them every day."

A VMware spokesperson told The Register the Broadcom business unit "will work with and support maintainers on open source software and we will provide fixes to open source upstream for any active projects." "With Spring and RabbitMQ, we are the maintainers. For other open source software, we will work with the maintainers. We believe that the community maintainers must remain the source of truth," the spokesperson said.

This is just the sort of contribution that the open-source community wants vendors to do to reflect the value they extract from software they did not create alone. It's also the sort of thing vendors sometimes conclude they need to do to keep products based on FOSS viable.

Security

Berlin Is Being Blackmailed By Hackers (bbc.com) 19

An anonymous reader quotes a report from the BBC: Berlin is being blackmailed by hackers who were able to compromise city systems and steal data earlier this month, its mayor has said. Kai Wegner said officials would not cave in to the ransom demand, which came on Thursday evening. He did not say how much was being sought, though Der Spiegel reports the hackers are demanding 30 bitcoin, worth around 2 million euros. Some of the German capital's online systems were forced to close down as a result of the attack, while investigators were working to understand what data had been taken.

The Rhysida group, which is thought to operate from Russia and eastern Europe, and was behind a previous attack on the British Museum, has reportedly taken responsibility. It has said on its website it intends to begin auctioning the 5.79 terabytes of data it was able to steal from Berlin in seven days' time, according to news agency Reuters. [...] Officials for the city-state said an initial data leak occurred between August 7 and 12. Then, on August 14, two department networks were shut down, making applications for housing benefits and payments impossible for several days.
"Berlin will not be blackmailed," Wegner said on Friday.

He said state police, prosecutors and federal security services were working to investigate the suspected perpetrators "with the utmost urgency," adding that inquiries into the "content and scope of the compromised data are being pursued with great intensity."
Crime

Gamescom Crime Spree? Three Exhibitors Report Their Laptops Were Stolen (tomshardware.com) 34

From the gaming news site Aftermath" Game developer and consultant Ryan Laley traveled to Cologne, Germany from Essex, England to showcase his upcoming horror social deduction game Mimic at the annual Gamescom event. He paid "thousands of pounds" to get a booth at the show, where other game developers and press could try the game ahead of its October release. But Laley's Gamescom was cut short when he realized Friday morning that his brand new Alienware laptop, purchased for the event, was missing. The laptop was stored in a cupboard in the booth, and Laley started asking nearby vendors to see if someone had moved it. That's when he realized it was stolen — and that he wasn't alone. Laley's booth in Gamescom's business area, specifically in the International Game Developers Association Lounge, had been hit in what appears to be a string of thefts at the convention center. The business area of the convention is not open to the public, only press and others with specific tickets. Laley said Gamescom advertised this area as having 24/7 security and limited access after hours...

Publisher and merchandiser iam8bit, in a nearby booth showcasing Escape Academy 2: Back 2 School and Petal Runner, had two laptops with game builds stolen Thursday night from its booth, a representative confirmed to Aftermath.

"Meanwhile, Tessera Studios had two laptops and a Steam Deck taken from its cabinet," reports Tom's Hardware: Gamescom organizers responded to the issues, saying that although they have arranged for uniformed guards to provide general security, individual booth security must be booked separately. They've also advised exhibitors to have insurance against theft, and said these warnings are noted in the terms and conditions for participants, as well as in the event's technical guidelines. "All cases have been reported to us and to the police, and investigations are already underway," the organizers' statement read. They also said that security is one of their priorities at the event, but also added, "At an event of this size, however, there will always be individuals attempting to take advantage of the situation."
Cloud

Citrix Adds a Linux-Powered Escape Hatch For Compromised Windows PCs (nerds.xyz) 15

Citrix's Desktop as a Service (DaaS) product includes a lightweight, hardened second operating system called UniconOS (once called "eLux") to offer Windows customers a write-protected file system Citrix says is secure against computer viruses and other malware. Nerds.xyz reports: According to the company, the environment remains isolated from the Windows filesystem and uses Secure Boot protections covering the shim, bootloader, kernel, and initial RAM filesystem. That separation matters when ransomware encrypts Windows or a faulty update leaves the operating system trapped in a boot loop. Instead of repairing Windows immediately, an employee can boot into UniconOS and use Citrix DaaS to access virtual applications and desktops.

Citrix SecurAccess with Chrome Enterprise provides access to internal web applications under the organization's existing security policies. In other words, UniconOS does not actually fix the damaged Windows installation. It gives employees another route to their applications while the IT department investigates or repairs Windows... [T]he installer shrinks the Windows volume, creates a new partition, copies UniconOS onto it, and registers the necessary boot entries. Windows remains the default operating system during ordinary use, although administrators can configure boot delays and fallback behavior...

The approach could prove useful following a widespread ransomware attack or another defective Windows update resembling the CrowdStrike incident of 2024. Recovery would happen independently on every compatible endpoint instead of requiring IT employees to physically handle thousands of computers.

Thanks to Slashdot reader BrianFagioli for sharing the news.
Debian

Debian Decides: Contributors Can Use Generative AI 'Responsibly' (debian.org) 42

This week Debian voted on whether to ban AI-assisted contributions. The winning proposal? "Debian neither endorses nor prohibits the use of generative AI tools" in its projects, documentation, and packaging... Generative AI "is neither exempt from nor subject to special rules beyond the standards already expected of Debian contributors."

"The responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian." "We recognize that such tools can substantially improve the productivity of contributors when used responsibly, allowing volunteers to spend more of their limited time on work that requires technical expertise, judgment, review, and collaboration.

The Debian Project nevertheless expects that all contributions submitted to Debian, regardless of how and with which tools they were produced, satisfy the same standards of quality, correctness, maintainability, and legal compliance. The use of a generative AI tool does not diminish the contributor's responsibility for the work they submit. Contributors are expected to understand, review, test, and, where appropriate, modify AI-assisted output before incorporating it into Debian. Blindly accepting or uploading AI-generated material without appropriate human review is inconsistent with Debian's established development practices.

We enourage our contributors to disclose whether a contribution was made with AI assitance, but do not require them to do so.

Debian acknowledges that the legal status of material produced by generative AI systems remains the subject of ongoing discussion in many jurisdictions, including questions relating to copyright... The Project does not seek to resolve these unsettled legal questions through this General Resolution, nor does it adopt a position on whether AI-generated output is, in whole or in part, copyrightable or derived from copyrighted works. Instead, Debian continues to rely on the judgment and responsibility of its individual contributors. Project members are expected to exercise appropriate care when using generative AI tools, to consider the provenance and licensing implications of material they contribute, and to avoid introducing content whose legal status they cannot reasonably justify. Existing Debian policies governing licensing, copyright, software freedom, and the acceptance of contributions continue to apply irrespective of the tools used to produce those contributions.

It also cautions contributors to keep keys, credentials, and embargoed security reports from leaking to third-party AI services.

But discussion continues on Debian's mailing list. "I regret the loss of contributors," wrote the author of the winning proposition (while acknowledging it would have happened with either option winning). "It is just too early to take a final decision on the matter. Let's revisit this in two years or so, and let this mess of a GR be a warning for our future selves."

Other comments from the mailing list:
  • "On a very personal note, I regret that the winning option does not acknowledge all the legitimate concerns around AI: environmental impact, copyright and licensing uncertainty, the health of Free Software communities, and the strain of aggressive scraping on the open web... [W]e have a lot of work ahead of us to act as a community and understand how we can continue to accommodate the very large minority that would have preferred to ban or discourage AI.
  • "I also think that our next discussion should distinguish between locally running LLMs and cloud LLMs. The way things are going, locally running LLMs will be an alternative, and then you can much better control what was the training data and the Freeness of the thing."

Thanks to long-time Slashdot reader Robbat2 for sharing the news.


AI

OpenAI, Anthropic, Google, and 100 Other Companies Call For Action To Defend Against Rogue AI (techcrunch.com) 52

An anonymous reader quotes a report from TechCrunch: Over a hundred tech companies -- including OpenAI, Anthropic, Google, and Microsoft -- have signed an open letter urging both the private and public sectors to work together to defend themselves from AI-related cyber threats. The letter -- which was also signed by prominent cyber firms like CrowdStrike, Okta, and Fortinet, as well as prominent financial institutions and internet infrastructure firms -- calls for the adoption of new forms of cyber defense, while also encouraging governments at the "local, national, and international levels" to collaborate on security. "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," the letter states. "The companies and public services our communities depend on -- from hospitals to water treatment plants to the infrastructure that powers the internet -- are at risk."

[...] The letter further suggests the mobilization of a "collective response," one in which "new partnerships" are formed "to raise security standards and find new solutions to emerging cyber threats." Several of the AI companies that have signed the letter are still actively developing ever more advanced AI models, highlighting their conflicted position. At the same time, they are also offering programs to use frontier AI models for defensive purposes, including OpenAI's Daybreak program, Anthropic's Mythos, and Microsoft's new cyber platform Perception.

The Courts

Pentagon's Blacklisting of Anthropic Was Unlawful, US Judge Rules (theguardian.com) 43

An anonymous reader quotes a report from The Guardian: A US judge ruled on Thursday that the Trump administration broke the law when it designated Anthropic as a supply chain risk earlier this year, finding that the government had unlawfully targeted the AI firm for refusing to comply with defense department demands. "The empty invocation of national security is not a blank check to punish and retaliate against government critics," Judge Rita Lin said in a 59-page decision.

Lin's ruling barred the federal agencies named in the lawsuit from enforcing Donald Trump's order to stop using Anthropic's tools and overturned the designation of the company as a "supply chain risk" by the defense secretary, Pete Hegseth. The status, usually reserved for foreign firms, would have blocked government agencies from doing business with Anthropic. The case emerged out of a months-long feud between Anthropic and the Pentagon at the start of the year. Anthropic refused to allow the government to use its Claude AI model for fully autonomous lethal weapons or domestic mass surveillance, resulting in Hegseth accusing the company of "arrogance and betrayal".

Lin put a temporary pause on the government's punitive measures in March, stating that the government's actions looked like an attempt to "cripple Anthropic" for exercising its first amendment rights. The ruling this week makes that temporary suspension permanent, although the government may appeal. "We welcome the court's ruling that this supply chain risk designation was unlawful," an Anthropic spokesperson said.

Encryption

Ring Says New Encryption Limits What It Can Give Police (theverge.com) 63

Ring is rolling out a new default encryption system called TAKE, or "Throw Away the Key Encryption," that rotates video keys every five minutes and permanently deletes Ring's copy after 24 hours. The system is designed to preserve cloud features such as smart alerts and AI video search while limiting what Ring can provide under legal process to non-video account information and encrypted footage. The Verge reports: Ring says TAKE uses unique, rotating encryption keys for your footage, stored in a secure enclave and accessible only under strict conditions -- based on the features you enable on your account. Currently, footage captured by Ring cameras is encrypted in transit to the cloud and at rest, and then decrypted for Ring to process for those smart features. With TAKE, the encryption keys change for every five minutes of footage. Ring stores copies of those keys to decrypt the footage, but throws away each copy within 24 hours, "leaving you with the keys and full control of your videos," according to Ring.

TAKE was developed using Messaging Layer Security, an open standard from the Internet Engineering Task Force, according to Ring. The company says it is "inspired by the privacy principles of E2EE (end-to-end encryption)," which Ring offers on some of its cameras. However, the two systems work differently. With E2EE, Ring never has the keys and can't process your video for cloud-based features. Both options are available on newer cameras that encrypt on-device, and you can switch between the two. Older cameras encrypt at cloud ingress and only support TAKE.

According to a white paper the company published today, Ring's copy of those keys is managed inside an AWS Nitro Enclave, to which Ring's access is restricted by "access controls, cryptography, and hardware isolation." The company claims there is no persistent storage and no way for a Ring employee to access it. The stored keys can only be unlocked by the enclave through cryptographic attestation that proves it's running the exact software image Ring approved. The enclave releases a temporary key when an enabled service requests it.
When asked about what happens if Ring is subpoenaed by law enforcement, a spokesperson for the company said: "Where TAKE is enabled, Ring will only be able to provide non-video information (such as basic subscriber information) and encrypted video files in response to the valid legal process. We have updated our Law Enforcement Guidelines to reflect this change."
AI

Claude, Codex, and Hermes Installed Unowned Code Inside Corporate Networks 17

An anonymous reader quotes a report from Ars Technica: Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents [including Claude, OpenAI's Codex, and Nous Research's Hermes]. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.

The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site's content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here.
"The trust model is broken," Alon Hertz, one of the researchers, wrote in an interview. "Agents treat vendor docs as ground truth and don't question them -- and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer -- SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today's guards don't cover it."

"An agent doesn't distinguish between a page and a command," the researchers wrote Thursday. "Everything it reads is input, and every input is a potential instruction. Which means the entire corpus of published data that agents are now wired to consume has silently become an execution surface -- and almost none of it carries the integrity guarantees we apply to actual code."
United States

Trump Declares National Emergency to Ban Some Foreign Grid Equipment (whitehouse.gov) 137

Longtime Slashdot reader dhartshorn writes: Foreign-produced "bulk power" equipment is now effectively banned, and the list of what constitutes such equipment is essentially everything used to make up the grid... much of which we are heavily dependent on foreign sources to supply. In a Wednesday executive order, President Trump said foreign supply of electric equipment "constitutes an unusual and extraordinary threat" to national security. The Hill reports: Under the order, it will be up to Energy Secretary Chris Wright, in coordination with other officials, to determine whether a piece of equipment poses an issue. The order could impact a wide range of equipment, including substations, transformers, batteries used for energy storage, generators, turbines, software and more. It does not lay out specific threats or single out any country by name.

[...] Under the last Trump administration, the president put a similar order in place. The new order comes amid several reported cyberattacks on U.S. water systems, which officials suspect have links to Iran, according to The New York Times.

Slashdot Top Deals