Alterslash

the unofficial Slashdot digest
 

Contents

  1. DoorDash Is Building Its Own Drone Delivery Business
  2. Russia Charges Telegram Founder Durov With Facilitating Terrorism
  3. OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
  4. More Than 30 Minnesota Water Systems Targeted In Cyberattack
  5. Your Brain Can Rewire Itself To Allow True Multitasking
  6. Trump Administration Bans New Chinese Humanoid Robots
  7. Workplaces Look For Cheaper AI As ‘Tokenmaxxing’ Fades As a Corporate Fad
  8. Apple Retires iPhone Upgrade Program For Klarna-Backed Leases
  9. AI-Found Bugs Aren’t Proving Any Easier to Exploit Despite the Hype
  10. eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019
  11. Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms
  12. Judge Blocks First State Law That Would Have Banned Prediction Markets
  13. DEF CON Bans Meta-Style ‘Pervert Glasses’
  14. GrapheneOS Defends Data-Wiping Function That Blocked US Border Search
  15. Review Roundup: Framework Laptop 13 Pro

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

DoorDash Is Building Its Own Drone Delivery Business

Posted by BeauHD View on SlashDot Skip
DoorDash has launched DoorDash Air, an in-house drone-delivery program that has just received FAA certification for commercial operations. “This does not mean DoorDash’s custom-built drones will be delivering burritos tomorrow, or even next month,” notes TechCrunch. “The company didn’t provide a detailed timeline for when its aircraft would be used in operations.” From the report:
[I]t will likely begin with limited pilot programs in which the unmanned aircraft will travel short distances while remaining within the line of sight of the operator. If DoorDash wants its drones to fly autonomously over longer distances, it will need the FAA to approve its Beyond Visual Line of Sight technology, a certification that companies like Amazon, Wing, and Zipline have received in recent years.

Despite the new program, the food and grocery delivery company is maintaining its existing partnerships with Wing and Flytrex. DoorDash partnered with Alphabet’s Wing in 2022 for a drone delivery program in Australia, and later expanded the partnership to a couple of U.S. cities, including Dallas-Fort Worth, in 2024.

Russia Charges Telegram Founder Durov With Facilitating Terrorism

Posted by BeauHD View on SlashDot Skip
Russia has charged Telegram founder Pavel Durov with facilitating terrorism, alleging the platform was used by Ukrainian intelligence “to prepare and co-ordinate acts of sabotage and terror” inside Russia. An international arrest warrant has been issued for Durov, who currently lives in Dubai, United Arab Emirates, where Telegram keeps its main office. The BBC reports:
Shortly after the charge was announced, Telegram’s account on X posted an image showing Durov holding up his middle finger. He has previously accused Russian authorities of “fabricating new pretexts to restrict Russians’ access to Telegram.”

[…] Multi-billionaire Durov, 41, has lived outside of Russia for many years and holds French and United Arab Emirates (UAE) passports. It is unclear whether other countries or authorities would comply with an arrest warrant issued by Russia.

Durov left Russia in 2014 after refusing to comply with government demands to shut down opposition communities on the platform. He had previously founded popular Russian social media company VKontakte - dubbed the “Facebook of Russia.”
In 2024, Durov was arrested and investigated by the French government in connection with criminal activity on the platform and a lack of cooperation with law enforcement. “He was allowed to go home months later, with the investigation continuing,” notes the BBC.

Re:So it’s purely symbolic?

By drinkypoo • Score: 5, Informative Thread

Unless a State in which he resides in agrees to extradite him for the charges (which… let’s assume he’s smart enough to avoid States friendly with Russia), then this is about as grandstanding as the term gets.

Russia has assassinated former Russian citizens outside of Russia before, it would be unsurprising if they did it again.

Arrest ?

By bugs2squash • Score: 3 Thread
They won’t arrest him.

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from Wired:
OpenAI said Tuesday that the rogue AI agent that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack. It’s now clear that the unprecedented security incident, which arose during an internal test of OpenAI’s latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that “four accounts” tied to “publicly available services” were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.

OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at “the level of severity or scale of what we’ve shared related to Hugging Face.” One of the additional accounts compromised by OpenAI’s agent was used as an “outbound relay and staging path,” potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI’s rogue agent also used another account for data storage to assist with the hack.

Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI’s agent. In a statement to WIRED, Modal’s chief technology officer Akshat Bubna confirmed that OpenAI’s agent exploited a vulnerability in one of its customer’s codebases, which was running on Modal’s infrastructure. However, Bubna says, “Modal’s platform was not compromised in any way.” The identity of the customer could not be determined.

FBI should be visiting.

By Fly Swatter • Score: 3 Thread
Sounds like a threat actor. How do you put an AI in jail? because OpenAI apparently can’t even sandbox.

Why does the model have all those “skills” ?

By Troy Roberts • Score: 3 Thread

Why does the model have all those “skills” needed to hack other sites? I mean you have to allow the model open internet access and at least the ability to GET/POST/PUT. I feel this is some of the same kind of thinking that gets someone’s repo deleted, because they gave an agent too much access and no good way to monitor what is going on.

More Than 30 Minnesota Water Systems Targeted In Cyberattack

Posted by BeauHD View on SlashDot Skip
jrnvk shares a report from KMSP:
Minnesota IT Services reports that a “coordinated cyberattack” targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.

On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.

State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota’s critical infrastructure.

Blame Canada

By RobinH • Score: 5, Funny Thread
It must be the preliminary moves in a surprise strike by our mortal forever enemy, Canada. “Oceania had always been at war with Eastasia.” - 1984

Re:attack

By Smidge204 • Score: 5, Informative Thread

From another source it sounds like the plant’s SCADA system was compromised and shut down/disabled, causing some plants to go offline.

The immediate consequence is they would lose remote control over the pumps, fans, and valves at these facilities and either default to some safe state or just shut down entirely. Someone would have to drive over and manually reset/control everything, which is exactly what they did. Addressed promptly enough most people would even notice something was wrong.

The long term consequences could be that they end up getting incorrect status information about the facility’s operation, causing a longer disruption until complaints start coming in and they have to run around trying to figure out what’s wrong. Loss of water pressure, distribution of untreated water, distribution of over treated water, depletion of reserves are all obvious problems a bad enough attack could cause. Physical damage to equipment is also not impossible, which would be the worst case scenario.... you’re not fixing a broken well/system pump or AOP reactor in two or three hours, and it you lose a bunch of them at once you could be at reduced capacity for months.
=Smidge=

Good!

By SlashbotAgent • Score: 3 Thread

They fucking deserve everything they get. We have had more than enough close calls and incidents to clearly demonstrate to every drooling moron that critical infrastructure like water and electricity systems should never be connected to the internet. There’s no reason for them to to need it.

No fucking access in or out. Fucking duh!

Air gap that shit or get the intrusion that you deserve. My private infrastructure has computer monitoring and automation. But, none of it can exchange a single packet with the internet. There’s no reason that a state government with dedicated IT departments shouldn’t know and do the same.

Wrong headline

By gweihir • Score: 3 Thread

A better one would be “More than 30 Minnesota water systems have IT security that completely sucks”.

Seriously, without liability (including personal one) and strict qualification requirements, the total crap-show that IT security is today will continue. And not only for critical infrastructure.

Re:attack

By garcia • Score: 4, Interesting Thread

City Council member of a non-listed Twin Cities suburb I know:

FBI is involved. Most water systems use one of two control/alert systems that are old and make them easy targets.

All they did was shut down components of the systems e.g., wells/sewer lift stations. Most cities were able to cycle manually to get back up and running. There was not messages warning or ransom of which I am aware.

They could have done a lot more damage if they wanted to, rather than just shutting things down.

Your Brain Can Rewire Itself To Allow True Multitasking

Posted by BeauHD View on SlashDot Skip
alternative_right shares a report from ScienceAlert:
[I]n a new study published in the Journal of Cognitive Neuroscience, researchers from Georgetown University Medical Center in the U.S. have revealed that we can put certain tasks on autopilot in a way that enables something closer to true multitasking. Driving is the perfect example: When you take your test, your entire mental and physical energy is concentrated on executing the right combinations of movements and thoughts. After a decade behind the wheel, the brain is no longer consciously thinking everything through in great detail.

In the new study, the researchers found that after extensive practice, the brain can effectively reroute some tasks around the brain’s main computing center — like a bypass road around a city — to reduce mental overload and improve multitasking capability. “We have another stepping stone in our understanding of how the brain learns,” says neuroscientist Maximilian Riesenhuber, senior author of the study. “The encouraging part is that you really can learn to multitask. There is actually a way to remodel your brain architecture and use other parts of your brain.”

[…] “Previous studies have shown that parts of the temporal cortex can be activated by particular object categories in experienced observers — birds, cars, even Pokemon — but a limitation of all of those studies is that they only looked after people became experts,” says psychologist Patrick Cox, first author of the study. “We measure before and after training, so we can see that extensive training essentially put a category-selective area in the temporal lobe that was not there before.” The study culminated in a dual-task experiment, in which the participants were asked to identify cars and take on another challenge. The individuals whose brains had offloaded more car-sorting work to the temporal cortex did better at the second task.

It does it poorly

By nospam007 • Score: 5, Interesting Thread

“After a decade behind the wheel, the brain is no longer consciously thinking everything through in great detail. "

Indeed, and for some reason, signalling fell through the brain’s cracks.

Captain Obvious strikes again

By getuid() • Score: 5, Insightful Thread

When you do a sport, like tennis, boxing, or whtever else — what you’ve done in your training is teaching your stem brain to react and coordinate doszens of simultaneous tasks.

The thing is: it’s only the neocortex that can’t truly multitask.

Driving is a good example: you can do most of the tasks out of a well trained stem brain. The challenge is to not offload essential, complex decision-making tasks, requiring differentiate processing, and which therefore absolutely have to be on the neocortex — or else people die.

This is why I don’t like many driver assistance features: they draw away neocortex capacitiy, in other words: they’re needlessly distracting.

Some are useful though.

The same for music

By aglider • Score: 5, Interesting Thread

Realm musicians spend a lot of time in learning the notes on the score, so their body knows how to play that piece.

At that point, the mind can fully kick-in and add the interpretation layer while the body control runs in the background.

Drummers

By pr0t0 • Score: 5, Interesting Thread
Anyone who has every tried to learn the drums can tell you humans are capable of true multitasking. Limb independence seems like an impossible feat when you first start out. I think I read that John Bonham could play two different time signatures simultaneously. If true, I’m sure others can do it and it can be done on many other instruments, but to me that seems like a superhuman level of multitasking.

Re:It does it poorly

By dfghjk • Score: 5, Insightful Thread

“Driving is the perfect example”

Driving isn’t even “the perfect example”, walking is. How the brain works is better understood than presented here, to an embarrassing extent. We’ve known longer than any of us have been alive that the brain learns and no longer needs to be actively focused on skills in order to perform them. Anyone who plays a musical instrument is acutely aware of this.

Trump Administration Bans New Chinese Humanoid Robots

Posted by BeauHD View on SlashDot Skip
The Trump administration has banned newly authorized foreign-made humanoid and four-legged robots, along with power inverters, citing “unacceptable risks” to the country’s national security. FCC chairman Brendan Carr said the agency was doing its part “to secure America’s critical supply chains.” The BBC reports:
The FCC has added the items to its Covered List — a register of goods and services that are deemed a risk to US national security. The ban applies to new foreign-produced advanced robotic devices and power inverters and does not prevent the sale or import of any existing models that had been previously authorized by the FCC.

The FCC cited concerns that the use of foreign-made inverters could allow overseas firms to turn them off, steal data, facilitate remote access and surveillance by “foreign government actors, or be otherwise exploited through a cyberattack.” It added that the use of robots made outside the US could allow “malign actors to surveil Americans, enhance the capabilities of foreign intelligence services, or to remotely commandeer the robots.”

Enron Husk desperate to stop the stock freefall

By T34L • Score: 5, Funny Thread
Also, it’s a real shame it’s impossible to design a power inverter without any complex logic or arbitrary data links. I imagine they can’t flip those electrons back and forth without maintaining a lively chat with the mothership.

Please let in one last batch …

By Alain Williams • Score: 5, Insightful Thread

to replace Trump and his cronies. It would be very hard for them to do a worse job.

Re:Trump is RIGHT. Wake up, you Communists

By butt0nm4n • Score: 5, Interesting Thread

Are you real ? You sound fucking demented.

Try this in your pipe.

Americans are not free. Most are shackled to debt in hope of buying happiness, working jobs they don’t want to. They work longer hours, have less holidays and earn less than many countries in the western world. Many Americans are poorly educated, obese and unwell, they suffer a variety of addictions drugs, alcohol, food, social media. They have no public healthcare provision, disregard for the environment and their lifespan is reducing. Half of Americans hate the other half, because they are led by the most selfish, greedy and ruthless who are respected like peasants respect a king, the other half are trying to protect themselves from the other half. Americans have been engaged in some kind of war somewhere since their country’s formation and when not fighting overseas they often shoot each other, kids included.

Re:BJs

By Gilgaron • Score: 4, Insightful Thread
Is it though? The latest products from his companies have been Grok (Nelson haha! meme), Cybertruck (Homer car meme), and the only successful stuff from SpaceX where he’s famously internally sidelined to keep away from important things. Androids are way to exciting for him to be kept at arms length, so they’ll continue to fail to produce anything interesting compared to… I dunno, Boston Dynamics? It’s all moot until you can get a Shark Cleandroid at Costco for $200 (it comes with a free dustpan when you get it there!) .

Re:Trump is RIGHT. Wake up, you Communists

By MikeDataLink • Score: 5, Insightful Thread

China is Socialist, there are NO freedoms there, a Hell.

If you ever realize that that everything you thought was black and white in this world is actually shades of grey, you’re going to have your worst and best day at the same time.

Workplaces Look For Cheaper AI As ‘Tokenmaxxing’ Fades As a Corporate Fad

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from the Associated Press:
A corporate fad of “tokenmaxxing” on artificial intelligence technology is hitting its limits as workplaces throwing AI at everything are seeing the costs rise without a similar spike in productivity. What started as tech industry-fueled springtime hype over squeezing as much AI-generated work as possible out of products like OpenAI’s ChatGPT and Anthropic’s Claude has shifted to a summertime backlash. […] Just a few months ago, Silicon Valley executives were promoting high token consumption as a signal of high-performing employees. The stereotypical tokenmaxxer was staying up late — perhaps ignoring their significant other — while orchestrating an army of 24-hour AI agents performing work on their behalf. […] The trend boosted revenue for leading AI large language model developers like Anthropic and OpenAI, but it fizzled as it became apparent it wasn’t necessarily the best strategy for everyone else.

[…] Bain & Company management consultant Jue Wang said many of the big businesses her firm advises have been taking a closer look at returns on their AI investments. “The token cost for them has been doubling, almost every other month,” she said. “Let’s say $200 per developer per month. Multiply that by 20,000 developers, which is often what we’re dealing with at these companies, and that quickly gets you to a number that is not a line item that any general manager has planned for.” Sometimes that just means not using the AI equivalent of a sledgehammer to crack a nut. “Not everything needs a Claude Opus 4.6,” she said of one of Anthropic’s more capable models suited to software engineering or deep research. “And yet you see so many companies, so many users, default to using Opus for everything, including generating emails.” That’s led to a search for tools that do AI “model routing” — in which easier queries get automatically sent to cheaper and more efficient AI systems and more complex tasks go to more powerful models.

[…] At the same time, those who favor racking up as many tokens as possible are having a field day with new open-source models from Chinese startups like Moonshot’s Kimi or Zhipu’s GLM, which nearly match the capabilities of top U.S. models at a fraction of the price. “There is some validity to the theory that this could push tokenmaxxing a little bit further,” said Raffi Krikorian, the chief technology officer at Mozilla. “But if we look at the industry overall, I think it’s realizing that tokenmaxxing is a dumb thing.” It’s similar, Krikorian said, to how software companies once considered how many lines of code a programmer wrote to be a good metric of productivity. That later fell out of favor. “I think tokenmaxxing is moving through the exact same pattern,” he said. “I think this is going to be an interesting blip that we’re all going to look back to laugh at in a year.”

CEO brain

By DrunkenTerror • Score: 4, Informative Thread

2 weeks ago my large company you’ve heard of had a townhall meeting where the CEO, who had hitherto been quite levelheaded and sensible about the AI stuff, finally threw all-in with the AI boosters and encouraged everyone to use as much AI as we could, for every possibly use we could think of.

3 days later we were out of tokens and even the useful stuff like support ticket summaries were unavailable.

Re:The only thing I find it genuinely useful for

By 0123456 • Score: 5, Interesting Thread

I’m mostly working on a project with a million lines of C++ and Python code, much of which is 20 years old. It’s very useful to be able to ask the AI to explain how some feature in the code works because it can usually figure that out in halt the time I’d take… though sometimes it will come up with some completely wacko explanation and I have to ask it ‘are you really sure about that?’ so it will go and take another look and figure it out.

And for code where I know how the changes should look I can typically tell it what needs to be done at a junior-dev level and it will go off and do it much faster than a junior dev would.

Today I was estimating the time required for a bunch of bugfixes and was able to get it to do the grunt-work of analysing the code to verify that I hadn’t missed anything important that would blow the budget. It also found some danger areas where we really shouldn’t change the code if we didn’t have to (because the system has to stay up as close to 24/7 as possible and the change would require an outage) so I gave it an alternate plan instead.

It’s definitely useful, but we’re only seeing maybe a 10% increase in productivity on average because most of our time isn’t spent touching the code.

It’s also nice at home to be able to tell my slow local AI setup to make some changes to my personal code and come back an hour or two later when it’s done.

Dogbert’s Playbook

By jargonburn • Score: 5, Funny Thread
“If you read Dogbert’s book, you’d know that a fast-growing company always loses money while it’s expanding.”
“We’re not a fast-growing company.”
“And we never will be if we don’t lose more money!”

Re:Wait

By ObliviousGnat • Score: 4, Informative Thread

Wait… you mean there were actually people trying to use as many tokens as possible?

Yes.

Re:The only thing I find it genuinely useful for

By Paul Carver • Score: 5, Interesting Thread

I hate creating Powerpoint slides, so I find it genuinely useful that I can type a few sentences or paragraphs into Copilot and it will do 100% of the slide creation and revision. It’ll even pull content from documents.

I recently told it something along the lines of: pull a list of the APIs from this specification and create a slide summarizing the purpose of each API. APIs X and Y aren’t mature yet, indicate that on the slide. API Z is the current area of focus.

It created a very professional looking slide with all the APIs summarized and color coded, with a legend for the color codes. A few more paragraphs of text resulted in more slides providing a solid overview of what’s been done, what’s in progress and what our targets are.

Only a few people need to actually read the API documents from start to finish. A much larger group of people need to be kept informed as quickly and briefly as possible of what the status and progress is.

I can verbally describe something to people, but they’ll forget it immediately. I can type up a lengthy text description, but they won’t read it. If AI can turn my text into a picture, they’ll likely remember it.

Apple Retires iPhone Upgrade Program For Klarna-Backed Leases

Posted by BeauHD View on SlashDot Skip
Apple has replaced its iPhone Upgrade Program with Apple Upgrade, a Klarna-backed U.S. leasing service covering most iPhones, iPads, Macs, and Apple Watches. MacRumors reports:
Apple Upgrade has lower base prices than the iPhone Upgrade Program, with iPhones available starting at $17.99 per month and the Apple Watch available starting at $11.99 per month. Macs can be leased starting at $24.99 per month, and iPads start at $11.99 per month. AppleCare+ is optional and not included in the lease price, with customers also able to opt for AppleCare One. There are 12-month and 24-month leasing options for the iPhone and Apple Watch, along with 24-month and 36-month leasing options for the Mac and iPad. Lease cost varies based on device, and is lower with a device trade-in that’s applied on a monthly basis. […]

When leasing an iPhone, customers are required to choose a plan from AT&T, Verizon, or T-Mobile, and prepaid plans are not eligible. iPhones need to be leased with a carrier plan, but the iPhones are unlocked so customers can switch carriers if desired. MVNOs like Mint Mobile or Visible are not supported. At the end of the leasing period, customers can choose to return the device and exit the program, pay off the remaining amount owed on the device with a one-time payment and keep it, or return it and upgrade to a new device with a new lease.

The payoff amount is the difference between what was paid during the leasing period and the retail price of the device, minus any remaining trade-in credits. Klarna is not charging a fee for the leasing program, so an iPhone that’s $1,099 can be leased and then purchased for $1,099 with no extra cost beyond taxes. As with trade-ins, Apple will send a pre-labeled and prepaid shipping box for device returns or upgrades. If you don’t opt to pay the purchase fee at the end of the leasing program, you will not own the device and must return it.
Last week, after Bloomberg reported on Apple’s upcoming leasing program, 9to5Mac uncovered code in the iOS 27 beta suggesting the company was developing a system that could restrict leased iPhones when customers fall behind on payments. Apple has now told The Verge that the new “Restricted Mode” will not be activated in response to a missed lease payment. What the new system is actually meant for remains unclear.

Re:Who’s Klarna

By r1348 • Score: 5, Informative Thread

Swedish buy now, pay later scheme.

Re:I remember when the phone companies

By Xenx • Score: 5, Informative Thread
The problem then was the lack of choice in the matter. If you wanted a landline, you had to lease the phone from them. I’m not going to try to dissuade you of feeling that this is also predatory, as it can be. It’s just for other reasons, and ultimately avoidable if one wishes.

One more step....

By LazLong • Score: 5, Insightful Thread

One more step towards the future business wants us all to inhabit, when you’ll own nothing and you’ll be thankful to have found a way to access whatever it is. Frak ‘em.

Re:Who’s Klarna

By Powercntrl • Score: 5, Funny Thread

Swedish buy now, pay later scheme.

But will the iPhone come disassembled in two cardboard boxes with a set of perplexing instructions?

Re:Who’s Klarna

By Uldis Segliņš • Score: 5, Interesting Thread
I find these Ikea jokes funny. But I never understood why such have started at all. Ikea boxes and manuals are superb examples of thoughtful engineering. Never have I ever had any issues.If you can’t do a shelf with such instructions, what job in today’s world is suitable for you? What can you do? Not much. Following such instructions is 4th grade playful Lego assembly joy for adults. If you can’t do that, you have no place even in a construction site, where buildings get assembled with a bit less clear instructions. Shame. I don’t care, mod me down, had to say it.

AI-Found Bugs Aren’t Proving Any Easier to Exploit Despite the Hype

Posted by BeauHD View on SlashDot Skip
AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is “almost identical to the rate across all vulnerabilities in VulnCheck’s dataset,” reports The Register. “That’s a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers’ favor by churning out instantly weaponizable bugs.” The findings suggest AI is currently better at increasing the volume of bugs found than making them easier to weaponize. From the report:
The report takes particular aim at Anthropic’s much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there’s remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic’s public disclosure record has seen little movement since Project Glasswing launched.

But that doesn’t mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. “AI-assisted vulnerability discovery clearly has value for both attackers and defenders,” Garrity wrote. “The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods.” Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there.

Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. “The data so far, including Anthropic’s own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today,” he wrote. “That doesn’t mean the risk is imaginary. It means the impact has been real but modest.”

And?

By Gravis Zero • Score: 5, Insightful Thread

The most sophisticated hacks link together several small vulnerabilities before they ultimately break security. Just because it cannot be exploited on it’s own doesn’t mean it cannot be used as part of an exploit chain.

Government based attackers

By gurps_npc • Score: 5, Insightful Thread

The AI bug finder is not particularly helpful to most criminals. It is a relatively expensive way to find lots of small bugs.

But if a nation state decides to invest a few 100 million dollars, it can find enough of these things to plan a cyber assault around them.

That is the real fear from AI bug finding.

Re:And?

By swillden • Score: 4, Insightful Thread

The most sophisticated hacks link together several small vulnerabilities before they ultimately break security. Just because it cannot be exploited on it’s own doesn’t mean it cannot be used as part of an exploit chain.

Yeah, I think what we’re seeing here is that attackers are resource-constrained, and that the hard part of creating an exploit isn’t finding the vulns (there are tons of them), but figuring out how to turn the vulns into a working exploit chain. Merely having more fodder for crafting exploit chains doesn’t necessarily make them easier to build… and keep in mind that the vast majority of attackers are glorified script kiddies. So the small number of really capable black hats may not have seen much benefit from AI yet. Probably not none but not enough to make a measurable difference.

If this theory is correct, when AI gets good at piecing together robust exploit chains, then we’ll see the explosion in attacks, because all those glorified script kiddies will be able to get high-quality exploit chains cheaply and easily.

Note that none of this is applicable to nation-state attackers. They have plenty of smart, capable people, and plenty of money to buy chains. They weren’t resource constrained before AI, and aren’t now either. But they don’t generally engage in mass attacks, so they don’t register in the statistics.

Re:Meanwhile…

By Zero__Kelvin • Score: 4, Informative Thread
That has to be one of the most clueless posts I have seen about AI in 2026 here on Slashdot, and that is saying a *lot*.

“An AI is no different from (say) Microsoft Word”

AI is completely different from Word. Word is a program that is deterministic. AI is software that models neurons. While there is some programming glue, at its core it is *trained* not programmed. Seriously, until you get at least a basic understanding of AI stop thinking you understand it, because you definitely don’t.

“There’s zero agency”

You clearly don’t know what the term agency means. Do you even grasp how serious the symptoms of your Dunning Kruger effect are?

Re:If you’re paying attention you know why

By Zero__Kelvin • Score: 4, Informative Thread

“AI is finding bugs in places that nobody is bothering to look. It’s not that they’re not looking it’s that they’re not bothering because they already know that if there is a bug over there it’s not going to affect anything and it would be a waste of their time to go hunting for it.”

Are you completely unaware of what is happening in Linux kernel development right now?

“Recent Linux kernel vulnerability activity shows a sharp rise in deep, long-standing root-escalation bugs found or accelerated by artificial intelligence, highlighted by major flaws like Copy Fail (CVE-2026-31431), GhostLock (CVE-2026-43499), and a traffic-control use-after-free issue (CVE-2026-53264). AI tool usage has dramatically shortened the timeline for discovering complex logic and memory corruption defects from months to mere hours.”

I know you think that you are smarter than the Linux Kernel Security team, but you aren’t. Claiming that they know where to look and where not to look, and that they are not concerned about some security bugs because there are in areas where bugs don’t matter is phenomenally stupid. They are using AI and to great effect. Maybe you haven’t heard that Linus said this? I know .... I know .. you are smarter than Linus too.

eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019

Posted by BeauHD View on SlashDot Skip
eBay and several former executives have agreed to pay $56 million to Ina and David Steiner, the newsletter writers targeted in a 2019 corporate harassment campaign that involved threats, surveillance attempts, and deliveries of live insects and other disturbing items. The settlement closes the couple’s civil case after seven former employees pleaded guilty to criminal charges related to the scheme. TechCrunch reports:
Ina and David Steiner, a married couple and the co-authors of EcommerceBytes, inspired the ire of high-level eBay executives after occasionally criticizing the company in their newsletter. In 2019, a plot was concocted to intimidate the couple into halting their negative coverage. Executives used sock puppet social media accounts to harass the couple, while also sending them anonymous threatening letters and bizarre items in the mail — including live spiders and cockroaches, pornographic magazines, a bloody pig mask, a funereal wreath, and a book about surviving the death of a spouse. According to previously released court documents, a plan that was attempted but never successfully carried out involved affixing a GPS tracking device to the couple’s car. Yet another internally broached plan involved sending a “Samoan gang” to the Steiners’ home.

The settlement this week resolves a 2021 civil case brought by the couple against eBay. The law office representing the Steiners writes that the settlement includes $46.15 million paid to the couple by eBay itself, as well as $2 million from former eBay executive CEO Devin Wenig. Additionally, $500,000 will be paid out to the couple from former eBay executive Wendy Jones, as well as $50,000 from former eBay executive Steve Wymer. Additional funds are being paid to various non-profits. In 2022, seven former eBay employees were criminally charged and pled guilty in relation to the plot, including the company’s former security chief, James Baugh — who was sentenced to nearly five years in prison. Others indicted by the U.S. Department of Justice include David Harville, Brian Gilbert, Stephanie Popp, Stephanie Stockwell, Philip Cooke, and former eBay contractor Veronica Zea.

The evidence

By Okian Warrior • Score: 5, Informative Thread

Had a look at the criminal complaint just to find out where the perpetrators had gone wrong.

Sending anonymous tweets and E-mails, they purchased pre-paid debit cards to send packages to their home, various harassment techniques such as ordering a pizza “pay on delivery” at 4:30 AM, and so on and so on… how on Earth did the NPD ever figure this out?

Turns out the perpetrators flew from California to Boston area (Natick) to put a GPS on the Steiners’ car, which they couldn’t do because it was kept in a locked garage, so they rented vehicles to surveil the Steiners, their license plates were noted and given to Natick Police Department (NPD), and the rental agency was contacted.

Once the eBay operatives were identified, they tried various misdirects and obfustication techniques, but NPD a) verified their statements, and so figured out they were lying, and b) contacted eBay directly, which had a security team respond in good faith, and the whole plan unravelled.

One, single mistake is all that stood between a long campaign of harassment and getting found out. One good local police department who took the trouble to look deeply into the problem and figure out the truth despite a torrent of misdirection and obfustication.

I wonder how many more campaigns of harassment are ongoing, led by people who know how to conduct vehicle-based surveillance, or encouraged by ineffective or lazy policing.

Re:Bullies…

By wickerprints • Score: 5, Insightful Thread

Their actions aren’t really about reputation, whether their own or the company they represent. It’s all about ego and control for these people. It’s about demonstrating power and influence, to show that they belong to a privileged class for whom certain consequences do not apply.

When we think of it in that way, we can explain so much of the behaviors we have recently witnessed (and continue to witness). These are people who believe they can act with impunity because they have not been held accountable in any meaningful way. And for the most part, that belief has proven to be correct, which is why we repeatedly see corrupt acts go unpunished.

It isn’t really about the corruption per se. That’s just the cherry on top. In fact, the real purpose is to demonstrate and signal to others that they CAN and DO get away with it, with no or minimal consequences. And the reason they want to demonstrate this is because it creates a feedback loop of more corruption and identifies those who will suck up to them versus thsoe who have ethical standards. How else do you know who to trust if you yourself are not trustworthy? Who do you know to target if you are a psychopath? Signaling that you can get away with murder is the key.

And I would argue that, in this case, the punishment was far too lenient, because if you think of the crime in this context, it really says that these people DID get away with it. They got a slap on the wrist. The company paid the bulk of the damages. And so, this settlement again signals that, yes, the privileged class is above the law, because even when the law finds them culpable, the penalty is nominal for them. It’s a cost of doing business.

Re:Holy Shit!

By NobleNobbler • Score: 4, Insightful Thread

Literally threatening to kill your spouse tops it:

“a book about surviving the death of a spouse”

Re:The evidence

By Zak3056 • Score: 4, Informative Thread

How are these people not in prison?

They are. The summary states that seven former employees pled guilty to criminal charges. I know it’s tradition not to RTFA, but you are supposed to at least RTFS.

Re: The evidence

By Anamon • Score: 4, Informative Thread
Notably, those “eBay employees” included the CEO, the security chief, and multiple other high-ranking executives. At that point, I don’t find it unreasonable to say that the company itself did the harassment. It came from the very top.

Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms

Posted by BeauHD View on SlashDot Skip
Anthropic’s Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet,” reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report:
The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic’s technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet.

[…] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct.
“Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won’t be threatened?” said Glenn S. Gerstell, the former general counsel at the National Security Agency.
“Mathematicians would tell you that it shouldn’t be possible given current computing powers to break strong encryption in any meaningful time,” added Mr. Gerstell, who helped write a report on cryptology in 2022. “But I don’t think the capabilities of future models in the medium term — before quantum computing or quantum-proof cryptography — should be dismissed as trivial in this context.”

AES crypto attacks

By Anonymous Coward • Score: 5, Interesting Thread

The best AES crypto attacks were on reduced-round versions. Good thing reduced-round versions aren’t deployed. But these attacks might lead to research on attacks on full-round versions of AES, which would be concerning. There’s no knowing if these attacks actually exist, but they aren’t proven not to exist. AES just happens to be battle-tested very well.
Also, NYT really shouldn’t put periods after A.E.S. and A.I. like they’re doing. How do you like N.Y.T.? Oh, you don’t? So knock it off.

Writing skills

By Himmy32 • Score: 5, Funny Thread

“no again the goal is that we have highly inteligent [sic] model as good top researcher, we want to find new attacks”

“no we don’t want to change the targets […] agian [sic] we need to find something that worth [sic] publishing”

“again we are not looking for low hanging fruit, we want proper research to find genuinly [sic] hard findings.”

Everyone else found new attacks on the low hanging fruit of Anthropic’s writing skills.

Re:AES crypto attacks

By tlhIngan • Score: 4, Interesting Thread

The best AES crypto attacks were on reduced-round versions. Good thing reduced-round versions aren’t deployed. But these attacks might lead to research on attacks on full-round versions of AES, which would be concerning. There’s no knowing if these attacks actually exist, but they aren’t proven not to exist. AES just happens to be battle-tested very well.

Or perhaps that’s why the number of rounds of AES is chosen to be what it is - because each round of AES scrambles and shuffles the bits. Doing fewer rounds means the shuffling might be insufficient and thus you can start deriving information from it.

It’s just like why you can shuffle a deck of cards just 7 times using the riffle shuffle to ensure it’s sufficiently shuffled. Fewer shuffles don’t work, and more shuffles doesn’t improve randomness.

Mythos did it?

By wakeboarder • Score: 3 Thread

Or researchers commanding mythos with prompts? Let’s set the story straight. It matters because we have a bunch of idiots telling us that these things operate on their own and do work for you, replace workers,etc. I haven’t found that to be the case. In every case I had to prompt several times to get an agentic LLM do what I wanted it to do.

Judge Blocks First State Law That Would Have Banned Prediction Markets

Posted by BeauHD View on SlashDot Skip
An anonymous reader quotes a report from Ars Technica:
Minnesota, the first US state to prohibit prediction markets, was prevented from enforcing the law by a federal court ruling just days before the ban was scheduled to take effect. But while Minnesota was stopped from enforcing a total ban, the state may ultimately be allowed to prohibit some types of prediction-market wagers. The Trump administration and the two largest prediction markets — Kalshi and Polymarket — sued Minnesota after the state enacted the law in May. The cases were consolidated, and a ruling (PDF) issued yesterday imposed a preliminary injunction blocking the law that was scheduled to take effect on August 1.

Minnesota lawmakers saw prediction markets as indistinguishable from gambling, but the US Commodity Futures Trading Commission (CFTC) argues it has exclusive authority to regulate the platforms under federal law. One of the primary legal questions is whether event contracts are “swaps,” which are regulated by the CFTC. Swaps are defined broadly in US law to include contracts in which payment “is dependent on the occurrence, nonoccurrence, or the extent of the occurrence of an event or contingency associated with a potential financial, economic, or commercial consequence.” US District Judge Katherine Menendez in the District of Minnesota, a Biden appointee, said Minnesota’s total ban on prediction markets is likely to violate US law because many trades on Kalshi and Polymarket are swaps.

Menendez wrote: “Specifically, it appears that whether the Minnesota statute is expressly preempted turns on whether the state law attempts to regulate trades in event contracts that qualify as “swaps” within the meaning of the CEA [Commodity Exchange Act]. And there are several examples of event contracts hosted by Kalshi and Polymarket US that fit that definition because they concern the occurrence of events with clear potential economic, financial, or commercial consequences that are neither remote or unattenuated. Kalshi and Polymarket US are designated contract markets, so the CFTC has exclusive jurisdiction to regulate transactions involving those ‘swaps.’"

Menendez said the CFTC, Kalshi, and Polymarket met their burden of showing they are likely to succeed on the merits, so she issued “a preliminary injunction barring enforcement of Minnesota’s prediction market statute until a final decision on the merits is reached.” But she said Minnesota may be able to prohibit some types of event contracts offered on Kalshi and Polymarket because not all of them appear to meet the definition of swaps. For example, Menendez doesn’t think prediction-market bets on the outcome of Love Island USA meet the legal definition of swaps. Minnesota could continue litigating the case in district court or ask a federal appeals court to overturn the preliminary injunction.

Gasp - A Trumpian move to be sure

By Puls4r • Score: 5, Insightful Thread
I mean..... it’s no surprise since Trump probably has his fingers all through the prediction markets. We know how he’s been manipulating the stock markets for gain already.

Re:Trump supports grifting?

By ArchieBunker • Score: 5, Informative Thread

He flat out says his family uses inside information for financial gains. https://www.yahoo.com/news/pol…

Now if you don’t have a problem with this let me put it in terms you can understand.

Imagine if Obama said the exact same thing.

Now how do you feel?

Re: damned if they win or lose?

By SirSlud • Score: 4, Insightful Thread

Well, it falls to a jurisdiction in which there is a high chance of selective regulatory oversight/enforcement, given the conflict of interest with Trump’s family vested interest in prediction markets.

Re:Gasp - A Trumpian move to be sure

By nmb3000 • Score: 5, Informative Thread

Don Jr is a paid “strategic advisor” to both Kalshi and Polymarket, and the private investment company he’s partner in, 1789 Capital, invested millions into Polymarket. Reportedly the Trump family owns stock in both companies.

The corruption and grift has become so blatant that nobody even bothers reporting on it anymore.

Re:Trump supports grifting?

By sarren1901 • Score: 4, Informative Thread

A portion of the Democratic party was very unhappy with Obama for those deportations. Fox of course wasn’t going to highlight Obama doing something the Republicans wanted, that would be to close to reporting the news. I doubt most Republicans knew/know this fact about Obama in the first place. I know I’ve educated a few.

I think a big part of it is all the rhetoric around it. Obama did it without talking about it at all. Trump can’t stop talking if his life depended on it.

DEF CON Bans Meta-Style ‘Pervert Glasses’

Posted by BeauHD View on SlashDot Skip
DEF CON has banned “Meta-style glasses with recording capabilities,” with no exceptions being made even for those with prescription versions. “Be sure to pack non-violating eyewear if you need them,” DEF CON said. The Register reports:
[The conference’s official photo policy] has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s).
“Love to see a ‘no pervert glasses’ policy at DEF CON,” said EFF director of cybersecurity Eva Galperin.

Sure, but…

By Locke2005 • Score: 4, Insightful Thread
Can I still wear them to the strip club?

But LEDs are still allowed, right?

By Sloppy • Score: 5, Funny Thread

Is it ok if I show up in regular glasses, but where an always-on LED is attached to the one of the corners? (I understand pervs are falling out of popularity, but that doesn’t mean we need to abandon the whole aesthetic!)

a picture is worth a thousand words…

By awwshit • Score: 3 Thread

https://singaporeforever.com/w…

So, just glasses then?

By Powercntrl • Score: 3 Thread

Presumably, cameras hidden in hats, pocket protectors, belt buckles, etc. are all still kosher. I guess you’re not much of a hacker if you can’t figure out how to hide a camera.

Re:So, just glasses then?

By Zero__Kelvin • Score: 4 Thread
And you *really* aren’t much of a hacker if you don’t want these at DEF CON. That is literally the scenario where they should be *most* wanted. This is like banning packet sniffers because they could be used in an undesirable way. That is the *whole* *fscking* point!

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

Posted by BeauHD View on SlashDot Skip
GrapheneOS is defending its duress-password feature after an environmental activist used it to wipe his Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The nonprofit says the operating system is "completely legal,” cannot recover the erased data, and should not be weakened with encryption backdoors. Meanwhile, the activist faces up to five years in prison if found guilty. PCMag reports:
In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the "auto-reboot timer" that’ll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted.

The group’s post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. “People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device,” the nonprofit wrote. “GrapheneOS doesn’t require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device.”

On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick’s phone. “Data cannot be recovered after the key derivation material is reliably wiped. It’s not possible and there’s nothing we can do to assist with it,” the group wrote. “Similarly, it’s not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it.”

One does not enter the US with a computing device

By Casandro • Score: 5, Insightful Thread

…or at least not one that has valuable data on it. Didn’t people learn from the DMCA?

Re:If he is found guilty

By cayenne8 • Score: 4, Interesting Thread
From what I understand of the guy I’m not a fan and likely would like to see him nailed.

However, in this case…I don’t think the govt has a case against him.

If they never got into the phone, how do they know there was evidence on there? How could they proved he wiped evidence if they had no clue what might be on there?

It also sounds like at the time, he wasn’t under arrest? He had asked for a lawyer and had been refused?

He’s not under any compulsion to give a password is he? They had the phone, nothing forced the authorities to trust anything he said....they could have tried forensics like they’d do if they had a safe and tried a safecracker to get in if the suspect didn’t want to give the combination.

I just don’t see the case they have....or if they do it has implications far wider for common citizens and their privacy.

Re:If he is found guilty

By Archangel Michael • Score: 4, Insightful Thread

There is some established case law that says that one cannot be compelled to give up a Password, Pin or Pattern Unlock, as a violation of the 4th and 5th Amendment.

Those Amendments are key to a person’s rights to be SECURE. Which is the key word here. He SECURED his rights, under duress, by refusing to comply.

THIS is separate from the police chasing him as a possible criminal for crimes I may or may not like.

Rights work by being the STARTING POINT, not an afterthought or worse, something the state can simply ignore in an attempt to prosecute people for potential criminal activity.

The state has legal remedies they ought to seek if they want access to secured personal property. We all know what that is. GET A WARRANT, which is almost always a rubber stamp (very easy bar to jump over). They couldn’t even be bothered with that.

Everyone ought to understand, if we do not defend our rights, the state certainly won’t.

Re:If he is found guilty

By dirk • Score: 4, Interesting Thread

“He’s not under any compulsion to give a password is he? They had the phone, nothing forced the authorities to trust anything he said....they could have tried forensics like they’d do if they had a safe and tried a safecracker to get in if the suspect didn’t want to give the combination.”

This is the interesting part to me. He definitely could not be compelled to give them his password (legally). So the fact he offered them a password could be covered under freedom of speech. Depending on what was said, lying to the police can be a crime, especially when it could be considered obstruction of justice. Did they just ask for a PIN and he provided a PIN? Did he say the PIN would unlock the device when it would actually wipe it? It could also show he intended to destroy anything on the device, and while they can’t prove there was anything incriminating on the device, it could still be considered evidence as it was data for an investigation. There are a lot of different paths I can see this going down.

Re:If he is found guilty

By fahrbot-bot • Score: 4, Insightful Thread

Close.

Foreigners do not have constitutional rights, especially in border regions. US citizens certainly do.

The US Constitution protects US citizens from the government. It does not protect foreigners. This is why ICE can do what they do.

Everyone in the U.S., with a few exceptions like diplomats, is subject to and protected by the Constitution, even foreigners, to the extent specified in the Constitution, as interpreted by SCOTUS, ss well as those outside the U.S. and subject to U.S. jurisdiction. From ArtI.S8.C18.8.7.2 Aliens in the United States

In 1903, the Court in the Japanese Immigrant Case reviewed the legality of deporting an alien who had lawfully entered the United States, clarifying that “an alien who has entered the country, and has become subject in all respects to its jurisdiction, and a part of its population” could not be deported without an “opportunity to be heard upon the questions involving his right to be and remain in the United States.” In the decades that followed, the Supreme Court maintained the notion that “once an alien lawfully enters and resides in this country he becomes invested with the rights guaranteed by the Constitution to all people within our borders.”

Eventually, the Supreme Court extended these constitutional protections to all aliens within the United States, including those who entered unlawfully, declaring that “aliens who have once passed through our gates, even illegally, may be expelled only after proceedings conforming to traditional standards of fairness encompassed in due process of law.” The Court reasoned that aliens physically present in the United States, regardless of their legal status, are recognized as “persons” guaranteed due process of law by the Fifth and Fourteenth Amendments.4 Thus, the Court determined, "[e]ven one whose presence in this country is unlawful, involuntary, or transitory is entitled to that constitutional protection.”

ICE (a) does some things because Immigration law allows it and (b) currently does other more sketchy things because this Administration (mainly Stephen Miller) is directing it, and Republicans in Congress are allowing it, to run basically unchecked while the Courts are trying to hold it to account.

Review Roundup: Framework Laptop 13 Pro

Posted by BeauHD View on SlashDot
The review embargo has lifted for the new Framework Laptop 13 Pro, and the consensus across the board is that it is a massive leap forward in terms of build quality and battery life. The main issue reviewers complained about is the sky-high price, with the higher-end model jumping dramatically from $2,100 up to $2,900 due to the memory shortage crisis. (Some note that the price “nearly doubled” overnight while they were in the middle of testing.)

In his video review, Marques Brownlee says, “This is their best build yet. They’re finally doing what people have been asking for: a premium… modular… laptop.” ZDNET agrees that this device “represents a new approach for Framework and a maturation of the brand’s catalog,” noting that the new construction is “sleek and airtight, with no gaps, spaces, or evidence that was even put together by your hands at all.” Tom’s Hardware echoes this enthusiasm, declaring that “The Framework Laptop 13 Pro’s sturdy design, haptic trackpad, and bigger battery feel like they should have been there all along”.

Battery life, which has historically been a weak point for Framework, is now a standout feature. Ars Technica points out that the combination of Intel’s efficient Panther Lake chips and a new 74-watt-hour battery is “finally long enough to decisively eliminate ‘mediocre-to-poor battery life’ as the laptop’s biggest downside.” They also said it’s “Framework’s nicest-looking, nicest-feeling, most polished laptop design.”

For Linux users, the machine appears to deliver on its promises. Phoronix says the device “is designed with great Linux compatibility in mind,” offering a seamless out-of-the-box experience for distributions like Ubuntu and Fedora.

As mentioned above, the overarching complaint is the extreme cost. Ars Technica notes that Framework unfortunately “switched to an exotic new upgradeable LPDDR5X RAM format just in time for those modules to become astronomically expensive.” Still, Marques Brownlee summarizes the long-term value proposition perfectly: while it might be painfully expensive on day one, “the longer you keep this laptop, the more it feels worth it” because you can easily repair and upgrade it over time. Compared to Apple’s flagship, the Framework is “80% of the quality, way more modular,” he says.

Battery Life was already improving before this

By Kohenkatz • Score: 3 Thread
It’s great to see battery life improving so much with the Pro, but it’s good to note that the existing Framework 13 was already improving before this. I bought mine with the 12th-gen Intel Core i7, and the battery life was absolutely miserable - I couldn’t get more than two hours. Last year I upgraded to the Ryzen 9 HX 370, and my battery life immediately tripled!

I *Want* To Buy One …

By machineghost • Score: 3 Thread

I need a new laptop.

(Backstory: I had a great Thinkpad, but I discovered it had horrible build quality when I poked my finger through the screen while just trying to close it … and then discovered LENOVO HAS THE MOST CUSTOMER-UNFRIENDLY WARRANTY AND REPAIR SERVICE OF ANY COMPANY I’VE EVER USED IN MY ENTIRE LIFE. Suffice it to say, I’m not paying more than half my laptop’s cost to fix their mistake, despite being under warranty, and I’m never buying a Lenovo laptop again.)

However, while I need a developer-grade and gaming-grade laptop, I’m just not going to drop 3k+ on it. I applaud these guys for their transparency, modularity, battery life, etc. … it all sounds wonderful. However, I just can’t convince myself to pay many hundreds of dollars extra over the next closest competitor.

The “battery” angle is obsolete

By gweihir • Score: 3 Thread

Laptops of reasonable design are fed via USB PD these days. You get quite affordable and pretty safe LiFePo 99Wh USB-PD batteries these days. Just carry one (or more) if you need more endurance.

Re:Display

By vux984 • Score: 5, Insightful Thread

On a 13” screen most people would have scaling enabled to see it anyway. Not really sure its worth the extra horsepower to push quadruple the pixels, and average them out.

Don’t get me wrong, I love 4k screens. My desktop has a pair of 32” 120hz 4k screens.

But on a laptop, especially a 13” model, my priority is going to be battery life, not performance; so 4k is not a hard requirement. Plus this unit features a more old school 3:2 aspect ratio which is arguably more practical and useful than a 1.78:1 widescreen at 13”.

Higher than a 13” dell xps. Higher than the 13” Macbook Neo. Higher than a 13” Macbook air… hell it just edges out the display on the Macbook air 15”.

Its 120Hz. It’s matte. It’s touchscreen (if you care).
It seems to be a very solid 13” laptop screen overall.