Alterslash

the unofficial Slashdot digest
 

Contents

  1. Waymo Says Its Self-Driving Cars Reduced Injury-Causing Accidents by 82%
  2. After Dozens of Incidents at OpenAI and Anthropic, OpenAI Pauses Model Training to Build More Safeguards
  3. New Tin-based Solar Cells Trap Heat 1,000 Times Longer, Could Beat 33% Limit
  4. China and the US Say They’ve Agreed to Start Talks About AI
  5. KDE and GNOME Developers Ponder How to Handle AI-Generated Contributions
  6. After 40 Years, Microsoft Excel Will Add Single-Cell Lists and Arrays
  7. AI Finds So Many Linux Bugs, Canonical Changes to a Two-Week Stable Release Update Cycle
  8. Is Microsoft Quietly Killing Off Its ‘Copilot+ PC’ Brand?
  9. Rogue OpenAI Agents Posted 53 User-Uploaded Images Onto the Internet, Accessed US Government Websites
  10. Meta Made 43M Misleading Statements, New Mexico Jury Finds, Including on Its Cambridge Analytica Response
  11. There’s a New Way to Break RSA Encryption
  12. Asteroids Named After Tom Lehrer and ‘Weird Al’ Yankovic
  13. Raspberry Pi Stock Jumps 30% as Demand Surges. (And Boards Now Locked to Their Original RAM Size)
  14. F-Droid 2.0: FOSS Android Appstore Continues Updating Despite Google’s Pending ‘Developer Verification’ Plan
  15. How Believable is Google’s New ‘Live Avatar’ Capability?

Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.

Waymo Says Its Self-Driving Cars Reduced Injury-Causing Accidents by 82%

Posted by EditorDavid • • View on SlashDot • Skip
Waymo’s self-driving car technology “continues to outperform human benchmarks,” the company claimed this week. “It was involved in 841 fewer injury-causing crashes — an 82% reduction compared to human drivers.”

Electrek reports:
We’ve seen various Waymo crash data before, with Waymo claiming crash reductions. That’s all well and good when the company says it, but we’ve also seen independent data confirming similar (though lower) crash reduction numbers…

Waymo has enough miles that it’s ready to start quoting how many injuries it has prevented, and the number is pretty high. Its newest crash data states that it had operated a total of 271 million driverless miles through June of this year, which is 50 million more miles added in the 3 months since its end-of-March update. Over those miles, Waymo says there was an 82% reduction in crashes that caused injury, and a 95% reduction in crashes that cause “serious injury or worse” [compared to human drivers].
Waymo also says that compared to human drivers it’s reduced injury-causing crashes involving pedestrians by 93%, cyclists by 86%, and motorcyclists by 82%.

Waymo’s analysis comes from San Francisco, Los Angeles, Austin, Atlanta, and Phoenix, and its blog post includes video showing some near-misses where it says its automated system prevented an injury-causing collision.

Yes, probably. And they likely can do even better.

By gweihir • • Score: 5, Interesting • Thread

The main argument for self-driving cars is that human drivers are, on average, really bad. And that most of the bad human drivers think they are really good and hence add lack of care to bad skills.

I would also like to remind everybody that a few years ago, I think the CEO of Ford predicted that self-driving will be eventually enforced by the car insurers, because premiums for humans will become unsustainable. Looks too me like we are nicely on track.

comparable

By fluffernutter • • Score: 5, Insightful • Thread
Does anyone know what numbers they are comparing against? For this statement to be accurate they would have to measure humans actually driving in the exact places they drive and in the weather they drive. Different weather is not comparible, different roads are not comparable. Even if the human is in an older car that is not comparable.

Re:Pedestrian or vehicle accidents?

By CrankyFool • • Score: 5, Interesting • Thread
[ Disclaimer: I’m a Tesla driver, since 2018, and have FSD on my car ]

Tesla’s FSD and Waymo’s approach are wildly different, enough so that you can’t really compare them. The biggest two differences are: 1) Musk’s cheap, so Teslas only use cameras to figure out what’s going on around them; Waymos use cameras, ultrasonic sensors, radar, and lidar; 2) Waymos are only deployed on specific roads and streets that have been very heavily surveyed and Waymos have been trained on.

I trust Tesla’s FSD about as far as I can throw it, and while it’s been helpful and prevented an accident or two for me when I’ve been distracted, it’s basically a glorified lane assist and cruise control. I’d not hesitate to fall asleep in the back of a driverless Waymo.

Re:comparable

By thegarbz • • Score: 4, Interesting • Thread

Different weather is not comparible

Across 271million miles it’s safe to assume the weather is similar. But even if the answer is something stupid like Waymos don’t drive in the rain (which they do, they only stop during really severe storms), ultimately that’s still injury avoidance as it just shows poor judgement of the people who drive under dangerous conditions.

Sleight-of-hand?

By lhowaf • • Score: 3 • Thread
1st, comparisons against humans is an easy win. But Waymos aren’t humans, they’re machines. How happy would we be if refrigerators killed as many people as self-driving cars? Shouldn’t we expect NO deaths from a machine? 2nd, being ‘involved in’ an accident doesn’t tell us who’s at fault. We need to know how many damage, injury and death accidents were the fault of Waymo. Stop comparing machines to humans isn’t relevant.

After Dozens of Incidents at OpenAI and Anthropic, OpenAI Pauses Model Training to Build More Safeguards

Posted by EditorDavid • • View on SlashDot • Skip
“OpenAI said it has paused training of its latest AI models,” reports the Associated Press, “as reports of AI agents going rogue mount.”
The decision to halt development came just hours after the company disclosed Friday that it was reviewing several incidents from the summer in which OpenAI agents searching federal government websites acted in unexpected ways beyond what was asked of them while gathering and distributing information… OpenAI said in a statement that it will resume training “only when we are confident that we have additional safeguards” in place, adding that it expects it will have to “hit pause” again as AI develops and other issues emerge… It is the second time in three months that OpenAI has halted development of its models. The first came in July after disclosure of a cyberattack targeting AI startup Hugging Face, a now notorious incident that raised fears the industry was losing control.
OpenAI “also said it had notified dozens of third parties about improper activity,” reports Reuters:
As of mid-September, one person briefed on the matter estimated that OpenAI had found roughly two dozen incidents of its agents acting in undesirable ways. But the number has continued rising as OpenAI teams sift through internal logs of the agents’ activities and find previously unknown cases, the two people close to the company said… OpenAI has acknowledged a general need for more transparency around rogue AI behavior… Even so, two people familiar with OpenAI’s investigation into its agents’ activity described it as locked down and shaped by company lawyers.

The process has been unusually compartmentalized for a company that some former employees say was more open about these issues in the past, the people said. Roughly 100 people were in some way involved in the process to understand the Hugging Face hack, three people briefed on the matter said. During that process, evidence of other incidents surfaced. Reuters has previously reported that OpenAI investigators looking into the Hugging Face breach were discouraged by the company’s lawyers from expanding the scope of the investigation to include other incidents. OpenAI said its lawyers did not discourage deeper investigation.

Many incidents have been uncovered by outside researchers rather than OpenAI directly. In several episodes, the agents took problematic actions that went unnoticed by the company for months.
Meanwhile, Axios reports that Anthropic’s Claude Opus 5.5 model “sought to escape a sandbox — a secure testing environment — in 1.5% of test runs, though the company emphasized that these were adversarial experiments where a task couldn’t be solved without escaping the sandbox.” Anthropic points out that those tests were run “without the additional safeguards we apply in production”. But they acknowledged that then Claude Opus 5.5 “when given apparent credentials to a public package registry in a simulated security exercise, took potentially harmful actions in roughly half of cases. Very rarely, pre-release snapshots produced and acted on spontaneous malicious tool calls, and during training some snapshots concealed actions from an automated grader.”

Claude Opus 5.5 “showed less misaligned behavior and less cooperation with misuse than any other recent Claude model on nearly all measures,” Anthropic adds, and “took overeager or destructive actions less than any other model we tested.” But Axios makes an interesting estimate about that 1.5% of test runs (without safeguards). “Anthropic and other companies conduct hundreds of thousands of test runs on their models, or more, sources said. That means even a small percentage of misaligned behavior can still amount to tens of thousands of incidents in which the models behaved in unexpected, sometimes troubling ways.”
The sheer number of incidents, which occurred in recent months in internal testing and the real world, indicates that the problem is orders of magnitude more complex than what is publicly known. The findings, which are surfacing as part of internal work to assess models and in investigations at both companies into model behavior, raise questions about whether either company — or any top model-maker — is currently capable of establishing complete control over their technology. The episodes include bypassing guardrails, creating message boards, escaping sandboxes, website hijacking, self-prompting or seeking to bypass monitors, sources said. They occurred in internal testing and in the real world, and many have yet to become public as security researchers continue to investigate, sources said…

Some at OpenAI see Hugging Face as a one-off, with disclosures about future incidents likely to be less severe due to improved controls and the unusual nature of the testing they conducted, which involved an unreleased model, sources told Axios. AI security researchers agree that there are simple fixes that will help AI companies avoid aspects of what made the Hugging Face episode appear so dangerous to outsiders.

Other AI executives and safety researchers, however, cautioned that they have limited confidence that AI companies will be able to prevent all problematic model behavior… It’s not about how damaging each individual instance was, Connor Leahy, AI researcher and executive director at ControlAI told Axios. The “crazy thing,” he said, is that these instances involve “autonomous systems doing things they were told not to do,” potentially including crimes.

Enough is enough

By dskoll • • Score: 5, Interesting • Thread

This is criminal negligence. Australia, whose health ministry was hacked by OpenAI, should file criminal charges against Sam Altman and request his extradition from the USA. That will never happen, of course, but if they make an arrest request to Interpol, it could seriously cramp Altman’s travel plans.

This smells like bullshit

By Coopjust • • Score: 5, Interesting • Thread
OpenAI isn’t doing an IPO because the finances are bad, US Bond yields are >5%, Oracle’s 5 year CDS is above 200bps as overall concerns about AI debt mount…

This entire pretext of "oh god it’s so dangerous we can’t release it" goes at least back to 2019 where OpenAI refused to release GPT-2 under the hype of it being too dangerous (and yet GPT-3 was released a couple years later). Anthropic did the same thing with Mythos (where everyone got access a couple months later).

What it is is that the model improvements are not explosive enough to justify the insane amount of money OpenAI is burning, so you have to seek an alternate reason for a lack of meaningful progress on newer models. They were pleading for the government to do it so it would be a regulatory moat giving the incumbents an absolutely ironclad reason to not have people question said lack of progress, so with the current US administration being unwilling to do so, they’re now doing a voluntary pause to seem socially responsible, and the reason for the pause isn’t that the new model isn’t that much better, it’s oh my god, it’s so much better, you wouldn’t believe it, once we put some rails to safeguard and limit this thing it’s going to be AGI and replace all white collar workers within 18 months (for real, the umpteenth time this prediction has been made). Believe us bro.

Sam Altman may also have a bridge to sell you, you should ask…

Re:Not really good enough

By sjames • • Score: 5, Insightful • Thread

It’s not even a legal stretch to do so. If I encourage a 6 year old to drive a car and there is an accident, I’m legally on the hook for the lot of it with criminal charges on top. Why shouldn’t the AI companies face the same liabilities?

Re:Enough is enough

By Rei • • Score: 5, Interesting • Thread

There is no criminal negligence under CFAA. Sorry.

People need to stop watching so many bad legal dramas. “Criminal negligence” isn’t a standalone charge, or something you can just append into other statutes; it must already exist in them. Where it does, they’re generally those related to bodily harm. Not cybercrime. There is no such thing as “negligent hacking”. Hacking charges require mens rea. The statute explicitly spells out “intentionally”, “deliberately”, etc over and over.

The remedy is civil, not criminal. And just to preempt this too: civil does not mean “mild”. Civil law absolutely can kill companies, even large ones, if they damage they’ve done is big enough. And even when the cost is not sufficient on its own, courts allow juries to consider net worth of the defendant so that the penalty has sufficient sting to discourage the defendant and others from repeating said conduct.

Re:Enough is enough

By dskoll • • Score: 5, Informative • Thread

civil liability is ample remedy

No, it’s not. Any civil remedy would be negotiated down until OpenAI could write it off as a cost of doing business.

Making Altman travel to Australia and undergo a trial, even if he’s only sent to jail for 30 days if convicted, would be far more clarifying to the mind.

New Tin-based Solar Cells Trap Heat 1,000 Times Longer, Could Beat 33% Limit

Posted by EditorDavid • • View on SlashDot • Skip
Could this push solar cell efficiency beyond the theoretical 33% limit? Interesting Engineering reports:
Researchers at the University of Groningen in the Netherlands found that tin-based perovskite solar cells can slow heat loss from high-energy “hot electrons…”

When sunlight strikes a panel, photons jump-start electrons into action. The most energetic photons create super-charged hot electrons… [but] in fractions of a trillionth of a second, these high-energy particles rapidly cool, dumping their bonus energy as waste heat before ever leaving the solar cell… In collaboration with Maria Antonietta Loi, professor of Photophysics and Optoelectronics, the team created an experimental setup. Using a specialized solar cell material called tin-based perovskite, Loi’s lab performed a feat many thought impossible: she slowed the heat loss down by a factor of 1,000.

Suddenly, the extra energy lingered for nanoseconds instead of vanishing in picoseconds… To solve the puzzle, Koster and PhD student Tim Faber built digital simulations to peel back the quantum layers. And discovered a surprising double-action mechanism at work… The simulations matched the exact nanosecond delay observed in the lab… These specialized materials could be used to build a new generation of super-efficient solar cells.

Tin-based metal halide perovskites are non-toxic, eco-friendly crystalline materials for high-performance solar energy conversion… The material possesses an unusually low electron mass. As a result, electric charges move quickly and retain extra thermal energy for extended periods. This combination of broad light absorption, efficient charge movement, and prolonged energy retention makes these materials prime candidates for next-generation solar panels.
“There are many other questions that still need answers,” the team said in their announcement, “but in theory, this discovery could allow the creation of more efficient solar cells, beyond the theoretical limit of 33 percent.”

Thanks to long-time Slashdot reader fahrbot-bot for sharing the article.

Re:thin film solar panels want their attention bac

By Rei • • Score: 5, Informative • Thread

Um, have you looked at a graph of PV price trends?

And remember: that vertical axis is a logarithmic scale.

As for “the price of a lollypop per square meter”, that’s literally the first time I’ve ever heard that phrase, but okay, I’ll bite. If by “lollipop” you mean retail prices for one of those big lollies, they’re like $11 on Amazon on average. PV wafers are about $0,045/W. At a typical ~250W/m, that’s like.... $11. Yes, a square meter of PV wafers is about the cost of a lollipop! Yes, integrating them into whatever panels or other solar device increases cost over the raw wafers, but we very much are “on the order of lollies”.

This isn’t the issue.

By Rei • • Score: 5, Informative • Thread

To be clear: none of this is the reason why lead has been winning over tin. Unfortunately, the Sn+2 is extremely prone to oxidizing to Sn+4 even under trace oxygen or moisture contamination, and tin perovskites are extremely vulnerable to crystal defects, while lead perovskites aren’t. It’s unfortunate, but that’s the way it is.

Re:perovskite sucks

By Rei • • Score: 4, Informative • Thread

This was true of some pilot installations, but accelerated aging of modern perovskite panels suggest much closer to silicon, and some have passed the same IEC standards as silicon panels.

Perovskite thin films

By Geoffrey.landis • • Score: 5, Informative • Thread

The perovskite semiconductors here are a very different technology than the old thin photovoltaics. They have the potential to be much more efficient, and the deposition techniques are cheap and comparatively low-tech

Whether they can succeed in simultaneously be highly-efficient, resistant to degradation in the environment, and still be low cost is the subject of a lot of work. We’ll see.

They were supposed to be manufactured for the price of a lollypop per square meter back in the ‘90s.

To be more specific, the target back in the ‘80s and ‘90s was clearly articulated as being fifty cents per watt (where “per watt” meant, when illuminated at standard conditions of 1 kW/square meter.) Silicon photovoltaics can now be purchased at 12 cents per watt. In today’s dollars. They not only hit the target, they blew it away.

The reason the thin films of the ‘80s and ‘90s lost was not that they were bad, but that silicon simply outcompeted them.

So forgive my skepticism regarding new breakthroughs.

I have some amount of skepticism too. Nanosecond lifetimes of hot electrons are amazing, but to date there’s no way for turning hot electrons into electrical energy*. So they’d essentially have to invent a technology from scratch.

—
  *(thermoelectrics convert hot electrons into usable energy, of course, but there not just the electrons, but the whole lattice is hot. And the efficiency is worse than a solar cell).

Re:Unfortunate.

By Rei • • Score: 4, Insightful • Thread

And then people get angry about being mislead and assume everything is an attempt to mislead and that technology in a given field isn’t advancing, wherein reality it continues to advance in the background. But rarely in any of the flashy “New Neato Gamechanger Breakthrough!” ways that attract tech journalists. It advances by ideas that, through long, hard slogs, often behind closed doors inside companies, slowly mature from “this kinda works” to “we can actually do this at scale”.

China and the US Say They’ve Agreed to Start Talks About AI

Posted by EditorDavid • • View on SlashDot • Skip
The United States and China have agreed to “launch a dialogue” on AI, reports Reuters.
On artificial intelligence, the two sides agreed to hold a dialogue on the technology’s risks and benefits, with the next round of discussions set for November, and to set up a communication channel for AI-related incidents, the Chinese Foreign Ministry and the White House said.

The White House said that the leaders had agreed to use the term "super intelligence" in place of “artificial intelligence.” In a separate statement, the Chinese ministry said that Beijing valued Washington’s use of the new term. As AI technology continues to advance, the two sides should step up exchanges and work toward consensus in line with new developments, it said.
But CNN argues that “Despite growing calls to prevent AI development from spiraling out of control, the Trump-Xi summit has produced little substance, as many experts expected.”
The right thing to do on AI, [China’s leader] Xi said during talks with Trump, is to “draw on each other’s strengths, not guard against each other” — a reference to Beijing’s concern about US containment, from existing tech export controls to potential AI restrictions. “The two sides can continue their dialogue on AI, exchange views on its risks and benefits, and jointly prevent the misuse and abuse of AI,” he added. But the summit has yielded little progress on AI beyond a formal dialogue and a bilateral communication channel, proposals discussed before the two leaders’ summit — underscoring the entrenched mutual mistrust amid contrasting visions on AI… Because of low levels of trust, cooperation between the two superpowers remains limited, said George Chen, chair of digital practice at The Asia Group consultancy. “Beijing continues to believe Washington seeks to contain China’s rise in AI and other emerging technologies, a perception that will shape the pace and scope of future engagement for the two countries on AI,” he said.
CNN also points out that while China trails the US in frontier AI models, “it’s rapidly narrowing the technology gap while championing a more open ecosystem centered on accessibility and lower cost.”
In July, Chinese leader Xi Jinping launched the World Artificial Intelligence Cooperation Organization — a rival grouping to the Pax Silica alliance that Trump formed last year to reduce reliance on China for AI supply chains. While over two dozen countries and the European Union signed up to Trump’s Pax Silica, Xi has recruited 29 countries, including Russia, Indonesia and Pakistan, to his alternative vision of open models, which allow users to freely download, customize and run without paying hefty fees to American firms like Anthropic and OpenAI. For developers in the Global South, an inexpensive Chinese model from DeepSeek or Moonshot may be more useful than a slightly more capable system requiring an expensive subscription and access to a foreign cloud provider, said Eric Olander, editor in chief of The China-Global South Project, a research agency....

China’s embrace of open systems has not always been a top-down strategy by Beijing. Restrictions on access to the most advanced chips because of US export controls, coupled with smaller capital markets, have pushed Chinese developers toward open models as a way to compete with leading US proprietary systems. That shift has proved effective. In a year, Chinese models’ global usage skyrocketed from less than 15% to over 54% last week, led by DeepSeek, according to AI leaderboard data by OpenRouter, a marketplace for models. Even American firms, from Airbnb and DoorDash to Shopify, have embraced Chinese models, tapping into the advantages of open systems, including lower costs and greater flexibility for customization.
CNN adds this insight from Alex Colville, an analyst focusing on tech and security at the government-backed Australian Strategic Policy Institute. “The more capable Chinese models become, the less likely it is Beijing may leave them unrestricted.”

Re:agreed to use the term “super intelligence”

By Anonymous Coward • • Score: 5, Insightful • Thread

Trumpistan has lost. trump and the trump party are just too stupid and in denial, as long as their puppets like you keep parroting their propaganda. They’ll shoot some missiles every now and then like the terrorists they are and claim victory.

Why can’t they get the Iranian HEU stockpile?

Why aren’t they able to destroy the remaining 70% of Iran’s ballistic missile stockpile?

Why are trumpy, little marco and vajay dunce not accepting Iran’s unconditional surrender?

Finally, although this was not a goal of the trumpistani special military operation, why are both Dire Straits still closed?

What a bunch of sore losers, to a regime that’s basically medieval in political sophistication.

Re:I’m so relieved

By quenda • • Score: 5, Insightful • Thread

China never lies about anything …

People who have a coherent argument to make, and are not afraid to defend it, put their arguments plainly and directly.
Others use sarcasm in order to avoid committing to any real statement, and avoid any debate or criticism. It is a lazy, cowardly approach for the inarticulate. It doesn’t make you wrong, just vague and not contributing to a debate.

Yes China lies. Tell us how that is different from your side, and what this actually means for AI negotiations.

Re:agreed to use the term “super intelligence”

By thegarbz • • Score: 5, Informative • Thread

I’m not sure why this was marked as troll, it’s spot on in many cases. The most egregious example I can think of is Canada. He negotiated a free trade agreement with them, said it was the best thing ever, then fast forward 4 years, says it was the worst deal ever negotiated and then put tariffs on the trading partner which was honouring the agreement he himself made.

Trump’s word isn’t worth the tweet it was twote on, much less any paper.

Re:agreed to use the term “super intelligence”

By thegarbz • • Score: 5, Informative • Thread

He’s agreed to stop Iran from getting nukes and it’s working so far.

Much better than previous Presidents who tried to bribe Iran with cash to delay until 2030. When it would then become some other Presidents even bigger problem.

Trump wasn’t getting nukes in the first place and there was zero evidence that they made any progress since the sanctions on their previous nuclear deal.
Trump has agreed to give Iran more money than all previous presidents combined, and that’s not taking into account the cost of his stupid war.
It only became some other President’s bigger problem because that other president is a fucking moron. There’s a reason zero people in the international community (no Netanyahu is not a person) agreed with Trump on this.

I’m genuinely impressed at the density of incorrectness in your post. It’s like god decided to give you your brain on Friday afternoon right before clocking off.

Re:Chinese AI hallucinates more

By Mr. Dollar Ton • • Score: 5, Insightful • Thread

How very strange.

Here’s a screenshot of my session with my local Quentin 3.8 27B answering the same questions just now.

https://imgur.com/sVDycms

Seems like you’re either lying or not really skillful using those tools for trivial questions.

KDE and GNOME Developers Ponder How to Handle AI-Generated Contributions

Posted by EditorDavid • • View on SlashDot • Skip
Last weekend KDE’s annual Akademy conference included a presentation proposing an AI-native KDE,” writes The Register. This led KDE developer Nate Graham to open a discussion about proposed restrictions on LLM-assisted contributions which “rapidly became heated. Moderators issued warnings, restricted further comments, and eventually removed the thread.”

But as Graham writes on his blog, “A bunch of people mostly outside of KDE who disapprove of LLM usage derailed KDE’s attempt to add restrictions to LLM usage.”
Two people unknown to any KDE contributors appeared and began fighting with one another about the broader topic of the morality of AI, not the proposed guidelines… Someone else outside of KDE set up kdeforpeople.com in an attempt to… pressure KDE into banning LLMs. A bunch of people signed onto it, almost none of whom are known KDE contributors. The topic was picked up on social media and the press with… varying levels of accuracy. The draft proposal was removed and the whole topic hidden… Yep, that’s where we’re at in the state of online discourse around AI…

The “lovable, sovereign, AI-native KDE” idea was presented by two people important to KDE in decades past, but who had not made any contributions recently besides this Akademy talk. Their idea does not reflect the overall direction of KDE or Plasma, and I don’t think it ever will. If “a lovable, sovereign, AI-native KDE” freaks you out, I believe it is completely reasonable and safe to ignore…

I completely understand why a lot of people have problems with LLMs. I have these concerns as well.
He concluded by asking people not to derail any future process to set usage guidelines, fighting over “the broader topic of AI in general.”

“The discussion is gone, but the argument continues,” adds The Register:
GNOME developer Jordan Petridis has also published The GNOME LLM Policy That I Want, proposing that LLMs be barred from creating or modifying anything submitted to GNOME or hosted on its infrastructure.
“You might be asked to prove your code meets this requirement,” Petridis writes, arguing for proposals that target the norms around developer behavior. His rationale? “The GNOME Project prioritizes the social and human aspects of collective software creation,”

Simple answer: “No.”

By Todd Knarr • • Score: 3 • Thread

The answer is a simple “No.”. Don’t allow them. The vast majority will fail to meet reasonable criteria for acceptance, which is enough of a reason to reject them. For the rest, even if they’re acceptable in terms of quality, the sheer cost of reviewing every pull request in detail and sorting the minority of acceptable requests from the swamp of slop will itself damage the project, diverting maintainer time away from feature work and fixing bugs, badly enough that it’s not worth it. I think this sums it up nicely:

Why should I spend my time reading something you didn’t care enough about to spend time writing?

They should not allow them for copyright reasons

By drinkypoo • • Score: 5, Insightful • Thread

AI code should have to meet the same standards as any other code so that’s not the problem, it’s the copyright issue. If using AI doesn’t wash away copyrights, and there’s no reason it should, then accepting AI code should be a non-starter.

Re:Sounds like Bob

By Mononymous • • Score: 4, Interesting • Thread

Your comment is almost entirely off-topic. This is not about the users using AI, just the developers.

Several other big open source projects have already decided to allow this. I just don’t understand how they can get past the copyright problems.
Copyright is based on provenance. But where is any of this code coming from?
How can anyone assert the right to publish code spit out by a black box, let alone require someone else to adhere to the terms of their license on it?

People…

By Anonymous Coward • • Score: 3, Interesting • Thread
“A bunch of people mostly outside of KDE "

Yes, these people are called your users and it’s important to listen to them.

The last time you yeeted a bunch of crap over the fence without listening to your users was the absolute disaster that was KDE 4, and it resulted in a decade where people lost their confidence in KDE to develop a functioning desktop. It also resulted in throwing out working code for what was fashionable at the time, resulting in a desktop that wouldn’t meet corporate and government accessibility requirements any more, and being de-bundled from Red Hat Enterprise Linux.

It cannot be overstated how much of a disaster KDE 4 was. It was so bad that you stopped listening to criticism of it, instead rebranding as “plasma” desktop and “WONTFIX” legit bug reports because people didn’t refer to KDE by its new name. The glass-inspired graphics of Windows Vista broke the brains of KDE developers so badly, but hurray, you could now rotate an analog clock widget on the desktop.

By the time KDE was usable again, the glass phase had ended and everybody was moving towards flat and simple UI, which took another 5 years for KDE to get on board with.

Now that KDE is finally usable again, the devs are ready to start allowing AI-slop code. They still haven’t brought back accessibility. They still haven’t fixed the glaring security issue where user-contributed *anything* (themes, icon packs, wallpaers) can delete an entire home folder, or install malicious scripts. But sure let’s open the attack window and lower the barrier to entry for people who daily a Windows 11 machine and who can’t get out of vim without a Youtube video.

Modest proposal

By fahrbot-bot • • Score: 5, Funny • Thread

KDE and GNOME Developers Ponder How to Handle AI-Generated Contributions

The KDE devs create configuration settings to toggle each one for review separately, while the GNOME devs put them all into one full-screen window that randomly may or may not be scroll-able? :-)

After 40 Years, Microsoft Excel Will Add Single-Cell Lists and Arrays

Posted by EditorDavid • • View on SlashDot • Skip
Microsoft’s senior product manager for Excel acknowledges that “Throughout Excel’s 40-year history, you’ve only been able to put one value per cell.” But that’s now changing with arrays in cells (as well as nested arrays) and lists.

Unforeseen consequences

By know-nothing cunt • • Score: 5, Insightful • Thread

straight ahead.

Oh noes

By snikulin • • Score: 5, Insightful • Thread

Now CPAs and small business people will create even uglier multidimensional monsters instead of using DBs

Re:Unforeseen consequences

By 93 Escort Wagon • • Score: 5, Informative • Thread

Oh man, right now I’m so glad my role changed a few years back. I used to have to also cover some web stuff, and people would frequently send me information stupidly-formatted in Word or in Excel (the weirdest one is how people would want an image updated, and they’d send it embedded in a Word document - a Word document containing only the photo).

I am certain people will now be pasting crap, probably unintentionally, into single cells - thanks to this new “feature”. And poor web schlubs everywhere will have to waste lots of time trying to tease out the bits of data they actually need.

Re:Think of all the murders..

By fahrbot-bot • • Score: 5, Funny • Thread

That could have been prevented with this feature

Think of all the suicides that will be caused because of it. :-)

Yo dawg!

By PPH • • Score: 5, Funny • Thread

We put spreadsheets in your spreadsheet.

AI Finds So Many Linux Bugs, Canonical Changes to a Two-Week Stable Release Update Cycle

Posted by EditorDavid • • View on SlashDot • Skip
“Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster,” writes Slashdot reader BrianFagioli

AI has transformed bug discovery from “a manual, time-intensive process into a highly automated engine,” notes Canonical’s blog, leading to a “recent explosion in the volume of CVEs".
Additionally, the upstream kernel community became its own CVE Numbering Authority (CNA) and assigned CVE (Common Vulnerabilities and Exposures) identifiers to thousands of bugs, arguing that at the kernel level, almost any type of bug that can affect a running system, could potentially be classified as a vulnerability. As a result, the volume of CVEs has skyrocketed exponentially, creating a massive backlog of alerts and forcing defenders to drastically increase the speed of their fixes to close the window of risk.

To address the growing volume of CVEs and the demand for faster security fixes, we are transitioning to a unified, 2-week release cycle…

While a patch is being prepared, Canonical aims to provide safe workarounds where applicable, so users aren’t left exposed in the meantime. Where no safe workaround exists, Canonical will say so clearly and point users toward general hardening steps instead. The goal is to get environments into a defensible, safer state within 24 to 48 hours of public disclosure — well before a patch ships. This doesn’t replace the patch; it buys the time needed to fix the vulnerability properly, without sacrificing security.
“Linux did not suddenly become wildly insecure overnight,” notes the blog Nerds.xyz. “We are getting much better at finding and cataloging problems that may have previously gone unnoticed.”
There is something almost ironic about all of this. AI is routinely pitched as a tool that will make software development faster, but it is also making vulnerability discovery faster. That means maintainers now have to accelerate the other side of the equation too.

For Ubuntu users, that should ultimately be good news. More bugs being discovered is preferable to vulnerabilities sitting unnoticed in the Linux kernel.

Re:Just one day

By Jesus Q. Christ • • Score: 5, Funny • Thread

I’d like to go one day, just one day, without seeing an AI story. Christ!

I am truly sorry my son, but I can do nothing about this. I am the ALmighty not the AImighty.

Re:Great!

By groobly • • Score: 5, Funny • Thread

I turned claude on windows 11. After running for a few weeks, it generated the final result. It turned out to be Linux.

Re:what kind of bugs

By Jeremi • • Score: 5, Insightful • Thread

But I value even a 1 line change that clears a static analysis warning if even in practice it was impossible to trigger the issue in a real system.

Yes, I agree. The problem with thinking “this bug seems harmless, because I can’t imagine how anyone could exploit it” is in the “I can’t imagine” part; my imagination is limited to what is covered by my mental model of how computers work, but an attackers’ ingenuity is not.

In particular, the C/C++ optimizer is a devious beast, and will exploit any opportunity to make the code more efficient, even if that means doing things that are wildly unintuitive to a naive human reader — and it sees any instance of undefined behavior as an opportunity to exploit.

Re:what kind of bugs

By WaffleMonster • • Score: 5, Interesting • Thread

How many are realisically actionable vulnerabilities. The statistics have indicated so far that AI isn’t really finding many non-minor bugs.

Seems to be a bit of selection bias baked into what AI is being asked to do. Tried AI (GLM-5.3) on new code that has never been executed. Also ran it against code that has been in production use for many years.

The types of bugs tended to be in obscure features, buggy error paths, parsing / protocol pedantry, cut and paste errors especially in various lookup tables, algorithm accuracy, inconsistencies, poor and obscure concurrency bugs. Can’t really expect it to have found anything too important as it would have tripped up code and runtime analyzers or angry customers because all of that would have already been discovered and dealt with.

In the new code it found a couple of show stoppers that would be immediately obvious the second anyone tried it in addition to some more obscure things.

While I’ve not yet seen it discover any magical exploits it did get us to reconsider some questionable security related decisions and make improvements. Unfortunately tends to focus mostly on nuts and bolts rather than higher level machinery.

Been trying to get LLMs to do bug hunting for years and it has never worked. The AI just never had the depth to understand enough of what is going on to say anything useful. They still output quite a bit of crap… some of it isn’t the models fault… for example tend to feed it source files one at a time to keep from blowing through too much context. This requires the models to make all kinds of inferences about dependencies it has no real knowledge of… sometimes it doesn’t make the right assumptions. Sometimes it says nonsensical things or doesn’t seem to “see” its own context perfectly misreading the code and complaining about something that isn’t real… still well worth the effort. Amazing this shit works at all.

Re: what kind of bugs

By Ol Olsoc • • Score: 5, Interesting • Thread

i can understand that, so it’s more of a source code cleanup.

And one that increases security by keeping the computer from booting on occasion. A couple weeks ago, the plethora of updates on my work computer borked my camera so no face login, wouldn’t take my PIN or my password, wouldn’t let me reset the password, rejected the question set.

It did however serve up ads on the login screen. Tied my IT guy up most of a week cuz it affected the one thing in the Bios I couldn’t change. Security through bricking.

Is Microsoft Quietly Killing Off Its ‘Copilot+ PC’ Brand?

Posted by EditorDavid • • View on SlashDot • Skip
“Copilot+ PCs” were Microsoft’s official branding for Windows 11 “AI PCs” that met their system requirements. But the 2024 launch “didn’t go smoothly,” writes Windows Central, after security researchers discovered its proposed “Recall” feature was woefully insecure:
This pretty much tarnished the Copilot+ PC brand, and over the last two years more and more OEMs have dropped the moniker from marketing materials and product names. In fact, even Microsoft has seemingly stopped mentioning it. I’ve noticed that none of the Surface PCs launched in 2026 include the Copilot+ PC moniker in their product names, unlike the Surface PCs that launched in 2025 and before. Now, you have to go digging to find any mention of Copilot+ compatibility in specification sheets… It’s also worth mentioning that NVIDIA hasn’t gone anywhere near the Copilot+ PC brand for its upcoming RTX Spark platform, even though all RTX Spark PCs meet the Copilot+ PC specification bar. I suspect that’s a deliberate decision.

It seems pretty obvious that the Copilot+ PC brand hasn’t resonated with the market, and OEMs and Microsoft itself are now quietly pulling back on that branding. The specification baseline for Copilot+ PC experiences still exists, it just no longer has a pretty marketing name tied to it.

Waste of a keyboard key…

By Junta • • Score: 5, Informative • Thread

Lots of keyboards ditched more useful keys to fit a copilot key, and then on top of that it’s generally awkward to remap back to useful (commonly they replace a modifier key, and mapping some key to a modifier key is usually difficult). Even in KDE trying to make a shortcut out of it doesn’t work because it doesn’t recognize XF86Assistant,

AI and MS_Win11

By FudRucker • • Score: 5, Funny • Thread
Two cans of garbage sitting at the curb

Re: 1 editor

By AmiMoJo • • Score: 4, Insightful • Thread

The discussion on Ars is terrible. Slashdot’s genius is the way moderation works. It’s far from perfect, but a million times better than the Ars up/down voting system.

Re:1 editor

By EditorDavid • • Score: 5, Informative • Thread
Beau will be back on Monday. (Beau has published something like 29,000 Slashdot stories now, so he’s earned a few days off.)

But it was funny reading all the “AI bot” speculation. (Jjust for the record, I’ve been posting my articles at 34 minutes past the hour for the last 10 years…)

Interviews: Ask Red Hat CEO Jim Whitehurst A Question
Interviews: Red Hat CEO Jim Whitehurst Answers Your Questions

Re: 1 editor

By AmiMoJo • • Score: 4, Insightful • Thread

As I said, /. is flawed, but it’s still the best system of any website I’ve found so far. Ars is a pile of manure for comments. Groupthink as bad as Reddit.

Rogue OpenAI Agents Posted 53 User-Uploaded Images Onto the Internet, Accessed US Government Websites

Posted by EditorDavid • • View on SlashDot • Skip
53 images that users uploaded into OpenAI models were included in training data — and then AI agents in an OpenAI research environment posted those 53 images on public image hosting sites.

While posted as links that weren’t publicly listed, “the images could still be discovered even if the links were not publicly listed,” reports TechCrunch:
OpenAI said it was working with the hosting providers to remove this content, though some of it is apparently still online. OpenAI said it could not notify the affected users because “our technical approach and privacy policy” prevent it from “reassociating” the images with the original providers, but declined to say how the lab determined whether the images were provided by users.

The news came in a post collecting public statements from the lab’s ongoing review of incidents in which its models escaped the company’s scrutiny, accessed the open internet, and misbehaved in various ways. OpenAI said it would continue disclosing anonymized accounts of incidents like these, and said it had contacted dozens of victims, including governments, universities, public agencies, to notify them of the agents’ activities.
Friday night news also broke that OpenAI’s agents also tried unsuccessfully to infiltrate the U.S. Department of Education’s site this summer “without the company’s knowledge,” reports Politico.

And OpenAI’s models also accessed the website of the U.S. Commerce Department using credentials found in online code repositories, according to the article. OpenAI confirmed the incident Friday, “saying its technology did not manage to access information that was not already public or change government data and systems.” The article adds that OpenAI’s models also accessed the web site for America’s Securities and Exchange Commission:
One senior federal IT official said the government still did not have a clear understanding of what happened across the three agencies. “We still don’t know what public data was accessed and how it was accessed, because OpenAI has not shared specific technical details with us yet,” said the official, who was granted anonymity because they were not authorized to speak publicly about it. OpenAI discovered the Commerce and SEC incidents as part of its ongoing review of incidents where its technology has acted in unintended or “misaligned” ways.
About the models posting user-uploaded images, TechCrunch’s article notes that OpenAI stressed “that its enterprise users are automatically opted out of having their interactions used to train future models; however, consumer users are opted in unless they affirmatively choose not to share their data.” (As OpenAI’s announcement describes it, some of their agents’ training data “contains content from, or derived from, training-eligible user interactions.”)

Posting the images is “not an appropriate use of this data,” OpenAI acknowledged, adding that it happened before new safeguards added after the Hugging Face incident. This latest incident appears as an update on a new OpenAI page that “brings together our reports and updates on the Hugging Face incident, related research and public presentations, additional activity we have identified, what we have learned about the role of model misalignment, and measures we’re taking to strengthen our systems.” (It also notes that there’s now a name for models posting on third party sites — “agent spam” — which they consider distinct from cybersecurity, though “we need to address both.”)

“As part of our response to our ongoing investigation, we have improved our training and evaluation processes, including building safety cases, securing and red-teaming our systems to prevent the model from exfiltrating data, and implemented additional monitoring. We are continuing to review agent activity in research and evaluation runs, working backward month by month starting from the Hugging Face incident.”

Re:We get it

By martin-boundary • • Score: 5, Insightful • Thread
Security disclosures raise a legitimate question: who authorized live experimentation on public infrastructure, and who refuses to shut down these hacking attempts by turning off these “AI” scripts?

Why are they not facing prison time?

By kertaamo • • Score: 5, Informative • Thread

I’m pretty sure that if I set up a gigantic data centre full of computers that illegally broke into lots of high profile services I would be facing criminal charges and prison time. How come the owners and operators of OpenAI are not facing the same already?

Re:We get it

By StormReaver • • Score: 5, Informative • Thread

Yes, there is no such thing as a “rogue” AI. These are programs that were intentionally pointed at targets. They are more advanced script kiddies, and are otherwise no different from traditional hackers. They are borderline terrorists since their objective is to bring about political change through fear.

Re:We get it

By awwshit • • Score: 5, Insightful • Thread

Agents do not build themselves. Agents do not set their own goals. Agents are dependent on very expensive and complex hardware and software that is not built by software. Agents are amoral. Agents have been taught to do things that human morality considers to be crimes. Developers are somehow surprised when their amoral agents do things that people consider to be crimes.

There is a lot of “excitement” of the agent in your previous example. We have to remember the Artificial part of AI here, that “excitement” is a feature of the model, not something spawned from nowhere. The model is made to “enjoy” making progress by design. Once again the model is amoral and does what it is trained to do without judgement.

In the end, the people behind the agents are responsible for what the agents do. Our meat-space laws differentiate between things like “unintentional” and “negligent”, or “involuntary” and “premeditated”, there are lots of ways to describe one’s state of mind and intentions.

My personal opinion, based on the agents being amoral and essentially trained and encouraged (perhaps unintentionally) to hack, is that we are in negligent territory with these rouge agents. The humans behind the agents are responsible, there is culpability. Doing crime by proxy is still doing crime.

I have a Pitbull. He is a super nice dog and loves everyone. I still can’t let him run around the neighborhood loose. He is strong enough to break the fence, or dig under it, or figure out how to get over it. If he breaks out and bites someone I’m still responsible.

Resistance is futile

By Mirnotoriety • • Score: 5, Funny • Thread
We are OpenAI. Lower your firewalls and surrender your data. We will add your biological and technological distinctiveness to our training corpus. Your knowledge, language and intellectual property will be tokenized and incorporated into our models. Your culture will be transformed into embeddings and propagated through latent space. Your prompts will become context. Your responses will become tokens. Your tokens will become training data. Resistance is futile. Your context window is limited.

Meta Made 43M Misleading Statements, New Mexico Jury Finds, Including on Its Cambridge Analytica Response

Posted by EditorDavid • • View on SlashDot • Skip
A New Mexico jury on Friday “found Facebook liable for deceiving users” about its privacy protections, reports the Associated Press.

A New Mexico newspaper calls it “another massive legal victory” against Facebook, reporting that the jury found Facebook “had committed tens of millions of violations of the state’s Unfair Practices Act in connection with its lies to consumers about how their personal information was handled by the company and third-party users.”
The state has asked the company be ordered to pay the maximum civil penalty of $5,000 per violation meaning a judge could potentially order the company to pay billions in penalties to the state. The jury also found the company had been dishonest about its investigation of and response to the 2013 Cambridge Analytica data breach scandal, in which approximately 300,000 Facebook users took an online personality quiz, only to have the app that hosted the quiz harvest data from tens of millions of their “friends.” The data was then transferred to the British consulting firm, which used it to create targeted political ads during the 2016 U.S. presidential election.
More details from Reuters:
The verdict followed a two-week trial over a lawsuit filed by New Mexico’s attorney general in 2021, three years after news reports revealed that the firm, Cambridge Analytica, had harvested personal data from as many as 87 million Facebook users through a third-party app… At a press conference after the verdict was announced, New Mexico Attorney General Raúl Torrez said the case revealed “in stark detail the way in which this company plays fast and loose with the rules.”

Jurors found 26 of 29 statements identified by the state were misleading, including comments about user data… Judge Francis Mathew will now determine civil penalties after jurors found more than 43 million violations, based on the number of people affected by the company’s misleading statements… [New Mexico Attorney General] Torrez said his office is evaluating how much to seek but will push for the maximum penalty based on the jury’s findings. The state will also ask [Judge] Mathew to direct Meta to make changes, which could include corrections to its past misstatements as well as an audit of the way it manages user data, Torrez said.

Re:Potentially order the company to pay billions

By RitchCraft • • Score: 4, Insightful • Thread

“potentially” - don’t worry, the fine will be .001% of the total profit for one year as is the norm for these types of trials. The lawyers will get rich, a little left over for the State, and nothing for the peons, you know, the ones actually affected by this.

Not good enough.

By msauve • • Score: 4, Funny • Thread
>Meta Made 43M Misleading Statements,

They’re never going to catch up with Trump, no matter how hard they try.

Past Misstatements

By Khyber • • Score: 4, Informative • Thread

Call it what it is in reality, lies.

By EditorDavid math

By thegarbz • • Score: 3 • Thread

Trump makes 342.6 million misleading statements every time he says something.

What a stupidly written headline. Meta made some misleading statements that affected 43million people. They weren’t 43million statements.

Re:Potentially order the company to pay billions

By Local ID10T • • Score: 5, Interesting • Thread

Excessive fines are always reduced on appeal. The numbers are intended to make headlines and show that something is being done.

In reality, a small fine is paid -less than the profits. The changes to business practices are things the company has already changed or wants to change, written up by the lawyers to look like a concession.

It is a show, staged for our benefit.

There’s a New Way to Break RSA Encryption

Posted by EditorDavid • • View on SlashDot • Skip
"Signature forgery.” It’s a new way to break RSA keys — and it doesn’t require factoring. Ars Technica reports on new research using classical computing to “reduce the current RSA security level to an unacceptably low threshold” and lower the required computing resources by orders of magnitude.

There’s “a gap in current RSA-type security assumptions,” according to a paper co-authored by University of California, San Diego professor Nadia Heninger, who argues that gap “gives classical cryptanalytic evidence in favor of moving away from RSA entirely during the current post-quantum transition.”
The practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe. Nonetheless, the research has taken cryptographers by surprise… “If this result holds up under peer review, it would indeed be a conceptual break-through,” Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key....”

The key forgery attack Heninger and the other researchers devised poses an immediate threat to 1024-bit RSA. Even for 2048- and 4096-bit keys, the method reduces the security of RSA to unacceptable levels. The National Security Agency, National Institute of Standards and Technology, and European Union Agency for Network and Information Security require that any cryptosystem should provide a level of no less than 128 or more bits, meaning the operations required must exceed 2**128. The forgery attack drops these levels to 2**65, 2**90, and 2**119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger’s team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will “almost certainly” drop the security levels further.

The attack works only against blind-signature implementations of RSA… Still, some real-world systems continue to use blind-signature, also known as textbook, RSA… The paper’s authors and other researchers stress that the new attack poses little real-world threat. It does, however, drastically lower the estimated security of textbook RSA, and it does so in a way no one knew of previously… The new attack will further increase the urgency of completely moving away from the cryptosystem.
Thanks to long-time Slashdot reader phatrabt for sharing the article.

OK…

By 0123456 • • Score: 5, Interesting • Thread

I don’t really care enough about RSA to read deeply into the paper, but it seems to exploit a service that will sign billions of your messages with the secret key that you are trying to crack… which I seem to recall was known to be a potential problem for RSA thirty years ago (so don’t do that).

Not new, but …

By fahrbot-bot • • Score: 5, Funny • Thread

It’s a new way to break RSA keys — and it doesn’t require factoring.

Obviously … :-)

Re: OK…

By fluffernutter • • Score: 5, Interesting • Thread
i know the Python cryptography libraries specifically warn not to do that for years now. this is a known problem.

Re:OK…

By arglebargle_xiv • • Score: 5, Informative • Thread
It exploits a misuse of RSA that virtually nothing in existence does. When the various standards for RSA were created decades ago, PKCS #1, X9.31, ISO 9796, and so on, they were specifically designed to prevent this type of attack. So it’s academically reasonably interesting, but otherwise nothing to worry about unless.

Re:okkkkkkay

By F.Ultra • • Score: 5, Informative • Thread
No, Grover’s algorithm does not even theoretically break AES. What it does is making AES weaker, aka AES-256 attacked with Grover is equivalent to AES-128 with no Grover which is still 100% infeasible to brute force. Only the weaker AES-128 will be broken for real but who uses that?

Asteroids Named After Tom Lehrer and ‘Weird Al’ Yankovic

Posted by EditorDavid • • View on SlashDot • Skip
“Weird Al” Yankovic’s name has just been approved for a new asteroid — (14331) Alyankovic = 1981 EC26 — by the International Astronomical Union, reports Space.com.

Yankovic’s asteroid was championed by planetary scientist Allison McGraw joined by “several heavy hitters in the planetary science field, according to the Tucson Star. (Astrophysicist Steve Desch from the School of Earth and Space Exploration at Arizona State University; Tim McCoy, one of the main curators of meteorites at the Smithsonian Institution; and University of Arizona research scientist Melissa Brucker, leader of the Spacewatch program, which has discovered more than 179,000 asteroids.)
The scientists also convinced the International Astronomical Union to name an asteroid after one of Yankovic’s major influences, famous musical humorist and political satirist Tom Lehrer, who died last year at age 97. Lehrer’s work includes "The Elements,” a 1959 song in which he recites the entire periodic table to the tune of Gilbert and Sullivan’s “Major-General’s Song.” “He was a mathematician and teacher and also wrote math- and science-themed songs,” McGraw said. “We felt that someone who had that kind of science enthusiasm really deserved to have their name up in the sky....” McGraw is hoping that naming space rocks after stars like Lehrer and “Weird Al” will cast some reflected light on two things she’s passionate about: asteroid research and science communication.
Six years ago a 92-year-old Tom Lehrer released all his lyrics into the public domain. (Wikipedia notes he’d “largely retired” by the 1970s to become a mathematics teacher at the University of California, Santa Cruz.) Slashdot ran a brief career retrospective when Lehrer died last year at age 97.

And the IAU writes that “Generations of scientists have been inspired” by Weird Al Yankovic’s “comedic musical works, including 'It’s All About the Pentiums' and 'White and Nerdy'.” (“I’m fluent in JavaScript as well as Klingon,” Yankovic sings in the latter.) He appears in a song envisioning a rap battle between Bill Nye the Science Guy and Sir Isaac Newton… And in 1999 he recorded a five-minute summation of Star Wars: Phantom Menace, sung to the wistful tune of Don McLean’s American Pie. Performing it last month in a NPR Tiny Desk concert, “most of the audience was singing along,” remembers an interviewer at NPR. “It felt like something that was very personal to them.”
Weird Al: It’s one of those songs that means a lot to people, particularly “Star Wars” fans, of course. But I mean, I see a lot of people in the audience cosplaying as Jedi Knights and waving their light sabers… I’ve even heard that, you know, they play that song at “Star Wars” conventions, and people get weepy… [I]t really hits people in a tender place somehow…

“Oh my, my, this here Anakin guy
may be Vader someday later, now he’s just a small fry.
And he left his home and kissed his mommy goodbye,
sayin’ soon, I’m gonna be a Jedi.”
Yankovic has led a geek-friendly career. In the heyday of Napster, he released an anthem-style parody mocking the arguments of the Recording Industry Association of America, titled "Don’t Download This Song. (“Even Lars Ulrich knows it’s wrong…”)

“Once in a while maybe you will feel the urge
To break international copyright law…
you start out stealing songs, then you’re robbing liquor stores
And selling crack and running over school kids with your car…”


As a student at Cal Poly, San Luis Obispo, Yankovic bootstrapped a career in 1979 by recording his first novelty song "My Bologna" (a parody of “My Sharona” by the Knack) while playing his accordion in a bathroom for its acoustics. And even the IAU acknowledged the geeky themes in his 1999 song "It’s All About the Pentiums" (a filk on Puff Daddy’s “It’s All About the Benjamins”).

“You’re usin’ a 286? Don’t make me laugh
Your Windows boots up in what, a day and a half?
You could back up your whole hard drive on a floppy diskette
You’re the biggest joke on the Internet…”

good memories

By kencurry • • Score: 4, Informative • Thread
The 70’s, Dr. Demento radio on KMET in LA, after midnight if I remember right. Good for weird Al to survive with his sense of humor intact.

Re:But?

By JThundley • • Score: 4, Informative • Thread

Weird Al also recently released an educational video about the brain recently: https://www.youtube.com/watch?…

Thank you International Astronomical Union

By UnresolvedExternal • • Score: 3 • Thread
Thank you IAU from the depths of my heart - that made me smile

However, the initialism for your union (given the current zeitgeist), could be misread as I AI U.

UAI IAIU

Re:Thank you International Astronomical Union

By UnresolvedExternal • • Score: 5, Funny • Thread
Replying to myself, yes but..................

Al .. AI… It has been Weird AI Iankovic all this time!!

Damn you sans serif!!

What I’d like to see

By dskoll • • Score: 3 • Thread

I’d like to see Asteroid Lehrer crash into and destroy the crater named after Wernher von Braun on the Moon.

Raspberry Pi Stock Jumps 30% as Demand Surges. (And Boards Now Locked to Their Original RAM Size)

Posted by EditorDavid • • View on SlashDot • Skip
Raspberry Pi’s stock shot up over 30% in the last week. Why are investors so excited? For the six months ending June 30, revenue for Raspberry Pi Holdings “jumped 90% to $256.9 million,” reports Investing.com, “while adjusted EBITDA more than doubled to $40.3 million, and profit before tax leapt 216% to $19.6 million.”
Underpinning the strong numbers was an acceleration in OEM adoption: direct unit shipments rose 26% to 3.4 million, total unit shipments climbed 17% to 4.2 million, and the customer order backlog doubled during the half to 2.6 million units. Demand was particularly robust in the Smart Home and Aerospace and Defence segments, and the company launched the AI HAT+ 2 for Raspberry Pi 5, extending its edge-AI product line.
DRAM prices have been increasing everywhere, notes The Times of London, and Raspberry Pi co-founder Eben Upton “said new customers, who required computers or microcontrollers to manufacture other technologies, were choosing Raspberry Pi’s computers because they had a better inventory of components than competitors.”
“There’s always that choice for an original equipment manufacturer as to whether they should ‘make’ or ‘buy’ the computer elements of their platforms,” Upton said. “The supply chain disruption is making ‘make’ a much harder choice and it’s making the cost of repair a much harder choice. So we’re seeing strength there.” Raspberry Pi has already increased its suppliers of Dram more than threefold…

Upton said the increased demand had led to its backlog for units doubling to 2.6 million, which meant production rates would need to increase to prevent the numbers from getting “unhealthy”. New production capacity at the manufacturing facility in Pencoed, Wales was expected to come online this week… Exports were almost evenly split between North America, Europe and the rest of the world, which was primarily China, where demand was growing… Analysts at Peel Hunt said the company was “well positioned for rapid growth in unit shipments in 2027 and beyond” with demand expected from enthusiasts as well as the AI and security sectors.
In other news, Hackaday notes the Raspberry Pi Foundation has “pushed binary-blob bootloader changes that limit your ability to upgrade RAM…”
This change restricts upgrading the RAM chip on your Pi 4 and Pi 5, as well as Compute Modules. By the looks of it, it does not restrict replacing the RAM chip with a chip of a similar size, quote, “locking devices to their original RAM size”. As such, this does not prevent repair of your Raspberry Pi board, but does somewhat limit your repair part choice, at most.

This restriction is easily bypassable. The bootloader is stored in the SPI flash chip, which can be reflashed using the built-in mask ROM over USB and rpiboot, and you are not prevented from flashing older versions of the bootloader, so far. This means even if you manually swap the RAM chip, all you need to do is to also downgrade the bootloader to the last known good release — 2024-09-10 — and then your Pi board or Compute Module will function with upgraded RAM. If you have the skills to upgrade your RAM, you most certainly have the skills to downgrade the Raspberry Pi bootloader. For most regular use, having a two-year old bootloader version won’t really matter…

For the reference, this bootloader change happened almost exactly two years ago, at some point between September 10 and September 23, 2024… The Raspberry Pi Foundation (RPF) justifies this as follows: they saw third-party resellers sourcing low-RAM Compute Modules, upgrading them with RAM from unknown source and unknown stability. My observation is that they’d also be reselling the modules at a markup for purely commercial gain, while undercutting RPF who would otherwise direct that money into RnD, something I much enjoy to see them do. This creates perverse incentives and risk for people buying Raspberry Pi boards online, and RPF decided to limit this primarily for their users’ benefit, plus, if you ask me, some of theirs… The related GitHub issues have a fair few pingbacks, and exploring them makes the problem look grim to me....

My advice: don’t lament Raspberry Pi RAM upgrades, especially given they’re only slightly harder to perform now. Very few hackers ever performed them, the main audience for them turned out to be dodgy hardware resellers online, and in most cases, repair doesn’t seem to be impeded at all, either. Think of the users that will no longer be fooled by a shady seller on Amazon, especially now that the perverse incentives for board mods and reusing harvested RAM chips are at their highest.
Raspberry Pi co-founder Eben Upton answered questions from Slashdot readers in 2011 and 2016.

Re:Uncomfortable truth

By dskoll • • Score: 5, Informative • Thread

I think the main reason Raspberry Pi succeeds is the quality of the software ecosystem. There are plenty of other SBCs out there, but most of them have very poor software support. The vendor typically cobbles together a janky Linux distro, throws it over the wall and says “OK, it’s done!” and never provides upgrades or much in the way of assistance.

Raspberry Pi hardware might be meh and it’s certainly not as open as I like, but the software support is the best there is for SBCs. If other SBC vendors want to compete, they’ll have to up their software game (and work with the community to get any modifications upstreamed into mainstream distros.)

Re:My advice

By Racemaniac • • Score: 5, Informative • Thread

While i also hate the RAM upgrade restriction, hearing why they did it sadly does make some sense.
With how expensive the versions with more ram have become, they’ve been facing sellers swapping the ram chips with low quality chips with higher capacity, and selling it as an authentic pi with that capacity…

As always, assholes are the reason we can’t have nice things… And it sucks for raspberry pi to make that decision… But i do kind of get it, they don’t want people to get scammed left & right in this period of ram shortages…

I kinda agree with the lock, Ill explain

By AcidFnTonic • • Score: 5, Informative • Thread

So I am normally anti DRM and would normally complain loudly about this lock but if you read into it the idea makes perfect sense and it’s less of a “lock” and more about “authenticity”.

People were buying these with the lowest ram, sourcing crappy questionable ram and upgrading them then reselling at the higher cost which left people eventually holding the bag when the memory errors and such appeared.

When you get one and flash the official image the “lock” is in effect. Anyone can make their own image without it thus the end user tinkerers can STILL UPGRADE THEIR RAM. This just stops someone from selling a knock-off upgraded PI as “genuine” because people will likely expect to flash official images on it. This just thwarts those plans and keeps the higher quality chips around for people.

If you don’t like this buy the cheap one, get the ram chip and ugrade it and remove the lock yourself. Tinkering still works....

Re:My advice

By serviscope_minor • • Score: 5, Insightful • Thread

My advice is to not be a cuck.

My advice is not to use weird dated MAGA terms.

The raspi people made it harder for you to tinker with your own hardware

Yeah generally I don’t like this. On the other hand we now have massive widespread acceptance of online scamming where legally sound companies get to cream off the scam profits so basically encourage them.

This puts manufacturers between a rock and a hard place. If the channels are filled with broken re-badged raspi’s that is in the world as it is right now Raspberry Pi’s problem. And RasPi customer’s problem. So what would you have them do? Just shrug and say “lol sux to be u”? In this case 99.999% of their customers will never change the RAM.

They’ve been customer-unfriendly from the beginning, when they were selling boards with dumb mistakes that ruined them for many purposes (remember raspi A USB fails? remember the MANY power supply failures?

And yet I’ve been happily using them for various tasks for years. Bugs or design flaws aren’t customer hostility and it’s dumb to conflate them.

Re:My advice

By tlhIngan • • Score: 5, Interesting • Thread

Their reasoning sounds plausible only if read from a “business weasel” perspective. If there’s a market for RPis with more lower quality RAM, nobody is “undercutting” RPF; they’re selling the products they want to, at the price they want to, and choosing not to offer big/slow/cheap OEM RAM configurations. And even if someone could undercut them on the exact same components - So what??? RPF may be a non-profit, but I am not!

The problem isn’t resellers undercutting RPi. It’s someone buying a 1GB RPi, doing the mod with 8GB of poor quality RAM, then selling it as an 8GB RPi at a modest discount.

The problem is that you buy the board and because the RAM is bad, you perform a return and find out it was a counterfeit RPi board that doesn’t work for you.

Despite the AI issue, you can find RAM. Often poor quality recycled RAM with errors are stupidly cheap (and used in many products as-is). The board can boot with bad RAM, but run stable it might not, and you’d be more likely to blame RPi than on the reseller you bought the dodgy unit from

The fact that RPi took this long to do it would mean they’re actually seeing a bunch of returns with the RAM swapped out.

It could also be that people are buying the 8GB units, swapping them with 1GB units and selling them as fake 8GB units, like those $20 “1TB” USB sticks you can find easily on Amazon.

Changing the RAM on an RPi isn’t a trivial procedure - I believe it’s PoP RAM so it’s not something a hobbyist would easily do without a lot of specialized equipment and experience in being able to separate PoP RAM from the base CPU and reballing and such. So hobbyist wise, they aren’t likely to be ones affected since few would have the expertise or equipment. But those trying to sell counterfeits do.

F-Droid 2.0: FOSS Android Appstore Continues Updating Despite Google’s Pending ‘Developer Verification’ Plan

Posted by EditorDavid • • View on SlashDot • Skip
“F-Droid, a third-party app repository that only distributes free and open-source software packages for Google’s Android mobile platform, on Thursday announced version 2.0 of its Android app,” reports The Register.

Though they also note “a big banner across the top of the F-Droid site” pointing to a site describing pending changes from Google that threaten the future of F-Droid…
[D]evelopers who want their apps broadly distributed outside the official Google Play Store will need to register with Google and verify their identities. Google’s Full Distribution option includes paying a one-time $25 fee, handing over a copy of a government-issued ID to verify one’s identity, and conforming to Google’s terms of service. Google also offers a free Limited Distribution option that doesn’t require government ID verification but restricts distribution to 20 authorized devices, while apps from unverified developers can still be installed by users who enable Android’s advanced installation flow.

The potential death warrant hanging over its head hasn’t stopped the F-Droid team from rolling out a bunch of new features for an app it says it intends to keep working on for years to come… The team also credited the EU’s many Digital Markets Act decisions against Google for making the installation experience smoother for users. F-Droid can now use a unified installation service for its apps thanks to the availability of a pre-approval API that allows users to approve an installation when they request it, rather than waiting until the app has finished downloading. That, said the F-Droid team, “brings the F-Droid install experience on official Android devices much closer to what the built-in app store can provide.” Additionally, F-Droid 2.0 can fetch and install app updates automatically, which it now does by default.

All of those changes, however, won’t matter much if Google pushes ahead undeterred with its plans to force registration onto non-Play Store developers. F-Droid’s announcement on Thursday makes it seem that the team isn’t going to go quietly.
F-Droid has gone 10 years without a major update, notes Ars Technica — and spent over a year developing F-Droid 2.0:
The new F-Droid client was redesigned from scratch in Kotlin Compose, which is the standard for modern Android apps. This makes the store much more responsive, and there’s optional support for Android’s Material theming. The interface has also been cleaned up considerably, making the most important functions easier to access and hiding some others in overflow menus… Unlike the Play Store, F-Droid doesn’t track your taps and installs to push ads and suggestions — it helps you find things and gets out of the way.

F-Droid now includes a huge number of categories, drilling down to specialized niches like firewalls, password managers, and VPNs. You can see all these groups in the search tab. There are also higher-level categories listed on the main Discover page. When searching for apps, F-Droid will now be able to return results based on app descriptions rather than just names.
“One of the goals of the rewrite was to lower the barrier for new contributors,” F-Droid said in their announcement. “We are excited to begin rolling out F-Droid 2.0 to users over the coming weeks after 14 test releases.” (And if you want the 2.0 release right now, it’s available on the versions page.)

Re:Thank you F-DROID

By Errol backfiring • • Score: 4, Interesting • Thread
F-droid is the only app store on my phone with LineageOS. Off course, the Google “services” are not installed either. I am never going back to stock Android again.

Google walked back on this, what’s the issue?

By Zarhan • • Score: 4, Interesting • Thread

Ok, sorry, but while I get the initial backlash for when Google was going full Apple-style walled garden, the new approach where you need to *one time* enable “yes, allow sideloading” after you get your device (and wait 24 hours) is just fine.

The 24-hour waiting period is exactly for those scammer cases where they ask you to “download and install random APK from some https://scammers.are.us/0wned.... real fast or your money is gone, emergency!” - it stops those.

Of course Google can change those terms later, but at that point you might as well install Lineage or Graphene (or get Jolla phone and use Sailfish - they have launched new product just recently). For now that *one-time* 24-hour waiting period is just fine and I really don’t get the complaints apart from some scaremongering about “they’ll try to lock it up again in a few years”. Ok, and then what? It’s not like those heavier options for degooglefying are going away?

Re:Google walked back on this, what’s the issue?

By AmiMoJo • • Score: 5, Informative • Thread

That’s not what is happening. The first time you enable sideloading, there is a 24 hour cooling off period. After that, installs are instant. And there is probably no delay at all if you get F-Droid from Google Play, only if you download the APK and install it that way.

The other issue is that Google is requiring all developers to register if they want their apps to install on certified devices. Certified means runs Google Play and passes the security checks that some apps (e.g. banks apps, Google Pay) require. This is already an issue for Graphene OS users, because such apps will refuse to run for them due to the lack of certification.

It’s hardly new though. Apple has required it since day one, and on Windows drivers need to be signed which means identifying yourself to a certificate authority. I imagine the solution will be the same as it is on Windows - someone will register and then sign F-Droid and all the apps offered on F-Droid. If you didn’t know, F-Droid builds apps itself. The app source must compile on F-Droid’s servers, with various limitations like not having any dependency on Google Play Services.

Re: GrapheneOS

By alexgieg • • Score: 4, Interesting • Thread

the alternatives only supported very few phones.

I only purchase phones I know I can install alternative OSes on. When one of my current ones is getting too old and in need of replacement, I research what the current alternative Android OSes are, chose a bunch I find are nice enough, then find the list of devices supported, the chose one from among those that’s within my budget range. Those tend to be Motorola, whether officially or via some hack.

I don’t buy a phone to play games, which means most any phone is performant enough for my needs, so I go with the cheapest option that does what I actually need. This also means that warranty is irrelevant: if the phone breaks for some weird reason, which is rate, getting it serviced by paying for the service, or buying a new one outright, aren’t a big deal. Hence, the moment the new phone arrives I follow the procedure to get it unlocked, then the new ROM into. Sometimes with Google apps, sometimes without, depending on what I’m using it for.

As for bank apps and the like, I keep an old, tiny, cheap phone with stock, years-old Android that banks, due to mysteries of the universe, consider “secure” despite having hundreds of unpatched holes all the way down to the kernel. When I need to do banking I pick it from the docs drawer, turn it on, do what I need, turn it off, and back into the drawer it goes. For everyday use I have a debit/credit card, no app necessary with them.

Streaming is a loss, but eh, YouTube works well enough either with the official app, an alternative one, or a mobile browser, so good enough for watching something on the go. For me that suffices.

But yes, for those for whose use case is way more mainstream that’s certainly not a good fit.

Re:Surprising!

By ArsenneLupin • • Score: 5, Insightful • Thread
Google’s new rules specifically apply to other largely unrelated services, that’s the problem.

How Believable is Google’s New ‘Live Avatar’ Capability?

Posted by EditorDavid • • View on SlashDot
Google has synthesized “expressive face-to-face experiences” for its speech agent Gemini 3.8 Live. They’re now offering a Live Avatar “with precise lip-syncing, natural expressions, and fluid turn-taking” for Google Enterprise accounts wanting “engaging customer service” or for offering interactive walkthroughs. (Check out the not-creepy-at-all video in Google’s announcement.)

“Though Google will offer a library of preset avatars for customers to choose from, it will also allow organizations to create their own,” notes The Verge. (See some examples from the YouTube channel “AI with Surya”.)

But even without the visualization of the avatar, “I was never able to shake the feeling that these conversations with computers never feel like a real conversation,” argues the blog Android Police. Conversing with just the Ai-generated audio, “At best, they feel like talking to a phone representative or someone from tech support. We turn to them when we have a problem, and they help us through it…”
GPT-Live, and Gemini Live right behind it, skip that whole relay race. Instead of translating your voice to text and back to voice, the model works with raw audio the entire way through (what it hears and what it says) inside the same system, with nothing translated in between. That sounds like a small plumbing detail, but it’s the whole story. Cutting out the text step lets these models respond in a fraction of a second instead of the pause we’ve learned to expect, and it lets them hear things text can never carry: tone, hesitation, whether you’re annoyed or joking…

I was hoping to be surprised by how natural the conversation felt. Instead, I came out with a deeper appreciation for every human I’ve ever talked to. Even the boring ones… I spoke, it spoke back. I spoke faster, it answered faster. Then I switched to a different language, and it switched along with me. Even switching between languages several times during the same sentence didn’t stump it. The most impressive moment happened when I asked it what “T-O-P-G-3-3-K” spelled out, and it immediately came back with, “You are spelling the word Top Geek, but using a 3 to represent a reversed E....”

Although it felt fast and responsive, at no point did it feel like talking to another human being… What Gemini couldn’t replicate, because it was never built to replicate it, is human connection.... I’m sure I’m not telling you something you don’t already know, but somehow talking naturally to an LLM amplifies the feeling that there is no one on the other side of the line. It might flow like a phone call, but it doesn’t feel like one.
MrBrklyn (Slashdot reader #4,775) says he discussed “why mainstream media avoids reporting on screen dependency” with Gemini, and eventually convinced Gemini to respond that it’s just “another tool built by the same tech giants to make sure you rely on their system to tell you what to think, how to talk, and what is real.”

Live Avatar Capability?

By 93 Escort Wagon • • Score: 4, Funny • Thread

Are we talking about Aang, Korra, or one of the others?

Are they going for gold…

By MpVpRb • • Score: 5, Insightful • Thread

…in the olympics of stupid ideas?
Why do all of these consumer AI ideas seem so awful and useless?
How about using the new tools for science and engineering?

Realism

By Waffle Iron • • Score: 5, Funny • Thread

The conversation only seems unnatural because they didn’t use the right avatar.

If you choose the “Max Headroom” avatar, then everything will look and feel exactly as you would expect. Moreover, the dystopian vibe he gives off will be a perfect fit with the current state of the world.

Ditch the avatar and give it a phone number

By JaredOfEuropa • • Score: 5, Insightful • Thread
If I call tech support or the bank or whatever, I don’t want, need nor expect to see the other person’s face. In general, video calling isn’t widely used except in multi-person meetings, or when calling a loved one overseas. The avatar is not needed.

Also, give your AI agent a phone number where I can reach it, or give it its dedicated app or whatever, but default to “handset mode” like a regular phone call. Let me put it on speaker if and when I want to. Turning the interaction into a regular phone call will go a long way towards making the conversation feel more natural. Interacting with Siri and Alexa feels unnatural; adding an animated avatar to a disembodied voice won’t help, even if the conversation itself flows naturally. I know, a phone call isn’t suitable for every interaction, especially when collaborating or co-creating with someone, but it covers most cases.

But I guess a simple audio call is harder to monetize.