×
Sony

New Sony Walkman Music Players Feature Stunning Good Looks, Android 12 (arstechnica.com) 48

Sony has a pair of new Android Walkmans out, the NW-A300 and NW-ZX700. Ars Technica reports: We'll start with the most consumer-friendly of the two, the NW-A300. This basic design debuted in 2019 with the NW-A105, but that shipped with Android 9. This is an upgraded version of that device with a less-ancient version of Android, a new SoC, and a scalloped back design. In Sony's home of Japan, the 32GB version is 46,000 yen (about $360), while in Europe, it's 399 euro (about $430). The NW-A300 is a tiny little device that measures 56.6x98.5x12 mm, so pretty close to a deck of playing cards. [...] The front is dominated by a 3.6-inch, 60 Hz, 1280x720 touchscreen LCD. There's 32GB of storage, and the device supports Wi-Fi 802.11AC and Bluetooth 5. That's about all Sony wants to talk about for official specs. It touts "longer battery life" but won't say how big the battery is, promising only "36 hours* of 44.1 KHz FLAC playback, up to 32 hours* of 96 KHz FLAC High-Resolution Audio playback." Presumably, that's all with the screen off. [...] This is a music player, so of course, there's a headphone jack on the bottom of the unit. You'll also find a spot for a lanyard, a speedy USB-C 3.2 Gen1 port for quick music transfers, and a MicroSD slot for storing all your music. Buttons along the side of the device also give you every music control you could want, like a hold switch, previous, play/pause, next, volume controls, and power.

There's another new Sony Walkman, the NW-ZX700. It's 104,500 yen ($818) in Japan, and while that sounds like a lot for a portable music player, it's actually a relative bargain compared to the "Signature Series" NW-WM1ZM2, which goes for an eye-popping $3,700 thanks to audiophile hocus-pocus like a "gold plated, oxygen-free, copper body." Anyway, back to this $800 model. Unlike regular phone equipment, this has a proper audio amplifier with big, beefy capacitors to power the analog audio output. That makes it much bigger than the A300, at 72.6x132 mm and a whopping 17 mm thick. It also has two audio outs: a standard 3.5 mm headphone jack and a 4.4 mm "balanced" audio jack, which is used by some high-end audio equipment. I'm sure Sony has a wonderful headphone collection to match. [...] Both this and the A300 use the S-Master HX digital amplifier chip, which supports Sony's high-resolution "NativeDSD" audio format, which is also used on Super Audio CDs. If you're some kind of heathen that is just streaming 128kb Spotify, Sony's "DSEE Ultimate" feature dubiously claims to be able to "upscale" your music with AI. There's also a "Vinyl Processor" that will add record player noises to your audio for an "authentic listening experience."

Microsoft

Microsoft 365 Basic is a New $1.99 a Month Subscription With 100GB of Storage (theverge.com) 63

Microsoft is introducing a new consumer tier to its Microsoft 365 subscription offerings. From a report: Priced at $1.99 per month, Microsoft 365 Basic is designed to replace the 100GB OneDrive storage option with some extra features that sit in between the free option and the $6.99 a month Personal subscription. Microsoft 365 Basic will be available worldwide on January 30th with 100GB of cloud storage, an ad-free Outlook web and mobile experience, and enhanced security features. The security features include data encryption for an Outlook mailbox, suspicious link checking, and virus / malware scanning for attachments. Existing OneDrive 100GB storage customers will be automatically upgraded to Microsoft 365 Basic at the same $1.99 monthly rate. [...] The main difference between the $6.99 Personal subscription and this new $1.99 Basic one (other than the amount of cloud storage) is that Microsoft 365 Basic doesn't include access to the desktop versions of Word, Excel, and PowerPoint apps. Basic subscribers will have to use the web or mobile versions instead.
The Courts

Seattle Schools Sue TikTok, Meta and Other Platforms Over Youth 'Mental Health Crisis' 46

Seattle public schools have sued the tech giants behind TikTok, Facebook, Instagram, YouTube and Snapchat, accusing them of creating a "mental health crisis among America's Youth." Engadget reports: The 91-page lawsuit (PDF) filed in a US district court states that tech giants exploit the addictive nature of social media, leading to rising anxiety, depression and thoughts of self-harm. "Defendants' growth is a product of choices they made to design and operate their platforms in ways that exploit the psychology and neurophysiology of their users into spending more and more time on their platforms," the complaint states. "[They] have successfully exploited the vulnerable brains of youth, hooking tens of millions of students across the country into positive feedback loops of excessive use and abuse of Defendants' social media platforms."

Harmful content pushed to users includes extreme diet plants, encouragement of self-harm and more, according to the complaint. That has led to a 30 percent increase between 2009 and 2019 of students who report feeling "so sad or hopeless... for two weeks or more in a row that [they] stopped doing some usual activities." That in turn leads to a drop in performance in their studies, making them "less likely to attend school, more likely to engage in substance use, and to act out, all of which directly affects Seattle Public Schools' ability to fulfill its educational mission." Section 230 of the US Communications Decency Act means that online platforms aren't responsible for content posted by third parties. However, the lawsuit claims that the provision doesn't protect social media companies for recommending, distributing and promoting content "in a way that causes harm."
Medicine

Cryonics Company Charges a Monthly Subscription Fee (Plus Your Life Insurance Payout) (deccanherald.com) 192

"To date, about 500 people have been put in cryogenic stasis after legal death," writes a Bloomberg Opinion technology columnist, "with the majority of them in the U.S.

"But a few thousand more, including Emil Kendziorra, are on waiting lists, wearing bracelets or necklaces with instructions for emergency responders. " Kendziorra, 36, runs Berlin-based Tomorrow Biostasis GmbH, one of the first cryonics businesses in Europe to join a market dominated by American firms organizations like The Alcor Life Extension Foundation and The Cryonics Institute. The former cancer doctor has several hundred people on his firm's waiting list. They skew to their late 30s, male and tend to work in technology. Patients can choose to have their entire body preserved and held upside down in a four-person dewars, a thermos-like aluminum vat filled with liquid nitrogen, or just preserve their brain, which is cheaper.

Kendziorra says cryopreservation overall has become less expensive over the past few decades on an inflation-adjusted basis, a claim that he bases on historic prices published by his peers, who he says are making a collective effort to bring down costs. That could be critical to shifting cryonics from a fringe pursuit to something a little more mainstream, especially since it is no longer just for billionaires like PayPal Inc. co-founder Peter Thiel (who has reportedly signed up with Alcor). Kendziorra, for instance, has made cryonics just another monthly subscription by capitalizing on insurance, he told me during a Twitter Spaces discussion on cryonics last month. His customers pay a 25-euro ($26.54) monthly fee to Tomorrow Biostasis, and they also make the company the beneficiary of a minimum 100,000-euro life insurance payout upon their legal death. Kendziorra says that covers the full cost of cryonics including the biggest outlay: maintenance over the next century or so.

All told, most of his customers are paying about 50 euros a month for both the company's subscription fee and the life insurance policy for the option of a long sleep at death. Of course, most companies don't survive for more than a century, so Tomorrow Biostasis also partners with a non-profit group in Switzerland to carry out the storage of customers on its behalf.... The domain itself is largely funded by wealthy individuals including CEOs of tech companies, angel investors and scientists, Kendziorra says, adding that for them to invest in his own firm, their primary motivation shouldn't be "monetary" but rather to help further the field.

The mechanics all sound sensible, but that still leaves the question of whether cryonics will work, medically speaking. Doctors and scientists have used words like quackery, pseudoscience and outright fraud to describe the field. Clive Cohen, a neuroscientist from Kings College London, has called it a "hopeless aspiration that reveals an appalling ignorance of biology." The Association of Cryobiology has compared it to turning a hamburger back into a cow.

Encryption

Amazon S3 Will Now Encrypt All New Data With AES-256 By Default 27

Amazon Simple Storage Service (S3) will now automatically encrypt all new objects added on buckets on the server side, using AES-256 by default. BleepingComputer reports: While the server-side encryption system has been available on AWS for over a decade, the tech giant has enabled it by default to bolster security. Administrators will not have to take any actions for the new encryption system to affect their buckets, and Amazon promises it won't have any negative performance impact. Administrators may leave the system to encrypt at the default 256-bit AES or choose one of the alternative methods, namely SSE-C or SSE-KMS.

The first option (SSE-C) gives bucket owners control of the keys, while the second (SSE-KMS) lets Amazon do the key management. However, bucket owners can set different permissions for each KMS key to maintain more granular control over the asset access system. To confirm that the changes have been applied to your buckets, admins can configure CloudTrail to log data events at no extra cost. Then perform a test object upload, and look in the event logs for the "SSEApplied": "Default_SSE_S3." field in the log for the uploaded file. To retroactively encrypt objects already in S3 buckets, follow this official guide.
"This change puts another security best practice into effect automatically -- with no impact on performance and no action required on your side," reads Amazon's announcement.

"S3 buckets that do not use default encryption will now automatically apply SSE-S3 as the default setting. Existing buckets currently using S3 default encryption will not change."
Transportation

Mercedes-Benz Will Build a $1 Billion EV Fast-Charging Network In the US (arstechnica.com) 88

An anonymous reader quotes a report from Ars Technica: On Thursday, Mercedes-Benz announced that it is entering the DC fast-charging arena for electric vehicles. The German automaker is in the midst of an electrification push and a plan to be carbon-neutral by 2039, and it evidently doesn't believe that the current charging infrastructure is as good as its new EVs, so it's doing something about the situation. Mercedes says it plans to deploy more than 10,000 fast chargers around the world, starting in North America. The new network is separate from and independent of Ionity, the European fast-charging network backed by Mercedes, BMW, Ford, and Volkswagen. Here in the US, Mercedes is partnering with the charging company ChargePoint and MN8 Energy, a solar and battery-storage company. Together, they will deploy more than 2,500 DC fast chargers at more than 400 sites around the US by 2027.

The chargers will feature plug-and-charge compatibility and won't be restricted to Mercedes' EVs. Mercedes also says the locations and surroundings will be carefully chosen -- all too often, banks of DC chargers are located in desolate and lonely corners of mall parking lots that can make charging at night a stressful experience for some drivers. So the OEM plans to build the chargers "with food outlets and restrooms situated nearby." It also says there will be surveillance cameras and other security in place to provide "a safe and secure charging environment." Expect a minimum of four DC chargers at each hub, similar to an Electrify America charging location. But some hubs will have as many as 12 chargers, and there are plans for as many as 30 in some locations. The hubs will use ChargePoint's modular Express Plus system, which is capable of up to 500 kW per charging port, although Mercedes says that chargers will be "up to 350 kW" in power. And load management will ensure that if multiple EVs are charging at the same time, one charger doesn't end up throttling the rest.

In keeping with the company's 2039 sustainability goals, the electricity it uses will come from green energy suppliers or come with renewable energy certificates. Some hubs will use solar to power the lighting and security cameras. None of this will be particularly cheap. In fact, the initiative will cost more than $1.1 billion (1 billion euro) over the next six or seven years, with the costs split evenly between Mercedes and MN8 Energy. And this is just the start -- plans for more charger deployment in Europe and China will be announced in the future.

AMD

AMD Claims New Laptop Chip Is 30% Faster Than M1 Pro, Promises Up To 30 Hours of Battery Life (macrumors.com) 74

At CES this week, AMD announced a suite of new chips for notebooks and desktop computers, with one notable announcement being the company's new AMD Ryzen 7040 series of processors for ultrathin notebooks that will compete with Apple's M1 Pro and M2 chips. MacRumors reports: The AMD Ryzen 7040 series of chips are "ultrathin" processors based on the 4nm process, and the highest-end chip part of the family is the Ryzen 9 7940HS. The Ryzen 9 7940HS has eight cores, 16 threads, and 5.2GHz boost speeds. Announcing the new chip, AMD CEO Lisa Su made bold claims about its performance, saying it's up to 30% faster than Apple's M1 Pro chip. In specific tasks, AMD claims the chip is 34% faster in multiprocessing workloads than the M1 Pro and 20% faster than the M2 in AI tasks.

One cornerstone of Apple silicon is energy efficiency, and in that area, AMD claims the new AMD Ryzen 7040 series will offer 30+ hours of video playback in ultrathin notebooks. Built directly into the series of chips is Ryzen AI, a dedicated AI engine embedded in the processor. AMD chips configured with Ryzen AI are 20% faster in AI tasks than Apple's M2 chip while being 50% more energy efficient, according to the company.

To showcase the new chip's performance, AMD compared the performance of a high-end Intel chip, the M1 Pro, and its new Ryzen 9 7940HS processor rendering an object in the popular application Blender. In the time-lapsed video shown on stage, the M1 Pro lags behind the Ryzen 9 7940HS in rendering the object. AMD says it made its performance claims against a MacBook Pro with M1 Pro, 32GB of unified memory, and 1TB of SSD storage running macOS Monterey. The M1 Pro is not Apple's highest-end and most powerful chip for laptops, which is the M1 Max, and AMD did not compare its chip to the M1 Max.
After roasting the M1 Pro, Ian Zelbo from FrontPageTech noticed AMD running their CES keynote on multiple 14-inch MacBook Pros. "Obviously these are contracted employees, and it means nothing," he tweeted. "I just always find stuff like this hilarious."

We do too... It's akin to the "Twitter for iPhone" line on tweets that have gotten Android promoters in hot water multiple times over the past several years.
Bitcoin

Key Bitcoin Developer Calls on FBI To Recover $3.6M in Digital Coin (arstechnica.com) 119

One of the prominent developers behind the bitcoin blockchain said he has asked the FBI to assist him in recovering $3.6 million worth of the digital coin that was stolen from his storage wallets on New Year's Eve. From a report: Luke Dashjr is a developer of the Bitcoin Core, an app that runs 97 percent of the nodes making up the bitcoin blockchain. Bitcoin Core derives from the software developed by the anonymous bitcoin inventor who uses the pseudonym Satoshi Nakamoto. That software was called simply Bitcoin but was later changed to Bitcoin Core to distinguish it from the coin. Dashjr has been contributing to the Bitcoin Core since 2011 and has long championed the concept of decentralization that the cryptocurrency was founded on.

On New Year's Day, Dashjr took to Twitter to report that his entire bitcoin holdings -- worth roughly $3.6 million -- were "basically all gone." He said the hack stemmed from the compromise of a PGP (Pretty Good Privacy) key that he used to ensure that his downloads of Bitcoin Core and a smaller app known as Bitcoin Knots weren't laced with malware. He said all his computers were compromised and urged people to hold off downloading new versions for the time being. "So to be clear: DO NOT DOWNLOAD BITCOIN KNOTS AND TRUST IT UNTIL THIS IS RESOLVED," he wrote. "If you already did in the last few months, consider shutting that system down for now." In the same thread, the developer said he had contacted the FBI and police but hadn't received a response. "What the heck @FBI @ic3. Why can't I reach anyone???" he wrote. "I paid those taxes and the police don't care. What a scam."

Games

EA Says It Can't Recover 60% of Players' Corrupted Madden Franchise Save Files 63

An anonymous reader shares a report: EA says that a temporary "data storage issue" led to the corruption of many Madden NFL 23 players' Connected Franchise Mode (CFM) save files last week. What's worse, the company now estimates it can recover fewer than half of those corrupted files from a backup. The issue started last Monday, December 26, when EA tweeted that it was "aware of players experiencing connection issues when trying to connect to CFM." That problem lasted until Wednesday, December 28, when EA announced that subsequent server maintenance meant that "users should now be able to play CFM without issue."

But users who attempted to log in to play online franchise games during a 22-hour period ranging from Wednesday afternoon to Thursday morning saw their franchise save data corrupted by the aforementioned "data storage issue," as EA confirmed over the weekend. And while EA says some of those corrupted save files can be recovered from a backup, it adds that the development team is "currently projecting around 40% of leagues to be recovered." Players that didn't log in during the outage period last week should be unaffected, EA says, adding that CFM is now "up and running" and is "safe to log in and play." But the company offered a similar message on Wednesday afternoon, just before the period that led players who logged in to lose their save files in the first place.
Hardware

Alienware Goes Bigger and Taller With the X16 and M18 Gaming Laptops (theverge.com) 17

Alienware is unveiling a refreshed lineup of its M- and X-series gaming laptops at CES 2023. Like some other laptop companies, including Razer and Acer, Alienware is shifting focus away from 15- and 17-inch laptops toward thin, powerful 16- and 18-inch models. From a report: The brand is going big with the new M18, an 18-inch model that's being pitched as a desktop replacement. This is actually a resurrection following the M18's previous spec update way back in 2015. The 2023 model will feature Intel's 13th Generation HX CPUs and Nvidia's RTX 4090 mobile graphics card. The latest processors and graphics options from AMD will be available in the M18 later in 2023. Not only is the M18 massive and powerful -- it's a big deal in other ways. It can be configured with an 18-inch QHD Plus screen in the taller 16:10 aspect ratio and set up to include a ton of ports, including two Thunderbolt 4 ports, HDMI 2.1, Ethernet, an SD card reader, and many others. It supports user-upgradeable dual DDR5 RAM slots, and you can also cram up to 9TB of NVMe M.2 storage in it. This model starts at $2,099, but the first configuration it's releasing will cost $2,899.
Japan

In the Pacific, Outcry Over Japan's Plan To Release Fukushima Wastewater (nytimes.com) 141

The proposal has angered many of Japan's neighbors, particularly those with the most direct experience of unexpected exposure to dangerous levels of radiation. From a report: Every day at the Fukushima Daiichi nuclear plant in Japan, officials flush over a hundred tons of water through its corroded reactors to keep them cool after the calamitous meltdown of 2011. Then the highly radioactive water is pumped into hundreds of white and blue storage tanks that form a mazelike array around the plant. For the last decade, that's where the water has stayed. But with more than 1.3 million tons in the tanks, Japan is running out of room. So next year in spring, it plans to begin releasing the water into the Pacific after treatment for most radioactive particles, as has been done elsewhere. The Japanese government, saying there is no feasible alternative, has pledged to carry out the release with close attention to safety standards. The plan has been endorsed by the United Nations' nuclear watchdog.

But the approach is increasingly alarming Japan's neighbors. Those in the South Pacific, who have suffered for decades from the fallout of a U.S. nuclear test in the Marshall Islands, are particularly skeptical of the promises of safety. Last month, a group representing more than a dozen countries in the Pacific, including Australia and the Marshall Islands, urged Tokyo to defer the wastewater releases. Now, Japan is poised to forge ahead even as it risks alienating a region it has tried in recent years to cultivate. Nuclear testing in the Pacific "was shrouded in this veil of lies," said Bedi Racule, an antinuclear activist from the Marshall Islands. "The trust is really not there."

Security

The LastPass Disclosure of Leaked Password Vaults Is Being Torn Apart By Security Experts (theverge.com) 78

Last week, LastPass announced that attackers stole customer vault data after breaching its cloud storage earlier this year using information stolen during an August 2022 incident. "While the company insists that your login information is still secure, some cybersecurity experts are heavily criticizing its post, saying that it could make people feel more secure than they actually are and pointing out that this is just the latest in a series of incidents that make it hard to trust the password manager," reports The Verge. Here's an excerpt from the report: LastPass' December 22nd statement was "full of omissions, half-truths and outright lies," reads a blog post from Wladimir Palant, a security researcher known for helping originally develop AdBlock Pro, among other things. Some of his criticisms deal with how the company has framed the incident and how transparent it's being; he accuses the company of trying to portray the August incident where LastPass says "some source code and technical information were stolen" as a separate breach when he says that in reality the company "failed to contain" the breach. He also highlights LastPass' admission that the leaked data included "the IP addresses from which customers were accessing the LastPass service," saying that could let the threat actor "create a complete movement profile" of customers if LastPass was logging every IP address you used with its service.

Another security researcher, Jeremi Gosney, wrote a long post on Mastodon explaining his recommendation to move to another password manager. "LastPass's claim of 'zero knowledge' is a bald-faced lie," he says, alleging that the company has "about as much knowledge as a password manager can possibly get away with." LastPass claims its "zero knowledge" architecture keeps users safe because the company never has access to your master password, which is the thing that hackers would need to unlock the stolen vaults. While Gosney doesn't dispute that particular point, he does say that the phrase is misleading. "I think most people envision their vault as a sort of encrypted database where the entire file is protected, but no -- with LastPass, your vault is a plaintext file and only a few select fields are encrypted."

Palant also notes that the encryption only does you any good if the hackers can't crack your master password, which is LastPass' main defense in its post: if you use its defaults for password length and strengthening and haven't reused it on another site, "it would take millions of years to guess your master password using generally-available password-cracking technology" wrote Karim Toubba, the company's CEO. "This prepares the ground for blaming the customers," writes Palant, saying that "LastPass should be aware that passwords will be decrypted for at least some of their customers. And they have a convenient explanation already: these customers clearly didn't follow their best practices." However, he also points out that LastPass hasn't necessarily enforced those standards. Despite the fact that it made 12-character passwords the default in 2018, Palant says, "I can log in with my eight-character password without any warnings or prompts to change it."

Bitcoin

FTX's Sam Bankman-Fried Borrowed From Alameda To Buy Robinhood Shares (coindesk.com) 71

Former FTX chief Sam Bankman-Fried borrowed hundreds of millions of dollars from Alameda Research to purchase his stake in trading app Robinhood Markets (HOOD), according to court documents (PDF). CoinDesk reports: In an affidavit provided to a Caribbean court before his arrest, Bankman-Fried said he and FTX co-founder Gary Wang together borrowed over $546 million from Alameda via promissory notes in April and May. They used that money to capitalize Emergent Fidelity Technologies Ltd., the shell corporation that in May bought a 7.6% stake of Robinhood. The affidavit provides a new curveball in the three-way race to lay claim to the 56 million Robinhood shares. Crypto lender BlockFi, FTX Group and Bankman-Fried himself have all attempted to lay claim to the shares, which could be worth over $440 million.

Crypto lender BlockFi, which like FTX has filed for bankruptcy, alleged in a court document (PDF) that it was owed the rights to the Robinhood shares due to a deal Bankman-Fried made in early November. The shares were pledged as collateral against a loan taken out by Alameda Research -- the same firm whose funds were used to purchase the shares to begin with, according to Tuesday's filing.

Software

Ask Slashdot: What Note-Taking App Do You Use? 187

An anonymous reader writes: This column about a writer's struggle to find the perfect note-taking app resonated a lot with me. "A singular productivity tool that works for everyone is a unicorn -- beautiful, perfect, and completely fictional. Still, there has to be some sort of middle ground between an unachievable fantasy and the current landscape. I would happily settle for two, maybe three apps. Honestly, less than 10 is all I'm asking for. Until then, my phone and laptop will be a cluttered mess of productivity apps that only do half their jobs," writes Victoria Song.

Over the years, I have tried Notion, Apple Notes, the good old Windows' Notepad, Roam Research, Obsidian, Google Keep, Google Docs, and OneNote among possibly many more that I am unable to recall anymore. Some support Apple Pencil, which is one of the usecases I find useful. Roam Research did not even have a native app for mobile devices for the longest time. Some applications are good, but they don't support online syncing, or support syncing with only a particular storage service. And have you noticed just how expensive some of these apps could get? As much as $15-$30 a month! Out of curiosity, and forget my usecases -- as I admit I have not mentioned many -- how do you maintain your notes for work and personal life. (I have been using physical notepads a lot more in recent months but would like an app for digital notes.)
Microsoft

CNET Touts 'Massive' Microsoft Office Deal: 91% Discount on a Lifetime License (cnet.com) 80

Meanwhile, over in the Microsoft ecosystem, CNET reports: You can ditch the subscription (with recurring charges) and snag a lifetime license of access to Microsoft's Word, Excel, PowerPoint, Outlook, Teams, OneNote, Publisher and Access for just $30...

That's back at the lowest price we've ever seen, and a whopping 91% off the usual price of $349.

However, this deal expires in just a few days, so be sure to get your order in soon.The offer, from StackSocial, applies to both the Windows and Mac version of the software.

Now, you can always opt to use the free online version of Microsoft Office (which has far fewer features). But compared to the online Microsoft 365 subscription suite that costs $10 per month or $100 per year, this downloadable version is a phenomenal bargain.

The Mac deal ends today, but the Windows deal extends through December 28th, according to CNET's article. "The two big caveats: You get a single key — which only works on a single computer — and there's no Microsoft OneDrive Cloud Storage included."
Cloud

LastPass: Hackers Stole Customer Vault Data In Cloud Storage Breach (bleepingcomputer.com) 38

LastPass revealed today that attackers stole customer vault data after breaching its cloud storage earlier this year using information stolen during an August 2022 incident. BleepingComputer reports: This follows a previous update issued last month when the company's CEO, Karim Toubba, only said that the threat actor gained access to "certain elements" of customer information. Today, Toubba added that the cloud storage service is used by LastPass to store archived backups of production data. The attacker gained access to Lastpass' cloud storage using "cloud storage access key and dual storage container decryption keys" stolen from its developer environment.

"The threat actor copied information from backup that contained basic customer account information and related metadata including company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service," Toubba said today. "The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data."

Fortunately, the encrypted data is secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user's master password. According to Toubba, the master password is never known to LastPass, it is not stored on Lastpass' systems, and LastPass does not maintain it. Customers were also warned that the attackers might try to brute force their master passwords to gain access to the stolen encrypted vault data. However, this would be very difficult and time-consuming if you've been following password best practices recommended by LastPass. If you do, "it would take millions of years to guess your master password using generally-available password-cracking technology," Toubba added. "Your sensitive vault data, such as usernames and passwords, secure notes, attachments, and form-fill fields, remain safely encrypted based on LastPass' Zero Knowledge architecture."

Bitcoin

FTX Asks Judge For Help In Fight Over Robinhood Shares Worth About $450 Million (coindesk.com) 7

FTX sought a U.S. bankruptcy court's help amid a battle over ownership of about $450 million worth of stock in Robinhood Markets (HOOD), according to a filing (PDF) Thursday. CoinDesk reports: At issue are about 56 million shares of the brokerage owned by Emergent Fidelity Technologies Ltd., a corporate entity organized in Antigua and Barbuda and 90% controlled by former FTX CEO Sam Bankman-Fried, according to the filing. Three parties, the filing says, have tried to get control of those shares: BlockFi (a lender that FTX had helped prop up earlier this year), Yonathan Ben Shimon (an FTX creditor appointed as a receiver in Antigua and granted permission to sell the shares under supervision of a court there) and Bankman-Fried himself (who has legal bills).

FTX's bankruptcy estate told ED&F Man Capital Markets, the brokerage where the shares are parked, to freeze the stock around the time the Chapter 11 case began on Nov. 11. FTX has determined that Emergent only "nominally" owns the shares and that they truly belong to FTX. "Emergent is a special-purpose holding company that appears to have no other business," the crypto exchange said in the filing. The judge overseeing the bankruptcy case should force the shares to remain frozen while FTX tries to figure out how to repay all its creditors, FTX argued in the filing.

Desktops (Apple)

Apple Scales Back High-End Mac Pro Plans, Weighs Production Move To Asia (bloomberg.com) 33

An anonymous reader quotes a report from Bloomberg, written by Mark Gurman: The new high-end Mac Pro with Apple silicon is behind schedule, and you can blame changes to the company's chip and manufacturing plans. When Apple announced plans in June 2020 to transition away from Intel processors to Mac chips designed in-house, the company said the move would take about two years. Now at the tail end of 2022, it's clear that Apple has missed its self-imposed deadline for completing the shift. In addition to not offering a Mac Pro with Apple silicon, the company still only sells the high-end version of the Mac mini desktop in an Intel flavor. While Apple has said little to nothing about its future Mac desktops or the reasons behind the holdup, the company continues to actively test an all-new Mac Pro and an M2 Pro-based Mac mini to replace the remaining Intel models. Apple had aimed to introduce the new Mac Pro by now, but the high-end machine has been held up for a number of reasons, including multiple changes to its features, a significant shift in the company's plans for high-end processors and a potential relocation of its manufacturing.

When Apple first set out to build a replacement for the Intel Mac Pro, it planned a machine with a processor based on the original M1 chip. The approach called for two main configurations: one chip equal to the power of two M1 Max processors -- the highest-end MacBook Pro chip -- and another equal to four M1 Max components combined. The dual M1 Max chip ended up first launching in the Mac Studio as the M1 Ultra, and Apple decided to push back the Mac Pro to the M2 generation. The company then planned for the Mac Pro to come in two configurations: an M2 Ultra version and a double-M2 Ultra that I've dubbed the "M2 Extreme." The M2 Ultra chip is destined to have some serious specifications for professional users, including up to 24 CPU cores, 76 graphics cores and the ability to top out the machine with at least 192 gigabytes of memory. An M2 Extreme chip would have doubled that to 48 CPU cores and 152 graphics cores. But here's the bad news: The company has likely scrapped that higher-end configuration, which may disappoint Apple's most demanding users -- the photographers, editors and programmers who prize that kind of computing power.

The company made the decision because of both the complexity and cost of producing a processor that is essentially four M2 Max chips fused together. It also will help Apple and partner Taiwan Semiconductor Manufacturing Co. save chip-production resources for higher-volume machines. Moreover, there are concerns about how much consumers are willing to spend. Using the highest-end M1 Ultra chip pushes the Mac Studio up to $5,000 -- only $1,000 less than the current Mac Pro. That's $3,000 more than the M1 Max Mac Studio. Based on Apple's current pricing structure, an M2 Extreme version of a Mac Pro would probably cost at least $10,000 -- without any other upgrades -- making it an extraordinarily niche product that likely isn't worth the development costs, engineering resources and production bandwidth it would require. Instead, the Mac Pro is expected to rely on a new-generation M2 Ultra chip (rather than the M1 Ultra) and will retain one of its hallmark features: easy expandability for additional memory, storage and other components.
Gurman says the Mac Mini update "will come in regular M2 and M2 Pro variations, while new 14-inch and 16-inch MacBook Pros are arriving early next year with M2 Pro and M2 Max options." A high-end iMac Pro with Apple silicon is also in the works, "but that machine has suffered internal delays for similar reasons as the Mac Pro," he notes.

In addition, Gurman says Apple is "working on multiple new external monitors [...], including an update to the Pro Display XDR that was launching alongside the Intel Mac Pro in 2019." The new monitors will also include Apple silicon.
Technology

Who Really Invented the Thumb Drive? (ieee.org) 134

IEEE Spectrum: In 2000, at a trade fair in Germany, an obscure Singapore company called Trek 2000 unveiled a solid-state memory chip encased in plastic and attached to a Universal Serial Bus (USB) connector. The gadget, roughly the size of a pack of chewing gum, held 8 megabytes of data and required no external power source, drawing power directly from a computer when connected. It was called the ThumbDrive. That device, now known by a variety of names -- including memory stick, USB stick, flash drive, as well as thumb drive -- changed the way computer files are stored and transferred. Today it is familiar worldwide. The thumb drive was an instant hit, garnering hundreds of orders for samples within hours. Later that year, Trek went public on the Singapore stock exchange, and in four months -- from April through July 2000 -- it manufactured and sold more than 100,000 ThumbDrives under its own label.

Before the invention of the thumb drive, computer users stored and transported their files using floppy disks. Developed by IBM in the 1960s, first 8-inch and later 5 1/4-inch and 3 1/2-inch floppy disks replaced cassette tapes as the most practical portable storage media. Floppy disks were limited by their relatively small storage capacity -- even double-sided, double-density disks could store only 1.44 MB of data. During the 1990s, as the size of files and software increased, computer companies searched for alternatives. Personal computers in the late 1980s began incorporating CD-ROM drives, but initially these could read only from prerecorded disks and could not store user-generated data. The Iomega Zip Drive, called a "superfloppy" drive and introduced in 1994, could store up to 750 MB of data and was writable, but it never gained widespread popularity, partly due to competition from cheaper and higher-capacity hard drives.

Computer users badly needed a cheap, high-capacity, reliable, portable storage device. The thumb drive was all that -- and more. It was small enough to slip in a front pocket or hang from a keychain, and durable enough to be rattled around in a drawer or tote without damage. With all these advantages, it effectively ended the era of the floppy disk. But Trek 2000 hardly became a household name. And the inventor of the thumb drive and Trek's CEO, Henn Tan, did not become as famous as other hardware pioneers like Robert Noyce, Douglas Engelbart, or Steve Jobs. Even in his home of Singapore, few people know of Tan or Trek. Why aren't they more famous? After all, mainstream companies including IBM, TEAC, Toshiba, and, ultimately, Verbatim licensed Trek's technology for their own memory stick devices. And a host of other companies just copied Tan without permission or acknowledgment.

Technology

How Amazon Put Ukraine's 'Government in a Box' (latimes.com) 23

An anonymous reader shares a report: Since Februrary, Amazon has been playing Santa Claus to Ukraine, delivering planeloads of goods, including blankets, hygiene kits, diapers, food and toys, for the war-torn nation and refugees in Poland and other parts of Europe. But long term, what's more important to Ukrainians than the gifts coming in is what's going out: massive amounts of government, tax, banking and property data vulnerable to destruction and abuse should Russian invaders get their hands on it. Since the day Russia launched its invasion Feb. 24, Amazon has been working closely with the Ukrainian government to download essential data and ferry it out of the country in suitcase-sized solid-state computer storage units called Snowball Edge, then funneling the data into Amazon's cloud computing system.

"This is the most technologically advanced war in human history," said Mykhailo Fedorov, Ukraine's 31-year-old vice prime minister and minister of digital transformation, referring not just to weapons but data too. Amazon Web Services' "leadership made a decision that saved the Ukrainian government and economy." Amazon has invested $75 million so far in its Ukraine effort, which includes the data transfer via the Snowballs. Fedorov, speaking at a tech conference in Las Vegas this month, called it "priceless." The data, 10 million gigabytes so far, represent "critical information infrastructure. This is core for operation of the economy, of the tax system, of banks, and the government overall," he said. The data also include property records whose safekeeping can help prevent theft of Ukrainian homes, businesses and land.

Through history, invaders have "come in and staged fake referendum and parceled out the land to their chums," said Liam Maxwell, head of government transformation at Amazon Web Services, the company's highly profitable cloud computing arm. "That kind of thing has been happening since William the Conquerer." The Odessa Journal newspaper reported in June that residents of the Russian-occupied city of Mariupol whose homes had been destroyed were being moved into the homes of citizens who had fled the area, and were being forced to find those who left and pressure them to cooperate in some fashion with the Russians. Maxwell, who's based in London, had already been working with Ukraine for years when it became clear by January that Russia planned to attack the country.

Slashdot Top Deals