×
Android

Murena, the Privacy-First Android Smartphone, Arrives (zdnet.com) 62

The /e/OS-powered Murena One is the first smartphone from Murena that does its best to free you from Google without sacrificing too many core features. There are no Google apps, Google Play Services, or even the Google Assistant. It's all been replaced by open-source software alternatives with privacy-respecting features. ZDNet's Steven Vaughan-Nichols reports: Murena and Mandrake Linux founder Gael Duval was sick of it by 2017. He wanted his data to be his data, and he wanted open-source software. Almost five years later, Duval and his co-developers launched the Murena One X2. It's the first high-end Android phone using the open-source /e/OS Android fork to arrive on the market. The privacy heart of the Murena One is /e/OS V1. There have been many attempts to create an alternative to Google-based Android and Apple's iOS -- Ubuntu One, FirefoxOS, and Windows Mobile -- but all failed. Duval's approach isn't to reinvent the mobile operating system wheel, but to clean up Android of its squeaky Google privacy-invading features and replace them with privacy-respecting ones. To make this happen, Duval started with LineageOS -- an Android-based operating system, which is descended from the failed CyanogenMod Android fork. It also blends in features from the Android Open Source Project (AOSP) source-code trees.

In the /e/OS, most (but not all) Google services have been removed and replaced with MicroG services. MicroG replaces Google's libraries with purely open-source implementations without hooks to Google's services. This includes libraries and apps which provide Google Play, Maps, Geolocation, and Messaging services for Android applications. In addition, /e/OS does its best to free you from higher-level Google services. For instance, Google's default search engine has been replaced with Murena's own meta-search engine. Other internet-based services, such as Domain Name Server (DNS) and Network Time Protocol (NTP), use non-Google servers. Above the operating system, you'll find Google-free applications. This includes a web browser; an e-mail client; a messaging app; a calendar; a contact manager; and a maps app that relies on Mozilla Location Service and OpenStreetMap. While it's not here yet, Murena is also working on its own take on Google Assistant, Elivia-AI. You can also run many, but not all Android apps. You'll find these apps on the operating system's App Lounge. [...]

There's still one big problem: the App Lounge still relies on you logging in with your Google account. In short, the App Lounge is mainly a gateway to Google Store apps. Munera assures me that the Lounge anonymizes your data -- except if you use apps that require payment. Still, this is annoying for people who want to cut all their ties with Google. The fundamental problem is this: Muena does all it can to separate its operating system and applications from Google, but it can't -- yet -- replace Google's e-commerce and software store system.
As for hardware specs, the $379 Murena One features a 6.5-inch IPS LCD display, eight-core MediaTek Helio P60 processor, side-mounted fingerprint scanner, three rear cameras (48MP + 8MP + 5MP) and 25MP front camera, and 4,500mAh battery. It also features a microSD card slot for expandable storage and headphone port.
Crime

New Linux-Based Ransomware Targets VMware Servers (csoonline.com) 36

"Researchers at Trend Micro have discovered some new Linux-based ransomware that's being used to attack VMware ESXi servers," reports CSO Online. (They describe the ESXi servers as "a bare-metal hypervisor for creating and running several virtual machines that share the same hard drive storage.") Called Cheerscrypt, the bad app is following in the footsteps of other ransomware programs — such as LockBit, Hive and RansomEXX — that have found ESXi an efficient way to infect many computers at once with malicious payloads.

Roger Grimes, a defense evangelist with security awareness training provider KnowBe4, explains that most of the world's organizations operate using VMware virtual machines. "It makes the job of ransomware attackers far easier because they can encrypt one server — the VMware server — and then encrypt every guest VM it contains. One compromise and encryption command can easily encrypt dozens to hundreds of other virtually run computers all at once."

"Most VM shops use some sort of VM backup product to back up all guest servers, so finding and deleting or corrupting one backup repository kills the backup image for all the hosted guest servers all at once," Grimes adds....

The gang behind Cheerscrypt uses a "double extortion" technique to extract money from its targets, the researchers explain. "Security Alert!!!" the attackers' ransom message declares. "We hacked your company successfully. All files have been stolen and encrypted by us. If you want to restore your files or avoid file leaks, please contact us."

Data Storage

Larger-than-30TB Hard Drives Are Coming Much Sooner Than Expected (techradar.com) 66

Inside of hard disk drives are platters which hold all your data; these are all manufactured by one company in Japan called Showa Denko which has announced it expects to "realize near-line HDD having storage capacity of more than 30TB" by the end of 2023. From a report: Deciphering that statement, we'd assume it will provide platters with a storage capacity of more than 3TB, sometime in 2023, to partners such as Toshiba, Seagate and Western Digital, who will then produce the hard disk drives, targeting hyperscalers and data centers operators. We'd expect some of them to end up in NAS and 3.5-inch external hard drives, but that won't be the main target markets, as performance is likely to be optimized for nearline usage.

Showa Denko has now started shipment of the platters that will go into new 26TB Ultrastar DC HC670 UltraSMR hard disk drives announced by Western Digital only a few days ago. A 2.6TB platter -- which uses energy-assisted magnetic recording and shingled magnetic recording -- also marks an important milestone as it hits the symbolic 1TB/in^2 density. Showa Denko's announcement comes as a surprise as Toshiba recently suggested 30TB drives (rather than higher capacities) would not come until 2024. A 30TB model would comprise of 11 platters with 2.73TB capacities each, a slight improvement on the 2.6TB capacity that are on the way. Given the fact that 26TB HDDs have now been announced in the first half of 2022, there's a remote chance that we could see 30TB drives before the end of the year or (as the saying goes), depending on market conditions.

Google

Russia Opens Cases Against Google, other Foreign Tech Over Data Storage (reuters.com) 51

Russia's communications regulator Roskomnadzor said on Friday it had opened administrative cases against Alphabet's Google and six other foreign technology companies for alleged violations of personal data legislation. From a report: Moscow has clashed with Big Tech over content, censorship, data and local representation in a simmering dispute that has erupted into a full-on information battle since Russia sent tens of thousands of troops into Ukraine on Feb. 24. Russia fined Google 3 million roubles ($46,540) last year for not storing the personal data of Russian users in databases on Russian territory, and on Friday said it had opened a new case over what it called Google's repeated failure to comply with Russian legislation.
Virtualization

Microsoft Dev Box Will Virtualize Your Windows Development PC In a Browser Window (arstechnica.com) 40

Microsoft Dev Box is intended to simplify the process of getting new developer workstations up and running quickly, with all necessary tools and dependencies installed and working out-of-the-box (so to speak), along with access to up-to-date source code and fresh copies of any nightly builds. Ars Technica reports: Dev Box is built on Windows 365, a service that IT admins can use to provide preconfigured virtual PCs to users. Admins can build operating system images and offer hardware configurations with different amounts of CPU power, storage, and RAM based on what particular users (or workloads) need. Windows 365 virtual machines, including but not limited to Dev Box VMs, can be accessed from other Windows PCs, or devices running macOS, iOS, Android, Linux, or ChromeOS.

"Microsoft Dev Box supports any developer IDE, SDK, or internal tool that runs on Windows," writes Microsoft product manager Anthony Cangialosi [in a blog post introducing the service]. "Dev Boxes can target any development workload you can build from a Windows desktop and are particularly well-suited for desktop, mobile, IoT, and gaming. You can even build cross-platform apps using Windows Subsystem for Linux." Dev Box is currently available in a private preview. If you're interested in testing it when the preview goes public, you can sign up to learn more here.

Power

Solar Panels Are Coming To IKEA (curbed.com) 37

Starting this fall with its locations in California, the Swedish furniture giant Ikea will sell the means to power your Starkvind (that's an air purifier) and Stjarnstatus (that's a fridge) by adding solar panels to the company's offerings. Thankfully, assembly will be handled by the professionals. Curbed reports: To bring photovoltaics -- the technical name for solar panels -- to the people, Ikea is partnering with SunPower, one of the largest solar-energy providers in the country, which will install the rooftop systems and a DC-battery storage unit. As with all solar installations, the cost and energy generated will vary depending on a range of factors, such as the size of the roof and how much sunlight it sees during the day. Incentives like tax credits can also help sweeten the deal, depending on where you live. [...]

The stated goal of Ikea's solar efforts is to zero out the emissions generated to power its plugged-in products, which the company estimates are about 20 percent of its total. Now let's see if Ikea can make solar panels as ubiquitous and affordable for U.S. homes as its Billy bookshelf -- one of which is made every three seconds.

Encryption

ProtonMail Unifies Encrypted Mail, Calendar, VPN, and Storage Services Under New 'Proton' Brand (macrumors.com) 37

Swiss-based encrypted email provider ProtonMail today announced a restructuring of its privacy-first services, bringing them under a new unifying brand name: Proton. "Today, we are undertaking our biggest step forward in the movement for an internet that respects your privacy. The new, updated Proton offers one account, many services, and one privacy-by-default ecosystem. You can now enjoy unified protection with a modernized look and feel. Evolving into a unified Proton reflects our growth from an end-to-end encrypted email provider to an entire privacy ecosystem, allowing us to deliver even more benefits to the Proton community and make privacy accessible to everyone," the company said. MacRumors adds: Previously, users could only subscribe to each service the company offered individually. Going forward, the new Proton offers one account to access all the services offered in the company's privacy-by-default ecosystem, including Proton Mail, Proton VPN, Proton Calendar, and Proton Drive, all of which can be accessed from proton.me. All Proton services remain available as a free tier, with more advanced features and more storage available via paid plans. The free Proton tier includes up to 1GB of storage and one Proton email address, as well as access to Proton's encrypted Calendar and VPN services. Further reading: Proton Is Trying to Become Google -- Without Your Data.
AMD

AMD Ryzen 7000 Smokes Alder Lake In Computex Keynote Zen 4 Tease (hothardware.com) 59

"AMD's Computex 2022 keynote marks the first appearance of company's new Zen 4-based Ryzen 7000 desktop chip in the flesh," writes Slashdot reader MojoKid. "And in its first quick benchmark tease, it's looking pretty buff." Here's an excerpt from a report via HotHardware: AMD Ryzen 7000-series processors that will be the first to ship with Zen 4 cores will include one or two 5nm Zen 4 CCDs -- topping out at 16 cores, just like Zen 3 -- as well as a new cIOD fabricated on 6nm chip process technology. The new cIOD will include PCIe 5.0 and DDR5 support, as well as an RDNA 2-based GPU for basic display support. [...] Initial performance claims regarding solid state storage weren't the only ones made during AMD's Computex keynote, however. As the keynote was wrapping up, Dr. Su showed two demos powered by a Ryzen 7000 series processor.

AMD Ryzen 7000-series processors that will be the first to ship with Zen 4 cores will include one or two 5nm Zen 4 CCDs -- topping out at 16 cores, just like Zen 3 -- as well as a new cIOD fabricated on 6nm chip process technology. The new cIOD will include PCIe 5.0 and DDR5 support, as well as an RDNA 2-based GPU for basic display support. In the second demo, a custom Ryzen 7000 3D image was being rendered in Blender, with an Intel Core i9-12900K 16-core / 24-thread processor running alongside an AMD Ryzen 7000 series 16-core / 32-thread processor. In the time-lapsed demo, the Ryzen 7000-based system finished the render 31% faster than the Intel system.

While AMD wasn't willing to commit to any specific date, the company did confirm that Zen 4 will be here this year, and well before the holiday shopping season. Dr. Su set a timeframe of "Fall" for availability of the new Ryzen 7000 CPUs, as well as the motherboards that will help enable the entire platform.
Slashdot reader UnknowingFool also shared the news (via AnandTech).

You can watch the entire AMD Computex 2022 Keynote presentation here.
HP

HP Chooses Ubuntu-Based Pop!_OS Linux For Its Upcoming Dev One Laptop (betanews.com) 64

System76's CEO Carl Richell announced that HP has chosen the Ubuntu-based Pop!_OS operating system to run on its 14-inch developer-focused notebook called "Dev One." Brian Fagioli from BetaNews speculates that a HP acquisition of System76 "could be a possibility in the future -- if this new relationship pans out at least." He continues: HP could be testing the waters with the upcoming Dev One. Keep in mind, System76 does not even build its own laptops, so we could see the company leave the notebook business and focus on desktops only -- let HP handle the Pop!_OS laptops. "We've got you covered. Experience exceptional multi-core performance from the AMD Ryzen 7 PRO processor and multitask with ease. Compile code, run a build, and keep all your apps running with more speed from the 16GB memory. Plus, load and save files in a flash, thanks to 1TB fast PCIe NVMe M.2 storage. We've even added a Linux Super key so shortcuts are a click away. Simply put, HP Dev One is built to help you code better," explains HP.

The company adds, "Pop!_OS is at your service. Create your ideal work experience with multiple tools to help you perform with peak efficiency. Use Stacking to organize and access multiple applications, browsers, and terminal windows. Move, resize, and arrange windows with ease or, let Pop!_OS keep you organized and efficient with Auto-tiling. And use Workspaces to reduce clutter by organizing windows across multiple desktops." Apparently, there will only be one configuration priced at $1,099. So far, no details about a release date have been announced other than "coming soon."

Hardware

Modular, DIY-Friendly Framework Laptop Gets Updated With 12th-Gen Intel CPUs (arstechnica.com) 39

An anonymous reader quotes a report from Ars Technica: An upgradeable laptop is only worthwhile if you can actually upgrade it [...], and Framework is making that possible starting today: The company is introducing a new iteration of the Framework Laptop's motherboard that uses 12th-gen Intel CPUs. A brand-new 12th-gen Framework Laptop starts at $1,049 for a Core i5-equipped base model, or $819 for a build-it-yourself kit with no memory or storage. These products will be available for preorder starting today, and shipping will start in July.

The 12th-generation Core processors use Intel's latest Alder Lake CPU architecture, which combines high-performance P-cores and high-efficiency E-cores to maximize performance under heavy load and reduce power usage when your computer is mostly idle. The base Core i5-1240P CPU includes four P-cores and eight E-cores, a big boost in core count compared to the quad-core 11th-gen CPUs. The Core i7-1260P upgrade has the same CPU core count with boosted clock speeds and a small increase in integrated GPU performance, while the top-end Core i7-1280P option will get you six P-cores and eight E-cores.

The rest of the Framework Laptop's hardware is staying mostly the same, though there are a few additional upgrades to be aware of. One is a 2.5Gbps Ethernet expansion card, the first wired LAN module to be available for the laptop. The card is based on Realtek's RTL8156 chipset and will be available "later this year." The company is also releasing a redesigned version of its top cover made with a new CNC manufacturing process that "substantially improv[es] rigidity." The new top cover will be the default option for all Framework Laptops going forward, though you can buy a new cover for your existing Framework Laptop for $89.
You can view pricing and configuration info here.
Power

Nuclear Energy: the Case Against (theguardian.com) 362

"We do not need to plunge headlong into a nuclear future," argues Serhii Plokhy, author of the book Atoms and Ashes: From Bikini Atoll to Fukushima.

He notes Belgium's adding a 10-year extension to the life of two of its nuclear reactors, France's program to build 14 new reactors, and Boris Johnson's pledge to create supply 25% of the UKs power needs with nuclear energy by 2050. On the surface, the switch to nuclear makes sense. It would not only enable European countries to meet their ambitious net zero targets, since it produces no CO2. It would also make them less vulnerable to Russian threats, and allow them to stop financing the Russian war machine....

What the Russian takeover of [Ukraine] nuclear facilities exposed is a hazard inherent in all nuclear power. In order for this method of producing electricity to be safe, everything else in society has to be functioning perfectly. Warfare, economic collapse, climate change itself — all of these increasingly real risks make nuclear sites potentially perilous places. Even without them, the dangers of atomic fission remain, and we must ask ourselves: are they really worth the cost...?

Technological developments, growing international cooperation and rising safety standards did indeed do a great deal to ensure that no major nuclear accident occurred for 25 years after Chernobyl. But the Fukushima explosions demonstrated that such improvements have not eradicated the dangers surrounding nuclear power plants.... Can anything be done to make reactors safer? A new generation of smaller modular reactors, designed from scratch to produce energy, not to facilitate warfare, has been proposed by Bill Gates, and embraced, among others, by Macron. The reactors promised by Gates's TerraPower company are still at the computer-simulation stage and years away from construction. But his claim that in such reactors "accidents would literally be prevented by the laws of physics" must be taken with a pinch of salt, as there are no laws of war protecting either old or new reactors from attack.

There is also serious concern that the rapid expansion in the number of plants, advocated as a way of dealing with climate change, will increase the probability of accidents. While new technology will help to avoid some of the old pitfalls, it will also bring new risks associated with untried reactors and systems. Responsibility for dealing with such risks is currently being passed on to future generations.

This is the second great risk from nuclear power: even if a reactor runs for its lifetime without incident, you still have a lot of dangerous material left at the end of it. Fuel from nuclear power plants will present a threat to human life and the environment for generations to come, with the half-life of some radioactive particles measured in tens of thousands of years.... Nuclear power plants generally have no alternative to storing their high-level radioactive waste on site....If what we bury today in the New Mexico desert — the waste created by our nuclear ambitions — is so repulsive to us, why do we pass it on to others to deal with?

The author's counter-proposal: expanding the use of renewable energy: New research should be encouraged, grid infrastructure should be built up, and storage capacity increased. Billions that would otherwise go to new nuclear infrastructure, with all the attendant costs of cleanup that continue for decades and beyond, should be pumped instead into clean energy.

In the meantime, we obviously have an existing nuclear industry, and the solution is not to run away in panic, but to take good care of the facilities that already dot our countryside. We must not abandon the industry to its current state of economic hardship, as that would only mean inviting the next accident sooner rather than later.

Hardware

Samsung Is Reportedly Planning To Raise Chip Prices By 20% (pcmag.com) 28

Samsung is currently considering raising the cost of its semiconductor products by up to 20%, as well as those it manufactures for other companies, which would ultimately lead to consumers paying more for new devices. PC Magazine reports: As Bloomberg reports, the price hike consideration is in response to just about everything in the world getting more expensive, including the cost of raw materials and the logistics surrounding production pipelines. The final price increase is expected to be linked to sophistication of the components being manufactured, but that still means vendors will end up paying between 15-20% more for chips. Samsung is a huge player in the semiconductor industry, producing processors for a wide-range of industries, as well as memory products, storage solutions, and foundry solutions which allow other semiconductor products to be manufactured. Adding up to a 20% price rise across all those sectors will inevitably push up prices for any products that use Samsung components.
Power

Giving Old Dams New Life Could Spark an Energy Boom (msn.com) 50

"Extreme drought has drastically reduced reservoir levels and is causing a decline in electricity production from hydropower," reports the Washington Post.

"Yet while climate change has parched the West, these same forces have greatly increased precipitation in much of the Midwest, the South and the East. There, hydropower is gaining momentum, and supporters say that in many places it is poised for a big resurgence." And the Post sees this benefiting "a growing effort to retrofit so-called nonpowered dams, or any dams created for a need other than hydropower, for electricity production..." In 2016, a U.S. Department of Energy study forecast that hydropower in the United States could expand from its current capacity of 101 gigawatts to nearly 150 gigawatts by 2050. This growth would come not from new dam construction but from upgrading existing hydroelectric resources, adding pumped storage capacity, and retrofitting nonpowered dams for hydropower.... Nonpowered dams compose the vast majority of America's dam infrastructure. They can be found across the country, come in all sizes and were built to address a wide array of needs, including flood control, navigation, water supply and recreation.

Out of the estimated 90,000 dams in the United States, about 2,200 of them generate hydroelectric power. These hydropower resources, however, account for 7 percent of national energy production and contribute 37 percent of the nation's renewable energy supply....

Solar and wind produce energy intermittently, but hydropower can operate day or night, 24/7. Some hydropower facilities can shut down or ramp up energy production very quickly, providing energy grids with stopgap flexibility during peak demand or in the case of blackouts.... The addition of hydropower to nonpowered dams can be financially attractive to developers. Typically the dam's operation is not changed, so there is usually much less opposition from communities and environmental groups than there would be to a new dam project.

The article points out that last year's U.S. infrastructure funding included money to add hydropower to "nonpowered dams."
Power

Rechargeable Molten Salt Battery Freezes Energy In Place For Long-Term Storage (scientificamerican.com) 40

An anonymous reader quotes a report from Scientific American: During spring in the Pacific Northwest, meltwater from thawing snow rushes down rivers and the wind often blows hard. These forces spin the region's many power turbines and generate a bounty of electricity at a time of mild temperatures and relatively low energy demand. But much of this seasonal surplus electricity -- which could power air conditioners come summer -- is lost because batteries cannot store it long enough. Researchers at Pacific Northwest National Laboratory (PNNL), a Department of Energy national laboratory in Richland, Wash., are developing a battery that might solve this problem. In a recent paper published in Cell Reports Physical Science, they demonstrated how freezing and thawing a molten salt solution creates a rechargeable battery that can store energy cheaply and efficiently for weeks or months at a time.

Most conventional batteries store energy as chemical reactions waiting to happen. When the battery is connected to an external circuit, electrons travel from one side of the battery to the other through that circuit, generating electricity. To compensate for the change, charged particles called ions move through the fluid, paste or solid material that separates the two sides of the battery. But even when the battery is not in use, the ions gradually diffuse across this material, which is called the electrolyte. As that happens over weeks or months, the battery loses energy. Some rechargeable batteries can lose almost a third of their stored charge in a single month.

"In our battery, we really tried to stop this condition of self-discharge," says PNNL researcher Guosheng Li, who led the project. The electrolyte is made of a salt solution that is solid at ambient temperatures but becomes liquid when heated to 180 degrees Celsius -- about the temperature at which cookies are baked. When the electrolyte is solid, the ions are locked in place, preventing self-discharge. Only when the electrolyte liquifies can the ions flow through the battery, allowing it to charge or discharge. Creating a battery that can withstand repeated cycles of heating and cooling is no small feat. Temperature fluctuations cause the battery to expand and contract, and the researchers had to identify resilient materials that could tolerate these changes. [...] The result is a rechargeable battery made from relatively inexpensive materials that can store energy for extended periods.
"Right now the experimental technology is aimed at utility-scale and industrial uses," notes the report. "The PNNL team plans to continue developing the technology, but ultimately it will be up to industry to develop a commercial product."
Piracy

Every ISP In the US Has Been Ordered To Block Three Pirate Streaming Services (arstechnica.com) 115

An anonymous reader quotes a report from Ars Technica: A federal judge has ordered all Internet service providers in the United States to block three pirate streaming services operated by Doe defendants who never showed up to court and hid behind false identities. The blocking orders affect Israel.tv, Israeli-tv.com, and Sdarot.tv, as well as related domains listed in the rulings and any other domains where the copyright-infringing websites may resurface in the future. The orders came in three essentially identical rulings (see here, here, and here) issued on April 26 in US District Court for the Southern District of New York.

Each ruling provides a list of 96 ISPs that are expected to block the websites, including Comcast, Charter, AT&T, Verizon, and T-Mobile. But the rulings say that all ISPs must comply even if they aren't on the list: "It is further ordered that all ISPs (including without limitation those set forth in Exhibit B hereto) and any other ISPs providing services in the United States shall block access to the Website at any domain address known today (including but not limited to those set forth in Exhibit A hereto) or to be used in the future by the Defendants ('Newly Detected Websites') by any technological means available on the ISPs' systems. The domain addresses and any Newly Detected Websites shall be channeled in such a way that users will be unable to connect and/or use the Website, and will be diverted by the ISPs' DNS servers to a landing page operated and controlled by Plaintiffs (the 'Landing Page')." That landing page is available here and cites US District Judge Katherine Polk Failla's "order to block all access to this website/service due to copyright infringement." "If you were harmed in any way by the Court's decision you may file a motion to the Federal Court in the Southern District of New York in the above case," the landing page also says.

The three lawsuits were filed by Israeli TV and movie producers and providers against Doe defendants who operate the websites. Each of the three rulings awarded damages of $7.65 million. TorrentFreak pointed out the rulings in an article Monday. The orders also contain permanent injunctions against the defendants themselves and other types of companies that provided services to the defendants or could do so in the future. That includes companies like Cloudflare, GoDaddy, Google, and Namecheap. In all three cases, none of the defendants responded to the complaints and did not appear in court, the judge's rulings said. "Defendants have gone to great lengths to conceal themselves and their ill-gotten proceeds from Plaintiffs' and this Court's detection, including by using multiple false identities and addresses associated with their operations and purposely deceptive contact information for the infringing Website," the rulings say. The defendants are liable for copyright infringement and violated the anti-circumvention provision of the Digital Millennium Copyright Act (DMCA), the judge wrote [...].

Security

A Stealthy New Espionage Group is Targeting Corporate Mergers and Acquisitions (techcrunch.com) 6

A new espionage actor is breaching corporate networks to steal emails from employees involved in big financial transactions like mergers and acquisitions. From a report: Mandiant researchers, which first discovered the advanced persistent threat (APT) group in December 2019 and now tracks it as "UNC3524," says that while the group's corporate targets hint at financial motivation, its longer-than-average dwell time in a victim's environment suggests an intelligence gathering mandate. In some cases, UNC3524 remained undetected in victims' environments for as long as 18 months, versus an average dwell time of 21 days in 2021.

Mandiant credits the group's success at achieving such a long dwell time to its unique approach to its use of a novel backdoor -- tracked as "QuietExit" -- on network appliances that do not support antivirus or endpoint detection, such as storage arrays, load balancers and wireless access point controllers. The QuietExit backdoor's command-and-control servers are part of a botnet built by compromising D-Link and LifeSize conference room camera systems, according to Mandiant, which said the compromised devices were likely breached due to the use of default credentials, rather than an exploit.

Power

Biden Administration Begins $3 Billion Plan for Electric Car Batteries (nytimes.com) 143

The Biden administration plans to begin a $3.1 billion effort on Monday to spur the domestic production of advanced batteries, which are essential to its plan to speed the adoption of electric vehicles and renewable energy. The New York Times reports: President Biden has prodded automakers to churn out electric vehicles and utilities to switch to solar, wind and other clean energy, saying the transitions are critical to eliminating the pollution that is dangerously heating the planet. In the wake of surging energy prices caused largely by Russia's invasion of Ukraine, administration officials also have described the transition to clean energy as a way to insulate consumers from the fluctuation of global oil markets and achieve true energy independence. Jennifer Granholm, the energy secretary, last week called renewable energy "the greatest peace plan this world will ever know." Yet currently, lithium, cobalt and other minerals needed for electric car batteries and energy storage are processed primarily in Asia. China alone controls nearly 80 percent of the world's processing and refining of those critical minerals.

Ms. Granholm plans to announce the funding plan on Monday during a visit to Detroit, a senior administration official said. The $3.1 billion in grants, along with a separate $60 million program for battery recycling, is an effort to "reduce our reliance on competing nations like China that have an advantage over the global supply chain," according to a Department of Energy statement. The funding is aimed at companies that can create new, retrofitted or expanded processing facilities as well as battery recycling programs, officials with the Department of Energy said. The grants will be funded through the $1 trillion infrastructure law, which includes more than $7 billion to improve the domestic battery supply chain.

Venkat Srinivasan, director of the Argonne Collaborative Center for Energy Storage Science at Argonne National Laboratory, told the panel that the United States "can become a dominant force in energy storage technology" and has a "once-in-a-lifetime opportunity to seize the moment." Between electric vehicles and grid storage, the market for lithium-ion batteries in the United States is expected to increase by a factor of 20 to 30 in the next decade but a secure domestic supply chain is needed, Dr. Srinivasan said. The Biden administration wants half of all new vehicles sold in the United States to be electric by 2030. The president also has issued procurement guidelines to transform the 600,000-vehicle federal fleet, so that all new cars and trucks purchased by the federal government by 2035 are zero-emission.

Data Storage

Two-Inch Diamond Wafers Could Store a Billion Blu-Ray's Worth of Data (newatlas.com) 81

Researchers in Japan have developed a new method for making 5-cm (2-in) wafers of diamond that could be used for quantum memory. The ultra-high purity of the diamond allows it to store a staggering amount of data -- the equivalent of one billion Blu-Ray discs. New Atlas reports: [R]esearchers at Saga University and Adamant Namiki Precision Jewelery Co. in Japan have developed a new method for manufacturing ultra-high purity diamond wafers that are big enough for practical use. With this technique, the team says the resulting diamond wafers measure 5 cm across, and have such immense data density that they can theoretically store the equivalent of a billion Blu-Ray discs. One Blu-Ray can store up to 25 GB (assuming it's single-layered), which would mean this diamond wafer should be able to store a whopping 25 exabytes (EB) of data. The company calls these wafers Kenzan Diamond. The key is that these diamonds have a nitrogen concentration of under three parts per billion (ppb), making them incredibly pure. The researchers say that these are the largest wafers with that level of purity -- most others only get to 4 mm2 (0.006 in2) at most.

Achieving this requires a new manufacturing technique. Diamond wafers are made by growing the crystals on a substrate material, and that material is usually a flat surface. The problem is, the diamond can crack under the strain, degrading the quality. In the new process, the team made a relatively simple change -- the substrate surface was shaped like steps, which spreads the strain horizontally and prevents cracking. This allows them to make larger diamond wafers with higher purity. The team hopes to commercialize these diamond wafers in 2023, and in the meantime are already working towards doubling the diameter to 10 cm (4 in).

Android

North Koreans Are Jailbreaking Phones To Access Forbidden Media (wired.com) 23

An anonymous reader quotes a report from Wired: For most of the world, the common practice of "rooting" or "jailbreaking" a phone allows the device's owner to install apps and software tweaks that break the restrictions of Apple's or Google's operating systems. For a growing number of North Koreans, on the other hand, the same form of hacking allows them to break out of a far more expansive system of control -- one that seeks to extend to every aspect of their lives and minds. On Wednesday, the North Korea-focused human rights organization Lumen and Martyn Williams, a researcher at the Stimson Center think tank's North Korea -- focused 38 North project, together released a report on the state of smartphones and telecommunications in the Democratic People's Republic of Korea, a country that restricts its citizens' access to information and the internet more tightly than any other in the world. The report details how millions of government-approved, Android-based smartphones now permeate North Korean society, though with digital restrictions that prevent their users from downloading any app or even any file not officially sanctioned by the state. But within that regime of digital repression, the report also offers a glimpse of an unlikely new group: North Korean jailbreakers capable of hacking those smartphones to secretly regain control of them and unlock a world of forbidden foreign content.

Learning anything about the details of subversive activity in North Korea -- digital or otherwise -- is notoriously difficult, given the Hermit Kingdom's nearly airtight information controls. Lumen's findings on North Korean jailbreaking are based on interviews with just two defectors from the country. But Williams says the two escapees both independently described hacking their phones and those of other North Koreans, roughly corroborating each others' telling. Other North Korea -- focused researchers who have interviewed defectors say they've heard similar stories. Both jailbreakers interviewed by Lumen and Williams said they hacked their phones -- government-approved, Chinese-made, midrange Android phones known as the Pyongyang 2423 and 2413 -- primarily so that they could use the devices to watch foreign media and install apps that weren't approved by the government. Their hacking was designed to circumvent a government-created version of Android on those phones, which has for years included a certificate system that requires any file downloaded to the device to be "signed" with a cryptographic signature from government authorities, or else it's immediately and automatically deleted. Both jailbreakers say they were able to remove that certificate authentication scheme from phones, allowing them to install forbidden apps, such as games, as well as foreign media like South Korean films, TV shows, and ebooks that North Koreans have sought to access for decades despite draconian government bans.

In another Orwellian measure, Pyongyang phones' government-created operating system takes screenshots of the device at random intervals, the two defectors say -- a surveillance feature designed to instill a sense that the user is always being monitored. The images from those screenshots are then kept in an inaccessible portion of the phone's storage, where they can't be viewed or deleted. Jailbreaking the phones also allowed the two defectors to access and wipe those surveillance screenshots, they say. The two hackers told Lumen they used their jailbreaking skills to remove restrictions from friends' phones, as well. They said they also knew of people who would jailbreak phones as a commercial service, though often for purposes that had less to do with information freedom than more mundane motives. Some users wanted to install a certain screensaver on their phone, for instance, or wipe the phone's surveillance screenshots merely to free up storage before selling the phone secondhand.
As for how the jailbreaking was done, the report says both jailbreakers "described attaching phones to a Windows PC via a USB cable to install a jailbreaking tool."

"One mentioned that the Pyongyang 2423's software included a vulnerability that allowed programs to be installed in a hidden directory. The hacker says they exploited that quirk to install a jailbreaking program they'd downloaded while working abroad in China and then smuggled back into North Korea." The other hacker might've obtained his jailbreaking tool in a computer science group at Pyongyang's elite Kim Il Sung University where he attended.
Power

Half of Tesla's New Cars Produced Use Cobalt-Free LFP Batteries (electrek.co) 70

Tesla confirmed that nearly half of all its vehicles produced last quarter are already using cobalt-free iron-phosphate (LFP) batteries. Electrek reports: Over the last few years, CEO Elon Musk has said multiple times that Tesla plans to shift more electric cars to LFP batteries in order to overcome nickel and cobalt supply concerns. Iron phosphate (LFP) batteries, which don't use nickel or cobalt, are traditionally cheaper and safer, but they offer less energy density, which means less efficient and shorter range for electric vehicles. However, they have improved enough recently that it now makes sense to use cobalt-free batteries in lower-end and shorter-range vehicles. It also frees up the production of battery cells with other, more energy-dense chemistries to produce more longer-range vehicles.

Tesla already moved its Standard Range Model 3 and Model Y produced in China to LFP cells. Last year, Tesla also announced it is "shifting to Lithium Iron Phosphate (LFP) battery chemistry globally" for "standard range vehicles." It confirmed that the automaker planned to switch the Model 3 Standard Range, also known as Model 3 Rear-Wheel-Drive, being produced in the Fremont factory to LFP cells, too.

Now with the release of Tesla's Q1 2022 financial results, Tesla confirmed that nearly half of all vehicles produced are now using LFP batteries: "Diversification of battery chemistries is critical for long-term capacity growth, to better optimize our products for their various use cases and expand our supplier base. This is why nearly half of Tesla vehicles produced in Q1 were equipped with a lithium iron phosphate (LFP) battery, containing no nickel or cobalt. Currently, LFP batteries are used in most of our standard range vehicle products, as well as commercial energy storage applications. As a result of our energy efficient motors, a Model 3 with an LFP battery pack can still achieve a 267-mile EPA range." This would mean that roughly half of Tesla's volume comes from Model 3 Rear-Wheel-Drive, the cheapest Tesla vehicle, and the Model Y Standard Range, which is only offered in China.

Slashdot Top Deals