Data Storage

How a Redditor Ended Up With an Industrial-Grade Netflix Server (vice.com) 40

A Redditor says they've managed to get a hold of an old Netflix server for free, and has posted a detailed online look at the once mysterious hardware. The devices were part of Netflix's Open Connect Content Delivery Network (CDN), and can often be found embedded within major ISP networks to ensure your Netflix streams don't suck. From a report: Reddit user PoisonWaffle3 said the ISP he currently works for has been offloading old Netflix servers as they upgrade to more modern equipment. In a Reddit thread titled "So I got a Netflix cache server..." he posted a photo of the server, which is bright Netflix red, and explained how he was curious about what's inside the boxes given how little public information was available.

"All I could find online was overviews, installation/config guides for their proprietary software, etc.," he said. "No specs, no clue what was inside the red box." Dave Temkin, Netflix's former Vice President of Network Systems Infrastructure told Motherboard there's nothing too mysterious about what the servers can do, though they significantly help improve video streaming by shortening overall content transit time. "They're just an Intel FreeBSD box," he said. "We got Linux running on some of the generations of that box as well."

Netflix's Open Connect Content Delivery Network hardware caches popular Netflix content to reduce overall strain across broadband networks. Netflix lets major broadband ISPs embed a CDN server on the ISP network for free; the shorter transit time then helps improve video delivery, of benefit to broadband providers and Netflix alike. It took all of three screws for PoisonWaffle3 to get inside the mysterious red unit, at which point users discovered a "fairly standard" Supermicro board, a single Xeon E5 2650L v2 processor, 64GB of DDR3 memory, and a 10 gigabit ethernet card. They also found 36 7.2TB 7200RPM drives and six 500GB Micron solid state drives, for a grand total of 262 terabytes of storage.


Google Introduces Cloud-Based Blockchain Node Service For Ethereum (coindesk.com) 44

Tech giant Google said Thursday it will be launching a cloud-based node engine for Ethereum projects. CoinDesk reports: The company said its Google Cloud Blockchain Node Engine will be a "fully managed node-hosting service that can minimize the need for node operations," meaning that Google will be responsible for monitoring node activity and restarting them during outages. A node is a type of computer that runs a blockchain's software to validate and store the history of transactions on a blockchain's network. At the time of launch, Google will be supporting only Ethereum nodes. Google's announcement signifies the growing attention that technology giants are giving toward blockchain, crypto and Web3 projects. "Blockchain is changing the way the world stores and moves its information," Google said in its announcement.

Samsung Privacy-Protecting Maintenance Mode Is Coming To Galaxy S22s Worldwide (theverge.com) 13

Samsung is starting to roll out a "Maintenance Mode" feature for its phones that's designed to keep your messages, photos, info, and accounts safe when you're getting your phone repaired. The Verge reports: According to Samsung's press release, Maintenance Mode basically creates a separate user account that will let someone access "core functions" of the phone without being able to see any of your data. That means a repair tech will still be able to test your phone, but you won't have to worry about them seeing anything they shouldn't. Once you get your phone back, you can unlock it to turn off Maintenance Mode, which will also undo anything that was done while the phone was being repaired (e.g., test photos will be erased, new apps will be uninstalled, and settings changes will be reversed).

Samsung says the feature will be "gradually rolling out over the next few months" to select phones running the Android 13-based One UI 5 -- if you want an idea of when your phone might be getting that update, check out this article. It'll also roll out to "more Galaxy devices" throughout next year. The company does warn, however, that the "timing of availability may vary by market, model and network provider," as updates can take a while to filter through carriers.


Atmospheric Levels of All Three Greenhouse Gases Hit Record High (theguardian.com) 143

Atmospheric levels of all three greenhouse gases have reached record highs, according to a study by the World Meteorological Organization, which scientists say means the world is "heading in the wrong direction." From a report: The WMO found there was the biggest year-on-year jump in methane concentrations in 2020 and 2021 since systematic measurements began almost 40 years ago. Methane levels have risen rapidly in recent years, puzzling scientists. Some blamed it on an increase in fracking in the US but this came into doubt as industrial emissions were not showing a similarly sharp rise.

Now the theory is that the methane rise could be caused by activities of microbes in wetlands, rice paddies and the guts of ruminants. Rising temperatures have caused the ideal conditions for microbial methane production, as they enjoy warm, damp areas. Carbon dioxide levels are also soaring, with the jump from 2020 to 2021 larger than the annual growth rate over the past decade. Measurements from WMO's global atmosphere watch network stations show these levels continue to rise. These greenhouse gases cause global heating, with the warming effect rising by 50% between 1990 and 2021. Carbon dioxide comprised about 80% of this increase. According to the WMO, carbon dioxide concentrations in 2021 were 415.7 parts per million, methane was 1908 parts per billion (ppb) and nitrous oxide was 334.5 ppb. These are respectively 149%, 262% and 124% of pre-industrial levels.

The Internet

Comcast's New Higher Upload Speeds Require $25-Per-Month xFi Complete Add-On 38

The availability of Comcast's promised internet speed boosts has a catch: users need to purchase a $25-per-month xFi Complete add-on. Ars Technica reports: "As markets launch, Xfinity Internet customers who subscribe to xFi Complete will have their upload speeds increased between 5 and 10 times faster," an announcement last week said. "xFi Complete includes an xFi gateway, advanced cybersecurity protection at home and on the go, tech auto-upgrades for a new gateway after three years, and wall-to-wall Wi-Fi coverage with an xFi Pod [Wi-Fi extender] included if recommended. Now, another benefit of xFi Complete is faster upload speeds."

Comcast is deploying the speed upgrade in the Northeast US over the next couple of months. Plans with 10Mbps upload speeds will get up to 100Mbps upload speeds once the new tiers roll out in your region -- if you pay for xFi Complete. Comcast told Ars that faster upload speeds will come to customer-owned modems "later next year" but did not provide a more specific timeline. There is a cheaper way to get the same xFi Gateway with Wi-Fi 6E, as Comcast offers the option to rent that piece of hardware for $14 a month. But Comcast is only making the upload boost available to those who subscribe to the pricier xFi Complete service. While the standard monthly rate for xFi Complete is $25, new customers who sign up by December 31 can get it for $20 monthly during the first year of service.

We asked Comcast today if there's any technical reason it can't deliver the higher upload speeds on customer-owned equipment. A company spokesperson responded that Comcast is working on bringing faster uploads to non-Comcast modems. "We intend to extend the experience to customer-owned modems later next year and are working through the technical requirements as we learn," Comcast said. "We started offering it with our own equipment first and now are working through how to extend to customer-owned equipment." Comcast also said that giving the upload boost to xFi Complete customers first follows its "typical validate, test, and certification process for a new network innovation." But if the reasons for limiting the upload boost to Comcast hardware initially are purely technical instead of revenue-based, it's not clear why people who rent the gateway for $14 a month shouldn't get the same benefit.
The Internet

Chip Can Transmit All of the Internet's Traffic Every Second (newscientist.com) 53

A single computer chip has transmitted a record 1.84 petabits of data per second via a fibre-optic cable -- enough bandwidth to download 230 million photographs in that time, and more traffic than travels through the entire internet's backbone network per second. From a report: Asbjorn Arvad Jorgensen at the Technical University of Denmark in Copenhagen and his colleagues have used a photonic chip -- a technology that allows optical components to be built onto computer chips -- to divide a stream of data into thousands of separate channels and transmit them all at once over 7.9 kilometres.

First, the team split the data stream into 37 sections, each of which was sent down a separate core of the fibre-optic cable. Next, each of these channels was split into 223 data chunks that existed in individual slices of the electromagnetic spectrum. This "frequency comb" of equidistant spikes of light across the spectrum allowed data to be transmitted in different colours at the same time without interfering with each other, massively increasing the capacity of each core. Although data transfer rates of up to 10.66 petabits per second have been achieved before using bulky equipment, this research sets a record for transmission using a single computer chip as a light source. The technology could enable the creation of simple, single chips that can send vastly more data than existing models, slashing energy costs and increasing bandwidth.
Journal reference: Nature, DOI: 10.1038/s41566-022-01082-z

Twitter Working on 'Wallet Prototype' that Supports Crypto Deposit and Withdrawal 25

Social network Twitter has bigger ambitions with crypto. According to Jane Manchun Wong, a Hong Kong-based app researcher and reverse engineer with a great track record of finding evidence of upcoming products and services, the company is working on a "wallet prototype" that supports crypto deposit and withdrawal. The move will make Twitter the latest mainstream tech giant to make further inroads with web 3.

The Difficulty of Creating a Laundry-folding Robot (npr.org) 75

"It might be a while before you can buy a 'Roomba for laundry'," jokes Slashdot reader Tony Isaac, pointing out that "while robots have been developed that can fold specific types of laundry, there's still not a good robot that can do the job quickly, or for all types."

But NPR reports laundry-folding robots are getting closer: As NPR has reported, machines need clear rules in order to function, and it's hard for them to figure out what exactly is going on in those messy piles That's not to say that it's completely impossible. University of California, Berkeley professor Pieter Abbeel spent years teaching a robot how to fold a towel, eventually cutting that process down from 20 minutes to a whopping minute and a half.

And Silicon Valley-based company FoldiMate raised hopes and eyebrows when it showed off a prototype of its eponymous laundry-folding robot at the Consumer Electronics Show in early 2019. It said the machine could fold some 25 pieces of laundry — except for small items like socks and large items like sheets — in under five minutes, with an estimated price tag of $980. It's unclear what happened to that company — its website is down and it hasn't tweeted since April 2020. Its sole competitor, a Japanese company with an AI-powered prototype, filed for bankruptcy.

In sum, most robots have not generally been equipped for the task. But an international group of researchers say their new method could change that — or at least speed up the process. Researchers are calling the new method, SpeedFolding. It's a "reliable and efficient bimanual system" — meaning it involves two hands — that's able to smooth and fold a crumpled garment in record speed (for robots, that is). SpeedFolding can fold 30 to 40 strewn-about garments per hour, compared to previous models that averaged three to six garments in that same time span, according to researchers. They say their robot can fold items in under two minutes, with a success rate of 93%.

"Real-world experiments show that the system is able to generalize to unseen garments of different color, shape, and stiffness," they add.

According to the article, the team will be presenting their paper at a robotics conference in Kyoto this month, and they've also posted a one-minute video on YouTube. (Their solution involves both an overhead camera and a novel neural network called BiManual Manipulation Network that "studied 4,300 human and machine-assisted actions in order to learn how to smooth and fold garments from a random configuration."

"While researchers describe SpeedFolding as a significant improvement, it's not likely to hit the market anytime soon," notes NPR. "For one, Ars Technica tracked down a robot similar to the one they used and found that it retails for $58,000."

Nym's Plan to Boost Internet Privacy Through 'Mixnets' (quantamagazine.org) 22

Harry Halpin helped create uniform cryptography standards for the World Wide Web Consortium, reports Quanta magazine — but "he also wanted to protect the lower, foundational level: the network through which the information is transmitted.

"In 2018, he started Nym Technologies to take on this problem.... Halpin spoke with Quanta from Nym's headquarters in Neuchâtel, Switzerland." Halpin: The trickier problem is this: How do I communicate with you so that no one else knows I'm communicating with you, even if our messages are encrypted? You can get a sense of what people are saying from the pattern of communication: Who are you talking with, when are your conversations, how long do they last...?

There are two key elements: One is the "mixnet," a technology invented by David Chaum in 1979 that my team has improved. It relies on the premise that you can't be anonymous by yourself; you can only be anonymous in a crowd. You start with a message and break it into smaller units, communications packets, that you can think of as playing cards. Next, you encrypt each card and randomly send it to a "mixnode" — a computer where it will be mixed with cards from other senders. This happens three separate times and at three separate mixnodes. Then each card is delivered to the intended recipient, where all the cards from the original message are decrypted and put back into the proper order. No person who oversees mixing at a single mixnode can know both the card's origin and its destination. In other words, no one can know who you are talking to.

Q: That was the original mixnet, so what improvements have you made?

Halpin: For one thing, we make use of the notion of entropy, a measure of randomness that was invented for this application by Claudia Diaz, a computer privacy professor at KU Leuven and Nym's chief scientist. Each packet you receive on the Nym network has a probability attached to it that tells you, for instance, the odds that it came from any given individual.... Our system uses a statistical process that allows you both to measure entropy and to maximize it — the greater the entropy, the greater the anonymity. There are no other systems out there today that can let users know how private their communications are.

Q: What's the second key element you referred to?

Halpin: Mixnets, as I said, have been around a long time. The reason they've never taken off has a lot to do with economics. Where do the people who are going to do the mixing come from, and how do you pay them? We think we have an answer. And the kernel of that idea came from a conversation I had in 2017 with Adam Back, a cryptographer who developed bitcoin's central "proof of work" algorithm. I asked him what he would do if he were to redesign bitcoin. He said it would be great if all the computer processing done to verify cryptocurrency transactions — by solving so-called Merkle puzzles that have no practical value outside of bitcoin — could instead be used to ensure privacy.

The computationally expensive part of privacy is the mixing, so it occurred to me that we could use a bitcoin-inspired system to incentivize people to do the mixing. We built our company around that idea....

A new paper that came out in June shows that this approach can lead to an economically sustainable mixnet....

We are not building a currency system or trying to replace the dollar. We just want to provide privacy to ordinary people.


Zeek Becoming Part of Microsoft Windows (corelight.com) 21

First released in 1998, the BSD-licensed software Zeek (originally named "Bro") is about to get more widely adopted, writes long-time Slashdot reader skinfaxi: Zeek, the open source network security monitoring platform, is being integrated into Windows and "is now deployed on more than one billion global endpoints," according to an announcement from Corelight.
From Corelight's press release: Corelight, the leader in open network detection and response, today announced the integration of Zeek, the world's most popular open source network security monitoring platform, as a component of Microsoft Windows and Defender for Endpoint. The integration will help security teams respond to the most challenging attacks by providing "richer signals for advanced threat hunting, complete and accurate discovery of IoT devices, and more powerful detection and response capabilities."

Originally created by Corelight co-founder and chief scientist Dr. Vern Paxson while at Lawrence Berkeley National Laboratory, Zeek transforms network traffic into compact and high-fidelity logs, file content, and behavioral analytics to accelerate security operations. Vital funding for Zeek came initially from the National Science Foundation and the US Department of Energy's Office of Science. As adoption increased, Corelight was founded to provide a financial model and corporate sponsor for the project....

"Microsoft is strongly committed to supporting open source projects and ecosystems," said Rob Lefferts, corporate vice president for Microsoft. "We're proud to be working with Zeek and are thrilled to bring this level of network intelligence and monitoring to our customers."

"This is an amazing development for Zeek and its community of contributors and users," said Paxson. "I never imagined that the tool I developed for network monitoring would find broader application in defending endpoints — but that's part of the creative magic of open source development.

"We are grateful for Microsoft's contributions and support, and we are excited that the project's impact, and that of the community of contributors, will increase so dramatically."

The Internet

French Police Probe Multiple Cuts of Major Internet Cables (apnews.com) 44

French police said Friday they're investigating multiple cuts to fiber-optic cables in France's second-largest city. Operators said the cables link Marseille to other cities in France and Europe and that internet and phone services were severely disrupted. From a report: The disruptions in Marseille were a taste of what analysts warn could be far larger problems in other cases if cables are systematically attacked. The vulnerability of fiber-optic cables, especially those underwater, and other key infrastructure was highlighted by the sabotage last month in the Baltic Sea of natural gas pipelines from Russia. The damage in the city in southern France also appeared to resemble suspected acts of sabotage to other cables in the country earlier this year. French cable operator and internet service provider Free said its repair teams were mobilized before dawn Wednesday to deal with "an act of vandalism on our fiber infrastructure." It said the attacks were simultaneous and on multiple spots of its fiber network near Marseille. Photos that Free published on Twitter showed multiple cables completely severed in their concrete housings buried in the ground. It said the cuts led to major disruptions to its network and phone services in the Marseille area.
Social Networks

Telegram To Auction Off Usernames Via Blockchain-based Platform (theblock.co) 20

Would you pay for a username on social media? Telegram is hoping yes. From a report: The messaging app is soon to launch a username auction platform on The Open Network (TON) blockchain, the company said in an official channel on Thursday. Telegram founder Pavel Durov revealed the project in August, citing inspiration from the success of a recent TON auction for their wallet usernames. Some, including "casino.ton," sold for over $200,000.

"If TON has been able to achieve these results, imagine how successful Telegram with its 700 million users could be if we put reserved @ usernames, group and channel links for auction," he said. But Durov isn't stopping there. "Other elements of the Telegram ecosystem, including channels, stickers or emoji, could later also become part of this marketplace," he added. Paying for usernames isn't new. Over half a million people have paid for usernames on Ethereum through the Ethereum Name Service (ENS), according to Non Fungible's market tracker. It's not just a web3 phenomenon either. It's becoming harder and harder to get the desired username on platforms like Twitter and Instagram and some people are going to great lengths to obtain them.

Lord of the Rings

'House of the Dragon' and 'Rings of Power' Face Off In Podcasting (bloomberg.com) 114

An anonymous reader quotes a report from Bloomberg: A good fall TV run comes to an end on Sunday when HBO airs its House of the Dragon season one finale, a week or so after Amazon wrapped up the first season of The Lord of the Rings: The Rings of Power. The shows aren't done yet providing content, though. Both Amazon and HBO offer companion podcasts to keep fans engaged, and both devised wildly different approaches for their audio. The podcasts offer behind-the-scenes chats with cast and crew and strive to become the definitive place to hear conversations around their respective programming. The shows' similarities end there, however.

HBO, for example, released three episodes of The Official Game of Thrones Podcast: House of the Dragon before the actual TV series aired, choosing to hype listeners up for the debut through an interview George R.R. Martin, as well as an "everything we know"-style show. Since then, the program has been released weekly alongside new episodes of the series on Sunday evenings. Michael Gluckstadt, director of podcasts for HBO and HBO Max, says the podcast will continue even after the series breaks between seasons. "There's no end date for this in sight," he said, which is atypical for podcasts the network has released in the past, including for Succession and The Gilded Age. [...] The podcast is available on all platforms, as well as on YouTube and the HBO Max app.

Meanwhile, Amazon didn't release any episodes of its The Official The Lord of the Rings: The Rings of Power Podcast until the season finale. Marshall Lewy, chief content officer at Amazon's Wondery, said the team wanted the streaming series to "speak for itself." Wondery has created companion podcasts before, namely for its own podcasts that were adapted for streaming, like Dr. Death and WeCrashed, but this marks the first time the team has worked in coordination with an Amazon series. "This is really our first opportunity to do a partnership like this connected to Prime Video," Lewy said. The podcast now receives front-and-center promotion ahead of each streaming video episode, which is the first time the coveted space has promoted something other than a Prime video series, he said. A promotion for The Official The Lord of the Rings: The Rings of Power Podcast that surfaces on Prime Video. The podcast is only available on Amazon Music, the Wondery app and Audible, a critical difference from HBO's strategy. Lewy said this decision made sense given that anyone watching the show is a Prime subscriber and can freely access Amazon Music.
"The effort put into these podcasts not only speaks to the need to increase fan engagement with the programming but to create an ongoing dialogue with viewers so they don't drop off from season to season," writes Bloomberg's Ashley Carman. "A person's podcast time likely differs from their streaming time, which in theory minimizes the risk of cannibalizing the hours that viewers could be spending on other Amazon or HBO series."

"The video services want more than just sixty minutes of their viewers' attention once a week -- they want to be a part of their day and part of their conversations with friends for as long as possible."

Parler Accidentally Doxed Elite Members When Announcing Kanye West Takeover (fortune.com) 71

Parler was so excited to tell its users that the artist formerly known as Kanye West had decided to buy the social media network, it accidentally doxed all its members. Fortune reports: The platform has been embraced by conservatives who departed Twitter over allegations of political censorship, and West, a known lover of controversy, agreed to buy it earlier this week so those users could "freely express" themselves. But in an email announcing the rapper's involvement, the company publicly copied in 300-plus email addresses of its verified VIP members instead of blind copying, allowing their personal contact details to be visible to everyone else in the email chain.

The incident was revealed by newsletter writer Adam Ryan who shared screenshots of the original message from Parler about the "monumental new chapter," explaining that they expected the acquisition to be complete by the end of the year and describing their VIP members as "an invaluable part of the Parler family and experience." Ryan's screenshot also showed the blurred-out addresses of "gold-badged" members in the email chain who consist of "influencers, celebrities, journalists, media organizations, public officials, government entities, businesses, organizations, and nonprofits."
Some of the well-known names in the email chain include Sen. Ted Cruz, former President Donald Trump, and Rep. Matt Gaetz.

Further reading: Ye's 'Buyout' Of Parler Looks Very Much Like A Failed Company Taking Advantage Of Troubled Rich Guy (Techdirt)

The Great Netflix Debate: Do Its Movies Belong in Theaters? (wsj.com) 104

Inside Netflix's movie studio, top executives lobbied Ted Sarandos, the company's co-chief executive, for much of this year to experiment with releasing more Netflix original movies broadly in theaters WSJ is reporting. From the report: They outlined their case in a memo shared in June on the company network. Some argued that Netflix is leaving hundreds of millions in box-office receipts on the table with its current strategy of showing only select movies in a few hundred theaters for at most a few weeks before streaming them, according to people familiar with the matter. Other executives thought showing movies in more theaters would create valuable buzz for the streaming service. Soon after, in an internal meeting, Mr. Sarandos told Netflix studio leaders that he had doubts, and still felt that streaming is the future of entertainment, movies included. Instead, he suggested that studio chief Scott Stuber and other executives meet with their counterparts at Sony Pictures Entertainment to see if they would agree to let Netflix stream Sony's movies just four to six weeks after they came out in theaters, instead of after six to eight months, as spelled out in a partnership the two studios reached last year.

If a new deal could be struck, some executives said, it would help Netflix understand how the company might benefit from streaming a movie shortly after it had been shown on thousands of big screens across the country. The debate inside Netflix over how best to distribute its films -- details of which haven't been previously reported -- is one that is playing out across an entertainment industry that has been rapidly upended by the rise of streaming video. Every major company in Hollywood is facing some version of the same question: What is the best way to release a movie? Is it in a cinema, with stadium seating, popcorn and digital surround sound? Or is it at home, streamed on a flat-screen TV or a laptop? Should movies go to theaters first, then to streaming, or should they be released at the same time? How long should a studio wait between theatrical and streaming release? How many theaters should show a film? Should all movies go to the big screen, or just splashy action thrillers?


Visitors of Qatar World Cup Need To Install Spyware On Their Phone (schneier.com) 110

"Everyone visiting Qatar for the World Cup needs to install spyware on their phone," writes security researcher Bruce Schneier. His comments are in response to an article from the Norwegian Broadcasting Corporation (NRK), reporting: Everyone traveling to Qatar during the football World Cup will be asked to download two apps called Ehteraz and Hayya. Briefly, Ehteraz is an covid-19 tracking app, while Hayya is an official World Cup app used to keep track of match tickets and to access the free Metro in Qatar. In particular, the covid-19 app Ehteraz asks for access to several rights on your mobile., like access to read, delete or change all content on the phone, as well as access to connect to WiFi and Bluetooth, override other apps and prevent the phone from switching off to sleep mode.

The Ehteraz app, which everyone over 18 coming to Qatar must download, also gets a number of other accesses such as an overview of your exact location, the ability to make direct calls via your phone and the ability to disable your screen lock. The Hayya app does not ask for as much, but also has a number of critical aspects. Among other things, the app asks for access to share your personal information with almost no restrictions. In addition, the Hayya app provides access to determine the phone's exact location, prevent the device from going into sleep mode, and view the phone's network connections.
It remains to be seen whether Qatar will strictly enforce the installation of these apps. "I know people who visited Saudi Arabia when that country had a similarly sketchy app requirement," says Schneier. "Some of them just didn't bother downloading the apps, and were never asked about it at the border."

Apple Restores Russian Social Network Webmail Provider To App Store (theguardian.com) 18

Apple has restored Russian social network VKontatke and webmail provider Mail.Ru to the App Store, three weeks after removing them both for sanctions violations. From a report: The two services, home-grown versions of Facebook and Gmail with domestic market share to match, were removed from Apple's platforms in late September, following a wave of British sanctions that targeted the financial organisations that own them. At the time of removal, Apple had said it was complying with the sanctions issued by the UK government.

Over 45,000 VMware ESXi Servers Just Reached End-of-Life (bleepingcomputer.com) 57

An anonymous reader quotes a report from BleepingComputer: Over 45,000 VMware ESXi servers inventoried by Lansweeper just reached end-of-life (EOL), with VMware no longer providing software and security updates unless companies purchase an extended support contract. Lansweeper develops asset management and discovery software that allows customers to track what hardware and software they are running on their network. As of October 15, 2022, VMware ESXi 6.5 and VMware ESXi 6.7 reached end-of-life and will only receive technical support but no security updates, putting the software at risk of vulnerabilities.

The company analyzed data from 6,000 customers and found 79,000 installed VMware ESXi servers. Of those servers, 36.5% (28,835) run version 6.7.0, released in April 2018, and 21.3% (16,830) are on version 6.5.0, released in November 2016. In total, there are 45,654 VMware ESXi servers reaching End of Life as of today. The findings of Lansweeper are alarming because apart from the 57% that enter a period of elevated risk, there are also another 15.8% installations that run even older versions, ranging from 3.5.0 to 5.5.0, which reached EOL quite some time ago.

In summary, right now, only about one out of four ESXi servers (26.4%) inventoried by Lansweeper are still supported and will continue to receive regular security updates until April 02, 2025. However, in reality, the number of VMware servers reaching EOL today, is likely far greater, as this report is based only on Lansweeper's customers. The technical guidance for ESXi 6.5 and 6.7 will carry on until November 15, 2023, but this concerns implementation issues, not including security risk mitigation. The only way to ensure you can continue to use older versions securely is to apply for the two-year extended support, which needs to be purchased separately. However, this does not include updates for third-party software packages. For more details about EOL dates on all VMware software products, check out this webpage.

Open Source

Fintech Giant 'The Clearing House' Joins Open-Source Patent Protection Powerhouse OIN (zdnet.com) 6

The Clearing House, a banking association and payments company owned by the largest commercial banks in the U.S., has joined the Open Invention Network (OIN) -- the world's largest patent nonaggression consortium. ZDNet reports: The OIN has long protected Linux and Linux-related software from patent aggression by rival companies. With the increase in patent troll attacks, the OIN is also defending companies from these assaults. You may not think financial companies and banks are subject to such attacks. I mean, TCH's roots go all the way back to 1853. Think again.

As Keith Bergelt, CEO of OIN, said in June, "The most sophisticated and compelling global banking and fintech companies have essentially become technology companies that employ open-source software to deliver their services at scale." Further, patent trolls "appear to be targeting them for this reason, along with the fact that financial services companies have not historically been active patent filers." That's because, historically, they've purchased most of their tech from third-party vendors.

That was then. This is now. Today, financial institutions generate more tech in-house, so they're more concerned about being granted patents, building patent portfolios, and related patent issues. Indeed, these days fintech businesses have their own Fintech Open Source Foundation (FINOS), the financial sector branch of the Linux Foundation. So, Bergelt said in a release Wednesday, "Advancements in financial services and fintech increasingly rely on open-source technologies. As the most experienced payment company in the US, and a keystone for the financial services industry, we are pleased that The Clearing House is committed to patent nonaggression in core Linux and adjacent open-source technologies."


Bitcoin Fails To Produce 1 Block For Over An Hour (coindesk.com) 189

It took more than an hour to mine a block of bitcoin (BTC) on Monday, leaving thousands of transactions stuck in an unconfirmed state. CoinDesk reports: According to on-chain data from several block explorers, the interval between the two latest blocks mined by Foundry USA and Luxor was 85 minutes. According to Mempool, over 13,000 transactions were pending before the latest block was mined.

Last week Bitcoin underwent a difficulty adjustment to ensure block confirmations kept taking place every 10 minutes. With mining difficulty surging to 35.6 trillion it becomes more expensive to mine bitcoin, which heaps pressure on a mining industry that is dealing with soaring energy prices and a crypto bear market. Tadge Dryja, founder of the Lightning Network, tweeted that an 85-minute interval between blocks can be expected to happen once every 34 days, not taking into account difficulty changes.

Slashdot Top Deals