New Revelations From the Snowden Archive Surface (computerweekly.com) 151

An anonymous reader quotes a report from Computer Weekly: A doctoral thesis by American investigative journalist and post-doctoral researcher Jacob Appelbaum has now revealed unpublished information from the Snowden archive. These revelations go back a decade, but remain of indisputable public interest:

- The NSA listed Cavium, an American semiconductor company marketing Central Processing Units (CPUs) – the main processor in a computer which runs the operating system and applications -- as a successful example of a "SIGINT-enabled" CPU supplier. Cavium, now owned by Marvell, said it does not implement back doors for any government.
- The NSA compromised lawful Russian interception infrastructure, SORM. The NSA archive contains slides showing two Russian officers wearing jackets with a slogan written in Cyrillic: "You talk, we listen." The NSA and/or GCHQ has also compromised Key European LI [lawful interception] systems.
- Among example targets of its mass surveillance program, PRISM, the NSA listed the Tibetan government in exile.

These revelations have surfaced for the first time thanks to a doctoral thesis authored by Appelbaum towards earning a degree in applied cryptography from the Eindhoven University of Technology in the Netherlands. Communication in a world of pervasive surveillance is a public document and has been downloaded over 18,000 times since March 2022 when it was first published. [...] We asked Jacob Appelbaum, currently a post-doctoral researcher at the Eindhoven University of Technology, why he chose to publish those revelations in a technically written thesis rather than a mass-circulation newspaper. He replied: "As an academic, I see that the details included are in the public interest, and highly relevant for the topic covered in my thesis, as it covers the topic of large-scale adversaries engaging in targeted and mass surveillance."
According to The Register, "Marvell (the owner of Cavium since 2018) denies the allegations that it or Cavium placed backdoors in products at the behest of the U.S. government.

Appelbaum's thesis wasn't given much attention until it was mentioned in Electrospaces.net's security blog last week.

French Drillers May Have Stumbled Upon a Mammoth Hydrogen Deposit (theverge.com) 121

An anonymous reader quotes a report from The Verge: On the outskirts of the small town of Folschviller in eastern France stand three nondescript sheds. One of these temporary structures has recently become a hive of activity due to a continuous stream of visitors, including scientists, journalists, and the public. The shed sits above a borehole first drilled in 2006 and houses a gas measurement system called SysMoG, which was originally developed to determine the underground methane concentration. While the device did detect almost pure methane (99 percent) at a depth of 650 meters, probing further down, the borehole resulted in an unexpected and surprising discovery: hydrogen in high concentration. "At 1,100 meters, the concentration of dissolved hydrogen is 14 percent. At 3,000 meters, the estimated concentration could be as high as 90 percent," Jacques Pironon, director of research at GeoRessources lab at the University de Lorraine, said. Based on the estimates of methane resources and the concentration of hydrogen detected so far, scientists have conjectured that the Lorraine region in eastern France, of which Folschviller is a part, could contain 46 million tons of white -- or naturally produced -- hydrogen. That would make it one of the world's largest known hydrogen deposits.

This remarkable discovery was not the objective of the project, called Regalor. Instead, it aimed to determine the feasibility of methane production in the Lorraine region and to record the presence of traces of other gases. "Our original research was related to the study of carboniferous sediments in northeast France. This was important as Lorraine was one of France's largest coal-producing regions," Pironon said. [...] Soon, the researchers will start taking measurements in three other boreholes at similar depths to understand if the hydrogen concentration remains high as you move laterally from the site of the original borehole. "If the concentration is similar, the next step, which is being discussed with the authorities, would be to drill a hole 3,000 meters deep to validate the evolution of the hydrogen concentration with depth," he said. The deeper borehole could also throw up another surprise. "Besides knowing the level of hydrogen concentration, we will also know if hydrogen is present in dissolved form or in gaseous state at these depths," Pironon said.

This study could also shed light on the source of this hydrogen. According to Pironon, there are two hypotheses, one of which is related to the presence of the mineral siderite. "Hydrogen could be produced by the reaction between water and siderite, which is made of iron carbonates. We consider that the siderite could be oxidized by water molecules to produce hydrogen. The oxygen then combines with iron to produce iron oxide." According to Pironon, the other hypothesis relates its presence to the chemical processes that form coal, which, along with the release of methane, can also produce hydrogen.

Parents In US Offered Refunds For Purchases Kids Made In Fortnite (bbc.com) 29

Parents in the U.S. whose children purchased items in the popular game Fortnite without their permission will be able to claim a refund from today. The BBC reports: The U.S. regulator accused the game of tricking players into making unintended purchases and breaching privacy. Fortnite developer Epic Games agreed to pay $245 million in refunds in 2022. The Federal Trade Commission (FTC) has now begun the process of contacting 37 million people to alert them to the compensation.

The FTC said Epic Games duped players with "deceptive interfaces" that could trigger purchases while the game loaded, and accused it of having default settings that breached people's privacy. In total, it agreed to a settlement of $520 million with Epic Games over the concerns. This includes a $275 million fine relating to how Fortnite collects data on its users, including those aged under 13, without informing parents. It is the largest fine ever levied by the FTC for breaking a rule. The rest of the settlement will be paid out as refunds.


FCC Plays Whack-a-Mole With Telcos Accused of Profiting From Robocalls (arstechnica.com) 58

An anonymous reader quotes a report from Ars Technica: A suspicious phone company is on the verge of having all its calls blocked by US-based telcos after being accused of ignoring orders to investigate and block robocalls. One Owl Telecom is a US-based gateway provider that routes phone calls from outside the U.S. to consumer phone companies such as Verizon. "Robocalls on One Owl's network apparently bombarded consumers without their consent with prerecorded messages about fictitious orders," the Federal Communications Commission said yesterday.

On August 1, the FCC sent One Owl a Notification of Suspected Illegal Robocall Traffic (PDF) ordering it to investigate robocall traffic identified by USTelecom's Industry Traceback Group, block all of the identified traffic within 14 days, and "continue to block the identified gateway traffic as well as substantially similar traffic on an ongoing basis." One Owl apparently hasn't taken any of the required steps, the FCC said yesterday. "One Owl never responded, and the [FCC Enforcement] Bureau is not aware of any measures One Owl has taken to comply with the Notice," an FCC order said.

Blocking robocall traffic from companies like One Owl is a bit like playing whack-a-mole. The FCC said it previously took enforcement actions "against two other entities to whom One Owl is closely related: Illum Telecommunication Limited and One Eye LLC. While operating under different corporate names, these entities have shared personnel, IP addresses, customers, and a penchant for disregarding FCC rules." If One Owl doesn't provide an adequate response within 14 days, all phone companies receiving calls from it "will then be required to block and cease accepting all traffic received from One Owl beginning 30 days after release of the Final Determination Order," the FCC said. "One Owl faces a simple choice -- comply or lose access to U.S. communications networks," FCC Enforcement Bureau Chief Loyaan Egal said in a press release.

Terraform Fork Gets Renamed OpenTofu, Joins Linux Foundation (techcrunch.com) 30

An anonymous reader quotes a report from TechCrunch: When HashiCorp announced it was changing its Terraform license in August, it set off a firestorm in the open source community, and actually represented an existential threat to startups that were built on top of the popular open source project. The community went into action and within weeks they had written a manifesto, and soon after that launched an official fork called OpenTF. Today, that group went a step further when the Linux Foundation announced OpenTofu, the official name for the Terraform fork, which will live forever under the auspices of the foundation as an open source project. At the same time, the project announced it would be applying for entry into the Cloud Native Computing Foundation (CNCF).

"OpenTofu is an open and community-driven response to Terraform's recently announced license change from a Mozilla Public License v2.0 (MPLv2) to a Business Source License v1.1 providing everyone with a reliable, open source alternative under a neutral governance model," the foundation said in a statement. The name is deliberately playful says Yevgeniy (Jim) Brikman from the OpenTofu founding team, who is also co-founder of Gruntwork. "I'm glad your reaction was to laugh. That's a good thing. We're trying to keep things a little more humorous," Brikman told TechCrunch, but the group is dead serious when it comes to building an open fork. [...]

"The first thing was to get an alpha release out there. So you can go to the OpenTofu website and download OpenTofu and start using it and trying it out," he said. "Then the next thing is a stable release. That's coming in the very near future, but there's work to do. Once you have a stable release, people can start using it. Then we can start growing adoption, and once we start growing adoption, some of the big players will start stepping in when some of the big players start stepping in other big players will start stepping in as well."


Almost Everyone in Europe is Breathing Toxic Air (theguardian.com) 114

Europe is facing a "severe public health crisis," with almost everyone across the continent living in areas with dangerous levels of air pollution, an investigation by the Guardian has found. From the report: Analysis of data gathered using cutting-edge methodology -- including detailed satellite images and measurements from more than 1,400 ground monitoring stations -- reveals a dire picture of dirty air, with 98% of people living in areas with highly damaging fine particulate pollution that exceed World Health Organization guidelines. Almost two-thirds live in areas where air quality is more than double the WHO's guidelines.

The worst hit country in Europe is North Macedonia. Almost two-thirds of people across the country live in areas with more than four times the WHO guidelines for PM2.5, while four areas were found to have air pollution almost six times the figure, including in its capital, Skopje. Eastern Europe is significantly worse than western Europe, apart from Italy, where more than a third of those living in the Po valley and surrounding areas in the north of the country breath air that is four times the WHO figure for the most dangerous airborne particulates.


China Accuses US of Hacking Huawei Servers as Far Back as 2009 (time.com) 29

China accused the U.S. of infiltrating Huawei servers beginning in 2009, part of a broad-based effort to steal data that culminated in tens of thousands of cyber-attacks against Chinese targets last year. From a report: The Tailored Access Operations unit of the National Security Agency carried out the attacks in 2009, which then continuously monitored the servers, China's Ministry of State Security said in a post on its official WeChat account on Wednesday. It didn't provide details of attacks since 2009. Cyberattacks are a point of tension between Washington and Beijing, which has accused its political rival of orchestrating attacks against Chinese targets ever since Edward Snowden made explosive allegations about U.S. spying. Washington and cybersecurity researchers have said the Asian country has sponsored attacks against the West.

The ministry's accusations emerged as the two countries battle for technological supremacy. Huawei in particular has spurred alarm in Washington since the telecom leader unveiled a smartphone powered by an advanced chip it designed, which was made by Semiconductor Manufacturing International Corp. That's in spite of years-long U.S. sanctions intended to cut Huawei off from the American technology it needs to design sophisticated chips and phones. The U.S. has been "over-stretching" the concept of national security with its clampdown on Chinese enterprises, Foreign Ministry spokeswoman Mao Ning told reporters at a regular press briefing in Beijing on Wednesday. "What we want to tell the US is that suppression and containing of China will not stop China's development. It will only make us more resolved in our development," Mao said.


Space Drugs Factory Denied Reentry To Earth (gizmodo.com) 66

After manufacturing crystals of an HIV drug in space, the first orbital factory is stuck in orbit after being denied reentry back to Earth due to safety concerns. Gizmodo reports: The U.S. Air Force denied a request from Varda Space Industries to land its in-space manufacturing capsule at a Utah training area, while the U.S. Federal Aviation Administration (FAA) did not grant the company permission to reenter Earth's atmosphere, leaving its spacecraft hanging as the company scrambles to find a solution, TechCrunch first reported. A spokesperson from the FAA told TechCrunch in an emailed statement that the company's request was not granted at this time "due to the overall safety, risk and impact analysis."

Gizmodo reached out to Varda Space to ask which regulatory requirements have not been met, but the company responded with a two-word email that ominously read, "no comment." The California-startup did provide an update on its spacecraft through X (formerly Twitter). "We're pleased to report that our spacecraft is healthy across all systems. It was originally designed for a full year on orbit if needed," Varda Space wrote on X. "We look forward to continuing to collaborate w/ our gov partners to bring our capsule back to Earth as soon as possible."
Varda Space Industries launched its first test mission on June 12, "successfully sending a 200-pound (90-kilogram) capsule designed to carry drug research into Earth's orbit," reported CNN. "The experiment, conducted in microgravity by simple onboard machines, aims to test whether it would be possible to manufacture pharmaceuticals in space remotely."

Most US Adults Don't Believe Benefits of AI Outweigh the Risks, New Survey Finds (axios.com) 96

The majority of U.S. adults don't believe the benefits of artificial intelligence outweigh the risks, according to a new Mitre-Harris Poll released Tuesday. From a report: 54% of the 2,063 adults in a Mitre-Harris Poll survey in July said they were more concerned about the risks of AI than they were excited about the potential benefits. At the same time, 39% of adults said they believed today's AI technologies are safe and secure -- down 9 points from the previous survey in November 2022. AI operators and the tech industry are eyeing new regulations and policy changes to secure their models and mitigate the security and privacy risks associated with them.

The new survey data is some of the first to highlight the growing support for these regulatory efforts. "While the public has started to benefit from new AI capabilities such as ChatGPT, we've all watched as chatbots have spread political disinformation and shared dangerous medical advice," said Douglas Robbins, vice president of engineering and prototyping at the nonprofit security research and development firm Mitre, in a statement. "Strengthening existing government regulation and increasing public and private investments in AI assurance can play a critical role in addressing these concerns," he added.

UK Parliament Passes Online Safety Bill (techcrunch.com) 75

An anonymous reader quotes a report from TechCrunch: Controversial UK legislation that brings in a new regime of content moderation rules for online platforms and services -- establishing the comms watchdog Ofcom as the main Internet regulator -- has been passed by parliament today, paving the way for Royal Assent and the Online Safety Bill becoming law in the coming days. Speaking during the bill's final stages in the House of Lords, Lord Parkinson of Whitley Bay reiterated that the government's intention for the legislation is "to make the UK the safest place in the world to be online, particularly for children." Following affirmative votes as peers considered some last stage amendments he added that attention now moves "very swiftly to Ofcom who stand ready to implement this -- and do so swiftly."

The legislation empowers Ofcom to levy fines of up to 10% (or up to 18 million pounds whichever is higher) of annual turnover for violations of the regime. The Online Safety (nee Harms) Bill has been years in the making as UK policymakers have grappled with how to response to a range of online safety concerns. In 2019 these efforts manifested as a white paper with a focus on rules for tackling illegal content (such as terrorism and CSAM) but also an ambition to address a broad sweep of online activity that might be considered harmful, such as violent content and the incitement of violence; encouraging suicide; disinformation; cyber bullying; and adult material being accessed by children. The effort then morphed into a bill that was finally published in May 2021. [...]

In a brief statement the UK's new web content sheriff gave no hint of the complex challenges that lie ahead -- merely welcoming the bill's passage through parliament and stating that it stands ready to implement the new rulebook. "Today is a major milestone in the mission to create a safer life online for children and adults in the UK. Everyone at Ofcom feels privileged to be entrusted with this important role, and we're ready to start implementing these new laws," said Dame Melanie Dawes, Ofcom's CEO. "Very soon after the Bill receives Royal Assent, we'll consult on the first set of standards that we'll expect tech firms to meet in tackling illegal online harms, including child sexual exploitation, fraud and terrorism." Beyond specific issues of concern, there is over-arching general worry over the scale of the regulatory burden the legislation will apply to the UK's digital economy -- since the rules apply not only to major social media platforms; scores of far smaller and less well resourced online services must also comply or risk big penalties.


Antarctic Sea-Ice at 'Mind-Blowing' Low Alarms Experts (bbc.com) 200

The sea-ice surrounding Antarctica is well below any previous recorded winter level, satellite data shows, a worrying new benchmark for a region that once seemed resistant to global warming. BBC: "It's so far outside anything we've seen, it's almost mind-blowing," says Walter Meier, who monitors sea-ice with the National Snow and Ice Data Center. An unstable Antarctica could have far-reaching consequences, polar experts warn. Antarctica's huge ice expanse regulates the planet's temperature, as the white surface reflects the Sun's energy back into the atmosphere and also cools the water beneath and near it.

Without its ice cooling the planet, Antarctica could transform from Earth's refrigerator to a radiator, experts say. The ice that floats on the Antarctic Ocean's surface now measures less than 17 million sq km - that is 1.5 million sq km of sea-ice less than the September average, and well below previous winter record lows. That's an area of missing ice about five times the size of the British Isles. Dr Meier is not optimistic that the sea-ice will recover to a significant degree.

Scientists are still trying to identify all the factors that led to this year's low sea-ice - but studying trends in Antarctica has historically been challenging. In a year when several global heat and ocean temperature records have broken, some scientists insist the low sea-ice is the measure to pay attention to. "We can see how much more vulnerable it is," says Dr Robbie Mallett, of the University of Manitoba, who is based on the Antarctic peninsula. Already braving isolation, extreme cold and powerful winds, this year's thin sea-ice has made his team's work even more difficult. "There is a risk that it breaks off and drifts out to sea with us on it," Dr Mallett says.


US News' 2024 College Ranking Boosts Public Universities (cbsnews.com) 28

U.S. News & World Report's 2024 college rankings features many of the usual prestigious institutions at the top of the list, but also vaults some schools much higher after the publisher revised its grading system to reward different criteria. From a report: U.S News' ranking algorithm now based more than 50% of an institution's score on what it describes as "success in enrolling and graduating students from all backgrounds with manageable debt and post-graduate success." The system also places greater emphasis on "social mobility," which generally refers to an individual making gains in education, income and other markers of socioeconomic status. Overall, more than a dozen public universities shot up 50 spots on the annual list of the U.S.' best colleges, while several elite private schools largely held their ground, the new report shows.

"The significant changes in this year's methodology are part of the ongoing evolution to make sure our rankings capture what is most important for students as they compare colleges and select the school that is right for them," U.S. News CEO Eric Gertler said in a statement. The change comes after a chorus of critics complained that the publication's rankings reinforce elitism and do little to help students find schools that suit their academic needs and financial circumstances. A growing number of schools, including elite institutions such as Columbia University and the Harvard and Yale law schools, also have stopped participating in the ranking and publicly criticized U.S. News' methodology.

US Federal Agencies Seek to Streamline 'Hodgepodge' of Cyber Reporting Rules (bloomberg.com) 7

The Department of Homeland Security wants Congress and other federal agencies to help it streamline 52 different cyber reporting requirements to protect critical infrastructure and ease regulatory burdens on hacking victims. On Tuesday, it released a 107-page report that it hopes will serve as a road map to smooth that process. From a report: More than 30 federal agencies and departments, including the Nuclear Regulatory Commission, Comptroller of the Currency and US Secret Service, have met since June 2022 to hammer out how to reduce regulatory overlap as the federal government grapples with the messy state of cyber reporting rules. They are among members of the Cybersecurity Incident Reporting Council, which was set up as part of a new cyber reporting law passed last year and developed the report recommendations.

"Everybody is desperate for some harmonization and standardization here," Robert Silvers, DHS's under secretary for strategy, policy and plans who chairs the council, told Bloomberg News in an interview. "This is a first-of-its-kind effort." Federal agencies know well that cyber reporting requirements have become "too much of a patchwork," Silvers added. There are already 45 existing reporting requirements administered by 22 federal agencies, spanning national and economic security concerns to consumer and privacy protections, according to the report. Seven more requirements are expected, including the reporting law that created the council, and a further five are under consideration, according to the report.

One of the FBI's Most Wanted Hackers Is Trolling the US Government (techcrunch.com) 52

An anonymous reader quotes a report from TechCrunch: Earlier this year, the U.S. government indicted Russian hacker Mikhail Matveev, also known by his online monikers "Wazawaka" and "Boriselcin," accusing him of being "a prolific ransomware affiliate" who carried out "significant attacks" against companies and critical infrastructure in the U.S. and elsewhere. The feds also accused him of being a "central figure" in the development and deployment of the notorious ransomware variants like Hive, LockBit, and Babuk. Matveev is such a prominent cybercriminal that the FBI designated him as one of its most wanted hackers. Matveev, who the FBI believes he remains in Russia, is unlikely to face extradition to the United States.

For Matveev, however, life seems to go on so well that he is now taunting the feds by making a T-shirt with his own most wanted poster, and asking his Twitter followers if they want merch. When reached by TechCrunch on X, formerly Twitter, Matveev verified it was really him by showing a picture of his left hand, which has only four fingers, per Matveev's FBI's most wanted page. Matveev also sent a selfie holding a piece of paper with this reporter's name on it.

After he agreed to do an interview, we asked Matveev a dozen questions about his life as a most wanted hacker, but he didn't answer any of them. Instead, he complained that we used the word "hacker." "I don't like this designation -- hacker, we are a separate type of specialist, practical and using our knowledge and resources without water and writing articles," he wrote in an X direct message. "I was interested only in terms of financial motivation, roughly speaking, I was thinking about what to do, sell people or become. it, [sic] let me tell you how I lost my finger?" At that point, Matveev stopped answering messages.

Court Blocks California's Online Child Safety Law (theverge.com) 23

A federal judge has granted a request to block the California Age-Appropriate Design Code Act (CAADCA), a law that requires special data safeguards for underage users online. The Verge reports: In a ruling (PDF) issued today, Judge Beth Freeman granted a preliminary injunction for tech industry group NetChoice, saying the law likely violates the First Amendment. It's the latest of several state-level internet regulations to be blocked while a lawsuit against them proceeds, including some that are likely bound for the Supreme Court. The CAADCA is meant to expand on existing laws -- like the federal COPPA framework -- that govern how sites can collect data from children. But Judge Freeman objected to several of its provisions, saying they would unlawfully target legal speech. "Although the stated purpose of the Act -- protecting children when they are online -- clearly is important, NetChoice has shown that it is likely to succeed on the merits of its argument that the provisions of the CAADCA intended to achieve that purpose do not pass constitutional muster," wrote Freeman.

Freeman cites arguments made by legal writer Eric Goldman, who argued that the law would force sites to erect barriers for children and adults alike. Among other things, the ruling takes issue with the requirement that sites estimate visitors' ages to detect underage users. The provision is ostensibly meant to cut down on the amount of data collected about young users, but Freeman notes that it could involve invasive technology like face scans or analyzing biometric information -- ironically requiring users to provide more personal information.

The law offers sites an alternative of making data collection for all users follow the standards for minors, but Freeman found that this would also chill legal speech since part of the law's goal is to avoid targeted advertising that would show objectionable content to children. "Data and privacy protections intended to shield children from harmful content, if applied to adults, will also shield adults from that same content," Freeman concluded.

Textbook Publishers Sue Shadow Library LibGen For Copyright Infringement (theregister.com) 30

A group of publishers in the U.S. have filed a lawsuit against the "notorious" online database Library Genesis (Libgen), a website known for providing free access to scientific papers and books. The lawsuit accuses Libgen of facilitating the unauthorized distribution of copyrighted academic materials. The Register reports: The suit, filed in a New York federal court [PDF], asks for a legal order "requiring the transfer of the Libgen domain names to plaintiffs or, at plaintiffs' election, canceling or deleting the Libgen domain names," with the idea of frustrating visitors -- mostly students -- believed to number in their millions. The filing said that according to similarweb.com, the sites collectively were visited by 9 million people from the U.S. each month from March to May 2023. The suit alleges that several of the Libgen websites solicit "donations" from users. "These solicitations are in English and seek payments only in Bitcoin or [Monero]." It adds: "one Libgen Site reports that it has raised $182,540 from donations since January 1, 2023."

The publishers also claim the people who run LibGen -- named in the suit as Does 1-50 and whom it says "are believed to reside outside of the United States at unknown foreign locations" -- derive "revenue from interstate or international commerce, including through advertisements." It goes on to add: "Defendants compete directly with Plaintiffs by distributing infringing copies of their works for free, displacing legitimate sales. When a consumer obtains Plaintiffs' works from the Libgen Sites instead of through legitimate channels, no remuneration is provided to Plaintiffs or their authors for the substantial investments they have made to create and publish the works."

The textbook publishers claim that "through social media and from their peers, students are bombarded with messages to use the Libgen Sites instead of paying for legal copies of textbooks" -- thus depriving the publishers and the authors they represent of their income. The suit also asks for damages without detailing an amount, although it asks for "an accounting and disgorgement of Defendants' profits, gains, and advantages realized from their unlawful conduct." The complaint claims the ads are in English and for various "U.S. products, such as browser extensions and online games". The suit adds that some "also appear to be phishing attempts, which can result in users downloading a virus or other malicious program onto their computers."

The lawsuit also calls out Google and "other intermediaries," U.S. companies it claims help LibGen "conduct their unlawful operations" -- "NameCheap for domain registration services, Cloudflare for proxy services, and Google for search engine services." It goes on to include a screenshot of Google's "knowledge panel," which it says "describes Libgen as a site [that] enables free access to content that is otherwise paywalled or not digitized elsewhere."

'In Most Industries, Regulation Tends To Prevent Competition' 261

Elad Gil, writing in a blog post: In most industries, regulation prevents competition. This famous chart of prices over time reflects how highly regulated industries (healthcare, education, energy) have their costs driven up over time, while less regulated industries (clothing, software, toys) drop costs dramatically over time. (Please note I do not believe these are inflation adjusted - so 60-70% may be "break even" pricing inflation adjusted.)

Regulation favors incumbents in two ways. First, it increase the cost of entering a market, in some cases dramatically. The high cost of clinical trials and the extra hurdles put in place to launch a drug are good examples of this. A must-watch video is this one with Paul Janssen, one of the giants of pharma, in which he states that the vast majority of drug development budgets are wasted on tests imposed by regulators which "has little to do with actual research or actual development." This is a partial explanation for why (outside of Moderna, an accident of COVID), no $40B+ market cap new biopharma company has been launched in almost 40 years (despite healthcare being 20% of US GDP).

Secondly, regulation favors incumbents via something known as "regulatory capture." In regulatory capture, the regulators become beholden to a specific industry lobby or group -- for example by receiving jobs in the industry after working as a regulator, or via specific forms of lobbying. There becomes a strong incentive to "play nice" with the incumbents by regulators and to bias regulations their way, in order to get favors later in life.
Additional resource: All-In Summit: Bill Gurley Presents 2,851 Miles.
US Asks for Help Finding Missing F-35 Fighter Jet After Crash (bloomberg.com) 103

The United States' military is on the hunt for an F-35 fighter jet that has gone missing following an incident that forced the pilot to eject from the advanced stealth aircraft over South Carolina. Bloomberg News: Emergency response teams are trying to find what's left of the F-35B Lightning II jet, which suffered what the military called a "mishap" on Sunday afternoon, according to social media posts by Joint Base Charleston, an air base in South Carolina. The unidentified pilot ejected safely and was taken to a local hospital in a stable condition. Joint Base Charleston called on the public to cooperate with military and civilian authorities as the search for the F-35 jet continues. The air base said it was working with Marine Corps Air Station Beaufort to search for the plane north of North Charleston around Lake Moultrie and Lake Marion, based on its last-known location.

Lockheed Martin is the manufacturer behind the F-35, a single-seat fighter craft used by militaries around the world. The aircraft was a vertical take-off version used by in the US Marine Corps, and the jet is popular for its stealth qualities that make it difficult to detect by radar. The F-35 program, the most expensive US weapons program ever, is projected to cost $400 billion in development and acquisition, plus an additional $1.2 trillion to operate and maintain the fleet over more than 60 years. Each jet can cost more than $160 million, depending on the variant.


Was China's 'Spy Balloon' Just Blown Off Course? (cbsnews.com) 112

China appears to have suspended its global surveillance balloon program after a balloon was spotted drifting over the United States in February.

But now an anonymous reader shares this report from CBS News: Seven months later, Gen. Mark Milley, chairman of the Joint Chiefs of Staff, tells "CBS News Sunday Morning" the balloon wasn't spying. "The intelligence community, their assessment — and it's a high-confidence assessment — [is] that there was no intelligence collection by that balloon," he said.

So, why was it over the United States? There are various theories, with at least one leading theory that it was blown off-track. The balloon had been headed toward Hawaii, but the winds at 60,000 feet apparently took over. "Those winds are very high," Milley said. "The particular motor on that aircraft can't go against those winds at that altitude..."

After the Navy raised the wreckage from the bottom of the Atlantic, technical experts discovered the balloon's sensors had never been activated while over the Continental United States. But by then, the damage to U.S.-China relations had been done.

On the CBS News show Sunday Morning, the host had this exchange with America's chairman of the Joint Chiefs of Staff.

CBS: "Bottom line, it was a spy balloon, but it wasn't spying?"

Chairman of the Joint Chiefs of Staff: "I would say it was a spy balloon that we know with high degree of certainty got no intelligence, and didn't transmit any intelligence back to China."

Las Vegas Still Struggling to Recover from Last Sunday's Cyberattack (go.com) 46

"Chaos and Concern in Sin City," read this morning's headline on a video report from ABC News about "the massive cyberattack in Las Vegas crippling several hotels and casinos, and putting a damper on getaways for thousands of tourists there." "Today marks a week since that cyberattack hit Las Vegas, and MGM hotels and casinos are still working on getting systems back up and running.. The online reservation site for MGM is still down, ATMs not working, and those playing the slot machines or even video poker having to wait for attendants to pay them out in cash. All of this fiasco leading to long lines at check-in, and now a cyber investigation with the FBI...

Other gaming resorts also having issues. Caesar's entertainment says they too were a victim of a cyberattack, but their online operations were not impacted. Then this weekend at the Venetian, an outage shutting down some slots, but the resort says they're back up, and that at least thankfully was not due to a cyber attack.

They report MGM properties were affected as far away as Atlantic City, New Jersey.

