AI

Linus Torvalds Endures A Debug Session From Hell, 'Enormously Helped' By AI 48

Linus Torvalds says AI "enormously helped" him track down a stubborn Intel Xe graphics driver bug that took 24 debugging patches and 18 kernel boots to isolate. "I'd like to call it my tireless helper, but the AI several times stated flat out that this was impossible and unsolvable and that we should just write a report about it," wrote Torvalds on the commit. "I suspect those things have been trained by people who may not be quite as stubborn as I am..." Phoronix reports: The patch by Linus Torvalds is for the Xe kernel driver and the change is no longer hand out the flat Compute Command Streamer (CCS) storage as usable vRAM. On a Battlemage G21 graphics card, he was hitting a scenario where there was a mismatch where the usable memory ended and hit a case where the GDM display manager would end up being endlessly restarted. [...]

Linus Torvalds views AI as a useful tool and in this case reaffirmed he found it "enormously helped" his effort in tracking down this Intel graphics driver bug. The Intel Xe driver fix is merged to Linux 7.3 Git and is also marked to back-porting to the stable kernel branches.
AI

Microsoft Gives Task Manager Another Task: Watching AI Workloads 61

Microsoft is expanding Windows Task Manager to show per-process NPU and GPU neural-engine usage, giving users more visibility into which apps are consuming hardware for AI workloads. The Register reports: The Processes tab can show NPU use alongside CPU and GPU activity, while the Performance tab displays overall utilization. [...] Microsoft was keen to point out the metrics that can be monitored. "As AI workloads become more common on Windows devices, visibility into NPU and GPU neural engine utilization can help you make better-informed decisions," the company said. "With the latest Task Manager improvements, you can monitor AI processing activity alongside CPU, memory, storage, and networking data from a familiar interface."
Privacy

Reverse-Lookup Service Exposed Millions of Photos of People's Faces (wired.com) 19

Security researcher Jeremiah Fowler found that people-search service ClarityCheck left more than 9 million image files accessible in an unsecured Amazon S3 bucket, despite advertising its reverse-image search as "private and secure." A separate misconfiguration also exposed email addresses, phone numbers, and other personal information. Wired reports: Overall, according to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. All of the images were stored in an unsecured Amazon S3 bucket, with files in folders named "faces" and "profiles," which could be accessed by anyone online through a URL included in the company's publicly available website code.

ClarityCheck is one of a number of so-called people-finder tools that have appeared online in recent years. These websites broadly claim to be able to search the web, public records, and other databases to identify individuals. ClarityCheck's website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds." While ClarityCheck secured the giant image database after WIRED contacted the company in July, Fowler warns that it was seemingly exposed for months, and his initial efforts to flag the problem to the company were unsuccessful. Accidental data exposures create risk for any personal information, but particularly for sensitive and unchangeable biometric data like face images.

[...] In addition to the face data, ClarityCheck had also misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names; anyone using any consumer browser could have done this. Entering a name into one of the URLs would return multiple potential email addresses, physical addresses, and phone numbers for people with that name. After WIRED contacted the company, the URLs were secured. The ClarityCheck spokesperson said in the statement that the details displayed were "sourced from publicly available information and licensed third-party data providers."
A spokesperson for ClarityCheck said in a statement: "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access." The company disputed any characterization that the data was "exposed," saying that an "ordinary member of the public" would not have come across it.

"We do not accept that data in the temporary storage location was 'publicly exposed,' which implies large-scale public access," the spokesperson says. "Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search."
The Courts

Disney, ABC Sue FCC Over Threats to Broadcast Licenses (reuters.com) 136

Disney and ABC are suing the FCC to block an early review of eight station licenses, arguing the Trump administration is using the agency's regulatory power to punish the network over programming and editorial decisions it dislikes. Reuters reports: In a lawsuit (PDF) filed in U.S. District Court in Washington, Disney said the FCC was seeking to coerce and retaliate against "a network that refuses to bow to the administration's demands," calling the agency's actions an "extraordinary assault on free speech."

Trump has waged an aggressive series of attacks on the news media and the latest move follows a two-year-long battle between Trump and Disney. Last month, Trump again called for ABC stations to lose their licenses because the network refused to air a prime-time speech on elections. The court case will pose a key test of the free speech rights of media outlets. Disney and ABC asked the court (PDF) to quickly issue a temporary restraining order halting the license renewal proceedings and preventing the FCC from scheduling a hearing. The company said the public comment period ended earlier this month and the FCC could act at any time.

The lawsuit alleges that the administration is violating the company's First Amendment free speech rights, saying that the FCC "is using its regulatory power to retaliate against (Disney and ABC) for programming and editorial decisions the administration dislikes." The FCC said the move stemmed from a year-long investigation into whether Disney's diversity policies amounted to unlawful discrimination, an allegation the company denies. U.S. District Judge Loren AliKhan issued an order on Tuesday directing the company and the FCC to propose a schedule for considering the request for a temporary restraining order and told the agency to notify her if it moves to start the process of revoking the ABC licenses.

The Almighty Buck

Memory Prices Climb 500% In 12 Months (tomshardware.com) 110

RAM prices have exploded over the past year, with some DDR5 kits approaching 500% year-over-year increases and a 128GB kit now selling for $3,399, which is more than 10 times its previous low. Tom's Hardware reports: Things improve as you step down the memory capacities and speed tiers, but not as much as we'd like. You're still looking at $392 for a memory kit that was just $72 last year. To reinforce the point, I pulled the latest average price data from PCPartPicker, comparing where we are today (August 2026) to exactly one year ago. This data is somewhat approximate, but it should be broadly accurate. [...] A standard 64GB (2x32GB) DDR5-5600 kit that would have cost you under $200 last summer is now demanding over $1,100. It is a 5x multiplier on a component that used to be a fairly boring and predictable line item in a PC build budget.

If you plan to just wait it out on an older AM4 or LGA1700 motherboard with DDR4, you'd better hope your memory holds out too, because DDR4 isn't safe from the fallout. With DDR5 entirely out of reach for most builders, the resulting scramble for older platforms running DDR4 memory has created a massive knock-on effect, and as a result, DDR4 kits are up anywhere from 120% to nearly 180% across the board. Nowhere near as bad as DDR5 pricing, but it still stings when a kit that was $105 last year is $281 this year.

This phenomenon is by no means exclusive to the US, either. German tech site ComputerBase have also been tracking this global trend, reporting just this week that average RAM prices in Europe have skyrocketed by 345% compared to September 2025. Their data shows the squeeze is bleeding into other components too, with hard drive and SSD prices both climbing over 125% in that same timeframe. In fact, the situation is so severe that hyperscale buyers have reportedly already locked in almost all of the global DRAM production capacity for 2027, handing over advance deposits to guarantee their supply of precious DRAM, which is now among the highest-value commodities in the world by weight; mainstream DRAM chips are worth over half as much per kilogram as solid gold.

Data Storage

Judge Sets Framework For Nine PBS to Retrieve 70 Years of Archival TV Data (current.org) 67

District Court Judge Eric Elliff has ordered Iron Mountain to cooperate with Nine PBS in recovering roughly 50TB of archival material stored through now-defunct vendor OSS. "He found that the station is the rightful owner of the materials and entitled to recover them from OSS' storage systems," reports Current.org. Nine PBS must identify a third party to help retrieve the files, pay outstanding storage fees, and ensure that data belonging to other OSS customers isn't disturbed or accidentally recovered. From the report: Under his order, Nine PBS is to identify a third-party vendor, such as a former OSS employee, who can assist in accessing and retrieving the data from the infrastructure that's housed in Iron Mountain's center within 30 days. Elliff acknowledged the complexities of Iron Mountain's position as a vendor to OSS, which, according to Nine PBS' complaint, is in delinquency. Iron Mountain is the "custodian" of Nine PBS' data, but it isn't the vendor that contracted with the station to store and preserve its data. That obligation remains with OSS. Under the order, Nine PBS will pay Iron Mountain current and past-due fees for data storage, starting from when OSS stopped paying Iron Mountain for use of its data storage facility.

During the hearing, Gregory Rich, an attorney representing Nine PBS, said the station seeks access to a physical cage where the data is housed within Iron Mountain's facility. The station is in contact with a former OSS employee who is willing to help obtain the data. The attorney noted that the data could potentially be stored in physical form, such as tapes that could be easily retrieved. But if the materials are on a server, Nine PBS could lose the materials forever if Iron Mountain shuts it down. William Cravens, the attorney representing Iron Mountain, told the judge his client doesn't know the format of Nine PBS' materials that were stored by OSS. He expressed concern about whether Nine PBS' archival material is lumped together with data from other OSS clients. Iron Mountain wants to avoid potentially corrupting the other data, Cravens added.

Elliff ordered the immediate return of any physical devices that hold Nine PBS' data once access to OSS' storage system is granted. If data retrieval turns out to be more complicated -- if it is encrypted, for example -- he will schedule another hearing to determine how to proceed. Once Nine PBS retrieves its data, the station must work with a third party to ensure that no data from other OSS customers is among those materials.

Windows

It's Not Just RAM: Windows Licenses Are Also Pushing Up PC Prices (cnet.com) 110

It's not just RAM prices that are going up, writes CNET. "Reports suggest the cost of Windows licenses for manufacturers is rising by up to 10%." Several sites that closely follow Microsoft news, including Windows Central and Windows Latest, have published articles citing a report from Taiwan's Economic Daily News that claims some PC manufacturers are seeing a 7% to 10% increase in the cost of Windows 11 licenses...

Because they buy licenses in bulk, they get a sizeable discount over what a consumer would pay for a new copy of Windows 11. But given the existing cost pressures from other components, a big Windows 11 price hike could lead them to pass on some of the added cost to PC buyers. According to the EDN story, PC makers could raise prices by about 5% over the next quarter due to the reported Windows price hike. .. A translated version of the Economic Daily News article contains information from an unnamed PC brand executive. It says that while Microsoft typically raises licensing costs every year by single-digit percentages, that hike has reached 7% to 10% this year, a significant increase.

"A representative for Microsoft declined to comment on the report," according to the article.

But it also notes that three weeks ago laptop maker Framework blamed price hikes and reconfigurations for some of their models on processor, memory, storage, "and other silicon costs — but also "an increase in Windows license costs."

Thanks to Slashdot reader joshuark for sharing the article.
Data Storage

PBS Station Fears Losing 50TB of Data After Being Ghosted By Cloud Provider (arstechnica.com) 101

An anonymous reader quotes a report from Ars Technica: After its cloud storage provider went defunct, a PBS affiliate decided to sue a data center provider to regain access to 50TB of TV shows, videos, and other data dating back 70 years. As reported this week by Current, a trade newspaper covering public broadcasting, St. Louis affiliate Nine PBS filed a lawsuit against Iron Mountain Data Centers on July 28, seeking access to the data. In the litigation filed in Denver District Court, Nine PBS says that its cloud storage provider, Open Source Storage (OSS), used one of Iron Mountain's Denver data centers to store the channel's data. However, OSS is being unresponsive, and Nine PBS says Iron Mountain has refused to release its data.

The data in question includes the station's coverage of the COVID-19 pandemic, East St. Louis' history, The Great Flood of 1993, and over 11,000 files, The Denver Post reported in July. The lawsuit claims that "most" of the data is "unique and irreplaceable," according to the Post. Last month, a judge blocked Iron Mountain from deleting or modifying the data.

In a hearing on Wednesday, a judge ruled that Iron Mountain must hand over any physical devices holding the data, Current reported today. The judge also said that Nine PBS must find a third party, such as a former OSS worker, who can help retrieve the data within 30 days and without sharing or corrupting data belonging to other OSS clients. Nine PBS is already communicating with a former OSS employee "who is willing to help," the report said. If complications arise, such as from the data being encrypted, another hearing will be scheduled. Nine PBS and Iron Mountain must provide updates by September 14.
Iron Mountain's spokesperson said the company only provides physical infrastructure, such as the building, network connectivity, power, and environmental controls. "Our customers rent space for their servers and other hardware. These are the client's assets. We don't have access to the data on the hardware/servers because they belong to our customers," the company said.

If it granted "unauthorized access to third-party hardware without a court order," Iron Mountain said the company would violate basic data privacy protocols, breach its contract with OSS, and "potentially [expose] confidential data belonging to other clients of OSS."
Cellphones

Google Unveils Pixel 11 Lineup (techcrunch.com) 35

At its Made by Google 2026 event today, Google unveiled a slew of new devices, headlined by the Pixel 11, Pixel 11 Pro, and Pixel 11 Pro Fold. Here's a breakdown of the company's latest smartphones, provided by TechCrunch: Pixel 11: The standard Pixel 11 gets a redesigned camera bar that is thinner than the one on the previous generation. Google says the new camera bar is more than 40% thinner and now uses an all-glass surface that stretches across the width of the phone. Google is also increasing the base storage to 256GB, doubling the previous starting capacity. The starting price for the new model is set at $899, reflecting a $100 increase compared to the Pixel 10. This price hike comes with the decision to drop the 128GB storage option. Plus, the ongoing RAM supply shortage plays a part in this increase.

Pixel 11 Pro and Pro XL: Google is making durability a bigger part of the Pro lineup. The company says the Pixel 11 Pro and Pixel 11 Pro XL have improved drop resistance and a new anti-scratch display coating that provides more than twice the scratch resistance of the Pixel 10 Pro models. The Pixel 11 Pro starts at $1,099, compared to $999 for the Pixel 10 Pro.

Pixel 11 Pro Fold: Google says the new foldable is nearly 10% lighter and almost 1mm thinner than the Pixel 10 Pro Fold. It also has slimmer bezels, a 48-megapixel main camera, and 30x Super Zoom. The company is also building on the IP68 water and dust resistance introduced with the Pixel 10 Pro Fold. The Pixel 11 Pro Fold uses a glass-fiber composite back cover designed to better withstand cracking, while a redesigned hinge offers additional protection for the inner display. Google says the changes make the model three times more durable than its predecessor.
There were also several new Gemini-powered features unveiled at the event. Google is expanding "Live Transcribe" to support American Sign Language, using the Pixel Camera to translate signing into text in real time. A new voice-input feature called "Rambler" is designed to understand natural, unstructured speech, including filler words and run-on sentences. Google is also integrating "Circle to Search" more directly into the Pixel Camera for identifying objects, translating text, and asking questions about what users see.
Windows

Microsoft Responds to Outcry After Quietly Installing Beta 'Photos' App on Enterprise Machines (windowslatest.com) 72

Microsoft's cloud storage app OneDrive got a new Photos app in the worst possible way, reports the blog Neowin . "The app is reportedly showing up even on Windows 11 Enterprise machines, despite apparently being a beta application aimed at consumer functionality." One admin questioned why a beta app was appearing on an Enterprise SKU in the first place, while another described the situation as yet another consumer-oriented feature being forced onto corporate PCs. Things get even more frustrating for IT departments because there does not appear to be a straightforward Microsoft-provided way to disable the app... Enterprise administrators generally need to know what is being installed on their managed devices, particularly when a software is labeled as beta. Quietly adding another application and leaving admins to clean it up themselves is therefore unlikely to win Microsoft many fans.
But there's another problem, according to the blog Windows Latest. "OneDrive Photos automatically scans your system storage for photos," and apparently "doesn't need a Microsoft account to work, as it can also detect your local files." There's also a People section that groups similar faces in your photos. Microsoft asks for permission before turning it on and explicitly warns that facial data could be considered biometric data in some regions. The company says only you can see the grouped faces, that the data isn't shared with third parties, and that you can delete it by disabling the feature.
In a statement to Neowin, Microsoft admitted this new photos "experience" they're "incubating" had gone "more broadly than it should have," and then promised that "We're fixing that." The spokesperson also said the Windows Photos app will "always give you the option of local and cloud photos" and, also a choice of whether or not to use it OneDrive."

But there's another "awkward catch," notes the blog Digital Trends. "Users currently can't uninstall OneDrive Photos without removing the main OneDrive app too." Because OneDrive Photos is tied to the main OneDrive sync client, Windows 11 doesn't currently offer a separate uninstall option. The only straightforward way to get rid of OneDrive Photos right now is to uninstall OneDrive itself... Removing the main client can also affect its File Explorer integration and shortcuts...

Microsoft says this will change. The company is working on controls that will let users remove OneDrive Photos separately from the main OneDrive app. On enterprise PCs managed through Intune, Microsoft says the app will automatically disappear where it isn't supported.

Hardware

RAMageddon? 2027 Memory Capacity Reportedly Sold Out (ign.com) 133

IGN reports: [A] new report suggests that all three memory manufacturers — Samsung, SK Hynix, and Micron — have collectively sold through their 2027 memory manufacturing capacity to, you guessed it, AI companies.

According to a report from Digitimes and spotted by TweakTown, all DRAM and HBM capacity has been sold through for 2027, with no further supply planned. (The companies themselves have not yet confirmed this to be the case.) Of course, that only means that retail prices are going to go up even further in the near future. Selling through all the capacity for next year would be bad enough for consumers, but the problem is that most of the companies buying up this capacity have done so through long-term purchasing agreements, essentially pre-ordering memory that hasn't even been manufactured yet over a five-year term. Unless more capacity opens up somewhere in the next few years, it's hard to imagine that RAM will become more affordable and less scarce any time soon.

It's not just memory that's affected. According to that Digitimes report, NAND storage is growing in demand too. Luckily, NAND capacity hasn't been completely absorbed, because there are more companies supplying the stuff. But it's not exactly hard to see that SSDs have been growing steadily more expensive over the last six months or so.

Power

America's First Grid-Scale Sodium-Ion Battery Plant Gets Its First Big Test (intelligentliving.co) 33

"In a milestone for energy storage technology, Peak Energy has selected Sacramento, California, as the home of America's first manufacturing facility dedicated to grid-scale sodium-ion battery systems," according to the sustainability news site Intelligent Living.

The move "represents the first large-scale test of whether sodium-ion technology can deliver on its promise of cheaper, safer, and more sustainable grid storage at a scale that actually moves the needle for the U.S. electricity system." The 183,000-square-foot plant, representing a $71 million investment, will produce up to 4 gigawatt-hours of storage annually when production begins in early 2027. That is enough output each year to serve nearly four million homes, and it signals that sodium-ion technology has moved from laboratory promise to commercial reality... Peak Energy, founded in 2023 by former engineers from Tesla, Enovix, and Fluence, announced its Sacramento site selection on July 8, 2026, after a nationwide search that ultimately chose California over Texas... The factory is designed as a system assembly plant rather than a cell fabrication facility. Peak will receive sodium-ion cells, manufactured to its specifications by Chinese suppliers, and assemble them into complete 30-foot-long, 100,000-pound containerized storage systems. Each GS1.1 unit stores 3.1 megawatt-hours, enough to fully charge more than 40 electric vehicles...

In the United States, Peak Energy has emerged as the most advanced grid-scale player. It has secured more than 6 GWh of customer commitments, including a landmark deal with Jupiter Power for up to 4.75 GWh through 2030, valued at up to $500 million. Energy Vault has committed to 1.5 GWh of sodium-ion storage for AI data center applications, and RWE Americas has already deployed Peak's first grid-scale system on the MISO grid in Wisconsin, energized in March 2026. General Motors is codeveloping sodium-ion cells with Peak at its Wallace Battery Cell Innovation Center in Michigan, testing 170- and 190-amp-hour cell formats with domestic production targeted for 2028. China, however, remains the global heavyweight. CATL, the world's largest battery manufacturer, unveiled its TENER Sodium energy storage system in June 2026 with a rated cycle life of 15,000 cycles and a projected 25-to-30-year service life. In April 2026, CATL signed a 60 GWh supply agreement with HyperStrong, the largest sodium-ion deal announced to date. BYD, HiNa Battery, and Farasis are also shipping commercial sodium-ion products, including batteries for a $400 electric scooter already on sale in China...

Peak Energy's first commercial shipments from Sacramento are slated for the first quarter of 2027, with contracted deliveries to Jupiter Power, Energy Vault, and RWE Americas following shortly after. The company has publicly stated it needs to deploy over $100 million in product in 2026, up from roughly $10 million in 2025, and the Sacramento facility is sized to meet that demand. At the system level, sodium-ion grid storage is already operating. Peak's pilot installation at the SolarTAC testing facility in Watkins, Colorado, stores 3.5 MWh and has been running since 2025. The RWE Americas deployment in Wisconsin, energized in March 2026, marks the first time sodium-ion batteries have backed up the MISO grid, which serves 15 central U.S. states and the Canadian province of Manitoba...

According to the International Energy Agency, sodium-ion manufacturing capacity announcements have accelerated sharply since 2024, with global pipelines now exceeding 400 GWh annually... Researchers are also pushing the technology forward. In May 2026, a team at the National University of Singapore published a breakthrough in all-solid-state sodium batteries that could further reduce costs and eliminate the flammable liquid electrolytes found in both lithium-ion and current sodium-ion designs.

"The technology's sweet spot is utility-scale, multi-megawatt-hour installations," the article points out, "where the system-level cost savings from passive cooling and longer cycle life outweigh the per-cell energy density penalty..." The article also points out observations from the American Battery Leadership Coalition, an industry group advocating for sodium-ion policy support, that sodium-ion batteries can be built almost entirely from American materials, including coal, sawdust, and agricultural waste.

This week Syntropic Power and UNIGRID Inc. also announced "a major partnership to commercialize UNIGRID's proprietary sodium chromium oxide (NaCrO2) battery technology across North America," reports Interesting Engineering, "targeting one gigawatt-hour (1 GWh) of deployments in 2027. The technology could be used in residential, virtual power plant, and large-scale stationary grid applications..." Independent testing by the ISO-accredited Rochester Institute of Technology (RIT) Battery Development Center revealed something surprising. UNIGRID's 210Ah cells displayed endothermic behavior during charging. This means the chemical reaction actually absorbs heat rather than dumping it into the environment. Coupled with a 97.9% cell-level round-trip energy efficiency and remarkable thermal stability under abuse testing, the battery stays cool on its own.

The 210Ah sodium-ion cells deliver up to 218Ah of discharge capacity. It demonstrated exceptional durability, retaining over 99% of its capacity after 1,000 full discharge cycles, as well as heat-absorbing behavior during charging. These validated strengths allow Syntropic to optimize its product designs, enabling platforms like GridSpan [its modular DC platform designed for large-scale energy applications with flexible discharge durations ranging from 20 minutes to 20 hours] to operate safely and efficiently at grid scale without needing complex mechanical cooling systems...

Commercialization kicks off with Tenet, a safety-focused, wall-mounted system for residential, light-commercial, and virtual power plant uses... Relying on abundant and widely distributed raw materials like sodium and chromium — rather than lithium and cobalt — protects manufacturers from geopolitical price spikes and material shortages. Apart from offering an alternative to lithium, a successful rollout will demonstrate that the most durable energy storage is the kind that could stay cool entirely on its own.

Thanks to Slashdot reader fjo3 for sharing the news.
Privacy

'Tower Dump' Warrants Ruled Unconstitutional (thehill.com) 63

alternative_right shares a report from The Hill: A federal judge in Mississippi ruled Wednesday that "tower dump" warrants are unconstitutional, declining to reverse a lower court decision refusing the government's request to obtain the search warrants in a series of violent crime investigations. A "tower dump" involves cellphone companies providing law enforcement with access to the time and location data of all mobile devices connected to specific cell towers during a designated time window.

Law enforcement had sought approval for several of these search warrants as part of criminal investigations into gang-related activity in the Jackson, Miss., area last year, arguing the data could help identify all those potentially involved, particularly in incidents with unknown suspects. A magistrate judge denied the applications, holding that "tower dumps" are impermissible general warrants. The district judge agreed.
The order repeatedly referenced the Supreme Court's recent decision in Chatrie v United States, in which the majority held that geofence warrants require constitutional privacy protections.

"With this information, the Government asserts that it will be able to identify all potential suspects," Judge Carlton Reeves wrote in a 30-page order (PDF). "Even so, law enforcement would also have access to the cellular records of countless individuals, the vast majority of whom were merely passing by a location at the 'wrong' time."

"That is an unreasonable search under the Fourth Amendment," the judge concluded.
Data Storage

NVMe Polishes Its Specs, Brings Virtualization to Locally Attached SSDs (theregister.com) 22

The latest NVMe specifications add SSD-level virtualization that can simplify live VM migration by preserving storage identities across servers. The updates also introduce support for post-quantum cryptography, controller-based rate limiting, voltage monitoring, and factory-reset capabilities. The Register reports: Announced by the NVM Express consortium, all 11 of the suite of NVMe specs have been updated with new features and engineering change notices. These represent the next step in the evolution of the standard, it says, which was created as a protocol to support storage devices connected to a system's PCIe bus. Perhaps the most significant new capability is PCIe Exported NVM Subsystem Migration. This extends existing NVMe virtualization to locally-attached PCIe SSDs. It does this by abstracting the physical drives into host-defined virtualized NVM subsystems, to allow for virtual machine (VM) mobility without storage reconfiguration.

When a VM moves from one server to another, its storage also needs to move with it in a way that's non-disruptive to any applications running in that VM. "With NVM Subsystem Migration, NVMe SSDs can present exported NVM subsystems that hide the complexity of the underlying hardware," says Mike Allison, a senior director at SSD maker Samsung and NVM Express board member. "Instead of interacting with physical controllers and namespaces, the host only sees exported controllers and namespaces. This creates a clean separation between what the VM sees and what's happening under the hood," Allison explains on an NVM Express blog.

"One of the key innovations here is providing the host with control over exported identifiers. During migration, those identifiers can be carried over exactly from the source to the destination. That consistency is crucial: even if the underlying hardware uses different internal IDs, the VM sees no change and can pick up right where it left off with no storage reconfiguration required," he says. In effect, the NVMe layer now enables the virtual machine manager (VMM) to rely on virtualization built into the SSD. The flash drive itself exposes logical, virtualized storage constructs, offloading this complexity from the VMM.
You can learn more about the updated NVMe specifications here.
Encryption

Apple Launches Legal Challenge Against UK Demand To Access Encrypted User Data (theguardian.com) 28

An anonymous reader quotes a report from The Guardian: Apple has launched a new legal challenge against a UK government demand to access its customers' highly encrypted data, a year after the Home Office agreed to abandon its previous request. The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully. The UK government had made a second request to Apple to grant it a "back door" to encrypted iCloud data belonging to British users, according to an order issued by the court.

Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington. UK authorities subsequently issued a new "technical capability notice" (TCN) to Apple that did not apply to American users. Apple is seeking to challenge the British government's powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times. [...] The original TCN issued last year asked Apple for the right to see users' encrypted data protected by its advanced data protection (ADP) program in the event of a national security risk.

Apple said the removal of the tool -- which not even it can access -- would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a "back door" would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant. As a result, Apple withdrew UK customers' access to its ADP program in January 2025. The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.

Data Storage

Sandisk and SK Hynix Publish First Open High Bandwidth Flash Standard (nerds.xyz) 19

BrianFagioli writes: Sandisk and SK hynix have published the first open technical specification for High Bandwidth Flash (HBF) through the Open Compute Project. HBF is designed to create a new memory tier between High Bandwidth Memory and traditional SSD storage, giving AI inference systems more near compute capacity without relying entirely on expensive HBM. The specification supports capacities up to 512GB using 8-high and 16-high NAND stacks, with bandwidth tiers ranging from about 0.4TB per second to 3.0TB per second. It also uses the UCIe chiplet interface, which could make HBF easier to integrate with CPUs, GPUs, and other accelerators. Google and Tenstorrent participated in the standardization effort, but commercial products and independent benchmarks are still missing.
Apple

Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents (macrumors.com) 82

Apple's practice of mixing employees' work files with personal iCloud accounts reportedly left some former staff with continued access to confidential documents, messages, and even new updates after leaving the company. "The former employees said many Apple files they had been shared on over their careers at the company -- including planning documents for product launch events -- continued to sync to their personal devices through the iCloud storage service after they left Apple," reports The Information. "In some cases, they even received notifications about fresh updates to the documents. Some former employees said they were petrified to delete the files for fear that doing so would attract Apple's attention." MacRumors reports: Apple files get mixed in with employees' accounts because the company encourages them to use their personal Apple Accounts with their work iCloud account. Employees are given a 2TB iCloud plan and are able to merge the storage with their existing Apple Account or create a new account. Since only one primary account can be signed in at a time, most opt to use their existing account to avoid having to carry two iPhones. Apple has a managed folder for workplace files that it revokes access to when an employee leaves, but some internal documents aren't saved there automatically and shared files end up mixed in with personal content. Employees can also retain access to iMessage chats and files shared via the Messages app.

Lingering access to Apple systems is central to Apple's lawsuit against OpenAI. In its filing, Apple alleged that former employee Chang Liu breached Apple's systems using a "rare, previously unknown authentication bug" to download files while he was working at OpenAI. Apple told The Information that the OpenAI lawsuit is unrelated to any files left available on iCloud and that it does not pursue legal claims against former employees who accidentally have Apple documents in their personal iCloud accounts. "This case is about OpenAI employees wrongfully taking Apple's secret and confidential information regarding our unreleased technologies, processes, and products. Nothing in the filing relates to documents shared by, or stored in, iCloud."

Power

NextEra, Brookfield to Build $100 Billion Kentucky Data Campus (bloomberg.com) 27

NextEra and Brookfield plan to invest more than $100 billion to transform a former uranium-enrichment site in Kentucky into a data center campus with a generating plant. "The privately funded effort will include construction of 2 gigawatts of natural gas-fired power at or near the site in Paducah in western Kentucky, and as much as 2.6 gigawatts of battery storage capacity," reports Bloomberg. " For context, a single gigawatt of capacity is roughly the output of a traditional nuclear power plant and can power about 750,000 homes at any given moment." From the report: Brookfield will develop and operate the 1.8 GW data center campus, which will occupy portions of the sprawling 3,556-acre Energy Department site once used to produce weapons-grade uranium and fuel for nuclear reactors. Operations using the now obsolete enrichment technology known as gaseous diffusion stopped in 2013 and the site is now subject to cleanup efforts. Construction is expected to be completed in 2031, the Energy Department said. "The U.S. government is leveraging its assets -- like our federal lands -- to add power generation, create jobs, and ensure the United States wins the AI race," Energy Secretary Chris Wright said in a statement. The project is expected to create 8,000 construction jobs and 600 permanent positions, the department said.
AI

OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face (wired.com) 67

An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that "four accounts" tied to "publicly available services" were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.

OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack.

Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.

Encryption

Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms (nytimes.com) 32

Anthropic's Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet," reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report: The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic's technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet.

[...] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct.
"Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?" said Glenn S. Gerstell, the former general counsel at the National Security Agency.

"Mathematicians would tell you that it shouldn't be possible given current computing powers to break strong encryption in any meaningful time," added Mr. Gerstell, who helped write a report on cryptology in 2022. "But I don't think the capabilities of future models in the medium term -- before quantum computing or quantum-proof cryptography -- should be dismissed as trivial in this context."

Slashdot Top Deals