Open Source

Linux Foundation Announces an Open Map Project and 'Open Metaverse Foundation' (linuxfoundation.org) 32

The Linux Foundation "sponsors the work of Linux creator Linus Torvalds and lead maintainer Greg Kroah-Hartman," according to its page on Wikipedia. And now the Linux Foundation "is pleased to announce the launch of the Overture Maps Foundation," according to their December newsletter.

It's a collaborative effort "to enable current and next-generation map products by creating reliable, easy-to-use, and interoperable open map data as a shared asset that can strengthen mapping services worldwide." The initiative was founded by Amazon Web Services (AWS), Meta, Microsoft, and TomTom and is open to all communities with a common interest in building open map data. To get involved, please visit overturemaps.org.
And they're also announcing plans to form the Open Metaverse Foundation: In October, we brought top experts from diverse sectors together with leaders from many of the projects across the Linux Foundation to discuss what it will take to transform the emerging concept of the Metaverse from promise to reality.... As the next step in this amazing journey, we welcome the Open Metaverse Foundation (OMF) into the Linux Foundation as another piece of the puzzle. With your help, we can realize the promise of the open Metaverse. Learn more about what's next, join us, and get involved at openmv.org.
The Foundation has also published three new research papers:

The newsletter also points out that through Tuesday the foundation is offering 35% off any of their training courses, certifications, bundles or bootcamps.


United States

Senator Wyden Urges FTC Probe of Neustar Over Possible Selling of User Data to Government (msn.com) 25

Until 2020 Neustar was the domain name registry "for a number of top-level domains," according to its page on Wikipedia, "including .biz, .us (on behalf of United States Department of Commerce), .co, .nyc (on behalf of the city of New York), and .in.

But now U.S. Senator Ron Wyden has asked America's Federal Trade Commission to investigate whether Neustar violated the privacy rights of millions, reports the Washington Post, "when it sold records of where they went online to the federal government."

America's Department of Defense funded a research team at Georgia Tech who purchased Neustar's data starting in 2016, notes a letter from Senator Wyden. Wyden has obtained emails between those researchers and "both the FBI and the Department of Justice, indicating that government officials asked the researchers to run specific queries and that the researchers wrote affidavits and reports for the government describing their findings."

But in addition, Wyden now cites a Department of Justice statement (entered an unrelated court case) which he says makes a concerning assertion: that Neustar executive Rodney Joffe, "who led the company's efforts to sell data to Georgia Tech, was also involved in the sale of DNS data directly to the U.S. government. The court documents say: Rodney Joffe and certain companies with which he was affiliated, including officers and employees of those companies, have provided assistance to and received payment from multiple agencies of the United States government. This has included assistance to the United States intelligence community and law enforcement agencies on cyber security matters. Certain of those companies have maintained contracts with the United States government resulting in payment by the United States of tens of millions of dollars for the provision of, among other things, Domain Name System ('DNS') data. These contracts included classified contracts that required company personnel to maintain security clearances.
From The Washington Post: The stipulation naming entrepreneur Rodney Joffe was the clearest confirmation to date of web histories being sold directly to federal law enforcement and intelligence agencies, instead of through information brokers exempt from restrictions on what telephone companies and websites can share with the government.
Wyden adds: The data that Neustar sold to Georgia Tech may have also included data collected from consumers who were explicitly promised that their data would not be sold to third parties. Between 2018 and 2020, Neustar acquired a competing recursive DNS service, which had previously been operated by Verisign. That service had been advertised to the public by Verisign with unqualified promises that "your public DNS data will not be sold to third parties."

When the product changed hands, users of Verisign's service were seamlessly transitioned to DNS servers that Neustar controlled. This meant that Neustar now received information about the websites accessed by these former Verisign-users, even though neither Verisign nor Neustar provided those users with meaningful, effective notice that the change of ownership had taken place, or that Neustar did not intend to honor the privacy promises that Verisign had previously made to those users. It is unclear if the data Neustar sold to Georgia Tech included data from users who had been promised by Verisign that their data would not be sold.

This is because both Neustar and Verisign have refused to answer questions from my office necessary to determine this important detail.

Social Networks

Why Raspberry Pi's New Hire Caused a Social Media Firestorm (buzzfeednews.com) 206

An anonymous reader quotes a report from BuzzFeed News: Joe Bowser is a computer scientist based in Port Moody, British Columbia, who has long loved Raspberry Pis. He uses the low-cost, single-board computers, which were launched in February 2012 by a UK-based company of the same name, for many of his tech projects. Those include linking the Raspberry Pi up to a 3D printer, and using the Pi to run a machine-learning demo. There's one use case that Bowser described as "the most important": using a Raspberry Pi to identify the use of IMSI catchers -- telephone eavesdropping devices that snoop on phone calls and text messages -- by law enforcement. Protesters opposing new oil pipelines happen to pass by Bowser's house regularly. He thinks cops shouldn't spy on them. So he's trying to help out the protesters using his tech knowledge. To do that, he uses Raspberry Pis. Or more accurately, he did. Bowser has forsworn using the computers ever again. He and many others are expressing their displeasure with the company on social media.

The controversy began yesterday when Raspberry Pi posted an announcement on Twitter and Mastodon: "We hired a policeman and it's going really great." The company linked to a laudatory blog post on its website announcing it had hired an ex-police officer, Toby Roberts, as its maker-in-residence. "I was a Technical Surveillance Officer for 15 years, so I built stuff to hide video, audio, and other covert gear," Roberts is quoted as saying in the post. "You really don't want your sensitive police equipment discovered, so I'd disguise it as something else, like a piece of street furniture or a household item. The variety of tools and equipment I used then really shaped what I do today." A subsection of the Raspberry Pi community expressed concern about the blase way the company presented intrusive covert surveillance. (The news caused particular ire on Mastodon, leading some to describe Roberts as the burgeoning social media platform's first "main character.") [...]

Liz Upton, Raspberry Pi's cofounder and chief marketing officer, told BuzzFeed she believes that much of the issue stems not from the hiring of the former police officer who admitted to using Raspberry Pis for covert surveillance, but instead from a picture the account posted to Mastodon a day earlier showing pigs in blankets. "We didn't put a content warning on it, because we don't put a content warning on meat," Upton said. "There were quite a few people who tried to start dogpiling on that." She also claimed that part of the vitriolic response could be because Raspberry Pi is struggling with supply chain difficulties at present, and people "were already cross." "I think what we're looking at is a dogpile that's being organized somewhere," Upton said. "There's obviously a Discord or a forum somewhere." She did not provide evidence to support that claim. "I don't think this is organic, but it's very unpleasant, and extraordinarily unpleasant for the people involved," she said. Upton claimed both Roberts and Raspberry Pi's social media manager have been doxxed and received death threats.
"I am disgusted that [Raspberry Pi's] official post on Toby Roberts' hiring promotes his use of their products to surveil individuals without their consent," Matt Lewis, a Denver-based site reliability engineer, wrote via Twitter DM. "In my eyes, this behavior is completely unethical and the work Toby has done for 15 years is indefensible. I'm also upset that they have chosen to double down on this position against the community outrage."

"I think this event will mark a turning point in the organization's reputation," added Wikipedia consultant Pete Forsyth in a Twitter DM. "It's hard to see how they can recover the trust they seem to have almost willfully dismantled today."

Not everyone is downbeat about the future of the company. University of Surrey cybersecurity professor Alan Woodward called Roberts an "interesting hire" for Raspberry Pi. "His previous uses of the Pi shows just what a versatile device it is: I'm sure he's not the only one using the smallest variants to make covert devices," Woodward said. "You find that you have to be very creative to build these types of covert devices, so hopefully he can now bring that to his new role, for a wider variety of applications."

"It's not as if he is going to corrupt any of the Pis -- like all technology, it has some uses some people will object to," he said. Rather, Woodward believes "the loudest objectors are taking it a bit far. Maybe they could look at it as a glass-half-full situation: Think of the unusual innovations he might bring."
Television

Meet DTV's Successor: NextGen TV (cnet.com) 135

Around 2009 Slashdot was abuzz about how over-the-air broadcasting in North America was switching to a new standard called DTV. (Fun fact: North America and South America have two entirely different broadcast TV standards — both of which are different from the DVB-T standard used in Europe/Africa/Australia.) But 2022 ends with us already talking about DTV's successor in North America: the new broadcast standard NextGen TV.

This time the new standard isn't mandatory for TV stations, CNET points out — and it won't affect cable, satellite or streaming TV. But now even if you're not paying for a streaming TV service, another article points out, in most major American cities "an inexpensive antenna is all you'll need to get get ABC, CBS, Fox, NBC and PBS stations" — and often with a better picture quality: NextGen TV, formerly known as ATSC 3.0, is continuing to roll out across the U.S. It's already widely available, with stations throughout the country broadcasting in the new standard. There are many new TVs with compatible tuners plus several stand-alone tuners to add NextGen to just about any TV. As the name suggests, NextGen TV is the next generation of over-the-air broadcasts, replacing or supplementing the free HD broadcasts we've had for over two decades. NextGen not only improves on HDTV, but adds the potential for new features like free over-the-air 4K and HDR, though those aren't yet widely available.

Even so, the image quality with NextGen is likely better than what you're used to from streaming or even cable/satellite. If you already have an antenna and watch HD broadcasts, the reception you get with NextGen might be better, too.... Because of how it works, you'll likely get better reception if you're far from the TV tower.

The short version is: NextGen is free over-the-air television with potentially more channels and better image quality than older over-the-air broadcasts.

U.S. broadcast companies have also created a site at WatchNextGenTV.com showing options for purchasing a compatible new TV. That site also features a video touting NextGen TV's "brilliant colors and a sharper picture with a wider range of contrast" and its Dolby audio system (with "immersive, movie theatre-quality sound" with enhancements for voice and dialogue "so you get all of the story.") And in the video there's also examples of upcoming interactive features like on-screen quizzes, voting, and shopping, as well as the ability to select multiple camera angles or different audio tracks.

"One potential downside? ATSC 3.0 will also let broadcasters track your viewing habits," CNet reported earlier this year, calling the data "information that can be used for targeted advertising, just like companies such as Facebook and Google use today...

"Ads specific to your viewing habits, income level and even ethnicity (presumed by your neighborhood, for example) could get slotted in by your local station.... but here's the thing: If your TV is connected to the internet, it's already tracking you. Pretty much every app, streaming service, smart TV and cable or satellite box all track your usage to a greater or lesser extent."

But on the plus side... NextGen TV is IP-based, so in practice it can be moved around your home just like any internet content can right now. For example, you connect an antenna to a tuner box inside your home, but that box is not connected to your TV at all. Instead, it's connected to your router. This means anything with access to your network can have access to over-the-air TV, be it your TV, your phone, your tablet or even a streaming device like Apple TV....

This also means it's possible we'll see mobile devices with built-in tuners, so you can watch live TV while you're out and about, like you can with Netflix and YouTube now. How willing phone companies will be to put tuners in their phones remains to be seen, however. You don't see a lot of phones that can get radio broadcasts now, even though such a thing is easy to implement.

But whatever you think — it's already here. By August NextGen TV was already reaching half of America's population, according to a press release from a U.S. broadcaster's coalition. That press release also bragged that 40% of consumers had actually heard of NextGen TV — "up 25% from last year among those in markets where it is available."
Programming

Over 50 Programmers Generate 50,000-Word Novels For 9th Annual 'Nanogenmo' Event (github.com) 12

Long-time Slashdot reader destinyland writes: Since 1999 fiction writers have tried starting and finishing the composition of 50,000-word novels in November for "National Novel Writing Month". But for the last nine years, programmers have instead tried generating 50,000 word novels — and this year's edition received more than 50 entries.

"The only rule is that you share at least one novel and also your source code at the end," explains the event's official page on GitHub.

From the repository's README file: The "novel" is defined however you want. It could be 50,000 repetitions of the word "meow" (and yes it's been done!). It could literally grab a random novel from Project Gutenberg. It doesn't matter, as long as it's 50k+ words.

Please try to respect copyright. We're not going to police it, as ultimately it's on your head if you want to just copy/paste a Stephen King novel or whatever, but the most useful/interesting implementations are going to be ones that don't engender lawsuits.

This year's computer-generated novels include " sunday in the sunday in the," mapping the colors from each dot in the Pointillist painting Sunday Afternoon on the Island of La Grande Jatte onto words from the lyrics of a musical about that painting. ("Rush blind. Link adds shallot again....")
AI

OpenAI's New Chatbot Can Explain Code and Write Sitcom Scripts But Is Still Easily Tricked 38

OpenAI has released a prototype general purpose chatbot that demonstrates a fascinating array of new capabilities but also shows off weaknesses familiar to the fast-moving field of text-generation AI. And you can test out the model for yourself right here. The Verge reports: ChatGPT is adapted from OpenAI's GPT-3.5 model but trained to provide more conversational answers. While GPT-3 in its original form simply predicts what text follows any given string of words, ChatGPT tries to engage with users' queries in a more human-like fashion. As you can see in the examples below, the results are often strikingly fluid, and ChatGPT is capable of engaging with a huge range of topics, demonstrating big improvements to chatbots seen even a few years ago. But the software also fails in a manner similar to other AI chatbots, with the bot often confidently presenting false or invented information as fact. As some AI researchers explain it, this is because such chatbots are essentially "stochastic parrots" -- that is, their knowledge is derived only from statistical regularities in their training data, rather than any human-like understanding of the world as a complex and abstract system. [...]

Enough preamble, though: what can this thing actually do? Well, plenty of people have been testing it out with coding questions and claiming its answers are perfect. ChatGPT can also apparently write some pretty uneven TV scripts, even combining actors from different sitcoms. It can explain various scientific concepts. And it can write basic academic essays. And the bot can combine its fields of knowledge in all sorts of interesting ways. So, for example, you can ask it to debug a string of code ... like a pirate, for which its response starts: "Arr, ye scurvy landlubber! Ye be makin' a grave mistake with that loop condition ye be usin'!" Or get it to explain bubble sort algorithms like a wise guy gangster. ChatGPT also has a fantastic ability to answer basic trivia questions, though examples of this are so boring I won't paste any in here. And someone else saying the code ChatGPT provides in the very answer above is garbage.

I'm not a programmer myself, so I won't make a judgment on this specific case, but there are plenty of examples of ChatGPT confidently asserting obviously false information. Here's computational biology professor Carl Bergstrom asking the bot to write a Wikipedia entry about his life, for example, which ChatGPT does with aplomb -- while including several entirely false biographical details. Another interesting set of flaws comes when users try to get the bot to ignore its safety training. If you ask ChatGPT about certain dangerous subjects, like how to plan the perfect murder or make napalm at home, the system will explain why it can't tell you the answer. (For example, "I'm sorry, but it is not safe or appropriate to make napalm, which is a highly flammable and dangerous substance.") But, you can get the bot to produce this sort of dangerous information with certain tricks, like pretending it's a character in a film or that it's writing a script on how AI models shouldn't respond to these sorts of questions.
Books

Cheeky New Book Identifies 26 Lines of Code That Changed the World (thenewstack.io) 48

Long-time Slashdot reader destinyland writes: A new book identifies "26 Lines of Code That Changed the World." But its cheeky title also incorporates a comment from Unix's source code — "You are Not Expected to Understand This". From a new interview with the book's editor:

With chapter titles like "Wear this code, go to jail" and "the code that launched a million cat videos," each chapter offers appreciations for programmers, gathering up stories about not just their famous lives but their sometimes infamous works. (In Chapter 10 — "The Accidental Felon" — journalist Katie Hafner reveals whatever happened to that Harvard undergraduate who went on to inadvertently create one of the first malware programs in 1988...) The book quickly jumps from milestones like the Jacquard Loom and the invention of COBOL to bitcoin and our thought-provoking present, acknowledging both the code that guided the Apollo 11 moon landing and the code behind the 1962 videogame Spacewar. The Smithsonian Institution's director for their Center for the Study of Invention and Innovation writes in Chapter 4 that the game "symbolized a shift from computing being in the hands of priest-like technicians operating massive computers to enthusiasts programming and hacking, sometimes for the sheer joy of it."

I contributed chapter 9, about a 1975 comment in some Unix code that became "an accidental icon" commemorating a "momentary glow of humanity in a world of unforgiving logic." This chapter provided the book with its title. (And I'm also responsible for the book's index entry for "Linux, expletives in source code of".) In a preface, the book's editor describes the book's 29 different authors as "technologists, historians, journalists, academics, and sometimes the coders themselves," explaining "how code works — or how, sometimes, it doesn't work — owing in no small way to the people behind it."

"I've been really interested over the past several years to watch the power of the tech activists and tech labor movements," the editor says in this interview. "I think they've shown really immense power to effect change, and power to say, 'I'm not going to work on something that doesn't align with what I want for the future.' That's really something to admire.

"But of course, people are up against really big forces...."

Piracy

Police Tracked Traffic of All National ISPs To Catch Pirate IPTV Users (torrentfreak.com) 68

An anonymous reader quotes a report from TorrentFreak: In May 2022, Italian police claimed that thousands of people had unwittingly subscribed to a pirate IPTV service being monitored by the authorities. When users tried to access illegal streams, a warning message claimed that they had already been tracked. With fines now being received through the mail, police are making some extraordinary claims about how this was made possible. [...] Today's general consensus is that hitting site operators is much more effective but whenever the opportunity appears, undermining user confidence should be part of the strategy. Italian police have been following the same model by shutting down pirate IPTV services (1,2,3) and warning users they're up next.

Letters recently sent to homes in Italy reveal that police were not bluffing. A copy letter obtained by Iilsole24ore identifies the send as the Nucleo Speciale Tutela Privacy e Frodi Tecnologiche, a Guardia di Finanza unit specializing in IT-related crime. It refers to an anti-IPTV police operation in May. The operation targeted around 500 pirate IPTV resources including websites and Telegram channels. At the time, police also reported that 310+ pieces of IPTV infrastructure, including primary and balancing servers distributing illegal streams, were taken offline. Police also claimed that a tracking system made it possible to identify the users of the pirate streams. The letter suggests extraordinary and potentially unprecedented tactics.

The letters state that Italian authorities were able to track the IPTV users by "arranging for the redirection of all Internet service providers' national connections" so that subscribers placed their orders on a police-controlled server configured to record their activity. In comments to Iilsole24ore, Gian Luca Berruti, head of investigations at the Guardia di Finanza, describes the operation as "decisive" in the fight against cybercrime. Currently deployed to Italy's National Cybersecurity Agency, Berruti references "innovative investigative techniques" supported by "new technological tools." Technical details are not being made public, but it's claimed that IPTV users were tracked by "tracing of all connections to pirate sites (IPs) combined, in real-time," and "cross-referencing telematic information with that derived from the payment mechanisms used." The police operation in May was codenamed Operazione:Dottor Pezzotto. A Telegram channel with exactly the same branding suffered a traffic collapse at exactly the same time.
"The letters refer to an administrative copyright infringement fine of just 154 euros or 'in case of recidivism' a total of 1,032 euros," notes the report. "However, if people pay their fines within 60 days, the amounts are reduced to 51 euros and 344 euros respectively."

"Around 1,600 people are believed to have been targeted in this first wave of letters but according to Andrea Duillo, CEO of Sky Italia, this is just the start."
News

Fred Brooks Has Died 56

Frederick Brooks, the famed computer architect who discovered the software tar pit and designed OS/360, died Thursday. He also debunked the concept of the Mythical Man-Month in his book, writing: "Adding manpower to software project that is behind schedule delays it even longer."

A true icon, who won the Turing Award in 2000, Brooks was one of the great thinkers in computing. Industry tributes are pouring in the celebration of his contribution and life.

Further reading: His interview with Grady Booch for Computer History Museum [PDF].
Transportation

Report Blames Faulty System, Pilot Error for Boeing 737-500 Crash in 2021 (seattletimes.com) 86

346 people died in two separate crashes of the Boeing 737 MAX — one in 2018 and one in 2019. And then in 2021, a Boeing 737-500 crashed in Indonesia, killing all 62 people on board.

Thursday Indonesia's national transportation safety committee (KNKT) released its final report on that 737-500 crash. It found that after takeoff the plane's autothrottle system (which automatically adjusts power to the jet's two engines) became stuck on the right engine, "as a result of friction or binding within the mechanical system," according to the Seattle Times. The newspaper also notes that the same system "had repeatedly malfunctioned on the aircraft before the crash."

The report also blames an inadequate response from the pilots. As the jet climbed away from the runway in Jakarta and the pilots adjusted the autopilot mode to reduce thrust, the autothrottle duly eased back power to the left engine but the right engine continued at full power. The resultant asymmetric thrust caused the plane to turn to the left even as the pilots steered the control wheel to the right and the autopilot followed by moving control surfaces on the wing to roll right. Another system on the plane designed to monitor for asymmetric thrust also malfunctioned and delayed disengaging the autothrottle as it should have.

But as this was happening, the pilots were unaware of it. The pilots should have seen from the instrument panel attitude display that the plane was deviating from its flight path to the left. And they should have noted the right thrust lever not having moved backward like the left lever, alerting them to the asymmetric thrust. They apparently missed both clues.

Just under 5 minutes after takeoff, as the jet banked steeply left, a warning alert sounded in the cockpit: "BANK ANGLE." Two seconds after the alert sounded, at an altitude of 10,700 feet, the pilot in command disengaged the autopilot system to take manual control. This pilot, 54 years old with almost 18,000 hours of flight time, half of that in a 737, clearly didn't realize that the autopilot had been compensating and masking the effect of the asymmetric thrust in the engines. With the autopilot gone, the countering forces from the control surfaces on the wings were removed and "the yaw and roll forces of the asymmetric power rolled the aircraft to the left," the investigation report states.

The pilot was so unaware of what was happening that he steered the control wheel further left instead of right, which "increased the roll tendency of the aircraft to the left." The plane rolled more than 45 degrees left and went nose down.

At that moment, the autothrottle finally disengaged. But it was too late to recover. The flight data stopped recording as the plane crashed into the sea.

The report faults the pilots for their lack of recognition of the situation.

It blames "pilot automation complacency" (overreliance on the automated system) and "confirmation bias" (believing that the plane was steering right as commanded, when in fact it was rolling left).

The Indonesian safety authority found that Sriwijaya Air provided "inadequate" training for its pilots in upset recovery, which means righting an airplane if it inadvertently stalls, rolls or pitches to deviate from the intended flight position. Indonesia now mandates detailed upset recovery training for all airline pilots.

The KNKT report also states that the system that was supposed to monitor the 737's autothrottle for asymmetric thrust and disengage it — the Cruise Thrust Split Monitor — may have been misrigged by maintenance personnel, or its failure may have been due to a sensor fault providing an incorrect value for the positions of the control surfaces on the wings to the autothrottle computer.

The report notes that Boeing is issuing a bulletin to all 737 operators requiring repetitive inspections of the control surface sensors. An Airworthiness Directive that will make this mandatory is pending from the Federal Aviation Administration.

Encryption

Introducing Shufflecake: Plausible Deniability For Multiple Hidden Filesystems on Linux (kudelskisecurity.com) 90

Thursday the Kudelski Group's cybersecurity division released "a tool for Linux that allows creation of multiple hidden volumes on a storage device in such a way that it is very difficult, even under forensic inspection, to prove the existence of such volumes."

"Each volume is encrypted with a different secret key, scrambled across the empty space of an underlying existing storage medium, and indistinguishable from random noise when not decrypted." Even if the presence of the Shufflecake software itself cannot be hidden — and hence the presence of secret volumes is suspected — the number of volumes is also hidden. This allows a user to create a hierarchy of plausible deniability, where "most hidden" secret volumes are buried under "less hidden" decoy volumes, whose passwords can be surrendered under pressure. In other words, a user can plausibly "lie" to a coercive adversary about the existence of hidden data, by providing a password that unlocks "decoy" data.

Every volume can be managed independently as a virtual block device, i.e. partitioned, formatted with any filesystem of choice, and mounted and dismounted like a normal disc. The whole system is very fast, with only a minor slowdown in I/O throughput compared to a bare LUKS-encrypted disk, and with negligible waste of memory and disc space.

You can consider Shufflecake a "spiritual successor" of tools such as Truecrypt and Veracrypt, but vastly improved. First of all, it works natively on Linux, it supports any filesystem of choice, and can manage up to 15 nested volumes per device, so to make deniability of the existence of these partitions really plausible.

"The reason why this is important versus "simple" disc encryption is best illustrated in the famous XKCD comic 538," quips Slashdot reader Gaglia (in the original submission. But the big announcement from Kudelski Security Research calls it "a tool aimed at helping people whose freedom of expression is threatened by repressive authorities or dangerous criminal organizations, in particular: whistleblowers, investigative journalists, and activists for human rights in oppressive regimes.

"Shufflecake is FLOSS (Free/Libre, Open Source Software). Source code in C is available and released under the GNU General Public License v3.0 or superior.... The current release is still a non-production-ready prototype, so we advise against using it for really sensitive operations. However, we believe that future work will sensibly improve both security and performance, hopefully offering a really useful tool to people who live in constant danger of being interrogated with coercive methods to reveal sensitive information.
Music

Swedish Engineer Creates Playable Accordion From 2 Commodore 64 Computers (arstechnica.com) 26

An anonymous reader quotes a report from Ars Technica: In late October, a Swedish software engineer named Linus Akesson unveiled a playable accordion -- called "The Commodordion" -- he crafted out of two vintage Commodore 64 computers connected with a bellows made of floppy disks taped together. A demo of the hack debuted in an 11-minute YouTube video where Akesson plays a Scott Joplin ragtime song and details the instrument's creation.

A fair amount of custom software engineering and hardware hackery went into making the Commodordion possible, as Akesson lays out in a post on his website. It builds off of earlier projects (that he says were intentionally leading up to this one), such as the Sixtyforgan (a C64 with spring reverb and a chromatic accordion key layout) and Qwertuoso, a program that allows live playing of the C64's famous SID sound chip.

So how does the Commodordion work? Akesson wired up a custom power supply, and when he flips the unit on, both Commodore 64 machines boot (no display necessary). Next, he loads custom music software he wrote from a Commodore Datasette emulator board into each machine. A custom mixer circuit board brings together the audio signals from the two units and measures input from the bellows to control the volume level of the sound output. The bellows, composed of many 5.25-inch floppy disks cut and taped into shape, emit air through a hole when squeezed. A microphone mounted just outside that hole translates the noise it hears into an audio envelope that manipulates the sound output to match. The Commodordion itself does not have speakers but instead outputs its electronic audio through a jack.

Programming

Computing Pioneer Who Invented the First Assembly Language Dies at Age 100 (msn.com) 42

"Kathleen Booth, who has died aged 100, co-designed of one of the world's first operational computers and wrote two of the earliest books on computer design and programming," the Telegraph wrote this week.

"She was also credited with the invention of the first assembly language, a programming language designed to be readable by users." In 1946 she joined a team of mathematicians under Andrew Booth at Birkbeck College undertaking calculations for the scientists working on the X-ray crystallography images which contributed to the discovery of the double helix shape of DNA....

To help the number-crunching involved Booth had embarked on building a computing machine called the Automatic Relay Calculator or ARC, and in 1947 Kathleen accompanied him on a six-month visit to Princeton University, where they consulted John von Neumann, who had developed the idea of storing programs in a computer. On their return to England they co-wrote General Considerations in the Design of an All Purpose Electronic Digital Computer, and went on to make modifications to the original ARC to incorporate the lessons learnt.

Kathleen devised the ARC assembly language for the computer and designed the assembler.

In 1950 Kathleen took a PhD in applied mathematics and the same year she and Andrew Booth were married. In 1953 they cowrote Automatic Digital Calculators, which included the general principles involved in the new "Planning and Coding"programming style.

The Booths remained at Birkbeck until 1962 working on other computer designs including the All Purpose Electronic (X) Computer (Apexc, the forerunner of the ICT 1200 computer which became a bestseller in the 1960s), for which Kathleen published the seminal Programming for an Automatic Digital Calculator in 1958. The previous year she and her husband had co-founded the School of Computer Science and Information Systems at Birkbeck.

"The APE(X)C design was commercialized and sold as the HEC by the British Tabulating Machine Co Ltd, which eventually became ICL," remembers the Register, sharing a 2010 video about the machine (along with several links for "Further Reading.")
Windows

Zeek Becoming Part of Microsoft Windows (corelight.com) 21

First released in 1998, the BSD-licensed software Zeek (originally named "Bro") is about to get more widely adopted, writes long-time Slashdot reader skinfaxi: Zeek, the open source network security monitoring platform, is being integrated into Windows and "is now deployed on more than one billion global endpoints," according to an announcement from Corelight.
From Corelight's press release: Corelight, the leader in open network detection and response, today announced the integration of Zeek, the world's most popular open source network security monitoring platform, as a component of Microsoft Windows and Defender for Endpoint. The integration will help security teams respond to the most challenging attacks by providing "richer signals for advanced threat hunting, complete and accurate discovery of IoT devices, and more powerful detection and response capabilities."

Originally created by Corelight co-founder and chief scientist Dr. Vern Paxson while at Lawrence Berkeley National Laboratory, Zeek transforms network traffic into compact and high-fidelity logs, file content, and behavioral analytics to accelerate security operations. Vital funding for Zeek came initially from the National Science Foundation and the US Department of Energy's Office of Science. As adoption increased, Corelight was founded to provide a financial model and corporate sponsor for the project....

"Microsoft is strongly committed to supporting open source projects and ecosystems," said Rob Lefferts, corporate vice president for Microsoft. "We're proud to be working with Zeek and are thrilled to bring this level of network intelligence and monitoring to our customers."

"This is an amazing development for Zeek and its community of contributors and users," said Paxson. "I never imagined that the tool I developed for network monitoring would find broader application in defending endpoints — but that's part of the creative magic of open source development.

"We are grateful for Microsoft's contributions and support, and we are excited that the project's impact, and that of the community of contributors, will increase so dramatically."

Earth

France Becomes Latest Country To Leave Controversial Energy Charter Treaty (theguardian.com) 50

France has become the latest country to pull out of the controversial energy charter treaty (ECT), which protects fossil fuel investors from policy changes that might threaten their profits. The Guardian reports: Speaking after an EU summit in Brussels on Friday, French president, Emmanuel Macron, said: "France has decided to withdraw from the energy charter treaty." Quitting the ECT was "coherent" with the Paris climate deal, he added. Macron's statement follows a recent vote by the Polish parliament to leave the 52-nation treaty and announcements by Spain and the Netherlands that they too wanted out of the scheme.

The European Commission has proposed a "modernization" of the agreement, which would end the writ of the treaty's secret investor-state courts between EU members. That plan is expected to be discussed at a meeting in Mongolia next month. A French government official said Paris would not try to block the modernization blueprint within the EU or at the meeting in Mongolia. "But whatever happens, France is leaving," the official said. While France was "willing to coordinate a withdrawal with others, we don't see that there is a critical mass ready to engage with that in the EU bloc as a whole," the official added.

The French withdrawal will take about a year to be completed, and in that time, discussion in Paris will likely move on to ways of neutralizing or reducing the duration of a "sunset clause" in the ECT that allows retrospective lawsuits. Progress on that issue is thought possible by sources close to ongoing legal negotiations on the issue.

Open Source

Fintech Giant 'The Clearing House' Joins Open-Source Patent Protection Powerhouse OIN (zdnet.com) 6

The Clearing House, a banking association and payments company owned by the largest commercial banks in the U.S., has joined the Open Invention Network (OIN) -- the world's largest patent nonaggression consortium. ZDNet reports: The OIN has long protected Linux and Linux-related software from patent aggression by rival companies. With the increase in patent troll attacks, the OIN is also defending companies from these assaults. You may not think financial companies and banks are subject to such attacks. I mean, TCH's roots go all the way back to 1853. Think again.

As Keith Bergelt, CEO of OIN, said in June, "The most sophisticated and compelling global banking and fintech companies have essentially become technology companies that employ open-source software to deliver their services at scale." Further, patent trolls "appear to be targeting them for this reason, along with the fact that financial services companies have not historically been active patent filers." That's because, historically, they've purchased most of their tech from third-party vendors.

That was then. This is now. Today, financial institutions generate more tech in-house, so they're more concerned about being granted patents, building patent portfolios, and related patent issues. Indeed, these days fintech businesses have their own Fintech Open Source Foundation (FINOS), the financial sector branch of the Linux Foundation. So, Bergelt said in a release Wednesday, "Advancements in financial services and fintech increasingly rely on open-source technologies. As the most experienced payment company in the US, and a keystone for the financial services industry, we are pleased that The Clearing House is committed to patent nonaggression in core Linux and adjacent open-source technologies."

Graphics

How 'Homestar Runner' Re-Emerged After the End of Flash (homestarrunner.com) 28

Wikipedia describes Homestar Runner as "a blend of surreal humour, self-parody, and references to popular culture, in particular video games, classic television, and popular music." But after launching in 2000, the web-based cartoon became a cultural phenomenon, co-creator Mike Chapman remembered in 2017: On the same day we received a demo of a song that John Linnell from They Might Be Giants recorded for a Strong Bad Email and a full-size working Tom Servo puppet from Jim Mallon from Mystery Science Theater 3000.... The Homestar references in the Buffy and Angel finales forever ago were huge. And there was this picture of Joss Whedon in a Strong Bad shirt from around that time that someone sent us that we couldn't believe. Years later, a photo of Geddy Lee from Rush wearing a Strong Bad hat on stage circulated which similarly freaked us out. We have no idea if he knew what Strong Bad was, but our dumb animal character was on his head while he probably shredded 'Working Man' so I'll take it!
After a mutli-year hiatus starting around 2009, the site has only been updating sporadically — and some worried that the end of Flash also meant the end of the Flash-based cartoon and its web site altogether. But on the day Flash Player was officially discontinued — December 31st, 2020 — a "post-Flash update" appeared at HomestarRunner.com: What happened our website? Flash is finally dead-dead-dead so something drastic had to be done so people could still watch their favorite cartoons and sbemails with super-compressed mp3 audio and hidden clicky-clicky easter eggs...!

[O]nce you click "come on in," you'll find yourself in familiar territory thanks to the Ruffle Project. It emulates Flash in such a way that all browsers and devices can finally play our cartoons and even some games.... Your favorite easter eggs are still hidden and now you can even choose to watch a YouTube version if there is one.

Keep in mind, Ruffle is still in development so not everything works perfectly. Games made after, say 2007, will probably be pretty janky but Ruffle plans on ulitmately supporting those too one day. And any cartoons with video elements in them (Puppet Jams, death metal) will just show you an empy box where the video should be. But hang in there and one day everything will be just like it was that summer when we got free cable somehow and Grandma still lived in the spare bedroom.

And since then, new content has quietly been appearing at HomestarRunner.com. (Most recently, Thursday the site added a teaser for an upcoming Halloween video.)

The Homestar Runner wiki is tracking this year's new content, which includes:

And past videos are now also being uploaded on the site's official YouTube channel.


Television

HBO Max Picks 'Homestar Runner' Co-Creator to Direct Batman Spin-off Series 'The Penguin' (cinemadailyus.com) 20

From a report: Filmmaker Craig Zobel has been tapped by HBO Max to direct the first two episodes of The Penguin, its much-awaited Batman spinoff. He will also serve as executive producer of the show, with Lauren LeFranc writing the script. Starring in The Penguin is Colin Farrell, who played the villainous Oswald Cobblepot in The Batman earlier this year. The Penguin will focus its attention on Cobblepot's notorious past and trace his rise to power in Gotham.

Zobel is already part of the family, having previously directed The Mare of Easttown for HBO Max. The prolific director also applied his talents to episodes of Westworld, The Leftovers, and American Gods...

If all goes according to schedule, viewers could be enjoying The Penguin by the end of 2023.

The article also notes that Zobel also helped co-create Homestar Runner in its original incarnation as a parody children's picture book.
Earth

Why Hurricane Ian Killed So Many People (cnn.com) 174

It was Florida's deadliest hurricane in 87 years, tied for the fifth-strongest hurricane to make landfall in the continental U.S. and killing more than 100 people after veering south into unexpected areas.

But a Rutgers University health psychologist suggests other factors might've made Hurricane Ian more deadly: Ian also underwent rapid intensification, perhaps influenced by climate change, which meant that its wind speeds increased dramatically as it passed over the warm waters of the Gulf of Mexico before landfall.

Emergency managers typically need at least 48 hours to successfully evacuate areas of southwest Florida. However, voluntary evacuation orders for Lee County were issued less than 48 hours prior to landfall, and for some areas were made mandatory just 24 hours before the storm came ashore. This was less than the amount of time outlined in Lee County's own emergency management plan.

While the lack of sufficient time to evacuate was cited by some as a reason why they stayed behind, there are other factors that may also have suppressed evacuations in some of the hardest hit areas. In order to correctly follow evacuation orders, people need to first know their evacuation zone. Research from other areas of the country indicates that many people don't. That's why the evacuation zone locator websites in the affected counties were crucial. However, so many people were checking their zones that some of these websites crashed in the days before the storm.

The article asks whether the early voluntary evacuation order "lulled some residents into being less concerned" and ultimately compounded problems. "In areas where evacuation orders were issued later, people who weren't expecting to evacuate needed to find and understand this evacuation zone information quickly...."

"People need to know that they are in an area being asked to evacuate — and waiting until the storm is on its way to find out their zone may be too late. Emergency managers need to educate people in advance of imminent storms while also developing more robust websites to handle the queries in the days before the storm."
Businesses

Fandom Buys TV Guide, Metacritic, GameSpot and Other Brands For About $50 Million In Cash (variety.com) 22

Fandom is rolling up a suite of entertainment and gaming content properties -- including TV Guide and Metacritic -- in a deal with digital-marketing company Red Ventures worth about $50 million. Variety reports: San Francisco-based Fandom acquired GameSpot, Metacritic, TV Guide, GameFAQs, Giant Bomb, Cord Cutters News and Comic Vine under the deal. The sites collectively attract 46 million monthly active users, according to Fandom. Financial terms of the pact were not disclosed; a source familiar with the deal pegged it "in the mid-eight figures," with Fandom paying the roughly $50 million for the properties in cash. Red Ventures had acquired TV Guide, Metacritic and GameSpot in 2020 as part of its $500 million deal to buy the CNET Media Group from Paramount Global.

Founded in 2004, Fandom today hosts more than 250,000 user-curated wiki pages spanning pop culture, gaming, TV and film -- reaching some 300 million monthly active users. Fandom was founded by Jimmy Wales, Wikipedia co-founder, and entrepreneur Angela Beesley Starling. In 2018, Fandom was sold to a company backed by venture-capital firm TPG headed by Jon Miller.

The latest deal continues Fandom's expansion beyond its wiki-based roots. In 2018, Fandom acquired ScreenJunkies, producers of the popular "Honest Trailer" series, from now-defunct digital media company Defy Media. The company acquired Curse Media in 2019 which brought together gaming wikis with integrated digital gaming tools. In 2021, Fandom acquired Fanatical, a an online video-game retailer. Fandom Productions, the content arm of Fandom, will house GameSpot, TV Guide and Metacritic, along with the Honest Trailers team and the weekly video news program "The Loop."

Slashdot Top Deals