Author name: Shannon Garcia

alpacas-in-idaho-test-positive-for-h5n1-bird-flu-in-another-world-first

Alpacas in Idaho test positive for H5N1 bird flu in another world first

Spit-take —

The alpacas were known to be in close contact with infected birds.

Suri alpacas on a farm in Pennsylvania.

Enlarge / Suri alpacas on a farm in Pennsylvania.

Four backyard alpacas in southern Idaho have tested positive for highly pathogenic avian influenza (HPAI) H5N1, marking the first time bird flu has been detected in members of the fleecy camelid family, according to the US Department of Agriculture.

On Tuesday, the USDA announced that the agency’s National Veterinary Services Laboratories confirmed the infection on a farm in Jerome County on May 16. While the infections are a first for the spitting llama relatives, the USDA said they weren’t particularly surprising. The alpacas were in close contact with HPAI-infected poultry on the farm, which were “depopulated” this month. Of 18 alpacas on the affected farm, only four were found to be infected. There were no deaths documented, according to a report the USDA submitted to the World Organization for Animal Health.

Genomic sequencing indicates that the H5N1 virus infecting the alpacas (B3.13) matches both the virus currently circulating among US dairy cows and the virus that infected birds on the farm.

According to the Alpaca Owners Association, there are over 264,000 alpacas in the US.

The finding does not increase the threat of H5N1 to the general public, but it again highlights the virus’s alarming ability to readily spread to mammals. The USDA has documented hundreds of cases of H5N1 in a wide range of mammals since May 2022, when the outbreak strain began spreading in North America. In March, the USDA announced the unprecedented outbreak among dairy cows. But the agency has found the virus spreading in mink, raccoons, foxes, cats, seals, bears, mountain lions, bottlenose dolphins, goats, and coyotes, among other animals. With each new species and infection, H5N1 gains new opportunities to adapt to better infect and spread among mammals. And as the virus jumps to mammals in close contact with humans, the risk increases that the virus will have the opportunity to adapt to spread among humans.

The USDA and state officials continue to identify H5N1 in dairy herds. According to the latest data on the USDA’s tracking site, at least 66 dairy herds in nine states have been infected.

Alpacas in Idaho test positive for H5N1 bird flu in another world first Read More »

sony-apologizes-for-interview-it-says-“misrepresented”-a-last-of-us-creator

Sony apologizes for interview it says “misrepresented” a Last of Us creator

Who said what now? —

Move comes after Druckmann publicly disavowed some quotes: “This is not quite what I said.”

Naughty Dog's Neil Druckmann, seen here not questioning the accuracy of a PR interview.

Enlarge / Naughty Dog’s Neil Druckmann, seen here not questioning the accuracy of a PR interview.

Sony has taken down an interview with Naughty Dog Studio Head Neil Druckmann (Uncharted, The Last of Us) that the company now says contains “several significant errors and inaccuracies that don’t represent his perspective and values.” The surprising move comes after Druckmann took the extreme measure of publicly questioning a portion of the PR interview by posting a lengthy transcript that conflicted with the heavily edited version Sony posted online.

The odd media saga began last Thursday, when Sony published the interview (archive here) under the heading “The Evolution of Storytelling Across Mediums.” The piece was part of the Creative Entertainment Vision section of Sony’s corporate site, a PR-driven concept exploring how Sony will “seamlessly connect multi-layered worlds where physical and virtual realities overlap to deliver limitless Kanto—through creativity and technology—working with creators.” Whatever that means.

Druckmann’s short interview started attracting attention almost immediately, primarily due to Druckmann’s apparent promotion of using AI tools in game development. Such tools “will allow us to create nuanced dialogues and characters, expanding creative possibilities,” Druckmann is quoted as saying. “AI is really going to revolutionize how content is being created, although it does bring up some ethical issues we need to address.”

Not so fast…

By Friday, though, Druckmann ended a months-long drought of social media posting by noting that, in at least one case, the words posted by Sony were “not quite what I said. In editing my rambling answers in my recent interview with Sony, some of my words, context, and intent were unfortunately lost.”

As evidence, Druckmann posted this “rambling” 457-word response to a question about a “personal vision or dream project” he hoped to create:

Well, I’ve been very lucky, in that I’ve already had that. I got the chance to make several of my dream projects. I am working on a new one right now. And it’s maybe the most excited I’ve been for a project yet. I can’t talk about it or our bosses will get very mad at me.

And I guess in general, there is something happening now that I think is very cool. Which is there’s a new appreciation for gaming that I’ve never seen before. Like when I was growing up, gaming was more of a kid’s thing. Now it’s clearly for everyone. But it’s like, if you’re a gamer, you know about the potential of games, and non-gamers, they don’t really know what they’re missing out on.

But my hope was, when we made The Last of Us as a TV show that we could change that. And why I became so involved with it. I wanted so badly for it to be good, because I wanted this to happen, which is like someone who will watch the show and really like it. And fall in love with those characters the way that we have fallen in love with those characters and their story. And then realize at the end, “Wait, that’s based on a video game?” and then go and check out the game and just see the wealth of narratives and everything that’s happening in games.

So now I feel like there’s kind of a spotlight on gaming. And you know, Fallout just came out. And that’s a big success for Amazon. And I find that really exciting. Not because games need to be movies, or they need to be TV shows, but I think it just kind of opens the eyes of a bunch of people that just weren’t aware of the kind of experiences that exist in games. I think right now we’ve hit a tipping point where it’s about to take off where people realize, “Oh my God, there’s all these incredible moving experiences in games!”

So, I’m not only excited for this game that we’re making—and it’s, it’s something really fresh for us—but I’m also excited to see how the world reacts to it. Because of The Last of Us, and the success of the show, people even outside of gaming are looking at us to see what it is that we put out next. I’m very excited to see what the reaction for this thing will be—and l’ve already said too much about it. I’ll stop there. So, you’re asking me for my dream projects. I’ve been very lucky to have worked on my favorite games with incredible collaborators and I’m very thankful for them.

For reference, here is the 127-word summary of that answer posted by Sony:

I’ve been lucky to work on several dream projects and am currently excited about a new one, which is perhaps the most thrilling yet. There’s a growing appreciation for gaming that transcends all age groups, unlike when I was growing up. This shift is highlighted by our venture into television with The Last of Us, which I hoped would bridge the gap between gamers and non-gamers. The show’s success has spotlighted gaming, illustrating the rich, immersive experiences it offers. This visibility excites me not only for our current project but for the broader potential of gaming to captivate a global audience. I’m eager to see how this new game resonates, especially following the success of The Last of Us, as it could redefine mainstream perceptions of gaming.

While the gist of Druckmann’s original answer is more or less preserved, the condensed version loses a lot of the specific details and flavor Druckmann highlighted in his answer. The edited version also inserts some key phrases and ideas that Druckmann didn’t use at all, such as his supposed hope that his new project “could redefine mainstream perceptions of gaming.”

Though we don’t know how much Druckmann’s other answers were clipped or amended in the editing process, Druckmann’s public annoyance with the edits was apparently enough to get Sony’s attention. Sometime after Tuesday night, the PlayStation-maker replaced the public interview with the following message:

In re-reviewing our recent interview with Naughty Dog’s Neil Druckmann, we have found several significant errors and inaccuracies that don’t represent his perspective and values (including topics such as animation, writing, technology, AI, and future projects). We apologize to Neil for misrepresenting his words and for any negative impact this interview might have caused him and his team. In coordination with Naughty Dog and SIE, we have removed the interview.

Journalists often edit interview responses for concision and clarity, but this interview skips the usual step of noting the existence of those kinds of edits near the top of the piece. And while press releases often contain executive quotes that have been carefully crafted in consultation with PR professionals, there was no indication in this article that the responses here were anything other than Druckmann’s own thoughts and words.

Game publishers and console makers have a long history of sharing developer interviews directly with the public rather than having those developers’ views filtered through the press. This is the first instance we can remember where the promotional process itself has become a source of controversy.

Sony apologizes for interview it says “misrepresented” a Last of Us creator Read More »

this-is-cadillac’s-new-entry-level-ev,-the-$54,000-optiq-crossover

This is Cadillac’s new entry-level EV, the $54,000 Optiq crossover

A red Cadillac Optiq

Enlarge / The Cadillac Optiq is the brand’s next EV, slotting underneath the electric Lyriq in the range.

Michael Teo Van Runkle

Earlier this month, Cadillac showed off the all-new, all-electric 2025 Optiq to select media in downtown Los Angeles. The Optiq will slot in below the larger Lyriq, Celestiq, and Escalade IQ SUVs but is still based on GM’s steadily proliferating Ultium electric vehicle architecture.

Having driven no fewer than five different Ultium-based vehicles in the past year, I visited the Optiq preview, hoping to learn how Cadillac can differentiate this compact crossover from other offerings in an increasingly competitive segment. I also wanted to see whether GM has effectively made the case for EV converts who are looking at entry-level options versus a lower price point for the similarly specced Chevrolet Equinox EV.

In person, the Optiq’s exterior styling continues the language established by Lyriq and Celestiq, if toned down to a slightly less-aggressive futuristic level. Straked patterns on the angular, faded quarter panels make for a nice touch, though the details looked two-dimensional, as if they were stickers, until I got up close enough to inspect the use of real glass layering.

On the other hand, piano black plastic cladding around most of the lower panels comes non-negotiable, creating a slightly less premium aesthetic compared to the extensively worked-over, if somewhat familiar, interior. Here, we’re at a new level of materials and patterns compared to any other Ultium vehicle I’ve experienced—including the baffling Acura ZDX, and especially considering the starting price tag of “an estimated $54,000.” Woven textures of 100 percent recycled yarn allow for much more subtle lighting patterns than the de rigueur mood strips that so many EV manufacturers believe are necessary.

  • The Optiq is very… shiny.

    Michael Teo Van Runkle

  • GM continues to quote how much range its EVs can gain in 10 minutes at a DC fast charger instead of telling us how long it takes to charge to 80 percent.

    Michael Teo Van Runkle

  • Not stickers, actual layered glass here.

    Michael Teo Van Runkle

At that price, the Optiq manages respectable, if not overwhelming, specs and stats. Cadillac hopes the 85 kWh battery pack will achieve an EPA-rated 300 miles (482 km) of range and allow customers to add up to 79 miles (127 km) of range in 10 minutes of DC fast-charging. Output steps up to 300 hp (223 kW) and 354 lb-ft (480 Nm) of torque for all trim levels, thanks to dual motors and all-wheel drive coming standard.

How will handling compare to the Equinox?

But this Cadillac era is defined by Blackwings and V packages, not dentists cruising around in land yachts. So the real challenge I laid to Caddy’s reps on hand involved driving dynamics since other Ultium cars tend to pair vague steering with a heavy chassis that seems to overwhelm suspension engineering. Thomas Schinderle, lead development engineer on the Optiq, happily fielded my questions.

“When you have the high-voltage battery enclosures as a structural element of the car,” he began, “it’s a really stiff structure overall that gives us a strong foundation to react to the steering forces.”

But that statement applies to all Ultium vehicles, I suggested. Schinderle nodded and explained that reduced electric steering assist, versus the Equinox in particular, will contribute to more resistance when the steering wheel turns off-center. Optiq’s steering ratio also tightens up significantly when compared to the Lyriq.

Cadillac uses this same 33-inch screen in the Lyriq and the facelifted XT4.

Enlarge / Cadillac uses this same 33-inch screen in the Lyriq and the facelifted XT4.

Michael Teo Van Runkle

“We’re leaning into this sporty, fun-to-drive aspect,” he said. “At 6 inches [152 mm] shorter wheelbase than the Lyriq, immediately, just based on physics, we’re 400 pounds [181 kg] lighter. Then you choose [antiroll] bar sizes, when I looked at roll gradient—that’s degrees per g that you’re leaning into the corner—we lowered that number for Optiq.”

I pressed for differences versus the Equinox, Chevrolet’s forthcoming compact EV that shares the same chassis as Optiq.

Damping things down

“We actually have technology on here that’s different than the Equinox,” Schinderle revealed. “We have what we’re marketing as ‘passive-plus dampers.’ Equinox does not have that.”

These dampers use a valve stack that flexes to open a dedicated orifice that allows fluid flow to reduce high-frequency chatter in the suspension. Schinderle brought up expansion cracks and frost heaves as an example, but the point was really that the “passive-plus” valving allowed his team to focus elsewhere while tuning the rest of the suspension.

“I can add control to that low-speed event,” he went on, “where you’ve got body roll and you’re coming through the big swells on the road. We’re able to tie those events down and add control to the damper without sacrificing isolation in those high-frequency events.”

This is Cadillac’s new entry-level EV, the $54,000 Optiq crossover Read More »

openai-board-first-learned-about-chatgpt-from-twitter,-according-to-former-member

OpenAI board first learned about ChatGPT from Twitter, according to former member

It’s a secret to everybody —

Helen Toner, center of struggle with Altman, suggests CEO fostered “toxic atmosphere” at company.

Helen Toner, former OpenAI board member, speaks onstage during Vox Media's 2023 Code Conference at The Ritz-Carlton, Laguna Niguel on September 27, 2023.

Enlarge / Helen Toner, former OpenAI board member, speaks during Vox Media’s 2023 Code Conference at The Ritz-Carlton, Laguna Niguel on September 27, 2023.

In a recent interview on “The Ted AI Show” podcast, former OpenAI board member Helen Toner said the OpenAI board was unaware of the existence of ChatGPT until they saw it on Twitter. She also revealed details about the company’s internal dynamics and the events surrounding CEO Sam Altman’s surprise firing and subsequent rehiring last November.

OpenAI released ChatGPT publicly on November 30, 2022, and its massive surprise popularity set OpenAI on a new trajectory, shifting focus from being an AI research lab to a more consumer-facing tech company.

“When ChatGPT came out in November 2022, the board was not informed in advance about that. We learned about ChatGPT on Twitter,” Toner said on the podcast.

Toner’s revelation about ChatGPT seems to highlight a significant disconnect between the board and the company’s day-to-day operations, bringing new light to accusations that Altman was “not consistently candid in his communications with the board” upon his firing on November 17, 2023. Altman and OpenAI’s new board later said that the CEO’s mismanagement of attempts to remove Toner from the OpenAI board following her criticism of the company’s release of ChatGPT played a key role in Altman’s firing.

“Sam didn’t inform the board that he owned the OpenAI startup fund, even though he constantly was claiming to be an independent board member with no financial interest in the company on multiple occasions,” she said. “He gave us inaccurate information about the small number of formal safety processes that the company did have in place, meaning that it was basically impossible for the board to know how well those safety processes were working or what might need to change.”

Toner also shed light on the circumstances that led to Altman’s temporary ousting. She mentioned that two OpenAI executives had reported instances of “psychological abuse” to the board, providing screenshots and documentation to support their claims. The allegations made by the former OpenAI executives, as relayed by Toner, suggest that Altman’s leadership style fostered a “toxic atmosphere” at the company:

In October of last year, we had this series of conversations with these executives, where the two of them suddenly started telling us about their own experiences with Sam, which they hadn’t felt comfortable sharing before, but telling us how they couldn’t trust him, about the toxic atmosphere it was creating. They use the phrase “psychological abuse,” telling us they didn’t think he was the right person to lead the company, telling us they had no belief that he could or would change, there’s no point in giving him feedback, no point in trying to work through these issues.

Despite the board’s decision to fire Altman, Altman began the process of returning to his position just five days later after a letter to the board signed by over 700 OpenAI employees. Toner attributed this swift comeback to employees who believed the company would collapse without him, saying they also feared retaliation from Altman if they did not support his return.

“The second thing I think is really important to know, that has really gone under reported is how scared people are to go against Sam,” Toner said. “They experienced him retaliate against people retaliating… for past instances of being critical.”

“They were really afraid of what might happen to them,” she continued. “So some employees started to say, you know, wait, I don’t want the company to fall apart. Like, let’s bring back Sam. It was very hard for those people who had had terrible experiences to actually say that… if Sam did stay in power, as he ultimately did, that would make their lives miserable.”

In response to Toner’s statements, current OpenAI board chair Bret Taylor provided a statement to the podcast: “We are disappointed that Miss Toner continues to revisit these issues… The review concluded that the prior board’s decision was not based on concerns regarding product safety or security, the pace of development, OpenAI’s finances, or its statements to investors, customers, or business partners.”

Even given that review, Toner’s main argument is that OpenAI hasn’t been able to police itself despite claims to the contrary. “The OpenAI saga shows that trying to do good and regulating yourself isn’t enough,” she said.

OpenAI board first learned about ChatGPT from Twitter, according to former member Read More »

researchers-crack-11-year-old-password,-recover-$3-million-in-bitcoin

Researchers crack 11-year-old password, recover $3 million in bitcoin

Illustration of a wallet

Flavio Coelho/Getty Images

Two years ago when “Michael,” an owner of cryptocurrency, contacted Joe Grand to help recover access to about $2 million worth of bitcoin he stored in encrypted format on his computer, Grand turned him down.

Michael, who is based in Europe and asked to remain anonymous, stored the cryptocurrency in a password-protected digital wallet. He generated a password using the RoboForm password manager and stored that password in a file encrypted with a tool called TrueCrypt. At some point, that file got corrupted, and Michael lost access to the 20-character password he had generated to secure his 43.6 BTC (worth a total of about 4,000 euros, or $5,300, in 2013). Michael used the RoboForm password manager to generate the password but did not store it in his manager. He worried that someone would hack his computer and obtain the password.

“At [that] time, I was really paranoid with my security,” he laughs.

Grand is a famed hardware hacker who in 2022 helped another crypto wallet owner recover access to $2 million in cryptocurrency he thought he’d lost forever after forgetting the PIN to his Trezor wallet. Since then, dozens of people have contacted Grand to help them recover their treasure. But Grand, known by the hacker handle “Kingpin,” turns down most of them, for various reasons.

Grand is an electrical engineer who began hacking computing hardware at age 10 and in 2008 cohosted the Discovery Channel’s Prototype This show. He now consults with companies that build complex digital systems to help them understand how hardware hackers like him might subvert their systems. He cracked the Trezor wallet in 2022 using complex hardware techniques that forced the USB-style wallet to reveal its password.

But Michael stored his cryptocurrency in a software-based wallet, which meant none of Grand’s hardware skills were relevant this time. He considered brute-forcing Michael’s password—writing a script to automatically guess millions of possible passwords to find the correct one—but determined this wasn’t feasible. He briefly considered that the RoboForm password manager Michael used to generate his password might have a flaw in the way it generated passwords, which would allow him to guess the password more easily. Grand, however, doubted such a flaw existed.

Michael contacted multiple people who specialize in cracking cryptography; they all told him “there’s no chance” of retrieving his money. But last June he approached Grand again, hoping to convince him to help, and this time Grand agreed to give it a try, working with a friend named Bruno in Germany who also hacks digital wallets.

Researchers crack 11-year-old password, recover $3 million in bitcoin Read More »

openai-training-its-next-major-ai-model,-forms-new-safety-committee

OpenAI training its next major AI model, forms new safety committee

now with 200% more safety —

GPT-5 might be farther off than we thought, but OpenAI wants to make sure it is safe.

A man rolling a boulder up a hill.

On Monday, OpenAI announced the formation of a new “Safety and Security Committee” to oversee risk management for its projects and operations. The announcement comes as the company says it has “recently begun” training its next frontier model, which it expects to bring the company closer to its goal of achieving artificial general intelligence (AGI), though some critics say AGI is farther off than we might think. It also comes as a reaction to a terrible two weeks in the press for the company.

Whether the aforementioned new frontier model is intended to be GPT-5 or a step beyond that is currently unknown. In the AI industry, “frontier model” is a term for a new AI system designed to push the boundaries of current capabilities. And “AGI” refers to a hypothetical AI system with human-level abilities to perform novel, general tasks beyond its training data (unlike narrow AI, which is trained for specific tasks).

Meanwhile, the new Safety and Security Committee, led by OpenAI directors Bret Taylor (chair), Adam D’Angelo, Nicole Seligman, and Sam Altman (CEO), will be responsible for making recommendations about AI safety to the full company board of directors. In this case, “safety” partially means the usual “we won’t let the AI go rogue and take over the world,” but it also includes a broader set of “processes and safeguards” that the company spelled out in a May 21 safety update related to alignment research, protecting children, upholding election integrity, assessing societal impacts, and implementing security measures.

OpenAI says the committee’s first task will be to evaluate and further develop those processes and safeguards over the next 90 days. At the end of this period, the committee will share its recommendations with the full board, and OpenAI will publicly share an update on adopted recommendations.

OpenAI says that multiple technical and policy experts, including Aleksander Madry (head of preparedness), Lilian Weng (head of safety systems), John Schulman (head of alignment science), Matt Knight (head of security), and Jakub Pachocki (chief scientist), will also serve on its new committee.

The announcement is notable in a few ways. First, it’s a reaction to the negative press that came from OpenAI Superalignment team members Ilya Sutskever and Jan Leike resigning two weeks ago. That team was tasked with “steer[ing] and control[ling] AI systems much smarter than us,” and their departure has led to criticism from some within the AI community (and Leike himself) that OpenAI lacks a commitment to developing highly capable AI safely. Other critics, like Meta Chief AI Scientist Yann LeCun, think the company is nowhere near developing AGI, so the concern over a lack of safety for superintelligent AI may be overblown.

Second, there have been persistent rumors that progress in large language models (LLMs) has plateaued recently around capabilities similar to GPT-4. Two major competing models, Anthropic’s Claude Opus and Google’s Gemini 1.5 Pro, are roughly equivalent to the GPT-4 family in capability despite every competitive incentive to surpass it. And recently, when many expected OpenAI to release a new AI model that would clearly surpass GPT-4 Turbo, it instead released GPT-4o, which is roughly equivalent in ability but faster. During that launch, the company relied on a flashy new conversational interface rather than a major under-the-hood upgrade.

We’ve previously reported on a rumor of GPT-5 coming this summer, but with this recent announcement, it seems the rumors may have been referring to GPT-4o instead. It’s quite possible that OpenAI is nowhere near releasing a model that can significantly surpass GPT-4. But with the company quiet on the details, we’ll have to wait and see.

OpenAI training its next major AI model, forms new safety committee Read More »

newly-discovered-ransomware-uses-bitlocker-to-encrypt-victim-data

Newly discovered ransomware uses BitLocker to encrypt victim data

GOING NATIVE —

ShrinkLocker is the latest ransomware to use Windows’ full-disk encryption.

A previously unknown piece of ransomware, dubbed ShrinkLocker, encrypts victim data using the BitLocker feature built into the Windows operating system.

BitLocker is a full-volume encryptor that debuted in 2007 with the release of Windows Vista. Users employ it to encrypt entire hard drives to prevent people from reading or modifying data in the event they get physical access to the disk. Starting with the rollout of Windows 10, BitLocker by default has used the 128-bit and 256-bit XTS-AES encryption algorithm, giving the feature extra protection from attacks that rely on manipulating cipher text to cause predictable changes in plain text.

Recently, researchers from security firm Kaspersky found a threat actor using BitLocker to encrypt data on systems located in Mexico, Indonesia, and Jordan. The researchers named the new ransomware ShrinkLocker, both for its use of BitLocker and because it shrinks the size of each non-boot partition by 100 MB and splits the newly unallocated space into new primary partitions of the same size.

“Our incident response and malware analysis are evidence that attackers are constantly refining their tactics to evade detection,” the researchers wrote Friday. “In this incident, we observed the abuse of the native BitLocker feature for unauthorized data encryption.”

ShrinkLocker isn’t the first malware to leverage BitLocker. In 2022, Microsoft reported that ransomware attackers with a nexus to Iran also used the tool to encrypt files. That same year, the Russian agricultural business Miratorg was attacked by ransomware that used BitLocker to encrypt files residing in the system storage of infected devices.

Once installed on a device, ShrinkLocker runs a VisualBasic script that first invokes the Windows Management Instrumentation and Win32_OperatingSystem class to obtain information about the operating system.

“For each object within the query results, the script checks if the current domain is different from the target,” the Kaspersky researchers wrote. “If it is, the script finishes automatically. After that, it checks if the name of the operating system contains ‘xp,’ ‘2000,’ ‘2003,’ or ‘vista,’ and if the Windows version matches any one of these, the script finishes automatically and deletes itself.”

A screenshot showing initial conditions for execution.

Enlarge / A screenshot showing initial conditions for execution.

Kaspersky

The script then continues to use the WMI for querying information about the OS. It goes on to perform the disk resizing operations, which can vary depending on the OS version detected. The ransomware performs these operations only on local, fixed drives. The decision to leave network drives alone is likely motivated by the desire not to trigger network detection protections.

Eventually, ShrinkLocker disables protections designed to secure the BitLocker encryption key and goes on to delete them. It then enables the use of a numerical password, both as a protector against anyone else taking back control of BitLocker and as an encryptor for system data. The reason for deleting the default protectors is to disable key recovery features by the device owner. ShrinkLocker then goes on to generate a 64-character encryption key using random multiplication and replacement of:

  • A variable with the numbers 0–9;
  • The famous pangram, “The quick brown fox jumps over the lazy dog,” in lowercase and uppercase, which contains every letter of the English alphabet;
  • Special characters.

After several additional steps, data is encrypted. The next time the device reboots, the display looks like this:

Screenshot showing the BitLocker recovery screen.

Enlarge / Screenshot showing the BitLocker recovery screen.

Kaspersky

Decrypting drives without the attacker-supplied key is difficult and likely impossible in many cases. While it is possible to recover some of the passphrases and fixed values used to generate the keys, the script uses variable values that are different on each infected device. These variable values aren’t easy to recover.

There are no protections specific to ShrinkLocker for preventing successful attacks. Kaspersky advises the following:

  • Use robust, properly configured endpoint protection to detect threats that try to abuse BitLocker;
  • Implement Managed Detection and Response (MDR) to proactively scan for threats;
  • If BitLocker is enabled, make sure it uses a strong password and that the recovery keys are stored in a secure location;
  • Ensure that users have only minimal privileges. This prevents them from enabling encryption features or changing registry keys on their own;
  • Enable network traffic logging and monitoring. Configure the logging of both GET and POST requests. In case of infection, the requests made to the attacker’s domain may contain passwords or keys;
  • Monitor for events associated with VBS execution and PowerShell, then save the logged scripts and commands to an external repository storing activity that may be deleted locally;
  • Make backups frequently, store them offline, and test them.

Friday’s report also includes indicators that organizations can use to determine if they have been targeted by ShrinkLocker.

Listing image by Getty Images

Newly discovered ransomware uses BitLocker to encrypt victim data Read More »

us-officials:-a-russian-rocket-launch-last-week-likely-deployed-a-space-weapon

US officials: A Russian rocket launch last week likely deployed a space weapon

Co-planar —

“Naming space as a warfighting domain was kind of forbidden, but that’s changed.”

A Russian Soyuz rocket climbs away from the Plesetsk Cosmodrome on May 16.

Enlarge / A Russian Soyuz rocket climbs away from the Plesetsk Cosmodrome on May 16.

The launch of a classified Russian military satellite last week deployed a payload that US government officials say is likely a space weapon.

In a series of statements, US officials said the new military satellite, named Kosmos 2576, appears to be similar to two previous “inspector” spacecraft launched by Russia in 2019 and 2022.

“Just last week, on May 16, Russia launched a satellite into low-Earth orbit that the United States assesses is likely a counter-space weapon presumably capable of attacking other satellites in low-Earth orbit,” said Robert Wood, the deputy US ambassador to the United Nations. “Russia deployed this new counter-space weapon into the same orbit as a US government satellite.”

Kosmos 2576 is flying in the same orbital plane as a National Reconnaissance Office (NRO) spy satellite, meaning it can regularly approach the top-secret US reconnaissance platform. The launch of Kosmos 2576 from Russia’s Plesetsk Cosmodrome on a Soyuz rocket was precisely timed to happen when the Earth’s rotation brought the launch site underneath the orbital path of the NRO spy satellite, officially designated USA 314.

The Soyuz rocket’s Fregat upper stage released Kosmos 2576 into an orbit roughly 275 miles (445 km) above Earth at an inclination of 97.25 degrees to the equator.

Conventional but concerning

So far, Kosmos 2576 is nowhere near USA 314, a bus-size spacecraft believed to carry a powerful Earth-facing telescope to capture high-resolution images for use by US intelligence agencies. This type of spacecraft is publicly known as a KH-11, or Keyhole-class, satellite, but its design and capabilities are top-secret.

It’s no surprise that the Russian military wants to get a close look in hopes of learning more about the US government’s most closely held secrets about what it does in orbit. Russian satellites have also flown near Western communications satellites in geostationary orbit, likely in an attempt to eavesdrop on radio transmissions.

Russia’s deputy foreign minister, Sergei Ryabkov, dismissed the US government’s assessment about the purpose of Kosmos 2576 as “fake news.” However, in the last few years, Russia has steered satellites into orbits intersecting with the paths of US spy platforms, and demonstrated it can take out an enemy satellite using a range of methods.

The current orbit of Kosmos 2576 will only occasionally bring it within a few hundred kilometers of the USA 314, according to Jonathan McDowell, an astrophysicist and expert tracker of spaceflight events. However, analysts expect additional maneuvers to raise the altitude Kosmos 2576 and put it into position for closer passes. This is what happened with a pair of Russian satellites launched in 2019 and 2022.

These two previous Russian satellites—Kosmos 2542 and Kosmos 2558— continually flew within a few dozen kilometers of two other NRO satellites—USA 245 and USA 326—in low-Earth orbit. In a post on the social media platform X, McDowell wrote that the Russian military craft “shadowed US satellites at a large distance but have not interfered with them.”

Because of this, McDowell wrote that he is “highly skeptical” that Kosmos 2576 is an anti-satellite weapon.

But one of these Russian satellites, Kosmos 2542, released a smaller sub-satellite, designated Kosmos 2543, which made its own passes near the USA 245 spacecraft, a KH-11 imaging satellite similar to USA 314. At one point, satellite trackers noticed USA 245 made a slight change to orbit. Its Russian pursuer later made a similar orbit adjustment to keep up.

In 2020, Kosmos 2543 backed off from USA 245. Once well away from the NRO satellite, Kosmos 2543 ejected a mysterious projectile into space at a speed fast enough to damage any target in its sights.

At the time, US Space Command called the event a “non-destructive test of a space-based anti-satellite weapon.” The projectile fired from Kosmos 2543 at a relative velocity of some 400 mph (700 km per hour), according to McDowell’s analysis of publicly available satellite tracking data.

Gen. Charles

Enlarge / Gen. Charles “CQ” Brown, chairman of the joint chiefs of staff, says the US military must have an ability to defend itself in space.

The US military has identified China as its most significant strategic adversary in the coming decades. Most aspects of Russia’s space program are in decline, but it still boasts formidable anti-satellite capabilities. Russia intentionally destroyed one of its retired satellites in orbit with a ground-based missile in 2021. The Russian military has also deployed several Peresvet laser units capable of disabling a satellite in orbit. A Russian cyberattack at the start of the invasion of Ukraine in 2022 knocked a commercial satellite communications network offline.

Most recently, US government officials have claimed Russia is developing a nuclear anti-satellite weapon. Russian officials also denied this. But Russia vetoed a UN Security Council resolution last month reiterating language from the 1967 Outer Space Treaty banning weapons of mass destruction in orbit.

The US military has its own fleet of inspector satellites in orbit to track what other nations are doing in space. The Space Force’s development of any offensive military capability in space is classified.

“The space domain is much more challenging today than it was a number a number of years ago,” said Air Force Gen. Charles “CQ” Brown, chairman of the joint chiefs of staff, in an event Wednesday hosted by the Atlantic Council. “We looked at it as a very benign environment, where you didn’t have to worry about conflicts in space. As a matter of fact, naming space as a warfighting domain was kind of forbidden, but that’s changed, and it’s been changed based what our adversaries are doing in space.”

“We don’t want to have our satellites … be challenged,” Brown said. “So we want to make sure that we have the capabilities to defend ourselves, no matter what domain we’re in, whether it’s in the space domain, air, land, or maritime. That’s where our focus is as a military, in making sure we’re investing to provide the capabilities and expertise to do that.”

US officials: A Russian rocket launch last week likely deployed a space weapon Read More »

bing-outage-shows-just-how-little-competition-google-search-really-has

Bing outage shows just how little competition Google search really has

Searching for new search —

Opinion: Actively searching without Google or Bing is harder than it looks.

Google logo on a phone in front of a Bing logo in the background

Getty Images

Bing, Microsoft’s search engine platform, went down in the very early morning today. That meant that searches from Microsoft’s Edge browsers that had yet to change their default providers didn’t work. It also meant that services relying on Bing’s search API—Microsoft’s own Copilot, ChatGPT search, Yahoo, Ecosia, and DuckDuckGo—similarly failed.

Services were largely restored by the morning Eastern work hours, but the timing feels apt, concerning, or some combination of the two. Google, the consistently dominating search platform, just last week announced and debuted AI Overviews as a default addition to all searches. If you don’t want an AI response but still want to use Google, you can hunt down the new “Web” option in a menu, or you can, per Ernie Smith, tack “&udm=14” onto your search or use Smith’s own “Konami code” shortcut page.

If dismay about AI’s hallucinations, power draw, or pizza recipes concern you—along with perhaps broader Google issues involving privacy, tracking, news, SEO, or monopoly power—most of your other major options were brought down by a single API outage this morning. Moving past that kind of single point of vulnerability will take some work, both by the industry and by you, the person wondering if there’s a real alternative.

Search engine market share, as measured by StatCounter, April 2023–April 2024.

Search engine market share, as measured by StatCounter, April 2023–April 2024.

StatCounter

Upward of a billion dollars a year

The overwhelming majority of search tools offering an “alternative” to Google are using Google, Bing, or Yandex, the three major search engines that maintain massive global indexes. Yandex, being based in Russia, is a non-starter for many people around the world at the moment. Bing offers its services widely, most notably to DuckDuckGo, but its ad-based revenue model and privacy particulars have caused some friction there in the past. Before his company was able to block more of Microsoft’s own tracking scripts, DuckDuckGo CEO and founder Gabriel Weinberg explained in a Reddit reply why firms like his weren’t going the full DIY route:

… [W]e source most of our traditional links and images privately from Bing … Really only two companies (Google and Microsoft) have a high-quality global web link index (because I believe it costs upwards of a billion dollars a year to do), and so literally every other global search engine needs to bootstrap with one or both of them to provide a mainstream search product. The same is true for maps btw — only the biggest companies can similarly afford to put satellites up and send ground cars to take streetview pictures of every neighborhood.

Bing makes Microsoft money, if not quite profit yet. It’s in Microsoft’s interest to keep its search index stocked and API open, even if its focus is almost entirely on its own AI chatbot version of Bing. Yet if Microsoft decided to pull API access, or it became unreliable, Google’s default position gets even stronger. What would non-conformists have to choose from then?

Bing outage shows just how little competition Google search really has Read More »

after-you-die,-your-steam-games-will-be-stuck-in-legal-limbo

After you die, your Steam games will be stuck in legal limbo

Pushing digital daisies —

So much for your descendants posthumously clearing out that massive backlog…

But... but I was just about to check out <em>Tacoma</em>.” src=”https://cdn.arstechnica.net/wp-content/uploads/2024/05/GettyImages-485865905-800×533.jpg”></img><figcaption>
<p><a data-height=Enlarge / But… but I was just about to check out Tacoma.

Getty Images

With Valve’s Steam gaming platform approaching the US drinking age this year, more and more aging PC gamers may be considering what will happen to their vast digital game libraries after they die. Unfortunately, legally, your collection of hundreds of backlogged games will likely pass into the ether along with you someday.

The issue of digital game inheritability gained renewed attention this week as a ResetEra poster quoted a Steam support response asking about transferring Steam account ownership via a last will and testament. “Unfortunately, Steam accounts and games are non-transferable” the response reads. “Steam Support can’t provide someone else with access to the account or merge its contents with another account. I regret to inform you that your Steam account cannot be transferred via a will.”

This isn’t the first time someone has asked this basic estate planning question, of course. Last year, a Steam forum user quoted a similar response from Steam support as saying, “Your account is yours and yours alone. Now you can share it with family members, but you cannot give it away.”

Potential loopholes

As a practical matter, Steam would have little way of knowing if you wrote down your Steam username and password and left instructions for your estate to give that information to your descendants. When it comes to legal ownership of that account, though, the Steam Subscriber Agreement seems relatively clear.

“You may not reveal, share, or otherwise allow others to use your password or Account except as otherwise specifically authorized by Valve,” the agreement reads, in part. “You may… not sell or charge others for the right to use your Account, or otherwise transfer your Account, nor may you sell, charge others for the right to use, or transfer any Subscriptions other than if and as expressly permitted by this Agreement… or as otherwise specifically permitted by Valve.”

Eagle-eyed readers might notice a potential loophole, though, in the clauses regarding account transfers that are “specifically permitted by Valve.” Steam forum users have suggested in the past that Valve “wouldn’t block this change of ownership” via a will if a user or their estate specifically requests it (Valve has not responded to a request for comment).

Donating all those 3DS and Wii U games to someone else might be difficult for Jirard “The Completionist” Khalil.

There also might be a partial, physical workaround for Steam users who bequeath an actual computer with downloaded titles installed. In a 2013 Santa Clara High Technology Law Journal article, author Claudine Wong writes that “digital content is transferable to a deceased user’s survivors if legal copies of that content are located on physical devices, such as iPods or Kindle e-readers.” But if that descendant wanted to download those games to a different device or reinstall them in the case of a hard drive failure, they’d legally be out of luck.

Beyond personal estate planning, the inability to transfer digital game licenses has some implications for video game preservation work as well. Last year, Jirard “The Completionist” Khalil spent nearly $20,000 to purchase and download every digital 3DS and Wii U game while they were still available. And while Khalil said he intends to donate the physical machines (and their downloads) to the Video Game History Foundation, subscriber agreements mean the charity may have trouble taking legal ownership of those digital games and accounts.

“There is no reasonable, legal path for the preservation of digital-born video games,” VGHF’s then co-director Kelsey Lewin told Ars last year. “Limiting library access only to physical games might have worked 20 years ago, but we no longer live in a world where all games are sold on physical media, and we haven’t for a long time.”

After you die, your Steam games will be stuck in legal limbo Read More »

the-rog-ally-x-leaks,-with-twice-the-battery-of-the-original-and-way-more-ram

The ROG Ally X leaks, with twice the battery of the original and way more RAM

Handheld gaming PCs —

This handheld has more RAM than my gaming PC, though the chip stays the same.

Heavily altered image of a ROG Ally X, with

Enlarge / VideoCardz’ leaked image of a ROG Ally X, seemingly having gone through the JPG blender a couple times.

Asus’ ROG Ally was the first major-brand attempt to compete with Valve’s Steam Deck. It was beefy and interesting, but it had three major flaws: It ran Windows on a little touchscreen, had unremarkable ergonomics, and its battery life was painful.

The Asus ROG (Republic of Gamers) Ally X, which has been announced and is due out June 2, seems to have had its specs leaked, and they indicate a fix for at least the battery life. Gaming site VideoCardz, starting its leak reveal with “No more rumors,” cites the ROG Ally X as having the same Ryzen Z1 Extreme APU as the prior ROG Ally, as well as the same 7-inch 1080p VRR screen with a 120 Hz refresh rate.

VideoCardz' leaked image, seemingly from Asus marketing materials, with the ROG Ally X's specifications.

VideoCardz’ leaked image, seemingly from Asus marketing materials, with the ROG Ally X’s specifications.

The battery and memory have changed substantially, though. An 80-watt-hour battery, up from 40, somehow adds just 70 grams of weight and about 5 mm of thickness to the sequel device. By increasing the RAM from 16GB to 24GB and making it LPDDR5, the ROG Ally X may be able to lend more of it to the GPU, upping performance somewhat without demanding a new chip or architecture. There is also a second USB-C port, with USB4 speeds, that should help quite a bit with docking, charging while playing with accessories, and, I would guess, Linux hackery.

How does it feel? Only Sean Hollister at The Verge knows, outside of ASUS employees. The sequel has lost the weirdly sharp angles on the back, and more of your hand fits around the back, without the rear buttons being accidentally triggered so easily. The triggers and buttons all seem to have received some feedback-based upgrades to durability and feel.

If Asus sticks close to the $800 price point (that was also leaked), it could compete with the Steam Deck OLED on features and flash, if not library and polish. But as I’ve said before, perhaps somewhat defensively, bring on the flashier handheld PCs.

Expanding the viability of handheld PC gaming means more developers targeting these systems, in specs or just accessibility. More demand for new types of handhelds makes the whole field more interesting and competitive. Microsoft, which is keenly aware of this developing market and is contemplating a more cloud-based and less Xbox-centered gaming future, can only make Windows better on handhelds because the bar is pretty low right now.

All of that gives me more games to play on the couch while the rice is cooking, whether or not the device I’m holding has more and faster RAM and better USB-C ports than my gaming PC.

The ROG Ally X leaks, with twice the battery of the original and way more RAM Read More »

rocket-report:-spacex-focused-on-starship-reentry;-firefly-may-be-for-sale

Rocket Report: SpaceX focused on Starship reentry; Firefly may be for sale

Fiery news —

“Teams are in the process of completing a follow-on propulsion system assessment.”

A Falcon 9 rocket launches the NROL-146 mission from California this week.

Enlarge / A Falcon 9 rocket launches the NROL-146 mission from California this week.

SpaceX

Welcome to Edition 6.45 of the Rocket Report! The most interesting news in launch this week, to me, is that Firefly is potentially up for sale. That makes two of the handful of US companies with operational rockets, Firefly and United Launch Alliance, actively on offer. I’ll be fascinated to see what the valuations of each end up being if/when sales go through.

As always, we welcome reader submissions, and if you don’t want to miss an issue, please subscribe using the box below (the form will not appear on AMP-enabled versions of the site). Each report will include information on small-, medium-, and heavy-lift rockets as well as a quick look ahead at the next three launches on the calendar.

Firefly may be up for sale. Firefly Aerospace investors are considering a sale that could value the closely held rocket and Moon lander maker at about $1.5 billion, Bloomberg reports. The rocket company’s primary owner, AE Industrial Partners, is working with an adviser on “strategic options” for Firefly. Neither AE nor Firefly commented to Bloomberg about the potential sale. AE invested $75 million into Texas-based Firefly as part of a series B financing round in 2022. The firm made a subsequent investment in its Series C round in November 2023.

Launches and landers … Now more than a decade old and with a history of financial struggles, Firefly has emerged as one of the apparent winners in the small launch race in the United States. The company’s Alpha rocket has now launched four times since its unsuccessful debut in September 2021, and it is due to fly a Venture Class Launch Services 2 mission for NASA in the coming weeks. Firefly also aims to launch its Blue Ghost spacecraft to the moon later this year and is working on an orbital transfer vehicle.

Blue Origin makes successful return to flight. With retired Air Force captain and test pilot Ed Dwight as the headline passenger, Blue Origin’s New Shepard spacecraft returned to flight on Sunday morning. An African American, Dwight was one of 26 pilots the Air Force recommended to NASA for the third class of astronauts in 1963, but the agency didn’t select him. It took another 20 years for America’s first Black astronaut, Guion Bluford, to fly in space in 1983. At the age of 90, Dwight finally entered the record books Sunday, becoming the oldest person to reach space. “I thought I didn’t need it in my life,” Dwight said after Sunday’s fight. “But I lied!”

One chute down … This was the seventh time Blue Origin, the space company owned by billionaire Jeff Bezos, has flown people to suborbital space, and the 25th flight overall of the company’s fleet of New Shepard rockets. It was the first time Blue Origin had launched people in nearly two years, resuming suborbital service after a rocket failure on an uncrewed research flight in September 2022. In December, Blue Origin launched another uncrewed suborbital research mission to set the stage for the resumption of human missions Sunday. There was one issue with the flight, as only two of the capsule’s three parachutes deployed. It’s unclear how long it will take to address this problem.

The easiest way to keep up with Eric Berger’s space reporting is to sign up for his newsletter, we’ll collect his stories in your inbox.

RFA tests first stage of its rocket. German launch startup Rocket Factory Augsburg announced Sunday that it had begun the hot-fire campaign for the first stage of its RFA One rocket. “We hot-fired a total of four Helix engines, igniting one by one at four-second intervals,” the company said on the social media site X. “All engines ran simultaneously for 8 seconds with a total hot-fire duration of 20 seconds. The test ran flawlessly through start-up, steady-state, and shutdown.” It’s a great step forward for the launch company.

Targeting a test flight this year, but … The test occurred at the SaxaVord Spaceport in the United Kingdom. The RFA One vehicle is powered by nine Helix engines and will have a payload capacity of 1.6 metric tons to low-Earth orbit. The company is targeting a debut launch later this year, but I’m fairly skeptical of that. By way of comparison, SpaceX began test firing its Falcon 9 first stage in 2008, with a full-duration test firing of all nine engines in November of that year. But the rocket did not make its debut flight until June 2010.

China expanding commercial spaceport. China is planning new phases of expansion for its new commercial spaceport to support an expected surge in launch and commercial space activity, Space News reports. Construction of the second of two launch pads at Hainan Commercial Launch Site could be completed by the end of May. The first, completed in December and dedicated to the Long March 8 rocket, could host its first launch before the end of June.

Fulfilling a mega-need … However this appears to be just the beginning, as the spaceport could have a total of 10 pads serving both liquid and solid rockets. The reason for the dramatic expansion appears to be increasing access to space and allowing China to achieve a launch rate needed to build a pair of low-Earth orbit megaconstellations, each over 10,000 satellites strong. It is also a further sign of China’s commitment to establishing a thriving commercial space sector. (submitted by Ken the Bin)

Rocket Report: SpaceX focused on Starship reentry; Firefly may be for sale Read More »