Policy

x-can’t-stop-spread-of-explicit,-fake-ai-taylor-swift-images

X can’t stop spread of explicit, fake AI Taylor Swift images

Escalating the situation —

Will Swifties’ war on AI fakes spark a deepfake porn reckoning?

X can’t stop spread of explicit, fake AI Taylor Swift images

Explicit, fake AI-generated images sexualizing Taylor Swift began circulating online this week, quickly sparking mass outrage that may finally force a mainstream reckoning with harms caused by spreading non-consensual deepfake pornography.

A wide variety of deepfakes targeting Swift began spreading on X, the platform formerly known as Twitter, yesterday.

Ars found that some posts have been removed, while others remain online, as of this writing. One X post was viewed more than 45 million times over approximately 17 hours before it was removed, The Verge reported. Seemingly fueling more spread, X promoted these posts under the trending topic “Taylor Swift AI” in some regions, The Verge reported.

The Verge noted that since these images started spreading, “a deluge of new graphic fakes have since appeared.” According to Fast Company, these harmful images were posted on X but soon spread to other platforms, including Reddit, Facebook, and Instagram. Some platforms, like X, ban sharing of AI-generated images but seem to struggle with detecting banned content before it becomes widely viewed.

Ars’ AI reporter Benj Edwards warned in 2022 that AI image-generation technology was rapidly advancing, making it easy to train an AI model on just a handful of photos before it could be used to create fake but convincing images of that person in infinite quantities. That is seemingly what happened to Swift, and it’s currently unknown how many different non-consensual deepfakes have been generated or how widely those images have spread.

It’s also unknown what consequences have resulted from spreading the images. At least one verified X user had their account suspended after sharing fake images of Swift, The Verge reported, but Ars reviewed posts on X from Swift fans targeting others who allegedly shared images whose accounts remain active. Swift fans also have been uploading countless favorite photos of Swift to bury the harmful images and prevent them from appearing in various X searches. Her fans seem dedicated to reducing the spread however they can, with some posting different addresses, seemingly in attempts to dox an X user who, they’ve alleged, is the initial source of the images.

Neither X nor Swift’s team has yet commented on the deepfakes, but it seems clear that solving the problem will require more than just requesting removals from social media platforms. The AI model trained on Swift’s images is likely still out there, likely procured through one of the known websites that specialize in making fine-tuned celebrity AI models. As long as the model exists, anyone with access could crank out as many new images as they wanted, making it hard for even someone with Swift’s resources to make the problem go away for good.

In that way, Swift’s predicament might raise awareness of why creating and sharing non-consensual deepfake pornography is harmful, perhaps moving the culture away from persistent notions that nobody is harmed by non-consensual AI-generated fakes.

Swift’s plight could also inspire regulators to act faster to combat non-consensual deepfake porn. Last year, she inspired a Senate hearing after a Live Nation scandal frustrated her fans, triggering lawmakers’ antitrust concerns about the leading ticket seller, The New York Times reported.

Some lawmakers are already working to combat deepfake porn. Congressman Joe Morelle (D-NY) proposed a law criminalizing deepfake porn earlier this year after teen boys at a New Jersey high school used AI image generators to create and share non-consensual fake nude images of female classmates. Under that proposed law, anyone sharing deepfake pornography without an individual’s consent risks fines and being imprisoned for up to two years. Damages could go as high as $150,000 and imprisonment for as long as 10 years if sharing the images facilitates violence or impacts the proceedings of a government agency.

Elsewhere, the UK’s Online Safety Act restricts any illegal content from being shared on platforms, including deepfake pornography. It requires moderation, or companies will risk fines worth more than $20 million, or 10 percent of their global annual turnover, whichever amount is higher.

The UK law, however, is controversial because it requires companies to scan private messages for illegal content. That makes it practically impossible for platforms to provide end-to-end encryption, which the American Civil Liberties Union has described as vital for user privacy and security.

As regulators tangle with legal questions and social media users with moral ones, some AI image generators have moved to limit models from producing NSFW outputs. Some did this by removing some of the large quantity of sexualized images in the models’ training data, such as Stability AI, the company behind Stable Diffusion. Others, like Microsoft’s Bing image creator, make it easy for users to report NSFW outputs.

But so far, keeping up with reports of deepfake porn seems to fall squarely on social media platforms’ shoulders. Swift’s battle this week shows how unprepared even the biggest platforms currently are to handle blitzes of harmful images seemingly uploaded faster than they can be removed.

X can’t stop spread of explicit, fake AI Taylor Swift images Read More »

amazon-ring-stops-letting-police-request-footage-in-neighbors-app-after-outcry

Amazon Ring stops letting police request footage in Neighbors app after outcry

Neighborhood watch —

Warrantless access may still be granted during vaguely defined “emergencies.”

Amazon Ring stops letting police request footage in Neighbors app after outcry

Amazon Ring has shut down a controversial feature in its community safety app Neighbors that has allowed police to contact homeowners and request doorbell and surveillance camera footage without a warrant for years.

In a blog, head of the Neighbors app Eric Kuhn confirmed that “public safety agencies like fire and police departments can still use the Neighbors app to share helpful safety tips, updates, and community events,” but the Request for Assistance (RFA) tool will be disabled.

“They will no longer be able to use the RFA tool to request and receive video in the app,” Kuhn wrote.

Kuhn did not explain why Neighbors chose to “sunset” the RFA tool, but privacy advocates and lawmakers have long criticized Ring for helping to expand police surveillance in communities, seemingly threatening privacy and enabling racial profiling, CNBC reported. Among the staunchest critics of Ring’s seemingly tight relationship with law enforcement is the Electronic Frontier Foundation (EFF), which has long advocated for Ring and its users to stop sharing footage with police without a warrant.

In a statement provided to Ars, EFF senior policy analyst Matthew Guariglia noted that Ring had launched the RFA tool after EFF and other organizations had criticized Ring for allowing police to privately email warrantless requests for footage in the Neighbors app. Rather than end requests through the app entirely, Ring appeared to see the RFA tool as a middle ground, providing transparency about how many requests were being made, without ending police access to community members readily sharing footage on the app.

“Now, Ring hopefully will altogether be out of the business of platforming casual and warrantless police requests for footage to its users,” Guariglia said.

Moving forward, police and public safety agencies with warrants will still be able to request footage, which Amazon documents in transparency reports published every six months. These reports show thousands of search warrant requests and even more “preservation requests,” which allow government agencies to request to preserve user information for up to 90 days, “pending the receipt of a legally valid and binding order.”

“If we are legally required to comply, we will provide information responsive to the government demand,” Ring’s website says.

Ring rebrand embraces “hope and joy”

Guariglia said that Ring sunsetting the RFA tool “is a step in the right direction,” but it has “come after years of cozy relationships with police and irresponsible handling of data” that has, for many, damaged trust in Ring.

In 2022, EFF reported that Ring admitted that “there are ’emergency’ instances when police can get warrantless access to Ring personal devices without the owner’s permission.” And last year, Ring reached a $5.8 million settlement with the Federal Trade Commission, refunding customers for what the FTC described as “compromising its customers’ privacy by allowing any employee or contractor to access consumers’ private videos and by failing to implement basic privacy and security protections, enabling hackers to take control of consumers’ accounts, cameras, and videos.”

Because of this history, Guariglia said that EFF is “still deeply skeptical about law enforcement’s and Ring’s ability to determine what is, or is not, an emergency that requires the company to hand over footage without a warrant or user consent.”

EFF recommends additional steps that Ring could take to enhance user privacy, like enabling end-to-end encryption by default and turning off default audio collection, Guariglia said.

Bloomberg noted that this change to the Neighbors app comes after a new CEO, Liz Hamren, came on board, announcing that last year “Ring was rethinking its mission statement.” Because Ring was adding indoor and backyard home monitoring and business services, the company’s initial mission statement—”to reduce crime in neighborhoods”—was no longer, as founding Ring CEO Jamie Siminoff had promoted it, “at the core” of what Ring does.

In Kuhn’s blog, barely any attention is given to ending the RFA tool. A Ring spokesperson declined to tell Ars how many users had volunteered to use the tool, so it remains unclear how popular it was.

Rather than clarifying the RFA tool controversy, Kuhn’s blog primarily focused on describing how much Ring users loved “heartwarming or silly” footage like a “bear relaxing in a pool.” Under Hamren and Kuhn’s guidance, it appears that the Neighbors app is embracing a new mission of connecting communities to find “hope and joy” in their areas by adding new features to Neighbors like Moments and Best of Ring.

By contrast, when Ring introduced the RFA tool, it said that its mission was “to make neighborhoods safer for everyone.” On a help page, Ring bragged that police had used Neighbors to recover stolen guns and medical supplies. Because of these selling points, Ring’s community safety features may still be priorities for some users. So, while Ring may be ready to move on from highlighting its partnership with law enforcement as a “core” part of its service, its users may still be used to seeing their cameras as tools that should be readily accessible to police.

As law enforcement agencies lose access to Neighbors’ RFA tool, Guariglia said that it’s important to raise awareness among Ring owners that police can’t demand access to footage without a warrant.

“This announcement will not stop police from trying to get Ring footage directly from device owners without a warrant,” Guariglia said. “Ring users should also know that when police knock on their door, they have the right to, and should, request that police get a warrant before handing over footage.”

Amazon Ring stops letting police request footage in Neighbors app after outcry Read More »

ebay-lays-off-1,000-employees,-about-9-percent-of-full-time-workforce

eBay lays off 1,000 employees, about 9 percent of full-time workforce

eBay layoffs —

Cutting 1,000 jobs, eBay says “headcount and expenses have outpaced” growth.

A large eBay logo on a sign near the company headquarters building.

Getty Images | Justin Sullivan

eBay is laying off approximately 1,000 employees in a move that reduces its full-time workforce by 9 percent, the company announced yesterday. eBay also plans “to scale back the number of contracts we have within our alternate workforce over the coming months,” CEO Jamie Iannone wrote in a message to staff that was titled, “Ensuring eBay’s Long-Term Success.”

Iannone cited “the challenging macroeconomic environment” and said that eBay has too many employees. “While we are making progress against our strategy, our overall headcount and expenses have outpaced the growth of our business,” he wrote.

eBay asked all US-based employees to work from home on Wednesday “to provide some space and privacy” for conversations in which laid-off employees were to be given the bad news. The 1,000 layoffs come nearly one year after eBay eliminated 500 employees.

eBay reported $2.5 billion of revenue in its most recent quarterly earnings, for Q3 2023, a rise of 5 percent year over year. Q3 2023 net income was $1.3 billion, whereas the company had reported a net loss of $70 million in Q3 2022. eBay’s Q3 operating income was $455 million, down from $568 million the previous year.

eBay exceeded earnings expectations

eBay also said it “returned $783 million to shareholders in Q3, including $651 million of share repurchases and $132 million paid in cash dividends.” eBay’s stock price was up 0.48 percent today but has fallen about 5 percent this month.

“In Q3, we met or exceeded expectations across all of our key financial metrics,” eBay Chief Financial Officer Steve Priest said at the time. “Our strong balance sheet and operational rigor enable us to adapt to the evolving changes in this dynamic macro environment. We will continue to be prudent with cost efficiencies, saving to invest for the future, while remaining good stewards of capital for our shareholders.”

Even though eBay beat earnings estimates in Q3, The Wall Street Journal pointed out some challenges facing the company going forward. “The company has been under pressure amid rising competition from the likes of Amazon.com and Walmart, as well as from emerging Chinese retailers such as Temu and Shein,” the WSJ wrote. “High interest rates and sticky inflation in the US and other major economies have also weighed on consumers’ discretionary spending.”

eBay’s layoff announcement is the latest in a string of job cuts in the tech industry. Amazon this month announced layoffs of 500 employees at Twitch and several hundred more at its MGM and Prime Video divisions. Google announced layoffs of 100 employees at YouTube after previously laying off hundreds of workers in several other divisions.

eBay lays off 1,000 employees, about 9 percent of full-time workforce Read More »

mugger-take-your-phone?-cash-apps-too-easily-let-thieves-drain-accounts,-da-says

Mugger take your phone? Cash apps too easily let thieves drain accounts, DA says

Mugger take your phone? Cash apps too easily let thieves drain accounts, DA says

Popular apps like Venmo, Zelle, and Cash App aren’t doing enough to protect consumers from fraud that occurs when unauthorized users gain access to unlocked devices, Manhattan District Attorney Alvin Bragg warned.

“Thousands or even tens of thousands can be drained from financial accounts in a matter of seconds with just a few taps,” Bragg said in letters to app makers. “Without additional protections, customers’ financial and physical safety is being put at risk.”

According to Bragg, his office and the New York Police Department have been increasingly prosecuting crimes where phones are commandeered by bad actors to quickly steal large amounts of money through financial apps.

This can happen to unwitting victims when fraudsters ask “to use an individual’s smartphone for personal use” or to transfer funds to initiate a donation for a specific cause. Or “in the most disturbing cases,” Bragg said, “offenders have violently assaulted or drugged victims, and either compelled them to provide a password for a device or used biometric ID to open the victim’s phone before transferring money once the individual is incapacitated.”

But prosecuting crimes alone won’t solve this problem, Bragg suggested. Prevention is necessary. That’s why the DA is requesting meetings with executives managing widely used financial apps to discuss “commonsense” security measures that Bragg said can be taken to “combat this growing concern.”

Bragg appears particularly interested in Apple’s recently developed “Stolen Device Protection,” which he said is “making it harder for perpetrators to use a phone’s passcode to steal funds when the user’s phone is not at home or at work.”

Apple just rolled out “Stolen Device Protection” for iOS 17.3. On its website, Apple explained that when “Stolen Device Protection” is enabled, “some features and actions have additional security requirements when your iPhone is away from familiar locations such as home or work.”

For users taking advantage of this enhanced security layer, biometric or FaceID would be required to access devices, with no option to bypass with a passcode. This alone could help deter crimes that Bragg described, potentially stopping thieves from rifling through someone’s passwords to get instant access to a cash app. “Stolen Device Protection” also sets up a security delay that could stop thieves from immediately changing the account password and locking an owner out of their device. To change a password in this more secure mode, thieves would need to wait one hour—perhaps giving time for the owner to report that the phone is stolen or missing—and then must provide a biometric or FaceID.

Bragg wants financial apps like Zelle or Venmo to follow Apple’s lead and build similar safeguards. He suggested that Apple’s release makes it clear that the technology exists where apps could detect when a user is attempting to send a large transaction from an unknown location and perhaps block or delay sending that transaction for up to a day without secondary verification. This could afford victims more time to discover and cancel fraudulent transfers before they go through, instead of after the theft, when it’s usually harder to claw back funds.

This problem goes well beyond Manhattan, Bragg wrote, pointing to “similar thefts and robberies” that have been “publicly reported” in major cities like Los Angeles and Orlando, as well as in West Virginia, Louisiana, Illinois, Kansas, Tennessee, Virginia, and “elsewhere across the United States.”

Overall, the DA traced a pattern showing that the more people were using financial apps, the more fraud claims spiked, “tripling between 2020 and 2022” and “costing consumers hundreds of millions of dollars each year.”

“While cash apps, like Cash App, offer consumers an easy and fast method to transfer funds, they also have made these platforms a favorite of fraudsters because consumers have no option to cancel transactions, even moments after authorizing them,” Bragg wrote to Cash App CEO Brian Grassadonia. “I am concerned about the troubling rise in illegal behavior that has developed because of insufficient security measures connected with your software and business policy decisions.”

While building tech like Apple’s “Stolen Device Protection” seems to be the most extreme step that Bragg recommended, he also pushed “commonsense solutions” that he claimed that financial apps currently overlook. These include steps like requiring multifactor authentication to help keep thieves locked out and lowering limits on daily transfers to make the scam less appealing to thieves looking for a big payday.

Mugger take your phone? Cash apps too easily let thieves drain accounts, DA says Read More »

patreon:-blocking-platforms-from-sharing-user-video-data-is-unconstitutional

Patreon: Blocking platforms from sharing user video data is unconstitutional

Patreon: Blocking platforms from sharing user video data is unconstitutional

Patreon, a monetization platform for content creators, has asked a federal judge to deem unconstitutional a rarely invoked law that some privacy advocates consider one of the nation’s “strongest protections of consumer privacy against a specific form of data collection.” Such a ruling would end decades that the US spent carefully shielding the privacy of millions of Americans’ personal video viewing habits.

The Video Privacy Protection Act (VPPA) blocks businesses from sharing data with third parties on customers’ video purchases and rentals. At a minimum, the VPPA requires written consent each time a business wants to share this sensitive video data—including the title, description, and, in most cases, the subject matter.

The VPPA was passed in 1988 in response to backlash over a reporter sharing the video store rental history of a judge, Robert Bork, who had been nominated to the Supreme Court by Ronald Reagan. The report revealed that Bork apparently liked spy thrillers and British costume dramas and suggested that maybe the judge had a family member who dug John Hughes movies.

Although the videos that Bork rented “revealed nothing particularly salacious” about the judge, the intent of reporting the “Bork Tapes” was to confront the judge “with his own vulnerability to privacy harms” during a time when the Supreme Court nominee had “criticized the constitutional right to privacy” as “a loose canon in the law,” Harvard Law Review noted.

Even though no harm was caused by sharing the “Bork Tapes,” policymakers on both sides of the aisle agreed that First Amendment protections ought to safeguard the privacy of people’s viewing habits, or else risk chilling their speech by altering their viewing habits. The US government has not budged on this stance since, supporting a lawsuit filed in 2022 by Patreon users who claimed that while no harms were caused, damages are owed after Patreon allegedly violated the VPPA by sharing data on videos they watched on the platform with Facebook through Meta Pixel without users’ written consent.

“Restricting the ability of those who possess a consumer’s video purchase, rental, or request history to disclose such information directly advances the goal of keeping that information private and protecting consumers’ intellectual freedom,” the Department of Justice’s brief said.

The Meta Pixel is a piece of code used by companies like Patreon to better target content to users by tracking their activity and monitoring conversions on Meta platforms. “In simplest terms,” Patreon users said in an amended complaint, “the Pixel allows Meta to know what video content one of its users viewed on Patreon’s website.”

The Pixel is currently at the center of a pile of privacy lawsuits, where people have accused various platforms of using the Pixel to covertly share sensitive data without users’ consent, including health and financial data.

Several lawsuits have specifically lobbed VPPA claims, which users have argued validates the urgency of retaining the VPPA protections that Patreon now seeks to strike. The DOJ argued that “the explosion of recent VPPA cases” is proof “that the disclosures the statute seeks to prevent are a legitimate concern,” despite Patreon’s arguments that the statute does “nothing to materially or directly advance the privacy interests it supposedly was enacted to protect.”

Patreon’s attack on the VPPA

Patreon has argued in a recent court filing that the VPPA was not enacted to protect average video viewers from embarrassing and unwarranted disclosures but “for the express purpose of silencing disclosures about political figures and their video-watching, an issue of undisputed continuing public interest and concern.”

That’s one of many ways that the VPPA silences speech, Patreon argued, by allegedly preventing disclosures regarding public figures that are relevant to public interest.

Among other “fatal flaws,” Patreon alleged, the VPPA “restrains speech” while “doing little if anything to protect privacy” and never protecting privacy “by the least restrictive means.”

Patreon claimed that the VPPA is too narrow, focusing only on pre-recorded videos. It prevents video service providers from disclosing to any other person the titles of videos that someone watched, but it does not necessarily stop platforms from sharing information about “the genres, performers, directors, political views, sexual content, and every other detail of pre-recorded video that those consumers watch,” Patreon claimed.

Patreon: Blocking platforms from sharing user video data is unconstitutional Read More »

robocall-with-artificial-joe-biden-voice-tells-democrats-not-to-vote

Robocall with artificial Joe Biden voice tells Democrats not to vote

A bunch of malarkey —

Fake Biden voice urges New Hampshire Democrats to skip tomorrow’s primary.

Joe Biden holds a cell phone to his ear while having a conversation.

Enlarge / President Joe Biden at a Rose Garden event at the White House on May 1, 2023, in Washington, DC.

Getty Images | Alex Wong

An anti-voting robocall that seems to use an artificially generated version of President Joe Biden’s voice is being investigated by the New Hampshire Attorney General’s office. The calls sent on Sunday told Democrats to avoid voting in the Presidential Primary on January 23.

“Although the voice in the robocall sounds like the voice of President Biden, this message appears to be artificially generated based on initial indications,” the state AG’s office said in an announcement today. The recorded message appears “to be an unlawful attempt to disrupt the New Hampshire Presidential Primary Election and to suppress New Hampshire voters,” the announcement said.

The “Biden” voice in the recording (available with this NBC News article) sounds a bit off but perhaps could fool some people into thinking it came from the president.

“What a bunch of malarkey,” the voice says. “You know the value of voting Democratic when our votes count. It’s important that you save your vote for the November election. We’ll need your help in electing Democrats up and down the ticket. Voting this Tuesday only enables the Republicans in their quest to elect Donald Trump again. Your vote makes a difference in November, not this Tuesday.”

NBC News reported that a spokesperson for the Trump campaign said it had no connection to the fake Biden call. “Not us, we have nothing to do with it,” the spokesperson said.

Spoofed Caller ID

The apparently spoofed Caller ID displayed the personal cell phone number of “a prominent New Hampshire Democrat,” NBC News wrote. Biden’s national campaign manager, Julie Chavez Rodriguez, said the “campaign is actively discussing additional actions to take immediately,” according to NBC News.

Biden isn’t officially on the ballot in New Hampshire this week because of a dispute over scheduling between New Hampshire Democrats and the Democratic National Committee. But there’s a write-in campaign supporting Biden in the Democratic primary, and a spokesperson for the write-in campaign described the robocall as “deepfake disinformation designed to harm Joe Biden, suppress votes, and damage our democracy.”

The New Hampshire AG’s office said the fake Biden call “appears to have been ‘spoofed’ to falsely show that it had been sent by the treasurer of a political committee that has been supporting the New Hampshire Democratic Presidential Primary write-in efforts for President Biden. The message’s content directed recipients who wished to be removed from a calling list to call the number belonging to this person.”

The AG’s office pointed out that no law prevents someone from voting in both January and November. “Voting in the New Hampshire Presidential Primary Election does not preclude a voter from additionally voting in the November General Election,” the AG’s office said.

Robocall with artificial Joe Biden voice tells Democrats not to vote Read More »

meta-relents-to-eu,-allows-unlinking-of-facebook-and-instagram-accounts

Meta relents to EU, allows unlinking of Facebook and Instagram accounts

Meta relents to EU, allows unlinking of Facebook and Instagram accounts

Meta will allow some Facebook and Instagram users to unlink their accounts as part of the platform’s efforts to comply with the European Union’s Digital Markets Act (DMA) ahead of enforcement starting March 1.

In a blog, Meta’s competition and regulatory director, Tim Lamb, wrote that Instagram and Facebook users in the EU, the European Economic Area, and Switzerland would be notified in the “next few weeks” about “more choices about how they can use” Meta’s services and features, including new opportunities to limit data-sharing across apps and services.

Most significantly, users can choose to either keep their accounts linked or “manage their Instagram and Facebook accounts separately so that their information is no longer used across accounts.” Up to this point, linking user accounts had provided Meta with more data to more effectively target ads to more users. The perk of accessing data on Instagram’s widening younger user base, TechCrunch noted, was arguably the $1 billion selling point explaining why Facebook acquired Instagram in 2012.

Also announced today, users protected by the DMA will soon be able to separate their Facebook Messenger, Marketplace, and Gaming accounts. However, doing so will limit some social features available in some of the standalone apps.

While Messenger users choosing to disconnect the chat service from their Facebook accounts will still “be able to use Messenger’s core service offering such as private messaging and chat, voice and video calling,” Marketplace users making that same choice will have to email sellers and buyers, rather than using Facebook’s messenger service. And unlinked Gaming app users will only be able to play single-player games, severing their access to social gaming otherwise supported by linking the Gaming service to their Facebook social networks.

While Meta may have had choices other than depriving users unlinking accounts of some features, Meta didn’t really have a choice in allowing newly announced options to unlink accounts. The DMA specifically requires that very large platforms designated as “gatekeepers” give users the “specific choice” of opting out of sharing personal data across a platform’s different core services or across any separate services that the gatekeepers manage.

Without gaining “specific” consent, gatekeepers will no longer be allowed to “combine personal data from the relevant core platform service with personal data from any further core platform services” or “cross-use personal data from the relevant core platform service in other services provided separately by the gatekeeper,” the DMA says. The “specific” requirement is designed to block platforms from securing consent at sign-up, then hoovering up as much personal data as possible as new services are added in an endless pursuit of advertising growth.

As defined under the General Data Protection Regulation, the EU requiring “specific” consent stops platforms from gaining user consent for broadly defined data processing by instead establishing “the need for granularity,” so that platforms always seek consent for each “specific” data “processing purpose.”

“This is an important ‘safeguard against the gradual widening or blurring of purposes for which data is processed, after a data subject has agreed to the initial collection of the data,’” the European Data Protection Supervisor explained in public comments describing “commercial surveillance and data security practices that harm consumers” provided at the request of the FTC in 2022.

According to Meta’s help page, once users opt out of sharing data between apps and services, Meta will “stop combining your info across these accounts” within 15 days “after you’ve removed them.” However, all “previously combined info would remain combined.”

Meta relents to EU, allows unlinking of Facebook and Instagram accounts Read More »

google-and-at&t-invest-in-starlink-rival-for-satellite-to-smartphone-service

Google and AT&T invest in Starlink rival for satellite-to-smartphone service

Satellite for smartphones —

AST SpaceMobile gets $206.5 million and is partnering with Google and AT&T.

Illustration of a large, square satellite orbiting the Earth.

Enlarge / Illustration of AST SpaceMobile’s cellular satellite.

AST SpaceMobile

Google, AT&T, and Vodafone are investing $206.5 million in AST SpaceMobile, a Starlink competitor that plans to offer smartphone service from low-Earth-orbit satellites.

This is the first investment in AST SpaceMobile from Google and AT&T, while Vodafone had already put money into the satellite company. AST SpaceMobile announced the funding in a press release on Thursday and announced a $100 million public offering of its stock on the same day.

“Vodafone and AT&T have placed purchase orders for network equipment from AST SpaceMobile to support planned commercial service,” the satellite company said. Google has meanwhile “agreed to collaborate on product development, testing, and implementation plans for SpaceMobile network connectivity on Android and related devices.” AST, which has one very large test satellite in orbit, previously received investments from Rakuten, American Tower, and Bell Canada.

SpaceX subsidiary Starlink has deals with T-Mobile in the US and several carriers in other countries for satellite-to-smartphone service. T-Mobile is expected to offer Starlink-enabled text messaging this year, with voice and data service beginning sometime in 2025.

Though AT&T hadn’t previously invested in AST SpaceMobile, the companies were already working together. AT&T is leasing spectrum in the 700 MHz and 850 MHz bands to AST SpaceMobile. They plan “to provide mobile broadband to unserved and underserved areas covered by the Leased Spectrum,” the companies told the Federal Communications Commission in an application last year.

AST SpaceMobile's BlueWalker 3 test satellite, which is 693 square feet in size.

Enlarge / AST SpaceMobile’s BlueWalker 3 test satellite, which is 693 square feet in size.

AST SpaceMobile

For hard-to-reach areas

Satellite-to-smartphone technology is generally seen as a supplement to cellular networks in hard-to-reach areas. “Because AST’s technology can focus satellite coverage in discrete portions of licensed areas, it does not need a nationwide swath of terrestrial mobile spectrum that a mobile network operator licensee has left fallow. Rather than displacing terrestrial network facilities nationwide, AST’s coverage will be complementary to AT&T’s extensive terrestrial network coverage,” the companies’ FCC filing said.

In April 2023, the companies announced that they completed the first two-way voice calls using AST SpaceMobile’s test satellite with standard mobile phones. “The first voice call was made from the Midland, Texas area to Rakuten in Japan over AT&T spectrum using a Samsung Galaxy S22 smartphone,” the announcement said.

In September 2023, AST SpaceMobile said it made “the first-ever 5G connection for voice and data between an everyday, unmodified smartphone and a satellite in space” and that it achieved a download rate of 14Mbps.

Five satellites should launch soon

AST SpaceMobile’s prototype satellite launched from a SpaceX rocket in September 2022. AST’s early plans detailed in 2020 called for 243 satellites overall, and its first five satellites for commercial operations are expected to launch by March 31, 2024. AST is manufacturing the satellites at its Texas facilities.

The prototype satellite delivers data over 5 MHz channels. “For the company’s planned operational satellites, beams are designed to support capacity of up to 40 Mhz, potentially enabling data transmission speeds of up to 120Mbps,” the company said.

An AST description of its satellite says it has “a large surface area of phased-array antennas, which work together to electronically form, steer, and shape wireless communication beams into cells of coverage,” similarly to cell towers on the ground. AST says its BlueWalker 3 test satellite is 693 square feet.

AST said it has “over 40 agreements and understandings with mobile network operators globally, who collectively service over 2 billion subscribers.” Besides Vodafone and AT&T, these “agreements and understandings” are with firms including Rakuten Mobile, Bell Canada, Orange, Telefonica, TIM, MTN, Saudi Telecom Company, Zain KSA, Etisalat, Indosat Ooredoo Hutchison, Telkomsel, Smart Communications, Globe Telecom, Millicom, Smartfren, Telecom Argentina, Telstra, Africell, and Liberty Latin America.

While Starlink already has over 5,000 satellites delivering home Internet service and plans to launch tens of thousands more, it isn’t too far ahead of AST SpaceMobile in terms of cellular-enabled satellites. SpaceX launched the first six Starlink satellites that can provide cellular transmissions to standard LTE phones a few weeks ago and demonstrated the technology with text messages sent between T-Mobile phones.

Google and AT&T invest in Starlink rival for satellite-to-smartphone service Read More »

hp-ceo-evokes-james-bond-style-hack-via-ink-cartridges

HP CEO evokes James Bond-style hack via ink cartridges

Office printer with

Last Thursday, HP CEO Enrique Lores addressed the company’s controversial practice of bricking printers when users load them with third-party ink. Speaking to CNBC Television, he said, “We have seen that you can embed viruses in the cartridges. Through the cartridge, [the virus can] go to the printer, [and then] from the printer, go to the network.”

That frightening scenario could help explain why HP, which was hit this month with another lawsuit over its Dynamic Security system, insists on deploying it to printers.

Dynamic Security stops HP printers from functioning if an ink cartridge without an HP chip or HP electronic circuitry is installed. HP has issued firmware updates that block printers with such ink cartridges from printing, leading to the above lawsuit (PDF), which is seeking class-action certification. The suit alleges that HP printer customers were not made aware that printer firmware updates issued in late 2022 and early 2023 could result in printer features not working. The lawsuit seeks monetary damages and an injunction preventing HP from issuing printer updates that block ink cartridges without an HP chip.

But are hacked ink cartridges something we should actually be concerned about?

To investigate, I turned to Ars Technica Senior Security Editor Dan Goodin. He told me that he didn’t know of any attacks actively used in the wild that are capable of using a cartridge to infect a printer.

Goodin also put the question to Mastodon, and cybersecurity professionals, many with expertise in embedded-device hacking, were decidedly skeptical.

Another commenter, going by Graham Sutherland / Polynomial on Mastodon, referred to serial presence detect (SPD) electrically erasable programmable read-only memory (EEPROM), a form of flash memory used extensively in ink cartridges, saying:

I’ve seen and done some truly wacky hardware stuff in my life, including hiding data in SPD EEPROMs on memory DIMMs (and replacing them with microcontrollers for similar shenanigans), so believe me when I say that his claim is wildly implausible even in a lab setting, let alone in the wild, and let alone at any scale that impacts businesses or individuals rather than selected political actors.

HP’s evidence

Unsurprisingly, Lores’ claim comes from HP-backed research. The company’s bug bounty program tasked researchers from Bugcrowd with determining if it’s possible to use an ink cartridge as a cyberthreat. HP argued that ink cartridge microcontroller chips, which are used to communicate with the printer, could be an entryway for attacks.

As detailed in a 2022 article from research firm Actionable Intelligence, a researcher in the program found a way to hack a printer via a third-party ink cartridge. The researcher was reportedly unable to perform the same hack with an HP cartridge.

Shivaun Albright, HP’s chief technologist of print security, said at the time:

A researcher found a vulnerability over the serial interface between the cartridge and the printer. Essentially, they found a buffer overflow. That’s where you have got an interface that you may not have tested or validated well enough, and the hacker was able to overflow into memory beyond the bounds of that particular buffer. And that gives them the ability to inject code into the device.

Albright added that the malware “remained on the printer in memory” after the cartridge was removed.

HP acknowledges that there’s no evidence of such a hack occurring in the wild. Still, because chips used in third-party ink cartridges are reprogrammable (their “code can be modified via a resetting tool right in the field,” according to Actionable Intelligence), they’re less secure, the company says. The chips are said to be programmable so that they can still work in printers after firmware updates.

HP also questions the security of third-party ink companies’ supply chains, especially compared to its own supply chain security, which is ISO/IEC-certified.

So HP did find a theoretical way for cartridges to be hacked, and it’s reasonable for the company to issue a bug bounty to identify such a risk. But its solution for this threat was announced before it showed there could be a threat. HP added ink cartridge security training to its bug bounty program in 2020, and the above research was released in 2022. HP started using Dynamic Security in 2016, ostensibly to solve the problem that it sought to prove exists years later.

Further, there’s a sense from cybersecurity professionals that Ars spoke with that even if such a threat exists, it would take a high level of resources and skills, which are usually reserved for targeting high-profile victims. Realistically, the vast majority of individual consumers and businesses shouldn’t have serious concerns about ink cartridges being used to hack their machines.

HP CEO evokes James Bond-style hack via ink cartridges Read More »

fujitsu-bugs-that-sent-innocent-people-to-prison-were-known-“from-the-start”

Fujitsu bugs that sent innocent people to prison were known “from the start”

British Post Office Scandal —

Software bugs were hidden from lawyers of wrongly convicted UK postal workers.

Paul Patterson, co-CEO of Fujitsu's European division, sits at a table in front of a microphone while testifying for a public inquiry.

Enlarge / Paul Patterson, co-CEO of Fujitsu’s European division, testifies for a public inquiry in London on January 19, 2024.

Getty Images | AFP

Fujitsu software bugs that helped send innocent postal employees to prison in the UK were known “right from the very start of deployment,” a Fujitsu executive told a public inquiry today.

“All the bugs and errors have been known at one level or not, for many, many years. Right from the very start of deployment of the system, there were bugs and errors and defects, which were well-known to all parties,” said Paul Patterson, co-CEO of Fujitsu’s European division.

That goes back to 1999, when the Horizon software system was installed in post offices by Fujitsu subsidiary International Computers Limited. From 1999 to 2015, Fujitsu’s faulty accounting software aided in the prosecution and conviction of more than 900 sub-postmasters and postmistresses who were accused of theft or fraud when the software wrongly made it appear that money was missing from their branches.

Some innocent people went to prison, while others were forced to make payments to the UK Post Office to cover the supposed shortfalls. So far, “only 93 convictions have been overturned and thousands of people are still waiting for compensation settlements,” a BBC report said.

Post Office lawyers rewrote Fujitsu witness statements

During the prosecutions, courts hearing cases against postal employees “were not told of 29 bugs identified as early as 1999 in the system it built,” The Guardian wrote in a summary of Patterson’s testimony today. The article said:

When bugs were acknowledged, witness statements from Fujitsu staff due to be heard in court were then edited by the Post Office as it sought to maintain the line that the system was working well as it pursued innocent people through the courts.

Paul Patterson agreed that both organizations had failed the accused. “I am surprised that that detail was not included in the witness statements given by Fujitsu staff to the Post Office and I have seen some evidence of editing witness statements by others,” he said.

Asked by the lead counsel of the public inquiry, Jason Beer KC, whether he agreed that this was shameful, Patterson, who has worked at the company for 14 years, said: “That would be one word I would use. Shameful and appalling. My understanding of how our laws work in this country, is that all of the evidence should have been put in front of the subpostmasters that the Post Office was relying on to prosecute them.”

A Financial Times article said that the public inquiry “heard in December last year that the Post Office’s lawyers had rewritten Fujitsu witness statements.”

The FT article also said the Post Office, which used prosecution powers available to private corporations in the UK, obtained 700 of the 900 convictions. The other convictions came in cases brought by Scottish prosecutors. The scandal may lead to reforms of the private prosecution system that lets organizations take people to court.

Bugs were understood “way back to 1999”

Earlier this week, Patterson told UK Parliament members that “Fujitsu would like to apologize for our part in this appalling miscarriage of justice. We were involved from the very start. We did have bugs and errors in the system and we did help the Post Office in their prosecutions of the sub-postmasters. For that we are truly sorry.”

Patterson also told Parliament members that Fujitsu has “a moral obligation” to contribute to the compensation for victims.

Patterson testified today in a different setting, answering questions from lawyers representing victims. One of those lawyers, Flora Page, asked Patterson, “Did nobody historically make that pretty obvious connection between very poor code going out into operation and then very poor data coming out and through the litigation support service?”

Patterson answered, “Whether people made that connection or not, what is very evident… is that that connection and understanding about what was going on and where was it, was understood by certainly Fujitsu and certainly understood by Post Office way back to 1999. It’s all about what you do with that information… that is a question for this inquiry.”

Post Office Minister Kevin Hollinrake, the MP for Thirsk and Malton, told the BBC that his “number one priority” is to “try and get compensation and get answers for people.”

“You’ve had marriages fail, people commit suicide, an horrendous impact on people’s lives,” he said. “It’s perfectly reasonable that the public should demand people are held to account and that should mean criminal prosecutions wherever possible.” The UK government also has plans for a new law to “swiftly exonerate and compensate” people who were falsely convicted.

Fujitsu bugs that sent innocent people to prison were known “from the start” Read More »

amazon’s-purchase-of-roomba-maker-irobot-likely-to-be-blocked-by-eu

Amazon’s purchase of Roomba-maker iRobot likely to be blocked by EU

Amazon/iRobot merger —

Amazon was told at meeting that deal is likely to be rejected, WSJ reports.

A store shelf holds several boxes that contain Roomba vacuum cleaners.

Getty Images | SOPA Images

European Union regulators intend to block Amazon’s attempt to purchase Roomba-maker iRobot, The Wall Street Journal reported yesterday.

European Commission competition officials “met Thursday with representatives from Amazon to discuss the deal,” the Journal wrote, citing people familiar with the matter. “Amazon was told during the meeting that the deal was likely to be rejected,” according to one of the Journal’s sources.

Amazon announced the $1.7 billion deal in August 2022. The EC has a February 14 deadline to reach a decision. European officials have said that Amazon could restrict the availability of Roomba rivals on the Amazon online retail store.

A move to block the iRobot purchase “would still need formal approval from the commission’s 27 top political leaders before a final decision can be issued,” the WSJ article said. “Historically, that process is unlikely to overrule a recommendation from the bloc’s competition commissioner, Margrethe Vestager.”

Amazon declined to comment when contacted by Ars today but pointed us toward a statement by lobby group Computer & Communications Industry Association (CCIA). “If the objective is to have more competition in the home robotics sector, this makes no sense,” CCIA President Matt Schruers said. “There is no plausible risk to competition from a US retailer acquiring a struggling US vacuum maker in a sector overtaken by dynamic Chinese manufacturers. Blocking this deal may well leave consumers with fewer options, and regulators cannot sweep that fact under the rug.”

EC told Amazon deal may restrict competition

In November 2023, the EC announced that it had “informed Amazon of its preliminary view that its proposed acquisition of iRobot may restrict competition in the market for robot vacuum cleaners.” The EC sent a statement of objections, a formal step in the process that could lead to a merger being blocked.

“Amazon may have the ability and the incentive to foreclose iRobot’s rivals,” the EC’s November statement said. The regulatory body said that Amazon could punish rival sellers of robot vacuum cleaners (RVCs) on its online store.

Possible Amazon tactics cited by the EC included “delisting rival RVCs; reducing visibility of rival RVCs in both non-paid (i.e., organic) and paid results (i.e., advertisements) displayed in Amazon’s marketplace; limiting access to certain widgets (e.g. ‘other products you may like’) or certain commercially attractive product labels (e.g. ‘Amazon’s choice’ or ‘Works With Alexa’); and/or directly or indirectly raising the costs of iRobot’s rivals to advertise and sell their RVCs on Amazon’s marketplace.”

Last week, Amazon missed a deadline to offer European officials remedies to address their concerns about the deal’s impact on competition.

As of this writing, iRobot’s stock price was down about 27 percent today. Amazon’s stock price was up around 1 percent.

Amazon’s purchase of Roomba-maker iRobot likely to be blocked by EU Read More »