Tech

openwrt,-now-20-years-old,-is-crafting-its-own-future-proof-reference-hardware

OpenWrt, now 20 years old, is crafting its own future-proof reference hardware

It’s time for a new blue box —

There are, as you might expect, a few disagreements about what’s most important.

Linksys WRT54G

Enlarge / Failing an image of the proposed reference hardware by the OpenWrt group, let us gaze upon where this all started: inside a device that tried to quietly use open source software without crediting or releasing it.

Jim Salter

OpenWrt, the open source firmware that sprang from Linksys’ use of open source code in its iconic WRT54G router and subsequent release of its work, is 20 years old this year. To keep the project going, lead developers have proposed creating a “fully upstream supported hardware design,” one that would prevent the need for handling “binary blobs” in modern router hardware and let DIY router enthusiasts forge their own path.

OpenWRT project members, 13 of which signed off on this hardware, are keeping the “OpenWrt One” simple, while including “some nice features we believe all OpenWrt supported platforms should have,” including “almost unbrickable” low-level firmware, an on-board real-time clock with a battery backup, and USB-PD power. The price should be under $100 and the schematics and code publicly available.

But OpenWrt will not be producing or selling these boards, “for a ton of reasons.” The group is looking to the Banana Pi makers to distribute a fitting device, with every device producing a donation to the Software Freedom Conservancy earmarked for OpenWrt. That money could then be used for hosting expenses, or “maybe an OpenWrt summit.”

OpenWrt tries to answer some questions about its designs. There are two flash chips on the board to allow for both a main loader and a write-protected recovery. There’s no USB 3.0 because all the USB and PCIe buses are shared on the board. And there’s such an emphasis on a battery-backed RTC because “we believe there are many things a Wi-Fi … device should have on-board by default.”

But members of the site have more questions, some of them beyond the scope of what OpenWrt is promising. Some want to see a device that resembles the blue boxes of old, with four or five Ethernet ports built in. Others are asking about a lack of PoE support, or USB 3.0 for network-attached drives. Some are actually wondering why the proposed device includes NVMe storage. And quite a few are asking why the device has 1Gbps and 2.5Gbps ports, given that this means anyone with Internet faster than 1Gbps will be throttled, since the 2.5 port will likely be used for wireless output.

There is no expected release date, though it’s noted that it’s the “first” community-driven reference hardware.

OpenWrt, which has existed in parallel with the DD-WRT project that sprang from the same firmware moment, powers a number of custom-made routers. It and other open source router firmware faced an uncertain future in the mid-2010s, when Federal Communications Commission rules, or at least manufacturers’ interpretation of them, made them seem potentially illegal. Because open firmware often allowed for pushing wireless radios beyond their licensed radio frequency parameters, firms like TP-Link blocked them, while Linksys (at that point owned by Belkin) continued to allow them. In 2020, OpenWrt patched a code-execution exploit due to unencrypted update channels.

OpenWrt, now 20 years old, is crafting its own future-proof reference hardware Read More »

ios-17.3-adds-multiple-features-originally-planned-for-ios-17

iOS 17.3 adds multiple features originally planned for iOS 17

New Features —

macOS 14.3, watchOS 10.3, and tvOS 17.3 were also released.

An iPhone sits on a wood table

Enlarge / The iPhone 15 Pro.

Samuel Axon

Apple yesterday released iOS and iPadOS 17.3 as well as watchOS 10.3, tvOS 17.3, and macOS Sonoma 14.3 for all supported devices.

iOS 17.3 primarily adds collaborative playlists in Apple Music, and what Apple calls “Stolen Device Protection.” Collaborative playlists have been on a bit of a journey; they were promised as part of iOS 17, then added in the beta of iOS 17.2, but removed before that update went live. Now they’re finally reaching all users.

When enabled, Stolen Device Protection requires Face ID or Touch ID authentication “with no passcode fallback” for some sensitive actions on the phone.

And a related feature called Security Delay requires one use of Face ID or Touch ID, then a full hour’s wait, then another biometric authentication before certain particularly important actions can be performed, like changing the device’s passcode.

Other iOS 17.3 additions include support for AirPlay in participating hotels, an improved view for seeing the warranty status of all your devices, a new Unity wallpaper honoring Black History Month, and “crash detection optimizations.”

As is so often the case for these simultaneous operating system updates from Apple, iOS is the most robust. macOS 14.3 also adds the collaborative playlist feature and the AppleCare & Warranty Settings panel, but that’s about it as far as user-facing additions.

watchOS 10.3 adds a new 2024 Black Unity face that is meant to pair with a new watchband by the same name. And tvOS 17.3 simply reintroduces the previously removed iTunes Movie and TV Show Wishlist feature.

iOS 17.3 release notes

Stolen Device Protection

  • Stolen Device Protection increases security of iPhone and Apple ID by requiring Face ID or Touch ID with no passcode fallback to perform certain actions
  • Security Delay requires Face ID or Touch ID, an hour wait, and then an additional successful biometric authentication before sensitive operations like changing device passcode or Apple ID password can be performed

Lock Screen

  • New Unity wallpaper honors Black history and culture in celebration of Black History Month

Music

  • Collaborate on playlists allows you to invite friends to join your playlist and everyone can add, reorder, and remove songs
  • Emoji reactions can be added to any track in a collaborative playlist

This update also includes the following improvements:

  • AirPlay hotel support lets you stream content directly to the TV in your room in select hotels
  • AppleCare & Warranty in Settings shows your coverage for all devices signed in with your Apple ID
  • Crash detection optimizations (all iPhone 14 and iPhone 15 models)

macOS 14.3 Sonoma release notes

  • Collaborate on playlists in Apple Music allows you to invite friends to join your playlist and everyone can add, reorder, and remove songs
  • Emoji reactions can be added to any track in a collaborative playlist in Apple Music
  • AppleCare & Warranty in Settings shows your coverage for all devices signed in with your Apple ID

iOS 17.3 adds multiple features originally planned for iOS 17 Read More »

google-lays-off-“dozens”-from-x-labs,-wants-projects-to-seek-outside-funding

Google lays off “dozens” from X Labs, wants projects to seek outside funding

At least you don’t have to work on a Monday —

Google wants projects to take outside venture capital as part of budget cuts.

A large Google sign seen on a window of Google's headquarters.

Enlarge / Exterior view of a Googleplex building, the corporate headquarters of Google and parent company Alphabet, May 2018.

Google/Alphabet CEO Sundar Pichai wasn’t kidding when, earlier this month, he said more layoffs are coming. The latest group to be hit is Alphabet’s X Lab, which is losing “dozens of employees,” according to a new report from Bloomberg. This is something like the 11th Google layoff announcement we’ve covered in the past 12 months and the fourth one this month.

The X Lab is Alphabet’s “moonshot” experimental group, which is responsible for wild concepts like a wearable head-up display, a self-driving car, smart contact lenses, flying Internet balloons, and delivery drones. This is the age of Google cost-cutting, and you’ll notice none of those projects is a rip-roaring commercial success. On Google’s financials, the X Lab is part of Alphabet’s “Other Bets” group, which burns through around a billion dollars every quarter. It’s a research arm, so the hope is that spending all this money will someday lead to new revenue streams. For the short-term Wall Street types, though, it’s a money loser, quarter to quarter, and that makes it a prime candidate for cuts.

Bloomberg has a copy of the memo announcing the cuts to the X Labs staff, and there’s more in there than just layoffs. X Lab CEO Astro Teller writes: “We’re expanding our approach to focus on spinning out more projects as independent companies funded through market-based capital. We’ll do this by opening our scope to collaborate with a broader base of industry and financial partners, and by continuing to emphasize lean teams and capital efficiency.” Basically, Google wants these money losers to find their own funding somewhere else, at least partially.

The “outside funding” model isn’t new for some of Alphabet’s biggest and most promising “Other Bets” projects. The self-driving car company, Waymo, took rounds of outside funding in 2020 and 2021, racking up over $5 billion of cash that didn’t come from the Google Ads money geyser. Verily, Alphabet’s health care data analytics company, has also raised billions in outside funding. Both groups started as X projects and later “graduated” to full-fledged Alphabet companies. Others, like Project Loon (Internet balloons) and Sidewalk Infrastructure Partners (infrastructure planning), were X or Alphabet companies and were spun out as fully independent entities, separate from the Alphabet earnings sheet. Apparently, Alphabet wants to push X projects down one of those two paths.

On one hand, outside funding will result in a tougher, more critical eye for some of these projects. On the other hand, the Bloomberg report notes that “Alphabet could only accommodate so many Other Bets, creating a bottleneck for X ventures that were ready to take the next step, according to one of the people with knowledge of the matter. Startups within X often faced a choice between waiting for a spot to open up or striking out on their own.”

Google lays off “dozens” from X Labs, wants projects to seek outside funding Read More »

hp-ceo-evokes-james-bond-style-hack-via-ink-cartridges

HP CEO evokes James Bond-style hack via ink cartridges

Office printer with

Last Thursday, HP CEO Enrique Lores addressed the company’s controversial practice of bricking printers when users load them with third-party ink. Speaking to CNBC Television, he said, “We have seen that you can embed viruses in the cartridges. Through the cartridge, [the virus can] go to the printer, [and then] from the printer, go to the network.”

That frightening scenario could help explain why HP, which was hit this month with another lawsuit over its Dynamic Security system, insists on deploying it to printers.

Dynamic Security stops HP printers from functioning if an ink cartridge without an HP chip or HP electronic circuitry is installed. HP has issued firmware updates that block printers with such ink cartridges from printing, leading to the above lawsuit (PDF), which is seeking class-action certification. The suit alleges that HP printer customers were not made aware that printer firmware updates issued in late 2022 and early 2023 could result in printer features not working. The lawsuit seeks monetary damages and an injunction preventing HP from issuing printer updates that block ink cartridges without an HP chip.

But are hacked ink cartridges something we should actually be concerned about?

To investigate, I turned to Ars Technica Senior Security Editor Dan Goodin. He told me that he didn’t know of any attacks actively used in the wild that are capable of using a cartridge to infect a printer.

Goodin also put the question to Mastodon, and cybersecurity professionals, many with expertise in embedded-device hacking, were decidedly skeptical.

Another commenter, going by Graham Sutherland / Polynomial on Mastodon, referred to serial presence detect (SPD) electrically erasable programmable read-only memory (EEPROM), a form of flash memory used extensively in ink cartridges, saying:

I’ve seen and done some truly wacky hardware stuff in my life, including hiding data in SPD EEPROMs on memory DIMMs (and replacing them with microcontrollers for similar shenanigans), so believe me when I say that his claim is wildly implausible even in a lab setting, let alone in the wild, and let alone at any scale that impacts businesses or individuals rather than selected political actors.

HP’s evidence

Unsurprisingly, Lores’ claim comes from HP-backed research. The company’s bug bounty program tasked researchers from Bugcrowd with determining if it’s possible to use an ink cartridge as a cyberthreat. HP argued that ink cartridge microcontroller chips, which are used to communicate with the printer, could be an entryway for attacks.

As detailed in a 2022 article from research firm Actionable Intelligence, a researcher in the program found a way to hack a printer via a third-party ink cartridge. The researcher was reportedly unable to perform the same hack with an HP cartridge.

Shivaun Albright, HP’s chief technologist of print security, said at the time:

A researcher found a vulnerability over the serial interface between the cartridge and the printer. Essentially, they found a buffer overflow. That’s where you have got an interface that you may not have tested or validated well enough, and the hacker was able to overflow into memory beyond the bounds of that particular buffer. And that gives them the ability to inject code into the device.

Albright added that the malware “remained on the printer in memory” after the cartridge was removed.

HP acknowledges that there’s no evidence of such a hack occurring in the wild. Still, because chips used in third-party ink cartridges are reprogrammable (their “code can be modified via a resetting tool right in the field,” according to Actionable Intelligence), they’re less secure, the company says. The chips are said to be programmable so that they can still work in printers after firmware updates.

HP also questions the security of third-party ink companies’ supply chains, especially compared to its own supply chain security, which is ISO/IEC-certified.

So HP did find a theoretical way for cartridges to be hacked, and it’s reasonable for the company to issue a bug bounty to identify such a risk. But its solution for this threat was announced before it showed there could be a threat. HP added ink cartridge security training to its bug bounty program in 2020, and the above research was released in 2022. HP started using Dynamic Security in 2016, ostensibly to solve the problem that it sought to prove exists years later.

Further, there’s a sense from cybersecurity professionals that Ars spoke with that even if such a threat exists, it would take a high level of resources and skills, which are usually reserved for targeting high-profile victims. Realistically, the vast majority of individual consumers and businesses shouldn’t have serious concerns about ink cartridges being used to hack their machines.

HP CEO evokes James Bond-style hack via ink cartridges Read More »

wordpad-out;-80gbps-usb-support-and-other-win-11-features-in-testing-this-month

WordPad out; 80Gbps USB support and other Win 11 features in testing this month

Can’t stop won’t stop —

Microsoft’s next batch of Windows 11 feature updates is taking shape.

Green USB-C cable

Windows 11’s big feature update in September included a long list of minor changes, plus the Copilot AI assistant; that update was followed by Windows 11 23H2 in late October, which reset the operating system’s timeline for technical support and security updates but didn’t add much else in and of itself. But Windows development never stops these days, and this month’s Insider Preview builds have already shown us a few things that could end up in the stable version of the operating system in the next couple of months.

One major addition, which rolled out to Dev Channel builds on January 11 and Beta Channel builds today, is support for 80Gbps USB 4 ports. These speeds are part of the USB4 Version 2.0 spec—named with the USB-IF’s typical flair for clarity and consistency—that was published in 2022. Full 80Gbps speeds are still rare and will be for the foreseeable future, but Microsoft says that they’ll be included the Razer Blade 18 and a handful of other PCs with Intel’s 14th-generation HX-series laptop processors. We’d expect the new speeds to proliferate slowly and mostly in high-end systems over the next few months and years.

Another addition to that January 11 Dev Channel build is a change in how the Copilot generative AI assistant works. Normally, Copilot is launched by the user manually, either by clicking the icon on the taskbar, hitting the Win+C key combo, or (in some new PCs) by using the dedicated Copilot button on the keyboard. In recent Dev Channel builds, the Copilot window will open automatically on certain PCs as soon as you log into Windows, becoming part of your default desktop unless you turn it off in Settings.

The Copilot panel will only open by default on screens that meet minimum size and resolution requirements, things that Windows already detects and takes into account when setting your PC’s default zoom and showing available Snap Layouts, among other things. Microsoft says it’s testing the feature on screens that are 27 inches or larger with 1,920 or more horizontal pixels (for most screens, this means a minimum resolution of 1080p). For PCs without Copilot, including those that haven’t been signed into a Microsoft account, the feature will continue to be absent.

The

Enlarge / The “richer weather experience on the Lock screen,” seen in the bottom-center of this screenshot.

Microsoft

Other additions to the Dev Channel builds this month include easy Snipping Tool editing for Android screenshots from phones that have been paired to your PC, custom user-created voice commands, the ability to share URLs directly to services like WhatsApp and Gmail from the Windows share window, a new Weather widget for the Windows lock screen, and app install notifications from the Microsoft store.

Microsoft hasn’t publicized any of the changes it has made to its Canary channel builds since January 4—this is typical since it changes the fastest, and the tested features are the most likely to be removed or significantly tweaked before being released to the public. Most of the significant additions from that announcement have since made it out to the other channels, but there are a couple of things worth noting. First, there’s a new Energy Saver taskbar icon for desktop PCs without batteries, making it easier to tell when the feature is on without creating confusion. And the venerable WordPad app, originally marked for deletion in September, has also been removed from these builds and can’t be reinstalled.

Microsoft doesn’t publish Windows feature updates on an exact cadence beyond its commitment to deliver one with a new version number once per year in the fall. Last year’s first major batch of Windows 11 additions rolled out at the end of February, so a late winter or early spring launch window for the next batch of features could make sense.

WordPad out; 80Gbps USB support and other Win 11 features in testing this month Read More »

everything-we-learned-today-about-vision-pro-configurations,-specs,-and-accessories

Everything we learned today about Vision Pro configurations, specs, and accessories

Spatial computing —

It’ll cost you $200 to double the storage of the base configuration.

Apple's Vision Pro headset.

Enlarge / Apple’s Vision Pro headset.

Samuel Axon

Apple’s Vision Pro went up for preorder this morning at 8 am ET. As expected, shipment dates for preorders quickly backed up to March as initial supply was accounted for. Regardless of whether you’re in for the start or taking a wait-and-see approach with Apple’s ultra-pricey new device, though, we have access to a little more information about the device than we did before thanks to updates to the Apple Store website.

The product page for Vision Pro reveals configurations and pricing, and a new specs page clarifies answers to some questions we’ve had for a while now.

You’ll find all the relevant new information below. We’ve also updated our “What to expect from Apple Vision Pro” roundup with new information from the specs page.

Hardware specifications

As previously rumored, the Vision Pro has a variant of the M2 chip with an 8-core CPU (4 performance cores and 4 efficiency), a 10-core GPU, and a 16-core NPU. It has 16GB of unified memory.

There’s also the new R1 chip, which Apple claims achieves “12‑millisecond photon‑to‑photon latency” and 256GB/s memory bandwidth.

As for the display, we didn’t learn too much new here. As Apple has stated before, the two displays push 23 million pixels combined. They support refresh rates of 90 Hz, 96 Hz, and 100 Hz, and support playback of 24 fps and 30 fps video. Apple claims 92 percent DCI-P3.

The specs page also reveals that Vision Pro supports AirPlay at up to 1080p on iPhones, Macs, Apple TVs, and AirPlay-capable smart TVs.

Storage comes in three configurations. The base 256GB model costs $3,499. Bumping up to 512GB adds $200, and going to 1TB adds another $200.

The device’s camera supports both spatial photo and video capture, and Apple lists the specs as an 18 mm, ƒ/2.00 aperture at 6.5 stereo megapixels.

Additionally, there are six world-facing tracking cameras, four eye-tracking cameras, a TrueDepth sensor, a lidar scanner, four inertial measurement units, a flicker sensor, and an ambient light sensor. The headset authenticates the user by looking at their iris.

On the audio front, we’re looking at a six-mic array for audio capture. Apple isn’t super specific on the specs page about the speakers, noting only that the device offers “spatial audio with dynamic head tracking” like AirPods Pro and “personalized Spatial Audio and audio ray tracing.” Vision Pro also supports low-latency, lossless audio with the second generation of AirPods Pro.

Connectivity options include Wi-Fi 6 and Bluetooth 5.3.

Apple promises two hours of battery life for “general use” and says video watching can be up to 2.5 hours. The specs page also clarifies that Vision Pro can be used while charging the battery, which is something Apple had previously stated but then confusingly removed from its online documentation. This page seems to settle that.

The headset weighs between 21.2 and 22.9 ounces (600–650 g) depending on the light seal and headband used. That doesn’t include the battery pack, which weighs 353 g. That means Apple made the headset substantially lighter by pushing the battery to a separate unit.

Accessories and additional purchase options

As with its other hardware products, Apple offers AppleCare+ for Vision Pro. It’s $499 for two years, or $24.99 per month for perpetual coverage.

That price might seem awfully steep, but Apple lists the repair fees for the device on its service page and repairs without AppleCare+ will be even pricier—up to $2,399, depending on what’s broken. Any damage to the front glass panel will cost $799 to fix.

  • Apple Vision Pro Travel Case.

    Apple

  • Apple Vision Pro battery.

    Apple

  • Apple Vision Pro Solo Knit Band.

    Apple

  • Apple Vision Pro Dual Loop Band.

    Apple

  • Apple Vision Pro Light Seal.

    Apple

  • Apple Vision Pro Light Cushion.

    Apple

  • ZEISS Optical Inserts.

    Apple

  • Belkin Battery Holder for Apple Vision Pro.

    Apple

There are also a few optional accessories or replacement components you can buy, including:

  • Apple Vision Pro Travel Case ($199) – A pill-shaped case that contains and protects the headset along with its attachments and battery.
  • Apple Vision Pro Battery ($199) – A replacement for the battery that comes with the headset. You could also buy one of these to double your capacity while traveling, like for a long flight.
  • Apple Vision Pro Light Seal ($199) – The soft part of the headset that conforms to your face when you put the device on your head. This includes two light seal cushions, each in a different size.
  • Apple Vision Pro Light Seal Cushion ($29) – This attaches to the end of the light seal, and is intended to be removed for cleaning. It’s available in four sizes: N, N+, W, and W+.
  • Apple Vision Pro Solo Knit Band ($99) – One of two variations of the band that keeps Vision Pro on your head. This is the version that simply wraps around the back of your head. It’s available in three sizes: small, medium, and large.
  • Apple Vision Pro Dual Loop Band ($99) – The version that wraps around both the back of your head and the top. This also comes in small, medium, and large.
  • ZEISS Optical Inserts ($99+) – Lens inserts for those who wear glasses, as glasses won’t fit inside the device. Available in prescription and reader variations. You don’t need these if you wear soft contact lenses.
  • Belkin Battery Holder for Apple Vision Pro ($49.95) – A third-party accessory for either attaching Vision Pro’s battery to your belt or pants, or securing it with a cross-body strap.

Everything we learned today about Vision Pro configurations, specs, and accessories Read More »

convicted-murderer,-filesystem-creator-writes-of-regrets-to-linux-list

Convicted murderer, filesystem creator writes of regrets to Linux list

Pre-release notes —

“The man I am now would do things very differently,” Reiser says in long letter.

Hans Reiser letter to Fredrick Brennan

Enlarge / A portion of the cover letter attached to Hans Reiser’s response to Fredrick Brennan’s prompt about his filesystem’s obsolescence.

Fredrick Brennan

With the ReiserFS recently considered obsolete and slated for removal from the Linux kernel entirely, Fredrick R. Brennan, font designer and (now regretful) founder of 8chan, wrote to the filesystem’s creator, Hans Reiser, asking if he wanted to reply to the discussion on the Linux Kernel Mailing List (LKML).

Reiser, 59, serving a potential life sentence in a California prison for the 2006 murder of his estranged wife, Nina Reiser, wrote back with more than 6,500 words, which Brennan then forwarded to the LKML. It’s not often you see somebody apologize for killing their wife, explain their coding decisions around balanced trees versus extensible hashing, and suggest that elementary schools offer the same kinds of emotional intelligence curriculum that they’ve worked through in prison, in a software mailing list. It’s quite a document.

What follows is a relative summary of Reiser’s letter, dated November 26, 2023, which we first saw on the Phoronix blog, and which, by all appearances, is authentic (or would otherwise be an epic bit of minutely detailed fraud for no particular reason). It covers, broadly, why Reiser believes his system failed to gain mindshare among Linux users, beyond the most obvious reason. This leads Reiser to detail the technical possibilities, his interpersonal and leadership failings and development, some lingering regrets about dealings with SUSE and Oracle and the Linux community at large, and other topics, including modern Russian geopolitics.

“LKML and Slashdot.org seem like reasonable places to send it (as of 2006)”

In a cover letter, Reiser tells Brennan that he hopes he can use OCR to import his lengthy letter and asks him to use his best judgment in where to send his reply. He also asks, if he has time, Brennan might send him information on “Reiser5, or any interesting papers on other Filesystems, compression (especially Deep Learning based compression), etc.”

Then Reiser addresses the kernel mailing list directly—very directly:

I was asked by a kind Fredrick Brennan for my comments that I might offer on the discussion of removing ReiserFS V3 from the kernel. I don’t post directly because I am in prison for killing my wife Nina in 2006.

I am very sorry for my crime–a proper apology would be off topic for this forum, but available to any who ask.

A detailed apology for how I interacted with the Linux kernel community, and some history of V3 and V4, are included, along with descriptions of what the technical issues were. I have been attending prison workshops, and working hard on improving my social skills to aid my becoming less of a danger to society. The man I am now would do things very differently from how I did things then.

ReiserFS V3 was “our first filesystem, and in doing it we made mistakes, because we didn’t know what we were doing,” Reiser writes. He worked through “years of dark depression” to get V3 up to the performance speeds of ext2, but regrets how he celebrated that milestone. “The man I was then presented papers with benchmarks showing that ReiserFS was faster than ext2. The man I am now would stat his papers … crediting them for being faster than the filesystems of other operating systems, and thanking them for the years we used their filesystem to write ours.” It was “my first serious social mistake in the Linux community, and it was completely unnecessary.”

Reiser asks that a number of people who worked on ReiserFS be included in “one last release” of the README, and to “delete anything in there I might have said about why they were not credited.” He says prison has changed him in conflict resolution and with his “tendency to see people in extremes.”

Reiser extensively praises Mikhail Gilula, the “brightest mind in his generation of computer scientists,” for his work on ReiserFS from Russia and for his ideas on rewriting everything the field knew about data structures. With their ideas on filesystems and namespaces combined, it would be “the most important refactoring of code ever.” His analogy at the time, Reiser wrote, was Adam Smith’s ideas of how roads, waterways, and free trade affected civilization development; ReiserFS’ ideas could similarly change “the expressive power of the operating system.”

Convicted murderer, filesystem creator writes of regrets to Linux list Read More »

inventor-of-ntp-protocol-that-keeps-time-on-billions-of-devices-dies-at-age-85

Inventor of NTP protocol that keeps time on billions of devices dies at age 85

A legend in his own time —

Dave Mills created NTP, the protocol that holds the temporal Internet together, in 1985.

A photo of David L. Mills taken by David Woolley on April 27, 2005.

Enlarge / A photo of David L. Mills taken by David Woolley on April 27, 2005.

David Woolley / Benj Edwards / Getty Images

On Thursday, Internet pioneer Vint Cerf announced that Dr. David L. Mills, the inventor of Network Time Protocol (NTP), died peacefully at age 85 on January 17, 2024. The announcement came in a post on the Internet Society mailing list after Cerf was informed of David’s death by Mills’ daughter, Leigh.

“He was such an iconic element of the early Internet,” wrote Cerf.

Dr. Mills created the Network Time Protocol (NTP) in 1985 to address a crucial challenge in the online world: the synchronization of time across different computer systems and networks. In a digital environment where computers and servers are located all over the world, each with its own internal clock, there’s a significant need for a standardized and accurate timekeeping system.

NTP provides the solution by allowing clocks of computers over a network to synchronize to a common time source. This synchronization is vital for everything from data integrity to network security. For example, NTP keeps network financial transaction timestamps accurate, and it ensures accurate and synchronized timestamps for logging and monitoring network activities.

In the 1970s, during his tenure at COMSAT and involvement with ARPANET (the precursor to the Internet), Mills first identified the need for synchronized time across computer networks. His solution aligned computers to within tens of milliseconds. NTP now operates on billions of devices worldwide, coordinating time across every continent, and has become a cornerstone of modern digital infrastructure.

As detailed in an excellent 2022 New Yorker profile by Nate Hopper, Mills faced significant challenges in maintaining and evolving the protocol, especially as the Internet grew in scale and complexity. His work highlighted the often under-appreciated role of key open source software developers (a topic explored quite well in a 2020 xkcd comic). Mills was born with glaucoma and lost his sight, eventually becoming completely blind. Due to difficulties with his sight, Mills turned over control of the protocol to Harlan Stenn in the 2000s.

A screenshot of Dr. David L. Mills' website at the University of Delaware captured on January 19, 2024.

Enlarge / A screenshot of Dr. David L. Mills’ website at the University of Delaware captured on January 19, 2024.

Aside from his work on NTP, Mills also invented the first “Fuzzball router” for NSFNET (one of the first modern routers, based on the DEC PDP-11 computer), created one of the first implementations of FTP, inspired the creation of “ping,” and played a key role in Internet architecture as the first chairman of the Internet Architecture Task Force.

Mills was widely recognized for his work, becoming a Fellow of the Association for Computing Machinery in 1999 and the Institute of Electrical and Electronics Engineers in 2002, as well as receiving the IEEE Internet Award in 2013 for contributions to network protocols and timekeeping in the development of the Internet.

Mills received his PhD in Computer and Communication Sciences from the University of Michigan in 1971. At the time of his death, Mills was an emeritus professor at the University of Delaware, having retired in 2008 after teaching there for 22 years.

Inventor of NTP protocol that keeps time on billions of devices dies at age 85 Read More »

google-search-is-losing-the-fight-with-seo-spam,-study-says

Google search is losing the fight with SEO spam, study says

Just wait until more AI sites arrive —

Study finds “search engines seem to lose the cat-and-mouse game that is SEO spam.”

Google search is losing the fight with SEO spam, study says

It’s not just you—Google Search is getting worse. A new study from Leipzig University, Bauhaus-University Weimar, and the Center for Scalable Data Analytics and Artificial Intelligence looked at Google search quality for a year and found the company is losing the war against SEO (Search Engine Optimization) spam.

The study, first spotted by 404media, “monitored Google, Bing and DuckDuckGo for a year on 7,392 product review queries,” using queries like “best headphones” to study search results. The focus was on product review queries because the researchers felt those searches were “particularly vulnerable to affiliate marketing due to its inherent conflict of interest between users, search providers, and content providers.”

Overall, the study found that “the majority of high-ranking product reviews in the result pages of commercial search engines (SERPs) use affiliate marketing, and significant amounts are outright SEO product review spam.” Search engines occasionally update their ranking algorithms to try to combat spam, but the study found that “search engines seem to lose the cat-and-mouse game that is SEO spam” and that there are “strong correlations between search engine rankings and affiliate marketing, as well as a trend toward simplified, repetitive, and potentially AI-generated content.”

The study found “an inverse relationship between a page’s optimization level and its perceived expertise, indicating that SEO may hurt at least subjective page quality.” Google and its treatment of pages is the primary force behind what does and doesn’t count as SEO, and to say Google’s guidelines reduce subjective page quality is a strike against Google’s entire ranking algorithm.

The bad news is that it doesn’t seem like this will get better any time soon. The study points out generative AI sites one or two times, but that was only in the past year. The elephant in the room is that generative AI is starting to be able to completely automate the processes of SEO spam. Some AI content farms can scan a human-written site, use it for “training data,” rewrite it slightly, and then stave off the actual humans with more aggressive SEO tactics. There are already people bragging about doing AI-powered “SEO heists” on X (formerly Twitter). The New York Times is taking OpenAI to court for copyright infringement, and a class-action suit for book publishers calls ChatGPT and LLaMA (Large Language Model Meta AI) “industrial-strength plagiarists.” Artists are in the same boat from tools like Midjourney and Stable Diffusion. Most websites do not have the legal capacity to take on an infinite wave of automated spam sites enabled by these tools. Google’s policy is to not penalize AI-generated content in its search results.

A Google spokesperson responded to the study by pointing out that Google is still doing better than its competition: “This particular study looked narrowly at product review content, and it doesn’t reflect the overall quality and helpfulness of Search for the billions of queries we see every day. We’ve launched specific improvements to address these issues – and the study itself points out that Google has improved over the past year and is performing better than other search engines. More broadly, numerous third parties have measured search engine results for other types of queries and found Google to be of significantly higher quality than the rest.”

This post was updated at 6: 00PM ET to add a statement from Google.

Google search is losing the fight with SEO spam, study says Read More »

“alexa-is-in-trouble”:-paid-for-alexa-gives-inaccurate-answers-in-early-demos

“Alexa is in trouble”: Paid-for Alexa gives inaccurate answers in early demos

Amazon Echo Show 8 with Alexa

Enlarge / Amazon demoed future generative AI capabilties for Alexa in September.

“If this fails to get revenue, Alexa is in trouble.”

A quote from an anonymous Amazon employee in a Wednesday Business Insider report paints a dire picture. Amazon needs its upcoming subscription version of Alexa to drive revenue in ways that its voice assistant never has before.

Amazon declined Ars’ request for comment on the report. But the opening quote in this article could have been uttered by anyone following voice assistants for the past year-plus. All voice assistants have struggled to drive revenue since people tend to use voice assistants for basic queries, like checking the weather, rather than transactions.

Amazon announced plans to drive usage and interest in Alexa by releasing a generative AI version that it said would one day require a subscription.

This leads to the question: Would you pay to use Alexa? Amazon will be challenged to convince people to change how they use Alexa while suddenly paying a monthly rate to enable that unprecedented behavior.

Workers within Amazon seemingly see this obstacle. Insider, citing an anonymous Amazon employee, reported that “some were questioning the entire premise of charging for Alexa. For example, people who already pay for an existing Amazon service, such as Amazon Music, might not be willing to pay additional money to get access to the newer version of Alexa.”

“There is tension over whether people will pay for Alexa or not,” one of the anonymous Amazon workers reportedly said.

Subscription-based Alexa originally planned for June release

Amazon hasn’t publicly confirmed a release date for generative AI Alexa. But Insider’s report, citing “internal documents and people familiar with the matter,” said Amazon has been planning to release its subscription plan on June 30. However, plans for what Insider said will be called “Alexa Plus” and built on “Remarkable Alexa” technology could be delayed due to numerous development challenges.

According to the report, the Remarkable Alexa tech has been being demoed by 15,000 customers and currently succeeds in being conversational but is “deflecting answers, often giving unnecessarily long or inaccurate responses.”

In September, then-SVP of devices and services at Amazon David Limp demoed Alexa understanding more complex commands, including Alexa not requiring the “Hey Alexa” prompt and being able to understand multiple demands for multiple apps through a single spoken phrase.

Insider reported: “The new Alexa still didn’t meet the quality standards expected for Alexa Plus, these people added, noting the technical challenges and complexity of redesigning Alexa.”

“Legacy constraints”

According to the report, people working on the original Alexa insisted on using what they had already built for the standard voice assistant with the paid-for version, resulting in a bloated technology and “internal politics.”

However, the original Alexa is based on a natural language model with multiple parts doing multiple things, compared to the colossal large language model of generative AI Alexa.

Now, generative AI Alexa is reportedly moving to a new technological stack to avoid the “legacy constraints” of today’s Alexa but potentially delaying things.

“Alexa is in trouble”: Paid-for Alexa gives inaccurate answers in early demos Read More »

samsung’s-$1,300-phone-might-someday-have-fees-for-ai-usage

Samsung’s $1,300 phone might someday have fees for AI usage

Will Samsung even care about AI in 2026? —

Samsung says Galaxy S24 AI features are “free until the end of 2025.”

Samsung’s $1,300 phone might someday have fees for AI usage

Samsung

Samsung’s big Galaxy S24 launch was yesterday, and to hear Samsung tell the story, the big highlight of the event was “Galaxy AI.” Another view is that Galaxy AI is the usual bundle of baked-in Samsung features skinned on top of Android, but with generative AI being the hot new thing, Samsung went with AI-centric branding. Whatever value you want to place on Samsung’s AI features, you might soon have to place an actual monetary value on them: Despite devices like the Galaxy S24 Ultra costing $1,300, Samsung might start charging for some of these AI phone features.

The fine print on Samsung’s Galaxy S24 promotional page features 44 asterisks and footnotes, and tucked away in that pile of caveats is the line “Galaxy AI features will be provided for free until the end of 2025 on supported Samsung Galaxy devices.” That means Samsung reserves the right to charge for Galaxy AI after 2025.

AI features that require server time have an ongoing cost. Google and Amazon figured this out in the last AI generation (if we can call it that) with the Google Assistant and Alexa voice assistants. Amazon’s finances on the whole situation are clearer than Google’s, and Amazon’s 2022 Alexa financials were reportedly a $10 billion loss. Amazon is planning on a subscription model for Alexa in the future. Google’s normal user subscription plan is Google One, and while that mainly gets you more account storage, it also unlocks some Google AI features like “Magic eraser” in Google Photos. ChatGPT has a subscription plan for its best model, ChatGPT 4, too. Samsung apparently wants to join the party.

The Galaxy S24's

Enlarge / The Galaxy S24’s “Live translate” feature in the phone app. You can speak one language, and the phone app will repeat your message in a different language after a delay.

Samsung

This is the company that makes Bixby and the notoriously poorly coded Tizen, though, so it’s hard to imagine Galaxy AI features being worth paying for. The first item on Samsung’s “Galaxy AI” promo page is Google’s “Circle to search,” a feature it can’t charge for and didn’t build. The Galaxy AI features made by Samsung include “Interpreter,” which is a copy of Google Translate’s conversation mode, and Voice Recorder, a voice transcription app that is just a copy of Google Recorder (and apparently not as good). “Chat Assist” is part of the keyboard and can rewrite any inputted text with generative AI, making your input sound more “fun” or “professional.” “Note Assist” is a Samsung Notes feature that can generate AI summaries of your notes. The one interesting feature is “Live Translate,” which does voice translation of a phone call, translating communication via speech-to-text-to-speech. There’s a lot that can go wrong there, though.

Samsung is a hardware company, and presumably, a lot of these use on-device processing instead of bothering a server somewhere, so it’s hard to know if Samsung even has any serious costs to recoup. Like most Samsung Android features, this feels more like throwing a pile of stuff at the wall and hoping something sticks rather than a collection of killer apps. These are essentially all just app features, too, meaning they have to compete with the nearly infinite Play Store app selection, and you could easily download a free competitor.

The first step to charging for something like this is throwing the idea out there, so Samsung is probably listening to how people will react between now and the end of 2025.

Samsung’s $1,300 phone might someday have fees for AI usage Read More »

netflix-won’t-have-a-vision-pro-app,-compromising-the-device’s-appeal

Netflix won’t have a Vision Pro app, compromising the device’s appeal

App Support —

You’ll be able to watch via the web browser, but that’s far from ideal.

Vision Pro will allow users to watch movies on a virtual TV set.

Enlarge / Vision Pro will allow users to watch movies on a virtual TV set.

Apple

In the leadup to Vision Pro preorders tomorrow, Apple has seemingly been prioritizing the message that the device will be an ideal way to watch movies and TV shows. In many ways, that might be true, but there’s one major caveat: Netflix.

In a statement reported by Bloomberg today, Netflix revealed that it does not plan to offer an app for Vision Pro. Instead, users will have to use a web-based interface to watch the streaming service.

Netflix compares the experience to the Mac, but there are a few reasons this won’t be an ideal experience for users. First, the iPad and iPhone mobile apps support offline viewing of downloaded videos. That’s particularly handy for when you’re flying, which is arguably one of the best use cases for Vision Pro.

Unfortunately, Netflix doesn’t support offline downloads on the web. It also remains to be seen what resolution will be achievable—the maximum resolution of a Netflix stream depends on the browser, with most capping out at 720p. That wouldn’t look so great on a 100-foot virtual screen.

Granted, Netflix streams at up to 4K on Safari for macOS, but we don’t know if that will be the case for Safari on Vision Pro.

It will also make launching the app more complicated, and the interface won’t be as nice to use as a native app.

There are two ways Netflix could have supported visionOS more directly. The company could have developed a full-fledged mixed reality app like Disney+ did, with visionOS-specific features. Or it could have at least adapted its iPad app to work well within visionOS.

The latter, while not completely trivial, is relatively easy for a company with Netflix’s development resources, so it’s hard not to see this as a deliberate snub.

This isn’t the first time Netflix has chosen not to play nice with a new Apple initiative. Netflix is the most notable service missing from Apple’s useful TV app on Apple TV and iPhone, which aggregates your viewing activity and makes recommendations that link out to individual streaming apps.

Netflix and Apple now compete in the streaming space. In particular, both have courted awards for their original films with limited theatrical releases and aggressive campaigns. That could be a motivator, but we can’t know what Netflix’s leadership is thinking for sure.

Most other major streaming services, including Disney+, Peacock, Max, and Amazon Prime Video, will have working visionOS apps when the device launches in early February, making Netflix a notable outlier.

While not a deal-breaker for everyone, the omission cuts at the heart of Apple’s messaging around Vision Pro’s value proposition; the steep $3,499 price could be seen as worth the investment if you see the device as replacing both an iPad and a high-end TV. But that pitch is a little bit compromised if the experience on that high-end TV is subpar for one of the most popular streaming services.

Netflix won’t have a Vision Pro app, compromising the device’s appeal Read More »