Forgot your password?
typodupeerror

Submission + - Reddit Is Killing RSS Feeds, Ending Public API Access (techcrunch.com)

An anonymous reader writes: Amid a number of updates for moderators and developers announced Wednesday comes bad news for supporters of a more open web: Reddit is ending support for RSS feeds. Reddit says RSS has now become a “common surface for large-scale scraping and automated abuse,” which is why it’s made the decision to wind down RSS feeds on its platform. “We know RSS has been a beloved part of the open web for a long time, and we’re grateful to everyone who used it to stay connected to Reddit,” the company noted in its announcement, where it also shared a March 2027 shutdown date for its public API. Reddit said RSS support will cease on November 13.

[...] The RSS change was one of several updates issued on Wednesday by the company. Another big change will be the end of its public API. Public API access will also end by March 2027, which will impact any tools that used it for programmatic access to Reddit conversations, including social listening products, those used by researchers, and AI products, such as AI assistants. Today, those assistants can use Reddit to answer questions, but after closing public API access, they will need to forgo commercial deals with Reddit for its data.

In addition, Reddit provided an update on its Rules Hub progress and auto-mod changes, and said it was “adding safeguards” to its classic, text-heavy version of its site known as Old Reddit. The latter will include limiting access to logged-in moderators and recent users — changes Reddit also said were required because of “abusive scraping and automated traffic.” Reddit said in the next few months it will limit access for logged-in users to those who have used Old Reddit in the last 90 days. The company also reminded developers building approved third-party apps and bots to register them with the company before January 12, 2027, to avoid disruption. After that date, Reddit will remove API access for any developer that hasn’t registered.

Submission + - Unfair Parking Ticket UK: Steps to Consider Before Paying (blogspot.com)

legateca writes: If you believe a parking ticket was issued unfairly, you may want to understand the available challenge process before making a decision. The appropriate route depends on whether the notice came from a council, another authority or a private parking operator. This guide explains what to consider when you challenge a parking ticket UK, including reviewing signage, checking evidence, observing deadlines and keeping copies of your correspondence. Understanding the process can help you respond appropriately.

Comment Thankfully it can all be disabled in the browser (Score 1) 163

For those on Firefox that aren't keen on the new Nova redesign, it can be disabled:

In your address bar, type `about:config`, acknowledge the warning, search for `browser.nova.enabled`, and then set it to false.

IMO, Nova is far too loud; I need my browser UI to be background noise.

Submission + - Researchers Found a New Way to Break RSA that Doesn't Require Factoring the Key (cybersecuritynews.com)

An anonymous reader writes: Security researchers have demonstrated a faster way to undermine certain RSA deployments without factoring the public modulus, challenging the assumption that RSA’s practical strength always tracks the cost of integer factorization.

The attack converts temporary access to a raw, unpadded RSA signing or decryption service into a lasting capability to forge signatures or decrypt chosen ciphertexts offline.

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented the technique against a 1,024-bit RSA key. Their computation consumed 1,380 CPU core-years over five months and required 232 oracle queries. By comparison, factoring a 1,024-bit RSA modulus is estimated to require roughly 500,000 to one million core-years.

The method, called eNFS by the researchers, belongs to the number field sieve family. Instead of the general number field sieve used to factor RSA moduli, it approaches the faster “special” number field sieve complexity by replacing part of the usual mathematical work with answers from the signing oracle. Crucially, it never recovers the prime factors or RSA private key.

The attack unfolds in stages. An approximately 1,200-core-year precomputation depends only on the public modulus and exponent. The attacker then submits selected values to the raw RSA oracle. Once those responses are collected, access can disappear: forging any chosen signature or decrypting a target takes about another 180 core-years and can be repeated offline.

The underlying algorithm is not new. Antoine Joux, David Naccache and Emmanuel Thomé introduced it in 2007, but the new work provides its first implementation and large-scale 1,024-bit demonstration. The code builds heavily on CADO-NFS while adding the engineering needed for polynomial selection, sieving, linear algebra, root extraction, and descent at this scale.

This is not a universal RSA break. The attacker needs temporary access to a raw exponentiation oracle, a capability that conventional RSA signatures using PKCS#1 v1.5 or RSA-PSS padding normally do not expose. More plausible targets include HSM interfaces permitting raw PKCS#11 RSA operations and blind-signature protocols such as Privacy Pass, where blinded requests can provide the required oracle behavior.

The researchers estimate 2^{90} work and 2^{43} oracle queries against 2,048-bit RSA in this model, versus the commonly assigned 112-bit factoring strength. They project roughly 2^{119} work for 4,096-bit RSA, leaving it short of a modern 128-bit security target. Those costs remain beyond attackers, but could matter to well-resourced adversaries and protocols with long-lived public keys.

Organizations do not need to abandon correctly padded RSA immediately. Operators should disable unnecessary raw RSA mechanisms, audit HSM policies, limit oracle exposure, and rotate vulnerable blind-signature keys more frequently.

Protocol designers can investigate zero-knowledge proofs of well-formed requests, while longer-term migration should favor modern signature schemes and post-quantum cryptography rather than treating larger RSA keys as a permanent solution.

Submission + - SourceHut changes terms of service limiting LLM use (sourcehut.org)

bjoast writes: The SourceHut Git hosting provider recently changed its terms of service to limit how users may make of use of LLMs in their work, citing resource constraints and ethical concerns. From the the new terms of service:

The new terms of service, which will go into effect for new projects after the usual two week notice period (i.e. September 10th), will now include the following under the list of prohibited content:

  • original content written with or which facilitates the use of LLMs (large language models) or other generative AI technologies

The use of LLMs or other generative AI tools to produce or assist with the production of source code, assets, tickets, emails, and so on, will no longer be permitted on SourceHut once these terms take effect. As with our other policy changes, the intention is to roll this out slowly and thoughtfully. Each possible violation will be evaluated on a case-by-case basis and we are open to making exceptions.


Comment Traditional Search has long been useless (Score 1) 85

The results that come first aren't there because they're useful, but because the site's owners have gamed the algorithm to come first, and then surrounded that algo-gaming content with as many tangibly related advertisements as possible in the hope of generating some cash.

Having an LLM help parse through the bollocks has been a refreshing experience, honestly.

Comment Re:Headline could be repeated every year (Score 1) 24

WordPress, usually, is 'good enough' for most SMEs that need something with editing capability; but nothing with any hugely complicated business or ecommerce logic.

For the agency I work for, WordPress is our default entry-level platform for SMEs that don't need ecommerce or complex custom development. It is *considerably* better than it was 10 years ago.

Submission + - Californians sign up to have data brokers delete their personal information (eastbaytimes.com)

ZipNada writes: More than 300,000 Californians have demanded that hundreds of data brokers erase information about their locations, finances, health and personal lives as the state’s first-in-the-nation Delete Act requires brokers to start the mandatory process of removing data on Aug. 1.

Brokers must start accessing deletion requests within 45 days after Aug. 1, then once they have collected those requests, they have another 45 days to report what data they have purged to the agency — known as CalPrivacy — and people who have signed up. ...
The information Californians are asking brokers to erase can be extraordinarily sensitive. Of the nearly 600 data brokers in CalPrivacy’s registry, 110 sell people’s precise locations, the registry shows. More than 40 sell identity data that can include Social Security numbers. Almost 70 sell information on people’s gender identity. Seven sell data related to reproductive health, and six sell information on union membership. Eighteen sell minors’ data — and Kemp said children can sign up for deletion using DROP, or parents can do it for them.

Many of the brokers build — and sell to advertisers and marketers — dossiers that are increasingly processed using artificial intelligence to draw conclusions about a person’s interests, family, politics, lifestyle, finances, sexual orientation and health.

Slashdot Top Deals

"Old age and treachery will beat youth and skill every time." -- a coffee cup

Working...