Forgot your password?
typodupeerror

Comment Bleem! (Score 1) 18

This already happened with a commercial emulator called Bleem. Long story short: Sony lost every lawsuit, but the legal fees were enough to shut down the defendants. In response to this, the United States Department of Justice exacted far-reaching reforms to ensure that in the future, no large corporation would be able to bully smaller players into bankruptcy.

Psych!

United States

China and the US Say They've Agreed to Start Talks About AI (cnn.com) 160

The United States and China have agreed to "launch a dialogue" on AI, reports Reuters. On artificial intelligence, the two sides agreed to hold a dialogue on the technology's risks and benefits, with the next round of discussions set for November, and to set up a communication channel for AI-related incidents, the Chinese Foreign Ministry and the White House said.

The White House said that the leaders had agreed to use the term "super intelligence" in place of "artificial intelligence." In a separate statement, the Chinese ministry said that Beijing valued Washington's use of the new term. As AI technology continues to advance, the two sides should step up exchanges and work toward consensus in line with new developments, it said.

But CNN argues that "Despite growing calls to prevent AI development from spiraling out of control, the Trump-Xi summit has produced little substance, as many experts expected." The right thing to do on AI, [China's leader] Xi said during talks with Trump, is to "draw on each other's strengths, not guard against each other" — a reference to Beijing's concern about US containment, from existing tech export controls to potential AI restrictions. "The two sides can continue their dialogue on AI, exchange views on its risks and benefits, and jointly prevent the misuse and abuse of AI," he added. But the summit has yielded little progress on AI beyond a formal dialogue and a bilateral communication channel, proposals discussed before the two leaders' summit — underscoring the entrenched mutual mistrust amid contrasting visions on AI... Because of low levels of trust, cooperation between the two superpowers remains limited, said George Chen, chair of digital practice at The Asia Group consultancy. "Beijing continues to believe Washington seeks to contain China's rise in AI and other emerging technologies, a perception that will shape the pace and scope of future engagement for the two countries on AI," he said.
CNN also points out that while China trails the US in frontier AI models, "it's rapidly narrowing the technology gap while championing a more open ecosystem centered on accessibility and lower cost." In July, Chinese leader Xi Jinping launched the World Artificial Intelligence Cooperation Organization — a rival grouping to the Pax Silica alliance that Trump formed last year to reduce reliance on China for AI supply chains. While over two dozen countries and the European Union signed up to Trump's Pax Silica, Xi has recruited 29 countries, including Russia, Indonesia and Pakistan, to his alternative vision of open models, which allow users to freely download, customize and run without paying hefty fees to American firms like Anthropic and OpenAI. For developers in the Global South, an inexpensive Chinese model from DeepSeek or Moonshot may be more useful than a slightly more capable system requiring an expensive subscription and access to a foreign cloud provider, said Eric Olander, editor in chief of The China-Global South Project, a research agency....

China's embrace of open systems has not always been a top-down strategy by Beijing. Restrictions on access to the most advanced chips because of US export controls, coupled with smaller capital markets, have pushed Chinese developers toward open models as a way to compete with leading US proprietary systems. That shift has proved effective. In a year, Chinese models' global usage skyrocketed from less than 15% to over 54% last week, led by DeepSeek, according to AI leaderboard data by OpenRouter, a marketplace for models. Even American firms, from Airbnb and DoorDash to Shopify, have embraced Chinese models, tapping into the advantages of open systems, including lower costs and greater flexibility for customization.

CNN adds this insight from Alex Colville, an analyst focusing on tech and security at the government-backed Australian Strategic Policy Institute. "The more capable Chinese models become, the less likely it is Beijing may leave them unrestricted."

Submission + - Researchers Found a New Way to Break RSA that Doesn't Require Factoring the Key (cybersecuritynews.com)

An anonymous reader writes: Security researchers have demonstrated a faster way to undermine certain RSA deployments without factoring the public modulus, challenging the assumption that RSA’s practical strength always tracks the cost of integer factorization.

The attack converts temporary access to a raw, unpadded RSA signing or decryption service into a lasting capability to forge signatures or decrypt chosen ciphertexts offline.

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented the technique against a 1,024-bit RSA key. Their computation consumed 1,380 CPU core-years over five months and required 232 oracle queries. By comparison, factoring a 1,024-bit RSA modulus is estimated to require roughly 500,000 to one million core-years.

The method, called eNFS by the researchers, belongs to the number field sieve family. Instead of the general number field sieve used to factor RSA moduli, it approaches the faster “special” number field sieve complexity by replacing part of the usual mathematical work with answers from the signing oracle. Crucially, it never recovers the prime factors or RSA private key.

The attack unfolds in stages. An approximately 1,200-core-year precomputation depends only on the public modulus and exponent. The attacker then submits selected values to the raw RSA oracle. Once those responses are collected, access can disappear: forging any chosen signature or decrypting a target takes about another 180 core-years and can be repeated offline.

The underlying algorithm is not new. Antoine Joux, David Naccache and Emmanuel Thomé introduced it in 2007, but the new work provides its first implementation and large-scale 1,024-bit demonstration. The code builds heavily on CADO-NFS while adding the engineering needed for polynomial selection, sieving, linear algebra, root extraction, and descent at this scale.

This is not a universal RSA break. The attacker needs temporary access to a raw exponentiation oracle, a capability that conventional RSA signatures using PKCS#1 v1.5 or RSA-PSS padding normally do not expose. More plausible targets include HSM interfaces permitting raw PKCS#11 RSA operations and blind-signature protocols such as Privacy Pass, where blinded requests can provide the required oracle behavior.

The researchers estimate 2^{90} work and 2^{43} oracle queries against 2,048-bit RSA in this model, versus the commonly assigned 112-bit factoring strength. They project roughly 2^{119} work for 4,096-bit RSA, leaving it short of a modern 128-bit security target. Those costs remain beyond attackers, but could matter to well-resourced adversaries and protocols with long-lived public keys.

Organizations do not need to abandon correctly padded RSA immediately. Operators should disable unnecessary raw RSA mechanisms, audit HSM policies, limit oracle exposure, and rotate vulnerable blind-signature keys more frequently.

Protocol designers can investigate zero-knowledge proofs of well-formed requests, while longer-term migration should favor modern signature schemes and post-quantum cryptography rather than treating larger RSA keys as a permanent solution.

Submission + - Ruby on Rails Creator Abandons Ruby During Keynote Speech (youtube.com) 1

Grady Martin writes: David Heinemeier Hansson, creator of Ruby on Rails, announced during a keynote speech at Rails World 2026 on Wednesday that his current project, HEY, has begun migrating from Ruby to a vibe-coded rewrite in Rust. His speech also touched on human productivity and the importance of optimization, noting that agentic developers can “do whatever the fuck [they] want” to achieve the latter. He closed the hour with a Malcom in the Middle meme and commanded the audience: “Don't be a loser”.

Submission + - New RSA attack takes cryptographers by surprise (arstechnica.com)

phatrabt writes: There’s a new way to break RSA that’s faster than anything we’ve seen before Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.

“If this result holds up under peer review, it would indeed be a conceptual break-through,” Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key.”


Submission + - More Than One in Five "Hi-Res" Audio Discs Are Just the CD, Tests Find (losslessextract.com)

packslash writes: Summary: The developer of Lossless Extract, built a detector for upsampled audio and has run it on 1,225 SACD, DVD-Audio and Blu-ray Audio discs anonymously from users' collections. 272 of them, 22 percent, failed. "They hold CD-quality audio, no better than the $10 CD, stretched to fit a bigger disc and sold back at triple the price," the developer writes. The failures include Prince's Purple Rain on Blu-ray, Rush's Moving Pictures and Dave Brubeck's Time Out. The test looks for music that stops dead at the CD's ceiling, with a silence above it "so perfect it can't happen in the real world." Results depend on the edition. The 2003 SACD of Norah Jones' Come Away With Me fails, while the 2012 SACD made from the analog tapes passes. The full list is public, and readers can test their own files in the browser without uploading anything.

Verify Hi res site https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Flosslessextract.com%2Fve...

Comment Enough Already (Score 4, Insightful) 130

When software does what it's not supposed to do, we call that a bug, and we fix it. When a corporation tries to spin its bugs as braggable episodes, laymen may quiver in fear (or excitement), but more capable people look down upon the corporation for its incompetence.

Submission + - AI Finds So Many Linux Bugs That Canonical changes Ubuntu Security Update (nerds.xyz)

BrianFagioli writes: Canonical is changing how Ubuntu kernel security updates are delivered as the number of reported Linux vulnerabilities continues to grow. The company says AI tools including large language models and specialized agents are helping researchers discover bugs faster. The Linux kernel becoming a CVE Numbering Authority has also increased the number of assigned CVEs.

Ubuntu is moving from separate four week regular and two week security kernel update cycles to overlapping two week cycles. The result will be a kernel release every week. Canonical says it will retain hardware certification and regression testing while organizations willing to test release candidates themselves can access fixes earlier through the proposed pocket.

The shift highlights an interesting consequence of AI assisted security research. Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster.

Comment Ebb and Flow (Score 1) 107

I don't follow politics closely, but even I can tell that the pendulum is going to swing back—how hard, I don't know; a lot can happen between now and 2028.

Almost no real change will take place, of course, but the people bitching now can go back to cheering, and the people cheering now can go back to bitching—wherein “cheering” is a ritual that mostly involves bitching about the past.

I choose to bitch in the comments section of Slashdot.

Slashdot Top Deals

Get hold of portable property. -- Charles Dickens, "Great Expectations"

Working...