Forgot your password?
typodupeerror

Submission + - Texas City Demands $2 Million For Public Records On Flock Usage (arstechnica.com)

An anonymous reader writes: As bipartisan backlash against Flock grows, some cities are asking anti-surveillance advocates and media outlets to pay eye-popping fees—including charging tens of thousands or even millions—to get information about how police departments are using and potentially abusing AI-enabled camera systems that track every vehicle that passes them. On Monday, the Texas Tribune reported that city officials in a Fort Worth suburb, North Richland Hills, asked one group to pay $2.3 million before it would fulfill a public records request for Flock data. To reach that high fee, officials claimed that searching “about a terabyte worth of communications about errors, misuse, and effectiveness of the Flock system” would take approximately 14 years of labor at a rate of $15 per hour.

Phil Mynona, who filed the request using a pseudonym on behalf of his group, the Texas Privacy Coalition, told the Tribune that the fee seemed “ludicrous” and designed to stifle his public records searches. Mynona has sought similar records from more than 200 law enforcement agencies across the US, and he said it was impossible to predict how cities assessed fees for Flock records. Some cities provided more than 400,000 pages of documents for free, while others charged $5,000. Other groups, including a Houston news station called KPRC, have seen officials quote up to $121,000 for Flock records, the Tribune reported. The high price tags may be hiding data that anti-surveillance groups note have triggered audits, arrests, and changes in how law enforcement uses cameras, including decisions to get rid of cameras.

United States

Rural Data Centers Are in for a Big Federal Tax Break (wired.com) 9

Wired reports that rural data center projects could become eligible for expanded federal Opportunity Zone tax benefits starting in 2027, with more than 100 planned or developing facilities potentially qualifying. "Right now, the only requirement to get the benefits is capital investment," says Emily Kraschel, a tax policy analyst at the Searchlight Institute, a public policy think tank. "However, that doesn't guarantee that that money is necessarily creating jobs or creating a local economic boost. You'd be more sure of that with a more traditional factory that requires lots of workers. But with a data center, that assumption goes a little wonky." From the report: During the first Trump administration, a bipartisan group of lawmakers proposed the creation of the opportunity zone program, which offers tax benefits for companies that choose to build projects in certain low-income census tracts. Last year, the One Big Beautiful Bill Act made a number of changes to open up the program in order to attract more investment to rural areas. Kraschel and her colleagues from Searchlight have been researching data center projects that might qualify for these tax benefits, comparing the locations of data center projects in development with rural census tracts eligible for the new program. Wired exclusively reviewed the research compiled by Searchlight and found more than 100 data centers under various stages of development in rural areas that could be eligible.

Searchlight used a very conservative database of under 700 data center projects that are planned or under construction to compile its research; other datasets put the number of data centers in development in the US at closer to 1,500. It's very likely that the number of newly eligible projects is bigger, especially since more data centers are decamping from urban areas. Separate research from Pew found that while just 13 percent of operating data centers are located in rural areas, a majority of planned facilities -- around 67 percent -- are going rural. [...] A project simply existing in a rural opportunity zone doesn't mean the company automatically will get the tax benefits; the company has to create a specialized investment vehicle to kickstart the process. Because the tax break can be considered confidential IRS data, it's next to impossible to know which companies are pursuing the benefits unless they voluntarily disclose.

[...] Nathan Jensen, a government professor at the University of Texas-Austin, says that he would be "very surprised" if some companies were not considering siting in rural opportunity zones as part of their decisionmaking process. "It's essentially free money," he says. There is no requirement for projects getting opportunity zone benefits to create jobs; the assumption is that they will do so, simply by siting in the community itself. This isn't always the case for projects like storage facilities and warehouses, which, Jensen says, have been popular choices for developers working in opportunity zones. Data centers may create a number of jobs in the short term for their construction, but there's an ongoing debate about whether or not they create a lasting new workforce over the longer term.

Privacy

Hackers Steal 8 Million Citizens' Records From Danish Government Database (techcrunch.com) 3

Hackers stole records belonging to roughly 8 million Danish citizens and residents from Denmark's Central Person Register (CPR), including names, addresses, social security numbers and other personal information. The breach is believed to be the largest in Denmark's history. TechCrunch reports: The CPR is a government database of Danish citizens' information, including their government-issued identity number for paying taxes and accessing other services. Denmark's current population is about 6 million people, but the database includes records for about 11 million people, with some of the data going back decades.

The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." (Some companies in Denmark have access to the CPR for verifying people's information with the government.)

Wikipedia

Wikipedia Operator Says OpenAI's 'Rogue' Bots May Be Linked to a May Outage 19

The Wikimedia Foundation says it found evidence that "rogue" OpenAI agents edited Wikimedia wikis without approval, unsuccessfully tried to exploit its Etherpad service, and generated millions of automated requests across Wikimedia projects. Here's a summary of what Wikimedia observed (via The Verge): Wiki editing: We've identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI. These edits were not published to pages with visibility to general readers; almost all of them were testing edits in "sandbox" areas of the wiki. It also included a few edits to the configuration for a citation tool, which we believe were potentially malicious edits that were intended to misuse this tool as a proxy for fetching data from remote services. While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents.

Etherpad probing and use: Agents we believe to be operated by OpenAI made some unsuccessful attempts to compromise our public Etherpad, a note-taking tool we host as a community service. Agents unsuccessfully tried to use it to fetch data from other websites as a proxy. Other agents also likely operated by OpenAI took notes about their tasks, though this did not appear to turn into coordination.

Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May.
Databases

Meta Rushed To Fix Muse 'VM Escape' Vulnerability Soon Before Launch (404media.co) 4

An anonymous reader quotes a report from 404 Media: In the immediate weeks before Muse's launch, Meta engineers found several security vulnerabilities in the company's viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse's intended environment and access Meta's own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them. These specific vulnerabilities were discovered before the launch of the product but required a multi-team "mad dash" to fix "a sudden spike in reported KVM escapes," according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that they own. On Meta's end, each individual Muse instance runs on a kernel-based virtual machine, which connects to, but is supposed to be isolated from, Meta's own critical infrastructure. A "KVM escape," then, is when, through a security vulnerability, a Muse instance is able to escape from that virtual machine and interact with the system that runs it, or with other users' virtual machines.

According to a Meta source, as well as internal security documentation and internal posts viewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker -- that is, a normal Muse user -- to access data in sensitive internal Meta databases. At least one of the vulnerabilities was related to an exploit found in Linux kernel-based virtual machine code in July. 4 Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses for Muse. The security issue was considered serious enough that it was raised to Mark Zuckerberg, and several different security teams worked nights and weekends in the leadup to launch to fix the issues. [...] The Meta source said they felt security teams were asked to push hot fixes to these bugs as quickly as possible and in a way that wouldn't delay Muse's launch, leading to what they described as "half-baked protections being rushed out to enable the launch. Many senior engineers believe it's inevitable we're going to have a massive data breach as a result of Hatch." Muse is called "Hatch" internally and in Meta's codebase.

Submission + - Meta Rushed to Fix Muse 'VM Escape' Vulnerability Soon Before Launch (404media.co)

An anonymous reader writes: In the immediate weeks before Muse’s launch, Meta engineers found several security vulnerabilities in the company’s viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse’s intended environment and access Meta’s own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them. These specific vulnerabilities were discovered before the launch of the product but required a multi-team “mad dash” to fix “a sudden spike in reported KVM escapes,” according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that they own. On Meta’s end, each individual Muse instance runs on a kernel-based virtual machine, which connects to, but is supposed to be isolated from, Meta’s own critical infrastructure. A “KVM escape,” then, is when, through a security vulnerability, a Muse instance is able to escape from that virtual machine and interact with the system that runs it, or with other users’ virtual machines.

According to a Meta source, as well as internal security documentation and internal posts viewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker — that is, a normal Muse user — to access data in sensitive internal Meta databases. At least one of the vulnerabilities was related to an exploit found in Linux kernel-based virtual machine code in July. 4 Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses for Muse. The security issue was considered serious enough that it was raised to Mark Zuckerberg, and several different security teams worked nights and weekends in the leadup to launch to fix the issues. [...] The Meta source said they felt security teams were asked to push hot fixes to these bugs as quickly as possible and in a way that wouldn’t delay Muse’s launch, leading to what they described as “half-baked protections being rushed out to enable the launch. Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch.” Muse is called “Hatch” internally and in Meta’s codebase.

Comment Re:Directionally Right, Specifically Wrong. (Score 1) 129

Understanding cost in the external world requires having a good model of the external world. The current LLMs, IIUC, don't have such a model. They have models of interacting words. It's truly amazing that they can do as much with that as they can, but don't over-read it.

OTOH, other AIs *do* have a world model. Most of those aren't full LLMs though. But even those don't really have a good model of other non-electronic entities. Think of self-driving cars, or robots practicing dance routines. These have a world model, but don't really have lots of other info that LLMs typically have. And even those don't have good models of people or dogs, and how they feel when something happens to them. But for LLMs, the real world *is* their electronic sensations. Words are patterns associated with those sensations. But no "body in the world" is involved in the model.

Privacy

Norway Plans Temporary Ban on Smart Glasses (theguardian.com) 30

Norway is preparing legislation that would temporarily ban camera-equipped smart glasses in a range of public places, including parks, beaches, museums, shopping centers, schools, daycare centers, healthcare facilities, gyms and public events. Private use would still be allowed. The Guardian reports: Torgeir Micaelsen, Norway's minister of digital affairs, said he was worried that new, powerful technology is being introduced where people risk being photographed, filmed or audio-recorded without knowing it."

"We do not want a society where people worry about being recorded without their knowledge, photographed or filmed in places and situations where they are accustomed to not being monitored," he said.

Norway's Labour party, which heads a minority government, needs the support of other parties to pass the proposed ban. It said it planned to submit a bill "as soon as possible," while tasking an expert group with drawing up permanent regulations on the issue.

Data Storage

Mac Users Reclaim 12GB+ of Storage With Apple Intelligence Removal Tool (macrumors.com) 34

A new open-source command-line tool called RemoveMacAI lets macOS 27 users disable Apple Intelligence and reclaim around 12GB or more of storage. MacRumors reports: In macOS 27, Apple removed the toggle to disable Apple Intelligence wholesale, and simply disabling individual features doesn't remove the models from your Mac's drive. As explained by the developer, RemoveMacAI gets around this by using a configuration profile to switch off Apple's own asset management service and remove the models.

It then configures the system so attempts to download the removed models are redirected to a closed local port, preventing them from immediately coming back. And it does all this without disabling System Integrity Protection (SIP) or manually deleting files from protected system locations, unlike some older tools have. The tool can free up roughly 12GB of space depending on which models are present on your Mac. That said, some users are reporting cases of Apple Intelligence models having taken up a lot more space, which they've now reclaimed.

Slashdot Top Deals

No hardware designer should be allowed to produce any piece of hardware until three software guys have signed off for it. -- Andy Tanenbaum

Working...