Connect with us

Sci-Tech

Did One Guy Just Stop a Huge Cyberattack?

Published

on


The internet, as anyone who works deep in its trenches will tell you, is not a smooth, well-oiled machine.

It’s a messy patchwork that has been assembled over decades, and is held together with the digital equivalent of Scotch tape and bubble gum. Much of it relies on open-source software that is thanklessly maintained by a small army of volunteer programmers who fix the bugs, patch the holes and ensure the whole rickety contraption, which is responsible for trillions of dollars in global G.D.P., keeps chugging along.

Last week, one of those programmers may have saved the internet from huge trouble.

His name is Andres Freund. He’s a 38-year-old software engineer who lives in San Francisco and works at Microsoft. His job involves developing a piece of open-source database software known as PostgreSQL, whose details would probably bore you to tears if I could explain them correctly, which I can’t.

Recently, while doing some routine maintenance, Mr. Freund inadvertently found a backdoor hidden in a piece of software that is part of the Linux operating system. The backdoor was a possible prelude to a major cyberattack that experts say could have caused enormous damage, if it had succeeded.

Now, in a twist fit for Hollywood, tech leaders and cybersecurity researchers are hailing Mr. Freund as a hero. Satya Nadella, the chief executive of Microsoft, praised his “curiosity and craftsmanship.” An admirer called him “the silverback gorilla of nerds.” Engineers have been circulating an old, famous-among-programmers web comic about how all modern digital infrastructure rests on a project maintained by some random guy in Nebraska. (In their telling, Mr. Freund is the random guy from Nebraska.)

In an interview this week, Mr. Freund — who is actually a soft-spoken, German-born coder who declined to have his photo taken for this story — said that becoming an internet folk hero had been disorienting.

“I find it very odd,” he said. “I’m a fairly private person who just sits in front of the computer and hacks on code.”

The saga began earlier this year, when Mr. Freund was flying back from a visit to his parents in Germany. While reviewing a log of automated tests, he noticed a few error messages he didn’t recognize. He was jet-lagged, and the messages didn’t seem urgent, so he filed them away in his memory.

But a few weeks later, while running some more tests at home, he noticed that an application called SSH, which is used to log into computers remotely, was using more processing power than normal. He traced the issue to a set of data compression tools called xz Utils, and wondered if it was related to the earlier errors he’d seen.

(Don’t worry if these names are Greek to you. All you really need to know is that these are all small pieces of the Linux operating system, which is probably the most important piece of open-source software in the world. The vast majority of the world’s servers — including those used by banks, hospitals, governments and Fortune 500 companies — run on Linux, which makes its security a matter of global importance.)

Like other popular open-source software, Linux gets updated all the time, and most bugs are the result of innocent mistakes. But when Mr. Freund looked closely at the source code for xz Utils, he saw clues that it had been intentionally tampered with.

In particular, he found that someone had planted malicious code in the latest versions of xz Utils. The code, known as a backdoor, would allow its creator to hijack a user’s SSH connection and secretly run their own code on that user’s machine.

In the cybersecurity world, a database engineer inadvertently finding a backdoor in a core Linux feature is a little like a bakery worker who smells a freshly baked loaf of bread, senses something is off and correctly deduces that someone has tampered with the entire global yeast supply. It’s the kind of intuition that requires years of experience and obsessive attention to detail, plus a healthy dose of luck.

At first, Mr. Freund doubted his own findings. Had he really discovered a backdoor in one of the world’s most heavily scrutinized open-source programs?

“It felt surreal,” he said. “There were moments where I was like, I must have just had a bad night of sleep and had some fever dreams.”

But his digging kept turning up new evidence, and last week, Mr. Freund sent his findings to a group of open-source software developers. The news set the tech world on fire. Within hours, some researchers were crediting him with preventing a potentially historic cyberattack.

“This could have been the most widespread and effective backdoor ever planted in any software product,” said Alex Stamos, the chief trust officer at SentinelOne, a cybersecurity research firm.

If it had gone undetected, Mr. Stamos said, the backdoor would have “given its creators a master key to any of the hundreds of millions of computers around the world that run SSH.” That key could have allowed them to steal private information, plant crippling malware, or cause major disruptions to infrastructure — all without being caught.

(The New York Times has sued Microsoft and its partner OpenAI on claims of copyright infringement involving artificial intelligence systems that generate text.)

Nobody knows who planted the backdoor. But the plot appears to have been so elaborate that some researchers believe only a nation with formidable hacking chops, such as Russia or China, could have attempted it.

According to some researchers who have gone back and looked at the evidence, the attacker appears to have used a pseudonym, “Jia Tan,” to suggest changes to xz Utils as far back as 2022. (Many open-source software projects are governed via hierarchy; developers suggest changes to a program’s code, then more experienced developers known as “maintainers” have to review and approve the changes.)

The attacker, using the Jia Tan name, appears to have spent several years slowly gaining the trust of other xz Utils developers and getting more control over the project, eventually becoming a maintainer, and finally inserting the code with the hidden backdoor earlier this year. (The new, compromised version of the code had been released, but was not yet in widespread use.)

Mr. Freund declined to guess who might have been behind the attack. But he said that whoever it was had been sophisticated enough to try to cover their tracks, including by adding code that made the backdoor harder to spot.

“It was very mysterious,” he said. “They clearly spent a lot of effort trying to hide what they were doing.”

Since his findings became public, Mr. Freund said, he had been helping the teams who are trying to reverse-engineer the attack and identify the culprit. But he’s been too busy to rest on his laurels. The next version of PostgreSQL, the database software he works on, is coming out later this year, and he’s trying to get some last-minute changes in before the deadline.

“I don’t really have time to go and have a celebratory drink,” he said.





Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Sci-Tech

Silicon Valley shaken as open-source AI models Llama 3.1 and Mistral Large 2 match industry leaders

Published

on


Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More


Open-source artificial intelligence has reached a watershed moment, challenging the long-held dominance of proprietary systems and promising to reshape the AI landscape.

This week, two significant developments have propelled open-source AI models to the forefront of technological capability, potentially democratizing access to cutting-edge AI tools.

On Tuesday, Mark Zuckerberg, chief executive of Meta, unveiled Llama 3.1, declaring it had achieved “frontier-level” status.

This bold claim suggests that Meta’s freely available AI now rivals the most advanced systems from industry leaders like OpenAI, Google, and Anthropic.

Just a day later, Mistral, an emerging French AI lab, released Mistral Large 2, a model that reportedly matches or surpasses existing top-tier systems, particularly in multilingual applications.

These back-to-back releases mark a pivotal shift in the AI world. For years, tech giants have jealously guarded their most powerful AI models, citing concerns over safety, potential misuse, and competitive advantage.

This week’s developments have shattered that paradigm, igniting debates about equity, innovation, and the ethical implications of democratizing such transformative technology.

Industry experts are hailing this week’s developments as a potential turning point in AI history, comparable to pivotal moments that have sparked technological revolutions in the past.

The sudden availability of frontier-level open-source models is expected to dramatically accelerate AI development globally, potentially reshaping entire industries and altering the balance of power in the tech world.

This rapid democratization of cutting-edge AI capabilities could usher in a new era of innovation and competition, with far-reaching consequences for businesses, researchers, and society at large.

Open-source challengers shake up the AI status quo

The implications of this week’s announcements are far-reaching. Smaller companies and individual developers can now access sophisticated AI capabilities without the hefty price tags or vendor lock-in associated with proprietary systems. This democratization could fuel an unprecedented wave of innovation, as diverse minds from around the globe contribute to and build upon these powerful tools.

However, the widespread availability of advanced AI also raises new challenges. Organizations must now grapple with how to differentiate themselves in a world where cutting-edge AI capabilities are becoming commoditized. The onus falls on business leaders and technical decision-makers to rapidly develop strategies that leverage these open technologies while adding unique value.

The geopolitical ramifications of this shift are equally significant. As AI becomes increasingly central to national competitiveness, the proliferation of open-source models could alter the global balance of power in technology. Countries and regions that effectively harness these openly available resources may gain significant advantages in AI development and application.

A double-edged sword: The thrilling and terrifying dawn of AI for all

Despite the excitement, skeptics urge caution in accepting claims of parity with top proprietary models at face value.

The AI field is known for its rapid advancements and shifting benchmarks, making “frontier-level” a moving target. Moreover, raw model capability is just one factor in AI system effectiveness; data quality, fine-tuning, and application-specific optimizations play crucial roles in real-world performance.

The abrupt open-sourcing of frontier-level AI also intensifies ongoing debates about AI safety and ethics. While transparency can aid in identifying and addressing biases or vulnerabilities, it may also lower barriers for malicious actors seeking to exploit these powerful tools. The AI community now faces the urgent challenge of striking a delicate balance between openness and responsible development.

For policymakers, this week’s developments underscore the critical need for adaptive regulatory frameworks that can keep pace with technological advancements while ensuring public safety and ethical use of AI. The tech industry may need to rapidly reevaluate business models and competitive strategies in a landscape where cutting-edge AI capabilities have suddenly become widely accessible.

Navigating the new frontier: Collaboration, ethics, and the future of AI

As the dust settles on this landmark week, the true impact of these milestones will be determined by how effectively the global community harnesses the potential of open-source AI while mitigating its risks.

The sudden democratization of frontier-level AI has the potential to accelerate innovation, reshape industries, and fundamentally alter our relationship with artificial intelligence.

In this new era, collaboration and ethical considerations will be paramount. The open-source AI revolution promises to unlock unprecedented possibilities, but it also demands a heightened sense of responsibility from developers, businesses, and society as a whole.

As we navigate this transformative period, one thing is clear: the future of AI is becoming more open, more accessible, and more participatory than ever before, and the pace of change is accelerating rapidly.



Source link
Continue Reading

Sci-Tech

ISPs are fighting to raise the price of low-income broadband

Published

on


A new government program is trying to encourage Internet service providers (ISPs) to offer lower rates for lower income customers by distributing federal funds through states. The only problem is the ISPs don’t want to offer the proposed rates.

 obtained a letter sent to US Commerce Secretary Gina Raimondo signed by more than 30 broadband industry trade groups like ACA Connects and the Fiber Broadband Association as well as several state based organizations. The letter raises “both a sense of alarm and urgency” about their ability to participate in the Broadband Equity, Access and Deployment (BEAD) program. The newly formed BEAD program provides over $42 billion in federal funds to “expand high-speed internet access by funding planning, infrastructure, deployment and adoption programs” in states across the country, according to the (NTIA).

The money first goes to the NTIA and then it’s distributed to states after they obtain approval from the NTIA by presenting a low-cost broadband Internet option. The ISP industries’ letter claims a fixed rate of $30 per month for high speed Internet access is “completely unmoored from the economic realities of deploying and operating networks in the highest-cost, hardest-to-reach areas.”

The letter urges the NTIA to revise the low-cost service option rate proposed or approved so far. have completed all of the BEAD program’s phases.

Americans pay an average of $89 a month for Internet access. New Jersey has the highest average bill at $126 per month, according to a survey conducted by . A 2021 study from the found that 57 percent of households with an annual salary of $30,000 or less have a broadband connection.



Source link

Continue Reading

Sci-Tech

These transparent earbuds by Nothing made my AirPods look and sound boring

Published

on


A hand holding the Nothing Ear (a) earbuds

Nina Raemont/ZDNET

ZDNET’s key takeaways 

  • For $99, the new Nothing Ear (a) earbuds offer clear sound and a thoughtful design. 
  • Their affordability, comfort, and long battery life make them a great option for budget-conscious shoppers.
  • Unfortunately, its middling noise-canceling tech doesn’t protect you from external noises. 

Most of the audio tech on the market right now errs on the side of aesthetic caution. I’ve tested plenty of earbuds this year, and something I’ve noticed is that many manufacturers sacrifice style for functionality, opting for blacks, grays, and enough matte finishes to fit inside a therapist’s office — much to my chagrin. In the words of the late, great Andre Leon Talley, “it’s a famine of beauty” over here.  

Also: Why I ditched my AirPods Pro for Nothing’s new transparent earbuds (and don’t regret it)

So when Nothing sent me its new earbuds, I was excited to finally see a cool, fresh, and exciting design, and they’re worthy of a callout. I’ve been testing the new Nothing Ear (a) earbuds since launch, taking them on a ten-mile run, working deskside, and commuting on the subway with them in my ears. One question that informed my initial testing was: Despite their stylish design, how does the audio tech stack up to similarly-priced competitors?

View at Amazon

The Nothing Ear (a) advances on the specs from the brand’s Ear (1) earbuds from 2021. The new buds offer plenty of upgrades like improved active noise cancellation, transparency mode, longer battery life, Bluetooth multipoint, minimized latency for gaming, and pinch controls.

Also: The best earbuds of 2024: Expert tested and reviewed

Nothing plays with solid color and transparent accents and puts the two at the forefront of its product design. You can’t help but obsess over the brand’s unique visual appeal: a stripped-down design that reveals the inner workings of the technology cast against bold colors. The clear design of both the earbud case and the earbuds itself offers users an inside look into the tech’s internal components and an appreciation for what is often obscured. 

Nothing Ear (a) on a table

Nina Raemont/ZDNET

The earbuds come with three ear tip sizes in the box and are available in three colors: black, white, and yellow. I tried these buds in yellow, which is the first non-neutral color in Nothing’s earbud lineup. The color feels daring and bright and is just as much a fashion accessory as it is a tech accessory. 

Other competitive earbuds can’t say the same: I looked at my list of best earbuds to see if there was any color diversity and found that every top earbuds I’ve included are either black, a muted white, or white, from Sony’s WF-1000XM5 and JBL’s Tour Pro 2, to Bose’s QuietComfort Ultra and Apple’s AirPods Pro. These earbuds, on the other hand, are like the AirPods Pro’s funkier younger sister who went to art school, buys gifts for friends through the MOMA Store, and can explain the difference between white and orange wine to you. 

The case is lightweight and compact, so it won’t be obstructive or heavy in your pocket. The earbuds themselves are comfortable and easy to wear, with an extra tactile ear tip that keeps the buds attached to your ear canal as you move around. Nothing also equipped these buds with Bluetooth multipoint and in-ear detection when you wear these, two nice touches that inexpensive earbuds occasionally lack. 

Also: The best earbuds I’ve ever listened to are not by Bose or Sony

I ran for five hours and worked and commuted with these earbuds for a week straight and still have a battery life of 80%. Needless to say, these earbuds won’t die easily on you. 

Nothing Ear (a) held up to a mirror

Nina Raemont/ZDNET

One of my favorite design choices with the Ear (a) is that the controls are dictated by pinches instead of taps and swipes, similar to the AirPods Pro 2. Most earbuds that I’ve tested with the same form factor have touch controls on the top of the ear stem where the bud meets the stem. I always run with earbuds in, and when my ears get too sweaty, and my earbuds begin to slip out, I accidentally touch and activate the touch controls when I’m attempting to press the bud back into my ears.

Also: The best earbuds under $100

Nothing eliminated this problem for me, as the touch controls are at the bottom of the stem, far away from accidental touches. Despite needing a pinch to activate the controls, they are reliable and responsive. The pinch controls allow you to play and pause music, skip tracks, and toggle between ANC and transparency mode.

Speaking of ANC, this feature is where the Ear (a) buds begin to show their affordable price. I turned on the ANC while I worked in the office, and I could still hear my colleagues’ computer notification pings and conversations around me. For $109, I wasn’t expecting mind-blowing ANC, and that’s certainly not what I got. The earbuds will drown out some noise, but you’ll have to pay a higher price for premium ANC.

Review: Nothing Ear Stick: Earbuds, but make it fashion

When it comes to the actual audio quality, however, these earbuds produce a balanced, clear, and bright sound. While listening to Moses Sumney and Shabaka’s Insecurities, the harp and flute whistles in the upper midrange shimmered in my ears without being too harsh. Bass-heavy songs can get an extra boost by tweaking the Bass Enhance algorithm in the Nothing app. While listening to Kaytranada’s What You Need, I toggled between the five levels of bass enhancement to boost the lower frequencies. This feature created a noticeably different sound with deeper, richer bass. 

ZDNET’s buying advice 

The Nothing Ear (a) are best for people who want a relatively affordable pair of earbuds with thoughtful functions and a unique design.

If you want earbuds with more effective noise-canceling for a similar price, consider the JLab JBuds ANC 3 for their strong noise-canceling and snug fit. If you like Nothing’s unique and charming design choices but want better sound, more effective ANC, and more premium features, try the Nothing Ear.





Source link

Continue Reading
Advertisement

Trending

Copyright © 2024 World Daily Info. Powered by Columba Ventures Co. Ltd.