Daily Deals (10-25-2023)

The GMK NucBox G3 is a 4.5″ x 4.2″ x 1.7″ desktop computer with a 6-watt Intel Processor N100 quad-core chip, support for up to 32GB of RAM and 2TB of PCIe solid state storage. When the little computer first launched earlier this mon…

The GMK NucBox G3 is a 4.5″ x 4.2″ x 1.7″ desktop computer with a 6-watt Intel Processor N100 quad-core chip, support for up to 32GB of RAM and 2TB of PCIe solid state storage. When the little computer first launched earlier this month, prices started at $180 for a model with 8GB of RAM […]

The post Daily Deals (10-25-2023) appeared first on Liliputing.

Hackers can force iOS and macOS browsers to divulge passwords and much more

iLeakage is practical and requires minimal resources. A patch isn’t (yet) available.

Hackers can force iOS and macOS browsers to divulge passwords and much more

Enlarge (credit: Kim et al.)

Researchers have devised an attack that forces Apple’s Safari browser to divulge passwords, Gmail message content, and other secrets by exploiting a side channel vulnerability in the A- and M-series CPUs running modern iOS and macOS devices.

iLeakage, as the academic researchers have named the attack, is practical and requires minimal resources to carry out. It does, however, require extensive reverse-engineering of Apple hardware and significant expertise in exploiting a class of vulnerability known as a side channel, which leaks secrets based on clues left in electromagnetic emanations, data caches, or other manifestations of a targeted system. The side channel in this case is speculative execution, a performance enhancement feature found in modern CPUs that has formed the basis of a wide corpus of attacks in recent years. The nearly endless stream of exploit variants has left chip makers—primarily Intel and, to a lesser extent, AMD—scrambling to devise mitigations.

Exploiting WebKit on Apple silicon

The researchers implement iLeakage as a website. When visited by a vulnerable macOS or iOS device, the website uses JavaScript to surreptitiously open a separate website of the attacker’s choice and recover site content rendered in a pop-up window. The researchers have successfully leveraged iLeakage to recover YouTube viewing history, the content of a Gmail inbox—when a target is logged in—and a password as it’s being autofilled by a credential manager. Once visited, the iLeakage site requires about five minutes to profile the target machine and, on average, roughly another 30 seconds to extract a 512-bit secret, such as a 64-character string.

Read 18 remaining paragraphs | Comments

Microtargeting: EU-Kommissarin lässt Werbekampagne zur Chatkontrolle prüfen

Hat die EU-Kommission mit einer Onlinekampagne zur Chatkontrolle gegen ihre eigenen Gesetze verstoßen? Kommissarin Johansson schließt das nicht mehr aus. (Chatkontrolle, Verschlüsselung)

Hat die EU-Kommission mit einer Onlinekampagne zur Chatkontrolle gegen ihre eigenen Gesetze verstoßen? Kommissarin Johansson schließt das nicht mehr aus. (Chatkontrolle, Verschlüsselung)

Honda says making cheap electric vehicles is too hard, ends deal with GM

The platform was to use GM’s Ultium batteries.

Ultium batteries and components Monday, December 13, 2021 at the General Motors Brownstown Battery facility in Brownstown Charter Township, Michigan. (Photo by Santa Fabio for General Motors)

Enlarge / A GM Ultium battery pack. (credit: Santa Fabio for General Motors)

Bad news for fans of cheaper electric vehicles: The planned collaboration between Honda and General Motors on a range of cheaper EVs has been canceled. The joint project, which was announced in April 2022, was supposed to develop a new platform for use in lower-cost EVs for North America, South America, and China, with cars appearing in 2027. But on Thursday, the two companies revealed that the plan is no more.

"After extensive studies and analysis, we have come to a mutual decision to discontinue the program. Each company remains committed to affordability in the EV market," Honda and GM said in a joint statement.

"After studying this for a year, we decided that this would be difficult as a business, so at the moment we are ending development of an affordable EV," said Honda CEO Toshihiro Mibe in an interview with Bloomberg. "GM and Honda will search for a solution separately. This project itself has been canceled," Mibe said.

Read 8 remaining paragraphs | Comments

“Do not open robots,” warns Oregon State amid college food delivery bomb prank

OSU officials isolate food robots after bomb threat, later resolved with an arrest.

A 2020 file photo of a Starship Technologies food delivery robot.

Enlarge / A 2020 file photo of a Starship Technologies food delivery robot. Food is stored inside the robot's housing during transportation and opened upon delivery. (credit: Leon Neal/Getty Images)

On Tuesday, officials at Oregon State University issued a warning on social media about a bomb threat concerning Starship Technologies food delivery robots, autonomous wheeled drones that deliver food orders stored within a built-in container. By 7 pm local time, a suspect had been arrested in the prank, and officials declared there had been no bombs hidden within the robots.

"Bomb Threat in Starship food delivery robots," reads the 12:20 pm initial X post from OSU. "Do not open robots. Avoid all robots until further notice." In follow-up posts, OSU officials said they were "remotely isolating robots in a safe location" for investigation by a technician. By 3:54 pm local time, experts had cleared the robots and promised they would be "back in service" by 4 pm.

In response, Starship Technologies provided this statement to the press: "A student at Oregon State University sent a bomb threat, via social media, that involved Starship’s robots on the campus. While the student has subsequently stated this is a joke and a prank, Starship suspended the service. Safety is of the utmost importance to Starship and we are cooperating with law enforcement and the university during this investigation."

Read 2 remaining paragraphs | Comments

LPDDR5-9600 smartphone memory is coming

Next year’s flagship smartphones could be the first to feature LPDDR5 memory with support for data transfer speeds up to 9.6 TB/s, or 9600 Mbit/s. Micron and SK Hynix have each announced that their next-gen memory solutions are designed to work …

Next year’s flagship smartphones could be the first to feature LPDDR5 memory with support for data transfer speeds up to 9.6 TB/s, or 9600 Mbit/s. Micron and SK Hynix have each announced that their next-gen memory solutions are designed to work in devices powered by Qualcomm’s new Snapdragon 8 Gen 3 processor. The SKY Hynix […]

The post LPDDR5-9600 smartphone memory is coming appeared first on Liliputing.

California suspends Cruise robotaxis after car dragged pedestrian 20 feet

Horrifying hit-and-run triggers California suspension of Cruise robotaxis.

California suspends Cruise robotaxis after car dragged pedestrian 20 feet

Enlarge (credit: Bloomberg / Contributor | Bloomberg)

Less than three months after the California Public Utilities Commission approved robotaxi-service Cruise's plan to provide around-the-clock driverless rides to passengers in San Francisco, the California Department of Motor Vehicles (DMV) has shut down Cruise's driverless operations in the state.

Yesterday, the California DMV suspended Cruise's permits for autonomous vehicle deployment and driverless testing "effective immediately" over pedestrian safety concerns.

"Public safety remains the California DMV’s top priority, and the department’s autonomous vehicle regulations provide a framework to facilitate the safe testing and deployment of this technology on California public roads," the DMV's announcement said. "When there is an unreasonable risk to public safety, the DMV can immediately suspend or revoke permits."

Read 11 remaining paragraphs | Comments

Sam Bankman-Fried may testify in hopes of avoiding life in prison

After lots of damaging testimony, reports say former FTX boss will take the stand.

Sam Bankman-Fried’s former flatmates (from top) Caroline Ellison, NIshad Singh and Gary Wang have given evidence against him

Enlarge / Sam Bankman-Fried’s former flatmates (from top) Caroline Ellison, NIshad Singh and Gary Wang have given evidence against him (credit: FT montage/Bloomberg/AP)

Early last summer, Adam Yedidia took Sam Bankman-Fried to one side after a game of paddle tennis. In the shadow of a hut in the grounds of the Bahamian penthouse they and others shared, he asked the crypto tycoon: “Are we OK?”

Yedidia told a New York court this month that he was worried FTX, the crypto exchange that Bankman-Fried had co-founded and at that time led, was in financial trouble. He recounted his old friend’s reply: “We were bulletproof last year, but we’re not bulletproof this year.”

FTX collapsed a few months later, sending shockwaves through the cryptocurrency industry. US prosecutors hope this chat, which they have taken to calling the “bulletproof conversation,” will help to show Bankman-Fried knew about, and concealed, an $8 billion cash shortfall for months at least before it was exposed.

Read 13 remaining paragraphs | Comments