Autonomes Fahren: BMW kombiniert Staupilot mit freihändigem Fahren

Bislang gab es keine Autos, die freihändiges Fahren auf der Autobahn in Kombination mit Level 3 ermöglichen. BMW hat nun die Zulassung erhalten. (Autonomes Fahren, Softwareentwicklung)

Bislang gab es keine Autos, die freihändiges Fahren auf der Autobahn in Kombination mit Level 3 ermöglichen. BMW hat nun die Zulassung erhalten. (Autonomes Fahren, Softwareentwicklung)

Anzeige: Von Java zu Kotlin – der Weg zu effizientem Code-Design

Von der besseren Lesbarkeit bis zur effizienteren Fehlervermeidung bringt die Umstellung auf Kotlin viele Vorteile. Das notwendige Wissen zum Ein- und Umstieg vermitteln zwei Online-Workshops der Golem Karrierewelt. (Golem Karrierewelt, Java)

Von der besseren Lesbarkeit bis zur effizienteren Fehlervermeidung bringt die Umstellung auf Kotlin viele Vorteile. Das notwendige Wissen zum Ein- und Umstieg vermitteln zwei Online-Workshops der Golem Karrierewelt. (Golem Karrierewelt, Java)

Sir Peter Beck unplugged: “Transporter can do it for free for all we care”

“Look, there’s no accidental monopoly. They are a ruthless competitor.”

Rocket Lab CEO Peter Beck speaks during the opening of the new Rocket Lab factory on October 12, 2018, in Auckland, New Zealand.

Enlarge / Rocket Lab CEO Peter Beck speaks during the opening of the new Rocket Lab factory on October 12, 2018, in Auckland, New Zealand. (credit: Phil Walter/Getty Images)

Peter Beck has been having a pretty great June. Earlier this month, he was made a Knight Companion of the New Zealand Order of Merit. Then, Sir Peter Beck presided as Rocket Lab launched its 50th Electron rocket, becoming the fastest company to launch its 50th privately developed booster.

Finally, last week, Rocket Lab revealed that it had signed its largest launch contract ever: 10 flights for the Japanese Earth-observation company Synspective. Ars caught up with Beck while he was in Tokyo for the announcement. What follows is a lightly edited transcript of our conversation, which touches on a variety of launch-related issues.

Ars Technica: Hi Pete. We've talked about competition in small launch for years. But when I tally up the record of some of your US competitors—Firefly, Astra, Relativity Space, Virgin Orbit, and ABL—they're 7-for-21 on launch attempts. And if you remove the now-retired rockets, it's 1-for-6. Some of these competitors have, or did, exist for a decade. What does this say about the launch business?

Read 33 remaining paragraphs | Comments

Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

Malicious updates available from WordPress.org create attacker-controlled admin account.

Stylized illustration a door that opens onto a wall of computer code.

Enlarge (credit: Getty Images)

WordPress plugins running on as many as 36,000 websites have been backdoored in a supply-chain attack with unknown origins, security researchers said on Monday.

So far, five plugins are known to be affected in the campaign, which was active as recently as Monday morning, researchers from security firm Wordfence reported. Over the past week, unknown threat actors have added malicious functions to updates available for the plugins on WordPress.org, the official site for the open source WordPress CMS software. When installed, the updates automatically create an attacker-controlled administrative account that provides full control over the compromised site. The updates also add content designed to goose search results.

Poisoning the well

“The injected malicious code is not very sophisticated or heavily obfuscated and contains comments throughout making it easy to follow,” the researchers wrote. “The earliest injection appears to date back to June 21st, 2024, and the threat actor was still actively making updates to plugins as recently as 5 hours ago.”

Read 6 remaining paragraphs | Comments

Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

Malicious updates available from WordPress.org create attacker-controlled admin account.

Stylized illustration a door that opens onto a wall of computer code.

Enlarge (credit: Getty Images)

WordPress plugins running on as many as 36,000 websites have been backdoored in a supply-chain attack with unknown origins, security researchers said on Monday.

So far, five plugins are known to be affected in the campaign, which was active as recently as Monday morning, researchers from security firm Wordfence reported. Over the past week, unknown threat actors have added malicious functions to updates available for the plugins on WordPress.org, the official site for the open source WordPress CMS software. When installed, the updates automatically create an attacker-controlled administrative account that provides full control over the compromised site. The updates also add content designed to goose search results.

Poisoning the well

“The injected malicious code is not very sophisticated or heavily obfuscated and contains comments throughout making it easy to follow,” the researchers wrote. “The earliest injection appears to date back to June 21st, 2024, and the threat actor was still actively making updates to plugins as recently as 5 hours ago.”

Read 6 remaining paragraphs | Comments

iOS and iPadOS 18 add the option to format external drives

The beta’s Files app lets you format external drives in APFS, exFat, and FAT.

The back of an iPad on a table

Enlarge / The 2024 iPad Pro. (credit: Samuel Axon)

Apple has added the ability to format external drives in iOS 18 and iPadOS 18, the major software updates for iPhones and iPads due later this year.

While the feature likely won't be tapped by all that many users, its inclusion is fascinating in that it shows just how far Apple has moved away from its original sensibilities with the iPhone and the iPad.

The feature was discovered in the iPadOS 18 beta by artist and developer Kaleb Cadle, who posted about it to his Substack ByteBits a couple of days ago. It was later found in iOS 18 as well.

Read 6 remaining paragraphs | Comments

IPTV Playlist Portal Survives DMCA Takedown From Warner Bros.

Warner Bros. asked GitHub to remove a popular IPTV playlist linking portal. The Hollywood major requested the page to be removed as it referred to allegedly infringing Warner channels, including HBO and Cartoon Network. Faced with a potential takedown, the owners of the site swiftly removed all Warner Bros. content from the site. At the time of writing, it remains online.

From: TF, for the latest news on copyright battles, piracy and more.

The M3U file format has been around for more than a quarter-century. In essence, it links to a streamable media file that can be loaded through media players.

In the early days, it was predominantly used to stream Internet radio though Winamp and other media players. While the format is still used for that today, M3U files have enjoyed a resurgence as a video streaming tool in recent years.

The M3U file format is content-neutral, but many people are using it to share IPTV streams, which are often redistributed without permission. Those who look hard enough can find access to pretty much any channel imaginable.

IPTV-org.github.io

One of the largest repositories of IPTV links is hosted through GitHub Pages. The site, iptv-org.github.io, has roughly a million monthly visits and lists more than 37,000 channels, many of which are streamable. Not all these streams are infringing, but some clearly are.

IPTV links

iptv

The maintainers of the site are aware of the potential copyright issues. However, they don’t see the links to M3U playlists as copyright infringements. Instead, they urge rightsholders to go after the providers that host these files.

“Note that linking does not directly infringe copyright because no copy is made on the site providing the link, and thus this is not a valid reason to send a DMCA notice to GitHub,” they explain.

This is an interesting take that could be worth defending in court. However, when torrent sites tried a similar defense in court, it failed, mainly because the infringing links are intentionally indexed, curated and categorized.

Warner Bros. Takedown

Warner Bros. already seems convinced that the links are infringing. A few days ago, the Hollywood studio sent a takedown notice to GitHub though its anti-piracy partner MarkScan, asking it to remove iptv-org.github.io in its entirety.

“Based on our investigation, we have determined that “iptv-org.github.io” is providing the Live TV channel of WBD illegally. This site is engaging in copyright piracy by providing unauthorized streams of digital content without the consent of the copyright owner,” the takedown notice reads.

Warner Bros. Takedown Notice

iptv-takedown

The takedown notice asks GitHub to remove or disable access to the infringing links. However, before taking any action, the developer platform nudged the maintainers of the site, allowing then resolve the matter on their own accord.

Self-Administered Takedown

GitHub allowed the developers one business day to remedy the Warner Bros. complaint. In this case, that means removing all WBD content, including HBO, Cartoon Network, and several Discovery channels.

GitHub’s Deadline

github deadline

While the developers previously suggested that these types of DMCA takedowns should not be valid, they didn’t file a counter notice. Instead, they swiftly identified all Warner Bros. and Discovery channels, to remove these from the site within the deadline.

“Successfully merging a pull request may close this issue,” an internal note reads, after which dozens of links were indeed removed.

The self-administered takedown appears to have been too broad initially, as several links – presumably unrelated to Warner Bros. – were later restored. However, the swift action appears to have saved the site.

remove add

GitHub typically publishes DMCA takedown notices after it has fully processed a matter, which often means that sites or repositories are removed. However, “iptv-org.github.io” is fully operational at the time of writing, minus the Warner Bros. content.

Warner Bros. had its takedown notice honored, as the infringing channels are no longer linked. However, instead of simply taking down the entire site, it became a ‘precision’ takedown, merely focusing on the content that it was supposed to target.

From: TF, for the latest news on copyright battles, piracy and more.

Microsoft removes documentation for switching to a local account in Windows 11

But most Microsoft account sign-in workarounds for Windows 11 continue to work.

A laptop PC running Windows 11 sitting next to a coffee mug.

Enlarge / A PC running Windows 11. (credit: Microsoft)

One of Windows 11's more contentious changes is that, by default, both the Home and Pro editions of the operating system require users to sign in with a Microsoft account during setup. Signing in with an account does get you some benefits, at least if you're a regular user of other Microsoft products like OneDrive, GamePass, or Microsoft 365 (aka Office). But if you don't use those services, a lot of what a Microsoft account gets you in Windows 11 is repeated ads and reminders about signing up for those services. Using Windows with a traditional local account is still extremely possible, but it does require a small amount of know-how beyond just clicking the right buttons.

On the know-how front, Microsoft has taken one more minor, but nevertheless irritating, step away from allowing users to sign in with local accounts. This official Microsoft support page walks users with local accounts through the process of signing in to a Microsoft account. As recently as June 12, that page also included instructions for converting a Microsoft account into a local account. But according to Tom's Hardware and the Internet Wayback Machine, those instructions disappeared on or around June 17 and haven't been seen since.

Despite the documentation change, most of the workarounds for creating a local account still work in both Windows 11 23H2 (the publicly available version of Windows 11 for most PCs) and 24H2 (available now on Copilot+ PCs, later this fall for everyone else). The easiest way to do it on a PC you just took out of the box is to press Shift+F10 during the setup process to bring up a command prompt window, typing OOBE\BYPASSNRO, rebooting, and then clicking the "I don't have Internet" button when asked to connect to a Wi-Fi network.

Read 3 remaining paragraphs | Comments