×
Privacy

Data Broker's 'Staggering' Sale of Sensitive Info Exposed in Unsealed FTC Filing (arstechnica.com) 30

One of the world's largest mobile data brokers, Kochava, has lost its battle to stop the Federal Trade Commission from revealing what the FTC has alleged is a disturbing, widespread pattern of unfair use and sale of sensitive data without consent from hundreds of millions of people. ArsTechnica: US District Judge B. Lynn Winmill recently unsealed a court filing, an amended complaint that perhaps contains the most evidence yet gathered by the FTC in its long-standing mission to crack down on data brokers allegedly "substantially" harming consumers by invading their privacy. The FTC has accused Kochava of violating the FTC Act by amassing and disclosing "a staggering amount of sensitive and identifying information about consumers," alleging that Kochava's database includes products seemingly capable of identifying nearly every person in the United States.

According to the FTC, Kochava's customers, ostensibly advertisers, can access this data to trace individuals' movements -- including to sensitive locations like hospitals, temporary shelters, and places of worship, with a promised accuracy within "a few meters" -- over a day, a week, a month, or a year. Kochava's products can also provide a "360-degree perspective" on individuals, unveiling personally identifying information like their names, home addresses, phone numbers, as well as sensitive information like their race, gender, ethnicity, annual income, political affiliations, or religion, the FTC alleged.

Beyond that, the FTC alleged that Kochava also makes it easy for advertisers to target customers by categories that are "often based on specific sensitive and personal characteristics or attributes identified from its massive collection of data about individual consumers." These "audience segments" allegedly allow advertisers to conduct invasive targeting by grouping people not just by common data points like age or gender, but by "places they have visited," political associations, or even their current circumstances, like whether they're expectant parents. Or advertisers can allegedly combine data points to target highly specific audience segments like "all the pregnant Muslim women in Kochava's database," the FTC alleged, or "parents with different ages of children."

Intel

Intel To Build 'Secure Enclave' Chip Facilities For Defense Applications (siliconangle.com) 21

According to the Wall Street Journal, Intel may receive billions in U.S. government funding to build secret facilities that produce microchips for the military. SiliconANGLE reports: The facilities, which have not yet been disclosed, would be designated as a "secure enclave" to reduce the military's dependence on chips imported from East Asia, particularly Taiwan, which is at risk of a future invasion from China. The funding for the new facilities would come from the $52.7 billion allocated under the Chips Act, signed into law by President Biden in August 2022. The Chips Act, which had bipartisan support, promotes chipmaking and scientific research through funding and tax credits. The law is aimed at encouraging domestic manufacturing of semiconductors and helping U.S. companies compete with China in developing cutting-edge technologies.

The new Intel facilities, presuming they go ahead, could reside partly at Intel's Arizona factory complex, according to sources referenced in the Journal report. The exact amount of funding that will be made available is not yet known, but "people familiar with the situation" tell the Journal that they could cost about $3 billion to $4 billion, which would come from the $39 billion set aside in the Chips Act for manufacturing grants. Officials from the Commerce Department, the Office of the Director of National Intelligence and the Defense Department are said to be negotiating the project with Intel but have not yet made a final decision.

The first manufacturing grants under the Chip Act are expected to be announced in the coming weeks. The program was reported to have had more than 500 entities express interest and more than 130 have submitted applications or pre-applications for funding.

United Kingdom

Tech Groups Fear New Powers Will Allow UK To Block Encryption (ft.com) 40

Tech groups have called on ministers to clarify the extent of proposed powers that they fear would allow the UK government to intervene and block the rollout of new privacy features for messaging apps. FT: The Investigatory Powers Amendment Bill, which was set out in the King's Speech on Tuesday, would oblige companies to inform the Home Office in advance about any security or privacy features they want to add to their platforms, including encryption. At present, the government has the power to force telecoms companies and messaging platforms to supply data on national security grounds and to help with criminal investigations.

The new legislation was designed to "recalibrate" those powers to respond to risks posed to public safety by multinational tech companies rolling out new services that "preclude lawful access to data," the government said. But Meredith Whittaker, president of private messaging group Signal, urged ministers to provide more clarity on what she described as a "bellicose" proposal amid fears that, if enacted, the new legislation would allow ministers and officials to veto the introduction of new safety features. "We will need to see the details, but what is being described suggests an astonishing level of technically confused government over-reach that will make it nearly impossible for any service, homegrown or foreign, to operate with integrity in the UK," she told the Financial Times.

Crime

'Encryption King' Arrested In Turkey (404media.co) 31

An anonymous reader quotes a report from 404 Media: Hakan Ayik, an infamous drug trafficker who also popularized the use of certain brands of encrypted phones around the world, was arrested during a series of dramatic raids in Turkey last week. At one point a group of heavily armed Turkish tactical officers in brown and gray camouflage piled outside an apartment and banged on the door repeatedly. They then smashed the door down and moved inside with a riot shield, according to a video tweeted by Turkey's Minister of the Interior. The video then showed a photograph of Ayik, shirtless and on his knees while staring straight ahead, surrounded by multiple officers.

It was a moment that capped off the arrest of Australia's most wanted man, and a sign that Turkey is no longer a safe haven to organized criminals. But it was also something of a closing act on Anom, a brand of encrypted phone that the FBI secretly took over and managed for years after inserting a backdoor into the product, allowing agents to read tens of millions of messages sent across it. Ayik unknowingly helped the FBI gain that piercing insight into organized crime by selling the devices to other criminal associates. Given Ayik's position as a trusted authority on what communications tools drug traffickers should use, one associate even referred to him as the 'encryption king' in an Anom message I've seen.
According to the Sydney Morning Herald, Ayik will not be extradited to Australia. Instead, Australian police are encouraging Turkish authorities to investigate and prosecute him as a Turkish citizen.
The Military

US Military Members' Personal Data Being Sold By Online Brokers, Report Finds 32

Jacob Knutson reports via Axios: Sensitive, highly detailed personal data for thousands of active-duty and veteran U.S. military members can be purchased for as little as one cent per name through data broker websites, according to a new study (PDF) published on Monday by Duke University researchers. [...] The data about military personnel purchased as part of the study included full names, physical and email addresses, health and financial information and details about their ethnicity, religious practices and political affiliation. In some cases, the information also included whether the person owned or rented a home, was married or had children. The children's ages and sexes were accessible, too.

The researchers bought data on up to around 45,000 military personnel for between $0.12 to $0.32 per record. They also bought data belonging to 5,000 friends and family members of military personnel. Larger data purchases of over 1.5 million service members were available for as little as $0.01 per record from at least one broker the researchers contacted. The researchers called on Congress to pass a comprehensive privacy law and for regulatory agencies like the Federal Trade Commission to develop rules to govern military personnel data purchases.
Transportation

Washington DC Gives Residents Free AirTags To Help Track Stolen Cars (pcmag.com) 110

The city of Washington D.C. is planning to give residents Apple AirTags to help officers track down stolen vehicles. PCMag reports: "Last week, we introduced legislation to address recent crime trends; this week, we are equipping residents with technology that will allow MPD to address these crimes, recover vehicles, and hold people accountable," D.C. Mayor Muriel Bowser said in a statement. "We have had success with similar programs where we make it easier for the community and MPD to work together -- from our Private Security Camera Incentive Program to the wheel lock distribution program -- and we will continue to use all the tools we have, and add new tools, to keep our city safe."

At launch, the AirTags will be available to residents in specific areas of the city that have recently seen the largest increase in vehicle thefts. To obtain the tags, residents will have to attend one of three scheduled distribution events next week where officers will install the device on the resident's cars and help them set up the tracking tag on their mobile devices. The program is currently available for residents who live in Police Service Areas 106, 501, 502, 603, 605, and 606. Check where you live on the MPD's website.

AI

OpenAI Offers To Pay For ChatGPT Customers' Copyright Lawsuits (theguardian.com) 27

Blake Montgomery reports via The Guardian: Rather than remove copyrighted material from ChatGPT's training dataset, the chatbot's creator is offering to cover its clients' legal costs for copyright infringement suits. OpenAI CEO Sam Altman said on Monday: "We can defend our customers and pay the costs incurred if you face legal claims around copyright infringement and this applies both to ChatGPT Enterprise and the API." The compensation offer, which OpenAI is calling Copyright Shield, applies to users of the business tier, ChatGPT Enterprise, and to developers using ChatGPT's application programming interface. Users of the free version of ChatGPT or ChatGPT+ were not included. [...] Getty Images, Shutterstock and Adobe have extended similar financial liability protection for their image-making software. The announcement was made at the company's first-ever developer conference today, where Altman said there are now 100 million weekly ChatGPT users. The company also announced a platform for making custom versions of ChatGPT for specific use cases -- no coding required.
China

Huawei and Tencent Spearhead China's Hold on Cybersecurity Patents (nikkei.com) 28

China's presence is growing in cybersecurity technology, with companies such as Huawei and Tencent accounting for six of the top 10 global patent holdings in the sector as of August. From a report: Chinese companies have made headway in technological fields that affect economic security, according to industry insiders, as they focus on fostering their own tech amid the growing standoff between the U.S. and China. The rankings, compiled by Nikkei in cooperation with U.S. information services provider LexisNexis, are based on patents registered in 95 countries and regions, including Japan, the U.S., China and the European Union. Patent registrations were screened for the cybersecurity field using such factors as the international patent classification, with filings of the same patent in multiple countries counted as a single patent.

As of August, IBM led the rankings with 6,363 patents. Huawei Technologies came in second with 5,735 patents and Tencent Holdings placed third with 4,803. Other Chinese companies in the top 10 included financial services provider Ant Group in sixth with 3,922 patents, followed by power transmission company State Grid Corp. of China with 3,696, Alibaba Group Holding with 3,122 and sovereign wealth fund China Investment with 3,042. Patent applications filed by Chinese companies have increased since around 2018, when the U.S. began to impose full-scale export controls on Chinese high-tech companies. Compared with 10 years ago, IBM's patent holdings increased by a factor of 1.5. In contrast, holdings for Huawei and Tencent were 2.3 times and 13 times higher, respectively.

The Courts

Epic Games Goes To Court To Challenge Google's App Store Practices (cnn.com) 63

Epic Games, the maker of the popular game "Fortnite," has launched a battle against Google in federal court in a closely watched antitrust showdown that could reshape how smartphone users get Android apps and pay for in-app content. From a report: Epic's lawsuit in the US District Court in California's Northern District targets the Google Play Store, focusing on Google's fees for in-app subscriptions and one-off transactions, along with other terms that app developers such as Epic say helped Google maintain an illegal monopoly in app distribution.

The legal battle follows a years-long debate about whether app store operators such as Google and Apple foster an open, competitive app ecosystem. The two companies argue their app stores help unlock billions in revenue for small businesses, while ensuring that Android and iOS users benefit from security oversight that the technology giants provide. The jury may hear high-profile witnesses testify from both sides, including Google CEO Sundar Pichai and Epic CEO Tim Sweeney.

The court fight traces back to 2020, when Epic launched Project Liberty, a plan to circumvent Apple and Google's app store terms. That move by Epic forced a confrontation with the tech giants. Epic updated the Fortnite app to encourage players to pay for in-app content directly through Epic's own website -- rather than through Apple and Google's in-app payment systems. That gambit triggered a violation of the app stores' developer terms. The move also prompted both app stores to remove the Fortnite app from their platforms.

Power

Maine Considers Giving the Boot To Corporate Electric Utilities (apnews.com) 176

The state of Maine is "poised to vote on an unprecedented plan to rid themselves of the state's two largest electric utilities and start with a clean slate," reports the Associated Press: The proposed takeover of two investor-owned utilities that distribute 97% of electricity in the state would mark the first time a U.S. state's utilities were forcibly removed at the same time. The referendum calls for dismantling Central Maine Power and Versant Power and replacing them with a nonprofit utility called Pine Tree Power to operate 28,000 miles (45,000 kilometers) of transmission lines...

The referendum calls for creation of a nonprofit utility with a board made up of mostly elected members and a few appointed ones. A primary selling point is that the new utility would be beholden only to ratepayers, not corporate shareholders, allowing lower costs, greater investments in the grid and improved performance, supporters said. Interest rates for long-term borrowing for capital improvements also would be less costly for Pine Tree Power. Supporters say there's little to lose: Both investor-owned utilities rank near the bottom in customer satisfaction, with longer-than-average response to power outages and higher-than-average electricity rates.

But critics, including Democratic Gov. Janet Mills, worry about the power grid becoming politicized. They also question savings projections because of the billions of dollars needed to buy out the utilities, and worry about the prospect of lengthy litigation. Maine Public Advocate William Harwood contends legal disputes could postpone the new utility's implementation by five to 10 years.

The American Public Power Association estimates that investor-owned utilities serve 66% of America's electricity consumers, according to the article. So the Associated Press notes that "Across the country, ratepayers who are unhappy with their utilities are watching what happens," citing this quote from energy-related research firm Clear View Energy Partners.

"What we say about state policy and trends is that it could become contagious."

Thanks to Slashdot reader jenningsthecat for sharing the article.
Government

'Stupid' Daylight Saving Time Ritual Continues. But Why? (nbcnews.com) 241

Many Americans want to abolish Daylight Saving Time, reports NBC News: Since 2018, nearly all states have passed or entertained legislation that would drop the twice-a-year time shift. And 19 states have passed laws or resolutions in support of year-round daylight saving time, according to data from the National Conference of State Legislatures. But there's a caveat: Nothing can change until Congress addresses a 1960s-era law blocking such action.
"This ritual of changing time twice a year is stupid," U.S. Senator Marco Rubio said in March, reintroducing legislation to end Daylight Saving Time. In an official statement the Senator announced that "Locking the clock has overwhelming bipartisan and popular support. This Congress, I hope that we can finally get this done."

But according to the Hill, "Both the House and Senate versions of the Sunshine Protection Act of 2023 haven't appeared to go far. The Senate bill has been read twice and referred to a committee, while the House bill has only been referred to a subcommittee."

While America waits, another medical association has come out in favor of ending Daylight Saving Time, reports NBC News: The American Academy of Sleep Medicine is a medical association whose professionals advocate for policies that improve sleep health. On Tuesday, the academy released a statement calling on the U.S. to eliminate daylight saving time completely, stating that standard time best supports health and safety, as it aligns with people's natural circadian rhythm. Undergoing the time switch itself raises the most concerns. Research shows that after the "spring forward" time change, workplace injuries, car crash deaths and heart attack risk have all increased. One 2023 study found that a week after transitioning from the time change, people reported more dissatisfaction with sleep and higher rates of insomnia.
The Courts

14 Big Landlords Used Software To Collude on Rent Prices, DC Lawsuit Says (arstechnica.com) 52

DC's attorney general has sued 14 of the city's largest landlord firms, claiming they entered into agreements with a property management software firm to keep rent prices high in a city with a housing affordability crisis. From a report: The complaint, filed earlier today by Attorney General Brian Schwalb, focuses on the multifamily landlords' use of software from Texas-based firm RealPage, which suggests rental prices based on a pricing algorithm. Key to those models, according to the suit, is the data fed in from the landlords and the pressure RealPage puts on them to stick to the code-derived rental rates. "RealPage and the defendant landlords illegally colluded to artificially raise rents by participating in a centralized, anticompetitive scheme, causing District residents to pay millions of dollars above fair market prices," Schwalb said in a release tied to the complaint.

The collaboration "amounts to a District-wide housing cartel," Schwalb said, noting that "well over" 30 percent of buildings with five or more units use RealPage's software, along with 60 percent of 50-unit-plus buildings. Across a wider Washington-Arlington-Alexandria area, more than 90 percent of units in large buildings are subject to RealPage pricing, according to Schwalb's office. RealPage's rent management service, YieldStar, has come under increasing scrutiny in recent years. RealPage and the property management firms utilizing their software were the subject of a class-action suit filed in the Southern District of California in October 2022, alleging the "cartel" artificially inflated prices. The Department of Justice's Antitrust Division opened an investigation in November 2022 into RealPage's role in potential landlord collusion.

Crime

FTX Founder Sam Bankman-Fried Found Guilty of Fraud (yahoo.com) 135

Slashdot readers schwit1 and Another Random Kiwi share the breaking news that FTX founder Sam Bankman-Fried has been found guilty of fraud. From the Associated Press: FTX founder Sam Bankman-Fried's spectacular rise and fall in the cryptocurrency industry -- a journey that included his testimony before Congress, a Super Bowl advertisement and dreams of a future run for president -- hit a new bottom Thursday when a New York jury convicted him of fraud in a scheme that cheated customers and investors of at least $10 billion. After the monthlong trial, jurors rejected Bankman-Fried's claim during four days on the witness stand in Manhattan federal court that he never committed fraud or meant to cheat customers before FTX, once the world's second-largest crypto exchange, collapsed into bankruptcy a year ago.

"His crimes caught up to him. His crimes have been exposed," Assistant U.S. Attorney Danielle Sassoon told the jury of the onetime billionaire just before they were read the law by Judge Lewis A. Kaplan and began deliberations. Sassoon said Bankman-Fried turned his customers' accounts into his "personal piggy bank" as up to $14 billion disappeared. [...] U.S. Attorney Damian Williams told reporters after the verdict that Bankman-Fried "perpetrated one of the biggest financial frauds in American history, a multibillion dollar scheme designed to make him the king of crypto." "But here's the thing: The cryptocurrency industry might be new. The players like Sam Bankman-Fried might be new. This kind of fraud, this kind of corruption is as old as time and we have no patience for it," he said.

China

US House Panel Seeks Ban On Federal Purchases of China Drones (reuters.com) 33

David Shepardson reports via Reuters: The top members of a U.S. House committee on China are introducing a bill that seeks to ban the U.S. government from buying Chinese drones. Mike Gallagher, the Republican chair of the committee, and Raja Krishnamoorthi, the ranking Democrat, are introducing the "American Security Drone Act" on Wednesday, the lawmakers said in a statement to Reuters. "This bill would prohibit the federal government from using American taxpayer dollars to purchase this equipment from countries like China," Gallagher said. "It is imperative that Congress pass this bipartisan bill to protect U.S. interests and our national security supply chain."

The bill would also bar local and state governments from purchasing Chinese drones using federal grants and require a federal report detailing the amount of foreign commercial off-the-shelf drones and covered unmanned aircraft systems procured by federal departments and agencies from China. Krishnamoorthi said the bill "helps protect against any vulnerabilities posed by our government agencies' reliance on foreign-manufactured drone technology and will encourage growth in the U.S. drone industry."

Separately, the U.S. Senate on Tuesday unanimously approved an amendment proposed by Republican Senator Marsha Blackburn and Democrat Mark Warner that would prohibit the Federal Aviation Administration (FAA) from operating or providing federal funds for drones produced in China, Russia, Iran, North Korea, Venezuela or Cuba. "Taxpayer dollars should never fund drones manufactured in regions that are hostile toward our nation," Blackburn said. China recently announced export controls on some drones and drone-related equipment, saying it wanted to safeguard "national security and interests."
The U.S. Commerce Department in 2020 added dozens of Chinese companies to a trade blacklist, including the country's top chipmaker SMIC and Chinese drone giant DJI.
Businesses

Amazon Made $1 Billion Through Secret Price Raising Algorithm, Says FTC (reuters.com) 60

Amazon used a secret algorithm to boost prices to U.S. households by more than $1 billion, says the FTC in ia new court filing. "The FTC lawsuit was filed in September but many details were withheld until Thursday when a version of the lawsuit with fewer redactions was made public in U.S. District Court in Seattle," notes Reuters. From the report: Amazon, which has 1 billion items in its online superstore, created a "secret algorithm internally code named 'Project Nessie' to identify specific products for which it predicts other online stores will follow Amazon's price increases. ... Amazon used Project Nessie to extract more than a billion dollars directly from Americans' pocketbooks," the FTC said.

Amazon began testing the pricing algorithm in 2010 to see if other online retailers tracked its prices and to raise prices for products that were likely to be tracked by competitors, the complaint said. After outside retailers began matching or increasing their own prices, Amazon would continue to sell the product at an inflated price, the FTC alleged, which resulted in $1 billion in excess profit. Amazon paused the algorithm during its Prime Day sales events and the holiday shopping season when there was more media and customer attention on the online retailer, the FTC said.

"After the public's focus turned elsewhere, Amazon turned Project Nessie back on and ran it more widely to make up for the pause," the lawsuit said. Amazon in April 2018 used it to set prices for more than 8 million items purchased by customers that collectively cost almost $194 million, the complaint said, before pausing it in 2019. Amazon retail executive Doug Herrington in January 2022 asked about using "old friend Nessie, perhaps with some new targeting logic" to boost profits for Amazon's retail arm, the complaint said. The FTC complaint also accuses Amazon of seeking to hide information about operations from antitrust enforcers by using the Signal messaging app's disappearing message feature and said the company destroyed communications from June 2019 to early 2022.
Amazon also required sellers using its Prime feature to utilize its logistics and delivery services, leading to increased fees for sellers who used its fulfillment services from 27% in 2014 to 39.5% in 2018, as per the FTC. Furthermore, the complaint mentioned that Amazon treated Walmart.com differently, not allowing it to sell on its platform and allegedly deterring Walmart from offering discounts to shoppers who picked up their purchases from Walmart stores.

Further reading: Amazon Boosted Junk Ads and Deleted Messages To Thwart Antitrust Probe, FTC Says
Google

Apple Called Android a 'Massive Tracking Device' In 2013 (9to5google.com) 29

An anonymous reader quotes a report from 9to5Google: Coming out of the ongoing Google antitrust trial, an internal Apple presentation has surfaced (via The Verge) in which the company called Android a "massive tracking device." The presentation in question was regarding a push within Apple to start "Competing on Privacy." The slides, made in January 2013, dove into how Apple's competitors (Google, Facebook, Amazon, and Microsoft primarily) handled privacy matters and user data. A "privacy timeline" includes some 2000s and 2010s events that made headlines regarding privacy, such as Google's Street View cars recording private Wi-Fi networks and Instagram's aim to use user photos in its ads, as well as Google's privacy policy move to combining user data across services. Apple went on to compare how its products handle privacy differently from Google and others.

The presentation culminates in the full-page statement [...] where Apple says that "Android is a massive tracking device." The slideshow is partially redacted and abridged, which leaves out the context of this statement, but it's certainly a bold way to talk about a competitor. Of course, all mobile devices do a whole lot of tracking, whether it's Android or iOS.

Privacy

Brave Responds To Bing and ChatGPT With a New 'Anonymous and Secure' AI Chatbot (theverge.com) 11

The Brave browser is rolling out a privacy-focused AI assistant named Leo, which the company claims provides "unparalleled privacy" compared to AI chatbot services likes Bing Chat, ChatGPT, Google Bard and others. The Verge reports: Following several months of testing, Leo is now available to use for free by all Brave desktop users running version 1.60 of the web browser. Leo is rolling out "in phases over the next few days" and will be available on Android and iOS "in the coming months."

The core features of Leo aren't too dissimilar from other AI chatbots like Bing Chat and Google Bard: it can translate, answer questions, summarize webpages, and generate new content. Brave says the benefits of Leo over those offerings are that it aligns with the company's focus on privacy -- conversations with the chatbot are not recorded or used to train AI models, and no login information is required to use it. As with other AI chatbots, however, Brave claims Leo's outputs should be "treated with care for potential inaccuracies or errors."

The standard version of Leo utilizes Meta's Llama 2 large language model and is free to use by default. For users who prefer to access a different AI language model, Brave is also introducing Leo Premium, a $15 monthly subscription that features Anthropic's AI assistant, Claude Instant -- a faster and cheaper version of Anthropic's Claude 2 large language model. Brave says that additional models will be available to Leo Premium users alongside access to higher-quality conversations, priority queuing during peak usage, higher rate limits, and early access to new features.

Power

Pennsylvania Court Permanently Blocks Effort To Make Power Plants Pay For Greenhouse Gas Emissions (apnews.com) 189

An anonymous reader quotes a report from the Associated Press: Pennsylvania cannot enforce a regulation to make power plant owners pay for their planet-warming greenhouse gas emissions, a state court ruled Wednesday, dealing another setback to the centerpiece of former Gov. Tom Wolf's plan to fight global warming. The Commonwealth Court last year temporarily blocked Pennsylvania from becoming the first major fossil fuel-producing state to adopt a carbon-pricing program, and the new ruling makes that decision permanent. The ruling is a victory for Republican lawmakers and coal-related interests that argued that the carbon-pricing plan amounted to a tax, and therefore would have required legislative approval. Wolf, a Democrat, had sought to get around legislative opposition by unconstitutionally imposing the requirement through a regulation, they said. The court agreed in a 4-1 decision.

The regulation written by Wolf's administration had authorized Pennsylvania to join the multistate Regional Greenhouse Gas Initiative, which imposes a price and declining cap on carbon dioxide emissions from power plants. It would be up to Wolf's successor, Democratic Gov. Josh Shapiro, to decide whether to appeal the decision to the state Supreme Court. Shapiro's administration had no comment Wednesday on whether it would appeal, and Shapiro himself hasn't said publicly whether he would follow through on the plan to join the consortium, should the courts allow it. Still, Shapiro is "focused on addressing climate change, reducing emissions, and protecting public health while creating jobs and protecting consumers," Shapiro's administration said in a statement.

Crime

Two Russian Nationals Charged For Hacking Taxi System At JFK Airport (theregister.com) 48

Thomas Claburn reports via The Register: For a period of two years between September 2019 and September 2021, two Americans and two Russians allegedly compromised the taxi dispatch system at John F. Kennedy International Airport in New York to sell cabbies a place at the front of the dispatch line. The two Russian nationals, Aleksandr Derebenetc and Kirill Shipulin, were indicted by a grand jury for conspiring to commit computer intrusions, the US Justice Department said on Tuesday. They remain at large. In early October, the two American nationals, Daniel Abayev and Peter Leyman, who were indicted last year, pleaded guilty, each to one count of conspiring to commit computer intrusions.

The scheme represented an attempt to monetize the demand among taxi drivers for lucrative airport fares -- the current flat rate for JFK to Manhattan is $70 plus additional charges. As described in the indictment (PDF), taxi drivers are required to wait in a holding lot at JFK, often for several hours, before being dispatched in the order of their arrival to airport terminals. And because time spent waiting in line is not paid, drivers have a financial incentive to avoid waiting in line. The conspirators allegedly developed a plan to hack the dispatch system around September 2019. The indictment describes several approaches that were tried, "including bribing someone to insert a flash drive containing malware into computers connected to the dispatch system, obtaining unauthorized access to the dispatch system via a Wi-Fi connect, and stealing computer tablets connected to the dispatch system."

The government's filing suggests that the group gained and lost access to the dispatch system several times. When they did have access, the alleged conspirators offered to move drivers to the front of the dispatch queue for a $10 fee, and waived the fee for those who found other drivers willing to pay to play. Many drivers took advantage of the service. According to the Justice Department, the group booked 2,463 queue cuts in a single week around December 2019. The scheme allegedly enabled as many as 1,000 trips per day that skipped the queue at JFK. The American conspirators are said to have collected the money from participating drivers and to have sent payments to the alleged Russian conspirators, describing the money transfers as "payment for software development" or "payment for services rendered." The indictment indicates that the Russians received more than $100,000 for their work. If apprehended -- which appears unlikely given current US relations with Russia -- the Russians face charges that carry a maximum sentence of ten years in prison. Abayev and Leyman each face up to five years in prison. They're scheduled to be sentenced early next year.

The Internet

Russia Blocks 167 VPNs, Steps Up OpenVPN and WireGuard Disruption (torrentfreak.com) 42

An anonymous reader quotes a report from TorrentFreak: The head of the Russian department responsible for identifying threats to the "stability, security and integrity" of the internet, has revealed the extent of the Kremlin's VPN crackdown. Former FSO officer Sergei Khutortsev, a central figure in Russia's 'sovereign internet' project, confirmed that 167 VPN services are now blocked along with over 200 email services. Russia is also reported as stepping up measures against protocols such as OpenVPN, IKEv2 and WireGuard. [...]

An in-depth report published by TheIns.ru has details of the monitoring/blocking system reportedly deployed in Russia, how much it costs (4.3 billion rubles/$43 million in 2020, 24.7 billion rubles/$247 million for 2022-2024), and the names of the companies supplying the components. The publication also obtained original documents that apparently show some of the protocols Russia initially intended to block. They include older VPN protocols IPSec, L2TP, and PPTP, plus the BitTorrent protocol still widely used today. The full report on the system, which reveals the use of Intel chips/chipsets in 965 servers manufactured by Huawei and already purchased by Russia, plus another 2400+ servers for 2023/24, is available here.

Slashdot Top Deals