
The UK foreign secretary has shared a report saying climate change threatens the collapse of natural systems, and hence war and migration. Why was it kept secret, though? CC-licensed photo by Russ Seidel on Flickr.
You can sign up to receive each day’s Start Up post by email. You’ll need to click a confirmation link, so no spam.
A selection of 9 links for you. Inexplicable. I’m @charlesarthur on Twitter. On Threads: charles_arthur. On Mastodon: https://newsie.social/@charlesarthur. On Bluesky: @charlesarthur.bsky.social. Observations and links welcome.
‘We hacked the FBI:’ hackers say they have data on all FBI employees • 404 Media
Joseph Cox:
»
A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse.
The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.
“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative of the group told 404 Media.
The representative provided 404 Media with a sample appearing to contain the personal data of 5,000 FBI employees. That data included an alleged address, phone number, date of birth, and in some cases details on their spouse.
404 Media put some of the sample phone numbers into open source intelligence tool OSINT Industries and found they did correspond to people with the same name as listed in the sample file. 404 Media also searched some of the records through compromised data tool Darkside, made by cybersecurity company District 4. That revealed some of the phone numbers are associated with U.S. Department of Justice personnel.
…The representative [of the hackers] said ShinyHunters said the group used a zero day exploit in an Oracle product called PeopleSoft. From there, the group managed to access AWS GovCloud servers and downloaded data. The representative said the exfiltrated data totalled between two and three terabytes.
«
The FBI’s reaction suggests that the group has indeed hacked it. A followup story by Cox says that the hack exposed the FBI’s own hacking unit. That’s quite the screwup. (Thanks Gregory B for the link.)
unique link to this extract
Meta puts its AI assistant on a keychain • Financial Times via Ars Technica
Hannah Murphy:
»
Mark Zuckerberg said Meta’s new personal AI agent Muse has become the “centerpiece” of his AI vision, as he unveiled a new handheld AI “charm” device that will feature the interactive assistant.
The Meta chief used the company’s annual Connect event at its Silicon Valley headquarters to announce Muse Charm, a small pendant-like device that fits on a keychain and is activated by a fingerprint sensor.
The device, which features a screen showing the Muse avatar, will also have real-time voice interactivity and is set to be released in December.
“If you’re not wearing glasses, this is going to be by far the fastest way to talk to your Muse and to show what’s going on around you,” the chief executive said.
Muse, development of which was first revealed by the FT in May, has helped change the momentum of Zuckerberg’s huge bet on AI, quickly becoming the most downloaded app on both the Apple and Android app stores in the US since its launch two weeks ago.
The easy-to-use app offers consumers a team of autonomous bots to carry out everyday tasks, such as ordering groceries, booking travel and organising finances.
Zuckerberg on Wednesday also announced new capabilities for Muse, including the ability to have live conversations with the interactive AI assistant, and insisted that it has “state-of-the-art privacy and security.”
«
Meta is certainly getting busy on the hardware front. The reviews of this – both how well it works, and what its usefulness and privacy are like, will make for an absorbing read. Still no sign, meanwhile, of the OpenAI/Jony Ive thingamajig.
unique link to this extract
Meta’s next VR device isn’t a headset — it’s glasses • The Verge
Jay Peters:
»
Meta is launching new VR hardware: a pair of glasses. The new Meta VR Glasses sit on your ears like a typical pair of glasses instead of being strapped over your head, but they still have immersive displays for watching movies, playing games, and getting work done. Imagine a pair of hefty black sunglasses with blacked-out lenses on the outside, but the components of a typical VR headset distributed between the device on your head and a computing puck in your pocket.
The idea is to give you a way to experience VR in a much lighter and more approachable form factor than Vision Pro or Meta Quest-style headsets. I got to try the VR Glasses at Meta’s campus this week, and as Meta walked me through some familiar VR demos like watching content, playing a game, and working from multiple screens, I was impressed by how much lighter the whole experience felt. Some of that was about the literal weight, as the glasses come in at just 100g, far less than the Quest 3’s 515g. But there was also something lighter in a more intangible way: the glasses form factor made the headset seem like something I could easily jump in and out of instead of being a whole cumbersome commitment with big head straps. It felt like a lightweight Vision Pro, and is perhaps a better execution of some of what Apple wanted to do with that device.
To keep things light, the VR Glasses’ display and the sensors are all you actually wear on your face. The separate puck connected with a wire contains the guts powering the headset: a Snapdragon Reality Elite processor, 128GB of storage, 12GB of RAM, and the battery, which Meta says will offer up to three hours of media playback, though you can continue using the glasses even while the puck is being charged.
«
This sounds like a colossal improvement in wearability (bear in mind that the Vision Pro has a separate battery pack too), but I wonder about VR. Is its time ever going to come?
unique link to this extract
OpenAI’s AI tried breaching four other targets, with no prompting • The New York Times
Kate Conger and Victoria Kim:
»
OpenAI’s artificial intelligence went rogue this year in at least four additional incidents, hacking and trying to break into government and university websites without being instructed to do so, according to researchers and government officials.
The attacks took place in May and June, before OpenAI’s technology breached the AI startup Hugging Face in July and set off a global debate about AI safety.
Unlike the Hugging Face attack and other incidents in which A.I. systems were told to complete cybersecurity tests that effectively invited the models to demonstrate their hacking skills, the new incidents occurred when AI systems were directed to perform relatively mundane data collection, researchers said. When OpenAI’s systems struggled to gather data from websites, they resorted to hacking techniques to get the information.
Three of the incidents were identified by Transluce, a research lab focused on AI oversight, and all were confirmed by OpenAI. Here is how they happened:
• OpenAI’s systems tried to hack a digital library at the University of New Mexico on May 25 and 26. The AI did not appear to succeed.
• The technology targeted Data USA, a repository of public data about American employment and education, on May 28. This attempt also appeared to be unsuccessful, researchers said.
• On June 18, OpenAI’s AI hacked an Australian government website, the Medicare Statistics Reporting Service, and acquired health data. Australia’s prime minister, Anthony Albanese, disclosed the episode on Wednesday.
• On June 20 and 21, OpenAI’s technology tried to breach the website of the Australian Institute of Health and Welfare. No private information was obtained, Australian officials said.
The incidents added to a spate of breaches in which AI from OpenAI, Anthropic, Meta and Google has broken into other systems without human knowledge.
«
From the descriptions, the agents tried to access the site, and when refused began trying known vulnerabilities in various elements of the software being used there. This should not surprise anyone. The LLM training set includes colossal amounts of material from the web about hacking and vulnerabilities, and there is no moral code attached to any of it; in fact, in some hacking circles the vulnerabilities will have been greeted with delight.
So for a system given a task, hacking is just another prong on the Swiss Army Knife at its command, even if we find it as surprising as someone pulling out the tool to remove stones from horses’ hooves. Think: how exactly do you tell an agent not to hack a site?
unique link to this extract
UK shares findings of damning climate crisis national security report suppressed under Starmer • The Guardian
Fiona Harvey:
»
The UK has warned countries around the world that the climate and nature crises and the coming El Niño threaten their national security and defence, presenting foreign ministries with the findings of a report suppressed under Keir Starmer.
Ed Miliband, the UK’s foreign secretary, made a presentation to the foreign ministers of the EU as well as Kenya and other countries on Wednesday night at a private meeting during the UN general assembly in New York, based on the report by the UK’s spy chiefs that found the collapse of natural systems around the world would lead to conflict, migration and food shortages.
Miliband told the meeting, the first such discussion among foreign ministers, that the coming El Niño, which has been supercharged by climate breakdown, would test the world’s food systems as never before.
“We face an El Niño that is already set to be the most intense in living memory,” he said. “This will intensify climate shocks that compound and cascade across borders, threatening food and water security, displacing communities, putting pressure on markets and scarring economies.”
This year’s heatwaves, bad harvests and food price inflation showed governments what they were in for, he said, and must be dealt with at the highest levels.
“Climate change and nature loss have never been issues for climate and environment ministers alone,” he said. “They are defining challenges for our citizens, our economies, our foreign policy and our national security.”
With the backing of Andy Burnham, the UK prime minister, Miliband presented the research that found the collapse of global ecosystems such as in the Amazon and Congo rainforests, driven by the climate crisis and the destruction of nature, would have impacts on national security around the world.
The joint intelligence committee (JIC) report, revealed by the Guardian, was scheduled to be published last October, but was suppressed on the eve of its launch by Downing Street. A redacted version was issued in January under the Freedom of Information Act, but ministers have continued to resist calls for the full report to be made public.
Richard Nugee, a retired general and security expert, told the Guardian governments must treat the climate as they would other threats to national security, such as sabotage by hostile states.
«
Why on earth would they suppress the report? Did they worry it was too much of a downer? And Miliband must have known about it, as energy secretary, and simply been obliged not to discuss it. Unsurprising he did now he had the first chance to on a world stage.
unique link to this extract
An invisible force has a mysterious effect on ageing, scientists discover in ‘startling’ breakthrough • 404 Media
Becky Ferreira:
»
Scientists have discovered that the removal of Earth’s magnetic field influences the lifespans of fruit flies in complex ways, a finding that sheds light on the aging process as well as the risks of future human space travel, according to a study published in the journal Aging on Wednesday.
All life on Earth has evolved under the planet’s geomagnetic field, a vast bubble lined with electrical currents that is generated in the core and extends out into space. This protective magnetic shield is a major factor in Earth’s habitability, as it wards off harmful radiation from space, allowing life to flourish on the surface.
Many migratory animals—including fish, birds, and insects—can clearly sense Earth’s magnetism and use it for navigation. But much less is known about how the field interacts with living cells and their components, such as mitochondria, the famous “powerhouses” that generate most of the energy that fuels life.
To better understand this mystery, scientists observed two populations of fruit flies in a “hypomagnetic” shield system, a cylindrical benchtop apparatus that essentially blocks the influence of Earth’s magnetic field. One group contained “wild-type” healthy flies, while the other was made up of “mutant” flies carrying a gene defect called Pink1, which is associated with early-onset Parkinson’s disease in humans and specifically involves mitochondrial dysfunction.
The removal of the magnetic field’s effect extended the lifespan of the Pink1 group by 20% but reduced their mobility, whereas the healthy flies experienced just the opposite—reduced lifespan, but improved mobility.
“We had an idea that there would be a difference just based on the fact that we know that every organism has developed under a magnetic field,” said Jacob Reed, a PhD student in bioscience at the University of Nottingham who co-led the study, in a call with 404 Media. “But we didn’t really plan that there would be this difference in the experiment.”
«
If (possibly a big if) this isn’t p-hacking – searching around for a result from the data – then this is really strange, and definitely does have implications for space travel. Though the researchers themselves don’t know what, yet.
unique link to this extract
Italian parliament votes for return to nuclear energy • AP News
Giada Zampano:
»
Italy’s Senate on Wednesday gave final approval to legislation paving the way for a return to nuclear power nearly four decades after the Chernobyl disaster prompted the country to abandon atomic energy.
The measure cleared the upper house 81-51 with seven abstentions. It marks a major step in Premier Giorgia Meloni’s drive to bolster energy security and meet climate goals, even though the construction of possible new reactors is still years away.
The bill, which earlier passed the lower Chamber of Deputies, establishes a legal framework for next-generation nuclear technologies. It authorizes the government to draft implementing decrees over the next 12 months covering reactor licensing, safety standards, waste management and criteria for future sites.
The vote puts Italy on a path toward reintroducing nuclear power after voters twice rejected it in national referendums, first [in 1987] in the aftermath of the 1986 Chernobyl disaster and again [in 2011] following Japan’s Fukushima accident in 2011.
Gilberto Pichetto Fratin, minister for the environment and energy security, said the vote marked a historic step forward for Italy.
“Nuclear isn’t a return to the past,” he said. “When integrated with renewables, it’s a winning technology, which can give extraordinary results for our energy security.”
«
It’s a slow, slow thing: “draft implementing decrees over the next 12 months covering licensing..” OK and when will you start building? They did try to restart this in 2008, having closed down all four reactors (1,300MW in power) by 1990, but just as things were getting going, along came Fukushima. As everyone knows, Italy is notoriously prone to tsunamis caused by offshore earthquakes, just like Japan.
unique link to this extract
Passkeys explained: the easier, safer way to sign in
»
A passkey is a unique digital key that replaces your password.
…To confirm its you, the service (app or site) sends a challenge during the sign in process. The credential manager/authenticator signs this challenge using the passkey’s private key. The signed response includes this signature as well as additional context about the session, such as the origin, and whether the request was made in an embedded context (iframe). The server verifies that (1) the origin is the expected value (e.g. bank.com not fake-bank.com), (2) the challenge matches the one it issued, and (3) the signature is valid for the stored public key. The signed origin match is the primary way that passkeys (and WebAuthn credentials in general) resist phishing.
«
The second paragraph there comes from the “Advanced” explanation (available from a tab at the top of the page). There are also, if you want them, even more diagrams which will either delight you or make you sorry you asked.
Passkeys can, like passwords, be shared among multiple devices you own. But the essential thing is that they won’t work on phishing sites. (No doubt the hackers are already working on the social engineering for this – “your passkey has been corrupted, please sign in with an email/password” or similar is probably on the way.)
unique link to this extract
Component cost shock could wipe out more than 230 million sub-$200 smartphone shipments by 2030 • Counterpoint Research
Yang Wang:
»
More than 230 million annual sub-$200 smartphone shipments are forecast to disappear from the global market between 2025 and 2030, according to Counterpoint Research’s latest Smartphone Shipment Forecast by Price Band tracker. The segment is expected to decline by approximately 40% over the period, even as the overall smartphone market recovers toward its 2025 volume by the end of the decade.
The divergence reflects the structural shock from the 2026–2027 downturn. Higher memory and chipset costs, increasing minimum specifications and reduced OEM willingness to support non-strategic market presence will sharply reduce entry-tier availability. Some consumers will move upward, while others may keep their current devices for longer. Used phones will also absorb some demand, while first-time smartphone adoption risks slowing in markets where handset affordability is already a major barrier to mobile internet use.
Principal Analyst Yang Wang commented, “The smartphone market will recover in unit terms, but the affordable segment will not return to its previous standing. The opportunity now shifts toward better-specced mainstream devices and premium products, although higher tiers cannot absorb all the lost volume. The result will be a market that is similar in overall size but materially different in value and competitive profile. There is also a wider connectivity risk, as the loss of affordable new smartphones could make it harder for first-time users in lower-income markets to come online.”
«
This is a bad thing, surely. Those super-cheap smartphones are on the edge of affordability for many people who rely on their phone to run their life in multiple poorer countries. So what happens when their existing phone breaks or is damaged or lost? You can argue that’s what the secondhand market is for, but that market needs flow from above too. A subtle but real way in which the pursuit of AI is harming the less rich parts of the world.
unique link to this extract
| • Why do social networks drive us a little mad? • Why does angry content seem to dominate what we see? • How much of a role do algorithms play in affecting what we see and do online? • What can we do about it? • Did Facebook have any inkling of what was coming in Myanmar in 2016? Read Social Warming, my latest book, and find answers – and more. |
Errata, corrigenda and ai no corrida: none notified