Start Up No.2757: Asos app shows hacking message, the gamer decompilation, Google data centre halted in Finland, and more


In the age of physical tape, we knew what “recording” was. But might modern digital devices listen without recording? CC-licensed photo by Carbon Arc on Flickr.

You can sign up to receive each day’s Start Up post by email. You’ll need to click a confirmation link, so no spam.


A selection of 9 links for you. Reely hard. I’m @charlesarthur on Twitter. On Threads: charles_arthur. On Mastodon: https://newsie.social/@charlesarthur. On Bluesky: @charlesarthur.bsky.social. Observations and links welcome.


“ASOS hacked”: app users receive notifications sent by hackers • BBC News

Joe Tidy and Liv McMahon:

»

Asos says it is investigating “unauthorised activity” involving third-party platforms it uses after customers received a notification from its app sent by hackers.

Dozens of people told the BBC they received the strange “ASOS HACKED” message from the clothing and beauty store’s app on Tuesday morning – with some saying it left them “scared” to open the app.

The notification was addressed to the company’s data protection officer and IT teams in what cyber security experts said looked like a “brazen” extortion attempt.

Asos acknowledged the “unauthorised customer notification” on Tuesday afternoon, saying some “basic personal information” may have been accessed. In an email to customers on Tuesday night, the company apologised and urged customers not to engage with the notification. And it said the website and app are “operating as usual” promising customers they can “shop with confidence” while it investigates the incident.

The company has not as of yet informed the UK’s data watchdog, the Information Commission’s Office (ICO), about any breach. Exactly how many Asos customers received the notification on Tuesday remains unclear, but Google’s Play store says the ASOS app has been downloaded to android devices more than 10 million times.

The British retailer has a substantial global footprint – serving around 17 million customers each year across more than 150 markets.

Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday.

Hackers seeking to pile pressure on potential victims by informing their customers is rare, as most extortions happen in private, so this incident may go down as a significant moment in cyber-attack history.

Shares in the company fell by around a tenth on Tuesday.

«

Asos is in hot water for not acknowledging the hack, but the biggest concern is what it implies about how badly the company has been hacked.
unique link to this extract


Viral Fallout and MW2 AI decompilation projects hit with DMCA • The Gamer

Nazmul Roosevelt:

»

DMCA takedowns for mods and fan overhauls have been happening for years, so it makes sense that decompilation projects, especially the ones assembled quickly and shared widely on social media, are now drawing the same kind of attention. These projects have exploded in number over the past week or so, but many rely heavily on generative AI. Even well‑known efforts like Ship of Harkinian use some form of genAI, despite beginning long before the current wave of vibe‑coded recreations.

The projects that went viral this week were built with far more aggressive AI assistance. One of the first was Fallout: New York. ChrisFirst shared a clip on Twitter showing a browser‑playable recreation of Fallout built with Claude Opus 5.5. It had quests, dialogue trees, VATS, a working Pip‑Boy, and an entire city generated without any texture or sound files. Every building, weapon, face, and ambient noise was “generated by code.” The post pulled in millions of views before ChrisFirst shared that he received a cease-and-desist from Bethesda and shut the project down.

The second project that’s since been taken down came from Maurice Heumann, who used generative AI to decompile Modern Warfare 2 on PC. He said he had seventeen agents working at the same time, reconstructing the game faster than any manual effort could. According to him, the game was already playable, most bugs were fixed, and he had even earned a nuke. Activision responded by removing the footage from his post and blocking access to the site hosting the code. Heumann later shared that his AI agents kept deleting his files.

The difference seems to come with scale. Ocarina of Time running in ultrawide at 280 frames is a transformative example of what was previously capable on native hardware. It’s impressive to see, even if the game was never meant to be viewed that way. The strongest decomp projects show evidence of careful manual work, but the rapid spread of AI‑assisted recreations is pushing the space into territory that publishers can no longer ignore.

«

What’s happening is that gamers can now use AI agents to decompile the executables of games, and then get those recompiled for other platforms, or add new elements that weren’t there before. And publishers don’t like it when such work is made public. (Obviously they can’t see any private work.)

Feels like this might drive games companies to cloud-based services which can’t be decompiled because they’re never running on the user’s computer.
unique link to this extract


Silicon Valley thinks AI will kill jobs. Economists are not convinced • Financial Times

Delphine Strauss:

»

The most worrying development is a cross-country slowdown in entry-level hiring in tech-related occupations — consistent with AI turbocharging the productivity of senior staff while taking over routine tasks done by juniors.

But there is no consensus on the cause. “Unemployment of young graduates has worsened since 2015. It’s a long-term trend. AI is clearly not the only factor,” Broecke argued, citing a potential oversupply of graduates, the rise of remote work and high interest rates.

The absence of aggregate job losses may simply be the calm before the storm. “Talk to executives in the non-tech sector — those who use AI as customers — and many say they don’t need as many workers as they did before AI,” Johnson said. “It is not yet in the numbers . . . but the automation threat is very real.”

Modelling by the Anthropic Institute, published last month, included an extreme scenario where rapid gains in AI’s capabilities cut “cognitive” employment by a fifth by 2030, leaving one in five white-collar workers and one in 10 of all workers unemployed.

The model is highly sensitive to underlying assumptions. The extreme scenario assumes AI will rapidly become able to perform most tasks without human oversight, will be widely adopted and will generate big productivity gains.

Other scenarios show more modest change, but Anton Korinek, who led the modelling, said he “personally put more weight” on those showing a rapid increase in AI adoption from 2028, with the technology becoming able to rival and replace senior executives, not just entry-level staff.

In practice, companies may be slow to shed workers even when AI tools can do the job. Broecke of the OECD said: “There is the cost of technology. There are legal barriers, social preferences, ethical issues. There are all sorts of reasons why something that is theoretically possible will not happen in practice.”

«

unique link to this extract


Google told to halt work on datacentres in Finland over environmental concerns • The Guardian

Miranda Bryant:

»

Google has been ordered to temporarily stop work on two datacentres in Finland after failing to do the necessary environmental impact assessments on its construction sites.

The planned datacentres in Muhos and Kajanni are part of a €13bn (£11bn) project across multiple sites in northern Finland by the technology company amid huge demand for space to house online infrastructure.

It comes after it emerged that Tuike Finland Oy, the company representing Google, had felled 330 hectares (815 acres) of forest in Muhos without completing an environmental impact assessment (EIA).

In Kajaani, the company has reportedly been logging across just under 200 hectares (494 acres) of land.

The Finnish Association for Nature Conservation said the sites had been reduced to “sand”, blaming the oversights on the “overheated” market for new datacentres.

On Tuesday, the Finnish Licensing and Supervision Authority (LVV) said it had issued a notice to the company to “immediately suspend” – by 23 October at the latest – “preparatory measures that significantly change the environment” of the two sites until the environmental impact assessment had been completed. Google has until next Wednesday to submit a written explanation.

The EIA is ongoing and expected to be completed later this year. But Google has gone ahead with “extensive preparatory measures”, including removing trees, stripping topsoil and constructing site roads, LVV said.

Tommi Muilu, the head of the environmental department at LVV, said: “In our opinion, the measures in question will change the environment and cause impacts, the identification and assessment of which are among the key objectives of the EIA procedure.”

«

The photograph in the story suggests that Google got a long way along in its felling before, oh, did we not do the impact assessment? Well, there’s the impact: mud where there used to be forest. But don’t worry! AI will solve the climate crisis just as soon as it’s finished making it worse.
unique link to this extract


We can’t just change the definition of “recording” • The Verge

Victoria Song:

»

The Apple Watch has had a microphone for ages, mostly for Siri and taking phone calls from the wrist. Of the four Audio Intelligence features, two have caused the most debate online: Live Rewind and Siri Recap. The former produces a transcript of the past 15 seconds, whereas the latter can generate high-level summaries of the conversations you have throughout the day.

In other words, Ray-Ban Meta glasses take photos and record video, which is stored on your phone. This rumoured Apple approach would mean cameras can see you, microphones can hear you — but neither is “saving” anything.

Does this count as recording? Apple doesn’t comment on rumours, but based on how it’s publicly communicated its Audio Intelligence privacy philosophy, I’d argue the company doesn’t think so. Apple says these features don’t save any audio. The raw data is deleted once it’s finished processing in a separate, secure exclave on the S11 [Watch] processor. Any information sent to the cloud is through [Apple’s] Private Cloud Compute and is therefore inaccessible to Apple or third parties.

It’s not just Apple, either. Sandeep Waraich, Google’s senior director of wearables, told The Verge in a conversation that Google is also mulling this concept. What if, he posited, cameras on smart glasses didn’t record data? For example, if the glasses could process visual data in your environment using AI, but didn’t save any footage for posterity. In that way, Waraich argued, the camera could “just” be an image sensor.

By these definitions, something has to be preserved and reviewable to be “recording” you. But wouldn’t any text transcripts generated by a smart home camera or smartwatch count as preserved and reviewable? Or, in trying to make AI hardware more palatable, are tech companies relying on what can be subpoenaed in court?

«

Sounds like it’s the latter. I guess we’ll find out when the American or Chinese governments demand to access it. You can’t subpoena data that’s not there any more.
unique link to this extract


ChatGPT is adding real cartoonists’ signatures to fake New Yorker cartoons • Nieman Journalism Lab

Andrew Deck:

»

At the pearly gates, Dolly Parton, in a sparkling gown, stands arm in arm with Tim Curry, dressed as Dr. Frank-N-Furter. “I knew I chose the right plus one,” Parton says to God, who is standing at heaven’s reception desk.

That’s the premise of a cartoon that went viral on Twitter in the days after the legendary entertainers’ deaths in late August. One tweet of the cartoon received 25,000 likes, while other versions of the image circulated on Facebook, Instagram, and Bluesky.

In the bottom right corner of the cartoon is the pen name “BLOPER,” the signature of New Yorker cartoonist Brendan Loper. But Loper didn’t draw the cartoon, or sign it. It was generated by ChatGPT and first posted to Facebook by a Dolly Parton fan. In the comments section of her post, she wrote she had simply asked ChatGPT to make “a New Yorker-style cartoon.”

“I had people writing to me about this cartoon, asking if it was mine,” Loper told me. First came a text from his twin brother, whose friend had seen the AI-generated image. Emails and DMs on social media from strangers followed. “It was very surreal,” he said.

…Loper already knew his work was “out there, getting harvested for all of this [AI] training,” he said. But an image generator faking his signature felt more personal. “I’m not a territorial person, but my name is my name. It felt very much like a violation of my personhood.”

…After I notified OpenAI of the issue, ChatGPT began to output a new message when I asked it to generate New Yorker-style cartoons: “This prompt may violate our guardrails concerning similarity to third-party content.”

«

“Guardrails”. Okey doke. (Thanks Joe S for the link.)

unique link to this extract


Steve Jobs said this kind of device would be “terrible”. Sixteen years later, Apple seems set to release it • Inc.com

Kit Eaton:

»

It’s impossible to think of Apple without a memory of Steve Jobs surfacing—whether it was his stylish product reveals, his blunt emails, or his vision for the future of Apple. But visionary as he was, Jobs wasn’t always right, and next week we may see more concrete proof of this with the release of a new device that Jobs once claimed would be “ergonomically terrible.” A slew of rumors suggest Apple is poised to release a redesigned MacBook Pro—and the new, super-slim laptop will (gasp!) have a touchscreen. 

Of course, iPhones, iPads, iPod Touches, and other Apple devices have had touchscreens for years, but these devices were designed from the start to be touch-friendly, with everything from the shape of the device to the design of the user interface being built around the touch experience. Back in 2010, three years after the iPhone’s launch, Jobs was speaking at an Apple event about the idea of bringing touchscreen tech to MacBooks. Apple had completed “tons of user testing,” presumably using prototype touchscreen Mac devices, and had concluded that “it doesn’t work. It’s ergonomically terrible.”

…But according to several different rumors, Apple will actually reveal a Mac with a touchscreen as part of its October event, set to happen on October 13 per prolific Apple leaker Mark Gurman of Bloomberg.

We may see the touchscreen HomePad smart-home controller arrive at the same time, representing a whole new category of device for Apple, along with refreshed AirPods and possibly a home security camera system. (Remember: All of this is unconfirmed.)

«

It’s true: you can read this Wired article from 2010, where Jobs is dismissive of the idea:

»

“We’ve done tons of user testing on this,” Steve Jobs said in Wednesday’s press conference, “and it turns out it doesn’t work. Touch surfaces don’t want to be vertical. It gives great demo, but after a short period of time you start to fatigue, and after an extended period of time, your arm wants to fall off.”

«

Indeed, at the time everyone agreed that touchscreens were a terrible idea for a laptop. Especially if it was super light – which the new laptops are rumoured to be.
unique link to this extract


Apple and a Hacker’s Future • Stratechery

Ben Thompson:

»

My computer got hacked, which is always embarrassing to admit, because it was my fault; the vulnerability that was exploited is detailed in this Ars Technica story:

»

Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.

«

…Claude in its Code harness seems to handle wide-ranging discussions better than Codex, and it follows my instructions about writing things down in the way I want to more gracefully. Code also has a persistent monitoring tool that I utilize as an inbox to capture interactions with a status board I built to visually track everything I have written down, as well as interactions with a Telegram bot (OpenAI’s new Dots achieve some of this functionality, which has been sorely needed in ChatGPT/Codex).

Said monitoring tool stands down every 30 minutes, so my agent restarts it on a schedule; that is what triggered an URGENT notification from Claude.

«

What’s remarkable is that Claude spotted the hack – which files had been changed, what had been added, precisely when it happened, and how to remove it. But Thompson has a strong point: Apple’s “install security updates automatically” option doesn’t automatically install security updates if they’re included as part of OS updates that you have chosen not to install automatically.

As he points out in the Dithering podcast with John Gruber, Apple needs to bend to the problem of allowing agents to run without needing stuff like Screen Sharing and constant clicking of security alerts. The simple solution: reanimate Mac OS X Server, designed for exactly this challenge. Which Apple discontinued in April 2022, just months before ChatGPT turned the world upside down in November that year.
unique link to this extract


A slow ceding of agency • Hot Takes

Adam Singer:

»

A voice or chat interface is in my opinion inferior to visually seeing all options (not just options the AI decides to show) presented in one window, with another window for your own research or context. As an adult I have a workstation with two monitors, plenty of screen real estate. I do not require an infantilized view, and since I am not cognitively impaired also do not require a machine to make decisions for me. Notably, I also don’t use mobile to accomplish these tasks, which are tasks suited for an office. Other people have no boundaries nor opinions on computing best practices and simply use mobile for everything. They’re measurably less happy by the way. I can see why they’d want to use AI instead, as they already don’t really like computing, do so without thought for ergonomics, sophisticated decision-making etc. Perhaps some percentage of the population doesn’t really want to do anything.

I’ve watched for years as the tech industry manically promotes the next thing merely because it’s new. But as agents are pushed on us, AI is especially pernicious because it presents a pretty large ceding of agency to machines. And while I want machines to do some things for me, I don’t want them to do everything. I personally disliked the time I even had a human personal assistant to book travel at a previous job. I prefer to do things myself (I also don’t pay someone else to work on my yard, aka get exercise outside for me, that’s enjoyable, too).

I want to live my own life, and that involves being capable and practiced at things, and more importantly, the one who decides the details. You start to lose something when you outsource too much of this. There’s a reason we encourage older people to stay socially, physically, and mentally active, and why cognitive stimulation is incorporated into care for people as they age. Using your brain, making decisions, remembering things, and learning skills are all forms of mental engagement. What happens when we systematically remove those little opportunities for agency and effort from everyday life, across an entire society? I don’t think we’ve really thought through what that means.

The irony here is so much of Silicon Valley talks about the importance of agency, and yet they themselves are building products that remove it from the user. A bit of “agency for me, not for thee”, and here, they are happy to become the intermediary in your life.

«

As you can see, Singer is not a fan of Silicon Valley’s obsession with AI agents.
unique link to this extract


• Why do social networks drive us a little mad?
• Why does angry content seem to dominate what we see?
• How much of a role do algorithms play in affecting what we see and do online?
• What can we do about it?
• Did Facebook have any inkling of what was coming in Myanmar in 2016?

Read Social Warming, my latest book, and find answers – and more.


Errata, corrigenda and ai no corrida: none notified

1 thought on “Start Up No.2757: Asos app shows hacking message, the gamer decompilation, Google data centre halted in Finland, and more”

  1. “(Google) had felled 330 hectares (815 acres) of forest in Muhos“

    Perhaps worth pointing out that there are 23 million (23000000) hectares of forests in Finland.

    Most of the forests, including the ones Google illegally cut, are monotonous industrial single tree forests or “tree fields”.

    Context is important and sadly nearly always missing when talking about data centres, be it land use, water use or anything else.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.