×
IT

Leak of MSI UEFI Signing Keys Stokes Fears of 'Doomsday' Supply Chain Attack (arstechnica.com) 62

A ransomware intrusion on hardware manufacturer Micro-Star International, better known as MSI, is stoking concerns of devastating supply chain attacks that could inject malicious updates that have been signed with company signing keys that are trusted by a huge base of end-user devices, a researcher said. From a report: "It's kind of like a doomsday scenario where it's very hard to update the devices simultaneously, and they stay for a while not up to date and will use the old key for authentication," Alex Matrosov, CEO, head of research, and founder of security firm Binarly, said in an interview. "It's very hard to solve, and I don't think MSI has any backup solution to actually block the leaked keys."

The intrusion came to light in April when, as first reported by Bleeping Computer, the extortion portal of the Money Message ransomware group listed MSI as a new victim and published screenshots purporting to show folders containing private encryption keys, source code, and other data. A day later, MSI issued a terse advisory saying that it had "suffered a cyberattack on part of its information systems." The advisory urged customers to get updates from the MSI website only. It made no mention of leaked keys. Since then, Matrosov has analyzed data that was released on the Money Message site on the dark web. To his alarm, included in the trove were two private encryption keys. The first is the signing key that digitally signs MSI firmware updates to cryptographically prove that they are legitimate ones from MSI rather than a malicious impostor from a threat actor. This raises the possibility that the leaked key could push out updates that would infect a computer's most nether regions without triggering a warning. To make matters worse, Matrosov said, MSI doesn't have an automated patching process the way Dell, HP, and many larger hardware makers do. Consequently, MSI doesn't provide the same kind of key revocation capabilities.

Virtualization

QEMU 8.0 Released with More ARM and RISC-V Emulation (9to5linux.com) 23

There's a major new update of QEMU, the open-source machine emulator, reports 9to5Linux: Coming a year after QEMU 7.0, the QEMU 8.0 release is here to improve support for ARM and RISC-V architectures.

- For ARM, it adds emulation support for FEAT_EVT, FEAT_FGT, and AArch32 ARMv8-R, CPU emulation for Cortex-A55 and Cortex-R52, support for a new Olimex STM32 H405 machine type, as well as gdbstub support for M-profile system registers.

- For the RISC-V architecture, QEMU 8.0 brings updated machine support for OpenTitan, PolarFire, and OpenSBI, additional ISA and Extension support for smstateen, native debug icount trigger, cache-related PMU events in virtual mode, Zawrs/Svadu/T-Head/Zicond extensions, and ACPI support. Moreover, RISC-V received multiple fixes covering PMP propagation for TLB, mret exceptions, uncompressed instructions, and other emulation/virtualization improvements.

Improvements were also made for the s390x (IBM Z) platform, the HP Precision Architecture (HPPA) platform, and x86.
Crime

Autonomy Founder Mike Lynch Loses Appeal Against Extradition To US (theguardian.com) 24

Mike Lynch, the tech entrepreneur once hailed as Britain's answer to Bill Gates, has lost an appeal against extradition to the US to answer criminal fraud charges. The Guardian reports: Lynch, the founding investor of the British cybersecurity firm Darktrace, is facing allegations that he duped the US firm Hewlett-Packard into overpaying when it struck an $11bn deal for his software firm Autonomy in 2011. Two high court judges considered Mike Lynch's challenge at a recent hearing in London and on Friday issued a ruling rejecting his appeal against extradition to face the charges.

Lynch, who could face a maximum prison sentence of 25 years if found guilty, has always denied the allegations and any wrongdoing. Lord Justice Lewis and Justice Julian Knowles ruled on Friday that Lynch, who made 500 million pounds from the sale to HP and was hailed as one of Britain's few global tech champions, should be extradited to the US to stand trial. Sushovan Hussain, Autonomy's former finance director, is already serving time in jail in the US after being found guilty of fraud relating to the same deal.

A spokesperson for Lynch said he was considering appealing to the European court of human rights. "Dr Lynch is very disappointed, but is reviewing the judgment and will continue to explore his options to appeal, including to the European court of human rights (ECHR)," he said. "The United States' legal overreach into the UK is a threat to the rights of all British citizens and the sovereignty of the UK." However, criminal defense law firm Corker Binning said that only 8% of applications to the ECHR in such cases -- seeking a Rule 39 order to stop the UK extradition until it has considered the case -- were successful last year.

HP

HP Outrages Printer Users With Firmware Update Suddenly Bricking Third-Party Ink (arstechnica.com) 199

An anonymous reader quotes a report from Ars Technica: HP customers are showing frustration online as the vendor continues to use firmware updates to discourage or, as users report, outright block the use of non-HP-brand ink cartridges in HP printers. HP has already faced class-action lawsuits and bad publicity from "dynamic security," but that hasn't stopped the company from expanding the practice. Dynamic security is a feature used by HP printers to authenticate ink cartridges and prevent use of cartridges that aren't HP-approved. As the company explains: "Dynamic security relies on the printer's ability to communicate with the security chips or electronic circuitry on the cartridges. HP uses dynamic security measures to protect the quality of our customer experience, maintain the integrity of our printing systems, and protect our intellectual property. Dynamic security equipped printers are intended to work only with cartridges that have new or reused HP chips or electronic circuitry. The printers use the dynamic security measures to block cartridges using non-HP chips or modified or non-HP electronic circuitry. Reused, remanufactured, and refilled cartridges that reuse the HP chip or electronic circuitry are unaffected by dynamic security."

HP is set on continuing to use DRM to discourage its printer customers from spending ink and toner money outside of the HP family. "HP have updated their printers to outright ban 'non-HP' ink! They no longer shows the 'can't guarantee quality' message, but instead cancels your print completely until you inset a HP ink cartridge," Reddit user grhhull posted Tuesday. "After contacting HP, they advised 'this is due to the recent 'update' of all printers.'" It's unclear when HP issued updates for which model printers, but there are alleged customer complaints online stemming from late last year, showing plenty of customers surprised their printer no longer worked with non-HP ink cartridges after an update. Some pointed to third-party brands they had relied on for years.

HP community support threads include complaints about the OfficeJet 7740 and OfficeJet Pro 6970. HP lists both printers, as well as others, as able to circumnavigate dynamic security under specific conditions. However, HP's support page states this only applies to models manufactured before December 1, 2016. For more examples, there are comments on HP's support community suggesting that HP's OfficeJet 6978 and 6968 were recently affected. Both printers are discontinued, but HP's product pages make it clear that the fickle nature of dynamic security means that third-party ink could stop working at any time. And HP's dynamic security page also leaves the door open for the sudden bricking of functioning ink: "Firmware updates delivered periodically over the internet will maintain the effectiveness of the dynamic security measures," the page reads. "Updates can improve, enhance, or extend the printer's functionality and features, protect against security threats, and serve other purposes, but these updates can also block cartridges using a non-HP chip or modified or non-HP circuitry from working in the printer, including cartridges that work today."

Businesses

Tesla Announces New Engineering HQ In California (thehill.com) 133

Slashdot reader Phact shares a report from The Hill: Elon Musk announced during a joint press conference with California Gov. Gavin Newsom that Tesla would be returning its global engineering headquarters to California, two years after a dramatic exit that saw the electric car company leave the Golden State for a facility in Austin, Texas. Tesla will open up shop in the former home of Hewlett Packard in Palo Alto, Musk said. The facility will serve as the company's engineering headquarters while the corporate headquarters remains in Austin.

Musk called the move into HP's old building a "poetic transition from the company that founded Silicon Valley to Tesla." Newsom has been a proponent of electric vehicles and revolutionizing America's energy production, and said he hopes the partnership between Musk and California will allow the state to "dominate in this space and change the way we produce and consume energy in this state, and this nation and the world we are trying to build." [...] Musk did not specifically address the reasoning for returning Tesla's headquarters to Silicon Valley. It's unclear if the state offered any incentives for the company to return, or if Musk simply wanted to be closer to the Twitter headquarters, which is located in San Francisco.
Tesla moved its headquarters out of California in late 2021 and into Texas. "At the time of the move, Musk was in an ongoing battle with Alameda County public health officials over his desire to reopen the Fremont manufacturing plant in the middle of the coronavirus pandemic," reports The Hill.
Printer

'My Printer Is Extorting Me', Complains Subscriber to HP's 'Instant Ink' Program (theatlantic.com) 253

A writer for the Atlantic complains that their HP printer is shaking them down like a loan shark. I discovered an error message on my computer indicating that my HP OfficeJet Pro had been remotely disabled by the company. When I logged on to HP's website, I learned why: The credit card I had used to sign up for HP's Instant Ink cartridge-refill program had expired, and the company had effectively bricked my device in response....

Instant Ink is a monthly subscription program that purports to monitor one's printer usage and ink levels and automatically send new cartridges when they run low. The name is misleading, because the monthly fee is not for the ink itself but for the number of pages printed. (The recommended household plan is $5.99 a month for 100 pages). Like others, I signed up in haste during the printer-setup process, only slightly aware of what I was purchasing. Getting ink delivered when I need it sounded convenient enough to me....

The monthly fee is incurred whether you print or not, and the ink cartridges occupy some liminal ownership space. You possess them, but you are, in essence, renting both them and your machine while you're enrolled in the program.... Here was a piece of technology that I had paid more than $200 for, stocked with full ink cartridges. My printer, gently used, was sitting on my desk in perfect working order but rendered useless by Hewlett-Packard, a tech corporation with a $28 billion market cap at the time of writing, because I had failed to make a monthly payment for a service intended to deliver new printer cartridges that I did not yet need....

There are tales of woe across HP's customer-support site, in Reddit threads, and on Twitter. A pending class-action lawsuit in California alleges that the Instant Ink program has "significant catches" and does not deliver new cartridges on time or allow those enrolled to use cartridges purchased outside the subscription service, rendering the consumer frequently unable to print. Parker Truax, a spokesperson for HP, told me, "Instant Ink cartridges will continue working until the end of the current billing cycle in which [a customer cancels]. To continue printing after they discontinue their Instant Ink subscription and their billing cycle ends, they can purchase and use HP original Standard or XL cartridges."

"Nobody told me that if I canceled, then all those cartridges would stop working," complains another owner of an HP printer cited in the article. "I guess this is our future, where your printer ink spies on you."

But the article ultimately concludes that the printer's shakedown is "just one example of how digital subscriptions have permeated physical tech so thoroughly that they are blurring the lines of ownership. Even if I paid for it, can I really say that I own my printer if HP can flip a switch and make it inert?"
GNOME

83% of GNOME Users Installed Extensions, Survey Shows (omglinux.com) 86

Last summer GNOME invited people to voluntarily run the tool gnome-info-collect on their systems to send back (non-sensitive/non-identifiable) data about their system configurations. 2,560 people ran the tool, and they're now releasing the data.

Here's the distribution of distros for all 2,560 respondents:

Fedora: 1,376 (54.69%)
Arch: 469 (18.64%)
Ubuntu: 267 (10.61%)
Manjaro: 140 (5.56%)
EndeavourOS: 66 (2.62%)
Debian: 44 (1.75%)
openSUSE: 38 (1.51%)
Pop! 38 (1.51%)
Other: 78 (3.10%)


And the breakdown of hardware manufacturers (top four):

Lenovo: 516 (23.54%)
Dell: 329 (15.01%)
ASUS: 261 (11.91%)
HP: 223 (10.17%)


The site OMG! Linux pointed out that 90% of systems had Flatpak installed — (though it's enabled by default on Fedora, which was 54.69% of all the respondents). Some other interesting stats they noticed: - Most common default browser: Firefox (73.14%), Chrome (11.64%), Brave (4.76%). [Microsoft Edge was the default browser on 37 systems (1.51%) ]

- 83% of users have at least one (non-default) GNOME extension installed
- 'App Indicator' is the most popular extension (by 43% of those using extensions)

- GSConnect, User Themes, and Dash to Panel/Dock also widely used

- Most popular desktop apps: GIMP (58.48%), VLC (53.71%), Steam (53.40%)


[...] The popularity of GNOME extensions will surprise no-one. It is a solid indicator that the existing GNOME extension system is good at doing what it's there to: let users augment and extend their system in the ways they want.

GNOME's report adds that "it's exciting to see the popularity of new GNOME apps like Flatseal, To Do, Bottles, and Fragments."

One other interesting stat from their report: 55% of the participants were using Online Accounts, with Google the most common one added, followed by Nextcloud and Microsoft. But "Some of the account types had very little usage at all, with Foursquare, Facebook, Media Server, Flickr and Last.fm all being active on less than 1% of systems."
Businesses

With PC Sales Down, Laptop Makers Turn To Services (theverge.com) 34

The PC market is in rough waters, and it was for much of last year. Every PC maker except Apple saw year-over-year decline. Laptop sales are said to have suffered the most. From a report: This all made for a somewhat uncertain backdrop heading into CES 2023, the annual conference where tech companies show off the products they'll be releasing in 2023. Throughout the show, executives and representatives from various PC manufacturers acknowledged that the industry has a big task ahead of it this year: keep the laptop exciting. Some companies are trying to do that with goofy hardware things (such as Lenovo's dual-screen, dual-OLED, and touchpad-less Yoga Book 9i). But others are moving away from hardware -- and the raw power that hardware can provide -- and emphasizing quirkier software capabilities in this year's lineups. AMD revealed that some of its new chips will come with its first Ryzen AI engine, built on its XDNA architecture.
Intel's upcoming Meteor Lake chips will also bring AI capabilities.
HP announced new features for its Omen Gaming Hub, including integration with Nvidia's GeForce Now, and new remote management and insight services for IT. A consumer Windows PC, the Dragonfly Pro, was also unveiled, with its integration with HP's new "live concierge" service touted as a highlight. The report adds: And HP isn't alone in this conviction -- quite a few other manufacturers that had a big presence at CES this year emphasized showy software features that utilized camera tracking and AI, from Asus' and Acer's glasses-free 3D displays to Razer's soundbar that follows your head around to optimize your music. Even Lenovo's aforementioned dual-screen Yoga Book is a software offering in many ways; the form factor is hardly new, but the investments Lenovo has made in an impressive system of gesture control are what make it a viable product.
Businesses

Chip Inventories Swell as Consumers Buy Fewer Gadgets (wsj.com) 56

The world is now awash in chips. The oversupply marks a sharp turnaround from a global shortage during two years of supercharged demand. From a report: Consumer appetite for electronics has weakened against a backdrop of rising interest rates, a falling stock market and recession fears. Chip inventories are swelling, mirroring what is happening in the wider economy where retailers are stuck with goods on their shelves and producers of a range of products in high demand early in the pandemic now face a glut. What is happening in chips amounts to good news for consumers who can get their hands on products from washing machines to laptops faster, and sometimes more cheaply, than a year ago. For chip makers, the shift has triggered a wave of job cuts and reduction in capital spending as companies try to restore profitability levels that have eroded in recent months.

Chip inventory levels are "well above our target level," said Sanjay Mehrotra, chief executive of memory maker Micron as the company on Thursday missed Wall Street earnings projections, gave a subdued outlook and said it would cut about 10% of its workforce. Lead times between chip orders and deliveries that swelled early in the pandemic have fallen in recent months, according to an analysis by Susquehanna International Group. Inventory levels, typically measured in days, are at their highest levels in more than a decade, or about 40 days above the median for the chip industry and its supply chain, according to a UBS analysis. Much of what is playing out for chip makers is illustrated by the reversal in fortunes that gadget makers have experienced over recent months. HP and Dell, two of the largest PC makers, say their products that flew off the shelves early in the pandemic now are sitting there for longer.

Christmas Cheer

NORAD Answers Questions About Their Annual Santa-Tracking Operation (noradsanta.org) 36

The North American Aerospace Defense Command is a US/Canada organization protecting the air sovereignty of the two nations.

But every year on December 24th, they also tell you where Santa is. From NORADSanta.org: The modern tradition of tracking Santa began in 1955 when a young child accidentally dialed the unlisted phone number of the Continental Air Defense Command Operations Center upon seeing an newspaper advertisement telling kids to call Santa. The Director of Operations, Colonel Harry Shoup, answered the phone and instructed his staff to check the radar for indications of Santa making his way south from the North Pole.... Each year since, NORAD has dutifully reported Santa's location on Dec. 24 to millions of children and families across the globe. NORAD receives calls from around the world on Dec. 24 asking for Santa's location. Children, families and fans also keep track of Santa's location on the NORAD Tracks Santa® website and our social media platforms.
The page lists the NORAD technologies involved in tracking Santa — including 47 radar installations and geo-synchronous satellites with infrared heat sensors. ("Rudolph's nose gives off an infrared signature similar to a missile launch...")

And this year NORAD also produced a special video highlighting the various military fleets protecting Santa. ("He may know when you're sleeping, he may know when you're awake... " it tells viewers. "But for 67 years now, when he takes flight, we'll know.")

More from NORADSanta.org: Canadian NORAD fighter pilots, flying the CF-18, take off out of Newfoundland and welcome Santa to North America. Then at numerous locations in Canada other CF-18 fighter pilots escort Santa. While in the United States, American NORAD fighter pilots in either the F-15s, F16s or F-22s get the thrill of flying with Santa and the famous Reindeer...

Q: How can Santa travel the world within 24 hours?

A: NORAD intelligence reports indicate that Santa does not experience time the way we do. His trip seems to take 24 hours to us, but to Santa it might last days, weeks or even months. Santa would not want to rush the important job of delivering presents to children and spreading joy to everyone, so the only logical conclusion is that Santa somehow functions within his own time-space continuum....

How does Santa get down chimneys?

Although NORAD has different hypotheses and theories as to how Santa actually gets down the chimneys, we don't have definitive information to explain the magical phenomenon.

Do your planes ever intercept Santa?

Over the past 65 years, our fighter jets (F-16s, F-15s, F-22s and CF-18s) have intercepted Santa many, many times. When the jets intercept Santa, they tip their wings to say, "Hello Santa! NORAD is tracking you again this year!" Santa always waves. He loves to see the pilots...!

How many people support this effort, and are they active duty military personnel?

More than 1,250 Canadian and American uniformed personnel and DOD civilians volunteer their time on December 24th to answer the thousands of phone calls and emails that flood in from around the world. In addition to the support provided by our corporate contributors to make this program possible, NORAD has two lead project officers who manage the program.

How much money is spent on this project?

The NORAD Tracks Santa program is made possible by volunteers and through the generous support of corporate licensees who bear virtually all of the costs.

Corporate contributors include Microsoft (with separate contributions from Microsoft's search engine Bing and from Microsoft Azure), AWS (and Amazon's Alexa), Verizon, and HP.

NORADSanta.org also boasts extra features like an "arcade" of online games, a jukebox of Christmas tunes, and a library of online books about Santa. And the site even provides some technical data on the weight of Santa's sleigh — although the unit of measurement used is gumdrops.
Government

Lobbyists Have Held Up Nation's First Right-To-Repair Bill In New York (arstechnica.com) 32

An anonymous reader quotes a report from Ars Technica: The Digital Fair Repair Act, the first right-to-repair bill to entirely pass through a state legislature, is awaiting New York Governor Kathy Hochul's signature. But lobbying by the nation's largest technology interests seems to have kept the bill parked on her desk for months, where it could remain until it dies early next year. Gay Gordon-Byrne, executive director of the Repair Association, said that "opposition has not backed off" despite the bill's nearly unanimous passage in June. Gordon-Byrne has heard that industry groups are pushing for late amendments favoring tech firms but that the bill's sponsors would have to approve -- or convince the governor to sign the bill without them. "It's up to the sponsors at this point," she said. The bill was delivered to the governor Friday, according to the New York Senate's bill tracker, though she has been considering it since late June.

Since passing in June, the New York bill has been aggressively lobbied by various trade groups to limit its impact. An earlier version of the bill would have included lawn equipment, gaming consoles, and appliances, but a "burst of end-of-session lobbying from companies worth billions and their affiliated trade associations" succeeded in stripping the bill down to small electronics, according to the Times Union of Albany. Assemblymember Patricia Fahy, the bill's sponsor, slimmed it down to ensure some part of it could pass in June. State filings showed that trade group TechNet (not to be confused with Microsoft's social/wiki entity) and lobbyists for Microsoft and Apple jumped in then, focusing their efforts on Hochul's office as the bill seemed destined to pass. The Times Union reported that Apple, Google, HP, and Microsoft all paid lobbyists from "the highest-earning professional lobbying firms in Albany" to push back against the bill at the legislative and executive levels.
The report notes that the governor has 30 days to act on the bill. "Failing to act has the same effect as a veto (a "pocket veto")."

Asked about the bill's status today by Ars Technica, a spokesperson responded that "Governor Hochul is reviewing the legislation."
Unix

OSnews Decries 'The Mass Extinction of Unix Workstations' (osnews.com) 284

Anyone remember the high-end commercial UNIX workstations from a few decades ago — like from companies like IBM, DEC, SGI, and Sun Microsystems?

Today OSnews looked back — but also explored what happens when you try to buy one today> : As x86 became ever more powerful and versatile, and with the rise of Linux as a capable UNIX replacement and the adoption of the NT-based versions of Windows, the days of the UNIX workstations were numbered. A few years into the new millennium, virtually all traditional UNIX vendors had ended production of their workstations and in some cases even their associated architectures, with a lacklustre collective effort to move over to Intel's Itanium — which didn't exactly go anywhere and is now nothing more than a sour footnote in computing history.

Approaching roughly 2010, all the UNIX workstations had disappeared.... and by now, they're all pretty much dead (save for Solaris). Users and industries moved on to x86 on the hardware side, and Linux, Windows, and in some cases, Mac OS X on the software side.... Over the past few years, I have come to learn that If you want to get into buying, using, and learning from UNIX workstations today, you'll run into various problems which can roughly be filed into three main categories: hardware availability, operating system availability, and third party software availability.

Their article details their own attempts to buy one over the years, ultimately concluding the experience "left me bitter and frustrated that so much knowledge — in the form of documentation, software, tutorials, drivers, and so on — is disappearing before our very eyes." Shortsightedness and disinterest in their own heritage by corporations, big and small, is destroying entire swaths of software, and as more years pass by, it will get ever harder to get any of these things back up and running.... As for all the third-party software — well, I'm afraid it's too late for that already. Chasing down the rightsholders is already an incredibly difficult task, and even if you do find them, they are probably not interested in helping you, and even if by some miracle they are, they most likely no longer even have the ability to generate the required licenses or release versions with the licensing ripped out. Stuff like Pro/ENGINEER and SoftWindows for UNIX are most likely gone forever....

Software is dying off at an alarming rate, and I fear there's no turning the tide of this mass extinction.

The article also wonders why companies like HPE don't just "dump some ISO files" onto an FTP server, along with patch depots and documentation. "This stuff has no commercial value, they're not losing any sales, and it will barely affect their bottom line.
Security

Samsung Galaxy S22 Hacked Again On Second Day of Pwn2Own (bleepingcomputer.com) 18

Contestants hacked the Samsung Galaxy S22 again during the second day of the consumer-focused Pwn2Own 2022 competition in Toronto, Canada. They also demoed exploits targeting zero-day vulnerabilities in routers, printers, smart speakers, and Network Attached Storage (NAS) devices from HP, NETGEAR, Synology, Sonos, TP-Link, Canon, Lexmark, and Western Digital. BleepingComputer reports: Security researchers representing the vulnerability research company Interrupt Labs were the ones to demonstrate a successful exploit against Samsung's flagship device on Wednesday. They executed an improper input validation attack and earned $25,000, 50% of the total cash award, because this was the third time the Galaxy S22 was hacked during the competition.

On the first day of Pwn2Own Toronto, the STAR Labs team and a contestant known as Chim demoed two other zero-day exploits as part of successful improper input validation attacks against the Galaxy S22. In all three cases, according to the contest rules, the devices ran the latest version of the Android operating system with all available updates installed.

The second day of Pwn2Own Toronto wrapped up with Trend Micro's Zero Day Initiative awarding $281,500 for 17 unique bugs across multiple categories. This brings the first two days of Pwn2Own total to $681,250 awarded for 46 unique zero-days, as ZDI's Head of Threat Awareness Dustin Childs revealed. The full schedule for Pwn2Own Toronto 2022's second day and the results for each challenge are available here. You can also find the complete schedule of the competition here.

Technology

The Internet Archive's PalmPilot Emulation Project Lets You Relive Tech History (engadget.com) 31

An anonymous reader shares a report: Fifteen years after the release of the iPhone, it's easy to overlook the role early innovators like Palm played in popularizing the smartphone. By the time HP unceremoniously shut down the company in 2011, Palm had struggled for a few years to carve out a niche for itself among Apple and Google. But ask anyone who had a chance to use a Palm PDA in the late '90s or early 2000s and they'll tell you how fondly they remember the hardware and software that made the company's vision possible. Now, it's easier than ever to see what made Palm OS so special back in its day.

Last week, archivist Jason Scott uploaded a database of Palm OS apps to the Internet Archive. In all, there are about 560 programs to check out, including old favorites like DopeWars and SpaceTrader. Even if you don't have any nostalgia for Palm, it's well worth spending a few minutes with the collection to see how much -- or, in some cases, little -- things have changed since Palm OS was a dominant player in the market. For instance, there's an entire section devoted to shareware and it's interesting to see just how much some developers thought it was appropriate to pay for their software. Want to use the full version of StockCalc? Just send $15 by post to DDT Investments in Plaistow, New Hampshire.

Transportation

Automakers Are Locking the Aftermarket Out of Engine Control Units (roadandtrack.com) 175

This month Road & Track looked at "increased cybersecurity measures" automakers are adding to car systems — and how it's affecting the vendors of "aftermarket" enhancements: As our vehicles start to integrate more complex systems such as Advanced Driver Assist Systems and over-the-air updates, automakers are growing wary of what potential bad actors could gain access to by way of hacking. Whether those hacks come in an attempt to retrieve personal customer data, or to take control of certain aspects of these integrated vehicles, automakers want to leave no part of that equation unchecked. "I think there are very specific reasons why the OEMs are taking encryption more seriously," HP Tuners director of marketing Eddie Xu told R&T. "There's personal identifiable data on vehicles, there's more considerations now than just engine control modules controlling the engine. It's everything involved."

In order to prevent this from becoming a potential safety or legal issue, companies like Ford have moved to heavily encrypt their vehicle's software. S650 Mustang chief engineer Ed Krenz specifically noted that the new FNV architecture can detect when someone attempts to modify any of the vehicle's coding, and that it can respond by shutting down an individual vehicle system or the vehicle entirely if that's what is required.

That sort of total lockout presents an interesting challenge for [car performance] tuners who rely on access to things like engine and transmission control modules to create their products.

Last month Ford acknowledged tuners would find the S650 Mustang "much more difficult," the article points out. And they add that Dodge also "intends to lock down the Engine Control Units of its upcoming electric muscle car offerings, though it will offer performance upgrades via its own over-the-air network."

"We don't want to lock the cars and say you can't modify them," Dodge CEO Kuniskis told Carscoops. "We just want to lock them and say modify them through us so that we know it's done right."

Thanks to long-time Slashdot reader schwit1 for submitting the article.
HP

HP Will Cut Up To 6,000 Jobs Over Next Three Years 32

Computer and printer maker HP said Tuesday it will cut between 4,000 and 6,000 jobs by the end of 2025 as part of a restructuring. Axios reports: HP said the move will save it at least $1.4 billion annually by the end of fiscal 2025. However, it expects to incur $1 billion in costs due to the restructuring, with $600 million in fiscal 2023 and the rest split over the remaining two years. It made the announcement alongside its quarterly earnings report.

As part of that report, HP said to expect per-share earnings of 70 cents to 80 cents, excluding items. That's below consensus expectations of about 86 cents per share, per CNBC.
Further reading: A Host of Tech Companies, Including Coinbase, Robinhood, Lyft, and Stripe, Announce Hiring Freezes and Job Cuts
Hardware

PC Shipments Are Still on the Decline - Unless You're Apple (theregister.com) 99

Global PC shipments declined in calendar Q3 by 15 percent year-on-year thanks to reduced demand and lingering supply chain issues, according to number cruncher IDC. From a report: The Q3 slowdown is similar to that seen in Q2 2022, when shipments crashed by 15.3 percent year-on-year. The slowed growth didn't just start this year. Signs first emerged in Q3 2021 as Chromebooks hit market saturation. For perspective, volumes still remain higher than before the COVID-19 pandemic.

Shipments also aren't as low as they could be thanks to companies like Apple that drove business with promotions. As industry-wide supply hit record lows, Apple supply increased to make up for lost orders during China's Q2 lockdowns, according to IDC research manager Jitesh Ubrani. [...] Apple came in fourth place in terms of market share for Q3 PC shipments behind Lenovo (first), HP (second), and Dell (third). While other companies declined in year-on-year growth, Apple soared with a net positive 40.2 percent increase in shipments year-on-year to 10.06 million Macs.

AMD

Rewritten OpenGL Drivers Make AMD's GPUs 'Up To 72%' Faster in Some Pro Apps (arstechnica.com) 23

Most development effort in graphics drivers these days, whether you're talking about Nvidia, Intel, or AMD, is focused on new APIs like DirectX 12 or Vulkan, increasingly advanced upscaling technologies, and specific improvements for new game releases. But this year, AMD has also been focusing on an old problem area for its graphics drivers: OpenGL performance. From a report: Over the summer, AMD released a rewritten OpenGL driver that it said would boost the performance of Minecraft by up to 79 percent (independent testing also found gains in other OpenGL games and benchmarks, though not always to the same degree). Now those same optimizations are coming to AMD's officially validated GPU drivers for its Radeon Pro-series workstation cards, providing big boosts to professional apps like Solidworks and Autodesk Maya. "The AMD Software: PRO Edition 22.Q3 driver has been tested and approved by Dell, HP, and Lenovo for stability and is available through their driver downloads," the company wrote in its blog post. "AMD continues to work with software developers to certify the latest drivers." Using a Radeon Pro W6800 workstation GPU, AMD says that its new drivers can improve Solidworks rendering speeds by up to 52 or 28 percent at 4K and 1080p resolutions, respectively. Autodesk Maya performance goes up by 34 percent at 4K or 72 percent at the default resolution. The size of the improvements varies based on the app and the GPU, but AMD's testing shows significant, consistent improvements across the board on the Radeon Pro W6800, W6600, and W6400 GPUs, improvements that AMD says will help those GPUs outpace analogous Nvidia workstation GPUs like the RTX A5000 and A2000 and the Nvidia T600.
Amiga

Ask Slashdot: What Was Your First Computer? 523

Long-time Slashdot reader destinyland writes: Today GitHub's official Twitter account asked the ultimate geek-friendly question. "You never forget your first computer. What was yours?"

And within 10 hours they'd gotten 2,700 responses.

Commodore 64, TRS-80, Atari 800, Compaq Presario... People posted names you haven't heard in years, like they were sharing memories of old friends. Gateway 2000, Sony VAIO, Vic-20, Packard Bell... One person just remembered they'd had "some sort of PC that had an orange and black screen with text and QBasic. It couldn't do much more than store recipes and play text based games."

And other memories started to flow. ("Jammed on Commander Keen & Island of Dr. Brain..." "Dammit that Doom game was amazing, can't forget Oregon Trail...")

Sharp PC-4500, Toshiba T3200, Timex Sinclair 1000, NEC PC-8801. Another's first computer was "A really really old HP laptop that has a broken battery!"

My first computer was an IBM PS/2. It had a 2400 baud internal modem. Though in those long-ago days before local internet services, it was really only good for dialing up BBS's. I played chess against a program on a floppy disk that I got from a guy from work.

Can you still remember yours? Share your best memories in the comments.

What was your first computer?
Canada

World's First Commercial Electric Seaplane Completes Short-Haul Flight (newatlas.com) 75

"An aviation company at the cutting edge of electrified air travel has taken a significant step forward, completing a first-of-a-kind test flight using a retrofitted seaplane," reports New Atlas: Harbour Air's De Havilland Beaver completed a short hop from the Canadian mainland to Vancouver Island using its all-electric drivetrain, demonstrating the viability of its cleaner approach to short-haul flights.

Harbour Air is the largest seaplane airline in North America and claims to transport around half a million passengers across 30,000 commercial flights each year. In 2019, it pledged to become the world's first all-electric airline, a bold vision that involves retrofitting its fleet of existing six-seater seaplanes with electric propulsion systems. These systems come via a partnership with electric motor company MagniX, which is making important advances with its high-power electric motors and has partnered with other ambitious companies in the aviation space.

In December of 2019, the modified De Havilland Beaver took off to complete the first successful flight of an all-electric commercial aircraft, a brief jaunt above the Fraser River at Harbour Air's terminal in Richmond, British Columbia. The company has since continued this testing program with an eye to certifying and approving the aircraft with the US Federal Aviation Administration (FAA) and Transport Canada.

"The historic De Havilland Beaver has been completely retrofitted in 2019 to operate using 100% electricity flew 45 miles in 24 minutes," the company said in a statement. They're calling the flight "a major milestone in the advancement of all-electric commercial flights." More data from the ePlane's web site: Our ePlane project will ultimately turn our 40+ fleet of seaplanes from carbon-neutral to carbon-zero!

We know that the electrification of our fleet is the next necessary step to truly make a difference in our environmental and economic goals. It is better for the communities we serve and it also to gives our passengers a better way to travel. It's a bold step in making a big difference for our planet.


Slashdot Top Deals