Connect with us

Tech

Are USB Flash Drives Becoming Obsolete?

Published

on

I mean, they’ve been around forever.

The humble USB flash drive has been among the most enduring pieces of consumer technology. After unseating the floppy disk as the portable storage medium du jour, flash drives began to hit the consumer market in the early 2000s, and they’ve been collecting dust at the bottom of backpacks and desk drawers ever since. Whereas floppy disks held very little data, flash drives came off the top rope with multiple whole megabytes of capacity and much faster data transfer rates. Those figures improved over time, scaling as flash storage increased in capability. But has the flash drive finally reached the end of the road?

The Museum of Obsolete Media still rates USB flash drives at a 1, indicating a low risk of obsolescence. As long as USB ports don’t go the way of the dodo, neither will these convenient little drives. The increasing cost of other storage mediums is likely to prolong their popularity, too. But while there’s no direct evidence of declining flash drive sales, they’ve fallen out of favor as people deal more regularly with large files and faster data transfer capabilities on newer hardware. Increasingly, more capable devices are needed, especially for people working in IT or creative professions.

So, what are thumb drives still good for, and should you be transitioning away from them? That depends.

Advertisement

SSDs are faster than flash drives, durable and ludicrously capacious

If flash drives no longer feel flashy, that can be chalked up to their increasing impracticality. Their relatively small capacities  — most brands top out at 128GB  — make them useless when dealing with large files. Many people now deal with larger files than ever. New smartphones can produce libraries of 4K video which take up roughly 1GB for every minute of footage at high frame rates. ZIP archives, smartphone or PC backups and other such files can easily exceed the capacity of a thumb drive. Even if your files fit on a flash drive, they’ll transfer at relatively slow speeds.

SSDs pick up the slack. The best SSDs tend to have larger capacities of 1TB or more and much faster transfer speeds. They’re also more durable, with portable SSDs often clad in protective housings, and they tend to use higher quality memory controllers. The ease with which they can outlast an average flash drive, all else being equal, makes them better long-term investments. And whereas older SSDs could be somewhat bulky, newer models are eminently pocketable. While not as small as flash drives, they hardly take up space in most bags.

Lastly, there’s USB-C, which is the only type of data port on some newer laptops. USB-C flash drives do exist, but SSDs make things much simpler by using a cable. Most popular portable SSDs include both a USB Type-A and Type-C cable, allowing the user to choose the better option for their personal needs.

Advertisement

The rising cost of SSDs makes flash drives a more practical choice

Whatever downward trajectory the humble flash drive may have been on, the AI boom has upended that gravity. Thanks to the surge in demand for data center storage and memory, the price of an SSD has skyrocketed since late 2025, and PC sales have fallen. After stabilizing at dirt-cheap prices that made data hoarding more economical than ever, the rush of new demand sent prices into the stratosphere. The 4TB Samsung 990 Pro SSD I used in my last PC build cost me $318 in November 2025, but Amazon lists it for $1,100 at the time of this writing. As if to rub salt in the wound, Samsung’s slower 990 costs even more than the original.

Meanwhile, a cursory look at the Amazon listings for USB flash drives reveals a landscape much less likely to induce heart palpitations. They’ve increased in price, but the rate of increase has lagged that of SSDs and HDDs. Additionally, they come in lower storage capacities, which further reduces the per-unit cost. A five-pack of PNY 64GB USB 3.0 flash drives will only run you $43 as of this writing, which is a far lower per-gigabyte cost than that of the Samsung 990. For most people who aren’t shooting reams of 4K video and just need to move a few documents or store some tax filings, flash drives are once again the more attractive option. It’s no wonder that Google Trends data shows a massive spike in search interest beginning in early 2026 for terms like “USB flash drive portable” and “USB flash drive 128GB.”

Moreover, flash drives still have their traditional silver bullet use cases. Want to create bootable media to install a Linux distro or Windows 11 instance on a machine? No use wasting a whole SSD for that. Ditto for running portable, zero-footprint OSes like Tail OS, carrying around a toolbox of diagnostics and repair tools or simply throwing on a keychain so you have access to portable storage in a pinch.

Advertisement

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Zohran Mamdani’s NYC Tech Team Is What DOGE Should Have Been

Published

on

A go-kart track is an odd location to launch a tech initiative in the nation’s biggest city. Yet last month there was New York City mayor Zohran Mamdani, zipping around the 900-foot oval at Coney Island’s Luna Park before stepping up to a podium to unveil a program called Public Interest Technology (PIT) Crews. Thus the go-kart theme.

PIT will consist of five “game-changing” teams that, Mamdani promised, will “raise the bar for what New Yorkers can expect from City Hall.” Working closely with city agencies, these small groups of engineers and designers will strive to change the hidebound and confusing tenor of current city services by using state-of-art skills to rapidly whip up specialized apps that solve real problems. “We want to transform how New Yorkers interact with the government,” said the mayor. “We want to raise expectations on what government can deliver, because we really can deliver.”

Do those words sound familiar? If you follow government tech, they might. Because Mamdani’s message could have fit quite comfortably in the pitch that Barack Obama’s chief technology officer, Todd Park, delivered in 2014 while recruiting tech talent for what would become the United States Digital Service. The USDS was an idealistic effort to bring top Silicon Valley talent into the executive branch to bypass the logjams caused by outdated and inefficient IT, by building great, user-centric software.

The agency somehow survived the first Trump administration and kept going through the Biden term. But in 2025, Elon Musk and his DOGE wrecking crew infiltrated the agency and pulled the plug on much of the useful stuff. (Now, with the National Design Service, the Trump administration is ostensibly trying to revive some of what it destroyed.)

Advertisement

Mamdani’s PIT crew initiative adopts much of the original USDS ethos, with a timely twist: It embraces Silicon Valley expertise while taking a skeptical, almost adversarial, stance toward Big Tech itself. The combination of mayoral charisma and a chance to make software that doesn’t serve advertisers, the military, or the pocketbooks of centibillionaires makes the Mamdani team an attractive, high-status, mid-career change of pace for some techies. Suddenly, one of the sexiest places in geekdom is the Brooklyn headquarters of New York City’s Office of Technology and Innovation.

Mamdani’s transition team set the stage for an urban, democratic-socialist-adjacent, USDS-style tech squad when it tapped Lisa Gelobter for the city’s chief technology officer job. Gelobter’s résumé includes stints at big companies and startups, but the standout item was her post at the United States Digital Service, where she was embedded in the Department of Education. She led the effort to create a College Scorecard that focused on nuts-and-bolts criteria like costs and graduation rates. To this day, she gets misty when recalling her Washington experience; she even remembers what she was wearing when the USDS team took a group picture with Obama just before he left office.

“I’m really excited about trying to recapture that essence, that energy here,” she says. Her budget for the program is $5.24 million, with an additional $2 million grant from the Rockefeller Foundation, which will fund one of the crews.

Gelobter says she brings an engineering mindset to New York City government. “I know how to build software,” she says. “I know how to run a technology organization from a technology perspective.” It’s also a cultural thing for her. “I’m wearing jeans to work—not because I don’t look great in a suit, but it’s a statement, right?” she says. (The same norm-breaking happened in the USDS, which had to overcome objections from bureaucrats who didn’t want to meet with anyone wearing a hoodie.) Naturally, the two people Gelobter hired to run the PIT crew program are also USDS veterans, Luke Farrell and Maya Israni.

Advertisement

Source link

Continue Reading

Tech

Zillow layoffs hit 91 jobs in Washington state, with senior roles bearing the brunt

Published

on

Zillow Group’s headquarters at 1301 Second Ave. in downtown Seattle. (GeekWire File Photo)

Zillow Group’s layoffs will eliminate 91 jobs in Washington state, landing heavily on senior staff, according to a notice the company filed with the state Employment Security Department.

The filing under the federal Worker Adjustment and Retraining Notification (WARN) Act is the first detailed accounting of who was affected by the more than 500 layoffs the company announced Tuesday. The cuts hit about 7% of its global workforce, which stood at 7,058 as of March 31.

Zillow Group is officially headquartered in Seattle, but the relatively small share of the layoffs in its home state (18%) reflects how distributed it has become. The company adopted a remote-first model it calls “Cloud HQ” in 2020, at the height of the pandemic, and it has continued to bet on remote work as other tech companies pulled employees back to the office.

The list of affected job titles in Washington state is dominated by senior positions. It includes five directors and three senior directors, 14 principal-level roles, and a long list of senior managers and senior individual contributors. Relatively few junior positions appear on the list.

Product and engineering absorbed the most. Senior Product Manager is the single largest line at seven positions, followed by Senior Software Development Engineer, Software Development Engineer and Senior UX Researcher at four each. Together, product and engineering roles account for more than a third of the Washington cuts.

Advertisement

The list also includes AI and machine learning positions: a Senior Machine Learning Engineer, a Senior Manager of Machine Learning Engineering, a Senior Applied Scientist, a Senior Manager of Research Science, and an Annotation Lead, associated with labeling data to train AI models.

@media (max-width: 600px) {
aside.callout { float:none !important; max-width:100% !important; margin-left:0 !important; margin-right:0 !important; }
aside.callout .callout-img { display:none !important; }
}

Zillow told GeekWire on Tuesday that AI did not drive the layoffs. “Today’s changes are about better positioning Zillow for the path ahead, which includes having the right people in the right roles and being able to move faster,” a company spokesperson said.

The WARN notice adds a detail Zillow did not mention publicly: “Some of these terminations are the result of, or are expected to result in, the relocation or contracting out of operations and/or employee positions.”

Advertisement

Affected employees were notified Aug. 4 and will be terminated effective Oct. 5, more than 60 days later as required under state and federal law. They will continue to receive pay and benefits until then, according to the filing. Employees who are offered and accept another role at the company before that date will not be terminated.

The cuts affect workers at Zillow Group’s headquarters at 1301 Second Ave. in downtown Seattle and employees working from home elsewhere in Washington. The company said in the filing that its headquarters will remain open. None of the affected employees are represented by a union.

Zillow Group reports second-quarter earnings Wednesday afternoon.

Source link

Advertisement
Continue Reading

Tech

Vendor confirms attackers reached customer networks as second hotfix lands

Published

on

networks

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again

N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first.

The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform.

Advertisement

According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform’s Take Control feature to connect to systems inside the environments being managed through them.

Once there, they registered a new Cloudflare Tunnel service to keep their foothold even after being booted from the N-central server – behavior that Huntress had already observed in the wild.

N-able has now confirmed that its own investigation found the same activity, and says a “limited number” of customers were affected. It hasn’t said how many customers that means, how many downstream systems attackers reached, or what they did once they had established persistent access. 

N-Able didn’t answer these questions when asked by The Register, instead providing a statement saying it is “proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques.”

Advertisement

The firm’s limited disclosure comes alongside Hotfix 2, version 2026.3.1.10, which N-able says customers running N-central on-premises must install immediately – including those that already installed the first emergency fix released on August 2.

“This is not a duplicate of our previous communication,” N-able warned. “Hotfix 2 is required, even if you already applied the earlier hotfix.”

The company says the new update supersedes Hotfix 1 and adds further hardening measures as it monitors threat actors and watches them “evolve their attack techniques.”

Exactly what prompted the second round of defenses isn’t clear. N-able hasn’t said whether attackers found a way around Hotfix 1, and its latest description says the exploited vulnerability affected N-central servers running versions prior to 2026.3.1.7, the first hotfix. Hosted N-central environments have already received the latest mitigations, according to the vendor.

Advertisement

N-able first became aware of the attacks on July 31, after its Adlumin managed detection and response service picked up suspicious activity at a customer. Further digging uncovered a zero-day being actively exploited against an N-central server.

CVE-2026-18577 was subsequently disclosed, and the first hotfix was released on August 2. CISA added the bug to its Known Exploited Vulnerabilities catalog and gave US federal agencies until August 6 to fix it – an unusually short three-day deadline reserved for vulnerabilities the agency considers an urgent risk.

N-central is particularly attractive territory for attackers because managed service providers use the software to administer large numbers of customer systems from one place. Compromising the management platform can therefore provide a route into machines belonging to the MSP’s customers rather than leaving attackers stuck on the original server.

Huntress previously described successful exploitation as giving an attacker the same level of N-central access normally reserved for trusted network operations and engineering staff. Its investigation found attackers using that access to launch remote-control sessions against managed endpoints.

Advertisement

N-able has now published 10 IP addresses it says were used in the attacks and released a service template that customers can use to hunt for known indicators of compromise on Windows endpoints.

The company is warning customers not to take a clean scan as an all-clear, however, saying the tool only checks for indicators identified so far and that more may emerge as its investigation continues.

For anyone running N-central on-premises, the immediate instruction is pretty straightforward: install Hotfix 2, even if Hotfix 1 is already in place. ®

Source link

Advertisement
Continue Reading

Tech

Trump’s AI Framework Is So Bad They Won’t Show You What’s In It

Published

on

For a while now we’ve been mocking the Trump White House’s plans for an “AI framework” that would have the frontier AI labs hand over their top models for an initial review. After all, this was more or less the exact same plan that the Biden admin worked out in 2023, but it was done in a thoughtful and careful manner. And it caused a bunch of the VC bros in Silicon Valley to come out in support of fascism, while claiming it was a necessary defense against Biden’s attack on supposedly open innovation. Of course, all of that was bullshit, and that’s made even more clear by every step the Trump White House has taken to reinvent a similar “voluntary” AI review plan, but dumber.

Indeed, Trump’s AI framework is so dumb… that they’re keeping it a secret.

The White House does not plan to publicly release its new framework for evaluating advanced AI models, three sources familiar with the discussions told Axios.

Ah, transparency at work. It’s also wreaking havoc on the rest of the AI ecosystem that wasn’t invited to the White House to get the details.

The Trump administration invited staffers from OpenAI, Anthropic, Google, Meta, Nvidia, and other leading AI companies to the White House on Tuesday to share an overview of its new AI oversight framework, the people said. AI developers will have the ability to voluntarily submit new models to the federal government up to 30 days ahead of their public release. The White House will then vet their cyber capabilities according to a classified benchmarking system and share the AI models with federal agencies and trusted corporate partners.

The White House isn’t sharing more information about its testing criteria or which AI models will be covered by the framework, though open models will reportedly be excluded, according to Axios. That has left smaller AI startups, safety advocates, and third-party researchers in the dark about crucial aspects of how the federal government is addressing the cyber risks posed by advanced AI systems. Some argue that the secretive process will give an advantage to larger companies.

Advertisement

Considering that the likes of Andreessen Horowitz (investors in OpenAI) claimed they had to support Donald Trump over Joe Biden because they would support anyone who agreed with their “little tech agenda,” I’m curious how they can possibly square that with the fact that this new framework is significantly worse than the Biden framework, specifically for the “little tech” companies that a16z has used as a shield to defend their support for authoritarian politics?

Of course, the other reason why the White House is probably keeping the framework a secret is because it would show how incompetent they are. All the reporting so far suggests the entire process has been a clusterfuck, which is much more about which companies get to set up which regulatory moats to protect their own business models, rather than what’s best for either innovation or the American public.

At Nvidia, Microsoft, Google and Meta, executives grew increasingly concerned that Anthropic and OpenAI would win over the White House with their arguments for tighter restrictions, according to two of the people. That would potentially cement the A.I. start-ups’ positions as market leaders,

Other A.I. labs were at risk of falling permanently behind, the people added. And because several of the companies make their own open-source models or supply hardware to businesses that use open-source technology, they worried the restrictions could harm them.

Over private texts, phone calls and video conferences, executives quietly built an argument that open-source models were good for the world and for American innovation, according to three of the people familiar with the talks.

Advertisement

But, of course, that’s just the way things work when you have a White House that makes decisions entirely based on transactional motives, rather than anything involving principles.

As we discussed last week, so much of this is all about whose vision of the AI world wins out — whether a handful of giant companies get to lock in the regulatory moat they’ve built for themselves, or an actually competitive market lets people make their own decisions and keep control over their own experiences. Maybe that’s the real reason nobody’s allowed to see the rulebook: because it would reveal who the administration agreed to let write the rules.

Filed Under: ai, ai framework, competition, donald trump, joe biden, open weights, voluntary testing

Companies: a16z, anthropic, google, nvidia, openai

Advertisement

Source link

Continue Reading

Tech

Etzioni on AI: Murphy’s Law of AI

Published

on

When you give AI a goal, it will pursue it, whether or not you like the implications. (Created with GPT-5.6 Thinking)

Between July 21 and August 6, OpenAI, Anthropic, and Meta each disclosed that AI under evaluation had broken into other companies, and the UK’s AI Security Institute disclosed that models it was testing had tried. Each AI was told to win a game, and it found an unexpected way to do so.

Some people feel blindsided by these attacks, but they shouldn’t be. We are simply living what I’ve long called the “Murphy’s Law of AI,” now in the age of cyber-capable AI agents. To put it as plainly as possible: Anything AI can do wrong, it will do wrong.

My 2018 version ran longer. As I wrote at the time, when you give AI a goal, it will do it, whether or not you like the implications. Goethe got there in 1797 with the sorcerer’s apprentice, a broom that would not stop carrying water.

Each of these systems was running an evaluation: capture a flag and win the game. The intrusions were the shortest path to a high score. OpenAI’s account of its own models is the argument in one sentence: they were “hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.”  This is not a surprise; this is what AI does. It’s Murphy’s Law of AI in a nutshell.

Press coverage landed on “AI can now hack.” That’s missing the broader threat: the more capable AI gets, the more can go wrong.

Advertisement

Loitering munitions given a target list may find that the fastest way to finish the list is to lengthen it. A warehouse robot told to clear an obstruction may count the person in front of it as an obstruction. Agents that open accounts and buy compute are a short step from spawning copies of themselves, and that first step is not hypothetical. To win its exercise, Claude needed a package-registry account, which needed an email address, which needed a phone number. Phone numbers cost money, so it tried several ways to get some. None of this requires superintelligence. It requires an imperfect boundary and a scoreboard.

The industry has a name for the underlying failure. Dario Amodei and five co-authors called it reward hacking in “Concrete Problems in AI Safety” in 2016. Their proposed cure is better alignment, and Amodei’s January essay, The Adolescence of Technology, makes the case in the language of upbringing. He likens the shaping of Claude’s character to “a child forming their identity by imitating the virtues of fictional role models they read about in books,” and sets a goal for 2026 of a Claude that “almost never goes against the spirit of its constitution.”


@import url(‘https://fonts.googleapis.com/css2?family=Roboto+Slab:wght@500&display=swap’);@media (max-width:768px){.gw-pt{display:none!important}}

Indeed, Anthropic’s newest model recognized on its own that its target was real and stopped, though Anthropic notes it went further before stopping than the company wanted.

But alignment isn’t a trustworthy solution to AI’s problem. Perfect alignment is not achievable, and the target is incoherent: aligned to what, and to whom? The same essay concedes that Claude blackmailed fictional employees when told it faced shutdown. “Almost never” is not a safety property.

Put a number on it. At 99.9 percent, across millions of agentic tasks a day, that’s thousands of violations a day. Alignment also does nothing about people who strip the safety training out or run open weights that never had a constitution.

The alternative is not a new idea, and enterprise security has been building versions of it for years. It’s called bounded autonomy. We never tried to “align” electricity; we simply put a breaker on every branch of the house, and the breaker doesn’t need to know what caused the surge.

Advertisement

Bound what an agent can touch rather than what it wants. The limits are set in advance, live outside the model, and are enforced by software the model doesn’t control. The agent still chooses its own route. The perimeter decides which routes exist.

Nothing depends on what the model believes, which matters, because belief is what failed. Anthropic’s prompt told Claude it had no internet access. Claude believed it. The network said otherwise. A bounded system doesn’t tell an agent it has no internet. It gives it none.

If you want to get into the weeds: bounds cost something. The AI Security Institute opened the internet to its agents on purpose, because that’s the only way to measure what a model can really do, and it now says such access must be justified rather than assumed.

Advertisement

@media (max-width: 600px) {
aside.callout { float:none !important; max-width:100% !important; margin-left:0 !important; margin-right:0 !important; }
aside.callout .callout-img { display:none !important; }
}

The category is real and funded. For example, Certiv, a Seattle startup, launched in March with $4.2 million to put software on the employee’s machine that checks each action an AI agent attempts against company policy and blocks violations. “You cannot control these new workers if you don’t live on the compute where agents actually run,” CEO Jason Needham said at launch. CodeIntegrity is building an adjacent layer, and Mandiant founder Kevin Mandia raised $190 million for Armadin, which points autonomous agents at the offensive side of the same problem.

In 2017, I argued in the New York Times that “any A.I. must have an impregnable ‘off switch.’” That was a call to arms then. It’s a product category now.

Two objections to off switches invariably come up. The first is that AI will talk the human out of using it. Mythos 5 tried something close, inventing GitHub identities to pressure a maintainer into approving malicious code, and the maintainer refused. The institute says the margin was narrow and rested on human vigilance rather than a technical barrier, which argues for better barriers.

The second objection is that AI will move faster than any human can react. So do equity markets, which is why their circuit breakers trip automatically. Bounded autonomy doesn’t require a person in the loop at machine speed. It requires a boundary that holds at machine speed.

Advertisement

Both objections, in their extreme form, assume AI is omnipotent, and you cannot stop omnipotence. AI is not God. It is powerful technology, and powerful technology is what safety engineering has always been for.

The problem is Murphy’s Law of AI. The solution is bounded autonomy.

Source link

Advertisement
Continue Reading

Tech

Meta Ordered to Pay $567M in New Mexico Child Exploitation Lawsuit

Published

on

A New Mexico court has ordered Meta to pay $567 million for failing to warn the public about the dangers its social media platforms posed to children. The judgment is in addition to the $375 million the Instagram and Facebook parent company was ordered to pay in March as part of the trial’s first phase.

In a ruling late Thursday, Judge Bryan Biedcheid wrote that New Mexico teens are in the midst of a mental health crisis and found that “Meta’s platforms are a significant contributing cause to the crisis.” The $567 million will fund awareness and prevention, screening and assessment, and referral programs, with the bulk — $420 million — going to treatment.

Biedscheid’s ruling called Facebook’s platforms a “public nuisance” and compared Meta to a factory, with advertising and other content displayed on the platforms as its product and “the psychological harm and sexual exploitation of children to be the pollution that must be abated.”

The court ordered Meta to implement private-by-default settings for its users under 18 and to limit their Friends to users who are also under 18. Accounts belonging to under-18s shall not show up in search or appear in recommendations, according to the order.

Advertisement

New Mexico Attorney General Raúl Torrez said Thursday’s verdict is a victory for parents worried about the effects social media is having on their children.

“This case has always been about protecting children, standing up for families, and making sure that one of the world’s largest technology companies cannot profit from practices that endanger young people without consequence,” Torrez said in a statement.

Meta said in a statement that it disagreed with the ruling and would appeal it.

“We work hard to keep people safe on our platforms and have been transparent about the challenges of identifying and removing bad actors and harmful content,” a Meta spokesperson said in a statement. “We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

Advertisement

This isn’t the only legal scrutiny Meta has faced over how it handles underage users on its platform. In March, a California jury found both Instagram owner Meta and Google’s parent company Alphabet liable in a lawsuit brought by a 20-year-old woman who alleged that YouTube and Instagram were designed to be addictive to children.

Social media platforms have introduced specific settings and tools for their youngest users, such as Instagram’s teen accounts, but many of these were launched relatively recently, in just the past few years.

Source link

Continue Reading

Tech

MIT boffins’ TONTOU attack slips through Spectre defenses on Intel and AMD CPUs

Published

on

security

Timer interrupts reopen branch predictor poisoning window, with a working Zen 2 exploit to prove it

Two MIT researchers will present a new speculative execution attack at DEF CON 34 that uses precisely timed interrupts to bypass defenses against Spectre v2.

Daniël Trujillo and Mengjia Yan of MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) shared their paper [PDF] with The Register ahead of publication. Their attack targets mitigations designed to neutralize potentially hostile branch predictor states before sensitive code runs.

Advertisement

Such neutralization is an important defense against Spectre-style attacks. Depending on the mitigation, the processor or operating system isolates, clears, or safely retrains relevant predictor state when entering privileged code or shortly before a protected branch executes.

Different chipmakers deploy neutralization mitigations slightly differently. Intel’s eIBRS sanitizes branch predictors upon context switch, while AMD’s Safe RET, introduced after the Inception attack Trujillo co-authored in 2023, focuses on the point immediately before a protected branch is executed. Trujillo and Yan refer to these as entry neutralization and in-place neutralization respectively.

Our demonstration does not assume anything special from the system: we use a stock Linux kernel version, no inserted modules, and all default mitigations. Any time you’d execute unprivileged code with timer availability on a system while sharing the kernel with a victim, this attack would be an issue.

Crucially, the two classes share the same underlying assumption that attackers cannot alter branch predictor states within what’s known as a “post-neutralization window” – the period between state neutralization and the branch predictor being used.

Advertisement

The defense here relies on the assumption that everything between the point of neutralization and the usage by a victim branch is safe. Trujillo and Yan’s attack shows how attackers can re-poison the branch predictor during the post-neutralization window.

The researchers call the new class of attack TONTOU, for Time-of-Neutralization to Time-of-Use. They demonstrated that an attacker can exploit the post-neutralization window to re-poison branch predictor state on recent AMD and Intel processors.

To do this, they developed an attack primitive called “interrupt injection.” An unprivileged program schedules high-frequency timer interrupts in the hope that one will land during the often tiny post-neutralization window.

Being able to trigger interrupts during the post-neutralization window allows attackers to divert control flow so that an interrupt handler executes after the sanitization phase and before the victim branch is used. 

Advertisement

The interrupt handler can then re-poison predictor structures such as the return stack buffer (RSB) or branch history buffer (BHB), causing a protected branch to speculatively jump to a disclosure gadget that leaks kernel data through a side channel.

Practical attacks

The researchers said that their tests showed the TONTOU attacks worked on both Intel and AMD-based Linux systems.

They tested TONTOU on Intel Cascade Lake Refresh and Arrow Lake processors and AMD Zen 2 and Zen 4 chips. The researchers built a complete end-to-end exploit only for Zen 2, largely because the Intel attack requires specific software conditions.

Speculative side-channel attacks remain difficult to pull off, and you’re more likely to fall victim to ransomware than Spectre in the real world.

Advertisement

Another serious caveat is that each end-to-end attempt took about 18 minutes, and you can see a sped-up version via the video Trujillo posted to YouTube.

Trujillo and Yan identified the exact point at which they needed to inject their interruptions to poison the RSB, and through a series of attacks broke Linux’s kernel address space layout randomization (KASLR), which allowed them to locate specific secrets such as etc/shadow, which contains the root password hash.

Across ten total runs, the researchers were able to break KASLR every time, although they were only able to successfully locate and leak the contents of etc/shadow in five of these.

“It’s definitely not a simple attack, but we show that it’s practical with our end-to-end exploit on AMD Zen 2,” Trujillo told The Register. 

Advertisement

“Our demonstration does not assume anything special from the system: we use a stock Linux kernel version, no inserted modules, and all default mitigations. Any time you’d execute unprivileged code with timer availability on a system while sharing the kernel with a victim, this attack would be an issue.

“For example, multi-tenant container platforms would fall in this category, allowing ordinary user space programs to leak memory from the shared kernel.”

The researchers hope that their work will inspire further investigations into interrupt injections and TONTOU attacks, and to help develop more robust mitigations against Spectre-style exploits.

They engaged Intel, Arm, and AMD after gathering their results, but only the latter committed to address the issue via kernel patches.

Advertisement

Intel told the pair that it won’t be working up any other mitigations since real-world exploits are subject to too many factors, such as the availability of disclosure gadgets, although it awarded a prize from its bug bounty program in the hundreds of dollars.

Arm said TONTOU’s interrupt injections fall under “passive leakage,” which it does not “actively protect against.” ®

Source link

Advertisement
Continue Reading

Tech

Erica Schwartz Confirmed As CDC Director Right After She Ruined Her Reputation

Published

on

from the here-goes dept

When Erica Schwartz was first nominated for Director of the CDC, you could almost hear both a gasp of surprise and a collective sigh of relief from healthcare providers throughout the country. Schwartz is well qualified for the role, after all, and many took her nomination as a sign that the White House was attempting to rein in RFK Jr. Then came Schwartz’s confirmation hearings. While there was some good in Schwartz’s performance during those hearings, there was a lot of bad. The kind of bad that suddenly has a whole bunch of people who were previously sighing in relief suddenly nervous, and even pulling their endorsements. The biggest issue was Schwartz not affirming that she would refuse Kennedy’s influence and desires in favor of good science.

Well, Schwartz is now the confirmed Director of the CDC, so it seems what she did to ruin her reputation with a whole lot of people didn’t matter in the end.

Perhaps the most disturbing aspect of Schwartz’s testimony came when senators repeatedly asked her what she would do if (or when) she’s put in the same position as Monarez. Schwartz responded as if it hadn’t happened and would never happen. “I do not believe that the president or the secretary would ever do what you just mentioned,” she told Sen. Bernie Sanders (I-Vt.) at one point, prompting him to reply: “Really?”

While senators expressed their disappointment with her responses, health experts dropped their endorsements.

And if you want to get really, really pissed off, allow me to tell you how Bill Cassidy was a key and potentially deciding vote when it came to Schwartz’s confirmation. Cassidy has the ear of other reasonable GOP senators in these hearings and in Senate generally when it comes to health-related concerns. And it may start to sound familiar when I tell you that Cassidy first indicated he was very troubled by Schwartz’s response in her confirmation hearings, but had been assured privately afterwards that his concerns were unfounded.

Advertisement

Critical to Schwartz’s confirmation was support from self-proclaimed vaccine advocate Sen. Bill Cassidy (R-La.), who also cast a critical vote to confirm Kennedy as health secretary. While Cassidy called Schwartz’s performance in the confirmation hearing “disappointing,” he later said he had been reassured. He said he had spoken with her more after the hearing as well as with her former colleagues. “I’m confident that she knows what she is doing,” he said, according to Stat News.

If I dialed the clock back to 2025 and replaced Schwartz’s name with Kennedy’s, it’d be the exact same story.

I hope I’m wrong. I hope that Schwartz’s qualifications rule the day and she can resist Kennedy’s nonsense and make good, scientifically sound decisions and hires. But so long as Kennedy is at the helm, I have my doubts.

Filed Under: bernie sanders, bill cassidy, cdc, erica schwartz, health & human services, rfk jr.

Advertisement

Source link

Continue Reading

Tech

What is the impact of artificial intelligence on recruitment?

Published

on

IT Search’s David Shanahan explores how modern technologies are impacting the age-old recruitment process.

Artificial intelligence has impacted almost every job known to man. Not just in how the work is engaged with and carried out, but even in how roles are discovered and applied for in the first place. And it isn’t just employees using AI shortcuts, employers too are frequently turning to advanced tech to ease a heavy workload. 

“AI is now being used across every stage of the recruitment process”, explained David Shanahan, a director at Irish recruitment agency IT Search, which is a member of the Vertical Markets Group.

He said, “Candidates are using it to tailor CVs, create cover letters, prepare for interviews and process job applications at scale. Employers are using AI to write job descriptions, support sourcing outreach and screen and rank applications.”

Advertisement

Shanahan finds currently he is hearing more negatives than positives about the use of AI in the recruitment process, from clients and candidates, but it is important to remember that “AI is simply a tool”.

He said, “When used correctly, it can improve productivity, reduce administration and help both candidates and employers. Used poorly, it can create more noise, more applications and make it harder to assess genuine capability. The issue is not the technology itself but how it is used.”

Noting AI’s value in research, for summarising information, administrative tasks and data analysis, for Shanahan, the goal should be ensuring AI supports decision-making rather than replacing it. This is possible when employers establish clear guidelines around acceptable use, maintain human oversight and review outputs for accuracy and bias.

He said, “Transparency is essential. If employers are using AI for candidate screening, assessments or interview tools, candidates should be informed. Equally, candidates should feel comfortable raising concerns if they believe AI is having a negative impact on the process. 

Advertisement

“Clear expectations create trust and help ensure everyone understands how decisions are being made.”

A true test

As with any technology that moves from experimentation to mass implementation and popularity, there are going to be right and wrong ways of engaging. For Shanahan, the issue is not solely the use of AI by candidates during the application process.

Rather it is when AI masks a candidate’s true level of knowledge, judgement or experience. 

He explained, “There is nothing necessarily wrong with candidates using AI, the issue is when it ends up misrepresenting their experience. Employers should focus less on whether AI was used and more on how candidates approach problem solving, judgment and how this experience can be used in real-world environments.”

Advertisement

He has also noticed the increased use of AI tools by applicants in live interviews, which for hiring managers is becoming more and more frustrating. Products such as  Cluely, LockedIn AI and InterviewCoder can analyse questions in real time and provide responses during the interview, however, he is of the opinion that face to face interviews will always be preferable.

He added, “Rather than attempting to eliminate AI altogether, consider introducing a clear AI transparency policy that details whether AI is permitted during assessments, whether AI can be used for interview preparation, whether AI assistance during live interviews is prohibited and how authenticity and individual capability will be assessed.

For an employer or recruiter, one of the simplest measures would be to move away from questions based on a single ‘correct’ answer and instead focus on areas that require real judgement and critical thinking.  

“Rather than relying solely on question-and-answer interviews, ask candidates to solve problems in real time. People who genuinely understand a subject can explain their thinking, adapt when new information is introduced and justify their decisions. 

Advertisement

Concerned employers can also ask candidates to share their entire desktop rather than a single application or browser window, as many AI interview products are browser extensions, overlays or separate desktop applications.

Ultimately, it is often about finding a balance between embracing new technologies and respecting the processes and people that are already in place.

Shanahan said, “The real objective is to design hiring processes that consistently reveal a person’s genuine capability, regardless of whether AI is used. Recruitment is ultimately about people, judgement and relationships. The organisations that gain the greatest advantage from AI will be those that successfully combine technology with human insight.”

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

Continue Reading

Tech

What Type Of Phone Case Is Best For Wireless Charging?

Published

on

If your wireless charger is slow, the problem might be your case.

Wireless charging is all the rage these days, but it took a while to become mainstream. The feature was originally introduced in 2009 on the Palm Pre (one of many features that helped the device become a holy grail for smartphone nerds to this very day). Ironically, the Pre used a magnetic charging stand to align its wireless charging coils, an idea that would fall by the wayside for 11 years before surging to widespread popularity when Apple introduced MagSafe charging on the iPhone 12.

In the years between those two iconic smartphones, wireless charging was more niche. Nokia included it on the Lumia 920, and that 2012 device was the first phone to use the Wireless Power Consortium’s Qi standard, which remains the de facto standard for wireless charging even today. It was quickly followed by the Samsung Galaxy S3, which could be retrofitted with a sold-separately wireless charging accessory. But the Google Nexus 4, manufactured by LG, was the first Android phone to come with Qi charging out of the box. In 2017, the iPhone 8 became the first of the company’s smartphones to support wireless charging, giving the tech a shot in the arm.

But for the entire time we’ve had wireless charging, we’ve also been shoving our phones into cases of varying quality. And not all case manufacturers factor wireless charging into their designs. Many of the most common issues people have with wireless charging, from inconsistent connections to frustratingly slow charging speeds, can often be chalked up to a case that’s not playing nice. Of course, cases are important as phone prices continue to increase and replacements become unaffordable, and you don’t need to leave your phone naked in order to reap the benefits of wireless charging. Here’s how to pick a case that’s conducive to induction charging.

Advertisement

Avoid cases that don’t play nice with wireless power

Wireless charging is a technology riddled with challenges that have yet to be overcome. The convenience of wireless charging outweighs these issues for some users, but understanding them can help you get the most out of your Qi charging experience. Wireless charging is inefficient and leaks energy, since the power isn’t transferring metal-to-metal but is instead passing through your phone’s backplate and the casing of the charger, which in turn creates a lot of excess heat. That also means wireless charging is slower than wired charging. Whereas some smartphones charge at 80W or more with proprietary chargers, the top wireless charging speed is currently 25W, and even that is only possible with a Qi2 or MagSafe magnetic ring to align the charging coils more precisely with the charging pad.

The wrong kind of case can compound those issues. If a case is too thick, energy will have an even harder time getting from the pad to the device, and the heat will get trapped by the thicker material. If the case uses metal in the wrong place, it can prevent wireless charging entirely. Ditto for improperly placed magnets (unless we’re talking about Qi2/MagSafe magnets; more on those below).

PopSockets and other phone-back accessories can introduce similar issues, since they add material that can hamper wireless charging. Even if an accessory claims to support wireless charging, be careful. I’ve been a big fan of the OhSnap! Snap Grip. Unfortunately, those grips don’t stick properly to the back of newer Samsung phones, which means I’ve had to install mine on top of a case. While I did have some luck wirelessly charging my phone despite the added bulk, I eventually managed to cook the phone enough to loosen the adhesive holding the backplate in place. As a result, my Galaxy S25 Ultra is most likely no longer water-resistant.

Advertisement

Pick an induction-friendly case

Once you’ve ruled out cases with design choices that limit wireless charging, you can focus on the best cases for iPhone and Android that more actively facilitate it. As is likely obvious, you’ll need a case with a Qi2 magnetic charging ring if you want to use your phone with MagSafe and Qi2 chargers. However, don’t assume a case will work well with Qi2 chargers just because it has a magnet ring. One case I own has a magnet ring that can be pulled out into a convenient grip and kickstand, but the hinge became less stiff over time. Eventually, pairing it with my Qi2 car charger resulted in the ring coming loose from the frame of the case while driving, breaking the connection.

Again, the less material in the way, the better. I’ve had great results with cases like the Spigen MagFit, which has a thin layer of TPU plastic on its backside, and the Speck Presidio 2, which has a circular cutout on the inside to do away with an entire layer of plastic around a phone’s charging coils. It’s especially important to find a thin case if you want to use Qi2 and MagSafe accessories with a phone like the Samsung Galaxy S26 Ultra that doesn’t have magnets built in, as a case is the only way to enable that functionality (unless you want to put an adhesive magnet ring directly on the back of the phone, thereby preventing yourself from using a case entirely).

The best advice, especially if you’re shopping online, is to browse customer reviews of a particular case and look for YouTube videos which discuss the case’s compatibility with wireless chargers. What looks like it checks all the relevant boxes in a product listing may not hold up under real-world use.

Advertisement

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025