Connect with us

Tech

Ctrl-Alt-Speech: License To Spill | Techdirt

Published

on

from the ctrl-alt-speech dept

Ctrl-Alt-Speech is a weekly podcast about the latest news in online speech, from Mike Masnick and Everything in Moderation‘s Ben Whitelaw.

Subscribe now on Apple Podcasts, Overcast, Spotify, Pocket Casts, YouTube, or your podcast app of choice — or go straight to the RSS feed. To get extended episodes with additional coverage, support us on Patreon.

In this week’s episode, Mike and Ben cover:

Advertisement

And in the extended episode for Patreon supporters, they cover:

Our fun links this week include a Korean AI dance generator and defrag your Windows PC.

Follow us on Instagram, YouTube, and Bluesky for video clips from this week’s episode!

If you’re already a Patreon supporter, you can get the extended episode on Patreon.

Advertisement

Filed Under: age verification, ai, artificial intelligence, content moderation, cybersecurity, trust and safety

Companies: openai

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Skyworth C2 Canvas Art TV Takes on Samsung The Frame With a Brighter QD Mini LED Screen

Published

on

Art TVs have spent years asking buyers to accept a peculiar bargain: your television can look like framed artwork when nobody is watching it, provided you are willing to surrender some picture quality when everyone sits down for movie night.

Skyworth thinks that compromise has gone on long enough.

The new Skyworth C2 Canvas Art TV, making its official debut at CEDIA Expo 2026, takes several of the display technologies introduced with the company’s much more expensive CE1 Canvas Elite and brings them to 55, 65 and 75-inch screen sizes.

The headline upgrade is QD Mini LED backlighting with more than 400 full-array local dimming zones, combined with 1,000 nits of claimed peak brightness, a 144Hz refresh rate and Skyworth’s OmniView Matte Screen. HDR support includes both Dolby Vision and HDR10+. That makes the C2 considerably more interesting than another television wearing a decorative wooden frame.

Advertisement

Related: Best TVs Of 2026: Editors’ Choice Podcast

This Is a Huge Upgrade Over the Skyworth C1

The difference between the existing C1 Canvas Art TV and the new C2 is substantial.

Skyworth’s current C1 uses a conventional LED backlight, operates at 60Hz and is rated at just 300 nits of brightness. It already offers a matte anti-glare screen, flush mounting, Art Mode and an included wood grain frame, but its specifications clearly place aesthetics ahead of serious HDR performance. 

The C2 changes that equation with 1,000 nits, 144Hz and full-array local dimming with more than 400 zones. In other words, this is not Skyworth changing the frame, adding three new Van Goghs and calling it a product cycle.

Advertisement

The additional brightness should provide significantly more headroom for HDR content, while local dimming gives the television far greater control over dark and bright portions of an image than the C1’s conventional LED backlight can provide. How well those 400-plus zones actually control blooming and black levels will require testing, but the underlying hardware represents a major step forward.

The 144Hz refresh rate also makes the C2 considerably more appropriate for gaming and fast-moving content than its 60Hz predecessor, although Skyworth has not yet provided a complete C2 connectivity specification or confirmed its HDMI configuration in the announcement.

That omission is worth keeping in mind before anyone starts assigning HDMI 2.1 ports that Skyworth has not actually announced.

Advertisement. Scroll to continue reading.
Advertisement
Skyworth Canvas Elite CE1 100-inch Art TV
Skyworth Canvas Elite CE1 100-inch Art TV

How Close Is It to the Canvas Elite CE1?

Skyworth introduced the CE1 Canvas Elite at CEDIA Expo 2025 in 86 and 100-inch sizes, and eCoustics subsequently named the 100-inch model our Best Art TV at CEDIA 2025.

The CE1 remains the superior display on paper. It uses QD Mini LED technology with more than 1,000 local dimming zones, reaches a claimed 2,000 nits, offers a 144Hz refresh rate and uses the same OmniView Matte Screen technology. The 86-inch model is currently listed at $3,999 and the 100-inch version at $5,999. 

The C2 therefore does not duplicate CE1 performance. It effectively moves some of the flagship’s display architecture further down the Canvas range, with roughly half the claimed peak brightness and substantially fewer dimming zones.

That is actually the more important story.

A 100-inch $5,999 lifestyle television is impressive, but it is not going into most living rooms. A 55, 65 or 75-inch version using full-array QD Mini LED technology has the potential to compete for considerably more wall space.

Advertisement

Pricing will determine whether that potential becomes reality.

skyworth-canvas-art-tv-front
Skyworth Canvas TV

Is the Skyworth C2 Really Unique?

Not entirely, and this is where the marketing department needs to put the champagne back in the refrigerator.

Mini LED is no longer exclusive to Skyworth among televisions designed to double as artwork. Samsung’s 2026 The Frame Pro uses its Neo QLED Mini LED platform and supports 144Hz operation, while TCL has also introduced QD Mini LED technology in its premium NXTVISION Art TV lineup. 

What makes the C2 Canvas Art TV noteworthy is the combination Skyworth is bringing into its standard Canvas range: full-array QD Mini LED backlighting, 400-plus local dimming zones, 1,000-nit claimed brightness, 144Hz operation, Dolby Vision, HDR10+ and a matte display.

Advertisement

There is another important distinction. Skyworth supports Dolby Vision, which Samsung still does not offer on its televisions.

The company has also integrated a subwoofer and Dolby Atmos audio into the C2. Skyworth goes so far as to suggest an external soundbar is unnecessary. We will reserve judgment on that one until somebody actually listens to it; physics has not yet received notice that it has been cancelled. 

CEDIA Is Also Part of the Story

The C2 is not being positioned solely as another television destined for a pallet at Costco.

Advertisement. Scroll to continue reading.
Advertisement

Skyworth says the new models will be distributed through its authorized custom integration dealer network, which helps explain the CEDIA Expo debut. The company supports integration with control platforms including Control4 and Crestron, while installers can order customizable frames through Skyworth’s partnership with Hydro Frames.

Standard frame finishes include black, silver, gold, white and walnut, with additional custom patterns and colors available. 

That flexibility matters in a category where the television is supposed to disappear into the room rather than announce that somebody bought another 75-inch black rectangle.

Skyworth Is Becoming Harder to Ignore

The C2 also arrives during a much more consequential year for Skyworth in North America.

Advertisement

Earlier in 2026, Panasonic announced a strategic partnership with Skyworth for its U.S. television business, with Skyworth USA assuming a major operational role covering sales, marketing and logistics while the relationship also leverages Skyworth’s manufacturing scale. That development followed Skyworth’s growing push into premium Art TVs and outdoor displays in the American market. 

That makes products like the C2 worth watching beyond their individual specifications. Skyworth is no longer merely another enormous Chinese television manufacturer trying to establish name recognition with American consumers. Its role in the North American television business is expanding rather quickly.

The Bottom Line

The Skyworth C2 Canvas Art TV looks like a far more consequential product than the C1 it follows.

Moving from a 300-nit, 60Hz conventional LED platform to 1,000 nits, 144Hz and more than 400 full-array local dimming zones changes the conversation from “television that looks attractive on the wall” to something that could potentially deliver credible home theater performance as well. It is not the first premium Art TV to embrace Mini LED, and Skyworth still needs to reveal important details including pricing, complete connectivity and final availability.

Advertisement

But if the C2 arrives at the right price, Samsung, Hisense and TCL will have another serious competitor hanging on the wall. And this one appears rather more interested in what happens after you stop looking at the Monet.

Price & Availability

The Skyworth USA website currently lists pricing at $1,399 to $2,499, but we haven’t received any information when it will become available yet.

Source link

Advertisement
Continue Reading

Tech

Startup Spotlight: Food photographer uses 25-year archive to build an AI tool that eliminates costly reshoots

Published

on

A hamburger photographed by SP Studio, left, and then tweaked by Scott Pitts in Pallat to add tomatoes. (Pallat Images)

Longtime Seattle food photographer Scott Pitts spent 25 years capturing commercial imagery for major brands, and now he’s using that quarter-century archive to train Pallat. The new AI-powered production system is designed to eliminate costly reshoots while keeping real studio craft at the center of generative creative tech.

@media (max-width: 600px) {
.gw-founder-box { float:none !important; max-width:100% !important; margin:20px 0 !important; padding:16px 18px !important; }
.gw-founder-box .gw-label { font-size:12px !important; margin-bottom:8px !important; }
.gw-founder-box .gw-hero { font-size:19px !important; }
.gw-founder-box .gw-byline { font-size:15px !important; }
.gw-founder-box .gw-meta { font-size:12px !important; margin-bottom:14px !important; }
.gw-founder-box .gw-facts { padding-top:14px !important; }
.gw-founder-box .gw-facts li { margin-bottom:12px !important; }
.gw-founder-box .gw-facts li:last-child { margin-bottom:0 !important; }
.gw-founder-box .gw-value { font-size:15px !important; line-height:1.45 !important; }
}

The platform combines fine-tuned open-weight models with Pitts’ extensive archive, allowing art directors to modify existing campaign assets — like swapping a topping, adjusting lighting, or changing a backdrop — in minutes through software rather than starting from scratch back on set.

Pitts, a non-technical founder operating Pallat out of his Seattle photo studio, SP Studio, leads a nimble five-person team and believes domain experience is key to competing with generic AI platforms.

“We are close to the problem, and we’re looking at it from a photographic eye,” he said. “We’re making sure those outputs look photoreal, that they’re not going to get labeled as AI slop.”

To show how the tech works in practice, Pitts points to a recent shoot for a national steakhouse client. After completing a complex setup for a burger — carefully layering the bun, patty, sauce, and greens — the brand asked if they had shot a version with tomatoes. Rather than calling back the food stylist and rebuilding the set, Pitts dropped the final image into Pallat, prompting it to add two tomato slices with subtle condensation, natural translucency, and accurate drop shadows cast onto the cheese below.

Advertisement

In another instance, a commercial seafood brand prepared packaging imagery for a buyer presentation, only for the client to ask to see the fish presented on a white plate instead. Pallat to the rescue.

Scott Pitts, founder of Pallat, inside his Seattle photography studio at Fishermen’s Terminal in Interbay. (Mark Malijan Photo)

Commercial photographers have long tweaked images using tools like Photoshop, but Pitts sees AI as the natural next step for advertising workflows — distinct from news photography, where image manipulation remains out of bounds. Where Photoshop requires painstaking manual editing to adjust a scene, Pallat handles complex lighting, translucency, and material physics in minutes based on a simple prompt.

The startup recently signed its first enterprise customer and is currently working directly with brands as a hands-on production partner while building toward full software access.

Pitts sees the technology not as a threat to his craft, but as a natural progression. He started his career shooting four-by-five film, then transitioned to digital and video. AI is another progression.

“My hope is that me building Pallat is sort of this bridge between tech and creative,” Pitts said. “Craft is still important. Judgment and taste are still probably some of the most important things.”

Advertisement

Continue reading for Pitts’ answers to our Startup Spotlight questionnaire.

In 50 words or less, give us your startup’s elevator pitch.

Pallat is a photographer-led AI production system built for food and beverage brands, born from a working photo studio. It combines licensed photography with generative workflows to help brands scale photo-centric content while maintaining the creative control expected from commercial photography.

What problem are you obsessed with solving?

Advertisement

I’ve spent 25 years watching brands solve the same problem: invest in a shoot, then ultimately need more usable imagery than the initial shoot was designed to deliver. Generic generative tools can create images, but weren’t built around the quality, control and production standards food and beverage brands require.

I’m obsessed with using AI to close the gap. Pallat gives brands a way to extend photography they’ve already invested in and create new production-ready imagery grounded in a licensed dataset and the standards of a traditional photoshoot.

What surprised you after talking to customers?

Because we’re so close to the problem we’re solving, their need for a solution and high bar for quality didn’t surprise me. 

Advertisement

What did was how much generated imagery disrupted their existing workflows. There is no obvious owner, no review path and no shared vocabulary for feedback and approvals. Brands are asking us to help establish new workflows, and that has turned out to be almost as important as building the tech itself.

How has AI changed the way you build your company?

AI is a big part of why a five-person team can build something like this. Our tech stack is built on open-weight models that we fine-tune using proprietary training data, while foundation models support planning and a handful of day-to-day operations.

Not to oversimplify it, but in many ways my role at Pallat parallels production. I built a team of experts, defined the problem we’re solving and established the criteria for the output. A growing part of my work is getting those standards out of my head and structuring evals so they hold when I’m not in the room.

Advertisement

What’s one thing people misunderstand about your startup?

That Pallat is trying to replace photography. It’s far from it.

Practical photos are important inputs, and our studio continues to create net-new ones to expand the system. Visual trends are always evolving, so datasets powering creative tech cannot be static. The future of production is hybrid: practical photography and generative imaging working together, with each deployed where it creates the most value. 

What’s the toughest decision you’ve made in the past year?

Advertisement

Resisting the urge to broaden Pallat before we establish product-market fit. The goal isn’t to automate every step as quickly as possible. It’s to understand which problems in the workflow are best solved through software.

What’s the one piece of advice you give to other entrepreneurs?

I truly believe some of the most interesting AI companies will come out of service businesses where the founder knows the industry exceptionally well — where the friction lives, which shortcuts a client will notice, and what excellence looks like in their vertical.

I spent a long time assuming my 25 years in photography was the past and AI was the future, and I had that backwards. The years on set that sharpened my taste and judgment, our dataset and the client relationships are the true compounding assets.

Advertisement

We’ll know our company has made it when…

When an art director at a food or beverage brand drafts a shot list dividing it into two columns: “Capture as Practical Photography” and “Generate in Pallat.”

When that becomes a normal way of planning, Pallat will have done what we set out to do.

Source link

Advertisement
Continue Reading

Tech

This is the folding iPhone, if case manufacters are right

Published

on

Ahead every iPhone release event, case manufacturers generate dummy units to see if their cases will fit properly. We’ve got our hands on these faked iPhone 18 Pro and folding iPhone models, so let’s take a look.

The dummy unit “industry” is bigger than ever this year, as you’d expect when there are three flagship models coming out, not just two. In recent weeks we’ve seen 3D prints and metal blanks, of what case manufacturers think that iPhone 18 Pro, iPhone 18 Pro Max, and folding iPhone will look like.

It’s also crucial to recognize that these are just useful to visualize the design and size of the new units. They give zero insight into the internals of the phone or what features it may support.

iPhone 18 Pro

Let’s look at the iPhone 18 Pro and iPhone 18 Pro Max first.

Advertisement
Purple smartphone lying face down, showing a dual camera bump with flash in the top corner, smooth matte back, and side buttons visible against a plain light background

A dummy model of the rumored iPhone 18 Pro Max in a dark cherry color

As the rumors suggested, the iPhone 18 Pro and iPhone 18 Pro Max will keep almost exactly the same form factor as the iPhone 17 Pro. Taking some calipers to these models, they’re almost exactly the same size as last year’s flagships.

Two smartphones shown from the back, one white and one magenta, each with multiple camera lenses in the top left corner against a plain light background

A real iPhone 17 Pro (left) vs iPhone 18 Pro Max dummy unit (right)

Side by side, the plastic dummies are nearly indistinguishable. We’ve heard that there may be some minor differences in the camera bump. It’s hard to tell with certainty here because of the poor tolerances on the engineering sample plastic.

Advertisement

Comparing the dummy iPhone 18 Pro Max next to our iPhone 17 Pro, we couldn’t tell much of a difference at all in the camera bump size. Perhaps the final models will have some slight tweaks here, but case manufacturers are already repackaging existing cases for the iPhone 17 Pro to suit.

So, right now, it seems that new cases will be backwards compatible, but not all older iPhone 17 cases will be forward compatible. Cases for iPhones are a billion-dollar industry, and it can be risky to start producing cases early when there may be these slight deviations.

The most likely way to tell an iPhone 18 Pro or iPhone 18 Pro Max device from an older one will be the colors. As it has ever been, there has been a lot of debate around the final colors.

It seems a dark cherry red will be in the mix, and our dummy unit has a version of this rumored dark red color. It looks nice, but it’s probably not for everybody.

Advertisement

It’s too early to judge though, as this is just based off the rumor. Don’t expect Apple’s color to perfectly match, or have the same semi-gloss finish.

One question we’ve had is on the Dynamic Island and whether or not it will see its size adjusted. Dummy units though, still can’t tell us anything on below-the-screen components.

The folding iPhone

More interesting to users is likely Apple’s long-rumored folding iPhone, commonly referred to as iPhone Ultra. Compared to early 3D printed models or dummies, our dummy is far more finished.

Closed silver and black foldable smartphone lying flat on a white surface, showing its side buttons and slim hinge edge

A dummy model of Apple’s rumored foldable with the Camera Control and power button

Advertisement

It has working hinges, pressable buttons, and a more polished camera plateau. Looking at the rear cameras, it does seem that aside from the wide and ultra-wide lenses, we’ll see a True Tone flash and possibly LiDAR located just to the right of the lenses.

Side view of a closed silver smartphone on a light background, showing its thin profile, side button, and slightly protruding rear camera module

On this dummy unit, the cameras stick out quite a bit

We’re unsure if the depth of the camera lenses is accurate, but if so, they stick out quite a bit. Since the body of the phone is so thin, and the plateau is thinner than on the iPhone Air, it makes the lenses protrude quite a bit on their own.

Silver foldable smartphone partially open on a light surface, showing dual rear cameras, side buttons, thin hinge, and upper speaker holes in a clean, minimalist setting

Top volume buttons and speaker on Apple’s rumored foldable, visualized with a dummy unit

Advertisement

There are the volume buttons on top of the right side when open. Camera Control and power are on the right edge, and USB-C is on the bottom-left when open.

When unfolded, the speakers are on opposite corners of the device. This should allow for stereo or possibly even Spatial Audio. This will help Apple avoid the problem of one-sided audio, which is a major complaint about the iPhone Air.

On the inside, the screen shows a fold down the middle, something Apple is rumored to have mostly solved on the real thing. You can see a small camera coming through the screen in the top-left corner.

A person's hand holding a closed, black foldable smartphone with rounded corners against a plain white background

Holding a dummy unit of Apple’s rumored folding iPhone

Advertisement

We’re not too concerned about what we feel is a flaw in the model. When closed, the hinge side has sharper corners, which isn’t super comfortable when held in the left hand.

The corners opposite the hinge are rounded, which do fit nicely into your palm while holding the dummy. It will be interesting if Apple chooses to round the right two corners of the display but keeps the left ones at a right angle, or if it rounds all four.

Otherwise, the form factor feels excellent in the hand. The exterior screen is a perfect size to reach all four corners with one hand and the interior screen is big and spacious, just a bit smaller than an iPad mini, and perfect for split-screen apps.

Close-up of a smartphone's top corner with the front camera and sensor barely visible on a reflective screen, held against a plain light background

The Dynamic Island may get smaller, but the dummy doesn’t tell us anything

Advertisement

If the prevailing rumors are accurate, this foldable will lack Face ID. It’s said that the device is too thin, but that doesn’t make a lot of sense, given that the iPhone Air has it. We’ll see.

Not only can we not determine if there is any TrueDepth camera system behind the display, we can’t tell which button may house the Touch ID sensor. It could theoretically be behind the screen too.

In all likelihood, if included, Touch ID will be contained in the power button, the same as it is on the iPad mini.

Two white smartphones lying flat on a table, shown from the side, highlighting their raised rear camera bumps and slim silver edges

A dummy foldable iPhone (left) versus a real iPhone Air (right)

Advertisement

When opened, as you’d expect, the foldable is about as thin as the iPhone Air.

Two white smartphones on a light surface, one with a single rear camera lens, the other with two lenses and a flash, partially showing a black screen edge

Camera plateaus on a real iPhone Air (left) versus a dummy unit for the foldable iPhone (right)

With the larger screen size, that makes the device feel even more futuristic than the iPhone Air.

The real thing is coming soon

Ultimately, these devices don’t do much more than confirm many of the rumors we’ve heard regarding the size, shape, and camera layouts. They’re a great physical representation of those rumors and an opportunity to see them in the real world.

Advertisement

These stoke interest further, building hype, and leaves us with more questions.

Software execution is just as important as hardware design and implementation. We don’t know for sure if it has vapor chamber cooling, if there is MagSafe, and if there’s Face ID.

Regardless, the new phones will be announced on September 9th at Apple’s Surprise and Shine event. And we’ll be there to cover it.

Advertisement

Source link

Continue Reading

Tech

39 New Methods That Compromise Passkey Authentication

Published

on

39 methods

Passkeys were introduced with a strong security proposition. Replace passwords with public key cryptography, bind the credential to the legitimate service, keep the private key away from the server, and many of the phishing and credential theft attacks that have plagued enterprise security for decades become dramatically harder.

All of that is true. But the security conversation has changed very quickly.

There are now at least 39 publicly documented methods, attack paths, research techniques, and exploitation scenarios involving passkeys and the infrastructure around them. Many already have working proof of concept tools or published research showing exactly how the techniques can be executed. Some are already appearing in real world attack patterns.

That does not mean criminals have operationalized all 39. It does mean the playbook is being written in public, and attackers no longer have to invent these techniques themselves.

Advertisement

More importantly, the research exposes a fundamental distinction that enterprises need to understand. The cryptography inside FIDO2 can remain completely intact while the account protected by the passkey is still compromised.

The Target Is No Longer Just the Passkey

A modern passkey authentication ceremony crosses an extraordinary number of trust boundaries. It can involve the web application, browser, operating system, password manager, cloud synchronization service, mobile device, Bluetooth transport, account recovery system, enrollment process, help desk, and ultimately the human being approving the authentication.

Researchers are attacking almost every one of those layers. Published techniques now include assertion mining, assertion replay, circuit breaker attacks, assertion phishing, browser hooking, assertion capture, challenge injection, detour replay, user verification manipulation, and user presence manipulation.

SpecterOps demonstrated the significance of this problem in its Pass the Passkey research. One of its most important observations was that malware does not necessarily need to extract a private key.

Advertisement

A malicious Windows application can ask the legitimate WebAuthn infrastructure to generate a signed assertion. The user sees what appears to be a legitimate Windows authentication experience, completes verification, and the attacker receives the resulting assertion.

The private key never left its protected location. The cryptography was not cracked. Yet the authentication process was successfully manipulated.

That distinction is central to understanding the new passkey threat model.

Passkeys are not completely secure unless they are tied to dedicated biometric hardware.

Advertisement

Learn how attackers exploit passkey enrollment rather than breaking passkey cryptography, and why dedicated biometric hardware strengthens enterprise identity assurance.

Download Report

Even the Passkey Prompt Is an Attack Surface

Several of the 39 published techniques target the user interface surrounding authentication.

Researchers have demonstrated passkey prompt flooding, credential interface deception, application metadata spoofing, window handle spoofing, remote desktop passkey phishing, and FIDO interface overlay attacks.

This recreates a problem the security industry already encountered with push-based MFA. Users become accustomed to authentication prompts. Once authentication becomes a routine visual interaction, attackers can manufacture, repeat, disguise, or strategically time those interactions.

Advertisement

SpecterOps demonstrated tooling capable of repeatedly invoking legitimate looking Windows passkey prompts. Researchers also demonstrated techniques that can make malicious authentication activity appear to originate from an application the employee already trusts.

The lesson is important. Phishing resistance at the cryptographic protocol layer does not guarantee deception resistance across the operating system, browser, application, and user interface layers surrounding that protocol.

Shareable Passkeys Expand the Attack Surface

The attack surface grows significantly when passkeys can be shared, synchronized, exported, restored, or moved between devices.

The published inventory now includes synced vault compromise, Apple or Google account takeover, cloud recovery takeover, stolen or compromised phones, mobile malware, rooted mobile devices, hybrid authentication manipulation, KeePassXC export theft, Bitwarden export theft, credential exchange theft, malicious browser extensions, and attacks involving CTAP and Bluetooth communication.

Advertisement

This is not fundamentally a cryptography problem. It is an architectural problem.

Once a credential can move between devices, synchronize through a cloud account, be exported from a vault, be restored using another identity, or be recovered through another process, the security boundary expands far beyond the original authenticator.

An attacker no longer needs to defeat FIDO2. The attacker needs to compromise one sufficiently trusted component somewhere in the surrounding ecosystem.

A synchronized passkey can therefore use extremely strong cryptography while still inheriting the weaknesses of the phone, operating system, password manager, cloud account, browser, recovery process, and synchronization system responsible for managing it.

Advertisement

Enrollment and Recovery Create Another Opening

Some of the most consequential attacks do not steal an existing passkey at all. They simply create another one.

Published techniques include shadow passkeys, enrollment vishing, attacker phone enrollment, attacker controlled passkey registration, help desk takeover, temporary credential abuse, SIM based recovery, reverse vishing, and migration pretext attacks.

Consider what happens when an attacker gains enough control of an employee account to initiate legitimate passkey registration. Instead of extracting the employee’s existing credential, the attacker registers an entirely new credential on a device controlled by the attacker.

Nothing has been cracked. Nothing has necessarily been stolen from the existing authenticator. The legitimate service itself creates a perfectly valid credential for the adversary.

Advertisement

This leads to an increasingly important identity principle. Phishing resistant authentication is insufficient if enrollment, replacement, recovery, and device registration are not protected to the same standard.

Dedicated Biometric Hardware Changes the Attack Surface

Dedicated biometric hardware approaches the problem very differently from passkeys stored on general purpose devices.

A purpose-built biometric authenticator can retain the private credential inside secure hardware with no cloud synchronization, no export mechanism, and no password manager responsible for moving the credential between devices.

Authentication can require a live fingerprint directly on the authenticator as well as physical proximity to the endpoint requesting access.

Advertisement

Just as importantly, a dedicated authenticator does not need to contain a traditional general-purpose operating system, an application store, a browser, or a screen.

That distinction eliminates enormous portions of the attack surface.

There are no third-party applications for an attacker to replace with malicious versions. Rogue applications cannot simply be installed on the authenticator. There is no browser extension ecosystem to compromise. There is no screen on which malware can present a deceptive authentication interface.

There is no consumer operating system filled with unrelated applications, permissions, background services, and update dependencies.

Advertisement

The authenticator performs a very small number of security specific functions and nothing else.

This drastically changes the economics of attacking it. Instead of attempting to compromise a huge general purpose computing environment, an attacker is confronting a tightly controlled hardware device designed specifically to protect cryptographic credentials and verify biometric identity.

It also makes the authentication process far more resistant to employee manipulation. An employee can be persuaded to visit a website, answer a telephone call, or follow instructions from someone claiming to be technical support. But social engineering cannot install a rogue application onto hardware that does not run ordinary applications.

It cannot manipulate a screen that does not exist. It cannot synchronize a credential through a cloud service that the authenticator does not use.

Advertisement

In that sense, properly designed dedicated biometric hardware becomes both highly resistant to attackers and highly resistant to mistakes made by employees.

Correct Service Configuration Is Critical

Dedicated hardware alone is not enough. The relying service must be configured to preserve the security model.

For sensitive enterprise environments, authentication and enrollment should be restricted to approved authenticator classes. The relying party should validate authenticator identity, enforce user verification, properly validate challenges and sessions, use appropriate signature counter protections, and prevent weaker methods from becoming fallback authentication paths.

Enrollment and recovery deserve particular attention. Adding a new authenticator should require proof from an already authorized authenticator rather than merely proving control of an account through a weaker recovery channel.

Advertisement

Configured correctly, this architecture prevents an attacker from simply enrolling an ordinary passkey from another laptop, phone, software vault, or security key. Cloud account takeover does not yield the credential. Password manager compromise does not yield it. Mobile malware cannot infect the authenticator.

A malicious application cannot be installed on it. And a remote attacker cannot manufacture the combination of dedicated hardware, biometric verification, physical proximity, and legitimate service interaction required to authenticate.

What the 39 Attacks Really Tell Us

The existence of 39 published attack methods does not mean FIDO2 cryptography failed. In many ways, it demonstrates the opposite.

Researchers repeatedly attack the software, synchronization systems, enrollment processes, operating systems, browsers, recovery mechanisms, and people surrounding the credential because defeating properly implemented cryptographic hardware directly is considerably more difficult.

Advertisement

That should tell security leaders where the next identity boundary needs to be.

For high value enterprise identities, credentials should not be freely shareable across consumer devices and cloud ecosystems. They should be bound to dedicated biometric hardware, the verified individual, the legitimate service, and an enterprise controlled enrollment and recovery process.

Passkeys solved a large part of the password problem. The 39 published attacks show us what attackers are targeting.

Dedicated biometric hardware, correctly implemented from enrollment through authentication and recovery, removes virtually all of that surrounding attack surface before an attacker ever gets the opportunity to use it.

Advertisement

Download the Token passkey security ebook to explore many published attack methods and see how dedicated biometric hardware changes the enterprise identity trust model.

Sponsored and written by Token.

Source link

Advertisement
Continue Reading

Tech

Google brings its best AI music model Lyria 3.5 to the Gemini app

Published

on

Google has added Lyria 3.5, its most advanced music generation model yet, to the Gemini app. Previously available through Google’s AI filmmaking tool Flow, the model is now rolling out to all Gemini users, making it easier to generate polished songs, instrumentals, and soundtracks from simple text prompts or even photos.

Lyria 3.5 makes AI-generated music sound more natural

Google says Lyria 3.5 delivers richer arrangements, more expressive vocals, and better prompt comprehension than previous versions. The model builds out full songs complete with actual verses, choruses, and bridges, rather than just looping a short melodic clip.

Inside Gemini, you can now pick or describe a genre, choose between vocal or instrumental styles, and decide whether you want a short clip or a longer track. If you are a beginner, you can use templates to get started and generate background music for a video, a custom jingle, or a personalized ringtone.

However, keep in mind that once a track is generated, you can’t edit it mid-prompt. Google is also making Lyria 3.5 available through the Gemini API, allowing developers to integrate AI music generation into their own apps and services.

Advertisement

Lyria 3.5 arrives at a chaotic moment for AI music

AI music has flooded music platforms like Deezer, where AI-generated songs now make up 44% of daily uploads, and a large share of the streams they’ve pulled in were later found to be fraudulent. This is why every track Lyria makes carries a SynthID watermark – an invisible marker meant to flag it as AI-generated content.

Lyria’s guardrails specifically block cloning an artist’s voice or reproducing copyrighted lyrics, following a recent European court ruling against Suno, a rival AI music company, over copyright issues. That ruling isn’t the final word on the matter, though. It’s still subject to appeal, so the legal picture around AI generated music remains unsettled for now.

Source link

Advertisement
Continue Reading

Tech

Two unreleased Apple game controllers found in macOS code

Published

on

Apple already supports nearly every major game controller, but new evidence suggests that the company may want to add its own hardware to the mix.

Apple may be looking to expand its ambitions beyond software and platform support. Newly discovered code references two unreleased controllers with notably different feature sets.

The references appeared within code briefly included in macOS 26.7, first spotted by pdfu, a MacRumors forum regular. The controllers in question are identified as “T6502” and “T1057”.

The game controllers will likely be similar to others that already exist on the market. There are notable differences between T6502 and T1057, though.

Advertisement

Both will feature a four-button ABXY layout, two clickable thumbtacks, shoulder buttons, analog triggers, and Home and Menu buttons. Essentially, they’ll have the same functionality as any of the first- or third-party PlayStation- or Xbox-like controllers out there.

T6502, the more basic of the pair, will also see the addition of an Options button. It will connect via USB only, and does not feature motion sensors or motion input through Apple’s GCMotion interface.

There will be no touchpad-like controls, rear buttons, speakers, microphones, or other advanced features.

Perhaps the most interesting part is Apple’s haptic channels. T6502 will utilize four separate haptic channels in software: Left, Left (Synthetic), Right, and Right (Synthetic).

Advertisement

According to pdfu, this may be created to let two software haptic request channels share the same physical motor. This should allow for proper feedback and reduce distortion and clipping.

T1507 seems to be the higher-end of the pair. It will connect via USB, as well as Bluetooth and Beats USB; it will not feature an Options button.

Its motor system doesn’t divide out synthetic channels. Instead, it has a single, addressable actuator motor.

It also includes an accelerometer and gyroscope. This should allow for input via acceleration and gyroscope readings on the X, Y, and Z axes.

Advertisement

The code was initially customer-facing. As pdfu notes, the references were pulled in the second release of macOS 26.7.

Late to the game

It’s not entirely clear why Apple would be creating a game controller now. The controller market is crowded with well-established first- and third-party options.

Apple has spent years expanding support for controllers that players likely already own, including those from PlayStation, Xbox, Nintendo, and countless third-parties. With plenty of options available at nearly every price point, an Apple-made controller would need to offer something more than just bog-standard game controls.

That isn’t to say it wouldn’t sell well if they did. There will always be a market for things Apple makes, a lesson we’ve learned from products like the iPhone Pocket and the original $19 Polishing Cloth.

Advertisement

Source link

Continue Reading

Tech

RFK Jr. Wants Your Medical Records

Published

on

from the seems-bad dept

This article is republished from The Conversation under a Creative Commons license. Read the original article.

You might assume that what you tell a doctor stays between you, your physician and perhaps your insurer. But the reality is more complicated.

The Health Insurance Portability and Accountability Act, the federal privacy law that governs health information and is commonly known as HIPAA, is narrower than its reputation suggests. It regulates hospitals, physicians, insurers and their business associates, but not the health data you generate everywhere else: not the period-tracking application on your phone, the internet search you ran about a diagnosis, the DNA you mailed to a genealogy company or the wearable that counts your heartbeats.

Even the records HIPAA does cover can be shared, sold or handed to the government in ways that might surprise you.

Advertisement

This gap in protection matters more than ever because the U.S. government is pushing hard to gather health data domestically and abroad. This is happening even as a growing body of research shows that the safeguard which these efforts to collect data lean on – anonymizing data by removing identifying information to make it difficult to trace back to an individual – is far weaker than officials claim.

As a professor of law at Indiana University, I study health information privacy and medical data regulation, which includes tracing how sensitive health information moves among clinics, government agencies and law enforcement. As a co-investigator on a federally funded study about opioid prescribing, I rely on health data in my own research. I appreciate its value for science, and I also see the danger of collecting it without meaningful safeguards.

Limits of medical privacy

HIPAA gives you several rights: You can see your health records, demand corrections and expect that a covered provider will not casually disclose your information.

But the law also permits release of some information without your consent. A hospital fully bound by HIPAA may release certain types of records without your authorization and without telling you. There are roughly a dozen such categories. Information about treatment, payment and routine healthcare logistics require no sign-off. Neither does information released for public health reportinglaw enforcementjudicial and administrative proceedingshealth plan oversightresearch or the broad catchall of essential government functions.

Advertisement

The statute is also thick with additional exceptions. In practice, much of your health information can be shared through these many open doors. And once data is sent outside the system covered by HIPAA, the HIPAA limits fall away.

For instance, prescription drug monitoring programs, which every state now operates, assemble detailed logs of who filled which controlled substance prescription and when. Federal law enforcement can often access these logs with a self-issued administrative subpoena – an order that doesn’t require a judge’s approval or oversight.

These programs have expanded beyond opioids into a dragnet that shares health data across state lines, exposing patients who seek reproductive or gender-affirming healthcare to surveillance far from home.

Health records can flow to many destinations under different rules. A given disclosure might feel more like a violation depending on who decides where it can go and who can then see it.

Advertisement

RFK Jr.’s push to access Americans’ health records

Since the spring of 2025, Health and Human Services Secretary Robert F. Kennedy, Jr. has sought federal access to Americans’ medical records to investigate whether vaccines cause autism. The scientific community has studied this question for decades and has shown decisively that they do not.

According to KFF Health News, HHS has been courting state health information exchanges – the little-known systems that let hospitals and clinics swap detailed, identifiable patient records – and asking how those records might be used for vaccine research. One proposal floated by state organizations would give HHS data on 90% of Americans’ medical records by 2028. In Nebraska, millions of federal grant dollars have flowed to a statewide health information exchange nonprofit that has cooperated with the effort.

Large health datasets can be useful. Pooled records can expose drug side effectstrack outbreaks and reveal disparities in care that smaller studies miss. Public health has always depended on some surrender of individual privacy for collective benefit.

The concern is not that the government should never collect health data. It is that meaningful safeguards have not kept pace with the scale of collection and capabilities of modern data analytics.

Advertisement

In seeking access to Americans’ medical records for a vaccine and autism study, HHS has declined to say how many states are involved, what data it collects, who can see it or how it will be protected.

Building a comprehensive repository to chase a question that science has already answered inverts the logic of research. Usually a hypothesis justifies the data collected, rather than the reverse.

Collecting identifiable records for tens of millions of people in a single database also creates a target for breachessecondary uses that no one consented to and abuses by current or future administrations with different priorities.

‘Anonymized’ doesn’t protect your health privacy

Officials have offered reassurances that data will be aggregated and stripped of identifiers so no individual can be singled out.

Advertisement

Decades of computer science research undercuts that promise. A study published in Nature in June 2026 sharpened the point, showing that in this age of artificial intelligence, stripping identifiers from patient records to protect identity does not protect all patients equally.

The researchers audited AI diagnostic models trained on clinical data, including chest X-rays, electrocardiograms and electronic health records. They asked whether an outsider could tell if a particular person’s data had been used to build the model. For instance, confirming that someone’s record helped train a cancer-prediction tool can reveal that that person has cancer. This exploit is known as a membership inference attack.

The research team found that while the average risk of being identified from data stripped of identifying information often looked reassuringly low, some patients faced near-certain reidentification The burden fell unevenly: Underrepresented groups, sorted by race, insurance status or diagnosis, were most at risk. Those most exposed were frequently already most vulnerable to discrimination.

Researchers have long established that removing identifiers from rich datasets does not reliably protect the people in them, and that identification gets easier the more information you have. Today’s AI technology makes it possible to carry out these attacks remotely and quickly.

Advertisement

The same privacy problems, exported

The U.S. government’s appetite for health data does not stop at the border. As ProPublica reported in June 2026, the State Department has been conditioning lifesaving aid to African nations on access to their citizens’ health data.

Under the Trump administration’s global health plan, Uganda agreed to give the United States real-time access to nine of its health data systems for seven years, including the central repository of the nation’s health information and the system managing individual electronic medical records, in exchange for up to US$1.7 billion over five years, a sum that shrinks each year and falls below prior U.S. support. Kenya struck a similar deal; Zambia, Zimbabwe and Ghana walked away from the initial terms.

The U.S. government has promised that the data will be aggregated and anonymized, but privacy experts warn that the agreements are vague and omit standard limits on how much data is taken and how it can be used. A Ugandan digital rights lawyer called the choice his country faced the essence of digital colonialism: Accept the deal and risk exploitation, or refuse it and watch people die.

The common thread

Domestic records collection and foreign data-for-aid deals rest on the same faith that anonymization neutralizes the risk of pooling sensitive health data.

Advertisement

The evidence says otherwise. This does not mean health data should never be gathered or studied, but I believe that the reassurances deserve skepticism, the safeguards deserve scrutiny, and the people whose bodies generated the data deserve a say. To safeguard privacy, a government seeking sensitive medical records should have to show why it needs them and how the safeguards it relies on hold up.

Privacy law was built for a world where data resided in filing cabinets. Governments from Kalamazoo to Kampala now operate in a world where even an anonymized digital record can point back to you.

Jennifer D. Oliva is Professor of Law, Indiana University

Filed Under: autism, hipaa, medical records, privacy, research, rfk jr., vaccines

Advertisement

Source link

Continue Reading

Tech

Lamborghini Temerario Polizia Unveiled, Boasts 907 Horses for Italy’s Most Urgent Runs

Published

on

Lamborghini Temerario Polizia Italian State Police
On Friday at Lamborghini’s Sant’Agata Bolognese headquarters, Interior Minister Matteo Piantedosi stood with Chairman and CEO Stephan Winkelmann as a Temerario in official Polizia colors entered service. Prefect Renato Cortese attended for Police Chief Vittorio Pisani. A book called “I motori della Polizia,” a short record of the force’s working machines, was presented with the car.



The Polizia di Stato’s collaboration with Lamborghini began in 2004, when a Gallardo made its maiden organ run late that September. But we’re talking about a whole different generation of automobiles now, with the Gallardo LP 560-4, Huracán lined up along the autostrada, and a Urus Performante coming in 2023. In twenty-two years, we’ve seen six donated Lamborghinis cover over 200 organ and medical supply trips before attending more than 1,500 road-safety events, and Temerario is now joining the ranks. It joins a group that includes those six Lamborghinis, as well as a host of other vehicles, and they have no plans to retire the ones that are already in service

Sale


LEGO Technic Lamborghini Revuelto Super Sports Car Toy – Building Set for Girls & Boys – Lamborghini…
  • REMOTE CONTROL TOY CAR – Builders ages 10+ can create a fully motorized LEGO Technic Lamborghini Revuelto supercar with authentic Italian styling…
  • INTERACTIVE SUPERCAR MODEL – This car toy connects to the CONTROL+ app where drivers can steer the vehicle, activate lights, and monitor live…
  • AUTHENTIC LAMBORGHINI FEATURES – The detailed car model includes glow-in-the-dark headlights, sleek aerodynamic body, and realistic proportions that…


The Temerario’s power comes from a fresh new 4.0-liter twin-turbo V8 and three electric motors that feed an eight-speed dual-clutch transmission. Overall, the combined output is 907 horsepower, with the V8 alone generating 800 CV, a staggering 10,000 rpm, and 730 Newton-meters of torque. Yeah, the factory-quoted time to 100 km/h is 2.7 seconds, and the top speed is 343 km/h. Oh, and the hybrid stack contains a 3.8-kilowatt-hour battery; this is the first plug-in hybrid in the police fleet’s history.

Advertisement

Lamborghini Temerario Polizia Italian State Police
Temerario appears to be sporting the same livery that we’ve come to associate with the Gallardos from their inception: blue and white paint, Polizia branding on the doors, and the traditional tricolor flashing lights. There is a light bar on the roof, however we are unsure whether there is a separate chilled medical section for medical purposes.

You may be wondering why a mid-engine coupe like this one is wearing this type of livery; the simple answer is that it is for organ transport. The truth is, most of the time it’s conducting routine officer duty, such as teaching kids in schools and driving at events, and it won’t be purchased with taxpayer money because Lamborghini gives each one. Instant shove off the line, followed by a brief period of calm running before the V8 kicks in, which is essentially what the electric motors bring to the party. Handy when you get a call and need to get on the road right away, especially if it starts in a metropolis. The prior Lamborghini police cars employed naturally aspirated V10 engines, so this is a completely different ballgame.

Lamborghini Temerario Polizia Italian State Police
You can tell that the Temerario transfer was portrayed as merely another chapter in what is turning out to be a remarkable collaboration between Lamborghini and the Polizia di Stato. Now it is up to Temerario to complete its next run on time.

Source link

Advertisement
Continue Reading

Tech

Why the Xbox Elite Series 2 Controller Still Carries Late Nights After Seven Years

Published

on

Xbox Elite Series 2 Controller
Microsoft shipped the Xbox Elite Wireless Controller Series 2, priced at $111.74 (was $150), in late 2019 as a heavier, more configurable pad built around metal parts, an internal battery, and a profile switch that lives on the face of the controller. Years later it still shows up in living rooms and on desks because the basics have held: four rear paddles, tension you can set with a small tool, trigger stops that shorten travel, and a grip that wraps far enough to keep sweaty hands from sliding during long sessions.



Four metal paddles clip onto the back and map to almost any input through the Xbox Accessories app on console or Windows. Plenty of players park jump or reload on the upper pair so thumbs stay on the sticks in shooters. If you only want two, you can get them off with some vigorous pulling, or you may opt for the thinner core version, which comes without them and allows you to add the whole accessory pack later. Medium and mini paddle shapes give you a choice in how far your fingers travel.a

Sale


Xbox Wireless Gaming Controller | Elite Series 2 Core | White | Console, PC, and Android | Adjustable…
  • XBOX ELITE WIRELESS CONTROLLER SERIES 2: Play like a pro with adjustable-tension thumbsticks, wrap-around rubberized grip, and shorter hair trigger…
  • CORE ESSENTIALS: Includes just the components you need to unleash your best game. Additional components sold separately for even more customization…
  • LIMITLESS CUSTOMIZATION: Exclusive button mapping options in the Xbox Accessories app—even pick which color the Xbox button lights up with.*


One enhancement that is sometimes ignored is adjustable stick tension. A little tool allows you to tighten or relax each analog stick to three levels of stiffness, so the sensation of returning to the middle matches the game. The full kit also includes a variety of extra toppers in traditional, tall, and dome designs, as well as an extra d-pad in case the one on the controller isn’t to your liking. Hair trigger locks on each analog trigger allow you to select from three different ‘stops’ to reduce the distance required to trigger a shot in a racing or shooting game without sacrificing the complete analog feel when needed.

Advertisement

Xbox Elite Series 2 Controller
The built-in rechargeable battery can last up to 40 hours, and we’ve seen it get close to that with the vibration turned off. You may charge it with a USB-C cable or place it on the magnetic dock in the carrying case that comes with the entire set. As for connectivity, this pad has Bluetooth, wireless Xbox, and USB-C all in one, so you can use it on a Series X, Series S, Xbox One, PC, or even an Android smartphone. Paired devices will require some effort to set up, as it can be unpleasant to try to pair them between many machines.

Xbox Elite Series 2 Controller
The Xbox Accessories app allows you to save up to three custom profiles and switch between them using the profile button and its three little LEDs. You may customize any face button, bumper, trigger, or paddle, adjust the sensitivity of the sticks, mute or stretch out the rumble and impulse triggers, and even change the color of the Xbox button light. Shift mapping adds an extra layer of commands without overloading the paddles.

Source link

Continue Reading

Tech

AI startup micro1 bids $12.5M for Spirit’s records, topping Google’s agreed $10M deal

Published

on

The AI training-data company micro1 has offered $12.5M for Spirit Aviation’s internal records, topping Google’s agreed $10M and proposing an ombudsman chosen by Spirit’s advisers rather than the buyer. European law would treat the deidentification promise as a question about capability rather than a label, but none of it applies to an American liquidation.

An AI training-data company has offered $12.5M for the internal records of a dead airline, $2.5M more than Google agreed to pay. micro1 made the offer in a court filing on Thursday, Bloomberg News reported.

Spirit Aviation Holdings stopped flying in May and is being liquidated. The records include 500 million Microsoft Teams items, 100 million emails and roughly 16 million customer chat sessions.

TNW reported last month that under the Google agreement Spirit must hand the material to parties the buyer designates. Google picked and paid for the deidentification firm, and that cost does not come off the price.

Advertisement

micro1’s pitch is aimed squarely at that. It proposes an ombudsman selected by Spirit’s own advisers, and says the data would be stored in the United States.

The court filing also excludes disciplinary and investigatory material, and anything connected to collective bargaining with the unions that represented Spirit staff. Those unions have already challenged the Google sale on privacy grounds.

Google says it will not receive any personal information from the dataset and will pay a third party to strip out sensitive customer details. A judge considers its purchase on 9 September.

Courts rarely reopen an auction that has already closed, so micro1 faces a procedural problem rather than a pricing one.

Advertisement

One detail complicates the premium. Google’s agreement left customer chat sessions out of the sale, along with loyalty records and call recordings, and micro1’s offer names roughly 16 million sessions.

In Europe none of this would turn on the word deidentified. The Court of Justice ruled last September that pseudonymised data is personal data or not depending on whether the recipient can realistically identify anyone.

That is a question about capability, not labelling. The Google contract requires preserving referential integrity, which keeps pseudonymous records linked to each other across systems.

The European Data Protection Board has also said a model trained on personal data is not automatically anonymous, and that regulators may examine whether training data was lawfully obtained.

Advertisement

Purpose limitation would bite too. Records generated to fly aircraft and pay 17,000 staff were not gathered to train models, and reusing them in the EU needs its own legal basis.

None of that applies here. Spirit’s estate is wound up under American law, which is why this is a bidding war rather than a regulatory question, and why EU data laws would have made it one.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025