1444 stories
·
0 followers

Judge Approves $1.5 Billion Anthropic Settlement Over Pirated Books Used To Train Claude

1 Share
A federal judge has approved Anthropic's $1.5 billion copyright settlement over pirated books used to train its Claude chatbot, with authors and publishers set to receive about $3,000 per book. The case produced a mixed ruling for the AI industry: training on copyrighted books was found not to be illegal, but Anthropic's use of pirated copies from shadow libraries was. The Associated Press reports: District Judge Araceli Martinez-Olguin said in a Monday ruling that the class-action settlement provides "meaningful relief" to affected authors and publishers. About 91% of the more than 482,000 books covered by the ruling have been claimed by authors or publishers who are now due payment. Plaintiff attorney Justin Nelson said in a statement that the settlement was "the largest known copyright recovery in history. We look forward to making distributions to the Class as promptly as possible."

Read more of this story at Slashdot.

Read the whole story
Share this story
Delete

AI Companies Are Buying Tons of Old Books Because They're Free of AI Slop

1 Share
An anonymous reader quotes a report from 404 Media: As AI companies search for more training data to improve their models, one company is offering old, printed books as an ideal source because they are guaranteed to be free of the very AI slop AI companies are producing. "The world's best AI training data is sitting on a shelf," ISBNdb, a company that produces what it claims is "the world's largest book database," and that offers high-volume book acquisition services for AI companies, says on its site. "Books represent curated, peer-reviewed, domain-specific human knowledge, structured in a way no web crawl can replicate. Dense, edited, authoritative." In one article on its site, ISBNdb explains that printed books published before 2022 are ideal for AI training data because they don't include AI generated text. As the article correctly notes, much of the data that AI companies can scrape from the internet today is likely to include AI generated text, which could result in "model collapse," a process by which AI models that are trained on AI generated data results in worse models that are more prone to errors. The article also notes that book authors who object to their writing being scraped for training purposes can now easily poison AI models by producing writing designed to manipulate and sabotage the resulting AI models. "Print books from the pre-LLM era are structurally guaranteed to be free of this contamination. That alone is a significant advantage [...] "Physical books published before this date [pre-2022] are structurally clean of modern poisoning tools." [...] ISBNdb advertises that it can keep the identity of AI companies secret. "Strict NDA [non-disclosure agreement] on every engagement," ISBNdb's site says. "Every project begins with a legally binding non-disclosure agreement. Your identity, strategy, and acquisition targets are never disclosed." ISBNdb notes that AI companies may not want to be caught destroying printed books during the scanning process. "The optics problem is real," ISBNdb's site says. "'AI company destroys two million books' is not a headline that generates sympathy."

Read more of this story at Slashdot.

Read the whole story
Share this story
Delete

LG to Ban Residential Proxies from Smart TV Apps

1 Share

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.

Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisions. Image: Spur.us.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components.

Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.”

Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company’s review of those apps is “well underway now.”

“As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs,” Taylor wrote in an emailed statement.

App makers looking for ways to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that turn the user’s device into a residential proxy node that is rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities.

A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. Image: Spur.us.

Spur’s report found the residential proxy network Bright Data accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. Bright Data did not respond to requests for comment.

Bright Data and other proxy providers named in Spur’s report all say they follow rigorous know-your-customer processes to validate legitimate uses of their services, which is often heavily tied to content-scraping activities by said customers. The proxy companies also say they incorporate technological countermeasures to prevent proxy service customers from being able to interact with and control other devices on the proxy user’s local network.

Spur argues the problem is not that residential proxy networks exist, but rather that they are being embedded at scale in devices that most consumers do not think of as computers and are not equipped to audit.

“A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”

LG’s announcement that it is culling residential proxy SDKs from its app store is welcome news, but the company recently came under fire for another questionable partnership: Pimping McAfee security products via software drivers included in its high-end LCD monitors.

Earlier this week, the Youtube channel Gamers Nexus showed that certain LG LCD monitors will automatically install an app that promotes paid McAfee antivirus subscriptions, and that the app arrives through Windows Update without an approval prompt.

Read the whole story
Share this story
Delete

Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk

1 Share
An anonymous reader quotes a report from TechCrunch: Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday. Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it "immediately." The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress. It's unclear how many WordPress-powered websites on the internet are at risk, but it's possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress' official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don't reflect websites that have recently been patched. Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15% are vulnerable. Applying Card's projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million. [...] One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites.

Read more of this story at Slashdot.

Read the whole story
Share this story
Delete

The first UL 3700-compliant plug-in solar microinverter is now available in the US

1 Share
It's a step toward making alternative energy accessible on a smaller, renter-friendly scale.

Read the whole story
Share this story
Delete

NRC is (sort of) getting rid of "as low as reasonably achievable" standard

1 Share

Last week, just before the US started its break for the July Fourth holiday, the Nuclear Regulatory Commission (NRC) proposed a new rule that would change how it regulated exposure to radiation. The Trump administration has been pushing to restart construction of nuclear power plants in the US, and many pro-nuclear advocates have been complaining about the US's existing regulations, portraying them as the main barrier to the flourishing of the industry. So, it had seemed likely that major revisions were coming.

Instead, the NRC's proposed new rules endorse the science behind its current rules and suggest that any problems are largely in the vagueness of the terminology that it has been using. So, instead, it's endorsing standards that are meant to accomplish the same thing, but avoid using some of the language it had relied on. Probably the clearest indication of the evolutionary change at play is that the NRC estimates the changing rules will save industry—not just power, but also medical and research applications—only about $9.5 million a year.

LNT and ALARA

There are two technical abbreviations at the center of US nuclear regulations. The first is LNT, which stands for "linear non-threshold." It's in reference to the issue of whether there's any level of radiation that is so low that it no longer produces harmful biological effects—the "threshold" in LNT. The "non-threshold" implies that it doesn't, and that's in keeping with biology, which has demonstrated that even single particles or photons of radiation can damage DNA and that the mechanisms cells have for repairing that damage are inherently error-prone. The "linear" in LNT simply describes how the impact of radiation scales directly with the dose.

Despite the solid foundation in basic biology, LNT has been difficult to demonstrate in the real world. Humans are exposed to many factors that can influence the development of cancer, including naturally occurring radiation. Teasing out the impact of a small dose of radiation that occurs in addition to all those other exposures is extremely challenging, and the impact of extremely low exposures has not been decisively demonstrated.

Complicating matters, a number of people have advocated for something called hormesis, in which small doses of radiation purportedly promote the cellular repair of damage from other sources. The evidence for this is even spottier, and when the NRC was petitioned to adopt hormesis as part of its scientific framework during Trump's first term, it rejected the petition.

Given its acceptance of an LNT model of exposure risks, the NRC had chosen exposure standards that fell under the general term of ALARA: as low as reasonably achievable. If any exposure to radiation poses a risk, then minimizing it is the clearest way to protect the health of people who work with radioactive substances. The challenge there is that it's possible to set exposure limits that people outside the industry regularly exceed each time they board a commercial aircraft.

So, the word "reasonable" plays an outsized role while remaining highly subjective. Critics have charged that it precipitates an endless cycle of reasonable exposure limits leading to searches for additional ways to lower them further, or of adoption without cost considerations. And here, the NRC is acknowledging that there have been issues. "In essence, the reasonableness test that is supposed to be inherent to ALARA-related decision-making has gradually become an expectation that if a means of dose reduction is available, regardless of its reasonableness in relation to the total dose and the amount of reduction, it should be applied without further consideration," its new proposal suggests.

In the past, the NRC has attempted to address this by attaching a financial value to each unit of exposure based on estimates of the value of healthy life developed elsewhere. But in the new proposal, it accepts that "there have been challenges in the implementation of the ALARA requirement, namely a lack of clarity of when dose reduction is deemed sufficient, excessive subjectivity, and susceptibility for selective or inconsistent enforcement." So, it's giving up on a term that it now views as a source of confusion.

What's different

One of the key things here is that the LNT model of exposure risks isn't going away. In its earlier denial of petitions that it change its standards, the NRC had concluded that "in the absence of convincing evidence that there is a dose threshold or that the health effects of low levels of radiation are fully understood, the LNT model for cancers and genetic effects was appropriate for formulating radiation protection standards and planning radiation protection programs." In the proposed new rules, that logic is left intact. "The NRC finds that no consensus-supported, regulation-ready alternative model to the LNT model exists at this time," it states.

More specifically, it states, "It is unlikely there might be a threshold level of exposure below which biological response does not occur. Such a threshold could only occur if DNA repair processes were totally effective in that dose range or if a single radiation track were unable to produce an effect."

It's worth noting that the NRC is making that decision despite the fact that Trump issued an executive order that describes LNT and then calls it irrational. "The NRC utilizes safety models that posit there is no safe threshold of radiation exposure and that harm is directly proportional to the amount of exposure," the order reads. "Those models lack sound scientific basis and produce irrational results." The agency is keeping LNT in place despite being specifically ordered to reconsider it.

With LNT intact, the scientific backing for ALARA remains in place. So, the new proposed regulations largely focus on calling it something else. "The NRC proposes to remove references to the ALARA principle, which rests on the LNT model’s assessment of risks from very low doses of radiation, from its regulations," the proposed changes say. "Instead, the NRC would apply a less-subjective, graded approach to managing doses below regulatory limits."

To replace ALARA, the NRC will start with a limit at which evidence clearly indicates radiation impacts would be apparent and set exposure thresholds below that. From lowest to highest exposure, these thresholds will require increasingly aggressive efforts to limit exposures.

The language of the details is a bit confused, however. As its name implies, the LNT model suggests there are no thresholds below which biological risks go away, and the NRC accepts that model. Yet it's regulated based on thresholds. It's also referring to those thresholds as an implementation of an "optimization" approach to safety. But it also quotes a definition of optimization that refers to it as a form of ALARA—which, again, is a term that the NRC wants to get rid of.

Beyond that action, the rule changes the NRC is proposing largely focus on updating regulations on the use of equipment to monitor exposures. Technology has advanced since the agency last modified its requirements there, and it's using this proposal to update them accordingly.

Number crunching

Regardless of the confusion, it's clear that the changes aren't going to cause the sort of boom in nuclear power that the Trump administration expected in its executive order. One of the key features of the planned rules is that any organization that's currently in compliance will remain that way without making any changes. Changes will only make sense if an organization thinks it can save money by adopting them.

And, as noted above, those savings for industry will be pretty minimal, with the total estimated at $9.5 million a year. Even if we assume that these savings go only to nuclear power and are ascribed only to dropping ALARA (as opposed to cheaper exposure monitoring, for example), spread out across the 57 nuclear plants in the US, that means just an average savings of a bit over $150,000 per plant.

So, those who viewed ALARA as the cause of all the nuclear industry's woes will likely be excited to see the NRC eliminate it. But they'll also be disappointed to find that its scientific foundations remain intact, and the regulatory environment will be minimally changed as a result.

Read full article

Comments



Read the whole story
Share this story
Delete
Next Page of Stories