Chinese communist party ‘accessed Hong Kong protesters’ TikTok data’ | The Guardian
A former executive at TikTok’s parent company, ByteDance, has alleged that the Chinese Communist party accessed user data from the social video app belonging to Hong Kong protesters and civil rights activists.
Yintao Yu, a former head of engineering at ByteDance’s US operation, claimed in a legal filing that a committee of Communist party members accessed TikTok data that included the users’ network information, Sim card identifications and IP addresses in a bid to identify the individuals and their locations.
The claims, in a wrongful dismissal lawsuit brought by Yu in a California court and reported by the Wall Street Journal, also allege the party accessed TikTok users’ communications, monitored Hong Kong users who uploaded protest-related content and that Beijing-based ByteDance maintained a “backdoor channel” for the party to access US user data.
Yu alleges in the filing that members of a Communist party committee inside ByteDance had access to a “superuser” credential which was also called a “God credential” and allowed them to view all data collected by ByteDance.
TikTok Creators’ Sensitive Financial Information Stored In China
https://www.forbes.com/sites/alexandralevine/2023/05/30/tiktok-creators-data-security-china/
TikTok has stored the most sensitive financial data of its biggest stars — including those in its “Creator Fund” — on servers in China. Earlier this year, CEO Shou Chew told Congress “American data has always been stored in Virginia and Singapore.”
Risk of extinction by AI should be global priority, say experts | The Guardian
Hundreds of tech leaders call for world to treat AI as danger on par with pandemics and nuclear war
Android phones are vulnerable to fingerprint brute-force attacks
Researchers at Tencent Labs and Zhejiang University have presented a new attack called ‘BrutePrint,’ which brute-forces fingerprints on modern smartphones to bypass user authentication and take control of the device.
Brute-force attacks rely on many trial-and-error attempts to crack a code, key, or password and gain unauthorized access to accounts, systems, or networks.
…
The attacker needs physical access to the target device to launch a BrutePrint attack
Lawyer cites fake cases invented by ChatGPT, judge is not amused
https://simonwillison.net/2023/May/27/lawyer-chatgpt/
A lawyer asked ChatGPT for examples of cases that supported an argument they were trying to make.
ChatGPT, as it often does, hallucinated wildly—it invented several supporting cases out of thin air.
When the lawyer was asked to provide copies of the cases in question, they turned to ChatGPT for help again—and it invented full details of those cases, which they duly screenshotted and copied into their legal filings.
At some point, they asked ChatGPT to confirm that the cases were real… and ChatGPT said that they were. They included screenshots of this in another filing.
The judge is furious. Many of the parties involved are about to have a very bad time.
NHS data breach: trusts shared patient details with Facebook without consent | The Guardian
Observer investigation reveals Meta Pixel tool passed on private details of web browsing on medical sites
Report: ‘massive’ Tesla leak reveals data breaches, thousands of safety complaints | The Guardian
Tesla has failed to adequately protect data from customers, employees and business partners and has received thousands of customer complaints regarding the carmaker’s driver assistance system, Germany’s Handelsblatt has reported, citing 100 gigabytes of confidential data leaked by a whistleblower.
The Handelsblatt report said customer data could be found “in abundance” in a data set labelled “Tesla Files”.
35 Ways Real People Are Using A.I. Right Now - The New York Times
AI image generation puts video game illustrators out of work - Rest of World
https://restofworld.org/2023/ai-image-china-video-game-layoffs/
Recent breakthroughs in AI image generation have created widespread anxiety in China’s video game art industry.
Given the high quality of AI-produced artwork, many illustrators are losing their jobs to AI image generators such as Stable Diffusion and DALL-E 2.
The gaming industry’s job market was already precarious after the Chinese government’s licensing freeze in 2021 threw thousands of game developers out of business.
ChatGPT sets record for fastest-growing user base | Reuters
ChatGPT, the popular chatbot from OpenAI, is estimated to have reached 100 million monthly active users in January, just two months after launch, making it the fastest-growing consumer application in history, according to a UBS study on Wednesday.
CISA, FDA warn of new Illumina DNA device vulnerability
https://therecord.media/illumina-dna-sequencing-devices-vulnerability-fda-cisa
Several U.S. agencies warned this week about a vulnerability affecting software in devices used for DNA research that would allow hackers access to sensitive patient information.
The Food and Drug Administration (FDA) and the company behind the devices — Illumina — said they have not received any reports indicating the vulnerability has been exploited.
Illumina is one of the world’s biggest manufacturers of medical devices that handle bioanalysis and DNA sequencing.
Europeisk forbrukernettverk advarer mot å bruke Klarna – NRK Kultur og underholdning
https://www.nrk.no/kultur/europeisk-forbrukernettverk-advarer-mot-a-bruke-klarna-1.16401582
Forbruker Europa er Forbrukertilsynets avdeling for handel på tvers av landegrensene i EU. De hjelper norske forbrukere som handler fra andre EU-land hvis noe går galt.
I fjor og hittil i år har de sett en økning av klager mot betalingstjenesten Klarna og nå advarer de mot å bruke tjenesten.
Facebook to be fined £648m for mishandling user information | Facebook | The Guardian
Decision by Ireland’s privacy regulator will set record for breach of EU’s data protection rules
Hibernation artificially triggered in potential space travel breakthrough | The Guardian
… scientists showed that hibernation can be artificially triggered in rodents using ultrasonic pulses.
The advance is seen as significant because the technique was effective in rats – animals that do not naturally hibernate. This raises the prospect that humans may also retain a vestigial hibernation circuit in the brain that could be artificially reactivated.
“If this proves feasible in humans, we could envision astronauts wearing a helmet-like device designed to target the hypothalamus region for inducing a hypothermia and hypometabolism state,” said Hong Chen, an associate professor at Washington University in St Louis, who led the work.
Hyundai and Kia thefts keep rising despite security fix
https://news.yahoo.com/hyundai-kia-thefts-keep-rising-144034139.html
Nearly three months ago, Hyundai and Kia unveiled software that was designed to thwart an epidemic of thefts of their vehicles, caused by a security flaw that was exposed on TikTok and other social media sites.
So far, it hasn’t solved the problem. Across the country, thieves are still driving off with the vehicles at an alarming rate.
…
The companies’ affected cars, many of them lower-cost models from the 2011 to early 2022 model years, were not equipped with a theft immobilizer. Such a device contains a computer chip in the key that must be recognized by another chip in the steering column before the engines will start.
Though most automakers have had the chips for years, Hyundai and Kia have lagged behind the industry as a whole in installing them on many models, thereby allowing thieves to exploit the security gap.
I block ads • Cory Dransfeldt
Major Photography Prize Winner Reveals Image Is AI-Generated, Rejects Award
https://www.vice.com/en/article/dy3vxy/sony-world-photography-awards-ai-generated
“I applied as a cheeky monkey, to find out if the competitions are prepared for AI images to enter. They are not,” he wrote. “We, the photo world, need an open discussion. A discussion about what we want to consider photography and what not. Is the umbrella of photography large enough to invite AI images to enter—or would this be a mistake? With my refusal of the award I hope to speed up this debate.”
NSO Group Exploited New Zero-Click Vulnerabilities in iOS
https://gizmodo.com/nso-group-exploited-new-zero-click-vulnerabilities-in-i-1850347936
Citizen Lab identified three new exploits that targeted iOS users worldwide in 2022. Apple’s Lockdown Mode reportedly worked as promised.