Author name: Kris Guyer

chatgpt-is-leaking-passwords-from-private-conversations-of-its-users,-ars-reader-says

ChatGPT is leaking passwords from private conversations of its users, Ars reader says

OPENAI SPRINGS A LEAK —

Names of unpublished research papers, presentations, and PHP scripts also leaked.

OpenAI logo displayed on a phone screen and ChatGPT website displayed on a laptop screen.

Getty Images

ChatGPT is leaking private conversations that include login credentials and other personal details of unrelated users, screenshots submitted by an Ars reader on Monday indicated.

Two of the seven screenshots the reader submitted stood out in particular. Both contained multiple pairs of usernames and passwords that appeared to be connected to a support system used by employees of a pharmacy prescription drug portal. An employee using the AI chatbot seemed to be troubleshooting problems that encountered while using the portal.

“Horrible, horrible, horrible”

“THIS is so f-ing insane, horrible, horrible, horrible, i cannot believe how poorly this was built in the first place, and the obstruction that is being put in front of me that prevents it from getting better,” the user wrote. “I would fire [redacted name of software] just for this absurdity if it was my choice. This is wrong.”

Besides the candid language and the credentials, the leaked conversation includes the name of the app the employee is troubleshooting and the store number where the problem occurred.

The entire conversation goes well beyond what’s shown in the redacted screenshot above. A link Ars reader Chase Whiteside included showed the chat conversation in its entirety. The URL disclosed additional credential pairs.

The results appeared Monday morning shortly after reader Whiteside had used ChatGPT for an unrelated query.

“I went to make a query (in this case, help coming up with clever names for colors in a palette) and when I returned to access moments later, I noticed the additional conversations,” Whiteside wrote in an email. “They weren’t there when I used ChatGPT just last night (I’m a pretty heavy user). No queries were made—they just appeared in my history, and most certainly aren’t from me (and I don’t think they’re from the same user either).”

Other conversations leaked to Whiteside include the name of a presentation someone was working on, details of an unpublished research proposal, and a script using the PHP programming language. The users for each leaked conversation appeared to be different and unrelated to each other. The conversation involving the prescription portal included the year 2020. Dates didn’t appear in the other conversations.

The episode, and others like it, underscore the wisdom of stripping out personal details from queries made to ChatGPT and other AI services whenever possible. Last March, ChatGPT maker OpenAI took the AI chatbot offline after a bug caused the site to show titles from one active user’s chat history to unrelated users.

In November, researchers published a paper reporting how they used queries to prompt ChatGPT into divulging email addresses, phone and fax numbers, physical addresses, and other private data that was included in material used to train the ChatGPT large language model.

Concerned about the possibility of proprietary or private data leakage, companies, including Apple, have restricted their employees’ use of ChatGPT and similar sites.

As mentioned in an article from December when multiple people found that Ubiquity’s UniFy devices broadcasted private video belonging to unrelated users, these sorts of experiences are as old as the Internet is. As explained in the article:

The precise root causes of this type of system error vary from incident to incident, but they often involve “middlebox” devices, which sit between the front- and back-end devices. To improve performance, middleboxes cache certain data, including the credentials of users who have recently logged in. When mismatches occur, credentials for one account can be mapped to a different account.

An OpenAI representative said the company was investigating the report.

ChatGPT is leaking passwords from private conversations of its users, Ars reader says Read More »

openai-and-common-sense-media-partner-to-protect-teens-from-ai-harms-and-misuse

OpenAI and Common Sense Media partner to protect teens from AI harms and misuse

Adventures in chatbusting —

Site gave ChatGPT 3 stars and 48% privacy score: “Best used for creativity, not facts.”

Boy in Living Room Wearing Robot Mask

On Monday, OpenAI announced a partnership with the nonprofit Common Sense Media to create AI guidelines and educational materials targeted at parents, educators, and teens. It includes the curation of family-friendly GPTs in OpenAI’s GPT store. The collaboration aims to address concerns about the impacts of AI on children and teenagers.

Known for its reviews of films and TV shows aimed at parents seeking appropriate media for their kids to watch, Common Sense Media recently branched out into AI and has been reviewing AI assistants on its site.

“AI isn’t going anywhere, so it’s important that we help kids understand how to use it responsibly,” Common Sense Media wrote on X. “That’s why we’ve partnered with @OpenAI to help teens and families safely harness the potential of AI.”

OpenAI CEO Sam Altman and Common Sense Media CEO James Steyer announced the partnership onstage in San Francisco at the Common Sense Summit for America’s Kids and Families, an event that was well-covered by media members on the social media site X.

For his part, Altman offered a canned statement in the press release, saying, “AI offers incredible benefits for families and teens, and our partnership with Common Sense will further strengthen our safety work, ensuring that families and teens can use our tools with confidence.”

The announcement feels slightly non-specific in the official news release, with Steyer offering, “Our guides and curation will be designed to educate families and educators about safe, responsible use of ChatGPT, so that we can collectively avoid any unintended consequences of this emerging technology.”

The partnership seems aimed mostly at bringing a patina of family-friendliness to OpenAI’s GPT store, with the most solid reveal being the aforementioned fact that Common Sense media will help with the “curation of family-friendly GPTs in the GPT Store based on Common Sense ratings and standards.”

Common Sense AI reviews

As mentioned above, Common Sense Media began reviewing AI assistants on its site late last year. This puts Common Sense Media in an interesting position with potential conflicts of interest regarding the new partnership with OpenAI. However, it doesn’t seem to be offering any favoritism to OpenAI so far.

For example, Common Sense Media’s review of ChatGPT calls the AI assistant “A powerful, at times risky chatbot for people 13+ that is best used for creativity, not facts.” It labels ChatGPT as being suitable for ages 13 and up (which is in OpenAI’s Terms of Service) and gives the OpenAI assistant three out of five stars. ChatGPT also scores a 48 percent privacy rating (which is oddly shown as 55 percent on another page that goes into privacy details). The review we cited was last updated on October 13, 2023, as of this writing.

For reference, Google Bard gets a three-star overall rating and a 75 percent privacy rating in its Common Sense Media review. Stable Diffusion, the image synthesis model, nets a one-star rating with the description, “Powerful image generator can unleash creativity, but is wildly unsafe and perpetuates harm.” OpenAI’s DALL-E gets two stars and a 48 percent privacy rating.

The information that Common Sense Media includes about each AI model appears relatively accurate and detailed (and the organization cited an Ars Technica article as a reference in one explanation), so they feel fair, even in the face of the OpenAI partnership. Given the low scores, it seems that most AI models aren’t off to a great start, but that may change. It’s still early days in generative AI.

OpenAI and Common Sense Media partner to protect teens from AI harms and misuse Read More »

beware-of-scammers-sending-live-couriers-to-liquidate-victims’-life-savings

Beware of scammers sending live couriers to liquidate victims’ life savings

CONFIDENCE GAMES —

The scams sound easy to detect, but they steal billions of dollars, often from the elderly.

Beware of scammers sending live couriers to liquidate victims’ life savings

Getty Images

Scammers are stepping up their game by sending couriers to the homes of elderly people and others as part of a ruse intended to rob them of their life savings, the FBI said in an advisory Monday.

“The FBI is warning the public about scammers instructing victims, many of whom are senior citizens, to liquidate their assets into cash and/or buy gold, silver, or other precious metals to protect their funds,” FBI officials with the agency’s Internet Crime Complaint Center said. “Criminals then arrange for couriers to meet the victims in person to pick up the cash or precious metals.”

The scammers pose as tech or customer support agents or government officials and sometimes use a multi-layered approach as they falsely claim they work on behalf of technology companies, financial institutions, or the US government. The scammers tell the targets they have been hacked or are at risk of being hacked and that their assets should be protected. The scammers then instruct the targets to liquidate assets into cash. In some cases, the scammers instruct targets to wire funds to a fake metal dealer who will ship purchased merchandise to the victims’ homes.

“Criminals then arrange for couriers to meet the victims in person to pick up the cash or precious metals,” Monday’s advisory warned.

Officials said that from May to December of last year, they tracked estimated aggregate losses topping $55 million from this sort of scam. More generally, the agency received 19,000 complaints of scams from January to June of 2023, with estimated victim losses of $542 million. Almost half of the victims were over 60 years old and accounted for 66 percent of the aggregated losses.

The types of scams included in Monday’s warning use tactics intended to coax the victim into developing trust and confidence in the perpetrators. The scammers promise to safeguard the assets in a protected account. In some cases, the scammers set a passcode with the target. If targets hand over money or other assets, they never hear from the scammers again.

Monday’s advisory comes four months after IC3 warned of an increase in complaints for what the agency calls “phantom hacker scams. This form of scam is an evolution of more traditional general tech ruses. They layer imposer tech support workers with workers from financial institutions and government agencies. Victims sometimes lose their entire holdings in bank, savings, retirement, or investment accounts.

Typically, the target receives a call from someone falsely claiming to work in tech or customer support from a known, reputable company and instructs the target to call a number for assistance resolving an imaginary problem. When a target calls, the scammer tricks the person into downloading and installing a program that gives remote access to the target’s device. The scammer then asks the target to open bank accounts or other types of accounts to investigate imaginary fraud. During this step, the scammer checks balances to see if there’s enough profit potential for follow-on activities.

In any follow-on activity, the scammers pose as either representatives of the financial institution or as an employee at the Federal Reserve or another US government agency. The scammers instruct the targets to wire money, in many cases directly to overseas recipients. The scammers may instruct the victim to send multiple transactions over a span of days or months. In the event the target grows suspicious, the scammers may send written correspondence over what appears to be official letterhead.

FBI IC3

The IC3 recommends people follow these practices to prevent falling victim to such scams:

  • The US Government and legitimate businesses will never request you purchase gold or other precious metals.
  • Protect your personal information. Never disclose your home address or agree to meet with unknown individuals to deliver cash or precious metals.
  • Do not click on unsolicited pop-ups on your computer, links sent via text messages, or email links and attachments.
  • Do not contact unknown telephone numbers provided in pop-ups, texts, or emails.
  • Do not download software at the request of unknown individuals who contact you.
  • Do not allow unknown individuals access to your computer.

The FBI requests victims report these types of fraud or suspicious activities to the IC3 as soon as possible. Victims should include as much transaction information as possible:

  • The name of the person or company that contacted you.
  • Methods of communication used, including websites, emails, and telephone numbers.
  • Any bank account number that received any wired funds, along with the recipient name(s).
  • The name and location of any metal dealer companies and the account that received the wired funds.

Beware of scammers sending live couriers to liquidate victims’ life savings Read More »

apple-warns-proposed-uk-law-will-affect-software-updates-around-the-world

Apple warns proposed UK law will affect software updates around the world

Heads up —

Apple may leave the UK if required to provide advance notice of product updates.

Apple warns proposed UK law will affect software updates around the world

Apple is “deeply concerned” that proposed changes to a United Kingdom law could give the UK government unprecedented power to “secretly veto” privacy and security updates to its products and services, the tech giant said in a statement provided to Ars.

If passed, potentially this spring, the amendments to the UK’s Investigatory Powers Act (IPA) could deprive not just UK users, but all users globally of important new privacy and security features, Apple warned.

“Protecting our users’ privacy and the security of their data is at the very heart of everything we do at Apple,” Apple said. “We’re deeply concerned the proposed amendments” to the IPA “now before Parliament place users’ privacy and security at risk.”

The IPA was initially passed in 2016 to ensure that UK officials had lawful access to user data to investigate crimes like child sexual exploitation or terrorism. Proposed amendments were announced last November, after a review showed that the “Act has not been immune to changes in technology over the last six years” and “there is a risk that some of these technological changes have had a negative effect on law enforcement and intelligence services’ capabilities.”

The proposed amendments require that any company that fields government data requests must notify UK officials of any updates they planned to make that could restrict the UK government’s access to this data, including any updates impacting users outside the UK.

UK officials said that this would “help the UK anticipate the risk to public safety posed by the rolling out of technology by multinational companies that precludes lawful access to data. This will reduce the risk of the most serious offenses such as child sexual exploitation and abuse or terrorism going undetected.”

According to the BBC, the House of Lords will begin debating the proposed changes on Tuesday.

Ahead of that debate, Apple described the amendments on Monday as “an unprecedented overreach by the government” that “if enacted” could allow the UK to “attempt to secretly veto new user protections globally, preventing us from ever offering them to customers.”

In a letter last year, Apple argued that “it would be improper for the Home Office to act as the world’s regulator of security technology.”

Apple told the UK Home Office that imposing “secret requirements on providers located in other countries” that apply to users globally “could be used to force a company like Apple, that would never build a backdoor, to publicly withdraw critical security features from the UK market, depriving UK users of these protections.” It could also “dramatically disrupt the global market for security technologies, putting users in the UK and around the world at greater risk,” Apple claimed.

The proposed changes, Apple said, “would suppress innovation, stifle commerce, and—when combined with purported extraterritorial application—make the Home Office the de facto global arbiter of what level of data security and encryption are permissible.”

UK defends proposed changes

The UK Home Office has repeatedly stressed that these changes do not “provide powers for the Secretary of State to approve or refuse technical changes,” but “simply” requires companies “to inform the Secretary of State of relevant changes before those changes are implemented.”

“The intention is not to introduce a consent or veto mechanism or any other kind of barrier to market,” a UK Home Office fact sheet said. “A key driver for this amendment is to give operational partners time to understand the change and adapt their investigative techniques where necessary, which may in some circumstances be all that is required to maintain lawful access.”

The Home Office has also claimed that “these changes do not directly relate to end-to-end encryption,” while admitting that they “are designed to ensure that companies are not able to unilaterally make design changes which compromise exceptional lawful access where the stringent safeguards of the IPA regime are met.”

This seems to suggest that companies will not be allowed to cut off the UK government from accessing encrypted data under certain circumstances, which concerns privacy advocates who consider end-to-end encryption a vital user privacy and security protection. Earlier this month, civil liberties groups including Big Brother Watch, Liberty, Open Rights Group and Privacy International filed a joint brief opposing the proposed changes, the BBC reported, warning that passing the amendments would be “effectively transforming private companies into arms of the surveillance state and eroding the security of devices and the Internet.”

“We have always been clear that we support technological innovation and private and secure communications technologies, including end-to-end encryption, but this cannot come at a cost to public safety,” a UK government official told the BBC.

The UK government may face more opposition to the amendments than from tech companies and privacy advocates, though. In Apple’s letter last year, the tech giant noted that the proposed changes to the IPA could conflict with EU and US laws, including the EU’s General Data Protection Regulation—considered the world’s strongest privacy law.

Under the GDPR, companies must implement measures to safeguard users’ personal data, Apple said, noting that “encryption is one means by which a company can meet” that obligation.

“Secretly installing backdoors in end-to-end encrypted technologies in order to comply with UK law for persons not subject to any lawful process would violate that obligation,” Apple argued.

Apple warns proposed UK law will affect software updates around the world Read More »

after-32-years,-one-of-the-’net’s-oldest-software-archives-is-shutting-down

After 32 years, one of the ’Net’s oldest software archives is shutting down

Ancient server dept. —

Hobbes OS/2 Archive: “As of April 15th, 2024, this site will no longer exist.”

Box art for IBM OS/2 Warp version 3, an OS released in 1995 that competed with Windows.

Enlarge / Box art for IBM OS/2 Warp version 3, an OS released in 1995 that competed with Windows.

IBM

In a move that marks the end of an era, New Mexico State University (NMSU) recently announced the impending closure of its Hobbes OS/2 Archive on April 15, 2024. For over three decades, the archive has been a key resource for users of the IBM OS/2 operating system and its successors, which once competed fiercely with Microsoft Windows.

In a statement made to The Register, a representative of NMSU wrote, “We have made the difficult decision to no longer host these files on hobbes.nmsu.edu. Although I am unable to go into specifics, we had to evaluate our priorities and had to make the difficult decision to discontinue the service.”

Hobbes is hosted by the Department of Information & Communication Technologies at New Mexico State University in Las Cruces, New Mexico. In the official announcement, the site reads, “After many years of service, hobbes.nmsu.edu will be decommissioned and will no longer be available. As of April 15th, 2024, this site will no longer exist.”

OS/2 version 1.2, released in late 1989.

OS/2 version 1.2, released in late 1989.

os2museum.com

We reached out to New Mexico State University to inquire about the history of the Hobbes archive but did not receive a response. The earliest record we’ve found of the Hobbes archive online is this 1992 Walnut Creek CD-ROM collection that gathered up the contents of the archive for offline distribution. At around 32 years old, minimum, that makes Hobbes one of the oldest software archives on the Internet, akin to the University of Michigan’s archives and ibiblio at UNC.

Archivists such as Jason Scott of the Internet Archive have stepped up to say that the files hosted on Hobbes are safe and already mirrored elsewhere. “Nobody should worry about Hobbes, I’ve got Hobbes handled,” wrote Scott on Mastodon in early January. OS/2 World.com also published a statement about making a mirror. But it’s still notable whenever such an old and important piece of Internet history bites the dust.

Like many archives, Hobbes started as an FTP site. “The primary distribution of files on the Internet were via FTP servers,” Scott tells Ars Technica. “And as FTP servers went down, they would also be mirrored as subdirectories in other FTP servers. Companies like CDROM.COM / Walnut Creek became ways to just get a CD-ROM of the items, but they would often make the data available at http://ftp.cdrom.com to download.”

The Hobbes site is a priceless digital time capsule. You can still find the Top 50 Downloads page, which includes sound and image editors, and OS/2 builds of the Thunderbird email client. The archive contains thousands of OS/2 games, applications, utilities, software development tools, documentation, and server software dating back to the launch of OS/2 in 1987. There’s a certain charm in running across OS/2 wallpapers from 1990, and even the archive’s Update Policy is a historical gem—last updated on March 12, 1999.

The legacy of OS/2

The final major IBM release of OS/2, Warp version 4.0, as seen running in an emulator.

Enlarge / The final major IBM release of OS/2, Warp version 4.0, as seen running in an emulator.

OS/2 began as a joint venture between IBM and Microsoft, undertaken as a planned replacement for IBM PC DOS (also called “MS-DOS” in the form sold by Microsoft for PC clones). Despite advanced capabilities like 32-bit processing and multitasking, OS/2 later competed with and struggled to gain traction against Windows. The partnership between IBM and Microsoft dissolved after the success of Windows 3.0, leading to divergent paths in OS strategies for the two companies.

Through iterations like the Warp series, OS/2 established a key presence in niche markets that required high stability, such as ATMs and the New York subway system. Today, its legacy continues in specialized applications and in newer versions (like eComStation) maintained by third-party vendors—despite being overshadowed in the broader market by Linux and Windows.

A footprint like that is worth preserving, and a loss of one of OS/2’s primary archives, even if mirrored elsewhere, is a cultural blow. Apparently, Hobbes has reportedly almost disappeared before but received a stay of execution. In the comments section for an article on The Register, someone named “TrevorH” wrote, “This is not the first time that Hobbes has announced it’s going away. Last time it was rescued after a lot of complaints and a number of students or faculty came forward to continue to maintain it.”

As the final shutdown approaches in April, the legacy of Hobbes is a reminder of the importance of preserving the digital heritage of software for future generations—so that decades from now, historians can look back and see how things got to where they are today.

After 32 years, one of the ’Net’s oldest software archives is shutting down Read More »

ryzen-8000g-review:-an-integrated-gpu-that-can-beat-a-graphics-card,-for-a-price

Ryzen 8000G review: An integrated GPU that can beat a graphics card, for a price

The most interesting thing about AMD's Ryzen 7 8700G CPU is the Radeon 780M GPU that's attached to it.

Enlarge / The most interesting thing about AMD’s Ryzen 7 8700G CPU is the Radeon 780M GPU that’s attached to it.

Andrew Cunningham

Put me on the short list of people who can get excited about the humble, much-derided integrated GPU.

Yes, most of them are afterthoughts, designed for office desktops and laptops that will spend most of their lives rendering 2D images to a single monitor. But when integrated graphics push forward, it can open up possibilities for people who want to play games but can only afford a cheap desktop (or who have to make do with whatever their parents will pay for, which was the big limiter on my PC gaming experience as a kid).

That, plus an unrelated but accordant interest in building small mini-ITX-based desktops, has kept me interested in AMD’s G-series Ryzen desktop chips (which it sometimes calls “APUs,” to distinguish them from the Ryzen CPUs). And the Ryzen 8000G chips are a big upgrade from the 5000G series that immediately preceded them (this makes sense, because as we all know the number 8 immediately follows the number 5).

We’re jumping up an entire processor socket, one CPU architecture, three GPU architectures, and up to a new generation of much faster memory; especially for graphics, it’s a pretty dramatic leap. It’s an integrated GPU that can credibly beat the lowest tier of currently available graphics cards, replacing a $100–$200 part with something a lot more energy-efficient.

As with so many current-gen Ryzen chips, still-elevated pricing for the socket AM5 platform and the DDR5 memory it requires limit the 8000G series’ appeal, at least for now.

From laptop to desktop

AMD's first Ryzen 8000 desktop processors are what the company used to call

Enlarge / AMD’s first Ryzen 8000 desktop processors are what the company used to call “APUs,” a combination of a fast integrated GPU and a reasonably capable CPU.

AMD

The 8000G chips use the same Zen 4 CPU architecture as the Ryzen 7000 desktop chips, but the way the rest of the chip is put together is pretty different. Like past APUs, these are actually laptop silicon (in this case, the Ryzen 7040/8040 series, codenamed Phoenix and Phoenix 2) repackaged for a desktop processor socket.

Generally, the real-world impact of this is pretty mild; in most ways, the 8700G and 8600G will perform a lot like any other Zen 4 CPU with the same number of cores (our benchmarks mostly bear this out). But to the extent that there is a difference, the Phoenix silicon will consistently perform just a little worse, because it has half as much L3 cache. AMD’s Ryzen X3D chips revolve around the performance benefits of tons of cache, so you can see why having less would be detrimental.

The other missing feature from the Ryzen 7000 desktop chips is PCI Express 5.0 support—Ryzen 8000G tops out at PCIe 4.0. This might, maybe, one day in the distant future, eventually lead to some kind of user-observable performance difference. Some recent GPUs use an 8-lane PCIe 4.0 interface instead of the typical 16 lanes, which limits performance slightly. But PCIe 5.0 SSDs remain rare (and PCIe 4.0 peripherals remain extremely fast), so it probably shouldn’t top your list of concerns.

The Ryzen 5 8500G is a lot different from the 8700G and 8600G, since some of the CPU cores in the Phoenix 2 chips are based on Zen 4c rather than Zen 4. These cores have all the same capabilities as regular Zen 4 ones—unlike Intel’s E-cores—but they’re optimized to take up less space rather than hit high clock speeds. They were initially made for servers, where cramming lots of cores into a small amount of space is more important than having a smaller number of faster cores, but AMD is also using them to make some of its low-end consumer chips physically smaller and presumably cheaper to produce. AMD didn’t send us a Ryzen 8500G for review, so we can’t see exactly how Phoenix 2 stacks up in a desktop.

The 8700G and 8600G chips are also the only ones that come with AMD’s “Ryzen AI” feature, the brand AMD is using to refer to processors with a neural processing unit (NPU) included. Sort of like GPUs or video encoding/decoding blocks, these are additional bits built into the chip that handle things that CPUs can’t do very efficiently—in this case, machine learning and AI workloads.

Most PCs still don’t have NPUs, and as such they are only barely used in current versions of Windows (Windows 11 offers some webcam effects that will take advantage of NPU acceleration, but for now that’s mostly it). But expect this to change as they become more common and as more AI-accelerated text, image, and video creating and editing capabilities are built into modern operating systems.

The last major difference is the GPU. Ryzen 7000 includes a pair of RDNA2 compute units that perform more or less like Intel’s desktop integrated graphics: good enough to render your desktop on a monitor or two, but not much else. The Ryzen 8000G chips include up to 12 RDNA3 CUs, which—as we’ve already seen in laptops and portable gaming systems like the Asus ROG Ally that use the same silicon—is enough to run most games, if just barely in some cases.

That gives AMD’s desktop APUs a unique niche. You can use them in cases where you can’t afford a dedicated GPU—for a time during the big graphics card shortage in 2020 and 2021, a Ryzen 5700G was actually one of the only ways to build a budget gaming PC. Or you can use them in cases where a dedicated GPU won’t fit, like super-small mini ITX-based desktops.

The main argument that AMD makes is the affordability one, comparing the price of a Ryzen 8700G to the price of an Intel Core i5-13400F and a GeForce GTX 1650 GPU (this card is nearly five years old, but it remains Nvidia’s newest and best GPU available for less than $200).

Let’s check on performance first, and then we’ll revisit pricing.

Ryzen 8000G review: An integrated GPU that can beat a graphics card, for a price Read More »

blockbuster-weight-loss-drugs-slashed-from-nc-state-plan-over-ballooning-costs

Blockbuster weight-loss drugs slashed from NC state plan over ballooning costs

Patients vs. profits —

The plan spent $102M on the weight-loss drugs last year, 10% of total drug costs.

Wegovy is an injectable prescription weight loss medicine that has helped people with obesity.

Enlarge / Wegovy is an injectable prescription weight loss medicine that has helped people with obesity.

The health plan for North Carolina state employees will stop covering blockbuster GLP-1 weight-loss drugs, including Wegovy and Zepbound, because—according to the plan’s board of trustees—the drugs are simply too expensive.

Last week, the board voted 4-3 to end all coverage of GLP-1 medications for weight loss on April 1. If the coverage is dropped, it is believed to be the first major state health plan to end coverage of the popular but pricey weight-loss drugs. The plan will continue to pay for GLP-1 medications prescribed to treat diabetes, including Ozempic.

The North Carolina State Health Plan covers nearly 740,000 people, including teachers, state employees, retirees, and their family members. In 2023, monthly premiums from the plan ranged from $25 for base coverage for an individual to up to $720 for premium family coverage. Members prescribed Wegovy paid a co-pay of between $30 and $50 per month for the drug, while the plan’s cost was around $800 a month.

In 2021, just under 2,800 members were taking the drugs for weight loss, but in 2023, the number soared to nearly 25,000 members, costing the plan $102 million. That’s about 10 percent of what the plan pays for all prescription drugs combined. If the current coverage continued, the plan’s pharmacy benefit manager, CVS Caremark, estimated that by 2025, the plan’s premiums would have to rise $48.50 across the board to offset the costs of the weight-loss drugs.

Without insurance, the list price of Wegovy is $1,349 per month, totaling $16,188 for a year of treatment. The average reported salary for members of North Carolina’s health plan is $56,431.

Last October, the board voted to grandfather the 25,000 or so current users, maintaining coverage for them moving forward, but then to stop offering new coverage to members. However, according to CVS Caremark, the move would mean losing a 40 percent rebate from Wegovy’s maker, Novo Nordisk. This would be a loss of $54 million, bringing projected 2024 costs to $139 million.

A spokesperson for Novo Nordisk called the vote to end coverage entirely “irresponsible,” according to a statement given to media. “We do not support insurers or bureaucrats inserting their judgment in these medically driven decisions,” the statement continued.

While the costs of weight-loss drugs are high everywhere, the pricing is particularly bitter for North Carolinians—Novo Nordisk manufactures Wegovy in Clayton, North Carolina, southeast of Raleigh.

“It certainly adds insult to injury,” Ardis Watkins, executive director of the State Employees Association of North Carolina, a group that lobbies on behalf of state health plan members, according to The New York Times. “Our economic climate that has been made so attractive to businesses to locate here is being used to manufacture a drug that is wildly marked up.”

While it appears to be the first time such a large state health plan has dropped coverage of the weight-loss drugs, North Carolina is not alone in wrestling with the costs. The University of Texas’ employee plan ceased coverage of Wegovy and Saxenda, another weight-loss drug, in September. Connecticut’s state health plan, meanwhile, added restrictions on how members could get a prescription covered. Some state health plans that cover GLP-1 medications for weight-loss have prior authorization procedures to try to limit use.

“Every state has been wrestling with it, every professional association that my staff is a part of has had some discussion about it,” Sam Watts, director of the North Carolina State Health Plan, told Bloomberg. “But to our knowledge, we’re the first major state health plan to act on it.”

Blockbuster weight-loss drugs slashed from NC state plan over ballooning costs Read More »

report:-deus-ex-title-killed-after-embracer-group’s-cuts-at-eidos

Report: Deus Ex title killed after Embracer Group’s cuts at Eidos

Not the ending most people would have chosen —

Swedish firm’s acquisitions continue trend of layoffs and canceled games.

Adam Jensen of Deus Ex: Mankind Divided, having coffee on the couch in diffuse sunlight

Enlarge / Adam Jensen of Deus Ex: Mankind Divided, taking in the news that no last-minute contrivance is going to save his series from what seemed like inevitable doom. (Pun credit to Andrew Cunningham).

Eidos Interactive

Embracer Group, the Swedish firm that bought up a number of known talents and gaming properties during the pandemic years, has canceled a Deus Ex game at its Eidos studio in Montreal, Canada, according to Bloomberg’s Jason Schreier.

The game, while not officially announced, has been known about since May 2022. It was due to enter production later in 2024 and had seen two years of pre-production development, according to Schreier’s sources. Many employees will be laid off as part of the cancellation.

Embracer Group acquired Eidos Montreal, along with Crystal Dynamics and Square Enix Montreal, for $300 million in mid-2022, buying up all of Japanese game publisher Square Enix’s Western game studios. That gave Embracer the keys to several influential and popular series, including Tomb RaiderJust CauseLife Is Strange, and Deus Ex.

Eidos published the first Deus Ex from developer Ion Storm, founded by id Software’s John Romero and Tom Hall. Gaming legend Warren Spector oversaw the development of the original Deus Ex, merging shooters, stealth, and open-world RPG game mechanics in a way that, for the year 2000, was wholly original. The game is often cited as one of the best PC games of all time and a progenitor of many immersive sims and RPG-inflected shooters to come.

Eidos Interactive was acquired in 2009 by Square Enix and became the primary developer of the Deus Ex series, starting with Deus Ex: Human Revolution in 2011. The last full-fledged title in the series was Deus Ex: Mankind Divided in 2016. Despite selling more than 14 million units across the series’ lifetime, and the perennial hunger by fans and critics to see a return to the series’ novel storytelling and sharp critique of mega-corp control, the reset button has been hit by a rather large corporation.

Another of Embracer Group’s notable acquisitions, the 2021 purchase of large independent developer Gearbox, looks to be unwinding, as well. Bloomberg’s Schreier reported in September 2023 that Embracer was looking to sell Gearbox after less than three years’ ownership. One month before that, Embracer Group shut down Volition, developer of Saints Row and Descent, after that studio’s 30th year of operation.

Ars has reached out to Embracer Group for comment and will update this post with any new information.

Most of the primary Deus Ex titles are on sale at the moment, at GOG and on Steam, for less than $5.

Listing image by Eidos Interactive

Report: Deus Ex title killed after Embracer Group’s cuts at Eidos Read More »

wear-os’s-most-consistent-oem-quits:-fossil-stops-making-smartwatches

Wear OS’s most consistent OEM quits: Fossil stops making smartwatches

The Samsung impactor is still visible from space —

Despite years of loyalty, Google dropped Fossil like a rock once Samsung came back.

The Fossil Gen 6 smartwatch.

Enlarge / The Fossil Gen 6 smartwatch.

Fossil

Fossil was the only brand keeping Google’s Wear OS alive for years, but now the fashion brand is quitting the smartwatch market. Just before the weekend, the company confirmed to The Verge: “We have made the strategic decision to exit the smartwatch business.” The company says existing smartwatches will continue to get software updates “for the next few years” while it refocuses on traditional watches and jewelry.

Wear OS is out of the dark ages now, but for years Fossil was the OS’s only lifeline. Back in the days when Qualcomm was strangling the OS with lackluster SoC updates, Fossil was the only company that kept the dream alive. Fossil jumped into the Android Wear/Wear OS market in 2015 and has been the only steady source of Android smartwatch hardware since then. All the big companies like Samsung, LG, Sony, Huawei, Motorola, and Asus made watches for only a year or two and quit.

In 2021, despite years of loyalty, Google dropped Fossil like a rock when Samsung offered to come back to the Wear OS ecosystem. Google lured Samsung away from its in-house Tizen OS with preferential treatment, including exclusive rights to the new “Wear OS 3” release and exclusive apps. That year, 2021, featured head-to-head August Wear OS releases of Samsung’s Galaxy Watch 4 and Fossil’s Gen 6 smartwatch. Samsung’s watch had a faster, Samsung-made SoC, ran Wear OS 3, and cost $250, while Fossil was stuck with Wear OS 2, a slower Qualcomm chip, and a $300 price tag. Fossil would barely be able to compete with Samsung if the playing field were level; but add to that Samsung’s exclusive chips and Google’s preferential treatment, and Fossil’s watches never stood a chance. The Gen 6 will be the company’s last smartwatch release.

Those years of releases for Fossil never resulted in huge sales. The IDC’s VP of Data & Analytics, Francisco Jeronimo, revealed that Fossil peaked at 6.7 percent smartwatch market share in 2015 and only sold 19 million units, or 2.2 percent of the total market from 2015-2023. During that eight-year run, Jeronimo says Apple shipped 248 million watches.

Wear OS’s most consistent OEM quits: Fossil stops making smartwatches Read More »

masters-of-the-air:-imagine-a-bunch-of-people-throwing-up,-including-me

Masters of the Air: Imagine a bunch of people throwing up, including me

Masters of People Vomiting Everywhere —

It’s a bad show. I wanted to love it, but it’s just not good.

Photograph showing two stars of the show standing in front of a B-17

Enlarge / Our two main heroes so far, Buck and Bucky. Or possibly Bucky and Buck. I forget which is which.

I’m writing this article under duress because it’s not going to create anything new or try to make the world a better place—instead, I’m going to do the thing where a critic tears down the work of others rather than offering up their own creation to balance the scales. So here we go: I didn’t like the first two episodes of Masters of the Air, and I don’t think I’ll be back for episode three.

The feeling that the show might not turn out to be what I was hoping for has been growing in my dark heart since catching the first trailer a month or so ago—it looked both distressingly digital and also maunderingly maudlin, with Austin Butler’s color-graded babyface peering out through a hazy, desaturated cloud of cigarette smoke and 1940s World War II pilot tropes. Unfortunately, the show at release made me feel exactly how I feared it might—rather than recapturing the magic of Band of Brothers or the horror of The Pacific, Masters so far has the depth and maturity of a Call of Duty cutscene.

Does this man look old enough to be allowed to fly that plane?

Enlarge / Does this man look old enough to be allowed to fly that plane?

Apple

World War Blech

After two episodes, I feel I’ve seen everything Masters has to offer: a dead-serious window into the world of B-17 Flying Fortress pilots, wholly lacking any irony or sense of self-awareness. There’s no winking and nodding to the audience, no joking around, no historic interviews with salt-and-pepper veterans to humanize the cast. The only thing allowed here is wall-to-wall jingoistic patriotism—the kind where there’s no room for anything except God, the United States of America, and bombing the crap out of the enemy. And pining wistfully for that special girl waiting at home.

Butler clearly gives a solid performance, but the man’s face is too perfect, like an Army Air Corps recruiting poster, with his tall hair and his cap parked jauntily at an angle atop it. He’s pretty to the point of being a distraction in every single scene he’s in. He noted in interviews that he signed up to work with a dialect coach to drop the Elvis accent he picked up while filming with Baz Luhrmann, and being notionally a cowboy from Casper, Wyoming, he wears his character’s “well, aw, shucks” down-home attitude as comfortably as the silk aviator’s scarf around his neck. But at least to this native Texan’s ear, there’s still a lot of Memphis coming out of the man’s mouth.

Every member of the cast has their 1940s-ness dialed up to 11—and perhaps that’s appropriate, given that World War II ended 80 years ago and “World War II” is fully a period aesthetic at this point, with its own rules and visuals any audience will expect to see. But the show wastes no opportunity to ram home that ’40s feeling—every room is dimly lit, and every Allied office feels like a ramshackle clapboard mess. Each scene’s framing feels like it was carefully assembled from comic book clippings, with barely disguised CGI trickery to keep everything hanging together. Watching in 4K HDR was beautiful, but it also made me cringe repeatedly whenever a VFX shot with bad tracking or bad color matching would flash past. There’s just nowhere to hide the digital-ness of it all, and boy, does it ever shine through. The overall effect is less like Saving Private Ryan and more like Sucker Punch—with a bit of Sky Captain and the World of Tomorrow thrown in.

Masters of the Air: Imagine a bunch of people throwing up, including me Read More »

gotta-go?-we’ve-finally-found-out-what-makes-urine-yellow

Gotta go? We’ve finally found out what makes urine yellow

It isn’t from eating corn —

The yellow color comes from bacteria metabolizing waste from red blood cells.

Image of a series of scientific sample tubes filled with yellow liquids.

There are many mysteries in life that we end up shrugging off. Why is urine yellow? It just is, right? Rather than flush that 125-year-old question down the toilet, scientists sought out the answer, discovering a previously unknown microbial enzyme was to blame.

The enzyme that has eluded us for so long is now known as bilirubin reductase. It was identified by researcher and assistant professor Brantley Hall of the University of Maryland, who was part of a team based at the university and the National Institutes of Health.

Bilirubin is an orange pigment released by red blood cells after they die. Gut microbes then use bilirubin reductase to break down bilirubin into colorless urobilinogen, which degrades into yellowish urobilin, giving urine that infamous hue. While urobilin previously had an association with the color of urine, the enzyme that starts the process by producing urobilinogen was unknown until now.

“Though it was previously thought that multiple enzymes were involved in the reduction of bilirubin, our results support the finding that a single enzyme performs the reduction of bilirubin to urobilinogen,” the research team said in a study recently published in Nature Microbiology.

Gut feeling

Because some gut bacteria had been known to reduce bilirubin, Hall and his team knew where to start but wanted to fill in the unknowns by finding out which particular species actually do this—and how. This meant they had to find the gene responsible for encoding bilirubin reductase.

Previous studies had found that the species Clostridiodes difficile was capable of reducing bilirubin (though the mechanism it used was unknown). Using C. difficile as a basis for comparison, the team cultured different species of gut bacteria and exposed them to bilirubin to see whether that bacteria could produce urobilinogen, detecting its presence using a fluorescence assay.

The fluorescence assay told Hall and his colleagues that there were nine strains within the tested species that they thought were capable of reducing bilirubin, although how these bacteria were breaking it down was still unclear.  After the fluorescence assay, the genomes of the most closely related strains were analyzed,  and several turned out to share a gene that encoded an enzyme that could reduce bilirubin—bilirubin reductase.

Bacterial strains that metabolized bilirubin using bilirubin reductase all came from species that were found to belong to a single clade (the researchers informally referred to it as the bilirubin reductase clade). Within that clade, most of these species are from the class Clostridia in the phylum Firmicutes, a phylum of bacteria important to gut health.

More than … you know

The discovery of bilirubin reductase goes beyond the origin of urine color. After identifying the enzyme, the researchers found out that, while bilirubin reductase is present in healthy adults, there is a deficit in newborns and adults with inflammatory bowel disease, which could eventually influence future treatments

By sequencing infant gut genomes, Hall and his team saw that bilirubin reductase was often missing during the first few months of life. Too much bilirubin building up in the blood turns the skin and the whites of the eyes yellow, a symptom known as jaundice. Most infants have some level of jaundice, but it usually goes away on its own.

The absence of bilirubin reductase is also associated with pigmented gallstones in adults with inflammatory bowel disease (inflammatory bowel disease or IBD is a general term that can refer to several different diagnoses). Sequencing adult gut genomes showed that there was a deficit of this enzyme in most patients with Crohn’s disease or ulcerative colitis whose gut genomes were sequenced.

“With the knowledge of the species, genes, and enzymes involved in bilirubin reduction, future research can now focus on the extent to which gut microbial bilirubin metabolism affects…the role of bilirubin reduction in health and disease,” the researchers said in the same study.

There is still more research to be done on bilirubin reductase and the health implications it could have. The team thinks there may be a link between the amount of urobilin produced in the body and insulin resistance, obesity, heart disease, and even heart failure. Next to that, we finally know why urine is yellow.

Nature Microbiology, 2023. DOI: 10.1038/s41564-023-01549-x

Gotta go? We’ve finally found out what makes urine yellow Read More »

air-pollution-from-canada’s-tar-sands-is-much-worse-than-we-thought

Air pollution from Canada’s tar sands is much worse than we thought

Aerial Views Of Oil Sands Operations

Enlarge / Aerial view of the Athabasca oil sands near Fort McMurray, Alberta, Canada.

Canada’s tar sands have gained infamy for being one of the world’s most polluting sources of oil, thanks to the large amounts of energy and water use required for their extraction. A new study says the operations are also emitting far higher levels of a range of air pollutants than previously known, with implications for communities living nearby and far downwind.

The research, published Thursday in Science, took direct measurements of organic carbon emissions from aircraft flying above the tar sands, also called oil sands, and found levels that were 20 to 64 times higher than what companies were reporting. Total organic carbon includes a wide range of compounds, some of which can contribute directly to hazardous air pollution locally and others that can react in the atmosphere to form small particulate matter, or PM 2.5, a dangerous pollutant that can travel long distances and lodge deep in the lungs.

The study found that tar sands operations were releasing as much of these pollutants as all other human-made sources in Canada combined. For certain classes of heavy organic compounds, which are more likely to form particulates downwind, the concentrations were higher than what’s generally found in large metropolises like Los Angeles.

“The absolute magnitude of those emissions were a lot higher than what we expected,” said John Liggio, a research scientist at Environment and Climate Change Canada, the nation’s environmental regulatory agency, and a co-author on the study. Researchers at Yale University also contributed.

Seth Shonkoff, executive director of PSE Healthy Energy, an independent scientific research institute in California, who was not involved in the study, said the findings suggest air pollution from tar sands operations is more damaging to people’s health than previously known.

“I actually could hardly believe what I was reading,” Shonkoff said of the new study.

Over the last decade, a growing body of research has examined emissions of different air pollutants from oil and gas operations across the United States and Canada, and much of that has shown that industry estimates tend to undercount what’s being released, he said. “But the scale of this discrepancy is very surprising.”

Mark Cameron, vice president of external relations at the Pathways Alliance, an oil sands industry group, said in an email that the findings warrant further review and that “the oil sands industry measures emissions using standards set by Environment and Climate Change Canada and we look forward to working together to explore opportunities to further enhance our measurement practices.”

Air pollution from Canada’s tar sands is much worse than we thought Read More »