Author name: Mike M.

from-recycling-to-food:-can-we-eat-plastic-munching-microbes?

From recycling to food: Can we eat plastic-munching microbes?

breaking it down —

Researchers are trying to turn plastic-eating bacteria into food source for humans.

From recycling to food: Can we eat plastic-munching microbes?

Olga Pankova/Moment via Getty Images

In 2019, an agency within the US Department of Defense released a call for research projects to help the military deal with the copious amount of plastic waste generated when troops are sent to work in remote locations or disaster zones. The agency wanted a system that could convert food wrappers and water bottles, among other things, into usable products, such as fuel and rations. The system needed to be small enough to fit in a Humvee and capable of running on little energy. It also needed to harness the power of plastic-eating microbes.

“When we started this project four years ago, the ideas were there. And in theory, it made sense,” said Stephen Techtmann, a microbiologist at Michigan Technological University, who leads one of the three research groups receiving funding. Nevertheless, he said, in the beginning, the effort “felt a lot more science-fiction than really something that would work.”

That uncertainty was key. The Defense Advanced Research Projects Agency, or DARPA, supports high-risk, high-reward projects. This means there’s a good chance that any individual effort will end in failure. But when a project does succeed, it has the potential to be a true scientific breakthrough. “Our goal is to go from disbelief, like, ‘You’re kidding me. You want to do what?’ to ‘You know, that might be actually feasible,’” said Leonard Tender, a program manager at DARPA who is overseeing the plastic waste projects.

The problems with plastic production and disposal are well-known. According to the United Nations Environment Program, the world creates about 440 million tons of plastic waste per year. Much of it ends up in landfills or in the ocean, where microplastics, plastic pellets, and plastic bags pose a threat to wildlife. Many governments and experts agree that solving the problem will require reducing production, and some countries and US states have additionally introduced policies to encourage recycling.

For years, scientists have also been experimenting with various species of plastic-eating bacteria. But DARPA is taking a slightly different approach in seeking a compact and mobile solution that uses plastic to create something else entirely: food for humans.

The goal, Techtmann hastens to add, is not to feed people plastic. Rather, the hope is that the plastic-devouring microbes in his system will themselves prove fit for human consumption. While Techtmann believes most of the project will be ready in a year or two, it’s this food step that could take longer. His team is currently doing toxicity testing, and then they will submit their results to the Food and Drug Administration for review. Even if all that goes smoothly, an additional challenge awaits. There’s an ick factor, said Techtmann, “that I think would have to be overcome.”

The military isn’t the only entity working to turn microbes into nutrition. From Korea to Finland, a small number of researchers, as well as some companies, are exploring whether microorganisms might one day help feed the world’s growing population.

Two birds, one stone

According to Tender, DARPA’s call for proposals was aimed at solving two problems at once. First, the agency hoped to reduce what he called supply-chain vulnerability: During war, the military needs to transport supplies to troops in remote locations, which creates a safety risk for people in the vehicle. Additionally, the agency wanted to stop using hazardous burn pits as a means of dealing with plastic waste. “Getting those waste products off of those sites responsibly is a huge lift,” Tender said.

The Michigan Tech system begins with a mechanical shredder, which reduces the plastic to small shards that then move into a reactor, where they soak in ammonium hydroxide under high heat. Some plastics, such as PET, which is commonly used to make disposable water bottles, break down at this point. Other plastics used in military food packaging—namely polyethylene and polypropylene—are passed along to another reactor, where they are subject to much higher heat and an absence of oxygen.

Under these conditions, the polyethylene and polypropylene are converted into compounds that can be upcycled into fuels and lubricants. David Shonnard, a chemical engineer at Michigan Tech who oversaw this component of the project, has developed a startup company called Resurgent Innovation to commercialize some of the technology. (Other members of the research team, said Shonnard, are pursuing additional patents related to other parts of the system.)

From recycling to food: Can we eat plastic-munching microbes? Read More »

cards-on-the-table:-are-butch-and-suni-coming-home-on-starliner-or-crew-dragon?

Cards on the table: Are Butch and Suni coming home on Starliner or Crew Dragon?

NASA astronauts Suni Williams and Butch Wilmore, seen in their Boeing flight suits.

Enlarge / NASA astronauts Suni Williams and Butch Wilmore, seen in their Boeing flight suits.

After months of consideration, NASA said Thursday that it will finally decide the fate of two astronauts on board the International Space Station, Butch Wilmore and Suni Williams, by this weekend. As soon as Saturday, the two crew members will learn whether they’ll return on a Starliner spacecraft in early September or a Crew Dragon vehicle next February.

On the eve of this fateful decision, the most consequential human spaceflight safety determination NASA has had to make in more than two decades, Ars has put together a summary of what we know, what we believe to be true, and what remains yet unknown.

Why has NASA taken so long?

Wilmore and Williams arrived at the International Space Station 11 weeks ago. Their mission was supposed to last eight days, but there was some expectation that they might stay a little longer. However, no one envisioned the crew remaining this long. That changed when, during Starliner’s flight to the space station, five of the 28 small thrusters that guide Starliner failed. After some touch-and-go operations, the astronauts and flight controllers at Johnson Space Center coaxed the spacecraft to a safe docking at the station.

This failure in space led to months of testing, both on board the vehicle in space and with similar thrusters on the ground in New Mexico. This has been followed by extensive data reviews and modeling by engineers to try to understand the root cause of the thruster problems. On Friday, lower-level managers will meet in a Program Control Board to discuss their findings and make recommendations to senior managers. Those officials, with NASA Administrator Bill Nelson presiding, will make a final decision at a Flight Readiness Review on Saturday in Houston.

What are the two options?

NASA managers will decide whether to send the astronauts home on Starliner, possibly as early as September 2, or to fly back to Earth on a Crew Dragon vehicle scheduled to be launched on September 24. To make room for Butch Wilmore and Suni Williams, this so-called “Crew-9” mission would launch with two astronauts instead of a full complement of four. Wilmore and Williams would then join this mission for their six-month increment on board the space station—their eight-day stay becoming eight months.

How are Butch and Suni feeling about this?

We don’t know, as they have not spoken to the media since it became apparent they could be in space for a long time. However, based on various sources, both of the crew members are taking it more or less in stride. They understand this is a test flight, and their training included the possibility of staying in space for an extended period of time if there were problems with Starliner.

That’s not to say it’s convenient. Both Wilmore and Williams have families back on Earth who expected them home by now, and the station was not set up for an extended stay. Wilmore, for example, has been having to sleep in a science laboratory rather than a designated sleeping area, so he has to pack up his personal things every morning.

What does seem clear is that Wilmore and Williams will accept NASA’s decision this weekend. In other words, they’re not going to stage a revolt in space. They trust NASA officials to make the right safety decision, whatever it ends up being. (So, for that matter, does Ars.)

Why is this a difficult decision?

First and foremost, NASA is concerned with getting its astronauts home safely. However, there are myriad other secondary decision factors, and bringing Butch and Suni home on Dragon instead of Starliner raises a host of new issues. Significantly among these is that it would be devastating for Boeing. Their public optics, should long-time rival SpaceX have to step in and “rescue” the crew from an “unsafe” Boeing vehicle, would be terrible. Moreover, the company has already lost $1.6 billion on the Starliner program, and there is the possibility that Boeing will shut it down. NASA does not want to lose a second provider of crew transport services to the space station.

Cards on the table: Are Butch and Suni coming home on Starliner or Crew Dragon? Read More »

android-malware-steals-payment-card-data-using-previously-unseen-technique

Android malware steals payment card data using previously unseen technique

NEW ATTACK SCENARIO —

Attacker then emulates the card and makes withdrawals or payments from victim’s account.

High angle shot of female hand inserting her bank card into automatic cash machine in the city. Withdrawing money, paying bills, checking account balances and make a bank transfer. Privacy protection, internet and mobile banking security concept

Newly discovered Android malware steals payment card data using an infected device’s NFC reader and relays it to attackers, a novel technique that effectively clones the card so it can be used at ATMs or point-of-sale terminals, security firm ESET said.

ESET researchers have named the malware NGate because it incorporates NFCGate, an open source tool for capturing, analyzing, or altering NFC traffic. Short for Near-Field Communication, NFC is a protocol that allows two devices to wirelessly communicate over short distances.

New Android attack scenario

“This is a new Android attack scenario, and it is the first time we have seen Android malware with this capability being used in the wild,” ESET researcher Lukas Stefanko said in a video demonstrating the discovery. “NGate malware can relay NFC data from a victim’s card through a compromised device to an attacker’s smartphone, which is then able to emulate the card and withdraw money from an ATM.”

Lukas Stefanko—Unmasking NGate.

The malware was installed through traditional phishing scenarios, such as the attacker messaging targets and tricking them into installing NGate from short-lived domains that impersonated the banks or official mobile banking apps available on Google Play. Masquerading as a legitimate app for a target’s bank, NGate prompts the user to enter the banking client ID, date of birth, and the PIN code corresponding to the card. The app goes on to ask the user to turn on NFC and to scan the card.

ESET said it discovered NGate being used against three Czech banks starting in November and identified six separate NGate apps circulating between then and March of this year. Some of the apps used in later months of the campaign came in the form of PWAs, short for Progressive Web Apps, which as reported Thursday can be installed on both Android and iOS devices even when settings (mandatory on iOS) prevent the installation of apps available from non-official sources.

The most likely reason the NGate campaign ended in March, ESET said, was the arrest by Czech police of a 22-year-old they said they caught wearing a mask while withdrawing money from ATMs in Prague. Investigators said the suspect had “devised a new way to con people out of money” using a scheme that sounds identical to the one involving NGate.

Stefanko and fellow ESET researcher Jakub Osmani explained how the attack worked:

The announcement by the Czech police revealed the attack scenario started with the attackers sending SMS messages to potential victims about a tax return, including a link to a phishing website impersonating banks. These links most likely led to malicious PWAs. Once the victim installed the app and inserted their credentials, the attacker gained access to the victim’s account. Then the attacker called the victim, pretending to be a bank employee. The victim was informed that their account had been compromised, likely due to the earlier text message. The attacker was actually telling the truth – the victim’s account was compromised, but this truth then led to another lie.

To “protect” their funds, the victim was requested to change their PIN and verify their banking card using a mobile app – NGate malware. A link to download NGate was sent via SMS. We suspect that within the NGate app, the victims would enter their old PIN to create a new one and place their card at the back of their smartphone to verify or apply the change.

Since the attacker already had access to the compromised account, they could change the withdrawal limits. If the NFC relay method didn’t work, they could simply transfer the funds to another account. However, using NGate makes it easier for the attacker to access the victim’s funds without leaving traces back to the attacker’s own bank account. A diagram of the attack sequence is shown in Figure 6.

NGate attack overview.

Enlarge / NGate attack overview.

ESET

The researchers said NGate or apps similar to it could be used in other scenarios, such as cloning some smart cards used for other purposes. The attack would work by copying the unique ID of the NFC tag, abbreviated as UID.

“During our testing, we successfully relayed the UID from a MIFARE Classic 1K tag, which is typically used for public transport tickets, ID badges, membership or student cards, and similar use cases,” the researchers wrote. “Using NFCGate, it’s possible to perform an NFC relay attack to read an NFC token in one location and, in real time, access premises in a different location by emulating its UID, as shown in Figure 7.”

Figure 7. Android smartphone (right) that read and relayed an external NFC token’s UID to another device (left).

Enlarge / Figure 7. Android smartphone (right) that read and relayed an external NFC token’s UID to another device (left).

ESET

The cloning could all occur in situations where the attacker has physical access to a card or is able to briefly read a card in unattended purses, wallets, backpacks, or smartphone cases holding cards. To perform and emulate such attacks requires the attacker to have a rooted and customized Android device. Phones that were infected by NGate didn’t have this requirement.

Android malware steals payment card data using previously unseen technique Read More »

amazon-is-bricking-primary-feature-on-$160-echo-device-after-1-year

Amazon is bricking primary feature on $160 Echo device after 1 year

Echo Show 8 Photos Edition —

Smart display will soon default to showing ads after three hours.

echo show 8 video call

In September of 2023, Amazon announced the Echo Show 8 Photos Edition. It looked just like the regular Echo Show 8 smart display/speaker but cost $10 more. Why? Because of its ability to show photos on the home screen for as long as you want—if you signed up for a $2 monthly subscription to Amazon’s PhotosPlus. Now, about a year after releasing the Echo Show 8 Photos Edition, Amazon is announcing that it’s discontinuing PhotosPlus. That means Echo Show 8 Photos Edition users will be forced to see ads instead of their beloved pics.

As per The Verge yesterday, Amazon started sending PhotosPlus subscribers emails saying that it will automatically cancel all PhotosPlus subscriptions on September 12 and will stop supporting PhotosPlus as of September 23. PhotosPlus, per Amazon’s message, “makes photos the primary home screen content you see on your Echo Show 8 and includes 25 GB of storage with Amazon Photos,” Amazon’s online photo storage offering. Users can continue using the 25GB of Amazon Photos storage after September.

However, users will no longer be able to make photos the indefinite home screen on the Alexa gadget. After September, their devices will no longer have the “photo-forward mode” that Amazon advertised for the Echo Show 8 Photos Edition. The photo-forward mode, per Amazon, let people make “selected personal photos the primary rotating content on the ambient screen” (photos rotated every 30 seconds). Now, Echo Show 8 Photo Editions will work like a regular Echo Show 8 and default to showing ads and promotions after three hours.

“The end of my Echo Show 8”

Amazon never explained why owners of the standard Echo Show 8 couldn’t use PhotosPlus or the photo-forward mode. The devices looked identical. It’s possible that the Photos Edition used extra hardware, but it’s likely that the Photos Edition’s $10 premium was meant to offset the lost ad revenue.

But now people who bought into the Photos Edition could feel like the victims of a bait-and-switch. After paying $10 extra to get a device capable of displaying photos indefinitely instead of ads, they’ll be forced into the same user experience as the cheaper Echo Show 8.

“I really have zero interest in keeping it if it’s going to show ads all day,” Reddit user Misschiff0 said in response to the news. “Sadly, this is the end of my Echo Show 8.”

Other apparent customers have discussed abandoning the Echo line entirely in response to the changes. As Reddit user Raybreezer wrote:

I’m dying for a replacement smart home speaker with a screen that’s not Google. Every day I hate the echo [sic] line more and more.

PhotosPlus was always a tough sell

Amazon may make more money selling ads than it has selling PhotosPlus subscriptions and relevant hardware. It was always somewhat peculiar that PhotosPlus only applied to one Amazon device. Amazon might have been considering extending PhotosPlus to other devices but didn’t get enough interest or money from the venture. Getting people to pay monthly for a feature that some would argue the gadget should already support out of the box seems difficult.

Amazon spokesperson Courtney Ramirez told The Verge that Amazon discontinued the Echo Show 8 Photos Edition in March, noting that Amazon regularly evaluates “products and services based on customer feedback” and that users can still get their Echo Show 8 Photos Editions to show photos.

But it’s hard to overlook Amazon discontinuing a product after about only six months and then bricking the device’s exclusive feature only a year after release. The short-lived Echo Show 8 Photos Edition and PhotosPlus service are joining Amazon’s graveyard of gadgets, which include the discontinued Astro business robot, Just Walk OutAmazon GlowFire PhoneDash buttons, and the Amazon Smart Oven.

Amazon’s quick discontinuation of the smart display and PhotosPlus is emblematic of its struggles to find a lucrative purpose and significant revenue source for Alexa-powered devices. Reports have claimed that Alexa went without a profit timeline for years and has cost Amazon tens of billions of dollars.

Amazon is banking on the upcoming generative AI version of Alexa being so good that people will pay a subscription fee to use it. But with tough competition, generative AI implementations varying in accuracy and relevance, and some consumers already turned off by consumer gadgets’ AI marketing hype, it’ll be hard for Amazon to turn things around. A premium-priced Alexa device losing its main feature after a year doesn’t instill confidence in future Amazon products either.

Amazon is bricking primary feature on $160 Echo device after 1 year Read More »

$1,700-“smart”-bassinet-adds-$20/month-sub—but-only-if-you-buy-it-used

$1,700 “smart” bassinet adds $20/month sub—but only if you buy it used

“SMART” —

Non-new Snoos now lose some use.

Picture of the Snoo

Enlarge / The Snoo, a “smart” bassinet.

Owners of the $1,695 Snoo “smart” bassinet like to gather in forums like Reddit’s r/snoolife to swap tracking graphs of their children’s sleep patterns. But they also like to complain about Happiest Baby, the company behind the Snoo. That’s because Happiest Baby this summer added a $20 monthly subscription fee to several of the Snoo’s “premium features,” which are controlled by a smartphone app.

Those who bought their Snoo from an “authorized” retailer before July 15, 2024, get the premium features free for nine months. No problem!

But those who bought their Snoo from an unauthorized retailer—that is, got it used—can “enjoy all the fun and benefits of our premium App features—for FREE—until July 15, 2024,” the company announced in its fine print. After that date, premium features went away; the only option for premium feature access on used Snoos now is to cough up $20 each month, atop the $600–$1,000 already spent on the device.

Because the Snoo is so [fabulously|ludicrously|incandescently] expensive, and because a bassinet is used only for those first few months while a newborn [learns to sleep|bawls its head off at least six times a night], and because having a new baby can be [expensive|extremely expensive], many [new parents|sleep-deprived zombies] seek out a non-new Snoo. And the parents are not happy about this new subscription fee. Says one Reddit user:

Just saying. This is bullshit. The current owners and users of Snoo should have been grandfathered in and continue to have access to basic feature like motion lock (the one I use most) and future new accounts should get a clear notification that without paying $20/mo they’re just buying a $2,000 basket.

Time to review bomb their app.

Dazed and confused

The Snoo works by rocking the bassinet at different levels while tracking the baby’s sleep level, and it can do things like simulate a car ride or offer gentle motion when a baby wakes at night. The idea is that the baby and parents both sleep more.

Basic features of the Snoo work for everyone, even those who purchased used devices, but the premium package includes things like the aforementioned “car ride mode,” responsiveness settings, weaning mode (to get ready for a crib), sleep tracking and logging, a “level lock,” and “sleepytime sounds.” In other words, the premium sub includes some pretty basic functionality that most Snoo owners want. (A common online complaint, in fact, is that the “premium” features are quite basic for a smart device like this.)

Many of the angriest online comments appear to get the actual details of the new subscription wrong, especially the fact that new Snoo purchasers do still get the premium features for free (well, for nine months).

But that’s part of the problem with these sorts of sudden business model changes—the details are confusing! Customers buy an expensive piece of hardware, hoping to placate a squalling child, and then find that in addition to a squalling child and a lot of cash out of pocket, they have to think about email addresses and online accounts and subscription fees and whether they bought a device new or used and if today is before or after July 15. Just rock the crying baby, smart bassinet!

In addition, whatever its legality, charging for features that used to be free can often feel like an injustice, leading even mild-mannered Snoo owners to take the above Redditor’s advice and start “review bombing” Happiest Baby’s apps.

On the Google Play Store, for instance, Happiest Baby’s smartphone app is currently down to 1.4 stars. Most of the recent reviews are one-star complaints that say things like:

When we first got our Snoo, the app was free and it worked properly. 5 months later you now charge to access the log (and other features) that were free. And now the app is glitching all the time too! Every time we go to turn it on, we have to reset the app first and then it’ll comment. Glad we only have 1 month left. I LOVE the snoo. It has been a savior. But the decision to charge for most of the app features out of no where was shameful. Even wean mode? That’s bull.

Or:

This app used to be great. But then they took many of the more important features and locked them behind a “Premium” subscription of $20/month, which is ridiculous. And just in case Happiest Baby tries to “clarify”, yes, the free version has several features. But that doesn’t change the fact that all of those “Premium” features USED TO BE FREE. It is purely a way to try and get more money out of parents who are just trying to do what is best for their kids.

Angry parents have also gone to the Better Business Bureau (BBB) to leave complaints about Happiest Baby, which currently has one out of five stars and is rated an “F.”

$1,700 “smart” bassinet adds $20/month sub—but only if you buy it used Read More »

peloton-announces-$95-“used-equipment-activation-fee”

Peloton announces $95 “used equipment activation fee”

Subscription revenue isn’t enough —

“Completely ridiculous.”

Peloton announces $95 “used equipment activation fee”

Peloton will start charging people a one-time $95 “used equipment activation fee” for used bikes purchased from outside of Peloton and its official distribution partners.

The fee will apply in the US and Canada. As pointed out by The Verge, Peloton confirmed in its fiscal Q4 2024 earnings call today that people who buy a used bike directly from Peloton or one of its third-party partners will not be subject to the fee.

During the call, Peloton’s interim CEO, Christopher Bruzzo, said that the activation fee “will be a source of incremental revenue and gross profit” and support Peloton’s “investments in improving the fitness experience for our members.”

Peloton also claimed in a letter to shareholders [PDF] that the fee is related to ensuring that the subscription customers that Peloton gains through used bike sales “receive the same high-quality onboarding experience.”

Secondhand bikes already help make Peloton money

Peloton doesn’t immediately make money when someone sells their unwanted bike to someone else for a discount, but it is making significant money from people buying subscriptions to use with their secondhand gear. In its Q4 2024 shareholder letter, Peloton said that secondhand bike sales deliver “a steady stream of paid connected fitness subscriber additions, up 16 percent” year over year in Peloton’s fiscal Q4.

People who buy used bikes outside of Peloton also “exhibit lower net churn rates” than people who pay Peloton to rent its hardware, per the letter.

But Peloton’s hardware sales have tumbled—as has its worth—since booming during the COVID-19 pandemic. The new activation fee is characteristic of a company desperate for more revenue after going from a valuation of $50 billion in January 2021 to $2.1 billion in December 2023.

Peloton’s Q4 2024 earnings report today showed hardware sales declining 4 percent year over year (YoY). Subscription revenue increased 2.3 percent (YoY). Overall, Peloton achieved its first revenue growth (0.2 percent YoY) since its fiscal quarter that ended on December 21, 2021. The company still reported a loss of $30.5 million; although, that’s an improvement from a year ago, when it lost $241.8 million.

Fee could deter used equipment sales

Peloton will have to continue making big moves to turn a profit. However, the $95 fee could be seen as a deterrent to the used market and as unnecessary for the user experience.

Peloton gear is already known for being expensive (its Bike+, for example, is $2,500 as of this writing). The used market makes Peloton’s products more accessible and allows people to recoup some of their losses from unwanted equipment while also avoiding connected gym equipment becoming e-waste. A $95 fee takes away some of the savings people have been enjoying for years by opting for a secondhand Peloton.

The fee is also a standout from most the secondhand market (imagine paying Toyota a “reactivation fee” to drive a used car you purchased, or having to pay Lenovo a separate fee in order to use the refurbished laptop you just got).

As nermal543 on Reddit put it:

That’s completely ridiculous. Why would you want to discourage people from buying used equipment and getting an active subscriber back on board for $50/month? Because presumably whoever is selling doesn’t want to pay the subscription fee anymore. Yikes.

Peloton continues to face challenges to bouncing back after a meteoric rise and fall tied to the pandemic. It’s also employing cost-cutting measures, like reducing marketing and sales spend, CNBC noted. And in May, Peloton announced layoffs of about 400 workers (about 15 percent of the workforce), as well as the quitting of its second CEO in two years. Peloton has undergone multiple rounds of layoffs lately, with job reductions by the hundreds also occurring in February 2023, October 2022, August 2022, July 2022, and in February 2022, when it announced that it was laying off 2,800 people. After having 8,600 workers in 2021, Peloton now employs about 3,000.

Some may be perturbed by Peloton’s efforts to make money. However, investors are seemingly happy, as CNBC noted that shares increased over 30 percent in afternoon trading.

This isn’t the first we’ve heard of a company, whose unit sales thrived during the pandemic, seeking novel and controversial ways to keep the money flowing. Last month, CEO Hanneke Faber discussed Logitech’s idea for a “forever mouse” that requires a subscription for software updates.

Peloton announces $95 “used equipment activation fee” Read More »

town-urges-curfew-over-mosquito-spread-disease-that-kills-up-to-50%-of-people

Town urges curfew over mosquito-spread disease that kills up to 50% of people

“Critical risk” —

Eastern Equine Encephalitis is very rare in the US, but when it strikes, it’s bad.

A mosquito collected to test for mosquito-borne diseases.

Enlarge / A mosquito collected to test for mosquito-borne diseases.

A small town in Massachusetts is urging residents to stay indoors in the evenings after the spread of a dangerous mosquito-spread virus reached “critical risk level.”

The virus causes Eastern equine encephalitis (EEE), which kills between 30 and 50 percent of people who are stricken—who are often children under the age of 15 and the elderly. Around half who survive are left permanently disabled, and some die within a few years due to complications. There is no treatment for EEE. So far, one person in the town—an elderly resident of Oxford—has already become seriously ill with neuroinvasive EEE.

EEE virus is spread by mosquitoes in certain swampy areas of the country, particularly in Atlantic and Gulf Coast states and the Great Lakes region. Mosquitoes shuttle the virus between wild birds and animals, including horses and humans. In humans, the virus causes very few cases in the US each year—an average of 11, according to the Centers for Disease Control and Prevention. But given the extreme risk of EEE, health officials take any spread seriously.

On August 16, the Massachusetts Department of Public Health announced the state’s first case and declared a “critical risk level” in the four communities of Douglas, Oxford, Sutton, and Webster. These all cluster in Worcester county near the state’s borders with Rhode Island and Connecticut.

Curfew

While the state health department did not identify the man as a resident of Oxford, the town’s manager confirmed his residence in a memorandum Wednesday. The manager, Jennifer Callahan, reported that the man remains hospitalized. She also reported that a horse across the border in Connecticut had recently died of EEE.

Also on Wednesday, the four towns—Douglas, Oxford, Sutton, and Webster—issued a joint health advisory, which included a recommended curfew.

Last night, The Oxford Board of Health voted to adopt the advisory, according to the Boston Globe. The recommendation is for residents to avoid mosquito’s peak activity time. They should “finish outdoor activities before 6: 00 PM through September 30th, 2024 and before 5: 00 PM October 1st, 2024 until the first hard frost.” The advisory also recommends residents wear insect repellent, wear protective clothing, and mosquito-proof their homes.

Officials emphasized that the curfew is a recommendation, not mandatory. However, to use town properties—such as recreation fields—people will first need to file an indemnification form and provide proof of adequate insurance coverage to the town.

To date, there have been only three cases of EEE in the US this year. One in Massachusetts, one in Vermont, and the last in New Jersey. All three are neuroinvasive. The CDC says that about 30 percent of cases are fatal, while Massachusetts health officials report that about half of people who develop EEE in the state have died.

In 2019, there was a multi-state outbreak of EEE, leading to a high of 38 cases. Twelve of the cases occurred in Massachusetts, and six died.

Town urges curfew over mosquito-spread disease that kills up to 50% of people Read More »

apple-splits-app-store-team-in-two,-introduces-new-leadership

Apple splits App Store team in two, introduces new leadership

Shake-up —

This is the latest in a series of changes resulting from EU regulation.

The Apple Park campus in Cupertino, California.

Enlarge / The Apple Park campus in Cupertino, California.

Apple is comprehensively restructuring its long-standing App Store team, splitting the team into two separate divisions as the executive who has run it for more than a decade says goodbye to the company.

There will now be one team for the familiar, Apple-run App Store, and another one to handle alternative app stores in the European Union. Apple recently partially opened the platform to third-party app stores in response to the Digital Markets Act, a set of European regulations meant to break up what legislators and regulators deemed to be app store monopolies.

As noted, the restructuring comes with some notable personnel changes, too. App Store Vice President Matt Fischer, who has been at the helm of the platform since 2010, will leave the company.

In a social media post and email to employees, Fischer wrote the following:

After 21 years at Apple, I’ve made the decision to step away from our incredible company. This has been on my mind for some time, and as we are also reorganizing the team to better manage new challenges and opportunities, now is the right moment to pass the baton to two outstanding leaders on my team—Carson Oliver and Ann Thai—both of whom are more than ready for this next chapter.

You can visit his LinkedIn post to see the full statement. According to Bloomberg, Carson Oliver will lead the Apple App Store division, while Ann Thai will head up the alternative app store team. Up to this point, Oliver has been a senior director of business management at Apple, while Thai has had the title of worldwide product director for the App Store and Apple Arcade.

It’s worth noting that Fischer was the overall lead for Apple Arcade, so that service will now be under new leadership.

Apple Fellow and former marketing SVP Phil Schiller will continue to oversee both of the new divisions.

It’s unclear what further changes, if any, will result from this shakeup. Apple has already made significant changes in response to EU regulations, but some developers and competitors are still critical, saying it hasn’t gone far enough.

Apple splits App Store team in two, introduces new leadership Read More »

saas-security-posture—it’s-not-you,-it’s-me!

SaaS Security Posture—It’s not you, it’s me!

In business, it’s not uncommon to take a software-as-a-service (SaaS)-first approach. It makes sense—there’s no need to deal with the infrastructure, management, patching, and hardening. You just turn on the SaaS app and let it do its thing.

But there are some downsides to that approach.

The Problem with SaaS

While SaaS has many benefits, it also introduces a host of new challenges, many of which don’t get the coverage they warrant. At the top of the list of challenges is security. So, while there are some very real benefits of SaaS, it’s also important to recognize the security risk that comes with it. When we talk about SaaS security, we’re not usually talking about the security of the underlying platform, but rather how we use it.

Remember, it’s not you, it’s me!

The Shared Responsibility Model

In the terms and conditions of most SaaS platforms is the “shared responsibility model.” What it usually says is that the SaaS vendor is responsible for providing a platform that is robust, resilient, and reliable—but they don’t take responsibility for how you use and configure it. And it is in these configuration changes that the security challenge lives.

SaaS platforms often come with multiple configuration options, such as ways to share data, ways to invite external users, how users can access the platform, what parts of the platform they can use, and so on. And every configuration change, every nerd knob turned, is the potential to take the platform away from its optimum security configuration or introduce an unexpected capability. While some applications, like Microsoft 365, offer guidance on security settings, this is not true for all of them. Even if they do, how easy is that to manage when you get to 10, 20, or even 100 SaaS apps?

Too Many Apps

Do you know how many SaaS apps you have? It’s not the SaaS apps you know about that are the issue, it’s the ones you don’t. Because SaaS is so accessible, it can easily evade management. There are apps that people use but an organization may not be aware of—like the app the sales team signed up for, that thing that marketing uses, and of course, everyone wants a GenAI app to play with. But these aren’t the only ones; there are also the apps that are part of the SaaS platforms you sign up for. Yes, even the ones you know about can contain additional apps you don’t know about. This is how an average enterprise gets to more than 100 SaaS applications. How do you manage each of those? How do you ensure you know they exist and they are configured in a way that meets good security practices and protects your information? Therein lies the challenge.

Introducing SSPM

SSPM can be the answer. It is designed to initially integrate with your managed SaaS applications to provide visibility into how they are configured, where configurations present risks, and how to address them. It will continually monitor them for new threats and configuration changes that introduce risk. It will also discover unmanaged SaaS applications that are in use, evaluate their posture and present risk profiles of both the application and the SaaS vendor itself. It centralizes the management and security of a SaaS infrastructure and where its management and configuration present risk.

Overlap with CASB and DLP

There is some overlap in the market, particularly with cloud access security broker (CASB) and data loss prevention (DLP) tools. But these tools are a bit like capturing the thief as he runs down the driveway, rather than making sure the doors and windows were secured in the first place.

SSPM is yet another security tool to manage and pay for. But is it a tool we need? Well, that is up to you; however, our use of SaaS, for all the benefits it brings, has brought a new complexity and a new set of risks. We have so many more apps than we have ever had, many of them we don’t manage centrally, and they have many configuration knobs to turn. Without oversight of them all, we do run security risks.

Next Steps

SaaS security posture management (SSPM) is another entry into the growing catalog of security posture management tools. They are often easy to try out, and many offer free assessments that can give you an idea of the scale of the challenge you face. SaaS security is tricky and often does not get the coverage it deserves, so getting an idea of where you stand could be helpful.

Before you find yourself on the wrong end of a security incident and your SaaS vendor tells you it’s you, not me, it may be worth seeing what an SSPM tool can do for you. To learn more, take a look at GigaOm’s SSPM Key Criteria and Radar reports. These reports provide a comprehensive overview of the market, outline the criteria you’ll want to consider in a purchase decision, and evaluate how a number of vendors perform against those decision criteria.

If you’re not yet a GigaOm subscriber, sign up here.

SaaS Security Posture—It’s not you, it’s me! Read More »

the-future-of-ztna:-a-convergence-of-network-access-solutions

The Future of ZTNA: A Convergence of Network Access Solutions

Zero trust network access (ZTNA) has emerged as a crucial security paradigm for organizations seeking to secure their applications and data in the cloud era. By implementing a least-privilege access model and leveraging identity and context as decision criteria, ZTNA solutions provide granular control over who can access what resources, reducing the attack surface and mitigating the risk of data breaches.

While ZTNA initially gained traction as a standalone solution, the future of this technology lies in its convergence with other security offerings, particularly secure access service edge (SASE) and software-defined perimeter (SDP). This convergence aims to create a comprehensive and integrated security solution that combines ZTNA’s secure access capabilities with additional security features like secure web gateways, cloud access security brokers, and firewall-as-a-service offerings.

Enhancing Security with SASE and SDP

As organizations continue to embrace cloud services and remote work, the demand for seamless and secure access to applications and resources from anywhere, on any device, will only grow. SASE, which combines networking and security functions into a single cloud-delivered service, is well-positioned to address this need. By integrating ZTNA capabilities into SASE offerings, vendors can provide a unified solution that not only secures access but also ensures optimal performance and user experience.

Similarly, SDP solutions, which create a secure perimeter around applications and resources, can benefit from the integration of ZTNA technologies. By combining the granular access controls and context-based policies of ZTNA with the application-level security provided by SDP, organizations can achieve a comprehensive zero-trust architecture that spans both the network and application layers.

While the convergence of ZTNA with SASE and SDP is a significant trend, it is essential to note that ZTNA will not be entirely subsumed by these broader security solutions. Many organizations may still opt for standalone ZTNA solutions, particularly those with specific use cases or unique requirements that demand a more focused approach.

The Evolution of ZTNA

In the coming 12 to 24 months, we can expect to see continued innovation in the ZTNA space, with vendors introducing new features and capabilities to address evolving security challenges. However, this innovation is likely to be incremental rather than disruptive, as the core principles of ZTNA are well-established.

Acquisitions may play a role in shaping the ZTNA market, as larger security vendors seek to bolster their offerings by acquiring promising ZTNA startups or integrating ZTNA capabilities into their existing platforms. However, given the relatively mature state of the ZTNA technology, these acquisitions are likely to be strategic moves rather than major market disruptors.

To prepare for the evolving character of the ZTNA sector, organizations should take a proactive approach to assessing their security posture and identifying potential gaps. Developing a comprehensive zero-trust strategy that aligns with business objectives and risk tolerance is crucial. Additionally, organizations should prioritize solutions that offer seamless integration with existing security infrastructure, support for diverse use cases and deployment models, and a robust vendor ecosystem.

By embracing the convergence of ZTNA with SASE and SDP, organizations can benefit from a holistic security solution that not only secures access but also optimizes performance, enhances user experience, and provides a unified framework for managing and enforcing security policies across the entire IT infrastructure.

Next Steps

To learn more, take a look at GigaOm’s ZTNA Key Criteria and Radar reports. These reports provide a comprehensive view of the market, outline the criteria you’ll want to consider in a purchase decision, and evaluate how a number of vendors perform against those decision criteria.

If you’re not yet a GigaOm subscriber, sign up here.

The Future of ZTNA: A Convergence of Network Access Solutions Read More »

meteorites-give-the-moon-its-extremely-thin-atmosphere

Meteorites give the Moon its extremely thin atmosphere

The exosphere gets the vapors —

Impacts that vaporize bits of the lunar surface maintain the Moon’s thin atmosphere.

Graphic of a spacecraft above a grey planetary body, with a distant sun in the background.

Enlarge / Artist’s rendition of the LADEE mission above the lunar surface.

The Moon may not have much of an atmosphere, mostly because of its weak gravitational field (whether it had a substantial atmosphere billions of years ago is debatable). But it is thought to presently be maintaining its tenuous atmosphere—also known as an exosphere—because of meteorite impacts.

Space rocks have been bombarding the Moon for its 4.5-billion-year existence. Researchers from MIT and the University of Chicago have now found that lunar soil samples collected by astronauts during the Apollo era show evidence that meteorites, from hulking meteors to micrometeoroids no bigger than specks of dust, have launched a steady flow of atoms into the exosphere.

Though some of these atoms escape into space and others fall back to the surface, those that do remain above the Moon create a thin atmosphere that keeps being replenished as more meteorites crash into the surface.

“Over long timescales, micrometeorite impact vaporization is the primary source of atoms in the lunar atmosphere,” the researchers said in a study recently published in Science Advances.

Ready for launch

When NASA sent its orbiter LADEE (Lunar Atmosphere and Dust Environment Explorer) to the Moon in 2013, the mission was intended to find out the origins of the Moon’s atmosphere. LADEE observed more atoms in the atmosphere during meteor showers, which suggested impacts had something to do with the atmosphere. However, it left questions about the mechanism that converts impact energy into a diffuse atmosphere.

To find these answers, a team of MIT and University of Chicago researchers, led by professor Nicole Nie of MIT’s Department of Earth, Atmospheric and Planetary Sciences, needed to analyze the isotopes of elements in lunar soil that are most susceptible to the effects of micrometeoroid impacts. They chose potassium and rubidium.

Potassium and rubidium ions are especially prone to two processes: impact vaporization and ion sputtering.

Impact vaporization results from particles colliding at high speeds and generating extreme amounts of heat that excite atoms enough to vaporize the material they are in and send them flying. Ion sputtering involves high-energy impacts that set atoms free without vaporization. Atoms that are released by ion sputtering tend to have more energy and move faster than those released by impact vaporization.

Either of these can create and maintain the lunar atmosphere in the wake of meteorite impacts.

So, if atoms sent into the atmosphere by ion sputtering have an energy advantage, then why did the researchers find that most atoms in the atmosphere actually come from impact vaporization?

Touching back down

Since the lunar soil samples provided by NASA had previously had their lighter and heavier isotopes of potassium and rubidium quantified, Lie’s team used calculations to determine which collision process is more likely to keep different isotopes from fleeing the atmosphere.

The researchers found that atoms transferred to the atmosphere by ion sputtering are sent zooming at such high energies that they often reach escape velocity—the minimum velocity needed to escape the Moon’s already feeble gravity—and continue to travel out into space. Atoms that end up in the atmosphere can also be lost from the atmosphere, after all.

The fraction of atoms that reach escape velocity after impact vaporization depends on the temperature of those atoms. Lower energy levels associated with impact vaporization result in lower temperatures, which give atoms a lower chance of escape.

“Impact vaporization is the dominant long-term source of the lunar atmosphere, likely contributing more than 65 percent of atmospheric [potassium] atoms, with ion sputtering accounting for the rest,” Lie and her team said in the same study.

There are other ways atoms are lost from the lunar atmosphere. It is mostly lighter ions that tend to stick around in the exosphere, with ions falling back to the surface if they’re too heavy. Others are photoionized by electromagnetic radiation from the solar wind and often carried off into space by solar wind particles.

What we’ve learned about the lunar atmosphere through lunar soil could influence studies of other bodies. Impact vaporization has already been found to launch atoms into the exosphere of Mercury, which is thinner than the Moon’s. Studying Martian soil, which may land on Earth with sample return missions in the future, could also give more insight into how meteorite impacts affect its atmosphere.

As we approach a new era of manned lunar missions, the Moon may have more to tell us about where its atmosphere comes from—and where it goes.

Science Advances, 2024.  DOI: 10.1126/sciadv.adm7074

Meteorites give the Moon its extremely thin atmosphere Read More »

passing-part-of-a-medical-licensing-exam-doesn’t-make-chatgpt-a-good-doctor

Passing part of a medical licensing exam doesn’t make ChatGPT a good doctor

Smiling doctor discussing medical results with a woman.

Enlarge / For now, “you should see a doctor” remains good advice.

ChatGPT was able to pass some of the United States Medical Licensing Exam (USMLE) tests in a study done in 2022. This year, a team of Canadian medical professionals checked to see if it’s any good at actual doctoring. And it’s not.

ChatGPT vs. Medscape

“Our source for medical questions was the Medscape questions bank,” said Amrit Kirpalani, a medical educator at the Western University in Ontario, Canada, who led the new research into ChatGPT’s performance as a diagnostic tool. The USMLE contained mostly multiple-choice test questions; Medscape has full medical cases based on real-world patients, complete with physical examination findings, laboratory test results, and so on.

The idea behind it is to make those cases challenging for medical practitioners due to complications like multiple comorbidities, where two or more diseases are present at the same time, and various diagnostic dilemmas that make the correct answers less obvious. Kirpalani’s team turned 150 of those Medscape cases into prompts that ChatGPT could understand and process.

This was a bit of a challenge because OpenAI, the company that made ChatGPT, has a restriction against using it for medical advice, so a prompt to straight-up diagnose the case didn’t work. This was easily bypassed, though, by telling the AI that diagnoses were needed for an academic research paper the team was writing. The team then fed it various possible answers, copy/pasted all the case info available at Medscape, and asked ChatGPT to provide the rationale behind its chosen answers.

It turned out that in 76 out of 150 cases, ChatGPT was wrong. But the chatbot was supposed to be good at diagnosing, wasn’t it?

Special-purpose tools

At the beginning of 2024. Google published a study on the Articulate Medical Intelligence Explorer (AMIE), a large language model purpose-built to diagnose diseases based on conversations with patients. AMIE outperformed human doctors in diagnosing 303 cases sourced from New England Journal of Medicine and ClinicoPathologic Conferences. And AMIE is not an outlier; during the last year, there was hardly a week without published research showcasing an AI performing amazingly well in diagnosing cancer and diabetes, and even predicting male infertility based on blood test results.

The difference between such specialized medical AIs and ChatGPT, though, lies in the data they have been trained on. “Such AIs may have been trained on tons of medical literature and may even have been trained on similar complex cases as well,” Kirpalani explained. “These may be tailored to understand medical terminology, interpret diagnostic tests, and recognize patterns in medical data that are relevant to specific diseases or conditions. In contrast, general-purpose LLMs like ChatGPT are trained on a wide range of topics and lack the deep domain expertise required for medical diagnosis.”

Passing part of a medical licensing exam doesn’t make ChatGPT a good doctor Read More »