• chevron_right

      The Ars Technica guide to keyboards: Mechanical, membrane, and buckling springs

      news.movim.eu / ArsTechnica · Wednesday, 27 March, 2024 - 11:00

    The Ars Technica guide to keyboards: Mechanical, membrane, and buckling springs

    Enlarge (credit: Aurich Lawson)

    Your keyboard is the thread that connects you to your computer. The way a keyboard feels—from the sensations of each key pressing down and resetting to the build of the board’s chassis—has a direct impact on your typing experience, affecting accuracy, speed, and fatigue.

    We’ve dug into the joys of quality keyboards and the thrills of customization at Ars Technica before. But what really makes one type of keyboard feel better than another? People say membrane keyboards feel mushy, but why ? And what about keyboards with cult-like followings? What makes decades-old IBM keyboards or expensive Topres so special?

    In this guide, we’ll look at how some of the most popular keyboard categories work and how their differences impact typing feel.

    Read 51 remaining paragraphs | Comments

    • chevron_right

      WWDC 2024 starts on June 10 with announcements about iOS 18 and beyond

      news.movim.eu / ArsTechnica · Tuesday, 26 March, 2024 - 19:02

    A colorful logo that says

    Enlarge / The logo for WWDC24. (credit: Apple)

    Apple has announced dates for this year's Worldwide Developers Conference (WWDC). WWDC24 will run from June 10 through June 14 at the company's Cupertino headquarters, but everything will be streamed online.

    Apple posted about the event with the following generic copy :

    Join us online for the biggest developer event of the year. Be there for the unveiling of the latest Apple platforms, technologies, and tools. Learn how to create and elevate your apps and games. Engage with Apple designers and engineers and connect with the worldwide developer community. All online and at no cost.

    As always, the conference will kick off with a keynote presentation on the first day, which is Monday, June 10. You can be sure Apple will use that event to at least announce the key features of its next round of annual software updates for iOS, iPadOS, macOS, watchOS, visionOS, and tvOS.

    Read 4 remaining paragraphs | Comments

    • chevron_right

      Apple dévoilera iOS 18 et sa stratégie sur l’intelligence artificielle le 10 juin 2024

      news.movim.eu / Numerama · Tuesday, 26 March, 2024 - 18:28

    La WWDC, le traditionnel événement d'Apple dédié aux développeurs, aura lieu du 10 au 14 juin. La marque devrait y dévoiler plusieurs mises à jour pour ses systèmes d'exploitation, en plus de nouveautés liées à l'intelligence artificielle.

    • chevron_right

      Hardware Vulnerability in Apple’s M-Series Chips

      news.movim.eu / Schneier · Tuesday, 26 March, 2024 - 16:23 · 2 minutes

    It’s yet another hardware side-channel attack:

    The threat resides in the chips’ data memory-dependent prefetcher, a hardware optimization that predicts the memory addresses of data that running code is likely to access in the near future. By loading the contents into the CPU cache before it’s actually needed, the DMP, as the feature is abbreviated, reduces latency between the main memory and the CPU, a common bottleneck in modern computing. DMPs are a relatively new phenomenon found only in M-series chips and Intel’s 13th-generation Raptor Lake microarchitecture, although older forms of prefetchers have been common for years.

    […]

    The breakthrough of the new research is that it exposes a previously overlooked behavior of DMPs in Apple silicon: Sometimes they confuse memory content, such as key material, with the pointer value that is used to load other data. As a result, the DMP often reads the data and attempts to treat it as an address to perform memory access. This “dereferencing” of “pointers”—meaning the reading of data and leaking it through a side channel—­is a flagrant violation of the constant-time paradigm.

    […]

    The attack, which the researchers have named GoFetch , uses an application that doesn’t require root access, only the same user privileges needed by most third-party applications installed on a macOS system. M-series chips are divided into what are known as clusters. The M1, for example, has two clusters: one containing four efficiency cores and the other four performance cores. As long as the GoFetch app and the targeted cryptography app are running on the same performance cluster—­even when on separate cores within that cluster­—GoFetch can mine enough secrets to leak a secret key.

    The attack works against both classical encryption algorithms and a newer generation of encryption that has been hardened to withstand anticipated attacks from quantum computers. The GoFetch app requires less than an hour to extract a 2048-bit RSA key and a little over two hours to extract a 2048-bit Diffie-Hellman key. The attack takes 54 minutes to extract the material required to assemble a Kyber-512 key and about 10 hours for a Dilithium-2 key, not counting offline time needed to process the raw data.

    The GoFetch app connects to the targeted app and feeds it inputs that it signs or decrypts. As its doing this, it extracts the app secret key that it uses to perform these cryptographic operations. This mechanism means the targeted app need not perform any cryptographic operations on its own during the collection period.

    Note that exploiting the vulnerability requires running a malicious app on the target computer. So it could be worse. On the other hand, like many of these hardware side-channel attacks, it’s not possible to patch.

    Slashdot thread .

    • chevron_right

      DoodStream: Hollywood, Netflix, Amazon & Apple Sue “Rogue Cyberlocker”

      news.movim.eu / TorrentFreak · Sunday, 24 March, 2024 - 20:28 · 4 minutes

    doodstream The Motion Picture Association’s interest in file-hosting platform DoodStream first came to light in a submission to the USTR in October 2022 .

    The MPA described DoodStream as a video hosting service offering free storage and premium services including priority encoding and an ad-free experience. Videos uploaded to the platform were embedded on many other streaming sites, the MPA reported, and as a result, traffic was booming.

    The MPA estimated the site received 82.7 million visits in August 2022, while using the services of DDoS-Guard in Russia and OVH in France.

    “DoodStream operates a partner program that offers financial remuneration, either per download or stream depending on the country of origin,” the MPA informed the USTR in its ‘notorious markets’ submission.

    DoodStream rates doodstream-partner

    A year later in a new submission to the USTR, the MPA described DoodStream as a ‘top priority’ for its anti-piracy efforts.

    DoodStream in the Spotlight

    In its October 2023 submission to the USTR’s notorious markets report, the MPA’s cyberlocker and video streaming category listed DoodStream front and center as the priority problem. The MPA still believed the site was operating from OVH in France but also listed other companies as hosts, including Online S.A.S., Hetzner Online GmbH, and Interkvm Host10 SRL.

    The MPA noted that the Delhi High Court had ordered ISPs to block DoodStream in 2023, a measure also handed down by a French court during the same year. The Paris court noted that the site “encouraged the infringement of copyright and related rights by setting up tools specifically designed for the mass and illicit sharing of protected content.”

    “The operators are located in India,” the MPA informed the USTR.

    Entertainment Giants Team Up Against DoodStream

    Two months later, Karyn Temple, Senior Executive Vice President and MPA Global General Counsel referenced DoodStream before the House Judiciary Subcommittee on Courts, Intellectual Property and the Internet ( pdf ) . DoodStream continued, business as usual, until now.

    In a lawsuit being heard at the High Court of Delhi, eight plaintiffs are listed as follows: Warner Bros. Entertainment Inc., Amazon Content Services LLC, Columbia Pictures Industries, Inc., Disney Enterprises, Inc., Netflix US, LLC, Paramount Pictures Corporation, Universal City Studios Productions LLP and Apple Video Programming.

    A total of six defendants include the domains doodstream.com, doodstream.co, dood.stream and their underlying websites (defendants 1-3), plus a server (defendant 4) used by defendants 1 to 3 which allegedly facilitates storing and dissemination of illegal content. Defendants 5 and 6, neither of whom have been named, are reportedly site operators.

    According to counsel for the plaintiffs, “rogue cyberlocker websites provide an infrastructure specifically designed to incentivize hosting, uploading, storing, sharing, streaming, and authorize the downloading of copyrighted material without obtaining authorization from the plaintiffs.

    Claims Against The DoodStream Defendants

    The plaintiffs allege that a massive amount of infringing content to which they have exclusive rights, is uploaded by users on the defendants’ websites.

    “Counsel for plaintiffs say the studios approached defendants upon noticing this infringing content, first in June, 2023, after they discovered the identity as to who was operating these websites, who happen to be individuals based in Coimbatore, Tamil Nadu, India, arrayed as defendants nos. 5 and 6,” an order from the court reads.

    “This, according to plaintiffs’ counsel, was achieved after some effort since the WHOIS details of defendant nos. 1 to 3 were masked.”

    The court notes that the plaintiffs continuously pursued the defendants to take the infringing content down. However, despite promises to comply, a mechanism built in to the site simply generated new links whenever content was supposedly removed.

    “Further, uploaded content would also generate a link which could be disseminated by the uploader and therefore, potentially could be disseminated through parallel websites. Thus, as per counsel for plaintiffs, the takedown itself was elusive and of no effect, since the system immediately permitted generation of a new link.”

    The court notes that through this mechanism, DoodStream becomes a “hydra-headed monster” that is difficult to police through takedowns alone.

    Plaintiffs Want DoodStream Shut Down

    The plaintiffs submit that DoodStream should either be comprehensively blocked or a Local Commissioner should be appointed to take over the administration of the sites. However, counsel for the defendants told the court that their clients are prepared to “exhaustively and completely” remove the plaintiffs’ content from the platform.

    Due to the link generation mechanism in operation on the site, the plaintiffs expressed concern that content taken down would nnot stay down. The defendants offered assurances that they would “change the features on their websites’ architecture” to ensure that once the process of takedown is complete, regeneration would not be allowed.

    In view of this undertaking, the court ordered ( pdf ) all content belonging to the plaintiffs to be taken down within 24 hours, and ordered the defendants to hire a chartered accountant to disclose all revenue generated by the sites since their launch.

    The case is listed for hearing on April 8, 2024.

    From: TF , for the latest news on copyright battles, piracy and more.

    • chevron_right

      Beeper Mini for Android sends and receives iMessages, no Mac server required

      news.movim.eu / ArsTechnica · Tuesday, 5 December, 2023 - 15:00

    Beeper messages looking iMessage-like blue on an Android phone

    Enlarge / A Pixel 3, messaging a savvy iPhone owner, one with the kinds of concerns Beeper hopes to resolve for its customers. (credit: Kevin Purdy)

    In the past week, I have sent an iMessage to one friend from a command-line Python app and to another from a Pixel 3 Android phone.

    Sending an iMessage without an Apple device isn't entirely new, but this way of doing it is. I didn't hand over my Apple credentials or log in with my Apple ID on a Mac server on some far-away rack. I put my primary SIM card in the Pixel, I installed Beeper Mini , and it sent a text message to register my number with Apple. I never gave Beeper Mini my Apple ID.

    From then on, my iPhone-toting friends who sent messages to my Pixel 3 saw them as other-iPhone blue, not noticeably distracting green. We could all access the typing, delivered/read receipts, emoji reactions, and most other iPhone-to-iPhone message features. Even if I had no active Apple devices, it seems, I could have chosen to meet Apple users where they were and gain end-to-end encryption by doing so.

    Read 16 remaining paragraphs | Comments

    • chevron_right

      Google researchers report critical zero-days in Chrome and all Apple OSes

      news.movim.eu / ArsTechnica · Friday, 1 December, 2023 - 00:38

    The phrase Zero Day can be spotted on a monochrome computer screen clogged with ones and zeros.

    Enlarge (credit: Getty Images )

    Researchers in Google's Threat Analysis Group have been as busy as ever, with discoveries that have led to the disclosure of three high-severity zero-day vulnerabilities under active exploitation in Apple OSes and the Chrome browser in the span of 48 hours.

    Apple on Thursday said it was releasing security updates fixing two vulnerabilities present in iOS, macOS, and iPadOS. Both of them reside in WebKit, the engine that drives Safari and a wide range of other apps, including Apple Mail, the App Store, and all browsers running on iPhones and iPads. While the update applies to all supported versions of Apple OSes, Thursday’s disclosure suggested in-the-wild attacks exploiting the vulnerabilities targeted earlier versions of iOS.

    “Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1,” Apple officials wrote of both vulnerabilities, which are tracked as CVE-2023-42916 and CVE-2023-42917.

    Read 4 remaining paragraphs | Comments

    • chevron_right

      New chip-packaging facility could save TSMC’s Arizona fab from “paperweight” status

      news.movim.eu / ArsTechnica · Thursday, 30 November, 2023 - 19:25 · 1 minute

    Apple wants to build more of its A- and M-series chips in the United States.

    Enlarge / Apple wants to build more of its A- and M-series chips in the United States. (credit: Apple)

    Late last year, Apple CEO Tim Cook announced that the company would definitely be buying chips made at Taiwan Semiconductor's new Arizona-based fab once it had opened. Apple working with TSMC isn't new; most, if not all, of the processors currently sold in Apple's products are made on one of TSMC's many manufacturing nodes. But being able to buy them from a US-based facility would be a first.

    The issue, as outlined by some TSMC employees speaking to The Information in September , is that the Arizona facility would manufacture chips, but it wouldn't be building a facility to handle packaging. And without packaging, the Arizona factory would essentially be a "paperweight," requiring any chips made there to be shipped to Taiwan for assembly before they could be put in any products.

    Today Apple announced that it had solved that particular problem, partnering with a company called Amkor to handle chip packaging in Arizona. Amkor says that it will invest $2 billion to build the facility, which will "employ approximately 2,000 people" and "is targeted to be ready for production within the next two to three years." Apple says that it has already worked with Amkor on chip packaging for "more than a decade."

    Read 5 remaining paragraphs | Comments

    • chevron_right

      MacBook Air gets solid-state active cooling in intriguing demo

      news.movim.eu / ArsTechnica · Wednesday, 29 November, 2023 - 18:46

    MacBook Air with AirJet Mini

    Enlarge / The active cooling chips are labeled and located in the upper-left corner near a custom heatsink in the 15-inch MacBook Air. (credit: Frore Systems )

    What if laptops could get fan-level cooling without moving parts? We could get thinner laptops, for one. We could also potentially squeeze more performance out of today's already impressively thin designs.

    That's what San Jose, California startup Frore Systems is trying to convince laptop makers of as it looks for the first OEM to adopt what it describes as the first solid-state active cooling chip.

    Most recently, the company equipped the M2 15-inch MacBook Air with three of its chips, dubbed AirJet Minis. Media witnesses to a recent demonstration reported that the chips helped bring MacBook Pro-comparable performance to sustained heavy workloads on the MacBook Air.

    Read 24 remaining paragraphs | Comments