Skip to main content

Millions of AirPlay Devices Can Be Hacked Over Wi-Fi

1 day 8 hours ago
A newly revealed set of vulnerabilities dubbed AirBorne in Apple's AirPlay SDK could allow attackers on the same Wi-Fi network to hijack tens of millions of third-party devices like smart TVs and speakers. While Apple has patched its own products, many third-party devices remain at risk, with the most severe (though unproven) threat being potential microphone access. 9to5Mac reports: Wired reports that a vulnerability in Apple's software development kit (SDK) means that tens of millions of those devices could be compromised by an attacker: "On Tuesday, researchers from the cybersecurity firm Oligo revealed what they're calling AirBorne, a collection of vulnerabilities affecting AirPlay, Apple's proprietary radio-based protocol for local wireless communication. Bugs in Apple's AirPlay software development kit (SDK) for third-party devices would allow hackers to hijack gadgets like speakers, receivers, set-top boxes, or smart TVs if they're on the same Wi-Fi network as the hacker's machine [...] Oligo's chief technology officer and cofounder, Gal Elbaz, estimates that potentially vulnerable third-party AirPlay-enabled devices number in the tens of millions. 'Because AirPlay is supported in such a wide variety of devices, there are a lot that will take years to patch -- or they will never be patched,' Elbaz says. 'And it's all because of vulnerabilities in one piece of software that affects everything.'" For consumers, an attacker would first need to gain access to your home Wi-Fi network. The risk of this depends on the security of your router: millions of wireless routers also have serious security flaws, but access would be limited to the range of your Wi-Fi. AirPlay devices on public networks, like those used everywhere from coffee shops to airports, would allow direct access. The researchers say the worst-case scenario would be an attacker gaining access to the microphones in an AirPlay device, such as those in smart speakers. However, they have not demonstrated this capability, meaning it remains theoretical for now.

Read more of this story at Slashdot.

BeauHD

With Its Llama API Service, Meta Platforms Finally Becomes A Cloud

1 day 8 hours ago

A lot of companies talk about open source, but it can be fairly argued that Meta Platforms, the company that built the largest social network in the world and that has open sourced a ton of infrastructure software as well as datacenter, server, storage, and switch designs, walks the talk the best. …

With Its Llama API Service, Meta Platforms Finally Becomes A Cloud was written by Timothy Prickett Morgan at The Next Platform.

Timothy Prickett Morgan

Google Funding Electrician Training As AI Power Crunch Intensifies

1 day 8 hours ago
Google is investing in training over 100,000 new U.S. electricians through a $10 million grant, aiming to address a critical labor shortage driven by AI-fueled data center growth and rising electricity demands. Reuters reports: A lack of access to power supplies has become the biggest problem for giant technology companies racing to develop artificial intelligence in energy-intensive data centers, which are driving up U.S. electricity demand after nearly 20 years of stagnation. The situation has led President Donald Trump to declare a national energy emergency aimed at speeding up permitting for generation and transmission projects. Google's funding, which includes a $10 million grant for electrical worker nonprofits, is the latest in a series of recent moves by giant technology companies to alleviate power project backlogs and electricity shortfalls across the United States. [...] The Google grant will be used for electrician apprenticeship programs and the training of existing workforce through organizations, including the Electrical Training Alliance, International Brotherhood of Electrical Workers and the National Electrical Contractors Association. It could increase the pipeline of electrical workers by 70% by the end of the decade, the company said. "This initiative with Google and our partners at NECA and the Electrical Training Alliance will bring more than 100,000 sorely needed electricians into the trade to meet the demands of an AI-driven surge in data centers and power generation," said Kenneth Cooper, international president of the IBEW labor union.

Read more of this story at Slashdot.

BeauHD

Musk’s DOGE probed by top watchdog after poking around Uncle Sam's systems

1 day 9 hours ago
Oligarch's crew makes audits harder, US comptroller general tells Congress

The US Government Accountability Office has confirmed it launched audits of Elon Musk's Trump-blessed cost-trimming DOGE unit amid concerns that its access to agency systems may be complicating oversight and involving sensitive data.…

Brandon Vigliarolo

Raspberry Pi Cuts Product Returns By 50% By Changing Up Its Pin Soldering

1 day 9 hours ago
An anonymous reader quotes a report from Ars Technica: Raspberry Pi boards have a combination of surface-mount devices (SMDs) and through-hole bits. SMDs allow for far more tiny chips, resistors, and other bits to be attached to boards by their tiny pins, flat contacts, solder balls, or other connections. For those things that are bigger, or subject to rough forces like clumsy human hands, through-hole soldering is still required, with leads poked through a connective hole and solder applied to connect and join them securely. The Raspberry Pi board has a 40-pin GPIO header on it that needs through-hole soldering, along with bits like the Ethernet and USB ports. These require robust solder joints, which can't be done the same way as with SMT (surface-mount technology) tools. "In the early days of Raspberry Pi, these parts were inserted by hand, and later by robotic placement," writes Roger Thornton, director of applications for Raspberry Pi, in a blog post. The boards then had to go through a follow-up wave soldering step. Now Pi boards have their tiny bits and bigger pieces soldered at the same time through an intrusive reflow soldering process undertaken with Raspberry Pi's UK manufacturing partner, Sony. After adjusting component placement, the solder stencil, and the connectors, the board makers could then place and secure all their components in the same stage. Intrusive reflow soldering this way involves putting solder paste on both the pads for SMD bits and into the through-hole pins. The through-hole parts are pushed onto the paste, and the whole board then goes into a reflow oven, where the solder paste melts, the connectors fall in more fully, and joints are formed for all the SMD and through-hole parts at once. You can watch the process up close in this mesmerizing video from Surface Mount Process. Intrusive reflow soldering is not a brand-new process, but what it did for the Raspberry Pi is notable, according to Thornton. The company saw "a massive 50% reduction in product returns," and it sped up production by 15 percent by eliminating the break between the two soldering stages. By removing the distinct soldering bath from its production line, the company also reduced its carbon dioxide output by 43 tonnes per year (or 47.4 US tons).

Read more of this story at Slashdot.

BeauHD