Huston: Revisiting time

Geoff Huston looks at the network
time protocol
, and efforts to secure it, in detail.

NTP operates in the clear, and it is often the case that the
servers used by a client are not local. This provides an
opportunity for an adversary to disrupt an NTP session, by
masquerading as a NTP server, or altering NTP payloads in an effort
to disrupt a client’s time-of-day clock. Many application-level
protocols are time sensitive, including TLS, HTTPS, DNSSEC and
NFS. Most Cloud applications rely on a coordinated time to
determine the most recent version of a data object. Disrupting time
can cause significant chaos in distributed network environments.

While it can be relatively straightforward to secure a TCP-based
protocol by adding an initial TLS handshake and operating a TLS
shim between TCP and the application traffic, it’s not so
straightforward to use TLS in place of a UDP-based protocol for
NTP. TLS can add significant jitter to the packet exchange. Where
the privacy of the UDP payload is essential, then DTLS might
conceivably be considered, but in the case of NTP the privacy of
the timestamps is not essential, but the veracity and authenticity
of the server is important.

NTS, a secured version of NTP, is designed to address this
requirement relating to the veracity and authenticity of packets
passed from a NTS server to an NTS client. The protocol adds a NTS
Key Establishment protocol (NTS-KE) in additional to a conventional
NTPv4 UDP packet exchange (RFC 8915).

How Anthropic’s Claude Helped Mozilla to Improve Firefox’s Security

“It took Anthropic’s most advanced artificial-intelligence model about 20 minutes to find its first Firefox browser bug during an internal test of its hacking prowess,” reports the Wall Street Journal.

The Anthropic team submitted it, and Firefox’s developers quickly wrote back: This bug was serious. Could they get on a call? “What else do you have? Send us more,” said Brian Grinstead, an engineer with Mozilla, Firefox’s parent organization.
Anthropic did. Over a two-week period in January, Claude Opus 4.6 found more high-severity bugs in Firefox than the rest of the world typically reports in two months, Mozilla said… In the two weeks it was scanning, Claude discovered more than 100 bugs in total, 14 of which were considered “high severity…” Last year, Firefox patched 73 bugs that it rated as either high severity or critical.

A Mozilla blog post calls Firefox “one of the most scrutinized and security-hardened codebases on the web. Open source means our code is visible, reviewable, and continuously stress-tested by a global community.” So they’re impressed — and also thankful Anthropic provided test cases “that allowed our security team to quickly verify and reproduce each issue.”
Within hours, our platform engineers began landing fixes, and we kicked off a tight collaboration with Anthropic to apply the same technique across the rest of the browser codebase… . A number of the lower-severity findings were assertion failures, which overlapped with issues traditionally found through fuzzing, an automated testing technique that feeds software huge numbers of unexpected inputs to trigger crashes and bugs. However, the model also identified distinct classes of logic errors that fuzzers had not previously uncovered…

We view this as clear evidence that large-scale, AI-assisted analysis is a powerful new addition in security engineers’ toolbox. Firefox has undergone some of the most extensive fuzzing, static analysis, and regular security review over decades. Despite this, the model was able to reveal many previously unknown bugs. This is analogous to the early days of fuzzing; there is likely a substantial backlog of now-discoverable bugs across widely deployed software.

“In the time it took us to validate and submit this first vulnerability to Firefox, Claude had already discovered fifty more unique crashing inputs” in 6,000 C++ files, Anthropic says in a blog post (which points out they’ve also used Claude Opus 4.6 to discover vulnerabilities in the Linux kernel).

“Anthropic “also rolled out Claude Code Security, an automated code security testing tool, last month,” reports Axios, noting the move briefly rattled cybersecurity stocks…


Read more of this story at Slashdot.

OpenAI’s head of robotics resigns following deal with the Department of Defense

OpenAI is going to need to find a new head of robotics. Caitlin Kalinowski, OpenAI’s now-former head of robotics, posted on X that she was resigning from her role, while criticizing the company’s haste in partnering with the Department of Defense without investigating proper guardrails.

Kalinowski, who previously worked at Meta before leaving to join OpenAI in late 2024, wrote on X that “surveillance of Americans without judicial oversight and lethal autonomy without human authorization are lines that deserved more deliberation than they got.” Responding to another post, the former OpenAI exec explained that “the announcement was rushed without the guardrails defined,” adding that it was a “governance concern first and foremost.”

OpenAI confirmed Kalinowski’s resignation and said in a statement to Engadget that the company understands people have “strong views” about these issues and will continue to engage in discussions with relevant parties. The company also explained in the statement that it doesn’t support the issues that Kalinowski brought up.

“We believe our agreement with the Pentagon creates a workable path for responsible national security uses of AI while making clear our red lines: no domestic surveillance and no autonomous weapons,” the OpenAI statement read.

Kalinowski’s resignation may be the most high-profile fallout from OpenAI’s decision to sign a deal with the Department of Defense. The decision came just after Anthropic refused to comply with lifting certain AI guardrails around mass surveillance and developing fully autonomous weapons. However, even OpenAI’s CEO, Sam Altman, said that he would amend the deal with the Department of Defense to prohibit spying on Americans.

This article originally appeared on Engadget at https://www.engadget.com/ai/openais-head-of-robotics-resigns-following-deal-with-the-department-of-defense-195918777.html?src=rss

Intel Panther Lake-H High-Res Die Shots Reveal 18A CPU Design

Intel Panther Lake-H High-Res Die Shots Reveal 18A CPU Design
In case you missed the memo, Intel’s been kicking butt in the mobile arena lately. Its Core Ultra 200V “Lunar Lake” processors offered a great blend of CPU compute, GPU horsepower, and excellent power efficiency, and the latest Core Ultra 300 “Panther Lake” chips continue that trend, ramping up performance in every area while maintaining fantastic

Military GPS Jamming is Interfering with the Navigation Systems of Commercial Ships

“Within 24 hours of the first US-Israeli strikes on Iran, ships in the region’s waters found their navigation systems had gone haywire,” reports CNN, “erroneously indicating that the vessels were at airports, a nuclear power plant and on Iranian land.

“The location confusion was a result of widespread jamming and spoofing of signals from global positioning satellite systems.”

Used by all sides in conflict zones to disrupt the paths of drones and missiles, the process involves militaries and affiliated groups intentionally broadcasting high-intensity radio signals in the same frequency bands used by navigation tools. Jamming results in the disruption of a vehicle’s satellite-based positioning while spoofing leads to navigation systems reporting a false location. Though commercial vessels are not the target, the electronic interference disrupted the navigation systems of more than 1,100 commercial ships in UAE, Qatari, Omani and Iranian waters on February 28, according to a report from Windward, a shipping intelligence firm. Jamming and spoofing also slowed marine traffic moving through the Strait of Hormuz, a congested shipping lane that handles roughly 20% of the world’s oil and gas exports and where precise navigation is essential, Windward’s data showed…. Daily incidents have more than doubled, rising from 350 when the conflict began to 672 by March 2, the firm reported.

As use of this warfare tactic grows, experts worry the impacts could reach far beyond battlespaces…. In June 2025, electronic interference with navigation systems was thought to be a factor in the collision between two oil tankers, Adalynn and Front Eagle, off the coast of the UAE… The number of global positioning system signal loss events affecting aircraft increased by 220% between 2021 and 2024, according to data from the International Air Transport Association. Last year, IATA said that the aviation industry must act to stay ahead of the threat.

Cockpits are seeing their navigation displays “literally drift away from reality,” said a commercial pilot, who didn’t want to be identified because he was not permitted to speak publicly. He said that he and his colleagues have experienced map shifts, where the aircraft location appears to move up to 1 mile away from the actual flight path, false altitude information that leads to phantom “pull up” commands, and systems suggesting an aircraft was on a taxiway, a path that connects runways with various airport facilities, when taking off. These incidents force pilots to rely on manual actions that increase workload, often during the most exhausting points of long-haul flights, he said.

“Alternative navigational tools that don’t rely on GPS, but instead harness quantum technology, are also in development,” the article points out, “but remain a long way off operational use.”


Read more of this story at Slashdot.

Valve’s Steam Machine 2026 Release Date And Pricing Reveal Could Be Soon

Valve’s Steam Machine 2026 Release Date And Pricing Reveal Could Be Soon
Some signs are pointing toward an imminent release date and pricing reveal for the Steam Machine, Steam Frame, and Steam Controller. Not only did Valve recently release a blog post reaffirming its commitment to “shipping all three products this year”, but data miners on SteamDB noticed a “Coming soon” listing change for all of the new Steam

Indonesia announces a social media ban for anyone under 16

Following in the footsteps of Australia, Indonesia will be the latest country to limit social media usage for children under 16. Meutya Hafid, Indonesia’s communication and digital affairs minister, announced that a new government regulation will require “high-risk” platforms to delete any accounts from Indonesia that are under 16, starting on March 28.

Hafid said in the announcement that the implementation would be done in stages, starting with major platforms like YouTube, TikTok, Facebook, Instagram, Threads, X, Roblox and Bigo Live, a live-streaming platform based in Singapore. The minister added that all platforms will have to fulfill compliance obligations from the Indonesian government, but didn’t specify what they were. In response to the ban, a Meta spokesperson told The New York Times that the company hasn’t received an official regulation from the country yet and was awaiting details.

While Australia was the first country to implement such a sweeping ban on social media, many other countries are currently in the process of doing the same. Spain’s Prime Minister Pedro Sanchez announced last month that the country is also ready to ban social media for users under 16, while Malaysia‘s cabinet approved a similar ban that will reportedly go into effect sometime this year.

This article originally appeared on Engadget at https://www.engadget.com/social-media/indonesia-announces-a-social-media-ban-for-anyone-under-16-174634956.html?src=rss

Seagate Just Unleashed 44TB Hard Drives

“Seagate says it is now shipping its Mozaic 4+ HAMR-based hard drives at up to 44TB per drive,” writes Slashdot reader BrianFagioli, “with production deployments already underway at two hyperscale cloud providers.

“The company claims the platform is the only heat-assisted magnetic recording [HAMR] implementation currently operating at scale, and it is targeting a path from today’s 4+TB per disk toward 10TB per disk, eventually enabling 100TB-class drives.”

In a one-exabyte deployment, Seagate estimates Mozaic could improve infrastructure efficiency by roughly 47% compared to standard 30TB drives, cutting both footprint and energy consumption… HAMR uses a tiny laser to heat the disk surface during writes, allowing higher recording density without sacrificing stability. With most major cloud storage providers reportedly qualified on the Mozaic platform, Seagate is positioning spinning disks, not flash, as the long-term answer for cost-effective AI-scale data growth.


Read more of this story at Slashdot.

First Solar Car Rolls Off Validation Assembly Line At Aptera

“Reservation holders, it’s finally time to get ready,” writes long-time Slashdot reader AirHog. The EV news site Electrek reports:

Aptera Motors, “the little startup that could,” announced another important milestone… completing the first example of its flagship solar EV on its validation assembly line in Southern California…

While the validation line at its headquarters remains a low-volume assembly process, its successful operation represents the startup’s transition from hand-built validation SEVs to a more structured assembly line process that will be fine-tuned for mass production… With low-volume assembly now being validated, Aptera is starting to publicly utter encouraging terms like “EPA certification” and, better yet, that holy grail of “initial customer deliveries.” Before then, however, the Aptera Solar EVs built on this low-volume validation line will be used for testing programs such as thermal validation, brake performance, and “some destructive testing.” Aptera shared that its assembly and integration team has grown to become the largest at the startup, “reflecting the beginning of its transition from engineering development to testing and production execution”…

As of March 2026, Aptera says it has over 50,000 reservations totaling over $2 billion in sales if all were to solidify following the launch of a deliverable vehicle.

Clean Technica notes the vehicles’ “generous cargo space that comes out to 60% more storage than a Honda Accord and 20% more storage than a Prius, according to the company.”
“Built with recyclable materials, this eco-friendly vehicle features a lightweight carbon fiber structure and no-welding assembly for maximum cost and production efficiency,” Aptera adds. The emphasis on lightweighting supports the goal of engineering a car that can travel on the electricity provided by its onboard solar panels.

The company currently advertises that the vehicle can travel 40 miles on solar power alone, with the battery providing extra juice as needed. Ideally, the car can keep recharging itself with sunlight, further elongating the time between charging sessions… [Its range is up to 1,000 miles with plug-in charging.] The new autocycle could also appeal to drivers who enjoy the challenge of hypermiling, which involves deploying a suite of driving techniques to minimize fuel consumption. Hypermiling can apply to gas-powered cars, but the magic really kicks in with the regenerative braking capability of EVs. Aptera’s onboard solar panels add another dimension to the fun.


Read more of this story at Slashdot.

Roblox introduces real-time AI-powered chat rephraser for inappropriate language

Roblox has launched a feature powered by AI that can rephrase inappropriate language in real time. The online game has been using AI filters to block out any language that goes against its policy for a while now, but it has been replacing censored chats with a series of hash signs (####). Roblox admits that encountering too many hashmarks can be disruptive and make conversations hard to follow. This new feature will instead replace words and phrases with what the AI deems as more appropriate substitutes.

Rajiv Bhatia, Roblox’s Chief Safety Office, said the game is starting with profanity. For instance, if a user sends “Hurry TF up” in chat, the system will replace it with “Hurry up!” Everyone in the chat will see a note when a message has been rephrased, and the sender will see what language was edited out. A user who keeps cursing in chat will still be penalized for breaking Roblox policy even if the AI rephrases their messages. “As these systems scale, they create a flywheel for civility, where real-time feedback helps users learn and adopt our Community Standards,” Bhatia said in a blog post.

Rephrasing has been rolled out to chats between age-checked users in similar age groups and in all the languages the game’s translation tool supports. Roblox introduced a mandatory age verification system back in January after reports came out that it has a “pedophile problem,” with adult players allegedly using the game to groom children. Kids under 13 can no longer use in-game chat outside of certain experiences, while everyone else can chat with players around their age. Age check, however, hasn’t stopped authorities from suing Roblox: LA County, in a lawsuit filed in February, said Roblox knows its platform “makes children easy prey for pedophiles.” Louisiana’s AG has also just filed a lawsuit, saying Roblox “created a public park and filled it with sex predators that are preying on… children.”

This article originally appeared on Engadget at https://www.engadget.com/gaming/roblox-introduces-real-time-ai-powered-chat-rephraser-for-inappropriate-language-160000063.html?src=rss

Prediction Market ‘Kalshi’ Sued for Not Paying $54 Million for Bets on Khamenei’s Death

An anonymous reader shared this report from the Independent:

A popular predictions market app will not pay out the $54 million some of its users believed they were owed after correctly forecasting the death of Ayatollah Ali Khamenei, according to a report.

Kalshi, which allows players to gamble on real-world events, offered customers favorable odds on Khamenei, 86, being “out as Supreme Leader” in response to the announcement of joint U.S.-Israeli airstrikes on Tehran in the early hours of Saturday morning. The company promoted the trade on its homepage and app and tweeted [last] Saturday: “BREAKING: The odds Ali Khamenei is out as Supreme Leader have surged to 68 percent.” It continued: “Reminder: Kalshi does not offer markets that settle on death. If Ali Khamenei dies, the market will resolve based on the last traded price prior to confirmed reporting of death.” Khamenei was later confirmed dead in the airstrikes and the company clarified in a follow-up post: “Please note: A prior version of this clarification was grammatically ambiguous. As a customer service measure, Kalshi will reimburse lost value due to trades made between these clarifications….”

While the company has offered to reimburse any bets, fees or losses from the trade placed prior to its clarification message, it has nevertheless attracted a firestorm of complaints on social media.
A Kalshi spokesperson told Reuters they’d reimbursed “net losses” out of pocket “to the tune of millions of dollars”. But a class action lawsuit was filed Thursday saying Kalshi had failed to pay $54 million:

Kalshi did not invoke a “death carveout” provision until after the Iranian leader was killed to avoid paying customers in Kalshi’s “Khamenei Market” what they were owed, the lawsuit said… The language specifying that Khamenei’s departure could be due to any cause, including death, was “clear, unambiguous and binary,” the lawsuit said, describing Kalshi’s actions as “deceptive” and “predatory.”

“In a notice filed Monday, the company proposed standardizing the terms of all its markets that implicitly depend on a person surviving…” reports Business Insider. “The update comes after Kalshi paid $2.2 million to resolve complaints from users who were confused by the way it divided the $55 million wagered on Iran’s Supreme Leader Ali Khamenei’s ouster after his targeted killing by Israel and the US.”

Their article cites a DePaul University law professor who says “There’s now sort of this nascent, but bipartisan movement against prediction markets. I think Kalshi’s feeling the heat.” For example, U.S. Senator Chris Murphy told the Washington Post, “People shouldn’t be rooting for people to die because they placed a bet.”


Read more of this story at Slashdot.