The Morning After: OpenAI’s week of security issues

Perhaps unsurprisingly, July 4th was a quiet day for news, but we’ve still got editorials on e-ink writing, the most-delayed video game ever and more bad news from the makers of ChatGPT. 

Earlier this week, engineer and Swift developer Pedro José Pereira Vieito dug into OpenAI's Mac ChatGPT app and found that it was storing user conversations locally in plain text, rather than encrypting them. Because that app is only available from OpenAI's website, and since it's not available on the App Store, it doesn't have to follow Apple's sandboxing requirements. OpenAI released an update that added encryption to locally stored chats.

Then, more bad news stemmed from issues in 2023. Last spring, a hacker obtained information about OpenAI after illicitly accessing the company's internal messaging systems. The New York Times reported that OpenAI technical program manager Leopold Aschenbrenner raised security concerns, arguing that the hack implied internal vulnerabilities.

Aschenbrenner now says he was fired for disclosing information about OpenAI and for surfacing security concerns. A representative from OpenAI told The Times that “while we share his commitment to building safe A.G.I., we disagree with many of the claims he has since made about our work” and added that his exit was not the result of whistleblowing.

It adds to an increasingly messy impression of how the company’s oversight and practices can be behind those closed corporate doors.

– Mat Smith

Finding the joy in writing again with the Supernote Nomad

FTC warns some PC manufacturers that they're violating right to repair rules

The most-delayed video game in history is finally available… on the Game Boy Advance

​​You can get these reports delivered daily direct to your inbox. Subscribe right here!

The Federal Trade Commission's (FTC) ban on noncompete agreements was supposed to take effect on September 4, but a Texan court has postponed its implementation. "Noncompete clauses keep wages low, suppress new ideas, and rob the American economy of dynamism," FTC Chair Lina M. Khan said when the rule was announced. So, surprise, a lot of companies are unhappy with the agency's rule. Dallas tax services firm Ryan LLC sued the FTC hours after its announcement. But the Chamber of Commerce’s chief counsel Daryl Joseffer called the ban an attempt by the government to micromanage business decision.

Continue reading.

TMA
Engadget

Picking a portable Bluetooth speaker can be tough. With so many options, finding the right mix of sound quality, durability, and portability is key. We tested dozens of speakers to help you choose, focusing on versatile portable speakers, not smart speakers. We've identified top performers for different needs, whether you want strong bass, long battery life, or a tough build.

Continue reading.

This article originally appeared on Engadget at https://www.engadget.com/the-morning-after-openais-week-of-security-issues-111545506.html?src=rss

The Morning After: OpenAI’s week of security issues

Perhaps unsurprisingly, July 4th was a quiet day for news, but we’ve still got editorials on e-ink writing, the most-delayed video game ever and more bad news from the makers of ChatGPT. 

Earlier this week, engineer and Swift developer Pedro José Pereira Vieito dug into OpenAI's Mac ChatGPT app and found that it was storing user conversations locally in plain text, rather than encrypting them. Because that app is only available from OpenAI's website, and since it's not available on the App Store, it doesn't have to follow Apple's sandboxing requirements. OpenAI released an update that added encryption to locally stored chats.

Then, more bad news stemmed from issues in 2023. Last spring, a hacker obtained information about OpenAI after illicitly accessing the company's internal messaging systems. The New York Times reported that OpenAI technical program manager Leopold Aschenbrenner raised security concerns, arguing that the hack implied internal vulnerabilities.

Aschenbrenner now says he was fired for disclosing information about OpenAI and for surfacing security concerns. A representative from OpenAI told The Times that “while we share his commitment to building safe A.G.I., we disagree with many of the claims he has since made about our work” and added that his exit was not the result of whistleblowing.

It adds to an increasingly messy impression of how the company’s oversight and practices can be behind those closed corporate doors.

– Mat Smith

Finding the joy in writing again with the Supernote Nomad

FTC warns some PC manufacturers that they're violating right to repair rules

The most-delayed video game in history is finally available… on the Game Boy Advance

​​You can get these reports delivered daily direct to your inbox. Subscribe right here!

The Federal Trade Commission's (FTC) ban on noncompete agreements was supposed to take effect on September 4, but a Texan court has postponed its implementation. "Noncompete clauses keep wages low, suppress new ideas, and rob the American economy of dynamism," FTC Chair Lina M. Khan said when the rule was announced. So, surprise, a lot of companies are unhappy with the agency's rule. Dallas tax services firm Ryan LLC sued the FTC hours after its announcement. But the Chamber of Commerce’s chief counsel Daryl Joseffer called the ban an attempt by the government to micromanage business decision.

Continue reading.

TMA
Engadget

Picking a portable Bluetooth speaker can be tough. With so many options, finding the right mix of sound quality, durability, and portability is key. We tested dozens of speakers to help you choose, focusing on versatile portable speakers, not smart speakers. We've identified top performers for different needs, whether you want strong bass, long battery life, or a tough build.

Continue reading.

This article originally appeared on Engadget at https://www.engadget.com/the-morning-after-openais-week-of-security-issues-111545506.html?src=rss

OpenAI hit by two big security issues this week

OpenAI seems to make headlines every day and this time it's for a double dose of security concerns. The first issue centers on the Mac app for ChatGPT, while the second hints at broader concerns about how the company is handling its cybersecurity.

Earlier this week, engineer and Swift developer Pedro José Pereira Vieito dug into the Mac ChatGPT app and found that it was storing user conversations locally in plain text rather than encrypting them. The app is only available from OpenAI's website, and since it's not available on the App Store, it doesn't have to follow Apple's sandboxing requirements. Vieito's work was then covered by The Verge, and after the exploit attracted attention, OpenAI released an update that added encryption to locally stored chats.

For the non-developers out there, sandboxing is a security practice that keeps potential vulnerabilities and failures from spreading from one application to others on a machine. And for non-security experts, storing local files in plain text means potentially sensitive data can be easily viewed by other apps or malware.

The second issue occurred in 2023 with consequences that have had a ripple effect continuing today. Last spring, a hacker was able to obtain information about OpenAI after illicitly accessing the company's internal messaging systems. The New York Times reported that OpenAI technical program manager Leopold Aschenbrenner raised security concerns with the company's board of directors, arguing that the hack implied internal vulnerabilities that foreign adversaries could take advantage of.

Aschenbrenner now says he was fired for disclosing information about OpenAI and for surfacing concerns about the company’s security. A representative from OpenAI told The Times that “while we share his commitment to building safe A.G.I., we disagree with many of the claims he has since made about our work” and added that his exit was not the result of whistleblowing.

App vulnerabilities are something that every tech company has experienced. Breaches by hackers are also depressingly common, as are contentious relationships between whistleblowers and their former employers. However, between how broadly ChatGPT has been adopted into major players' services and how chaotic the company's oversight, practices and public reputation have been, these recent issues are beginning to paint a more worrying picture about whether OpenAI can manage its data.

This article originally appeared on Engadget at https://www.engadget.com/openai-hit-by-two-big-security-issues-this-week-214316082.html?src=rss

OpenAI hit by two big security issues this week

OpenAI seems to make headlines every day and this time it's for a double dose of security concerns. The first issue centers on the Mac app for ChatGPT, while the second hints at broader concerns about how the company is handling its cybersecurity.

Earlier this week, engineer and Swift developer Pedro José Pereira Vieito dug into the Mac ChatGPT app and found that it was storing user conversations locally in plain text rather than encrypting them. The app is only available from OpenAI's website, and since it's not available on the App Store, it doesn't have to follow Apple's sandboxing requirements. Vieito's work was then covered by The Verge, and after the exploit attracted attention, OpenAI released an update that added encryption to locally stored chats.

For the non-developers out there, sandboxing is a security practice that keeps potential vulnerabilities and failures from spreading from one application to others on a machine. And for non-security experts, storing local files in plain text means potentially sensitive data can be easily viewed by other apps or malware.

The second issue occurred in 2023 with consequences that have had a ripple effect continuing today. Last spring, a hacker was able to obtain information about OpenAI after illicitly accessing the company's internal messaging systems. The New York Times reported that OpenAI technical program manager Leopold Aschenbrenner raised security concerns with the company's board of directors, arguing that the hack implied internal vulnerabilities that foreign adversaries could take advantage of.

Aschenbrenner now says he was fired for disclosing information about OpenAI and for surfacing concerns about the company’s security. A representative from OpenAI told The Times that “while we share his commitment to building safe A.G.I., we disagree with many of the claims he has since made about our work” and added that his exit was not the result of whistleblowing.

App vulnerabilities are something that every tech company has experienced. Breaches by hackers are also depressingly common, as are contentious relationships between whistleblowers and their former employers. However, between how broadly ChatGPT has been adopted into major players' services and how chaotic the company's oversight, practices and public reputation have been, these recent issues are beginning to paint a more worrying picture about whether OpenAI can manage its data.

This article originally appeared on Engadget at https://www.engadget.com/openai-hit-by-two-big-security-issues-this-week-214316082.html?src=rss

Nintendo ends Wii U repairs

Earlier this year, Nintendo said it would shut down all Wii U servers, putting an end to multiplayer, co-op and other services. Now, the company has announced that it's ending Wii U repairs as well, effectively giving last rites to the loveable but not very popular console.

In May, Nintendo forewarned the end of Wii U repairs. "The period for retaining repair parts as stipulated in the repair service regulations has expired, so as soon as the current stock of parts is depleted, repair services will end," the company wrote in a service notice. The Wii U is now listed as no longer eligible for repair on an end-of-life service page, just as Nintendo previewed.

The Wii U launched in late 2012 as a successor to the Wii, but it failed to catch on with consumers, selling just 13.56 million units. It was eventually replaced by the Switch, which has gone on to more than 10 times the sales at 141.3 million units.

The defining feature of the Wii U was its Gamepad with a built-in 6.2-inch touchscreen. That allowed you to play either fully handheld or connected to a TV, a new feature at the time. The other key selling point was the first-party games like Splatoon, Super Smash Bros. for Wii U, Mario Kart 8 and Super Mario 3D World. At the time, those offered local multiplayer action you couldn't find anywhere else.

It was also just a quirky, weird and fun console that "wiggled its way into the hearts of many players, including myself," Engadget's Jessica Conditt wrote back in 2015. Nintendo is set to announce its successor to the Switch before March 2025, but if you're still playing on Wii U, you'd need to take extra good care of it now that repairs will be far more challenging.

This article originally appeared on Engadget at https://www.engadget.com/nintendo-ends-wii-u-repairs-190023430.html?src=rss

You can now get AI Judy Garland or James Dean to read you the news

I love an account on X (formerly Twitter) called @LizaMinnelliOutlives (shockingly not run by the icon herself) that lists things like famous deaths or agreements. Well, in a twist, the real Liza Minnelli no longer outlives new words from her deceased mother, Judy Garland. The actress and singer has given ElevenLabs, an AI startup with cloning services, permission to recreate her mother's voice for their new Reader App. Garland joins James Dean, Burt Reynolds and Sir Laurence Olivier as deceased stars whose AI voices are in the "Iconic voice collection," thanks to deals with their estates for undisclosed sums. 

The voices will exist solely on the Reader App and people can use them for things like narrating an e-book. "It's exciting to see our mother's voice available to the countless millions of people who love her," Minnelli, the representative of the Garland Estate, said. "Through the spectacular new technology offered by ElevenLabs, our family believes that this will bring new fans to Mama, and be exciting to those who already cherish the unparalleled legacy that Mama gave and continues to give to the world." A sample of Garland reading The Wizard of Oz appears in ElevenLab's promotional video on YouTube — personally, I find it a little bit eerie, but I can see the appeal. 

ElevenLabs released its Reader App in late June to allow users to hear any text on their phone, including messages, PDFs and news articles. It's currently only available in English for iOS users in the United States, United Kingdom and Canada. However, ElevenLabs has a waitlist for Android users and claims it will launch in the Google Play store in the "coming weeks." The company also says it's working on making the app available in every language its Multilingual model supports (29 as of now) and will, subsequently, launch it globally.

This article originally appeared on Engadget at https://www.engadget.com/you-can-now-get-ai-judy-garland-or-james-dean-to-read-you-the-news-160023595.html?src=rss

I’m finding the joy in writing again with a little help from the Supernote Nomad

I've recently accepted the fact that I am, and always will be, a pen-and-paper kind of gal. When it comes to writing, nothing does it for me quite like the act of scrawling by hand. I’m more creative, less distracted and more emotionally invested in what I’m doing than when I type on a keyboard.

But over the last decade or so of writing professionally, I've become disconnected from writing by hand. I spend most of my time hunched over a laptop, and have unwittingly conditioned myself into writing almost exclusively in this way for the sake of efficiency. While that’s undoubtedly what works best for the day-to-day demands of news blogging (I mean, how else could we do it?), my shift away from notebooks has killed my will to do any creative writing outside of work. These days, every time I crack open a laptop to write in my off-hours, it feels like a chore.

But what also feels like a chore is typing up pages upon pages of handwritten text after dumping all the words in my brain out onto paper. This burden is what first got me looking into digital notepads; since many of them can convert handwritten notes to text files, they’re kind of the best of both worlds. For a while, though, none of the available options really spoke to me — the reMarkable 2 and other E Ink tablets are just too big for my taste. Then, Ratta came out with the Supernote Nomad, and I was sold.

The Nomad is perfectly compact. With a 7.8-inch screen, it’s more like the size of an ereader, meaning I can toss it in a mini-backpack and bring it with me everywhere — and I do. My Nomad arrived in May (I ordered the $329 Crystal version, because I’m a sucker for a transparent shell) and I've been using it just about every day since. I was cautiously optimistic about what actually writing on this thing would be like, but it exceeded all of my expectations.

It took only a few minutes to get used to, which mainly came down to me getting over my somewhat irrational fear that the pen — the one that’s made for this device — would scratch the display. (It was expensive, okay?) The tablet doesn’t come with a writing implement, and I shelled out a little extra for the $89 Heart of Metal pen, a decision I’m super happy with. It’s nothing like a stylus, but instead has a sharp, precision tip like a real pen — hence my initial hesitation.

The experience of writing on the Nomad is so close to the feeling of actually using a pen and paper. There’s texture to it, something you don’t get with the smooth experience of writing on an iPad. I write pretty fast, and haven't had many issues so far with lagging. It comes with a bunch of writing templates, including lined “paper” with a few different ruling size options, and you can create your own templates or download those made by others. I haven't messed around much yet with custom versions, though, because the built-in offerings have been adequate for free writing, note-taking and organizing my life.

I was pleasantly surprised by how well the handwriting recognition tool has been able to convert my chicken scratch to typed text. My handwriting is fine at best, but when I'm working fast, things can get pretty messy. It's not 100 percent accurate — it’ll throw in the occasional string of gibberish — but the device mostly gets it right. You can export the converted writing as a .TXT or .DOCX file, and have the Nomad format it for you. This requires some cleaning up, but it’s never a huge job.

Supernote devices can sync with a number of different cloud storage providers, like Dropbox and Google Drive (though Google is currently not working for me, so that’s one point against it), along with the company’s own cloud. You can lock individual files and folders behind a passcode, too, which I really appreciate. Nothing haunts me more than the thought of someone reading through my unfinished drafts, some of which aren’t destined to ever see the light of day.

And I’ve finally ditched my paper planner — something I never thought would happen. Supernote’s built-in monthly calendar and weekly planner have finally given me an alternative that actually works for me. One of the main things that’s kept me using paper planners is that I like to doodle as a way to make important events or tasks stand out, and the Supernote Nomad allows me to do this. The only thing I miss is using stickers and pens of different colors, but I’ll survive.

In the last month or so using the Supernote Nomad, I’ve probably gotten more writing done (the “for me” kind) than I had in the last year. It just doesn't trigger that dreaded “you’re at work” feeling that my laptop and even other distraction-free writing devices, like the Freewrite Traveler, have. Eventually, I hope to get around to drawing and reading on it as well, but for the moment, all I want to do on this thing is write because I'm having such a great time doing it. And before you ask — yes, I wrote this article on my Nomad.

This article originally appeared on Engadget at https://www.engadget.com/im-finding-the-joy-in-writing-again-with-a-little-help-from-the-supernote-nomad-130048878.html?src=rss

FTC warns some PC manufacturers that they’re violating right to repair rules

The Federal Trade Commission (FTC) is reminding several computer companies that "warranty void if removed" stickers are illegal, as is language discouraging consumers from fixing their own devices. The Commission warned ASRock, Gigabyte and Zotech to get rid of them and remove terms threatening to void warranties if users break the seal, it wrote in a press release spotted by The Verge

"Letters to three other companies warn against their use of stickers containing 'warranty void if removed' or similar language that are placed in locations on products that hinder consumers’ ability to perform routine maintenance and repairs on their products," the FTC wrote. "These letters were issued to ASRock, Zotac, and Gigabyte, companies that market and sell gaming PCs, graphics chips, motherboards, and other accessories."

It wasn't just the stickers, but language in the warranties stating that guarantees would be voided if said seals were broken. The practices "may be standing in the way of consumers' right to repair products they have purchased," according to the release. Commission staff will review the companies' websites after 30 days and failure to correct violations may result in law enforcement action. 

Right to repair laws have spread across US states, but the FTC is actually referencing decades-old rules. Under the 1975 Magnuson-Moss Warranty Act, companies can't place restrictions on repairs unless they provide the parts or services for free or receive a waiver from the FTC. 

This isn't a new occurrence, as we wrote about a similar warning from the FTC way back in 2018. At that time, the watchdog sent warnings to six companies: Nintendo, Sony, Microsoft, ASUS, HTC and Hyundai. Such stickers and policies aren't necessarily illegal in other nations though, as iFixit wrote last year

This article originally appeared on Engadget at https://www.engadget.com/ftc-warns-some-pc-manufacturers-that-theyre-violating-right-to-repair-rules-120009736.html?src=rss

The Morning After: Samsung’s Galaxy Z Flip 6 and Fold 6 leak early

We already told you what to expect, but if you demand more proof, the leakers will oblige. This time, @evleaks on X released copies of product pages (and images) for the Galaxy Z Fold 6 and Galaxy Z Flip 6.

The main spec changes are for the flip. Previous Galaxy Z Flip models only had 12-megapixel rear cameras, so the Flip 6's purported 50-megapixel wide camera (paired with a 12-megapixel ultrawide) is a huge upgrade. If the leak is accurate, it'll also have a bigger battery.

According to the product pages, Samsung didn't give the Galaxy Z Fold 6 many substantial upgrades, but the new model will have a slightly larger front display. Conversely, the folding main display is slightly smaller and the phone is a bit thinner.

The leak spoils Samsung’s July 10 party a little, but we reckon the company has plenty more to show off, including the official debut of its Galaxy Ring, Galaxy Watch 7, Galaxy Watch Ultra, Galaxy Buds 3 and Galaxy Buds 3 Pro. That’s a lot to get through in a single presentation — hopefully, Samsung keeps a tight run-time for my sanity.

– Mat Smith

Your next webcam could be a Game Boy Camera

The best early Amazon Prime Day deals for 2024

What Meta should change about Threads

​​You can get these reports delivered daily direct to your inbox. Subscribe right here!

TMA
Getty images

Japan’s Digital Agency announced on Wednesday it ditched the use of outdated floppy disks to operate its government computer systems. The only system still in place that requires the use of floppy disks is an environmental system that monitors vehicle recycling, according to Reuters. Digital Minister Taro Kono told the news agency in a statement, “We have won the war on floppy disks on June 28!”

Kono’s battle against outdated tech in government departments started in 2022. I. The country’s love affair with fax machines is well known — Kono has his sights on those next.

Continue reading.

While some apps still need extra support to run on Windows on Arm, the Surface Laptop 7 and Qualcomm’s Snapdragon X Elite chip have combined to create a nearly ideal platform for everyday productivity. The design is appealing, the battery life is excellent and the display is bright. The price is premium, starting at $1,300, but Microsoft has finally nailed the Arm-powered laptop.

Continue reading.

Proton now has its own version of Google Docs in its own cloud storage service, and like the company's other products, it comes with end-to-end encryption. The company says its flavor of Docs "offers a unique solution in a market where most popular products neglect privacy" and recommends it for use in the healthcare, media, finance, and legal industries. Like Google Docs, Proton Docs has advanced formatting and image embed options. You’ll also be able to pull other document formats into Proton for editing, like Word files.

Continue reading.

This article originally appeared on Engadget at https://www.engadget.com/the-morning-after-samsungs-galaxy-z-flip-6-and-fold-6-leak-early-111522211.html?src=rss

The best 4th of July sales from Apple, Amazon, Anker and more

July 4 isn't really a boon for tech deals. Seasonal sales can be hit or miss if you have things like headphones, tablets and other tech gear on your shopping list — you're actually better off looking for early Prime Day deals (if you're a Prime member) right now, since Amazon has already kicked off the discounts in preparation for its July Prime Day event. But we scoured the internet to find as many of the worthwhile tech deals you can get for July 4 — many of them overlap with Prime Day deals, but there are some from the likes of Solo Stove, Casetify, ThermoWorks and others that appear to be limited-time, seasonal discounts. Here are the best July 4 tech deals you can get this year.

Follow @EngadgetDeals on Twitter and subscribe to the Engadget Deals newsletter for the latest tech deals and buying advice.

This article originally appeared on Engadget at https://www.engadget.com/the-best-4th-of-july-sales-from-apple-amazon-anker-and-more-090027133.html?src=rss