• Risks Digest 34.68 (2/2)

    From RISKS List Owner@21:1/5 to All on Mon Jun 23 19:09:21 2025
    [continued from previous message]

    https://nymag.com/intelligencer/article/metas-privacy-goof-shows-how-people-really-use-ai-chatbots.html

    ------------------------------

    Date: Sun, 15 Jun 2025 11:59:23 -0700
    From: Lauren Weinstein <lauren@vortex.com>
    Subject: Tesla blows past stopped school bus and hits kid-sized dummies in
    Full Self-Driving tests (Enadget)

    https://www.engadget.com/transportation/tesla-blows-past-stopped-school-bus-and-hits-kid-sized-dummies-in-full-self-driving-tests-183756251.html

    ------------------------------

    Date: Wed, 18 Jun 2025 20:14:13 -0700
    From: geoff goodfellow <geoff@iconia.com>
    Subject: Couple steals back their own car after tracking an AirTag in it

    *When London police wouldn't recover a stolen car despite an AirTag giving
    its location, the owners say they tracked it down and stole it back for themselves...* [...]

    https://appleinsider.com/articles/25/06/13/couple-steals-back-their-own-car-after-tracking-an-airtag-in-it

    ------------------------------

    Date: Fri, 13 Jun 2025 14:50:31 -0400
    From: "Steven J. Greenwald" <greenwald.steve@gmail.com>
    Subject: Finger Grease Mitigation for Tesla PIN Pad

    From Tesla, a post about how they have mitigated a threat to thieves
    trying to figure out a user's PIN by checking for finger grease on the
    touchscreen.

    "If you set up PIN to drive, a thief would not be able to drive off in your Tesla, even if they somehow gain access to your keycard, phone or vehicle

    "The PIN pad also appears in a slightly different place on the screen every time, so finger grease doesn't give away your PIN.''

    Link to source post on X:
    https://x.com/Tesla/status/1933516310475952191

    ------------------------------

    Date: Mon, 16 Jun 2025 15:15:43 -0700
    From: Lauren Weinstein <lauren@vortex.com>
    Subject: San Francisco bicyclist sues over crash involving 2 Waymo cars

    https://www.siliconvalley.com/2025/06/10/san-francisco-bicyclist-crash-waymo/

    ------------------------------

    Date: Tue, 17 Jun 2025 11:35:42 -0700
    From: "Jim" <jgeissman@socal.rr.com>
    Subject: I lost Spectrum for about two hours

    Would-be copper thieves caused Internet outage affecting LA and Ventura
    counties (LA Times)

    https://www.latimes.com/california/story/2025-06-15/would-be-copper-thieves- cause-internet-outage-affecting-l-a-ventura-counties

    ------------------------------

    Date: Tue, 17 Jun 2025 11:36:31 -0700
    From: "Jim" <jgeissman@socal.rr.com>
    Subject: How scammers are using AI to steal college financial aid (LA Times)

    https://www.latimes.com/california/story/2025-06-17/how-scammers-are-using-a i-to-steal-college-financial-aid

    Fake college enrollments have surged as crime rings deploy "ghost students," chatbots that join online classrooms and stay just long enough to collect a financial aid check. In some cases, professors discover almost no one in
    their class is real.

    ------------------------------

    Date: Fri, 13 Jun 2025 14:24:09 -0400
    From: Gabe Goldberg <gabe@gabegold.com>
    Subject: U.S. air traffic control still runs on Windows 95 and floppy
    disks (Ars Technica)

    Agency seeks contractors to modernize decades-old systems within four years.

    On Wednesday, acting FAA Administrator Chris Rocheleau told the House Appropriations Committee that the Federal Aviation Administration plans to replace its aging air traffic control systems, which still rely on floppy
    disks and Windows 95 computers, Tom's Hardware reports. The agency has
    issued a Request For Information to gather proposals from companies willing
    to tackle the massive infrastructure overhaul.

    "The whole idea is to replace the system. No more floppy disks or paper strips," Rocheleau said during the committee hearing. Transportation
    Secretary Sean Duffy called the project "the most important infrastructure project that we've had in this country for decades," describing it as a bipartisan priority.

    Most air traffic control towers and facilities across the US currently
    operate with technology that seems frozen in the 20th century, although that isn't necessarily a bad thing—when it works. Some controllers currently use paper strips to track aircraft movements and transfer data between systems using floppy disks, while their computers run Microsoft's Windows 95
    operating system, which launched in 1995.

    https://arstechnica.com/information-technology/2025/06/faa-to-retire-floppy-disks-and-windows-95-amid-air-traffic-control-overhaul/

    ------------------------------

    Date: Wed, 11 Jun 2025 19:02:24 -0700
    From: "Jim" <jgeissman@socal.rr.com>
    Subject: States sue to block the sale of genetic data collected by DNA
    testing company 23andMe (LA Times)

    Dozens of states have filed a joint lawsuit <https://www.washingtonpost.com/documents/809d3c27-44d5-4042-80a2-3ea3c1743d b2.pdf> against the bankrupt DNA-testing company 23andMe to block the
    company's sale of its customers' genetic data without explicit consent.

    The suit, filed this week in U.S. Bankruptcy Court in the Eastern District
    of Missouri, comes months after 23andMe began a court-supervised sale
    process of its assets.

    The South San Francisco-based venture was once valued at $6 billion and has collected DNA samples from more than 15 million customers.

    https://www.latimes.com/business/story/2025-06-11/23andme-bankruptcy-follow

    ------------------------------

    From: "Steven J. Greenwald" <greenwald.steve@gmail.com>
    Date: Tue, 10 Jun 2025 15:29:47 -0400
    Subject: Using Malicious Image Patches in Social Media to Hijack AI Agents

    From the thread posted on X by the researchers: "Beware: Your AI assistant could be hijacked just by encountering a malicious image online! "Our
    latest research exposes critical security risks in AI assistants. An
    attacker can hijack them by simply posting an image on social media and
    waiting for it to be captured."

    ------------------------------

    Date: Wed, 11 Jun 2025 09:16:25 -0700
    From: "Jim" <jgeissman@socal.rr.com>
    Subject: Weather precision loss

    As of today (11 June 2025) the NWS forecast for Van Nuys (3 mi SE of the observation site at KVNY Van Nuys Airport) has been changed from that
    specific location to the "Western San Fernando Valley", a larger area. Presumably other point forecasts in the region have also changed. For
    example, yesterday's forecast was for a high of 89; today it says "in the
    80s to around 90". Also, the forecast for Simi Valley has been broadened to "Southeastern Ventura County Valleys" with a range of temperatures instead
    of a single number. Is this a response to falling staff numbers?

    [They could get rid of a huge number of sensors and staff by aggregating
    larger areas. Where I live there are microclimates from San Fran to
    surroundings with variations of sometimes 55-degree differences within a
    30-mile radius. I suppose this strategy could lead to large-area
    predictions of 55 to 110 for the whole Bay Area. That would not be very
    helpful. PGN]

    ------------------------------

    Date: Thu, 5 Jun 2025 06:02:06 -0700
    From: Rob Slade <rslade@gmail.com>
    Subject: Grief scams on Facebook

    In a very short space of time I have had multiple romance/grief scams
    contacts on Fakebook--all of them (within the first few messages) telling me
    "I can't send you friend request," and either instructing or implying that I should attempt to "friend" them, or contact them via private messaging.

    (Interestingly, in one case, despite the fact that my email address was available, the scammer did *not*, in fact, contact me via email.)

    Facebook/Meta is lousy at protecting its users from such scams. But I
    assume that, somewhere in the bowels of the "algorithm," there is some awareness of the types of messages that scammers send their "friends," and
    thus the scammers have learned to avoid "friending" too many marks at a
    time. I also assume that these attempts are part of an organized scam
    "farm" operation, given the frequency and consistency of the attempts on Facebook, and the avoidance of email.

    ------------------------------

    Date: Sat, 28 Oct 2023 11:11:11 -0800
    From: RISKS-request@csl.sri.com
    Subject: Abridged info on RISKS (comp.risks)

    The ACM RISKS Forum is a MODERATED digest. Its Usenet manifestation is
    comp.risks, the feed for which is donated by panix.com as of June 2011.
    SUBSCRIPTIONS: The mailman Web interface can be used directly to
    subscribe and unsubscribe:
    http://mls.csl.sri.com/mailman/listinfo/risks

    SUBMISSIONS: to risks@CSL.sri.com with meaningful SUBJECT: line that
    includes the string `notsp'. Otherwise your message may not be read.
    *** This attention-string has never changed, but might if spammers use it.
    SPAM challenge-responses will not be honored. Instead, use an alternative
    address from which you never send mail where the address becomes public!
    The complete INFO file (submissions, default disclaimers, archive sites,
    copyright policy, etc.) has moved to the ftp.sri.com site:
    <risksinfo.html>.
    *** Contributors are assumed to have read the full info file for guidelines!

    OFFICIAL ARCHIVES: http://www.risks.org takes you to Lindsay Marshall's
    delightfully searchable html archive at newcastle:
    http://catless.ncl.ac.uk/Risks/VL.IS --> VoLume, ISsue.
    Also, ftp://ftp.sri.com/risks for the current volume/previous directories
    or ftp://ftp.sri.com/VL/risks-VL.IS for previous VoLume
    If none of those work for you, the most recent issue is always at
    http://www.csl.sri.com/users/risko/risks.txt, and index at /risks-34.00
    ALTERNATIVE ARCHIVES: http://seclists.org/risks/ (only since mid-2001)
    *** NOTE: If a cited URL fails, we do not try to update them. Try
    browsing on the keywords in the subject line or cited article leads.
    Apologies for what Office365 and SafeLinks may have done to URLs.
    Special Offer to Join ACM for readers of the ACM RISKS Forum:
    <http://www.acm.org/joinacm1>

    ------------------------------

    End of RISKS-FORUM Digest 34.68
    ************************

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)