×
Security

Record Breach of French Government Exposes Up To 43 Million People's Data 11

France Travail, the government agency responsible for assisting the unemployed, has fallen victim to a massive data breach exposing the personal information of up to 43 million French citizens dating back two decades, the department announced on Wednesday. The incident, which has been reported to the country's data protection watchdog (CNIL), is the latest in a series of high-profile cyber attacks targeting French government institutions and underscores the growing threat to citizens' private data. From a report: The department's statement reveals that names, dates of birth, social security numbers, France Travail identifiers, email addresses, postal addresses, and phone numbers were exposed. Passwords and banking details aren't affected, at least. That said, CNIL warned that the data stolen during this incident could be linked to stolen data in other breaches and used to build larger banks of information on any given individual. It's not clear whether the database's entire contents were stolen by attackers, but the announcement suggests that at least some of the data was extracted.
Businesses

Outdoor Voices To Close All Stores This Week (nytimes.com) 54

Outdoor Voices, an athletic apparel company, is closing all its stores on Sunday, The New York Times reported this week, citing four employees at four different stores. From the report: In an internal Slack message reviewed by The New York Times, some employees were notified on Wednesday that "Outdoor Voices is embarking on a new chapter as we transition to an exclusively online business." Products in stores are going to be discounted 50 percent, according to the Slack message. The news came as a surprise, two of the employees said, adding that they were not offered severance.

Outdoor Voices, which lists 16 retail locations on its website, did not immediately respond to a request for comment. Founded in 2014 by Ty Haney, the brand became popular for its muted tones and highly Instagrammable aesthetics. Think matching crop tops and leggings in pale shades of earthy tones. Its hashtag and company mantra, #DoingThings, became popular on social media, where brand loyalists would regularly share images of themselves participating in athletic activities like running or hiking or spinning. The company often hosted events, like group exercise classes, and even built an editorial platform called The Recreationalist. Many Outdoor Voices customers weren't just shoppers; they were devotees. The company was a chic athleisure brand perfectly positioned to attract millennials, but it was also selling a lifestyle. A lifestyle that helped the brand raise millions in funding.

Privacy

Stanford University Failed To Detect Ransomware Intruders For 4 Months (theregister.com) 22

Connor Jones reports via The Register: Stanford University says the cybersecurity incident it dealt with last year was indeed ransomware, which it failed to spot for more than four months. Keen readers of El Reg may remember the story breaking toward the end of October 2023 after Akira posted Stanford to its shame site, with the university subsequently issuing a statement simply explaining that it was investigating an incident, avoiding the dreaded R word. Well, surprise, surprise, ransomware was involved, according to a data breach notice sent out to the 27,000 people affected by the attack.

Akira targeted the university's Department of Public Safety (DPS) and this week's filing with the Office of the Maine Attorney General indicates that Stanford became aware of the incident on September 27, more than four months after the initial breach took place. According to Monday's filing, the data breach occurred on May 12 2023 but was only discovered on September 27 of last year, raising questions about whether the attacker(s) was inside the network the entire time and why it took so long to spot the intrusion.

It's not fully clear what information was compromised, but the draft letters include placeholders for three different variables. However, the filing with Maine's AG suggests names and social security numbers are among the data types to have been stolen. All affected individuals have been offered 24 months of free credit monitoring, including access to a $1 million insurance reimbursement policy and ID theft recovery services. Akira's post dedicated to Stanford on its leak site claims it stole 430 GB worth of data, including personal information and confidential documents. It's all available to download via a torrent file and the fact it remains available for download suggests the research university didn't pay whatever ransom the attackers demanded.

Canada

Canada's 'Online Harms' Bill Would Be an Assault On Free Speech, Civil Liberties Groups Say (torontosun.com) 200

A Toronto Sun columnist writes that two Canadian civil liberties groups are "sounding alarms" about the proposed new Online Harms Act (C-63): The Canadian Civil Liberties Association (CCLA) and the Canadian Constitution Foundation (CCF) say while the proposed legislation contains legitimate measures to protect children from online sexual abuse, cyber-bulling and self-harm, and to combat the spread of so-called "revenge porn," its provisions to prevent the expression of hate are draconian, vaguely worded and an attack on free speech... "[D]on't be fooled," said CCF executive director Joanna Baron. "Most of the bill is aimed at restricting freedom of expression. This heavy-handed bill needs to be severely pared down to comply with the constitution."

Both the CCLA and CCF warn the bill could lead to life imprisonment for someone convicted of "incitement to genocide" — a vague term only broadly defined in the bill — and up to five years in prison for other vaguely defined hate speech crimes. The legislation, for example, defines illegal hate speech as expressing "detestation or vilification of an individual or group of individuals," while legally protected speech, "expresses dislike or disdain, or ... discredits, humiliates, hurts or offends." The problem, critics warn, will be determining in advance which is which, with the inevitable result that people and organizations will self-censor themselves because of fear of being prosecuted criminally, or fined civilly, for what is actually legal speech.

"Both the CCLA and the CCF say the proposed legislation, known as Bill C-63, will require major amendments before becoming law to pass constitutional muster," according to the columnist.

Some specific complains:
  • The CCF argues that the Bill "would allow judges to put prior restraints on people who they believe on reasonable grounds may commit speech crimes in the future."
  • The CCLA adds that the proposed bill also grants authorities "sweeping new search powers of electronic data, with no warrant requirement," according to the Toronto Sun, and also warns about the creation of a government-appointed "digital safety commission" given "vast authority" and "sweeping powers" to "interpret the law, make up new rules, enforce them, and then serve as judge, jury, and executioner."

And in addition, the CCF points out under the proposed rules the Canadian Human Rights Commission "could order fines of up to $50,000, and awards of up to $20,000 paid to complainants, who in some cases would be anonymous."

"Findings would be based on a mere 'balance of probabilities' standard rather than the criminal standard of proof beyond a reasonable doubt... The mere threat of human rights complaints will chill large amounts of protected speech."

Thanks to long-time Slashdot reader sinij for sharing the article.


Businesses

Does Reddit Represent the Return of the Junk Stock IPO? (forbes.com) 74

An article in Inc notes a "wild projection" in Reddit's SEC filing that Reddit's global market opportunity by 2027 is $1.4 trillion." Some of the numbers lead back to a single individual: Sam Altman. The co-founder and chief executive of ChatGPT-maker OpenAI owns an 8.7 percent stake in Reddit, more than its co-founder and CEO, Steve Huffman, who owns 3.3 percent... Altman, through various funds and holding companies he owns or manages, controls more than a million shares of Reddit at $60 million in aggregate purchase price — and holds more than 9 percent of voting rights...

Discussing Reddit's future, financial analyst and journalist Herb Greenberg recently told CNBC, "This is an AI play."

But the senior investing editor for Kiplinger.com argues that retail investors "may want to hold tight before rushing out to buy the Reddit IPO." While IPO stocks tend to have strong first-day showings, returns for the first year are generally weak, says the team of analysts at Trivariate Research, a market research firm based in New York. And since 2020, "the average IPO has lagged its industry average by 30% over the subsequent three years following its first closing price..."

Other commenters have noted that Reddit's allotment of shares to select Redditors could lower demand on the first day of trading, which would work against any IPO pop.

"Over the past few years, there have been a bunch of IPOs in the U.S. in which overhyped names enjoyed flashy stock-market debuts only to drop sharply soon after," notes the Street. Notable examples include Coinbase, which plummeted by almost 90% after its debut, Robinhood, still down 53% since its IPO, and Rivian, down over 91% since its debut. However, it's crucial to note that all of these IPOs occurred in 2021 amid market euphoria fueled by low interest rates, significant economic stimulus, and the lingering effects of the Covid-19 pandemic. Although the current macroeconomic landscape differs from three years ago, valuations of tech and growth stocks remain stretched.
Kiplingers.com concludes it "boils down to your own personal investing goals and risk tolerance. If you do decide to buy Reddit stock when it first begins trading, do so in a small amount that you can afford to lose."

But they also cite analysis from David Trainer, CEO of New Constructs, a research firm powered by artificial intelligence. "Reddit's IPO marks the return of the junk IPO," Trainer wrote in Forbes. "[The valuation] implies that Reddit will grow its user base to 26 times current levels, which would be nearly five times the size of [Snapchat-maker] Snap, and a highly unlikely feat. Reddit looks overvalued, and we think investors should pass on this IPO."

Trainer writes: [T]he company has never been profitable and should not be a publicly traded company... I think the company may never monetize its platform without angering its users and the entire premise of Reddit is user-generated content. This business model is inescapably built on a catch-22: make money or please users... Reddit looks overvalued, and I think investors should pass on this IPO.
Buyers and analysts told the site Marketing Brew "that they see the platform as nice-to-have, but that it is not an essential part of their media plans, like Meta or Google are." "They've always been solidly in the second or third tier of social networks," alongside Snap, Pinterest, and X, Brian Wieser, a former GroupM exec who's now author of the industry newsletter Madison and Wall, told Marketing Brew.
Yet Trainer notes that "98% of Reddit's revenue in 2023 came from third-party advertising on the site and 28% of all revenue came from ten customers," and "Reddit's cost of revenue, sales & marketing, general & administrative, and research & development costs were 117% of revenue in 2023."

Trainer concludes "Reddit is nowhere near breakeven. Reddit is an unprofitable social media company fighting for users."

Bloomberg adds that the subreddit r/WallStreetBets "has threatened to bet against the stock, with many people noting that the company still loses money two decades into its existence. (Reddit lost $90.8 million last year, down from $158.6 million the year before.)" Some have complained that the invitation to invest fails to make up for the unpaid labor they've invested making the site work... In 2021 the platform's WallStreetBets forum ignited a meme-stock frenzy, propelling skyward the stocks of nostalgic but struggling companies like GameStop Corp. and AMC Entertainment Holdings Inc. and sending shockwaves through the financial industry... When it goes public, the platform that invented meme stocks runs the risk of becoming one itself.

Reddit noted the possibility as a risk in its IPO filing. "Given the broad awareness and brand recognition of Reddit, including as a result of the popularity of r/wallstreetbets among retail investors," the company warned that its stock could "experience extreme volatility ... which could cause you to lose all or part of your investment if you are unable to sell your shares at or above the initial offering price."

Users on WallStreetBets got a kick out of the fact that the company listed the forum as a risk factor, posting about it with a sly smiling emoji...

Meanwhile, reports that marketers are infiltrating subreddits have been confirmed. Over 200 businesses have "integrated Reddit Pro into their digital strategies," reports Search Engine Land, including "well-known names such as Taco Bell, the NFL, and The Wall Street Journal...

"During the initial alpha testing phase with approximately 20 businesses, Reddit reported its Pro partners, on average, generated 11 additional posts and comments per month."
Security

US Cybersecurity Agency Forced to Take Two Systems Offline Last Month After Ivanti Compromise (therecord.media) 4

" A federal agency in charge of cybersecurity discovered it was hacked last month..." reports CNN.

Last month the U.S. Department of Homeland Security experienced a breach at its Cybersecurity and Infrastructure Security Agency, reports the Record, "through vulnerabilities in Ivanti products, officials said..."

"The impact was limited to two systems, which we immediately took offline," the spokesperson said. We continue to upgrade and modernize our systems, and there is no operational impact at this time."

"This is a reminder that any organization can be affected by a cyber vulnerability and having an incident response plan in place is a necessary component of resilience." CISA declined to answer a range of questions about who was behind the incident, whether data had been accessed or stolen and what systems were taken offline.

Ivanti makes software that organizations use to manage IT, including security and system access. A source with knowledge of the situation told Recorded Future News that the two systems compromised were the Infrastructure Protection (IP) Gateway, which houses critical information about the interdependency of U.S. infrastructure, and the Chemical Security Assessment Tool (CSAT), which houses private sector chemical security plans. CISA declined to confirm or deny whether these are the systems that were taken offline. CSAT houses some of the country's most sensitive industrial information, including the Top Screen tool for high-risk chemical facilities, Site Security Plans and the Security Vulnerability Assessments.

CISA said organizations should review an advisory the agency released on February 29 warning that threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways including CVE-2023-46805, CVE-2024-21887 and CVE-2024-21893.

"Last week, several of the world's leading cybersecurity agencies revealed that hackers had discovered a way around a tool Ivanti released to help organizations check if they had been compromised," the article points out.

The statement last week from CISA said the agency "has conducted independent research in a lab environment validating that the Ivanti Integrity Checker Tool is not sufficient to detect compromise and that a cyber threat actor may be able to gain root-level persistence despite issuing factory resets."

UPDATE: The two systems run on older technology that was already set to be replaced, sources told CNN..." While there is some irony in it, even cybersecurity agencies or officials can be victims of hacking. After all, they rely on the same technology that others do. The US' top cybersecurity diplomat Nate Fick said last year that his personal account on social media platform X was hacked, calling it part of the "perils of the job."
Earth

Earth Has Its Warmest February Ever - the 9th Record-Setting Month in a Row (axios.com) 91

An anonymous reader shared this report from the Washington Post: The Earth just observed its warmest February, setting a monthly record for the ninth time in a row, the European Union's Copernicus Climate Change Service announced Wednesday.

The unrelenting and exceptional global warmth — fueled by a combination of human-caused warming and the El Niño climate pattern — has spanned both land and ocean areas since June. It has scientists worried about the planet crossing a critical climate threshold and prospects for an active Atlantic hurricane season. The month's average global air temperature of 13.5 degrees Celsius (56.3 degrees Fahrenheit) was 0.12 degrees (0.22 degrees Fahrenheit) warmer than the previous warmest February in 2016.

The warmth of the last 12-month period is unprecedented in modern records, coming in at 1.56 degrees (2.8 degrees Fahrenheit) warmer than preindustrial levels... Scientists fear that tipping points, such as those that could lead to catastrophic sea level rises or the collapse of critical ocean circulations, will become more likely to be reached if the Earth's temperature remains near or above that threshold for multiple years.

Axios adds: This is significant, since these 12 months exceeded the Paris Agreement's 1.5-degree target for a full year. However, the pact is aimed at averting multiple decades above that level, meaning the target hasn't yet been officially breached. Europe was especially warm compared to average during February, along with central and northwest North America, much of South America, Africa and western Australia, Copernicus found.
The Washington Post notes that in the United States, "more than 200 locations in the Midwest and Northeast set records for winter warmth."

They also quote a weather historian who posted on social media that "We are witnessing something extraordinary and unprecedented. Several thousands of records pulverized all over the world in a matter of hours, with margins never seen before."
AI

Reddit Will Now Use an AI Model To Fight Harassment (androidauthority.com) 75

An APK teardown performed by Android Authority has revealed that Reddit is now using a Large Language Model (LLM) to detect harassment on the platform. From the report: Reddit also updated its support page a week ago to mention the use of an AI model as part of its harassment filter. "The filter is powered by a Large Language Model (LLM) that's trained on moderator actions and content removed by Reddit's internal tools and enforcement teams," reads an excerpt from the page. The Register reports: The filter can be enabled in a Reddit community's mod tools, but individual moderators will need to have permissions to change subreddit settings to enable it. The harassment filter can be set to low ("filters the least content but with the most accurate results") and high ("filters the most content but may be less accurate"), and also includes an explicit allow list to force the AI to ignore certain keywords, up to 15 of which can be added. Once enabled, the filter creates a new tag in the moderation queue called "potential harassment," which moderators can review for accuracy. Reddit's help page says the feature is now available on desktop and the official Reddit apps, though it's not clear when the feature was added.
Government

Bipartisan Bill Could Force ByteDance To Divest TikTok (bbc.com) 49

An anonymous reader quotes a report from the BBC: A group of US lawmakers has introduced a bill that would require Chinese tech giant ByteDance to sell off the popular video-sharing TikTok app within six months or face a ban. For years American officials have raised concerns that data from the app could fall into the hands of the Chinese government. A bipartisan set of 19 lawmakers introduced the legislation on Tuesday. TikTok called the bill a disguised "outright ban."

In a statement announcing the bill, the lawmakers said "applications like TikTok that are controlled by foreign adversaries pose an unacceptable risk to US national security." The bill would give ByteDance 165 days to divest, or it would be blocked from the app store and web hosting platforms in the US. TikTok has previously argued against divestment, saying a change in ownership would not impose new restrictions on data use. [...] The House Energy and Commerce Committee said it would consider the latest bill on Thursday.
"This legislation will trample the First Amendment rights of 170 million Americans and deprive 5 million small businesses of a platform they rely on to grow and create jobs," TikTok said in a statement to the BBC.

Former President Donald Trump attempted to completely ban TikTok in 2020, but that was unsuccessful. More recently, a group of senators introduced legislation to block TikTok last year, but it was stalled due to lobbying from the company.
Security

Fidelity Customers' Financial Info Feared Stolen In Suspected Ransomware Attack (theregister.com) 22

An anonymous reader quotes a report from The Register: Criminals have probably stolen nearly 30,000 Fidelity Investments Life Insurance customers' personal and financial information -- including bank account and routing numbers, credit card numbers and security or access codes -- after breaking into Infosys' IT systems in the fall. According to Fidelity, in documents filed with the Maine attorney general's office, miscreants "likely acquired" information about 28,268 people's life insurance policies after infiltrating Infosys.

"At this point, [Infosys] are unable to determine with certainty what personal information was accessed as a result of this incident," the insurer noted in a letter [PDF] sent to customers. However, the US-headquartered firm says it "believes" the data included: names, Social Security numbers, states of residence, bank accounts and routing numbers, or credit/debit card numbers in combination with access code, password, and PIN for the account, and dates of birth. In other words: Potentially everything needed to drain a ton of people's bank accounts, pull off any number of identity theft-related scams -- or at least go on a massive online shopping spree.

LockBit claimed to be behind the Infosys intrusion in November, shortly after the Indian tech services titan disclosed the "cybersecurity incident" affecting its US subsidiary, Infosys McCamish Systems aka IMS. It reported that the intrusion shuttered some of its applications and IT systems [PDF]. This was before law enforcement shut down at least some of LockBit's infrastructure in December, although that's never a guarantee that the gang will slink off into obscurity -- as we're already seen.
"Since learning of this event, we have been engaged with IMS to understand IMS's actions to investigate and contain the event, implement remedial measures, and safely restore its services," Fidelity assured its customers. "In addition, we remain engaged with IMS as they continue their investigation of this incident and its impact on the data they maintain."
Cellphones

Screen Time Robs Average Toddler of Hearing 1,000 Words Spoken By Adult a Day, Study Finds (theguardian.com) 86

An anonymous reader quotes a report from The Guardian: The average toddler is missing out on hearing more than 1,000 words spoken by an adult each day due to screen time, setting back their language skills, a first-of-its kind study has found. The research, published on Tuesday in the Journal of the American Medical Association (Jama) Pediatrics, tracked 220 Australian families over two years to measure the relationship between family screen use and children's language environment. Families recorded all the audio around their child using advanced speech recognition technology over a 16-hour period on an average day at home. They repeated this process every six months between the ages of 12 and 36 months. The lead researcher, Dr Mary Brushe from the Telethon Kids Institute, said: "The technology we use is essentially like a Fitbit, but instead of counting the number of steps, this device counts the number of words spoken by, to and around the child." The device also picked up electronic noise, which the researchers analyzed to calculate screen time.

The researchers found young children's exposure to screens including TVs and phones was interfering with their language opportunities, with the association most pronounced at three years of age. For every extra minute of screen time, the three-year-olds in the study were hearing seven fewer words, speaking five fewer words themselves and engaging in one less conversation. The study found the average three-year-old in the study was exposed to two hours and 52 minutes of screen time a day. Researchers estimated this led to those children being exposed to 1,139 fewer adult words, 843 fewer child words and 194 fewer conversations. Because the study couldn't capture parents' silent phone use, including reading emails, texting or quietly scrolling through websites or social media, Brushe said they might have underestimated how much screen usage is affecting children.

A language-rich home environment was critical in supporting infants and toddlers' language development, Brushe said. While some educational children's shows were designed to help children's language skills, very young kids in the age group of the study could struggle to translate television shows into their own life, she said. This study did not differentiate between whether children were watching high- or low-quality screen content.

Emulation (Games)

Nintendo Switch Emulator Yuzu To Shut Down, Pay $2.4 Million To Settle Lawsuit (liliputing.com) 62

An anonymous reader quotes a report from Liliputing: Yuzu is a free and open source emulator that makes it possible to run Nintendo Switch games on Windows, Linux, and Android devices. First released in 2018, the software has been under constant development since then (the Android port was released less than a year ago). But last week Nintendo sued the developers, claiming that the primary purpose of the software is to circumvent Nintendo Switch encryption and allow users to play pirated games. Rather than fight the case in court, Tropic Haze (the developers behind Yuzu) have agreed to a settlement which involves paying $2.4 million in damages to Nintendo and basically shutting down Yuzu.

As part of a permanent injunction, Tropic Haze has agreed to stop distributing, advertising, or promoting Yuzu or any of its source code or features or any other "software or devices that circumvent Nintendo's technical protection measures." The court is also ordering the developers to turn over the yuzu-emu.org website to Nintendo and bars them "from supporting or facilitating access" to any other related websites, social media, chatrooms, or apps. In one of the more bizarre parts of the court order, the Yuzu team is told to delete all "circumvention devices," which includes any tools used for development of Yuzu and "all copies of Yuzu."

Social Networks

How Will Reddit's IPO Change the Service? (bbc.co.uk) 86

"Reddit users have been reacting with deep gloom to the firm saying it plans to sell shares to the public..." the BBC recently reported: The company has said its plans are "exciting" and will offer the business opportunities for growth. However many users worry the move will fundamentally change the website... "When the most important customers shift from [users] to shareholders, the product always [suffers]," said one person. "It becomes 'what can we do this quarter to squeak out an additional point of revenue', instead of 'how can we make this product better'...."

[T]he company has recorded losses every year since its start, including more than $90m last year. In the filing, Reddit said it had not started trying to make money seriously until 2018. It reported $804m in revenue last year, up more than 20% from 2022. Advertising accounted for nearly all of the revenue, but in a note to prospective investors chief executive Steve Huffman said he was excited about opportunities to make the platform a venue for commerce and license its content to AI companies.

Moon

Japan's Moon Lander Survived a 354-Hour Lunar Night. Now It Faces a Second One (space.com) 11

It completed the most precise landing ever on the moon — albeit upside-down. And then it faced a "lunar night" lasting about two weeks where temperatures drop to -270 degrees Fahrenheit, reports the Times of India.

But then, "Despite not being designed for the extreme temperatures, SLIM surprised scientists by coming back to life after the two-week-long lunar night." More from Space.com: The lander woke up on February 26 during extremely hot temperatures of 212 Fahrenheit (100 Celsius) in its region and has been making contact here and there with Earth in the days since. Most recently, SLIM attempted observations with its multiband spectroscopic camera, but "it did not work properly," JAXA officials wrote. "This seems to be due to the effects of overnight," the update continued, referring to the frigid two-week-long lunar night that SLIM experienced before the sun shone near Shioli crater again. "But we will continue to investigate based on the data we have obtained for the next opportunity...."
"We received so much support for our operations after the lunar night," the agency posted on social media — adding "thank you!"

The Times of India reports that "JAXA officially announced SLIM's return to a dormant state on March 1, sharing an image of the lunar surface captured by the probe."

Above the photo, JAXA posted this hopeful message. "Although the probability of a failure increases with the repeated severe temperature cycles, SLIM operation will attempt to resume when the sun rises (late March). #GoodAfterMoon."

And Space.com notes that "Despite all, SLIM has met both main and extended mission objectives: Landing precisely on the moon, deploying two tiny rovers and conducting science with its navigation camera and its spectroscopic camera, particularly searching for signs of olivine on the surface."

Thanks to long-time Slashdot reader AmiMoJo for sharing the news.
Youtube

Watch the Moment 43 Unionized YouTube Contractors Were All Laid Off (msn.com) 178

An anonymous Slashdot reader shared this report from The Washington Post: A YouTube contractor was addressing the Austin City Council on Thursday, calling on them to urge Google to negotiate with his union, when a colleague interrupted him with jaw-dropping news: His 43-person team of contractors had all been laid off...

The YouTube workers, who work for Google and Cognizant, unanimously voted to unionize under the Alphabet Workers Union-CWA in April 2023. Since then, the workers say that Google has refused to bargain with them. Thursday's layoff signifies continued tensions between Google and its workers, some of whom in 2021 formed a union...

Workers had about 20 minutes to gather their belongings and leave the premises before they were considered trespassing.

Video footage of the moment is embedded at the top of the article. "I was speechless, shocked," said the contractor who'd been speaking. He told the Washington Post "I didn't know what to do. But angered, that was the main feeling." The council meeting was streaming live online and has since spread on social media. The contractors view the layoff as retaliation for unionizing, but Google and information technology subcontractor Cognizant said it was the normal end of a business contract.

The ability for layoffs to spread over social media highlights how the painful experience of a job loss is frequently being made public, from employees sharing recordings of Zoom meetings to posting about their unemployment. The increasing tension between YouTube's contractors and Google comes as massive layoffs continue to hit the tech industry — leaving workers uneasy and companies emboldened. Google already has had rounds of cuts the past two years.

Google has been in a long-running battle with many of its contractors as they seek the perks and high pay that full-time Google workers are accustomed to. The company has tens of thousands of contractors doing everything from food service to sales to writing code... Google maintains that Cognizant is responsible for the contractors' employment and working conditions, and therefore isn't responsible for bargaining with them. Cognizant said it is offering the workers seven weeks of paid time to explore other roles at the company and use its training resources.

Last year, the National Labor Relations Board ruled that Cognizant and Google are joint employers of the contractors. In January, the NLRB sent a cease-and-desist letter to both employers for failing to bargain with the union. Since then the issue of joint employment, which would ultimately determine which company is responsible for bargaining, has landed in an appeals court and has yet to be ruled on.

"Workers say they don't have sick pay, receive minimal benefits and are paid as little as $19 an hour," according to the article, "forcing some to work multiple jobs to make ends meet." Sam Regan, a data analyst contractor for YouTube Music, told the Washington Post that he was one of the last workers to leave the meeting where the layoffs were announced.

"Upon leaving, he heard one of the security guards call the non-emergency police line to report trespassers."
Social Networks

Threads' API Is Coming in June (techcrunch.com) 17

In 2005 Gabe Rivera was a compiler software engineer at Intel — before starting the tech-news aggregator Techmeme. And last year his Threads profile added the words "This is a little self-serving, but I want all social networks to be as open as possible."

Friday Threads engineer Jesse Chen posted that it was Rivera's post when Threads launched asking for an API that "convinced us to go for it." And Techmeme just made its first post using the API, according to Chen. The Verge reports : Threads plans to release its API by the end of June after testing it with a limited set of partners, including Hootsuite, Sprinklr, Sprout Social, Social News Desk, and Techmeme. The API will let developers build third-party apps for Threads and allow sites to publish directly to the platform.
More from TechCrunch: Engineer Jesse Chen posted that the company has been building the API for the past few months. The API currently allows users to authenticate, publish threads and fetch the content they post through these tools. "Over the past few months, we've been building the Threads API to enable creators, developers, and brands to manage their Threads presence at scale and easily share fresh, new ideas with their communities from their favorite third-party applications," he said...

The engineer added that Threads is looking to add more capabilities to APIs for moderation and insights gathering.

Crime

Ransomware Attack Hampers Prescription Drug Sales at 90% of US Pharmacies (msn.com) 81

"A ransomware gang once thought to have been crippled by law enforcement has snarled prescription processing for millions of Americans over the past week..." reports the Washington Post.

"The hackers stole data about patients, encrypted company files and demanded money to unlock them, prompting the company to shut down most of its network as it worked to recover." Insurance giant UnitedHealthcare Group said the hackers struck its Change Health business unit, which routes prescription claims from pharmacies to companies that determine whether patients are covered by insurance and what they should pay... Change Health and a rival, CoverMyMeds, are the two biggest players in the so-called switch business, charging pharmacies a small fee for funneling claims to insurers. "When one of them goes down, obviously it's a major problem," said Patrick Berryman, a senior vice president at the National Community Pharmacists Association...

UnitedHealth estimated that more than 90 percent of the nation's 70,000-plus pharmacies have had to alter how they process electronic claims as a result of the Change Health outage. But it said only a small number of patients have been unable to get their prescriptions at some price. At CVS, which operates one of the largest pharmacy networks in the nation, a spokesperson said there are "a small number of cases in which our pharmacies are not able to process insurance claims" as a result of the outage. It said workarounds were allowing it to fill prescriptions, however...

For pharmacies that were not able to quickly route claims to a different company, the Change Health outage left pharmacists to try to manually calculate a patient's co-pay or offer them the cash price. Compounding the impact, thousands of organizations cut off Change Health from their systems to ensure the hackers did not infect their networks as well... The attack on Change Health has left many pharmacies in a cash-flow bind, as they face bills from the companies that deliver the medication without knowing when they will be reimbursed by insurers. Some pharmacies are requiring customers to pay full price for their prescriptions when they cannot tell if they are covered by insurance. In some cases, that means people are paying more than $1,000 out of pocket, according to social media posts.

The situation has been "extremely disruptive," said Erin Fox, associate chief pharmacy officer at University of Utah Health. "At our system, our retail pharmacies were providing three-day gratis emergency supplies for patients who could not afford to pay the cash price," Fox said by email. "In some cases, like for inhalers, we had to send product out at risk, not knowing if we will ever get paid, but we need to take care of the patients." Axis Pharmacy Northwest near Seattle is "going out on a limb and dispensing product with absolutely no inkling if we'll get paid or not," said Richard Molitor, the pharmacist in charge.
UPDATE: CNN reports Change Healthcare has now announced "plans for a temporary loan program to get money flowing to health care providers affected by the outage." It's a stop-gap measure meant to give some financial relief to health care providers, which analysts say are losing millions of dollars per day because of the outage. Some US officials and health care executives told CNN it may be weeks before Change Healthcare returns to normal operations.
"Once standard payment operations resume, the funds will simply need to be repaid," the company said in a statement. Change Healthcare has been under pressure from senior US officials to get their systems back online. Officials from the White House and multiple federal agencies, including the department of Health and Human Services, have been concerned by the broad financial and health impact of the hack and have been pressing for ways to get Change Healthcare back online, sources told CNN...

In a message on its website Friday afternoon, Change Healthcare also said that it was launching a new version of its online prescribing service following the cyberattack.

Thanks to Slashdot reader CaptainDork for sharing the news.
EU

European Parliament Bans Amazon From Its Premises (euractiv.com) 102

Longtime Slashdot reader Kant shares a report from Euractiv: The European Parliament decided to ban Amazon representatives from accessing its buildings on Tuesday (February 27), due to multiple events where the global retailing giant did not attend meetings requested by members of the European Parliament, the European Parliament press service confirmed Euractiv. "In line with rule 123/3 and at the request of the [Employment and Social Affairs] Committee, the Quaestors have authorized the Secretary General [Alessandro Chiocchetti] to withdraw the long-term access badges of the interest representatives of Amazon." It is now the responsibility of the secretary general to concretely initiate the process of withdrawing their badges and to determine the duration of the ban, a European Parliament source close to the matter told Euractiv.

According to the EMPL chair Dragos Pislaru, who signed the letter, the US e-commerce company refuses to attend more than one meeting with EU lawmakers to discuss the condition of Amazon workers. Four cases are mentioned in the letter. The first occurred in May 2021, when Amazon did not attend a parliamentary committee meeting on "Amazon attacks on fundamental workers' rights and freedoms: freedom of assembly and association, and the right to collective bargain and action." The second event concerns the refusal by Amazon CEO Jeff Bezos to attend an exchange of views with EU lawmakers -- instead, the company sent a written answer. The last two episodes happened in December 2023 and January 2024. In the former event, Amazon refused access to its facilities in German and Poland to a MEP, while on the latter, the company did not attend another parliamentary committee meeting dedicated to Amazon workers' conditions.
In a statement to Euractiv, an Amazon spokesperson said: "We are very disappointed with this decision, as we want to engage constructively with policymakers. [...] Our commitment continues despite this decision. Amazon regularly participates in activities organized by the European Parliament and other EU institutions -- including Parliamentary hearings -- and we remain committed to participating in balanced, constructive dialogue on issues that affect European citizens."
Bitcoin

Reddit Discloses Bitcoin and Ether Investments In IPO Filing (techreport.com) 7

As part of its IPO filing with the SEC, Reddit disclosed that it has invested some of its excess cash in bitcoin, ether and Polygon. From a report: Based on the document, the firm now holds BTC and ETH in its balance sheet. Notably, Reddit filing came as part of the IPO registration statement with the SEC. Apart from ETH and BTC, the filing revealed Reddit's investment in Polygon (MATIC). According to the document, the social media platform plans to use both Ether and Polygon as a form of payment for digital goods. Further, Reddit noted that the amount of Polygon and Ethereum from virtual goods is currently immaterial. However, it indicated the possibility of a continuous addition of Bitcoin and Ethereum to its treasury. Also, it plans to keep trying out its passion for virtual goods. Moreover, the document revealed that Reddit made the investments using some of its excess cash reserves. However, the firm didn't disclose details of the crypto investments it made.

Reddit's filing document revealed why the popular social media platform dabbled into crypto. According to the firm, it holds Bitcoin and Ethereum to enable its engineering and product teams to use them. Further, it cited the present regulatory stance that suggests these two assets are potentially non-securities under US laws. Also, Reddit disclosed its plans to expand its crypto holding by including other digital assets in its balance sheet. However, it highlighted that such a move will depend on future regulations that exempt crypto as a security.

Government

White House Looks To Curb Foreign Powers' Ability To Buy Americans' Sensitive Personal Data With Executive Order (cnn.com) 117

President Joe Biden will issue an executive order on Wednesday aimed at curbing foreign governments' ability to buy Americans' sensitive personal information such as heath and geolocation data, according to senior US officials. From a report: The move marks a rare policy effort to address a longstanding US national security concern: the ease with which anyone, including a foreign intelligence services, can legally buy Americans' data and then use the information for espionage, hacking and blackmail. The issue, a senior Justice Department official told reporters this week, is a "growing threat to our national security."

The executive order will give the Justice Department the authority to regulate commercial transactions that "pose an unacceptable risk" to national security by, for example, giving a foreign power large-scale access to Americans' personal data, the Justice Department official said. The department will also issue regulations that require better protection of sensitive government information, including geolocation data on US military members, according to US officials. A lot of the online trade in personal information runs through so-called data brokers, which buy information on people's Social Security numbers, names, addresses, income, employment history and criminal background, as well as other items.

"Countries of concern, such as China and Russia, are buying Americans' sensitive personal data from data brokers," a separate senior administration official told reporters. In addition to health and location data, the executive order is expected to cover other sensitive information like genomic and financial data. Administration officials told reporters the new executive order would be applied narrowly so as not to hurt business transactions that do not pose a national security risk.
The White House's press release.

Slashdot Top Deals