Computerworld.com [Hacking News]

Syndikovat obsah
Making technology work for business
Aktualizace: 4 min 52 sek zpět

Automattic CEO Matt Mullenweg is out: Does this mean long-term viability, or liability, for WordPress customers?

11 Září, 2026 - 02:52

Automattic CEO Matt Mullenweg has been abruptly put on a paid leave of absence from the company by its board of directors, despite his objections. But enterprise IT executives who rely on WordPress may find the shift doesn’t mean much as long as Mullenweg fully controls WordPress.org, which handles all of the product’s patches and updates.

“The part of WordPress that actually keeps enterprise IT up at night isn’t Automattic’s org chart. It’s WordPress.org, the plugin and theme directory every WordPress site pulls its security updates from, and the WordPress trademark,” said Frank Dickson, principal analyst at Dickson Research. “Mullenweg owns and controls both personally, outside of Automattic, and nothing about this week’s vote touches that. He also remains a director on Automattic’s board. The company changed who runs its hosting business without changing who controls the distribution pipeline millions of those hosted sites still depend on.”

For IT leaders who rely on WordPress, it’s important to differentiate what is currently known about the change and what is speculation. A statement emailed to Computerworld from Automattic merely said: “Matt Mullenweg is currently on leave from Automattic. Mark Davies, Automattic’s CFO, will lead the company as interim CEO. The Board has full confidence in Mark’s leadership and in the team’s ability to execute against the company’s priorities.” 

However, messages from Mullenweg to Automattic employees made it clear that the move was one that he strongly opposed. He posted on his X account, “the next step in this playbook is to restart the smear attacks, so get ready for some National Enquirer rumors or hit pieces.”

He added: “I appreciate the hundreds of colleagues who have already expressed public and private support, and are organizing in solidarity. It’s a big help to counter the ‘Matt is an idiot and shouldn’t run an ice cream stand’ allegations. Also, whatever you can say about me, I’m direct and probably overcommunicate, which I’m going to continue doing through this mess folks have made.”

He also posted separately that he is looking to hire, but that applicants cannot be current Automattic employees. “I really need some great sysadmin and security researchers to hire really quick, no one from @automattic. I’m on the board there and fully support Mark Davies in his interim CEO role. But I think it’s probably good if I move some of my stuff currently hosted there, elsewhere.”

Next steps unclear

What is unclear are likely next steps. Is the leave permanent or temporary? And if temporary, how temporary? Is the board negotiating with Mullenweg, and might those negotiations involve whether Mullenweg continues to control WordPress.org? Neither Automattic nor Mullenweg provided clarification.

Melody Brue, analyst-in-residence at Moor Insights & Strategy, who has closely tracked WordPress for years, said that the apparent speed of Mullenweg’s removal as Automattic CEO suggests that the board was trying to sidestep something serious.

“It has to be some exposure or risk that was severe enough that speed outweighed any optics or fairness. Boards don’t generally move that abruptly,” she said. The appointment of the CFO as interim CEO “definitely shows some stabilization and possibly some legal compliance cleanup. What it doesn’t say is renewed product investment.”

IT worried about instability

But the longstanding worries among CIOs about WordPress were not primarily about the perceived lack of continued investment. It was the concern that Mullenweg has a tendency to react strongly to a situation, apparently without many thoughts of the consequences. 

Nothing better illustrated this than Mullenweg’s personal war with WordPress hosting provider WP Engine that resulted in a series of legal rulings in WP Engine’s favor. 

WP Engine litigation is still ongoing, and that may have played a role in the board’s actions. 

Part of that lawsuit is at the heart of enterprise IT concerns: Mullenweg had denied WP Engine access to WordPress.org resources, including patches, plugins and security updates for the software. 

The IT fear is that Mullenweg could unilaterally take similar actions against any customer, even an enterprise. 

“I would still treat this as vendor risk, because WordPress.org is still controlled by Matt, separate from Automattic,” Brue said. “The question is, who actually controls the plugins that these IT leaders rely on? It’s still a structural risk. Look at whether the patches flow through one person. For now, they still do. Is that pipeline protected by independent governance, oversight? That is what matters for enterprise IT.”

Flavio Villanustre, CISO at the LexisNexis Risk Solutions Group, agreed. 

“Most of the concerns from enterprises about using WordPress come from the fragmented ecosystem and the inconsistent security controls and support of modules and extensions, which have led to significant vulnerabilities in the past,” Villanustre said. “The change of CEO in their parent company won’t directly affect this, especially because Matt Mullenweg will continue as the WordPress[.org] leader anyway.”

Dickson also agreed, noting that the question of who sits in the CEO seat at Automattic was not the issue.

“The enterprise IT concern was never really about Automattic’s management bench. It was about one person holding unilateral, unaccountable control over a piece of critical open-source infrastructure,” he said. “In 2024, Mullenweg used exactly that control to cut WP Engine’s customers off from plugin and theme updates overnight, with no board sign-off and no customer input, purely as leverage in a business dispute. This week’s vote proves a board can restrain him inside Automattic. It says nothing about what restrains him at WordPress.org, because the honest answer is still nothing.”

In fact, rather than reducing those IT worries, Dickson argued that this move could worsen them. 

“If anything, this should sharpen the concern rather than settle it. A board just decided it couldn’t function with him running a corporate entity with ordinary fiduciary obligations,” he pointed out. “That same person still holds sole authority over the update pipeline for software that runs over 40% of the web. Risk teams that were nervous about concentration risk in WordPress now have a fresh, concrete data point: the concentration is real, and untouched by whatever just happened at Automattic’s board table.”

This change could help

Mike Wilkes, enterprise CISO at Aikido Security, interpreted the events differently, and suggested that it might indeed make WordPress look more attractive to enterprise IT.

“This could ultimately make WordPress more attractive to enterprise buyers, but only if it becomes the beginning of stronger institutional governance rather than simply a change in personalities,” he said. “CIOs don’t particularly care about palace intrigue until that intrigue can affect software updates, supply-chain dependencies or business continuity. The WP Engine conflict demonstrated that governance risk can become operational risk surprisingly quickly. The ongoing litigation underscores that this is not merely historical baggage.”

Wilkes pointed out that the next few steps taken by the board and by Mullenweg will likely be far more informative than any analysis of the board’s CEO change.

“I wouldn’t tell a CIO that yesterday’s announcement makes WordPress either safer or riskier today. I would tell them to watch what happens next,” he said. “If Automattic uses this moment to create clearer separation between corporate interests, WordPress.org infrastructure, and community governance, it could reduce one of the ecosystem’s most persistent concentration risks. If the same authority simply migrates to different individuals without structural reform, enterprise concerns haven’t really changed. In cybersecurity terms, replacing the administrator isn’t the same thing as eliminating the single point of failure.”

Dylan Forde, owner of Harmonic Design in Oakville, Ontario, Canada, and a WordPress developer for more than ten years, applauded the CEO change. 

“It is my opinion that the removal of Mr. Mullenweg is a good thing for both the WordPress community and open source,” he said. “He has been divisive for a long time, with many grievances that I overall understand, but I oppose his responses to. It sucks to build something used by millions of people and businesses around the world, all profiting off your work while giving nothing back. But cutting off and targeting individuals is not the answer. Open source is supposed to work for everyone, and my assumption is that anyone whose core business relies on WordPress will be sleeping easier now.”

Kategorie: Hacking & Security

How Apple is trying to normalize always-on AI

10 Září, 2026 - 19:28

Apple does seem to have tried to ensure its controversial Audio Intelligence feature isn’t abused. Alongside the iPhone Duo and new iPhone 18 Pro range, Apple on Wednesday introduced a new Apple Watch equipped with a brand new feature it calls Audio Intelligence. The existence of this surprising tool was confirmed only on the eve of the launch event. Enabled by the new S11 chip on the latest Watch devices, this is actually a collection of four features:

  • Siri Recap, which creates high-level summaries of conversations during your day.
  • Live Rewind, which transcribes the previous 15 seconds of a conversation as text.
  • Music recognition, which relies on Shazam.
  • Sound recognition, which can identify things like sirens or alarms.

All of these features must be consciously enabled by the user and are not on by default.

What they have in common is use of artificial intelligence along with always-on microphones. While all four of these tools are being presented as opt-in, their existence will inevitably — and justifiably — raise privacy concerns. 

Apple saw those concerns coming, and to make the features work it has placed a Secure Exclave on the S11 chip inside the latest watches. This is a dedicated secure buffer on the chip that processes audio privately on the fly. It does so without creating a recording of ambient sound around you, and the data it works with is isolated from the rest of the system. That Exclave pairs with the iPhone’s Enclave using “a new audio-verified pairing mechanism that exists in addition to Bluetooth pairing,” Apple explains in a detailed white paper about how it works. 

For Siri Recap, the process works like this:
  • Apple Watch recognizes a conversation is taking place.
  • If so, audio flows into the Secure Exclave, encrypted, and transmitted to a similarly Secure Enclave on your paired iPhone.
  • The audio is then immediately deleted from the Watch. 
  • The phone will decrypt and transcribe the audio, condense it, and send that transcript to Private Cloud Compute for processing. 
  • The short summary is then made, returned, and deleted after seven days.
  • Speakers are not identified, recordings are not made, and detailed transcripts are not created or retained.

The company has also introduced safeguards for those around you. The system will deliberately omit some information, including potentially harmful content, financial data, or personal identifiers. When you use the Live Rewind tool, an audible chime plays on your device to alert nearby people that you are using the feature.

Challenges will emerge

For one thing, we don’t yet know whether the company will provide enterprise IT with device management tools to disable the feature on managed devices. It’s crystal clear that devices that are constantly gathering data will be seen as potential security risks — particularly in regulated industries. And it seems far more logical to provide new APIs to disable Audio Intelligence on managed devices than it would be to insist anyone wearing an Apple Watch put it in a lead-lined box before beginning the next safeguarding, healthcare, or product development meeting.

Another problem I see concerns Europe’s Digital Markets Act. It is, after all, inevitable that competitors (maybe including Meta) will want their devices to have equal access to the information gathered by Audio Intelligence. Based on the decisions Apple has made so far, it seems equally likely it will want to refuse such access; this is why these new features will not initially be available in the EU. 

There is also no doubt hackers will attempt to break into the system, though doing so will not be at all easy on account of the intentional way the company has built in security. I suspect, but do not know, that attempts will focus on the points at which data is exchanged across devices, rather than when the information sits within secure enclaves on those devices. It also makes sense that everyone who uses iCloud services for their data should put 2FA in place and pick strong passwords. 

What about iCloud storage?

The other challenge will be encryption, specifically ongoing attempts to penetrate iCloud data encryption by some nations, led by the UK. Even so, if access could be achieved to iCloud-stored Audio Intelligence text, what is obtained would only be summary data, not a recording. The system is architected so recordings are never made.

Apple’s white paper on the feature explores this in more depth: “Audio from the microphone enters the Secure Exclave of Apple Watch, where it is initially processed for speech, sounds, or music, without transcribing or storing the raw audio. This buffer is a continuously overwritten stream that exists only within the protected hardware and never creates an audio recording.”

Once you decide to keep a Recap or Life Rewind text, the raw audio is not saved to iCloud, only the text, and then only if you use 2FA and a device passcode. No one else, including Apple, can access the encrypted data you save, Apple said.

Where does this go next?

One pre-event rumor that didn’t come true concerned AirPods equipped with cameras and Vision Intelligence to understand physical context and surrounding, with the aim of enhancing Siri AI. I’ve expressed reservations about this idea, but do think the security model Apple has put in place for Audio Intelligence will turn out to be an echo of its intentions to secure Vision Intelligence transactions.

This implies a new chip with Silicon Enclave for AirPods Pro, a similar exchange of information in real time for summary and determination of context and content, and a process in which no recordings are made and media access beyond brief, time-limited summaries, is available. In short, Apple will use the same security model.

What about the rest of them?

That’s fine as far as it goes. But the other subtext is that while Apple seems genuine in its attempt to deliver relatively intrusive tech advances right, others will show less commitment to privacy and security. So, while it’s furthering the conversation about using these tools, Apple is also pushing public acceptance of such technologies.

I’m not entirely sure we’re ready.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon

Kategorie: Hacking & Security

Qualcomm’s next Snapdragon mobile chip comes into focus with on-device AI

10 Září, 2026 - 15:01

Qualcomm is taking an unusual approach to the launch of its next-generation premium Snapdragon mobile platform this year. Instead of holding everything for its annual Snapdragon Summit in Maui happening later this month, the company has been methodically disclosing the architecture that will power the next wave of flagship Android phones over the past couple of weeks.

First, the company disclosed its new Oryon CPU architecture, followed by a major overhaul of its Adreno GPU. Today, Qualcomm is detailing the next-generation Hexagon NPU that will serve as the platform’s primary AI engine.

Taken together, the disclosures give us a pretty good picture of where Qualcomm is going before we even know the chip’s official name.

There is obviously a strong performance story here, anchored by a 5GHz CPU, but the more interesting theme running through the architecture is memory locality and specialized AI acceleration. Qualcomm is trying to keep more data close to the compute resources that need it, while distributing AI workloads across the CPU, GPU and NPU.

These architectural changes are important as the company continues to drive on-device AI beyond relatively simple generative features toward more persistent, agentic workloads.

Oryon hits 5GHz, bolstered by FlexCache

Qualcomm disclosed in August that its next Oryon CPU will be the first mobile CPU to reach 5GHz. The eight-core design includes two 5GHz Prime cores and six Performance cores, with Qualcomm attributing the frequency gains to its fully custom Oryon microarchitecture, an in-house Arm-based CPU design that gives the company full control over the cores, cache and memory hierarchy, branch prediction and CPU subsystem.

The 5GHz headline is certainly going to get attention. However, Qualcomm’s new FlexCache architecture may ultimately have a larger impact on sustained performance. FlexCache allows Oryon’s Prime and Performance cores to tap into the same shared cache pool, with capacity dynamically allocated based on the workload. So rather than a demanding core being limited to a fixed slice of cache, it can draw on more of the available pool when needed. This keeps larger working data sets close to the CPU cores and reduces high-latency trips out to system memory.

This approach should benefit everything from gaming and multitasking to content creation, but it also aligns well with agentic AI workloads, where tasks may move through several stages of processing and across different CPU cores. The basic goal is straightforward: keep the CPU fed and avoid expensive trips to external memory.

Qualcomm’s next-gen Adreno GPU adds dedicated AI engines

Qualcomm’s next disclosure focused on graphics, where the company is making one of the more significant changes to its Adreno GPU engine in recent years. The new GPU adds dedicated Adreno Matrix Cores for running AI models directly inside the graphics pipeline. They’re paired with 18MB of Adreno High-Performance Memory, or HPM, which provides low-latency local storage for tile-based rendering, frame buffers and GPU compute.

Qualcomm claims HPM provides a 12% power improvement compared to its previous-gen Snapdragon 8 Elite Gen 5.

The more visible feature for users, however, may be Adreno Neural Fusion, which combines AI super resolution, neural processing and frame generation in a unified graphics pipeline. There are obvious parallels here to what NVIDIA, AMD and others are doing with neural rendering on the PC, though Qualcomm’s next-gen Snapdragon SoC has to operate within a much tighter mobile power envelope.

Qualcomm claims enabling Neural Fusion reduces power consumption by up to 40% in its internal testing using the company’s Dragon Alley graphics demo. That’s an impressive number, though as always, we’ll want to see how the technology behaves across actual shipping games and devices before drawing any definitive conclusions.

Qualcomm has also helped integrate Neural Fusion technology into Unity and Unreal Engine, which may ultimately be just as important as the underlying hardware. Developer adoption determines whether features like this become meaningful platform advantages or just another tick box on a spec sheet.

Qualcomm’s Hexagon NPU is being reworked for agentic AI

Qualcomm

The most recent disclosure centers on Qualcomm’s Hexagon NPU, where the broader architecture starts to come together. The company’s next-generation Hexagon introduces a new Element Accelerator designed for transformer workloads, alongside its existing vector and scalar processing resources. Qualcomm says the new block is optimized for fast action loops, key-value (KV) cache acceleration and context lengths of up to 32K.

Hexagon is also getting 50% more shared memory, and again, that memory complement is important. Model state, context and KV-cache data can generate substantial memory traffic, particularly with larger language models. Keeping more of that data close to the NPU can reduce latency and power consumption. Qualcomm says the architecture is designed for long-context reasoning, multimodal models, concurrent agents and low-latency action loops.

For INT4 quantized models, the company claims up to a 50% improvement in pre-fill performance versus its previous-generation Snapdragon 8 Elite Gen 5. Qualcomm is also targeting Mixture-of-Experts, or MoE, models as large as 30 billion parameters. In its example, the company points to a 30B model that activates only about 3 billion parameters during a given token-generation step. That selective approach is a natural fit for the tight power and memory constraints of a handset.

Qualcomm isn’t suggesting that a smartphone will simply run a 30B dense model entirely from DRAM, however. By activating only the experts needed for a particular task, MoE architectures can dramatically reduce active compute and memory bandwidth requirements, potentially making much larger classes of AI models practical on mobile hardware.

Qualcomm’s next-gen Snapdragon mobile impact

There is a larger competitive story here as well. For years, flagship smartphone competition largely came down to CPU, GPU, modem performance and power efficiency. AI is now another major area of differentiation, and Qualcomm is clearly designing its next-gen Snapdragon mobile platform around this need.

Apple has the advantage of controlling its silicon, operating system and software stack end-to-end. MediaTek continues to push aggressively into premium Android devices as well. Qualcomm’s response is to make its custom Oryon CPU, Adreno GPU and Hexagon NPU work more like a fully integrated compute platform, tuned for modern AI and agentic workloads.

This is a solid advantage for Android handset OEMs because many don’t have the resources to engineer this level of silicon integration themselves. Qualcomm can effectively provide its Android OEM partners, including Samsung, Xiaomi, Honor and others, with a common hardware foundation for on-device AI, advanced graphics and agentic computing. It also gives Qualcomm another way to defend its premium Snapdragon position.

The company’s custom Oryon architecture now spans smartphones and Windows PCs, and soon servers, while AI acceleration is distributed across its CPU, GPU and NPU. For business users, that could mean more AI processing happens locally, reducing cloud and network dependence, improving response times and keeping more potentially sensitive data on-device. And for IT organizations, Qualcomm now has an opportunity to provide a more consistent AI compute foundation across Windows PCs with Snapdragon X and premium Android handsets.

There is still plenty we don’t know, however. Qualcomm hasn’t disclosed the complete SoC specifications, final performance or power characteristics, or which devices will ship with it initially. Many of these AI experiences will also depend heavily on Android, app developers and the models themselves.

The new 5GHz mobile CPU may generate the biggest headline at Snapdragon Summit, but the more important developments may be what sit around it: more local memory, specialized AI acceleration and tighter integration between the CPU, GPU and NPU.

If Qualcomm can translate this architecture into better sustained performance, enhanced power efficiency and useful on-device AI experiences, it could strengthen its position in premium Android phones while putting more competitive pressure on Apple. For business users, the payoff could be more capable local AI without sacrificing the performance and battery life expected of a flagship device.

That is the part I’ll be watching most closely when the complete silicon picture is unveiled at Snapdragon Summit later this month. And I may even get some hands-on time with it in some benchmarks, as we have in years past, so we shall see.

Kategorie: Hacking & Security

Anthropic maps three AI futures for 2030; the most extreme could upend the economy

10 Září, 2026 - 04:16

AI is evolving faster than most people, even those building it, could even fathom, and its impact on the workforce and the economy is, at this point, really anyone’s guess.

Researchers from The Anthropic Institute are offering a few possibilities: They have built a nuanced framework looking at how AI might impact jobs, unemployment, and gross domestic product (GDP) growth between now and 2030.

They posit three potential scenarios for an AI-augmented future: “modest,” “substantial,” and “extreme,” and have created an interactive tool where users can explore how productive, or disruptive, AI will become in the workplace, based on their predictions of how they will work in 2030.

“Which of these worlds we are heading toward may become clearer within a year or two, and preparing for potential disruption seems to us the prudent course,” the researchers noted.

The goal of their work is to inform debate as AI becomes more powerful and capable. “AI is likely to reshape the US and global economies in profound ways in the coming decade, but how, and by how much, is extraordinarily uncertain,” they wrote.

How different scenarios could play out

If you add up every single task performed by people, machines, and software, the US has created a staggering $30 trillion in value over just the last year, the Anthropic researchers estimated. Their model and the corresponding tool are a way to explore how AI impacts tasks that contribute to the economy, the tasks it augments and creates, impacts on productivity, and speed of adoption.

“The answers to these questions have direct effects on GDP, the labor market, and the share of the pie taken home by workers,” they wrote.

Under their definition of “modest” change, AI will add less than half a point to GDP by 2030, meaning it will increase the growth rate of the national economy by just 0.5%, and will raise unemployment by just a tenth of a point, a minor shift. In this future, it’s difficult to see AI’s impact in macroeconomic data; change is steady but gradual, similar to that of the internet. “It drives real economic gains, but they’re within the historical norm for new technologies,” the researchers noted.

In the “substantial” scenario, AI will be capable of doing half of all knowledge work by 2030, the majority of it autonomously. Still, it wouldn’t be adopted for all work; in fact, most knowledge work tasks would still be completed without AI. Correspondingly, the economy would grow at twice its normal rate, but even as some non-knowledge workers see gains, wages for knowledge workers wouldn’t rise.

In this case, “AI makes a bigger impact than the internet, or the railroad,” the researchers wrote. Reallocation could be costly, but it is in line with what the US labor market has historically absorbed.

In the “extreme” scenario, of course, AI would be more productive than humans on the majority of knowledge work tasks, would do all of them autonomously, and subsequently would create no new knowledge tasks for humans.

The technology would “drive a completely transformed, unprecedented economy” arising from recursively self-improving AI. GDP growth would rise to 15% per year, but nearly one in five cognitive workers would be unemployed, and their relative wage would fall “immensely.”

The conundrum is that resources to compensate unemployed or under-paid workers will exist, but it’s unclear whether they would be fairly allocated. Mechanisms by which people can benefit from a much richer economy (retraining, income support, or universal basic income, for example) would become a question of economic policy.

“Whether and how those resources reach the people who bear the cost is not something growth delivers by itself,” the researchers wrote.

What users think

As well as developing the framework, the Anthropic researchers conducted a survey among roughly 11,000 Americans, asking them to predict AI use, productivity gains, automation versus augmentation, and displaced work.

They found that, in the main, public expectations land around the “substantial” scenario. That is, GDP would be 10% higher by 2030 than it would be without AI, and the overall unemployment rate would rise to around 5%.

Roughly 10% of respondents, on the other hand, had views in line with the “extreme” scenario.

Anyone can generate their own forecast using the researchers’ interactive tool, answering questions like: “Out of every 100 instances of a task AI can do in 2030, how many will AI actually be doing?”, “How many will be fully automated?”, or  “How much more gets done in an hour in 2030, compared with doing the tasks without AI?” The tool then responds, mapping their predictions to one of the three scenarios.

“Ultimately, what the economy looks like in 2030 depends on many factors, like what AI can do, and how companies and workers choose to adopt it,” the researchers wrote. “It also depends on how the financial benefit of this technology is shared.”

The between-the-lines reality

Sanchit Vir Gogia, chief analyst at Greyhound Research, emphasized that the Anthropic research “maps the conditions under which very different futures appear, it does not schedule destiny.”

He sees the distribution result, rather than the unemployment result, as the serious finding. In the extreme case, GDP is 32.4% above the no AI path, and the cognitive wage bill is 31% below it. Labor’s share of income falls from 60% to 45.2%, and capital income rises 81.4 %. That means a full 15% of GDP is captured as ROI rather than being paid out in labor costs.

In other words, he pointed out: “A richer economy is not automatically a fairer one.” Capability, diffusion, productivity, automation, and occupational friction all have to arrive together.

“AI will touch a large and rising share of knowledge work and will execute a much smaller share under independent authority,” he said. There is no single honest adoption percentage, because worker use, company use, technical exposure, and executed task instances are four different measurements.

Lessons from the research

Enterprises can take important lessons from the research as they deploy AI and consider its impact on their systems, workflows, and workforce, Gogia said.

“For enterprises, the binding variable is permission to delegate,” he noted. “A model that can draft a payment instruction is not thereby permitted to move money.”

His firm identifies five recurring concerns that come up in enterprise conversations: Durable returns after the full cost of deployment, control over authority being granted, augmentation quietly becoming substitution, erosion of professional formation, and fairness of how gains and risks land.

Some of those changes are progressing faster than the governance around them, he observed. Once a system can inspect customer data, change configurations, or act on workforce records, autonomy has stopped being a feature and has instead become an allocation of institutional authority.

“And the tasks easiest to automate are frequently the tasks through which judgement is learned,” he noted.

Kategorie: Hacking & Security

Layoff remorse: Gartner says at least one in three positions eliminated by AI will be restored by 2029–at a higher cost

10 Září, 2026 - 03:27

Gartner on Wednesday said that it expects 30% of the positions eliminated by AI-related layoffs to be refilled by 2029, suggesting that the initial terminations were ill-advised and excessive.

“When business and IT executives look back on the early AI era, they will realize their greatest mistake was believing that work automation was the point, when workforce amplification was the opportunity,” said Tori Paulman, VP analyst at Gartner. “The competitive advantage will go to the CIOs and business executives who build an AI-shaped organization where AI value compounds by reshaping roles and allowing workflows to cross traditional boundaries, increasing velocity and reducing friction.”  

The Gartner report noted that it is finding that the cuts “deplete talent pipelines and erode institutional knowledge.” Beyond the immediate workforce disruptions associated with any mass layoff, companies will also face steep increases in costs for recruitment, training, and onboarding.

It also predicted that, by 2027, “75% of organizations that prioritize capturing AI productivity gains as cost savings will be eclipsed by competitors that aggressively reinvest those gains into innovation, modernization and upskilling.”

In an interview with Computerworld, Paulman said that the 30% figure represents the average impact on organizations of all sizes; they estimate that the layoff boomerang for enterprises would be even higher, roughly 40%. 

Paulman said that Gartner’s research found a lot of what they called “AI washing” by executives who want/need to do layoffs for purely budgetary reasons, and will falsely blame AI for the reductions because it makes them look better.

“More than 50% of our enterprise clients have been given a number [by their bosses],” Paulman said, and have been told by senior management to find that percentage of savings from AI.

But despite widespread evidence of problems due to AI-related layoffs, such job cuts are still increasing. 

Layoffs were ‘excessive’

Other analysts and consultants agreed with the Gartner suggestion that many of these job losses attributed to AI are going to be walked back, but questioned the specific statistic. Some also noted that 70% of the AI-attributed layoffs may remain in force, which would suggest that the original terminations were mostly justified. 

However, Frank Dickson, principal analyst at Dickson Research, argued that a lot of the layoff reversals will occur in a variety of ways that will obscure the fact that they are restoring a terminated role. 

“A lot of that 70% never shows up as a clean rehire even when the original cut was wrong,” he said, pointing out that some of the losses caused service to quietly get worse, and stay poor, some of the work was contracted out or offshored, some of the roles were reconstituted with a different position or title, and some was covered by the remaining staff absorbing the load. This,” he noted, “shows up later as burnout and attrition, not as a line item on this report. None of that gets counted in the 30%, and none of it is evidence the original call was sound.”

Melody Brue, principal analyst for Moor Insights & Strategy, added that the 70% scenario “could show that a substantial share of the AI-related workforce reductions is durable,” but, she stressed, “it shouldn’t be mistaken for endorsement of how those layoffs were made. What it doesn’t show is whether the organization captured the full economic value it expected. A lower headcount is not by itself evidence of a successful AI transformation.”

Valence Howden, advisory fellow at Info-Tech Research Group, questioned the methodology behind the calculation of Gartner’s 30% figure, but he agreed with the overall sentiment that layoffs attributed to AI have been excessive.

“I’m not sure we can substantiate those numbers, since it’s much more of a guesswork statement than anything else,” he said. “I do believe the current trend is going to lead to rehiring, especially as AI governance requirements ramp up and given AI’s lack of contextual semantic understanding. We know AI has not provided the value proposition that it has been sold as providing, and unless costs are controlled, it will be cheaper to use humans to perform some of the advanced work.”

Supporting data

Dickson also raised questions about the Gartner report because it lacked comparative layoff statistics. 

“Gartner doesn’t say what the reversal rate looks like for ordinary layoffs, the ones that have nothing to do with AI,” he said. “Suppose normal cuts get walked back at 10% to 15% in a typical five-year window, which is plausible given ordinary churn and business-cycle rehiring. A 30% rate specific to AI-driven layoffs would still run well above that, and that’s a damning number. Without that comparison, 30% is just a figure floating with no anchor.”

However, Dickson pointed to various datapoints supporting the position that AI layoffs have been excessive, noting that Forrester reported that 55% of businesses “already regret AI-driven cuts and are predicting half of those layoffs get quietly reversed.” 

“Robert Half puts it at a third of hiring executives who eliminated roles for AI having already rehired. Ford, IBM, Booz Allen Hamilton, Alphabet and CSX have all walked back cuts or announced rehiring drives,” Dickson said. “Gartner’s 30% by 2029 sits comfortably inside that range.” Klarna has also walked back AI layoffs. 

A ‘major indictment’

He added that many AI layoffs amounted to a corporate version of a crash diet. “You cut fast, you look great on the next earnings call, and eighteen months later, the weight is back, plus interest, because nobody fixed why the cut was made in the first place.”

Gartner’s Paulman agreed, noting, “business and IT executives who use AI primarily as a tool for cost cutting risk making reductions that are too deep and too soon, affecting their ability to innovate their business model and compete in new markets as AI continues to mature.”

Mike Wilkes, enterprise CISO at Aikido Security, said that even if the 30% figure turns out to be accurate, it is a major indictment of the layoffs. 

“If 30% of AI-driven layoffs must be reversed, that is an enormous error rate for a strategic workforce decision,” Wilkes said. “Imagine any other major capital decision where nearly one-third had to be unwound at a premium three years later. No CFO would call that a strong outcome.”

Kategorie: Hacking & Security

The iPhone is now Apple’s ‘intelligent personal hub’

9 Září, 2026 - 23:11

Twenty-five years ago, I sat near the front of the room while then-Apple CEO Steve Jobs rolled out Apple’s digital hub strategy, a vision in which the Mac would become the central manager of all manner of portable digital devices.

Now, a quarter of a century later, nearly all of those digital devices have become features on your iPhone, and the arrival of AI means the iPhone has become the intelligent personal hub, the central manager of, well, of you. Apple’s new CEO, John Ternus, went straight for the concept in his important opening remarks at Wednesday’s big iPhone launch, where nearly all the pre-event speculation came true.

The intelligent personal hub

“As we look ahead, we see a future filled with enormous discovery and transformation,” Ternus said at the Surprise and Shine event. “AI makes entirely new kinds of experiences possible. An AI can become even more useful when it brings together your life with the apps, services, and products you use every day. And this means the product at the center of your experiences becomes even more essential — what I like to think of as an intelligent personal hub.”

(To be clear: He’s talking about the iPhone.)

Think about it: all those tasks you now do on your iPhone are tasks AI can help you with. Siri AI lets you work on files and folders using spoken commands, while contextual AI lets you sift through all the data once gathered by your iPhone to do things, make things, create networks, or even organize luncheon. 

“It’s the intersection of broad new capability, and a deep understanding of your personal context that makes this idea so powerful,” Ternus explained.

AI’s brave new world

That’s the context within which Apple will be introducing all its future products, a battle the company now feels confident marching into now that it appears to have resolved its historical challenges with AI. At the same time, the company also seems to be doing its best to lean into privacy — enabling life-changing AI transformation of daily lives while putting a brake on scary privacy attacks. This is going to be foundational to what happens next at Apple.

Of course, you’re not reading this to look too deeply into what Ternus said about the future of Apple; you’ll also want some insight into the slew of devices the company introduced at its event. That list includes the:

The big surprise? Price

For some, the biggest surprise in these introductions was price. All of the accessories were kept at the same price as last year’s equivalents, while the new Pro iPhones came in at only $100 more for the entry-level model, rising to around $300 more at the more price-resistant highest end. An iPhone 18 Pro Max equipped with the max 2TB storage comes in at $2,499 compared to the $1,199 iPhone 18 Pro entry point. 

When it came to price, though, all eyes were certainly on the iPhone Duo, and Apple has given everyone (except competitors) a pleasant surprise on that. 

With a starting price of $1,999, the folding phone’s price hit the low end of expectations, and while that grows to an eye-watering $3,199 with 2TB of storage, it compares well with the market leader, Samsung. While the Galaxy Z Fold 8 begins at $1,899, in terms of features and design, Apple’s folding phone lines up with the Galaxy Z Fold 8 Ultra, which costs from $2,099. 

Dig a little deeper and you’ll see that while the iPhone has IP68-rated dust and water resistance, the Samsung equivalent has only IP48. You can drop the Fold 8 into five feet of water for up to half an hour and it should be OK, but you can chuck your iPhone Duo in almost twenty feet of water, and it should survive. Though you probably shouldn’t test that unless you’re a hugely successful “influencer” already generating a small nation state of money through clicks. If that’s you, good for you. I’m only slightly envious. 

A productivity powerhouse?

What that suggests is that the iPhone is less likely to get damaged and is better engineered, though it’s also ever so slightly thicker. Apple’s device is powered by what the company modestly described as the most powerful mobile processor on the planet — which it is, particularly for the AI tasks all the new iPhones can handle. That matters, particularly for applied contextual AI deployed across daily lives.

It also matters because the combination turns Apple’s device into a mobile productivity powerhouse, one that I think will likely affect iPad sales more than anything else. Though this wouldn’t be the first time a new Apple release ended up eating its siblings. 

The productive possibilities of Apple’s premium device will also be realized as app developers embrace both the form factor and Siri AI. Apple said during the keynote that more than 300,000 apps already work with Siri AI and more than 2.5 billion Siri requests are being made each day. That latter number will only grow now that Siri performance has been dramatically improved. 

While this argument applies to all Apple’s new devices, the fact of the matter is that you now have an iPad-sized object you can carry in your pocket that is capable of doing some really powerful tasks by spoken command alone. That’s the iPhone Duo – a product of an unexplored territory at the crossroads between mobile computing, daily digital existence, and the opportunities of AI.

It’s not for everyone, yet

I don’t expect the Duo will be for everyone; the vast majority of users won’t be spending $2,000 on a phone. But we know that the cost of technologies like this tends to decline, which suggests that in perhaps five years’ time, it will be possible to create equivalent devices for a much lower price. Right now, it’s for affluent Apple consumers, C-class executives, students, AI pros, medical professionals and others who might actually need this kind of performance and display space to get things done.

This, incidentally, is precisely the same group of people that first embraced the iPad when it appeared, turning that into the world’s best-selling tablet.

What might this mean for Apple? 

I traded a few messages with IDC analyst Francisco Jeronimo, who sees it like this: “Apple entered the foldable market and, in one keynote, set the price and the standard every rival will now be measured against.”

He also pointed out, the iPhone Duo is “…a direct test of whether Apple can use design, ecosystem integration and premium positioning to reshape a segment that has so far remained selective.” 

He’s right, of course, but Ternus also just defined what that segment, and the industry, is driving for. I’s the same thing Apple was aiming at 25 years ago. “iPhone sits at the center of an amazing ecosystem of intelligent features and experiences that work seamlessly across the products you use every day,” the company said — an “intelligent personal hub.” And the Macs are all right, too.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Adobe Acrobat evolves beyond PDFs with enterprise search, AI content creation

9 Září, 2026 - 20:23

Adobe on Wednesday unveiled a range of updates to Acrobat, including the ability to turn PDF documents into interactive visual reports and podcasts. And a new Knowledge Base feature connects Adobe’s Acrobat AI assistant to document sources such as Microsoft SharePoint and Google Drive.

It’s the biggest Acrobat update in several years, Adobe said, and highlights the application’s evolution from PDF reader to what the company now describes as an AI-powered document productivity and creativity platform. 

Acrobat users open more than 400 billion PDFs in the app each year, Adobe said, claiming 650 million monthly active users as of last year. 

Among the new additions is the ability to turn dense PDFs into interactive, visual documents and presentation slides. To create these, Acrobat’s AI assistant scans the selected file, asks questions about the user’s intent, then generates documents charts, images and navigation.

It’s also possible to turn documents and web links into podcast-style audio summaries — similar to capabilities in Google’s NotebookLLM and Microsoft Copilot Notebook. A new Stylize feature can enhance plain-looking documents, applying a template to turn them into “professional deliverables” such as CVs and invoices, Adobe said.

The audio and visual generation features are all available in paid Acrobat plans (Acrobat Studio, Acrobat Express and Acrobat AI Assistant). 

Another addition, Acrobat Knowledge Base, lets customers connect the Acrobat AI assistant to a wider range of file types, enabling users to ask questions about information held in documents stored in Microsoft SharePoint and Google Drive, for example.  

Acrobat’s Knowledge Base “transforms curated document collections — policies, playbooks, product information, pricing guidance, research — into cited answers available from Slack, Microsoft Teams, Acrobat, and other places employees already work,” Abhigyan Modi, senior vice president for Adobe Document Cloud, said in a blog post. 

Adobe also added an Analyzer tool designed to retrieve data from large volumes of documents. This could involve analyzing thousands of contracts or invoices to identify information such as renewal dates and revenue clauses.

That turns information once trapped in files into data that can inform finance, procurement, compliance, and the systems that support them, said Modi.

Analyzer is the more interesting of the two releases, said Mike Leone, vice president and principal analyst at Moor Insights & Strategy. “Knowledge Base is a search product and search products get judged feature against feature. Analyzer is closer to a data product, because that extraction work is what companies currently pay people and pipelines to do,” he said. 

“What I’d want Adobe to answer is whether that data can leave Acrobat and land where the rest of the company’s data lives. If it can, this starts competing for real data budget. If it stays inside the app, it’s a very good Acrobat feature.” 

Access to Analyzer and Knowledge Base requires an Acrobat Studio for Enterprise subscription. (Adobe doesn’t publish pricing.) 

In addition, Knowledge Base includes a credit-based model that places some restrictions on usage, with licensed users allowed up to 1,000 queries a month. Other actions, such as document uploads, queries from Slack and Microsoft Teams, and queries by employees without an Acrobat Studio license, draw varying amounts of Acrobat Studio “shared credits.” Adobe didn’t say how much additional credits cost once a yearly limit is reached.

 More information about Adobe’s Knowledge Base credit usage policy is available on Adobe’s website. 

Analyzer also includes a credit system that limits document ingestion and attribute extraction.

For enterprise customers, usage-based pricing can add complexity when managing employee access.

“The issue for a broad deployment is that headcount barely predicts usage,” said Leone. “One person pointing it at 10,000 contracts will burn more credits than a hundred people asking the occasional question. Pooling the credits across the whole organization is the right design, because usage on something like this is rarely spread evenly.

“One of the big challenges is that people could very well start rationing themselves because they don’t know what a question costs,” he said. “Or worse, a couple folks use all the credits and everyone else is out of luck. The last thing any organization wants is to pay for a knowledge tool that people won’t use or can’t use.”

Kategorie: Hacking & Security

No, AI is not killing jobs for everyone, studies say

9 Září, 2026 - 18:43

A slew of recent studies indicate that AI isn’t dramatically displacing workers. At the same time, there were no indicators that the fast-moving technology is creating a lot of jobs, even as AI skills remain in high demand.

Stanford University researchers in an August study found that any AI-related job declines were concentrated among young workers aged 22–25. But for older and more experienced workers that wasn’t the case.

“Claims of economy-wide AI-driven job losses are not visible in payroll data through June 2026,” the researchers said, citing ADP payroll information. Stanford partnered with ADP to conduct the research.

The decline for young workers is more often related to the automation of some work tasks by AI, as opposed to its use to complement work. In contrast, AI is more often used by experienced workers to augment what they do. 

According to the Stanford report, workers between 22 and 25 and employed in jobs highly exposed to disruption by AI are falling behind their older counterparts. Their employment levels in June were about 19% below the same age group in less-exposed occupations. That’s compared to where they would be if both groups had kept pace with each other.

“Experienced workers show no comparable gap,” the researchers said, adding that “this is consistent with recent reports of a worsening job market for entry-level workers.”

Employment of younger workers in AI-exposed jobs fell about 11% from late 2022, while the same age group in less-exposed jobs actually grew about 10%. “For older age groups, we find much less marked differences in employment growth across AI exposure quintiles,” the researchers said.

Stanford, which created a lab last year to study AI’s impact amid heightened fears of the technology’s economic effects, said its numbers were based on available indicators.

AI’s adverse impact on young workers has been well documented, with many of them laid off in the initial wave of AI automation. AI has also suppressed wages for entry-level workers.

AI was cited for 116,175 job cuts in 2026, but that number is declining. The technology  was blamed for 3,462 cuts in August, according to data from Challenger, Gray and Christmas.

It’s the “lowest monthly total since December 2025 when 142 cuts were attributed to AI,” the company wrote in a blog entry. The research firm also noted aggressive hiring plans for companies in 2027.

AI is adding value to companies in different ways, and humans are an important part of that process, said Michael Chui, a senior fellow at QuantumBlack, AI at McKinsey. “The night shift is real now,” he said. “People are sending off their agents to write code and checking in the morning.”

MIT late last year established an AI labor index to determine how agents are affecting the workforce. The school’s Project Iceberg looks at how the coordination and interaction with agentic AI changes how work is done.

Despite the disruptions, demand for AI-related talent continues to rise, tech industry consortium CompTIA said last week. About 320,000 job listings in August required AI-related capabilities, a 4.5% increase from July.

AI-related hiring is outperforming the broader tech market, with demand for AI skills up 96% year-over-year, said Kye Mitchell, head of Experis North America, which is part of ManpowerGroup.

“We’re seeing real growth…in marketing management and project management roles, suggesting employers are looking beyond the people building AI to the people applying it,” Mitchell said.

More broadly, the US economy added 162,000 jobs in August, according to US Department of Labor figures released last week. CompTIA noted that tech employment across all sectors rose by 86,000 workers in August.

But within the tech sector, 14,700 positions were cut, CompTIA said.

Kategorie: Hacking & Security

Siri AI Recaps? Even if Apple builds it responsibly, others might not

9 Září, 2026 - 15:05

Late-breaking reports suggest Apple has built a new Siri AI ‘Recaps’ feature that summarizes your day for you. The idea sounds great until you recognize that this summary will also include overheard conversations. 

Suspending the huge red flag of concern over privacy and data protection for a moment or two, why would this be useful and who is it for?

How it’s supposed to work

First, it is being described as an Apple Watch feature that will only be available on the latest models: Apple Watch Series 12 and Apple Watch Ultra 4, as these allegedly include secure audio processing hardware. Reading between the lines, that suggests the devices will be able to listen to and process audio on device, which implies that the information won’t need to leave your smartwatch, not even to your iPhone.

The report also says the feature doesn’t make a transcript, nor does it store the audio; it instead gathers key datapoints from what is said to include in the summary, deleting all the remaining information in the process. You can have the feature working all day, on-demand, or only in specific locations. The idea seems to be to provide some kind of actionable summary of events and key conversations that take place during the day. I imagine the subtext is to digitize as much as possible of your daily existence as Apple thinks you will be comfortable with to create the kind of datapoints contextual AI requires if it is going to help with your life.

The case for it

That sounds fine, up to a point — the idea that a digital assistant will be able to recognize key events, moments, and requirements to remind us of them, act on them, or suggest next steps concerning them is certainly a notion that’s gained currency in tech circles. They see it as augmenting human achievement, enabling people to become more productive, more efficient, and capable of doing more with less effort. At least, that’s part of the argument.

What is wrong with that (other than concerns over privacy or a desire not to have one’s entire waking life transformed into a series of datapoints that can be measured, tested, or surveyed by entities outside of our control), right? If you have nothing to hide, you have nothing to fear, at least, not until times change and what didn’t need to be hidden in the past becomes something that must be shrouded in future.

Apple’s privacy defense

Apple, of course, has its strong privacy story to lean into as it introduces this surveillance-as-a-service solution; it’s an argument that says it recognizes how this tech can be abused, and wants to deploy it correctly. It will point to that record as it promises its system doesn’t gather data, doesn’t collect it, and doesn’t keep any form of transcript on or off the device. The company should be commended for building a system that works this way, recognizing as it does that the best way to protect confidential information is not to gather it in the first place.

The warning

But what Apple has also done with this new speculated upon — and as-yet-unconfirmed product — is to show us what these tools can already do. Much of this is already visible; take recent news that LG smart TVs constantly collect and upload user data as an illustration of the seemingly egregious ways in which such tech is used. (LG denies the claim.) What Apple shows us is that with AI in the picture, all your waking moments can be collated, curated, analyzed, digitized and rendered into actionable data. Apple may not be doing that, but others will not be equally cautious, so we owe Apple a debt for warning us of what’s at stake.

Though we don’t know whether Apple will actually introduce this new service, the source of the claims is one of the strongest in the industry. What we do know is that the technology required to build systems like this exists, along with AI systems capable of sourcing, sharing, and sifting through that information. What we don’t yet know is how to remove ourselves from the data stack.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

AI notetakers at work could leave companies at risk for lawsuits

9 Září, 2026 - 13:00

AI note-taking applications are increasingly used by workers to record meetings, generate conversation summaries and suggest post-meeting action items. 

Along with the promised productivity benefits — enabling users to focus on meetings rather than actively taking notes — the emergence of these AI tools has raised privacy questions, particularly around obtaining prior consent by meeting participants for their use. Those concerns, in turn, have prompted a spate of lawsuits against software vendors that sell AI notetaking tools.

In some ways, the underlying questions are not new: It’s long been possible to record a phone call with a dictaphone, and laws around surreptitious recording have been around for decades. Yet widespread access to AI notetakers via desktop or smartphone apps means that it’s easier than ever to record a conversation for future reference. 

Among the thorny questions arising from the technology’s use: what happens to conversation data sent to a software vendor’s servers for processing? Are the recording and transcript used to train those vendors’ AI models, for example, or create biometric voiceprints? Those practices are among the issues being considered in US courts. 

Otter, which claims to have 35 million users, was subject to a class-action complaint in a federal court in California last year. That complaint accused Otter of recording individuals without consent and using their voices to train its speech recognition AI tools. Last month, a judge rejected Otter’s attempt to dismiss the main claims, though the scope of the case was narrowed.

A lawsuit filed against another vendor, Fireflies, in an Illinois court late last year, alleges the company collects and stores biometric voiceprints without user consent, in violation of the Illinois Biometric Information Privacy Act (BIPA). Fireflies claims to have more than 20 million individuals and 1 million organizations as customers.

Earlier this year, a class-action complaint in a Washington court claimed that a live transcription feature in Microsoft’s Teams collaboration application also violates BIPA by collecting biometric data without consent. 

And most recently, a complaint alleged that Granola, a well-funded startup, designed its product to be used without the knowledge of all meeting participants, in violation of the Electronic Communications Privacy Act (ECPA). That complaint also claims Granola trains its AI models on conversation data without consent. 

None of these cases has yet been resolved, and it’s unclear whether any of the vendors broke the law in the design and delivery of their products and services. But the lawsuits highlight considerations for businesses that allow the use of AI notetakers, both in terms of prior consent for recordings and understanding how conversation data is handled.

More broadly, the lawsuits raise questions about how existing privacy and consent rules apply to new technologies that make it easier to record others, whether through AI note-taking apps, smartglasses, or other recording devices.

Computerworld spoke with Brian McGinnis, partner at law firm Barnes & Thornburg and a founding member and co-chair of the firm’s Data Security and Privacy Law practice group, about the focus of the lawsuits, potential outcomes, and how businesses can deploy AI notetaking apps safely.

Several cases have already been brought against popular AI note-taking apps. What are some of the main commonalities between these? Which laws are the vendors accused of breaching? “The common allegation is that these companies capture communications of people who did not agree to the recording or receive adequate notice. Some of the lawsuits also allege that meeting data is used to train AI models and that consent cannot meaningfully be withdrawn once the data has been processed.

“There are various federal and state claims. You’ve got the Electronic Communications Privacy Act, a federal wiretapping statute. As a general matter, the Electronic Communications Privacy Act permits an interception when one party consents, subject to statutory exceptions and questions about whether the technology constitutes an unlawful interception or third-party eavesdropping. In other words, if you, as the user, provide consent, you can be on a meeting with 20 other people and it’s deemed to be sufficient; you don’t necessarily need to get the consent of other people. 

“But California and a minority of other states are what we call ‘two-party consent’ states, meaning each individual on the call has to give consent; it’s not sufficient for you as the person who turns the notetaker on to provide the consent — you also have to get the consent of others that are being recorded. There are state laws around that.

“There’s a law called CIPA, the California Invasion of Privacy Act, that’s being utilized in this context.  We see a lot of suits being brought under that law — it’s a wiretapping statute designed for telephone wiretapping that’s now being applied to the internet.”

What about the use of biometric data? “A growing number of states regulate biometric data, with Illinois’ BIPA being particularly prominent because it provides a private right of action. This means an individual can sue a company for violation of the law.  

“That law covers biometric information. With an audio recording or recording of ‘dumb’ video that isn’t running any algorithms, you’re not necessarily collecting any biometrics. But when you start identifying people, you’re recording things like faceprints or voiceprints, which are in the definition of biometric information within the statute. Now you’re not only collecting personal information, but also biometric information, which is considered very sensitive and much more highly regulated. 

“Then you’ve got the private right of action that goes against it. Part of the argument here is that recordings taken by the AI notetakers can be used to produce some form of biometric information, such as a voiceprint.  

“We’ve seen a lot of cases, and a lot of changes in industry as a result of this law. Shutterfly had a famous case about scanning for people’s faces and things like that in Illinois that changed the photo storage and processing industry a little bit. 

“A lot of companies stay out of Illinois to avoid this law specifically. But a customer organization might not know exactly who’s in a meeting and where a person is located at the time of the meeting. So, you need to either follow that law and get individual consent, or stay out of states with biometric laws if you want to use some of these tools. 

“It’s just a further challenge for these applications if the goal is to be used as much as possible with as little detection as possible.”

What are some of the potential outcomes for these cases? “I think it’d be unlikely to get an outright ban, absent passing some kind of new law that says these tools are per se illegal for use. It’s much more likely the outcome will require some changes and controls over the way that they get used. The clearest case would be some kind of a pop-up notice: ‘Hey, this meeting’s being recorded, here’s who it is, here’s their privacy policy, here’s their terms of service – do you consent to it?’ And getting opt-in consent from anybody who wants to be recorded. 

“The notion that only one person in the meeting has to say it’s okay and you can just automatically record everybody else, I think that’s probably at risk, and could potentially be replaced with a standard that requires everybody to consent before it’s considered legal.

“But the newer —and more interesting — wave of these is the Granola case, where part of its marketing is that people aren’t aware that it’s there. The Granola complaint alleges that the product was designed to operate without alerting other participants. It’s possible that kind of activity could result in a decision that would ultimately ban it outright. In other words, that it’s illegal to utilize these tools if you aren’t providing notice to everybody and/or aren’t getting consent from everyone on the call. That’s a possible outcome that we could see.

“To me, that’s interesting when you think beyond AI note-taking and into the broader world, with conversations around, like, Meta Glasses, or any of these kinds of AI wearables. Granola in particular has an Apple Watch app, and there are other wearable or physical devices — there’s one [Plaud Note] that sticks on the back of your phone and is essentially an always-on recording device. 

“With these devices, you’re going from an online meeting where you can provide notice and there’s a structure to obtain consent, to walking down the sidewalk and recording people and casual conversations. Maybe it’s somebody you’re having a conversation with, maybe it’s somebody at the table next to you in the coffee shop that you have no relationship with whatsoever — what are the laws around consent and notice in those cases, where there’s no digital interface to put that up in front of people? Do you have to go around with a pad of paper and a pen and get people to sign consent to use these things? Do you have to physically tell them?

“Those are the more interesting conversations that this line of cases is just at the beginning of helping us get some answers on. In other words; how do you get consent? How do you provide notice in a world where we don’t have documents or screens in front of us to easily handle that? Those are interesting questions that the law will have to figure out here.”

These tools are increasingly used in the workplace. How can businesses be sure they deploy the technologies safely? “We’re getting a lot of questions from our clients about this topic, because they’re really unsure and uncertain of how to handle these tools.

“Obviously, there’s a push for broad use of AI within their companies, for productivity increases within their company. People like the tools; they want to be able to use them. But then we also hear a lot of stories about ‘I jumped on a meeting; I didn’t even know it was being recorded, then I got an email afterward with a transcript of it,’ and ‘half of what it recorded wasn’t actually what I said, or it was interpreted incorrectly’ — things like that. So there’s a lot of consternation amongst our clients about the people within their organizations using it. 

“I can’t tell clients definitively that they’re legal as they are; there are ways to use this legally and safely that aren’t going to get your organization sued, but you probably have to do some things that are beyond what’s provided ‘out of the box’ by the software providers. 

“With Granola, for example, my understanding is that certain notice features may not be enabled by default. You can turn on video or audio watermarking, and you can turn on the notice that pops up in these things, but I think it ships without those features enabled. That puts the responsibility on the individual user to determine and then implement their own legal privacy and legal compliance mechanisms using their settings.

“You really have to play to the most stringent state’s law. I would advise a company that, to decrease your chances of getting in trouble for use of these tools, you need to obtain consent of all parties on the call. You can do that verbally, as well; written is even better. 

“Then it’s about having an internal AI note-taking policy. Think of a BYOD policy, which all these companies have, or an AI usage policy — this could be part of that policy, or a standalone policy: ‘Here’s how our organization thinks about these tools:  you can only use these approved tools and, if you’re going to use them, you have to turn on these features. You have to get consent from everyone. Here are limits on what you can do with the output of those transcripts or recordings.’ 

“If you set all that up and do the compliance and governance work, I think you can use these tools and most likely stay on the right side of the law. Certainly, the law doesn’t prevent consenting adults from consenting to the use of these kinds of tools.  

“But the further you get away from that written consent standard, the more problematic it becomes. If you just want to go to a notice standard and not obtain actual opt-in consent, or, even worse, if you want to try and do this without anybody knowing, that potentially could get challenged.”

Kategorie: Hacking & Security

Wanna make your own Android ping tone? Ask Gemini

9 Září, 2026 - 11:45

By now, you probably know my stance on Gemini and other generative AI gobbledegook — right?

In short: It’s an insanely powerful form of technology (obviously). But it’s also wildly inaccurate and ineffective as an all-purpose answer engine, and by cramming it into every last nook and cranny, Google is doing a serious disservice to its users — and to itself.

That being said, generative AI can be incredibly useful. The key is simply to frame it as a purpose-specific tool for the right type of limited task as opposed to treating it as the end-all answer for everything, as most tech players seem overly eager to do these days.

Here in the land of Android, I’m always looking for purpose-specific ways Gemini can make our lives easier. Over time, I’ve found those ideas often aren’t the big headline-making features Google and other tech companies market but rather random little off-the-beaten-path possibilities that rarely get emphasized.

Today, I’ve got a new Gemini Android advantage for you to explore — another one that I’ve never seen advertised anywhere but that works brilliantly well and solves a long-standing limitation of our modern mobile gizmos.

It’ll take you all of a minute to master and cost you precisely $0 to pull off. Ready?

[Get next-level knowledge in your inbox with my free Android Intelligence newsletter — one useful new thing to try every Friday, straight from me to ye.]

Gemini’s custom sound advantage

This Gemini-provided power-up very much follows the path of thinking about AI as a limited, purpose-specific tool for a narrow task — the exact sort of area where AI excels.

I won’t keep you waiting: Gemini, as I discovered whilst poking around within it recently, is really good at generating unique, custom ringtones and notification sounds based on your personal preferences and specifications.

It almost seems obvious, once you think about it. But I sure hadn’t thought about it up until now — and I suspect most other folks haven’t, either.

The advantage here goes beyond just superficial silliness, too: By creating your own custom ringtones and notification noises, you can know exactly what event your phone is alerting you to within a split second of hearing the associated sound — without having to rely on the same limited and often underwhelming pool of default options that everyone else uses (or, worse yet, having to lean on shady, ad-ridden “ringtone apps” to find mediocre alternatives). That means you’ll know within a heartbeat when your boss or an especially important client is calling or if an incoming call is a random unknown number.

On the notification front, you can create a specific, memorable sound to accompany a new message in an important work-related Slack channel and a different distinctive sound for a high-priority email. They’ll all be sounds that you make and identity with and that no one else in the world uses. That’s pretty powerful.

And creating these custom sounds couldn’t be much easier, either, once you realize it’s possible:

First, just fire up Gemini on your phone (or on any device you’re using) and tell it what you want. So, for instance…

  • Create a soft, subtle ringtone that’s reminiscent of an old office phone sound.
  • Create a ringtone that sounds like an 8-bit version of The Final Countdown.
  • Create a one-second high-pitched notification sound that brings to mind the Super Mario Bros theme song.
  • Create a short notification sound that mimics the Back to the Future time circuits noise.
  • Create a notification sound that sounds like a robot saying “ALERT, ALERT!”

The only limit is your imagination. And if you’re not feeling especially imaginative, you can even ask Gemini to give you a list of ideas for distinctive, memorable ringtones or notification sounds based on geeky nostalgia, 80s pop-metal, or whatever it is that tickles your fancy.

Once you’ve sent a request, Gemini will — somewhat confusingly — spit back a big honkin’ block of HTML code. This is because, for reasons unknown, the system can’t or won’t just provide a sound file directly. Go figure.

Ask, and ye shall receive: Gemini’s ringtone-creating prowess in action.

JR Raphael, Foundry

But from there, it’s just one more quick step to get the file you need: Click or tap the copy icon in the upper-right corner of that code block — the icon that looks kinda like two stacked, rounded rectangles — to copy the entire chunk of code onto your system clipboard.

Then open up your browser and go to the website JSFiddle.net. It’s a well-known, long-standing tool for running code like HTML right in your browser and seeing the result, and it works entirely in the browser and without any downloads or special permissions required.

Tap or click into the “HTML” field, then paste in the code from your clipboard (by long-pressing any open space, on Android, and selecting “Paste” from the menu that appears). Click or tap the “Run” button, and — ta-da: You’ll see a player to listen to your custom Gemini-generated sound and a button to download it.

The JSFiddle website makes it easy to take Gemini’s output and both play and download a sound file from right within your web browser.

JR Raphael, Foundry

Provided you like what you hear, hit the button to download the file, then head into the Sound section of your Android system settings to save it and make it available for applying as any kind of alert or ringtone. The exact steps for doing that will vary from one type of Android device to another, but on a Pixel or another phone that follows Google’s core Android interface, you’ll tap on either “Ringtone” or “Notification,” then tap “My Sounds” and tap the plus icon to import your own custom file from your phone’s local storage.

On a Samsung device, you’ll start the same way but look for the plus icon within the “Ringtone” section of the settings, then tap the “Folders” tab to find your locally downloaded files. Samsung doesn’t make it easy to add in your own custom notification sounds, annoyingly, so what you’ll have to do is open up the Google Files app, find the file you downloaded in your “Downloads” folder, then tap the three-dot icon alongside it to copy it to the folder called “Notifications.” Once the file is in that folder, it should show up as a notification noise option within the Samsung Android settings.

And remember: You can use Android’s notification channels to set specific sounds to be used for different types of alerts, even within a single app — and you can use the Google Contacts app to set custom ringtones for different people, too.

With Gemini as your personal composer, you’ll never be stuck with generic overused sounds again — and you’ll always know exactly what’s happening from the first note of whatever noise you hear.

Keep the experience-enhancing wisdom coming with my free Android Intelligence newsletter. One new useful trick in your inbox every Friday!

Kategorie: Hacking & Security

Leap second proposal will keep software stacks in sync

9 Září, 2026 - 07:24

For decades, global time experts have mapped atomic clock time to the earth’s rotation, periodically adding a second (aka a leap second) as rotation slowed. But the planet’s rotation has now slightly sped up, which could mean that a negative adjustment will be required. 

The problem is that computer systems have not been programmed to do that.

To avoid this issue, the General Conference on Weights and Measures (GCWM) in October will vote on a proposal to maintain the Coordinated Universal Time (UTC) as a continuous time from May 20, 2027, without adjustment via leap seconds, allowing UT1, the measure of time based on the earth’s rotation, and UTC to drift apart by up to one hour.

It pointed out, “a negative leap second has not previously been applied, and it is considered to pose a high risk of causing anomalies and disruption to critical infrastructures that are largely unprepared, and the preparation would create, for the industries that rely on time synchronization, a need for financial investment, whose amount is estimated to be similar to their preparations for the millennium bug.”

The group said that a 2025 workshop which included experts on Earth rotation estimated that the probability of a negative leap second will increase rapidly in the near future, reaching 30% by 2035. Acceptance of the proposal, it said, will ensure the long-term continuity for UTC for several centuries.

Unexpected requirement

Jeremy Roberts, senior director at Info-Tech Research Group, said that authorities never expected the need to reverse time. 

“We have been adding leap seconds for decades, basically to keep atomic time in line with observed time, but this is the first time we’d have to take one away. The problem is that computer systems aren’t designed to work this way,” Roberts said. “Rather than introduce a negative leap second, the proposal here is to let the two clocks go out of sync rather than keep adjusting to keep synchronicity with UT1 time and atomic time, which is much more consistent and not impacted by changes in the Earth’s rotation. This would make it easier for those building and maintaining infrastructure, because the clock would behave in a predictable way.”

Still, Roberts stressed that the proposed approach might eventually cause problems. 

“As with all things, this will require work to implement, and because the proposal includes a provision that allows for the clocks to go up to an hour out of sync, that would presumably create a problem for our descendants when we eventually reach that point,” Roberts said. “[But] being indecisive could cause fragmentation in standard time as different entities move to different standards, which could come with its own set of problems.”

Frank Dickson, principal analyst at Dickson Research, added that this proposed move is revolutionary in time-keeping circles.

“This is the biggest change to civil timekeeping since the leap second itself was adopted in 1972,” Dickson said. “Earth’s rotation has historically been slowing down, so that’s the only direction the system has ever had to handle. What’s crazy is that the Earth’s rotation has been speeding up in recent years, requiring a negative leap second, subtracting a second instead of adding one. Nobody has ever run that in production, at global scale, on the systems the world actually depends on.”

Dickson said that it is critically important that the vote pass, because the IT community has seen what happens when clocks malfunction.

“In a world of interlocking software applications, you cannot always predict how a global change will impact digital systems. In 2012, one ordinary positive leap second took down Reddit, LinkedIn, and Qantas’s booking system,” Dickson said. “It also triggered a race condition in the Linux kernel that spiked CPU load across servers worldwide. Nobody had tested for it because it had never happened before.”

And another incident involving timekeeping took down the Telstra network in Australia just last month. 

A ‘more rational’ engineering decision

Mike Wilkes, enterprise CISO at Aikido Security, pointed out that the consequences of a negative leap second could be significant. “Skipping a second can expose assumptions buried in databases, distributed systems, authentication systems, schedulers, market infrastructure and logging platforms,” he said. “The CGPM proposal is effectively saying that, rather than forcing the entire digital economy to prepare for a novel failure mode, we should make UTC continuous. That seems like a far more rational engineering decision.”

Most consultants and analysts agreed that if the vote to adjust current time procedures fails, the resultant problems would likely happen gradually, and possibly dramatically.

“The most likely problem would not necessarily be one spectacular global outage. I would be more concerned about thousands of smaller inconsistencies occurring simultaneously,” said Boris Kolev, global head of technology at JA Worldwide. The problems he anticipated included timestamps appearing out of order, distributed transactions behaving unexpectedly, authentication tokens being interpreted incorrectly, monitoring and audit trails becoming inconsistent, or different systems disagreeing about the sequence of events.

Systemic technology risk

But Kolev warned of a potentially more severe problem, as different companies sharing varied technology dependencies with enterprises try tackling the time problem differently.

“That means an enterprise does not only have to worry about what its own servers do. It has to consider what happens when its cloud provider, operating system, identity provider, database, external APIs, and on premises systems interpret the same moment differently,” Kolev said. “This is precisely the type of systemic technology risk that concerns CIOs: individually, every dependency may look manageable, but globally there are millions of interconnected systems maintained by different organizations, written in different eras, and operating under different assumptions.”

Justin Greis, CEO of consulting firm Acceligence, also said that he hoped the proposal would pass. 

“I think this is one of those cases where delaying what appears to be the technically correct answer may actually be the more responsible engineering decision. At some point, you have to ask whether preserving the relationship between civil time and the Earth’s rotation to within a second is worth introducing operational risk across financial systems, telecommunications networks, cloud platforms, power infrastructure, transportation systems and countless other technologies that depend on precise synchronization,” Greis said. “For the overwhelming majority of enterprise technology, I don’t think it is.”

This article originally appeared on Network World.

Kategorie: Hacking & Security

Apple after Cook: The Ternus age begins this week

8 Září, 2026 - 13:46

We’re hurtling toward the loss of something big. Finally, after months of speculation, Apple is about to introduce its first-ever folding smartphone. And once it does, the conversation will change as the annual iPhone rumor season is replaced with the reality of whatever Apple unveils.

Except, it won’t quite be the same as in the past. Because no sooner will new Apple CEO John Ternus finish his iPhone announcement keynote speech tomorrow than the speculation will shift to next year’s 20th-anniversary iPhone, what’s coming to the iPhone 18 and e-series iPhones, and expectations around Apple’s upcoming wave of smart home products, including health and home security services. There’s a lot going on.

Meet John Ternus

Having a lot going on is one of the prime expectations of Apple under its new boss. A family man with a wife and kids, he’s led Apple’s hardware division for five years after an eight-year stint running hardware engineering. He joined the company in 2001 and is described as a highly competent, hugely talented, and modest by nature. 

His hobby is quite revealing — he drives race cars, is a regular at California’s Laguna Seca Raceway, and owns an incredibly rare 2019 Porsche 935. To me it suggests a calm, competent, individual with excellent mental and physical reflexes who can make life or death decisions at speed. He’s also deeply committed to good product design.

He’ll need that calm embrace of speed and adrenaline to manage the company his predecessor, Tim Cook, led to become the world’s most valuable firm. 

A hard act to follow

He’s also got a hard act to follow, as while Cook had to carve out his reputation in the shadow of Steve Jobs, Ternus must sculpt his own destiny in the shadow of Cook, who managed to make shareholders of record in 2011 around 20 times richer by the time he quit. (Apple stock rose from $13.74 per share on a split adjusted basis to $319.97 per share today.)

While Cook was frequently criticized for not being a product guy, he presided over the launch of the Apple Watch, AirPods, Apple Silicon, and the Vision Pro, and helped grow Apple’s services income to become its second-biggest product category, diversifying Apple’s revenue and creating financial stability. That’s no easy task.

Building his own team

Can Ternus improve on that? He’s certainly being positioned as someone who can. His deep experience in hardware has led to expectations that Apple will double down on product under his watch, so a great deal is expected of him in consequence. He is also putting together a hardware-focused team, including Laura Legros, former vice president of hardware engineering, as a direct report.

What will we see of this tomorrow? To be fair, while he will lead the announcement on the keynote stage, development of this first tranche of products took place under the leadership of Cook, and while Ternus will have had a big hand in development, this year’s Apple event should be seen as a moment of transition. 

“I’m just as excited about what lies beyond that, including the incredible products already in the works and the ones we haven’t even imagined yet that we’ll dream up and create together. There’s no team in the world I’d rather build the future with,” Ternus told Apple staff in his first memo as CEO.

It’s what Apple does in the next couple of years that will truly define the new leadership. He’s literally been CEO for a week!

What to expect on Sept. 9

Here’s my TL; DR list:

  • First folding iPhone: Apple’s response to folding devices from Samsung, Google, Huawei, Xiaomi. It’s expected to have a highly durable, near invisible hinge and a powerful 2nm A20 chip around 20% more performant than the 17 series devices; Touch ID; a 48MP camera; and be able to unfold from a 5.5-in. to a 7.8-in. display. Potentially called iPhone Ultra, some predict it might be the “iPhone Duo” or “iPhone Fold.” It’s likely to cost $2,000+.
  • iPhone 18 Pro series: Equipped with a fantastic new display, smaller Dynamic Island, 48MP main camera, and telescopic lens and supported by a fresh tranche of pro-photography features, the 18 Pro/Pro Max range will also use A20 chips. Both the fold and Pro devices will carry significantly more RAM, enabling them to handle on-device AI tasks. Apple is expected to introduce the iPhone 18, iPhone Air 2, and iPhone 18e devices at a spring 2027 event. Prices on all iPhones are expected to increase by $100 or more, depending on model.
  • Apple Watch Series 12, Apple Watch Ultra 4: While Apple is thought to be working on new designs for next year, this year’s models will — for the first time in years — include an improved processor, better networking, and more accurate heart monitors. A model with a ceramic body is expected, while the devices will be equipped with additional storage, and integrated satellite emergency features. 
  • AirPods 5: Earlier speculation about cameras inside AirPods remains, but these aren’t expected at the launch. Instead, Apple’s AirPods 5 will be boosted with a new H3 Wireless Chip for better voice isolation, noise cancellation, and spatial audio. They may also provide some basic health monitoring features with a built-in temperature sensor and heart rate monitoring.
  • Smart home products: Apple is still expected to introduce additional products for smart homes, including an Apple TV with a faster processor and SiriAI support, a HomePod mini upgrade, and — potentially — a new home hub. The latter could effectively be a combination of an iPad with a HomePod to run apps, control smart devices, take and make calls, and run Siri.
Finding the next big thing

While all these products are important to the company, the smart home devices should demand attention (if they appear at all), as the indicators suggest Apple intends to explore the smart home space with a range of future hardware, including domestic robotics, security services, and smart devices. This hardware proliferation in new markets could end up becoming one of the hallmarks of Ternus’ Apple leadership, as will Apple’s AR spectacles (once they are introduced). 

Equally, it cannot be ignored that one of Ternus’ main tasks since becoming vice president of hardware has been the introduction of new Macs and the transition to Apple Silicon. So he’ll be expected to strike a balance between improving Apple’s traditional product lines while racing his company toward new and emerging opportunities in hardware. (I believe Apple should pay much more attention to the enterprise space within that.) 

Apple’s little AI problem

The biggest challenge to all of this will be Apple’s success in implementing AI that’s good enough to get things done while avoiding the unexpected dangers of poor implementation. We don’t want AI agents corroding smart home security, for example, which is why Ternus seems likely to maintain Cook’s focus on security and privacy as enabling technologies to support trusted hardware/software product designs.

Another thing? Tomorrow’s keynote will likely begin with the single word, “Hello,” and feels very likely to also include that classic Apple keynote line, “…One more thing.”

We’ll find out more as the conversation moves from speculation to reality after the 10am (PT) keynote.

Please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

Swiss government explores replacing Microsoft 365 with open-source software

8 Září, 2026 - 13:10

Swiss authorities have launched a pilot project to determine whether it is possible to replace Microsoft 365 with similar open-source services, RTS reports. This follows a proof-of-concept project in which 172 civil servants tested the German open-source platform openDesk.

According to Matthias Stürmer, a professor at the University of Bern, there are three main reasons for the switch: to reduce dependence on US services, to improve operational reliability, and to reduce costs.

In the first phase, the migration involves 3,000 computers, which corresponds to 7% of Switzerland’s federal workforce. The government has more than 54,000 workstations in operation. The pilot will prioritize employees who have access to highly sensitive data, according to RTS.

A move by the Swiss Armed Forces from Microsoft 365 to openDesk is already underway, with that migration expected to be completed in October, It’s FOSS reports.

Switzerland’s move is part of a larger ‘digital sovereignty’ effort in the European Union that aims to retain local control over data, applications, and infrastructure. In January, lawmakers directed the European Commission to map critical technology dependencies and then develop policies to reduce reliance on foreign providers.

This article originally appeared on Computer Sweden.

More on the EU’s digital sovereignty push:

Kategorie: Hacking & Security

Judge spares Google’s ad-tech business from a breakup

8 Září, 2026 - 13:00

Back in April 2025, the US Department of Justice (DoJ) proudly proclaimed that it had prevailed in a landmark antitrust case against Google’s ad business. Yeah. Right.

You see, just last week, US District Judge Leonie M. Brinkema rejected the DoJ’s effort to force Google to sell its AdX ad exchange. What began as a major anti-monopoly victory has become a mouse-sized settlement. 

[ Google US antitrust trials: A timeline ]

Does any of this this sound familiar? It should. We’ve seen this show before. Last year, Google had also been convicted of abusing its search business. At first, all the talk was about how Google might be forced to divest itself of the Chrome browser and/or the Android operating system. 

Instead, Google was allowed to keep making search deals and only had to share some search data with its rivals. 

I say rivals, but in fact Google still dominates the search market. Indeed, its control has actually expanded a bit. By StatCounter’s numbers, in August 2025, Google search owned 89.89% of the market. By last month, almost a year after the company had been slapped on the wrist, its share had grown to 91.1%. 

Boy, wasn’t that a win?

The remedies phase of the government’s ad-tech antitrust case order is a similar Google win. No, it doesn’t overturn the April 2025 finding that Google unlawfully maintained monopolies in the publisher ad-server and ad-exchange markets, or that it illegally tied its ad server and exchange together. Instead, it determines how the company must change its conduct.

The DoJ wanted Google to divest itself of AdX, the company’s ad exchange for matching publisher inventory with advertiser demand. It also sought to require Google to open-source the final-auction logic in its DoubleClick for Publishers (DFP) ad server and, if necessary, divest its DFP business. 

Brinkema rejected all three requests. Instead, her short order accepts “most” of the parties’ proposed behavioral remedies, subject to modifications described in a memorandum opinion that remains sealed while the parties identify confidential information for redaction.

Specifically, the court directed Google and the plaintiffs to meet and submit a joint proposed final judgment within 30 days. If they cannot agree on the details, each side must submit its own proposed version.

Google — as it should — sees this as a win. As Lee-Anne Mulholland, Google’s vice president of regulatory affairs, said in a statement, “We’re very pleased the Court rejected the DOJ’s proposal to break apart tools that help small businesses reach new customers and grow.”

Far less convincing is the DOJ’s characterizing the decision as a win. “The Antitrust Division is pleased that the court ordered substantial relief in the Google ad-tech case. We are one step closer to restoring competition and bringing relief for the American people in online advertising markets.” 

Oh please! It does nothing of the sort.

To quote Laurel Kilgour, research manager at the American Economic Liberties Project, an anti-monopoly, nonprofit group: “Judges keep finding Google guilty, but Google keeps walking away with both its ill-gotten gains and its empire intact. Without actual structural remedies, antitrust rulings are just inconvenient speed bumps that allow Google to lock down search and ad tech markets today while using that same unchecked power to monopolize tomorrow’s AI frontier.”

Exactly so. 

The specific obligations Google will face are not yet public, because Brinkema’s explanatory opinion remains under seal. Earlier, Google had proposed making real-time bidding responses from AdX available to rival ad servers, removing Unified Pricing Rules, and accepting a monitoring trustee for a three-year supervision period. None of that will even dent Google’s ad business.  

When all’s said and done, Google is still in charge of both its exchange and publisher ad-server operations. I expect the minor changes required won’t amount to a hill of beans. Restoring competition in markets where the company was found to have used its vertically integrated position unlawfully? Give me a break. 

Public Knowledge, a free speech and internet advocacy group, described the decision as one that leaves Google’s monopoly power substantially intact. 

As Public Knowledge Legal Director John Bergmayer said, “The court found that Google illegally acquired and maintained monopolies in publisher ad servers and ad exchanges, and used its control of DFP and AdX to shut out rivals.” He concluded, “Telling a monopolist to do better is not the same as restoring competition.… A finding of liability means little if the remedy leaves the market fundamentally unchanged.”

Ya think? 

In Google’s last reported quarter, the company reported $81.6 billion in advertising revenue. Next year, when Google is being “punished,” I expect its revenue will be even higher. 

Kategorie: Hacking & Security

BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

8 Září, 2026 - 12:54

A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said.

The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel.

The panel contained 5,137 credential records linked to 461 targeted organizations across more than 40 countries. CloudSEK also reported 4,148 captured session cookies and 1,032 plaintext passwords. The firm said 474 records showed completed logins in which attackers captured the authenticated session created after MFA.

BigBear 2.0 is built on Evilginx2, a framework that places an attacker-controlled reverse proxy between the victim and Microsoft’s legitimate authentication service. The victim signs in through the proxied page and completes MFA as usual. Once Microsoft issues an authenticated session cookie, the phishing infrastructure can intercept it and allow the attacker to reuse the session without completing the authentication process again.

The operation also uses residential proxies selected according to the victim’s country, which can make malicious authentication traffic appear geographically consistent with the user. CloudSEK said this technique can weaken location-based checks used in Conditional Access policies.

Researchers also found custom code designed to disable FIDO2/WebAuthn authentication on the phishing pages, potentially steering users toward weaker, phishable authentication methods.

CloudSEK described BigBear 2.0 as a multi-user service with at least five identified affiliate operators. The company said it observed 42 virtual private server (VPS) nodes over the campaign, with 26 deleted from the panel since late July.

IT services and managed service providers accounted for 151 of the organizations identified by CloudSEK, making them the most heavily represented sector in its data. Such organizations can present especially valuable targets because employees may hold privileged access to customer environments and administrative systems.

Session theft moves into the mainstream

The significance of BigBear 2.0 is not just its ability to capture authenticated sessions after MFA, but the way it packages techniques once associated with more skilled attackers into a service that can be used at scale, said Keith Prabhu, founder and CEO of Confidis.

The underlying technique is not new, said Akshat Tyagi, associate practice leader at HFS Research. “What BigBear 2.0 changes is accessibility and scale,” Tyagi said. “It packages AiTM phishing, residential proxies and automated cookie replay into a service that lowers the expertise needed to run these attacks.”

That shift means enterprises need to think beyond protecting the authentication event itself, he said, because a captured session may give an attacker access to Microsoft 365 without another password or MFA challenge.

Prabhu added that successful MFA should no longer be treated as proof that an account or session remains secure.

Session cookies and access and refresh tokens should be treated as high-value authentication material rather than technical artifacts behind the password, said Sakshi Grover, senior research manager for cybersecurity products and services at IDC Asia Pacific.

The risk, she said, is that many enterprise controls are still geared toward detecting credential theft rather than the hijacking of an already authenticated session.

Phishing-resistant authentication becomes critical

OTP, SMS, and push-based MFA should not be relied on as standalone defenses against this type of attack, Tyagi said, because the attacker can allow the legitimate user to complete authentication before stealing the resulting session.

Tyagi said enterprises should enforce phishing-resistant authentication such as FIDO2/WebAuthn passkeys rather than merely making it available alongside weaker alternatives. Prabhu pointed to Windows Hello for Business and certificate-based authentication as additional options, with stronger methods enforced through Conditional Access authentication strengths.

Grover said organizations should also use Continuous Access Evaluation and token protection where Microsoft 365 supports them, but cautioned against treating token protection as a complete solution because coverage varies across platforms, clients and workloads.

The problem is also operational, Grover said. Identity and access tools are not always sufficiently integrated with security operations or SIEM platforms, leaving potentially useful identity signals disconnected from the analysts responsible for detecting attacks.

Password resets are not enough

“Treat the event as an active session compromise, not merely a stolen-password incident,” Prabhu said.

He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication. Incident responders should then examine Microsoft 365 logs for evidence of mailbox access, malicious inbox rules, unusual OAuth consent, newly registered MFA devices, privilege changes, and access to other cloud applications.

Tyagi cautioned that IP location may provide limited reassurance in such investigations because residential proxies can make attacker activity appear geographically consistent with the legitimate user. Responders should instead focus on reconstructing what occurred during the compromised session, he said.

Investigators should also determine whether the stolen session was used to reach other employees, customers, or external contacts, Prabhu added.

Grover said organizations should also include session hijacking in tabletop exercises, testing how identity, security operations, messaging, and cloud teams would coordinate during an authenticated-session compromise. Such exercises can expose gaps that may not emerge in simulations centered on conventional credential theft or ransomware, she said.

The article originally appeared on CSO.

Kategorie: Hacking & Security

Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access

7 Září, 2026 - 14:20

OpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.”

“First, sorry for the messy rollout,” OpenAI CEO Sam Altman acknowledged the issue in a post on X. “Second, when we screw up, we try to make it right.”

OpenAI had said GPT-6 Astra would be rolled out across ChatGPT tiers and APIs, positioning it as its most advanced model to date. However, the initial rollout did not translate into immediate access for all users, highlighting the gap between model launch and availability across subscription tiers.

Only the organizations enrolled in its Daybreak cybersecurity program were able to access the model, whereas Plus, Pro, Business, and Enterprise ChatGPT subscribers, along with developers using the OpenAI API, were left out.

“Third, we should be able to begin broad rollout to API customers and ChatGPT subscribers in the near future. As usual, we will start with pro subscribers,” Altman continued in the post.

Altman wrote in a follow-up X post on Friday that OpenAI had extended Astra to Pro, Enterprise, and Business Premium users in ChatGPT’s Work and Codex products and had opened it up through the API.

“It might take a few days to roll out to our Plus and Business users,” OpenAI’s official X account posted on September 5.

The company did not immediately respond to a request for comment.

Phased rollout continues without firm timelines

OpenAI introduced GPT-6 Astra on September 4, stating that availability would expand over time rather than being enabled simultaneously for all users.

Altman’s post followed complaints about access during the initial rollout window, although OpenAI has not disclosed how many users were affected or how access varied across tiers.

In a subsequent post on X, Altman said: “We are working towards getting Astra in everyone’s hands as quickly as we can; I know it is frustrating,” indicating that access was being expanded incrementally.

OpenAI technical staff member Thibault Sottiaux confirmed in a separate X post that Plus and Business users had gained access too, crediting the company’s infrastructure: “more scalable than we anticipated.”

The rollout approach is consistent with OpenAI’s initial communication that Astra would be made available over several days, rather than at once. Gartner also noted that the model was first released to a limited set of organizations before broader expansion.

Rollout highlights the gap between launch and access

Analysts said the sequence reflects a distinction between model announcement and actual availability.

Greyhound Research said the Astra rollout should be treated as an operational signal rather than a confirmation of readiness.

“Announced, available, entitled, and production-ready are four separate states,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “This must be treated as operational evidence, neither dismissed as theatre nor inflated into proof that Astra has failed.”

He added that staged availability reinforces the need for enterprises to verify what level of access they actually receive, rather than assume uniform rollout across users or environments.

Gartner said enterprises will need to strengthen governance as they evaluate Astra’s capabilities.

“CIOs must balance Astra’s advanced automation with stronger cybersecurity, governance, and cost controls before adoption,” Gartner analysts said in an initial note on the launch shared with Computerworld

The firm said Astra’s ability to execute more autonomous workflows will require tighter evaluation controls and observability.

It also pointed to challenges around identity, security posture, and accountability as AI agents take on more complex roles.

Contracts and control models under scrutiny

Greyhound Research said the rollout raises questions about how enterprises define access and operational control.

“A conventional uptime SLA is too narrow for Astra,” said Gogia. “Critical describes the engine. It does not tell the buyer how much of that engine reaches the road.”

He said enterprises need to account for how such systems behave in production, particularly when access, interruption, or task continuity may vary.

“A stop leaves a state the enterprise did not choose, and that state needs a record it can defend,” Gogia said.

The rollout also highlights changes in how governance responsibilities are distributed.

Gogia said administrative controls alone do not address enterprise requirements.

“Admin opt-in is not a safety certificate,” he said. “It is the point at which accountability crosses from vendor release policy into an enterprise governance decision.”

He added that such controls do not extend automatically to API-based deployments, where enforcement depends on enterprise-level systems.

Capability gains introduce trade-offs

OpenAI has positioned GPT-6 Astra as an advance in reasoning, coding, and automation capabilities.

Gartner said these improvements introduce trade-offs that enterprises will need to evaluate in production settings.

While Astra may reduce token usage for some tasks, organizations must consider overall task costs, including validation and oversight, the firm noted.

Gartner also cautioned against over-indexing on early capability claims. “Without more evidence, CIOs should ignore the AGI hype for now and instead focus on use-case-specific evaluations, demonstrated business outcomes and reliable autonomy,” the firm said.

The story originally appeared on CSO.

Kategorie: Hacking & Security

16 Gmail power moves for more efficient inbox management

7 Září, 2026 - 12:00

You might not know it from looking, but Gmail is jam-packed with time-saving tricks.

Some of ’em are right there in front of your face, if you know how to find ’em — while others require a teensy bit of under-the-hood tinkering to activate. But all of ’em are built right into Gmail and have the potential to make managing your email a heck of a lot easier.

Check out these 16 splendid Gmail tips and get ready to master your inbox once and for all.

(Note that unless otherwise specified, these tips are specific to Gmail’s web-based desktop version.)

Inbox step-savers

1. You can actually view attachments right from your Gmail inbox. Provided you haven’t switched away from the service’s “default” interface arrangement, you’ll see small tiles for every file associated with an email right below the message’s subject line. And you can click on any of those tiles to open or preview the file’s contents and get directly to the info you need.

Gmail’s attachment tiles are a great way to jump directly to attachments without having to open an email.

JR Raphael / Foundry

2. It’s easy to miss, but take note: When you hover your mouse over a message in your inbox, Gmail gives you a series of quick-access actions at the far-right side of the line. You can archive the email, delete it, mark it as read or unread, snooze it, or even RSVP to a meeting request right then and there — without ever having to open the message.

3. A super-useful keyboard shortcut I always forget to use: While viewing a multi-email thread of messages — a conversation in which you have numerous back-and-forth replies under the same subject — hit the semicolon key (;) to expand the entire conversation and show every message in the thread. And then hit the colon key (:) to collapse it back down so you see only the most recent email.

Just make sure you enable keyboard shortcuts first, if you haven’t already: Click the gear icon in the website’s upper-right corner, then click “See all settings” and look for the “Keyboard shortcuts” option midway down the screen that comes up. Select the “Keyboard shortcuts on” setting and then be sure to click the Save Changes button at the bottom of the screen.

4. Some of Gmail’s best keyboard shortcuts are the ones you create yourself. Go back into the website’s settings and this time, click the Advanced tab. See the line labeled “Custom keyboard shortcuts”? Click “Enable” next to that, then click the Save Changes button at the bottom of the screen.

Once Gmail refreshes itself to apply the changes, go back to the Settings area again and look for the newly present Keyboard Shortcuts tab. There, you can adjust any of the default keyboard settings to make them simpler to activate or easier to remember.

One of my favorite adjustments, for instance — and one I rely on constantly — is adding in a second command for the “Go to inbox” shortcut, which is typically gi by default. In Google’s old Inbox service, that shortcut was simplified down to just i, and once you get used to that shorter sequence, you won’t want to go back.

5. The panel at the right of Gmail’s web interface lets you pull up Google Calendar, Google Keep, Google Tasks, or Google Contacts right inside your inbox so you can manage info from each of those apps without having to switch tabs or open anything new. And here’s a handy hidden trick: With Tasks, you can drag messages directly from your inbox into the panel to create new tasks around them.

Creating new tasks from emails is as simple as dragging and dropping, as is being done here with the topmost message.

JR Raphael / Foundry

Unfortunately — and somewhat strangely — the same drag-and-drop behavior isn’t currently possible with Calendar or Keep, nor is it possible for Contacts.

6. Even with a miniature version of Contacts being available inside that handy side panel, you might sometimes want to pull up the full Google Contacts website for its complete set of features. Provided you’ve got Gmail’s keyboard shortcuts enabled now, commit this workaround to memory: Pressing g and then c will open up Contacts in a separate tab, no matter what else you’re doing in your inbox.

Composing shortcuts

Editor’s note: Assuming you’ve enabled keyboard shortcuts (see tip 3), the following keyboard shortcuts work in any browser on any desktop operating system. Mac users, just swap in the ⌘ key for “Ctrl” wherever you see it.

7. Ever like marking messages as unread after you’ve opened ’em? Gmail makes that incredibly easy to do: Anytime you have an email open, look for the envelope icon directly to the right of the trash can in the horizontal row of icons above your message (in the area directly beneath the search bar). That’ll let you mark the message as unread with a single click. Or, for a faster and more powerful one-two punch, just type an underscore (_) while viewing any message. That’ll mark it as unread and zap you back to your main inbox.

8. Speaking of combining multiple actions into a single command, simplify your inbox organization process by enabling Gmail’s convenient Send & Archive button. It places a second button alongside the regular Send button whenever you’re responding to an existing message, and clicking that button (or, even better yet, hitting Ctrl-Enter on your keyboard) will send your response and archive the thread in one fell swoop.

To enable it, look for the “Send and Archive” option within the General tab of Gmail’s settings. Click “Show ‘Send & Archive’ button in reply,” hit the Save Changes button at the bottom of the screen, and then get ready to save yourself steps the next time you type a reply.

Gmail’s Send & Archive button (the blue one to the left of the regular Send button) turns two steps into one.

JR Raphael / Foundry

9. I don’t know about you, but I frequently start typing an email and then decide against sending it. (Rather fittingly, I started typing out a lengthy explanation of the reasons but then decided against including it.) If the same thing ever happens to you, remember this: Hitting Ctrl-Shift-D while you’re in the Gmail compose tool will close the compose window and discard your draft. And it works whether you’re writing a new email or a reply.

10. Another awesome time-saver: In addition to the obvious Ctrl-B for bold and Ctrl-I for italics email formatting shortcuts, Gmail has hotkeys for doing some advanced forms of text formatting — things that’d otherwise require multiple clicks and much menu-hunting to accomplish.

The ones I use the most:

  • Ctrl-Shift-8 will add a bulleted list into your email (just like this list!), and Ctrl-Shift-7 will add a numbered one.
  • Ctrl-Shift-9 will offset text in a blockquote style.
  • Ctrl-] will indent text, while Ctrl-[ will remove any indentation.
  • And Ctrl-\ will remove any formatting on your selected text and make it as plain as can be.

11. You’d never know it, but the Gmail compose tool itself can take on various forms, depending on your preferences. Make a mental note of these possibilities and the shortcuts to get to ’em:

  • To start a new message in the default lower-right-corner-of-the-screen window view, hit c.
  • To start a new message in a pop-up window totally separate from your main Gmail tab, hit Shift-C. You can do the same thing for a reply by hitting Shift-R while viewing a message thread — or Shift-A for reply-all.
  • To start a new message in a full-screen compose window within your main Gmail tab, hit c — then click the little arrow icon in the compose tool’s upper-right corner. (You can also hit Shift while clicking that icon to pop the message out into a separate pop-up window form.)
  • If you’d rather use that full-screen compose window all the time, by default, click the three-dot menu icon in the lower-right corner of the compose tool and look for the “Default to full-screen” option there. (If you ever change your mind, you’ll find the option to disable that preference in that very same spot.)
  • If for some reason you like the idea of composing a message in a new tab instead of a pop-up window or within the main Gmail tab, just hit d while in your inbox. That’ll do the trick!

To see more keyboard shortcuts, just type ? while viewing any message list within Gmail.

Smarter snoozing

12. Don’t forget to take advantage of Gmail’s super-handy snoozing tool: Instead of letting messages linger in your inbox and pile up to an unmanageable point, use the snooze function to help yourself deal with everything as soon as you see it.

A good rule of thumb to maintain: If you can respond to something in less than a minute, do it. If something doesn’t require any action on your behalf, archive it immediately. And if something requires some sort of action but you don’t have the time to mess with it at that moment, snooze it to a day and time when you will be able to handle it.

You can snooze an email from your inbox by hovering over the message and selecting the clock-shaped Snooze icon, as noted in tip 2. You can also snooze an email while it’s open by clicking the three-dot menu icon to the right of the folder symbol directly above the email and then clicking “Snooze” within the menu that pops up. Or you can simply press b while you’re viewing a message or while you have it selected in your inbox.

Snoozing a message causes it to vanish from your inbox and then reappear at any day and time you choose.

JR Raphael / Foundry

13. Gmail even makes it possible to snooze multiple messages at the same time — in case you see more than one email that needs to be pushed back to the same point. From your inbox, simply click the boxes to the left of any messages you want to include, then click the three-dot menu icon within the row of icons toward the top of the screen and select “Snooze” from there.

14. Need to get back to something you snoozed — or change the day and time at which it’s set to reappear? You can always find all of your snoozed emails in Gmail’s Snoozed section, located beneath the “Inbox” line in the left-hand panel. Once you’re there, just hover over any email and click the clock-shaped icon to change its snooze settings or unsnooze it entirely.

15. You can snooze messages from the Gmail mobile apps, too, though the option is a bit buried. From the inbox view, press and hold a message to select it, then tap the three-dot menu icon at the top of the screen and look for “Snooze” in the list of options that appears. If you’ve already opened the message, tap the three-dot menu icon at the top of that screen; you should see “Snooze” show up as part of the options there as well.

16. Make snoozing even simpler in the Gmail mobile app by assigning it to one of your inbox swipe actions. Just open up the app, tap the three-line menu icon in its upper-left corner, then select “Settings.” On Android, tap “General settings” followed by “Swipe actions”; on iOS, you’ll tap “Inbox customizations” and then “Mail swipe actions.”

All that’s left is to set either your left swipe or right swipe to “Snooze,” and then, you can simply swipe any message in that direction from your inbox to snooze it — no wasted taps or menu diving required. (The Gmail Android app has several other similarly useful hidden features, by the way, most of which aren’t available on iOS.)

With one quick setting adjustment, you can snooze any message from the  Gmail mobile app simply by swiping it to the left or the right from your  inbox.

JR Raphael / Foundry

And with that, your Gmail time-saving toolbox is officially complete! The next logical step in your inbox improvement adventure is mastering the art of Gmail labels to fight back against email chaos — and I’ve got just the guide to get you started.

This story was originally published in May 2018 and most recently updated in September 2026.

Kategorie: Hacking & Security

Google US antitrust trials: A timeline

5 Září, 2026 - 12:20

Google’s dominance in the search arena has given rise to two major antitrust lawsuits from the US government alleging the company has manipulated the market to maintain that dominance, to the exclusion of competitors and the detriment of the public at large.

The first lawsuit, targeting Google’s search business, kicked off in mid-September 2023 and drew to a close in May 2024; US District Judge Amit Mehta ruled against the tech giant in August 2024. The remedy phase of the trial ended in September 2025 with Judge Mehta rejecting the DOJ’s request to break up the company, instead imposing data-sharing requirements.

The second trial against the tech giant, focused on advertising, took place over 15 days in September 2024, with US District Judge Leonie Brinkema ruling against Google in April 2025. In September 2026, Judge Brinkema ruled that Google is not required to break off its ad exchange, instead opting for behavioral changes that have yet to be revealed publicly.

The cases heavily echo the turn-of-the-century Microsoft antitrust case in several respects, most notably that Google, like Microsoft before it, has evaded the forced breakup requested by regulators.

Here’s our condensed timeline of the two overlapping lawsuits and their progress through the court system.

Sep. 2, 2026, advertising lawsuit: In a second big win for Google, Judge Brinkema rules that the company does not have to sell its AdX ad exchange. The search giant is also not required to open-source the final-auction logic in its DoubleClick for Publishers (DFP) ad server or divest its DFP business. Behavioral remedies are sealed while the parties identify confidential information for redaction.

Sep. 2, 2025, search lawsuit: In a significant win for Google, Judge Mehta rules that the tech giant does not have to divest its Chrome and Android businesses as the US government had requested, and it will be allowed to continue paying Apple and other browser makers for default search placement. To level the competitive playing field, Google will have to share search index and user-interaction data with rivals and offer search results syndication.

April 21, 2025, search: The remedy phase of Google’s search antitrust trial begins with Judge Mehta presiding. Federal prosecutors warn that Google might leverage artificial intelligence to entrench its search monopoly, demanding “strong measures” to prevent the tech giant from extending its market control into the AI era. These include requiring Google to divest Chrome, end exclusive default search agreements, license its search data to competitors, and potentially sell its Android operating system if other remedies fail.

April 17, 2025, advertising: In a second landmark defeat for Google, Judge Brinkema rules that Google illegally monopolized the ad tech market. The company’s “exclusionary conduct substantially harmed Google’s publisher customers, the competitive process, and, ultimately, consumers of information on the open web,” she wrote in the ruling. Remedies, which could include the breakup of Google’s advertising products and/or changes to its business practices, will be imposed at a future date.

Oct. 8, 2024, search: The US Department of Justice submits a court filing proposing that the Chrome browser and Android operating system be split off from Google as part of sweeping remedies aimed at curbing the tech giant’s monopoly in online search and advertising.

Sept. 20, 2024, advertising: The US Department of Justice is set to wrap its case in the Google antitrust trial after an eventful two weeks. The tech giant is accused of engaging in monopolistic behavior by strategically acquiring certain companies and controlling the adtech industry’s most widely-used tools and exchanges,  beginning with its acquisition of advertising company DoubleClick in 2008.

Sept. 9, 2024, advertising: The second major case against Google begins with the company defending itself against claims it engaged in illegal behavior to maintain control of the ad tech market. The US government is accusing Google of purposefully manipulating that market, snuffing out competitors and gobbling up key technologies through acquisitions. If the DoJ successfully makes its case, Google risks being broken up by regulators.

Aug. 5, 2024, search: In a major defeat for Google, Judge Amit Mehta rules that the company had engaged in anticompetitive behavior in an effort to protect its search business. In the 277-page decision, Mehta was blunt: “After having carefully considered and weighed the witness testimony and evidence, the court reaches the following conclusion: Google is a monopolist, and it has acted as one to maintain its monopoly. It has violated Section 2 of the Sherman Act.” Mehta’s ruling did not include remedies for the anticompetitive behavior; those will be decided later.

May 3, 2024, search: Over two days of closing arguments, the DoJ revisits its case for Google having a monopoly on search advertising, and Judge Mehta quizzes both parties about whether other platforms could be viewed as substitutes for Google’s search advertising business. He hasn’t said how long he expects to take to reach a decision, but if he rules against Google, a second hearing will take place to decide on any remedies.

Nov. 16, 2023, search: The evidentiary phase of the trial finishes, as Judge Mehta issues instructions for post-trial submissions. Despite considerable amounts of redaction and closed-door testimony, the case revealed some unprecedented details about the relationships between the largest tech companies in the world, including the fact that Apple apparently keeps 36% of the search revenue from Google searches in Safari, and Apple once considered buying Microsoft’s Bing search engine as leverage against Google. Judge Mehta has scheduled closing arguments in the case for May 1, 2024.

Oct. 31, 2023, search: Google CEO Sundai Pichai takes the stand, for long-awaited testimony about the relationship between his company and Apple. He gave some details about Google’s negotiations with Apple over a contract that made Google the default search engine on Apple’s iPhones, iPads, and Macs. Google has paid billions for the privilege of being the default search on Apple products, and the relationship is a key part of the case – which was underlined by the Justice Department’s cross-examination of Pichai, during which he admitted that default search status is a major driver of market share.

Oct. 18, 2023, search: Google begins its defense, calling Paul Nayak, a vice president of search, to the stand as its first witness. Nayak downplays the importance of scale in his testimony, stressing that machine intelligence, compute infrastructure, and a team of 16,000 staff that checks on search results are crucial to maintaining quality of service. DOJ witnesses including DuckDuckGo CEO Gabriel Weinberg and Microsoft CEO Satya Nadella had testified that Google keeps an edge over competitors via an ever-increasing trove of data — the result of its default search engine status, maintained through exclusive contracts and billions of dollars in payments to Apple, Samsung and other companies. This data gives Google an advantage in refining search engine results, they said. 

Oct. 3, 2023, search: As a witness for the prosecution in the Google antitrust trial, Microsoft CEO Satya Nadella warns that Google’s monopoly profits could lock in publishers as AI-enabled search arrives. Nadella argued that it’s almost impossible to compete with Google, given the search leader’s massive competitive edge in collecting and analyzing user data. He also warned that Google, with its vast profits and lock on the search market, stands poised to extend its monopoly power in a new era where artificial intelligence technologies will turbocharge the search business.

Sept. 26, 2023, search: Apple’s Eddy Cue testifies behind closed doors in the Google search case, as critics slam presiding Judge Amit Mehta’s decision to hold much of the trial’s testimony from witnesses secret, allow documents to be heavily redacted, and block some documents from public view — mainly at the insistence of Google, but also at the request of other companies, including Apple. By the end of Cue’s testimony — and after a wek of wrangling by all parties — Judge Mehta rules that documents used during the trial can be published online at the end of each day, but still allows time Google and third parties to object to exhibits being shown publicly before the DOJ presents them in court. 

Sept. 21, 2023, search: Judge Mehta rules that public access to court exhibits, which have been mostly internal Google documents thus far, should be removed, after Google challenged the Justice Department’s regular publication of them. The company said that it was concerned for its employees’ privacy.

Sept. 12, 2023, search: The default search trial begins with opening statements, and the government begins its case.

Aug. 2023, search: Judge Mehta grants partial summary judgment for Google in the search case, saying that the government had failed to raise a genuine dispute of material fact on antitrust charges relating to contracts around the use of the Android operating system, as well as Google Assistant and IoT devices. The claims relating to Google’s exclusive “default search” contracts, however, are allowed to proceed to trial.

July/Aug. 2023, search: Google and the plaintiffs in the search case argue various motions in limine, designed to control what evidence should be included or excluded in the actual trial. Discovery and motion practice over evidence continues in the advertising case.

June 2023, search: Judge Mehta schedules a trial date of September 12, 2023 for the search case.

April 2023, advertising: Judge Leonie M. Brinkema denies Google’s motion to dismiss in the advertising case.

March 2023, advertising: Google’s motion to transfer the advertising case to New York is denied by Judge Brinkema, who orders the parties to propose discovery schedules within two weeks of the order. Two weeks later, Google moves to dismiss the case for failure to state a claim, arguing that the plaintiffs have simply produced legal conclusions, and not specific facts, that could support their claims. Judge Brinkema schedules pre-trial conferences for January 2024.

Feb. 2023, search: The plaintiffs in the default search case case move for sanctions against Google, accusing it of spoliation, which refers to the destruction, alteration or failure to preserve relevant evidence in a case. Elsewhere, in the advertising case, Google moves to transfer the case from the Eastern District of Virginia to the Southern District of New York, which is seen as an attempt to consolidate the case with related digital advertising antitrust litigation.

Jan. 2023, advertising: A second antitrust action, pushed by eight states and the DoJ, is filed in federal district court in eastern Virginia. The plaintiffs, who call for Google’s advertising business to be split up, accuse Google of manipulating its dominant position in the online advertising world to squeeze out rivals and control both the supply and demand side of the advertising market. Google, according to the complaint, thwarted fair competition by manipulating fees, punished advertisers for using alternative platforms and ad exchanges, and engaged in a host of further anti-competitive behavior in the interest of monopolizing the marketplace. (This is case that began in September 2024.)

Dec. 2022, search: Google moves for summary judgment against the separate Colorado case and the larger, DoJ-led case. A summary judgement motion is essentially a request by one of the parties in a lawsuit that the judge rule in their favor and end the case, arguing that, based on the undisputed facts, they are entitled to win the case as a matter of law.

May 2022, search: A deadline of June 17 is set for the production of all discovery materials. Further documents – for example, those whose is existence is first disclosed in late in the discovery window – can be produced until June 30.

May 2022, search: Judge Mehta denies a government motion to sanction Google for inaccurately classifying documents as attorney-client privileged. The plaintiffs had argued that emails on which Google’s lawyers were listed as recipients or CCed, but that the lawyers never responded to, constituted a misuse of the attorney-client privilege rules.

Dec. 2021, search: Judge Mehta conditionally splits Colorado’s claims from the case at large, ordering that separate trials on that state’s issues of liability and remedies will be “more convenient for the Court and the Parties, and will expedite and economize this litigation.”

Aug.-Oct. 2021, search: Discovery-related motions and orders continue, as Yelp and Samsung join the fray. (Those companies, like Microsoft and Apple, are relevant to the case even if they aren’t parties themselves, as their internal records are potentially relevant to Google’s liability.)

June/July 2021, search: The discovery process continues, and the US and Google both file several documents with the court under seal. (Microsoft files two sealed documents, as well, in response to Google’s subpoenas for company records, and Apple becomes involved after the government requests access to some of its internal information.)

March 2021, search: Meetings between Google and the various governmental plaintiffs continue, with periodic status reports on the discovery process.

Jan. 2021, search: Google files a response to the complaint, admitting to many of the facts alleged by the Justice Department and associated attorneys general, but categorically denying the substance of the government’s claims of illegality. Further responses to separate but related claims, generally to specific state attorneys general, follow in the subsequent weeks and months.

Dec. 2020, search: Judge Amit Mehta approves the joinder of Michigan, Wisconsin and California to the suit.

Oct. 2020, search: The Department of Justice, along with the attorneys general of 11 states, sues Google in DC federal district court for unlawfully maintaining a monopoly, in violation of Section 2 of the Sherman Act. The case centers on Google’s use of exclusive contracts that mandate its use as the default search engine in a host of different hardware and software applications, with the government alleging that this represents an artificial constraint on any possible competition for the search giant.

Kategorie: Hacking & Security

How to automate your Gmail inbox — without AI

5 Září, 2026 - 12:00

Gmail is filled with hidden features and add-on possibilities, but one of the service’s most powerful organizational tools is sitting right in the heart of its regular settings.

As you may have guessed by now (especially if you read this story’s headline, you clever little cat), I’m talking about filters — Gmail’s long-standing system for automating your inbox with a series of custom-crafted rules. At a glance, filters can seem complicated. They can seem overwhelming. They can even seem unnecessary.

But don’t let yourself be fooled by the feature’s curiously crusty exterior. Gmail filters have the potential to completely reshape your inbox and the way your incoming messages are handled. They can help you keep your email in order with no ongoing thought or effort.

And, unlike Google’s new AI Inbox option (which notably still doesn’t seem to be available for most people as of this writing), filters (a) don’t require your personal messages to be processed by generative AI systems — and (b) give you complete control over exactly how your email is handled instead of forcing you to rely on inherently unreliable technology to figure out what you want for you (and then likely come up short at least some of the time).

Best of all? All it takes is a teensy touch of one-time planning to get Gmail filters set up to your exact specifications and working for you quietly and automatically from that moment onward.

Follow the filter-centric Gmail tips in this guide, and your inbox will be running like a well-oiled (but not too greasy) machine in no time.

Part 1: Figuring out your Gmail filters

Let’s start by thinking through some Gmail filter possibilities to get an idea for the sorts of setups you might want to consider — then, we’ll go step by step through the process of creating them.

With Gmail filters, you could:

  • Ensure messages from specific high-priority senders always go into your inbox’s Primary tab, where you’re certain to see them
  • Ensure specific sorts of lower-priority messages — like invoices, reports, or updates from different services you use — automatically get sorted into an out-of-the-way location and never even show up in your inbox
  • Keep messages from annoying people out of your hair (but still available in case you need to find them) by automatically archiving them as soon as they arrive
  • Forward messages from a specific address or with a specific phrase in their subjects to other members of your team or family
  • Instantly respond to messages to or from a specific address with a prewritten template
  • Label messages sent to a specific variation of your Gmail address (like [email protected]) or written with a specific word or phrase in the subject (like “urgent,” “important,” or “hey jerkwad, pay attention to this”) as “VIP” and then receive notifications only for messages with that designation
  • Mark specific types of messages from yourself as reminders by giving them a bright yellow “REMINDER” label that makes them stand out in your inbox
  • Get a snickerdoodle delivered to your desk every time your boss emails you

All right, so that last one isn’t really possible (not yet, anyway) — just wanted to make sure you were still paying attention. Everything else in that list, however, is absolutely doable and actually quite easy to set up with Gmail filters.

Got some ideas of your own? Good deal. Time to make ’em happen.

Part 2: Creating your Gmail filters

The simplest way to start a new Gmail filter is to click the control panel icon — the symbol showing three horizontal lines stacked on top of each other — within the big search box at the top of the Gmail website. (Filters can’t easily be managed on mobile, unfortunately, so you’ll need to do all of this in a desktop browser.)

That’ll pull up a form where you can fill in whatever you want to use as the basis for your filtering — a word or phase that might appear within an email’s subject or body, an address from which a message could originate, or any other variable or combination of variables you like.

The form for creating a filter is filled with options for controlling email automation.

JR Raphael / Foundry

Fill in the fields as appropriate, using however many variables you want — even employing quotation marks around multiword terms along with operators like “AND” and “OR” between terms, if you really want to get fancy — and then click “Create filter” at the bottom of the box.

You can use any combination of variables, even employing operators within a single field, to control when your filter will run.

JR Raphael / Foundry

One quick warning: By default, your filter will apply to any and all incoming messages — hence the “All Mail” setting that shows up next to the “Search” option in the filter creation pop-up. If you change that option to “Inbox,” you’re likely to see an error message informing you that the parameters you chose are not recommended and may not work properly. Leave that “Search” option set to “All Mail” — which is probably what you want, anyway — and you’ll steer clear of any errors and allow things to work the way they should.

Now it’s time for the fun part — the part where you decide exactly what happens when a message meeting your conditions arrives. You can select any combination of actions from the list and then configure them as needed. You can even tell Gmail to apply your filter retroactively to messages already in your account (as opposed to using it only for new messages that arrive from that point forward) by checking the “Also apply filter to matching conversations” option at the bottom of the box.

Gmail’s filters include a variety of actions that can execute when your conditions are met.

JR Raphael / Foundry

Once you’ve got that finished, click the blue “Create filter” button — and that’s it: Your new Gmail filter is officially in place and active. The next time any message comes in that meets the parameters you outlined, the actions you specified will automatically take place faster than you can say “I embrace Workspace in my workplace cyberspace.”

Part 3: Managing your Gmail filters

Last but not least, make yourself a mental note in case you ever need to adjust your filters in the future: If you want to edit, delete, or even just revisit a filter you created, just click the gear-shaped icon in the upper-right corner of the Gmail website, click “Settings,” then click the “Filters and Blocked Addresses” tab at the top of the settings screen. You’ll see every filter you’ve ever created there and can tweak or remove any of ’em with a couple quick clicks.

Now if only we could find a way to get the filters to deliver those blasted snickerdoodles for us. Hey, Google: Any chance you can make that happen?

This article was originally published in October 2019 and most recently updated in September 2026.

Kategorie: Hacking & Security