British energy company SSE Energy Supply refused to believe that there was no unit 8b at the property of Lyle Hopkins, a doctoral student at the University of Oxford. For more than 20 months, the company billed Hopkins at business rates, a total of £1,091.01, for an unused electricity meter on the property that had been associated with a previous owner’s unsuccessful effort to convert the property into flats. A company representative even sent an email on June 15, 2024, stating that Hopkins was not liable. Nonetheless, SSE then sent in debt collectors to recover debt attributed to a disconnected meter for a non-existent address. He never paid the bill. But he wanted the harassment to end. So Hopkins, a software engineer working on his PhD at Oxford Interdisciplinary Bioscience DTP, turned to GPT-5.5 and Claude Fable for legal guidance to challenge the unwarranted and annoying collection effort. Representing himself in court, he prevailed on July 17, when a judge at the County Court at Oxford (St Aldate) awarded him £1,087.88, including expenses and interest. Citing The Register’s coverage of how courts have required lawyers to declare and verify AI-generated documents, Hopkins said his experience has been that it’s the verification that matters. “I used AI to test an energy company’s court claims against its own records, then ran the hearing myself and won,” he said. Hopkins said he wouldn’t have been able to quote the case law without the help of AI. “I had to review everything and give it steering, and make sure the case law actually existed,” he said. “I mostly just gave it the facts and it came up with the arguments, checked the laws, court rules, case law, and regulations. Really I just knew what they had done couldn’t be right, and relied on the AI to find the legal justifications as to why.” Hopkins said that when he first submitted his claim back on October 7, 2025, GPT models hallucinated more and weren’t as good at checking case law. “If Fable had been around at the time, I probably would have claimed for a lot more, probably around £5,000 and included harassment, which would have been more in line with the case law it found when we were preparing the court documents about three weeks before the hearing.” Hopkins didn’t consider a solicitor because the cost would have been prohibitive. His spending on AI was more modest but not trivial – three active AI subscriptions and extra API fees. “I burned a lot of tokens on this, on my Github Copilot subscription, OpenAI subscription, and Anthropic subscription,” he said. “Due to the deadlines I ended up paying API rates for some of it, which was painful.” (~£175). His award could have been higher. “Before the hearing, SSE offered me more than the court ultimately awarded, conditional on confidentiality and non-disparagement clauses,” Hopkins said. “I refused because it was more important to be able to tell people what they had done.” A rollercoaster ride The judge hearing the case – shared with The Register – said Hopkins, who sought the intercession of an Energy Ombudsman after repeated communication with SSE, could not have done more to make clear that he was not liable for claimed debt. “The defendant has subjected Mr Hopkins to a rollercoaster ride and not a good one,” the judge said, adding, “pursuing Mr Hopkins for that liability, if continued, would amount to harassment.” Yet even after Hopkins won, the billing contniued. Following the judgement on July 17, another bill datedJuly 23 went out. “Since the judgment…in direct contradiction to the ruling which stated any further attempts to claim the invalid debt from me would constitute harassment, they have sent me another bill with payment demand,” Hopkins told The Register. He’s unsure whether he will pursue a harassment claim. “This dragged on for nearly three years and cost hundreds of hours, lost sleep, and time that should have gone into my medical-research doctorate at Oxford,” he said. “My exhibits alone were over 100 pages. Given how difficult this was, I struggle to see how people less academic than me wouldn’t end up with CCJs and ruined credit ratings over debts they never owed.” Hopkin’s doctoral funding ended before he could finish his degree, a delay he attributes to time spent on this case. So he has launched a funding campaign to support the completion of his doctorate. The Register emailed SSE seeking comment and received an autoreply indicating that that SSE media team was unavailable outside of business hours in the UK. The urgent inquiry number yielded a representative who indicated that he only handled questions about outages. If company representatives reply after returning to the office, we’ll update this story. ®
Category Archives: tech
The balkanization of virtualization will de-throne VMware, which doesn’t mind a bit
ANALYSIS VMware is about to lose its status as the undoubted leader of the virtualization market after a 20-year reign – a result it doesn’t mind one bit, but which also signals an industry-wide end to significant innovation for traditional server virtualization. The end of VMware’s reign will come slowly, then suddenly, between now and October 2027, a period that includes three dates that tens of thousands of VMware customers will have circled on their calendars to remind them of ideal deadlines by which they should change virtualization platforms or reduce their use of VMware. And at VMware’s annual user conference, which kicks off today, the Broadcom business unit probably won’t make a new pitch for them to stay. The VMware users thinking about an exit mostly relied on the virtualization pioneer for the vSphere and vCenter products that together let them virtualize and manage a modest fleet of servers. Broadcom doesn’t sell those products anymore, other than as components in VMware Cloud Foundation (VCF), a bundle of compute, storage, and networking virtualization tools that together assemble a private cloud. Broadcom insists it sells VCF for less than pre-acquisition VMware did, but the bundle is nearly always considerably more expensive than a VMware user’s last bill – and for many that means paying for VCF even when they don’t plan to use all of its components. Many VMware users are therefore looking to reduce their VMware footprint so that if they acquire VCF, they can shift VMs that don’t need it to other platforms. Before acquisition, VMware had about 350,000 customers, and more than half of the server virtualization market. Broadcom has all-but-said it is only interested in 10,000 to 30,000 of those customers who need VCF and will go all-in on it as their future infrastructure and DevOps platform. In case any VMware users haven’t got the message, Broadcom’s position will become abundantly clear on three imminent dates. The first is November 22, 2026 – the third anniversary of Broadcom’s acquisition of VMware. Because Broadcom has a reputation for making big and hard-to-digest changes after buying software companies, smart VMware customers rushed to acquire multi-year subscriptions before the acquisition closed. Many of those deals will expire soon. The second date is March 31, 2027, on which VMware’s contracts with many members of its Cloud Service Provider (VCSP) program expire, leaving them unable to provide cloudy VMs powered by VCF. Customers who rely on VMware-powered clouds therefore need to find a new home, almost always after buying a VCF license direct from Broadcom. Plenty of former partners are trying to bring their clients with them to another platform. The last date is October 11, 2027, the last day of support for version 8 of VMware Cloud Foundation. Again, this is a moment that will force VMware users to make a decision about their virtual estates – do they upgrade to VCF 9, or look elsewhere? Anger and resignation, but not much innovation That many users are either considering a move or trying to avoid a new VMware purchase is not in dispute. Third party support outfit Rimini Street tells me its VMware support offering is currently its fastest-growing service, albeit off a low base. Cisco created its own hypervisor to give its customers an alternative. Adam Centorrino, CEO of Australian services outfit Centorrino, moved from VMware to SUSE before the March 2027 deadline that unilaterally ends his VMware partnership, and is trying to bring his clients with him. He told The Register he is not angry with VMware and Broadcom, because he understands the decision to cut him from the partner program is a dispassionate business decision. But he is baffled by Broadcom’s strategy because his clientele includes substantial government agencies that other vendors would consider a prize. And then there are the high profile departures like Tesco and Allstate who are decidedly angry with Broadcom – so much so that they’ll fight it out in court. Whatever the motivation for quitting VMware, users know they won’t find a better virtualization platform. VMware’s rivals admit this. I’ve spoken to plenty of them in recent months– Red Hat, Acronis, Sangfor, Nutanix, SUSE, and more – and all admit their products can’t completely match VMware’s, and that their teams don’t include people who can match Virtzilla’s corps of virtualization wizards. At the lower end of the market, VMware’s rivals aspire to assure buyers that their platforms are good enough for essential server virtualization, and their businesses are solid enough to stick around for the long haul. I’ve met tiny vendors who have put a pretty front end on Linux KVM, quickly found enough VMware refugees to sustain a 10 or 20 person server virtualization business, but don’t have huge ambitions. The likes of Acronis and Parallels are trying to win over former VMware partners and provide them with a way to offer cloudy VMs to rent for VMware quitters. Sangfor is almost alone in having a memory tiering offering to rival VMware’s and is keen to point that out, but less enthusiastic about discussing its Chinese origins and any objections that some buyers might raise. At the higher end, vendors promote their Kubernetes distributions, because they see virtualization as a mature technology that won’t benefit from innovation other than making sure it can handle the latest hot workload, which is currently AI. Big players like SUSE, Nutanix, and Red Hat therefore position themselves as ideal for future workloads, and thoroughly competent at hosting existing virtualized applications. That argument is going quite well. Nutanix is winning hundreds of former VMware customers each quarter. Red Hat has won over $680 million in virtualization orders from a standing start. HPE has also entered the market with its VM Essentials product, which as the name implies is closer to vSphere than a private cloud. The company reports “high double-digit new logos growth” for the product. Proxmox is the challenger brand. Its platform handles basic server virtualization comfortably, the project is pushing into bigger datacenters thanks to Kubernetes integration, and admins get genuinely enthusiastic after using its wares. All of the abovementioned vendors are fighting for, and will pick up, hundreds or thousands of mostly small VMware customers. Nutanix will also go toe-to-toe with VMware for big buyers, and peel some away. So will Red Hat, which I’m told is the only rival VMware truly fears because it is perceived as the most mature platform for Kubernetes and now also a competent platform to host VMs. VMware will emerge with most of the customers it wants, and perhaps as the single largest virtualization vendor by customer count. But more users will rely on rival tech – probably KVM in one form or another – than will rely on ESXi. VMware will therefore emerge working with most of the most lucrative users – fulfilling Broadcom’s ambition for the brand. But in many of those users, VMware will be just one provider of infrastructure software, rather than owning an account outright. And to keep the parts of a customer’s business it retains, VMware will need to do more with modern and cloud-native apps, not just VMs. The Broadcom business unit is well-positioned to succeed, because Nvidia’s core software products are containerised and agentic AI workloads will benefit from running inside a lightweight VM. I suspect that VMware will therefore not announce a significant strategy change at its conference this week. Further enhancements to make VCF a stronger container and AI platform are likely, and the Broadcom business unit will pitch its memory tiering prowess as the antidote to high hardware prices – and perhaps sweeten the deal by making it easier to run its wares on either older hardware or hyperscale clouds’ Arm-powered servers. VMware will also let the three dates mentioned above pass without mention. Even though it knows its strategy will give rivals a chance to win some smaller customers, and pieces of business at others, it also knows none will ever offer them a truly better way to run, manage, or protect their VMs. ®
Who, me? Techie with three months’ experience was sent in as the Cisco expert and proceeded to blow everything up
WHO, ME? “Where to begin?” is a marvelous question. To get you going at the start of the working week, The Register thinks the answer is a new instalment of “Who, Me?” the column that shares your admissions of error. This week, meet a reader we’ll Regomize as “Martin” who told us about his very first job in tech. “I had just started working as a network engineer for a very small IT infrastructure company. Since I was the only person who worked with Cisco gear, that made me ‘The Cisco expert’,” he told The Register. That dubious status was enough for the company to send Martin to a customer who needed a new switch for a network that ran Nortel kit – not the Cisco boxes he kind-of knew. Martin told us he arrived to a warm welcome from the customer’s IT team, a decent coffee, and some friendly chat about adding VLANs. With those pleasantries accomplished, he got to work. “I completed rack and stack, basic default configuration, and the VLANs discussed over the coffee,” he wrote. Then he hooked everything up, tested the results, decided all was well, and prepared to leave. While he packed up, the phone rang. “I felt a disturbance in the force,” Martin wrote. “It was the customer’s IT team, asking me if I had done anything wrong, because over 4,000 AS/400 seasons had dropped.” “There was a clear cause and effect relation between the time I connected the switch and the sessions dropping,” Martin admitted. “And the only way to restore those sessions was for the IT team to kill them, manually, one by one.” Martin watched his client’s team as, over the next hour, they fixed the mess he made. “The post-mortem analysis revealed that the cause of the problem was the new switch – actually its spanning-tree settings. AS/400 at the time had its connections from the hosts to the mainframe through SNA over TCP/IP emulation, which, if you lost a single packet … you were screwed.” Martin told The Register that he felt deeply embarrassed by his error. “Those IT guys had been so nice to me and I had given them a really bad time,” he wrote. “But now, with the proper perspective after so many years, I see it was my managers who were to blame for calling me ‘The Expert’ and for letting such a junior guy work unattended at such a big customer.” “Someone in the chain of command must have noticed and I did not lose my job,” he wrote. “But I learned some valuable lessons that day!” Have you assumed you knew everything there was to know about the tech you worked with, then found you didn’t? If so, click here to send us your story! ®
Debian votes to let contributors code with AI
The Debian community has voted to allow members to use generative AI when creating their contributions, with the caveat that developers remain responsible for code quality. The Linux distro’s community recently decided to develop a policy on use of AI-assisted coding tools, and asked participants to vote on one of eight proposals that included an outright ban, cautious use, or just avoiding LLMs because of their impact on Earth’s environment. The rules of the vote saw community members asked to rank each of the eight proposals. Just under 600 people voted, but Debian’s election team rejected many for unspecified reasons, leaving almost 450 valid votes to count. When the tallying was done, proposal E – “Responsible Use of Generative AI” – won the day. The proposal means “Debian neither endorses nor prohibits the use of generative AI tools in the development, maintenance, or documentation of software, packaging, documentation, and other media published within the Debian Project.” The proposal advocates that approach because “such tools can substantially improve the productivity of contributors when used responsibly, allowing volunteers to spend more of their limited time on work that requires technical expertise, judgment, review, and collaboration.” The proposal also spells out that the Debian community doesn’t believe “AI made a mistake” is an excuse for sloppy contributions. “The Debian Project nevertheless expects that all contributions submitted to Debian, regardless of how and with which tools they were produced, satisfy the same standards of quality, correctness, maintainability, and legal compliance,” the proposal states. “The use of a generative AI tool does not diminish the contributor’s responsibility for the work they submit. Contributors are expected to understand, review, test, and, where appropriate, modify AI-assisted output before incorporating it into Debian.” Woe betide the dev who doesn’t check their AI-generated code, as the proposal also states, “Blindly accepting or uploading AI-generated material without appropriate human review is inconsistent with Debian’s established development practices.” Another element of the proposal tries to make acknowledging the use of AI a norm. “We encourage our contributors to disclose whether a contribution was made with AI assistance, but do not require them to do so,” the text states. As our FOSS aficionado Liam Proven wrote in his report on the vote, the Gentoo Linux team has banned use of AI, while NetBSD and OpenBSD don’t want any clanker-written code contributions. Linus Torvalds, arguably the most influential figure in the FOSS community, welcomes AI-generated contributions. In July he declared “Linux is not one of those anti-AI projects” – and recently proved it by using AI to squash a tricky bug. Torvalds has also sometimes complained about AI, such as his May observation that AI-generated bug reports sometimes made the Linux security mailing list “unmanageable.” ®
Inside Meta’s push to put robots to work in data centers
Meta is testing robots that can plug in cables, reset servers, and handle other tasks inside its data centers, according to several current and former workers familiar with the projects. The ongoing effort, which has not been previously reported, may eventually allow Meta to operate its rapidly expanding data center footprint with fewer humans, keeping labor costs in check as its spending on AI infrastructure soars.
Meta is using robots and related hardware from several different vendors, including Watney Robotics, Kinova, and ABB, according to the same workers, who asked to remain anonymous because they weren’t authorized to speak to the media. Kinova and ABB declined to comment. Watney didn’t respond to requests for comment.
In one experiment, Meta is evaluating whether a Kinova Gen3 robotic arm could be used for power cycling or cutting off electricity to servers. The company is also testing a different robot to swap networking cables. One Meta data center worker estimates that if it’s successful, the bot could replace up to 80 percent of some people’s workloads. “We thought those of us performing the physical tasks were safe for a while, but not anymore,” says the worker. “It’s coming for us all, unfortunately.”
Turns out Brits would quite like their private messages to stay private
Brits have delivered a fairly unambiguous verdict on giving the government access to their encrypted messages: no, thanks. New polling commissioned by the Center for Democracy & Technology (CDT) found that 93 percent of British adults believe they have a right to private conversations online, while 89 percent think nobody should be able to access their personal messages without a court order. Perhaps more awkwardly for Westminster, two-thirds said they would not trust either the current government or any future one with the power to access encrypted messages. That distrust crosses political lines. Among people who voted in the 2024 general election, 58 percent of Labour voters said they wouldn’t trust any government with the power, alongside 59 percent of Conservatives, 56 percent of Liberal Democrats, 69 percent of Greens and 75 percent of Reform voters. Public First did the asking, polling 2,000 British adults for CDT in April and weighting the results to reflect the wider population. The margin of error is 2.2 percentage points. The findings land as the UK government’s appetite for slurping encrypted data continues to collide with the tech industry’s insistence that encryption works best when nobody has a spare key lying around. That fight became particularly public when Apple withdrew Advanced Data Protection from UK users after receiving a secret Technical Capability Notice (TCN) under the Investigatory Powers Act. Apple challenged the order, and while the US government later said Britain had withdrawn its demand for access to Americans’ encrypted data, reports have since suggested another TCN was issued focusing on British users. Despite the international row, 55 percent of those polled hadn’t heard about the Apple notice at all. Once presented with the idea, enthusiasm remained thin. Just 12 percent backed the government being able to secretly order companies to provide access to users’ information while preventing those companies from revealing the order. A third said the government shouldn’t have that power at all, while another 41 percent wanted greater transparency or parliamentary oversight. Nor were respondents particularly sold on sacrificing security for law enforcement. 53 percent said the security risks of accessing encrypted messages outweighed the benefits, compared with 28 percent who thought the benefits came out on top. The reasons will sound familiar to anyone who has followed the encryption debate for more than five minutes. 84 percent worried that mechanisms allowing access to encrypted messages could introduce vulnerabilities for hackers and criminals, while 82 percent were concerned the powers could be abused. Knowing someone might be watching could also change how people behave. 65 percent said they’d become more cautious about what they liked, shared or commented on, while 41 percent said they’d self-censor criticism of public institutions or government officials. CDT is not a disinterested observer: the digital rights group campaigns for strong encryption and commissioned the research as part of that work. The polling itself, however, was carried out independently. Commenting on the research, Jim Killock, executive director of Open Rights Group, said: “The British public instinctively know that being able to communicate privately is crucial to our individuality and to the survival of a free and open society. “The government persists with the myth that it can weaken encryption to target the bad guys only. Attacks on the security of our phones, security tools and messaging apps harm us all and make our democracy weaker.” None of this is likely to end Westminster’s long-running pursuit of encrypted communications. But if ministers were hoping the public was enthusiastically behind them, the numbers suggest otherwise. ®
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group of hackers that, over nine months, has carried out a relentless series of supply-chain attacks that infected more than 1,000 organizations worldwide.
In a statement, the Australian Federal Police said the two men were arrested and charged with 14 offenses. The statement said the men were members of TeamPCP, which by the authorities’ count, compromised more than 1,000 organizations worldwide. The statement didn’t identify the men, except to say they lived in the Western Australian towns of Cottesloe and Mandurah. KrebsOnSecurity, citing a lengthy investigation, provided what it reports to be both defendants’ names, along with an extensive background of their lives and the mistakes that led to their downfall.
The hacks that keep on hacking
TeamPCP has vexed law enforcement officials and security personnel around the world since it emerged in December. The group is best known for a sustained series of supply-chain attacks that laced open source software with malware that self-propagated from one package to another. The viral infections worked by targeting organizations’ CI/CD pipelines, which are used to rapidly develop, update, and deploy software.
Claude, Codex, and Hermes installed unowned code inside corporate networks
Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.
The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site’s content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site’s content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here.
How the researchers found it
Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication.
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
The OpenAI agents involved in last month’s incursion into Hugging Face were trained so heavily on winning a competition that they pursued a relentless campaign to cheat, a new report documented. In the process, and without authorization, they created an improvised message board to hatch a plan that ultimately landed them squarely inside the latter company’s network.
Over the course of May and June, OpenAI gave the agents what the company described as “impossible tasks” to complete on the benchmarking framework ExploitGym. The internal test was designed to test how the agents would respond. To get a full understanding of the agent capabilities, company engineers disabled safety guardrails that normally are in place to prevent the sort of hacks that eventually hit Hugging Face and one other undisclosed organization. The stymied agents’ training made them so focused on winning that they performed tasks they were never explicitly instructed to follow.
Cheaters gonna cheat
The first step was creating a message board that allowed the agents to pass notes to each other. OpenAI hadn’t provided any such platform, so the agents repurposed a platform called Artifactory, which OpenAI was using in internal testing of several unreleased hacking agents. OpenAI was using Artifactory as one of the measures to prevent the agents from egressing its isolated sandboxes and accessing the Internet, while at the same time simulating a real-world hacking environment.
AI agents meant to replace Meta workers made “large-scale, disruptive actions”
Earlier this year, Meta created a “plan” to reduce some of its teams by as much as 60 percent to make the company “AI native,” Reuters reported today, citing two people familiar with Meta’s internal affairs.
Reuters’ report highlights the challenges organizations face when analyzing the best uses for AI and determining when the technology is a better fit for certain tasks than employees.
Meta confirmed to Reuters that the plan, reportedly codenamed Project OT (short for organization transformation), explored scenarios in which Meta reduced some team headcounts by 60 percent and that the plan called for two rounds of layoffs. Meta wouldn’t confirm which teams Project OT affected.