Modalità di lettura

Commentaires sur Framacount : partagez l’addition sans partager vos données par JBrickelt963

Un super outil encore une fois ^^ merci Framasoft 😁 j’ai peut-être loupé l’info dans l’article mais est-ce qu’il y a la possibilité de les supprimer après utilisation ? Je vois qu’il y a l’option supprimer un participant ou archiver. Combien de temps est conservé le groupe archivé ?

  •  

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.

Pedro Falé is a threat researcher with the security firm Bitsight. Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as H96.

An H96 TV streaming device currently advertised for sale on Amazon.

Falé said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funneled to the domain, he discovered nearly all of the TV boxes transmitting data claimed to be mobile phone models from a variety of manufacturers, including Samsung, Vivo, Huawei, and Xiaomi.

“We noticed something was wildly wrong,” Falé said. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.'”

Image: Bitsight.

The researcher found all of the devices reported having the same two apps installed, and that those apps were made by a company called Zhejiang Fengwo IoT Technology Ltd, an entity founded in 2019 in mainland China which operates an ad-publishing portfolio under the name Fengwo Group. Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

“Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group,” Falé wrote in a report released today about their findings.

Falé said an analysis of the apps shows they help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group.

Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music and food blogs. But they also found none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices.

AI DIGITAL HUMANS

The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of human-AI interaction,” and that it has created more than 120,000 “AI digital humans” available to rent for everything from emotional companionship to 24/7 customer service and creative design.

The homepage for fwgcloud dot com.

Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.

According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.

The Blockly homepage.

“An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type,” reads Bitsight’s report. “Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use.”

Bitsight even found one of the Fengwo Group app developers mentioning exactly these advantages, noting the developer remarked that “only a small number of highly-skilled developers are needed to build the template execution-unit images,” and that “developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs.”

Falé said if a user’s H96 streaming stick is selected for a specific fraud task, it will be pushed the appropriate Blockly module according to the task desired, which can include silently launching a web browser, visiting websites, browsing pages, managing tabs, and clicking on ads.

To ensure the TV boxes masquerading as mobile phones can reliably click on ads displayed via the AI-generated websites, the Fengwo group “fuses three vision and reasoning systems into a single interface,” allowing the bots to correctly identify an ad on the webpage and navigate the site much like a human would, the Bitsight report observed.

Examples of ad landing pages linked to the Fengwo Group. Image: Bitsight.

TV ON? PROXY. TV OFF? AD FRAUD

Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.

Falé said he believes the TV boxes are set up this way because its ad fraud activities are far more resource intensive and could interfere with the device’s stated purpose — streaming video content over the Internet.

Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.

Image: fbi.gov.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed. This software rents the user’s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals.

What’s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves.

SHOW ME THE MONEY

Bitsight said it tracked approximately 38,000 TV boxes globally phoning home to the expired Fengwo Group domain, and based on that number the report estimates this ad fraud network brings in revenues of close to $50,000 a day (not counting substantial revenue from the residential proxy side of the business). However, Falé emphasized that these estimates are highly conservative and based on telemetry from just one of the Fengwo Group’s core (but older) domains.

As for the Fengwo Group’s claim to have 120,000 “digital humans” at their disposal, Bitsight’s report concludes it could be just a clever marketing scheme and/or a way to avoid drawing suspicion to the company’s operations.

“Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size,” Falé wrote in the report. “This could also be the case here.”

If the Fengwo Group truly does have tens of thousands of “AI humans” at its beck and call, it does not appear to have dedicated any of them to fielding inquiries from its own website. KrebsOnSecurity sought comment from the Fengwo Group by emailing the contact address listed on the company’s homepage, but the request bounced back with the reply, “Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now.”

As Bitsight’s analysis shows, when it comes to TV boxes and streaming sticks, it’s best to stick to name brands from reputable manufacturers, and then to be sparing and careful with any apps you choose to install on the device — as many of those can bundle residential proxy software as well. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following these instructions.

Additionally, Synthient maintains a running list of IoT devices that have been known to ship to consumers with residential proxy software and other malicious apps pre-installed. Careful readers will notice Synthient’s list includes other IoT devices apart from streaming sticks and boxes: As the FBI has warned, residential proxy software has also been found in other popular consumer IoT devices from random brands, particularly digital photo frames.

  •  

GNU Binutils 2.47 Released with New RISC-V Features, Linker Improvements, and Reproducible Builds

GNU Binutils 2.47 Released with New RISC-V Features, Linker Improvements, and Reproducible Builds

The GNU Project has officially released GNU Binutils 2.47, the latest version of its essential collection of binary development tools for Linux and other Unix-like systems. The release delivers numerous bug fixes alongside new assembler, linker, and disassembler capabilities, expanded RISC-V support, reproducible source archives, and continued modernization of the GNU toolchain.

Used by developers worldwide, GNU Binutils forms a core part of the software development ecosystem, providing the low-level tools needed to assemble, link, inspect, and manipulate executable programs and object files.

What Is GNU Binutils?

GNU Binutils is a collection of command-line utilities that work closely with compilers such as GCC and Clang. While a compiler translates source code into object files, Binutils provides the tools needed to transform those object files into executable programs and libraries.

The package includes well-known utilities such as:

  • ld (GNU Linker)
  • as (GNU Assembler)
  • objdump
  • objcopy
  • readelf
  • nm
  • strip
  • ar
  • strings

Together, these tools are used daily by Linux distributions, embedded developers, operating system projects, and software engineers building applications in C, C++, Rust, Go, and many other languages.

Expanded Support for RISC-V

One of the biggest improvements in Binutils 2.47 is expanded support for the rapidly growing RISC-V architecture.

The release adds support for several additional standard RISC-V extensions, allowing developers targeting modern RISC-V processors to work with newer instruction sets and hardware capabilities. These additions continue the GNU toolchain's strong commitment to one of the fastest-growing open processor architectures.

As more Linux distributions, development boards, and enterprise hardware adopt RISC-V, keeping development tools current is becoming increasingly important.

New Assembler Options

GNU Assembler (gas) gains several useful enhancements in version 2.47.

Among the most notable is a new command-line option:

  • --reloc-section-sym=[all|internal|none]

This option gives developers finer control over how relocations referencing locally bound symbols are converted to section symbols, improving flexibility for certain assembly and linking workflows.

The release also introduces numerous assembler improvements across multiple CPU architectures.

Better Disassembly for AArch64

Developers working with Arm-based systems also benefit from new functionality.

  •  

GOG Officially Expands Linux Support with Native Galaxy Client in Development

GOG Officially Expands Linux Support with Native Galaxy Client in Development

After years of requests from the Linux gaming community, GOG has officially confirmed that it is developing native Linux support for the GOG Galaxy launcher. The announcement marks one of the biggest shifts in the company's history and signals a stronger commitment to Linux as a first-class gaming platform. While GOG has offered DRM-free Linux game downloads since 2014, its Galaxy launcher has remained exclusive to Windows and macOS—until now.

Although the company has not announced a release date, GOG says Linux has become a major area of investment, with development already underway.

A Long-Requested Feature Finally Becomes Reality

Native GOG Galaxy support has consistently ranked among the most requested features from Linux users. Until now, players who wanted to use Galaxy's library management, cloud saves, achievements, and automatic updates had to rely on compatibility layers or community-developed launchers.

In a statement to GamingOnLinux, GOG joint CEO Krzysztof Papliński said the company has hired a dedicated specialist and is actively exploring the best approach for bringing Galaxy to Linux. He described Linux as "one of the topics we hear the most about from our community," emphasizing that the project is now an active development priority.

Why GOG Galaxy Matters

Unlike the web-based game downloads that Linux users already have access to, GOG Galaxy serves as a full-featured game management application.

The launcher currently offers features including:

  • Automatic game installation and updates
  • Cloud save synchronization
  • Achievement tracking
  • Playtime statistics
  • Game library organization
  • Integrated storefront browsing
  • Friends lists and social features
  • Cross-platform launcher integration

Today, Linux users typically access these capabilities through community projects such as Heroic Games Launcher, Lutris, or Bottles. A native Galaxy client would provide an officially supported alternative with direct integration into GOG's ecosystem.

Linux Is No Longer an Afterthought

GOG's announcement reflects the growing importance of Linux gaming over the past several years.

The rapid adoption of Valve's Steam Deck, continuous improvements to Proton, and increasing hardware compatibility have significantly expanded Linux's role in PC gaming. As Linux's share of Steam users has grown, more developers and publishers have begun treating the platform as a viable target rather than a niche operating system.

For GOG, supporting Linux more fully aligns with its philosophy of giving users greater control over their purchased games.

  •  

Dans #PeerTube, vous pouvez configurer la confidentialité de vos vidéos.Pub…

Dans #PeerTube, vous pouvez configurer la confidentialité de vos vidéos.

Publique, non-listée, privée ou encore protégée par mot de passe... vous pouvez choisir différentes options en fonction de votre usage !

👉 https://docs.joinpeertube.org/use/create-upload-video#video-confidentiality-options-what-do-they-mean

#PeerTubeTipOfTheWeek

  •  

L’Italia invasa dai data center

Immagine in evidenza rielaborata con intelligenza artificiale

Secondo i dati più recenti, i data center – le infrastrutture che ospitano i server necessari, tra le altre cose, ad addestrare e utilizzare i sistemi di intelligenza artificiale – presenti o in progettazione in Italia sono 262: solo un anno fa erano 146. La crescita non riguarda soltanto il numero degli impianti, ma anche il loro fabbisogno energetico. Nel 2024 i data center italiani hanno consumato 5,8 TWh, pari a circa il 2% dei consumi elettrici nazionali. Secondo alcuni scenari riportati dall’Osservatorio Data Center del Politecnico di Milano, entro il 2035 potrebbero arrivare a consumare tra 24,5 e 42 TWh, pari al 7-12% del totale nazionale.

Di fronte a un’espansione così rapida, è necessario chiedersi se lo sviluppo dei data center possa essere governato in modo sostenibile o rischi invece di riprodurre le distorsioni già osservate negli Stati Uniti e in altri paesi: consumo di acqua ed energia, occupazione del suolo, aumento dei costi per i cittadini e benefici occupazionali inferiori alle attese.

È in questo scenario che il Ministero delle Imprese e del Made in Italy ha elaborato la “Strategia per l’attrazione in Italia degli investimenti industriali esteri in data center”. L’obiettivo di questa strategia è mostrare come il territorio italiano, con una rete di infrastrutture (fibra ottica, 5G e cavi sottomarini) distribuita in modo omogeneo in tutta la penisola, “possa garantire uno sviluppo sostenuto e sostenibile dei data center in grado di moltiplicare il fattore attrattivo agli investimenti”. Il documento presenta in tal senso un’analisi di settore e una strategia per ridurre e semplificare tempi e modalità di investimento, per rendere l’Italia un polo di investimenti strategico, definito ‘Hub del Mediterraneo’. 

La diffusione dei data center in Italia

Il mercato dei data center in Italia è effettivamente in fortissima crescita: nel triennio 2023-2025 ci sono stati investimenti pari a 7,1 miliardi di euro e per i prossimi tre anni ci si aspetta di raggiungere i 25 miliardi. Una cifra comunque inferiore rispetto alle previsioni del 2023: secondo i dati riportati sempre dall’Osservatorio del Politecnico, ci si aspettava infatti di raggiungere 10,5 miliardi di euro. L’incongruenza è dovuta principalmente agli errori di previsione di operatori internazionali, che sono entrati nel mercato italiano con eccessivo ottimismo riguardo alle tempistiche burocratiche italiane. Ed è proprio per venire incontro alle esigenze degli investitori internazionali e capitalizzare il più possibile le previsioni di mercato che è stata sviluppata la Strategia del Mimit. 

Attualmente, dalla richiesta di costruzione di un data center fino al diritto di iniziare i lavori è previsto un iter che va dai 18 mesi ai 3 anni, periodo nel quale vengono espletate le valutazioni urbanistiche e ambientali. Un periodo che secondo l’Italian Data Center Association (IDA), citata nella strategia, pone il nostro paese in svantaggio competitivo rispetto ad altre nazioni europee. Per superare questo limite, il Mimit propone l’introduzione di un’Autorizzazione Unica a livello nazionale, che possa semplificare le procedure e unificarle sotto un unico ente amministrativo, così da garantire tempi certi.

L’impatto dei data center sul territorio

La semplificazione, in linea di principio, non sottovaluta l’impatto dei data center nel territorio italiano. Anzi, la strategia identifica quattro potenziali effetti benefici a livello territoriale e locale derivanti dagli investimenti sui data center: riqualificazione di aree industriali dismesse (i cosiddetti siti brownfield), iniezione di risorse economiche nei comuni coinvolti, utilizzo del calore di scarto per teleriscaldamento, aumento dei posti di lavoro nel territorio. Va tuttavia verificato se e in che modo questi benefici possono concretizzarsi, analizzando la situazione nei territori protagonisti della crescita del settore. 

La Lombardia è di gran lunga la regione che riceve più investimenti, candidandosi a essere una delle maggiori regioni europee per numero di data center, attualmente concentrati soprattutto nella città metropolitana di Milano, a Bergamo e, più di recente, nella provincia di Pavia. Questi territori stanno vivendo un aumento vertiginoso di nuove strutture: secondo Data Center Map, sono oltre 110 i data center attivi nella sola Lombardia, a cui se ne aggiungeranno una trentina nei prossimi anni. Il rapido sviluppo di queste strutture porta con sé alcune controversie rispetto ai benefici ambientali, specialmente riguardo alla bonifica e riutilizzo delle aree industriali e al teleriscaldamento tramite il calore di scarto. 

Su questi aspetti, la strategia pone solo delle linee guida da rispettare laddove possibile: per esempio, riconvertire siti brownfield invece di utilizzare aree verdi (greenfield) o prediligere sistemi a circuito chiuso in grado di consumare meno acqua. Tuttavia, in assenza di una legge, queste linee guida non vincolano chi investe nel territorio italiano. Per colmare questo vuoto, e per l’ampio numero di investitori, nel maggio scorso la Lombardia è stata la prima regione italiana a promulgare una legge in questa direzione, che pone disincentivi fino al 200% per chi costruisce su terreni verdi che potrebbero essere destinati all’agricoltura.

“Ma la legge non ha tenuto conto delle richieste”, commenta, parlando con Guerre di Rete, Renato Bertoglio di Legambiente Pavia. “Abbiamo chiesto di governare il processo, di porre vincoli, invece hanno messo disincentivi che il più delle volte non hanno un effetto reale, perché costa meno pagare il sovrapprezzo piuttosto che bonificare un’ex area industriale”. Anche da parte di Legambiente, dunque, c’è la richiesta di una legge nazionale che definisca delle condizioni e le renda vincolanti. In assenza di essa, il sito di costruzione di un data center è soggetto alle contingenze del luogo e degli attori coinvolti: può essere effettivamente scelto un sito brownfield, come nel caso del progetto del data center hyperscale della società DC Adriatic a Bari, oppure occupare 60mila metri quadri di terreno verde, come a Certosa di Pavia.

L’invasione del pavese

Negli ultimi anni, proprio la zona del pavese sta vedendo la costruzione di numerosi data center: oltre a Certosa, a Lacchiarella è previsto un campus con cinque data center da oltre 200mila metri quadri, a Vellezzo Bellini 110mila, a Bornasco 165mila. Non sempre i progetti offrono ai territori in cui sono installati i benefici indicati nella strategia: se a Magenta, per esempio, è stata riqualificata la vecchia area industriale della Novaceta, a Certosa si vuole costruire su un terreno verde che era destinato ad uso agricolo. 

In entrambi i casi, i cittadini denunciano la costruzione a breve distanza dalle abitazioni: “Non si è considerato che, negli ultimi anni, i paesi si sono espansi in contiguità alle aree dismesse”, dice a Guerre di Rete Sergio Manera, fisico e membro del Comitato di tutela del territorio Certosino. “Non si può costruire vicino alle case, così si rischiano di ripetere gli errori del passato, quando si costruiva senza la sensibilità ambientale che abbiamo oggi”. Nella legge della Regione Lombardia è assente qualsiasi riferimento al limite di vicinanza, e ciò, secondo Manera, fa perdere valore agli immobili del territorio, ridimensionando in questo modo anche gli oneri di urbanizzazione che, secondo la strategia, dovrebbero costituire risorse economiche per i comuni dove si costruisce. 

Come sottolinea Chiara Brocchetta, vicepresidente del Comitato Certosino, ci sono altre vie per far girare l’economia locale: “Certosa ha guadagnato tre milioni dagli oneri dovuti alla costruzione, ma il vicino comune di Borgarello ne ha presi molti di più attraverso progetti europei. In tutto il territorio stanno nascendo sempre più data center, bisogna considerare gli effetti cumulativi di questi impianti in un corridoio agricolo che è anche un’area ad alto interesse turistico”.

D’altronde, l’impatto ambientale non riguarda soltanto i comuni in cui vengono costruiti i data center, ma anche in quelli confinanti. Ce lo spiega Alberta Samuele, sindaca di Borgarello, comune che confina con Certosa e con l’area in cui sorgerà il data center: “L’effetto inquinante sarà prevalentemente nel nostro comune, che non godrà di alcun beneficio economico da questa struttura. Negli ultimi anni abbiamo vinto bandi da sei milioni di euro spesi in opere pubbliche: costruzione di un ambulatorio, ristrutturazione della scuola, depavimentazione. Ci può essere crescita economica anche senza snaturare il territorio”. 

Da quanto emerge da queste testimonianze, la scelta di siti brownfield, laddove venisse effettuata, non sarebbe comunque sufficiente per mitigare gli impatti ambientali, che rimarrebbero elevati specialmente perché si costruiscono tanti impianti in un’area ridotta. In Lombardia è presente quasi la metà dei data center nazionali e anche guardando le richieste di allacciamento (dunque l’interesse futuro) per i data center, La Lombardia da sola rappresenta quasi il 50% di potenza richiesta, seguita con molto distacco da Piemonte (15%) e Puglia (10%). 

Nonostante la maggior parte delle richieste non sia concretamente realizzabile, il rapporto mostra bene la loro distribuzione. La sola Milano, secondo dati del Politecnico, concentra il 68% della potenza energetica nominale installata a livello nazionale con 414 MW IT e punta a superare il valore simbolico di 1 GW entro il 2028. D’altra parte, la strategia del Ministero si propone di distribuire queste infrastrutture su tutta la penisola, ma i comitati cittadini e Legambiente sono d’accordo nel chiedere con celerità una legge nazionale che governi il fenomeno.

Teleriscaldamento e rinnovabili

Anche l’energia pulita gode di grande attenzione. Oggi, con il mix energetico che è al 40% circa composto da fonti rinnovabili, le emissioni di CO2 da parte dei data center sono approssimativamente un milione di tonnellate, a quanto riporta il Politecnico di Milano. Secondo il Piano Nazionale Integrato Energia e Clima (PNIEC) entro il 2030 sarà necessario installare in Italia circa 65 GW di nuova capacità rinnovabile per realizzare un mix elettrico decarbonizzato al 65%. Se anche fosse raggiunto questo obiettivo, secondo l’Osservatorio del Politecnico le emissioni raggiungerebbero un intervallo tra 2,9 e 5 milioni di tonnellate. Una crescita sostenuta e dovuta proprio all’aumento dei data center, ma comunque contenuta rispetto alle 5-8 milioni di tonnellate di emissioni previste se il mix energetico rimanesse invariato. 

La strada verso le rinnovabili è un impegno fondamentale e la strategia del Ministero si muove in questa direzione. Tuttavia, l’energia pulita, da sola, non è sufficiente, perché, come ci spiega Manera, “nel momento in cui ci si allaccia alla corrente elettrica, si utilizza il mix nazionale. Quindi non è possibile, come dicono alcuni, realizzare un data center con energia al 100% rinnovabile, a meno di togliere le fonti pulite ad altri, visto che la coperta è corta”.

Per questo motivo, grande importanza è dedicata anche alle tecnologie che permettono di ridurre inquinamento e dispersione di calore. Il teleriscaldamento, capace di riutilizzare il calore di scarto dei data center per riscaldare abitazioni vicine, è per esempio considerato da varie parti la soluzione ottimale. Permette di ridurre i costi dell’energia così come le emissioni di CO2: esemplare è il caso del data center Avalon 3 di Retelit, a Milano, che, secondo IDA, consente di riscaldare le abitazioni di 1.250 famiglie del Municipio 6, con un risparmio energetico equivalente a 1.300 tonnellate di petrolio e una riduzione delle emissioni di CO2 di 3.300 tonnellate. Ad oggi sono però ben pochi i progetti che godono di tale efficienza. “Ma sono necessari: l’alternativa è la dispersione di calore nell’aria”, spiega Manera, che fa notare come esista una direttiva UE che impone alle imprese uno studio di efficienza energetica per questo tipo di impianti.

La crescita occupazionale

La strategia del Mimit cita tra gli impatti benefici sui territori anche la “creazione di posti di lavoro ad alta specializzazione, sia nelle fasi di progettazione e costruzione sia nella gestione operativa delle infrastrutture stesse”. Secondo l’Italian Data Center Association (IDA), nel 2024 si contavano 28mila lavoratori nell’orbita dei data center, ma di questi solo 1200 erano lavoratori diretti nelle strutture. La maggioranza dei nuovi posti di lavoro riguarda la fase di costruzione, oppure si concentra nelle imprese legate al mondo del digitale e dell’intelligenza artificiale, e quindi la creazione di data center è solo in parte causa di queste nuove assunzioni. 

Non è facile trovare dati sulla crescita dell’occupazione nei data center, ma varie fonti riportano che il settore è agli ultimi posti riguardo a numero di lavoratori per metro quadro. Un recente articolo del Wall Street Journal ha riportato il caso di Abeline, una città in Texas in cui per un data center che inizialmente avrebbe dovuto occupare 100mila metri quadrati non sarebbero stati assunti più di 100 lavoratori. In questo modo, creare un data center in un territorio non significa necessariamente aumentare i posti di lavoro in quel dato luogo. 

Nella strategia del Mimit, molta attenzione è dedicata alla semplificazione amministrativa per ridurre i tempi degli investimenti, mentre per le questioni ambientali si rimanda alle direttive europee e alle linee guida del Ministero dell’Ambiente. Anche per questo è necessaria una legge complessiva, che garantisca una visione a lungo termine di sviluppo tecnologico sostenibile.

L'articolo L’Italia invasa dai data center proviene da Guerre di Rete.

  •  

Andy Beshear Set Out to Make Drug Treatment Widely Available in Kentucky. Fraud and Abuse Followed.

A man with short brown hair wearing a pale blue button-down speaks at a microphone with a U.S. flag and Kentucky flag.
Experts disagree with Kentucky Gov. Andy Beshear’s belief that loosening Medicaid guardrails helped alleviate the state’s drug crisis. Ryan Hermens/Lexington Herald-Leader

By the end of 2020, Kentucky’s newly elected Gov. Andy Beshear had one goal above all others: Keep people alive. The state was battling two merciless threats. COVID-19 was killing hundreds of people each month, and deadly drug overdoses were among the highest in the nation. Calling addiction a disease that breeds in isolation, Beshear worried people would stop seeking treatment for fear of contracting COVID-19. 

So Beshear set out to make drug treatment easier to access. Kentucky joined more than 40 other states in lifting some restrictions on Medicaid, which served most of the Kentuckians enrolled in substance abuse programs: Recovery centers were allowed to offer expensive treatment to clients without seeking approval from state Medicaid insurers.  

By 2023, as the pandemic waned, other states restored Medicaid requirements that treatment centers gain prior approval before providing addiction treatment. Kentucky stayed the course. That year, providers offered more than 1,100 spots for people seeking long-term treatment that allows them to live in a facility, a state record and more slots per capita than any other state.

But as the Medicaid bills for all that treatment started piling up, so did the warnings. 

In 2024 letters to Beshear’s administration and in at least three public meetings, experts across the health industry said that as a result of the 2020 changes, drug treatment providers were billing too much for subpar care that was leading to worse outcomes. By December 2025, the Kentucky attorney general’s office said Medicaid fraud in drug treatment had become a primary “area of concern.”

Despite the warnings, the Beshear administration did little to rein in the skyrocketing state spending. 

Almost all those warnings came true.

In a February 2025 meeting about soaring Medicaid costs, Kentucky Medicaid Commissioner Lisa Lee said the previous year’s spending on behavioral health and addiction treatment had reached an unprecedented $2.3 billion. Stuart Owen, who works for a Kentucky Medicaid insurer, told a state advisory committee months earlier that much of that spending was driven by the drug treatment industry, including “unscrupulous providers who are exploiting the heck out of that for money.” 

The payout was especially lucrative for one company, Addiction Recovery Care. ARC was Kentucky’s largest drug treatment provider and the largest recipient of state funds between 2019 and 2025. This spring, the Lexington Herald-Leader, in partnership with ProPublica, reported on how ARC exploited Kentucky’s loosened spending controls and may have falsified billing.

Beshear has been unapologetic about state spending on drug treatment. In an interview in early June with ProPublica and the Lexington Herald-Leader, he pointed to the continued decline in drug overdose deaths as proof that he made the right choice when he did not force treatment centers to show that costly drug recovery services were medically necessary before treating people for addiction.

“If we’d gone back in time too early and changed things too drastically, how many more people would have died that we’ve saved? With four straight years of drug overdose decreases, they can throw blame at me,” Beshear said. “We’ll talk about dollars, but there are people’s kids that are still alive today because they were able to get addiction treatment services and get them quickly.”

While Kentucky’s overdose deaths declined significantly between 2020 and 2025, experts said the drop was not unique. Other states hit hard by the opioid epidemic also saw year-over-year decreases in fatal overdoses, including states that didn’t loosen Medicaid billing rules, like Tennessee and West Virginia. 

Academic studies mostly agree that the drop in the death rate around the country had more to do with declining opioid prescriptions, an increase in the use of the drug naloxone to reverse overdoses, and less fentanyl in the drug supply. Medicaid and behavioral health experts in Kentucky have said in state hearings that some of the services drug treatment companies billed the most for were not directly associated with a decline in overdose deaths.

Nonetheless, Kentucky’s policies allowed ARC and other companies to bill more and more for services like peer support groups rather than those led by a licensed doctor or therapist. At one time ARC treated about one-third of the Kentuckians seeking drug treatment in the state; more than half of the services it billed for were the same lower-level services that Medicaid experts warned were being abused, according to state data. 

The FBI has been investigating ARC for two years, and more recently, the company’s troubles have intensified. This week the Department of Justice announced it had reached a $16 million settlement with ARC over Medicaid fraud allegations. The company directed employees to falsely bill Medicaid for services like peer support, according to the allegations, which stem from a 2023 whistleblower lawsuit filed by three former ARC employees. 

The settlement resolved the allegations, the Department of Justice said, and there has been no determination of liability. In another investigation, the DOJ last month indicted ARC’s leader, Tim Robinson, for wire fraud and money laundering for a separate alleged scheme to defraud multiple lenders. He has pleaded not guilty to those charges.

The company said in April it “has never knowingly or fraudulently billed Medicaid for services, and there is no evidence that the organization encouraged employees to falsify group notes for billing purposes.” 

Two balding men wearing suits walk side by side outdoors. The man on the right wears a blue suit, a blue tie and rings on both ring fingers.
The Department of Justice recently indicted Tim Robinson, right, founder of Addiction Recovery Care, for wire fraud and money laundering. Ryan Hermens/Lexington Herald-Leader

ARC has over the last two years been forced to close most of its facilities, resulting in a 56% decrease in long-term residential treatment beds statewide, according to the most recent data available.

By 2025, Republicans had seen enough and passed a bill requiring treatment centers to seek approval from insurers before providing treatment services. Beshear vetoed the bill, saying it “will put up barriers to and delay healthcare for Kentuckians.” Republicans overrode the veto, citing waste, fraud and abuse. 

A Raft of Warnings

At public meetings and in letters throughout 2023 and 2024, Medicaid insurers and actuaries warned that Beshear’s decision not to reinstate the spending guardrails sooner had allowed billing abuse by drug treatment providers to proliferate. 

Some of those Medicaid insurers sent warning letters to providers, some who were suspected of  overbilling, on how to appropriately bill. At least one also tried to limit excessive billing by setting its own guidelines for services deemed “intensive, high cost and/or have the potential for overutilization,” according to a memo from Passport by Molina Healthcare, one of Kentucky’s Medicaid insurers, referring to peer support services. Peer support is similar to a 12-step program. 

In August 2024, the Kentucky Association of Health Plans, which represents the state’s Medicaid insurers, sent a letter telling the state Cabinet for Health and Family Services that weak oversight had allowed “unnecessary” spending on treatment and that the services treatment centers were billing the most for weren’t leading to better health outcomes for patients.

The letter warned that addiction treatment providers were overbilling for services that weren’t based on evidence or provided by a licensed doctor or therapist. 

Part of the solution, the association said in subsequent public hearings, was to reinstate the spending guardrails, known as prior authorization, that Beshear had removed during the pandemic. The prior authorization process is supposed to prevent providers from billing fraudulently or excessively for medically unnecessary services by forcing providers to get permission from insurance companies before administering care.

Tom Stephens, president of the group representing Kentucky’s five Medicaid insurers and the letter’s author, said in an interview that it was not the first time Medicaid insurers had shared concerns with the Beshear administration; it was “simply one example of concerns that had been raised over time.” 

Asked about this letter, Beshear spokesperson Scottie Ellis wrote that the governor “monitored the concerns expressed publicly and those shared with his administration” and that the state health agency worked with Medicaid insurers to address them. Ellis declined to answer follow-up questions about what specific measures the administration took during that time. 

More warnings followed. The next month, Somerset Mayor Alan Keck also wrote to the Beshear administration asking it to reinstate Medicaid spending controls.

Keck, whose rural southeastern Kentucky county was hit hard by opioids, told the state health secretary  that treatment centers across his region were recruiting patients from out of state and using company addresses to establish residency for them in order to bill Kentucky Medicaid. He also said some companies were fraudulently billing Medicaid by misrepresenting the services they provided.

“Our communities are seeing an influx of sober living facilities that are taking advantage of Kentucky’s Medicaid system and the lax requirements that linger from the Covid-19 pandemic,” Keck wrote to then-health Secretary Eric Friedlander.

Keck, who lost a Republican primary for governor in 2023, said recently that Friedlander never responded to his letter. He believes Beshear’s administration should’ve done more to rein in the drug treatment industry’s “explosive growth.”

Beshear’s spokesperson didn’t address questions about whether the administration responded to Keck. 

In November and December 2024, officials from Anthem and WellCare, two Medicaid insurers, reinforced their concerns in meetings with legislators and Medicaid officials.

Tell Us About Your Experience With Kentucky’s Addiction Recovery Care

We’re taking a closer look at how ARC treated the people who came to the organization seeking help with their sobriety. If you’re a current or former client or employee, we want to hear from you.

The state’s own data from that period supports the insurers’ claim that the state was paying heavily for services that required little or no time from licensed doctors and therapists: Kentucky behavioral health providers were paid more than $147 million for peer support services in 2023 and 2024, Lee, the state Medicaid commissioner, told lawmakers in February 2025. During that time, Medicaid payments for psychoeducation jumped from $40.4 million to more than $168 million. 

Psychoeducation is normally a part of regular appointment when a clinician explains a diagnosis and treatment plan to a patient. Most of the money spent in Kentucky on psychoeducation went to ARC. Medicaid insurers warned Kentucky was one of the only states that allowed this service to be billed for separately, and providers were abusing it.

At the heart of all of this was the suspension of prior authorization, which had served as the only check on the overuse and overbilling for low-quality care. Without it, Kentucky’s treatment landscape became a Medicaid free-for-all, said Shelby Steuart, a professor who studies health policy at the University of Maryland. 

“It just became an opportunity for people to make money,” she said.  

When asked about these warnings and the reasons Beshear didn’t reinstate Medicaid spending guardrails sooner, the governor’s office said his decision “helped save lives.”

Ellis, the spokesperson for Beshear, said in an email that amid the public warnings, the Cabinet for Health and Family Services, the state’s health agency, met with Kentucky’s Medicaid insurers “to discuss concerns” about the spike in spending on drug treatment. 

She said that the administration sent a letter in November 2024 to clarify when and how to bill for certain services Medicaid insurers had flagged, which resulted in a more than $100 million decline in billing from 2025 to 2026. But, as the attorney general’s Office of Medicaid Fraud and Abuse Control told lawmakers in December 2025, billing increased by $40 million for other services that experts warned were being abused.

Ellis said the policies should be measured by lives saved. “In the end, actions taken by Gov. Beshear and his administration have decreased overdose deaths for four straight years,” she said.

“Willfully Ignorant, Derelict in Their Duties”

In 2024, ARC disclosed what it called billing errors that resulted in overpayments from the state, according to emails obtained through Kentucky’s open records laws. 

About that time, Kentucky’s Medicaid insurers began to raise questions about excessive billing and started to sever contracts with the company. ARC turned to the state’s health agency for help, asking the health secretary to delay reinstating spending controls and to enact a system that would force Medicaid insurers to continue working with ARC.

“Time is of the essence,” ARC founder Robinson wrote in a September 2024 email to Friedlander.

Beshear’s administration balked at forcing insurers to work with the company, but ultimately declined to reinstate tighter spending controls. That year ARC was paid a record $103 million by Kentucky Medicaid, mostly for services Medicaid insurers warned were being abused.

In a June interview, Beshear defended that decision and denied that his 2020 order led to a rise in Medicaid fraud or abuse.

Beshear said that by the time Kentucky’s Republican-controlled legislature reinstated spending controls in July 2025, he was in the process of coordinating with the state’s health agency to enact some spending guardrails, but acknowledged that “admittedly, the Cabinet was probably taking too long,” he said.

Republicans have accused Beshear of mismanaging the state’s Medicaid program. During the 2025 legislative session, they revoked the governor’s power to make changes to Kentucky Medicaid without their permission. Beshear vetoed that bill, which included a provision to reinstate tighter spending controls, but the legislature overrode his veto. 

Republican Sen. Chris McDaniel, who championed the bill, said in March 2025 that Beshear’s administration “had to be one of three things: willfully ignorant, derelict in their duties, or complicit. It was just too much money in one space for them not to have known better.”

Beshear in June said he’ll take the hit; at the end of the day, he said, the tide of addiction in Kentucky has receded, and it was worth it. 

“If we continue at this pace, there’s a chance we end an epidemic that started in our lifetime,” Beshear said. “Opening up services through Medicaid in general to more people has been one of, if not the, most important things we’ve done to get people back on track.”

The post Andy Beshear Set Out to Make Drug Treatment Widely Available in Kentucky. Fraud and Abuse Followed. appeared first on ProPublica.

  •  
❌