Ubuntu 26.04 LTS released

Post Syndicated from jzb original https://lwn.net/Articles/1069399/

Ubuntu 26.04 (“Resolute Raccoon”) LTS has been released
on schedule.

This release brings a significant uplift in security, performance,
and usability across desktop, server, and cloud environments. Ubuntu
26.04 LTS introduces TPM-backed full-disk encryption, expanded use of
memory-safe components, improved application permission controls, and
Livepatch support for Arm systems, helping reduce downtime and
strengthen system resilience. […]

The newest Edubuntu, Kubuntu, Lubuntu, Ubuntu Budgie, Ubuntu Cinnamon,
Ubuntu Kylin, Ubuntu Studio, Ubuntu Unity, and Xubuntu are also being
released today. For more details on these, read their individual release
notes under the Official flavors section:

https://documentation.ubuntu.com/release-notes/26.04/#official-flavors

Maintenance updates will be provided for 5 years for Ubuntu Desktop, Ubuntu
Server, Ubuntu Cloud, Ubuntu WSL, and Ubuntu Core. All the remaining flavors
will be supported for 3 years.

See the release
notes
for a list of changes, system requirements, and more.

Ubuntu 26.04 LTS Moving the Industry forward with Linux 7.0 and More

Post Syndicated from Patrick Kennedy original https://www.servethehome.com/ubuntu-26-04-lts-moving-the-industry-forward-with-linux-7-0-and-more/

Ubuntu 26.04 LTS is out moving the industry forward with Linux 7.0 and a number of enhancements for the important Linux distribution

The post Ubuntu 26.04 LTS Moving the Industry forward with Linux 7.0 and More appeared first on ServeTheHome.

Казах ви

Post Syndicated from Светла Енчева original https://www.toest.bg/kazah-vi/

Казах ви

Предупреждение: тази статия ще бъде поне толкова неприятна, колкото е заглавието ѝ. Ако не искате да се дразните, сега е времето да престанете да я четете.

Не съм тук, за да ви кажа „казах ли ви“… Заклевам се – не се канех да го кажа! –

изрича Камала Харис през смях по повод последствията от победата на конкурента ѝ в президентската надпревара Доналд Тръмп. Оправдателната ѝ реакция се дължи на добре известния факт, че никой не обича да му посочват грешките в лицето с натяквания от типа на „Аз казах ли ти, че така ще стане?“. За разлика от Харис обаче, нямам кариерни амбиции и затова мога да си позволя лукса да бъда неприятна. Правя го не за удоволствие, а за да покажа, че системното замитане под килима на определени теми като маловажни има висока цена.

Къде сбърках(ме)?

Преди да премина към нещата, които съм предвидила вярно, е редно да кажа и къде съм сгрешила в прогнозите си. Сбърках там, където и социологическите агенции, а също и почти всички анализатори – не очаквах „Прогресивна България“ да спечели пълно мнозинство от първия опит. Предполагах, че ще се стигне до някаква форма на концентрация на власт, но след още поне едни избори и/или в резултат на реформа на избирателната система, улесняваща акумулирането на повече власт в един политически субект.

Когато сме свикнали с нещо, сме склонни да предпоставяме, че то ще продължава. Например от четвърт век политическата ни система разчита на коалиции, значи все така ще бъде. Ала както казва шотландският философ Дейвид Хюм, ако слънцето изгрява всяка сутрин, от това не следва, че то ще изгрее и утре. Приемането на реалността за даденост пречи да забележим процесите, които клокочат под повърхността и в един момент могат да я променят коренно.

Що се отнася до електоралните изследвания,

които хем не са прогнози, а „моментни снимки“, хем се използват именно за предвиждане на резултатите от изборите, нещо сериозно не е наред с тях. Една от предпоставките за това е, че в общество, в което социалните медии са мощен инструмент за влияние, анкетирането по стандартния начин може да остави важни тенденции скрити. По повод на изборите през ноември 2021 г., когато агенциите не предвидиха победата на „Продължаваме промяната“, социоложката Марина Лякова написа за „Тоест“:

Във време, в което Google и Facebook знаят кой номер обувки носим, електоралните социолози продължават да ни задават „едно въпросче“. Дали не е време да се потърсят и други начини за прогнозиране на вота на гласоподавателите и как може да изглеждат те – това са теми на дълъг разговор в професионалната общност. Дано той да се проведе скоро.

Е, близо пет години по-късно няма признаци такъв разговор да е започнал да се води. Друг е въпросът

колко честно е спечелила „Прогресивна България“.

Кабинетът на Андрей Гюров (и най-вече вътрешният министър Емил Дечев и и.д. главен секретар на МВР Георги Кандев) получи заслужени похвали за ограничаването на купения и контролирания вот. Но кабинетът постигна това, което беше възможно в рамките на едно служебно правителство. Извън обсега му останаха съмненията за други форми на влияние върху вота, както и за финансирането на кампанията на „Прогресивна България“.

Не беше разследвана например масовата и често неавтентична подкрепа за Радев в социалните мрежи – смяна на имената на над 70 групи във Facebook с общо близо 1,3 млн. последователи, някои от тях – в един и същи ден, както и координираната подкрепа за него в TikTok. Също и най-големият бюджет за кампания на последните избори – над половин милион евро за „Прогресивна България“ (което е повече от 85% от даренията за всички партии и коалиции), събрани основно от множество еднотипни дарения от по 500 и 600 лв. За такива суми по закон не се изисква деклариране на произхода на средствата, но анализът на даренията поражда въпроси: например защо хора с еднакви фамилни имена решават да даряват в един и същи ден?

За да се разследват обаче тези странности и за да се стигне до отговор на по-важния въпрос – откъде идват парите (ако допуснем, че не всички са от хора, които доброволно са решили да дарят), има нужда от разследващи органи, прокуратура и разузнавателни служби – все институции, които не са подвластни на служебния кабинет.

Къде отиде енергията от протеста?

В края на 2025 г. в България се проведоха безпрецедентни по масовостта си за последните трийсетина години протести, които бяха организирани от ПП–ДБ. Това окрили представителите и симпатизантите на коалицията, а Надежда Йорданова и Асен Василев дори дадоха заявка, че ще се борят за мнозинство в парламента. Целта беше постигната, обаче не от ПП–ДБ. Безпрецедентните протести доведоха до безпрецедентни резултати.

Когато електоралните изследвания започнаха да показват спад в подкрепата за коалицията след първоначалния ръст, настана едно тюхкане: защо спихна протестната енергия? Ала още преди еуфорията от масовите демонстрации да беше позаглъхнала, си позволих да изразя опасението, че натрупаната мобилизация може да приеме форма, различна от очакваната. Предположих, че е възможно да възникне нов политически субект и че той може да се сформира около тогава-все-още-президента Румен Радев.

Когато грешната прогноза е добра новина
Връщаме се в играта там, където спряхме – с протестите от края на 2025-та и с това, което те всъщност значат и носят за българското общество. Някои прогнози не се сбъднаха – и това е добра новина. Други обаче чакат своя ред. Тяхното сбъдване няма да донесе нищо хубаво. Коментар на Светла Енчева.
Казах ви

Съвсем не бях единствената с подобно предположение – хипотези, че Радев ще влезе в политиката и ще бъде припознат като новия „спасител“, циркулират от години. Но смятам, че бях малцинство с натякването си на една от важните предпоставки това да стане –

акцентирането върху борбата с корупцията, а не върху демократичните ценности.

Заради очевадно крадливия проектобюджет на кабинета на Росен Желязков темата за корупцията най-сетне успя да резонира в българското общество, чийто гняв доведе до свалянето на правителството. И заслугата за това е основно на ПП–ДБ, но друг им дръпна килимчето под краката и дойде на бял кон – както се случи с ДБ и след протестите през 2020 г., когато спечели „Има такъв народ“.

Работата е там, че борбата против корупцията и за правосъдна реформа не е свързана нито с геополитическата ориентация, нито с демократичните ценности. Тя може да се окаже чудесна основа за едно почти непоклатимо авторитарно и пропутинско управление. Едно такова управление може да ни накара да си спомняме за ненавистния ни днес модел „Борисов–Пеевски“ с известна носталгия. Защото сега имаме някаква свобода, независими медии, макар и малко, неправителствени организации, които не са послушни на властта, протести… Все неща, които смятаме за даденост – като изгрева на слънцето (по Хюм).

Защо не се говори за демократични ценности?

Партиите и коалициите в България все по-малко излъчват послания в защита на либералната демокрация от желание да привлекат повече избиратели. И съответно – от страх да не отблъснат по-консервативните от тях. Така правят и политическите субекти, които се идентифицират като демократични и дори либерални. „Продължаваме промяната“ е част от групата на либералите в Европарламента, но в предизборната ѝ програма – само корупция, та корупция. (Знам, че се повтарям, но това е идеята на тази статия.) В това отношение няма и поколенчески различия – GenZ-тата с политически амбиции следват „правилната“ партийна линия.

Изборите, които нямаме
Този текст тръгва от привидно прост въпрос и стига до неудобен извод: в предстоящите избори изборът не е между модели на управление, а между различни версии на едно и също обещание, от което леко ни е втръснало. Какво всъщност ни предлагат партиите? От Светла Енчева.
Казах ви

Европейската ориентация на България в политическото говорене на ПП–ДБ се свежда основно до Шенген, еврозоната, еврофондовете и подкрепата за Украйна. Това я превръща в изпразнена от съдържание черупка, за която няма особен смисъл да се бориш – вече сме в Шенген и в еврозоната, като направим правосъдната реформа, еврофондовете ще потекат. Единственото място за спор остава подкрепата за Украйна и респективно – отношението към Русия.

Принадлежността към ЕС обаче е свързана със споделянето на либералнодемократични ценности.

Несъобразяването с този факт води най-малкото до осъдителни съдебни решения, ако не и до изолация в рамките на Съюза. Тук му е мястото да обърна внимание, че в предизборната програма на ПП е заложена една доста популистка мярка – магистратите да носят лична отговорност за осъдителни решения на Европейския съд по правата на човека (ЕСПЧ) срещу България. Предлага се провинилите се да не бъдат повишавани и да им се намаляват заплатите.

Но политиците от ПП и коалиционните им партньори от ДБ вече две години и половина не предприеха нищо по отношение на решението на ЕСПЧ, според което България нарушава правата на еднополовите двойки, сключили брак в чужбина. На кои магистрати трябва да се намаляват заплатите в този случай – на тези от Конституционния съд ли?

Така де, като говорим за осъдителни решения, трябва да сме последователни.

ПП не казват нищо за решенията на Съда на ЕС, но вече има такива и за еднополовите двойки, и за смяната на юридическия пол на транс хората. А наскоро Съдът на ЕС излезе с решение, с което квалифицира като противоречащи на европейските ценности унгарските закони, каквито вече има и в България, против „ЛГБТ пропагандата“ в училище и за публичния „регистър на педофилите“. Не защото ЕС „защитава педофилите“ или иска ЛГБТИ хората да имат „специални права“, а защото плурализмът, човешкото достойнство, защитата на личния живот и личните данни, както и недопускането на дискриминация са сред основните му принципи.

За публичния „регистър на педофилите“ впрочем депутатите от ПП–ДБ гласуваха единодушно. Не от убеждение, а защото бяха във фокуса на компроматна война след трагедията в Петрохан и се страхуваха да не бъдат наречени „защитници на педофилите“ (което и без това се случваше). Много лесни се оказаха ПП–ДБ: спретнеш им активно мероприятие, наречеш ги „педофилска секта“ – и гласуват всичко, което поискаш. „Прогресивна България“ да си води бележки (ако не разполага вече с цял списък на слабите страни на наричаните от Радев „сглобкаджии“).

На позорния стълб
Темата „педофилия“ е достатъчно токсична, за да накара политиците да изглеждат единодушни. Така без особени колебания парламентът направи част от „регистъра на педофилите“ публична. Но предпазва ли това децата, или просто превръща страха в удобен политически инструмент? От Светла Енчева.
Казах ви

Сами ли се демократизират обществата?

Давам предимно примери с ЛГБТ хората не (само) защото принадлежа към тази група, а защото отношението към нея е показателно за демократичността на една страна, както и за геополитическата ѝ ориентация. И защото ограничаването на правата на тази група често е индикатор, че се задават по-широки ограничения на гражданските свободи.

В България сме свикнали да се казва „обществото още не е узряло“ и „първо да оправим еди-кое си, пък после това“. Само че в една държава винаги има нещо за оправяне, затова „първо да оправим това, пък после другото“ е просто извинение, за да не се захващаме никога с другото. Не може и да се разчита на някаква естествена еволюция в посока към либерална демокрация, която да доведе до лелеяното узряване на обществото. Ако преди две-три десетилетия е изглеждало, че всички страни неизбежно вървят към демократизиране, както навремето социалистическите страни вървяха уж към комунизма, вече е ясно, че нещата не стават по този начин.

В началото на 90-те младите тогава ЛГБТИ хора в България чакаха „обществото“ да узрее, но за близо 37 години, което е около половин човешки живот, няма и помен от равни права. А поради антиевропейската и антидемократичната пропаганда в някои отношения дори става по-зле (например законът против „пропагандата“ в училище, забраната за смяната на юридическия пол на транс хората). С малки изключения, основното от които е, че през 2023 г. сексуалната ориентация влезе като защитен признак в Наказателния кодекс – по предложение на ПП–ДБ, които преди три години бяха „по-узрели“ по тази тема от днес.

Същевременно и по други теми се наблюдава регрес – например жените на практика изчезнаха от предизборните програми. А преди десет-двайсет години равенството между половете беше обичайна тема за политическите партии, ако не и банална. През 1991 г. пък България ратифицира Конвенцията на ООН за правата на детето. Тогавашните бебета днес са на възраст да имат свои деца, но страната ни още не разполага нито със стратегия за детето, нито със съвременно, а не сталинистко детско правосъдие.

Анахронизъм: Жените в предизборните програми през 2026 г.
В предизборните програми на партиите и коалициите жените почти липсват, освен като майки и демографски ресурс. Теми като равенство, насилие и труд остават встрани или се появяват бегло. Прегледът на тези програми показва системно изместване на разговора за правата на жените. От Светла Енчева.
Казах ви

Ала проевропейските ни политици разчитат на илюзорната еволюция.

И се държат, сякаш демократизирането на обществото не е нещо, което зависи от тях. По отношение на „маркерите за прогресивност“, по които журналистът Веселин Дремджиев питаше събеседниците си по време на предизборната кампания, Асен Василев отговори отчасти утвърдително само на един от тях – за евтаназията. Що се отнася до узаконяването на гражданския съюз, той каза, че това не е централна тема, защото

равноправието, което е необходимо, първо минава през премахването на дискриминацията. А ние сме още много далече от тази първа стъпка.

Дискриминацията обаче не се премахва от само себе си – за това са нужни не на последно място конкретни политически действия. А и какво означава „първа стъпка“, след като в България от 2003 г. има Закон за защита от дискриминация, признаците на дискриминация са описани в него през 2004 г. и един от тях е сексуалната ориентация? През 2015 г. чрез допълнителните разпоредби към тях се добавя и смяната на пола. Но това не пречи в наши дни Конституционният съд, Върховният касационен съд и парламентът да си позволяват да дискриминират.

Трансът на Върховния касационен съд
28 съдии от ВКС забраниха възможността за юридическа смяна на пола и на практика предопределиха изхода от десетки дела, чакащи решение. Не че хората нямат право да водят подобни дела, просто е ясно, че няма да завършат в тяхна полза. Какво още ни казва решението на ВКС – от Светла Енчева.
Казах ви

Когато властта насажда дискриминация, обществото трудно ще узрее. То попива това, което му се представя за „традиционни ценности“ и „правна традиция“ и което повечето медии безкритично отразяват. И все повече се отдалечава от базовите принципи, върху които е изграден ЕС.

Ще реши ли всички проблеми правосъдната реформа?

В изборния ден Румен Радев каза, че се надява с ПП–ДБ да гледат „в една и съща посока, що се отнася до Висшия съдебен съвет“, и добави: „Очаквам партии, които направиха заявки за съдебна реформа, да ги спазят.“

Правосъдната реформа е основната цел на ПП–ДБ като най-важното условие за справяне с корупцията. Една правосъдна реформа обаче, в чийто център не стоят основните принципи на либералната демокрация, на която се основава европейското правосъдие, може да произведе чудовище. Въпреки добрите намерения. Особено ако реформата се провежда от политическа сила, която разполага с мнозинство и която е с евроскептичен уклон.

Впрочем дори по време на проевропейското управление на ОДС в края на 90-те, когато правителството на Иван Костов разполагаше с цялата власт, но нямаше изградена демократична култура, правосъдната система произведе чудовищност. В сравнение с Иван Филчев, тогавашния главен прокурор, Иван Гешев и Борислав Сарафов приличат на герои от ситком.

Припомням, че така и не бяха разсеяни съмненията, че Филчев има нещо общо с убийството на свой отявлен критик – прокурора Николай Колев. Всъщност именно във връзка с този случай ЕСПЧ постанови, че България трябва да въведе механизъм за разследване на главния прокурор. А съпругата на убития прокурор твърдеше, че Филчев е убил сливенската адвокатка Надежда Георгиева – нещо, за което също останаха съмнения.

Това не означава да не се прави правосъдна реформа, а да се имат предвид възможните рискове от една или друга промяна.

И да се противостои на популизма. За да не се превърне накрая прекрасната на хартия реформа в инструмент за въвеждане и на диктатура, каквато в Унгария беше изградена в немалка степен. Засега Радев дава заявка да е по-приемлив за ЕС от Орбан. Но ако допуснем, че някой тайничко му е ударил едно рамо за победата – било чрез влиянието върху социалните мрежи, било чрез даренията, било и чрез двете, този някой вероятно очаква нещо в замяна. Това нещо може и да е промяна на геополитическата ориентация на България.

При всички случаи, ако ПП–ДБ участва в реформирането на правосъдието, както вероятно ще стане, всички негативи ще се пишат на тях, а всички позитиви – на Радев. Защото ПП–ДБ това умеят най-добре – да се набутват между шамарите в опит да се преборят за бленуваните реформи и после да обират негативите. Ако при осъществяването на реформата настояват за съблюдаване на демократичните ценности и ги изпълват с конкретно съдържание, а не ги развяват като кухи фрази, от поредната им жертва ще е имало някакъв смисъл.

Point-to-Point at 100Gbps: What AI-Grade Infrastructure Actually Requires

Post Syndicated from Brent Nowak original https://www.backblaze.com/blog/point-to-point-at-100gbps-what-ai-grade-infrastructure-actually-requires/

A decorative image that shows several cubes on a background.

Bandwidth purchased for data center connectivity surged by nearly 330% between 2020 and 2024, driven primarily by AI workloads. And in 2024, just 10 buyers accounted for nearly 62% of all purchases, according to Zayo’s Bandwidth Report. That concentration is a structural feature of how AI moves data.

Every training run that pulls data from Backblaze storage to a neocloud passes through our network, and our telemetry captures what those flows look like in real time. Our Q4 2025 Network Stats report covers a full quarter of that data. It shows AI workloads producing a distinct network signature: sustained, high-volume transfers between a small number of endpoints, with infrastructure requirements specific enough to be worth examining in detail.

This piece walks through what that signature looks like and what it means for the infrastructure decisions teams are making right now.

The AI model lifecycle and how it moves data

AI model development is a cycle. Large datasets are ingested and consolidated, exported to compute for training, pulled back for evaluation, then pushed out again as models are refined, retrained, and updated with new data. Each stage requires moving substantial volumes of data between storage and compute, repeatedly, over the life of a model.

That structure produces a specific kind of network traffic. AI training moves petabyte-scale data between storage and compute nodes in sustained, long-lived flows—what network engineers call elephant flows—with training jobs running for hours or days under continuous network load. Add frequent checkpointing, model updates, and periodic data refreshes, and the result is traffic that is high in volume and persistent across the entire training run.

This shows up clearly in the Q4 2025 Network Stats data. Neocloud traffic spiked sharply from July through November, peaking in October, then settled into a higher baseline heading into the new year. One interpretation of that shape is the AI lifecycle playing out across a concentration of large training cycles: ingestion, training egress, then a new steady state as stored models get served and periodically retrained. As we accumulate more quarters of data across a broader customer mix, we’ll be better positioned to distinguish that pattern from seasonal budget cycles or customer-specific factors.

Also visible in the Q4 data is where this traffic is going. Cloud-to-cloud traffic grew from 36.2% to 49.6% quarter-over-quarter, with hyperscaler destinations rising from 3.5% to 18%. As the report notes, it’s too early to call these statistically significant trends; the dataset reflects Backblaze’s specific customer mix and covers a single quarter. The direction is consistent with how AI teams operate in practice: moving workloads across neoclouds and hyperscalers depending on price, availability, and job requirements. The storage layer is what persists across those compute environments, which has direct implications for how it needs to be designed.

What elephant flows require from a network

Traditional cloud infrastructure is designed around a specific traffic profile: many clients, many sessions, many discrete transactions. Routing, load balancing, and edge capacity are all optimized for that pattern, distributing load broadly and handling high volumes of short-lived connections efficiently.

Elephant flows don’t fit that profile. AI training establishes persistent, high-volume connections between client and storage that sustain continuous data movement for hours or days at a time. These connections are stickier than typical cloud traffic, particularly on peered networks, and the strain they produce is concentrated rather than distributed—showing up primarily at the edge, where routers handle sustained throughput at scale. Most traditional cloud infrastructure wasn’t provisioned for that kind of sustained pressure at the edge, because most workloads don’t produce it. Internal to the network, depending on a myriad of things—object size, concurrent threads, hardware, internal routing logic—your network path being sticky doesn’t reduce the number of I/O operations for servers, and often that becomes one of the biggest bottlenecks. 

The stakes make this consequential. Training the most advanced models now costs hundreds of millions of dollars, according to Epoch AI—though we also know this is a new technology, and therefore likely the compute will get more efficient over time. That said, the storage is still storage: Data has to live somewhere.  

Infrastructure that can’t sustain throughput under continuous load doesn’t just slow training down; it adds cost to every run. The practical answer is building throughput capacity at the connection points between storage infrastructure and the internet or peer network, sized for sustained flows rather than peak bursts.

That’s what AI-grade storage infrastructure is designed around: sustained throughput to a small number of destinations, at 100Gbps to 1Tbps per transfer for the largest AI workflows. Achieving that in practice means rethinking how a network is designed, routed, and scaled. We’ve written separately about what that looked like for Backblaze’s own infrastructure. Latency matters here for a specific reason: on long-distance transfers, higher latency directly limits achievable sustained throughput, which is one reason why geographic proximity to compute infrastructure affects real-world performance. 

The Q4 Network Stats heatmaps show this pattern from two angles. The magnitude heatmap, measuring bits transferred per unique IP address, shows high-magnitude neocloud flows clustering clearly in regions serving AI-heavy compute endpoints. The uniqueness heatmap shows neocloud traffic involving fewer, more persistent endpoints than CDN or ISP traffic, consistent with AI pipelines that rely on stable, long-standing connections between storage and compute.

The geography of AI infrastructure

The heatmaps show where AI traffic concentrates geographically today. Neocloud activity in the Q4 dataset clusters in Chicago, Dallas-Houston, Denver, New York, the Northern Virginia Reston/Ashburn corridor, and Atlanta, with a clear skew toward the East Coast. This reflects where AI compute infrastructure was built first and remains densest. Keeping latency low between storage and compute is a prerequisite for sustaining the high throughput rates AI workflows require, and that constraint has historically made East Coast proximity an advantage.

That concentration is consistent with broader infrastructure dynamics. AI training workloads are driving demand for regions with available power, fiber density, and compute infrastructure, and power constraints in preferred markets are already forcing operators to explore secondary locations and invest in custom power infrastructure. Demand in markets outside traditional data center hubs is growing rapidly as a result: Metro bandwidth in Memphis grew from 0.3 terabits to 13.2 terabits between 2023 and 2024. On the flip side, building out cabling to those traditionally under-utilized locations is expensive, often adding thousands of dollars per month to data center economics. High-capacity interconnects are central to making those secondary locations viable; without them, the compute investment is stranded. 

The scale of what’s being built reflects the trajectory of the workload. AI training infrastructure is projected to grow at a 22% compound annual growth rate (CAGR) through 2030, reaching more than 60GW of capacity, while inference infrastructure is expected to grow faster still at 35% CAGR, reaching more than 90GW, according to McKinsey. Training and inference have different geographic requirements: training tolerates latency and can sit in power-rich remote locations, while inference needs to be close to users, which means the buildout will be distributed across both dense metro markets and secondary locations connected by high-capacity fiber.

Backblaze’s own infrastructure decisions reflect this pattern directly. The East Coast concentration drove the decision to double Backblaze’s US-East footprint. At 100Gbps and above, proximity to where AI compute is actually running is a determining factor in storage performance.

What AI-ready storage infrastructure actually means

Storage has traditionally been sized for capacity and evaluated on cost per terabyte. AI workflows change the calculus. When a training run is pulling petabytes of data from object storage to flash storage at sustained 100Gbps rates, the storage layer is as much a performance determinant as the compute layer. A storage system that can’t sustain those throughput rates creates a bottleneck that no amount of GPU capacity can compensate for.

Throughput capability is one requirement. Portability is the other. The multi-cloud behavior visible in the Q4 data reflects how AI teams actually operate: moving workloads to whichever compute provider offers the best price-performance for a given job. Storage that is tightly coupled to one cloud provider is structurally incompatible with that workflow. Data that can’t move freely across cloud environments becomes a constraint on the model development process.

This is the infrastructure problem Backblaze B2 Overdrive is designed to address. By building a direct, high-performance path between Backblaze’s storage layer and the neoclouds where AI processing takes place, it provides the sustained throughput that training workflows require alongside the portability to move data as compute requirements change. The connections between Backblaze and neocloud endpoints visible in the Q4 heatmaps represent that architecture in practice.

The point extends beyond any single product. As AI workloads become a larger share of overall data center activity, the criteria for evaluating storage infrastructure are shifting. Capacity and cost per terabyte remain relevant, but sustained throughput capability, interoperability with compute providers, and network proximity to AI infrastructure are becoming equally important factors. Teams that treat storage as a passive component in AI pipeline design are likely to find it becomes the active constraint.

Early signal, long trend

The Q4 2025 Network Stats data is one quarter of observations from one storage provider’s network. The patterns it shows—high-magnitude flows to a small number of endpoints, East Coast geographic concentration, rising cloud-to-cloud traffic, a higher baseline heading into the new year—are consistent with what the broader industry understands about how AI moves data. What’s new is that they’re visible in real network telemetry rather than modeled projections.

We’ll be watching how neocloud traffic concentration evolves regionally, how the training-to-inference ratio shifts as inference infrastructure scales, and whether the cloud-to-cloud growth visible this quarter continues.

The full dataset, methodology, and visualizations are in the Q4 2025 Network Stats report. For background on how we classify and measure network traffic, the Q3 2025 report covers the dataset in detail, and you can follow the whole series here.

The post Point-to-Point at 100Gbps: What AI-Grade Infrastructure Actually Requires appeared first on Backblaze Blog | Cloud Storage & Cloud Backup

Избори и избирателни системи. Между черните дупки и реалността

Post Syndicated from original https://www.toest.bg/izbori-i-izbiratelni-sistemi-mezhdu-chernite-dupki-i-realnostta/

Избори и избирателни системи. Между черните дупки и реалността

Едно от най-големите чудеса на Космоса са огромните черни дупки, като TON 618 и Phoenix A. По сегашните математически модели, с които борави астрофизиката, те не би трябвало да съществуват. След като ги наблюдаваме с телескопи обаче, няма как да заключим като шопа, който, виждайки жираф, възкликнал: „Е те такова животно нема!“ Принудени сме да се съобразим с обективните данни и да преосмислим разбирането си за Вселената.

Подобно нещо може да се случи и на някой, който се занимава със социални науки. Наскоро писах, че България е обречена да бъде управлявана от коалиции, тъй като партийната ни система е пропорционална и това предполага повече политически играчи с парламентарно представителство. Това от своя страна раздробява вота и прави победата на една партия с абсолютно мнозинство трудно въобразима.

Партийните системи по света и де е България в тях
Отново предстоят избори. Асен Василев призовава гласоподавателите на ПП–ДБ да изберат коалицията с пълно мнозинство. Александър Драганов обаче се аргументира защо според него тази цел не е постижима.
Избори и избирателни системи. Между черните дупки и реалността

Подобно на черната дупка Феникс А, която би обхванала цялата Слънчева система с размерите си, коалицията „Прогресивна България“ (около доскорошния президент Румен Радев) разби този мой теоретичен модел. Тук роля изигра бариерата от 4% за парламентарно представителство – тя попречи на редица малки, но не съвсем незначителни политически сили, като МЕЧ, БСП и „Величие“, да влязат в Народното събрание и позволи на ПБ да доминира.

Изборните резултати до голяма степен обезсмислят дебатите дали има нужда от фундаментална промяна на избирателната система в страната – било с бонус към резултата на победителя както в Гърция, било чрез преминаване към мажоритарен модел, каквито призиви наскоро отново отправи неговият дългогодишен радетел Валери Найденов. Може би точно защото не става дума за наболял актуален проблем, можем спокойно да разгледаме двете системи, да анализираме предимствата и недостатъците им, както и да проверим дали има междинен вариант и струва ли си да се спираме на него.

Мажоритарната илюзия за „личностите“

Когато мажоритарната система се представя на българския зрител, най-често се набляга на това, че в нея „изпъкват личностите“. Хората си представят, че мажоритарният вот предполага ярки лица, които с авторитет влизат в парламента, докато партийните листи фаворизират „послушковците“. Това е доста опростено схващане, което игнорира реалностите в държавите с такива системи, където също се държи на строгата партийна дисциплина. Такива са например САЩ, Канада и Великобритания.

Най-лесният начин човек да направи разликата между пропорционалната и мажоритарната система е да разбере логиката на състезанието при двете. При пропорционалната, противно на клишето, също се залага на личности в кандидатските листи. Такъв пример е волейболистът Владимир Николов, който в Пловдив беше кандидат на ПБ. Това е ярка и популярна публична фигура със силен авторитет. Точно това, за което ни препоръчват мажоритарната система, но се оказва, че няма нужда от нея – поне не и в случая.

Коремно възлизане през април
Кампанията тръгва с разместване на силите, нови играчи и познати лица в нови роли. Данните се люлеят, коалициите са отворени, а протестният вот търси поредния си носител. Въпросът вече е не кой води, а с кого и докъде може да стигне. Коментар на Емилия Милчева.
Избори и избирателни системи. Между черните дупки и реалността

В пропорционалната система обаче има едно голямо национално състезание. Политическите сили, преминали минимума от поне 4% от общите гласове. влизат в Народното събрание. После местата в парламента се разпределят спрямо изборните резултати. Оттам идва и определението „пропорционална“. Има значение кой в коя част на страната е силен, но само ако формацията му премине изискуемия минимум на национално ниво.

В мажоритарната система всичко е наопаки 

Може да си сравнително популярен в страната, но това не ти гарантира представителство, тъй като състезанието не е едно, а са много. Държавата се разделя на окръзи – в Канада например се наричат неофициално и метафорично райдинги (ridings), което означава „езда“, но също и пътищата, които ездачите изминават. Във всеки от окръзите партиите излъчват свой кандидат. Мястото се печели от победителя, а изборите – от политическата сила, чиито представители са успели да надделеят в най-много окръзи. Тук се получава парадокс: партия със силно концентрирана подкрепа в една част от страната може да загуби от друга партия, която има по-малка като цяло, но по-равномерно разпределена подкрепа.

Азбучен пример за мажоритарност е странната, архаична система на президентските избори в САЩ. Противно на масовото разбиране, американският президент не се избира пряко от гражданите. За него гласуват т.нар. електори, излъчени от съответната партия в Избирателната колегия – нещо като специално Народно събрание, което се събира само за да избере президента и няма пряка връзка с Конгреса. Всеки щат разполага с различен брой електори, определен на базата на населението му, но те се разпределят не пропорционално, а мажоритарно (на принципа „победителят взема всичко“). Тоест партията, спечелила щата, получава всичките му електори, дори да води с десети от процента.

Преди изборите, или как се става кандидат-президент в САЩ
Предстоят президентски избори в САЩ, които вълнуват целия свят. В поредица от статии Йоанна Елми ще разказва за най-важното и най-интересното около вота. Започваме с обяснения как изобщо се става кандидат-президент в САЩ.
Избори и избирателни системи. Между черните дупки и реалността

Тази система е в услуга на републиканците. През 2000 г. Ал Гор спечели повече гласове от Джордж Буш-младши, но загуби в повече щати. През 2016 г. същото сполетя Хилъри Клинтън, състезаваща се срещу Доналд Тръмп. Последните два пъти, когато либералът Джъстин Трюдо стана министър-председател на Канада, той имаше по-малка национална подкрепа от консерваторите, но по-равномерно разпределена и това му позволи да спечели.

Българският сценарий и цената на стабилността

Нека опитаме да си представим как би изглеждала мажоритарната система в България. Разделяме страната на 240 избирателни окръга. Във всеки от тях се провежда отделно състезание. Партията, която печели окръга, излъчва депутат. В случая с вота от 19 април 2026 г., това още повече би увеличило преднината на ПБ. Вероятно щеше да изтрие ГЕРБ и да остави в парламента само ДПС и може би ПП–ДБ като опозиция заради силното им присъствие на определени места. За много хора, уморени от управлението на Бойко Борисов, тази перспектива звучи страхотно. Ако обаче върнем лентата към април 2021 г., ГЕРБ вероятно щеше да спечели абсолютно мнозинство по брой окръзи заради равномерно разпределената си подкрепа от около 800 000 гласа – въпреки протестите срещу партията на Бойко Борисов.

Ами ако победителят във всеки избирателен окръг се избира на балотаж? Това е популярно възражение въпреки факта, че подобна система в чист вид се среща на много малко места. При балотажи през 2021 г. вероятно в битката за депутатски места щяха да останат главно ГЕРБ и ИТН, плюс няколко места за ДПС в смесените райони. ПП изобщо нямаше да се появи, а ДБ трудно щеше да пробие извън София.

Тук обаче идва следващото възражение:

как така в парламенти като британския има също толкова голямо разнообразие от партии, колкото и в българския, след като избирателната система също е мажоритарна? Вижте примерите за ДПС по-горе. Във Великобритания има голям брой регионални партии. Такива са например шотландските националисти – те издигат кандидати само в родината си и често печелят значително по-малко гласове на национално ниво от либералите например. Но като представителство дълго време бяха трети след лейбъристите и консерваторите, тъй като печелеха почти всички места в Шотландия. Това беше системна слабост на лейбъристите и изглеждаше, че присъствието на регионалните сили заплашва двупартийната система. А подобни партии има още в Уелс и Северна Ирландия.

Лейбъристите се съвзеха, но начинът, по който това стана, показва най-голямата слабост на мажоритарния вот. През 2024 г. тяхната партия, водена от сър Киър Стармър, спечели 33% от гласовете, а с тях – 411 от общо 650 места в британския Парламент. За сравнение, през 2019 г. лейбъристите са получили 32%, но само 242 места. Разликата е един процентен пункт, но резултатът – почти двоен. През същата 2019 година консерваторите имаха 365 места при 43% от гласовете. В тази система общият резултат на практика няма значение – важат само спечелените отделни битки.

За голяма държава мажоритарният вот може би работи, макар британският ѝ вариант в момента да скърца сериозно. „Утехата“, че от дефектите ѝ печели умерен политик като Стармър, ще се изпари, ако на следващи избори от тях се възползва националист като Найджъл Фарадж.

Има ли трети път?

В т.нар. смесена система част от депутатите се избират пропорционално, а друга – мажоритарно. Тя обикновено облагодетелства победителя. У нас за последно изпробвахме такъв модел през 2009 г., когато правителството на тройната коалиция въведе наред с пропорционалния вот и мажоритарни избори за отделните 31 избирателни района. ГЕРБ победи почти навсякъде в мажоритарната надпревара, което увеличи мнозинството на партията на Бойко Борисов, а иницииралите промените социалисти останаха разочаровани. Нещо подобно се случи и в Унгария, където въведената от Орбан смесена система помогна на новия му съперник Мадяр да спечели с огромно мнозинство.

Отива ли България там, откъдето Унгария се връща?
Унгария затваря цикъл, а България сякаш е на прага на нов. Между фигурата на „спасителя“, руското влияние и отслабващите институции стои въпросът „Накъде завиваме ние?“. Коментар на Светла Енчева.
Избори и избирателни системи. Между черните дупки и реалността

Съществува и вариантът с двукамарен парламент. На теория долната камара може да се избира пропорционално, а горната – хипотетичен Сенат – мажоритарно. Илюзия е обаче да се мисли, че щом сенаторите са избрани мажоритарно, от това автоматично следва, че те ще бъдат личности, заслужаващи уважение. Някои от най-спорните фигури в американската политика, като Тед Круз и Мич Макконъл, са дългогодишни сенатори с нисък рейтинг сред колегите си и в обществото, но с достатъчна подкрепа в своя регион.

Мажоритарната система обаче не бива да бъде демонизирана.

След като водещи демокрации я използват, тя има своите предимства. Когато всяко място в парламента е отделно състезание, политическите сили залагат на хора с по-силни характери. 

Те по-трудно се поддават на партийна дисциплина и могат да защитят интересите на своите избиратели, макар това понякога да влудява съпартийците им. Емблематичен пример беше сенатор Джон Маккейн, който не се колебаеше да застава срещу Тръмп, уверен в доверието на хората от Аризона. Също така мажоритарният вот по-лесно дава ясен мандат на спечелилата партия, така че отговорността да не се размива. Ситуации като „сглобката“ при такава система са много по-малко вероятни.

Цената обаче е по-малка представителност и по-ограничен избор. Никъде това не е толкова видимо, колкото в САЩ. Политическите партии там са „големи шатри“, в които се обединяват течения, нямащи много общо помежду си – например либертарианци и религиозни консерватори при републиканците или центристи и социалисти при демократите. Целта е да могат да спечелят избори, но така избирателят купува „котка в чувал“ – заедно с приоритетите, които подкрепя, получава и идеи, с които не е съгласен. 

В една пропорционална система човек може да направи по-нюансиран избор на сила, която отразява възгледите му по-точно –

например зелена партия, ако основната му грижа е екологията. Рискът е въпросната партия да не прескочи бариерата, но той е по-нисък от този при необходимостта от задължителна победа в конкретен регион.

Избирателните системи са математически модели, с които се опитваме да подредим хаоса на обществените желания. Но точно както ултрамасивните черни дупки съществуват въпреки познатите ни астрофизични закони, така и живият политически процес винаги ще намира начин да изненада теоретиците. Дори да променим правилата на играта, не бива да забравяме, че в политиката, както и в астрофизиката най-голямата грешка е да повярваме на модела повече, отколкото на самата реалност.

[$] Famfs, FUSE, and BPF

Post Syndicated from corbet original https://lwn.net/Articles/1068686/

The famfs filesystem first showed up on the
mailing lists
in early 2024; since then, it has been the topic of
regular discussions at the Linux Storage, Filesystem, Memory Management and
BPF (LSFMM+BPF) Summit. It has also, as result of those discussions, been
through some significant changes since that initial posting. So it is not
surprising that a suggestion that it needed to be rewritten yet again was
not entirely well received. How much more rewriting will actually be
needed is unclear, but more discussion appears certain.

AI is Changing Vulnerability Discovery and your Software Supply Chain Strategy has to Change with it

Post Syndicated from Wade Woolwine original https://www.rapid7.com/blog/post/ai-changing-vulnerability-discovery-software-supply-chain-strategy

Wade Woolwine is Senior Director, Product Security at Rapid7.

The headlines around Glasswing have focused on how quickly AI can surface vulnerabilities, which has naturally caught the attention of security leaders. In my conversations with teams and customers, the more useful discussion has been about what that speed means in practice for business protection, especially across open source risk, dependency choices, and software supply chain resilience. The deeper issue for security leaders sits elsewhere. 

Software risk is becoming harder to manage across the full lifecycle, especially in open source dependencies, build pipelines, developer environments, and the operational processes that sit between disclosure and remediation. When vulnerabilities can be found faster and at greater depth, security teams need more than another source of findings. They need a stronger way to understand what they run, what they trust, what they can patch quickly, and where a single weak dependency can create disproportionate risk.

Faster discovery makes software supply chain resilience a more immediate leadership issue. CISOs need a clearer view of how dependencies are chosen, monitored, validated, and governed across production, build, and developer environments, especially as open source remains essential to modern software development.

Organizations already struggle to absorb vulnerability disclosures at the pace they are coming in, because when discovery gets faster, the operational gap widens between knowing there is a problem and being able to do something useful about it. That gap is especially serious in the software supply chain, where a single dependency can introduce risk into build systems, production workloads, developer endpoints, and the tools used to secure them.

This is why I would frame AI-driven vulnerability discovery risk as a lifecycle challenge. The pressure does not sit in one place, but across inventory, dependency decisions, threat intelligence, patching discipline, and validation – with people, process, and visibility shaping how well an organization can respond. Technology matters, but it cannot compensate for a weak operating model underneath it.

Open source still matters. Dependency choices matter more.

Open source remains essential to modern software development because it helps teams move faster and get products to market without rebuilding common functionality from scratch. The better response is to be more deliberate about where and how third-party code enters the environment. 

Open source has always involved a trade-off between speed, efficiency, flexibility, and inherited risk, and that trade-off becomes harder to manage as AI makes code review deeper and faster. More flaws and supply chain compromises will likely be found in packages that teams have trusted for years, including transitive dependencies most developers did not knowingly choose. One only needs to look back a few weeks to find that the widely used Axios package suffered a supply chain compromise that bundled a Remote Access Trojan (RAT) charged with stealing secrets. That raises the value of understanding which dependencies are essential, which ones can be removed, which ones pull in large chains of transitives, and which ones are maintained by too few people to inspire confidence.

That work starts with a more disciplined question than “Is there a package that does this?” It starts with “Do we need this dependency, and do we understand the risk that comes with it?” The safest dependency is often the one that never enters the environment in the first place.

Why inventory has to go deeper than package lists

Supply chain resilience begins with knowing what you are actually running, which sounds straightforward until a critical disclosure lands in a package no one realized was in the environment three layers deep. Dependency graphs are deeper than most teams think, and transitive risk is where a lot of operational pain begins. A package chosen directly by a developer may bring in dozens of additional packages, each with its own maintainers, release cadence, security posture, and potential failure points.

A mature approach to inventory needs to move beyond a static package list, because CISOs need confidence in three views at once: What is declared in source, what is resolved and built, and what is actually running in production? Those views often drift apart over time, which means a package can be patched in source and still remain unpatched in a deployed container or runtime environment. An SBOM on its own will not close that gap; continuous, usable inventory will.

That inventory also needs clear ownership attached to it, because the moment a critical dependency is identified, someone has to decide what happens next, coordinate the change, and absorb the operational consequences. Security teams cannot do that well if responsibility is unclear, which is why ownership needs to be treated as part of resilience rather than an administrative detail.

Build pipelines and developer environments deserve the same scrutiny as production

Supply chain conversations still tend to start with production systems, even though recent incidents have shown how quickly compromise can move through the build layer, developer tooling, or the security tooling inside the pipeline itself. Those environments hold code, secrets, and trust relationships that attackers know how to exploit, while developer workstations often carry a rich mix of credentials and elevated privileges because speed matters to the business. Build systems are predictable and privileged, which makes them both valuable and vulnerable, but also easier to monitor.

Seeing those layers as part of the same attack surface means asking harder questions about how code enters the build, how package updates are governed, how actions and dependencies are pinned, what secrets exist in CI/CD, and what controls are in place on developer endpoints to detect anomalous behavior or stop high-risk package activity before it goes unnoticed.

You can gauge the maturity of the operating model with the answers to a few basic questions:

  • How tightly are dependencies controlled in CI?

  • How are package lifecycle scripts governed?

  • What secrets exist in CI/CD, and what protections surround them?

  • What visibility exists into anomalous behavior on developer endpoints?

  • How would the team detect or prevent high-risk package activity before it spreads?

If those answers are unclear, important parts of the model are still missing.

Why prioritization matters more as scanning accelerates

When software risk rises, the instinct is often to add another scanner because more visibility feels like progress. What matters more over time, though, is how well teams can prioritize the findings that follow, assign them to the right owner, choose the right mitigation, and prove that exposure actually went down. Broader scanning and faster discovery mostly add to the pile unless the operating model behind them is strong enough to turn findings into action. Feed more issues into a process that is already stretched and the backlog grows, priorities become harder to sort, and remediation slows in the places where speed matters most. The organizations that come through this period well will be the ones that treat supply chain resilience as a systems problem, with stronger intake, clearer governance, better intelligence, and faster paths from alert to action.

What stronger software supply chain resilience looks like in practice

A stronger response starts with a deeper inventory of dependencies across source, build, and runtime, so teams can see both direct and transitive packages and connect them back to real environments and real owners. Once that picture is in place, intelligence monitoring becomes far more useful when it runs continuously against credible signals on vulnerabilities, package risk, maintainer health, end-of-life software, and unusual changes in dependency behavior.

The same level of care needs to carry through into dependency governance, where better decisions depend on asking whether a new package is necessary, how much transitive risk it introduces, whether its maintenance model is healthy, and what policy governs its path into production. Build and developer controls belong in that same conversation, because version pinning, private registries, secret handling, script restrictions, immutable builds, ephemeral runners, and stronger endpoint monitoring all reduce the attack surface around the software supply chain.

Monitoring threat intelligence for notifications about new vulnerabilities and compromised packages and having a well defined and practiced process for scoping and remediating emerging threats becomes critical. Your supply chain vulnerability and compromise response should be practiced – just like your incident response plan – through table top exercises and simulated threat events. You don’t want to wait until the house is on fire to know how to execute an effective response.

Similarly, Engineering, DevOps, and Security teams should collaborate on establishing a trust and reputation scoring mechanism for supply chain dependencies. Being able to evaluate the speed of response, transparency of communication and updates, and ultimate resolution of the vulnerability or compromise speak volumes for how much you can trust the maintainers of the software you depend on. The OpenSSF Scorecard project offers a great place to start evaluating the open source packages you’re already using.

Organizations should also have a fallback plan for when obtaining a security patch is not available. Some options to consider include exploring other open source packages that perform similar functions, exploring other mitigations such as application firewalling, or even forking and contributing a security patch back to the community.

Validation closes the loop by showing whether the artifact came from where it was supposed to, whether the package has drifted in unexpected ways, and whether the mitigations applied are reducing live risk rather than simply documenting the process.

How CISOs should think about the next 12 months

The strain on security teams is only growing, and the potential for AI to relieve some of that pressure is understandably compelling, especially when boards, CEOs, and CFOs are asking how the organization plans to adopt it. That makes this a leadership question as much as a technology one. CISOs need a clear point of view on where AI can genuinely improve resilience, where it still introduces too much uncertainty, and how to explain those choices in business terms.

If software engineering teams are already adopting AI-assisted development, security teams should be part of that conversation early, especially around dependency management. I have seen teams begin connecting AI coding agents to vulnerability management workflows so those agents can interpret vulnerabilities found in the code base, assess reachability with more context, help plan remediation, and validate updates much faster than traditional handoffs usually allow. Used well, that can reduce drag across the workflow and help teams move faster on classes of issues that are currently slowing them down.

Getting there safely still depends on the foundation underneath it. A more resilient path starts with a clearer picture of the environment and a more complete inventory of dependencies across source, build, and runtime. From there, ownership needs to be explicit, threat and vulnerability intelligence needs to be embedded into how the organization prioritizes, and dependency sprawl needs to be reduced with more discipline around what actually enters production. The same mindset should carry through to the build layer and developer endpoints, where tighter controls and better visibility help reduce unnecessary exposure, while faster and more repeatable paths from disclosure to action make it easier for teams to respond before risk compounds.

That foundation will matter regardless of which AI model or platform becomes dominant six or twelve months from now. It will also matter if the next wave of AI makes backlog reduction, lower-tier remediation, or patch validation more practical. Organizations that know what they run and how they operate will be in a much better position to adopt those capabilities with intent.

The shift security leaders should make now

Security in an AI-accelerated world needs to be managed as a systems challenge, with supply chain resilience shaped by how well organizations connect software composition, exposure visibility, dependency governance, threat intelligence, build integrity, endpoint controls, remediation workflows, and validation. When those layers are treated separately, gaps open quickly; when they are tied together through a stronger operating model, teams are in a much better position to absorb faster discovery without losing control of the response.

For CISOs, that means continuing to use open source with a more deliberate view of dependency risk, reducing unnecessary packages where possible, knowing what is running and who owns it, and monitoring threat and vulnerability intelligence with enough discipline to act before the queue overwhelms the team. It also means paying closer attention to the attack surface across production, build, and developer environments, while treating AI as something that will amplify both the strengths and the weaknesses already present in the program. Faster discovery is here, and the organizations that handle it best will be the ones that can respond with the same level of discipline.

Modernizing KYC with AWS serverless solutions and agentic AI for financial services

Post Syndicated from Neeraj Kaushik original https://aws.amazon.com/blogs/architecture/modernizing-kyc-with-aws-serverless-solutions-and-agentic-ai-for-financial-services/

Regulators worldwide require financial institutions to implement Know Your Customer (KYC) processes that help prevent money laundering, terrorist financing, fraud, and identity theft. KYC has evolved from a compliance checkbox to a core security function for financial institutions. Financial institutions must modernize their KYC architectures because of several factors: rising transaction volumes, increasing regulatory complexity, and customer demands for instant onboarding. Legacy systems create multiple problems. They slow down compliance processes and expose institutions to both operational risks and regulatory penalties. However, traditional KYC orchestration systems, often built on monolithic architectures, struggle to meet these demands because of latency, availability, and scalability challenges. Their reliance on batch processing and manual handoffs leads to higher operational costs and impediments to real-time compliance validation, reinforcing the need for architectural modernization.

This post extends IBM’s approach to real-time KYC validation using generative AI, as previously discussed in the post IBM Digital KYC on AWS uses Generative AI to transform Client Onboarding and KYC Operations. It transforms compliance operations through autonomous decision-making and intelligent automation using agentic AI, event-driven architecture, and AWS serverless services. The solution addresses the fundamental limitations of traditional rule-based systems. It provides autonomous decision-making, dynamic adaptation, and intelligent automation that transforms compliance operations.

Financial institutions can break down KYC workflows into separate business functions. Amazon Managed Streaming for Apache Kafka (Amazon MSK) handles real-time event streaming, which speeds up processing. Amazon Bedrock automates document analysis and risk assessment with AI. AWS Lambda provides serverless computing that scales on demand and supports instant customer onboarding.

The critical role of KYC

KYC protects financial systems by verifying customer identities and detecting fraud in four ways. It supports regulatory compliance with anti-money laundering (AML) and counter-terrorist financing (CTF) regulations. It helps prevent fraud by detecting identity theft and forged documents. It manages risk by assessing customer profiles and monitoring transactions. And it builds customer trust through transparency. As financial institutions broaden their footprint across products, industries, and regions, KYC compliance becomes increasingly complex. Each financial service offering presents unique requirements, from traditional banking to digital wallets, investment systems, and cryptocurrency services. Expansion into retail, SME, and corporate segments brings diverse identity structures and risk profiles. Operating across multiple jurisdictions requires navigation of various regulatory frameworks. These frameworks include the Bank Secrecy Act (BSA) and USA PATRIOT Act in the US, Anti-Money Laundering Directives (AMLD) in the EU, and guidelines from international regulators like the Monetary Authority of Singapore (MAS) and Financial Action Task Force (FATF).

Traditional KYC

Traditional KYC processes verify customer identities, assess risk, and monitor for money laundering. They rely on manual document collection, identity checks across multiple databases, and periodic reviews. While these established processes have served the financial industry for decades, they were designed for a different era with lower transaction volumes, simpler product offerings, and less sophisticated threat landscapes. Today’s digital-first financial environment demands a fundamental reimagining of KYC at scale.

Current challenges

Legacy systems create several bottlenecks. They process requests in batches rather than real-time, making instant onboarding impossible. Manual validation across jurisdictions leads to inconsistent compliance. Without event-driven capabilities, these systems can’t integrate with modern AI and machine learning (ML) services or adapt to new fraud patterns without manual reconfiguration.

Cloud-native KYC solution architecture using agentic AI

This architecture illustrates a comprehensive cloud-native real-time KYC validation system designed to process live customer onboarding requests and validate identity information using AI-powered automation. The architecture uses an event-driven pipeline to process high-volume KYC validations securely in under 5 minutes. The system processes real-time KYC requests containing sensitive financial data including PII while maintaining strict security and regulatory compliance requirements across multiple geographies.

High-level Agentic Architecture for real-time KYC

High-level Agentic Architecture for real-time KYC

This architecture diagram illustrates an AI-driven Know Your Customer (KYC) Orchestration Framework built using Amazon Bedrock AgentCore and Amazon Managed Streaming for Apache Kafka (Amazon MSK). The design showcases how multiple specialized AI agents collaborate to automate and optimize KYC workflows, from document ingestion to compliance validation and fraud detection, while maintaining real-time integration with on-premises financial systems.

At the heart of the architecture is the AgentCore Runtime Environment, which provides native orchestration capabilities, session management, and memory persistence. Within this runtime, the KYC Orchestration Supervisor Agent acts as the intelligent coordinator, delegating tasks to five domain-specific sub-agents: Identity Verification, Document Analysis, Fraud Detection, Compliance & Risk, and Customer Experience. Unlike traditional multi-agent systems, AgentCore provides built-in session state management, shared memory across sub-agents, and automatic context preservation throughout asynchronous processing workflows.

The architecture uses asynchronous invocation patterns where MSK consumers trigger AgentCore processing without blocking, enabling sub-5-minute processing times while handling thousands of concurrent KYC requests. Lambda functions serve as the integration layer, consuming events from MSK, invoking AgentCore asynchronously, and publishing results back to Kafka topics for downstream system consumption.

Each sub-agent uses foundation models hosted on Amazon Bedrock for tasks such as optical character recognition (OCR), language processing, behavioral analysis, and regulatory interpretation. These agents operate within the AgentCore Runtime, sharing context through AgentCore Memory (a built-in feature of Bedrock AgentCore that automatically manages session state and context) and accessing external systems through tools defined using OpenAPI schemas and Lambda targets.

The agents use KYC Knowledge Bases, powered by Amazon OpenSearch Serverless and Amazon Simple Storage Service (Amazon S3), to access contextual information from internal policies, compliance rules, vendor documentation, and regulations. This approach provides consistent, explainable, and policy-aligned decision-making. These knowledge bases integrate with AgentCore’s retrieval mechanisms, providing sub-agents with grounded information during processing.

Finally, the solution connects with existing on-premises systems, such as customer management, transaction monitoring, case management, risk/AML systems, and core banking systems. These connections use tools defined with OpenAPI schemas as targets and Lambda-based integrations using AgentCore Gateway. AgentCore Gateway uses these OpenAPI specifications to understand API contracts, handle authentication, validate requests and responses, and manage retries. AgentCore Identity manages authentication and authorization for agents and their tool access, so that only authorized sub-agents can invoke specific tools and access the Knowledge Base. With this approach, financial institutions can achieve an intelligent, scalable, and compliance-aligned KYC process that minimizes manual intervention, improves onboarding speed, and reduces fraud and regulatory risks.

Solution Components

Event-Driven Communication Infrastructure with Amazon MSK

Amazon MSK serves as the communication backbone, enabling asynchronous, real-time message exchange between agentic AI components and enterprise systems. The streaming infrastructure organizes into distinct topic categories supporting bi-directional flows.

Inbound topics capture customer interactions through KYC requests (new applications), document uploads (identity documents), ID verification results (third-party vendor responses), and transaction events (fraud/risk signals). Event listeners pre-process these streams. These listeners filter onboarding requests, prepare documents for OCR, normalize vendor data formats, and correlate transaction signals with customer profiles.

Outbound topics publish KYC decisions with confidence scores and audit trails to core banking systems, route complex cases to human reviewers through case management events, and trigger fraud alerts to security teams. With this decoupled architecture, you can achieve sub-5-minute processing while maintaining full event auditability and allowing independent scaling of individual agents based on workload patterns.

Agentic AI Orchestration Layer

KYC Orchestration Supervisor Agent

The Supervisor Agent implements intelligent routing logic using Amazon Bedrock AgentCore to dynamically determine optimal sub-agent collaboration patterns. Unlike rule-based systems following rigid workflows, the supervisor analyzes case characteristics (document types, customer geography, risk indicators, and historical patterns) to construct context-aware execution plans that invoke sub-agents in parallel or sequentially based on dependencies. The supervisor monitors sub-agent confidence scores to guide decision-making: high confidence (>95%) results in automatic approvals, medium confidence (75-95%) triggers additional verification, and low confidence (<75%) escalates to human review with comprehensive context.

Five Specialized Sub-Agents operate as autonomous decision-makers, each using foundation models for domain-specific tasks:

  • Identity Verification Sub-Agent validates customer identities against watchlists and sanctions databases. It calls third-party verification APIs and uses natural language processing to handle name variations.
  • Document Analysis Sub-Agent extracts data from identity documents using OCR. The agent handles poor image quality and multiple languages and detects forgery by analyzing watermarks and security features.
  • Fraud Detection Sub-Agent identifies suspicious patterns through behavioral analysis. The agent detects multiple applications from the same IP address or inconsistent information across form fields. It correlates current applications with historical fraud cases using semantic similarity search and maintains dynamic risk scores with explainable fraud assessments.
  • Compliance & Risk Sub-Agent supports regulatory adherence by interpreting jurisdiction-specific KYC requirements across different geographies. It translates regulatory frameworks into concrete validation actions and generates compliance attestations with audit trails for regulatory examinations.
  • Customer Experience Sub-Agent optimizes the onboarding journey by analyzing application progress in real time, identifying friction points, and recommending strategies to reduce abandonment while identifying upselling opportunities based on customer profiles.

Intelligent Knowledge Management Architecture

The KYC Knowledge Base implements a retrieval augmented generation (RAG) pattern that grounds agent decisions in factual, current information rather than relying solely on foundation model training. Amazon S3 stores source documents, including regulations from financial authorities, institution-specific compliance rules, internal policies, and vendor documentation, enabled to track changes over time. Documents undergo automated preprocessing for text extraction, metadata enrichment, and quality validation before the system indexes them. Amazon OpenSearch Serverless provides semantic search using vector embeddings generated by Amazon Bedrock. When agents query using natural language questions, the system embeds queries into the same vector space and identifies semantically relevant document chunks through cosine similarity search, improving retrieval accuracy over keyword matching.

Context-aware retrieval enriches queries with case-specific information, including customer jurisdiction, document types, and risk levels – facilitating highly relevant regulatory guidance. This continuous knowledge access keeps agent decisions grounded in institutional knowledge rather than hallucinating responses.

Real-Time Decision Store (Amazon DynamoDB) complements the Knowledge Base with sub-millisecond access to frequently accessed structured data, including current KYC decision status, risk scores, customer interaction history, and dynamic configuration parameters controlling agent behavior.

Secure integration with on-premises financial systems

The architecture integrates with on-premises financial systems through Action Groups bridging the cloud-native agentic layer and existing enterprise infrastructure.

Customer Management Systems receive real-time KYC decisions, updating verification status and account activation flags. Transaction Monitoring Systems consume fraud alerts and risk scores, enabling immediate action on suspicious patterns. Case Management Systems receive escalated cases with comprehensive agent analysis context, accelerating human review. Risk and AML Systems integrate bidirectionally to maintain consistent risk assessments. Core Banking Systems receive approved validations, triggering account activation.

Secure connectivity through AWS Direct Connect or AWS Site-to-Site VPN provides encrypted data transmission over dedicated network paths. API calls include comprehensive audit logging through AWS CloudTrail and Amazon CloudWatch, satisfying regulatory requirements.

Security Considerations

The solution should incorporate multi-layered security controls, continuous monitoring, and automated compliance auditing to meet the rigorous expectations of financial regulators and internal risk teams. Financial institutions should conduct a comprehensive threat modelling to identify risks including introduced by agentic AI systems. For further information please refer Security Guidance.

Conclusion

This KYC architecture uses AWS serverless services and Amazon Bedrock to process validations faster and at scale. The parallel agent execution model is designed to reduce KYC validation time from the typical 3-5 days to near-real time for standard cases. This approach enables exponentially faster processing through simultaneous operation of Document Analysis, Identity Verification, and Fraud Detection agents rather than sequential workflows.

With this architecture, financial institutions can handle high-volume validations through elastic scaling, optimize costs through serverless pay-per-use pricing, and improve accuracy through multi-agent collaboration. Automated document processing and intelligent routing are expected to reduce manual review workload, allowing each compliance specialist to handle up to 4x their current caseload while focusing on complex cases requiring human expertise. Explainable AI decisions with comprehensive audit trails support regulatory compliance and enable rapid audit responses.

Event-driven architecture and agentic AI help financial institutions compete in digital landscapes while meeting regulatory requirements.

Note: The architecture presented here is for reference purposes only. IBM and AWS will work closely with you to execute a Proof of Concept and implementation plan in accordance with industry standards and compliance requirements.

Further Reading

IBM Consulting is an AWS Premier Tier Services Partner that helps customers who use AWS to harness the power of innovation and drive their business transformation. They are recognized as a Global Systems Integrator (GSI) for over 30 competencies, including Financial Services Consulting. For additional information, please contact an IBM Representative.


About the authors

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1069356/

Security updates have been issued by AlmaLinux (kernel and osbuild-composer), Debian (cpp-httplib, firefox-esr, gimp, and packagekit), Fedora (chromium, composer, libcap, pgadmin4, pie, python3-docs, python3.14, and sudo), Mageia (gvfs), Oracle (.NET 8.0, delve, freerdp, giflib, ImageMagick, kernel, OpenEXR, and osbuild-composer), SUSE (erlang, giflib, google-guest-agent, GraphicsMagick, ignition, imagemagick, kea, kernel, kissfft, libraw, libssh, ocaml-patch, opam, openCryptoki, openexr, openssl-1_1, tomcat, tomcat10, tomcat11, and tor), and Ubuntu (linux, linux-aws, linux-aws-5.4, linux-azure, linux-gcp, linux-gcp-5.4,
linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm,
linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux-aws, linux-aws-6.17, linux-hwe-6.17, linux-oracle, linux-oracle-6.17, linux-azure, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-oracle-5.15, linux-azure-5.4, linux-azure-fips, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-hwe-6.8, linux-ibm-6.8, linux-raspi, linux-oracle, linux-oracle-6.8, linux-raspi, linux-raspi-5.4, linux-raspi-realtime, packagekit, python-tornado, ruby-rack-session, slurm-llnl, and strongswan).

FBI Extracts Deleted Signal Messages from iPhone Notification Database

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2026/04/fbi-extracts-deleted-signal-messages-from-iphone-notification-database.html

404 Media reports (alternate site):

The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database….

The news shows how forensic extraction—­when someone has physical access to a device and is able to run specialized software on it—­can yield sensitive data derived from secure messaging apps in unexpected places. Signal already has a setting that blocks message content from displaying in push notifications; the case highlights why such a feature might be important for some users to turn on.

“We learned that specifically on iPhones, if one’s settings in the Signal app allow for message notifications and previews to show up on the lock screen, [then] the iPhone will internally store those notifications/message previews in the internal memory of the device,” a supporter of the defendants who was taking notes during the trial told 404 Media.

[$] LWN.net Weekly Edition for April 23, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1067989/

Inside this week’s LWN.net Weekly Edition:

  • Front: LLMs and Python bugs; scheduler regression; new Rust traits; dependency cooldowns; 7.1 merge window; Shor’s algorithm; drama at The Document Foundation.
  • Briefs: Firefox zero-days; kernel code removal; reproduceible Arch; Debian election; Firefox 150; Forgejo 15.0; Git 2.54.0; KDE Gear 26.04; LillyPond 2.26.0; Rust 1.95.0; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

The collective thoughts of the interwebz