Седмицата (19–24 януари)

Post Syndicated from Надежда Радулова original https://www.toest.bg/sedmitsata-19-24-yanuari/

Седмицата (19–24 януари)

Тази „президентска“ седмица започна – обещаващо – с оставка и с няколко разменени писма.

Оставката я подаде президентът Румен Радев, който се възползва от последните си минути на поста, за да стартира предизборна кампания, все още лишена от конкретност, но очевидно и очаквано прицелена към младите. Оставям настранa съдържанието на речта и се фокусирам само върху жеста на оставката – за мен жалка проява на (меко казано) нелоялност и безотговорност към президентската институция и към цялата държава.

Да си президент не е като да си касиерка в супермаркет А, която в дните преди Коледа напуска, защото в супермаркет Б са ѝ предложили по-добри условия. Да си президент в известен смисъл е като да си пилот – не върви да зарежеш пътниците и да скочиш с парашут, преди полетът да е приключил. Президентът има мандат и отказът от поста би трябвало да е (морално и всякак) възможен само при изключителни обстоятелства. Каквито предстоящите избори не са. И личното му политическо битие и бъдеще не е. Още по-малко биха могли да бъдат оправдание евентуално поетите ангажименти към трети и пети лица, политически проекти, партии, организации и прочее…

Основната мисия на президента е да стои начело на народа, който го е избрал, във времето, за което е избран. Независимо дали повереният му самолет се движи по разписание, закъснява, или всеки момент ще се разбие в земята. Но Румен Радев за пореден път демонстрира, че не служи на интересите на България и нищо не (може да) пилотира просто защото през цялото време се вози в чужд самолет.

Още по темата за тази срамна оставка, както и за останалите позорни деяния, свършени от управниците ни през последните дни четете в анализа на Емилия Милчева „Отечество любезно, аз ще те спася“.

Отечество любезно, аз ще те спася!
Точно преди 40 години Тина Търнър изпя We don’t need another hero. Колко продължения на реалност а ла „Лудия Макс“ са ни необходими, за да спрем да повтаряме същата грешка? Емилия Милчева за новия спасител, задаващ се на хоризонта, и за останалите месии, които играят като за последно десет.
Седмицата (19–24 януари)

Въпреки очевидно спекулативния монолог на Радев от понеделник вечер, опасявам се, че сърцераздирателният му тон вероятно е докоснал немалко сърца, чийто вот на предстоящите избори вече е предопределен. Податливостта ни на пропаганда и манипулация става все по-плашеща, докато капацитетът ни да анализираме реалността отслабва. Във връзка с тази тема ви предлагаме да се „запознаете“ с един бивш служител на ДС – полковник А., който не е подписал дебютната си статия в „Тоест“ „Манипулацията – този стар и все тъй полезен занаят“, но по всичко личи, че стои зад думите си. А те са свързани именно с механизмите, по които биваме управлявани, и с евентуалните начини да противостоим на манипулацията и пропагандата. Ето какво съветва полковник А.:

Като първоначален тест винаги си задавайте още един въпрос: въздейства ли материалът, който четете, слушате или гледате, върху мисълта ви – или върху емоциите ви? Ако отговорът е второто, в 99% от случаите става дума за манипулация. Проверявайте. И не се хващайте.

Манипулацията – този стар и все тъй полезен занаят
Свикнали сме да свързваме Държавна сигурност със задкулисието. Бившият служител на ДС Полковник А. обаче иска да бъде полезен на обществото. В дебютната си статия за „Тоест“ той ни дава насоки как да разберем кога ни манипулират. И има още много неща да ни каже. Дали ще го чуем, зависи от нас.
Седмицата (19–24 януари)

Добър съвет в момент, в който ни предстоят важни избори. На тях – според Александър Драганов и статията му „Партийните системи по света и де е България в тях“ – целта ПП–ДБ да получат пълно мнозинство в парламента е трудно постижима. И това се дължи най-вече на пропорционалната избирателна система у нас, както и на степента на поляризация в обществото. Ето какво казва Александър в тази връзка:

България е средноевропейска държава и пропорционалната избирателна система е нормална за нея. От това следват няколко неща. Преди всичко в Народното събрание ще попадат различни партии. Причината се корени не само в разделението ни на различни политически племена (по Димитър Ганев) и във факта, че в България „всяка коза е за свой крак“, а най-вече в обстоятелството, че това състояние е очакваното – и дори желаното – за избирателна система като нашата. Различните групи от населението с различни виждания и интереси получават представителство. Задача на политиците е да намерят работеща формула, за да се съобразят с тях.

Партийните системи по света и де е България в тях
Отново предстоят избори. Асен Василев призовава гласоподавателите на ПП–ДБ да изберат коалицията с пълно мнозинство. Александър Драганов обаче се аргументира защо според него тази цел не е постижима.
Седмицата (19–24 януари)

И докато с омерзение наблюдаваме години наред как политиците така и не намират работещата формула, налага се да вършим и други неща, например да си раждаме и отглеждаме децата, при все че светът изглежда все по-неподходящо място за тази дейност. На „Раждането – между физиологията и системата“ е посветена поредната статия на Надежда Цекулова от рубриката ѝ за женското здраве. И най-вече на добрите и недотам добрите практики в родилната помощ и тяхното прилагане у нас. Практики, които в редица случаи наистина опират не до степен на експертност и ниво на оборудване, а до базисни етически норми:

Осем години след публикуването им много от препоръките на Световната здравна организация за позитивно раждане все още са масово недостъпни за родилките в България: да бъдат подкрепяни от близък човек, да могат да консумират лека храна и течности в първия етап на раждането, да бъдат третирани с уважение. 

Раждането – между физиологията и системата
Когато говорим за женско здраве, няма как да не стане дума и за раждащата жена. Надежда Цекулова обобщава важна информация за процеса на раждане с поглед върху най-добрите медицински практики и с едно наум, че в България те се прилагат на твърде малко места.
Седмицата (19–24 януари)

И от темата за женското здраве плавно преминаваме към проблема с психичното ни здраве, което родната действителност за поредна седмица изправя пред неимоверни предизвикателства. Съветът за оцеляване на Е.Т. в епизод 38 гласи:

Представете си, че сте панда. Не виждам друго спасение.

И така, бавно и със стрък бамбук между зъбите, прекрачваме границите на страната, за да огледаме какво се случва на международната сцена.

Тук идва моментът да се върнем към „писмата“, за които споменах по-горе и които рязко ни настроиха на вълните на срещата в Давос още преди реално тя да е започнала. Та в началото на седмицата президентът дадаист, „кралят Юбю“ на нашето време, възпят още като Тръмпти Дъмпти, изпрати обидено писмо отговор до норвежкия премиер Йонас Гар Стьоре, в което обясни, че след като си е дал труда да спре осем войни, че и отгоре, за което не е получил полагаемата му се Нобелова награда за мир, световният мир вече не е негова грижа и отговорност. Така щял да се фокусира върху важните за САЩ задачи, като например присъединяването на заветната Гренландия.

За да забършат капките от поредното изплискване на президентския леген и евентуално да укротят буйстващия вътре Доналд, на когото му е отказана желаната играчка, други лидери отвърнаха с доста възпитани, макар и еднозначни кратки текстови съобщения. В съобщението си Макрон например кани Тръмп на вечеря, директно заявява, че не разбира историята с Гренландия, и два пъти използва думата great – явно за да слезе до нивото на речника на американския президент. Марк Рюте от своя страна също гали Тръмп по посока на косъма за Сирия, като използва друга любима дума на Доналд – incredible. И разбира се, отново повдига темата за Гренландия.

Гренландия, естествено, присъстваше и в давоските речи, като специално тази на Тръмп продължи над час и изобилстваше от лъжи и полуистини, подправени с доза невежество и обвити в дементна мъгла, чието разплитане може да проследите тук. За пореден път американският президент заяви апетитите си към Гренландия, която безсрамно омаловажи и обиди, наричайки я „парче лед“.

На този фон речта на канадския премиер Марк Карни в Давос заслужено стана вайръл с непоколебимия си тон; с дързостта да назове нещата с истинските им имена – „разрив“, а не „преход“; с избора на Вацлав Хавел и „живота в истина“ като отправна точка в бъдещето; с визията за коалициите на средните сили, чийто ход може да бъде съзидателен, за разлика от действията на великите геополитически съперници. И разбира се, с коментара по актуалната тема за ледения остров:

По отношение на арктическия суверенитет ние твърдо стоим зад Гренландия и Дания и напълно подкрепяме тяхното уникално право да определят бъдещето на Гренландия.

Идеята за новите коалиции, както и заявената воля за консолидиране на Европа в отпор на безобразната външна политика на президента на САЩ е хоризонт, спрямо който България, пълноправна членка на ЕС, би трябвало да ориентира позицията си. Уви, обаче, по-малко от денонощие след безумната реч на Тръмп премиерът Желязков тихомълком, без ясно заявено решение от правителството или парламента, въз основа на „поверителен акт“, приет в късни доби от Министерския съвет, се изстреля на учредяването на т.нар. Съвет за мир на Тръмп – формирование, което водещите страни в ЕС бойкотираха. С участието си в Съвета България се откъсва от политическите си съюзници и застава до страни като Унгария, Турция, Беларус, Аржентина, Парагвай, Катар, Саудитска Арабия и пр. А задната мисъл в целия този резил, разбира се, е да се откупи „свободата“ на г-н Пеевски от списъка „Магнитски“.

След тази турбулентна седмица, в която знаковите думи на отминалата година „евро“, „безобразие“ и „протест“ бяха изтласкани от следващи потенциални претенденти, като „оставка“, „разрив“, „Гренландия“ и нови измерения на „безобразието“, ви предлагаме малко почивка от политиката, без рязко да сменяме темата. Затова ви припомняме няколко красиви и информативни текста на Светла Стоянова от северната ѝ поредица, която публикувахме през 2024, доста преди „парчето лед“ да се превърне в гореща геополитическа хапка. Тези пътеписи ще ви помогнат да усетите истинската Гренландия – с магията на леда, кучешките впрягове, пъстрите къщи, екзотичния език и храна, нравите на инуитите… Приятно четене!

А ако сте пропуснали да чуете на живо шести епизод от рубриката „Тоест разговаряме“, в който гост е Йоанна Елми – дългогодишна авторка в „Тоест“ и водеща на бюлетина „Гласовете на Америка“, вече може да го направите ето тук.

Тоест разговаряме – епизод 6
Какво всъщност се разпада днес – митовете, институциите или социалният договор? Гледайте в шестия епизод на „Тоест разговаряме“ с Йоанна Елми, дългогодишна авторка в „Тоест“ и водеща на бюлетина „Гласовете на Америка“.
Седмицата (19–24 януари)

Следващата среща ще бъде с Михаил Ангелов – биолог, агроном и водещ на рубриката „Научни новини“ в „Тоест“. Разговорът ще се излъчи на живо в YouTube Live на 7 февруари, събота, от 16:00 ч.

За финал ви поздравявам с едно неостаряващо парче на Боб Дилън, което – в духа на речта на Карни – отново става актуално:

И по-добре започвай да плуваш,
иначе ще потънеш като камък,
защото светът се променя.

И не забравяйте, че за да плуваме заедно, се нуждаем от вашата подкрепа. Защото светът се променя… А желаещите да ни пратят на дъното неспирно работят по въпроса. Благодарим ви!

Updated PCI PIN compliance package for AWS Payment Cryptography now available

Post Syndicated from Tushar Jain original https://aws.amazon.com/blogs/security/updated-pci-pin-compliance-package-for-aws-payment-cryptography-now-available/

Amazon Web Services (AWS) is pleased to announce the successful completion of Payment Card Industry Personal Identification Number (PCI PIN) audit for the AWS Payment Cryptography service.

With AWS Payment Cryptography, your payment processing applications can use payment hardware security modules (HSMs) that are PCI PIN Transaction Security (PTS) HSM certified and fully managed by AWS, with PCI PIN-compliant key management. This attestation gives you the flexibility to deploy your regulated workloads with reduced compliance overhead.

The PCI PIN compliance report package for AWS Payment Cryptography includes two key components:

  • PCI PIN Attestation of Compliance (AOC) – demonstrating that AWS Payment Cryptography was successfully validated against the PCI PIN standard with zero findings
  • PCI PIN Responsibility Summary – provides guidance to help AWS customers understand their responsibilities in developing and operating a highly secure environment for handling PIN-based transactions

AWS was evaluated by Coalfire, a third-party Qualified Security Assessor (QSA). Customers can access the PCI PIN Attestation of Compliance (AOC) and PCI PIN Responsibility Summary reports through AWS Artifact.

To learn more about our PCI programs and other compliance and security programs, visit the AWS Compliance Programs page. As always, we value your feedback and questions; reach out to the AWS Compliance team through the Compliance Support page.

If you have feedback about this post, submit comments in the Comments section below. If you have questions about this post, contact AWS Support.

Tushar Jain

Tushar Jain

Tushar is a Compliance Program Manager at AWS. He leads multiple security and privacy initiatives within AWS. Tushar holds a Master of Business Administration from Indian Institute of Management Shillong, India and a Bachelor of Technology in electronics and telecommunication engineering from Marathwada University, India. He has over 13 years of experience in information security and holds CCSK and CSXF certifications.

Will Black

Will Black

Will is a Compliance Program Manager at Amazon Web Services. He leads multiple security and compliance initiatives within AWS. He has ten years of experience in compliance and security assurance and holds a degree in Management Information Systems from Temple University. Additionally, he holds the CCSK and ISO 27001 Lead Implementer certifications.

Friday Squid Blogging: Giant Squid in the Star Trek Universe

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2026/01/friday-squid-blogging-giant-squid-in-the-star-trek-universe.html

Spock befriends a giant space squid in the comic Star Trek: Strange New Worlds: The Seeds of Salvation #5.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

AWS achieves 2025 C5 Type 2 attestation report with 183 services in scope 

Post Syndicated from Tea Jioshvili original https://aws.amazon.com/blogs/security/aws-achieves-2025-c5-type-2-attestation-report-with-183-services-in-scope/

Amazon Web Services (AWS) is pleased to announce a successful completion of the 2025 Cloud Computing Compliance Criteria Catalogue (C5) attestation cycle with 183 services in scope. This alignment with C5 requirements demonstrates our ongoing commitment to adhere to the heightened expectations for cloud service providers. AWS customers in Germany and across Europe can run their applications in the AWS Regions that are in scope of the C5 report with the assurance that AWS aligns with C5 criteria.

The C5 attestation scheme is backed by the German government and was introduced by the Federal Office for Information Security (BSI) in 2016. AWS has adhered to the C5 requirements since their inception. C5 helps organizations demonstrate operational security against common cybersecurity threats when using cloud services.

Independent third-party auditors evaluated AWS for the period of October 1, 2024, through September 30, 2025. The C5 report illustrates the compliance status of AWS for both the basic and additional criteria of C5. Customers can download the C5 report through AWS Artifact, a self-service portal for on-demand access to AWS compliance reports. Sign in to AWS Artifact in the AWS Management Console or learn more at Getting Started with AWS Artifact.

AWS has added the following five services to the current C5 scope:

The following AWS Regions are in scope of the 2025 C5 attestation: Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Milan), Europe (Paris), Europe (Stockholm), Europe (Spain), Europe (Zurich), and Asia Pacific (Singapore). For up-to-date information, see the C5 page of our AWS Services in Scope by Compliance Program.

Security and compliance is a shared responsibility between AWS and the customer. When customers move their computer systems and data to the cloud, security responsibilities are shared between the customer and the cloud service provider. For more information, see the AWS Shared Security Responsibility Model.

To learn more about our compliance and security programs, see AWS Compliance Programs. As always, we value your feedback and questions; reach out to the AWS Compliance team through the Contact Us page.

Reach out to your AWS account team if you have questions or feedback about the C5 report.
If you have feedback about this post, submit comments in the Comments section below.

Tea Jioshvili

Tea Jioshvili

Tea is a Manager in AWS Compliance & Security Assurance based in Berlin, Germany. She leads various third-party audit programs across Europe. She previously worked in security assurance and compliance, business continuity, and operational risk management in the financial industry for 20 years.

Metasploit Wrap-Up 01/23/2026

Post Syndicated from Jack Heysel original https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-01-23-2026

Oracle E-Business Suite Unauth RCE

This week, we are pleased to announce the addition of a module that exploits CVE-2025-61882, a pre-authentication remote code execution vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. The exploit chains multiple flaws—including SSRF, path traversal, HTTP request smuggling, and XSLT injection—to coerce the target into fetching and executing a malicious XSL file hosted by the attacker. Successful exploitation results in arbitrary command execution and an interactive shell on both Linux/Unix and Windows targets. The module is reliable, repeatable, and we here at Metasploit hope you enjoy it, happy hacking!

New module content (3)

Authenticated RCE in Splunk (splunk_archiver app)

Authors: Alex Hordijk, Maksim Rogov, and psytester Type: Exploit Pull request: #20770 contributed by vognik Path: linux/http/splunk_auth_rce_cve_2024_36985 AttackerKB reference: CVE-2024-36985

Description: This adds two separate Metasploit exploit modules targeting Remote Code Execution (RCE) vulnerabilities in Splunk Enterprise. CVE-2024-36985 exploits unsafe use of the “copybuckets” lookup function within the splunk_archiver application, resulting in execution of the sudobash helper script with attacker-controlled arguments. Affected versions: All releases prior to 9.0.10, 9.1.2 through 9.1.5, 9.2.0 through 9.2.2 CVE-2022-43571, exploits a Python code injection vulnerability in Splunk SimpleXML dashboards by injecting malicious code into sparkline style parameters. Malicious code is executed when a user exports the dashboard to PDF. Affected versions: All releases prior to 8.1.12, 8.2.0 through 8.2.9, 9.0.0 through 9.0.2.

Oracle E-Business Suite CVE-2025-61882 RCE

Authors: Mathieu Dupas and watchTowr (Sonny, Sina Kheirkhah, Jake Knott) Type: Exploit Pull request: #20750 contributed by MatDupas Path: multi/http/oracle_ebs_cve_2025_61882_exploit_rce AttackerKB reference: CVE-2025-61882

Description: This adds an exploit for CVE-2025-61882, a critical Remote Code Execution (RCE) vulnerability in Oracle E-Business Suite (EBS). The flaw allows unauthenticated attackers to execute arbitrary code by leveraging a combination of SSRF, HTTP request smuggling and XSLT injection. Affected Versions: Oracle E-Business Suite, 12.2.3-12.2.14.

Authenticated RCE in Splunk (SimpleXML dashboard PDF generation)

Authors: Danylo Dmytriiev, Maksim Rogov, and psytester Type: Exploit Pull request: #20770 contributed by vognik Path: multi/http/splunk_auth_rce_cve_2022_43571 AttackerKB reference: CVE-2022-43571

Description: This adds two separate Metasploit exploit modules targeting Remote Code Execution (RCE) vulnerabilities in Splunk Enterprise. CVE-2024-36985 exploits unsafe use of the “copybuckets” lookup function within the splunk_archiver application, resulting in execution of the sudobash helper script with attacker-controlled arguments. Affected versions: All releases prior to 9.0.10, 9.1.2 through 9.1.5, 9.2.0 through 9.2.2 CVE-2022-43571, exploits a Python code injection vulnerability in Splunk SimpleXML dashboards by injecting malicious code into sparkline style parameters. Malicious code is executed when a user exports the dashboard to PDF. Affected versions: All releases prior to 8.1.12, 8.2.0 through 8.2.9, 9.0.0 through 9.0.2.

Enhancements and features (3)

  • #20755 from rudraditya21 – This adds an advanced datastore option, KrbClockSkew, to modules that use Kerberos authentication, allowing operators to adjust the Kerberos clock from the Metasploit side to fix clock skew errors.
  • #20840 from xaitax – This updates the MongoBleed auxiliary module and adds new options. The module can now use Wiz Magic Packet to detect the vulnerability quickly; it can detect compression libraries used by MongoDB (and warns or stops the user if zlib is not enabled). The module can also reuse the MongoDB socket connection during memory scanning, which significantly improves performance. Finally, it can better leak secrets, either by pattern matching or by storing the extracted information in raw or JSON format.
  • #20861 from bcoles – Adds multiple improvements to get_hostname resolution logic for post exploitation modules.

Bugs fixed (1)

  • #20888 from jheysel-r7 – Fixes an issue that caused dMSA kerberos authentication to fail.

Documentation

You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

AWS renews the GSMA SAS-SM certification for two AWS Regions and expands to cover four new Regions

Post Syndicated from Michael Murphy original https://aws.amazon.com/blogs/security/aws-renews-the-gsma-sas-sm-certification-for-two-aws-regions-and-expands-to-cover-four-new-regions/

Amazon Web Services (AWS) is pleased to announce the expansion of GSMA Security Accreditation Scheme for Subscription Management (SAS-SM) certification to four new AWS Regions: US West (Oregon), Europe (Frankfurt), Asia Pacific (Tokyo), and Asia Pacific (Singapore). Additionally, the AWS US East (Ohio) and Europe (Paris) Regions have been recertified. All certifications are under the GSM Association (GSMA) SAS-SM with scope Data Centre Operations and Management (DCOM). AWS was evaluated by GSMA-selected independent third-party auditors, and all Region certifications are valid through October 2026. The Certificate of Compliance that shows AWS achieved GSMA compliance status is available on both the GSMA and AWS websites.

The US East (Ohio) Region first obtained GSMA certification in September 2021, and the Europe (Paris) Region first obtained GSMA certification in October 2021. Since then, multiple independent software vendors (ISVs) have inherited the controls of our SAS-SM DCOM certification to build GSMA compliant subscription management or eSIM (embedded subscriber identity module) services on AWS. For established market leaders, this reduces technical debt while meeting the scalability and performance needs of their customers. Startups innovating with eSIM solutions can accelerate their time to market by many months, compared to on-premises deployments.

Until 2023, the shift from physical subscriber identity modules (SIMs) to eSIMs was primarily driven by automotives, cellular connected wearables, and companion devices such as tablets. GSMA is promoting the SGP.31 and SGP.32 specifications, which standardize protocols and guarantee compatibility and consistent user experience for all eSIM devices spanning smartphones, IoT, smart home, industrial Internet of Things (IoT), and so on. As more device manufacturers launch eSIM only models, our customers are demanding robust, cloud-centered eSIM solutions. Over 400 telecom operators around the world now support eSIM services for their subscribers. Hosting eSIM platforms in the cloud allows them to integrate efficiently with their next generation cloud-based operations support systems (OSS) and business support systems (BSS).

The AWS expansion to certify four new Regions into scope in November 2025 demonstrates our continuous commitment to adhere to the heightened expectations for cloud service providers and extends our global coverage for GSMA-certified infrastructure. With two GSMA-certified Regions in the US, EU, and Asia respectively, customers can now build geo-redundant eSIM solutions to improve their disaster recovery and resiliency posture.

For up-to-date information related to the certification, see the AWS GSMA Compliance Program page.

To learn more about our compliance and security programs, see AWS Compliance Programs. As always, we value your feedback and questions; reach out to the AWS Compliance team through the Contact Us page. If you have feedback about this post, submit comments in the Comments section below.

Michael Murphy

Michael Murphy

Michael is a Compliance Program Manager at AWS where he leads multiple security and privacy initiatives. Michael has over 14 years of experience in information security and holds a master’s degree and a bachelor’s degree in computer engineering from Stevens Institute of Technology. He also holds CISSP, CRISC, CISA, and CISM certifications.

Noah Miller

Noah Miller

Noah is a Compliance Program Manager at AWS and supports multiple security and privacy initiatives within AWS. Noah has 6 years of experience in information security. He has a master’s degree in Cybersecurity Risk Management and a bachelor’s degree in informatics from Indiana University.

Nyef Khan

Nayef Khan

Nayef Khan is a Senior Solutions Architect at AWS in Canada, with over 15 years of experience in security assurance across financial and telecom industries. He is passionate about using cloud technologies to solve real-life customer challenges. Nayef has collaborated with a numerous Telecom customers globally throughout his career, launching industry-first solutions like mobile payments and eSIM. He holds an MBA in Strategic Management from Wilfrid Laurier University, and a bachelor’s degree in Computer Engineering from the University of Waterloo.

The collective thoughts of the interwebz