Mastodon Stories for systemd v259

Post Syndicated from Lennart Poettering original https://0pointer.net/blog/mastodon-stories-for-systemd-v259.html

On Dec 17 we released systemd v259 into the wild.

In the weeks leading up to that release (and since then) I have posted
a series of serieses of posts to Mastodon about key new features in
this release, under the
#systemd259
hash tag. In case you aren’t using Mastodon, but would like to
read up, here’s a list of all 25 posts:

I intend to do a similar series of serieses of posts for the next systemd
release (v260), hence if you haven’t left tech Twitter for Mastodon yet, now is
the opportunity.

My series for v260 will begin in a few weeks most likely, under the
#systemd260
hash tag.

In case you are interested, here is the corresponding blog story for
systemd v258
,
here for
v257
,
and here for
v256
.

Stenberg: No strcpy either

Post Syndicated from jzb original https://lwn.net/Articles/1052355/

Daniel Stenberg has written a blog
post
about the decision to ban the use strcpy()
in curl:

The main challenge with strcpy is that when using it we do not
specify the length of the target buffer nor of the source string. […]

To make sure that the size checks cannot be separated from the copy
itself we introduced a string copy replacement function the other day
that takes the target buffer, target size,
source buffer and source string length as arguments
and only if the copy can be made and the null terminator also fits
there, the operation is done.

Enhance email security using VPC endpoints with Amazon SES Manager

Post Syndicated from Gabrielle Zhou original https://aws.amazon.com/blogs/messaging-and-targeting/enhance-email-security-using-vpc-endpoints-with-amazon-ses-manager/

Organizations managing on-premises email infrastructure face a critical challenge: how to modernize email systems while maintaining strict security and compliance standards. For healthcare providers, financial institutions, and government agencies, email messages often contain sensitive data that must remain on private networks throughout processing.

The virtual private cloud (VPC) endpoint feature of Amazon Simple Email Service (Amazon SES) Mail Manager addresses this challenge by enabling SMTP messages to remain on your private network throughout processing, routing, and compliance logging before final delivery. This post walks you through implementing this solution to securely modernize your email infrastructure.

Consider this scenario: You’re responsible for a healthcare organization’s email infrastructure that processes thousands of patient communications daily. Your on-premises Exchange servers are aging, maintenance costs are climbing, and your organization is moving workloads to AWS. Your security team requires that email processing for sensitive patient communications—including workflow processing, temporary storage, rule-based routing, and compliance logging—remain within private, controlled networks until ready for final delivery. The Amazon SES Mail Manager VPC endpoint feature addresses this requirement by maintaining network-level isolation for email operations from generation through processing, minimizing data exposure, meeting compliance requirements, and providing defense-in-depth security before final message delivery.

This post demonstrates how to implement VPC endpoints with Amazon SES Mail Manager using exercises from the Amazon SES Mail Manager workshop. We show how to configure VPC endpoints, security groups, and ingress endpoints to maintain private network connectivity for your email processing workflows.

Solution overview

Our approach combines AWS services to create a secure, private email infrastructure:

This solution requires your applications to run within a VPC or have established connectivity between your on-premises network and Amazon VPC through AWS Direct Connect or VPN. For guidance on connecting on-premises networks to AWS, refer to Hybrid network connections.

The following diagram illustrates the solution architecture.

The workflow consists of the following steps:

  1. Amazon Elastic Compute Cloud (Amazon EC2) instances running the sender email application on subnet 10.0.0.0/18 connect to the Amazon SES Mail Manager ingress endpoint through a VPC endpoint.
  2. Sender credentials are retrieved securely from Secrets Manager.
  3. AWS KMS decrypts credentials using your managed encryption keys.
  4. Authenticated email traffic flows securely to SES Amazon SES Mail Manager.

Prerequisites

Before beginning your migration, ensure you have the following:

  • AWS account – Use an AWS account with appropriate permissions for creating and managing a VPC, Secrets Manager, AWS KMS, and Amazon SES. Make sure AWS Identity and Access Management (IAM) policies follow least privilege principles.
  • Existing VPC infrastructure – Use a VPC that hosts your applications in the same AWS account and AWS Region as Amazon SES. For more information, see Plan your VPC.
  • Amazon SES configured – Configure Amazon SES in the same Region and AWS account.
  • Network connectivity – Deploy application servers either on premises with network connectivity to your VPC using Direct Connect or VPN, or already running within the VPC.

For this example, we use Linux SMTP commands from an EC2 instance in the VPC to connect to the Amazon SES Mail Manager ingress endpoint through a VPC endpoint on port 587.

Create traffic policy

Create an Amazon SES Mail Manager traffic policy to filter incoming messages by a combination of recipient address, sender IP address range, and TLS protocol version (1.2 or 1.3). For more details about Amazon SES Mail Manager traffic policies, refer to Traffic policies and policy statements. In this example, we use a traffic policy with minimum TLS version of 1.2.

Complete the following steps:

  1. Open the Amazon SES console in the target Region.
  2. In the navigation pane, under SES Mail Manager, choose Traffic policies.
  3. Choose Create traffic policy.
  4. For Policy name, enter a descriptive name, such as first-traffic-policy.
  5. For Default action, choose Deny.
  6. Choose Add new policy statement.
  7. For Allow or deny properties, choose Allow.
  8. For Properties, choose TLS protocol version.
  9. For Operator, choose Minimum version.
  10. For Value, choose TLS 1.2.
  11. Choose Create traffic policy.

Create rule set

Rule sets are containers for an ordered set of rules that determine how the messages are processed. For more information, see Rule sets and rules. In this example, we use the archive rule to archive all emails processed by Amazon SES Mail Manager.

Complete the following steps:

  1. On the Amazon SES console, under Amazon SES Mail Manager in the navigation pane, choose Rule sets.
  2. Choose Create rule set.
  3. Name the rule (for example, first-rule-set) and choose Create rule set.
  4. Choose Create new rule, then choose Create new rule again.
  5. Under Rule settings, name the rule (for example, archive_all).
  6. Under Actions, choose Add new action.
  7. Chose Archive.
  8. Choose Create archive.
  9. Give the archive a name, such as archive_all.
  10. Set a retention period (3 months for testing).
  11. Choose Create archive.

  1. For Archive resource name, choose archive_all.
  2. Choose Save rule set.

Create security group

Complete the following steps to create a security group:

  1. On the Amazon VPC console, under Security in the navigation pane, choose Security groups.
  2. Choose Create security group.
  3. For Security group name, provide a name that uniquely identifies the security group. For this example, we name the security group my-sg-mail-manager.
  4. For Description, describe the purpose of this security group.
  5. For VPC, choose the VPC that hosts your applications.
  6. For Inbound rules, choose Add rule.
  7. For Type, choose SMTP.
  8. For Source, enter the IP range of your private subnet.
  9. Choose Add rule again.
  10. For Port range, enter 587 and the IP range of your private subnet.
  11. Choose Create security group.

Create VPC endpoint

VPC endpoints make it possible to keep your email traffic within your private AWS network. Complete the following steps to create a VPC endpoint:

  1. Open the Amazon VPC console in the target Region.
  2. Under PrivateLink and Lattice in the navigation pane, choose Endpoints.
  3. Choose Create endpoint.
  4. For Name tag, enter an optional tag, such as mm-vpce-auth-ingress-endpoint.
  5. Select AWS services.
  6. For Services, enter mail-manager to search for Amazon SES Mail Manager VPC endpoints.
  7. Select com.amazonaws.us-east-1.mail-manager-smtp.auth.fips.

  1. For VPC, choose the VPC that hosts your applications.
  2. For DNS name, select Enable DNS name
  3. For DNS record IP type, select IPv4.
  4. Under Subnets, select all Availability Zones and choose the subnet ID for each subnet.
  5. For IP type, select IPv4.

  1. For Security groups, select the group my-sg-mail-manager.
  2. Choose Create endpoint.

Create ingress endpoint

Complete the following steps to create an authenticated ingress endpoint using Secrets Manager and AWS KMS:

  1. On the Amazon SES console, under Amazon SES Mail Manager in the navigation pane, choose Ingress endpoints.
  2. Choose Create ingress endpoint.
  3. For Ingress endpoint name, enter a unique name for the ingress endpoint. For this example, we use my-authenticated-ingress-endpoint.
  4. For Type, choose Authenticated.
  5. For Authentication type, choose Secret.
  6. Choose Create new, which will open a new tab.
  7. For Secret type, choose Other type of secret.
  8. Under Key/value pairs, enter password as the key (anything else will cause authentication to fail), then enter a password as the value.
  9. For Encryption Key, choose Add new key, which will open a new tab.
  10. Choose Create key.
  11. Keep the default values for Key type and Key usage and choose Next.

  1. For Alias, enter a unique name for your custom managed key. For this example, we use my-mail-manager-key.
  2. For Description, describe the purpose of the key.
  3. Choose Next.

  1. For Key administrators, choose any users (other than yourself) or roles you want to permit to administer the key, then choose Next.
  2. For Key users, choose any users (other than yourself) or roles you want to permit to use the key, then choose Next.
  3. For Key policy, choose Edit, then enter the following KMS key policy into the key policy JSON text editor at the "statement" level by adding it as an additional statement separated by a comma. Replace the Region and account number with your own.
{
    "Effect": "Allow",
    "Principal": {
        "Service": "ses.amazonaws.com"
    },
    "Action": "kms:Decrypt",
    "Resource": "*",
    "Condition": {
        "StringEquals": {
           "kms:ViaService": "secretsmanager.us-east-1.amazonaws.com",
            "aws:SourceAccount": "000000000000"
        },
        "ArnLike": {
            "aws:SourceArn": "arn:aws:ses:us-east-1:000000000000:mailmanager-ingress-point/*"
        }
    }
}
  1. Choose Next.
  2. Review and choose Finish.
  3. Switch to the Secrets Manager tab and choose the refresh icon.
  4. Choose the KMS key you just created, then choose Next.

  1. For Secret name, provide a unique name for the secret. For this example, we use my-mail-manager-secret.
  2. For Description, describe the purpose for the secret.
  3. For Resource permissions, replace the example JSON code in the editor with the following policy. Replace the Region and the account number with your own.
{
    "Version": "2012-10-17",
    "Id": "Id",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "ses.amazonaws.com"
            },
            "Action": "secretsmanager:GetSecretValue",
            "Resource": "*",
            "Condition": {
                "StringEquals": {
                    "aws:SourceAccount": "000000000000"
                },
                "ArnLike": {
                    "aws:SourceArn": "arn:aws:ses:us-east-1:000000000000:mailmanager-ingress-point/*"
                }
            }
        }
    ]
}
  1. Choose Save, then choose Next.
  2. Configuring automatic rotation is optional. We skip this step and choose Next.
  3. Review and choose Store.
  4. Switch back to the Amazon SES console tab to finish creating the ingress endpoint.
  5. For Secret ARN, choose Refresh list, then choose the secret you just created.
  6. For Rule set, choose first-rule-set.
  7. For Traffic policy, choose first-traffic-policy.
  8. For Network type, select Private.
  9. For VPC endpoint ID, choose mm-vpce-auth-ingress-endpoint.
  10. Choose Create ingress endpoint.

Test configuration

Complete the following steps to test your configuration:

  1. Open the Amazon VPC console in the target Region.
  2. Under PrivateLink and Lattice in the navigation pane, choose Endpoints.
  3. Choose the VPC endpoint ID of mm-vpce-auth-ingress-endpoint to open the details page.
  4. Find the DNS names for the VPC endpoint. The first DNS name on this list is the Regional DNS name of the VPC endpoint; copy this DNS name and save it on a notepad for later use.

  1. Open the Amazon SES console in the target Region.
  2. Under Amazon SES Mail Manager in the navigation pane, choose Ingress endpoints.
  3. Choose my-authenticated-ingress-endpoint.
  4. In the Authentication section, locate the SMTP user name (typically starts with inp-).

  1. Connect to your EC2 instance using SSH.
  2. Use the command line to send an email using the Amazon SES SMTP interface to test the connectivity. Replace the endpoint with the DNS name of the VPC endpoint you copied earlier.

The message 250 OK esllb73q6bd94cnq004ujd544f169sog39bc9ug1 indicates the message was successfully accepted by Amazon SES Mail Manager.

Clean up

When you’re done with this solution, clean up the resources you created including Mail Manager configurations, security groups, VPC endpoints, KMS keys, and Secrets Manager secrets to avoid additional charges.

Conclusion

In this post, we showed how to enhance email security by implementing Amazon SES Mail Manager with VPC endpoints. This solution can help you modernize your email infrastructure while maintaining network-level isolation and meeting enterprise compliance requirements.

To learn more about Amazon SES, see the Amazon SES Developer Guide. For additional security best practices, refer to AWS Best Practices for Security, Identity, & Compliance. To get started using Amazon SES Mail Manager, participate in an Amazon SES Mail Manager workshop event, explore the advanced workflow features of Amazon SES Mail Manager, and consider integrating with your existing monitoring and alerting systems.


About the authors

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1052327/

Security updates have been issued by Debian (openjpeg2, osslsigncode, php-dompdf, and python-django), Fedora (fluidsynth, golang-github-alecthomas-chroma-2, golang-github-evanw-esbuild, golang-github-jwt-5, and opentofu), Mageia (ceph and ruby-rack), and SUSE (anubis, apache2-mod_auth_openidc, dpdk22, kernel, libpng16, and python311-openapi-core).

Годината в 10 точки и едно заключение

Post Syndicated from Bozho original https://blog.bozho.net/blog/4556

Политическата 2025 г. беше дълга и изпълнена със събития. Ще си позволя да направя обзор на вътрешнополитическите събития, подредени хронологично, както и техните първопричини и последствия.

Външнополитическият контекст е важен, външнополитическите лупинги на управляващите – също, но дори без тях, вътрешнополитическата картина остава същата. Може би с уточнението, че вътрешната нестабилност винаги е подхранвана допълнително от външните турбуленции.

Но нашата си системна политическа криза щеше да е факт дори без външните фактори, защото тя е криза не нелегитимното упражняване на публична власт. Тя се усложнява от разломните линии в българското общество по отношение на външната политика, но не те са в нейната основа.

  1. Преговорите за правителство

Годината започна с преговори за правителство, на които освен ГЕРБ, БСП и ИТН, участвахме и ние от Демократична България. Няма да припомням всички подробности освен две: 1) преговорите бяха прекратени едностранно от ГЕРБ, с прессъобщение на 5-ти януари, след като 30 минути по-рано се бяхме разделили с ангажимент за уточняване на часа за следващата среща. 2) в окончателното коалиционно споразумение между трите останали партии бяха премахнати точно точките, които бяха част от санитарния кордон срещу Пеевски. Някои от тях – символни и декларативни, други – много конкретни по отношение на съдебната власт, службите, подслушванията и злоупотребите на прокуратурата в наказателния процес.

Защо беше нужно потвърждение на очевидното за някои, особено след провала на ротацията – че ГЕРБ и Борисов не могат да участват в ограничаване на нелегитимното влияние на Пеевски (или на който и да било друг). Защото това далеч не беше очевидно за широката публика, на която беше внушено, че ние сме политически неблагонадежни – че искаме постове, или че не знаем какво искаме.

Тези преговори бяха риск за нас и понесохме много критика. Все пак държахме те да са публично и да е ясно, че се водят – за разлика от преговорите след нашето изваждане от тях. И смятам, че показахме как трябва да се водят политически преговори – спокойно, културно, но неотстъпчиво за най-важните неща; и поставяйки приоритетите и споразумението преди изобщо въпроса за постовете. По този начин беше частично неутрализиран и последващия разказ, че ГЕРБ са нямали друг избор, освен да изберат Пеевски. За да стане кристално ясно, че изборът на Пеевски за партньор не е на база на политическа логика, а на база на страх от наказателно преследване.

Всичко, което последва в политическата 2025 г. е резултат от това решение тогава – ескалиращата наглост на Пеевски беше неизбежна при отказа на основните партии да го ограничат.

  1. Натискът за еврозоната

В началото на мандата на този кабинет трябваше да се вземе решение дали да се поиска конвергентен доклад, който да позволи влизане в еврозоната. Управляващата коалиция изобщо не беше ентусиазирана – при първото ми участие в Панорама след гласуването на кабинета поставих този въпрос, а Тошко Йорданов каза (по спомен), че България не е готова за еврозоната. В процеса на преговорите БСП също имаха сериозни резерви за еврозоната. А знаците от Министерство на финансите и управляващото мнозинство бяха много обезпокоителни – говореше се за огромна дупка в бюджета (която реално не съществуваше), в опит да се намери публично оправдание за отказа от еврозоната. Неофициално от МФ излизаше информация, че готвеният проект на бюджет е с над 3% дефицит, което би ни дисквалифицирало за еврозоната, а Борисов в няколко излизания пред медиите казваше, че няма да лъжем Брюксел и ще покажем реалния дефицит, което се четеше, че няма да се опитваме да влизаме в еврозоната. В началото на януари мнозинството отхвърли и изменения в Закона за БНБ, които бяха изискване за еврозоната.

На база на тази информация ние предприехме масирана комуникационна офанзива. Във всички свои участия посочвахме отказа на правителството от еврозоната. Всеки ден говорихме и в пленарна зала, и пред медиите в парламента, че правителството отстъпва от този стратегически приоритет.

Накрая конвергентен доклад беше поискан, а бюджетът беше внесен с 3% дефицит. Твърденията за дупката от 18 млрд. лв. се изпариха.

Сега ще слушаме опорните точки кой ни е “вкарал е еврозоната” и как ние сме били в опозиция на еврозоната, но нашата роля беше именно на катализатор на това правилно решение.

  1. Решението на Конституционния съд за изборните резултати

Решението на Конституционния съд от 13-ти март, макар да не промени значително съотношенията в парламента, беше ключово – бяха проверени около 2200 секции (от 12 хиляди), на база на това бяха установени съществени нарушения в доста секции, а при преизчисляването цяла нова парламентарна група влезе в Народното събрание. Решението показа нагледно какви изборни манипулации се правят и от кои партии – най-много гласове бяха надписани на ДПС Ново начало и ГЕРБ. С бюлетини, попълвани от един и същи човек, с дописване на гласове в протоколите и какво ли още не (все неща, които машинното гласуване елиминира).

Решението намали мнозинството на ГЕРБ, БСП, ИТН и АПС на 121 гласа, но то дойде в момент, в който вече беше ясно, че Пеевски не само подкрепя правителството, а и получава повече услуги от мнозинството, отколкото АПС: беше избран Орлин Колев в Конституционния съд, беше направено предложението за “Магазин за хората” в проекта на бюджет, а същият беше подкрепен на първо четене от ДПС-НН.

Трябва да припомним и как се стигна до този резултат – след изборите и обоснованото усещане за масови изборни нарушения, няколко парламентарни групи, в т.ч. ПП-ДБ, оспорихме частично изборите пред Конституционния съд. Списъкът със секции в нашето искане беше най-пълен и беше базиран на различни установени аномалии в данните от изборите. Аномалии, които до голяма степен след това Конституционният съд потвърди, че са изборни нарушения.

  1. Приемането ни в еврозоната

Приемането ни в еврозоната се случи в началото на юли с решения на съответните европейски институции. Но това беше предхождано от няколко събития.

В името на този приоритет, ние (ПП-ДБ) отказахме да участваме във вотове на недоверие до официалните актове на европейските институции, с които България да бъде приета в еврозоната. Това не значеше подкрепа за правителството, но не значеше и че искаме да го сваляме, преди еврозоната да бъде необратима.

След като президентът направи заявка за референдум, имаше нужда, вкл. пред международните партньори, да се покаже ясното мнозинство в българския парламент за еврозоната. Затова премиерът и гуверньорът на БНБ предложиха декларация, която да бъде подписана от всички, за които еврозоната е приоритет. Нашите подписи бяха на тази декларация.

За съжаление смятам, че бяха допуснати грешки при реализацията – в Закона за еврото бяха приети прекалено рискови силови правомощия. В регулаторите (основно КЗК) бяха избрани хора без нужните качества. Информационната кампания не беше адекватна и липсваше в социалните мрежи. Предстои да видим дали всички технически проблеми са решени. Но за всичко това отговорността е на мнозинството и правителството.

  1. Арестите и дългосрочното задържане под стража

В деня на официалното ни приемане в еврозоната през юли, Пеевски реализира своята мръсна операция по задържането на варненския кмет. Много може да се напише за процесуалните способи, чрез които може един обвиняем да бъде държан дълго време в ареста. Но за тези арести трябва да се кажат 5 неща.

1) Пеевски показа, че разполагайки с прокуратурата, разследващия орган (инспекторите от КПК) и съответния административен ръководител на съда чрез контрола си върху ВСС, може да гарантира дългосрочно задържане в ареста;

2) това е демонстрация както към опозицията, така и към партньорите/подчинените в управлението – ако много се отваряте, мога да ви държа в ареста;

3) в изтритите точки от коалиционното споразумение имаше мерки срещу тази злоупотреба, преди още тя да се случи: случайно разпределение при разглеждане на мерки за неотклонение;

4) никой не възразява срещу това да има разследване за корупция – и ако някой е виновен, съдът да реши – но без напълно ненужни задържания в досъдебна фаза, които по европейските стандарти трябва да се прилагат в изключителни случаи;

5) това безобразие беше един от факторите, заради които се натрупа обществено напрежение, довело до масочите протести.

Използването на прокуратурата с политически цели не започна с тези арести, но те бяха кулминацията на процесуалния произвол. Исканията за имунитетите на Кирил, Лена и мен дадоха началото на опита за саморазправа с опозицията. Знаейки, че всичко ще се разпадне в съда, си дадохме имунитетите веднага. Но срещу нас не е имало опит за задържане, което прави летните арести прекомерни дори за самозабравилия се Пеевски и неговия обслужващ персонал в прокуратурата и КПК.

  1. Вот на недоверие за завладяната държава

През септември темата в парламента беше “завладяната държава” – темата на вота на недоверие, който внесохме. Мотивите (80 страници) бяха задълбочено изследване на механизмите на дозавладяване на институциите и на отказа на правителството и мнозинството да противодейства на тези механизми. “Завладяна държава” е термин, който описва държави, чиито институции действат в частна полза, а не в обществена, за каквато са създадени. В мотивите приведохме множество конкретни примери (напр. натиска върху кметове и снимките под герба в каб. 222А, покриване на контрабандата на цигари от МВР в Пловдив, монополизация на продуктови такси) и конкретни имена – Пеевски, Таки, Ковачки.

Предходните вотове на недоверие не бяха сериозни и това стабилизираше управляващите. Те с лекота отбиваха тезите на вносителите на предходните вотове, основно с аргумента, че за няколко месеца няма как да се решат проблеми на няколко десетилетия. С вота на недоверие през септември това не беше така, тъй като фоксът беше върху това как действа и бездейства именно настоящото правителство (основно – в сектори правосъдие и вътрешни работи). И аргументи по същество в защита на кабинета почти нямаше, като изключим опитите на министъра на правосъдието да направи помен с чужда пита, хвалейки с резултати, постигнати на база на работата, свършена от предходните правителства.

Вотът на недоверие включваше и друга голяма тема през годината, стартирала от прокараните от нас изменения в Закона за съдебната власт, с които Сарафов не можеше да бъде избран за редовен главен прокурор и можеше да бъде изпълняващ функциите само 6 месеца, съответно последващото бездействие на изпълнителната власт по отношение на спазването на закона, след като Сарафов остана на поста и след законовия срок, допълвайки картината на завладените институции и на сринатото доверие в съдебната власт.

Във връзка с темата на вота от Да, България (официално с ново ръководство от май месец) формулирахме и т.нар. “План за противодействие и отпор на завладяната държава” с 10 конкретни точки, в които показахме, че не просто стоим и се оплакваме, а планираме и работим за демонтиране на модела.

Благодарение на този вот на недоверие, “завладяната държава” стана устойчив израз в публичния разговор за политика. Този вот на недоверие фокусира нелегитимните инструменти, чрез които се упражнява властта и илюстрира какво конкретно стои зад повтарянето на името на Пеевски, за което често ни обвиняваха. С този вот на недоверие разбирането на завладяната държава се пренесе сред много по-широк кръг хора и смятам, че това също допринесе за протестната енергия.

  1. Местните избори в Пазарджик и превземането на ГЕРБ

Местните избори в Пазарджик бяха сериозен трус в управлението. Мандатоносителят ГЕРБ стана 6-та политическа сила на местни избори в областен град. А Пеевски, с мащабно купуване на гласове под чадъра на МВР, стана първи.

Това беше резултат от много процеси, вкл. процеси по превземане на мрежите на влияние на ГЕРБ по места. Пеевски, през прокуратурата и КПК, тихомълком, придърпваше бизнесмени, близки преди до ГЕРБ. Това изсмуква контролирания и купен вот на ГЕРБ и ги оставя единствено по автентичната им подкрепа, която е недостатъчна за да бъдат първа политическа сила. Това се случи и в Пазарджик. Това беше посочено и в sms-а, който Иво Мирчев изпрати на Борисов. В него се казваше, че всичко това е резултат от отказа да бъде подкрепен санитарния кордон.

След това Борисов излезе и са “самовзриви” (образно казано), казвайки някои истини, които отричаха доскоро. На практика бяха потвърдени мотивите на нашия вот на недоверие, че “кръгове и кръгчета” управляват министерства, а искането му за оставки в МВР заради поголовното купуване на гласове потвърди нашите твърдения, че Пеевски е овладял МВР. Оставки не последваха, а шефа на областната дирекция беше преместен в звеното за подпомагане на министъра. Борисов, обаче, беше “успокоен” с няколко кратки прессъобщения и брифинга на Пеевски, с които му каза, че няма да му позволи да отиде на избори и няма да го направи премиер.

Но местните избори в Пазарджик осветиха процесите на превземане и отслабване на ГЕРБ от страна на Пеевски и невъзможността на ГЕРБ да противодейства на това.

  1. Най-лошият бюджет

В началото на ноември беше внесен най-лошият бюджет от близо 30 години. С него се увеличаваше данъчно-осигурителната тежест – т.е. вземаха се пари от работещите и от бизнеса, предвиждаше се 20 млрд. лв. дълг, за да се дадат големи увеличения на силовите структури и за да се напълнят корупционните касички на Пеевски, вкл. Българската банка за развитие.

Ние бяхме започнали да говорим за бюджета още от началото на октомври. Може би за изненада на всички тогава, от Да, България предложихме голям пакет от разумни десни мерки, които да позволяват стабилни публични финанси. Мерките бяха реформаторски и непопулярни. Включваха ограничаване на корупционния риск, ограничаване на неефективни разходи и стимулиране на бизнес средата. В продължение на 2 месеца тезата ни беше “бюджетът може да стане добър, ако в него има реформи – вкл. нашите реформи”. По този начин показахме ясната алтернатива на правителството. А правителството и мнозинството, със своята арогантност и самодоволство, вкараха бюджет, който дори сами не можеха да защитят. Единствената защита дойде от ДПС “Ново начало”, което беше ясна индикация, че това е бюджетът на Пеевски.

В нормална политическа ситуация, бюджетът е резултат от компромиси. Партията с 66 депутати прави най-малко компромиси, а партията с 29 депутати – повече. Реалността, обаче е, антиполитическа – партията с 29 депутати диктува основните параметри на бюджета, а останалите дори не смеят да го защитят. Бюджетът беше пряко следствие от завладяването на институциите, но също така и инструмент за допълнително финансиране на този корупционен модел от парите на българските граждани и бизнес.

Бюджетът беше числовото изражение на завладяната държава и като такъв изпълни нашата политическа теза с неоспоримо съдържание.

  1. Най-големият протест от 1997 г. досега

Протестът започна като протест срещу бюджета, на който се събраха десетки хиляди протестиращи. Но бюджетът беше просто последната капка, с която чашата на търпението преля. Арогантното завладяване на институциите, неспазването на базово приличие, комисия за 26 секунди, промените в специалните закони за службите, с които те да бъдат дадени на Пеевски, продължаващото узурпиране на властта от Сарафов и продължаващите злоупотреби на КПК, натътрузването на Пеевски върху всяка тема, анонса за държавата с “главно Д” и безобразното поведение на депутатите на Ново начало. Всичко това създаде среда, в която протестите срещу Сарафов и незаконните арести, протестите за достойно заплащане на младите лекари и недоволството от бюджета, се сляха в една неудържима вълна от гняв.

След няколко неадекватни маневри (“ще го изтеглим, “няма да го изтеглим”, “това е протест на работодатели”, “тези хора не знаят какво искат”, “ще го изтеглим, ама ще е почти същия”), на 10.12. по площадите в цялата страна излязоха вероятно над 200 хил. души. Освен над 100 хил. на жълтите павета, имаше протести в десетки градове – дори в такива, в които никога е нямало протести, дори през 1997 г.

Контрапротестите, организирани от Пеевски, бяха гротеска на гърба на бедни и онеправдани хора, докарани почти насила по площадите. Това добави към обществения гняв, заедно с опита да бъдат омаловажени протестите в началото.

На протестите имаше всякакви хора с всякакви идеи. Но със сигурност това не бяха антиевропейски протести, не бяха срещу еврото. Бяха протести срещу модела на завладяната държава, олицетворяван от Пеевски и Борисов и тяхното взаимодействие.

Важен елемент от протестната енергия беше и включването на малцинствата, които Пеевски се опита да “загради”, но те му казаха, че не им е никакъв. Демонополизирането на етническия вот продължи да бъде тема и след края на политическия сезон – явно Пеевски и Борисов са изнервени от тези тенденции.

Протестите бяха мирни, а опитите да бъдат компрометирани с внедряване на провокатори и неадекватна реакция на МВР, не бяха успешни. Това им даде още по-голяма тежест и легитимност. И изходът беше неизбежен.

Но протестът не изчезна и след оставката, което означава, че има гражданска енергия за промени. И за противопоставяне на безобразията и преяждането с власт, вкл. на уволненията на неудобни журналисти.

  1. Оставката на правителството

Когато насред декемврийския студ броят на протестиращите срещу теб расте, а не намалява, политическата логика изисква оставка. Защото явно си счупи нещо толкова сериозно, че си загубил легитимност. Това е ефектът “Пеевски” – до каквото и да се допре, го делегитимира.

Оставката на правителството е значим успех за протеста, който акумулира толкова гражданска подкрепа и енергия, че оставането на власт щеше да бъде напук на обществените настроения, а това винаги има катастрофални резултати.

Изглежда оставката не беше по вкуса на Пеевски, защото той искаше да се възползва от контрола си върху правителството 4 години. Пеевски и неговите говорители обясняваха цяла година, че повече правителства няма да падат след протести. И ето, че площадът ги опроверга, слагайки санитарния кордон, който мнозинството в парламента го беше страх да сложи в началото на годината.

А сега накъде?

Годината затвори един цикъл – от отказа за изолиране на Пеевски от страна на мнозинството в парламента, до неизбежния обществен взрив в резултат на този отказ.

Геополитическият контекст се променя много динамично и ще предстоят трудни решения. Ще има опити за подкопаване на бъдещи общи европейски позиции по ключови геостратегически въпроси. България трябва да бъде силен глас за общата европейска политика в сферата на сигурността и отбраната.

В началото на 2026 г. предстоят избори, на които ние ще трябва да положим всички усилия, за да убедим хората, излезли на протест и хората, които подкрепяха протеста, че техният политически инструмент за демонтиране на модела на завладяната държава сме ние. Трябва да убедим хората в това, че ние сме най-добре подготвени и сме най-решителни да направим най-малко следното:

  1. Да демонтираме корупционния модел на управление
  2. Да гарантираме европейската принадлежност на страната в сложния геополитически контекст
  3. Да ограничим проникването на руско и на всякакво друго зловредно влияние
  4. Да намалим административната тежест и тормоза върху бизнеса
  5. Да запазим данъчните и осигурителните ставки, правейки необходимите реформи в публичните системи

Всички тези приоритет и степента, в която ще можем да ги изпълняваме, зависят от изборите и изборния резултат. Протестите и оставката са само началото. Поредно начало, което този път трябва да доведем докрай, въпреки всички неизбежни трудности по пътя.

През 2026 отново българските граждани ще решават.

 

Материалът Годината в 10 точки и едно заключение е публикуван за пръв път на БЛОГодаря.

Graham: [KDE] Highlights from 2025

Post Syndicated from corbet original https://lwn.net/Articles/1052241/

Nate Graham looks
back at how 2025 went
for the KDE project.

Today Plasma is the default desktop environment in a bunch of the
hottest new gaming-focused distros, including Bazzite, CachyOS,
Garuda, Nobara, and of course SteamOS on Valve’s gaming
devices. Fedora’s Plasma edition was also promoted to co-equal
status with the GNOME edition, and Asahi Linux — the single
practical option for Linux on newer Macs — only supports KDE
Plasma. Parrot Linux recently switched to Plasma by default,
too. And Plasma remains the default on old standbys like
EndeavourOS, Manjaro, NixOS, OpenMandriva, Slackware and TuxedoOS —
which ships on all devices sold by Tuxedo Computers!

What’s New in Rapid7 Products & Services: H2 2025 in Review

Post Syndicated from Margaret Wei original https://www.rapid7.com/blog/post/pt-whats-new-rapid7-products-services-h2-2025-review-mdr-siem-eap

Over the last six months we’ve delivered significant advancements across the Command Platform, as well as received recognition as a Leader in Exposure Management and Managed Detection and Response (MDR) analyst reports. From launching new AI-driven capabilities – including our new next-gen SIEM Incident Command – to introducing real-time visibility into organizational risk with enhanced dashboarding, we continued to innovate in ways that support faster, more confident decision making. Explore the highlights of what we’ve been up to below.

Exposure Management: Prioritize risk across your attack surface

Rapid7 named a Leader in the 2025 Gartner® Magic Quadrant™ for Exposure Assessment Platforms

Rapid7 was recognized as a Leader in the inaugural 2025 Gartner® Magic Quadrant™ for Exposure Assessment Platforms (EAP). We believe this reflects our ability to help customers continuously understand, prioritize, and reduce risk across their hybrid environments. Exposure Command brings unified visibility, attacker-aware prioritization, and guided remediation together in one platform, enabling teams to make faster, more confident decisions with validated, business-aligned risk insights. Check out our recent blog post to learn more.

Remediate vulnerabilities faster with AI-generated Risk Intelligence

Prioritizing remediation is difficult when teams are flooded with CVEs and lack actionable context about real-world risk. We introduced AI-generated risk intelligence within Remediation Hub to help teams focus on the vulnerabilities that matter most and drive faster, more consistent risk reduction by distilling exploitability, business impact, toxic combinations, and patchability into clear summaries and guided actions. Check out our recent blog post to learn more.

⠀

Rapid7-AI-Generated-Remediation-Summary-Remediation-Hub.png
AI-generated Remediation Summary in Remediation Hub

Gain real-time visibility and communicate progress with the Exposure Management Dashboard

To effectively plan, track, and communicate exposure reduction, teams need a clear, real-time view of their security posture. The new Exposure Management Dashboard provides this view with an at-a-glance snapshot of asset coverage, exposure trends, and remediation progress — ideal for quarterly planning cycles and board-level reporting. Exportable views make it easy to justify investment decisions, demonstrate measurable improvements, and show how tool consolidation is strengthening your security program. Learn more in our recent blog.

⠀

Rapid7-Exposure-Management-Dashboard.png
Exposure Management Dashboard, built to give you a real-time view of organizational risk

Validate real cloud exposures with Public Exposure Validation

When cloud configurations drift or controls degrade, it’s critical to know which assets are actually exposed to the public internet. Public Exposure Validation confirms externally reachable cloud resources using real external scans, reducing noise and eliminating theoretical findings.

Teams gain clearer visibility into true attack paths, shorten investigation cycles, and validate that remediation efforts are closing real gaps. This strengthens their posture with evidence, not assumptions. Learn more in our recent blog.

Keep external visibility accurate with Dynamic EASM Discovery

Accurate external discovery depends on seeds that reflect what’s truly exposed. But static seed lists can quickly become outdated. Dynamic EASM Discovery continuously pulls domains and public IP ranges from authoritative sources such as MarkMonitor, NetBox, and Rapid7 AppSec, ensuring your discovery scope stays current without manual upkeep.

This eliminates blind spots, keeps external inventories aligned with real-world change, and strengthens CTEM outcomes by grounding scope, discovery, and prioritization in real-time data rather than spreadsheets. See our recent blog on Dynamic EASM Discovery to learn more.

Detection and Response: Transform your SOC operations

Rapid7 named a Leader in the 2025 Frost Radar™ for Managed Detection and Response

In addition to being named a Leader in Exposure Assessment, we’re proud to share that we have also received this recognition for Managed Detection and Response with Frost & Sullivan recognizing Rapid7 as a Leader in the 2025 Frost Radar™ for MDR, based on innovation and growth in a field of 120 evaluated vendors. The report highlights:

  • Rapid7’s AI-driven triage accuracy of 99.93%, which helps security teams close benign alerts and reclaim 200+ SOC hours per week

  • Our unified platform combining MDR with exposure management, threat hunting, and active remediation

  • 180+ third-party integrations across endpoint, network, cloud, and identity

This recognition reinforces Rapid7’s commitment to proactive, outcome-driven security and delivering continuous innovation, transparent AI, and measurable value to customers. Learn more.

IDC publishes its Business Value of Rapid7 MDR Study

IDC recently published its Business Value of Rapid7 MDR study, highlighting how customers can achieve a 422% three-year ROI, a 5-month payback period, and an impressive range of additional security outcomes delivered through Rapid7 Managed Detection and Response. The study found that Rapid7 MDR significantly reduced the chances of major security incidents and improved the speed to identify threats for customers – translating to both risk reduction and cost savings. Learn more about the study in our blog or download the full report.

New third party event sources available for Rapid7 SOC management

For organizations to stay secure, they need visibility across their entire attack surface. With recent third party event source expansions, our Rapid7 SOC can now manage PAN Cortex XDR, Okta Identity, and Google Security Command Center alerts as a part of our MDR and Managed Threat Complete offerings. This reinforces our defense-in-depth approach, in which Rapid7 collects, correlates, and maps native and third party telemetry to the MITRE ATT&CK framework, providing expanded visibility and greater protection across your entire attack surface. Learn more about SOC-supported third-party event sources here.

Introducing Incident Command

In July we announced our new AI-powered, next-gen SIEM, Incident Command. Designed to transform how security teams manage investigations and response, Incident Command automates manual tasks and guides analysts through complex workflows — accelerating triage, providing real-time recommended actions, and unifying critical context across alerts and incidents. 

Backed with generative AI, our next-gen SIEM helps teams reduce mean time to respond (MTTR), improve consistency, and scale security operations without adding headcount. Learn more about what Incident Command can do for your team here.

⠀

Rapid7-Incident-Command-Home-Page.png
The Incident Command Home Page brings critical SOC analyst tools together into a singular, actionable view

Rapid7 recognized for the 7th consecutive year in Gartner® Magic Quadrant™ for SIEM

Rapid7 has been recognized in the 2025 Gartner® Magic Quadrant™ for Security Information and Event Management (SIEM), proof of our continued focus on helping security teams work smarter, respond faster, and stay ahead of evolving threats. This year’s report explores how SIEMs are transforming to meet the demands of modern, hybrid environments with greater automation, stronger analytics, and improved efficiency across security operations. We believe our inclusion underscores our commitment to delivering speed, transparency, and extensibility with our next-gen SIEM. Read the report for more insights.

InsightGovCloud: Trusted security for federal agencies

Rapid7 achieves FedRAMP authorization for InsightGovCloud platform

Our achievement of FedRAMP Authorization to Operate (ATO) underscores our commitment to delivering secure, trusted cloud security solutions for federal agencies. The InsightGovCloud Platform provides government customers with vetted capabilities for vulnerability management, cloud security posture, and threat detection, meeting the rigorous standards required to protect sensitive federal environments, while enabling faster, more efficient security operations. Learn more.

Rapid7 Labs: Uplevel your defenses with our latest cybersecurity intelligence and research findings

New research: Q3 2025 Threat Landscape Report

Our Threat Landscape Report provides an analysis of global adversary behavior drawn from Rapid7’s MDR operations, vulnerability intelligence, and threat research. Our latest Q3 2025 report outlines key trends that are shaping today’s threat environment – including AI-assisted attacks and the rapid operationalization of new vulnerabilities – offering clear guidance to help security teams anticipate emerging risks and strengthen defenses in an increasingly fast-evolving landscape. Read the report here.

Emergent threat response: Real-time guidance for critical threats

Rapid7’s Emergent Threat Response (ETR) program from Rapid7 Labs delivers fast, expert analysis and first-rate security content for the highest-priority security threats. In H2 2025, Rapid7’s ETR team provided expert analysis, content, and mitigation guidance for a variety of notable vulnerabilities, including:

Follow along here to see the latest emergent threat guidance from our team.

Technical assessments of CVEs in AttackerKB

Rapid7 researchers also publish additional vulnerability assessments in AttackerKB to help customers and the community understand and prioritize notable CVEs. Notable contributions from the back-half of 2025 include: 

Stay tuned for more!

As always, we’re continuing to work on exciting product enhancements and releases throughout the year. Keep an eye on our blog and release notes as we continue to highlight the latest in product and service investments at Rapid7.

MongoBleed CVE-2025-14847: Critical Memory Leak in MongoDB Allowing Attackers to Extract Sensitive Data

Post Syndicated from Rapid7 original https://www.rapid7.com/blog/post/etr-mongobleed-cve-2025-1484-critical-memory-leak-in-mongodb-allowing-attackers-to-extract-sensitive-data

Overview

On December 19, 2025, MongoDB Inc. disclosed a critical new vulnerability, CVE-2025-14847, which has since been dubbed MongoBleed. This vulnerability is a high-severity unauthenticated memory leak affecting MongoDB, one of the world’s most popular document-oriented databases. While initially identified as a data exposure flaw, the severity is underscored by the fact that it allows attackers to bypass authentication entirely to extract sensitive information directly from server memory. On December 26, 2025, public proof-of-concept (PoC) exploit code was published and on December 29th, 2025 exploitation in-the-wild has been confirmed.

While CVE-2025-14847 is rated as a high-severity vulnerability, CVSS 8.7, its impact is critical. Successful exploitation allows a remote, unauthenticated attacker to “bleed” uninitialized heap memory from the database server by manipulating Zlib-compressed network packets. This memory often contains high-value secrets such as cleartext credentials, authentication tokens, and sensitive customer data from other concurrent sessions. Because the vulnerability returns “uninitialized heap memory,” an attacker cannot target specific credentials or data records with precision; they must instead rely on repeated exploitation attempts and chance to capture sensitive information.

The vulnerability specifically affects MongoDB servers configured to use the Zlib compression algorithm for network messages, which is a common configuration in many production environments. It affects a wide range of versions, including the 4.4, 5.0, 6.0, 7.0, and 8.0 branches. Older, End-of-Life (EOL) versions are also believed to be vulnerable but will not receive official patches, leaving users of legacy systems at significant continued risk.

As of this writing, the public PoC has been successfully verified by Rapid7 Labs. Unlike scenarios where valid exploits are initially scarce, the exploit for MongoBleed is functional and reliable.

Organizations running self-managed MongoDB instances are urged to remediate this vulnerability on an urgent basis, outside of normal patch cycles. Given the nature of the leak, simply patching is insufficient; organizations are advised to also rotate all database and application credentials that may have been exposed prior to remediation.

Mitigation guidance

CVE-2025-14847 affects a wide range of versions, including the 4.4, 5.0, 6.0, 7.0, and 8.0 branches. Older, End-of-Life (EOL) versions are also believed to be vulnerable but will not receive official patches, leaving users of legacy systems at significant continued risk. Organizations managing their own MongoDB instances should prioritize upgrading to the fixed versions released by the vendor (e.g., 8.0.4, 7.0.16, 6.0.20, etc.) immediately. This is the only complete remediation for the vulnerability. 

If an immediate upgrade is not feasible, or if the organization is running an End-of-Life (EOL) version that will not receive a patch, the risk can be effectively mitigated by disabling the Zlib network compressor in the server configuration. This prevents the specific memory allocation path used by the exploit.

In addition, because CVE-2025-14847 allows for the exfiltration of credentials and session tokens from server memory, patching alone is insufficient to ensure security. Administrators should assume that any secrets residing in the database memory prior to patching may have been compromised; therefore, all database passwords, API keys, and application secrets should be rotated immediately after the vulnerability is remediated. 

Rapid7 customers

Exposure Command, InsightVM, and Nexpose

Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2025-14847 with a vulnerability check expected to be available in today’s (Dec 29) content release.

Intelligence Hub

Customers leveraging Rapid7’s Intelligence Hub can track the latest developments surrounding CVE-2025-14847, including a Suricata rule. 

Rapid7 observations

Rapid7 Labs has become aware of a new exploitation tool that streamlines the extraction of sensitive data from vulnerable MongoDB instances. This utility introduces a graphical user interface that allows an attacker to either batch-dump 10MB of memory or monitor the extraction process via a live visual feed. Rapid7 Labs has confirmed the tool operates as described, as demonstrated in the video below.

Click to view in new tab

Detection and Hunting

Velociraptor 

Velociraptor published a Linux.Detection.CVE202514847.MongoBleed hunting artifact written by Eric Capuano designed to detect indicators related to CVE-2025-14847 memory leakage activity. This artifact enables defenders to proactively identify suspicious network or process behaviors consistent with mangled Zlib protocol abuse.

Updates

  • December 29, 2025: Initial publication

  • December 29, 2025: “Rapid7 Observations” section added with video

  • December 29, 2025: Added exploitation confirmation

Водещият твърде много питаше

Post Syndicated from Тоест original https://www.toest.bg/vodeshtiyat-tvurde-mnogo-pitashe/

Водещият твърде много питаше

Ние, журналистите от:

  • Actualno.com
  • „Булевард България“
  • Gospodari.com
  • Gramofona.com
  • „Дарик радио“
  • „Ден“
  • „Дневник“
  • „Дупница нюз“
  • „За истината“
  • „Икономически живот“
  • „Капитал“
  • „Клуб Z“
  • „Маргиналия“
  • Mediapool.bg
  • „Момичетата от града“
  • OFFNews
  • „Отзвук“
  • „Под тепето“
  • „Радиан“
  • „Сакар нюз“
  • „Сега“
  • „Тоест“
  • zagabrovo.bg
  • EUalive.bg и EUalive.net
  • Metrocast

Изразяваме своята подкрепа към колегите, свалени от ефир след политически натиск заради неудобни въпроси. Като част от подкрепата в медиите започна кампания „Водещият твърде много питаше“.

В последния ни бюлетин за 2025 г. дежурната редакторка Боряна Телбис написа: 

Ще се превърне ли Мария Цънцарова от водеща на сутрешен блок в поредното празно столче, зависи от степента на наглост на опразнителите на столчета, но в голяма степен и от обществената и най-вече от гилдийната непримиримост по темата. 

Седмица по-късно тази гилдийна непримиримост е факт и от „Тоест“ с искрена радост се присъединяваме към инициативата.

Ако други колеги и медии искат да се включат в кампанията, моля, пишете на contact[@]toest.bg, за да изпратим материалите.

Are We Ready to Be Governed by Artificial Intelligence?

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2025/12/are-we-ready-to-be-governed-by-artificial-intelligence.html

Artificial Intelligence (AI) overlords are a common trope in science-fiction dystopias, but the reality looks much more prosaic. The technologies of artificial intelligence are already pervading many aspects of democratic government, affecting our lives in ways both large and small. This has occurred largely without our notice or consent. The result is a government incrementally transformed by AI rather than the singular technological overlord of the big screen.

Let us begin with the executive branch. One of the most important functions of this branch of government is to administer the law, including the human services on which so many Americans rely. Many of these programs have long been operated by a mix of humans and machines, even if not previously using modern AI tools such as Large Language Models.

A salient example is healthcare, where private insurers make widespread use of algorithms to review, approve, and deny coverage, even for recipients of public benefits like Medicare. While Biden-era guidance from the Centers for Medicare and Medicaid Services (CMS) largely blesses this use of AI by Medicare Advantage operators, the practice of overriding the medical care recommendations made by physicians raises profound ethical questions, with life and death implications for about thirty million Americans today.

This April, the Trump administration reversed many administrative guardrails on AI, relieving Medicare Advantage plans from the obligation to avoid AI-enabled patient discrimination. This month, the Trump administration took a step further. CMS rolled out an aggressive new program that financially rewards vendors that leverage AI to reject rapidly prior authorization for "wasteful" physician or provider-requested medical services. The same month, the Trump administration also issued an executive order limiting the abilities of states to put consumer and patient protections around the use of AI.

This shows both growing confidence in AI’s efficiency and a deliberate choice to benefit from it without restricting its possible harms. Critics of the CMS program have characterized it as effectively establishing a bounty on denying care; AI—in this case—is being used to serve a ministerial function in applying that policy. But AI could equally be used to automate a different policy objective, such as minimizing the time required to approve pre-authorizations for necessary services or to minimize the effort required of providers to achieve authorization.

Next up is the judiciary. Setting aside concerns about activist judges and court overreach, jurists are not supposed to decide what law is. The function of judges and courts is to interpret the law written by others. Just as jurists have long turned to dictionaries and expert witnesses for assistance in their interpretation, AI has already emerged as a tool used by judges to infer legislative intent and decide on cases. In 2023, a Colombian judge was the first publicly to use AI to help make a ruling. The first known American federal example came a year later when United States Circuit Judge Kevin Newsom began using AI in his jurisprudence, to provide second "opinions" on the plain language meaning of words in statute. A District of Columbia Court of Appeals similarly used ChatGPT in 2025 to deliver an interpretation of what common knowledge is. And there are more examples from Latin America, the United Kingdom, India, and beyond.

Given that these examples are likely merely the tip of the iceberg, it is also important to remember that any judge can unilaterally choose to consult an AI while drafting his opinions, just as he may choose to consult other human beings, and a judge may be under no obligation to disclose when he does.

This is not necessarily a bad thing. AI has the ability to replace humans but also to augment human capabilities, which may significantly expand human agency. Whether the results are good or otherwise depends on many factors. These include the application and its situation, the characteristics and performance of the AI model, and the characteristics and performance of the humans it augments or replaces. This general model applies to the use of AI in the judiciary.

Each application of AI legitimately needs to be considered in its own context, but certain principles should apply in all uses of AI in democratic contexts. First and foremost, we argue, AI should be applied in ways that decentralize rather than concentrate power. It should be used to empower individual human actors rather than automating the decision-making of a central authority. We are open to independent judges selecting and leveraging AI models as tools in their own jurisprudence, but we remain concerned about Big Tech companies building and operating a dominant AI product that becomes widely used throughout the judiciary.

This principle brings us to the legislature. Policymakers worldwide are already using AI in many aspects of lawmaking. In 2023, the first law written entirely by AI was passed in Brazil. Within a year, the French government had produced its own AI model tailored to help the Parliament with the consideration of amendments. By the end of that year, the use of AI in legislative offices had become widespread enough that twenty percent of state-level staffers in the United States reported using it, and another forty percent were considering it.

These legislative members and staffers, collectively, face a significant choice: to wield AI in a way that concentrates or distributes power. If legislative offices use AI primarily to encode the policy prescriptions of party leadership or powerful interest groups, then they will effectively cede their own power to those central authorities. AI here serves only as a tool enabling that handover.

On the other hand, if legislative offices use AI to amplify their capacity to express and advocate for the policy positions of their principals—the elected representatives—they can strengthen their role in government. Additionally, AI can help them scale their ability to listen to many voices and synthesize input from their constituents, making it a powerful tool for better realizing democracy. We may prefer a legislator who translates his principles into the technical components and legislative language of bills with the aid of a trustworthy AI tool executing under his exclusive control rather than with the aid of lobbyists executing under the control of a corporate patron.

Examples from around the globe demonstrate how legislatures can use AI as tools for tapping into constituent feedback to drive policymaking. The European civic technology organization Make.org is organizing large-scale digital consultations on topics such as European peace and defense. The Scottish Parliament is funding the development of open civic deliberation tools such as Comhairle to help scale civic participation in policymaking. And Japanese Diet member Takahiro Anno and his party Team Mirai are showing how political innovators can build purpose-fit applications of AI to engage with voters.

AI is a power-enhancing technology. Whether it is used by a judge, a legislator, or a government agency, it enhances an entity’s ability to shape the world. This is both its greatest strength and its biggest danger. In the hands of someone who wants more democracy, AI will help that person. In the hands of a society that wants to distribute power, AI can help to execute that. But, in the hands of another person, or another society, bent on centralization, concentration of power, or authoritarianism, it can also be applied toward those ends.

We are not going to be fully governed by AI anytime soon, but we are already being governed with AI—and more is coming. Our challenge in these years is more a social than a technological one: to ensure that those doing the governing are doing so in the service of democracy.

This essay was written with Nathan E. Sanders, and originally appeared in Merion West.

The collective thoughts of the interwebz