SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums

Post Syndicated from Milan Spinka original https://www.rapid7.com/blog/post/tr-santastealer-is-coming-to-town-a-new-ambitious-infostealer-advertised-on-underground-forums

Summary

Rapid7 Labs has identified a new malware-as-a-service information stealer being actively promoted through Telegram channels and on underground hacker forums. The stealer is advertised under the name “SantaStealer” and is planned to be released before the end of 2025. Open source intelligence suggests that it recently underwent a rebranding from the name “BluelineStealer.”

The malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of applications, and aims to operate entirely in-memory to avoid file-based detection. Stolen data is then compressed, split into 10 MB chunks, and sent to a C2 server over unencrypted HTTP.

While the stealer is advertised as “fully written in C”, featuring a “custom C polymorphic engine” and being “fully undetected,” Rapid7 has found unobfuscated and unstripped SantaStealer samples that allow for an in-depth analysis. These samples can shed more light on this malware’s true level of sophistication.

Discovery

In early December 2025, Rapid7 identified a Windows executable triggering a generic infostealer detection rule, which we usually see triggered by samples from the Raccoon stealer family. Initial inspection of the sample (SHA-256 beginning with 1a27…) revealed a 64-bit DLL with over 500 exported symbols (all bearing highly descriptive names such as “payload_main”, “check_antivm” or “browser_names”) and a plethora of unencrypted strings that clearly hinted at credential-stealing capabilities.

While it is not clear why the malware authors chose to build a DLL, or how the stealer payload was to be invoked by a potential stager, this choice had the (presumably unintended) effect of including the name of every single function and global variable not declared as static in the executable’s export directory. Even better, this includes symbols from statically linked libraries, which we can thus identify with minimal effort.

The statically linked libraries in this particular DLL include:

  • cJSON, an “ultralightweight JSON parser”
  • miniz, a “single C source file zlib-replacement library”
  • sqlite3, the C library for interfacing with SQLite v3

Another pair of exported symbols in the DLL are named notes_config_size and notes_config_data. These point to a string containing the JSON-encoded stealer configuration, which contains, among other things, a banner (“watermark”) with Unicode art spelling “SANTA STEALER” and a link to the stealer Telegram channel, t[.]me/SantaStealer.

1-config-json.png

Figure 1: A preview of the stealer’s configuration

2-tg_screen.png

Figure 2: A Telegram message from November 25th advertising the rebranded SantaStealer

3-tg_screen2.png

Figure 3: A Telegram message announcing the rebranding and expected release schedule

Visiting SantaStealer’s Telegram channel, we observed the affiliate web panel, where we were able to register an account and access more information provided by the operators, such as a list of features, the pricing model, or the various build configuration options. This allowed us to cross-correlate information from the panel with the configuration observed in samples, and get a basic idea of the ongoing evolution of the stealer.

Apart from Telegram, the stealer can be found advertised also on the Lolz hacker forum at lolz[.]live/santa/. The use of this Russian-speaking forum, the top-level domain name of the web panel bearing the country code of the Soviet Union (su), and the ability to configure the stealer not to target Russian-speaking victims (described later) hints at Russian citizenship of the operators — not at all unusual on the infostealer market.

4-webpanel-features.png

Figure 4: A list of features advertised in the web panel

As the above screenshot illustrates, the stealer operators have ambitious plans, boasting anti-analysis techniques, antivirus software bypasses, and deployment in government agencies or complex corporate networks. This is reflected in the pricing model, where a basic variant is advertised for $175 per month, and a premium variant is valued at $300 per month, as captured in the following screenshot.

5-webpanel-pricing.png

Figure 5: Pricing model for SantaStealer (web panel)

In contrast to these claims, the samples we have seen until now are far from undetectable, or in any way difficult to analyze. While it is possible that the threat actor behind SantaStealer is still developing some of the mentioned anti-analysis or anti-AV techniques, having samples leaked before the malware is ready for production use — complete with symbol names and unencrypted strings — is a clumsy mistake likely thwarting much of the effort put into its development and hinting at poor operational security of the threat actor(s).

Interestingly, the web panel includes functionality to “scan files for malware” (i.e. check whether a file is being detected or not). While the panel assures the affiliate user that no files are shared and full anonymity is guaranteed, one may have doubts about whether this is truly the case.

6-webpanel-scan.png

Figure 6: Web panel allows to scan files for malware.

Some of the build configuration options within the web panel are shown in Figures 7 through 9.

7-webpanel-build.png

Figure 7: SantaStealer build configuration

8-webpanel-build2.png

Figure 8: More SantaStealer build configuration options

9-webpanel-build3.png

Figure 9: SantaStealer build configuration options, including CIS countries detection

One final aspect worth pointing out is that, rather unusually, the decision whether to target countries in the Commonwealth of Independent States (CIS) is seemingly left up to the buyer and is not hardcoded, as is often the case with commercial infostealers.

Technical analysis of SantaStealer

Having read the advertisement of SantaStealer’s capabilities by the developers, one might be interested in seeing how they are implemented on a technical level. Here, we will explore one of the EXE samples (SHA-256 beginning with 926a…), as attempts at executing the DLL builds with rundll32.exe ran into issues with the C runtime initialization. However, the DLL builds (such as SHA-256 beginning with 1a27…) are still useful for static analysis and cross-referencing with the EXE.

At the moment, detecting and tracking these payloads is straightforward, due to the fact that both the malware configuration and the C2 server IP address are embedded in the executable in plain text. However, if SantaStealer indeed does turn out to be competitive and implements some form of encryption, obfuscation, or anti-analysis techniques (as seen with Lumma or Vidar) these tasks may become less trivial for the analyst. A deeper understanding of the patterns and methods utilized by SantaStealer may be beneficial.

10-send-upload-chunk.png

Figure 10: Code in the send_upload_chunk exported function references plaintext strings

The user-defined entry point in the executable corresponds to the payload_main DLL export. Within this function, the stealer first checks the anti_cis and exec_delay_seconds values from the embedded config and behaves accordingly. If the CIS check is enabled and a Russian keyboard layout is detected using the GetKeyboardLayoutList API, the stealer drops an empty file named “CIS” and ends its execution. Otherwise, SantaStealer waits for the configured number of seconds before calling functions named check_antivm, payload_credentials, create_memory_based_log and creating a thread running the routine named ThreadPayload1 in the DLL exports.

The anti-VM function is self-explanatory, but its implementation differs across samples, hinting at the ongoing development of the stealer. One sample checks for blacklisted processes (by hashing the names of running process executables using a custom rolling checksum and searching for them in a blacklist), suspicious computer names (using the same method) and an “analysis environment,” which is just a hard-coded blacklist of working directories, like “C:\analysis” and similar. Another sample checks the number of running processes, the system uptime, the presence of a VirtualBox service (by means of a call to OpenServiceA with “VBoxGuest”) and finally performs a time-based debugger check. In either case, if a VM or debugger is detected, the stealer ends its execution.

Next, payload_credentials attempts to steal browser credentials, including passwords, cookies, and saved credit cards. For Chromium-based browsers, this involves bypassing a mechanism known as AppBound Encryption (ABE). For this purpose, SantaStealer embeds an additional executable, either as a resource or directly in section data, which is either dropped to disk and executed (screenshot below), or loaded and executed in-memory, depending on the sample.

11-chromelevator.png

Figure 11: Execution of an embedded executable specialized in browser hijacking

The extracted executable, in turn, contains an encrypted DLL in its resources, which is decrypted using two consecutive invocations of ChaCha20 with two distinct pairs of 32-byte key and 12-byte nonce. This DLL exports functions called ChromeElevator_Initialize, ChromeElevator_ProcessAllBrowsers and ChromeElevator_Cleanup, which are called by the executable in that order. Based on the symbol naming, as well as usage of ChaCha20 encryption for obfuscation and presence of many recognizable strings, we assess with moderate confidence that this executable and DLL are heavily based on code from the ChromeElevator project (https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption), which employs direct syscall-based reflective process hollowing to inject code into the target browser. Hijacking the security context of a legitimate browser process this way allows the attacker to decrypt AppBound encryption keys and thereby decrypt stored credentials.

12-chromelevator-memory.png

Figure 12: The embedded EXE decrypts and loads a DLL in-memory and calls its exports.

The next function called from main, create_memory_based_log, demonstrates the modular design of the stealer. For each included module, it creates a thread running the module_thread routine with an incremented numerical ID for that module, starting at 0. It then waits for 45 seconds before joining all thread handles and writing all files collected in-memory into a ZIP file named “Log.zip” in the TEMP directory.

The module_thread routine simply takes the index it was passed as parameter and calls a handler function at that index in a global table, for some reason called memory_generators in the DLL. The module function takes only a single output parameter, which is the number of files it collected. In the so helpfully annotated DLL build, we can see 14 different modules. Besides generic modules for reading environment variables, taking screenshots, or grabbing documents and notes, there are specialized modules for stealing data from the Telegram desktop application, Discord, Steam, as well as browser extensions, histories and passwords.

13-module-fns.png

Figure 13: A list of named module functions in a SantaStealer sample

Finally, after all the files have been collected, ThreadPayload1 is run in a thread. It sleeps for 15 seconds and then calls payload_send, which in turn calls send_zip_from_memory_0, which splits the ZIP into 10 MB chunks that are uploaded using send_upload_chunk.

The file chunks are exfiltrated over plain HTTP to an /upload endpoint on a hard-coded C2 IP address on port 6767, with only a couple special headers:

User-Agent: upload
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary[...]
auth: [...]
w: [...]
complete: true (only on final request)

The auth header appears to be a unique build ID, and w is likely the optional “tag” used to distinguish between campaigns or “traffic sources”, as is mentioned in the features.

Conclusion

The SantaStealer malware is in active development, set to release sometime in the remainder of this month or in early 2026. Our analysis of the leaked builds reveals a modular, multi-threaded design fitting the developers’ description. Some, but not all, of the improvements described in SantaStealer’s Telegram channel are reflected in the samples we were able to analyze. For one, the malware can be seen shifting to a completely fileless collection approach, with modules and the Chrome decryptor DLL being loaded and executed in-memory. On the other hand, the anti-analysis and stealth capabilities of the stealer advertised in the web panel remain very basic and amateurish, with only the third-party Chrome decryptor payload being somewhat hidden.

To avoid getting infected with SantaStealer, it is recommended to pay attention to unrecognized links and e-mail attachments. Watch out for fake human verification, or technical support instructions, asking you to run commands on your computer. Finally, avoid running any kind of unverified code from sources such as pirated software, videogame cheats, unverified plugins, and extensions.

Stay safe and off the naughty list!

Rapid7 Customers

Intelligence Hub

Customers using Rapid7’s Intelligence Hub gain direct access to SantaStealer IOCs, along with ongoing intelligence on new activity and related campaigns. The platform also has detections for a wide range of other infostealers, including Lumma, StealC, RedLine, and more, giving security teams broader visibility into emerging threats.

Indicators of compromise (IoCs)

SantaStealer DLLs with exported symbols (SHA-256)

  • 1a277cba1676478bf3d47bec97edaa14f83f50bdd11e2a15d9e0936ed243fd64
  • abbb76a7000de1df7f95eef806356030b6a8576526e0e938e36f71b238580704
  • 5db376a328476e670aeefb93af8969206ca6ba8cf0877fd99319fa5d5db175ca
  • a8daf444c78f17b4a8e42896d6cb085e4faad12d1c1ae7d0e79757e6772bddb9
  • 5c51de7c7a1ec4126344c66c70b71434f6c6710ce1e6d160a668154d461275ac
  • 48540f12275f1ed277e768058907eb70cc88e3f98d055d9d73bf30aa15310ef3
  • 99fd0c8746d5cce65650328219783c6c6e68e212bf1af6ea5975f4a99d885e59
  • ad8777161d4794281c2cc652ecb805d3e6a9887798877c6aa4babfd0ecb631d2
  • 73e02706ba90357aeeb4fdcbdb3f1c616801ca1affed0a059728119bd11121a4
  • e04936b97ed30e4045d67917b331eb56a4b2111534648adcabc4475f98456727
  • 66fef499efea41ac31ea93265c04f3b87041a6ae3cd14cd502b02da8cc77cca8
  • 4edc178549442dae3ad95f1379b7433945e5499859fdbfd571820d7e5cf5033c

SantaStealer EXEs (SHA-256)

  • 926a6a4ba8402c3dd9c33ceff50ac957910775b2969505d36ee1a6db7a9e0c87
  • 9b017fb1446cdc76f040406803e639b97658b987601970125826960e94e9a1a6
  • f81f710f5968fea399551a1fb7a13fad48b005f3c9ba2ea419d14b597401838c

SantaStealer C2s

  • 31[.]57[.]38[.]244:6767 (AS 399486)
  • 80[.]76[.]49[.]114:6767 (AS 399486)

MITRE ATT&CK

  • Account Discovery (T1087)
  • Automated Exfiltration (T1020)
  • Data Compressed (T1002)
  • Browser Information Discovery (T1217)
  • Archive Collected Data (T1560)
  • Data Transfer Size Limits (T1030)
  • Archive via Library (T1560.002)
  • Automated Collection (T1119)
  • Exfiltration Over C2 Channel (T1041)
  • Clipboard Data (T1115)
  • Debugger Evasion (T1622)
  • Email Account (T1087.003)
  • File and Directory Discovery (T1083)
  • Credentials In Files (T1552.001)
  • Credentials from Password Stores (T1555)
  • Data from Local System (T1005)
  • Credentials from Web Browsers (T1503)
  • Financial Theft (T1657)
  • Credentials from Web Browsers (T1555.003)
  • Credentials in Files (T1081)
  • Malware (T1587.001)
  • Process Discovery (T1057)
  • Local Email Collection (T1114.001)
  • Messaging Applications (T1213.005)
  • Screen Capture (T1113)
  • Server (T1583.004)
  • Software Discovery (T1518)
  • System Checks (T1497.001)
  • DLL (T1574.001)
  • System Information Discovery (T1082)
  • System Language Discovery (T1614.001)
  • Time Based Evasion (T1497.003)
  • Virtualization/Sandbox Evasion (T1497)
  • Deobfuscate/Decode Files or Information (T1140)
  • Web Protocols (T1071.001)
  • Private Keys (T1145)
  • Private Keys (T1552.004)
  • Dynamic API Resolution (T1027.007)
  • Steal Application Access Token (T1528)
  • Steal Web Session Cookie (T1539)
  • Embedded Payloads (T1027.009)
  • Encrypted/Encoded File (T1027.013)
  • File Deletion (T1070.004)
  • File Deletion (T1107)
  • Portable Executable Injection (T1055.002)
  • Process Hollowing (T1055.012)
  • Process Hollowing (T1093)
  • Reflective Code Loading (T1620)

Да разкажеш света наново: Джанет Уинтърсън в разговор за властта и въображението

Post Syndicated from original https://www.toest.bg/da-razkazhesh-sveta-nanovo-jeanette-winterson-v-razgovor-za-vlastta-i-vaobrazhenieto/

Да разкажеш света наново: Джанет Уинтърсън в разговор за властта и въображението

Джанет Уинтърсън не говори, а гори. Това си мисля, докато слушам как стремително разгръща идеите си – леви и открито хуманистични.

За поколението, което през 90-те жадно наваксваше със света, името ѝ беше синоним на свобода. И макар оттогава на български да са издадени само три нейни книги, за познавачите на съвременната литература не е тайна, че Джанет Уинтърсън е смятана за един от най-смелите гласове в британската проза.

Десетилетия по-късно писателката е в София като специален гост на 13-тия Софийски международен литературен фестивал (9–14 декември) с майсторски клас и публична дискусия. Уинтърсън донесе със себе си и заряда на най-новата си книга One Aladdin Two Lamps (Penguin, 2025) – хибриден текст, в който „Хиляда и една нощ“ среща бъдещето, за да попита какво се случва, ако дадем на изкуствения интелект силата на джина, когото може би вече не можем да върнем в лампата.

Срещаме се с Уинтърсън в момент на кипящо гражданско недоволство в страната – контекст, който тя не подминава.

Вероятно вече знаете, че в момента в България стотици хиляди хора протестират срещу правителството, дългогодишната корупция и дезинформацията. Мнозина вече не знаят в какво и на кого да вярват. В книгите си често пишете за историята, властта и истината. Каква според Вас е ролята на писателя във времена на политически и емоционални сътресения?

Доверието е разрушено навсякъде. Вече никой не знае кой казва истината. Живеем в свят на постистина. Администрацията на Тръмп направи нещата още по-лоши – всекидневните лъжи започнаха да изглеждат нормални. И в моята страна е така – хората чувстват, че могат да казват каквото си поискат, без значение дали е вярно.

… А целият човешки договор се основава на доверие. По природа се раждаме доверчиви – децата растат с усещането, че на възрастните може да се разчита, че са силни, мъдри и ще се грижат за тях. После порастваме и виждаме как хората на власт злоупотребяват, лъжат и нарушават този договор.

Корупцията е точно това – прекъсване на вярата, загуба на доверие. Не става дума само за кражба или измама, а за нарушаване на човешкия договор. Затова корупцията е едно от най-тежките неща, които човек може да причини на друг човек.

Надежда ми дават младите хора. И тук е така – те са на площадите и казват: „Не можем да ви вярваме, че ще се грижите за нас, затова поемаме нещата в свои ръце.“ Това ми вдъхва надежда.

Един от лозунгите на протеста е: „Gen Z идва. Мафията – вън!“ Често казват, че новото поколение не се интересува от политика, но на площадите виждаме обратното. Според Вас, особено след написването на One Aladdin Two Lamps, какво e различното в отношението на тoва поколение към властта и истината?

Те излязоха от апатията. Осъзнават, че ако не влезеш в политиката, ако нямаш власт, не можеш да промениш нищо.

Радва ме също, че жените преоткриват феминизма – изправят се срещу идеята за trad wife (традиционната съпруга) и казват: „Искам да работя; искам свои пари.“

Доскоро изглеждаше, че важните въпроси са решени. Но това се промени с Брекзит, с Тръмп, а сега и с войната на Путин в Украйна. Младите се оглеждат и казват: „Чакайте, вижте какво направихте с планетата. Това е нашият свят. Как да имам деца в такъв свят?“ Те са ядосани, а гневът е катализатор на промяната.

Писателите и артистите трябва да ги подкрепят. Ние вярваме във въображението и в критичното мислене, умеем да разговаряме. Така че, ако имаш някаквo влияние, използвай го за добро. Всичко е история, а прогресът идва, когато разкажеш по-добра история.

Най-важното е да разберем, че общественият ред не е природен закон като гравитацията. Той е история, която можем да променяме. Тъкмо тук имаме избор.

One Aladdin Two Lamps е книга, която вижда надежда в технологиите, но е и много мрачна по отношение на капитализма, мизогинията и крайното дясно. Как съчетавате този оптимизъм за инструментите, с които разполагаме, с песимизма си за обществените ни модели?

Аз съм оптимистка по природа. Вярвам в решенията. Моята мантра е:

Мога да променя историята, защото аз съм историята.

Промених собствения си живот, затова знам, че прогресът е възможен. Но сега осъзнавам и структурното неравенство – колко трудно е за някои хора да постигнат промяна, когато всичко в живота е срещу тях. Надеждата е в това, че ние сме изградили тази система, следователно можем да я разрушим и да построим нова.

И аз като всички останали си мисля: „Това е пълен ад.“ Екологичните щети, последиците от хищническия капитализъм, това как богатите стават все по-богати, а хората не могат да водят нормален, достоен живот.

Нуждаем се от голяма, истинска промяна. Може да е опасно, защото революцията винаги носи щети наред с ползите, но на този етап не виждам друг начин. Алтернативата е още по-болезнена – просто да се предадем на разрушителните сили. Хора като Доналд Тръмп, Илън Мъск, Питър Тийл, т.нар. технобратя – това е „елитът“, който реално контролира нещата. Но ние можем да се изправим срещу тях.

Когато казват, че четенето и писането са лукс, аз отговарям така: всичко започва като идея в нечия глава – било то политическо движение, борба за справедливост или изобретение. Ако можеш да промениш нагласите, да развиеш въображението, да научиш хората да мислят, отиваш точно там, откъдето всичко започва.

Ето защо изкуството никога не е лукс. Литературата взема „това, което е“ и пита: „Ами ако?“

Да разкажеш света наново: Джанет Уинтърсън в разговор за властта и въображението

Винаги сте писала за куиър любовта, за семейството, което сами избираме, и за идентичностите извън нормата. Описвала сте литературата като вид убежище. Как изглежда то днес, в края на 2025 г., на фона на възобновената морална истерия?

И за какво е цялата истерия?! Опасността не идва от гей хората, които просто искат да създадат дом и семейство с човека, когото обичат. Не идва и от жените, които искат работа и равни права. Това са нормални неща.

Западът дестабилизира света и направи невъзможно за хората да останат в собствените си държави. Това е наследството на империята. Повечето от тези хора не искат да се местят – те искат да си останат у дома! Ние сами забъркахме тази каша. Трябва да разберем връзките между империализма, капитализма и системното източване на ресурси.

Първата стъпка е да бъдем реалисти. Важно е да седнем и да споделим страховете си, без да се притесняваме, че ще бъдем „канселирани“ [отхвърлени – бел.ред.]. В момента сме в състояние на крайна поляризация. Живея в страна, където всеки ден водещите заглавия са за самозвани пазители на реда, които отиват до Ламанша и разрязват малките лодки на мигрантите. По-грозно нещо не съм виждала през целия си живот.

Тръмп легитимира това с имиграционните си политики. Знаете как работят идеите – немислимото бавно става радикално, а след това се превръща в мейнстрийм. Някога немислимото беше „жените трябва да гласуват“. Сега виждаме обратното движение: „може би жените не трябва да гласуват“.

Това, за което хората избягват да говорят, е вярата. Притеснявам се от екстремизма във вярата, защото самата аз бях отгледана в религиозна секта. Страхувам се от ортодоксалността, без значение дали става дума за десни бели християни, за ислямисти, или за ортодоксални евреи, които отказват интеграция. Всички те се кланят на различен небесен бог, но всички са реакционни. А нещата се свеждат до едно и също – потискане на жените, потискане на гей хората и желание да се върнем към някакъв идеал, в който мъжете държат цялата власт.

Няма значение на кой небесен бог се кланяте. Ако вярвате, че един бог, когото никога не сте виждали, е на ваша страна и иска да победите, това е лудост. Ще използвате това, за да оправдаете своята неморалност и жестокост.

Истинският проблем на нашето време са войните на вярата. Но хората казват: „Не, не можем да говорим за това, ще ги обидим.“ А аз си мисля: „Хайде да ги обидим.“

Книгите Ви често са многопластови. В тях има истории в историите и различни времена на една и съща страница. Тази структура вероятно е Вашият начин да се противопоставите на опростените разкази с „една възможна истина“.

Да, защото наративите за една-единствена истина не вършат работа. Ние сме много по-сложни. Светът вече е глобален, свързани сме по начини, които не можем да променим. Връщането назад към „Това е моята страна, моите граници, моята църква“ няма да ни спаси.

Винаги мисля за това как умът се движи между минало, настояще и бъдеще. Литературата е ненадмината в умението да пренесе този вътрешен свят на ума върху страницата.

Господинов ми е любим писател, срещнах се с него вчера. „Времеубежище“ е толкова дълбока книга за това колко ненадеждна е паметта. Всички ние сме ненадеждни разказвачи. Литературата ти казва: „Това е истината за теб.“ И трябва да се научиш да живееш с тази несигурност.

Но четенето също така помага да разберем историята не просто като обективна хроника. Начинът, по който четем миналото, се променя, защото ние самите се променяме.

Например радикалната десница в Америка често повтаря: „Процентът на разводите се е утроил между 1960 и 1980 г.“ Това е факт. Но защо? Защото жените си намериха работа, зароди се феминизмът. Едната страна представя това като разпад на семейството. Другата страна поглежда и казва: „Да, жените осъзнаха, че могат да изкарват собствени пари, и не искаха децата им да бъдат отглеждани от някакъв пропаднал неудачник.“ Ето ви пример за критично мислене – да уважаваш факта, но да погледнеш по-дълбоко.

Това се опитвам да предам на моите студенти. Нека не „канселираме“ миналото или религията. Нека провокираме тези млади умове, като говорим за това какво всъщност се случва. Аз съм категорично против кенсъл културата. Трябва да се изправяме пред трудните теми. Именно така промяната става възможна.

Ако можехте да изпратите една история, есе или образ от Вашето творчество като писмо в бутилка до българите, какво би било то?

Би било нещото, което наистина помогна и на мен – четете себе си и като фикция, и като факт. Осъзнайте, че вие сте история. Вие сте творба в процес на създаване. Нищо не е предопределено.

Това е и красивото в историите на Шехерезада. Намесата на другите наистина има значение. Някой те спасява, ти помагаш на някого. В „Хиляда и една нощ“ никой не казва: „Това не е моя работа.“ Всички се включват. Ние сме общността, а не самотният герой.

Това виждам в протестите по улиците тук. Хора, които отправят общи призиви. Така ще съживим феминизма, ще се справим с расизма. Когато се съберем и отправим общи призиви.

В друго интервю Ви попитаха кое е най-важното нещо на света, и отговорът ви беше „любовта“. Все още ли това е отговорът Ви?

Винаги съм вярвала, че любовта е най-висшата ценност. Един от проблемите на секуларизма е, че той отдалечи хората от идеята за вътрешен свят – свят, който не може да бъде наситен с материални придобивки. Героизмът, саможертвата, любовта към детето ти – това са неща красиви и истински.

Но докато вървим към бъдеще, изградено от изкуствен интелект… Той няма лимбична система. Той мисли, но не чувства. А ние чувстваме. Винаги ме напушва смях, когато мъжете кажат, че жените са „твърде емоционални“, а след това отиват и започват някоя война. И ми идва да кажа: „Пич, виж какво направи току-що! Не ми говори за емоционалност.“

Замислих се обаче: кое ще ни бъде абсолютно необходимо, ако наистина съсипем планетата? Въображението! Ако наистина я разрушим, ще трябва да намерим начин да си представим света наново. Може дори да се наложи да преосмислим любовта.

Но дори и да стабилизираме планетата и да преживеем всичко това, ние ще съжителстваме с небиологични същности. Не можем да научим изкуствения интелект да обича, можем обаче да го научим да си представя. Големите езикови модели са просто огромни машини за предсказване, но ние все още не сме създали машина за въображение. Ето това ме вълнува. И може би точно това е нещото, което трябва да пренесем в новия свят.

За победителите, победените и наследниците

Post Syndicated from Григор original http://www.gatchev.info/blog/?p=2675

Казват, че историята я пишат победителите. Че те изкарват някого герой или злодей.

И че е глупост във война да спасяваш цивилните на врага. За победените му военни – да не говорим…

Спомням си за Салваторе Тодаро. Командир на италианска подводница през Втората световна война. Спасил екипажа на потопен от него (по погрешка) белгийски товарен кораб, излагайки подводницата си на голям риск. Повече за него – https://en.wikipedia.org/wiki/Salvatore_Todaro_(naval_officer)

Когато Дьониц научава за постъпката му, заявява: „Това е война, а не мисионерство. Не можем да си позволим донкихотщина.“ Тодаро отговаря задочно: „Някои нямат зад гърба си две хиляди години цивилизация. Аз имам.“

Всъщност значат ли много тези две хиляди години цивилизация? Във военен хуманизъм Рим си е варварски – поводите за гордост, че си му наследник, не са много. Други страни имат повече за по година-две.

Но Тодаро създава с тази си постъпка повод за гордост да си наследник на него самия. Физически – да си му потомък. Национален – да си италианец. Духовен – да си човек, който на негово място би постъпил така.

Затова и за него – победения във Втората световна война – има филм, пълен с възхищение. („Comandante“ – 2023.) Направен и от страна, която се води победител – Белгия. Такъв филмов химн на Дьониц няма и няма да има.

Няма и за адмиралите на страните-победителки. Днешните им командири седят под техните портрети, но се възхищават на Тодаро. И се гордеят, че са национални наследници на своите адмирали, но искат да са духовни наследници на Тодаро. Поне истинските хора между тях.

Човечността и доброто побеждават дори когато са били във война на губещата страна. Народът на тази губеща страна се гордее с тях, приема достойнството и човечността за своя национална черта и се възправя. И физическото поколение на победилите ги, но не толкова достойни лично, се вдъхновява от тях и става тяхно духовно поколение.

Така ще е и с днешните войни, и с бъдещите. Поелите риск заради доброто може и да не оставят физически наследници. Но техни духовни наследници стават всички достойни хора, дори сред врага им. Колкото повече зло е показал този враг, толкова повече физическите му деца избират да са духовни деца на достойните, дори ако са победени. А гените са само плът, опаковка – духът е личността и истинската същност на човека.

Ето така доброто и достойното оставя наследство, а злото – не. Дори когато наглед е изгубило война.

И в дни като днешните е добре да не го забравяме.

Upcoming Speaking Engagements

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2025/12/upcoming-speaking-engagements-51.html

This is a current list of where and when I am scheduled to speak:

  • I’m speaking and signing books at the Chicago Public Library in Chicago, Illinois, USA, at 6:00 PM CT on February 5, 2026. Details to come.
  • I’m speaking at Capricon 44 in Chicago, Illinois, USA. The convention runs February 5-8, 2026. My speaking time is TBD.
  • I’m speaking at the Munich Cybersecurity Conference in Munich, Germany on February 12, 2026.
  • I’m speaking at Tech Live: Cybersecurity in New York City, USA on March 11, 2026.
  • I’m giving the Ross Anderson Lecture at the University of Cambridge’s Churchill College on March 19, 2026.
  • I’m speaking at RSAC 2026 in San Francisco, California, USA on March 25, 2026.

The list is maintained on this page.

Kernel prepatch 6.19-rc1

Post Syndicated from corbet original https://lwn.net/Articles/1050381/

Linus has released 6.19-rc1, perhaps a bit
earlier than expected.

So it’s Sunday afternoon in the part of the world where I am now,
so if somebody was looking at trying to limbo under the merge
window timing with one last pull request and is taken by surprise
by the slightly unusual timing of the rc1 release, that failed.

Teaching moment, or random capricious acts? You be the judge.

A Quick Look at Kaytus KSManage Used to Manage Clusters of Servers

Post Syndicated from Patrick Kennedy original https://www.servethehome.com/a-quick-look-at-kaytus-ksmanage-used-to-manage-clusters-of-servers/

We had the opportunity to look at Kaytus KSManage, used to manage servers, but also integrated AI racks and data center infrastructure

The post A Quick Look at Kaytus KSManage Used to Manage Clusters of Servers appeared first on ServeTheHome.

Conill: Rethinking sudo with object capabilities

Post Syndicated from corbet original https://lwn.net/Articles/1050370/

Ariadne Conill is
exploring
a capability-based approach to privilege escalation on Linux
systems.

Inspired by the object-capability model, I’ve been working on a
project named capsudo. Instead of
treating privilege escalation as a temporary change of identity,
capsudo reframes it as a mediated interaction with a service called
capsudod that holds specific authority, which may range
from full root privileges to a narrowly scoped set of capabilities
depending on how it is deployed.

Седмицата (8–13 декември)

Post Syndicated from Йовко Ламбрев original https://www.toest.bg/sedmitsata-8-13-dekemvri/

Седмицата (8–13 декември)

Едва ли може да има друга новина на седмицата освен тази, че след изключително силна и многобройна протестна вълна в цялата страна премиерът Росен Желязков депозира оставката на воденото от него правителство.

Протестите бяха реакция срещу неадекватния проектобюджет, но и срещу политическата арогантност, както сам призна и министър-председателят в оставка. Задържането на опозиционни политици без доказателства за вина в продължение на месеци възмути мнозина. А хората постигнаха този впечатляващ успех, защото преоткриха формулата на обединените усилия. Опозицията, разбира се, захрани протеста с хора и енергия, но и успя да напипа общите мотиви хората да останат заедно на площадите. Естествено бе и прицелването върху дуото Борисов–Пеевски, което така или иначе отдавна се е комплектувало като архивраг на поне две поколения будни българи.

Това е ситуация, в която не сме били от 1997 г. насам. Изкуствено въведените от пропагандата разделения и плашила: българи/турци, либерали/консерватори, европейци/националисти, чрез които ДПС и „Атака“ (условно) се подхранваха един друг, бяха заличени. Защото всички сме български граждани, свободни хора, обичащи семействата си, българи в Европа. Не знам дали си давате сметка какъв потенциал е това.

Владимир Йончев, OFFNews

Това, което мен лично ме жегна много силно тези дни, още преди оставката да стане факт, бе констатация на младежи в едно телевизионно студио. Те тъжно споделиха, че целият им съзнателен живот е белязан от факта, че Борисов и Пеевски са запушили държавата и бъдещето пред страната. Не знам как моето поколение може да заличи този грях…

Седмицата (8–13 декември)
10 декември 2025, Пловдив © Димитър Цанков Димитров

Но след като коалицията на политическата самонадеяност и арогантност, състояща се от ГЕРБ на Бойко Борисов, БСП на Атанас Зафиров и ИТН на Слави Трифонов, с (уж неофициалната) подкрепа от ДПС – Ново начало на Делян Пеевски е вече история, на ход е Емилия Милчева с очакванo трезв и на моменти дори болезнен обзор на ситуацията и на възможните посоки на развитие на събитията оттук нататък. Защото най-трудното тепърва предстои. След оставката. И след предсрочните избори.

За саркастичен поглед върху събитията от седмицата, разбира се, разчитаме на Елена Телбис. И този път тя е във вихъра си, заредена с оптимизъм и приятни усещания насред парламентарната криза.

На друг бюджет – на новия бюджет на Европейския съюз – пък е посветен материалът на Анахит Хачикян тази седмица. Така наречената многогодишна финансова рамка покрива период от седем години (2028–2034) и предизвикателството е не само да се предвидят достатъчно средства за всички области, за които е известно, че е нужно финансиране – трябва да има и достатъчно запас за извънредни разходи, които е трудно да се предвидят и разпознаят като критични от днешна гледна точка.

През отминалата седмица с радост посрещнахме новината, че Българският хелзинкски комитет връчва отличието „Човек на годината“ на Боян Юруков за активната му дейност по анализирането и публикуването на данни в полза на обществото. Сигурен съм, че сред номинираните е имало и други достойни за отличието, но Боян отдавна заслужава неговите усилия да бъдат забелязани и отразени подобаващо. Честито!

За съжаление обаче, неприятно развитие има по друга тема, която в „Тоест“ отдавна следим отблизо. Буквално в последните дни на своя мандат датското председателство на Съвета на ЕС успя да съгласува компромисен вариант на силно противоречивия Регламент за борба със сексуалното насилие над деца (CSAR), добил известност като #chatcontrol, който допуска автоматичното сканиране на личната ни комуникация. Компромисът се състои в това, че прилагането на Регламента няма да бъде задължително, а ще бъде приемано от отделните държави на доброволен принцип. Само Чехия, Италия, Нидерландия и Полша са възразили срещу този абсурд. А най-разочароваща е промяната на позицията на Германия.

Опасенията не са само, че институциите си запазват правото на всеки три години да определят кои услуги са „високорискови“, и да вменяват на доставчиците задължение за сканиране на съобщенията. Заедно с това се отварят вратите пред американски технологични гиганти, като Meta или Google, да проверяват безразборно личните ни съобщения без никакви първоначални основания. При това ползвайки алгоритми, за които е известно, че допускат ужасно много грешки.

Това е все едно да се отваря превантивно всяко писмо, за да се види дали случайно не съдържа нещо за незаконна дейност.

Същевременно всички държави (дори тези извън ЕС), ратифицирали Европейската конвенция за правата на човека, имат законодателство, което защитава тайната на кореспонденцията.

Чл. 34. (1) Свободата и тайната на кореспонденцията и на другите съобщения са неприкосновени.
(2) Изключения от това правило се допускат само с разрешение на съдебната власт, когато това се налага за разкриване или предотвратяване на тежки престъпления.

Конституция на Република България

Най-циничното е, че проектът съдържа изключение от сканиране на съобщенията на органите за сигурност, на политиците, на организации, които използват собствени платформи за комуникация, както и на представители на органи на властта (по преценка на държавите членки).

Иначе казано, ще сканират безогледно нашите писма и съобщения, но техните остават неприкосновени.

Сега на ход е Европейският парламент. В негова власт е да спре това безумие, а в наша – да убедим представителите си да гласуват против новата версия на Регламента.

Другият голям срам от последните дни е и т.нар. Стратегия за национална сигурност на САЩ на Доналд Тръмп. Ако сте се почувствали объркани от заглавията, коментарите и интерпретациите по тази тема, Йоанна Елми прави дисекция на документа и тезите в него в десетия брой на бюлетина си „Гласовете на Америка“:

Ако трябва да обобщим Стратегията за национална сигурност на втората администрация на Тръмп в няколко думи, те биха били: личности над принципи и пари над всичко, откровено заявено като държавна политика.

Светла Енчева сама признава в статията си „Мила родино, ти си ергенски рай“, че си е причинила целия сезон на въпросното популярно риалити заради лекомислено обещание, че след като е отбелязала началото му със статия, трябва да напише и друга след финала му. И докато е страдала, гледайки епизод след епизод, все повече се е убеждавала, че шоуто е добро приближение на състоянието, в което се намира държавата ни.

Светла Енчева ще бъде и поредният събеседник на Владислав Севов в петия епизод на видеопоредицата ни „Тоест разговаряме“ – ще излъчим на живо техния разговор днес от 16:00 часа. Дотогава все още може да завършите изречението „Равните права са…“ и да зададете въпрос на Светла в нашата кратка анкета.

Зареденото с обществена напрегнатост ежедневие този път не подмина дори рубриката „Порция език“ на Павлина Върбанова. В текста ѝ, разбира се, отново става дума за правопис и етимология, но този път Павлина е провокирана от една диалектна дума, която характеропатиите на политическия ни елит вкараха в активно обращение в последните дни. Прочетете повече в статията „За мършляка – безпристрастно“.

Съзнавам, че вече е крайно време да ви оставя да се наслаждавате на уикенда си, но искам да препоръчам още нещо за четене – лекцията на унгарския писател Ласло Краснахоркаи, тазгодишния нобелов лауреат за литература. Нека помислим заедно с него за лошите думи, новите ангели и бунта. Все актуални теми, нали?

И наистина накрая… да напомня, че „Тоест“ разчита на подкрепата на читателите си, за да оцелее като свободна медия, която акцентира върху важните неща. Затова, ако и за вас е важно екипът ни да продължи със своята мисия, следвайки установените принципи за почтена и независима журналистика, подкрепете ни.

Приятно четене!

[$] The state of the kernel Rust experiment

Post Syndicated from corbet original https://lwn.net/Articles/1050174/

The ability to write kernel code in Rust was explicitly added as an
experiment — if things did not go well, Rust would be removed again. At
the 2025 Maintainers Summit, a session was held to evaluate the state of
that experiment, and to decide whether the time had come to declare the
result to be a success. The (arguably unsurprising) conclusion was that
the experiment is indeed a success, but there were some interesting points
made along the way.

How Bayer transforms Pharma R&D with a cloud-based data science ecosystem using Amazon SageMaker

Post Syndicated from Avinash Erupaka original https://aws.amazon.com/blogs/big-data/how-bayer-transforms-pharma-rd-with-a-cloud-based-data-science-ecosystem-using-amazon-sagemaker/

This post was written with Avinash Erupaka from Bayer (IT PH, Drug Innovation platform)

How can pharmaceutical companies unlock the full potential of their data to drive breakthrough innovations? Bayer, a global leader in health and nutrition, is dedicated to tackling the pressing challenges of our time, including a growing and aging population and the strain on our planet’s ecosystems. Its mission of “Health for All, Hunger for None” drives its commitment to addressing societal and environmental needs through groundbreaking research. Bayer is focused on developing innovative solutions that make a tangible difference in the world and value for its customers, employees, and stakeholders. Headquartered in Leverkusen, Germany, Bayer operates across 80 countries and is pioneering a data science ecosystem that transforms how research teams access, analyze, and derive insights from complex scientific data.

By harnessing the power of data, analytics, artificial intelligence and machine learning (AI/ML), and generative AI, Bayer is creating a cloud-based Pharma R&D Data Science Ecosystem (DSE) on AWS that powers cutting-edge technologies and concepts with robust data management. In doing so, R&D teams can fully realize the potential of unified data and analytics.

In this post, we discuss how Bayer used the next generation of SageMaker to build a solution that unified data ingestion, storage, analytics, and AI/ML workflows. Built on data mesh principles, Bayer’s DSE integrates advanced data ingestion, storage, analytics, and ML workflows to enable agile experimentation and scalable insight generation. It democratizes access to analytics, fosters cross-Region collaboration, and provides flexible integration of structured, semi-structured, and unstructured data.

Challenges in pharmaceutical research

In pharmaceutical research, data has become the most critical asset for driving innovation. However, managing this data effectively presents unprecedented challenges and traditional data management approaches are becoming increasingly inadequate for complex, global research initiatives. Many pharma R&D organization face a complex ecosystem of data and analytics related obstacles that hinder scientific discovery and operational efficiency:

  • Siloed datasets – Research datasets are siloed across domains, limiting reuse and slowing discovery.
  • Multiple data modalities – Clinical trial data (structured), real-world evidence (semi-structured), and genomic files (unstructured) existed in isolation, complicating integration and analysis.
  • Inflexible ingestion capabilities – Systems that support batch processing (such as trial data), real-time data streams (for example, from lab equipment), and event-driven ingestion (such as regulatory updates).
  • Rising R&D costs – Disparate technologies and disconnected systems create operational inefficiencies and increased licensing and maintenance costs.
  • Inconsistent landscape to fully use ML – The absence of a unified data architecture and standardized, domain-agnostic MLOps workflows mean that data and analytics innovation is often ad hoc and non-repeatable. Teams lack a streamlined way to scale successful patterns, resulting in redundant efforts, longer development cycles, and missed opportunities for cross-domain synergy.
  • Disconnected architectures – Software solutions are not integrated into the wider unified ecosystem, resulting in silos, redundancies, and inefficiencies.

Recognizing these systemic challenges, Bayer embarked on a transformative journey. DSE is not just a technological solution, but a strategic reimagining of how research data and analytics could be used across a global organization. By bringing together cutting-edge technologies, standardized frameworks, a collaborative data mesh, and lakehouse architecture, Bayer set out to help researchers and engineers accelerate pharmaceutical innovation.

Finding a solution with the next generation of SageMaker

Bayer envisioned a unified data science ecosystem that would provide the following:

  • A unified collaborative development experience for all data scientists regardless of their location or specialization
  • Seamless access to both structured and unstructured data through a consistent interface
  • Built-in governance and compliance controls appropriate for pharmaceutical research
  • Scalable compute resources to handle the most complex analytical workloads

Bayer conducted a comprehensive evaluation of various solutions before selecting the next generation of SageMaker as the cornerstone of their new data science ecosystem. Although other options had merits, Bayer prioritized the following capabilities:

  • Access to multimodal data – Essential for genomics, proteomics, and advanced biomarker research
  • Centralized asset marketplace – Central hub to discover and reuse data, features, models, and other enterprise assets
  • Integrated tooling ecosystem – Streamlined access to key tools like Git, ETL, MLflow, and generative AI application builders in one place
  • Multi-domain and cross-Region support – Critical for global research collaboration
  • Price-performance – Necessary for sustainable, long-term scaling

The capabilities of Amazon SageMaker Unified Studio and Amazon SageMaker Catalog aligned with Bayer’s vision of decentralized mesh execution combined with centralized discovery and governance. They enabled teams to work with their preferred tools, such as Jupyter Notebooks or workflow builders, while maintaining discoverability and reusability of assets.

Solution overview

This section describes the key features and architecture of Bayer’s DSE built on SageMaker. The DSE solution addresses the identified challenges through a multi-layered architecture:

  • Breaking down data silos – Multimodal data ingestion capabilities of the solution break down data silos by enabling unified storage, processing of structured, semi-structured, and unstructured data through batch, streaming, and event-driven pipelines.
  • Handling diverse data modalities – A hybrid lakehouse architecture, built on Amazon Simple Storage Service (Amazon S3), Apache Iceberg, and Amazon Redshift, provides a flexible foundation for handling diverse data modalities and maturities while providing data consistency and accessibility.
  • Reducing costs through standardization – To address rising R&D costs and operational inefficiencies, pre-wired analytical workbenches offer standardized templates and integrated development environments (IDEs) that reduce redundancy and accelerate workflow development.
  • Unlocking AI/ML with Amazon SageMaker AI and Amazon Bedrock – Advanced AI/ML capabilities, powered by Amazon SageMaker AI and Amazon Bedrock, create a standardized, domain-agnostic MLOps environment that enables repeatable innovation and cross-domain synergy.
  • Managing tools ecosystem with end-to-end observability – Robust governance and observability features provide compliance and system reliability while integrating previously disconnected tools into a unified, well-monitored ecosystem that breaks down architectural silos and promotes efficient resource utilization.

The DSE architecture implements data mesh principles where data domains (omics, regulatory, clinical trials) are treated as products, with ownership and management responsibilities assigned to domain experts. These domains are decentralized for execution but remain discoverable and reusable through SageMaker Catalog. At the core of the architecture is a hybrid mesh lakehouse architecture that combines Amazon S3 and Iceberg, providing the flexibility to handle both structured and unstructured data efficiently. SageMaker Unified Studio provides an analytical layer where researchers can access the full suite of tools needed for their work. The following diagram illustrates this architecture.

architecture diagram showing Bayer's data science ecosystem

Impact

The first phase of Bayer’s DSE confirmed the next generation of SageMaker as a powerful foundation for their R&D DSE—designed to balance decentralized innovation with centralized governance through a scalable data mesh architecture. With this solution, Bayer can catalog and manage multimodal data assets—including structured and unstructured data, ML features, models, and custom scientific assets—with context-rich metadata across diverse Pharma R&D domains. Bayer is now positioned to onboard over 300 TB of biomarker data and integrate siloed omics, clinical, and chemistry data repositories into a cohesive environment. With integrated tools like JupyterLab Spaces, MLflow, and SageMaker AI Studio, the DSE platform is laying the groundwork for a comprehensive, GxP-aware ML workbench—paving the way to operationalize over 25 high-value ML use cases and support more than 100 data scientists across the organization.

“The Data Science Ecosystem is vital for developing our medicines,” says Daniel Gusenleitner, Mission Lead for the R&D Data Science Ecosystem. “It enhances our business workflows with advanced analytics, helping us accelerate the search for new treatments. By integrating data from the entire research and development process, we improve the chances of technical success and ensure our efforts are efficient. Unlocking our data also facilitates target discovery, leading to groundbreaking advancements in patient care.”

Next steps

Bayer has successfully begun their Data Science Ecosystem on the next generation of Amazon SageMaker and is working to onboard the first use case of advanced biomarker research. Building on the strong foundation, Bayer is also accelerating the evolution of the DSE solution with the following key enhancements:

  • Federated catalogs and cross-domain integration – Enabling search and reuse of data assets across therapeutic areas and business units
  • Advanced ontology and semantic layer – Enriching metadata with domain knowledge to support AI-based search, discovery, and reasoning
  • Adoption of generative and agentic AI workflows – Driving novel drug discovery and accelerating hypothesis generation

Conclusion

By leveraging the next generation of Amazon SageMaker to build their cloud-based Data Science Ecosystem, Bayer is creating a foundation for faster, more efficient research and discovery. Amazon SageMaker is unifying diverse data types, enabling global collaboration, and standardizing ML workflows to help position Bayer at the forefront of data-driven innovation.

To learn more and get started with the next generation of SageMaker, refer to Amazon SageMaker or the AWS console.


About the Authors

Avinash Erupaka

Avinash Erupaka

Avinash is a Principal Engineering Lead at Bayer’s Drug Innovation platform. With deep experience across pharmaceuticals, crop science, and consumer health, he has led large-scale transformations spanning cloud platforms, AI/ML, and data infrastructure. Avinash brings a unique blend of technical depth and business acumen, having worked across the life sciences value chain—from research to manufacturing. He holds a Master’s in Engineering and an Executive MBA, and is passionate about building scalable, reusable solutions to accelerate scientific discovery.

Modood Alvi

Modood Alvi

Modood was a Senior Solutions Architect at AWS. Modood is passionate about digital transformation and is committed to helping large enterprise customers across the globe accelerate their adoption of and migration to the cloud. Modood brings more than a decade of experience in software development, having held a variety of technical roles within companies like SAP and Porsche Digital. Modood earned his Diploma in Computer Science from the University of Stuttgart.

Radhika Kashyap

Radhika Kashyap

Radhika is a Senior Customer Solutions Manager at AWS. Radhika brings over a decade of experience in technical program management and works with AWS customers to accelerate their journey to the cloud. She holds a master’s degree in management information systems and a bachelor’s degree in information technology.

Friday Squid Blogging: Giant Squid Eating a Diamondback Squid

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2025/12/friday-squid-blogging-giant-squid-eating-a-diamondback-squid.html

I have no context for this video—it’s from Reddit—but one of the commenters adds some context:

Hey everyone, squid biologist here! Wanted to add some stuff you might find interesting.

With so many people carrying around cameras, we’re getting more videos of giant squid at the surface than in previous decades. We’re also starting to notice a pattern, that around this time of year (peaking in January) we see a bunch of giant squid around Japan. We don’t know why this is happening. Maybe they gather around there to mate or something? who knows! but since so many people have cameras, those one-off monster-story encounters are now caught on video, like this one (which, btw, rips. This squid looks so healthy, it’s awesome).

When we see big (giant or colossal) healthy squid like this, it’s often because a fisher caught something else (either another squid or sometimes an antarctic toothfish). The squid is attracted to whatever was caught and they hop on the hook and go along for the ride when the target species is reeled in. There are a few colossal squid sightings similar to this from the southern ocean (but fewer people are down there, so fewer cameras, fewer videos). On the original instagram video, a bunch of people are like “Put it back! Release him!” etc, but he’s just enjoying dinner (obviously as the squid swims away at the end).

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

Implementing HTTP Strict Transport Security (HSTS) across AWS services

Post Syndicated from Abhishek Avinash Agawane original https://aws.amazon.com/blogs/security/implementing-http-strict-transport-security-hsts-across-aws-services/

Modern web applications built on Amazon Web Services (AWS) often span multiple services to deliver scalable, performant solutions. However, customers encounter challenges when implementing a cohesive HTTP Strict Transport Security (HSTS) strategy across these distributed architectures.

Customers face fragmented security implementation challenges because different AWS services require distinct approaches to HSTS configuration, leading to inconsistent security postures.Applications using Amazon API Gateway for APIs, Amazon CloudFront for content delivery, and Application load balancers for web traffic lack unified HSTS policies, leading to complex multi-service environments. Security scanners flag missing HSTS headers, but remediation guidance is scattered across service-specific documentation, causing security compliance gaps.

HSTS is a web security policy mechanism that protects websites against protocol downgrade attacks and cookie hijacking. When properly implemented, HSTS instructs browsers to interact with applications exclusively through HTTPS connections, providing critical protection against man-in-the-middle issues.

This post provides a comprehensive approach to implementing HSTS across key AWS services that form the foundation of modern cloud applications:

  1. Amazon API Gateway: Secure REST and HTTP APIs with centralized header management
  2. Application Load Balancer: Infrastructure-level HSTS enforcement for web applications
  3. Amazon CloudFront: Edge-based security header delivery for global content

By following the implementation steps in this post, you can establish a unified HSTS strategy that aligns with AWS Well-Architected Framework security principles while maintaining optimal application performance.

Understanding HSTS security and its benefits

HTTP Strict Transport Security is a web security policy mechanism that helps protect websites against protocol downgrade attacks and cookie hijacking. When a web server declares HSTS policy through the Strict-Transport-Security header, compliant browsers automatically convert HTTP requests to HTTPS for the specified domain. This enforcement occurs at the browser level, providing protection even before the initial request reaches your infrastructure.

HSTS enforcement applies specifically to web browser clients. Most programmatic clients (such as SDKs, command line tools, or application-to-application communication) don’t enforce HSTS policies. For comprehensive security, configure your applications and infrastructure to only use HTTPS connections regardless of client type rather than relying solely on HSTS for protocol enforcement.

HTTP to HTTPS redirection enforcement on the server ensures future requests reach your applications over encrypted connections. However, it leaves a security gap during the initial browser request. Understanding this gap helps explain why client-side HSTS serves as an essential security layer in modern web applications.

For example, when users access web applications, the typical flow with redirects configured is as follows:

  1. User enters example.com in their browser.
  2. Browser sends an HTTP request to http://example.com.
  3. Server responds with HTTP 301/302 redirect to https://example.com.
  4. Browser follows redirection and establishes HTTPS connection

The initial HTTP request in step 2 creates an opportunity for protocol downgrade issues. An unauthorized party positioned between the user and your infrastructure can intercept this request and respond with content that appears legitimate while maintaining an insecure connection. This technique, known as SSL stripping, can occur even when your server-side AWS infrastructure is properly configured with HTTPS redirects.

HSTS addresses this security gap by moving security enforcement to the browser level. After a browser receives an HSTS policy, it automatically converts HTTP requests to HTTPS before sending them over the network:

  1. User enters example.com in browser.
  2. Browser automatically converts to HTTPS due to stored HSTS policy.
  3. Browser sends HTTPS request directly to https://example.com.
  4. No initial HTTP request removes the opportunity for interception.

This browser-level enforcement provides protection that complements your AWS infrastructure security configurations, creating defense in depth against protocol downgrade issues.

Although current browsers warn about insecure connections, HSTS provides programmatic enforcement. This prevents unauthorized parties from exploiting the security gap because they can’t forge valid HTTPS certificates for protected domains.

The security benefits of HSTS extend beyond simple protocol enforcement. HSTS helps prevent protocol downgrade issues after HSTS policy is established in the browser. It mitigates against man-in-the-middle issues, preventing unauthorized parties from intercepting communications. It also helps prevent unauthorized session access to protect against credential theft and unintended session access.
HSTS requires HTTPS connections and removes the option to bypass certificate warnings.

This post focuses exclusively on implementing the HTTP Strict-Transport-Security header. Although the examples include additional security headers for completeness, detailed configuration of those headers is beyond the scope of this post.

Key use cases for HSTS implementation

HSTS protects scenarios that HTTP redirects miss. For example, when legacy systems serve mixed content, or when SSO flows redirect users between providers, HSTS keeps connections encrypted throughout.

Applications serving both modern HTTPS content and legacy HTTP resources face protocol downgrade risks. When users access example.com/app that loads resources from legacy.example.com, HSTS prevents browsers from making initial HTTP requests to any subdomain, eliminating the vulnerability window during resource loading.

SSO implementations redirecting users between identity providers and applications create multiple HTTP request opportunities. Due to HSTS, authentication tokens and session data remain encrypted throughout the entire SSO flow, preventing credential interception during provider redirects.

Microservices architectures using API Gateway often involve service-to-service communication and client redirects. HSTS protects API endpoints from protocol downgrade during initial client connections, which means that API keys and authentication headers are not transmitted over HTTP.

Applications using CloudFront with multiple origin servers face security challenges when origins change or fail over. HSTS prevents browsers from falling back to HTTP when accessing cached content or during origin failover scenarios, maintaining encryption even during infrastructure changes.

From an AWS Well-Architected perspective, implementing HSTS demonstrates adherence to the defense in depth principle by adding an additional layer of security at the application protocol level. This approach complements other AWS security services and features, creating a comprehensive security posture that helps to protect data both in transit and at rest.

Implementing HSTS with Amazon API Gateway

Amazon API Gateway lacks built-in features to enable HSTS for the API resources. There are several different ways to configure HSTS headers in HTTP APIs and REST APIs.
For HTTP APIs, you can configure response parameter mapping to set HSTS headers when it’s invoked using a default endpoint or custom domain.

To configure response parameter mapping:

  1. Navigate to your desired HTTP API’s route configuration in the AWS API Gateway console
  2. Access the route’s integration settings under Manage integrations tab.
Figure 1: Integration settings of the HTTP Api

Figure 1: Integration settings of the HTTP Api

  1. To configure parameter mapping, under Response key, enter 200.
  2. Under Modification type, select Append in the dropdown menu.
  3. Under “Parameter to modify”, enter header.Strict-Transport-Security
  4. Under Value, enter max-age=31536000; includeSubDomains; preload.
Figure 2: Parameter Mapping for the HTTP Api integration

Figure 2: Parameter Mapping for the HTTP Api integration

REST APIs in Amazon API Gateway offer more granular control over HSTS implementation through both proxy and non-proxy integration patterns.

For proxy integrations, the backend service assumes responsibility for HSTS header generation. For example, an AWS Lambda proxy integration must return the HSTS headers in its response as shown in the following code example:

import json 
def lambda_handler(event, context):     
	return {         
        'statusCode': 200,         
        'headers': {             
            'Strict-Transport-Security': 'max-age=31536000; includeSubDomains; preload'         
        },         
        'body': json.dumps('Secure response with HSTS headers')     
    }

For non-proxy integrations, the HSTS headers must be returned by the Rest API by implementing one of two methods, either mapping templates or method response.

In the mapping templates method, the mapping template is used to configure the HSTS headers. The Velocity Template Language (VTL) for the mapping template is used for dynamic header generation. To implement this method:

  1. Navigate to the desired REST API and click on the method for the desired resource.
  2. Under the ‘Integration response’ tab, use the following mapping template to set the response headers:
$input.json("$") 
#set($newValue = "$input.params().header.get('Host')") 
#set($context.responseOverride.header.Strict-Transport-Security 
= "max-age=31536000; includeSubDomains; preload")

Figure 3: Adding mapping template to integration response of the Rest Api

Figure 3: Adding mapping template to integration response of the Rest Api

The ‘Method response’ tab provides declarative configuration through explicit header mapping in the configuration. To implement this method:

  1. Navigate to your desired REST API and select the method for the desired resource.
  2. Choose Method response and under Header name, add the HSTS header strict-transport-security.
Figure 4: Method response of the Rest Api

Figure 4: Method response of the Rest Api

3. Choose Integration response and under Header mappings, enter the HSTS header strict-transport-security. Add the Mapping value for the header as max-age=31536000; includeSubDomains; preload.

Figure 5: Integration response of the Rest Api

Figure 5: Integration response of the Rest Api

To test and validate, use the following command:

Verify HSTS implementation for both HTTP API and REST API using curl with response headers logged:

curl -i https://your-api-gateway-url.execute-
api.region.amazonaws.com/stage/resource

The expected response should include:

HTTP/2 200 

date: Tue, 20 Sep 2025 16:34:35 GMT 
content-type: application/json 
content-length: 3 
x-amzn-requestid: 76543210-9aaa-4bbb-accc-987654321012
strict-transport-security: max-age=31536000; includeSubDomains; preload 
x-amz-apigw-id: ABCDEFGHIJKLMNO

Implementing HSTS with AWS Application Load Balancers

Application Load Balancers now provide built-in support for HTTP response header modification, including HSTS headers. This lets you enforce consistent security policies across all your services from a single point, reducing development effort and ensuring uniform protection regardless of which backend technologies you’re using.

Prerequisites and infrastructure requirements

Before implementing HSTS with load balancers, ensure your infrastructure meets these requirements:

  • Functional HTTPS listener – The ALB listener must be configured with HTTPS correctly.
  • Valid certificates – The ALB listener must have proper TLS certificate chain in AWS Certificate Manager and validation.
  • Application Load Balancer – The header modification feature for the ALB must be enabled for the listener since it is turned off by default.

Configuration

Application Load Balancers support direct HSTS header injection through the response header modification feature. This approach provides centralized security policy enforcement without requiring individual application configuration.

To enable HTTP header modification for your Application Load Balancer:

  1. Open the Amazon Elastic Compute Cloud (Amazon EC2) console and navigate to Load Balancers.
  2. Select your Application Load Balancer.
  3. On the Listeners and rules tab, select the HTTPS listener.
  4. On the Attributes tab, choose Edit.
    Figure 6: ALB HTTPS listener Attributes configuration

    Figure 6: ALB HTTPS listener Attributes configuration

  5. Expand the Add response headers section.
  6. Select Add HTTP Strict Transport Security (HSTS) header.
  7. To configure the header value, enter max-age=31536000; includeSubDomains; preload.
  8. Choose Save changes.
Figure 7: Add response headers in attributes configuration of the ALB HTTPS listener

Figure 7: Add response headers in attributes configuration of the ALB HTTPS listener

Header modification behavior

When ALB header modification is enabled:

  • Header addition – If the backend response doesn’t include the specified header, ALB adds it with the configured value
  • Header override – If the backend response includes the header, ALB replaces the existing value with the configured value
  • Centralized control – Responses from the load balancer include the configured security headers, ensuring consistent policy enforcement

To test and validate, use the following command:
curl -I https://my-loadbalancer-1234567890.us-west-2.elb.amazonaws.com

The following code example shows the expected response headers:

HTTP/2 200
date: Tue, 23 Sep 2025 16:34:35 GMT
strict-transport-security: max-age=31536000; includeSubDomains; preload

Header value constraints:

  • Maximum header value size – 1 KB
  • Supported characters – Alphanumeric (a-z, A-Z, 0-9) and special characters (_ :;.,/’?!(){}[]@<>=-+*#&`|~^%)
  • Empty values revert to default behavior (no header modification)

When implementing header modifications, there are several operational considerations to keep in mind. Header modification must be explicitly enabled on each listener where you want the functionality to work. Once enabled, any changes you configure will apply to all responses that come from the load balancer, affecting every request processed through that listener. Application Load Balancer performs basic input validation on the headers you configure, but it has limited capability for header-specific validation, so you should ensure your header configurations follow proper formatting and standards.

This built-in Application Load Balancer capability significantly simplifies HSTS implementation by eliminating the need for backend application modifications while providing centralized security policy enforcement across your entire application infrastructure.

Implementing HSTS with Amazon CloudFront

Amazon CloudFront provides built-in support for HTTP security headers, including HSTS, through response headers policies. This feature enables centralized security header management at the CDN edge, providing consistent policy enforcement across cached and non-cached content.

Response headers policy configuration

You can use the CloudFront response headers policy feature to configure security headers that are automatically added to responses served by your distribution. You can use managed response headers policies that include predefined values for the most common HTTP security headers. Or, you can create a custom response header policy with custom security headers and values that you can add to the required CloudFront behavior.

To configure security headers:

  1. On the CloudFront console, navigate to Policies and then Response headers.
  2. Choose Create response headers policy.
  3. Configure policy settings:
    • Name – HSTS-Security-Policy
    • Description – HSTS and security headers for web applications
  4. Under Security headers, configure:
    • Strict Transport Security – Select
    • Max age – 31,536,000 seconds (1 year)
    • Preload – Select (optional)
    • IncludeSubDomains – Select (optional)
  5. Add additional security headers:

    • X-Content-Type-Options
    • X-Frame-Options – Select Origin as “SAMEORIGIN”
    • Referrer-Policy – Select “strict-origin-when-cross-origin”
    • X-XSS-Protection – Select “Enabled”, Tick “Block”
    • Choose Create.
Figure 8: Configuring response header policy for the Cloudfront distribution

Figure 8: Configuring response header policy for the Cloudfront distribution

To attach the policy to the distribution:

  1. Navigate to your CloudFront distribution.
  2. Select the Behaviors tab.
  3. Edit the default behavior (or create a new one).
  4. Under Response headers policy, select your created policy.
  5. Choose Save changes.
Figure 9: Selecting the response headers policy

Figure 9: Selecting the response headers policy

Header override behavior:
CloudFront response headers policies provide origin override functionality that controls how headers are managed between the origin and CloudFront. When origin override is enabled, CloudFront will replace existing headers that come from the origin server. Conversely, when origin override is disabled, CloudFront will only add the policy-defined headers if those same headers are not already present in the origin response, preserving the original headers from the source.

To test and validate, use the following command:

curl -I https://your-cloudfront-domain.cloudfront.net

The following code example shows the expected response headers:

HTTP/2 200 
date: Tue, 23 Sep 2025 16:34:35 GMT 
strict-transport-security: max-age=31536000; includeSubDomains; preload 
x-content-type-options: nosniff 
x-frame-options: SAMEORIGIN 
referrer-policy: strict-origin-when-cross-origin 
x-xss-protection: 1; mode=block 
x-cache: Hit from cloudfront

Using CloudFront has several advantages. It offers consistent header application across all content types and centralized security policy management. Edge-level enforcement reduces latency, and no origin server modifications are required. AWS edge locations offer global policy distribution.

Security considerations and best practices

Implementing HSTS requires careful consideration of several security implications and operational requirements.

The max-age directive determines how long browsers will enforce HTTPS-only access. The duration guidelines are as follows:

  • 300 seconds (5 minutes) – Safe for experimentation during initial testing phase.
  • 86,400 seconds (1 day) – For short-term commitment such as development environments.
  • 259,2000 seconds (30 days) – For medium-term validation such as staging environments.
  • 31,536,000 seconds (1 year) – For long-term commitment such as production environments.

We recommend that you start with shorter max-age values during initial implementation and gradually increase them as you gain confidence in your HTTPS infrastructure stability.

The includeSubDomains directive extends HSTS enforcement to all subdomains. It offers several benefits, including comprehensive protection across the entire domain hierarchy, prevention of subdomain-based attacks, and simplified security policy management.

Requirements for using this directive include:

  • Subdomains should support HTTPS to use this directive effectively.
  • Subdomains should have valid SSL certificates.
  • You must maintain a consistent security policy across domain hierarchy.

Consider implementing HSTS preloading for maximum security coverage:

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

Preloading benefits include protection for first-time visitors, browser-level enforcement before network requests, and maximizing security coverage.

The following are some preloading considerations:

  • It requires submission to browser preload lists.
  • It’s difficult to reverse because removal takes months.
  • It requires long-term commitment to HTTPS infrastructure.

For more information, see:

Conclusion

Implementing HSTS across AWS services provides a robust foundation for securing web applications against protocol downgrade attacks and enabling encrypted communications. By using the built-in capabilities of API Gateway, CloudFront, and Application Load Balancers, organizations can create comprehensive security policies that align with AWS Well-Architected Framework principles.

If you have feedback about this post, submit comments in the Comments section below. If you have questions about this post, contact AWS Support.

Abhishek Avinash Agawane
Abhishek Avinash Agawane

Abhishek is a Security Consultant at Amazon Web Services with more than 8 years of industry experience. He helps organizations architect resilient, secure, and efficient cloud environments, guiding them through complex challenges and large-scale infrastructure transformations. He has helped numerous organizations enhance their cloud operations through targeted optimizations, robust architectures, and best-practice implementations.

The collective thoughts of the interwebz