Dell Pro Max 18 Plus Review a HUGE Laptop with a NVIDIA RTX Pro 5000 Blackwell GPU

Post Syndicated from Patrick Kennedy original https://www.servethehome.com/dell-pro-max-18-plus-review-a-huge-laptop-with-a-nvidia-rtx-pro-5000-blackwell-gpu-intel/

In our Dell Pro Max 18 Plus review, we see how this huge system with lots of performance through its NVIDIA RTX Pro 5000 Blackwell performs

The post Dell Pro Max 18 Plus Review a HUGE Laptop with a NVIDIA RTX Pro 5000 Blackwell GPU appeared first on ServeTheHome.

Metasploit Wrap-Up 12/12/2025

Post Syndicated from Spencer McIntyre original https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-12-12-2025

React2shell Module

As you may have heard, on December 3, 2025, the React team announced a critical Remote Code Execution (RCE) vulnerability in servers using the React Server Components (RSC) Flight protocol. The vulnerability, tracked as CVE-2025-55182, carries a CVSS score of 10.0 and is informally known as “React2Shell”. It allows attackers to achieve prototype pollution during deserialization of RSC payloads by sending specially crafted multipart requests with “proto”, “constructor”, or “prototype” as module names. We’re happy to announce that community contributor vognik submitted an exploit module for React2Shell which landed earlier this week and is included in this week’s release.

MSSQL Improvements

Over the past couple of weeks Metasploit has made a couple of key improvements to the framework’s MSSQL attack capabilities. The first (PR 20637) is a new NTLM relay module, auxiliary/server/relay/smb_to_mssql, which enables users to start a malicious SMB server that will relay authentication attempts to one or more target MSSQL servers. When successful, the Metasploit operator will have an interactive session to the MSSQL server that can be used to run interactive queries, or MSSQL auxiliary modules.

Building on this work, it became clear that users would need to interact with MSSQL servers that required encryption as many do in hardened environments. To achieve that objective, issue 18745 was closed by updating Metasploits MSSQL protocol library to offer better encryption support. Now, Metasploit users can open interactive sessions to servers that offer and even require encrypted connections. This functionality is available automatically in the auxiliary/scanner/mssql/mssql_login and new auxiliary/server/relay/smb_to_mssql modules.

New module content (5)

Magento SessionReaper

Authors: Blaklis, Tomais Williamson, and Valentin Lobstein [email protected] 

Type: Exploit

Pull request: #20725 contributed by Chocapikk 

Path:multi/http/magento_sessionreaper

AttackerKB reference: CVE-2025-54236

Description: This adds a new exploit module for CVE-2025-54236 (SessionReaper), a critical vulnerability in Magento/Adobe Commerce that allows unauthenticated remote code execution. The vulnerability stems from improper handling of nested deserialization in the payment method context, combined with an unauthenticated file upload endpoint.

Unauthenticated RCE in React and Next.js

Authors: Lachlan Davidson, Maksim Rogov, and maple3142

Type: Exploit

Pull request: #20760 contributed by sfewer-r7 

Path: multi/http/react2shell_unauth_rce_cve_2025_55182 

AttackerKB reference: CVE-2025-66478

Description: This adds an exploit for CVE-2025-55182 which is an unauthenticated RCE in React. This vulnerability has been referred to as React2Shell.

WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE

Authors: Peter Thaleikis and Valentin Lobstein [email protected] 

Type: Exploit

Pull request: #20746 contributed by Chocapikk 

Path: multi/http/wp_king_addons_privilege_escalation 

AttackerKB reference: CVE-2025-8489

Description: This adds an exploit module for CVE-2025-8489, an unauthenticated privilege escalation vulnerability in the WordPress King Addons for Elementor plugin (versions 24.12.92 to 51.1.14). The vulnerability allows unauthenticated attackers to create administrator accounts by specifying the user_role parameter during registration, enabling remote code execution through plugin upload.

Linux Reboot

Author: bcoles [email protected] 

Type: Payload (Single)

Pull request: #20682 contributed by bcoles 

Path:linux/loongarch64/reboot

Description: This extends our payloads support to a new architecture, LoongArch64. The first payload introduced for this new architecture is the reboot payload, which will cause the target system to restart once triggered.

Enhanced Modules (2)

Modules which have either been enhanced, or renamed:

Enhancements and features (1)

  • #20704 from dwelch-r7 – The module auxiliary/scanner/ssh/ssh_login_pubkey has been removed. Its functionality has been moved into auxiliary/scanner/ssh/ssh_login.

Documentation

You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

Building zero trust generative AI applications in healthcare with AWS Nitro Enclaves

Post Syndicated from Nathan Pogue original https://aws.amazon.com/blogs/compute/building-zero-trust-generative-ai-applications-in-healthcare-with-aws-nitro-enclaves/

In healthcare, generative AI is transforming how medical professionals analyze data, summarize clinical notes, and generate insights to improve patient outcomes. From automating medical documentation to assisting in diagnostic reasoning, large language models (LLMs) have the potential to augment clinical workflows and accelerate research. However, these innovations also introduce significant privacy, security, and intellectual property challenges.

Healthcare data often contains Protected Health Information (PHI), which is governed by strict regulations and compliance frameworks. At the same time, organizations or researchers who have invested substantial time and compute resources into training medical LLMs must protect their proprietary model architectures, weights, and fine-tuned datasets. Traditional deployment models necessitate mutual trust between the model publisher and the healthcare data provider — trust that sensitive data won’t be leaked, and that the model itself won’t be copied, tampered with, or exfiltrated. The absence of a secure and verifiable trust model between model publishers and consumers remains one of the main barriers to scaling generative AI in regulated medical environments.

To address this concern, both parties need a secure environment to publish and consume models without exposing data or intellectual property. Amazon Web Services (AWS) Nitro Enclaves provide isolated, attested, and cryptographically verified compute environments that help protect sensitive workloads. Model owners can encrypt their LLMs with AWS Key Management Service (AWS KMS) and allow only verified Nitro Enclaves to decrypt and run them, making sure that the model can’t be accessed outside the Nitro Enclave. Healthcare organizations and consumers can use this to process sensitive data within their own AWS environment entirely within the Nitro Enclave, helping keep PHI private and contained. Hardware-based attestation provides proof that the Nitro Enclave is running trusted code, so that both sides can exchange information with confidence.

In this post, we demonstrate how to deploy a publicly available foundational model (FM) using Nitro Enclaves for isolated, more secure compute, AWS KMS for model encryption, Amazon Simple Storage Service (Amazon S3) for storing model artifacts and images, and Amazon Simple Queue Service (Amazon SQS) for securely delivering queries, enabling private, privacy-preserving inferences while helping protect both model intellectual property and sensitive patient data.

Solution overview

This solution outlines how to build a more secure end-to-end pipeline that enables zero trust medical LLM publication and inference with Nitro Enclaves. This post demonstrates a guide for setting up an Amazon Elastic Compute Cloud (Amazon EC2) instance with Nitro Enclaves enabled, downloading and encrypting a publicly available FM to an S3 bucket with an AWS KMS key, sending medical text and image-based queries to an SQS queue for processing, and storing results in an Amazon DynamoDB table.

This project is intended solely for educational and demonstration purposes and isn’t suitable for production or clinical use. Its outputs aren’t validated for clinical accuracy and must not be used for patient care or medical decision-making. Before any real-world deployment, make sure that you implement comprehensive security, privacy, and compliance safeguards. These include health data protection controls, secrets management, and regulatory validation. Furthermore, you must consult the appropriate clinical, legal, and security experts.

For demonstration purposes, this solution is deployed in a single AWS account. Ideally, in production, it would be deployed across separate AWS accounts: one for the model owner and one for the model consumer. The model owner can use cross-account AWS Identity and Access Management (IAM) permissions and encrypted model sharing through AWS KMS to securely provide access to their model without exposing the underlying weights or logic. At the same time, the consumer can run sensitive inferences within their own environment, maintaining strict data privacy and zero trust principles. In a real-world implementation, the model provider should also establish a robust entitlement and licensing framework to manage customer access, enabling fine-grained control over who can invoke the model, track usage, and support license revocation to immediately remove permissions from specific customers when necessary.

The following diagram shows the solution architecture:

Scope of solution

The steps of the solution include:

  1. Amazon EC2 setup: An EC2 instance is launched with Nitro Enclaves and Trusted Platform Module (TPM) enabled. For this project, a c7i.12xlarge instance with a 150 GB Amazon EBS volume is used to provide the necessary compute resources for running LLMs.
  2. Public FM download: A publicly available FM is retrieved from Hugging Face and stored in an S3 bucket within the model consumer’s AWS account.
  3. Model encryption: The model is encrypted using AWS KMS envelope encryption. Only a Nitro Enclave presenting a valid attestation document can request the decryption key from AWS KMS, which helps prevent unauthorized access to the model weights outside the Nitro Enclave.
  4. Nitro Enclave setup: A Docker image containing the llama.cpp inference runtime is built and deployed inside the Nitro Enclave.
  5. Model decryption and setup: When the Nitro Enclave launched, it requests decryption of the model artifacts using its attestation credentials. Then, the model can be securely decrypted inside the memory of the Nitro Enclave and loaded by the llama.cpp server. This means that the decrypted model weights aren’t visible outside of the Nitro Enclave boundary.
  6. Medical query: Users can submit either text or image-based queries to the model. Queries are sent through vsock, a secure communication channel from the client application to the model server inside the Nitro Enclave. Image queries necessitate that users upload images to an S3 bucket. The upload event triggers an SQS queue, which signals the Amazon EC2 parent to fetch and send the image to the Nitro Enclave image for the medical LLM to process with its multimodal capabilities.
  7. Message history: Each interaction, including the user’s prompt and the model’s response, is logged to a DynamoDB table. This provides a persistent conversation history that enables traceability and auditing while keeping PHI securely stored within the consumer’s account. If necessary, the DynamoDB table can be encrypted and sealed for another layer of security and privacy.

About Google MedGemma 4B

Google MedGemma is a family of medically-optimized LLMs built on Gemma 3, with 4B and 27B parameter variants supporting both text and multimodal versions for medical image inputs. The 4B model offers efficiency and strong performance for multimodal tasks such as report generation and medical Q&A, while the 27B models excel at more demanding scenarios, such as electronic health record interpretation and complex longitudinal data analysis.

MedGemma models are well-suited for automated radiology report generation, clinical triage and documentation, patient education, medical image pre-interpretation, and medical education systems. The 4B model is ideal for portable or resource-constrained deployments, whereas the 27B multimodal delivers maximal performance.

In this project, MedGemma 4B serves as a reference medical LLM, showing how domain-adapted fine-tuning can enhance a model’s ability to interpret, reason about, and respond to complex medical queries. It also provides a foundation for exploring the safe and effective use of LLMs in healthcare applications, while being securely deployed within a Nitro Enclave. However, you can choose to deploy your own medical FM if needed. This is a deeper overview on the 4B model.

Prerequisites

To implement the proposed solution, make sure that you have the following:

  • The AWS Command Line Interface (AWS CLI) installed on your machine to create the EC2 instance.
  • AWS permissions with access to EC2 c7i.12xlarge instances and Nitro Enclaves.
  • Knowledge of Amazon S3, AWS KMS, Amazon SQS, AWS Lambda, and DynamoDB.
  • Basic knowledge of Nitro Enclaves and healthcare data security.
  • The GitHub repository cloned to your local machine.

Environment setup

The following sections outline how to set up your environment for this solution.

Create S3 buckets

In this solution, you create two S3 buckets: one for the model artifacts and one for the image inputs.

To create the S3 buckets

  1. Sign in to the Amazon S3 console, choose Create bucket, and follow the prompts to create a new S3 bucket.
  2. For the model artifact bucket, give it a unique name (for example AWSACCOUNTNUMBER-medgemma-model) in the same Region you use for the other project resources.
  3. Repeat the same process for the image bucket (for example AWSACCOUNTNUMBER-medgemma-image-inputs).
  4. Update the S3_BUCKET_NAME variable with your model bucket name in envelope_encrypt_model.sh and run.sh.

Create an SQS queue

When images are uploaded to the S3 image bucket, they are sent to an SQS queue for processing in sequential order by the model running in the Nitro Enclave.

To create an SQS queue

  1. Sign in to the Amazon SQS console, choose Create queue, and follow the prompts to create a new SQS queue.
  2. Choose Standard Queue, provide a name, leave the rest as default, and choose Create queue.
  3. Replace the SQS_QUEUE_URL variable in image_processor.py and lambda_function.py (in the client and assets folder, respectively) with your URL.

Create a Lambda function

For image-based queries, MedGemma 4B expects images encoded in base64 format to be passed in the prompt. To convert the images to this format, a Lambda function is invoked using an Amazon S3 trigger when an image is uploaded to the bucket.

To create a Lambda function

  1. Sign in to the Lambda console, choose Create function, and follow the prompts to create a new Lambda function from scratch.
  2. Choose a name, choose a Python runtime (for example Python 3.13), and paste in the Lambda function code from the assets folder.
  3. Next, update the Lambda function’s IAM role in Permissions under the Configuration tab with access to your S3 image bucket and the SQS queue that you created with inline policy permissions. Attach the following policies:
    1. Amazon S3 policy:
      {
       "Version": "2012-10-17",
       "Statement": [
           {
               "Sid": "Statement1",
               "Effect": "Allow",
               "Action": [
                   "s3:*"
               ],
               "Resource": [
                   "arn:aws:s3:::<IMAGE_BUCKET_NAME>",
                   "arn:aws:s3:::<IMAGE_BUCKET_NAME>/*"
               ]
           }
       ]
      }

    2. Amazon SQS policy:
      {
       "Version": "2012-10-17",
       "Statement": [
           {
               "Sid": "VisualEditor0",
               "Effect": "Allow",
               "Action": "sqs:ListQueues",
               "Resource": "*"
           },
           {
               "Sid": "VisualEditor1",
               "Effect": "Allow",
               "Action": "sqs:*",
              "Resource": "arn:aws:sqs:<REGION>:<ACCOUNT_NUMBER>:<QUEUE_NAME>"
           }
       ]
      }

  4. Finally, within the Lambda Designer, add a trigger, choose Amazon S3, and choose your image bucket. You should see the following example when the trigger is enabled.

AWS Lambda configuration interface showing S3 bucket trigger setup for medical image processing workflow

Create a DynamoDB table

When the queries have been processed by the model for inference, the prompts and responses are logged to a DynamoDB table for auditing and message history purposes.

To create a DynamoDB table

  1. Sign in to the DynamoDB console, choose Create table, and follow the prompts to create a new DynamoDB table.
  2. Give it a partition key named ID as a String type.
  3. Replace the TABLE_NAME variable with the table name and REGION variable with your AWS Region in direct_query.py and image_processor.py files.

Create an AWS KMS key

An AWS KMS key is used to envelope-encrypt the model artifacts before they are uploaded to the S3 model bucket. During encryption, the AWS KMS key policy is configured with conditions that restrict decryption to only those Nitro Enclaves presenting a valid attestation document. This attestation includes platform configuration registers (PCR) hashes that represent the measured state of the Nitro Enclave, which covers the signed Nitro Enclave image, runtime, and configuration. When the Nitro Enclave is launched, it generates an attestation document signed by the Amazon EC2 Nitro hypervisor, proving that its PCR values match the expected trusted measurements defined in the AWS KMS key policy. The key is released only if these PCR hashes align and the attestation is verified by AWS KMS, allowing the Nitro Enclave to decrypt and load the model securely in memory.

To create an AWS KMS key

  1. Sign in to the AWS KMS console, choose Create key, and follow the prompts to create a new AWS KMS key.
  2. Choose Symmetric as the key type and Encrypt and decrypt for the key usage. Make the alias AppKmsKey. Leave the default settings and choose Finish.
  3. Replace the REGION variable in vsock-proxy.yaml in the client folder with your AWS Region.

Create an EC2 instance

Now that the necessary resources are set up, you can proceed to launch the EC2 instance and create the Nitro Enclave image. For this solution, a c7i.12xlarge instance with a 150 GB EBS volume is provisioned.

To launch an EC2 instance with Nitro Enclaves enabled

  1. Within the GitHub repository on your local machine, run ./create_ec2.sh to create the EC2 instance.
cd scripts 
chmod +x create_ec2.sh 
./create_ec2.sh

  1. The script launches an EC2 instance called MedGemmaNitroEnclaveDemo. When the instance is running, you must create an IAM policy and add it to the Amazon EC2 IAM role with necessary permissions to the resources created previously.
  2. Sign in to the IAM console and navigate to Policies, choose Create policy, choose JSON, and paste the following policy, making sure that you update the bucket, queue URL, AWS Region, account number, and table variables:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "s3modelbucket",
      "Effect": "Allow",
      "Action": [
        "s3:*"
      ],
      "Resource": [
        "arn:aws:s3:::<MODEL_BUCKET_NAME>",
        "arn:aws:s3:::<MODEL_BUCKET_NAME>/*"
      ]
    },
    {
      "Sid": "dynamodb",
      "Effect": "Allow",
      "Action": [
        "dynamodb:*"
      ],
      "Resource": [
        "arn:aws:dynamodb:<REGION>:<ACCOUNT_NUMBER>:table/<TABLE_NAME>"
      ]
    },
    {
      "Sid": "sqslist",
      "Effect": "Allow",
      "Action": "sqs:ListQueues",
      "Resource": "*"
    },
    {
      "Sid": "sqsqueue",
      "Effect": "Allow",
      "Action": "sqs:*",
      "Resource": "arn:aws:sqs:<REGION>:<ACCOUNT_NUMBER>:<QUEUE_NAME>"
    }
  ]
}
  1. Give it a name (for example enclave-permissions) and choose Create policy.
  2. Navigate to Roles, choose Create role, choose EC2 as the AWS service for the Trusted entity type, then choose your policy that you created under Add permissions.
  3. Update your EC2 instance to use the role by going to the Security setting under the Actions dropdown, then modifying its IAM role.
  4. You can upload the modified repository to your EC2 instance using SCP. Alternatively, you can transfer the repository through rsync
rsync -avz -e "ssh -i /path/to/directory/sample-for-secure-medical-llm-inference-with-nitro-enclaves/nitro-enclave-key.pem" --exclude='*.pem' /path/to/directory/sample-for-secure-medical-llm-inference-with-nitro-enclaves/ ec2-user@<PUBLIC_IP>:~ 
cd sample-for-secure-medical-llm-inference-with-nitro-enclaves
  1. Make the scripts executable (in client, server and scripts).
chmod +x *.sh

Nitro Enclave setup

With Amazon EC2 loaded with the necessary scripts, you can begin building the Nitro Enclave image. During this process, the Docker container is converted into an Enclave Image File (EIF), which generates cryptographic measurements (PCR hashes) that uniquely identify the code and configuration of the enclave. These measurements are embedded into the AWS KMS key policy, creating a hardware-attested trust boundary that makes sure only this specific, unmodified Nitro Enclave can decrypt and access the model weights.

  1. Run the complete setup script, which sets up the client on the EC2 parent instance and the server running within the Nitro Enclave. You can observe the different scripts in the client, server, and scripts folders.
sudo ./run_complete_setup.sh
  1. The various scripts run to download the MedGemma 4B model, encrypt the model with the AWS KMS key, build a Docker image to run a llama.cpp server, start a Nitro Enclave, and decrypt and run the model. This process takes approximately 10 minutes.
  2. When the Nitro Enclave is running, it runs in debug mode so that you can observe the various startup logs outputted. Wait until llama.cpp server logs are outputted that indicate the server is ready and listening.

Inference examples

When the model is decrypted and running on the llama.cpp server within the Nitro Enclave, you can begin to invoke the model with either image or text-based queries. Open a new terminal session in your EC2 instance. You can navigate to the client folder to run the scripts for queries.

Image-based queries

For inference on medical images, upload an image to your Amazon S3 image bucket. When it is uploaded, run python3 image_processor.py to pass the image from the SQS queue to the Nitro Enclave for processing. The following are examples of image inputs and model outputs.

Brain CT scan:

Medical brain CT scan image showing anatomical structures in grayscale

Case courtesy of Dr Henry Knipe, Radiopaedia.org, rID: 46289

Model response:Complete processing log showing secure medical image analysis pipeline from upload through diagnostic outputChest X-ray:

Chest X-ray image in AP sitting position

Model response:Model inference logs showing automated chest X-ray analysis with detailed radiological findings and considerationsText-based queries

For inference on text-queries, run python3 direct_query.py "<YOUR_MEDICAL_QUERY>" to invoke the model. The following are examples of text-based inputs and model outputs.

Basic usage:

python3 direct_query.py "What are the symptoms of pneumonia?"

Model response:Model inference output describing pneumonia symptoms, diagnosis, and treatment optionsLab result interpretation:

python3 direct_query.py "Patient has elevated troponin levels (15.2 ng/mL), elevated CK-MB, and ST elevation in leads II, III, aVF. What does this suggest?"

Model response:Model inference output analyzing cardiac lab results and ECG findings

Cleaning up

To avoid incurring future charges, delete the resources used in this solution:

  1. Stop and terminate the EC2 instance.
  2. Empty and delete the S3 buckets.
  3. Delete the DynamoDB table.
  4. Delete the SQS queue.
  5. Delete the AWS KMS Key.
  6. Delete the Lambda function.

Conclusion

You can combine the isolation and attestation capabilities of AWS Nitro Enclaves, the encryption controls of AWS KMS, and the scalability of services such as Amazon S3, Amazon SQS, and Amazon DynamoDB to build a more secure, zero trust pipeline for deploying generative AI models in healthcare. Using Google MedGemma 4B as your reference medical LLM, you can enable privacy-preserving inference where both PHI and model intellectual property remain protected. For more information, consult the following resources:

Lifecycle Rules: Now Supported Through S3-Compatible APIs

Post Syndicated from Bala Krishna Gangisetty original https://www.backblaze.com/blog/lifecycle-rules-now-supported-through-s3-compatible-apis/

A decorative image showing a cloud, gears, and an alarm notification.

Managing object lifecycles is one of the simplest ways to control storage costs, keep buckets organized, and automate data hygiene. Backblaze B2 has supported lifecycle rules for years through our B2 Native APIs and the web application. Today, we’re expanding that support by adding S3 compatible lifecycle rule APIs, making it easier for you to use S3 tools and workflows to manage your data on Backblaze B2 (check out the docs: S3 Put Lifecycle Configuration, S3 Get Lifecycle Configuration, S3 Delete Lifecycle Configuration). This provides you with more flexibility and control over object management—all with Backblaze’s signature simplicity and affordability.

New survey: The Hidden Cost of Cloud Storage

We surveyed over 400 IT decision makers and one thing stood out. Surprise charges affect almost everyone. Learn what’s driving them—and how to avoid them.

Download the Report

What’s new

You can now create, edit, and manage lifecycle rules on B2 Cloud Storage using standard S3 compatible APIs, including:

Lifecycle rules can be applied to:

  • Entire buckets
  • Specific prefixes (e.g., logs/, images/monkeys/)
  • Nested folders with overlapping logic (e.g., animals/ and animals/cows/)

Why this matters

1. Seamless migrations from AWS

If you’re moving workloads from AWS S3, you can bring your existing lifecycle configurations with minimal changes. This reduces work while migrating your workloads to Backblaze B2.

2. More flexibility for complex data structures 

With support for nested and overlapping prefixes, you can apply precise expiration rules to different datasets with overlapping prefixes in the same bucket. Whether you’re managing rapidly changing logs or long-term archives, lifecycle rules allow more controlled, automated retention.

3. Increased functionality for multi-cloud architectures 

For teams looking to capitalize on multi-cloud architecture, this means more seamless integration up and down the stack.

4. Cost optimization

We apply the most cost-saving configuration for you in case of overlapping rules.

How it works

S3 compatible lifecycle rules define automated actions based on object age or status. With Backblaze B2, you can use rules to:

  • Delete objects after a set number of days
  • Hide objects after a set number of days
  • Expire noncurrent versions
  • Delete multipart uploads that are incomplete for a set number of days
  • Set multiple rules for nested prefixes for granular control

For example:

<LifecycleConfiguration>
<Rule>
<ID>DeleteTempFiles</ID>
<Status>Enabled</Status>
<Filter>
<Prefix>temp/</Prefix>
</Filter>
<Expiration>
<Days>30</Days>
</Expiration>
</Rule>
</LifecycleConfiguration>

This configuration automatically hides objects under temp/ after 30 days.

Example use cases

  1. Automated cleanup for short-lived objects: Temporary files, build artifacts, or test data can expire automatically after a given retention period.
  2. Compliance-driven policies: Organizations with strict retention and deletion requirements can enforce rules consistently across buckets.
  3. Automated cleanup of incomplete multipart uploads: Save money by removing partial upload fragments that were never completed due to network interruptions, client failures, or abandoned sessions automatically. 
  4. Tiered retention for nested prefixes: Allow broad retention for the general dataset while enforcing a faster cleanup cycle for a particular subset that changes more frequently or has lower long-term value. For example, you can apply a 30-day expiration rule to all objects under the prefix temp/, while assigning a shorter 7-day expiration rule to the more specific prefix temp/webserver/. 

How it complements existing B2 Lifecycle Rules

Backblaze continues to support lifecycle rules through the B2 Native API, which many customers use today. The new S3 compatible support offers an additional path for lifecycle automation, especially for customers with S3 style infrastructure or tooling.

Although both S3 compatible and B2 Native lifecycle rules can coexist, we strongly recommend using a single method depending on your workflow preferences to manage lifecycle rules. 

Getting started

You can begin using lifecycle rules today through:

  • S3 compatible SDKs
  • S3 CLI tools
  • Direct API calls

Refer to Backblaze S3 Compatible API documentation for more details, specifically:

Most customers can apply their existing AWS lifecycle rules directly, without modification. 

Availability

S3 compatible lifecycle rules are now available. 

Wrapping up

Lifecycle rules help automate routine object cleanup and give teams predictable control over object retention. With the addition of S3 compatible lifecycle APIs, Backblaze B2 makes it even easier for customers to bring their existing S3 workflows to our platform while continuing to use the lifecycle management strategies they already trust.

Get started with Backblaze today by signing up for an account or contacting Sales. 

The post Lifecycle Rules: Now Supported Through S3-Compatible APIs appeared first on Backblaze Blog | Cloud Storage & Cloud Backup

Meet digital sovereignty needs with AWS Dedicated Local Zones expanded services

Post Syndicated from Max Peterson original https://aws.amazon.com/blogs/security/meet-digital-sovereignty-needs-with-aws-dedicated-local-zones-expanded-services/

At Amazon Web Services (AWS), we continue to invest in and deliver digital sovereignty solutions to help customers meet their most sensitive workload requirements. To address the regulatory and digital sovereignty needs of public sector and regulated industry customers, we launched AWS Dedicated Local Zones in 2023, with the Government Technology Agency of Singapore (GovTech Singapore) as our first customer.

Today, we’re excited to announce expanded service availability for Dedicated Local Zones, giving customers more choice and control without compromise. In addition to the data residency, sovereignty, and data isolation benefits they already enjoy, the expanded service list gives customers additional options for compute, storage, backup, and recovery.

Dedicated Local Zones are AWS infrastructure fully managed by AWS, built for exclusive use by a customer or community, and placed in a customer-specified location or data center. They help customers across the public sector and regulated industries meet security and compliance requirements for sensitive data and applications through a private infrastructure solution configured to meet their needs. Dedicated Local Zones can be operated by local AWS personnel and offer the same benefits of AWS Local Zones, such as elasticity, scalability, and pay-as-you-go pricing, with added security and governance features.

Since being launched, Dedicated Local Zones have supported a core set of compute, storage, database, containers, and other services and features for local processing. We continue to innovate and expand our offerings based on what we hear from customers to help meet their unique needs.

More choice and control without compromise

The following new services and capabilities deliver greater flexibility for customers to run their most critical workloads while maintaining strict data residency and sovereignty requirements.

New generation instance types

To support complex workloads in AI and high-performance computing, customers can now use newer generation instance types, including Amazon Elastic Compute Cloud (Amazon EC2) generation 7 with accelerated computing capabilities.

AWS storage options

AWS storage options provide two storage classes including Amazon Simple Storage Service (Amazon S3) Express One Zone, which offers high-performance storage for customers’ most frequently accessed data, and Amazon S3 One Zone-Infrequent Access, which is designed for data that is accessed less frequently and is ideal for backups.

Advanced block storage capabilities are delivered through Amazon Elastic Block Store (Amazon EBS) gp3 and io1 volumes, which customers can use to store data within a specific perimeter to support critical data isolation and residency requirements. By using the latest AWS general purpose SSD volumes (gp3), customers can provision performance independently of storage capacity with an up to 20% lower price per gigabyte than existing gp2 volumes. For intensive, latency-sensitive transactional workloads, such as enterprise databases, provisioned IOPS SSD (io1) volumes provide the necessary performance and reliability.

Backup and recovery capabilities

We have added backup and recovery capabilities through Amazon EBS Local Snapshots, which provides robust support for disaster recovery, data migration, and compliance. Customers can create backups within the same geographical boundary as EBS volumes, helping meet data isolation requirements. Customers can also create AWS Identity and Access Management (IAM) policies for their accounts to enable storing snapshots within the Dedicated Local Zone. To automate the creation and retention of local snapshots, customers can use Amazon Data Lifecycle Manager (DLM).

Customers can use local Amazon Machine Images (AMIs) to create and register AMIs while maintaining underlying local EBS snapshots within Dedicated Local Zones, helping achieve adherence to data residency requirements. By creating AMIs from EC2 instances or registering AMIs using locally stored snapshots, customers maintain complete control over their data’s geographical location.

Dedicated Local Zones meet the same high AWS security standards and sovereign-by-design principles that apply to AWS Regions and Local Zones. For instance, the AWS Nitro System provides the foundation with hardware- and software-level security. This is complemented by AWS Key Management Service (AWS KMS) and AWS Certificate Manager (ACM) for encryption management, Amazon Inspector, Amazon GuardDuty, and AWS Shield to help protect workloads, and AWS CloudTrail for audit logging of user and API activity across AWS accounts.

Continued innovation with GovTech Singapore

One of GovTech Singapore’s key focuses is on the nation’s digital government transformation and enhancing the public sector’s engineering capabilities. Our collaboration with GovTech Singapore involved configuring their Dedicated Local Zones with specific services and capabilities to support their workloads and meet stringent regulatory requirements. This architecture addresses data isolation and security requirements and ensures consistency and efficiency across Singapore Government cloud environments.

With the availability of the new AWS services with Dedicated Local Zones, government agencies can simplify operations and meet their digital sovereignty requirements more effectively. For instance, agencies can use Amazon Relational Database Service (Amazon RDS) to create new databases rapidly. Amazon RDS in Dedicated Local Zones helps simplify database management by automating tasks such as provisioning, configuring, backing up, and patching. This collaboration is just one example of how AWS innovates to meet customer needs and configures Dedicated Local Zones based on specific requirements.

Chua Khi Ann, Director of GovTech Singapore’s Government Digital Products division, who oversees the Cloud Programme, shared:
“The deployment of Dedicated Local Zones by our Government on Commercial Cloud (GCC) team, in collaboration with AWS, now enables Singapore government agencies to host systems with confidential data in the cloud. By leveraging cloud-native services like advanced storage and compute, we can achieve better availability, resilience, and security of our systems, while reducing operational costs compared to on-premises infrastructure.”

Get started with Dedicated Local Zones

AWS understands that every customer has unique digital sovereignty needs, and we remain committed to offering customers the most advanced set of sovereignty controls and security features available in the cloud. Dedicated Local Zones are designed to be customizable, resilient, and scalable across different regulatory environments, so that customers can drive ongoing innovation while meeting their specific requirements.

Ready to explore how Dedicated Local Zones can support your organization’s digital sovereignty journey? Visit AWS Dedicated Local Zones to learn more.

TAGS: AWS Digital Sovereignty Pledge, Digital Sovereignty, Security Blog, Sovereign-by-design, Public Sector, Singapore, AWS Dedicated Local Zones

Max Peterson
Max Peterson

Max is the Vice President of AWS Sovereign Cloud. He leads efforts to help public sector organizations modernize their missions with the cloud while meeting necessary digital sovereignty requirements. Max previously oversaw broader digital sovereignty efforts at AWS and served as the VP of AWS Worldwide Public Sector with a focus on empowering government, education, healthcare, and nonprofit organizations to drive rapid innovation.
Stéphane Israël
Stéphane Israël

Stéphane is the Managing Director of the AWS European Sovereign Cloud and Digital Sovereignty. He is responsible for the management and operations of the AWS European Sovereign Cloud GmbH, including infrastructure, technology, and services, and leads broader worldwide digital sovereignty efforts at AWS. Prior to AWS, he was the CEO of Arianespace, where he oversaw numerous successful space missions, including the launch of the James Webb Space Telescope.

[$] Best practices for linux-next

Post Syndicated from corbet original https://lwn.net/Articles/1050027/

One of the key components in the kernel’s development process is the
linux-next repository. Every day, a large number of branches, each
containing commits intended for the next kernel development cycle, is
pulled into linux-next and integrated. If there are conflicts between
branches, the linux-next process will reveal them. In theory, many other
types of problems can be found as well. Some developers feel that
linux-next does not work as well as it could, though. At the 2025
Maintainers Summit, Mark Brown, who helps to keep linux-next going, led a
session on how it could be made to work more effectively.

Гласовете на Америка – брой 10

Post Syndicated from Йоанна Елми original https://www.toest.bg/glasovete-na-amerika-broy-10/

Гласовете на Америка – брой 10

През изминалата седмица администрацията на Доналд Тръмп публикува документ, който предефинира стратегията за национална сигурност на страната в синхрон с приоритетите на президента и неговите идеологически и политически цели. Новата стратегия предизвика вълна от коментари – журналистически, експертни, дипломатически. Консенсусът е, че документът очертава най-сериозната промяна във външната политика на САЩ от края на Втората световна война насам. Така ли е обаче в действителност и какво всъщност ни казва той? 

Какво е Стратегията за национална сигурност? 

Стратегията за национална сигурност се изготвя периодично от изпълнителната власт на САЩ и изброява приоритетите и политиките в областта на националната сигурност, както и какви са плановете на администрацията за справяне с основни проблеми. Изначалната цел на документа е да насочи визията на изпълнителната власт към законодателната власт, както и да легитимира последващи бюджетни искания например. 

Освен това той очертава стратегията и визията на САЩ както пред международната общност, така и пред нацията – администрацията често цели да покаже на избирателите, че припознава проблемите, които ги вълнуват, и че предлага смислена и дългосрочна стратегия, в която избирателят да се припознае. Документът е и инструмент за постигане на вътрешен консенсус по отношение на външната политика, като има и символичен характер – изразява позицията на президента и основните му послания към американците. 

В случаи, когато гореизброените не са основно застъпени в президентската кампания предходната година,

Стратегията за национална сигурност се счита за значима заявка към избирателите и към новоназначените федерални служители, които придобиват представа в каква посока ще работи кабинетът през идния мандат.

Документът помага и за координиране между федералните агенции и департаменти, тъй като сред основните му цели е артикулирането на консенсус относно цялостната политика на правителството. 

Така например през 1991 г. Стратегията за национална сигурност за пръв път засяга екологичната катастрофа и рисковете пред околната среда. Стратегията след атаките на 11 септември 2001 г. чертае доктрината на президента Джордж Буш-младши за политиката му спрямо Близкия изток. А публикуваната от Обама през 2010 г. Стратегия – също смятана за радикално различна от тогавашното статукво – призовава за засилени връзки с Русия, Китай и Индия. 

Стратегията за национална сигурност на втората администрация на Тръмп 

предизвика полемики в няколко направления: òтказа Русия да бъде директно назована като риск за националната сигурност на страната; приоритизирането на Западното полукълбо като основна сфера на влияние на САЩ; заявката за балансирани отношения с Китай, както и остра промяна на позицията спрямо съюзниците в Западна Европа. 

Основна тема е съживяването и допълването на доктрината „Монро“, 

която определя обсега на политическите и геостратегическите интереси на САЩ в Северна и Южна Америка (Западното полукълбо) през по-голямата част от XIX и първата половина на XX век. Доктрината е изкована в контекста на имперска, колониална Европа, като целта ѝ е да предотврати превръщането на Америките в обект на колонизация за европейските империи, както и да осигури ненамеса в делата на съществуващите европейски колонии и територии, зависими от Европа. 

Доктрината „Монро“ е част от изолационистката традиция в САЩ, според която държавата следва политика на ненамеса във вътрешните работи на други държави, като същевременно защитава американските търговски интереси в региона. Очертана е през 1823 г., когато държавите от Латинска Америка са в процес на отвоюване на независимостта си от колониалното господство, а американците живо следят събитията и са солидарни с каузата за независимост (което не пречи на американската администрация да осъзнава интересите си в региона, включително по отношение на търговията). 

Отказът на президента Джеймс Монро да се намесва в европейските дела е свързан с нарастващата подкрепа за гръцка независимост (Гърция отвоюва независимостта си от Османската империя на 3 февруари 1830 г.). 

Повтаряне на историята, завръщане към историята или писане на нова история – 

това са три възможни интерпретации на втората стратегия за национална сигурност на Тръмп. От една страна, тя се вписва в исторически прецедент, като дори администрацията посочва, че президентът Тръмп прави своя принос към вече съществуващата доктрина „Монро“. От друга, документът прави заявка за нов курс в политиката на САЩ. Въпросът е дали е началото на нова глава в историята на световната геополитика, или просто назовава вече очевидни истини. 

Русия 

приветства новата стратегия като съответстваща на визията на Москва. „Адаптациите, които виждаме […] са в синхрон с нашата визия – заяви говорителят на Кремъл Дмитрий Песков. – Смятаме това за положителна промяна.“ 

За разлика от първия мандат на Тръмп, когато Русия бе назована като основен геополитически противник, във втората стратегия за национална сигурност на американския президент липсва критика към Русия, която за пръв път не е очертана като държава съперник на САЩ. Вместо това има остри критики към Европа (както и формулировката „множество европейци смятат Русия за заплаха за съществуването на континента“), която е обвинена, че не полага достатъчно усилия за осигуряване на мир след нахлуването на Русия на територията на Украйна през 2022 г. САЩ поставят акцента върху сътрудничеството между водещите световни сили. В Стратегията се подчертава, че оцеляването на Украйна като суверенна държава е важно, важно е и нейното възстановяване, но не се казва нищо конкретно как ще бъдат постигнати тези цели. 

Сближаването с авторитарни режими 

се изразява не само в промяната на отношението спрямо Русия, но и в преориентирането спрямо Китай и Близкия изток, който вече не е регион от основна значимост за американската политика. Това съответства на предишни заявки на администрацията, например по време на речта на Тръмп в Рияд, когато президентът заяви, че Америка вече няма да се намесва във вътрешните работи на Близкия изток. Според Стратегията военното присъствие на САЩ също ще бъде изместено от региона към борбата с наркотрафика в Западното полукълбо. 

В новата стратегия изобщо не се споменава Северна Корея и се омаловажава заплахата от Иран – традиционни противници на САЩ.

Относно съседите в Латинска Америка става ясно, че „не бива да игнорираме държави с различни идеологически възгледи от нашите, с които независимо от това имаме общ интерес“. Целта е стабилно и добре управлявано Западно полукълбо; никъде не се казва, че демокрацията е условие за съществуването на такова. 

Колкото до Западното полукълбо, 

както и по отношение на цялостната стратегия, въпросите са повече от отговорите: какво ще се случи например, ако държавите от Латинска Америка нямат желание да си сътрудничат със САЩ и да поемат курса на новата американска политика? Следва ли да бъдат задължени? Във време на търговските войни и употребяване на мигрантите като разменна монета, както и на откритите изказвания и опити за влияние върху националните избори (президентът Тръмп подкрепи десния кандидат-президент на изборите в Хондурас и заплаши, че ще спре американската помощ за страната, ако неговият кандидат не спечели), отговорът е доста неясен. 

Спирането на миграцията към САЩ е приоритет на администрацията, като не е уточнено легална или нелегална миграция. В Стратегията се казва, че в идеалния случай гражданство на чужденци трябва да бъде давано сравнително рядко. Друга важна точка е борбата с „наркотерористите“ и използването на американска военна сила за справяне с „преки заплахи в нашето полукълбо“. Това силно вероятно задава цялостния тон на Стратегията за национална сигурност, която всъщност се изготвя от Министерството на отбраната (понастоящем преименувано на Министерство на войната), оглавявано от Пийт Хегсет – в момента обект на критика заради американски удари над цивилни край Венецуела. 

Според Уил Фриман, регионален експерт в Съвета за чуждестранни връзки, организираната престъпност в Западното полукълбо е сред основните причини за смъртността в САЩ и следва да бъде обект на национална сигурност. Фриман обаче допълва, че има и други мотиви: регионът е богат на ресурси и добре позициониран с оглед на снабдяването на САЩ в икономическата надпревара с Китай. Китайците също упражняват влияние в региона чрез търговски връзки и дигитална инфраструктура, което е акцентирано и в Стратегията. Фриман обаче смята, че документът по-скоро поставя акцент върху региона като рисков, отколкото като източник на възможности, а външната политика се върти около овладяването на проблемни според администрацията звена: масовата миграция, организираната престъпност и злонамереното чуждо влияние. 

Промяната в ориентацията спрямо Китай 

също е очевидна, най-вече за специалистите, които отчитат както разликите между стратегиите на двете администрации на Тръмп, така и спрямо досегашната политика на САЩ. Стратегията призовава съюзниците в региона за помощ в стабилизирането на отношенията между Китай и Тайван, но и извежда като основна цел „взаимноизгодно икономическо сътрудничество с Пекин“ – пълен завой както от първия мандат, така и от общата реторика на Тръмп, който бе избран и благодарение на крайните си изказвания спрямо Китай и който допреди месеци заявяваше уверено, че ще подчини китайците чрез търговска война. 

Предходната стратегия на първата администрация на Тръмп описваше Китай като пълна противоположност на САЩ – конкурент както от икономическа и геополитическа, така и от идеологическа гледна точка. Настоящата стратегия дава предимство на икономическата полза, а Китай е споменат чак в последните страници на документа, и то основно като пазарен съперник без оглед на стратегическите рискове, които биха могли да представляват евентуалнoто сближаване и икономически ползи. Стратегията не отчита и че Китай има интерес в регионите, където Америка планира да намали влиянието си, например Близкия изток.

Виновна е Европа, 

с която няма нито планове за икономически изгодно сътрудничество, нито за ненамеса във вътрешните работи, независимо от идеологията и формата на управление на държавите. Напротив, по отношение на Стария континент Стратегията на Тръмп е силно идеологически политизирана и повтаря клишетата на консервативното дясно: Европа цензурира и потиска политическата опозиция (винаги дясноконсервативна); континентът е икономически и военно слаб, както и застрашен от „цивилизационно унищожение“. Европейците игнорират „западните“ ценности (вероятно тук разбирани като националконсервативните ценности) и „губят европейската си идентичност“ поради завишена миграция и ниска раждаемост. Европейският съюз пък подкопава политическата свобода и суверенитета, затова в Стратегията се насърчава гласуването за десни и крайнодесни сили (патриотични) с цел устояване на тези тенденции. 

На мушката е основно Западна Европа, което е точно толкова лоша новина и за Източна и Южна Европа с оглед на това, че администрацията на Тръмп видимо търси съюз с автократи, клептократи и силно компрометирани лидери в региона. Приемането на нови членки в НАТО също е поставено под въпрос. Макар че Стратегията признава икономическата значимост на Европа, най-вече спрямо Китай, тя игнорира факта, че Китай е също толкова активен на Балканите, които са и по-уязвими на външно влияние. 

Много думи – малко стратегия 

На Африка са отделени няколко параграфа, които също оставят много въпросителни. В Стратегията се изразява желание да се работи със „способни, надеждни партньори“, но както и навсякъде другаде по света, подобни партньори не могат да съществуват без среда с прозрачно управление, върховенство на правото и борба с корупцията – звена, които привидно се влошават под управлението на Тръмп дори на национално ниво в САЩ. 

Експертите са единодушни, че документът има грешна мишена – европейските съюзници, а не държавите, които действително представляват риск за САЩ. Документът е пълен с неоснователни твърдения и вътрешни противоречия, за което специалисти от CATO Institute (един от големите тинктанкове във Вашингтон с либертариански уклон) казват, че е очаквано, имайки предвид колко е трудно да се създаде добра стратегия в силно политизирана, импулсивна, хаотична и опортюнистична администрация. 

Ако трябва да обобщим Стратегията за национална сигурност на втората администрация на Тръмп в няколко думи, те биха били: личности над принципи и пари над всичко, откровено заявено като държавна политика. Вече няма злодеи (Русия, Китай), няма добри, няма и общи ценности – има взаимноизгодни сътрудничества. И във всички случаи, много малко информация какъв всъщност е планът за стигане от точка А до точка Б. 

Възможните интерпретации са три. 

Най-положителната е, че САЩ се обръщат към националния си интерес на всяка цена – дори на цената на ценни съюзи и дългосрочно демократично управление. 

Втората е, че администрацията на Тръмп е кулминация на последното десетилетие фанатизъм и идеологизиране и че последствията от такава политика нямат значение, поне засега, стига да побеждават „правилната“ страна и правилните ценности. Дори те да нямат нищо общо с реалността.  

Третата е, че администрацията на Тръмп е началото на превръщането на държавата в корпорация, на политиката в бизнес, на ценностите в разменна монета в зависимост от случая. 

Според някои безцеремонното представяне на Стратегията – късно вечерта, без съпътстващи речи от президента или съветниците по национална сигурност – подсказва, че за Белия дом документът вероятно не е от особена важност, нито изразява стратегическо намерение. Други виждат в него просто потвърждение на очевидния курс, по който е поела администрацията. 

Възможните интерпретации са три. И те в никакъв случай не се изключват взаимно. 


Абонирайте се, за да получавате този бюлетин на електронната си поща в момента, в който излезе!

Вече сте регистриран потребител на Toest.bg? Може директно от настройките на бюлетините в своя профил да изберете „Гласовете на Америка“ или да натиснете бутона по-долу:

Още нямате профил в Toest.bg? Регистрирайте се само с няколко клика:


Secondary school maths showing that AI systems don’t think

Post Syndicated from Jane Waite original https://www.raspberrypi.org/blog/secondary-school-maths-showing-that-ai-systems-dont-think/

At a time when many young people are using AI for personal and learning purposes, schools are trying to figure out what to teach about AI and how (find out more in this summer 2025 data about young people’s usage of AI in the UK). One aspect of this is how technical we should get in explaining how AI works, particularly if we want to debunk naive views of the capabilities of the technology, such as that AI tools ‘think’. In this month’s research seminar, we found out how AI contexts can be added to current classroom maths to make maths more interesting and relevant while teaching the core concepts of AI.

Prof. Dr. Martin Frank, Assistant Prof. Dr. Sarah Schönbrodt, Research Associate Stephan Kindler
Prof. Dr. Martin Frank, Assistant Prof. Dr. Sarah Schönbrodt, Research Associate Stephan Kindler

At our computing education research seminar in July, a group of researchers from the CAMMP (Computational and Mathematical Modeling Program) research project shared their work:

  • Prof. Dr. Martin Frank, Founder of CAMMP (Karlsruhe Institute of Technology (KIT), Germany).
  • Assistant Prof. Dr. Sarah Schönbrodt (University of Salzburg, Austria)
  • Research Associate Stephan Kindler (Karlsruhe Institute of Technology (KIT), Germany)

They talked about how maths already taught in secondary schools can be used to demystify AI. At first glance, this seems difficult to do, as it is often assumed that school-aged learners will not be able to understand how these systems work. This is especially the case for artificial neural networks, which are usually seen as a black box technology — they may be relatively easy to use, but it’s not as easy to understand how they work. Despite this, the Austrian and German team have developed a clear way to explain some of the fundamental elements of AI using school-based maths.

Sarah Schönbrodt started by challenging us to consider that learning maths is an essential part in developing AI skills, as: 

  1. AI systems using machine learning are data-driven and are based on mathematics, especially statistics and data
  2. Authentic machine learning techniques can be used to bring to life existing classroom maths concepts
  3. Real and relevant problems and associated data are available for teachers to use

A set of workshops for secondary maths classrooms

Sarah explained how the CAMMP team have developed a range of teaching and learning materials on AI (and beyond) with an overall goal to “allow students to solve authentic, real and relevant problems using mathematical modeling and computers”. 

She reflected that much of school maths is set in contexts that are abstract, and may not be very interesting or relevant to students. Therefore, introducing AI-based contexts, which are having a huge impact on society and students’ lives, is both an opportunity to make maths more engaging and also a way to demystify AI.

A glance at the schoolbook diagram
Old-fashioned contexts are often used to teach classroom maths concepts. Those same concepts could be taught using real-world AI contexts. (Slide from the researchers’ presentation.)

Workshops designed and researched by the team include contexts such as privacy in social networks to learn about decision trees, personalised Netflix recommendations to learn about k-nearest neighbour, word predictions to learn about N-Grams, and predicting life expectancy to learn about regression and neural networks.

Learning about classification models: traffic lights and the support vector machine

For the seminar, Sarah walked through the steps to learn about support vector machines. This is an upper secondary workshop for students aged 17 to 18 years old. The context of the lesson is an image problem — specifically, classifying the data representing the colours of a simplified traffic light system (two lights to start with) to work out if a traffic light is red or green.

She walked through each of the steps of the maths workshop:

  • Plotting data points of two classes, the representation of green and red traffic lights
  • Finding a line that best separates the data points of both classes
  • Figuring out what best is
  • Classifying the data points in relation to the chosen (separating) line
  • Validating the model statistically to see if it is useful in classifying new data points, including using test data and creating a contingency table (also called a confusion matrix)
  • Discussing limitations, including social and ethical issues
  • Explaining how three traffic lights can be expressed as three-dimensional data by using planes
Classification problems diagram
By classifying green and red traffic light data, students are learning about lines, classifying data, and considering limitations. (Slide from the researchers’ presentation.)

Throughout the presentation, Sarah pointed out where the maths taught was linked to the Austrian and German mathematics curriculum.

Classification problems diagram
Learning about planes, separating planes, and starting to see how data can be represented in vectors. (Slide from the researchers’ presentation.)

Learning about social and ethical issues

Learning about the social and ethical issues in data-driven systems. (Slide from the researchers’ presentation.)

As well as learning about lines, planes, distances, dot product and statistical measures, learners are also engaged in discussing the social and ethical issues of the approach taken. They are encouraged to think about bias, data diversity, privacy, and the impact of errors on people. For example, if the model wrongly predicts a light as green when it is red, then an autonomous car would run through a red traffic light. This would likely be a bigger consequence than stopping at a green traffic light that was mis-predicted as red. So should the best line reduce this kind of error?

To teach the workshops, Sarah explained they have developed interactive Jupyter notebooks, where no programming skills are needed. Students fill in the gaps of example code, explore simulations, and write their ideas for discussion for the whole class. No software needs to be installed, feedback is direct, and there are in-depth tasks and staggered hints.

Learning about regression models: Weather forecasting and the toy artificial neural network

Stephan went on to introduce artificial neural networks (ANNs), which are the basis of generative AI applications like chatbots and image generation systems. He focused on regression models, such as those used in weather forecasting. 

ANNs are very complex. Therefore, to start to understand the fundamentals of this technology, he introduced a ‘toy ANN’ with one input, three nodes, and one output. A function is performed on the input data at each node. With the toy network, the team wants to tackle a major and common misconception: that students think that ANN systems learn, recognise, see, and understand, when really it’s all just maths.

Tackling misconceptions about ANNs by exploring how they work in a toy version. (Slide from the researchers’ presentation.)

The learning activity starts by looking at one node with one input and one output, and can be described as a mathematical function, with a concatenation of two functions (in this case a linear and activation function). Stephan shared an online simulator that visualises how the toy neural network can be explored as students change two parameters (in this case, weight and bias of the functions). Students then look at the overall network, and the way that the output from the three nodes is combined. Again, they can explore this in the simulator. Students compare simple data about weather prediction to the model, and discover they need more functions — more nodes to better fit the data. The activity helps students learn that ANN systems are just highly adjustable mathematical functions that, by adding nodes, can approximate relationships in a given data set. But the approximation only works in the bounds (intervals) in which data points are given, showing that ANNs do not ‘understand’ or ’know’ — it’s just maths.

Stephen finished by explaining the mutual benefits of AI education and maths education. He suggested maths will enable a deeper understanding of AI, and give students a way to realistically assess the opportunities and risks of AI tools and show them the role that humans have in designing AI systems. He also explained that classroom maths education can benefit from incorporating AI contexts. This approach highlights how maths underpins the design and understanding of everyday systems, supports more effective teaching, and promotes an interdisciplinary way of learning across subjects.

Some personal reflections — which may not be quite right!

I have been researching the teaching of AI and machine learning for around five years now, since before ChatGPT and other similar tools burst on the scene. Since then, I have seen an increasing number of resources to teach about the social and ethical issues of the topic, and there are a bewildering number of learning activities and tools for students to train simple models. There are frameworks for the data lifecycle, and an emerging set of activities to follow to prepare data, compare model types, and deploy simple applications. However, I felt the need to understand and to teach about, at a very simple level, the basic building blocks of data-driven technologies. When I heard the CAMMP team present their work at the AIDEA conference in February 2025, I was entirely amazed and I asked them to present here at our research seminar series. This was a piece of the puzzle that I had been searching for — a way to explain the ‘bottom of the technical stack of fundamental concepts’. The team is taking very complex ideas and reducing them to such an extent that we can use secondary classroom maths to show that AI is not magic and AI systems do not think. It’s just maths. The maths is still hard, and teachers will still need the skills to carefully guide students step by step so they can build a useful mental model. 

Photo of a class of students at computers, in a computer science classroom.

I think we can simplify these ideas further, and create unplugged activities, simulations, and ways for students to explore these basic building blocks of data representation, as well as classification and representing approximations of complex patterns and prediction. I can sense the beginnings of new ideas in computational thinking, though they’re still taking shape. We’re researching these further and will keep you updated.

Finding out more

If you would like to find out more about the CAMMP resources, you can watch the seminar recording, look at the CAMMP website or try out their online materials. For example, the team shared a link to the jupyter notebooks they use to teach the workshops they demonstrated (and others). You can use these with a username of ‘cammp_YOURPSEUDONYM’, where you can set ‘YOURPSEUDONYM’ to any letters, and you can choose any password. They also shared their toy ANN simulation.
The CAMMP team are not the only researchers who are investigating how to teach about AI in maths lessons. You can find a set of other research papers here.

Join our next seminar

In our current seminar series, we’re exploring teaching about AI and data science. Join us at our last seminar of the series on Tuesday, 27 January 2026 from 17:00 to 18:30 GMT to hear Salomey Afua Addo talk about using unplugged approaches to teach about neural networks.

To sign up and take part, click the button below. We’ll then send you information about joining. We hope to see you there.

The schedule of our upcoming seminars is online. You can catch up on past seminars on our previous seminars page.

The post Secondary school maths showing that AI systems don’t think appeared first on Raspberry Pi Foundation.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1050251/

Security updates have been issued by AlmaLinux (firefox, luksmeta, mysql, mysql:8.0, mysql:8.4, tomcat, and wireshark), Debian (chromium, kernel, and tzdata), Fedora (brotli, dr_libs, perl-Alien-Brotli, python-urllib3, singularity-ce, wireshark, and yarnpkg), Oracle (firefox, grafana, lasso, libsoup3, luksmeta, ruby, ruby:3.3, tomcat, and wireshark), Slackware (mozilla), SUSE (container-suseconnect, kubernetes-client, libpoppler-cpp2, postgresql14, postgresql15, and python3), and Ubuntu (c-ares, keystone, linux, linux-aws, linux-aws-5.15, linux-azure, linux-gcp, linux-gcp-5.15,
linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15,
linux-intel-iotg, linux-intel-iotg-5.15, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra,
linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle,
linux-oracle-5.15, linux-xilinx-zynqmp, linux-azure, linux-azure-4.15, linux-oracle,, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-fips, linux-aws-fips, linux-gcp-fips, linux-hwe-6.8, linux-oracle-6.8, linux-raspi, linux-realtime, linux-intel-iot-realtime, and python-urllib3).

Идва ли освобождение след оставката?

Post Syndicated from Емилия Милчева original https://www.toest.bg/idva-li-osvobozhdenie-sled-ostavkata/

Идва ли освобождение след оставката?

В действителност протестиращите по площадите и улиците на България и Европа десетки хиляди български граждани не искаха оставката на правителството. Те искат освобождение от модела „Борисов – Пеевски“ и от мрежите му. Падането на правителството на Росен Желязков е само първият пробив в стената. 

Същинският оздравителен процес ще започне с изваждането от политиката на лидера на ГЕРБ Бойко Борисов и на санкционирания за корупция от САЩ и Великобритания олигарх Делян Пеевски. А тази работа може да свърши прокуратурата, ако пожелае да служи на държавността и да изпълнява функциите си на защитник на обществения интерес вместо на куче пазач на завладяната от „Борисов–Пеевски“ държавност. 

Формулата на бившата правосъдна министърка на Румъния Моника Маковей „Изчистете съдебната система и тя ще изчисти всичко останало“ не проработи в България.

Сега държавното обвинение е заключено в отколешните си зависимости – мудно и удобно за силните на деня. Но от него зависи ще има ли освобождение след оставката, или всичко ще остане само в периметъра на протестния шум. 

Също и от гражданската енергия – ще нарасне ли още до предсрочните парламентарни избори (вероятно през март), или ще спадне и как ще се трансформира в избирателна активност. Замлъкне ли улицата, избутаните в ъгъла на ринга бързо ще се окопитят и оставката ще е само моментен триумф.

„Все пак е победа, да се порадваме за малко“, казва таксиметровият шофьор, който със съжаление отбелязва, че не е успял за третия, най-многоброен протест, тъй като му се паднал дълъг курс извън София. Точно след този протест и преди гласуването на шестия вот на недоверие правителството подаде оставка, а премиерът Росен Желязков я мотивира с „гласа на народа“:

Ние, както заявихме нееднократно, чуваме гласа на гражданите, които протестират срещу управлението. Чуваме го осъзнато. Затова и трябва да бъдем на висотата на техните искания. Техните искания са за оставка на правителството. Това е настоящият момент. За оставката глас издигнаха и млади, и стари, хора от различни етноси, от различни религии.

51-вото Народно събрание няма да успее да произведе второ правителство, след като основните политически сили декларираха отказ да участват в преговори за нов кабинет. Както е тръгнало, няма да участват и в гласуването на редактирания проектобюджет за 2026 г., което означава, че поне до юни догодина държавата ще остане със старата финансова рамка, тоест с удължителен бюджет. Няма нови програми или увеличения на разходи (освен ако не се гласува отделно за извънредни ситуации), следователно в МВР, МО, ДАТО и навсякъде, където възнагражденията са увеличени, ще се запазят сегашните нива на заплащане.

Ако слушаме Борисов, ГЕРБ излиза от това 11-месечно управление с вдигната глава и след „брилянтни действия“. Също така нямало защо да се сърдят на „децата на площада“ – той като тийнейджър мечтаел семейният москвич да стане лада:

Защо им се сърдим, че искат да мечтаят? Да имат мечти. Я се замислете вие като сте били на тия години, за какво сте си мечтали. Аз дори съм благодарен, че Господ не ме е чул. Мечтата ми беше москвичът на татко да стане лада. Това ми беше и само си виках: „Ей, Господи, само това ми дай. Нищо друго няма да поискам. Една лада да карам аз.“ Това ми беше мечтата на тия години, 15–16–17. Те затова и площадът им е празник.

Изглежда, че Борисов е изключение от максимата „Човек е толкова голям, колкото големи са мечтите му“. Въпреки скромните дори и за социалистически младеж мечти, той създаде и оглави най-голямата партия в най-новата история на България, три пъти беше премиер, а футболният отбор „Витоша (Бистрица)“, в който играе, спечели тази година и купата при ветераните. 

За какво мечтае Борисов днес, е въпрос за 1 милион евро. В последния си трети мандат той караше гигантска тойота, през чийто отворен прозорец „разхвърляше“ пари като на селска сватба, все едно няма правила, програми, проекти за публичните средства.

„Зурлички“ навсякъде

Положението сега е „Борисов–Пеевски“ падна! Да живее „Борисов–Пеевски!“. Причината да се перифразират изрази от протокола на френския кралски двор е, че от всеки регулатор и институция надничат „зурлички“ – наложените от „Борисов–Пеевски“ и избрани от мнозинството кандидати. Те могат да бламират и провалят всяка смислена инициатива, а засега неуспешно „се справят“ с овладяване на ръста на цените.

За дългия път към промяната предупреди и съпредседателят на „Демократична България“ Ивайло Мирчев:

Кабинета го свалиха хората, които излязоха масово на площадите няколко пъти поред. […] Тази нова гражданска енергия, това връщане на гражданското общество всъщност беше правилният път. Но това е само първа стъпка към свалянето на кабинета. Но това е първа стъпка към разграждането на този модел.

Какво ще се случи с гражданската енергия до предсрочните избори (евентуално) през март, е в пряка връзка с действията след 1 януари. Повишението на цените има потенциал да разгневи гражданите и от протест за ценностите на демокрацията да преминат към социален. Тази промяна би предопределила и политическите сили, които ще се възползват от страховете на обществото и от неговия гняв.

Системата, която създава и укрепва на власт персони като Борисов и Пеевски, не е счупена – така че битката за нормална европейска България предстои. Поредната.

Политиците ще трябва да се равняват по гражданското недоволство. А на площадите хората идваха гневни поради различни причини, но с общ знаменател – несправедливост в разпределението на публичните средства, несправедливост в правораздаването, несправедливост в достъпа до услуги и възможности, които би трябвало да са универсални за всички. Държавата работи за малка група привилегировани и наказва останалите с бюрократичен произвол, несигурност и непрозрачност.

Предсрочните избори също така ще са тест за президентските наесен. Ще запази ли ГЕРБ преднина? Дали коалицията ПП–ДБ ще капитализира гражданската енергия и ще се утвърди като реален политически фактор преди президентския вот? Къде ще са Пеевски и неговото ДПС – Ново начало? Социологическо проучване на „Маркет Линкс“ им отрежда четвърто място с резултат 9,1%. В същото време ГЕРБ губи значителен дял от подкрепата си само за три месеца. Спадът от 22 на 17% е заради протестите, бюджет 2026 и кризата във властта.

Радев ще скочи ли?

За предстоящите парламентарни избори на Румен Радев ще му се наложи да напусне президентските покои и да скочи в бурния водовъртеж на политиката. Така предизборната кампания на вицето му Илияна Йотова ще започне с поемането на президентския пост. 

Ако иска избиратели, доскорошният държавен глава ще трябва да изостави патетичните обръщения към нацията и да стане интерактивен играч на политическата сцена. Президентът, който през последните години се позиционира като глас на гражданската енергия, има възможност да даде сигнал за продължаване на натиска върху модела „Борисов–Пеевски“. 

Досегашните му действия обаче показват предпазливост – изказванията са ясни, но реалните стъпки за подпомагане на реформаторските процеси са не просто оскъдни, а липсват. Въпреки това и ГЕРБ, и ПП–ДБ са уклончиви относно бъдещи съвместни действия с президентски проект. В този вакуум на доверие и разочарование Румен Радев стои на старта на изборната надпревара, за да се опита да се утвърди като ключов фактор в следващата политическа конфигурация. 

За българските демократи е добре да помнят, че всъщност е преоблечен Орбан.

Building Trustworthy AI Agents

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2025/12/building-trustworthy-ai-agents.html

The promise of personal AI assistants rests on a dangerous assumption: that we can trust systems we haven’t made trustworthy. We can’t. And today’s versions are failing us in predictable ways: pushing us to do things against our own best interests, gaslighting us with doubt about things we are or that we know, and being unable to distinguish between who we are and who we have been. They struggle with incomplete, inaccurate, and partial context: with no standard way to move toward accuracy, no mechanism to correct sources of error, and no accountability when wrong information leads to bad decisions.

These aren’t edge cases. They’re the result of building AI systems without basic integrity controls. We’re in the third leg of data security—the old CIA triad. We’re good at availability and working on confidentiality, but we’ve never properly solved integrity. Now AI personalization has exposed the gap by accelerating the harms.

The scope of the problem is large. A good AI assistant will need to be trained on everything we do and will need access to our most intimate personal interactions. This means an intimacy greater than your relationship with your email provider, your social media account, your cloud storage, or your phone. It requires an AI system that is both discreet and trustworthy when provided with that data. The system needs to be accurate and complete, but it also needs to be able to keep data private: to selectively disclose pieces of it when required, and to keep it secret otherwise. No current AI system is even close to meeting this.

To further development along these lines, I and others have proposed separating users’ personal data stores from the AI systems that will use them. It makes sense; the engineering expertise that designs and develops AI systems is completely orthogonal to the security expertise that ensures the confidentiality and integrity of data. And by separating them, advances in security can proceed independently from advances in AI.

What would this sort of personal data store look like? Confidentiality without integrity gives you access to wrong data. Availability without integrity gives you reliable access to corrupted data. Integrity enables the other two to be meaningful. Here are six requirements. They emerge from treating integrity as the organizing principle of security to make AI trustworthy.

First, it would be broadly accessible as a data repository. We each want this data to include personal data about ourselves, as well as transaction data from our interactions. It would include data we create when interacting with others—emails, texts, social media posts—and revealed preference data as inferred by other systems. Some of it would be raw data, and some of it would be processed data: revealed preferences, conclusions inferred by other systems, maybe even raw weights in a personal LLM.

Second, it would be broadly accessible as a source of data. This data would need to be made accessible to different LLM systems. This can’t be tied to a single AI model. Our AI future will include many different models—some of them chosen by us for particular tasks, and some thrust upon us by others. We would want the ability for any of those models to use our data.

Third, it would need to be able to prove the accuracy of data. Imagine one of these systems being used to negotiate a bank loan, or participate in a first-round job interview with an AI recruiter. In these instances, the other party will want both relevant data and some sort of proof that the data are complete and accurate.

Fourth, it would be under the user’s fine-grained control and audit. This is a deeply detailed personal dossier, and the user would need to have the final say in who could access it, what portions they could access, and under what circumstances. Users would need to be able to grant and revoke this access quickly and easily, and be able to go back in time and see who has accessed it.

Fifth, it would be secure. The attacks against this system are numerous. There are the obvious read attacks, where an adversary attempts to learn a person’s data. And there are also write attacks, where adversaries add to or change a user’s data. Defending against both is critical; this all implies a complex and robust authentication system.

Sixth, and finally, it must be easy to use. If we’re envisioning digital personal assistants for everybody, it can’t require specialized security training to use properly.

I’m not the first to suggest something like this. Researchers have proposed a “Human Context Protocol” (https://papers.ssrn.com/sol3/ papers.cfm?abstract_id=5403981) that would serve as a neutral interface for personal data of this type. And in my capacity at a company called Inrupt, Inc., I have been working on an extension of Tim Berners-Lee’s Solid protocol for distributed data ownership.

The engineering expertise to build AI systems is orthogonal to the security expertise needed to protect personal data. AI companies optimize for model performance, but data security requires cryptographic verification, access control, and auditable systems. Separating the two makes sense; you can’t ignore one or the other.

Fortunately, decoupling personal data stores from AI systems means security can advance independently from performance (https:// ieeexplore.ieee.org/document/ 10352412). When you own and control your data store with high integrity, AI can’t easily manipulate you because you see what data it’s using and can correct it. It can’t easily gaslight you because you control the authoritative record of your context. And you determine which historical data are relevant or obsolete. Making this all work is a challenge, but it’s the only way we can have trustworthy AI assistants.

This essay was originally published in IEEE Security & Privacy.

Т.Е. от Е.Т. – епизод 35

Post Syndicated from Тоест original https://www.toest.bg/t-e-ot-e-t-epizod-35/

Т.Е. от Е.Т. – епизод 35

Оставката е подадена от т.нар. министър-председател. Сега остава и да има за кого да гласуваме – и животът ще дойде по-хубав от песен.
Какво още? Е.Т. обобщава.


Следете видеорубриката на Елена Телбис за „Тоест“ и във Facebook, Instagram и TikTok.

The collective thoughts of the interwebz