<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=jueves+quack%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 05:21:29 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 05:21:29 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=jueves+quack%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=jueves+quack%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[viable/strict/1781213548: Add PyTorch QuACK GEMM epilogue adapter e.g FlexGemm (#186483)]]></title>
<description><![CDATA[Summary
Groundwork PR

Adds the hop
Adds the quack impl
Only supports pointwise
no aux buffers
All this to make follow up prs easier to review

sanity check

Notes for reviewer
API;
# Do be made public later
 from torch._higher_order_ops import flex_gemm

 out = flex_gemm(
     gemm_op,          ...]]></description>
<link>https://tsecurity.de/de/3591898/downloads/viablestrict1781213548-add-pytorch-quack-gemm-epilogue-adapter-eg-flexgemm-186483/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591898/downloads/viablestrict1781213548-add-pytorch-quack-gemm-epilogue-adapter-eg-flexgemm-186483/</guid>
<pubDate>Thu, 11 Jun 2026 23:46:46 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Summary</h2>
<p>Groundwork PR</p>
<ol>
<li>Adds the hop</li>
<li>Adds the quack impl</li>
<li>Only supports pointwise</li>
<li>no aux buffers</li>
<li>All this to make follow up prs easier to review</li>
</ol>
<p>sanity check<br>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/32754868/605346325-eafd7127-4584-4c1b-9349-668239f77727.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEyMTQ2OTAsIm5iZiI6MTc4MTIxNDM5MCwicGF0aCI6Ii8zMjc1NDg2OC82MDUzNDYzMjUtZWFmZDcxMjctNDU4NC00YzFiLTkzNDktNjY4MjM5Zjc3NzI3LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA2MTElMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNjExVDIxNDYzMFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWZmOTczOTlhZjIxNTNkMGI2ZDhiM2NhMjEwY2JkYzU1MWIyMmFiNTFjZDRkNzAzMTc2YmI5OTkxNDNlZGZmZTUmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.lMiiMggM2OhhBZSovIks6u2xVELAEmDnPU04PLDOX28"><img width="2000" height="349" alt="image" src="https://private-user-images.githubusercontent.com/32754868/605346325-eafd7127-4584-4c1b-9349-668239f77727.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODEyMTQ2OTAsIm5iZiI6MTc4MTIxNDM5MCwicGF0aCI6Ii8zMjc1NDg2OC82MDUzNDYzMjUtZWFmZDcxMjctNDU4NC00YzFiLTkzNDktNjY4MjM5Zjc3NzI3LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA2MTElMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNjExVDIxNDYzMFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWZmOTczOTlhZjIxNTNkMGI2ZDhiM2NhMjEwY2JkYzU1MWIyMmFiNTFjZDRkNzAzMTc2YmI5OTkxNDNlZGZmZTUmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.lMiiMggM2OhhBZSovIks6u2xVELAEmDnPU04PLDOX28" content-type-secured-asset="image/png"></a></p>
<h3>Notes for reviewer</h3>
<p>API;</p>
<div class="highlight highlight-source-python notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="# Do be made public later
 from torch._higher_order_ops import flex_gemm

 out = flex_gemm(
     gemm_op,          # torch.mm / torch.addmm / aten op overload expanded to a wider set scaled_mm, grouped friends
     gemm_args,        # tuple of tensor/scalar operands orignal args ot he base func
     epilogue_fn,      # Python fn over accumulator/result
     *,
     gemm_kwargs=None, # non-tensor kwargs only
     kernel_options={},  # dict of options, will be backend, fastmath, tune
 )
"><pre><span class="pl-c"># Do be made public later</span>
 <span class="pl-k">from</span> <span class="pl-s1">torch</span>.<span class="pl-s1">_higher_order_ops</span> <span class="pl-k">import</span> <span class="pl-s1">flex_gemm</span>

 <span class="pl-s1">out</span> <span class="pl-c1">=</span> <span class="pl-en">flex_gemm</span>(
     <span class="pl-s1">gemm_op</span>,          <span class="pl-c"># torch.mm / torch.addmm / aten op overload expanded to a wider set scaled_mm, grouped friends</span>
     <span class="pl-s1">gemm_args</span>,        <span class="pl-c"># tuple of tensor/scalar operands orignal args ot he base func</span>
     <span class="pl-s1">epilogue_fn</span>,      <span class="pl-c"># Python fn over accumulator/result</span>
     <span class="pl-c1">*</span><span class="pl-s1"></span>,
     <span class="pl-s1">gemm_kwargs</span><span class="pl-c1">=</span><span class="pl-c1">None</span>, <span class="pl-c"># non-tensor kwargs only</span>
     <span class="pl-s1">kernel_options</span><span class="pl-c1">=</span>{},  <span class="pl-c"># dict of options, will be backend, fastmath, tune</span>
 )</pre></div>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4604765393" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186483" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186483/hovercard" href="https://github.com/pytorch/pytorch/pull/186483">#186483</a><br>
Approved by: <a href="https://github.com/mlazos">https://github.com/mlazos</a>, <a href="https://github.com/eellison">https://github.com/eellison</a><br>
ghstack dependencies: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4633136494" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186944" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186944/hovercard" href="https://github.com/pytorch/pytorch/pull/186944">#186944</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/906979aa9de162759f996c8d859d5ec82d1faa79: Fix QuACK vendoring source and patch split (#186944)]]></title>
<description><![CDATA[Summary
Pointed quack at my upstream fork, pointing back to main and using patchsets as intended
Pull Request resolved: #186944
Approved by: https://github.com/slayton58]]></description>
<link>https://tsecurity.de/de/3591263/downloads/trunk906979aa9de162759f996c8d859d5ec82d1faa79-fix-quack-vendoring-source-and-patch-split-186944/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591263/downloads/trunk906979aa9de162759f996c8d859d5ec82d1faa79-fix-quack-vendoring-source-and-patch-split-186944/</guid>
<pubDate>Thu, 11 Jun 2026 18:32:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Summary</h2>
<p>Pointed quack at my upstream fork, pointing back to main and using patchsets as intended</p>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4633136494" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186944" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186944/hovercard" href="https://github.com/pytorch/pytorch/pull/186944">#186944</a><br>
Approved by: <a href="https://github.com/slayton58">https://github.com/slayton58</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/319ee4ea19c03438d7ae3c585bc65b11fb9dd266: Add PyTorch QuACK GEMM epilogue adapter (#186310)]]></title>
<description><![CDATA[Pull Request resolved: #186310
Approved by: https://github.com/slayton58
ghstack dependencies: #186284]]></description>
<link>https://tsecurity.de/de/3577017/downloads/trunk319ee4ea19c03438d7ae3c585bc65b11fb9dd266-add-pytorch-quack-gemm-epilogue-adapter-186310/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577017/downloads/trunk319ee4ea19c03438d7ae3c585bc65b11fb9dd266-add-pytorch-quack-gemm-epilogue-adapter-186310/</guid>
<pubDate>Sat, 06 Jun 2026 05:31:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4593729274" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186310" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186310/hovercard" href="https://github.com/pytorch/pytorch/pull/186310">#186310</a><br>
Approved by: <a href="https://github.com/slayton58">https://github.com/slayton58</a><br>
ghstack dependencies: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4592710704" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186284" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186284/hovercard" href="https://github.com/pytorch/pytorch/pull/186284">#186284</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/8e484e4c69687609eb77c451aa12baec25b04fe6: Bring in gemm kernels form quack and CI testing for patch set (#186284)]]></title>
<description><![CDATA[Summary
What does this do;

.github/workflows/quack-vendor-reproducibility.yml add a ci test that make sure the final checked in code is sha + patch set applied
fix patches from update
puts the sha as source of truth in the vendor.sh
adds gitattributes to minimize by default the vendored code -> ...]]></description>
<link>https://tsecurity.de/de/3574348/downloads/trunk8e484e4c69687609eb77c451aa12baec25b04fe6-bring-in-gemm-kernels-form-quack-and-ci-testing-for-patch-set-186284/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574348/downloads/trunk8e484e4c69687609eb77c451aa12baec25b04fe6-bring-in-gemm-kernels-form-quack-and-ci-testing-for-patch-set-186284/</guid>
<pubDate>Fri, 05 Jun 2026 06:31:28 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Summary</h2>
<p>What does this do;</p>
<ol>
<li>.github/workflows/quack-vendor-reproducibility.yml add a ci test that make sure the final checked in code is sha + patch set applied</li>
<li>fix patches from update</li>
<li>puts the sha as source of truth in the vendor.sh</li>
<li>adds gitattributes to minimize by default the vendored code -&gt; makes easier to review</li>
<li>expand vendor.sh to cover gemms need for flex gemm</li>
</ol>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4592710704" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186284" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186284/hovercard" href="https://github.com/pytorch/pytorch/pull/186284">#186284</a><br>
Approved by: <a href="https://github.com/slayton58">https://github.com/slayton58</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/137a3dbeb0e2632f8655c2452a1d3ebfef5218a6: [Native DSL] Register-resident topk for small K, small N (#184927)]]></title>
<description><![CDATA[Adds a second cutedsl topk kernel covering K in {16, 32}, where the
radix kernel can't run (K>=64) and one-CTA-per-row's launch overhead
dominates anyway. One warp per row, register-resident keys, no smem
or global staging - only the final K writes hit gmem.
Structurally similar to quack's small-...]]></description>
<link>https://tsecurity.de/de/3564611/downloads/trunk137a3dbeb0e2632f8655c2452a1d3ebfef5218a6-native-dsl-register-resident-topk-for-small-k-small-n-184927/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564611/downloads/trunk137a3dbeb0e2632f8655c2452a1d3ebfef5218a6-native-dsl-register-resident-topk-for-small-k-small-n-184927/</guid>
<pubDate>Tue, 02 Jun 2026 02:31:28 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Adds a second cutedsl topk kernel covering K in {16, 32}, where the<br>
radix kernel can't run (K&gt;=64) and one-CTA-per-row's launch overhead<br>
dominates anyway. One warp per row, register-resident keys, no smem<br>
or global staging - only the final K writes hit gmem.</p>
<p>Structurally similar to quack's small-K topk, but lossless: keys carry<br>
the full original index so output is bit-exact to aten on values with<br>
deterministic tie order, at the cost of lower throughput.</p>
<p>Dispatch in cutedsl_impl.py:</p>
<ul>
<li>K=16, N pow2 in [64, 2048]: register kernel</li>
<li>K=32, N=256:                register kernel</li>
<li>K in {64..1024} with existing radix N gates: radix</li>
<li>else: aten</li>
</ul>
<p>On B200: K=16 2.24x geomean (1.16-4.45x), K=32 1.04x geomean<br>
(1.00-1.45x), no regressions across the eligible (K, N, M) grid.</p>
<p>Test plan:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="python test/python_native/test_topk_cutedsl.py"><pre class="notranslate"><code>python test/python_native/test_topk_cutedsl.py
</code></pre></div>
<p>Authored by Claude.<br>
Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505704759" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184927" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/184927/hovercard" href="https://github.com/pytorch/pytorch/pull/184927">#184927</a><br>
Approved by: <a href="https://github.com/ngimel">https://github.com/ngimel</a><br>
ghstack dependencies: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505704501" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184926" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/184926/hovercard" href="https://github.com/pytorch/pytorch/pull/184926">#184926</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/d9ae411a24a7346c1140865b821b0a5e06b59c6e: Skip Quack RMSNorm override on ROCm and non-CUDA tensors (#185644)]]></title>
<description><![CDATA[Summary:
The Quack RMSNorm override in _native/ops/norm/rmsnorm_impl.py is selected for any tensor whose dtype is fp16/bf16/fp32 and whose torch.cuda.get_device_capability major is 9 or 10.
Two cases slip through that shouldn't:

ROCm builds (e.g. MI300x). get_device_capability on gfx942 returns ...]]></description>
<link>https://tsecurity.de/de/3558088/downloads/trunkd9ae411a24a7346c1140865b821b0a5e06b59c6e-skip-quack-rmsnorm-override-on-rocm-and-non-cuda-tensors-185644/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558088/downloads/trunkd9ae411a24a7346c1140865b821b0a5e06b59c6e-skip-quack-rmsnorm-override-on-rocm-and-non-cuda-tensors-185644/</guid>
<pubDate>Sat, 30 May 2026 02:30:56 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Summary:<br>
The Quack RMSNorm override in <code>_native/ops/norm/rmsnorm_impl.py</code> is selected for any tensor whose dtype is fp16/bf16/fp32 and whose <code>torch.cuda.get_device_capability</code> major is 9 or 10.</p>
<p>Two cases slip through that shouldn't:</p>
<ul>
<li>ROCm builds (e.g. MI300x). <code>get_device_capability</code> on gfx942 returns <code>major=9</code>, matching the H100 check, so the dispatcher routes to Quack - a CUTLASS/CUDA-only kernel that has no business running on AMD.</li>
<li>CPU tensors. <code>_is_supported</code> never checks <code>input.device.type</code>. When a CPU tensor is passed (e.g. during the FX <code>Interpreter.run</code> in <code>splitting/utils.py:remove_unexpected_type_cast</code>), <code>get_device_capability</code> reports the current CUDA device's capability, the cond passes, and the kernel crashes with <code>ValueError: Mismatched Tensor ... expected device_type=cuda</code>.</li>
</ul>
<p>Test Plan: This fixed 3 tests internally</p>
<p>Differential Revision: D106733305</p>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550209748" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/185644" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/185644/hovercard" href="https://github.com/pytorch/pytorch/pull/185644">#185644</a><br>
Approved by: <a href="https://github.com/desertfire">https://github.com/desertfire</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/rocm-mi300/181963]]></title>
<description><![CDATA[Support QuACK row reductions feeding main]]></description>
<link>https://tsecurity.de/de/3527535/downloads/ciflowrocm-mi300181963/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527535/downloads/ciflowrocm-mi300181963/</guid>
<pubDate>Tue, 19 May 2026 02:16:09 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Support QuACK row reductions feeding main</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/torchtitan/181963]]></title>
<description><![CDATA[Support QuACK row reductions feeding main]]></description>
<link>https://tsecurity.de/de/3527534/downloads/ciflowtorchtitan181963/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527534/downloads/ciflowtorchtitan181963/</guid>
<pubDate>Tue, 19 May 2026 02:16:08 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Support QuACK row reductions feeding main</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/inductor/181963]]></title>
<description><![CDATA[Support QuACK row reductions feeding main]]></description>
<link>https://tsecurity.de/de/3527533/downloads/ciflowinductor181963/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527533/downloads/ciflowinductor181963/</guid>
<pubDate>Tue, 19 May 2026 02:16:06 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Support QuACK row reductions feeding main</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/h100/181963]]></title>
<description><![CDATA[Support QuACK row reductions feeding main]]></description>
<link>https://tsecurity.de/de/3527532/downloads/ciflowh100181963/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527532/downloads/ciflowh100181963/</guid>
<pubDate>Tue, 19 May 2026 02:16:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Support QuACK row reductions feeding main</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/b200/181963]]></title>
<description><![CDATA[Support QuACK row reductions feeding main]]></description>
<link>https://tsecurity.de/de/3527531/downloads/ciflowb200181963/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527531/downloads/ciflowb200181963/</guid>
<pubDate>Tue, 19 May 2026 02:16:03 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Support QuACK row reductions feeding main</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[viable/strict/1778963571: Revert "[Native DSL] Quack-based cuteDSL RMSNorm (#182108)"]]></title>
<description><![CDATA[This reverts commit 9e329a3.
Reverted #182108 on behalf of https://github.com/pytorch-auto-revert due to Reverted automatically by pytorch's autorevert, to avoid this behaviour add the tag autorevert: disable (comment)]]></description>
<link>https://tsecurity.de/de/3522690/downloads/viablestrict1778963571-revert-native-dsl-quack-based-cutedsl-rmsnorm-182108/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3522690/downloads/viablestrict1778963571-revert-native-dsl-quack-based-cutedsl-rmsnorm-182108/</guid>
<pubDate>Sat, 16 May 2026 22:46:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This reverts commit <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/pytorch/pytorch/commit/9e329a397ee607ae1fc43b2f95225548de77d9d7/hovercard" href="https://github.com/pytorch/pytorch/commit/9e329a397ee607ae1fc43b2f95225548de77d9d7"><tt>9e329a3</tt></a>.</p>
<p>Reverted <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364390570" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/182108" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/182108/hovercard" href="https://github.com/pytorch/pytorch/pull/182108">#182108</a> on behalf of <a href="https://github.com/pytorch-auto-revert">https://github.com/pytorch-auto-revert</a> due to Reverted automatically by pytorch's autorevert, to avoid this behaviour add the tag autorevert: disable (<a href="https://github.com/pytorch/pytorch/pull/182108#issuecomment-4467340699" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/182108/hovercard">comment</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/75ab8d65182cebcf68b98304763ce7bbcdb66146: Revert "[Native DSL] Quack-based cuteDSL RMSNorm (#182108)"]]></title>
<description><![CDATA[This reverts commit 9e329a3.
Reverted #182108 on behalf of https://github.com/pytorch-auto-revert due to Reverted automatically by pytorch's autorevert, to avoid this behaviour add the tag autorevert: disable (comment)]]></description>
<link>https://tsecurity.de/de/3522400/downloads/trunk75ab8d65182cebcf68b98304763ce7bbcdb66146-revert-native-dsl-quack-based-cutedsl-rmsnorm-182108/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3522400/downloads/trunk75ab8d65182cebcf68b98304763ce7bbcdb66146-revert-native-dsl-quack-based-cutedsl-rmsnorm-182108/</guid>
<pubDate>Sat, 16 May 2026 18:16:41 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This reverts commit <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/pytorch/pytorch/commit/9e329a397ee607ae1fc43b2f95225548de77d9d7/hovercard" href="https://github.com/pytorch/pytorch/commit/9e329a397ee607ae1fc43b2f95225548de77d9d7"><tt>9e329a3</tt></a>.</p>
<p>Reverted <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364390570" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/182108" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/182108/hovercard" href="https://github.com/pytorch/pytorch/pull/182108">#182108</a> on behalf of <a href="https://github.com/pytorch-auto-revert">https://github.com/pytorch-auto-revert</a> due to Reverted automatically by pytorch's autorevert, to avoid this behaviour add the tag autorevert: disable (<a href="https://github.com/pytorch/pytorch/pull/182108#issuecomment-4467340699" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/182108/hovercard">comment</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/9e329a397ee607ae1fc43b2f95225548de77d9d7: [Native DSL] Quack-based cuteDSL RMSNorm (#182108)]]></title>
<description><![CDATA[Summary:
Add fused rmsnorm fwd/bwd implementations from quack, written in
cutedsl. Rely on vendored quack.
Add testing to OpInfo for composability with other PyT systems, and
test_nn to match the existing fused norm tests.
Test Plan:
  python -m pytest -v \
    test/test_nn.py -k rmsnorm \
    te...]]></description>
<link>https://tsecurity.de/de/3522014/downloads/trunk9e329a397ee607ae1fc43b2f95225548de77d9d7-native-dsl-quack-based-cutedsl-rmsnorm-182108/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3522014/downloads/trunk9e329a397ee607ae1fc43b2f95225548de77d9d7-native-dsl-quack-based-cutedsl-rmsnorm-182108/</guid>
<pubDate>Sat, 16 May 2026 13:46:22 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Summary:</p>
<p>Add fused rmsnorm fwd/bwd implementations from quack, written in<br>
cutedsl. Rely on vendored quack.</p>
<p>Add testing to OpInfo for composability with other PyT systems, and<br>
test_nn to match the existing fused norm tests.</p>
<p>Test Plan:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="  python -m pytest -v \
    test/test_nn.py -k rmsnorm \
    test/python_native/ \
    test/test_ops.py -k 'rms_norm' \
    test/inductor/test_torchinductor_opinfo.py -k 'rms_norm'

  # Then separately, since OPINFO_RESTRICT_TO_DSL filters op_db globally:
  OPINFO_RESTRICT_TO_DSL=cutedsl python -m pytest -v \
    test/test_ops.py -k 'rms_norm and cutedsl' \
    test/inductor/test_torchinductor_opinfo.py -k 'rms_norm and cutedsl' \
    test/export/test_export_opinfo.py -k 'rms_norm and cutedsl'"><pre class="notranslate"><code>  python -m pytest -v \
    test/test_nn.py -k rmsnorm \
    test/python_native/ \
    test/test_ops.py -k 'rms_norm' \
    test/inductor/test_torchinductor_opinfo.py -k 'rms_norm'

  # Then separately, since OPINFO_RESTRICT_TO_DSL filters op_db globally:
  OPINFO_RESTRICT_TO_DSL=cutedsl python -m pytest -v \
    test/test_ops.py -k 'rms_norm and cutedsl' \
    test/inductor/test_torchinductor_opinfo.py -k 'rms_norm and cutedsl' \
    test/export/test_export_opinfo.py -k 'rms_norm and cutedsl'
</code></pre></div>
<p>Authors:</p>
<p>Originally from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130543671" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/178326" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/178326/hovercard" href="https://github.com/pytorch/pytorch/pull/178326">#178326</a></p>
<p>Co-authored-by: AaronWang04</p>
<p>Signed-off-by: Simon Layton <a href="mailto:simonlayton@meta.com">simonlayton@meta.com</a></p>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364390570" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/182108" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/182108/hovercard" href="https://github.com/pytorch/pytorch/pull/182108">#182108</a><br>
Approved by: <a href="https://github.com/drisspg">https://github.com/drisspg</a></p>
<p>Co-authored-by: AaronWang04 <a href="mailto:aaronw23880@gmail.com">aaronw23880@gmail.com</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In response to Rumsfeld's, "If you disagree with me, you're a Nazi appeaser"]]></title>
<description><![CDATA[“The man who sees absolutes, where all other men see nuances and shades of meaning, is either a prophet, or a quack.
Donald H. Rumsfeld is not a prophet.”

A very powerful signoff from Keith Olbermann, host of NBC “Countdown”. Read the transcript here, or watch the video in wmv or qt format.]]></description>
<link>https://tsecurity.de/de/3501054/unix-server/in-response-to-rumsfelds-if-you-disagree-with-me-youre-a-nazi-appeaser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501054/unix-server/in-response-to-rumsfelds-if-you-disagree-with-me-youre-a-nazi-appeaser/</guid>
<pubDate>Fri, 08 May 2026 23:03:09 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<blockquote>
<p>“The man who sees absolutes, where all other men see nuances and shades of meaning, is either a prophet, or a quack.</p>
<p>Donald H. Rumsfeld is not a prophet.”</p>
</blockquote>
<p>A very powerful signoff from Keith Olbermann, host of NBC “Countdown”. Read the transcript <a href="http://www.msnbc.msn.com/id/12131617/#060830b">here</a>, or watch the video in <a href="http://movies.crooksandliars.com/OlbermannBlastsRumsfeldOnFacism.wmv">wmv</a> or <a href="http://movies.crooksandliars.com/OlbermannBlastsRumsfeldOnFacism.mov">qt</a> format.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Peeve of the day]]></title>
<description><![CDATA[Ok, so I have lots of pet peeves, and if I wanted to blog them all I'd have no time for anything else (and a lot more blog posts than the occasional one), but this one struck me the other day.I was at the optometrist with Patricia, who is near-sighted like me. Or rather - not like me, since I've ...]]></description>
<link>https://tsecurity.de/de/3500956/unix-server/peeve-of-the-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500956/unix-server/peeve-of-the-day/</guid>
<pubDate>Fri, 08 May 2026 23:00:17 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="blsp-spelling-error">Ok</span>, so I have <span>lots</span> of pet peeves, and if I wanted to blog them all I'd have no time for anything else (and a lot more blog posts than the occasional one), but this one struck me the other day.<br><br>I was at the optometrist with Patricia, who is near-sighted like me. Or rather - not like me, since I've had <span class="blsp-spelling-error">lasik</span>, and since she's more nearsighted than I ever was. She's blind as a bat without glasses or contacts, in other words.<br><br>Also like me, she's allergic to pollen. She gets itchy, watery eyes. So at the optometrist, when they ask about whether she's had problems with her eyes, the allergies come up. And what do you know, they have eye-drops for that.<br><br><span class="blsp-spelling-error">Ok</span>, not surprising. But what I <span>do</span> find surprising is the kind of eye-drops they have. This is a doctor's office, you'd expect them to be professional. But their eye-drops are homeopathic, and the doctor talks them up as not having any harsh medication in them. Well, duh! They're saline solution.<br><br>So I sit there quietly, and don't call him out for being a quack, because real doctors do actually prescribe placebos, and maybe he does know better. And there's also no question that plain saline solution isn't a fine thing to use when your eyes are itchy.<br><br>So afterwards, I spend some time afterwards talking to Patricia about placebos and homeopathy and quackery, in my never-ending hope that my kids won't grow up to be morons. But it's been a few days, and quite frankly, it still disturbs me. I've not had any other issues with that optometrist, but I'm seriously wondering if this is worth switching eye doctors over.<br><br>Do I want somebody who sells snake-oil (<span class="blsp-spelling-error">ok</span>, so he gave a free sample, and no way would I have paid for it anyway) looking at my kids eyes? Even if it's harmless and even beneficial?<br><br>I'd much rather have seen free samples of "sterile saline solution". And oh yes, please feel free to make a big deal out of the "sterile" part, and feel free to talk about how it is "all natural" and free of <span class="blsp-spelling-error">Tetrahydrozoline</span> or other chemicals.<br><br>But this piece-of-crap saline solution talked about the magical homeopathic "active ingredients" (non-existent and bogus), and while it did list the "inactive ingredients" (<span class="blsp-spelling-error">ie</span> water and sodium chloride - aka "saline solution"), it was basically a huge advert for teaching people bad science and paying extra for it.<br><br>And I'm not crazy. I'm not going to make my own saline solution to save money. I'll happily pay extra for "sterile". I'll pay extra for nice prepared droppers in tiny sizes, even if it means you pay actual money for just tiny amounts of water with some table salt in it (no iodine - get the "kosher" salt if you want to make your own, and use distilled water).  I'll happily pay for the convenience of having somebody else prepare saline solution of the proper strength and in a convenient package.<br><br>And the funny thing is, I don't mind it when I see the same thing at the checkout counter in the organic grocery store I prefer to go to. I <span></span>go there because quite frankly, the average meat department in something like a Safeway or <span class="blsp-spelling-error">Albertsons</span> leaves a lot to be desired. And hey, it's an organic store, so I kind of <span>expect</span> it to then cater to the ignorant and the crack-pots too.<br><br>But at the doctors' office?]]></content:encoded>
</item>
<item>
<title><![CDATA[CIO ForwardTech & ThreatScape Spain será el gran escaparate de las tendencias tecnológicas y de ciberseguridad en 2026]]></title>
<description><![CDATA[En un panorama de presión regulatoria creciente y con la irrupción, cada vez más vertiginosa, de nuevas tecnologías de la información transformadoras, como los últimos sabores de IA que están redefiniendo los procesos, decisiones y modelos de negocio, las organizaciones deben moverse con más agil...]]></description>
<link>https://tsecurity.de/de/3430366/it-nachrichten/cio-forwardtech-threatscape-spain-ser-el-gran-escaparate-de-las-tendencias-tecnolgicas-y-de-ciberseguridad-en-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3430366/it-nachrichten/cio-forwardtech-threatscape-spain-ser-el-gran-escaparate-de-las-tendencias-tecnolgicas-y-de-ciberseguridad-en-2026/</guid>
<pubDate>Tue, 14 Apr 2026 01:02:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>En un panorama de presión regulatoria creciente y con la irrupción, cada vez más vertiginosa, de nuevas tecnologías de la información transformadoras, como los últimos sabores de IA que están redefiniendo los procesos, decisiones y modelos de negocio, las organizaciones deben moverse con más agilidad, seguridad y responsabilidad. Sobre los desafíos que afrontan los máximos responsables de su estrategia de sistemas de información (los CIO) pero también de seguridad (los CISO) versará el evento <strong><a href="https://event.foundryco.com/forwardtech-threatscape-spain/" rel="nofollow">CIO ForwardTech &amp; ThreatScape Spain</a></strong>, organizado por las cabeceras CIO y COMPUTERWORLD | CSO de Foundry España el próximo jueves 16 de abril en Madrid.</p>



<p>Durante la jornada, los más de cien profesionales del ámbito de la tecnología y la ciberseguridad del país que acudirán al evento podrán explorar cómo construir empresas capaces de innovar con confianza y resistir en un ecosistema donde cada avance trae consigo nuevos riesgos y nuevas oportunidades.</p>



<p>La jornada, en la que abundarán los debates estratégicos, las sesiones prácticas y encuentros entre responsables de alto nivel, tiene una agenda exhaustiva dividida en dos ejes: <strong>ThreatScape</strong>, una serie de ponencias y paneles especializados en cómo responder a un panorama de amenazas cada vez más automatizado y sofisticado y donde se examinarán modelos de resiliencia, continuidad operativa y decisiones críticas bajo presión; y <strong>ForwardTech</strong>, charlas y sesiones de debate donde se profundizará en cómo aplicar la IA y la automatización, pero también otras tecnologías como el <strong>edge</strong>, 5G y la sostenibilidad digital, con el fin de construir organizaciones más eficientes, responsables y orientadas al futuro.</p>



<p>El encuentro, presentado por <strong>Fernando Muñoz</strong>, director de CIO Executive de Foundry, y <strong>Esther Macías</strong>, directora editorial de CIO y COMPUTERWORLD en España, y en el que participarán directivos de la industria tecnológica de compañías como <strong>Avanade, Riot, Object First, ManageEngine, Rubrik, Thales, Tanium, Everpure|Rubrik y OnSoluciones</strong>, arrancará con una charla inspiracional impartida por <strong>Madhu Bhabuta</strong>, fundadora y CIO de Brnovate, quien dará las claves para liderar con confianza en la era de la innovación segura.</p>



<h2 class="wp-block-heading">Ponencias y debates de primer nivel</h2>



<p>También habrá <strong>ponencias </strong>por parte de <strong>Jaime López Ostio, director global de TI de Faes Farma</strong>, que ahondará en el papel de España ante la Nueva Ley de Gobernanza Cibernética; <strong>Víctor Yubero, director de TI para la gobernanza de la inteligencia artificial en Banco Sabadell</strong>, que profundizará en la IA ética y transparente y el rol del país como modelo europeo de confianza; <strong>Izaskun Onandia de los Rios, directora asociada de Seguridad y Cumplimiento Normativo en materia de Información de ITP Aero</strong>, que centrará su exposición sobre el valor estratégico de la seguridad y la ciberseguridad como inversión, no como gasto; y <strong>Jessica Ferreira Vicente, directora de la Oficina de Transformación Digital de SEAT</strong>, que hablará sobre la gobernanza de la IA y la ética, la escalabilidad y la confianza en la transformación digital.</p>



<p>Los <strong>debates </strong>conformarán uno de los platos fuertes de la jornada, unos encuentros en los que participarán ejecutivos como Olga Forné, CISO global del <strong>Grupo Abertis</strong>; Paloma Garbayo-Tavera, CISO de <strong>Iberdrola</strong>; Daniel Damas, director de IT Assurance &amp; CISO de <strong>Nationale-Nederlanden</strong>; José Ángel Álvarez, director del Centro de Ciberseguridad del <strong>Ayuntamiento de Madrid</strong>; Josep Bardallo, CISO de <strong>Argal Alimentación</strong>; Rafael García del Poyo, abogado y socio director del Departamento de Derecho de las Tecnologías de la Información y de la Propiedad Intelectual de <strong>Osborne Clarke España</strong>; Manuel Asenjo, CISO de <strong>Écija</strong>; Javier Sánchez-Ureta, PSPO – responsable de Riesgos y Gobernanza de <strong>Roche</strong>; Joan Barceló, CIO de <strong>W2M</strong>; Carlos Martin, responsable de ciencia de datos en <strong>Boehringer Ingelheim España</strong>; María Ángeles Vicente, CIO de <strong>Alsa</strong>; Amador Nieto, CISO de <strong>Decathlon</strong> España; Javier Tobal, director de seguridad de la información y GRC de <strong>Planet</strong>; Javier Sánchez, CISO de <strong>Engie </strong>España; David Pérez Sánchez, subdirector corporativo de Gestión de Riesgos de Seguridad y Fraude de <strong>MAPFRE</strong>; Israel Devesa, director general Digital &amp; Tecnólogo del <strong>Grupo Aldesa</strong>; Carlos Garriga, CIO del <strong>IE Business School</strong>; Rubén Andrés Priego, director general de Tecnología, Operaciones e Innovación de <strong>Singular Bank</strong>; Sonia Segade, CIO de <strong>Renfe</strong>; Ricard Guasch, CIO de <strong>Zurich Insurance</strong> Company; Enric Llaudet, responsable de Seguridad de la Información en el ámbito internacional de <strong>Teladoc Health Internacional</strong>; y Carlos Manchado, CISO global de <strong>Acciona</strong>.</p>


<div class="text text--no-top-margin"><h2></h2><p></p><p><a class="button button--primary" data-amp-height="40" target="" href="https://register.foundryco.com/event/7b577976-2e4a-4e3d-8c1d-22d6fbd13676/regProcessStep1?RefId=we&amp;_gl=1*u6f9dm*_gcl_au*MTE2NjY4MDY3Ni4xNzcwOTgwNTk4*_ga*R0ExLjEuR0ExLjEuMTQ3NzczNTE5Ni4xNzcwOTgwNTk4*_ga_25Y4GBLQQ5*czE3NzYwODk2MjIkbzIxJGcxJHQxNzc2MDg5NjI0JGo1OCRsMCRoMTgwNzAxMDg0Nw..&amp;rp=9d2fad9a-0cd2-4871-846a-85dcf31121f9" rel="nofollow">Regístrese aquí para acudir a CIO ForwardTech &amp; ThreatScape Spain</a></p></div>


<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[QUACK: Hindering Deserialization Attacks via Static Duck Typing]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 2x - Views:18 Managed languages facilitate convenient ways for serializing objects, allowing applications to persist and transfer them easily, yet this feature opens them up to attacks. By manipulating serialized objects, attackers can trigger a chained execution of...]]></description>
<link>https://tsecurity.de/de/3191298/it-security-video/quack-hindering-deserialization-attacks-via-static-duck-typing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3191298/it-security-video/quack-hindering-deserialization-attacks-via-static-duck-typing/</guid>
<pubDate>Fri, 02 Jan 2026 19:46:56 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 2x - Views:18 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/hrtVuYfswCg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Managed languages facilitate convenient ways for serializing objects, allowing applications to persist and transfer them easily, yet this feature opens them up to attacks. By manipulating serialized objects, attackers can trigger a chained execution of existing code segments, using them as gadgets to form an exploit. Protecting deserialization calls against attacks is cumbersome and tedious, leading to many developers avoiding deploying defenses properly.<br />
<br />
We present QUACK, a framework for automatically protecting applications by fixing calls to deserialization APIs. This "binding" limits the classes allowed for usage in the deserialization process, severely limiting the code available for (ab)use as part of exploits. QUACK computes the set of classes that should be allowed using a novel static duck typing inference technique. In particular, it statically collects all statements in the program code that manipulate objects after they are deserialized, and puts together a filter for the list of classes that should be available at runtime. We have implemented QUACK for PHP and evaluated it on a set of applications with known CVEs and popular applications crawled from GitHub. QUACK managed to fix the applications in a way that prevented any attempt at automatically generating an exploit against them, by blocking, on average, 97% of the application's code that could be used as gadgets. We submitted a sample of three fixes generated by QUACK as pull requests, and their developers merged them.<br />
<br />
By:<br />
Neophytos Christou  |  PhD Candidate, Brown University<br />
Andreas Kellas  |  Security Researcher, Columbia University<br />
<br />
Presentation Materials Available at:<br />
https://blackhat.com/us-25/briefings/schedule/?#quack-hindering-deserialization-attacks-via-static-duck-typing-44934<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Uber lanza un programa piloto para que sus conductores entrenen a la IA]]></title>
<description><![CDATA[Tras su entrada en el ámbito del etiquetado de datos el año pasado con el lanzamiento de una nueva división, Scaled Solutions, Uber presentó este jueves un proyecto piloto en el mercado estadounidense en el que sus conductores, al igual que sus homólogos de la India, anotarán datos para su uso en...]]></description>
<link>https://tsecurity.de/de/3045925/it-security-nachrichten/uber-lanza-un-programa-piloto-para-que-sus-conductores-entrenen-a-la-ia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3045925/it-security-nachrichten/uber-lanza-un-programa-piloto-para-que-sus-conductores-entrenen-a-la-ia/</guid>
<pubDate>Fri, 17 Oct 2025 10:04:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Tras su <strong>entrada en el ámbito del etiquetado de datos</strong> el año pasado con el lanzamiento de una nueva división, Scaled Solutions, <strong>Uber presentó este jueves un proyecto piloto en el mercado estadounidense en el que sus conductores, al igual que sus homólogos de la India, anotarán datos para su uso en el entrenamiento de la inteligencia artificial</strong>.</p>



<p><strong>Megha Yethadka, directora global de la división</strong>, ahora rebautizada como <strong>Uber AI Solutions</strong>, dijo que el programa piloto en la India, lanzado el mes pasado, permite a los conductores de 12 ciudades indias utilizar su tiempo de inactividad para completar tareas digitales, que abarcan desde la clasificación de imágenes y el análisis de textos hasta la transcripción de audio y la digitalización de recibos.</p>



<p>La medida llega después del <strong>anuncio realizado el pasado junio de expandir la plataforma de IA de Uber</strong>, que la empresa describió como un conjunto de ofertas que incluyen “soluciones personalizadas para crear modelos y agentes de IA más inteligentes, redes globales de tareas digitales y herramientas para ayudar a las empresas a crear y probar modelos de IA de forma más eficiente”. Según un comunicado, Uber AI Solutions “ofrece las herramientas y los datos necesarios para ayudar a entrenar a agentes de IA inteligentes, incluyendo flujos de tareas realistas, anotaciones de alta calidad, simulaciones y soporte multilingüe, lo que ayuda a los agentes de IA a comprender y navegar por los procesos empresariales del mundo real”.</p>



<p><strong>El programa piloto estadounidense, anunciado en un evento (Only on Uber) de la organización, contará, según el <em><a href="https://www.uber.com/blog/digital-tasks/" target="_blank" rel="nofollow">blog </a></em>de la empresa, con “un grupo selecto de conductores y mensajeros que realizarán tareas digitales, como grabarse hablando en el idioma con el que se sientan más cómodos, enviar documentos escritos en diferentes idiomas y subir imágenes</strong>”.</p>



<p><strong>Shashi Bellamkonda, director principal de investigación de Info-Tech Research Group, describe el anuncio como “una medida inteligente y estratégica de Uber</strong>”. Según él, la empresa ya cuenta con “una amplia audiencia global de conductores y repartidores. Es de suponer que dispondrán de algo de tiempo libre entre un viaje y otro para interactuar y realizar pequeñas tareas digitales que ayuden a entrenar los modelos de IA”.</p>



<p>“<strong>Uber es, ante todo, una empresa de datos y logística</strong>, y esta medida aprovecha esas fortalezas de una manera que podría generar datos de entrenamiento valiosos y diversos”, observa. “Esto me recuerda cómo CAPTCHA/reCAPTCHA sigue utilizándose para entrenar modelos de IA. Uber ahorra dinero al hacerlo ‘internamente’ y también podría ofrecer los datos recabados de alguna forma a otras empresas”.</p>



<p>Señaló que la medida también “<strong>introduce un nuevo actor en el mercado del etiquetado de datos con intervención humana</strong>, que ha estado dominado por unos pocos proveedores especializados. Con la escala y el alcance de Uber, podría aumentar la competencia y aportar más flexibilidad y presión sobre los precios a un mercado que sigue siendo demasiado costoso y que requiere muchos recursos para muchas organizaciones. También muestra cómo la preparación y el etiquetado de datos se están convirtiendo en productos básicos, y por qué los directores de informática deberían empezar a considerar estas funciones como categorías de adquisición estratégicas en lugar de simples tareas técnicas especializadas”.</p>



<p>Los directores de TI, según Bellamkonda, también “luchan por alinear sus inversiones en IA con un valor empresarial claro. <strong>Hay dos lecciones que aprender aquí. En primer lugar, explorar si los datos propios de las operaciones diarias podrían utilizarse en una iniciativa de etiquetado de datos propia, aunque solo sea para casos de uso limitados</strong>”. La segunda lección, según él, es que “la anotación de datos de Uber podría ofrecer una <strong>nueva oportunidad y ayudar a los CIO que desean un conjunto de datos globalmente diverso</strong>. Cuando esté disponible, podría valer la pena evaluar el ahorro potencial de costes que supone el uso de este nuevo conjunto de datos y llevar a cabo un pequeño programa piloto para compararlo con los proveedores existentes”.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Interesting report on how you can be tracked using your mobile phone and SS7]]></title>
<description><![CDATA[submitted by    /u/le-quack   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3041218/it-security-nachrichten/interesting-report-on-how-you-can-be-tracked-using-your-mobile-phone-and-ss7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3041218/it-security-nachrichten/interesting-report-on-how-you-can-be-tracked-using-your-mobile-phone-and-ss7/</guid>
<pubDate>Wed, 15 Oct 2025 09:34:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/security/comments/1o74ibd/interesting_report_on_how_you_can_be_tracked/"> <img src="https://external-preview.redd.it/Cz0qyfOTQcJ5XbaYQitemZdQVb__zbnq-wHobXCy3r0.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=a001dc3e5be0fcc43525a73f45afebb5ddaa683c" alt="Interesting report on how you can be tracked using your mobile phone and SS7" title="Interesting report on how you can be tracked using your mobile phone and SS7"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/le-quack"> /u/le-quack </a> <br> <span><a href="https://www.lighthousereports.com/methodology/surveillance-secrets-explainer/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1o74ibd/interesting_report_on_how_you_can_be_tracked/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[El BCE elige una “startup” portuguesa de IA para prevenir el fraude con el euro digital]]></title>
<description><![CDATA[El Banco Central Europeo (BCE) ha anunciado la elección de la startup portuguesa Feedzai, especializada en inteligencia artificial, con el objetivo de ayudar a prevenir el fraude con su proyecto de euro digital, según ha informado Reuters.



El contrato, de cuatro años de duración con opción de ...]]></description>
<link>https://tsecurity.de/de/3022862/it-security-nachrichten/el-bce-elige-una-startup-portuguesa-de-ia-para-prevenir-el-fraude-con-el-euro-digital/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3022862/it-security-nachrichten/el-bce-elige-una-startup-portuguesa-de-ia-para-prevenir-el-fraude-con-el-euro-digital/</guid>
<pubDate>Mon, 06 Oct 2025 10:33:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>El Banco Central Europeo (BCE) ha anunciado la elección de la <em>startup</em> portuguesa Feedzai, especializada en inteligencia artificial, con el objetivo de ayudar a prevenir el fraude con su proyecto de euro digital, según ha informado <em>Reuters</em>.</p>



<p>El contrato, de cuatro años de duración con opción de prórroga a 15 años y que tiene un valor de 237,3 millones de euros, pretende impulsar un proyecto que el BCE considera clave para la autonomía financiera de la zona euro respecto a Estados Unidos.</p>



<p>Tal y recoge, Feedzai y su subcontratista PwC proporcionarán un modelo de inteligencia artificial para puntuar los pagos en euros digitales en función de su riesgo de fraude. Para ello se basarán en cualquier desviación del comportamiento, las interacciones y el historial habituales de un cliente.</p>



<p>El objetivo es ayudar a los proveedores de servicios de pago a decidir si aprueban una transacción en euros digitales, que es esencialmente un intercambio entre monederos electrónicos respaldados por el banco central.</p>



<p>En total, el BCE ha adjudicado otros cuatro contratos de euro digital por un valor de entre 27,6 y 220,7 millones de euros a otras empresas, entre ellas Capgemini (CAPP.PA). Según lo estipulado en estos acuerdos marco, no pagará a los contratistas hasta que comience el proyecto.</p>



<p>De todas formas, el BCE sigue a la espera de la aprobación legislativa de su euro digital, que ha presentado como respuesta al dominio de Visa y Mastercard y a la promoción por parte del presidente de Estados Unidos, Donald Trump, de las monedas estables vinculadas al dólar, según ha destacado <em>Reuters</em>.</p>



<p>De ahí que espera recibir el visto bueno a mediados del próximo año, con vistas a lanzar la moneda digital en 2029.</p>



<p>En cuanto a la portuguesa Feedzai, se trata de una <em>startup</em> que procesa pagos por valor de 8 billones de dólares al año para clientes como el banco portugués Novobanco y el Wio Bank de Abu Dabi. Además, el pasado jueves también anunció una financiación de 75 millones de dólares (64,24 millones de euros) por parte de Lince Capital, Iberis Capital y Explorer Investments, entre otros.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Quack: Part 1 by Sora 2]]></title>
<description><![CDATA[Author: OpenAI - Bewertung: 305x - Views:3211]]></description>
<link>https://tsecurity.de/de/3019447/videos/the-quack-part-1-by-sora-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3019447/videos/the-quack-part-1-by-sora-2/</guid>
<pubDate>Fri, 03 Oct 2025 19:30:53 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/Gdzm0-8_61c/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: OpenAI - Bewertung: 305x - Views:3211 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Gdzm0-8_61c?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EIC25-Videotalk: Darum ist der Swissbit iShield Key 2 ein echter Alleskönner]]></title>
<description><![CDATA[Der Swissbit iShield Key 2 ist ein echter Alleskönner, schenkt man den Worten von Jan M. Quack von der Swissbit AG Glauben. Warum das so ist und warum ich Jan ausgerechnet am Stand von RSA Security getroffen habe, erzählt er mir in 80 Sekunden. Entstanden ist das Video auf der European Identity &...]]></description>
<link>https://tsecurity.de/de/2798953/it-nachrichten/eic25-videotalk-darum-ist-der-swissbit-ishield-key-2-ein-echter-alleskoenner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2798953/it-nachrichten/eic25-videotalk-darum-ist-der-swissbit-ishield-key-2-ein-echter-alleskoenner/</guid>
<pubDate>Mon, 26 May 2025 21:45:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Swissbit iShield Key 2 ist ein echter Alleskönner, schenkt man den Worten von Jan M. Quack von der Swissbit AG Glauben. Warum das so ist und warum ich Jan ausgerechnet am Stand von RSA Security getroffen habe, erzählt er mir in 80 Sekunden. Entstanden ist das Video auf der European Identity &amp; Cloud Conference … <p class="link-more"><a href="https://www.it-techblog.de/eic25-videotalk-darum-ist-der-swissbit-ishield-key-2-ein-echter-alleskoenner/05/2025/" class="more-link">Mehr <span class="screen-reader-text">über "EIC25-Videotalk: Darum ist der Swissbit iShield Key 2 ein echter Alleskönner" </span>Lesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Arch Ricing from 2011]]></title>
<description><![CDATA[i'm currently doing some clean up of my old HDDs and i spot this screenshot, my ArchLinux setup back in 2011! at the time conky was a must have and gnome shell wasn't even a thing. https://preview.redd.it/3qrn0jn56zxe1.png?width=1920&format=png&auto=webp&s=c72865cb85d792b4560b1ef27f88999fa2391aa7...]]></description>
<link>https://tsecurity.de/de/2751197/linux-tipps/arch-ricing-from-2011/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2751197/linux-tipps/arch-ricing-from-2011/</guid>
<pubDate>Wed, 30 Apr 2025 15:39:58 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>i'm currently doing some clean up of my old HDDs and i spot this screenshot, my ArchLinux setup back in 2011!</p> <p>at the time conky was a must have and gnome shell wasn't even a thing.</p> <p><a href="https://preview.redd.it/3qrn0jn56zxe1.png?width=1920&amp;format=png&amp;auto=webp&amp;s=c72865cb85d792b4560b1ef27f88999fa2391aa7">https://preview.redd.it/3qrn0jn56zxe1.png?width=1920&amp;format=png&amp;auto=webp&amp;s=c72865cb85d792b4560b1ef27f88999fa2391aa7</a></p> <p>it was a nice time to be alive !</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/duck-and-quack"> /u/duck-and-quack </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1kbgnxq/arch_ricing_from_2011/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1kbgnxq/arch_ricing_from_2011/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist ein Meme? Erklärung, Wortherkunft und Beispiele]]></title>
<description><![CDATA[Memes sind aus der Internetkultur nicht wegzudenken. Die lustigen Bilder oder Videoclips werden auf allen Plattformen gepostet, bewertet und weiterverschickt. Aber was genau ist eigentlich ein Meme?Herkunft des Begriffes „Meme“Der Begriff „Meme“ bezeichnet kurze Videos und Bilder, die mit Schrift...]]></description>
<link>https://tsecurity.de/de/2679653/it-nachrichten/was-ist-ein-meme-erklaerung-wortherkunft-und-beispiele/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2679653/it-nachrichten/was-ist-ein-meme-erklaerung-wortherkunft-und-beispiele/</guid>
<pubDate>Fri, 21 Mar 2025 15:00:38 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><b>Memes sind aus der Internetkultur nicht wegzudenken. Die lustigen Bilder oder Videoclips werden auf allen Plattformen gepostet, bewertet und weiterverschickt. Aber was genau ist eigentlich ein Meme?</b></p><h2>Herkunft des Begriffes „Meme“</h2><p>Der Begriff „Meme“ bezeichnet kurze Videos und Bilder, die mit Schriftzügen, Bildmanipulation oder Musik<b> immer neu interpretiert oder abgeändert</b> werden, um witzige Aussagen zu treffen (Quelle: Duden). Dafür werden oft Abbildungen von berühmten Persönlichkeiten, klassischer Kunst, Comics, Stock Fotos und weiteren originalen Motiven so bearbeitet, dass ein neuer Inhalt entsteht.</p><p>Das Wort „Meme“ wurden vom griechischen Wort „mīmēma“ abgewandelt und bedeutet so viel wie <b>„etwas Nachgeahmtes“</b>. Ursprünglich vermutlich in der Genetik durch den Evolutionsbiologen Richard Dawkins in seinem Buch „Das egoistische Gen“ etabliert, verbreitete sich der Begriff später auch in der Internetkultur.</p><p>Ähnlich wie ein Gen soll sich laut Dawkins und anderen Wissenschaftlern ein Meme, das für eine Informationseinheit steht, <b>durch Wiederholung weiterverbreiten</b>. Dabei kann es sich auch um einen Witz handeln, den einzelne Personen besonders lustig finden, und den sie deshalb weitererzählen, sodass er zum Meme wird (Quelle: NYT).</p><p>Ein bekanntes Beispiel für ein Internet-Meme ist das <b>Doge-Meme</b>. Aus dem Bild eines knuffigen Shiba-Inus (so heißt die Hunderasse) wurde die Grundlage für ein ganzes Meme-Format, aus dem eine Reihe lustige Bilder entstanden sind. Irgendwann wurde daraus sogar eine eigene Krypto-Währung namens Dogecoin.</p><img src="https://static.giga.de/06/b9/c7/085c9d0b503e3941fd7e6432cc_AzA5MGMwMDMxNzRj_15c811a94585412fbd732cb37c05ff2b254e37a8.jpg" alt="Das Doge Meme. Ein Shiba-Inu schaut unsicher in die Kamera." width="500" height="500">Die Hündin, die zum Meme wurde: Die Shiba-Inu-Dame namens Kabosu<h2>Wo findet man Memes?</h2><p>Memes sind eine eigene Subkultur, die ihr <b>auf allen populären Sozialen Medien des Internets </b>findet. Über Social-Media-Kanäle auf Tumblr, Facebook, Twitter oder Instagram werden täglich Millionen Memes verschickt und gepostet. Auf Plattformen wie 9gag und Reddit sind Memes aber besonders häufig zu sehen.</p><p><i>Es gibt auch Memes, die sich auf das Leben in Deutschland beziehen.</i></p>Link<h2>Arten von Memes</h2><p>Es gibt viele Arten von Memes. Am besten lassen sie sich nach ihrem thematischem Inhalt unterteilen. Allerdings sei hier gesagt, dass es zu viele Meme-Kategorien gibt, um sie alle aufzulisten. Im Folgenden bekommt ihr aber einen Überblick über die wichtigsten Arten.</p>Politische Memes<p>Diese Memes haben meist einen ernsteren Charakter und befassen sich mit einem aktuellen Thema. Dabei bekommen oft bekannte <b>Politiker oder Parteien </b>„ihr Fett weg“. Ein Beispiel dafür wäre ein Meme zu Angela Merkel und ihrer Aussage: „Das Internet ist für uns alle Neuland.“</p>Fan-Memes<p>Solche Bilder und Clips werden besonders zu <b>Videospielen oder Filmen </b>erstellt. Besonders beliebt sind hier die Filmreihen Star Wars oder Herr der Ringe. Aber auch Videospiele fanden blitzschnell Einzug in die Meme-Kultur. Auch Sport-Memes stehen bei vielen auf der Tagesordnung. Besonders, wenn man konkurrierende Vereine ärgern kann.   </p>Musik-Memes<p>Diese Memes sind besonders beliebt, da sie mit den Werken von musikalischen Idolen ihren Schabernack treiben. Beliebt sind in dieser Kategorie zum Beispiel <b>Parodie-Songs</b>. Auch sehr beliebt sind Videos von tanzenden Tieren. </p><p>Eine Ikone des Internets ist das Meme <b>„Bongo Cat“</b> – eine Cartoon-Katze, die auf verschiedenen Instrumenten bekannte Lieder nachspielt, wie zum Beispiel „Never Gonna Give You Up“ von Rick Astley – ein Song, der selbst
schon längst zum Meme geworden ist.</p>LinkDank-Memes<p>Diese Art von Meme lässt sich schon nicht mehr so leicht erklären. Ursprünglich bedeutet das englische Wort „dank“ so viel wie „nasskalt“ oder „feucht“. Im Internet-Slang meint ein Dank Meme jedoch Inhalte, die<b> besonders seltsam</b> sein sollen und von seiner originalen Vorlage recht weit abgewandelt wurden.</p><p>Man erkennt Dank Memes an<b> besonders starker Bildbearbeitung</b>, beispielsweise durch Verzerren oder Verpixeln. Videos mit Dank-Memes sind oft zusätzlich mit völlig übersteuerter Musik unterlegt. Lustig sind sie vor allem für diejenigen, die die enthaltenen Insider verstehen oder ihres Memes gerne so absurd wie möglich haben wollen.</p><img src="https://static.giga.de/30/13/9b/db5950c776cc67ceeeb4610ab7_AzMzZDljNjZlYjFi_duck-meme-bearb.jpg" alt="Beispiel für ein Dank Meme. Oben steht: „When a duck sees another duck“, darunter ist die Abbildung eines Mannes mit rot leuchtenden Augen zu sehen. Unten steht „Quack“ " width="1920" height="1080">„Wenn eine Ente eine andere Ente sieht“ – Beispiel für ein Dank Meme.<h2>Memes selber erstellen und posten</h2><p>Um selbst Memes zu gestalten, braucht ihr genau zwei Dinge:<b> </b>ein simples <b>Bild- oder Video-Bearbeitungsprogamm und eine Idee</b>.<b> </b>Ihr braucht dafür keine kostenpflichtige Premium-Software. Für kostenlose Bildbearbeitung empfehlen wir GIMP. Aber auch Canva oder der Meme-Generator von Adobe Express sind beliebte Optionen. Kostenlose Videobearbeitung funktioniert beispielsweise mit Shotcut.</p>Link<h2>Memes und Urheberrecht: Darauf solltet ihr achten</h2><p>Wichtig bei der Frage nach einer möglichen Urheberrechtsverletzung ist, ob es sich bei eurem Meme um eine persönliche geistige Schöpfung handelt. Je nach Meme muss daher im Einzelfall geprüft werden, ob das Werk individuell und kreativ genug ist, um als <b>eigenständige Neuschöpfung</b> durchzugehen. </p><p>Generell fallen Memes üblicherweise in die Kategorie der <b>Parodie, Karikatur oder Pastiche</b> und sind damit zulässig. Vorsicht ist jedoch geboten, wenn das Recht auf das eigene Bild verletzt werden könnte oder wenn Unternehmen gegen Markenrechte verstoßen (Quelle: Urheberrecht.de).</p>Link]]></content:encoded>
</item>
<item>
<title><![CDATA[Día Rosa Tecnológico: el movimiento mundial de TI del CIO de Estée Lauder para financiar la investigación del cáncer de mama]]></title>
<description><![CDATA[Cuando se unió a The Estée Lauder Companies en 2017, Michael Smith reconoció una forma en que podría ayudar a marcar la diferencia de una manera diferente a sus típicas tareas de CIO: crear conciencia sobre el cáncer de mama.



Para ayudar a recaudar fondos para la investigación a través de la B...]]></description>
<link>https://tsecurity.de/de/2374014/it-security-nachrichten/da-rosa-tecnolgico-el-movimiento-mundial-de-ti-del-cio-de-este-lauder-para-financiar-la-investigacin-del-cncer-de-mama/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2374014/it-security-nachrichten/da-rosa-tecnolgico-el-movimiento-mundial-de-ti-del-cio-de-este-lauder-para-financiar-la-investigacin-del-cncer-de-mama/</guid>
<pubDate>Tue, 08 Oct 2024 13:03:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cuando se unió a <strong>The Estée Lauder Companies</strong> en 2017, <strong>Michael Smith</strong> reconoció una forma en que podría ayudar a marcar la diferencia de una manera diferente a sus típicas tareas de CIO: <strong>crear conciencia sobre el cáncer de mama</strong>.</p>



<p><strong>Para ayudar a recaudar fondos para la investigación a través de la Breast Cancer Research Foundation (BCRF), Smith inició el Día Rosa Tecnológico en Estée Lauder</strong>, anunciando que donaría una cantidad fija a la BCRF por cada selfie que un miembro del equipo de TI publicara con el <em>hashtag</em> TechDayofPink. La idea caló y varios CIO de la red de Smith se comprometieron a hacer lo mismo.</p>



<p>Desde entonces, el Día Rosa Tecnológico se ha convertido en un movimiento anual mundial. El segundo jueves de cada mes de octubre, se invita a profesionales y organizaciones del sector tecnológico a reconocer el Mes de Sensibilización sobre el Cáncer de Mama a través de esta iniciativa. <strong>Este año, el Día Rosa Tecnológico tendrá lugar el 10 de octubre. </strong>Las empresas de Estée Lauder ofrecen ideas para que su organización participe.</p>



<p>“Es una iniciativa dedicada a movilizar a la comunidad tecnológica mundial para ayudar a crear un mundo libre de cáncer de mama: esa es la misión de la Breast Cancer Research Foundation, de la campaña contra el cáncer de mama de Estée Lauder Companies, y es la misión del Día Rosa Tecnológico: ver el fin del cáncer de mama en nuestras vidas”, afirma Smith.</p>



<p><strong>Evelyn H. Lauder, ex vicepresidenta corporativa y jefa de Desarrollo de Fragancias de Estée Lauder, inspiró a Smith para la iniciativa.</strong> Lauder era una apasionada de la causa y ayudó a cofundar el lazo rosa, un símbolo que ahora es sinónimo de concienciación sobre el cáncer de mama. La difunta ejecutiva también ayudó a fundar la BCRF en 1993 junto con el Dr. Larry Norton.</p>



<p>Inspirado por el legado filantrópico de Lauder, <strong>Smith se dio cuenta de que su puesto como CIO de Estée Lauder le brindaba la oportunidad perfecta para “unir a tecnólogos y profesionales de TI de todo el mundo en torno a la concienciación sobre el cáncer de mama”.</strong> Su objetivo sigue siendo concienciar a la industria tecnológica -una industria que está demostrando ser decisiva en los avances sanitarios- y recaudar fondos para la investigación del cáncer de mama.</p>



<p>“La investigación está revolucionando nuestra comprensión del cáncer, nos está llevando al núcleo de la enfermedad. Está transformando vidas cada día, ya que tanto mujeres como hombres reciben la ayuda que necesitan cuando se les diagnostica”, afirma.</p>



<p>Smith añade que gran parte de esa investigación es aplicable a otros tipos de cáncer, lo que significa que un avance en la investigación del cáncer de mama puede beneficiar potencialmente a más pacientes diagnosticados de otros tipos de cáncer.</p>



<p>“En 2022 se diagnosticó cáncer de mama a 2,3 millones de mujeres en todo el mundo. Y cada 14 segundos, en algún lugar del mundo, una mujer es diagnosticada de cáncer de mama. Es el cáncer más frecuente en las mujeres, tanto en el mundo desarrollado como en el menos desarrollado, y es el cáncer más frecuente en las mujeres en general. Es el cáncer más diagnosticado en 157 de los 185 países del mundo”, afirma.</p>



<h2 class="wp-block-heading">Una llamada a la acción para los tecnólogos</h2>



<p>El Día Rosa Tecnológico empezó siendo pequeño, pero ha crecido hasta convertirse en un movimiento mundial más amplio, junto con un concierto benéfico anual y una subasta silenciosa. Este tercer concierto benéfico anual del Día Rosa Tecnológico, que se celebrará el 10 de octubre en Nueva York, contará con una subasta silenciosa y la actuación de Pink Sweat$, nominada a los Grammy. Todos los beneficios del concierto, incluida la venta de entradas, se destinan directamente a la BCRF para financiar la investigación del cáncer de mama.</p>



<p><strong>Los tecnólogos que no puedan asistir a la gala benéfica pueden participar de otras formas, como publicando una foto en las redes sociales vestidos de rosa o con un lazo rosa y compartiéndola con el hashtag #TechInPink2024</strong>, junto con la razón por la que la causa es importante para usted. La concienciación a través de las redes sociales es la base del Día Rosa Tecnológico, y una buena forma de empezar si quieres participar.</p>



<p>También se anima a las organizaciones y a los tecnólogos a<strong> encontrar nuevas formas de concienciar en torno al Día Rosa Tecnológico, ya sea mediante donaciones u organizando sus propios eventos en torno a la causa</strong>. Por ejemplo, en 2021, los Grupos de Mujeres Tecnólogas y Mujeres de la Cadena de Suministro de Estee Lauder organizaron un maratón anual del Día Rosa Tecnológico, que ha contribuido a atraer a más empresas, socios y donantes.</p>



<p><strong>Smith dice que ha descubierto que los CIO están ansiosos por “tener un impacto, marcar la diferencia y hacer el bien en este mundo”. </strong>Muchos CIO y ejecutivos tecnológicos están empezando a “reconocer las plataformas que tienen y el impacto que pueden tener, y no sólo a través de la tecnología en sí, sino a través de su influencia y su impacto. La gente está muy entusiasmada por participar y marcar la diferencia”.</p>



<p>Pero no hace falta ser un ejecutivo para participar: la causa es para todos los miembros de la industria tecnológica que quieran apoyar la concienciación y la investigación sobre el cáncer de mama. El objetivo es que el día sea accesible para todos, con una barrera de entrada baja para que todo el mundo pueda formar parte de la lucha contra el cáncer de mama.</p>



<p>“Lo más fácil que puedes hacer para influir, y que no te cuesta nada más que unos minutos de tu tiempo, es enviar un mensaje. Y esa sigue siendo la principal llamada a la acción. Cualquiera que disponga de tecnología puede hacerlo, y eso marca una gran diferencia: casi todo el mundo tiene una historia que contar. E incluso si no tienes una historia que contar, te animamos a que publiques”, dice Smith.</p>



<h2 class="wp-block-heading">Un impacto global</h2>



<p><strong>Iniciar más conversaciones sobre el cáncer de mama, especialmente en un sector tradicionalmente dominado por los hombres, también ha contribuido a impulsar los programas de salud de la mujer en las organizaciones</strong>, afirma Smith. Estas conversaciones, añade, han desencadenado avances en torno a prestaciones sanitarias, como mamografías gratuitas, especialmente en zonas del mundo donde estos temas suelen ser tabú, dejando a las mujeres “sin diagnosticar o tratar”.</p>



<p>“Estamos concienciando, a veces en estas culturas donde es un estigma, de que realmente somos capaces de salvar vidas”, afirma.</p>



<p>Smith también ha recibido comentarios a lo largo de los años en el sentido de que <strong>el Día Rosa Tecnológico puede contribuir en gran medida a unir a los equipos tecnológicos y fomentar la unión entre ellos</strong>. Aunque el objetivo es ayudar a poner fin al cáncer de mama mediante la concienciación, la educación y la financiación, Smith afirma que un “beneficio secundario” ha sido que el Día Rosa Tecnológico es también un “gran momento de creación de equipo que genera orgullo en las personas”.</p>



<p>Aunque es imposible hacer un seguimiento del impacto financiero exacto del Día Rosa Tecnológico, dado que muchos participantes hacen donaciones directas a la Breast Cancer Research Foundation, Smith afirma que pueden atribuir <strong>más de 165.000 dólares donados el año pasado a la BCRF</strong>. Eso fue sólo de las donaciones obtenidas a través del concierto benéfico, la subasta silenciosa y el maratón. <strong>Este año aspiran a que la cifra de donaciones ascienda a 250.000 dólares, suficiente para financiar a un investigador durante todo un año a través de la BCRF.</strong></p>



<p>Esta es la octava edición anual del Día Rosa Tecnológico, y el mayor deseo de Smith es “no tener que volver a hacerlo nunca más, porque acabaremos con el cáncer de mama”, pero mientras tanto espera que la causa siga creciendo tanto en concienciación como en financiación, atrayendo a más trabajadores de la tecnología al redil. Espera conseguir más embajadores para la causa, atrayendo a más “personas que sigan impulsando esta causa, hasta que veamos el éxito de la misión”.</p>



<p>“Nunca habría imaginado en el primer año que tendríamos millones de personas participando, cientos de empresas, que tendríamos un concierto, o que haríamos un maratón a pie. Quiero asegurarme de que este esfuerzo continúe hasta que acabemos con el cáncer de mama”, afirma Smith.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[El tratado internacional sobre IA añade incertidumbre a los CIO]]></title>
<description><![CDATA[Este jueves se dio a conocer la firma del primer tratado internacional jurídicamente vinculante sobre inteligencia artificial (IA), negociado por representantes de 57 países, pero su lenguaje es tan general que no está claro si los CIO de las empresas tendrán que hacer algo diferente para cumplir...]]></description>
<link>https://tsecurity.de/de/2318967/it-security-nachrichten/el-tratado-internacional-sobre-ia-aade-incertidumbre-a-los-cio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2318967/it-security-nachrichten/el-tratado-internacional-sobre-ia-aade-incertidumbre-a-los-cio/</guid>
<pubDate>Fri, 06 Sep 2024 11:04:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Este jueves se dio a conocer la firma del <a href="https://www.computerworld.es/article/3506368/ee-uu-gran-bretana-y-la-ue-firmaran-el-primer-tratado-internacional-sobre-ia.html">primer tratado internacional jurídicamente vinculante sobre inteligencia artificial (IA)</a>, negociado por representantes de 57 países, pero su lenguaje es tan general que no está claro si los CIO de las empresas tendrán que hacer algo diferente para cumplirlo.</p>



<p>Esta iniciativa, mayoritariamente europea, se suma a la larga lista de iniciativas de cumplimiento de la normativa mundial sobre IA, además de los numerosos intentos legales de regular la IA en Estados Unidos. Los signatarios iniciales fueron <strong>Andorra, Georgia, Islandia, Noruega, la República de Moldavia, San Marino y el Reino Unido, así como Israel, Estados Unidos y la Unión Europea</strong>.</p>



<p>En su anuncio, el Consejo de Europa afirmaba que “existen graves riesgos y peligros derivados de determinadas actividades dentro del ciclo de vida de la IA, como la discriminación en diversos contextos, la desigualdad de género, el menoscabo de los procesos democráticos, de la dignidad humana o de la autonomía individual, o los usos indebidos de los sistemas de inteligencia artificial por parte de algunos Estados con fines represivos, en violación de la legislación internacional sobre derechos humanos”.</p>



<h2 class="wp-block-heading">Qué dice el tratado</h2>



<p>El tratado, denominado <strong>Convenio Marco sobre la Inteligencia Artificial y los Derechos Humanos, la Democracia y el Estado de Derecho</strong>, hace hincapié en que <strong>las empresas deben dejar claro a los usuarios si se están comunicando con un ser humano o con una IA.</strong></p>



<p>Según el tratado, las empresas deben “avisar de que se está interactuando con un sistema de inteligencia artificial y no con un ser humano”, así como “llevar a cabo evaluaciones de riesgo e impacto con respecto a las repercusiones reales y potenciales sobre los derechos humanos, la democracia y el Estado de derecho”.</p>



<p>Las entidades también deben documentar todo lo que puedan sobre el uso de la IA y estar dispuestas a ponerlo a disposición de cualquiera que pregunte al respecto. El acuerdo dice que las entidades deben “<strong>documentar la información pertinente sobre los sistemas de IA y su uso y ponerla a disposición de las personas afectadas</strong>. La información debe ser suficiente para permitir a las personas afectadas impugnar la decisión o decisiones tomadas mediante el uso del sistema o basadas sustancialmente en él, así como impugnar el uso del propio sistema” y poder “presentar una denuncia ante las autoridades competentes”.</p>



<h2 class="wp-block-heading">Doble estándar</h2>



<p>Una observadora del proceso de negociación del tratado, <strong>Francesca Fanucci, especialista jurídica de ECNL (European Center for Not-for-Profit Law Stichting),</strong> describió el esfuerzo como “diluido”, sobre todo al tratar de las empresas privadas y la seguridad nacional. “<strong>La formulación de principios y obligaciones en esta convención es tan amplia y está tan plagada de salvedades que plantea serias dudas sobre su seguridad jurídica y su aplicabilidad efectiva</strong>“, declaró a <em>Reuters</em>.</p>



<p>El documento final excluye explícitamente las cuestiones de seguridad nacional: “Las cuestiones relativas a la defensa nacional no entran en el ámbito de aplicación del presente Convenio”.</p>



<p>En una entrevista con <strong>COMPUTERWORLD</strong>, Fanucci dijo que la versión final del tratado trata a las empresas de forma muy diferente a los gobiernos. El tratado “establece obligaciones para los Estados Partes, no para los actores privados directamente. Este tratado impone a los Estados Partes que <strong>apliquen sus normas al sector público, pero que elijan si las aplican en su legislación nacional al sector privado y cómo hacerlo</strong>. Se trata de un compromiso alcanzado con los países que pidieron específicamente que se excluyera al sector privado, entre ellos Estados Unidos, Canadá, Israel y Reino Unido”, explicó Fanucci. “Prácticamente se les permite formular una reserva al tratado”.</p>



<p>“Este doble estándar es decepcionante”, añadió.</p>



<h2 class="wp-block-heading">Falta de concreción</h2>



<p><strong>Tim Peters, directivo de la empresa canadiense de cumplimiento Enghouse Systems</strong>, fue uno de los muchos que aplaudió la idea y la intención del tratado, aunque cuestionó sus detalles concretos.</p>



<p>“El tratado sobre IA del Consejo de Europa <strong>es un intento bienintencionado, pero fundamentalmente erróneo</strong>, de regular un espacio en rápida evolución con herramientas de ayer. Aunque el tratado se autoproclama tecnológicamente neutral, esta neutralidad puede ser su talón de Aquiles”, afirmó Peters. “La IA no es una solución única, y tratar de aplicar normas generales que regulen todo, desde los robots de atención al cliente hasta las armas autónomas, podría ahogar la innovación y empujar a Europa a una camisa de fuerza reguladora”.</p>



<p>Peters agregó que esto <strong>podría socavar en última instancia los esfuerzos de IA empresarial</strong>. “Los ejecutivos de TI de las empresas deberían preocuparse por las consecuencias no deseadas: sofocar su capacidad de adaptación, ralentizar el desarrollo de la IA y llevar el talento y la inversión a regiones más amigables con la IA”, dijo Peters. “En última instancia, este tratado podría crear una división competitiva entre las empresas que juegan sobre seguro en Europa y las que empujan los límites en otros lugares. Las empresas que quieren prosperar necesitan pensar críticamente sobre el impacto a largo plazo de este tratado, no solo en la ética de la IA, sino en su capacidad de innovar”.</p>



<p>Otro ejecutivo del sector, <strong>Andrew Gamino-Cheong, CTO de Trustible</strong>, también cuestionó la falta de concreción del acuerdo. “<strong>El contenido real del tratado no es especialmente sólido y se trata sobre todo de declaraciones de principios de alto nivel</strong>. Pero creo que se trata sobre todo de un esfuerzo para que los países se unan a la hora de hacer valer sus derechos como entidades soberanas sobre el mundo digital. Para contextualizar un poco lo que quiero decir, veo lo que está ocurriendo con Elon Musk y Brasil como un buen ejemplo de los retos a los que se enfrentan los gobiernos con la tecnología”, dijo Gamino-Cheong. “Es tecnológicamente difícil bloquear Starlink en Brasil, lo que a su vez puede permitir el acceso a X, que es capaz de establecer sus propias normas de contenido y esquivar lo que Brasil quiere que hagan. Del mismo modo, aunque Clearview AI no opere legalmente en la UE, el hecho de que tengan datos de ciudadanos de la UE es suficiente para que se interpongan demandas GDPR contra ellos allí”.</p>



<p><strong>El director gerente de Ernst &amp; Young, Brian Levine</strong>, abordó las preguntas sobre la aplicabilidad de este tratado, especialmente con empresas de Estados Unidos, a pesar de que este país fue uno de los firmantes. No es raro que las empresas estadounidenses ignoren las multas y sanciones europeas.</p>



<p>“Hay que ir paso a paso. No se pueden aplicar reglas y normas compartidas hasta que no se llega a un acuerdo sobre cuáles son esas reglas y normas”, dijo Levine. “Estamos saliendo rápidamente de la fase del ‘Salvaje Oeste’ de la IA. Prepárense para el cambio de muy poca regulación y orientación a demasiada”.</p>



<p>El tratado entrará en vigor “el primer día del mes siguiente a la expiración de un plazo de tres meses a partir de la fecha en que cinco signatarios, incluidos al menos tres Estados miembros del Consejo de Europa, lo hayan ratificado”, según el anuncio.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Being Data-Driven]]></title>
<description><![CDATA[Why we are fooled by data and how to stop itsource: unsplash.comOften, when making decisions based on data, we feel as if we have made a more intelligent, accurate choice. The reality is a little different. From using it to purchase property, to deciding to go on a diet, to selecting a new board ...]]></description>
<link>https://tsecurity.de/de/2306416/ai-nachrichten/stop-being-data-driven/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2306416/ai-nachrichten/stop-being-data-driven/</guid>
<pubDate>Fri, 30 Aug 2024 02:50:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Why we are fooled by data and how to stop it</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*-DMUzqsJxapVIqS9"><figcaption>source: <a href="https://unsplash.com/">unsplash.com</a></figcaption></figure><p>Often, when making decisions based on data, we feel as if we have made a more intelligent, accurate choice. The reality is a little different. From using it to <a href="https://www.fullstackeconomics.com/p/why-zillow-is-like-my-bad-fantasy-football-team">purchase property</a>, to deciding to go on a <a href="https://www.scientificamerican.com/article/quack-cancer-diets-endanger-people-stick-to-science-backed-medicine/">diet</a>, to <a href="https://www.spectator.co.uk/article/is-diversity-actually-good-for-business/">selecting a new board member</a> for your company, data can be an amazing catalyst to help make the worst decisions.</p><p>Using real-world examples, this article covers common ways data can drive us over a cliff of misinformation. Fortunately, this article also gives actionable, easy-to-use advice on how to avoid such scenarios by following a four-step ladder to assess the quality of data-driven insights:</p><ol><li>evaluating the data source,</li><li>considering the bias of the data presenter,</li><li>recognising the bias of the data reader,</li><li>identifying any logical missteps between the data and the insight.</li></ol><h3>TL;DR</h3><ul><li>Always question the source of the data. If the source isn’t credible or isn’t provided, don’t be shy in rejecting the entire analysis.</li><li>Don’t hesitate to fact-check claims, especially when they seem counterintuitive.</li><li>Be aware of the data presenters bias. Ask yourself if they’d present the same analysis if it led to the opposite conclusion.</li><li>Be aware of confirmation bias. Ask yourself if you’d accept the same analysis if it led to the opposite conclusion.</li><li>Consider whether the analysis makes logical sense. Just because two things are correlated doesn’t mean one causes the other.</li><li>Recognise that data interpretation often involves assumptions and leaps in logic. It’s crucial to identify and evaluate these leaps using your own judgment.</li></ul><h3>Question One — Where did the data come from?</h3><p>Here is an excerpt from an article published in The Spectator, titled: ‘<a href="https://www.spectator.co.uk/article/the-unfashionable-truth-about-the-riots/">The unfashionable truth about the riots</a>’. Its subject is the 2024 anti-immigration riots in the UK.</p><blockquote>…I decided to do some checking on the employment stats for some of the northern towns that have seen the worst rioting in the past week. I also checked the 2011 statistics and then compared the two. I should warn you in advance that if you’re easily depressed, you should look away now.</blockquote><blockquote>Back in 2011, the proportion on out-of-work benefits (including incapacity benefit) in Sunderland was 18 per cent; today it is 19 per cent. In 2011 the unemployment figure in Rotherham was 16 per cent; today it is 18 per cent. In Hartlepool, it was 21 per cent; today, 23 per cent.</blockquote><blockquote>— <a href="https://www.spectator.co.uk/article/the-unfashionable-truth-about-the-riots/">The unfashionable truth about the riots</a>, The Spectator</blockquote><p>So, where did this data come from?</p><p>In the example, all we have is “the employment stats”… What the heck does that mean? In the UK there isn’t a centralised place for employment statistics, so it’s far from obvious what data the author is referring to. You might be content with dismissing the data and thus dismissing the rest of the article, since its premise is based on this data. However, I’m a try-hard, so I put on my best Sherlock Holmes hat and set about finding the un-cited data.</p><p>Sadly, I am not Sherlock Holmes. Despite considerable online sleuthing, I couldn’t find any data that matched the article’s. I did, however, find other “employment stats”. Specifically the Office of National Statistics (ONS)’s <a href="https://www.ons.gov.uk/employmentandlabourmarket/peoplenotinwork/unemployment">measure of unemployment</a> by region. It paints a very different picture. In fact the polar opposite picture! Of the three areas the article highlights as having reduced in employment since 2011, the ONS in fact finds they all increased!* I’m afraid the only unfashionable truth illuminated by this article is the degradation of news media. (Or was it always like this?)</p><p><em>*Data links: </em><a href="https://www.nomisweb.co.uk/reports/lmp/la/1946157068/subreports/ea_time_series/report.aspx?"><em>Sunderland</em></a><em>, </em><a href="https://www.nomisweb.co.uk/reports/lmp/la/1946157122/subreports/ea_time_series/report.aspx?"><em>Rotherham</em></a><em>, and </em><a href="https://www.nomisweb.co.uk/reports/lmp/la/1946157059/subreports/ea_time_series/report.aspx?"><em>Hartlepool</em></a><em> employment stats.</em></p><h3>Question Two — What if the opposite result were true?</h3><blockquote>…Using laboratory and field experiments, we find that signing before–rather than after–the opportunity to cheat makes ethics salient when they are needed most and significantly reduces dishonesty.</blockquote><blockquote>— <a href="https://sci-hub.se/10.1073/pnas.1209746109">Signing at the beginning makes ethics salient and decreases dishonest self-reports in comparison to signing at the end</a>, Lisa L. Shu et al.</blockquote><p>This quote comes from the abstract of a highly influential research paper in Behavioural Science. In case you didn’t quite understand the quote, since it is written in the classic academic obfuscation style, the quote is saying that signing your name on the top of a document makes you less likely to lie about the document than if you had signed on the bottom.</p><p>The data came from a collection of researchers based in highly regarded universities, most notably Francesca Gino who was a professor at Harvard Business School at the time of publication. For me, this passes our first question about the data (‘Where did the data come from?’).</p><p>Next we need to ask: ‘Would the data be presented if the opposite result were true?’ To answer this we first need to understand a little about the people and/or institutes presenting the data. In this case it is a group of Behavioural Science academics. Academia is a cut-throat industry, with an exceptionally <a href="https://www.youtube.com/watch?v=XAOs-frRfa4&amp;t=285s">high failure rate</a>. Therefore, it is critical for academics to be considered ‘successful’ as early as possible to avoid being culled. The key factor to determine an academic’s success is, unsurprisingly, their work. But how do you measure the quality of their work? A common method is <a href="https://www.stjude.org/research/progress/2020/the-benefits-of-being-highly-cited.html#:~:text=The%20more%20citations%20you%20have,based%20on%20their%20impact%20factor.">citation count</a>, that is the number of times an academic’s work is mentioned in the work of other academics.</p><p>The issue with this is you are far more likely to to be cited if you have an unexpected/interesting result in your paper. Going back to the original quote, do you think a result where there was no difference in honesty between the group who signed at the top vs the bottom of a document would have been nearly as influential? No, because that would have been the expectation. The conclusion is that there is a strong incentive for academics to generate unexpected/interesting results. Therefore, in our example, we should understand that there is a strong bias for the authors to claim a (significant) difference in honesty between the two groups.</p><p>This sort of bias is so strong that it has led the <a href="https://www.bbc.co.uk/news/science-environment-39054778">majority of scientific research to be unreproducible by fellow academics</a>. Unreproducible means an academic writes a research paper that copies another academic’s research paper’s method/experiment, but ends up with significantly different results to the original paper. Turning once more to our case study as an example, following the impactful success of the research paper, a number of other studies attempted to run the same or similar experiment. <a href="https://www.pnas.org/doi/10.1073/pnas.1911695117">All results</a> of the experiments found no correlation between honesty and location of document signature. It turned out the original paper’s finding was very likely the result of <a href="https://datacolada.org/109">data fraud</a>. As were a <a href="https://www.youtube.com/watch?v=yNK4nXWA_s8">number of other influential papers</a> co-authored by the prestigious Harvard professor, Francesca Gino.</p><p>This sort of skin-in-the-game bias isn’t only found in academia. From <a href="https://www.starburst.io/blog/lie-5-vendor-benchmarks-measure-real-world-performance/">tech vendors posting their latest performances vs competitors</a>, to investment banks presenting to prospective clients that they are no. 1 in the league tables*, bias is rife. And it isn’t only other people you should be concerned about. The strongest bias of all is most likely you—yes, YOU. Commonly referred to as confirmation bias, it is the tendency to search for, interpret, favour, and recall information in a way that confirms or supports your prior beliefs.</p><p>Ever wondered why such a mass of people could be so stupid on so many political topics? Sadly, it is more likely a result of <a href="https://danielnations.medium.com/why-do-republicans-and-democrats-let-other-people-do-their-thinking-dc6d208945e4">your own confirmation bias</a> than the collective dim-wittedness of millions of people.</p><p>If you want to avoid the pitfalls of your own biases, as well as the biases of the data presenter, you not only need to ask: ‘Would the data be presented if the opposite result were true?’ But also: ‘Would I consider the data presented if the opposite result were true?’ It may be a tough pill to swallow, but overcoming your own bias may enlighten you more than all the research in the world.</p><p><em>*</em><a href="https://maycontainlies.com/"><em>May Contain Lies</em></a><em>, Alex Edmans. Page 130.</em></p><h3>Question Three — Is there a flaw with the leap from data to insight?</h3><blockquote>For most university graduates, having a degree pays.</blockquote><blockquote>Over the course of a lifetime, estimates suggest women can expect to earn about £250,000 more if they have a degree, while the figure is roughly £170,000 for men.</blockquote><blockquote>— <a href="https://www.bbc.co.uk/news/education-41693230">The degrees that make you rich… and the ones that don’t</a>, BBC News</blockquote><p>This quote comes from the news department of the prestigious British Broadcasting Corporation (BBC). Specifically, their article titled: ‘<a href="https://www.bbc.co.uk/news/education-41693230">The degrees that make you rich… and the ones that don’t</a>’. First things first, is there a reliable data source?</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ejPw85eNRuPOq5sE-3YQzg.png"><figcaption>The source. BBC News, <a href="https://www.bbc.co.uk/news/education-41693230">The degrees that make you rich… and the ones that don’t</a></figcaption></figure><p>Great news, the answer is (probably*) yes! The article cites their data from another prestigious organisation, the Institute of Fiscal Studies. You may want to delve deeper into the exact report of the data source, but for a surface-level analysis, I’m happy with where this raw data has come from.</p><p>Second we want to ask ourselves, ‘would this information be presented if the opposite result was true?’ Given the BBC has (to my knowledge) no reason to support higher education institutions, it’s fair to assume that the BBC would have published an article highlighting no financial benefits to studying at university if the data suggested it.</p><p>However, unfortunately, we still can’t trust the BBC’s findings just yet. We have one final important question to ask: ‘Does the analysis make sense?’ After looking at the <a href="https://www.bbc.co.uk/news/education-41693230">article</a>’s chart on average earnings by subject, have a go at answering the following question before moving on to the next paragraph: ‘Given people with Medicine degrees earn more than the average degree, does it make sense to assume that the Medicine degree was the cause of the higher salary?’</p><p>My answer: Medicine degrees are necessary to become qualified doctors, and doctors generally earn a high income. This supports the idea that a Medicine degree is the specific reason for average higher future earnings. On the other hand, you don’t just need to pick Medicine, you also need to <em>be</em> picked for Medicine. Given the average A-level results for a UK Medicine graduate is an outstanding <a href="https://www.medify.co.uk/blog/a-level-requirements#:~:text=Most%20medical%20schools%20require%20AAA,each%20medical%20school%20requires%20below.&amp;text=A*AA%20(AAA%20considered%20if,biology%20and%20EPQ%20grade%20B)">AAA</a>, you could argue the reason for the high average salaries is because the average Medicine student is exceptionally cognitively capable (in academia at least), which has nothing to do with whether they actually chose Medicine as a degree or not.</p><p>What about the degree with the second highest average salary, Economics? Unlike Medicine, you don’t strictly need an Economics degree to qualify for any specific high-paying jobs. I’d argue an Economics degree is much less likely a direct factor in increasing a graduate’s future salary. For example, someone who is genuinely interested in money at school will be more likely to base their career decisions on what pays more. That same person may also be more likely to pick Economics at university.** If that’s true, then pushing someone who is not interested in money to study Economics may not benefit their future career or financial prospects as much as the article is implying.</p><p>Similarly, someone who earns a university degree in general may be little to no better off than if they hadn’t gone to university at all. It may simply be a side effect. For example, in the UK <a href="https://commonslibrary.parliament.uk/research-briefings/cbp-9195/#:~:text=Pupils%20eligible%20for%20free%20school,second%20year%20in%20higher%20education.">children with wealthy parents are significantly more likely to attend university</a>. The wealth of their parents may also have an impact on the child’s high-paying job prospects; for example, they might provide invaluable knowledge to their children on how to interview, climb the greasy corporate ladder, and/or network. Given this thought process, the article’s finding that “For most university graduates, having a degree pays” is, at the very least, not a proven fact, and should not be treated as such.</p><p>Deciding what ‘makes sense’ is subjective; for example, you may not have been convinced by my arguments above. However, it’s important to recognise the leaps in assumptions people make from data to insights, and to do your own ‘makes sense’ assessment before accepting them.</p><p><em>*It’s important to acknowledge the limitations of time we have on the depth of our investigation. For very serious things you will want to go deeper, but as a pragmatist, it isn’t possible for every data analysis we see.</em></p><p><em>**You may be thinking: ‘hang on a minute, you didn’t provide any data to back up that theory’. And you’re right! However, often times we don’t have all the data available to us, we simply have to use our own experiences and intuition. As an Economics graduate who has also been fascinated with finance from an early age, the theory makes sense to me.</em></p><h3>Wrapping up</h3><p>In conclusion, data should not be the driver of your decisions. Like an unpredictable friend, data belongs firmly in the passenger seat, preferably with the child-lock on. They can provide suggestions, but ultimately you need to be sceptical before making any decision based off of them.</p><p>Remember, when looking into data, statistics, and/or research, you need to ask yourself:</p><ol><li>Where did this data come from?</li><li>Would this data be presented if the opposite result were true?</li><li>Would I consider the data if the opposite result were true?</li><li>Is there a flaw with the leap from data to insight?</li></ol><h3><strong>Final note for data scientists/analysts</strong></h3><p>For data scientists and analysts, these questions are not just a safeguard — they’re a responsibility. As gatekeepers of data-driven insights, your role is crucial in ensuring that decisions are informed by sound reasoning, not just raw numbers and algorithms. By applying this mindset, you can avoid being that unpredictable friend in your organisation. And who know’s, one day you may even be invited into the driving seat.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=583b5e7abe7b" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/stop-being-data-driven-583b5e7abe7b">Stop Being Data-Driven</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Being Data-Driven]]></title>
<description><![CDATA[Why we are fooled by data and how to stop itsource: unsplash.comOften, when making decisions based on data, we feel as if we have made a more intelligent, accurate choice. The reality is a little different. From using it to purchase property, to deciding to go on a diet, to selecting a new board ...]]></description>
<link>https://tsecurity.de/de/2306415/ai-nachrichten/stop-being-data-driven/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2306415/ai-nachrichten/stop-being-data-driven/</guid>
<pubDate>Fri, 30 Aug 2024 02:50:01 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Why we are fooled by data and how to stop it</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*-DMUzqsJxapVIqS9"><figcaption>source: <a href="https://unsplash.com/">unsplash.com</a></figcaption></figure><p>Often, when making decisions based on data, we feel as if we have made a more intelligent, accurate choice. The reality is a little different. From using it to <a href="https://www.fullstackeconomics.com/p/why-zillow-is-like-my-bad-fantasy-football-team">purchase property</a>, to deciding to go on a <a href="https://www.scientificamerican.com/article/quack-cancer-diets-endanger-people-stick-to-science-backed-medicine/">diet</a>, to <a href="https://www.spectator.co.uk/article/is-diversity-actually-good-for-business/">selecting a new board member</a> for your company, data can be an amazing catalyst to help make the worst decisions.</p><p>Using real-world examples, this article covers common ways data can drive us over a cliff of misinformation. Fortunately, this article also gives actionable, easy-to-use advice on how to avoid such scenarios by following a four-step ladder to assess the quality of data-driven insights:</p><ol><li>evaluating the data source,</li><li>considering the bias of the data presenter,</li><li>recognising the bias of the data reader,</li><li>identifying any logical missteps between the data and the insight.</li></ol><h3>TL;DR</h3><ul><li>Always question the source of the data. If the source isn’t credible or isn’t provided, don’t be shy in rejecting the entire analysis.</li><li>Don’t hesitate to fact-check claims, especially when they seem counterintuitive.</li><li>Be aware of the data presenters bias. Ask yourself if they’d present the same analysis if it led to the opposite conclusion.</li><li>Be aware of confirmation bias. Ask yourself if you’d accept the same analysis if it led to the opposite conclusion.</li><li>Consider whether the analysis makes logical sense. Just because two things are correlated doesn’t mean one causes the other.</li><li>Recognise that data interpretation often involves assumptions and leaps in logic. It’s crucial to identify and evaluate these leaps using your own judgment.</li></ul><h3>Question One — Where did the data come from?</h3><p>Here is an excerpt from an article published in The Spectator, titled: ‘<a href="https://www.spectator.co.uk/article/the-unfashionable-truth-about-the-riots/">The unfashionable truth about the riots</a>’. Its subject is the 2024 anti-immigration riots in the UK.</p><blockquote>…I decided to do some checking on the employment stats for some of the northern towns that have seen the worst rioting in the past week. I also checked the 2011 statistics and then compared the two. I should warn you in advance that if you’re easily depressed, you should look away now.</blockquote><blockquote>Back in 2011, the proportion on out-of-work benefits (including incapacity benefit) in Sunderland was 18 per cent; today it is 19 per cent. In 2011 the unemployment figure in Rotherham was 16 per cent; today it is 18 per cent. In Hartlepool, it was 21 per cent; today, 23 per cent.</blockquote><blockquote>— <a href="https://www.spectator.co.uk/article/the-unfashionable-truth-about-the-riots/">The unfashionable truth about the riots</a>, The Spectator</blockquote><p>So, where did this data come from?</p><p>In the example, all we have is “the employment stats”… What the heck does that mean? In the UK there isn’t a centralised place for employment statistics, so it’s far from obvious what data the author is referring to. You might be content with dismissing the data and thus dismissing the rest of the article, since its premise is based on this data. However, I’m a try-hard, so I put on my best Sherlock Holmes hat and set about finding the un-cited data.</p><p>Sadly, I am not Sherlock Holmes. Despite considerable online sleuthing, I couldn’t find any data that matched the article’s. I did, however, find other “employment stats”. Specifically the Office of National Statistics (ONS)’s <a href="https://www.ons.gov.uk/employmentandlabourmarket/peoplenotinwork/unemployment">measure of unemployment</a> by region. It paints a very different picture. In fact the polar opposite picture! Of the three areas the article highlights as having reduced in employment since 2011, the ONS in fact finds they all increased!* I’m afraid the only unfashionable truth illuminated by this article is the degradation of news media. (Or was it always like this?)</p><p><em>*Data links: </em><a href="https://www.nomisweb.co.uk/reports/lmp/la/1946157068/subreports/ea_time_series/report.aspx?"><em>Sunderland</em></a><em>, </em><a href="https://www.nomisweb.co.uk/reports/lmp/la/1946157122/subreports/ea_time_series/report.aspx?"><em>Rotherham</em></a><em>, and </em><a href="https://www.nomisweb.co.uk/reports/lmp/la/1946157059/subreports/ea_time_series/report.aspx?"><em>Hartlepool</em></a><em> employment stats.</em></p><h3>Question Two — What if the opposite result were true?</h3><blockquote>…Using laboratory and field experiments, we find that signing before–rather than after–the opportunity to cheat makes ethics salient when they are needed most and significantly reduces dishonesty.</blockquote><blockquote>— <a href="https://sci-hub.se/10.1073/pnas.1209746109">Signing at the beginning makes ethics salient and decreases dishonest self-reports in comparison to signing at the end</a>, Lisa L. Shu et al.</blockquote><p>This quote comes from the abstract of a highly influential research paper in Behavioural Science. In case you didn’t quite understand the quote, since it is written in the classic academic obfuscation style, the quote is saying that signing your name on the top of a document makes you less likely to lie about the document than if you had signed on the bottom.</p><p>The data came from a collection of researchers based in highly regarded universities, most notably Francesca Gino who was a professor at Harvard Business School at the time of publication. For me, this passes our first question about the data (‘Where did the data come from?’).</p><p>Next we need to ask: ‘Would the data be presented if the opposite result were true?’ To answer this we first need to understand a little about the people and/or institutes presenting the data. In this case it is a group of Behavioural Science academics. Academia is a cut-throat industry, with an exceptionally <a href="https://www.youtube.com/watch?v=XAOs-frRfa4&amp;t=285s">high failure rate</a>. Therefore, it is critical for academics to be considered ‘successful’ as early as possible to avoid being culled. The key factor to determine an academic’s success is, unsurprisingly, their work. But how do you measure the quality of their work? A common method is <a href="https://www.stjude.org/research/progress/2020/the-benefits-of-being-highly-cited.html#:~:text=The%20more%20citations%20you%20have,based%20on%20their%20impact%20factor.">citation count</a>, that is the number of times an academic’s work is mentioned in the work of other academics.</p><p>The issue with this is you are far more likely to to be cited if you have an unexpected/interesting result in your paper. Going back to the original quote, do you think a result where there was no difference in honesty between the group who signed at the top vs the bottom of a document would have been nearly as influential? No, because that would have been the expectation. The conclusion is that there is a strong incentive for academics to generate unexpected/interesting results. Therefore, in our example, we should understand that there is a strong bias for the authors to claim a (significant) difference in honesty between the two groups.</p><p>This sort of bias is so strong that it has led the <a href="https://www.bbc.co.uk/news/science-environment-39054778">majority of scientific research to be unreproducible by fellow academics</a>. Unreproducible means an academic writes a research paper that copies another academic’s research paper’s method/experiment, but ends up with significantly different results to the original paper. Turning once more to our case study as an example, following the impactful success of the research paper, a number of other studies attempted to run the same or similar experiment. <a href="https://www.pnas.org/doi/10.1073/pnas.1911695117">All results</a> of the experiments found no correlation between honesty and location of document signature. It turned out the original paper’s finding was very likely the result of <a href="https://datacolada.org/109">data fraud</a>. As were a <a href="https://www.youtube.com/watch?v=yNK4nXWA_s8">number of other influential papers</a> co-authored by the prestigious Harvard professor, Francesca Gino.</p><p>This sort of skin-in-the-game bias isn’t only found in academia. From <a href="https://www.starburst.io/blog/lie-5-vendor-benchmarks-measure-real-world-performance/">tech vendors posting their latest performances vs competitors</a>, to investment banks presenting to prospective clients that they are no. 1 in the league tables*, bias is rife. And it isn’t only other people you should be concerned about. The strongest bias of all is most likely you—yes, YOU. Commonly referred to as confirmation bias, it is the tendency to search for, interpret, favour, and recall information in a way that confirms or supports your prior beliefs.</p><p>Ever wondered why such a mass of people could be so stupid on so many political topics? Sadly, it is more likely a result of <a href="https://danielnations.medium.com/why-do-republicans-and-democrats-let-other-people-do-their-thinking-dc6d208945e4">your own confirmation bias</a> than the collective dim-wittedness of millions of people.</p><p>If you want to avoid the pitfalls of your own biases, as well as the biases of the data presenter, you not only need to ask: ‘Would the data be presented if the opposite result were true?’ But also: ‘Would I consider the data presented if the opposite result were true?’ It may be a tough pill to swallow, but overcoming your own bias may enlighten you more than all the research in the world.</p><p><em>*</em><a href="https://maycontainlies.com/"><em>May Contain Lies</em></a><em>, Alex Edmans. Page 130.</em></p><h3>Question Three — Is there a flaw with the leap from data to insight?</h3><blockquote>For most university graduates, having a degree pays.</blockquote><blockquote>Over the course of a lifetime, estimates suggest women can expect to earn about £250,000 more if they have a degree, while the figure is roughly £170,000 for men.</blockquote><blockquote>— <a href="https://www.bbc.co.uk/news/education-41693230">The degrees that make you rich… and the ones that don’t</a>, BBC News</blockquote><p>This quote comes from the news department of the prestigious British Broadcasting Corporation (BBC). Specifically, their article titled: ‘<a href="https://www.bbc.co.uk/news/education-41693230">The degrees that make you rich… and the ones that don’t</a>’. First things first, is there a reliable data source?</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ejPw85eNRuPOq5sE-3YQzg.png"><figcaption>The source. BBC News, <a href="https://www.bbc.co.uk/news/education-41693230">The degrees that make you rich… and the ones that don’t</a></figcaption></figure><p>Great news, the answer is (probably*) yes! The article cites their data from another prestigious organisation, the Institute of Fiscal Studies. You may want to delve deeper into the exact report of the data source, but for a surface-level analysis, I’m happy with where this raw data has come from.</p><p>Second we want to ask ourselves, ‘would this information be presented if the opposite result was true?’ Given the BBC has (to my knowledge) no reason to support higher education institutions, it’s fair to assume that the BBC would have published an article highlighting no financial benefits to studying at university if the data suggested it.</p><p>However, unfortunately, we still can’t trust the BBC’s findings just yet. We have one final important question to ask: ‘Does the analysis make sense?’ After looking at the <a href="https://www.bbc.co.uk/news/education-41693230">article</a>’s chart on average earnings by subject, have a go at answering the following question before moving on to the next paragraph: ‘Given people with Medicine degrees earn more than the average degree, does it make sense to assume that the Medicine degree was the cause of the higher salary?’</p><p>My answer: Medicine degrees are necessary to become qualified doctors, and doctors generally earn a high income. This supports the idea that a Medicine degree is the specific reason for average higher future earnings. On the other hand, you don’t just need to pick Medicine, you also need to <em>be</em> picked for Medicine. Given the average A-level results for a UK Medicine graduate is an outstanding <a href="https://www.medify.co.uk/blog/a-level-requirements#:~:text=Most%20medical%20schools%20require%20AAA,each%20medical%20school%20requires%20below.&amp;text=A*AA%20(AAA%20considered%20if,biology%20and%20EPQ%20grade%20B)">AAA</a>, you could argue the reason for the high average salaries is because the average Medicine student is exceptionally cognitively capable (in academia at least), which has nothing to do with whether they actually chose Medicine as a degree or not.</p><p>What about the degree with the second highest average salary, Economics? Unlike Medicine, you don’t strictly need an Economics degree to qualify for any specific high-paying jobs. I’d argue an Economics degree is much less likely a direct factor in increasing a graduate’s future salary. For example, someone who is genuinely interested in money at school will be more likely to base their career decisions on what pays more. That same person may also be more likely to pick Economics at university.** If that’s true, then pushing someone who is not interested in money to study Economics may not benefit their future career or financial prospects as much as the article is implying.</p><p>Similarly, someone who earns a university degree in general may be little to no better off than if they hadn’t gone to university at all. It may simply be a side effect. For example, in the UK <a href="https://commonslibrary.parliament.uk/research-briefings/cbp-9195/#:~:text=Pupils%20eligible%20for%20free%20school,second%20year%20in%20higher%20education.">children with wealthy parents are significantly more likely to attend university</a>. The wealth of their parents may also have an impact on the child’s high-paying job prospects; for example, they might provide invaluable knowledge to their children on how to interview, climb the greasy corporate ladder, and/or network. Given this thought process, the article’s finding that “For most university graduates, having a degree pays” is, at the very least, not a proven fact, and should not be treated as such.</p><p>Deciding what ‘makes sense’ is subjective; for example, you may not have been convinced by my arguments above. However, it’s important to recognise the leaps in assumptions people make from data to insights, and to do your own ‘makes sense’ assessment before accepting them.</p><p><em>*It’s important to acknowledge the limitations of time we have on the depth of our investigation. For very serious things you will want to go deeper, but as a pragmatist, it isn’t possible for every data analysis we see.</em></p><p><em>**You may be thinking: ‘hang on a minute, you didn’t provide any data to back up that theory’. And you’re right! However, often times we don’t have all the data available to us, we simply have to use our own experiences and intuition. As an Economics graduate who has also been fascinated with finance from an early age, the theory makes sense to me.</em></p><h3>Wrapping up</h3><p>In conclusion, data should not be the driver of your decisions. Like an unpredictable friend, data belongs firmly in the passenger seat, preferably with the child-lock on. They can provide suggestions, but ultimately you need to be sceptical before making any decision based off of them.</p><p>Remember, when looking into data, statistics, and/or research, you need to ask yourself:</p><ol><li>Where did this data come from?</li><li>Would this data be presented if the opposite result were true?</li><li>Would I consider the data if the opposite result were true?</li><li>Is there a flaw with the leap from data to insight?</li></ol><h3><strong>Final note for data scientists/analysts</strong></h3><p>For data scientists and analysts, these questions are not just a safeguard — they’re a responsibility. As gatekeepers of data-driven insights, your role is crucial in ensuring that decisions are informed by sound reasoning, not just raw numbers and algorithms. By applying this mindset, you can avoid being that unpredictable friend in your organisation. And who know’s, one day you may even be invited into the driving seat.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=583b5e7abe7b" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/stop-being-data-driven-583b5e7abe7b">Stop Being Data-Driven</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Pulls Popular Indian Apps From Store Over Fees Violation]]></title>
<description><![CDATA[An anonymous reader shares a report: Google pulled more than a dozen popular Indian apps including recruitment platform Naukri, matrimony service Shaadi, audio storytelling platforms Kuku FM and Stage and real-estate manager 99acres from Play Store on Friday after warning that it will be taking a...]]></description>
<link>https://tsecurity.de/de/2053199/it-security-nachrichten/google-pulls-popular-indian-apps-from-store-over-fees-violation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2053199/it-security-nachrichten/google-pulls-popular-indian-apps-from-store-over-fees-violation/</guid>
<pubDate>Fri, 01 Mar 2024 15:52:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader shares a report: Google pulled more than a dozen popular Indian apps including recruitment platform Naukri, matrimony service Shaadi, audio storytelling platforms Kuku FM and Stage and real-estate manager 99acres from Play Store on Friday after warning that it will be taking actions against developers who have persistently not complied with its billing policies, escalating a three-year dispute in what is the company's largest market by users. Google said that 10 companies in the country, including "many well-established" names it did not disclose, had avoided paying fees despite benefiting from the platform. 

The Android-maker, owned by Alphabet, said a small group of developers in India had more than three years to prepare and comply with Play Store's payments policy but opted against it. These firms continue to comply with payment policies of other app stores, Google said. Some Android apps of matrimony platforms Shaadi, Matrimony.com and Bharat Matrimony were pulled from the Play Store Friday. Info Edge's Naukri and 99acres, audio storytelling apps Kuku FM and Stage, Alt Balaji's Altt, dating service Quack Quack were also axed from the store. 

Murugavel Janakiraman, chief executive of Bharat Matrimony, said Google had pulled about 10 of the Indian firm's apps from the store. Bharat Matrimony is evaluating legal options, he told TechCrunch, adding that he believes Google has violated an Indian antitrust watchdog's order in its removal of the apps today. It's a "dark day for the India internet," he added. Lal Chand Bisu, co-founder and chief executive of Kuku FM lambasted at Google, saying the Android-maker had turned "the most evil" partner to do business with and the Indian startup ecosystem was "completely" in its control.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Google+Pulls+Popular+Indian+Apps+From+Store+Over+Fees+Violation%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F24%2F03%2F01%2F1441203%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F24%2F03%2F01%2F1441203%2Fgoogle-pulls-popular-indian-apps-from-store-over-fees-violation%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/24/03/01/1441203/google-pulls-popular-indian-apps-from-store-over-fees-violation?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BlueBunny - BLE Based C2 For Hak5's Bash Bunny]]></title>
<description><![CDATA[C2 solution that communicates directly over Bluetooth-Low-Energy with your Bash Bunny Mark II.Send your Bash Bunny all the instructions it needs just over the air.  Overview  Structure  Installation & Start    Install required dependencies    pip install pygatt "pygatt[GATTTOOL]"  Make sure BlueZ...]]></description>
<link>https://tsecurity.de/de/1953770/it-security-nachrichten/bluebunny-ble-based-c2-for-hak5s-bash-bunny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1953770/it-security-nachrichten/bluebunny-ble-based-c2-for-hak5s-bash-bunny/</guid>
<pubDate>Thu, 07 Dec 2023 12:35:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blogger.googleusercontent.com/img/a/AVvXsEgoq9tFrX8iPAgtHe4y6eQJwBPwkX02L4RJdvUOgK7kaWHlXUBf_eJ1GNa8bGmLIgFETUt4kdBe5UctXhnBBMtzidXgzPopRzyCAfQzrDCUleZk9i_RU2JZCsObpFxjP33P_505Ci_kdqI3t4_zhrvuWYGH-u-tPo8rM2xoZkAvN90GBgeu_0qefQSfz6GS"><img alt="" border="0" height="214" src="https://blogger.googleusercontent.com/img/a/AVvXsEgoq9tFrX8iPAgtHe4y6eQJwBPwkX02L4RJdvUOgK7kaWHlXUBf_eJ1GNa8bGmLIgFETUt4kdBe5UctXhnBBMtzidXgzPopRzyCAfQzrDCUleZk9i_RU2JZCsObpFxjP33P_505Ci_kdqI3t4_zhrvuWYGH-u-tPo8rM2xoZkAvN90GBgeu_0qefQSfz6GS=w640-h214" width="640"></a></p><p dir="auto"><br></p>  <p align="center" dir="auto">    C2 solution that communicates directly over Bluetooth-Low-Energy with your Bash Bunny Mark II.<br>Send your Bash Bunny all the instructions it needs just over the air.</p>  <h2 dir="auto" tabindex="-1">Overview</h2>  <h4 dir="auto" tabindex="-1">Structure</h4><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxFaZHnzMUstOB7syhqIQyWtZ8dU6S5G8gdbtrbJ55_TWnFjpxCouOOFtPB5d077NA5meNFqkni5obyaUMo8FHlVwrldFtU77BsDmFhEUE9OSPQ_4M836o2o94NgcAir6okASuOt7t_XURfL48ie8fa0txcMQmfyYhFPBIxPVWcFbo-iD5ZsWrNWhQkcat/s4057/279433433-3004fb10-feef-45c8-8624-1393c2fb7288.png" imageanchor="1"><img border="0" data-original-height="923" data-original-width="4057" height="146" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxFaZHnzMUstOB7syhqIQyWtZ8dU6S5G8gdbtrbJ55_TWnFjpxCouOOFtPB5d077NA5meNFqkni5obyaUMo8FHlVwrldFtU77BsDmFhEUE9OSPQ_4M836o2o94NgcAir6okASuOt7t_XURfL48ie8fa0txcMQmfyYhFPBIxPVWcFbo-iD5ZsWrNWhQkcat/w640-h146/279433433-3004fb10-feef-45c8-8624-1393c2fb7288.png" width="640"></a></div><span><a name="more"></a></span><p dir="auto"><br></p>  <h2 dir="auto" tabindex="-1">Installation &amp; Start</h2>  <ol dir="auto">  <li>Install required dependencies</li>  </ol>  <div><pre><code>pip install pygatt "pygatt[GATTTOOL]"<br></code></pre></div>  <p dir="auto">Make sure <a href="http://www.bluez.org/download/" rel="nofollow" target="_blank" title="BlueZ">BlueZ</a> is installed and <code>gatttool</code> is usable</p>  <div><pre><code>sudo apt install bluez<br></code></pre></div>  <ol dir="auto" start="2">  <li>Download BlueBunny's repository (and switch into the correct folder)</li>  </ol>  <div><pre><code>git clone https://github.com/90N45-d3v/BlueBunny<br>cd BlueBunny/C2<br></code></pre></div>  <ol dir="auto" start="3">  <li>Start the C2 server</li>  </ol>  <div><pre><code>sudo python c2-server.py<br></code></pre></div>  <ol dir="auto" start="4">  <li>Plug your Bash Bunny with the BlueBunny <a href="https://www.kitploit.com/search/label/Payload" target="_blank" title="payload">payload</a> into the target machine (payload at: <code>BlueBunny/payload.txt</code>).</li>  <li>Visit your C2 server from your browser on <code>localhost:1472</code> and connect your Bash Bunny (Your Bash Bunny will light up green when it's ready to pair).</li>  </ol>  <h2 dir="auto" tabindex="-1">Manual communication with the Bash Bunny through Python</h2>  <p dir="auto">You can use BlueBunny's BLE backend and communicate with your Bash Bunny manually.</p>  <h4 dir="auto" tabindex="-1">Example Code</h4>  <div class="highlight highlight-source-python notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='# Import the backend (BlueBunny/C2/BunnyLE.py)  import BunnyLE    # Define the data to send  data = "QUACK STRING I love my Bash Bunny"  # Define the type of the data to send ("cmd" or "payload") (payload data will be temporary written to a file, to execute multiple commands like in a payload script file)  d_type = "cmd"    # Initialize BunnyLE  BunnyLE.init()    # Connect to your Bash Bunny  bb = BunnyLE.connect()    # Send the data and let it execute  BunnyLE.send(bb, data, d_type)' dir="auto"><pre><code># Import the backend (BlueBunny/C2/BunnyLE.py)<br>import BunnyLE<br><br># Define the data to send<br>data = "QUACK STRING I love my Bash Bunny"<br># Define the type of the data to send ("cmd" or "payload") (payload data will be temporary written to a file, to execute multiple commands like in a payload script file)<br>d_type = "cmd"<br><br># Initialize BunnyLE<br>BunnyLE.init()<br><br># Connect to your Bash Bunny<br>bb = BunnyLE.connect()<br><br># Send the data and let it execute<br>BunnyLE.send(bb, data, d_type)</code></pre></div>  <h2 dir="auto" tabindex="-1">Troubleshooting</h2>  <h4 dir="auto" tabindex="-1">Connecting your Bash Bunny doesn't work? Try the following instructions:</h4>  <ul dir="auto">  <li>Try connecting a few more times</li>  <li>Check if your bluetooth adapter is available</li>  <li>Restart the system your C2 server is running on</li>  <li>Check if your Bash Bunny is running the BlueBunny payload properly</li>  <li>How far away from your Bash Bunny are you? Is the environment (distance, interferences etc.) still sustainable for typical BLE connections?</li>  </ul>  <h4 dir="auto" tabindex="-1">Bugs within BlueZ</h4>  <p dir="auto">The <a href="https://www.kitploit.com/search/label/Bluetooth" target="_blank" title="Bluetooth">Bluetooth</a> stack used is well known, but also very buggy. If starting the connection with your Bash Bunny does not work, it is probably a temporary problem due to BlueZ. Here are some kind of errors that can be caused by temporary bugs. These usually disappear at the latest after rebooting the C2's operating system, so don't be surprised and calm down if they show up.</p>  <ul dir="auto">  <li>Timeout after 5.0 seconds</li>  <li>Unknown error while <a href="https://www.kitploit.com/search/label/Scanning" target="_blank" title="scanning">scanning</a> for BLE devices</li>  </ul>  <h2 dir="auto" tabindex="-1">Working on...</h2>  <ul dir="auto">  <li>Remote shell access</li>  <li>BLE <a href="https://www.kitploit.com/search/label/Exfiltration" target="_blank" title="exfiltration">exfiltration</a> channel</li>  <li>Improved connecting process</li>  </ul>  <h2 dir="auto" tabindex="-1">Additional information</h2>  <p dir="auto">As I said, BlueZ, the base for the bluetooth part used in BlueBunny, is somewhat bug prone. If you encounter any non-temporary bugs when connecting to Bash Bunny as well as any other bugs/difficulties in the whole BlueBunny project, you are always welcome to contact me. Be it a problem, an idea/solution or just a nice feedback.</p>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/90N45-d3v/BlueBunny" rel="nofollow" target="_blank" title="Download BlueBunny">Download BlueBunny</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Serverless Query Engine from Spare Parts]]></title>
<description><![CDATA[An open-source implementation of a Data Lake with DuckDB and AWS LambdasA duck in the cloud. Photo by László Glatz on UnsplashIn this post we will show how to build a simple end-to-end application in the cloud on a serverless infrastructure. The purpose is simple: we want to show that we can deve...]]></description>
<link>https://tsecurity.de/de/1882621/ai-nachrichten/a-serverless-query-engine-from-spare-parts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1882621/ai-nachrichten/a-serverless-query-engine-from-spare-parts/</guid>
<pubDate>Thu, 27 Apr 2023 08:04:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><strong><em>An open-source implementation of a Data Lake with DuckDB and AWS Lambdas</em></strong></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*lAx4iKFf7JMZFVUq"><figcaption>A duck in the cloud. Photo by <a href="https://unsplash.com/ko/@glatz0?utm_source=medium&amp;utm_medium=referral">László Glatz</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><p>In this post we will show how to build a simple end-to-end application in the cloud on a serverless infrastructure. The purpose is simple: we want to show that we can develop directly against the cloud while minimizing the cognitive overhead of designing and building infrastructure. Plus, we will put together a design that minimizes costs compared to modern data warehouses, such as Big Query or Snowflake.</p><p>As data practitioners we want (and love) to build applications on top of our data as seamlessly as possible. Whether you work in BI, Data Science or ML all that matters is the final application and how fast you can see it working end-to-end. The infrastructure often gets in the way though.</p><p>Imagine, as a practical example, that we need to build a new customer-facing analytics application for our product team. Because it’s client-facing we have performance constraints we need to respect, such as low latency.</p><p>We can start developing it directly in the cloud, but it would immediately bring us to some infra questions: where do we run it? How big a machine do we need? Because of the low-latency requirement, do we need to build a caching layer? If so, how do we do it?</p><p>Alternatively, we can develop our app locally. It will probably be more intuitive from the developer experience point of view but it only postpones the infra questions, since in the end we will have to find a way to go from our local project to actual pipelines. Moreover, the data will need to leave the cloud env to go on our machine, which is not exactly secure and auditable.</p><p>To make the cloud experience as smooth as possible we designed a data lake architecture where data are sitting in a simple cloud storage (AWS S3) and a serverless infrastructure that embeds DuckDB works as a query engine. At the end of the cycle, we will have an analytics app that can be used to both visualize and query the data in real time with virtually no infra costs.</p><p>Of course, this is a bit of a simplification, as some tweaks would be needed to run this project in real production scenarios. What we provide is a general blueprint to leverage the separation of storage and compute to build a data lake with a query engine in the cloud. We show how to power an interactive data app with an (almost) free cloud endpoint, no warehouse setup, and lighting fast performance. In our implementation, the final application is a simple <a href="https://streamlit.io/">Streamlit</a> app, but that’s merely for explanatory purposes: you can easily think of plugging in your favorite BI tool.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TmZw8AZHHRciFVxr_kkqoQ.gif"><figcaption>A lightinign fast analytics app built with our system. Image from the authors.</figcaption></figure><h4><strong>Ducks go serverless</strong></h4><p>Y’all know DuckDB at this point. It is an open-source in-process SQL OLAP database built specifically for analytical queries. It is somewhat still unclear how much DuckDB is actually <a href="https://dlthub.com/docs/blog/duckdb-1M-downloads-users">used in production</a>, but for us today the killer feature is the possibility of querying parquet files directly in S3 with SQL syntax.</p><p>So most practitioners seem to be using it right now as a local engine for data exploration, <em>ad hoc</em> analysis, POCs and prototyping (with some <a href="https://duckdb.org/2022/10/12/modern-data-stack-in-a-box.html">creative ideas</a> on how to extend its initial purpose to cover more surface:). People create notebooks or small data apps with embedded DuckDB to prototype and experiment with production data locally.</p><h3>fs111 @fs111@mastodon.xyz on Twitter: "It is infinitely nicer to use @duckdb to quickly look at @ApacheParquet files than using any of the horrible hadoop/spark things. / Twitter"</h3><p>It is infinitely nicer to use @duckdb to quickly look at @ApacheParquet files than using any of the horrible hadoop/spark things.</p><p>The cloud is better. And if we often feel it isn’t, it’s because something is wrong with the tool chain we use, but there is a very big difference between a <a href="https://www.facebook.com/CoachBillHart/videos/yep-worst-idea-ever/682926339663235/">bad idea</a> and a <a href="https://www.ebay.com/itm/256040369567">good idea badly executed</a>.</p><p>If we combine a data lake architecture, a serverless design, DuckDB and a bit of ingenuity we can build a very fast data stack from spare parts: no warehouse setup, lighting fast performance and outrageously cheap costs — S3 most expensive standard pricing is $0.023 per GB, AWS Lambda is very fast and scales to zero when not in use, so it is a no-fat computation bill, plus AWS gives you 1M calls for free.</p><p>Buckle up,<a href="https://github.com/BauplanLabs/quack-reduce/"> clone the repo</a>, sing along and for more details, please refer to the <a href="https://github.com/BauplanLabs/quack-reduce#quack-reduce">README</a>.</p><h4><strong>Architecture</strong></h4><p>This project is pretty self-contained and requires only introductory-level familiarity with cloud services and Python.</p><p>The idea is to start from a Data Lake where our data are stored. Once the data is uploaded in our S3 in a parquet format, we can then trigger the lambda with a SQL query. At that point, our lambda goes up, spins up a DuckDB instance in memory, computes the query and gets back to the user with the results, which can be directly rendered as tables in the Terminal.</p><p>The architecture has a number of advantages mostly coming from the serverless design: speed, proximity to the data and one line deployment are nice; plus, of course, the system scales to zero when not used, so we only pay per query.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/0*7seeuwA56eSL5wcB"><figcaption>General architecture of our system. Image from the authors</figcaption></figure><h4><strong>Your first query engine + data lake from spare parts</strong></h4><p>We provide a simple script that will create an S3 bucket and populate it with a portion of the <a href="https://www.nyc.gov/site/tlc/about/tlc-trip-record-data.page">NYC TLC Trip Record Data </a>(available under the <a href="https://www.nyc.gov/home/terms-of-use.page">nyc.gov terms of use</a>), both as a unique file and as a hive-partitioned directory (you can run it with <a href="https://github.com/BauplanLabs/quack-reduce/blob/74846468fd7b5dd2087691d1bc3d7aaa8417aa39/src/Makefile#L15">Make</a>). Once the data are in the data lake we can set up and use our lambda: if you have the Serverless CLI setup correctly, deploying the lambda is <a href="https://github.com/BauplanLabs/quack-reduce/blob/74846468fd7b5dd2087691d1bc3d7aaa8417aa39/src/Makefile#L7">one command of Make again</a>.</p><p>The lambda can be invoked in any of the usual ways, and accepts a query as its main payload: when it runs, it uses DuckDB (re-using an instance if on a warm start) to execute the query on the data lake. DuckDb does not know anything about the data before and after the execution, making the lambda purely stateless as far as data semantics is concerned.</p><p>For instance, you can use the simple Python script in the project to send this query to the lambda, and display the results:</p><pre>SELECT<br>  pickup_at as pickup_time,<br>  dropoff_at as dropoff_location,<br>  trip_distance<br>FROM read_parquet(your_s3_bucket/dataset/taxi_2019_04.parquet')<br>WHERE pickup_at &gt;= '2019–04–01' AND pickup_at &lt; '2019–04–03'<br>LIMIT 10</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*saLF4CCyp2kl91aW"><figcaption>The results are visualized directly in your terminal. Image from the authors.</figcaption></figure><p>Et voilà! You can now query your data lake, securely in the cloud. This very simple design addresses directly two of the typical frictions for working in cloud data warehouses:</p><ul><li>The setup is significantly simplified since all the user needs to do is to have her AWS credential. Once the setup is done, the user only needs access to the lambda (or any proxy to it!): that is good, as it gives the user full query capabilities without access to the underlying storage.</li><li>The performances are so good that it feels like developing locally, even if we always go through the cloud. A snappy cloud experience helps tame the too familiar feeling that advantages of working on remote machines is paid in the coin of good developer experience.</li></ul><h4><strong>(Almost) Free Analytics</strong></h4><p>It’s all good and boujee, but let us say that we want to do a bit more than query data on the fly. Let’s say that we want to build an application on top of a table. It’s a very simple app, there is no orchestration and no need to calibrate the workload.</p><p>At the same time, let’s say that this application needs to be responsive, it needs to be fast. Anyone who deals with clients directly, for instance, knows how it is important to provide a fresh responsive experience to the clients who want to see their data. The one thing nobody likes is a dashboard that takes minutes to load.</p><p>To see how this architecture can bridge the gap between data pipelines and real-time querying for analytics, we provide a small dbt DAG to simulate running some offline SQL transformations over the original dataset resulting in a new artifact in the data lake (the equivalent of a dashboard view).</p><p>To keep things as self contained as possible, we included a version that you can run locally on your machine (see README for more details — nor dbt nor the engine behind it matter for this pattern to work). However, you can use a different runtime for dbt and export the final artifact as a parquet file, with <a href="https://docs.snowflake.com/en/user-guide/script-data-load-transform-parquet">Snowflake</a> or <a href="https://cloud.google.com/dataflow/docs/guides/templates/provided/bigquery-to-parquet">BigQuery</a>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/0*ZDbuYkUEJALqcYxb"><figcaption>Architecture of our system paired with a dbt project. Image from the authors.</figcaption></figure><p>For the time being, we’ll stick to our super simple DAG made of two nodes. The first node takes the pickup_location_id from our data lake and order them by the number of trips:</p><pre>SELECT<br>  pickup_location_id AS location_id,<br>COUNT(*) AS counts<br>FROM read_parquet(['s3://{{ env_var('S3_BUCKET_NAME') }}/dataset/taxi_2019_04.parquet'])<br>GROUP BY 1</pre><p>The second that gives as the top 200 pick up locations in our data set:</p><pre>SELECT<br>  location_id,<br>  counts<br>FROM {{ ref('trips_by_pickup_location') }}<br>ORDER BY 2 DESC<br>LIMIT 200</pre><p>We can visualize the DAG with dbt docs:</p><p>Once our pipeline is done, the final artifact is uploaded back to our data lake in:</p><pre>s3:/your_s3_bucket/dashboard/my_view.parquet</pre><p>We can then reuse the query engine we built before to query the second (and final) node of our DAG to visualize the data in a Streamlit app, simply by running in the terminal:</p><pre>(venv) cirogreco@Ciros-MBP src % make dashboard</pre><p>Every time we hit the dashboard, the dashboard hits the lambda behind the scenes. If you like this simple architecture, the same pattern can be used in your own Streamlit app, or in your favorite BI tool.</p><h4><strong>A few remarks on the “Reasonable Scale”</strong></h4><p><a href="https://tenor.com/view/yeah-i-member-memberberries-south-park-i-remember-oh-yeah-gif-20408218">A while ago</a>, we wrote a series of posts on what we called <a href="https://towardsdatascience.com/tagged/mlops-without-much-ops">MLOps at Reasonable Scale</a> where we talked about the best strategies to build reliable ML applications in companies that do not process data at internet scale and have a number of constraints that truly Big-Data companies typically do not have. We mostly talked about it from the point of view of ML and MLOps because operationalizing successfully ML was a major problem for organizations at the time (maybe it still is, I am not sure), but one general observation remains: most data organizations are “Reasonable Scale” and they should design their systems around this assumption. Note that being a reasonable scale organization does not necessarily mean being a small company. The enterprise world is full of data teams who deal with a lot of complexity within large — sometimes enormous — organizations and yet have many reasonable scale pipelines, often for internal stakeholders, ranging from a few GB to at most a TB.</p><p>Recently, we happily witnessed a growing debate around whether companies need Big Data systems to deal with their data problems,. The most important takeaway from our point of view remains that, if you are a Reasonable Scale organization, dealing with unnecessary infrastructure can be a very serious burden with plenty of nefarious ramifications in your organization processes. You could in principle build an entire data stack to support low latency dashboards — maybe you could use a Data Warehouse and a caching layer -, but since your resources are limited, wouldn’t it be nice to have a simpler and cheaper way?</p><p>In this post, we showed that the combination of data-first storage formats, on-demand compute and in-memory OLAP processing opens up for new possibilities at Reasonable Scale. The system is far from perfect and <a href="https://github.com/BauplanLabs/quack-reduce#whats-next">could use many improvements</a>, but it shows that one can build an interactive data app with no warehouse setup, lighting fast performances and virtually no costs. By removing the db from DuckDB, we can combine what is fundamentally right about local (“single node processing is all you need”) with what is fundamentally right about the cloud (“data is better processed elsewhere”).</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=bd6320f10353" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/a-serverless-query-engine-from-spare-parts-bd6320f10353">A Serverless Query Engine from Spare Parts</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ducky One 3 SF im Test: „Quack Mechanics“ ist mehr als Marketing-Geschnatter]]></title>
<description><![CDATA[Die neue Ducky-Tastatur One 3 SF setzt auf „Quack Mechanics“. Das klingt nach Marketing-Geschnatter, hat aber ordentlich Biss. Das neue Quaken macht die One 3 SF zu einem deutlichen Upgrade. Nicht alle Neuerungen sind allerdings eindeutige Fortschritte.]]></description>
<link>https://tsecurity.de/de/1561913/it-nachrichten/ducky-one-3-sf-im-test-quack-mechanics-ist-mehr-als-marketing-geschnatter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1561913/it-nachrichten/ducky-one-3-sf-im-test-quack-mechanics-ist-mehr-als-marketing-geschnatter/</guid>
<pubDate>Wed, 06 Jul 2022 10:05:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/0/3/6/3/2-c16975bb28074fa2/article-640x360.4ad818f7.jpg"><p>Die neue Ducky-Tastatur One 3 SF setzt auf „Quack Mechanics“. Das klingt nach Marketing-Geschnatter, hat aber ordentlich Biss. Das neue Quaken macht die One 3 SF zu einem deutlichen Upgrade. Nicht alle Neuerungen sind allerdings eindeutige Fortschritte.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Search Milestone Gives DuckDuckGo Something to Quack About]]></title>
<description><![CDATA[DuckDuckGo reached a significant milestone last week when it racked up more than 100 million searches in a single day. While still a paltry number compared to the more than five billion daily searches performed by Google, the milestone is a major one for the search engine that doesn't store any o...]]></description>
<link>https://tsecurity.de/de/1355094/it-nachrichten/search-milestone-gives-duckduckgo-something-to-quack-about/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1355094/it-nachrichten/search-milestone-gives-duckduckgo-something-to-quack-about/</guid>
<pubDate>Tue, 19 Jan 2021 14:01:52 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[DuckDuckGo reached a significant milestone last week when it racked up more than 100 million searches in a single day. While still a paltry number compared to the more than five billion daily searches performed by Google, the milestone is a major one for the search engine that doesn't store any of its users' personal information, archive their search histories, or track their search activity.]]></content:encoded>
</item>
<item>
<title><![CDATA[Among 2020's Most Underreported Stories: Pharmaceutical Profiteering May Accelerate Superbugs]]></title>
<description><![CDATA[Since 1976 "Project Censored," a U.S.-based nonprofit media watchdog organization, has been identifying "the news that didn't make the news," the most significant stories it believes are being systematically overlooked. Slashdot ran stories about its annual list of the year's most censored news s...]]></description>
<link>https://tsecurity.de/de/1341556/it-security-nachrichten/among-2020s-most-underreported-stories-pharmaceutical-profiteering-may-accelerate-superbugs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1341556/it-security-nachrichten/among-2020s-most-underreported-stories-pharmaceutical-profiteering-may-accelerate-superbugs/</guid>
<pubDate>Sun, 03 Jan 2021 02:16:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Since 1976 "Project Censored," a U.S.-based nonprofit media watchdog organization, has been identifying "the news that didn't make the news," the most significant stories it believes are being systematically overlooked. Slashdot ran stories about its annual list of the year's most censored news stories in 1999, 2003, 2004, and in 2007, when they'd presciently warned that the media was ignoring the issue of net neutrality. 

But their latest list of underreported stories includes this disturbing headline: "Antibiotic Abuse: Pharmaceutical Profiteering Accelerates Superbugs."

Pharmaceutical giants Abbott and Sun Pharma are providing dangerous amounts of antibiotics to unlicensed doctors in India and incentivizing them to overprescribe. In August 2019 the Bureau of Investigative Journalism (BIJ) reported that these unethical business practices are leading to a rise in superbugs, or bacterial infections that are resistant to antibiotic treatment. Bacteria naturally evolve a resistance to antibiotics over time, but the widespread and inappropriate use of antibiotics accelerates this process. Superbugs are killing at least 58,000 babies each year and rendering a growing number of patients untreatable with all available drugs. 

India's unlicensed medical practitioners, known as "quack" doctors, are being courted by Abbott and Sun Pharma, billion-dollar companies that do business in more than one hundred countries, including the United States. The incentives these companies provide to quack doctors to sell antibiotics have included free medical equipment, gift cards, televisions, travel, and cash, earning some doctors nearly a quarter of their salary. "Sales representatives would also offer extra pills or money as an incentive to buy more antibiotics, encouraging potentially dangerous overprescription," a Sun Pharma sales representative revealed to an undercover BIJ reporter... [P]atients without access to better care often turn to quack doctors for treatment, and many are unaware that their local medical "professionals" have no formal training and are being bribed to sell unnecessary antibiotics. 

In September 2019, the BIJ reported on similar problems with broken healthcare systems, medical corruption, and dangerous superbugs in Cambodia. Their account describes how patients often request antibiotics for common colds, to pour onto wounds, and to feed to animals. Illegally practicing doctors and pharmacists in Cambodia admitted that they would often prescribe based on customer requests rather than appropriate medical guidelines. As the BIJ noted, "This kind of misuse speeds up the creation of drug resistant bacteria, or superbugs, which are predicted to kill 10 million people by 2050 if no action is taken...." 

Although superbugs have attracted some attention, their cause and importance remain poorly understood by the public. The Independent and BuzzFlash republished the Bureau of Investigative Journalism's report; otherwise, the role of pharmaceutical companies in the rise of dangerous superbugs has been drastically underreported. 

The site's list of the top 25 censored stories of 2019 - 2020 also includes:

 Growing interest in so-called "public" banks, "not legally obligated to maximize profits, as private banks are; instead, public banks are mandated to serve their communities."
How rising sea levels and warmer waters will impact nuclear power plants, "posing increased risks of nuclear disasters."
Proposals to revitalize journalism through public funding.
How the U.S. military represents "a massive, hidden contributor to the climate crisis."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Among+2020's+Most+Underreported+Stories%3A+Pharmaceutical+Profiteering+May+Accelerate+Superbugs%3A+https%3A%2F%2Fbit.ly%2F3hAt7Yf"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F21%2F01%2F02%2F0456221%2Famong-2020s-most-underreported-stories-pharmaceutical-profiteering-may-accelerate-superbugs%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/21/01/02/0456221/among-2020s-most-underreported-stories-pharmaceutical-profiteering-may-accelerate-superbugs?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CDPwn Cisco RCE vulnerability affecting millions of devices]]></title>
<description><![CDATA[submitted by    /u/le-quack  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1014422/it-security-nachrichten/cdpwn-cisco-rce-vulnerability-affecting-millions-of-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1014422/it-security-nachrichten/cdpwn-cisco-rce-vulnerability-affecting-millions-of-devices/</guid>
<pubDate>Wed, 05 Feb 2020 20:01:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table><tr><td> <a href="https://www.reddit.com/r/security/comments/ezdkt1/cdpwn_cisco_rce_vulnerability_affecting_millions/"> <img src="https://b.thumbs.redditmedia.com/LUT2IkJ2egMjnq-gc7SDa1zUjWrAk6Dq3hluFXPUpFY.jpg" alt="CDPwn Cisco RCE vulnerability affecting millions of devices" title="CDPwn Cisco RCE vulnerability affecting millions of devices"></a> </td><td>   submitted by   <a href="https://www.reddit.com/user/le-quack"> /u/le-quack </a> <br><span><a href="https://www.armis.com/cdpwn/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/ezdkt1/cdpwn_cisco_rce_vulnerability_affecting_millions/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[EmoCheck and Emotet Infection Detection Tool]]></title>
<description><![CDATA[submitted by    /u/le-quack  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1012420/it-security-nachrichten/emocheck-and-emotet-infection-detection-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1012420/it-security-nachrichten/emocheck-and-emotet-infection-detection-tool/</guid>
<pubDate>Tue, 04 Feb 2020 10:30:12 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table><tr><td> <a href="https://www.reddit.com/r/security/comments/eynbfo/emocheck_and_emotet_infection_detection_tool/"> <img src="https://b.thumbs.redditmedia.com/EUVcW74hL12o5GJfZbFJyZNVybpO3o2ywutXg1wsYBQ.jpg" alt="EmoCheck and Emotet Infection Detection Tool" title="EmoCheck and Emotet Infection Detection Tool"></a> </td><td>   submitted by   <a href="https://www.reddit.com/user/le-quack"> /u/le-quack </a> <br><span><a href="https://github.com/JPCERTCC/EmoCheck/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/eynbfo/emocheck_and_emotet_infection_detection_tool/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Remote code execution vulnerability in SMTP mail server used by some BSD/Linux distros.]]></title>
<description><![CDATA[submitted by    /u/le-quack  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1007876/it-security-nachrichten/remote-code-execution-vulnerability-in-smtp-mail-server-used-by-some-bsdlinux-distros/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1007876/it-security-nachrichten/remote-code-execution-vulnerability-in-smtp-mail-server-used-by-some-bsdlinux-distros/</guid>
<pubDate>Wed, 29 Jan 2020 19:45:12 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/le-quack"> /u/le-quack </a> <br><span><a href="https://www.qualys.com/2020/01/28/cve-2020-7247/lpe-rce-opensmtpd.txt">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/evqk9y/remote_code_execution_vulnerability_in_smtp_mail/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious library in PyPi present for almost a year. Recommend all projects using the package index check dependencies]]></title>
<description><![CDATA[submitted by    /u/le-quack  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/938162/it-security-nachrichten/malicious-library-in-pypi-present-for-almost-a-year-recommend-all-projects-using-the-package-index-check-dependencies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/938162/it-security-nachrichten/malicious-library-in-pypi-present-for-almost-a-year-recommend-all-projects-using-the-package-index-check-dependencies/</guid>
<pubDate>Wed, 04 Dec 2019 20:01:31 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table><tr><td> <a href="https://www.reddit.com/r/security/comments/e62wxi/malicious_library_in_pypi_present_for_almost_a/"> <img src="https://b.thumbs.redditmedia.com/h029L4GL3e3HEkdofyP5VfHAbsiqhrXH0gTv37-riDY.jpg" alt="Malicious library in PyPi present for almost a year. Recommend all projects using the package index check dependencies" title="Malicious library in PyPi present for almost a year. Recommend all projects using the package index check dependencies"></a> </td><td>   submitted by   <a href="https://www.reddit.com/user/le-quack"> /u/le-quack </a> <br><span><a href="https://github.com/dateutil/dateutil/issues/984">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/e62wxi/malicious_library_in_pypi_present_for_almost_a/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[AV and client firewall for Linux]]></title>
<description><![CDATA[It's been a while since I've used Linux in a non professional setting (even then I'm primarily a MS environment tech but I've got a basic knowledge of Linux) but I'm going to use Linux on my everyday laptop for a while as a bit of a refresher. What the recommended AV product? Is it still clamav? ...]]></description>
<link>https://tsecurity.de/de/422736/linux-tipps/av-and-client-firewall-for-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/422736/linux-tipps/av-and-client-firewall-for-linux/</guid>
<pubDate>Fri, 07 Dec 2018 08:15:47 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<p>It's been a while since I've used Linux in a non professional setting (even then I'm primarily a MS environment tech but I've got a basic knowledge of Linux) but I'm going to use Linux on my everyday laptop for a while as a bit of a refresher. What the recommended AV product? Is it still clamav? </p> <p>Also while I can use IP tables I use glasswire on Windows and little snitch on macOS and love the notifications/decisions on new connections and the ease in which you can get complete visibility of your connections (seriously the GUIs make these products). Are there any similar products for Linux? </p> <p>I pay for both glasswire and littlesnitch so I don't mind spending a little for either AV or a decent firewall/visibility product. </p> <p>Thanks</p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/le-quack"> /u/le-quack </a> <br><span><a href="https://www.reddit.com/r/linux/comments/a3xh8y/av_and_client_firewall_for_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/a3xh8y/av_and_client_firewall_for_linux/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Quickpost: Bash Bunny & Keyboard Layouts]]></title>
<description><![CDATA[This Quickpost is for my Bash Bunny with the original firmware. Since my first Bash Bunny post a couple of days ago, firmware 1.1 was released, but I have not yet upgraded. When I used my Bash Bunny as a keyboard emulator (attackmode HID) to type string Attack! (QUACK STRING Attack!), I got the s...]]></description>
<link>https://tsecurity.de/de/145444/it-security-nachrichten/quickpost-bash-bunny-keyboard-layouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/145444/it-security-nachrichten/quickpost-bash-bunny-keyboard-layouts/</guid>
<pubDate>Sun, 09 Apr 2017 16:31:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This Quickpost is for my Bash Bunny with the original firmware. Since my first Bash Bunny post a couple of days ago, firmware 1.1 was released, but I have not yet upgraded. When I used my Bash Bunny as a keyboard emulator (attackmode HID) to type string Attack! (QUACK STRING Attack!), I got the same […]<img alt="" border="0" src="https://pixel.wp.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=5077&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Revealed: 'Suicide bomber Barbie' and other TSA quack science that cost $1.5 billion]]></title>
<description><![CDATA[ACLU urges end to behavioral screening of travelers From 2007 through 2015, the US Transportation Security Administration (TSA) spent $1.5 billion trying to identify potentially dangerous travelers by observing their behavior through an ongoing program called SPOT.…]]></description>
<link>https://tsecurity.de/de/122506/it-security-nachrichten/revealed-suicide-bomber-barbie-and-other-tsa-quack-science-that-cost-15-billion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/122506/it-security-nachrichten/revealed-suicide-bomber-barbie-and-other-tsa-quack-science-that-cost-15-billion/</guid>
<pubDate>Thu, 09 Feb 2017 00:15:56 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>ACLU urges end to behavioral screening of travelers</h4> <p>From 2007 through 2015, the US Transportation Security Administration (TSA) spent $1.5 billion trying to identify potentially dangerous travelers by observing their behavior through an ongoing program called SPOT.…</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,04ms -->