POPULARITY
Categories
******Support the channel******Patreon: https://www.patreon.com/thedissenterPayPal: paypal.me/thedissenterPayPal Subscription 1 Dollar: https://tinyurl.com/yb3acuuyPayPal Subscription 3 Dollars: https://tinyurl.com/ybn6bg9lPayPal Subscription 5 Dollars: https://tinyurl.com/ycmr9gpzPayPal Subscription 10 Dollars: https://tinyurl.com/y9r3fc9mPayPal Subscription 20 Dollars: https://tinyurl.com/y95uvkao ******Follow me on******Website: https://www.thedissenter.net/The Dissenter Goodreads list: https://shorturl.at/7BMoBFacebook: https://www.facebook.com/thedissenteryt/Twitter: https://x.com/TheDissenterYT This show is sponsored by Enlites, Learning & Development done differently. Check the website here: http://enlites.com/ Turi Munthe is a journalist and policy analyst turned media entrepreneur and writer. As a journalist and Middle East policy analyst, Turi has written for the Economist, Guardian, TLS, THES, the Nation, Spectator, and many others. He has appeared on the BBC, Fox, CNN, al-Jazeera, NBC and others, and given lectures at universities all over the world - Oxford, Sciences Politiques Paris, CUNY, and elsewhere. He has also advised governments across Europe and the Middle East. He is the author of Why We Think What We Think: The Unexpected Origins of Our Deepest Beliefs. In this episode, we focus on Why We Think What We Think. We talk about what opinions are, and the many factors that influence them. We explore the social aspects that predict people's opinions; climate and geography; why conventionally attractive people are more right-wing; and peanut butter preferences. We discuss a biological basis to political beliefs, the social functions of opinions, and tribalism. Finally, we talk about philosophy and science, and political radicalization and polarization.--A HUGE THANK YOU TO MY PATRONS/SUPPORTERS: PER HELGE LARSEN, BERNARDO SEIXAS, ADAM KESSEL, MATTHEW WHITINGBIRD, ARNAUD WOLFF, TIM HOLLOSY, HENRIK AHLENIUS, ROBERT WINDHAGER, RUI INACIO, ZOOP, MARCO NEVES, COLIN HOLBROOK, PHIL KAVANAGH, SAMUEL ANDREEFF, FRANCIS FORDE, TIAGO NUNES, FERGAL CUSSEN, HAL HERZOG, NUNO MACHADO, JONATHAN LEIBRANT, JOÃO LINHARES, STANTON T, SAMUEL CORREA, ERIK HAINES, MARK SMITH, JOÃO EIRA, TOM HUMMEL, SARDUS FRANCE, DAVID SLOAN WILSON, YACILA DEZA-ARAUJO, ROMAIN ROCH, YANICK PUNTER, CHARLOTTE BLEASE, NICOLE BARBARO, PAWEL OSTASZEWSKI, NELLEKE BAK, GUY MADISON, GARY G HELLMANN, SAIMA AFZAL, ADRIAN JAEGGI, JOÃO BARBOSA, JULIAN PRICE, HEDIN BRØNNER, FRANCA BORTOLOTTI, URSULA LITZCKE, SCOTT, ZACHARY FISH, TIM DUFFY, SUNNY SMITH, JON WISMAN, WILLIAM BUCKNER, LUKE GLOWACKI, GEORGIOS THEOPHANOUS, CHRIS WILLIAMSON, PETER WOLOSZYN, DAVID WILLIAMS, DIOGO COSTA, ALEX CHAU, CORALIE CHEVALLIER, BANGALORE ATHEISTS, LARRY D. LEE JR., OLD HERRINGBONE, DAN SPERBER, ROBERT GRESSIS, JEFF MCMAHAN, JAKE ZUEHL, MARK CAMPBELL, TOMAS DAUBNER, LUKE NISSEN, KIMBERLY JOHNSON, JESSICA NOWICKI, LINDA BRANDIN, VALENTIN STEINMANN, ALEXANDER HUBBARD, BR, JONAS HERTNER, URSULA GOODENOUGH, DAVID PINSOF, SEAN NELSON, MIKE LAVIGNE, JOS KNECHT, LUCY, MANVIR SINGH, PETRA WEIMANN, CAROLA FEEST, MAURO JÚNIOR, TONY BARRETT, NIKOLAI VISHNEVSKY, STEVEN GANGESTAD, TED FARRIS, HUGO B., JORDAN MANSFIELD, CHARLOTTE ALLEN, DAVID TONNER, PATRICK DALTON-HOLMES, NICK KRASNEY, RACHEL ZAK, DENNIS XAVIER, CHINMAYA BHAT, RHYS, ALEX MACLEOD, HAIDAR, JULIEN PORCHER, ROBERT SUNDSTRÖM, JON STEWART, AND JAMES DORLING!A SPECIAL THANKS TO MY PRODUCERS, YZAR WEHBE, JIM FRANK, ŁUKASZ STAFINIAK, TOM VANEGDOM, BERNARD HUGUENEY, CURTIS DIXON, THOMAS TRUMBLE, KATHRINE AND PATRICK TOBIN, JONCARLO MONTENEGRO, NICK GOLDEN, CHRISTINE GLASS, IGOR NIKIFOROVSKI, PER KRAULIS, ADAM HUNT, AND JOÃO BARBOSA!AND TO MY EXECUTIVE PRODUCERS, MATTHEW LAVENDER,SERGIU CODREANU, AND GREGORY HASTINGS!
The ASX 200 drifted around to close down 5 points at 8,791, as the banks paused after last week's rise and resources came back into focus. US futures sliding lower sapped early enthusiasm.The Big Bank Basket was flat at $283.68 (-0.7%) with MQG falling 0.8% and NWL down 2.2%. Insurers were slightly firmer, with QBE up 1.8% and MPL rising 0.6%, although REITs eased, with SGP down 1.0% and GMG off 0.9%. Industrials were mixed again, with defensives such as the supermarkets slightly firmer, along with TLS and REA, which continued to find some friends. Retail was also mixed, with WES up 0.2%, while others failed to keep pace.In the tech space, selling continued, with XRO down 2.1% and WTC off 3.6%, although there were buyers in MAQ.Resources were mixed. BHP steadied, RIO slipped 1.9%, lithium stocks remained depressed, and the gold sector bounced back from earlier losses, with WGX up 2.1% and WAF rising 2.6%. S32 had a good day, up 4.6%, after beating quarterly guidance.Oil and gas stocks were firmer as crude prices continued to push higher, with WDS up 1.4% alongside STO. Coal stocks also edged higher, with WHC up 2.7%, while uranium stocks posted modest gains.It was a relatively quiet day on the corporate front. PPT rejected the latest proposal from EQT, while CEH surged 15.2% on plans to develop its Queensland site. We also saw interim chairman of WJL spend $1 million buying shares, lifting his stake to around 5%, or approximately 24.5 million shares. EQR rallied 34.1% after Andrew Forrest's Tattarang disclosed a 16.8% stake.It was a quiet day on the economic front.Asian markets were weaker, Nikkei 225 down 4%, HK up 1.8% and China up 0.5% - Korea down 4.5%US futures mixed - Dow down 50 and Nasdaq up 8. Oil above $91. European markets set to fall 0.3%Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
The ASX 200 closed down 44 pts at 8,797 as US futures weakened and Asian technology stocks were hit hard. Down 10pts for the week. Our market saw both the banks and resources come under pressure. The banks gave up ground, with CBA down 0.8% and WBC falling 0.2%. The Big Bank Basket fell to $284.25 (-0.5%) with a late rally helping. Insurers, however, held their ground, while other financials also performed reasonably well, with AMP rising for the second day in a row.Elsewhere, defensives in the industrial sector held firm, with TLS up 2.7% despite CEO Vicki Brady facing lawmakers in Canberra. WES also gained 0.9%, while in healthcare CSL edged higher and RMD rose 1.5%.Technology stocks were mixed. XRO gained 0.9% and WTC was little changed, but the data centre sector remained under pressure, with NXT falling another X%. MP1 had another horrible session, down 8.5%, while AI-related stocks were sold heavily. EIQ fell 5.7% and WBT tumbled nearly 10.5%. In fact, anything with a Vegas AI connection was under pressure today. Resources were once again the weak link. BHP continued to slide following its quarterly result, falling 2.7%. RIO also eased 2.4%, while FMG held up, but only just. Lithium stocks were once again under pressure, with PLS down 3.1% and MIN falling 2.6%. Gold miners also suffered despite bullion prices rising in Asian trade, with NST and EVN both down over 4%. Oil and gas stocks bucked the trend, with WDS up 3.3% and STO gaining 1.9%, although coal stocks failed to fire.There was little of note on the corporate front. ZIP fell 5.1% after announcing it would exit its New Zealand business. PRU delivered a stronger-than-expected quarterly update. SKC climbed after announcing the sale of investment properties in Auckland. COL walked away from its proposed acquisition of Greencross from TPG Capital, while RRL fell 8.4% after issuing a softer FY27 outlook.In economic news, Westpac Chief Economist Luci Ellis warned that the current AI boom could face a correction if commercial returns fail to justify the lofty valuations.Asian markets were slammed, Nikkei 225 down 4.6%, HK down 2.3% and China down 3.9% - Korea closed for a holiday.US futures down - Dow down 403 and Nasdaq down 465. Oil up 0.9%. European markets set to fall 1%Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
“If you can only explain the arguments of the other side because they're mad or dangerous or dumb, the problem is with you.” — Turi Munthe On yesterday's show, the psychiatrist Sally Satel described how Americans imagine their own mental condition differently, depending on their politics and age. Which is a nice segue for today's conversation with the Anglo-French journalist turned media entrepreneur Turi Munthe. It's not just in our mental health self-evaluation, Munthe argues, that we hallucinate reality. Indeed, the French born Munthe often sounds like one of his post-structuralist compatriots in his defiantly slippery notion of ontological reality. In Why We Think What We Think: The Unexpected Origins of Our Deepest Beliefs, Munthe argues that our deepest convictions turn out to be shaped by genetics, brain shape and sometimes even by the agricultural legacy of our distant ancestors. Left and right thinkers, Munthe argues, are different political phenotypes — each hallucinating their own version of reality. Total relativism, then — the full French post-structuralist monty? Not quite. Here's where Munthe's Englishness kicks in. Following the Anglo-Russian philosopher Isaiah Berlin, Munthe insists pluralism and relativism are different. So Turi Munthe doesn't just think what he thinks because of his English or French origins. Borrowing from the cognitive scientists Dan Sperber and Hugo Mercier, Munthe defines thinking as a “contact sport”. So, for example, believing that the 2020 election was stolen is what Munthe calls a social commitment, because humans would rather be wrong together than right alone. Speaking of convenient segues, Munthe's thoughts on thinking set the scene for next Tuesday's conversation with Emily Eakin, author of The Frenchmen. It's her history of seductive post-structuralists like Foucault, Derrida and Lacan who corrupted a whole generation of literary American Ivy Leaguers (including Eakin) into hallucinating reality. Five Takeaways • Pluralism Is Not Relativism. Munthe opens with Isaiah Berlin's distinction: registering the sincerity and value of opinions across the political, religious, and ethical spectrum does not relativize truth. That Charles Windsor is King of the United Kingdom is a statement of fact; whether you're a monarchist or a republican is where opinion begins. The book confines itself to the second category — beliefs, values, and opinions that cannot be factually proven — and asks what the nonrational influences on them actually are. The answer is humbling: genetics account for perhaps half of political persuasion, and the rest is shaped by everything from brain anatomy to the agriculture of our ancestors. • Different Political Phenotypes. At the margins, left and right differ neurologically: right-leaners are on average more readily startled by loud noises and more attentive to threat, while left-leaners carry a slightly larger anterior cingulate cortex — the brain region where we process ambiguity and split hairs. That anatomy, Munthe argues, explains the ideological capture of academia and media better than any conspiracy: hair-splitters go where the hair-splitting is, and a conservative 22-year-old doesn't volunteer for a newsroom where 80% of colleagues think differently. We are, in his phrase, different political phenotypes, each hallucinating a different version of reality. • Thinking as a Contact Sport. Drawing on Dan Sperber and Hugo Mercier's research, Munthe argues that reason didn't evolve for solitary contemplation — Rodin's Thinker is the wrong image — but for argument: to convince you to hunt the buffalo with me, I need reasons that look objective to you too. The evidence is everywhere, from the most impactful academic papers being written by pairs and groups to the creative density of small university towns. The implication is political: the people we disagree with are not obstacles to good thinking but the condition of it — the loyal opposition that helps us get out of ourselves. • Wrong Together Rather Than Right Alone. Munthe's reading of January 6 and the stolen-election faith is social rather than psychiatric: an enormous number of our beliefs matter more for what they do than for what they say, and professing them is a commitment to a group. From an evolutionary perspective, believing what your village believes — even about the god who is a giant rock at the end of the field — is intelligent, because the ostracized lose the protection of the group. The terrifying data point is the marriage test: in the 1950s, around 4% of families would have objected to a child marrying across party lines; today it approaches 45%. That is affective polarization, and it can pull societies apart. • The Problem Is With You. Munthe spent his twenties unable to fathom American gun rights — supporters had to be bought, dumb, or morally corrupt — until he did the work and found a tradition he now calls beautiful and heroic, whether or not he shares it. His rule of thumb: if you can only explain the other side's arguments as madness, danger, or stupidity, the problem is with you. This is not centrism — there was no middle ground on slavery or the Holocaust — but a defense of the clash itself: societies need the left to fix inequality and the right to defend the village, and we think best when the two are, in his words, continually bashed against each other. About the Guest Turi Munthe is a journalist and policy analyst turned media entrepreneur. He founded Demotix, which became the largest network of photojournalists in the world before its sale to Corbis in 2012, and Parlia, an encyclopedia of opinion. He has written for The Economist, The Guardian, the TLS, The Nation, and The Spectator, has sat on the boards of Index on Censorship, openDemocracy, and the Bureau of Investigative Journalism, and is a board member of the Italian media group GEDI, publisher of La Repubblica and La Stampa. He studied Arabic and History at Oxford. Why We Think What We Think: The Unexpected Origins of Our Deepest Beliefs (Penguin/Hutchinson Heinemann) is out now in the UK, with US publication early next year. References: • Why We Think What We Think: The Unexpected Origins of Our Deepest Beliefs by Turi Munthe (Penguin/Hutchinson Heinemann, 2026). Timothy Garton Ash: “Thinking is a contact sport.” • Isaiah Berlin — the Anglo-Russian philosopher whose insistence that pluralism and relativism are not the same thing frames the whole book. • Dan Sperber and Hugo Mercier...
The ASX 200 recovered from early losses to close up just 3 points at 8,809, despite weakness across the region, particularly in Korea. Once again, the banks held firm, with the Big Bank Basket rising to $283.41 (up 0.8%). ANZ was the best of the bunch, gaining 1.1%. Insurers also rallied, with IAG rising 2.0% and SUN adding 0.9%.Other financials eased, with BVS falling 5.5% on profit-taking after a strong week. Industrials were generally soggy. CSL fell 1.3%, RMD dropped 4.9%, and technology stocks remained unloved. XRO fell 4.3% following CEO share sales, WTC drifted another 2.0% lower, and WBT crashed back to earth, falling 10.6%.TLS recovered 1.6% after its week from hell. REITs were surprisingly firm, with SCG up 0.3% and GPT gaining 0.2%. The supermarkets were not so super, with WOW down 0.8% and COL falling 1.9%.In resources, it was once again heavy going as Treasury yields rose and the gold price came under pressure. Iron ore stocks held firm, but the gold miners succumbed. NST fell 2.8%, while GMD gained 3.7% as RRL pulled out.In corporate news, RRL threw in the towel on its bid for VAU. OML extended due diligence for the three interested parties, while CCX soared following a positive trading update. There was nothing of note on the local economic front.Asian markets were mixed with the Nikkei 225 down 2.6%, the Hang Seng down 0.2%, and the CSI index down 1.7%. Kopsi crashed 9.0% as SK Hynix fell hard.US futures were weaker with the Dow down 208 and the Nasdaq down 388. European market expected to open 0.6% weaker.Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
The ASX 200 rose 44 points to 8,806, up 0.5%, after a slow start, with the banks finding their feet. For the week, the ASX 200 fell 38 pts. CBA rose 0.5% and ANZ gained 0.8%. The Big Bank Basket rose to $281.06 (0.6%). Other financials also firmed, with MQG up 0.9% and NWL rising 2.2%. ZIP rallied 2.0%. REITs were better, with GMG up 0.2% and CHC rising 2.2%. In the industrials, we saw some profit-taking, with TLS under pressure now that Vicki Brady is back on board from her holiday. WOW and COL were also in profit-taking mode after defensive buying earlier this week. Elsewhere, the healthcare sector pulled back after a strong week, with CSL down 2.1% and RMD falling 0.9%. Technology stocks were under pressure, unable to capitalise on the improved outlook for US software companies, with XRO down 1.3% and WTC falling another 1.8%. The All-Tech Index fell 0.6%.Resource stocks were the heroes today, as the iron ore miners pushed higher. BHP bounced 2.5%, RIO also recovered after yesterday's heavy falls, rising 3.8%, while FMG edged up 2.0%. Gold miners were back in the green after this week's weakness, with EVN up 3.4% and NST gaining 1.7%. Lithium stocks remained under a little pressure, with PLS up 0.4%. Oil and gas stocks eased, with WDS and STO both lower. Uranium stocks were stronger, with PDN up 4.1%, while SLX was one of the standout performers, soaring 9.4%.In corporate news, INA responded to media reports of an approach from PPC. BVS jumped after it upgraded its FY26 earnings. WTC fell despite reassuring the market on DSV relations. SFR up strongly on an increase in its Black Butte mine life. There was nothing of note on the local economic front.Asian markets were mixed with the Nikkei 225 up 1.7%, the Hang Seng up 1.3%, and the CSI index down 1.0%. Kopsi up 4.2% ahead of SK Hynix debut. European futures were narrowly mixed.US futures were weaker with the Dow up 12 and the Nasdaq down 153. Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
The ASX 200 fell 23 points as, once again, resources came under pressure. BHP fell 1.1%, RIO was hit hard following a broker downgrade, down 3.3%, and FMG also lost ground. Gold miners were weaker despite gold holding relatively steady. NST fell 0.9%, while EVN down 1.7%. Elsewhere, lithium and rare earth stocks also drifted lower, with S32 down 3.5%.Meanwhile, in the oil and gas sector, both WDS and STO rose, along with uranium stocks, following the deal with India announced by the Prime Minister. Banks drifted lower, with NAB the weakest of the Big Four, taking the Big Bank Basket down to $279.35 -0.1%). Insurers were mixed, as were financials, with ZIP falling 1.0%. The REIT sector also drifted lower, led by GMG down 0.9% and SGP off 3.7%, following yesterday's strong gains.Industrials and healthcare were slightly firmer. TLS recovered 1.2% after the outage issue, while both WOW and COL gained as investors sought out defensive names. Healthcare was also better, with CSL up 1.0%, although RMD slipped 2.8%.In the tech sector, XRO edged higher, although WTC eased slightly. Retail stocks also had a good session, with JBH up 0.3% and APE also rising 2.2%. Travel stocks eased as renewed US strikes in Iran pushed the oil price up 1.2%.In corporate news, SDF rose slightly as discussions continued on the takeover bid. FDC rocketed 12.3% higher after raising $400m in the largest IPO of the year, while LTR fell after securing gold price protection through forward selling to manage volatility.There was nothing of note on the local economic front, although we did see Chinese CPI and PPI data released today.Asian markets were mixed with the Nikkei 225 up 1.2%, the Hang Seng down 1%, and the CSI index up 0.6% European futures were firmer.US futures were also better with the Dow up 50 and the Nasdaq up 162Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
The ASX 200 fell another 19 points to 8785 (0.2%) as resources were once again under pressure. Well off the lows though of around 120 pts down. BHP fell 2.3% on potential strike action, RIO dropped 2.6% and FMG held up relatively well. Lithium plays remained depressed, with PLS down 3.3% and LTR falling 4.3%. Gold miners were also under pressure, although well off their lows, with NST down 1.7%, EVN crashing 4.2% and GMD also in trouble. LYC managed a small gain, as did BSL. Oil and gas stocks were a bright spot as crude prices rose, with WDS up 3.2% and STO rising 5.8%. Coal stocks also fared better, with WHC up 2.1% and YAL rising 4.0%. Uranium stocks were mixed.The banks were once again a safe haven, with the Big Bank Basket rising to $279.89 (0.98%) as CBA added 0.9% and ANZ jumped 1.2%. MQG slid 0.5%, while other financials were also under the pump, with NWL dropping 3.9%. Insurers were firmer on higher bond yields. REITs also pushed ahead, with SGP up 5.1% and SCG rising 0.8%. Healthcare took a breather today, with RMD dropping 0.8% and SIG falling 0.7%. The tech space was once again unloved, with WTC giving back recent gains, falling 7.3%, and XRO dropping another 1.2%. NXT fell 1.0%, while TLS eased % as a serious outage damaged the brand. The All-Tech Index down 1.4%. Retailers firmed, with WES up 0.5% and JBH gaining 1.9%.In corporate news, RMD sold a software business, GGP appointed a new COO, and ADH warned of a $43m loss driven by impairments.On the economic front, the RBNZ raised rates for the first time in three years. Locally, dwelling commencements fell 11.2%.Asian markets were weaker. The Nikkei 225 fell 1.2%, Hong Kong up 2.9%, China dropped 0.2%, while the Kospi fell 5.5% following Samsung's results. European futures were slightly weaker.US futures were also softer, with the Dow down 99 points and the Nasdaq off 42 points.Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
AWS Morning Brief for the week of July, 6th with Corey Quinn. Links:Announcing general availability of Amazon WorkSpaces for AI agentsAmazon CloudWatch supports creating alarms from log queriesECS Service Connect now supports Zone-Aware routingHow InterWiz reduced AI costs by 90% with Amazon BedrockAccelerate your infrastructure deployments by up to 4x with AWS CloudFormation Express modeAutomate public TLS certificate issuance with ACME support in AWS Certificate ManagerUpgrade Amazon EKS clusters with confidence using Kubernetes version rollbacksSafely Releasing Frontier Models to CustomersAccelerating government FinOps with Amazon QuickFour CVEs: AWS reads half your request, leaks the rest
A bi-weekly news show informing you on the latest in Bitcoin, privacy and open source tech hosted by Ungovernables, Max and Q. AOB• Holiday season is over• UK no longer melting• Samourai updatesNEWS• GitHub permanently bans Rust Lightning (LDK); Corallo moves Bitcoin dev infra to self-hosted Forgejo - Bitcoin Magazine: Corallo urges Bitcoin projects to exit GitHub after Rust Lightning ban• Sparrow Wallet Apple developer-account scare resolved - Bitcoin Magazine / Craig Raw / Sparrow Wallet• FISA Section 702 lapses for the first time since 2008 - EFF: Victory, 702 Has Expired• Canada's surveillance-and-speech week: Lawful Access bill (C-22) rammed to a June 19 deadline, "Combatting Hate" Act (C-9) gets royal assent June 18 - EFF: Canada Is Forging Ahead with Its Dangerous Surveillance Bill / Canada.ca: stronger hate crime protections become law• US CBDC ban through 2030 heads to the President's desk - House Financial Services Committee• Developer-protection carve-out (BRCA) being sanded down as CLARITY Act stalls; passage odds cut to 50-50 - Bitcoin Magazine: Galaxy Research cuts CLARITY Act passage odds• Bull Bitcoin secures MiCA license in France while keeping self-custody/privacy model - Bitcoin Magazine / Bull Bitcoin• ESMA tells unlicensed crypto providers to wind down as MiCA deadline arrives - ESMA public statement PDF• LND zero-timestamp DoS vulnerability publicly disclosed - Bitcoin Optech #411RELEASESWallets• Envoy v2.3.0-beta - 2026-06-22Redesigned Send flow with inter-account transfers, message signing, Address Explorer, sub-sat fee rates, and custom block-explorer support, plus Passport Prime pairing/Bluetooth reliability fixes. Disclose it is ours.• Zeus v13.1.0 - 2026-06-17Feature release: Cashu multi-mint sends, queue-less Nostr Wallet Connect payments on iOS, CLINK noffer support, and Cashu-token detection in URLs. Strong ecash plus Nostr-native payments stack for a self-custodial Lightning wallet.• Zeus v13.1.1 - 2026-06-26Patch: fixes TLS cert verification for LND/CLN REST over Tor and a currency-converter input bug.• Phoenix 2.8.1 - 2026-06-18Adds an iOS debug screen for signing swap-in transactions and fixes an Android amount-display bug, on updated lightning-kmp.• Blockstream Green iOS 5.5.0 - 2026-06-15Adds support for paying LNURL, BOLT12, and BIP-353 payment instructions, improves Lightning invoice handling, and shows funding fees in the receive flow.• Blockstream Green Desktop 3.4.1 - 2026-06-17Adds BOLT12 offer descriptions and updates GDK to 0.77.6. Secondary to the iOS release, but it reinforces the same BOLT12/BIP-353 direction.• Blink Mobile 3.0.1 - 2026-06-26Pre-release build that continues Blink's self-custodial wallet implementation, including wallet creation, seed backup/recovery, Blink Lightning address, LNURL pay, and Stable Balance with BTC-USD conversion. Mention only as a prerelease / watch item.Lightning / node ops• Core Lightning 26.06.2 - 2026-06-29Point release recommended for minimal OS setups and Docker images lacking root TLS certificates. Late-breaking / record-day item if recording after June 29; not a lead, but useful for node operators.Self-hosting / payments infra• BTCPay Server v2.4.0 - 2026-06-25Major release: multisig wallet setup, loginless passkey auth, and granular per-wallet permissions. Breaking: removes the LNBank and Lightning Charge backends.Bitcoin / wallet infrastructure• Liquid GDK 0.77.6 - 2026-06-16Adds Python 3.14 wheels and fixes singlesig GDK use over Tor that broke after a ureq dependency update. Developer/infrastructure note rather than listener-facing wallet news.Hardware / multisig / inheritance• Nunchuk 2.6.0 - 2026-06-17 (Blog Post: https://nunchuk.io/blog/phased-rollout )Phased rollout of the off-chain inheritance protocol, plus fixes and performance work. Self-custodied estate planning for multisig users.P2P / no-KYC trading• Mostro v0.17.5 - 2026-06-16Anti-abuse bonds harden the Nostr-based P2P marketplace while staying non-custodial. Adds multi-source price aggregation and maker-timeout penalties.• BULL Wallet v6.11.1 - 2026-06-22CSV export, payment notes, auto swap-claim retries, better Electrum reliability, experimental Linux desktop support. • Peach Bitcoin 0.69.0 - 2026-06-25Faster funding-flow sync, but ships a new EU-compliance sign-up step. Worth naming the privacy/compliance tradeoff for a no-KYC-leaning audience.On-chain privacy / coinjoin• Ashigaru Desktop 1.0 - 2026-06-24 Ashigaru Desktop 1.0.0 (June 19, 2026) is the inaugural stable release of the Whirlpool coinjoin desktop wallet, shipping Tx0/zeroleak mixing with Premix/Postmix/Badbank account management, built-in Tor, Mix To for routing postmix funds offline, a receive-only attack-surface reduction model, BIP-329 label import/export, and an offline BIP47 message verifier. It also adds a polished dark-theme UI with live coinjoin progress tracking, full cross-platform packaging (Windows/macOS/Linux plus headless server builds), reproducible builds, and BIP47-signed three-step release verification.• JoinMarket NG 0.33.0 - 2026-06-24Correction/update from earlier 0.32.0 note. 0.33.0 adds forced-address-reuse defences, a config center, TUI send validation, wallet history API work, and fidelity-bond / tumbler fixes.• Wasabi Wallet 2.8.0 - 2026-06-28This release adds P2P sync for compact filters, pay-in-coinjoin, sub-1 sat/vByte fees, payment batching, a Scheme scripting language, Signet support, and Tor forward compatibility. It also broadens platform reach with arm64 Linux, Tails, and Whonix support.• Payjoin Dev Kit payjoin-mailroom 0.1.2 - 2026-06-26Hardens the combined Payjoin Directory and OHTTP Relay with bounded file-descriptor usage, recovery from transient accept errors, database/per-request metrics, and unified mailbox TTL.General wallet / spend• Stack Wallet 2.6.0 - 2026-06-27Adds CakePay gift-card support. EDUCATION• The Fed Is Working on a CBDCThe Rage reports that despite public denials, the Fed is internally researching CBDC design. A concrete surveillance-money piece that pairs directly with the 702 lapse for a “financial panopticon” segment. Also pair with the new ROAD to Housing Act CBDC-ban item: the ban runs only through 2030, which is the punchline.• BIP 110 Fork Simulator / explainerInteractive explainer of the BIP 110 “Reduced Data Temporary Softfork”: activation mechanics, what gets restricted, and how the data-filtering debate could split consensus.• How-To Guide: Running an Ecash MintHands-on Cashu / LNbits + Nutshell mint walkthrough. Ecash is the privacy tech of the moment; a good “run your own mint” counterweight to “just use a wallet.”• Bitcoin Privacy in 2026: A Practical GuideDated 2026-06-04, outside even the grace cutoff, so use as evergreen rather than news. Good “where do listeners actually start” resource.• Bitcoin Optech #411Carries the LND zero-timestamp DoS disclosure plus the usual protocol-discussion roundup. Patch reminder for node runners.• Bitcoin Optech #410Summarises an active dev debate to remove opt-in RBF signaling because it now mainly fingerprints the wallet that created the transaction, plus Sparrow Silent Payments, JoinMarket, and Ark items.KEEP AN EYE ON• EU “Chat Control” final trilogue - Patrick Breyer / fightchatcontrol.euThe fourth and likely final trilogue on the permanent CSAM-scanning regulation is set for Monday 2026-06-29. Member states have reportedly dropped the forced encrypted-message-scanning mandate, but the Council text would still codify “voluntary” scanning and extend the interim derogation, with formal adoption expected in July. Outcome not yet known as of record date.• MiCA enforcement after July 1 - ESMA / Bull BitcoinBull Bitcoin is the self-custody-friendly example to watch, while ESMA's wind-down warning is the enforcement backdrop. After July 1, check which EU-accessible services remain available, which providers stop onboarding, and whether “compliant but non-custodial” survives contact with implementation.TO DONATE TO ROMAN'S DEFENSE FUND: https://freeromanstorm.com/donateHELP GET SAMOURAI A PARDONSIGN THE PETITION ----> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools DONATE TO THE FAMILIES ----> https://www.givesendgo.com/billandkeonneSUPPORT ON SOCIAL MEDIA ---> https://billandkeonne.org/VALUE FOR VALUEThanks for listening you…
The ASX 200 dropped 56 points today to close at 8,723 (0.6%), with the banks suffering steep losses. CBA dropped 2.4%, and ANZ fell 2.5%, with the Big Bank Basket declining to $266.89 (-2.3%). Other financials were mixed, with MQG falling 1.2%, although HUB had a good day, rising 5.4%. REITs were again a little on the nose as distributions and higher bond yields continued to weigh on the sector. SCG fell 0.3%, and CHC dropped 2.7%. Industrials painted another mixed picture, with ALL falling 2.1%. Retail was also mixed, with JBH down 2.8% and WOW falling 1.8%. COL was hit hard following reports it was interested in acquiring the Green Cross veterinary business. TLS fell 1.0%. Healthcare was again mixed, with CSL continuing to add to recent gains, rising 3.2%, while RMD fell 1.6%. In technology, XRO dropped 2.8%, while WTC fell 0.4%. The All-Tech Index slipping 1.0%, helped by another strong performance from CPU, which gained 1.0%.In resources, a mixed picture as S32 sold its aluminium business to AAI, jumping 9.7%. BHP up 0.9% and FMG managing a 0.5% gain. Gold miners continue to push lower, NST down 0.8% and NEM falling 1.9%. Lithium stocks improved, PLS up 1.8% and LTR roaring 2.4% ahead. Oil and gas flat, uranium stocks slightly better, PDN up 6.8%.In corporate news, IPX jumped 5.9% after it secured up to $US6.6m from the US DoD to expand domestic production. ORI rose 1.6% after it agreed to proceed with its Hunter Valley Hydrogen Hub in NSW, with construction scheduled to begin in 2026 and first production targeted for early 2029. ASX reached an agreement with the corporate regulator and the Reserve Bank to reset its risk review program. WDS has assumed the role of operator of the Gippsland Basin oil and gas venture from 50% partner ExxonMobil. PPT jumped 16.8% before a trading halt as EQT look to have made a NBIO.On the economic front, building approvals fell slightly.Nikkei 225 up 0.8%, Kospi down1.2% HK closed and Shanghai unchanged. US futures drifting DJ down 163, Nasdaq down 81. Marcus Today – Daily Market Insights Marcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise. If you'd like to go further: Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcast Join Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offer MT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcast Principles – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast — Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
The ASX 200 finished the financial year on a lacklustre note, falling 45 points to 8779 (0.5%) as the banks gained and gold miners came under renewed pressure. The Big Bank Basket rose to $273.04 (0.4%) despite CBA holding firm. Other financials fared well too with ZIP up 3.5% and SUN rising 1.2%. REITs struggled as ex-dividend stocks weighed on the sector, with GMG down 3.0% and SCG off 1.5%. Industrials were mixed. TLS fell 1.6%, while tech eased, with XRO up only 0.1% and WTC falling 2.4%. The All - Tech Index gained 1.3% as CPU rallied hard, up 4.0%. Retail stocks drifted lower, while ALL rose 1.3%. Healthcare succumbed to sellers, with CSL down 0.6% and RMD falling 2.2%.Resources were a sea of red. Gold miners were whacked again as bullion slipped below US$4,000. NST fell 5.8% and EVN dropped 5.2%. Copper stocks were slightly firmer, with SFR up 1.0%, while lithium stocks enjoyed a better session, led by LTR, which ‘roared' back, rising 1.5%. The big iron ore miners all fell, with BHP down 0.7%, FMG off 1.9% and BSL 3.8% weaker. Oil and gas stocks bucked the trend, with WDS up 0.9% and STO rising 0.8%. Uranium stocks drifted lower.In corporate news, CKF fell 2.5% after reporting slowing sales in Germany. ALX was unchanged as IFM increased its stake to 55%.On the economic front, RBA Minutes today. ANZ Consumer confidence picked up slightly. Nikkei 225 up 1.3%, Kospi up 1.2% HK down 1.4% and Shanghai up 0.7%. US futures firm DJ up 4, Nasdaq up 76. European futures slightly higher.Marcus Today – Daily Market Insights Marcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise. If you'd like to go further: Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcast Join Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offer MT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcast Principles – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast — Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
Erich Schaffer critiques the “super greenhouse effect” and argues that tropical outgoing longwave radiation stays flat mainly because tropospheric temperature is sluggish relative to surface temperature, not because water vapor amplifies greenhouse trapping. He says regional and seasonal proxies for water vapor feedback are invalid (citing admissions by Ramanathan/Inamdar and Dessler et al.) and claims interannual proxy results are distorted by aspect-ratio choices and improper OLS regression, advocating TLS or rotated-benchmark methods. Reanalyzing published plots (Spencer, Lindzen-Choi, Chung, Andy May), he concludes water vapor plus lapse rate implies strong negative feedback and low ECS (~1 K). He also alleges data “fudging” and broader scientific incompetence.00:00 Super Greenhouse Effect02:20 OLR Calculations Explained03:28 Troposphere Sluggishness05:32 Ramanathan Admission10:23 Feedback Breakdown Math12:37 Two Proxies Debunked14:05 Revisiting Interannual Proxy16:02 Bad Regression Plotting17:16 Aspect Ratio Distortion23:45 OLS vs TLS Regression30:53 Negative Feedback Emerges33:22 Spencer Regression Mystery37:45 Lindzen Choi Critique41:03 Fixing Lindzen Plot51:17 Recent Andy May Example53:21 Rotate Plot Method55:19 Benchmark Slope Trick57:38 Questionable Outliers01:01:26 Proxies Fall Apart01:02:22 Lapse Rate Physics01:05:45 Tropical Hotspot Feedback01:11:10 AR6 Codependency Critique01:14:24 MODTRAN Water Vapor Test01:19:44 Emission Altitudes Explained01:25:22 Net Feedback and ECS01:27:17 Blunders and Sociology01:40:54 Q&A and Takeaway01:44:44 Bonus Coal Math Error01:47:42 Wrap UpErich Schaffer: “Water Vapor Feedback, Part One”: https://youtu.be/2O4mOf9gk-shttps://x.com/erich_schafferhttps://greenhousedefect.com/=========Slides, summaries, references, and transcripts of my podcasts: https://tomn.substack.com/p/podcast-summariesMy Linktree: https://linktr.ee/tomanelson1
The ASX 200 fell another 60 points to 8,749, down 0.7%. Once again, it was resources that bore the brunt of the selling, with the gold price testing $4,000 and heading below it, and gold miners slipping. NST down 3.3%, EVN down 3.8%, with the iron ore miners also under pressure today. RIO off 2.3%, FMG down 1.6%. Lithium stocks also fell away, with PLS down 5.0% and LTR also falling 7.4%. Copper stocks were very much on the nose, following falls in resource and commodity prices overseas. SFR down 3.6%. Meanwhile, oil and gas stocks were also easier as the oil price slipped another 1.7% in Asian trade, with WDS down 2.9% and STO down 2.8%. Not much happened in the uranium sector, with PDN slightly firmer on some results from Canada.The banks also struggled today, with CBA holding up better than the other three, still down 1.3%, while NAB was the worst of the bunch, down 3.4% following JDO's results and the stock being hammered 40.4%. The theory is that NAB is the most exposed to the business sector. The Big Bank Basket fell 1.3%. Other financials were less affected, with the insurers once again pushing higher. QBE up 1.3% and MPL up 2.7%. Industrials were a bright spot today across the board, with WES pushing up 2.5%, ALL up 2.4%, and retail stocks performing better after the jobs numbers released today. This points to an improving economic backdrop. We also saw WOW and COL continue to receive buying as defensive plays. TLS rose 0.6%.The REIT sector also did well today, with GMG up 1.1% and CHC up 1.0%. Healthcare was a standout sector as CSL continued to power ahead, up 2.3% and RMD also had a good day out, up 4.6%, with SIG performing well too. Once again, though, we saw losses in the technology sector, with XRO down another 3.5% and WTC giving back some of its gains from yesterday, falling X%, with the All Tech Index unchanged at CPU rose 0.5%In corporate news, A2M rose after declaring a special $300 million dividend. TEA also upgraded its earnings growth forecast, and THL received a fresh offer from a mystery suitor valuing the company at between NZ$3.30 and NZ$3.40 a share. JDO 40.4% smashed on higher provisions and slowdown. WOR down 9.7% on a second profit warning. EIQ soared 30.2% on an investment from PME.On the economic front, the headline unemployment rate fell to 4.4% in May, with employment rising by 40,000 and the number of unemployed people falling by 18,000. Most of the jobs growth, however, came from part-time employment, with only 5,000 new full-time jobs created.Nikkei 225 up 4.5%, South Korea up 7.0%, HK down 1.3% and Shanghai up 1.7%.US futures mixed, Nasdaq up 600 plus – Dow Jones up 65Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
Sur Internet, l'heure exacte est une infrastructure invisible. Tant qu'elle fonctionne, personne n'y pense. Mais sans elle, les certificats expirent, les connexions sécurisées échouent, les authentifications se bloquent et les journaux de cybersécurité deviennent impossibles à exploiter.Cette synchronisation repose largement sur un protocole né en 1985 : NTP, pour Network Time Protocol. Son rôle est simple : permettre à un ordinateur, un téléphone ou un routeur de se caler sur une heure de référence. Le système fonctionne en strates. Tout en haut, on trouve des horloges atomiques ou des récepteurs GPS. En dessous, des serveurs redistribuent cette heure au reste du réseau. Le problème, c'est que la quasi-totalité de cette chaîne dépend, directement ou indirectement, du GPS américain. Or le GPS est d'abord un système militaire, contrôlé par le département de la Défense des États-Unis. Jusqu'en 2000, Washington dégradait volontairement le signal civil avec un mécanisme appelé Selective Availability. Cette dégradation a été désactivée, mais rien n'empêche théoriquement de la réactiver.Pour un humain, quelques millisecondes d'écart n'ont aucune importance. Pour un système informatique, c'est autre chose. TLS, qui sécurise les connexions HTTPS, vérifie la validité temporelle des certificats. Kerberos, très utilisé dans les entreprises, rejette les authentifications avec plus de cinq minutes de décalage. Et dans les outils de cybersécurité, une horloge fausse peut désordonner toute la chronologie d'une attaque.NTP peut aussi être détourné. Un attaquant peut décaler l'heure d'une cible, ou exploiter des serveurs mal configurés pour amplifier une attaque. En 2014, une attaque NTP avait atteint 400 gigabits par seconde contre un client de Cloudflare. Même sans attaque, une mauvaise gestion d'une seconde intercalaire avait fait tomber Reddit, LinkedIn, Mozilla ou encore Yelp en 2012. L'Europe dispose pourtant d'alternatives. Galileo diffuse un signal de temps précis. En France, l'Observatoire de Paris, via le SYRTE, maintient l'heure légale avec des horloges atomiques extrêmement fiables et propose des serveurs NTP publics. L'Allemagne, la Suède ou le Royaume-Uni ont aussi leurs références.Mais ces sources ne sont presque jamais configurées par défaut. Ni Windows, ni macOS, ni les routeurs grand public, ni les grands clouds ne les privilégient. Les textes comme NIS2 ou DORA imposent la résilience numérique, sans exiger de sources de temps souveraines. L'Europe a donc les moyens de maîtriser son heure numérique. Elle n'a simplement pas encore décidé d'en faire une priorité. Hébergé par Acast. Visitez acast.com/privacy pour plus d'informations.
The ASX 200 finally made up its mind after oscillating between positive and negative territory and closed down 29 points at 8,787 (-0.3%). Resource stocks were back on the nose as the gold price slipped lower in Asian trade, with NST down 2.7%, EVN down 2.5%, and NEM down 2.1%. BHP eased slightly, along with RIO, while lithium stocks once again came under pressure, with PLS down 1.1% and MIN off 2.5%. Most resource stocks finished lower on the day. Uranium stocks also came under pressure, along with oil and gas names, with WDS down 0.4% and VEA falling 2.4% on news of issues with its refining capacity.The other sector struggling today was technology, which simply can't seem to catch a break. After a small bounce yesterday, WTC once again succumbed to selling pressure and fell 4.4%, while XRO continued its recent decline, falling 5.3%. TNE also had a shocking session, down 7.1%. Data centre stocks were weaker following the sell-off in the US, with NXT down 1.7% and MP1 coming back to earth by 5.1% Industrials were mixed, although we did see some defensive buying in TLS and the supermarket stocks. The banks were firm and helped limit the market's losses. CBA rose 0.5%, ANZ was one of the best performers, up 1.4%, and the Big Bank Basket closed at $273.76 (+0.8%).Retail stocks drifted lower, as did healthcare, although CSL slipped back into negative territory. Retail names eased as bond yields pushed slightly higher. Fast-food stocks were also weaker, with CKF down 5.4% and DMP falling 5.2%.In corporate news, WTC remained in focus after the company said Richard White was not aware of any investigation by the AFP. RWC fell 3.0% after announcing it would close its brass casting operations in Victoria. There was nothing on the economic front today.Nikkei 225 down 1.8% South Korea down 4%, HK down 1.5% and Shanghai down 1.8%. US Futures - Dow Jones down 300, Nasdaq down 630 European futures showing a 1% loss.Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
Big thanks to TryHackMe for sponsoring this video. Learn Cyber Security with Practical Labs on TryHackMe:https://tryhackme.com/DavidBombalTech Use my code DAVIDTECH25 to get 25% OFF on Annual Subscription! Dr. Mike Pound joins David Bombal to explain symmetric encryption, AES, secret keys, VPN encryption, TLS, block ciphers, stream ciphers and why encryption is one of the most important building blocks in modern cybersecurity. In this video, Mike explains what encryption actually does: it takes readable plaintext and turns it into unreadable ciphertext so that only someone with the correct secret key can decrypt it. He breaks down how symmetric encryption works, why the same key is used to encrypt and decrypt, and why algorithms like AES are used everywhere from secure websites and VPNs to BitLocker and full disk encryption. You'll learn why AES is so fast on modern CPUs, how keys interact with encryption algorithms, and why AES uses rounds of substitution and permutation to scramble data. Mike also explains the difference between block ciphers and stream ciphers, including AES, DES, Triple DES, ChaCha20 and older algorithms like RC4 and A5/1. The discussion also covers why symmetric encryption is used for bulk encryption in protocols like TLS and IPsec, why asymmetric encryption is used differently, and why you should never write your own encryption algorithm or implement your own AES code for real-world security. If you want to understand how encryption protects your data, how VPNs and secure web traffic work, and why AES is still one of the most important algorithms in cybersecurity, this is a great place to start. // Mike SOCIAL // X: / _mikepound YouTube Channel: / computerphile // YouTube Video REFERENCE //Password Cracking: Can a Rainbow table reverse a hashed password?: • Password Cracking: Can a Rainbow table rev... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:27 - TryHackMe Sponsor 0:49 - Intro 01:18 - Symmetric vs Asymmetric Encryption 04:38 - Key Exchange and VPN Analogy 06:10 - Examples of Symmetric Algorithms 08:56 - Advantages of Stream vs Block Cyber 10:31 - Deeper AES Explanation 14:34 - Substitution, Permutation, Mixing in AES 19:24 - Don't Implement your Own Encryption 20:16 - TryHackMe Sponsor - DEMO 24:21 - DES Algorithm and the NSA 26:01 - Where to Learn More about Encryption 27:42 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #symmetricencryption #aes #des
The ASX 200 staged a remarkable comeback to finish down only 20 points at 8633 (-0.2%) after falling nearly 100 points in early trade. A stronger US futures market helped, as did a calming in the oil price and the absence of any collapse in Korea.Once again, though, we saw sector rotation, with the banks still under pressure. CBA fell 2.4%, WBC dropped 2.6%, and MQG eased 0.7%. The Big Bank Basket fell to $260.43 (-2.3%). Other financials performed slightly better, and insurers continued to do well, with QBE the star of the show, up 3.7%. REITs also gained, with CHC up 2.8% and SGP rising 3.3%. Industrials were a mixed bag. The rally in WES continues, and retail stocks held firm, with TLS up 0.4% and both WOW and COL continuing their strong winning streaks.Technology was once again very much on the nose, with tax-loss selling and ongoing pessimism surrounding SaaS business models. XRO fell 3.6%, WTC dropped 2.8%, and NXT was hit hard as well. Healthcare was a mixed bag of lollies, with CSL continuing to push higher, gaining another 4.2%. However, RMD fell 0.9%, while SIG continued to drift lower on concerns about a UK expansion push.Meanwhile, resources recovered some poise, although the move lacked conviction. BHP rose 1.0%, and some lithium names improved, with PLS rising alongside LTR, which enjoyed a strong day, up 4.2%. Gold stocks also found some support, with EVN up 2.1% and RMS also edging higher. Oil and gas stocks were stronger, with WDS up 1.6% and STO jumping 2.0%. While coal stocks recovered, uranium stocks continued to struggle.In corporate news, LLC rose 4.6% following the appointment of a new CEO and the maintenance of guidance between 28 cents and 34 cents. NST fell slightly as Elliott Investment Management called for further board changes. SXL dropped 4.4% after the company downgraded its full-year earnings outlook and announced 300 job cuts. AAI fell 8.3% following a warning about its Middle East operations.In economic news, the CBA said the RBA is likely to keep rates on hold for the first time this year. Australian wages rose 0.8% in May, with consistent growth recorded over the last 18 months.Asian markets weaker. Japan flat, Hong Kong down 1.0%, and China down 0.7%. South Korea fell slightly.US futures: Dow up 88 and Nasdaq up 150. Oil up 1.0%. Europe opening easier. ECB expected to hike rates today.Marcus Today – Daily Market Insights Marcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise. If you'd like to go further: Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcast Join Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offer MT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcast Principles – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast — Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
The ASX 200 showed solid gains to finish up 49 points at 8,653. Once again, it was the tale of two cities, with the best of times and the worst of times. The banks held steady, with CBA down 0.2%, and WBC doing well, up 2.0%. Insurers also pushed higher, led by QBE up 2.4%, and even ASX up 0.6%, with the Big Bank Basket at $266.54. Elsewhere, industrials were once again stronger, with defensive stocks taking the bull by the horns. WES rose 4.3%, TLS rose 2.0%, and both the supermarket stocks WOW and COL did very well, building on recent gains in the healthcare space. CSL was also strong as it looks to have turned the corner, up 3.5%, with SHL also firm, although SIG fell 5.5% on the back of media speculation that it was looking at buying the Boots chemist chain in the UK. REITs were positive, with GMG up 1.6%, CHC up 1.8%, and other industrials faring okay. Retail also had a good bounce, with JBH up 3.5% and ALL up 2.2%. Technology stocks were still very much in the doghouse, with XRO down 2.0%, TNE down 2.3%, and NXT down 4.1%. Utilities firmed in this environment, and the All-Tech Index fell 1.8%.Meanwhile, resources were once again on the nose, with BHP up 0.2%, and RIO and FMG also falling as iron ore came under pressure. Lithium stocks fell, PLS down 1.7%, and LTR falling a big 8.0%, with MIN also suffering heavy losses. The gold sector was also slammed again as the gold price fell out of bed, with NST down 3.5%, EVN falling 5.0%, and RMS also having a bad day, down 3.8%. Over in the energy space, Woodside slipped slightly, and Santos pushed ahead somewhat, with coal stocks under pressure, WHC down 4.4%, and uranium stocks still on the nose.In corporate news, SDF rose 36.2% after receiving a $6.00 non-binding indicative offer. IGO fell hard after a fire broke out at the Chemical Grade Plant 3 facility at Greenbushes. WES had a good investor day reaction, saying it would drive growth through AI and data monetisation. Citi downgraded banks following the budget changes. In economic news, the ANZ-Roy Morgan consumer confidence rose for the second consecutive week, lifting two points to 70.8.Asian markets weaker. Japan down 1.9% Hong Kong down 0.9%, and China down 1.1%. South Korea falls again.US futures: Dow down 78 and Nasdaq down 132. Oil down 1.5%. Europe opening easier. Marcus Today – Daily Market Insights Marcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise. If you'd like to go further: Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcast Join Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offer MT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcast Principles – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast — Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
The ASX 200 closed down 21 points at 8604 (0.2%), well off its lows for the day, with most sectors rallying throughout the session and the banking sector staging a turnaround. CBA fell 0.3%, with the Big Bank Basket easing only slightly to $265.42 (0.4%). Financials were generally firm, with MQG up 0.7%, while the insurance sector also performed well, led by QBE up 0.9% and MPL higher. REITs enjoyed a solid session, with GMG up 0.3% and SCG rising 1.6%. TLS also had a strong day, gaining 2.2%, although REA was a disappointment, falling heavily. Both WOW and COL posted gains as defensive buying in the supermarket sector helped push them higher. Retail stocks were also in demand, led by WES up 1.3% and APE rising 4.3%.Healthcare was another bright spot, with CSL recovering a further 1.6% and RMD also posting gains. Elsewhere, technology stocks remained under pressure but recovered from their lows, with XRO down 1.1% and WTC off 4.6%, while the All-Tech Index fell 0.1%.It was a different story in resources, although the sector also bounced from early lows. BHP fell 1.9% and RIO dropped 1.8% as iron ore and copper prices weakened. Gold stocks were also under pressure, with NST down3.3% and NEM lower. Lithium stocks slipped away, with MIN falling 2.6% and LTR off 3.3%. In energy, WDS rose alongside STO, although gains were relatively muted. Uranium stocks came under heavy pressure, with PDN dropping 8.8% and DYL down 7.6% as short sellers gained the upper hand.In corporate news, OML had a good day, up 9.6%, after receiving yet another NBIO, this time from Bain Capital. QUB rose 0.4% after the PNG competition regulator backed the company's planned takeover by Macquarie. On the economic front, NAB is now saying the next move in local interest rates is likely to be a cut. Business confidence rebounded as price pressures softened, according to the NAB Business Survey. However, Australian consumer confidence slipped back towards record lows, with the Melbourne Institute-Westpac Consumer Sentiment Index falling to 80.6, one of the lowest readings in its history.Asian markets mixed. Japan up 2.1%, Hong Kong up 0.1%, and China up 0.8%. South Korea jumps 8%.US futures: Dow up 8 and Nasdaq up 170. Oil down 1.5%. Europe opening slightly easier. Marcus Today – Daily Market Insights Marcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise. If you'd like to go further: Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcast Join Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offer MT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcast Principles – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast — Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
fatgid, why zfs is ideal for media production, the CTF scene is dead, private repo behind TLS, and more... NOTES This episode of BSDNow is brought to you by Tarsnap and the BSDNow Patreon Headlines fatgid Why ZFS is the ideal filesystem for multi-user media production News Roundup The CTF scene is dead A Private pkg Repo Behind Mutual TLS This blog ran on Ubuntu 16.04 for 10 years. I migrated it to FreeBSD Tarsnap This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups. Send questions, comments, show ideas/topics, or stories you want mentioned on the show to feedback@bsdnow.tv Join us and other BSD Fans in our BSD Now Telegram channel
The ASX 200 fell 100 points to close at 8686 _1.1%), with losses across the board. Banks held up better, with CBA down 0.6%, and WBC the worst of the bunch, down 1.7%, with MQG also falling 1.1%. The Big Bank Basket dropped to $270.46 (-1.8%). Insurers were better as bond yields rose, with QBE up 1.2% and the rest of the financials losing ground. Tech stocks were struggling today, with XRO falling back to earth by 4.2% and the All-Tech Index falling 1.4% as profit-taking moved in after the recent bounce. In the industrials, we saw TLS fall 2.9%, although defensive stocks bucked the downtrend, with WOW and COL both positive, along with utilities ORG and APA. Healthcare stocks were showing some signs of life, with RMD finding a bottom, at least temporarily, up 2.6%, and CSL up 0.4%. The real damage, though, today was done in the resource sector, as the iron ore price came under pressure and profit-takers moved into the iron ore stocks, with BHP down 3.3%, RIO down 3.3%, and FMG down 4.1%. Elsewhere in the gold space, we saw selling again in NST, off 6.1%, and EVN falling 3.0%, with lithium and rare earth stocks all under pressure. PLS dropped 4.5%. Big losers today as well were the big winners yesterday in the uranium sector, with PDN falling 8.2% and DYL down 5.2%. The oil and gas space was modestly higher, with both Woodside and Santos rising, together with coal stocks, with WHC rising 3.0%.In corporate news today, PME secured a five-year renewal in the U.S. TWE had a very good day as it presented to investors with no downgrades and some optimistic outlook statements. IPX fell 4.6% after its DFS study for its Critical Minerals project in Tennessee.Nothing significant on the economic front, although we did have some international goods trade data out, showing exports increased 7.2%, driven by metal ores and minerals.Asian markets mixed. Japan down 1.5%, Hong Kong down 1.4%, and China down 0.6%. South Korea eases back around 1.6%US futures: Dow up 26 and Nasdaq down 151. Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
The Modern Therapist's Survival Guide with Curt Widhalm and Katie Vernoy
Modern Therapist's Consumer Guide: Paubox. HIPAA Compliant Email, Secure Communication, and Practice Privacy. An Interview with Hoala Greevy, Founder and CEO of Paubox Curt and Katie talk with Hoala Greevy, Founder and CEO of Paubox, about what HIPAA compliant email actually requires, where standard Google Workspace and Microsoft 365 Business Associate Agreements leave gaps, and why most secure-portal solutions fail at the inbox. Paubox is a HIPAA compliant email security platform built to deliver encrypted messages straight to the recipient's inbox, without portals, plugins, or extra clicks. Hoala explains how Paubox wraps around the email systems therapists already use, why domain ownership and TLS encryption matter, and how inbound threats like display-name spoofing affect small practices. The conversation also covers HITRUST certification, AI scraping, the Paubox Foundations, the Paubox Kahikina Scholarship supporting Native Hawaiian students in STEM, and how to evaluate a HIPAA compliant email vendor on security, reliability, and ease of use. This episode is part of our Modern Therapist's Consumer Guide series. While this interview is a paid partnership, our discussion and opinions are our own. In this episode, we discuss: - Where standard Google and Microsoft BAAs leave HIPAA compliant email gaps - Why most secure-portal solutions never get read on mobile - How TLS encryption and secure email delivery actually work - What domain ownership has to do with HIPAA compliance - How Paubox integrates with Google Workspace and Microsoft 365 - Inbound threats, display-name spoofing, and ExecProtect - HITRUST certification and how to evaluate a HIPAA compliant email vendor Timestamps: - 02:18 – What Paubox does and why it was created - 05:19 – Mission, vision, and the Paubox Foundations - 08:38 – What HIPAA compliant email actually requires - 10:26 – The Google and Microsoft BAA gray area - 14:48 – What the client experience looks like - 21:09 – Inbound email security and display-name spoofing - 24:32 – Data access, HITRUST certification, and trust - 34:05 – Pricing, value, and the referral program - 38:43 – Curt and Katie Chat: Our Review of Paubox Guest Bio: Hoala Greevy is the Founder and CEO of Paubox, a leading provider of HIPAA compliant email solutions for healthcare organizations. Born and raised in Honolulu, he founded Paubox after a meeting with the CEO of the Make-A-Wish Foundation of Hawai'i revealed a critical need for secure healthcare communication. Greevy supports Native Hawaiian students entering STEM and technology careers through the Paubox Kahikina Scholarship. Learn more at paubox.com. Special Offer for Modern Therapist Listeners: Get $250 off an annual Paubox plan. Visit paubox.com and use promo code MODERN. Full show notes and transcript: mtsgpodcast.com Join the Modern Therapist Community Patreon: https://www.patreon.com/c/mtsgpodcast Facebook Group: https://www.facebook.com/groups/therapyreimagined Modern Therapist's Survival Guide Creative Credits Voice Over by DW McCann: https://www.facebook.com/McCannDW/ Music by Crystal Grooms Mangano: https://groomsymusic.com/
The ASX 200 started slowly with early losses, but after a benign and better-than-expected CPI read, the bulls were back. The ASX 200 closed up 60 points at 8718 (0.7%). Banks fought back from bigger early losses, with CBA up modestly and WBC down 0.6X%. The Big Bank Basket unchanged at $275.52, whilst other financials improved, with MQG up 1.0%. IFT was having a good day on some broker upgrades, up 5.8%, and HUB was doing well too, up 2.0%. A horror run continued for ASX as it fell another 9.7% on the news yesterday of a further capex blowout and broker commentary today. The industrial space was mainly better, with WES gaining 1.4%, ALL up 3.2%, and GMG also having a good day after the results yesterday. Healthcare perked up slightly, with a good run from CSL up 2.4% and FPH also having another good day, up 4.1%. The tech space was mixed, with TLS down 1.0%, WTC up 1.4%, and TNE up as well. The All -Tech Index rose 2% today.In resources, it was a mixed session, with lithium stocks a little under pressure. PLS fell 1.9%, and MIN also down slightly, but BHP up 1.5% and FMG also doing well. Gold miners were mixed, with a bias to the upside, as NEM rose 1.3%, and coal stocks again were firm, with YAL up 2.1% and WHC up 2.2%. Uranium stocks were also slightly firmer, with PDN up 2.4%.In corporate news today, WEB rose slightly following results, with guidance maintained. EDV fell 4.9% after it flagged a major restructure of its wine operations. SXL was up strongly after Gina Rinehart emerged as a major shareholder. KMD was also doing well on a strategic review, up 17.3%. NUF also had a good day, up 13.7%, as profits jumped on higher margins.In economic news, the monthly consumer price index showed inflation slowed slightly to 4.2%, below the 4.4% forecast. The dollar slid slightly on this news and hopes that the RBA is on hold firmed.Asian markets were once again gripped by chip fever in South Korea and Taiwan. Records and new trillion-dollar valuations. Japan up 0.4%, HK down 1.1% and China off 0.6%. Kopsi up 3.6%. Taiwan up 2.4%.US futures slightly better. Brent crude down 1.6%No news on peace deal. US Cabinet meeting today.—Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
Parce que… c'est l'épisode 0x300! Shameless plug 3 au 5 juin 2026 - SSTIC 2026 24 et 25 juin 2026 - Troopers 26 et 27 juin 2026 - leHACK 19 septembre 2026 - Bsides Montréal 1 au 3 décembre 2026 - Forum INCYBER - Canada 2026 24 et 25 février 2027 - SéQCure 2027 Description Dans cet épisode du podcast Polysécure enregistré au NorthSec, Gaëtan Ferry et Guillaume Valadon, tous deux cyber security researchers chez GitGuardian depuis deux ans, présentent une recherche consacrée aux fuites de clés privées cryptographiques. Guillaume est par ailleurs mainteneur du logiciel Scapy et rédacteur en chef du magazine MISC. Le problème de l'attribution Contrairement à des secrets classiques comme les clés AWS, dont on peut retrouver le propriétaire en interrogeant les services associés, une clé privée cryptographique (RSA par exemple) ne se rattache à aucune identité. C'est un simple objet mathématique aux propriétés cryptographiques, utilisable pour de multiples usages : connexion SSH, protection d'un site web en TLS, etc. En regardant la clé seule, impossible de savoir à quoi elle sert ou à qui elle appartient. Quelques indices existent parfois — le nom de fichier (norssec.io.key) — mais souvent on tombe sur des private.key inexploitables. L'enjeu de la recherche était donc de trouver une technique générique de catégorisation. La méthode : Certificate Transparency La solution repose sur les Certificate Transparency logs, un mécanisme de l'infrastructure X.509 datant de 2015. Chaque fois qu'une autorité de certification émet un certificat, elle doit le journaliser dans ces registres publics, souvent opérés par d'autres autorités. Ces journaux contiennent donc l'historique de tous les certificats émis. Le principe du matching est le suivant : une clé privée contient des informations sur sa partie publique (le module, dans le cas de RSA). On extrait cette partie publique, on calcule une empreinte SHA-256, et on fait de même pour les certificats. Comme un certificat TLS associe une clé publique à une identité (généralement le nom du site protégé), une simple jointure entre les deux bases d'empreintes permet de relier une clé privée à un site et à son propriétaire. La recherche s'est accélérée lors de la conférence Pass the SALT à Lille, où des contacts chez Google les ont alertés : les anciens logs de Certificate Transparency, coûteux à opérer, allaient être mis hors ligne. Or c'était précisément la dimension historique du dataset qui les intéressait. Un partenariat s'est noué : GitGuardian a fourni une liste d'empreintes, et Google a effectué la correspondance dans sa base propriétaire, renvoyant les certificats associés. Les chiffres Le dataset de fin 2025 comptait un million de clés privées distinctes, collectées via l'activité historique de GitGuardian — le public monitoring qui scanne GitHub, Docker Hub et d'autres sources à la recherche de secrets codés en dur, puis avertit les victimes en mode « bon samaritain ». Sur ce million, 42 000 clés correspondaient à des certificats émis par des autorités. Le chiffre peut sembler modeste, mais la majorité des clés ne servent jamais au TLS (projets personnels, SSH, autorités privées d'entreprise absentes des logs publics). Ces 42 000 clés étaient liées à plus de 140 000 certificats, signe que certaines avaient servi à émettre plusieurs certificats successifs, prolongeant d'autant la durée d'exposition. Après vérification, 2 600 clés restaient associées à un certificat valide en septembre 2025. Grâce à des techniques d'OSINT, 1 300 certificats ont pu être rattachés à environ 600 entités. La divulgation responsable, un parcours décevant L'équipe a entrepris un responsible disclosure en envoyant environ 4 300 emails à ces 600 entreprises. Résultat : seulement 54 réponses, soit environ 9 %. Même en se limitant aux adresses certaines à près de 100 %, le taux ne dépassait pas 36 %. Pour gérer un envoi aussi massif sans être bloqués comme spam, ils ont dû collaborer avec leurs collègues du marketing, rompus aux techniques de délivrabilité. Plus frappant que le silence : l'incompréhension des répondants. Beaucoup confondaient clé privée et certificat. Certains ont répondu avoir « changé le certificat », croyant le problème réglé. Une équipe de réponse à incident d'une grande entreprise a même produit une analyse détaillée pour conclure que l'endpoint utilisait désormais un autre certificat, refusant toute révocation — alors qu'un attaquant peut toujours mener une attaque man-in-the-middle avec l'ancien certificat non révoqué. Le certificat a fini par expirer un mois plus tard. Fait notable, 19 entités gouvernementales étaient concernées, et aucune n'a répondu. Comprendre TLS Le malentendu de fond tient au fonctionnement de TLS. On génère sa clé privée chez soi, puis on signe une demande de certificat (CSR) envoyée à l'autorité avec la clé publique. L'autorité vérifie les informations, journalise dans CT et renvoie le certificat. Le certificat n'est qu'une partie publique : il associe une clé publique à une identité, sans contenir le secret. Changer de certificat sans changer de clé n'invalide donc rien : l'ancien certificat reste exploitable pour usurper le service tant qu'il n'est pas révoqué. Forcer la révocation et la vraie solution Face au silence, l'équipe a contacté directement les autorités de certification pour demander la révocation, en fournissant les preuves de possession. Cette voie autoritative s'est révélée plus efficace, mais a généré des réactions parfois hostiles — dont un individu insultant expliquant que sa clé était « volontairement publique » pour permettre l'interception (cas d'usage type Burp), sans que le site l'indique clairement. Les chercheurs avouent un moment de doute, au point de vérifier auprès d'anciens collègues de l'ANSSI : le problème est bien systémique. La solution qu'ils privilégient n'est pas seulement l'éducation, mais l'automatisation. La réduction drastique de la durée de vie des certificats (vers 47 jours) imposera des outils comme Certbot, qui renouvelle déjà la clé privée en même temps que le certificat. Or 20 % des clés trouvées avaient fui plus de deux ans avant l'expiration du certificat le plus récent : des clés compromises réutilisées sur de nouveaux certificats pendant des années. Renouveler systématiquement la clé aurait éliminé ce cinquième des compromissions. Notes Private Key Leaks in the Wild: Insights from Certificate Transparency Collaborateurs Nicolas-Loïc Fortin Guillaume Valadon Gaetan Ferry Crédits Montage par Intrasecure inc Locaux réels par NorthSec
The ASX 200 eased back 34 points today to 8658 (0.4%) in a quiet session, with US and UK markets closed last night. The banking sector was modestly lower, with NAB falling 0.8% and some more profit taking in MQG down1.6%. The Big Bank Basket $274.56 (-0.3%). Financials generally were under pressure as ASX revealed a further blowout in capex, and the shares fell hard, down 13.2%. Elsewhere, industrials were generally weaker across the board: TLS fell 0.9%, REA down 0.7%, and in the health care sector, CSL continued to push lower. REITs also eased back with an update from GMG, disappointing slightly. WES rose slightly, but generally the markets were on hold ahead of more news coming out of the Gulf.Tech stocks were barely changed with XRO down 0.1%, WTC off 2.6% and the All-Tech Index off 0.4%.Resources were mixed. Iron ore miners pushed higher, and S32 had a good day, up 4.8%, with a little interest in lithium stocks, but gold miners eased back as bullion prices fell on a lack of progress in the peace negotiations. NEM off 2.2% Coal stocks gave up some of the gains from yesterday and STO fell 0.9% despite encouraging news from an investor day. Uranium stocks were also easier, with PDN down 3.4%.In corporate news, KGN ran hard on a positive trading update, and MIN also had a good day. In other news, IFM has rejected the independent valuation of ALX, with directors urging shareholders to reject the takeover bid.In economic news, the ANZ-Roy Morgan Consumer Confidence index remained near its historic low last week, slipping 0.3 points to 66.1, as households remained under pressure from weak financial conditions and elevated inflation expectations.Asian markets were mixed with Japan down 0.2%, Hong Kong up 0.3%, China up 0.2%, and the Kospi up again to a new record. US futures were better, with the Dow up 327 and the Nasdaq up 255. European futures are opening slightly lower. Brent crude up around 2%. The US and UK reopen today.—Marcus Today – Daily Market InsightsMarcus Today provides clear, practical commentary for self-directed investors – covering markets, portfolios, education, and decision-making without the noise.If you'd like to go further:Start a free 14-day trial of Marcus Today http://bit.ly/mt-trial-podcastJoin Marcus Today Use code MTPODCAST for 10% off http://bit.ly/mt-join-podcast-offerMT20 – Managed ETF Portfolio A professionally managed portfolio run by Marcus Padley and the team, using ASX-listed ETFs with active market timing. http://bit.ly/mt20-podcastPrinciples – How We Think About Investing A short video series on timing, behaviour, and decision-making. No stock tips. http://bit.ly/mt-principles-podcast—Disclaimer This podcast is general information only and does not consider your personal circumstances. It is not personal financial advice.
With JDK 27 introducing hybrid key exchange schemes that combine ML-KEM with traditional ECDHE algorithms, Java applications can gain TLS-layer protection against the harvest-now, decrypt-later threat without rewriting business logic. In this episode of the Inside Java Newscast, Ana explains post-quantum hybrid key exchange for TLS 1.3 and demonstrates how a Java application can take advantage of it. See https://inside.java/podcast
Get help reviewing contracts using a new Legal Agent for Microsoft Word. Sync up to 1 million files with OneDrive. But consult your IT Support to learn if this is right for you. Finally, Outlook gets some action with M365 Copilot. I mean, can take action... via instructions, productive ones. 0:00 Welcome 2:41 Exchange Online: Retirement of legacy TLS versions for POP and IMAP connections - MC1293480 4:35 Microsoft 365 Copilot: Use Copilot in Outlook to manage your inbox - available in Frontier Public - MC1293485 7:07 OneDrive sync supports up to 1 million items on Windows - MC1294528 10:47 Microsoft Teams: Retirement of Together mode - MC1296478 12:47 Microsoft 365 Copilot will use private community and event content as grounding sources - MC1296480 18:06 Microsoft 365 Copilot (Premium): Teams meetings as a reference in Copilot Notebooks - MC1296488 24:03 Microsoft 365 Copilot: Legal Agent for Word - MC1296877
On Episode 262, Josh, Chris, and Mark discuss the risks of edtech tools that add generative AI without age checks or strong guardrails, share a new K12 SIX resource and rubric for security essentials, and cover email security best practices. For the main topic, the guys talk about "secure email." Districts are being asked to send more sensitive information outside the network - to parents, agencies, vendors - but there's no shared standard for what "secure email" even means in K12. TLS encryption in transit isn't the same as end-to-end encryption. A password-protected PDF isn't a secure channel. And most staff don't know the difference. ———— Sponsored by: PowerGistics: How K-12 Charging Models Impact Chromebook Sustainability Textbooks Didn't have Cables Bring Chromebooks Back to the Classroom, but NOT Carts! One-Person Tech Department Success Story SysCloud Fortinet Extreme Networks ———— Join the K12TechPro Community (exclusively for K12 Tech professionals) Buy some swag (tech dept gift boxes, shirts, hoodies...)!!! Email us at k12techtalk@gmail.com OR our "professional" email addy is info@k12techtalkpodcast.com X @k12techtalkpod Facebook Visit our LinkedIn Music by Colt Ball Disclaimer: The views and work done by Josh, Chris, and Mark are solely their own and do not reflect the opinions or positions of sponsors or any respective employers or organizations associated with the guys. K12 Tech Talk itself does not endorse or validate the ideas, views, or statements expressed by Josh, Chris, and Mark's individual views and opinions are not representative of K12 Tech Talk. Furthermore, any references or mention of products, services, organizations, or individuals on K12 Tech Talk should not be considered as endorsements related to any employer or organization associated with the guys.
#SatanicPanic #SatanicRitualAbuse #Satanism #PaceMemo #GlennPace #LDS #MormonThe Pace memorandum was a 1990 memorandum written by Glenn L. Pace, an LDS Church general authority, describing to a committee of the church the complaints of sixty members of the church that said they had been subjected to SRA by family members and other church members.There are many people today who still deny such atrocities, so let's dig a little deeper with Ben McClintock of the Tree of Liberty Society. Check out their links below!GUEST LINKS - Tree of Liberty Society:- TLS Website: https://treeoflibertysociety.com- TLS on X: https://x.com/TreeOfLibertyS- TLS on YouTube: https://www.youtube.com/@treeoflibertysociety- TLS Merch Store: https://treeoflibertysociety.com/shop/RISE TO LIBERTY - LINKS:• RISE TO LIBERTY – MASTER LINK: https://allmylinks.com/risetoliberty/ • RISE TO LIBERTY – SPREAKER: https://open.spreaker.com/A4NZ/nf256a4z • RISE TO LIBERTY – MERCH STORE: https://risetoliberty.store/• RISE TO LIBERTY – SUPPORTER CLUB:$6 monthLY = ad free episodes & exclusive content for subscribers: https://www.spreaker.com/podcast/rise-to-liberty--6854487/supportWatch the video version on Rumble, YouTube, & on X! Links down below!Rumble: https://rumble.com/v7879qg-60-lds-church-members-testified-to-satanic-ritual-abuseheres-what-happened.htmlYouTube: https://youtube.com/live/EE9LNazgWgIRTL on X: https://x.com/RiseToLiberty/status/2039388188192788534?s=20
AOBPrime SHIPPING!FTF with ZachSamourai Domain PSALauren on with Danny from WBDQ still vibingNEWSKentucky HB 380 requires HWW manufacturers to reset users' seeds upon request https://x.com/bitcoinpolicy/status/2034702487995768878GrapeheneOS refuses to comply with new age verification laws for OS https://www.tomshardware.com/software/operating-systems/grapheneos-refuses-to-comply-with-age-verification-lawsGoogle reverses Android developer verification requirement amidst user backlash - https://www.scworld.com/brief/google-reverses-android-developer-verification-requirement-amidst-user-backlashDOJ Seeks October Retrial for Tornado Cash Developer Roman Storm — https://www.coindesk.com/business/2026/03/10/u-s-requests-october-retrial-for-tornado-cash-developer-roman-stormBitrefill Hacked by North Korea's Lazarus Group — 18,500 Purchase Records Exposed — https://bitcoinmagazine.com/news/bitrefill-cyberattack-points-north-koreaPokemon Go's 30 Billion Images Now Training Delivery Robots — Mass Surveillance Data Harvesting Revealed — https://www.therage.co/pokemon-go-users-trained-killer-robots/UPDATES/RELEASESAm I Exposed? https://am-i.exposed/ by Arkad and CoSelf hosted chain analysis toolAlready on startOSStealth Fork already emergedhttps://x.com/MgkMshrmBrkfst/status/2033771448255566082?s=20Last Signal App https://lastsignal.app/Self hosted dead man switchSparrow Wallet 2.4.2 — March 10, 2026Introduces support for v3 transactions in the editor, implements TOFU certificate pinning for TLS connections, and adds BIP-322 signing via QR and file methods. Numerous dependency upgrades plus bug fixes for PSBTv2 transaction issues, potential database corruption, and dark theme display problems.https://github.com/sparrowwallet/sparrow/releases/tag/2.4.2Aqua v0.4.1 — March 13, 2026Patch addressing multiple bugs and performance improvements. Re-adds region selector to the marketplace, introduces Arabic and Chinese language support, and adds new iOS icon designs. Fixes wallet setup errors when scanning certain QR codes.https://github.com/AquaWallet/aqua-wallet/releases/tag/v0.4.1Boltz USDT Swaps - March 18, 2026Announces USDT Swaps - connecting Bitcoin to the world's most used stablecoin. Swap between Lightning and USDT on all major networks, without custody, accounts, or KYC! Envoy 2.2.12 — March 13, 2026Major update centred on Passport Prime device support. Includes multi-device pairing capability, Bluetooth reliability improvements, and fixes for dozens of bugs across BLE pairing, QuantumLink stability, and the Passport Prime onboarding flow.https://github.com/Foundation-Devices/envoy/releases/tag/2.2.12BTCPay v2.3.6 — March 15, 2026Stable release introducing wallet label filtering, API enhancements for payment method inclusion, invoice modal improvements, security upgrades for API key permissions, and plugin permission policy creation.https://github.com/btcpayserver/btcpayserver/releases/tag/v2.3.6Bisq v2.1.10 — March 17, 2026Implements new trade rules for payment references, adds trade history and QR code pairing support for the Bisq Connect mobile app, introduces TLS support for clearnet connections.https://github.com/bisq-network/bisq2/releases/tag/v2.1.10Phoenix Android v2.7.5 — March 17, 2026Introduces a diagnostics button and adds the spend-channel-address recovery tool to iOS. Android app now supports Indonesian language.https://github.com/ACINQ/phoenix/releases/tag/android-v2.7.5Nunchuk 2.2.8 — March 18, 2026Introduces support for sending to Silent Payment addresses and adds an option to view seed phrases for software keys after a two-hour security delay, along with various bug fixes.https://github.com/nunchuk-io/nunchuk-android/releases/tag/2.2.8Peach Bitcoin 0.69.0 — March 18, 2026Introduces unlimited premium functionality for offers, decimal premium values, improved dark mode colour contrast, and fixes for Revolut/Wise/M-Pesa payment information transmission.https://github.com/Peach2Peach/peach-app/releases/tag/v0.69.0-337Mostro v0.17.0 — March 19, 2026Three releases in the window (v0.16.4, v0.16.5, v0.17.0). Major refactoring work: migration to AppContext-based dependency injection, removal of legacy global state patterns, elimination of password-based database encryption infrastructure.https://github.com/MostroP2P/mostro/releases/tag/v0.17.0Cake Wallet v6.0.1–v6.0.3 — March 6–21, 2026Major redesign + Bitcoin Lightning support via Spark protocol. v6.0.1 (March 6) was the major release with the new UI and Lightning; v6.0.2 (March 17) added Linux distribution support; v6.0.3 (March 21) adds design improvements, performance enhancements, and bug fixes.https://github.com/cake-tech/cake_wallet/releases/tag/v6.0.3Pre-release / Alpha / BetaBitkey App Release 2026.2.1 — March 18, 2026App update with emergency APK download for users who have lost app access and an Emergency Exit Kit reference document for account recovery.https://github.com/proto-at-block/bitkey/releases/tag/2026.2.1Ibis Wallet v3.0 + v3.0.1-betaLiquid w/LN swaps, Boltz on backend, wallet locks, cancel txs with RBF, notificationsLNBits v1.5.2-rc3 — March 20, 2026Three release candidates (rc1 through rc3) published March 18–20, building toward v1.5.2 stable.https://github.com/lnbits/lnbits/releases/tag/v1.5.2-rc3Mempool v3.3.0-beta2 — March 20, 2026Beta release tag with minimal release notes.https://github.com/mempool/mempool/releases/tag/v3.3.0-beta2Start9 v0.4.0-alpha.21 — March 18, 2026UI refinements for port labelling, SSH corrections, WiFi fixes, and support for preferred external ports beyond port 443.https://github.com/Start9Labs/start-os/releases/tag/v0.4.0-alpha.21EducationThe Core Issue: Your Node Vs. The Digital Wilderness — https://bitcoinmagazine.com/print/the-core-issue-your-node-vs-the-digital-wildernessThe Core Issue: Outrunning Entropy, Why Bitcoin Can't Stand Still — https://bitcoinmagazine.com/print/the-core-issue-outrunning-entropy-why-bitcoin-cant-stand-stillThe Core Issue: Consensus Cleanup — https://bitcoinmagazine.com/print/the-core-issue-consensus-cleanupTO DONATE TO ROMAN'S DEFENSE FUND: https://freeromanstorm.com/donateHELP GET SAMOURAI A PARDONSIGN THE PETITION ----> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools DONATE TO THE FAMILIES ----> https://www.givesendgo.com/billandkeonneSUPPORT ON SOCIAL MEDIA ---> https://billandkeonne.org/VALUE FOR VALUEThanks for listening you Ungovernable Misfits, we appreciate your continued support and hope you enjoy the shows.You can support this episode using your time, talent or treasure.TIME:- create fountain clips for the show- create a meetup- help boost the signal on social mediaTALENT:- create ungovernable misfit inspired art, animation or music- design or implement some software that can make the podcast better- use whatever talents you have to make a contribution to the show!TREASURE:- BOOST IT OR STREAM SATS on the Podcasting 2.0 apps @ https://podcastapps.com- DONATE via Monero @ https://xmrchat.com/ugmf- BUY SOME STICKERS @ https://www.ungovernablemisfits.com/shop/FOUNDATIONhttps://foundation.xyz/ungovernableFoundation builds Bitcoin-centric tools that empower you to reclaim your digital sovereignty.As a sovereign computing company, Foundation is the antithesis of today's tech conglomerates. Returning to cypherpunk principles, they build open source technology that “can't be evil”.Thank you Foundation Devices for sponsoring the show!Use code: Ungovernable for $10 off of your purchaseCAKE WALLEThttps://cakewallet.comCake Wallet is an open-source, non-custodial wallet available on Android, iOS, macOS, and Linux.Features:- Built-in Exchange: Swap easily between Bitcoin and Monero.- User-Friendly: Simple interface for all users.Monero Users:- Batch Transactions: Send multiple payments at once.- Faster Syncing: Optimized syncing via specified restore heights- Proxy Support: Enhance privacy with proxy node options.Bitcoin Users:- Coin Control: Manage your transactions effectively.- Silent Payments: Static bitcoin addresses- Batch Transactions: Streamline your payment process.Thank you Cake Wallet for sponsoring the show!MYNYMBOXhttps://mynymbox.ioYour go-to for anonymous server hosting solutions, featuring: virtual private & dedicated servers, domain registration and DNS parking. We don't require any of your personal information, and you can purchase using Bitcoin, Lightning, Monero and many other cryptos.Explore benefits such as No KYC, complete privacy & security, and human support.(00:00:00) INTRO(00:00:57) THANK YOU FOUNDATION(00:01:38) THANK YOU CAKE WALLET(00:02:43) PRIME TIME(00:07:16) PSA: Avoid SamouraiWallet.com(00:12:16) Vibe Coding Corner(00:20:09) Kentucky HB 380 Would Break Self‑Custody(00:24:31) GrapheneOS Stands Firm(00:25:21)
Gros zoom sur les skills et leurs usages dans les coding agents, sur les benchmarks de stacks techniques MCP, mais aussi du Java 26-27, du HttpClient, du NodeJS, des scenarios nucléaires pilotés par l'IA, de la méthodologie, bref on ne s'ennuie pas ! Enregistré le 15 mars 2026 Téléchargement de l'épisode LesCastCodeurs-Episode-338.mp3 ou en vidéo sur YouTube. News Langages Bruno Borges a créé un site, inspiré d'un site récent qui montrait comment CSS avait évolué, qui illustre justement comment Java a bien évolué au fil du temps, et est devenu un langage encore plus élégant https://javaevolved.github.io/ Code simplifié: main() allégé, var, blocs de texte, API String enrichie. Pattern Matching: switch sur types, instanceof amélioré, record patterns. Données: Records, collections immuables faciles à créer, méthodes de listes. Concurrence: Threads virtuels, CompletableFuture, StructuredTaskScope, ScopedValue. Erreurs & Sécurité: NPE précis, catch multiples, Optional amélioré, filtres de désérialisation. I/O & Réseau: HttpClient moderne, E/S fichiers/console simplifiées, transferTo. Dates & Heures: API modernisée, précise, immutables et thread-safe. Langage: Interfaces sealed/private, import de modules, Math.clamp Streams: Nouveaux opérateurs (takeWhile, mapMulti, Gatherers, teeing). Outils & Perf: jshell, exécution simplifiée, jwebserver, AOT, JFR, optimisation mémoire. 10+ raisons de ne pas utiliser le HttpClient du JDK, avec un article très détaillé de Brice Dutheil https://blog.arkey.fr/2026/02/08/ten-reasons-to-not-use-jdk-httpclient/ JDK HttpClient: intégré, non-upgradable. OkHttp: plus lourd (dépendance Kotlin). TLS/SSL: JDK: SSLContext limité, vérif hôte globale, épinglage manuel, SSLParameters rigides. OkHttp: contrôle fin (SSLSocketFactory/TrustManager), vérif hôte/épinglage dédiés, ConnectionSpec structuré. Connexions: JDK: pas de repli, fabrique socket custom impossible (pas UDS/Named Pipes direct), pool limité (propriétés système, contrôle pauvre avant JDK 20/21). OkHttp: repli automatique, fabrique custom, pool granulaire. Réseau: JDK: résolveur DNS par défaut, Authenticator unique. OkHttp: résolveur DNS custom, authentificateurs séparés (proxy/serveur). Cycle Requêtes: JDK: pas d'intercepteurs ni API événements intégrés. OkHttp: addInterceptor, EventListener pour événements granulaires. Ressources: JDK: pas d'arrêt propre avant JDK 21. OkHttp: arrêt granulaire (pool, exécuteur, cache). Timeout: JDK: désactivé après en-têtes; le transfert du corps peut dépasser le timeout initial. JDK 26 et JDK 27 : ce qui nous attend — https://www.infoq.com/news/2026/02/java-26-so-far/ JDK 26 est une version non-LTS prévue le 17 mars 2026, avec 10 nouvelles fonctionnalités réparties en 5 catégories Le support HTTP/3 arrive enfin dans l'API HTTP Client standard de Java (JEP 517) La Structured Concurrency (projet Loom) en est à sa 6e preview, avec l'ajout d'une méthode onTimeout() sur StructuredTaskScope.Joiner Les Lazy Constants passent en 2e preview : des constantes initialisées à la demande, utiles pour optimiser le démarrage Le G1 GC gagne en performance via une réduction des synchronisations entre threads applicatifs et threads GC (JEP 522) Le cache d'objets AOT (JEP 516) est étendu pour fonctionner avec n'importe quel GC, y compris ZGC L'API Applet est définitivement supprimée (JEP 504), fermant une page historique de Java L'encodage PEM des objets cryptographiques continue sa preview avec support de chiffrement/déchiffrement de KeyPair Pour JDK 27 (septembre 2026), l'échange de clés post-quantique hybride pour TLS 1.3 est déjà ciblé (JEP 527) Project Valhalla progresse avec une preview des Value Classes : objets sans identité, à champs final uniquement Librairies Une étude de performance montre que Java est un super choix pour développer des serveurs MCP https://www.tmdevlab.com/mcp-server-performance-benchmark.html Comparaison de performances de serveurs MCP (Model Context Protocol) en Java, Go, Node.js, Python. Méthodologie: 3,9 millions requêtes, environnement Docker (1 cœur CPU, 1 Go RAM/serveur). Fiabilité: 0% d'erreurs pour toutes les implémentations. Tiers de performance: 1 (Haute): Go & Java (latence < 1ms, ~1600 requêtes/s). ▪︎ Go: Efficacité mémoire exceptionnelle (18 Mo vs 220 Mo pour Java). ▪︎ Java: Latence marginalement meilleure, mais 12x plus de mémoire. 2 (Moyenne): Node.js (latence ~10,7 ms, ~560 requêtes/s). Surcharge par instanciation. 3 (Faible): Python (latence ~26,5 ms, ~290 requêtes/s). Limité par GIL. Recommandations production: Go: Optimal forte charge, cloud-native, optimisation coûts. Java: Latence très basse critique, infrastructure Java existante. Node.js & Python: Adaptés charges modérées/faibles, développement/test. Node.js et Python peuvent être optimisés pour améliorer leurs performances en production. Et encore, en Java, le benchmark n'a pas utilisé GraalVM pour une compilation native, ce qui aurait donné des chiffres côté mémoire qui aurait concurrencé Go Qui a la meilleure perf entre Quarkus et Spring pour faire des serveurs MCP ? https://medium.com/@egekaraosmanoglu/spring-boot-vs-quarkus-which-java-runtime-wins-the-ai-mcp-tools-performance-battle-4da9d6a248d5 Quarkus JVM: Débit et latence les plus élevés (jusqu'à 16 381 req/s, 65% plus rapide que Spring Boot), surpasse Spring Boot même avec Apache Camel. Quarkus Native: Consommation mémoire la plus faible (118 MB), démarrage instantané, performance prédictible. Spring Boot MVC: Bonnes performances, écosystème mature, nécessite un "warm-up" important (jusqu'à 44% de gain). Spring Boot WebFlux: Légèrement meilleur débit et latence que MVC (~5%), mais plus de mémoire et complexité réactive. Coût architectural: MapStruct: Impact négligeable (< ±5%). Apache Camel: Réduction de débit de 8-21%, mais valeur ajoutée significative; Quarkus JVM + Camel reste > Spring Boot baseline. Protocole MCP: Sur Quarkus JVM (avec Camel), surpasse gRPC. Recommandations: Débit max: Quarkus JVM. Coût/Serverless: Quarkus Native. Intégration d'entreprise: Quarkus JVM + Camel + MapStruct. Meilleur choix Spring: Spring Boot WebFlux + MapStruct. Benchmark des stacks qui implémentent MCP https://www.tmdevlab.com/mcp-server-performance-benchmark-v2.html MCP (Model Context Protocol) est le protocole d'Anthropic pour connecter les LLMs à des outils et sources de données externes ; ce benchmark compare 15 implémentations serveur. 39,9 millions de requêtes traitées avec zéro erreur, sur des charges I/O réalistes (Redis + HTTP API) plutôt que des tâches CPU synthétiques. Rust atteint 4 845 RPS avec seulement 10,9 Mo de RAM ; Quarkus obtient 4 739 RPS avec la meilleure latence (4,04 ms en moyenne, 8,13 ms au P95). Go (3 616 RPS) et Spring MVC (3 540 RPS) constituent un second groupe solide. Node.js plafonne à 423 RPS ; Bun est 2,2x plus rapide sur un code identique (876 RPS) ; Python atteint 259 RPS avec 4 workers et uvloop. Découverte notable : un bug dans le SDK Rust rmcp v0.16 ajoutait ~40 ms de latence à toutes les réponses HTTP, limitant le débit à 1 283 RPS ; corrigé en v0.17 via la PR #683. Les images natives GraalVM réduisent la mémoire de 27 à 81 % mais dégradent le débit de 20 à 36 % ; Quarkus-native est l'exception avec 36 Mo RAM et 3 449 RPS. Spring MVC (bloquant) surpasse WebFlux (réactif) à 50 utilisateurs simultanés, rappelant que le modèle réactif n'est pas toujours gagnant. Recommandations : Rust ou Quarkus pour la production haute charge, Go pour le cloud-native, Bun plutôt que Node.js en JavaScript. Jakarta EE 12 Milestone 2 : données, cohérence et configuration https://www.infoq.com/articles/jakartaee-12-milestone-2/ Jakarta EE est la plateforme Java entreprise open-source, socle de frameworks comme Quarkus et Spring, qui standardise les APIs pour la persistance, les transactions, la sécurité, etc. Jakarta EE 12 adopte Java 21 comme baseline (avec support Java 25) et supprime définitivement le SecurityManager déprécié. La nouvelle spec Jakarta Query unifie JPQL (SQL/relationnel) et JDQL (NoSQL) en un seul langage avec deux profils : Core Language (portable) et Persistence Language (relationnel). Jakarta Data 1.1 introduit les requêtes dynamiques via une API fluente avec Restriction et l'annotation @Is pour des conditions plus expressives. Jakarta Data supporte désormais les repositories stateful, permettant la gestion du cycle de vie des entités (persist, merge, detach, refresh) comme en JPA classique. Jakarta NoSQL 1.1 intègre Jakarta Query via une nouvelle interface Query et supporte les projections avec des Java records. Jakarta Persistence 4.0 supporte SequencedCollection (Java 21) comme type de collection dans les entités. Une nouvelle spec Jakarta Agentic AI est en cours, visant des APIs vendor-neutral pour construire des agents IA sur les runtimes Jakarta EE, avec intégration prévue de LangChain4j et Spring AI. Cette release est encore un milestone (pas pour la prod) — l'adoption large dépendra de la maturité des outils (IDE, validation de requêtes, diagnostics). Nouveaux benchmarks Quarkus vs Spring Boot : performance complète et transparente https://quarkus.io/blog/new-benchmarks/ Quarkus est un framework Java optimisé pour les conteneurs, connu pour son faible usage mémoire et son démarrage rapide, concurrent principal de Spring Boot. Les anciens graphiques de performance sur quarkus.io étaient obsolètes, sans date, sans source, et ne montraient pas le débit (throughput). L'absence de données sur le throughput faisait croire à tort que Quarkus avait de mauvaises performances à ce niveau. Un nouveau benchmark open source a été créé, transparent et reproductible, disponible sur GitHub. Résultats : Quarkus gère 2,7x plus de transactions par seconde que Spring Boot, démarre 2,3x plus vite, avec deux fois moins de mémoire. Des experts Spring Boot externes ont contribué à rendre la comparaison plus équitable, notamment sur la configuration des pools de connexions. Les threads virtuels améliorent le débit d'environ 6000 tps supplémentaires pour tous les frameworks testés. Spring Boot 4 offre un meilleur débit que Spring Boot 3, mais au prix d'un démarrage plus lent et d'une empreinte mémoire plus élevée. En mode natif (GraalVM), le démarrage est ultra-rapide mais le throughput est divisé par deux, pour Quarkus comme pour Spring Boot. Le mode natif n'est recommandé que pour les applis démarrées/arrêtées très fréquemment ou à faible charge. Quarkus 3.32 : fondations pour la prochaine LTS https://quarkus.io/blog/quarkus-3-32-released/ Quarkus est un framework Java cloud-natif optimisé pour GraalVM et HotSpot, conçu pour les microservices et les environnements conteneurisés. Cette version marque le feature freeze pour la prochaine version LTS 3.33. Intégration de Project Leyden (AOT JVM) : le démarrage d'une application REST minimale passe de 370ms à 80ms. L'entraînement Leyden peut se déclencher au build ou via les tests d'intégration. Amélioration du graceful shutdown HTTP, avec des contributions de l'équipe Keycloak. Enregistrement automatique dans Consul via l'extension Stork pour la découverte de services. Nouvelles fonctionnalités de sécurité : DPoP nonce providers personnalisés, support de rich authorization pour OIDC. Possibilité de personnaliser l'ordre des mécanismes d'authentification et ajout de OIDCAuthenticationCompletionAction. Mise à jour du framework Google Cloud Functions en version 2.0, ainsi que Camel Quarkus et Quarkus CXF. Les utilisateurs sur LTS 3.27 sont encouragés à tester la migration vers 3.33 pour faire remonter des retours. NodeJS change sa cadence de releases https://nodejs.org/en/blog/announcements/evolving-the-nodejs-release-schedule Node.js est le runtime JavaScript côté serveur le plus utilisé, géré par la OpenJS Foundation avec un cycle de releases actif depuis la fusion avec io.js il y a dix ans. À partir de Node.js 27 (octobre 2026), le projet passe d'une release majeure tous les six mois à une seule par an. Chaque release deviendra LTS, supprimant la distinction entre versions paires (LTS) et impaires (non-LTS). Un nouveau canal Alpha est introduit, permettant les changements semver-major pendant la phase de test précoce. Les phases deviennent : Alpha (6 mois, oct. à mars), Current (6 mois, avr. à oct.), LTS (30 mois), puis EOL. La durée totale de support reste de 36 mois, identique au modèle actuel. La numérotation des versions s'aligne sur l'année calendaire de la release Current (ex : 27.0.0 en 2027). La version Alpha est signée, taguée et testée via CITGM, mais n'est pas destinée à la production. La motivation principale : les versions impaires étaient peu adoptées, la distinction pair/impair perturbait les débutants, et réduire les lignes de release parallèles allège la charge des bénévoles. Les auteurs de bibliothèques sont encouragés à intégrer les releases Alpha dans leur CI dès que possible pour détecter les régressions en amont. Web jQuery v4 est sorti https://www.infoq.com/news/2026/02/jquery-4-release/?utm_source=twitter&utm_medium=link&utm_campaign=calendar jQuery est une bibliothèque JavaScript historique qui simplifie la manipulation du DOM, la gestion des événements et les requêtes AJAX, encore très présente dans de nombreuses bases de code. Cette version majeure sort pour les 20 ans de la bibliothèque, après presque une décennie sans version majeure. Suppression du support d'Internet Explorer 10 et antérieur, Edge Legacy et les anciennes versions iOS/Android. IE11 reste encore supporté dans jQuery 4, mais sa suppression est prévue pour jQuery 5. Le code source migre d'AMD vers les ES modules, pour une meilleure compatibilité avec les outils de build modernes. Le bundler passe de RequireJS à Rollup. Suppression des fonctions dépréciées comme jQuery.isArray, jQuery.parseJSON et jQuery.trim, désormais disponibles nativement en JavaScript. Le fichier gzippé gagne plus de 3 000 octets ; le build slim descend à environ 19,5 ko. Ajout du support des Trusted Types pour faciliter la compatibilité avec les Content Security Policy strictes. jQuery reste pertinent pour la maintenance de bases de code existantes et les projets nécessitant une faible dépendance aux frameworks. La réactivité en frontend : concepts et approches https://www.sfeir.dev/front/quest-ce-que-la-reactivite-en-frontend/ Un article qui resume comment la reactivite est implementee en front web La réactivité en frontend désigne le mécanisme qui permet de mettre à jour automatiquement l'UI quand les données changent, sans manipulation directe du DOM. Sans réactivité, les développeurs doivent mettre à jour manuellement chaque élément de l'interface, ce qui est fastidieux et source d'erreurs. Le data binding unidirectionnel (React) distingue le flux de données des callbacks d'interaction utilisateur. Le data binding bidirectionnel (Angular) synchronise automatiquement données et UI dans les deux sens. Le Virtual DOM (React, Vue) compare une représentation en mémoire avec le DOM réel avant d'appliquer uniquement les changements nécessaires. Les observables via RxJS (Angular) permettent de gérer des flux de données asynchrones et des événements complexes. Les signaux (SolidJS, Angular récent, Svelte) offrent des mises à jour granulaires et de meilleures performances que les approches précédentes. Les signaux proposent une API plus simple que les observables tout en restant très performants. La réactivité abstrait la manipulation du DOM et permet aux développeurs de se concentrer sur l'état de l'application. Data et Intelligence Artificielle Gunnar Morling a annoncé la sortie de Hardwood, un nouveau parseur Java pour les fichiers Apache Parquet, grâce aux leçons apprises par le 1BRC challenge https://www.morling.dev/blog/hardwood-new-parser-for-apache-parquet/ Hardwood : Nouveau parseur Apache Parquet open-source (Java 21+). But : Dépasser parquet-java (dépendances lourdes, lecteur mono-threadé). Points clés : Dépendances minimes, pipeline de décodage multi-threadé. APIs : RowReader (ligne) et ColumnReader (colonne, haute perf.). Optimisations : Parallélisme pages, préchargement adaptatif, moins d'allocations. Développement : Assisté par IA (Claude Code), révision humaine. Futur : "Predicate push-down", compatibilité parquet-java, écriture, CLI, intégration Iceberg. Apicurio Registry passe AI-Native — https://www.apicur.io/blog/2026/02/05/apicurio-registry-ai-natural-evolution Apicurio Registry est un registre open-source de schemas (OpenAPI, AsyncAPI, Avro, Protobuf…) gérant versioning, validation et gouvernance des APIs. Le projet étend ses capacités pour devenir une plateforme native AI, en appliquant les mêmes principes de gouvernance aux agents IA. Support du protocole A2A (Agent-to-Agent) : les agents s'enregistrent via des "Agent Cards" et se découvrent mutuellement via des endpoints standardisés. Un serveur MCP intégré permet aux LLMs d'interagir directement avec le registre (découverte de schémas, validation, création). L'intégration avec Claude Desktop est déjà documentée, permettant de gérer les artefacts en langage naturel. Deux nouveaux types d'artefacts : PROMPT_TEMPLATE (templates de prompts versionnés avec variables) et MODEL_SCHEMA (validation des entrées/sorties des agents). Les SDKs Java (LangChain4j, Quarkus) et Python (LangChain, LlamaIndex) sont disponibles. Une démo multi-agents illustre le "context chaining" : chaque agent reçoit les sorties des agents précédents dans la pipeline. La roadmap prévoit : gestion du cycle de vie des agents, recherche sémantique, intégration dans les pipelines de déploiement. L'Histoire du Deep Learning : quand les machines ont commencé à apprendre https://blog.ippon.fr/2026/02/20/lhistoire-du-deep-learning-quand-les-machines-ont-commence-a-apprendre/ un article qui retrace les avancées clées du machine learning Le deep learning est un sous-domaine du ML basé sur des réseaux de neurones empilés en couches, aujourd'hui omniprésent dans la vision, le langage et la recommandation. Le Perceptron (1957) est le premier modèle formel d'apprentissage supervisé, mais il échoue sur des problèmes non linéaires comme le XOR : une limite structurelle, pas algorithmique. La rétropropagation du gradient (années 80) permet d'entraîner des réseaux multi-couches, mais souffre du problème de "vanishing gradient" qui bloque l'apprentissage en profondeur. L'essor du deep learning dans les années 2000 est autant une révolution matérielle qu'algorithmique : les GPU, conçus pour le jeu vidéo, se révèlent parfaitement adaptés aux calculs matriciels. AlexNet (2012) marque une rupture industrielle en démontrant qu'un CNN profond entraîné sur GPU surpasse largement les méthodes classiques en reconnaissance d'images. Les LSTM (1997) résolvent les problèmes de mémoire à long terme des RNN, mais leur nature séquentielle limite fortement la parallélisation. Les Transformers ("Attention Is All You Need", 2017) révolutionnent le domaine en remplaçant la récursion par un mécanisme d'attention parallélisable, adaptable aux GPU et TPU. L'IA générative introduit une rupture conceptuelle : les modèles apprennent la distribution des données pour en produire de nouveaux exemples, et non plus simplement classifier. Les LLM offrent un socle généraliste réutilisable pour de nombreuses tâches, là où l'IA prédictive nécessitait un modèle spécifique par problème. La question de l'AGI reste ouverte et très incertaine, mais l'IA devient déjà un "acteur logiciel" capable de raisonner et d'agir de manière autonome via les agents. Ca y est, Agent to Agent Protocol (A2A) est sorti en version 1.0 https://a2a-protocol.org/latest/announcing-1.0/ Prêt pour la prod Support multi-version ( multi-protocoles (gRPC, HTTP+JSON…) Multi-tenancy : un même endpoint peut supporter et exposer plusieurs agents distincts Agent Cards signées et vérifiables cryptographiquement pour vérifier l'identité des agents Flexibilité : les clients peuvent choisir de consommer les résultats par polling, streaming, ou également webhooks Outillage Le guide complet pour créer des skills pour vos agents, par Anthropic https://resources.anthropic.com/hubfs/The-Complete-Guide-to-Building-Skill-for-Claude.pdf Définition et structure : Les skills sont des dossiers contenant des instructions (fichier SKILL.md obligatoire) et des scripts qui enseignent aux agents comment exécuter des tâches spécifiques ou utiliser des outils MCP de manière fiable. Fonctionnement technique : Le système repose sur la "divulgation progressive" via un en-tête YAML critique, permettant à Claude de charger le contexte de la compétence uniquement lorsque la demande de l'utilisateur le nécessite. Cycle de vie : Le guide couvre toutes les étapes de développement, de la définition des cas d'usage (automatisation, création de documents) aux protocoles de test et de distribution. il couvre aussi comment tester (brievement) et des patterns communs Apprendre a utiliser les skills pour structurer son code ia https://philippart-s.github.io/blog/2026-02-18-anthropic-skills/ Les Skills Claude sont des packages d'instructions dans un dossier enseignant à Claude comment gérer des tâches spécifiques de façon cohérente. Un skill se compose au minimum d'un fichier SKILL.md avec un frontmatter YAML et des instructions en Markdown. Le frontmatter YAML impose deux champs obligatoires : name (en kebab-case) et description (max 1024 caractères expliquant quoi faire et quand le déclencher). Les skills fonctionnent de façon identique sur Claude.ai, Claude Code et l'API sans modification. Trois catégories principales : création de documents/assets, automatisation de workflows multi-étapes, et amélioration d'intégrations MCP. Les skills s'appuient sur le principe de divulgation progressive : frontmatter toujours chargé, corps du SKILL.md si pertinent, fichiers liés à la demande. Cinq patterns courants : orchestration séquentielle, coordination multi-MCP, raffinement itératif, sélection d'outils contextuelle, intelligence métier embarquée. Les tests doivent couvrir le déclenchement (90% des requêtes pertinentes), le fonctionnel et la comparaison avec la baseline sans skill. Pour la distribution, héberger sur GitHub avec un README séparé du dossier du skill (pas de README.md dans le dossier lui-même). Un skill-creator officiel permet de générer un premier SKILL.md en 15-30 minutes à partir d'une description en langage naturel. Les skills pour les agents, c'est une façon d'automatiser des tâches répétitives https://glaforge.dev/posts/2026/02/21/easily-build-a-local-mcp-server-in-java-with-a-skill-in-gemini-cli/ Construction facile de serveurs MCP Java locaux pour Gemini CLI et autres agents. Solution au code Java répétitif : JBang + LangChain4j + un "skill" utilisé par Gemini CLI. Idée clée : Une "skill" pour Gemini CLI automatise génération et installation des serveurs. La "skill" génère un fichier Java, le compile et l'enregistre dans les paramètres de Gemini CLI. Avantages : Élimine le boilerplate, enregistrement automatique, développement rapide. Conclusion : Les "skills" d'agent automatisent les tâches répétitives et systématisent l'expérimentation. Un SKILL.md par Julien Dubois pour permettre aux agents IA de créer des projets Spring en suivant les bonnes pratiques à la JHipster https://github.com/jdubois/dr-jskill/blob/main/SKILL.md Dr JSkill est une "Agent Skill" conçue pour aider les IA (GitHub Copilot CLI, Claude Code) à générer des applications Spring Boot 4.x selon les meilleures pratiques de Julien Dubois. Permet de créer des projets full-stack modernes utilisant Java 25, PostgreSQL et Docker, avec un choix de frameworks front-end (Vue.js par défaut, React, Angular ou Vanilla JS). Intègre des scripts Node.js multiplateformes pour automatiser la génération de projets via start.spring.io sans dépendances npm externes. Préconise des choix technologiques stricts : Maven uniquement, pas de Lombok, et utilisation de Hibernate ddl-auto pour la gestion du schéma (pas de Flyway/Liquibase). Supporte nativement la compilation GraalVM (images natives) pour des démarrages ultra-rapides (
In this episode, we sit down with the Radare community leader, Pancake, the creator of the Radare2 reverse engineering framework. Whether you've never heard of Radare, already use it daily, or are thinking about contributing to its development, this conversation will demystify what makes Radare unique, why thousands of engineers rely on it, and how you can step into the community. This segment is sponsored by NowSecure. Discover how AI-powered mobile app security testing finds hidden vulns and leaks at https://securityweekly.com/nowsecure. In the security news: The US national cyber strategy in the category of dumb laws and 3d printing guns Iranian threat analysis ESP32 Bus Pirate gets some amazing updates I can reset the admin password Rick-rolling yourself Chrome 0days Re-purposing those old Ubiquiti cloud keys The new TLS certificate lifecycle A Flipper Zero add-on and news on the FlipperOne glassword malware Do you care about exploits or patching? attacking nuclear research centers how we uncovered 9 vulnerabilities in IP KVMs and hacking your laundry card with Claude Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-918
In this episode, we sit down with the Radare community leader, Pancake, the creator of the Radare2 reverse engineering framework. Whether you've never heard of Radare, already use it daily, or are thinking about contributing to its development, this conversation will demystify what makes Radare unique, why thousands of engineers rely on it, and how you can step into the community. This segment is sponsored by NowSecure. Discover how AI-powered mobile app security testing finds hidden vulns and leaks at https://securityweekly.com/nowsecure. In the security news: The US national cyber strategy in the category of dumb laws and 3d printing guns Iranian threat analysis ESP32 Bus Pirate gets some amazing updates I can reset the admin password Rick-rolling yourself Chrome 0days Re-purposing those old Ubiquiti cloud keys The new TLS certificate lifecycle A Flipper Zero add-on and news on the FlipperOne glassword malware Do you care about exploits or patching? attacking nuclear research centers how we uncovered 9 vulnerabilities in IP KVMs and hacking your laundry card with Claude Show Notes: https://securityweekly.com/psw-918
In this episode, we sit down with the Radare community leader, Pancake, the creator of the Radare2 reverse engineering framework. Whether you've never heard of Radare, already use it daily, or are thinking about contributing to its development, this conversation will demystify what makes Radare unique, why thousands of engineers rely on it, and how you can step into the community. This segment is sponsored by NowSecure. Discover how AI-powered mobile app security testing finds hidden vulns and leaks at https://securityweekly.com/nowsecure. In the security news: The US national cyber strategy in the category of dumb laws and 3d printing guns Iranian threat analysis ESP32 Bus Pirate gets some amazing updates I can reset the admin password Rick-rolling yourself Chrome 0days Re-purposing those old Ubiquiti cloud keys The new TLS certificate lifecycle A Flipper Zero add-on and news on the FlipperOne glassword malware Do you care about exploits or patching? attacking nuclear research centers how we uncovered 9 vulnerabilities in IP KVMs and hacking your laundry card with Claude Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-918
In this episode, we sit down with the Radare community leader, Pancake, the creator of the Radare2 reverse engineering framework. Whether you've never heard of Radare, already use it daily, or are thinking about contributing to its development, this conversation will demystify what makes Radare unique, why thousands of engineers rely on it, and how you can step into the community. This segment is sponsored by NowSecure. Discover how AI-powered mobile app security testing finds hidden vulns and leaks at https://securityweekly.com/nowsecure. In the security news: The US national cyber strategy in the category of dumb laws and 3d printing guns Iranian threat analysis ESP32 Bus Pirate gets some amazing updates I can reset the admin password Rick-rolling yourself Chrome 0days Re-purposing those old Ubiquiti cloud keys The new TLS certificate lifecycle A Flipper Zero add-on and news on the FlipperOne glassword malware Do you care about exploits or patching? attacking nuclear research centers how we uncovered 9 vulnerabilities in IP KVMs and hacking your laundry card with Claude Show Notes: https://securityweekly.com/psw-918
On this week's show, Patrick Gray, Adam Boileau and James WIlson discuss the week's cybersecurity news. They discuss: Iran's Intune-based wiper attack on medical device maker Stryker Qihoo 360's AI publishes its own wildcard TLS cert private key Instagram is canning its end-to-end encrypted messaging What's going on with mobile internet access in Moscow? The Xbox One's bootloader gets voltage glitched into submission Oh Qualys! We love you! (At least, whoever is in the basement writing these beautiful .txt files…) This week's episode is sponsored by browser-based detection and response company, Push Security. Researcher Dan Green and Field CTO Mark Orlando join Pat to talk through the InstallFix variant of the *Fix attack technique. This episode is also available on Youtube. Show notes Iranian Hacktivists Strike Medical Device Maker Stryker in "Severe" Attack that Wiped Systems Stryker says it's restoring systems after pro-Iran hackers wiped thousands of employee devices | TechCrunch Stryker attack raises concerns about role of device management tool | Cybersecurity Dive Stryker tells SEC that timeline for recovery from cyberattack unknown | The Record from Recorded Future News How ‘Handala' Became the Face of Iran's Hacker Counterattacks | WIRED U.S Strikes Killed Iranian Cyber Chiefs, But The Hacks Continued Risky Business Features: Being a Wartime CISO Supply-chain attack using invisible code hits GitHub and other repositories - Ars Technica China's biggest cybersecurity company, Qihoo 360 just leaked their own wildcard SSL private key Emergent Cyber Behavior: When AI Agents Become Offensive Threat Actors - Irregular Risky Business Features: MCP is Dead Measuring AI Agents' Progress on Multi-Step Cyber Attack Scenarios Measuring AI Agents' Progress on Multi-Step Cyber Attack Scenarios What is end-to-end encryption on Instagram | Instagram Help Center US Lawmakers Move to Kill the FBI's Warrantless Wiretap Access | WIRED Website "whitelists" launched in Moscow | Forbes.ru Exclusive: Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show | Reuters Feds say another DigitalMint negotiator ran ransomware attacks and helped extort $75 million | CyberScoop Researchers disclose vulnerabilities in IP KVMs from four manufacturers - Ars Technica RE//verse 2026: Hacking the Xbox One by Markus 'doom' Gaasedelen - YouTube CrackArmor: Multiple vulnerabilities in AppArmor
professorjrod@gmail.comIn this episode of Technology Tap: CompTIA Study Guide, we dive into the fundamentals of Windows security, an essential topic for anyone preparing for IT certifications like the CompTIA A+ Core 2 exam. Understanding Windows security is critical for IT skills development and technology education, as it functions as an ongoing trust engine that verifies user identity and access permissions seamlessly.We explore the underlying architecture of Windows security, moving beyond rote memorization to help you reason through security protocols and apply them both on the job and during your tech exam prep. Whether you're studying in a group or solo, this guide will strengthen your comprehension of complex security concepts and better prepare you for your IT certification exams.We connect the CIA triad to the real Windows controls you touch every day, then break down identity and access management step by step: identification, authentication, authorization, and access control. From there, we get practical about access control lists, implicit deny, and least privilege, including why over-privileged accounts turn small mistakes into big incidents. We also clear up a common confusion that derails newer techs: hashing versus encryption, plus where symmetric encryption, asymmetric encryption, digital signatures, and TLS key exchange show up in real life.Then we move into the account and admin side of Windows: local accounts versus Microsoft accounts, the power of security groups, quick account management with Net User, and why User Account Control is both a security control and a behavior check. We close with an enterprise view of privileged access management, just-in-time admin access, Zero Trust, and modern multi-factor authentication like authenticator apps and one-time passwords. This is Act One of a two-parter, so we also preview the next step where Windows turns into a full enterprise security platform. Subscribe, share this with a friend studying IT, and leave a review with your biggest Windows security question.Support the showArt By Sarah/DesmondMusic by Joakim KarudLittle chacha ProductionsJuan Rodriguez can be reached atTikTok @ProfessorJrodProfessorJRod@gmail.com@Prof_JRodInstagram ProfessorJRod
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Encrypted Client Hello: Ready for Prime Time? https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778 The ExifTool vulnerability: how an image can infect macOS systems https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/ Remote code execution in Nextcloud Flow via vulnerable Windmill version https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf
Last November Nick and John introduced Dimitra Fimi, the magnificent maven of Tolkien Studies and Professor of Fantasy and Children's Literature at the University of Glasgow, to students of J. K. Rowling's work. In that discussion, ‘Reading Rowling as Myth Maker and Myth Re-Writer: A Conversation with Dr Dimitra Fimi,' she shared her thoughts about Rowling's creative use of mythology in Harry Potter but especially in the Cormoran Strike series.The Hogwarts Professor team asked her to join us again because of Rowling's yuletide charm bracelet gift to Strike fandom and the recent announcement of the Strike 9 title, Sleep Tight, Evangeline. Her insights about the Longfellow poem as a possible even likely source of the next book's epigraphs are engaging, but it is her expertise in the arcane area of miniature books as well as mythology and the light each shines on the two items attached to the last link of the charm bracelet that open up exciting possibilities.Her idea is that the Psalter on the ninth link of the charm bracelet may actually be, unlike the other tokens on the bracelet's nine links, an object that will play a part in the story, a miniature book. It turns out that one inch high books were something of an industry as curios in the 19th and early 20th century, a means of demonstrating technological mastery.Dr Fimi discussed several projects she has been a part of in conjunctions with nano-technologists and the librarians at the University of Glasgow's special collections division. The one that has the most obvious link to English literature is the ‘Tiny Alice project,' a contemporary effort to minituarize Lewis Carroll's Alice stories to unfathomable minuteness:The Tiny Alice Project has produced one of the world's smallest books: a tiny reproduction of Lewis Carroll's children's classic Alice's Adventures in Wonderland (1865). All 78 pages and 26,764 words of the story have been transposed on to a tiny silicon chip, with each page just the width of a human hair (60 microns). Each individual letter is just two microns high, and made from pure gold!Click on the icons below to find out more about the project, the technology behind it, and Lewis Carroll and his interest in the minuscule. Via the tabs above you can also discover the long tradition of miniature books, and teaching resources.Clip: Twixter link to tweet aboveYou can read Dr Fimi's write-up of ‘Tiny Alice' and the Miniature Book exhibition she curated at the University of Glasgow to highlight their special collection of these treasures at her 2019 blog post about them. Pictures that include annotated miniature books — copies in which their owners made notes in the miniscule margins of the printed pages — can be seen here.Later this week, Nick will be sharing his thoughts on Robert Browning's The Ring and the Book as the Ironbridge Murder story's template within Hallmarked Man, John, Nick, Sandy Hope, and Ed Shardlow will be parsing the ring within Strike8's Part Seven, and more about Longfellow's Evangeline — stay tuned!The Ten Questions Guiding Today's Conversation with Dr Fimi with the Necessary Links for Fun Follow-Up:(Intro) So everything Serious Strikers are thinking and talking about this month made me think of you, Dimitra, and to write you hat-in-hand with an invitation for your return to HogwartsProfessor to share your perspective, knowledge, and first impressions. Thank you for making time to join us!1. (John) Jumping right in, then, two of the charms on the Strike9 or ‘Evangeline' bracelet are Fimi areas of unique expertise: the Psalter and the Head of Persephone. I had urged readers to read your Miniature Books in Children's Fantasy at A Kind of Elvish Craft: The Dimitra Fimi Substack Site in the links after our conversation here last November but I confess to being surprised still when you asked for the dimensions of the Psalter charm after Nick and I posted our thoughts on the subject. For those who haven't read your ‘Miniature Books' post, please share how one of the world authorities on the writing of J. R. R. Tolkien became interested in the smallest of texts, the ‘Little Books' of 19th century printing.2. (Nick) So you asked for the dimensions of the Psalter, you weren't thinking as we were that the Psalter charms would be a box holding a folded up paper with a psalm, maybe two, inside it. You're thinking it might actually be a complete Coverdale Psalter? Is that possible?3. (John) What Nick and I hope to contribute to the nascent field of Rowling Studies, as you know, is a refocusing of the scholarship and the serious reader attention about her work on to her Lake Springs -- the biographical part of story inspiration -- her Shed Tools or intentional artistry, and the Golden Threads, the plot points and themes that run throughout her work, i.e., to bring Rowling Studies more in line with all literary scholarship about notable authors, living and dead.One of the Golden Threads we talked about in our Kanreki series last summer was the ‘Embedded Text,' the books inside a book topos that is in almost every book Rowling writes (Kanreki Golden Thread posts one and two). Detective fiction is always about an embedded text, the narrative ‘written' by the criminal to prevent the detective from reading the real story of what happened and Rowling-Galbraith often makes this narrative an actual book (Dumbledore Chocolate Frog Card, Tales of Beedle the Bard, Bombyx Mori, Talbot's ‘True Book,' The Predictions of Tycho Dodonus, etc.). How do you think a Psalter miniaturized book would appear in a Strike novel?4. (Nick) Has an author used a miniaturized book before in this way? Were there 19th Century Psalters that people wore as talismans or carried as the original Pocket Books?5. (John) And what about the Head of Persephone charm on that bracelet? It's on the ninth and last link, paired with that Psalter. You shared your first thought about the Persephone charm, a hopeful note, on the comment thread here. As our go-to authority on Greek mythology, I'm dying to know more of your thinking about (a) the specific charm and its relation to the Cupid and Psyche myth-template to the Strike series, (b) its pairing with the Psalter, and (c) its position as the last charm on the bracelet. Do you still think it's a sign that Robin will survive Sleep Tight, Evangeline?6. (Nick) As someone immersed in mythological studies and more than familiar with Rowling's use of myth, do you think the Jungian interpretation of that myth as the ‘actualization of feminine identity' is a better lens through which to read that embedded text or is the Spenserian lens of Eros/Anteros, False Cupid and Cupid more helpful? Or is this not a case of Either/Or but Both/And? Valentines Day Special7. (John) Rowling is a close reader and admirer of J. R. R. Tolkien, though that is more evident in the clear pointers to his work in her own work than from her interviews. How does her use of myth contrast with that of Tolkien and Lewis? (See John's 2008 post about Rowling's debts to Tolkien and the two part podcast with Tolkien scholars and Rowling Readers Dr Amy H Sturgis and Dr Sara Brown here and here for more on that influence.)8. (Nick) In an in-person meeting with UK Serious Strikers last week, Rowling shared with them and later via X with everyone the title of the ninth Strike novel, Sleep Tight, Evangeline. We're pretty sure that title refers to a song by an American Blues group called ‘The Whiskey Shambles' (story of the hunt, why Whiskey Shambles is a good bet). There is a famous poem, though, by Henry Wadsworth Longfellow called ‘Evangeline,' one perhaps not as famous as ‘Aurora Leigh' or ‘The Ring and the Book,' other texts Rowling may have used as back-drops to her novels, but still another poem very famous in its own time akin to those epics. Is its subject matter as good a match-up with the possible direction of Sleep Tight as the Victorian poetry back-drop is with other Rowling models?9. (John) You're a native Greek speaker; what does ‘Evangeline' mean in Greek? Is it a common name in Greece or is it a ‘Virtue Name' in the Puritan tradition of grace-filled names (cf., Credence Barebone is probably a reference to an Englishman named “Praise-God Barebone, whose son Nicholas may have been given the name If-Jesus-Christ-had-not-died-for-thee-thou-hadst-been-damned[3]“).10. (Nick) Don't leave before trying to tie together the pieces of this conversation! Is there a thread joining the Psalter, the Head of Persephone, miniaturized books, and the title Sleep Tight, Evangeline?Dimitra Fimi is Professor of Fantasy and Children's Literature at the University of Glasgow and Co-Director of the Centre for Fantasy and the Fantastic. Her Tolkien, Race and Cultural History won the Mythopoeic Scholarship Award for Inklings Studies and she co-edited the critical edition of A Secret Vice: Tolkien on Invented Languages which won the Tolkien Society Award for Best Book. Her Celtic Myth in Contemporary Children's Fantasy won the Mythopoeic Scholarship Award in Myth and Fantasy Studies. Other work includes co-editing Sub-creating Arda: World-building in J.R.R. Tolkien's Work, its Precursors and its Legacies and Imagining the Celtic Past in Modern Fantasy. She has contributed articles for the TLS and The Conversation, and has appeared on numerous radio and TV programs.When the rightly famous and beloved ‘The Great Courses' series decided to offer a Lord of the Rings entry for their catalog of the very best in scholarship for adult-learners, they asked Dimitra Fimi to create ‘The World of J. R. R. Tolkien,' one of their most popular courses and one you can enjoy in an Audible edition.Links Promised in Conversation:A Kind of Elvish Craft: The Dimitra Fimi Substack Site* Miniature Books in Children's Fantasy* Parabasis: A Tribute to Dionysis Stavvopoulos* On Tolkien's Letter 131 (4): “Romance” vs. ScienceDimitra Fimi articles at ‘The Conversation'* After 150 years, we still haven't solved the puzzle of Alice in Wonderland (2015) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit hogwartsprofessor.substack.com/subscribe
Our winter season continues with Adina Hoffman (recipient of a 2013 Windham-Campbell Prize for Nonfiction) chatting with Michael Kelleher about Georges Perec's magical and mercurial and maddening An Attempt at Exhausting a Place in Paris, translated by Marc Lowenthal. Adina Hoffman is the author of House of Windows: Portraits from a Jerusalem Neighborhood, My Happiness Bears No Relation to Happiness: A Poet's Life in the Palestinian Century, Sacred Trash: The Lost and Found World of the Cairo Geniza (with Peter Cole), Till We Have Built Jerusalem: Architects of a New City, and Ben Hecht: Fighting Words, Moving Pictures. Hoffman's essays and criticism have appeared in the Nation, the Washington Post, the New York Times, the TLS, Raritan, Bookforum, the Boston Globe, New York Newsday, Tin House, and on the World Service of the BBC. She is formerly a film critic for the American Prospect and the Jerusalem Post and was one of the founders and editors of Ibis Editions, a small press devoted to the publication of the literature of the Levant. She has been a visiting professor at Wesleyan University, Middlebury College, and NYU, as well as the Franke Fellow at Yale's Whitney Humanities Center. She lives in Jerusalem and New Haven.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
We have seen much talk of the upcoming drop of maximum TLS term to 200 days, followed by 100 days, and eventually down to 47 days. It happens that all those numbers are too large and the actual maxima will be less than that. We explain.
You've got Tyler & Brad and In this episode, we break down the early versions of Transport Layer Security (TLS) — TLS 1.0 and TLS 1.1 — and explain why these once-standard encryption protocols are now considered insecure. We'll cover when they were released, how modern attacks and cryptographic weaknesses caught up with them, and why today's internet relies on newer, more secure protocols like TLS 1.2 and TLS 1.3.We'll also discuss how even “secure” protocols can become vulnerable when weak ciphers are enabled, using Sweet32 as a real-world example of cipher-level risk.Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇Spencer's Links: https://go.spenceralessi.com/links Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
ZFS Scrubs and Data integrity, Propolice, FreeBSD vs Slackware and more. NOTES This episode of BSDNow is brought to you by Tarsnap and the BSDNow Patreon Headlines Understanding ZFS Scrubs and Data Integrity The story of Propolice Desk reviews describe comment ask questions No reponses, no justications. [Tj's Desk](media/bsdnow649-tjs-desk.jpg) [Ruben's Desk](media/bsdnow649-rubens-desk.jpg) News Roundup FreeBSD vs. Slackware: Which super stable OS is right for you? Prometheus, Let's Encrypt, and making sure all our TLS certificates are monitored Wait, a repairable ThinkPad!? Tarsnap This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups. Feedback/Questions Send questions, comments, show ideas/topics, or stories you want mentioned on the show to feedback@bsdnow.tv Join us and other BSD Fans in our BSD Now Telegram channel
Welcome to The Chrisman Commentary, your go-to daily mortgage news podcast, where industry insights meet expert analysis. Hosted by Robbie Chrisman, this podcast delivers the latest updates on mortgage rates, capital markets, and the forces shaping the housing finance landscape. Whether you're a seasoned professional or just looking to stay informed, you'll get clear, concise breakdowns of market trends and economic shifts that impact the mortgage world.In today's episode, we go through the chatter from the hallways at MBA's Independent Mortgage Banker Conference. Plus, Robbie sits down with TLS' Will Pendleton and Calque's Jeremy Foster for a discussion on how the Buy Before You Sell model helps brokers remove timing and contingency risk for today's buyers, and why transparent, well-integrated solutions like this are increasingly becoming essential tools for brokers navigating more competitive and complex housing markets. And we close by talking about the bond markets reaction to the new Fed Chair announcement.Thank you to Truework, the one verification solution to replace in-house waterfalls. Verify any borrower with a VOIE solution that automates the entire process to quickly deliver the most accurate and complete reports with broad GSE coverage.
Everybody knows about March 15 and the drop in maximum public TLS certificate term to 200 days. But that only scratches the surface on key dates with this maximum term reduction. Join us as we go over "all the dates" for TLS maximum term reduction.
Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security.In this episode of Secure IT, host Jason Kikta is joined by Mark Cooper, CEO and founder of PKI Solutions, to unpack why PKI is so critical to identity, authentication, and trust, and what happens when it fails.They explore how certificates enable passwordless authentication, secure TLS connections, IoT devices, endpoints, and enterprise systems, while also examining why misconfigured or poorly monitored PKI environments often become an attacker's fastest path to privilege escalation. From certificate expirations and operational outages to real-world breach scenarios and pen test failures, this conversation maps the full PKI risk spectrum.Jason and Mark also challenge a common assumption in cybersecurity: that recovery equals resilience. Instead, they argue that true resilience means staying secure and operational, even during misconfiguration, failure, or attack.Whether you're new to PKI or responsible for running it, this episode will change how you think about identity infrastructure, resilience, and trust.Topics covered:- What PKI is and why most organizations already depend on it- Certificates, passwordless authentication, and digital identity- How PKI misconfigurations enable high-impact attacks- Why recovery is the weakest form of resilience- The hidden operational and security risks of foundational systems
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
DLLs & TLS Callbacks As a follow-up to last week's diary about DLL Entrypoints, Didier is looking at TLS ( Thread Local Storage ) and how it can be abused. https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580 FreeBSD Remote code execution via ND6 Router Advertisements A critical vulnerability in FreeBSD allows for remote code execution. But an attacker must be on the same network. https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc NIST Time Server Problems The atomic ensemble time scale at the NIST Boulder campus has failed due to a prolonged utility power outage. One impact is that the Boulder Internet Time Services no longer have an accurate time reference. https://tf.nist.gov/tf-cgi/servers.cgi https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I
In the final show of 2025, Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: React2Shell attacks continue, surprising no one The unholy combination of OAuth consent phishing, social engineering and Azure CLI Venezuela's state oil firm gets ransomware'd, blames US… but what if it really is a US cyber op?! Russian junk-hacktivist gets indicted for cybering critical… err… a car wash and a fountain Microsoft finally turns RC4 off by default in Active Directory Kerberos Traefik's TLS verify=on … turns it off, whoopsie
This week, Jake and Travis sit down with journalist Will Sommer to unpack his investigation into the New Age wellness empire selling stacks of glowing TV monitors as a cure‑all. Jason Shurka, the brains behind the multi-million dollar operation, used the funds to bankroll a brand new streaming platform, Unifyd TV, whose offerings include documentaries made by QAnon promoters. According to the promoters of this quack cure, their work is approved by a secret society of powerful entities who are dedicated to elevating humankind called “The Light Systems” cabal or “TLS.” One member of The Light Systems, a figure called “Ray,” is regularly filmed while wearing a face-concealing hoodie and gloves in order to preserve his anonymity in interviews with Shurka available on Unifyd TV. It's a lot. Just listen to the episode. Subscribe for $5 a month to get all the premium episodes: www.patreon.com/qaa Will Sommer https://bsky.app/profile/willsommer.bsky.social How a Bizarre Healing-TV-Screen Tycoon Is Funding MAGA Media https://www.thebulwark.com/p/bizarre-healing-tv-screen-tycoon-funding-maga-media-unifyd-eesystem The first two episodes of Annie Kelly's new podcast miniseries “Truly, Tradly, Deeply” will be released on the Cursed Media podcast network on the 29th of October. https://www.cursedmedia.net/ Cursed Media subscribers also get access to every episode of every QAA miniseries we produced, including Manclan by Julian Feeld and Annie Kelly, Trickle Down by Travis View, The Spectral Voyager by Jake Rockatansky and Brad Abrahams, and Perverts by Julian Feeld and Liv Agar. Plus, Cursed Media subscribers will get access to at least three new exclusive podcast miniseries every year. https://www.cursedmedia.net/ Editing by Corey Klotz. Theme by Nick Sena. Additional music by Pontus Berghe. Theme Vocals by THEY/LIVE (instagram.com/theyylivve / sptfy.com/QrDm). Cover Art by Pedro Correa: (pedrocorrea.com) qaapodcast.com QAA was known as the QAnon Anonymous podcast.