Caitlin Condon

@catc0n@infosec.exchange
1.2K Followers
671 Following
774 Posts
Adventurer. Takes a lot of photos, calls many places home. Previously vulnerability research director @ Rapid7 + @metasploit. Opinions mine, etc. She/her.
Websitecaitlincondon.com
Techmeme (@Techmeme@techhub.social)

Abridge, which uses AI to automate doctors' note-taking, raised $300M led by a16z at a $5.3B valuation, after raising $250M at a $2.75B valuation in February (Belle Lin/Wall Street Journal) https://www.wsj.com/articles/abridge-whose-ai-app-takes-notes-for-doctors-valued-at-5-3-billion-at-funding-801825f3?st=Xqhhtg&reflink=desktopwebshare_permalink http://www.techmeme.com/250624/p10#a250624p10

TechHub

“One particularly acute example is in Louisiana. A Meta data center under development in the northeastern corner of the state is projected to use, by our calculations, twice as much energy as the city of New Orleans.

Entergy, the regional monopoly utility, is proposing to build more than US$3 billion worth of new gas-fired power plants and delivery infrastructure to meet the data center’s energy demand. Rather than billing Meta directly for these costs, Entergy is proposing to include the costs in rates paid by all customers.”

https://newsie.social/@TheConversationUS/114736013470787522

The Conversation U.S. (@TheConversationUS@newsie.social)

Big Tech’s AI boom is spiking power demand – and you could be paying for it. Utilities are striking secret deals with Big Tech to power data centers, pushing billions in costs onto regular ratepayers. Harvard research reveals how the public is subsidizing it: https://theconversation.com/how-your-electric-bill-may-be-paying-for-big-data-centers-energy-use-257794

Newsie

The libxml2 maintainer is no longer accepting embargoed security reports. They just get treated like regular issues.

This bit in a comment on the announcement really resonates with me:

> these companies make billions of profits and refuse to pay back their technical debt, either by switching to better solutions, developing their own or by trying to improve libxml2.

Too often a company will depend on some library, and then when there are issues with it, shame the maintainer into fixing them. "There's a problem with your project, it is your responsibility to fix it".

No.

You chose to build on top of this library, and with that took on all responsibility that comes with that choice. Any tech debt or bugs are now YOUR tech debt and bugs. What are you going to do about them?

https://gitlab.gnome.org/GNOME/libxml2/-/issues/913

Triaging security issues reported by third parties (#913) · Issues · GNOME / libxml2 · GitLab

I have to spend several hours each week dealing with security issues reported by third parties. Most of these issues aren't critical but it's still a lot of...

GitLab

libxslt project maintainer steps down, citing the amount of time it takes to triage embargoed security issues.

“I’ve been doing this long enough to know that most of the secrecy around security issues is just theater. All the ‘best practices’ like OpenSSF Scorecards are just an attempt by big tech companies to guilt trip OSS maintainers and make them work for free.”

https://gitlab.gnome.org/GNOME/libxml2/-/issues/913

Triaging security issues reported by third parties (#913) · Issues · GNOME / libxml2 · GitLab

I have to spend several hours each week dealing with security issues reported by third parties. Most of these issues aren't critical but it's still a lot of...

GitLab
Dear Entire World:
We're sorry. Most of us, anyway. So fucking sorry.
Remedies for jet lag parts 2 and 3

'Meredith,' some guys ask, 'why won't you shove AI into Signal?'

Because we love privacy, and we love you, and this shit is predictable and unacceptable. Use Signal ❤️

I don't know why, but it's endlessly amusing to me that "wanton noodles" is a popular (and fucking delicious) dish in Singapore. These noodles ain't demure or mindful, they're here to sex it up!
Eight-foot-tall ‘Dictator Approved’ sculpture appears on National Mall https://archive.is/Eeiu1
@TheOldGuy oh my god, HEROES
×
Remedies for jet lag part 1
Remedies for jet lag parts 2 and 3