Otmar Lendl

216 Followers
74 Following
416 Posts

ISP veteran.
Built up CERT.at.
National and international CSIRT liaison for CERT.at

Private Blog is here: https://lendl.priv.at

Websitehttps://lendl.priv.at/

Advice from the UK: keeping code secret will not really save you from LLM-powered vulnerability search.

https://www.gov.uk/guidance/ai-open-code-and-vulnerability-risk-in-the-public-sector

AI, open code and vulnerability risk in the public sector

Guidance for safely publishing source code in the open, and reducing the risk of AI-accelerated vulnerability discovery.

GOV.UK
Yesterday I attended the first Democratic Tech Alliance (DTA) Assembly over at the European Parliament. The DTA is a political/think tank/civil society/industry initiative that hopes to foster a tech-ecosystem on which we can continue to run our European democracies. Because it is not looking good. Useful progress was made, and here is what I learned: https://berthub.eu/articles/posts/democratic-tech-alliance-may-2026/
The First Democratic Tech Alliance Assembly - Bert Hubert's writings

Yesterday I attended the first assembly of the Democratic Tech Alliance (DTA), which gathered in the European Parliament. Membership of the alliance includes European political groups like the Greens/EFA, the liberal/center right Renew Europe, the European People’s Party of Christian democratic, conservative and liberal-conservative persuasion and also the Progressive Alliance of Socialists and Democrats. This is a broad, quite sane and actually impressive collection of political groups, which gives me some hope.

Bert Hubert's writings
Anne Applebaum in Vienna: a speech worth reading: https://www.festwochen.at/en/a-speech-to-europe-2026-text
A Speech to Europe 2026 – Anne Applebaum

Read the full Speech to Europe 2026 by Anne Applebaum with the title `The European Moment´, held on 13 May 2026 at Judenplatz, Vienna.

Wiener Festwochen

@EUCommission the only way to enforce age verification of minors is through total internet supervision of everybody. And it won't help with any of the problems on the internet, because facilitating and effectively rewarding terrible behaviour optimises the revenue of the main players.

If you want a better internet, step one is to ban behaviour-based profiling for advertising, with no "consent" loophole. It makes surveillance ("tracking cookies") immediately illegal (no "legitimate interest" excuse, GDPR does the rest). That trashes the direct "more bullying and hate leads to greater revenue" connection, which immediately removes the incentive to put active effort into more vicious online spaces. This applies to Google, Meta, X, Reddit, etc.

Note that the "consent is not an excuse" part is critical. "Ask me later" just means that people are worn down into clicking "yes" eventually, just to get it out of the way, you know yourself the dark patterns, you know yourself the cookie consent forms, where "none of them" is tedious and must be repeated on every visit, but "yes please" is simple and eternal. Try changing that decision later.

Ban the surveillance. Yes, it's many companies' entire business model. That's too bad for them, should have tried being socially positive. Yes, many services will have to start some sort of subscription or pay per use model instead of being fake-free. That's OK, they'll also be disincentivised to enshittify.

It'd make the internet better for everyone, including children, who could continue to find and create so many positive communities online, instead of being blanket-banned.

The Boring Internet

The internet you grew up on isn't dying. A commercial veneer glued on top of it is. A visual essay about what actually persists.

Terry Godier
Everything Is Broken

Once upon a time, a friend of mine accidentally took over thousands of computers. He had found a vulnerability in a piece of software and…

Medium

I'm endlessly confused by the wave of legislation to ban children from accessing social media, rather than banning social media companies from harming children.

And yes I know Free Speech but now we know that we can torture and sicken people, including kids, in this medium. Some of the things we currently call Free Speech turn out to be poison, mental control, and torture.

At some point we have to separate the "innovation" from the digital lead and asbestos tech companies are feeding people.

I just read https://philpapers.org/rec/LERTAF

I have a really hard time reading philosophical reasoning. Nevertheless, for me, there are a number of red flags in the text. I cannot support the conclusion of the author.

What do you all think?

Alexander Lerchner, The Abstraction Fallacy: Why AI Can Simulate But Not Instantiate Consciousness - PhilPapers

Computational functionalism dominates current debates on AI consciousness. This is the hypothesis that subjective experience emerges entirely from abstract causal topology, regardless of the underlying physical substrate. We argue this view ...

Aktuelle Neuigkeiten: LLM-basierte Schwachstellensuche
https://www.cert.at/de/aktuelles/2026/4/llm-basierte-schwachstellensuche
CERT.at - Show

Triggered by reading my slides from last year:

What happened with the minerals deal that Trump so desperately wanted from Ukraine last year?