https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
3,009 karma · joined August 24, 2009
https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
And even if their internet service provider is uniquely capable for now, it only fills a strategic need for certain customers.
So instead, Musk and Co. need to find bubbling market trends that look like they will have huge gigantic TAMs to justify the potential growth of this company.
OpenAI and Anthropic may have gone silent on how they build their models, but other companies have different incentives.
Relevant parts for those who have cool-downs at the top of mind:
> Across Homebrew’s history far more users have been protected by shipping zero-day fixes quickly than have been exposed to npm-style token-theft or crypto-mining attacks, so a global cooldown would be a net negative for most users’ security. The deeper reason Homebrew does not need a general cooldown is that, unlike language package managers, it already separates publishing from distribution: an upstream release does not reach users until it has passed human review, CI and checksum verification, which is the very review window that language-ecosystem cooldowns are trying to recreate.
[...]
> For ecosystems with a track record of fast-moving supply-side attacks, Homebrew applies a download cooldown: a freshly-published upstream version is not adopted immediately, giving the wider community time to detect and report a malicious release before Homebrew users are exposed. Cooldowns have been added for:
Bundler
RubyGems livecheck
npm and pip defaults
PyPI resource resolution
npm and PyPI in bumpTo put it neutrally, VC partners are treating these are parts of their same portfolios, so if one team doesn't pan out on its own, it can be merged into another with somewhat similar overall goals or markets.
To put it more pointedly, it's perhaps all about who one knows and making sure that everyone gets to tell a story of successful exits.
Security researchers identified a series of exploitable vulnerabilities in github.com by using LLMs to review the compiled GitHub Enterprise Server binaries: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-38...
For better or worse, it's an acquihire.
The number of intermediaries that some customers, especially governmental agencies, go through to get just an Azure bill can be wild...
Great for summarizing a multi-step process and quick to render with simple tools.
grith.ai appears to be in the business of guiding you click a "request early access" button so they can eventually sell you software (or so they can pitch seed investors on the length of their list of prospects)
Again, I'm not criticizing. Just pointing out a pattern that's becoming pretty common on HN, especially for stories about vulnerabilities written up by companies selling cybersecurity solutions or services.
Don't get me wrong. This post is an interesting read. But the company publishing it appears to have nothing to do with the exploit or the people who discovered or patched it.
I tip my hat at their successfully marketing :)
If this were a news outline writing "Department of War" I would be concerned. But in the case of the Anthropic CEO's blog post, I can understand why they are picking their fights.
> Charged with regulating stationary sources of air pollution emissions, the Air District drafted its first two regulations in the 1950s: Regulation 1, which banned open burning at dumps and wrecking yards, and Regulation 2, which established controls on dust, droplets, and combustion gases from certain industrial sources.
> Much research and discussion went into the shaping of Regulation 2, but there was no doubt about the need for it. During a fact-finding visit to one particular facility, Air District engineers discovered that filters were used over air in-take vents to protect the plant's machinery from its own corrosive emissions! This much-debated regulation was finally adopted in 1960.
https://www.baaqmd.gov/en/about-the-air-district/history-of-...
> It's not a lack of knowledge by Caltrans or Santa Clara County's congestion management agency that is keeping that interchange as-is. Rather, it's the physical constraints of a nearby airport (so no room for flyovers), a nearby river (so probably no tunneling), and surrounding private landowners and train tracks.
The most recent budget estimate is $1bn for any changes to this interchange
Where Google/Apple's coverage is quite valuable is for near-real-time speeds for atypical events -- say like yesterday's Super Bowl. But that's not what this blog post is about -- this post is about a well-established pattern that can be identified with historical datasets.
All that to say that vendors sell a wide variety of data products to transportation planners, but just because Google is now entering this niche market doesn't mean they'll be "the best" or even realize what their strengths are.
This research team used Google's first-party location data to identify San Jose's Interstate 880/US 101 interchange as a site with statistically extreme amounts of hard braking by Android Auto users.
But you don't need machine learning to know that... San Jose Mercury News readers voted that exact location as the worst interchange in the entire Bay Area in a 2018 reader poll [1]
It's not a lack of knowledge by Caltrans or Santa Clara County's congestion management agency that is keeping that interchange as-is. Rather, it's the physical constraints of a nearby airport (so no room for flyovers), a nearby river (so probably no tunneling), and surrounding private landowners and train tracks.
Leaving aside the specifics of the 880/101 interchange, the Google blog post suggests that they'll use this worst-case scenario on a limited access freeway to inform their future machine-learning analyses of other roads around the country, including ones where presumably there are also pedestrians and cyclists.
No doubt some state departments of transportation will line up to buy these new "insights" from Google (forgetting that they actually already buy similar products from TomTom, Inrix, StreetLight, et al.) [2]
While I genuinely see the value in data-informed decision making for transportation and urban planning, it's not a lack of data that's causing problems at this particular freeway intersection. This blog post is an underbaked advertisement.
[1] https://www.mercurynews.com/2018/04/13/101-880-ranks-as-bay-...
[2] https://www.tomtom.com/products/traffic-stats/ https://inrix.com/products/ai-traffic/ https://www.streetlightdata.com/traffic-planning/
FWIW, the team that eventually created "Docker" was working at the same time on dotCloud as a direct Heroku competitor. I remember meeting them at a meet-up in the old Twitter building but couldn't tell you exactly which year that was. Maybe 2010 or 2011?
‘A Recipe for Idiocracy’: What happens when even college students can’t do math anymore?
(The Atlantic, Nov. 2025)
I do have a print subscription to The Atlantic and appreciate some of their coverage, but it's embarrassing how much they're always on the lookout for upper-middle-class panics to milk...
- Their "peer-reviewed model" compares Waymo vehicles against only "Level 0" vehicles. However even my decade-old vehicle is considered "Level 1" because it has an automated emergency braking system. No doubt my Subaru's camera-based EBS performs worse than Waymo's, still it's not being included in their "peer-reviewed model." That comparison is intentionally comparing Waymo performance against the oldest vehicles on the road -- not the majority of cars sold currently.
- This incident happened during school dropoff. There was a double-parked SUV that occluded the view of the student. This crash was the fault of that double-parked driver. But why was the uncrewed Waymo driving at 17 mph to begin with? Do they not have enough situational awareness to slow the f*ck down around dropoff time immediately near an elementary school?
Automotive sensor/control packages are very useful and will be even more useful over time -- but Waymo is intentionally making their current offering look comparatively better than it actually is.
That's probably more relevant to fleet vehicles for construction and maintenance firms than to individuals towing boats. But just to offer an example of how the F150 Lightning is a great fit for certain uses.