
Привет! Я Арина Сокова, аналитик в Авито Подработке. Мы отвечаем за то, чтобы смены на платформе закрывались, исполнители и заказчики находили друг друга, а платформа не тратила на продвижение сервиса слишком много. В статье расскажу, что такое субсидии в Авито Подработке, и как мы перешли от ручного назначения субсидий по бизнес-правилам к автоматической системе.
Текст будет полезен аналитикам и продакт-менеджерам, которые работают с ценообразованием, субсидиями, промомеханиками и любыми задачами оптимизации бюджета при ограничениях.
Читать далееWinds of more than 80mph, severe flooding and tornadoes swept through Indiana, Ohio, Illinois and Kentucky
Powerful storms swept across the midwest on Tuesday, leaving three dead and more than 800,000 without power in four states as winds gusts of more than 80mph (130km/h) tore down trees and power lines.
In Indiana, a four-year-old child died after a tree fell on his home in Geneva Township and a person died in a suspected weather-related house explosion in Portage, a city about 30 miles south-east of Chicago.
Continue reading...Winds of more than 80mph, severe flooding and tornadoes swept through Indiana, Ohio, Illinois and Kentucky
Powerful storms swept across the midwest on Tuesday, leaving three dead and more than 800,000 without power in four states as winds gusts of more than 80mph (130km/h) tore down trees and power lines.
In Indiana, a four-year-old child died after a tree fell on his home in Geneva Township and a person died in a suspected weather-related house explosion in Portage, a city about 30 miles south-east of Chicago.
Continue reading...
Какая формула из мира физики самая популярная вне этой науки? Конечно же это легендарная E=mc². Её можно увидеть и на чехлах для смартфонов, и на чашечках с кофе, где расшифровка выглядит совсем не-физически, и даже в каких-то мутных околонаучных трудах, когда всё утрируется до элементарного и ей подкрепляется, что любой объект есть энергия. Даже в рекламе кое-какого напитка её использовали, потому можно с уверенностью утверждать об огромной популярности соотношения среди самых разных людей и отличающихся уровней знания.
Читать далее
Dr. Raj Panjabi founded Last Mile Health to bring healthcare to people living in remote areas. The group is the 2026 recipient of the Conrad N. Hilton Humanitarian Prize.
(Image credit: Last Mile Health)

Собрал шесть AI-сервисов, которыми сейчас можно пользоваться бесплатно или с крупными стартовыми кредитами: FLUX 3 для генерации видео, Manus, Postman Agent Mode, Claude через API, Atomesus и Deepgram с $200 на Voice AI. Проверил регистрацию и условия на своих аккаунтах, добавил скриншоты и короткие инструкции. Актуально на 12 августа 2026 года.
Читать далееVice-chancellor Deborah Prentice says she recognises the ‘difficult case’ has damaged the university
Cambridge University’s leadership has bowed to internal pressure for an independent investigation into its appointment of Jason Arday as a professor, with its vice-chancellor admitting the affair has damaged the institution.
Prof Deborah Prentice said she recognised the “anger and anxiety around this damaging and difficult case” but described it as an aberration that should not be used to cast aspersions on the abilities of its staff of colour.
Continue reading...After her defiant femininity outraged many in Brazil, she lived through a military dictatorship and was boycotted for years. But after more than 30 albums, she explains how she kept going
At 78, Joyce Moreno is one of Brazil’s musical icons, but for decades that status seemed far from assured: this headstrong singer, guitarist and composer was frequently viewed as a threat by her country’s establishment. Aged 19, the reaction to her song Me Disseram – which began “I was told my man didn’t love me” – almost torpedoed her career before it even started. “I’d often heard the expression ‘my man’ sung by Billie Holiday and Edith Piaf, so for me it was normal,” she says. “But I was a beach girl from Ipanema, writing and singing in the first person. People were shocked.”
Then, inspired by trailblazing actor Leila Diniz (“her liberal attitudes lost her jobs”), Moreno refused requests that she “dress like a sexy bimbo”, and endured male critics who thought her music “too good to have been written by a woman”. When, in 1980, she discovered that her label had given another female singer the blueprints for songs she had written, she “looked for a lawyer, of course” and successfully sued; in her memoir she claims she was then boycotted by Brazil’s major record companies for a decade.
Continue reading...Investigators believe Vikings and Hells Angels members involved in violence that preceded death of Brecon man
A man was killed in what is believed to have been a violent brawl between rival motorcycle gangs in the south Wales valleys, police have said.
Anthony “Tony” Jones, 56, of Brecon, died of his injuries in hospital after the violence in Pontnewynydd, near Pontypool, last Thursday evening, which reportedly involved knives and hammers.
Continue reading...
Dr. Raj Panjabi founded Last Mile Health to bring healthcare to people living in remote areas. The group is the 2026 recipient of the Conrad H. Hilton Humanitarian Prize.
(Image credit: Last Mile Health)

Let’s Encrypt всегда проверял только доменные имена. Однако с развитием микросервисных архитектур, API-взаимодействий и IoT-устройств возникла необходимость защищать трафик серверов, у которых нет домена. 15 января 2026 года стал общедоступным профиль shortlived с 6-дневными сертификатами для «чистых» IP-адресов. Теперь не нужно тратить деньги и время на покупку и регистрацию бесполезных доменных имен.
На Хабре уже есть подробные статьи и руководства на тему настройки HTTPS, выпуска сертификатов и конфигурации веб-серверов, но в большинстве случаев они объясняют, как защитить сайт с доменом. Мы же разберём, как обойтись без него и выпустить официальный доверенный TLS-сертификат прямо на «голый» IPv4-адрес.
Читать далееWhatsApp is committed to helping people stay safe while protecting the privacy of their messages. As scam tactics evolve — from impersonation to social engineering to AI-generated lures — we’re always evolving as well, so that our protections stay ahead of scammers while protecting people’s personal messages with end-to-end encryption.
Today, we’re sharing an early look at Scam Alert, a new, optional feature that runs an on-device machine learning model to alert a user about potential scam messages. No message content leaves the device for classification or is auto-reported to WhatsApp, Meta, or anyone else. The feature complements end-to-end encryption while enabling a user-controlled, optional scam alert when the model believes there’s a likely scam.
Before we make this feature available to all WhatsApp users, we are publishing this early technical overview alongside the feature’s limited rollout in Beta, and will continue working with our Bug Bounty community to stress-test this system. To help validate our implementation, we welcome feedback from the broader security research community.
Recent advances in on-device machine learning models make it possible to run accurate text classification entirely on mobile hardware without the performance, battery, or model-size tradeoffs that previously made on-device classification less practical. Scam Alert is well-suited to this approach: The model is small enough to run on-device, simple enough to publish for independent review, and effective without server-side components. The architecture we chose reflects a set of deliberate choices about what this system can and cannot do.
To that end, we designed Scam Alert to meet the following principles that adhere to the core guarantees of end-to-end encryption:
Scam Alert is optional. Once the user turns it on, Scam Alert downloads a machine learning model to the device, where it runs inferences to classify whether incoming messages from non-contacts match known scam patterns. The model is trained on patterns observed in scam conversations from reports that users have sent to us. It performs probabilistic classification based on conversational structure and linguistic signals. No content is automatically reported to WhatsApp, Meta, or any third party.
If the model identifies a message as a likely scam attempt, the user sees a warning in the chat, which is not visible to the other person. From there, the user can decide what to do: block, report, or continue the conversation. If they decide that a warning is incorrectly flagged, the user can mark the chat as trusted, in which case the warning is removed and Scam Alert will not flag that chat again. If a user marks that they trust a chat, they can also opt in to share the last 5 messages received with WhatsApp to help improve the feature’s accuracy.
To uphold the principles above, we designed Scam Alert with the following foundational requirements and safeguards, with each architecturally enforced and independently verifiable by security researchers through an expanded bug bounty program and by users themselves through in-app logs.
The rest of this post details the technical implementation of each requirement.
As referenced above, all inference happens on-device. But we need to know that the feature itself is working – i.e., it is indeed catching real scams – and know if we need to update it to stay ahead of constantly evolving scams and improve the model over time.
To that end, our approach follows a set of data minimization principles. Message content does not leave the device, and logging is limited by design to only the signals that are needed to measure whether the feature is working as intended. Even those signals are processed within a confidential computing environment built on TEEs, which ensures that processing occurs in a secure environment that no one, including Meta and WhatsApp, can access. Our experience building and securing systems like Private Processing has informed the design of this system. Only anonymous, differentially private aggregates are made available to Meta and WhatsApp. Differential privacy works by adding carefully calibrated noise to provide a mathematical guarantee that adding or removing any single person’s data has a negligible effect on the anonymous, aggregated numbers. Hence these aggregates show how the feature performs across the population while telling us nothing about any individual.
For Scam Alert, that data is limited to two categories of approximate, aggregate counts:
To anonymize these warning and user action counts, we built a confidential federated analytics pipeline designed around the following privacy and security guarantees, each architecturally enforced and externally verifiable:
The foundations of this pipeline were established in Meta’s peer-reviewed federated analytics work, publicly outlined in “PAPAYA Federated Analytics Stack: Engineering Privacy, Scalability and Practicality” (USENIX NSDI 2025). Here, we describe how Scam Alert applies and extends that foundation.
The pipeline works as follows:
The confidential federated analytics pipeline is built so that, by the time any totals reach WhatsApp, the counts have been aggregated across many users and had differential privacy noise added – so we only ever see approximate counts of how many warnings were shown and how many were acted on. We will not know what the messages was, who sent or received them, or which conversation triggered a warning.

This confidential federated analytics pipeline operates in a highly adversarial environment. Our threat model accounts for three categories of attacker: third-party or supply chain vendors with access to system components, malicious or compromised insiders with access to infrastructure, and external actors attempting to exploit the pipeline’s attack surface.
Data in transit is encrypted between the device and the TEE and routed through a third-party OHTTP relay. The relay’s role is limited to stripping the client’s IP address – it cannot decrypt, inspect, or modify the data itself. Because this data is already not visible to the third-party, a compromised relay cannot access the data or associate datasets with a specific user. During processing, data is protected by TEE code isolation, with entry points limited to a small set of reviewed components.
The TEE prohibits remote shell access, including from the host machine. Neither Meta engineers nor networked systems can gain access to the CVM shell at runtime. Software is built exclusively from checked-in source code and artifacts, where any change requires multiple engineers to modify the build artifacts or build pipeline. All code changes are auditable, enabling both continuous internal audits and external security researchers to inspect our binaries. Unaggregated data is never readable outside the TEE; when stored, it is encrypted under keys released only to a TEE running the same attested binary, and retained only for a bounded period before being merged into running aggregates and discarded.
Because TEE guarantees are not absolute, we apply defense-in-depth: encrypted DRAM, CVM hardening, enhanced host monitoring, and OHTTP relay routing that prevents directing a specific user’s data to a specific machine. A targeted attack would require compromising the entire system in a way that is publicly discoverable through verifiable transparency.
The model is downloaded from a CDN, not hardcoded into the app, so that improvements in accuracy and coverage of emerging scam tactics can reach people without requiring a forced app upgrade. And to that end, we are also ensuring that there is no path to deliver a different model to a specific user.
Every model version — including its SHA-256 hash — is published on a third-party append-only transparency ledger before it is served to anyone. An append-only ledger is a public log where entries can be added but never modified or deleted, ensuring a tamper-evident history that researchers can inspect.
We designed the model download system around three guarantees:
Before rolling out a new model version globally, we must evaluate its accuracy and effectiveness by testing model variants with subsets of users. This experimentation must not create a path for targeting (ie delivering a specific model to a specific user). The model download flow is designed to prevent this:
Because the entire verification and experimentation flow runs on the client, security researchers can examine the app binary to confirm these checks are performed.

We outlined above how neither Meta nor WhatsApp can deliver a specific model to a specific user, and how the confidential federated analytics pipeline preserves privacy. But neither answers a more fundamental question: how can anyone verify that the model is built only to identify potential scam messages, unless its behavior can be independently examined?
We designed the model verification system around two guarantees:
We will be expanding our Bug Bounty scope to include the models to test them against their own inputs, analyze their behavior across a range of scenarios, and report any findings where the model deviates from its declared purpose or where its capabilities can be systematically evaded.
The confidential federated analytics pipeline ensures that even the act of measuring model performance protects user privacy. The transparency ledger and third-party signing ensure that every model we ship is publicly recorded and tamper-evident. And published model artifacts, client-side transparency logs, and a dedicated Bug Bounty program ensure that what the model does can be independently verified.
As mentioned above, this feature is only beginning to roll out in a limited Beta capacity. We will continue iterating and improving on it during the Beta phase before production, but we wanted to take this opportunity to outline our principles.
Scammers will continue to evolve their tactics. To keep staying ahead of them, so will we.
We welcome feedback from users, security researchers, and the broader security community through our security research program: Contact us.
Thank you to Ronald Anthony, Shafin Anwarsha, Samyukta Mogily, Lenny Grokop, Riccardo Tortul, Harish Srinivas, Kiran Teja Tummuri, Roman Dashchakivskyi, Chao Zhang, Jitendra Mohanty, and the many others across the company who helped make Scam Alert possible.
The post How We’re Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees appeared first on Engineering at Meta.

Или как один лотерейный билет превратился в несколько сотен требований, десятки интеграций и пять месяцев Discovery.
Когда мне предложили заняться разработкой с нуля цифрового сервиса Альфа‑Мании, я была уверена, что понимаю задачу. Что может быть проще? Клиент открывает мобильное приложение банка, выбирает лотерейный билет, оплачивает его, ждет розыгрыш и, если цифры в лотерейном билете совпали — получает выигрыш. На первый взгляд всё выглядело как вполне стандартный цифровой продукт: несколько экранов мобильного приложения, интеграция с партнером, немного аналитики, немного CRM‑коммуникаций и привычная продуктовая работа.
Я никогда так не ошибалась.
Через несколько месяцев я уже обсуждала особенности прогрессивной шкалы НДФЛ, разбиралась в требованиях к онлайн‑кассам, участвовала в проработке процессов идентификации победителей и спорила с коллегами о трактовке отдельных пунктов законодательства о лотереях.
При этом ТЗ всё ещё не было.
Наверное, это первый проект в моей карьере, где мы сознательно не писали бизнес‑требования почти пять месяцев. Но не потому что не успевали или не хватало ресурсов, и уж точно не потому что не умели писать BRD. Просто довольно быстро стало понятно, что писать требования к тому, чего ты сам пока не понимаешь — самый быстрый способ построить неправильный продукт. Поэтому вместо того, чтобы открывать шаблон BRD, мы начали исследования.
Именно тогда я поняла, что самые сложные продукты начинаются не тогда, когда команда не знает решения, а тогда, когда она практически ничего не знает про предметную область. Об этом я и расскажу. Эта статья про discovery. Про исследования, важность которых часто недооценивается.
Читать далееLabour chair says Reform deputy leader is trying to harass journalists over reporting on his financial affairs
Richard Tice has been accused by Labour’s Bridget Phillipson of mounting a “deeply chilling attempt to silence the free press” after he sent a legal threat to the Guardian over its reporting on his financial affairs.
Lawyers for Tice, the deputy leader of Reform UK, singled out a Guardian correspondent for her journalism about a series of Tice’s financial transactions that were referred to the National Crime Agency.
Continue reading...Бывает так: есть фулстек проект, и в нём всё хорошо. Откуда-то есть сквозные типы (tRPC, генерация из OpenAPI), есть авторизация, есть основной функционал. А потом вы решаете добавить реалтайм: уведомление о новом посте в ленте, чат между пользователями, интерактивную доску. И появляется целый новый слой абстракций, в котором надо заново изобрести всё, что в проекте уже есть, только на новый лад. И дальше поддерживать две разные системы.
В своём фреймворке Point0 я добавил четыре новых реалтайм-поинта (структурные единицы наравне со страницами, лэйаутами, квери, мутациями): канал, спейс, клиентский хэндлер, серверный хэндлер. На них собирается практически любая реалтайм-функциональность, кода получается мало, и читается он интуитивно. Эти поинты несут те же свойства, что и все остальные:
код сервера и клиента живут в одном файле, компилятор вырезает клиентский код из серверной сборки, а серверный из клиентской
типизация сквозная и выводится из дженериков самого фреймворка, без генерации типов
Под катом покажу на примерах, как это работает, и объясню суть парадигмы, чтобы вы могли собрать любое реалтайм-приложение.
Читать далееThe Guardian’s picture editors select photographs from around the world
Continue reading...
Маск анонсировал проект орбитальных ИИ-дата-центров под скромным названием AI Sat Mini. Заявленная цель — вывод 100 ГВт компьюта (вычислительной мощности) в год, что потребует вывода на орбиту тысяч тяжелых спутников. Это крайне затратный процесс, поэтому предлагается перенести сборку на Луну и отправлять аппараты на орбиту с помощью электромагнитной катапульты: низкая гравитация и отсутствие атмосферы кратно упрощают запуск.
Однако производство современных чипов на Луне невозможно. Нанолитография требует сверхчистых стерильных сред, бесперебойных поставок редких химических реагентов и колоссальных объемов очищенной воды. Производственная цепочка распределена по миру и жизнеспособна только когда миллиардный глобальный спрос окупает триллионные затраты на полупроводниковые фабрики. Попытка перенести процесс на Луну приведет к экономическому коллапсу.
Однако для всей идеи это не приговор. Да, вычислительные чипы важны, но они составляют малую часть от общей массы. Основной вес аппарата приходится на силовые каркасы, радиаторы охлаждения и солнечные панели. Их конструкция относительно проста, а значит, плавить лунный реголит для отливки корпусов и раскатывать подложки панелей можно прямо на месте, доставляя остальные компоненты с Земли для финальной сборки.
Здесь возникает главный вопрос: насколько вообще реалистичен такой подход и есть ли в нем практический смысл, если разделить производство на лунную и земную части?
Этому вопросу и посвящен цикл статей. В нем мы последовательно разберем ключевые узлы спутниковой платформы. Начнем с солнечных панелей — основного источника энергии. Затем рассмотрим радиаторы охлаждения, силовой корпус, гиродины для ориентации, двигательную установку и другие системы.
Читать далее
J1939 это высокоуровневый проприетарный протокол используемый поверх CAN. Появился в середине 198х годов. Этот протокол работает в груpовых автомобилях: автобусы, грузовики, самосвалы, фуры, БелАЗы и прочее. Протокол J1939 принципиально не применяется в легковых автомобилях.
В автомобилях много датчиков: напряжения, температуры, давления масла, датчики дальномеры для помощи парковки, радары круиз конторля, давление в шинах. Все эти данные передаются в блок управления двигателем по протоколу J1939.
По J1939 происходит управление трансмиссией, генератором, двигатели, форсунками, тормозами и прочим.
Читать далее
В предыдущих постах мы подробно разбирали каждый слой: CPU, арифметику, скриптовый интерпретатор, оборудование. Вот, что окончательный отчёт о синтезе Quartus сообщает обо всех них: в готовой архитектуре используется 1593 логические ячейки из доступных в EP2C5 4608 (35% чипа) с 594 выделенными логическими регистрами и 17 блоками памяти M4K. Сам модуль CPU занимает 1173 из этих логических ячеек и 400 регистров. Остальная логика отдана периферии: драйверу ЖК‑дисплея (154 логические ячейки), сканеру клавиатуры (97), интерфейсу термопринтера (64), таймеру CTC (49) и аппаратному PRNG (20). 12 блоков памяти M4K занимает ROM микрокода (49152 бит: это полная программа калькулятора), 2 блока — ROM скриптинга (8192 бита), 1 — ROM BCD‑констант, 1 — таблица поиска для BCD‑умножения внутри CPU и 1 блок — ОЗУ. Меня это очень радует: полнофункциональный научный калькулятор уместился в 35% небольшой дешёвой FPGA.
Читать далее