๐ช๐ต๐ฎ๐ ๐ฎ๐ฟ๐ฒ ๐ข๐๐๐๐ต ๐ฎ.๐ฌ, ๐ข๐ฝ๐ฒ๐ป ๐๐ ๐๐ผ๐ป๐ป๐ฒ๐ฐ๐, ๐๐ฆ๐ข๐ก ๐ช๐ฒ๐ฏ ๐๐ผ๐ธ๐ฒ๐ป๐, ๐ฎ๐ป๐ฑ ๐ฆ๐๐ ๐?
When explaining various authorization and authentication standards to their peers or management, such as OAuth, OpenID Connect, and SAML, many professionals in the field need help. They understand the concepts and how they're used, but because these protocols are similar, they might need clarification from someone trying to learn about them. All of this is usually called Identity and Access Management (IAM).
First, we have some ๐ฟ๐ฒ๐๐ผ๐๐ฟ๐ฐ๐ฒ ๐ถ๐ป ๐ผ๐๐ฟ ๐๐๐๐๐ฒ๐บ (app, API, etc.) and someone who needs to access that resource (called identity). That someone can be a user or some other software.
Second, we must also understand ๐๐ต๐ฎ๐ ๐ถ๐ ๐ฎ๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐ฎ๐ป๐ฑ ๐๐ต๐ฎ๐ ๐ถ๐ ๐ฎ๐ป ๐ฎ๐๐๐ต๐ผ๐ฟ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป. With authentication, we verify the identity of who needs to access our resources if they are who they claim to be. With authorization, we determine what resources that identity can access.
So, IAM solutions allow us toย ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น ๐ถ๐ฑ๐ฒ๐ป๐๐ถ๐๐ ๐๐ฎ๐น๐ถ๐ฑ๐ฎ๐๐ถ๐ผ๐ป ๐ฎ๐ป๐ฑ ๐ฟ๐ฒ๐๐ผ๐๐ฟ๐ฐ๐ฒ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ ๐๐ผ๐ผ. They define which user information to store and how users must prove their identity. Identity providers create and maintain user identity information and can provide it to other applications. Examples of identity providers are Microsoft AD and Twitter.
Different standards exist, such as:
๐น ๐ข๐๐๐๐ต ๐ฎ.๐ฌ: is an industry-standard that apps use to grant access to client applications. It is commonly used for users to grant websites access to their information on other websites but without giving them the passwords. Amazon, Google, and Microsoft use it to permit users to share info about their accounts with 3rd party apps.
๐น ๐ข๐ฝ๐ฒ๐ป ๐๐ ๐๐ผ๐ป๐ป๐ฒ๐ฐ๐: is a layer on top of OAuth and it adds an extra layer of security by encrypting the connection between the user and the app or site.ย We can use it to enable single sign-on (SSO) between applications using a security token (ID token).
๐น ๐๐ฆ๐ข๐ก ๐ช๐ฒ๐ฏ ๐๐ผ๐ธ๐ฒ๐ป๐: is an open standard to share security information between a client and a server in JSON format. JWT is sent in the HTTP request with a digital signature. It can be signed using a secret or a public/private key pair.
๐น ๐ฆ๐๐ ๐: is an open standard where authorization and authentication information is exchanged between a service provider and an identity provider (in XML format). It was created in 2002, so it's one of the oldest protocols.
In the image, you can see the G2 Grid for IAM.
Check the link in the comments.
#softwareengineering #programming #technology #security #techworldwithmilan
Okta compromisedโฆ again. Hereโs how @Cloudflare, even though we were (again) targeted, was able to mitigate the attack. And some best security practice suggestions for @okta and their customers. https://t.co/E1LYgveKGO
Flexoki is an inky color scheme for prose and code that I created for my personal site. It's now open source.
Flexoki is designed for reading and writing on digital screens. It is inspired by analog printing inks and warm shades of paper.
The name Flexoki comes from flexography โ a common printing process for paper and cardboard. I spent many years working with dyes and inks particularly for my companies Inkodye and Lumi. I also have a fascination with digital paper. I wanted to bring the comfort of analog color to emissive digital screens.
One challenge is that ink on paper is a subtractive process whereas LCD and OLED screens use additive color. Replicating the effect of mixing pigments digitally is difficult.
Mixing blue and yellow paint creates green, whereas digital color mixing results in a brownish hue. Watercolors retain their saturation when you dilute them, whereas reducing the opacity of digital colors makes them look desaturated.
Another challenge with digital color is human perception across color spaces. Ethan Schoonoverโs color scheme Solarized (2011) was an important inspiration for Flexoki. His emphasis on CIELAB lightness relationships helped me understand how to find colors that appear cohesive.
I found that choosing colors with perfect perceptual consistency can be at odds with the distinctiveness of colors in practical applications like syntax highlighting. If you adhere too closely to evenness in perceptual lightness you can end up with a palette that looks washed out and difficult to parse.
Solving for all of these problems is how I arrived at Flexoki. I wish it could have been more science than art, but it wasnโt. Some day, I hope to arrive at a more reliable way to generate digital color palettes that respect the constraints I laid out. In the meantime, I hope you find this iteration of Flexoki useful.
This is going to change databases!
There are 1.7 million deployments of PostgreSQL worldwide. This makes it one of the world's most popular relational database management systems.
The team behind @postgresml reached out to me and showed me their open-source extension, PostgresML.
It's pretty cool!
You can use this extension to train a model on text and tabular data using SQL queries.
This example trains a model using XGBoost using a query!
select * from pgml.train('Handwritten Digit Image Classifier',
algorithm => 'xgboost',
'classification',
'pgml.digits',
'target'
);
The extension integrates Hugging Face ๐ค Transformers. You can use it to run NLP models right into the database.
Here is an example to determine the sentiment of some text:
select pgml.transform(
task => 'text-classification',
inputs => ARRAY[
'This product didn't work for our family.',
'This has been the best purchase of the year!'
]
) as positivity;
I had never seen this before.
You can train and run supervised and unsupervised algorithms. You can run pre-trained models. Machine Learning and AI right at the database level!
Here is the GitHub repository: https://t.co/WOmAy6DE55
This post is sponsored by @postgresml and their fully managed cloud service. You can use them in addition to their open-source library. Horizontal scalability and support for JavaScript, Python, and Rust.
Machine learning is now getting everywhere.
How long before this is part of every database management system out there?
Here's the most effective GPT-4 prompt I've developed for writing tasks.
It's like having a professional editor by your side.
Use it to enhance the clarity and readability of your writing:
---
Given some text, make it clearer.
Do not rewrite it entirely. Just make it clearer and more readable.
Take care to emulate the original text's tone, style, and meaning.
Approach it like an editor โ not a rewriter.
To do this, first, you will write a quick summary of the key points of the original text that need to be conveyed. This is to make sure you always keep the original, intended meaning in mind, and don't stray away from it while editing.
Then, you will write a new draft. Next, you will evaluate the draft, and reflect on how it can be improved.
Then, write another draft, and do the same reflection process.
Then, do this one more time.
After writing the three drafts, with all of the revisions so far in mind, write your final, best draft.
Do so in this format:
===
# Meaning
$meaning_bulleted_summary
# Round 1
## Draft
``$draft_1``
## Reflection
``$reflection_1``
# Round 2
## Draft
``$draft_2``
## Reflection
``$reflection_2``
# Round 3
## Draft
``$draft_3``
## Reflection
``$reflection_3``
# Final Draft
``$final_draft``
===
To improve your text, you'll need to go through three rounds of writing and reflection. For each round, write a draft, evaluate it, and then reflect on how it could be improved. Once you've done this three times, you'll have your final, best draft.
---
Netflix's Tech Stack.
This post is based on research from many Netflix engineering blogs and open-source projects. If you come across any inaccuracies, please feel free to inform us.
Mobile and web: Netflix has adopted Swift and Kotlin to build native mobile apps. For its web application, it uses React.
Frontend/server communication: GraphQL.
Backend services: Netflix relies on ZUUL, Eureka, the Spring Boot framework, and other technologies.
Databases: Netflix utilizes EV cache, Cassandra, CockroachDB, and other databases.
Messaging/streaming: Netflix employs Apache Kafka and Fink for messaging and streaming purposes.
Video storage: Netflix uses S3 and Open Connect for video storage.
Data processing: Netflix utilizes Flink and Spark for data processing, which is then visualized using Tableau. Redshift is used for processing structured data warehouse information.
CI/CD: Netflix employs various tools such as JIRA, Confluence, PagerDuty, Jenkins, Gradle, Chaos Monkey, Spinnaker, Altas, and more for CI/CD processes.
โ-
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/uc5M7CdXXC
๐๐ฃ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ต๐ฒ๐ฐ๐ธ๐น๐ถ๐๐
Checklist the most critical security countermeasures when designing, testing, and releasing your API.
Full link in the comments.
_____
If you like my posts, please follow me, @milan_milanovic, and hit the ๐ on my profile to get a notification for all my new posts.
Learn something new every day ๐!
#api #security #apidesign #softwareengineering #programming
VS Code and Postman are no longer adjacent tools, theyโre now fully integrated!
The long-awaited VS Code extension from Postman has been released.
You can now develop and test your APIs without leaving your code editor.
Check it out: https://t.co/t44pZUe74E
From VMs to containers and then back to (micro)VMs ๐ง
Finally, a working Firecracker tutorial:
- Build a VM rootfs
- Get a Linux Kernel
- Add an init system
- Build a disk image
- Configure networking
- Start a Firecracker microVM
Thanks, @alexellisuk!
https://t.co/KpO0UiKy7A
How is data transmitted between applications?
The diagram below shows how a server sends data to another server.
Assume a chat application running in the user space sends out a chat message. The message is sent to the send buffer in the kernel space. The data then goes through the network stack and is wrapped with a TCP header, an IP header, and a MAC header. The data also goes through qdisc (Queueing Disciplines) for flow control. Then the data is sent to the NIC (Network Interface Card) via a ring buffer.
The data is sent to the internet via NIC. After many hops among routers and switches, the data arrives at the NIC of the receiving server.
The NIC of the receiving server puts the data in the ring buffer and sends a hard interrupt to the CPU. The CPU sends a soft interrupt so that ksoftirqd receives data from the ring buffer. Then the data is unwrapped through the data link layer, network layer and transport layer. Eventually, the data (chat message) is copied to the user space and reaches the chat application on the receiving side.
Over to you: What happens when the ring buffer is full? Will it lose packets?
โ
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/uc5M7CdXXC
This actually happened to Evernote. They took the advice of โkeep talking to your customers and ship whatever they wantโ as the only guiding principle for product development. And what ended up happening was paying users liked it, but the product become unintuitive and feature overload for the new user. To the extent that they had to rebuild a version for the new user.
Users donโt always know if they really want something. Itโs your job to take the extra step to think on their behalf: whether they really need this. Or can what they ask be done through something much simpler. Or can you solve multiple problems of different users with one new redesign rather than a bunch of changes. The right principle is: โKeep talking and listening to your users, spend the additional time thinking on their behalf what they actually want, and ship thatโ.
๐ฅ๐ฎ๐ฏ๐ฏ๐ถ๐๐ ๐ค vs ๐๐ฎ๐ณ๐ธ๐ฎ vs ๐๐ฐ๐๐ถ๐๐ฒ๐ ๐ค
Let's briefly look at how each of these stands out:
1๏ธโฃ ๐ฅ๐ฎ๐ฏ๐ฏ๐ถ๐๐ ๐ค
โข ๐๐ฎ๐ป๐ด๐๐ฎ๐ด๐ฒ: Built on Erlang
โข ๐ฃ๐ฟ๐ผ๐๐ผ๐ฐ๐ผ๐น๐: Supports a multitude of protocols, including AMQP, MQTT, and STOMP.
โข ๐๐ฎ๐๐ฒ ๐ผ๐ณ ๐จ๐๐ฒ: Known for being developer-friendly.
โข ๐จ๐๐ฒ-๐ฐ๐ฎ๐๐ฒ: Excellent for complex routing to multiple consumers.
2๏ธโฃ ๐๐ฎ๐ณ๐ธ๐ฎ
โข ๐๐ฎ๐ป๐ด๐๐ฎ๐ด๐ฒ: Built on Scala and Java
โข ๐ฃ๐ฟ๐ผ๐๐ผ๐ฐ๐ผ๐น๐: Proprietary Kafka Protocol over TCP
โข ๐ฆ๐ฐ๐ฎ๐น๐ฎ๐ฏ๐ถ๐น๐ถ๐๐: Highly scalable with the ability to handle huge volumes of data.
โข ๐จ๐๐ฒ-๐ฐ๐ฎ๐๐ฒ: Perfect for real-time analytics and monitoring, data lakes, aggregating data from different sources.
3๏ธโฃ ๐๐ฐ๐๐ถ๐๐ฒ๐ ๐ค
โข ๐๐ฎ๐ป๐ด๐๐ฎ๐ด๐ฒ: Built on Java
โข ๐ฃ๐ฟ๐ผ๐๐ผ๐ฐ๐ผ๐น๐: Supports various protocols like AMQP, STOMP, MQTT, and more.
โข ๐๐น๐ฒ๐ ๐ถ๐ฏ๐ถ๐น๐ถ๐๐: Provides a lot of features and can be used in multiple configurations.
โข ๐จ๐๐ฒ-๐ฐ๐ฎ๐๐ฒ: Often used in enterprise systems and excels in scenarios that require complex routing and transformations.
Credit: Brij kishore Pandey