Techlist.io - Korean Tech Blog Curator

line3 min readCurated summary

Applying Spark on Kubernetes to process large-scale advertising data for LINE services

LINE Ads processes tens of billions of advertising events daily and nearly one hundred billion internal data records. As growing numbers of features increased computational demands, its Spark-on-YARN environment suffered from resource contention, inefficient scaling, and Hadoop dependencies. The team migrated to Spark on Kubernetes to achieve infrastructure independence, containerized execution, flexible scaling, and easier operational automation. ## Large-Scale LINE Ads Data Pipelines - The data pipeline supports: - Real-time advertising-event processing - Abuse and validity checks - Machine-learning systems and model training - Analytics and system integration - Advertiser reporting - The platform must handle hundreds of billions of events per day and hundreds of thousands per second. - It must provide low latency, elastic capacity, minimal service impact during failures, and rapid recovery. - The most heavily used table grew to approximately 2.91 times its December 2022 size by December 2025 as more features were added. ## Limitations of Spark on YARN - Hadoop’s storage and compute resources were colocated, causing Spark workloads to compete with HDFS and other Hadoop components. - Scaling compute required adding Hadoop nodes, even when additional storage was unnecessary, increasing cost and wasting capacity. - JVM and Spark versions were difficult to manage independently, limiting access to newer Spark features. - Applications became tightly coupled to the Hadoop infrastructure. ## How Spark on Kubernetes Works - Kubernetes replaces YARN as the cluster manager. - Spark drivers and executors run as separate Kubernetes pods. - In cluster mode: - `spark-submit` requests a driver pod. - Kubernetes schedules the driver on an appropriate node. - The driver creates a `SparkContext`, builds the DAG, and requests executors. - Executors run as independent pods with individually allocated CPU and memory. - The driver divides the DAG into stages and distributes tasks to executors. - Shuffle data is normally tied to executor-pod lifecycles unless an external shuffle service is configured. ## Advantages over YARN - **Containerized execution:** Docker images package application dependencies, improving reproducibility and CI/CD integration. - **Infrastructure independence:** Spark can use HDFS, S3, GCS, or other storage systems without requiring a Hadoop cluster. - **Simpler autoscaling:** Kubernetes can scale pods and integrate with cloud VM autoscalers. - **Unified platform:** Spark, Airflow, machine-learning workloads, and API servers can share a Kubernetes cluster. - **Governance and isolation:** Namespaces, `ResourceQuota`, and RBAC provide flexible team-level controls. - **Operational automation:** Helm, ArgoCD, GitOps, and rolling updates enable more automated application management. ## LINE Ads’ Kubernetes-Based System The platform is organized into four layers: - **Deployment layer** - GitHub Actions runs CI workflows based on repository events. - ArgoCD monitors desired and deployed states and supports easier rollback and synchronization. - **Compute layer** - Kubeflow’s Spark Operator deploys applications through the `SparkApplication` Kubernetes custom resource. - Apache YuniKorn schedules batch jobs and supports resource coordination and gang scheduling. - LogSender forwards pod logs to OpenSearch. - ClusterMonitoring sends Prometheus metrics to the company’s monitoring system. - **Storage layer** - Kafka provides high-throughput, low-latency storage for real-time advertising actions. - Hadoop remains available for large-scale, long-term analysis. - **Monitoring layer** - Kubernetes workers and Spark applications are monitored through exposed Prometheus metrics and centralized logging. The migration to Spark on Kubernetes is recommended for organizations whose Spark workloads are outgrowing tightly coupled Hadoop environments. It separates compute from storage, improves deployment flexibility, and allows data applications to be managed as cloud-native workloads.

Read original(opens in new tab)
google3 min readCurated summary

Building better AI benchmarks: How many raters are enough?

Human disagreement makes AI benchmarks difficult to reproduce, yet evaluations often use only one to five raters per item and reduce their responses to a majority vote. The study introduces an `(N, K)` framework—balancing the number of items (`N`) against raters per item (`K`)—to determine how annotation budgets should be allocated. It concludes that the best balance depends on the evaluation goal: broad sampling for majority accuracy, but deeper rating for capturing nuanced human opinions. ## The Breadth-versus-Depth Trade-off - The “forest” strategy rates many items with few raters per item. - The “tree” strategy rates fewer items with many raters per item. - Historically, AI benchmarks have favored the forest approach, typically using one to five raters per example. - This approach can miss both the overall distribution of opinions and meaningful disagreement among raters. ## Simulating Annotation Budgets - The researchers built a simulator using real-world subjective datasets, including toxicity, hate speech, safety, offensiveness, and job-related tweet classification. - They varied: - **Scale (`N`)**: 100 to 50,000 total items. - **Crowd (`K`)**: 1 to 500 raters per item. - Thousands of configurations were tested for statistical reliability, including whether model comparisons reached significance at `p < 0.05`. - The simulator also examined messy conditions such as highly imbalanced categories and tasks with multiple labels. - The simulator has been released as open source. ## Why Three to Five Raters Are Often Insufficient - Low-rater evaluations may fail to represent natural human disagreement. - They provide too little depth to reveal nuanced opinions and too little breadth to establish a reliable overall picture. - In many settings, more than 10 raters per item are needed to produce results that reflect the variation in human judgments. - More ratings per item can make model comparisons more statistically reliable. ## The Evaluation Metric Determines the Optimal Strategy - **Majority-vote accuracy** - If the goal is to determine whether a model agrees with the majority of people, rating more items is generally more effective. - This favors the forest strategy. - **Opinion range and nuance** - If the evaluation must distinguish between responses such as “yes,” “maybe,” and “no,” more raters per item are essential. - This favors the tree strategy because only repeated ratings reveal the full distribution of human opinions. - There is no universally optimal number of items or raters; the correct allocation depends on what the benchmark is intended to measure. ## Reproducibility Without Unlimited Budgets - An appropriately chosen item-to-rater ratio can produce highly reproducible results with roughly 1,000 total annotations in some settings. - Spending more money does not guarantee reliability if the budget is distributed poorly. - The study’s framework is intended to help benchmark designers choose the allocation that best fits their metric and data characteristics. ## Moving Beyond a Single Ground Truth - Many AI evaluations assume that every example has one objectively correct label. - This assumption becomes increasingly problematic for subjective tasks involving toxicity, harmful intent, ethics, safety, or social interaction. - Preserving disagreement instead of collapsing it into a plurality label can make benchmarks more representative of real human judgment. - The authors argue that understanding disagreement is as important as measuring consensus. Benchmark designers should first decide whether they need majority accuracy or a detailed picture of human opinion, then allocate ratings accordingly. In subjective evaluations, using substantially more than five raters per item may be necessary for reliable and reproducible conclusions.

Read original(opens in new tab)
google3 min readCurated summary

Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

Google Quantum AI argues that future cryptographically relevant quantum computers could break the elliptic-curve cryptography securing many cryptocurrencies sooner and with fewer resources than previously estimated. Its research presents circuits for attacking 256-bit elliptic-curve discrete logarithms using fewer than 1,200–1,450 logical qubits and 70–90 million Toffoli gates. Google urges cryptocurrency developers to migrate to post-quantum cryptography while disclosing the findings through verifiable zero-knowledge proofs rather than publishing exploitable attack details. ## Updated Quantum Resource Estimates - The relevant threat is Shor’s algorithm running on a large, fault-tolerant quantum computer. - Google developed two circuits for solving ECDLP-256: - Fewer than 1,200 logical qubits and 90 million Toffoli gates. - Fewer than 1,450 logical qubits and 70 million Toffoli gates. - Under assumptions aligned with some superconducting quantum hardware, the attack could require: - Fewer than 500,000 physical qubits. - Only a few minutes of computation. - This represents an estimated 20-fold reduction in physical-qubit requirements compared with earlier estimates. - Google connects the findings to its proposed 2029 timeline for beginning migration to post-quantum cryptography. ## Protecting Cryptocurrencies with PQC - Most blockchains and cryptocurrencies rely on elliptic-curve cryptography for essential security functions. - Post-quantum cryptography offers a practical, established direction for protecting blockchains against quantum attacks. - Migration will take significant time, creating urgency for networks to begin transitioning now. - Short- and long-term recommendations include: - Avoid exposing vulnerable wallet addresses. - Do not reuse vulnerable addresses. - Consider policy responses for abandoned or inaccessible coins. - The post points to existing post-quantum blockchain projects and experimental deployments as evidence that migration is feasible. ## Responsible Disclosure Through Zero-Knowledge Proofs - Public vulnerability disclosure must balance two risks: - Revealing enough information for defenders to respond. - Giving attackers a usable blueprint. - Cryptocurrency disclosure is especially sensitive because fear and unsupported claims can damage public confidence even before a technical attack is possible. - Google says it reduced this risk by clarifying which blockchain components are not vulnerable and emphasizing existing post-quantum progress. - It also published a zero-knowledge proof that allows independent parties to verify the resource estimates without accessing the underlying quantum circuits. - Google encourages other research groups to adopt similarly responsible disclosure practices. ## Outlook for the Cryptocurrency Ecosystem - Google hopes the work will encourage coordinated discussion among quantum researchers, security experts, cryptocurrency developers, and policymakers. - The broader goal is to preserve confidence in blockchain systems while giving them enough time to complete a post-quantum transition. Cryptocurrency projects should begin planning and testing PQC migration now, while avoiding address exposure and reuse in the interim. At the same time, quantum researchers should disclose attack estimates in ways that support verification and defense without unnecessarily enabling exploitation.

Read original(opens in new tab)
gitlab2 min readCurated summary

Changes to packages.gitlab.com: What you need to know

GitLab is migrating `packages.gitlab.com` to a new package hosting system while keeping the base domain unchanged. Existing configurations will continue working through rewrite rules until September 30, 2026, but old URL formats, GPG key locations, network requirements, and download paths must be updated before then. New installations already use the updated formats. ## Timeline and Required Updates - The legacy PackageCloud system and UI shut down on March 31, 2026. - Backward-compatible URL rewrites will be removed by the end of September 2026. - Existing users should: - Re-run the latest DEB or RPM installation script, or update repository configuration manually. - Change the GPG key URL to `https://packages.gitlab.com/gpgkey/gpg.key`. - Allow `https://storage.googleapis.com/packages-ops` through firewalls and proxies. - Update repository mirrors and direct-download automation. - Change GitLab Runner RPM references from `noarch` to `x86_64`. ## DEB Repository URL Changes - `gitlab/*` repositories such as `gitlab-ee` and `gitlab-ce` now include the distribution codename in the URL path. - Example: - Old: `.../ubuntu/` - New: `.../ubuntu/jammy` - This produces standard Debian paths containing `dists/jammy` and `pool`. - Re-running the installation script is the simplest migration method: - DEB: `script.deb.sh` - RPM: `script.rpm.sh` - `runner/*` DEB repositories, including `runner/gitlab-runner`, are unchanged. ## GPG Keys and Installation Scripts - Replace: - `https://packages.gitlab.com/gpg.key` - With: - `https://packages.gitlab.com/gpgkey/gpg.key` - Previously saved installation scripts should not be reused; download current versions from GitLab. ## Direct Package Downloads - The old PackageCloud UI used URLs ending in `download.deb` or `download.rpm`. - The new UI links directly to the actual package paths. - Automation that scrapes the old UI or constructs these legacy URLs must be changed to use the new paths or standard package-manager repositories. ## GitLab Runner RPM Packages - Runner RPM packages that were previously under a `noarch` path have moved to `x86_64`. - This affects RPM-based systems such as EL8 and EL9. - Debian-based Runner packages are unaffected. - Update scripts or configurations that reference the old `noarch/Packages` paths. ## Firewall and Network Requirements - Package downloads now redirect to Google Cloud Storage instead of AWS CloudFront. - Permit both `packages.gitlab.com` and `storage.googleapis.com/packages-ops`. - Missing allowlist entries can cause HTTP 503 errors or connection timeouts. Existing installations should be migrated well before September 30, 2026. For new setups, following GitLab’s current installation documentation handles the changes automatically.

Read original(opens in new tab)
aws3 min readCurated summary

AWS Weekly Roundup: AWS AI/ML Scholars program, Agent Plugin for AWS Serverless, and more (March 30, 2026) | Amazon Web Services

The March 30, 2026 AWS Weekly Roundup highlights the new AWS AI & ML Scholars program, which will offer free generative AI education to up to 100,000 people and fully funded Udacity Nanodegrees to 4,500 top participants. It also emphasizes new tools for serverless development, SageMaker IDE integration, expanded Lambda Managed Instance capacity, and streaming speech synthesis. AWS Summit and Community Day events are also scheduled worldwide. ## AWS AI & ML Scholars Program - Open to anyone aged 18 or older, with no prior AI or machine learning experience required. - Includes: - A foundational generative AI Challenge phase. - A fully funded three-month Udacity Nanodegree for the top 4,500 performers. - Applications close June 24, 2026. ## Serverless and Database Improvements - **Aurora PostgreSQL express configuration** enables serverless databases to be created and connected in seconds using preconfigured defaults. - **Aurora PostgreSQL is now part of the AWS Free Tier**, with eligible new customers receiving AWS credits. - The **Agent Plugin for AWS Serverless** adds skills, sub-agents, and Model Context Protocol servers to AI coding assistants such as Kiro, Claude Code, and Cursor. - It supports building, deploying, troubleshooting, and managing production-ready serverless applications. - The **Aurora DSQL Connector for Ruby** automatically generates authentication tokens for each connection while remaining compatible with the `pg` gem. ## SageMaker and AWS Console Updates - **SageMaker Studio** now supports remote connections from Kiro and Cursor, combining those IDEs’ coding workflows with SageMaker’s scalable compute. - The AWS Management Console now supports visual customization, including account colors and hiding unused regions or services to reduce interface clutter. ## Expanded Lambda Managed Instance Capacity - The file descriptor limit has increased from 1,024 to 4,096, supporting higher-concurrency and file-intensive workloads. - Functions can now use up to: - 32 GB of memory - 16 vCPUs - Users can select memory-to-vCPU ratios of 2:1, 4:1, or 8:1 for workloads such as data processing, media transcoding, and scientific simulations. ## Conversational Speech with Amazon Polly - Polly’s new Bidirectional Streaming API supports incremental text-to-speech generation. - Audio synthesis can begin before an LLM or other application has produced the complete response, making it better suited to conversational AI. ## Upcoming AWS Events - AWS Summits are free, in-person events covering cloud, AI, best practices, and networking. - Upcoming locations include Paris, London, Bengaluru, Singapore, Tel Aviv, and Stockholm. - AWS Community Days in San Francisco and Romania will feature community-led talks, workshops, and hands-on labs. AWS developers can follow the AWS News Blog and “What’s New with AWS” for additional announcements, while the AWS Builder Center and Events and Webinars pages provide opportunities for learning and community participation.

Read original(opens in new tab)
meta3 min readCurated summary

AI for American-Produced Cement and Concrete

Meta is expanding its use of AI to help concrete producers create stronger, more sustainable, and more domestically sourced mixes. Its new open-source model, Bayesian Optimization for Concrete (BOxCrete), uses existing performance data and lab results to identify promising formulations faster than traditional trial-and-error methods. Early projects show that AI can improve curing speed and reduce cracking while supporting greater use of U.S.-made cement and materials. ## The Case for AI-Designed Concrete - The U.S. produces about 400 million cubic yards of concrete annually. - Although ready-mix concrete is generally produced domestically, roughly 20–25% of cement consumption is supplied by imports. - Concrete mix designers must balance: - Structural strength - Curing speed - Workability and slump - Cost - Sustainability - Traditional design depends on laboratory experimentation, engineer judgment, and historical knowledge, making it slow and expensive to adapt. - Different cements have different chemistries, so a formulation that works with one cement may fail with another. ## Supporting Domestic Cement Production - Greater use of U.S.-made cement could strengthen domestic manufacturing, jobs, and investment. - Reshoring and foreign direct investment have returned more than 1.1 million jobs to the U.S. since 2020. - The cement and concrete sector contributes over $130 billion annually and supports approximately 600,000 jobs. - AI can help producers reformulate mixes around locally available materials without compromising performance. ## BOxCrete and Open Data - Meta is releasing BOxCrete on GitHub as an open-source model for concrete mix design. - Compared with earlier models, BOxCrete is more robust to noisy data and can predict concrete slump, an important measure of workability. - Meta is also publishing the foundational dataset used to develop the concrete mix for its Rosemount, Minnesota, data center. - The associated research paper describes the model, data, and methodology. ## Results in Minnesota - Meta, Amrize, Mortenson, and the University of Illinois used BOxCrete to design a mix for a data center foundation. - The mix used domestically sourced materials. - It reached full structural strength 43% faster than the original formulation. - It reduced cracking risk by nearly 10%. - After meeting structural requirements, the mix was approved for use in additional parts of the data center. ## Industry Partnerships in Illinois and Pennsylvania - Meta is working with Amrize and the University of Illinois to apply AI to industrial-scale concrete production. - Amrize operates 18 cement plants, 141 cement terminals, and 269 ready-mix sites across North America. - Amrize has introduced a “Made in America” cement label and announced nearly $1 billion in planned 2026 investments, partly aimed at increasing domestic cement production. - Pennsylvania-based Quadrel integrated Meta’s open-source framework into its ready-mix software. - Quadrel uses the technology for data preprocessing, batch and test normalization, feature engineering, customer-specific model training, and quality-control workflows. - Its models improve continuously as new field-test results are incorporated. ## Adaptive Experimentation - Meta’s Adaptive Experimentation platform uses Bayesian optimization to search the large space of possible concrete formulations. - The system: - Learns from historical mix designs, laboratory results, and performance metrics. - Proposes candidate mixes likely to satisfy target specifications. - Compares the performance of domestic and imported materials. - Applies technical and ingredient constraints before testing. - Updates its predictions after each new experiment. Meta’s work suggests that open-source AI can make concrete development faster, more data-driven, and better suited to domestic materials. Producers can use BOxCrete and adaptive experimentation to reduce laboratory costs, improve performance, and support more sustainable and resilient U.S. cement and concrete supply chains.

Read original(opens in new tab)
github1 min readCurated summary

GitHub for Beginners: Getting started with GitHub security

Kedasha is a Developer Advocate at GitHub who shares her software development experience with the broader developer community. She is passionate about helping others learn about technology and the tech industry. ### Professional Role - Works as a Developer Advocate at GitHub. - Shares lessons from her career with developers and learners. ### Community Engagement - Enjoys helping others understand the technology industry. - Maintains an online presence as **@itsthatladydev**.

Read original(opens in new tab)
line4 min readCurated summary

Image Content Moderation in Large-Scale Service Environments (feat. Multimodal LLM)

Image content moderation has evolved from simple rule-based filtering into an AI-powered decision system capable of handling visual context, text, and policy complexity. At large platforms, the challenge is not only accuracy but also latency, cost, scalability, and adaptability to changing policies. LY Corporation addresses these demands through optimized traditional ML models, a hybrid ML–multimodal LLM pipeline, and modular decision-making that combines OCR, visual analysis, and contextual reasoning. ## The Evolution of Content Moderation - Early systems relied on keyword matching, rule-based filters, and predefined patterns. - Machine learning enabled broader pattern recognition and detection of modified or less explicit violations. - Modern systems combine: - Deep learning for text and image classification - Multimodal models for joint image–text understanding - LLMs for context-sensitive judgments - Separate prediction and policy layers for operational flexibility - Despite these advances, image moderation remains difficult because images lack explicit structure and their meaning often depends on context. ## Why Image Moderation Is Difficult - **Visual complexity:** Backgrounds, objects, people, colors, and composition interact in ways that simple object detection cannot fully interpret. - **Context dependency:** Symbols, gestures, and imagery may have different meanings across cultures; embedded text can also determine whether an image is harmful. - **Evasion and variation:** Memes, composites, partially obscured images, and AI-generated edits continually challenge existing detectors. - **Scale requirements:** Platforms may receive millions or tens of millions of images daily, requiring high accuracy alongside low latency, reliability, and cost efficiency. ## LY Corporation’s Moderation API - LY Corporation operates a monitoring platform designed to process large-scale traffic and enforce diverse content policies. - Its image moderation API detects: - Adult content - Violent or graphic scenes - Offensive or disturbing imagery - Identity documents containing personal information - Social media screenshots and other policy-sensitive images - The system is designed to apply service-specific policies consistently while maintaining high throughput. ## Improving Accuracy, Speed, and Cost ### Traditional ML Model Optimization - A PyTorch-based image classification model was selected with latency, cost, and throughput in mind. - The model was converted to ONNX and optimized with FP16 precision. - ONNX Runtime improved execution efficiency, while FP16 reduced memory usage and inference time. - These changes increased throughput by up to **4.3 times**. ### Hybrid ML and Multimodal LLM Architecture - The traditional classifier acts as a fast first-stage filter. - Clear cases are resolved immediately by the image model. - Ambiguous cases are sent to a multimodal LLM for deeper analysis. - More than 90% of production data could be classified by the traditional model alone. - Since multimodal LLM throughput was over 100 times lower than that of the traditional model, routing every image to the LLM would have significantly increased GPU usage and cost. - The hybrid approach preserves high-quality reasoning where necessary while avoiding unnecessary LLM calls. ### vLLM-Based LLM Optimization The team optimized multimodal LLM serving with vLLM, using characteristics such as repeated prompts, predictable token lengths, and prefill-heavy workloads. - **`enable_prefix_caching`:** Reuses KV-cache blocks for repeated system prompts and templates, reducing prefill computation. - **`max_model_len`:** Limits the maximum input-plus-output length to avoid excessive KV-cache allocation. - **`max_num_seqs`:** Controls concurrent requests, balancing throughput against per-request latency and resource contention. - **`max_num_batched_tokens`:** Sets the token budget per scheduling step; larger values can improve throughput for prefill-heavy workloads. - Regularly updating vLLM is recommended because new releases add improvements such as asynchronous scheduling, CUDA graph support, and broader quantization options. ## Moving Beyond Single-Model Policy Prediction - Earlier end-to-end vision models directly predicted final policy categories from images. - This worked for visually obvious violations, such as detecting smoking, but struggled with complex behaviors such as tobacco sales. - Sales-related judgments may require combining: - Product presence - Prices - Sales language - Contact information - Encouragement to purchase - Directly learning every combination of national regulations, service policies, and exceptions created overly complex output classes. - It also made the model harder to extend and maintain, while limiting the use of text embedded in images. ## Hybrid Decision-Making with OCR and Multimodal Reasoning - The redesigned system separates visual and textual information rather than forcing one model to learn every policy combination. - OCR extracts text from images when relevant. - Extracted text helps identify policy-violating behavior or intent. - Visual signals and textual evidence are then combined with a multimodal LLM. - This allows the system to reason about context and intent beyond simple object detection, while making policy logic more modular and adaptable. The practical recommendation is to avoid routing all traffic through expensive general-purpose models. Use fast specialized models for clear cases, reserve multimodal LLMs for ambiguity, optimize serving according to workload characteristics, and separate content understanding from policy decisions so the system can evolve as requirements change.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Cloudflare Client-Side Security: smarter detection, now open to everyone

Cloudflare is making its Client-Side Security Advanced product self-serve and offering domain-based threat intelligence free to users of its basic bundle. The service detects malicious browser-side JavaScript through browser reporting, AST-based behavioral analysis, and a new LLM review layer. Its goal is to catch sophisticated skimming attacks while reducing false positives and avoiding performance impacts on customer applications. ## Growing Threat of Client-Side Attacks - Browser skimmers can steal credentials, payment data, and personal information without disrupting page loads or checkout flows. - Recent examples include: - A browser keylogger placed on a major U.S. bank’s employee merchandise store. - Malicious npm package releases capable of enabling browser-based crypto theft when bundled into front-end applications. - These attacks often exploit trusted first-party or third-party scripts rather than obvious server vulnerabilities. ## Broader Access to Client-Side Security - Client-Side Security Advanced, formerly the Page Shield add-on, is now available to self-serve customers. - Domain-based threat intelligence is complimentary for customers using the free Client-Side Security bundle. - Advanced capabilities include: - Machine-learning and LLM-assisted malicious script detection. - Continuous code-change monitoring for compliance requirements such as PCI DSS v4.0 requirement 11.6.1. - Proactive positive security rules maintained through ongoing monitoring. ## Browser-Based Monitoring Without Application Changes - Cloudflare evaluates approximately 3.5 billion scripts per day, with enterprise zones averaging about 2,200 scripts. - The system gathers signals through browser reporting mechanisms such as Content Security Policy. - Customers do not need scanners or application instrumentation. - Traffic must be proxied through Cloudflare. - The approach adds no latency to web applications. ## Detecting Script Intent - Enterprise sites may contain thousands of scripts, and roughly one-third change within a 30-day period. - Manually approving every DOM interaction or outbound connection would create excessive operational overhead. - Cloudflare instead analyzes what scripts are attempting to do. - JavaScript is represented as an Abstract Syntax Tree (AST), allowing the system to identify behavioral patterns even when code is minified, renamed, or obfuscated. ## Reducing False Positives - Client-side compromises are relatively rare but potentially severe, unlike the high-volume attacks typically handled by a WAF. - Because genuine incidents are uncommon, even accurate detection systems can produce more false alarms than real alerts. - False positives contribute to security-team fatigue and can obscure actual compromises. - Legitimate but heavily obfuscated code—such as bot challenges, tracking pixels, advertising bundles, and minified frameworks—can resemble malicious code structurally. ## GNN and LLM Detection Pipeline - Cloudflare’s primary detector is a Graph Neural Network (GNN) operating on JavaScript ASTs. - The GNN learns structural representations of code and can recognize similar behavior despite syntactic changes. - It is optimized for high recall to detect novel and zero-day threats. - Although fewer than 0.3% of analyzed traffic is incorrectly flagged, Cloudflare’s scale makes that percentage a significant number of alerts. - An LLM provides semantic context, recognizing common JavaScript frameworks, domain-specific coding patterns, and benign forms of suspicious-looking obfuscation. - The LLM complements rather than replaces the GNN: - Scripts classified as benign stop after the fast GNN evaluation. - Scripts exceeding the GNN’s risk threshold are sent to an open-source LLM hosted on Cloudflare Workers AI for a second opinion. Cloudflare’s approach combines low-overhead browser telemetry, structural machine learning, and semantic LLM review. For organizations handling payments or sensitive user data, enabling these controls can improve visibility into third-party scripts, detect unexpected code changes, and reduce the chance that false alarms overwhelm security teams.

Read original(opens in new tab)
grammarly3 min readCurated summary

What Is AI Chat? Definition, How It Works, and Key Benefits

AI chat enables open-ended, context-aware conversations with systems that generate responses dynamically rather than following fixed scripts. Powered by large language models (LLMs), it supports tasks such as writing, brainstorming, learning, summarizing, planning, and coding. Its flexibility comes with limitations: responses reflect learned patterns rather than true understanding, so users should provide clear context and verify results. ## What AI Chat Is - AI chat allows users to ask questions naturally and refine requests through follow-up messages. - It can answer questions, explain complex subjects, draft and revise text, summarize documents, generate code, and provide feedback. - Unlike fixed chatbot flows, it handles unstructured requests and evolving conversations without requiring users to restart. ## How AI Chat Works - **LLM training:** Models learn language patterns from massive text datasets rather than memorizing a fixed set of answers. - **Natural language processing:** The system analyzes prompts to infer meaning, intent, tone, and context beyond exact keyword matches. - **Response generation:** The model predicts and selects text one word at a time based on the prompt and patterns learned during training. - **Conversation context:** Recent messages help the system interpret follow-up requests, such as understanding that “make it shorter” refers to a previously generated summary. - **Ongoing refinement:** Fine-tuning and human feedback improve safety, accuracy, and alignment. Models generally do not learn from individual conversations in real time. ## AI Chat Compared with Traditional Chatbots - Traditional chatbots commonly use rules, decision trees, and scripted responses. - They work well for narrow, repeatable tasks such as FAQs, appointment booking, and order tracking. - AI chat is better suited to open-ended activities including brainstorming, drafting, explanations, and problem-solving. - “Conversational AI chatbot” usually describes a chatbot interface powered by generative AI, making it more flexible than a fully rules-based system. ## Common Uses - **Writing and editing:** Draft emails, rewrite passages, adjust tone, improve clarity, and revise reports or presentations. - **Brainstorming:** Generate ideas, outlines, alternatives, and new perspectives through iterative discussion. - **Learning and planning:** Explore unfamiliar topics, simplify complex information, and develop plans. - **Coding support:** Generate code, explain technical concepts, and help troubleshoot problems. ## Effective Use - Write clear prompts and provide relevant context. - State the goal, desired format, audience, and preferences. - Use follow-up questions to refine the response. - Review outputs for factual errors, bias, and inappropriate assumptions. AI chat is most useful as a flexible assistant rather than an unquestionable authority. Use it for exploration and productivity, but verify important information and apply human judgment before relying on its output.

Read original(opens in new tab)
grammarly3 min readCurated summary

How to Create a Chatbot Step by Step: A Beginner’s Guide

Chatbot development begins with a focused purpose, not technology. By choosing the right interaction method, chatbot type, and platform, organizations can automate routine tasks and improve user experiences without necessarily needing developers. Successful chatbots also require deliberate conversation design, testing, monitoring, and continuous improvement. ## What Chatbots Can Do - Simulate conversations through text or voice. - Answer frequently asked questions and provide information. - Handle structured tasks such as: - Checking order status - Booking appointments - Explaining policies - Guiding users through onboarding - AI-powered and hybrid chatbots can manage follow-up questions and more complex, multistep interactions. - They can reduce repetitive work, improve response consistency, and help users reach solutions faster. ## Define the Chatbot’s Goal - Identify two or three specific tasks the chatbot should handle. - Define the target audience, such as customers, employees, or students. - Establish success metrics, including: - Fewer support tickets - Faster response times - Higher task-completion rates - A narrow, well-defined purpose makes the chatbot easier to design, test, and refine. ## Choose the Interaction Method - Decide whether the chatbot will be text-based or voice-based. - Text is generally simpler to build. - Voice requires additional technical setup. - Choose where it will operate, such as: - A website - Mobile application - Messaging platform - Internal company tool - Determine how conversations begin, whether through typed messages, preset options, or proactive prompts. - The access point and interaction style directly affect development and maintenance requirements. ## Select the Chatbot Type - **Rule-based chatbots** use predefined flows, menus, and decision trees for predictable requests. - **Keyword-based chatbots** respond to specific words or short phrases, such as “pricing” or “hours.” - **AI chatbots** use artificial intelligence and natural language processing to handle varied questions and contextual follow-ups, but require more testing and oversight. - **Hybrid chatbots** combine structured rules for common tasks with AI for open-ended questions. - The choice determines the chatbot’s flexibility, behavior, complexity, and ongoing management effort. ## Choose a Building Platform - **No-code platforms** such as Chatling, Voiceflow, Zapier, and Landbot use visual interfaces and are suitable for beginners and simple chatbot tasks. - **Low-code or full-code approaches** using technologies such as Python, Node.js, or AI frameworks provide greater customization and integration capabilities. - Platform selection should account for: - Cost - Integrations - Analytics - Scalability - Data protection - Required technical expertise ## Design the Conversation Flow - Map typical conversations before implementing the chatbot. - Planning helps identify missing responses, avoid dead ends, and create a smoother user experience. - Traditional chatbots generally use structured decision paths, while AI chatbots support more flexible conversations. - The flow should reflect the chatbot’s purpose and provide a clear route for completing tasks or escalating complex issues. ## Ongoing Improvement - Building and launching the chatbot is only the beginning. - Chatbots should be tested before release and monitored afterward. - Regular refinement, accurate training data, configuration updates, and performance reviews help maintain quality over time. A practical approach is to start with a narrow use case and a simple platform, then expand as user needs and performance data become clearer. Choose AI or custom development only when the chatbot requires more flexibility, deeper integrations, or complex conversational capabilities.

Read original(opens in new tab)
cloudflare2 min readCurated summary

How we use Abstract Syntax Trees (ASTs) to turn Workflows code into visual diagrams

Cloudflare uses Abstract Syntax Trees (ASTs) to turn code-based Workflows into visual diagrams. Because Workflows execute dynamically—supporting parallel promises, awaits, loops, and conditionals—the system analyzes code structure and relationships to infer execution order. The resulting diagrams help developers understand workflow shape, especially as coding agents generate more application code. ## Why Code-Based Workflows Are Difficult to Visualize - Unlike declarative workflow builders, Cloudflare Workflows are ordinary code. - Workflows may contain: - `Promise` and `await` relationships - `Promise.all` for parallel execution - Loops and conditionals - Steps nested inside functions or classes - The runtime discovers and executes steps as it encounters them, rather than following a predefined sequence. - Unawaited steps can execute in parallel, while `await` establishes blocking dependencies. ## How Workflow Execution Works - A supervisor Durable Object, called the engine, starts for each workflow instance. - The engine dispatches execution to the user Worker. - When the Worker encounters `step.do`, control returns to the engine. - The engine executes the step, persists its result or error, and invokes the Worker again. - Since the engine does not inherently retain the complete intended order of steps, diagram generation must reconstruct those relationships from the source code. ## Parsing and Building the Workflow Graph - Cloudflare fetches the bundled Worker script at deployment time. - A parser converts the script into an Abstract Syntax Tree. - An internal service: - Identifies `WorkflowEntrypoints` - Finds calls to workflow steps - Builds and traverses an intermediate graph - Produces the final diagram through Cloudflare’s API - AST analysis tracks promises and `await` expressions to determine: - Which steps depend on one another - Which steps block execution - Which steps can run concurrently ## Handling Bundled and Minified JavaScript - Workers are generally bundled with tools such as esbuild and may be minified. - Minified output can obscure the original TypeScript structure and vary between bundlers. - The diagram system therefore has to recognize workflow patterns in dense, transformed JavaScript. - For example, several agent steps—such as summary, correctness, and clarity agents—may be created without awaiting them, indicating parallel execution. - The generated graph makes that concurrency visible even when the deployed code is difficult to read. Cloudflare’s AST-based approach provides a practical way to visualize dynamic, code-defined workflows. Developers can inspect how steps connect, branch, and execute in parallel directly from the dashboard, though the beta diagrams will continue to improve as more workflow patterns are supported.

Read original(opens in new tab)
discord3 min readCurated summary

How Multi-Factor Authentication Helps Keep Your Discord Account Safe

Discord recommends strengthening accounts with multi-factor authentication (MFA), especially passkeys or authenticator apps. MFA adds protection beyond a password, which can be stolen, guessed, or leaked. The post explains Discord’s available login protections and emphasizes using unique passwords and securely storing recovery credentials. ## Login Verification Emails - Accounts with verified email addresses receive a verification email when signing in from a new device or location. - Users must select “Verify Login” before Discord allows access. - This protection is ineffective if the email account is compromised, particularly when the same password is reused. - Discord strongly recommends using a different password for every online account. ## How Multi-Factor Authentication Works - MFA adds one or more authentication factors beyond a password: - **Something you know:** A password or secret phrase. - **Something you have:** A phone, computer, security key, or other device. - **Something you are:** A fingerprint or facial biometric. - Using multiple factors makes account takeover more difficult. - Enabling any MFA option disables login verification emails. ## Passkeys - Passkeys are presented as Discord’s fastest and most secure option because they are practically phishing-resistant. - They use a cryptographic exchange between Discord and a device, unlocked with a fingerprint, face scan, or device PIN. - Biometric data stays on the user’s device; Discord receives only the cryptographic credential needed to approve the login. - Discord supports up to 16 passkeys per account, including passkeys stored in password managers, browsers, mobile devices, or hardware security keys. - Users are encouraged to keep a backup passkey in a credential manager such as 1Password or Bitwarden. ## Authenticator Apps - Authenticator apps generate time-based one-time passwords. - Discord and the app share a secret starter value, allowing them to generate matching codes. - A new code is created every 30 seconds, while Discord also accepts the previous code to provide roughly a one-minute login window. - Supported apps include Authy, Microsoft Authenticator, and Google Authenticator. - Backup codes should be saved in a password manager or another secure, reliable location. - Backup codes can be regenerated through **My Account > View Backup Codes > Generate New Backup Codes**. ## Recommended Account Protection - Enable MFA on every Discord account. - Prefer one or more passkeys. - Use an authenticator app if passkeys are unavailable. - Use unique passwords across all services. - Store passkeys and backup codes securely, with a backup recovery method available. Overall, Discord recommends passkeys as the strongest option, with authenticator apps as the next-best choice. Login verification emails provide basic protection, but MFA offers substantially stronger defense against stolen or reused passwords.

Read original(opens in new tab)
aws2 min readCurated summary

Customize your AWS Management Console experience with visual settings including account color, region and service visibility | Amazon Web Services

AWS has expanded User Experience Customization (UXC) to let administrators tailor the Management Console by account color, visible Regions, and visible services. These settings help teams distinguish accounts and reduce clutter by showing only relevant resources. They affect console appearance only and do not restrict access through the CLI, SDKs, APIs, or Amazon Q Developer. ## Account Color Customization - Administrators can assign a color to an AWS account through **Account display settings**. - The color appears in the console navigation bar to make account purpose easier to recognize. - Teams can use colors such as: - Orange for development - Light blue for testing - Red for production ## Region Visibility - Administrators can configure which AWS Regions appear in the console’s Region selector. - They can either show all available Regions or select a specific list. - After saving, only the chosen Regions appear in the navigation bar. - This reduces unnecessary scrolling and helps users focus on approved or relevant Regions. ## Service Visibility - Administrators can select which AWS services appear in the **All services** menu and console search results. - Services can be searched for or selected by category, such as Popular services. - Hidden services are removed from the console interface but remain accessible through programmatic tools. ## Programmatic Configuration - Account customization can be managed through the `AWS::UXC::AccountCustomization` CloudFormation resource. - The resource supports: - `AccountColor` - `VisibleServices` - `VisibleRegions` - Example configurations can expose services such as `s3`, `ec2`, and `lambda`, while limiting Regions to `us-east-1` and `us-west-2`. - Templates can be deployed with the AWS CLI using `aws cloudformation deploy`. AWS administrators can use these settings to create a clearer, more focused console experience without changing permissions or underlying account access.

Read original(opens in new tab)
github1 min readCurated summary

A year of open source vulnerability trends: CVEs, advisories, and malware

The passage identifies a security professional involved in several major vulnerability-management initiatives. They curate the GitHub Advisory Database, participate in GitHub’s Security Lab, issue CVE IDs, and publish CVE records. ### Responsibilities and Affiliations - Works as a security analyst. - Curates entries in the GitHub Advisory Database. - Is a member of the Security Lab. - Helps issue CVE identifiers for vulnerabilities. - Publishes official CVE records. Overall, the individual contributes to documenting, coordinating, and communicating software security vulnerabilities.

Read original(opens in new tab)